Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL Extras logfile created on: 1/23/2017 12:44:58 PM - Run 1
- OTL by OldTimer - Version 3.2.69.0 Folder = D:\
- 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
- Internet Explorer (Version = 8.0.7601.17514)
- Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
- 3.87 Gb Total Physical Memory | 1.28 Gb Available Physical Memory | 33.07% Memory free
- 7.75 Gb Paging File | 5.04 Gb Available in Paging File | 65.05% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
- Drive C: | 195.21 Gb Total Space | 164.70 Gb Free Space | 84.37% Space Free | Partition Type: NTFS
- Drive D: | 292.97 Gb Total Space | 273.30 Gb Free Space | 93.29% Space Free | Partition Type: NTFS
- Drive E: | 292.97 Gb Total Space | 292.87 Gb Free Space | 99.97% Space Free | Partition Type: NTFS
- Drive G: | 150.26 Gb Total Space | 144.04 Gb Free Space | 95.86% Space Free | Partition Type: NTFS
- Computer Name: GUNADI-PC | User Name: gunadi | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
- Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Extra Registry (SafeList) ==========[/color]
- [color=#E56717]========== File Associations ==========[/color]
- [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
- .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
- .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
- [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
- .html [@ = ChromeHTML] -- Reg Error: Key error. File not found
- [color=#E56717]========== Shell Spawning ==========[/color]
- [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
- batfile [open] -- "%1" %*
- cmdfile [open] -- "%1" %*
- comfile [open] -- "%1" %*
- exefile [open] -- "%1" %*
- helpfile [open] -- Reg Error: Key error.
- inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
- InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
- InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
- piffile [open] -- "%1" %*
- regfile [merge] -- Reg Error: Key error.
- scrfile [config] -- "%1"
- scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
- scrfile [open] -- "%1" /S
- txtfile [edit] -- Reg Error: Key error.
- Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
- Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
- Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
- Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
- Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
- Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
- Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
- Folder [explore] -- Reg Error: Value error.
- Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
- batfile [open] -- "%1" %*
- cmdfile [open] -- "%1" %*
- comfile [open] -- "%1" %*
- cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
- exefile [open] -- "%1" %*
- helpfile [open] -- Reg Error: Key error.
- inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
- piffile [open] -- "%1" %*
- regfile [merge] -- Reg Error: Key error.
- scrfile [config] -- "%1"
- scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
- scrfile [open] -- "%1" /S
- txtfile [edit] -- Reg Error: Key error.
- Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
- Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
- Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
- Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
- Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
- Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
- Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
- Folder [explore] -- Reg Error: Value error.
- Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
- [color=#E56717]========== Security Center Settings ==========[/color]
- [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
- "cval" = 1
- [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
- [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
- "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
- "AntiVirusOverride" = 0
- "AntiSpywareOverride" = 0
- "FirewallOverride" = 0
- [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
- [color=#E56717]========== Firewall Settings ==========[/color]
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
- "EnableFirewall" = 1
- "DisableNotifications" = 0
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
- "EnableFirewall" = 1
- "DisableNotifications" = 0
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
- "EnableFirewall" = 1
- "DisableNotifications" = 0
- [color=#E56717]========== Authorized Applications List ==========[/color]
- [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
- "{003E0F6F-AD52-490D-BFD2-5E106A062F3D}" = lport=137 | protocol=17 | dir=in | app=system |
- "{131C828D-4ED3-4AEB-842E-5E2F60B705A1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
- "{1B032173-C327-4E40-BAA6-899B0483C6A4}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
- "{21134D77-7B80-41A0-8235-1108A4CC9D76}" = lport=139 | protocol=6 | dir=in | app=system |
- "{22E4B9B2-B436-48B1-84FB-1AE8A4E38CAE}" = rport=137 | protocol=17 | dir=out | app=system |
- "{429D5E5B-C679-4DB4-B80A-9DDF2B83CD68}" = rport=139 | protocol=6 | dir=out | app=system |
- "{52C64C94-FCE0-48EB-B611-73E707F81BEE}" = lport=138 | protocol=17 | dir=in | app=system |
- "{720D3A76-0CDF-4741-BDDB-03BCE7B4F0DC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
- "{972C3FF3-8FD1-4032-8080-ACD1CB951BC2}" = rport=138 | protocol=17 | dir=out | app=system |
- "{AB16A163-A502-4432-97E4-9BAD884DF2E6}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
- "{B2B48118-4E49-438A-9A27-370FB7ED4F06}" = lport=445 | protocol=6 | dir=in | app=system |
- "{BBB5F5F1-D68F-459D-AB60-6CE7E8DFF7B9}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
- "{D67F1132-60C7-41AA-8D2F-9FDFF00AF3C7}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
- "{DE079644-D731-4CE2-9459-FA7963E8A3B0}" = lport=1688 | protocol=6 | dir=in | app=c:\windows\kms-r@1n.exe |
- "{F0A08C7E-0283-424A-8582-E35B727E97A0}" = rport=445 | protocol=6 | dir=out | app=system |
- "{F2EA3381-BA94-47E0-BFD0-840D20E601D5}" = lport=1688 | protocol=6 | dir=out | app=c:\windows\kms-r@1n.exe |
- [color=#E56717]========== Vista Active Application Exception List ==========[/color]
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
- "{334BFA3E-F054-467B-B9D2-EBC644F3CA14}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
- "{3E2460F9-168A-4769-AFB6-496E6B9EE98C}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
- "{4B225CCE-C2F6-415B-B54B-F0491EE1A055}" = dir=in | app=c:\program files (x86)\firefox\firefox.exe |
- "{4F4A7B4F-C7E3-45A0-9679-B649E10D54E3}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
- "{6646940B-2999-43C0-AEDC-BF43973EC873}" = dir=in | app=c:\program files (x86)\applefat\application\chrome.exe |
- "{7FAD5BC3-EE8B-4B43-80A9-054128A0D3B6}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
- "{B3A845F7-193B-46C0-9B4E-88A3BA271B2A}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
- "{B990B6EF-16EF-4FDA-AB82-539A68565FA4}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
- "{BBC7DE54-1750-4AE2-A1BA-05D373E7CEDA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
- "{C8523A72-A777-4278-90B8-446D4FA015F9}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
- "{D9C4C8CB-34E9-4FFD-90F5-AF3E34A092C4}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
- "{E31D8B46-24D2-43A8-B08D-4BFB34E7F057}" = dir=in | app=c:\program files (x86)\firefox\bin\firefoxupdate.exe |
- "{F72FB879-F297-4B88-82E6-7A73FACD9028}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
- "TCP Query User{57C5024B-9696-42D0-A5F5-DE3DB001C68D}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
- "TCP Query User{5B7F6A68-9C90-4A3F-AC93-BB98FB5FE68B}C:\program files (x86)\amulec2\amule.exe" = protocol=6 | dir=in | app=c:\program files (x86)\amulec2\amule.exe |
- "UDP Query User{1FB20A16-8B77-45B7-9CA2-F9F3E17059FB}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
- "UDP Query User{9FEC9F86-16FB-4DA6-AE6D-F491BE840AB4}C:\program files (x86)\amulec2\amule.exe" = protocol=17 | dir=in | app=c:\program files (x86)\amulec2\amule.exe |
- [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
- 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
- "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
- "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
- "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
- "{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
- "{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
- "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
- "{9EA981E5-EE67-4662-86F1-58937D31FE07}" = Nitro Reader 3
- "{B5E06417-A4AC-4225-B36E-7E34C91616E7}" = Intel® Trusted Connect Service Client
- "CPUID CPU-Z_is1" = CPUID CPU-Z 1.78
- "EPSON L120 Series" = EPSON L120 Series Printer Uninstall
- "PerformanceTest 7_is1" = PerformanceTest v7.0 (64-bit)
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
- "{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver
- "{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
- "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
- "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
- "{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1" = SMADAV version 11.1
- "{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1" = Zemana AntiMalware
- "{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
- "{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
- "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
- "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
- "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
- "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
- "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
- "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
- "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
- "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
- "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
- "{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
- "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
- "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
- "{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
- "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
- "{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
- "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
- "{DADC7AB0-E554-4705-9F6A-83EA82ED708E}" = Realtek Ethernet Diagnostic Utility
- "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
- "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
- "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
- "AVG Secure Search" = AVG Security Toolbar
- "BlueStacks" = BlueStacks App Player
- "GOM Player" = GOM Player
- "Google Chrome" = Google Chrome
- "Hard Disk Sentinel_is1" = Hard Disk Sentinel PRO
- "iSafe" = YAC(Yet Another Cleaner!)
- "KLiteCodecPack_is1" = K-Lite Codec Pack 6.9.0 (Basic)
- "Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
- "Mozilla Firefox 43.0.1 (x86 en-US)" = Mozilla Firefox 43.0.1 (x86 en-US)
- "MozillaMaintenanceService" = Mozilla Maintenance Service
- "Office14.PROPLUS" = Microsoft Office Professional Plus 2010
- "PowerISO" = PowerISO
- "Winamp" = Winamp
- "WinRAR archiver" = WinRAR archiver
- [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
- "Winamp Detect" = Winamp Detector Plug-in
- [color=#E56717]========== Last 20 Event Log Errors ==========[/color]
- [ Application Events ]
- Error - 1/22/2017 9:13:00 PM | Computer Name = gunadi-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1500
- Description = Windows cannot log you on because your profile cannot be loaded. Check
- that you are connected to the network, and that your network is functioning correctly.
- DETAIL - The system cannot find the file specified.
- Error - 1/22/2017 9:13:08 PM | Computer Name = gunadi-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1500
- Description = Windows cannot log you on because your profile cannot be loaded. Check
- that you are connected to the network, and that your network is functioning correctly.
- DETAIL - The system cannot find the file specified.
- Error - 1/22/2017 9:13:17 PM | Computer Name = gunadi-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1500
- Description = Windows cannot log you on because your profile cannot be loaded. Check
- that you are connected to the network, and that your network is functioning correctly.
- DETAIL - The system cannot find the file specified.
- Error - 1/22/2017 9:13:45 PM | Computer Name = gunadi-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1500
- Description = Windows cannot log you on because your profile cannot be loaded. Check
- that you are connected to the network, and that your network is functioning correctly.
- DETAIL - The system cannot find the file specified.
- Error - 1/22/2017 9:13:56 PM | Computer Name = gunadi-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1500
- Description = Windows cannot log you on because your profile cannot be loaded. Check
- that you are connected to the network, and that your network is functioning correctly.
- DETAIL - The system cannot find the file specified.
- Error - 1/22/2017 9:14:28 PM | Computer Name = gunadi-PC | Source = WinMgmt | ID = 10
- Description =
- Error - 1/22/2017 9:14:45 PM | Computer Name = gunadi-PC | Source = Microsoft-Windows-User Profiles Service | ID = 1500
- Description = Windows cannot log you on because your profile cannot be loaded. Check
- that you are connected to the network, and that your network is functioning correctly.
- DETAIL - The system cannot find the file specified.
- Error - 1/22/2017 9:16:03 PM | Computer Name = gunadi-PC | Source = WinMgmt | ID = 10
- Description =
- Error - 1/22/2017 9:39:15 PM | Computer Name = gunadi-PC | Source = Customer Experience Improvement Program | ID = 1008
- Description =
- Error - 1/22/2017 9:49:09 PM | Computer Name = gunadi-PC | Source = WinMgmt | ID = 10
- Description =
- [ System Events ]
- Error - 1/22/2017 9:45:52 PM | Computer Name = gunadi-PC | Source = Service Control Manager | ID = 7034
- Description = The YAC Service service terminated unexpectedly. It has done this
- 1 time(s).
- Error - 1/22/2017 9:47:18 PM | Computer Name = gunadi-PC | Source = EventLog | ID = 6008
- Description = The previous system shutdown at 8:45:44 AM on ?1/?23/?2017 was unexpected.
- Error - 1/22/2017 9:47:18 PM | Computer Name = gunadi-PC | Source = Service Control Manager | ID = 7000
- Description = The YAC Service service failed to start due to the following error:
- %%2
- Error - 1/22/2017 9:47:25 PM | Computer Name = gunadi-PC | Source = Service Control Manager | ID = 7026
- Description = The following boot-start or system-start driver(s) failed to load:
- iSafeKrnlR3
- Error - 1/22/2017 9:55:14 PM | Computer Name = gunadi-PC | Source = Service Control Manager | ID = 7034
- Description = The iThemes5 service terminated unexpectedly. It has done this 1
- time(s).
- Error - 1/22/2017 9:55:14 PM | Computer Name = gunadi-PC | Source = Service Control Manager | ID = 7034
- Description = The ed2k idle service service terminated unexpectedly. It has done
- this 1 time(s).
- Error - 1/22/2017 9:55:15 PM | Computer Name = gunadi-PC | Source = Service Control Manager | ID = 7034
- Description = The Office Software Protection Platform service terminated unexpectedly.
- It has done this 1 time(s).
- Error - 1/22/2017 9:55:15 PM | Computer Name = gunadi-PC | Source = Service Control Manager | ID = 7031
- Description = The Update Service(FirefoxU) service terminated unexpectedly. It
- has done this 1 time(s). The following corrective action will be taken in 300000
- milliseconds: Restart the service.
- Error - 1/22/2017 9:55:15 PM | Computer Name = gunadi-PC | Source = Service Control Manager | ID = 7034
- Description = The KMS-R@1n service terminated unexpectedly. It has done this 1
- time(s).
- Error - 1/22/2017 10:00:15 PM | Computer Name = gunadi-PC | Source = Service Control Manager | ID = 7000
- Description = The Update Service(FirefoxU) service failed to start due to the following
- error: %%3
- < End of report >
- OTL logfile created on: 1/23/2017 12:44:58 PM - Run 1
- OTL by OldTimer - Version 3.2.69.0 Folder = D:\
- 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
- Internet Explorer (Version = 8.0.7601.17514)
- Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
- 3.87 Gb Total Physical Memory | 1.28 Gb Available Physical Memory | 33.07% Memory free
- 7.75 Gb Paging File | 5.04 Gb Available in Paging File | 65.05% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
- Drive C: | 195.21 Gb Total Space | 164.70 Gb Free Space | 84.37% Space Free | Partition Type: NTFS
- Drive D: | 292.97 Gb Total Space | 273.30 Gb Free Space | 93.29% Space Free | Partition Type: NTFS
- Drive E: | 292.97 Gb Total Space | 292.87 Gb Free Space | 99.97% Space Free | Partition Type: NTFS
- Drive G: | 150.26 Gb Total Space | 144.04 Gb Free Space | 95.86% Space Free | Partition Type: NTFS
- Computer Name: GUNADI-PC | User Name: gunadi | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
- Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - D:\OTL.exe (OldTimer Tools)
- PRC - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Zemana Ltd.)
- PRC - C:\Program Files (x86)\Explorer\iedvutils.exe ()
- PRC - C:\Program Files (x86)\SMADAV\SMΔRTP.exe (Smadsoft)
- PRC - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
- PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.5.0\ToolbarUpdater.exe (AVG Secure Search)
- PRC - C:\Program Files (x86)\SMADAV\SmadavProtect32.exe (Smadav Software)
- PRC - C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe (Google Inc.)
- PRC - C:\Program Files (x86)\Bluestacks\HD-Agent.exe (BlueStack Systems, Inc.)
- PRC - C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.)
- PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
- PRC - C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe ()
- PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
- PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
- PRC - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
- PRC - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
- PRC - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (Power Software Ltd)
- PRC - C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\a2eb039301af47660eebc7566ce02b9c\PresentationFramework.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\b9fe579783a35b57dd7e69375f35e239\PresentationCore.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\ef90aeb894485d14b249d102309b6df3\WindowsBase.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web\1cf870daa92622a1f98b0b5c818a3381\System.Web.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\ae01d58bd1cb283ec7b603919e2a8fb3\PresentationFramework.Aero.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\05ca0ca95b6fcc0d710b63b6200cc178\System.Windows.Forms.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d91f3556f8011a5d48e1448e3fa8df9e\System.Xml.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\4e69f1e7d86d79012db2d7e0dadc8880\System.Core.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\c4477b3ce64d0d612d1ab0dba425b77f\System.Drawing.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\639f444db9491d25b5d158531e1f7d9b\System.Xaml.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\13f5eb7285c90c219d2be24eebb55cd9\System.Management.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\1f56d5786274992934de0c900431c447\System.Configuration.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\79f6324a598a7c4446a4a1168be7c4b1\System.ni.dll ()
- MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\045c9588954c3662d542b53f4462268b\mscorlib.ni.dll ()
- MOD - C:\Program Files (x86)\Smadav\SM?RTP.exe ()
- MOD - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
- MOD - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libglesv2.dll ()
- MOD - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libegl.dll ()
- MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
- MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
- [color=#E56717]========== Services (SafeList) ==========[/color]
- SRV:[b]64bit:[/b] - (Intel(R) -- C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe (Intel(R) Corporation)
- SRV:[b]64bit:[/b] - (Intel(R) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel(R) Corporation)
- SRV:[b]64bit:[/b] - (NitroReaderDriverReadSpool3) -- C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe (Nitro PDF Software)
- SRV:[b]64bit:[/b] - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
- SRV:[b]64bit:[/b] - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
- SRV:[b]64bit:[/b] - (PowerISOReferenceAssemblies) -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
- SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
- SRV - (ZAMSvc) -- C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Zemana Ltd.)
- SRV - (MSLN) -- C:\ProgramData\Microsoft\IdentityCRL\ppcrlconf.dll ()
- SRV - (iedvutils) -- C:\Program Files (x86)\Explorer\iedvutils.exe ()
- SRV - (vToolbarUpdater19.5.0) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.5.0\ToolbarUpdater.exe (AVG Secure Search)
- SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
- SRV - (BstHdLogRotatorSvc) -- C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.)
- SRV - (BstHdAndroidSvc) -- C:\Program Files (x86)\Bluestacks\HD-Service.exe (BlueStack Systems, Inc.)
- SRV - (BstHdPlusAndroidSvc) -- C:\Program Files (x86)\Bluestacks\HD-Plus-Service.exe (BlueStack Systems, Inc.)
- SRV - (asComSvc) -- C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe ()
- SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
- SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
- SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
- SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV:[b]64bit:[/b] - (ZAM_Guard) -- C:\Windows\SysNative\drivers\zamguard64.sys (Zemana Ltd.)
- DRV:[b]64bit:[/b] - (ZAM_EarlyBoot) -- C:\Windows\SysNative\drivers\zam64.sys (Zemana Ltd.)
- DRV:[b]64bit:[/b] - (ZAM) -- C:\Windows\SysNative\drivers\zam64.sys (Zemana Ltd.)
- DRV:[b]64bit:[/b] - (RTTEAMPT) -- C:\Windows\SysNative\drivers\RtTeam620.sys (Realtek Corporation)
- DRV:[b]64bit:[/b] - (RtNdPt60) -- C:\Windows\SysNative\drivers\RtNdPt60.sys (Realtek )
- DRV:[b]64bit:[/b] - (RTVLANPT) -- C:\Windows\SysNative\drivers\RtVlan620.sys (Realtek Corporation)
- DRV:[b]64bit:[/b] - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
- DRV:[b]64bit:[/b] - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
- DRV:[b]64bit:[/b] - (MEIx64) -- C:\Windows\SysNative\drivers\TeeDriverx64.sys (Intel Corporation)
- DRV:[b]64bit:[/b] - (iusb3hcs) -- C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
- DRV:[b]64bit:[/b] - (iusb3xhc) -- C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
- DRV:[b]64bit:[/b] - (iusb3hub) -- C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
- DRV:[b]64bit:[/b] - (RTL8168) -- C:\Windows\SysNative\drivers\Rt630x64.sys (Realtek )
- DRV:[b]64bit:[/b] - (SCDEmu) -- C:\Windows\SysNative\drivers\scdemu.sys (Power Software Ltd)
- DRV:[b]64bit:[/b] - (TEAM) -- C:\Windows\SysNative\drivers\RtTeam60.sys (Realtek Corporation)
- DRV:[b]64bit:[/b] - (tpg64win7) -- C:\Windows\SysNative\drivers\tpg64win7.sys (TP-LINK TECHNOLOGIES CO., LTD)
- DRV:[b]64bit:[/b] - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
- DRV:[b]64bit:[/b] - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
- DRV:[b]64bit:[/b] - (tsusbhub) -- C:\Windows\SysNative\drivers\tsusbhub.sys (Microsoft Corporation)
- DRV:[b]64bit:[/b] - (Synth3dVsc) -- C:\Windows\SysNative\drivers\Synth3dVsc.sys (Microsoft Corporation)
- DRV:[b]64bit:[/b] - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
- DRV:[b]64bit:[/b] - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
- DRV:[b]64bit:[/b] - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
- DRV:[b]64bit:[/b] - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
- DRV:[b]64bit:[/b] - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
- DRV:[b]64bit:[/b] - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
- DRV:[b]64bit:[/b] - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
- DRV:[b]64bit:[/b] - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
- DRV:[b]64bit:[/b] - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
- DRV:[b]64bit:[/b] - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
- DRV:[b]64bit:[/b] - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
- DRV:[b]64bit:[/b] - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
- DRV:[b]64bit:[/b] - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
- DRV:[b]64bit:[/b] - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
- DRV - (BstHdDrv) -- C:\Program Files (x86)\Bluestacks\HD-Hypervisor-amd64.sys (BlueStack Systems)
- DRV - (BstkDrv) -- C:\Program Files (x86)\Bluestacks\BstkDrv.sys (Bluestack System Inc. )
- DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
- [color=#E56717]========== Standard Registry (All) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
- IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
- IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
- IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
- IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
- IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
- IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
- IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope =
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.amisites.com/?type=hp&ts=1484265018&z=290a08558abf030c79d71edg1z9bbz3ofq0w8edg5m&from=che0812&uid=WDCXWD10EZEX-00WN4A0_WD-WCC6Y0RSKVTHSKVTH
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.amisites.com/search/?type=ds&ts=1484265018&z=290a08558abf030c79d71edg1z9bbz3ofq0w8edg5m&from=che0812&uid=WDCXWD10EZEX-00WN4A0_WD-WCC6Y0RSKVTHSKVTH&q={searchTerms}
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.amisites.com/search/?type=ds&ts=1484265018&z=290a08558abf030c79d71edg1z9bbz3ofq0w8edg5m&from=che0812&uid=WDCXWD10EZEX-00WN4A0_WD-WCC6Y0RSKVTHSKVTH&q={searchTerms}
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.amisites.com/?type=hp&ts=1484265018&z=290a08558abf030c79d71edg1z9bbz3ofq0w8edg5m&from=che0812&uid=WDCXWD10EZEX-00WN4A0_WD-WCC6Y0RSKVTHSKVTH
- IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.amisites.com/search/?type=ds&ts=1484265018&z=290a08558abf030c79d71edg1z9bbz3ofq0w8edg5m&from=che0812&uid=WDCXWD10EZEX-00WN4A0_WD-WCC6Y0RSKVTHSKVTH&q={searchTerms}
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
- IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
- IE - HKCU\..\SearchScopes,DefaultScope =
- IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
- IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={E280C532-5732-4475-9616-F6205526F18A}&mid=e078338ac04c47cfafa802edbd1556ca-1202a8ed2f2104b8661330ab5fd628bb4fcb069f&lang=en&ds=st011&coid=&cmpid=&pr=sa&d=2016-12-29 18:14:39&v=19.6.0.592&pid=avg&sg=&sap=dsp&q={searchTerms}
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.countryCode: "ID"
- FF - prefs.js..browser.search.order.1: "luck"
- FF - prefs.js..browser.search.region: "ID"
- FF - prefs.js..browser.search.useDBForOrder: true
- FF - prefs.js..browser.startup.homepage: "about:home"
- FF - prefs.js..extensions.enabledAddons: artur.dubovoy%40gmail.com:13.2.4
- FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:43.0.1
- FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.6
- FF - user.js - File not found
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\19.5.0\\npsitesafety.dll File not found
- FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
- FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll (Google Inc.)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\13.2.0.3
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 43.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 43.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
- FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 43.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
- FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 43.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
- [2016/12/30 09:21:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\gunadi\AppData\Roaming\Mozilla\Extensions
- [2016/12/30 09:21:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\gunadi\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
- [2017/01/10 14:26:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\gunadi\AppData\Roaming\Mozilla\Firefox\Profiles\46rpzh0y.default\extensions
- [2017/01/10 14:22:56 | 000,000,000 | ---D | M] ("Flash Video Downloader - YouTube HD Download [4K]") -- C:\Users\gunadi\AppData\Roaming\Mozilla\Firefox\Profiles\46rpzh0y.default\extensions\artur.dubovoy@gmail.com
- [2017/01/10 14:11:11 | 000,050,432 | ---- | M] () (No name found) -- C:\Users\gunadi\AppData\Roaming\Mozilla\Firefox\Profiles\46rpzh0y.default\extensions\cccc5f0d-b9d0-4314-88b5-7e27551f9e84@jetpack.xpi
- [2017/01/10 14:26:22 | 000,208,039 | ---- | M] () (No name found) -- C:\Users\gunadi\AppData\Roaming\Mozilla\Firefox\Profiles\46rpzh0y.default\extensions\feca4b87-3be4-43da-a1b1-137c24220968@jetpack.xpi
- [2017/01/10 14:22:56 | 000,021,080 | ---- | M] () (No name found) -- C:\Users\gunadi\AppData\Roaming\Mozilla\Firefox\Profiles\46rpzh0y.default\extensions\{a3a5c777-f583-4fef-9380-ab4add1bc2a5}.xpi
- [2017/01/23 10:22:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
- [2017/01/23 10:22:14 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- O1 HOSTS File: ([2009/06/11 04:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
- O2:[b]64bit:[/b] - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
- O2:[b]64bit:[/b] - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
- O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
- O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\19.6.0.592\AVG Secure Search_toolbar.dll (AVG Secure Search)
- O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
- O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\19.6.0.592\AVG Secure Search_toolbar.dll (AVG Secure Search)
- O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
- O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
- O4:[b]64bit:[/b] - HKLM..\Run: [ZAM] C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Zemana Ltd.)
- O4 - HKLM..\Run: [BCSSync] C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
- O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (Power Software Ltd)
- O4 - HKLM..\Run: [ROC_roc_ssl_v12] C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe ()
- O4 - HKLM..\Run: [SMΔRT-Protection] C:\Program Files (x86)\Smadav\SMΔRTP.exe (Smadsoft)
- O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
- O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
- O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
- O4 - HKCU..\Run: [BlueStacks Agent] C:\Program Files (x86)\Bluestacks\HD-Agent.exe (BlueStack Systems, Inc.)
- O4:[b]64bit:[/b] - HKLM..\RunOnce: [Zemana AntiMalware] C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Zemana Ltd.)
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowRun = 1
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1 = Mshta.exe (Microsoft Corporation)
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 2 = powershell.exe (Microsoft Corporation)
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 3 = bitsadmin.exe (Microsoft Corporation)
- O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
- O8:[b]64bit:[/b] - Extra context menu item: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
- O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
- O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
- O9:[b]64bit:[/b] - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
- O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
- O9:[b]64bit:[/b] - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
- O9:[b]64bit:[/b] - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
- O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
- O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
- O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
- O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
- O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
- O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
- O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
- O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
- O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
- O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
- O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
- O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
- O13[b]64bit:[/b] - gopher Prefix: missing
- O13 - gopher Prefix: missing
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7CA4753C-5461-4CD0-82E1-3B3DF95289B9}: NameServer = 8.8.8.8
- O18:[b]64bit:[/b] - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Handler\viprotocol - No CLSID value found
- O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
- O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
- O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
- O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
- O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
- O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
- O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
- O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
- O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
- O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
- O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
- O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
- O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
- O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
- O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
- O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
- O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
- O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
- O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\19.5.0\ViProtocol.dll (AVG Secure Search)
- O18:[b]64bit:[/b] - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
- O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
- O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
- O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
- O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
- O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
- O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
- O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
- O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O28:[b]64bit:[/b] - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
- O28:[b]64bit:[/b] - HKLM ShellExecuteHooks: {F797446C-D3F2-11E6-AB72-64006A5CFC35} - C:\Users\gunadi\AppData\Roaming\Terlcultclhach\Hejuck.dll File not found
- O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
- O29:[b]64bit:[/b] - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
- O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
- O30:[b]64bit:[/b] - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
- O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
- O30:[b]64bit:[/b] - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
- O30:[b]64bit:[/b] - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
- O30:[b]64bit:[/b] - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
- O30:[b]64bit:[/b] - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
- O30:[b]64bit:[/b] - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
- O30:[b]64bit:[/b] - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
- O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
- O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
- O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
- O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
- O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
- O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
- O31 - SafeBoot: AlternateShell - cmd.exe
- O32 - HKLM CDRom: AutoRun - 1
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
- O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
- O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
- O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2017/01/23 10:22:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
- [2017/01/23 08:39:01 | 000,203,680 | ---- | C] (Zemana Ltd.) -- C:\Windows\SysNative\drivers\zamguard64.sys
- [2017/01/23 08:39:01 | 000,203,680 | ---- | C] (Zemana Ltd.) -- C:\Windows\SysNative\drivers\zam64.sys
- [2017/01/23 08:39:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
- [2017/01/23 08:38:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Zemana AntiMalware
- [2017/01/23 08:38:54 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Zemana
- [2017/01/19 14:19:37 | 000,000,000 | -H-D | C] -- C:\$Windows.~WS
- [2017/01/19 14:10:37 | 000,000,000 | ---D | C] -- C:\ESD
- [2017/01/19 14:05:17 | 000,000,000 | ---D | C] -- C:\$WINDOWS.~BT
- [2017/01/19 13:33:02 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MagicISO
- [2017/01/19 13:33:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicISO
- [2017/01/19 13:33:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MagicISO
- [2017/01/19 06:41:05 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Applefat
- [2017/01/19 06:41:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Applefat
- [2017/01/19 06:27:35 | 000,052,392 | ---- | C] (Elex do Brasil Participações Ltda) -- C:\Windows\SysNative\drivers\iSafeNetFilter.sys
- [2017/01/19 06:27:34 | 000,055,056 | ---- | C] (Elex do Brasil Participações Ltda) -- C:\Windows\SysNative\drivers\iSafeKrnlBoot.sys
- [2017/01/19 06:27:33 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\log
- [2017/01/19 06:27:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Elex-tech
- [2017/01/19 06:17:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Explorer
- [2017/01/18 13:03:00 | 000,000,000 | ---D | C] -- C:\Users\gunadi\Documents\PassMark
- [2017/01/18 13:02:56 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\PassMark
- [2017/01/18 13:02:51 | 004,992,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_39.dll
- [2017/01/18 13:02:51 | 003,977,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_31.dll
- [2017/01/18 13:02:51 | 001,942,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_39.dll
- [2017/01/18 13:02:51 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_39.dll
- [2017/01/18 13:02:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PerformanceTest (64-bit)
- [2017/01/18 13:02:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Passmark
- [2017/01/18 13:02:42 | 000,000,000 | ---D | C] -- C:\Program Files\PerformanceTest
- [2017/01/18 08:08:19 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Macromedia
- [2017/01/18 08:08:19 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Macromedia
- [2017/01/18 08:08:19 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Adobe
- [2017/01/18 07:25:23 | 000,000,000 | ---D | C] -- C:\Users\gunadi\Documents\aMule Downloads
- [2017/01/18 07:24:23 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueStacksSetup
- [2017/01/18 07:23:47 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Bluestacks
- [2017/01/18 07:21:17 | 000,000,000 | ---D | C] -- C:\Windows\Migration
- [2017/01/18 07:10:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Bluestacks
- [2017/01/18 07:10:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bluestacks
- [2017/01/16 12:44:39 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Hard Disk Sentinel
- [2017/01/16 12:44:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hard Disk Sentinel
- [2017/01/16 12:44:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hard Disk Sentinel
- [2017/01/16 11:17:20 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Firefox
- [2017/01/16 11:17:17 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Firefox
- [2017/01/16 11:17:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Firefox
- [2017/01/16 10:30:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus
- [2017/01/13 15:01:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited
- [2017/01/13 15:00:58 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Canneverbe Limited
- [2017/01/13 15:00:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDBurnerXP
- [2017/01/13 07:11:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\58781B22_jumpeasy
- [2017/01/12 09:26:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVG Secure Search
- [2017/01/11 11:46:59 | 000,000,000 | -HSD | C] -- C:\[Smad-Cage]
- [2017/01/11 11:46:59 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Smadav
- [2017/01/11 11:46:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SMADAV
- [2017/01/11 10:50:03 | 000,000,000 | ---D | C] -- C:\Program Files\f09er35s
- [2017/01/11 08:12:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\3p03nvn0
- [2017/01/11 06:35:41 | 000,000,000 | ---D | C] -- C:\Program Files\3p03nvn0
- [2017/01/10 14:12:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
- [2017/01/10 14:12:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Avg
- [2017/01/10 14:12:21 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
- [2017/01/10 14:12:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Shawosataleent Cloud
- [2017/01/10 14:12:07 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Profiles
- [2017/01/10 14:12:07 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Presowardanahotion
- [2017/01/10 14:12:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Anomusyercit
- [2017/01/09 14:19:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
- [2017/01/09 14:19:47 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
- [2017/01/09 14:19:41 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Programs
- [2017/01/09 14:17:33 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Nitro
- [2017/01/09 14:17:33 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\FileOpen
- [2017/01/09 14:17:33 | 000,000,000 | ---D | C] -- C:\ProgramData\FileOpen
- [2017/01/09 12:00:32 | 000,029,712 | ---- | C] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalmon2.dll
- [2017/01/09 12:00:32 | 000,017,936 | ---- | C] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalui2.dll
- [2017/01/09 12:00:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Nitro
- [2017/01/09 12:00:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nitro
- [2017/01/09 12:00:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nitro
- [2017/01/09 12:00:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nitro
- [2017/01/09 12:00:03 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Downloaded Installations
- [2017/01/09 11:31:48 | 000,648,808 | ---- | C] (TP-LINK TECHNOLOGIES CO., LTD) -- C:\Windows\SysNative\drivers\tpg64win7.sys
- [2017/01/09 11:31:48 | 000,074,344 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\SysNative\RtNicProp.dll
- [2017/01/09 11:00:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\EPSON
- [2017/01/09 11:00:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
- [2017/01/09 11:00:43 | 000,000,000 | ---D | C] -- C:\ProgramData\EPSON
- [2017/01/09 10:57:11 | 000,760,032 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt630x64.sys
- [2017/01/09 10:57:10 | 000,074,344 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\SysNative\RtNicProp64.dll
- [2017/01/09 10:52:43 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
- [2017/01/05 20:28:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
- [2017/01/05 20:28:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
- [2017/01/05 20:27:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
- [2017/01/05 20:27:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
- [2017/01/05 20:27:41 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
- [2017/01/05 20:27:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework
- [2017/01/05 20:27:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
- [2017/01/05 20:26:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
- [2017/01/05 20:25:42 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
- [2017/01/05 20:25:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
- [2017/01/05 20:25:24 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Microsoft Help
- [2017/01/05 20:25:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
- [2017/01/05 20:25:13 | 000,000,000 | RH-D | C] -- C:\MSOCache
- [2017/01/05 02:48:45 | 000,058,000 | ---- | C] (Realtek Corporation) -- C:\Windows\SysNative\drivers\RtTeam60.sys
- [2017/01/05 02:48:45 | 000,032,400 | ---- | C] (Realtek Corporation) -- C:\Windows\SysNative\drivers\RtVlan60.sys
- [2016/12/31 03:09:47 | 000,000,000 | ---D | C] -- C:\Users\gunadi\Documents\GomPlayer
- [2016/12/30 09:30:10 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Google
- [2016/12/30 09:30:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
- [2016/12/30 09:29:10 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\WinRAR
- [2016/12/30 09:28:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
- [2016/12/30 09:28:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\K-Lite Codec Pack
- [2016/12/30 09:24:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
- [2016/12/30 09:24:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
- [2016/12/30 09:23:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player
- [2016/12/30 09:23:54 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\GRETECH
- [2016/12/30 09:23:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GRETECH
- [2016/12/30 09:21:38 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
- [2016/12/30 09:21:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
- [2016/12/30 09:21:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR
- [2016/12/30 09:21:18 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Mozilla
- [2016/12/30 09:21:18 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Mozilla
- [2016/12/30 09:16:20 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\PowerISO
- [2016/12/30 09:14:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
- [2016/12/30 09:14:49 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\AVG Secure Search
- [2016/12/30 09:14:44 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search
- [2016/12/30 09:14:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVG Secure Search
- [2016/12/30 09:14:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search
- [2016/12/30 09:14:33 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
- [2016/12/30 09:14:26 | 000,126,944 | ---- | C] (Power Software Ltd) -- C:\Windows\SysNative\drivers\scdemu.sys
- [2016/12/30 09:14:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PowerISO
- [2016/12/30 08:47:08 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Diagnostics
- [2016/12/30 08:44:10 | 000,058,512 | ---- | C] (Realtek Corporation) -- C:\Windows\SysNative\drivers\RtTeam620.sys
- [2016/12/30 08:44:10 | 000,032,544 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\RtNdPt60.sys
- [2016/12/30 08:44:10 | 000,032,400 | ---- | C] (Realtek Corporation) -- C:\Windows\SysNative\drivers\RtVlan620.sys
- [2016/12/30 08:44:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
- [2016/12/30 06:19:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp
- [2016/12/30 06:19:50 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Detector Plug-in
- [2016/12/30 06:19:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winamp Detect
- [2016/12/30 06:19:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
- [2016/12/30 06:19:48 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Winamp
- [2016/12/30 06:19:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winamp
- [2016/12/30 06:16:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
- [2016/12/30 03:19:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
- [2016/12/30 03:16:16 | 000,064,000 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.DLL
- [2016/12/30 03:16:16 | 000,060,416 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.DLL
- [2016/12/30 03:16:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel
- [2016/12/30 03:06:09 | 000,028,672 | ---- | C] (ASUSTek Computer Inc.) -- C:\Windows\SysWow64\AsIO.dll
- [2016/12/30 03:06:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ASUS
- [2016/12/30 03:06:05 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFx.dll
- [2016/12/30 03:06:05 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFHost.exe
- [2016/12/30 03:06:05 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFPlatform.dll
- [2016/12/30 03:06:05 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFCoinstaller.dll
- [2016/12/30 03:06:03 | 000,000,000 | ---D | C] -- C:\Program Files\ASUS
- [2016/12/30 03:04:57 | 000,041,984 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\USB3Ver.dll
- [2016/12/30 03:04:22 | 000,016,344 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\IntelMEFWVer.dll
- [2016/12/30 03:04:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
- [2016/12/30 03:04:15 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
- [2016/12/30 03:04:02 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
- [2016/12/30 03:03:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\postureAgent
- [2016/12/30 03:03:51 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfLdr.sys
- [2016/12/30 03:03:51 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wdfres.dll
- [2016/12/30 03:03:41 | 000,000,000 | ---D | C] -- C:\Intel
- [2016/12/30 03:03:39 | 001,795,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WdfCoInstaller01011.dll
- [2016/12/30 03:03:39 | 000,099,288 | ---- | C] (Intel Corporation) -- C:\Windows\SysNative\drivers\TeeDriverx64.sys
- [2016/12/30 03:03:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
- [2016/12/30 03:03:26 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\InstallShield
- [2016/12/30 03:02:57 | 000,016,896 | ---- | C] (ASUS) -- C:\Windows\AsTaskSched.dll
- [2016/12/30 03:02:45 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
- [2016/12/30 03:02:45 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
- [2016/12/30 03:02:36 | 002,080,120 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib64.dll
- [2016/12/30 03:02:36 | 001,361,336 | ---- | C] (TOSHIBA Corporation) -- C:\Windows\SysNative\tosade.dll
- [2016/12/30 03:02:36 | 000,836,544 | ---- | C] (TOSHIBA Corporation) -- C:\Windows\SysNative\tadefxapo264.dll
- [2016/12/30 03:02:36 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
- [2016/12/30 03:02:36 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
- [2016/12/30 03:02:36 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
- [2016/12/30 03:02:36 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
- [2016/12/30 03:02:36 | 000,148,416 | ---- | C] (TOSHIBA Corporation) -- C:\Windows\SysNative\tadefxapo.dll
- [2016/12/30 03:02:36 | 000,065,944 | ---- | C] (TOSHIBA CORPORATION.) -- C:\Windows\SysNative\tepeqapo64.dll
- [2016/12/30 03:02:35 | 001,561,744 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTSnMg64.cpl
- [2016/12/30 03:02:35 | 000,772,224 | ---- | C] (Sony Corporation) -- C:\Windows\SysNative\SFSS_APO.dll
- [2016/12/30 03:02:35 | 000,221,024 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFNHK64.dll
- [2016/12/30 03:02:35 | 000,081,248 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFCOM64.dll
- [2016/12/30 03:02:35 | 000,078,688 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFAPO64.dll
- [2016/12/30 03:02:35 | 000,074,064 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysWow64\SFCOM.dll
- [2016/12/30 03:02:34 | 002,743,440 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtPgEx64.dll
- [2016/12/30 03:02:34 | 000,331,880 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtlCPAPI64.dll
- [2016/12/30 03:02:33 | 003,673,232 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkAPO64.dll
- [2016/12/30 03:02:33 | 000,881,808 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkApi64.dll
- [2016/12/30 03:02:33 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
- [2016/12/30 03:02:33 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
- [2016/12/30 03:02:33 | 000,149,608 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCfg64.dll
- [2016/12/30 03:02:33 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
- [2016/12/30 03:02:33 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
- [2016/12/30 03:02:33 | 000,014,952 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCoLDR64.dll
- [2016/12/30 03:02:32 | 001,269,904 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTCOM64.dll
- [2016/12/30 03:02:32 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
- [2016/12/30 03:02:32 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
- [2016/12/30 03:02:31 | 010,619,904 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoRes64.dat
- [2016/12/30 03:02:31 | 000,118,928 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoInstII64.dll
- [2016/12/30 03:02:29 | 007,164,176 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEP64A.dll
- [2016/12/30 03:02:29 | 000,434,960 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EED64A.dll
- [2016/12/30 03:02:29 | 000,141,584 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEL64A.dll
- [2016/12/30 03:02:29 | 000,124,176 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEA64A.dll
- [2016/12/30 03:02:29 | 000,075,024 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEG64A.dll
- [2016/12/30 03:02:28 | 000,394,616 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxVolumeSDAPO.dll
- [2016/12/30 03:02:27 | 009,546,616 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioRealtek64.dll
- [2016/12/30 03:02:27 | 001,460,600 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioRealtek264.dll
- [2016/12/30 03:02:26 | 002,028,920 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ64.dll
- [2016/12/30 03:02:26 | 000,869,752 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPOShell64.dll
- [2016/12/30 03:02:26 | 000,603,984 | ---- | C] (Knowles Acoustics ) -- C:\Windows\SysNative\KAAPORT64.dll
- [2016/12/30 03:02:26 | 000,394,616 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO30.dll
- [2016/12/30 03:02:26 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
- [2016/12/30 03:02:21 | 002,714,720 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
- [2016/12/30 03:02:21 | 000,712,296 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSSymmetryDLL64.dll
- [2016/12/30 03:02:21 | 000,693,352 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
- [2016/12/30 03:02:21 | 000,501,192 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSU2PLFX64.dll
- [2016/12/30 03:02:21 | 000,487,368 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSU2PGFX64.dll
- [2016/12/30 03:02:21 | 000,415,688 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSU2PREC64.dll
- [2016/12/30 03:02:20 | 001,756,264 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
- [2016/12/30 03:02:20 | 001,568,360 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
- [2016/12/30 03:02:20 | 001,486,952 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBoostDLL64.dll
- [2016/12/30 03:02:20 | 000,491,112 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSNeoPCDLL64.dll
- [2016/12/30 03:02:20 | 000,432,744 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLimiterDLL64.dll
- [2016/12/30 03:02:20 | 000,428,648 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
- [2016/12/30 03:02:20 | 000,242,792 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLFXAPO64.dll
- [2016/12/30 03:02:20 | 000,242,792 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPO64.dll
- [2016/12/30 03:02:20 | 000,241,768 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPONS64.dll
- [2016/12/30 03:02:19 | 000,728,680 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
- [2016/12/30 03:02:19 | 000,110,592 | ---- | C] (Real Sound Lab SIA) -- C:\Windows\SysNative\CONEQMSAPOGUILibrary.dll
- [2016/12/30 03:02:18 | 000,202,336 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AERTAC64.dll
- [2016/12/30 03:02:18 | 000,108,640 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AERTAR64.dll
- [2016/12/30 03:02:09 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
- [2016/12/30 03:02:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
- [2016/12/30 03:02:06 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp
- [2016/12/30 03:02:04 | 001,706,640 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlExUpd.dll
- [2016/12/30 03:02:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
- [2016/12/29 13:23:31 | 000,000,000 | R--D | C] -- C:\Users\gunadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- [2016/12/29 13:23:31 | 000,000,000 | R--D | C] -- C:\Users\gunadi\Searches
- [2016/12/29 13:23:31 | 000,000,000 | R--D | C] -- C:\Users\gunadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- [2016/12/29 13:23:31 | 000,000,000 | -H-D | C] -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
- [2016/12/29 13:23:24 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Identities
- [2016/12/29 13:23:22 | 000,000,000 | R--D | C] -- C:\Users\gunadi\Contacts
- [2016/12/29 13:23:16 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\VirtualStore
- [2016/12/29 13:23:12 | 000,000,000 | --SD | C] -- C:\Users\gunadi\AppData\Roaming\Microsoft
- [2016/12/29 13:23:12 | 000,000,000 | R--D | C] -- C:\Users\gunadi\Videos
- [2016/12/29 13:23:12 | 000,000,000 | R--D | C] -- C:\Users\gunadi\Saved Games
- [2016/12/29 13:23:12 | 000,000,000 | R--D | C] -- C:\Users\gunadi\Pictures
- [2016/12/29 13:23:12 | 000,000,000 | R--D | C] -- C:\Users\gunadi\Music
- [2016/12/29 13:23:12 | 000,000,000 | R--D | C] -- C:\Users\gunadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
- [2016/12/29 13:23:12 | 000,000,000 | R--D | C] -- C:\Users\gunadi\Links
- [2016/12/29 13:23:12 | 000,000,000 | R--D | C] -- C:\Users\gunadi\Favorites
- [2016/12/29 13:23:12 | 000,000,000 | R--D | C] -- C:\Users\gunadi\Downloads
- [2016/12/29 13:23:12 | 000,000,000 | R--D | C] -- C:\Users\gunadi\Documents
- [2016/12/29 13:23:12 | 000,000,000 | R--D | C] -- C:\Users\gunadi\Desktop
- [2016/12/29 13:23:12 | 000,000,000 | R--D | C] -- C:\Users\gunadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\AppData\Local\Temporary Internet Files
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\Templates
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\Start Menu
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\SendTo
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\Recent
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\PrintHood
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\NetHood
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\Documents\My Videos
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\Documents\My Pictures
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\Documents\My Music
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\My Documents
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\Local Settings
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\AppData\Local\History
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\Cookies
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\Application Data
- [2016/12/29 13:23:12 | 000,000,000 | -HSD | C] -- C:\Users\gunadi\AppData\Local\Application Data
- [2016/12/29 13:23:12 | 000,000,000 | -H-D | C] -- C:\Users\gunadi\AppData
- [2016/12/29 13:23:12 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Temp
- [2016/12/29 13:23:12 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Local\Microsoft
- [2016/12/29 13:23:12 | 000,000,000 | ---D | C] -- C:\Users\gunadi\AppData\Roaming\Media Center Programs
- [2016/12/29 13:22:33 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
- [2016/12/29 13:22:33 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
- [2016/12/29 13:22:17 | 000,000,000 | -HSD | C] -- C:\Recovery
- [2016/12/29 13:22:16 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
- [2016/12/29 13:19:23 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
- [2016/12/29 13:18:59 | 000,000,000 | -HSD | C] -- C:\System Volume Information
- [2016/12/29 13:18:29 | 000,000,000 | ---D | C] -- C:\Windows\Panther
- [1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2017/01/23 12:46:04 | 000,543,289 | ---- | M] () -- C:\Windows\ZAM.krnl.trace
- [2017/01/23 12:46:04 | 000,091,464 | ---- | M] () -- C:\Windows\ZAM_Guard.krnl.trace
- [2017/01/23 12:42:59 | 000,000,678 | ---- | M] () -- C:\Users\gunadi\Desktop\OTL - Shortcut.lnk
- [2017/01/23 10:22:25 | 000,001,064 | ---- | M] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
- [2017/01/23 08:55:16 | 000,001,000 | ---- | M] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
- [2017/01/23 08:55:16 | 000,001,000 | ---- | M] () -- C:\Users\Public\Desktop\Internet Explorer.lnk
- [2017/01/23 08:55:15 | 000,001,160 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
- [2017/01/23 08:55:15 | 000,001,160 | ---- | M] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
- [2017/01/23 08:55:15 | 000,000,983 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
- [2017/01/23 08:53:20 | 000,781,298 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
- [2017/01/23 08:53:20 | 000,661,656 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
- [2017/01/23 08:53:20 | 000,121,524 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
- [2017/01/23 08:49:33 | 000,000,000 | ---- | M] () -- C:\Users\Public\Documents\report.dat
- [2017/01/23 08:47:22 | 000,000,000 | ---- | M] () -- C:\Users\Public\Documents\temp.dat
- [2017/01/23 08:47:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2017/01/23 08:47:14 | 3120,128,000 | -HS- | M] () -- C:\hiberfil.sys
- [2017/01/23 08:39:01 | 000,203,680 | ---- | M] (Zemana Ltd.) -- C:\Windows\SysNative\drivers\zamguard64.sys
- [2017/01/23 08:39:01 | 000,203,680 | ---- | M] (Zemana Ltd.) -- C:\Windows\SysNative\drivers\zam64.sys
- [2017/01/23 08:39:00 | 000,001,148 | ---- | M] () -- C:\Users\Public\Desktop\Zemana AntiMalware.lnk
- [2017/01/20 06:57:16 | 000,000,019 | ---- | M] () -- C:\Users\Public\Documents\cc.ini
- [2017/01/19 14:24:39 | 000,023,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- [2017/01/19 14:24:39 | 000,023,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- [2017/01/19 14:18:30 | 000,004,379 | ---- | M] () -- C:\Windows\diagwrn.xml
- [2017/01/19 14:18:30 | 000,002,507 | ---- | M] () -- C:\Windows\diagerr.xml
- [2017/01/19 13:58:14 | 000,000,400 | RHS- | M] () -- C:\ProgramData\ntuser.pol
- [2017/01/19 13:33:02 | 000,001,799 | ---- | M] () -- C:\Users\gunadi\Desktop\MagicISO.lnk
- [2017/01/19 09:40:00 | 000,395,429 | ---- | M] () -- C:\Users\gunadi\Documents\lazada.jpg
- [2017/01/18 11:44:40 | 000,292,466 | ---- | M] () -- C:\Users\gunadi\Documents\wifi.jpg
- [2017/01/18 07:24:18 | 000,001,632 | ---- | M] () -- C:\Users\Public\Desktop\BlueStacks.lnk
- [2017/01/18 07:22:07 | 000,773,536 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
- [2017/01/17 12:44:18 | 000,001,209 | ---- | M] () -- C:\Users\gunadi\Desktop\Panduan Pengguna Presensi Online Woowtime 6 - Shortcut.lnk
- [2017/01/16 12:44:37 | 000,001,027 | ---- | M] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\Hard Disk Sentinel.lnk
- [2017/01/16 12:44:37 | 000,001,003 | ---- | M] () -- C:\Users\gunadi\Desktop\Hard Disk Sentinel.lnk
- [2017/01/13 15:00:58 | 000,001,147 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
- [2017/01/11 11:15:25 | 000,002,003 | ---- | M] () -- C:\Users\Public\Desktop\Nitro Reader.lnk
- [2017/01/09 14:19:47 | 000,000,869 | ---- | M] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
- [2017/01/05 22:20:19 | 000,442,248 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
- [2017/01/05 02:47:19 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
- [2016/12/30 09:23:55 | 000,001,209 | ---- | M] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
- [2016/12/30 09:23:55 | 000,001,185 | ---- | M] () -- C:\Users\Public\Desktop\GOM Player.lnk
- [2016/12/30 09:21:18 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
- [2016/12/30 09:14:52 | 000,001,007 | ---- | M] () -- C:\Users\Public\Desktop\PowerISO.lnk
- [2016/12/30 08:43:23 | 000,058,512 | ---- | M] (Realtek Corporation) -- C:\Windows\SysNative\drivers\RtTeam620.sys
- [2016/12/30 08:43:23 | 000,032,544 | ---- | M] (Realtek ) -- C:\Windows\SysNative\drivers\RtNdPt60.sys
- [2016/12/30 08:43:23 | 000,032,400 | ---- | M] (Realtek Corporation) -- C:\Windows\SysNative\drivers\RtVlan620.sys
- [2016/12/30 06:19:55 | 000,001,003 | ---- | M] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
- [2016/12/30 06:19:55 | 000,000,979 | ---- | M] () -- C:\Users\Public\Desktop\Winamp.lnk
- [2016/12/30 03:17:20 | 000,015,396 | ---- | M] () -- C:\Windows\SysNative\results.xml
- [2016/12/30 03:16:18 | 000,000,716 | ---- | M] () -- C:\Users\Public\Desktop\Intel(R) HD Graphics Control Panel.lnk
- [2016/12/30 03:13:55 | 000,733,184 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\MetroIntelGenericUIFramework.dll
- [2016/12/30 03:13:52 | 000,064,000 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.DLL
- [2016/12/30 03:13:52 | 000,064,000 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\Intel_OpenCL_ICD64.dll
- [2016/12/30 03:13:52 | 000,060,416 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.DLL
- [2016/12/30 03:13:52 | 000,060,416 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\Intel_OpenCL_ICD32.dll
- [2016/12/30 03:13:50 | 000,320,512 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\IntelOpenCL64.dll
- [2016/12/30 03:13:50 | 000,279,024 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\IntelCpHeciSvc.exe
- [2016/12/30 03:13:50 | 000,265,216 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\IntelOpenCL32.dll
- [2016/12/30 03:13:49 | 002,813,952 | ---- | M] () -- C:\Windows\SysNative\iglhxa64.cpa
- [2016/12/30 03:13:49 | 000,182,784 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxCoIn_v3412.dll
- [2016/12/30 03:13:49 | 000,044,025 | ---- | M] () -- C:\Windows\SysNative\iglhxo64.vp
- [2016/12/30 03:13:49 | 000,043,816 | ---- | M] () -- C:\Windows\SysNative\iglhxc64_dev.vp
- [2016/12/30 03:13:49 | 000,043,494 | ---- | M] () -- C:\Windows\SysNative\iglhxc64.vp
- [2016/12/30 03:13:49 | 000,043,298 | ---- | M] () -- C:\Windows\SysNative\iglhxg64_dev.vp
- [2016/12/30 03:13:49 | 000,043,256 | ---- | M] () -- C:\Windows\SysNative\iglhxg64.vp
- [2016/12/30 03:13:49 | 000,042,079 | ---- | M] () -- C:\Windows\SysNative\iglhxo64_dev.vp
- [2016/12/30 03:13:49 | 000,002,944 | ---- | M] () -- C:\Windows\SysNative\iglhxs64.vp
- [2016/12/30 03:13:49 | 000,001,125 | ---- | M] () -- C:\Windows\SysNative\iglhxa64.vp
- [2016/12/30 03:13:48 | 001,127,424 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\iglhsip64.dll
- [2016/12/30 03:13:48 | 001,123,328 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\iglhsip32.dll
- [2016/12/30 03:13:48 | 000,391,152 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxtray.exe
- [2016/12/30 03:13:48 | 000,346,624 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxTMM.dll
- [2016/12/30 03:13:48 | 000,214,528 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\iglhcp64.dll
- [2016/12/30 03:13:48 | 000,179,712 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\iglhcp32.dll
- [2016/12/30 03:13:47 | 000,906,224 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxstarter.exe
- [2016/12/30 03:13:47 | 000,845,296 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxsrvc.exe
- [2016/12/30 03:13:47 | 000,525,824 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrsky.lrc
- [2016/12/30 03:13:47 | 000,525,312 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrsve.lrc
- [2016/12/30 03:13:47 | 000,525,312 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrslv.lrc
- [2016/12/30 03:13:47 | 000,524,800 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrtrk.lrc
- [2016/12/30 03:13:47 | 000,523,776 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrtha.lrc
- [2016/12/30 03:13:47 | 000,066,560 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxsrvc.dll
- [2016/12/30 03:13:46 | 000,527,360 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrplk.lrc
- [2016/12/30 03:13:46 | 000,526,848 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrrus.lrc
- [2016/12/30 03:13:46 | 000,526,336 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrrom.lrc
- [2016/12/30 03:13:46 | 000,526,336 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrnld.lrc
- [2016/12/30 03:13:46 | 000,525,824 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrptg.lrc
- [2016/12/30 03:13:46 | 000,524,800 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrptb.lrc
- [2016/12/30 03:13:46 | 000,524,288 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrnor.lrc
- [2016/12/30 03:13:46 | 000,516,096 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrkor.lrc
- [2016/12/30 03:13:45 | 009,081,856 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxress.dll
- [2016/12/30 03:13:45 | 000,527,360 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrfra.lrc
- [2016/12/30 03:13:45 | 000,526,336 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrita.lrc
- [2016/12/30 03:13:45 | 000,525,824 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrhun.lrc
- [2016/12/30 03:13:45 | 000,525,824 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrhrv.lrc
- [2016/12/30 03:13:45 | 000,525,312 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrfin.lrc
- [2016/12/30 03:13:45 | 000,522,240 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrheb.lrc
- [2016/12/30 03:13:45 | 000,517,632 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrjpn.lrc
- [2016/12/30 03:13:44 | 000,527,872 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrell.lrc
- [2016/12/30 03:13:44 | 000,527,360 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxresn.lrc
- [2016/12/30 03:13:44 | 000,526,848 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrdeu.lrc
- [2016/12/30 03:13:44 | 000,524,288 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrdan.lrc
- [2016/12/30 03:13:44 | 000,371,200 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrenu.lrc
- [2016/12/30 03:13:43 | 000,770,544 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxpers.exe
- [2016/12/30 03:13:43 | 000,548,864 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxpph.dll
- [2016/12/30 03:13:43 | 000,525,824 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrcsy.lrc
- [2016/12/30 03:13:43 | 000,521,728 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrara.lrc
- [2016/12/30 03:13:43 | 000,514,048 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrcht.lrc
- [2016/12/30 03:13:43 | 000,513,536 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxrchs.lrc
- [2016/12/30 03:13:43 | 000,397,808 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxext.exe
- [2016/12/30 03:13:42 | 000,624,640 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxdev.dll
- [2016/12/30 03:13:42 | 000,493,056 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\igfxdv32.dll
- [2016/12/30 03:13:42 | 000,279,040 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxcpl.cpl
- [2016/12/30 03:13:42 | 000,243,712 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxdo.dll
- [2016/12/30 03:13:42 | 000,163,328 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxcmrt64.dll
- [2016/12/30 03:13:42 | 000,137,728 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\igfxcmrt32.dll
- [2016/12/30 03:13:42 | 000,029,696 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxexps.dll
- [2016/12/30 03:13:42 | 000,025,600 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\igfxexps32.dll
- [2016/12/30 03:13:42 | 000,012,288 | ---- | M] ( ) -- C:\Windows\SysNative\IGFXDEVLib.dll
- [2016/12/30 03:13:41 | 004,474,368 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igdusc64.dll
- [2016/12/30 03:13:41 | 003,558,912 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\igdusc32.dll
- [2016/12/30 03:13:41 | 002,065,920 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfxcmjit64.dll
- [2016/12/30 03:13:41 | 001,815,040 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\igfxcmjit32.dll
- [2016/12/30 03:13:41 | 000,155,136 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igfx11cmrt64.dll
- [2016/12/30 03:13:41 | 000,133,120 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\igfx11cmrt32.dll
- [2016/12/30 03:13:40 | 019,380,224 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igdumdim64.dll
- [2016/12/30 03:13:39 | 018,629,632 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\igdumdim32.dll
- [2016/12/30 03:13:38 | 003,224,064 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igdrcl64.dll
- [2016/12/30 03:13:38 | 002,896,384 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\igdrcl32.dll
- [2016/12/30 03:13:38 | 000,373,760 | ---- | M] () -- C:\Windows\SysNative\igdmd64.dll
- [2016/12/30 03:13:38 | 000,299,520 | ---- | M] () -- C:\Windows\SysWow64\igdmd32.dll
- [2016/12/30 03:13:37 | 025,971,712 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igdfcl64.dll
- [2016/12/30 03:13:37 | 004,221,440 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\drivers\igdkmd64.sys
- [2016/12/30 03:13:35 | 020,954,112 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\igdfcl32.dll
- [2016/12/30 03:13:34 | 000,222,208 | ---- | M] () -- C:\Windows\SysNative\igdde64.dll
- [2016/12/30 03:13:33 | 021,088,256 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igd10iumd64.dll
- [2016/12/30 03:13:33 | 000,329,216 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\igdbcl64.dll
- [2016/12/30 03:13:33 | 000,290,816 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\igdbcl32.dll
- [2016/12/30 03:13:33 | 000,182,272 | ---- | M] () -- C:\Windows\SysWow64\igdde32.dll
- [2016/12/30 03:13:33 | 000,160,256 | ---- | M] () -- C:\Windows\SysNative\igdail64.dll
- [2016/12/30 03:13:33 | 000,142,848 | ---- | M] () -- C:\Windows\SysWow64\igdail32.dll
- [2016/12/30 03:13:32 | 020,433,408 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\igd10iumd32.dll
- [2016/12/30 03:13:28 | 007,947,776 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\ig75icd64.dll
- [2016/12/30 03:13:28 | 006,289,408 | ---- | M] (Intel Corporation) -- C:\Windows\SysWow64\ig75icd32.dll
- [2016/12/30 03:13:26 | 000,771,568 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\hkcmd.exe
- [2016/12/30 03:13:26 | 000,094,208 | ---- | M] () -- C:\Windows\SysNative\IccLibDll_x64.dll
- [2016/12/30 03:13:25 | 007,597,040 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\GfxUIEx.exe
- [2016/12/30 03:13:25 | 000,755,184 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\GfxUIHotKeyMenu.exe
- [2016/12/30 03:13:25 | 000,224,256 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\hccutils.dll
- [2016/12/30 03:13:25 | 000,001,806 | ---- | M] () -- C:\Windows\SysNative\GfxUIEx.exe.config
- [2016/12/30 03:13:25 | 000,000,264 | ---- | M] () -- C:\Windows\SysNative\GfxUIHotKeyMenu.exe.config
- [2016/12/30 03:13:24 | 000,194,560 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\gfxSrvc.dll
- [2016/12/30 03:13:24 | 000,175,571 | ---- | M] () -- C:\Windows\SysNative\Gfxres.tr-TR.resources
- [2016/12/30 03:13:24 | 000,154,805 | ---- | M] () -- C:\Windows\SysNative\Gfxres.zh-TW.resources
- [2016/12/30 03:13:24 | 000,152,993 | ---- | M] () -- C:\Windows\SysNative\Gfxres.zh-CN.resources
- [2016/12/30 03:13:23 | 000,267,407 | ---- | M] () -- C:\Windows\SysNative\Gfxres.th-TH.resources
- [2016/12/30 03:13:23 | 000,235,401 | ---- | M] () -- C:\Windows\SysNative\Gfxres.ru-RU.resources
- [2016/12/30 03:13:23 | 000,180,936 | ---- | M] () -- C:\Windows\SysNative\Gfxres.ko-KR.resources
- [2016/12/30 03:13:23 | 000,176,838 | ---- | M] () -- C:\Windows\SysNative\Gfxres.ro-RO.resources
- [2016/12/30 03:13:23 | 000,175,067 | ---- | M] () -- C:\Windows\SysNative\Gfxres.nl-NL.resources
- [2016/12/30 03:13:23 | 000,174,802 | ---- | M] () -- C:\Windows\SysNative\Gfxres.pl-PL.resources
- [2016/12/30 03:13:23 | 000,174,269 | ---- | M] () -- C:\Windows\SysNative\Gfxres.pt-BR.resources
- [2016/12/30 03:13:23 | 000,173,276 | ---- | M] () -- C:\Windows\SysNative\Gfxres.sk-SK.resources
- [2016/12/30 03:13:23 | 000,173,059 | ---- | M] () -- C:\Windows\SysNative\Gfxres.sv-SE.resources
- [2016/12/30 03:13:23 | 000,172,833 | ---- | M] () -- C:\Windows\SysNative\Gfxres.pt-PT.resources
- [2016/12/30 03:13:23 | 000,168,215 | ---- | M] () -- C:\Windows\SysNative\Gfxres.sl-SI.resources
- [2016/12/30 03:13:23 | 000,166,833 | ---- | M] () -- C:\Windows\SysNative\Gfxres.nb-NO.resources
- [2016/12/30 03:13:22 | 002,384,896 | ---- | M] () -- C:\Windows\SysNative\GfxRes.dll
- [2016/12/30 03:13:22 | 000,253,466 | ---- | M] () -- C:\Windows\SysNative\Gfxres.el-GR.resources
- [2016/12/30 03:13:22 | 000,198,725 | ---- | M] () -- C:\Windows\SysNative\Gfxres.ja-JP.resources
- [2016/12/30 03:13:22 | 000,192,758 | ---- | M] () -- C:\Windows\SysNative\Gfxres.he-IL.resources
- [2016/12/30 03:13:22 | 000,180,850 | ---- | M] () -- C:\Windows\SysNative\Gfxres.it-IT.resources
- [2016/12/30 03:13:22 | 000,178,473 | ---- | M] () -- C:\Windows\SysNative\Gfxres.es-ES.resources
- [2016/12/30 03:13:22 | 000,178,290 | ---- | M] () -- C:\Windows\SysNative\Gfxres.fr-FR.resources
- [2016/12/30 03:13:22 | 000,175,862 | ---- | M] () -- C:\Windows\SysNative\Gfxres.hu-HU.resources
- [2016/12/30 03:13:22 | 000,173,792 | ---- | M] () -- C:\Windows\SysNative\Gfxres.fi-FI.resources
- [2016/12/30 03:13:22 | 000,171,691 | ---- | M] () -- C:\Windows\SysNative\Gfxres.hr-HR.resources
- [2016/12/30 03:13:22 | 000,161,534 | ---- | M] () -- C:\Windows\SysNative\Gfxres.en-US.resources
- [2016/12/30 03:13:21 | 000,530,928 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\DPTopologyApp.exe
- [2016/12/30 03:13:21 | 000,201,128 | ---- | M] () -- C:\Windows\SysNative\Gfxres.ar-SA.resources
- [2016/12/30 03:13:21 | 000,178,123 | ---- | M] () -- C:\Windows\SysNative\Gfxres.de-DE.resources
- [2016/12/30 03:13:21 | 000,172,554 | ---- | M] () -- C:\Windows\SysNative\Gfxres.cs-CZ.resources
- [2016/12/30 03:13:21 | 000,166,220 | ---- | M] () -- C:\Windows\SysNative\Gfxres.da-DK.resources
- [2016/12/30 03:13:21 | 000,153,072 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\difx64.exe
- [2016/12/30 03:13:21 | 000,000,935 | ---- | M] () -- C:\Windows\SysNative\DPTopologyApp.exe.config
- [2016/12/30 03:13:19 | 000,450,520 | ---- | M] (Intel(R) Corporation) -- C:\Windows\SysNative\drivers\IntcDAud.sys
- [2016/12/30 03:13:19 | 000,397,296 | ---- | M] (Intel Corporation) -- C:\Windows\SysNative\CustomModeApp.exe
- [2016/12/30 03:13:19 | 000,000,935 | ---- | M] () -- C:\Windows\SysNative\CustomModeApp.exe.config
- [2016/12/30 03:08:06 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_ASMBSW_01_11_00.Wdf
- [2016/12/30 03:06:09 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\MsftWdf_user_01_11_00.Wdf
- [2016/12/30 03:05:11 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_iusb3hcs_01009.Wdf
- [2016/12/30 03:03:56 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
- [2016/12/30 03:03:55 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Coinstaller_Critical.Wdf
- [2016/12/30 03:02:57 | 000,016,896 | ---- | M] (ASUS) -- C:\Windows\AsTaskSched.dll
- [2016/12/30 03:01:59 | 000,001,769 | ---- | M] () -- C:\Windows\Language_trs.ini
- [2016/12/29 13:22:43 | 000,014,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\slwga.dll
- [2016/12/29 13:22:43 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\slwga.dll
- [2016/12/29 13:22:42 | 001,008,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\user32.dll
- [2016/12/29 13:22:42 | 000,419,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\systemcpl.dll
- [2016/12/29 13:20:48 | 000,116,385 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
- [2016/12/29 13:20:48 | 000,116,385 | ---- | M] () -- C:\Windows\SysNative\license.rtf
- [1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2017/01/23 12:42:59 | 000,000,678 | ---- | C] () -- C:\Users\gunadi\Desktop\OTL - Shortcut.lnk
- [2017/01/23 08:47:17 | 000,539,099 | ---- | C] () -- C:\Windows\ZAM.krnl.trace
- [2017/01/23 08:47:17 | 000,090,977 | ---- | C] () -- C:\Windows\ZAM_Guard.krnl.trace
- [2017/01/23 08:39:00 | 000,001,148 | ---- | C] () -- C:\Users\Public\Desktop\Zemana AntiMalware.lnk
- [2017/01/20 06:57:16 | 000,000,019 | ---- | C] () -- C:\Users\Public\Documents\cc.ini
- [2017/01/19 14:18:03 | 000,004,379 | ---- | C] () -- C:\Windows\diagwrn.xml
- [2017/01/19 14:18:03 | 000,002,507 | ---- | C] () -- C:\Windows\diagerr.xml
- [2017/01/19 13:33:02 | 000,001,799 | ---- | C] () -- C:\Users\gunadi\Desktop\MagicISO.lnk
- [2017/01/19 09:40:00 | 000,395,429 | ---- | C] () -- C:\Users\gunadi\Documents\lazada.jpg
- [2017/01/19 06:17:05 | 000,001,000 | ---- | C] () -- C:\Users\Public\Desktop\Internet Explorer.lnk
- [2017/01/18 11:44:40 | 000,292,466 | ---- | C] () -- C:\Users\gunadi\Documents\wifi.jpg
- [2017/01/18 07:24:33 | 000,000,570 | ---- | C] () -- C:\Users\gunadi\AppData\Local\TroubleshooterConfig.json
- [2017/01/18 07:24:18 | 000,001,632 | ---- | C] () -- C:\Users\Public\Desktop\BlueStacks.lnk
- [2017/01/17 12:44:18 | 000,001,209 | ---- | C] () -- C:\Users\gunadi\Desktop\Panduan Pengguna Presensi Online Woowtime 6 - Shortcut.lnk
- [2017/01/16 12:44:37 | 000,001,027 | ---- | C] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\Hard Disk Sentinel.lnk
- [2017/01/16 12:44:37 | 000,001,003 | ---- | C] () -- C:\Users\gunadi\Desktop\Hard Disk Sentinel.lnk
- [2017/01/13 15:00:58 | 000,001,147 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
- [2017/01/13 15:00:58 | 000,001,105 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
- [2017/01/13 14:41:29 | 000,000,400 | RHS- | C] () -- C:\ProgramData\ntuser.pol
- [2017/01/13 07:11:13 | 000,000,000 | ---- | C] () -- C:\Users\Public\Documents\report.dat
- [2017/01/13 07:11:11 | 000,000,000 | ---- | C] () -- C:\Users\Public\Documents\temp.dat
- [2017/01/09 14:19:47 | 000,000,869 | ---- | C] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
- [2017/01/09 12:00:30 | 000,002,003 | ---- | C] () -- C:\Users\Public\Desktop\Nitro Reader.lnk
- [2017/01/09 12:00:29 | 000,002,499 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Reader 3.lnk
- [2017/01/05 02:47:19 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
- [2016/12/30 09:30:18 | 000,001,160 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
- [2016/12/30 09:30:18 | 000,001,160 | ---- | C] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
- [2016/12/30 09:30:18 | 000,001,160 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
- [2016/12/30 09:28:26 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
- [2016/12/30 09:24:25 | 000,000,983 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
- [2016/12/30 09:23:55 | 000,001,209 | ---- | C] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
- [2016/12/30 09:23:55 | 000,001,185 | ---- | C] () -- C:\Users\Public\Desktop\GOM Player.lnk
- [2016/12/30 09:21:18 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
- [2016/12/30 09:21:16 | 000,001,064 | ---- | C] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
- [2016/12/30 09:21:16 | 000,000,983 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
- [2016/12/30 09:14:52 | 000,001,007 | ---- | C] () -- C:\Users\Public\Desktop\PowerISO.lnk
- [2016/12/30 06:24:59 | 000,001,000 | ---- | C] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
- [2016/12/30 06:19:55 | 000,001,003 | ---- | C] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
- [2016/12/30 06:19:55 | 000,000,979 | ---- | C] () -- C:\Users\Public\Desktop\Winamp.lnk
- [2016/12/30 06:18:31 | 000,773,536 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
- [2016/12/30 03:17:20 | 000,015,396 | ---- | C] () -- C:\Windows\SysNative\results.xml
- [2016/12/30 03:16:18 | 000,000,716 | ---- | C] () -- C:\Users\Public\Desktop\Intel(R) HD Graphics Control Panel.lnk
- [2016/12/30 03:08:06 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_ASMBSW_01_11_00.Wdf
- [2016/12/30 03:06:09 | 000,015,232 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
- [2016/12/30 03:06:09 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_user_01_11_00.Wdf
- [2016/12/30 03:06:05 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
- [2016/12/30 03:05:11 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_iusb3hcs_01009.Wdf
- [2016/12/30 03:03:56 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
- [2016/12/30 03:03:55 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Coinstaller_Critical.Wdf
- [2016/12/30 03:03:51 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
- [2016/12/30 03:02:32 | 000,378,949 | ---- | C] () -- C:\Windows\SysNative\drivers\RTAIODAT.DAT
- [2016/12/30 03:01:59 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
- [2016/12/29 13:23:36 | 000,001,000 | ---- | C] () -- C:\Users\gunadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
- [2016/12/29 13:23:33 | 000,001,000 | ---- | C] () -- C:\Users\gunadi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
- [2016/12/29 13:23:12 | 000,000,290 | ---- | C] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
- [2016/12/29 13:23:12 | 000,000,272 | ---- | C] () -- C:\Users\gunadi\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
- [2016/12/29 13:20:43 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
- [2016/12/29 13:20:34 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
- [2016/12/29 13:18:59 | 3120,128,000 | -HS- | C] () -- C:\hiberfil.sys
- [color=#E56717]========== ZeroAccess Check ==========[/color]
- [2009/07/14 11:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
- [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- "" = C:\Windows\SysNative\shell32.dll -- [2010/11/21 10:23:55 | 014,174,208 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- "" = %SystemRoot%\system32\shell32.dll -- [2010/11/21 10:24:02 | 012,872,192 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 08:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
- "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 10:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 08:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Both
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
- [color=#E56717]========== LOP Check ==========[/color]
- [2017/01/13 15:00:58 | 000,000,000 | ---D | M] -- C:\Users\gunadi\AppData\Roaming\Canneverbe Limited
- [2017/01/09 12:00:03 | 000,000,000 | ---D | M] -- C:\Users\gunadi\AppData\Roaming\Downloaded Installations
- [2017/01/09 14:17:33 | 000,000,000 | ---D | M] -- C:\Users\gunadi\AppData\Roaming\FileOpen
- [2017/01/16 11:17:17 | 000,000,000 | ---D | M] -- C:\Users\gunadi\AppData\Roaming\Firefox
- [2017/01/16 12:44:39 | 000,000,000 | ---D | M] -- C:\Users\gunadi\AppData\Roaming\Hard Disk Sentinel
- [2017/01/09 14:17:33 | 000,000,000 | ---D | M] -- C:\Users\gunadi\AppData\Roaming\Nitro
- [2016/12/30 09:16:20 | 000,000,000 | ---D | M] -- C:\Users\gunadi\AppData\Roaming\PowerISO
- [2017/01/10 14:12:09 | 000,000,000 | ---D | M] -- C:\Users\gunadi\AppData\Roaming\Profiles
- [2017/01/16 10:31:00 | 000,000,000 | ---D | M] -- C:\Users\gunadi\AppData\Roaming\Smadav
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Files - Unicode (All) ==========[/color]
- [2017/01/16 10:30:57 | 000,001,072 | ---- | M] ()(C:\Users\Public\Desktop\SMAD?V.lnk) -- C:\Users\Public\Desktop\SMADΔV.lnk
- [2017/01/11 11:46:57 | 000,001,072 | ---- | C] ()(C:\Users\Public\Desktop\SMAD?V.lnk) -- C:\Users\Public\Desktop\SMADΔV.lnk
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement