Advertisement
Guest User

Untitled

a guest
Aug 28th, 2011
90
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 62.58 KB | None | 0 0
  1. aOTL logfile created on: 28.8.2011. 18:58:22 - Run 1
  2. OTL by OldTimer - Version 3.2.26.6 Folder = C:\Users\Mateo\Desktop
  3. 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
  4. Internet Explorer (Version = 9.0.8112.16421)
  5. Locale: 0000041a | Country: Hrvatska | Language: HRV | Date Format: d.M.yyyy.
  6.  
  7. 4,00 Gb Total Physical Memory | 2,21 Gb Available Physical Memory | 55,30% Memory free
  8. 8,00 Gb Paging File | 6,11 Gb Available in Paging File | 76,46% Paging File free
  9. Paging file location(s): ?:\pagefile.sys [binary data]
  10.  
  11. %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
  12. Drive C: | 78,03 Gb Total Space | 12,76 Gb Free Space | 16,35% Space Free | Partition Type: NTFS
  13. Drive D: | 853,38 Gb Total Space | 2,30 Gb Free Space | 0,27% Space Free | Partition Type: NTFS
  14. Drive F: | 465,76 Gb Total Space | 455,45 Gb Free Space | 97,79% Space Free | Partition Type: NTFS
  15. Drive G: | 465,76 Gb Total Space | 208,82 Gb Free Space | 44,84% Space Free | Partition Type: NTFS
  16.  
  17. Computer Name: MATEO-PC | User Name: Mateo | Logged in as Administrator.
  18. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
  19. Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
  20.  
  21. [color=#E56717]========== Processes (SafeList) ==========[/color]
  22.  
  23. PRC - [2011.08.28 18:30:35 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Mateo\Desktop\OTL.exe
  24. PRC - [2011.08.22 21:44:36 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
  25. PRC - [2011.08.17 10:59:51 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
  26. PRC - [2011.08.02 03:58:18 | 000,140,952 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.21.65\GoogleCrashHandler.exe
  27. PRC - [2011.06.24 17:30:48 | 000,393,112 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
  28. PRC - [2011.04.22 15:08:52 | 000,801,680 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe
  29. PRC - [2011.04.22 15:08:52 | 000,402,832 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe
  30. PRC - [2011.04.22 15:08:52 | 000,352,656 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe
  31. PRC - [2011.03.31 16:08:14 | 000,080,896 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
  32. PRC - [2011.02.23 16:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
  33. PRC - [2011.02.23 16:04:19 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
  34. PRC - [2011.02.15 13:20:22 | 000,364,544 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
  35. PRC - [2010.07.21 23:31:10 | 001,916,928 | ---- | M] () -- C:\Program Files (x86)\ACSPMonitor\ASMonitor.exe
  36.  
  37.  
  38. [color=#E56717]========== Modules (No Company Name) ==========[/color]
  39.  
  40. MOD - [2011.08.17 10:59:51 | 001,846,232 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
  41. MOD - [2011.08.13 14:09:09 | 006,277,280 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
  42. MOD - [2011.04.22 15:08:54 | 000,347,024 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 4\madexcept_.bpl
  43. MOD - [2011.04.22 15:08:54 | 000,179,088 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 4\madbasic_.bpl
  44. MOD - [2011.04.22 15:08:54 | 000,046,480 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 4\maddisAsm_.bpl
  45. MOD - [2011.02.15 13:20:22 | 000,364,544 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
  46. MOD - [2011.02.15 13:20:08 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
  47. MOD - [2011.02.15 13:20:02 | 000,278,528 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
  48. MOD - [2011.02.15 13:19:44 | 000,229,376 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTCore.dll
  49. MOD - [2011.02.15 13:19:30 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTUI.dll
  50. MOD - [2011.02.15 13:19:20 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTFC.dll
  51. MOD - [2010.07.27 06:37:16 | 000,013,312 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTTSH.dll
  52. MOD - [2010.07.21 23:35:04 | 000,020,992 | ---- | M] () -- C:\Program Files (x86)\ACSPMonitor\hprog.dll
  53. MOD - [2010.07.21 23:34:44 | 000,018,944 | ---- | M] () -- C:\Program Files (x86)\ACSPMonitor\hk.dll
  54. MOD - [2010.07.21 23:31:10 | 001,916,928 | ---- | M] () -- C:\Program Files (x86)\ACSPMonitor\ASMonitor.exe
  55.  
  56.  
  57. [color=#E56717]========== Win32 Services (SafeList) ==========[/color]
  58.  
  59. SRV:[b]64bit:[/b] - [2011.04.20 04:04:18 | 000,203,776 | ---- | M] (AMD) [Disabled | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
  60. SRV:[b]64bit:[/b] - [2011.02.23 16:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
  61. SRV:[b]64bit:[/b] - [2010.09.22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
  62. SRV:[b]64bit:[/b] - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
  63. SRV:[b]64bit:[/b] - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
  64. SRV - [2011.08.24 13:12:51 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
  65. SRV - [2011.08.22 21:44:36 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
  66. SRV - [2011.08.04 14:34:48 | 002,329,480 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
  67. SRV - [2011.07.01 23:16:50 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
  68. SRV - [2011.06.24 17:30:48 | 000,393,112 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe -- (Application Updater)
  69. SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
  70. SRV - [2011.06.01 14:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
  71. SRV - [2011.04.22 15:08:52 | 000,352,656 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe -- (AdvancedSystemCareService)
  72. SRV - [2011.03.31 16:08:14 | 000,080,896 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
  73. SRV - [2011.03.01 18:29:58 | 000,130,976 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
  74. SRV - [2010.03.25 14:39:22 | 000,490,280 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
  75. SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
  76. SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
  77.  
  78.  
  79. [color=#E56717]========== Driver Services (SafeList) ==========[/color]
  80.  
  81. DRV:[b]64bit:[/b] - [2011.07.17 11:24:02 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
  82. DRV:[b]64bit:[/b] - [2011.07.17 11:24:02 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
  83. DRV:[b]64bit:[/b] - [2011.05.25 08:09:17 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
  84. DRV:[b]64bit:[/b] - [2011.05.14 19:40:23 | 000,236,544 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
  85. DRV:[b]64bit:[/b] - [2011.05.10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
  86. DRV:[b]64bit:[/b] - [2011.04.20 04:44:48 | 009,319,936 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
  87. DRV:[b]64bit:[/b] - [2011.04.20 04:44:48 | 009,319,936 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
  88. DRV:[b]64bit:[/b] - [2011.04.20 03:22:32 | 000,306,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
  89. DRV:[b]64bit:[/b] - [2011.04.16 13:01:51 | 000,027,176 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsemc.sys -- (ggsemc)
  90. DRV:[b]64bit:[/b] - [2011.04.16 13:01:51 | 000,013,352 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt)
  91. DRV:[b]64bit:[/b] - [2011.04.15 07:21:37 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
  92. DRV:[b]64bit:[/b] - [2011.03.30 20:46:44 | 000,114,704 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
  93. DRV:[b]64bit:[/b] - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
  94. DRV:[b]64bit:[/b] - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
  95. DRV:[b]64bit:[/b] - [2011.02.23 15:57:04 | 000,280,408 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
  96. DRV:[b]64bit:[/b] - [2011.02.23 15:57:01 | 000,505,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
  97. DRV:[b]64bit:[/b] - [2011.02.23 15:55:53 | 000,053,592 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
  98. DRV:[b]64bit:[/b] - [2011.02.23 15:55:13 | 000,031,064 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr.sys -- (aswRdr)
  99. DRV:[b]64bit:[/b] - [2011.02.23 15:55:05 | 000,064,344 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
  100. DRV:[b]64bit:[/b] - [2011.02.23 15:54:58 | 000,022,360 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
  101. DRV:[b]64bit:[/b] - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
  102. DRV:[b]64bit:[/b] - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
  103. DRV:[b]64bit:[/b] - [2010.11.20 13:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
  104. DRV:[b]64bit:[/b] - [2010.11.09 15:35:24 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
  105. DRV:[b]64bit:[/b] - [2010.06.25 16:08:10 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
  106. DRV:[b]64bit:[/b] - [2010.04.12 10:55:00 | 000,091,568 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
  107. DRV:[b]64bit:[/b] - [2010.03.18 11:00:40 | 000,041,040 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
  108. DRV:[b]64bit:[/b] - [2010.03.18 11:00:16 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
  109. DRV:[b]64bit:[/b] - [2010.03.18 11:00:00 | 000,063,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
  110. DRV:[b]64bit:[/b] - [2010.01.28 16:33:38 | 000,116,736 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
  111. DRV:[b]64bit:[/b] - [2009.12.30 12:21:24 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
  112. DRV:[b]64bit:[/b] - [2009.11.01 19:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
  113. DRV:[b]64bit:[/b] - [2009.07.23 00:22:43 | 000,358,144 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)
  114. DRV:[b]64bit:[/b] - [2009.07.23 00:22:41 | 000,066,304 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)
  115. DRV:[b]64bit:[/b] - [2009.07.23 00:20:23 | 000,187,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)
  116. DRV:[b]64bit:[/b] - [2009.07.23 00:20:23 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)
  117. DRV:[b]64bit:[/b] - [2009.07.23 00:20:19 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpcuxd.sys -- (vpcuxd)
  118. DRV:[b]64bit:[/b] - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
  119. DRV:[b]64bit:[/b] - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
  120. DRV:[b]64bit:[/b] - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
  121. DRV:[b]64bit:[/b] - [2009.07.14 02:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
  122. DRV:[b]64bit:[/b] - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
  123. DRV:[b]64bit:[/b] - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
  124. DRV:[b]64bit:[/b] - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
  125. DRV:[b]64bit:[/b] - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
  126. DRV:[b]64bit:[/b] - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
  127. DRV:[b]64bit:[/b] - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
  128. DRV:[b]64bit:[/b] - [2008.03.26 21:31:26 | 000,036,432 | ---- | M] (DemoForge, LLC) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dfmirage.sys -- (dfmirage)
  129. DRV:[b]64bit:[/b] - [2007.08.20 10:05:02 | 000,012,744 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Entech64.sys -- (ENTECH64)
  130. DRV:[b]64bit:[/b] - [2007.06.25 09:42:22 | 000,108,072 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s117bus.sys -- (s117bus) Sony Ericsson Device 117 driver (WDM)
  131. DRV:[b]64bit:[/b] - [2007.05.11 03:12:06 | 000,038,160 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\blueletaudio.sys -- (BlueletAudio)
  132. DRV:[b]64bit:[/b] - [2007.05.09 02:00:58 | 000,044,688 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btcusb.sys -- (Btcsrusb)
  133. DRV:[b]64bit:[/b] - [2007.03.05 05:48:12 | 000,037,648 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
  134. DRV:[b]64bit:[/b] - [2007.03.05 05:47:08 | 000,025,360 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BtNetDrv.sys -- (BT)
  135. DRV:[b]64bit:[/b] - [2007.03.05 05:39:28 | 000,063,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VcommMgr.sys -- (VcommMgr)
  136. DRV:[b]64bit:[/b] - [2007.03.05 05:38:20 | 000,047,120 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VComm.sys -- (VComm)
  137. DRV - [2011.06.20 13:28:14 | 000,004,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\nocashio.sys -- (nocashio)
  138. DRV - [2010.05.27 02:43:00 | 000,014,648 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\MSI Afterburner\RTCore64.sys -- (RTCore64)
  139. DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
  140. DRV - [2007.05.11 03:12:06 | 000,038,160 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\blueletaudio.sys -- (BlueletAudio)
  141. DRV - [2007.05.09 02:00:58 | 000,044,688 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\btcusb.sys -- (Btcsrusb)
  142. DRV - [2007.03.05 05:48:12 | 000,037,648 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
  143. DRV - [2007.03.05 05:47:08 | 000,025,360 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\btnetdrv.sys -- (BT)
  144. DRV - [2007.03.05 05:42:54 | 000,049,680 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
  145. DRV - [2007.03.05 05:41:34 | 000,024,976 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\vbtenum.sys -- (BTHidEnum)
  146. DRV - [2007.03.05 05:39:28 | 000,063,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\VCommMgr.sys -- (VcommMgr)
  147. DRV - [2007.03.05 05:38:20 | 000,047,120 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\VComm.sys -- (VComm)
  148. DRV - [2004.06.22 15:44:50 | 000,005,632 | ---- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\Entech64.sys -- (ENTECH64)
  149.  
  150.  
  151. [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
  152.  
  153.  
  154. [color=#E56717]========== Internet Explorer ==========[/color]
  155.  
  156. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
  157.  
  158. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.hr/
  159. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
  160. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = hr
  161. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 31 26 11 70 AB F0 CB 01 [binary data]
  162. IE - HKCU\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.5\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
  163. IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  164. IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
  165.  
  166. [color=#E56717]========== FireFox ==========[/color]
  167.  
  168. FF - prefs.js..browser.search.defaultenginename: "Web Search..."
  169. FF - prefs.js..browser.search.useDBForOrder: true
  170. FF - prefs.js..browser.startup.homepage: "http://www.google.hr/"
  171. FF - prefs.js..keyword.URL: "http://vshare.toolbarhome.com/search.aspx?srch=ku&q="
  172.  
  173. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
  174. FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
  175. FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
  176. FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
  177. FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
  178. FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
  179. FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
  180. FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
  181. FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
  182. FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: File not found
  183. FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: File not found
  184. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
  185. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
  186. FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
  187. FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Mateo\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
  188.  
  189. FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files (x86)\Google\Google Gears\Firefox\ [2011.06.05 10:53:36 | 000,000,000 | ---D | M]
  190. FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011.07.17 15:41:51 | 000,000,000 | ---D | M]
  191. FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.08.17 10:59:51 | 000,000,000 | ---D | M]
  192. FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.08.10 16:07:57 | 000,000,000 | ---D | M]
  193.  
  194. [2011.08.09 13:31:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mateo\AppData\Roaming\Mozilla\Extensions
  195. [2011.08.09 13:23:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mateo\AppData\Roaming\Mozilla\Firefox\Profiles\77cuhd3z.default\extensions
  196. [2011.08.09 13:31:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mateo\AppData\Roaming\Mozilla\Firefox\Profiles\lzvjtc6w.default\extensions
  197. [2011.08.10 18:09:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
  198. [2011.08.10 18:09:14 | 000,000,000 | ---D | M] (Click to call with Skype) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
  199. [2011.04.14 21:29:36 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
  200. [2011.07.02 22:49:11 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
  201. [2011.08.17 10:59:51 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
  202. [2011.05.04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
  203. [2010.01.01 10:00:00 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
  204. [2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
  205. [2010.01.01 10:00:00 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
  206. [2010.01.01 10:00:00 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
  207. [2011.07.04 15:10:32 | 000,002,048 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml
  208. [2010.01.01 10:00:00 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
  209.  
  210. O1 HOSTS File: ([2011.07.01 23:19:58 | 000,000,857 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
  211. O1 - Hosts: 127.0.0.1 activate.adobe.com
  212. O2:[b]64bit:[/b] - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ()
  213. O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
  214. O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
  215. O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
  216. O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.5\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
  217. O3:[b]64bit:[/b] - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll ()
  218. O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
  219. O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.5\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
  220. O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
  221. O4 - HKCU..\Run: [1] C:\Users\Mateo\AppData\Local\Temp\wmplog05.sqv ()
  222. O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
  223. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
  224. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
  225. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: application = C:\Program Files (x86)\ACSPMonitor\ASMonitor.exe hs ()
  226. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
  227. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
  228. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
  229. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
  230. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
  231. O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
  232. O8:[b]64bit:[/b] - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm ()
  233. O8 - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\Savevid\redirect.htm ()
  234. O9 - Extra 'Tools' menuitem : &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
  235. O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
  236. O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
  237. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
  238. O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
  239. O13 - gopher Prefix: missing
  240. O13 - gopher Prefix: missing
  241. O16 - DPF: {173D9E48-B527-4AA0-A929-30B446002AA8} http://213.147.118.29:6055/DVRemoteAx.cab (DVRemoteControl Class)
  242. O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
  243. O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
  244. O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
  245. O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
  246. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
  247. O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
  248. O18:[b]64bit:[/b] - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
  249. O18:[b]64bit:[/b] - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
  250. O18:[b]64bit:[/b] - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
  251. O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
  252. O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
  253. O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
  254. O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
  255. O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
  256. O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
  257. O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found
  258. O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
  259. O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
  260. O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
  261. O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
  262. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
  263. O32 - HKLM CDRom: AutoRun - 1
  264. O33 - MountPoints2\G\Shell - "" = AutoRun
  265. O33 - MountPoints2\H\Shell - "" = AutoRun
  266. O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\Setup.exe
  267. O33 - MountPoints2\I\Shell - "" = AutoRun
  268. O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\SETUP.EXE
  269. O33 - MountPoints2\J\Shell - "" = AutoRun
  270. O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\steambackup.exe
  271. O33 - MountPoints2\K\Shell - "" = AutoRun
  272. O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\SETUP.EXE
  273. O33 - MountPoints2\L\Shell - "" = AutoRun
  274. O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\SETUP.EXE
  275. O33 - MountPoints2\M\Shell - "" = AutoRun
  276. O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\SETUP.EXE
  277. O34 - HKLM BootExecute: (autocheck autochk *) - File not found
  278. O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
  279. O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
  280. O35 - HKLM\..comfile [open] -- "%1" %*
  281. O35 - HKLM\..exefile [open] -- "%1" %*
  282. O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
  283. O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
  284. O37 - HKLM\...com [@ = comfile] -- "%1" %*
  285. O37 - HKLM\...exe [@ = exefile] -- "%1" %*
  286.  
  287. NetSvcs:[b]64bit:[/b] AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
  288.  
  289. Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
  290. Drivers32:[b]64bit:[/b] VIDC.FPS1 - frapsv64.dll (Beepa P/L)
  291. Drivers32:[b]64bit:[/b] VIDC.XFR1 - xfcodec64.dll ()
  292. Drivers32: msacm.divxa32 - C:\Windows\SysWow64\msaud32_divx.acm (Microsoft Corporation)
  293. Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
  294. Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
  295. Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
  296. Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
  297. Drivers32: VIDC.RTV1 - rtvcvfw32.dll File not found
  298. Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
  299. Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
  300. Drivers32: VIDC.XFR1 - C:\Windows\SysWow64\xfcodec.dll ()
  301.  
  302. CREATERESTOREPOINT
  303. Restore point Set: OTL Restore Point
  304.  
  305. [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
  306.  
  307. [2011.08.28 18:21:50 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Users\Mateo\Desktop\OTL.exe
  308. [2011.08.28 17:39:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
  309. [2011.08.26 14:47:30 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Local\Ahead
  310. [2011.08.26 14:44:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Ahead
  311. [2011.08.22 15:36:34 | 000,000,000 | ---D | C] -- C:\Users\Mateo\Desktop\_minecraft beta 1.7.3_ns n00b edition
  312. [2011.08.22 15:36:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Minecraft Beta
  313. [2011.08.22 14:41:49 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
  314. [2011.08.22 14:41:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
  315. [2011.08.21 22:30:15 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LIMBO
  316. [2011.08.21 22:30:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LIMBO
  317. [2011.08.21 09:21:04 | 000,000,000 | ---D | C] -- C:\Users\Mateo\Desktop\snm_190b
  318. [2011.08.16 20:28:44 | 000,695,296 | ---- | C] (AnjoCaido) -- C:\Users\Mateo\Desktop\MinecraftSP.exe
  319. [2011.08.11 19:39:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
  320. [2011.08.11 13:27:58 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\.minecraft
  321. [2011.08.11 13:27:30 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\Minecraft
  322. [2011.08.11 08:19:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
  323. [2011.08.11 08:19:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
  324. [2011.08.10 20:09:38 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft Beta Cracked
  325. [2011.08.10 20:03:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft Beta
  326. [2011.08.10 16:45:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor
  327. [2011.08.10 16:45:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSI Kombustor
  328. [2011.08.10 16:29:29 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Local\Micro-Star_Int'l_Co.,_Ltd
  329. [2011.08.10 13:18:56 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Virtual PC
  330. [2011.08.10 12:14:46 | 000,000,000 | R--D | C] -- C:\Users\Mateo\Virtual Machines
  331. [2011.08.10 12:11:17 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Virtual PC
  332. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\zh-TW
  333. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\zh-CN
  334. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Virtual PC
  335. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\tr-TR
  336. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\th-TH
  337. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\sv-SE
  338. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\ru-RU
  339. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\ro-RO
  340. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\pt-PT
  341. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\pt-BR
  342. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\pl-PL
  343. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\nl-NL
  344. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\nb-NO
  345. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\ko-KR
  346. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\ja-JP
  347. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\it-IT
  348. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\hu-HU
  349. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\he-IL
  350. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\fr-FR
  351. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\fi-FI
  352. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\es-ES
  353. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\el-GR
  354. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\de-DE
  355. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\da-DK
  356. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\cs-CZ
  357. [2011.08.10 12:11:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\ar-SA
  358. [2011.08.10 11:47:38 | 000,000,000 | ---D | C] -- C:\CtJbFW
  359. [2011.08.10 11:37:28 | 000,000,000 | ---D | C] -- C:\Program Files\Creative
  360. [2011.08.10 11:19:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SWF Studio
  361. [2011.08.10 11:18:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
  362. [2011.08.10 11:17:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Creative
  363. [2011.08.09 19:55:32 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\go
  364. [2011.08.09 19:55:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Easybits GO
  365. [2011.08.09 17:40:52 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\DVRemote
  366. [2011.08.09 16:39:00 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\Malwarebytes
  367. [2011.08.09 16:38:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
  368. [2011.08.09 16:38:52 | 000,025,912 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
  369. [2011.08.09 12:51:23 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Local\WMTools Downloaded Files
  370. [2011.08.09 12:50:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Movie Maker
  371. [2011.08.09 12:50:27 | 000,000,000 | ---D | C] -- C:\Windows\RegisteredPackages
  372. [2011.08.09 12:26:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Movie Maker 2.6
  373. [2011.08.09 12:22:07 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Local\{40BBE863-FB8E-4A8F-B01C-84920A4C6CAB}
  374. [2011.08.09 12:20:12 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Local\{21644081-F2B3-4664-9EB7-B759D342BA9A}
  375. [2011.08.07 20:32:15 | 000,000,000 | ---D | C] -- C:\ProgramData\YouTube Downloader
  376. [2011.08.07 20:32:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Downloader
  377. [2011.08.07 20:32:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\YouTube Downloader
  378. [2011.08.07 20:08:57 | 000,000,000 | ---D | C] -- C:\Download
  379. [2011.08.07 20:08:11 | 000,000,000 | ---D | C] -- C:\tmpDownload
  380. [2011.08.07 20:08:05 | 000,000,000 | ---D | C] -- C:\YoutubeMusicDownloader
  381. [2011.08.06 19:22:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Futuremark
  382. [2011.08.06 19:21:46 | 000,000,000 | ---D | C] -- C:\Users\Mateo\Desktop\Benchmark
  383. [2011.08.05 20:52:00 | 000,000,000 | ---D | C] -- C:\Users\Mateo\Documents\3DMark 11
  384. [2011.08.05 16:22:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDInfoPro
  385. [2011.08.04 11:50:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\LogiShrd
  386. [2011.08.04 11:50:01 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\LogiShrd
  387. [2011.08.04 11:49:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Logishrd
  388. [2011.08.04 11:49:35 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\Logitech
  389. [2011.08.04 11:49:35 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\Logishrd
  390. [2011.08.04 11:45:05 | 000,000,000 | ---D | C] -- C:\Users\Mateo\Documents\DriverGenius
  391. [2011.08.04 11:44:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Genius Professional Edition
  392. [2011.08.04 11:44:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Driver-Soft
  393. [2011.08.02 19:30:37 | 000,000,000 | ---D | C] -- C:\Users\Mateo\Documents\OJOsoft Corporation
  394. [2011.08.02 09:02:18 | 000,000,000 | ---D | C] -- C:\Users\Mateo\.mobione
  395. [2011.08.01 19:16:04 | 000,000,000 | ---D | C] -- C:\Users\Mateo\Documents\call of juarez
  396. [2011.08.01 19:14:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft
  397. [2011.08.01 11:18:04 | 000,000,000 | ---D | C] -- C:\Users\Mateo\Documents\Call of Juarez - Bound in Blood
  398. [2011.07.31 15:47:02 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Suite
  399. [2011.07.31 14:07:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Bcgsoft
  400. [2011.07.31 14:05:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\The Game Creators
  401. [2011.07.31 14:05:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Game Creators
  402. [2011.07.31 13:21:29 | 000,000,000 | ---D | C] -- C:\Users\Mateo\AppData\Roaming\WindSolutions
  403. [2011.07.31 13:21:28 | 000,000,000 | ---D | C] -- C:\ProgramData\WindSolutions
  404. [2011.07.31 12:08:00 | 000,000,000 | ---D | C] -- C:\Windows\occache
  405. [2011.07.31 12:07:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Viewpoint
  406. [2011.07.31 12:07:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nullsoft
  407. [2011.07.31 12:07:41 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\AOL Downloads
  408. [2011.07.31 12:07:40 | 001,044,480 | ---- | C] (eHelp Corporation.) -- C:\Windows\SysWow64\roboex32.dll
  409. [2011.07.31 12:07:40 | 000,054,784 | ---- | C] (Blue Sky Software Corporation.) -- C:\Windows\SysWow64\Inetwh32.dll
  410. [2011.07.31 12:07:40 | 000,029,184 | ---- | C] (Blue Sky Software) -- C:\Windows\SysWow64\popup.ocx
  411. [2011.07.31 12:07:26 | 000,000,000 | ---D | C] -- C:\ProgramData\AOL
  412. [2011.07.31 12:07:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AOL
  413. [5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
  414. [26 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
  415.  
  416. [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
  417.  
  418. [2011.08.28 19:03:01 | 000,000,946 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
  419. [2011.08.28 18:38:41 | 002,328,078 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
  420. [2011.08.28 18:38:41 | 001,688,706 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
  421. [2011.08.28 18:38:41 | 000,006,592 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
  422. [2011.08.28 18:33:54 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job
  423. [2011.08.28 18:33:51 | 000,000,942 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
  424. [2011.08.28 18:33:42 | 000,000,412 | ---- | M] () -- C:\Windows\tasks\AWC Update.job
  425. [2011.08.28 18:33:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
  426. [2011.08.28 18:33:30 | 3220,578,304 | -HS- | M] () -- C:\hiberfil.sys
  427. [2011.08.28 18:32:54 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
  428. [2011.08.28 18:32:53 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
  429. [2011.08.28 18:30:35 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Mateo\Desktop\OTL.exe
  430. [2011.08.28 17:39:44 | 000,001,247 | ---- | M] () -- C:\Users\Public\Desktop\Quick Care.lnk
  431. [2011.08.28 17:39:44 | 000,001,225 | ---- | M] () -- C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
  432. [2011.08.28 13:18:37 | 000,000,039 | ---- | M] () -- C:\Windows\Irremote.ini
  433. [2011.08.26 17:28:04 | 000,043,062 | ---- | M] () -- C:\Windows\SysWow64\UserImages.bmp
  434. [2011.08.25 14:10:03 | 000,103,736 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
  435. [2011.08.25 14:10:03 | 000,103,736 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
  436. [2011.08.25 11:18:42 | 000,001,189 | ---- | M] () -- C:\Users\Mateo\AppData\Roaming\vso_ts_preview.xml
  437. [2011.08.25 10:49:14 | 000,123,392 | ---- | M] () -- C:\Users\Mateo\Desktop\Rango.cld
  438. [2011.08.24 10:56:25 | 000,214,520 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
  439. [2011.08.22 23:26:39 | 000,002,656 | ---- | M] () -- C:\Windows\SysWow64\io02.sys
  440. [2011.08.22 21:44:36 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
  441. [2011.08.22 15:33:24 | 003,017,480 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
  442. [2011.08.17 11:00:06 | 000,002,052 | ---- | M] () -- C:\Users\Mateo\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
  443. [2011.08.16 20:28:47 | 000,695,296 | ---- | M] (AnjoCaido) -- C:\Users\Mateo\Desktop\MinecraftSP.exe
  444. [2011.08.11 13:21:46 | 000,270,142 | ---- | M] () -- C:\Users\Mateo\AppData\Roaming\Minecraft.exe
  445. [2011.08.10 16:07:59 | 000,001,142 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
  446. [2011.08.09 13:29:09 | 054,571,196 | ---- | M] () -- C:\Users\Mateo\Desktop\Movie.avi
  447. [2011.08.09 12:53:08 | 000,012,800 | ---- | M] () -- C:\Users\Mateo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
  448. [2011.08.09 12:10:32 | 000,001,125 | -HS- | M] () -- C:\Windows\System\spy.lnk
  449. [2011.08.02 09:04:02 | 000,000,600 | ---- | M] () -- C:\Users\Mateo\AppData\Roaming\winscp.rnd
  450. [2011.07.31 12:17:12 | 000,000,002 | ---- | M] () -- C:\Windows\msoffice.ini
  451. [2011.07.31 12:11:55 | 000,000,814 | -H-- | M] () -- C:\IPH.PH
  452. [2011.07.31 12:07:09 | 000,000,335 | ---- | M] () -- C:\Windows\nsreg.dat
  453. [5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
  454. [26 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
  455.  
  456. [color=#E56717]========== Files Created - No Company Name ==========[/color]
  457.  
  458. [2011.08.28 17:39:44 | 000,001,247 | ---- | C] () -- C:\Users\Public\Desktop\Quick Care.lnk
  459. [2011.08.28 17:39:44 | 000,001,225 | ---- | C] () -- C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
  460. [2011.08.28 16:42:17 | 000,000,412 | ---- | C] () -- C:\Windows\tasks\AWC Update.job
  461. [2011.08.26 17:28:04 | 000,043,062 | ---- | C] () -- C:\Windows\SysWow64\UserImages.bmp
  462. [2011.08.26 14:44:59 | 000,000,039 | ---- | C] () -- C:\Windows\Irremote.ini
  463. [2011.08.25 10:49:14 | 000,123,392 | ---- | C] () -- C:\Users\Mateo\Desktop\Rango.cld
  464. [2011.08.21 09:21:20 | 000,002,656 | ---- | C] () -- C:\Windows\SysWow64\io02.sys
  465. [2011.08.11 13:24:09 | 000,270,142 | ---- | C] () -- C:\Users\Mateo\AppData\Roaming\Minecraft.exe
  466. [2011.08.10 14:04:12 | 000,149,504 | ---- | C] () -- C:\Windows\UNWISE.EXE
  467. [2011.08.09 19:55:32 | 000,001,686 | ---- | C] () -- C:\Users\Mateo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play games (EasyBits GO).lnk
  468. [2011.08.09 13:31:41 | 000,002,052 | ---- | C] () -- C:\Users\Mateo\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
  469. [2011.08.09 13:27:46 | 054,571,196 | ---- | C] () -- C:\Users\Mateo\Desktop\Movie.avi
  470. [2011.08.09 13:17:53 | 000,001,142 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
  471. [2011.08.09 12:26:56 | 000,002,507 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 2.6.lnk
  472. [2011.07.31 16:15:03 | 000,000,600 | ---- | C] () -- C:\Users\Mateo\AppData\Roaming\winscp.rnd
  473. [2011.07.31 12:17:12 | 000,000,002 | ---- | C] () -- C:\Windows\msoffice.ini
  474. [2011.07.31 12:07:10 | 000,000,814 | -H-- | C] () -- C:\IPH.PH
  475. [2011.07.26 21:08:02 | 000,001,189 | ---- | C] () -- C:\Users\Mateo\AppData\Roaming\vso_ts_preview.xml
  476. [2011.07.18 14:42:48 | 000,000,000 | ---- | C] () -- C:\Windows\EngineExe.INI
  477. [2011.07.18 14:05:23 | 000,000,000 | ---- | C] () -- C:\Windows\PanelExe.INI
  478. [2011.07.03 13:49:22 | 000,001,370 | ---- | C] () -- C:\Windows\wininit.ini
  479. [2011.06.27 15:33:04 | 000,000,990 | -HS- | C] () -- C:\Users\Mateo\AppData\Roaming\systemfl.$dk
  480. [2011.06.25 19:26:18 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
  481. [2011.06.24 13:09:40 | 000,000,267 | ---- | C] () -- C:\Windows\game.ini
  482. [2011.06.20 13:28:13 | 000,004,096 | ---- | C] () -- C:\Windows\SysWow64\drivers\nocashio.sys
  483. [2011.06.10 16:26:26 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat
  484. [2011.06.05 16:20:00 | 000,000,285 | ---- | C] () -- C:\Windows\EReg072.dat
  485. [2011.05.27 09:43:39 | 000,003,972 | ---- | C] () -- C:\Windows\SysWow64\drivers\PciBus.sys
  486. [2011.05.20 22:35:28 | 000,304,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
  487. [2011.04.15 06:56:58 | 000,000,108 | ---- | C] () -- C:\Windows\disney.ini
  488. [2011.04.15 06:56:41 | 000,000,194 | ---- | C] () -- C:\Windows\disneysy.ini
  489. [2011.04.14 22:37:41 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
  490. [2011.04.14 22:37:31 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
  491. [2011.04.14 22:37:23 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
  492. [2011.04.14 22:17:58 | 000,000,248 | ---- | C] () -- C:\Windows\SMM_HCEditor.INI
  493. [2011.04.14 22:11:51 | 000,012,800 | ---- | C] () -- C:\Users\Mateo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
  494. [2011.04.14 21:52:47 | 000,006,574 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
  495. [2011.04.13 21:59:14 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
  496. [2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
  497. [2011.04.08 16:17:50 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
  498. [2011.04.08 13:28:58 | 000,041,872 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
  499. [2011.04.05 16:44:51 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
  500. [2011.04.02 10:42:39 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
  501. [2011.04.01 22:41:49 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat
  502. [2011.04.01 18:55:00 | 000,007,605 | ---- | C] () -- C:\Users\Mateo\AppData\Local\Resmon.ResmonCfg
  503. [2011.04.01 18:20:16 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
  504. [2011.03.17 19:51:44 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
  505. [2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
  506. [2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
  507. [2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
  508. [2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
  509. [2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
  510. [2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
  511. [2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
  512. [2008.05.22 21:24:18 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\unrar_mpfc.dll
  513. [2006.10.09 00:29:22 | 000,032,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\BTNetFilter.sys
  514.  
  515. [color=#E56717]========== LOP Check ==========[/color]
  516.  
  517. [2011.08.13 02:09:29 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\.minecraft
  518. [2011.08.28 17:42:10 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Azureus
  519. [2011.06.08 16:28:08 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\BSplayer
  520. [2011.06.08 16:26:33 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\BSplayer Pro
  521. [2011.04.27 09:36:27 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Canon
  522. [2011.04.02 09:57:59 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\CD-LabelPrint
  523. [2011.04.01 22:20:19 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\com.w3i.FlipToast
  524. [2011.04.15 07:22:25 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\DAEMON Tools Lite
  525. [2011.07.02 11:38:30 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Day 1 Studios
  526. [2011.07.03 18:41:30 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Dev-Cpp
  527. [2011.05.22 12:15:37 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\DisneyInteractiveStudios
  528. [2011.05.14 19:56:11 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Drivers For Free
  529. [2011.08.09 17:40:52 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\DVRemote
  530. [2011.05.12 17:39:11 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\ESET
  531. [2011.07.26 12:35:44 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\GetRightToGo
  532. [2011.07.01 12:16:29 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\GlarySoft
  533. [2011.08.10 15:52:02 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\go
  534. [2011.07.03 12:29:29 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\HD Tune Pro
  535. [2011.07.18 13:37:03 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\HTC
  536. [2011.07.18 13:30:36 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
  537. [2011.04.02 16:16:26 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\ImgBurn
  538. [2011.06.04 16:28:58 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\InfraRecorder
  539. [2011.08.28 18:07:10 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\IObit
  540. [2011.05.01 17:04:03 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Leadertech
  541. [2011.08.11 13:27:31 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Minecraft
  542. [2011.07.18 13:03:15 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Mobile Action
  543. [2011.06.29 09:11:54 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Navigator
  544. [2011.06.11 15:25:18 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Need for Speed World
  545. [2011.07.18 13:37:03 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Outlook
  546. [2011.07.02 13:05:51 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\PowerRangers
  547. [2011.06.11 19:16:29 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Rovio
  548. [2011.06.27 19:09:17 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\runic games
  549. [2011.07.23 11:19:10 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Sierra Entertainment
  550. [2011.04.02 10:47:49 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Softplicity
  551. [2011.06.04 11:28:14 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\SystemRequirementsLab
  552. [2011.04.20 16:28:54 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\TeamViewer
  553. [2011.06.10 23:52:11 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Tunngle
  554. [2011.04.23 13:30:43 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Ubisoft
  555. [2011.06.26 19:47:30 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Unity
  556. [2011.08.28 16:38:49 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\uTorrent
  557. [2011.08.25 11:18:42 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\Vso
  558. [2011.07.31 15:46:54 | 000,000,000 | ---D | M] -- C:\Users\Mateo\AppData\Roaming\WindSolutions
  559. [2011.08.28 18:33:42 | 000,000,412 | ---- | M] () -- C:\Windows\Tasks\AWC Update.job
  560. [2011.08.28 18:33:54 | 000,000,324 | ---- | M] () -- C:\Windows\Tasks\GlaryInitialize.job
  561. [2011.08.28 07:13:03 | 000,032,646 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
  562.  
  563. [color=#E56717]========== Purity Check ==========[/color]
  564.  
  565.  
  566.  
  567. [color=#E56717]========== Custom Scans ==========[/color]
  568.  
  569.  
  570. [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
  571. [2010.11.20 14:40:07 | 000,383,786 | ---- | M] () -- C:\bootmgr
  572. [2011.08.28 18:33:30 | 3220,578,304 | -HS- | M] () -- C:\hiberfil.sys
  573. [2011.07.31 12:11:55 | 000,000,814 | -H-- | M] () -- C:\IPH.PH
  574. [2011.08.28 18:33:30 | 4294,107,136 | -HS- | M] () -- C:\pagefile.sys
  575.  
  576. [color=#A23BEC]< %systemroot%\Fonts\*.com >[/color]
  577. [2009.07.14 07:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
  578. [2009.07.14 07:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
  579. [2009.07.14 07:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
  580. [2009.07.14 07:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
  581.  
  582. [color=#A23BEC]< %systemroot%\Fonts\*.dll >[/color]
  583.  
  584. [color=#A23BEC]< %systemroot%\Fonts\*.ini >[/color]
  585. [2009.06.10 22:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
  586.  
  587. [color=#A23BEC]< %systemroot%\Fonts\*.ini2 >[/color]
  588.  
  589. [color=#A23BEC]< %systemroot%\Fonts\*.exe >[/color]
  590.  
  591. [color=#A23BEC]< %systemroot%\system32\spool\prtprocs\w32x86\*.* >[/color]
  592.  
  593. [color=#A23BEC]< %systemroot%\REPAIR\*.bak1 >[/color]
  594.  
  595. [color=#A23BEC]< %systemroot%\REPAIR\*.ini >[/color]
  596.  
  597. [color=#A23BEC]< %systemroot%\system32\*.jpg >[/color]
  598.  
  599. [color=#A23BEC]< %systemroot%\*.jpg >[/color]
  600.  
  601. [color=#A23BEC]< %systemroot%\*.png >[/color]
  602.  
  603. [color=#A23BEC]< %systemroot%\*.scr >[/color]
  604. [2011.02.23 16:04:21 | 000,040,648 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
  605. [5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
  606.  
  607. [color=#A23BEC]< %systemroot%\*._sy >[/color]
  608.  
  609. [color=#A23BEC]< %APPDATA%\Adobe\Update\*.* >[/color]
  610.  
  611. [color=#A23BEC]< %ALLUSERSPROFILE%\Favorites\*.* >[/color]
  612.  
  613. [color=#A23BEC]< %APPDATA%\Microsoft\*.* >[/color]
  614.  
  615. [color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
  616. [2011.08.28 18:20:32 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
  617.  
  618. [color=#A23BEC]< %APPDATA%\Update\*.* >[/color]
  619.  
  620. [color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
  621.  
  622. [color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color]
  623.  
  624. [color=#A23BEC]< %PROGRAMFILES%\bak. /s >[/color]
  625.  
  626. [color=#A23BEC]< %systemroot%\system32\bak. /s >[/color]
  627.  
  628. [color=#A23BEC]< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >[/color]
  629.  
  630. [color=#A23BEC]< %systemroot%\system32\config\systemprofile\*.dat /x >[/color]
  631.  
  632. [color=#A23BEC]< %systemroot%\*.config >[/color]
  633.  
  634. [color=#A23BEC]< %systemroot%\system32\*.db >[/color]
  635.  
  636. [color=#A23BEC]< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >[/color]
  637. [2011.04.11 22:52:23 | 000,000,221 | -HS- | M] () -- C:\Users\Mateo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
  638.  
  639. [color=#A23BEC]< %USERPROFILE%\Desktop\*.exe >[/color]
  640. [2011.08.16 20:28:47 | 000,695,296 | ---- | M] (AnjoCaido) -- C:\Users\Mateo\Desktop\MinecraftSP.exe
  641. [2011.08.28 18:30:35 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Mateo\Desktop\OTL.exe
  642.  
  643. [color=#A23BEC]< %PROGRAMFILES%\Common Files\*.* >[/color]
  644.  
  645. [color=#A23BEC]< %systemroot%\*.src >[/color]
  646.  
  647. [color=#A23BEC]< %systemroot%\install\*.* >[/color]
  648.  
  649. [color=#A23BEC]< %systemroot%\system32\DLL\*.* >[/color]
  650.  
  651. [color=#A23BEC]< %systemroot%\system32\HelpFiles\*.* >[/color]
  652.  
  653. [color=#A23BEC]< %systemroot%\system32\rundll\*.* >[/color]
  654.  
  655. [color=#A23BEC]< %systemroot%\winn32\*.* >[/color]
  656.  
  657. [color=#A23BEC]< %systemroot%\Java\*.* >[/color]
  658.  
  659. [color=#A23BEC]< %systemroot%\system32\test\*.* >[/color]
  660.  
  661. [color=#A23BEC]< %systemroot%\system32\Rundll32\*.* >[/color]
  662.  
  663. [color=#A23BEC]< %systemroot%\AppPatch\Custom\*.* >[/color]
  664.  
  665. [color=#A23BEC]< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >[/color]
  666.  
  667. [color=#A23BEC]< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >[/color]
  668.  
  669. [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.tmp >[/color]
  670.  
  671. [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.dat >[/color]
  672.  
  673. [color=#A23BEC]< %USERPROFILE%\My Documents\*.exe >[/color]
  674.  
  675. [color=#A23BEC]< %USERPROFILE%\*.exe >[/color]
  676.  
  677. [color=#A23BEC]< %systemroot%\ADDINS\*.* >[/color]
  678. [2009.06.10 23:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
  679.  
  680. [color=#A23BEC]< %systemroot%\assembly\*.bak2 >[/color]
  681.  
  682. [color=#A23BEC]< %systemroot%\Config\*.* >[/color]
  683.  
  684. [color=#A23BEC]< %systemroot%\REPAIR\*.bak2 >[/color]
  685.  
  686. [color=#A23BEC]< %systemroot%\SECURITY\Database\*.sdb /x >[/color]
  687.  
  688. [color=#A23BEC]< %systemroot%\SYSTEM\*.bak2 >[/color]
  689.  
  690. [color=#A23BEC]< %systemroot%\Web\*.bak2 >[/color]
  691.  
  692. [color=#A23BEC]< %systemroot%\Driver Cache\*.* >[/color]
  693.  
  694. [color=#A23BEC]< %PROGRAMFILES%\Mozilla Firefox\0*.exe >[/color]
  695.  
  696. [color=#A23BEC]< %ProgramFiles%\Microsoft Common\*.* >[/color]
  697.  
  698. [color=#A23BEC]< %ProgramFiles%\TinyProxy. >[/color]
  699.  
  700. [color=#A23BEC]< %USERPROFILE%\Favorites\*.url /x >[/color]
  701. [2011.04.01 23:42:38 | 000,000,402 | -HS- | M] () -- C:\Users\Mateo\Favorites\desktop.ini
  702.  
  703. [color=#A23BEC]< %systemroot%\System32\Wbem\*.exe >[/color]
  704. [2009.07.14 03:14:24 | 000,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\mofcomp.exe
  705. [2009.07.14 03:14:45 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WinMgmt.exe
  706. [2009.07.14 03:14:46 | 000,115,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIADAP.exe
  707. [2009.07.14 03:14:46 | 000,395,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIC.exe
  708. [2010.11.20 14:17:55 | 000,257,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WmiPrvSE.exe
  709.  
  710. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >[/color]
  711.  
  712. [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >[/color]
  713.  
  714. [color=#E56717]========== Alternate Data Streams ==========[/color]
  715.  
  716. @Alternate Data Stream - 368 bytes -> C:\Users\Mateo\AppData\Local\desktop.ini:722b2b1c349a06abf0e866180e5a7e63
  717.  
  718. < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement