OTL logfile created on: 17. 1. 2012 15:45:51 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Fester\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 0000041b | Country: Slovenská republika | Language: SKY | Date Format: d. M. yyyy
4,00 Gb Total Physical Memory | 2,39 Gb Available Physical Memory | 59,69% Memory free
5,46 Gb Paging File | 3,47 Gb Available in Paging File | 63,57% Paging File free
Paging file location(s): c:\pagefile.sys 1500 2048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 41,89 Gb Total Space | 1,35 Gb Free Space | 3,22% Space Free | Partition Type: NTFS
Drive G: | 554,18 Gb Total Space | 1,20 Gb Free Space | 0,22% Space Free | Partition Type: NTFS
Computer Name: FESTER-PC | User Name: Fester | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Processes (SafeList) ==========
PRC - [2012/01/16 16:53:39 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Fester\Desktop\OTL.exe
PRC - [2012/01/03 14:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/12/24 17:50:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/12/21 09:07:08 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/06/30 20:47:42 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/05/25 08:25:28 | 002,214,504 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/05/20 21:35:16 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/04/27 15:45:15 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011/04/01 09:31:38 | 002,271,608 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2011/03/29 06:50:35 | 000,399,736 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2010/11/05 16:21:09 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/10/19 12:01:32 | 000,075,064 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2010/08/31 18:12:22 | 005,896,656 | -H-- | M] () -- G:\QIP\QIP Infium PafoPack 9040\infium.exe
PRC - [2009/04/30 16:01:12 | 000,125,464 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
PRC - [2009/04/27 17:24:08 | 001,707,520 | ---- | M] (ASUSTek) -- C:\Program Files (x86)\ASUS\iTracker\iTracker.exe
PRC - [2008/11/18 12:15:30 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
========== Modules (No Company Name) ==========
MOD - [2012/01/01 17:58:45 | 008,527,008 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2011/12/21 09:07:08 | 002,124,760 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/10/14 15:28:52 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\07cdef1a740151932dcf161f3306bd9c\PresentationFramework.Aero.ni.dll
MOD - [2011/10/14 15:28:16 | 014,339,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\bb7848a42e8c9dd8577af34b9bd511a1\PresentationFramework.ni.dll
MOD - [2011/10/14 15:27:58 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll
MOD - [2011/10/14 15:27:49 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll
MOD - [2011/10/14 15:27:46 | 012,234,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\d2b301555648e46137965de64da03b93\PresentationCore.ni.dll
MOD - [2011/10/14 15:27:32 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll
MOD - [2011/10/14 15:27:25 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/10/14 15:27:21 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/10/14 15:27:20 | 007,963,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/10/14 15:27:13 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011/05/20 21:35:00 | 000,247,400 | ---- | M] () -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
MOD - [2011/03/16 23:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/11/13 03:36:45 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_cs_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010/11/05 02:54:43 | 000,237,568 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_cs_31bf3856ad364e35\PresentationFramework.resources.dll
MOD - [2010/08/31 18:12:26 | 000,438,224 | ---- | M] () -- G:\QIP\QIP Infium PafoPack 9040\Protos\Social\Social.dll
MOD - [2010/08/31 18:12:24 | 001,993,680 | ---- | M] () -- G:\QIP\QIP Infium PafoPack 9040\Protos\InfICQ\inficq.dll
MOD - [2010/08/31 18:12:24 | 000,086,992 | ---- | M] () -- G:\QIP\QIP Infium PafoPack 9040\Core\WebWindow.dll
MOD - [2010/08/31 18:12:22 | 005,896,656 | -H-- | M] () -- G:\QIP\QIP Infium PafoPack 9040\infium.exe
MOD - [2009/06/24 10:30:55 | 001,805,312 | ---- | M] () -- G:\QIP\QIP Infium PafoPack 9040\Plugins\TVp\TVp.dll
MOD - [2009/06/09 18:21:24 | 002,046,464 | ---- | M] () -- G:\QIP\QIP Infium PafoPack 9040\Plugins\RSSNews\RSSNews.dll
MOD - [2009/03/07 17:36:02 | 001,478,656 | ---- | M] () -- G:\QIP\QIP Infium PafoPack 9040\Plugins\FMtune\FMtune.dll
MOD - [2009/01/24 18:11:52 | 000,584,192 | ---- | M] () -- G:\QIP\QIP Infium PafoPack 9040\Plugins\QIPGraffiti\QIPGraffiti.dll
MOD - [2009/01/12 16:10:50 | 001,174,528 | ---- | M] () -- G:\QIP\QIP Infium PafoPack 9040\Plugins\Weather\Weather.dll
MOD - [2008/11/24 16:04:35 | 000,316,416 | ---- | M] () -- G:\QIP\QIP Infium PafoPack 9040\Plugins\Svatky\svatky.dll
MOD - [2008/05/15 22:01:18 | 001,083,392 | ---- | M] () -- G:\QIP\QIP Infium PafoPack 9040\Plugins\ExMusic\ExMusic.dll
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:
64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2009/07/14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:
64bit: - [2009/04/30 16:01:00 | 000,190,488 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcS64)
SRV - [2012/01/03 14:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/06/30 20:47:42 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/05/25 08:25:28 | 002,214,504 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/05/20 21:35:16 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/04/27 15:45:15 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/04/01 09:31:38 | 002,271,608 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2011/03/21 13:21:24 | 000,632,832 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/01/12 14:41:40 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/10/19 12:01:32 | 000,075,064 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010/09/16 09:06:12 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2010/09/16 08:07:51 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/11/18 12:15:30 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2011/12/10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:
64bit: - [2011/08/17 09:58:26 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys -- (UsbserFilt)
DRV:
64bit: - [2011/08/17 09:58:22 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev)
DRV:
64bit: - [2011/08/17 09:58:20 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc)
DRV:
64bit: - [2011/08/17 09:58:16 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd)
DRV:
64bit: - [2011/06/30 20:47:43 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:
64bit: - [2011/06/30 20:47:43 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:
64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2011/01/11 01:48:22 | 000,015,872 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\EIO64.sys -- (EIO64)
DRV:
64bit: - [2010/12/09 16:04:32 | 000,034,032 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\seehcri.sys -- (seehcri)
DRV:
64bit: - [2010/12/09 16:02:40 | 000,144,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s125mdm.sys -- (s125mdm)
DRV:
64bit: - [2010/12/09 16:02:38 | 000,126,216 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s125mgmt.sys -- (s125mgmt) Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM)
DRV:
64bit: - [2010/12/09 16:02:38 | 000,123,656 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s125obex.sys -- (s125obex)
DRV:
64bit: - [2010/12/09 16:02:38 | 000,108,296 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s125bus.sys -- (s125bus) Sony Ericsson Device 125 driver (WDM)
DRV:
64bit: - [2010/12/09 16:02:38 | 000,019,720 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s125mdfl.sys -- (s125mdfl)
DRV:
64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2010/11/20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2010/11/20 11:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:
64bit: - [2010/09/23 13:54:47 | 000,035,112 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV:
64bit: - [2010/09/22 23:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:
64bit: - [2010/05/10 08:09:36 | 000,617,048 | ---- | M] (TechniSat Digital, S.A.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SkyNET_AMD64.sys -- (SKYNET)
DRV:
64bit: - [2010/04/27 15:57:20 | 000,016,200 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmVirHid.sys -- (WmVirHid)
DRV:
64bit: - [2010/04/27 15:57:12 | 000,026,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmBEnum.sys -- (WmBEnum)
DRV:
64bit: - [2010/04/27 13:03:12 | 000,077,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmXlCore.sys -- (WmXlCore)
DRV:
64bit: - [2010/04/27 13:02:42 | 000,043,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmFilter.sys -- (WmFilter)
DRV:
64bit: - [2009/12/17 23:25:17 | 000,034,472 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:
64bit: - [2009/09/28 08:22:00 | 000,395,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:
64bit: - [2009/09/11 06:47:38 | 000,605,968 | ---- | M] (TechniSat Digital, S.A.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SkyNetBDA_AMD64.sys -- (SkyNetBDA_AMD64) TechniSat DVB-PC TV Star PCI (BDA)
DRV:
64bit: - [2009/08/09 22:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:
64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009/05/01 00:03:06 | 006,377,496 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64) Logitech QuickCam Pro 5000(UVC)
DRV:
64bit: - [2009/05/01 00:01:34 | 000,327,576 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:
64bit: - [2009/04/30 23:59:22 | 000,271,640 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvpopf64.sys -- (lvpopf64)
DRV:
64bit: - [2009/04/30 15:59:48 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon)
DRV:
64bit: - [2009/04/30 15:59:48 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64)
DRV:
64bit: - [2009/04/21 13:12:50 | 001,288,192 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\P17.sys -- (P17)
DRV:
64bit: - [2008/08/28 12:44:42 | 000,025,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV:
64bit: - [2008/07/26 15:26:34 | 000,050,072 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVUSBS64.sys -- (LVUSBS64)
DRV:
64bit: - [2007/11/22 12:06:46 | 001,064,448 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrxusb.sys -- (athrusb)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2006/03/29 07:49:26 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\pfc.sys -- (pfc)
DRV - [2002/07/17 08:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Stopped] -- C:\Windows\SysWOW64\drivers\ASPI32.SYS -- (Aspi32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2701260577-2833626082-2814547817-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]
IE - HKU\S-1-5-21-2701260577-2833626082-2814547817-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 7F C8 7A 7D AB 86 CC 01 [binary data]
IE - HKU\S-1-5-21-2701260577-2833626082-2814547817-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Winamp Search"
FF - prefs.js..browser.search.defaulturl: "
http://slirsredirect.search.aol.com/sli ... ie7&query="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Winamp Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
www.google.com"
FF - prefs.js..extensions.enabledItems: {62760FD6-B943-48C9-AB09-F99C6FE96088}:2.1.4
FF - prefs.js..extensions.enabledItems: {340c2bbc-ce74-4362-90b5-7c26312808ef}:1.5
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.86
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems:
battlefieldheroespatcher@ea.com:5.0.31.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems:
pastebin.com@gmail.com:2.1
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1
FF - prefs.js..keyword.URL: "
http://slirsredirect.search.aol.com/sli ... pab&query="
FF - prefs.js..network.proxy.type: 0
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "
http://search.qip.ru/search?from=FF&query="
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Fester\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Fester\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Fester\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Fester\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Fester\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
bkmrksync@nokia.com: G:\Program Files (x86)\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/09/25 14:19:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/02/17 21:14:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/12/27 10:43:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/01/15 19:48:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/02/17 21:14:46 | 000,000,000 | ---D | M]
[2011/04/14 12:37:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Fester\AppData\Roaming\Mozilla\Extensions
[2011/04/14 12:37:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Fester\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/04/06 14:46:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Fester\AppData\Roaming\Mozilla\Firefox\Profiles\5phhygcy.default\extensions
[2010/10/09 11:32:26 | 000,000,000 | ---D | M] (Firefox Sync) -- C:\Users\Fester\AppData\Roaming\Mozilla\Firefox\Profiles\5phhygcy.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}
[2010/09/30 14:32:48 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\Fester\AppData\Roaming\Mozilla\Firefox\Profiles\5phhygcy.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2010/10/09 11:32:27 | 000,000,000 | ---D | M] (eBay Sidebar for Firefox) -- C:\Users\Fester\AppData\Roaming\Mozilla\Firefox\Profiles\5phhygcy.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}
[2010/10/19 12:26:18 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Fester\AppData\Roaming\Mozilla\Firefox\Profiles\5phhygcy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/10/14 19:13:35 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\Fester\AppData\Roaming\Mozilla\Firefox\Profiles\5phhygcy.default\extensions\
battlefieldheroespatcher@ea.com
[2010/10/19 17:19:34 | 000,000,000 | ---D | M] (Pastebin) -- C:\Users\Fester\AppData\Roaming\Mozilla\Firefox\Profiles\5phhygcy.default\extensions\
pastebin.com@gmail.com
[2012/01/07 11:40:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Fester\AppData\Roaming\Mozilla\Firefox\Profiles\n74pss22.default\extensions
[2011/11/12 22:32:14 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Fester\AppData\Roaming\Mozilla\Firefox\Profiles\n74pss22.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/12/27 10:43:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) -- C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) -- C:\USERS\FESTER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5PHHYGCY.DEFAULT\EXTENSIONS\{0B38152B-1B20-484D-A11F-5E04A9B0661F}
[2011/12/21 09:07:09 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/23 12:20:20 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/03 21:49:21 | 000,076,288 | ---- | M] (Foxit Software Company) -- C:\Program Files (x86)\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2011/12/21 06:25:11 | 000,001,583 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\atlas-sk.xml
[2011/12/21 06:25:11 | 000,001,380 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\azet-sk.xml
[2011/12/21 06:25:11 | 000,001,479 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\dunaj-sk.xml
[2011/12/21 06:25:11 | 000,001,473 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\slovnik-sk.xml
[2010/08/16 15:38:48 | 000,002,181 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\vmndtxtb3.xml
[2011/12/21 06:25:11 | 000,001,104 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-sk.xml
[2011/12/21 06:25:11 | 000,000,830 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\zoznam-sk.xml
O1 HOSTS File: ([2012/01/16 16:50:02 | 000,000,100 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1
www.tune-up.com
O1 - Hosts: 127.0.0.1
www.tune-up.com/order
O1 - Hosts: 127.0.0.1
www.registertuneup.com
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [AllShareAgent] C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-21-2701260577-2833626082-2814547817-1001..\Run: [Infium] G:\QIP\QIP Infium PafoPack 9040\infium.exe ()
O4 - HKU\S-1-5-21-2701260577-2833626082-2814547817-1001..\Run: [iTracker] C:\Program Files (x86)\ASUS\iTracker\iTracker.exe (ASUSTek)
O4 - HKU\S-1-5-21-2701260577-2833626082-2814547817-1001..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2701260577-2833626082-2814547817-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2701260577-2833626082-2814547817-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2701260577-2833626082-2814547817-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2701260577-2833626082-2814547817-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8:
64bit: - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://G:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://G:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 10.1.0)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://ccfiles.creative.com/Web/softwar ... /CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{22AEC24C-2CF8-4F4F-99BD-6DDA379D54C3}: DhcpNameServer = 0.0.0.0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{42425AF2-528A-49C2-A4D4-C982B165DA92}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D94FB4E-82FA-4061-BDD7-8E11A11F1D4C}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B7072825-6698-4A30-A660-F3A730093F15}: DhcpNameServer = 192.168.1.1
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:
64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\Windows\SysWow64\ir32_32.dll (Intel(R) Corporation)
Drivers32: vidc.iv32 - C:\Windows\SysWow64\ir32_32.dll (Intel(R) Corporation)
Drivers32: vidc.iv41 - C:\Windows\SysWow64\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (
www.helixcommunity.org)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2012/01/16 16:53:48 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Fester\Desktop\OTL.exe
[2012/01/14 17:00:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/13 09:04:01 | 000,000,000 | -HSD | C] -- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2012/01/12 20:31:13 | 000,000,000 | ---D | C] -- C:\rsit
[2012/01/12 20:30:47 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2012/01/12 20:30:47 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webio.dll
[2012/01/12 20:30:47 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webio.dll
[2012/01/12 20:30:47 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2012/01/12 20:30:47 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2012/01/12 20:30:47 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2012/01/12 15:09:52 | 001,572,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2012/01/12 15:09:52 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2012/01/12 15:09:52 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2012/01/12 15:09:52 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2012/01/12 15:09:50 | 001,731,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2012/01/12 15:09:48 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll
[2012/01/12 15:09:48 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll
========== Files - Modified Within 7 Days ==========
[2012/01/17 15:48:04 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012/01/17 15:21:01 | 000,000,950 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2701260577-2833626082-2814547817-1001UA.job
[2012/01/17 15:16:35 | 001,609,780 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/17 15:16:35 | 000,669,632 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2012/01/17 15:16:35 | 000,663,484 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/01/17 15:16:35 | 000,144,322 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2012/01/17 15:16:35 | 000,125,420 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/01/17 15:06:05 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/17 15:03:14 | 000,020,000 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/17 15:03:14 | 000,020,000 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/17 14:55:42 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/17 14:55:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/17 00:21:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2701260577-2833626082-2814547817-1001Core.job
[2012/01/16 16:53:39 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Fester\Desktop\OTL.exe
[2012/01/16 16:50:02 | 000,000,100 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/01/15 13:52:43 | 000,043,706 | ---- | M] () -- C:\Users\Fester\Desktop\troy-polamalu-hair-490x325.jpg
[2012/01/14 17:00:18 | 000,001,073 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/14 00:30:58 | 001,579,840 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/01/13 09:09:29 | 000,458,240 | ---- | M] () -- C:\Users\Fester\Desktop\CKScanner.exe
[2012/01/12 22:07:33 | 000,000,981 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
========== Files Created - No Company Name ==========
[2012/01/16 16:59:43 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012/01/15 13:52:40 | 000,043,706 | ---- | C] () -- C:\Users\Fester\Desktop\troy-polamalu-hair-490x325.jpg
[2012/01/14 17:00:18 | 000,001,073 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/13 09:09:35 | 000,458,240 | ---- | C] () -- C:\Users\Fester\Desktop\CKScanner.exe
[2011/07/16 15:37:58 | 000,000,022 | ---- | C] () -- C:\Windows\SysWow64\config.ini
[2011/07/13 19:47:56 | 000,000,000 | ---- | C] () -- C:\Users\Fester\AppData\Local\{6BE02757-0BFD-4633-A96A-85852C478669}
[2011/06/02 11:47:30 | 000,000,600 | ---- | C] () -- C:\Users\Fester\AppData\Roaming\winscp.rnd
[2011/05/20 21:35:28 | 000,304,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/05/11 19:20:16 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011/05/11 19:20:15 | 000,631,808 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011/05/11 19:20:15 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011/05/11 19:20:14 | 000,080,896 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/05/05 21:07:13 | 000,000,000 | ---- | C] () -- C:\Users\Fester\AppData\Local\{C8170AA0-C8C5-41B6-A270-280D17FE8972}
[2011/05/05 20:42:57 | 000,000,000 | ---- | C] () -- C:\Users\Fester\AppData\Local\{F9F2B95C-BDF0-49C5-83E4-65DB5BE38805}
[2011/05/04 21:10:46 | 000,000,000 | ---- | C] () -- C:\Windows\graphedit.INI
[2011/05/03 21:06:42 | 000,000,000 | ---- | C] () -- C:\Windows\graphedt.INI
[2011/05/02 15:53:26 | 000,000,130 | ---- | C] () -- C:\Windows\EurekaLog.ini
[2011/04/27 10:21:38 | 003,268,096 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
[2011/04/09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/04/06 11:45:59 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/03/03 21:35:53 | 000,000,093 | ---- | C] () -- C:\Windows\NoClose.ini
[2011/01/09 22:24:09 | 000,056,899 | ---- | C] () -- C:\Windows\SysWow64\x264-uninstall.exe
[2010/12/14 08:43:05 | 000,000,057 | ---- | C] () -- C:\Windows\rocksoft.ini
[2010/12/07 22:04:08 | 000,000,000 | ---- | C] () -- C:\Windows\PowerReg.dat
[2010/12/02 14:11:57 | 000,007,603 | ---- | C] () -- C:\Users\Fester\AppData\Local\Resmon.ResmonCfg
[2010/11/29 10:01:58 | 000,009,728 | ---- | C] () -- C:\Users\Fester\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/27 12:08:51 | 000,000,000 | ---- | C] () -- C:\Windows\graphedt_x64.INI
[2010/11/27 00:28:30 | 000,001,008 | ---- | C] () -- C:\Users\Fester\AppData\Local\SRDownloader.nast
[2010/11/14 17:57:49 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2010/11/02 00:47:46 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll
[2010/10/22 18:52:14 | 000,000,133 | ---- | C] () -- C:\Windows\VobEdit.INI
[2010/10/22 11:08:16 | 000,000,000 | ---- | C] () -- C:\Windows\acehtml6.ini
[2010/10/19 12:02:03 | 000,215,016 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010/10/19 12:01:32 | 000,075,064 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010/10/12 18:44:54 | 000,000,600 | ---- | C] () -- C:\Users\Fester\AppData\Local\PUTTY.RND
[2010/10/11 14:43:17 | 001,579,840 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/10 15:45:52 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010/10/09 11:36:17 | 000,000,271 | ---- | C] () -- C:\Windows\maketorrent.ini
[2010/10/08 12:11:56 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010/10/07 05:14:55 | 000,003,328 | ---- | C] () -- C:\Windows\SysWow64\secustat.dat
[2010/09/16 08:07:15 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2010/09/16 08:07:15 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2010/09/16 07:52:40 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI
[2009/07/14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/03/28 11:55:22 | 001,571,817 | ---- | C] () -- C:\Windows\SysWow64\libeay32.dll
[2008/11/13 13:07:24 | 000,002,177 | ---- | C] () -- C:\Windows\P17EP.ini
[2008/06/29 19:48:48 | 000,311,128 | ---- | C] () -- C:\Windows\SysWow64\libssl32.dll
[2008/06/05 10:02:36 | 000,061,440 | ---- | C] () -- C:\Windows\SysWow64\ASIT.exe
[2000/01/01 01:00:00 | 000,000,023 | RHS- | C] () -- C:\Windows\mtlid64s2.dat
========== LOP Check ==========
[2011/04/13 20:23:11 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\.purple
[2010/11/02 01:08:45 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Aegisub
[2011/04/13 16:47:58 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Ashampoo
[2011/02/22 14:47:41 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Autodesk
[2010/10/15 16:39:02 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\BITS
[2011/04/13 14:51:10 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Canneverbe Limited
[2010/12/11 11:25:30 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Canon
[2011/06/11 11:24:06 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/03/29 16:41:40 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\com.caffeinatedmind.Sendoid
[2010/09/17 06:44:56 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\com.prakaz.project.photogettr.FBAB9E68ED32BC183252F597C39DBF71CF315A79.1
[2010/09/16 11:37:32 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\e
[2010/09/16 07:52:35 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\FlashGet
[2010/09/16 07:52:32 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\FlashGetBHO
[2010/12/23 10:30:22 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\fltk.org
[2011/05/10 22:17:29 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Foxit Software
[2011/04/13 17:24:39 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Gajim
[2011/03/03 21:23:56 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\GHISLER
[2011/04/13 17:46:37 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\gtk-2.0
[2011/01/09 16:23:02 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\HDRsoft
[2010/10/31 00:19:55 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Imagenomic
[2010/12/22 16:08:29 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Kenny Kerr
[2010/10/18 22:04:28 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\LolClient
[2010/10/15 12:05:01 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Mirillis
[2010/10/08 13:03:07 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\mkvtoolnix
[2011/11/27 23:03:18 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\MOBILedit
[2011/06/10 20:12:59 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\mojosoft
[2011/11/27 23:23:33 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\MyPhoneExplorer
[2010/11/02 11:40:25 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Nik Software
[2011/11/15 21:33:12 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Nokia
[2011/02/17 21:43:45 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Nokia Ovi Suite
[2010/10/15 12:15:02 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Notepad++
[2011/03/30 20:06:33 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\OpenCandy
[2011/11/27 23:07:00 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\PC Suite
[2011/03/20 21:45:36 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\PDF Writer
[2010/09/23 12:40:03 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\PPLive
[2010/10/17 21:04:24 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Promixis
[2011/11/13 11:54:50 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Publish Providers
[2010/10/05 08:05:18 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\QIP
[2011/04/13 20:01:20 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\qutim
[2011/04/13 20:01:35 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\qxdg
[2010/10/17 10:16:13 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\RGSystemFonts
[2010/12/14 09:17:16 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Rockwell Software
[2011/10/15 12:43:55 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Samsung
[2011/11/13 11:54:46 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Sony
[2010/11/07 09:39:14 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Sparx Systems
[2010/11/22 11:38:13 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/07/10 12:07:44 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\StepMania 5
[2010/09/28 17:23:27 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Stereoscopic Player
[2011/02/26 09:45:37 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\TeamViewer
[2011/04/14 12:37:03 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Thunderbird
[2011/02/24 19:48:44 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Toad Data Modeler Freeware
[2010/11/09 18:07:16 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Trillian
[2012/01/13 09:05:51 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\TuneUp Software
[2012/01/17 15:50:44 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\uTorrent
[2011/03/03 22:14:42 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\VisualAssist
[2010/10/05 19:18:19 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\VitySoft
[2010/10/21 20:32:16 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\vmndtxtb
[2010/11/14 20:11:10 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Windows Live Writer
[2011/03/25 15:07:31 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Youtube Downloader HD
[2010/12/30 22:45:57 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Zoner
[2011/12/27 10:37:45 | 000,032,560 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< netsvc >
< MD5 for: ATAPI.SYS >
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\ERDNT\cache64\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010/11/20 14:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010/11/20 14:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2009/07/14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009/07/14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
[2010/11/20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010/11/20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2009/07/14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys
[2010/11/20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010/11/20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010/11/20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2011/02/26 07:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 07:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\ERDNT\cache86\explorer.exe
[2009/10/31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 14:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 07:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 07:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
< MD5 for: HAL.DLL >
[2009/07/14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_071de44b735b3dfc\hal.dll
[2010/11/20 14:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010/11/20 14:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
< MD5 for: SCECLI.DLL >
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\ERDNT\cache86\scecli.dll
[2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\ERDNT\cache64\scecli.dll
[2009/07/14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010/11/20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010/11/20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010/11/20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: SVCHOST.EXE >
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\ERDNT\cache86\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2011/12/24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\ERDNT\cache64\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2011/04/25 06:28:24 | 001,893,248 | ---- | M] (Microsoft Corporation) MD5=1F748D5439B65E0BEBD92F65048F030D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20951_none_0fb918de99201ffb\tcpip.sys
[2011/09/29 18:41:37 | 001,912,176 | ---- | M] (Microsoft Corporation) MD5=3810F06A4D74A7D62641EE73D6B3C660 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_11c6e9949627e69c\tcpip.sys
[2010/11/20 14:33:57 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2011/06/21 07:16:55 | 001,888,128 | ---- | M] (Microsoft Corporation) MD5=5279D4DD69C7C71524B8E7A5746D15CC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20992_none_0f8ed978993fa916\tcpip.sys
[2010/06/14 07:39:16 | 001,889,152 | ---- | M] (Microsoft Corporation) MD5=542C6767C68C9D6AAACA59436B0D15C2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20733_none_0fd0b57e990e2079\tcpip.sys
[2011/04/25 06:32:22 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=61DC720BB065D607D5823F13D2A64321 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16802_none_0f668bf97fd90dd3\tcpip.sys
[2010/06/14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\ERDNT\cache64\tcpip.sys
[2010/06/14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16610_none_0f59b7ad7fe2fcc8\tcpip.sys
[2009/07/14 02:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
[2011/04/25 06:33:51 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
[2011/06/21 07:20:30 | 001,914,752 | ---- | M] (Microsoft Corporation) MD5=A0EB71E0DC047C7CC95CD6AB4036296E -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21754_none_11a276c29643d7ec\tcpip.sys
[2011/09/29 17:17:51 | 001,886,064 | ---- | M] (Microsoft Corporation) MD5=AC3E29880DB5659532A1AA3439304A43 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21060_none_0fad20ca992955d7\tcpip.sys
[2011/04/25 07:16:34 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
[2011/06/21 07:27:14 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=B9D87C7707F058AC652A398CD28DE14B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16839_none_0f4d1e3b7feb1307\tcpip.sys
[2011/06/21 07:34:00 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=F0E98C00A09FDF791525829A1D14240F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17638_none_11327af77d12659c\tcpip.sys
[2011/09/29 17:24:44 | 001,897,328 | ---- | M] (Microsoft Corporation) MD5=F18F56EFC0BFB9C87BA01C37B27F4DA5 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16889_none_0f170e9f80139ebc\tcpip.sys
[2011/09/29 17:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\SysNative\drivers\tcpip.sys
[2011/09/29 17:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_10f09b257d43f3eb\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010/11/20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\ERDNT\cache86\userinit.exe
[2009/07/14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\ERDNT\cache64\userinit.exe
[2009/07/14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010/11/20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010/11/20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010/11/20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2011/12/24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\ERDNT\cache64\winlogon.exe
[2009/10/28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< %systemroot%*.* /U /s >
[3 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[7 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[112 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2011/04/13 20:23:11 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\.purple
[2011/07/24 00:21:42 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Adobe
[2010/11/02 01:08:45 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Aegisub
[2011/11/01 08:12:13 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Ahead
[2010/12/25 15:04:16 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Apple Computer
[2011/05/11 14:32:45 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\ArcSoft
[2011/04/13 16:47:58 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Ashampoo
[2011/02/22 14:47:41 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Autodesk
[2010/09/15 22:47:04 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Avira
[2010/10/15 16:39:02 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\BITS
[2011/04/13 14:51:10 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Canneverbe Limited
[2010/12/11 11:25:30 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Canon
[2011/06/11 11:24:06 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/03/29 16:41:40 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\com.caffeinatedmind.Sendoid
[2010/09/17 06:44:56 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\com.prakaz.project.photogettr.FBAB9E68ED32BC183252F597C39DBF71CF315A79.1
[2010/09/16 11:26:00 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Creative
[2011/05/05 13:35:08 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\CyberLink
[2010/09/23 21:31:40 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\DivX
[2011/01/11 01:43:07 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Download Manager
[2010/09/16 11:37:32 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\e
[2010/09/16 07:52:35 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\FlashGet
[2010/09/16 07:52:32 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\FlashGetBHO
[2010/12/23 10:30:22 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\fltk.org
[2011/05/10 22:17:29 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Foxit Software
[2011/04/13 17:24:39 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Gajim
[2011/03/03 21:23:56 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\GHISLER
[2011/04/13 17:46:37 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\gtk-2.0
[2011/01/09 16:23:02 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\HDRsoft
[2010/09/15 20:45:01 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Identities
[2010/10/31 00:19:55 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Imagenomic
[2010/12/22 16:08:29 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Kenny Kerr
[2010/10/18 22:04:28 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\LolClient
[2010/09/15 23:02:32 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Macromedia
[2012/01/14 18:14:22 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Malwarebytes
[2009/07/14 16:36:58 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Media Center Programs
[2011/07/29 20:18:53 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Media Player Classic
[2011/07/27 21:40:13 | 000,000,000 | --SD | M] -- C:\Users\Fester\AppData\Roaming\Microsoft
[2010/11/21 22:56:41 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Microsoft Corporation
[2010/10/15 12:05:01 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Mirillis
[2010/10/08 13:03:07 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\mkvtoolnix
[2011/11/27 23:03:18 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\MOBILedit
[2011/06/10 20:12:59 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\mojosoft
[2011/04/06 11:46:03 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Mozilla
[2011/11/27 23:23:33 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\MyPhoneExplorer
[2010/09/17 06:40:49 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Nero
[2010/11/02 11:40:25 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Nik Software
[2011/11/15 21:33:12 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Nokia
[2011/02/17 21:43:45 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Nokia Ovi Suite
[2010/10/15 12:15:02 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Notepad++
[2010/09/24 07:23:22 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\NVIDIA
[2010/09/28 17:08:36 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\NVIDIA 3D Vision Video Player
[2011/03/30 20:06:33 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\OpenCandy
[2011/11/27 23:07:00 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\PC Suite
[2011/03/20 21:45:36 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\PDF Writer
[2010/09/23 12:40:03 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\PPLive
[2010/10/17 21:04:24 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Promixis
[2011/11/13 11:54:50 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Publish Providers
[2010/10/05 08:05:18 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\QIP
[2011/04/13 20:01:20 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\qutim
[2011/04/13 20:01:35 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\qxdg
[2011/05/07 09:35:49 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Real
[2010/10/17 10:16:13 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\RGSystemFonts
[2010/12/14 09:17:16 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Rockwell Software
[2011/10/15 12:43:55 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Samsung
[2011/11/13 13:24:44 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Skype
[2011/08/29 15:49:01 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\skypePM
[2011/11/13 11:54:46 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Sony
[2010/11/07 09:39:14 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Sparx Systems
[2010/11/22 11:38:13 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/07/10 12:07:44 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\StepMania 5
[2010/09/28 17:23:27 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Stereoscopic Player
[2011/02/26 09:45:37 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\TeamViewer
[2011/04/14 12:37:03 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Thunderbird
[2011/02/24 19:48:44 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Toad Data Modeler Freeware
[2010/11/09 18:07:16 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Trillian
[2012/01/13 09:05:51 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\TuneUp Software
[2012/01/17 16:08:25 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\uTorrent
[2011/03/03 22:14:42 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\VisualAssist
[2010/10/05 19:18:19 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\VitySoft
[2010/10/21 20:32:16 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\vmndtxtb
[2011/07/24 00:36:27 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Winamp
[2010/11/14 20:11:10 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Windows Live Writer
[2010/09/16 09:50:22 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\WinRAR
[2011/03/25 15:07:31 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Youtube Downloader HD
[2010/12/30 22:45:57 | 000,000,000 | ---D | M] -- C:\Users\Fester\AppData\Roaming\Zoner