Advertisement
Guest User

Untitled

a guest
Mar 27th, 2012
98
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 43.18 KB | None | 0 0
  1. OTL logfile created on: 3/27/2012 9:18:14 PM - Run 2
  2. OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Bruno\Desktop
  3. 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
  4. Internet Explorer (Version = 8.0.7600.16385)
  5. Locale: 00000409 | Country: Croatia | Language: HRV | Date Format: d.M.yyyy.
  6.  
  7. 2.00 Gb Total Physical Memory | 0.99 Gb Available Physical Memory | 49.74% Memory free
  8. 5.00 Gb Paging File | 3.91 Gb Available in Paging File | 78.15% Paging File free
  9. Paging file location(s): C:\pagefile.sys 3070 3070 [binary data]
  10.  
  11. %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
  12. Drive C: | 77.15 Gb Total Space | 50.55 Gb Free Space | 65.53% Space Free | Partition Type: NTFS
  13. Drive D: | 71.89 Gb Total Space | 63.38 Gb Free Space | 88.16% Space Free | Partition Type: NTFS
  14. Drive F: | 983.72 Mb Total Space | 40.48 Mb Free Space | 4.12% Space Free | Partition Type: FAT
  15.  
  16. Computer Name: GREGOR | User Name: Bruno | Logged in as Administrator.
  17. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
  18. Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
  19.  
  20. [color=#E56717]========== Processes (SafeList) ==========[/color]
  21.  
  22. PRC - [2012/03/27 21:00:16 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
  23. PRC - [2012/03/19 18:30:45 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
  24. PRC - [2012/02/28 18:38:56 | 001,987,976 | ---- | M] (LogMeIn Inc.) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
  25. PRC - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
  26. PRC - [2012/01/13 14:53:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
  27. PRC - [2011/09/05 19:04:58 | 002,904,984 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
  28. PRC - [2009/07/24 20:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
  29. PRC - [2008/02/23 01:52:48 | 001,253,376 | ---- | M] (Ovislink Corp.) -- C:\Program Files (x86)\OVISLINK\Common\AirliveUI.exe
  30.  
  31.  
  32. [color=#E56717]========== Modules (No Company Name) ==========[/color]
  33.  
  34. MOD - [2012/03/19 18:30:44 | 001,969,080 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
  35. MOD - [2012/03/14 11:23:53 | 008,527,520 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
  36. MOD - [2009/07/14 03:15:51 | 000,232,448 | ---- | M] () -- \\?\globalroot\systemroot\syswow64\mswsock.DLL
  37.  
  38.  
  39. [color=#E56717]========== Win32 Services (SafeList) ==========[/color]
  40.  
  41. SRV:[b]64bit:[/b] - [2010/12/14 15:39:14 | 000,036,160 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
  42. SRV:[b]64bit:[/b] - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
  43. SRV:[b]64bit:[/b] - [2009/07/14 03:39:46 | 000,005,120 | ---- | M] (Iomega) [Auto | Running] -- C:\Windows\SysNative\mindrepair.dll -- (belmonitorservice)
  44. SRV - [2012/02/28 18:38:54 | 002,343,816 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
  45. SRV - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
  46. SRV - [2011/08/23 22:34:24 | 004,729,616 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
  47. SRV - [2010/12/14 15:42:40 | 002,019,648 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
  48. SRV - [2010/12/14 15:39:10 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
  49. SRV - [2009/07/24 20:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
  50. SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
  51.  
  52.  
  53. [color=#E56717]========== Driver Services (SafeList) ==========[/color]
  54.  
  55. DRV:[b]64bit:[/b] - [2011/12/10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
  56. DRV:[b]64bit:[/b] - [2011/05/06 15:30:50 | 000,019,936 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdrvio.sys -- (pwdrvio)
  57. DRV:[b]64bit:[/b] - [2011/05/06 15:30:46 | 000,013,280 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdspio.sys -- (pwdspio)
  58. DRV:[b]64bit:[/b] - [2009/07/14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
  59. DRV:[b]64bit:[/b] - [2009/07/14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
  60. DRV:[b]64bit:[/b] - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
  61. DRV:[b]64bit:[/b] - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
  62. DRV:[b]64bit:[/b] - [2009/07/14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
  63. DRV:[b]64bit:[/b] - [2009/07/14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
  64. DRV:[b]64bit:[/b] - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
  65. DRV:[b]64bit:[/b] - [2009/07/13 23:59:33 | 005,020,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
  66. DRV:[b]64bit:[/b] - [2009/06/10 22:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
  67. DRV:[b]64bit:[/b] - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
  68. DRV:[b]64bit:[/b] - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
  69. DRV:[b]64bit:[/b] - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
  70. DRV:[b]64bit:[/b] - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
  71. DRV:[b]64bit:[/b] - [2009/03/18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
  72. DRV:[b]64bit:[/b] - [2007/09/27 14:37:32 | 000,370,176 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr6164.sys -- (rt61x64)
  73. DRV - [2010/11/29 20:27:40 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
  74. DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
  75. DRV - [2005/01/04 11:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)
  76.  
  77.  
  78. [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
  79.  
  80.  
  81. [color=#E56717]========== Internet Explorer ==========[/color]
  82.  
  83. IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  84. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  85. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
  86. IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
  87. IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  88.  
  89. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home?AF=17284
  90. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
  91. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = hr
  92. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C0 7A 7A A7 95 B3 CC 01 [binary data]
  93. IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
  94. IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
  95. IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&babsrc=SP_def&AF=17284
  96. IE - HKCU\..\SearchScopes\{C24588AA-EB0C-48A1-B289-007A6BAB4096}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=FF&o=14594&src=crm&q={searchTerms}&locale=&apn_ptnrs=FV&apn_dtid=YYYYYYYYHR&apn_uid=51629682-d1a3-4c9a-907a-80c3c0b95e1d&apn_sauid=6FA2B757-1323-49E7-BFC3-67961FC6CD59&
  97. IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  98.  
  99. [color=#E56717]========== FireFox ==========[/color]
  100.  
  101. FF - prefs.js..browser.search.defaultengine: "Google"
  102. FF - prefs.js..browser.search.defaultenginename: "Google"
  103. FF - prefs.js..browser.search.defaultenginename,S: S", "Search the web (Babylon)"
  104. FF - prefs.js..browser.search.order.1: "Ask.com"
  105. FF - prefs.js..browser.search.order.1,S: S", "Search the web (Babylon)"
  106. FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
  107. FF - prefs.js..browser.search.selectedEngine,S: S", "Search the web (Babylon)"
  108. FF - prefs.js..browser.startup.homepage: "http://www.google.hr/"
  109. FF - prefs.js..browser.startup.homepage: h", "h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,http://search.babylon.com/home?AF=17284"
  110. FF - prefs.js..keyword.URL,h: h", "http://search.babylon.com/?babsrc=KW_def&AF=17284&q="
  111.  
  112.  
  113. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
  114. FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
  115. FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
  116. FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll File not found
  117. FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
  118. FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
  119. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
  120. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
  121. FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
  122.  
  123. FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
  124. FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/12/16 09:38:08 | 000,000,000 | ---D | M]
  125. FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/19 18:30:45 | 000,000,000 | ---D | M]
  126. FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Bruno\AppData\Roaming\IDM\idmmzcc5
  127.  
  128. [2011/12/05 23:38:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bruno\AppData\Roaming\mozilla\Extensions
  129. [2012/03/09 23:31:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bruno\AppData\Roaming\mozilla\Firefox\Profiles\el669tnl.default\extensions
  130. [2012/03/03 12:46:21 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Bruno\AppData\Roaming\mozilla\Firefox\Profiles\el669tnl.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
  131. [2012/01/11 20:19:57 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Bruno\AppData\Roaming\mozilla\Firefox\Profiles\el669tnl.default\extensions\ffxtlbr@babylon.com
  132. [2011/11/17 20:25:44 | 000,002,333 | ---- | M] () -- C:\Users\Bruno\AppData\Roaming\Mozilla\Firefox\Profiles\el669tnl.default\searchplugins\askcom.xml
  133. [2012/01/11 20:15:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
  134. [2011/12/10 13:25:16 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
  135. [2012/03/19 18:30:45 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
  136. [2012/01/08 22:23:56 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
  137. [2012/01/11 18:52:46 | 000,002,226 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
  138. [2012/01/08 22:23:56 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
  139. [2012/01/08 22:23:56 | 000,000,769 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
  140. [2012/01/08 22:23:56 | 000,000,786 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eudict.xml
  141. [2012/02/03 21:05:28 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
  142. [2012/01/08 22:23:56 | 000,001,193 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-hr.xml
  143.  
  144. [color=#E56717]========== Chrome ==========[/color]
  145.  
  146. CHR - default_search_provider: Search the web (Babylon) (Enabled)
  147. CHR - default_search_provider: search_url = http://search.babylon.com/?q={searchTerms}&babsrc=SP_def&AF=17284
  148. CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
  149. CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\17.0.963.83\gcswf32.dll
  150. CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
  151. CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
  152. CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
  153. CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\17.0.963.83\ppGoogleNaClPluginChrome.dll
  154. CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\17.0.963.83\pdf.dll
  155. CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
  156. CHR - plugin: Default Plug-in (Enabled) = default_plugin
  157. CHR - Extension: YouTube = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
  158. CHR - Extension: Google Search = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.18_0\
  159. CHR - Extension: Skype Click to Call = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
  160. CHR - Extension: Facebook Notifications = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0\
  161. CHR - Extension: Gmail = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
  162. CHR - Extension: Browser QuickLinks = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\plpjogfhobhpdcmcblieglnoooccfcmm\1.4_0\
  163.  
  164. O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
  165. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
  166. O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
  167. O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
  168. O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
  169. O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
  170. O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
  171. O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
  172. O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
  173. O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
  174. O4 - HKLM..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe (Simply Super Software)
  175. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
  176. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
  177. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
  178. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
  179. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
  180. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
  181. O8:[b]64bit:[/b] - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
  182. O8:[b]64bit:[/b] - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
  183. O8:[b]64bit:[/b] - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
  184. O8:[b]64bit:[/b] - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
  185. O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
  186. O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
  187. O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
  188. O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
  189. O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
  190. O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
  191. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
  192. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
  193. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
  194. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
  195. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
  196. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
  197. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
  198. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
  199. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
  200. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
  201. O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\pnrpnsp.dll File not found
  202. O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\pnrpnsp.dll File not found
  203. O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\pnrpnsp.dll File not found
  204. O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\pnrpnsp.dll File not found
  205. O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\pnrpnsp.dll File not found
  206. O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\pnrpnsp.dll File not found
  207. O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\pnrpnsp.dll File not found
  208. O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\pnrpnsp.dll File not found
  209. O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\pnrpnsp.dll File not found
  210. O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\pnrpnsp.dll File not found
  211. O13[b]64bit:[/b] - gopher Prefix: missing
  212. O13 - gopher Prefix: missing
  213. O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
  214. O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
  215. O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
  216. O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
  217. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
  218. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{19F5CA04-D1BA-42D6-BB99-E5F4CE9A6DA9}: DhcpNameServer = 192.168.1.1
  219. O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found
  220. O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
  221. O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
  222. O18:[b]64bit:[/b] - Protocol\Handler\skype-ie-addon-data - No CLSID value found
  223. O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
  224. O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
  225. O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
  226. O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
  227. O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
  228. O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found
  229. O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
  230. O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
  231. O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
  232. O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  233. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  234. O32 - HKLM CDRom: AutoRun - 1
  235. O32 - AutoRun File - [2010/07/31 01:48:44 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
  236. O32 - AutoRun File - [2002/01/30 15:59:48 | 000,000,031 | ---- | M] () - D:\autoexec.bat -- [ NTFS ]
  237. O34 - HKLM BootExecute: (autocheck autochk *)
  238. O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
  239. O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
  240. O35 - HKLM\..comfile [open] -- "%1" %*
  241. O35 - HKLM\..exefile [open] -- "%1" %*
  242. O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
  243. O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
  244. O37 - HKLM\...com [@ = comfile] -- "%1" %*
  245. O37 - HKLM\...exe [@ = exefile] -- "%1" %*
  246.  
  247. NetSvcs:[b]64bit:[/b] UxTuneUp - C:\Windows\SysNative\uxtuneup.dll (TuneUp Software)
  248. NetSvcs:[b]64bit:[/b] belmonitorservice - C:\Windows\SysNative\mindrepair.dll (Iomega)
  249. NetSvcs:[b]64bit:[/b] AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
  250.  
  251. Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
  252. Drivers32:[b]64bit:[/b] VIDC.XFR1 - xfcodec64.dll ()
  253. Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
  254. Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
  255. Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
  256. Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
  257. Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
  258. Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
  259. Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
  260.  
  261. CREATERESTOREPOINT
  262. Restore point Set: OTL Restore Point
  263.  
  264. [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
  265.  
  266. [2012/03/27 20:59:45 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
  267. [2012/03/27 18:19:01 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Documents\My Cheat Tables
  268. [2012/03/27 18:18:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.1
  269. [2012/03/26 21:42:56 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Documents\Simply Super Software
  270. [2012/03/26 21:42:55 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
  271. [2012/03/26 21:42:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
  272. [2012/03/26 21:42:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover
  273. [2012/03/26 21:42:41 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Roaming\Simply Super Software
  274. [2012/03/26 21:42:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
  275. [2012/03/26 20:40:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Documents\RegRun2
  276. [2012/03/26 20:40:23 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\regruninfo
  277. [2012/03/26 20:40:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\UnHackMe
  278. [2012/03/26 16:40:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
  279. [2012/03/26 16:40:28 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
  280. [2012/03/26 16:40:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
  281. [2012/03/26 16:10:21 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Roaming\Malwarebytes
  282. [2012/03/26 16:10:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
  283. [2012/03/26 13:04:13 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
  284. [2012/03/26 12:59:16 | 000,000,000 | -HSD | C] -- C:\Users\Bruno\AppData\Local\670ec7e8
  285. [2012/03/25 14:52:54 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\IsolatedStorage
  286. [2012/03/25 14:51:02 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\Sublight_Labs
  287. [2012/03/19 15:13:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Documents\New Star Soccer 5
  288. [2012/03/15 19:56:41 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\Microsoft Games
  289. [2012/03/09 23:18:04 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Roaming\Gebenym
  290. [2012/03/09 23:18:04 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Roaming\Eki
  291. [2012/03/04 20:37:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Zylom
  292. [2012/03/04 20:37:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yahtzee
  293. [2012/03/04 20:36:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ReflexiveArcade
  294. [2012/03/03 16:41:05 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Zero G Registry
  295. [2012/03/03 16:40:03 | 000,000,000 | -H-D | C] -- C:\Users\Bruno\InstallAnywhere
  296. [2012/03/01 11:19:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
  297. [2012/03/01 11:19:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
  298.  
  299. [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
  300.  
  301. [2012/03/27 21:16:28 | 000,000,946 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
  302. [2012/03/27 21:00:16 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
  303. [2012/03/27 18:13:11 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
  304. [2012/03/27 18:13:11 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
  305. [2012/03/27 13:24:15 | 000,000,942 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
  306. [2012/03/27 13:23:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
  307. [2012/03/27 13:23:43 | 000,000,000 | -HS- | M] () -- C:\Windows\SysNative\dds_log_ad13.cmd
  308. [2012/03/27 12:31:40 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
  309. [2012/03/27 12:31:40 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
  310. [2012/03/27 12:31:40 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
  311. [2012/03/26 21:42:45 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
  312. [2012/03/26 16:40:30 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
  313. [2012/03/21 16:40:54 | 000,001,665 | ---- | M] () -- C:\Users\Bruno\AppData\Local\RT61_{19F5CA04-D1BA-42D6-BB99-E5F4CE9A6DA9}_prof
  314. [2012/03/21 16:40:53 | 000,000,837 | ---- | M] () -- C:\Users\Bruno\AppData\Local\RT61_{19F5CA04-D1BA-42D6-BB99-E5F4CE9A6DA9}_sta
  315. [2012/03/17 11:06:48 | 000,000,772 | ---- | M] () -- C:\Windows\Rtcwplat.INI
  316. [2012/03/07 22:47:17 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
  317. [2012/03/04 23:58:49 | 000,914,280 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
  318. [2012/03/04 18:03:32 | 000,140,871 | ---- | M] () -- C:\Windows\FontData.fdb
  319.  
  320. [color=#E56717]========== Files Created - No Company Name ==========[/color]
  321.  
  322. [2012/03/26 21:42:45 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
  323. [2012/03/26 21:42:43 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\UNRAR3.dll
  324. [2012/03/26 21:42:43 | 000,075,264 | ---- | C] () -- C:\Windows\SysWow64\unacev2.dll
  325. [2012/03/26 16:40:30 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
  326. [2012/03/26 13:00:26 | 000,000,000 | -HS- | C] () -- C:\Windows\SysNative\dds_log_ad13.cmd
  327. [2012/03/17 11:06:46 | 000,000,772 | ---- | C] () -- C:\Windows\Rtcwplat.INI
  328. [2012/02/12 18:40:29 | 000,000,540 | ---- | C] () -- C:\Windows\eReg.dat
  329. [2012/02/04 16:45:33 | 000,051,270 | ---- | C] () -- C:\Users\Bruno\AppData\Roaming\room_v3.dat
  330. [2012/01/26 19:48:20 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
  331. [2012/01/22 16:44:27 | 000,000,116 | -H-- | C] () -- C:\ProgramData\msadoex.dll
  332. [2012/01/21 16:35:19 | 000,000,046 | ---- | C] () -- C:\Windows\SysWow64\E302AF636FDE.ini
  333. [2012/01/13 22:12:29 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
  334. [2011/12/16 16:14:20 | 000,010,752 | ---- | C] () -- C:\Windows\SysWow64\BASSMOD.dll
  335. [2011/12/11 01:00:32 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
  336. [2011/12/11 01:00:31 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
  337. [2011/12/11 01:00:30 | 000,790,528 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
  338. [2011/12/11 01:00:30 | 000,134,144 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
  339. [2011/12/11 01:00:29 | 000,108,032 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
  340. [2011/12/09 20:39:14 | 000,000,144 | ---- | C] () -- C:\Windows\SysWow64\lkfl.dat
  341. [2011/12/09 20:39:14 | 000,000,128 | ---- | C] () -- C:\Windows\SysWow64\pdfl.dat
  342. [2011/12/09 20:39:14 | 000,000,080 | ---- | C] () -- C:\Windows\SysWow64\ibfl.dat
  343. [2011/12/09 16:55:43 | 000,000,162 | ---- | C] () -- C:\Windows\ODBC.INI
  344. [2011/12/06 07:20:19 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
  345. [2011/12/05 23:34:01 | 000,000,837 | ---- | C] () -- C:\Users\Bruno\AppData\Local\RT61_{19F5CA04-D1BA-42D6-BB99-E5F4CE9A6DA9}_sta
  346. [2011/12/05 23:33:15 | 000,001,665 | ---- | C] () -- C:\Users\Bruno\AppData\Local\RT61_{19F5CA04-D1BA-42D6-BB99-E5F4CE9A6DA9}_prof
  347.  
  348. [color=#E56717]========== LOP Check ==========[/color]
  349.  
  350. [2012/01/12 00:20:56 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\BSplayer PRO
  351. [2011/12/09 20:40:18 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\CheckPoint
  352. [2011/12/08 14:58:19 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\com.w3i.FlipToast
  353. [2011/12/07 21:27:21 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\DMCache
  354. [2012/03/09 23:25:16 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Eki
  355. [2012/03/26 16:17:26 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Gebenym
  356. [2011/12/10 21:59:29 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\MailFrontier
  357. [2012/03/26 21:42:41 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Simply Super Software
  358. [2012/03/26 20:09:09 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\TS3Client
  359. [2012/01/09 20:27:51 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\TuneUp Software
  360. [2011/12/24 19:29:16 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Xilisoft
  361. [2012/02/23 10:36:18 | 000,032,654 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
  362.  
  363. [color=#E56717]========== Purity Check ==========[/color]
  364.  
  365.  
  366.  
  367. [color=#E56717]========== Custom Scans ==========[/color]
  368.  
  369. [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
  370. [2010/07/31 01:48:44 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
  371. [2010/07/31 01:41:25 | 000,000,211 | -H-- | M] () -- C:\Boot.BAK
  372. [2011/12/06 07:16:49 | 000,000,355 | RHS- | M] () -- C:\Boot.ini.saved
  373. [2009/07/14 03:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
  374. [2011/12/06 07:16:51 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
  375. [2010/07/31 01:48:44 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
  376. [2009/08/02 10:59:51 | 000,171,136 | RHS- | M] () -- C:\grldr
  377. [2010/07/31 01:48:44 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
  378. [2012/02/26 10:10:52 | 000,000,000 | ---- | M] () -- C:\Log.txt
  379. [2010/07/31 01:48:44 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
  380. [2008/04/14 14:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
  381. [2008/04/14 14:00:00 | 000,250,048 | RHS- | M] () -- C:\ntldr
  382. [2012/03/27 13:23:39 | 3219,128,320 | -HS- | M] () -- C:\pagefile.sys
  383.  
  384. [color=#A23BEC]< %systemroot%\Fonts\*.com >[/color]
  385. [2009/07/14 07:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
  386. [2009/07/14 07:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
  387. [2009/07/14 07:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
  388. [2009/07/14 07:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
  389.  
  390. [color=#A23BEC]< %systemroot%\Fonts\*.dll >[/color]
  391.  
  392. [color=#A23BEC]< %systemroot%\Fonts\*.ini >[/color]
  393. [2009/06/10 22:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
  394.  
  395. [color=#A23BEC]< %systemroot%\Fonts\*.ini2 >[/color]
  396.  
  397. [color=#A23BEC]< %systemroot%\Fonts\*.exe >[/color]
  398.  
  399. [color=#A23BEC]< %systemroot%\system32\spool\prtprocs\w32x86\*.* >[/color]
  400.  
  401. [color=#A23BEC]< %systemroot%\REPAIR\*.bak1 >[/color]
  402.  
  403. [color=#A23BEC]< %systemroot%\REPAIR\*.ini >[/color]
  404.  
  405. [color=#A23BEC]< %systemroot%\system32\*.jpg >[/color]
  406.  
  407. [color=#A23BEC]< %systemroot%\*.jpg >[/color]
  408.  
  409. [color=#A23BEC]< %systemroot%\*.png >[/color]
  410.  
  411. [color=#A23BEC]< %systemroot%\*.scr >[/color]
  412.  
  413. [color=#A23BEC]< %systemroot%\*._sy >[/color]
  414.  
  415. [color=#A23BEC]< %APPDATA%\Adobe\Update\*.* >[/color]
  416.  
  417. [color=#A23BEC]< %ALLUSERSPROFILE%\Favorites\*.* >[/color]
  418.  
  419. [color=#A23BEC]< %APPDATA%\Microsoft\*.* >[/color]
  420.  
  421. [color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
  422. [2009/07/14 06:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
  423.  
  424. [color=#A23BEC]< %APPDATA%\Update\*.* >[/color]
  425.  
  426. [color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
  427.  
  428. [color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color]
  429.  
  430. [color=#A23BEC]< %PROGRAMFILES%\bak. /s >[/color]
  431.  
  432. [color=#A23BEC]< %systemroot%\system32\bak. /s >[/color]
  433.  
  434. [color=#A23BEC]< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >[/color]
  435.  
  436. [color=#A23BEC]< %systemroot%\system32\config\systemprofile\*.dat /x >[/color]
  437.  
  438. [color=#A23BEC]< %systemroot%\*.config >[/color]
  439.  
  440. [color=#A23BEC]< %systemroot%\system32\*.db >[/color]
  441.  
  442. [color=#A23BEC]< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >[/color]
  443. [2011/12/05 23:34:18 | 000,000,221 | -HS- | M] () -- C:\Users\Bruno\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
  444.  
  445. [color=#A23BEC]< %USERPROFILE%\Desktop\*.exe >[/color]
  446. [2012/03/27 21:00:16 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
  447.  
  448. [color=#A23BEC]< %PROGRAMFILES%\Common Files\*.* >[/color]
  449.  
  450. [color=#A23BEC]< %systemroot%\*.src >[/color]
  451.  
  452. [color=#A23BEC]< %systemroot%\install\*.* >[/color]
  453.  
  454. [color=#A23BEC]< %systemroot%\system32\DLL\*.* >[/color]
  455.  
  456. [color=#A23BEC]< %systemroot%\system32\HelpFiles\*.* >[/color]
  457.  
  458. [color=#A23BEC]< %systemroot%\system32\rundll\*.* >[/color]
  459.  
  460. [color=#A23BEC]< %systemroot%\winn32\*.* >[/color]
  461.  
  462. [color=#A23BEC]< %systemroot%\Java\*.* >[/color]
  463.  
  464. [color=#A23BEC]< %systemroot%\system32\test\*.* >[/color]
  465.  
  466. [color=#A23BEC]< %systemroot%\system32\Rundll32\*.* >[/color]
  467.  
  468. [color=#A23BEC]< %systemroot%\AppPatch\Custom\*.* >[/color]
  469.  
  470. [color=#A23BEC]< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >[/color]
  471.  
  472. [color=#A23BEC]< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >[/color]
  473.  
  474. [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.tmp >[/color]
  475.  
  476. [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.dat >[/color]
  477.  
  478. [color=#A23BEC]< %USERPROFILE%\My Documents\*.exe >[/color]
  479.  
  480. [color=#A23BEC]< %USERPROFILE%\*.exe >[/color]
  481.  
  482. [color=#A23BEC]< %systemroot%\ADDINS\*.* >[/color]
  483. [2009/06/10 23:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
  484.  
  485. [color=#A23BEC]< %systemroot%\assembly\*.bak2 >[/color]
  486.  
  487. [color=#A23BEC]< %systemroot%\Config\*.* >[/color]
  488.  
  489. [color=#A23BEC]< %systemroot%\REPAIR\*.bak2 >[/color]
  490.  
  491. [color=#A23BEC]< %systemroot%\SECURITY\Database\*.sdb /x >[/color]
  492. [2011/12/06 07:27:13 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
  493. [2011/12/06 07:27:13 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
  494. [2011/12/06 07:21:12 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
  495. [2011/12/06 07:21:12 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
  496.  
  497. [color=#A23BEC]< %systemroot%\SYSTEM\*.bak2 >[/color]
  498.  
  499. [color=#A23BEC]< %systemroot%\Web\*.bak2 >[/color]
  500.  
  501. [color=#A23BEC]< %systemroot%\Driver Cache\*.* >[/color]
  502.  
  503. [color=#A23BEC]< %PROGRAMFILES%\Mozilla Firefox\0*.exe >[/color]
  504.  
  505. [color=#A23BEC]< %ProgramFiles%\Microsoft Common\*.* >[/color]
  506.  
  507. [color=#A23BEC]< %ProgramFiles%\TinyProxy. >[/color]
  508.  
  509. [color=#A23BEC]< %USERPROFILE%\Favorites\*.url /x >[/color]
  510. [2011/12/05 22:42:23 | 000,000,402 | -HS- | M] () -- C:\Users\Bruno\Favorites\desktop.ini
  511.  
  512. [color=#A23BEC]< %systemroot%\System32\Wbem\*.exe >[/color]
  513. [2009/07/14 03:14:24 | 000,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\mofcomp.exe
  514. [2009/07/14 03:14:45 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WinMgmt.exe
  515. [2009/07/14 03:14:46 | 000,115,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIADAP.exe
  516. [2009/07/14 03:14:46 | 000,395,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIC.exe
  517. [2009/07/14 03:14:47 | 000,254,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WmiPrvSE.exe
  518.  
  519. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >[/color]
  520.  
  521. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >[/color]
  522.  
  523. [color=#E56717]========== Alternate Data Streams ==========[/color]
  524.  
  525. @Alternate Data Stream - 209 bytes -> C:\ProgramData\TEMP:CB0AACC9
  526.  
  527. < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement