Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 19.7.2013 16:14:28 - Run 1
- OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Đurić\Desktop
- Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
- Internet Explorer (Version = 8.0.6001.18702)
- Locale: 0000041A | Country: Croatia | Language: HRV | Date Format: d.M.yyyy
- 1,87 Gb Total Physical Memory | 1,19 Gb Available Physical Memory | 63,42% Memory free
- 3,72 Gb Paging File | 3,03 Gb Available in Paging File | 81,43% Paging File free
- Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
- Drive C: | 97,65 Gb Total Space | 74,85 Gb Free Space | 76,64% Space Free | Partition Type: NTFS
- Drive D: | 200,43 Gb Total Space | 111,11 Gb Free Space | 55,44% Space Free | Partition Type: NTFS
- Drive G: | 7,39 Gb Total Space | 7,21 Gb Free Space | 97,54% Space Free | Partition Type: FAT32
- Computer Name: CDT | User Name: Đurić | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Quick Scan
- Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2013.07.19 16:12:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Đurić\Desktop\OTL.exe
- PRC - [2013.07.19 11:26:16 | 000,182,184 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
- PRC - [2013.07.12 20:49:47 | 000,846,288 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
- PRC - [2013.02.16 00:04:53 | 001,352,776 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe
- PRC - [2009.10.07 09:16:50 | 000,472,280 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
- PRC - [2009.10.07 09:15:42 | 001,461,080 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
- PRC - [2008.09.16 12:03:18 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
- PRC - [2008.04.14 13:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
- PRC - [2008.03.20 20:23:22 | 000,083,240 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
- PRC - [2008.03.19 00:18:24 | 000,496,128 | ---- | M] (Beiley Software Inc.) -- C:\Program Files\Remind-Me\RemindMe.exe
- PRC - [2007.12.20 14:36:50 | 000,135,168 | ---- | M] (Vimicro Corporation) -- C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe
- PRC - [2006.05.12 11:16:50 | 000,072,704 | ---- | M] (Autodata Limited) -- C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
- PRC - [2000.01.01 02:00:00 | 001,258,856 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2013.07.12 20:49:44 | 000,396,240 | ---- | M] () -- C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Chrome\Application\28.0.1500.72\ppgooglenaclpluginchrome.dll
- MOD - [2013.07.12 20:49:42 | 004,052,944 | ---- | M] () -- C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Chrome\Application\28.0.1500.72\pdf.dll
- MOD - [2013.07.12 20:48:49 | 001,597,392 | ---- | M] () -- C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Chrome\Application\28.0.1500.72\ffmpegsumo.dll
- MOD - [2008.04.14 13:00:00 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
- MOD - [2008.04.14 13:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
- [color=#E56717]========== Services (SafeList) ==========[/color]
- SRV - [2013.07.19 11:26:16 | 000,182,184 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
- SRV - [2013.07.05 21:55:37 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
- SRV - [2013.06.21 09:53:36 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
- SRV - [2009.10.07 09:21:14 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
- SRV - [2009.10.07 09:16:50 | 000,472,280 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
- SRV - [2009.10.01 11:38:01 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
- SRV - [2008.09.16 12:03:18 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor7.0)
- SRV - [2006.05.12 11:16:50 | 000,072,704 | ---- | M] (Autodata Limited) [Auto | Running] -- C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe -- (Autodata Limited License Service)
- SRV - [2000.01.01 02:00:00 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
- DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\LV561AV.SYS -- (PID_0928)
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
- DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
- DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\LVUSBSta.sys -- (LVUSBSta)
- DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
- DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
- DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
- DRV - [2010.01.12 17:42:54 | 000,252,928 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VMUVC.sys -- (VMUVC)
- DRV - [2009.10.07 09:18:36 | 000,035,168 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
- DRV - [2009.10.07 09:12:22 | 000,054,184 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\easdrv.sys -- (easdrv)
- DRV - [2009.10.07 09:11:10 | 000,040,824 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
- DRV - [2009.02.06 13:25:42 | 000,100,736 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\nvatabus.sys -- (nvatabus)
- DRV - [2008.07.01 11:12:32 | 000,398,720 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vvftUVC.sys -- (vvftUVC)
- DRV - [2008.02.01 17:24:04 | 000,041,456 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD8\000.fcl -- ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054})
- DRV - [2006.06.19 05:37:34 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
- DRV - [2000.01.01 02:00:00 | 006,141,584 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
- DRV - [2000.01.01 02:00:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
- DRV - [2000.01.01 02:00:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
- DRV - [2000.01.01 02:00:00 | 000,168,040 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvgts.sys -- (nvgts)
- DRV - [2000.01.01 02:00:00 | 000,070,912 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
- DRV - [2000.01.01 02:00:00 | 000,013,824 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
- DRV - [1999.09.10 12:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (ASPI32)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1ewenusDefaultPack/UP97_FRPage
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = hr
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 86 4E 75 ED 2B E1 CD 01 [binary data]
- IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
- IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKCU\..\SearchScopes\{00C1499D-5976-463F-BB0F-287EF3F210C0}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
- IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
- IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.defaultenginename: "Bing "
- FF - prefs.js..browser.search.defaultthis.engineName: " "
- FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
- FF - prefs.js..browser.search.order.3: "Bing "
- FF - prefs.js..browser.search.selectedEngine: "Bing "
- FF - prefs.js..browser.startup.homepage: "http://www.msn.com/?pc=UP97&ocid=UP97DHP&dt=071413"
- FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
- FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
- FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
- FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.1.1
- FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
- FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
- FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
- FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
- FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=UP97DF&PC=UP97&dt=071413&q="
- FF - user.js - File not found
- FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
- FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
- FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
- FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
- FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
- FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=4.0: C:\Program Files\MSN Toolbar\Platform\4.0.0357.1\npwinext.dll (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
- FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
- FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
- FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll (Yahoo! Inc.)
- FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Đurić\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
- FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
- FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.06.09 16:34:40 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\msntoolbar@msn.com: C:\Program Files\MSN Toolbar\Platform\4.0.0357.1\Firefox [2011.06.09 16:35:43 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011.06.09 16:35:46 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.07.05 21:55:17 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.07.19 13:45:15 | 000,000,000 | ---D | M]
- FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011.06.09 16:34:40 | 000,000,000 | ---D | M]
- [2009.11.06 21:39:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Đurić\Application Data\Mozilla\Extensions
- [2013.05.10 06:13:59 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Đurić\Application Data\Mozilla\Firefox\Profiles\f1i8eks7.default\extensions
- [2012.07.06 16:35:38 | 000,123,385 | ---- | M] () (No name found) -- C:\Documents and Settings\Đurić\Application Data\Mozilla\Firefox\Profiles\f1i8eks7.default\extensions\elemhidehelper@adblockplus.org.xpi
- [2013.05.10 06:13:59 | 000,870,680 | ---- | M] () (No name found) -- C:\Documents and Settings\Đurić\Application Data\Mozilla\Firefox\Profiles\f1i8eks7.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- [2013.07.14 20:29:45 | 000,002,402 | ---- | M] () -- C:\Documents and Settings\Đurić\Application Data\Mozilla\Firefox\Profiles\f1i8eks7.default\searchplugins\bingp.xml
- [2011.06.20 14:07:48 | 000,000,863 | ---- | M] () -- C:\Documents and Settings\Đurić\Application Data\Mozilla\Firefox\Profiles\f1i8eks7.default\searchplugins\conduit.xml
- [2013.07.05 21:55:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
- [2013.07.05 21:55:39 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- [2010.05.25 10:15:32 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
- [2009.11.06 17:37:19 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
- [2009.11.06 17:37:20 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
- [2007.03.10 01:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
- [color=#E56717]========== Chrome ==========[/color]
- CHR - default_search_provider: Google (Enabled)
- CHR - default_search_provider: search_url = http://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&aq=t
- CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/complete/search?q={searchTerms}
- CHR - homepage: http://www.msn.com/?pc=UP97&ocid=UP97DHP&dt=071413
- CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\\u0110uri\u0107\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll
- CHR - plugin: Chrome Remote Desktop Viewer (Disabled) = internal-remoting-viewer
- CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\\u0110uri\u0107\Local Settings\Application Data\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
- CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\\u0110uri\u0107\Local Settings\Application Data\Google\Chrome\Application\28.0.1500.72\pdf.dll
- CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
- CHR - plugin: Coupons Inc., Coupon Printer Manager (Disabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
- CHR - plugin: Coupons Inc., Coupon Printer Manager (Disabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
- CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Disabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
- CHR - plugin: RealJukebox NS Plugin (Disabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
- CHR - plugin: RealPlayer Download Plugin (Disabled) = C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll
- CHR - plugin: Yahoo! activeX Plug-in Bridge (Disabled) = C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
- CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
- CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Disabled) = C:\Program Files\Windows Media Player\npdsplay.dll
- CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
- CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Disabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
- CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Disabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
- CHR - plugin: Facebook Plugin (Disabled) = C:\Documents and Settings\\u0110uri\u0107\Application Data\Facebook\npfbplugin_1_0_3.dll
- CHR - plugin: Google Update (Disabled) = C:\Documents and Settings\\u0110uri\u0107\Local Settings\Application Data\Google\Update\1.3.21.145\npGoogleUpdate3.dll
- CHR - plugin: Google Earth Plugin (Disabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
- CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
- CHR - plugin: Java(TM) Platform SE 7 U9 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
- CHR - plugin: RealPlayer Version Plugin (Disabled) = C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
- CHR - plugin: MSN\u00AE Toolbar (Disabled) = C:\Program Files\MSN Toolbar\Platform\4.0.0357.1\npwinext.dll
- CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
- CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
- CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
- CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll
- CHR - plugin: Shockwave Flash (Disabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll
- CHR - plugin: Java Deployment Toolkit 7.0.90.5 (Enabled) = C:\WINDOWS\system32\npDeployJava1.dll
- CHR - Extension: Google Docs = C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
- CHR - Extension: Google Drive = C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
- CHR - Extension: YouTube = C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
- CHR - Extension: Google Search = C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
- CHR - Extension: AdBlock = C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.2_0\
- CHR - Extension: Skype Extension = C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.3.0.7550_0\
- CHR - Extension: Gmail = C:\Documents and Settings\Đurić\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
- O1 HOSTS File: ([2012.08.11 16:32:36 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
- O1 - Hosts: 127.0.0.1 localhost
- O1 - Hosts: ::1 localhost
- O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
- O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
- O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
- O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
- O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe ()
- O4 - HKLM..\Run: [RemoteControl8] C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe (Cyberlink Corp.)
- O4 - HKLM..\Run: [Vistadrv] C:\Program Files\VistaDrives\vsdrv.exe ()
- O4 - HKLM..\Run: [VMonitorVMUVC] C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe (Vimicro Corporation)
- O4 - Startup: C:\Documents and Settings\Đurić\Start Menu\Programs\Startup\RemindMe.lnk = C:\Program Files\Remind-Me\RemindMe.exe (Beiley Software Inc.)
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 01 00 00 00 [binary data]
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 01 00 00 00 [binary data]
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
- O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A37DAC44-5023-4478-84AE-31B382D1CB5D}: DhcpNameServer = 192.168.1.1
- O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
- O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
- O24 - Desktop WallPaper: C:\Documents and Settings\Đurić\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
- O24 - Desktop BackupWallPaper: C:\Documents and Settings\Đurić\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
- O32 - HKLM CDRom: AutoRun - 1
- O32 - AutoRun File - [2009.10.01 10:50:19 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
- O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
- NetSvcs: 6to4 - File not found
- NetSvcs: Ias - File not found
- NetSvcs: Iprip - File not found
- NetSvcs: Irmon - File not found
- NetSvcs: NWCWorkstation - File not found
- NetSvcs: Nwsapagent - File not found
- NetSvcs: WmdmPmSp - File not found
- Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
- Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
- Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
- Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
- Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
- Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
- Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
- Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
- Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
- Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
- Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
- Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
- CREATERESTOREPOINT
- Restore point Set: OTL Restore Point
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2013.07.19 16:12:43 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Đurić\Desktop\OTL.exe
- [2013.07.19 12:30:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Đurić\Start Menu\Programs\CyberLink PowerDVD 8
- [2013.07.19 12:00:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Đurić\Recent
- [2013.07.05 21:55:17 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
- [2009.10.01 13:05:13 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Đurić\Application Data\pcouffin.sys
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2013.07.19 16:13:00 | 000,001,028 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-1682526488-1801674531-1003UA.job
- [2013.07.19 16:12:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Đurić\Desktop\OTL.exe
- [2013.07.19 15:44:00 | 000,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
- [2013.07.19 14:15:29 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
- [2013.07.19 12:29:53 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-583907252-1682526488-1801674531-1003.job
- [2013.07.19 12:29:52 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-583907252-1682526488-1801674531-1003.job
- [2013.07.19 12:29:24 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
- [2013.07.19 12:29:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
- [2013.07.19 12:29:12 | 2011,680,768 | -HS- | M] () -- C:\hiberfil.sys
- [2013.07.19 11:57:04 | 000,000,211 | -HS- | M] () -- C:\boot.ini
- [2013.07.19 11:03:46 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{851352E7-9810-4FCD-8147-8EEB829A56D0}.job
- [2013.07.18 20:13:00 | 000,000,976 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-1682526488-1801674531-1003Core.job
- [2013.07.16 20:16:46 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
- [2013.07.13 12:12:07 | 000,002,309 | ---- | M] () -- C:\Documents and Settings\Đurić\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
- [2013.07.13 12:12:07 | 000,002,291 | ---- | M] () -- C:\Documents and Settings\Đurić\Desktop\Google Chrome.lnk
- [2013.07.11 21:32:44 | 000,463,616 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
- [2013.07.11 16:21:12 | 000,435,870 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
- [2013.07.11 16:21:12 | 000,068,766 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2012.10.26 21:30:03 | 000,010,084 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
- [2012.10.26 21:24:20 | 000,025,548 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTAIODAT.DAT
- [2012.08.11 17:45:27 | 001,072,544 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
- [2012.08.11 17:45:27 | 001,072,544 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
- [2012.08.11 17:45:27 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
- [2012.08.11 17:44:48 | 002,816,504 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
- [2012.02.16 19:25:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
- [2009.10.01 13:49:03 | 000,100,352 | ---- | C] () -- C:\Documents and Settings\Đurić\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
- [2009.10.01 13:07:52 | 000,001,044 | ---- | C] () -- C:\Documents and Settings\Đurić\Application Data\vso_ts_preview.xml
- [2009.10.01 13:05:13 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Đurić\Application Data\inst.exe
- [2009.10.01 13:05:13 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Đurić\Application Data\pcouffin.cat
- [2009.10.01 13:05:13 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Đurić\Application Data\pcouffin.inf
- [color=#E56717]========== ZeroAccess Check ==========[/color]
- [2009.10.01 11:20:03 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
- [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- "" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 13:00:00 | 001,499,136 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
- "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 14:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
- "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 13:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Both
- [color=#E56717]========== LOP Check ==========[/color]
- [2009.10.01 11:58:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
- [2012.12.23 18:36:32 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
- [2009.10.01 11:25:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ConeXware
- [2011.07.27 09:28:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Easybits GO
- [2009.10.01 13:47:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
- [2011.06.09 21:05:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData
- [2010.04.04 12:54:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fallout2
- [2009.10.01 12:40:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GrebleSoft
- [2011.06.28 21:13:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MAGIX
- [2011.06.30 13:20:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
- [2011.06.30 13:20:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
- [2012.12.28 15:50:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
- [2009.10.01 12:14:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
- [2011.06.28 23:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
- [2012.08.23 11:26:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Web Installer
- [2009.10.01 13:02:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\5imyshow.Ltd
- [2009.10.01 11:58:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\Autodesk
- [2011.03.06 18:29:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\EPSON
- [2012.12.25 22:53:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\EuroTalk
- [2010.05.25 21:40:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\Facebook
- [2011.07.27 09:28:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\go
- [2009.10.01 13:01:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\JLC's Software
- [2012.12.28 15:50:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\langmaster.com
- [2010.12.29 23:47:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\LimeWire
- [2009.10.01 12:47:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\MAGIX
- [2012.08.08 23:02:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\Oracle
- [2011.09.18 21:17:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\PriceGong
- [2009.10.01 12:40:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\Remind-Me
- [2011.01.01 12:51:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\Spacejock Software
- [2011.06.28 23:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\Ulead Systems
- [2012.10.26 21:11:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\uTorrent
- [2012.05.25 21:52:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\Vso
- [2009.10.01 12:28:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Đurić\Application Data\WeatherWatcher
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Custom Scans ==========[/color]
- [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
- [2003.04.11 19:42:24 | 000,002,366 | ---- | M] () -- C:\1.03readme.txt
- [2003.06.15 17:33:42 | 000,005,903 | ---- | M] () -- C:\1.04readme.txt
- [2011.06.09 21:05:08 | 000,000,000 | ---- | M] () -- C:\AdobeDebug.txt
- [2009.10.01 10:50:19 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
- [2013.07.19 11:57:04 | 000,000,211 | -HS- | M] () -- C:\boot.ini
- [1999.07.16 02:28:20 | 000,000,615 | ---- | M] () -- C:\Children Readme.txt
- [2009.10.01 10:50:19 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
- [2009.10.01 12:30:44 | 000,001,961 | ---- | M] () -- C:\ErrLog.txt
- [2013.07.19 12:29:12 | 2011,680,768 | -HS- | M] () -- C:\hiberfil.sys
- [2009.10.01 10:50:19 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
- [2009.10.01 10:50:19 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
- [2008.04.14 13:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
- [2008.04.14 13:00:00 | 000,250,048 | RHS- | M] () -- C:\ntldr
- [2013.07.19 12:29:10 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
- [color=#A23BEC]< %systemroot%\Fonts\*.com >[/color]
- [2006.04.18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
- [2006.06.29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
- [2006.04.18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
- [2006.06.29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
- [color=#A23BEC]< %systemroot%\Fonts\*.dll >[/color]
- [color=#A23BEC]< %systemroot%\Fonts\*.ini >[/color]
- [2009.10.01 10:49:59 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
- [color=#A23BEC]< %systemroot%\Fonts\*.ini2 >[/color]
- [color=#A23BEC]< %systemroot%\Fonts\*.exe >[/color]
- [color=#A23BEC]< %systemroot%\system32\spool\prtprocs\w32x86\*.* >[/color]
- [2008.07.06 14:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
- [2010.01.06 14:23:24 | 000,319,488 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp101.dll
- [2006.10.26 19:58:12 | 000,030,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
- [2006.10.26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
- [2008.07.06 12:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
- [color=#A23BEC]< %systemroot%\REPAIR\*.bak1 >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.ini >[/color]
- [color=#A23BEC]< %systemroot%\system32\*.jpg >[/color]
- [color=#A23BEC]< %systemroot%\*.jpg >[/color]
- [color=#A23BEC]< %systemroot%\*.png >[/color]
- [color=#A23BEC]< %systemroot%\*.scr >[/color]
- [color=#A23BEC]< %systemroot%\*._sy >[/color]
- [color=#A23BEC]< %APPDATA%\Adobe\Update\*.* >[/color]
- [color=#A23BEC]< %ALLUSERSPROFILE%\Favorites\*.* >[/color]
- [color=#A23BEC]< %APPDATA%\Microsoft\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
- [color=#A23BEC]< %APPDATA%\Update\*.* >[/color]
- [color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
- [color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color]
- [2009.10.01 12:37:18 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
- [2009.10.01 12:37:18 | 001,089,536 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
- [2009.10.01 12:37:18 | 000,897,024 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
- [color=#A23BEC]< %PROGRAMFILES%\bak. /s >[/color]
- [color=#A23BEC]< %systemroot%\system32\bak. /s >[/color]
- [color=#A23BEC]< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >[/color]
- [2009.10.01 10:50:19 | 000,000,294 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
- [color=#A23BEC]< %systemroot%\system32\config\systemprofile\*.dat /x >[/color]
- [color=#A23BEC]< %systemroot%\*.config >[/color]
- [color=#A23BEC]< %systemroot%\system32\*.db >[/color]
- [color=#A23BEC]< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >[/color]
- [2009.10.01 10:55:31 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\Đurić\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
- [2013.03.29 15:25:52 | 000,000,385 | ---- | M] () -- C:\Documents and Settings\Đurić\Application Data\Microsoft\Internet Explorer\Quick Launch\Prečac.txt
- [2009.10.01 10:55:30 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Đurić\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
- [color=#A23BEC]< %USERPROFILE%\Desktop\*.exe >[/color]
- [2013.07.19 16:12:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Đurić\Desktop\OTL.exe
- [color=#A23BEC]< %PROGRAMFILES%\Common Files\*.* >[/color]
- [color=#A23BEC]< %systemroot%\*.src >[/color]
- [color=#A23BEC]< %systemroot%\install\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\DLL\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\HelpFiles\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\rundll\*.* >[/color]
- [color=#A23BEC]< %systemroot%\winn32\*.* >[/color]
- [color=#A23BEC]< %systemroot%\Java\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\test\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\Rundll32\*.* >[/color]
- [color=#A23BEC]< %systemroot%\AppPatch\Custom\*.* >[/color]
- [color=#A23BEC]< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.tmp >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.dat >[/color]
- [color=#A23BEC]< %USERPROFILE%\My Documents\*.exe >[/color]
- [color=#A23BEC]< %USERPROFILE%\*.exe >[/color]
- [color=#A23BEC]< %systemroot%\ADDINS\*.* >[/color]
- [color=#A23BEC]< %systemroot%\assembly\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Config\*.* >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\SECURITY\Database\*.sdb /x >[/color]
- [color=#A23BEC]< %systemroot%\SYSTEM\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Web\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Driver Cache\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Mozilla Firefox\0*.exe >[/color]
- [color=#A23BEC]< %ProgramFiles%\Microsoft Common\*.* >[/color]
- [color=#A23BEC]< %ProgramFiles%\TinyProxy. >[/color]
- [color=#A23BEC]< %USERPROFILE%\Favorites\*.url /x >[/color]
- [2009.10.01 10:55:30 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Đurić\Favorites\Desktop.ini
- [color=#A23BEC]< %systemroot%\System32\Wbem\*.exe >[/color]
- [2008.04.14 13:00:00 | 000,016,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Wbem\mofcomp.exe
- [2008.04.14 13:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Wbem\scrcons.exe
- [2008.04.14 13:00:00 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Wbem\unsecapp.exe
- [2008.04.14 13:00:00 | 000,116,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Wbem\wbemtest.exe
- [2008.04.14 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Wbem\winmgmt.exe
- [2008.04.14 13:00:00 | 000,196,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Wbem\wmiadap.exe
- [2008.04.14 13:00:00 | 000,126,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Wbem\wmiapsrv.exe
- [2008.04.14 13:00:00 | 000,358,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Wbem\wmic.exe
- [2009.02.06 12:10:02 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Wbem\wmiprvse.exe
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >[/color]
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >[/color]
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-07-11 14:21:54
- [color=#E56717]========== Alternate Data Streams ==========[/color]
- @Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:004166BE
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement