View difference between Paste ID: HedXqgw4 and EQcPrqkK
SHOW: | | - or go back to the newest paste.
1-
OTL logfile created on: 17.3.2012. 14:59:51 - Run 1
1+
OTL logfile created on: 4/26/2012 2:00:48 AM - Run 1
2-
OTL by OldTimer - Version 3.2.39.0     Folder = C:\Users\Maja\Desktop
2+
OTL by OldTimer - Version 3.2.42.0     Folder = C:\Users\Spaski\Desktop
3-
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
3+
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
4-
Internet Explorer (Version = 8.0.7600.16385)
4+
Internet Explorer (Version = 8.0.7601.17514)
5-
Locale: 0000041a | Country: Hrvatska | Language: HRV | Date Format: d.M.yyyy.
5+
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6
 
7-
3,93 Gb Total Physical Memory | 2,84 Gb Available Physical Memory | 72,23% Memory free
7+
4.00 Gb Total Physical Memory | 2.69 Gb Available Physical Memory | 67.37% Memory free
8-
7,86 Gb Paging File | 6,70 Gb Available in Paging File | 85,22% Paging File free
8+
8.00 Gb Paging File | 6.55 Gb Available in Paging File | 81.96% Paging File free
9
Paging file location(s): ?:\pagefile.sys [binary data]
10
 
11
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
12-
Drive C: | 146,39 Gb Total Space | 11,90 Gb Free Space | 8,13% Space Free | Partition Type: NTFS
12+
Drive C: | 97.66 Gb Total Space | 82.41 Gb Free Space | 84.39% Space Free | Partition Type: NTFS
13-
Drive D: | 151,60 Gb Total Space | 2,20 Gb Free Space | 1,45% Space Free | Partition Type: NTFS
13+
Drive D: | 658.07 Gb Total Space | 15.81 Gb Free Space | 2.40% Space Free | Partition Type: NTFS
14-
Drive F: | 100,00 Mb Total Space | 61,66 Mb Free Space | 61,66% Space Free | Partition Type: NTFS
14+
Drive E: | 175.78 Gb Total Space | 8.94 Gb Free Space | 5.08% Space Free | Partition Type: NTFS
15-
Drive G: | 32,77 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
15+
16
Computer Name: SPASKI-PC | User Name: Spaski | Logged in as Administrator.
17-
Computer Name: MAJA-PC | User Name: Maja | Logged in as Administrator.
17+
18
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
19
 
20
[color=#E56717]========== Processes (SafeList) ==========[/color]
21
 
22
PRC - [2012/04/26 01:59:33 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Spaski\Desktop\OTL.scr
23-
PRC - [2012.03.17 14:57:39 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\Maja\Desktop\OTL.com
23+
PRC - [2012/04/26 01:45:19 | 000,353,440 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_233_ActiveX.exe
24-
PRC - [2012.03.06 13:58:29 | 000,855,904 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe
24+
PRC - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
25-
PRC - [2012.03.06 13:58:28 | 000,827,232 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
25+
PRC - [2009/02/06 14:23:36 | 000,727,720 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
26-
PRC - [2012.03.02 10:54:53 | 000,114,688 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\T-Mobile Internet Manager.exe
26+
27-
PRC - [2010.11.30 17:26:12 | 000,749,384 | ---- | M] (AVG) -- C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\BoostSpeed.exe
27+
28-
PRC - [2010.08.19 09:52:14 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
28+
29-
PRC - [2010.08.19 09:52:04 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe
29+
30-
PRC - [2010.03.03 20:21:16 | 000,325,200 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
30+
31-
PRC - [2009.12.09 22:12:50 | 001,118,208 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWlan.exe
31+
32-
PRC - [2009.12.07 13:49:24 | 000,040,960 | ---- | M] (Realtek) -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
32+
33
SRV:[b]64bit:[/b] - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
34
SRV:[b]64bit:[/b] - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
35
SRV:[b]64bit:[/b] - [2009/02/06 14:27:10 | 000,023,296 | ---- | M] (ESET) [On_Demand | Unknown] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
36
SRV:[b]64bit:[/b] - [2009/02/06 14:23:36 | 000,727,720 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)
37-
MOD - [2012.03.06 13:58:28 | 001,547,104 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll
37+
SRV - [2012/04/26 01:45:19 | 000,253,088 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
38-
MOD - [2012.03.06 13:58:28 | 000,827,232 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
38+
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
39-
MOD - [2012.03.02 10:54:53 | 000,114,688 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\T-Mobile Internet Manager.exe
39+
40-
MOD - [2010.11.30 17:26:54 | 000,350,024 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\madExcept_.bpl
40+
41-
MOD - [2010.11.30 17:26:52 | 000,184,136 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\madBasic_.bpl
41+
42-
MOD - [2010.11.30 17:26:52 | 000,050,504 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl
42+
43-
MOD - [2010.08.18 18:02:20 | 000,159,744 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\SMSPlugin.dll
43+
DRV:[b]64bit:[/b] - [2010/11/21 05:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
44-
MOD - [2010.07.31 14:54:06 | 000,065,536 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\SpeedManagerPlugin.dll
44+
DRV:[b]64bit:[/b] - [2010/11/21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
45-
MOD - [2010.07.21 11:57:06 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DialUpPlugin.dll
45+
DRV:[b]64bit:[/b] - [2010/11/21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
46-
MOD - [2010.07.21 11:53:42 | 000,122,880 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DeviceMgrPlugin.dll
46+
DRV:[b]64bit:[/b] - [2010/11/21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
47-
MOD - [2010.07.21 11:53:26 | 000,237,568 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DeviceMgrUIPlugin.dll
47+
DRV:[b]64bit:[/b] - [2010/11/21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
48-
MOD - [2010.07.21 11:51:42 | 001,019,904 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\NDISAPI.dll
48+
DRV:[b]64bit:[/b] - [2010/11/21 05:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
49-
MOD - [2010.06.28 15:41:34 | 000,155,648 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DetectDev.dll
49+
DRV:[b]64bit:[/b] - [2010/11/21 05:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
50-
MOD - [2009.09.08 12:54:44 | 000,065,536 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\ConfigFilePlugin.dll
50+
DRV:[b]64bit:[/b] - [2010/11/21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
51-
MOD - [2009.09.08 12:49:12 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\NetInfoPlugin.dll
51+
DRV:[b]64bit:[/b] - [2010/11/21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
52-
MOD - [2009.05.23 11:02:32 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\XCodec.dll
52+
DRV:[b]64bit:[/b] - [2010/11/21 05:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
53-
MOD - [2009.05.23 11:02:30 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\DeviceOperate.dll
53+
DRV:[b]64bit:[/b] - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
54-
MOD - [2009.05.23 11:02:24 | 000,557,056 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\atcomm.dll
54+
DRV:[b]64bit:[/b] - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
55-
MOD - [2009.01.09 11:31:54 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\LocaleMgrPlugin.dll
55+
DRV:[b]64bit:[/b] - [2009/07/14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
56-
MOD - [2009.01.09 11:30:38 | 000,032,768 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\NotifyServicePlugin.dll
56+
DRV:[b]64bit:[/b] - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
57-
MOD - [2008.11.08 10:52:10 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\FileManager.dll
57+
DRV:[b]64bit:[/b] - [2009/06/10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
58-
MOD - [2008.11.08 10:52:08 | 000,014,848 | ---- | M] () -- C:\Program Files (x86)\T-Mobile\InternetManager_H\isaputrace.dll
58+
DRV:[b]64bit:[/b] - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
59
DRV:[b]64bit:[/b] - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
60
DRV:[b]64bit:[/b] - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
61
DRV:[b]64bit:[/b] - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
62
DRV:[b]64bit:[/b] - [2009/02/06 14:24:50 | 000,120,128 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
63-
SRV:[b]64bit:[/b] - [2010.02.05 19:23:06 | 000,865,824 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe -- (ePowerSvc)
63+
DRV:[b]64bit:[/b] - [2009/02/06 14:23:20 | 000,132,464 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
64-
SRV:[b]64bit:[/b] - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
64+
DRV:[b]64bit:[/b] - [2009/02/06 14:19:56 | 000,141,728 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamon.sys -- (eamon)
65-
SRV:[b]64bit:[/b] - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
65+
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
66-
SRV - [2012.03.06 13:58:29 | 000,855,904 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe -- (vToolbarUpdater)
66+
67-
SRV - [2012.01.31 15:02:52 | 007,391,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
67+
68-
SRV - [2011.11.10 14:17:31 | 000,167,264 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
68+
69-
SRV - [2011.02.08 04:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe -- (avgwd)
69+
70-
SRV - [2010.08.19 09:52:04 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe)
70+
71-
SRV - [2010.03.03 20:21:16 | 000,325,200 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
71+
72-
SRV - [2009.12.07 13:49:24 | 000,040,960 | ---- | M] (Realtek) [Auto | Running] -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe -- (Realtek11nSU)
72+
73-
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
73+
74
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
75
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
76
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
77
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
78-
DRV:[b]64bit:[/b] - [2011.05.27 19:05:26 | 000,118,864 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
78+
79-
DRV:[b]64bit:[/b] - [2011.04.04 23:59:54 | 000,377,936 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
79+
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
80-
DRV:[b]64bit:[/b] - [2011.03.16 15:03:18 | 000,037,456 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
80+
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
81-
DRV:[b]64bit:[/b] - [2011.03.01 13:25:18 | 000,041,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
81+
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
82-
DRV:[b]64bit:[/b] - [2011.02.22 07:12:46 | 000,026,704 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AVGIDSEH.sys -- (AVGIDSEH)
82+
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC E9 C9 62 3C 23 CD 01  [binary data]
83-
DRV:[b]64bit:[/b] - [2011.02.10 06:53:34 | 000,029,264 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
83+
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
84-
DRV:[b]64bit:[/b] - [2011.01.07 05:41:44 | 000,304,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
84+
85-
DRV:[b]64bit:[/b] - [2010.04.09 15:24:38 | 000,079,360 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
85+
86-
DRV:[b]64bit:[/b] - [2010.04.09 15:24:32 | 000,076,288 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator)
86+
87-
DRV:[b]64bit:[/b] - [2010.03.20 11:56:56 | 000,114,560 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
87+
88-
DRV:[b]64bit:[/b] - [2010.02.09 17:19:14 | 001,586,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
88+
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2012/04/26 01:36:13 | 000,000,000 | ---D | M]
89-
DRV:[b]64bit:[/b] - [2009.12.15 10:46:38 | 000,039,552 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tcpipBM.sys -- (tcpipBM)
89+
90-
DRV:[b]64bit:[/b] - [2009.12.15 10:46:30 | 000,016,512 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BMLoad.sys -- (BMLoad)
90+
91-
DRV:[b]64bit:[/b] - [2009.11.12 01:54:46 | 000,676,864 | R--- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rtl8192su.sys -- (RTL8192su)
91+
O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
92-
DRV:[b]64bit:[/b] - [2009.09.02 10:54:18 | 007,369,728 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
92+
O4:[b]64bit:[/b] - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
93-
DRV:[b]64bit:[/b] - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
93+
94-
DRV:[b]64bit:[/b] - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
94+
95-
DRV:[b]64bit:[/b] - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
95+
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
96-
DRV:[b]64bit:[/b] - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
96+
97-
DRV:[b]64bit:[/b] - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
97+
98-
DRV:[b]64bit:[/b] - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
98+
99-
DRV:[b]64bit:[/b] - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
99+
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
100-
DRV:[b]64bit:[/b] - [2009.06.18 19:12:32 | 000,272,432 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
100+
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.16.1
101-
DRV:[b]64bit:[/b] - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
101+
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EA34F33F-7074-46F2-B36C-F844CA338550}: DhcpNameServer = 192.168.16.1
102-
DRV:[b]64bit:[/b] - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
102+
103-
DRV:[b]64bit:[/b] - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
103+
104-
DRV:[b]64bit:[/b] - [2009.06.10 21:34:18 | 000,057,344 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20)
104+
105-
DRV:[b]64bit:[/b] - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
105+
106-
DRV - [2009.09.02 08:58:08 | 000,225,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\RtsUStor.sys -- (RSUSBSTOR)
106+
107-
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
107+
108-
DRV - [2006.07.24 15:05:00 | 000,005,632 | ---- | M] () [File_System | System | Stopped] -- C:\Windows\SysWow64\drivers\StarOpen.sys -- (StarOpen)
108+
109
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
110
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
111
O32 - HKLM CDRom: AutoRun - 1
112
O34 - HKLM BootExecute: (autocheck autochk *)
113
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
114
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
115
O35 - HKLM\..comfile [open] -- "%1" %*
116
O35 - HKLM\..exefile [open] -- "%1" %*
117
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
118
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
119
O37 - HKLM\...com [@ = comfile] -- "%1" %*
120
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
121
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
122-
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.hr/
122+
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
123-
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
123+
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
124-
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = hr
124+
125-
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A6 8D C9 AC C8 6B CB 01  [binary data]
125+
126-
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
126+
127-
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
127+
CREATERESTOREPOINT
128
Restore point Set: OTL Restore Point
129-
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={C6BE1A76-DC2E-409F-A6A3-647C6F1480E7}&mid=fe26c648f094485fa33cd32616c0ea32-ecd91c8af34f63441a093be8e041007713a83bc3&lang=us&ds=AVG&pr=fr&d=2012-03-06 13:57:59&v=9.0.0.18&sap=dsp&q={searchTerms}
129+
130
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
131
 
132-
[color=#E56717]========== FireFox ==========[/color]
132+
[2012/04/26 11:24:10 | 000,000,000 | ---D | C] -- C:\Windows\Panther
133
[2012/04/26 11:23:56 | 000,000,000 | -HSD | C] -- C:\Boot
134-
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
134+
[2012/04/26 10:25:33 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
135-
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
135+
[2012/04/26 10:25:02 | 000,000,000 | -HSD | C] -- C:\System Volume Information
136-
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
136+
[2012/04/26 01:59:29 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Spaski\Desktop\OTL.scr
137-
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
137+
[2012/04/26 01:58:54 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Spaski\Desktop\OTL.com
138-
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1423
138+
[2012/04/26 01:45:25 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Roaming\Macromedia
139-
FF - prefs.js..extensions.enabledItems: avg@toolbar:9.0.0.18.3
139+
[2012/04/26 01:45:24 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Roaming\Adobe
140-
FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7B4d61166e-13cb-4446-afe2-7009775e8b88%7D&mid=fe26c648f094485fa33cd32616c0ea32-ecd91c8af34f63441a093be8e041007713a83bc3&ds=AVG&v=9.0.0.18.3&lang=us&pr=fr&d=2012-03-06%2013%3A57%3A59&sap=ku&q="
140+
[2012/04/26 01:43:26 | 000,249,656 | ---- | C] (Doctor Web, Ltd.) -- C:\Users\Spaski\Desktop\te94decrypt.exe
141-
FF - user.js - File not found
141+
[2012/04/26 01:38:48 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
142
[2012/04/26 01:38:48 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
143-
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
143+
[2012/04/26 01:36:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
144-
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
144+
[2012/04/26 01:36:13 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
145-
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
145+
[2012/04/26 01:36:13 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
146-
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
146+
[2012/04/26 01:35:44 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
147-
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
147+
[2012/04/26 01:31:50 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
148-
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Maja\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
148+
[2012/04/26 01:30:58 | 000,000,000 | R--D | C] -- C:\Users\Spaski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
149-
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Maja\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
149+
[2012/04/26 01:30:58 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Searches
150
[2012/04/26 01:30:58 | 000,000,000 | R--D | C] -- C:\Users\Spaski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
151-
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG10\Firefox4\ [2012.03.07 10:38:13 | 000,000,000 | ---D | M]
151+
[2012/04/26 01:30:58 | 000,000,000 | -H-D | C] -- C:\Users\Spaski\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
152-
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon
152+
[2012/04/26 01:30:51 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Roaming\Identities
153-
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\9.0.0.18\ [2012.03.06 13:58:38 | 000,000,000 | ---D | M]
153+
[2012/04/26 01:30:49 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Contacts
154-
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.07.03 21:42:25 | 000,000,000 | ---D | M]
154+
[2012/04/26 01:30:48 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Local\VirtualStore
155-
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.07.21 02:55:30 | 000,000,000 | ---D | M]
155+
[2012/04/26 01:30:41 | 000,000,000 | --SD | C] -- C:\Users\Spaski\AppData\Roaming\Microsoft
156
[2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Videos
157-
[2010.10.14 19:33:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maja\AppData\Roaming\mozilla\Extensions
157+
[2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Saved Games
158-
[2010.10.14 19:33:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Maja\AppData\Roaming\mozilla\Firefox\Profiles\b26k63zr.default\extensions
158+
[2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Pictures
159-
[2012.03.06 14:45:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
159+
[2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Music
160-
[2010.10.14 19:17:00 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
160+
[2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
161-
[2011.02.19 21:07:48 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
161+
[2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Links
162-
[2012.03.07 10:38:13 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES (X86)\AVG\AVG10\FIREFOX4
162+
[2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Favorites
163-
[2012.03.06 13:58:38 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\PROGRAMDATA\AVG SECURE SEARCH\9.0.0.18
163+
[2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Downloads
164-
[2011.02.02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
164+
[2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Documents
165-
[2012.03.06 13:58:28 | 000,003,766 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
165+
[2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\Desktop
166
[2012/04/26 01:30:41 | 000,000,000 | R--D | C] -- C:\Users\Spaski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
167-
[color=#E56717]========== Chrome  ==========[/color]
167+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\AppData\Local\Temporary Internet Files
168
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Templates
169-
CHR - default_search_provider: AVG Secure Search (Enabled)
169+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Start Menu
170-
CHR - default_search_provider: search_url = http://search.avg.com/?d=4de4b7d4&v=7.4.22.4&i=26&tp=ggl-chrome&q={searchTerms}
170+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\SendTo
171-
CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/complete/search?output=chrome&client=chrome&q={searchTerms}
171+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Recent
172-
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
172+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\PrintHood
173-
CHR - plugin: Native Client (Enabled) = C:\Users\Maja\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
173+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\NetHood
174-
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Maja\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll
174+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Documents\My Videos
175-
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Maja\AppData\Local\Google\Chrome\Application\17.0.963.56\gcswf32.dll
175+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Documents\My Pictures
176-
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
176+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Documents\My Music
177-
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Maja\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1374_0\plugins/avgnpss.dll
177+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\My Documents
178-
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
178+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Local Settings
179-
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
179+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\AppData\Local\History
180-
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
180+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Cookies
181-
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
181+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\Application Data
182-
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
182+
[2012/04/26 01:30:41 | 000,000,000 | -HSD | C] -- C:\Users\Spaski\AppData\Local\Application Data
183-
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
183+
[2012/04/26 01:30:41 | 000,000,000 | -H-D | C] -- C:\Users\Spaski\AppData
184-
CHR - plugin: Google Update (Enabled) = C:\Users\Maja\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
184+
[2012/04/26 01:30:41 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Local\Temp
185-
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
185+
[2012/04/26 01:30:41 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Local\Microsoft
186-
CHR - plugin: Default Plug-in (Enabled) = default_plugin
186+
[2012/04/26 01:30:41 | 000,000,000 | ---D | C] -- C:\Users\Spaski\AppData\Roaming\Media Center Programs
187-
CHR - Extension: AVG Safe Search = C:\Users\Maja\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1374_0\
187+
[2012/04/26 01:30:31 | 000,000,000 | -HSD | C] -- C:\Recovery
188
 
189-
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
189+
190-
O2:[b]64bit:[/b] - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll (AVG Technologies CZ, s.r.o.)
190+
191-
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
191+
[2012/04/26 11:23:58 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
192-
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office12\GR469A~1.DLL (Microsoft Corporation)
192+
[2012/04/26 10:29:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
193-
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll ()
193+
[2012/04/26 10:28:57 | 3220,578,304 | -HS- | M] () -- C:\hiberfil.sys
194-
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll ()
194+
[2012/04/26 10:28:15 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
195-
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
195+
[2012/04/26 10:28:15 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
196-
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
196+
[2012/04/26 10:28:12 | 000,116,385 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
197-
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
197+
[2012/04/26 10:28:12 | 000,116,385 | ---- | M] () -- C:\Windows\SysNative\license.rtf
198-
O4:[b]64bit:[/b] - HKLM..\Run: [Acer ePower Management] C:\Program Files\eMachines\eMachines Power Management\ePowerTray.exe (Acer Incorporated)
198+
[2012/04/26 10:25:20 | 000,274,320 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
199-
O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
199+
[2012/04/26 01:59:33 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Spaski\Desktop\OTL.scr
200-
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
200+
[2012/04/26 01:59:15 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Spaski\Desktop\OTL.com
201-
O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
201+
[2012/04/26 01:45:20 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
202-
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
202+
[2012/04/26 01:43:37 | 000,249,656 | ---- | M] (Doctor Web, Ltd.) -- C:\Users\Spaski\Desktop\te94decrypt.exe
203-
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
203+
[2012/04/26 01:37:28 | 000,001,441 | ---- | M] () -- C:\Users\Spaski\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
204-
O4 - HKLM..\Run: [DataCardMonitor] C:\Program Files (x86)\T-Mobile\InternetManager_H\DataCardMonitor.exe (Huawei Technologies Co., Ltd.)
204+
[2012/04/26 01:34:34 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
205-
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD\Language\Language.exe ()
205+
[2012/04/26 01:34:34 | 000,615,122 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
206-
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
206+
[2012/04/26 01:34:34 | 000,103,496 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
207-
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
207+
208-
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
208+
209-
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe (Nero AG)
209+
210-
O4 - HKCU..\Run: [HW_OPENEYE_OUC_T-Mobile Internet Manager] C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe (Huawei Technologies Co., Ltd.)
210+
[2012/04/26 11:23:58 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
211
[2012/04/26 11:23:56 | 000,383,786 | RHS- | C] () -- C:\bootmgr
212
[2012/04/26 10:28:05 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
213-
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
213+
[2012/04/26 10:27:59 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
214
[2012/04/26 10:25:03 | 3220,578,304 | -HS- | C] () -- C:\hiberfil.sys
215-
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
215+
[2012/04/26 01:45:20 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
216-
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
216+
[2012/04/26 01:37:28 | 000,001,441 | ---- | C] () -- C:\Users\Spaski\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
217-
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
217+
[2012/04/26 01:31:04 | 000,001,413 | ---- | C] () -- C:\Users\Spaski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
218-
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
218+
[2012/04/26 01:30:59 | 000,001,447 | ---- | C] () -- C:\Users\Spaski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
219-
O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
219+
[2012/04/26 01:30:41 | 000,000,290 | ---- | C] () -- C:\Users\Spaski\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
220-
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found
220+
[2012/04/26 01:30:41 | 000,000,272 | ---- | C] () -- C:\Users\Spaski\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
221-
O9 - Extra Button: Pošalji u OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
221+
222-
O9 - Extra 'Tools' menuitem : Po&šalji u OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
222+
223-
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
223+
224
[2009/07/14 07:08:49 | 000,002,378 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
225
 
226-
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
226+
227-
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
227+
228-
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
228+
229-
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{63DC5AC7-ECD5-45C9-B9C8-E441DDB029C4}: DhcpNameServer = 192.168.1.254
229+
230-
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AFC4BA4A-C081-4228-92CA-D3A028DF3867}: NameServer = 87.252.156.25 10.48.65.30
230+
231-
O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found
231+
232-
O18:[b]64bit:[/b] - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll (AVG Technologies CZ, s.r.o.)
232+
233-
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
233+
234-
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
234+
[color=#A23BEC]< MD5 for: AGP440.SYS  >[/color]
235-
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
235+
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
236-
O18:[b]64bit:[/b] - Protocol\Handler\viprotocol - No CLSID value found
236+
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
237-
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~2\Office12\GRA32A~1.DLL (Microsoft Corporation)
237+
[2009/07/14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
238-
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
238+
239-
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
239+
240-
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
240+
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
241-
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll ()
241+
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
242-
O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
242+
[2009/07/14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
243-
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
243+
244
[color=#A23BEC]< MD5 for: CNGAUDIT.DLL  >[/color]
245
[2009/07/14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
246
[2009/07/14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
247
[2009/07/14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
248
[2009/07/14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
249
 
250
[color=#A23BEC]< MD5 for: IASTORV.SYS  >[/color]
251-
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
251+
[2010/11/21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\drivers\iaStorV.sys
252
[2010/11/21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
253
[2010/11/21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
254-
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office12\GR469A~1.DLL (Microsoft Corporation)
254+
255
[color=#A23BEC]< MD5 for: NETLOGON.DLL  >[/color]
256-
O32 - AutoRun File - [2010.08.19 17:49:08 | 000,126,976 | R--- | M] () - G:\AutoRun.exe -- [ CDFS ]
256+
[2010/11/21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
257-
O32 - AutoRun File - [2009.06.30 17:43:22 | 000,000,048 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ]
257+
[2010/11/21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
258-
O33 - MountPoints2\{595ed4ff-644d-11e1-882c-705ab6e1773c}\Shell - "" = AutoRun
258+
[2010/11/21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
259-
O33 - MountPoints2\{595ed4ff-644d-11e1-882c-705ab6e1773c}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.08.19 17:49:08 | 000,126,976 | R--- | M] ()
259+
[2010/11/21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
260-
O33 - MountPoints2\{595ed514-644d-11e1-882c-705ab6e1773c}\Shell - "" = AutoRun
260+
261-
O33 - MountPoints2\{595ed514-644d-11e1-882c-705ab6e1773c}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.08.19 17:49:08 | 000,126,976 | R--- | M] ()
261+
[color=#A23BEC]< MD5 for: NVSTOR.SYS  >[/color]
262-
O33 - MountPoints2\{c1f35d6e-644e-11e1-bbc5-705ab6e1773c}\Shell - "" = AutoRun
262+
[2010/11/21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\drivers\nvstor.sys
263-
O33 - MountPoints2\{c1f35d6e-644e-11e1-bbc5-705ab6e1773c}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2010.08.19 17:49:08 | 000,126,976 | R--- | M] ()
263+
[2010/11/21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
264
[2010/11/21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
265-
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgchsva.exe /sync)
265+
266-
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgrsa.exe /sync /restart)
266+
[color=#A23BEC]< MD5 for: SCECLI.DLL  >[/color]
267
[2010/11/21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
268
[2010/11/21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
269
[2010/11/21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
270
[2010/11/21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
271
 
272
[color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
273
 
274
[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
275-
O37 - HKCU\...exe [@ = F4D55] -- "C:\ProgramData\F4D55F3B0000765F0003AE0FA6014588\F4D55F3B0000765F0003AE0FA6014588.exe" -s "%1" %*
275+
276
< End of report >