Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 3/27/2012 9:18:14 PM - Run 2
- OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Bruno\Desktop
- 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
- Internet Explorer (Version = 8.0.7600.16385)
- Locale: 00000409 | Country: Croatia | Language: HRV | Date Format: d.M.yyyy.
- 2.00 Gb Total Physical Memory | 0.99 Gb Available Physical Memory | 49.74% Memory free
- 5.00 Gb Paging File | 3.91 Gb Available in Paging File | 78.15% Paging File free
- Paging file location(s): C:\pagefile.sys 3070 3070 [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
- Drive C: | 77.15 Gb Total Space | 50.55 Gb Free Space | 65.53% Space Free | Partition Type: NTFS
- Drive D: | 71.89 Gb Total Space | 63.38 Gb Free Space | 88.16% Space Free | Partition Type: NTFS
- Drive F: | 983.72 Mb Total Space | 40.48 Mb Free Space | 4.12% Space Free | Partition Type: FAT
- Computer Name: GREGOR | User Name: Bruno | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
- Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2012/03/27 21:00:16 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
- PRC - [2012/03/19 18:30:45 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- PRC - [2012/02/28 18:38:56 | 001,987,976 | ---- | M] (LogMeIn Inc.) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
- PRC - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
- PRC - [2012/01/13 14:53:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
- PRC - [2011/09/05 19:04:58 | 002,904,984 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
- PRC - [2009/07/24 20:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
- PRC - [2008/02/23 01:52:48 | 001,253,376 | ---- | M] (Ovislink Corp.) -- C:\Program Files (x86)\OVISLINK\Common\AirliveUI.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2012/03/19 18:30:44 | 001,969,080 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
- MOD - [2012/03/14 11:23:53 | 008,527,520 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
- MOD - [2009/07/14 03:15:51 | 000,232,448 | ---- | M] () -- \\?\globalroot\systemroot\syswow64\mswsock.DLL
- [color=#E56717]========== Win32 Services (SafeList) ==========[/color]
- SRV:[b]64bit:[/b] - [2010/12/14 15:39:14 | 000,036,160 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
- SRV:[b]64bit:[/b] - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
- SRV:[b]64bit:[/b] - [2009/07/14 03:39:46 | 000,005,120 | ---- | M] (Iomega) [Auto | Running] -- C:\Windows\SysNative\mindrepair.dll -- (belmonitorservice)
- SRV - [2012/02/28 18:38:54 | 002,343,816 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
- SRV - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
- SRV - [2011/08/23 22:34:24 | 004,729,616 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
- SRV - [2010/12/14 15:42:40 | 002,019,648 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
- SRV - [2010/12/14 15:39:10 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
- SRV - [2009/07/24 20:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
- SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV:[b]64bit:[/b] - [2011/12/10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
- DRV:[b]64bit:[/b] - [2011/05/06 15:30:50 | 000,019,936 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdrvio.sys -- (pwdrvio)
- DRV:[b]64bit:[/b] - [2011/05/06 15:30:46 | 000,013,280 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdspio.sys -- (pwdspio)
- DRV:[b]64bit:[/b] - [2009/07/14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
- DRV:[b]64bit:[/b] - [2009/07/14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
- DRV:[b]64bit:[/b] - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
- DRV:[b]64bit:[/b] - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
- DRV:[b]64bit:[/b] - [2009/07/14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
- DRV:[b]64bit:[/b] - [2009/07/14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
- DRV:[b]64bit:[/b] - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
- DRV:[b]64bit:[/b] - [2009/07/13 23:59:33 | 005,020,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
- DRV:[b]64bit:[/b] - [2009/06/10 22:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
- DRV:[b]64bit:[/b] - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
- DRV:[b]64bit:[/b] - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
- DRV:[b]64bit:[/b] - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
- DRV:[b]64bit:[/b] - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
- DRV:[b]64bit:[/b] - [2009/03/18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
- DRV:[b]64bit:[/b] - [2007/09/27 14:37:32 | 000,370,176 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr6164.sys -- (rt61x64)
- DRV - [2010/11/29 20:27:40 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
- DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
- DRV - [2005/01/04 11:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home?AF=17284
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = hr
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C0 7A 7A A7 95 B3 CC 01 [binary data]
- IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
- IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
- IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&babsrc=SP_def&AF=17284
- IE - HKCU\..\SearchScopes\{C24588AA-EB0C-48A1-B289-007A6BAB4096}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=FF&o=14594&src=crm&q={searchTerms}&locale=&apn_ptnrs=FV&apn_dtid=YYYYYYYYHR&apn_uid=51629682-d1a3-4c9a-907a-80c3c0b95e1d&apn_sauid=6FA2B757-1323-49E7-BFC3-67961FC6CD59&
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.defaultengine: "Google"
- FF - prefs.js..browser.search.defaultenginename: "Google"
- FF - prefs.js..browser.search.defaultenginename,S: S", "Search the web (Babylon)"
- FF - prefs.js..browser.search.order.1: "Ask.com"
- FF - prefs.js..browser.search.order.1,S: S", "Search the web (Babylon)"
- FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
- FF - prefs.js..browser.search.selectedEngine,S: S", "Search the web (Babylon)"
- FF - prefs.js..browser.startup.homepage: "http://www.google.hr/"
- FF - prefs.js..browser.startup.homepage: h", "h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,h,http://search.babylon.com/home?AF=17284"
- FF - prefs.js..keyword.URL,h: h", "http://search.babylon.com/?babsrc=KW_def&AF=17284&q="
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
- FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
- FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
- FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll File not found
- FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
- FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/12/16 09:38:08 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/19 18:30:45 | 000,000,000 | ---D | M]
- FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Bruno\AppData\Roaming\IDM\idmmzcc5
- [2011/12/05 23:38:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bruno\AppData\Roaming\mozilla\Extensions
- [2012/03/09 23:31:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bruno\AppData\Roaming\mozilla\Firefox\Profiles\el669tnl.default\extensions
- [2012/03/03 12:46:21 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Bruno\AppData\Roaming\mozilla\Firefox\Profiles\el669tnl.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
- [2012/01/11 20:19:57 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Bruno\AppData\Roaming\mozilla\Firefox\Profiles\el669tnl.default\extensions\ffxtlbr@babylon.com
- [2011/11/17 20:25:44 | 000,002,333 | ---- | M] () -- C:\Users\Bruno\AppData\Roaming\Mozilla\Firefox\Profiles\el669tnl.default\searchplugins\askcom.xml
- [2012/01/11 20:15:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
- [2011/12/10 13:25:16 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- [2012/03/19 18:30:45 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
- [2012/01/08 22:23:56 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
- [2012/01/11 18:52:46 | 000,002,226 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
- [2012/01/08 22:23:56 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
- [2012/01/08 22:23:56 | 000,000,769 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
- [2012/01/08 22:23:56 | 000,000,786 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eudict.xml
- [2012/02/03 21:05:28 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
- [2012/01/08 22:23:56 | 000,001,193 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-hr.xml
- [color=#E56717]========== Chrome ==========[/color]
- CHR - default_search_provider: Search the web (Babylon) (Enabled)
- CHR - default_search_provider: search_url = http://search.babylon.com/?q={searchTerms}&babsrc=SP_def&AF=17284
- CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
- CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\17.0.963.83\gcswf32.dll
- CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
- CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
- CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
- CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\17.0.963.83\ppGoogleNaClPluginChrome.dll
- CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\17.0.963.83\pdf.dll
- CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
- CHR - plugin: Default Plug-in (Enabled) = default_plugin
- CHR - Extension: YouTube = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
- CHR - Extension: Google Search = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.18_0\
- CHR - Extension: Skype Click to Call = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
- CHR - Extension: Facebook Notifications = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0\
- CHR - Extension: Gmail = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
- CHR - Extension: Browser QuickLinks = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\plpjogfhobhpdcmcblieglnoooccfcmm\1.4_0\
- O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
- O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
- O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
- O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
- O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
- O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
- O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
- O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
- O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
- O4 - HKLM..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe (Simply Super Software)
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
- O8:[b]64bit:[/b] - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
- O8:[b]64bit:[/b] - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
- O8:[b]64bit:[/b] - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
- O8:[b]64bit:[/b] - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
- O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
- O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
- O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
- O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
- O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\pnrpnsp.dll File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\pnrpnsp.dll File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\pnrpnsp.dll File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\pnrpnsp.dll File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\pnrpnsp.dll File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\pnrpnsp.dll File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\pnrpnsp.dll File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\pnrpnsp.dll File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\pnrpnsp.dll File not found
- O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\pnrpnsp.dll File not found
- O13[b]64bit:[/b] - gopher Prefix: missing
- O13 - gopher Prefix: missing
- O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
- O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
- O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
- O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{19F5CA04-D1BA-42D6-BB99-E5F4CE9A6DA9}: DhcpNameServer = 192.168.1.1
- O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\skype-ie-addon-data - No CLSID value found
- O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
- O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
- O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found
- O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
- O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O32 - HKLM CDRom: AutoRun - 1
- O32 - AutoRun File - [2010/07/31 01:48:44 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
- O32 - AutoRun File - [2002/01/30 15:59:48 | 000,000,031 | ---- | M] () - D:\autoexec.bat -- [ NTFS ]
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
- O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- NetSvcs:[b]64bit:[/b] UxTuneUp - C:\Windows\SysNative\uxtuneup.dll (TuneUp Software)
- NetSvcs:[b]64bit:[/b] belmonitorservice - C:\Windows\SysNative\mindrepair.dll (Iomega)
- NetSvcs:[b]64bit:[/b] AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
- Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
- Drivers32:[b]64bit:[/b] VIDC.XFR1 - xfcodec64.dll ()
- Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
- Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
- Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
- Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
- Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
- Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
- Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
- CREATERESTOREPOINT
- Restore point Set: OTL Restore Point
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2012/03/27 20:59:45 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
- [2012/03/27 18:19:01 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Documents\My Cheat Tables
- [2012/03/27 18:18:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.1
- [2012/03/26 21:42:56 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Documents\Simply Super Software
- [2012/03/26 21:42:55 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
- [2012/03/26 21:42:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
- [2012/03/26 21:42:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover
- [2012/03/26 21:42:41 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Roaming\Simply Super Software
- [2012/03/26 21:42:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
- [2012/03/26 20:40:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Documents\RegRun2
- [2012/03/26 20:40:23 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\regruninfo
- [2012/03/26 20:40:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\UnHackMe
- [2012/03/26 16:40:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
- [2012/03/26 16:40:28 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
- [2012/03/26 16:40:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
- [2012/03/26 16:10:21 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Roaming\Malwarebytes
- [2012/03/26 16:10:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
- [2012/03/26 13:04:13 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
- [2012/03/26 12:59:16 | 000,000,000 | -HSD | C] -- C:\Users\Bruno\AppData\Local\670ec7e8
- [2012/03/25 14:52:54 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\IsolatedStorage
- [2012/03/25 14:51:02 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\Sublight_Labs
- [2012/03/19 15:13:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Documents\New Star Soccer 5
- [2012/03/15 19:56:41 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\Microsoft Games
- [2012/03/09 23:18:04 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Roaming\Gebenym
- [2012/03/09 23:18:04 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Roaming\Eki
- [2012/03/04 20:37:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Zylom
- [2012/03/04 20:37:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yahtzee
- [2012/03/04 20:36:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ReflexiveArcade
- [2012/03/03 16:41:05 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Zero G Registry
- [2012/03/03 16:40:03 | 000,000,000 | -H-D | C] -- C:\Users\Bruno\InstallAnywhere
- [2012/03/01 11:19:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
- [2012/03/01 11:19:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2012/03/27 21:16:28 | 000,000,946 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
- [2012/03/27 21:00:16 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
- [2012/03/27 18:13:11 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- [2012/03/27 18:13:11 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- [2012/03/27 13:24:15 | 000,000,942 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
- [2012/03/27 13:23:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2012/03/27 13:23:43 | 000,000,000 | -HS- | M] () -- C:\Windows\SysNative\dds_log_ad13.cmd
- [2012/03/27 12:31:40 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
- [2012/03/27 12:31:40 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
- [2012/03/27 12:31:40 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
- [2012/03/26 21:42:45 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
- [2012/03/26 16:40:30 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
- [2012/03/21 16:40:54 | 000,001,665 | ---- | M] () -- C:\Users\Bruno\AppData\Local\RT61_{19F5CA04-D1BA-42D6-BB99-E5F4CE9A6DA9}_prof
- [2012/03/21 16:40:53 | 000,000,837 | ---- | M] () -- C:\Users\Bruno\AppData\Local\RT61_{19F5CA04-D1BA-42D6-BB99-E5F4CE9A6DA9}_sta
- [2012/03/17 11:06:48 | 000,000,772 | ---- | M] () -- C:\Windows\Rtcwplat.INI
- [2012/03/07 22:47:17 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
- [2012/03/04 23:58:49 | 000,914,280 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
- [2012/03/04 18:03:32 | 000,140,871 | ---- | M] () -- C:\Windows\FontData.fdb
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2012/03/26 21:42:45 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
- [2012/03/26 21:42:43 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\UNRAR3.dll
- [2012/03/26 21:42:43 | 000,075,264 | ---- | C] () -- C:\Windows\SysWow64\unacev2.dll
- [2012/03/26 16:40:30 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
- [2012/03/26 13:00:26 | 000,000,000 | -HS- | C] () -- C:\Windows\SysNative\dds_log_ad13.cmd
- [2012/03/17 11:06:46 | 000,000,772 | ---- | C] () -- C:\Windows\Rtcwplat.INI
- [2012/02/12 18:40:29 | 000,000,540 | ---- | C] () -- C:\Windows\eReg.dat
- [2012/02/04 16:45:33 | 000,051,270 | ---- | C] () -- C:\Users\Bruno\AppData\Roaming\room_v3.dat
- [2012/01/26 19:48:20 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
- [2012/01/22 16:44:27 | 000,000,116 | -H-- | C] () -- C:\ProgramData\msadoex.dll
- [2012/01/21 16:35:19 | 000,000,046 | ---- | C] () -- C:\Windows\SysWow64\E302AF636FDE.ini
- [2012/01/13 22:12:29 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
- [2011/12/16 16:14:20 | 000,010,752 | ---- | C] () -- C:\Windows\SysWow64\BASSMOD.dll
- [2011/12/11 01:00:32 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
- [2011/12/11 01:00:31 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
- [2011/12/11 01:00:30 | 000,790,528 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
- [2011/12/11 01:00:30 | 000,134,144 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
- [2011/12/11 01:00:29 | 000,108,032 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
- [2011/12/09 20:39:14 | 000,000,144 | ---- | C] () -- C:\Windows\SysWow64\lkfl.dat
- [2011/12/09 20:39:14 | 000,000,128 | ---- | C] () -- C:\Windows\SysWow64\pdfl.dat
- [2011/12/09 20:39:14 | 000,000,080 | ---- | C] () -- C:\Windows\SysWow64\ibfl.dat
- [2011/12/09 16:55:43 | 000,000,162 | ---- | C] () -- C:\Windows\ODBC.INI
- [2011/12/06 07:20:19 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
- [2011/12/05 23:34:01 | 000,000,837 | ---- | C] () -- C:\Users\Bruno\AppData\Local\RT61_{19F5CA04-D1BA-42D6-BB99-E5F4CE9A6DA9}_sta
- [2011/12/05 23:33:15 | 000,001,665 | ---- | C] () -- C:\Users\Bruno\AppData\Local\RT61_{19F5CA04-D1BA-42D6-BB99-E5F4CE9A6DA9}_prof
- [color=#E56717]========== LOP Check ==========[/color]
- [2012/01/12 00:20:56 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\BSplayer PRO
- [2011/12/09 20:40:18 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\CheckPoint
- [2011/12/08 14:58:19 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\com.w3i.FlipToast
- [2011/12/07 21:27:21 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\DMCache
- [2012/03/09 23:25:16 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Eki
- [2012/03/26 16:17:26 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Gebenym
- [2011/12/10 21:59:29 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\MailFrontier
- [2012/03/26 21:42:41 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Simply Super Software
- [2012/03/26 20:09:09 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\TS3Client
- [2012/01/09 20:27:51 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\TuneUp Software
- [2011/12/24 19:29:16 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Xilisoft
- [2012/02/23 10:36:18 | 000,032,654 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Custom Scans ==========[/color]
- [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
- [2010/07/31 01:48:44 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
- [2010/07/31 01:41:25 | 000,000,211 | -H-- | M] () -- C:\Boot.BAK
- [2011/12/06 07:16:49 | 000,000,355 | RHS- | M] () -- C:\Boot.ini.saved
- [2009/07/14 03:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
- [2011/12/06 07:16:51 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
- [2010/07/31 01:48:44 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
- [2009/08/02 10:59:51 | 000,171,136 | RHS- | M] () -- C:\grldr
- [2010/07/31 01:48:44 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
- [2012/02/26 10:10:52 | 000,000,000 | ---- | M] () -- C:\Log.txt
- [2010/07/31 01:48:44 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
- [2008/04/14 14:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
- [2008/04/14 14:00:00 | 000,250,048 | RHS- | M] () -- C:\ntldr
- [2012/03/27 13:23:39 | 3219,128,320 | -HS- | M] () -- C:\pagefile.sys
- [color=#A23BEC]< %systemroot%\Fonts\*.com >[/color]
- [2009/07/14 07:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
- [2009/07/14 07:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
- [2009/07/14 07:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
- [2009/07/14 07:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
- [color=#A23BEC]< %systemroot%\Fonts\*.dll >[/color]
- [color=#A23BEC]< %systemroot%\Fonts\*.ini >[/color]
- [2009/06/10 22:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
- [color=#A23BEC]< %systemroot%\Fonts\*.ini2 >[/color]
- [color=#A23BEC]< %systemroot%\Fonts\*.exe >[/color]
- [color=#A23BEC]< %systemroot%\system32\spool\prtprocs\w32x86\*.* >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.bak1 >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.ini >[/color]
- [color=#A23BEC]< %systemroot%\system32\*.jpg >[/color]
- [color=#A23BEC]< %systemroot%\*.jpg >[/color]
- [color=#A23BEC]< %systemroot%\*.png >[/color]
- [color=#A23BEC]< %systemroot%\*.scr >[/color]
- [color=#A23BEC]< %systemroot%\*._sy >[/color]
- [color=#A23BEC]< %APPDATA%\Adobe\Update\*.* >[/color]
- [color=#A23BEC]< %ALLUSERSPROFILE%\Favorites\*.* >[/color]
- [color=#A23BEC]< %APPDATA%\Microsoft\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
- [2009/07/14 06:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
- [color=#A23BEC]< %APPDATA%\Update\*.* >[/color]
- [color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
- [color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\bak. /s >[/color]
- [color=#A23BEC]< %systemroot%\system32\bak. /s >[/color]
- [color=#A23BEC]< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >[/color]
- [color=#A23BEC]< %systemroot%\system32\config\systemprofile\*.dat /x >[/color]
- [color=#A23BEC]< %systemroot%\*.config >[/color]
- [color=#A23BEC]< %systemroot%\system32\*.db >[/color]
- [color=#A23BEC]< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >[/color]
- [2011/12/05 23:34:18 | 000,000,221 | -HS- | M] () -- C:\Users\Bruno\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
- [color=#A23BEC]< %USERPROFILE%\Desktop\*.exe >[/color]
- [2012/03/27 21:00:16 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
- [color=#A23BEC]< %PROGRAMFILES%\Common Files\*.* >[/color]
- [color=#A23BEC]< %systemroot%\*.src >[/color]
- [color=#A23BEC]< %systemroot%\install\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\DLL\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\HelpFiles\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\rundll\*.* >[/color]
- [color=#A23BEC]< %systemroot%\winn32\*.* >[/color]
- [color=#A23BEC]< %systemroot%\Java\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\test\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\Rundll32\*.* >[/color]
- [color=#A23BEC]< %systemroot%\AppPatch\Custom\*.* >[/color]
- [color=#A23BEC]< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.tmp >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.dat >[/color]
- [color=#A23BEC]< %USERPROFILE%\My Documents\*.exe >[/color]
- [color=#A23BEC]< %USERPROFILE%\*.exe >[/color]
- [color=#A23BEC]< %systemroot%\ADDINS\*.* >[/color]
- [2009/06/10 23:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
- [color=#A23BEC]< %systemroot%\assembly\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Config\*.* >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\SECURITY\Database\*.sdb /x >[/color]
- [2011/12/06 07:27:13 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
- [2011/12/06 07:27:13 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
- [2011/12/06 07:21:12 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
- [2011/12/06 07:21:12 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
- [color=#A23BEC]< %systemroot%\SYSTEM\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Web\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Driver Cache\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Mozilla Firefox\0*.exe >[/color]
- [color=#A23BEC]< %ProgramFiles%\Microsoft Common\*.* >[/color]
- [color=#A23BEC]< %ProgramFiles%\TinyProxy. >[/color]
- [color=#A23BEC]< %USERPROFILE%\Favorites\*.url /x >[/color]
- [2011/12/05 22:42:23 | 000,000,402 | -HS- | M] () -- C:\Users\Bruno\Favorites\desktop.ini
- [color=#A23BEC]< %systemroot%\System32\Wbem\*.exe >[/color]
- [2009/07/14 03:14:24 | 000,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\mofcomp.exe
- [2009/07/14 03:14:45 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WinMgmt.exe
- [2009/07/14 03:14:46 | 000,115,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIADAP.exe
- [2009/07/14 03:14:46 | 000,395,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIC.exe
- [2009/07/14 03:14:47 | 000,254,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WmiPrvSE.exe
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >[/color]
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >[/color]
- [color=#E56717]========== Alternate Data Streams ==========[/color]
- @Alternate Data Stream - 209 bytes -> C:\ProgramData\TEMP:CB0AACC9
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement