Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 10.10.2012. 11:11:17 - Run 1
- OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Hrvoje\Desktop
- 64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation
- Internet Explorer (Version = 9.10.9200.16384)
- Locale: 0000041a | Country: Hrvatska | Language: HRV | Date Format: d.M.yyyy.
- 4,00 Gb Total Physical Memory | 2,77 Gb Available Physical Memory | 69,14% Memory free
- 7,50 Gb Paging File | 6,10 Gb Available in Paging File | 81,30% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
- Drive C: | 298,08 Gb Total Space | 278,92 Gb Free Space | 93,57% Space Free | Partition Type: NTFS
- Computer Name: HRVOJE-PC | User Name: Hrvoje | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
- Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2012.10.10 11:10:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Hrvoje\Desktop\OTL.exe
- PRC - [2012.10.04 03:16:02 | 001,239,064 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- PRC - [2012.08.27 15:05:06 | 000,306,688 | ---- | M] (Skillbrains) -- C:\Users\Hrvoje\AppData\Local\Skillbrains\lightshot\3.0.0.0\Lightshot.exe
- PRC - [2012.08.27 06:21:12 | 026,924,984 | ---- | M] (Dropbox, Inc.) -- C:\Users\Hrvoje\AppData\Roaming\Dropbox\bin\Dropbox.exe
- PRC - [2012.01.22 06:05:46 | 004,091,904 | ---- | M] () -- C:\Program Files (x86)\Clipdiary\clipdiary.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2012.10.04 03:16:00 | 000,460,312 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\ppgooglenaclpluginchrome.dll
- MOD - [2012.10.04 03:15:58 | 012,435,992 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\PepperFlash\pepflashplayer.dll
- MOD - [2012.10.04 03:15:56 | 004,005,912 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\pdf.dll
- MOD - [2012.10.04 03:14:41 | 000,578,072 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\libglesv2.dll
- MOD - [2012.10.04 03:14:40 | 000,123,928 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\libegl.dll
- MOD - [2012.10.04 03:14:29 | 000,156,712 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\avutil-51.dll
- MOD - [2012.10.04 03:14:27 | 000,275,496 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\avformat-54.dll
- MOD - [2012.10.04 03:14:26 | 002,168,360 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\avcodec-54.dll
- MOD - [2012.01.22 06:05:46 | 004,091,904 | ---- | M] () -- C:\Program Files (x86)\Clipdiary\clipdiary.exe
- MOD - [2010.08.24 00:57:10 | 000,542,036 | ---- | M] () -- C:\Program Files (x86)\Clipdiary\sqlite3.dll
- [color=#E56717]========== Services (SafeList) ==========[/color]
- SRV:[b]64bit:[/b] - [2012.07.26 06:46:56 | 002,366,984 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
- SRV:[b]64bit:[/b] - [2012.07.26 05:30:05 | 002,675,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
- SRV:[b]64bit:[/b] - [2012.07.26 05:17:59 | 000,015,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
- SRV:[b]64bit:[/b] - [2012.07.26 05:08:04 | 001,968,128 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:07:47 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:07:42 | 000,263,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:07:40 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:07:30 | 000,169,984 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
- SRV:[b]64bit:[/b] - [2012.07.26 05:07:27 | 000,178,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
- SRV:[b]64bit:[/b] - [2012.07.26 05:07:25 | 000,012,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:06:36 | 000,463,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
- SRV:[b]64bit:[/b] - [2012.07.26 05:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
- SRV:[b]64bit:[/b] - [2012.07.26 05:06:33 | 000,161,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:06:33 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
- SRV:[b]64bit:[/b] - [2012.07.26 05:06:00 | 000,438,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:55 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:38 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:34 | 000,037,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:28 | 000,207,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:24 | 000,342,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:11 | 000,174,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:08 | 000,169,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:08 | 000,122,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AUInstallAgent.dll -- (AllUserInstallAgent)
- SRV:[b]64bit:[/b] - [2012.07.26 05:05:04 | 000,187,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
- SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
- SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
- SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
- SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
- SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
- SRV:[b]64bit:[/b] - [2012.07.26 02:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
- SRV - [2012.10.10 08:41:23 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
- SRV - [2012.07.26 05:30:05 | 002,675,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify)
- SRV - [2012.07.26 05:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV:[b]64bit:[/b] - [2012.07.26 07:26:46 | 000,025,328 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
- DRV:[b]64bit:[/b] - [2012.07.26 07:26:45 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\condrv.sys -- (condrv)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:58 | 000,445,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBHUB3.SYS -- (USBHUB3)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:58 | 000,337,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBXHCI.SYS -- (USBXHCI)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:58 | 000,322,800 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS -- (VSTXRAID)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:58 | 000,212,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\UCX01000.SYS -- (UCX01000)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:58 | 000,106,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\VerifierExt.sys -- (VerifierExt)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:58 | 000,097,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\uaspstor.sys -- (UASPStor)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:57 | 000,077,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\acpiex.sys -- (acpiex)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:55 | 000,283,888 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\spaceport.sys -- (spaceport)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:55 | 000,120,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpioclx.sys -- (GPIOClx0101)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:55 | 000,077,552 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\storahci.sys -- (storahci)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:55 | 000,064,240 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\mvumis.sys -- (mvumis)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:55 | 000,030,960 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\stexstor.sys -- (stexstor)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:55 | 000,028,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpiowin32.sys -- (msgpiowin32)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:54 | 000,056,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdstor.sys -- (sdstor)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:52 | 003,295,984 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\evbda.sys -- (ebdrv)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:52 | 000,092,400 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sas2.sys -- (LSI_SAS2)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:52 | 000,081,136 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sss.sys -- (LSI_SSS)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:52 | 000,064,752 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\HpSAMD.sys -- (HpSAMD)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:51 | 000,113,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:51 | 000,081,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorClass.sys -- (EhStorClass)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:49 | 000,539,376 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\bxvbda.sys -- (b06bdrv)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:49 | 000,258,288 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsbs.sys -- (amdsbs)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:49 | 000,106,736 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\3ware.sys -- (3ware)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:49 | 000,076,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsata.sys -- (amdsata)
- DRV:[b]64bit:[/b] - [2012.07.26 07:00:48 | 000,026,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdxata.sys -- (amdxata)
- DRV:[b]64bit:[/b] - [2012.07.26 06:59:35 | 000,193,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdbus.sys -- (sdbus)
- DRV:[b]64bit:[/b] - [2012.07.26 06:59:35 | 000,148,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\tpm.sys -- (TPM)
- DRV:[b]64bit:[/b] - [2012.07.26 06:59:32 | 000,055,024 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\Drivers\dam.sys -- (dam)
- DRV:[b]64bit:[/b] - [2012.07.26 06:58:00 | 000,068,848 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\pdc.sys -- (pdc)
- DRV:[b]64bit:[/b] - [2012.07.26 06:57:54 | 000,361,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\clfs.sys -- (CLFS)
- DRV:[b]64bit:[/b] - [2012.07.26 06:54:34 | 000,096,496 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\wfplwfs.sys -- (WFPLWFS)
- DRV:[b]64bit:[/b] - [2012.07.26 06:53:16 | 000,067,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpci.sys -- (vpci)
- DRV:[b]64bit:[/b] - [2012.07.26 06:44:30 | 000,258,288 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\WdFilter.sys -- (WdFilter)
- DRV:[b]64bit:[/b] - [2012.07.26 06:36:15 | 000,034,216 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\WdBoot.sys -- (WdBoot)
- DRV:[b]64bit:[/b] - [2012.07.26 05:17:38 | 000,036,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\terminpt.sys -- (terminpt)
- DRV:[b]64bit:[/b] - [2012.07.26 05:17:38 | 000,027,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
- DRV:[b]64bit:[/b] - [2012.07.26 04:29:14 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mshidumdf.sys -- (mshidumdf)
- DRV:[b]64bit:[/b] - [2012.07.26 04:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicDisplay.sys -- (BasicDisplay)
- DRV:[b]64bit:[/b] - [2012.07.26 04:29:03 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\HyperVideo.sys -- (HyperVideo)
- DRV:[b]64bit:[/b] - [2012.07.26 04:28:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicRender.sys -- (BasicRender)
- DRV:[b]64bit:[/b] - [2012.07.26 04:28:27 | 000,031,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:58 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\fxppm.sys -- (FxPPM)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmgencounter.sys -- (gencounter)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:41 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\kdnic.sys -- (kdnic)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:37 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpitime.sys -- (acpitime)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\npsvctrig.sys -- (npsvctrig)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:31 | 000,029,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthhfHid.sys -- (bthhfhid)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:29 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys -- (WpdUpFltr)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:16 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpipagr.sys -- (acpipagr)
- DRV:[b]64bit:[/b] - [2012.07.26 04:27:01 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hyperkbd.sys -- (hyperkbd)
- DRV:[b]64bit:[/b] - [2012.07.26 04:26:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SerCx.sys -- (SerCx)
- DRV:[b]64bit:[/b] - [2012.07.26 04:26:43 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SpbCx.sys -- (SpbCx)
- DRV:[b]64bit:[/b] - [2012.07.26 04:26:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbGD.sys -- (TsUsbGD)
- DRV:[b]64bit:[/b] - [2012.07.26 04:26:13 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\bthhfenum.sys -- (BthHFEnum)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:57 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dmvsc.sys -- (dmvsc)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys -- (TsUsbFlt)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:54 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hidi2c.sys -- (hidi2c)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:26 | 000,203,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\Vid.sys -- (Vid)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:22 | 000,067,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\storvsp.sys -- (storvsp)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:13 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\wpcfltr.sys -- (wpcfltr)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:12 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmbusr.sys -- (vmbusr)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:12 | 000,066,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpcivsp.sys -- (vpcivsp)
- DRV:[b]64bit:[/b] - [2012.07.26 04:25:01 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys -- (NdisImPlatform)
- DRV:[b]64bit:[/b] - [2012.07.26 04:23:53 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\mslldp.sys -- (MsLldp)
- DRV:[b]64bit:[/b] - [2012.07.26 04:23:42 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\Ndu.sys -- (Ndu)
- DRV:[b]64bit:[/b] - [2012.07.26 00:53:22 | 011,926,528 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmdag.sys -- (amdkmdag)
- DRV:[b]64bit:[/b] - [2012.06.29 04:00:48 | 000,360,448 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmpag.sys -- (amdkmdap)
- DRV:[b]64bit:[/b] - [2012.06.02 16:34:38 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\VSTDPV6.SYS -- (SrvHsfV92)
- DRV:[b]64bit:[/b] - [2012.06.02 16:34:38 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
- DRV:[b]64bit:[/b] - [2012.06.02 16:34:38 | 000,411,136 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\VSTBS26.SYS -- (SrvHsfPCI)
- DRV:[b]64bit:[/b] - [2012.06.02 16:31:52 | 000,344,192 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\nvmf6264.sys -- (NVNET)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_500_90.dll File not found
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_500_90.dll ()
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
- [color=#E56717]========== Chrome ==========[/color]
- CHR - homepage: http://www.comodo.com/
- CHR - default_search_provider: Google (Enabled)
- CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
- CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
- CHR - homepage: http://www.comodo.com/
- CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\PepperFlash\pepflashplayer.dll
- CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
- CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\ppGoogleNaClPluginChrome.dll
- CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.92\pdf.dll
- CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
- CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
- CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
- CHR - Extension: YouTube = C:\Users\Hrvoje\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
- CHR - Extension: Google pretra\u017Eivanje = C:\Users\Hrvoje\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
- CHR - Extension: Photo Zoom for Facebook = C:\Users\Hrvoje\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi\1.1208.30.1_0\
- CHR - Extension: AdBlock = C:\Users\Hrvoje\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.45_0\
- CHR - Extension: Classic = C:\Users\Hrvoje\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkacjpbfdknhflllbcmjibkdeoafencn\1.1_0\
- CHR - Extension: EXIF Viewer = C:\Users\Hrvoje\AppData\Local\Google\Chrome\User Data\Default\Extensions\lplmljfembbkocngnlkkdgabpnfokmnl\2.1.9_0\
- CHR - Extension: Gmail = C:\Users\Hrvoje\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
- O1 HOSTS File: ([2012.07.26 07:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
- O4 - HKCU..\Run: [Clipdiary] C:\Program Files (x86)\Clipdiary\clipdiary.exe ()
- O4 - HKCU..\Run: [LightShot] C:\Users\Hrvoje\AppData\Local\Skillbrains\lightshot\LightShot.exe ()
- O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
- O4 - Startup: C:\Users\Hrvoje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Hrvoje\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O13[b]64bit:[/b] - gopher Prefix: missing
- O13 - gopher Prefix: missing
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C85974ED-B7B4-49AD-8660-22ADAD9C74AE}: DhcpNameServer = 192.168.1.1
- O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
- O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
- O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O30 - LSA: Security Packages - (livessp) - File not found
- O32 - HKLM CDRom: AutoRun - 1
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
- O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
- O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
- NetSvcs:[b]64bit:[/b] wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
- NetSvcs:[b]64bit:[/b] DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
- NetSvcs:[b]64bit:[/b] NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
- NetSvcs:[b]64bit:[/b] SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
- NetSvcs:[b]64bit:[/b] AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
- CREATERESTOREPOINT
- Restore point Set: OTL Restore Point
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2012.10.10 11:10:50 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Hrvoje\Desktop\OTL.exe
- [2012.10.08 15:16:37 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Local\Diagnostics
- [2012.10.08 00:42:08 | 000,000,000 | ---D | C] -- C:\Windows\Panther
- [2012.10.08 00:41:54 | 000,000,000 | -HSD | C] -- C:\Boot
- [2012.10.07 17:28:42 | 000,000,000 | ---D | C] -- C:\Windows\AutoKMS
- [2012.10.07 17:22:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
- [2012.10.07 17:22:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
- [2012.10.07 17:21:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
- [2012.10.07 17:21:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
- [2012.10.07 17:20:54 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
- [2012.10.07 17:20:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework
- [2012.10.07 17:18:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
- [2012.10.07 17:18:19 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
- [2012.10.07 17:17:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
- [2012.10.07 17:17:50 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Local\Microsoft Help
- [2012.10.07 17:17:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
- [2012.10.07 17:17:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
- [2012.10.07 17:17:39 | 000,000,000 | RH-D | C] -- C:\MSOCache
- [2012.10.07 16:24:24 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\Dropbox
- [2012.10.07 16:23:21 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
- [2012.10.07 16:22:18 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Roaming\Dropbox
- [2012.10.07 16:00:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clipdiary
- [2012.10.07 16:00:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Clipdiary
- [2012.10.07 15:54:33 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Roaming\YourFileDownloader
- [2012.10.07 15:51:10 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Roaming\Clipdiary
- [2012.10.07 15:47:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Skillbrains
- [2012.10.07 15:47:52 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LightShot
- [2012.10.07 15:47:48 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Local\Skillbrains
- [2012.10.07 15:45:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
- [2012.10.07 15:44:35 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Roaming\uTorrent
- [2012.10.07 15:38:06 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Roaming\Xfire
- [2012.10.07 15:38:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xfire
- [2012.10.07 15:38:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Xfire
- [2012.10.07 15:37:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xfire
- [2012.10.07 15:17:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc
- [2012.10.07 15:17:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IZArc
- [2012.10.07 15:06:12 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Roaming\Macromedia
- [2012.10.07 14:57:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
- [2012.10.07 14:55:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
- [2012.10.07 14:55:41 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Local\Google
- [2012.10.07 14:50:25 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- [2012.10.07 14:50:25 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\Searches
- [2012.10.07 14:50:25 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\Contacts
- [2012.10.07 14:50:25 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- [2012.10.07 14:50:25 | 000,000,000 | -H-D | C] -- C:\Users\Hrvoje\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
- [2012.10.07 14:50:22 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Roaming\Adobe
- [2012.10.07 14:49:53 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Local\VirtualStore
- [2012.10.07 14:49:44 | 000,000,000 | ---D | C] -- C:\ProgramData\PRICache
- [2012.10.07 14:49:44 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Local\Packages
- [2012.10.07 14:49:40 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\AppData\Local\Temporary Internet Files
- [2012.10.07 14:49:40 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\Templates
- [2012.10.07 14:49:40 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\Local Settings
- [2012.10.07 14:49:40 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\AppData\Local\History
- [2012.10.07 14:49:40 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\AppData\Local\Application Data
- [2012.10.07 14:49:39 | 000,000,000 | --SD | C] -- C:\Users\Hrvoje\AppData\Roaming\Microsoft
- [2012.10.07 14:49:39 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\Videos
- [2012.10.07 14:49:39 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
- [2012.10.07 14:49:39 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\Saved Games
- [2012.10.07 14:49:39 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\Pictures
- [2012.10.07 14:49:39 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\Music
- [2012.10.07 14:49:39 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\Links
- [2012.10.07 14:49:39 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\Favorites
- [2012.10.07 14:49:39 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\Downloads
- [2012.10.07 14:49:39 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\Documents
- [2012.10.07 14:49:39 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\Desktop
- [2012.10.07 14:49:39 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
- [2012.10.07 14:49:39 | 000,000,000 | R--D | C] -- C:\Users\Hrvoje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
- [2012.10.07 14:49:39 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\Start Menu
- [2012.10.07 14:49:39 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\SendTo
- [2012.10.07 14:49:39 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\Recent
- [2012.10.07 14:49:39 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\PrintHood
- [2012.10.07 14:49:39 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\NetHood
- [2012.10.07 14:49:39 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\Documents\My Videos
- [2012.10.07 14:49:39 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\Documents\My Pictures
- [2012.10.07 14:49:39 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\Documents\My Music
- [2012.10.07 14:49:39 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\My Documents
- [2012.10.07 14:49:39 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\Cookies
- [2012.10.07 14:49:39 | 000,000,000 | -HSD | C] -- C:\Users\Hrvoje\Application Data
- [2012.10.07 14:49:39 | 000,000,000 | -H-D | C] -- C:\Users\Hrvoje\AppData
- [2012.10.07 14:49:39 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Local\Temp
- [2012.10.07 14:49:39 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
- [2012.10.07 14:49:39 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Local\Microsoft
- [2012.10.07 14:49:39 | 000,000,000 | ---D | C] -- C:\Users\Hrvoje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
- [2012.10.07 14:49:39 | 000,000,000 | ---D | C] -- C:\Windows\CSC
- [2012.10.07 14:46:55 | 000,000,000 | -HSD | C] -- C:\Recovery
- [2012.10.07 14:43:57 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
- [2012.10.07 14:43:12 | 000,000,000 | -HSD | C] -- C:\System Volume Information
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2012.10.10 11:10:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Hrvoje\Desktop\OTL.exe
- [2012.10.10 11:00:00 | 000,000,968 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
- [2012.10.10 10:40:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
- [2012.10.10 08:40:39 | 000,000,964 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
- [2012.10.10 08:38:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2012.10.09 19:59:00 | 000,000,410 | ---- | M] () -- C:\Windows\tasks\update-S-1-5-21-4279191772-1735002514-807911598-1001.job
- [2012.10.09 19:25:00 | 000,000,410 | ---- | M] () -- C:\Windows\tasks\update-sys.job
- [2012.10.09 09:26:06 | 000,803,370 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
- [2012.10.09 09:26:06 | 000,674,750 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
- [2012.10.09 09:26:06 | 000,124,636 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
- [2012.10.09 09:24:39 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
- [2012.10.08 00:41:56 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
- [2012.10.07 17:25:32 | 000,422,160 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
- [2012.10.07 17:25:19 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
- [2012.10.07 17:25:18 | 3435,593,728 | -HS- | M] () -- C:\hiberfil.sys
- [2012.10.07 16:24:24 | 000,001,041 | ---- | M] () -- C:\Users\Hrvoje\Desktop\Dropbox.lnk
- [2012.10.07 16:23:41 | 000,001,051 | ---- | M] () -- C:\Users\Hrvoje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
- [2012.10.07 16:00:17 | 000,001,045 | ---- | M] () -- C:\Users\Hrvoje\Desktop\Clipdiary.lnk
- [2012.10.07 15:47:56 | 000,000,544 | ---- | M] () -- C:\Users\Hrvoje\AppData\Local\UserProducts.xml
- [2012.10.07 15:45:16 | 000,000,967 | ---- | M] () -- C:\Users\Hrvoje\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
- [2012.10.07 15:45:16 | 000,000,943 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
- [2012.10.07 15:38:04 | 000,000,959 | ---- | M] () -- C:\Users\Public\Desktop\Xfire.lnk
- [2012.10.07 15:05:11 | 000,000,000 | ---- | M] () -- C:\Users\Hrvoje\slmgr
- [2012.10.07 14:57:48 | 000,002,251 | ---- | M] () -- C:\Users\Hrvoje\Desktop\Google Chrome.lnk
- [2012.10.07 14:53:01 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf
- [2012.10.07 14:52:04 | 000,001,424 | ---- | M] () -- C:\Users\Hrvoje\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
- [2012.10.07 14:45:46 | 000,040,858 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
- [2012.10.07 14:45:46 | 000,040,858 | ---- | M] () -- C:\Windows\SysNative\license.rtf
- [2012.10.07 14:44:14 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
- [2012.10.07 14:44:14 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\atiicdxx.dat
- [2012.10.03 04:29:58 | 000,042,440 | ---- | M] () -- C:\Windows\SysWow64\xfcodec.dll
- [2012.10.03 04:29:56 | 000,028,104 | ---- | M] () -- C:\Windows\SysNative\xfcodec64.dll
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2012.10.09 09:24:39 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
- [2012.10.08 00:41:56 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
- [2012.10.07 17:42:36 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
- [2012.10.07 16:24:24 | 000,001,041 | ---- | C] () -- C:\Users\Hrvoje\Desktop\Dropbox.lnk
- [2012.10.07 16:23:41 | 000,001,051 | ---- | C] () -- C:\Users\Hrvoje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
- [2012.10.07 16:00:17 | 000,001,045 | ---- | C] () -- C:\Users\Hrvoje\Desktop\Clipdiary.lnk
- [2012.10.07 15:47:56 | 000,000,544 | ---- | C] () -- C:\Users\Hrvoje\AppData\Local\UserProducts.xml
- [2012.10.07 15:47:56 | 000,000,410 | ---- | C] () -- C:\Windows\tasks\update-S-1-5-21-4279191772-1735002514-807911598-1001.job
- [2012.10.07 15:47:55 | 000,000,410 | ---- | C] () -- C:\Windows\tasks\update-sys.job
- [2012.10.07 15:45:16 | 000,000,967 | ---- | C] () -- C:\Users\Hrvoje\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
- [2012.10.07 15:45:16 | 000,000,943 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
- [2012.10.07 15:38:04 | 000,000,959 | ---- | C] () -- C:\Users\Public\Desktop\Xfire.lnk
- [2012.10.07 15:04:47 | 000,000,000 | ---- | C] () -- C:\Users\Hrvoje\slmgr
- [2012.10.07 14:57:32 | 000,002,251 | ---- | C] () -- C:\Users\Hrvoje\Desktop\Google Chrome.lnk
- [2012.10.07 14:55:48 | 000,000,968 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
- [2012.10.07 14:55:48 | 000,000,964 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
- [2012.10.07 14:53:01 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf
- [2012.10.07 14:52:04 | 000,001,424 | ---- | C] () -- C:\Users\Hrvoje\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
- [2012.10.07 14:50:22 | 000,001,430 | ---- | C] () -- C:\Users\Hrvoje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
- [2012.10.07 14:49:39 | 000,000,352 | ---- | C] () -- C:\Users\Hrvoje\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
- [2012.10.07 14:49:39 | 000,000,334 | ---- | C] () -- C:\Users\Hrvoje\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
- [2012.10.07 14:46:23 | 3435,593,728 | -HS- | C] () -- C:\hiberfil.sys
- [2012.10.07 14:44:14 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
- [2012.10.07 14:44:14 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\atiicdxx.dat
- [2012.10.07 14:43:15 | 268,435,456 | -HS- | C] () -- C:\swapfile.sys
- [2012.10.03 04:29:58 | 000,042,440 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
- [2012.10.03 04:29:56 | 000,028,104 | ---- | C] () -- C:\Windows\SysNative\xfcodec64.dll
- [2012.07.26 10:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
- [2012.07.26 10:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
- [2012.07.26 09:21:26 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
- [2012.07.26 03:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
- [2012.07.26 02:48:53 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
- [2012.07.25 22:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
- [2012.07.25 22:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
- [2012.06.02 16:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
- [color=#E56717]========== ZeroAccess Check ==========[/color]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- "" = C:\Windows\SysNative\shell32.dll -- [2012.07.26 05:07:16 | 019,779,584 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- "" = %SystemRoot%\system32\shell32.dll -- [2012.07.26 05:19:59 | 017,559,552 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012.07.26 05:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
- "" = %systemroot%\system32\wbem\fastprox.dll -- [2012.07.26 05:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012.07.26 05:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Both
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
- [color=#E56717]========== Custom Scans ==========[/color]
- [color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]
- [color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
- [2012.07.26 05:50:01 | 002,114,936 | ---- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E -- C:\Windows\SysWOW64\explorer.exe
- [2012.07.26 05:50:01 | 002,114,936 | ---- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_b4d2f8c937e166b1\explorer.exe
- [2012.07.26 06:49:13 | 002,380,440 | ---- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 -- C:\Windows\explorer.exe
- [2012.07.26 06:49:13 | 002,380,440 | ---- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_aa7e4e770380a4b6\explorer.exe
- [color=#A23BEC]< MD5 for: SERVICES >[/color]
- [2012.07.26 07:26:47 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..ucture-other-minwin_31bf3856ad364e35_6.2.9200.16384_none_8e0944daeed62829\services
- [color=#A23BEC]< MD5 for: SERVICES.EXE >[/color]
- [2012.07.26 07:26:45 | 000,410,624 | ---- | M] (Microsoft Corporation) MD5=754A2CC1F32107EA87CBD305ABE3E618 -- C:\Windows\SysNative\services.exe
- [2012.07.26 07:26:45 | 000,410,624 | ---- | M] (Microsoft Corporation) MD5=754A2CC1F32107EA87CBD305ABE3E618 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16384_none_97e26cd38667756c\services.exe
- [color=#A23BEC]< MD5 for: SERVICES.EXE.MUI >[/color]
- [2012.07.26 09:48:33 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=8BCB19134E995FA62587DCE26E13B36C -- C:\Windows\SysNative\en-US\services.exe.mui
- [2012.07.26 09:48:33 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=8BCB19134E995FA62587DCE26E13B36C -- C:\Windows\WinSxS\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.2.9200.16384_en-us_c2c6ee7bafb963b8\services.exe.mui
- [color=#A23BEC]< MD5 for: SERVICES.JS >[/color]
- [2012.07.26 09:54:06 | 000,056,775 | ---- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 -- C:\Program Files\WindowsApps\Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
- [2012.07.26 09:53:58 | 000,056,775 | ---- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 -- C:\Program Files\WindowsApps\Microsoft.BingNews_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
- [2012.07.26 09:53:55 | 000,056,775 | ---- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 -- C:\Program Files\WindowsApps\Microsoft.BingSports_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
- [2012.07.26 09:54:33 | 000,056,775 | ---- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 -- C:\Program Files\WindowsApps\Microsoft.BingTravel_1.2.0.145_x64__8wekyb3d8bbwe\platform\js\services.js
- [2012.07.26 09:54:01 | 000,056,775 | ---- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 -- C:\Program Files\WindowsApps\Microsoft.BingWeather_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
- [color=#A23BEC]< MD5 for: SERVICES.LNK >[/color]
- [2012.07.25 22:19:37 | 000,001,158 | ---- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
- [2012.07.25 22:19:37 | 000,001,158 | ---- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
- [2012.07.25 22:19:37 | 000,001,158 | ---- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 -- C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_282d8a08cf7f1ada\services.lnk
- [color=#A23BEC]< MD5 for: SERVICES.MOCHIADS.COM.SOL >[/color]
- [2012.10.10 10:05:49 | 000,000,351 | ---- | M] () MD5=C2D17BF746539AA90A905319A8D7C83C -- C:\Users\Hrvoje\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HW2YJ2K7\mochiads.com\services.mochiads.com.sol
- [color=#A23BEC]< MD5 for: SERVICES.MOF >[/color]
- [2012.06.02 16:35:05 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\SysNative\wbem\services.mof
- [2012.06.02 16:35:05 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.2.9200.16384_none_282967cc570d3701\services.mof
- [color=#A23BEC]< MD5 for: SERVICES.MSC >[/color]
- [2012.07.26 09:48:57 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\SysNative\en-US\services.msc
- [2012.06.02 16:31:20 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\SysNative\services.msc
- [2012.07.26 09:48:57 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\SysWOW64\en-US\services.msc
- [2012.06.02 16:31:13 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\SysWOW64\services.msc
- [2012.07.26 09:48:57 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.2.9200.16384_en-us_fd08be678622fdab\services.msc
- [2012.06.02 16:31:20 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_282d8a08cf7f1ada\services.msc
- [2012.06.02 16:31:13 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\WinSxS\wow64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_3282345b03dfdcd5\services.msc
- [2012.07.26 09:48:57 | 000,092,746 | ---- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 -- C:\Windows\WinSxS\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.2.9200.16384_en-us_a0ea22e3cdc58c75\services.msc
- [color=#A23BEC]< MD5 for: SERVICES.PTXML >[/color]
- [2012.07.25 22:30:54 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\SysNative\wdi\perftrack\Services.ptxml
- [2012.07.25 22:30:54 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.2.9200.16384_none_282967cc570d3701\Services.ptxml
- [color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color]
- [2012.07.26 05:20:58 | 000,023,040 | ---- | M] (Microsoft Corporation) MD5=0A175AF8B65797BD22C11903A8BFEB2D -- C:\Windows\SysWOW64\svchost.exe
- [2012.07.26 05:20:58 | 000,023,040 | ---- | M] (Microsoft Corporation) MD5=0A175AF8B65797BD22C11903A8BFEB2D -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.16384_none_b2666581d6b482a6\svchost.exe
- [2012.07.26 05:08:47 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=57350BEDE3834915B6145B67C71C7BDA -- C:\Windows\SysNative\svchost.exe
- [2012.07.26 05:08:47 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=57350BEDE3834915B6145B67C71C7BDA -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.16384_none_0e8501058f11f3dc\svchost.exe
- [color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
- [2012.07.26 05:08:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 -- C:\Windows\SysNative\userinit.exe
- [2012.07.26 05:08:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_34f2617a5b742e02\userinit.exe
- [2012.07.26 05:21:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 -- C:\Windows\SysWOW64\userinit.exe
- [2012.07.26 05:21:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_d8d3c5f6a316bccc\userinit.exe
- [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
- [2012.07.26 05:08:50 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 -- C:\Windows\SysNative\winlogon.exe
- [2012.07.26 05:08:50 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16384_none_c88ca87b5eb5b1ec\winlogon.exe
- [color=#A23BEC]< c:\windows\installer\@ /s >[/color]
- [color=#A23BEC]< c:\windows\installer\*.@ /s >[/color]
- [color=#A23BEC]< %systemdrive%\$Recycle.Bin|@;true;true;true >[/color]
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS /s >[/color]
- "DisplayName" = @%SystemRoot%\system32\qmgr.dll,-1000
- "ErrorControl" = 1
- "ImagePath" = %SystemRoot%\System32\svchost.exe -k netsvcs -- [2012.07.26 05:20:58 | 000,023,040 | ---- | M] (Microsoft Corporation)
- "Start" = 3
- "Type" = 32
- "Description" = @%SystemRoot%\system32\qmgr.dll,-1001
- "DependOnService" = RpcSsEventSystem [binary data]
- "ObjectName" = LocalSystem
- "ServiceSidType" = 1
- "RequiredPrivileges" = SeCreateGlobalPrivilegeSeImperson [Binary data over 200 bytes]
- "DelayedAutoStart" = 1
- "FailureActions" = 80 51 01 00 00 00 00 00 00 00 00 00 03 00 00 00 14 00 00 00 01 00 00 00 60 EA 00 00 01 00 00 00 C0 D4 01 00 00 00 00 00 00 00 00 00 [binary data]
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Parameters]
- "ServiceDll" = %SystemRoot%\System32\qmgr.dll
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Performance]
- "Close" = PerfMon_Close
- "Open" = PerfMon_Open
- "Collect" = PerfMon_Collect
- "Library" = C:\Windows\System32\bitsperf.dll -- [2012.07.26 05:18:01 | 000,018,944 | ---- | M] (Microsoft Corporation)
- "InstallType" = 1
- "PerfIniFile" = bitsctrs.ini
- "First Counter" = 5164
- "Last Counter" = 5180
- "First Help" = 5165
- "Last Help" = 5181
- "Object List" = 5164
- "PerfMMFileName" = Global\MMF_BITS_s
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Security]
- "Security" = 01 00 14 80 90 00 00 00 A0 00 00 00 14 00 00 00 34 00 00 00 02 00 20 00 01 00 00 00 02 C0 18 00 00 00 0C 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 02 00 5C 00 04 00 00 00 00 02 14 00 FF 01 0F 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 04 00 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 06 00 00 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 [Binary data over 200 bytes]
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement