Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 17.3.2012. 14:59:51 - Run 1
- OTL by OldTimer - Version 3.2.39.0 Folder = C:\Users\Maja\Desktop
- 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
- Internet Explorer (Version = 8.0.7600.16385)
- Locale: 0000041a | Country: Hrvatska | Language: HRV | Date Format: d.M.yyyy.
- 3,93 Gb Total Physical Memory | 2,84 Gb Available Physical Memory | 72,23% Memory free
- 7,86 Gb Paging File | 6,70 Gb Available in Paging File | 85,22% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
- Drive C: | 146,39 Gb Total Space | 11,90 Gb Free Space | 8,13% Space Free | Partition Type: NTFS
- Drive D: | 151,60 Gb Total Space | 2,20 Gb Free Space | 1,45% Space Free | Partition Type: NTFS
- Drive F: | 100,00 Mb Total Space | 61,66 Mb Free Space | 61,66% Space Free | Partition Type: NTFS
- Drive G: | 32,77 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
- Computer Name: MAJA-PC | User Name: Maja | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
- Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2012.03.17 14:57:39 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\Maja\Desktop\OTL.com
- PRC - [2012.03.06 13:58:29 | 000,855,904 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe
- PRC - [2012.03.06 13:58:28 | 000,827,232 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
- PRC - [2012.03.02 10:54:53 | 000,114,688 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\T-Mobile Internet Manager.exe
- PRC - [2010.11.30 17:26:12 | 000,749,384 | ---- | M] (AVG) -- C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\BoostSpeed.exe
- PRC - [2010.08.19 09:52:14 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
- PRC - [2010.08.19 09:52:04 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe
- PRC - [2010.03.03 20:21:16 | 000,325,200 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
- PRC - [2009.12.09 22:12:50 | 001,118,208 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWlan.exe
- PRC - [2009.12.07 13:49:24 | 000,040,960 | ---- | M] (Realtek) -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2012.03.06 13:58:28 | 001,547,104 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll
- MOD - [2012.03.06 13:58:28 | 000,827,232 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
- MOD - [2012.03.02 10:54:53 | 000,114,688 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\T-Mobile Internet Manager.exe
- MOD - [2010.11.30 17:26:54 | 000,350,024 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\madExcept_.bpl
- MOD - [2010.11.30 17:26:52 | 000,184,136 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\madBasic_.bpl
- MOD - [2010.11.30 17:26:52 | 000,050,504 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl
- MOD - [2010.08.18 18:02:20 | 000,159,744 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\SMSPlugin.dll
- MOD - [2010.07.31 14:54:06 | 000,065,536 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\SpeedManagerPlugin.dll
- MOD - [2010.07.21 11:57:06 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DialUpPlugin.dll
- MOD - [2010.07.21 11:53:42 | 000,122,880 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DeviceMgrPlugin.dll
- MOD - [2010.07.21 11:53:26 | 000,237,568 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DeviceMgrUIPlugin.dll
- MOD - [2010.07.21 11:51:42 | 001,019,904 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\NDISAPI.dll
- MOD - [2010.06.28 15:41:34 | 000,155,648 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DetectDev.dll
- MOD - [2009.09.08 12:54:44 | 000,065,536 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\ConfigFilePlugin.dll
- MOD - [2009.09.08 12:49:12 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\NetInfoPlugin.dll
- MOD - [2009.05.23 11:02:32 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\XCodec.dll
- MOD - [2009.05.23 11:02:30 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DeviceOperate.dll
- MOD - [2009.05.23 11:02:24 | 000,557,056 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\atcomm.dll
- MOD - [2009.01.09 11:31:54 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\LocaleMgrPlugin.dll
- MOD - [2009.01.09 11:30:38 | 000,032,768 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\NotifyServicePlugin.dll
- MOD - [2008.11.08 10:52:10 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\FileManager.dll
- MOD - [2008.11.08 10:52:08 | 000,014,848 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\isaputrace.dll
- [color=#E56717]========== Win32 Services (SafeList) ==========[/color]
- SRV:[b]64bit:[/b] - [2010.02.05 19:23:06 | 000,865,824 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe -- (ePowerSvc)
- SRV:[b]64bit:[/b] - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
- SRV:[b]64bit:[/b] - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
- SRV - [2012.03.06 13:58:29 | 000,855,904 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe -- (vToolbarUpdater)
- SRV - [2012.01.31 15:02:52 | 007,391,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
- SRV - [2011.11.10 14:17:31 | 000,167,264 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
- SRV - [2011.02.08 04:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe -- (avgwd)
- SRV - [2010.08.19 09:52:04 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe)
- SRV - [2010.03.03 20:21:16 | 000,325,200 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
- SRV - [2009.12.07 13:49:24 | 000,040,960 | ---- | M] (Realtek) [Auto | Running] -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe -- (Realtek11nSU)
- SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV:[b]64bit:[/b] - [2011.05.27 19:05:26 | 000,118,864 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
- DRV:[b]64bit:[/b] - [2011.04.04 23:59:54 | 000,377,936 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
- DRV:[b]64bit:[/b] - [2011.03.16 15:03:18 | 000,037,456 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
- DRV:[b]64bit:[/b] - [2011.03.01 13:25:18 | 000,041,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
- DRV:[b]64bit:[/b] - [2011.02.22 07:12:46 | 000,026,704 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AVGIDSEH.sys -- (AVGIDSEH)
- DRV:[b]64bit:[/b] - [2011.02.10 06:53:34 | 000,029,264 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
- DRV:[b]64bit:[/b] - [2011.01.07 05:41:44 | 000,304,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
- DRV:[b]64bit:[/b] - [2010.04.09 15:24:38 | 000,079,360 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
- DRV:[b]64bit:[/b] - [2010.04.09 15:24:32 | 000,076,288 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator)
- DRV:[b]64bit:[/b] - [2010.03.20 11:56:56 | 000,114,560 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
- DRV:[b]64bit:[/b] - [2010.02.09 17:19:14 | 001,586,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
- DRV:[b]64bit:[/b] - [2009.12.15 10:46:38 | 000,039,552 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tcpipBM.sys -- (tcpipBM)
- DRV:[b]64bit:[/b] - [2009.12.15 10:46:30 | 000,016,512 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BMLoad.sys -- (BMLoad)
- DRV:[b]64bit:[/b] - [2009.11.12 01:54:46 | 000,676,864 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rtl8192su.sys -- (RTL8192su)
- DRV:[b]64bit:[/b] - [2009.09.02 10:54:18 | 007,369,728 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
- DRV:[b]64bit:[/b] - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
- DRV:[b]64bit:[/b] - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
- DRV:[b]64bit:[/b] - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
- DRV:[b]64bit:[/b] - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
- DRV:[b]64bit:[/b] - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
- DRV:[b]64bit:[/b] - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
- DRV:[b]64bit:[/b] - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
- DRV:[b]64bit:[/b] - [2009.06.18 19:12:32 | 000,272,432 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
- DRV:[b]64bit:[/b] - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
- DRV:[b]64bit:[/b] - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
- DRV:[b]64bit:[/b] - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
- DRV:[b]64bit:[/b] - [2009.06.10 21:34:18 | 000,057,344 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20)
- DRV:[b]64bit:[/b] - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
- DRV - [2009.09.02 08:58:08 | 000,225,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\RtsUStor.sys -- (RSUSBSTOR)
- DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
- DRV - [2006.07.24 15:05:00 | 000,005,632 | ---- | M] () [File_System | System | Stopped] -- C:\Windows\SysWow64\drivers\StarOpen.sys -- (StarOpen)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.hr/
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = hr
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A6 8D C9 AC C8 6B CB 01 [binary data]
- IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
- IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
- IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
- IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={C6BE1A76-DC2E-409F-A6A3-647C6F1480E7}&mid=fe26c648f094485fa33cd32616c0ea32-ecd91c8af34f63441a093be8e041007713a83bc3&lang=us&ds=AVG&pr=fr&d=2012-03-06 13:57:59&v=9.0.0.18&sap=dsp&q={searchTerms}
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
- FF - prefs.js..browser.startup.homepage: "http://www.google.com"
- FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
- FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
- FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1423
- FF - prefs.js..extensions.enabledItems: avg@toolbar:9.0.0.18.3
- FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7B4d61166e-13cb-4446-afe2-7009775e8b88%7D&mid=fe26c648f094485fa33cd32616c0ea32-ecd91c8af34f63441a093be8e041007713a83bc3&ds=AVG&v=9.0.0.18.3&lang=us&pr=fr&d=2012-03-06%2013%3A57%3A59&sap=ku&q="
- FF - user.js - File not found
- FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
- FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
- FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
- FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
- FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Maja\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
- FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Maja\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG10\Firefox4\ [2012.03.07 10:38:13 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\9.0.0.18\ [2012.03.06 13:58:38 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.07.03 21:42:25 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.07.21 02:55:30 | 000,000,000 | ---D | M]
- [2010.10.14 19:33:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maja\AppData\Roaming\mozilla\Extensions
- [2010.10.14 19:33:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maja\AppData\Roaming\mozilla\Firefox\Profiles\b26k63zr.default\extensions
- [2012.03.06 14:45:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
- [2010.10.14 19:17:00 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
- [2011.02.19 21:07:48 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
- [2012.03.07 10:38:13 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES (X86)\AVG\AVG10\FIREFOX4
- [2012.03.06 13:58:38 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\PROGRAMDATA\AVG SECURE SEARCH\9.0.0.18
- [2011.02.02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
- [2012.03.06 13:58:28 | 000,003,766 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
- [color=#E56717]========== Chrome ==========[/color]
- CHR - default_search_provider: AVG Secure Search (Enabled)
- CHR - default_search_provider: search_url = http://search.avg.com/?d=4de4b7d4&v=7.4.22.4&i=26&tp=ggl-chrome&q={searchTerms}
- CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/complete/search?output=chrome&client=chrome&q={searchTerms}
- CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
- CHR - plugin: Native Client (Enabled) = C:\Users\Maja\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
- CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Maja\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll
- CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Maja\AppData\Local\Google\Chrome\Application\17.0.963.56\gcswf32.dll
- CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
- CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Maja\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1374_0\plugins/avgnpss.dll
- CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
- CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
- CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
- CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
- CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
- CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
- CHR - plugin: Google Update (Enabled) = C:\Users\Maja\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
- CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
- CHR - plugin: Default Plug-in (Enabled) = default_plugin
- CHR - Extension: AVG Safe Search = C:\Users\Maja\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1374_0\
- O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
- O2:[b]64bit:[/b] - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll (AVG Technologies CZ, s.r.o.)
- O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
- O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office12\GR469A~1.DLL (Microsoft Corporation)
- O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll ()
- O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll ()
- O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
- O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
- O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
- O4:[b]64bit:[/b] - HKLM..\Run: [Acer ePower Management] C:\Program Files\eMachines\eMachines Power Management\ePowerTray.exe (Acer Incorporated)
- O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
- O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
- O4 - HKLM..\Run: [DataCardMonitor] C:\Program Files (x86)\T-Mobile\InternetManager_H\DataCardMonitor.exe (Huawei Technologies Co., Ltd.)
- O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD\Language\Language.exe ()
- O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
- O4 - HKLM..\Run: [NBKeyScan] C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
- O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
- O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe (Nero AG)
- O4 - HKCU..\Run: [HW_OPENEYE_OUC_T-Mobile Internet Manager] C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe (Huawei Technologies Co., Ltd.)
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
- O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
- O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
- O9 - Extra Button: Pošalji u OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
- O9 - Extra 'Tools' menuitem : Po&šalji u OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
- O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
- O13[b]64bit:[/b] - gopher Prefix: missing
- O13 - gopher Prefix: missing
- O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
- O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
- O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{63DC5AC7-ECD5-45C9-B9C8-E441DDB029C4}: DhcpNameServer = 192.168.1.254
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AFC4BA4A-C081-4228-92CA-D3A028DF3867}: NameServer = 87.252.156.25 10.48.65.30
- O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll (AVG Technologies CZ, s.r.o.)
- O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\viprotocol - No CLSID value found
- O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~2\Office12\GRA32A~1.DLL (Microsoft Corporation)
- O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
- O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
- O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
- O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll ()
- O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
- O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found
- O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
- O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
- O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office12\GR469A~1.DLL (Microsoft Corporation)
- O32 - HKLM CDRom: AutoRun - 1
- O32 - AutoRun File - [2010.08.19 17:49:08 | 000,126,976 | R--- | M] () - G:\AutoRun.exe -- [ CDFS ]
- O32 - AutoRun File - [2009.06.30 17:43:22 | 000,000,048 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ]
- O33 - MountPoints2\{595ed4ff-644d-11e1-882c-705ab6e1773c}\Shell - "" = AutoRun
- O33 - MountPoints2\{595ed4ff-644d-11e1-882c-705ab6e1773c}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.08.19 17:49:08 | 000,126,976 | R--- | M] ()
- O33 - MountPoints2\{595ed514-644d-11e1-882c-705ab6e1773c}\Shell - "" = AutoRun
- O33 - MountPoints2\{595ed514-644d-11e1-882c-705ab6e1773c}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.08.19 17:49:08 | 000,126,976 | R--- | M] ()
- O33 - MountPoints2\{c1f35d6e-644e-11e1-bbc5-705ab6e1773c}\Shell - "" = AutoRun
- O33 - MountPoints2\{c1f35d6e-644e-11e1-bbc5-705ab6e1773c}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.08.19 17:49:08 | 000,126,976 | R--- | M] ()
- O34 - HKLM BootExecute: (autocheck autochk *)
- O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgchsva.exe /sync)
- O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgrsa.exe /sync /restart)
- O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
- O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- O37 - HKCU\...exe [@ = F4D55] -- "C:\ProgramData\F4D55F3B0000765F0003AE0FA6014588\F4D55F3B0000765F0003AE0FA6014588.exe" -s "%1" %*
- NetSvcs:[b]64bit:[/b] AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2012.03.17 14:57:26 | 000,594,944 | ---- | C] (OldTimer Tools) -- C:\Users\Maja\Desktop\OTL.com
- [2012.03.17 13:02:50 | 000,000,000 | ---D | C] -- C:\Users\Maja\Desktop\Nova mapa
- [2012.03.11 21:38:26 | 000,000,000 | ---D | C] -- C:\Users\Maja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
- [2012.03.07 18:25:40 | 000,000,000 | ---D | C] -- C:\Users\Maja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Smart Fortress 2012
- [2012.03.07 18:22:15 | 000,000,000 | ---D | C] -- C:\ProgramData\F4D55F3B0000765F0003AE0FA6014588
- [2012.03.06 13:58:31 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search
- [2012.03.06 13:58:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVG Secure Search
- [2012.03.06 13:58:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search
- [2012.03.02 10:56:22 | 000,000,000 | ---D | C] -- C:\Users\Maja\AppData\Roaming\T-Mobile Internet Manager
- [2012.03.02 10:55:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\T-Mobile Internet Manager
- [2012.03.02 10:55:42 | 000,000,000 | ---D | C] -- C:\Users\Maja\AppData\Roaming\T-Mobile
- [2012.03.02 10:55:41 | 000,308,352 | ---- | C] (Bytemobile, Inc.) -- C:\Windows\SysWow64\bminstall.dll
- [2012.03.02 10:55:40 | 000,039,552 | ---- | C] (Bytemobile, Inc.) -- C:\Windows\SysNative\drivers\tcpipBM.sys
- [2012.03.02 10:55:40 | 000,016,512 | ---- | C] (Bytemobile, Inc.) -- C:\Windows\SysNative\drivers\BMLoad.sys
- [2012.03.02 10:55:17 | 000,079,360 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys
- [2012.03.02 10:55:17 | 000,076,288 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_jubusenum.sys
- [2012.03.02 10:55:17 | 000,049,664 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_jucdcecm.sys
- [2012.03.02 10:55:17 | 000,027,136 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_juextctrl.sys
- [2012.03.02 10:55:10 | 001,001,472 | ---- | C] (DiBcom SA) -- C:\Windows\SysNative\drivers\mod7700.sys
- [2012.03.02 10:55:10 | 000,250,368 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ewusbnet.sys
- [2012.03.02 10:55:10 | 000,120,704 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ewusbmdm.sys
- [2012.03.02 10:55:10 | 000,032,768 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\Windows\SysNative\drivers\ewdcsc.sys
- [2012.03.02 10:55:10 | 000,013,952 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys
- [2012.03.02 10:55:00 | 000,114,560 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys
- [2012.03.02 10:54:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\T-Mobile
- [2012.03.02 10:53:21 | 000,000,000 | ---D | C] -- C:\ProgramData\DatacardService
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2012.03.17 15:00:16 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- [2012.03.17 15:00:16 | 000,016,944 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- [2012.03.17 15:00:09 | 000,717,956 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
- [2012.03.17 15:00:09 | 000,610,094 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
- [2012.03.17 15:00:09 | 000,104,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
- [2012.03.17 14:57:39 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\Maja\Desktop\OTL.com
- [2012.03.17 14:52:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2012.03.17 14:52:42 | 3166,150,656 | -HS- | M] () -- C:\hiberfil.sys
- [2012.03.17 13:35:23 | 000,000,954 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-120546333-2585630232-2128625777-1001UA.job
- [2012.03.17 12:56:41 | 000,000,017 | ---- | M] () -- C:\Users\Maja\AppData\Local\resmon.resmoncfg
- [2012.03.16 16:36:25 | 000,002,391 | ---- | M] () -- C:\Users\Maja\Desktop\Google Chrome.lnk
- [2012.03.07 17:49:08 | 091,023,286 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
- [2012.03.07 11:35:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-120546333-2585630232-2128625777-1001Core.job
- [2012.03.07 10:38:27 | 000,000,953 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2011.lnk
- [2012.03.02 10:56:17 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ew_jucdcacm_01009.Wdf
- [2012.03.02 10:55:48 | 000,001,286 | ---- | M] () -- C:\Users\Public\Desktop\T-Mobile Internet Manager.lnk
- [2012.03.02 10:55:27 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ew_jubusenum_01009.Wdf
- [2012.02.26 17:33:54 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2012.03.17 12:56:41 | 000,000,017 | ---- | C] () -- C:\Users\Maja\AppData\Local\resmon.resmoncfg
- [2012.03.02 10:56:17 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ew_jucdcacm_01009.Wdf
- [2012.03.02 10:55:48 | 000,001,286 | ---- | C] () -- C:\Users\Public\Desktop\T-Mobile Internet Manager.lnk
- [2012.03.02 10:55:27 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ew_jubusenum_01009.Wdf
- [2011.10.07 15:44:24 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
- [2011.02.01 02:18:26 | 001,467,637 | ---- | C] () -- C:\Users\Maja\AppData\Roaming\UserTile.png
- [2011.01.11 16:26:29 | 000,722,802 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
- [2010.11.13 20:54:26 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
- [2010.10.21 12:22:29 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
- [2010.10.21 12:17:31 | 000,005,632 | ---- | C] () -- C:\Windows\SysWow64\drivers\StarOpen.sys
- [2010.10.15 14:05:20 | 000,000,010 | ---- | C] () -- C:\Windows\popcinfo.dat
- [2010.10.14 19:46:56 | 000,000,026 | ---- | C] () -- C:\Windows\Irremote.ini
- [2010.10.14 19:33:53 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
- [2010.10.14 19:10:43 | 000,982,220 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
- [2010.10.14 19:10:43 | 000,134,592 | ---- | C] () -- C:\Windows\SysWow64\igfcg500.bin
- [2010.10.14 19:10:43 | 000,092,216 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
- [2010.10.14 19:10:42 | 000,439,300 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
- [color=#E56717]========== LOP Check ==========[/color]
- [2011.01.14 02:34:50 | 000,000,000 | ---D | M] -- C:\Users\Maja\AppData\Roaming\AVG
- [2010.10.14 19:29:46 | 000,000,000 | ---D | M] -- C:\Users\Maja\AppData\Roaming\AVG10
- [2010.10.21 12:47:28 | 000,000,000 | ---D | M] -- C:\Users\Maja\AppData\Roaming\Samsung
- [2012.03.02 10:55:42 | 000,000,000 | ---D | M] -- C:\Users\Maja\AppData\Roaming\T-Mobile
- [2012.03.06 11:24:10 | 000,000,000 | ---D | M] -- C:\Users\Maja\AppData\Roaming\T-Mobile Internet Manager
- [2011.03.11 01:57:20 | 000,000,000 | ---D | M] -- C:\Users\Maja\AppData\Roaming\uTorrent
- [2012.02.20 21:57:50 | 000,032,608 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Custom Scans ==========[/color]
- [color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]
- [color=#A23BEC]< %ALLUSERSPROFILE%\Application Data\*.exe >[/color]
- [color=#A23BEC]< MD5 for: AFD.SYS >[/color]
- [2009.07.14 00:21:42 | 000,500,224 | ---- | M] (Microsoft Corporation) MD5=B9384E03479D2506BC924C16A3DB87BC -- C:\Windows\SysNative\drivers\afd.sys
- [2009.07.14 00:21:42 | 000,500,224 | ---- | M] (Microsoft Corporation) MD5=B9384E03479D2506BC924C16A3DB87BC -- C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7600.16385_none_33dd3439781e25f7\afd.sys
- [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
- [2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
- [2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
- [2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
- [color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
- [2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
- [2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\SysWOW64\explorer.exe
- [2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
- [2009.08.03 07:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
- [2009.10.31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\explorer.exe
- [2009.10.31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
- [2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
- [2009.10.31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
- [2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
- [2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
- [2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
- [2009.08.03 07:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
- [color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color]
- [2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
- [2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
- [2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
- [2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
- [color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
- [2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
- [2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
- [2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
- [2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
- [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
- [2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
- [2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
- [2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
- [2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
- [color=#A23BEC]< C:\Windows\assembly\tmp\U\*.* /s >[/color]
- [color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
- [color=#A23BEC]< hklm\software\clients\startmenuinternet|command /rs >[/color]
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011.07.03 21:42:25 | 000,552,464 | ---- | M] (Mozilla Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011.07.03 21:42:25 | 000,552,464 | ---- | M] (Mozilla Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011.07.03 21:42:25 | 000,552,464 | ---- | M] (Mozilla Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files (x86)\Mozilla Firefox\firefox.exe [2011.07.03 21:42:24 | 000,912,344 | ---- | M] (Mozilla Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -preferences [2011.07.03 21:42:24 | 000,912,344 | ---- | M] (Mozilla Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode [2011.07.03 21:42:24 | 000,912,344 | ---- | M] (Mozilla Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Users\Maja\AppData\Local\Google\Chrome\Application\chrome.exe" --show-icons [2012.03.10 10:21:44 | 001,049,072 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Users\Maja\AppData\Local\Google\Chrome\Application\chrome.exe" --hide-icons [2012.03.10 10:21:44 | 001,049,072 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Users\Maja\AppData\Local\Google\Chrome\Application\chrome.exe" --make-default-browser [2012.03.10 10:21:44 | 001,049,072 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Users\Maja\AppData\Local\Google\Chrome\Application\chrome.exe" [2012.03.10 10:21:44 | 001,049,072 | ---- | M] (Google Inc.)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2009.07.14 02:14:21 | 000,176,128 | ---- | M] (Microsoft Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2009.07.14 02:14:21 | 000,176,128 | ---- | M] (Microsoft Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2009.07.14 02:14:21 | 000,176,128 | ---- | M] (Microsoft Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -extoff [2010.09.08 05:31:24 | 000,673,040 | ---- | M] (Microsoft Corporation)
- HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files (x86)\Internet Explorer\iexplore.exe [2010.09.08 05:31:24 | 000,673,040 | ---- | M] (Microsoft Corporation)
- [color=#A23BEC]< hklm\software\clients\startmenuinternet|command /64 /rs >[/color]
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /HIDESHORTCUTS [2011.07.03 21:42:25 | 000,552,464 | ---- | M] (Mozilla Corporation)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SHOWSHORTCUTS [2011.07.03 21:42:25 | 000,552,464 | ---- | M] (Mozilla Corporation)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SETASDEFAULTAPPGLOBAL [2011.07.03 21:42:25 | 000,552,464 | ---- | M] (Mozilla Corporation)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE [2011.07.03 21:42:24 | 000,912,344 | ---- | M] (Mozilla Corporation)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -PREFERENCES [2011.07.03 21:42:24 | 000,912,344 | ---- | M] (Mozilla Corporation)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -SAFE-MODE [2011.07.03 21:42:24 | 000,912,344 | ---- | M] (Mozilla Corporation)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\USERS\MAJA\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --SHOW-ICONS [2012.03.10 10:21:44 | 001,049,072 | ---- | M] (Google Inc.)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\USERS\MAJA\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --HIDE-ICONS [2012.03.10 10:21:44 | 001,049,072 | ---- | M] (Google Inc.)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\USERS\MAJA\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --MAKE-DEFAULT-BROWSER [2012.03.10 10:21:44 | 001,049,072 | ---- | M] (Google Inc.)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\USERS\MAJA\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE" [2012.03.10 10:21:44 | 001,049,072 | ---- | M] (Google Inc.)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2009.07.14 02:39:12 | 000,073,728 | ---- | M] (Microsoft Corporation)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2009.07.14 02:39:12 | 000,073,728 | ---- | M] (Microsoft Corporation)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2009.07.14 02:39:12 | 000,073,728 | ---- | M] (Microsoft Corporation)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2010.09.08 05:31:24 | 000,673,040 | ---- | M] (Microsoft Corporation)
- 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE [2010.09.08 05:31:24 | 000,673,040 | ---- | M] (Microsoft Corporation)
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /s >[/color]
- "Adobe Reader Speed Launcher" = "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" -- [2011.06.08 05:02:26 | 000,037,296 | ---- | M] (Adobe Systems Incorporated)
- "Adobe ARM" = "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" -- [2012.01.03 08:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated)
- "AVG_TRAY" = C:\Program Files (x86)\AVG\AVG10\avgtray.exe -- [2012.01.17 20:03:24 | 002,339,168 | ---- | M] (AVG Technologies CZ, s.r.o.)
- "RemoteControl" = "C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe" -- [2006.11.23 14:10:42 | 000,056,928 | ---- | M] (Cyberlink Corp.)
- "LanguageShortcut" = "C:\Program Files (x86)\CyberLink\PowerDVD\Language\Language.exe" -- [2006.12.05 21:55:32 | 000,054,832 | ---- | M] ()
- "NBKeyScan" = "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" -- [2007.09.20 08:51:46 | 001,836,328 | ---- | M] (Nero AG)
- "GrooveMonitor" = "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" -- [2006.10.26 23:47:42 | 000,031,016 | ---- | M] (Microsoft Corporation)
- "LManager" = C:\Program Files (x86)\Launch Manager\LManager.exe -- [2010.03.03 20:21:16 | 001,300,560 | ---- | M] (Dritek System Inc.)
- "SunJavaUpdateSched" = "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" -- [2010.10.29 14:49:28 | 000,249,064 | ---- | M] (Sun Microsystems, Inc.)
- "DataCardMonitor" = C:\Program Files (x86)\T-Mobile\InternetManager_H\DataCardMonitor.exe -- [2012.03.02 10:54:55 | 000,253,952 | ---- | M] (Huawei Technologies Co., Ltd.)
- "vProt" = "C:\Program Files (x86)\AVG Secure Search\vprot.exe" -- [2012.03.06 13:58:28 | 000,827,232 | ---- | M] ()
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
- "" =
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
- "" =
- "Installed" = 1
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
- "" =
- "Installed" = 1
- "NoChange" = 1
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
- "" =
- "Installed" = 1
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost /s >[/color]
- "netsvcs" = [Binary data over 100 bytes]
- "LocalService" = [Binary data over 100 bytes]
- "LocalSystemNetworkRestricted" = [Binary data over 100 bytes]
- "LocalServiceNoNetwork" = PLA [binary data] -- [2009.07.14 02:16:12 | 001,508,864 | ---- | M] (Microsoft Corporation)
- "rpcss" = RpcSs [binary data]
- "LocalServiceNetworkRestricted" = AudioSrvBthHFSrvLmHostswscsvcWPCSvc [binary data]
- "LocalServiceAndNoImpersonation" = SSDPSRVupnphostSCardSvrTBSQWAVEwcncsvc [binary data]
- "DcomLaunch" = PowerPlugPlayDcomLaunch [binary data]
- "NetworkService" = [Binary data over 100 bytes]
- "imgsvc" = StiSvc [binary data]
- "wcssvc" = WcsPlugInService [binary data] -- [2009.07.14 02:16:18 | 000,032,768 | ---- | M] (Microsoft Corporation)
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService]
- "AuthenticationCapabilities" = 8192
- "CoInitializeSecurityParam" = 1
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation]
- "AuthenticationCapabilities" = 8192
- "CoInitializeSecurityParam" = 1
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceNetworkRestricted]
- "CoInitializeSecurityParam" = 1
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceNoNetwork]
- "CoInitializeSecurityParam" = 1
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted]
- "CoInitializeSecurityParam" = 1
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs]
- "AuthenticationCapabilities" = 12320
- "CoInitializeSecurityParam" = 1
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkService]
- "CoInitializeSecurityParam" = 1
- "DefaultRpcStackSize" = 28
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkServiceRemoteDesktopHyperVAgent]
- "CoInitializeSecurityParam" = 1
- "AuthenticationCapabilities" = 8192
- "AuthenticationLevel" = 6
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkServiceRemoteDesktopPublishing]
- "CoInitializeSecurityParam" = 1
- "AuthenticationCapabilities" = 8192
- "AuthenticationLevel" = 6
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\termsvcs]
- "CoInitializeSecurityParam" = 1
- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost\wcssvc]
- "CoInitializeSecurityParam" = 1
- "CoInitializeSecurityAppID" = {CD11FAB6-1C0E-45e1-BA31-5C6008EF2607}
- [color=#E56717]========== Alternate Data Streams ==========[/color]
- @Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:0B4227B4
- @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0B4227B4
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment