Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 01-Aug-15 17:58:54 - Run 2
- OTL by OldTimer - Version 3.2.69.0 Folder = D:\Đurić\Desktop
- 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
- Internet Explorer (Version = 9.11.9600.17239)
- Locale: 00000409 | Country: Sjedinjene Države | Language: ENU | Date Format: dd-MMM-yy
- 3.87 Gb Total Physical Memory | 2.03 Gb Available Physical Memory | 52.33% Memory free
- 7.75 Gb Paging File | 5.46 Gb Available in Paging File | 70.52% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
- Drive C: | 97.56 Gb Total Space | 58.32 Gb Free Space | 59.78% Space Free | Partition Type: NTFS
- Drive D: | 368.10 Gb Total Space | 216.88 Gb Free Space | 58.92% Space Free | Partition Type: NTFS
- Computer Name: DJURIC-PC | User Name: Đurić | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
- Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2015-07-30 19:16:35 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Đurić\Desktop\OTL.exe
- PRC - [2015-07-07 20:12:28 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
- PRC - [2015-07-05 21:38:57 | 000,377,000 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- PRC - [2015-05-01 11:17:04 | 001,772,672 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
- PRC - [2015-05-01 11:16:10 | 001,394,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
- PRC - [2013-11-21 08:31:44 | 000,287,592 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
- PRC - [2013-11-21 08:31:44 | 000,015,720 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
- PRC - [2013-04-11 05:11:06 | 000,292,848 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
- PRC - [2013-03-07 12:57:42 | 000,650,528 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
- PRC - [2012-12-13 17:37:26 | 000,012,288 | ---- | M] (Autodesk, Inc.) -- C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
- PRC - [2012-01-18 07:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
- PRC - [2000-01-01 02:00:00 | 000,390,616 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
- PRC - [2000-01-01 02:00:00 | 000,169,432 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2014-09-08 11:53:05 | 001,222,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\63f1339786fa9b84e97073f9859f8c51\System.WorkflowServices.ni.dll
- MOD - [2014-09-08 11:52:34 | 001,140,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\449cb8fbbaf8ae2456b7ef4a1f06bd45\System.ServiceModel.Discovery.ni.dll
- MOD - [2014-09-08 11:52:34 | 000,369,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\56f330e897ee2b713d49400e592ab592\System.ServiceModel.Routing.ni.dll
- MOD - [2014-09-08 11:52:33 | 000,082,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\e3dc87f1531b61606b24be7c88c28464\System.ServiceModel.Channels.ni.dll
- MOD - [2014-09-08 11:52:15 | 001,392,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\b58c47b19c9590780cadddf930f6bd2a\System.ServiceModel.Activities.ni.dll
- MOD - [2014-09-08 11:52:08 | 001,072,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\8a46112332f7dce3042642c03d2734ba\System.IdentityModel.ni.dll
- MOD - [2014-09-08 11:52:07 | 018,058,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\a283fadbb6dcc293c05dee07024f3b64\System.ServiceModel.ni.dll
- MOD - [2014-09-08 11:40:22 | 001,086,464 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\51b881a42d54d3042b901c7ba7708f95\System.ServiceModel.Web.ni.dll
- MOD - [2014-09-08 11:38:54 | 001,021,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\f2b32d7477ee2c1220bf4173743425ea\System.Runtime.DurableInstancing.ni.dll
- MOD - [2014-09-08 11:38:52 | 000,143,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\b8e891c1c9ccf87e5f74aef0d2f171ff\SMDiagnostics.ni.dll
- MOD - [2014-09-08 11:38:50 | 002,647,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\4fde6b1690bd0bc5b57536efbde46ddb\System.Runtime.Serialization.ni.dll
- MOD - [2014-09-08 11:37:43 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\5a4de0d567696567ddd0ad7ddf4a9e0d\System.Xaml.ni.dll
- MOD - [2014-09-08 11:24:48 | 013,102,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\adeb9af3c309921ae1b7fb8a621ee243\System.Windows.Forms.ni.dll
- MOD - [2014-09-08 11:24:37 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\717c6a68a2ad575e93bccc52a11f7c52\System.Xml.ni.dll
- MOD - [2014-09-08 11:24:31 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\276f7b53f15e66e518278753c57b78b2\System.Configuration.ni.dll
- MOD - [2014-09-08 11:24:25 | 007,069,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\e09bc975f73e4bc24ab3eb7f6373288e\System.Core.ni.dll
- MOD - [2014-09-08 11:24:21 | 001,652,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\5c5b46515e207b2025a474340de7ae15\System.Drawing.ni.dll
- MOD - [2014-09-08 11:24:20 | 009,086,464 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\68131da3061b5a1c048abf73c5bae11d\System.ni.dll
- MOD - [2014-09-08 11:24:16 | 014,407,680 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ac9bfacce80c52220e4b4b3a814aaa3d\mscorlib.ni.dll
- MOD - [2013-03-07 12:58:16 | 000,499,488 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll
- MOD - [2013-03-07 12:55:12 | 000,472,576 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll
- MOD - [2013-03-07 12:54:20 | 000,013,824 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll
- MOD - [2013-03-07 12:53:58 | 000,015,872 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll
- MOD - [2010-12-17 12:56:54 | 002,603,520 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll
- MOD - [2010-12-17 12:56:54 | 001,006,592 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll
- MOD - [2010-12-17 12:56:54 | 000,382,464 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll
- MOD - [2010-12-16 12:16:56 | 000,195,584 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll
- MOD - [2010-01-17 23:34:58 | 000,062,464 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll
- MOD - [2010-01-12 16:55:18 | 000,400,384 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll
- MOD - [2010-01-12 16:55:18 | 000,322,048 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll
- [color=#E56717]========== Services (SafeList) ==========[/color]
- SRV:[b]64bit:[/b] - [2014-09-08 11:35:03 | 001,471,352 | ---- | M] (Flexera Software LLC) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FlexNet Licensing Service 64)
- SRV:[b]64bit:[/b] - [2014-08-17 05:04:40 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
- SRV:[b]64bit:[/b] - [2014-08-17 04:53:31 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
- SRV:[b]64bit:[/b] - [2013-11-21 08:31:44 | 000,015,720 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
- SRV:[b]64bit:[/b] - [2013-10-23 17:14:22 | 000,348,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
- SRV:[b]64bit:[/b] - [2013-10-23 17:14:22 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
- SRV:[b]64bit:[/b] - [2013-08-27 14:32:30 | 000,828,376 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe -- (Intel(R)
- SRV:[b]64bit:[/b] - [2013-08-27 14:32:14 | 000,747,520 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
- SRV:[b]64bit:[/b] - [2012-12-11 17:59:08 | 000,027,768 | ---- | M] (VIA Technologies, Inc.) [Auto | Running] -- C:\Windows\SysNative\ViakaraokeSrv.exe -- (VIAKaraokeService)
- SRV:[b]64bit:[/b] - [2009-07-14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
- SRV:[b]64bit:[/b] - [2000-01-01 02:00:00 | 000,319,080 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\igfxCUIService.exe -- (igfxCUIService1.0.0.0)
- SRV - [2015-07-27 18:24:27 | 000,268,976 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
- SRV - [2015-07-07 20:12:28 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
- SRV - [2015-07-05 21:38:56 | 000,148,136 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
- SRV - [2015-06-18 08:39:50 | 001,133,880 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
- SRV - [2015-06-18 08:39:46 | 001,871,160 | ---- | M] (Malwarebytes Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
- SRV - [2015-06-03 16:42:38 | 000,327,296 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
- SRV - [2015-05-01 11:17:04 | 001,772,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
- SRV - [2015-05-01 11:16:10 | 001,394,816 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
- SRV - [2014-08-17 04:59:44 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
- SRV - [2014-02-28 11:32:36 | 000,174,368 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe -- (iumsvc)
- SRV - [2012-12-13 17:37:26 | 000,012,288 | ---- | M] (Autodesk, Inc.) [Auto | Running] -- C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe -- (Autodesk Content Service)
- SRV - [2012-01-18 07:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
- SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
- SRV - [2000-01-01 02:00:00 | 000,390,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
- SRV - [2000-01-01 02:00:00 | 000,280,680 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
- SRV - [2000-01-01 02:00:00 | 000,169,432 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV:[b]64bit:[/b] - [2015-06-18 08:41:56 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
- DRV:[b]64bit:[/b] - [2015-06-18 08:41:40 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
- DRV:[b]64bit:[/b] - [2014-08-17 05:03:49 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
- DRV:[b]64bit:[/b] - [2014-08-17 05:03:49 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
- DRV:[b]64bit:[/b] - [2014-08-17 05:03:13 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
- DRV:[b]64bit:[/b] - [2014-08-17 05:03:13 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
- DRV:[b]64bit:[/b] - [2014-08-17 04:46:49 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
- DRV:[b]64bit:[/b] - [2014-08-17 04:45:40 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
- DRV:[b]64bit:[/b] - [2014-08-17 04:45:40 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
- DRV:[b]64bit:[/b] - [2014-01-22 08:52:10 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
- DRV:[b]64bit:[/b] - [2014-01-22 08:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
- DRV:[b]64bit:[/b] - [2013-11-21 08:31:28 | 000,632,168 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
- DRV:[b]64bit:[/b] - [2013-11-21 08:31:28 | 000,028,008 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF)
- DRV:[b]64bit:[/b] - [2013-09-27 09:53:06 | 000,134,944 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
- DRV:[b]64bit:[/b] - [2013-04-11 05:10:40 | 000,020,464 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
- DRV:[b]64bit:[/b] - [2013-04-11 05:10:38 | 000,785,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
- DRV:[b]64bit:[/b] - [2013-04-11 05:10:38 | 000,366,576 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
- DRV:[b]64bit:[/b] - [2013-03-27 09:51:04 | 000,842,312 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
- DRV:[b]64bit:[/b] - [2013-01-29 18:56:20 | 002,210,376 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
- DRV:[b]64bit:[/b] - [2012-01-18 07:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
- DRV:[b]64bit:[/b] - [2012-01-18 07:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
- DRV:[b]64bit:[/b] - [2010-11-21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
- DRV:[b]64bit:[/b] - [2010-11-21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
- DRV:[b]64bit:[/b] - [2010-11-21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
- DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
- DRV:[b]64bit:[/b] - [2010-07-29 00:25:10 | 000,029,720 | ---- | M] (Initio Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ivusb.sys -- (ivusb)
- DRV:[b]64bit:[/b] - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
- DRV:[b]64bit:[/b] - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
- DRV:[b]64bit:[/b] - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
- DRV:[b]64bit:[/b] - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
- DRV:[b]64bit:[/b] - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
- DRV:[b]64bit:[/b] - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
- DRV:[b]64bit:[/b] - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
- DRV:[b]64bit:[/b] - [2009-05-25 04:38:20 | 000,966,144 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr28ux.sys -- (netr28ux)
- DRV:[b]64bit:[/b] - [2008-05-06 16:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
- DRV:[b]64bit:[/b] - [2000-01-01 02:00:00 | 003,788,728 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
- DRV:[b]64bit:[/b] - [2000-01-01 02:00:00 | 000,454,416 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
- DRV:[b]64bit:[/b] - [2000-01-01 02:00:00 | 000,100,312 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TeeDriverx64.sys -- (MEIx64)
- DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/en-gb/?ocid=iehp
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = hr-HR
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC 78 82 AD E9 DE CF 01 [binary data]
- IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.countryCode: "HR"
- FF - prefs.js..browser.search.highlightCount: 2
- FF - prefs.js..browser.search.isUS: false
- FF - prefs.js..browser.search.order.3: "Bing "
- FF - prefs.js..browser.search.region: "HR"
- FF - prefs.js..browser.search.selectedEngine: "Bing "
- FF - prefs.js..browser.startup.homepage: "https://www.facebook.com/"
- FF - prefs.js..extensions.enabledAddons: %7Bdd3d7613-0246-469d-bc65-2a3cc1668adc%7D:1.1.8.1-signed
- FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:39.0
- FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q="
- FF - user.js - File not found
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll File not found
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.51.2: C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.51.2: C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll (Oracle Corporation)
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
- FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll ()
- FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
- FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
- FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
- FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 39.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 39.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2015-07-28 00:46:34 | 000,000,000 | ---D | M]
- FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\BingExtension\\BingSearchExtension: removed
- FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\BingExtension\\DSE: true
- [2014-09-12 05:48:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Extensions
- [2015-07-30 00:33:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\3666idxz.Vlastin Firefox\extensions
- [2015-07-27 18:30:50 | 000,000,000 | ---D | M] (Block site) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\3666idxz.Vlastin Firefox\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
- [2015-07-27 18:35:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\8daukedh.Boska\extensions
- [2015-07-27 18:35:37 | 000,000,000 | ---D | M] (Block site) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\8daukedh.Boska\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
- [2015-07-28 17:59:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\f9haetlg.default\extensions
- [2015-07-27 18:32:48 | 000,000,000 | ---D | M] (Block site) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\f9haetlg.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
- [2015-07-27 18:34:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\wwdz4zpm.Cvijece\extensions
- [2015-07-27 18:34:29 | 000,000,000 | ---D | M] (Block site) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\wwdz4zpm.Cvijece\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
- [2015-07-27 18:05:00 | 000,117,790 | ---- | M] () (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\3666idxz.Vlastin Firefox\extensions\elemhidehelper@adblockplus.org.xpi
- [2015-07-30 00:33:53 | 000,032,327 | ---- | M] () (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\3666idxz.Vlastin Firefox\extensions\imagetab@next.gen.nz.xpi
- [2015-07-27 18:20:12 | 000,466,687 | ---- | M] () (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\3666idxz.Vlastin Firefox\extensions\langpack-en-GB@firefox.mozilla.org.xpi
- [2015-07-27 18:20:36 | 000,540,254 | ---- | M] () (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\3666idxz.Vlastin Firefox\extensions\{25A1388B-6B18-46c3-BEBA-A81915D0DE8F}.xpi
- [2015-07-28 21:02:01 | 000,963,213 | ---- | M] () (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\3666idxz.Vlastin Firefox\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- [2015-05-08 23:45:22 | 000,124,845 | ---- | M] () (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\8daukedh.Boska\extensions\elemhidehelper@adblockplus.org.xpi
- [2015-05-08 23:44:57 | 000,970,672 | ---- | M] () (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\8daukedh.Boska\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- [2015-05-29 05:29:52 | 000,117,790 | ---- | M] () (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\f9haetlg.default\extensions\elemhidehelper@adblockplus.org.xpi
- [2015-07-28 17:59:45 | 000,963,213 | ---- | M] () (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\f9haetlg.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- [2015-05-08 22:29:13 | 000,124,845 | ---- | M] () (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\wwdz4zpm.Cvijece\extensions\elemhidehelper@adblockplus.org.xpi
- [2014-12-22 02:14:38 | 000,979,699 | ---- | M] () (No name found) -- C:\Users\Đurić\AppData\Roaming\Mozilla\Firefox\Profiles\wwdz4zpm.Cvijece\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- [2015-07-30 20:44:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
- [2015-07-30 20:44:20 | 000,000,000 | ---D | M] (SmartWhois Launcher) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{45925a5c-e3de-447f-bed2-ded87acae111}
- [2015-07-05 21:38:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
- [2015-07-05 21:38:57 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- File not found (No name found) -- C:\USERS\ÄURIć\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\F9HAETLG.DEFAULT\EXTENSIONS\{DD3D7613-0246-469D-BC65-2A3CC1668ADC}
- [2012-10-01 20:33:44 | 000,034,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
- [color=#E56717]========== Chrome ==========[/color]
- CHR - plugin: Error reading preferences file
- CHR - Extension: No name found = C:\Users\Đurić\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
- CHR - Extension: No name found = C:\Users\Đurić\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
- CHR - Extension: No name found = C:\Users\Đurić\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.0_0\
- CHR - Extension: No name found = C:\Users\Đurić\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
- CHR - Extension: No name found = C:\Users\Đurić\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\
- CHR - Extension: No name found = C:\Users\Đurić\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimnmioipafcokbfikbljfdeojpcgbh\3.1.11_0\
- CHR - Extension: No name found = C:\Users\Đurić\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
- CHR - Extension: No name found = C:\Users\Đurić\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.36.2_0\
- CHR - Extension: No name found = C:\Users\Đurić\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\
- CHR - Extension: No name found = C:\Users\Đurić\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
- O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
- O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll (Oracle Corporation)
- O2:[b]64bit:[/b] - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
- O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll (Oracle Corporation)
- O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
- O4:[b]64bit:[/b] - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
- O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
- O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
- O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
- O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
- O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
- O9:[b]64bit:[/b] - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
- O9:[b]64bit:[/b] - Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
- O9:[b]64bit:[/b] - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
- O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
- O9 - Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
- O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
- O13[b]64bit:[/b] - gopher Prefix: missing
- O13 - gopher Prefix: missing
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C5F0AFEC-F442-4ABF-91A3-3D9D90816F6D}: DhcpNameServer = 192.168.1.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E40F5701-B530-4A79-B580-11A57AAA89A2}: DhcpNameServer = 192.168.15.1
- O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\osf - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
- O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
- O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O32 - HKLM CDRom: AutoRun - 1
- O33 - MountPoints2\{148f233d-377e-11e5-914c-7427ead33557}\Shell - "" = AutoRun
- O33 - MountPoints2\{148f233d-377e-11e5-914c-7427ead33557}\Shell\AutoRun\command - "" = F:\Windows\CHECK\DriveNavigator.exe
- O33 - MountPoints2\{2e22c311-3599-11e4-8da0-806e6f6e6963}\Shell - "" = AutoRun
- O33 - MountPoints2\{2e22c311-3599-11e4-8da0-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Autorun.EXE
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
- O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
- O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
- O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2015-08-01 17:11:31 | 000,064,000 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\Intel_OpenCL_ICD64.dll
- [2015-08-01 17:11:31 | 000,060,416 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\Intel_OpenCL_ICD32.dll
- [2015-08-01 17:09:13 | 000,000,000 | ---D | C] -- C:\ProgramData\SlimWare Utilities, Inc
- [2015-08-01 17:08:00 | 000,000,000 | ---D | C] -- C:\Users\Đurić\AppData\Local\SlimWare Utilities Inc
- [2015-08-01 17:07:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers
- [2015-08-01 17:07:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SlimDrivers
- [2015-08-01 17:07:51 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Downloaded Installers
- [2015-08-01 17:07:28 | 000,981,728 | ---- | C] (SlimWare Utilities, Inc.) -- D:\Đurić\Desktop\SlimDrivers-setup.exe
- [2015-07-31 21:25:47 | 000,000,000 | ---D | C] -- D:\Đurić\Desktop\Season 3
- [2015-07-31 20:39:14 | 000,000,000 | ---D | C] -- D:\Đurić\Desktop\Season 2
- [2015-07-31 17:20:02 | 000,000,000 | ---D | C] -- C:\Users\Đurić\AppData\Local\CEF
- [2015-07-30 20:55:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced IP Scanner v2
- [2015-07-30 20:55:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Advanced IP Scanner
- [2015-07-30 20:44:21 | 000,000,000 | ---D | C] -- C:\ProgramData\TamoSoft
- [2015-07-30 19:16:34 | 000,602,112 | ---- | C] (OldTimer Tools) -- D:\Đurić\Desktop\OTL.exe
- [2015-07-27 18:46:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
- [2015-07-27 18:45:01 | 000,000,000 | ---D | C] -- C:\Program Files\Java
- [2015-07-26 14:32:34 | 000,000,000 | ---D | C] -- C:\Users\Đurić\AppData\Roaming\FastStone
- [2015-07-26 14:32:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Image Viewer
- [2015-07-26 14:32:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FastStone Image Viewer
- [2015-07-05 21:38:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
- [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2015-08-01 17:49:36 | 000,000,410 | ---- | M] () -- C:\Windows\tasks\SlimDrivers Startup.job
- [2015-08-01 17:48:17 | 000,026,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- [2015-08-01 17:48:17 | 000,026,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- [2015-08-01 17:47:43 | 000,113,880 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
- [2015-08-01 17:47:19 | 000,783,970 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
- [2015-08-01 17:47:19 | 000,655,392 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
- [2015-08-01 17:47:19 | 000,121,762 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
- [2015-08-01 17:46:16 | 000,000,120 | ---- | M] () -- C:\Users\Đurić\advanced_ip_scanner_MAC.bin
- [2015-08-01 17:42:41 | 000,001,936 | ---- | M] () -- C:\Users\Đurić\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 1510 series.lnk
- [2015-08-01 17:42:21 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2015-08-01 17:42:16 | 3119,927,296 | -HS- | M] () -- C:\hiberfil.sys
- [2015-08-01 17:28:50 | 000,000,366 | ---- | M] () -- C:\Windows\tasks\SlimCleaner Plus (Scheduled Scan - Đurić).job
- [2015-08-01 17:26:53 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
- [2015-08-01 17:15:05 | 000,015,328 | ---- | M] () -- C:\Windows\SysNative\results.xml
- [2015-08-01 17:13:31 | 000,000,704 | ---- | M] () -- C:\Users\Public\Desktop\Intel(R) HD Graphics Control Panel.lnk
- [2015-08-01 17:07:54 | 000,002,467 | ---- | M] () -- C:\Users\Public\Desktop\SlimDrivers.lnk
- [2015-08-01 17:07:28 | 000,981,728 | ---- | M] (SlimWare Utilities, Inc.) -- D:\Đurić\Desktop\SlimDrivers-setup.exe
- [2015-07-30 20:55:54 | 000,000,988 | ---- | M] () -- C:\Users\Public\Desktop\Advanced IP Scanner.lnk
- [2015-07-30 19:16:35 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Đurić\Desktop\OTL.exe
- [2015-07-30 05:27:27 | 000,002,186 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
- [2015-07-29 13:53:02 | 000,075,209 | ---- | M] () -- D:\Đurić\Desktop\10294267_862579973759788_1038784545424223757_n.jpg
- [2015-07-28 17:24:32 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
- [2015-07-28 17:24:32 | 000,000,944 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
- [2015-07-28 12:52:20 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
- [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2015-08-01 17:26:53 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
- [2015-08-01 17:15:28 | 000,000,366 | ---- | C] () -- C:\Windows\tasks\SlimCleaner Plus (Scheduled Scan - Đurić).job
- [2015-08-01 17:15:05 | 000,015,328 | ---- | C] () -- C:\Windows\SysNative\results.xml
- [2015-08-01 17:13:31 | 000,000,704 | ---- | C] () -- C:\Users\Public\Desktop\Intel(R) HD Graphics Control Panel.lnk
- [2015-08-01 17:11:30 | 000,086,528 | ---- | C] () -- C:\Windows\SysNative\igfxCUIServicePS.dll
- [2015-08-01 17:11:30 | 000,069,632 | ---- | C] ( ) -- C:\Windows\SysNative\igfxDHLibv2_0.dll
- [2015-08-01 17:11:30 | 000,059,392 | ---- | C] ( ) -- C:\Windows\SysNative\igfxDHLib.dll
- [2015-08-01 17:11:30 | 000,010,752 | ---- | C] ( ) -- C:\Windows\SysNative\igfxDILib.dll
- [2015-08-01 17:11:30 | 000,010,240 | ---- | C] ( ) -- C:\Windows\SysNative\igfxEMLibv2_0.dll
- [2015-08-01 17:11:30 | 000,010,240 | ---- | C] ( ) -- C:\Windows\SysNative\igfxEMLib.dll
- [2015-08-01 17:11:30 | 000,010,240 | ---- | C] ( ) -- C:\Windows\SysNative\igfxDILibv2_0.dll
- [2015-08-01 17:11:30 | 000,005,120 | ---- | C] ( ) -- C:\Windows\SysNative\igfxLHMLibv2_0.dll
- [2015-08-01 17:11:30 | 000,005,120 | ---- | C] ( ) -- C:\Windows\SysNative\igfxLHMLib.dll
- [2015-08-01 17:11:27 | 000,224,256 | ---- | C] () -- C:\Windows\SysNative\igdde64.dll
- [2015-08-01 17:11:27 | 000,185,856 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
- [2015-08-01 17:11:26 | 000,162,304 | ---- | C] () -- C:\Windows\SysNative\igdail64.dll
- [2015-08-01 17:11:26 | 000,143,872 | ---- | C] () -- C:\Windows\SysWow64\igdail32.dll
- [2015-08-01 17:11:18 | 000,255,488 | ---- | C] () -- C:\Windows\SysNative\igfxCPL.cpl
- [2015-08-01 17:11:18 | 000,187,844 | RHS- | C] () -- C:\Windows\SysNative\resTHA.cui
- [2015-08-01 17:11:18 | 000,180,644 | RHS- | C] () -- C:\Windows\SysNative\resELL.cui
- [2015-08-01 17:11:18 | 000,176,500 | RHS- | C] () -- C:\Windows\SysNative\resRUS.cui
- [2015-08-01 17:11:18 | 000,162,356 | RHS- | C] () -- C:\Windows\SysNative\resARA.cui
- [2015-08-01 17:11:18 | 000,161,812 | RHS- | C] () -- C:\Windows\SysNative\resHEB.cui
- [2015-08-01 17:11:18 | 000,161,764 | RHS- | C] () -- C:\Windows\SysNative\resJPN.cui
- [2015-08-01 17:11:18 | 000,157,172 | RHS- | C] () -- C:\Windows\SysNative\resFRA.cui
- [2015-08-01 17:11:18 | 000,157,156 | RHS- | C] () -- C:\Windows\SysNative\resHUN.cui
- [2015-08-01 17:11:18 | 000,155,460 | RHS- | C] () -- C:\Windows\SysNative\resKOR.cui
- [2015-08-01 17:11:18 | 000,155,364 | RHS- | C] () -- C:\Windows\SysNative\resITA.cui
- [2015-08-01 17:11:18 | 000,155,364 | RHS- | C] () -- C:\Windows\SysNative\resDEU.cui
- [2015-08-01 17:11:18 | 000,155,204 | RHS- | C] () -- C:\Windows\SysNative\resROM.cui
- [2015-08-01 17:11:18 | 000,155,092 | RHS- | C] () -- C:\Windows\SysNative\resESN.cui
- [2015-08-01 17:11:18 | 000,154,660 | RHS- | C] () -- C:\Windows\SysNative\resPLK.cui
- [2015-08-01 17:11:18 | 000,154,516 | RHS- | C] () -- C:\Windows\SysNative\resSKY.cui
- [2015-08-01 17:11:18 | 000,154,324 | RHS- | C] () -- C:\Windows\SysNative\resNLD.cui
- [2015-08-01 17:11:18 | 000,153,764 | RHS- | C] () -- C:\Windows\SysNative\resPTB.cui
- [2015-08-01 17:11:18 | 000,153,620 | RHS- | C] () -- C:\Windows\SysNative\resTRK.cui
- [2015-08-01 17:11:18 | 000,153,604 | RHS- | C] () -- C:\Windows\SysNative\resCSY.cui
- [2015-08-01 17:11:18 | 000,153,460 | RHS- | C] () -- C:\Windows\SysNative\resPTG.cui
- [2015-08-01 17:11:18 | 000,153,060 | RHS- | C] () -- C:\Windows\SysNative\resFIN.cui
- [2015-08-01 17:11:18 | 000,152,612 | RHS- | C] () -- C:\Windows\SysNative\resHRV.cui
- [2015-08-01 17:11:18 | 000,152,164 | RHS- | C] () -- C:\Windows\SysNative\resSVE.cui
- [2015-08-01 17:11:18 | 000,152,004 | RHS- | C] () -- C:\Windows\SysNative\resSLV.cui
- [2015-08-01 17:11:18 | 000,151,060 | RHS- | C] () -- C:\Windows\SysNative\resNOR.cui
- [2015-08-01 17:11:18 | 000,150,548 | RHS- | C] () -- C:\Windows\SysNative\resDAN.cui
- [2015-08-01 17:11:18 | 000,149,236 | RHS- | C] () -- C:\Windows\SysNative\resENU.cui
- [2015-08-01 17:11:18 | 000,147,460 | RHS- | C] () -- C:\Windows\SysNative\resCHT.cui
- [2015-08-01 17:11:18 | 000,146,628 | RHS- | C] () -- C:\Windows\SysNative\resCHS.cui
- [2015-08-01 17:11:18 | 000,002,564 | ---- | C] () -- C:\Windows\SysNative\iglhxs64.vp
- [2015-08-01 17:11:18 | 000,000,895 | ---- | C] () -- C:\Windows\SysNative\CustomModeAppv2_0.exe.config
- [2015-08-01 17:11:18 | 000,000,889 | ---- | C] () -- C:\Windows\SysNative\CustomModeApp.exe.config
- [2015-08-01 17:08:05 | 000,000,410 | ---- | C] () -- C:\Windows\tasks\SlimDrivers Startup.job
- [2015-08-01 17:07:54 | 000,002,467 | ---- | C] () -- C:\Users\Public\Desktop\SlimDrivers.lnk
- [2015-07-30 20:57:22 | 000,000,120 | ---- | C] () -- C:\Users\Đurić\advanced_ip_scanner_MAC.bin
- [2015-07-30 20:55:54 | 000,000,988 | ---- | C] () -- C:\Users\Public\Desktop\Advanced IP Scanner.lnk
- [2015-07-29 13:53:01 | 000,075,209 | ---- | C] () -- D:\Đurić\Desktop\10294267_862579973759788_1038784545424223757_n.jpg
- [2014-09-08 16:27:43 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
- [2014-09-08 11:35:40 | 000,000,153 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
- [2014-09-06 10:45:47 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
- [2014-09-06 10:45:47 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
- [2014-09-06 10:45:47 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
- [2014-09-06 10:45:46 | 000,218,200 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
- [2014-09-06 10:45:45 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
- [2014-09-06 10:11:45 | 000,788,460 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
- [2014-08-14 00:23:38 | 012,728,192 | ---- | C] () -- C:\Windows\SysWow64\igd11dxva32.dll
- [color=#E56717]========== ZeroAccess Check ==========[/color]
- [2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
- [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- "" = C:\Windows\SysNative\shell32.dll -- [2014-08-17 05:02:39 | 014,175,744 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- "" = %SystemRoot%\system32\shell32.dll -- [2014-08-17 05:02:39 | 012,874,240 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
- "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Both
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
- [color=#E56717]========== LOP Check ==========[/color]
- [2014-09-08 10:39:58 | 000,000,000 | ---D | M] -- C:\Users\Đurić\AppData\Roaming\Ashampoo
- [2014-09-08 11:43:34 | 000,000,000 | ---D | M] -- C:\Users\Đurić\AppData\Roaming\Autodesk
- [2014-09-08 10:42:44 | 000,000,000 | ---D | M] -- C:\Users\Đurić\AppData\Roaming\DVDVideoSoft
- [2014-09-06 10:46:11 | 000,000,000 | ---D | M] -- C:\Users\Đurić\AppData\Roaming\MPC-HC
- [2014-11-14 23:52:06 | 000,000,000 | ---D | M] -- C:\Users\Đurić\AppData\Roaming\Oracle
- [2015-05-10 11:59:21 | 000,000,000 | ---D | M] -- C:\Users\Đurić\AppData\Roaming\uTorrent
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Custom Scans ==========[/color]
- [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
- [2015-08-01 17:42:16 | 3119,927,296 | -HS- | M] () -- C:\hiberfil.sys
- [2015-07-20 06:05:24 | 000,124,962 | ---- | M] () -- C:\IFRToolLog.txt
- [2015-08-01 17:42:18 | 4159,905,792 | -HS- | M] () -- C:\pagefile.sys
- [2014-09-06 10:09:30 | 000,000,189 | ---- | M] () -- C:\RTL8168.log
- [color=#A23BEC]< %systemroot%\Fonts\*.com >[/color]
- [2009-07-14 07:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
- [2009-07-14 07:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
- [2009-07-14 07:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
- [2009-07-14 07:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
- [color=#A23BEC]< %systemroot%\Fonts\*.dll >[/color]
- [color=#A23BEC]< %systemroot%\Fonts\*.ini >[/color]
- [2009-06-10 22:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
- [color=#A23BEC]< %systemroot%\Fonts\*.ini2 >[/color]
- [color=#A23BEC]< %systemroot%\Fonts\*.exe >[/color]
- [color=#A23BEC]< %systemroot%\system32\spool\prtprocs\w32x86\*.* >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.bak1 >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.ini >[/color]
- [color=#A23BEC]< %systemroot%\system32\*.jpg >[/color]
- [color=#A23BEC]< %systemroot%\*.jpg >[/color]
- [color=#A23BEC]< %systemroot%\*.png >[/color]
- [color=#A23BEC]< %systemroot%\*.scr >[/color]
- [color=#A23BEC]< %systemroot%\*._sy >[/color]
- [color=#A23BEC]< %APPDATA%\Adobe\Update\*.* >[/color]
- [color=#A23BEC]< %ALLUSERSPROFILE%\Favorites\*.* >[/color]
- [color=#A23BEC]< %APPDATA%\Microsoft\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
- [2009-07-14 06:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
- [color=#A23BEC]< %APPDATA%\Update\*.* >[/color]
- [color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
- [color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\bak. /s >[/color]
- [color=#A23BEC]< %systemroot%\system32\bak. /s >[/color]
- [color=#A23BEC]< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >[/color]
- [color=#A23BEC]< %systemroot%\system32\config\systemprofile\*.dat /x >[/color]
- [color=#A23BEC]< %systemroot%\*.config >[/color]
- [color=#A23BEC]< %systemroot%\system32\*.db >[/color]
- [color=#A23BEC]< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >[/color]
- [2014-09-06 10:19:50 | 000,000,221 | -HS- | M] () -- C:\Users\Đurić\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
- [color=#A23BEC]< %USERPROFILE%\Desktop\*.exe >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Common Files\*.* >[/color]
- [color=#A23BEC]< %systemroot%\*.src >[/color]
- [color=#A23BEC]< %systemroot%\install\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\DLL\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\HelpFiles\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\rundll\*.* >[/color]
- [color=#A23BEC]< %systemroot%\winn32\*.* >[/color]
- [color=#A23BEC]< %systemroot%\Java\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\test\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\Rundll32\*.* >[/color]
- [color=#A23BEC]< %systemroot%\AppPatch\Custom\*.* >[/color]
- [color=#A23BEC]< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.tmp >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.dat >[/color]
- [color=#A23BEC]< %USERPROFILE%\My Documents\*.exe >[/color]
- [color=#A23BEC]< %USERPROFILE%\*.exe >[/color]
- [color=#A23BEC]< %systemroot%\ADDINS\*.* >[/color]
- [2009-06-10 23:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
- [color=#A23BEC]< %systemroot%\assembly\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Config\*.* >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\SECURITY\Database\*.sdb /x >[/color]
- [color=#A23BEC]< %systemroot%\SYSTEM\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Web\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Driver Cache\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Mozilla Firefox\0*.exe >[/color]
- [color=#A23BEC]< %ProgramFiles%\Microsoft Common\*.* >[/color]
- [color=#A23BEC]< %ProgramFiles%\TinyProxy. >[/color]
- [color=#A23BEC]< %USERPROFILE%\Favorites\*.url /x >[/color]
- [color=#A23BEC]< %systemroot%\System32\Wbem\*.exe >[/color]
- [2009-07-14 03:14:24 | 000,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\mofcomp.exe
- [2009-07-14 03:14:45 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WinMgmt.exe
- [2009-07-14 03:14:46 | 000,115,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIADAP.exe
- [2009-07-14 03:14:46 | 000,395,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIC.exe
- [2010-11-21 05:24:27 | 000,257,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WmiPrvSE.exe
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >[/color]
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >[/color]
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement