1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Control Panel Not Working

Discussion in 'Malware and Virus Removal Archive' started by scorekeeper, 2010/06/16.

  1. 2010/06/20
    scorekeeper

    scorekeeper Inactive Thread Starter

    Joined:
    2007/02/18
    Messages:
    104
    Likes Received:
    0
    Ran eset from Mozillia and it said it had to install to run that way. Allowed it, but it froze the machine. Restarted and ran it from explorer. It froze the machine after 20%.

    Waiting for further instructions.
     
  2. 2010/06/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please run a BitDefender Online Scan

    • Disable your antivirus program.
    • Click Start Scanner button.
    • Click Start scan button
    • Allow browser plug-in to be installed when prompted.
    • Click I Agree to agree to the EULA.
    • Please refrain from using the computer until the scan is finished.
    • When the scan is finished, click on View log.
    • Notepad will open with scan results.
    • Save the report to your desktop and post its content in your next reply.
     

  3. to hide this advert.

  4. 2010/06/20
    scorekeeper

    scorekeeper Inactive Thread Starter

    Joined:
    2007/02/18
    Messages:
    104
    Likes Received:
    0
    Will try in a bit. Have some work to do right now.

    But, I have some info you might want to be aware of. When I was working on a problem with the machine before, see "should have allowed the kid.. ", something I did killed my outlook express's ability to read message bodies. Well, evidently it was when the machine froze trying to run eset, because the message bodies are gone again.

    Luckily, the run command regsvr32 inetcomm.dll brings them back.
     
  5. 2010/06/20
    scorekeeper

    scorekeeper Inactive Thread Starter

    Joined:
    2007/02/18
    Messages:
    104
    Likes Received:
    0
    QuickScan Beta 32-bit v0.9.9.23
    -------------------------------
    Scan date: Sun Jun 20 12:41:40 2010
    Machine ID: 10BDC44F

    C:\WINNT\ShellIconCache - could not be scanned


    No infection found.
    -------------------



    Processes
    ---------
    <unsigned> FinePrint pdfFactory 1708 C:\WINNT\System32\spool\DRIVERS\W32X86\2\fppdis1.exe
    <unsigned> iTouch 1616 C:\Program Files\Logitech\iTouch\iTouch.exe
    <unsigned> Microsoft (R) DRM 984 C:\WINNT\system32\mspmspsv.exe
    <unsigned> Microsoft(R) Windows (R) 2000 Operating 996 C:\WINNT\Explorer.EXE
    <unsigned> Microsoft(R) Windows (R) 2000 Operating 196 C:\WINNT\system32\csrss.exe
    <unsigned> Microsoft(R) Windows (R) 2000 Operating 256 C:\WINNT\system32\lsass.exe
    <unsigned> Microsoft(R) Windows (R) 2000 Operating 780 C:\WINNT\system32\regsvc.exe
    <unsigned> Microsoft(R) Windows (R) 2000 Operating 244 C:\WINNT\system32\services.exe
    <unsigned> Microsoft(R) Windows (R) 2000 Operating 168 C:\WINNT\System32\smss.exe
    <unsigned> Microsoft(R) Windows (R) 2000 Operating 504 C:\WINNT\system32\spoolsv.exe
    <unsigned> Microsoft(R) Windows (R) 2000 Operating 408 C:\WINNT\system32\svchost.exe
    <unsigned> Microsoft(R) Windows (R) 2000 Operating 460 C:\WINNT\System32\svchost.exe
    <unsigned> Microsoft(R) Windows (R) 2000 Operating 1008 C:\WINNT\system32\svchost.exe
    <unsigned> Microsoft(R) Windows (R) 2000 Operating 216 C:\WINNT\system32\winlogon.exe
    <unsigned> Microsoft® Windows® Task Scheduler 796 C:\WINNT\system32\MSTask.exe
    <unsigned> Mixer 1696 C:\WINNT\Mixer.exe
    <unsigned> MouseWare 1648 C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
    <unsigned> Musicmatch Jukebox 1688 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    <unsigned> NETGEAR WG111 Smart Wizard-Wireless Ass 1868 C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
    <unsigned> Norton Speed Disk 920 C:\Program Files\Norton SystemWorks\Norton Utilities\Speed Disk\NOPDB.exe
    <unsigned> RtlWake Application 1876 C:\Program Files\802.11 Wireless LAN\WLAN Cardbus\RtlWake.exe
    <unsigned> Windows Management Instrumentation 1500 C:\WINNT\System32\WBEM\unsecapp.exe
    <unsigned> Windows Management Instrumentation 960 C:\WINNT\System32\WBEM\WinMgmt.exe

    <verified> Ad-Aware Service Application 676 C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    <verified> Ad-Aware Tray Application 2068 C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    <verified> Client and Host Security Platform 1716 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    <verified> Client and Host Security Platform 1068 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    <verified> Client and Host Security Platform 560 C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    <verified> Client and Host Security Platform 580 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    <verified> Client and Host Security Platform 2204 C:\Program Files\Norton Internet Security\ccEmFlSv.exe
    <verified> Firefox 2336 C:\Program Files\Mozilla Firefox\firefox.exe
    <verified> Java(TM) Platform SE 6 U20 644 C:\Program Files\Java\jre6\bin\jqs.exe
    <verified> Java(TM) Platform SE Auto Updater 2 0 1760 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    <verified> LiveUpdate 532 C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    <verified> Norton AntiVirus 1820 C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    <verified> Norton GoBack 624 C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
    <verified> Norton Security Console 1604 C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    <verified> Norton SystemWorks 1232 C:\Program Files\Common Files\Symantec Shared\SymTray.exe
    <verified> Norton Utilities 740 C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    <verified> SPBBC 876 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    <verified> Symantec Security Drivers 832 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    <verified> symlcsvc.exe 932 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


    Autoruns and critical files
    ---------------------------
    <unsigned> Adobe Acrobat C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    <unsigned> Adobe Systems, Inc. Adobe Gamma Loader C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    <unsigned> FinePrint pdfFactory C:\WINNT\System32\spool\DRIVERS\W32X86\2\fppdis1.exe
    <unsigned> iTouch C:\Program Files\Logitech\iTouch\iTouch.exe
    <unsigned> Microsoft Office 2000 C:\Program Files\Microsoft Office\Office\OSA9.EXE
    <unsigned> Microsoft Synchronization Manager C:\WINNT\system32\mobsync.exe
    <unsigned> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\CRYPT32.DLL
    <unsigned> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\CRYPTNET.DLL
    <unsigned> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\cscdll.dll
    <unsigned> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\netshell.dll
    <unsigned> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\sclgntfy.dll
    <unsigned> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\SHELL32.DLL
    <unsigned> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\stobject.dll
    <unsigned> Microsoft(R) Windows (R) 2000 Operating c:\winnt\system32\userinit.exe
    <unsigned> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\wlnotify.dll
    <unsigned> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\wzcdlg.dll
    <unsigned> Microsoft® Windows® Operating System C:\WINNT\system32\webcheck.dll
    <unsigned> Mixer C:\WINNT\Mixer.exe
    <unsigned> MouseWare C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
    <unsigned> Musicmatch Jukebox C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    <unsigned> NETGEAR WG111 Smart Wizard-Wireless Ass C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
    <unsigned> Norton SystemWorks C:\Program Files\Common Files\Symantec Shared\SymDrmc.exe
    <unsigned> Norton SystemWorks C:\Program Files\Common Files\Symantec Shared\Symtrdr.exe
    <unsigned> RtlWake Application C:\Program Files\802.11 Wireless LAN\WLAN Cardbus\RtlWake.exe

    <verified> Ad-Aware Admin Application C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
    <verified> Client and Host Security Platform C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    <verified> Java(TM) Platform SE Auto Updater 2 0 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    <verified> Microsoft® Windows® Operating System C:\WINNT\system32\BROWSEUI.DLL
    <verified> Norton AntiVirus C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVW32.EXE
    <verified> Norton Security Center C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    <verified> Norton SystemWorks C:\Program Files\Common Files\Symantec Shared\SymTray.exe
    <verified> Norton SystemWorks C:\Program Files\Norton SystemWorks\OBC.exe


    Browser plugins
    ---------------
    <unsigned> Adobe Acrobat C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
    <unsigned> bdoscandel.exe C:\WINNT\bdoscandel.exe
    <unsigned> bdscanonline C:\WINNT\Downloaded Program Files\oscan82.ocx
    <unsigned> ipsupd.dll C:\WINNT\Downloaded Program Files\ipsupd.dll
    <unsigned> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\RNR20.DLL
    <unsigned> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\rsvpsp.dll
    <unsigned> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\winrnr.dll
    <unsigned> msdxm.ocx c:\winnt\system32\msdxm.ocx
    <unsigned> QuickTime Plug-in 6.5.1 C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
    <unsigned> QuickTime Plug-in 6.5.1 C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
    <unsigned> QuickTime Plug-in 6.5.1 C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
    <unsigned> QuickTime Plug-in 6.5.1 C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
    <unsigned> QuickTime Plug-in 6.5.1 C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
    <unsigned> QuickTime Plug-in 6.5.1 C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
    <unsigned> QuickTime Plug-in 6.5.1 C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
    <unsigned> Symantec Shared Components C:\WINNT\Downloaded Program Files\symdlmgr.dll
    <unsigned> tgctlsi Module C:\WINNT\Downloaded Program Files\tgctlsi.dll
    <unsigned> tgctlsr Module C:\WINNT\Downloaded Program Files\tgctlsr.dll

    <verified> AcroIEHelper Library c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
    <verified> BitDefender QuickScan C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q4k9xxk3.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
    <verified> BitDefender QuickScan C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q4k9xxk3.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
    <verified> ECOM Loader C:\WINNT\Downloaded Program Files\ecmldr32.dll
    <verified> ECOM Server C:\WINNT\Downloaded Program Files\ecmsvr32.dll
    <verified> GoogleToolbarNotifier c:\program files\google\googletoolbarnotifier\3.0.1225.9868\swg.dll
    <verified> Internet Security c:\program files\common files\symantec shared\adblocking\nisshext.dll
    <verified> Java Deployment Toolkit 6.0.200.2 C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
    <verified> Java(TM) Platform SE 6 U20 c:\program files\java\jre6\bin\jp2ssv.dll
    <verified> Java(TM) Platform SE 6 U20 c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    <verified> LiveReg C:\WINNT\Downloaded Program Files\LSSupCtl.dll
    <verified> Microsoft(R) Windows (R) 2000 Operating C:\WINNT\system32\msafd.dll
    <verified> Microsoft® Windows® Operating System C:\WINNT\system32\SHDOCVW.DLL
    <verified> Mozilla Default Plug-in C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
    <verified> NAVAPI C:\WINNT\Downloaded Program Files\navapi32.dll
    <verified> Norton AntiVirus C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL
    <verified> NPSWF32.dll C:\WINNT\system32\Macromed\Flash\NPSWF32.dll
    <verified> SymAData Module C:\WINNT\Downloaded Program Files\CONFLICT.1\SymAData.dll
    <verified> SymAData Module C:\WINNT\Downloaded Program Files\SymAData.dll
    <verified> Symantec Antivirus Engine C:\WINNT\Downloaded Program Files\naveng32.dll
    <verified> Symantec Antivirus Engine C:\WINNT\Downloaded Program Files\navex32a.dll
    <verified> Symantec Security Check C:\WINNT\Downloaded Program Files\avsniff.dll
    <verified> Symantec Security Check C:\WINNT\Downloaded Program Files\rufsi.dll
    <verified> tgctlsi Module C:\WINNT\Downloaded Program Files\CONFLICT.1\tgctlsi.dll
    <verified> tgctlsr Module C:\WINNT\Downloaded Program Files\CONFLICT.1\tgctlsr.dll
    <verified> TODO: <Product name> C:\WINNT\Downloaded Program Files\avsniffdlgs.dll
    <verified> WholeSecurity Confidence Online(tm) for C:\WINNT\Downloaded Program Files\AXXPEE.dll


    Scan
    ----
    <unsigned> MD5: bfc4086f3dc8ebbba9364c94a3316619 C:\Program Files\802.11 Wireless LAN\WLAN Cardbus\RtlWake.exe
    <unsigned> MD5: 4b0991cd076b617a2231b19a6663c1c9 C:\Program Files\Adobe\Acrobat 7.0\ActiveX\pdfshell.dll
    <unsigned> MD5: dfcb9ade94a4f8a7c42eef41101a30ad C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    <unsigned> MD5: 716c4d3071cafcd468dd478b846f726f C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    <unsigned> MD5: 9f28ea00bc669b73aa10fc5588fe70fa C:\Program Files\Common Files\Logitech\Scrolling\LGMSGHK.DLL
    <unsigned> MD5: 7692009a8054b59413881d0c3756285d C:\Program Files\Common Files\Symantec Shared\AntiSpam\bteuclid.dll
    <unsigned> MD5: 3d073194647e0a364bbc21b7d47f674f C:\Program Files\Common Files\Symantec Shared\AntiSpam\btutils.dll
    <unsigned> MD5: a70e6dbd573a3c7edf21032bedba046b C:\Program Files\Common Files\Symantec Shared\SymDrmc.exe
    <unsigned> MD5: 93bfc7bcd56a3b9ab2f3ef8e77e0d65b C:\Program Files\Common Files\Symantec Shared\Symtrdr.exe
    <unsigned> MD5: 3b1e4019deaba870966c9f29c9ef4f6a C:\Program Files\Common Files\System\Mapi\1033\NT\OMINT.DLL
    <unsigned> MD5: eecdcbcb1c2c947d5f17f051fe5da3f4 C:\Program Files\Common Files\System\Mapi\1033\NT\OMIPSTNT.DLL
    <unsigned> MD5: 2ad50fa9ffaf7e6d66206e9d78788f11 C:\Program Files\InterBase\Bin\ibguard.exe
    <unsigned> MD5: 5a937d9e33ebcb3716209ef0827d5ae4 C:\Program Files\InterBase\Bin\ibserver.exe
    <unsigned> MD5: 86f1895ae8c5e8b17d99ece768a70732 C:\Program Files\Java\jre6\bin\msvcr71.dll
    <unsigned> MD5: a3922cd380f968b898da4bb414c38900 C:\Program Files\Lavasoft\Ad-Aware\unrar.dll
    <unsigned> MD5: ed4410259011a492bff4396bae2e0973 C:\Program Files\Logitech\iTouch\itchhk.dll
    <unsigned> MD5: 9aee9bcb32d82bcc36474eb921f3bb49 C:\Program Files\Logitech\iTouch\iTouch.exe
    <unsigned> MD5: 95e2ba17e78bea02b19396662d1b889b C:\Program Files\Logitech\iTouch\iTouchrc.dll
    <unsigned> MD5: 88f40ed6afe965281cf952f0235ac55f C:\Program Files\Logitech\iTouch\KbdHook.dll
    <unsigned> MD5: c36bec52897ad7157567053ef4cd13ee C:\Program Files\Logitech\MouseWare\system\ccresrce.dll
    <unsigned> MD5: 8749ef6848f3f41d212ddc20804c38cc C:\Program Files\Logitech\MouseWare\system\CCSTMGLB.DLL
    <unsigned> MD5: b6e739e21c050e4b766d22a233d27156 C:\Program Files\Logitech\MouseWare\system\CCUSTOM.DLL
    <unsigned> MD5: 8904d91f638667a2ef6953158d447c5b C:\Program Files\Logitech\MouseWare\system\DEVICES.DLL
    <unsigned> MD5: bcdbcd110dae1abca8f3787c8fcd3166 C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
    <unsigned> MD5: c73eee62b358e01dc5731b8038373ac2 C:\Program Files\Logitech\MouseWare\system\GlbResLt.dll
    <unsigned> MD5: ba25c7a6db78c12de2c820cd9f6ae045 C:\Program Files\Microsoft Office\Office\OSA9.EXE
    <unsigned> MD5: 26b018758226a5dc06de45496c394d40 C:\Program Files\Mozilla Firefox\freebl3.dll
    <unsigned> MD5: 9dfb30f203999a3ae0f258a33fa598f9 C:\Program Files\Mozilla Firefox\nssdbm3.dll
    <unsigned> MD5: 8ef356da145f60c3f11df7ef03b97449 C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
    <unsigned> MD5: 3da5a7d28be963e2727dd422c410aca5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
    <unsigned> MD5: 3da5a7d28be963e2727dd422c410aca5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
    <unsigned> MD5: 3da5a7d28be963e2727dd422c410aca5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
    <unsigned> MD5: 3da5a7d28be963e2727dd422c410aca5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
    <unsigned> MD5: 3da5a7d28be963e2727dd422c410aca5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
    <unsigned> MD5: 3da5a7d28be963e2727dd422c410aca5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
    <unsigned> MD5: 3da5a7d28be963e2727dd422c410aca5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
    <unsigned> MD5: 1fd6c03c0001a5e1eaf61596c2502f0c C:\Program Files\Mozilla Firefox\softokn3.dll
    <unsigned> MD5: 0f7324983a21b03bc7633cc56684f0d4 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\CoreDll.dll
    <unsigned> MD5: 90fa3d8333385e3152ecce365155f279 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Enforce.dll
    <unsigned> MD5: 662fea521755a305d609555409243464 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FileAssoc.dll
    <unsigned> MD5: 34fc457931d0f9c7cf2f1371764d715c C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    <unsigned> MD5: 3664a35169efd15cc96802f3821a7d08 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMC70U.DLL
    <unsigned> MD5: 9799184394dcc17e52e55e5eec617760 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMReg.dll
    <unsigned> MD5: 0071d1d75c776d124eb0505e11933cdf C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMVCP70.dll
    <unsigned> MD5: 80ef6653710a2a53e8183981badd582f C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMVCR70.dll
    <unsigned> MD5: 3afafd6b7730cb9ed068e8c3d95cfd35 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\SkinnedCtrls.dll
    <unsigned> MD5: b265dd544947b7dab5a6695ea2973b7c C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\TrackUtils.dll
    <unsigned> MD5: e2a8efa2871bdce7136828f9c6aae242 C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
    <unsigned> MD5: 5b6d8718ba27d4e661dbc9927695b3c6 C:\Program Files\Norton SystemWorks\Norton Utilities\Speed Disk\NOPDB.exe
    <unsigned> MD5: 70ec5139b780b39bf000195462fccb53 C:\Program Files\Norton SystemWorks\Norton Utilities\Speed Disk\SDOptions.dll
    <unsigned> MD5: f35a584e947a5b401feb0fe01db4a0d7 C:\Program Files\Symantec\LiveUpdate\MFC71.DLL
    <unsigned> MD5: 561fa2abb31dfa8fab762145f81667c2 C:\Program Files\Symantec\LiveUpdate\MSVCP71.DLL
    <unsigned> MD5: 86f1895ae8c5e8b17d99ece768a70732 C:\Program Files\Symantec\LiveUpdate\MSVCR71.DLL
    <unsigned> MD5: d74bab451c174b61820c262b980f7fc1 C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
    <unsigned> MD5: 5ea4bb7f05675dee437f5a54f4cbea48 C:\PROGRA~1\Logitech\MOUSEW~1\system\CCMSGHK.DLL
    <unsigned> MD5: bcdbcd110dae1abca8f3787c8fcd3166 C:\PROGRA~1\Logitech\MOUSEW~1\system\EM_EXEC.EXE
    <unsigned> MD5: 37c3c042362f3cfa50f2bd4cfc3d655e C:\PROGRA~1\Logitech\MOUSEW~1\system\EVENTEX.DLL
    <unsigned> MD5: f558760a2d541887208ff5374e15d238 C:\PROGRA~1\Logitech\MOUSEW~1\system\LGMOUSHK.DLL
    <unsigned> MD5: a430faae0a4db973500b6c882f8848e5 C:\PROGRA~1\Logitech\MOUSEW~1\system\MFC42.DLL
    <unsigned> MD5: 48e0bbc0d15852d5aee107fbf1b32d98 C:\PROGRA~1\NORTON~1\NORTON~2\S32KRNLL.DLL
    <unsigned> MD5: b363a665f4eab87809da0698989d8124 C:\PROGRA~1\NORTON~1\NORTON~2\S32UTILL.DLL
    <unsigned> MD5: 5b6d8718ba27d4e661dbc9927695b3c6 C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.exe
    <unsigned> MD5: 41a001cff829e123c9a460a41d43e49b C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\SDException.dll
    <unsigned> MD5: 1332851e6a936f3f186ae631390606f6 C:\PROGRA~1\WinZip\WZSHLSTB.DLL
    <unsigned> MD5: b75e2a565ae6b03dd3941a5dd4e2f31c C:\WINNT\bdoscandel.exe
    <unsigned> MD5: 2b1c4c87eb20addba59dca975e28dffb C:\WINNT\Downloaded Program Files\ipsupd.dll
    <unsigned> MD5: a9f9db72cad15e93ad756acff7e4c7dd C:\WINNT\Downloaded Program Files\oscan82.ocx
    <unsigned> MD5: 5e44aa9b99a086e410d4c3bd2282e9f2 C:\WINNT\Downloaded Program Files\symdlmgr.dll
    <unsigned> MD5: 8c17d4046d09e3aae7316a603d1806cd C:\WINNT\Downloaded Program Files\tgctlsi.dll
    <unsigned> MD5: 47ea24991c9184c8186e5447be22f364 C:\WINNT\Downloaded Program Files\tgctlsr.dll
    <unsigned> MD5: 59cf2b7dced9111f48f51b4b570e672d C:\WINNT\Explorer.EXE
    <unsigned> MD5: f83709d0bacba84d297183825f089d98 C:\WINNT\Mixer.exe
    <unsigned> MD5: e372b281026591f830eab4753dcf3062 C:\WINNT\system32\acctres.dll
    <unsigned> MD5: 5200155df5cd700ebe717a8d6dbdccc7 C:\WINNT\system32\activeds.dll
    <unsigned> MD5: f898815e2a3d185df0d61214cb1768ef C:\WINNT\system32\adsldpc.dll
    <unsigned> MD5: 67d5fc28cab4066922da01eb9c28167a C:\WINNT\system32\ADVAPI32.DLL
    <unsigned> MD5: de58dd48cd4794d7b48ccc122dcab010 C:\WINNT\system32\atl.dll
    <unsigned> MD5: 8f2097e8b174f38178570c611464935f C:\WINNT\system32\atl71.dll
    <unsigned> MD5: 4daebd9f0f5b16fbdae8f26cd4ab7b74 C:\WINNT\system32\BASESRV.DLL
    <unsigned> MD5: e6475b864136ac29317ad7552faf1a4f C:\WINNT\system32\batmeter.dll
    <unsigned> MD5: b4f3ecaaebc715edbea44a28fdeda851 C:\WINNT\system32\browser.dll
    <unsigned> MD5: d84e59313ed41baf7b3c04e7fe2dae4f C:\WINNT\system32\cabinet.dll
    <unsigned> MD5: 5505dc90fbac613be8a15dfdc3bde112 C:\WINNT\system32\certcli.dll
    <unsigned> MD5: 6dad3811e7b208a54d2e2009562d2a7d C:\WINNT\system32\cfgmgr32.dll
    <unsigned> MD5: 2830a2c82270f387265dfa658656eb99 C:\WINNT\System32\cisvc.exe
    <unsigned> MD5: 6b8970e4791049d3ee5c3514e62797ee C:\WINNT\system32\clbcatq.dll
    <unsigned> MD5: 804212b6b82354cf4f0c2d567575688a C:\WINNT\system32\clipsrv.exe
    <unsigned> MD5: 632204c5af38904b2ced4d1ac1afab38 C:\WINNT\system32\CLUSAPI.DLL
    <unsigned> MD5: 6e6b078275e583496ede4512df3036ed C:\WINNT\system32\cmd.exe
    <unsigned> MD5: 4ceda87bd146e666bb8c7ddf2d715a41 C:\WINNT\system32\cmnprop.dll
    <unsigned> MD5: b2f88d1944081f17763d63718eb559d2 C:\WINNT\system32\cnbjmon.dll
    <unsigned> MD5: f4230caa2b9166e5114441f6b7b2dc3f C:\WINNT\system32\comctl32.dll
    <unsigned> MD5: 41c157ba2f205017ec26998009ccb046 C:\WINNT\system32\COMDLG32.DLL
    <unsigned> MD5: fe5ad5e08e6cf9c2bd3b867261872e6c C:\WINNT\system32\COMNCTR.DLL
    <unsigned> MD5: 324c4d2cfbc69c8eb078d26d83b8e0d9 C:\WINNT\system32\comsvcs.dll
    <unsigned> MD5: 9726a08c3e529c5e6a48fff274a32932 C:\WINNT\system32\CRYPT32.DLL
    <unsigned> MD5: ee17a46fc66015d893f0db557fb28f4b C:\WINNT\system32\cryptdll.dll
    <unsigned> MD5: fef2014ba0c5ab8f553cb014885d7b1c C:\WINNT\system32\CRYPTNET.DLL
    <unsigned> MD5: 7d77d4af905903aedbeed9989857a9a5 C:\WINNT\system32\cryptsvc.dll
    <unsigned> MD5: 57195d61577bdb075063524d84b173e9 C:\WINNT\system32\CRYPTUI.DLL
    <unsigned> MD5: 99b3f8bc2e6dd1eece66eb6ca5007729 C:\WINNT\system32\cscdll.dll
    <unsigned> MD5: 2338214ee7338ae91c60f3e8b727aae0 C:\WINNT\system32\cscui.dll
    <unsigned> MD5: 6533392c5af4bf5c7ff12e453dd59ae5 C:\WINNT\system32\csrss.exe
    <unsigned> MD5: c61f9e2b07c53ae98bd48db674352339 C:\WINNT\system32\dbghelp.dll
    <unsigned> MD5: 4f17861b7f354f156d3e3663c426cb13 C:\WINNT\system32\DHCPCSVC.DLL
    <unsigned> MD5: 7b080c0ac30884e981221342da197c1e C:\WINNT\System32\dmadmin.exe
    <unsigned> MD5: 80e282a8972662e8b0ba74c693de4752 C:\WINNT\system32\dmserver.dll
    <unsigned> MD5: ca12f2f17ca3588bf29e2374e71d4f3b C:\WINNT\system32\docprop2.dll
    <unsigned> MD5: 083049d5dc3f32d17c2edfb732c78a09 C:\WINNT\System32\DRIVERS\ACPI.sys
    <unsigned> MD5: 4b10b4db777ee2ef8e755e7f3d7c4fe8 C:\WINNT\system32\drivers\ACPIEC.sys
    <unsigned> MD5: ed8cee58c1e4c5893f5b2fd686a272bf C:\WINNT\system32\drivers\ASPI32.sys
    <unsigned> MD5: 5d3d77c9eb3a8e6a14cc8e1252b6cc5c C:\WINNT\system32\DRIVERS\asyncmac.sys
    <unsigned> MD5: 8c718aa8c77041b3285d55a0ce980867 C:\WINNT\System32\DRIVERS\atapi.sys
    <unsigned> MD5: 3e348b3313ea633d45caf59da0d631ba C:\WINNT\System32\DRIVERS\atmarpc.sys
    <unsigned> MD5: 39d57104a45270f0d376e9ddb484ebbd C:\WINNT\System32\DRIVERS\audstub.sys
    <unsigned> MD5: df012c2853281ce2bf536e8de871c8c1 C:\WINNT\system32\drivers\BEEP.sys
    <unsigned> MD5: 1478e6a09512235b9e119d2920477021 C:\WINNT\system32\DRIVERS\CCDECODE.sys
    <unsigned> MD5: b101e013d810d6125e17125e324fcd2c C:\WINNT\system32\drivers\Cdaudio.sys
    <unsigned> MD5: 66c19373d5eb657fb028133bde5d2acb C:\WINNT\system32\drivers\CDFS.sys
    <unsigned> MD5: 9880f86f4261699273f818ae50216b8c C:\WINNT\system32\drivers\Cdr4_2K.sys
    <unsigned> MD5: 300500fb3ef21374f7194f9f42b130bc C:\WINNT\system32\drivers\Cdralw2k.sys
    <unsigned> MD5: 4b86a90a7f0095d514d22a9083826488 C:\WINNT\System32\DRIVERS\cdrom.sys
    <unsigned> MD5: e5842ccf0953d3d46d5e26427b67e901 C:\WINNT\system32\drivers\cmaudio.sys
    <unsigned> MD5: 6be1d6403727bdd8a2b2568dbe6bfb8b C:\WINNT\system32\drivers\CO_MON.sys
    <unsigned> MD5: 322b9a3774dbf119f6635a476b0eb058 C:\WINNT\System32\DRIVERS\disk.sys
    <unsigned> MD5: fd94497dd145b3920f5c393eab50ee3a C:\WINNT\system32\drivers\DISKPERF.sys
    <unsigned> MD5: 0b91c63540682bc3c826fc6d8b3ecb7b C:\WINNT\system32\drivers\DMBOOT.sys
    <unsigned> MD5: 6b35bfdbdbc247113852f18bf0f10e3c C:\WINNT\system32\drivers\dmio.sys
    <unsigned> MD5: 3f1701ffa97ab012685abc8a2d6fce22 C:\WINNT\system32\drivers\DMLOAD.sys
    <unsigned> MD5: 3431984234b5988d4c09f043cf4cd779 C:\WINNT\system32\drivers\DMusic.sys
    <unsigned> MD5: 8563d9bb03ab4a564ac26e753f8f4daf C:\WINNT\system32\drivers\EAPPKT.sys
    <unsigned> MD5: b2916926428c0410fc1a26da0b650e41 C:\WINNT\system32\drivers\EFS.sys
    <unsigned> MD5: 533478c99ca81fd700bcf6a2754ce793 C:\WINNT\system32\drivers\FASTFAT.sys
    <unsigned> MD5: 233e2c4dae9c84cef241f0ea30619629 C:\WINNT\System32\DRIVERS\fdc.sys
    <unsigned> MD5: b27a36d4725a362a13d0c52ad6c7175b C:\WINNT\system32\drivers\FIPS.sys
    <unsigned> MD5: 6ca845333da54f27a8657be7ee0b600d C:\WINNT\System32\DRIVERS\flpydisk.sys
    <unsigned> MD5: f574c40cd0db393c361363cc21592f4a C:\WINNT\system32\drivers\FLTMGR.sys
    <unsigned> MD5: 405f231ad65c03dac70992a2aba759a5 C:\WINNT\system32\drivers\FS_REC.sys
    <unsigned> MD5: c757a3eefa44ea2d562424a4060329a6 C:\WINNT\system32\drivers\ftdisk.sys
    <unsigned> MD5: 1ee4975fbc708f34a6b07c8e47f6fa3a C:\WINNT\System32\DRIVERS\gameenum.sys
    <unsigned> MD5: 7fd2305ebf68fa79b4b905da2c04b960 C:\WINNT\system32\drivers\GBDEVICE.sys
    <unsigned> MD5: d8abf306eff34531d3079af2a1b543ce C:\WINNT\system32\drivers\GBFSHOOK.sys
    <unsigned> MD5: c75fc9fd29744362c7b9f0d2b8946c33 C:\WINNT\system32\drivers\GoBack2K.sys
    <unsigned> MD5: 3b538e8a6b5e078406159edfe09a5e53 C:\WINNT\System32\DRIVERS\i8042prt.sys
    <unsigned> MD5: 09a604211e2b2334fc023a41337e3165 C:\WINNT\System32\DRIVERS\ipfltdrv.sys
    <unsigned> MD5: dbc1437b56eea1af02cd39c011904491 C:\WINNT\System32\DRIVERS\ipinip.sys
    <unsigned> MD5: adb8a3465c0fc01c3ae633adb33fcbb3 C:\WINNT\system32\drivers\IPNAT.sys
    <unsigned> MD5: 7f5315e32be0632f680b30e03a2ca809 C:\WINNT\System32\DRIVERS\irenum.sys
    <unsigned> MD5: b630369ca276fd208c1b5146920b5f2e C:\WINNT\System32\DRIVERS\isapnp.sys
    <unsigned> MD5: 8f1ba487b35f0c8f637e05113aa815f8 C:\WINNT\System32\DRIVERS\itchfltr.sys
    <unsigned> MD5: 399055f5c4a98f39b47d26888a72145d C:\WINNT\System32\DRIVERS\kbdclass.sys
    <unsigned> MD5: 8e198ec9e823aa42edf45b07efe395ac C:\WINNT\system32\drivers\kmixer.sys
    <unsigned> MD5: 80ffb99dcb8e6ab8a01be04fcb0b0758 C:\WINNT\system32\drivers\KSECDD.sys
    <unsigned> MD5: 009c4267a8d74f98533c899710ee7419 C:\WINNT\System32\DRIVERS\L8042pr2.sys
    <unsigned> MD5: 74ab237c1106216814c5052481a990d5 C:\WINNT\System32\DRIVERS\lkbdflt2.sys
    <unsigned> MD5: 90bfbcf6ef78e59466b8fb7d3b012688 C:\WINNT\System32\DRIVERS\lmouflt2.sys
    <unsigned> MD5: d7010580bf4e45d5e793a1fe75758c69 C:\WINNT\system32\drivers\MDC8021X.sys
    <unsigned> MD5: f9a1ccc84d1c8b392d67bf2e661ed334 C:\WINNT\system32\drivers\MNMDD.sys
    <unsigned> MD5: 37478d40030b15ca3860509d4f5d39d8 C:\WINNT\system32\drivers\Modem.sys
    <unsigned> MD5: 8d038dde3f19b88427968e99a6216766 C:\WINNT\System32\DRIVERS\mouclass.sys
    <unsigned> MD5: 75e57b9f5c36137ea79466c3b63c38cc C:\WINNT\system32\drivers\MOUNTMGR.sys
    <unsigned> MD5: 83eff7b976ae24f1a496ca94a8a19919 C:\WINNT\System32\DRIVERS\MPE.sys
    <unsigned> MD5: 8840bc3953d2c0bbb104932cab848a27 C:\WINNT\system32\drivers\MSFS.sys
    <unsigned> MD5: 6667d07854a3ae7715d22b82761cf0e7 C:\WINNT\System32\DRIVERS\msgpc.sys
    <unsigned> MD5: 85736f804191cb420a31aca2a7f0674f C:\WINNT\system32\drivers\MSKSSRV.sys
    <unsigned> MD5: e943adb93d83c5cbc0ca3f53f53b48cc C:\WINNT\system32\drivers\MSPCLOCK.sys
    <unsigned> MD5: bb041315c9930063e5eab0bee90acff6 C:\WINNT\system32\drivers\MSPQM.sys
    <unsigned> MD5: d5059366b361f0e1124753447af08aa2 C:\WINNT\system32\drivers\MSTEE.sys
    <unsigned> MD5: bb1c45d114b6dab0babf6b2fb0336db2 C:\WINNT\system32\DRIVERS\NABTSFEC.sys
    <unsigned> MD5: fb4f2d0595bd3546a4dd915e4a9b4809 C:\WINNT\system32\drivers\NDIS.sys
    <unsigned> MD5: e6f675c75c53887c58b98d6db356b153 C:\WINNT\System32\DRIVERS\ndistapi.sys
    <unsigned> MD5: 69ecae880bdac3c288f0508df9cdeef0 C:\WINNT\system32\drivers\NDISUIO.sys
    <unsigned> MD5: b86a37aa73868343a9eee148fdfce1e0 C:\WINNT\System32\DRIVERS\ndiswan.sys
    <unsigned> MD5: 1f426863d87bdf75aec76584223cd0c7 C:\WINNT\system32\drivers\NDPROXY.sys
    <unsigned> MD5: 5151e6020a26bf7bc21c18fd612506bd C:\WINNT\system32\drivers\NETBIOS.sys
    <unsigned> MD5: a7ca87628217bbf4a6f501db65b19e9d C:\WINNT\system32\drivers\NETBT.sys
    <unsigned> MD5: 9b2a6147a22f7e696cc7538283de6346 C:\WINNT\system32\drivers\netdtect.sys
    <unsigned> MD5: a13bc7db063787a5a29f88a78821beb7 C:\WINNT\system32\drivers\NPDRIVER.sys
    <unsigned> MD5: e85a77dfcb8f1088f85120ca123ce191 C:\WINNT\system32\drivers\NPFS.sys
    <unsigned> MD5: 7dc1f0f9bf87ca5cee9a46c9a63dc1d3 C:\WINNT\system32\drivers\NTFS.sys
    <unsigned> MD5: 3c25d8a23c366fbe1511b4a250a1a2ad C:\WINNT\System32\DRIVERS\NTIDrvr.sys
    <unsigned> MD5: 280209cde798720a24d232bf9cfda8e9 C:\WINNT\system32\drivers\NULL.sys
    <unsigned> MD5: 9b0d6fb5c5d6a7571aedb0c1a7a9c1b6 C:\WINNT\System32\DRIVERS\nwlnkflt.sys
    <unsigned> MD5: 09fa39e4812fdd042834650df09675a0 C:\WINNT\System32\DRIVERS\nwlnkfwd.sys
    <unsigned> MD5: 3eb4141801e4c71eb766faf73e870dc3 C:\WINNT\System32\DRIVERS\openhci.sys
    <unsigned> MD5: ea27799907eabdb66d2d56af68cd4f06 C:\WINNT\System32\DRIVERS\parallel.sys
    <unsigned> MD5: 69b713583d6e063ac487e2da30c04289 C:\WINNT\System32\DRIVERS\parport.sys
    <unsigned> MD5: f9e922dbe9f3719ce8376cc7ed18cb8d C:\WINNT\system32\drivers\PARTMGR.sys
    <unsigned> MD5: 888f6a6ad5810f5828de594e17fe8f3b C:\WINNT\system32\drivers\PARVDM.sys
    <unsigned> MD5: f0791b1f424f8d84a81d9ae6cfadf089 C:\WINNT\System32\DRIVERS\pci.sys
    <unsigned> MD5: 7d0bcb325d29d15024d6a572044e410b C:\WINNT\System32\DRIVERS\pciide.sys
    <unsigned> MD5: b737c89d439b771d92d7c5e8b8d3917c C:\WINNT\system32\drivers\Pcmcia.sys
    <unsigned> MD5: b78775f217255f786c2e8dbe4334e413 C:\WINNT\System32\DRIVERS\ptilink.sys
    <unsigned> MD5: db3b30c3a4cdcf07e164c14584d9d0f2 C:\WINNT\System32\Drivers\PxHelp20.sys
    <unsigned> MD5: 63051b814e005dc62c7a0971668c52b4 C:\WINNT\system32\drivers\RASACD.sys
    <unsigned> MD5: ec6037c594f20adedea65f0d809493d2 C:\WINNT\System32\DRIVERS\rasl2tp.sys
    <unsigned> MD5: 0e0212bbbf15800f1536cbfa157dddd6 C:\WINNT\System32\DRIVERS\raspptp.sys
    <unsigned> MD5: cb09a98e97e52c389ab17b1e003c9566 C:\WINNT\System32\DRIVERS\raspti.sys
    <unsigned> MD5: afce1f733a6aa3a90ac60794dfb26104 C:\WINNT\system32\drivers\RCA.sys
    <unsigned> MD5: b5120cb5081865b0c7d93c305c7da939 C:\WINNT\System32\DRIVERS\redbook.sys
    <unsigned> MD5: e531b8a1bd182d01a7532d2eea71f843 C:\WINNT\system32\DRIVERS\RTL8180.SYS
    <unsigned> MD5: a2e5685caa762cff440cb149721f1191 C:\WINNT\System32\DRIVERS\s3legacy.sys
    <unsigned> MD5: ac2e5fa94155bc0c4c7ab8f97e181f6f C:\WINNT\system32\drivers\SDDRIVER.sys
    <unsigned> MD5: 6db5fdf67486679da3149ef212374861 C:\WINNT\System32\DRIVERS\serenum.sys
    <unsigned> MD5: 80f28698f48e298d278057f23206133b C:\WINNT\System32\DRIVERS\serial.sys
    <unsigned> MD5: 96b8aae4f799e81a23aeda935e14f768 C:\WINNT\system32\drivers\Sfloppy.sys
    <unsigned> MD5: 1082e347d1842a0b7437381a7ca87cbb C:\WINNT\System32\DRIVERS\sis300p.sys
    <unsigned> MD5: 3d7ef286e806f9bd9339aa52e28dcd67 C:\WINNT\system32\drivers\SJYPKT.sys
    <unsigned> MD5: 92723fbdd30771c293fe5ed266a31ca6 C:\WINNT\system32\DRIVERS\SLIP.sys
    <unsigned> MD5: 4544fd0db39cb7b385a5392c068162cd C:\WINNT\system32\DRIVERS\StreamIP.sys
    <unsigned> MD5: 616a013d3ea068b6dee83d905e92ee9f C:\WINNT\System32\DRIVERS\swenum.sys
    <unsigned> MD5: 8c7cd06d097a59391d94b59715fca67c C:\WINNT\system32\drivers\swmidi.sys
    <unsigned> MD5: 6c14d96f8c1ba929fad4ba40a29217fa C:\WINNT\system32\drivers\sysaudio.sys
    <unsigned> MD5: 1151500efb8759a69c3a0bb1f274138c C:\WINNT\system32\drivers\UDFS.sys
    <unsigned> MD5: 7a77f319935328cf30945fe0f3c69c9a C:\WINNT\System32\DRIVERS\update.sys
    <unsigned> MD5: 5c202078f5d500786a1f3279fac3aa64 C:\WINNT\System32\DRIVERS\usbhub.sys
    <unsigned> MD5: 13eba8a2da3447fe7f217e34210ac554 C:\WINNT\System32\DRIVERS\USBSTOR.SYS
    <unsigned> MD5: 1b0040415ba34497a8d76a553aee88aa C:\WINNT\system32\drivers\VGA.sys
    <unsigned> MD5: aa8c76dfc4afa72f09fdbc6621b7d38d C:\WINNT\system32\drivers\WANARP.sys
    <unsigned> MD5: 997d25513bc89614417829b5bec7c75c C:\WINNT\system32\drivers\wdmaud.sys
    <unsigned> MD5: 5dc04e2badf701d7a9d00365b623df2f C:\WINNT\system32\DRIVERS\wg111nd5.sys
    <unsigned> MD5: caf97f8647939f93105620759feb9cbb C:\WINNT\System32\DRIVERS\winacpci.sys
    <unsigned> MD5: c8a15978b9c09023a3e096cb9b6689c5 C:\WINNT\system32\drivers\WS2IFSL.sys
    <unsigned> MD5: 04aca6442e639a794293828e8dda7a44 C:\WINNT\system32\DRIVERS\WSTCODEC.SYS
    <unsigned> MD5: 83c6595bff046c1deaa213c193d80f26 C:\WINNT\system32\dssenh.dll
    <unsigned> MD5: 019bd72a117c13df44d6ca3b96a345d6 C:\WINNT\system32\es.dll
    <unsigned> MD5: 355ac398a306c5a1db00de660ae8db4e C:\WINNT\system32\esent.dll
    <unsigned> MD5: e7f03344ae103b02135c20112b557051 C:\WINNT\system32\EVENTLOG.DLL
    <unsigned> MD5: b816393b4d430853f23831576076f284 C:\WINNT\system32\faxshell.dll
    <unsigned> MD5: c63946c8124a58a6c86efb0ebec7ccf9 C:\WINNT\system32\faxsvc.exe
    <unsigned> MD5: 9aa9174806924748a51d4de1b705d058 C:\WINNT\system32\fltlib.dll
    <unsigned> MD5: f460662fba619dd19c3aedff6aac28b4 C:\WINNT\system32\fppmon1.dll
    <unsigned> MD5: 4ee5c3941f1d5bdf1149e43337183232 C:\WINNT\system32\fppr132.dll
    <unsigned> MD5: ddc864563d0c543cbed08f32864a87a9 C:\WINNT\system32\GDI32.DLL
    <unsigned> MD5: 753020967507e6ee89f7e6b4ecdc2275 C:\WINNT\system32\h323.tsp
    <unsigned> MD5: 33aeb493842bb1f604c91f84e34cb5f6 C:\WINNT\system32\hid.dll
    <unsigned> MD5: eabdb948f90cc5f8e342c83ae10a71fe C:\WINNT\system32\icmp.dll
    <unsigned> MD5: 73aa2a817308c74e3ee8f3a9df9d65de C:\WINNT\system32\IMAGEHLP.DLL
    <unsigned> MD5: 873794ce17dd72420d9c4072d4d112e5 C:\WINNT\system32\imm32.dll
    <unsigned> MD5: 8a2e7f1c1c099c5915a31cc5b64a3939 C:\WINNT\system32\inetpp.dll
    <unsigned> MD5: bdb90d50415b9eb037ad5fd5a3c77675 C:\WINNT\system32\ipconf.tsp
    <unsigned> MD5: 0239d8d4b29b7664d73e16005cfefcce C:\WINNT\system32\IPHLPAPI.DLL
    <unsigned> MD5: aea7a0f7c23337f36b57666dac442cf1 C:\WINNT\system32\ipnathlp.dll
    <unsigned> MD5: 3ed2ac7e999788ea1806ad51e48fdf70 C:\WINNT\system32\kerberos.dll
    <unsigned> MD5: 0ab23b46ccaeba64d748a5cf79cb4bb6 C:\WINNT\system32\KERNEL32.DLL
    <unsigned> MD5: f350c8ff1fc71089425d219217d89a70 C:\WINNT\system32\kmddsp.tsp
    <unsigned> MD5: eb0ea3ef05d648455d691348c819e479 C:\WINNT\system32\linkinfo.dll
    <unsigned> MD5: 3b176c416f7b00f17963ef5621a33b98 C:\WINNT\system32\LMHSVC.DLL
    <unsigned> MD5: 7cdb74136940dd17461e60a33035bcaa C:\WINNT\system32\LOCALSPL.DLL
    <unsigned> MD5: ad57e33f4f7f404d9aba97e8b33fa21b C:\WINNT\System32\locator.exe
    <unsigned> MD5: 4f362fcc763ff844c84fe26c9c6a8bb3 C:\WINNT\system32\LSASRV.DLL
    <unsigned> MD5: f19d0a319ab4bf5496f08807cb9b8651 C:\WINNT\system32\lsass.exe
    <unsigned> MD5: 486298f7d8f63d3c441579783541a01b C:\WINNT\system32\lz32.dll
    <unsigned> MD5: d7de6ffcdd34da3d7b22dd73832762a6 C:\WINNT\system32\mapi32.dll
    <unsigned> MD5: 8c0cc40bf9c71083d50dff3a0b7c341e C:\WINNT\system32\mfc42u.dll
    <unsigned> MD5: f35a584e947a5b401feb0fe01db4a0d7 C:\WINNT\system32\MFC71.dll
    <unsigned> MD5: aa213a1b082e910b768c17093fd4e0c1 C:\WINNT\system32\mlang.dll
    <unsigned> MD5: eeee63b92ca888ac9fb3d13581751ec2 C:\WINNT\System32\mnmsrvc.exe
    <unsigned> MD5: 9b2f5b9e745deaaa57fb78329ed03061 C:\WINNT\system32\mobsync.exe
    <unsigned> MD5: 95dfe030b87311e11f3556915331f8c4 C:\WINNT\system32\modemui.dll
    <unsigned> MD5: bbe0c0025a82681055660d91cef145ef C:\WINNT\system32\mpr.dll
    <unsigned> MD5: bb88f06f7aed4237df2a121deccb4d8a C:\WINNT\system32\mprapi.dll
    <unsigned> MD5: 4e9825dbdb508f8ff6f6aa8162b14595 C:\WINNT\System32\mprdim.dll
    <unsigned> MD5: c7428a1a88eb172d66317aedb6ad48f0 C:\WINNT\system32\msacm32.dll
    <unsigned> MD5: 4bfd2599ed4c793054f627b1c1470e43 C:\WINNT\system32\msacm32.drv
    <unsigned> MD5: 06b8756d002236631b11ff8bf39a328c C:\WINNT\system32\msasn1.dll
    <unsigned> MD5: 9c83110f9d7d43f2d6be92f76ca9afbb C:\WINNT\system32\mscat32.dll
    <unsigned> MD5: bf142fea3299d8416d293253db20a164 C:\WINNT\system32\mscms.dll
    <unsigned> MD5: edc54e17cdf1811a472d518a82182449 C:\WINNT\System32\msdtc.exe
    <unsigned> MD5: 7a96525db14b8ccf0108f6ef3bef8f61 C:\WINNT\system32\msdtcprx.dll
    <unsigned> MD5: 755aa1f85e3788c3c287ffa03cf58627 c:\winnt\system32\msdxm.ocx
    <unsigned> MD5: 56d9eaa4d4add8400ff1435bc633a9fa C:\WINNT\system32\msfaxmon.dll
    <unsigned> MD5: 1c142b2ebd4aacc7eca0c28f06843655 C:\WINNT\system32\MSGINA.DLL
    <unsigned> MD5: 4b6e4c650721d2a51b8f51b7e5787552 C:\WINNT\system32\MSGSVC.DLL
    <unsigned> MD5: f75dd2e82d0019ddddd926ba9b07a325 C:\WINNT\system32\msi.dll
    <unsigned> MD5: 835811c8216962f3bf9bd50f1f7e2bab C:\WINNT\system32\msidle.dll
    <unsigned> MD5: a0cb6ad826f75e958950c7a053744552 C:\WINNT\system32\msidntld.dll
    <unsigned> MD5: f5f0146580e7023adb963879840777f8 C:\WINNT\system32\msiexec.exe
    <unsigned> MD5: 6463e7716ac0acffa85d4218058eec10 C:\WINNT\system32\msimg32.dll
    <unsigned> MD5: a679d6c1e61ed3840948adb4b17f347e C:\WINNT\system32\msls31.dll
    <unsigned> MD5: 61e99aa0a399d3d82dcfb162c712f658 C:\WINNT\system32\mspatcha.dll
    <unsigned> MD5: 36678803a8030ee9a771935cfc1848bd C:\WINNT\system32\mspmsnsv.dll
    <unsigned> MD5: af619b3908bb1c9336fb6981609018fe C:\WINNT\system32\mspmspsv.exe
    <unsigned> MD5: 1b672c28f798dce46fcf52e99772d630 C:\WINNT\system32\MSPRIVS.DLL
    <unsigned> MD5: c4b3d1c42eefe4ee910ad72149fee516 C:\WINNT\system32\mstask.dll
    <unsigned> MD5: b00529eae5d0ce97010b69cc677128c8 C:\WINNT\system32\MSTask.exe
    <unsigned> MD5: 1dfa06dea950dff34c57d04b7392d29e C:\WINNT\system32\MSV1_0.DLL
    <unsigned> MD5: cb21d826d9c39aed19dd431c1880f5de C:\WINNT\system32\msvcp60.dll
    <unsigned> MD5: 561fa2abb31dfa8fab762145f81667c2 C:\WINNT\system32\msvcp71.dll
    <unsigned> MD5: 86f1895ae8c5e8b17d99ece768a70732 C:\WINNT\system32\Msvcr71.dll
    <unsigned> MD5: ba7be6f92680b28b9031170659fd222d C:\WINNT\system32\msvcrt.dll
    <unsigned> MD5: 586636e7522400e2c20c11aba00739da C:\WINNT\system32\msvfw32.dll
    <unsigned> MD5: e7a3fcb568797785750308dd6db2bdc0 C:\WINNT\system32\msxml3.dll
    <unsigned> MD5: 91c9b0d90095e8169434169789768913 C:\WINNT\system32\mtxclu.dll
    <unsigned> MD5: 3327e705cb22ef064ee3fe08beb7851d C:\WINNT\system32\NDDEAPI.DLL
    <unsigned> MD5: 7c4b23ec8bdc45354a45fb99bee3f05e C:\WINNT\system32\ndptsp.tsp
    <unsigned> MD5: 7bbba94bcae7b4371254167c24972dfc C:\WINNT\system32\NETAPI32.DLL
    <unsigned> MD5: d06990ae4383f80c64ccc0916ce22a91 C:\WINNT\system32\netcfgx.dll
    <unsigned> MD5: f9b001cb9573d32433e051ec9f4ff203 C:\WINNT\system32\netdde.exe
    <unsigned> MD5: be8fc3c74ab5212cd4067e8973764ad6 C:\WINNT\system32\NETLOGON.DLL
    <unsigned> MD5: 600104d606ab3e9b9ab36076e6261a05 C:\WINNT\system32\netman.dll
    <unsigned> MD5: 3de628eb3d632875b8a24bdc53e67277 C:\WINNT\system32\netrap.dll
    <unsigned> MD5: fc1783b19a718444de5f6fe5c9143079 C:\WINNT\system32\netshell.dll
    <unsigned> MD5: a19d2705a2728bd9ffbe35273a00e59f C:\WINNT\system32\netui0.dll
    <unsigned> MD5: 9e65344e445a287fc3a299ff5304dbe5 C:\WINNT\system32\netui1.dll
    <unsigned> MD5: 4c0f0b57de8c1669aa6f49d285b3865a C:\WINNT\system32\NTDLL.DLL
    <unsigned> MD5: 1a9f0053b554fd71730b21e23458bc53 C:\WINNT\system32\ntdsapi.dll
    <unsigned> MD5: 5e135566b76bd640d217244ff6977d5d C:\WINNT\system32\NTLANMAN.DLL
    <unsigned> MD5: dca4e1b0fdc25579ccef23435f6ae7bb C:\WINNT\system32\ntlsapi.dll
    <unsigned> MD5: 65ae65d9ee439a16f5acf10e37f41897 C:\WINNT\system32\NTMARTA.DLL
    <unsigned> MD5: e15377596519a815c1878a5372260d05 C:\WINNT\system32\ntmsdba.dll
    <unsigned> MD5: 56d893a01269008c28fbf2d025b2fa78 C:\WINNT\system32\ntmssvc.dll
    <unsigned> MD5: 8648b1b3700ff6998aca8d99dd6de719 C:\WINNT\system32\ntshrui.dll
    <unsigned> MD5: 7f22f0fb5437b1b83bca7380385faf2d C:\WINNT\system32\OLE32.DLL
    <unsigned> MD5: fff4eaa996ec3521b227f64056a3a0f0 C:\WINNT\system32\oleacc.dll
    <unsigned> MD5: 6c81e3b6dde5b04290f4429f64b4959d C:\WINNT\system32\OLEAUT32.DLL
    <unsigned> MD5: 4da7121c98c3fe4355c8a115d2675958 C:\WINNT\system32\OLEDLG.DLL
    <unsigned> MD5: 6a8e009f98dd75553066c17b43afb0a5 C:\WINNT\system32\OLEPRO32.DLL
    <unsigned> MD5: 58c5ea3de400fe1d08cfeca6d5c14ebd C:\WINNT\system32\PCANDIS5.SYS
    <unsigned> MD5: af238673651efc0226ea74239b502a6f C:\WINNT\system32\pdf995mon.dll
    <unsigned> MD5: e1db653f8d58b0e3233bec48c134c15b C:\WINNT\system32\pdh.dll
    <unsigned> MD5: b24ba6115e2b75a1e7e65cda5cb4f392 C:\WINNT\system32\perfdisk.dll
    <unsigned> MD5: 5c29c9cf6a160eba8a0951b42576d701 C:\WINNT\system32\perfos.dll
    <unsigned> MD5: ae8f1468c686fd195ecb699cb4c2dfc3 C:\WINNT\system32\pjlmon.dll
    <unsigned> MD5: 0a35f356726069b95f4bb2a99203fdd4 C:\WINNT\system32\powrprof.dll
    <unsigned> MD5: 6d252e14e13830706c8f1ad6d7ebc412 C:\WINNT\system32\profmap.dll
    <unsigned> MD5: 7f7005d2f1d9c579179807818c3ac4c7 C:\WINNT\system32\psapi.dll
    <unsigned> MD5: 5e0b40dc14919bd3083fc70da478ebf6 C:\WINNT\system32\PSBASE.DLL
    <unsigned> MD5: dcd38d8178bf1bea585f2f003ee3460e C:\WINNT\system32\qmgr.dll
    <unsigned> MD5: 15c7fe3ef6c5f43a10a8c3eb3b993dd6 C:\WINNT\system32\rasadhlp.dll
    <unsigned> MD5: c2d3211d940675d7d25ccd1129126337 C:\WINNT\system32\RASAPI32.DLL
    <unsigned> MD5: 8b904d85988e71b01700b28ff4d966fe C:\WINNT\system32\RASAUTO.DLL
    <unsigned> MD5: 5b1aa71522fb43a463d0659bf41a5803 C:\WINNT\system32\RASDLG.DLL
    <unsigned> MD5: b342275d0a3e43983f9e27367c052ef1 C:\WINNT\system32\RASMAN.DLL
    <unsigned> MD5: 24ebc147155a809e4d815aeeb4f63299 C:\WINNT\system32\rasppp.dll
    <unsigned> MD5: 2ef3581845f5e60b02828994a0d62dd5 C:\WINNT\system32\rastapi.dll
    <unsigned> MD5: aa49b26e0d1736881a185621f777b5f2 C:\WINNT\system32\regapi.dll
    <unsigned> MD5: 250c4ce389783fa2398e3afa4317008c C:\WINNT\system32\regsvc.exe
    <unsigned> MD5: 81fba25a87da8a1be68fed1c8f7bc3e8 C:\WINNT\system32\RESUTILS.DLL
    <unsigned> MD5: 0f42b8b4045b7e7286a14a14023c5042 C:\WINNT\system32\riched20.dll
    <unsigned> MD5: 804d815826fe00d6471c72d8299fcbb5 C:\WINNT\system32\riched32.dll
    <unsigned> MD5: 11ff66de71088617a7ac172f33b6fda5 C:\WINNT\system32\RNR20.DLL
    <unsigned> MD5: 30572953af1743d992dffe57c37f7e9c C:\WINNT\system32\rpcrt4.dll
    <unsigned> MD5: 037ebcf93df5f0c31ccd2ff7e31e3ba5 C:\WINNT\system32\rpcss.dll
    <unsigned> MD5: 99cc1857e220543e0e63a792dfb7e228 C:\WINNT\system32\RSABASE.DLL
    <unsigned> MD5: 0ce723e5b4c61b1202eea0dc26118a00 C:\WINNT\system32\rsaenh.dll
    <unsigned> MD5: 2a21bddb1ba9b5cd776949380ab46a76 C:\WINNT\System32\rsvp.exe
    <unsigned> MD5: c950179659144c3e38a3c773c06de69f C:\WINNT\system32\rsvpsp.dll
    <unsigned> MD5: c1fcf708669031c78dcd68589abd9d4c C:\WINNT\system32\rtutils.dll
    <unsigned> MD5: abda35a92538d23407d3f394f5179002 C:\WINNT\system32\samlib.dll
    <unsigned> MD5: b94bc692ef5c8a837e43cf0d9218075c C:\WINNT\system32\SAMSRV.DLL
    <unsigned> MD5: 13c381e66cda8d4d80e84bf18307551f C:\WINNT\System32\SCardSvr.exe
    <unsigned> MD5: 6fcce1622e75c7dc46509f7ec4b314a3 C:\WINNT\system32\scecli.dll
    <unsigned> MD5: 9743cd4445d55f98d05d6520b8d10196 C:\WINNT\system32\scesrv.dll
    <unsigned> MD5: 83424d46daf1f22598bf1a6de1bcf13a C:\WINNT\system32\SCHANNEL.DLL
    <unsigned> MD5: dddc9a84e9b1ad3bd1dfaf531c15da9e C:\WINNT\system32\sclgntfy.dll
    <unsigned> MD5: 09606b361cf2b1c67fd3280a2b4a376b C:\WINNT\system32\seclogon.dll
    <unsigned> MD5: 54b5e42ba5203c79c44b5e7aaf70fef5 C:\WINNT\system32\secur32.dll
    <unsigned> MD5: 37bf0882ee939c02a2d3cf209831f2c5 C:\WINNT\system32\sens.dll
    <unsigned> MD5: d8017a6f9ae29679b0e7d4ae8a070123 C:\WINNT\system32\sensapi.dll
    <unsigned> MD5: b861b4e6e9637eb76a40c10c552e0229 C:\WINNT\system32\services.exe
    <unsigned> MD5: 9726125daa47dcbf34f53cef8c677b9c C:\WINNT\system32\SETUPAPI.DLL
    <unsigned> MD5: 7645645bb506c26b96b8f31893378c4b C:\WINNT\system32\sfcfiles.dll
    <unsigned> MD5: fd95707b90e2798a38ddfc4c59529c61 C:\WINNT\system32\shdoclc.dll
    <unsigned> MD5: 73ee318beeede628220ee4d357c4caa7 C:\WINNT\system32\SHELL32.DLL
    <unsigned> MD5: b52fe46bf6c62bc5c427c7fceaeccc18 C:\WINNT\system32\shfolder.dll
    <unsigned> MD5: 96be1bc88031f27722336073678e120b C:\WINNT\system32\shim.dll
    <unsigned> MD5: f4f35fe5f46262d45491822d8a66bf62 C:\WINNT\system32\smlogsvc.exe
    <unsigned> MD5: f07c69367770a1c129a22f9158afaa2b C:\WINNT\System32\smss.exe
    <unsigned> MD5: d3673dac986b3053a934c640d33c19d0 C:\WINNT\System32\spool\DRIVERS\W32X86\2\fppdis1.exe
    <unsigned> MD5: 36f42f4422638b436ab949b297a4bfaa C:\WINNT\system32\spool\drivers\w32x86\2\fppint1.dll
    <unsigned> MD5: 4ee5c3941f1d5bdf1149e43337183232 C:\WINNT\system32\spool\drivers\w32x86\2\fppr132.dll
    <unsigned> MD5: bf196968d49bb2d210912c54f1534821 C:\WINNT\system32\spoolss.dll
    <unsigned> MD5: facfb75ecc070103619fa044e0b210d3 C:\WINNT\system32\spoolsv.exe
    <unsigned> MD5: c95136a6013a49086420cefb0de7af8b C:\WINNT\system32\srvsvc.dll
    <unsigned> MD5: 34660338069fd5665b921ecffc96e0ce C:\WINNT\system32\stobject.dll
    <unsigned> MD5: 9e64ad53cfd9da2d22e8a924f8c6e62c C:\WINNT\system32\svchost.exe
    <unsigned> MD5: 1345278cf4e09542f684d824ec90674d C:\WINNT\system32\TAPI32.DLL
    <unsigned> MD5: e1086008e7bce8621f09e6f13b89cc31 C:\WINNT\system32\tapisrv.dll
    <unsigned> MD5: 826fafa8518fe2de9b297dd80a21ea5c C:\WINNT\system32\tcpmon.dll
    <unsigned> MD5: fa57d2175f4978e2f32cb1b02781d76a C:\WINNT\system32\tlntsvr.exe
    <unsigned> MD5: 3e9dd19f5ec900a3240c86678ab1d4bd C:\WINNT\system32\trkwks.dll
    <unsigned> MD5: 7d303f4281c0afbedeb790c026f9e101 C:\WINNT\system32\txfaux.dll
    <unsigned> MD5: 2c5e37de32b94dbe1063734cb286aece C:\WINNT\system32\UMPNPMGR.DLL
    <unsigned> MD5: d7fdcf7e1d6c422343e3df17189ab39b C:\WINNT\system32\UNIMDM.TSP
    <unsigned> MD5: 09ea38827601fb5796d5a613b07f1c04 C:\WINNT\system32\unimdmat.dll
    <unsigned> MD5: 09d1efad67d3366c6db67b1f22c6f897 C:\WINNT\system32\uniplat.dll
    <unsigned> MD5: 222a997aa4c7f7a2b3453b556afa4406 C:\WINNT\System32\ups.exe
    <unsigned> MD5: 5851a2ad3dd40a761ca6f30fed140e23 C:\WINNT\system32\usbmon.dll
    <unsigned> MD5: 40023a7103796b1af6ca41a6dbc54775 C:\WINNT\system32\USER32.DLL
    <unsigned> MD5: 099cd26e9c34225002e4477c8ac8dcb0 C:\WINNT\system32\USERENV.DLL
    <unsigned> MD5: bf179c5b8a722cc79aef1ca90d6c7d48 c:\winnt\system32\userinit.exe
    <unsigned> MD5: c1a1b306a3048fc8dc7d1cfd576eff60 C:\WINNT\system32\usp10.dll
    <unsigned> MD5: feecca1c633f66c0a73b4cc009361f15 C:\WINNT\system32\utildll.dll
    <unsigned> MD5: 7a960f1e9a0b2f7d14f1d0eddd74375c C:\WINNT\System32\UtilMan.exe
    <unsigned> MD5: ca34bd29eb86bd772d59d35b959d43ee C:\WINNT\system32\version.dll
    <unsigned> MD5: f3c722f1a5372e4c9b7e76d76619a3a0 C:\WINNT\system32\W32N50.dll
    <unsigned> MD5: 84f0c7af5a2175676ae4e1290205efee C:\WINNT\system32\WakeResDll.dll
    <unsigned> MD5: 1eeca5226da72cf2ebd9156a6e7d2e37 C:\WINNT\system32\wbem\cimwin32.dll
    <unsigned> MD5: 26a31a6e5182df87abe02ea2ac356844 C:\WINNT\system32\wbem\fastprox.dll
    <unsigned> MD5: 049cf02ab2a93ff8b17d64cde07be655 C:\WINNT\system32\wbem\framedyn.dll
    <unsigned> MD5: 8a02ace7329b4ff8074693e41bbe1aa8 C:\WINNT\System32\WBEM\unsecapp.exe
    <unsigned> MD5: 1eef3ec347c1ef3437ed186946d2ee8d C:\WINNT\system32\wbem\wbemcomn.dll
    <unsigned> MD5: 5b50102e2f1fb079a67e83a094f91ff0 C:\WINNT\system32\wbem\wbemcore.dll
    <unsigned> MD5: 82444b006776f06902a590c5f001d184 C:\WINNT\system32\wbem\wbemess.dll
    <unsigned> MD5: 17fa736b454dea3388e6e084451afcdc C:\WINNT\system32\wbem\wbemprox.dll
    <unsigned> MD5: d8c368e73b9eaa433bb7c840eb44b59d C:\WINNT\system32\wbem\wbemsvc.dll
    <unsigned> MD5: 05b2001e1bc653fd6091e741b46f71b4 C:\WINNT\System32\WBEM\WinMgmt.exe
    <unsigned> MD5: 64edee207678b40a3b0a777292744caa C:\WINNT\system32\wdmaud.drv
    <unsigned> MD5: f2786dc35401fceb401a0f5810e22ab6 C:\WINNT\system32\webcheck.dll
    <unsigned> MD5: 67df8626cf368ee39b211fc0e14f6f72 C:\WINNT\system32\WIN32SPL.DLL
    <unsigned> MD5: e962adea0d262846b430dc05e8b79ea6 C:\WINNT\system32\winhttp.dll
    <unsigned> MD5: bb1daf6a5737652646d52665251a0265 C:\WINNT\system32\winlogon.exe
    <unsigned> MD5: 89ae2927b977604d720b1680e208af47 C:\WINNT\system32\winmm.dll
    <unsigned> MD5: 71325b58bc6a78b951cfe71b7514f91e C:\WINNT\system32\winrnr.dll
    <unsigned> MD5: 8e0c8e951e2bf9041bf8b81e4891b2ac C:\WINNT\system32\winscard.dll
    <unsigned> MD5: e58bf969aa9e4c548473474d8e9d971a C:\WINNT\system32\WINSPOOL.DRV
    <unsigned> MD5: e3211e4884a21375f4d64a4b3986bca3 C:\WINNT\system32\WINSRV.DLL
    <unsigned> MD5: 04ca4218d9d4a08e5159d4f7f49a1ddf C:\WINNT\system32\winsta.dll
    <unsigned> MD5: 50d5a80be9bea46b100c1391b7eef46d C:\WINNT\system32\WKSSVC.DLL
    <unsigned> MD5: 0da1335235dc386dab3c2329bcf2d4ee C:\WINNT\system32\WLDAP32.DLL
    <unsigned> MD5: 0ac7c01fae29d99696147295cbd0a0be C:\WINNT\system32\wlnotify.dll
    <unsigned> MD5: e880e1f2067442054fc5de2d55031625 C:\WINNT\system32\wmi.dll
    <unsigned> MD5: f1cbdecc305ba08e29089082aa97f608 C:\WINNT\system32\wmicore.dll
    <unsigned> MD5: 0190c62de42396d78db9be771cf2403e C:\WINNT\system32\ws2_32.dll
    <unsigned> MD5: 28336b1300ec048124197091354251b6 C:\WINNT\system32\ws2help.dll
    <unsigned> MD5: ad5819f9b7371d46ff706630309de706 C:\WINNT\system32\wshtcpip.dll
    <unsigned> MD5: 183d2d8e28a0393b4798addd46ad27b0 C:\WINNT\system32\wsock32.dll
    <unsigned> MD5: caf6fe23565afcddf26666707178aee8 C:\WINNT\system32\wtsapi32.dll
    <unsigned> MD5: c9921283e4c271dbb51b3e5d5283dd04 C:\WINNT\system32\wuauserv.dll
    <unsigned> MD5: 40217a42449dab0124957f81c6f33ecd C:\WINNT\system32\wzcdlg.dll
    <unsigned> MD5: 54a1ca77d1f2698c77bc8bf8ed2cf4e2 C:\WINNT\system32\wzcsapi.dll
    <unsigned> MD5: c56caa178ffd4c28d4ef3801ee1cd0df C:\WINNT\system32\wzcsvc.dll


    No file uploaded.

    Scan finished - communication took 6 sec
    Total traffic - 0.07 MB sent, 2.68 KB recvd
    Scanned 1129 files and modules - 88 seconds

    ==============================================================================
     
  6. 2010/06/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OTL Clean-Up
    Clean up with OTL:

    * Double-click OTL.exe to start the program.
    * Close all other programs apart from OTL as this step will require a reboot
    * On the OTL main screen, press the CLEANUP button
    * Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    ===============================================================

    Your computer is clean :)

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point.

    Turn off System Restore:

    - Windows XP:
    1. Click Start.
    2. Right-click the My Computer icon, and then click Properties.
    3. Click the System Restore tab.
    4. Check "Turn off System Restore ".
    5. Click Apply.
    6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
    7. Click OK.
    - Windows Vista and 7:
    1. Click Start.
    2. Right-click the Computer icon, and then click Properties.
    3. Click on System Protection under the Tasks column on the left side
    4. Click on Continue on the "User Account Control" window that pops up
    5. Under the System Protection tab, find Available Disks
    6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C: ")
    7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
    8. Click OK

    2. Restart computer.

    3. Turn System Restore on.

    4. Make sure, Windows Updates are current.

    [SIZE= "4"]5. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately![/SIZE]

    6. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    7. Run defrag at your convenience.

    8. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    9. Please, let me know, how is your computer doing.
     
  7. 2010/06/21
    scorekeeper

    scorekeeper Inactive Thread Starter

    Joined:
    2007/02/18
    Messages:
    104
    Likes Received:
    0
    Well, the machine may be clean, but the control panel still isn’t working correctly. However, I can run the CP items, except add/remove programs. I still get a script error that says. “Access is denied to: res://appwiz.cpl/places.htc”.

    Any other thoughts?
     
  8. 2010/06/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    From my research, it seems like your issue has something to do with corrupted Internet explorer.

    Try "sfc ".

    Go Start>Run ( "Start Search" in Vista/7), type in:
    sfc /scannow
    Click OK (hold CTRL, and SHIFT, hit Enter in Vista/7).
    Have Windows CD/DVD handy (with Vista/7, most likely, you won't need it).
    If System File Checker (sfc) will find any errors, it may ask you for the CD/DVD (rarely in Vista/7 case).

    If the above doesn't work, try IE6 repair: http://www.theeldergeek.com/repair_ie6.htm (Method 2, same for Win 2K)
     
  9. 2010/06/22
    scorekeeper

    scorekeeper Inactive Thread Starter

    Joined:
    2007/02/18
    Messages:
    104
    Likes Received:
    0
    Well, now I have a real issue. I ran the sfc and it asked for the 2000 CD to reload an altered file. I haven't got a clue what's happened to the CD. I've looked for it, but haven't found it as yet.
     
  10. 2010/06/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Well, if "sfc" asked for a CD, it means, some system file(s) is corrupted, so, basically, you have two options:
    - find the CD
    - live with Add\Remove issue

    Since your computer is malware free, I'll mark this thread as resolved.
     
  11. 2010/06/23
    scorekeeper

    scorekeeper Inactive Thread Starter

    Joined:
    2007/02/18
    Messages:
    104
    Likes Received:
    0
    Well, at least I know for sure that there is a problem and how I can hopefully get rid of it. I shall continue to try to find the 2000 CD. Is there anyplace I can get my hands on one that you know of?

    Thanx for all the help, its much appreciated!
     
  12. 2010/06/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Win 2K is pretty old OS, so I'd say your best bet is probably eBay, or Craigslist.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.