Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 6.1.2017. 7:52:12 - Run 3
- OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Korisnik\Desktop
- 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
- Internet Explorer (Version = 9.11.9600.16428)
- Locale: 0000041a | Country: Hrvatska | Language: HRV | Date Format: d.M.yyyy.
- 3,90 Gb Total Physical Memory | 1,80 Gb Available Physical Memory | 46,11% Memory free
- 7,80 Gb Paging File | 5,55 Gb Available in Paging File | 71,18% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
- Drive C: | 78,03 Gb Total Space | 13,62 Gb Free Space | 17,45% Space Free | Partition Type: NTFS
- Drive D: | 387,63 Gb Total Space | 324,96 Gb Free Space | 83,83% Space Free | Partition Type: NTFS
- Computer Name: KORISNIK-PC | User Name: Korisnik | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
- Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2017.01.05 22:44:03 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Korisnik\Desktop\OTL.exe
- PRC - [2017.01.03 12:54:26 | 009,080,768 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
- PRC - [2017.01.03 12:51:43 | 000,197,128 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
- PRC - [2016.12.14 12:54:09 | 000,510,920 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- PRC - [2016.11.17 01:28:54 | 001,269,048 | ---- | M] (Apple, Inc.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe
- PRC - [2016.10.21 19:02:44 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
- PRC - [2012.02.28 03:01:58 | 000,291,608 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
- PRC - [2011.10.11 22:43:16 | 000,109,184 | ---- | M] (Conexant Systems, Inc.) -- C:\Program Files\CONEXANT\SA3\CxUtilSvc.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2017.01.03 12:52:12 | 048,936,448 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
- MOD - [2017.01.03 12:51:49 | 000,482,928 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\ffl2.dll
- MOD - [2017.01.03 12:51:44 | 000,169,064 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
- MOD - [2016.11.17 01:29:02 | 001,041,720 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
- MOD - [2016.09.01 17:13:20 | 000,080,184 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
- [color=#E56717]========== Services (SafeList) ==========[/color]
- SRV:[b]64bit:[/b] - File not found [On_Demand | Stopped] -- C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe -- (AvastVBoxSvc)
- SRV:[b]64bit:[/b] - [2017.01.03 12:51:43 | 000,197,128 | ---- | M] (AVAST Software) [Auto | Stop_Pending] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
- SRV:[b]64bit:[/b] - [2016.10.17 08:52:13 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
- SRV:[b]64bit:[/b] - [2012.03.05 13:08:52 | 000,235,520 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
- SRV:[b]64bit:[/b] - [2012.02.02 02:31:02 | 000,945,440 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
- SRV:[b]64bit:[/b] - [2012.01.29 07:43:50 | 000,048,128 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE -- (wltrysvc)
- SRV:[b]64bit:[/b] - [2011.10.11 22:43:16 | 000,109,184 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Program Files\CONEXANT\SA3\CxUtilSvc.exe -- (CxUtilSvc)
- SRV:[b]64bit:[/b] - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
- SRV:[b]64bit:[/b] - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
- SRV:[b]64bit:[/b] - [2008.03.28 17:55:34 | 000,263,720 | ---- | M] (ActivIdentity) [Auto | Running] -- C:\Program Files\ActivIdentity\ActivClient\accoca.exe -- (accoca)
- SRV - [2016.12.14 12:54:09 | 000,172,488 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
- SRV - [2016.12.14 12:47:17 | 000,270,936 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
- SRV - [2016.10.21 19:02:44 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
- SRV - [2016.09.20 11:54:54 | 000,324,224 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
- SRV - [2012.07.09 00:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
- SRV - [2012.03.20 00:44:18 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
- SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV:[b]64bit:[/b] - File not found [Kernel | Auto | Stopped] -- C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys -- (VBoxAswDrv)
- DRV:[b]64bit:[/b] - [2017.01.03 12:54:07 | 000,293,352 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
- DRV:[b]64bit:[/b] - [2017.01.03 12:54:04 | 000,513,632 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
- DRV:[b]64bit:[/b] - [2017.01.03 12:54:01 | 000,969,184 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
- DRV:[b]64bit:[/b] - [2017.01.03 12:52:27 | 000,163,416 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
- DRV:[b]64bit:[/b] - [2017.01.03 12:52:24 | 000,108,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
- DRV:[b]64bit:[/b] - [2017.01.03 12:52:24 | 000,074,544 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
- DRV:[b]64bit:[/b] - [2017.01.03 12:52:24 | 000,037,656 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
- DRV:[b]64bit:[/b] - [2017.01.03 12:52:22 | 000,103,064 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
- DRV:[b]64bit:[/b] - [2017.01.03 12:51:27 | 000,037,144 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswKbd.sys -- (aswKbd)
- DRV:[b]64bit:[/b] - [2015.11.05 15:23:52 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
- DRV:[b]64bit:[/b] - [2015.09.02 17:49:44 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
- DRV:[b]64bit:[/b] - [2014.04.17 08:19:29 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
- DRV:[b]64bit:[/b] - [2013.08.06 15:13:30 | 000,023,040 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
- DRV:[b]64bit:[/b] - [2012.09.12 15:20:04 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
- DRV:[b]64bit:[/b] - [2012.07.18 02:12:08 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
- DRV:[b]64bit:[/b] - [2012.03.20 00:32:02 | 014,745,600 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdpmd64.sys -- (intelkmd)
- DRV:[b]64bit:[/b] - [2012.03.14 10:42:50 | 000,201,008 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
- DRV:[b]64bit:[/b] - [2012.03.10 04:41:16 | 000,685,160 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
- DRV:[b]64bit:[/b] - [2012.03.05 13:34:48 | 010,729,984 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
- DRV:[b]64bit:[/b] - [2012.03.05 12:05:44 | 000,328,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
- DRV:[b]64bit:[/b] - [2012.02.28 03:01:00 | 000,788,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
- DRV:[b]64bit:[/b] - [2012.02.28 03:01:00 | 000,356,120 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
- DRV:[b]64bit:[/b] - [2012.02.28 03:01:00 | 000,016,152 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
- DRV:[b]64bit:[/b] - [2012.02.02 03:07:18 | 000,615,976 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (btwampfl)
- DRV:[b]64bit:[/b] - [2012.02.02 03:07:18 | 000,134,696 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcbtums.sys -- (bcbtums)
- DRV:[b]64bit:[/b] - [2012.02.02 03:07:12 | 000,211,496 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
- DRV:[b]64bit:[/b] - [2012.02.02 03:07:12 | 000,184,360 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
- DRV:[b]64bit:[/b] - [2012.02.02 03:07:12 | 000,039,976 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
- DRV:[b]64bit:[/b] - [2012.02.02 03:07:12 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
- DRV:[b]64bit:[/b] - [2012.02.01 20:54:56 | 000,031,872 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdkmpfd.sys -- (amdkmpfd)
- DRV:[b]64bit:[/b] - [2012.02.01 17:59:38 | 000,313,448 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUVStor.sys -- (RSUSBVSTOR)
- DRV:[b]64bit:[/b] - [2012.01.29 07:43:50 | 000,022,592 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcm42rly.sys -- (BCM42RLY)
- DRV:[b]64bit:[/b] - [2012.01.22 17:59:50 | 005,439,040 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
- DRV:[b]64bit:[/b] - [2011.12.14 23:20:08 | 001,601,152 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
- DRV:[b]64bit:[/b] - [2011.12.06 12:23:08 | 000,331,264 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
- DRV:[b]64bit:[/b] - [2011.10.22 16:06:06 | 000,021,568 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcmvwl64.sys -- (BcmVWL)
- DRV:[b]64bit:[/b] - [2011.01.20 16:11:09 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
- DRV:[b]64bit:[/b] - [2011.01.20 16:10:54 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
- DRV:[b]64bit:[/b] - [2011.01.20 16:09:36 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
- DRV:[b]64bit:[/b] - [2011.01.20 16:09:36 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
- DRV:[b]64bit:[/b] - [2011.01.20 16:09:36 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
- DRV:[b]64bit:[/b] - [2011.01.20 16:09:36 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
- DRV:[b]64bit:[/b] - [2011.01.20 16:09:34 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
- DRV:[b]64bit:[/b] - [2011.01.20 16:09:34 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
- DRV:[b]64bit:[/b] - [2011.01.20 16:09:34 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
- DRV:[b]64bit:[/b] - [2011.01.20 16:09:32 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
- DRV:[b]64bit:[/b] - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
- DRV:[b]64bit:[/b] - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
- DRV:[b]64bit:[/b] - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
- DRV:[b]64bit:[/b] - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
- DRV:[b]64bit:[/b] - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
- DRV:[b]64bit:[/b] - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
- DRV:[b]64bit:[/b] - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
- DRV:[b]64bit:[/b] - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
- DRV:[b]64bit:[/b] - [2008.06.27 06:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
- DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.hr/
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = hr
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP =
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
- IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
- IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
- IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searcerms}&src=IE-SearchBox&FORM=IESR02
- IE - HKCU\..\SearchScopes\{9B531F9C-C052-4F10-922C-0475518CC5F4}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.countryCode: "HR"
- FF - prefs.js..browser.search.region: "HR"
- FF - prefs.js..browser.startup.homepage: "www.google.hr"
- FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.77
- FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:50.1.0
- FF - user.js - File not found
- FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll File not found
- FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_186.dll ()
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.7: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
- FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
- FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
- FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
- FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
- FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
- FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.4: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
- FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
- 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2017.01.05 21:59:30 | 000,000,000 | ---D | M]
- 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\sp@avast.com: C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\SAFEPRICE\FF [2017.01.05 21:59:30 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2017.01.05 21:59:30 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\sp@avast.com: C:\Program Files\AVAST Software\Avast\SafePrice\FF [2017.01.05 21:59:30 | 000,000,000 | ---D | M]
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ocr@babylon.com: C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\ocr@babylon.com
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 50.1.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 50.1.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 45.5.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 45.5.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
- [2016.11.30 09:06:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Korisnik\AppData\Roaming\Mozilla\Extensions
- [2016.11.30 08:47:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\9zczxlr8.default-1462637685184\extensions
- [2016.05.07 12:34:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\d5yk5qrg.default-1438020423371\extensions
- [2016.10.31 20:30:24 | 000,155,857 | ---- | M] () (No name found) -- C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\9zczxlr8.default-1462637685184\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
- [2016.05.07 12:34:28 | 000,150,384 | ---- | M] () (No name found) -- C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\d5yk5qrg.default-1438020423371\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
- [2016.04.29 23:46:11 | 000,319,627 | ---- | M] () (No name found) -- C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\d5yk5qrg.default-1438020423371\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
- [2016.12.14 12:54:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
- [color=#E56717]========== Chrome ==========[/color]
- CHR - default_search_provider: (Enabled)
- CHR - default_search_provider: search_url =
- CHR - default_search_provider: suggest_url =
- CHR - plugin: Error reading preferences file
- CHR - Extension: No name found = C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
- CHR - Extension: No name found = C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
- CHR - Extension: No name found = C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\
- CHR - Extension: No name found = C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\
- CHR - Extension: No name found = C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.0_0\
- CHR - Extension: No name found = C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5416.905.0.6_0\
- CHR - Extension: No name found = C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\
- O1 HOSTS File: ([2015.03.18 00:52:59 | 000,450,922 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
- O1 - Hosts: 127.0.0.1 activate.adobe.com
- O1 - Hosts: 127.0.0.1 www.007guard.com
- O1 - Hosts: 127.0.0.1 007guard.com
- O1 - Hosts: 127.0.0.1 008i.com
- O1 - Hosts: 127.0.0.1 www.008k.com
- O1 - Hosts: 127.0.0.1 008k.com
- O1 - Hosts: 127.0.0.1 www.00hq.com
- O1 - Hosts: 127.0.0.1 00hq.com
- O1 - Hosts: 127.0.0.1 010402.com
- O1 - Hosts: 127.0.0.1 www.032439.com
- O1 - Hosts: 127.0.0.1 032439.com
- O1 - Hosts: 127.0.0.1 www.0scan.com
- O1 - Hosts: 127.0.0.1 0scan.com
- O1 - Hosts: 127.0.0.1 1000gratisproben.com
- O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
- O1 - Hosts: 127.0.0.1 1001namen.com
- O1 - Hosts: 127.0.0.1 www.1001namen.com
- O1 - Hosts: 127.0.0.1 100888290cs.com
- O1 - Hosts: 127.0.0.1 www.100888290cs.com
- O1 - Hosts: 127.0.0.1 www.100sexlinks.com
- O1 - Hosts: 127.0.0.1 100sexlinks.com
- O1 - Hosts: 127.0.0.1 10sek.com
- O1 - Hosts: 127.0.0.1 www.10sek.com
- O1 - Hosts: 127.0.0.1 www.1-2005-search.com
- O1 - Hosts: 127.0.0.1 1-2005-search.com
- O1 - Hosts: 15474 more lines...
- O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
- O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - No CLSID value found.
- O4:[b]64bit:[/b] - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
- O4:[b]64bit:[/b] - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
- O4:[b]64bit:[/b] - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SA3\SACpl.exe (Conexant Systems, Inc.)
- O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
- O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
- O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
- O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
- O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
- O13[b]64bit:[/b] - gopher Prefix: missing
- O13 - gopher Prefix: missing
- O15 - HKCU\..Trusted Domains: dell.com ([]* in Trusted sites)
- O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab (Reg Error: Key error.)
- O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Reg Error: Key error.)
- O16 - DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab (Reg Error: Key error.)
- O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab (Reg Error: Key error.)
- O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{426E8BAF-5ED9-4EE8-8ED7-0217731FC58C}: DhcpNameServer = 192.168.1.1 192.168.1.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4AE37400-E338-49EC-A7EA-629BA33E45D4}: DhcpNameServer = 172.20.10.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{72513F98-EAF5-43DA-8697-186E8D7582EE}: DhcpNameServer = 91.148.126.2
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CD6F6739-A9F5-41B4-BA9D-61EB3C97DD56}: DhcpNameServer = 172.20.10.1
- O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
- O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
- O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
- O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
- O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O32 - HKLM CDRom: AutoRun - 1
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
- O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
- O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
- O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
- NetSvcs:[b]64bit:[/b] AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
- Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
- Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
- Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
- Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
- CREATERESTOREPOINT
- Restore point Set: OTL Restore Point
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2017.01.05 22:43:59 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Korisnik\Desktop\OTL.exe
- [2017.01.05 21:59:31 | 000,391,496 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
- [2017.01.03 12:51:51 | 000,053,208 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
- [2016.12.26 10:05:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
- [2016.12.26 10:04:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
- [2016.12.09 17:02:36 | 000,000,000 | ---D | C] -- C:\Users\Korisnik\AppData\Local\Opera Software
- [2016.12.09 11:06:01 | 000,000,000 | ---D | C] -- C:\Users\Korisnik\AppData\Local\CEF
- [9 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2017.01.06 07:51:54 | 000,783,792 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
- [2017.01.06 07:51:54 | 000,655,590 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
- [2017.01.06 07:51:54 | 000,121,932 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
- [2017.01.06 07:48:57 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
- [2017.01.06 07:48:56 | 000,000,940 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-403930124-1647038812-4077872958-1000UA.job
- [2017.01.06 07:48:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2017.01.05 22:44:03 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Korisnik\Desktop\OTL.exe
- [2017.01.05 22:18:09 | 000,293,814 | ---- | M] () -- C:\Users\Korisnik\Documents\cc_20170105_221755.reg
- [2017.01.05 22:13:15 | 000,002,070 | ---- | M] () -- C:\Users\Korisnik\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
- [2017.01.05 22:05:19 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- [2017.01.05 22:05:19 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- [2017.01.05 21:56:14 | 3142,864,896 | -HS- | M] () -- C:\hiberfil.sys
- [2017.01.05 12:49:56 | 000,000,918 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-403930124-1647038812-4077872958-1000Core.job
- [2017.01.04 17:50:15 | 000,048,850 | ---- | M] () -- C:\Users\Korisnik\Desktop\struja4.jpg
- [2017.01.04 17:49:50 | 000,056,988 | ---- | M] () -- C:\Users\Korisnik\Desktop\struja3.jpg
- [2017.01.04 17:44:47 | 000,016,409 | ---- | M] () -- C:\Users\Korisnik\Desktop\struja2.jpg
- [2017.01.04 17:44:27 | 000,126,705 | ---- | M] () -- C:\Users\Korisnik\Desktop\struja1.jpg
- [2017.01.03 12:54:07 | 000,293,352 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswVmm.sys
- [2017.01.03 12:54:04 | 000,513,632 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
- [2017.01.03 12:54:01 | 000,969,184 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
- [2017.01.03 12:52:27 | 000,163,416 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
- [2017.01.03 12:52:24 | 000,513,496 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsp.sys.148344444472910
- [2017.01.03 12:52:24 | 000,391,496 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
- [2017.01.03 12:52:24 | 000,292,704 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswvmm.sys.148344444714712
- [2017.01.03 12:52:24 | 000,108,816 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
- [2017.01.03 12:52:24 | 000,074,544 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRvrt.sys
- [2017.01.03 12:52:24 | 000,037,656 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswHwid.sys
- [2017.01.03 12:52:22 | 000,103,064 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
- [2017.01.03 12:51:51 | 000,053,208 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
- [2017.01.03 12:51:28 | 000,969,560 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsnx.sys.148344444165607
- [2017.01.03 12:51:27 | 000,037,144 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswKbd.sys
- [2017.01.03 12:42:23 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player PPAPI Notifier.job
- [2016.12.28 17:17:50 | 001,263,033 | ---- | M] () -- C:\Users\Korisnik\Desktop\braco i seka.JPG
- [2016.12.22 08:08:41 | 000,054,944 | ---- | M] () -- C:\Users\Korisnik\Desktop\ss.jpg
- [2016.12.11 09:51:22 | 000,160,937 | ---- | M] () -- C:\Users\Korisnik\Desktop\nba.png
- [9 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2017.01.05 22:18:00 | 000,293,814 | ---- | C] () -- C:\Users\Korisnik\Documents\cc_20170105_221755.reg
- [2017.01.04 17:50:15 | 000,048,850 | ---- | C] () -- C:\Users\Korisnik\Desktop\struja4.jpg
- [2017.01.04 17:49:50 | 000,056,988 | ---- | C] () -- C:\Users\Korisnik\Desktop\struja3.jpg
- [2017.01.04 17:44:47 | 000,016,409 | ---- | C] () -- C:\Users\Korisnik\Desktop\struja2.jpg
- [2017.01.04 17:44:27 | 000,126,705 | ---- | C] () -- C:\Users\Korisnik\Desktop\struja1.jpg
- [2016.12.28 17:22:43 | 001,263,033 | ---- | C] () -- C:\Users\Korisnik\Desktop\braco i seka.JPG
- [2016.12.22 08:08:40 | 000,054,944 | ---- | C] () -- C:\Users\Korisnik\Desktop\ss.jpg
- [2016.12.11 09:51:21 | 000,160,937 | ---- | C] () -- C:\Users\Korisnik\Desktop\nba.png
- [2016.02.21 00:09:30 | 000,000,017 | ---- | C] () -- C:\Users\Korisnik\AppData\Local\resmon.resmoncfg
- [2015.09.28 08:25:18 | 000,007,168 | ---- | C] () -- C:\Users\Korisnik\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
- [2015.04.17 13:44:54 | 000,000,085 | ---- | C] () -- C:\Windows\wininit.ini
- [color=#E56717]========== ZeroAccess Check ==========[/color]
- [2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
- [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- "" = C:\Windows\SysNative\shell32.dll -- [2011.01.20 16:09:47 | 014,174,208 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- "" = %SystemRoot%\system32\shell32.dll -- [2011.01.20 16:10:01 | 012,872,192 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
- "" = %systemroot%\system32\wbem\fastprox.dll -- [2011.01.20 16:10:38 | 000,606,208 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Both
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
- [color=#E56717]========== LOP Check ==========[/color]
- [2015.06.02 18:37:05 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\.ACEStream
- [2014.01.22 02:29:50 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\.Torrent Stream
- [2013.10.25 13:41:42 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\AVAST Software
- [2012.11.02 17:42:16 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\BSplayer Pro
- [2016.04.07 11:56:18 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\DAEMON Tools Lite
- [2014.05.17 18:28:55 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\Dropbox
- [2015.07.27 16:38:32 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\IrfanView
- [2014.04.17 08:27:26 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\Leadertech
- [2013.03.04 10:49:55 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\libimobiledevice
- [2016.04.28 13:21:11 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\Opera Software
- [2015.08.13 17:58:43 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\PCDr
- [2012.11.02 17:46:37 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\Softland
- [2013.03.05 20:21:32 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\Thunderbird
- [2017.01.04 17:45:19 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\ViberPC
- [2017.01.05 21:47:39 | 000,000,000 | ---D | M] -- C:\Users\Korisnik\AppData\Roaming\WhatsApp
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Custom Scans ==========[/color]
- [color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
- [2015.06.03 09:30:56 | 000,000,717 | ---- | M] () -- C:\DelFix.txt
- [2017.01.05 21:56:14 | 3142,864,896 | -HS- | M] () -- C:\hiberfil.sys
- [2017.01.05 21:56:17 | 4190,486,528 | -HS- | M] () -- C:\pagefile.sys
- [color=#A23BEC]< %systemroot%\Fonts\*.com >[/color]
- [2009.07.14 06:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
- [2009.07.14 06:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
- [2009.07.14 06:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
- [2009.07.14 06:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
- [color=#A23BEC]< %systemroot%\Fonts\*.dll >[/color]
- [color=#A23BEC]< %systemroot%\Fonts\*.ini >[/color]
- [2009.06.10 21:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
- [color=#A23BEC]< %systemroot%\Fonts\*.ini2 >[/color]
- [color=#A23BEC]< %systemroot%\Fonts\*.exe >[/color]
- [color=#A23BEC]< %systemroot%\system32\spool\prtprocs\w32x86\*.* >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.bak1 >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.ini >[/color]
- [color=#A23BEC]< %systemroot%\system32\*.jpg >[/color]
- [color=#A23BEC]< %systemroot%\*.jpg >[/color]
- [color=#A23BEC]< %systemroot%\*.png >[/color]
- [color=#A23BEC]< %systemroot%\*.scr >[/color]
- [2017.01.03 12:51:51 | 000,053,208 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
- [2012.09.12 15:57:44 | 000,322,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
- [color=#A23BEC]< %systemroot%\*._sy >[/color]
- [color=#A23BEC]< %APPDATA%\Adobe\Update\*.* >[/color]
- [color=#A23BEC]< %ALLUSERSPROFILE%\Favorites\*.* >[/color]
- [color=#A23BEC]< %APPDATA%\Microsoft\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
- [2009.07.14 05:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
- [color=#A23BEC]< %APPDATA%\Update\*.* >[/color]
- [color=#A23BEC]< %systemroot%\*. /mp /s >[/color]
- [color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\bak. /s >[/color]
- [color=#A23BEC]< %systemroot%\system32\bak. /s >[/color]
- [color=#A23BEC]< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >[/color]
- [color=#A23BEC]< %systemroot%\system32\config\systemprofile\*.dat /x >[/color]
- [color=#A23BEC]< %systemroot%\*.config >[/color]
- [color=#A23BEC]< %systemroot%\system32\*.db >[/color]
- [color=#A23BEC]< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >[/color]
- [2012.11.02 17:43:26 | 000,000,221 | -HS- | M] () -- C:\Users\Korisnik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
- [color=#A23BEC]< %USERPROFILE%\Desktop\*.exe >[/color]
- [2017.01.05 22:44:03 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Korisnik\Desktop\OTL.exe
- [color=#A23BEC]< %PROGRAMFILES%\Common Files\*.* >[/color]
- [color=#A23BEC]< %systemroot%\*.src >[/color]
- [color=#A23BEC]< %systemroot%\install\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\DLL\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\HelpFiles\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\rundll\*.* >[/color]
- [color=#A23BEC]< %systemroot%\winn32\*.* >[/color]
- [color=#A23BEC]< %systemroot%\Java\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\test\*.* >[/color]
- [color=#A23BEC]< %systemroot%\system32\Rundll32\*.* >[/color]
- [color=#A23BEC]< %systemroot%\AppPatch\Custom\*.* >[/color]
- [color=#A23BEC]< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.tmp >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Internet Explorer\*.dat >[/color]
- [color=#A23BEC]< %USERPROFILE%\My Documents\*.exe >[/color]
- [color=#A23BEC]< %USERPROFILE%\*.exe >[/color]
- [color=#A23BEC]< %systemroot%\ADDINS\*.* >[/color]
- [2009.06.10 22:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf
- [color=#A23BEC]< %systemroot%\assembly\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Config\*.* >[/color]
- [color=#A23BEC]< %systemroot%\REPAIR\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\SECURITY\Database\*.sdb /x >[/color]
- [2012.11.02 18:01:12 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
- [2012.11.02 18:01:12 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
- [2012.11.02 18:01:12 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
- [2012.11.02 18:01:12 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
- [2012.11.02 18:01:11 | 000,786,432 | ---- | M] () -- C:\Windows\SECURITY\Database\edbtmp.log
- [2012.11.02 18:01:12 | 001,056,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SECURITY\Database\tmp.edb
- [color=#A23BEC]< %systemroot%\SYSTEM\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Web\*.bak2 >[/color]
- [color=#A23BEC]< %systemroot%\Driver Cache\*.* >[/color]
- [color=#A23BEC]< %PROGRAMFILES%\Mozilla Firefox\0*.exe >[/color]
- [color=#A23BEC]< %ProgramFiles%\Microsoft Common\*.* >[/color]
- [color=#A23BEC]< %ProgramFiles%\TinyProxy. >[/color]
- [color=#A23BEC]< %USERPROFILE%\Favorites\*.url /x >[/color]
- [2012.11.02 17:17:37 | 000,000,402 | -HS- | M] () -- C:\Users\Korisnik\Favorites\desktop.ini
- [color=#A23BEC]< %systemroot%\System32\Wbem\*.exe >[/color]
- [2009.07.14 02:14:24 | 000,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\mofcomp.exe
- [2009.07.14 02:14:45 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WinMgmt.exe
- [2009.07.14 02:14:46 | 000,115,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIADAP.exe
- [2009.07.14 02:14:46 | 000,395,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WMIC.exe
- [2011.01.20 16:10:41 | 000,257,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wbem\WmiPrvSE.exe
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >[/color]
- [color=#A23BEC]< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >[/color]
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement