Night_Raven Публикувано Ноември 1, 2011 Report Share Публикувано Ноември 1, 2011 Таке е по-добре. Дневникът е чист. Стартирай отново OTL и кликни бутон CleanUp. Това ще премахне инструмента и принадлежащите му фалове и папки. Бих ти препоръчал да актуализираш Malwarebytes' Anti-Malware и да пуснеш едно бързо сканиране. Профилактично. След това ще е време да си инсталираш някаква надеждна антивирусна, че така голичък да стоиш не е добра идея. Цитирай Link to comment Сподели другаде More sharing options...
kaloqnvr Публикувано Април 14, 2012 Report Share Публикувано Април 14, 2012 До: Night_Raven Здравей имам проблем с фейсбука не мога да го отворя следвах инструкциите ти ето двата файла от OTL.С XP съм OTL.Txt Extras.Txt Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Април 14, 2012 Report Share Публикувано Април 14, 2012 Стартирай отново OTL. В празното поле "Custom Scans/Fixes" (в долната част на програмата) постави следния текст (маркирай го, натисни Ctrl+C и после в полето на OTL натисни Ctrl+V): :Processes killallprocesses :OTL O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O4 - HKLM..\Run: [tray_ico] File not found O4 - HKLM..\Run: [tray_ico1] File not found O4 - HKLM..\Run: [tray_ico2] File not found O4 - HKLM..\Run: [tray_ico3] File not found O4 - HKLM..\Run: [tray_ico4] File not found O8 - Extra context menu item: &Search - Reg Error: Value error. File not found O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm File not found O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm File not found O32 - AutoRun File - [2011.03.25 20:03:11 | 000,000,000 | ---D | M] - D:\AutoRun -- [ NTFS ] O33 - MountPoints2\{172c883a-b438-11de-972e-00030d83037b}\Shell\AutoRun\command - "" = 8dtyjjf.exe O33 - MountPoints2\{172c883a-b438-11de-972e-00030d83037b}\Shell\open\Command - "" = 8dtyjjf.exe [2011.07.25 21:01:34 | 000,246,272 | ---- | C] () -- C:\WINDOWS\unrar.exe [2011.07.25 20:43:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\loader2.exe_ok [2010.07.28 14:56:52 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll @Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1 :Files C:\WINDOWS\*.tmp C:\WINDOWS\system32\*.tmp :Commands [resethosts] [emptytemp] [reboot]Копирай текста точно както е в полето. Внимавай да не изтървеш началното двуеточие и всяка команда да е на отделен ред, както е в полето. Кликни бутон Run Fix. Потвърди с OK на съобщението, че е нужен рестарт на системата. Цитирай Link to comment Сподели другаде More sharing options...
kaloqnvr Публикувано Април 14, 2012 Report Share Публикувано Април 14, 2012 фейсбука вече работи.Благодаря ти много ако трябва да направя още нещо ще следвам инструкциите ти Цитирай Link to comment Сподели другаде More sharing options...
Magdalena Tsoncheva Публикувано Май 13, 2012 Report Share Публикувано Май 13, 2012 И аз съм със същият проблем с фейсбука. От 3 дни се мъча да го отстряня, но нищо не става...Изчетох няколко пъти всичко от тук, изтеглих си и сканиращите програмки, поизчистих си машинката от гадости, изпълних и гореописаните стъпки. С XP съм. Ще съм страшно благодарна, ако помогнете и на мен. Поразгледах кодовете, но не мога да се отиентирам какво точно се прави и защо... Ето какво ми е съдържанието на файла extras.txt:OTL Extras logfile created on: 12.5.2012 г. 18:35:56 - Run 1OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Mitko\DesktopWindows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstationInternet Explorer (Version = 8.0.6001.18702)Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 1,99 Gb Total Physical Memory | 1,23 Gb Available Physical Memory | 61,94% Memory free3,84 Gb Paging File | 3,12 Gb Available in Paging File | 81,38% Paging File freePaging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 68,36 Gb Total Space | 20,82 Gb Free Space | 30,46% Space Free | Partition Type: NTFSDrive D: | 43,43 Gb Total Space | 14,42 Gb Free Space | 33,21% Space Free | Partition Type: NTFS Computer Name: MAGI | User Name: Mitko | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All usersCompany Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>].cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software) [HKEY_USERS\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Classes\<extension>].html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]batfile [open] -- "%1" %*cmdfile [open] -- "%1" %*comfile [open] -- "%1" %*cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*exefile [open] -- "%1" %*htmlfile [edit] -- Reg Error: Key error.http [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)https [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)piffile [open] -- "%1" %*regfile [merge] -- Reg Error: Key error.scrfile [config] -- "%1"scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %lscrfile [open] -- "%1" /Stxtfile [edit] -- Reg Error: Key error.Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]"FirstRunDisabled" = 1"AntiVirusDisableNotify" = 0"FirewallDisableNotify" = 1"UpdatesDisableNotify" = 1"AntiVirusOverride" = 0"FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]"DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]"Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]"Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]"EnableFirewall" = 1"DoNotAllowExceptions" = 0"DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008"2706:TCP" = 2706:TCP:*:Enabled:Inhatch P2P Streaming"2707:TCP" = 2707:TCP:*:Enabled:Inhatch P2P Streaming"2708:TCP" = 2708:TCP:*:Enabled:Inhatch P2P Streaming"2709:TCP" = 2709:TCP:*:Enabled:Inhatch P2P Streaming ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)"C:\Documents and Settings\Mitko\My Documents\Downloads\ComNet_TV.exe" = C:\Documents and Settings\Mitko\My Documents\Downloads\COMNET_TV.EXE:*:Enabled:COMNET_TV.EXE"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer"C:\Documents and Settings\Mitko\Local Settings\Temp\Torrent2Exe\T2E.exe" = C:\Documents and Settings\Mitko\Local Settings\Temp\Torrent2Exe\T2E.exe:*:Enabled:Torrent2Exe -- (http://www.torrent2exe.com)"C:\Documents and Settings\Mitko\My Documents\Downloads\SweetImSetup.exe" = C:\Documents and Settings\Mitko\My Documents\Downloads\SweetImSetup.exe:*:Enabled:SweetIM Installer"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console -- (Microsoft Corporation)"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Computer, Inc.)"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath -- (Skype Technologies S.A.)"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 -- (AVG Technologies CZ, s.r.o.)"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.)"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"{00640E90-FF0B-4561-AD85-F5EC43E27B75}" = Fun&Learning - Memory&Logic"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic UDF Reader"{17079027-EB8A-42C6-9BF8-825B78889F6A}" = Garmin Communicator Plugin"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP"{3BC1AB78-2D98-4906-84B5-4230B5420DCC}" = Offline Course Player"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3"{411949AB-6EE8-4C62-9C72-EBC93B6A7935}" = AVG 2012"{50842BAB-FD22-4B64-BE6D-4DC632EFBF39}" = Fun&Learning - Creativity"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3"{73284F36-E17E-44B0-85E2-F0336A6E749F}" = PC Connectivity Solution"{74C5EA04-AF1E-45B2-949B-4841EE949C40}" = Nokia Connectivity Cable Driver"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific"{A7836FF5-7293-40A4-B86E-E2038F82E8F3}" = AVG 2012"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = USB PC Camera Plus"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver"{FCD8DCE6-94C8-4FF6-8E3E-D3C96A5A707E}" = Nokia PC Suite"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)"6A630DCEC5EEC912115F2FF59D8C2C769798D930" = Windows Driver Package - Nokia Modem (10/12/2007 3.6)"819D45A9F73817F5B6D7C71A33ADAB88C5DA1765" = Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2)"9925DD2E3ADF2DA7C8A0212FB775F1D2FB6C56E8" = Windows Driver Package - Nokia (WUDFRd) WPD (11/05/2007 6.85.35.3)"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3"Ask Toolbar_is1" = Ask Toolbar"AVG" = AVG 2012"CDex" = CDex extraction audio"EVEREST Home Edition_is1" = EVEREST Home Edition v1.10"F1CB0AC2D40DDCFCA6933082B115073476C155DE" = Windows Driver Package - Nokia Modem (08/03/2007 3.2)"FlexType 2K" = FlexType 2K"Foxit Reader" = Foxit Reader"HDMI" = Intel® Graphics Media Accelerator Driver"ie8" = Windows Internet Explorer 8"Inhatch web plugins" = Inhatch web plugins"IrfanView" = IrfanView (remove only)"KLiteCodecPack_is1" = K-Lite Codec Pack 4.5.3 (Full)"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware, версия 1.61.0.1400"Nero - Burning Rom!UninstallKey" = Ahead Nero 6 Demo"Nokia PC Suite" = Nokia PC Suite"Opera 11.64.1403" = Opera 11.64"PROPLUS" = Microsoft Office Professional Plus 2007"Replay Media Catcher" = Replay Media Catcher"SA Dictionary 2002 Professional" = SA Dictionary 2002 Professional"TOSHIBA Software Modem" = TOSHIBA Software Modem"Unlocker" = Unlocker 1.8.7"uTorrent" = µTorrent"VLC media player" = VLC media player 1.1.7"Winamp" = Winamp"WinRAR archiver" = WinRAR archiver ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"Google Chrome" = Google Chrome"uTorrent" = µTorrent ========== Last 10 Event Log Errors ========== [ Application Events ]Error - 02.5.2011 г. 01:00:45 | Computer Name = MAGI | Source = Application Error | ID = 1000Description = Faulting application firefox.exe, version 1.9.2.4127, faulting modulemsvcr90.dll, version 9.0.30729.4148, fault address 0x00059231. Error - 03.5.2011 г. 00:55:58 | Computer Name = MAGI | Source = Application Error | ID = 1000Description = Faulting application firefox.exe, version 1.9.2.4127, faulting modulemsvcr90.dll, version 9.0.30729.4148, fault address 0x00059231. Error - 03.5.2011 г. 00:56:18 | Computer Name = MAGI | Source = Application Error | ID = 1000Description = Faulting application firefox.exe, version 1.9.2.4127, faulting modulemsvcr90.dll, version 9.0.30729.4148, fault address 0x00059231. Error - 03.5.2011 г. 00:56:22 | Computer Name = MAGI | Source = Application Error | ID = 1001Description = Fault bucket -1882036877. Error - 09.5.2011 г. 01:17:44 | Computer Name = MAGI | Source = Application Error | ID = 1000Description = Faulting application firefox.exe, version 1.9.2.4127, faulting modulemsvcr90.dll, version 9.0.30729.4148, fault address 0x00059231. Error - 12.5.2011 г. 16:14:15 | Computer Name = MAGI | Source = crypt32 | ID = 131083Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>with error: A required certificate is not within its validity period when verifyingagainst the current system clock or the timestamp in the signed file. Error - 12.5.2011 г. 16:14:15 | Computer Name = MAGI | Source = crypt32 | ID = 131083Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>with error: A required certificate is not within its validity period when verifyingagainst the current system clock or the timestamp in the signed file. Error - 15.5.2011 г. 00:48:09 | Computer Name = MAGI | Source = Application Error | ID = 1000Description = Faulting application firefox.exe, version 1.9.2.4127, faulting modulemsvcr90.dll, version 9.0.30729.4148, fault address 0x00059231. Error - 30.5.2011 г. 08:41:44 | Computer Name = MAGI | Source = Application Hang | ID = 1002Description = Hanging application mplayerc.exe, version 1.2.972.0, hang module hungapp,version 0.0.0.0, hang address 0x00000000. Error - 01.6.2011 г. 12:49:00 | Computer Name = MAGI | Source = Application Error | ID = 1000Description = Faulting application firefox.exe, version 1.9.2.4127, faulting modulemsvcr90.dll, version 9.0.30729.4148, fault address 0x00059231. [ System Events ]Error - 11.5.2012 г. 19:57:17 | Computer Name = MAGI | Source = SideBySide | ID = 16842784Description = Dependent Assembly Microsoft.VC90.CRT could not be found and LastError was The referenced assembly is not installed on your system. Error - 11.5.2012 г. 19:57:17 | Computer Name = MAGI | Source = SideBySide | ID = 16842811Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference errormessage: The referenced assembly is not installed on your system. . Error - 11.5.2012 г. 19:57:17 | Computer Name = MAGI | Source = SideBySide | ID = 16842811Description = Generate Activation Context failed for C:\Program Files\AVG\AVG2012\avgcfgx.dll.Referenceerror message: The operation completed successfully. . Error - 11.5.2012 г. 19:57:42 | Computer Name = MAGI | Source = SideBySide | ID = 16842784Description = Dependent Assembly Microsoft.VC90.CRT could not be found and LastError was The referenced assembly is not installed on your system. Error - 11.5.2012 г. 19:57:42 | Computer Name = MAGI | Source = SideBySide | ID = 16842811Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference errormessage: The referenced assembly is not installed on your system. . Error - 11.5.2012 г. 19:57:42 | Computer Name = MAGI | Source = SideBySide | ID = 16842811Description = Generate Activation Context failed for C:\Program Files\AVG\AVG2012\avgcfgx.dll.Referenceerror message: The operation completed successfully. . Error - 11.5.2012 г. 21:01:20 | Computer Name = MAGI | Source = System Error | ID = 1003Description = Error code 10000050, parameter1 e144401c, parameter2 00000000, parameter3bf83291e, parameter4 00000001. Error - 11.5.2012 г. 21:01:38 | Computer Name = MAGI | Source = System Error | ID = 1003Description = Error code 1000008e, parameter1 c0000005, parameter2 bf951755, parameter39ba9bc00, parameter4 00000000. Error - 11.5.2012 г. 21:01:40 | Computer Name = MAGI | Source = System Error | ID = 1003Description = Error code 1000008e, parameter1 c0000005, parameter2 bf951755, parameter395c53c00, parameter4 00000000. Error - 12.5.2012 г. 12:41:36 | Computer Name = MAGI | Source = Dhcp | ID = 1000Description = Your computer has lost the lease to its IP address 85.11.187.219 onthe Network Card with network address 001D60F34F30. < End of report > ето и съдържанието на otl.txt:OTL logfile created on: 12.5.2012 г. 18:35:56 - Run 1OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Mitko\DesktopWindows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstationInternet Explorer (Version = 8.0.6001.18702)Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 1,99 Gb Total Physical Memory | 1,23 Gb Available Physical Memory | 61,94% Memory free3,84 Gb Paging File | 3,12 Gb Available in Paging File | 81,38% Paging File freePaging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 68,36 Gb Total Space | 20,82 Gb Free Space | 30,46% Space Free | Partition Type: NTFSDrive D: | 43,43 Gb Total Space | 14,42 Gb Free Space | 33,21% Space Free | Partition Type: NTFS Computer Name: MAGI | User Name: Mitko | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All usersCompany Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days ========== Processes (SafeList) ========== PRC - [2012.05.12 18:20:32 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mitko\Desktop\OTL.exePRC - [2012.05.12 17:49:20 | 000,949,104 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exePRC - [2012.05.11 17:00:26 | 001,116,544 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exePRC - [2012.05.04 13:37:37 | 000,932,736 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exePRC - [2012.05.01 09:48:04 | 003,905,920 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exePRC - [2012.04.30 09:44:38 | 005,106,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgidsagent.exePRC - [2012.04.19 04:51:54 | 001,254,992 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exePRC - [2012.04.05 05:12:34 | 002,587,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exePRC - [2012.03.19 05:18:12 | 000,979,840 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exePRC - [2012.02.14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exePRC - [2012.02.14 04:53:14 | 000,758,112 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exePRC - [2012.02.14 04:52:38 | 000,338,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exePRC - [2011.08.11 16:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exePRC - [2011.06.03 05:00:08 | 000,042,872 | ---- | M] () -- C:\Program Files\Offline Course Player\OlpSynch.exePRC - [2009.03.10 18:28:36 | 000,262,144 | ---- | M] (SONIX) -- C:\WINDOWS snpstd3.exePRC - [2007.11.22 12:49:08 | 000,385,024 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exePRC - [2007.11.09 13:16:24 | 000,688,128 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exePRC - [2007.11.06 09:36:34 | 000,352,768 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exePRC - [2007.11.06 06:38:46 | 000,009,216 | R--- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exePRC - [2007.10.26 08:55:58 | 000,122,880 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exePRC - [2007.10.23 10:03:00 | 000,117,248 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exePRC - [2007.10.09 22:28:32 | 000,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exePRC - [2006.09.18 14:12:12 | 000,843,776 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exePRC - [2006.06.13 06:20:00 | 000,127,036 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLACTRLW.EXEPRC - [2004.08.03 14:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exePRC - [2000.11.07 18:05:40 | 000,145,920 | ---- | M] () -- C:\WINDOWS\Datecs\Flex2K.exe ========== Modules (No Company Name) ========== MOD - [2012.05.12 18:31:29 | 000,052,736 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dllMOD - [2012.05.12 18:31:28 | 000,065,024 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dllMOD - [2012.05.12 18:05:34 | 000,117,760 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLLMOD - [2012.05.12 18:05:34 | 000,052,224 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dllMOD - [2012.05.12 17:49:25 | 000,783,360 | ---- | M] () -- C:\Program Files\Opera\gstreamer\gstreamer.dllMOD - [2012.05.12 17:49:25 | 000,316,928 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstoggdec.dllMOD - [2012.05.12 17:49:25 | 000,276,480 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwebmdec.dllMOD - [2012.05.12 17:49:25 | 000,168,448 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstffmpegcolorspace.dllMOD - [2012.05.12 17:49:25 | 000,099,840 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstcoreplugins.dllMOD - [2012.05.12 17:49:25 | 000,098,816 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioresample.dllMOD - [2012.05.12 17:49:25 | 000,098,816 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioconvert.dllMOD - [2012.05.12 17:49:25 | 000,078,336 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwavparse.dllMOD - [2012.05.12 17:49:25 | 000,076,800 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdirectsound.dllMOD - [2012.05.12 17:49:25 | 000,068,608 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdecodebin2.dllMOD - [2012.05.12 17:49:25 | 000,064,000 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstautodetect.dllMOD - [2012.05.12 17:49:25 | 000,046,592 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwaveform.dllMOD - [2012.05.12 17:49:25 | 000,045,568 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gsttypefindfunctions.dllMOD - [2012.05.11 17:00:26 | 001,116,544 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exeMOD - [2012.05.04 13:37:37 | 000,932,736 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exeMOD - [2012.05.04 13:37:37 | 000,130,944 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\SiteSafety.dllMOD - [2011.06.03 05:00:08 | 000,042,872 | ---- | M] () -- C:\Program Files\Offline Course Player\OlpSynch.exeMOD - [2007.11.09 13:16:24 | 000,688,128 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exeMOD - [2007.10.26 08:55:58 | 000,122,880 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exeMOD - [2007.10.23 10:03:00 | 000,117,248 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exeMOD - [2007.10.09 22:28:32 | 000,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exeMOD - [2007.08.27 12:35:54 | 001,581,056 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\QtCore4.dllMOD - [2007.08.02 17:16:58 | 000,131,072 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\Imageformats\qjpeg4.dllMOD - [2007.08.02 17:05:42 | 006,402,048 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\QtGui4.dllMOD - [2007.08.02 16:51:54 | 000,356,352 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\QtXml4.dllMOD - [2006.09.18 14:12:12 | 000,843,776 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exeMOD - [2000.11.07 18:05:40 | 000,145,920 | ---- | M] () -- C:\WINDOWS\Datecs\Flex2K.exeMOD - [2000.10.19 00:03:34 | 000,028,672 | ---- | M] () -- C:\WINDOWS\system32\newdll.dll ========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)SRV - [2012.05.11 16:59:42 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)SRV - [2012.05.04 13:37:37 | 000,932,736 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe -- (vToolbarUpdater11.0.2)SRV - [2012.04.30 09:44:38 | 005,106,744 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgidsagent.exe -- (AVGIDSAgent)SRV - [2012.02.29 08:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)SRV - [2012.02.14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)SRV - [2012.02.01 08:51:01 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)SRV - [2011.08.11 16:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore.exe -- (!SASCORE)SRV - [2007.11.06 09:36:34 | 000,352,768 | ---- | M] (Nokia.) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)SRV - [2007.11.06 06:38:46 | 000,009,216 | R--- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)DRV - File not found [Kernel | System | Stopped] -- -- (Changer)DRV - [2012.04.19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\avgidshx.sys -- (AVGIDSHX)DRV - [2012.03.19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)DRV - [2012.02.22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)DRV - [2012.01.31 04:46:50 | 000,031,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avgrkx86.sys -- (Avgrkx86)DRV - [2011.12.23 13:32:14 | 000,041,040 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)DRV - [2011.12.23 13:32:08 | 000,017,232 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsshimx.sys -- (AVGIDSShim)DRV - [2011.12.23 13:32:06 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsfilterx.sys -- (AVGIDSFilter)DRV - [2011.12.23 13:32:00 | 000,139,856 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)DRV - [2011.07.22 09:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)DRV - [2011.07.12 14:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)DRV - [2009.03.25 15:29:52 | 000,130,432 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)DRV - [2008.05.01 21:15:44 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)DRV - [2007.11.28 01:02:43 | 000,007,680 | ---- | M] (ATK0100) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor)DRV - [2007.11.19 19:06:16 | 010,246,400 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)DRV - [2007.11.06 06:41:42 | 000,264,576 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8187B.sys -- (RTL8187B)DRV - [2007.11.06 06:40:12 | 004,608,000 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)DRV - [2007.11.06 06:38:44 | 001,161,888 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)DRV - [2007.02.22 10:15:56 | 000,137,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcd.sys -- (nmwcd)DRV - [2007.02.22 10:15:14 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcm.sys -- (nmwcdcm)DRV - [2007.02.22 10:15:14 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcj.sys -- (nmwcdcj)DRV - [2007.02.22 10:15:14 | 000,008,320 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdc.sys -- (nmwcdc)DRV - [2006.06.13 06:20:00 | 000,094,460 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)DRV - [2006.06.13 06:20:00 | 000,088,476 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)DRV - [2006.06.13 06:20:00 | 000,086,844 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)DRV - [2006.06.13 06:20:00 | 000,025,724 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)DRV - [2006.06.13 06:20:00 | 000,014,716 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)DRV - [2006.06.13 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)DRV - [2006.06.13 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)DRV - [2006.03.17 09:35:24 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)DRV - [2006.03.17 09:34:46 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)DRV - [2004.08.03 15:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)DRV - [2004.08.03 13:07:46 | 000,223,616 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers cpip6.sys -- (Tcpip6) ========== Standard Registry (All) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-onsIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRiskIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.c...99&gct=&gc=1&q=IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htmIE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search...p={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htmIE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearchIE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.bg/IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value foundIE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll ()IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRCIE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.c...fr&d=2012-05-11 17:00:27&v=11.0.0.9&sap=dsp&q={searchTerms}IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.c...m=1&toolbar=FXTIE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"FF - prefs.js..browser.search.defaulturl: ""FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"FF - prefs.js..browser.startup.homepage: "www.google.bg"FF - prefs.js..extensions.enabledItems: avg@igeared:7.005.030.004FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1374FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:2.0FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7B0a39fc7f-d42b-4ff0-82a9-4c8b3e737d36%7D&mid=f1b63638aed18a771891905ba4517535-b60b068c4d1eaa979e5403bc9cfd8062c9d87e23&ds=AVG&v=11.0.0.9&lang=en&pr=fr&d=2012-05-11%2017%3A00%3A27&sap=ku&q="FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "AVG Secure Search"FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "AVG Secure Search"FF - prefs.js..browser.startup.homepage: "www.google.bg"FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll ()FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)FF - HKLM\Software\MozillaPlugins\@inhatch.com,version=0.7.2: C:\Program Files\InhatchTeam\Inhatch\npinhatch.dll File not foundFF - HKLM\Software\MozillaPlugins\@inhatch.com,version=0.7.5: C:\Program Files\InhatchTeam\Inhatch\npinhatch.dll File not foundFF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012.05.11 17:00:35 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\11.0.0.9\ [2012.05.04 13:37:41 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012.05.11 16:59:59 | 000,000,000 | ---D | M] [2010.04.21 03:22:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Extensions[2010.04.21 03:22:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}[2010.04.16 09:58:10 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\extensions[2010.04.16 09:58:10 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}[2012.05.11 12:21:30 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\extensions[2010.04.16 23:04:29 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}[2011.09.14 19:53:41 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}[2011.09.14 17:41:09 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\searchplugins\sweetim.xml[2012.05.12 17:48:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions[2012.04.01 19:51:42 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}[2011.06.23 21:37:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions[2011.06.23 21:37:35 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}[2012.05.04 13:37:41 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AVG SECURE SEARCH\11.0.0.9[2010.04.25 04:16:34 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll[2006.10.26 21:12:16 | 000,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL[2011.06.03 05:00:08 | 000,061,440 | ---- | M] (Element K Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOlp32.dll[2004.11.03 19:43:00 | 000,000,680 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.png[2012.05.11 17:00:25 | 000,003,766 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml[2004.11.03 19:43:00 | 000,000,356 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.png[2004.11.03 19:43:00 | 000,000,557 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\dictionary.png[2004.11.03 19:43:00 | 000,000,210 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.gif[2004.11.03 19:43:00 | 000,001,076 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.gif[2004.11.03 19:43:00 | 000,000,088 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.gif ========== Chrome ========== CHR - default_search_provider: AVG Secure Search (Enabled)CHR - default_search_provider: search_url = http://isearch.avg.c...fr&d=2012-05-11 17:00:27&v=11.0.0.9&sap=dsp&q={searchTerms}CHR - default_search_provider: suggest_url = http://clients5.goog...outputEncoding}CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewerCHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\ppGoogleNaClPluginChrome.dllCHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\pdf.dllCHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\gcswf32.dllCHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dllCHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\plugins/avgnpss.dllCHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dllCHR - plugin: Java Deployment Toolkit 6.0.180.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dllCHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLLCHR - plugin: Offline Course Player Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOlp32.dllCHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dllCHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dllCHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dllCHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dllCHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dllCHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dllCHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dllCHR - Extension: YouTube = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\CHR - Extension: Google \u0422\u044A\u0440\u0441\u0435\u043D\u0435 = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\CHR - Extension: AVG Safe Search = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\CHR - Extension: Skype Click to Call = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\CHR - Extension: AVG Do Not Track = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\CHR - Extension: Gmail = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2001.08.23 04:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hostsO1 - Hosts: 127.0.0.1 localhostO2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll ()O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not foundO3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll ()O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)O4 - HKLM..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)O4 - HKLM..\Run: [OLPSYNCH] C:\Program Files\Offline Course Player\OlpSynch.exe ()O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)O4 - HKLM..\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 File not foundO4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [skyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS snpstd3.exe (SONIX)O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()O4 - HKU\.DEFAULT..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)O4 - HKU\S-1-5-18..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [Google Update] C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe ()O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\WINDOWS\Datecs\Flex2K.exe ()O4 - Startup: C:\Documents and Settings\Mitko\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 85.11.187.1 85.11.160.15O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6126DBBF-0FEC-4DE0-AFF0-D72FBE92E8B2}: DhcpNameServer = 85.11.187.1 85.11.160.15O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\ipp - No CLSID value foundO18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\msdaipp - No CLSID value foundO18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler v {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.0.2\ViProtocol.dll ()O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter ext/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O18 - Protocol\Filter ext/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify ermsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)O24 - Desktop Components:0 (My Current Home Page) - About:HomeO24 - Desktop WallPaper: C:\Documents and Settings\Mitko\Local Settings\Application Data\Microsoft\Wallpaper1.bmpO24 - Desktop BackupWallPaper: C:\Documents and Settings\Mitko\Local Settings\Application Data\Microsoft\Wallpaper1.bmpO28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)O31 - SafeBoot: AlternateShell - cmd.exeO32 - HKLM CDRom: AutoRun - 1O32 - AutoRun File - [2010.04.16 06:53:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]O34 - HKLM BootExecute: (autocheck autochk *)O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)O35 - HKLM\..comfile [open] -- "%1" %*O35 - HKLM\..exefile [open] -- "%1" %*O37 - HKLM\...com [@ = comfile] -- "%1" %*O37 - HKLM\...exe [@ = exefile] -- "%1" %*O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not foundNetSvcs: Ias - File not foundNetSvcs: Iprip - File not foundNetSvcs: Irmon - File not foundNetSvcs: NWCWorkstation - File not foundNetSvcs: Nwsapagent - File not foundNetSvcs: WmdmPmSp - File not found NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not foundNetSvcs: Ias - File not foundNetSvcs: Iprip - File not foundNetSvcs: Irmon - File not foundNetSvcs: NWCWorkstation - File not foundNetSvcs: Nwsapagent - File not foundNetSvcs: WmdmPmSp - File not found SafeBootMin: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)SafeBootMin: Base - Driver GroupSafeBootMin: Boot Bus Extender - Driver GroupSafeBootMin: Boot file system - Driver GroupSafeBootMin: File system - Driver GroupSafeBootMin: Filter - Driver GroupSafeBootMin: PCI Configuration - Driver GroupSafeBootMin: PNP Filter - Driver GroupSafeBootMin: Primary disk - Driver GroupSafeBootMin: SCSI Class - Driver GroupSafeBootMin: sermouse.sys - DriverSafeBootMin: System Bus Extender - Driver GroupSafeBootMin: vga.sys - DriverSafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllersSafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM DriveSafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDriveSafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controllerSafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - HdcSafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - KeyboardSafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - MouseSafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA AdaptersSafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapterSafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - SystemSafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk driveSafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - VolumeSafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)SafeBootNet: Base - Driver GroupSafeBootNet: Boot Bus Extender - Driver GroupSafeBootNet: Boot file system - Driver GroupSafeBootNet: File system - Driver GroupSafeBootNet: Filter - Driver GroupSafeBootNet: NDIS Wrapper - Driver GroupSafeBootNet: NetBIOSGroup - Driver GroupSafeBootNet: NetDDEGroup - Driver GroupSafeBootNet: Network - Driver GroupSafeBootNet: NetworkProvider - Driver GroupSafeBootNet: nm - File not foundSafeBootNet: nm.sys - File not foundSafeBootNet: PCI Configuration - Driver GroupSafeBootNet: PNP Filter - Driver GroupSafeBootNet: PNP_TDI - Driver GroupSafeBootNet: Primary disk - Driver GroupSafeBootNet: SCSI Class - Driver GroupSafeBootNet: sermouse.sys - DriverSafeBootNet: Streams Drivers - Driver GroupSafeBootNet: System Bus Extender - Driver GroupSafeBootNet: TDI - Driver GroupSafeBootNet: vga.sys - DriverSafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllersSafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM DriveSafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDriveSafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controllerSafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - HdcSafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - KeyboardSafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - MouseSafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - NetSafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClientSafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetServiceSafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTransSafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA AdaptersSafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapterSafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - SystemSafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk driveSafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - VolumeSafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices ========== Files/Folders - Created Within 90 Days ========== [2012.05.12 18:20:31 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mitko\Desktop\OTL.exe[2012.05.12 18:06:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Application Data\Malwarebytes[2012.05.12 18:06:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware[2012.05.12 18:06:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes[2012.05.12 18:06:06 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys[2012.05.12 18:06:06 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware[2012.05.12 18:05:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Application Data\SUPERAntiSpyware.com[2012.05.12 18:05:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware[2012.05.12 18:04:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com[2012.05.12 18:04:54 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware[2012.05.12 17:49:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Local Settings\Application Data\Opera[2012.05.12 17:49:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Application Data\Opera[2012.05.12 17:49:19 | 000,000,000 | ---D | C] -- C:\Program Files\Opera[2012.05.11 21:44:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Start Menu\Programs\Google Chrome[2012.05.11 17:00:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search[2012.05.11 16:59:19 | 004,126,880 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe[2012.05.11 14:31:30 | 000,419,488 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe[2012.05.11 12:14:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla[2012.05.11 09:49:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel[2012.05.08 19:24:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Desktop\New Folder (3)[2012.05.04 13:37:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Local Settings\Application Data\AVG Secure Search[2012.05.04 13:37:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG[2012.04.19 04:50:26 | 000,024,896 | ---- | C] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\System32\drivers\avgidshx.sys[2012.04.16 10:37:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Desktop\New Folder (2)[2012.04.12 08:30:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Desktop\New Folder[2012.04.01 19:50:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype[2012.04.01 19:50:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype[2012.02.27 20:20:21 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Mitko\IECompatCache[2012.02.22 11:29:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Local Settings\Application Data\Element K[2012.02.22 11:12:20 | 000,000,000 | ---D | C] -- C:\Program Files\Offline Course Player[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ][1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ][1 C:\Documents and Settings\Mitko\Application Data\*.tmp files -> C:\Documents and Settings\Mitko\Application Data\*.tmp -> ] ========== Files - Modified Within 90 Days ========== [2012.05.12 18:42:37 | 098,041,082 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm[2012.05.12 18:38:19 | 000,001,078 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskUserS-1-5-21-1454471165-1123561945-839522115-1003UA.job[2012.05.12 18:30:29 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat[2012.05.12 18:20:32 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mitko\Desktop\OTL.exe[2012.05.12 18:16:14 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl[2012.05.12 18:06:13 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk[2012.05.12 18:05:00 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk[2012.05.12 17:59:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS asks\Adobe Flash Player Updater.job[2012.05.12 17:49:25 | 000,001,510 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk[2012.05.12 17:49:25 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk[2012.05.11 21:44:27 | 000,002,284 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\Google Chrome.lnk[2012.05.11 21:44:27 | 000,002,262 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk[2012.05.11 21:35:14 | 000,034,814 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\dt.dat[2012.05.11 17:00:35 | 000,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk[2012.05.11 16:59:39 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe[2012.05.11 16:59:39 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl[2012.05.11 16:59:19 | 004,126,880 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe[2012.05.11 07:38:05 | 000,001,026 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskUserS-1-5-21-1454471165-1123561945-839522115-1003Core.job[2012.05.11 00:52:56 | 000,133,316 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm[2012.05.10 05:38:12 | 000,005,632 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2012.05.08 19:34:23 | 047,993,083 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\New Folder (3).rar[2012.05.07 17:45:41 | 000,034,119 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\product_952.jpg[2012.05.05 17:20:57 | 000,051,386 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\Meridian_14___4e6f0962e2008.jpg[2012.04.24 12:03:01 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Untitled.alv[2012.04.19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\System32\drivers\avgidshx.sys[2012.04.17 10:36:21 | 000,151,718 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\160-Fantasy-Nature-Wallpaper.jpg[2012.04.17 10:29:46 | 000,378,375 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\fantasy-space-art-068.jpg[2012.04.05 06:36:47 | 000,314,842 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat[2012.04.05 06:36:47 | 000,041,170 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat[2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys[2012.03.19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys[2012.03.10 20:02:32 | 000,059,154 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Untitled-1.gif[2012.02.22 11:29:31 | 000,001,883 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\Microsoft E-Learning Offline Player.lnk[2012.02.22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ][1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ][1 C:\Documents and Settings\Mitko\Application Data\*.tmp files -> C:\Documents and Settings\Mitko\Application Data\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.05.12 18:06:13 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk[2012.05.12 18:05:00 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk[2012.05.12 17:49:25 | 000,001,510 | ---- | C] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk[2012.05.12 17:49:25 | 000,001,498 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk[2012.05.12 17:49:25 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk[2012.05.11 21:44:27 | 000,002,284 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\Google Chrome.lnk[2012.05.11 21:44:27 | 000,002,262 | ---- | C] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk[2012.05.11 21:35:14 | 000,034,814 | ---- | C] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\dt.dat[2012.05.11 14:31:30 | 000,000,830 | ---- | C] () -- C:\WINDOWS asks\Adobe Flash Player Updater.job[2012.05.08 19:32:26 | 047,993,083 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\New Folder (3).rar[2012.05.07 17:45:45 | 000,034,119 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\product_952.jpg[2012.05.05 17:20:58 | 000,051,386 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\Meridian_14___4e6f0962e2008.jpg[2012.05.04 13:37:44 | 000,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk[2012.04.24 12:03:01 | 000,000,630 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\Untitled.alv[2012.04.17 10:36:23 | 000,151,718 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\160-Fantasy-Nature-Wallpaper.jpg[2012.04.17 10:29:49 | 000,378,375 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\fantasy-space-art-068.jpg[2012.03.10 20:02:32 | 000,059,154 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\Untitled-1.gif[2012.02.22 11:29:31 | 000,001,889 | ---- | C] () -- C:\Documents and Settings\Mitko\Start Menu\Programs\Microsoft E-Learning Offline Player.lnk[2012.02.22 11:29:31 | 000,001,883 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\Microsoft E-Learning Offline Player.lnk[2011.11.19 21:45:45 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll[2011.09.29 07:20:59 | 000,843,776 | ---- | C] () -- C:\WINDOWS\vsnpstd3.exe[2011.09.29 07:20:59 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini[2011.09.29 07:20:56 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll[2011.09.29 07:20:56 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll[2011.09.29 07:20:56 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll[2011.09.29 07:20:56 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll[2011.07.03 05:53:27 | 000,001,890 | ---- | C] () -- C:\WINDOWS\compedia.ini[2010.11.15 08:00:39 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat[2010.11.13 23:12:05 | 000,000,172 | ---- | C] () -- C:\WINDOWS\wininit.ini ========== LOP Check ========== [2012.05.04 13:37:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search[2011.10.13 09:25:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012[2010.11.19 21:55:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9[2010.11.19 22:41:49 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files[2010.04.16 10:03:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations[2012.05.12 18:42:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData[2010.04.16 10:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite[2011.09.14 17:41:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SweetIM[2011.10.13 09:10:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\AVG Secure Search[2011.10.13 09:09:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\AVG2012[2010.07.26 21:51:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\AVG9[2010.04.16 09:58:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Foxit[2012.02.05 10:23:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Garmin[2011.03.15 23:20:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\goalbit[2010.04.16 10:04:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Nokia[2010.09.07 23:00:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Nokia Multimedia Player[2012.05.12 17:49:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Opera[2010.04.20 09:41:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\PC Suite[2010.04.23 03:15:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Thinstall[2012.05.11 20:39:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\uTorrent ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* >[2010.04.16 06:53:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT[2010.04.16 06:47:31 | 000,000,211 | -HS- | M] () -- C:\boot.ini[2010.04.16 06:53:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS[2010.04.16 06:53:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS[2010.04.16 06:53:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS[2004.08.03 12:38:34 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM[2004.08.03 12:59:34 | 000,250,032 | RHS- | M] () -- C:\ntldr[2012.05.12 18:30:25 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys[2011.07.10 13:57:12 | 000,000,408 | ---- | M] () -- C:\T2Exe.log < %USERPROFILE%\*.* >[2012.05.12 18:28:58 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\Mitko\ntuser.dat[2012.05.12 18:39:29 | 000,001,024 | -H-- | M] () -- C:\Documents and Settings\Mitko\ntuser.dat.LOG[2012.05.12 18:28:58 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Mitko\ntuser.ini < %USERPROFILE%\AppData\Local\*.* > < %USERPROFILE%\AppData\Roaming\*.* >Invalid Environment Variable: ProgramData < %CommonProgramFiles%\*.* > < %PROGRAMFILES%\*.* > < %systemroot%\system32\*.dll /lockedfiles >[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /90 >[2012.04.19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\system32\drivers\avgidshx.sys[2012.02.22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgldx86.sys[2012.03.19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgtdix.sys[2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\system32\Spool\prtprocs\w32x86\*.dll > < MD5 for: EXPLORER.EXE >[2004.08.03 14:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\explorer.exe[2004.08.03 14:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\system32\dllcache\explorer.exe < MD5 for: USERINIT.EXE >[2004.08.03 14:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\dllcache\userinit.exe[2004.08.03 14:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\userinit.exe < MD5 for: VOLSNAP.SYS >[2004.08.03 13:00:18 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B -- C:\WINDOWS\system32\dllcache\volsnap.sys[2004.08.03 13:00:18 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B -- C:\WINDOWS\system32\drivers\volsnap.sys < MD5 for: WINLOGON.EXE >[2004.08.03 14:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\dllcache\winlogon.exe[2004.08.03 14:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\winlogon.exe[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe < End of report > Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Май 13, 2012 Report Share Публикувано Май 13, 2012 Никой не е казал, че инструкциите са същите или че няма промени. Т.е. не е трябвало да бързаш да ги изпълняваш. Изтегли OTL и го запази на работния плот:- стартирай инструмента;- постави отметка в горната част на Scan All Users;- в поле Standard Registry избери All;- от падащо меню File Age избери 90 Days;- постави отметки още на: Skip Microsoft Files, LOP Check и Purity Check;- в поле Custom Scans/Fixes (в долната част на програмата) постави следния текст (маркирай го, натисни Ctrl+C и после в полето на OTL натисни Ctrl+V):netsvcs msconfig safebootminimal safebootnetwork "%WinDir%\$NtUninstallKB*$." /30 C:\Program Files\Common Files\ComObjects\*.* /s %SYSTEMDRIVE%\*.* %USERPROFILE%\*.* %USERPROFILE%\Application Data\*.* %USERPROFILE%\Local Settings\Application Data\*.* %AllUsersProfile%\*.* %AllUsersProfile%\Application Data\*.* %USERPROFILE%\My Documents\*.* %CommonProgramFiles%\*.* %PROGRAMFILES%\*.* %systemroot%\system32\config\systemprofile\*.* %windir%\ServiceProfiles\LocalService\AppData\Local\Temp\*.* %windir%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.* %windir% emp*.* %windir%\system32\*. %Temp%\smtmp\1\*.* %Temp%\smtmp\2\*.* %Temp%\smtmp\3\*.* %Temp%\smtmp\4\*.* %systemroot%\system32\DBBK\*.* /s %systemroot%\system32\*.dll /lockedfiles %systemroot%\Tasks\*.job /lockedfiles %systemroot%\system32\drivers\*.sys /90 %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\system32\Spool\prtprocs\w32x86\*.dll %systemroot%\*. /rp /s %systemroot%\assembly mp\*.* /S /MD5 %systemroot%\assembly emp\*.* /S /MD5 %systemroot%\assembly\GAC_32\*.* /S /MD5 %systemroot%\assembly\GAC_MSIL\*.* /S /MD5 >C:\commands.txt echo list vol /raw /hide /c /wait >C:\DiskReport.txt diskpart /s C:\commands.txt /raw /hide /c /wait type c:\diskreport.txt /c /wait erase c:\commands.txt /hide /c /wait erase c:\diskreport.txt /hide /c /md5start smss.exe winlogon.exe services.exe lsass.exe svchost.exe explorer.exe userinit.exe atapi.sys iaStor.sys serial.sys disk.sys volsnap.sys redbook.sys i8042prt.sys afd.sys netbt.sys tcpip.sys ipsec.sys hlp.dat /md5stop- кликни бутон Run Scan; След това прикачи новосъздадения файл OTL.txt и вече създадения при първото сканиране Extras.txt. Цитирай Link to comment Сподели другаде More sharing options...
Magdalena Tsoncheva Публикувано Май 13, 2012 Report Share Публикувано Май 13, 2012 Благодаря за бързия отговор! Ами да-прав си, никой не е казал, ама бързам и аз...ето съдържанието на новополучения OTL.txt:OTL logfile created on: 12.5.2012 г. 20:15:47 - Run 2OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Mitko\DesktopWindows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstationInternet Explorer (Version = 8.0.6001.18702)Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 1,99 Gb Total Physical Memory | 1,44 Gb Available Physical Memory | 72,47% Memory free3,84 Gb Paging File | 3,08 Gb Available in Paging File | 80,35% Paging File freePaging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 68,36 Gb Total Space | 22,10 Gb Free Space | 32,33% Space Free | Partition Type: NTFSDrive D: | 43,43 Gb Total Space | 14,42 Gb Free Space | 33,21% Space Free | Partition Type: NTFS Computer Name: MAGI | User Name: Mitko | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All usersCompany Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days ========== Processes (SafeList) ========== PRC - [2012.05.12 18:20:32 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mitko\Desktop\OTL.exePRC - [2012.05.12 17:49:20 | 000,949,104 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exePRC - [2012.05.11 17:00:26 | 001,116,544 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exePRC - [2012.05.04 13:37:37 | 000,932,736 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exePRC - [2012.05.01 09:48:04 | 003,905,920 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exePRC - [2012.04.30 09:44:38 | 005,106,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgidsagent.exePRC - [2012.04.19 04:51:54 | 001,254,992 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exePRC - [2012.04.05 05:12:34 | 002,587,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exePRC - [2012.03.19 05:18:12 | 000,979,840 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exePRC - [2012.02.14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exePRC - [2012.02.14 04:53:14 | 000,758,112 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exePRC - [2012.02.14 04:52:38 | 000,338,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exePRC - [2011.08.11 16:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exePRC - [2011.06.03 05:00:08 | 000,042,872 | ---- | M] () -- C:\Program Files\Offline Course Player\OlpSynch.exePRC - [2009.03.10 18:28:36 | 000,262,144 | ---- | M] (SONIX) -- C:\WINDOWS snpstd3.exePRC - [2007.11.22 12:49:08 | 000,385,024 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exePRC - [2007.11.09 13:16:24 | 000,688,128 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exePRC - [2007.11.06 09:36:34 | 000,352,768 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exePRC - [2007.11.06 06:38:46 | 000,009,216 | R--- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exePRC - [2007.10.26 08:55:58 | 000,122,880 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exePRC - [2007.10.23 10:03:00 | 000,117,248 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exePRC - [2007.10.09 22:28:32 | 000,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exePRC - [2006.09.18 14:12:12 | 000,843,776 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exePRC - [2006.06.13 06:20:00 | 000,127,036 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLACTRLW.EXEPRC - [2004.08.03 14:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exePRC - [2000.11.07 18:05:40 | 000,145,920 | ---- | M] () -- C:\WINDOWS\Datecs\Flex2K.exe ========== Modules (No Company Name) ========== MOD - [2012.05.12 19:42:00 | 000,065,024 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dllMOD - [2012.05.12 19:42:00 | 000,052,736 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dllMOD - [2012.05.12 18:05:34 | 000,117,760 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLLMOD - [2012.05.12 18:05:34 | 000,052,224 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dllMOD - [2012.05.12 17:49:25 | 000,783,360 | ---- | M] () -- C:\Program Files\Opera\gstreamer\gstreamer.dllMOD - [2012.05.12 17:49:25 | 000,316,928 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstoggdec.dllMOD - [2012.05.12 17:49:25 | 000,276,480 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwebmdec.dllMOD - [2012.05.12 17:49:25 | 000,168,448 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstffmpegcolorspace.dllMOD - [2012.05.12 17:49:25 | 000,099,840 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstcoreplugins.dllMOD - [2012.05.12 17:49:25 | 000,098,816 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioresample.dllMOD - [2012.05.12 17:49:25 | 000,098,816 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioconvert.dllMOD - [2012.05.12 17:49:25 | 000,078,336 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwavparse.dllMOD - [2012.05.12 17:49:25 | 000,076,800 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdirectsound.dllMOD - [2012.05.12 17:49:25 | 000,068,608 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdecodebin2.dllMOD - [2012.05.12 17:49:25 | 000,064,000 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstautodetect.dllMOD - [2012.05.12 17:49:25 | 000,046,592 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwaveform.dllMOD - [2012.05.12 17:49:25 | 000,045,568 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gsttypefindfunctions.dllMOD - [2012.05.11 17:00:26 | 001,116,544 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exeMOD - [2012.05.04 13:37:37 | 000,932,736 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exeMOD - [2012.05.04 13:37:37 | 000,130,944 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\SiteSafety.dllMOD - [2011.06.03 05:00:08 | 000,042,872 | ---- | M] () -- C:\Program Files\Offline Course Player\OlpSynch.exeMOD - [2007.11.09 13:16:24 | 000,688,128 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exeMOD - [2007.10.26 08:55:58 | 000,122,880 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exeMOD - [2007.10.23 10:03:00 | 000,117,248 | ---- | M] () -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exeMOD - [2007.10.09 22:28:32 | 000,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exeMOD - [2007.08.27 12:35:54 | 001,581,056 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\QtCore4.dllMOD - [2007.08.02 17:16:58 | 000,131,072 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\Imageformats\qjpeg4.dllMOD - [2007.08.02 17:05:42 | 006,402,048 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\QtGui4.dllMOD - [2007.08.02 16:51:54 | 000,356,352 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 6\QtXml4.dllMOD - [2006.09.18 14:12:12 | 000,843,776 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exeMOD - [2000.11.07 18:05:40 | 000,145,920 | ---- | M] () -- C:\WINDOWS\Datecs\Flex2K.exeMOD - [2000.10.19 00:03:34 | 000,028,672 | ---- | M] () -- C:\WINDOWS\system32\newdll.dll ========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)SRV - [2012.05.11 16:59:42 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)SRV - [2012.05.04 13:37:37 | 000,932,736 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe -- (vToolbarUpdater11.0.2)SRV - [2012.04.30 09:44:38 | 005,106,744 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgidsagent.exe -- (AVGIDSAgent)SRV - [2012.02.29 08:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)SRV - [2012.02.14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)SRV - [2012.02.01 08:51:01 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)SRV - [2011.08.11 16:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore.exe -- (!SASCORE)SRV - [2007.11.06 09:36:34 | 000,352,768 | ---- | M] (Nokia.) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)SRV - [2007.11.06 06:38:46 | 000,009,216 | R--- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)DRV - File not found [Kernel | System | Stopped] -- -- (Changer)DRV - [2012.04.19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\avgidshx.sys -- (AVGIDSHX)DRV - [2012.03.19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)DRV - [2012.02.22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)DRV - [2012.01.31 04:46:50 | 000,031,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avgrkx86.sys -- (Avgrkx86)DRV - [2011.12.23 13:32:14 | 000,041,040 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)DRV - [2011.12.23 13:32:08 | 000,017,232 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsshimx.sys -- (AVGIDSShim)DRV - [2011.12.23 13:32:06 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsfilterx.sys -- (AVGIDSFilter)DRV - [2011.12.23 13:32:00 | 000,139,856 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)DRV - [2011.07.22 09:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)DRV - [2011.07.12 14:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)DRV - [2009.03.25 15:29:52 | 000,130,432 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)DRV - [2008.05.01 21:15:44 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)DRV - [2007.11.28 01:02:43 | 000,007,680 | ---- | M] (ATK0100) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor)DRV - [2007.11.19 19:06:16 | 010,246,400 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)DRV - [2007.11.06 06:41:42 | 000,264,576 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8187B.sys -- (RTL8187B)DRV - [2007.11.06 06:40:12 | 004,608,000 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)DRV - [2007.11.06 06:38:44 | 001,161,888 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)DRV - [2007.02.22 10:15:56 | 000,137,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcd.sys -- (nmwcd)DRV - [2007.02.22 10:15:14 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcm.sys -- (nmwcdcm)DRV - [2007.02.22 10:15:14 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcj.sys -- (nmwcdcj)DRV - [2007.02.22 10:15:14 | 000,008,320 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdc.sys -- (nmwcdc)DRV - [2006.06.13 06:20:00 | 000,094,460 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)DRV - [2006.06.13 06:20:00 | 000,088,476 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)DRV - [2006.06.13 06:20:00 | 000,086,844 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)DRV - [2006.06.13 06:20:00 | 000,025,724 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)DRV - [2006.06.13 06:20:00 | 000,014,716 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)DRV - [2006.06.13 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)DRV - [2006.06.13 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)DRV - [2006.03.17 09:35:24 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)DRV - [2006.03.17 09:34:46 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)DRV - [2004.08.03 15:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)DRV - [2004.08.03 13:07:46 | 000,223,616 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers cpip6.sys -- (Tcpip6) ========== Standard Registry (All) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-onsIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRiskIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=101699&gct=&gc=1&q=IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htmIE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htmIE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearchIE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.bg/IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value foundIE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll ()IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRCIE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={DF009E60-C8C3-4EAF-9CBA-D4BAEF07B9D8}&mid=f1b63638aed18a771891905ba4517535-b60b068c4d1eaa979e5403bc9cfd8062c9d87e23&lang=en&ds=AVG&pr=fr&d=2012-05-11 17:00:27&v=11.0.0.9&sap=dsp&q={searchTerms}IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedirect?gct=&gc=1&q={searchTerms}&crm=1&toolbar=FXTIE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"FF - prefs.js..browser.search.defaulturl: ""FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"FF - prefs.js..browser.startup.homepage: "www.google.bg"FF - prefs.js..extensions.enabledItems: avg@igeared:7.005.030.004FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1374FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:2.0FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7B0a39fc7f-d42b-4ff0-82a9-4c8b3e737d36%7D&mid=f1b63638aed18a771891905ba4517535-b60b068c4d1eaa979e5403bc9cfd8062c9d87e23&ds=AVG&v=11.0.0.9&lang=en&pr=fr&d=2012-05-11%2017%3A00%3A27&sap=ku&q="FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "AVG Secure Search"FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "AVG Secure Search"FF - prefs.js..browser.startup.homepage: "www.google.bg"FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll ()FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)FF - HKLM\Software\MozillaPlugins\@inhatch.com,version=0.7.2: C:\Program Files\InhatchTeam\Inhatch\npinhatch.dll File not foundFF - HKLM\Software\MozillaPlugins\@inhatch.com,version=0.7.5: C:\Program Files\InhatchTeam\Inhatch\npinhatch.dll File not foundFF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012.05.11 17:00:35 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\11.0.0.9\ [2012.05.04 13:37:41 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012.05.11 16:59:59 | 000,000,000 | ---D | M] [2010.04.21 03:22:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Extensions[2010.04.21 03:22:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}[2010.04.16 09:58:10 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\extensions[2010.04.16 09:58:10 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}[2012.05.11 12:21:30 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\extensions[2010.04.16 23:04:29 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}[2011.09.14 19:53:41 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}[2011.09.14 17:41:09 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\Mozilla\Firefox\Profiles\wpbiru71.default\searchplugins\sweetim.xml[2012.05.12 17:48:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions[2012.04.01 19:51:42 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}[2011.06.23 21:37:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions[2011.06.23 21:37:35 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}[2012.05.04 13:37:41 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AVG SECURE SEARCH\11.0.0.9[2010.04.25 04:16:34 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll[2006.10.26 21:12:16 | 000,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL[2011.06.03 05:00:08 | 000,061,440 | ---- | M] (Element K Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOlp32.dll[2004.11.03 19:43:00 | 000,000,680 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.png[2012.05.11 17:00:25 | 000,003,766 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml[2004.11.03 19:43:00 | 000,000,356 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.png[2004.11.03 19:43:00 | 000,000,557 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\dictionary.png[2004.11.03 19:43:00 | 000,000,210 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.gif[2004.11.03 19:43:00 | 000,001,076 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.gif[2004.11.03 19:43:00 | 000,000,088 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.gif ========== Chrome ========== CHR - default_search_provider: AVG Secure Search (Enabled)CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={DF009E60-C8C3-4EAF-9CBA-D4BAEF07B9D8}&mid=f1b63638aed18a771891905ba4517535-b60b068c4d1eaa979e5403bc9cfd8062c9d87e23&lang=en&ds=AVG&pr=fr&d=2012-05-11 17:00:27&v=11.0.0.9&sap=dsp&q={searchTerms}CHR - default_search_provider: suggest_url = http://clients5.google.com/complete/search?hl={language}&q={searchTerms}&client=ie8&inputencoding={inputEncoding}&outputencoding={outputEncoding}CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewerCHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\ppGoogleNaClPluginChrome.dllCHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\pdf.dllCHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\gcswf32.dllCHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dllCHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dllCHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\plugins/avgnpss.dllCHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dllCHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dllCHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dllCHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dllCHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dllCHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dllCHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dllCHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dllCHR - Extension: YouTube = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\CHR - Extension: Google \u0422\u044A\u0440\u0441\u0435\u043D\u0435 = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\CHR - Extension: AVG Safe Search = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\CHR - Extension: Skype Click to Call = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\CHR - Extension: AVG Do Not Track = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\CHR - Extension: Gmail = C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2012.05.12 19:39:05 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\HostsO1 - Hosts: 127.0.0.1 localhostO1 - Hosts: ::1 localhostO2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll ()O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not foundO3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll ()O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O3 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)O4 - HKLM..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)O4 - HKLM..\Run: [OLPSYNCH] C:\Program Files\Offline Course Player\OlpSynch.exe ()O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)O4 - HKLM..\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 File not foundO4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [skyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS snpstd3.exe (SONIX)O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()O4 - HKU\.DEFAULT..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)O4 - HKU\S-1-5-18..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [Google Update] C:\Documents and Settings\Mitko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe ()O4 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\WINDOWS\Datecs\Flex2K.exe ()O4 - Startup: C:\Documents and Settings\Mitko\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 85.11.187.1 85.11.160.15O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6126DBBF-0FEC-4DE0-AFF0-D72FBE92E8B2}: DhcpNameServer = 85.11.187.1 85.11.160.15O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\ipp - No CLSID value foundO18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\msdaipp - No CLSID value foundO18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler v {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.0.2\ViProtocol.dll ()O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter ext/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O18 - Protocol\Filter ext/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify ermsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)O24 - Desktop Components:0 (My Current Home Page) - About:HomeO24 - Desktop WallPaper: C:\Documents and Settings\Mitko\Local Settings\Application Data\Microsoft\Wallpaper1.bmpO24 - Desktop BackupWallPaper: C:\Documents and Settings\Mitko\Local Settings\Application Data\Microsoft\Wallpaper1.bmpO28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)O31 - SafeBoot: AlternateShell - cmd.exeO32 - HKLM CDRom: AutoRun - 1O32 - AutoRun File - [2010.04.16 06:53:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]O34 - HKLM BootExecute: (autocheck autochk *)O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)O35 - HKLM\..comfile [open] -- "%1" %*O35 - HKLM\..exefile [open] -- "%1" %*O37 - HKLM\...com [@ = comfile] -- "%1" %*O37 - HKLM\...exe [@ = exefile] -- "%1" %*O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not foundNetSvcs: Ias - File not foundNetSvcs: Iprip - File not foundNetSvcs: Irmon - File not foundNetSvcs: NWCWorkstation - File not foundNetSvcs: Nwsapagent - File not foundNetSvcs: WmdmPmSp - File not found SafeBootMin: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)SafeBootMin: Base - Driver GroupSafeBootMin: Boot Bus Extender - Driver GroupSafeBootMin: Boot file system - Driver GroupSafeBootMin: File system - Driver GroupSafeBootMin: Filter - Driver GroupSafeBootMin: PCI Configuration - Driver GroupSafeBootMin: PNP Filter - Driver GroupSafeBootMin: Primary disk - Driver GroupSafeBootMin: SCSI Class - Driver GroupSafeBootMin: sermouse.sys - DriverSafeBootMin: System Bus Extender - Driver GroupSafeBootMin: vga.sys - DriverSafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllersSafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM DriveSafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDriveSafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controllerSafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - HdcSafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - KeyboardSafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - MouseSafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA AdaptersSafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapterSafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - SystemSafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk driveSafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - VolumeSafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)SafeBootNet: Base - Driver GroupSafeBootNet: Boot Bus Extender - Driver GroupSafeBootNet: Boot file system - Driver GroupSafeBootNet: File system - Driver GroupSafeBootNet: Filter - Driver GroupSafeBootNet: NDIS Wrapper - Driver GroupSafeBootNet: NetBIOSGroup - Driver GroupSafeBootNet: NetDDEGroup - Driver GroupSafeBootNet: Network - Driver GroupSafeBootNet: NetworkProvider - Driver GroupSafeBootNet: nm - File not foundSafeBootNet: nm.sys - File not foundSafeBootNet: PCI Configuration - Driver GroupSafeBootNet: PNP Filter - Driver GroupSafeBootNet: PNP_TDI - Driver GroupSafeBootNet: Primary disk - Driver GroupSafeBootNet: SCSI Class - Driver GroupSafeBootNet: sermouse.sys - DriverSafeBootNet: Streams Drivers - Driver GroupSafeBootNet: System Bus Extender - Driver GroupSafeBootNet: TDI - Driver GroupSafeBootNet: vga.sys - DriverSafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllersSafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM DriveSafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDriveSafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controllerSafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - HdcSafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - KeyboardSafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - MouseSafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - NetSafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClientSafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetServiceSafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTransSafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA AdaptersSafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapterSafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - SystemSafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk driveSafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - VolumeSafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices ========== Files/Folders - Created Within 90 Days ========== [2012.05.12 18:56:41 | 000,000,000 | ---D | C] -- C:\_OTL[2012.05.12 18:20:31 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mitko\Desktop\OTL.exe[2012.05.12 18:06:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Application Data\Malwarebytes[2012.05.12 18:06:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware[2012.05.12 18:06:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes[2012.05.12 18:06:06 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys[2012.05.12 18:06:06 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware[2012.05.12 18:05:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Application Data\SUPERAntiSpyware.com[2012.05.12 18:05:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware[2012.05.12 18:04:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com[2012.05.12 18:04:54 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware[2012.05.12 17:49:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Local Settings\Application Data\Opera[2012.05.12 17:49:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Application Data\Opera[2012.05.12 17:49:19 | 000,000,000 | ---D | C] -- C:\Program Files\Opera[2012.05.11 21:44:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Start Menu\Programs\Google Chrome[2012.05.11 17:00:26 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search[2012.05.11 16:59:19 | 004,126,880 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe[2012.05.11 14:31:30 | 000,419,488 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe[2012.05.11 12:14:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla[2012.05.11 09:49:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel[2012.05.08 19:24:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Desktop\New Folder (3)[2012.05.04 13:37:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Local Settings\Application Data\AVG Secure Search[2012.05.04 13:37:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG[2012.04.19 04:50:26 | 000,024,896 | ---- | C] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\System32\drivers\avgidshx.sys[2012.04.16 10:37:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Desktop\New Folder (2)[2012.04.12 08:30:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Desktop\New Folder[2012.04.01 19:50:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype[2012.04.01 19:50:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype[2012.02.27 20:20:21 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Mitko\IECompatCache[2012.02.22 11:29:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mitko\Local Settings\Application Data\Element K[2012.02.22 11:12:20 | 000,000,000 | ---D | C] -- C:\Program Files\Offline Course Player[1 C:\Documents and Settings\Mitko\Application Data\*.tmp files -> C:\Documents and Settings\Mitko\Application Data\*.tmp -> ] ========== Files - Modified Within 90 Days ========== [2012.05.12 19:59:15 | 000,000,830 | ---- | M] () -- C:\WINDOWS asks\Adobe Flash Player Updater.job[2012.05.12 19:41:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat[2012.05.12 19:39:05 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts[2012.05.12 19:38:00 | 000,001,078 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskUserS-1-5-21-1454471165-1123561945-839522115-1003UA.job[2012.05.12 18:42:37 | 098,041,082 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm[2012.05.12 18:20:32 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mitko\Desktop\OTL.exe[2012.05.12 18:16:14 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl[2012.05.12 18:06:13 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk[2012.05.12 18:05:00 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk[2012.05.12 17:49:25 | 000,001,510 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk[2012.05.12 17:49:25 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk[2012.05.11 21:44:27 | 000,002,284 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\Google Chrome.lnk[2012.05.11 21:44:27 | 000,002,262 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk[2012.05.11 21:35:14 | 000,034,814 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\dt.dat[2012.05.11 17:00:35 | 000,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk[2012.05.11 16:59:39 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe[2012.05.11 16:59:39 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl[2012.05.11 16:59:19 | 004,126,880 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe[2012.05.11 07:38:05 | 000,001,026 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskUserS-1-5-21-1454471165-1123561945-839522115-1003Core.job[2012.05.11 00:52:56 | 000,133,316 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm[2012.05.10 05:38:12 | 000,005,632 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2012.05.08 19:34:23 | 047,993,083 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\New Folder (3).rar[2012.05.07 17:45:41 | 000,034,119 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\product_952.jpg[2012.05.05 17:20:57 | 000,051,386 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\Meridian_14___4e6f0962e2008.jpg[2012.04.24 12:03:01 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Untitled.alv[2012.04.19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\System32\drivers\avgidshx.sys[2012.04.17 10:36:21 | 000,151,718 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\160-Fantasy-Nature-Wallpaper.jpg[2012.04.17 10:29:46 | 000,378,375 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\fantasy-space-art-068.jpg[2012.04.05 06:36:47 | 000,314,842 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat[2012.04.05 06:36:47 | 000,041,170 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat[2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys[2012.03.19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys[2012.03.10 20:02:32 | 000,059,154 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Untitled-1.gif[2012.02.22 11:29:31 | 000,001,883 | ---- | M] () -- C:\Documents and Settings\Mitko\Desktop\Microsoft E-Learning Offline Player.lnk[2012.02.22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys[1 C:\Documents and Settings\Mitko\Application Data\*.tmp files -> C:\Documents and Settings\Mitko\Application Data\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.05.12 18:06:13 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk[2012.05.12 18:05:00 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk[2012.05.12 17:49:25 | 000,001,510 | ---- | C] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk[2012.05.12 17:49:25 | 000,001,498 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk[2012.05.12 17:49:25 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk[2012.05.11 21:44:27 | 000,002,284 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\Google Chrome.lnk[2012.05.11 21:44:27 | 000,002,262 | ---- | C] () -- C:\Documents and Settings\Mitko\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk[2012.05.11 21:35:14 | 000,034,814 | ---- | C] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\dt.dat[2012.05.11 14:31:30 | 000,000,830 | ---- | C] () -- C:\WINDOWS asks\Adobe Flash Player Updater.job[2012.05.08 19:32:26 | 047,993,083 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\New Folder (3).rar[2012.05.07 17:45:45 | 000,034,119 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\product_952.jpg[2012.05.05 17:20:58 | 000,051,386 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\Meridian_14___4e6f0962e2008.jpg[2012.05.04 13:37:44 | 000,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk[2012.04.24 12:03:01 | 000,000,630 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\Untitled.alv[2012.04.17 10:36:23 | 000,151,718 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\160-Fantasy-Nature-Wallpaper.jpg[2012.04.17 10:29:49 | 000,378,375 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\fantasy-space-art-068.jpg[2012.03.10 20:02:32 | 000,059,154 | ---- | C] () -- C:\Documents and Settings\Mitko\My Documents\Untitled-1.gif[2012.02.22 11:29:31 | 000,001,889 | ---- | C] () -- C:\Documents and Settings\Mitko\Start Menu\Programs\Microsoft E-Learning Offline Player.lnk[2012.02.22 11:29:31 | 000,001,883 | ---- | C] () -- C:\Documents and Settings\Mitko\Desktop\Microsoft E-Learning Offline Player.lnk[2011.11.19 21:45:45 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll[2011.09.29 07:20:59 | 000,843,776 | ---- | C] () -- C:\WINDOWS\vsnpstd3.exe[2011.09.29 07:20:59 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini[2011.09.29 07:20:56 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll[2011.09.29 07:20:56 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll[2011.09.29 07:20:56 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll[2011.09.29 07:20:56 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll[2011.07.03 05:53:27 | 000,001,890 | ---- | C] () -- C:\WINDOWS\compedia.ini[2010.11.15 08:00:39 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat[2010.11.13 23:12:05 | 000,000,172 | ---- | C] () -- C:\WINDOWS\wininit.ini ========== LOP Check ========== [2012.05.04 13:37:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search[2011.10.13 09:25:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012[2010.11.19 21:55:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9[2010.11.19 22:41:49 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files[2010.04.16 10:03:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations[2012.05.12 18:42:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData[2010.04.16 10:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite[2011.09.14 17:41:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SweetIM[2011.10.13 09:10:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\AVG Secure Search[2011.10.13 09:09:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\AVG2012[2010.07.26 21:51:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\AVG9[2010.04.16 09:58:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Foxit[2012.02.05 10:23:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Garmin[2011.03.15 23:20:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\goalbit[2010.04.16 10:04:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Nokia[2010.09.07 23:00:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Nokia Multimedia Player[2012.05.12 17:49:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Opera[2010.04.20 09:41:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\PC Suite[2010.04.23 03:15:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\Thinstall[2012.05.12 19:38:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mitko\Application Data\uTorrent ========== Purity Check ========== ========== Custom Scans ========== < "%WinDir%\$NtUninstallKB*$." /30 > < C:\Program Files\Common Files\ComObjects\*.* /s > < %SYSTEMDRIVE%\*.* >[2010.04.16 06:53:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT[2010.04.16 06:47:31 | 000,000,211 | -HS- | M] () -- C:\boot.ini[2010.04.16 06:53:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS[2010.04.16 06:53:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS[2010.04.16 06:53:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS[2004.08.03 12:38:34 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM[2004.08.03 12:59:34 | 000,250,032 | RHS- | M] () -- C:\ntldr[2012.05.12 19:41:02 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys[2011.07.10 13:57:12 | 000,000,408 | ---- | M] () -- C:\T2Exe.log < %USERPROFILE%\*.* >[2012.05.12 19:39:40 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\Mitko\ntuser.dat[2012.05.12 20:13:51 | 000,001,024 | -H-- | M] () -- C:\Documents and Settings\Mitko\ntuser.dat.LOG[2012.05.12 19:39:37 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Mitko\ntuser.ini < %USERPROFILE%\Application Data\*.* >[2010.08.03 09:31:11 | 001,031,680 | ---- | M] (http://mediainfo.sourceforge.net) -- C:\Documents and Settings\Mitko\Application Data\analyzer.bin[2010.04.16 01:42:07 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Mitko\Application Data\desktop.ini[2010.04.16 23:13:30 | 006,328,832 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\engine.bin[2011.08.17 00:54:44 | 000,000,095 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\engine.dsc[2010.04.16 23:13:24 | 000,746,232 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\engine2.bin[2010.04.16 23:13:24 | 000,614,648 | ---- | M] () -- C:\Documents and Settings\Mitko\Application Data\engine3.bin[1 C:\Documents and Settings\Mitko\Application Data\*.tmp files -> C:\Documents and Settings\Mitko\Application Data\*.tmp -> ] < %USERPROFILE%\Local Settings\Application Data\*.* >[2012.05.10 05:38:12 | 000,005,632 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2012.05.11 21:35:14 | 000,034,814 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\dt.dat[2012.02.01 09:39:34 | 000,070,000 | ---- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\GDIPFONTCACHEV1.DAT[2010.11.13 23:13:05 | 007,432,338 | -H-- | M] () -- C:\Documents and Settings\Mitko\Local Settings\Application Data\IconCache.db < %AllUsersProfile%\*.* > < %AllUsersProfile%\Application Data\*.* >[2010.04.16 01:42:08 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini < %USERPROFILE%\My Documents\*.* >[2012.04.17 10:36:21 | 000,151,718 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\160-Fantasy-Nature-Wallpaper.jpg[2012.01.27 06:00:08 | 000,000,076 | -HS- | M] () -- C:\Documents and Settings\Mitko\My Documents\desktop.ini[2012.04.17 10:29:46 | 000,378,375 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\fantasy-space-art-068.jpg[2012.05.12 18:14:26 | 000,004,296 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\mbam-log-2012-05-12 (18-07-41).txt[2012.04.21 17:08:05 | 000,052,224 | -HS- | M] () -- C:\Documents and Settings\Mitko\My Documents\Thumbs.db[2012.03.10 20:02:32 | 000,059,154 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Untitled-1.gif[2012.04.24 12:03:01 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Untitled.alv[2011.11.08 12:29:57 | 000,000,188 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\Митко-бс.txt[2011.11.22 11:44:03 | 000,011,802 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\ОФЕРТА.dotx[2011.12.09 05:52:47 | 000,075,484 | ---- | M] () -- C:\Documents and Settings\Mitko\My Documents\рецепта.rtf < %CommonProgramFiles%\*.* > < %PROGRAMFILES%\*.* > < %systemroot%\system32\config\systemprofile\*.* >[2011.06.22 20:32:47 | 000,249,856 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\ntuser.dat < %windir%\ServiceProfiles\LocalService\AppData\Local\Temp\*.* > < %windir%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.* > < %windir% emp*.* > < %windir%\system32\*. >[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1025[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1028[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1031[2010.04.16 01:27:19 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1033[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1037[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1041[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1042[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1054[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\2052[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\3076[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\3com_dmi[2010.06.20 10:18:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\appmgmt[2012.03.12 10:02:58 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\cache[2012.02.01 08:28:43 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\CatRoot[2012.05.12 19:42:11 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\CatRoot2[2010.04.16 06:49:39 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Com[2012.05.05 22:12:09 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\dhcp[2010.11.13 23:12:29 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\DirectX[2010.11.13 23:12:05 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\DLA[2012.05.11 16:59:13 | 000,000,000 | RHSD | M] -- C:\WINDOWS\system32\dllcache[2012.05.12 19:37:20 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\drivers[2010.04.16 10:04:26 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\DRVSTORE[2012.01.27 05:55:39 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\en-US[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\export[2010.04.16 06:52:28 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ias[2010.04.16 01:27:50 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\icsxml[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\IME[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\inetsrv[2010.04.16 07:42:08 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Lang[2010.04.16 06:50:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Macromed[2010.04.16 07:00:04 | 000,000,000 | --SD | M] -- C:\WINDOWS\system32\Microsoft[2010.04.16 06:49:32 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\MsDtc[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\mui[2010.04.16 01:29:33 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\npp[2010.04.16 06:51:09 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\oobe[2010.04.16 01:27:56 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ras[2011.11.19 21:45:52 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ReinstallBackups[2011.06.23 21:39:05 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Restore[2010.04.16 07:51:56 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\RTCOM[2010.04.16 01:30:30 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Setup[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ShellExt[2010.04.16 06:47:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\spool[2010.04.16 01:30:32 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\usmt[2012.05.05 22:11:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\wbem[2010.04.16 01:26:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\wins[2010.04.16 07:42:08 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\x64[2010.04.16 06:53:17 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\xircom < %Temp%\smtmp\1\*.* > < %Temp%\smtmp\2\*.* > < %Temp%\smtmp\3\*.* > < %Temp%\smtmp\4\*.* > < %systemroot%\system32\DBBK\*.* /s > < %systemroot%\system32\*.dll /lockedfiles > < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /90 >[2012.04.19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\system32\drivers\avgidshx.sys[2012.02.22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgldx86.sys[2012.03.19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgtdix.sys[2012.04.04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\system32\Spool\prtprocs\w32x86\*.dll > < %systemroot%\*. /rp /s > < %systemroot%\assembly mp\*.* /S /MD5 > < %systemroot%\assembly emp\*.* /S /MD5 > < %systemroot%\assembly\GAC_32\*.* /S /MD5 > < %systemroot%\assembly\GAC_MSIL\*.* /S /MD5 > < type c:\diskreport.txt /c >Microsoft DiskPart version 5.1.3565Copyright © 1999-2003 Microsoft Corporation.On computer: MAGIVolume ### Ltr Label Fs Type Size Status Info---------- --- ----------- ----- ---------- ------- --------- --------Volume 0 E DVD-ROM 0 BVolume 1 C NTFS Partition 68 GB Healthy SystemVolume 2 D NTFS Partition 43 GB Healthy < MD5 for: AFD.SYS >[2004.08.03 13:14:16 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=5AC495F4CB807B2B98AD2AD591E6D92E -- C:\WINDOWS\system32\dllcache\afd.sys[2004.08.03 13:14:16 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=5AC495F4CB807B2B98AD2AD591E6D92E -- C:\WINDOWS\system32\drivers\afd.sys < MD5 for: ATAPI.SYS >[2004.08.03 15:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys[2004.08.03 15:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys < MD5 for: DISK.SYS >[2004.08.03 15:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys[2004.08.03 12:59:56 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\system32\drivers\disk.sys < MD5 for: EXPLORER.EXE >[2004.08.03 14:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\explorer.exe[2004.08.03 14:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\system32\dllcache\explorer.exe < MD5 for: I8042PRT.SYS >[2004.08.03 15:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:i8042prt.sys[2004.08.03 13:14:38 | 000,052,736 | ---- | M] (Microsoft Corporation) MD5=5502B58EEF7486EE6F93F3F164DCB808 -- C:\WINDOWS\system32\drivers\i8042prt.sys < MD5 for: IASTOR.SYS >[2007.11.28 01:02:46 | 000,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- C:\WINDOWS\NLDRV\004\iastor.sys[2007.12.03 02:06:50 | 000,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- C:\WINDOWS\NLDRV\009\iastor.sys[2007.12.03 02:06:50 | 000,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- C:\WINDOWS\system32\drivers\iaStor.sys < MD5 for: IPSEC.SYS >[2004.08.03 13:14:30 | 000,074,752 | ---- | M] (Microsoft Corporation) MD5=64537AA5C003A6AFEEE1DF819062D0D1 -- C:\WINDOWS\system32\dllcache\ipsec.sys[2004.08.03 13:14:30 | 000,074,752 | ---- | M] (Microsoft Corporation) MD5=64537AA5C003A6AFEEE1DF819062D0D1 -- C:\WINDOWS\system32\drivers\ipsec.sys < MD5 for: LSASS.EXE >[2004.08.03 14:56:52 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=84885F9B82F4D55C6146EBF6065D75D2 -- C:\WINDOWS\system32\dllcache\lsass.exe[2004.08.03 14:56:52 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=84885F9B82F4D55C6146EBF6065D75D2 -- C:\WINDOWS\system32\lsass.exe < MD5 for: NETBT.SYS >[2004.08.03 13:14:38 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=0C80E410CD2F47134407EE7DD19CC86B -- C:\WINDOWS\system32\dllcache\netbt.sys[2004.08.03 13:14:38 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=0C80E410CD2F47134407EE7DD19CC86B -- C:\WINDOWS\system32\drivers\netbt.sys < MD5 for: REDBOOK.SYS >[2004.08.03 15:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:redbook.sys[2004.08.03 15:59:38 | 000,057,472 | ---- | M] (Microsoft Corporation) MD5=B31B4588E4086D8D84ADBF9845C2402B -- C:\WINDOWS\system32\drivers\redbook.sys < MD5 for: SERIAL.SYS >[2004.08.03 15:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:serial.sys[2004.08.03 13:15:54 | 000,064,896 | ---- | M] (Microsoft Corporation) MD5=CD9404D115A00D249F70A371B46D5A26 -- C:\WINDOWS\system32\drivers\serial.sys < MD5 for: SERVICES.EXE >[2004.08.03 14:56:56 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\WINDOWS\system32\dllcache\services.exe[2004.08.03 14:56:56 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\WINDOWS\system32\services.exe < MD5 for: SMSS.EXE >[2004.08.03 14:56:58 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=BD7FB0957C716F1A60333AEE04DE2178 -- C:\WINDOWS\system32\dllcache\smss.exe[2004.08.03 14:56:58 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=BD7FB0957C716F1A60333AEE04DE2178 -- C:\WINDOWS\system32\smss.exe < MD5 for: SVCHOST.EXE >[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe[2004.08.03 14:56:58 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\system32\dllcache\svchost.exe[2004.08.03 14:56:58 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\system32\svchost.exe < MD5 for: TCPIP.SYS >[2004.08.03 13:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\system32\dllcache cpip.sys[2004.08.03 13:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\system32\drivers cpip.sys < MD5 for: USERINIT.EXE >[2004.08.03 14:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\dllcache\userinit.exe[2004.08.03 14:56:58 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\system32\userinit.exe < MD5 for: VOLSNAP.SYS >[2004.08.03 13:00:18 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B -- C:\WINDOWS\system32\dllcache\volsnap.sys[2004.08.03 13:00:18 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B -- C:\WINDOWS\system32\drivers\volsnap.sys < MD5 for: WINLOGON.EXE >[2004.08.03 14:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\dllcache\winlogon.exe[2004.08.03 14:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\winlogon.exe[2012.04.04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe < End of report > ето и Extras.txt:OTL Extras logfile created on: 12.5.2012 г. 18:35:56 - Run 1OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Mitko\DesktopWindows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstationInternet Explorer (Version = 8.0.6001.18702)Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 1,99 Gb Total Physical Memory | 1,23 Gb Available Physical Memory | 61,94% Memory free3,84 Gb Paging File | 3,12 Gb Available in Paging File | 81,38% Paging File freePaging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 68,36 Gb Total Space | 20,82 Gb Free Space | 30,46% Space Free | Partition Type: NTFSDrive D: | 43,43 Gb Total Space | 14,42 Gb Free Space | 33,21% Space Free | Partition Type: NTFS Computer Name: MAGI | User Name: Mitko | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All usersCompany Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>].cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software) [HKEY_USERS\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Classes\<extension>].html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]batfile [open] -- "%1" %*cmdfile [open] -- "%1" %*comfile [open] -- "%1" %*cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*exefile [open] -- "%1" %*htmlfile [edit] -- Reg Error: Key error.http [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)https [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)piffile [open] -- "%1" %*regfile [merge] -- Reg Error: Key error.scrfile [config] -- "%1"scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %lscrfile [open] -- "%1" /Stxtfile [edit] -- Reg Error: Key error.Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]"FirstRunDisabled" = 1"AntiVirusDisableNotify" = 0"FirewallDisableNotify" = 1"UpdatesDisableNotify" = 1"AntiVirusOverride" = 0"FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]"DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]"Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]"Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]"EnableFirewall" = 1"DoNotAllowExceptions" = 0"DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008"2706:TCP" = 2706:TCP:*:Enabled:Inhatch P2P Streaming"2707:TCP" = 2707:TCP:*:Enabled:Inhatch P2P Streaming"2708:TCP" = 2708:TCP:*:Enabled:Inhatch P2P Streaming"2709:TCP" = 2709:TCP:*:Enabled:Inhatch P2P Streaming ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)"C:\Documents and Settings\Mitko\My Documents\Downloads\ComNet_TV.exe" = C:\Documents and Settings\Mitko\My Documents\Downloads\COMNET_TV.EXE:*:Enabled:COMNET_TV.EXE"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer"C:\Documents and Settings\Mitko\Local Settings\Temp\Torrent2Exe\T2E.exe" = C:\Documents and Settings\Mitko\Local Settings\Temp\Torrent2Exe\T2E.exe:*:Enabled:Torrent2Exe -- (http://www.torrent2exe.com)"C:\Documents and Settings\Mitko\My Documents\Downloads\SweetImSetup.exe" = C:\Documents and Settings\Mitko\My Documents\Downloads\SweetImSetup.exe:*:Enabled:SweetIM Installer"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console -- (Microsoft Corporation)"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Computer, Inc.)"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath -- (Skype Technologies S.A.)"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 -- (AVG Technologies CZ, s.r.o.)"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.)"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"{00640E90-FF0B-4561-AD85-F5EC43E27B75}" = Fun&Learning - Memory&Logic"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic UDF Reader"{17079027-EB8A-42C6-9BF8-825B78889F6A}" = Garmin Communicator Plugin"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP"{3BC1AB78-2D98-4906-84B5-4230B5420DCC}" = Offline Course Player"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3"{411949AB-6EE8-4C62-9C72-EBC93B6A7935}" = AVG 2012"{50842BAB-FD22-4B64-BE6D-4DC632EFBF39}" = Fun&Learning - Creativity"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3"{73284F36-E17E-44B0-85E2-F0336A6E749F}" = PC Connectivity Solution"{74C5EA04-AF1E-45B2-949B-4841EE949C40}" = Nokia Connectivity Cable Driver"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific"{A7836FF5-7293-40A4-B86E-E2038F82E8F3}" = AVG 2012"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = USB PC Camera Plus"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver"{FCD8DCE6-94C8-4FF6-8E3E-D3C96A5A707E}" = Nokia PC Suite"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)"6A630DCEC5EEC912115F2FF59D8C2C769798D930" = Windows Driver Package - Nokia Modem (10/12/2007 3.6)"819D45A9F73817F5B6D7C71A33ADAB88C5DA1765" = Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2)"9925DD2E3ADF2DA7C8A0212FB775F1D2FB6C56E8" = Windows Driver Package - Nokia (WUDFRd) WPD (11/05/2007 6.85.35.3)"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3"Ask Toolbar_is1" = Ask Toolbar"AVG" = AVG 2012"CDex" = CDex extraction audio"EVEREST Home Edition_is1" = EVEREST Home Edition v1.10"F1CB0AC2D40DDCFCA6933082B115073476C155DE" = Windows Driver Package - Nokia Modem (08/03/2007 3.2)"FlexType 2K" = FlexType 2K"Foxit Reader" = Foxit Reader"HDMI" = Intel® Graphics Media Accelerator Driver"ie8" = Windows Internet Explorer 8"Inhatch web plugins" = Inhatch web plugins"IrfanView" = IrfanView (remove only)"KLiteCodecPack_is1" = K-Lite Codec Pack 4.5.3 (Full)"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware, версия 1.61.0.1400"Nero - Burning Rom!UninstallKey" = Ahead Nero 6 Demo"Nokia PC Suite" = Nokia PC Suite"Opera 11.64.1403" = Opera 11.64"PROPLUS" = Microsoft Office Professional Plus 2007"Replay Media Catcher" = Replay Media Catcher"SA Dictionary 2002 Professional" = SA Dictionary 2002 Professional"TOSHIBA Software Modem" = TOSHIBA Software Modem"Unlocker" = Unlocker 1.8.7"uTorrent" = µTorrent"VLC media player" = VLC media player 1.1.7"Winamp" = Winamp"WinRAR archiver" = WinRAR archiver ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1454471165-1123561945-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"Google Chrome" = Google Chrome"uTorrent" = µTorrent ========== Last 10 Event Log Errors ========== [ Application Events ]Error - 02.5.2011 г. 01:00:45 | Computer Name = MAGI | Source = Application Error | ID = 1000Description = Faulting application firefox.exe, version 1.9.2.4127, faulting modulemsvcr90.dll, version 9.0.30729.4148, fault address 0x00059231. Error - 03.5.2011 г. 00:55:58 | Computer Name = MAGI | Source = Application Error | ID = 1000Description = Faulting application firefox.exe, version 1.9.2.4127, faulting modulemsvcr90.dll, version 9.0.30729.4148, fault address 0x00059231. Error - 03.5.2011 г. 00:56:18 | Computer Name = MAGI | Source = Application Error | ID = 1000Description = Faulting application firefox.exe, version 1.9.2.4127, faulting modulemsvcr90.dll, version 9.0.30729.4148, fault address 0x00059231. Error - 03.5.2011 г. 00:56:22 | Computer Name = MAGI | Source = Application Error | ID = 1001Description = Fault bucket -1882036877. Error - 09.5.2011 г. 01:17:44 | Computer Name = MAGI | Source = Application Error | ID = 1000Description = Faulting application firefox.exe, version 1.9.2.4127, faulting modulemsvcr90.dll, version 9.0.30729.4148, fault address 0x00059231. Error - 12.5.2011 г. 16:14:15 | Computer Name = MAGI | Source = crypt32 | ID = 131083Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>with error: A required certificate is not within its validity period when verifyingagainst the current system clock or the timestamp in the signed file. Error - 12.5.2011 г. 16:14:15 | Computer Name = MAGI | Source = crypt32 | ID = 131083Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>with error: A required certificate is not within its validity period when verifyingagainst the current system clock or the timestamp in the signed file. Error - 15.5.2011 г. 00:48:09 | Computer Name = MAGI | Source = Application Error | ID = 1000Description = Faulting application firefox.exe, version 1.9.2.4127, faulting modulemsvcr90.dll, version 9.0.30729.4148, fault address 0x00059231. Error - 30.5.2011 г. 08:41:44 | Computer Name = MAGI | Source = Application Hang | ID = 1002Description = Hanging application mplayerc.exe, version 1.2.972.0, hang module hungapp,version 0.0.0.0, hang address 0x00000000. Error - 01.6.2011 г. 12:49:00 | Computer Name = MAGI | Source = Application Error | ID = 1000Description = Faulting application firefox.exe, version 1.9.2.4127, faulting modulemsvcr90.dll, version 9.0.30729.4148, fault address 0x00059231. [ System Events ]Error - 11.5.2012 г. 19:57:17 | Computer Name = MAGI | Source = SideBySide | ID = 16842784Description = Dependent Assembly Microsoft.VC90.CRT could not be found and LastError was The referenced assembly is not installed on your system. Error - 11.5.2012 г. 19:57:17 | Computer Name = MAGI | Source = SideBySide | ID = 16842811Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference errormessage: The referenced assembly is not installed on your system. . Error - 11.5.2012 г. 19:57:17 | Computer Name = MAGI | Source = SideBySide | ID = 16842811Description = Generate Activation Context failed for C:\Program Files\AVG\AVG2012\avgcfgx.dll.Referenceerror message: The operation completed successfully. . Error - 11.5.2012 г. 19:57:42 | Computer Name = MAGI | Source = SideBySide | ID = 16842784Description = Dependent Assembly Microsoft.VC90.CRT could not be found and LastError was The referenced assembly is not installed on your system. Error - 11.5.2012 г. 19:57:42 | Computer Name = MAGI | Source = SideBySide | ID = 16842811Description = Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference errormessage: The referenced assembly is not installed on your system. . Error - 11.5.2012 г. 19:57:42 | Computer Name = MAGI | Source = SideBySide | ID = 16842811Description = Generate Activation Context failed for C:\Program Files\AVG\AVG2012\avgcfgx.dll.Referenceerror message: The operation completed successfully. . Error - 11.5.2012 г. 21:01:20 | Computer Name = MAGI | Source = System Error | ID = 1003Description = Error code 10000050, parameter1 e144401c, parameter2 00000000, parameter3bf83291e, parameter4 00000001. Error - 11.5.2012 г. 21:01:38 | Computer Name = MAGI | Source = System Error | ID = 1003Description = Error code 1000008e, parameter1 c0000005, parameter2 bf951755, parameter39ba9bc00, parameter4 00000000. Error - 11.5.2012 г. 21:01:40 | Computer Name = MAGI | Source = System Error | ID = 1003Description = Error code 1000008e, parameter1 c0000005, parameter2 bf951755, parameter395c53c00, parameter4 00000000. Error - 12.5.2012 г. 12:41:36 | Computer Name = MAGI | Source = Dhcp | ID = 1000Description = Your computer has lost the lease to its IP address 85.11.187.219 onthe Network Card with network address 001D60F34F30. < End of report > Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Май 13, 2012 Report Share Публикувано Май 13, 2012 Malwarebytes Anti-Malware и SUPERAntiSpyware Free откриха ли нещо при сканирането? Ако да, моля, прикачи и дневници от техните сканирания. Все още ли имаш проблем с Facebook? Под всеки браузър ли е така? С други сайтове имаш ли проблеми? Някакви други странни проблеми имаш ли с компютъра? Цитирай Link to comment Сподели другаде More sharing options...
Magdalena Tsoncheva Публикувано Май 13, 2012 Report Share Публикувано Май 13, 2012 3 пъти пусках Anti-Malware и SUPERAntiSpyware Free, докато спряха да откриват по нещо. Facebook вървеше на 6 първоначално-след процедурата, но отново не зарежда. Само с този сайт е проблема. Ще пусна отново програмките и ще прикача сканиранията, ако открият нещо. Незнам защо така се получи-тъкмо се зарадвах, че се оправил, и след малко отново не зарежда. Да не би някакъв вирус уж да е изчезнал, а след малко да се е възпроизвел? Сканирах с двете програмки и нищо не беше открито. Сега пък пробвах - и се зареди Facebook. Дано да не прави повече проблеми. Ако отново имам проблем със зареждането, да повторя ли процедурата с OTL приложението? Благодаря много на Night_Raven за светкавичната помощ и съдействие И все пак на какво се дължеше проблема-на вирус, или на нещо друго, което спира зареждането точно на този сайт? Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Май 13, 2012 Report Share Публикувано Май 13, 2012 Ако се появи отново, просто пиши отново или си създай нова тема, не бързай да изпълняваш инструкции. На какво се е дължал проблемът не може да се каже, защото в дневниците не видях нищо обезпокоително. Освен може би FlexType, която ти препоръчвам да премахнеш, защото е боклук, и да ползваш вградената поддръжка в Windows. За повече информация погледни тази тема. Цитирай Link to comment Сподели другаде More sharing options...
Viksi95 Публикувано Май 13, 2012 Report Share Публикувано Май 13, 2012 И аз съм със същият проблем с фейсбука.С XP съм и изпълних и гореописаните стъпки. Моля да ми помогнете.. extras.txt: OTL Extras logfile created on: 13.5.2012 г. 21:26:26 - Run 1OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Vasko1\DesktopWindows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstationInternet Explorer (Version = 8.0.6001.18702)Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 2,87 Gb Total Physical Memory | 1,68 Gb Available Physical Memory | 58,53% Memory free4,71 Gb Paging File | 3,51 Gb Available in Paging File | 74,58% Paging File freePaging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 19,53 Gb Total Space | 0,19 Gb Free Space | 0,99% Space Free | Partition Type: NTFSDrive D: | 911,97 Gb Total Space | 420,02 Gb Free Space | 46,06% Space Free | Partition Type: NTFSDrive F: | 503,94 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: VASKO | User Name: Vasko1 | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All usersCompany Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>].cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* [HKEY_USERS\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Classes\<extension>].html [@ = FirefoxHTML] -- D:\Programs\Mozilla\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]batfile [open] -- "%1" %*cmdfile [open] -- "%1" %*comfile [open] -- "%1" %*cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*exefile [open] -- "%1" %*htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)piffile [open] -- "%1" %*regfile [merge] -- Reg Error: Key error.scrfile [config] -- "%1"scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %lscrfile [open] -- "%1" /Stxtfile [edit] -- Reg Error: Key error.Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]"FirstRunDisabled" = 1"UpdatesDisableNotify" = 0"AntiVirusDisableNotify" = 0"FirewallDisableNotify" = 0"AntiVirusOverride" = 1"FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]"DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]"Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]"Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management "80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In) ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)"C:\WINDOWS\system32\rundll32.exe" = C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App -- (Microsoft Corporation)"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe" = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil -- (IVT Corporation.)"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)"D:\Games\PES\pes2011.exe" = D:\Games\PES\pes2011.exe:*:Enabled:Pro Evolution Soccer 2011 -- (Konami Digital Entertainment Co., Ltd.)"D:\Games\gMOD\hl2.exe" = D:\Games\gMOD\hl2.exe:*:Enabled:hl2 -- ()"D:\Games\Mafia\Steam.exe" = D:\Games\Mafia\Steam.exe:*:Enabled:Steam -- (Valve Corporation)"D:\Games\TDU\Test Drive Unlimited GOLD\TestDriveUnlimited.exe" = D:\Games\TDU\Test Drive Unlimited GOLD\TestDriveUnlimited.exe:*:Enabled:Test Drive Unlimited -- (Eden Games)"D:\Games\Fifa\fifa07.exe" = D:\Games\Fifa\fifa07.exe:*:Enabled:fifa07 -- ()"D:\Games\NWO\New World Order\NWO\NWO.exe" = D:\Games\NWO\New World Order\NWO\NWO.exe:*:Enabled:NWO -- ()"D:\Games\Prototype\prototypef.exe" = D:\Games\Prototype\prototypef.exe:*:Enabled:Prototype -- (Activision)"D:\Games\X-Men\Binaries\Wolverine.exe" = D:\Games\X-Men\Binaries\Wolverine.exe:*:Enabled:X-Men Origins - Wolverine -- (Raven Software)"D:\Games\CoD\CoD2MP_s.exe" = D:\Games\CoD\CoD2MP_s.exe:*:Enabled:CoD2MP_s -- ()"C:\WINDOWS\system32\PnkBstrA.exe" = C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA -- ()"C:\WINDOWS\system32\PnkBstrB.exe" = C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB -- ()"D:\Games\Wolfenstein\MP\Wolf2MP.exe" = D:\Games\Wolfenstein\MP\Wolf2MP.exe:*:Enabled:Wolfenstein -- (Activision)"D:\Games\Wolfenstein\MP\Wolf2MPLite.exe" = D:\Games\Wolfenstein\MP\Wolf2MPLite.exe:*:Enabled:Wolfenstein -- (Activision)"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth -- (Google)"D:\Games\Free Running\FreeRunning.exe" = D:\Games\Free Running\FreeRunning.exe:*:Enabled:FreeRunning -- ()"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace -- (Microsoft Corporation)"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote -- (Microsoft Corporation)"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)"C:\Program Files\Oleansoft\Hc\servemp.exe" = C:\Program Files\Oleansoft\Hc\servemp.exe:*:Enabled:HC Employee -- (Oleansoft)"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Computer, Inc.)"D:\Games\CS\Counter-Strike 1.6 Sector Edition\cstrike.exe" = D:\Games\CS\Counter-Strike 1.6 Sector Edition\cstrike.exe:*:Enabled:Counter-Strike Launcher -- (Non Steam Powered)"C:\Betfair JPC\arch\win32\jre\bin\java.exe" = C:\Betfair JPC\arch\win32\jre\bin\java.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)"D:\Games\Stalker\S.T.A.L.K.E.R\bin\XR_3DA.exe" = D:\Games\Stalker\S.T.A.L.K.E.R\bin\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (CLI) -- ()"D:\Games\Stalker\S.T.A.L.K.E.R\bin\dedicated\XR_3DA.exe" = D:\Games\Stalker\S.T.A.L.K.E.R\bin\dedicated\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (SRV) -- ()"C:\Program Files\Winamp\winamp.exe" = C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp -- (Nullsoft, Inc.)"D:\Games\CS\Counter-Strike 1.6 Sector Edition\hlds.exe" = D:\Games\CS\Counter-Strike 1.6 Sector Edition\hlds.exe:*:Enabled:HLDS Launcher -- (Valve)"D:\Games\Fifa 12\FIFA 12\Game\fifa.exe" = D:\Games\Fifa 12\FIFA 12\Game\fifa.exe:*:Enabled:FIFA 12 -- (Electronic Arts)"D:\Games\CS\CS 1.6\cstrike.exe" = D:\Games\CS\CS 1.6\cstrike.exe:*:Enabled:Half-Life Launcher -- (Valve)"C:\Documents and Settings\Vasko1\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe" = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin -- (Skype Limited)"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"{01E9B2FF-DAF4-4529-9CC9-2101625517C7}" = nero.prerequisites.msi"{034DCAF9-96E7-4936-9A07-712F80B5181E}" = Nero RescueAgent 11"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended"{0C38DE0A-5FC3-47E8-9FD0-69B5DC75FFB7}" = CT Special Forces - Fire For Effect"{11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}" = Nero ControlCenter 11"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java 6 Update 31"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3"{40A0B29E-B270-450B-BF4D-34493A934523}" = Домашен Кулинар FX"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater"{4FF4016F-793C-4AFC-AE78-E2E8E70F36DB}_is1" = Counter-Strike 1.6 Version 29, Exe build: 3647"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings"{53F7746A-96AA-49A5-86B8-59989680DAC5}" = Nero Burning ROM 11 Help (CHM)"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3"{55EB7967-5BB1-4EA2-8AFF-B2F9E487E553}" = PC Connectivity Solution"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Земя"{5A438E06-0BB3-4C5F-0085-B14F1F4077E6}" = FIFA 07"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable"{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159"{7F0B94C6-828C-4EDE-A86B-ECF4D792B68D}" = Activision®"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable"{842E6EBA-FBC9-4077-B5EF-E73268D08286}" = ESET NOD32 Antivirus"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support"{90140000-0010-0402-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Bulgarian) 14"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0015-0402-0000-0000000FF1CE}" = Microsoft Office Access MUI (Bulgarian) 2010"{90140000-0015-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0016-0402-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Bulgarian) 2010"{90140000-0016-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0018-0402-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Bulgarian) 2010"{90140000-0018-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0019-0402-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Bulgarian) 2010"{90140000-0019-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001A-0402-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Bulgarian) 2010"{90140000-001A-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001B-0402-0000-0000000FF1CE}" = Microsoft Office Word MUI (Bulgarian) 2010"{90140000-001B-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001F-0402-0000-0000000FF1CE}" = Microsoft Office Proof (Bulgarian) 2010"{90140000-001F-0402-0000-0000000FF1CE}_Office14.PROPLUS_{0709C35F-CF3B-4B05-8A2D-6FFD8F9A5F67}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010"{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUS_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001F-0419-0000-0000000FF1CE}" = Microsoft Office Proof (Russian) 2010"{90140000-001F-0419-0000-0000000FF1CE}_Office14.PROPLUS_{DD6E7CDF-BDFF-43CF-8CCE-84FBEC5ABB77}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-002C-0402-0000-0000000FF1CE}" = Microsoft Office Proofing (Bulgarian) 2010"{90140000-002C-0402-0000-0000000FF1CE}_Office14.PROPLUS_{C8054E0D-931E-4977-873A-017236B74357}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0044-0402-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Bulgarian) 2010"{90140000-0044-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-006E-0402-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Bulgarian) 2010"{90140000-006E-0402-0000-0000000FF1CE}_Office14.PROPLUS_{2800BF0D-D21D-49F8-988D-6F521900953C}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-00A1-0402-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Bulgarian) 2010"{90140000-00A1-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-00BA-0402-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Bulgarian) 2010"{90140000-00BA-0402-0000-0000000FF1CE}_Office14.PROPLUS_{59A0F32E-76D1-4BD1-BE32-554DD2F05DB4}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3"{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings"{9773450C-E2F3-46C3-9464-1D7EDE5EFB63}" = Pro Evolution Soccer 2011"{993960EE-CA4D-443F-8F88-E24260DD5FD2}" = LG PC Suite"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2"{A804B134-F03D-4EFD-9BC0-DCD257AA1B22}" = Hitman Blood Money"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86"{AF88496B-4BBA-4922-97E9-2582D3A28358}" = Nokia Connectivity Cable Driver"{B1846721-A8E6-46C7-83B6-0DCF7ADB4267}" = Nero Burning ROM 11"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call"{B9A17C96-1348-45CB-BB0A-1BCB3A0F854E}" = Bluesoleil2.7.0.35 VoIP Release 080317"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3"{B9B81B80-F4B4-43FB-A075-2094FC1C2647}" = Prince of Persia The Two Thrones"{B9FA15C8-17D4-4E71-A6D9-C33E7BDA83AF}_is1" = International Volleyball 2010"{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components 11"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1"{D01CE99A-8802-483C-A79F-298B691EB432}" = Nero RescueAgent 11 Help (CHM)"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas"{D4D66270-9147-4BDF-9946-FCA2B303AA8F}" = Nero ControlCenter 11 Help (CHM)"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings"{DFFE2B1F-07E0-45A9-8801-CD8514CAA876}" = Prince of Persia T2T"{E1978666-DFBF-4B42-87F6-2EF088D342AA}" = InnerPass Web Meetings"{E2494AD8-314D-44F8-B39C-4358A60DC184}" = LogMeIn Hamachi"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime"{E656D89A-8CBB-497F-918F-8361A4071C26}" = Nero Burning ROM 11"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver"{F48C6EA5-3B43-11D6-86A6-0050BA0259A2}" = ICatch (VI) PC Camera"{F9835182-794B-4F24-902A-E2CA9D43380F}" = NVIDIA PhysX"{F9B37992-968C-4264-8449-489032FC28DE}" = Wolfenstein"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)"779B2C05-7C84-4948-BFE9-D284AD37E8CA" = Button Beats Virtual Piano"82A44D22-9452-49FB-00FB-CEC7DCAF7E23" = EA SPORTS online 2007"Adobe Acrobat 5.0" = Adobe Acrobat 5.0"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin"Adobe Shockwave Player" = Adobe Shockwave Player 11.6"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3"Advanced SystemCare 3_is1" = Advanced SystemCare 3"Alcatraz Tycoon" = Alcatraz Tycoon"Ashampoo Burning Studio 10_is1" = Ashampoo Burning Studio 10 v.10.0.15"Betfair Poker JPC_is1" = Betfair Poker JPC 1.0.0"BS_Player Toolbar" = BS Player Toolbar"BSPlayerf" = BS.Player FREE"CCleaner" = CCleaner"Clownfish" = Clownfish for Skype"DAEMON Tools Lite" = DAEMON Tools Lite"Dave Mirra freestyle BMX" = Dave Mirra freestyle BMX"Defraggler" = Defraggler"Delete Doctor" = Delete Doctor 2.3"Evaer Video Recorder for Skype" = Evaer Video Recorder for Skype 1.2.0.15"FaceOffMax" = Face Off Max"FIFA 12 © EA_is1" = FIFA 12 © EA version 1"FileHippo.com" = FileHippo.com Update Checker"Free Running_is1" = Free Running"Game Booster_is1" = Game Booster"GetFLV Pro_is1" = GetFLV Pro 9.0.1.8"GOM Encoder" = GOM Encoder"GOM Picker" = GOM PICKER"GOM Player" = GOM Player"ie8" = Windows Internet Explorer 8"InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III"InstallShield_{7F0B94C6-828C-4EDE-A86B-ECF4D792B68D}" = X-Men Origins - Wolverine"InstallShield_{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2"InstallShield_{F9B37992-968C-4264-8449-489032FC28DE}" = Wolfenstein"IObit Security 360_is1" = IObit Security 360"KLiteCodecPack_is1" = K-Lite Codec Pack 6.5.0 (Full)"LogMeIn Hamachi" = LogMeIn Hamachi"Mario Forever" = Mario Forever"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended"Mozilla Firefox 13.0 (x86 en-US)" = Mozilla Firefox 13.0 (x86 en-US)"MozillaMaintenanceService" = Mozilla Maintenance Service"MP3 To Ringtone Gold_is1" = MP3 To Ringtone Gold 5.23"MPEG2 Codec(libmpeg2/mad)" = MPEG2 Codec(libmpeg2/mad)"Office14.PROPLUS" = Microsoft Office Professional Plus 2010"Pamela" = Pamela Pro 4.8"PhotoScape" = PhotoScape"PokerStars" = PokerStars"PokerStars.net" = PokerStars.net"PunkBusterSvc" = PunkBuster Services"QuickStores-Toolbar_is1" = QuickStores-Toolbar 1.1.0"RealHideIP" = Real Hide IP"Recuva" = Recuva"Roads Of Rome ." = Roads Of Rome ."S.T.A.L.K.E.R._is1" = S.T.A.L.K.E.R. [v1.0001]"SoftwareUpdUtility" = Download Updater (AOL LLC)"Speccy" = Speccy"Test Drive Unlimited GOLD_is1" = Test Drive Unlimited GOLD 1.66A Rus"Ultra Video Converter_is1" = Ultra Video Converter 5.2.0411"uTorrent" = µTorrent"uTorrentBar Toolbar" = uTorrentBar Toolbar"VLC media player" = VLC media player 1.1.11"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9"Winamp" = Winamp"Winamp Toolbar" = Winamp Toolbar"WinAVI Video Converter" = WinAVI Video Converter"WinAVI Video Converter 9.09.0" = WinAVI Video Converter 9.0"Windows Media Format Runtime" = Windows Media Format 11 runtime"WinRAR archiver" = WinRAR 4.00 (32-битова версия)"WMFDist11" = Windows Media Format 11 runtime"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0"XP Codec Pack" = XP Codec Pack"xvid" = Xvid MPEG-4 Video Codec ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"{79A765E1-C399-405B-85AF-466F52E918B0}" = Nero Toolbar Updater"Counter-Strike 1.6: New Era" = Counter-Strike 1.6: New Era"FolderLock6" = Folder Lock"Game Organizer" = GameXN GO"Google Chrome" = Google Chrome"Winamp Detect" = Winamp Detector Plug-in"Winamp Toolbar" = Winamp Toolbar ========== Last 10 Event Log Errors ========== [ Application Events ]Error - 16.4.2012 г. 15:01:09 | Computer Name = VASKO | Source = .NET Runtime Optimization Service | ID = 1101Description = .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - 1>Failed to compile: Microsoft.Build.Utilities.v4.0, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80131f06 Error - 23.4.2012 г. 19:04:36 | Computer Name = VASKO | Source = Application Error | ID = 1000Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x062f6a80. Error - 24.4.2012 г. 19:36:30 | Computer Name = VASKO | Source = Application Error | ID = 1000Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x05be6a80. Error - 27.4.2012 г. 17:55:40 | Computer Name = VASKO | Source = Application Error | ID = 1000Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x05b06a80. Error - 28.4.2012 г. 18:42:43 | Computer Name = VASKO | Source = Application Error | ID = 1000Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x05816a80. Error - 06.5.2012 г. 18:22:38 | Computer Name = VASKO | Source = Application Error | ID = 1000Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x05016a80. Error - 11.5.2012 г. 11:20:29 | Computer Name = VASKO | Source = .NET Runtime Optimization Service | ID = 1103Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown Error - 11.5.2012 г. 15:29:39 | Computer Name = VASKO | Source = crypt32 | ID = 131083Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. Error - 11.5.2012 г. 15:29:39 | Computer Name = VASKO | Source = crypt32 | ID = 131083Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. Error - 11.5.2012 г. 15:40:42 | Computer Name = VASKO | Source = MsiInstaller | ID = 11313Description = Product: Домашен Кулинар FX -- Error 1313. The volume E:\ is currently unavailable. Please select another. [ System Events ]Error - 04.5.2012 г. 07:38:37 | Computer Name = VASKO | Source = HTTP | ID = 15005Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. Error - 04.5.2012 г. 07:38:50 | Computer Name = VASKO | Source = HTTP | ID = 15005Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. Error - 07.5.2012 г. 11:43:20 | Computer Name = VASKO | Source = HTTP | ID = 15005Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. Error - 07.5.2012 г. 11:43:20 | Computer Name = VASKO | Source = HTTP | ID = 15005Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. Error - 08.5.2012 г. 17:58:13 | Computer Name = VASKO | Source = HTTP | ID = 15005Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. Error - 09.5.2012 г. 04:15:10 | Computer Name = VASKO | Source = HTTP | ID = 15005Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. Error - 09.5.2012 г. 04:15:10 | Computer Name = VASKO | Source = HTTP | ID = 15005Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. Error - 11.5.2012 г. 04:15:51 | Computer Name = VASKO | Source = HTTP | ID = 15005Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. Error - 11.5.2012 г. 04:15:51 | Computer Name = VASKO | Source = HTTP | ID = 15005Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. Error - 12.5.2012 г. 17:56:45 | Computer Name = VASKO | Source = HTTP | ID = 15005Description = Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. < End of report > otl.txt: OTL logfile created on: 13.5.2012 г. 21:26:26 - Run 1OTL by OldTimer - Version 3.2.42.3 Folder = C:\Documents and Settings\Vasko1\DesktopWindows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstationInternet Explorer (Version = 8.0.6001.18702)Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 2,87 Gb Total Physical Memory | 1,68 Gb Available Physical Memory | 58,53% Memory free4,71 Gb Paging File | 3,51 Gb Available in Paging File | 74,58% Paging File freePaging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program FilesDrive C: | 19,53 Gb Total Space | 0,19 Gb Free Space | 0,99% Space Free | Partition Type: NTFSDrive D: | 911,97 Gb Total Space | 420,02 Gb Free Space | 46,06% Space Free | Partition Type: NTFSDrive F: | 503,94 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: VASKO | User Name: Vasko1 | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All usersCompany Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days ========== Processes (SafeList) ========== PRC - [2012.05.13 21:14:46 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Vasko1\Desktop\OTL.exePRC - [2012.04.28 05:07:02 | 001,224,176 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\chrome.exePRC - [2012.04.09 17:43:42 | 001,557,160 | ---- | M] (Ask) -- C:\Program Files\Ask.com\Updater\Updater.exePRC - [2012.04.01 01:31:19 | 000,347,008 | ---- | M] (EasyBits Software AS) -- C:\Documents and Settings\All Users\Application Data\GameXN\GameXNGO.exePRC - [2012.03.06 19:33:01 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- D:\Programs\fwfef\bin\jqs.exePRC - [2012.02.28 22:59:29 | 000,740,216 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exePRC - [2012.02.28 18:38:52 | 001,373,576 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exePRC - [2012.01.19 20:08:34 | 003,477,312 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exePRC - [2011.11.05 22:50:14 | 000,413,184 | ---- | M] (Oleansoft) -- C:\Program Files\Oleansoft\Hc\servemp.exePRC - [2011.09.23 19:37:42 | 000,641,832 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Update\NASvc.exePRC - [2011.09.21 10:37:50 | 001,686,016 | ---- | M] (Evaer) -- C:\Program Files\Evaer\videochannel.exePRC - [2011.07.22 00:07:38 | 000,718,720 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXEPRC - [2011.03.17 22:56:22 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exePRC - [2011.01.19 18:37:32 | 003,470,168 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Security 360\is360.exePRC - [2010.06.11 19:14:24 | 001,280,344 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Security 360\is360tray.exePRC - [2010.06.11 19:14:22 | 000,312,152 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Security 360\is360srv.exePRC - [2008.11.10 15:34:26 | 000,711,240 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exePRC - [2008.11.10 15:34:18 | 001,980,200 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exePRC - [2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exePRC - [2008.03.19 17:52:44 | 000,166,520 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exePRC - [2008.03.19 17:52:40 | 000,709,640 | ---- | M] (IVT Corporation.) -- C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exePRC - [2008.03.19 17:52:38 | 000,051,816 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exePRC - [2008.03.19 17:52:36 | 000,138,840 | ---- | M] (IVT Corporation.) -- C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe ========== Modules (No Company Name) ========== MOD - [2012.04.28 05:07:01 | 000,444,400 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\ppgooglenaclpluginchrome.dllMOD - [2012.04.28 05:06:59 | 003,915,248 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\pdf.dllMOD - [2012.04.28 05:05:34 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\avutil-51.dllMOD - [2012.04.28 05:05:33 | 000,220,672 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\avformat-53.dllMOD - [2012.04.28 05:05:32 | 001,747,456 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\avcodec-53.dllMOD - [2012.04.28 04:09:18 | 008,743,584 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\gcswf32.dllMOD - [2011.11.03 18:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dllMOD - [2011.05.28 14:54:08 | 000,073,600 | ---- | M] () -- C:\WINDOWS\system32\ezGOSvc.dllMOD - [2011.03.17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODFMOD - [2011.03.02 13:40:51 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dllMOD - [2009.12.24 18:02:22 | 000,511,312 | ---- | M] () -- C:\Program Files\IObit\IObit Security 360\sqlite3.dllMOD - [2009.02.12 16:26:20 | 000,167,424 | ---- | M] () -- C:\Program Files\IObit\IObit Security 360\madbasic_.bplMOD - [2009.02.12 16:26:20 | 000,044,032 | ---- | M] () -- C:\Program Files\IObit\IObit Security 360\maddisAsm_.bplMOD - [2009.01.12 19:56:14 | 000,071,504 | ---- | M] () -- C:\Program Files\IObit\IObit Security 360 askdll.dllMOD - [2008.07.09 12:05:50 | 000,421,888 | ---- | M] () -- C:\WINDOWS\system32\ac3filter.acmMOD - [2008.04.14 05:42:04 | 000,192,512 | ---- | M] () -- C:\WINDOWS\system32\qcap.dllMOD - [2008.04.14 05:42:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dllMOD - [2008.04.14 05:41:52 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dllMOD - [2008.03.19 17:52:44 | 000,166,520 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exeMOD - [2008.03.19 17:52:38 | 000,051,816 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exeMOD - [2004.08.04 15:00:00 | 000,015,360 | ---- | M] () -- C:\WINDOWS\system32 sd32.dll ========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)SRV - [2012.05.12 14:28:11 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)SRV - [2012.03.06 19:33:01 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- D:\Programs\fwfef\bin\jqs.exe -- (JavaQuickStarterService)SRV - [2012.02.29 08:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)SRV - [2012.02.28 18:38:52 | 001,373,576 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)SRV - [2011.11.10 17:21:06 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)SRV - [2011.10.27 11:34:30 | 000,718,384 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)SRV - [2011.09.23 19:37:42 | 000,641,832 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Update\NASvc.exe -- (NAUpdate)SRV - [2011.06.12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)SRV - [2011.05.28 14:54:08 | 000,073,600 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\ezGOSvc.dll -- (ezGOSvc)SRV - [2010.06.11 19:14:22 | 000,312,152 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\IObit Security 360\is360srv.exe -- (IS360service)SRV - [2008.11.10 15:35:30 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)SRV - [2008.11.10 15:34:26 | 000,711,240 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)SRV - [2008.03.19 17:52:44 | 000,166,520 | ---- | M] () [Auto | Running] -- C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe -- (BlueSoleil Hid Service)SRV - [2008.03.19 17:52:38 | 000,051,816 | ---- | M] () [Auto | Running] -- C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe -- (Start BT in service) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Vasko1\LOCALS~1\Temp\RarSFX1\kerneld.wnt -- (EverestDriver)DRV - File not found [Kernel | System | Stopped] -- -- (Changer)DRV - [2012.03.07 23:54:49 | 000,180,224 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\WinVd32.sys -- (WinVd32)DRV - [2012.03.07 23:54:47 | 000,010,752 | ---- | M] () [File_System | Auto | Running] -- C:\WINDOWS\system32\WinFLdrv.sys -- (WinFLdrv)DRV - [2012.02.11 14:33:46 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01)DRV - [2011.08.17 14:03:58 | 000,137,472 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)DRV - [2011.08.17 14:03:50 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)DRV - [2011.08.17 13:56:32 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)DRV - [2011.08.17 13:56:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)DRV - [2011.08.17 13:56:26 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)DRV - [2011.08.17 13:56:22 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)DRV - [2011.05.13 14:39:33 | 000,137,344 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hwpsgt.sys -- (hwpsgt)DRV - [2011.05.13 14:39:32 | 000,009,472 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lemsgt.sys -- (lemsgt)DRV - [2010.04.30 17:56:24 | 006,032,928 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)DRV - [2010.03.22 17:30:22 | 000,222,672 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)DRV - [2010.01.19 06:50:10 | 000,235,520 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntcDAud.sys -- (IntcDAud) Intel®DRV - [2009.11.18 08:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)DRV - [2009.11.18 08:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)DRV - [2009.03.18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)DRV - [2008.11.10 15:34:46 | 000,092,168 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)DRV - [2008.11.10 15:34:22 | 000,104,456 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)DRV - [2008.11.10 15:33:28 | 000,110,600 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)DRV - [2008.08.26 11:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)DRV - [2007.06.24 22:56:54 | 000,038,920 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)DRV - [2007.06.24 22:56:40 | 000,027,656 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)DRV - [2007.06.24 22:56:34 | 000,034,312 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)DRV - [2007.03.05 21:59:04 | 000,018,320 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btnetdrv.sys -- (BT)DRV - [2007.03.05 21:56:18 | 000,035,600 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\BTHidMgr.sys -- (BTHidMgr)DRV - [2007.03.05 21:55:12 | 000,020,880 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\vbtenum.sys -- (BTHidEnum)DRV - [2007.03.05 21:53:18 | 000,044,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)DRV - [2007.03.05 21:52:18 | 000,034,448 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)DRV - [2005.03.16 09:23:54 | 000,013,696 | R--- | M] (BIOSTAR Group) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\BIOS.sys -- (BIOS)DRV - [2005.01.14 19:14:07 | 000,047,616 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)DRV - [2004.12.03 13:20:41 | 000,020,544 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)DRV - [2004.10.28 13:47:59 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)DRV - [2002.10.01 14:43:32 | 000,119,798 | ---- | M] (SP) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SPCA561.SYS -- (CA561) ICatch (VI) ========== Standard Registry (All) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-onsIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRiskIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htmIE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKU\.DEFAULT\..\SearchScopes\{010E94D5-BCD7-4A3B-9D22-F08EB415378A}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=NRO&o=101913&src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=EW&apn_dtid=YYYYYYYYBG&apn_uid=2E0E9C44-88DF-41E9-AB3F-AC04194DF491&apn_sauid=3AE21784-B8DB-4CCB-9FCC-B3C5CC54F566IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKU\S-1-5-18\..\SearchScopes\{010E94D5-BCD7-4A3B-9D22-F08EB415378A}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=NRO&o=101913&src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=EW&apn_dtid=YYYYYYYYBG&apn_uid=2E0E9C44-88DF-41E9-AB3F-AC04194DF491&apn_sauid=3AE21784-B8DB-4CCB-9FCC-B3C5CC54F566IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htmIE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/?pc=AVBRIE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1750559IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTo0.dll (Conduit Ltd.)IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\URLSearchHook: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRCIE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{0BAF872C-D696-46D0-90C5-C8556F783F05}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=NRO&o=101913&src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=EW&apn_dtid=YYYYYYYYBG&apn_uid=2E0E9C44-88DF-41E9-AB3F-AC04194DF491&apn_sauid=3AE21784-B8DB-4CCB-9FCC-B3C5CC54F566IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=10588IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{288575EA-507B-42CB-97BE-ACED08F1998A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBRIE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1750559IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}: "URL" = http://www.ask.com/web?o=15710&l=dis&q={searchTerms}IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-winamp-chromesbox-en-us&tb_uuid=20110320113708234&tb_oid=20-03-2011&tb_mrud=20-03-2011IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\Moikrug: "URL" = http://moikrug.ru/persons/?clid=1783273&charset=utf-8&keywords={searchTerms}&submitted=1IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\SearchScopes\Yandex: "URL" = http://yandex.ru/yandsearch?clid=1783273&text={searchTerms}IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=;ftp=;https=; ========== FireFox ========== FF - prefs.js..network.proxy.gopher: ""FF - prefs.js..network.proxy.gopher_port: 0FF - prefs.js..network.proxy.share_proxy_settings: trueFF - prefs.js..network.proxy.type: 0FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: D:\Programs\fwfef\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\Vasko1\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2011.05.04 15:07:42 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\jqs@sun.com: D:\Programs\fwfef\lib\deploy\jqs\ff [2012.03.06 19:33:03 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: D:\Programs\Mozilla\components [2012.05.12 17:21:06 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: D:\Programs\Mozilla\pluginsFF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011.03.20 15:18:23 | 000,000,000 | ---D | M] [2012.05.12 17:21:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Vasko1\Application Data\Mozilla\Extensions[2012.01.21 03:47:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Vasko1\Application Data\Mozilla\Firefox\extensions[2012.01.21 03:47:03 | 000,000,000 | ---D | M] (BS Player Community Toolbar) -- C:\Documents and Settings\Vasko1\Application Data\Mozilla\Firefox\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}[2012.05.13 20:20:17 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Vasko1\Application Data\Mozilla\Firefox\Profiles\0px2n2cr.default\extensions[2012.05.12 23:45:04 | 000,004,527 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\VASKO1\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\0PX2N2CR.DEFAULT\EXTENSIONS\SUPPORT@REAL-HIDE-IP.COM.XPI[2012.05.13 20:20:17 | 001,184,804 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\VASKO1\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\0PX2N2CR.DEFAULT\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM.XPI ========== Chrome ========== CHR - default_search_provider: Google (Enabled)CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewerCHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\ppGoogleNaClPluginChrome.dllCHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\pdf.dllCHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.168\gcswf32.dllCHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dllCHR - plugin: Skype Click to Call (Enabled) = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\npSkypeChromePlugin.dllCHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dllCHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dllCHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dllCHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = D:\PFiles\Plugins\np-mswmp.dllCHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dllCHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dllCHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLLCHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLLCHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dllCHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dllCHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dllCHR - plugin: Java Platform SE 6 U31 (Enabled) = D:\Programs\fwfef\bin\plugin2\npjp2.dllCHR - Extension: YouTube = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\CHR - Extension: Hide My Ass! Web Proxy = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cmgnmcnlncejehjlnhaglpnoolgbflbd\1.2.4_0\CHR - Extension: Google \u0422\u044A\u0440\u0441\u0435\u043D\u0435 = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\CHR - Extension: Skype Click to Call = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\CHR - Extension: Gmail = C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2012.05.13 20:42:38 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hostsO1 - Hosts: 127.0.0.1 localhostO2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()O2 - BHO: (QuickStores-Toolbar) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programs\fwfef\bin\ssv.dll (Sun Microsystems, Inc.)O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTo0.dll (Conduit Ltd.)O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Programs\fwfef\bin\jp2ssv.dll (Sun Microsystems, Inc.)O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Programs\fwfef\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)O2 - BHO: (GretechBHO Class) - {F0181C6E-9218-4792-9F3C-E8DF52B2F1AC} - C:\Program Files\GRETECH\GomPicker\GomPickerBHO.dll (Gretech Corporation)O2 - BHO: (BS Player Toolbar) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)O3 - HKLM\..\Toolbar: (QuickStores-Toolbar) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTo0.dll (Conduit Ltd.)O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)O3 - HKLM\..\Toolbar: (BS Player Toolbar) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\prxtbuTo0.dll (Conduit Ltd.)O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (BS Player Toolbar) - {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\prxtbuTo0.dll (Conduit Ltd.)O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (BS Player Toolbar) - {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\prxtbuTo0.dll (Conduit Ltd.)O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL Inc.)O3 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\..\Toolbar\WebBrowser: (BS Player Toolbar) - {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)O4 - HKLM..\Run: [] File not foundO4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)O4 - HKLM..\Run: [bCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)O4 - HKLM..\Run: [HCEmployee] C:\Program Files\Oleansoft\Hc\servemp.exe (Oleansoft)O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)O4 - HKLM..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)O4 - HKLM..\Run: [iObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not foundO4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)O4 - HKU\.DEFAULT..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)O4 - HKU\S-1-5-18..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)O4 - HKU\S-1-5-19..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)O4 - HKU\S-1-5-20..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [avichannel] C:\Program Files\Evaer\videochannel.exe (Evaer)O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [Facebook Update] C:\Documents and Settings\Vasko1\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [GameXN] C:\Documents and Settings\All Users\Application Data\GameXN\GameXNGO.exe (EasyBits Software AS)O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [GameXN (news)] C:\Documents and Settings\All Users\Application Data\GameXN\GameXNGO.exe (EasyBits Software AS)O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [GameXN (update)] C:\Documents and Settings\All Users\Application Data\GameXN\GameXNGO.exe (EasyBits Software AS)O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [Google Update] C:\Documents and Settings\Vasko1\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)O4 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\gprs.exe (IVT Corporation.)O4 - Startup: C:\Documents and Settings\Vasko1\Start Menu\Programs\Startup\Изрязване на екран и стартиране на OneNote 2010.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery presentO6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-21-823518204-1303643608-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0O8 - Extra context menu item: &Експортиране към Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)O8 - Extra context menu item: &Изпрати към OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not foundO9 - Extra Button: Изпрати към OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)O9 - Extra 'Tools' menuitem : &Изпрати към OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)O9 - Extra Button: &Свързани бележки на OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)O9 - Extra 'Tools' menuitem : &Свързани бележки на OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe File not foundO9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{40884B3B-8CDF-4E11-8909-90FA5144F299}: DhcpNameServer = 192.168.1.1O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\ipp - No CLSID value foundO18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Handler\msdaipp - No CLSID value foundO18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler v {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)O18 - Protocol\Filter ext/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O18 - Protocol\Filter ext/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)O20 - Winlogon\Notify\dimsntfy: DllName - (%SystemRoot%\System32\dimsntfy.dll) - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify ermsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)O24 - Desktop Components:0 (My Current Home Page) - About:HomeO24 - Desktop WallPaper: C:\Documents and Settings\Vasko1\Local Settings\Application Data\Microsoft\Wallpaper1.bmpO24 - Desktop BackupWallPaper: C:\Documents and Settings\Vasko1\Local Settings\Application Data\Microsoft\Wallpaper1.bmpO28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)O31 - SafeBoot: AlternateShell - cmd.exeO32 - HKLM CDRom: AutoRun - 1O32 - AutoRun File - [2011.03.16 22:49:19 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]O32 - AutoRun File - [2009.09.15 15:12:05 | 000,315,392 | R--- | M] () - F:\autorun.exe -- [ CDFS ]O32 - AutoRun File - [2009.10.12 12:38:06 | 000,000,042 | R--- | M] () - F:\autorun.inf -- [ CDFS ]O33 - MountPoints2\{44a3cec4-54a4-11e1-ad04-001167c760f5}\Shell - "" = AutoRunO33 - MountPoints2\{44a3cec4-54a4-11e1-ad04-001167c760f5}\Shell\AutoRun - "" = Auto&PlayO33 - MountPoints2\{44a3cec4-54a4-11e1-ad04-001167c760f5}\Shell\AutoRun\command - "" = F:\autorun.exe -- [2009.09.15 15:12:05 | 000,315,392 | R--- | M] ()O33 - MountPoints2\{eee94026-52f5-11e0-b5ee-001167c760f5}\Shell - "" = AutoRunO33 - MountPoints2\{eee94026-52f5-11e0-b5ee-001167c760f5}\Shell\AutoRun - "" = Auto&PlayO33 - MountPoints2\{eee94026-52f5-11e0-b5ee-001167c760f5}\Shell\AutoRun\command - "" = F:\setup.exe -- [2010.03.24 14:09:28 | 527,596,262 | R--- | M] (IQ Publishing )O34 - HKLM BootExecute: (autocheck autochk *)O35 - HKLM\..comfile [open] -- "%1" %*O35 - HKLM\..exefile [open] -- "%1" %*O37 - HKLM\...com [@ = comfile] -- "%1" %*O37 - HKLM\...exe [@ = exefile] -- "%1" %*O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) NetSvcs: 6to4 - File not foundNetSvcs: Ias - File not foundNetSvcs: Iprip - File not foundNetSvcs: Irmon - File not foundNetSvcs: NWCWorkstation - File not foundNetSvcs: Nwsapagent - File not foundNetSvcs: WmdmPmSp - File not foundNetSvcs: ezGOSvc - C:\WINDOWS\system32\ezGOSvc.dll ()NetSvcs: 2.httpool.com/", [ "http://00.creativecdn.com/", 1.8572295440774185, "http://ad.yieldmanager.com/", 0.48469568125582047, "http://ad2.httpool.com/", 0.48469568125582047, "http://content.yieldmanager.edgesuite.net/", 0.2148418158770503, "http://creativecdn.com/", 1.8572295440774185 ] ], [ "http://ads.garga.biz/", [ "http://ads.garga.biz/", 0.832716631910619 ] ], [ "http://api.zippyshare.com/", [ "http://www65.zippyshare.com/", - File not found SafeBootMin: Base - Driver GroupSafeBootMin: Boot Bus Extender - Driver GroupSafeBootMin: Boot file system - Driver GroupSafeBootMin: File system - Driver GroupSafeBootMin: Filter - Driver GroupSafeBootMin: PCI Configuration - Driver GroupSafeBootMin: PNP Filter - Driver GroupSafeBootMin: Primary disk - Driver GroupSafeBootMin: SCSI Class - Driver GroupSafeBootMin: sermouse.sys - DriverSafeBootMin: System Bus Extender - Driver GroupSafeBootMin: vga.sys - DriverSafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllersSafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM DriveSafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDriveSafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controllerSafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - HdcSafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - KeyboardSafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - MouseSafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA AdaptersSafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapterSafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - SystemSafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk driveSafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - VolumeSafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: Base - Driver GroupSafeBootNet: Boot Bus Extender - Driver GroupSafeBootNet: Boot file system - Driver GroupSafeBootNet: File system - Driver GroupSafeBootNet: Filter - Driver GroupSafeBootNet: Hamachi2Svc - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)SafeBootNet: NDIS Wrapper - Driver GroupSafeBootNet: NetBIOSGroup - Driver GroupSafeBootNet: NetDDEGroup - Driver GroupSafeBootNet: Network - Driver GroupSafeBootNet: NetworkProvider - Driver GroupSafeBootNet: PCI Configuration - Driver GroupSafeBootNet: PNP Filter - Driver GroupSafeBootNet: PNP_TDI - Driver GroupSafeBootNet: Primary disk - Driver GroupSafeBootNet: SCSI Class - Driver GroupSafeBootNet: sermouse.sys - DriverSafeBootNet: Streams Drivers - Driver GroupSafeBootNet: System Bus Extender - Driver GroupSafeBootNet: TDI - Driver GroupSafeBootNet: vga.sys - DriverSafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllersSafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM DriveSafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDriveSafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controllerSafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - HdcSafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - KeyboardSafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - MouseSafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - NetSafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClientSafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetServiceSafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTransSafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA AdaptersSafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapterSafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - SystemSafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk driveSafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - VolumeSafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices ========== Files/Folders - Created Within 90 Days ========== [2012.05.13 21:23:36 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Vasko1\Desktop\OTL.exe[2012.05.13 16:11:14 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Vasko1\Recent[2012.05.12 17:21:07 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service[2012.05.12 17:12:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Start Menu\Programs\Google Chrome[2012.05.12 14:04:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla[2012.05.12 12:36:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\My Documents\My Games[2012.05.11 23:27:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\IQ Publishing[2012.05.11 22:41:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Start Menu\Programs\Difference World[2012.05.11 18:57:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Application Data\Avant Downloader[2012.04.27 23:02:03 | 000,000,000 | ---D | C] -- C:\Program Files\Opera[2012.04.25 16:26:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\My Documents\haha[2012.04.21 22:36:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared[2012.04.21 22:36:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton[2012.04.21 22:36:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller[2012.04.01 17:58:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Start Menu\Programs\Buziol Games[2012.04.01 15:07:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\WindowsPowerShell[2012.04.01 15:07:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\winrm[2012.04.01 15:07:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy[2012.04.01 15:07:01 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$968930Uinstall_KB968930$[2012.04.01 01:34:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype[2012.04.01 01:34:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype[2012.04.01 01:31:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\GameXN[2012.03.18 19:19:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Games[2012.03.10 16:57:39 | 000,503,808 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioEditor.dll[2012.03.10 16:57:39 | 000,339,968 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioTransform.dll[2012.03.10 16:57:39 | 000,290,816 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTWMAFile.dll[2012.03.10 16:57:39 | 000,282,624 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioVisualization.dll[2012.03.10 16:57:39 | 000,274,432 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioRecord.dll[2012.03.10 16:57:39 | 000,274,432 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioPlayer.dll[2012.03.10 16:57:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\MP3 To Ringtone Gold[2012.03.10 16:57:38 | 001,703,936 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioFile.dll[2012.03.10 16:57:38 | 000,892,928 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioInformation.dll[2012.03.10 16:57:38 | 000,327,680 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioGrabber.dll[2012.03.10 16:57:38 | 000,070,144 | ---- | C] (TODO: <Company name>) -- C:\WINDOWS\System32\AudioFileConvert.ocx[2012.03.08 00:14:39 | 000,000,000 | ---D | C] -- C:\Program Files\Folder Lock 6[2012.03.07 23:54:47 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Vasko1\Application Data\.#[2012.03.07 23:54:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Start Menu\Programs\Folder Lock 6[2012.03.06 19:35:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Application Data\.minecraft[2012.03.06 19:33:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun[2012.03.06 19:33:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java[2012.03.06 19:33:12 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll[2012.03.06 19:33:12 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe[2012.03.06 19:33:12 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe[2012.03.06 19:33:12 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe[2012.03.06 19:33:12 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl[2012.03.06 19:32:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Application Data\Sun[2012.03.01 12:57:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\LogMeIn Hamachi[2012.03.01 12:57:01 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi[2012.02.29 19:26:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\My Documents\FIFA 12[2012.02.20 01:47:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\PackageAware[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ][2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 90 Days ========== [2012.05.13 21:28:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS asks\Adobe Flash Player Updater.job[2012.05.13 21:26:00 | 000,000,236 | ---- | M] () -- C:\WINDOWS asks\Scheduled Update for Ask Toolbar.job[2012.05.13 21:14:46 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Vasko1\Desktop\OTL.exe[2012.05.13 20:46:06 | 000,001,002 | ---- | M] () -- C:\WINDOWS asks\FacebookUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003UA.job[2012.05.13 20:35:00 | 000,001,082 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003UA.job[2012.05.13 20:32:00 | 000,000,986 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskMachineUA.job[2012.05.13 15:35:00 | 000,001,030 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003Core.job[2012.05.13 14:46:00 | 000,000,980 | ---- | M] () -- C:\WINDOWS asks\FacebookUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003Core.job[2012.05.13 10:44:49 | 000,504,810 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat[2012.05.13 10:44:49 | 000,088,656 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat[2012.05.13 10:41:14 | 000,000,260 | ---- | M] () -- C:\WINDOWS asks\WGASetup.job[2012.05.13 10:40:24 | 000,000,982 | ---- | M] () -- C:\WINDOWS asks\GoogleUpdateTaskMachineCore.job[2012.05.13 10:40:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat[2012.05.12 17:21:38 | 000,000,539 | ---- | M] () -- C:\Documents and Settings\Vasko1\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk[2012.05.12 17:21:38 | 000,000,539 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk[2012.05.12 17:12:58 | 000,002,293 | ---- | M] () -- C:\Documents and Settings\Vasko1\Desktop\Google Chrome.lnk[2012.05.12 17:12:58 | 000,002,271 | ---- | M] () -- C:\Documents and Settings\Vasko1\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk[2012.05.12 14:28:09 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe[2012.05.12 14:28:09 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl[2012.05.12 12:41:40 | 000,146,432 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2012.05.12 12:34:54 | 000,000,038 | ---- | M] () -- C:\WINDOWS\avisplitter.ini[2012.05.12 01:42:48 | 001,567,000 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT[2012.05.11 22:41:15 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI[2012.05.10 16:03:26 | 000,000,320 | ---- | M] () -- C:\WINDOWS\mafosav.INI[2012.05.10 16:03:07 | 000,000,100 | ---- | M] () -- C:\WINDOWS\forevermopt.INI[2012.05.10 10:32:36 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl[2012.04.25 16:31:24 | 000,288,768 | -H-- | M] () -- C:\Documents and Settings\Vasko1\My Documents\photothumb.db[2012.03.27 00:05:04 | 000,000,123 | ---- | M] () -- C:\Documents and Settings\Vasko1\Desktop\NOVA.pls[2012.03.12 12:12:54 | 002,720,291 | ---- | M] () -- C:\Documents and Settings\Vasko1\Desktop\DSC00390.JPG[2012.03.12 01:19:01 | 007,453,553 | ---- | M] () -- C:\Documents and Settings\Vasko1\Desktop\DSC00082.JPG[2012.03.10 16:18:01 | 000,320,178 | ---- | M] () -- C:\WINDOWS\ThemeMakerWallpaper.bmp[2012.03.08 00:38:59 | 005,242,880 | ---- | M] () -- C:\Documents and Settings\Vasko1\My Documents\Locker01.flk[2012.03.08 00:25:44 | 000,000,726 | ---- | M] () -- C:\Documents and Settings\Vasko1\Application Data\Microsoft\Internet Explorer\Quick Launch\Folder Lock 6.lnk[2012.03.07 23:54:49 | 000,180,224 | ---- | M] () -- C:\WINDOWS\System32\WinVd32.sys[2012.03.07 23:54:47 | 000,007,680 | ---- | M] () -- C:\WINDOWS\System32\WinFLsrv.exe[2012.03.06 19:33:01 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll[2012.03.06 19:33:01 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe[2012.03.06 19:33:01 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe[2012.03.06 19:33:01 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe[2012.03.06 19:33:01 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ][2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2012.05.12 17:21:38 | 000,000,539 | ---- | C] () -- C:\Documents and Settings\Vasko1\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk[2012.05.12 17:21:38 | 000,000,539 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk[2012.05.12 17:21:38 | 000,000,539 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk[2012.05.12 17:12:58 | 000,002,293 | ---- | C] () -- C:\Documents and Settings\Vasko1\Desktop\Google Chrome.lnk[2012.05.12 17:12:58 | 000,002,271 | ---- | C] () -- C:\Documents and Settings\Vasko1\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk[2012.04.01 01:31:25 | 000,001,798 | ---- | C] () -- C:\Documents and Settings\Vasko1\Start Menu\Programs\Играене на игри (GameXN).lnk[2012.03.27 00:05:04 | 000,000,123 | ---- | C] () -- C:\Documents and Settings\Vasko1\Desktop\NOVA.pls[2012.03.13 00:09:25 | 000,217,835 | ---- | C] () -- C:\Documents and Settings\Vasko1\Desktop\27072009_003.jpg[2012.03.13 00:09:25 | 000,201,995 | ---- | C] () -- C:\Documents and Settings\Vasko1\Desktop\27072009_004.jpg[2012.03.12 01:11:12 | 007,453,553 | ---- | C] () -- C:\Documents and Settings\Vasko1\Desktop\DSC00082.JPG[2012.03.11 00:13:23 | 002,720,291 | ---- | C] () -- C:\Documents and Settings\Vasko1\Desktop\DSC00390.JPG[2012.03.10 16:57:38 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\ammpp.dll[2012.03.10 16:57:38 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll[2012.03.10 16:57:38 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\a1.dll[2012.03.10 16:57:38 | 000,003,772 | ---- | C] () -- C:\WINDOWS\System32\AudioFileConvert.tlb[2012.03.10 16:57:37 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\qscl.dll[2012.03.10 16:57:37 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\amrdec.dll[2012.03.10 16:57:37 | 000,144,896 | ---- | C] () -- C:\WINDOWS\System32\lame_dshow.ax[2012.03.10 16:57:37 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\qcpsdk.dll[2012.03.10 16:17:30 | 000,320,178 | ---- | C] () -- C:\WINDOWS\ThemeMakerWallpaper.bmp[2012.03.08 00:27:32 | 005,242,880 | ---- | C] () -- C:\Documents and Settings\Vasko1\My Documents\Locker01.flk[2012.03.07 23:54:48 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\WinVd32.sys[2012.03.07 23:54:47 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\WinFLsrv.exe[2012.03.07 23:54:43 | 000,000,726 | ---- | C] () -- C:\Documents and Settings\Vasko1\Application Data\Microsoft\Internet Explorer\Quick Launch\Folder Lock 6.lnk[2012.02.29 19:24:06 | 000,000,664 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\FIFA 12.lnk[2012.02.15 01:33:03 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll[2012.02.15 01:33:03 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll[2012.01.17 01:01:19 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\AVERM.dll[2012.01.17 01:01:19 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll[2011.11.06 13:20:44 | 000,000,233 | ---- | C] () -- C:\WINDOWS\MTConfig.INI[2011.11.06 12:04:12 | 000,065,536 | ---- | C] () -- C:\WINDOWS\DTDraw.dll[2011.11.05 22:53:35 | 000,007,012 | ---- | C] () -- C:\WINDOWS\hctabl212.ini[2011.11.05 22:53:35 | 000,001,028 | ---- | C] () -- C:\WINDOWS\hcpict212.ini[2011.11.05 22:53:35 | 000,000,369 | ---- | C] () -- C:\WINDOWS\hcreg212.ini[2011.10.18 15:43:57 | 000,118,784 | ---- | C] () -- C:\WINDOWS\ShowBmp.exe[2011.10.18 15:43:57 | 000,014,385 | ---- | C] () -- C:\WINDOWS\Tw561a.ini[2011.10.18 15:43:57 | 000,000,081 | ---- | C] () -- C:\WINDOWS\Setup8a.ini[2011.09.27 19:42:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI[2011.09.17 16:47:37 | 000,139,152 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys[2011.09.17 16:47:37 | 000,139,152 | ---- | C] () -- C:\Documents and Settings\Vasko1\Application Data\PnkBstrK.sys[2011.09.17 16:47:23 | 000,111,928 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe[2011.09.17 16:47:22 | 000,075,064 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe[2011.09.17 16:47:21 | 000,794,408 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe[2011.09.17 16:12:52 | 000,000,257 | ---- | C] () -- C:\WINDOWS\game.ini[2011.06.17 16:19:14 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll[2011.06.08 20:53:27 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI[2011.05.29 18:41:31 | 000,073,600 | ---- | C] () -- C:\WINDOWS\System32\ezGOSvc.dll[2011.05.13 14:39:33 | 000,137,344 | ---- | C] () -- C:\WINDOWS\System32\drivers\hwpsgt.sys[2011.05.13 14:39:32 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\lemsgt.sys[2011.04.30 17:58:10 | 000,000,151 | ---- | C] () -- C:\WINDOWS\disney.ini[2011.03.28 06:50:18 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll[2011.03.28 06:49:42 | 000,649,728 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll[2011.03.20 14:34:29 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll[2011.03.20 14:34:28 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini[2011.03.17 00:40:37 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat[2011.03.17 00:34:42 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI[2011.03.17 00:32:52 | 001,567,000 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT[2011.03.16 23:41:16 | 000,080,416 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll[2011.03.16 23:40:24 | 000,127,896 | ---- | C] () -- C:\WINDOWS\System32\igcompkrng575.bin[2011.03.16 23:40:23 | 000,874,032 | ---- | C] () -- C:\WINDOWS\System32\igkrng575.bin[2011.03.16 23:40:23 | 000,004,096 | ---- | C] ( ) -- C:\WINDOWS\System32\IGFXDEVLib.dll[2011.03.16 23:40:23 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\GfxUI.exe.config[2011.03.16 23:04:09 | 000,146,432 | ---- | C] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2011.03.16 22:57:00 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat[2011.03.16 22:43:35 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat ========== LOP Check ========== [2011.03.20 14:12:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software[2011.03.20 18:10:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo[2011.03.20 14:07:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software[2011.09.27 19:51:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BabylonUpdater[2011.03.19 19:13:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bluetooth[2012.02.04 12:25:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite[2011.10.08 17:55:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Default[2012.04.01 01:31:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Easybits GO[2011.12.13 14:19:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts[2011.03.20 15:18:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET[2011.06.10 22:27:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FaceOffMax[2012.05.13 21:25:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameXN[2011.04.22 19:11:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InterAction studios[2011.09.18 00:53:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit[2011.04.30 21:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\KONAMI[2011.11.20 19:41:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia[2011.05.22 18:24:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaAccount[2011.05.22 17:38:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache[2011.12.13 14:22:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Origin[2011.06.28 11:23:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite[2011.09.17 14:48:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\POP3Profiles[2011.06.05 14:50:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Test Drive Unlimited[2011.10.06 21:08:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Application Data\PC Suite[2012.05.12 12:36:19 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Vasko1\Application Data\.#[2012.03.06 19:37:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\.minecraft[2011.03.20 18:11:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Ashampoo[2012.01.22 22:51:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\AskToolbar[2011.04.30 19:36:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Avanquest[2012.05.11 18:57:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Avant Downloader[2012.04.19 09:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\BSplayer[2012.01.21 03:46:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\BSplayer Pro[2012.05.13 10:40:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\DAEMON Tools Lite[2011.09.30 12:38:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Evaer[2011.06.10 22:12:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\FaceOffMax[2012.05.13 16:00:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\go[2012.01.22 17:55:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\hidden smilies 2.0[2011.09.16 21:50:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\InterTrust[2012.04.01 15:08:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\IObit[2011.11.20 19:40:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Nokia[2011.05.22 18:04:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Nokia Ovi Suite[2011.12.20 15:32:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Opera[2011.09.30 12:35:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Pamela[2011.05.22 18:04:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\PC Suite[2012.03.12 01:15:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\PhotoScape[2011.09.18 00:56:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\PriceGong[2011.12.15 23:03:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\QuickStoresToolbar[2011.06.22 01:01:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\Roads Of Rome[2012.03.23 19:28:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\TeamViewer[2012.05.13 21:28:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\uTorrent[2011.12.15 23:56:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\WinAVI[2011.05.01 14:12:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vasko1\Application Data\YoudaGames[2012.05.13 14:46:00 | 000,000,980 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003Core.job[2012.05.13 20:46:06 | 000,001,002 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003UA.job[2012.05.13 21:26:00 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job[2012.05.13 10:41:14 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job ========== Purity Check ========== ========== Custom Scans ========== < "%WinDir%\$NtUninstallKB*$." /30 > < C:\Program Files\Common Files\ComObjects\*.* /s > < %SYSTEMDRIVE%\*.* >[2011.09.17 15:34:46 | 000,439,601 | ---- | M] () -- C:\AnalysisLog.sr0[2011.03.16 22:49:19 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT[2011.03.16 22:39:55 | 000,000,211 | -HS- | M] () -- C:\boot.ini[2011.03.16 22:49:19 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS[2011.03.16 22:49:19 | 000,000,000 | RHS- | M] () -- C:\IO.SYS[2011.12.15 23:20:14 | 000,038,111 | ---- | M] () -- C:\MP4debug.log[2011.03.16 22:49:19 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS[2008.04.13 22:13:04 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM[2008.04.14 00:01:44 | 000,250,048 | RHS- | M] () -- C:\ntldr[2012.05.13 10:40:21 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys[2011.03.16 23:42:50 | 000,002,080 | ---- | M] () -- C:\RHDSetup.log[2011.11.27 00:08:39 | 000,000,275 | ---- | M] () -- C:\Shortcut to Local Disk (D).lnk[2012.05.12 12:36:11 | 000,000,449 | ---- | M] () -- C:\Sys_LogWin.log < %USERPROFILE%\*.* >[2012.05.13 03:35:27 | 009,961,472 | -H-- | M] () -- C:\Documents and Settings\Vasko1\NTUSER.DAT[2012.05.13 21:26:27 | 000,057,344 | -H-- | M] () -- C:\Documents and Settings\Vasko1\ntuser.dat.LOG[2012.05.13 03:35:27 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Vasko1\ntuser.ini < %USERPROFILE%\Application Data\*.* >[2011.03.17 00:33:42 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Vasko1\Application Data\desktop.ini[2011.09.17 16:47:37 | 000,139,152 | ---- | M] () -- C:\Documents and Settings\Vasko1\Application Data\PnkBstrK.sys < %USERPROFILE%\Local Settings\Application Data\*.* >[2012.05.12 12:41:40 | 000,146,432 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2012.05.12 14:44:11 | 000,070,760 | ---- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT[2012.05.13 03:35:18 | 008,623,608 | -H-- | M] () -- C:\Documents and Settings\Vasko1\Local Settings\Application Data\IconCache.db < %AllUsersProfile%\*.* > < %AllUsersProfile%\Application Data\*.* >[2011.03.17 00:33:42 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini < %USERPROFILE%\My Documents\*.* >[2011.03.20 21:12:43 | 000,000,077 | -HS- | M] () -- C:\Documents and Settings\Vasko1\My Documents\desktop.ini[2012.03.08 00:38:59 | 005,242,880 | ---- | M] () -- C:\Documents and Settings\Vasko1\My Documents\Locker01.flk[2012.04.25 16:31:24 | 000,288,768 | -H-- | M] () -- C:\Documents and Settings\Vasko1\My Documents\photothumb.db[2012.02.11 18:08:45 | 000,432,128 | -HS- | M] () -- C:\Documents and Settings\Vasko1\My Documents\Thumbs.db < %CommonProgramFiles%\*.* >[2009.06.19 12:12:46 | 001,828,176 | ---- | M] (Skype Technologies) -- C:\Program Files\Common Files\Skype4COM.dll < %PROGRAMFILES%\*.* > < %systemroot%\system32\config\systemprofile\*.* >[2011.11.18 12:41:33 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\NtUser.dat[2012.05.12 13:11:51 | 000,001,024 | -H-- | M] () -- C:\WINDOWS\system32\config\systemprofile\NtUser.dat.LOG < %windir%\ServiceProfiles\LocalService\AppData\Local\Temp\*.* > < %windir%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.* > < %windir% emp*.* > < %windir%\system32\*. >[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1025[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1028[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1031[2011.03.17 00:26:59 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1033[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1037[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1041[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1042[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\1054[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\2052[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\3076[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\3com_dmi[2012.04.21 22:18:33 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Adobe[2011.04.21 21:46:48 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\appmgmt[2011.05.22 18:33:09 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\CatRoot[2012.05.11 18:02:20 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\CatRoot2[2011.03.16 22:43:36 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Com[2012.04.01 15:07:30 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\config[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\dhcp[2012.03.18 19:18:20 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\DirectX[2012.05.11 18:00:50 | 000,000,000 | RHSD | M] -- C:\WINDOWS\system32\dllcache[2012.05.08 19:54:57 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\drivers[2012.02.11 14:33:47 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\DRVSTORE[2011.03.17 00:30:41 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\en[2011.05.01 12:40:30 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\en-US[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\export[2012.04.01 15:07:16 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\GroupPolicy[2011.03.17 00:27:04 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ias[2011.03.17 00:27:33 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\icsxml[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\IME[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\inetsrv[2011.03.20 21:05:53 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\KB905474[2011.03.16 23:44:07 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Lang[2011.09.17 16:47:21 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\LogFiles[2011.03.16 22:45:41 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Macromed[2011.03.16 23:00:25 | 000,000,000 | --SD | M] -- C:\WINDOWS\system32\Microsoft[2011.03.16 22:43:22 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\MsDtc[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\mui[2011.03.17 00:30:51 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\npp[2011.03.16 22:45:11 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\oobe[2011.03.20 19:08:19 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\PreInstall[2011.03.17 00:27:51 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ras[2011.09.19 19:13:14 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ReinstallBackups[2011.03.16 23:00:26 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Restore[2011.03.16 23:42:44 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\RTCOM[2011.03.17 00:31:13 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\scripting[2011.03.17 00:31:42 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\Setup[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\ShellExt[2011.03.20 14:15:51 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\SoftwareDistribution[2011.05.03 15:02:43 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\spool[2011.04.30 22:38:05 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\URTTEMP[2011.03.17 00:31:33 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\usmt[2012.04.01 15:07:16 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\wbem[2012.04.01 15:07:18 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\WindowsPowerShell[2012.04.01 15:07:16 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\winrm[2011.03.17 00:25:54 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\wins[2011.03.16 22:49:37 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\xircom[2012.05.11 18:17:20 | 000,000,000 | ---D | M] -- C:\WINDOWS\system32\XPSViewer < %Temp%\smtmp\1\*.* > < %Temp%\smtmp\2\*.* > < %Temp%\smtmp\3\*.* > < %Temp%\smtmp\4\*.* > < %systemroot%\system32\DBBK\*.* /s > < %systemroot%\system32\*.dll /lockedfiles >[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ] < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /90 > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >[2008.07.06 15:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll[2003.06.18 17:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\mdippr.dll < %systemroot%\*. /rp /s > < %systemroot%\assembly mp\*.* /S /MD5 > < %systemroot%\assembly emp\*.* /S /MD5 > < %systemroot%\assembly\GAC_32\*.* /S /MD5 >[2012.05.11 18:13:41 | 000,069,120 | ---- | M] () MD5=DC426A365577F27187F99EB506ECD5D1 -- C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll[2012.05.11 18:13:44 | 000,072,192 | ---- | M] () MD5=29B35A999E341A37BE67771BE01CC275 -- C:\WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll[2011.10.26 18:51:12 | 000,136,624 | ---- | M] () MD5=F8330DA53EA42B4080EBBA5D20E40F66 -- C:\WINDOWS\assembly\GAC_32\Microsoft.Office.Access.BusinessDataCatalog\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Access.BusinessDataCatalog.DLL[2011.11.30 01:57:21 | 000,964,480 | ---- | M] () MD5=408A13B0A1F61FFBA355AFDE05ADBBCA -- C:\WINDOWS\assembly\GAC_32\Microsoft.Office.BusinessData\14.0.0.0__71e9bce111e9429c\microsoft.office.businessdata.dll[2011.10.26 18:50:32 | 000,120,744 | ---- | M] () MD5=F7EB7A8AE50075F53819BA22599B3A2E -- C:\WINDOWS\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll[2011.11.30 01:57:20 | 000,518,016 | ---- | M] () MD5=4C0D1677B819E9D29F5E0B5B0427E41A -- C:\WINDOWS\assembly\GAC_32\Microsoft.SharePoint.BusinessData.Administration.Client\14.0.0.0__71e9bce111e9429c\Microsoft.SharePoint.BusinessData.Administration.Client.dll[2011.05.03 15:02:56 | 000,163,840 | ---- | M] () MD5=36BDD82A92AA704034475C2DEF7FBD29 -- C:\WINDOWS\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll[2011.10.26 18:51:26 | 000,370,608 | ---- | M] () MD5=99D8B5B9A5D631608242BAA23249B2E1 -- C:\WINDOWS\assembly\GAC_32\Microsoft.VisualStudio.Tools.Applications.InteropAdapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.InteropAdapter.dll[2012.05.11 18:13:42 | 000,066,728 | ---- | M] () MD5=C01B81BB10AD14DBC5C4ECD350638096 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\big5.nlp[2012.05.11 18:13:42 | 000,082,172 | ---- | M] () MD5=EE1F60F8774D74BED8B13498F3FE737A -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bopomofo.nlp[2012.05.11 18:13:42 | 000,116,756 | ---- | M] () MD5=F6DFDA5A31162D848634504565F6D321 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\ksc.nlp[2012.05.11 18:13:41 | 004,550,656 | ---- | M] () MD5=3BDAE07DA44654FA393A2A2BA242EA41 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll[2012.05.11 18:13:42 | 000,059,342 | ---- | M] () MD5=DA5748A89E22A3932387E65694B25BBB -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normidna.nlp[2012.05.11 18:13:42 | 000,045,794 | ---- | M] () MD5=3831A5E217D6FA828CCE1011DA26E677 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfc.nlp[2012.05.11 18:13:42 | 000,039,284 | ---- | M] () MD5=DBDE664E0BA4BACD0A6A04AE2232B205 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfd.nlp[2012.05.11 18:13:42 | 000,066,384 | ---- | M] () MD5=C9B88B759FE81D59CE8EBF5A0A8EB75A -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfkc.nlp[2012.05.11 18:13:42 | 000,060,294 | ---- | M] () MD5=3CAB6AB66759FCDF73B61EE262C9ACF4 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfkd.nlp[2012.05.11 18:13:42 | 000,083,748 | ---- | M] () MD5=54144F43EDF5AA8F504A30E7C1D1A7B5 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\prc.nlp[2012.05.11 18:13:42 | 000,083,748 | ---- | M] () MD5=901863C68E6523336CAC602FE9320ABC -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\prcp.nlp[2012.05.11 18:13:42 | 000,262,148 | ---- | M] () MD5=FB59D247F7143C3B9683A547E808A88B -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp[2012.05.11 18:13:42 | 000,020,320 | ---- | M] () MD5=FF13BA175F0013D2311827E0D438C60B -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp[2012.05.11 18:13:42 | 000,028,288 | ---- | M] () MD5=09E420F90A329BDA68477FA4AF43CB28 -- C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\xjis.nlp[2012.05.11 18:07:38 | 004,214,784 | ---- | M] () MD5=E0EB0BDC866E2C0CC792B83BD2422501 -- C:\WINDOWS\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll[2012.05.11 18:13:33 | 000,486,400 | ---- | M] () MD5=759FD3779911F89C450CCAE06B92AE3A -- C:\WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll[2012.05.11 18:13:47 | 002,933,248 | ---- | M] () MD5=16F96C1496CBD0965285AB19A9271D02 -- C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll[2012.05.11 18:13:40 | 000,258,048 | ---- | M] () MD5=9631B15DB7C43C267636FF43C3075E07 -- C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll[2012.05.11 18:13:40 | 000,113,664 | ---- | M] () MD5=E786C33D35D39C5CCB523AECC18D7BD7 -- C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll[2012.05.11 18:07:46 | 000,368,640 | ---- | M] () MD5=E915933B0E68B61A6AC22E06BD1AD651 -- C:\WINDOWS\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll[2012.05.11 18:13:38 | 000,261,632 | ---- | M] () MD5=F054572A92573CA32D5F3AA8C15D2BAC -- C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll[2012.05.11 18:13:32 | 005,246,976 | ---- | M] () MD5=661268A6BEEF1C1B0D1B9137F530A9FD -- C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll[2011.12.14 01:22:45 | 000,045,304 | ---- | M] () MD5=723130DF7BBCA7FC4BFB1F829ABD13B3 -- C:\WINDOWS\assembly\GAC_32\Update\1.1.3.0__318d21d4b0463a3b\Update.exe < %systemroot%\assembly\GAC_MSIL\*.* /S /MD5 >[2012.05.11 18:13:41 | 000,010,752 | ---- | M] () MD5=A5A56B4957BD59D324821522FE14F751 -- C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll[2012.05.11 18:13:34 | 000,507,904 | ---- | M] () MD5=B8FE2350B2236EE3D1CECA34E0C0FF17 -- C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll[2012.05.11 18:13:41 | 000,013,312 | ---- | M] () MD5=107F49F1BF0FB27A6CD758EB8C4D95A0 -- C:\WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll[2012.05.11 18:13:45 | 000,008,192 | ---- | M] () MD5=6CD7461E06CB8BAEE3B16C3D7F637CD0 -- C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll[2012.05.11 18:13:44 | 000,077,824 | ---- | M] () MD5=24F0385D06BD86A97412B8905483313E -- C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll[2012.05.11 18:13:43 | 000,006,656 | ---- | M] () MD5=11F3AC2D47E566615819F5BF0DD18379 -- C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll[2011.12.14 01:22:45 | 000,126,976 | ---- | M] () MD5=2613734670B491BE45410D496CEF7FA8 -- C:\WINDOWS\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__ffdc4657f9a00288\Interop.SHDocVw.dll[2011.10.26 18:50:32 | 000,030,608 | ---- | M] () MD5=D347C753E1BDECF73DEE86D3104529A7 -- C:\WINDOWS\assembly\GAC_MSIL\ipdmctrl\11.0.0.0__71e9bce111e9429c\IPDMCTRL.DLL[2012.04.01 15:07:37 | 000,007,168 | ---- | M] () MD5=75C183E262BD4400EB0F20349F6EF383 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.BackgroundIntelligentTransfer.Management.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.BackgroundIntelligentTransfer.Management.resources.dll[2012.04.01 15:07:36 | 000,057,344 | ---- | M] () MD5=2F7FE3A781BA8C0A67C775F20E3E9F70 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.BackgroundIntelligentTransfer.Management\1.0.0.0__31bf3856ad364e35\Microsoft.BackgroundIntelligentTransfer.Management.dll[2011.05.03 15:03:38 | 000,106,496 | ---- | M] () MD5=29CED3B606BA7E2B49E52931C5CB53B7 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Conversion.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Conversion.v3.5.dll[2012.05.11 18:13:43 | 000,348,160 | ---- | M] () MD5=996AAEEC01C734347DE8A72542FD1C12 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll[2011.05.03 15:03:39 | 000,733,184 | ---- | M] () MD5=31C6E94759BF4D2FBE3239FFA717967D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll[2012.05.11 18:13:43 | 000,036,864 | ---- | M] () MD5=D2A1C3150E43738BAB3D0AD9921B3E50 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll[2011.05.03 15:03:39 | 000,036,864 | ---- | M] () MD5=17C6F3F73858732DE59D6D957958E9AF -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll[2011.05.03 15:03:39 | 000,802,816 | ---- | M] () MD5=37F17D4698086C90127BBD90E73D7FE2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v3.5.dll[2012.05.11 18:13:43 | 000,655,360 | ---- | M] () MD5=8A3F5B72C3F402C8D33027A4C77F55AC -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll[2011.05.03 15:03:39 | 000,094,208 | ---- | M] () MD5=E32A06F647517D0DEA80F29B459E8FA2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v3.5.dll[2012.05.11 18:13:44 | 000,077,824 | ---- | M] () MD5=640BF6BB259B53BEFF59135645C63B18 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll[2011.10.26 18:51:19 | 000,116,632 | ---- | M] () MD5=668818ADBB2240C42567907FC1044E6E -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.BusinessData\14.0.0.0__71e9bce111e9429c\Microsoft.BusinessData.dll[2012.05.11 18:13:37 | 000,749,568 | ---- | M] () MD5=EB535D00C508119EEE4042B737165A3B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll[2011.10.26 18:50:41 | 000,096,128 | ---- | M] () MD5=94A1986FF31DADBE7ED939AE8C09B77A -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.Diagnostics\14.0.0.0__71e9bce111e9429c\microsoft.office.businessapplications.diagnostics.dll[2011.10.26 18:47:48 | 000,023,408 | ---- | M] () MD5=9073098C8053F437E010941E6BDCE1FD -- C:\WINDOWS\assembly\GAC_MSIL\microsoft.office.businessapplications.runtime.intl.resources\14.0.0.0_bg_71e9bce111e9429c\Microsoft.Office.BusinessApplications.Runtime.intl.resources.dll[2011.10.26 18:51:43 | 000,018,304 | ---- | M] () MD5=43D271F04CBA9737B85CB230930034A6 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.Runtime.Intl\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.Runtime.Intl.dll[2011.11.30 01:57:13 | 000,567,168 | ---- | M] () MD5=09A2E0159EC7A49B3D4D38BAA06A7FC3 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.Runtime\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.Runtime.dll[2011.10.26 18:47:48 | 000,055,152 | ---- | M] () MD5=C8F38CE5A181C03A788B903D315DBFF2 -- C:\WINDOWS\assembly\GAC_MSIL\microsoft.office.businessapplications.runtimeui.intl.resources\14.0.0.0_bg_71e9bce111e9429c\Microsoft.Office.BusinessApplications.RuntimeUi.intl.resources.dll[2011.10.26 18:51:46 | 000,079,744 | ---- | M] () MD5=9C984C911F3F7EB43F1CAD0A046434A2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.RuntimeUi.Intl\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.RuntimeUi.Intl.dll[2011.10.26 18:50:43 | 000,665,472 | ---- | M] () MD5=CE223A1E43DD5E16F70E9252C39741C2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.RuntimeUi\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.RuntimeUi.dll[2011.10.26 18:47:48 | 000,067,440 | ---- | M] () MD5=B19E8513537F049BEAE990233F990D80 -- C:\WINDOWS\assembly\GAC_MSIL\microsoft.office.businessapplications.syncservices.intl.resources\14.0.0.0_bg_71e9bce111e9429c\Microsoft.Office.BusinessApplications.SyncServices.Intl.Resources.dll[2011.10.26 18:51:46 | 000,051,072 | ---- | M] () MD5=150C4A73D0BF82623ABF8E42280EBDFC -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.SyncServices.Intl\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.SyncServices.Intl.dll[2011.11.30 01:57:13 | 001,689,472 | ---- | M] () MD5=E2AF2BAA129BD7DE59E756CD759D779F -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.SyncServices\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.SyncServices.dll[2011.10.26 18:51:43 | 000,051,072 | ---- | M] () MD5=0810C44901F6BE8B07C6CB4010E0DB4D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.Tools.AutoGen\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.Tools.AutoGen.dll[2011.11.30 01:57:14 | 000,169,856 | ---- | M] () MD5=AEDDE69A63A53B38310D2DDECDA831A7 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.Tools.Intl\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.Tools.Intl.dll[2011.11.30 01:57:14 | 000,427,904 | ---- | M] () MD5=A0FF9B104263F7E54C022D37D578938C -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessApplications.Tools\14.0.0.0__71e9bce111e9429c\Microsoft.Office.BusinessApplications.Tools.dll[2011.10.26 18:47:48 | 000,268,144 | ---- | M] () MD5=DBBC2A2194043A6C7E97696F3E2B3A0E -- C:\WINDOWS\assembly\GAC_MSIL\microsoft.office.businessdata.intl.resources\14.0.0.0_bg_71e9bce111e9429c\Microsoft.Office.BusinessData.Intl.Resources.dll[2011.10.26 18:50:41 | 000,206,720 | ---- | M] () MD5=ADDDFB6CE545CF14FA57039B75C22589 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.BusinessData.Intl\14.0.0.0__71e9bce111e9429c\microsoft.office.businessdata.intl.dll[2011.10.26 18:51:35 | 000,546,704 | ---- | M] () MD5=4210A244E3FC04751F24E27CCDF33B36 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll[2011.10.26 18:50:32 | 000,042,880 | ---- | M] () MD5=3B161FBED7099618C08AA69B6D8B14D0 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.FormControl\14.0.0.0__71e9bce111e9429c\microsoft.office.infopath.formcontrol.dll[2011.10.26 18:51:35 | 000,014,224 | ---- | M] () MD5=BFAC08A7315492592B3F528018BC8713 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Permission\14.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Permission.dll[2011.10.26 18:51:38 | 000,034,680 | ---- | M] () MD5=046E63D3804F5AA2A54211727E1A8886 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Vsta\14.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Vsta.dll[2011.10.26 18:51:35 | 000,059,248 | ---- | M] () MD5=AC59BB0E798D654A403632D2512F668B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.dll[2011.10.26 18:51:12 | 000,079,744 | ---- | M] () MD5=BB39161455A053800391C52840FC010A -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Access.Dao\14.0.0.0__71e9bce111e9429c\Microsoft.Office.interop.access.dao.dll[2011.11.30 01:57:10 | 001,857,400 | ---- | M] () MD5=E068F5F2FEAB127A11451C028CF157AE -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Access\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Access.dll[2011.10.26 18:50:22 | 001,550,200 | ---- | M] () MD5=79A6278FF98538E5F3E51D8A01C246E5 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Excel\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll[2011.10.26 18:50:26 | 000,149,368 | ---- | M] () MD5=EB2CFA115D1D16117F7EF8A253EF53DC -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Graph\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll[2011.10.26 18:50:31 | 000,407,440 | ---- | M] () MD5=3862D60F6AE28C9AE434BFB5FEFBD98C -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.InfoPath.SemiTrust\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.SemiTrust.dll[2011.10.26 18:51:38 | 000,087,936 | ---- | M] () MD5=EB10E40E824FA29F56C2B2FB17853116 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.InfoPath.Xml\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.Xml.dll[2011.10.26 18:51:35 | 000,161,656 | ---- | M] () MD5=388D4284E3050DC447E57C0400F015BB -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.InfoPath\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.dll[2011.10.26 18:51:58 | 000,016,248 | ---- | M] () MD5=C41AE505E62434EB08F42EBEC6DBEB2C -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.OneNote\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OneNote.dll[2011.10.26 18:50:56 | 000,046,968 | ---- | M] () MD5=8318FE8E736EA06662275CB6E53F488E -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.OneNote\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OneNote.dll[2011.10.26 18:52:00 | 000,972,664 | ---- | M] () MD5=D56157EC631B91BB9E439FDC597F0E36 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Outlook\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll[2011.10.26 18:50:54 | 000,025,480 | ---- | M] () MD5=BE021CFEEE55BA6E1147451A259F098C -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.OutlookViewCtl\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll[2011.10.26 18:52:02 | 000,386,944 | ---- | M] () MD5=114882E8C607D45E4769CFFC931CF5BF -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.PowerPoint\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll[2011.10.26 18:52:03 | 000,247,680 | ---- | M] () MD5=3796C003FA4D78FB569967A5E3F9325B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Publisher\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Publisher.dll[2011.10.26 18:50:47 | 000,019,320 | ---- | M] () MD5=370BA1A9D8155AD569F79283E91888B8 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.SmartTag\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll[2011.10.26 18:52:07 | 000,907,120 | ---- | M] () MD5=386CC49F35BE2A90E2E3339619102BF3 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Interop.Word\14.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll[2011.10.26 18:50:23 | 000,356,352 | ---- | M] () MD5=0A8FCA67378EC92E2F304E6750DD9FD1 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Tools.Common.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Common.v9.0.dll[2011.10.26 18:50:23 | 000,438,272 | ---- | M] () MD5=409B1D3ED9ECAAB3D7DA66A83E1161A9 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Tools.Excel.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Excel.v9.0.dll[2011.10.26 18:51:25 | 000,077,824 | ---- | M] () MD5=41D096C3E61378485D7B8AAFF00C245D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Tools.Outlook.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Outlook.v9.0.dll[2011.10.26 18:50:48 | 000,094,208 | ---- | M] () MD5=CF53CB86A8D49F5CCA58D8FF8AE246A9 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Tools.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.v9.0.dll[2011.10.26 18:51:25 | 000,299,008 | ---- | M] () MD5=8447FB78623AACCCFC609F01D1723935 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.Tools.Word.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.Office.Tools.Word.v9.0.dll[2012.04.01 15:07:37 | 000,010,752 | ---- | M] () MD5=4E2482E69BAAF3A5B13DB8101C063EBF -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.resources.dll[2012.04.01 15:07:35 | 000,102,400 | ---- | M] () MD5=08E87E8ABF7B41B28663DCE817CE0AB6 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll[2012.04.01 15:07:36 | 000,036,864 | ---- | M] () MD5=B87E087FC013225E2AA1CB60C080647D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.resources.dll[2012.04.01 15:07:34 | 000,262,144 | ---- | M] () MD5=F3AC3F844F90380AAB2B4C0836C4288F -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll[2012.04.01 15:07:36 | 000,049,152 | ---- | M] () MD5=1CE73FB3F88C716CFC3FD550547D2B35 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.resources.dll[2012.04.01 15:07:34 | 000,618,496 | ---- | M] () MD5=DFEB401CC051E5DA721C584FF6A90F88 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll[2012.04.01 15:07:36 | 000,040,960 | ---- | M] () MD5=36FF641F37918F2CCA98E7F407AC4D75 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.resources.dll[2012.04.01 15:07:34 | 000,200,704 | ---- | M] () MD5=3991B7FA452A9C9C291C06365A236792 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll[2012.04.01 15:07:40 | 000,069,632 | ---- | M] () MD5=37BED865557084DD9988350AB1675E0B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Editor.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Editor.resources.dll[2012.04.01 15:07:39 | 000,991,232 | ---- | M] () MD5=208FA9D0EBE2CEB9616042772E96598E -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Editor\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Editor.dll[2012.04.01 15:07:40 | 000,040,960 | ---- | M] () MD5=108500A98B9A2F66823E7615398FC87B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.GPowerShell.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.GPowerShell.resources.dll[2012.04.01 15:07:40 | 000,651,264 | ---- | M] () MD5=D4EEFCCDC3DE6CED901535FA4153C491 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.GPowerShell\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.GPowerShell.dll[2012.04.01 15:07:40 | 000,016,896 | ---- | M] () MD5=5A69FB5D686F863E0E13268D671EF16D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.GraphicalHost.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.GraphicalHost.resources.dll[2012.04.01 15:07:39 | 000,278,528 | ---- | M] () MD5=3EAB4DBDC290EDC4D53FE77F1FDB9E59 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.GraphicalHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.GraphicalHost.dll[2012.04.01 15:07:36 | 000,009,216 | ---- | M] () MD5=C7A0D1321A67A2AFD330C5FBE79BEFD1 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Security.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.PowerShell.Security.resources.dll[2012.04.01 15:07:35 | 000,069,632 | ---- | M] () MD5=53A9D748EF09920A0D06DA2583C298AD -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll[2011.10.26 18:51:43 | 000,206,720 | ---- | M] () MD5=B1B0C658E5E2DEE8273A8667D5CAB7E0 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.SharePoint.BusinessData.Administration.Client.Intl\14.0.0.0__71e9bce111e9429c\Microsoft.SharePoint.BusinessData.Administration.Client.Intl.dll[2011.10.26 18:50:26 | 000,115,744 | ---- | M] () MD5=DA5EE020BEF41DC95C3532CBAA1EA8F4 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Synchronization.Data.Server\1.0.0.0__89845dcd8080cc91\Microsoft.Synchronization.Data.Server.dll[2011.10.26 18:51:29 | 000,095,312 | ---- | M] () MD5=5C8089FDA655A38440F279DEB7925C46 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Synchronization.Data.SqlServerCe\3.5.0.0__89845dcd8080cc91\Microsoft.Synchronization.Data.SqlServerCe.dll[2011.10.26 18:51:28 | 000,115,744 | ---- | M] () MD5=01B68622F7B4A699D52F9A0B5EA5E4EC -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Synchronization.Data\1.0.0.0__89845dcd8080cc91\Microsoft.Synchronization.Data.dll[2011.05.03 15:02:55 | 000,397,312 | ---- | M] () MD5=66F6B3248D6C39CEFA49174133A694FE -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll[2011.10.26 18:50:25 | 000,374,640 | ---- | M] () MD5=786BABFD5E40B254EE46F3EEE81C36F4 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll[2011.10.26 18:51:08 | 000,063,336 | ---- | M] () MD5=572E69066CE577FBF849E8D715CE0B82 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vbe.Interop\14.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll[2012.05.11 18:13:37 | 000,110,592 | ---- | M] () MD5=D676BC7C829F86A215676281A1032C6B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll[2012.05.11 18:13:39 | 000,372,736 | ---- | M] () MD5=226956F70AEBBBF5ACBC9ADA6522B6F6 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll[2012.05.11 18:13:44 | 000,028,672 | ---- | M] () MD5=3D61BFCBE13C2DC8F5AE20BF02145322 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll[2012.05.11 18:13:39 | 000,659,456 | ---- | M] () MD5=EFC806A1C4C6CE9F69AECE0AB72C1E34 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll[2011.05.03 15:03:38 | 000,041,984 | ---- | M] () MD5=9F065BF574C956B85DB355C32E7E995E -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\1.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.STLCLR.dll[2012.05.11 18:13:42 | 000,005,632 | ---- | M] () MD5=7E50D25F9A5BC75F22CA7AEB52176CA2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll[2011.10.26 18:51:26 | 000,286,720 | ---- | M] () MD5=F0DA890A63403E2010788FDBC1801FA7 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Adapter.v9.0.dll[2011.10.26 18:51:26 | 000,210,848 | ---- | M] () MD5=2E57C4C703D80B484CDDE2C13BA27BF1 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Adapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Adapter.dll[2011.11.30 01:57:11 | 000,041,408 | ---- | M] () MD5=01740C30C6063A7E942EA6330E88DAC6 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v10.0.dll[2011.10.26 18:51:47 | 000,045,056 | ---- | M] () MD5=8510E5F664F1C9136E73A13B0C8E5357 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.dll[2011.10.26 18:50:24 | 000,104,368 | ---- | M] () MD5=9C7403906909E432EA6A2511D1B3CDF2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInManager\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInManager.dll[2011.10.26 18:51:26 | 000,329,632 | ---- | M] () MD5=5DDDB6F96BF41B9FE9C4AB0920A0E445 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Blueprints\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Blueprints.dll[2011.10.26 18:51:26 | 000,038,832 | ---- | M] () MD5=CC5ECB09FFDD2A7915E3E98A15DF262E -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.dll[2011.11.30 01:57:10 | 000,024,496 | ---- | M] () MD5=ABE26CE56EAA14ABF51E6BA779A3984E -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.dll[2011.10.26 18:51:24 | 000,022,016 | ---- | M] () MD5=6581FE75715D9D6FF9BFD2264F825FB0 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.dll[2011.10.26 18:50:24 | 000,038,808 | ---- | M] () MD5=907114FE32F4DFB0C5EDA360BE0740C7 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Contract\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Contract.dll[2011.10.26 18:50:23 | 000,071,592 | ---- | M] () MD5=5949DF7B1BF7951C55A31803CD4DC6E2 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.DesignTime\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.DesignTime.dll[2011.11.30 01:57:14 | 000,035,256 | ---- | M] () MD5=9BF071EFED4CEBB1B03FDE7942E0BE80 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.dll[2011.11.30 01:57:11 | 000,153,008 | ---- | M] () MD5=8EDF67A0526AC03E4EAFDB062AC273B8 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Hosting.v10.0.dll[2011.10.26 18:50:24 | 000,143,360 | ---- | M] () MD5=BF1B6B22209E8126A184BFA2C4FB49BE -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Hosting.v9.0.dll[2011.11.30 01:57:14 | 000,032,688 | ---- | M] () MD5=46E3223333A8DD1684B7639F42D9584D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll[2011.10.26 18:51:47 | 000,077,824 | ---- | M] () MD5=DC553264A749613C331C8B989A1A9B2A -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.dll[2011.11.30 01:57:10 | 000,193,472 | ---- | M] () MD5=066BB2ABAA5C8E45ED37E691355B5185 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v10.0.dll[2011.10.26 18:50:47 | 000,110,592 | ---- | M] () MD5=3A717D3B1B2F5921871B0561E71DD4D8 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ServerDocument.v9.0.dll[2011.10.26 18:50:44 | 000,081,920 | ---- | M] () MD5=A7278626DFE2AAFDDBA6B8B82AA94CEF -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll[2011.10.26 18:50:24 | 000,131,072 | ---- | M] () MD5=B169C95A3BEFA21EBA58D21992EB6A9C -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.AppInfoDocument.v9.0.dll[2011.11.30 01:57:15 | 000,062,392 | ---- | M] () MD5=022AFCC5C5CE34EA13C706AE0A296AD4 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.ContainerControl.v10.0.dll[2011.11.30 01:57:11 | 000,023,976 | ---- | M] () MD5=CD8C6E27F96A8A8A894F78B1512C188A -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Contract.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.dll[2011.10.26 18:50:23 | 000,049,152 | ---- | M] () MD5=77249A017C234EC21BC60DABB8515896 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Contract.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.dll[2011.10.26 18:50:44 | 000,036,864 | ---- | M] () MD5=AD54FE98130FA82E5A75A1906F7F14A9 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.dll[2011.10.26 18:50:44 | 000,053,248 | ---- | M] () MD5=07E7E7818586A3B3F1EC50E5E2511FC0 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Excel.AddInProxy.v9.0.dll[2011.11.30 01:57:11 | 000,077,752 | ---- | M] () MD5=F8EA342008DD949F1706FCAAC0E07FE7 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Excel.HostAdapter.v10.0.dll[2011.11.30 01:57:15 | 000,063,408 | ---- | M] () MD5=DDD9726B8F5801145DDCE84FA40916C3 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.HostAdapter.v10.0.dll[2011.11.30 01:57:12 | 000,041,408 | ---- | M] () MD5=3ADC112241D4D0F55EF7EF2EDEAEDC2F -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Outlook.HostAdapter.v10.0.dll[2011.11.30 01:57:12 | 000,363,936 | ---- | M] () MD5=F17156AE7E7696601B3221090AB9D20F -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Runtime.v10.0.dll[2011.10.26 18:51:48 | 000,036,864 | ---- | M] () MD5=0C5700ED83D92BBB5E6F70AB89C26F04 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.dll[2011.10.26 18:51:48 | 000,065,536 | ---- | M] () MD5=4167FAFE231BE780D7158B0A7E5D337D -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0\9.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Word.AddInProxy.v9.0.dll[2011.11.30 01:57:12 | 000,083,896 | ---- | M] () MD5=145C93E147C9C5F809E2E1D398C4C5E4 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0\10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Office.Word.HostAdapter.v10.0.dll[2012.05.11 18:13:45 | 000,012,800 | ---- | M] () MD5=B27AA2EA41728FAF5E9642CFD2958FB9 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll[2012.05.11 18:13:39 | 000,032,768 | ---- | M] () MD5=D251A67B7D6DE2194F6E264055E020FB -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll[2011.10.23 23:12:24 | 000,884,736 | ---- | M] () MD5=E42998E3BB92E6696A82EF796EFAC507 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Web.Services3\3.0.0.0__31bf3856ad364e35\Microsoft.Web.Services3.dll[2012.04.01 15:07:37 | 000,013,824 | ---- | M] () MD5=6372EA7D2ACED7185183CF3FCDD3577B -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.WSMan.Management.resources\1.0.0.0_en_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll[2012.04.01 15:07:35 | 000,274,432 | ---- | M] () MD5=1A4E900C2FE3CD31D10107670D184FE6 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll[2012.04.01 15:07:35 | 000,007,168 | ---- | M] () MD5=F7DA27672D2E4C21A1F996EE31DE0DBF -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll[2012.05.11 18:13:37 | 000,007,168 | ---- | M] () MD5=9659028AFA77387D6D2BF4280C10AB94 -- C:\WINDOWS\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll[2011.10.26 18:51:57 | 000,448,360 | ---- | M] () MD5=6E84AAA11121D806DADC159CED3E3DDA -- C:\WINDOWS\assembly\GAC_MSIL\office\14.0.0.0__71e9bce111e9429c\OFFICE.DLL[2011.11.30 01:57:10 | 000,000,900 | ---- | M] () MD5=3B7B0D23927E9331354BFD0DFA09910F -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Access\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Access.config[2011.11.30 01:57:10 | 000,011,656 | ---- | M] () MD5=7E982B4F2EDEE4C8FBDA3F28DB13940E -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Access\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Access.dll[2011.10.26 18:50:22 | 000,000,898 | ---- | M] () MD5=E3C1C0D2C327FEC85FB9857E3F899785 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Excel\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.config[2011.10.26 18:51:24 | 000,011,656 | ---- | M] () MD5=7EAF6D9700040029FA01375A920B521F -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Excel\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll[2011.10.26 18:50:27 | 000,000,898 | ---- | M] () MD5=10615D207C75102FC721755BB0B3CD8E -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Graph\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.config[2011.10.26 18:51:30 | 000,011,656 | ---- | M] () MD5=7E9ABF813463163E3575E5C92BE71A8D -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Graph\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll[2011.10.26 18:50:36 | 000,000,912 | ---- | M] () MD5=E3EFA5C36AB83B5E678ED1CADE23B412 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.config[2011.10.26 18:51:40 | 000,011,664 | ---- | M] () MD5=9E8528A64196AA99876B3034F312CC98 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.dll[2011.10.26 18:51:38 | 000,000,904 | ---- | M] () MD5=DCADD75D7AF7337A635A78D7C7F20D9A -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.InfoPath\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.config[2011.10.26 18:50:36 | 000,011,664 | ---- | M] () MD5=3A7A2A7C91F9F50D000F593810A5618C -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.InfoPath\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.dll[2011.10.26 18:52:00 | 000,000,902 | ---- | M] () MD5=6294F9D1634C5110426C7DAFE2F685A0 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Outlook\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Outlook.config[2011.10.26 18:50:59 | 000,011,656 | ---- | M] () MD5=AF6DCC105912C2A9D514D8941F1F3339 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Outlook\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Outlook.dll[2011.10.26 18:50:54 | 000,000,916 | ---- | M] () MD5=333236C30617B03AE650230780E21EAA -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.config[2011.10.26 18:51:58 | 000,011,672 | ---- | M] () MD5=A1B80AAF87F8EBC0DF0857BCDF48F4BC -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll[2011.10.26 18:52:03 | 000,000,908 | ---- | M] () MD5=EC791B712B81C85372E03A0617D24BF7 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.PowerPoint\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.config[2011.10.26 18:51:01 | 000,011,664 | ---- | M] () MD5=C8239B3E66BDB63D8A1938FE7B4DCE20 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.PowerPoint\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll[2011.10.26 18:52:03 | 000,000,906 | ---- | M] () MD5=449F5367C27EBC6CB917460F0DE2B0CB -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Publisher\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Publisher.config[2011.10.26 18:51:02 | 000,011,664 | ---- | M] () MD5=7511DBE6D0B0EA4B0383F137AEC72D55 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Publisher\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Publisher.dll[2011.10.26 18:50:47 | 000,000,904 | ---- | M] () MD5=4F7AB727B60621BB36E47B682F4BFE23 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.SmartTag\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.config[2011.10.26 18:51:55 | 000,011,664 | ---- | M] () MD5=9883D76E2777A0FF724BB34C4F47C80F -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.SmartTag\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll[2011.10.26 18:52:08 | 000,000,896 | ---- | M] () MD5=C018AC4E3EFFBFF5ABB8E5D9608A8762 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Word\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.config[2011.10.26 18:51:09 | 000,011,656 | ---- | M] () MD5=2BD0AF3F15E24A3B97E4453357BCAD3E -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Office.Interop.Word\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll[2011.10.26 18:51:08 | 000,000,880 | ---- | M] () MD5=6CF29BFDC5FA7B2FE06AE04FA0DDB1B2 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Vbe.Interop\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.config[2011.10.26 18:52:06 | 000,011,640 | ---- | M] () MD5=96A8D791500D842A026A2A32BDC7BCA6 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.Microsoft.Vbe.Interop\14.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll[2011.10.26 18:51:57 | 000,000,850 | ---- | M] () MD5=8E5E41526B4BF8D28A10C54D04D04866 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.office\14.0.0.0__71e9bce111e9429c\Policy.11.0.office.config[2011.10.26 18:50:52 | 000,011,104 | ---- | M] () MD5=BBF1A582F1C6155590108B38C8075759 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.11.0.office\14.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll[2011.10.26 18:50:32 | 000,000,930 | ---- | M] () MD5=F3BFE3718EC61BEB4EEF7180EC9E2F66 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath.Client.Internal.Host\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.Client.Internal.Host.config[2011.10.26 18:51:35 | 000,011,664 | ---- | M] () MD5=975E7224274D8EA867067B752EFF87D1 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath.Client.Internal.Host\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.Client.Internal.Host.dll[2011.10.26 18:50:32 | 000,000,912 | ---- | M] () MD5=8178E3FB89E1EE2F91F678D5E13367BF -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath.FormControl\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.FormControl.config[2011.10.26 18:51:35 | 000,011,664 | ---- | M] () MD5=927BCDEC2365C4CAEB00B60AC689507D -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath.FormControl\14.0.0.0__71e9bce111e9429c\policy.12.0.Microsoft.Office.InfoPath.FormControl.dll[2011.10.26 18:50:36 | 000,000,910 | ---- | M] () MD5=1D48EED186B3272682634155C17AAB1E -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath.Permission\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.Permission.config[2011.10.26 18:51:38 | 000,011,664 | ---- | M] () MD5=78E3D657EA7770BD031C6619536DE2A4 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath.Permission\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.Permission.dll[2011.10.26 18:51:38 | 000,000,888 | ---- | M] () MD5=66DFFED0DCD33FFAA9295DA912CC237C -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.config[2011.10.26 18:50:36 | 000,011,664 | ---- | M] () MD5=651C9951412B3441ABE5BE9ADE9E2DB4 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.InfoPath\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.InfoPath.dll[2011.10.26 18:51:13 | 000,000,908 | ---- | M] () MD5=8A9FDA784C76AEBFCC8266727C31A77D -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Access.Dao\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Access.Dao.config[2011.10.26 18:50:13 | 000,011,664 | ---- | M] () MD5=1AD4166C04970B0F4C69A3E7DDC3CC2D -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Access.Dao\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Access.Dao.dll[2011.11.30 01:57:09 | 000,000,900 | ---- | M] () MD5=6E5E053BA637800ECBBCCDBB3C046104 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Access\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Access.config[2011.11.30 01:57:09 | 000,011,656 | ---- | M] () MD5=F0CD5F9618DED7E0F612DD8F94494CD3 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Access\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Access.dll[2011.10.26 18:51:11 | 000,000,898 | ---- | M] () MD5=E0CE8837AA281AE2C19739274386F0C1 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Excel\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Excel.config[2011.10.26 18:52:10 | 000,011,656 | ---- | M] () MD5=0660718DE1A3740CD87109BE1BEEC730 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Excel\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Excel.dll[2011.10.26 18:50:26 | 000,000,898 | ---- | M] () MD5=3D00C53C80C2B84B5D948F41D1A58469 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Graph\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Graph.config[2011.10.26 18:51:30 | 000,011,656 | ---- | M] () MD5=A5B6A68F5F4075BBCBC287C371972FC2 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Graph\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Graph.dll[2011.10.26 18:50:36 | 000,000,912 | ---- | M] () MD5=A581EAC28DAEEB75339122F5C9015AD6 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.InfoPath.Xml\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.InfoPath.Xml.config[2011.10.26 18:51:41 | 000,011,664 | ---- | M] () MD5=5B54654ECD53D7100802002B179EEA6D -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.InfoPath.Xml\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.InfoPath.Xml.dll[2011.10.26 18:51:38 | 000,000,904 | ---- | M] () MD5=544EA0940AABB6C6C918CDF6563783CF -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.InfoPath\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.InfoPath.config[2011.10.26 18:50:36 | 000,011,664 | ---- | M] () MD5=AF24B14845D68C24D756C4AD57BB1770 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.InfoPath\14.0.0.0__71e9bce111e9429c\policy.12.0.Microsoft.Office.Interop.InfoPath.dll[2011.10.26 18:52:00 | 000,000,902 | ---- | M] () MD5=44193BB603AD240A860033F7EFC2E7E8 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Outlook\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Outlook.config[2011.10.26 18:50:59 | 000,011,656 | ---- | M] () MD5=027FA86FD3041FE291464465FCDB337E -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Outlook\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Outlook.dll[2011.10.26 18:50:52 | 000,000,916 | ---- | M] () MD5=30336C1CC94EDD19CDFB724E3A5AF015 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.OutlookViewCtl\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.OutlookViewCtl.config[2011.10.26 18:51:57 | 000,011,672 | ---- | M] () MD5=ECC242CB7160EEB8E1885E200449F65E -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.OutlookViewCtl\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.OutlookViewCtl.dll[2011.10.26 18:52:02 | 000,000,908 | ---- | M] () MD5=8199AE1C79C0443071D0352D70CE4DAA -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.PowerPoint\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.PowerPoint.config[2011.10.26 18:51:01 | 000,011,664 | ---- | M] () MD5=A611CBFFCAA65D8BF465A15F9693679F -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.PowerPoint\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.PowerPoint.dll[2011.10.26 18:52:03 | 000,000,906 | ---- | M] () MD5=8C6C64A729444CD2E32FC753D71DB76C -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Publisher\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Publisher.config[2011.10.26 18:51:02 | 000,011,664 | ---- | M] () MD5=719B94FFCC629739E2AEC68D70F2F77A -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Publisher\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Publisher.dll[2011.10.26 18:50:47 | 000,000,904 | ---- | M] () MD5=0AFCE67890E647DCADD27A5C0DA495C3 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.SmartTag\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.SmartTag.config[2011.10.26 18:51:55 | 000,011,664 | ---- | M] () MD5=8D8DBB9C4811EC4255B878D50D06B627 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.SmartTag\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.SmartTag.dll[2011.10.26 18:52:07 | 000,000,896 | ---- | M] () MD5=F3D871161A09684A2930117D6BDAAF91 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Word\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Word.config[2011.10.26 18:51:09 | 000,011,656 | ---- | M] () MD5=A7D719DF8AB1D3C9278C279C1D273ACF -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Office.Interop.Word\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Office.Interop.Word.dll[2011.10.26 18:51:08 | 000,000,880 | ---- | M] () MD5=C96C6F48979A5F9F131AA9FCB228B0D1 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Vbe.Interop\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Vbe.Interop.config[2011.10.26 18:52:06 | 000,011,640 | ---- | M] () MD5=AC9E566B2E1EF289B6B44934CA3CB160 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.Microsoft.Vbe.Interop\14.0.0.0__71e9bce111e9429c\Policy.12.0.Microsoft.Vbe.Interop.dll[2011.10.26 18:51:57 | 000,000,850 | ---- | M] () MD5=E387AFF00A5E533338760D8E78ED8AFB -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.office\14.0.0.0__71e9bce111e9429c\Policy.12.0.office.config[2011.10.26 18:50:52 | 000,011,104 | ---- | M] () MD5=36E29C6106F087A16A45EEA7E044C3D1 -- C:\WINDOWS\assembly\GAC_MSIL\Policy.12.0.office\14.0.0.0__71e9bce111e9429c\Policy.12.0.Office.dll[2011.10.26 18:50:22 | 000,000,565 | ---- | M] () MD5=728C41A6BE9A4A809F7E063FFA2F56D1 -- C:\WINDOWS\assembly\GAC_MSIL\policy.3.5.System.Data.SqlServerCe.Entity\3.5.0.0__89845dcd8080cc91\entitypub.config[2011.10.26 18:51:22 | 000,013,392 | ---- | M] () MD5=8CD049B83846CEB2B5B50CC7DE1DD5DD -- C:\WINDOWS\assembly\GAC_MSIL\policy.3.5.System.Data.SqlServerCe.Entity\3.5.0.0__89845dcd8080cc91\policy.3.5.System.Data.SqlServerCe.Entity.dll[2011.10.26 18:51:02 | 000,013,392 | ---- | M] () MD5=ECB1B568E8E97CC8BB1F1CA55C942F1F -- C:\WINDOWS\assembly\GAC_MSIL\policy.3.5.System.Data.SqlServerCe\3.5.0.0__89845dcd8080cc91\policy.3.5.System.Data.SqlServerCe.dll[2011.10.26 18:52:03 | 000,000,558 | ---- | M] () MD5=2D562F88863EDF6FF31D3D374F3A33C2 -- C:\WINDOWS\assembly\GAC_MSIL\policy.3.5.System.Data.SqlServerCe\3.5.0.0__89845dcd8080cc91\publisher.config[2011.05.03 15:03:02 | 000,598,016 | ---- | M] () MD5=28595FA306E58AACD7DAFF001F430703 -- C:\WINDOWS\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll[2011.05.03 15:02:59 | 000,032,768 | ---- | M] () MD5=93F9CC2360815D8EF955407CF92B38AA -- C:\WINDOWS\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll[2011.05.03 15:03:02 | 000,046,104 | ---- | M] () MD5=8BA7C024070F2B7FDD98ED8A4BA41789 -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFontCache\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe[2011.05.03 15:03:03 | 000,196,608 | ---- | M] () MD5=0C488A21B5A63055CB7736E3E0C75B1F -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll[2011.05.03 15:03:03 | 000,139,264 | ---- | M] () MD5=DA8417F8973EC51F0F1859CA0B334FC5 -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll[2011.05.03 15:03:03 | 000,397,312 | ---- | M] () MD5=7E61032F4F2BAB036B859D3B22D26DD0 -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll[2011.05.03 15:03:03 | 000,163,840 | ---- | M] () MD5=D1E117EDDEFEB220351BE0C7B27A4646 -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll[2012.05.11 18:07:40 | 005,283,840 | ---- | M] () MD5=2CFE88EE740380F4B594B2DE58AA933D -- C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll[2011.05.03 15:03:04 | 000,864,256 | ---- | M] () MD5=428D3714C85BACE55476C91E0D90E495 -- C:\WINDOWS\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll[2011.12.14 01:22:45 | 000,040,184 | ---- | M] () MD5=5494D46CBE14A5E0644CB219C9AC2FEA -- C:\WINDOWS\assembly\GAC_MSIL\QuickStoresToolbar\1.1.0.0__318d21d4b0463a3b\QuickStoresToolbar.dll[2012.05.11 18:07:45 | 000,532,480 | ---- | M] () MD5=E785AE3CC6341D63346B5F899B6FE7AC -- C:\WINDOWS\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll[2011.05.03 15:03:40 | 000,005,632 | ---- | M] () MD5=807B70A78ACE7D01F769FE502A769E67 -- C:\WINDOWS\assembly\GAC_MSIL\Sentinel.v3.5Client\3.5.0.0__b03f5f7f11d50a3a\Sentinel.v3.5Client.dll[2011.05.04 15:03:57 | 000,110,592 | ---- | M] () MD5=BD6B60E0F4FA84FF4E3089EDF9B81C9A -- C:\WINDOWS\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll[2012.05.11 18:13:42 | 000,110,592 | ---- | M] () MD5=0AD1C94AB2D36B79B9F2B54EADEB300A -- C:\WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll[2011.05.03 15:03:40 | 000,045,056 | ---- | M] () MD5=B34B75256D536385B927193FB1DCBB81 -- C:\WINDOWS\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll[2011.10.26 18:51:27 | 000,038,744 | ---- | M] () MD5=7137B00CD3C6AD6AAAC4D7EE614137D5 -- C:\WINDOWS\assembly\GAC_MSIL\System.AddIn\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.dll[2012.05.11 18:16:58 | 000,163,840 | ---- | M] () MD5=AA647B387E4086FDE32C8E976732F635 -- C:\WINDOWS\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll[2011.05.03 15:03:44 | 000,057,344 | ---- | M] () MD5=34AAEA0DCF908A7D3C1D8C2132B0E4D4 -- C:\WINDOWS\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\3.5.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll[2012.05.11 18:13:45 | 000,081,920 | ---- | M] () MD5=41BC941761FB3D1E21826C3C0E3CEEEE -- C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll[2012.05.11 18:13:37 | 000,425,984 | ---- | M] () MD5=C1C4025B5F5311AC8BCC318B0C244D58 -- C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll[2011.05.03 15:03:41 | 000,667,648 | ---- | M] () MD5=6617F24759BB1F3873C88AD9E0DF0435 -- C:\WINDOWS\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll[2011.05.03 15:03:41 | 000,053,248 | ---- | M] () MD5=1FDC244EEDD9B7804C7829DA11F1522E -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.DataSetExtensions\3.5.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll[2011.05.03 15:03:41 | 000,229,376 | ---- | M] () MD5=3FE6C3CDB01F039110152B1B0AE4980F -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.Entity.Design\3.5.0.0__b77a5c561934e089\System.Data.Entity.Design.dll[2011.05.03 15:03:41 | 002,879,488 | ---- | M] () MD5=CB45DFC6F9E1F954A718769D02D9C312 -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.Entity\3.5.0.0__b77a5c561934e089\System.Data.Entity.dll[2011.05.03 15:03:38 | 000,684,032 | ---- | M] () MD5=DDFB10C4A14ADD5D0A6C96E6DC3D29DF -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.Linq\3.5.0.0__b77a5c561934e089\System.Data.Linq.dll[2011.05.03 15:06:41 | 000,294,912 | ---- | M] () MD5=2F69FF4ED483D3FF399534F99BD4694A -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll[2011.05.03 15:03:37 | 000,114,688 | ---- | M] () MD5=0A7F3B1C1A9CC722F48A7A16394F61C4 -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.Services.Design\3.5.0.0__b77a5c561934e089\System.Data.Services.Design.dll[2011.05.03 15:06:41 | 000,442,368 | ---- | M] () MD5=AE975C122A442146D7D5A6A996C42F91 -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll[2011.10.26 18:50:26 | 000,230,480 | ---- | M] () MD5=715D600994E95E5F32701BFB012FD749 -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlServerCe.Entity\3.5.1.0__89845dcd8080cc91\System.Data.SqlServerCe.Entity.dll[2011.10.26 18:51:29 | 000,271,440 | ---- | M] () MD5=51BE126F0D1CBBE278514F779FCDD29A -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlServerCe\3.5.0.0__89845dcd8080cc91\System.Data.SqlServerCe.dll[2011.10.26 18:51:29 | 000,271,440 | ---- | M] () MD5=156FDE0E85025D180598E8FBD4DB3D23 -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlServerCe\3.5.1.0__89845dcd8080cc91\System.Data.SqlServerCe.dll[2012.05.11 18:13:47 | 000,745,472 | ---- | M] () MD5=6388F9A7AA6E22DDA2E0D84E5BCE537C -- C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll[2012.05.11 18:13:48 | 000,970,752 | ---- | M] () MD5=97DDAFB2A7B33DC3F746EF35C9EDF892 -- C:\WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll[2012.05.11 18:13:34 | 005,062,656 | ---- | M] () MD5=5C368BEBD58562133856B35BDCEFEADA -- C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll[2011.05.03 15:03:38 | 000,286,720 | ---- | M] () MD5=4C6FBCBB7E7D4E3B0CAAA42043B6A01F -- C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\3.5.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll[2012.05.11 18:13:40 | 000,188,416 | ---- | M] () MD5=F0D4CE77F1F9D9A7468335B1CE4C061B -- C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll[2012.05.11 18:13:40 | 000,401,408 | ---- | M] () MD5=F485CF34C45F850B25A7E38B08A7C435 -- C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll[2012.05.11 18:13:36 | 000,081,920 | ---- | M] () MD5=36ABC218228871A981027174216A2DA8 -- C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll[2012.05.11 18:13:46 | 000,630,784 | ---- | M] () MD5=DD110208ACE51F9AAC2FFC949CB6D937 -- C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll[2011.05.03 15:03:04 | 000,126,976 | ---- | M] () MD5=311A345681A73C66D3EE49C5157A473B -- C:\WINDOWS\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll[2011.05.04 15:03:58 | 000,438,272 | ---- | M] () MD5=DB076F159D89B90924C465222BA128FE -- C:\WINDOWS\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll[2011.05.03 15:02:56 | 000,131,072 | ---- | M] () MD5=80E67BFFD101CC6312B489BEE255430D -- C:\WINDOWS\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll[2012.04.01 15:07:36 | 000,253,952 | ---- | M] () MD5=2286B57ECC2D32D24049C51989084268 -- C:\WINDOWS\assembly\GAC_MSIL\System.Management.Automation.resources\1.0.0.0_en_31bf3856ad364e35\System.Management.Automation.resources.dll[2012.04.01 15:07:33 | 002,682,880 | ---- | M] () MD5=4D8AB4FAD244F7985D8C59D456E026D7 -- C:\WINDOWS\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll[2011.05.03 15:03:42 | 000,143,360 | ---- | M] () MD5=217A1E1DED132261C825313A7FB2616C -- C:\WINDOWS\assembly\GAC_MSIL\System.Management.Instrumentation\3.5.0.0__b77a5c561934e089\System.Management.Instrumentation.dll[2012.05.11 18:13:39 | 000,372,736 | ---- | M] () MD5=EBAADBBFB6C455E54EB6A0E47267D33C -- C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll[2012.05.11 18:13:38 | 000,258,048 | ---- | M] () MD5=7F9F1F17D368EE1EEA7E246FD934B9EC -- C:\WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll[2011.05.03 15:03:44 | 000,233,472 | ---- | M] () MD5=2E66DE31546A6AB3A8160CE337E1C6BC -- C:\WINDOWS\assembly\GAC_MSIL\System.Net\3.5.0.0__b03f5f7f11d50a3a\System.Net.dll[2012.05.11 18:13:38 | 000,303,104 | ---- | M] () MD5=2849F13593D2712CCB97FFBDD3C1232E -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll[2012.05.11 18:13:38 | 000,131,072 | ---- | M] () MD5=C415D86079D431E7E1E32D0835A3FE81 -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll[2011.05.04 15:03:58 | 000,970,752 | ---- | M] () MD5=2CF02DF42A90A054D546BF3A85409DC4 -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll[2012.05.11 18:13:47 | 000,258,048 | ---- | M] () MD5=0DFCD96DED6DB52064203C07B927357E -- C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll[2011.05.03 15:02:58 | 000,073,728 | ---- | M] () MD5=A80F41C8B2168E8B3ADD0AA4FCBDDC93 -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll[2011.05.04 15:03:59 | 000,032,768 | ---- | M] () MD5=764E1A3E53C5885976F2EE6E206208EF -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll[2011.05.03 15:03:37 | 000,569,344 | ---- | M] () MD5=1565B7FAFDFA6EEE16101388E57E749F -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.Web\3.5.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll[2011.05.04 15:03:58 | 005,967,872 | ---- | M] () MD5=4120A37565491CA998E226BCBE8EF6E8 -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll[2012.05.11 18:13:48 | 000,114,688 | ---- | M] () MD5=50D2943D426BA91771AD87FDEC802AC3 -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll[2011.05.03 15:03:02 | 000,688,128 | ---- | M] () MD5=31588B867657A7DF046AC1908550D73C -- C:\WINDOWS\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll[2011.05.03 15:03:45 | 000,077,824 | ---- | M] () MD5=2C3559C513F7CD6F95DC382F31A6A22D -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Abstractions\3.5.0.0__31bf3856ad364e35\System.Web.Abstractions.dll[2011.05.03 15:03:45 | 000,032,768 | ---- | M] () MD5=9E0D101B086297D5E166E03A8ACBF260 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.DynamicData.Design\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.Design.dll[2011.05.03 15:06:42 | 000,229,376 | ---- | M] () MD5=CC8D03C33986926A68696DAAAB5FF2F8 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.DynamicData\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.dll[2011.05.03 15:03:42 | 000,131,072 | ---- | M] () MD5=A6A5297AAD0A9BA8829D20B1CBD68D32 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Entity.Design\3.5.0.0__b77a5c561934e089\System.Web.Entity.Design.dll[2011.05.03 15:06:42 | 000,139,264 | ---- | M] () MD5=E42797003722BD930D83AB26998394D8 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Entity\3.5.0.0__b77a5c561934e089\System.Web.Entity.dll[2011.05.03 15:03:46 | 000,335,872 | ---- | M] () MD5=7E83B8040233DDCDE03CF7F0A5F2837B -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Extensions.Design\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.Design.dll[2012.01.12 04:06:52 | 001,277,952 | ---- | M] () MD5=821B0AAB24CB11417381F8AE881309A2 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll[2012.05.11 18:13:33 | 000,835,584 | ---- | M] () MD5=C22D59F4EAC00510D1A86061A428C633 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll[2012.05.11 18:13:34 | 000,077,824 | ---- | M] () MD5=F27A80887F125661CAC1A6039107428F -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll[2011.05.03 15:03:46 | 000,061,440 | ---- | M] () MD5=5B7868DF14D71D328EE8C1213F852393 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Routing\3.5.0.0__31bf3856ad364e35\System.Web.Routing.dll[2012.05.11 18:13:33 | 000,839,680 | ---- | M] () MD5=A89DFA6DB0C3D00559F770A214962A60 -- C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll[2012.05.11 18:13:35 | 005,025,792 | ---- | M] () MD5=7A3C1F1942074D251CCFA44D4815AD33 -- C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll[2011.05.03 15:03:43 | 000,012,288 | ---- | M] () MD5=044C3400A836E5FB60D4A49EAEC24544 -- C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Presentation\3.5.0.0__b77a5c561934e089\System.Windows.Presentation.dll[2011.05.03 15:03:01 | 001,138,688 | ---- | M] () MD5=A96933F3898290AA509080A90E0C7C5F -- C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll[2011.05.03 15:03:01 | 001,630,208 | ---- | M] () MD5=C4503F6EADC2638D6898514290A7A60B -- C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll[2011.05.03 15:03:01 | 000,540,672 | ---- | M] () MD5=6623152B2FB7DC650C6A8FE01AF71F44 -- C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll[2011.05.03 15:03:37 | 000,507,904 | ---- | M] () MD5=E249D1B3114088C0D390A60643BF2BBC -- C:\WINDOWS\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\System.WorkflowServices.dll[2011.05.03 15:03:43 | 000,139,264 | ---- | M] () MD5=64925CC79EA9E8245A4F18703CCABEC4 -- C:\WINDOWS\assembly\GAC_MSIL\System.Xml.Linq\3.5.0.0__b77a5c561934e089\System.Xml.Linq.dll[2012.05.11 18:13:46 | 002,048,000 | ---- | M] () MD5=EB97291E3C9E0035B47B45DBB1AF710D -- C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll[2012.05.11 18:13:45 | 003,186,688 | ---- | M] () MD5=6D37DFFE4B89AB1E17367FEEF2327B34 -- C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll[2011.05.03 15:03:02 | 000,167,936 | ---- | M] () MD5=F303A07A6EF37B8B6DD928D97A016B75 -- C:\WINDOWS\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\UIAutomationClient.dll[2011.05.03 15:03:03 | 000,385,024 | ---- | M] () MD5=09658EF5F16F2ABD74FE577D50C0D155 -- C:\WINDOWS\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll[2011.05.03 15:03:00 | 000,040,960 | ---- | M] () MD5=A93561FB224FA8539357C74065403630 -- C:\WINDOWS\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll[2011.05.03 15:03:00 | 000,098,304 | ---- | M] () MD5=5BE33FC308914C1AE6577A908D97A4FF -- C:\WINDOWS\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll[2012.05.11 18:07:46 | 001,249,280 | ---- | M] () MD5=D91A6B3FDF14C0319333FC583D969126 -- C:\WINDOWS\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll[2011.05.03 15:03:03 | 000,094,208 | ---- | M] () MD5=E205A79EA6C06F91EA08BBE59FE83503 -- C:\WINDOWS\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll < type c:\diskreport.txt /c >Microsoft DiskPart version 5.1.3565Copyright © 1999-2003 Microsoft Corporation.On computer: VASKO Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- Volume 0 E DVD-ROM 0 B Volume 1 F IV2010 CDFS DVD-ROM 504 MB Volume 2 C NTFS Partition 20 GB Healthy System Volume 3 D NTFS Partition 912 GB Healthy < MD5 for: AFD.SYS >[2011.08.17 16:49:54 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=1E44BC1E83D8FD2305F8D452DB109CF9 -- C:\WINDOWS\system32\dllcache\afd.sys[2011.08.17 16:49:54 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=1E44BC1E83D8FD2305F8D452DB109CF9 -- C:\WINDOWS\system32\drivers\afd.sys[2008.04.14 00:49:24 | 000,138,112 | ---- | M] (Microsoft Corporation) MD5=322D0E36693D6E24A2398BEE62A268CD -- C:\WINDOWS\$NtUninstallKB951748$\afd.sys[2011.02.16 16:22:48 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=355556D9E580915118CD7EF736653A89 -- C:\WINDOWS\$NtUninstallKB2592799$\afd.sys[2008.10.16 18:07:58 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=38D7B715504DA4741DF35E3594FE2099 -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\afd.sys[2008.08.14 13:34:26 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=4D43E74F2A1239D53929B82600F1971C -- C:\WINDOWS\$hf_mig$\KB956803\SP3QFE\afd.sys[2008.08.14 13:34:26 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=4D43E74F2A1239D53929B82600F1971C -- C:\WINDOWS\SoftwareDistribution\Download\a94a6432dbac6901fc5bf15157f718f8\SP3QFE\afd.sys[2008.08.14 12:51:43 | 000,138,368 | ---- | M] (Microsoft Corporation) MD5=55E6E1C51B6D30E54335750955453702 -- C:\WINDOWS\SoftwareDistribution\Download\a94a6432dbac6901fc5bf15157f718f8\SP2GDR\afd.sys[2008.08.14 12:48:52 | 000,138,368 | ---- | M] (Microsoft Corporation) MD5=6A0397376853E604DE8E1E7A87FC08AC -- C:\WINDOWS\SoftwareDistribution\Download\a94a6432dbac6901fc5bf15157f718f8\SP2QFE\afd.sys[2008.10.16 17:43:01 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7618D5218F2A614672EC61A80D854A37 -- C:\WINDOWS\$NtUninstallKB2503665$\afd.sys[2008.08.14 13:04:36 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7E775010EF291DA96AD17CA4B17137D7 -- C:\WINDOWS\$NtUninstallKB2509553$\afd.sys[2008.08.14 13:04:36 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7E775010EF291DA96AD17CA4B17137D7 -- C:\WINDOWS\SoftwareDistribution\Download\a94a6432dbac6901fc5bf15157f718f8\SP3GDR\afd.sys[2011.02.16 16:25:05 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=8D499B1276012EB907E7A9E0F4D8FDA4 -- C:\WINDOWS\$hf_mig$\KB2503665\SP3QFE\afd.sys[2008.06.20 14:48:03 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=D6EE6014241D034E63C49A50CB2B442A -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\afd.sys[2008.06.20 14:40:08 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=E3049B90FE06F3F740B7CFDA44995E2C -- C:\WINDOWS\$NtUninstallKB956803$\afd.sys[2011.08.17 16:41:46 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=F6B7B1ECD7B41736BDB6FF4B092BCB79 -- C:\WINDOWS\$hf_mig$\KB2592799\SP3QFE\afd.sys < MD5 for: ATAPI.SYS >[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys < MD5 for: DISK.SYS >[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys[2008.04.14 00:10:48 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys < MD5 for: EXPLORER.EXE >[2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe[2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe < MD5 for: I8042PRT.SYS >[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:i8042prt.sys[2008.04.14 00:48:02 | 000,052,480 | ---- | M] (Microsoft Corporation) MD5=4A0B06AA8943C1E332520F7440C0AA30 -- C:\WINDOWS\system32\drivers\i8042prt.sys < MD5 for: IPSEC.SYS >[2008.04.14 00:49:44 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=23C74D75E36E7158768DD63D92789A91 -- C:\WINDOWS\system32\dllcache\ipsec.sys[2008.04.14 00:49:44 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=23C74D75E36E7158768DD63D92789A91 -- C:\WINDOWS\system32\drivers\ipsec.sys < MD5 for: LSASS.EXE >[2008.04.14 05:42:26 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\system32\dllcache\lsass.exe[2008.04.14 05:42:26 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\system32\lsass.exe < MD5 for: NETBT.SYS >[2008.04.14 00:51:02 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=74B2B2F5BEA5E9A3DC021D685551BD3D -- C:\WINDOWS\system32\dllcache\netbt.sys[2008.04.14 00:51:02 | 000,162,816 | ---- | M] (Microsoft Corporation) MD5=74B2B2F5BEA5E9A3DC021D685551BD3D -- C:\WINDOWS\system32\drivers\netbt.sys < MD5 for: REDBOOK.SYS >[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:redbook.sys[2008.04.14 03:10:28 | 000,057,600 | ---- | M] (Microsoft Corporation) MD5=F828DD7E1419B6653894A8F97A0094C5 -- C:\WINDOWS\system32\drivers\redbook.sys < MD5 for: SERIAL.SYS >[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:serial.sys[2008.04.14 00:45:46 | 000,064,512 | ---- | M] (Microsoft Corporation) MD5=CCA207A8896D4C6A0C9CE29A4AE411A7 -- C:\WINDOWS\system32\drivers\serial.sys < MD5 for: SERVICES.EXE >[2009.02.06 14:06:24 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe[2008.04.14 05:42:36 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe[2009.02.06 14:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\dllcache\services.exe[2009.02.06 14:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\services.exe < MD5 for: SMSS.EXE >[2008.04.14 05:42:38 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=5F816C1F539266D2D4C78694239DA0B5 -- C:\WINDOWS\system32\dllcache\smss.exe[2008.04.14 05:42:38 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=5F816C1F539266D2D4C78694239DA0B5 -- C:\WINDOWS\system32\smss.exe < MD5 for: SVCHOST.EXE >[2008.04.14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\dllcache\svchost.exe[2008.04.14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe < MD5 for: TCPIP.SYS >[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$ cpip.sys[2008.06.20 14:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE cpip.sys[2008.06.20 14:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE cpip.sys[2011.05.13 12:15:05 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=D24EA301E2B36C4E975FD216CA85D8E7 -- C:\WINDOWS\system32\dllcache\TCPIP.SYS[2011.05.13 12:15:05 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=D24EA301E2B36C4E975FD216CA85D8E7 -- C:\WINDOWS\system32\drivers\TCPIP.SYS < MD5 for: USERINIT.EXE >[2008.04.14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\dllcache\userinit.exe[2008.04.14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe < MD5 for: VOLSNAP.SYS >[2008.04.14 00:11:02 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\system32\dllcache\volsnap.sys[2008.04.14 00:11:02 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\system32\drivers\volsnap.sys < MD5 for: WINLOGON.EXE >[2008.04.14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe[2008.04.14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe ========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction[C:\WINDOWS\assembly\GAC_32\Update\1.1.3.0__318d21d4b0463a3b] -> C:\WINDOWS\WinSxS\x86_Update_318d21d4b0463a3b_1.1.3.0_x-ww_46a5f7d3 -> Junction[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction[C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492 -> Junction[C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35] -> C:\WINDOWS\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5 -> Junction < End of report > Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Май 13, 2012 Report Share Публикувано Май 13, 2012 Ако имаш антивирусна програма инсталирана, я спри, както и всякакви други излишни програми. Изтегли ComboFix (ако случайно вече имаш някаква версия, я замени) и го запази на работния плот.Стартирай го, кликни I Agree, изчакай да се разархивира и сканира докрай. Не кликай по прозореца на инструмента. Ако бъдеш попитан(а) дали да бъде инсталирана Recovery Console, кликни Yes и потвърди след това с OK и отново Yes (два пъти). Сканирането ще продължи. Ако има нужда от рестарт, компютърът ще се рестартира автоматично. След рестарта трябва да продължи сканирането. Отново не закачай прозореца, докато той не се самозатвори. След това постави съдържанието на текстовия файл C:\ComboFix.txt тук или го прикачи към коментара си. Ако не можеш да установиш връзка с интернет след използване на ComboFix, рестартирай системата. Цитирай Link to comment Сподели другаде More sharing options...
Viksi95 Публикувано Май 14, 2012 Report Share Публикувано Май 14, 2012 Благодаря ти Вече мога да влизам във facebook. ComboFix 12-05-13.03 - Vasko1 05.2012 г. 0:12.1.4 - x86Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2935.2297 [GMT 3:00]Running from: c:\documents and settings\Vasko1\Desktop\ComboFix.exeAV: ESET NOD32 Antivirus 3.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} * Created a new restore point..((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))..c:\documents and settings\Vasko1\Application Data\.#c:\documents and settings\Vasko1\Application Data\.#\MBX@138C@3837B8.###c:\documents and settings\Vasko1\Application Data\.#\MBX@138C@3837C8.###c:\documents and settings\Vasko1\Application Data\.#\MBX@138C@3837D8.###c:\documents and settings\Vasko1\Application Data\PriceGongc:\documents and settings\Vasko1\Application Data\PriceGong\Data\1.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\a.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\b.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\c.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\d.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\e.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\f.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\g.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\h.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\i.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\J.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\k.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\l.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\m.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\mru.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\n.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\o.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\p.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\q.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\r.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\s.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data .xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\u.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\v.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\w.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\x.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\y.xmlc:\documents and settings\Vasko1\Application Data\PriceGong\Data\z.xmlc:\documents and settings\Vasko1\WINDOWSc:\windows\ktkm2.dllc:\windows\ktkm3.dllc:\windows\ktkm34.dllc:\windows\ktkm36.dllc:\windows\ktkm4.dllc:\windows\ktkm8.dllc:\windows\system32\_000012_.tmp.dll..((((((((((((((((((((((((( Files Created from 2012-04-13 to 2012-05-13 )))))))))))))))))))))))))))))))..2012-05-13 18:55 . 2012-05-13 18:55 -------- d-----w- c:\documents and settings\Vasko1\Application Data\SUPERAntiSpyware.com2012-05-13 18:54 . 2012-05-13 18:54 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com2012-05-13 18:45 . 2012-05-13 18:45 -------- d-----w- c:\documents and settings\Vasko1\Application Data\Malwarebytes2012-05-13 18:45 . 2012-05-13 18:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes2012-05-13 18:45 . 2012-04-04 12:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys2012-05-12 14:21 . 2012-05-13 07:40 -------- d-----w- c:\program files\Mozilla Maintenance Service2012-05-11 19:41 . 2012-05-11 19:41 30208 ----a-r- c:\documents and settings\Vasko1\Application Data\Microsoft\Installer\{40A0B29E-B270-450B-BF4D-34493A934523}\Icon40A0B29E.exe2012-05-11 15:57 . 2012-05-11 15:57 -------- d-----w- c:\documents and settings\Vasko1\Application Data\Avant Downloader2012-04-27 20:02 . 2012-04-27 20:29 -------- d-----w- c:\program files\Opera2012-04-21 19:36 . 2012-04-21 19:36 -------- d-----w- c:\program files\Common Files\Symantec Shared2012-04-21 19:36 . 2012-04-27 12:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton...(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2012-05-12 11:28 . 2012-01-10 21:41 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe2012-05-12 11:28 . 2011-05-20 10:00 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl2012-04-11 13:14 . 2008-04-13 21:54 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe2012-04-11 13:12 . 2008-04-13 22:00 1862272 ----a-w- c:\windows\system32\win32k.sys2012-04-11 12:35 . 2008-04-14 00:01 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe2012-03-07 20:54 . 2012-03-07 20:54 180224 ----a-w- c:\windows\system32\WinVd32.sys2012-03-07 20:54 . 2012-03-07 20:54 7680 ----a-w- c:\windows\system32\WinFLsrv.exe2012-03-06 16:33 . 2012-03-06 16:33 73728 ----a-w- c:\windows\system32\javacpl.cpl2012-03-06 16:33 . 2012-03-06 16:33 472808 ----a-w- c:\windows\system32\deployJava1.dll2012-03-01 11:01 . 2008-04-14 02:42 1469440 ------w- c:\windows\system32\inetcpl.cpl2012-03-01 11:01 . 2008-04-14 02:42 916992 ----a-w- c:\windows\system32\wininet.dll2012-03-01 11:01 . 2008-04-14 02:41 43520 ------w- c:\windows\system32\licmgr10.dll2012-02-29 14:10 . 2008-04-14 02:42 177664 ----a-w- c:\windows\system32\wintrust.dll2012-02-29 14:10 . 2008-04-14 02:41 148480 ----a-w- c:\windows\system32\imagehlp.dll2012-02-29 12:17 . 2008-04-13 21:07 385024 ------w- c:\windows\system32\html.iec2012-02-14 09:09 . 2012-02-14 09:09 1070352 ----a-w- c:\windows\system32\MSCOMCTL.OCX2009-06-19 09:12 . 2009-06-19 09:12 1828176 ----a-w- c:\program files\Common Files\Skype4COM.dll..------- Sigcheck -------Note: Unsigned files aren't necessarily malware..[-] 2011-05-13 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\TCPIP.SYS[-] 2011-05-13 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\TCPIP.SYS[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE cpip.sys[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE cpip.sys[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$ cpip.sys.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4.[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-04-09 1519272]"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2011-03-11 1373512]"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTo0.dll" [2011-05-09 176936]"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\prxtbBS_P.dll" [2011-05-09 176936].[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}].[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}][HKEY_CLASSES_ROOT\WinampTb.AOLTBSearch.1][HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}][HKEY_CLASSES_ROOT\WinampTb.AOLTBSearch].[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}].[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}].[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]2011-05-09 09:49 176936 ----a-w- c:\program files\uTorrentBar\prxtbuTo0.dll.[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]2012-04-09 14:43 1519272 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll.[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]2011-05-09 08:49 176936 ----a-w- c:\program files\BS_Player\prxtbBS_P.dll.[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTo0.dll" [2011-05-09 176936]"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-04-09 1519272]"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\prxtbBS_P.dll" [2011-05-09 176936].[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}].[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}][HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1][HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}][HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd].[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}].[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\prxtbuTo0.dll" [2011-05-09 176936]"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-04-09 1519272]"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\prxtbBS_P.dll" [2011-05-09 176936].[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}].[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}][HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1][HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}][HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd].[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}].[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-02-28 740216]"avichannel"="c:\program files\Evaer\videochannel.exe" [2011-09-21 1686016]"Facebook Update"="c:\documents and settings\Vasko1\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" [2011-10-19 137536]"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2011-07-21 718720]"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-01-19 3477312]"GameXN (update)"="c:\documents and settings\All Users\Application Data\GameXN\GameXNGO.exe" [2012-03-31 347008]"GameXN (news)"="c:\documents and settings\All Users\Application Data\GameXN\GameXNGO.exe" [2012-03-31 347008]"GameXN"="c:\documents and settings\All Users\Application Data\GameXN\GameXNGO.exe" [2012-03-31 347008]"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-02-29 17148552]"SUPERAntiSpyware"="d:\programs\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-05-01 3905920].[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-18 141848]"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-18 174104]"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-18 144920]"RTHDCPL"="RTHDCPL.EXE" [2010-04-30 19523616]"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-03-17 74752]"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-11-10 1980200]"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-11 1280344]"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]"HCEmployee"="c:\program files\Oleansoft\Hc\servemp.exe" [2011-11-05 413184]"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-04-09 1557160]"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-28 1987976]"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696].[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360].c:\documents and settings\Vasko1\Start Menu\Programs\Startup\Изрязване на екран и стартиране на OneNote 2010.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712].c:\documents and settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\gprs.exe [2008-3-19 43608].[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\programs\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024].[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]2011-05-04 17:54 551296 ----a-w- d:\programs\SUPERAntiSpyware\SASWINLO.DLL.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]@="".[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]@="Driver".[HKEY_LOCAL_MACHINE\software\microsoft\security center]"AntiVirusOverride"=dword:00000001.[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\system32\\sessmgr.exe"="c:\\WINDOWS\\system32\\dpvsetup.exe"="c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"="c:\\Program Files\\uTorrent\\uTorrent.exe"="c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"="d:\\Games\\PES\\pes2011.exe"="d:\\Games\\gMOD\\hl2.exe"="d:\\Games\\Mafia\\Steam.exe"="d:\\Games\\TDU\\Test Drive Unlimited GOLD\\TestDriveUnlimited.exe"="d:\\Games\\Fifa\\fifa07.exe"="d:\\Games\\NWO\\New World Order\\NWO\\NWO.exe"="d:\\Games\\Prototype\\prototypef.exe"="d:\\Games\\X-Men\\Binaries\\Wolverine.exe"="d:\\Games\\CoD\\CoD2MP_s.exe"="c:\\WINDOWS\\system32\\PnkBstrA.exe"="c:\\WINDOWS\\system32\\PnkBstrB.exe"="d:\\Games\\Wolfenstein\\MP\\Wolf2MP.exe"="d:\\Games\\Wolfenstein\\MP\\Wolf2MPLite.exe"="c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"="d:\\Games\\Free Running\\FreeRunning.exe"="c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"="c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"="c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"="c:\\Program Files\\Oleansoft\\Hc\\servemp.exe"="c:\\Program Files\\Bonjour\\mDNSResponder.exe"="d:\\Games\\CS\\Counter-Strike 1.6 Sector Edition\\cstrike.exe"="c:\\Betfair JPC\\arch\\win32\\jre\\bin\\java.exe"="d:\\Games\\Stalker\\S.T.A.L.K.E.R\\bin\\XR_3DA.exe"="d:\\Games\\Stalker\\S.T.A.L.K.E.R\\bin\\dedicated\\XR_3DA.exe"="c:\\Program Files\\Winamp\\winamp.exe"="d:\\Games\\CS\\Counter-Strike 1.6 Sector Edition\\hlds.exe"="d:\\Games\\Fifa 12\\FIFA 12\\Game\\fifa.exe"="d:\\Games\\CS\\CS 1.6\\cstrike.exe"="c:\\Documents and Settings\\Vasko1\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"="c:\\Program Files\\Skype\\Phone\\Skype.exe"=.[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management .R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [16.3.2011 г. 23:38 13696]R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [11.2.2012 г. 14:33 242240]R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [10.11.2008 г. 15:34 104456]R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [10.11.2008 г. 15:34 92168]R1 SASDIFSV;SASDIFSV;d:\programs\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 г. 19:27 12880]R1 SASKUTIL;SASKUTIL;d:\programs\SUPERAntiSpyware\SASKUTIL.SYS [13.7.2011 г. 00:55 67664]R2 !SASCORE;SAS Core Service;d:\programs\SUPERAntiSpyware\SASCore.exe [12.8.2011 г. 02:38 116608]R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [10.11.2008 г. 15:34 711240]R2 ezGOSvc;Easybits GO Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [14.4.2008 г. 05:42 14336]R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [28.2.2012 г. 18:38 1373576]R2 NAUpdate;@c:\program files\Nero\Update\NASvc.exe,-200;c:\program files\Nero\Update\NASvc.exe [23.9.2011 г. 19:37 641832]R2 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [19.3.2008 г. 17:52 51816]R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [07.3.2012 г. 23:54 10752]R3 IntcDAud;Intel® Display Audio;c:\windows\system32\drivers\IntcDAud.sys [16.3.2011 г. 23:40 235520]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 г. 13:16 130384]S2 gupdate;Услуга Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [21.4.2011 г. 21:43 136176]S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [20.3.2011 г. 16:07 312152]S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [29.2.2012 г. 08:50 158856]S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [11.1.2012 г. 00:41 257696]S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [16.3.2011 г. 23:42 1691480]S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\docume~1\Vasko1\LOCALS~1\Temp\RarSFX1\kerneld.wnt --> c:\docume~1\Vasko1\LOCALS~1\Temp\RarSFX1\kerneld.wnt [?]S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [21.4.2011 г. 21:43 136176]S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [12.6.2011 г. 11:15 31125880]S3 MozillaMaintenance;Mozilla Maintenance Service;"c:\program files\Mozilla Maintenance Service\maintenanceservice.exe" --> c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [?]S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [17.11.2011 г. 12:24 137472]S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [17.11.2011 г. 12:24 8576]S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09.1.2010 г. 21:37 4640000]S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14.4.2008 г. 05:42 14336]S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 г. 13:16 753504].[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]WINRM REG_MULTI_SZ WINRM.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcsezGOSvc.Contents of the 'Scheduled Tasks' folder.2012-05-13 c:\windows\Tasks\Adobe Flash Player Updater.job- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-01-10 11:28].2012-05-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003Core.job- c:\documents and settings\Vasko1\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-19 11:41].2012-05-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003UA.job- c:\documents and settings\Vasko1\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-19 11:41].2012-05-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-21 18:43].2012-05-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-21 18:43].2012-05-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003Core.job- c:\documents and settings\Vasko1\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-02 15:55].2012-05-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1303643608-1417001333-1003UA.job- c:\documents and settings\Vasko1\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-02 15:55].2012-05-13 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job- c:\program files\Ask.com\UpdateTask.exe [2012-04-09 14:43].2012-05-13 c:\windows\Tasks\WGASetup.job- c:\windows\system32\KB905474\wgasetup.exe [2011-03-20 20:18]..------- Supplementary Scan -------.uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT1750559uInternet Connection Wizard,ShellNext = iexploreuInternet Settings,ProxyServer = http=;ftp=;https=;IE: &Експортиране към Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000IE: &Изпрати към OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000TCP: DhcpNameServer = 192.168.1.1FF - ProfilePath - c:\documents and settings\Vasko1\Application Data\Mozilla\Firefox\Profiles\0px2n2cr.default\FF - prefs.js: network.proxy.gopher - FF - prefs.js: network.proxy.gopher_port - 0FF - prefs.js: network.proxy.type - 0.- - - - ORPHANS REMOVED - - - -.AddRemove-PokerStars.net - c:\program files\PokerStars.NET\PokerStarsUninstall.exeAddRemove-FolderLock6 - c:\program files\Folder Lock\Uninstall.exe...**************************************************************************.catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2012-05-14 00:14Windows 5.1.2600 Service Pack 3 NTFS.scanning hidden processes ... .scanning hidden autostart entries ... .scanning hidden files ... ..c:\windows\system32\sys_drv.dat 9036 bytesc:\windows\system32\sys_drv_2.dat 7028 bytesc:\windows\system32\WinFLdrv.sys 10752 bytes executablec:\documents and settings\Vasko1\Application Data\systemfl.$dk 990 bytes.scan completed successfullyhidden files: 4.**************************************************************************.[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]"ImagePath"="\??\c:\docume~1\Vasko1\LOCALS~1\Temp\RarSFX1\kerneld.wnt".--------------------- LOCKED REGISTRY KEYS ---------------------.[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\B20@O=5 *=0 *C*C*l*e*a*n*e*r*& \command]@="c:\\Program Files\\CCleaner\\ccleaner.exe".--------------------- DLLs Loaded Under Running Processes ---------------------.- - - - - - - > 'winlogon.exe'(892)d:\programs\SUPERAntiSpyware\SASWINLO.DLLc:\windows\system32\WININET.dll.Completion time: 2012-05-14 00:15:52ComboFix-quarantined-files.txt 2012-05-13 21:15.Pre-Run: 2 498 985 984 bytes freePost-Run: 2 464 538 624 bytes free.WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe[boot loader]timeout=2default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS[operating systems]c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdconsUnsupportedDebug="do not select this" /debugmulti(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect.- - End Of File - - 98D11FA03A267582ED981C6812743828 Цитирай Link to comment Сподели другаде More sharing options...
Night_Raven Публикувано Май 14, 2012 Report Share Публикувано Май 14, 2012 Дотук добре. Да видим дали ще се намери нещо след това... Сканирай с Malwarebytes Anti-Malware. Ако тепърва инсталираш програмата, в края инсталацията ще има отметка за автоматична актуализация, не я премахвай. В противен случай обнови дефинициите й ръчно. Ако вече имаш програмата, провери дали имаш последната версия и ако нямаш, премахни твоята и инсталирай най-новата, като в края на инсталацията остави отметката за актуализация на дефинициите. Инструкции за сканиране:- стартирай програмата;- избери Perform quick scan (Бързо сканиране) и кликни бутон Scan (Сканиране);- след като приключи сканирането, ако не са открити заплахи, ще се отвори автоматично текстов файл (който можеш да затвориш) и програмата ще те уведоми, че не е открила нищо, след което можеш да кликнеш бутон OK и да я затвориш;- ако са открити заплахи, кликни бутон OK и после Show Results (Покажи резултатите);- кликни бутон Remove Selected (Премахни избраните);Ако е нужен рестарт, се съгласи и рестартирай веднага. След рестарта стартирай отново програмата, иди на подпорозиорец Logs (Дневници), маркирай последния дневник, кликни бутон Open (Отвори) и му копирай съдържанието тук. Ако не е бил нужен рестарт, трябва да се появи текстов файл - копирай му съдържанието тук. Цитирай Link to comment Сподели другаде More sharing options...
Viksi95 Публикувано Май 14, 2012 Report Share Публикувано Май 14, 2012 Malwarebytes Anti-Malware 1.61.0.1400www.malwarebytes.org Версия на базата от данни: v2012.05.13.04 Windows XP Service Pack 3 x86 NTFSInternet Explorer 8.0.6001.18702Vasko1 :: VASKO [администратор] 14.5.2012 г. 20:59:46mbam-log-2012-05-14 (20-59-46).txt Тип сканиране: Бързо сканиранеВключени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUMИзключени опции за сканиране: P2PСканирани обекти: 208445Изминало време: 1 минута(и), 41 секунда(и) Открити процеси в паметта: 0(Не бяха открити зловредни обекти) Открити модули в паметта: 0(Не бяха открити зловредни обекти) Открити ключове в системния регистър: 0(Не бяха открити зловредни обекти) Открити стойности в системния регистър: 0(Не бяха открити зловредни обекти) Открити информационни обекти в системния регистър: 0(Не бяха открити зловредни обекти) Открити папки: 0(Не бяха открити зловредни обекти) Открити файлове: 0(Не бяха открити зловредни обекти) (край) Цитирай Link to comment Сподели другаде More sharing options...
Препоръчан пост
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.