Som rad, ze sa este nieco da urobit

Teraz som si vsimol, ze AdBlock sa mi vzdy zablokuje a nefunguje. Ked ho povolim v nastaveniach, vydrzi 5 sekund a zase sa deaktivuje. Co s tym?
Tu su logy:
OTL logfile created on: 17.6.2015 14:07:28 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Gabriel\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d.M.yyyy
1021,31 Mb Total Physical Memory | 719,43 Mb Available Physical Memory | 70,44% Memory free
2,40 Gb Paging File | 1,96 Gb Available in Paging File | 81,51% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149,04 Gb Total Space | 65,45 Gb Free Space | 43,92% Space Free | Partition Type: NTFS
Drive D: | 3,92 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: GABRIELN | User Name: Gabriel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2015.06.17 14:05:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Gabriel\Desktop\OTL.exe
PRC - [2015.06.02 16:24:26 | 000,244,392 | ---- | M] (Foxit Software Inc.) -- C:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
PRC - [2015.05.12 10:33:03 | 005,515,496 | ---- | M] (Avast Software s.r.o.) -- C:\Program Files\AVAST Software\Avast\avastui.exe
PRC - [2015.05.10 12:56:33 | 000,343,336 | ---- | M] (Avast Software s.r.o.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2015.05.06 09:30:08 | 000,108,032 | ---- | M] (Freemake) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
PRC - [2014.12.19 09:38:38 | 000,093,040 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2014.07.23 01:47:10 | 000,142,648 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2009.10.08 11:14:32 | 000,069,632 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
PRC - [2009.07.15 13:43:46 | 000,109,168 | ---- | M] (Portrait Displays, Inc.) -- C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
PRC - [2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008.04.10 21:07:20 | 000,413,696 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
========== Modules (No Company Name) ==========
MOD - [2015.06.17 13:50:36 | 002,952,704 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\15061700\algo.dll
MOD - [2015.06.16 21:05:41 | 002,952,704 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\15061602\algo.dll
MOD - [2015.05.10 12:56:37 | 040,540,672 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2015.05.10 12:56:34 | 000,104,400 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\log.dll
MOD - [2015.05.10 12:56:33 | 000,081,728 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
MOD - [2014.05.03 11:48:06 | 001,886,208 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Web.Services\a741d9ff6728605a3429f8a4c9b97fc9\System.Web.Services.ni.dll
MOD - [2014.05.03 11:47:59 | 000,221,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\2e3fdae8546832614633495638bef8d0\System.ServiceProcess.ni.dll
MOD - [2014.05.03 11:47:49 | 018,109,440 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\dd733c6f1f9f50f3517d48da5bea80d2\System.ServiceModel.ni.dll
MOD - [2014.05.03 11:47:13 | 001,218,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Management\7612d2ecdf9c6beedc264e9390e97b0f\System.Management.ni.dll
MOD - [2014.05.03 11:45:26 | 000,148,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\d1389795ee255d46ed3ed84776d2bb69\System.Configuration.Install.ni.dll
MOD - [2014.05.03 11:44:24 | 001,021,440 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\469dd20488c4a9606abe21189a3c1ab9\System.Runtime.DurableInstancing.ni.dll
MOD - [2014.05.03 11:44:22 | 002,658,304 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\fa954900a6cf3a095efadfa4c683a32c\System.Runtime.Serialization.ni.dll
MOD - [2014.05.03 11:44:22 | 000,143,360 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\27bdc6196968e44234654e30e1028750\SMDiagnostics.ni.dll
MOD - [2014.05.03 00:48:11 | 007,053,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\a4b5a1a06d2d7f77258943c8c228a5e0\System.Core.ni.dll
MOD - [2014.05.03 00:48:08 | 005,628,928 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\850fa7110c7423c324762c1ad3130219\System.Xml.ni.dll
MOD - [2014.05.03 00:48:02 | 001,014,272 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\991c4e11f571a4074b9c4a5841222338\System.Configuration.ni.dll
MOD - [2014.05.03 00:47:59 | 009,099,776 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\4c906eb82e6f56aea01b2a7291fab7ea\System.ni.dll
MOD - [2014.05.03 00:47:50 | 014,416,896 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\4e62d1d9b7dd2c2d14915abb73c22d50\mscorlib.ni.dll
MOD - [2014.02.14 12:33:16 | 011,906,048 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\f0b0625c2db624ba9c97ad1b12490d79\System.Web.ni.dll
MOD - [2014.02.14 12:31:10 | 000,978,944 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b6e70acd99dc22e29b7fc8f9ac340c4\System.Configuration.ni.dll
MOD - [2014.02.14 12:30:04 | 000,025,600 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\06b454361516e65eca55a743cd93cefc\Accessibility.ni.dll
MOD - [2014.02.14 01:15:49 | 000,303,104 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2014.02.14 01:13:43 | 005,462,016 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\7faf645dc46781225cb722edf9e1e738\System.Xml.ni.dll
MOD - [2014.02.14 01:13:37 | 012,434,432 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1cdfe1998ad6794db3237006906c6fa2\System.Windows.Forms.ni.dll
MOD - [2014.02.14 01:12:59 | 001,593,344 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\424bff3295c6e7539cc6df62b9425bd0\System.Drawing.ni.dll
MOD - [2014.02.14 01:06:53 | 007,977,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\4b0455ae94e3cecca4bb3ba8c96828c9\System.ni.dll
MOD - [2014.02.14 01:06:05 | 011,497,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\dae02331a443fb52216ca83292cb2f21\mscorlib.ni.dll
MOD - [2012.09.18 13:51:42 | 000,016,384 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
MOD - [2012.08.15 21:19:12 | 000,270,336 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2010.03.16 12:22:12 | 000,014,848 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll
MOD - [2009.10.08 11:14:32 | 000,069,632 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2015.06.02 16:24:26 | 000,244,392 | ---- | M] (Foxit Software Inc.) [Auto | Running] -- C:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe -- (FoxitCloudUpdateService)
SRV - [2015.05.12 16:22:30 | 000,580,144 | ---- | M] (WiseCleaner.com) [Auto | Stopped] -- C:\Program Files\Wise\Wise Care 365\BootTime.exe -- (WiseBootAssistant)
SRV - [2015.05.10 12:56:33 | 000,343,336 | ---- | M] (Avast Software s.r.o.) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2015.05.06 09:30:08 | 000,108,032 | ---- | M] (Freemake) [Auto | Running] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe -- (Freemake Improver)
SRV - [2014.12.19 09:38:38 | 000,093,040 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2014.07.23 01:47:10 | 000,142,648 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore.exe -- (!SASCORE)
SRV - [2009.10.08 11:14:32 | 000,069,632 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe -- (DTSRVC)
SRV - [2009.07.15 13:43:46 | 000,109,168 | ---- | M] (Portrait Displays, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe -- (PdiService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [File_System | Auto | Stopped] -- -- (StarOpen)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\anvsnddrv.sys -- (anvsnddrv)
DRV - [2015.06.13 09:49:56 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2015.05.14 09:55:45 | 000,013,264 | ---- | M] (wisecleaner.com) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\WiseHDInfo32.dll -- (WiseHDInfo)
DRV - [2015.05.10 12:56:37 | 000,427,992 | ---- | M] (Avast Software s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\aswSP.sys -- (aswSP)
DRV - [2015.05.10 12:56:37 | 000,209,048 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2015.05.10 12:56:37 | 000,074,976 | ---- | M] (Avast Software s.r.o.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2015.05.10 12:56:37 | 000,057,888 | ---- | M] (Avast Software s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2015.05.10 12:56:37 | 000,055,200 | ---- | M] (Avast Software s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2015.05.10 12:56:37 | 000,049,904 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2015.05.10 12:56:37 | 000,024,144 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\aswHwid.sys -- (aswHwid)
DRV - [2015.05.10 12:56:30 | 000,787,760 | ---- | M] (Avast Software s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2015.05.02 14:29:29 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DrvAgent32.sys -- (DrvAgent32)
DRV - [2013.01.31 10:19:50 | 000,181,344 | ---- | M] (DEVGURU Co., LTD.(
www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2013.01.31 10:19:50 | 000,083,168 | ---- | M] (DEVGURU Co., LTD.(
www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2012.08.16 04:58:38 | 006,810,624 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2012.02.23 14:31:22 | 000,099,856 | R--- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtihdXP3.sys -- (AtiHDAudioService)
DRV - [2011.07.22 18:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011.07.12 23:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2009.07.15 13:43:32 | 000,017,136 | ---- | M] (Portrait Displays, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PdiPorts.sys -- (PdiPorts)
DRV - [2009.03.03 11:42:00 | 000,017,465 | ---- | M] (Portrait Displays, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\pivot.sys -- (Pivot)
DRV - [2009.03.03 11:41:58 | 000,011,323 | ---- | M] (Portrait Displays, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pivotmou.sys -- (pivotmou)
DRV - [2008.04.10 21:10:10 | 001,271,032 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2008.01.09 11:28:34 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\seehcri.sys -- (seehcri)
DRV - [2006.11.02 07:00:08 | 000,039,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\winusb.sys -- (WinUSB)
DRV - [2005.12.03 02:38:04 | 000,041,728 | ---- | M] (Sonic Focus, Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sfng32.sys -- (sfng32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1645522239-1417001333-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-1645522239-1417001333-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKU\S-1-5-21-1645522239-1417001333-839522115-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1645522239-1417001333-839522115-1004\..\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}: "URL" =
http://www.google.com/search?q={searchTerms}
IE - HKU\S-1-5-21-1645522239-1417001333-839522115-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-1645522239-1417001333-839522115-1004\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchT ... {startPage}
IE - HKU\S-1-5-21-1645522239-1417001333-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:10.0.2204.148
FF - prefs.js..extensions.enabledAddons: Stratiform%40SoapySpew:3.0.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.0.2
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1218158.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.45.2: C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.45.2: C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/DownloadManager,version=1.1: C:\WINDOWS\ [2015.06.16 16:48:37 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2015.05.10 12:56:38 | 000,000,000 | ---D | M]
[2014.06.30 17:06:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Gabriel\Application Data\Mozilla\Extensions
[2012.10.06 19:49:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Gabriel\Application Data\Mozilla\Extensions\
home2@tomtom.com
[2015.06.14 19:53:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Gabriel\Application Data\Mozilla\Firefox\Profiles\g7je0c2u.default\extensions
[2014.11.04 14:35:35 | 000,240,755 | ---- | M] () (No name found) -- C:\Documents and Settings\Gabriel\Application Data\Mozilla\Firefox\Profiles\g7je0c2u.default\extensions\
Stratiform@SoapySpew.xpi
[2014.11.04 14:28:56 | 000,979,610 | ---- | M] () (No name found) -- C:\Documents and Settings\Gabriel\Application Data\Mozilla\Firefox\Profiles\g7je0c2u.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.02.04 12:21:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\GABRIEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\G7JE0C2U.DEFAULT\EXTENSIONS\
ASCSURFINGPROTECTION@IOBIT.COM
[2015.05.10 12:56:38 | 000,000,000 | ---D | M] ("Avast Online Security") -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
O1 HOSTS File: ([2015.06.14 19:53:59 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (Avast Software s.r.o.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-1645522239-1417001333-839522115-1004\..\Toolbar\ShellBrowser: (no name) - {10921475-03CE-4E04-90CE-E2E7EF20C814} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (Avast Software s.r.o.)
O4 - HKLM..\Run: [DT PHL] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKU\S-1-5-21-1645522239-1417001333-839522115-1004..\Run: [EPSON SX125 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIGGE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-1645522239-1417001333-839522115-1004..\Run: [Wisdom-soft ScreenHunter 6.0 Free] 0 File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1645522239-1417001333-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKU\S-1-5-21-1645522239-1417001333-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://windowsupdate.microsoft.com/wind ... 7923174796 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftup ... 7923229796 (MUWebControl Class)
O16 - DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE}
http://download.microsoft.com/download/ ... anager.cab (Microsoft Download Manager ActiveX control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{19BFFC58-3D34-4234-B47E-2C29FDF351E7}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Gabriel\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Gabriel\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005.02.25 18:24:44 | 000,000,051 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2015.06.17 14:05:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Gabriel\Desktop\OTL.exe
[2015.06.16 01:09:12 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Gabriel\Recent
[2015.06.14 18:29:24 | 000,112,107 | ---- | C] (forum.viry.cz) -- C:\Documents and Settings\Gabriel\My Documents\VerzeOS.exe
[2015.06.14 18:06:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gabriel\My Documents\CrystalDiskInfo5_0_0
[2015.06.13 08:50:19 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2015.06.06 14:00:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gabriel\My Documents\KOJAK
[2015.06.06 13:25:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gabriel\Local Settings\Application Data\FreemakeVideoConverter
[2015.06.06 13:24:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gabriel\My Documents\Freemake
[2015.06.06 13:24:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gabriel\Start Menu\Programs\Freemake
[2015.06.06 13:24:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Freemake
[2015.06.06 13:24:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Freemake
[2015.06.06 13:23:56 | 000,000,000 | ---D | C] -- C:\Program Files\Freemake
[2015.06.06 13:16:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gabriel\Application Data\tiger-k
[2015.06.06 13:16:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gabriel\Application Data\Leawo
[2015.06.06 13:16:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Leawo
[2015.06.06 13:13:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\K-Lite Codec Pack
[2015.06.06 13:12:45 | 000,139,264 | ---- | C] (
http://www.xvid.org) -- C:\WINDOWS\System32\xvid.ax
[2015.05.31 20:16:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Fraps
[2015.05.31 20:16:37 | 000,000,000 | ---D | C] -- C:\Fraps
[2015.05.29 18:03:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gabriel\My Documents\PassMark
[2015.05.29 18:03:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gabriel\Local Settings\Application Data\PassMark
[2015.05.29 18:03:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Passmark
[2015.05.29 17:41:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\CPUID
[2015.05.29 17:41:45 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
[2004.06.22 09:04:56 | 000,442,425 | ---- | C] (Hewlett-Packard) -- C:\Program Files\hpzjpp01.dll
[2004.06.22 09:04:56 | 000,290,873 | ---- | C] (Hewlett-Packard) -- C:\Program Files\hpzjut01.dll
[2004.06.22 09:04:56 | 000,254,005 | ---- | C] (Microsoft Corporation) -- C:\Program Files\msvcrt.dll
[2004.06.22 09:04:56 | 000,200,704 | ---- | C] (HP) -- C:\Program Files\hpzpnp10.dll
[2004.06.22 09:04:56 | 000,176,128 | ---- | C] (HP) -- C:\Program Files\hpzscr10.dll
[2004.06.22 09:04:56 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Program Files\msvcirt.dll
[2004.06.22 09:04:56 | 000,049,212 | ---- | C] (Hewlett-Packard) -- C:\Program Files\hpzjvp01.dll
[2004.06.22 09:04:56 | 000,026,768 | ---- | C] (Microsoft Corporation) -- C:\Program Files\usbhub.sys
[2004.06.22 09:04:56 | 000,022,608 | ---- | C] (Microsoft Corporation) -- C:\Program Files\usbprint.sys
[2004.06.22 09:04:56 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Program Files\usbmon.dll
[2004.06.22 09:04:54 | 000,270,336 | ---- | C] (HP) -- C:\Program Files\hpzglu10.exe
[2004.06.22 09:04:54 | 000,270,336 | ---- | C] (Hewlett-Packard Co.) -- C:\Program Files\hpzc3212.dll
[2004.06.22 09:04:54 | 000,028,722 | ---- | C] (Hewlett-Packard) -- C:\Program Files\hpzjlog.dll
========== Files - Modified Within 30 Days ==========
[2015.06.17 14:10:19 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2015.06.17 14:05:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Gabriel\Desktop\OTL.exe
[2015.06.17 12:57:16 | 000,000,366 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2015.06.17 09:47:57 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2015.06.16 16:48:15 | 000,122,928 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2015.06.14 19:53:59 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2015.06.14 18:29:35 | 000,112,107 | ---- | M] (forum.viry.cz) -- C:\Documents and Settings\Gabriel\My Documents\VerzeOS.exe
[2015.06.14 14:49:07 | 001,496,172 | ---- | M] () -- C:\Documents and Settings\Gabriel\My Documents\CrystalDiskInfo5_0_0.zip
[2015.06.14 14:16:32 | 000,162,304 | ---- | M] () -- C:\Documents and Settings\Gabriel\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2015.06.14 11:11:09 | 002,231,296 | ---- | M] () -- C:\Documents and Settings\Gabriel\My Documents\adwcleaner_4.206.exe
[2015.06.13 09:49:56 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2015.06.11 09:39:24 | 000,001,695 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Wise Care 365.lnk
[2015.06.10 20:41:24 | 000,778,416 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2015.06.10 20:41:24 | 000,142,512 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2015.06.10 20:15:36 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2015.06.09 13:01:38 | 000,113,084 | ---- | M] () -- C:\Documents and Settings\Gabriel\My Documents\Ziadost_pri_opakovanej_evidencii (1).rtf
[2015.06.08 13:12:24 | 415,132,812 | ---- | M] () -- C:\Documents and Settings\Gabriel\My Documents\gta_sa 2015-06-08 13-11-54-43.avi
[2015.06.07 20:30:43 | 000,031,342 | ---- | M] () -- C:\Documents and Settings\Gabriel\My Documents\Ziadost_pri_opakovanej_evidencii.rtf
[2015.06.06 22:00:18 | 000,640,792 | ---- | M] () -- C:\Documents and Settings\Gabriel\My Documents\11224358_1146927288667869_814114173278784505_n.png
[2015.06.06 13:24:28 | 000,000,973 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Freemake Video Converter.lnk
[2015.06.06 00:47:03 | 000,000,038 | ---- | M] () -- C:\WINDOWS\AviSplitter.INI
[2015.06.05 00:45:21 | 006,904,007 | ---- | M] () -- C:\Documents and Settings\Gabriel\My Documents\Ponuky uchádzačov.pdf
[2015.06.04 22:59:35 | 000,209,490 | ---- | M] () -- C:\Documents and Settings\Gabriel\Desktop\brana Omama.jpg
[2015.05.31 20:16:39 | 000,000,478 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Fraps.lnk
[2015.05.29 18:57:48 | 000,129,207 | ---- | M] () -- C:\Documents and Settings\Gabriel\Desktop\bot Anna.jpg
[2015.05.29 17:51:23 | 000,078,544 | ---- | M] () -- C:\Documents and Settings\Gabriel\My Documents\GABRIELN.html
[2015.05.29 13:30:58 | 000,000,852 | ---- | M] () -- C:\Documents and Settings\Gabriel\Desktop\Any Video Converter.lnk
[2015.05.27 00:48:46 | 000,130,142 | ---- | M] () -- C:\Documents and Settings\Gabriel\Desktop\JFTW.jpg
[2015.05.25 00:47:33 | 000,112,958 | ---- | M] () -- C:\Documents and Settings\Gabriel\Desktop\organigram_byt_cintorinska.jpg
[2015.05.23 15:42:37 | 000,101,417 | ---- | M] () -- C:\Documents and Settings\Gabriel\Desktop\trueb.d.jpg
========== Files Created - No Company Name ==========
[2015.06.17 14:10:19 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2015.06.16 16:48:15 | 000,122,928 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2015.06.14 14:48:25 | 001,496,172 | ---- | C] () -- C:\Documents and Settings\Gabriel\My Documents\CrystalDiskInfo5_0_0.zip
[2015.06.14 11:10:38 | 002,231,296 | ---- | C] () -- C:\Documents and Settings\Gabriel\My Documents\adwcleaner_4.206.exe
[2015.06.09 13:01:30 | 000,113,084 | ---- | C] () -- C:\Documents and Settings\Gabriel\My Documents\Ziadost_pri_opakovanej_evidencii (1).rtf
[2015.06.08 13:11:54 | 415,132,812 | ---- | C] () -- C:\Documents and Settings\Gabriel\My Documents\gta_sa 2015-06-08 13-11-54-43.avi
[2015.06.06 22:00:14 | 000,640,792 | ---- | C] () -- C:\Documents and Settings\Gabriel\My Documents\11224358_1146927288667869_814114173278784505_n.png
[2015.06.06 13:24:28 | 000,000,973 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Freemake Video Converter.lnk
[2015.06.06 13:13:47 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2015.06.05 00:44:51 | 006,904,007 | ---- | C] () -- C:\Documents and Settings\Gabriel\My Documents\Ponuky uchádzačov.pdf
[2015.06.04 22:59:35 | 000,209,490 | ---- | C] () -- C:\Documents and Settings\Gabriel\Desktop\brana Omama.jpg
[2015.05.31 20:16:39 | 000,000,478 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Fraps.lnk
[2015.05.29 18:57:48 | 000,129,207 | ---- | C] () -- C:\Documents and Settings\Gabriel\Desktop\bot Anna.jpg
[2015.05.29 17:51:23 | 000,078,544 | ---- | C] () -- C:\Documents and Settings\Gabriel\My Documents\GABRIELN.html
[2015.05.27 00:48:46 | 000,130,142 | ---- | C] () -- C:\Documents and Settings\Gabriel\Desktop\JFTW.jpg
[2015.05.25 00:47:18 | 000,112,958 | ---- | C] () -- C:\Documents and Settings\Gabriel\Desktop\organigram_byt_cintorinska.jpg
[2015.05.23 15:42:37 | 000,101,417 | ---- | C] () -- C:\Documents and Settings\Gabriel\Desktop\trueb.d.jpg
[2015.05.10 12:56:48 | 000,209,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2015.05.10 12:56:47 | 000,049,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2015.05.10 12:56:46 | 000,024,144 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswHwid.sys
[2015.05.06 11:07:54 | 005,677,056 | ---- | C] () -- C:\Documents and Settings\Gabriel\ntuser.rhk
[2014.09.16 22:53:44 | 000,000,091 | ---- | C] () -- C:\WINDOWS\CIV.INI
[2013.12.14 15:12:44 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2013.11.13 19:11:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI
[2013.10.02 15:26:47 | 000,000,118 | ---- | C] () -- C:\Documents and Settings\Gabriel\Application Data\settings.xml
[2013.08.05 17:17:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2013.08.05 17:16:50 | 000,632,252 | R--- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2013.08.05 12:15:56 | 000,007,432 | ---- | C] () -- C:\WINDOWS\System32\Machnm32.sys
[2012.09.22 17:39:47 | 000,004,943 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Application Data\mtbjfghn.xbe
[2012.09.18 00:36:52 | 000,162,304 | ---- | C] () -- C:\Documents and Settings\Gabriel\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004.06.22 09:04:56 | 000,000,399 | ---- | C] () -- C:\Program Files\hpzprl01.dat
[2004.06.22 09:04:56 | 000,000,297 | ---- | C] () -- C:\Program Files\Readme.html
[2004.06.22 09:04:56 | 000,000,205 | ---- | C] () -- C:\Program Files\hpzprl02.dat
[2004.06.22 09:04:54 | 000,447,400 | ---- | C] () -- C:\Program Files\hpoprn08.cat
[2004.06.22 09:04:54 | 000,137,124 | ---- | C] () -- C:\Program Files\hpoprn08.inf
[2004.06.22 09:04:54 | 000,094,438 | ---- | C] () -- C:\Program Files\hposcu08.inf
[2004.06.22 09:04:54 | 000,066,431 | ---- | C] () -- C:\Program Files\hpoprl04.dat
[2004.06.22 09:04:54 | 000,065,420 | ---- | C] () -- C:\Program Files\hpoprl05.dat
[2004.06.22 09:04:54 | 000,053,670 | ---- | C] () -- C:\Program Files\hposcu08.cat
[2004.06.22 09:04:54 | 000,052,349 | ---- | C] () -- C:\Program Files\hpzius13.cat
[2004.06.22 09:04:54 | 000,052,349 | ---- | C] () -- C:\Program Files\HPZius12.cat
[2004.06.22 09:04:54 | 000,051,467 | ---- | C] () -- C:\Program Files\hpzist13.cat
[2004.06.22 09:04:54 | 000,051,467 | ---- | C] () -- C:\Program Files\hpzist12.cat
[2004.06.22 09:04:54 | 000,051,467 | ---- | C] () -- C:\Program Files\hpzipr13.cat
[2004.06.22 09:04:54 | 000,051,467 | ---- | C] () -- C:\Program Files\HPZipr12.cat
[2004.06.22 09:04:54 | 000,051,467 | ---- | C] () -- C:\Program Files\hpzid413.cat
[2004.06.22 09:04:54 | 000,051,467 | ---- | C] () -- C:\Program Files\HPZid412.cat
[2004.06.22 09:04:54 | 000,051,026 | ---- | C] () -- C:\Program Files\HPOunp08.cat
[2004.06.22 09:04:54 | 000,050,615 | ---- | C] () -- C:\Program Files\hpzid412.inf
[2004.06.22 09:04:54 | 000,022,636 | ---- | C] () -- C:\Program Files\hpzid413.inf
[2004.06.22 09:04:54 | 000,020,168 | ---- | C] () -- C:\Program Files\hpzius12.inf
[2004.06.22 09:04:54 | 000,019,578 | ---- | C] () -- C:\Program Files\hpoprl03.dat
[2004.06.22 09:04:54 | 000,014,815 | ---- | C] () -- C:\Program Files\hpzius13.inf
[2004.06.22 09:04:54 | 000,012,922 | ---- | C] () -- C:\Program Files\hpzipr12.inf
[2004.06.22 09:04:54 | 000,009,777 | ---- | C] () -- C:\Program Files\hpzipr13.inf
[2004.06.22 09:04:54 | 000,009,773 | ---- | C] () -- C:\Program Files\hpousc08.inf
[2004.06.22 09:04:54 | 000,007,579 | ---- | C] () -- C:\Program Files\hpound08.inf
[2004.06.22 09:04:54 | 000,006,704 | ---- | C] () -- C:\Program Files\hpounp08.inf
[2004.06.22 09:04:54 | 000,005,538 | ---- | C] () -- C:\Program Files\hpzist12.inf
[2004.06.22 09:04:54 | 000,004,144 | ---- | C] () -- C:\Program Files\hpousb08.inf
[2004.06.22 09:04:54 | 000,004,132 | ---- | C] () -- C:\Program Files\hpzist13.inf
[2004.06.22 09:04:54 | 000,004,014 | ---- | C] () -- C:\Program Files\hpoprl08.dat
[2004.06.22 09:04:54 | 000,001,980 | ---- | C] () -- C:\Program Files\hpoprl07.dat
[2004.06.22 09:04:54 | 000,000,314 | ---- | C] () -- C:\Program Files\hpqprl01.dat
[2004.06.22 09:04:52 | 000,017,176 | ---- | C] () -- C:\Program Files\hpomdl04.dat
[2004.06.22 09:04:52 | 000,014,845 | ---- | C] () -- C:\Program Files\hpoapd01.dat
[2004.06.22 09:04:52 | 000,004,779 | ---- | C] () -- C:\Program Files\hpoglu08.inf
[2004.06.22 09:04:52 | 000,004,768 | ---- | C] () -- C:\Program Files\hpoprl01.dat
[2004.06.22 09:04:52 | 000,003,448 | ---- | C] () -- C:\Program Files\hpohub08.inf
[2004.06.22 09:04:52 | 000,002,542 | ---- | C] () -- C:\Program Files\hpoprl02.dat
[2004.06.22 09:04:52 | 000,000,065 | ---- | C] () -- C:\Program Files\dxprl.dat
========== ZeroAccess Check ==========
[2012.09.18 15:51:11 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2012.10.31 13:33:26 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 14:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 05:42:10 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2009.11.14 01:19:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\.freeciv
[2011.06.16 21:35:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\.minecraft
[2009.04.04 19:09:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Ashampoo
[2012.09.11 23:08:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Auslogics
[2010.03.28 16:21:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Canneverbe Limited
[2010.09.27 01:11:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\ChemTable Software
[2012.03.31 19:56:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\DAEMON Tools Lite
[2009.02.11 22:43:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\DAEMON Tools Pro
[2011.05.05 19:13:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Epson
[2010.11.22 13:27:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Feedreader
[2012.03.21 13:13:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Foxit Software
[2009.07.07 15:40:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\gtk-2.0
[2010.02.26 18:06:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\id Software
[2010.03.07 21:36:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Jpeg Resampler
[2009.10.09 18:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Leawo
[2009.09.26 01:38:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\MSNInstaller
[2011.04.10 20:45:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\MyPhoneExplorer
[2009.03.25 17:49:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\OpenOffice.org
[2011.05.25 16:49:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Opera
[2012.06.16 23:35:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Oracle
[2011.04.29 11:28:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\PCToolsFirewallPlus
[2011.06.16 21:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Roaming
[2009.10.22 12:29:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\SystemRequirementsLab
[2009.01.03 22:48:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Teleca
[2009.07.22 16:40:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\TomTom
[2010.11.20 03:14:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\uTorrent
[2010.02.04 15:21:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Windows Desktop Search
[2010.02.04 15:22:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\Windows Search
[2009.11.23 13:17:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Application Data\ZipGenius
[2008.05.09 23:18:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acronis
[2010.02.08 22:37:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009.02.28 21:22:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo
[2012.09.17 13:09:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2010.03.28 16:20:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010.02.12 23:18:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Codemasters
[2012.04.26 22:16:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2009.11.07 13:25:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011.09.27 13:48:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2009.03.22 02:30:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2014.06.30 16:41:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2011.10.05 12:39:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IC_Katalog
[2010.02.26 18:04:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\id Software
[2010.03.16 21:23:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2012.09.17 22:40:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009.07.22 16:44:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
[2011.09.27 13:52:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2012.03.25 01:29:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YouTube Downloader
[2009.03.31 22:41:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010.05.31 15:45:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009.11.12 22:11:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2015.05.10 12:55:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\AVAST Software
[2015.05.08 12:27:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Baidu
[2012.09.18 15:33:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\BVRP Software
[2012.10.08 19:36:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Canneverbe Limited
[2013.11.13 19:07:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\EPSON
[2015.06.06 13:25:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Freemake
[2014.11.15 18:33:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\HitmanPro
[2014.11.21 22:18:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\IObit
[2014.10.07 14:35:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\IsolatedStorage
[2015.06.06 13:16:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Leawo
[2013.03.16 14:59:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Licenses
[2015.04.23 19:55:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Oracle
[2015.05.11 12:02:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Package Cache
[2015.05.29 18:03:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Passmark
[2013.04.16 00:05:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Samsung
[2015.06.09 23:39:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2012.09.18 15:58:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\TomTom
[2014.06.04 10:55:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Western Digital
[2014.01.09 01:11:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Zoner
[2013.10.26 23:25:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\0ad
[2015.06.14 13:41:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\AnvSoft
[2014.10.01 17:14:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Audacity
[2015.05.10 12:57:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\AVAST Software
[2013.11.22 23:35:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\avidemux
[2012.10.10 20:31:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Canneverbe Limited
[2012.09.22 17:39:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Carambis
[2013.10.02 15:24:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\convertaudiofree
[2013.08.05 12:18:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\DisplayTune
[2014.06.06 12:03:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Dropbox
[2014.06.06 10:02:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\DropboxMaster
[2013.05.11 11:50:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\DVDVideoSoft
[2013.11.13 19:07:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\EPSON
[2013.11.23 19:12:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Eusing
[2014.03.16 21:56:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Foxit Software
[2014.11.21 21:36:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\IObit
[2015.06.06 13:16:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Leawo
[2013.12.11 02:01:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Machete Lite
[2013.09.24 21:04:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\OpenOffice
[2012.09.21 01:14:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\OpenOffice.org
[2012.09.18 00:25:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Opera
[2014.04.11 20:56:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Opera Software
[2013.06.24 00:07:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Oracle
[2013.05.06 09:34:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\PhotoFiltre 7
[2013.04.16 00:05:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Samsung
[2013.11.10 13:45:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Sony
[2014.05.08 21:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\SystemRequirementsLab
[2015.06.06 13:17:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\tiger-k
[2012.09.18 15:56:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\TomTom
[2014.07.27 23:45:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Unity
[2015.06.11 09:46:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Wise Care 365
[2014.08.25 12:49:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\XnView
[2015.05.03 21:28:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\YoWindow
[2011.05.05 13:50:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Opera
[2014.03.16 21:57:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\Foxit Software
========== Purity Check ==========
========== Custom Scans ==========
< >
[2012.09.17 23:26:56 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2012.09.17 23:33:19 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2015.05.10 12:57:02 | 000,000,366 | -H-- | C] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job
< >
< MD5 for: AGP440.SYS >
[2006.02.28 14:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2006.02.28 14:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2006.02.28 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0059\DriverFiles\i386\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0060\DriverFiles\i386\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 02:12:12 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\cmdcons\autochk.exe
[2008.04.14 05:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 05:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\system32\autochk.exe
[2006.02.28 14:00:00 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=B3415B9D6026F65E43089ABED096C38C -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe
< MD5 for: CDROM.SYS >
[2006.02.28 14:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\Documents and Settings\admin\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20120426T202212968750\gencdrom\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\Documents and Settings\admin\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20120426T203355765625\gencdrom\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\Documents and Settings\admin\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20120426T204653062500\gencdrom\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\Documents and Settings\admin\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20120426T205454828125\gencdrom\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\Documents and Settings\admin\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20120426T210614937500\gencdrom\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\Documents and Settings\admin\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20120702T200914921875\gencdrom\cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2006.02.28 14:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2006.02.28 14:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=10654F9DDCEA9C46CFB77554231BE73B -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 05:41:52 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=3D4E199942E29207970E04315D02AD3B -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 05:41:52 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=3D4E199942E29207970E04315D02AD3B -- C:\WINDOWS\system32\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2006.02.28 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008.04.14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2006.02.28 14:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: HAL.DLL >
[2006.02.28 14:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.13 20:31:28 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\Documents and Settings\admin\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20120426T202212968750\acpiapic_mp\hal.dll
[2008.04.13 20:31:28 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\Documents and Settings\admin\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20120426T203355765625\acpiapic_mp\hal.dll
[2008.04.13 20:31:28 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\Documents and Settings\admin\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20120426T204653062500\acpiapic_mp\hal.dll
[2008.04.13 20:31:28 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\Documents and Settings\admin\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20120426T205454828125\acpiapic_mp\hal.dll
[2008.04.13 20:31:28 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\Documents and Settings\admin\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20120426T210614937500\acpiapic_mp\hal.dll
[2008.04.13 20:31:28 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\Documents and Settings\admin\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20120702T200914921875\acpiapic_mp\hal.dll
[2008.04.14 00:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.14 00:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2006.02.28 14:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
< MD5 for: CHANGER.SYS >
[2006.02.28 14:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
< MD5 for: ISAPNP.SYS >
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2008.04.14 00:06:42 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=05A299EC56E52649B1CF2FC52D20F2D7 -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 00:06:42 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=05A299EC56E52649B1CF2FC52D20F2D7 -- C:\WINDOWS\system32\drivers\isapnp.sys
[2001.08.17 13:58:02 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=E504F706CCB699C2596E9A3DA1596E87 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2006.02.28 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=E504F706CCB699C2596E9A3DA1596E87 -- C:\WINDOWS\system32\ReinstallBackups\0055\DriverFiles\i386\isapnp.sys
< MD5 for: LSASS.EXE >
[2006.02.28 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=84885F9B82F4D55C6146EBF6065D75D2 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 05:42:26 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 05:42:26 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2006.02.28 14:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
< MD5 for: NETLOGON.DLL >
[2008.04.14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2006.02.28 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2006.02.28 14:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2008.04.14 05:42:38 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=5F816C1F539266D2D4C78694239DA0B5 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 05:42:38 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=5F816C1F539266D2D4C78694239DA0B5 -- C:\WINDOWS\system32\smss.exe
[2006.02.28 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=BD7FB0957C716F1A60333AEE04DE2178 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2004.08.04 01:56:58 | 000,152,576 | ---- | M] (Microsoft Corporation) MD5=DA5CF1C368B33D75602FD6B3A7F5E0C6 -- C:\cmdcons\SYSTEM32\SMSS.EXE
< MD5 for: SVCHOST.EXE >
[2008.04.14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2006.02.28 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2013.04.04 15:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2006.02.28 14:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2006.02.28 14:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008.04.14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2006.02.28 14:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2013.04.04 15:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.04.14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.04.14 05:42:12 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 05:42:12 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll
[2006.02.28 14:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[40 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< %ALLUSERSPROFILE%\Application Data\*. >
[2014.10.30 15:51:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple
[2014.10.30 15:50:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
[2013.08.05 17:20:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\ATI
[2015.05.10 12:55:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\AVAST Software
[2015.05.10 12:52:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
[2015.05.08 12:27:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Baidu
[2012.09.18 15:33:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\BVRP Software
[2012.10.08 19:36:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Canneverbe Limited
[2013.11.13 19:07:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\EPSON
[2015.06.06 13:25:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Freemake
[2014.05.15 13:25:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\GRETECH
[2014.11.15 18:33:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\HitmanPro
[2012.09.18 23:24:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Intel
[2014.11.21 22:18:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\IObit
[2014.10.07 14:35:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\IsolatedStorage
[2015.06.06 13:16:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Leawo
[2013.03.16 14:59:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Licenses
[2015.03.08 02:05:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
[2013.05.23 12:53:46 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
[2012.09.20 13:57:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Mozilla
[2014.12.16 17:01:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton
[2014.12.16 16:07:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\NortonInstaller
[2015.04.23 19:55:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Oracle
[2015.05.11 12:02:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Package Cache
[2015.05.29 18:03:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Passmark
[2013.04.16 00:05:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Samsung
[2015.06.05 10:11:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype
[2012.09.18 15:30:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Sony Ericsson
[2013.04.28 23:48:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Sun
[2015.04.13 13:26:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
[2015.06.09 23:39:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2012.09.18 15:58:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\TomTom
[2014.06.04 10:55:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Western Digital
[2012.10.26 00:43:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Windows Genuine Advantage
[2014.01.09 01:11:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Zoner
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
[2015.05.06 09:30:08 | 000,108,032 | ---- | M] (Freemake) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
[2015.05.06 09:30:06 | 000,304,128 | ---- | M] (Freemake) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Freemake\FreemakeUtilsService\ErrorReporter\FreemakeErrorReporter.exe
[2015.06.12 21:31:37 | 021,546,080 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
< %APPDATA%\*. >
[2013.10.26 23:25:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\0ad
[2012.09.18 11:51:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Adobe
[2015.06.14 13:41:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\AnvSoft
[2014.11.21 21:36:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Apple Computer
[2013.08.05 17:20:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\ATI
[2014.10.01 17:14:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Audacity
[2015.05.10 12:57:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\AVAST Software
[2013.11.22 23:35:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\avidemux
[2012.10.10 20:31:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Canneverbe Limited
[2012.09.22 17:39:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Carambis
[2013.10.02 15:24:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\convertaudiofree
[2013.08.05 12:18:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\DisplayTune
[2014.06.06 12:03:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Dropbox
[2014.06.06 10:02:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\DropboxMaster
[2013.05.11 11:50:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\DVDVideoSoft
[2013.11.13 19:07:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\EPSON
[2013.11.23 19:12:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Eusing
[2014.03.16 21:56:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Foxit Software
[2013.10.04 10:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\GRETECH
[2012.09.17 23:35:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Identities
[2012.09.18 23:24:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Intel
[2014.11.21 21:36:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\IObit
[2015.06.06 13:16:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Leawo
[2013.12.11 02:01:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Machete Lite
[2012.09.18 00:36:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Macromedia
[2015.03.08 02:06:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Malwarebytes
[2014.05.08 21:50:35 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Gabriel\Application Data\Microsoft
[2014.11.04 14:21:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Mozilla
[2013.09.24 21:04:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\OpenOffice
[2012.09.21 01:14:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\OpenOffice.org
[2012.09.18 00:25:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Opera
[2014.04.11 20:56:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Opera Software
[2013.06.24 00:07:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Oracle
[2013.05.06 09:34:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\PhotoFiltre 7
[2013.04.16 00:05:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Samsung
[2015.06.16 23:59:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Skype
[2013.11.10 13:45:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Sony
[2013.04.28 23:44:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Sun
[2015.04.13 13:28:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\SUPERAntiSpyware.com
[2014.05.08 21:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\SystemRequirementsLab
[2015.06.06 13:17:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\tiger-k
[2012.09.18 15:56:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\TomTom
[2014.07.27 23:45:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Unity
[2012.09.18 09:52:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\WinRAR
[2015.06.11 09:46:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\Wise Care 365
[2014.08.25 12:49:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\XnView
[2015.05.03 21:28:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gabriel\Application Data\YoWindow
< %APPDATA%\*.exe /s >
[2015.05.18 05:50:26 | 005,494,882 | ---- | M] () -- C:\Documents and Settings\Gabriel\Application Data\AnvSoft\Common\youtube-dl.exe
[2014.05.20 02:45:22 | 033,322,312 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Gabriel\Application Data\Dropbox\bin\Dropbox.exe
[2014.05.20 02:47:16 | 000,244,368 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Gabriel\Application Data\Dropbox\bin\DropboxUninstaller.exe
[2014.05.20 02:45:26 | 000,143,648 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Gabriel\Application Data\Dropbox\bin\DropboxUpdateHelper.exe
[2015.04.22 14:53:18 | 004,881,120 | ---- | M] (Foxit Corporation) -- C:\Documents and Settings\Gabriel\Application Data\Foxit Software\Addon\Foxit Reader\FoxitReaderUpdater.exe
[2014.03.25 04:47:24 | 000,139,368 | ---- | M] () -- C:\Documents and Settings\Gabriel\Application Data\GRETECH\GomPlayer\GrLauncher.exe
[2014.11.21 21:36:31 | 000,588,608 | ---- | M] () -- C:\Documents and Settings\Gabriel\Application Data\IObit\IObit Uninstaller\Install_PintoStartMenutemp.exe
[2014.11.21 21:36:35 | 000,629,568 | ---- | M] () -- C:\Documents and Settings\Gabriel\Application Data\IObit\IObit Uninstaller\UninstallDisplaytemp.exe
[2014.01.21 12:06:26 | 002,129,728 | ---- | M] (IObit) -- C:\Documents and Settings\Gabriel\Application Data\IObit\IObit Uninstaller\UninstallPromotetemp.exe
[2014.01.22 23:12:32 | 000,145,408 | ---- | M] () -- C:\Documents and Settings\Gabriel\Application Data\Sun\Java\jre1.7.0_51\lzma.exe
[2014.05.08 22:02:49 | 000,145,408 | ---- | M] () -- C:\Documents and Settings\Gabriel\Application Data\Sun\Java\jre1.7.0_55\lzma.exe
[2014.06.29 23:25:55 | 000,145,408 | ---- | M] () -- C:\Documents and Settings\Gabriel\Application Data\Sun\Java\jre1.7.0_60\lzma.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2012.09.18 01:11:52 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2012.09.18 01:11:52 | 000,634,880 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2012.09.18 01:11:52 | 000,921,600 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2015.06.16 16:48:15 | 000,122,928 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 05:42:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
"EPSON SX125 Series" = C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIGGE.EXE /FU "C:\DOCUME~1\Gabriel\LOCALS~1\Temp\E_S1AB.tmp" /EF "HKCU" -- [2009.09.14 08:00:00 | 000,200,704 | ---- | M] (SEIKO EPSON CORPORATION)
"Wisdom-soft ScreenHunter 6.0 Free" = 0
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs