Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 18.4.2012 9:19:26 - Run 1
- OTL by OldTimer - Version 3.2.40.0 Folder = C:\Documents and Settings\Administrator\Desktop
- Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
- Internet Explorer (Version = 7.0.5730.13)
- Locale: 0000141A | Country: Bosnia and Herzegovina | Language: BSB | Date Format: d.M.yyyy
- 1023,47 Mb Total Physical Memory | 391,26 Mb Available Physical Memory | 38,23% Memory free
- 2,40 Gb Paging File | 1,84 Gb Available in Paging File | 76,49% Paging File free
- Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
- Drive C: | 39,06 Gb Total Space | 19,38 Gb Free Space | 49,61% Space Free | Partition Type: NTFS
- Drive D: | 35,46 Gb Total Space | 8,01 Gb Free Space | 22,59% Space Free | Partition Type: NTFS
- Computer Name: MIRZA | User Name: Administrator | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Quick Scan
- Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2012.04.18 09:15:25 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
- PRC - [2012.03.18 19:27:29 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
- PRC - [2012.02.19 19:02:03 | 000,185,896 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
- PRC - [2012.01.12 12:50:10 | 000,920,576 | ---- | M] () -- C:\Program Files\WGA Remover\wgaremover.exe
- PRC - [2009.10.07 10:16:50 | 000,472,280 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
- PRC - [2009.10.07 10:15:42 | 001,461,080 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
- PRC - [2008.04.14 12:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
- PRC - [2007.04.05 10:29:28 | 000,208,896 | ---- | M] (UASSOFT.COM) -- C:\Program Files\Mouse Driver\KMWDSrv.exe
- PRC - [2007.04.04 11:30:40 | 000,327,680 | ---- | M] (UASSOFT.COM) -- C:\Program Files\Mouse Driver\KMProcess.exe
- PRC - [2007.03.28 00:38:48 | 000,397,312 | ---- | M] (UASSOFT.COM) -- C:\Program Files\Mouse Driver\KMCONFIG.exe
- PRC - [2007.03.06 14:51:14 | 000,212,992 | ---- | M] (UASSOFT.COM) -- C:\Program Files\Mouse Driver\StartAutorun.exe
- PRC - [2006.05.03 11:48:46 | 000,307,200 | ---- | M] (ta2027) -- C:\Program Files\Styler\Styler.exe
- PRC - [2004.09.19 20:27:44 | 000,065,536 | ---- | M] () -- C:\Program Files\LClock\LClock.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2012.04.17 18:55:22 | 000,085,288 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qbreaqmx.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\RadioWMPCoreGecko11.dll
- MOD - [2012.04.13 22:57:26 | 008,797,344 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll
- MOD - [2012.03.18 19:27:28 | 001,969,080 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
- MOD - [2012.01.30 18:00:53 | 011,808,768 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\14634aa365ed184dafe26b8a07da62d3\System.Web.ni.dll
- MOD - [2012.01.30 17:59:41 | 000,962,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\91c6e72142859b4cb386a7e1c5394108\System.Configuration.ni.dll
- MOD - [2012.01.30 17:58:50 | 000,026,624 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\6bdd97a6a4ccf74b8a794ab6235afb0b\Accessibility.ni.dll
- MOD - [2012.01.30 17:56:10 | 005,640,192 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\0711a6c796f04f409affb31ad4b3cbf0\System.Xml.ni.dll
- MOD - [2012.01.30 17:56:00 | 013,107,200 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f0425ed1a6aca542b7ddcad36f2578f4\System.Windows.Forms.ni.dll
- MOD - [2012.01.30 17:55:33 | 001,626,112 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\993919d565f078419ba03dd6c83093a3\System.Drawing.ni.dll
- MOD - [2012.01.30 17:55:27 | 008,093,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\7d4c22f0d7294441a81fade328295518\System.ni.dll
- MOD - [2012.01.30 17:54:53 | 011,415,552 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\5c19cb4e7c789b4592b713840a10ddfb\mscorlib.ni.dll
- MOD - [2012.01.30 17:53:39 | 000,299,008 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- MOD - [2012.01.12 12:50:10 | 000,920,576 | ---- | M] () -- C:\Program Files\WGA Remover\wgaremover.exe
- MOD - [2011.12.05 22:45:14 | 000,270,336 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
- MOD - [2010.03.16 13:22:12 | 000,014,848 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll
- MOD - [2008.04.14 12:00:00 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
- MOD - [2008.04.14 12:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
- MOD - [2007.09.20 19:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
- MOD - [2007.03.29 12:17:42 | 000,106,496 | ---- | M] () -- C:\Program Files\Mouse Driver\keydll.dll
- MOD - [2005.05.04 19:12:46 | 000,028,672 | ---- | M] () -- C:\Program Files\Mouse Driver\MouseHook.dll
- MOD - [2005.05.01 13:10:10 | 000,159,744 | ---- | M] () -- C:\Program Files\Styler\UNRAR\unrar.dll
- MOD - [2004.09.19 20:27:44 | 000,065,536 | ---- | M] () -- C:\Program Files\LClock\LClock.exe
- MOD - [2004.09.19 20:27:34 | 000,069,632 | ---- | M] () -- C:\Program Files\LClock\LC.dll
- MOD - [2004.09.19 20:27:30 | 000,081,920 | ---- | M] () -- C:\Program Files\LClock\Calendar.dll
- [color=#E56717]========== Win32 Services (SafeList) ==========[/color]
- SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
- SRV - [2012.04.13 22:57:30 | 000,253,088 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
- SRV - [2012.02.29 08:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
- SRV - [2009.10.07 10:21:14 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
- SRV - [2009.10.07 10:16:50 | 000,472,280 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
- SRV - [2007.04.05 10:29:28 | 000,208,896 | ---- | M] (UASSOFT.COM) [Auto | Running] -- C:\Program Files\Mouse Driver\KMWDSrv.exe -- (KMWDSERVICE)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
- DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
- DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
- DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
- DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
- DRV - [2011.12.20 09:39:28 | 000,100,368 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtihdXP3.sys -- (AtiHDAudioService)
- DRV - [2011.12.06 05:42:18 | 007,490,560 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
- DRV - [2011.08.17 10:56:32 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
- DRV - [2011.08.17 10:56:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
- DRV - [2011.08.17 10:56:26 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
- DRV - [2011.08.17 10:56:22 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
- DRV - [2009.10.07 10:18:36 | 000,035,168 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
- DRV - [2009.10.07 10:12:22 | 000,054,184 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\easdrv.sys -- (easdrv)
- DRV - [2009.10.07 10:11:10 | 000,040,824 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
- DRV - [2009.07.24 08:56:16 | 000,009,472 | ---- | M] (Primax Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NMgamingms.sys -- (NMgamingmsFltr)
- DRV - [2008.04.14 02:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
- DRV - [2008.02.12 05:46:51 | 000,392,704 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
- DRV - [2007.05.14 10:12:28 | 003,526,464 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtHDMI.sys -- (RTHDMIAzAudService)
- DRV - [2007.01.30 19:12:06 | 000,045,568 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
- DRV - [2006.07.19 13:29:08 | 000,027,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidKE.Sys -- (LHidKE)
- DRV - [2006.07.19 13:28:56 | 000,071,936 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouKE.Sys -- (LMouKE)
- DRV - [2006.07.19 13:28:04 | 000,036,736 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidUsbK.sys -- (LHidUsbK)
- DRV - [2006.07.19 13:27:26 | 000,013,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
- DRV - [2004.09.29 22:36:29 | 000,015,360 | RH-- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NetMotCM.sys -- (ndiscm)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2790392
- IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\G, = http://www.google.com/search?q=%s
- IE - HKCU\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
- IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
- IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2790392
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.defaultthis.engineName: "BitTorrentBar Customized Web Search"
- FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}"
- FF - prefs.js..browser.search.suggest.enabled: false
- FF - prefs.js..browser.search.useDBForOrder: true
- FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT2790392&SearchSource=13"
- FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
- FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=2&q="
- FF - user.js - File not found
- FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll ()
- FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
- FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
- FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
- FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2897: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
- FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2955: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
- FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1675: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
- FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
- FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\Administrator\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
- FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
- FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
- FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.03.18 19:27:31 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.02.19 19:02:32 | 000,000,000 | ---D | M]
- [2012.01.30 17:00:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
- [2012.04.17 20:17:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qbreaqmx.default\extensions
- [2012.04.17 20:17:42 | 000,000,000 | ---D | M] (BitTorrentBar Community Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qbreaqmx.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
- [2012.03.18 19:27:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
- [2012.04.02 17:56:48 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- [2012.03.18 19:27:30 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
- [2012.02.19 05:23:39 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
- [2012.02.19 00:03:34 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
- [2012.02.19 00:03:34 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
- [2012.02.19 00:03:34 | 000,000,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
- [2012.02.19 00:03:34 | 000,000,786 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eudict.xml
- [2012.02.19 00:03:34 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
- [2012.02.19 00:03:34 | 000,001,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-hr.xml
- [color=#E56717]========== Chrome ==========[/color]
- CHR - default_search_provider: Conduit (Enabled)
- CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?q={searchTerms}&hl=en&SelfSearch=1&SearchSource=49&ctid=CT2790392
- CHR - default_search_provider: suggest_url = http://search.conduit.com/
- CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
- CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
- CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\pdf.dll
- CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
- CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll
- CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll
- CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
- CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
- CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
- CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
- CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
- CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
- CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
- CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
- CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
- CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll
- CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
- CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
- CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
- CHR - Extension: YouTube = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
- CHR - Extension: Google pretra\u017Eivanje = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
- CHR - Extension: General Crawler = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel\2.5_0\
- CHR - Extension: Skype Click to Call = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\
- CHR - Extension: BitTorrentBar = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mhfdcmehmjcclgopdodkjdicohagipid\2.3.7.1_0\
- CHR - Extension: Gmail = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
- O1 HOSTS File: ([2012.04.16 12:02:00 | 000,000,833 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
- O1 - Hosts: 127.0.0.1 localhost
- O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
- O1 - Hosts: 127.0.0.1 www.igre123.net
- O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
- O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
- O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O2 - BHO: (Help the General-Search Project) - {CA4520F3-AE13-4FB1-A513-58E23991C86D} - C:\Documents and Settings\Administrator\Application Data\Media Finder\Extensions\gencrawler_gc.dll ()
- O3 - HKLM\..\Toolbar: (StylerToolBar) - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll (StyleFantasist)
- O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
- O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.)
- O4 - HKLM..\Run: [KMCONFIG] C:\Program Files\Mouse Driver\StartAutorun.exe KMConfig.exe File not found
- O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Nero AG)
- O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
- O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
- O4 - HKLM..\Run: [WGA Remover] C:\Program Files\WGA Remover\wgaremover.exe ()
- O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\Administrator\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
- O4 - HKCU..\Run: [LClock] C:\Program Files\LClock\LClock.exe ()
- O4 - HKCU..\Run: [Media Finder] "C:\Program Files\Media Finder\MF.exe" /opentotray File not found
- O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Styler.lnk = C:\Documents and Settings\Administrator\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe ()
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Start_NotifyNewApps = 0
- O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html File not found
- O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1328000885468 (WUWebControl Class)
- O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
- O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
- O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 77.77.192.10 77.78.192.10 94.140.66.194
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9286C6F4-D226-41C1-B4D1-1D95018D1BAC}: DhcpNameServer = 77.77.192.10 77.78.192.10 94.140.66.194
- O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
- O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
- O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
- O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
- O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
- O32 - HKLM CDRom: AutoRun - 1
- O32 - AutoRun File - [2012.01.30 16:06:45 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- NetSvcs: 6to4 - File not found
- NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
- NetSvcs: Ias - File not found
- NetSvcs: Iprip - File not found
- NetSvcs: Irmon - File not found
- NetSvcs: NWCWorkstation - File not found
- NetSvcs: Nwsapagent - File not found
- NetSvcs: WmdmPmSp - File not found
- CREATERESTOREPOINT
- Restore point Set: OTL Restore Point
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2012.04.18 09:14:58 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
- [2012.04.16 14:10:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\Coma
- [2012.04.16 14:04:29 | 000,000,000 | ---D | C] -- C:\Program Files\BitTorrent
- [2012.04.16 14:02:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\BitTorrent
- [2012.04.16 11:47:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\Download
- [2012.04.16 11:47:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Media Finder
- [2012.04.16 11:47:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Media Finder
- [2012.04.14 10:01:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\TeamViewer 7
- [2012.04.10 10:15:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\MSI PM8PM-V
- [2012.04.06 21:37:34 | 000,015,360 | RH-- | C] (Motorola Inc.) -- C:\WINDOWS\System32\drivers\NetMotCM.sys
- [2012.04.06 13:57:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\Mouse Driver
- [2012.04.06 13:57:28 | 000,000,000 | ---D | C] -- C:\Program Files\Mouse Driver
- [2012.04.04 07:29:12 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\Administrative Tools
- [2012.04.02 17:56:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype
- [2012.04.02 17:56:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
- [2012.03.19 18:17:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
- [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2012.04.18 09:15:25 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
- [2012.04.18 09:14:47 | 000,000,069 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\kako napraviti OTL logove - Forum.hr.URL
- [2012.04.18 08:57:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
- [2012.04.18 08:38:00 | 000,001,010 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1993962763-1417001333-500UA.job
- [2012.04.18 07:27:01 | 000,001,030 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1757981266-1993962763-1417001333-500UA.job
- [2012.04.18 06:44:10 | 000,002,261 | ---- | M] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Styler.lnk
- [2012.04.18 06:44:04 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
- [2012.04.18 01:38:00 | 000,000,958 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1993962763-1417001333-500Core.job
- [2012.04.17 10:27:00 | 000,001,008 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1757981266-1993962763-1417001333-500Core.job
- [2012.04.16 14:33:15 | 000,008,192 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
- [2012.04.16 14:04:58 | 000,000,673 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk
- [2012.04.16 14:04:58 | 000,000,655 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\BitTorrent.lnk
- [2012.04.16 12:44:39 | 000,002,349 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Google Chrome.lnk
- [2012.04.16 12:44:39 | 000,002,327 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
- [2012.04.16 12:02:00 | 000,000,833 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
- [2012.04.16 11:34:28 | 000,000,060 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Besplatni DOWNLOAD filmova visoke kvalitete!.URL
- [2012.04.14 17:04:39 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
- [2012.04.14 10:01:14 | 000,000,820 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TeamViewer 7.lnk
- [2012.04.09 08:02:11 | 000,032,931 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Picture 002.jpg
- [2012.04.08 17:09:53 | 000,000,353 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\VEDO POSAO.lnk
- [2012.04.05 16:28:14 | 000,000,127 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Printer Centar Diskusije • View topic - pomoc - CANON NP-7161 kopir aparat izbacuje crni list.URL
- [2012.04.02 17:56:24 | 000,001,878 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
- [2012.03.31 07:39:15 | 000,000,125 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Nogomet Austrija Erste Liga tipovi.URL
- [2012.03.30 08:09:47 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
- [2012.03.30 00:37:35 | 000,395,530 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
- [2012.03.30 00:37:35 | 000,059,644 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
- [2012.03.19 23:31:17 | 000,074,240 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Diploma za Ajlich.pub
- [2012.03.19 18:18:15 | 000,000,211 | -HS- | M] () -- C:\boot.ini
- [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2012.04.18 09:14:47 | 000,000,069 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\kako napraviti OTL logove - Forum.hr.URL
- [2012.04.16 14:04:58 | 000,000,673 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk
- [2012.04.16 14:04:57 | 000,000,655 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\BitTorrent.lnk
- [2012.04.16 11:34:28 | 000,000,060 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Besplatni DOWNLOAD filmova visoke kvalitete!.URL
- [2012.04.14 10:01:14 | 000,000,820 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TeamViewer 7.lnk
- [2012.04.09 08:02:11 | 000,032,931 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Picture 002.jpg
- [2012.04.08 17:09:53 | 000,000,353 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\VEDO POSAO.lnk
- [2012.04.05 16:28:14 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Printer Centar Diskusije • View topic - pomoc - CANON NP-7161 kopir aparat izbacuje crni list.URL
- [2012.04.02 17:56:24 | 000,001,878 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
- [2012.03.31 07:38:30 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Nogomet Austrija Erste Liga tipovi.URL
- [2012.03.29 19:41:34 | 000,000,830 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
- [2012.03.19 23:31:17 | 000,074,240 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Diploma za Ajlich.pub
- [2012.03.16 14:11:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
- [2012.03.15 14:29:54 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
- [2012.03.09 17:48:47 | 000,000,238 | ---- | C] () -- C:\WINDOWS\mafosav.INI
- [2012.03.07 13:03:17 | 000,000,641 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
- [2012.03.07 12:57:39 | 000,008,192 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
- [2012.03.07 12:49:42 | 000,000,486 | ---- | C] () -- C:\WINDOWS\Tcsofla.INI
- [2012.01.30 19:01:22 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
- [2012.01.30 17:00:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
- [2012.01.30 16:57:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
- [2012.01.30 16:52:26 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
- [2012.01.30 16:42:57 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
- [2012.01.30 16:42:57 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
- [2012.01.30 16:42:57 | 000,608,507 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
- [2012.01.30 16:42:57 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
- [2012.01.30 16:42:12 | 000,263,024 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
- [2012.01.30 16:24:15 | 000,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
- [2012.01.30 16:24:11 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
- [2012.01.30 16:24:11 | 000,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
- [2012.01.30 16:24:11 | 000,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
- [2012.01.30 16:24:10 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
- [2012.01.30 16:09:52 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
- [2012.01.30 16:02:48 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
- [2012.01.02 22:20:56 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
- [2011.12.05 23:04:00 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\OpenVideo.dll
- [2011.12.05 23:03:52 | 000,054,784 | ---- | C] () -- C:\WINDOWS\System32\OVDecode.dll
- [color=#E56717]========== LOP Check ==========[/color]
- [2012.04.16 14:32:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\BitTorrent
- [2012.02.12 03:48:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\com.adobe.downloadassistant.AdobeDownloadAssistant
- [2012.02.20 13:17:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Hotdog Hotshot
- [2012.02.10 03:44:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\MB-Ruler
- [2012.04.16 11:58:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Media Finder
- [2012.02.25 12:28:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\PoivY
- [2012.01.06 08:06:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Styler
- [2012.04.14 10:01:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\TeamViewer
- [2012.02.28 01:44:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\TS3Client
- [2012.02.23 21:46:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\YoudaGames
- [2012.04.08 17:16:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Big Fish Games
- [2012.02.09 13:38:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
- [2012.03.17 03:37:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
- [2012.02.20 16:32:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
- [2012.02.23 19:02:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Youdagames
- [2012.04.17 10:27:00 | 000,001,008 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1757981266-1993962763-1417001333-500Core.job
- [2012.04.18 07:27:01 | 000,001,030 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1757981266-1993962763-1417001333-500UA.job
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Custom Scans ==========[/color]
- [color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]
- [2009.01.30 14:43:56 | 000,323,169 | ---- | M] () -- C:\DPsFnshr.exe
- [color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
- [2008.04.14 12:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
- [2008.04.14 02:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\AGP440.SYS
- [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
- [2008.04.14 12:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
- [2008.04.14 12:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
- [color=#A23BEC]< MD5 for: EVENTLOG.DLL >[/color]
- [2008.04.14 12:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll
- [2008.04.14 12:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
- [color=#A23BEC]< MD5 for: IASTOR.SYS >[/color]
- [2008.09.12 19:32:56 | 000,327,192 | ---- | M] (Intel Corporation) MD5=8EF427C54497C5F8A7A645990E4278C7 -- C:\D\M\I4\IaStor.sys
- [2007.09.29 23:03:12 | 000,308,248 | ---- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F -- C:\D\M\I3\IASTOR.SYS
- [color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color]
- [2008.04.14 12:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll
- [2008.04.14 12:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
- [color=#A23BEC]< MD5 for: NVATABUS.SYS >[/color]
- [2006.02.26 17:21:18 | 000,089,856 | ---- | M] (NVIDIA Corporation) MD5=83F0275A21D9772B51CEF57E35AFAE61 -- C:\D\M\NV123\NVATABUS.sys
- [2006.04.24 17:52:28 | 000,100,736 | ---- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 -- C:\D\M\NVTM\NVATABUS.sys
- [color=#A23BEC]< MD5 for: NVGTS.SYS >[/color]
- [2007.07.27 22:16:02 | 000,105,984 | ---- | M] (NVIDIA Corporation) MD5=4BC4BAAED05161E0D331627E90A10745 -- C:\D\M\NV6\nvgts.sys
- [color=#A23BEC]< MD5 for: NVRD32.SYS >[/color]
- [2007.07.27 22:15:56 | 000,116,736 | ---- | M] (NVIDIA Corporation) MD5=77AC69AC4F07BD9D29528B8FCC71FB49 -- C:\D\M\NV6\nvrd32.sys
- [color=#A23BEC]< MD5 for: SCECLI.DLL >[/color]
- [2008.04.14 12:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll
- [2008.04.14 12:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
- [color=#A23BEC]< MD5 for: VIAMRAID.SYS >[/color]
- [2008.07.10 03:19:02 | 000,117,248 | ---- | M] (VIA Technologies inc,.ltd) MD5=00046AA2E396EDC2238556E740A8E5AF -- C:\D\M\V1\viamraid.sys
- [color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
- [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
- [1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
- [color=#E56717]========== Alternate Data Streams ==========[/color]
- @Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:04BB186B
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement