Advertisement
Guest User

Untitled

a guest
Oct 21st, 2015
24
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 49.42 KB | None | 0 0
  1. OTL logfile created on: 22.10.2015. 0:27:33 - Run 1
  2. OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\VIP\Desktop
  3. 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
  4. Internet Explorer (Version = 8.0.7601.17514)
  5. Locale: 0000041a | Country: Hrvatska | Language: HRV | Date Format: d.M.yyyy.
  6.  
  7. 4,00 Gb Total Physical Memory | 2,25 Gb Available Physical Memory | 56,31% Memory free
  8. 7,99 Gb Paging File | 6,21 Gb Available in Paging File | 77,69% Paging File free
  9. Paging file location(s): ?:\pagefile.sys [binary data]
  10.  
  11. %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
  12. Drive C: | 97,66 Gb Total Space | 73,96 Gb Free Space | 75,74% Space Free | Partition Type: NTFS
  13. Drive D: | 135,13 Gb Total Space | 108,97 Gb Free Space | 80,64% Space Free | Partition Type: NTFS
  14.  
  15. Computer Name: VIP-PC | User Name: VIP | Logged in as Administrator.
  16. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
  17. Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
  18.  
  19. [color=#E56717]========== Processes (SafeList) ==========[/color]
  20.  
  21. PRC - [2015.10.22 00:25:11 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\VIP\Desktop\OTL.exe
  22. PRC - [2015.10.18 02:15:45 | 003,426,504 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_226.exe
  23. PRC - [2015.10.15 03:14:23 | 000,377,000 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
  24. PRC - [2015.03.12 01:54:32 | 000,066,816 | ---- | M] (Tweaking.com) -- C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
  25.  
  26.  
  27. [color=#E56717]========== Modules (No Company Name) ==========[/color]
  28.  
  29. MOD - [2015.10.18 02:15:45 | 017,599,688 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll
  30. MOD - [2010.01.21 01:34:10 | 008,793,952 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
  31. MOD - [2010.01.09 20:18:18 | 004,254,560 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
  32.  
  33.  
  34. [color=#E56717]========== Services (SafeList) ==========[/color]
  35.  
  36. SRV:[b]64bit:[/b] - [2015.10.09 16:30:52 | 002,505,472 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
  37. SRV:[b]64bit:[/b] - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
  38. SRV:[b]64bit:[/b] - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
  39. SRV - [2015.10.17 21:32:49 | 000,136,048 | ---- | M] (Dropbox, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe -- (dbupdatem)
  40. SRV - [2015.10.17 21:32:49 | 000,136,048 | ---- | M] (Dropbox, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe -- (dbupdate)
  41. SRV - [2015.10.15 03:14:40 | 000,147,624 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
  42. SRV - [2015.10.05 09:48:46 | 001,135,416 | ---- | M] (Malwarebytes) [Disabled | Stopped] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
  43. SRV - [2015.07.11 05:41:02 | 000,024,888 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- c:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe -- (HPSupportSolutionsFrameworkService)
  44. SRV - [2015.07.09 13:14:04 | 000,327,296 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
  45. SRV - [2015.06.19 23:14:56 | 000,104,120 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
  46. SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
  47.  
  48.  
  49. [color=#E56717]========== Driver Services (SafeList) ==========[/color]
  50.  
  51. DRV:[b]64bit:[/b] - [2015.10.18 03:04:28 | 002,978,296 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
  52. DRV:[b]64bit:[/b] - [2015.10.05 09:50:18 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
  53. DRV:[b]64bit:[/b] - [2015.10.05 09:50:06 | 000,025,816 | ---- | M] (Malwarebytes) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
  54. DRV:[b]64bit:[/b] - [2015.07.30 12:41:36 | 000,264,040 | ---- | M] (ESET) [File_System | System | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
  55. DRV:[b]64bit:[/b] - [2015.07.30 12:41:36 | 000,186,784 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
  56. DRV:[b]64bit:[/b] - [2015.07.30 12:41:36 | 000,170,792 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
  57. DRV:[b]64bit:[/b] - [2010.11.21 05:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
  58. DRV:[b]64bit:[/b] - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
  59. DRV:[b]64bit:[/b] - [2010.11.21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
  60. DRV:[b]64bit:[/b] - [2010.11.21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
  61. DRV:[b]64bit:[/b] - [2010.11.21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
  62. DRV:[b]64bit:[/b] - [2010.11.21 05:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
  63. DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
  64. DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
  65. DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
  66. DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
  67. DRV:[b]64bit:[/b] - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
  68. DRV:[b]64bit:[/b] - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
  69. DRV:[b]64bit:[/b] - [2009.07.14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
  70. DRV:[b]64bit:[/b] - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
  71. DRV:[b]64bit:[/b] - [2009.07.13 23:59:33 | 005,020,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
  72. DRV:[b]64bit:[/b] - [2009.06.10 23:01:06 | 001,146,880 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
  73. DRV:[b]64bit:[/b] - [2009.06.10 22:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
  74. DRV:[b]64bit:[/b] - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
  75. DRV:[b]64bit:[/b] - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
  76. DRV:[b]64bit:[/b] - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
  77. DRV:[b]64bit:[/b] - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
  78. DRV:[b]64bit:[/b] - [2009.02.24 18:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mcdbus.sys -- (mcdbus)
  79. DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
  80. DRV - [2009.02.24 18:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\mcdbus.sys -- (mcdbus)
  81.  
  82.  
  83. [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
  84.  
  85.  
  86. [color=#E56717]========== Internet Explorer ==========[/color]
  87.  
  88. IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  89. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  90. IE:[b]64bit:[/b] - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  91. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
  92. IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  93. IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  94.  
  95. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
  96. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = hr
  97. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 36 7E 24 67 10 09 D1 01 [binary data]
  98. IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  99. IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
  100. IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  101.  
  102. [color=#E56717]========== FireFox ==========[/color]
  103.  
  104. FF - prefs.js..browser.search.countryCode: "HR"
  105. FF - prefs.js..browser.search.region: "HR"
  106. FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:41.0.2
  107. FF - user.js - File not found
  108.  
  109. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll File not found
  110. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.60.2: C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
  111. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.60.2: C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll (Oracle Corporation)
  112. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
  113. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll ( Microsoft Corporation)
  114. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  115. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
  116. FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll ()
  117. FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1220162.dll (Adobe Systems, Inc.)
  118. FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
  119. FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
  120. FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
  121. FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
  122. FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.60.2: C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
  123. FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.60.2: C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll (Oracle Corporation)
  124. FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
  125. FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll ( Microsoft Corporation)
  126. FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
  127. FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
  128.  
  129. FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 41.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
  130. FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 41.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
  131.  
  132. [2015.10.17 21:54:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\VIP\AppData\Roaming\Mozilla\Extensions
  133. [2015.10.17 22:08:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\VIP\AppData\Roaming\Mozilla\Firefox\Profiles\s4siomwd.default\extensions
  134. [2015.10.17 21:54:58 | 000,120,696 | ---- | M] () (No name found) -- C:\Users\VIP\AppData\Roaming\Mozilla\Firefox\Profiles\s4siomwd.default\extensions\elemhidehelper@adblockplus.org.xpi
  135. [2015.10.17 21:54:42 | 000,962,762 | ---- | M] () (No name found) -- C:\Users\VIP\AppData\Roaming\Mozilla\Firefox\Profiles\s4siomwd.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
  136. [2015.10.17 21:25:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
  137. [2015.10.17 21:25:59 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
  138.  
  139. O1 HOSTS File: ([2015.10.20 23:52:03 | 000,000,855 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
  140. O1 - Hosts: 127.0.0.1 localhost
  141. O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll (Oracle Corporation)
  142. O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll (Oracle Corporation)
  143. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll (Oracle Corporation)
  144. O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll (Oracle Corporation)
  145. O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
  146. O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
  147. O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
  148. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
  149. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
  150. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
  151. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
  152. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
  153. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
  154. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
  155. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: verbosestatus = 1
  156. O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
  157. O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
  158. O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
  159. O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Microsoft)
  160. O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Microsoft)
  161. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
  162. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
  163. O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
  164. O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
  165. O13[b]64bit:[/b] - gopher Prefix: missing
  166. O13 - gopher Prefix: missing
  167. O15:[b]64bit:[/b] - ..Trusted Domains: eset.com ([help] http in Trusted sites)
  168. O15 - HKLM\..Trusted Domains: eset.com ([help] http in Trusted sites)
  169. O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://test.catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1445118636217 (MUCatalogWebControl Class)
  170. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.5.1
  171. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6683622C-4037-451B-9CE3-F052E65B1BB9}: DhcpNameServer = 192.168.5.1
  172. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9E11D69C-1AE0-46F8-8BDF-D28D911936DA}: NameServer = 193.198.184.130 193.198.184.140
  173. O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
  174. O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
  175. O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\System32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
  176. O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
  177. O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
  178. O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  179. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  180. O32 - HKLM CDRom: AutoRun - 1
  181. O33 - MountPoints2\{db00cb8d-7528-11e5-bf70-00226457cfd9}\Shell - "" = AutoRun
  182. O33 - MountPoints2\{db00cb8d-7528-11e5-bf70-00226457cfd9}\Shell\AutoRun\command - "" = F:\Windows\CHECK\DriveNavigator.exe
  183. O34 - HKLM BootExecute: (autocheck autochk *)
  184. O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
  185. O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
  186. O35 - HKLM\..comfile [open] -- "%1" %*
  187. O35 - HKLM\..exefile [open] -- "%1" %*
  188. O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
  189. O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
  190. O37 - HKLM\...com [@ = comfile] -- "%1" %*
  191. O37 - HKLM\...exe [@ = exefile] -- "%1" %*
  192. O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
  193. O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
  194. O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
  195.  
  196. NetSvcs:[b]64bit:[/b] AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
  197.  
  198. Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
  199. Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
  200. Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
  201.  
  202. CREATERESTOREPOINT
  203. Restore point Set: OTL Restore Point
  204.  
  205. [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
  206.  
  207. [2015.10.22 00:25:08 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\VIP\Desktop\OTL.exe
  208. [2015.10.21 00:00:45 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
  209. [2015.10.21 00:00:42 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\catroot2
  210. [2015.10.20 23:32:28 | 000,000,000 | ---D | C] -- C:\RegBackup
  211. [2015.10.20 21:30:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
  212. [2015.10.20 21:29:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tweaking.com
  213. [2015.10.20 17:13:20 | 000,000,000 | R--D | C] -- C:\Users\VIP\Documents\Scanned Documents
  214. [2015.10.20 17:13:20 | 000,000,000 | ---D | C] -- C:\Users\VIP\Documents\Fax
  215. [2015.10.18 23:27:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Auslogics
  216. [2015.10.18 22:57:48 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\MPC-HC
  217. [2015.10.18 06:44:47 | 000,000,000 | ---D | C] -- C:\Windows\Panther
  218. [2015.10.18 03:04:35 | 000,000,000 | ---D | C] -- C:\Program Files\Broadcom
  219. [2015.10.18 02:57:39 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\Hewlett-Packard
  220. [2015.10.18 02:57:34 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\Hewlett-Packard
  221. [2015.10.18 02:57:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
  222. [2015.10.18 02:54:45 | 000,000,000 | ---D | C] -- C:\System.sav
  223. [2015.10.18 02:54:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Hewlett-Packard
  224. [2015.10.18 02:54:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\InstallShield Installation Information
  225. [2015.10.18 02:53:37 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\hpqLog
  226. [2015.10.18 02:53:18 | 000,000,000 | ---D | C] -- C:\ProgramData\{C6FA530F-BB98-4D9F-BA00-45FD0698077C}
  227. [2015.10.18 02:52:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hewlett-Packard
  228. [2015.10.18 02:52:33 | 000,000,000 | ---D | C] -- C:\swsetup
  229. [2015.10.18 02:48:28 | 000,000,000 | ---D | C] -- C:\Windows\pss
  230. [2015.10.18 02:37:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
  231. [2015.10.18 02:37:54 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
  232. [2015.10.18 02:37:52 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
  233. [2015.10.18 02:15:55 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\Macromedia
  234. [2015.10.18 02:15:55 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\Macromedia
  235. [2015.10.18 02:15:55 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\Adobe
  236. [2015.10.18 02:15:44 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
  237. [2015.10.18 02:15:35 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
  238. [2015.10.18 02:15:08 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\Adobe
  239. [2015.10.18 02:13:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
  240. [2015.10.18 02:13:43 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
  241. [2015.10.18 02:05:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
  242. [2015.10.18 02:05:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
  243. [2015.10.18 02:05:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
  244. [2015.10.18 02:05:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
  245. [2015.10.18 02:04:35 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
  246. [2015.10.18 02:04:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework
  247. [2015.10.18 02:04:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
  248. [2015.10.18 02:02:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
  249. [2015.10.18 02:01:47 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
  250. [2015.10.18 02:01:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
  251. [2015.10.18 02:01:27 | 000,000,000 | ---D | C] -- C:\Windows\SHELLNEW
  252. [2015.10.18 02:01:16 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\Microsoft Help
  253. [2015.10.18 02:01:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
  254. [2015.10.18 02:01:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
  255. [2015.10.18 02:01:06 | 000,000,000 | RH-D | C] -- C:\MSOCache
  256. [2015.10.18 01:58:40 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MagicDisc
  257. [2015.10.18 01:58:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicDisc
  258. [2015.10.18 01:58:23 | 000,255,552 | ---- | C] (MagicISO, Inc.) -- C:\Windows\SysWow64\drivers\mcdbus.sys
  259. [2015.10.18 01:58:23 | 000,255,552 | ---- | C] (MagicISO, Inc.) -- C:\Windows\SysNative\drivers\mcdbus.sys
  260. [2015.10.18 01:58:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MagicDisc
  261. [2015.10.18 01:08:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
  262. [2015.10.17 22:51:16 | 000,000,000 | ---D | C] -- C:\Windows\CheckSur
  263. [2015.10.17 21:56:44 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\WindowsUpdate
  264. [2015.10.17 21:54:05 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\Mozilla
  265. [2015.10.17 21:54:05 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\Mozilla
  266. [2015.10.17 21:52:47 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\Skype
  267. [2015.10.17 21:52:40 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\Skype
  268. [2015.10.17 21:51:44 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\qBittorrent
  269. [2015.10.17 21:51:37 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\qBittorrent
  270. [2015.10.17 21:43:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
  271. [2015.10.17 21:43:10 | 000,109,272 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
  272. [2015.10.17 21:43:10 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
  273. [2015.10.17 21:43:10 | 000,025,816 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbam.sys
  274. [2015.10.17 21:43:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
  275. [2015.10.17 21:43:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
  276. [2015.10.17 21:40:43 | 000,000,000 | ---D | C] -- C:\Program Files\paint.net
  277. [2015.10.17 21:40:24 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\paint.net
  278. [2015.10.17 21:40:13 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\Canneverbe Limited
  279. [2015.10.17 21:40:12 | 000,000,000 | ---D | C] -- C:\Program Files\CDBurnerXP
  280. [2015.10.17 21:36:47 | 000,000,000 | ---D | C] -- C:\Windows\Migration
  281. [2015.10.17 21:36:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
  282. [2015.10.17 21:34:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
  283. [2015.10.17 21:33:08 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\Dropbox
  284. [2015.10.17 21:32:49 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\Dropbox
  285. [2015.10.17 21:32:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Dropbox
  286. [2015.10.17 21:32:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dropbox
  287. [2015.10.17 21:32:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
  288. [2015.10.17 21:32:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
  289. [2015.10.17 21:32:03 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
  290. [2015.10.17 21:31:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
  291. [2015.10.17 21:31:51 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\Foxit Software
  292. [2015.10.17 21:31:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
  293. [2015.10.17 21:31:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Foxit Software
  294. [2015.10.17 21:30:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
  295. [2015.10.17 21:30:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\K-Lite Codec Pack
  296. [2015.10.17 21:30:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
  297. [2015.10.17 21:30:27 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
  298. [2015.10.17 21:30:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
  299. [2015.10.17 21:30:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\qBittorrent
  300. [2015.10.17 21:30:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
  301. [2015.10.17 21:30:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Auslogics
  302. [2015.10.17 21:29:59 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\Programs
  303. [2015.10.17 21:29:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
  304. [2015.10.17 21:29:56 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
  305. [2015.10.17 21:29:49 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Adobe
  306. [2015.10.17 21:28:59 | 000,000,000 | ---D | C] -- C:\Program Files\Java
  307. [2015.10.17 21:28:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
  308. [2015.10.17 21:28:07 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\Sun
  309. [2015.10.17 21:28:07 | 000,000,000 | ---D | C] -- C:\Users\VIP\.oracle_jre_usage
  310. [2015.10.17 21:28:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
  311. [2015.10.17 21:27:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
  312. [2015.10.17 21:27:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
  313. [2015.10.17 21:27:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
  314. [2015.10.17 21:26:17 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
  315. [2015.10.17 21:26:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
  316. [2015.10.17 21:26:07 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
  317. [2015.10.17 21:26:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
  318. [2015.10.17 21:25:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
  319. [2015.10.17 21:08:06 | 000,000,000 | R--D | C] -- C:\Users\VIP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
  320. [2015.10.17 21:08:06 | 000,000,000 | R--D | C] -- C:\Users\VIP\Searches
  321. [2015.10.17 21:08:06 | 000,000,000 | R--D | C] -- C:\Users\VIP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
  322. [2015.10.17 21:08:05 | 000,000,000 | -H-D | C] -- C:\Users\VIP\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
  323. [2015.10.17 21:07:55 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\Identities
  324. [2015.10.17 21:07:51 | 000,000,000 | R--D | C] -- C:\Users\VIP\Contacts
  325. [2015.10.17 21:07:49 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\VirtualStore
  326. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\AppData\Local\Temporary Internet Files
  327. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\Templates
  328. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\Start Menu
  329. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\SendTo
  330. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\Recent
  331. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\PrintHood
  332. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\NetHood
  333. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\Documents\My Videos
  334. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\Documents\My Pictures
  335. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\Documents\My Music
  336. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\My Documents
  337. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\Local Settings
  338. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\AppData\Local\History
  339. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\Cookies
  340. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\Application Data
  341. [2015.10.17 21:07:27 | 000,000,000 | -HSD | C] -- C:\Users\VIP\AppData\Local\Application Data
  342. [2015.10.17 21:07:26 | 000,000,000 | --SD | C] -- C:\Users\VIP\AppData\Roaming\Microsoft
  343. [2015.10.17 21:07:26 | 000,000,000 | R--D | C] -- C:\Users\VIP\Videos
  344. [2015.10.17 21:07:26 | 000,000,000 | R--D | C] -- C:\Users\VIP\Saved Games
  345. [2015.10.17 21:07:26 | 000,000,000 | R--D | C] -- C:\Users\VIP\Pictures
  346. [2015.10.17 21:07:26 | 000,000,000 | R--D | C] -- C:\Users\VIP\Music
  347. [2015.10.17 21:07:26 | 000,000,000 | R--D | C] -- C:\Users\VIP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
  348. [2015.10.17 21:07:26 | 000,000,000 | R--D | C] -- C:\Users\VIP\Links
  349. [2015.10.17 21:07:26 | 000,000,000 | R--D | C] -- C:\Users\VIP\Favorites
  350. [2015.10.17 21:07:26 | 000,000,000 | R--D | C] -- C:\Users\VIP\Downloads
  351. [2015.10.17 21:07:26 | 000,000,000 | R--D | C] -- C:\Users\VIP\Documents
  352. [2015.10.17 21:07:26 | 000,000,000 | R--D | C] -- C:\Users\VIP\Desktop
  353. [2015.10.17 21:07:26 | 000,000,000 | R--D | C] -- C:\Users\VIP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
  354. [2015.10.17 21:07:26 | 000,000,000 | -H-D | C] -- C:\Users\VIP\AppData
  355. [2015.10.17 21:07:26 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\Temp
  356. [2015.10.17 21:07:26 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Local\Microsoft
  357. [2015.10.17 21:07:26 | 000,000,000 | ---D | C] -- C:\Users\VIP\AppData\Roaming\Media Center Programs
  358. [2015.10.17 21:06:02 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
  359. [2015.10.17 21:06:02 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
  360. [2015.10.17 20:59:36 | 000,000,000 | -HSD | C] -- C:\Recovery
  361. [2015.10.17 20:46:33 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
  362. [2015.10.17 20:45:46 | 000,000,000 | -HSD | C] -- C:\System Volume Information
  363.  
  364. [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
  365.  
  366. [2015.10.22 00:25:11 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\VIP\Desktop\OTL.exe
  367. [2015.10.22 00:16:06 | 000,778,180 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
  368. [2015.10.22 00:16:06 | 000,648,236 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
  369. [2015.10.22 00:16:06 | 000,116,970 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
  370. [2015.10.22 00:11:54 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
  371. [2015.10.22 00:11:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
  372. [2015.10.22 00:11:40 | 3217,502,208 | -HS- | M] () -- C:\hiberfil.sys
  373. [2015.10.21 22:09:35 | 000,020,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
  374. [2015.10.21 22:09:35 | 000,020,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
  375. [2015.10.21 00:08:11 | 000,000,207 | ---- | M] () -- C:\Windows\tweaking.com-regbackup-VIP-PC-Microsoft-Windows-7-Ultimate-(64-bit).dat
  376. [2015.10.21 00:07:11 | 000,002,286 | ---- | M] () -- C:\Users\Public\Desktop\Tweaking.com - Simple System Tweaker.lnk
  377. [2015.10.21 00:00:10 | 000,419,736 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
  378. [2015.10.20 23:52:03 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
  379. [2015.10.20 23:32:34 | 000,000,207 | ---- | M] () -- C:\Windows\tweaking.com-regbackup-VIP-PC-Windows-7-Ultimate-(64-bit).dat
  380. [2015.10.20 23:09:08 | 000,003,552 | ---- | M] () -- C:\bootsqm.dat
  381. [2015.10.20 21:30:09 | 000,002,163 | ---- | M] () -- C:\Users\VIP\Desktop\Tweaking.com - Windows Repair.lnk
  382. [2015.10.18 21:58:02 | 000,067,739 | ---- | M] () -- C:\Users\VIP\Desktop\Capture.JPG
  383. [2015.10.18 18:30:46 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\DropboxUpdateTaskMachineUA.job
  384. [2015.10.18 18:30:46 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\DropboxUpdateTaskMachineCore.job
  385. [2015.10.18 03:05:24 | 000,998,786 | ---- | M] () -- C:\Windows\SysNative\oem6.inf
  386. [2015.10.18 03:04:29 | 000,006,656 | ---- | M] () -- C:\Windows\SysNative\bcmwlrc.dll
  387. [2015.10.17 22:33:46 | 000,000,653 | ---- | M] () -- C:\Users\VIP\Desktop\VLASTA.lnk
  388. [2015.10.17 21:38:01 | 000,749,824 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
  389. [2015.10.17 21:31:40 | 000,001,379 | ---- | M] () -- C:\Users\VIP\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
  390. [2015.10.17 21:17:00 | 000,001,441 | ---- | M] () -- C:\Users\VIP\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
  391. [2015.10.17 20:49:25 | 000,116,385 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
  392. [2015.10.17 20:49:25 | 000,116,385 | ---- | M] () -- C:\Windows\SysNative\license.rtf
  393. [2015.10.17 20:47:53 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
  394. [2015.10.17 20:47:53 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\atiicdxx.dat
  395. [2015.10.05 09:50:18 | 000,063,704 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
  396. [2015.10.05 09:50:10 | 000,109,272 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
  397. [2015.10.05 09:50:06 | 000,025,816 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbam.sys
  398.  
  399. [color=#E56717]========== Files Created - No Company Name ==========[/color]
  400.  
  401. [2015.10.21 00:08:11 | 000,000,207 | ---- | C] () -- C:\Windows\tweaking.com-regbackup-VIP-PC-Microsoft-Windows-7-Ultimate-(64-bit).dat
  402. [2015.10.21 00:07:11 | 000,002,286 | ---- | C] () -- C:\Users\Public\Desktop\Tweaking.com - Simple System Tweaker.lnk
  403. [2015.10.21 00:00:39 | 000,065,536 | ---- | C] () -- C:\Windows\SysNative\Ikeext.etl
  404. [2015.10.20 23:32:34 | 000,000,207 | ---- | C] () -- C:\Windows\tweaking.com-regbackup-VIP-PC-Windows-7-Ultimate-(64-bit).dat
  405. [2015.10.20 23:09:08 | 000,003,552 | ---- | C] () -- C:\bootsqm.dat
  406. [2015.10.20 21:30:09 | 000,002,163 | ---- | C] () -- C:\Users\VIP\Desktop\Tweaking.com - Windows Repair.lnk
  407. [2015.10.18 21:58:02 | 000,067,739 | ---- | C] () -- C:\Users\VIP\Desktop\Capture.JPG
  408. [2015.10.18 03:05:42 | 000,998,786 | ---- | C] () -- C:\Windows\SysNative\oem6.inf
  409. [2015.10.18 03:04:38 | 000,006,656 | ---- | C] () -- C:\Windows\SysNative\bcmwlrc.dll
  410. [2015.10.17 22:33:48 | 000,000,653 | ---- | C] () -- C:\Users\VIP\Desktop\VLASTA.lnk
  411. [2015.10.17 21:40:53 | 000,001,188 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
  412. [2015.10.17 21:40:13 | 000,001,692 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
  413. [2015.10.17 21:38:01 | 000,749,824 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
  414. [2015.10.17 21:32:56 | 000,000,902 | ---- | C] () -- C:\Windows\tasks\DropboxUpdateTaskMachineUA.job
  415. [2015.10.17 21:32:53 | 000,000,898 | ---- | C] () -- C:\Windows\tasks\DropboxUpdateTaskMachineCore.job
  416. [2015.10.17 21:31:40 | 000,001,379 | ---- | C] () -- C:\Users\VIP\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
  417. [2015.10.17 21:26:04 | 000,001,163 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
  418. [2015.10.17 21:17:00 | 000,001,441 | ---- | C] () -- C:\Users\VIP\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
  419. [2015.10.17 21:08:15 | 000,001,413 | ---- | C] () -- C:\Users\VIP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
  420. [2015.10.17 21:08:09 | 000,001,447 | ---- | C] () -- C:\Users\VIP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
  421. [2015.10.17 21:07:26 | 000,000,290 | ---- | C] () -- C:\Users\VIP\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
  422. [2015.10.17 21:07:26 | 000,000,272 | ---- | C] () -- C:\Users\VIP\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
  423. [2015.10.17 20:49:17 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
  424. [2015.10.17 20:49:07 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
  425. [2015.10.17 20:47:53 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
  426. [2015.10.17 20:47:53 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\atiicdxx.dat
  427. [2015.10.17 20:45:46 | 3217,502,208 | -HS- | C] () -- C:\hiberfil.sys
  428.  
  429. [color=#E56717]========== ZeroAccess Check ==========[/color]
  430.  
  431. [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
  432.  
  433. [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  434.  
  435. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  436.  
  437. [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
  438.  
  439. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
  440.  
  441. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  442. "" = C:\Windows\SysNative\shell32.dll -- [2013.07.26 04:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
  443. "ThreadingModel" = Apartment
  444.  
  445. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  446. "" = %SystemRoot%\system32\shell32.dll -- [2013.07.26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
  447. "ThreadingModel" = Apartment
  448.  
  449. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
  450. "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
  451. "ThreadingModel" = Free
  452.  
  453. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
  454. "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
  455. "ThreadingModel" = Free
  456.  
  457. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
  458. "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
  459. "ThreadingModel" = Both
  460.  
  461. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
  462.  
  463. [color=#E56717]========== LOP Check ==========[/color]
  464.  
  465. [2015.10.17 21:40:13 | 000,000,000 | ---D | M] -- C:\Users\VIP\AppData\Roaming\Canneverbe Limited
  466. [2015.10.17 21:33:08 | 000,000,000 | ---D | M] -- C:\Users\VIP\AppData\Roaming\Dropbox
  467. [2015.10.20 17:04:40 | 000,000,000 | ---D | M] -- C:\Users\VIP\AppData\Roaming\Foxit Software
  468. [2015.10.18 22:57:48 | 000,000,000 | ---D | M] -- C:\Users\VIP\AppData\Roaming\MPC-HC
  469. [2015.10.17 22:02:37 | 000,000,000 | ---D | M] -- C:\Users\VIP\AppData\Roaming\qBittorrent
  470.  
  471. [color=#E56717]========== Purity Check ==========[/color]
  472.  
  473.  
  474.  
  475. [color=#E56717]========== Custom Scans ==========[/color]
  476.  
  477. [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
  478. [2015.10.20 23:09:08 | 000,003,552 | ---- | M] () -- C:\bootsqm.dat
  479. [2015.10.22 00:11:40 | 3217,502,208 | -HS- | M] () -- C:\hiberfil.sys
  480. [2015.10.22 00:11:39 | 4290,002,944 | -HS- | M] () -- C:\pagefile.sys
  481.  
  482. [color=#A23BEC]< %systemroot%\Fonts\*.com >[/color]
  483. [2009.07.14 07:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
  484. [2009.07.14 07:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
  485. [2009.07.14 07:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
  486. [2009.07.14 07:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
  487.  
  488. [color=#A23BEC]< %systemroot%\Fonts\*.dll >[/color]
  489.  
  490. [color=#A23BEC]< %systemroot%\Fonts\*.ini >[/color]
  491. [2009.06.10 22:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
  492.  
  493. [color=#A23BEC]< %systemroot%\Fonts\*.ini2 >[/color]
  494.  
  495. [color=#A23BEC]< %systemroot%\Fonts\*.exe >[/color]
  496.  
  497. [color=#A23BEC]< %systemroot%\system32\spool\prtprocs\w32x86\*.* >[/color]
  498.  
  499. [color=#A23BEC]< %systemroot%\REPAIR\*.bak1 >[/color]
  500.  
  501. [color=#A23BEC]< %systemroot%\REPAIR\*.ini >[/color]
  502.  
  503. [color=#A23BEC]< %systemroot%\system32\*.jpg >[/color]
  504.  
  505. [color=#A23BEC]< %systemroot%\*.jpg >[/color]
  506.  
  507. [color=#A23BEC]< %systemroot%\*.png >[/color]
  508.  
  509. [color=#A23BEC]< %systemroot%\*.scr >[/color]
  510.  
  511. [color=#A23BEC]< %systemroot%\*._sy >[/color]
  512.  
  513. [color=#A23BEC]< %APPDATA%\Adobe\Update\*.* >[/color]
  514.  
  515. [color=#A23BEC]< %ALLUSERSPROFILE%\Favorites\*.* >[/color]
  516.  
  517. [color=#A23BEC]< %APPDATA%\Microsoft\*.* >[/color]
  518.  
  519. [color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
  520. [2009.07.14 06:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
  521.  
  522. [color=#A23BEC]< %APPDATA%\Update\*.* >[/color]
  523.  
  524. [color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
  525.  
  526. [color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color]
  527.  
  528. [color=#A23BEC]< %PROGRAMFILES%\bak. /s >[/color]
  529.  
  530. [color=#A23BEC]< %systemroot%\system32\bak. /s >[/color]
  531.  
  532. [color=#A23BEC]< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >[/color]
  533.  
  534. [color=#A23BEC]< %systemroot%\system32\config\systemprofile\*.dat /x >[/color]
  535.  
  536. [color=#A23BEC]< %systemroot%\*.config >[/color]
  537.  
  538. [color=#A23BEC]< %systemroot%\system32\*.db >[/color]
  539.  
  540. [color=#A23BEC]< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >[/color]
  541. [2015.10.17 21:17:00 | 000,000,221 | -HS- | M] () -- C:\Users\VIP\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
  542.  
  543. [color=#A23BEC]< %USERPROFILE%\Desktop\*.exe >[/color]
  544. [2015.10.22 00:25:11 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\VIP\Desktop\OTL.exe
  545.  
  546. [color=#A23BEC]< %PROGRAMFILES%\Common Files\*.* >[/color]
  547.  
  548. [color=#A23BEC]< %systemroot%\*.src >[/color]
  549.  
  550. [color=#A23BEC]< %systemroot%\install\*.* >[/color]
  551.  
  552. [color=#A23BEC]< %systemroot%\system32\DLL\*.* >[/color]
  553.  
  554. [color=#A23BEC]< %systemroot%\system32\HelpFiles\*.* >[/color]
  555.  
  556. [color=#A23BEC]< %systemroot%\system32\rundll\*.* >[/color]
  557.  
  558. [color=#A23BEC]< %systemroot%\winn32\*.* >[/color]
  559.  
  560. [color=#A23BEC]< %systemroot%\Java\*.* >[/color]
  561.  
  562. [color=#A23BEC]< %systemroot%\system32\test\*.* >[/color]
  563.  
  564. [color=#A23BEC]< %systemroot%\system32\Rundll32\*.* >[/color]
  565.  
  566. [color=#A23BEC]< %systemroot%\AppPatch\Custom\*.* >[/color]
  567.  
  568. [color=#A23BEC]< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >[/color]
  569.  
  570. [color=#A23BEC]< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >[/color]
  571.  
  572. [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.tmp >[/color]
  573.  
  574. [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.dat >[/color]
  575.  
  576. [color=#A23BEC]< %USERPROFILE%\My Documents\*.exe >[/color]
  577.  
  578. [color=#A23BEC]< %USERPROFILE%\*.exe >[/color]
  579.  
  580. [color=#A23BEC]< %systemroot%\ADDINS\*.* >[/color]
  581. [2009.06.10 23:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
  582.  
  583. [color=#A23BEC]< %systemroot%\assembly\*.bak2 >[/color]
  584.  
  585. [color=#A23BEC]< %systemroot%\Config\*.* >[/color]
  586.  
  587. [color=#A23BEC]< %systemroot%\REPAIR\*.bak2 >[/color]
  588.  
  589. [color=#A23BEC]< %systemroot%\SECURITY\Database\*.sdb /x >[/color]
  590.  
  591. [color=#A23BEC]< %systemroot%\SYSTEM\*.bak2 >[/color]
  592.  
  593. [color=#A23BEC]< %systemroot%\Web\*.bak2 >[/color]
  594.  
  595. [color=#A23BEC]< %systemroot%\Driver Cache\*.* >[/color]
  596.  
  597. [color=#A23BEC]< %PROGRAMFILES%\Mozilla Firefox\0*.exe >[/color]
  598.  
  599. [color=#A23BEC]< %ProgramFiles%\Microsoft Common\*.* >[/color]
  600.  
  601. [color=#A23BEC]< %ProgramFiles%\TinyProxy. >[/color]
  602.  
  603. [color=#A23BEC]< %USERPROFILE%\Favorites\*.url /x >[/color]
  604. [2015.10.18 01:44:15 | 000,000,402 | -HS- | M] () -- C:\Users\VIP\Favorites\desktop.ini
  605.  
  606. [color=#A23BEC]< %systemroot%\System32\Wbem\*.exe >[/color]
  607. [2009.07.14 03:14:24 | 000,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\mofcomp.exe
  608. [2009.07.14 03:14:45 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WinMgmt.exe
  609. [2009.07.14 03:14:46 | 000,115,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIADAP.exe
  610. [2009.07.14 03:14:46 | 000,395,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIC.exe
  611. [2010.11.21 05:24:27 | 000,257,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WmiPrvSE.exe
  612.  
  613. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >[/color]
  614.  
  615. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >[/color]
  616.  
  617. < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement