Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 21.9.2014. 22:16:28 - Run 1
- OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Denis\Desktop
- 64bit- Enterprise Edition (Version = 6.2.9200) - Type = NTWorkstation
- Internet Explorer (Version = 9.10.9200.17088)
- Locale: 0000041a | Country: Hrvatska | Language: HRV | Date Format: d.M.yyyy.
- 5,75 Gb Total Physical Memory | 3,58 Gb Available Physical Memory | 62,30% Memory free
- 6,69 Gb Paging File | 4,12 Gb Available in Paging File | 61,59% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
- Drive C: | 97,66 Gb Total Space | 43,86 Gb Free Space | 44,91% Space Free | Partition Type: NTFS
- Drive D: | 97,56 Gb Total Space | 66,71 Gb Free Space | 68,38% Space Free | Partition Type: NTFS
- Drive E: | 270,45 Gb Total Space | 160,03 Gb Free Space | 59,17% Space Free | Partition Type: NTFS
- Computer Name: DENIS | User Name: Denis | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
- Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2014.09.21 22:15:45 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Denis\Desktop\OTL.exe
- PRC - [2014.09.19 23:05:07 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- PRC - [2014.09.09 19:28:54 | 001,870,000 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
- PRC - [2014.08.02 10:25:25 | 004,085,896 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
- PRC - [2014.08.02 10:24:49 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
- PRC - [2014.06.27 11:52:26 | 002,088,408 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
- PRC - [2014.06.24 10:42:12 | 004,101,576 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
- PRC - [2014.06.24 10:41:42 | 001,738,168 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
- PRC - [2014.04.25 14:12:20 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
- PRC - [2013.12.17 12:38:33 | 005,341,536 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
- PRC - [2013.01.27 22:31:16 | 002,570,560 | ---- | M] (IntelliBreeze Software) -- C:\Program Files (x86)\Gmail Notifier Pro\GmailNotifierPro.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2014.09.19 23:05:05 | 003,734,640 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
- MOD - [2014.09.09 19:28:52 | 016,825,520 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
- MOD - [2014.08.02 10:24:53 | 019,329,904 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
- MOD - [2014.08.02 10:24:52 | 000,301,152 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswProperty.dll
- MOD - [2014.05.13 12:04:48 | 000,167,768 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
- MOD - [2014.05.13 12:04:46 | 000,109,400 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
- MOD - [2014.05.13 12:04:42 | 000,416,600 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
- MOD - [2012.10.21 22:59:04 | 001,128,448 | ---- | M] () -- C:\Program Files (x86)\Gmail Notifier Pro\DotNetOpenAuth.dll
- [color=#E56717]========== Services (SafeList) ==========[/color]
- SRV:[b]64bit:[/b] - [2014.08.02 10:24:49 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
- SRV:[b]64bit:[/b] - [2014.05.30 01:02:28 | 000,439,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
- SRV:[b]64bit:[/b] - [2014.03.29 10:05:59 | 000,016,056 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
- SRV:[b]64bit:[/b] - [2014.01.09 07:15:48 | 001,025,408 | ---- | M] (Enigma Software Group USA, LLC.) [Auto | Running] -- C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe -- (SpyHunter 4 Service)
- SRV:[b]64bit:[/b] - [2013.08.16 07:39:26 | 002,371,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
- SRV:[b]64bit:[/b] - [2013.06.25 00:54:45 | 000,263,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
- SRV:[b]64bit:[/b] - [2013.06.01 11:19:58 | 000,207,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
- SRV:[b]64bit:[/b] - [2013.05.04 08:58:02 | 000,470,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
- SRV:[b]64bit:[/b] - [2013.05.04 08:57:05 | 000,179,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
- SRV:[b]64bit:[/b] - [2013.04.09 06:48:42 | 000,169,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
- SRV:[b]64bit:[/b] - [2013.03.02 04:45:07 | 000,171,008 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
- SRV:[b]64bit:[/b] - [2013.03.02 04:45:05 | 000,180,224 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
- SRV:[b]64bit:[/b] - [2013.01.10 01:23:16 | 001,964,544 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
- SRV:[b]64bit:[/b] - [2012.11.06 06:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
- SRV:[b]64bit:[/b] - [2012.09.20 08:31:18 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:07:47 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:07:40 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:07:25 | 000,012,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
- SRV:[b]64bit:[/b] - [2012.07.26 05:06:33 | 000,161,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:06:33 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:55 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:34 | 000,037,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:24 | 000,342,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:08 | 000,122,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AUInstallAgent.dll -- (AllUserInstallAgent)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:04 | 000,187,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
- SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
- SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
- SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
- SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
- SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
- SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
- SRV - [2014.09.19 23:05:06 | 000,114,288 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
- SRV - [2014.09.09 19:28:55 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
- SRV - [2014.05.12 07:24:42 | 000,860,472 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- D:\Nova mapa\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
- SRV - [2014.05.12 07:24:40 | 001,809,720 | ---- | M] (Malwarebytes Corporation) [Disabled | Stopped] -- D:\Nova mapa\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
- SRV - [2013.12.17 12:38:33 | 005,341,536 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
- SRV - [2013.10.23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
- SRV - [2012.11.06 06:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify)
- SRV - [2012.07.26 05:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
- SRV - [2012.07.13 17:27:00 | 000,769,432 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV:[b]64bit:[/b] - [2014.08.02 10:25:22 | 000,427,360 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\Drivers\aswsp.sys -- (aswSP)
- DRV:[b]64bit:[/b] - [2014.08.02 10:25:02 | 001,041,168 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\Drivers\aswSnx.sys -- (aswSnx)
- DRV:[b]64bit:[/b] - [2014.08.02 10:25:02 | 000,224,896 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
- DRV:[b]64bit:[/b] - [2014.08.02 10:25:02 | 000,092,008 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\aswStm.sys -- (aswStm)
- DRV:[b]64bit:[/b] - [2014.08.02 10:25:02 | 000,079,184 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\Drivers\aswMonFlt.sys -- (aswMonFlt)
- DRV:[b]64bit:[/b] - [2014.08.02 10:25:02 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
- DRV:[b]64bit:[/b] - [2014.08.02 10:25:02 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\aswHwid.sys -- (aswHwid)
- DRV:[b]64bit:[/b] - [2014.08.02 10:25:01 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\aswRdr2.sys -- (aswRdr)
- DRV:[b]64bit:[/b] - [2014.05.12 07:26:14 | 000,064,216 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mwac.sys -- (MBAMWebAccessControl)
- DRV:[b]64bit:[/b] - [2014.05.12 07:25:56 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\Drivers\mbam.sys -- (MBAMProtector)
- DRV:[b]64bit:[/b] - [2014.03.28 21:19:38 | 000,035,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdBoot.sys -- (WdBoot)
- DRV:[b]64bit:[/b] - [2014.03.24 00:11:52 | 000,269,592 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdFilter.sys -- (WdFilter)
- DRV:[b]64bit:[/b] - [2014.01.07 03:47:06 | 000,014,872 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
- DRV:[b]64bit:[/b] - [2013.11.18 03:18:34 | 000,017,088 | ---- | M] (Glarysoft Ltd) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\BootDefragDriver.sys -- (BootDefragDriver)
- DRV:[b]64bit:[/b] - [2013.10.10 13:53:35 | 000,096,600 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\wfplwfs.sys -- (WFPLWFS)
- DRV:[b]64bit:[/b] - [2013.10.05 08:10:20 | 000,285,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\spaceport.sys -- (spaceport)
- DRV:[b]64bit:[/b] - [2013.10.02 04:50:07 | 000,447,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBHUB3.SYS -- (USBHUB3)
- DRV:[b]64bit:[/b] - [2013.08.16 07:41:13 | 000,058,200 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\Drivers\dam.sys -- (dam)
- DRV:[b]64bit:[/b] - [2013.08.10 08:30:22 | 000,151,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\tpm.sys -- (TPM)
- DRV:[b]64bit:[/b] - [2013.07.25 16:53:46 | 000,023,040 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\netaapl64.sys -- (Netaapl)
- DRV:[b]64bit:[/b] - [2013.07.09 10:04:07 | 000,120,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpioclx.sys -- (GPIOClx0101)
- DRV:[b]64bit:[/b] - [2013.07.02 03:41:47 | 000,337,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBXHCI.SYS -- (USBXHCI)
- DRV:[b]64bit:[/b] - [2013.07.02 03:41:47 | 000,213,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\UCX01000.SYS -- (UCX01000)
- DRV:[b]64bit:[/b] - [2013.06.29 08:15:54 | 000,195,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdbus.sys -- (sdbus)
- DRV:[b]64bit:[/b] - [2013.06.01 05:08:57 | 000,037,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
- DRV:[b]64bit:[/b] - [2013.03.02 12:57:46 | 000,077,544 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\storahci.sys -- (storahci)
- DRV:[b]64bit:[/b] - [2013.03.02 12:39:38 | 000,069,864 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\pdc.sys -- (pdc)
- DRV:[b]64bit:[/b] - [2013.01.22 09:52:08 | 000,075,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dc3d.sys -- (dc3d)
- DRV:[b]64bit:[/b] - [2013.01.10 03:53:32 | 000,028,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpiowin32.sys -- (msgpiowin32)
- DRV:[b]64bit:[/b] - [2012.12.13 14:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbaapl64.sys -- (USBAAPL64)
- DRV:[b]64bit:[/b] - [2012.11.27 05:55:44 | 000,029,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthhfHid.sys -- (bthhfhid)
- DRV:[b]64bit:[/b] - [2012.11.20 06:54:31 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hidi2c.sys -- (hidi2c)
- DRV:[b]64bit:[/b] - [2012.11.06 05:55:44 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\fxppm.sys -- (FxPPM)
- DRV:[b]64bit:[/b] - [2012.10.12 10:08:01 | 000,027,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
- DRV:[b]64bit:[/b] - [2012.10.11 09:25:48 | 000,056,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdstor.sys -- (sdstor)
- DRV:[b]64bit:[/b] - [2012.10.11 07:19:44 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WSDScan.sys -- (WSDScan)
- DRV:[b]64bit:[/b] - [2012.09.20 09:55:27 | 003,265,256 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\evbda.sys -- (ebdrv)
- DRV:[b]64bit:[/b] - [2012.09.20 09:55:24 | 000,533,224 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\bxvbda.sys -- (b06bdrv)
- DRV:[b]64bit:[/b] - [2012.08.21 14:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
- DRV:[b]64bit:[/b] - [2012.07.26 07:26:46 | 000,025,328 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
- DRV:[b]64bit:[/b] - [2012.07.26 07:26:45 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\condrv.sys -- (condrv)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:58 | 000,322,800 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS -- (VSTXRAID)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:58 | 000,106,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\VerifierExt.sys -- (VerifierExt)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:58 | 000,097,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\uaspstor.sys -- (UASPStor)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:57 | 000,077,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\acpiex.sys -- (acpiex)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:55 | 000,064,240 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\mvumis.sys -- (mvumis)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:55 | 000,030,960 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\stexstor.sys -- (stexstor)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:52 | 000,092,400 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sas2.sys -- (LSI_SAS2)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:52 | 000,081,136 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sss.sys -- (LSI_SSS)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:52 | 000,064,752 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\HpSAMD.sys -- (HpSAMD)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:51 | 000,113,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:51 | 000,081,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\EhStorClass.sys -- (EhStorClass)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:49 | 000,258,288 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsbs.sys -- (amdsbs)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:49 | 000,106,736 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\3ware.sys -- (3ware)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:49 | 000,076,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsata.sys -- (amdsata)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:48 | 000,026,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdxata.sys -- (amdxata)
- DRV:[b]64bit:[/b] - [2012.07.26 06:57:54 | 000,361,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\clfs.sys -- (CLFS)
- DRV:[b]64bit:[/b] - [2012.07.26 06:53:16 | 000,067,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpci.sys -- (vpci)
- DRV:[b]64bit:[/b] - [2012.07.26 06:50:20 | 000,053,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\Synth3dVsc.sys -- (Synth3dVsc)
- DRV:[b]64bit:[/b] - [2012.07.26 05:17:38 | 000,036,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\terminpt.sys -- (terminpt)
- DRV:[b]64bit:[/b] - [2012.07.26 04:29:47 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WSDPrint.sys -- (WSDPrintDevice)
- DRV:[b]64bit:[/b] - [2012.07.26 04:29:14 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mshidumdf.sys -- (mshidumdf)
- DRV:[b]64bit:[/b] - [2012.07.26 04:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicDisplay.sys -- (BasicDisplay)
- DRV:[b]64bit:[/b] - [2012.07.26 04:29:03 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\HyperVideo.sys -- (HyperVideo)
- DRV:[b]64bit:[/b] - [2012.07.26 04:28:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicRender.sys -- (BasicRender)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmgencounter.sys -- (gencounter)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:41 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\kdnic.sys -- (kdnic)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:37 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpitime.sys -- (acpitime)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\npsvctrig.sys -- (npsvctrig)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:29 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys -- (WpdUpFltr)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:16 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpipagr.sys -- (acpipagr)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:01 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hyperkbd.sys -- (hyperkbd)
- DRV:[b]64bit:[/b] - [2012.07.26 04:26:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SerCx.sys -- (SerCx)
- DRV:[b]64bit:[/b] - [2012.07.26 04:26:43 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SpbCx.sys -- (SpbCx)
- DRV:[b]64bit:[/b] - [2012.07.26 04:26:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbGD.sys -- (TsUsbGD)
- DRV:[b]64bit:[/b] - [2012.07.26 04:26:13 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\bthhfenum.sys -- (BthHFEnum)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:57 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dmvsc.sys -- (dmvsc)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys -- (TsUsbFlt)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:26 | 000,203,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\Vid.sys -- (Vid)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:22 | 000,067,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\storvsp.sys -- (storvsp)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:13 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\wpcfltr.sys -- (wpcfltr)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:12 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmbusr.sys -- (vmbusr)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:12 | 000,066,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpcivsp.sys -- (vpcivsp)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:01 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys -- (NdisImPlatform)
- DRV:[b]64bit:[/b] - [2012.07.26 04:23:53 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mslldp.sys -- (MsLldp)
- DRV:[b]64bit:[/b] - [2012.07.26 04:23:42 | 000,115,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\tsusbhub.sys -- (tsusbhub)
- DRV:[b]64bit:[/b] - [2012.07.26 04:23:42 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\Ndu.sys -- (Ndu)
- DRV:[b]64bit:[/b] - [2012.07.26 00:53:22 | 011,926,528 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmdag.sys -- (amdkmdag)
- DRV:[b]64bit:[/b] - [2012.06.29 04:00:48 | 000,360,448 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmpag.sys -- (amdkmdap)
- DRV:[b]64bit:[/b] - [2012.06.22 11:01:32 | 000,022,704 | ---- | M] () [File_System | Auto | Stop_Pending] -- C:\Windows\SysNative\Drivers\EsgScanner.sys -- (EsgScanner)
- DRV:[b]64bit:[/b] - [2012.06.02 16:31:37 | 000,425,472 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\k57nd60a.sys -- (k57nd60a)
- DRV:[b]64bit:[/b] - [2012.06.02 16:31:32 | 002,935,808 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\athrx.sys -- (athr)
- DRV:[b]64bit:[/b] - [2012.03.27 07:50:38 | 000,284,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BrSerIb.sys -- (BrSerIb)
- DRV:[b]64bit:[/b] - [2011.07.18 22:58:32 | 000,015,360 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BrUsbSIb.sys -- (BrUsbSIb)
- DRV:[b]64bit:[/b] - [2011.04.08 23:00:20 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\nuidfltr.sys -- (NuidFltr)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}: "URL" = http://www.default-search.net/search?sid=503&aid=100&itype=n&ver=13001&tm=394&src=ds&p={searchTerms}
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- IE - HKLM\..\SearchScopes,DefaultScope =
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}: "URL" = http://www.default-search.net/search?sid=503&aid=100&itype=n&ver=13001&tm=394&src=ds&p={searchTerms}
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
- IE - HKCU\..\SearchScopes,DefaultScope =
- IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
- IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}: "URL" = http://www.default-search.net/search?sid=503&aid=100&itype=n&ver=13001&tm=394&src=ds&p={searchTerms}
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.defaultengine: "Google"
- FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?btnG=Google+Search&q="
- FF - prefs.js..browser.search.useDBForOrder: "false"
- FF - prefs.js..extensions.enabledAddons: system-monitor%40clear-code.com:0.7.0
- FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:9.0.2021.112
- FF - prefs.js..extensions.enabledAddons: foxmarks%40kei.com:4.3.3
- FF - prefs.js..extensions.enabledAddons: %7Bcc6cc772-f121-49e0-b1f0-c26583cb0c5e%7D:0.1
- FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:32.0.2
- FF - user.js - File not found
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll File not found
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
- FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
- FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
- FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
- FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
- FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
- FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Denis\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll File not found
- FF - HKCU\Software\MozillaPlugins\autodesk.com/Autodesk123DShapes: C:\Users\Denis\AppData\Local\Autodesk\123DPlugins\Autodesk 123D Shapes321.0.129\npAutodesk123DShapes32.dll (Autodesk)
- FF - HKCU\Software\MozillaPlugins\autodesk.com/Autodesk3DPrintingPlugIn: C:\Users\Denis\AppData\Local\Autodesk\123DPlugins\Autodesk 3D Printing321.0.12\npAutodesk3DPrinting32.dll (Autodesk)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014.08.02 10:25:03 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
- [2014.04.20 15:56:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Denis\AppData\Roaming\mozilla\Extensions
- [2014.04.20 15:56:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Denis\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
- [2014.09.15 22:29:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Denis\AppData\Roaming\mozilla\Firefox\Profiles\rgha27iq.default\extensions
- [2014.09.15 22:29:54 | 000,000,000 | ---D | M] ("Website Counselor") -- C:\Users\Denis\AppData\Roaming\mozilla\Firefox\Profiles\rgha27iq.default\extensions\{cc6cc772-f121-49e0-b1f0-c26583cb0c5e}
- [2014.08.14 08:46:32 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Denis\AppData\Roaming\mozilla\Firefox\Profiles\rgha27iq.default\extensions\foxmarks@kei.com
- [2014.09.15 22:21:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Denis\AppData\Roaming\mozilla\Firefox\Profilesrgha27iq.default\extensions
- [2014.09.15 22:21:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Denis\AppData\Roaming\mozilla\Firefox\Profilesrgha27iq.default\extensions\staged
- [2013.02.01 11:04:52 | 000,070,479 | ---- | M] () (No name found) -- C:\Users\Denis\AppData\Roaming\mozilla\firefox\profiles\rgha27iq.default\extensions\system-monitor@clear-code.com.xpi
- [2014.08.13 16:08:51 | 000,967,685 | ---- | M] () (No name found) -- C:\Users\Denis\AppData\Roaming\mozilla\firefox\profiles\rgha27iq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- [2014.09.19 23:04:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
- [2014.09.19 23:05:09 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- [2014.08.02 10:25:03 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
- [color=#E56717]========== Chrome ==========[/color]
- CHR - default_search_provider: (Enabled)
- CHR - default_search_provider: search_url =
- CHR - default_search_provider: suggest_url =
- CHR - plugin: Error reading preferences file
- CHR - Extension: No name found = C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajpgkpeckebdhofmmjfgcjjiiejpodla\1.0.28_0\
- CHR - Extension: No name found = C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
- CHR - Extension: No name found = C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
- CHR - Extension: No name found = C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
- CHR - Extension: No name found = C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
- CHR - Extension: No name found = C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmpncdjcpgnbcgfkboljpaagkkkcbbbk\1_0\
- CHR - Extension: No name found = C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\9.0.2022.122_0\
- CHR - Extension: No name found = C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.7.13_0\
- CHR - Extension: No name found = C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2022.121_0\
- CHR - Extension: No name found = C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbhppfbabandkdmgjmifahoabeodiep\1.4.1_0\
- CHR - Extension: No name found = C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
- CHR - Extension: No name found = C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
- O1 HOSTS File: ([2012.07.26 07:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
- O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
- O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
- O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
- O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
- O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
- O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
- O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
- O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
- O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
- O4 - HKCU..\Run: [GmailNotifierPro] C:\Program Files (x86)\Gmail Notifier Pro\GmailNotifierPro.exe (IntelliBreeze Software)
- O4 - HKCU..\Run: [GUDelayStartup] D:\Nova mapa\Glary Utilities 4\StartupManager.exe (Glarysoft Ltd)
- O4 - HKCU..\Run: [Viber] C:\Users\Denis\AppData\Local\Viber\Viber.exe ()
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
- O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
- O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
- O13[b]64bit:[/b] - gopher Prefix: missing
- O13 - gopher Prefix: missing
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4A8B2A46-8D70-4D62-8420-4D88C1A3EEB8}: DhcpNameServer = 172.20.10.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8CD720C3-01BA-43E4-A574-9A022B515DC6}: DhcpNameServer = 192.168.1.1
- O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
- O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
- O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
- O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
- O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O30 - LSA: Security Packages - (livessp) - File not found
- O32 - HKLM CDRom: AutoRun - 1
- O32 - AutoRun File - [2014.09.19 22:46:57 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
- O33 - MountPoints2\{6da856b6-c8c9-11e3-bec4-206a8a058368}\Shell - "" = AutoRun
- O33 - MountPoints2\{6da856b6-c8c9-11e3-bec4-206a8a058368}\Shell\AutoRun\command - "" = "G:\AutoRun.exe"
- O33 - MountPoints2\{6da856f0-c8c9-11e3-bec4-206a8a058368}\Shell - "" = AutoRun
- O33 - MountPoints2\{6da856f0-c8c9-11e3-bec4-206a8a058368}\Shell\AutoRun\command - "" = "G:\AutoRun.exe"
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
- O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
- O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
- NetSvcs:[b]64bit:[/b] wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
- NetSvcs:[b]64bit:[/b] DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
- NetSvcs:[b]64bit:[/b] NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
- NetSvcs:[b]64bit:[/b] SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
- NetSvcs:[b]64bit:[/b] AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
- Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
- Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
- Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
- CREATERESTOREPOINT
- Restore point Set: OTL Restore Point
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2014.09.21 22:15:44 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Denis\Desktop\OTL.exe
- [2014.09.21 20:59:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
- [2014.09.21 20:59:15 | 000,021,040 | ---- | C] (Safer Networking Limited) -- C:\Windows\SysNative\sdnclean64.exe
- [2014.09.21 20:59:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
- [2014.09.21 20:59:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
- [2014.09.19 23:04:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
- [2014.09.19 22:46:18 | 000,000,000 | ---D | C] -- C:\Users\Denis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
- [2014.09.19 22:46:16 | 000,000,000 | ---D | C] -- C:\sh4ldr
- [2014.09.19 22:46:16 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
- [2014.09.19 22:45:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
- [2014.09.17 21:26:52 | 000,000,000 | ---D | C] -- C:\Users\Denis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacije sustava Chrome
- [2014.09.17 21:25:38 | 000,000,000 | ---D | C] -- C:\Users\Denis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
- [2014.09.15 22:28:33 | 000,000,000 | ---D | C] -- C:\Users\Denis\.replicatorg
- [2014.09.15 22:28:23 | 000,000,000 | ---D | C] -- C:\Users\Denis\.replicatorg-backup-269364315136529
- [2014.09.15 22:27:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 3.3
- [2014.09.15 22:21:41 | 000,000,000 | ---D | C] -- C:\Users\Denis\AppData\Roaming\WebExtend
- [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2014.09.21 22:15:45 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Denis\Desktop\OTL.exe
- [2014.09.21 22:03:00 | 000,000,958 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
- [2014.09.21 21:28:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
- [2014.09.21 20:59:21 | 000,001,383 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
- [2014.09.21 09:03:00 | 000,000,954 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
- [2014.09.19 22:46:57 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
- [2014.09.19 22:46:19 | 000,002,218 | ---- | M] () -- C:\Users\Denis\Desktop\SpyHunter.lnk
- [2014.09.19 20:09:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2014.09.17 21:25:38 | 000,002,333 | ---- | M] () -- C:\Users\Denis\Desktop\Pokretač aplikacija sustava Chrome.lnk
- [2014.09.15 22:20:22 | 021,086,208 | ---- | M] () -- C:\Users\Denis\Desktop\python-3-3-3-amd64.msi
- [2014.09.15 19:09:57 | 000,000,322 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize 4.job
- [2014.09.12 19:40:13 | 000,305,688 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
- [2014.09.12 19:39:13 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
- [2014.09.12 19:39:11 | 642,707,455 | -HS- | M] () -- C:\hiberfil.sys
- [2014.09.11 14:30:11 | 000,002,179 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
- [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2014.09.21 20:59:21 | 000,001,395 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
- [2014.09.21 20:59:21 | 000,001,383 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
- [2014.09.19 22:46:57 | 000,000,000 | ---- | C] () -- C:\autoexec.bat
- [2014.09.19 22:46:22 | 000,022,704 | ---- | C] () -- C:\Windows\SysNative\drivers\EsgScanner.sys
- [2014.09.19 22:46:19 | 000,002,218 | ---- | C] () -- C:\Users\Denis\Desktop\SpyHunter.lnk
- [2014.09.17 21:25:38 | 000,002,333 | ---- | C] () -- C:\Users\Denis\Desktop\Pokretač aplikacija sustava Chrome.lnk
- [2014.09.15 22:19:28 | 021,086,208 | ---- | C] () -- C:\Users\Denis\Desktop\python-3-3-3-amd64.msi
- [2014.04.17 20:27:46 | 000,405,881 | ---- | C] () -- C:\Windows\KJ.exe
- [2013.12.09 19:07:07 | 000,024,064 | ---- | C] () -- C:\Windows\zoek-delete.exe
- [2013.09.11 20:01:46 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
- [2013.03.23 12:01:32 | 000,000,410 | ---- | C] () -- C:\Windows\BRWMARK.INI
- [2013.03.23 12:01:32 | 000,000,034 | ---- | C] () -- C:\Windows\SysWow64\BD7320.DAT
- [2013.01.29 12:16:17 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
- [color=#E56717]========== ZeroAccess Check ==========[/color]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- "" = C:\Windows\SysNative\shell32.dll -- [2014.03.28 10:23:06 | 019,759,104 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- "" = %SystemRoot%\system32\shell32.dll -- [2014.03.28 08:18:26 | 017,562,112 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012.07.26 05:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
- "" = %systemroot%\system32\wbem\fastprox.dll -- [2012.07.26 05:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012.07.26 05:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Both
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
- [color=#E56717]========== LOP Check ==========[/color]
- [2014.07.09 22:15:27 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\Autodesk
- [2013.12.06 20:44:39 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\AVAST Software
- [2014.04.25 21:24:28 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\Bitcoin
- [2013.11.24 02:07:33 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\BitTorrent Sync
- [2014.08.15 10:43:14 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\Dropbox
- [2014.08.15 10:43:13 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\DropboxMaster
- [2014.05.04 22:04:21 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\DVDVideoSoft
- [2013.10.30 20:46:40 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\fltk.org
- [2013.11.26 21:47:26 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\Glarysoft
- [2014.09.10 21:59:10 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\GmailNotifierPro
- [2014.06.18 22:46:46 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\iFunbox_UserCache
- [2013.10.23 20:31:35 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\IsolatedStorage
- [2013.12.20 15:19:05 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\lonesock software
- [2013.10.30 15:48:51 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\OpenOffice.org
- [2013.07.11 23:30:23 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\redsn0w
- [2014.05.24 10:44:52 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\TeamViewer
- [2014.03.28 20:05:54 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\Thunderbird
- [2014.04.20 15:56:44 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\TomTom
- [2013.10.02 12:43:45 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\TuneUp Software
- [2014.05.02 21:46:59 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\uTorrent
- [2014.09.15 19:10:09 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\ViberPC
- [2014.09.15 22:21:41 | 000,000,000 | ---D | M] -- C:\Users\Denis\AppData\Roaming\WebExtend
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Custom Scans ==========[/color]
- [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
- [2014.09.19 22:46:57 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
- [2012.07.26 05:44:30 | 000,398,156 | RHS- | M] () -- C:\bootmgr
- [2012.06.02 16:30:55 | 000,000,001 | -HS- | M] () -- C:\BOOTNXT
- [2014.04.17 20:29:02 | 000,203,316 | ---- | M] () -- C:\grldr.bak
- [2014.09.12 19:39:11 | 642,707,455 | -HS- | M] () -- C:\hiberfil.sys
- [2014.09.12 19:39:13 | 1006,632,960 | -HS- | M] () -- C:\pagefile.sys
- [2014.09.12 19:39:13 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
- [2014.04.17 20:29:30 | 000,000,003 | RHS- | M] () -- C:\win7ldr
- [2013.12.09 19:12:27 | 000,007,452 | ---- | M] () -- C:\zoek-results.log
- [color=#A23BEC]< %systemroot%\Fonts\*.com >[/color]
- [2013.01.29 16:37:54 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
- [2013.01.29 16:37:54 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
- [2013.01.29 16:37:54 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
- [2013.01.29 16:37:54 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
- [color=#A23BEC]< %systemroot%\Fonts\*.dll >[/color]
- [color=#A23BEC]< %systemroot%\Fonts\*.ini >[/color]
- [2012.07.26 10:11:41 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
- [color=#A23BEC]< %systemroot%\Fonts\*.ini2 >[/color]
- [color=#A23BEC]< %systemroot%\Fonts\*.exe >[/color]
- [color=#A23BEC]< %systemroot%\system32\spool\prtprocs\w32x86\*.* >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.bak1 >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.ini >[/color]
- [color=#A23BEC]< %systemroot%\system32\*.jpg >[/color]
- [color=#A23BEC]< %systemroot%\*.jpg >[/color]
- [color=#A23BEC]< %systemroot%\*.png >[/color]
- [color=#A23BEC]< %systemroot%\*.scr >[/color]
- [2014.08.02 10:25:00 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
- [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
- [color=#A23BEC]< %systemroot%\*._sy >[/color]
- [color=#A23BEC]< %APPDATA%\Adobe\Update\*.* >[/color]
- [color=#A23BEC]< %ALLUSERSPROFILE%\Favorites\*.* >[/color]
- [color=#A23BEC]< %APPDATA%\Microsoft\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
- [2012.07.26 10:11:35 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
- [color=#A23BEC]< %APPDATA%\Update\*.* >[/color]
- [color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
- [color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\bak. /s >[/color]
- [color=#A23BEC]< %systemroot%\system32\bak. /s >[/color]
- [color=#A23BEC]< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >[/color]
- [color=#A23BEC]< %systemroot%\system32\config\systemprofile\*.dat /x >[/color]
- [color=#A23BEC]< %systemroot%\*.config >[/color]
- [color=#A23BEC]< %systemroot%\system32\*.db >[/color]
- [color=#A23BEC]< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >[/color]
- [2013.01.29 12:24:51 | 000,000,223 | -HS- | M] () -- C:\Users\Denis\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
- [color=#A23BEC]< %USERPROFILE%\Desktop\*.exe >[/color]
- [2014.09.21 22:15:45 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Denis\Desktop\OTL.exe
- [color=#A23BEC]< %PROGRAMFILES%\Common Files\*.* >[/color]
- [color=#A23BEC]< %systemroot%\*.src >[/color]
- [color=#A23BEC]< %systemroot%\install\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\DLL\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\HelpFiles\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\rundll\*.* >[/color]
- [color=#A23BEC]< %systemroot%\winn32\*.* >[/color]
- [color=#A23BEC]< %systemroot%\Java\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\test\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\Rundll32\*.* >[/color]
- [color=#A23BEC]< %systemroot%\AppPatch\Custom\*.* >[/color]
- [color=#A23BEC]< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.tmp >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.dat >[/color]
- [color=#A23BEC]< %USERPROFILE%\My Documents\*.exe >[/color]
- [color=#A23BEC]< %USERPROFILE%\*.exe >[/color]
- [color=#A23BEC]< %systemroot%\ADDINS\*.* >[/color]
- [2012.06.02 16:31:36 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
- [color=#A23BEC]< %systemroot%\assembly\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Config\*.* >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\SECURITY\Database\*.sdb /x >[/color]
- [color=#A23BEC]< %systemroot%\SYSTEM\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Web\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Driver Cache\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Mozilla Firefox\0*.exe >[/color]
- [color=#A23BEC]< %ProgramFiles%\Microsoft Common\*.* >[/color]
- [color=#A23BEC]< %ProgramFiles%\TinyProxy. >[/color]
- [color=#A23BEC]< %USERPROFILE%\Favorites\*.url /x >[/color]
- [2014.05.17 09:01:50 | 000,000,402 | -HS- | M] () -- C:\Users\Denis\Favorites\desktop.ini
- [color=#A23BEC]< %systemroot%\System32\Wbem\*.exe >[/color]
- [2012.07.26 05:20:50 | 000,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\mofcomp.exe
- [2012.07.26 05:21:01 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WinMgmt.exe
- [2012.07.26 05:21:02 | 000,124,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIADAP.exe
- [2012.07.26 05:21:02 | 000,385,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIC.exe
- [2013.02.02 10:40:58 | 000,375,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WmiPrvSE.exe
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >[/color]
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >[/color]
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement