Re: Prosim o kontrolu logu.
Napsal: 21 zář 2010 16:04
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2004.08.17 15:49:24 | 000,015,360 | ---- | M] (Microsoft Corporation)
< c:\windows\*.* /U >
[4 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2008.11.18 15:05:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Adobe
[2010.03.12 21:19:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Ahead
[2009.05.13 15:53:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Apple Computer
[2008.11.07 22:46:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ATI
[2010.04.14 11:49:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Autodesk
[2010.07.19 16:35:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Azureus
[2009.05.03 21:19:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Capcom
[2008.11.11 13:17:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\CyberLink
[2010.07.05 16:03:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DAEMON Tools
[2009.03.28 14:54:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite
[2009.03.28 15:38:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Pro
[2009.09.20 15:18:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Download Manager
[2010.09.11 10:51:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\dvdcss
[2009.01.28 13:05:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\EPSON
[2008.11.07 23:36:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ESET
[2008.11.11 10:42:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\FaxCtr
[2008.12.14 01:18:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Help
[2009.06.08 16:06:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ICQ
[2008.11.07 22:36:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Identities
[2008.11.07 22:50:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\InstallShield
[2008.11.18 15:05:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\InterTrust
[2010.03.06 14:56:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Kingston
[2010.08.05 20:31:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\LangSoft
[2008.11.19 14:59:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Leadertech
[2008.11.07 23:42:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Macromedia
[2009.10.06 21:30:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Malwarebytes
[2009.03.10 18:33:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Media Player Classic
[2009.01.20 22:59:21 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft
[2010.01.03 22:52:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\MOBILedit
[2008.11.08 11:11:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla
[2010.03.12 20:05:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Nero
[2009.09.04 20:49:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Nordic Games
[2009.01.02 01:02:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ProtectDisc
[2008.11.11 00:03:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Publish Providers
[2010.08.09 18:22:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Raptr
[2010.03.06 14:56:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Security_File
[2008.12.05 16:04:55 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\SecuROM
[2010.09.04 14:46:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Skype
[2008.11.13 11:39:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Sony
[2009.12.21 21:59:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Sports Interactive
[2008.12.06 00:37:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Sun
[2010.02.04 19:02:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Tropico 3
[2009.01.14 14:47:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\TuneUp Software
[2010.04.14 16:22:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Ubisoft
[2009.03.10 18:25:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Uniblue
[2010.09.20 20:06:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\uTorrent
[2009.02.28 11:40:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\VitySoft
[2010.08.27 15:00:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\vlc
[2010.08.15 13:20:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Vso
[2009.07.03 11:43:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\WinRAR
< %APPDATA%\*.exe /s >
[2009.09.29 12:12:08 | 001,519,616 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Kingston\SecureTraveler.exe
[2008.11.07 22:42:33 | 000,009,158 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{5399ACAF-7B15-43D5-9233-4E797B184FD2}\ARPPRODUCTICON.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_124305e.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_12db153c.exe
[2010.09.20 21:08:56 | 000,005,430 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_154754de.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_16496df1.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_18be6784.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_26e91eb.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_294823.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_2cd672ae.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_39b32d12.exe
[2010.09.20 21:08:57 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_428b26a6.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_440d491c.exe
[2010.09.20 21:08:57 | 000,013,262 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_45091238.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_4ae13d6c.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_4d064db7.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_5af141bb.exe
[2010.09.20 21:08:57 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_644366bb.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_69525f90.exe
[2010.09.20 21:08:57 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_701f5d03.exe
[2010.09.20 21:08:57 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_74d4dc8.exe
[2010.09.20 21:08:57 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_7a5a767d.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_7e87390c.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_bb32ea6.exe
[2010.09.20 21:08:56 | 000,009,662 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_f3e99.exe
[2007.01.29 16:34:14 | 002,479,568 | ---- | M] ( ) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\y6oatlgg.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe
[2009.09.29 12:12:08 | 001,519,616 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Security_File\AP\SecureTraveler.exe
[2010.05.28 03:48:25 | 000,922,400 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\Lukáš\Data aplikací\Sun\Java\JRERunOnce.exe
< MD5 for: AGP440.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\agp440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 09:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\cmdcons\autochk.exe
[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\autochk.exe
[2004.08.17 15:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\system32\autochk.exe
[2004.08.17 15:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\system32\dllcache\autochk.exe
< MD5 for: CDROM.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\cdrom.sys
[2004.08.03 22:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\cryptsvc.dll
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
[2008.04.14 09:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 09:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\eventlog.dll
[2007.05.17 22:34:04 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files\CyberLink\PowerDirector\EventLog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 09:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\hal.dll
[2004.08.03 22:59:14 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\changer.sys
< MD5 for: ISAPNP.SYS >
[2001.10.25 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\isapnp.sys
< MD5 for: LSASS.EXE >
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\lsass.exe
[2008.04.14 09:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.14 01:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\dllcache\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\netlogon.dll
[2008.04.14 09:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\scecli.dll
[2008.04.14 09:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\scecli.dll
< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\dllcache\smss.exe
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\smss.exe
[2004.08.17 16:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 09:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\dllcache\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.04.14 01:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\system32\drivers\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 09:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\dllcache\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\system32\winlogon.exe
[2008.04.14 09:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\winlogon.exe
< MD5 for: WS2_32.DLL >
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\ws2_32.dll
[2008.04.14 09:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2010.09.21 17:57:38 | 000,524,288 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010.09.21 15:49:09 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\security.sav
[2010.09.21 17:57:38 | 040,632,320 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010.09.21 17:57:38 | 010,485,760 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0\0
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2010.09.21 16:16:19 | 000,000,288 | ---- | M] () -- C:\WINDOWS\system32\$winnt$.inf
[2010.09.21 16:13:03 | 000,016,832 | ---- | M] () -- C:\WINDOWS\system32\amcompat.tlb
[2010.09.21 16:12:08 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\system32\cdplayer.exe.manifest
[2010.09.21 16:10:38 | 000,023,876 | ---- | M] () -- C:\WINDOWS\system32\emptyregdb.dat
[2010.09.21 16:18:47 | 000,298,848 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[2010.09.21 16:12:13 | 000,000,488 | RH-- | M] () -- C:\WINDOWS\system32\logonui.exe.manifest
[2010.09.21 16:12:08 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\system32\ncpa.cpl.manifest
[2010.09.21 16:13:03 | 000,023,392 | ---- | M] () -- C:\WINDOWS\system32\nscompat.tlb
[2010.09.21 16:12:08 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\system32\nwc.cpl.manifest
[2010.09.21 16:23:26 | 000,100,572 | ---- | M] () -- C:\WINDOWS\system32\perfc005.dat
[2010.09.21 16:23:26 | 000,087,544 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2010.09.21 16:23:26 | 000,496,788 | ---- | M] () -- C:\WINDOWS\system32\perfh005.dat
[2010.09.21 16:23:26 | 000,501,294 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2010.09.21 16:23:25 | 001,204,914 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2010.09.21 16:12:08 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\system32\sapi.cpl.manifest
[2010.09.21 16:12:13 | 000,000,488 | RH-- | M] () -- C:\WINDOWS\system32\WindowsLogon.manifest
[2010.09.21 16:22:24 | 000,002,228 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2010.09.21 16:12:08 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\system32\wuaucpl.cpl.manifest
< End of report >
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2004.08.17 15:49:24 | 000,015,360 | ---- | M] (Microsoft Corporation)
< c:\windows\*.* /U >
[4 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2008.11.18 15:05:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Adobe
[2010.03.12 21:19:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Ahead
[2009.05.13 15:53:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Apple Computer
[2008.11.07 22:46:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ATI
[2010.04.14 11:49:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Autodesk
[2010.07.19 16:35:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Azureus
[2009.05.03 21:19:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Capcom
[2008.11.11 13:17:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\CyberLink
[2010.07.05 16:03:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DAEMON Tools
[2009.03.28 14:54:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite
[2009.03.28 15:38:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Pro
[2009.09.20 15:18:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Download Manager
[2010.09.11 10:51:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\dvdcss
[2009.01.28 13:05:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\EPSON
[2008.11.07 23:36:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ESET
[2008.11.11 10:42:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\FaxCtr
[2008.12.14 01:18:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Help
[2009.06.08 16:06:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ICQ
[2008.11.07 22:36:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Identities
[2008.11.07 22:50:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\InstallShield
[2008.11.18 15:05:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\InterTrust
[2010.03.06 14:56:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Kingston
[2010.08.05 20:31:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\LangSoft
[2008.11.19 14:59:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Leadertech
[2008.11.07 23:42:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Macromedia
[2009.10.06 21:30:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Malwarebytes
[2009.03.10 18:33:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Media Player Classic
[2009.01.20 22:59:21 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft
[2010.01.03 22:52:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\MOBILedit
[2008.11.08 11:11:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla
[2010.03.12 20:05:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Nero
[2009.09.04 20:49:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Nordic Games
[2009.01.02 01:02:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ProtectDisc
[2008.11.11 00:03:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Publish Providers
[2010.08.09 18:22:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Raptr
[2010.03.06 14:56:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Security_File
[2008.12.05 16:04:55 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\SecuROM
[2010.09.04 14:46:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Skype
[2008.11.13 11:39:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Sony
[2009.12.21 21:59:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Sports Interactive
[2008.12.06 00:37:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Sun
[2010.02.04 19:02:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Tropico 3
[2009.01.14 14:47:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\TuneUp Software
[2010.04.14 16:22:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Ubisoft
[2009.03.10 18:25:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Uniblue
[2010.09.20 20:06:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\uTorrent
[2009.02.28 11:40:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\VitySoft
[2010.08.27 15:00:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\vlc
[2010.08.15 13:20:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Vso
[2009.07.03 11:43:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\WinRAR
< %APPDATA%\*.exe /s >
[2009.09.29 12:12:08 | 001,519,616 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Kingston\SecureTraveler.exe
[2008.11.07 22:42:33 | 000,009,158 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{5399ACAF-7B15-43D5-9233-4E797B184FD2}\ARPPRODUCTICON.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_124305e.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_12db153c.exe
[2010.09.20 21:08:56 | 000,005,430 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_154754de.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_16496df1.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_18be6784.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_26e91eb.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_294823.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_2cd672ae.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_39b32d12.exe
[2010.09.20 21:08:57 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_428b26a6.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_440d491c.exe
[2010.09.20 21:08:57 | 000,013,262 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_45091238.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_4ae13d6c.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_4d064db7.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_5af141bb.exe
[2010.09.20 21:08:57 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_644366bb.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_69525f90.exe
[2010.09.20 21:08:57 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_701f5d03.exe
[2010.09.20 21:08:57 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_74d4dc8.exe
[2010.09.20 21:08:57 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_7a5a767d.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_7e87390c.exe
[2010.09.20 21:08:56 | 000,015,086 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_bb32ea6.exe
[2010.09.20 21:08:56 | 000,009,662 | R--- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft\Installer\{DE6A7775-D036-4216-AD8A-2ACBAC49F532}\_f3e99.exe
[2007.01.29 16:34:14 | 002,479,568 | ---- | M] ( ) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\y6oatlgg.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe
[2009.09.29 12:12:08 | 001,519,616 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Security_File\AP\SecureTraveler.exe
[2010.05.28 03:48:25 | 000,922,400 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\Lukáš\Data aplikací\Sun\Java\JRERunOnce.exe
< MD5 for: AGP440.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\agp440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 09:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\cmdcons\autochk.exe
[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\autochk.exe
[2004.08.17 15:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\system32\autochk.exe
[2004.08.17 15:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\system32\dllcache\autochk.exe
< MD5 for: CDROM.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\cdrom.sys
[2004.08.03 22:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\cryptsvc.dll
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
[2008.04.14 09:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 09:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\eventlog.dll
[2007.05.17 22:34:04 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files\CyberLink\PowerDirector\EventLog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 09:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\hal.dll
[2004.08.03 22:59:14 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\changer.sys
< MD5 for: ISAPNP.SYS >
[2001.10.25 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\isapnp.sys
< MD5 for: LSASS.EXE >
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\lsass.exe
[2008.04.14 09:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.14 01:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\dllcache\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\netlogon.dll
[2008.04.14 09:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\scecli.dll
[2008.04.14 09:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\scecli.dll
< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\dllcache\smss.exe
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\smss.exe
[2004.08.17 16:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 09:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\dllcache\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.04.14 01:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\system32\drivers\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 09:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\dllcache\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\system32\winlogon.exe
[2008.04.14 09:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\winlogon.exe
< MD5 for: WS2_32.DLL >
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\ws2_32.dll
[2008.04.14 09:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\ff65d7285a0ac7b11c922fdff2c799a3\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2010.09.21 17:57:38 | 000,524,288 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010.09.21 15:49:09 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\security.sav
[2010.09.21 17:57:38 | 040,632,320 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010.09.21 17:57:38 | 010,485,760 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0\0
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2010.09.21 16:16:19 | 000,000,288 | ---- | M] () -- C:\WINDOWS\system32\$winnt$.inf
[2010.09.21 16:13:03 | 000,016,832 | ---- | M] () -- C:\WINDOWS\system32\amcompat.tlb
[2010.09.21 16:12:08 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\system32\cdplayer.exe.manifest
[2010.09.21 16:10:38 | 000,023,876 | ---- | M] () -- C:\WINDOWS\system32\emptyregdb.dat
[2010.09.21 16:18:47 | 000,298,848 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[2010.09.21 16:12:13 | 000,000,488 | RH-- | M] () -- C:\WINDOWS\system32\logonui.exe.manifest
[2010.09.21 16:12:08 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\system32\ncpa.cpl.manifest
[2010.09.21 16:13:03 | 000,023,392 | ---- | M] () -- C:\WINDOWS\system32\nscompat.tlb
[2010.09.21 16:12:08 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\system32\nwc.cpl.manifest
[2010.09.21 16:23:26 | 000,100,572 | ---- | M] () -- C:\WINDOWS\system32\perfc005.dat
[2010.09.21 16:23:26 | 000,087,544 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2010.09.21 16:23:26 | 000,496,788 | ---- | M] () -- C:\WINDOWS\system32\perfh005.dat
[2010.09.21 16:23:26 | 000,501,294 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2010.09.21 16:23:25 | 001,204,914 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2010.09.21 16:12:08 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\system32\sapi.cpl.manifest
[2010.09.21 16:12:13 | 000,000,488 | RH-- | M] () -- C:\WINDOWS\system32\WindowsLogon.manifest
[2010.09.21 16:22:24 | 000,002,228 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2010.09.21 16:12:08 | 000,000,749 | RH-- | M] () -- C:\WINDOWS\system32\wuaucpl.cpl.manifest
< End of report >