NetSvcs: 6to4 - File not found
NetSvcs: Ias - D:\WINDOWS\system32\ias [2010.03.12 15:49:50 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - D:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - D:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - D:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - D:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - D:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - D:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - D:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - D:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.WMV3 - D:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)
========== Files/Folders - Created Within 30 Days ==========
[2010.07.01 11:24:01 | 000,574,464 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\Libor\Plocha\OTL.exe
[2010.07.01 10:53:17 | 000,000,000 | ---D | C] -- D:\Program Files\trend micro
[2010.07.01 10:53:00 | 000,000,000 | ---D | C] -- D:\rsit
[2010.06.30 19:45:47 | 000,000,000 | -HSD | C] -- D:\Documents and Settings\Libor\Data aplikací\Security Master AV
[2010.06.30 19:45:43 | 000,000,000 | -HSD | C] -- D:\Documents and Settings\All Users\Data aplikací\SMEAZRPSSRAV
[2010.06.30 19:44:36 | 000,000,000 | -HSD | C] -- D:\Documents and Settings\All Users\Data aplikací\f06aa2c
[2010.06.24 13:00:03 | 000,000,000 | ---D | C] -- D:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Google
[2010.06.24 12:56:39 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Libor\Data aplikací\Google
[2010.06.24 12:55:55 | 000,000,000 | ---D | C] -- D:\Documents and Settings\LocalService\Local Settings\Data aplikací\Google
[2010.06.24 12:55:42 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Data aplikací\Sun
[2010.06.24 12:54:31 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Libor\Local Settings\Data aplikací\Google
[2010.06.24 12:48:09 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Data aplikací\Google
[2010.06.24 12:48:06 | 000,000,000 | ---D | C] -- D:\Program Files\Google
[2010.06.24 12:39:09 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\deployJava1.dll
[2010.06.24 12:39:08 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\javaws.exe
[2010.06.24 12:39:08 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\javaw.exe
[2010.06.24 12:39:08 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\java.exe
[4 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.07.01 11:24:06 | 000,574,464 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Libor\Plocha\OTL.exe
[2010.07.01 11:00:34 | 000,000,938 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.07.01 08:40:54 | 000,000,934 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.07.01 08:38:02 | 000,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT
[2010.07.01 08:37:58 | 100,192,256 | -HS- | M] () -- D:\hiberfil.sys
[2010.07.01 08:37:58 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2010.06.30 20:57:08 | 001,835,008 | -H-- | M] () -- D:\Documents and Settings\Libor\NTUSER.DAT
[2010.06.30 20:57:08 | 000,000,178 | -HS- | M] () -- D:\Documents and Settings\Libor\ntuser.ini
[2010.06.30 20:56:48 | 003,220,848 | -H-- | M] () -- D:\Documents and Settings\Libor\Local Settings\Data aplikací\IconCache.db
[2010.06.30 20:11:18 | 000,001,142 | ---- | M] () -- D:\WINDOWS\WINCMD.INI
[2010.06.30 09:02:42 | 000,013,646 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2010.06.29 11:10:34 | 000,000,265 | ---- | M] () -- D:\Documents and Settings\Libor\Plocha\VAZ 2121 NIVA ‹ Katalog produktů Náhradní díly Lada.url
[2010.06.25 14:58:30 | 000,000,405 | ---- | M] () -- D:\Documents and Settings\Libor\Plocha\Většina lidí po pětačtyřicítce nemá na sex energii, souloží v posteli a za tmy – Novinky.cz.url
[2010.06.24 12:37:38 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\javaws.exe
[2010.06.24 12:37:38 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\javaw.exe
[2010.06.24 12:37:38 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\java.exe
[2010.06.24 12:37:38 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\javacpl.cpl
[2010.06.24 12:37:36 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\deployJava1.dll
[2010.06.16 13:58:46 | 000,002,505 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT
[2010.06.14 09:39:14 | 000,000,240 | ---- | M] () -- D:\Documents and Settings\Libor\Plocha\Plné zobrazení fotografie z bazaru plavidel (
www.plavidla.cz).url
[2010.06.11 12:45:12 | 000,020,480 | ---- | M] () -- D:\Documents and Settings\Libor\Dokumenty\KUPNÍ SMLOUVA Lodní motor.doc
[2010.06.11 08:58:04 | 000,093,480 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT
[2010.06.10 16:44:28 | 000,001,374 | ---- | M] () -- D:\WINDOWS\imsins.BAK
[2010.06.07 10:19:10 | 000,000,282 | ---- | M] () -- D:\Documents and Settings\Libor\Plocha\PRODÁM KRÁSNOU LOĎ (1069841589) - Aukro - Aukce OnLine.url
[4 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.06.29 11:10:27 | 000,000,265 | ---- | C] () -- D:\Documents and Settings\Libor\Plocha\VAZ 2121 NIVA ‹ Katalog produktů Náhradní díly Lada.url
[2010.06.25 14:58:26 | 000,000,405 | ---- | C] () -- D:\Documents and Settings\Libor\Plocha\Většina lidí po pětačtyřicítce nemá na sex energii, souloží v posteli a za tmy – Novinky.cz.url
[2010.06.24 12:55:29 | 000,000,938 | ---- | C] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.06.24 12:55:24 | 000,000,934 | ---- | C] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.06.14 09:39:11 | 000,000,240 | ---- | C] () -- D:\Documents and Settings\Libor\Plocha\Plné zobrazení fotografie z bazaru plavidel (
www.plavidla.cz).url
[2010.06.11 12:45:04 | 000,020,480 | ---- | C] () -- D:\Documents and Settings\Libor\Dokumenty\KUPNÍ SMLOUVA Lodní motor.doc
[2010.06.07 10:19:08 | 000,000,282 | ---- | C] () -- D:\Documents and Settings\Libor\Plocha\PRODÁM KRÁSNOU LOĎ (1069841589) - Aukro - Aukce OnLine.url
[2010.03.12 18:07:58 | 000,001,142 | ---- | C] () -- D:\WINDOWS\WINCMD.INI
[2010.03.12 15:43:54 | 000,027,440 | ---- | C] () -- D:\WINDOWS\System32\drivers\secdrv.sys
========== LOP Check ==========
[2010.03.13 09:11:12 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2010.06.30 19:44:38 | 000,000,000 | -HSD | M] -- D:\Documents and Settings\All Users\Data aplikací\f06aa2c
[2010.06.30 19:45:44 | 000,000,000 | -HSD | M] -- D:\Documents and Settings\All Users\Data aplikací\SMEAZRPSSRAV
[2010.05.05 08:55:52 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Libor\Data aplikací\Control Components
[2010.06.30 19:45:48 | 000,000,000 | -HSD | M] -- D:\Documents and Settings\Libor\Data aplikací\Security Master AV
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = D:\WINDOWS\system32\ctfmon.exe -- [2006.03.02 12:00:00 | 000,015,360 | ---- | M] (Microsoft Corporation)
"MSMSGS" = "D:\Program Files\Messenger\msmsgs.exe" /background -- [2004.08.17 15:58:18 | 001,667,584 | ---- | M] (Microsoft Corporation)
"ccagent.exe" = D:\Documents and Settings\Libor\Data aplikací\Control Components\ccagent.exe -- File not found
"swg" = "D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -- [2010.06.24 12:52:04 | 000,039,408 | ---- | M] (Google Inc.)
"Security Master AV" = "D:\Documents and Settings\All Users\Data aplikací\f06aa2c\SMf06a_2144.exe" /s /d -- [2010.06.30 19:45:00 | 003,502,080 | ---- | M] (Vfftksl)
< c:\windows\*.* /U >
[1 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
[2007.07.25 14:19:34 | 006,383,200 | ---- | M] (InstallShield Software Corporation) -- D:\pci_us_smartrecovery.exe
[2007.12.21 08:46:32 | 017,760,400 | ---- | M] (DivX, Inc.) -- D:\DivXInstaller.exe
[2009.09.07 16:27:52 | 001,236,215 | ---- | M] () -- D:\DTI.EXE
[2009.08.10 17:21:42 | 017,558,968 | ---- | M] (JAP-Team) -- D:\japsetup.exe
[2009.09.07 16:39:32 | 000,790,016 | ---- | M] (Microsoft Corporation) -- D:\nusb33a_cs.exe
[2009.09.07 16:50:32 | 000,774,144 | ---- | M] (Microsoft Corporation) -- D:\nusb33e.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.03.12 15:56:06 | 000,000,000 | --SD | M] -- D:\Documents and Settings\Libor\Data aplikací\Microsoft
[2010.03.12 16:18:36 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Libor\Data aplikací\Identities
[2010.03.12 18:29:28 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Libor\Data aplikací\Sun
[2010.03.16 15:36:58 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Libor\Data aplikací\Macromedia
[2010.04.02 13:58:22 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Libor\Data aplikací\Help
[2010.04.10 13:38:22 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Libor\Data aplikací\Adobe
[2010.05.05 08:55:52 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Libor\Data aplikací\Control Components
[2010.06.24 12:56:40 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Libor\Data aplikací\Google
[2010.06.30 19:45:48 | 000,000,000 | -HSD | M] -- D:\Documents and Settings\Libor\Data aplikací\Security Master AV
< %APPDATA%\*.exe /s >
[2010.05.05 08:55:54 | 000,067,090 | ---- | M] () -- D:\Documents and Settings\Libor\Data aplikací\Control Components\uninstall.exe
< MD5 for: AGP440.SYS >
[2006.03.02 12:00:00 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\agp440.sys
< MD5 for: ATAPI.SYS >
[2006.03.02 12:00:00 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\atapi.sys
[2006.03.02 12:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- D:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\autochk.exe
[2006.03.02 12:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- D:\WINDOWS\system32\autochk.exe
[2006.03.02 13:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- D:\WINDOWS\system32\dllcache\autochk.exe
< MD5 for: CDROM.SYS >
[2006.03.02 12:00:00 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cdrom.sys
[2006.03.02 12:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- D:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2006.03.02 12:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- D:\WINDOWS\system32\cryptsvc.dll
[2006.03.02 13:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- D:\WINDOWS\system32\dllcache\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 05:21:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\eventlog.dll
[2006.03.02 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- D:\WINDOWS\system32\dllcache\eventlog.dll
[2006.03.02 12:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- D:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\explorer.exe
[2006.03.02 12:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- D:\WINDOWS\explorer.exe
[2006.03.02 12:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- D:\WINDOWS\system32\dllcache\explorer.exe
[1999.05.05 22:22:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=81EF5B254642034E4139BC589B45D629 -- D:\zaloha_old_disk\zaloha\c\WIN.OLD\EXPLORER.EXE
[1999.05.05 22:22:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=81EF5B254642034E4139BC589B45D629 -- D:\zaloha_old_disk\zaloha\c\WINDOWS\EXPLORER.EXE
< MD5 for: HAL.DLL >
[2006.03.02 12:00:00 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\hal.dll
[2006.03.02 12:00:00 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- D:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2006.03.02 12:00:00 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\changer.sys
< MD5 for: ISAPNP.SYS >
[2006.03.02 12:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- D:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 04:27:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\isapnp.sys
< MD5 for: LSASS.EXE >
[2006.03.02 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- D:\WINDOWS\system32\dllcache\lsass.exe
[2006.03.02 12:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- D:\WINDOWS\system32\lsass.exe
[2008.04.14 05:22:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.13 21:20:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ndis.sys
[2006.03.02 12:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- D:\WINDOWS\system32\dllcache\ndis.sys
[2006.03.02 12:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- D:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- D:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- D:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2006.03.02 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- D:\WINDOWS\system32\dllcache\netlogon.dll
[2006.03.02 12:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- D:\WINDOWS\system32\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\netlogon.dll
< MD5 for: SCECLI.DLL >
[2006.03.02 13:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- D:\WINDOWS\system32\dllcache\scecli.dll
[2006.03.02 12:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- D:\WINDOWS\system32\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\scecli.dll
< MD5 for: SMSS.EXE >
[2006.03.02 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- D:\WINDOWS\system32\dllcache\smss.exe
[2006.03.02 12:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- D:\WINDOWS\system32\smss.exe
[2008.04.14 05:22:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\svchost.exe
[2006.03.02 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- D:\WINDOWS\system32\dllcache\svchost.exe
[2006.03.02 12:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- D:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.06.20 12:45:14 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- D:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:45:14 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- D:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- D:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- D:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2006.03.02 12:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- D:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- D:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\userinit.exe
[2006.03.02 12:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- D:\WINDOWS\system32\dllcache\userinit.exe
[2006.03.02 12:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- D:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2006.03.02 13:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- D:\WINDOWS\system32\dllcache\winlogon.exe
[2006.03.02 12:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- D:\WINDOWS\system32\winlogon.exe
[2008.04.14 05:22:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\winlogon.exe
< MD5 for: WS2_32.DLL >
[2006.03.02 13:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- D:\WINDOWS\system32\dllcache\ws2_32.dll
[2006.03.02 12:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- D:\WINDOWS\system32\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- D:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ws2_32.dll
[1999.05.05 22:22:00 | 000,073,728 | ---- | M] (Microsoft Corporation) MD5=B61FD94EA42E742C4E45CD93C92A5886 -- D:\zaloha_old_disk\zaloha\c\WIN.OLD\SYSTEM\WS2_32.DLL
[1999.05.05 22:22:00 | 000,073,728 | ---- | M] (Microsoft Corporation) MD5=B61FD94EA42E742C4E45CD93C92A5886 -- D:\zaloha_old_disk\zaloha\c\WINDOWS\SYSTEM\WS2_32.DLL
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2010.04.16 17:38:08 | 000,357,888 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- D:\WINDOWS\system32\dxtmsft.dll
[2010.04.16 17:38:08 | 000,205,312 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- D:\WINDOWS\system32\dxtrans.dll
[2010.04.16 17:38:08 | 000,251,392 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- D:\WINDOWS\system32\iepeers.dll
[1 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2010.03.12 15:55:02 | 000,454,656 | ---- | M] () -- D:\WINDOWS\system32\config\system.sav
[2010.03.12 15:55:02 | 000,638,976 | ---- | M] () -- D:\WINDOWS\system32\config\software.sav
[2010.03.12 15:55:02 | 000,094,208 | ---- | M] () -- D:\WINDOWS\system32\config\default.sav
< %systemroot%\system32\*.dll /lockedfiles >
[2010.04.16 17:38:08 | 000,357,888 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- D:\WINDOWS\system32\dxtmsft.dll
[2010.04.16 17:38:08 | 000,205,312 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- D:\WINDOWS\system32\dxtrans.dll
[2010.04.16 17:38:08 | 000,251,392 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- D:\WINDOWS\system32\iepeers.dll
[1 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0\0
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2010.06.30 09:02:42 | 000,013,646 | ---- | M] () -- D:\WINDOWS\system32\wpa.dbl
[1 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]
< End of report >