Jump to content

Препоръчан пост

Таке е по-добре. Дневникът е чист.

 

Стартирай отново OTL и кликни бутон CleanUp. Това ще премахне инструмента и принадлежащите му фалове и папки.

 

Бих ти препоръчал да актуализираш Malwarebytes' Anti-Malware и да пуснеш едно бързо сканиране. Профилактично.

 

След това ще е време да си инсталираш някаква надеждна антивирусна, че така голичък да стоиш не е добра идея.

Link to comment
Сподели другаде

  • 5 months later...
  • Отговори 112
  • Създадена
  • Последен отговор

ТОП потребители в тази тема

ТОП потребители в тази тема

Публикувани изображения

Стартирай отново OTL. В празното поле "Custom Scans/Fixes" (в долната част на програмата) постави следния текст (маркирай го, натисни Ctrl+C и после в полето на OTL натисни Ctrl+V):

 

:Processes
killallprocesses
:OTL
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [tray_ico] File not found
O4 - HKLM..\Run: [tray_ico1] File not found
O4 - HKLM..\Run: [tray_ico2] File not found
O4 - HKLM..\Run: [tray_ico3] File not found
O4 - HKLM..\Run: [tray_ico4] File not found
O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm File not found
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm File not found
O32 - AutoRun File - [2011.03.25 20:03:11 | 000,000,000 | ---D | M] - D:\AutoRun -- [ NTFS ]
O33 - MountPoints2\{172c883a-b438-11de-972e-00030d83037b}\Shell\AutoRun\command - "" = 8dtyjjf.exe
O33 - MountPoints2\{172c883a-b438-11de-972e-00030d83037b}\Shell\open\Command - "" = 8dtyjjf.exe
[2011.07.25 21:01:34 | 000,246,272 | ---- | C] () -- C:\WINDOWS\unrar.exe
[2011.07.25 20:43:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\loader2.exe_ok
[2010.07.28 14:56:52 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
:Files
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp
:Commands
[resethosts]
[emptytemp]
[reboot]

Копирай текста точно както е в полето. Внимавай да не изтървеш началното двуеточие и всяка команда да е на отделен ред, както е в полето.

 

Кликни бутон Run Fix. Потвърди с OK на съобщението, че е нужен рестарт на системата.

Link to comment
Сподели другаде

  • 4 weeks later...

И аз съм със същият проблем с фейсбука. От 3 дни се мъча да го отстряня, но нищо не става...Изчетох няколко пъти всичко от тук, изтеглих си и сканиращите програмки, поизчистих си машинката от гадости, изпълних и гореописаните стъпки. С XP съм. Ще съм страшно благодарна, ако помогнете и на мен. Поразгледах кодовете, но не мога да се отиентирам какво точно се прави и защо... Ето какво ми е съдържанието на файла extras.txt:

OTL Extras logfile created on: 12.5.2012 г. 18:35:56 - Run 1

OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Mitko\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'

 

1,99 Gb Total Physical Memory | 1,23 Gb Available Physical Memory | 61,94% Memory free

3,84 Gb Paging File | 3,12 Gb Available in Paging File | 81,38% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 68,36 Gb Total Space | 20,82 Gb Free Space | 30,46% Space Free | Partition Type: NTFS

Drive D: | 43,43 Gb Total Space | 14,42 Gb Free Space | 33,21% Space Free | Partition Type: NTFS

 

Computer Name: MAGI | User Name: Mitko | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)

 

[HKEY_USERS\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Classes\<extension>]

.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

htmlfile [edit] -- Reg Error: Key error.

http [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)

https [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 1

"UpdatesDisableNotify" = 1

"AntiVirusOverride" = 0

"FirewallOverride" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

========== System Restore Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DoNotAllowExceptions" = 0

"DisableNotifications" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

"2706:TCP" = 2706:TCP:*:Enabled:Inhatch P2P Streaming

"2707:TCP" = 2707:TCP:*:Enabled:Inhatch P2P Streaming

"2708:TCP" = 2708:TCP:*:Enabled:Inhatch P2P Streaming

"2709:TCP" = 2709:TCP:*:Enabled:Inhatch P2P Streaming

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)

"C:\Documents and Settings\Mitko\My Documents\Downloads\ComNet_TV.exe" = C:\Documents and Settings\Mitko\My Documents\Downloads\COMNET_TV.EXE:*:Enabled:COMNET_TV.EXE

"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox

"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer

"C:\Documents and Settings\Mitko\Local Settings\Temp\Torrent2Exe\T2E.exe" = C:\Documents and Settings\Mitko\Local Settings\Temp\Torrent2Exe\T2E.exe:*:Enabled:Torrent2Exe -- (http://www.torrent2exe.com)

"C:\Documents and Settings\Mitko\My Documents\Downloads\SweetImSetup.exe" = C:\Documents and Settings\Mitko\My Documents\Downloads\SweetImSetup.exe:*:Enabled:SweetIM Installer

"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)

"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console -- (Microsoft Corporation)

"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Computer, Inc.)

"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath -- (Skype Technologies S.A.)

"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software)

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00640E90-FF0B-4561-AD85-F5EC43E27B75}" = Fun&Learning - Memory&Logic

"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3

"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting

"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic UDF Reader

"{17079027-EB8A-42C6-9BF8-825B78889F6A}" = Garmin Communicator Plugin

"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86

"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{3BC1AB78-2D98-4906-84B5-4230B5420DCC}" = Offline Course Player

"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3

"{411949AB-6EE8-4C62-9C72-EBC93B6A7935}" = AVG 2012

"{50842BAB-FD22-4B64-BE6D-4DC632EFBF39}" = Fun&Learning - Creativity

"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings

"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3

"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers

"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All

"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3

"{73284F36-E17E-44B0-85E2-F0336A6E749F}" = PC Connectivity Solution

"{74C5EA04-AF1E-45B2-949B-4841EE949C40}" = Nokia Connectivity Cable Driver

"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3

"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support

"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12

"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007

"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007

"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007

"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007

"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007

"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007

"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007

"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007

"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007

"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007

"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3

"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings

"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3

"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps

"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific

"{A7836FF5-7293-40A4-B86E-E2038F82E8F3}" = AVG 2012

"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings

"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver

"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0

"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call

"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3

"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2

"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware

"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client

"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files

"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility

"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings

"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings

"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3

"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = USB PC Camera Plus

"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{FCD8DCE6-94C8-4FF6-8E3E-D3C96A5A707E}" = Nokia PC Suite

"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup

"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)

"6A630DCEC5EEC912115F2FF59D8C2C769798D930" = Windows Driver Package - Nokia Modem (10/12/2007 3.6)

"819D45A9F73817F5B6D7C71A33ADAB88C5DA1765" = Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2)

"9925DD2E3ADF2DA7C8A0212FB775F1D2FB6C56E8" = Windows Driver Package - Nokia (WUDFRd) WPD (11/05/2007 6.85.35.3)

"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin

"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3

"Ask Toolbar_is1" = Ask Toolbar

"AVG" = AVG 2012

"CDex" = CDex extraction audio

"EVEREST Home Edition_is1" = EVEREST Home Edition v1.10

"F1CB0AC2D40DDCFCA6933082B115073476C155DE" = Windows Driver Package - Nokia Modem (08/03/2007 3.2)

"FlexType 2K" = FlexType 2K

"Foxit Reader" = Foxit Reader

"HDMI" = Intel® Graphics Media Accelerator Driver

"ie8" = Windows Internet Explorer 8

"Inhatch web plugins" = Inhatch web plugins

"IrfanView" = IrfanView (remove only)

"KLiteCodecPack_is1" = K-Lite Codec Pack 4.5.3 (Full)

"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware, версия 1.61.0.1400

"Nero - Burning Rom!UninstallKey" = Ahead Nero 6 Demo

"Nokia PC Suite" = Nokia PC Suite

"Opera 11.64.1403" = Opera 11.64

"PROPLUS" = Microsoft Office Professional Plus 2007

"Replay Media Catcher" = Replay Media Catcher

"SA Dictionary 2002 Professional" = SA Dictionary 2002 Professional

"TOSHIBA Software Modem" = TOSHIBA Software Modem

"Unlocker" = Unlocker 1.8.7

"uTorrent" = µTorrent

"VLC media player" = VLC media player 1.1.7

"Winamp" = Winamp

"WinRAR archiver" = WinRAR archiver

 

========== HKEY_USERS Uninstall List ==========

 

[HKEY_USERS\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Google Chrome" = Google Chrome

"uTorrent" = µTorrent

 

========== Last 10 Event Log Errors ==========

 

[ Application Events ]

Error - 02.5.2011 г. 01:00:45 | Computer Name = MAGI | Source = Application Error | ID = 1000

Description = Faulting application firefox.exe, version 1.9.2.4127, faulting module

msvcr90.dll, version 9.0.30729.4148, fault address 0x00059231.

 

Error - 03.5.2011 г. 00:55:58 | Computer Name = MAGI | Source = Application Error | ID = 1000

Description = Faulting application firefox.exe, version 1.9.2.4127, faulting module

msvcr90.dll, version 9.0.30729.4148, fault address 0x00059231.

 

Error - 03.5.2011 г. 00:56:18 | Computer Name = MAGI | Source = Application Error | ID = 1000

Description = Faulting application firefox.exe, version 1.9.2.4127, faulting module

msvcr90.dll, version 9.0.30729.4148, fault address 0x00059231.

 

Error - 03.5.2011 г. 00:56:22 | Computer Name = MAGI | Source = Application Error | ID = 1001

Description = Fault bucket -1882036877.

 

Error - 09.5.2011 г. 01:17:44 | Computer Name = MAGI | Source = Application Error | ID = 1000

Description = Faulting application firefox.exe, version 1.9.2.4127, faulting module

msvcr90.dll, version 9.0.30729.4148, fault address 0x00059231.

 

Error - 12.5.2011 г. 16:14:15 | Computer Name = MAGI | Source = crypt32 | ID = 131083

Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>

with error: A required certificate is not within its validity period when verifying

against the current system clock or the timestamp in the signed file.

 

Error - 12.5.2011 г. 16:14:15 | Computer Name = MAGI | Source = crypt32 | ID = 131083

Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>

with error: A required certificate is not within its validity period when verifying

against the current system clock or the timestamp in the signed file.

 

Error - 15.5.2011 г. 00:48:09 | Computer Name = MAGI | Source = Application Error | ID = 1000

Description = Faulting application firefox.exe, version 1.9.2.4127, faulting module

msvcr90.dll, version 9.0.30729.4148, fault address 0x00059231.

 

Error - 30.5.2011 г. 08:41:44 | Computer Name = MAGI | Source = Application Hang | ID = 1002

Description = Hanging application mplayerc.exe, version 1.2.972.0, hang module hungapp,

version 0.0.0.0, hang address 0x00000000.

 

Error - 01.6.2011 г. 12:49:00 | Computer Name = MAGI | Source = Application Error | ID = 1000

Description = Faulting application firefox.exe, version 1.9.2.4127, faulting module

msvcr90.dll, version 9.0.30729.4148, fault address 0x00059231.

 

[ System Events ]

Error - 11.5.2012 г. 19:57:17 | Computer Name = MAGI | Source = SideBySide | ID = 16842784

Description = Dependent Assembly Microsoft.VC90.CRT could not be found and Last

Error was The referenced assembly is not installed on your system.

 

Error - 11.5.2012 г. 19:57:17 | Computer Name = MAGI | Source = SideBySide | ID = 16842811

Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error

message: The referenced assembly is not installed on your system. .

 

Error - 11.5.2012 г. 19:57:17 | Computer Name = MAGI | Source = SideBySide | ID = 16842811

Description = Generate Activation Context failed for C:\Program Files\AVG\AVG2012\avgcfgx.dll.

Reference

error message: The operation completed successfully. .

 

Error - 11.5.2012 г. 19:57:42 | Computer Name = MAGI | Source = SideBySide | ID = 16842784

Description = Dependent Assembly Microsoft.VC90.CRT could not be found and Last

Error was The referenced assembly is not installed on your system.

 

Error - 11.5.2012 г. 19:57:42 | Computer Name = MAGI | Source = SideBySide | ID = 16842811

Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error

message: The referenced assembly is not installed on your system. .

 

Error - 11.5.2012 г. 19:57:42 | Computer Name = MAGI | Source = SideBySide | ID = 16842811

Description = Generate Activation Context failed for C:\Program Files\AVG\AVG2012\avgcfgx.dll.

Reference

error message: The operation completed successfully. .

 

Error - 11.5.2012 г. 21:01:20 | Computer Name = MAGI | Source = System Error | ID = 1003

Description = Error code 10000050, parameter1 e144401c, parameter2 00000000, parameter3

bf83291e, parameter4 00000001.

 

Error - 11.5.2012 г. 21:01:38 | Computer Name = MAGI | Source = System Error | ID = 1003

Description = Error code 1000008e, parameter1 c0000005, parameter2 bf951755, parameter3

9ba9bc00, parameter4 00000000.

 

Error - 11.5.2012 г. 21:01:40 | Computer Name = MAGI | Source = System Error | ID = 1003

Description = Error code 1000008e, parameter1 c0000005, parameter2 bf951755, parameter3

95c53c00, parameter4 00000000.

 

Error - 12.5.2012 г. 12:41:36 | Computer Name = MAGI | Source = Dhcp | ID = 1000

Description = Your computer has lost the lease to its IP address 85.11.187.219 on

the Network Card with network address 001D60F34F30.

 

 

< End of report >

 

ето и съдържанието на otl.txt:

OTL logfile created on: 12.5.2012 г. 18:35:56 - Run 1

OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Mitko\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'

 

1,99 Gb Total Physical Memory | 1,23 Gb Available Physical Memory | 61,94% Memory free

3,84 Gb Paging File | 3,12 Gb Available in Paging File | 81,38% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 68,36 Gb Total Space | 20,82 Gb Free Space | 30,46% Space Free | Partition Type: NTFS

Drive D: | 43,43 Gb Total Space | 14,42 Gb Free Space | 33,21% Space Free | Partition Type: NTFS

 

Computer Name: MAGI | User Name: Mitko | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2012.05.12 18:20:32 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mitko\Desktop\OTL.exe

PRC - [2012.05.12 17:49:20 | 000,949,104 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe

PRC - [2012.05.11 17:00:26 | 001,116,544 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe

PRC - [2012.05.04 13:37:37 | 000,932,736 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe

PRC - [2012.05.01 09:48:04 | 003,905,920 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

PRC - [2012.04.30 09:44:38 | 005,106,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgidsagent.exe

PRC - [2012.04.19 04:51:54 | 001,254,992 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe

PRC - [2012.04.05 05:12:34 | 002,587,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe

PRC - [2012.03.19 05:18:12 | 000,979,840 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe

PRC - [2012.02.14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe

PRC - [2012.02.14 04:53:14 | 000,758,112 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe

PRC - [2012.02.14 04:52:38 | 000,338,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe

PRC - [2011.08.11 16:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe

PRC - [2011.06.03 05:00:08 | 000,042,872 | ---- | M] () -- C:\Program Files\Offline Course Player\OlpSynch.exe

PRC - [2009.03.10 18:28:36 | 000,262,144 | ---- | M] (SONIX) -- C:\WINDOWS snpstd3.exe

PRC - [2007.11.22 12:49:08 | 000,385,024 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe

PRC - [2007.11.09 13:16:24 | 000,688,128 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe

PRC - [2007.11.06 09:36:34 | 000,352,768 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

PRC - [2007.11.06 06:38:46 | 000,009,216 | R--- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe

PRC - [2007.10.26 08:55:58 | 000,122,880 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe

PRC - [2007.10.23 10:03:00 | 000,117,248 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe

PRC - [2007.10.09 22:28:32 | 000,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe

PRC - [2006.09.18 14:12:12 | 000,843,776 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe

PRC - [2006.06.13 06:20:00 | 000,127,036 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLACTRLW.EXE

PRC - [2004.08.03 14:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2000.11.07 18:05:40 | 000,145,920 | ---- | M] () -- C:\WINDOWS\Datecs\Flex2K.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2012.05.12 18:31:29 | 000,052,736 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll

MOD - [2012.05.12 18:31:28 | 000,065,024 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll

MOD - [2012.05.12 18:05:34 | 000,117,760 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

MOD - [2012.05.12 18:05:34 | 000,052,224 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll

MOD - [2012.05.12 17:49:25 | 000,783,360 | ---- | M] () -- C:\Program Files\Opera\gstreamer\gstreamer.dll

MOD - [2012.05.12 17:49:25 | 000,316,928 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstoggdec.dll

MOD - [2012.05.12 17:49:25 | 000,276,480 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwebmdec.dll

MOD - [2012.05.12 17:49:25 | 000,168,448 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstffmpegcolorspace.dll

MOD - [2012.05.12 17:49:25 | 000,099,840 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstcoreplugins.dll

MOD - [2012.05.12 17:49:25 | 000,098,816 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioresample.dll

MOD - [2012.05.12 17:49:25 | 000,098,816 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioconvert.dll

MOD - [2012.05.12 17:49:25 | 000,078,336 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwavparse.dll

MOD - [2012.05.12 17:49:25 | 000,076,800 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdirectsound.dll

MOD - [2012.05.12 17:49:25 | 000,068,608 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdecodebin2.dll

MOD - [2012.05.12 17:49:25 | 000,064,000 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstautodetect.dll

MOD - [2012.05.12 17:49:25 | 000,046,592 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwaveform.dll

MOD - [2012.05.12 17:49:25 | 000,045,568 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gsttypefindfunctions.dll

MOD - [2012.05.11 17:00:26 | 001,116,544 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe

MOD - [2012.05.04 13:37:37 | 000,932,736 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe

MOD - [2012.05.04 13:37:37 | 000,130,944 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\SiteSafety.dll

MOD - [2011.06.03 05:00:08 | 000,042,872 | ---- | M] () -- C:\Program Files\Offline Course Player\OlpSynch.exe

MOD - [2007.11.09 13:16:24 | 000,688,128 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe

MOD - [2007.10.26 08:55:58 | 000,122,880 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe

MOD - [2007.10.23 10:03:00 | 000,117,248 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe

MOD - [2007.10.09 22:28:32 | 000,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe

MOD - [2007.08.27 12:35:54 | 001,581,056 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\QtCore4.dll

MOD - [2007.08.02 17:16:58 | 000,131,072 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\Imageformats\qjpeg4.dll

MOD - [2007.08.02 17:05:42 | 006,402,048 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\QtGui4.dll

MOD - [2007.08.02 16:51:54 | 000,356,352 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\QtXml4.dll

MOD - [2006.09.18 14:12:12 | 000,843,776 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe

MOD - [2000.11.07 18:05:40 | 000,145,920 | ---- | M] () -- C:\WINDOWS\Datecs\Flex2K.exe

MOD - [2000.10.19 00:03:34 | 000,028,672 | ---- | M] () -- C:\WINDOWS\system32\newdll.dll

 

 

========== Win32 Services (SafeList) ==========

 

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)

SRV - [2012.05.11 16:59:42 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2012.05.04 13:37:37 | 000,932,736 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe -- (vToolbarUpdater11.0.2)

SRV - [2012.04.30 09:44:38 | 005,106,744 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgidsagent.exe -- (AVGIDSAgent)

SRV - [2012.02.29 08:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)

SRV - [2012.02.14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)

SRV - [2012.02.01 08:51:01 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)

SRV - [2011.08.11 16:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore.exe -- (!SASCORE)

SRV - [2007.11.06 09:36:34 | 000,352,768 | ---- | M] (Nokia.) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)

SRV - [2007.11.06 06:38:46 | 000,009,216 | R--- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio)

 

 

========== Driver Services (SafeList) ==========

 

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)

DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)

DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)

DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)

DRV - File not found [Kernel | System | Stopped] -- -- (Changer)

DRV - [2012.04.19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\avgidshx.sys -- (AVGIDSHX)

DRV - [2012.03.19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)

DRV - [2012.02.22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)

DRV - [2012.01.31 04:46:50 | 000,031,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avgrkx86.sys -- (Avgrkx86)

DRV - [2011.12.23 13:32:14 | 000,041,040 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)

DRV - [2011.12.23 13:32:08 | 000,017,232 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsshimx.sys -- (AVGIDSShim)

DRV - [2011.12.23 13:32:06 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsfilterx.sys -- (AVGIDSFilter)

DRV - [2011.12.23 13:32:00 | 000,139,856 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)

DRV - [2011.07.22 09:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)

DRV - [2011.07.12 14:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)

DRV - [2009.03.25 15:29:52 | 000,130,432 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)

DRV - [2008.05.01 21:15:44 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)

DRV - [2007.11.28 01:02:43 | 000,007,680 | ---- | M] (ATK0100) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor)

DRV - [2007.11.19 19:06:16 | 010,246,400 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)

DRV - [2007.11.06 06:41:42 | 000,264,576 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8187B.sys -- (RTL8187B)

DRV - [2007.11.06 06:40:12 | 004,608,000 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)

DRV - [2007.11.06 06:38:44 | 001,161,888 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)

DRV - [2007.02.22 10:15:56 | 000,137,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcd.sys -- (nmwcd)

DRV - [2007.02.22 10:15:14 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcm.sys -- (nmwcdcm)

DRV - [2007.02.22 10:15:14 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcj.sys -- (nmwcdcj)

DRV - [2007.02.22 10:15:14 | 000,008,320 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdc.sys -- (nmwcdc)

DRV - [2006.06.13 06:20:00 | 000,094,460 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)

DRV - [2006.06.13 06:20:00 | 000,088,476 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)

DRV - [2006.06.13 06:20:00 | 000,086,844 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)

DRV - [2006.06.13 06:20:00 | 000,025,724 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)

DRV - [2006.06.13 06:20:00 | 000,014,716 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)

DRV - [2006.06.13 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)

DRV - [2006.06.13 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)

DRV - [2006.03.17 09:35:24 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)

DRV - [2006.03.17 09:34:46 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)

DRV - [2004.08.03 15:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)

DRV - [2004.08.03 13:07:46 | 000,223,616 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers cpip6.sys -- (Tcpip6)

 

 

========== Standard Registry (All) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.c...99&gct=&gc=1&q=

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}

IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search...p={searchTerms}

 

 

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.bg/

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll ()

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRC

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.c...fr&d=2012-05-11 17:00:27&v=11.0.0.9&sap=dsp&q={searchTerms}

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.c...m=1&toolbar=FXT

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

 

========== FireFox ==========

 

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"

FF - prefs.js..browser.search.defaulturl: ""

FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"

FF - prefs.js..browser.startup.homepage: "www.google.bg"

FF - prefs.js..extensions.enabledItems: avg@igeared:7.005.030.004

FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1374

FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:2.0

FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7B0a39fc7f-d42b-4ff0-82a9-4c8b3e737d36%7D&mid=f1b63638aed18a771891905ba4517535-b60b068c4d1eaa979e5403bc9cfd8062c9d87e23&ds=AVG&v=11.0.0.9&lang=en&pr=fr&d=2012-05-11%2017%3A00%3A27&sap=ku&q="

FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "AVG Secure Search"

FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""

FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "AVG Secure Search"

FF - prefs.js..browser.startup.homepage: "www.google.bg"

FF - user.js - File not found

 

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()

FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll ()

FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)

FF - HKLM\Software\MozillaPlugins\@inhatch.com,version=0.7.2: C:\Program Files\InhatchTeam\Inhatch\npinhatch.dll File not found

FF - HKLM\Software\MozillaPlugins\@inhatch.com,version=0.7.5: C:\Program Files\InhatchTeam\Inhatch\npinhatch.dll File not found

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012.05.11 17:00:35 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\11.0.0.9\ [2012.05.04 13:37:41 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012.05.11 16:59:59 | 000,000,000 | ---D | M]

 

[2010.04.21 03:22:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Extensions

[2010.04.21 03:22:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2010.04.16 09:58:10 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\extensions

[2010.04.16 09:58:10 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}

[2012.05.11 12:21:30 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\extensions

[2010.04.16 23:04:29 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2011.09.14 19:53:41 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}

[2011.09.14 17:41:09 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\searchplugins\sweetim.xml

[2012.05.12 17:48:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2012.04.01 19:51:42 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

[2011.06.23 21:37:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions

[2011.06.23 21:37:35 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2012.05.04 13:37:41 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AVG SECURE SEARCH\11.0.0.9

[2010.04.25 04:16:34 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll

[2006.10.26 21:12:16 | 000,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL

[2011.06.03 05:00:08 | 000,061,440 | ---- | M] (Element K Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOlp32.dll

[2004.11.03 19:43:00 | 000,000,680 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.png

[2012.05.11 17:00:25 | 000,003,766 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml

[2004.11.03 19:43:00 | 000,000,356 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.png

[2004.11.03 19:43:00 | 000,000,557 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\dictionary.png

[2004.11.03 19:43:00 | 000,000,210 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.gif

[2004.11.03 19:43:00 | 000,001,076 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.gif

[2004.11.03 19:43:00 | 000,000,088 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.gif

 

========== Chrome ==========

 

CHR - default_search_provider: AVG Secure Search (Enabled)

CHR - default_search_provider: search_url = http://isearch.avg.c...fr&d=2012-05-11 17:00:27&v=11.0.0.9&sap=dsp&q={searchTerms}

CHR - default_search_provider: suggest_url = http://clients5.goog...outputEncoding}

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\pdf.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\gcswf32.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll

CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\plugins/avgnpss.dll

CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll

CHR - plugin: Java Deployment Toolkit 6.0.180.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll

CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL

CHR - plugin: Offline Course Player Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOlp32.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll

CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll

CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll

CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll

CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll

CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll

CHR - Extension: YouTube = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\

CHR - Extension: Google \u0422\u044A\u0440\u0441\u0435\u043D\u0435 = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\

CHR - Extension: AVG Safe Search = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\

CHR - Extension: Skype Click to Call = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\

CHR - Extension: AVG Do Not Track = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\

CHR - Extension: Gmail = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

 

O1 HOSTS File: ([2001.08.23 04:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)

O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)

O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)

O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)

O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll ()

O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found

O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)

O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll ()

O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.

O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)

O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)

O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)

O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)

O4 - HKLM..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)

O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)

O4 - HKLM..\Run: [OLPSYNCH] C:\Program Files\Offline Course Player\OlpSynch.exe ()

O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)

O4 - HKLM..\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 File not found

O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [skyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()

O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS snpstd3.exe (SONIX)

O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()

O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()

O4 - HKU\.DEFAULT..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)

O4 - HKU\S-1-5-18..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)

O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [Google Update] C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)

O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe ()

O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)

O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\WINDOWS\Datecs\Flex2K.exe ()

O4 - Startup: C:\Documents and Settings\Mitko\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)

O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 85.11.187.1 85.11.160.15

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6126DBBF-0FEC-4DE0-AFF0-D72FBE92E8B2}: DhcpNameServer = 85.11.187.1 85.11.160.15

O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)

O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)

O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler v {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.0.2\ViProtocol.dll ()

O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)

O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter ext/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O18 - Protocol\Filter ext/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)

O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)

O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)

O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)

O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify ermsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O24 - Desktop Components:0 (My Current Home Page) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\Mitko\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mitko\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)

O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)

O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2010.04.16 06:53:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *)

O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

 

NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found

NetSvcs: Ias - File not found

NetSvcs: Iprip - File not found

NetSvcs: Irmon - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found

 

NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found

NetSvcs: Ias - File not found

NetSvcs: Iprip - File not found

NetSvcs: Irmon - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found

 

 

SafeBootMin: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)

SafeBootMin: Base - Driver Group

SafeBootMin: Boot Bus Extender - Driver Group

SafeBootMin: Boot file system - Driver Group

SafeBootMin: File system - Driver Group

SafeBootMin: Filter - Driver Group

SafeBootMin: PCI Configuration - Driver Group

SafeBootMin: PNP Filter - Driver Group

SafeBootMin: Primary disk - Driver Group

SafeBootMin: SCSI Class - Driver Group

SafeBootMin: sermouse.sys - Driver

SafeBootMin: System Bus Extender - Driver Group

SafeBootMin: vga.sys - Driver

SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

 

SafeBootNet: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)

SafeBootNet: Base - Driver Group

SafeBootNet: Boot Bus Extender - Driver Group

SafeBootNet: Boot file system - Driver Group

SafeBootNet: File system - Driver Group

SafeBootNet: Filter - Driver Group

SafeBootNet: NDIS Wrapper - Driver Group

SafeBootNet: NetBIOSGroup - Driver Group

SafeBootNet: NetDDEGroup - Driver Group

SafeBootNet: Network - Driver Group

SafeBootNet: NetworkProvider - Driver Group

SafeBootNet: nm - File not found

SafeBootNet: nm.sys - File not found

SafeBootNet: PCI Configuration - Driver Group

SafeBootNet: PNP Filter - Driver Group

SafeBootNet: PNP_TDI - Driver Group

SafeBootNet: Primary disk - Driver Group

SafeBootNet: SCSI Class - Driver Group

SafeBootNet: sermouse.sys - Driver

SafeBootNet: Streams Drivers - Driver Group

SafeBootNet: System Bus Extender - Driver Group

SafeBootNet: TDI - Driver Group

SafeBootNet: vga.sys - Driver

SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net

SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient

SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService

SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans

SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

 

========== Files/Folders - Created Within 90 Days ==========

 

[2012.05.12 18:20:31 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mitko\Desktop\OTL.exe

[2012.05.12 18:06:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Application Data\Malwarebytes

[2012.05.12 18:06:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware

[2012.05.12 18:06:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2012.05.12 18:06:06 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2012.05.12 18:06:06 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2012.05.12 18:05:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Application Data\SUPERAntiSpyware.com

[2012.05.12 18:05:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware

[2012.05.12 18:04:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com

[2012.05.12 18:04:54 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware

[2012.05.12 17:49:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Local Settings\Application Data\Opera

[2012.05.12 17:49:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Application Data\Opera

[2012.05.12 17:49:19 | 000,000,000 | ---D | C] -- C:\Program Files\Opera

[2012.05.11 21:44:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Start Menu\Programs\Google Chrome

[2012.05.11 17:00:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search

[2012.05.11 16:59:19 | 004,126,880 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe

[2012.05.11 14:31:30 | 000,419,488 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe

[2012.05.11 12:14:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla

[2012.05.11 09:49:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel

[2012.05.08 19:24:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Desktop\New Folder (3)

[2012.05.04 13:37:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Local Settings\Application Data\AVG Secure Search

[2012.05.04 13:37:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG

[2012.04.19 04:50:26 | 000,024,896 | ---- | C] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\System32\drivers\avgidshx.sys

[2012.04.16 10:37:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Desktop\New Folder (2)

[2012.04.12 08:30:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Desktop\New Folder

[2012.04.01 19:50:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype

[2012.04.01 19:50:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype

[2012.02.27 20:20:21 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Mitko\IECompatCache

[2012.02.22 11:29:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Local Settings\Application Data\Element K

[2012.02.22 11:12:20 | 000,000,000 | ---D | C] -- C:\Program Files\Offline Course Player

[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[1 C:\Documents and Settings\Mitko\Application Data\*.tmp files -> C:\Documents and Settings\Mitko\Application Data\*.tmp -> ]

 

========== Files - Modified Within 90 Days ==========

 

[2012.05.12 18:42:37 | 098,041,082 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm

[2012.05.12 18:38:19 | 000,001,078 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskUserS-1-5-21-1454471165-1123561945-839522115-1003UA.job

[2012.05.12 18:30:29 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2012.05.12 18:20:32 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mitko\Desktop\OTL.exe

[2012.05.12 18:16:14 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2012.05.12 18:06:13 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk

[2012.05.12 18:05:00 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk

[2012.05.12 17:59:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS asks\Adobe Flash Player Updater.job

[2012.05.12 17:49:25 | 000,001,510 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk

[2012.05.12 17:49:25 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk

[2012.05.11 21:44:27 | 000,002,284 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\Google Chrome.lnk

[2012.05.11 21:44:27 | 000,002,262 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2012.05.11 21:35:14 | 000,034,814 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\dt.dat

[2012.05.11 17:00:35 | 000,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk

[2012.05.11 16:59:39 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe

[2012.05.11 16:59:39 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl

[2012.05.11 16:59:19 | 004,126,880 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe

[2012.05.11 07:38:05 | 000,001,026 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskUserS-1-5-21-1454471165-1123561945-839522115-1003Core.job

[2012.05.11 00:52:56 | 000,133,316 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm

[2012.05.10 05:38:12 | 000,005,632 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2012.05.08 19:34:23 | 047,993,083 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\New Folder (3).rar

[2012.05.07 17:45:41 | 000,034,119 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\product_952.jpg

[2012.05.05 17:20:57 | 000,051,386 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\Meridian_14___4e6f0962e2008.jpg

[2012.04.24 12:03:01 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Untitled.alv

[2012.04.19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\System32\drivers\avgidshx.sys

[2012.04.17 10:36:21 | 000,151,718 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\160-Fantasy-Nature-Wallpaper.jpg

[2012.04.17 10:29:46 | 000,378,375 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\fantasy-space-art-068.jpg

[2012.04.05 06:36:47 | 000,314,842 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2012.04.05 06:36:47 | 000,041,170 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2012.03.19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys

[2012.03.10 20:02:32 | 000,059,154 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Untitled-1.gif

[2012.02.22 11:29:31 | 000,001,883 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\Microsoft E-Learning Offline Player.lnk

[2012.02.22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys

[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[1 C:\Documents and Settings\Mitko\Application Data\*.tmp files -> C:\Documents and Settings\Mitko\Application Data\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2012.05.12 18:06:13 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk

[2012.05.12 18:05:00 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk

[2012.05.12 17:49:25 | 000,001,510 | ---- | C] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk

[2012.05.12 17:49:25 | 000,001,498 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk

[2012.05.12 17:49:25 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk

[2012.05.11 21:44:27 | 000,002,284 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\Google Chrome.lnk

[2012.05.11 21:44:27 | 000,002,262 | ---- | C] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2012.05.11 21:35:14 | 000,034,814 | ---- | C] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\dt.dat

[2012.05.11 14:31:30 | 000,000,830 | ---- | C] () -- C:\WINDOWS asks\Adobe Flash Player Updater.job

[2012.05.08 19:32:26 | 047,993,083 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\New Folder (3).rar

[2012.05.07 17:45:45 | 000,034,119 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\product_952.jpg

[2012.05.05 17:20:58 | 000,051,386 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\Meridian_14___4e6f0962e2008.jpg

[2012.05.04 13:37:44 | 000,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk

[2012.04.24 12:03:01 | 000,000,630 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\Untitled.alv

[2012.04.17 10:36:23 | 000,151,718 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\160-Fantasy-Nature-Wallpaper.jpg

[2012.04.17 10:29:49 | 000,378,375 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\fantasy-space-art-068.jpg

[2012.03.10 20:02:32 | 000,059,154 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\Untitled-1.gif

[2012.02.22 11:29:31 | 000,001,889 | ---- | C] () -- C:\Documents and Settings\Mitko\Start Menu\Programs\Microsoft E-Learning Offline Player.lnk

[2012.02.22 11:29:31 | 000,001,883 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\Microsoft E-Learning Offline Player.lnk

[2011.11.19 21:45:45 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll

[2011.09.29 07:20:59 | 000,843,776 | ---- | C] () -- C:\WINDOWS\vsnpstd3.exe

[2011.09.29 07:20:59 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini

[2011.09.29 07:20:56 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll

[2011.09.29 07:20:56 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll

[2011.09.29 07:20:56 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll

[2011.09.29 07:20:56 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll

[2011.07.03 05:53:27 | 000,001,890 | ---- | C] () -- C:\WINDOWS\compedia.ini

[2010.11.15 08:00:39 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2010.11.13 23:12:05 | 000,000,172 | ---- | C] () -- C:\WINDOWS\wininit.ini

 

========== LOP Check ==========

 

[2012.05.04 13:37:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search

[2011.10.13 09:25:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012

[2010.11.19 21:55:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9

[2010.11.19 22:41:49 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files

[2010.04.16 10:03:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations

[2012.05.12 18:42:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData

[2010.04.16 10:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite

[2011.09.14 17:41:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SweetIM

[2011.10.13 09:10:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\AVG Secure Search

[2011.10.13 09:09:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\AVG2012

[2010.07.26 21:51:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\AVG9

[2010.04.16 09:58:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Foxit

[2012.02.05 10:23:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Garmin

[2011.03.15 23:20:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\goalbit

[2010.04.16 10:04:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Nokia

[2010.09.07 23:00:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Nokia Multimedia Player

[2012.05.12 17:49:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Opera

[2010.04.20 09:41:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\PC Suite

[2010.04.23 03:15:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Thinstall

[2012.05.11 20:39:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\uTorrent

 

========== Purity Check ==========

 

 

 

========== Custom Scans ==========

 

< %SYSTEMDRIVE%\*.* >

[2010.04.16 06:53:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT

[2010.04.16 06:47:31 | 000,000,211 | -HS- | M] () -- C:\boot.ini

[2010.04.16 06:53:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS

[2010.04.16 06:53:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS

[2010.04.16 06:53:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS

[2004.08.03 12:38:34 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM

[2004.08.03 12:59:34 | 000,250,032 | RHS- | M] () -- C:\ntldr

[2012.05.12 18:30:25 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys

[2011.07.10 13:57:12 | 000,000,408 | ---- | M] () -- C:\T2Exe.log

 

< %USERPROFILE%\*.* >

[2012.05.12 18:28:58 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\Mitko\ntuser.dat

[2012.05.12 18:39:29 | 000,001,024 | -H-- | M] () -- C:\Documents and Settings\Mitko\ntuser.dat.LOG

[2012.05.12 18:28:58 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Mitko\ntuser.ini

 

< %USERPROFILE%\AppData\Local\*.* >

 

< %USERPROFILE%\AppData\Roaming\*.* >

Invalid Environment Variable: ProgramData

 

< %CommonProgramFiles%\*.* >

 

< %PROGRAMFILES%\*.* >

 

< %systemroot%\system32\*.dll /lockedfiles >

[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

 

< %systemroot%\Tasks\*.job /lockedfiles >

 

< %systemroot%\system32\drivers\*.sys /90 >

[2012.04.19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\system32\drivers\avgidshx.sys

[2012.02.22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgldx86.sys

[2012.03.19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgtdix.sys

[2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys

 

< %systemroot%\system32\drivers\*.sys /lockedfiles >

 

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

 

< MD5 for: EXPLORER.EXE >

[2004.08.03 14:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\explorer.exe

[2004.08.03 14:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\system32\dllcache\explorer.exe

 

< MD5 for: USERINIT.EXE >

[2004.08.03 14:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\dllcache\userinit.exe

[2004.08.03 14:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\userinit.exe

 

< MD5 for: VOLSNAP.SYS >

[2004.08.03 13:00:18 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B -- C:\WINDOWS\system32\dllcache\volsnap.sys

[2004.08.03 13:00:18 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B -- C:\WINDOWS\system32\drivers\volsnap.sys

 

< MD5 for: WINLOGON.EXE >

[2004.08.03 14:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\dllcache\winlogon.exe

[2004.08.03 14:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\winlogon.exe

[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

 

< End of report >

Link to comment
Сподели другаде

Никой не е казал, че инструкциите са същите или че няма промени. Т.е. не е трябвало да бързаш да ги изпълняваш.

 

Изтегли OTL и го запази на работния плот:

- стартирай инструмента;

- постави отметка в горната част на Scan All Users;

- в поле Standard Registry избери All;

- от падащо меню File Age избери 90 Days;

- постави отметки още на: Skip Microsoft Files, LOP Check и Purity Check;

- в поле Custom Scans/Fixes (в долната част на програмата) постави следния текст (маркирай го, натисни Ctrl+C и после в полето на OTL натисни Ctrl+V):

netsvcs
msconfig
safebootminimal
safebootnetwork
"%WinDir%\$NtUninstallKB*$." /30
C:\Program Files\Common Files\ComObjects\*.* /s
%SYSTEMDRIVE%\*.*
%USERPROFILE%\*.*
%USERPROFILE%\Application Data\*.*
%USERPROFILE%\Local Settings\Application Data\*.*
%AllUsersProfile%\*.*
%AllUsersProfile%\Application Data\*.*
%USERPROFILE%\My Documents\*.*
%CommonProgramFiles%\*.*
%PROGRAMFILES%\*.*
%systemroot%\system32\config\systemprofile\*.*
%windir%\ServiceProfiles\LocalService\AppData\Local\Temp\*.*
%windir%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.*
%windir%	emp*.*
%windir%\system32\*.
%Temp%\smtmp\1\*.*
%Temp%\smtmp\2\*.*
%Temp%\smtmp\3\*.*
%Temp%\smtmp\4\*.*
%systemroot%\system32\DBBK\*.* /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /90
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
%systemroot%\*. /rp /s
%systemroot%\assembly	mp\*.* /S /MD5
%systemroot%\assembly	emp\*.* /S /MD5
%systemroot%\assembly\GAC_32\*.* /S /MD5
%systemroot%\assembly\GAC_MSIL\*.* /S /MD5
>C:\commands.txt echo list vol /raw /hide /c
/wait
>C:\DiskReport.txt diskpart /s C:\commands.txt /raw /hide /c
/wait
type c:\diskreport.txt /c
/wait
erase c:\commands.txt /hide /c
/wait
erase c:\diskreport.txt /hide /c
/md5start
smss.exe
winlogon.exe
services.exe
lsass.exe
svchost.exe
explorer.exe
userinit.exe
atapi.sys
iaStor.sys
serial.sys
disk.sys
volsnap.sys
redbook.sys
i8042prt.sys
afd.sys
netbt.sys
tcpip.sys
ipsec.sys
hlp.dat
/md5stop

- кликни бутон Run Scan;

 

След това прикачи новосъздадения файл OTL.txt и вече създадения при първото сканиране Extras.txt.

Link to comment
Сподели другаде

Благодаря за бързия отговор! Ами да-прав си, никой не е казал, ама бързам и аз...

ето съдържанието на новополучения OTL.txt:

OTL logfile created on: 12.5.2012 г. 20:15:47 - Run 2

OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Mitko\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'

 

1,99 Gb Total Physical Memory | 1,44 Gb Available Physical Memory | 72,47% Memory free

3,84 Gb Paging File | 3,08 Gb Available in Paging File | 80,35% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 68,36 Gb Total Space | 22,10 Gb Free Space | 32,33% Space Free | Partition Type: NTFS

Drive D: | 43,43 Gb Total Space | 14,42 Gb Free Space | 33,21% Space Free | Partition Type: NTFS

 

Computer Name: MAGI | User Name: Mitko | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2012.05.12 18:20:32 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mitko\Desktop\OTL.exe

PRC - [2012.05.12 17:49:20 | 000,949,104 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe

PRC - [2012.05.11 17:00:26 | 001,116,544 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe

PRC - [2012.05.04 13:37:37 | 000,932,736 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe

PRC - [2012.05.01 09:48:04 | 003,905,920 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

PRC - [2012.04.30 09:44:38 | 005,106,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgidsagent.exe

PRC - [2012.04.19 04:51:54 | 001,254,992 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe

PRC - [2012.04.05 05:12:34 | 002,587,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe

PRC - [2012.03.19 05:18:12 | 000,979,840 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe

PRC - [2012.02.14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe

PRC - [2012.02.14 04:53:14 | 000,758,112 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe

PRC - [2012.02.14 04:52:38 | 000,338,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe

PRC - [2011.08.11 16:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe

PRC - [2011.06.03 05:00:08 | 000,042,872 | ---- | M] () -- C:\Program Files\Offline Course Player\OlpSynch.exe

PRC - [2009.03.10 18:28:36 | 000,262,144 | ---- | M] (SONIX) -- C:\WINDOWS snpstd3.exe

PRC - [2007.11.22 12:49:08 | 000,385,024 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe

PRC - [2007.11.09 13:16:24 | 000,688,128 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe

PRC - [2007.11.06 09:36:34 | 000,352,768 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

PRC - [2007.11.06 06:38:46 | 000,009,216 | R--- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe

PRC - [2007.10.26 08:55:58 | 000,122,880 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe

PRC - [2007.10.23 10:03:00 | 000,117,248 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe

PRC - [2007.10.09 22:28:32 | 000,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe

PRC - [2006.09.18 14:12:12 | 000,843,776 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe

PRC - [2006.06.13 06:20:00 | 000,127,036 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLACTRLW.EXE

PRC - [2004.08.03 14:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2000.11.07 18:05:40 | 000,145,920 | ---- | M] () -- C:\WINDOWS\Datecs\Flex2K.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2012.05.12 19:42:00 | 000,065,024 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll

MOD - [2012.05.12 19:42:00 | 000,052,736 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll

MOD - [2012.05.12 18:05:34 | 000,117,760 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

MOD - [2012.05.12 18:05:34 | 000,052,224 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll

MOD - [2012.05.12 17:49:25 | 000,783,360 | ---- | M] () -- C:\Program Files\Opera\gstreamer\gstreamer.dll

MOD - [2012.05.12 17:49:25 | 000,316,928 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstoggdec.dll

MOD - [2012.05.12 17:49:25 | 000,276,480 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwebmdec.dll

MOD - [2012.05.12 17:49:25 | 000,168,448 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstffmpegcolorspace.dll

MOD - [2012.05.12 17:49:25 | 000,099,840 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstcoreplugins.dll

MOD - [2012.05.12 17:49:25 | 000,098,816 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioresample.dll

MOD - [2012.05.12 17:49:25 | 000,098,816 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioconvert.dll

MOD - [2012.05.12 17:49:25 | 000,078,336 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwavparse.dll

MOD - [2012.05.12 17:49:25 | 000,076,800 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdirectsound.dll

MOD - [2012.05.12 17:49:25 | 000,068,608 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdecodebin2.dll

MOD - [2012.05.12 17:49:25 | 000,064,000 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstautodetect.dll

MOD - [2012.05.12 17:49:25 | 000,046,592 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwaveform.dll

MOD - [2012.05.12 17:49:25 | 000,045,568 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gsttypefindfunctions.dll

MOD - [2012.05.11 17:00:26 | 001,116,544 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe

MOD - [2012.05.04 13:37:37 | 000,932,736 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe

MOD - [2012.05.04 13:37:37 | 000,130,944 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\SiteSafety.dll

MOD - [2011.06.03 05:00:08 | 000,042,872 | ---- | M] () -- C:\Program Files\Offline Course Player\OlpSynch.exe

MOD - [2007.11.09 13:16:24 | 000,688,128 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe

MOD - [2007.10.26 08:55:58 | 000,122,880 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe

MOD - [2007.10.23 10:03:00 | 000,117,248 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe

MOD - [2007.10.09 22:28:32 | 000,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe

MOD - [2007.08.27 12:35:54 | 001,581,056 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\QtCore4.dll

MOD - [2007.08.02 17:16:58 | 000,131,072 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\Imageformats\qjpeg4.dll

MOD - [2007.08.02 17:05:42 | 006,402,048 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\QtGui4.dll

MOD - [2007.08.02 16:51:54 | 000,356,352 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\QtXml4.dll

MOD - [2006.09.18 14:12:12 | 000,843,776 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe

MOD - [2000.11.07 18:05:40 | 000,145,920 | ---- | M] () -- C:\WINDOWS\Datecs\Flex2K.exe

MOD - [2000.10.19 00:03:34 | 000,028,672 | ---- | M] () -- C:\WINDOWS\system32\newdll.dll

 

 

========== Win32 Services (SafeList) ==========

 

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)

SRV - [2012.05.11 16:59:42 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2012.05.04 13:37:37 | 000,932,736 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe -- (vToolbarUpdater11.0.2)

SRV - [2012.04.30 09:44:38 | 005,106,744 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgidsagent.exe -- (AVGIDSAgent)

SRV - [2012.02.29 08:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)

SRV - [2012.02.14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)

SRV - [2012.02.01 08:51:01 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)

SRV - [2011.08.11 16:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore.exe -- (!SASCORE)

SRV - [2007.11.06 09:36:34 | 000,352,768 | ---- | M] (Nokia.) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)

SRV - [2007.11.06 06:38:46 | 000,009,216 | R--- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio)

 

 

========== Driver Services (SafeList) ==========

 

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)

DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)

DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)

DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)

DRV - File not found [Kernel | System | Stopped] -- -- (Changer)

DRV - [2012.04.19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\avgidshx.sys -- (AVGIDSHX)

DRV - [2012.03.19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)

DRV - [2012.02.22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)

DRV - [2012.01.31 04:46:50 | 000,031,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avgrkx86.sys -- (Avgrkx86)

DRV - [2011.12.23 13:32:14 | 000,041,040 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)

DRV - [2011.12.23 13:32:08 | 000,017,232 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsshimx.sys -- (AVGIDSShim)

DRV - [2011.12.23 13:32:06 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsfilterx.sys -- (AVGIDSFilter)

DRV - [2011.12.23 13:32:00 | 000,139,856 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)

DRV - [2011.07.22 09:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)

DRV - [2011.07.12 14:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)

DRV - [2009.03.25 15:29:52 | 000,130,432 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)

DRV - [2008.05.01 21:15:44 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)

DRV - [2007.11.28 01:02:43 | 000,007,680 | ---- | M] (ATK0100) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor)

DRV - [2007.11.19 19:06:16 | 010,246,400 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)

DRV - [2007.11.06 06:41:42 | 000,264,576 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8187B.sys -- (RTL8187B)

DRV - [2007.11.06 06:40:12 | 004,608,000 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)

DRV - [2007.11.06 06:38:44 | 001,161,888 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)

DRV - [2007.02.22 10:15:56 | 000,137,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcd.sys -- (nmwcd)

DRV - [2007.02.22 10:15:14 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcm.sys -- (nmwcdcm)

DRV - [2007.02.22 10:15:14 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcj.sys -- (nmwcdcj)

DRV - [2007.02.22 10:15:14 | 000,008,320 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdc.sys -- (nmwcdc)

DRV - [2006.06.13 06:20:00 | 000,094,460 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)

DRV - [2006.06.13 06:20:00 | 000,088,476 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)

DRV - [2006.06.13 06:20:00 | 000,086,844 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)

DRV - [2006.06.13 06:20:00 | 000,025,724 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)

DRV - [2006.06.13 06:20:00 | 000,014,716 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)

DRV - [2006.06.13 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)

DRV - [2006.06.13 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)

DRV - [2006.03.17 09:35:24 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)

DRV - [2006.03.17 09:34:46 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)

DRV - [2004.08.03 15:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)

DRV - [2004.08.03 13:07:46 | 000,223,616 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers cpip6.sys -- (Tcpip6)

 

 

========== Standard Registry (All) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=101699&gct=&gc=1&q=

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}

IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms}

 

 

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.bg/

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll ()

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={DF009E60-C8C3-4EAF-9CBA-D4BAEF07B9D8}&mid=f1b63638aed18a771891905ba4517535-b60b068c4d1eaa979e5403bc9cfd8062c9d87e23&lang=en&ds=AVG&pr=fr&d=2012-05-11 17:00:27&v=11.0.0.9&sap=dsp&q={searchTerms}

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedirect?gct=&gc=1&q={searchTerms}&crm=1&toolbar=FXT

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

 

========== FireFox ==========

 

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"

FF - prefs.js..browser.search.defaulturl: ""

FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"

FF - prefs.js..browser.startup.homepage: "www.google.bg"

FF - prefs.js..extensions.enabledItems: avg@igeared:7.005.030.004

FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1374

FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:2.0

FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7B0a39fc7f-d42b-4ff0-82a9-4c8b3e737d36%7D&mid=f1b63638aed18a771891905ba4517535-b60b068c4d1eaa979e5403bc9cfd8062c9d87e23&ds=AVG&v=11.0.0.9&lang=en&pr=fr&d=2012-05-11%2017%3A00%3A27&sap=ku&q="

FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "AVG Secure Search"

FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""

FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "AVG Secure Search"

FF - prefs.js..browser.startup.homepage: "www.google.bg"

FF - user.js - File not found

 

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()

FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll ()

FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)

FF - HKLM\Software\MozillaPlugins\@inhatch.com,version=0.7.2: C:\Program Files\InhatchTeam\Inhatch\npinhatch.dll File not found

FF - HKLM\Software\MozillaPlugins\@inhatch.com,version=0.7.5: C:\Program Files\InhatchTeam\Inhatch\npinhatch.dll File not found

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012.05.11 17:00:35 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\11.0.0.9\ [2012.05.04 13:37:41 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012.05.11 16:59:59 | 000,000,000 | ---D | M]

 

[2010.04.21 03:22:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Extensions

[2010.04.21 03:22:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2010.04.16 09:58:10 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\extensions

[2010.04.16 09:58:10 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}

[2012.05.11 12:21:30 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\extensions

[2010.04.16 23:04:29 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2011.09.14 19:53:41 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}

[2011.09.14 17:41:09 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\searchplugins\sweetim.xml

[2012.05.12 17:48:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2012.04.01 19:51:42 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

[2011.06.23 21:37:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions

[2011.06.23 21:37:35 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2012.05.04 13:37:41 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AVG SECURE SEARCH\11.0.0.9

[2010.04.25 04:16:34 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll

[2006.10.26 21:12:16 | 000,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL

[2011.06.03 05:00:08 | 000,061,440 | ---- | M] (Element K Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOlp32.dll

[2004.11.03 19:43:00 | 000,000,680 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.png

[2012.05.11 17:00:25 | 000,003,766 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml

[2004.11.03 19:43:00 | 000,000,356 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.png

[2004.11.03 19:43:00 | 000,000,557 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\dictionary.png

[2004.11.03 19:43:00 | 000,000,210 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.gif

[2004.11.03 19:43:00 | 000,001,076 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.gif

[2004.11.03 19:43:00 | 000,000,088 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.gif

 

========== Chrome ==========

 

CHR - default_search_provider: AVG Secure Search (Enabled)

CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={DF009E60-C8C3-4EAF-9CBA-D4BAEF07B9D8}&mid=f1b63638aed18a771891905ba4517535-b60b068c4d1eaa979e5403bc9cfd8062c9d87e23&lang=en&ds=AVG&pr=fr&d=2012-05-11 17:00:27&v=11.0.0.9&sap=dsp&q={searchTerms}

CHR - default_search_provider: suggest_url = http://clients5.google.com/complete/search?hl={language}&q={searchTerms}&client=ie8&inputencoding={inputEncoding}&outputencoding={outputEncoding}

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\pdf.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\gcswf32.dll

CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll

CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\plugins/avgnpss.dll

CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll

CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll

CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll

CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll

CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll

CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll

CHR - Extension: YouTube = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\

CHR - Extension: Google \u0422\u044A\u0440\u0441\u0435\u043D\u0435 = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\

CHR - Extension: AVG Safe Search = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\

CHR - Extension: Skype Click to Call = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\

CHR - Extension: AVG Do Not Track = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\

CHR - Extension: Gmail = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

 

O1 HOSTS File: ([2012.05.12 19:39:05 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: ::1 localhost

O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)

O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)

O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)

O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)

O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll ()

O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found

O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)

O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll ()

O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)

O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)

O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)

O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)

O4 - HKLM..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)

O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)

O4 - HKLM..\Run: [OLPSYNCH] C:\Program Files\Offline Course Player\OlpSynch.exe ()

O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)

O4 - HKLM..\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 File not found

O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [skyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()

O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS snpstd3.exe (SONIX)

O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()

O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()

O4 - HKU\.DEFAULT..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)

O4 - HKU\S-1-5-18..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)

O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [Google Update] C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)

O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe ()

O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\WINDOWS\Datecs\Flex2K.exe ()

O4 - Startup: C:\Documents and Settings\Mitko\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)

O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 85.11.187.1 85.11.160.15

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6126DBBF-0FEC-4DE0-AFF0-D72FBE92E8B2}: DhcpNameServer = 85.11.187.1 85.11.160.15

O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)

O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)

O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler v {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.0.2\ViProtocol.dll ()

O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)

O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter ext/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O18 - Protocol\Filter ext/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)

O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)

O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)

O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)

O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify ermsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O24 - Desktop Components:0 (My Current Home Page) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\Mitko\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mitko\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)

O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)

O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2010.04.16 06:53:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *)

O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

 

NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found

NetSvcs: Ias - File not found

NetSvcs: Iprip - File not found

NetSvcs: Irmon - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found

 

 

SafeBootMin: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)

SafeBootMin: Base - Driver Group

SafeBootMin: Boot Bus Extender - Driver Group

SafeBootMin: Boot file system - Driver Group

SafeBootMin: File system - Driver Group

SafeBootMin: Filter - Driver Group

SafeBootMin: PCI Configuration - Driver Group

SafeBootMin: PNP Filter - Driver Group

SafeBootMin: Primary disk - Driver Group

SafeBootMin: SCSI Class - Driver Group

SafeBootMin: sermouse.sys - Driver

SafeBootMin: System Bus Extender - Driver Group

SafeBootMin: vga.sys - Driver

SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

 

SafeBootNet: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)

SafeBootNet: Base - Driver Group

SafeBootNet: Boot Bus Extender - Driver Group

SafeBootNet: Boot file system - Driver Group

SafeBootNet: File system - Driver Group

SafeBootNet: Filter - Driver Group

SafeBootNet: NDIS Wrapper - Driver Group

SafeBootNet: NetBIOSGroup - Driver Group

SafeBootNet: NetDDEGroup - Driver Group

SafeBootNet: Network - Driver Group

SafeBootNet: NetworkProvider - Driver Group

SafeBootNet: nm - File not found

SafeBootNet: nm.sys - File not found

SafeBootNet: PCI Configuration - Driver Group

SafeBootNet: PNP Filter - Driver Group

SafeBootNet: PNP_TDI - Driver Group

SafeBootNet: Primary disk - Driver Group

SafeBootNet: SCSI Class - Driver Group

SafeBootNet: sermouse.sys - Driver

SafeBootNet: Streams Drivers - Driver Group

SafeBootNet: System Bus Extender - Driver Group

SafeBootNet: TDI - Driver Group

SafeBootNet: vga.sys - Driver

SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net

SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient

SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService

SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans

SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

 

========== Files/Folders - Created Within 90 Days ==========

 

[2012.05.12 18:56:41 | 000,000,000 | ---D | C] -- C:\_OTL

[2012.05.12 18:20:31 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mitko\Desktop\OTL.exe

[2012.05.12 18:06:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Application Data\Malwarebytes

[2012.05.12 18:06:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware

[2012.05.12 18:06:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2012.05.12 18:06:06 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2012.05.12 18:06:06 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2012.05.12 18:05:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Application Data\SUPERAntiSpyware.com

[2012.05.12 18:05:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware

[2012.05.12 18:04:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com

[2012.05.12 18:04:54 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware

[2012.05.12 17:49:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Local Settings\Application Data\Opera

[2012.05.12 17:49:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Application Data\Opera

[2012.05.12 17:49:19 | 000,000,000 | ---D | C] -- C:\Program Files\Opera

[2012.05.11 21:44:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Start Menu\Programs\Google Chrome

[2012.05.11 17:00:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search

[2012.05.11 16:59:19 | 004,126,880 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe

[2012.05.11 14:31:30 | 000,419,488 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe

[2012.05.11 12:14:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla

[2012.05.11 09:49:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel

[2012.05.08 19:24:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Desktop\New Folder (3)

[2012.05.04 13:37:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Local Settings\Application Data\AVG Secure Search

[2012.05.04 13:37:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG

[2012.04.19 04:50:26 | 000,024,896 | ---- | C] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\System32\drivers\avgidshx.sys

[2012.04.16 10:37:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Desktop\New Folder (2)

[2012.04.12 08:30:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Desktop\New Folder

[2012.04.01 19:50:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype

[2012.04.01 19:50:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype

[2012.02.27 20:20:21 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Mitko\IECompatCache

[2012.02.22 11:29:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Local Settings\Application Data\Element K

[2012.02.22 11:12:20 | 000,000,000 | ---D | C] -- C:\Program Files\Offline Course Player

[1 C:\Documents and Settings\Mitko\Application Data\*.tmp files -> C:\Documents and Settings\Mitko\Application Data\*.tmp -> ]

 

========== Files - Modified Within 90 Days ==========

 

[2012.05.12 19:59:15 | 000,000,830 | ---- | M] () -- C:\WINDOWS asks\Adobe Flash Player Updater.job

[2012.05.12 19:41:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2012.05.12 19:39:05 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts

[2012.05.12 19:38:00 | 000,001,078 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskUserS-1-5-21-1454471165-1123561945-839522115-1003UA.job

[2012.05.12 18:42:37 | 098,041,082 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm

[2012.05.12 18:20:32 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mitko\Desktop\OTL.exe

[2012.05.12 18:16:14 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2012.05.12 18:06:13 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk

[2012.05.12 18:05:00 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk

[2012.05.12 17:49:25 | 000,001,510 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk

[2012.05.12 17:49:25 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk

[2012.05.11 21:44:27 | 000,002,284 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\Google Chrome.lnk

[2012.05.11 21:44:27 | 000,002,262 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2012.05.11 21:35:14 | 000,034,814 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\dt.dat

[2012.05.11 17:00:35 | 000,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk

[2012.05.11 16:59:39 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe

[2012.05.11 16:59:39 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl

[2012.05.11 16:59:19 | 004,126,880 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe

[2012.05.11 07:38:05 | 000,001,026 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskUserS-1-5-21-1454471165-1123561945-839522115-1003Core.job

[2012.05.11 00:52:56 | 000,133,316 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm

[2012.05.10 05:38:12 | 000,005,632 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2012.05.08 19:34:23 | 047,993,083 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\New Folder (3).rar

[2012.05.07 17:45:41 | 000,034,119 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\product_952.jpg

[2012.05.05 17:20:57 | 000,051,386 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\Meridian_14___4e6f0962e2008.jpg

[2012.04.24 12:03:01 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Untitled.alv

[2012.04.19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\System32\drivers\avgidshx.sys

[2012.04.17 10:36:21 | 000,151,718 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\160-Fantasy-Nature-Wallpaper.jpg

[2012.04.17 10:29:46 | 000,378,375 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\fantasy-space-art-068.jpg

[2012.04.05 06:36:47 | 000,314,842 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2012.04.05 06:36:47 | 000,041,170 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2012.03.19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys

[2012.03.10 20:02:32 | 000,059,154 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Untitled-1.gif

[2012.02.22 11:29:31 | 000,001,883 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\Microsoft E-Learning Offline Player.lnk

[2012.02.22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys

[1 C:\Documents and Settings\Mitko\Application Data\*.tmp files -> C:\Documents and Settings\Mitko\Application Data\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2012.05.12 18:06:13 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk

[2012.05.12 18:05:00 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk

[2012.05.12 17:49:25 | 000,001,510 | ---- | C] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk

[2012.05.12 17:49:25 | 000,001,498 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk

[2012.05.12 17:49:25 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk

[2012.05.11 21:44:27 | 000,002,284 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\Google Chrome.lnk

[2012.05.11 21:44:27 | 000,002,262 | ---- | C] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2012.05.11 21:35:14 | 000,034,814 | ---- | C] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\dt.dat

[2012.05.11 14:31:30 | 000,000,830 | ---- | C] () -- C:\WINDOWS asks\Adobe Flash Player Updater.job

[2012.05.08 19:32:26 | 047,993,083 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\New Folder (3).rar

[2012.05.07 17:45:45 | 000,034,119 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\product_952.jpg

[2012.05.05 17:20:58 | 000,051,386 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\Meridian_14___4e6f0962e2008.jpg

[2012.05.04 13:37:44 | 000,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk

[2012.04.24 12:03:01 | 000,000,630 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\Untitled.alv

[2012.04.17 10:36:23 | 000,151,718 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\160-Fantasy-Nature-Wallpaper.jpg

[2012.04.17 10:29:49 | 000,378,375 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\fantasy-space-art-068.jpg

[2012.03.10 20:02:32 | 000,059,154 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\Untitled-1.gif

[2012.02.22 11:29:31 | 000,001,889 | ---- | C] () -- C:\Documents and Settings\Mitko\Start Menu\Programs\Microsoft E-Learning Offline Player.lnk

[2012.02.22 11:29:31 | 000,001,883 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\Microsoft E-Learning Offline Player.lnk

[2011.11.19 21:45:45 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll

[2011.09.29 07:20:59 | 000,843,776 | ---- | C] () -- C:\WINDOWS\vsnpstd3.exe

[2011.09.29 07:20:59 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini

[2011.09.29 07:20:56 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll

[2011.09.29 07:20:56 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll

[2011.09.29 07:20:56 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll

[2011.09.29 07:20:56 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll

[2011.07.03 05:53:27 | 000,001,890 | ---- | C] () -- C:\WINDOWS\compedia.ini

[2010.11.15 08:00:39 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2010.11.13 23:12:05 | 000,000,172 | ---- | C] () -- C:\WINDOWS\wininit.ini

 

========== LOP Check ==========

 

[2012.05.04 13:37:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search

[2011.10.13 09:25:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012

[2010.11.19 21:55:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9

[2010.11.19 22:41:49 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files

[2010.04.16 10:03:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations

[2012.05.12 18:42:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData

[2010.04.16 10:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite

[2011.09.14 17:41:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SweetIM

[2011.10.13 09:10:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\AVG Secure Search

[2011.10.13 09:09:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\AVG2012

[2010.07.26 21:51:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\AVG9

[2010.04.16 09:58:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Foxit

[2012.02.05 10:23:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Garmin

[2011.03.15 23:20:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\goalbit

[2010.04.16 10:04:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Nokia

[2010.09.07 23:00:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Nokia Multimedia Player

[2012.05.12 17:49:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Opera

[2010.04.20 09:41:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\PC Suite

[2010.04.23 03:15:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Thinstall

[2012.05.12 19:38:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\uTorrent

 

========== Purity Check ==========

 

 

 

========== Custom Scans ==========

 

< "%WinDir%\$NtUninstallKB*$." /30 >

 

< C:\Program Files\Common Files\ComObjects\*.* /s >

 

< %SYSTEMDRIVE%\*.* >

[2010.04.16 06:53:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT

[2010.04.16 06:47:31 | 000,000,211 | -HS- | M] () -- C:\boot.ini

[2010.04.16 06:53:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS

[2010.04.16 06:53:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS

[2010.04.16 06:53:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS

[2004.08.03 12:38:34 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM

[2004.08.03 12:59:34 | 000,250,032 | RHS- | M] () -- C:\ntldr

[2012.05.12 19:41:02 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys

[2011.07.10 13:57:12 | 000,000,408 | ---- | M] () -- C:\T2Exe.log

 

< %USERPROFILE%\*.* >

[2012.05.12 19:39:40 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\Mitko\ntuser.dat

[2012.05.12 20:13:51 | 000,001,024 | -H-- | M] () -- C:\Documents and Settings\Mitko\ntuser.dat.LOG

[2012.05.12 19:39:37 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Mitko\ntuser.ini

 

< %USERPROFILE%\Application Data\*.* >

[2010.08.03 09:31:11 | 001,031,680 | ---- | M] (http://mediainfo.sourceforge.net) -- C:\Documents and Settings\Mitko\Application Data\analyzer.bin

[2010.04.16 01:42:07 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Mitko\Application Data\desktop.ini

[2010.04.16 23:13:30 | 006,328,832 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\engine.bin

[2011.08.17 00:54:44 | 000,000,095 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\engine.dsc

[2010.04.16 23:13:24 | 000,746,232 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\engine2.bin

[2010.04.16 23:13:24 | 000,614,648 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\engine3.bin

[1 C:\Documents and Settings\Mitko\Application Data\*.tmp files -> C:\Documents and Settings\Mitko\Application Data\*.tmp -> ]

 

< %USERPROFILE%\Local Settings\Application Data\*.* >

[2012.05.10 05:38:12 | 000,005,632 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2012.05.11 21:35:14 | 000,034,814 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\dt.dat

[2012.02.01 09:39:34 | 000,070,000 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[2010.11.13 23:13:05 | 007,432,338 | -H-- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\IconCache.db

 

< %AllUsersProfile%\*.* >

 

< %AllUsersProfile%\Application Data\*.* >

[2010.04.16 01:42:08 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini

 

< %USERPROFILE%\My Documents\*.* >

[2012.04.17 10:36:21 | 000,151,718 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\160-Fantasy-Nature-Wallpaper.jpg

[2012.01.27 06:00:08 | 000,000,076 | -HS- | M] () -- C:\Documents and Settings\Mitko\My Documents\desktop.ini

[2012.04.17 10:29:46 | 000,378,375 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\fantasy-space-art-068.jpg

[2012.05.12 18:14:26 | 000,004,296 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\mbam-log-2012-05-12 (18-07-41).txt

[2012.04.21 17:08:05 | 000,052,224 | -HS- | M] () -- C:\Documents and Settings\Mitko\My Documents\Thumbs.db

[2012.03.10 20:02:32 | 000,059,154 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Untitled-1.gif

[2012.04.24 12:03:01 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Untitled.alv

[2011.11.08 12:29:57 | 000,000,188 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Митко-бс.txt

[2011.11.22 11:44:03 | 000,011,802 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\ОФЕРТА.dotx

[2011.12.09 05:52:47 | 000,075,484 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\рецепта.rtf

 

< %CommonProgramFiles%\*.* >

 

< %PROGRAMFILES%\*.* >

 

< %systemroot%\system32\config\systemprofile\*.* >

[2011.06.22 20:32:47 | 000,249,856 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\ntuser.dat

 

< %windir%\ServiceProfiles\LocalService\AppData\Local\Temp\*.* >

 

< %windir%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.* >

 

< %windir% emp*.* >

 

< %windir%\system32\*. >

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1025

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1028

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1031

[2010.04.16 01:27:19 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1033

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1037

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1041

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1042

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1054

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\2052

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\3076

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\3com_dmi

[2010.06.20 10:18:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\appmgmt

[2012.03.12 10:02:58 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\cache

[2012.02.01 08:28:43 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\CatRoot

[2012.05.12 19:42:11 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\CatRoot2

[2010.04.16 06:49:39 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Com

[2012.05.05 22:12:09 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\dhcp

[2010.11.13 23:12:29 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\DirectX

[2010.11.13 23:12:05 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\DLA

[2012.05.11 16:59:13 | 000,000,000 | RHSD | M] -- C:\WINDOWS\system32\dllcache

[2012.05.12 19:37:20 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\drivers

[2010.04.16 10:04:26 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\DRVSTORE

[2012.01.27 05:55:39 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\en-US

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\export

[2010.04.16 06:52:28 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ias

[2010.04.16 01:27:50 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\icsxml

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\IME

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\inetsrv

[2010.04.16 07:42:08 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Lang

[2010.04.16 06:50:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Macromed

[2010.04.16 07:00:04 | 000,000,000 | --SD | M] -- C:\WINDOWS\system32\Microsoft

[2010.04.16 06:49:32 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\MsDtc

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\mui

[2010.04.16 01:29:33 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\npp

[2010.04.16 06:51:09 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\oobe

[2010.04.16 01:27:56 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ras

[2011.11.19 21:45:52 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ReinstallBackups

[2011.06.23 21:39:05 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Restore

[2010.04.16 07:51:56 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\RTCOM

[2010.04.16 01:30:30 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Setup

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ShellExt

[2010.04.16 06:47:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\spool

[2010.04.16 01:30:32 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\usmt

[2012.05.05 22:11:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\wbem

[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\wins

[2010.04.16 07:42:08 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\x64

[2010.04.16 06:53:17 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\xircom

 

< %Temp%\smtmp\1\*.* >

 

< %Temp%\smtmp\2\*.* >

 

< %Temp%\smtmp\3\*.* >

 

< %Temp%\smtmp\4\*.* >

 

< %systemroot%\system32\DBBK\*.* /s >

 

< %systemroot%\system32\*.dll /lockedfiles >

 

< %systemroot%\Tasks\*.job /lockedfiles >

 

< %systemroot%\system32\drivers\*.sys /90 >

[2012.04.19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\system32\drivers\avgidshx.sys

[2012.02.22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgldx86.sys

[2012.03.19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgtdix.sys

[2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys

 

< %systemroot%\system32\drivers\*.sys /lockedfiles >

 

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

 

< %systemroot%\*. /rp /s >

 

< %systemroot%\assembly mp\*.* /S /MD5 >

 

< %systemroot%\assembly emp\*.* /S /MD5 >

 

< %systemroot%\assembly\GAC_32\*.* /S /MD5 >

 

< %systemroot%\assembly\GAC_MSIL\*.* /S /MD5 >

 

< type c:\diskreport.txt /c >

Microsoft DiskPart version 5.1.3565

Copyright © 1999-2003 Microsoft Corporation.

On computer: MAGI

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

Volume 0 E DVD-ROM 0 B

Volume 1 C NTFS Partition 68 GB Healthy System

Volume 2 D NTFS Partition 43 GB Healthy

 

< MD5 for: AFD.SYS >

[2004.08.03 13:14:16 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=5AC495F4CB807B2B98AD2AD591E6D92E -- C:\WINDOWS\system32\dllcache\afd.sys

[2004.08.03 13:14:16 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=5AC495F4CB807B2B98AD2AD591E6D92E -- C:\WINDOWS\system32\drivers\afd.sys

 

< MD5 for: ATAPI.SYS >

[2004.08.03 15:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys

[2004.08.03 15:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys

 

< MD5 for: DISK.SYS >

[2004.08.03 15:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys

[2004.08.03 12:59:56 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\system32\drivers\disk.sys

 

< MD5 for: EXPLORER.EXE >

[2004.08.03 14:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\explorer.exe

[2004.08.03 14:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\system32\dllcache\explorer.exe

 

< MD5 for: I8042PRT.SYS >

[2004.08.03 15:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:i8042prt.sys

[2004.08.03 13:14:38 | 000,052,736 | ---- | M] (Microsoft Corporation) MD5=5502B58EEF7486EE6F93F3F164DCB808 -- C:\WINDOWS\system32\drivers\i8042prt.sys

 

< MD5 for: IASTOR.SYS >

[2007.11.28 01:02:46 | 000,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- C:\WINDOWS\NLDRV\004\iastor.sys

[2007.12.03 02:06:50 | 000,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- C:\WINDOWS\NLDRV\009\iastor.sys

[2007.12.03 02:06:50 | 000,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- C:\WINDOWS\system32\drivers\iaStor.sys

 

< MD5 for: IPSEC.SYS >

[2004.08.03 13:14:30 | 000,074,752 | ---- | M] (Microsoft Corporation) MD5=64537AA5C003A6AFEEE1DF819062D0D1 -- C:\WINDOWS\system32\dllcache\ipsec.sys

[2004.08.03 13:14:30 | 000,074,752 | ---- | M] (Microsoft Corporation) MD5=64537AA5C003A6AFEEE1DF819062D0D1 -- C:\WINDOWS\system32\drivers\ipsec.sys

 

< MD5 for: LSASS.EXE >

[2004.08.03 14:56:52 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=84885F9B82F4D55C6146EBF6065D75D2 -- C:\WINDOWS\system32\dllcache\lsass.exe

[2004.08.03 14:56:52 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=84885F9B82F4D55C6146EBF6065D75D2 -- C:\WINDOWS\system32\lsass.exe

 

< MD5 for: NETBT.SYS >

[2004.08.03 13:14:38 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=0C80E410CD2F47134407EE7DD19CC86B -- C:\WINDOWS\system32\dllcache\netbt.sys

[2004.08.03 13:14:38 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=0C80E410CD2F47134407EE7DD19CC86B -- C:\WINDOWS\system32\drivers\netbt.sys

 

< MD5 for: REDBOOK.SYS >

[2004.08.03 15:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:redbook.sys

[2004.08.03 15:59:38 | 000,057,472 | ---- | M] (Microsoft Corporation) MD5=B31B4588E4086D8D84ADBF9845C2402B -- C:\WINDOWS\system32\drivers\redbook.sys

 

< MD5 for: SERIAL.SYS >

[2004.08.03 15:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:serial.sys

[2004.08.03 13:15:54 | 000,064,896 | ---- | M] (Microsoft Corporation) MD5=CD9404D115A00D249F70A371B46D5A26 -- C:\WINDOWS\system32\drivers\serial.sys

 

< MD5 for: SERVICES.EXE >

[2004.08.03 14:56:56 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\WINDOWS\system32\dllcache\services.exe

[2004.08.03 14:56:56 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\WINDOWS\system32\services.exe

 

< MD5 for: SMSS.EXE >

[2004.08.03 14:56:58 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=BD7FB0957C716F1A60333AEE04DE2178 -- C:\WINDOWS\system32\dllcache\smss.exe

[2004.08.03 14:56:58 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=BD7FB0957C716F1A60333AEE04DE2178 -- C:\WINDOWS\system32\smss.exe

 

< MD5 for: SVCHOST.EXE >

[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe

[2004.08.03 14:56:58 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\system32\dllcache\svchost.exe

[2004.08.03 14:56:58 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\system32\svchost.exe

 

< MD5 for: TCPIP.SYS >

[2004.08.03 13:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\system32\dllcache cpip.sys

[2004.08.03 13:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\system32\drivers cpip.sys

 

< MD5 for: USERINIT.EXE >

[2004.08.03 14:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\dllcache\userinit.exe

[2004.08.03 14:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\userinit.exe

 

< MD5 for: VOLSNAP.SYS >

[2004.08.03 13:00:18 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B -- C:\WINDOWS\system32\dllcache\volsnap.sys

[2004.08.03 13:00:18 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B -- C:\WINDOWS\system32\drivers\volsnap.sys

 

< MD5 for: WINLOGON.EXE >

[2004.08.03 14:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\dllcache\winlogon.exe

[2004.08.03 14:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\winlogon.exe

[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

 

< End of report >

ето и Extras.txt:

OTL Extras logfile created on: 12.5.2012 г. 18:35:56 - Run 1

OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Mitko\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'

 

1,99 Gb Total Physical Memory | 1,23 Gb Available Physical Memory | 61,94% Memory free

3,84 Gb Paging File | 3,12 Gb Available in Paging File | 81,38% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 68,36 Gb Total Space | 20,82 Gb Free Space | 30,46% Space Free | Partition Type: NTFS

Drive D: | 43,43 Gb Total Space | 14,42 Gb Free Space | 33,21% Space Free | Partition Type: NTFS

 

Computer Name: MAGI | User Name: Mitko | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)

 

[HKEY_USERS\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Classes\<extension>]

.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

htmlfile [edit] -- Reg Error: Key error.

http [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)

https [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 1

"UpdatesDisableNotify" = 1

"AntiVirusOverride" = 0

"FirewallOverride" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

========== System Restore Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DoNotAllowExceptions" = 0

"DisableNotifications" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

"2706:TCP" = 2706:TCP:*:Enabled:Inhatch P2P Streaming

"2707:TCP" = 2707:TCP:*:Enabled:Inhatch P2P Streaming

"2708:TCP" = 2708:TCP:*:Enabled:Inhatch P2P Streaming

"2709:TCP" = 2709:TCP:*:Enabled:Inhatch P2P Streaming

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)

"C:\Documents and Settings\Mitko\My Documents\Downloads\ComNet_TV.exe" = C:\Documents and Settings\Mitko\My Documents\Downloads\COMNET_TV.EXE:*:Enabled:COMNET_TV.EXE

"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox

"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer

"C:\Documents and Settings\Mitko\Local Settings\Temp\Torrent2Exe\T2E.exe" = C:\Documents and Settings\Mitko\Local Settings\Temp\Torrent2Exe\T2E.exe:*:Enabled:Torrent2Exe -- (http://www.torrent2exe.com)

"C:\Documents and Settings\Mitko\My Documents\Downloads\SweetImSetup.exe" = C:\Documents and Settings\Mitko\My Documents\Downloads\SweetImSetup.exe:*:Enabled:SweetIM Installer

"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)

"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console -- (Microsoft Corporation)

"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Computer, Inc.)

"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath -- (Skype Technologies S.A.)

"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software)

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00640E90-FF0B-4561-AD85-F5EC43E27B75}" = Fun&Learning - Memory&Logic

"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3

"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting

"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic UDF Reader

"{17079027-EB8A-42C6-9BF8-825B78889F6A}" = Garmin Communicator Plugin

"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86

"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{3BC1AB78-2D98-4906-84B5-4230B5420DCC}" = Offline Course Player

"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3

"{411949AB-6EE8-4C62-9C72-EBC93B6A7935}" = AVG 2012

"{50842BAB-FD22-4B64-BE6D-4DC632EFBF39}" = Fun&Learning - Creativity

"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings

"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3

"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers

"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All

"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3

"{73284F36-E17E-44B0-85E2-F0336A6E749F}" = PC Connectivity Solution

"{74C5EA04-AF1E-45B2-949B-4841EE949C40}" = Nokia Connectivity Cable Driver

"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3

"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support

"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12

"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007

"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007

"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007

"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007

"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007

"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007

"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007

"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007

"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007

"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007

"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3

"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings

"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3

"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps

"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific

"{A7836FF5-7293-40A4-B86E-E2038F82E8F3}" = AVG 2012

"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings

"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver

"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0

"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call

"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3

"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2

"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware

"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client

"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files

"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility

"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings

"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings

"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3

"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = USB PC Camera Plus

"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{FCD8DCE6-94C8-4FF6-8E3E-D3C96A5A707E}" = Nokia PC Suite

"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup

"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)

"6A630DCEC5EEC912115F2FF59D8C2C769798D930" = Windows Driver Package - Nokia Modem (10/12/2007 3.6)

"819D45A9F73817F5B6D7C71A33ADAB88C5DA1765" = Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2)

"9925DD2E3ADF2DA7C8A0212FB775F1D2FB6C56E8" = Windows Driver Package - Nokia (WUDFRd) WPD (11/05/2007 6.85.35.3)

"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin

"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3

"Ask Toolbar_is1" = Ask Toolbar

"AVG" = AVG 2012

"CDex" = CDex extraction audio

"EVEREST Home Edition_is1" = EVEREST Home Edition v1.10

"F1CB0AC2D40DDCFCA6933082B115073476C155DE" = Windows Driver Package - Nokia Modem (08/03/2007 3.2)

"FlexType 2K" = FlexType 2K

"Foxit Reader" = Foxit Reader

"HDMI" = Intel® Graphics Media Accelerator Driver

"ie8" = Windows Internet Explorer 8

"Inhatch web plugins" = Inhatch web plugins

"IrfanView" = IrfanView (remove only)

"KLiteCodecPack_is1" = K-Lite Codec Pack 4.5.3 (Full)

"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware, версия 1.61.0.1400

"Nero - Burning Rom!UninstallKey" = Ahead Nero 6 Demo

"Nokia PC Suite" = Nokia PC Suite

"Opera 11.64.1403" = Opera 11.64

"PROPLUS" = Microsoft Office Professional Plus 2007

"Replay Media Catcher" = Replay Media Catcher

"SA Dictionary 2002 Professional" = SA Dictionary 2002 Professional

"TOSHIBA Software Modem" = TOSHIBA Software Modem

"Unlocker" = Unlocker 1.8.7

"uTorrent" = µTorrent

"VLC media player" = VLC media player 1.1.7

"Winamp" = Winamp

"WinRAR archiver" = WinRAR archiver

 

========== HKEY_USERS Uninstall List ==========

 

[HKEY_USERS\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Google Chrome" = Google Chrome

"uTorrent" = µTorrent

 

========== Last 10 Event Log Errors ==========

 

[ Application Events ]

Error - 02.5.2011 г. 01:00:45 | Computer Name = MAGI | Source = Application Error | ID = 1000

Description = Faulting application firefox.exe, version 1.9.2.4127, faulting module

msvcr90.dll, version 9.0.30729.4148, fault address 0x00059231.

 

Error - 03.5.2011 г. 00:55:58 | Computer Name = MAGI | Source = Application Error | ID = 1000

Description = Faulting application firefox.exe, version 1.9.2.4127, faulting module

msvcr90.dll, version 9.0.30729.4148, fault address 0x00059231.

 

Error - 03.5.2011 г. 00:56:18 | Computer Name = MAGI | Source = Application Error | ID = 1000

Description = Faulting application firefox.exe, version 1.9.2.4127, faulting module

msvcr90.dll, version 9.0.30729.4148, fault address 0x00059231.

 

Error - 03.5.2011 г. 00:56:22 | Computer Name = MAGI | Source = Application Error | ID = 1001

Description = Fault bucket -1882036877.

 

Error - 09.5.2011 г. 01:17:44 | Computer Name = MAGI | Source = Application Error | ID = 1000

Description = Faulting application firefox.exe, version 1.9.2.4127, faulting module

msvcr90.dll, version 9.0.30729.4148, fault address 0x00059231.

 

Error - 12.5.2011 г. 16:14:15 | Computer Name = MAGI | Source = crypt32 | ID = 131083

Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>

with error: A required certificate is not within its validity period when verifying

against the current system clock or the timestamp in the signed file.

 

Error - 12.5.2011 г. 16:14:15 | Computer Name = MAGI | Source = crypt32 | ID = 131083

Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>

with error: A required certificate is not within its validity period when verifying

against the current system clock or the timestamp in the signed file.

 

Error - 15.5.2011 г. 00:48:09 | Computer Name = MAGI | Source = Application Error | ID = 1000

Description = Faulting application firefox.exe, version 1.9.2.4127, faulting module

msvcr90.dll, version 9.0.30729.4148, fault address 0x00059231.

 

Error - 30.5.2011 г. 08:41:44 | Computer Name = MAGI | Source = Application Hang | ID = 1002

Description = Hanging application mplayerc.exe, version 1.2.972.0, hang module hungapp,

version 0.0.0.0, hang address 0x00000000.

 

Error - 01.6.2011 г. 12:49:00 | Computer Name = MAGI | Source = Application Error | ID = 1000

Description = Faulting application firefox.exe, version 1.9.2.4127, faulting module

msvcr90.dll, version 9.0.30729.4148, fault address 0x00059231.

 

[ System Events ]

Error - 11.5.2012 г. 19:57:17 | Computer Name = MAGI | Source = SideBySide | ID = 16842784

Description = Dependent Assembly Microsoft.VC90.CRT could not be found and Last

Error was The referenced assembly is not installed on your system.

 

Error - 11.5.2012 г. 19:57:17 | Computer Name = MAGI | Source = SideBySide | ID = 16842811

Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error

message: The referenced assembly is not installed on your system. .

 

Error - 11.5.2012 г. 19:57:17 | Computer Name = MAGI | Source = SideBySide | ID = 16842811

Description = Generate Activation Context failed for C:\Program Files\AVG\AVG2012\avgcfgx.dll.

Reference

error message: The operation completed successfully. .

 

Error - 11.5.2012 г. 19:57:42 | Computer Name = MAGI | Source = SideBySide | ID = 16842784

Description = Dependent Assembly Microsoft.VC90.CRT could not be found and Last

Error was The referenced assembly is not installed on your system.

 

Error - 11.5.2012 г. 19:57:42 | Computer Name = MAGI | Source = SideBySide | ID = 16842811

Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error

message: The referenced assembly is not installed on your system. .

 

Error - 11.5.2012 г. 19:57:42 | Computer Name = MAGI | Source = SideBySide | ID = 16842811

Description = Generate Activation Context failed for C:\Program Files\AVG\AVG2012\avgcfgx.dll.

Reference

error message: The operation completed successfully. .

 

Error - 11.5.2012 г. 21:01:20 | Computer Name = MAGI | Source = System Error | ID = 1003

Description = Error code 10000050, parameter1 e144401c, parameter2 00000000, parameter3

bf83291e, parameter4 00000001.

 

Error - 11.5.2012 г. 21:01:38 | Computer Name = MAGI | Source = System Error | ID = 1003

Description = Error code 1000008e, parameter1 c0000005, parameter2 bf951755, parameter3

9ba9bc00, parameter4 00000000.

 

Error - 11.5.2012 г. 21:01:40 | Computer Name = MAGI | Source = System Error | ID = 1003

Description = Error code 1000008e, parameter1 c0000005, parameter2 bf951755, parameter3

95c53c00, parameter4 00000000.

 

Error - 12.5.2012 г. 12:41:36 | Computer Name = MAGI | Source = Dhcp | ID = 1000

Description = Your computer has lost the lease to its IP address 85.11.187.219 on

the Network Card with network address 001D60F34F30.

 

 

< End of report >

Link to comment
Сподели другаде

Malwarebytes Anti-Malware и SUPERAntiSpyware Free откриха ли нещо при сканирането? Ако да, моля, прикачи и дневници от техните сканирания.

 

Все още ли имаш проблем с Facebook? Под всеки браузър ли е така? С други сайтове имаш ли проблеми? Някакви други странни проблеми имаш ли с компютъра?

Link to comment
Сподели другаде

3 пъти пусках Anti-Malware и SUPERAntiSpyware Free, докато спряха да откриват по нещо. Facebook вървеше на 6 първоначално-след процедурата, но отново не зарежда. Само с този сайт е проблема. Ще пусна отново програмките и ще прикача сканиранията, ако открият нещо. Незнам защо така се получи-тъкмо се зарадвах, че се оправил, и след малко отново не зарежда. Да не би някакъв вирус уж да е изчезнал, а след малко да се е възпроизвел? :jokingly:

 

Сканирах с двете програмки и нищо не беше открито. Сега пък пробвах - и се зареди Facebook. Дано да не прави повече проблеми. Ако отново имам проблем със зареждането, да повторя ли процедурата с OTL приложението? Благодаря много на Night_Raven за светкавичната помощ и съдействие :yes: И все пак на какво се дължеше проблема-на вирус, или на нещо друго, което спира зареждането точно на този сайт?

Link to comment
Сподели другаде

Ако се появи отново, просто пиши отново или си създай нова тема, не бързай да изпълняваш инструкции. На какво се е дължал проблемът не може да се каже, защото в дневниците не видях нищо обезпокоително. Освен може би FlexType, която ти препоръчвам да премахнеш, защото е боклук, и да ползваш вградената поддръжка в Windows. За повече информация погледни тази тема.
Link to comment
Сподели другаде

И аз съм със същият проблем с фейсбука.С XP съм и изпълних и гореописаните стъпки. Моля да ми помогнете.. :)

extras.txt:

 

OTL Extras logfile created on: 13.5.2012 г. 21:26:26 - Run 1

OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Vasko1\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'

 

2,87 Gb Total Physical Memory | 1,68 Gb Available Physical Memory | 58,53% Memory free

4,71 Gb Paging File | 3,51 Gb Available in Paging File | 74,58% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 19,53 Gb Total Space | 0,19 Gb Free Space | 0,99% Space Free | Partition Type: NTFS

Drive D: | 911,97 Gb Total Space | 420,02 Gb Free Space | 46,06% Space Free | Partition Type: NTFS

Drive F: | 503,94 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

 

Computer Name: VASKO | User Name: Vasko1 | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

 

[HKEY_USERS\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- D:\Programs\Mozilla\firefox.exe (Mozilla Corporation)

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()

Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)

Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)

Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"UpdatesDisableNotify" = 0

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"AntiVirusOverride" = 1

"FirewallOverride" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

========== System Restore Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management

"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)

"C:\WINDOWS\system32\rundll32.exe" = C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App -- (Microsoft Corporation)

"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe" = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil -- (IVT Corporation.)

"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)

"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)

"D:\Games\PES\pes2011.exe" = D:\Games\PES\pes2011.exe:*:Enabled:Pro Evolution Soccer 2011 -- (Konami Digital Entertainment Co., Ltd.)

"D:\Games\gMOD\hl2.exe" = D:\Games\gMOD\hl2.exe:*:Enabled:hl2 -- ()

"D:\Games\Mafia\Steam.exe" = D:\Games\Mafia\Steam.exe:*:Enabled:Steam -- (Valve Corporation)

"D:\Games\TDU\Test Drive Unlimited GOLD\TestDriveUnlimited.exe" = D:\Games\TDU\Test Drive Unlimited GOLD\TestDriveUnlimited.exe:*:Enabled:Test Drive Unlimited -- (Eden Games)

"D:\Games\Fifa\fifa07.exe" = D:\Games\Fifa\fifa07.exe:*:Enabled:fifa07 -- ()

"D:\Games\NWO\New World Order\NWO\NWO.exe" = D:\Games\NWO\New World Order\NWO\NWO.exe:*:Enabled:NWO -- ()

"D:\Games\Prototype\prototypef.exe" = D:\Games\Prototype\prototypef.exe:*:Enabled:Prototype -- (Activision)

"D:\Games\X-Men\Binaries\Wolverine.exe" = D:\Games\X-Men\Binaries\Wolverine.exe:*:Enabled:X-Men Origins - Wolverine -- (Raven Software)

"D:\Games\CoD\CoD2MP_s.exe" = D:\Games\CoD\CoD2MP_s.exe:*:Enabled:CoD2MP_s -- ()

"C:\WINDOWS\system32\PnkBstrA.exe" = C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA -- ()

"C:\WINDOWS\system32\PnkBstrB.exe" = C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB -- ()

"D:\Games\Wolfenstein\MP\Wolf2MP.exe" = D:\Games\Wolfenstein\MP\Wolf2MP.exe:*:Enabled:Wolfenstein -- (Activision)

"D:\Games\Wolfenstein\MP\Wolf2MPLite.exe" = D:\Games\Wolfenstein\MP\Wolf2MPLite.exe:*:Enabled:Wolfenstein -- (Activision)

"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth -- (Google)

"D:\Games\Free Running\FreeRunning.exe" = D:\Games\Free Running\FreeRunning.exe:*:Enabled:FreeRunning -- ()

"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace -- (Microsoft Corporation)

"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote -- (Microsoft Corporation)

"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)

"C:\Program Files\Oleansoft\Hc\servemp.exe" = C:\Program Files\Oleansoft\Hc\servemp.exe:*:Enabled:HC Employee -- (Oleansoft)

"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Computer, Inc.)

"D:\Games\CS\Counter-Strike 1.6 Sector Edition\cstrike.exe" = D:\Games\CS\Counter-Strike 1.6 Sector Edition\cstrike.exe:*:Enabled:Counter-Strike Launcher -- (Non Steam Powered)

"C:\Betfair JPC\arch\win32\jre\bin\java.exe" = C:\Betfair JPC\arch\win32\jre\bin\java.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)

"D:\Games\Stalker\S.T.A.L.K.E.R\bin\XR_3DA.exe" = D:\Games\Stalker\S.T.A.L.K.E.R\bin\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (CLI) -- ()

"D:\Games\Stalker\S.T.A.L.K.E.R\bin\dedicated\XR_3DA.exe" = D:\Games\Stalker\S.T.A.L.K.E.R\bin\dedicated\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (SRV) -- ()

"C:\Program Files\Winamp\winamp.exe" = C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp -- (Nullsoft, Inc.)

"D:\Games\CS\Counter-Strike 1.6 Sector Edition\hlds.exe" = D:\Games\CS\Counter-Strike 1.6 Sector Edition\hlds.exe:*:Enabled:HLDS Launcher -- (Valve)

"D:\Games\Fifa 12\FIFA 12\Game\fifa.exe" = D:\Games\Fifa 12\FIFA 12\Game\fifa.exe:*:Enabled:FIFA 12 -- (Electronic Arts)

"D:\Games\CS\CS 1.6\cstrike.exe" = D:\Games\CS\CS 1.6\cstrike.exe:*:Enabled:Half-Life Launcher -- (Valve)

"C:\Documents and Settings\Vasko1\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe" = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin -- (Skype Limited)

"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{01E9B2FF-DAF4-4529-9CC9-2101625517C7}" = nero.prerequisites.msi

"{034DCAF9-96E7-4936-9A07-712F80B5181E}" = Nero RescueAgent 11

"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam

"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3

"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting

"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended

"{0C38DE0A-5FC3-47E8-9FD0-69B5DC75FFB7}" = CT Special Forces - Fire For Effect

"{11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}" = Nero ControlCenter 11

"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java 6 Update 31

"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile

"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3

"{40A0B29E-B270-450B-BF4D-34493A934523}" = Домашен Кулинар FX

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{4FF4016F-793C-4AFC-AE78-E2E8E70F36DB}_is1" = Counter-Strike 1.6 Version 29, Exe build: 3647

"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings

"{53F7746A-96AA-49A5-86B8-59989680DAC5}" = Nero Burning ROM 11 Help (CHM)

"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3

"{55EB7967-5BB1-4EA2-8AFF-B2F9E487E553}" = PC Connectivity Solution

"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Земя

"{5A438E06-0BB3-4C5F-0085-B14F1F4077E6}" = FIFA 07

"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM

"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update

"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin

"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All

"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2

"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3

"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable

"{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III

"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159

"{7F0B94C6-828C-4EDE-A86B-ECF4D792B68D}" = Activision®

"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3

"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable

"{842E6EBA-FBC9-4077-B5EF-E73268D08286}" = ESET NOD32 Antivirus

"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar

"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3

"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support

"{90140000-0010-0402-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Bulgarian) 14

"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010

"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0015-0402-0000-0000000FF1CE}" = Microsoft Office Access MUI (Bulgarian) 2010

"{90140000-0015-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0016-0402-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Bulgarian) 2010

"{90140000-0016-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0018-0402-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Bulgarian) 2010

"{90140000-0018-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0019-0402-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Bulgarian) 2010

"{90140000-0019-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001A-0402-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Bulgarian) 2010

"{90140000-001A-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001B-0402-0000-0000000FF1CE}" = Microsoft Office Word MUI (Bulgarian) 2010

"{90140000-001B-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0402-0000-0000000FF1CE}" = Microsoft Office Proof (Bulgarian) 2010

"{90140000-001F-0402-0000-0000000FF1CE}_Office14.PROPLUS_{0709C35F-CF3B-4B05-8A2D-6FFD8F9A5F67}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010

"{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUS_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010

"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0419-0000-0000000FF1CE}" = Microsoft Office Proof (Russian) 2010

"{90140000-001F-0419-0000-0000000FF1CE}_Office14.PROPLUS_{DD6E7CDF-BDFF-43CF-8CCE-84FBEC5ABB77}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-002C-0402-0000-0000000FF1CE}" = Microsoft Office Proofing (Bulgarian) 2010

"{90140000-002C-0402-0000-0000000FF1CE}_Office14.PROPLUS_{C8054E0D-931E-4977-873A-017236B74357}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0044-0402-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Bulgarian) 2010

"{90140000-0044-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-006E-0402-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Bulgarian) 2010

"{90140000-006E-0402-0000-0000000FF1CE}_Office14.PROPLUS_{2800BF0D-D21D-49F8-988D-6F521900953C}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-00A1-0402-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Bulgarian) 2010

"{90140000-00A1-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-00BA-0402-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Bulgarian) 2010

"{90140000-00BA-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3

"{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype

"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings

"{9773450C-E2F3-46C3-9464-1D7EDE5EFB63}" = Pro Evolution Soccer 2011

"{993960EE-CA4D-443F-8F88-E24260DD5FD2}" = LG PC Suite

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3

"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps

"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific

"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2

"{A804B134-F03D-4EFD-9BC0-DCD257AA1B22}" = Hitman Blood Money

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings

"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86

"{AF88496B-4BBA-4922-97E9-2582D3A28358}" = Nokia Connectivity Cable Driver

"{B1846721-A8E6-46C7-83B6-0DCF7ADB4267}" = Nero Burning ROM 11

"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0

"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call

"{B9A17C96-1348-45CB-BB0A-1BCB3A0F854E}" = Bluesoleil2.7.0.35 VoIP Release 080317

"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3

"{B9B81B80-F4B4-43FB-A075-2094FC1C2647}" = Prince of Persia The Two Thrones

"{B9FA15C8-17D4-4E71-A6D9-C33E7BDA83AF}_is1" = International Volleyball 2010

"{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components 11

"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3

"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2

"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2

"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver

"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{D01CE99A-8802-483C-A79F-298B691EB432}" = Nero RescueAgent 11 Help (CHM)

"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2

"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client

"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2

"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files

"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas

"{D4D66270-9147-4BDF-9946-FCA2B303AA8F}" = Nero ControlCenter 11 Help (CHM)

"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings

"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings

"{DFFE2B1F-07E0-45A9-8801-CD8514CAA876}" = Prince of Persia T2T

"{E1978666-DFBF-4B42-87F6-2EF088D342AA}" = InnerPass Web Meetings

"{E2494AD8-314D-44F8-B39C-4358A60DC184}" = LogMeIn Hamachi

"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86

"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime

"{E656D89A-8CBB-497F-918F-8361A4071C26}" = Nero Burning ROM 11

"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3

"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8

"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{F48C6EA5-3B43-11D6-86A6-0050BA0259A2}" = ICatch (VI) PC Camera

"{F9835182-794B-4F24-902A-E2CA9D43380F}" = NVIDIA PhysX

"{F9B37992-968C-4264-8449-489032FC28DE}" = Wolfenstein

"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup

"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)

"779B2C05-7C84-4948-BFE9-D284AD37E8CA" = Button Beats Virtual Piano

"82A44D22-9452-49FB-00FB-CEC7DCAF7E23" = EA SPORTS online 2007

"Adobe Acrobat 5.0" = Adobe Acrobat 5.0

"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin

"Adobe Shockwave Player" = Adobe Shockwave Player 11.6

"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3

"Advanced SystemCare 3_is1" = Advanced SystemCare 3

"Alcatraz Tycoon" = Alcatraz Tycoon

"Ashampoo Burning Studio 10_is1" = Ashampoo Burning Studio 10 v.10.0.15

"Betfair Poker JPC_is1" = Betfair Poker JPC 1.0.0

"BS_Player Toolbar" = BS Player Toolbar

"BSPlayerf" = BS.Player FREE

"CCleaner" = CCleaner

"Clownfish" = Clownfish for Skype

"DAEMON Tools Lite" = DAEMON Tools Lite

"Dave Mirra freestyle BMX" = Dave Mirra freestyle BMX

"Defraggler" = Defraggler

"Delete Doctor" = Delete Doctor 2.3

"Evaer Video Recorder for Skype" = Evaer Video Recorder for Skype 1.2.0.15

"FaceOffMax" = Face Off Max

"FIFA 12 © EA_is1" = FIFA 12 © EA version 1

"FileHippo.com" = FileHippo.com Update Checker

"Free Running_is1" = Free Running

"Game Booster_is1" = Game Booster

"GetFLV Pro_is1" = GetFLV Pro 9.0.1.8

"GOM Encoder" = GOM Encoder

"GOM Picker" = GOM PICKER

"GOM Player" = GOM Player

"ie8" = Windows Internet Explorer 8

"InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III

"InstallShield_{7F0B94C6-828C-4EDE-A86B-ECF4D792B68D}" = X-Men Origins - Wolverine

"InstallShield_{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype

"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2

"InstallShield_{F9B37992-968C-4264-8449-489032FC28DE}" = Wolfenstein

"IObit Security 360_is1" = IObit Security 360

"KLiteCodecPack_is1" = K-Lite Codec Pack 6.5.0 (Full)

"LogMeIn Hamachi" = LogMeIn Hamachi

"Mario Forever" = Mario Forever

"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended

"Mozilla Firefox 13.0 (x86 en-US)" = Mozilla Firefox 13.0 (x86 en-US)

"MozillaMaintenanceService" = Mozilla Maintenance Service

"MP3 To Ringtone Gold_is1" = MP3 To Ringtone Gold 5.23

"MPEG2 Codec(libmpeg2/mad)" = MPEG2 Codec(libmpeg2/mad)

"Office14.PROPLUS" = Microsoft Office Professional Plus 2010

"Pamela" = Pamela Pro 4.8

"PhotoScape" = PhotoScape

"PokerStars" = PokerStars

"PokerStars.net" = PokerStars.net

"PunkBusterSvc" = PunkBuster Services

"QuickStores-Toolbar_is1" = QuickStores-Toolbar 1.1.0

"RealHideIP" = Real Hide IP

"Recuva" = Recuva

"Roads Of Rome ." = Roads Of Rome .

"S.T.A.L.K.E.R._is1" = S.T.A.L.K.E.R. [v1.0001]

"SoftwareUpdUtility" = Download Updater (AOL LLC)

"Speccy" = Speccy

"Test Drive Unlimited GOLD_is1" = Test Drive Unlimited GOLD 1.66A Rus

"Ultra Video Converter_is1" = Ultra Video Converter 5.2.0411

"uTorrent" = µTorrent

"uTorrentBar Toolbar" = uTorrentBar Toolbar

"VLC media player" = VLC media player 1.1.11

"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9

"Winamp" = Winamp

"Winamp Toolbar" = Winamp Toolbar

"WinAVI Video Converter" = WinAVI Video Converter

"WinAVI Video Converter 9.09.0" = WinAVI Video Converter 9.0

"Windows Media Format Runtime" = Windows Media Format 11 runtime

"WinRAR archiver" = WinRAR 4.00 (32-битова версия)

"WMFDist11" = Windows Media Format 11 runtime

"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

"XP Codec Pack" = XP Codec Pack

"xvid" = Xvid MPEG-4 Video Codec

 

========== HKEY_USERS Uninstall List ==========

 

[HKEY_USERS\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{79A765E1-C399-405B-85AF-466F52E918B0}" = Nero Toolbar Updater

"Counter-Strike 1.6: New Era" = Counter-Strike 1.6: New Era

"FolderLock6" = Folder Lock

"Game Organizer" = GameXN GO

"Google Chrome" = Google Chrome

"Winamp Detect" = Winamp Detector Plug-in

"Winamp Toolbar" = Winamp Toolbar

 

========== Last 10 Event Log Errors ==========

 

[ Application Events ]

Error - 16.4.2012 г. 15:01:09 | Computer Name = VASKO | Source = .NET Runtime Optimization Service | ID = 1101

Description = .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32)

- 1>Failed to compile: Microsoft.Build.Utilities.v4.0, Version=4.0.0.0, Culture=neutral,

PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80131f06

 

Error - 23.4.2012 г. 19:04:36 | Computer Name = VASKO | Source = Application Error | ID = 1000

Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting

module unknown, version 0.0.0.0, fault address 0x062f6a80.

 

Error - 24.4.2012 г. 19:36:30 | Computer Name = VASKO | Source = Application Error | ID = 1000

Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting

module unknown, version 0.0.0.0, fault address 0x05be6a80.

 

Error - 27.4.2012 г. 17:55:40 | Computer Name = VASKO | Source = Application Error | ID = 1000

Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting

module unknown, version 0.0.0.0, fault address 0x05b06a80.

 

Error - 28.4.2012 г. 18:42:43 | Computer Name = VASKO | Source = Application Error | ID = 1000

Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting

module unknown, version 0.0.0.0, fault address 0x05816a80.

 

Error - 06.5.2012 г. 18:22:38 | Computer Name = VASKO | Source = Application Error | ID = 1000

Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting

module unknown, version 0.0.0.0, fault address 0x05016a80.

 

Error - 11.5.2012 г. 11:20:29 | Computer Name = VASKO | Source = .NET Runtime Optimization Service | ID = 1103

Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)

- Tried to start a service that wasn't the latest version of CLR Optimization service.

Will shutdown

 

Error - 11.5.2012 г. 15:29:39 | Computer Name = VASKO | Source = crypt32 | ID = 131083

Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>

with error: A required certificate is not within its validity period when verifying

against the current system clock or the timestamp in the signed file.

 

Error - 11.5.2012 г. 15:29:39 | Computer Name = VASKO | Source = crypt32 | ID = 131083

Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>

with error: A required certificate is not within its validity period when verifying

against the current system clock or the timestamp in the signed file.

 

Error - 11.5.2012 г. 15:40:42 | Computer Name = VASKO | Source = MsiInstaller | ID = 11313

Description = Product: Домашен Кулинар FX -- Error 1313. The volume E:\ is currently

unavailable. Please select another.

 

[ System Events ]

Error - 04.5.2012 г. 07:38:37 | Computer Name = VASKO | Source = HTTP | ID = 15005

Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP

Listen-Only list may contain a reference to an interface which may not exist on

this machine. The data field contains the error number.

 

Error - 04.5.2012 г. 07:38:50 | Computer Name = VASKO | Source = HTTP | ID = 15005

Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP

Listen-Only list may contain a reference to an interface which may not exist on

this machine. The data field contains the error number.

 

Error - 07.5.2012 г. 11:43:20 | Computer Name = VASKO | Source = HTTP | ID = 15005

Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP

Listen-Only list may contain a reference to an interface which may not exist on

this machine. The data field contains the error number.

 

Error - 07.5.2012 г. 11:43:20 | Computer Name = VASKO | Source = HTTP | ID = 15005

Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP

Listen-Only list may contain a reference to an interface which may not exist on

this machine. The data field contains the error number.

 

Error - 08.5.2012 г. 17:58:13 | Computer Name = VASKO | Source = HTTP | ID = 15005

Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP

Listen-Only list may contain a reference to an interface which may not exist on

this machine. The data field contains the error number.

 

Error - 09.5.2012 г. 04:15:10 | Computer Name = VASKO | Source = HTTP | ID = 15005

Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP

Listen-Only list may contain a reference to an interface which may not exist on

this machine. The data field contains the error number.

 

Error - 09.5.2012 г. 04:15:10 | Computer Name = VASKO | Source = HTTP | ID = 15005

Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP

Listen-Only list may contain a reference to an interface which may not exist on

this machine. The data field contains the error number.

 

Error - 11.5.2012 г. 04:15:51 | Computer Name = VASKO | Source = HTTP | ID = 15005

Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP

Listen-Only list may contain a reference to an interface which may not exist on

this machine. The data field contains the error number.

 

Error - 11.5.2012 г. 04:15:51 | Computer Name = VASKO | Source = HTTP | ID = 15005

Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP

Listen-Only list may contain a reference to an interface which may not exist on

this machine. The data field contains the error number.

 

Error - 12.5.2012 г. 17:56:45 | Computer Name = VASKO | Source = HTTP | ID = 15005

Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP

Listen-Only list may contain a reference to an interface which may not exist on

this machine. The data field contains the error number.

 

 

< End of report >

 

otl.txt:

 

OTL logfile created on: 13.5.2012 г. 21:26:26 - Run 1

OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Vasko1\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'

 

2,87 Gb Total Physical Memory | 1,68 Gb Available Physical Memory | 58,53% Memory free

4,71 Gb Paging File | 3,51 Gb Available in Paging File | 74,58% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 19,53 Gb Total Space | 0,19 Gb Free Space | 0,99% Space Free | Partition Type: NTFS

Drive D: | 911,97 Gb Total Space | 420,02 Gb Free Space | 46,06% Space Free | Partition Type: NTFS

Drive F: | 503,94 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

 

Computer Name: VASKO | User Name: Vasko1 | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days

 

========== Processes (SafeList) ==========

 

PRC - [2012.05.13 21:14:46 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Vasko1\Desktop\OTL.exe

PRC - [2012.04.28 05:07:02 | 001,224,176 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

PRC - [2012.04.09 17:43:42 | 001,557,160 | ---- | M] (Ask) -- C:\Program Files\Ask.com\Updater\Updater.exe

PRC - [2012.04.01 01:31:19 | 000,347,008 | ---- | M] (EasyBits Software AS) -- C:\Documents and Settings\All Users\Application Data\GameXN\GameXNGO.exe

PRC - [2012.03.06 19:33:01 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- D:\Programs\fwfef\bin\jqs.exe

PRC - [2012.02.28 22:59:29 | 000,740,216 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe

PRC - [2012.02.28 18:38:52 | 001,373,576 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe

PRC - [2012.01.19 20:08:34 | 003,477,312 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe

PRC - [2011.11.05 22:50:14 | 000,413,184 | ---- | M] (Oleansoft) -- C:\Program Files\Oleansoft\Hc\servemp.exe

PRC - [2011.09.23 19:37:42 | 000,641,832 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Update\NASvc.exe

PRC - [2011.09.21 10:37:50 | 001,686,016 | ---- | M] (Evaer) -- C:\Program Files\Evaer\videochannel.exe

PRC - [2011.07.22 00:07:38 | 000,718,720 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE

PRC - [2011.03.17 22:56:22 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe

PRC - [2011.01.19 18:37:32 | 003,470,168 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Security 360\is360.exe

PRC - [2010.06.11 19:14:24 | 001,280,344 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Security 360\is360tray.exe

PRC - [2010.06.11 19:14:22 | 000,312,152 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Security 360\is360srv.exe

PRC - [2008.11.10 15:34:26 | 000,711,240 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

PRC - [2008.11.10 15:34:18 | 001,980,200 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

PRC - [2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2008.03.19 17:52:44 | 000,166,520 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe

PRC - [2008.03.19 17:52:40 | 000,709,640 | ---- | M] (IVT Corporation.) -- C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe

PRC - [2008.03.19 17:52:38 | 000,051,816 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe

PRC - [2008.03.19 17:52:36 | 000,138,840 | ---- | M] (IVT Corporation.) -- C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2012.04.28 05:07:01 | 000,444,400 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\ppgooglenaclpluginchrome.dll

MOD - [2012.04.28 05:06:59 | 003,915,248 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\pdf.dll

MOD - [2012.04.28 05:05:34 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\avutil-51.dll

MOD - [2012.04.28 05:05:33 | 000,220,672 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\avformat-53.dll

MOD - [2012.04.28 05:05:32 | 001,747,456 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\avcodec-53.dll

MOD - [2012.04.28 04:09:18 | 008,743,584 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\gcswf32.dll

MOD - [2011.11.03 18:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll

MOD - [2011.05.28 14:54:08 | 000,073,600 | ---- | M] () -- C:\WINDOWS\system32\ezGOSvc.dll

MOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF

MOD - [2011.03.02 13:40:51 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll

MOD - [2009.12.24 18:02:22 | 000,511,312 | ---- | M] () -- C:\Program Files\IObit\IObit Security 360\sqlite3.dll

MOD - [2009.02.12 16:26:20 | 000,167,424 | ---- | M] () -- C:\Program Files\IObit\IObit Security 360\madbasic_.bpl

MOD - [2009.02.12 16:26:20 | 000,044,032 | ---- | M] () -- C:\Program Files\IObit\IObit Security 360\maddisAsm_.bpl

MOD - [2009.01.12 19:56:14 | 000,071,504 | ---- | M] () -- C:\Program Files\IObit\IObit Security 360 askdll.dll

MOD - [2008.07.09 12:05:50 | 000,421,888 | ---- | M] () -- C:\WINDOWS\system32\ac3filter.acm

MOD - [2008.04.14 05:42:04 | 000,192,512 | ---- | M] () -- C:\WINDOWS\system32\qcap.dll

MOD - [2008.04.14 05:42:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll

MOD - [2008.04.14 05:41:52 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll

MOD - [2008.03.19 17:52:44 | 000,166,520 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe

MOD - [2008.03.19 17:52:38 | 000,051,816 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe

MOD - [2004.08.04 15:00:00 | 000,015,360 | ---- | M] () -- C:\WINDOWS\system32 sd32.dll

 

 

========== Win32 Services (SafeList) ==========

 

SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)

SRV - [2012.05.12 14:28:11 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2012.03.06 19:33:01 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- D:\Programs\fwfef\bin\jqs.exe -- (JavaQuickStarterService)

SRV - [2012.02.29 08:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)

SRV - [2012.02.28 18:38:52 | 001,373,576 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)

SRV - [2011.11.10 17:21:06 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)

SRV - [2011.10.27 11:34:30 | 000,718,384 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)

SRV - [2011.09.23 19:37:42 | 000,641,832 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Update\NASvc.exe -- (NAUpdate)

SRV - [2011.06.12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)

SRV - [2011.05.28 14:54:08 | 000,073,600 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\ezGOSvc.dll -- (ezGOSvc)

SRV - [2010.06.11 19:14:22 | 000,312,152 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\IObit Security 360\is360srv.exe -- (IS360service)

SRV - [2008.11.10 15:35:30 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)

SRV - [2008.11.10 15:34:26 | 000,711,240 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)

SRV - [2008.03.19 17:52:44 | 000,166,520 | ---- | M] () [Auto | Running] -- C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe -- (BlueSoleil Hid Service)

SRV - [2008.03.19 17:52:38 | 000,051,816 | ---- | M] () [Auto | Running] -- C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe -- (Start BT in service)

 

 

========== Driver Services (SafeList) ==========

 

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)

DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)

DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)

DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Vasko1\LOCALS~1\Temp\RarSFX1\kerneld.wnt -- (EverestDriver)

DRV - File not found [Kernel | System | Stopped] -- -- (Changer)

DRV - [2012.03.07 23:54:49 | 000,180,224 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\WinVd32.sys -- (WinVd32)

DRV - [2012.03.07 23:54:47 | 000,010,752 | ---- | M] () [File_System | Auto | Running] -- C:\WINDOWS\system32\WinFLdrv.sys -- (WinFLdrv)

DRV - [2012.02.11 14:33:46 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01)

DRV - [2011.08.17 14:03:58 | 000,137,472 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)

DRV - [2011.08.17 14:03:50 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)

DRV - [2011.08.17 13:56:32 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)

DRV - [2011.08.17 13:56:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)

DRV - [2011.08.17 13:56:26 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)

DRV - [2011.08.17 13:56:22 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)

DRV - [2011.05.13 14:39:33 | 000,137,344 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hwpsgt.sys -- (hwpsgt)

DRV - [2011.05.13 14:39:32 | 000,009,472 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lemsgt.sys -- (lemsgt)

DRV - [2010.04.30 17:56:24 | 006,032,928 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)

DRV - [2010.03.22 17:30:22 | 000,222,672 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)

DRV - [2010.01.19 06:50:10 | 000,235,520 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntcDAud.sys -- (IntcDAud) Intel®

DRV - [2009.11.18 08:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)

DRV - [2009.11.18 08:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)

DRV - [2009.03.18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)

DRV - [2008.11.10 15:34:46 | 000,092,168 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)

DRV - [2008.11.10 15:34:22 | 000,104,456 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)

DRV - [2008.11.10 15:33:28 | 000,110,600 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)

DRV - [2008.08.26 11:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)

DRV - [2007.06.24 22:56:54 | 000,038,920 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)

DRV - [2007.06.24 22:56:40 | 000,027,656 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)

DRV - [2007.06.24 22:56:34 | 000,034,312 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)

DRV - [2007.03.05 21:59:04 | 000,018,320 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btnetdrv.sys -- (BT)

DRV - [2007.03.05 21:56:18 | 000,035,600 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\BTHidMgr.sys -- (BTHidMgr)

DRV - [2007.03.05 21:55:12 | 000,020,880 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\vbtenum.sys -- (BTHidEnum)

DRV - [2007.03.05 21:53:18 | 000,044,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)

DRV - [2007.03.05 21:52:18 | 000,034,448 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)

DRV - [2005.03.16 09:23:54 | 000,013,696 | R--- | M] (BIOSTAR Group) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\BIOS.sys -- (BIOS)

DRV - [2005.01.14 19:14:07 | 000,047,616 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)

DRV - [2004.12.03 13:20:41 | 000,020,544 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)

DRV - [2004.10.28 13:47:59 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)

DRV - [2002.10.01 14:43:32 | 000,119,798 | ---- | M] (SP) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SPCA561.SYS -- (CA561) ICatch (VI)

 

 

========== Standard Registry (All) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}

 

 

IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\.DEFAULT\..\SearchScopes\{010E94D5-BCD7-4A3B-9D22-F08EB415378A}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=NRO&o=101913&src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=EW&apn_dtid=YYYYYYYYBG&apn_uid=2E0E9C44-88DF-41E9-AB3F-AC04194DF491&apn_sauid=3AE21784-B8DB-4CCB-9FCC-B3C5CC54F566

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-18\..\SearchScopes\{010E94D5-BCD7-4A3B-9D22-F08EB415378A}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=NRO&o=101913&src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=EW&apn_dtid=YYYYYYYYBG&apn_uid=2E0E9C44-88DF-41E9-AB3F-AC04194DF491&apn_sauid=3AE21784-B8DB-4CCB-9FCC-B3C5CC54F566

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/?pc=AVBR

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1750559

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTo0.dll (Conduit Ltd.)

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\URLSearchHook: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{0BAF872C-D696-46D0-90C5-C8556F783F05}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=NRO&o=101913&src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=EW&apn_dtid=YYYYYYYYBG&apn_uid=2E0E9C44-88DF-41E9-AB3F-AC04194DF491&apn_sauid=3AE21784-B8DB-4CCB-9FCC-B3C5CC54F566

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=10588

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{288575EA-507B-42CB-97BE-ACED08F1998A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1750559

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}: "URL" = http://www.ask.com/web?o=15710&l=dis&q={searchTerms}

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-winamp-chromesbox-en-us&tb_uuid=20110320113708234&tb_oid=20-03-2011&tb_mrud=20-03-2011

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\Moikrug: "URL" = http://moikrug.ru/persons/?clid=1783273&charset=utf-8&keywords={searchTerms}&submitted=1

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\Yandex: "URL" = http://yandex.ru/yandsearch?clid=1783273&text={searchTerms}

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=;ftp=;https=;

 

========== FireFox ==========

 

FF - prefs.js..network.proxy.gopher: ""

FF - prefs.js..network.proxy.gopher_port: 0

FF - prefs.js..network.proxy.share_proxy_settings: true

FF - prefs.js..network.proxy.type: 0

FF - user.js - File not found

 

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: D:\Programs\fwfef\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\Vasko1\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2011.05.04 15:07:42 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\jqs@sun.com: D:\Programs\fwfef\lib\deploy\jqs\ff [2012.03.06 19:33:03 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: D:\Programs\Mozilla\components [2012.05.12 17:21:06 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: D:\Programs\Mozilla\plugins

FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011.03.20 15:18:23 | 000,000,000 | ---D | M]

 

[2012.05.12 17:21:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Vasko1\Application Data\Mozilla\Extensions

[2012.01.21 03:47:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Vasko1\Application Data\Mozilla\Firefox\extensions

[2012.01.21 03:47:03 | 000,000,000 | ---D | M] (BS Player Community Toolbar) -- C:\Documents and Settings\Vasko1\Application Data\Mozilla\Firefox\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}

[2012.05.13 20:20:17 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Vasko1\Application Data\Mozilla\Firefox\Profiles\0px2n2cr.default\extensions

[2012.05.12 23:45:04 | 000,004,527 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\VASKO1\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\0PX2N2CR.DEFAULT\EXTENSIONS\SUPPORT@REAL-HIDE-IP.COM.XPI

[2012.05.13 20:20:17 | 001,184,804 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\VASKO1\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\0PX2N2CR.DEFAULT\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM.XPI

 

========== Chrome ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\pdf.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\gcswf32.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll

CHR - plugin: Skype Click to Call (Enabled) = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\npSkypeChromePlugin.dll

CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll

CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = D:\PFiles\Plugins\np-mswmp.dll

CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll

CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

CHR - plugin: Java Platform SE 6 U31 (Enabled) = D:\Programs\fwfef\bin\plugin2\npjp2.dll

CHR - Extension: YouTube = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\

CHR - Extension: Hide My Ass! Web Proxy = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cmgnmcnlncejehjlnhaglpnoolgbflbd\1.2.4_0\

CHR - Extension: Google \u0422\u044A\u0440\u0441\u0435\u043D\u0435 = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\

CHR - Extension: Skype Click to Call = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\

CHR - Extension: Gmail = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

 

O1 HOSTS File: ([2012.05.13 20:42:38 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()

O2 - BHO: (QuickStores-Toolbar) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)

O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)

O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programs\fwfef\bin\ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)

O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTo0.dll (Conduit Ltd.)

O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Programs\fwfef\bin\jp2ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Programs\fwfef\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

O2 - BHO: (GretechBHO Class) - {F0181C6E-9218-4792-9F3C-E8DF52B2F1AC} - C:\Program Files\GRETECH\GomPicker\GomPickerBHO.dll (Gretech Corporation)

O2 - BHO: (BS Player Toolbar) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)

O3 - HKLM\..\Toolbar: (QuickStores-Toolbar) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTo0.dll (Conduit Ltd.)

O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)

O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)

O3 - HKLM\..\Toolbar: (BS Player Toolbar) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)

O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\prxtbuTo0.dll (Conduit Ltd.)

O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)

O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)

O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (BS Player Toolbar) - {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)

O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\prxtbuTo0.dll (Conduit Ltd.)

O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)

O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)

O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (BS Player Toolbar) - {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)

O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\prxtbuTo0.dll (Conduit Ltd.)

O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)

O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)

O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\WebBrowser: (BS Player Toolbar) - {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)

O4 - HKLM..\Run: [] File not found

O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)

O4 - HKLM..\Run: [bCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)

O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)

O4 - HKLM..\Run: [HCEmployee] C:\Program Files\Oleansoft\Hc\servemp.exe (Oleansoft)

O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)

O4 - HKLM..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)

O4 - HKLM..\Run: [iObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)

O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found

O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)

O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)

O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)

O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)

O4 - HKU\.DEFAULT..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKU\S-1-5-18..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKU\S-1-5-19..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKU\S-1-5-20..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [avichannel] C:\Program Files\Evaer\videochannel.exe (Evaer)

O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)

O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [Facebook Update] C:\Documents and Settings\Vasko1\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)

O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [GameXN] C:\Documents and Settings\All Users\Application Data\GameXN\GameXNGO.exe (EasyBits Software AS)

O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [GameXN (news)] C:\Documents and Settings\All Users\Application Data\GameXN\GameXNGO.exe (EasyBits Software AS)

O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [GameXN (update)] C:\Documents and Settings\All Users\Application Data\GameXN\GameXNGO.exe (EasyBits Software AS)

O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [Google Update] C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)

O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)

O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)

O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\gprs.exe (IVT Corporation.)

O4 - Startup: C:\Documents and Settings\Vasko1\Start Menu\Programs\Startup\Изрязване на екран и стартиране на OneNote 2010.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0

O8 - Extra context menu item: &Експортиране към Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)

O8 - Extra context menu item: &Изпрати към OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found

O9 - Extra Button: Изпрати към OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Изпрати към OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)

O9 - Extra Button: &Свързани бележки на OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Свързани бележки на OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)

O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)

O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe File not found

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)

O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{40884B3B-8CDF-4E11-8909-90FA5144F299}: DhcpNameServer = 192.168.1.1

O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)

O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler v {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter ext/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O18 - Protocol\Filter ext/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)

O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)

O20 - Winlogon\Notify\dimsntfy: DllName - (%SystemRoot%\System32\dimsntfy.dll) - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)

O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify ermsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O24 - Desktop Components:0 (My Current Home Page) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\Vasko1\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Vasko1\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)

O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2011.03.16 22:49:19 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2009.09.15 15:12:05 | 000,315,392 | R--- | M] () - F:\autorun.exe -- [ CDFS ]

O32 - AutoRun File - [2009.10.12 12:38:06 | 000,000,042 | R--- | M] () - F:\autorun.inf -- [ CDFS ]

O33 - MountPoints2\{44a3cec4-54a4-11e1-ad04-001167c760f5}\Shell - "" = AutoRun

O33 - MountPoints2\{44a3cec4-54a4-11e1-ad04-001167c760f5}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{44a3cec4-54a4-11e1-ad04-001167c760f5}\Shell\AutoRun\command - "" = F:\autorun.exe -- [2009.09.15 15:12:05 | 000,315,392 | R--- | M] ()

O33 - MountPoints2\{eee94026-52f5-11e0-b5ee-001167c760f5}\Shell - "" = AutoRun

O33 - MountPoints2\{eee94026-52f5-11e0-b5ee-001167c760f5}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{eee94026-52f5-11e0-b5ee-001167c760f5}\Shell\AutoRun\command - "" = F:\setup.exe -- [2010.03.24 14:09:28 | 527,596,262 | R--- | M] (IQ Publishing )

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

 

NetSvcs: 6to4 - File not found

NetSvcs: Ias - File not found

NetSvcs: Iprip - File not found

NetSvcs: Irmon - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found

NetSvcs: ezGOSvc - C:\WINDOWS\system32\ezGOSvc.dll ()

NetSvcs: 2.httpool.com/", [ "http://00.creativecdn.com/", 1.8572295440774185, "http://ad.yieldmanager.com/", 0.48469568125582047, "http://ad2.httpool.com/", 0.48469568125582047, "http://content.yieldmanager.edgesuite.net/", 0.2148418158770503, "http://creativecdn.com/", 1.8572295440774185 ] ], [ "http://ads.garga.biz/", [ "http://ads.garga.biz/", 0.832716631910619 ] ], [ "http://api.zippyshare.com/", [ "http://www65.zippyshare.com/", - File not found

 

 

SafeBootMin: Base - Driver Group

SafeBootMin: Boot Bus Extender - Driver Group

SafeBootMin: Boot file system - Driver Group

SafeBootMin: File system - Driver Group

SafeBootMin: Filter - Driver Group

SafeBootMin: PCI Configuration - Driver Group

SafeBootMin: PNP Filter - Driver Group

SafeBootMin: Primary disk - Driver Group

SafeBootMin: SCSI Class - Driver Group

SafeBootMin: sermouse.sys - Driver

SafeBootMin: System Bus Extender - Driver Group

SafeBootMin: vga.sys - Driver

SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

 

SafeBootNet: Base - Driver Group

SafeBootNet: Boot Bus Extender - Driver Group

SafeBootNet: Boot file system - Driver Group

SafeBootNet: File system - Driver Group

SafeBootNet: Filter - Driver Group

SafeBootNet: Hamachi2Svc - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)

SafeBootNet: NDIS Wrapper - Driver Group

SafeBootNet: NetBIOSGroup - Driver Group

SafeBootNet: NetDDEGroup - Driver Group

SafeBootNet: Network - Driver Group

SafeBootNet: NetworkProvider - Driver Group

SafeBootNet: PCI Configuration - Driver Group

SafeBootNet: PNP Filter - Driver Group

SafeBootNet: PNP_TDI - Driver Group

SafeBootNet: Primary disk - Driver Group

SafeBootNet: SCSI Class - Driver Group

SafeBootNet: sermouse.sys - Driver

SafeBootNet: Streams Drivers - Driver Group

SafeBootNet: System Bus Extender - Driver Group

SafeBootNet: TDI - Driver Group

SafeBootNet: vga.sys - Driver

SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net

SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient

SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService

SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans

SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

 

========== Files/Folders - Created Within 90 Days ==========

 

[2012.05.13 21:23:36 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Vasko1\Desktop\OTL.exe

[2012.05.13 16:11:14 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Vasko1\Recent

[2012.05.12 17:21:07 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service

[2012.05.12 17:12:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Start Menu\Programs\Google Chrome

[2012.05.12 14:04:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla

[2012.05.12 12:36:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\My Documents\My Games

[2012.05.11 23:27:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\IQ Publishing

[2012.05.11 22:41:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Start Menu\Programs\Difference World

[2012.05.11 18:57:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Application Data\Avant Downloader

[2012.04.27 23:02:03 | 000,000,000 | ---D | C] -- C:\Program Files\Opera

[2012.04.25 16:26:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\My Documents\haha

[2012.04.21 22:36:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared

[2012.04.21 22:36:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton

[2012.04.21 22:36:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller

[2012.04.01 17:58:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Start Menu\Programs\Buziol Games

[2012.04.01 15:07:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\WindowsPowerShell

[2012.04.01 15:07:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\winrm

[2012.04.01 15:07:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy

[2012.04.01 15:07:01 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$968930Uinstall_KB968930$

[2012.04.01 01:34:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype

[2012.04.01 01:34:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype

[2012.04.01 01:31:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\GameXN

[2012.03.18 19:19:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Games

[2012.03.10 16:57:39 | 000,503,808 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioEditor.dll

[2012.03.10 16:57:39 | 000,339,968 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioTransform.dll

[2012.03.10 16:57:39 | 000,290,816 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTWMAFile.dll

[2012.03.10 16:57:39 | 000,282,624 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioVisualization.dll

[2012.03.10 16:57:39 | 000,274,432 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioRecord.dll

[2012.03.10 16:57:39 | 000,274,432 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioPlayer.dll

[2012.03.10 16:57:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\MP3 To Ringtone Gold

[2012.03.10 16:57:38 | 001,703,936 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioFile.dll

[2012.03.10 16:57:38 | 000,892,928 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioInformation.dll

[2012.03.10 16:57:38 | 000,327,680 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioGrabber.dll

[2012.03.10 16:57:38 | 000,070,144 | ---- | C] (TODO: <Company name>) -- C:\WINDOWS\System32\AudioFileConvert.ocx

[2012.03.08 00:14:39 | 000,000,000 | ---D | C] -- C:\Program Files\Folder Lock 6

[2012.03.07 23:54:47 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Vasko1\Application Data\.#

[2012.03.07 23:54:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Start Menu\Programs\Folder Lock 6

[2012.03.06 19:35:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Application Data\.minecraft

[2012.03.06 19:33:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun

[2012.03.06 19:33:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java

[2012.03.06 19:33:12 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll

[2012.03.06 19:33:12 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe

[2012.03.06 19:33:12 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe

[2012.03.06 19:33:12 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe

[2012.03.06 19:33:12 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl

[2012.03.06 19:32:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Application Data\Sun

[2012.03.01 12:57:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\LogMeIn Hamachi

[2012.03.01 12:57:01 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi

[2012.02.29 19:26:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\My Documents\FIFA 12

[2012.02.20 01:47:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\PackageAware

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

========== Files - Modified Within 90 Days ==========

 

[2012.05.13 21:28:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS asks\Adobe Flash Player Updater.job

[2012.05.13 21:26:00 | 000,000,236 | ---- | M] () -- C:\WINDOWS asks\Scheduled Update for Ask Toolbar.job

[2012.05.13 21:14:46 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Vasko1\Desktop\OTL.exe

[2012.05.13 20:46:06 | 000,001,002 | ---- | M] () -- C:\WINDOWS asks\FacebookUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003UA.job

[2012.05.13 20:35:00 | 000,001,082 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003UA.job

[2012.05.13 20:32:00 | 000,000,986 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskMachineUA.job

[2012.05.13 15:35:00 | 000,001,030 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003Core.job

[2012.05.13 14:46:00 | 000,000,980 | ---- | M] () -- C:\WINDOWS asks\FacebookUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003Core.job

[2012.05.13 10:44:49 | 000,504,810 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2012.05.13 10:44:49 | 000,088,656 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2012.05.13 10:41:14 | 000,000,260 | ---- | M] () -- C:\WINDOWS asks\WGASetup.job

[2012.05.13 10:40:24 | 000,000,982 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskMachineCore.job

[2012.05.13 10:40:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2012.05.12 17:21:38 | 000,000,539 | ---- | M] () -- C:\Documents and Settings\Vasko1\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk

[2012.05.12 17:21:38 | 000,000,539 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

[2012.05.12 17:12:58 | 000,002,293 | ---- | M] () -- C:\Documents and Settings\Vasko1\Desktop\Google Chrome.lnk

[2012.05.12 17:12:58 | 000,002,271 | ---- | M] () -- C:\Documents and Settings\Vasko1\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2012.05.12 14:28:09 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe

[2012.05.12 14:28:09 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl

[2012.05.12 12:41:40 | 000,146,432 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2012.05.12 12:34:54 | 000,000,038 | ---- | M] () -- C:\WINDOWS\avisplitter.ini

[2012.05.12 01:42:48 | 001,567,000 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2012.05.11 22:41:15 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI

[2012.05.10 16:03:26 | 000,000,320 | ---- | M] () -- C:\WINDOWS\mafosav.INI

[2012.05.10 16:03:07 | 000,000,100 | ---- | M] () -- C:\WINDOWS\forevermopt.INI

[2012.05.10 10:32:36 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2012.04.25 16:31:24 | 000,288,768 | -H-- | M] () -- C:\Documents and Settings\Vasko1\My Documents\photothumb.db

[2012.03.27 00:05:04 | 000,000,123 | ---- | M] () -- C:\Documents and Settings\Vasko1\Desktop\NOVA.pls

[2012.03.12 12:12:54 | 002,720,291 | ---- | M] () -- C:\Documents and Settings\Vasko1\Desktop\DSC00390.JPG

[2012.03.12 01:19:01 | 007,453,553 | ---- | M] () -- C:\Documents and Settings\Vasko1\Desktop\DSC00082.JPG

[2012.03.10 16:18:01 | 000,320,178 | ---- | M] () -- C:\WINDOWS\ThemeMakerWallpaper.bmp

[2012.03.08 00:38:59 | 005,242,880 | ---- | M] () -- C:\Documents and Settings\Vasko1\My Documents\Locker01.flk

[2012.03.08 00:25:44 | 000,000,726 | ---- | M] () -- C:\Documents and Settings\Vasko1\Application Data\Microsoft\Internet Explorer\Quick Launch\Folder Lock 6.lnk

[2012.03.07 23:54:49 | 000,180,224 | ---- | M] () -- C:\WINDOWS\System32\WinVd32.sys

[2012.03.07 23:54:47 | 000,007,680 | ---- | M] () -- C:\WINDOWS\System32\WinFLsrv.exe

[2012.03.06 19:33:01 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll

[2012.03.06 19:33:01 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe

[2012.03.06 19:33:01 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe

[2012.03.06 19:33:01 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe

[2012.03.06 19:33:01 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2012.05.12 17:21:38 | 000,000,539 | ---- | C] () -- C:\Documents and Settings\Vasko1\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk

[2012.05.12 17:21:38 | 000,000,539 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk

[2012.05.12 17:21:38 | 000,000,539 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

[2012.05.12 17:12:58 | 000,002,293 | ---- | C] () -- C:\Documents and Settings\Vasko1\Desktop\Google Chrome.lnk

[2012.05.12 17:12:58 | 000,002,271 | ---- | C] () -- C:\Documents and Settings\Vasko1\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2012.04.01 01:31:25 | 000,001,798 | ---- | C] () -- C:\Documents and Settings\Vasko1\Start Menu\Programs\Играене на игри (GameXN).lnk

[2012.03.27 00:05:04 | 000,000,123 | ---- | C] () -- C:\Documents and Settings\Vasko1\Desktop\NOVA.pls

[2012.03.13 00:09:25 | 000,217,835 | ---- | C] () -- C:\Documents and Settings\Vasko1\Desktop\27072009_003.jpg

[2012.03.13 00:09:25 | 000,201,995 | ---- | C] () -- C:\Documents and Settings\Vasko1\Desktop\27072009_004.jpg

[2012.03.12 01:11:12 | 007,453,553 | ---- | C] () -- C:\Documents and Settings\Vasko1\Desktop\DSC00082.JPG

[2012.03.11 00:13:23 | 002,720,291 | ---- | C] () -- C:\Documents and Settings\Vasko1\Desktop\DSC00390.JPG

[2012.03.10 16:57:38 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\ammpp.dll

[2012.03.10 16:57:38 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll

[2012.03.10 16:57:38 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\a1.dll

[2012.03.10 16:57:38 | 000,003,772 | ---- | C] () -- C:\WINDOWS\System32\AudioFileConvert.tlb

[2012.03.10 16:57:37 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\qscl.dll

[2012.03.10 16:57:37 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\amrdec.dll

[2012.03.10 16:57:37 | 000,144,896 | ---- | C] () -- C:\WINDOWS\System32\lame_dshow.ax

[2012.03.10 16:57:37 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\qcpsdk.dll

[2012.03.10 16:17:30 | 000,320,178 | ---- | C] () -- C:\WINDOWS\ThemeMakerWallpaper.bmp

[2012.03.08 00:27:32 | 005,242,880 | ---- | C] () -- C:\Documents and Settings\Vasko1\My Documents\Locker01.flk

[2012.03.07 23:54:48 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\WinVd32.sys

[2012.03.07 23:54:47 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\WinFLsrv.exe

[2012.03.07 23:54:43 | 000,000,726 | ---- | C] () -- C:\Documents and Settings\Vasko1\Application Data\Microsoft\Internet Explorer\Quick Launch\Folder Lock 6.lnk

[2012.02.29 19:24:06 | 000,000,664 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\FIFA 12.lnk

[2012.02.15 01:33:03 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll

[2012.02.15 01:33:03 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll

[2012.01.17 01:01:19 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\AVERM.dll

[2012.01.17 01:01:19 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll

[2011.11.06 13:20:44 | 000,000,233 | ---- | C] () -- C:\WINDOWS\MTConfig.INI

[2011.11.06 12:04:12 | 000,065,536 | ---- | C] () -- C:\WINDOWS\DTDraw.dll

[2011.11.05 22:53:35 | 000,007,012 | ---- | C] () -- C:\WINDOWS\hctabl212.ini

[2011.11.05 22:53:35 | 000,001,028 | ---- | C] () -- C:\WINDOWS\hcpict212.ini

[2011.11.05 22:53:35 | 000,000,369 | ---- | C] () -- C:\WINDOWS\hcreg212.ini

[2011.10.18 15:43:57 | 000,118,784 | ---- | C] () -- C:\WINDOWS\ShowBmp.exe

[2011.10.18 15:43:57 | 000,014,385 | ---- | C] () -- C:\WINDOWS\Tw561a.ini

[2011.10.18 15:43:57 | 000,000,081 | ---- | C] () -- C:\WINDOWS\Setup8a.ini

[2011.09.27 19:42:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI

[2011.09.17 16:47:37 | 000,139,152 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys

[2011.09.17 16:47:37 | 000,139,152 | ---- | C] () -- C:\Documents and Settings\Vasko1\Application Data\PnkBstrK.sys

[2011.09.17 16:47:23 | 000,111,928 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe

[2011.09.17 16:47:22 | 000,075,064 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe

[2011.09.17 16:47:21 | 000,794,408 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe

[2011.09.17 16:12:52 | 000,000,257 | ---- | C] () -- C:\WINDOWS\game.ini

[2011.06.17 16:19:14 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll

[2011.06.08 20:53:27 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2011.05.29 18:41:31 | 000,073,600 | ---- | C] () -- C:\WINDOWS\System32\ezGOSvc.dll

[2011.05.13 14:39:33 | 000,137,344 | ---- | C] () -- C:\WINDOWS\System32\drivers\hwpsgt.sys

[2011.05.13 14:39:32 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\lemsgt.sys

[2011.04.30 17:58:10 | 000,000,151 | ---- | C] () -- C:\WINDOWS\disney.ini

[2011.03.28 06:50:18 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll

[2011.03.28 06:49:42 | 000,649,728 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll

[2011.03.20 14:34:29 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll

[2011.03.20 14:34:28 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini

[2011.03.17 00:40:37 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat

[2011.03.17 00:34:42 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2011.03.17 00:32:52 | 001,567,000 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2011.03.16 23:41:16 | 000,080,416 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll

[2011.03.16 23:40:24 | 000,127,896 | ---- | C] () -- C:\WINDOWS\System32\igcompkrng575.bin

[2011.03.16 23:40:23 | 000,874,032 | ---- | C] () -- C:\WINDOWS\System32\igkrng575.bin

[2011.03.16 23:40:23 | 000,004,096 | ---- | C] ( ) -- C:\WINDOWS\System32\IGFXDEVLib.dll

[2011.03.16 23:40:23 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\GfxUI.exe.config

[2011.03.16 23:04:09 | 000,146,432 | ---- | C] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011.03.16 22:57:00 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2011.03.16 22:43:35 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

 

========== LOP Check ==========

 

[2011.03.20 14:12:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software

[2011.03.20 18:10:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo

[2011.03.20 14:07:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software

[2011.09.27 19:51:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BabylonUpdater

[2011.03.19 19:13:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bluetooth

[2012.02.04 12:25:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite

[2011.10.08 17:55:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Default

[2012.04.01 01:31:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Easybits GO

[2011.12.13 14:19:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts

[2011.03.20 15:18:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET

[2011.06.10 22:27:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FaceOffMax

[2012.05.13 21:25:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameXN

[2011.04.22 19:11:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InterAction studios

[2011.09.18 00:53:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit

[2011.04.30 21:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\KONAMI

[2011.11.20 19:41:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia

[2011.05.22 18:24:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaAccount

[2011.05.22 17:38:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache

[2011.12.13 14:22:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Origin

[2011.06.28 11:23:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite

[2011.09.17 14:48:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\POP3Profiles

[2011.06.05 14:50:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Test Drive Unlimited

[2011.10.06 21:08:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Application Data\PC Suite

[2012.05.12 12:36:19 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Vasko1\Application Data\.#

[2012.03.06 19:37:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\.minecraft

[2011.03.20 18:11:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Ashampoo

[2012.01.22 22:51:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\AskToolbar

[2011.04.30 19:36:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Avanquest

[2012.05.11 18:57:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Avant Downloader

[2012.04.19 09:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\BSplayer

[2012.01.21 03:46:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\BSplayer Pro

[2012.05.13 10:40:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\DAEMON Tools Lite

[2011.09.30 12:38:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Evaer

[2011.06.10 22:12:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\FaceOffMax

[2012.05.13 16:00:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\go

[2012.01.22 17:55:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\hidden smilies 2.0

[2011.09.16 21:50:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\InterTrust

[2012.04.01 15:08:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\IObit

[2011.11.20 19:40:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Nokia

[2011.05.22 18:04:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Nokia Ovi Suite

[2011.12.20 15:32:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Opera

[2011.09.30 12:35:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Pamela

[2011.05.22 18:04:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\PC Suite

[2012.03.12 01:15:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\PhotoScape

[2011.09.18 00:56:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\PriceGong

[2011.12.15 23:03:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\QuickStoresToolbar

[2011.06.22 01:01:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Roads Of Rome

[2012.03.23 19:28:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\TeamViewer

[2012.05.13 21:28:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\uTorrent

[2011.12.15 23:56:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\WinAVI

[2011.05.01 14:12:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\YoudaGames

[2012.05.13 14:46:00 | 000,000,980 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003Core.job

[2012.05.13 20:46:06 | 000,001,002 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003UA.job

[2012.05.13 21:26:00 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

[2012.05.13 10:41:14 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job

 

========== Purity Check ==========

 

 

 

========== Custom Scans ==========

 

< "%WinDir%\$NtUninstallKB*$." /30 >

 

< C:\Program Files\Common Files\ComObjects\*.* /s >

 

< %SYSTEMDRIVE%\*.* >

[2011.09.17 15:34:46 | 000,439,601 | ---- | M] () -- C:\AnalysisLog.sr0

[2011.03.16 22:49:19 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT

[2011.03.16 22:39:55 | 000,000,211 | -HS- | M] () -- C:\boot.ini

[2011.03.16 22:49:19 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS

[2011.03.16 22:49:19 | 000,000,000 | RHS- | M] () -- C:\IO.SYS

[2011.12.15 23:20:14 | 000,038,111 | ---- | M] () -- C:\MP4debug.log

[2011.03.16 22:49:19 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS

[2008.04.13 22:13:04 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM

[2008.04.14 00:01:44 | 000,250,048 | RHS- | M] () -- C:\ntldr

[2012.05.13 10:40:21 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys

[2011.03.16 23:42:50 | 000,002,080 | ---- | M] () -- C:\RHDSetup.log

[2011.11.27 00:08:39 | 000,000,275 | ---- | M] () -- C:\Shortcut to Local Disk (D).lnk

[2012.05.12 12:36:11 | 000,000,449 | ---- | M] () -- C:\Sys_LogWin.log

 

< %USERPROFILE%\*.* >

[2012.05.13 03:35:27 | 009,961,472 | -H-- | M] () -- C:\Documents and Settings\Vasko1\NTUSER.DAT

[2012.05.13 21:26:27 | 000,057,344 | -H-- | M] () -- C:\Documents and Settings\Vasko1\ntuser.dat.LOG

[2012.05.13 03:35:27 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Vasko1\ntuser.ini

 

< %USERPROFILE%\Application Data\*.* >

[2011.03.17 00:33:42 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Vasko1\Application Data\desktop.ini

[2011.09.17 16:47:37 | 000,139,152 | ---- | M] () -- C:\Documents and Settings\Vasko1\Application Data\PnkBstrK.sys

 

< %USERPROFILE%\Local Settings\Application Data\*.* >

[2012.05.12 12:41:40 | 000,146,432 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2012.05.12 14:44:11 | 000,070,760 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[2012.05.13 03:35:18 | 008,623,608 | -H-- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\IconCache.db

 

< %AllUsersProfile%\*.* >

 

< %AllUsersProfile%\Application Data\*.* >

[2011.03.17 00:33:42 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini

 

< %USERPROFILE%\My Documents\*.* >

[2011.03.20 21:12:43 | 000,000,077 | -HS- | M] () -- C:\Documents and Settings\Vasko1\My Documents\desktop.ini

[2012.03.08 00:38:59 | 005,242,880 | ---- | M] () -- C:\Documents and Settings\Vasko1\My Documents\Locker01.flk

[2012.04.25 16:31:24 | 000,288,768 | -H-- | M] () -- C:\Documents and Settings\Vasko1\My Documents\photothumb.db

[2012.02.11 18:08:45 | 000,432,128 | -HS- | M] () -- C:\Documents and Settings\Vasko1\My Documents\Thumbs.db

 

< %CommonProgramFiles%\*.* >

[2009.06.19 12:12:46 | 001,828,176 | ---- | M] (Skype Technologies) -- C:\Program Files\Common Files\Skype4COM.dll

 

< %PROGRAMFILES%\*.* >

 

< %systemroot%\system32\config\systemprofile\*.* >

[2011.11.18 12:41:33 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\NtUser.dat

[2012.05.12 13:11:51 | 000,001,024 | -H-- | M] () -- C:\WINDOWS\system32\config\systemprofile\NtUser.dat.LOG

 

< %windir%\ServiceProfiles\LocalService\AppData\Local\Temp\*.* >

 

< %windir%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.* >

 

< %windir% emp*.* >

 

< %windir%\system32\*. >

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1025

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1028

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1031

[2011.03.17 00:26:59 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1033

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1037

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1041

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1042

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1054

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\2052

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\3076

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\3com_dmi

[2012.04.21 22:18:33 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Adobe

[2011.04.21 21:46:48 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\appmgmt

[2011.05.22 18:33:09 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\CatRoot

[2012.05.11 18:02:20 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\CatRoot2

[2011.03.16 22:43:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Com

[2012.04.01 15:07:30 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\dhcp

[2012.03.18 19:18:20 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\DirectX

[2012.05.11 18:00:50 | 000,000,000 | RHSD | M] -- C:\WINDOWS\system32\dllcache

[2012.05.08 19:54:57 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\drivers

[2012.02.11 14:33:47 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\DRVSTORE

[2011.03.17 00:30:41 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\en

[2011.05.01 12:40:30 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\en-US

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\export

[2012.04.01 15:07:16 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\GroupPolicy

[2011.03.17 00:27:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ias

[2011.03.17 00:27:33 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\icsxml

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\IME

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\inetsrv

[2011.03.20 21:05:53 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\KB905474

[2011.03.16 23:44:07 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Lang

[2011.09.17 16:47:21 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\LogFiles

[2011.03.16 22:45:41 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Macromed

[2011.03.16 23:00:25 | 000,000,000 | --SD | M] -- C:\WINDOWS\system32\Microsoft

[2011.03.16 22:43:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\MsDtc

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\mui

[2011.03.17 00:30:51 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\npp

[2011.03.16 22:45:11 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\oobe

[2011.03.20 19:08:19 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\PreInstall

[2011.03.17 00:27:51 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ras

[2011.09.19 19:13:14 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ReinstallBackups

[2011.03.16 23:00:26 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Restore

[2011.03.16 23:42:44 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\RTCOM

[2011.03.17 00:31:13 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\scripting

[2011.03.17 00:31:42 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Setup

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ShellExt

[2011.03.20 14:15:51 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\SoftwareDistribution

[2011.05.03 15:02:43 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\spool

[2011.04.30 22:38:05 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\URTTEMP

[2011.03.17 00:31:33 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\usmt

[2012.04.01 15:07:16 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\wbem

[2012.04.01 15:07:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\WindowsPowerShell

[2012.04.01 15:07:16 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\winrm

[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\wins

[2011.03.16 22:49:37 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\xircom

[2012.05.11 18:17:20 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\XPSViewer

 

< %Temp%\smtmp\1\*.* >

 

< %Temp%\smtmp\2\*.* >

 

< %Temp%\smtmp\3\*.* >

 

< %Temp%\smtmp\4\*.* >

 

< %systemroot%\system32\DBBK\*.* /s >

 

< %systemroot%\system32\*.dll /lockedfiles >

[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

 

< %systemroot%\Tasks\*.job /lockedfiles >

 

< %systemroot%\system32\drivers\*.sys /90 >

 

< %systemroot%\system32\drivers\*.sys /lockedfiles >

 

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

[2008.07.06 15:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll

[2003.06.18 17:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\mdippr.dll

 

< %systemroot%\*. /rp /s >

 

< %systemroot%\assembly mp\*.* /S /MD5 >

 

< %systemroot%\assembly emp\*.* /S /MD5 >

 

< %systemroot%\assembly\GAC_32\*.* /S /MD5 >

[2012.05.11 18:13:41 | 000,069,120 | ---- | M] () MD5=DC426A365577F27187F99EB506ECD5D1 -- C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll

[2012.05.11 18:13:44 | 000,072,192 | ---- | M] () MD5=29B35A999E341A37BE67771BE01CC275 -- C:\WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll

[2011.10.26 18:51:12 | 000,136,624 | ---- | M] () MD5=F8330DA53EA42B4080EBBA5D20E40F66 -- C:\WINDOWS\assembly\GAC_32\Microsoft.Office.Access.BusinessDataCatalog\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Access.BusinessDataCatalog.DLL

[2011.11.30 01:57:21 | 000,964,480 | ---- | M] () MD5=408A13B0A1F61FFBA355AFDE05ADBBCA -- C:\WINDOWS\assembly\GAC_32\Microsoft.Office.BusinessData\14.0.0.0__71e9bce111e9429c\microsoft.office.businessdata.dll

[2011.10.26 18:50:32 | 000,120,744 | ---- | M] () MD5=F7EB7A8AE50075F53819BA22599B3A2E -- C:\WINDOWS\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll

[2011.11.30 01:57:20 | 000,518,016 | ---- | M] () MD5=4C0D1677B819E9D29F5E0B5B0427E41A -- C:\WINDOWS\assembly\GAC_32\Microsoft.SharePoint.BusinessData.Administration.Client\14.0.0.0__71e9bce111e9429c\Microsoft.SharePoint.BusinessData.Administration.Client.dll

[2011.05.03 15:02:56 | 000,163,840 | ---- | M] () MD5=36BDD82A92AA704034475C2DEF7FBD29 -- C:\WINDOWS\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll

[2011.10.26 18:51:26 | 000,370,608 | ---- | M] () MD5=99D8B5B9A5D631608242BAA23249B2E1 -- C:\WINDOWS\assembly\GAC_32\Microsoft.VisualStudio.Tools.Applications.InteropAdapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.InteropAdapter.dll

[2012.05.11 18:13:42 | 000,066,728 | ---- | M] () MD5=C01B81BB10AD14DBC5C4ECD350638096 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\big5.nlp

[2012.05.11 18:13:42 | 000,082,172 | ---- | M] () MD5=EE1F60F8774D74BED8B13498F3FE737A -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bopomofo.nlp

[2012.05.11 18:13:42 | 000,116,756 | ---- | M] () MD5=F6DFDA5A31162D848634504565F6D321 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\ksc.nlp

[2012.05.11 18:13:41 | 004,550,656 | ---- | M] () MD5=3BDAE07DA44654FA393A2A2BA242EA41 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll

[2012.05.11 18:13:42 | 000,059,342 | ---- | M] () MD5=DA5748A89E22A3932387E65694B25BBB -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normidna.nlp

[2012.05.11 18:13:42 | 000,045,794 | ---- | M] () MD5=3831A5E217D6FA828CCE1011DA26E677 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfc.nlp

[2012.05.11 18:13:42 | 000,039,284 | ---- | M] () MD5=DBDE664E0BA4BACD0A6A04AE2232B205 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfd.nlp

[2012.05.11 18:13:42 | 000,066,384 | ---- | M] () MD5=C9B88B759FE81D59CE8EBF5A0A8EB75A -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfkc.nlp

[2012.05.11 18:13:42 | 000,060,294 | ---- | M] () MD5=3CAB6AB66759FCDF73B61EE262C9ACF4 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfkd.nlp

[2012.05.11 18:13:42 | 000,083,748 | ---- | M] () MD5=54144F43EDF5AA8F504A30E7C1D1A7B5 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\prc.nlp

[2012.05.11 18:13:42 | 000,083,748 | ---- | M] () MD5=901863C68E6523336CAC602FE9320ABC -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\prcp.nlp

[2012.05.11 18:13:42 | 000,262,148 | ---- | M] () MD5=FB59D247F7143C3B9683A547E808A88B -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp

[2012.05.11 18:13:42 | 000,020,320 | ---- | M] () MD5=FF13BA175F0013D2311827E0D438C60B -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp

[2012.05.11 18:13:42 | 000,028,288 | ---- | M] () MD5=09E420F90A329BDA68477FA4AF43CB28 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\xjis.nlp

[2012.05.11 18:07:38 | 004,214,784 | ---- | M] () MD5=E0EB0BDC866E2C0CC792B83BD2422501 -- C:\WINDOWS\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll

[2012.05.11 18:13:33 | 000,486,400 | ---- | M] () MD5=759FD3779911F89C450CCAE06B92AE3A -- C:\WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll

[2012.05.11 18:13:47 | 002,933,248 | ---- | M] () MD5=16F96C1496CBD0965285AB19A9271D02 -- C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll

[2012.05.11 18:13:40 | 000,258,048 | ---- | M] () MD5=9631B15DB7C43C267636FF43C3075E07 -- C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll

[2012.05.11 18:13:40 | 000,113,664 | ---- | M] () MD5=E786C33D35D39C5CCB523AECC18D7BD7 -- C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll

[2012.05.11 18:07:46 | 000,368,640 | ---- | M] () MD5=E915933B0E68B61A6AC22E06BD1AD651 -- C:\WINDOWS\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll

[2012.05.11 18:13:38 | 000,261,632 | ---- | M] () MD5=F054572A92573CA32D5F3AA8C15D2BAC -- C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll

[2012.05.11 18:13:32 | 005,246,976 | ---- | M] () MD5=661268A6BEEF1C1B0D1B9137F530A9FD -- C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll

[2011.12.14 01:22:45 | 000,045,304 | ---- | M] () MD5=723130DF7BBCA7FC4BFB1F829ABD13B3 -- C:\WINDOWS\assembly\GAC_32\Update\1.1.3.0__318d21d4b0463a3b\Update.exe

 

< %systemroot%\assembly\GAC_MSIL\*.* /S /MD5 >

[2012.05.11 18:13:41 | 000,010,752 | ---- | M] () MD5=A5A56B4957BD59D324821522FE14F751 -- C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll

[2012.05.11 18:13:34 | 000,507,904 | ---- | M] () MD5=B8FE2350B2236EE3D1CECA34E0C0FF17 -- C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll

[2012.05.11 18:13:41 | 000,013,312 | ---- | M] () MD5=107F49F1BF0FB27A6CD758EB8C4D95A0 -- C:\WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll

[2012.05.11 18:13:45 | 000,008,192 | ---- | M] () MD5=6CD7461E06CB8BAEE3B16C3D7F637CD0 -- C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll

[2012.05.11 18:13:44 | 000,077,824 | ---- | M] () MD5=24F0385D06BD86A97412B8905483313E -- C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll

[2012.05.11 18:13:43 | 000,006,656 | ---- | M] () MD5=11F3AC2D47E566615819F5BF0DD18379 -- C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll

[2011.12.14 01:22:45 | 000,126,976 | ---- | M] () MD5=2613734670B491BE45410D496CEF7FA8 -- C:\WINDOWS\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__ffdc4657f9a00288\Interop.SHDocVw.dll

[2011.10.26 18:50:32 | 000,030,608 | ---- | M] () MD5=D347C753E1BDECF73DEE86D3104529A7 -- C:\WINDOWS\assembly\GAC_MSIL\ipdmctrl\11.0.0.0__71e9bce111e9429c\IPDMCTRL.DLL

[2012.04.01 15:07:37 | 000,007,168 | ---- | M] () MD5=75C183E262BD4400EB0F20349F6EF383 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.BackgroundIntelligentTransfer.Management.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.BackgroundIntelligentTransfer.Management.resources.dll

[2012.04.01 15:07:36 | 000,057,344 | ---- | M] () MD5=2F7FE3A781BA8C0A67C775F20E3E9F70 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.BackgroundIntelligentTransfer.Management\1.0.0.0__31bf3856ad364e35\Microsoft.BackgroundIntelligentTransfer.Management.dll

[2011.05.03 15:03:38 | 000,106,496 | ---- | M] () MD5=29CED3B606BA7E2B49E52931C5CB53B7 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Conversion.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Conversion.v3.5.dll

[2012.05.11 18:13:43 | 000,348,160 | ---- | M] () MD5=996AAEEC01C734347DE8A72542FD1C12 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll

[2011.05.03 15:03:39 | 000,733,184 | ---- | M] () MD5=31C6E94759BF4D2FBE3239FFA717967D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll

[2012.05.11 18:13:43 | 000,036,864 | ---- | M] () MD5=D2A1C3150E43738BAB3D0AD9921B3E50 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll

[2011.05.03 15:03:39 | 000,036,864 | ---- | M] () MD5=17C6F3F73858732DE59D6D957958E9AF -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll

[2011.05.03 15:03:39 | 000,802,816 | ---- | M] () MD5=37F17D4698086C90127BBD90E73D7FE2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v3.5.dll

[2012.05.11 18:13:43 | 000,655,360 | ---- | M] () MD5=8A3F5B72C3F402C8D33027A4C77F55AC -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll

[2011.05.03 15:03:39 | 000,094,208 | ---- | M] () MD5=E32A06F647517D0DEA80F29B459E8FA2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v3.5.dll

[2012.05.11 18:13:44 | 000,077,824 | ---- | M] () MD5=640BF6BB259B53BEFF59135645C63B18 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll

[2011.10.26 18:51:19 | 000,116,632 | ---- | M] () MD5=668818ADBB2240C42567907FC1044E6E -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.BusinessData\14.0.0.0__71e9bce111e9429c\Microsoft.BusinessData.dll

[2012.05.11 18:13:37 | 000,749,568 | ---- | M] () MD5=EB535D00C508119EEE4042B737165A3B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll

[2011.10.26 18:50:41 | 000,096,128 | ---- | M] () MD5=94A1986FF31DADBE7ED939AE8C09B77A -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.Diagnostics\14.0.0.0__71e9bce111e9429c\microsoft.office.businessapplications.diagnostics.dll

[2011.10.26 18:47:48 | 000,023,408 | ---- | M] () MD5=9073098C8053F437E010941E6BDCE1FD -- C:\WINDOWS\assembly\GAC_MSIL\microsoft.office.businessapplications.runtime.intl.resources\14.0.0.0_bg_71e9bce111e9429c\Microsoft.Office.BusinessApplications.Runtime.intl.resources.dll

[2011.10.26 18:51:43 | 000,018,304 | ---- | M] () MD5=43D271F04CBA9737B85CB230930034A6 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.Runtime.Intl\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.Runtime.Intl.dll

[2011.11.30 01:57:13 | 000,567,168 | ---- | M] () MD5=09A2E0159EC7A49B3D4D38BAA06A7FC3 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.Runtime\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.Runtime.dll

[2011.10.26 18:47:48 | 000,055,152 | ---- | M] () MD5=C8F38CE5A181C03A788B903D315DBFF2 -- C:\WINDOWS\assembly\GAC_MSIL\microsoft.office.businessapplications.runtimeui.intl.resources\14.0.0.0_bg_71e9bce111e9429c\Microsoft.Office.BusinessApplications.RuntimeUi.intl.resources.dll

[2011.10.26 18:51:46 | 000,079,744 | ---- | M] () MD5=9C984C911F3F7EB43F1CAD0A046434A2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.RuntimeUi.Intl\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.RuntimeUi.Intl.dll

[2011.10.26 18:50:43 | 000,665,472 | ---- | M] () MD5=CE223A1E43DD5E16F70E9252C39741C2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.RuntimeUi\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.RuntimeUi.dll

[2011.10.26 18:47:48 | 000,067,440 | ---- | M] () MD5=B19E8513537F049BEAE990233F990D80 -- C:\WINDOWS\assembly\GAC_MSIL\microsoft.office.businessapplications.syncservices.intl.resources\14.0.0.0_bg_71e9bce111e9429c\Microsoft.Office.BusinessApplications.SyncServices.Intl.Resources.dll

[2011.10.26 18:51:46 | 000,051,072 | ---- | M] () MD5=150C4A73D0BF82623ABF8E42280EBDFC -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.SyncServices.Intl\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.SyncServices.Intl.dll

[2011.11.30 01:57:13 | 001,689,472 | ---- | M] () MD5=E2AF2BAA129BD7DE59E756CD759D779F -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.SyncServices\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.SyncServices.dll

[2011.10.26 18:51:43 | 000,051,072 | ---- | M] () MD5=0810C44901F6BE8B07C6CB4010E0DB4D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.Tools.AutoGen\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.Tools.AutoGen.dll

[2011.11.30 01:57:14 | 000,169,856 | ---- | M] () MD5=AEDDE69A63A53B38310D2DDECDA831A7 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.Tools.Intl\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.Tools.Intl.dll

[2011.11.30 01:57:14 | 000,427,904 | ---- | M] () MD5=A0FF9B104263F7E54C022D37D578938C -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.Tools\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.Tools.dll

[2011.10.26 18:47:48 | 000,268,144 | ---- | M] () MD5=DBBC2A2194043A6C7E97696F3E2B3A0E -- C:\WINDOWS\assembly\GAC_MSIL\microsoft.office.businessdata.intl.resources\14.0.0.0_bg_71e9bce111e9429c\Microsoft.Office.BusinessData.Intl.Resources.dll

[2011.10.26 18:50:41 | 000,206,720 | ---- | M] () MD5=ADDDFB6CE545CF14FA57039B75C22589 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessData.Intl\14.0.0.0__71e9bce111e9429c\microsoft.office.businessdata.intl.dll

[2011.10.26 18:51:35 | 000,546,704 | ---- | M] () MD5=4210A244E3FC04751F24E27CCDF33B36 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll

[2011.10.26 18:50:32 | 000,042,880 | ---- | M] () MD5=3B161FBED7099618C08AA69B6D8B14D0 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.FormControl\14.0.0.0__71e9bce111e9429c\microsoft.office.infopath.formcontrol.dll

[2011.10.26 18:51:35 | 000,014,224 | ---- | M] () MD5=BFAC08A7315492592B3F528018BC8713 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Permission\14.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Permission.dll

[2011.10.26 18:51:38 | 000,034,680 | ---- | M] () MD5=046E63D3804F5AA2A54211727E1A8886 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Vsta\14.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Vsta.dll

[2011.10.26 18:51:35 | 000,059,248 | ---- | M] () MD5=AC59BB0E798D654A403632D2512F668B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.dll

[2011.10.26 18:51:12 | 000,079,744 | ---- | M] () MD5=BB39161455A053800391C52840FC010A -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Access.Dao\14.0.0.0__71e9bce111e9429c\Microsoft.Office.interop.access.dao.dll

[2011.11.30 01:57:10 | 001,857,400 | ---- | M] () MD5=E068F5F2FEAB127A11451C028CF157AE -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Access\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Access.dll

[2011.10.26 18:50:22 | 001,550,200 | ---- | M] () MD5=79A6278FF98538E5F3E51D8A01C246E5 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Excel\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll

[2011.10.26 18:50:26 | 000,149,368 | ---- | M] () MD5=EB2CFA115D1D16117F7EF8A253EF53DC -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Graph\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll

[2011.10.26 18:50:31 | 000,407,440 | ---- | M] () MD5=3862D60F6AE28C9AE434BFB5FEFBD98C -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.InfoPath.SemiTrust\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.SemiTrust.dll

[2011.10.26 18:51:38 | 000,087,936 | ---- | M] () MD5=EB10E40E824FA29F56C2B2FB17853116 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.InfoPath.Xml\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.Xml.dll

[2011.10.26 18:51:35 | 000,161,656 | ---- | M] () MD5=388D4284E3050DC447E57C0400F015BB -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.InfoPath\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.dll

[2011.10.26 18:51:58 | 000,016,248 | ---- | M] () MD5=C41AE505E62434EB08F42EBEC6DBEB2C -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.OneNote\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OneNote.dll

[2011.10.26 18:50:56 | 000,046,968 | ---- | M] () MD5=8318FE8E736EA06662275CB6E53F488E -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.OneNote\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OneNote.dll

[2011.10.26 18:52:00 | 000,972,664 | ---- | M] () MD5=D56157EC631B91BB9E439FDC597F0E36 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Outlook\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll

[2011.10.26 18:50:54 | 000,025,480 | ---- | M] () MD5=BE021CFEEE55BA6E1147451A259F098C -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.OutlookViewCtl\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll

[2011.10.26 18:52:02 | 000,386,944 | ---- | M] () MD5=114882E8C607D45E4769CFFC931CF5BF -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.PowerPoint\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll

[2011.10.26 18:52:03 | 000,247,680 | ---- | M] () MD5=3796C003FA4D78FB569967A5E3F9325B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Publisher\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Publisher.dll

[2011.10.26 18:50:47 | 000,019,320 | ---- | M] () MD5=370BA1A9D8155AD569F79283E91888B8 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.SmartTag\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll

[2011.10.26 18:52:07 | 000,907,120 | ---- | M] () MD5=386CC49F35BE2A90E2E3339619102BF3 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Word\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll

[2011.10.26 18:50:23 | 000,356,352 | ---- | M] () MD5=0A8FCA67378EC92E2F304E6750DD9FD1 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Tools.Common.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Common.v9.0.dll

[2011.10.26 18:50:23 | 000,438,272 | ---- | M] () MD5=409B1D3ED9ECAAB3D7DA66A83E1161A9 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Tools.Excel.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Excel.v9.0.dll

[2011.10.26 18:51:25 | 000,077,824 | ---- | M] () MD5=41D096C3E61378485D7B8AAFF00C245D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Tools.Outlook.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Outlook.v9.0.dll

[2011.10.26 18:50:48 | 000,094,208 | ---- | M] () MD5=CF53CB86A8D49F5CCA58D8FF8AE246A9 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Tools.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.v9.0.dll

[2011.10.26 18:51:25 | 000,299,008 | ---- | M] () MD5=8447FB78623AACCCFC609F01D1723935 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Tools.Word.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Word.v9.0.dll

[2012.04.01 15:07:37 | 000,010,752 | ---- | M] () MD5=4E2482E69BAAF3A5B13DB8101C063EBF -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.resources.dll

[2012.04.01 15:07:35 | 000,102,400 | ---- | M] () MD5=08E87E8ABF7B41B28663DCE817CE0AB6 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll

[2012.04.01 15:07:36 | 000,036,864 | ---- | M] () MD5=B87E087FC013225E2AA1CB60C080647D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.resources.dll

[2012.04.01 15:07:34 | 000,262,144 | ---- | M] () MD5=F3AC3F844F90380AAB2B4C0836C4288F -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll

[2012.04.01 15:07:36 | 000,049,152 | ---- | M] () MD5=1CE73FB3F88C716CFC3FD550547D2B35 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.resources.dll

[2012.04.01 15:07:34 | 000,618,496 | ---- | M] () MD5=DFEB401CC051E5DA721C584FF6A90F88 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll

[2012.04.01 15:07:36 | 000,040,960 | ---- | M] () MD5=36FF641F37918F2CCA98E7F407AC4D75 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.resources.dll

[2012.04.01 15:07:34 | 000,200,704 | ---- | M] () MD5=3991B7FA452A9C9C291C06365A236792 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll

[2012.04.01 15:07:40 | 000,069,632 | ---- | M] () MD5=37BED865557084DD9988350AB1675E0B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Editor.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Editor.resources.dll

[2012.04.01 15:07:39 | 000,991,232 | ---- | M] () MD5=208FA9D0EBE2CEB9616042772E96598E -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Editor\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Editor.dll

[2012.04.01 15:07:40 | 000,040,960 | ---- | M] () MD5=108500A98B9A2F66823E7615398FC87B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.GPowerShell.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.GPowerShell.resources.dll

[2012.04.01 15:07:40 | 000,651,264 | ---- | M] () MD5=D4EEFCCDC3DE6CED901535FA4153C491 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.GPowerShell\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.GPowerShell.dll

[2012.04.01 15:07:40 | 000,016,896 | ---- | M] () MD5=5A69FB5D686F863E0E13268D671EF16D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.GraphicalHost.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.GraphicalHost.resources.dll

[2012.04.01 15:07:39 | 000,278,528 | ---- | M] () MD5=3EAB4DBDC290EDC4D53FE77F1FDB9E59 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.GraphicalHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.GraphicalHost.dll

[2012.04.01 15:07:36 | 000,009,216 | ---- | M] () MD5=C7A0D1321A67A2AFD330C5FBE79BEFD1 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Security.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Security.resources.dll

[2012.04.01 15:07:35 | 000,069,632 | ---- | M] () MD5=53A9D748EF09920A0D06DA2583C298AD -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll

[2011.10.26 18:51:43 | 000,206,720 | ---- | M] () MD5=B1B0C658E5E2DEE8273A8667D5CAB7E0 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.SharePoint.BusinessData.Administration.Client.Intl\14.0.0.0__71e9bce111e9429c\Microsoft.SharePoint.BusinessData.Administration.Client.Intl.dll

[2011.10.26 18:50:26 | 000,115,744 | ---- | M] () MD5=DA5EE020BEF41DC95C3532CBAA1EA8F4 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Synchronization.Data.Server\1.0.0.0__89845dcd8080cc91\Microsoft.Synchronization.Data.Server.dll

[2011.10.26 18:51:29 | 000,095,312 | ---- | M] () MD5=5C8089FDA655A38440F279DEB7925C46 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Synchronization.Data.SqlServerCe\3.5.0.0__89845dcd8080cc91\Microsoft.Synchronization.Data.SqlServerCe.dll

[2011.10.26 18:51:28 | 000,115,744 | ---- | M] () MD5=01B68622F7B4A699D52F9A0B5EA5E4EC -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Synchronization.Data\1.0.0.0__89845dcd8080cc91\Microsoft.Synchronization.Data.dll

[2011.05.03 15:02:55 | 000,397,312 | ---- | M] () MD5=66F6B3248D6C39CEFA49174133A694FE -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll

[2011.10.26 18:50:25 | 000,374,640 | ---- | M] () MD5=786BABFD5E40B254EE46F3EEE81C36F4 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll

[2011.10.26 18:51:08 | 000,063,336 | ---- | M] () MD5=572E69066CE577FBF849E8D715CE0B82 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vbe.Interop\14.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll

[2012.05.11 18:13:37 | 000,110,592 | ---- | M] () MD5=D676BC7C829F86A215676281A1032C6B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll

[2012.05.11 18:13:39 | 000,372,736 | ---- | M] () MD5=226956F70AEBBBF5ACBC9ADA6522B6F6 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll

[2012.05.11 18:13:44 | 000,028,672 | ---- | M] () MD5=3D61BFCBE13C2DC8F5AE20BF02145322 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll

[2012.05.11 18:13:39 | 000,659,456 | ---- | M] () MD5=EFC806A1C4C6CE9F69AECE0AB72C1E34 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll

[2011.05.03 15:03:38 | 000,041,984 | ---- | M] () MD5=9F065BF574C956B85DB355C32E7E995E -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\1.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.STLCLR.dll

[2012.05.11 18:13:42 | 000,005,632 | ---- | M] () MD5=7E50D25F9A5BC75F22CA7AEB52176CA2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll

[2011.10.26 18:51:26 | 000,286,720 | ---- | M] () MD5=F0DA890A63403E2010788FDBC1801FA7 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.dll

[2011.10.26 18:51:26 | 000,210,848 | ---- | M] () MD5=2E57C4C703D80B484CDDE2C13BA27BF1 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Adapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Adapter.dll

[2011.11.30 01:57:11 | 000,041,408 | ---- | M] () MD5=01740C30C6063A7E942EA6330E88DAC6 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.dll

[2011.10.26 18:51:47 | 000,045,056 | ---- | M] () MD5=8510E5F664F1C9136E73A13B0C8E5357 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.dll

[2011.10.26 18:50:24 | 000,104,368 | ---- | M] () MD5=9C7403906909E432EA6A2511D1B3CDF2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInManager\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInManager.dll

[2011.10.26 18:51:26 | 000,329,632 | ---- | M] () MD5=5DDDB6F96BF41B9FE9C4AB0920A0E445 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Blueprints\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Blueprints.dll

[2011.10.26 18:51:26 | 000,038,832 | ---- | M] () MD5=CC5ECB09FFDD2A7915E3E98A15DF262E -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.dll

[2011.11.30 01:57:10 | 000,024,496 | ---- | M] () MD5=ABE26CE56EAA14ABF51E6BA779A3984E -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.dll

[2011.10.26 18:51:24 | 000,022,016 | ---- | M] () MD5=6581FE75715D9D6FF9BFD2264F825FB0 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.dll

[2011.10.26 18:50:24 | 000,038,808 | ---- | M] () MD5=907114FE32F4DFB0C5EDA360BE0740C7 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Contract\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Contract.dll

[2011.10.26 18:50:23 | 000,071,592 | ---- | M] () MD5=5949DF7B1BF7951C55A31803CD4DC6E2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.DesignTime\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.DesignTime.dll

[2011.11.30 01:57:14 | 000,035,256 | ---- | M] () MD5=9BF071EFED4CEBB1B03FDE7942E0BE80 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.dll

[2011.11.30 01:57:11 | 000,153,008 | ---- | M] () MD5=8EDF67A0526AC03E4EAFDB062AC273B8 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.dll

[2011.10.26 18:50:24 | 000,143,360 | ---- | M] () MD5=BF1B6B22209E8126A184BFA2C4FB49BE -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.dll

[2011.11.30 01:57:14 | 000,032,688 | ---- | M] () MD5=46E3223333A8DD1684B7639F42D9584D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll

[2011.10.26 18:51:47 | 000,077,824 | ---- | M] () MD5=DC553264A749613C331C8B989A1A9B2A -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.dll

[2011.11.30 01:57:10 | 000,193,472 | ---- | M] () MD5=066BB2ABAA5C8E45ED37E691355B5185 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.dll

[2011.10.26 18:50:47 | 000,110,592 | ---- | M] () MD5=3A717D3B1B2F5921871B0561E71DD4D8 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.dll

[2011.10.26 18:50:44 | 000,081,920 | ---- | M] () MD5=A7278626DFE2AAFDDBA6B8B82AA94CEF -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll

[2011.10.26 18:50:24 | 000,131,072 | ---- | M] () MD5=B169C95A3BEFA21EBA58D21992EB6A9C -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.dll

[2011.11.30 01:57:15 | 000,062,392 | ---- | M] () MD5=022AFCC5C5CE34EA13C706AE0A296AD4 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.dll

[2011.11.30 01:57:11 | 000,023,976 | ---- | M] () MD5=CD8C6E27F96A8A8A894F78B1512C188A -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Contract.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.dll

[2011.10.26 18:50:23 | 000,049,152 | ---- | M] () MD5=77249A017C234EC21BC60DABB8515896 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Contract.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.dll

[2011.10.26 18:50:44 | 000,036,864 | ---- | M] () MD5=AD54FE98130FA82E5A75A1906F7F14A9 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.dll

[2011.10.26 18:50:44 | 000,053,248 | ---- | M] () MD5=07E7E7818586A3B3F1EC50E5E2511FC0 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.dll

[2011.11.30 01:57:11 | 000,077,752 | ---- | M] () MD5=F8EA342008DD949F1706FCAAC0E07FE7 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.dll

[2011.11.30 01:57:15 | 000,063,408 | ---- | M] () MD5=DDD9726B8F5801145DDCE84FA40916C3 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.dll

[2011.11.30 01:57:12 | 000,041,408 | ---- | M] () MD5=3ADC112241D4D0F55EF7EF2EDEAEDC2F -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.dll

[2011.11.30 01:57:12 | 000,363,936 | ---- | M] () MD5=F17156AE7E7696601B3221090AB9D20F -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.dll

[2011.10.26 18:51:48 | 000,036,864 | ---- | M] () MD5=0C5700ED83D92BBB5E6F70AB89C26F04 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.dll

[2011.10.26 18:51:48 | 000,065,536 | ---- | M] () MD5=4167FAFE231BE780D7158B0A7E5D337D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.dll

[2011.11.30 01:57:12 | 000,083,896 | ---- | M] () MD5=145C93E147C9C5F809E2E1D398C4C5E4 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.dll

[2012.05.11 18:13:45 | 000,012,800 | ---- | M] () MD5=B27AA2EA41728FAF5E9642CFD2958FB9 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll

[2012.05.11 18:13:39 | 000,032,768 | ---- | M] () MD5=D251A67B7D6DE2194F6E264055E020FB -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll

[2011.10.23 23:12:24 | 000,884,736 | ---- | M] () MD5=E42998E3BB92E6696A82EF796EFAC507 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Web.Services3\3.0.0.0__31bf3856ad364e35\Microsoft.Web.Services3.dll

[2012.04.01 15:07:37 | 000,013,824 | ---- | M] () MD5=6372EA7D2ACED7185183CF3FCDD3577B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.WSMan.Management.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll

[2012.04.01 15:07:35 | 000,274,432 | ---- | M] () MD5=1A4E900C2FE3CD31D10107670D184FE6 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll

[2012.04.01 15:07:35 | 000,007,168 | ---- | M] () MD5=F7DA27672D2E4C21A1F996EE31DE0DBF -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll

[2012.05.11 18:13:37 | 000,007,168 | ---- | M] () MD5=9659028AFA77387D6D2BF4280C10AB94 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll

[2011.10.26 18:51:57 | 000,448,360 | ---- | M] () MD5=6E84AAA11121D806DADC159CED3E3DDA -- C:\WINDOWS\assembly\GAC_MSIL\office\14.0.0.0__71e9bce111e9429c\OFFICE.DLL

[2011.11.30 01:57:10 | 000,000,900 | ---- | M] () MD5=3B7B0D23927E9331354BFD0DFA09910F -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Access\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Access.config

[2011.11.30 01:57:10 | 000,011,656 | ---- | M] () MD5=7E982B4F2EDEE4C8FBDA3F28DB13940E -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Access\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Access.dll

[2011.10.26 18:50:22 | 000,000,898 | ---- | M] () MD5=E3C1C0D2C327FEC85FB9857E3F899785 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Excel\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.config

[2011.10.26 18:51:24 | 000,011,656 | ---- | M] () MD5=7EAF6D9700040029FA01375A920B521F -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Excel\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll

[2011.10.26 18:50:27 | 000,000,898 | ---- | M] () MD5=10615D207C75102FC721755BB0B3CD8E -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Graph\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.config

[2011.10.26 18:51:30 | 000,011,656 | ---- | M] () MD5=7E9ABF813463163E3575E5C92BE71A8D -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Graph\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll

[2011.10.26 18:50:36 | 000,000,912 | ---- | M] () MD5=E3EFA5C36AB83B5E678ED1CADE23B412 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.config

[2011.10.26 18:51:40 | 000,011,664 | ---- | M] () MD5=9E8528A64196AA99876B3034F312CC98 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.dll

[2011.10.26 18:51:38 | 000,000,904 | ---- | M] () MD5=DCADD75D7AF7337A635A78D7C7F20D9A -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.InfoPath\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.config

[2011.10.26 18:50:36 | 000,011,664 | ---- | M] () MD5=3A7A2A7C91F9F50D000F593810A5618C -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.InfoPath\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.dll

[2011.10.26 18:52:00 | 000,000,902 | ---- | M] () MD5=6294F9D1634C5110426C7DAFE2F685A0 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Outlook\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Outlook.config

[2011.10.26 18:50:59 | 000,011,656 | ---- | M] () MD5=AF6DCC105912C2A9D514D8941F1F3339 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Outlook\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Outlook.dll

[2011.10.26 18:50:54 | 000,000,916 | ---- | M] () MD5=333236C30617B03AE650230780E21EAA -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.config

[2011.10.26 18:51:58 | 000,011,672 | ---- | M] () MD5=A1B80AAF87F8EBC0DF0857BCDF48F4BC -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll

[2011.10.26 18:52:03 | 000,000,908 | ---- | M] () MD5=EC791B712B81C85372E03A0617D24BF7 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.PowerPoint\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.config

[2011.10.26 18:51:01 | 000,011,664 | ---- | M] () MD5=C8239B3E66BDB63D8A1938FE7B4DCE20 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.PowerPoint\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll

[2011.10.26 18:52:03 | 000,000,906 | ---- | M] () MD5=449F5367C27EBC6CB917460F0DE2B0CB -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Publisher\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Publisher.config

[2011.10.26 18:51:02 | 000,011,664 | ---- | M] () MD5=7511DBE6D0B0EA4B0383F137AEC72D55 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Publisher\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Publisher.dll

[2011.10.26 18:50:47 | 000,000,904 | ---- | M] () MD5=4F7AB727B60621BB36E47B682F4BFE23 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.SmartTag\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.config

[2011.10.26 18:51:55 | 000,011,664 | ---- | M] () MD5=9883D76E2777A0FF724BB34C4F47C80F -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.SmartTag\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll

[2011.10.26 18:52:08 | 000,000,896 | ---- | M] () MD5=C018AC4E3EFFBFF5ABB8E5D9608A8762 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Word\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.config

[2011.10.26 18:51:09 | 000,011,656 | ---- | M] () MD5=2BD0AF3F15E24A3B97E4453357BCAD3E -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Word\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll

[2011.10.26 18:51:08 | 000,000,880 | ---- | M] () MD5=6CF29BFDC5FA7B2FE06AE04FA0DDB1B2 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Vbe.Interop\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.config

[2011.10.26 18:52:06 | 000,011,640 | ---- | M] () MD5=96A8D791500D842A026A2A32BDC7BCA6 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Vbe.Interop\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll

[2011.10.26 18:51:57 | 000,000,850 | ---- | M] () MD5=8E5E41526B4BF8D28A10C54D04D04866 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.office\14.0.0.0__71e9bce111e9429c\Policy.11.0.office.config

[2011.10.26 18:50:52 | 000,011,104 | ---- | M] () MD5=BBF1A582F1C6155590108B38C8075759 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.office\14.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll

[2011.10.26 18:50:32 | 000,000,930 | ---- | M] () MD5=F3BFE3718EC61BEB4EEF7180EC9E2F66 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath.Client.Internal.Host\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.Client.Internal.Host.config

[2011.10.26 18:51:35 | 000,011,664 | ---- | M] () MD5=975E7224274D8EA867067B752EFF87D1 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath.Client.Internal.Host\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.Client.Internal.Host.dll

[2011.10.26 18:50:32 | 000,000,912 | ---- | M] () MD5=8178E3FB89E1EE2F91F678D5E13367BF -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath.FormControl\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.FormControl.config

[2011.10.26 18:51:35 | 000,011,664 | ---- | M] () MD5=927BCDEC2365C4CAEB00B60AC689507D -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath.FormControl\14.0.0.0__71e9bce111e9429c\policy.12.0.Microsoft.Office.InfoPath.FormControl.dll

[2011.10.26 18:50:36 | 000,000,910 | ---- | M] () MD5=1D48EED186B3272682634155C17AAB1E -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath.Permission\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.Permission.config

[2011.10.26 18:51:38 | 000,011,664 | ---- | M] () MD5=78E3D657EA7770BD031C6619536DE2A4 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath.Permission\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.Permission.dll

[2011.10.26 18:51:38 | 000,000,888 | ---- | M] () MD5=66DFFED0DCD33FFAA9295DA912CC237C -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.config

[2011.10.26 18:50:36 | 000,011,664 | ---- | M] () MD5=651C9951412B3441ABE5BE9ADE9E2DB4 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.dll

[2011.10.26 18:51:13 | 000,000,908 | ---- | M] () MD5=8A9FDA784C76AEBFCC8266727C31A77D -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Access.Dao\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Access.Dao.config

[2011.10.26 18:50:13 | 000,011,664 | ---- | M] () MD5=1AD4166C04970B0F4C69A3E7DDC3CC2D -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Access.Dao\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Access.Dao.dll

[2011.11.30 01:57:09 | 000,000,900 | ---- | M] () MD5=6E5E053BA637800ECBBCCDBB3C046104 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Access\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Access.config

[2011.11.30 01:57:09 | 000,011,656 | ---- | M] () MD5=F0CD5F9618DED7E0F612DD8F94494CD3 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Access\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Access.dll

[2011.10.26 18:51:11 | 000,000,898 | ---- | M] () MD5=E0CE8837AA281AE2C19739274386F0C1 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Excel\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Excel.config

[2011.10.26 18:52:10 | 000,011,656 | ---- | M] () MD5=0660718DE1A3740CD87109BE1BEEC730 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Excel\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Excel.dll

[2011.10.26 18:50:26 | 000,000,898 | ---- | M] () MD5=3D00C53C80C2B84B5D948F41D1A58469 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Graph\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Graph.config

[2011.10.26 18:51:30 | 000,011,656 | ---- | M] () MD5=A5B6A68F5F4075BBCBC287C371972FC2 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Graph\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Graph.dll

[2011.10.26 18:50:36 | 000,000,912 | ---- | M] () MD5=A581EAC28DAEEB75339122F5C9015AD6 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.InfoPath.Xml\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.InfoPath.Xml.config

[2011.10.26 18:51:41 | 000,011,664 | ---- | M] () MD5=5B54654ECD53D7100802002B179EEA6D -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.InfoPath.Xml\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.InfoPath.Xml.dll

[2011.10.26 18:51:38 | 000,000,904 | ---- | M] () MD5=544EA0940AABB6C6C918CDF6563783CF -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.InfoPath\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.InfoPath.config

[2011.10.26 18:50:36 | 000,011,664 | ---- | M] () MD5=AF24B14845D68C24D756C4AD57BB1770 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.InfoPath\14.0.0.0__71e9bce111e9429c\policy.12.0.Microsoft.Office.Interop.InfoPath.dll

[2011.10.26 18:52:00 | 000,000,902 | ---- | M] () MD5=44193BB603AD240A860033F7EFC2E7E8 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Outlook\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Outlook.config

[2011.10.26 18:50:59 | 000,011,656 | ---- | M] () MD5=027FA86FD3041FE291464465FCDB337E -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Outlook\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Outlook.dll

[2011.10.26 18:50:52 | 000,000,916 | ---- | M] () MD5=30336C1CC94EDD19CDFB724E3A5AF015 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.OutlookViewCtl\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.OutlookViewCtl.config

[2011.10.26 18:51:57 | 000,011,672 | ---- | M] () MD5=ECC242CB7160EEB8E1885E200449F65E -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.OutlookViewCtl\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.OutlookViewCtl.dll

[2011.10.26 18:52:02 | 000,000,908 | ---- | M] () MD5=8199AE1C79C0443071D0352D70CE4DAA -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.PowerPoint\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.PowerPoint.config

[2011.10.26 18:51:01 | 000,011,664 | ---- | M] () MD5=A611CBFFCAA65D8BF465A15F9693679F -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.PowerPoint\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.PowerPoint.dll

[2011.10.26 18:52:03 | 000,000,906 | ---- | M] () MD5=8C6C64A729444CD2E32FC753D71DB76C -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Publisher\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Publisher.config

[2011.10.26 18:51:02 | 000,011,664 | ---- | M] () MD5=719B94FFCC629739E2AEC68D70F2F77A -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Publisher\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Publisher.dll

[2011.10.26 18:50:47 | 000,000,904 | ---- | M] () MD5=0AFCE67890E647DCADD27A5C0DA495C3 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.SmartTag\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.SmartTag.config

[2011.10.26 18:51:55 | 000,011,664 | ---- | M] () MD5=8D8DBB9C4811EC4255B878D50D06B627 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.SmartTag\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.SmartTag.dll

[2011.10.26 18:52:07 | 000,000,896 | ---- | M] () MD5=F3D871161A09684A2930117D6BDAAF91 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Word\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Word.config

[2011.10.26 18:51:09 | 000,011,656 | ---- | M] () MD5=A7D719DF8AB1D3C9278C279C1D273ACF -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Word\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Word.dll

[2011.10.26 18:51:08 | 000,000,880 | ---- | M] () MD5=C96C6F48979A5F9F131AA9FCB228B0D1 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Vbe.Interop\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Vbe.Interop.config

[2011.10.26 18:52:06 | 000,011,640 | ---- | M] () MD5=AC9E566B2E1EF289B6B44934CA3CB160 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Vbe.Interop\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Vbe.Interop.dll

[2011.10.26 18:51:57 | 000,000,850 | ---- | M] () MD5=E387AFF00A5E533338760D8E78ED8AFB -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.office\14.0.0.0__71e9bce111e9429c\Policy.12.0.office.config

[2011.10.26 18:50:52 | 000,011,104 | ---- | M] () MD5=36E29C6106F087A16A45EEA7E044C3D1 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.office\14.0.0.0__71e9bce111e9429c\Policy.12.0.Office.dll

[2011.10.26 18:50:22 | 000,000,565 | ---- | M] () MD5=728C41A6BE9A4A809F7E063FFA2F56D1 -- C:\WINDOWS\assembly\GAC_MSIL\policy.3.5.System.Data.SqlServerCe.Entity\3.5.0.0__89845dcd8080cc91\entitypub.config

[2011.10.26 18:51:22 | 000,013,392 | ---- | M] () MD5=8CD049B83846CEB2B5B50CC7DE1DD5DD -- C:\WINDOWS\assembly\GAC_MSIL\policy.3.5.System.Data.SqlServerCe.Entity\3.5.0.0__89845dcd8080cc91\policy.3.5.System.Data.SqlServerCe.Entity.dll

[2011.10.26 18:51:02 | 000,013,392 | ---- | M] () MD5=ECB1B568E8E97CC8BB1F1CA55C942F1F -- C:\WINDOWS\assembly\GAC_MSIL\policy.3.5.System.Data.SqlServerCe\3.5.0.0__89845dcd8080cc91\policy.3.5.System.Data.SqlServerCe.dll

[2011.10.26 18:52:03 | 000,000,558 | ---- | M] () MD5=2D562F88863EDF6FF31D3D374F3A33C2 -- C:\WINDOWS\assembly\GAC_MSIL\policy.3.5.System.Data.SqlServerCe\3.5.0.0__89845dcd8080cc91\publisher.config

[2011.05.03 15:03:02 | 000,598,016 | ---- | M] () MD5=28595FA306E58AACD7DAFF001F430703 -- C:\WINDOWS\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll

[2011.05.03 15:02:59 | 000,032,768 | ---- | M] () MD5=93F9CC2360815D8EF955407CF92B38AA -- C:\WINDOWS\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll

[2011.05.03 15:03:02 | 000,046,104 | ---- | M] () MD5=8BA7C024070F2B7FDD98ED8A4BA41789 -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFontCache\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe

[2011.05.03 15:03:03 | 000,196,608 | ---- | M] () MD5=0C488A21B5A63055CB7736E3E0C75B1F -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll

[2011.05.03 15:03:03 | 000,139,264 | ---- | M] () MD5=DA8417F8973EC51F0F1859CA0B334FC5 -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll

[2011.05.03 15:03:03 | 000,397,312 | ---- | M] () MD5=7E61032F4F2BAB036B859D3B22D26DD0 -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll

[2011.05.03 15:03:03 | 000,163,840 | ---- | M] () MD5=D1E117EDDEFEB220351BE0C7B27A4646 -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll

[2012.05.11 18:07:40 | 005,283,840 | ---- | M] () MD5=2CFE88EE740380F4B594B2DE58AA933D -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll

[2011.05.03 15:03:04 | 000,864,256 | ---- | M] () MD5=428D3714C85BACE55476C91E0D90E495 -- C:\WINDOWS\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll

[2011.12.14 01:22:45 | 000,040,184 | ---- | M] () MD5=5494D46CBE14A5E0644CB219C9AC2FEA -- C:\WINDOWS\assembly\GAC_MSIL\QuickStoresToolbar\1.1.0.0__318d21d4b0463a3b\QuickStoresToolbar.dll

[2012.05.11 18:07:45 | 000,532,480 | ---- | M] () MD5=E785AE3CC6341D63346B5F899B6FE7AC -- C:\WINDOWS\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll

[2011.05.03 15:03:40 | 000,005,632 | ---- | M] () MD5=807B70A78ACE7D01F769FE502A769E67 -- C:\WINDOWS\assembly\GAC_MSIL\Sentinel.v3.5Client\3.5.0.0__b03f5f7f11d50a3a\Sentinel.v3.5Client.dll

[2011.05.04 15:03:57 | 000,110,592 | ---- | M] () MD5=BD6B60E0F4FA84FF4E3089EDF9B81C9A -- C:\WINDOWS\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll

[2012.05.11 18:13:42 | 000,110,592 | ---- | M] () MD5=0AD1C94AB2D36B79B9F2B54EADEB300A -- C:\WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll

[2011.05.03 15:03:40 | 000,045,056 | ---- | M] () MD5=B34B75256D536385B927193FB1DCBB81 -- C:\WINDOWS\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll

[2011.10.26 18:51:27 | 000,038,744 | ---- | M] () MD5=7137B00CD3C6AD6AAAC4D7EE614137D5 -- C:\WINDOWS\assembly\GAC_MSIL\System.AddIn\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.dll

[2012.05.11 18:16:58 | 000,163,840 | ---- | M] () MD5=AA647B387E4086FDE32C8E976732F635 -- C:\WINDOWS\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll

[2011.05.03 15:03:44 | 000,057,344 | ---- | M] () MD5=34AAEA0DCF908A7D3C1D8C2132B0E4D4 -- C:\WINDOWS\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\3.5.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll

[2012.05.11 18:13:45 | 000,081,920 | ---- | M] () MD5=41BC941761FB3D1E21826C3C0E3CEEEE -- C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll

[2012.05.11 18:13:37 | 000,425,984 | ---- | M] () MD5=C1C4025B5F5311AC8BCC318B0C244D58 -- C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll

[2011.05.03 15:03:41 | 000,667,648 | ---- | M] () MD5=6617F24759BB1F3873C88AD9E0DF0435 -- C:\WINDOWS\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll

[2011.05.03 15:03:41 | 000,053,248 | ---- | M] () MD5=1FDC244EEDD9B7804C7829DA11F1522E -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.DataSetExtensions\3.5.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll

[2011.05.03 15:03:41 | 000,229,376 | ---- | M] () MD5=3FE6C3CDB01F039110152B1B0AE4980F -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.Entity.Design\3.5.0.0__b77a5c561934e089\System.Data.Entity.Design.dll

[2011.05.03 15:03:41 | 002,879,488 | ---- | M] () MD5=CB45DFC6F9E1F954A718769D02D9C312 -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.Entity\3.5.0.0__b77a5c561934e089\System.Data.Entity.dll

[2011.05.03 15:03:38 | 000,684,032 | ---- | M] () MD5=DDFB10C4A14ADD5D0A6C96E6DC3D29DF -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.Linq\3.5.0.0__b77a5c561934e089\System.Data.Linq.dll

[2011.05.03 15:06:41 | 000,294,912 | ---- | M] () MD5=2F69FF4ED483D3FF399534F99BD4694A -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll

[2011.05.03 15:03:37 | 000,114,688 | ---- | M] () MD5=0A7F3B1C1A9CC722F48A7A16394F61C4 -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.Services.Design\3.5.0.0__b77a5c561934e089\System.Data.Services.Design.dll

[2011.05.03 15:06:41 | 000,442,368 | ---- | M] () MD5=AE975C122A442146D7D5A6A996C42F91 -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll

[2011.10.26 18:50:26 | 000,230,480 | ---- | M] () MD5=715D600994E95E5F32701BFB012FD749 -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlServerCe.Entity\3.5.1.0__89845dcd8080cc91\System.Data.SqlServerCe.Entity.dll

[2011.10.26 18:51:29 | 000,271,440 | ---- | M] () MD5=51BE126F0D1CBBE278514F779FCDD29A -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlServerCe\3.5.0.0__89845dcd8080cc91\System.Data.SqlServerCe.dll

[2011.10.26 18:51:29 | 000,271,440 | ---- | M] () MD5=156FDE0E85025D180598E8FBD4DB3D23 -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlServerCe\3.5.1.0__89845dcd8080cc91\System.Data.SqlServerCe.dll

[2012.05.11 18:13:47 | 000,745,472 | ---- | M] () MD5=6388F9A7AA6E22DDA2E0D84E5BCE537C -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll

[2012.05.11 18:13:48 | 000,970,752 | ---- | M] () MD5=97DDAFB2A7B33DC3F746EF35C9EDF892 -- C:\WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll

[2012.05.11 18:13:34 | 005,062,656 | ---- | M] () MD5=5C368BEBD58562133856B35BDCEFEADA -- C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll

[2011.05.03 15:03:38 | 000,286,720 | ---- | M] () MD5=4C6FBCBB7E7D4E3B0CAAA42043B6A01F -- C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\3.5.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll

[2012.05.11 18:13:40 | 000,188,416 | ---- | M] () MD5=F0D4CE77F1F9D9A7468335B1CE4C061B -- C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll

[2012.05.11 18:13:40 | 000,401,408 | ---- | M] () MD5=F485CF34C45F850B25A7E38B08A7C435 -- C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll

[2012.05.11 18:13:36 | 000,081,920 | ---- | M] () MD5=36ABC218228871A981027174216A2DA8 -- C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll

[2012.05.11 18:13:46 | 000,630,784 | ---- | M] () MD5=DD110208ACE51F9AAC2FFC949CB6D937 -- C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll

[2011.05.03 15:03:04 | 000,126,976 | ---- | M] () MD5=311A345681A73C66D3EE49C5157A473B -- C:\WINDOWS\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll

[2011.05.04 15:03:58 | 000,438,272 | ---- | M] () MD5=DB076F159D89B90924C465222BA128FE -- C:\WINDOWS\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll

[2011.05.03 15:02:56 | 000,131,072 | ---- | M] () MD5=80E67BFFD101CC6312B489BEE255430D -- C:\WINDOWS\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll

[2012.04.01 15:07:36 | 000,253,952 | ---- | M] () MD5=2286B57ECC2D32D24049C51989084268 -- C:\WINDOWS\assembly\GAC_MSIL\System.Management.Automation.resources\1.0.0.0_en_31bf3856ad364e35\System.Management.Automation.resources.dll

[2012.04.01 15:07:33 | 002,682,880 | ---- | M] () MD5=4D8AB4FAD244F7985D8C59D456E026D7 -- C:\WINDOWS\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll

[2011.05.03 15:03:42 | 000,143,360 | ---- | M] () MD5=217A1E1DED132261C825313A7FB2616C -- C:\WINDOWS\assembly\GAC_MSIL\System.Management.Instrumentation\3.5.0.0__b77a5c561934e089\System.Management.Instrumentation.dll

[2012.05.11 18:13:39 | 000,372,736 | ---- | M] () MD5=EBAADBBFB6C455E54EB6A0E47267D33C -- C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll

[2012.05.11 18:13:38 | 000,258,048 | ---- | M] () MD5=7F9F1F17D368EE1EEA7E246FD934B9EC -- C:\WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll

[2011.05.03 15:03:44 | 000,233,472 | ---- | M] () MD5=2E66DE31546A6AB3A8160CE337E1C6BC -- C:\WINDOWS\assembly\GAC_MSIL\System.Net\3.5.0.0__b03f5f7f11d50a3a\System.Net.dll

[2012.05.11 18:13:38 | 000,303,104 | ---- | M] () MD5=2849F13593D2712CCB97FFBDD3C1232E -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll

[2012.05.11 18:13:38 | 000,131,072 | ---- | M] () MD5=C415D86079D431E7E1E32D0835A3FE81 -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll

[2011.05.04 15:03:58 | 000,970,752 | ---- | M] () MD5=2CF02DF42A90A054D546BF3A85409DC4 -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll

[2012.05.11 18:13:47 | 000,258,048 | ---- | M] () MD5=0DFCD96DED6DB52064203C07B927357E -- C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll

[2011.05.03 15:02:58 | 000,073,728 | ---- | M] () MD5=A80F41C8B2168E8B3ADD0AA4FCBDDC93 -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll

[2011.05.04 15:03:59 | 000,032,768 | ---- | M] () MD5=764E1A3E53C5885976F2EE6E206208EF -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll

[2011.05.03 15:03:37 | 000,569,344 | ---- | M] () MD5=1565B7FAFDFA6EEE16101388E57E749F -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.Web\3.5.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll

[2011.05.04 15:03:58 | 005,967,872 | ---- | M] () MD5=4120A37565491CA998E226BCBE8EF6E8 -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll

[2012.05.11 18:13:48 | 000,114,688 | ---- | M] () MD5=50D2943D426BA91771AD87FDEC802AC3 -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll

[2011.05.03 15:03:02 | 000,688,128 | ---- | M] () MD5=31588B867657A7DF046AC1908550D73C -- C:\WINDOWS\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll

[2011.05.03 15:03:45 | 000,077,824 | ---- | M] () MD5=2C3559C513F7CD6F95DC382F31A6A22D -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Abstractions\3.5.0.0__31bf3856ad364e35\System.Web.Abstractions.dll

[2011.05.03 15:03:45 | 000,032,768 | ---- | M] () MD5=9E0D101B086297D5E166E03A8ACBF260 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.DynamicData.Design\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.Design.dll

[2011.05.03 15:06:42 | 000,229,376 | ---- | M] () MD5=CC8D03C33986926A68696DAAAB5FF2F8 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.DynamicData\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.dll

[2011.05.03 15:03:42 | 000,131,072 | ---- | M] () MD5=A6A5297AAD0A9BA8829D20B1CBD68D32 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Entity.Design\3.5.0.0__b77a5c561934e089\System.Web.Entity.Design.dll

[2011.05.03 15:06:42 | 000,139,264 | ---- | M] () MD5=E42797003722BD930D83AB26998394D8 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Entity\3.5.0.0__b77a5c561934e089\System.Web.Entity.dll

[2011.05.03 15:03:46 | 000,335,872 | ---- | M] () MD5=7E83B8040233DDCDE03CF7F0A5F2837B -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Extensions.Design\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.Design.dll

[2012.01.12 04:06:52 | 001,277,952 | ---- | M] () MD5=821B0AAB24CB11417381F8AE881309A2 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll

[2012.05.11 18:13:33 | 000,835,584 | ---- | M] () MD5=C22D59F4EAC00510D1A86061A428C633 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll

[2012.05.11 18:13:34 | 000,077,824 | ---- | M] () MD5=F27A80887F125661CAC1A6039107428F -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll

[2011.05.03 15:03:46 | 000,061,440 | ---- | M] () MD5=5B7868DF14D71D328EE8C1213F852393 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Routing\3.5.0.0__31bf3856ad364e35\System.Web.Routing.dll

[2012.05.11 18:13:33 | 000,839,680 | ---- | M] () MD5=A89DFA6DB0C3D00559F770A214962A60 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll

[2012.05.11 18:13:35 | 005,025,792 | ---- | M] () MD5=7A3C1F1942074D251CCFA44D4815AD33 -- C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll

[2011.05.03 15:03:43 | 000,012,288 | ---- | M] () MD5=044C3400A836E5FB60D4A49EAEC24544 -- C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Presentation\3.5.0.0__b77a5c561934e089\System.Windows.Presentation.dll

[2011.05.03 15:03:01 | 001,138,688 | ---- | M] () MD5=A96933F3898290AA509080A90E0C7C5F -- C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll

[2011.05.03 15:03:01 | 001,630,208 | ---- | M] () MD5=C4503F6EADC2638D6898514290A7A60B -- C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll

[2011.05.03 15:03:01 | 000,540,672 | ---- | M] () MD5=6623152B2FB7DC650C6A8FE01AF71F44 -- C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll

[2011.05.03 15:03:37 | 000,507,904 | ---- | M] () MD5=E249D1B3114088C0D390A60643BF2BBC -- C:\WINDOWS\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\System.WorkflowServices.dll

[2011.05.03 15:03:43 | 000,139,264 | ---- | M] () MD5=64925CC79EA9E8245A4F18703CCABEC4 -- C:\WINDOWS\assembly\GAC_MSIL\System.Xml.Linq\3.5.0.0__b77a5c561934e089\System.Xml.Linq.dll

[2012.05.11 18:13:46 | 002,048,000 | ---- | M] () MD5=EB97291E3C9E0035B47B45DBB1AF710D -- C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll

[2012.05.11 18:13:45 | 003,186,688 | ---- | M] () MD5=6D37DFFE4B89AB1E17367FEEF2327B34 -- C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll

[2011.05.03 15:03:02 | 000,167,936 | ---- | M] () MD5=F303A07A6EF37B8B6DD928D97A016B75 -- C:\WINDOWS\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\UIAutomationClient.dll

[2011.05.03 15:03:03 | 000,385,024 | ---- | M] () MD5=09658EF5F16F2ABD74FE577D50C0D155 -- C:\WINDOWS\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll

[2011.05.03 15:03:00 | 000,040,960 | ---- | M] () MD5=A93561FB224FA8539357C74065403630 -- C:\WINDOWS\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll

[2011.05.03 15:03:00 | 000,098,304 | ---- | M] () MD5=5BE33FC308914C1AE6577A908D97A4FF -- C:\WINDOWS\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll

[2012.05.11 18:07:46 | 001,249,280 | ---- | M] () MD5=D91A6B3FDF14C0319333FC583D969126 -- C:\WINDOWS\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll

[2011.05.03 15:03:03 | 000,094,208 | ---- | M] () MD5=E205A79EA6C06F91EA08BBE59FE83503 -- C:\WINDOWS\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll

 

< type c:\diskreport.txt /c >

Microsoft DiskPart version 5.1.3565

Copyright © 1999-2003 Microsoft Corporation.

On computer: VASKO

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

Volume 0 E DVD-ROM 0 B

Volume 1 F IV2010 CDFS DVD-ROM 504 MB

Volume 2 C NTFS Partition 20 GB Healthy System

Volume 3 D NTFS Partition 912 GB Healthy

 

< MD5 for: AFD.SYS >

[2011.08.17 16:49:54 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=1E44BC1E83D8FD2305F8D452DB109CF9 -- C:\WINDOWS\system32\dllcache\afd.sys

[2011.08.17 16:49:54 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=1E44BC1E83D8FD2305F8D452DB109CF9 -- C:\WINDOWS\system32\drivers\afd.sys

[2008.04.14 00:49:24 | 000,138,112 | ---- | M] (Microsoft Corporation) MD5=322D0E36693D6E24A2398BEE62A268CD -- C:\WINDOWS\$NtUninstallKB951748$\afd.sys

[2011.02.16 16:22:48 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=355556D9E580915118CD7EF736653A89 -- C:\WINDOWS\$NtUninstallKB2592799$\afd.sys

[2008.10.16 18:07:58 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=38D7B715504DA4741DF35E3594FE2099 -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\afd.sys

[2008.08.14 13:34:26 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=4D43E74F2A1239D53929B82600F1971C -- C:\WINDOWS\$hf_mig$\KB956803\SP3QFE\afd.sys

[2008.08.14 13:34:26 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=4D43E74F2A1239D53929B82600F1971C -- C:\WINDOWS\SoftwareDistribution\Download\a94a6432dbac6901fc5bf15157f718f8\SP3QFE\afd.sys

[2008.08.14 12:51:43 | 000,138,368 | ---- | M] (Microsoft Corporation) MD5=55E6E1C51B6D30E54335750955453702 -- C:\WINDOWS\SoftwareDistribution\Download\a94a6432dbac6901fc5bf15157f718f8\SP2GDR\afd.sys

[2008.08.14 12:48:52 | 000,138,368 | ---- | M] (Microsoft Corporation) MD5=6A0397376853E604DE8E1E7A87FC08AC -- C:\WINDOWS\SoftwareDistribution\Download\a94a6432dbac6901fc5bf15157f718f8\SP2QFE\afd.sys

[2008.10.16 17:43:01 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7618D5218F2A614672EC61A80D854A37 -- C:\WINDOWS\$NtUninstallKB2503665$\afd.sys

[2008.08.14 13:04:36 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7E775010EF291DA96AD17CA4B17137D7 -- C:\WINDOWS\$NtUninstallKB2509553$\afd.sys

[2008.08.14 13:04:36 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7E775010EF291DA96AD17CA4B17137D7 -- C:\WINDOWS\SoftwareDistribution\Download\a94a6432dbac6901fc5bf15157f718f8\SP3GDR\afd.sys

[2011.02.16 16:25:05 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=8D499B1276012EB907E7A9E0F4D8FDA4 -- C:\WINDOWS\$hf_mig$\KB2503665\SP3QFE\afd.sys

[2008.06.20 14:48:03 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=D6EE6014241D034E63C49A50CB2B442A -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\afd.sys

[2008.06.20 14:40:08 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=E3049B90FE06F3F740B7CFDA44995E2C -- C:\WINDOWS\$NtUninstallKB956803$\afd.sys

[2011.08.17 16:41:46 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=F6B7B1ECD7B41736BDB6FF4B092BCB79 -- C:\WINDOWS\$hf_mig$\KB2592799\SP3QFE\afd.sys

 

< MD5 for: ATAPI.SYS >

[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys

[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys

[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys

[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys

 

< MD5 for: DISK.SYS >

[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys

[2008.04.14 00:10:48 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys

 

< MD5 for: EXPLORER.EXE >

[2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe

[2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe

 

< MD5 for: I8042PRT.SYS >

[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:i8042prt.sys

[2008.04.14 00:48:02 | 000,052,480 | ---- | M] (Microsoft Corporation) MD5=4A0B06AA8943C1E332520F7440C0AA30 -- C:\WINDOWS\system32\drivers\i8042prt.sys

 

< MD5 for: IPSEC.SYS >

[2008.04.14 00:49:44 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=23C74D75E36E7158768DD63D92789A91 -- C:\WINDOWS\system32\dllcache\ipsec.sys

[2008.04.14 00:49:44 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=23C74D75E36E7158768DD63D92789A91 -- C:\WINDOWS\system32\drivers\ipsec.sys

 

< MD5 for: LSASS.EXE >

[2008.04.14 05:42:26 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\system32\dllcache\lsass.exe

[2008.04.14 05:42:26 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\system32\lsass.exe

 

< MD5 for: NETBT.SYS >

[2008.04.14 00:51:02 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=74B2B2F5BEA5E9A3DC021D685551BD3D -- C:\WINDOWS\system32\dllcache\netbt.sys

[2008.04.14 00:51:02 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=74B2B2F5BEA5E9A3DC021D685551BD3D -- C:\WINDOWS\system32\drivers\netbt.sys

 

< MD5 for: REDBOOK.SYS >

[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:redbook.sys

[2008.04.14 03:10:28 | 000,057,600 | ---- | M] (Microsoft Corporation) MD5=F828DD7E1419B6653894A8F97A0094C5 -- C:\WINDOWS\system32\drivers\redbook.sys

 

< MD5 for: SERIAL.SYS >

[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:serial.sys

[2008.04.14 00:45:46 | 000,064,512 | ---- | M] (Microsoft Corporation) MD5=CCA207A8896D4C6A0C9CE29A4AE411A7 -- C:\WINDOWS\system32\drivers\serial.sys

 

< MD5 for: SERVICES.EXE >

[2009.02.06 14:06:24 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe

[2008.04.14 05:42:36 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe

[2009.02.06 14:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\dllcache\services.exe

[2009.02.06 14:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\services.exe

 

< MD5 for: SMSS.EXE >

[2008.04.14 05:42:38 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=5F816C1F539266D2D4C78694239DA0B5 -- C:\WINDOWS\system32\dllcache\smss.exe

[2008.04.14 05:42:38 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=5F816C1F539266D2D4C78694239DA0B5 -- C:\WINDOWS\system32\smss.exe

 

< MD5 for: SVCHOST.EXE >

[2008.04.14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\dllcache\svchost.exe

[2008.04.14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe

 

< MD5 for: TCPIP.SYS >

[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$ cpip.sys

[2008.06.20 14:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE cpip.sys

[2008.06.20 14:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE cpip.sys

[2011.05.13 12:15:05 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=D24EA301E2B36C4E975FD216CA85D8E7 -- C:\WINDOWS\system32\dllcache\TCPIP.SYS

[2011.05.13 12:15:05 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=D24EA301E2B36C4E975FD216CA85D8E7 -- C:\WINDOWS\system32\drivers\TCPIP.SYS

 

< MD5 for: USERINIT.EXE >

[2008.04.14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\dllcache\userinit.exe

[2008.04.14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe

 

< MD5 for: VOLSNAP.SYS >

[2008.04.14 00:11:02 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\system32\dllcache\volsnap.sys

[2008.04.14 00:11:02 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\system32\drivers\volsnap.sys

 

< MD5 for: WINLOGON.EXE >

[2008.04.14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe

[2008.04.14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe

 

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========

[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction

[C:\WINDOWS\assembly\GAC_32\Update\1.1.3.0__318d21d4b0463a3b] -> C:\WINDOWS\WinSxS\x86_Update_318d21d4b0463a3b_1.1.3.0_x-ww_46a5f7d3 -> Junction

[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction

[C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492 -> Junction

[C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35] -> C:\WINDOWS\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5 -> Junction

 

< End of report >

Link to comment
Сподели другаде

Ако имаш антивирусна програма инсталирана, я спри, както и всякакви други излишни програми. Изтегли ComboFix (ако случайно вече имаш някаква версия, я замени) и го запази на работния плот.

Стартирай го, кликни I Agree, изчакай да се разархивира и сканира докрай. Не кликай по прозореца на инструмента. Ако бъдеш попитан(а) дали да бъде инсталирана Recovery Console, кликни Yes и потвърди след това с OK и отново Yes (два пъти). Сканирането ще продължи. Ако има нужда от рестарт, компютърът ще се рестартира автоматично. След рестарта трябва да продължи сканирането. Отново не закачай прозореца, докато той не се самозатвори. След това постави съдържанието на текстовия файл C:\ComboFix.txt тук или го прикачи към коментара си.

 

Ако не можеш да установиш връзка с интернет след използване на ComboFix, рестартирай системата.

Link to comment
Сподели другаде

Благодаря ти :)Вече мога да влизам във facebook.

 

ComboFix 12-05-13.03 - Vasko1 05.2012 г. 0:12.1.4 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2935.2297 [GMT 3:00]

Running from: c:\documents and settings\Vasko1\Desktop\ComboFix.exe

AV: ESET NOD32 Antivirus 3.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

* Created a new restore point

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\Vasko1\Application Data\.#

c:\documents and settings\Vasko1\Application Data\.#\MBX@138C@3837B8.###

c:\documents and settings\Vasko1\Application Data\.#\MBX@138C@3837C8.###

c:\documents and settings\Vasko1\Application Data\.#\MBX@138C@3837D8.###

c:\documents and settings\Vasko1\Application Data\PriceGong

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\1.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\a.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\b.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\c.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\d.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\e.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\f.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\g.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\h.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\i.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\J.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\k.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\l.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\m.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\mru.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\n.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\o.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\p.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\q.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\r.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\s.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data .xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\u.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\v.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\w.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\x.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\y.xml

c:\documents and settings\Vasko1\Application Data\PriceGong\Data\z.xml

c:\documents and settings\Vasko1\WINDOWS

c:\windows\ktkm2.dll

c:\windows\ktkm3.dll

c:\windows\ktkm34.dll

c:\windows\ktkm36.dll

c:\windows\ktkm4.dll

c:\windows\ktkm8.dll

c:\windows\system32\_000012_.tmp.dll

.

.

((((((((((((((((((((((((( Files Created from 2012-04-13 to 2012-05-13 )))))))))))))))))))))))))))))))

.

.

2012-05-13 18:55 . 2012-05-13 18:55 -------- d-----w- c:\documents and settings\Vasko1\Application Data\SUPERAntiSpyware.com

2012-05-13 18:54 . 2012-05-13 18:54 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com

2012-05-13 18:45 . 2012-05-13 18:45 -------- d-----w- c:\documents and settings\Vasko1\Application Data\Malwarebytes

2012-05-13 18:45 . 2012-05-13 18:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2012-05-13 18:45 . 2012-04-04 12:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-05-12 14:21 . 2012-05-13 07:40 -------- d-----w- c:\program files\Mozilla Maintenance Service

2012-05-11 19:41 . 2012-05-11 19:41 30208 ----a-r- c:\documents and settings\Vasko1\Application Data\Microsoft\Installer\{40A0B29E-B270-450B-BF4D-34493A934523}\Icon40A0B29E.exe

2012-05-11 15:57 . 2012-05-11 15:57 -------- d-----w- c:\documents and settings\Vasko1\Application Data\Avant Downloader

2012-04-27 20:02 . 2012-04-27 20:29 -------- d-----w- c:\program files\Opera

2012-04-21 19:36 . 2012-04-21 19:36 -------- d-----w- c:\program files\Common Files\Symantec Shared

2012-04-21 19:36 . 2012-04-27 12:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-05-12 11:28 . 2012-01-10 21:41 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2012-05-12 11:28 . 2011-05-20 10:00 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-04-11 13:14 . 2008-04-13 21:54 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe

2012-04-11 13:12 . 2008-04-13 22:00 1862272 ----a-w- c:\windows\system32\win32k.sys

2012-04-11 12:35 . 2008-04-14 00:01 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe

2012-03-07 20:54 . 2012-03-07 20:54 180224 ----a-w- c:\windows\system32\WinVd32.sys

2012-03-07 20:54 . 2012-03-07 20:54 7680 ----a-w- c:\windows\system32\WinFLsrv.exe

2012-03-06 16:33 . 2012-03-06 16:33 73728 ----a-w- c:\windows\system32\javacpl.cpl

2012-03-06 16:33 . 2012-03-06 16:33 472808 ----a-w- c:\windows\system32\deployJava1.dll

2012-03-01 11:01 . 2008-04-14 02:42 1469440 ------w- c:\windows\system32\inetcpl.cpl

2012-03-01 11:01 . 2008-04-14 02:42 916992 ----a-w- c:\windows\system32\wininet.dll

2012-03-01 11:01 . 2008-04-14 02:41 43520 ------w- c:\windows\system32\licmgr10.dll

2012-02-29 14:10 . 2008-04-14 02:42 177664 ----a-w- c:\windows\system32\wintrust.dll

2012-02-29 14:10 . 2008-04-14 02:41 148480 ----a-w- c:\windows\system32\imagehlp.dll

2012-02-29 12:17 . 2008-04-13 21:07 385024 ------w- c:\windows\system32\html.iec

2012-02-14 09:09 . 2012-02-14 09:09 1070352 ----a-w- c:\windows\system32\MSCOMCTL.OCX

2009-06-19 09:12 . 2009-06-19 09:12 1828176 ----a-w- c:\program files\Common Files\Skype4COM.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[-] 2011-05-13 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\TCPIP.SYS

[-] 2011-05-13 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\TCPIP.SYS

[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE cpip.sys

[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE cpip.sys

[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$ cpip.sys

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-04-09 1519272]

"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2011-03-11 1373512]

"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTo0.dll" [2011-05-09 176936]

"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\prxtbBS_P.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]

.

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]

[HKEY_CLASSES_ROOT\WinampTb.AOLTBSearch.1]

[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]

[HKEY_CLASSES_ROOT\WinampTb.AOLTBSearch]

.

[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]

.

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]

2011-05-09 09:49 176936 ----a-w- c:\program files\uTorrentBar\prxtbuTo0.dll

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]

2012-04-09 14:43 1519272 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

2011-05-09 08:49 176936 ----a-w- c:\program files\BS_Player\prxtbBS_P.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTo0.dll" [2011-05-09 176936]

"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-04-09 1519272]

"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\prxtbBS_P.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]

.

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]

[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

.

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\prxtbuTo0.dll" [2011-05-09 176936]

"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-04-09 1519272]

"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\prxtbBS_P.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]

.

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]

[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

.

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-02-28 740216]

"avichannel"="c:\program files\Evaer\videochannel.exe" [2011-09-21 1686016]

"Facebook Update"="c:\documents and settings\Vasko1\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" [2011-10-19 137536]

"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2011-07-21 718720]

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-01-19 3477312]

"GameXN (update)"="c:\documents and settings\All Users\Application Data\GameXN\GameXNGO.exe" [2012-03-31 347008]

"GameXN (news)"="c:\documents and settings\All Users\Application Data\GameXN\GameXNGO.exe" [2012-03-31 347008]

"GameXN"="c:\documents and settings\All Users\Application Data\GameXN\GameXNGO.exe" [2012-03-31 347008]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-02-29 17148552]

"SUPERAntiSpyware"="d:\programs\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-05-01 3905920]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-18 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-18 174104]

"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-18 144920]

"RTHDCPL"="RTHDCPL.EXE" [2010-04-30 19523616]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-03-17 74752]

"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-11-10 1980200]

"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-11 1280344]

"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"HCEmployee"="c:\program files\Oleansoft\Hc\servemp.exe" [2011-11-05 413184]

"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-04-09 1557160]

"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-28 1987976]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

.

c:\documents and settings\Vasko1\Start Menu\Programs\Startup\

Изрязване на екран и стартиране на OneNote 2010.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\gprs.exe [2008-3-19 43608]

.

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\programs\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2011-05-04 17:54 551296 ----a-w- d:\programs\SUPERAntiSpyware\SASWINLO.DLL

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=

"d:\\Games\\PES\\pes2011.exe"=

"d:\\Games\\gMOD\\hl2.exe"=

"d:\\Games\\Mafia\\Steam.exe"=

"d:\\Games\\TDU\\Test Drive Unlimited GOLD\\TestDriveUnlimited.exe"=

"d:\\Games\\Fifa\\fifa07.exe"=

"d:\\Games\\NWO\\New World Order\\NWO\\NWO.exe"=

"d:\\Games\\Prototype\\prototypef.exe"=

"d:\\Games\\X-Men\\Binaries\\Wolverine.exe"=

"d:\\Games\\CoD\\CoD2MP_s.exe"=

"c:\\WINDOWS\\system32\\PnkBstrA.exe"=

"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

"d:\\Games\\Wolfenstein\\MP\\Wolf2MP.exe"=

"d:\\Games\\Wolfenstein\\MP\\Wolf2MPLite.exe"=

"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=

"d:\\Games\\Free Running\\FreeRunning.exe"=

"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=

"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=

"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=

"c:\\Program Files\\Oleansoft\\Hc\\servemp.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"d:\\Games\\CS\\Counter-Strike 1.6 Sector Edition\\cstrike.exe"=

"c:\\Betfair JPC\\arch\\win32\\jre\\bin\\java.exe"=

"d:\\Games\\Stalker\\S.T.A.L.K.E.R\\bin\\XR_3DA.exe"=

"d:\\Games\\Stalker\\S.T.A.L.K.E.R\\bin\\dedicated\\XR_3DA.exe"=

"c:\\Program Files\\Winamp\\winamp.exe"=

"d:\\Games\\CS\\Counter-Strike 1.6 Sector Edition\\hlds.exe"=

"d:\\Games\\Fifa 12\\FIFA 12\\Game\\fifa.exe"=

"d:\\Games\\CS\\CS 1.6\\cstrike.exe"=

"c:\\Documents and Settings\\Vasko1\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management

.

R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [16.3.2011 г. 23:38 13696]

R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [11.2.2012 г. 14:33 242240]

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [10.11.2008 г. 15:34 104456]

R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [10.11.2008 г. 15:34 92168]

R1 SASDIFSV;SASDIFSV;d:\programs\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 г. 19:27 12880]

R1 SASKUTIL;SASKUTIL;d:\programs\SUPERAntiSpyware\SASKUTIL.SYS [13.7.2011 г. 00:55 67664]

R2 !SASCORE;SAS Core Service;d:\programs\SUPERAntiSpyware\SASCore.exe [12.8.2011 г. 02:38 116608]

R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [10.11.2008 г. 15:34 711240]

R2 ezGOSvc;Easybits GO Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [14.4.2008 г. 05:42 14336]

R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [28.2.2012 г. 18:38 1373576]

R2 NAUpdate;@c:\program files\Nero\Update\NASvc.exe,-200;c:\program files\Nero\Update\NASvc.exe [23.9.2011 г. 19:37 641832]

R2 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [19.3.2008 г. 17:52 51816]

R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [07.3.2012 г. 23:54 10752]

R3 IntcDAud;Intel® Display Audio;c:\windows\system32\drivers\IntcDAud.sys [16.3.2011 г. 23:40 235520]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 г. 13:16 130384]

S2 gupdate;Услуга Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [21.4.2011 г. 21:43 136176]

S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [20.3.2011 г. 16:07 312152]

S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [29.2.2012 г. 08:50 158856]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [11.1.2012 г. 00:41 257696]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [16.3.2011 г. 23:42 1691480]

S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\docume~1\Vasko1\LOCALS~1\Temp\RarSFX1\kerneld.wnt --> c:\docume~1\Vasko1\LOCALS~1\Temp\RarSFX1\kerneld.wnt [?]

S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [21.4.2011 г. 21:43 136176]

S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [12.6.2011 г. 11:15 31125880]

S3 MozillaMaintenance;Mozilla Maintenance Service;"c:\program files\Mozilla Maintenance Service\maintenanceservice.exe" --> c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [?]

S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [17.11.2011 г. 12:24 137472]

S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [17.11.2011 г. 12:24 8576]

S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09.1.2010 г. 21:37 4640000]

S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14.4.2008 г. 05:42 14336]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 г. 13:16 753504]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

WINRM REG_MULTI_SZ WINRM

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

ezGOSvc

.

Contents of the 'Scheduled Tasks' folder

.

2012-05-13 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-01-10 11:28]

.

2012-05-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003Core.job

- c:\documents and settings\Vasko1\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-19 11:41]

.

2012-05-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003UA.job

- c:\documents and settings\Vasko1\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-19 11:41]

.

2012-05-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-21 18:43]

.

2012-05-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-21 18:43]

.

2012-05-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003Core.job

- c:\documents and settings\Vasko1\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-02 15:55]

.

2012-05-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003UA.job

- c:\documents and settings\Vasko1\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-02 15:55]

.

2012-05-13 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job

- c:\program files\Ask.com\UpdateTask.exe [2012-04-09 14:43]

.

2012-05-13 c:\windows\Tasks\WGASetup.job

- c:\windows\system32\KB905474\wgasetup.exe [2011-03-20 20:18]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT1750559

uInternet Connection Wizard,ShellNext = iexplore

uInternet Settings,ProxyServer = http=;ftp=;https=;

IE: &Експортиране към Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000

IE: &Изпрати към OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.1.1

FF - ProfilePath - c:\documents and settings\Vasko1\Application Data\Mozilla\Firefox\Profiles\0px2n2cr.default\

FF - prefs.js: network.proxy.gopher -

FF - prefs.js: network.proxy.gopher_port - 0

FF - prefs.js: network.proxy.type - 0

.

- - - - ORPHANS REMOVED - - - -

.

AddRemove-PokerStars.net - c:\program files\PokerStars.NET\PokerStarsUninstall.exe

AddRemove-FolderLock6 - c:\program files\Folder Lock\Uninstall.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2012-05-14 00:14

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

.

c:\windows\system32\sys_drv.dat 9036 bytes

c:\windows\system32\sys_drv_2.dat 7028 bytes

c:\windows\system32\WinFLdrv.sys 10752 bytes executable

c:\documents and settings\Vasko1\Application Data\systemfl.$dk 990 bytes

.

scan completed successfully

hidden files: 4

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]

"ImagePath"="\??\c:\docume~1\Vasko1\LOCALS~1\Temp\RarSFX1\kerneld.wnt"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\B20@O=5 *=0 *C*C*l*e*a*n*e*r*& \command]

@="c:\\Program Files\\CCleaner\\ccleaner.exe"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'winlogon.exe'(892)

d:\programs\SUPERAntiSpyware\SASWINLO.DLL

c:\windows\system32\WININET.dll

.

Completion time: 2012-05-14 00:15:52

ComboFix-quarantined-files.txt 2012-05-13 21:15

.

Pre-Run: 2 498 985 984 bytes free

Post-Run: 2 464 538 624 bytes free

.

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

.

- - End Of File - - 98D11FA03A267582ED981C6812743828

Link to comment
Сподели другаде

Дотук добре. Да видим дали ще се намери нещо след това...

 

Сканирай с Malwarebytes Anti-Malware. Ако тепърва инсталираш програмата, в края инсталацията ще има отметка за автоматична актуализация, не я премахвай. В противен случай обнови дефинициите й ръчно. Ако вече имаш програмата, провери дали имаш последната версия и ако нямаш, премахни твоята и инсталирай най-новата, като в края на инсталацията остави отметката за актуализация на дефинициите.

 

Инструкции за сканиране:

- стартирай програмата;

- избери Perform quick scan (Бързо сканиране) и кликни бутон Scan (Сканиране);

- след като приключи сканирането, ако не са открити заплахи, ще се отвори автоматично текстов файл (който можеш да затвориш) и програмата ще те уведоми, че не е открила нищо, след което можеш да кликнеш бутон OK и да я затвориш;

- ако са открити заплахи, кликни бутон OK и после Show Results (Покажи резултатите);

- кликни бутон Remove Selected (Премахни избраните);

Ако е нужен рестарт, се съгласи и рестартирай веднага. След рестарта стартирай отново програмата, иди на подпорозиорец Logs (Дневници), маркирай последния дневник, кликни бутон Open (Отвори) и му копирай съдържанието тук. Ако не е бил нужен рестарт, трябва да се появи текстов файл - копирай му съдържанието тук.

Link to comment
Сподели другаде

Malwarebytes Anti-Malware 1.61.0.1400

www.malwarebytes.org

 

Версия на базата от данни: v2012.05.13.04

 

Windows XP Service Pack 3 x86 NTFS

Internet Explorer 8.0.6001.18702

Vasko1 :: VASKO [администратор]

 

14.5.2012 г. 20:59:46

mbam-log-2012-05-14 (20-59-46).txt

 

Тип сканиране: Бързо сканиране

Включени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUM

Изключени опции за сканиране: P2P

Сканирани обекти: 208445

Изминало време: 1 минута(и), 41 секунда(и)

 

Открити процеси в паметта: 0

(Не бяха открити зловредни обекти)

 

Открити модули в паметта: 0

(Не бяха открити зловредни обекти)

 

Открити ключове в системния регистър: 0

(Не бяха открити зловредни обекти)

 

Открити стойности в системния регистър: 0

(Не бяха открити зловредни обекти)

 

Открити информационни обекти в системния регистър: 0

(Не бяха открити зловредни обекти)

 

Открити папки: 0

(Не бяха открити зловредни обекти)

 

Открити файлове: 0

(Не бяха открити зловредни обекти)

 

(край)

Link to comment
Сподели другаде

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Гост
Отговори на тази тема

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   Не можете да качите директно снимка. Качете или добавете изображението от линк (URL)

Loading...

×
×
  • Създай ново...