OTL.txt part 2
========== LOP Check ==========
[2009/02/07 19:47:02 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\acccore
[2010/03/28 20:18:59 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\AVG9
[2009/01/28 22:58:28 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\CiscoCAA
[2009/08/05 20:01:12 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/06/27 12:55:11 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\LimeWire
[2009/08/27 22:33:47 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Red Kawa
[2009/07/10 06:16:31 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\RegistryPC
[2010/06/27 21:21:29 | 000,032,596 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %systemroot%\*. /mp /s >
< c:\$recycle.bin\*.* /s >
[2010/03/30 22:32:48 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-1000\desktop.ini
[2010/06/20 18:53:11 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$I2A1E2V.JPG
[2010/03/23 19:46:50 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$I33AH7Y.exe
[2010/03/23 19:47:48 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$I34QU8R.asd
[2010/06/20 18:52:38 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$I5AZ9DM.JPG
[2010/06/20 18:51:55 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$I9PBK4G.JPG
[2010/05/27 20:49:19 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$IDE3RJN.JPG
[2010/05/04 21:57:00 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$IFSLMMZ.JPG
[2010/06/24 08:11:38 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$IICRLLW.ipsw
[2010/06/20 18:51:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$ILCA9CE.JPG
[2010/05/04 21:57:03 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$IMUOIMH.JPG
[2010/03/23 19:57:55 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$IQK971X.exe
[2010/04/05 08:09:14 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$ISEVTOJ.m4v
[2010/06/12 09:52:57 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$IT6MDIP.jpg
[2010/03/23 19:57:52 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$IVIMIA7.exe
[2010/03/23 19:46:37 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$IVRC9ET.exe
[2010/05/04 21:56:57 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$IX7D4HN.JPG
[2010/06/19 20:26:21 | 000,825,215 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$R2A1E2V.JPG
[2010/03/03 08:27:15 | 005,061,512 | ---- | M] (Malwarebytes Corporation ) -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$R33AH7Y.exe
[2010/03/13 10:40:11 | 000,026,112 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$R34QU8R.asd
[2010/06/19 20:26:16 | 000,799,404 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$R5AZ9DM.JPG
[2010/06/19 20:25:46 | 001,141,570 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$R9PBK4G.JPG
[2010/05/22 01:50:11 | 000,746,195 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$RDE3RJN.JPG
[2010/05/01 12:56:39 | 000,780,573 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$RFSLMMZ.JPG
[2010/02/28 11:42:46 | 295,870,806 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$RICRLLW.ipsw
[2010/05/22 01:50:11 | 000,746,195 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$RLCA9CE.JPG
[2010/05/01 12:56:46 | 000,584,786 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$RMUOIMH.JPG
[2010/03/03 08:32:57 | 000,348,600 | ---- | M] (Honlyn (Macao Commercia) -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$RQK971X.exe
[2010/04/05 08:09:00 | 004,500,352 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$RSEVTOJ.m4v
[2009/09/10 18:58:33 | 000,019,109 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$RT6MDIP.jpg
[2010/03/02 09:19:06 | 001,936,640 | ---- | M] (ParetoLogic Inc.) -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$RVIMIA7.exe
[2010/03/01 21:28:25 | 000,000,000 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$RVRC9ET.exe
[2010/05/01 10:35:04 | 000,557,341 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\$RX7D4HN.JPG
[2010/03/23 17:41:00 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-371945664-4036494631-2048450281-500\desktop.ini
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-06-25 07:04:05
< MD5 for: AGP440.SYS >
[2007/02/18 12:01:10 | 011,678,589 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\amd64\sp2.cab:AGP440.sys
[2007/02/18 12:01:10 | 011,678,589 | ---- | M] () .cab file -- C:\Windows.old\Windows\ServicePackFiles\amd64\sp2.cab:AGP440.sys
[2008/01/20 22:21:09 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\ERDNT\cache\agp440.sys
[2008/01/20 22:21:09 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\agp440.sys
[2008/01/20 22:21:09 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/20 22:21:09 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/20 22:21:09 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/20 22:21:09 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2007/02/17 01:03:12 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=3373905E7DED6168676707F318C612FA -- C:\Windows.old\Windows\ServicePackFiles\amd64\agp440.sys
[2006/11/02 05:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >
[2007/02/18 12:01:10 | 011,678,589 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\amd64\sp2.cab:atapi.sys
[2007/02/18 12:01:10 | 011,678,589 | ---- | M] () .cab file -- C:\Windows.old\Windows\ServicePackFiles\amd64\sp2.cab:atapi.sys
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\ERDNT\cache\atapi.sys
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/20 22:21:09 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/20 22:21:09 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 05:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2005/03/24 18:12:00 | 000,148,480 | ---- | M] (Microsoft Corporation) MD5=72C77044943340964FA513B92D6D6874 -- C:\Windows.old\Windows\$NtServicePackUninstall$\atapi.sys
[2005/03/25 08:00:00 | 000,148,480 | ---- | M] (Microsoft Corporation) MD5=72C77044943340964FA513B92D6D6874 -- C:\Windows.old\Windows\system32\ReinstallBackups\0006\DriverFiles\amd64\atapi.sys
[2005/03/24 18:12:00 | 000,148,480 | ---- | M] (Microsoft Corporation) MD5=72C77044943340964FA513B92D6D6874 -- C:\Windows.old\Windows\system32\ReinstallBackups\0007\DriverFiles\amd64\atapi.sys
[2007/02/17 01:03:34 | 000,150,016 | ---- | M] (Microsoft Corporation) MD5=7A1814D0D112F50F828E25557A1ED29F -- C:\Windows.old\Windows\ServicePackFiles\amd64\atapi.sys
[2007/02/17 01:03:34 | 000,150,016 | ---- | M] (Microsoft Corporation) MD5=7A1814D0D112F50F828E25557A1ED29F -- C:\Windows.old\Windows\system32\drivers\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2009/04/11 02:27:20 | 000,643,072 | ---- | M] (Microsoft Corporation) MD5=10761177A6EBE45843F443E99509F5E7 -- C:\Windows\System32\autochk.exe
[2009/04/11 02:27:20 | 000,643,072 | ---- | M] (Microsoft Corporation) MD5=10761177A6EBE45843F443E99509F5E7 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6002.18005_none_e3df6655bee2ee3b\autochk.exe
[2007/02/18 11:50:18 | 000,817,664 | ---- | M] (Microsoft Corporation) MD5=2C40794C5094E7D49D8597D7B0C617FC -- C:\Windows.old\Windows\ServicePackFiles\amd64\autochk.exe
[2007/02/18 11:50:18 | 000,817,664 | ---- | M] (Microsoft Corporation) MD5=2C40794C5094E7D49D8597D7B0C617FC -- C:\Windows.old\Windows\system32\autochk.exe
[2008/01/20 22:22:54 | 000,642,560 | ---- | M] (Microsoft Corporation) MD5=2FC5BE79B51714B479809358E4908FC3 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6001.18000_none_e1f3ed49c1c122ef\autochk.exe
[2007/02/18 12:05:20 | 000,594,944 | ---- | M] (Microsoft Corporation) MD5=39ECC326D3F5531A13A1C0F0B43A8EDD -- C:\Windows.old\Windows\SysWOW64\autochk.exe
[2005/03/25 08:00:00 | 000,817,664 | ---- | M] (Microsoft Corporation) MD5=B2825C5030B3B77B149D6EB48D24DD0C -- C:\Windows.old\Windows\$NtServicePackUninstall$\autochk.exe
< MD5 for: BEEP.SYS >
[2008/01/20 22:21:53 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=67E506B75BD5326A3EC7B70BD014DFB6 -- C:\Windows\ERDNT\cache\beep.sys
[2008/01/20 22:21:53 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=67E506B75BD5326A3EC7B70BD014DFB6 -- C:\Windows\System32\drivers\beep.sys
[2008/01/20 22:21:53 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=67E506B75BD5326A3EC7B70BD014DFB6 -- C:\Windows\winsxs\x86_microsoft-windows-beepsys_31bf3856ad364e35_6.0.6001.18000_none_c420a153079d485b\beep.sys
[2005/03/25 08:00:00 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=8BA2E5CDFDE406DC4646AFB894804844 -- C:\Windows.old\Windows\system32\dllcache\beep.sys
[2005/03/25 08:00:00 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=8BA2E5CDFDE406DC4646AFB894804844 -- C:\Windows.old\Windows\system32\drivers\beep.sys
< MD5 for: CNGAUDIT.DLL >
[2006/11/02 05:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\ERDNT\cache\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: EVENTLOG.DLL >
[2005/03/25 08:00:00 | 000,130,048 | ---- | M] (Microsoft Corporation) MD5=2C1641EFCDA764DCC29E01A528F227A1 -- C:\Windows.old\Windows\$NtServicePackUninstall$\eventlog.dll
[2007/02/17 01:20:32 | 000,130,560 | ---- | M] (Microsoft Corporation) MD5=589B15B2B3254E2745CB205243EB8588 -- C:\Windows.old\Windows\ServicePackFiles\amd64\eventlog.dll
[2007/02/17 01:20:32 | 000,130,560 | ---- | M] (Microsoft Corporation) MD5=589B15B2B3254E2745CB205243EB8588 -- C:\Windows.old\Windows\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008/10/29 02:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2005/03/25 08:00:00 | 001,050,624 | ---- | M] (Microsoft Corporation) MD5=4B93BB34AF478A0FD9765D9B73356DC9 -- C:\Windows.old\Windows\$NtServicePackUninstall$\explorer.exe
[2008/10/29 02:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 23:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2007/02/18 12:05:28 | 001,053,184 | ---- | M] (Microsoft Corporation) MD5=A26C39540F8BE3729846E360E2C57344 -- C:\Windows.old\Windows\SysWOW64\explorer.exe
[2007/02/17 01:20:36 | 001,364,480 | ---- | M] (Microsoft Corporation) MD5=AE7A08C05F72A9242734C03230A5CD7F -- C:\Windows.old\Windows\explorer.exe
[2007/02/17 01:20:36 | 001,364,480 | ---- | M] (Microsoft Corporation) MD5=AE7A08C05F72A9242734C03230A5CD7F -- C:\Windows.old\Windows\ServicePackFiles\amd64\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\ERDNT\cache\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 22:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 22:22:34 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: IASTORV.SYS >
[2008/01/20 22:21:31 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008/01/20 22:21:31 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/20 22:21:31 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 05:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: IMM32.DLL >
[2007/02/18 12:05:32 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=27046C93A8DAE93A784989C2C283AF67 -- C:\Windows.old\Windows\SysWOW64\imm32.dll
[2007/02/17 01:30:36 | 000,212,992 | ---- | M] (Microsoft Corporation) MD5=7B9E669EA7D780F50E1918C65D9A625D -- C:\Windows.old\Windows\ServicePackFiles\amd64\imm32.dll
[2007/02/17 01:30:36 | 000,212,992 | ---- | M] (Microsoft Corporation) MD5=7B9E669EA7D780F50E1918C65D9A625D -- C:\Windows.old\Windows\system32\imm32.dll
[2005/03/25 08:00:00 | 000,212,992 | ---- | M] (Microsoft Corporation) MD5=9B3C3CAF26C4EEA4450833EAE4E92ED5 -- C:\Windows.old\Windows\$NtServicePackUninstall$\imm32.dll
[2009/04/11 02:28:20 | 000,114,688 | ---- | M] (Microsoft Corporation) MD5=C8BDCECEE082B54F0BAC838BF0A34597 -- C:\Windows\ERDNT\cache\imm32.dll
[2009/04/11 02:28:20 | 000,114,688 | ---- | M] (Microsoft Corporation) MD5=C8BDCECEE082B54F0BAC838BF0A34597 -- C:\Windows\System32\imm32.dll
[2009/04/11 02:28:20 | 000,114,688 | ---- | M] (Microsoft Corporation) MD5=C8BDCECEE082B54F0BAC838BF0A34597 -- C:\Windows\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6002.18005_none_5e419722778cc84e\imm32.dll
[2008/01/20 22:22:34 | 000,114,688 | ---- | M] (Microsoft Corporation) MD5=EC17194A193CD8E90D27CFB93DFA9A2E -- C:\Windows\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6001.18000_none_5c561e167a6afd02\imm32.dll
< MD5 for: KERNEL32.DLL >
[2009/02/13 04:21:09 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=1987D817D08F5EAF0B7F334026FDDB79 -- C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.22376_none_9401d8206f9c7e67\kernel32.dll
[2007/04/18 11:27:08 | 001,009,664 | ---- | M] (Microsoft Corporation) MD5=6BE19D6D9DAEE20CD590FE87AA533F20 -- C:\Windows.old\Windows\SysWOW64\kernel32.dll
[2007/02/17 01:34:12 | 001,503,232 | ---- | M] (Microsoft Corporation) MD5=761E392BF121D4AFC3A8E616D6835FC8 -- C:\Windows.old\Windows\$NtUninstallKB935839$\kernel32.dll
[2007/02/17 01:34:12 | 001,503,232 | ---- | M] (Microsoft Corporation) MD5=761E392BF121D4AFC3A8E616D6835FC8 -- C:\Windows.old\Windows\ServicePackFiles\amd64\kernel32.dll
[2009/02/13 03:26:37 | 000,875,520 | ---- | M] (Microsoft Corporation) MD5=B82C7AC1D559F0FD088792171D64C7F3 -- C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.16820_none_91c20a8f593529ed\kernel32.dll
[2009/02/13 03:13:01 | 000,875,520 | ---- | M] (Microsoft Corporation) MD5=BB792054BD990EC05D9E260D50FEAD39 -- C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6000.21010_none_92564f68724ae108\kernel32.dll
[2009/04/11 02:28:20 | 000,891,392 | ---- | M] (Microsoft Corporation) MD5=BB8509089E7DF514310814E1B2593FFC -- C:\Windows\ERDNT\cache\kernel32.dll
[2009/04/11 02:28:20 | 000,891,392 | ---- | M] (Microsoft Corporation) MD5=BB8509089E7DF514310814E1B2593FFC -- C:\Windows\System32\kernel32.dll
[2009/04/11 02:28:20 | 000,891,392 | ---- | M] (Microsoft Corporation) MD5=BB8509089E7DF514310814E1B2593FFC -- C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6002.18005_none_95a95e4d536d53fa\kernel32.dll
[2005/03/25 08:00:00 | 001,500,160 | ---- | M] (Microsoft Corporation) MD5=D3CBC6E982BDC19E52917A989BA9C63E -- C:\Windows.old\Windows\$NtServicePackUninstall$\kernel32.dll
[2009/02/13 04:49:05 | 000,888,832 | ---- | M] (Microsoft Corporation) MD5=DB6E3731E6F5C8AE2843F80B5787F7C6 -- C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18215_none_93b81a93564f1da0\kernel32.dll
[2008/01/20 22:22:21 | 000,888,320 | ---- | M] (Microsoft Corporation) MD5=DC2338093F91BA4E0512208E60206DDD -- C:\Windows\winsxs\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6001.18000_none_93bde541564b88ae\kernel32.dll
[2007/04/18 11:25:04 | 001,504,256 | ---- | M] (Microsoft Corporation) MD5=F231BAB7C8816A0C41180796E32C1A55 -- C:\Windows.old\Windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
[2007/04/18 11:27:06 | 001,503,744 | ---- | M] (Microsoft Corporation) MD5=F3F1C3C6DFA9266E9B3C1656F8C9BB29 -- C:\Windows.old\Windows\system32\dllcache\kernel32.dll
[2007/04/18 11:27:06 | 001,503,744 | ---- | M] (Microsoft Corporation) MD5=F3F1C3C6DFA9266E9B3C1656F8C9BB29 -- C:\Windows.old\Windows\system32\kernel32.dll
< MD5 for: MSWSOCK.DLL >
[2008/06/21 16:07:46 | 000,233,472 | ---- | M] (Microsoft Corporation) MD5=4EFACAA7671DFB04608CA0076EA35F77 -- C:\Windows.old\Windows\SysWOW64\mswsock.dll
[2005/03/25 08:00:00 | 000,489,472 | ---- | M] (Microsoft Corporation) MD5=50FB63888AE8515FAE0E4367BC16B7A8 -- C:\Windows.old\Windows\$NtServicePackUninstall$\mswsock.dll
[2008/06/21 03:29:34 | 000,493,056 | ---- | M] (Microsoft Corporation) MD5=7522FBD86A6494EFAB98AF49B12F525C -- C:\Windows.old\Windows\$hf_mig$\KB951748\SP2QFE\mswsock.dll
[2007/02/17 01:39:44 | 000,492,032 | ---- | M] (Microsoft Corporation) MD5=7F6F508DAE92E99B62287562F10343B1 -- C:\Windows.old\Windows\$NtUninstallKB951748$\mswsock.dll
[2007/02/17 01:39:44 | 000,492,032 | ---- | M] (Microsoft Corporation) MD5=7F6F508DAE92E99B62287562F10343B1 -- C:\Windows.old\Windows\ServicePackFiles\amd64\mswsock.dll
[2009/04/11 02:28:22 | 000,223,232 | ---- | M] (Microsoft Corporation) MD5=8617350C9B590B63E620881092751BCB -- C:\Windows\ERDNT\cache\mswsock.dll
[2009/04/11 02:28:22 | 000,223,232 | ---- | M] (Microsoft Corporation) MD5=8617350C9B590B63E620881092751BCB -- C:\Windows\System32\mswsock.dll
[2009/04/11 02:28:22 | 000,223,232 | ---- | M] (Microsoft Corporation) MD5=8617350C9B590B63E620881092751BCB -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.0.6002.18005_none_ba3ed0122a6d89da\mswsock.dll
[2008/01/20 22:22:10 | 000,223,232 | ---- | M] (Microsoft Corporation) MD5=89FD0595EEA4E505CABEFCF7008F2612 -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.0.6001.18000_none_b85357062d4bbe8e\mswsock.dll
[2008/06/21 16:07:28 | 000,492,544 | ---- | M] (Microsoft Corporation) MD5=9A143C80CA47FC111FB565B56B2867A9 -- C:\Windows.old\Windows\system32\dllcache\mswsock.dll
[2008/06/21 16:07:28 | 000,492,544 | ---- | M] (Microsoft Corporation) MD5=9A143C80CA47FC111FB565B56B2867A9 -- C:\Windows.old\Windows\system32\mswsock.dll
< MD5 for: NDIS.SYS >
[2005/03/25 08:00:00 | 000,334,336 | ---- | M] (Microsoft Corporation) MD5=0A7F61EA2F78BF940D0ADA7C14D51B68 -- C:\Windows.old\Windows\$NtServicePackUninstall$\ndis.sys
[2009/04/11 02:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\ERDNT\cache\ndis.sys
[2009/04/11 02:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\System32\drivers\ndis.sys
[2009/04/11 02:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6002.18005_none_a9b2a4d31930d864\ndis.sys
[2007/02/17 01:39:56 | 000,361,984 | ---- | M] (Microsoft Corporation) MD5=6FE83D05AEBEF7930D7CE91568DC99DF -- C:\Windows.old\Windows\ServicePackFiles\amd64\ndis.sys
[2007/02/17 01:39:56 | 000,361,984 | ---- | M] (Microsoft Corporation) MD5=6FE83D05AEBEF7930D7CE91568DC99DF -- C:\Windows.old\Windows\system32\drivers\ndis.sys
[2008/01/20 22:21:58 | 000,529,464 | ---- | M] (Microsoft Corporation) MD5=9BDC71790FA08F0A0B5F10462B1BD0B1 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_a7c72bc71c0f0d18\ndis.sys
< MD5 for: NETLOGON.DLL >
[2007/02/18 12:05:42 | 000,430,592 | ---- | M] (Microsoft Corporation) MD5=451564B8F22461D90CF8ED3945637845 -- C:\Windows.old\Windows\SysWOW64\netlogon.dll
[2005/03/25 08:00:00 | 000,681,984 | ---- | M] (Microsoft Corporation) MD5=918FF7D96DE11D01DBA8BFFB3218C5A0 -- C:\Windows.old\Windows\$NtServicePackUninstall$\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\ERDNT\cache\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/20 22:22:13 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
[2007/02/17 01:40:06 | 000,681,472 | ---- | M] (Microsoft Corporation) MD5=BFF99E983A1F35B4E8AA74DEA19D014B -- C:\Windows.old\Windows\ServicePackFiles\amd64\netlogon.dll
[2007/02/17 01:40:06 | 000,681,472 | ---- | M] (Microsoft Corporation) MD5=BFF99E983A1F35B4E8AA74DEA19D014B -- C:\Windows.old\Windows\system32\netlogon.dll
< MD5 for: NTFS.SYS >
[2009/04/11 02:32:49 | 001,083,880 | ---- | M] (Microsoft Corporation) MD5=6A4A98CEE84CF9E99564510DDA4BAA47 -- C:\Windows\ERDNT\cache\ntfs.sys
[2009/04/11 02:32:49 | 001,083,880 | ---- | M] (Microsoft Corporation) MD5=6A4A98CEE84CF9E99564510DDA4BAA47 -- C:\Windows\System32\drivers\ntfs.sys
[2009/04/11 02:32:49 | 001,083,880 | ---- | M] (Microsoft Corporation) MD5=6A4A98CEE84CF9E99564510DDA4BAA47 -- C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6002.18005_none_a85ca2c91a0d64df\ntfs.sys
[2005/03/25 08:00:00 | 001,120,256 | ---- | M] (Microsoft Corporation) MD5=7855BF547765226E996A9A49D763D198 -- C:\Windows.old\Windows\$NtServicePackUninstall$\ntfs.sys
[2008/01/20 22:21:58 | 001,081,912 | ---- | M] (Microsoft Corporation) MD5=B4EFFE29EB4F15538FD8A9681108492D -- C:\Windows\winsxs\x86_microsoft-windows-ntfs_31bf3856ad364e35_6.0.6001.18000_none_a67129bd1ceb9993\ntfs.sys
[2007/02/18 11:57:50 | 001,041,920 | ---- | M] (Microsoft Corporation) MD5=C8904B5F90AB2236692E83D491C4D426 -- C:\Windows.old\Windows\ServicePackFiles\amd64\ntfs.sys
[2007/02/18 11:57:50 | 001,041,920 | ---- | M] (Microsoft Corporation) MD5=C8904B5F90AB2236692E83D491C4D426 -- C:\Windows.old\Windows\system32\drivers\ntfs.sys
< MD5 for: NTMSSVC.DLL >
[2005/03/25 08:00:00 | 000,794,112 | ---- | M] (Microsoft Corporation) MD5=266D43093AC3C2C28E496220DA802B6D -- C:\Windows.old\Windows\$NtServicePackUninstall$\ntmssvc.dll
[2007/02/17 01:41:30 | 000,794,112 | ---- | M] (Microsoft Corporation) MD5=A398462077F68A41B4DFF9FB7E8FC7B8 -- C:\Windows.old\Windows\ServicePackFiles\amd64\ntmssvc.dll
[2007/02/17 01:41:30 | 000,794,112 | ---- | M] (Microsoft Corporation) MD5=A398462077F68A41B4DFF9FB7E8FC7B8 -- C:\Windows.old\Windows\system32\ntmssvc.dll
[2008/01/20 22:23:39 | 000,460,288 | ---- | M] (Microsoft Corporation) MD5=A7DFF9642D510BE1EEC6664CD0369953 -- C:\Windows\winsxs\x86_microsoft-windows-r..emanagement-service_31bf3856ad364e35_6.0.6001.18000_none_0e3e31f00e12b007\ntmssvc.dll
< MD5 for: NVSTOR.SYS >
[2006/11/02 05:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/20 22:21:29 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008/01/20 22:21:29 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/20 22:21:29 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: PROQUOTA.EXE >
[2007/02/17 01:50:24 | 000,071,680 | ---- | M] (Microsoft Corporation) MD5=086678EC458D5C1F7E787350B00C25F6 -- C:\Windows.old\Windows\ServicePackFiles\amd64\proquota.exe
[2007/02/17 01:50:24 | 000,071,680 | ---- | M] (Microsoft Corporation) MD5=086678EC458D5C1F7E787350B00C25F6 -- C:\Windows.old\Windows\system32\proquota.exe
[2005/03/25 08:00:00 | 000,071,168 | ---- | M] (Microsoft Corporation) MD5=9B54A96C2923A2CB3A39487A14FB2CD7 -- C:\Windows.old\Windows\$NtServicePackUninstall$\proquota.exe
[2006/11/02 05:45:33 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=C31AE90F24870B9A51655C36A9EB4BF3 -- C:\Windows\System32\proquota.exe
[2006/11/02 05:45:33 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=C31AE90F24870B9A51655C36A9EB4BF3 -- C:\Windows\winsxs\x86_microsoft-windows-proquota_31bf3856ad364e35_6.0.6000.16386_none_259035db957a1715\proquota.exe
[2007/02/18 12:05:46 | 000,053,248 | ---- | M] (Microsoft Corporation) MD5=E915E1D41B4C5B3FB28AB8355D4B70A3 -- C:\Windows.old\Windows\SysWOW64\proquota.exe
< MD5 for: QMGR.DLL >
[2008/01/20 22:23:10 | 000,758,272 | ---- | M] (Microsoft Corporation) MD5=02ED7B4DBC2A3232A389106DA7515C3D -- C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6001.18000_none_2390c4ecf9720b8c\qmgr.dll
[2005/03/25 08:00:00 | 000,707,072 | ---- | M] (Microsoft Corporation) MD5=049B94073E8BC3EA91D0CE96C9FFC077 -- C:\Windows.old\Windows\$NtServicePackUninstall$\qmgr.dll
[2007/02/17 01:50:54 | 000,706,560 | ---- | M] (Microsoft Corporation) MD5=749C15323919984A6E08BAD427D89936 -- C:\Windows.old\Windows\ServicePackFiles\amd64\qmgr.dll
[2007/02/17 01:50:54 | 000,706,560 | ---- | M] (Microsoft Corporation) MD5=749C15323919984A6E08BAD427D89936 -- C:\Windows.old\Windows\system32\qmgr.dll
[2009/04/11 02:28:23 | 000,758,784 | ---- | M] (Microsoft Corporation) MD5=93952506C6D67330367F7E7934B6A02F -- C:\Windows\ERDNT\cache\qmgr.dll
[2009/04/11 02:28:23 | 000,758,784 | ---- | M] (Microsoft Corporation) MD5=93952506C6D67330367F7E7934B6A02F -- C:\Windows\System32\qmgr.dll
[2009/04/11 02:28:23 | 000,758,784 | ---- | M] (Microsoft Corporation) MD5=93952506C6D67330367F7E7934B6A02F -- C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6002.18005_none_257c3df8f693d6d8\qmgr.dll
< MD5 for: SCECLI.DLL >
[2008/01/20 22:22:59 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2007/02/17 01:54:00 | 000,315,392 | ---- | M] (Microsoft Corporation) MD5=40453F57AAC02F32F785642F5C2E211E -- C:\Windows.old\Windows\ServicePackFiles\amd64\scecli.dll
[2007/02/17 01:54:00 | 000,315,392 | ---- | M] (Microsoft Corporation) MD5=40453F57AAC02F32F785642F5C2E211E -- C:\Windows.old\Windows\system32\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\ERDNT\cache\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
[2005/03/25 08:00:00 | 000,315,392 | ---- | M] (Microsoft Corporation) MD5=A832D97D4113E28DB89C33219D9E7D20 -- C:\Windows.old\Windows\$NtServicePackUninstall$\scecli.dll
[2007/02/18 12:05:48 | 000,188,928 | ---- | M] (Microsoft Corporation) MD5=E7B7FD7D8907DADED4928E922608887F -- C:\Windows.old\Windows\SysWOW64\scecli.dll
< MD5 for: SFCFILES.DLL >
[2005/03/25 08:00:00 | 002,277,376 | ---- | M] (Microsoft Corporation) MD5=169CEF2B1C7FA6E5B5C2EA0CCC126D6D -- C:\Windows.old\Windows\$NtServicePackUninstall$\sfcfiles.dll
[2007/02/18 12:05:50 | 002,374,656 | ---- | M] (Microsoft Corporation) MD5=67BE14F048F09F0D197AC4D2459AD1EE -- C:\Windows.old\Windows\SysWOW64\sfcfiles.dll
[2007/02/17 01:54:48 | 002,323,968 | ---- | M] (Microsoft Corporation) MD5=6AA02E6A7115DEAC6483FD1E332F32AA -- C:\Windows.old\Windows\ServicePackFiles\amd64\sfcfiles.dll
[2007/02/17 01:54:48 | 002,323,968 | ---- | M] (Microsoft Corporation) MD5=6AA02E6A7115DEAC6483FD1E332F32AA -- C:\Windows.old\Windows\system32\sfcfiles.dll
< MD5 for: SPOOLSV.EXE >
[2009/04/11 02:28:05 | 000,127,488 | ---- | M] (Microsoft Corporation) MD5=524BFBEA40E6E404737CCBC754647A2E -- C:\Windows\ERDNT\cache\spoolsv.exe
[2009/04/11 02:28:05 | 000,127,488 | ---- | M] (Microsoft Corporation) MD5=524BFBEA40E6E404737CCBC754647A2E -- C:\Windows\System32\spoolsv.exe
[2009/04/11 02:28:05 | 000,127,488 | ---- | M] (Microsoft Corporation) MD5=524BFBEA40E6E404737CCBC754647A2E -- C:\Windows\winsxs\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6002.18005_none_d8371c2dbeaa9062\spoolsv.exe
[2007/02/17 01:55:54 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=5918677301E62A935A837EC22BA7088C -- C:\Windows.old\Windows\ServicePackFiles\amd64\spoolsv.exe
[2007/02/17 01:55:54 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=5918677301E62A935A837EC22BA7088C -- C:\Windows.old\Windows\system32\spoolsv.exe
[2008/01/20 22:22:54 | 000,125,952 | ---- | M] (Microsoft Corporation) MD5=846CDF9A3CF4DA9B306ADFB7D55EE4C2 -- C:\Windows\winsxs\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6001.18000_none_d64ba321c188c516\spoolsv.exe
[2005/03/25 08:00:00 | 000,109,568 | ---- | M] (Microsoft Corporation) MD5=91B7BD2B38884601E54ED5CED837459A -- C:\Windows.old\Windows\$NtServicePackUninstall$\spoolsv.exe
< MD5 for: SRSVC.DLL >
[2005/03/25 08:00:00 | 000,231,424 | ---- | M] (Microsoft Corporation) MD5=10E36DCEC537563E1EB0CAABD2E6C16B -- C:\Windows.old\Windows\$NtServicePackUninstall$\srsvc.dll
[2007/02/17 01:56:32 | 000,231,424 | ---- | M] (Microsoft Corporation) MD5=7B6DA719973755BD091131E53AD6EC23 -- C:\Windows.old\Windows\ServicePackFiles\amd64\srsvc.dll
[2007/02/17 01:56:32 | 000,231,424 | ---- | M] (Microsoft Corporation) MD5=7B6DA719973755BD091131E53AD6EC23 -- C:\Windows.old\Windows\system32\srsvc.dll
< MD5 for: SVCHOST.EXE >
[2008/01/20 22:21:53 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\ERDNT\cache\svchost.exe
[2008/01/20 22:21:53 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\System32\svchost.exe
[2008/01/20 22:21:53 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
[2007/02/17 01:59:04 | 000,025,600 | ---- | M] (Microsoft Corporation) MD5=46300880A5062A41C16DF5E3E836A6C9 -- C:\Windows.old\Windows\ServicePackFiles\amd64\svchost.exe
[2007/02/17 01:59:04 | 000,025,600 | ---- | M] (Microsoft Corporation) MD5=46300880A5062A41C16DF5E3E836A6C9 -- C:\Windows.old\Windows\system32\svchost.exe
[2005/03/25 08:00:00 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=BDDFEB952617080316692951215793E9 -- C:\Windows.old\Windows\$NtServicePackUninstall$\svchost.exe
[2007/02/18 12:05:52 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=C09CCFE81DEC9B162533D7184D705682 -- C:\Windows.old\Windows\SysWOW64\svchost.exe
< MD5 for: TERMSRV.DLL >
[2009/04/11 02:28:24 | 000,449,024 | ---- | M] (Microsoft Corporation) MD5=BB95DA09BEF6E7A131BFF3BA5032090D -- C:\Windows\ERDNT\cache\termsrv.dll
[2009/04/11 02:28:24 | 000,449,024 | ---- | M] (Microsoft Corporation) MD5=BB95DA09BEF6E7A131BFF3BA5032090D -- C:\Windows\System32\termsrv.dll
[2009/04/11 02:28:24 | 000,449,024 | ---- | M] (Microsoft Corporation) MD5=BB95DA09BEF6E7A131BFF3BA5032090D -- C:\Windows\winsxs\x86_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.0.6002.18005_none_908abad45165e2ae\termsrv.dll
[2008/01/20 22:22:20 | 000,448,512 | ---- | M] (Microsoft Corporation) MD5=D605031E225AACCBCEB5B76A4F1603A6 -- C:\Windows\winsxs\x86_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.0.6001.18000_none_8e9f41c854441762\termsrv.dll
[2005/03/25 08:00:00 | 000,363,008 | ---- | M] (Microsoft Corporation) MD5=E99987410B7F2202114C567480271600 -- C:\Windows.old\Windows\$NtServicePackUninstall$\termsrv.dll
[2007/02/17 01:59:44 | 000,364,032 | ---- | M] (Microsoft Corporation) MD5=F4849A4962779132B02CA4BBF696F434 -- C:\Windows.old\Windows\ServicePackFiles\amd64\termsrv.dll
[2007/02/17 01:59:44 | 000,364,032 | ---- | M] (Microsoft Corporation) MD5=F4849A4962779132B02CA4BBF696F434 -- C:\Windows.old\Windows\system32\termsrv.dll
< MD5 for: USERINIT.EXE >
[2008/01/20 22:22:58 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\ERDNT\cache\userinit.exe
[2008/01/20 22:22:58 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008/01/20 22:22:58 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2007/02/17 02:00:56 | 000,039,424 | ---- | M] (Microsoft Corporation) MD5=438393CC0B5122B5D988BD7BA05FE3C9 -- C:\Windows.old\Windows\ServicePackFiles\amd64\userinit.exe
[2007/02/17 02:00:56 | 000,039,424 | ---- | M] (Microsoft Corporation) MD5=438393CC0B5122B5D988BD7BA05FE3C9 -- C:\Windows.old\Windows\system32\userinit.exe
[2005/03/25 08:00:00 | 000,039,424 | ---- | M] (Microsoft Corporation) MD5=5EF907A339CAF229F3CE38909C93F53B -- C:\Windows.old\Windows\$NtServicePackUninstall$\userinit.exe
[2007/02/18 12:05:56 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=B5FEB3B971A8B8C81CE9DE65031A87E5 -- C:\Windows.old\Windows\SysWOW64\userinit.exe
< MD5 for: WS2_32.DLL >
[2005/03/25 08:00:00 | 000,180,736 | ---- | M] (Microsoft Corporation) MD5=30949CC9AD21DCA6E1DC8373CBBE0261 -- C:\Windows.old\Windows\$NtServicePackUninstall$\ws2_32.dll
[2007/02/18 12:06:02 | 000,083,456 | ---- | M] (Microsoft Corporation) MD5=5C34F97D87B2A8C9CB4422E67F2DAB61 -- C:\Windows.old\Windows\SysWOW64\ws2_32.dll
[2007/02/17 02:04:26 | 000,178,688 | ---- | M] (Microsoft Corporation) MD5=9E36B0413B6C3FADAF9E5C61A3F7F888 -- C:\Windows.old\Windows\ServicePackFiles\amd64\ws2_32.dll
[2007/02/17 02:04:26 | 000,178,688 | ---- | M] (Microsoft Corporation) MD5=9E36B0413B6C3FADAF9E5C61A3F7F888 -- C:\Windows.old\Windows\system32\ws2_32.dll
[2008/01/20 22:22:57 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B -- C:\Windows\ERDNT\cache\ws2_32.dll
[2008/01/20 22:22:57 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B -- C:\Windows\System32\ws2_32.dll
[2008/01/20 22:22:57 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.0.6001.18000_none_f2b7b0c2ce5605c4\ws2_32.dll
< MD5 for: XMLPROV.DLL >
[2007/02/17 02:05:28 | 000,326,144 | ---- | M] (Microsoft Corporation) MD5=A1ABA5A0B4F1FF9B83C50F92F8C080A2 -- C:\Windows.old\Windows\ServicePackFiles\amd64\xmlprov.dll
[2007/02/17 02:05:28 | 000,326,144 | ---- | M] (Microsoft Corporation) MD5=A1ABA5A0B4F1FF9B83C50F92F8C080A2 -- C:\Windows.old\Windows\system32\xmlprov.dll
[2005/03/25 08:00:00 | 000,326,144 | ---- | M] (Microsoft Corporation) MD5=BB72B18E7DFB6C348DEAEAF55B771261 -- C:\Windows.old\Windows\$NtServicePackUninstall$\xmlprov.dll
[2007/02/18 12:06:04 | 000,131,584 | ---- | M] (Microsoft Corporation) MD5=C5B83F9A09A3EBFE8A931472F6DA4E38 -- C:\Windows.old\Windows\SysWOW64\xmlprov.dll
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 32892 bytes -> C:\Users\Administrator\Documents\083.AVI:TOC.WMV
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >