OTL
OTL logfile created on: 8.11.2014 17:20:56 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\admin\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
6,00 Gb Total Physical Memory | 3,66 Gb Available Physical Memory | 61,06% Memory free
12,00 Gb Paging File | 9,14 Gb Available in Paging File | 76,15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372,51 Gb Total Space | 78,74 Gb Free Space | 21,14% Space Free | Partition Type: NTFS
Computer Name: ADMIN-PC | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014.11.08 17:18:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\admin\Downloads\OTL.exe
PRC - [2014.11.08 16:23:32 | 001,868,800 | ---- | M] () -- C:\ProgramData\Downloader\downloader.exe
PRC - [2014.10.21 20:22:40 | 001,529,536 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
PRC - [2014.10.21 20:22:40 | 000,833,728 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
PRC - [2014.10.21 20:22:38 | 001,938,624 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\Steam.exe
PRC - [2014.09.21 23:14:09 | 004,085,896 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014.09.12 19:14:55 | 004,799,760 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
PRC - [2014.09.12 10:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014.09.11 08:57:26 | 002,480,312 | ---- | M] (Sysinternals -
www.sysinternals.com) -- C:\Users\admin\Desktop\procexp.exe
PRC - [2014.08.14 19:30:18 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014.05.29 13:16:09 | 000,189,248 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrB.exe
PRC - [2014.05.29 13:16:01 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2014.05.25 12:45:46 | 000,567,880 | ---- | M] () -- C:\Program Files (x86)\puush\puush.exe
PRC - [2014.01.23 06:57:02 | 000,866,584 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2013.07.18 16:39:40 | 000,762,192 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2012.07.09 00:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
========== Modules (No Company Name) ==========
MOD - [2014.10.21 20:22:58 | 002,226,880 | ---- | M] () -- C:\Program Files (x86)\Steam\video.dll
MOD - [2014.10.21 20:22:40 | 000,682,176 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.dll
MOD - [2014.10.02 00:16:02 | 000,774,656 | ---- | M] () -- C:\Program Files (x86)\Steam\SDL2.dll
MOD - [2014.09.05 00:29:26 | 034,589,376 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll
MOD - [2014.09.05 00:29:26 | 000,837,824 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\ffmpegsumo.dll
MOD - [2014.08.21 19:15:22 | 001,171,456 | ---- | M] () -- C:\Program Files (x86)\Steam\libavcodec-56.dll
MOD - [2014.08.21 19:15:22 | 000,485,888 | ---- | M] () -- C:\Program Files (x86)\Steam\libswscale-3.dll
MOD - [2014.08.21 19:15:22 | 000,442,368 | ---- | M] () -- C:\Program Files (x86)\Steam\libavutil-54.dll
MOD - [2014.08.21 19:15:22 | 000,403,968 | ---- | M] () -- C:\Program Files (x86)\Steam\libavformat-56.dll
MOD - [2014.08.21 19:15:22 | 000,332,800 | ---- | M] () -- C:\Program Files (x86)\Steam\libavresample-2.dll
MOD - [2014.08.14 19:30:20 | 019,329,904 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014.08.14 19:30:18 | 000,301,152 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswProperty.dll
MOD - [2014.06.01 10:08:56 | 000,035,328 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
MOD - [2014.05.25 12:45:46 | 000,567,880 | ---- | M] () -- C:\Program Files (x86)\puush\puush.exe
MOD - [2014.05.24 17:41:24 | 000,892,416 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\libstdc++-6.dll
MOD - [2014.05.24 17:41:24 | 000,091,648 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\libgcc_s_sjlj-1.dll
MOD - [2014.02.21 06:31:03 | 013,632,904 | ---- | M] () -- C:\Users\admin\AppData\Local\Google\Chrome\User Data\PepperFlash\12.0.0.70\pepflashplayer.dll
MOD - [2014.01.23 06:57:00 | 000,399,640 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\ppgooglenaclpluginchrome.dll
MOD - [2014.01.23 06:56:56 | 004,055,320 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\pdf.dll
MOD - [2014.01.23 06:56:02 | 000,715,544 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\libglesv2.dll
MOD - [2014.01.23 06:56:01 | 000,100,120 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\libegl.dll
MOD - [2014.01.23 06:55:58 | 001,634,584 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.102\ffmpegsumo.dll
MOD - [2009.07.14 05:55:57 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\4bdeb88758dccd625f4703ed77aaf348\System.Runtime.Remoting.ni.dll
MOD - [2009.07.14 05:55:32 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll
MOD - [2009.07.14 05:55:26 | 001,586,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll
MOD - [2009.07.14 05:55:09 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll
MOD - [2009.07.14 05:55:06 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll
MOD - [2009.07.14 05:55:05 | 007,949,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll
MOD - [2009.07.14 05:55:00 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll
========== Services (SafeList) ==========
SRV:
64bit: - [2014.08.14 19:30:18 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:
64bit: - [2013.12.17 02:17:18 | 000,627,992 | ---- | M] (Wacom Technology, Corp.) [Auto | Stopped] -- C:\Program Files\Tablet\Pen\WTabletServiceCon.exe -- (WTabletServiceCon)
SRV:
64bit: - [2013.12.06 21:52:10 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:
64bit: - [2013.12.06 16:06:06 | 000,344,064 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:
64bit: - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014.11.07 21:46:40 | 000,114,288 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014.10.21 20:22:40 | 000,833,728 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014.09.16 15:03:34 | 002,078,984 | ---- | M] (BinarySense, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\BinarySense\hldasvc.exe -- (HDDlife HDD Access service)
SRV - [2014.09.12 19:14:55 | 004,799,760 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
SRV - [2014.09.12 10:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014.05.29 13:16:09 | 000,189,248 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrB.exe -- (PnkBstrB)
SRV - [2014.05.29 13:16:01 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2013.07.18 16:39:40 | 000,762,192 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2012.10.24 09:16:51 | 004,702,568 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2012.07.09 00:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.07.14 02:16:19 | 000,348,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2009.07.08 17:23:25 | 002,314,752 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\postreusif.exe -- (Windows Update)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2014.09.21 23:14:03 | 000,427,360 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsp.sys -- (aswSP)
DRV:
64bit: - [2014.08.14 19:30:22 | 001,041,168 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:
64bit: - [2014.08.14 19:30:22 | 000,224,896 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:
64bit: - [2014.08.14 19:30:22 | 000,092,008 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:
64bit: - [2014.08.14 19:30:21 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:
64bit: - [2014.08.14 19:30:21 | 000,079,184 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:
64bit: - [2014.08.14 19:30:21 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:
64bit: - [2014.08.14 19:30:21 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:
64bit: - [2014.01.03 23:54:28 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\taphss6.sys -- (taphss6)
DRV:
64bit: - [2013.12.06 22:52:14 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:
64bit: - [2013.12.06 21:21:44 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:
64bit: - [2013.11.12 01:16:03 | 000,090,424 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wachidrouter.sys -- (WacHidRouter)
DRV:
64bit: - [2013.11.12 01:16:03 | 000,015,160 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wacomrouterfilter.sys -- (wacomrouterfilter)
DRV:
64bit: - [2013.11.12 01:16:02 | 000,014,136 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidkmdf.sys -- (hidkmdf)
DRV:
64bit: - [2013.09.24 15:53:50 | 000,094,208 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:
64bit: - [2013.09.19 23:05:02 | 000,059,648 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.2.0)
DRV:
64bit: - [2012.07.31 09:45:10 | 000,038,992 | ---- | M] (Screaming Bee LLC) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ScreamingBAudio64.sys -- (ScreamBAudioSvc)
DRV:
64bit: - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009.06.10 21:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:
64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
www.google.com
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:
64bit: - HKLM\..\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B}: "URL" =
http://speedial.com/results.php?f=4&q={ ... 284091&ir=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-992597708-1987578634-1854157398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
www.google.com
IE - HKU\S-1-5-21-992597708-1987578634-1854157398-1000\..\URLSearchHook: {06197747-A47F-41FB-83D1-A00E9E00E276} - C:\Program Files (x86)\FLV Toolbar\IE\9.0\flvToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-992597708-1987578634-1854157398-1000\..\SearchScopes,DefaultScope = {B5A9A7D4-ADA4-4E46-929D-20F5840681E9}
IE - HKU\S-1-5-21-992597708-1987578634-1854157398-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-992597708-1987578634-1854157398-1000\..\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B}: "URL" =
http://speedial.com/results.php?f=4&q={ ... 284091&ir=
IE - HKU\S-1-5-21-992597708-1987578634-1854157398-1000\..\SearchScopes\{B5A9A7D4-ADA4-4E46-929D-20F5840681E9}: "URL" =
http://search.yahoo.com/search?fr=chr-g ... earchTerms}
IE - HKU\S-1-5-21-992597708-1987578634-1854157398-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-992597708-1987578634-1854157398-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;localhost;10.*;192.168.*;127.0.0.1:895;127.0.0.1:896;<local>
IE - HKU\S-1-5-21-992597708-1987578634-1854157398-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8555;https=127.0.0.1:8555
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7B81BF1D23-5F17-408D-AC6B-BD6DF7CAF670%7D:8.8.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.0.3
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.3: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.4.0: C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.449: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.3: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@screenleap.com/ScreenleapPlugin,version=1.1: C:\Users\admin\AppData\Local\Screenleap\npscreenleap1.1.dll (ScreenLeap, Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\admin\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\admin\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\admin\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\admin\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\admin\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\admin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014.09.21 23:12:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 33.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 33.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2014.07.21 18:06:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\Extensions
[2014.11.07 21:39:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\Firefox\Profiles\3dbn8y8u.default\extensions
[2014.11.07 21:39:53 | 000,000,000 | ---D | M] (iMacros for Firefox) -- C:\Users\admin\AppData\Roaming\mozilla\Firefox\Profiles\3dbn8y8u.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2014.11.07 21:46:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014.11.07 21:46:41 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: file:///C:/Users/admin/Desktop/IMAGES
CHR - Extension: iMacros for Chrome = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp\8.0.7_0\
CHR - Extension: Search by Image (by Google) = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm\1.5.1_0\
CHR - Extension: AdBlock = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.13_0\
CHR - Extension: Scroll To Top Button = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\chiikmhgllekggjhdfjhajkfdkcngplp\6.3.1_0\
CHR - Extension: Facebook Invite All = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmhkeajgflmokoaaoadgkhhmibjbpj\1.3.6_0\
CHR - Extension: UTADRemmovalApp = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkpdkpbibaghgfbibljdibbibehdlnh\2.0_0\
CHR - Extension: Pen\u011B\u017Eenka Google = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:
64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:
64bit: - HKLM\..\Toolbar: (no name) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-992597708-1987578634-1854157398-1000..\Run: [Clownfish] C:\Program Files (x86)\Clownfish\Clownfish.exe (Bogdan Sharkov)
O4 - HKU\S-1-5-21-992597708-1987578634-1854157398-1000..\Run: [GSplay.exe] C:\Users\admin\Desktop\GSplay.exe File not found
O4 - HKU\S-1-5-21-992597708-1987578634-1854157398-1000..\Run: [puush] C:\Program Files (x86)\puush\puush.exe ()
O4 - HKU\S-1-5-21-992597708-1987578634-1854157398-1000..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HDDlife.lnk = C:\Program Files (x86)\BinarySense\HDDlife 4\HDDlifePro.exe (BinarySense, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3619BC61-FC79-4E87-9672-61A92CE173F3}: DhcpNameServer = 192.168.1.1
O18:
64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:
64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:
64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs:
64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:
64bit: aux - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: aux2 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: aux3 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: aux4 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: aux5 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: aux6 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: aux7 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: aux8 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: aux9 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi2 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi3 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi4 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi5 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi6 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi7 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi8 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi9 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midimapper - midimap.dll (Microsoft Corporation)
Drivers32:
64bit: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: mixer2 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: mixer3 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: mixer4 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: mixer5 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: mixer6 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: mixer7 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: mixer9 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: msacm.bdmpeg - bdmpega64.acm ()
Drivers32:
64bit: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:
64bit: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32:
64bit: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32:
64bit: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32:
64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:
64bit: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.iyuv - iyuv_32.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.mjpg - bdmjpeg64.dll ()
Drivers32:
64bit: vidc.mpeg - bdmpegv64.dll ()
Drivers32:
64bit: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.uyvy - msyuv.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.yuy2 - msyuv.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.yvu9 - tsbyuv.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.yvyu - msyuv.dll (Microsoft Corporation)
Drivers32:
64bit: wave - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wave2 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wave3 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wave4 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wave5 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wave6 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wave7 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wave9 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wavemapper - msacm32.drv (Microsoft Corporation)
Drivers32: aux - wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux2 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux3 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux4 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux5 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux6 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux7 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux8 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux9 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi - wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi3 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi4 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi5 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi6 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi7 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi8 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi9 - wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - midimap.dll (Microsoft Corporation)
Drivers32: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer3 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer4 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer5 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer6 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer7 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer9 - wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.ac3acm - ac3acm.acm (fccHandler)
Drivers32: msacm.bdmpeg - bdmpega.acm ()
Drivers32: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - lameACM.acm (
http://www.mp3dev.org/)
Drivers32: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32: vidc.cvid - iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - ff_vfw.dll ()
Drivers32: VIDC.FPS1 - frapsvid.dll (Beepa P/L)
Drivers32: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.iyuv - iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mjpg - bdmjpeg.dll ()
Drivers32: vidc.mpeg - bdmpegv.dll ()
Drivers32: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.XVID - xvidvfw.dll ()
Drivers32: vidc.yuy2 - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YV12 - yv12vfw.dll (
www.helixcommunity.org)
Drivers32: vidc.yvu9 - tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - msyuv.dll (Microsoft Corporation)
Drivers32: wave - wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave3 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave4 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave5 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave6 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave7 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave9 - wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - msacm32.drv (Microsoft Corporation)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2014.11.08 16:51:42 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2014.11.08 16:51:42 | 000,000,000 | ---D | C] -- C:\rsit
[2014.11.08 16:23:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloader
[2014.11.08 16:00:33 | 002,480,312 | ---- | C] (Sysinternals -
www.sysinternals.com) -- C:\Users\admin\Desktop\procexp.exe
[2014.11.07 21:46:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014.11.07 21:39:57 | 000,000,000 | ---D | C] -- C:\Users\admin\Documents\iMacros
[2014.11.04 18:03:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clownfish
[2014.11.04 18:03:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Clownfish
[2014.11.02 00:52:58 | 000,000,000 | ---D | C] -- C:\Users\admin\Desktop\zaloha
[2014.10.26 12:06:21 | 000,000,000 | ---D | C] -- C:\Users\admin\Documents\Navicat
[2014.10.26 11:44:13 | 304,870,262 | ---- | C] (Installshield Software Corporation ) -- C:\Users\admin\Desktop\Metin2_2004.exe
[2014.10.26 11:23:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremiumSoft
[2014.10.26 11:23:35 | 000,000,000 | ---D | C] -- C:\Program Files\PremiumSoft
[2014.10.25 14:47:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PuTTY
[2014.10.25 14:47:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PuTTY
[2014.10.24 16:29:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HammerMT2 Server 1 2014
[2014.10.24 16:27:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HammerMT2 Server 1 2014
[2014.10.24 12:29:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blender Foundation
[2014.10.24 12:29:03 | 000,000,000 | ---D | C] -- C:\Program Files\Blender Foundation
[2014.10.22 19:22:29 | 000,000,000 | ---D | C] -- C:\Users\admin\GSplay
[2014.10.22 19:12:51 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6
[2014.10.22 19:11:08 | 000,000,000 | ---D | C] -- C:\Counter-Strike 1.6
[2014.10.20 20:31:39 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Roaming\.minecraft
[2014.10.14 16:28:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Logs
[2014.10.11 13:28:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014.10.11 13:28:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014.11.08 17:22:30 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2014.11.08 17:19:00 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-992597708-1987578634-1854157398-1000UA.job
[2014.11.08 17:01:00 | 000,000,950 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.11.08 16:23:32 | 001,868,800 | ---- | M] () -- C:\Users\admin\Desktop\downloader.exe
[2014.11.08 16:18:02 | 000,000,946 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.11.08 16:12:09 | 000,781,298 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014.11.08 16:12:09 | 000,653,526 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014.11.08 16:12:09 | 000,121,398 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014.11.08 16:10:23 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.11.08 16:10:23 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.11.08 16:05:45 | 000,002,108 | ---- | M] () -- C:\Windows\SysWow64\postreusif.bin
[2014.11.08 16:04:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.11.08 16:04:44 | 546,788,692 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2014.11.08 16:04:42 | 536,322,047 | -HS- | M] () -- C:\hiberfil.sys
[2014.11.08 16:00:24 | 001,188,194 | ---- | M] () -- C:\Users\admin\Desktop\ProcessExplorer.zip
[2014.11.08 15:50:56 | 000,007,648 | ---- | M] () -- C:\Users\admin\AppData\Local\resmon.resmoncfg
[2014.11.08 13:28:13 | 000,001,212 | ---- | M] () -- C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HDDlife.lnk
[2014.11.08 13:27:15 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-992597708-1987578634-1854157398-1000Core.job
[2014.11.08 12:17:21 | 000,051,720 | ---- | M] () -- C:\Users\admin\Desktop\25.jpg
[2014.11.08 11:20:54 | 000,062,561 | ---- | M] () -- C:\Users\admin\Desktop\sexy-ass-girls02.jpg
[2014.11.08 11:07:18 | 000,022,563 | ---- | M] () -- C:\Users\admin\Desktop\10614352_580909572015178_6960596359635039912_n.jpg
[2014.11.08 11:02:52 | 000,062,776 | ---- | M] () -- C:\Users\admin\Desktop\hhhn.jpg
[2014.11.08 10:46:58 | 000,091,513 | ---- | M] () -- C:\Users\admin\Desktop\15.png
[2014.11.08 10:15:51 | 000,227,411 | ---- | M] () -- C:\Users\admin\Desktop\tumblr_neochrV7Qk1rsx7u3o1_1280.jpg
[2014.11.07 22:35:20 | 000,001,044 | ---- | M] () -- C:\Users\admin\Desktop\Auto.mcs
[2014.11.07 20:39:38 | 000,097,234 | ---- | M] () -- C:\Users\admin\Desktop\10703752_1043126125712776_4227052219071656414_n.jpg
[2014.11.07 17:03:37 | 000,064,431 | ---- | M] () -- C:\Users\admin\Desktop\fbf.jpg
[2014.11.07 17:02:45 | 000,060,276 | ---- | M] () -- C:\Users\admin\Desktop\gbg.jpg
[2014.11.07 16:29:33 | 000,039,995 | ---- | M] () -- C:\Users\admin\Desktop\363.jpg
[2014.11.07 16:25:00 | 000,055,550 | ---- | M] () -- C:\Users\admin\Desktop\gbh.jpg
[2014.11.07 16:22:56 | 000,063,035 | ---- | M] () -- C:\Users\admin\Desktop\3.jpg
[2014.11.07 16:15:26 | 000,125,080 | ---- | M] () -- C:\Users\admin\Desktop\559223_433109550078285_948473081_n.jpg
[2014.11.06 23:31:22 | 000,000,256 | ---- | M] () -- C:\Users\admin\Desktop\index.html
[2014.11.06 23:31:09 | 000,000,256 | ---- | M] () -- C:\Users\admin\Desktop\index.php
[2014.11.06 23:01:24 | 000,011,413 | ---- | M] () -- C:\Users\admin\AppData\Local\recently-used.xbel
[2014.11.05 22:38:22 | 000,131,125 | ---- | M] () -- C:\Users\admin\Desktop\qs.png
[2014.11.05 18:49:51 | 000,225,980 | ---- | M] () -- C:\Users\admin\Desktop\dvf.jpg
[2014.11.04 23:03:32 | 000,043,357 | ---- | M] () -- C:\Users\admin\Desktop\fb.jpg
[2014.11.04 20:14:14 | 000,026,053 | ---- | M] () -- C:\Users\admin\Desktop\52.jpg
[2014.11.04 17:40:57 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2014.11.03 15:33:33 | 000,000,528 | ---- | M] () -- C:\Windows\SysNative\postreusif.bin
[2014.11.03 11:57:11 | 000,000,600 | ---- | M] () -- C:\Users\admin\AppData\Local\PUTTY.RND
[2014.10.28 00:25:40 | 000,113,801 | ---- | M] () -- C:\Users\admin\Desktop\2014-10-28_00.25.40.png
[2014.10.26 12:05:50 | 000,366,527 | ---- | M] () -- C:\Users\admin\Desktop\rain_mysql.tar.gz
[2014.10.26 11:44:21 | 304,870,262 | ---- | M] (Installshield Software Corporation ) -- C:\Users\admin\Desktop\Metin2_2004.exe
[2014.10.26 11:39:44 | 053,396,038 | ---- | M] () -- C:\Users\admin\Desktop\rain.tar.gz
[2014.10.26 11:25:40 | 000,000,753 | ---- | M] () -- C:\Users\admin\Desktop\XAMPP Control Panel.lnk
[2014.10.26 11:25:29 | 000,001,010 | ---- | M] () -- C:\Users\admin\Desktop\Navicat Premium.lnk
[2014.10.25 14:47:43 | 000,000,963 | ---- | M] () -- C:\Users\Public\Desktop\PuTTY.lnk
[2014.10.24 12:29:38 | 000,001,857 | ---- | M] () -- C:\Users\Public\Desktop\Blender.lnk
[2014.10.20 20:32:03 | 000,001,946 | ---- | M] () -- C:\Users\Public\Desktop\Hrát na MC Titan
www.mctitan.cz.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014.11.08 17:22:30 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2014.11.08 17:05:18 | 001,868,800 | ---- | C] () -- C:\Users\admin\Desktop\downloader.exe
[2014.11.08 16:00:33 | 000,072,154 | ---- | C] () -- C:\Users\admin\Desktop\procexp.chm
[2014.11.08 16:00:18 | 001,188,194 | ---- | C] () -- C:\Users\admin\Desktop\ProcessExplorer.zip
[2014.11.08 12:17:19 | 000,051,720 | ---- | C] () -- C:\Users\admin\Desktop\25.jpg
[2014.11.08 11:20:53 | 000,062,561 | ---- | C] () -- C:\Users\admin\Desktop\sexy-ass-girls02.jpg
[2014.11.08 11:07:18 | 000,022,563 | ---- | C] () -- C:\Users\admin\Desktop\10614352_580909572015178_6960596359635039912_n.jpg
[2014.11.08 11:02:51 | 000,062,776 | ---- | C] () -- C:\Users\admin\Desktop\hhhn.jpg
[2014.11.08 10:46:57 | 000,091,513 | ---- | C] () -- C:\Users\admin\Desktop\15.png
[2014.11.08 10:15:49 | 000,227,411 | ---- | C] () -- C:\Users\admin\Desktop\tumblr_neochrV7Qk1rsx7u3o1_1280.jpg
[2014.11.07 22:26:10 | 000,001,044 | ---- | C] () -- C:\Users\admin\Desktop\Auto.mcs
[2014.11.07 20:39:37 | 000,097,234 | ---- | C] () -- C:\Users\admin\Desktop\10703752_1043126125712776_4227052219071656414_n.jpg
[2014.11.07 17:03:37 | 000,064,431 | ---- | C] () -- C:\Users\admin\Desktop\fbf.jpg
[2014.11.07 17:02:19 | 000,060,276 | ---- | C] () -- C:\Users\admin\Desktop\gbg.jpg
[2014.11.07 16:29:32 | 000,039,995 | ---- | C] () -- C:\Users\admin\Desktop\363.jpg
[2014.11.07 16:25:00 | 000,055,550 | ---- | C] () -- C:\Users\admin\Desktop\gbh.jpg
[2014.11.07 16:22:56 | 000,063,035 | ---- | C] () -- C:\Users\admin\Desktop\3.jpg
[2014.11.07 16:15:22 | 000,125,080 | ---- | C] () -- C:\Users\admin\Desktop\559223_433109550078285_948473081_n.jpg
[2014.11.06 23:29:11 | 000,000,256 | ---- | C] () -- C:\Users\admin\Desktop\index.php
[2014.11.06 23:06:06 | 000,000,256 | ---- | C] () -- C:\Users\admin\Desktop\index.html
[2014.11.06 23:01:24 | 000,011,413 | ---- | C] () -- C:\Users\admin\AppData\Local\recently-used.xbel
[2014.11.05 22:38:22 | 000,131,125 | ---- | C] () -- C:\Users\admin\Desktop\qs.png
[2014.11.05 18:47:31 | 000,225,980 | ---- | C] () -- C:\Users\admin\Desktop\dvf.jpg
[2014.11.04 23:03:32 | 000,043,357 | ---- | C] () -- C:\Users\admin\Desktop\fb.jpg
[2014.11.04 20:14:14 | 000,026,053 | ---- | C] () -- C:\Users\admin\Desktop\52.jpg
[2014.11.04 17:40:57 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2014.10.28 17:23:33 | 000,113,801 | ---- | C] () -- C:\Users\admin\Desktop\2014-10-28_00.25.40.png
[2014.10.26 12:05:49 | 000,366,527 | ---- | C] () -- C:\Users\admin\Desktop\rain_mysql.tar.gz
[2014.10.26 11:39:43 | 053,396,038 | ---- | C] () -- C:\Users\admin\Desktop\rain.tar.gz
[2014.10.26 11:25:40 | 000,000,753 | ---- | C] () -- C:\Users\admin\Desktop\XAMPP Control Panel.lnk
[2014.10.26 11:24:18 | 000,001,010 | ---- | C] () -- C:\Users\admin\Desktop\Navicat Premium.lnk
[2014.10.26 11:23:38 | 001,988,096 | ---- | C] () -- C:\Windows\SysNative\libmysql_e.dll
[2014.10.25 14:48:02 | 000,000,600 | ---- | C] () -- C:\Users\admin\AppData\Local\PUTTY.RND
[2014.10.25 14:47:43 | 000,000,963 | ---- | C] () -- C:\Users\Public\Desktop\PuTTY.lnk
[2014.10.24 12:29:38 | 000,001,857 | ---- | C] () -- C:\Users\Public\Desktop\Blender.lnk
[2014.10.22 19:15:14 | 546,788,692 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2014.10.20 20:32:03 | 000,001,946 | ---- | C] () -- C:\Users\Public\Desktop\Hrát na MC Titan
www.mctitan.cz.lnk
[2014.09.15 17:42:58 | 000,002,108 | ---- | C] () -- C:\Windows\SysWow64\postreusif.bin
[2014.09.15 17:42:57 | 000,000,008 | ---- | C] () -- C:\Users\admin\AppData\Roaming\_
[2014.09.09 20:07:57 | 000,007,648 | ---- | C] () -- C:\Users\admin\AppData\Local\resmon.resmoncfg
[2014.08.30 17:10:12 | 000,000,120 | ---- | C] () -- C:\Users\admin\.screenleap
[2014.05.29 21:44:45 | 000,721,263 | ---- | C] () -- C:\Windows\SysWow64\AiCM64.dll
[2014.05.29 21:44:44 | 000,214,528 | ---- | C] () -- C:\Windows\SysWow64\AiCM32.dll
[2014.05.29 13:16:02 | 000,189,248 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2014.05.29 13:16:01 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2014.04.01 16:40:43 | 000,000,057 | ---- | C] () -- C:\Windows\directx.sys
[2014.01.30 21:57:37 | 000,002,446 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014.01.28 21:41:54 | 000,178,176 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2014.01.28 21:41:54 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2014.01.28 21:41:53 | 003,596,288 | ---- | C] () -- C:\Windows\SysWow64\qt-dx331.dll
[2014.01.28 21:41:53 | 000,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2014.01.28 21:41:53 | 000,205,824 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2014.01.28 21:41:52 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2014.01.28 21:10:23 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\AVEQT.dll
[2014.01.22 16:53:40 | 000,000,000 | -HS- | C] () -- C:\Users\admin\AppData\Local\LumaEmu
[2014.01.13 17:18:13 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2014.01.13 17:14:52 | 000,757,660 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.12.06 22:38:38 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013.12.06 22:38:38 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013.12.06 21:39:24 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.12.06 21:39:24 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013.12.06 16:44:26 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2013.08.05 07:15:08 | 000,066,104 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
[2013.08.05 07:15:06 | 000,023,080 | ---- | C] () -- C:\Windows\SysWow64\bdmjpeg.dll
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2009.07.14 02:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009.07.14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014.11.07 18:12:08 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\.minecraft
[2014.05.30 13:21:54 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Aimersoft Video Converter Ultimate
[2014.09.21 23:09:03 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\AVAST Software
[2014.01.28 20:38:12 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\BANDISOFT
[2014.05.11 20:37:35 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Battle.net
[2014.09.29 16:29:29 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\BinarySense
[2014.01.20 06:38:28 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\DeepBurner
[2014.08.25 22:46:49 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Dropbox
[2014.11.03 20:36:07 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\FileZilla
[2014.07.06 22:56:59 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\FlvtoConverter
[2014.09.21 23:02:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\GameMaker-Studio
[2014.06.08 17:02:14 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\GHISLER
[2014.07.08 16:32:36 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\iWesoft
[2014.08.14 17:13:45 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\LaRoXion
[2014.01.27 15:43:42 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\LolClient
[2014.09.21 23:02:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\MC Titan Technic
[2014.09.21 23:02:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\MC Titan Technic v2
[2014.09.21 23:02:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\mctitanpokemine4
[2014.09.23 08:38:39 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Mikrotik
[2014.08.30 22:17:59 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Notepad++
[2014.09.21 23:02:52 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\OBS
[2014.05.29 05:45:04 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Origin
[2014.01.17 15:40:19 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Publish Providers
[2014.09.21 23:02:52 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\puush
[2014.01.26 13:36:22 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Riot Games
[2014.05.06 19:58:56 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Screaming Bee
[2014.08.14 16:36:24 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Sony
[2014.01.22 16:55:15 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\SpaceEngineers
[2014.03.11 20:16:15 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\steamvr
[2014.02.19 20:54:15 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\StepMania 5
[2014.01.19 16:11:11 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Sublime Text 3
[2014.04.20 12:01:01 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\SYSTEMAX Software Development
[2014.02.15 23:45:58 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TeamViewer
[2014.01.23 19:28:37 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TERA
[2014.11.07 21:55:06 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TS3Client
[2014.04.07 16:22:14 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Unity
[2014.10.25 23:04:36 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\uTorrent
[2014.07.10 18:37:55 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Wacom
[2014.06.08 17:51:54 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\z5a52yal.s2j
[2014.01.28 23:54:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\zbusoft
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 06:08:49 | 000,032,570 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.07.14 06:08:49 | 000,032,588 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU(43).TXT
[2009.07.14 06:08:49 | 000,032,588 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU(49).TXT
[2014.01.14 18:51:16 | 000,000,946 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2014.01.14 18:51:17 | 000,000,950 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2014.02.28 22:14:32 | 000,000,910 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-992597708-1987578634-1854157398-1000Core.job
[2014.02.28 22:14:33 | 000,000,962 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-992597708-1987578634-1854157398-1000UA.job
< >
< MD5 for: AGP440.SYS >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\SysWOW64\autochk.exe
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\SysNative\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
< MD5 for: CDROM.SYS >
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysNative\drivers\cdrom.sys
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_8363d00ecae4322d\cdrom.sys
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys
< MD5 for: CNGAUDIT.DLL >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: CRYPTSVC.DLL >
[2009.07.14 02:40:24 | 000,175,104 | ---- | M] (Microsoft Corporation) MD5=8C57411B66282C01533CB776F98AD384 -- C:\Windows\SysNative\cryptsvc.dll
[2009.07.14 02:40:24 | 000,175,104 | ---- | M] (Microsoft Corporation) MD5=8C57411B66282C01533CB776F98AD384 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.16385_none_d1f48b0bb4805490\cryptsvc.dll
[2009.07.14 02:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) MD5=9C231178CE4FB385F4B54B0A9080B8A4 -- C:\Windows\SysWOW64\cryptsvc.dll
[2009.07.14 02:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) MD5=9C231178CE4FB385F4B54B0A9080B8A4 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.16385_none_75d5ef87fc22e35a\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2013.03.12 16:00:10 | 000,025,600 | ---- | M] () MD5=3296A6B39A35330F1734A79B20B89FDE -- C:\xampp\perl\vendor\lib\auto\Win32\EventLog\EventLog.dll
< MD5 for: EXPLORER.EXE >
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\SysWOW64\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
< MD5 for: HAL.DLL >
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\SysNative\hal.dll
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_071de44b735b3dfc\hal.dll
< MD5 for: IASTORV.SYS >
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
< MD5 for: ISAPNP.SYS >
[2009.07.14 02:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\drivers\isapnp.sys
[2009.07.14 02:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\isapnp.sys
[2009.07.14 02:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\isapnp.sys
< MD5 for: LSASS.EXE >
[2009.07.14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\SysNative\lsass.exe
[2009.07.14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16385_none_023f7c69767c3edd\lsass.exe
< MD5 for: NDIS.SYS >
[2009.07.14 02:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) MD5=CAD515DBD07D082BB317D9928CE8962C -- C:\Windows\SysNative\drivers\ndis.sys
[2009.07.14 02:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) MD5=CAD515DBD07D082BB317D9928CE8962C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_03bc1d6e35c013bf\ndis.sys
< MD5 for: NETLOGON.DLL >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
< MD5 for: NVRAID.SYS >
[2009.07.14 02:48:27 | 000,149,056 | ---- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D -- C:\Windows\SysNative\drivers\nvraid.sys
[2009.07.14 02:48:27 | 000,149,056 | ---- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvraid.sys
[2009.07.14 02:48:27 | 000,149,056 | ---- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvraid.sys
< MD5 for: NVSTOR.SYS >
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\drivers\nvstor.sys
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
< MD5 for: SCECLI.DLL >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
< MD5 for: SMSS.EXE >
[2009.07.14 02:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\SysNative\smss.exe
[2009.07.14 02:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_082f99a432e2a661\smss.exe
< MD5 for: SVCHOST.EXE >
[2014.05.12 06:24:30 | 000,750,392 | ---- | M] (MalwareBytes) MD5=09882E8EDD1144E6EF1AF6D1F98305EE -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2009.07.14 02:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\SysNative\drivers\tcpip.sys
[2009.07.14 02:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
< MD5 for: USERINIT.EXE >
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
< MD5 for: WINLOGON.EXE >
[2014.05.12 06:24:30 | 000,750,392 | ---- | M] (MalwareBytes) MD5=09882E8EDD1144E6EF1AF6D1F98305EE -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\SysNative\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
< MD5 for: WS2_32.DLL >
[2009.07.14 02:41:58 | 000,296,448 | ---- | M] (Microsoft Corporation) MD5=7083F463788CB34FCC42F565D56F89E8 -- C:\Windows\SysNative\ws2_32.dll
[2009.07.14 02:41:58 | 000,296,448 | ---- | M] (Microsoft Corporation) MD5=7083F463788CB34FCC42F565D56F89E8 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_4eaca269e8070c6b\ws2_32.dll
[2009.07.14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\SysWOW64\ws2_32.dll
[2009.07.14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_f28e06e62fa99b35\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[2 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[68 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\03a05fa9049b3527c1ed36dd79b47c28\*.tmp files -> C:\Windows\SoftwareDistribution\Download\03a05fa9049b3527c1ed36dd79b47c28\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\0e30a62a2ea49f44c884f666c5718702\*.tmp files -> C:\Windows\SoftwareDistribution\Download\0e30a62a2ea49f44c884f666c5718702\*.tmp -> ]
[434 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 07:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2014.11.07 18:12:08 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\.minecraft
[2014.05.26 14:58:28 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Adobe
[2014.05.30 13:21:54 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Aimersoft Video Converter Ultimate
[2014.01.13 17:18:47 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\ATI
[2014.09.21 23:09:03 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\AVAST Software
[2014.01.28 20:38:12 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\BANDISOFT
[2014.05.11 20:37:35 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Battle.net
[2014.09.29 16:29:29 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\BinarySense
[2014.01.20 06:38:28 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\DeepBurner
[2014.08.25 22:46:49 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Dropbox
[2014.11.03 20:36:07 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\FileZilla
[2014.07.06 22:56:59 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\FlvtoConverter
[2014.09.21 23:02:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\GameMaker-Studio
[2014.06.08 17:02:14 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\GHISLER
[2014.01.13 17:09:44 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Identities
[2014.01.15 18:08:43 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\InstallShield
[2014.07.08 16:32:36 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\iWesoft
[2014.08.14 17:13:45 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\LaRoXion
[2014.01.27 15:43:42 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\LolClient
[2014.01.23 19:08:40 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Macromedia
[2014.09.21 23:02:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\MC Titan Technic
[2014.09.21 23:02:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\MC Titan Technic v2
[2014.09.21 23:02:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\mctitanpokemine4
[2009.07.14 08:45:14 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Media Center Programs
[2014.10.20 21:25:07 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Media Player Classic
[2014.10.03 18:36:46 | 000,000,000 | --SD | M] -- C:\Users\admin\AppData\Roaming\Microsoft
[2014.09.23 08:38:39 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Mikrotik
[2014.07.21 18:06:11 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Mozilla
[2014.01.20 06:19:15 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Nero
[2014.08.30 22:17:59 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Notepad++
[2014.09.21 23:02:52 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\OBS
[2014.05.29 05:45:04 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Origin
[2014.04.10 18:25:50 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\PSpad
[2014.01.17 15:40:19 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Publish Providers
[2014.09.21 23:02:52 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\puush
[2014.01.26 13:36:22 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Riot Games
[2014.05.06 19:58:56 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Screaming Bee
[2014.11.08 16:09:09 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Skype
[2014.08.14 16:36:24 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Sony
[2014.01.22 16:55:15 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\SpaceEngineers
[2014.03.11 20:16:15 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\steamvr
[2014.02.19 20:54:15 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\StepMania 5
[2014.01.19 16:11:11 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Sublime Text 3
[2014.04.20 12:01:01 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\SYSTEMAX Software Development
[2014.02.15 23:45:58 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TeamViewer
[2014.01.23 19:28:37 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TERA
[2014.11.07 21:55:06 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TS3Client
[2014.04.07 16:22:14 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Unity
[2014.10.25 23:04:36 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\uTorrent
[2014.07.10 18:37:55 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Wacom
[2014.01.14 20:36:26 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\WinRAR
[2014.07.10 18:41:37 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\WTablet
[2014.06.08 17:51:54 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\z5a52yal.s2j
[2014.01.28 23:54:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\zbusoft
< %APPDATA%\*.exe /s >
[2014.10.20 20:32:03 | 000,125,466 | ---- | M] () -- C:\Users\admin\AppData\Roaming\.minecraft\Odinstalovat.exe
[2014.10.12 02:13:20 | 002,788,696 | ---- | M] (YoYo Games Ltd) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\5piceIDE.exe
[2014.10.12 02:13:24 | 004,180,480 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\ffmpeg.exe
[2014.06.07 13:38:11 | 024,923,136 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\ffprobe.exe
[2014.10.12 02:13:24 | 000,150,872 | ---- | M] (YoYo Games Ltd.) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\GameMaker-Studio.exe
[2014.10.12 02:13:24 | 001,610,072 | ---- | M] (YoYo Games Ltd.) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\GMAssetCompiler.exe
[2014.10.12 02:13:24 | 000,775,000 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\GMWebServer.exe
[2014.10.12 02:13:26 | 002,988,888 | ---- | M] (YoYo Games Ltd. ) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Runner.exe
[2014.10.12 02:13:27 | 000,167,936 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\unzip.exe
[2014.10.12 02:13:28 | 000,135,168 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\zip.exe
[2014.10.12 02:13:24 | 001,369,600 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\GMDebug\GMDebug.exe
[2014.10.12 02:13:25 | 000,292,184 | ---- | M] (Microsoft Corporation) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\makensis\dxwebsetup.exe
[2014.10.12 02:13:25 | 000,496,128 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\makensis\makensis.exe
[2014.06.07 13:38:20 | 000,005,632 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\default.exe
[2014.06.07 13:38:20 | 000,006,144 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\modern.exe
[2014.06.07 13:38:20 | 000,004,096 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\modern_headerbmp.exe
[2014.06.07 13:38:20 | 000,004,096 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\modern_headerbmpr.exe
[2014.06.07 13:38:20 | 000,003,584 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\modern_nodesc.exe
[2014.06.07 13:38:20 | 000,003,584 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\modern_smalldesc.exe
[2014.06.07 13:38:20 | 000,006,144 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\makensis\Contrib\UIs\sdbarker_tiny.exe
[2014.10.12 02:13:25 | 000,372,224 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\OpenSSL\openssl.exe
[2014.10.12 02:13:26 | 000,303,104 | ---- | M] (Simon Tatham) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\putty\plink.exe
[2014.10.12 02:13:26 | 000,315,392 | ---- | M] (Simon Tatham) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\putty\pscp.exe
[2014.10.12 02:13:26 | 000,483,328 | ---- | M] (Simon Tatham) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\putty\putty.exe
[2014.06.07 13:38:23 | 000,018,432 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Shaders\D3D11ShaderParser.exe
[2014.10.12 02:13:26 | 000,104,448 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Shaders\HLSLCompiler.exe
[2014.06.07 13:38:25 | 000,010,752 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x64\bin\svn-populate-node-origins-index.exe
[2014.10.12 02:13:26 | 000,228,864 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x64\bin\svn.exe
[2014.10.12 02:13:26 | 000,072,704 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x64\bin\svnadmin.exe
[2014.06.07 13:38:26 | 000,019,456 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x64\bin\svnauthz-validate.exe
[2014.06.07 13:38:26 | 000,040,960 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x64\bin\svndumpfilter.exe
[2014.10.12 02:13:26 | 000,071,168 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x64\bin\svnlook.exe
[2014.06.07 13:38:26 | 000,023,552 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x64\bin\svnmucc.exe
[2014.10.12 02:13:26 | 000,054,784 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x64\bin\svnrdump.exe
[2014.10.12 02:13:26 | 000,148,480 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x64\bin\svnserve.exe
[2014.10.12 02:13:26 | 000,056,320 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x64\bin\svnsync.exe
[2014.06.07 13:38:26 | 000,024,576 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x64\bin\svnversion.exe
[2014.10.12 02:13:27 | 000,189,440 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x86\bin\svn.exe
[2014.10.12 02:13:27 | 000,058,880 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x86\bin\svnadmin.exe
[2014.06.07 13:38:27 | 000,036,352 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x86\bin\svndumpfilter.exe
[2014.10.12 02:13:27 | 000,057,344 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x86\bin\svnlook.exe
[2014.06.07 13:38:27 | 000,021,504 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x86\bin\svnmucc.exe
[2014.10.12 02:13:27 | 000,045,056 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x86\bin\svnrdump.exe
[2014.10.12 02:13:27 | 000,047,616 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x86\bin\svnsync.exe
[2014.06.07 13:38:27 | 000,024,064 | ---- | M] (
http://subversion.apache.org/) -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Subversion\x86\bin\svnversion.exe
[2014.06.08 17:50:43 | 003,556,123 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Tizen\Device\TizenRunner.exe
[2014.06.08 17:50:43 | 003,816,788 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Tizen\Emulator\TizenRunner.exe
[2014.06.07 13:38:35 | 000,013,312 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Windows8\LaunchMetroApp.exe
[2014.06.07 13:38:39 | 000,012,288 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Windows8\Stop-Appx.exe
[2014.10.12 02:13:28 | 000,094,720 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Windows8\Native\arm\WinMetroRunner.exe
[2014.10.12 02:13:28 | 000,095,232 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\Windows8\Native\x86\WinMetroRunner.exe
[2014.06.08 17:50:44 | 000,029,696 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\WinPhone\DeploymentTool.exe
[2014.06.07 13:38:44 | 018,664,448 | ---- | M] () -- C:\Users\admin\AppData\Roaming\GameMaker-Studio\YYC\bin\clang++.exe
[2014.10.12 02:13:29 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\admin\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2014.10.12 02:13:36 | 000,134,014 | ---- | M] () -- C:\Users\admin\AppData\Roaming\MC Titan Technic v2\Odinstalovat.exe
[2014.10.12 02:13:32 | 000,134,102 | ---- | M] () -- C:\Users\admin\AppData\Roaming\MC Titan Technic\Odinstalovat.exe
[2014.10.12 02:13:40 | 000,128,312 | ---- | M] () -- C:\Users\admin\AppData\Roaming\mctitanpokemine4\Odinstalovat.exe
[2014.10.12 02:13:40 | 000,231,463 | ---- | M] () -- C:\Users\admin\AppData\Roaming\mctitanpokemine4\Uninstal.exe
[2014.07.22 20:32:40 | 000,102,134 | R--- | M] () -- C:\Users\admin\AppData\Roaming\Microsoft\Installer\{90D83CB4-3692-458C-95D4-E60CC7E0B278}\_2DC32E96981458BD6B33CF.exe
[2014.07.22 20:32:40 | 000,102,134 | R--- | M] () -- C:\Users\admin\AppData\Roaming\Microsoft\Installer\{90D83CB4-3692-458C-95D4-E60CC7E0B278}\_3259EBB7DD8B81CCA77E0F.exe
[2014.07.22 20:32:40 | 000,102,134 | R--- | M] () -- C:\Users\admin\AppData\Roaming\Microsoft\Installer\{90D83CB4-3692-458C-95D4-E60CC7E0B278}\_6EEBBB904B912B9C1DEC88.exe
[2014.07.22 20:32:40 | 000,102,134 | R--- | M] () -- C:\Users\admin\AppData\Roaming\Microsoft\Installer\{90D83CB4-3692-458C-95D4-E60CC7E0B278}\_853F67D554F05449430E7E.exe
[2014.10.27 10:05:34 | 000,252,928 | ---- | M] (obsproject.com) -- C:\Users\admin\AppData\Roaming\OBS\updates\updater.exe
[2014.10.12 02:13:50 | 000,393,728 | ---- | M] (BitTorrent, Inc.) -- C:\Users\admin\AppData\Roaming\uTorrent\utorrent.exe
[2014.10.24 16:27:07 | 1263,743,684 | ---- | M] (HammerMT2, Inc. ) -- C:\Users\admin\AppData\Roaming\uTorrent\;\HammerMT2 Server 1 2014.exe
[2014.05.28 20:30:39 | 037,210,678 | ---- | M] (Aimersoft Software ) -- C:\Users\admin\AppData\Roaming\uTorrent\;\Aimersoft Video Converter Ultimate v5.6.0.1 Incl Crack - [MUMBAI]\aimer-video-ultimate_full523.exe
[2014.10.12 02:13:46 | 003,388,416 | ---- | M] (Aimersoft Software) -- C:\Users\admin\AppData\Roaming\uTorrent\;\Aimersoft Video Converter Ultimate v5.6.0.1 Incl Crack - [MUMBAI]\Crack\VideoConverterUltimate.exe
[2014.10.12 02:13:46 | 004,812,672 | ---- | M] (Piriform Ltd) -- C:\Users\admin\AppData\Roaming\uTorrent\;\CCleaner v4.15.4725 Business & Professional Edition Incl. Crack [ATOM]\ccsetup415.exe
[2014.10.12 02:13:47 | 000,204,800 | ---- | M] () -- C:\Users\admin\AppData\Roaming\uTorrent\;\crack vegas 9\Keygen.exe
[2014.10.12 02:13:47 | 000,096,256 | ---- | M] () -- C:\Users\admin\AppData\Roaming\uTorrent\;\crack vegas 9\Sony_VegasPro8_DVDArchitect45_SoundForge9_CRACK.exe
[2014.10.12 02:13:47 | 001,489,920 | ---- | M] () -- C:\Users\admin\AppData\Roaming\uTorrent\;\Fraps 3.5.99 Fully Registered Sept 2014\setup.exe
[2014.10.12 02:13:48 | 000,463,152 | ---- | M] (Microsoft Corporation) -- C:\Users\admin\AppData\Roaming\uTorrent\;\MicroSoft Office 2007 With Key -THADOGG\setup.exe
[2014.10.12 02:13:48 | 000,145,184 | ---- | M] (Microsoft Corporation) -- C:\Users\admin\AppData\Roaming\uTorrent\;\MicroSoft Office 2007 With Key -THADOGG\Enterprise.WW\ose.exe
[2014.10.12 02:13:48 | 000,813,384 | ---- | M] (Microsoft Corporation) -- C:\Users\admin\AppData\Roaming\uTorrent\;\MicroSoft Office 2007 With Key -THADOGG\Office.en-us\DW20.EXE
[2014.10.12 02:13:48 | 000,434,528 | ---- | M] (Microsoft Corporation) -- C:\Users\admin\AppData\Roaming\uTorrent\;\MicroSoft Office 2007 With Key -THADOGG\Office.en-us\dwtrig20.exe
[2014.05.29 17:01:33 | 155,346,841 | ---- | M] (TeamExtreme ) -- C:\Users\admin\AppData\Roaming\uTorrent\;\Minecraft 1.7.9 by TeamExtremeMc.com\Minecraft 1.7.9.exe
[2014.10.12 02:13:49 | 000,378,880 | ---- | M] (Install.exe) -- C:\Users\admin\AppData\Roaming\uTorrent\;\rzr-skrm\install.exe
[2014.10.12 02:13:49 | 000,355,920 | ---- | M] (Valve Corporation) -- C:\Users\admin\AppData\Roaming\uTorrent\;\rzr-skrm\Setup.exe
[2014.10.12 02:13:49 | 000,411,016 | ---- | M] (Valve Corporation) -- C:\Users\admin\AppData\Roaming\uTorrent\;\rzr-skrm\SteamService.exe
[2014.10.12 02:13:49 | 004,726,270 | ---- | M] ( ) -- C:\Users\admin\AppData\Roaming\uTorrent\;\Watch Dogs ENG\setup.exe
[2014.10.12 02:13:49 | 000,087,040 | ---- | M] () -- C:\Users\admin\AppData\Roaming\uTorrent\;\Watch Dogs ENG\Crack\GameLauncher_x64.exe
[2014.05.25 16:53:11 | 062,404,320 | ---- | M] (Ubisoft) -- C:\Users\admin\AppData\Roaming\uTorrent\;\Watch Dogs ENG\uPlay\UplayInstaller.exe
[2014.06.07 13:38:44 | 018,664,448 | ---- | M] () -- C:\Users\admin\AppData\Roaming\z5a52yal.s2j\YYC\bin\clang++.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009.07.08 20:34:27 | 000,010,752 | ---- | M] ()
Unable to obtain MD5 -- C:\Windows\system32\lonertotedoust.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
[2009.07.08 20:34:27 | 000,010,752 | ---- | M] ()
Unable to obtain MD5 -- C:\Windows\system32\lonertotedoust.dll
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2014.11.08 16:05:45 | 000,002,108 | ---- | M] () -- C:\Windows\system32\postreusif.bin
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 07:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Steam" = "C:\Program Files (x86)\Steam\steam.exe" -silent -- [2014.10.21 20:22:38 | 001,938,624 | ---- | M] (Valve Corporation)
"puush" = C:\Program Files (x86)\puush\puush.exe -- [2014.05.25 12:45:46 | 000,567,880 | ---- | M] ()
"Skype" = "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun -- [2014.08.27 08:20:30 | 022,041,192 | R--- | M] (Skype Technologies S.A.)
"GSplay.exe" = C:\Users\admin\Desktop\GSplay.exe
"Clownfish" = "C:\Program Files (x86)\Clownfish\Clownfish.exe" -- [2014.09.24 09:57:38 | 001,323,776 | ---- | M] (Bogdan Sharkov)
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe -k netsvcs
< >
< type c:\boot.ini >> test.txt /c >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2014.11.08 17:22:30 | 000,000,512 | ---- | M] () MD5=4B77BC0B0FE07AED7CCC98BAD86E2F4F -- C:\PhysicalMBR.bin