SHOW:
|
|
- or go back to the newest paste.
| 1 | - | OTL logfile created on: 17.3.2012. 14:59:51 - Run 1 |
| 1 | + | OTL logfile created on: 4/26/2012 2:00:48 AM - Run 1 |
| 2 | - | OTL by OldTimer - Version 3.2.39.0 Folder = C:\Users\Maja\Desktop |
| 2 | + | OTL by OldTimer - Version 3.2.42.0 Folder = C:\Users\Spaski\Desktop |
| 3 | - | 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation |
| 3 | + | 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation |
| 4 | - | Internet Explorer (Version = 8.0.7600.16385) |
| 4 | + | Internet Explorer (Version = 8.0.7601.17514) |
| 5 | - | Locale: 0000041a | Country: Hrvatska | Language: HRV | Date Format: d.M.yyyy. |
| 5 | + | Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy |
| 6 | ||
| 7 | - | 3,93 Gb Total Physical Memory | 2,84 Gb Available Physical Memory | 72,23% Memory free |
| 7 | + | 4.00 Gb Total Physical Memory | 2.69 Gb Available Physical Memory | 67.37% Memory free |
| 8 | - | 7,86 Gb Paging File | 6,70 Gb Available in Paging File | 85,22% Paging File free |
| 8 | + | 8.00 Gb Paging File | 6.55 Gb Available in Paging File | 81.96% Paging File free |
| 9 | Paging file location(s): ?:\pagefile.sys [binary data] | |
| 10 | ||
| 11 | %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) | |
| 12 | - | Drive C: | 146,39 Gb Total Space | 11,90 Gb Free Space | 8,13% Space Free | Partition Type: NTFS |
| 12 | + | Drive C: | 97.66 Gb Total Space | 82.41 Gb Free Space | 84.39% Space Free | Partition Type: NTFS |
| 13 | - | Drive D: | 151,60 Gb Total Space | 2,20 Gb Free Space | 1,45% Space Free | Partition Type: NTFS |
| 13 | + | Drive D: | 658.07 Gb Total Space | 15.81 Gb Free Space | 2.40% Space Free | Partition Type: NTFS |
| 14 | - | Drive F: | 100,00 Mb Total Space | 61,66 Mb Free Space | 61,66% Space Free | Partition Type: NTFS |
| 14 | + | Drive E: | 175.78 Gb Total Space | 8.94 Gb Free Space | 5.08% Space Free | Partition Type: NTFS |
| 15 | - | Drive G: | 32,77 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS |
| 15 | + | |
| 16 | Computer Name: SPASKI-PC | User Name: Spaski | Logged in as Administrator. | |
| 17 | - | Computer Name: MAJA-PC | User Name: Maja | Logged in as Administrator. |
| 17 | + | |
| 18 | Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days | |
| 19 | ||
| 20 | [color=#E56717]========== Processes (SafeList) ==========[/color] | |
| 21 | ||
| 22 | PRC - [2012/04/26 01:59:33 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Spaski\Desktop\OTL.scr | |
| 23 | - | PRC - [2012.03.17 14:57:39 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\Maja\Desktop\OTL.com |
| 23 | + | PRC - [2012/04/26 01:45:19 | 000,353,440 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_233_ActiveX.exe |
| 24 | - | PRC - [2012.03.06 13:58:29 | 000,855,904 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe |
| 24 | + | PRC - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe |
| 25 | - | PRC - [2012.03.06 13:58:28 | 000,827,232 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe |
| 25 | + | PRC - [2009/02/06 14:23:36 | 000,727,720 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe |
| 26 | - | PRC - [2012.03.02 10:54:53 | 000,114,688 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\T-Mobile Internet Manager.exe |
| 26 | + | |
| 27 | - | PRC - [2010.11.30 17:26:12 | 000,749,384 | ---- | M] (AVG) -- C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\BoostSpeed.exe |
| 27 | + | |
| 28 | - | PRC - [2010.08.19 09:52:14 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe |
| 28 | + | |
| 29 | - | PRC - [2010.08.19 09:52:04 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe |
| 29 | + | |
| 30 | - | PRC - [2010.03.03 20:21:16 | 000,325,200 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe |
| 30 | + | |
| 31 | - | PRC - [2009.12.09 22:12:50 | 001,118,208 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWlan.exe |
| 31 | + | |
| 32 | - | PRC - [2009.12.07 13:49:24 | 000,040,960 | ---- | M] (Realtek) -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe |
| 32 | + | |
| 33 | SRV:[b]64bit:[/b] - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) | |
| 34 | SRV:[b]64bit:[/b] - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) | |
| 35 | SRV:[b]64bit:[/b] - [2009/02/06 14:27:10 | 000,023,296 | ---- | M] (ESET) [On_Demand | Unknown] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv) | |
| 36 | SRV:[b]64bit:[/b] - [2009/02/06 14:23:36 | 000,727,720 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn) | |
| 37 | - | MOD - [2012.03.06 13:58:28 | 001,547,104 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll |
| 37 | + | SRV - [2012/04/26 01:45:19 | 000,253,088 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) |
| 38 | - | MOD - [2012.03.06 13:58:28 | 000,827,232 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe |
| 38 | + | SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) |
| 39 | - | MOD - [2012.03.02 10:54:53 | 000,114,688 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\T-Mobile Internet Manager.exe |
| 39 | + | |
| 40 | - | MOD - [2010.11.30 17:26:54 | 000,350,024 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\madExcept_.bpl |
| 40 | + | |
| 41 | - | MOD - [2010.11.30 17:26:52 | 000,184,136 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\madBasic_.bpl |
| 41 | + | |
| 42 | - | MOD - [2010.11.30 17:26:52 | 000,050,504 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl |
| 42 | + | |
| 43 | - | MOD - [2010.08.18 18:02:20 | 000,159,744 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\SMSPlugin.dll |
| 43 | + | DRV:[b]64bit:[/b] - [2010/11/21 05:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) |
| 44 | - | MOD - [2010.07.31 14:54:06 | 000,065,536 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\SpeedManagerPlugin.dll |
| 44 | + | DRV:[b]64bit:[/b] - [2010/11/21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) |
| 45 | - | MOD - [2010.07.21 11:57:06 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DialUpPlugin.dll |
| 45 | + | DRV:[b]64bit:[/b] - [2010/11/21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub) |
| 46 | - | MOD - [2010.07.21 11:53:42 | 000,122,880 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DeviceMgrPlugin.dll |
| 46 | + | DRV:[b]64bit:[/b] - [2010/11/21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc) |
| 47 | - | MOD - [2010.07.21 11:53:26 | 000,237,568 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DeviceMgrUIPlugin.dll |
| 47 | + | DRV:[b]64bit:[/b] - [2010/11/21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) |
| 48 | - | MOD - [2010.07.21 11:51:42 | 001,019,904 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\NDISAPI.dll |
| 48 | + | DRV:[b]64bit:[/b] - [2010/11/21 05:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt) |
| 49 | - | MOD - [2010.06.28 15:41:34 | 000,155,648 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DetectDev.dll |
| 49 | + | DRV:[b]64bit:[/b] - [2010/11/21 05:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) |
| 50 | - | MOD - [2009.09.08 12:54:44 | 000,065,536 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\ConfigFilePlugin.dll |
| 50 | + | DRV:[b]64bit:[/b] - [2010/11/21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) |
| 51 | - | MOD - [2009.09.08 12:49:12 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\NetInfoPlugin.dll |
| 51 | + | DRV:[b]64bit:[/b] - [2010/11/21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) |
| 52 | - | MOD - [2009.05.23 11:02:32 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\XCodec.dll |
| 52 | + | DRV:[b]64bit:[/b] - [2010/11/21 05:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) |
| 53 | - | MOD - [2009.05.23 11:02:30 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DeviceOperate.dll |
| 53 | + | DRV:[b]64bit:[/b] - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) |
| 54 | - | MOD - [2009.05.23 11:02:24 | 000,557,056 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\atcomm.dll |
| 54 | + | DRV:[b]64bit:[/b] - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) |
| 55 | - | MOD - [2009.01.09 11:31:54 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\LocaleMgrPlugin.dll |
| 55 | + | DRV:[b]64bit:[/b] - [2009/07/14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) |
| 56 | - | MOD - [2009.01.09 11:30:38 | 000,032,768 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\NotifyServicePlugin.dll |
| 56 | + | DRV:[b]64bit:[/b] - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) |
| 57 | - | MOD - [2008.11.08 10:52:10 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\FileManager.dll |
| 57 | + | DRV:[b]64bit:[/b] - [2009/06/10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) |
| 58 | - | MOD - [2008.11.08 10:52:08 | 000,014,848 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\isaputrace.dll |
| 58 | + | DRV:[b]64bit:[/b] - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) |
| 59 | DRV:[b]64bit:[/b] - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) | |
| 60 | DRV:[b]64bit:[/b] - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) | |
| 61 | DRV:[b]64bit:[/b] - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) | |
| 62 | DRV:[b]64bit:[/b] - [2009/02/06 14:24:50 | 000,120,128 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr) | |
| 63 | - | SRV:[b]64bit:[/b] - [2010.02.05 19:23:06 | 000,865,824 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe -- (ePowerSvc) |
| 63 | + | DRV:[b]64bit:[/b] - [2009/02/06 14:23:20 | 000,132,464 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv) |
| 64 | - | SRV:[b]64bit:[/b] - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) |
| 64 | + | DRV:[b]64bit:[/b] - [2009/02/06 14:19:56 | 000,141,728 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamon.sys -- (eamon) |
| 65 | - | SRV:[b]64bit:[/b] - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) |
| 65 | + | DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) |
| 66 | - | SRV - [2012.03.06 13:58:29 | 000,855,904 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe -- (vToolbarUpdater) |
| 66 | + | |
| 67 | - | SRV - [2012.01.31 15:02:52 | 007,391,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent) |
| 67 | + | |
| 68 | - | SRV - [2011.11.10 14:17:31 | 000,167,264 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service) |
| 68 | + | |
| 69 | - | SRV - [2011.02.08 04:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe -- (avgwd) |
| 69 | + | |
| 70 | - | SRV - [2010.08.19 09:52:04 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe) |
| 70 | + | |
| 71 | - | SRV - [2010.03.03 20:21:16 | 000,325,200 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService) |
| 71 | + | |
| 72 | - | SRV - [2009.12.07 13:49:24 | 000,040,960 | ---- | M] (Realtek) [Auto | Running] -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe -- (Realtek11nSU) |
| 72 | + | |
| 73 | - | SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) |
| 73 | + | |
| 74 | IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
| |
| 75 | IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm | |
| 76 | IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
| |
| 77 | IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
| |
| 78 | - | DRV:[b]64bit:[/b] - [2011.05.27 19:05:26 | 000,118,864 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AVGIDSDriver.sys -- (AVGIDSDriver) |
| 78 | + | |
| 79 | - | DRV:[b]64bit:[/b] - [2011.04.04 23:59:54 | 000,377,936 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia) |
| 79 | + | IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ |
| 80 | - | DRV:[b]64bit:[/b] - [2011.03.16 15:03:18 | 000,037,456 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64) |
| 80 | + | IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp |
| 81 | - | DRV:[b]64bit:[/b] - [2011.03.01 13:25:18 | 000,041,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64) |
| 81 | + | IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us |
| 82 | - | DRV:[b]64bit:[/b] - [2011.02.22 07:12:46 | 000,026,704 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AVGIDSEH.sys -- (AVGIDSEH) |
| 82 | + | IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC E9 C9 62 3C 23 CD 01 [binary data] |
| 83 | - | DRV:[b]64bit:[/b] - [2011.02.10 06:53:34 | 000,029,264 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AVGIDSFilter.sys -- (AVGIDSFilter) |
| 83 | + | IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
|
| 84 | - | DRV:[b]64bit:[/b] - [2011.01.07 05:41:44 | 000,304,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64) |
| 84 | + | |
| 85 | - | DRV:[b]64bit:[/b] - [2010.04.09 15:24:38 | 000,079,360 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys -- (huawei_cdcacm) |
| 85 | + | |
| 86 | - | DRV:[b]64bit:[/b] - [2010.04.09 15:24:32 | 000,076,288 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator) |
| 86 | + | |
| 87 | - | DRV:[b]64bit:[/b] - [2010.03.20 11:56:56 | 000,114,560 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) |
| 87 | + | |
| 88 | - | DRV:[b]64bit:[/b] - [2010.02.09 17:19:14 | 001,586,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) |
| 88 | + | FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2012/04/26 01:36:13 | 000,000,000 | ---D | M] |
| 89 | - | DRV:[b]64bit:[/b] - [2009.12.15 10:46:38 | 000,039,552 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tcpipBM.sys -- (tcpipBM) |
| 89 | + | |
| 90 | - | DRV:[b]64bit:[/b] - [2009.12.15 10:46:30 | 000,016,512 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BMLoad.sys -- (BMLoad) |
| 90 | + | |
| 91 | - | DRV:[b]64bit:[/b] - [2009.11.12 01:54:46 | 000,676,864 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rtl8192su.sys -- (RTL8192su) |
| 91 | + | O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts |
| 92 | - | DRV:[b]64bit:[/b] - [2009.09.02 10:54:18 | 007,369,728 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) |
| 92 | + | O4:[b]64bit:[/b] - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET) |
| 93 | - | DRV:[b]64bit:[/b] - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) |
| 93 | + | |
| 94 | - | DRV:[b]64bit:[/b] - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) |
| 94 | + | |
| 95 | - | DRV:[b]64bit:[/b] - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) |
| 95 | + | O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 |
| 96 | - | DRV:[b]64bit:[/b] - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) |
| 96 | + | |
| 97 | - | DRV:[b]64bit:[/b] - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) |
| 97 | + | |
| 98 | - | DRV:[b]64bit:[/b] - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) |
| 98 | + | |
| 99 | - | DRV:[b]64bit:[/b] - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) |
| 99 | + | O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
|
| 100 | - | DRV:[b]64bit:[/b] - [2009.06.18 19:12:32 | 000,272,432 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) |
| 100 | + | O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.16.1 |
| 101 | - | DRV:[b]64bit:[/b] - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) |
| 101 | + | O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EA34F33F-7074-46F2-B36C-F844CA338550}: DhcpNameServer = 192.168.16.1
|
| 102 | - | DRV:[b]64bit:[/b] - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) |
| 102 | + | |
| 103 | - | DRV:[b]64bit:[/b] - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) |
| 103 | + | |
| 104 | - | DRV:[b]64bit:[/b] - [2009.06.10 21:34:18 | 000,057,344 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20) |
| 104 | + | |
| 105 | - | DRV:[b]64bit:[/b] - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) |
| 105 | + | |
| 106 | - | DRV - [2009.09.02 08:58:08 | 000,225,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\RtsUStor.sys -- (RSUSBSTOR) |
| 106 | + | |
| 107 | - | DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) |
| 107 | + | |
| 108 | - | DRV - [2006.07.24 15:05:00 | 000,005,632 | ---- | M] () [File_System | System | Stopped] -- C:\Windows\SysWow64\drivers\StarOpen.sys -- (StarOpen) |
| 108 | + | |
| 109 | O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
| |
| 110 | O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
| |
| 111 | O32 - HKLM CDRom: AutoRun - 1 | |
| 112 | O34 - HKLM BootExecute: (autocheck autochk *) | |
| 113 | O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* | |
| 114 | O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* | |
| 115 | O35 - HKLM\..comfile [open] -- "%1" %* | |
| 116 | O35 - HKLM\..exefile [open] -- "%1" %* | |
| 117 | O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* | |
| 118 | O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* | |
| 119 | O37 - HKLM\...com [@ = comfile] -- "%1" %* | |
| 120 | O37 - HKLM\...exe [@ = exefile] -- "%1" %* | |
| 121 | O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) | |
| 122 | - | IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.hr/ |
| 122 | + | O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) |
| 123 | - | IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/ |
| 123 | + | O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) |
| 124 | - | IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = hr |
| 124 | + | |
| 125 | - | IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A6 8D C9 AC C8 6B CB 01 [binary data] |
| 125 | + | |
| 126 | - | IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
|
| 126 | + | |
| 127 | - | IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
|
| 127 | + | CREATERESTOREPOINT |
| 128 | Restore point Set: OTL Restore Point | |
| 129 | - | IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={C6BE1A76-DC2E-409F-A6A3-647C6F1480E7}&mid=fe26c648f094485fa33cd32616c0ea32-ecd91c8af34f63441a093be8e041007713a83bc3&lang=us&ds=AVG&pr=fr&d=2012-03-06 13:57:59&v=9.0.0.18&sap=dsp&q={searchTerms}
|
| 129 | + | |
| 130 | [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] | |
| 131 | ||
| 132 | - | [color=#E56717]========== FireFox ==========[/color] |
| 132 | + | [2012/04/26 11:24:10 | 000,000,000 | ---D | C] -- C:\Windows\Panther |
| 133 | [2012/04/26 11:23:56 | 000,000,000 | -HSD | C] -- C:\Boot | |
| 134 | - | FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search" |
| 134 | + | [2012/04/26 10:25:33 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch |
| 135 | - | FF - prefs.js..browser.startup.homepage: "http://www.google.com" |
| 135 | + | [2012/04/26 10:25:02 | 000,000,000 | -HSD | C] -- C:\System Volume Information |
| 136 | - | FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
|
| 136 | + | [2012/04/26 01:59:29 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Spaski\Desktop\OTL.scr |
| 137 | - | FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
|
| 137 | + | [2012/04/26 01:58:54 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Spaski\Desktop\OTL.com |
| 138 | - | FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1423
|
| 138 | + | [2012/04/26 01:45:25 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Roaming\Macromedia |
| 139 | - | FF - prefs.js..extensions.enabledItems: avg@toolbar:9.0.0.18.3 |
| 139 | + | [2012/04/26 01:45:24 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Roaming\Adobe |
| 140 | - | FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7B4d61166e-13cb-4446-afe2-7009775e8b88%7D&mid=fe26c648f094485fa33cd32616c0ea32-ecd91c8af34f63441a093be8e041007713a83bc3&ds=AVG&v=9.0.0.18.3&lang=us&pr=fr&d=2012-03-06%2013%3A57%3A59&sap=ku&q=" |
| 140 | + | [2012/04/26 01:43:26 | 000,249,656 | ---- | C] (Doctor Web, Ltd.) -- C:\Users\Spaski\Desktop\te94decrypt.exe |
| 141 | - | FF - user.js - File not found |
| 141 | + | [2012/04/26 01:38:48 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed |
| 142 | [2012/04/26 01:38:48 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed | |
| 143 | - | FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () |
| 143 | + | [2012/04/26 01:36:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET |
| 144 | - | FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) |
| 144 | + | [2012/04/26 01:36:13 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET |
| 145 | - | FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) |
| 145 | + | [2012/04/26 01:36:13 | 000,000,000 | ---D | C] -- C:\Program Files\ESET |
| 146 | - | FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation) |
| 146 | + | [2012/04/26 01:35:44 | 000,000,000 | -HSD | C] -- C:\Windows\Installer |
| 147 | - | FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) |
| 147 | + | [2012/04/26 01:31:50 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution |
| 148 | - | FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Maja\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.) |
| 148 | + | [2012/04/26 01:30:58 | 000,000,000 | R--D | C] -- C:\Users\Spaski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup |
| 149 | - | FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Maja\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.) |
| 149 | + | [2012/04/26 01:30:58 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Searches |
| 150 | [2012/04/26 01:30:58 | 000,000,000 | R--D | C] -- C:\Users\Spaski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools | |
| 151 | - | FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG10\Firefox4\ [2012.03.07 10:38:13 | 000,000,000 | ---D | M]
|
| 151 | + | [2012/04/26 01:30:58 | 000,000,000 | -H-D | C] -- C:\Users\Spaski\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned |
| 152 | - | FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon |
| 152 | + | [2012/04/26 01:30:51 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Roaming\Identities |
| 153 | - | FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\9.0.0.18\ [2012.03.06 13:58:38 | 000,000,000 | ---D | M] |
| 153 | + | [2012/04/26 01:30:49 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Contacts |
| 154 | - | FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.07.03 21:42:25 | 000,000,000 | ---D | M] |
| 154 | + | [2012/04/26 01:30:48 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Local\VirtualStore |
| 155 | - | FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.07.21 02:55:30 | 000,000,000 | ---D | M] |
| 155 | + | [2012/04/26 01:30:41 | 000,000,000 | --SD | C] -- C:\Users\Spaski\AppData\Roaming\Microsoft |
| 156 | [2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Videos | |
| 157 | - | [2010.10.14 19:33:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maja\AppData\Roaming\mozilla\Extensions |
| 157 | + | [2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Saved Games |
| 158 | - | [2010.10.14 19:33:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maja\AppData\Roaming\mozilla\Firefox\Profiles\b26k63zr.default\extensions |
| 158 | + | [2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Pictures |
| 159 | - | [2012.03.06 14:45:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions |
| 159 | + | [2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Music |
| 160 | - | [2010.10.14 19:17:00 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
|
| 160 | + | [2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance |
| 161 | - | [2011.02.19 21:07:48 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
|
| 161 | + | [2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Links |
| 162 | - | [2012.03.07 10:38:13 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES (X86)\AVG\AVG10\FIREFOX4 |
| 162 | + | [2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Favorites |
| 163 | - | [2012.03.06 13:58:38 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\PROGRAMDATA\AVG SECURE SEARCH\9.0.0.18 |
| 163 | + | [2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Downloads |
| 164 | - | [2011.02.02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll |
| 164 | + | [2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Documents |
| 165 | - | [2012.03.06 13:58:28 | 000,003,766 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml |
| 165 | + | [2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Desktop |
| 166 | [2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories | |
| 167 | - | [color=#E56717]========== Chrome ==========[/color] |
| 167 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\AppData\Local\Temporary Internet Files |
| 168 | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Templates | |
| 169 | - | CHR - default_search_provider: AVG Secure Search (Enabled) |
| 169 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Start Menu |
| 170 | - | CHR - default_search_provider: search_url = http://search.avg.com/?d=4de4b7d4&v=7.4.22.4&i=26&tp=ggl-chrome&q={searchTerms}
|
| 170 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\SendTo |
| 171 | - | CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/complete/search?output=chrome&client=chrome&q={searchTerms}
|
| 171 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Recent |
| 172 | - | CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer |
| 172 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\PrintHood |
| 173 | - | CHR - plugin: Native Client (Enabled) = C:\Users\Maja\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll |
| 173 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\NetHood |
| 174 | - | CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Maja\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll |
| 174 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Documents\My Videos |
| 175 | - | CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Maja\AppData\Local\Google\Chrome\Application\17.0.963.56\gcswf32.dll |
| 175 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Documents\My Pictures |
| 176 | - | CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll |
| 176 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Documents\My Music |
| 177 | - | CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Maja\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1374_0\plugins/avgnpss.dll |
| 177 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\My Documents |
| 178 | - | CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll |
| 178 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Local Settings |
| 179 | - | CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll |
| 179 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\AppData\Local\History |
| 180 | - | CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll |
| 180 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Cookies |
| 181 | - | CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll |
| 181 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Application Data |
| 182 | - | CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL |
| 182 | + | [2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\AppData\Local\Application Data |
| 183 | - | CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll |
| 183 | + | [2012/04/26 01:30:41 | 000,000,000 | -H-D | C] -- C:\Users\Spaski\AppData |
| 184 | - | CHR - plugin: Google Update (Enabled) = C:\Users\Maja\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll |
| 184 | + | [2012/04/26 01:30:41 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Local\Temp |
| 185 | - | CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll |
| 185 | + | [2012/04/26 01:30:41 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Local\Microsoft |
| 186 | - | CHR - plugin: Default Plug-in (Enabled) = default_plugin |
| 186 | + | [2012/04/26 01:30:41 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Roaming\Media Center Programs |
| 187 | - | CHR - Extension: AVG Safe Search = C:\Users\Maja\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1374_0\ |
| 187 | + | [2012/04/26 01:30:31 | 000,000,000 | -HSD | C] -- C:\Recovery |
| 188 | ||
| 189 | - | O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts |
| 189 | + | |
| 190 | - | O2:[b]64bit:[/b] - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll (AVG Technologies CZ, s.r.o.)
|
| 190 | + | |
| 191 | - | O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
|
| 191 | + | [2012/04/26 11:23:58 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK |
| 192 | - | O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office12\GR469A~1.DLL (Microsoft Corporation)
|
| 192 | + | [2012/04/26 10:29:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat |
| 193 | - | O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll ()
|
| 193 | + | [2012/04/26 10:28:57 | 3220,578,304 | -HS- | M] () -- C:\hiberfil.sys |
| 194 | - | O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll ()
|
| 194 | + | [2012/04/26 10:28:15 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 |
| 195 | - | O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
|
| 195 | + | [2012/04/26 10:28:15 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 |
| 196 | - | O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
|
| 196 | + | [2012/04/26 10:28:12 | 000,116,385 | ---- | M] () -- C:\Windows\SysWow64\license.rtf |
| 197 | - | O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
|
| 197 | + | [2012/04/26 10:28:12 | 000,116,385 | ---- | M] () -- C:\Windows\SysNative\license.rtf |
| 198 | - | O4:[b]64bit:[/b] - HKLM..\Run: [Acer ePower Management] C:\Program Files\eMachines\eMachines Power Management\ePowerTray.exe (Acer Incorporated) |
| 198 | + | [2012/04/26 10:25:20 | 000,274,320 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT |
| 199 | - | O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) |
| 199 | + | [2012/04/26 01:59:33 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Spaski\Desktop\OTL.scr |
| 200 | - | O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) |
| 200 | + | [2012/04/26 01:59:15 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Spaski\Desktop\OTL.com |
| 201 | - | O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) |
| 201 | + | [2012/04/26 01:45:20 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job |
| 202 | - | O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) |
| 202 | + | [2012/04/26 01:43:37 | 000,249,656 | ---- | M] (Doctor Web, Ltd.) -- C:\Users\Spaski\Desktop\te94decrypt.exe |
| 203 | - | O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.) |
| 203 | + | [2012/04/26 01:37:28 | 000,001,441 | ---- | M] () -- C:\Users\Spaski\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk |
| 204 | - | O4 - HKLM..\Run: [DataCardMonitor] C:\Program Files (x86)\T-Mobile\InternetManager_H\DataCardMonitor.exe (Huawei Technologies Co., Ltd.) |
| 204 | + | [2012/04/26 01:34:34 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI |
| 205 | - | O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD\Language\Language.exe () |
| 205 | + | [2012/04/26 01:34:34 | 000,615,122 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat |
| 206 | - | O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) |
| 206 | + | [2012/04/26 01:34:34 | 000,103,496 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat |
| 207 | - | O4 - HKLM..\Run: [NBKeyScan] C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG) |
| 207 | + | |
| 208 | - | O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe () |
| 208 | + | |
| 209 | - | O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe (Nero AG)
|
| 209 | + | |
| 210 | - | O4 - HKCU..\Run: [HW_OPENEYE_OUC_T-Mobile Internet Manager] C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe (Huawei Technologies Co., Ltd.) |
| 210 | + | [2012/04/26 11:23:58 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK |
| 211 | [2012/04/26 11:23:56 | 000,383,786 | RHS- | C] () -- C:\bootmgr | |
| 212 | [2012/04/26 10:28:05 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk | |
| 213 | - | O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 |
| 213 | + | [2012/04/26 10:27:59 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk |
| 214 | [2012/04/26 10:25:03 | 3220,578,304 | -HS- | C] () -- C:\hiberfil.sys | |
| 215 | - | O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 |
| 215 | + | [2012/04/26 01:45:20 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job |
| 216 | - | O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 |
| 216 | + | [2012/04/26 01:37:28 | 000,001,441 | ---- | C] () -- C:\Users\Spaski\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk |
| 217 | - | O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 |
| 217 | + | [2012/04/26 01:31:04 | 000,001,413 | ---- | C] () -- C:\Users\Spaski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk |
| 218 | - | O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1 |
| 218 | + | [2012/04/26 01:30:59 | 000,001,447 | ---- | C] () -- C:\Users\Spaski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk |
| 219 | - | O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found |
| 219 | + | [2012/04/26 01:30:41 | 000,000,290 | ---- | C] () -- C:\Users\Spaski\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk |
| 220 | - | O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found |
| 220 | + | [2012/04/26 01:30:41 | 000,000,272 | ---- | C] () -- C:\Users\Spaski\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk |
| 221 | - | O9 - Extra Button: Pošalji u OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
|
| 221 | + | |
| 222 | - | O9 - Extra 'Tools' menuitem : Po&šalji u OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
|
| 222 | + | |
| 223 | - | O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
|
| 223 | + | |
| 224 | [2009/07/14 07:08:49 | 000,002,378 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT | |
| 225 | ||
| 226 | - | O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
|
| 226 | + | |
| 227 | - | O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
|
| 227 | + | |
| 228 | - | O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
|
| 228 | + | |
| 229 | - | O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{63DC5AC7-ECD5-45C9-B9C8-E441DDB029C4}: DhcpNameServer = 192.168.1.254
|
| 229 | + | |
| 230 | - | O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AFC4BA4A-C081-4228-92CA-D3A028DF3867}: NameServer = 87.252.156.25 10.48.65.30
|
| 230 | + | |
| 231 | - | O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found |
| 231 | + | |
| 232 | - | O18:[b]64bit:[/b] - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll (AVG Technologies CZ, s.r.o.)
|
| 232 | + | |
| 233 | - | O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found |
| 233 | + | |
| 234 | - | O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found |
| 234 | + | [color=#A23BEC]< MD5 for: AGP440.SYS >[/color] |
| 235 | - | O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found |
| 235 | + | [2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys |
| 236 | - | O18:[b]64bit:[/b] - Protocol\Handler\viprotocol - No CLSID value found |
| 236 | + | [2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys |
| 237 | - | O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~2\Office12\GRA32A~1.DLL (Microsoft Corporation)
|
| 237 | + | [2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys |
| 238 | - | O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
|
| 238 | + | |
| 239 | - | O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
|
| 239 | + | |
| 240 | - | O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
|
| 240 | + | [2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys |
| 241 | - | O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll ()
|
| 241 | + | [2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys |
| 242 | - | O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
|
| 242 | + | [2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys |
| 243 | - | O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
|
| 243 | + | |
| 244 | [color=#A23BEC]< MD5 for: CNGAUDIT.DLL >[/color] | |
| 245 | [2009/07/14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll | |
| 246 | [2009/07/14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll | |
| 247 | [2009/07/14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll | |
| 248 | [2009/07/14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll | |
| 249 | ||
| 250 | [color=#A23BEC]< MD5 for: IASTORV.SYS >[/color] | |
| 251 | - | O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) |
| 251 | + | [2010/11/21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\drivers\iaStorV.sys |
| 252 | [2010/11/21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys | |
| 253 | [2010/11/21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys | |
| 254 | - | O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office12\GR469A~1.DLL (Microsoft Corporation)
|
| 254 | + | |
| 255 | [color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color] | |
| 256 | - | O32 - AutoRun File - [2010.08.19 17:49:08 | 000,126,976 | R--- | M] () - G:\AutoRun.exe -- [ CDFS ] |
| 256 | + | [2010/11/21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll |
| 257 | - | O32 - AutoRun File - [2009.06.30 17:43:22 | 000,000,048 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ] |
| 257 | + | [2010/11/21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll |
| 258 | - | O33 - MountPoints2\{595ed4ff-644d-11e1-882c-705ab6e1773c}\Shell - "" = AutoRun
|
| 258 | + | [2010/11/21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll |
| 259 | - | O33 - MountPoints2\{595ed4ff-644d-11e1-882c-705ab6e1773c}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.08.19 17:49:08 | 000,126,976 | R--- | M] ()
|
| 259 | + | [2010/11/21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll |
| 260 | - | O33 - MountPoints2\{595ed514-644d-11e1-882c-705ab6e1773c}\Shell - "" = AutoRun
|
| 260 | + | |
| 261 | - | O33 - MountPoints2\{595ed514-644d-11e1-882c-705ab6e1773c}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.08.19 17:49:08 | 000,126,976 | R--- | M] ()
|
| 261 | + | [color=#A23BEC]< MD5 for: NVSTOR.SYS >[/color] |
| 262 | - | O33 - MountPoints2\{c1f35d6e-644e-11e1-bbc5-705ab6e1773c}\Shell - "" = AutoRun
|
| 262 | + | [2010/11/21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\drivers\nvstor.sys |
| 263 | - | O33 - MountPoints2\{c1f35d6e-644e-11e1-bbc5-705ab6e1773c}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.08.19 17:49:08 | 000,126,976 | R--- | M] ()
|
| 263 | + | [2010/11/21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys |
| 264 | [2010/11/21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys | |
| 265 | - | O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgchsva.exe /sync) |
| 265 | + | |
| 266 | - | O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgrsa.exe /sync /restart) |
| 266 | + | [color=#A23BEC]< MD5 for: SCECLI.DLL >[/color] |
| 267 | [2010/11/21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll | |
| 268 | [2010/11/21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll | |
| 269 | [2010/11/21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll | |
| 270 | [2010/11/21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll | |
| 271 | ||
| 272 | [color=#A23BEC]< %systemroot%\*. /mp /s >[/color] | |
| 273 | ||
| 274 | [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color] | |
| 275 | - | O37 - HKCU\...exe [@ = F4D55] -- "C:\ProgramData\F4D55F3B0000765F0003AE0FA6014588\F4D55F3B0000765F0003AE0FA6014588.exe" -s "%1" %* |
| 275 | + | |
| 276 | < End of report > |