Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 10/10/2015 7:31:31 PM - Run 1
- OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Admin\My Documents\Downloads
- Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
- Internet Explorer (Version = 8.0.6001.18702)
- Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
- 1023.48 Mb Total Physical Memory | 522.24 Mb Available Physical Memory | 51.03% Memory free
- 2.40 Gb Paging File | 1.89 Gb Available in Paging File | 78.64% Paging File free
- Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
- Drive C: | 37.26 Gb Total Space | 27.70 Gb Free Space | 74.34% Space Free | Partition Type: NTFS
- Drive E: | 127.99 Gb Total Space | 121.18 Gb Free Space | 94.68% Space Free | Partition Type: NTFS
- Drive F: | 58.32 Gb Total Space | 58.25 Gb Free Space | 99.89% Space Free | Partition Type: NTFS
- Computer Name: WXPPX86BE-6997 | User Name: Admin | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user
- Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2015/10/10 19:30:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Admin\My Documents\Downloads\OTL.scr
- PRC - [2015/09/24 04:34:44 | 000,815,944 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
- PRC - [2015/07/22 04:03:48 | 000,182,696 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
- PRC - [2013/07/02 16:16:32 | 000,589,184 | ---- | M] (Oracle Corporation) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
- PRC - [2013/01/31 13:22:47 | 001,259,296 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
- PRC - [2010/09/14 03:02:44 | 000,399,872 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\Program Files\UPHClean\uphclean.exe
- PRC - [2008/07/03 12:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
- PRC - [2007/04/16 14:28:22 | 000,651,264 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
- PRC - [2002/03/20 00:30:00 | 001,241,664 | ---- | M] () -- C:\WINDOWS\system32\TaskSwitch.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2013/12/03 17:36:22 | 000,268,288 | ---- | M] () -- C:\Program Files\WinRAR\RarLng.dll
- MOD - [2013/01/31 13:22:47 | 000,357,224 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\nview\nvShell.dll
- MOD - [2010/07/04 23:32:38 | 000,010,752 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerCOM.dll
- MOD - [2008/04/14 13:00:00 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
- MOD - [2008/04/14 13:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
- MOD - [2002/03/20 00:30:00 | 001,241,664 | ---- | M] () -- C:\WINDOWS\system32\TaskSwitch.exe
- [color=#E56717]========== Services (SafeList) ==========[/color]
- SRV - [2015/10/03 15:25:39 | 000,147,624 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
- SRV - [2015/07/22 04:03:48 | 000,182,696 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
- SRV - [2013/01/31 13:22:47 | 001,259,296 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
- SRV - [2010/09/14 03:02:44 | 000,399,872 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Auto | Running] -- C:\Program Files\UPHClean\uphclean.exe -- (UPHClean)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
- DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
- DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
- DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
- DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
- DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
- DRV - File not found [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\iilnqn.sys -- (amsint32)
- DRV - [2014/01/12 11:05:46 | 000,076,288 | ---- | M] (Nuvoton Technology Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nuvserial.sys -- (Serial)
- DRV - [2014/01/12 11:05:46 | 000,017,920 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nuvserenum.sys -- (serenum)
- DRV - [2013/12/16 19:27:47 | 000,014,184 | ---- | M] (Marvell Semiconductor Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\mvxxmm.sys -- (mvxxmm)
- DRV - [2013/12/16 19:27:47 | 000,005,632 | ---- | M] (Marvell Semiconductor Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\mv64xxmm.sys -- (mv64xxmm)
- DRV - [2013/12/16 19:27:46 | 000,014,184 | ---- | M] (Marvell Semiconductor Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\mv61xxmm.sys -- (mv61xxmm)
- DRV - [2011/08/08 20:13:10 | 000,117,584 | ---- | M] (SysProgs.org) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BazisVirtualCDBus.sys -- (BazisVirtualCDBus)
- DRV - [2010/07/04 21:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
- DRV - [2008/09/24 09:40:22 | 004,122,368 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM)
- DRV - [2006/06/16 11:04:38 | 000,035,712 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SISAGPX.SYS -- (SISAGP)
- DRV - [2006/02/14 16:02:56 | 000,032,768 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisnicxp.sys -- (SISNICXP)
- DRV - [2003/03/25 19:50:46 | 000,004,096 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\siside.sys -- (siside)
- DRV - [2001/08/17 11:19:34 | 000,040,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\es1371mp.sys -- (es1371)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
- IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.countryCode: "BA"
- FF - prefs.js..browser.search.region: "BA"
- FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:41.0.1
- FF - user.js - File not found
- FF - HKLM\Software\MozillaPlugins\@adobe.com/AuthorwarePlayer: C:\WINDOWS\system32\Macromed\AUTHORWA\np32asw.dll (Macromedia, Inc.)
- FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
- FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
- FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
- FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
- FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
- FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
- FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@mozilla.zeniko.ch/SumatraPDF_Browser_Plugin: C:\Program Files\SumatraPDF\npPdfViewer.dll (Simon Bünzli)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll (Google Inc.)
- FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Admin\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 41.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 41.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
- [2015/08/04 10:19:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Admin\Application Data\Mozilla\Extensions
- [2015/09/24 16:32:52 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\2n15k6je.default\extensions
- [2015/10/03 15:25:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
- [2015/10/03 15:25:49 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- [color=#E56717]========== Chrome ==========[/color]
- CHR - Extension: No name found = C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
- CHR - Extension: No name found = C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
- CHR - Extension: No name found = C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.0_0\
- CHR - Extension: No name found = C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
- CHR - Extension: No name found = C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\
- CHR - Extension: No name found = C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
- CHR - Extension: No name found = C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\0.5_0\
- CHR - Extension: No name found = C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\0.3.0.5_0\
- CHR - Extension: No name found = C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.2.0_0\
- CHR - Extension: No name found = C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
- O1 HOSTS File: ([2008/04/14 13:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
- O1 - Hosts: 127.0.0.1 localhost
- O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
- O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
- O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
- O4 - HKLM..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd File not found
- O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
- O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
- O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
- O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
- O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
- O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MS .NET Framework v4 - Slow Windows XP Boot Fix.vbs ()
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MaxRecentDocs = 18
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
- O13 - gopher Prefix: missing
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3544B818-443B-4E3C-AFBE-CE2CB77B6777}: DhcpNameServer = 192.168.1.1
- O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
- O24 - Desktop WallPaper: C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
- O24 - Desktop BackupWallPaper: C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
- O32 - HKLM CDRom: AutoRun - 1
- O32 - AutoRun File - [2015/07/22 03:53:14 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
- O32 - AutoRun File - [2015/07/21 22:31:42 | 000,000,238 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
- O32 - AutoRun File - [2005/07/18 20:09:53 | 000,000,000 | ---- | M] () - E:\AUTOEXEC.BAT -- [ NTFS ]
- O32 - AutoRun File - [2015/07/21 22:31:42 | 000,000,302 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
- O32 - AutoRun File - [2015/07/21 22:31:42 | 000,000,311 | RHS- | M] () - F:\autorun.inf -- [ NTFS ]
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
- O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2015/10/10 19:27:14 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Admin\IECompatCache
- [2015/10/10 19:24:18 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
- [2015/10/04 17:29:21 | 000,040,704 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\drivers\es1371mp.sys
- [2015/10/03 15:25:13 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
- [2015/09/15 12:51:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Application Data\MPC-HC
- [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
- [2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
- [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2015/10/10 19:25:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
- [2015/10/10 19:16:16 | 000,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
- [2015/10/10 19:16:16 | 000,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
- [2015/10/10 17:11:34 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
- [2015/10/10 17:11:33 | 000,000,222 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Logon.job
- [2015/10/10 17:11:29 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
- [2015/10/10 17:11:24 | 1073,274,880 | -HS- | M] () -- C:\hiberfil.sys
- [2015/10/08 15:04:38 | 000,000,216 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Monthly.job
- [2015/10/08 07:52:46 | 000,002,184 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
- [2015/09/27 14:51:01 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
- [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
- [2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
- [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2015/07/23 18:57:26 | 001,072,544 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
- [2015/07/23 18:57:26 | 001,072,544 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
- [2015/07/23 18:57:26 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
- [2015/07/23 18:55:55 | 002,816,504 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
- [2015/07/22 04:05:16 | 000,650,752 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
- [2015/07/22 04:05:16 | 000,243,200 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
- [2015/07/22 04:05:16 | 000,216,064 | ---- | C] ( ) -- C:\WINDOWS\System32\lagarith.dll
- [2015/07/22 04:05:13 | 000,217,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
- [2015/07/22 04:05:07 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
- [2015/07/22 03:54:51 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
- [2015/07/22 03:50:10 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
- [2015/07/21 22:36:58 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
- [2015/07/21 22:32:55 | 000,715,038 | ---- | C] () -- C:\WINDOWS\unins000.exe
- [2015/07/21 22:32:55 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\utv_core.dll
- [2015/07/21 22:32:55 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\utv_vcm.dll
- [2015/07/21 22:32:55 | 000,001,745 | ---- | C] () -- C:\WINDOWS\unins000.dat
- [2015/07/21 22:24:59 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
- [2015/07/21 22:20:32 | 000,100,640 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
- [2014/02/09 18:36:04 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
- [color=#E56717]========== ZeroAccess Check ==========[/color]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- "" = %SystemRoot%\system32\shdocvw.dll -- [2013/10/25 01:53:19 | 001,510,400 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
- "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 11:56:36 | 000,473,600 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
- "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 13:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Both
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement