alex1009 | 29.11.2009 15:07 | Code:
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.tscc - C:\Windows\System32\tsccvid.dll (TechSmith Corporation)
OTL cannot create restorepoints on Vista OSs!
========== Files/Folders - Created Within 14 Days ==========
[2009.11.29 12:21:27 | 00,000,000 | ---D | C] -- C:\Programme\trend micro
[2009.11.29 12:21:26 | 00,000,000 | ---D | C] -- C:\rsit
[2009.11.29 11:53:49 | 00,000,000 | ---D | C] -- C:\Users\Hank\Desktop\Malware
[2009.11.29 09:59:13 | 00,000,000 | ---D | C] -- C:\Users\Hank\AppData\Roaming\Malwarebytes
[2009.11.29 09:59:07 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009.11.29 09:59:05 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009.11.29 09:59:05 | 00,000,000 | ---D | C] -- C:\Programme\Malwarebytes' Anti-Malware
[2009.11.29 09:59:05 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009.11.29 09:46:24 | 00,000,000 | ---D | C] -- C:\Programme\CCleaner
[2009.11.19 20:48:44 | 00,000,000 | ---D | C] -- C:\Programme\Windows Portable Devices
========== Files - Modified Within 14 Days ==========
[2009.11.29 14:27:09 | 04,456,448 | ---- | M] () -- C:\Users\Hank\ntuser.dat
[2009.11.29 14:22:01 | 00,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2009.11.29 14:09:48 | 00,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009.11.29 14:09:47 | 00,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009.11.29 14:00:02 | 00,000,498 | ---- | M] () -- C:\Windows\tasks\1-Klick-Wartung.job
[2009.11.29 12:57:00 | 00,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2009.11.29 12:21:19 | 00,781,909 | ---- | M] () -- C:\Users\Hank\Desktop\RSIT.exe
[2009.11.29 11:56:58 | 00,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2009.11.29 11:56:43 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009.11.29 11:56:40 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009.11.29 11:56:38 | 21,370,42944 | -HS- | M] () -- C:\hiberfil.sys
[2009.11.29 11:55:24 | 00,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2009.11.29 11:55:07 | 00,524,288 | -HS- | M] () -- C:\Users\Hank\ntuser.dat{24b7e877-803c-11dd-bf0f-001d093f44ce}.TMContainer00000000000000000001.regtrans-ms
[2009.11.29 11:55:07 | 00,065,536 | -HS- | M] () -- C:\Users\Hank\ntuser.dat{24b7e877-803c-11dd-bf0f-001d093f44ce}.TM.blf
[2009.11.29 11:55:01 | 06,291,456 | -H-- | M] () -- C:\Users\Hank\AppData\Local\IconCache.db
[2009.11.29 09:59:10 | 00,000,820 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.11.29 09:46:25 | 00,001,672 | ---- | M] () -- C:\Users\Hank\Desktop\CCleaner.lnk
[2009.11.28 08:52:02 | 00,000,056 | -H-- | M] () -- C:\Windows\System32\ezsidmv.dat
[2009.11.27 16:43:27 | 00,003,808 | ---- | M] () -- C:\Windows\fs1235.dat
[2009.11.21 02:53:34 | 01,593,836 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009.11.21 02:53:34 | 00,685,418 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2009.11.21 02:53:34 | 00,642,214 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009.11.21 02:53:34 | 00,150,882 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2009.11.21 02:53:34 | 00,122,762 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009.11.20 20:37:58 | 00,000,575 | ---- | M] () -- C:\Users\Hank\Desktop\2004_08_07 Grillen zu Hause - Verknüpfung.lnk
[2009.11.20 18:00:44 | 00,015,629 | ---- | M] () -- C:\Users\Hank\Reifen.docx
[2009.11.20 15:33:58 | 00,014,543 | ---- | M] () -- C:\Users\Hank\G Chat.docx
[2009.11.20 12:51:57 | 00,001,217 | ---- | M] () -- C:\Users\Hank\Desktop\Free YouTube to MP3 Converter.lnk
[2009.11.20 12:49:01 | 00,001,034 | ---- | M] () -- C:\Users\Hank\Desktop\DVDVideoSoft Free Studio.lnk
[2009.11.20 08:35:26 | 00,011,961 | ---- | M] () -- C:\Users\Hank\Guido.docx
[2009.11.20 05:54:38 | 00,002,631 | ---- | M] () -- C:\Users\Hank\Desktop\Microsoft Office Word 2007.lnk
[2009.11.19 21:22:34 | 00,001,973 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2009.11.19 20:48:30 | 00,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2009.11.19 20:48:22 | 00,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2009.11.15 17:34:07 | 00,014,526 | ---- | M] () -- C:\Windows\System32\TuneUpDefragService_20091115-163405.dmp
========== Files Created - No Company Name ==========
[2009.11.29 12:20:55 | 00,781,909 | ---- | C] () -- C:\Users\Hank\Desktop\RSIT.exe
[2009.11.29 09:59:10 | 00,000,820 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.11.29 09:46:25 | 00,001,672 | ---- | C] () -- C:\Users\Hank\Desktop\CCleaner.lnk
[2009.11.28 08:52:02 | 00,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2009.11.27 16:37:56 | 00,003,808 | ---- | C] () -- C:\Windows\fs1235.dat
[2009.11.20 20:37:58 | 00,000,575 | ---- | C] () -- C:\Users\Hank\Desktop\2004_08_07 Grillen zu Hause - Verknüpfung.lnk
[2009.11.20 18:00:40 | 00,015,629 | ---- | C] () -- C:\Users\Hank\Reifen.docx
[2009.11.20 15:33:57 | 00,014,543 | ---- | C] () -- C:\Users\Hank\G Chat.docx
[2009.11.20 12:51:57 | 00,001,217 | ---- | C] () -- C:\Users\Hank\Desktop\Free YouTube to MP3 Converter.lnk
[2009.11.20 08:33:30 | 00,011,961 | ---- | C] () -- C:\Users\Hank\Guido.docx
[2009.11.19 20:48:30 | 00,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2009.11.19 20:48:22 | 00,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2009.11.15 17:34:05 | 00,014,526 | ---- | C] () -- C:\Windows\System32\TuneUpDefragService_20091115-163405.dmp
[2009.08.28 21:54:04 | 00,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.04.18 18:09:26 | 01,953,696 | ---- | C] () -- C:\Windows\System32\igklg400.dll
[2009.04.18 18:09:26 | 01,533,360 | ---- | C] () -- C:\Windows\System32\igklg450.dll
[2009.04.18 18:09:26 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1409.dll
[2009.04.18 18:09:26 | 00,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2009.04.08 13:51:00 | 00,000,021 | ---- | C] () -- C:\Windows\DvInesKurusOleServer003.INI
[2009.02.11 22:00:42 | 00,000,074 | ---- | C] () -- C:\Windows\tm.ini
[2009.01.17 13:18:37 | 00,087,552 | ---- | C] () -- C:\Windows\System32\cpwmon2k.dll
[2008.09.14 13:00:43 | 00,210,944 | ---- | C] () -- C:\Windows\System32\MSVCRT10.DLL
[2008.04.09 14:47:35 | 00,000,027 | ---- | C] () -- C:\Windows\VIPZKA.INI
[2008.04.09 14:02:24 | 00,000,151 | ---- | C] () -- C:\Windows\ODBC.INI
[2008.04.09 13:51:45 | 00,014,616 | ---- | C] () -- C:\Windows\System32\skypdfmonpro.dll
[2008.04.09 13:51:45 | 00,012,568 | ---- | C] () -- C:\Windows\System32\skypdfmonuipro.dll
[2008.04.09 13:19:35 | 00,000,092 | ---- | C] () -- C:\Users\Hank\AppData\Local\fusioncache.dat
[2008.04.09 13:00:56 | 00,000,021 | ---- | C] () -- C:\Windows\DvInesKurusOleServer002.INI
[2008.04.09 12:57:30 | 00,000,103 | ---- | C] () -- C:\Windows\dvinesinstalllocation001.INI
[2008.04.09 12:57:28 | 00,000,103 | ---- | C] () -- C:\Windows\dvinesinstart001.INI
[2008.04.09 12:55:00 | 00,000,021 | ---- | C] () -- C:\Windows\Startup.INI
[2008.04.03 14:57:52 | 00,116,224 | ---- | C] () -- C:\Windows\System32\redmonnt.dll
[2008.03.21 07:57:08 | 00,054,784 | ---- | C] () -- C:\Users\Hank\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.03.19 04:08:37 | 00,910,304 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2008.03.19 04:08:37 | 00,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1253.dll
[2008.03.19 04:08:35 | 00,004,608 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll
[2008.03.19 04:08:34 | 00,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2007.07.25 17:40:02 | 00,999,424 | ---- | C] () -- C:\Windows\System32\WLIHVUI.dll
[2006.11.03 18:25:56 | 00,389,120 | ---- | C] () -- C:\Windows\System32\btwhidcs.dll
[2006.11.02 13:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 11:25:44 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006.11.02 08:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2001.11.14 13:56:00 | 01,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
[1999.01.19 14:18:30 | 00,110,080 | ---- | C] () -- C:\Windows\System32\LFPNG60N.DLL
[1999.01.19 14:18:30 | 00,046,080 | ---- | C] () -- C:\Windows\System32\LFTIF60N.DLL
[1999.01.19 14:18:30 | 00,043,008 | ---- | C] () -- C:\Windows\System32\LTFIL60N.DLL
[1999.01.19 14:18:30 | 00,020,480 | ---- | C] () -- C:\Windows\System32\LFPSD60N.DLL
[1999.01.19 14:18:30 | 00,019,968 | ---- | C] () -- C:\Windows\System32\LFTGA60N.DLL
[1999.01.19 14:18:30 | 00,019,456 | ---- | C] () -- C:\Windows\System32\LFWPG60N.DLL
[1999.01.19 14:18:30 | 00,019,456 | ---- | C] () -- C:\Windows\System32\LFWMF60N.DLL
[1999.01.19 14:18:28 | 00,176,128 | ---- | C] () -- C:\Windows\System32\LFFAX60N.DLL
[1999.01.19 14:18:28 | 00,141,824 | ---- | C] () -- C:\Windows\System32\LFCMP60N.DLL
[1999.01.19 14:18:28 | 00,023,552 | ---- | C] () -- C:\Windows\System32\LFPCX60N.DLL
[1999.01.19 14:18:28 | 00,022,528 | ---- | C] () -- C:\Windows\System32\LFPCT60N.DLL
[1999.01.19 14:18:28 | 00,022,528 | ---- | C] () -- C:\Windows\System32\LFEPS60N.DLL
[1999.01.19 14:18:28 | 00,022,016 | ---- | C] () -- C:\Windows\System32\LFBMP60N.DLL
[1999.01.19 14:18:28 | 00,018,432 | ---- | C] () -- C:\Windows\System32\LFMSP60N.DLL
[1999.01.19 14:18:28 | 00,017,920 | ---- | C] () -- C:\Windows\System32\LFMAC60N.DLL
[1995.02.14 23:11:00 | 00,017,920 | ---- | C] () -- C:\Windows\System32\IMPLODE.DLL
========== LOP Check ==========
[2009.09.27 10:45:18 | 00,000,000 | ---D | M] -- C:\Users\Hank\AppData\Roaming\Ashampoo Cover Studio 2
[2009.11.07 10:57:01 | 00,000,000 | ---D | M] -- C:\Users\Hank\AppData\Roaming\Audacity
[2008.08.03 09:59:03 | 00,000,000 | ---D | M] -- C:\Users\Hank\AppData\Roaming\CDBurnerXP_Soft
[2008.03.27 17:13:21 | 00,000,000 | ---D | M] -- C:\Users\Hank\AppData\Roaming\eBay
[2009.01.05 20:47:01 | 00,000,000 | ---D | M] -- C:\Users\Hank\AppData\Roaming\Nokia
[2009.10.25 05:03:11 | 00,000,000 | ---D | M] -- C:\Users\Hank\AppData\Roaming\PC Suite
[2008.03.26 16:05:44 | 00,000,000 | ---D | M] -- C:\Users\Hank\AppData\Roaming\TuneUp Software
[2008.10.05 16:13:19 | 00,000,000 | ---D | M] -- C:\Users\Hank\AppData\Roaming\Zylom
[2009.11.29 14:00:02 | 00,000,498 | ---- | M] () -- C:\Windows\Tasks\1-Klick-Wartung.job
[2009.11.29 11:55:32 | 00,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2009.04.10 22:28:26 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2006.11.02 10:46:12 | 00,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2008.01.19 08:36:19 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009.04.10 22:28:26 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2009.04.10 22:28:24 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2006.11.02 10:46:11 | 00,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2008.01.19 08:35:36 | 00,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
[2009.04.10 22:28:24 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
[2006.11.02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< %SYSTEMDRIVE%\sceclt.dll /s /md5 >
< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >
< %SYSTEMDRIVE%\logevent.dll /s /md5 >
< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
[2007.09.06 17:43:26 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Drivers\storage\R166200\iastor.sys
[2007.03.21 13:58:56 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Programme\Intel\Intel Matrix Storage Manager\Driver\IaStor.sys
[2007.03.21 13:59:30 | 00,381,720 | ---- | M] (Intel Corporation) MD5=9D7ED4275702E2FC409F2CC563245740 -- C:\Programme\Intel\Intel Matrix Storage Manager\Driver64\IaStor.sys
[2007.09.06 17:43:26 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\drivers\iaStor.sys
[2007.09.06 17:43:26 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_3a63e5a6\iaStor.sys
[2007.09.06 17:43:26 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_5f6e7be5\iaStor.sys
< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
[2006.11.02 10:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2008.01.19 08:42:09 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2006.11.02 10:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.19 08:42:09 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2009.04.10 22:32:28 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2008.03.19 03:51:01 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=9E7E85EC61D1C9C3171CC08427108863 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_5a9555b4\atapi.sys
[2008.03.19 04:07:57 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=61CA2C1E145809813C28752298CF9843 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_5da5d093\atapi.sys
[2008.03.21 08:59:45 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_64dfd8ea\atapi.sys
[2008.03.19 04:07:57 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=7EB55F6BEFB392BD312CD0CD5263305D -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_6c3af7d3\atapi.sys
[2008.03.21 08:59:46 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.03.19 03:51:36 | 00,019,048 | ---- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_82339ef2\atapi.sys
[2009.04.10 22:32:28 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2006.11.02 10:49:36 | 00,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.01.19 08:41:30 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.03.19 03:51:50 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=3E39E69F31F95D056703212E94320899 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_e6b2949c\atapi.sys
[2008.03.19 03:51:36 | 00,019,048 | ---- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16391_none_daf194c024ab5b06\atapi.sys
[2008.03.19 04:07:57 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=7EB55F6BEFB392BD312CD0CD5263305D -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16470_none_db063634249c06f4\atapi.sys
[2008.03.21 08:59:46 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.03.19 03:51:36 | 00,019,048 | ---- | M] (Microsoft Corporation) MD5=5653737BAD8C6C10136451C195C19881 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20485_none_db8a029f3dbd443b\atapi.sys
[2008.03.19 03:51:01 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=9E7E85EC61D1C9C3171CC08427108863 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20509_none_dbe4850d3d78c736\atapi.sys
[2008.03.19 03:51:50 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=3E39E69F31F95D056703212E94320899 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20544_none_dbb443eb3d9db847\atapi.sys
[2008.03.19 04:07:57 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=61CA2C1E145809813C28752298CF9843 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20580_none_db8503133dc1c2af\atapi.sys
[2008.03.21 08:59:45 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
[2008.01.19 08:41:30 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2009.04.10 22:32:28 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >
< %SYSTEMDRIVE%\viasraid.sys /s /md5 >
< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2008.03.19 03:51:04 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 -- C:\Windows\System32\drivers\AGP440.sys
[2008.01.19 08:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.03.19 03:51:04 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_8ed06b47\AGP440.sys
[2006.11.02 10:49:52 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[2008.01.19 08:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.03.19 03:51:04 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16400_none_b82caac9c18a4e3b\AGP440.sys
[2008.03.19 03:51:04 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=BF34B4A0E0B64440C5389AA6B902F4AD -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20496_none_b85af81edaeb8461\AGP440.sys
[2008.01.19 08:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.19 08:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >
< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >
< End of report > |