OTL logfile created on: 4.4.2014 20:16:21 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Martinka\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000041B | Country: Slovensko | Language: SKY | Date Format: d.M.yyyy
1013,88 Mb Total Physical Memory | 266,61 Mb Available Physical Memory | 26,30% Memory free
2,38 Gb Paging File | 1,57 Gb Available in Paging File | 65,99% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142,05 Gb Total Space | 47,86 Gb Free Space | 33,70% Space Free | Partition Type: NTFS
Computer Name: ACER-9B8A28C521 | User Name: Martinka | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014.04.04 20:14:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Martinka\Desktop\OTL.exe
PRC - [2014.03.15 02:50:42 | 000,859,976 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2014.02.25 12:07:57 | 000,440,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2014.02.25 12:07:44 | 000,689,744 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2014.02.25 12:07:44 | 000,440,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2013.12.18 22:05:43 | 000,182,696 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2013.12.18 16:27:35 | 000,431,672 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2013.07.08 10:42:48 | 001,922,600 | ---- | M] (Pandora.TV) -- C:\Program Files\PANDORA.TV\PanService\KMPService.exe
PRC - [2013.07.08 10:42:38 | 001,798,696 | ---- | M] (PandoraTV) -- C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe
PRC - [2011.05.31 16:27:00 | 000,047,704 | ---- | M] (Alcor) -- C:\WINDOWS\WebCam\S6000\S6000Mnt.exe
PRC - [2009.02.11 16:46:28 | 000,565,248 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer VCM\AcerVCM.exe
PRC - [2009.02.05 09:14:56 | 000,237,568 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer VCM\RS_Service.exe
PRC - [2008.12.30 09:09:54 | 000,875,016 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\LManager.exe
PRC - [2008.10.14 11:15:08 | 000,032,768 | ---- | M] () -- C:\WINDOWS\WebCam\M3000\M3000Mnt.exe
PRC - [2008.04.15 18:54:42 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008.04.15 18:54:40 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008.04.14 14:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.11.01 16:55:30 | 000,576,104 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2007.06.20 23:04:52 | 000,046,432 | ---- | M] (Microsoft® Corporation) -- C:\Program Files\Microsoft Works\WkCalRem.exe
PRC - [2003.07.25 02:40:06 | 000,335,872 | ---- | M] (Globe Software) -- C:\Program Files\Globe Software\StatBar\StatBar.exe
========== Modules (No Company Name) ==========
MOD - [2014.03.15 02:50:40 | 000,394,568 | ---- | M] () -- C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\Application\33.0.1750.154\ppgooglenaclpluginchrome.dll
MOD - [2014.03.15 02:50:38 | 004,061,000 | ---- | M] () -- C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\Application\33.0.1750.154\pdf.dll
MOD - [2014.03.15 02:50:32 | 001,647,432 | ---- | M] () -- C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\Application\33.0.1750.154\ffmpegsumo.dll
MOD - [2014.03.15 02:50:30 | 000,051,016 | ---- | M] () -- C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\Application\33.0.1750.154\chrome_elf.dll
MOD - [2013.08.06 00:55:39 | 000,394,824 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2012.10.22 11:21:42 | 001,277,952 | ---- | M] () -- C:\Program Files\PANDORA.TV\PanService\avformat-53.dll
MOD - [2012.07.09 17:57:30 | 002,090,496 | ---- | M] () -- C:\Program Files\PANDORA.TV\PanService\avcodec-53.dll
MOD - [2012.03.23 10:07:34 | 000,224,768 | ---- | M] () -- C:\Program Files\PANDORA.TV\PanService\libupnp.dll
MOD - [2011.12.06 16:19:48 | 000,133,632 | ---- | M] () -- C:\Program Files\PANDORA.TV\PanService\avutil-51.dll
MOD - [2009.01.02 19:07:40 | 000,331,776 | ---- | M] () -- C:\WINDOWS\system\M3000Dex.dll
MOD - [2008.10.14 11:15:08 | 000,032,768 | ---- | M] () -- C:\WINDOWS\WebCam\M3000\M3000Mnt.exe
MOD - [2008.04.14 14:00:00 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2008.04.14 14:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2007.11.01 16:53:34 | 002,842,624 | ---- | M] () -- C:\WINDOWS\system32\btwicons.dll
MOD - [2007.11.01 16:51:36 | 000,040,960 | ---- | M] () -- C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll
MOD - [2003.06.07 07:30:08 | 000,057,344 | ---- | M] () -- C:\Program Files\Launch Manager\PowerUtl.dll
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2014.03.12 19:38:41 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014.02.25 12:07:57 | 000,440,400 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2014.02.25 12:07:50 | 001,017,424 | ---- | M] (Avira Operations GmbH & Co. KG) [Disabled | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService)
SRV - [2014.02.25 12:07:44 | 000,440,400 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2014.02.24 20:13:27 | 000,118,896 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.12.18 22:05:43 | 000,182,696 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2013.10.23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.07.08 10:42:48 | 001,922,600 | ---- | M] (Pandora.TV) [Auto | Running] -- C:\Program Files\PANDORA.TV\PanService\KMPService.exe -- (PanService)
SRV - [2011.06.29 15:59:18 | 000,155,344 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe -- (Sony Ericsson PCCompanion)
SRV - [2010.01.26 12:41:08 | 000,652,800 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009.02.05 09:14:56 | 000,237,568 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer VCM\RS_Service.exe -- (RS_Service)
SRV - [2008.04.15 18:54:42 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Rts5161ccid.sys -- (USBCCID)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Rts516xIR.sys -- (Rts516xIR)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] -- c:\acernb\int15.sys -- (int15.sys)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a1icrfas)
DRV - [2013.12.18 16:28:17 | 000,135,648 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2013.12.18 16:28:17 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2013.11.25 13:49:38 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2013.08.06 00:56:01 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2012.02.24 15:39:56 | 003,361,408 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\S6000KNT.sys -- (S6000KNT)
DRV - [2010.03.12 23:07:10 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2009.11.19 14:06:48 | 000,098,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s1039bus.sys -- (s1039bus)
DRV - [2009.11.19 14:06:48 | 000,025,456 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s1039nd5.sys -- (s1039nd5)
DRV - [2009.11.19 14:06:46 | 000,124,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s1039mdm.sys -- (s1039mdm)
DRV - [2009.11.19 14:06:46 | 000,123,504 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s1039unic.sys -- (s1039unic)
DRV - [2009.11.19 14:06:46 | 000,117,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s1039mgmt.sys -- (s1039mgmt)
DRV - [2009.11.19 14:06:46 | 000,113,904 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s1039obex.sys -- (s1039obex)
DRV - [2009.11.19 14:06:46 | 000,014,960 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s1039mdfl.sys -- (s1039mdfl)
DRV - [2009.04.06 09:13:52 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2009.04.06 09:13:52 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ggflt.sys -- (ggflt)
DRV - [2009.03.02 07:03:46 | 000,038,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1c51x86.sys -- (L1c)
DRV - [2009.02.25 20:17:52 | 001,344,224 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\athw.sys -- (AR5416)
DRV - [2009.02.24 10:49:44 | 005,032,448 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2009.02.03 08:42:30 | 000,162,816 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009.01.02 18:33:54 | 000,145,408 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\M3000KNT.sys -- (M3000Srv)
DRV - [2008.08.26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.08.05 14:10:12 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2007.11.05 10:54:00 | 000,879,528 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2007.11.05 10:53:58 | 000,539,576 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2007.08.27 06:58:18 | 000,074,656 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2007.06.29 05:38:30 | 000,156,392 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2007.03.31 06:02:40 | 000,055,352 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid)
DRV - [2007.03.23 03:50:08 | 000,037,424 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2006.11.02 15:27:36 | 000,020,112 | ---- | M] (Dritek System Inc.) [Kernel | System | Running] -- C:\Program Files\Launch Manager\DPortIO.sys -- (DritekPortIO)
DRV - [2006.01.04 09:41:48 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.acer.com/rdr.aspx?b=ACA ... aspire_one
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = about:newtab
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:newtab
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar =
http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page =
http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = about:newtab
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = about:newtab
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://search.certified-toolbar.com?si= ... earchTerms}
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = about:newtab
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:newtab
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar =
http://search.certified-toolbar.com?si= ... =chrome&q=
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page =
http://search.certified-toolbar.com?si= ... =chrome&q=
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = about:newtab
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = about:newtab
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKU\.DEFAULT\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://search.certified-toolbar.com?si= ... earchTerms}
IE - HKU\.DEFAULT\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.certified-toolbar.com?si= ... earchTerms}
IE - HKU\.DEFAULT\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" =
http://search.sweetim.com/search.asp?sr ... earchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = about:newtab
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:newtab
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar =
http://search.certified-toolbar.com?si= ... =chrome&q=
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page =
http://search.certified-toolbar.com?si= ... =chrome&q=
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = about:newtab
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = about:newtab
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKU\S-1-5-18\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://search.certified-toolbar.com?si= ... earchTerms}
IE - HKU\S-1-5-18\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.certified-toolbar.com?si= ... earchTerms}
IE - HKU\S-1-5-18\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" =
http://search.sweetim.com/search.asp?sr ... earchTerms}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL =
http://www.google.com
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar =
http://www.google.com
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page =
http://www.google.com
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL =
http://www.google.com
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page =
http://www.google.com
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={ ... orm=IE8SRC
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\..\SearchScopes\{334124D7-FE32-4999-8DAC-7594D4253552}: "URL" =
http://www.cas.sk/vyhladavanie/?q={sear ... 020666e51a
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\..\SearchScopes\{59383B96-E70C-4A31-99B4-8DE0B7D8626A}: "URL" =
http://search.yahoo.com/search?fr=chr-g ... earchTerms}
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://www.google.com/search?sourceid=i ... SK341SK341
IE - HKU\S-1-5-21-963918322-3784137826-972506294-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: false
FF - prefs.js..browser.startup.homepage: "
http://www.google.sk/"
FF - prefs.js..extensions.enabledAddons: %7B800b5000-a755-47e1-992b-48a1c1357f07%7D:1.5.3
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.15
FF - prefs.js..extensions.enabledAddons: %7B0545b830-f0aa-4d7e-8820-50a4629a56fe%7D:22.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Martinka\Application Data\Facebook\npfbplugin_1_0_3.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014.02.24 20:13:09 | 000,000,000 | ---D | M]
[2010.09.17 22:05:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Martinka\Application Data\Mozilla\Extensions
[2014.03.30 13:32:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Martinka\Application Data\Mozilla\Firefox\Profiles\0ek1zvuf.default\extensions
[2014.03.04 22:01:30 | 000,000,000 | ---D | M] ("ColorfulTabs") -- C:\Documents and Settings\Martinka\Application Data\Mozilla\Firefox\Profiles\0ek1zvuf.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2014.03.30 01:04:40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Martinka\Application Data\Mozilla\Firefox\Profiles\0ek1zvuf.default\extensions\staged
[2014.03.30 01:04:40 | 000,490,466 | ---- | M] () (No name found) -- C:\Documents and Settings\Martinka\Application Data\Mozilla\Firefox\Profiles\0ek1zvuf.default\extensions\
jid1-vW9nopuIAJiRHw@jetpack.xpi
[2014.02.24 20:12:54 | 000,287,566 | ---- | M] () (No name found) -- C:\Documents and Settings\Martinka\Application Data\Mozilla\Firefox\Profiles\0ek1zvuf.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2012.08.17 13:45:12 | 000,002,342 | ---- | M] () -- C:\Documents and Settings\Martinka\Application Data\Mozilla\Firefox\Profiles\0ek1zvuf.default\searchplugins\icq-search.xml
[2014.02.24 20:13:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014.02.24 20:13:29 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MARTINKA\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\0EK1ZVUF.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
========== Chrome ==========
CHR - default_search_provider: Web Search (Enabled)
CHR - default_search_provider: search_url =
http://search.certified-toolbar.com?si= ... earchTerms}
CHR - default_search_provider: suggest_url = ,
CHR - homepage:
http://www.google.sk/
CHR - plugin: Error reading preferences file
CHR - Extension: Disk Google = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: SocialReviver = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bfipfkeoidmndggnnpobeenlamiclald\4.4_0\
CHR - Extension: YouTube = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: HÄľadaĹĄ v Google = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1\
CHR - Extension: Black carbon + silver metal = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lodhggoaglindpoejnjldimdlikkphph\3_0\
CHR - Extension: PeĹaĹľenka Google = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\
CHR - Extension: Gmail = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Disk Google = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: SocialReviver = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bfipfkeoidmndggnnpobeenlamiclald\4.4_0\
CHR - Extension: YouTube = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: HÄľadaĹĄ v Google = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1\
CHR - Extension: Black carbon + silver metal = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lodhggoaglindpoejnjldimdlikkphph\3_0\
CHR - Extension: PeĹaĹľenka Google = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\
CHR - Extension: Gmail = C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012.04.13 23:57:31 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\S-1-5-21-963918322-3784137826-972506294-1005\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [M3000Mnt] Rundll32.exe M3000Rmv.dll ,WinMainRmv /StartStillMnt File not found
O4 - HKLM..\Run: [S6000Mnt] Rundll32.exe S6000Rmv.dll ,WinMainRmv /StartStillMnt File not found
O4 - HKU\S-1-5-21-963918322-3784137826-972506294-1005..\Run: [StatBar] C:\Program Files\Globe Software\StatBar\StatBar.exe (Globe Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer VCM.lnk = C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\Martinka\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Martinka\Start Menu\Programs\Startup\wkcalrem.LNK = C:\Program Files\Microsoft Works\WkCalRem.exe (Microsoft® Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-963918322-3784137826-972506294-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 10.51.2)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 10.51.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/pub/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CC67FEA2-B6E4-43BD-806B-DD16C00DDD2B}: DhcpNameServer = 192.168.2.1 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/html - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Martinka\Application Data\Microsoft\Windows Live Photo Gallery\Windows Live Fotogaléria – tapeta.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Martinka\Application Data\Microsoft\Windows Live Photo Gallery\Windows Live Fotogaléria – tapeta.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.03.16 17:35:15 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{22d1f52c-8b35-11de-9053-002556577709}\Shell - "" = AutoRun
O33 - MountPoints2\{22d1f52c-8b35-11de-9053-002556577709}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{41b75e05-c899-11de-90be-00235ae44841}\Shell\AutoRun\command - "" = system32/rundll.exe
O33 - MountPoints2\{41b75e05-c899-11de-90be-00235ae44841}\Shell\explore\command - "" = system32/rundll.exe
O33 - MountPoints2\{41b75e05-c899-11de-90be-00235ae44841}\Shell\open\command - "" = system32/rundll.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
System Restore Service not available.
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2014.04.04 20:13:55 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Martinka\Desktop\OTL.exe
[2014.03.30 15:16:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martinka\Desktop\RK_Quarantine
[2014.03.30 15:13:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martinka\Desktop\CrystalDiskInfo5_0_0
[2014.03.30 13:26:57 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014.03.29 21:32:04 | 017,523,384 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Martinka\Desktop\mbam-setup-2.0.0.1000.exe
[2014.03.29 14:45:45 | 000,000,000 | ---D | C] -- C:\rsit
[2014.03.19 22:26:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Bcgsoft
[2014.03.19 22:25:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Picture Collage Maker Pro
[2014.03.19 22:25:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\PearlMountain
[2014.03.19 22:25:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PearlMountain
[2014.03.19 22:25:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martinka\Application Data\PearlMountain
[2014.03.19 22:24:59 | 000,000,000 | ---D | C] -- C:\Program Files\Picture Collage Maker Pro
[2014.03.19 22:04:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martinka\My Documents\FotoMix Data
[2014.03.19 21:19:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Martinka\My Documents\Updater
[2014.03.19 01:03:41 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Martinka\Recent
[2014.03.12 17:04:55 | 000,000,000 | R-SD | C] -- C:\Documents and Settings\Martinka\My Documents\My Stationery
[2014.03.10 17:46:06 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xp_eos.exe
[2014.03.10 17:46:06 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xp_eos.exe
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014.04.04 20:27:28 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2014.04.04 20:14:26 | 000,477,494 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2014.04.04 20:14:26 | 000,077,858 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2014.04.04 20:14:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Martinka\Desktop\OTL.exe
[2014.04.04 20:09:02 | 000,000,924 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014.04.04 20:08:35 | 000,000,228 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Logon.job
[2014.04.04 20:08:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014.04.04 20:08:23 | 1063,198,720 | -HS- | M] () -- C:\hiberfil.sys
[2014.04.03 23:43:00 | 000,000,928 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014.04.03 23:38:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014.04.03 22:49:00 | 000,001,028 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-963918322-3784137826-972506294-1005UA.job
[2014.04.03 21:09:27 | 000,140,288 | ---- | M] () -- C:\Documents and Settings\Martinka\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014.04.03 21:01:43 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2014.03.31 19:00:00 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RMSchedule.job
[2014.03.30 15:15:13 | 003,972,608 | ---- | M] () -- C:\Documents and Settings\Martinka\Desktop\RogueKiller.exe
[2014.03.30 15:12:39 | 001,496,172 | ---- | M] () -- C:\Documents and Settings\Martinka\Desktop\CrystalDiskInfo5_0_0.zip
[2014.03.30 13:49:02 | 000,000,976 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-963918322-3784137826-972506294-1005Core.job
[2014.03.30 13:26:22 | 001,950,720 | ---- | M] () -- C:\Documents and Settings\Martinka\Desktop\adwcleaner.exe
[2014.03.29 21:32:12 | 017,523,384 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Martinka\Desktop\mbam-setup-2.0.0.1000.exe
[2014.03.29 14:39:38 | 000,781,383 | ---- | M] () -- C:\Documents and Settings\Martinka\Desktop\RSIT.exe
[2014.03.16 15:32:57 | 000,002,485 | ---- | M] () -- C:\Documents and Settings\Martinka\Desktop\Microsoft Office OneNote 2007.lnk
[2014.03.15 22:56:51 | 000,002,343 | ---- | M] () -- C:\Documents and Settings\Martinka\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2014.03.15 22:56:50 | 000,002,325 | ---- | M] () -- C:\Documents and Settings\Martinka\Desktop\Google Chrome.lnk
[2014.03.14 19:19:54 | 000,344,216 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2014.03.12 19:38:41 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2014.03.12 19:38:40 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2014.03.11 18:28:21 | 000,000,222 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Monthly.job
[2014.03.11 09:22:14 | 000,002,563 | ---- | M] () -- C:\Documents and Settings\Martinka\Desktop\Microsoft Office Word 2007.lnk
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014.04.04 20:27:28 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2014.03.30 15:15:11 | 003,972,608 | ---- | C] () -- C:\Documents and Settings\Martinka\Desktop\RogueKiller.exe
[2014.03.30 15:12:33 | 001,496,172 | ---- | C] () -- C:\Documents and Settings\Martinka\Desktop\CrystalDiskInfo5_0_0.zip
[2014.03.30 13:26:19 | 001,950,720 | ---- | C] () -- C:\Documents and Settings\Martinka\Desktop\adwcleaner.exe
[2014.03.29 14:39:37 | 000,781,383 | ---- | C] () -- C:\Documents and Settings\Martinka\Desktop\RSIT.exe
[2014.03.11 09:01:14 | 000,000,228 | ---- | C] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Logon.job
[2014.03.11 09:01:13 | 000,000,222 | ---- | C] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Monthly.job
[2014.01.16 22:50:02 | 000,015,190 | ---- | C] () -- C:\WINDOWS\S6000Twn.ini
[2014.01.16 22:50:01 | 000,076,376 | ---- | C] () -- C:\WINDOWS\System32\S6000DIF.dll
[2013.01.29 19:51:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Martinka\CUSTOM.DICCUSTOM.DIC
[2010.09.03 00:16:03 | 000,000,063 | ---- | C] () -- C:\Documents and Settings\Martinka\Local Settings\Application Data\phone_update_wizard.ini
[2010.03.27 00:04:38 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Martinka\Application Data\winscp.rnd
[2009.09.09 21:59:25 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\Martinka\Application Data\wklnhst.dat
[2009.08.17 17:13:46 | 000,140,288 | ---- | C] () -- C:\Documents and Settings\Martinka\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2009.03.16 17:39:19 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 14:00:00 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 14:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 14:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2014.01.16 22:46:25 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010.03.12 23:06:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2013.04.03 20:35:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eSobi
[2014.03.30 13:31:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2013.08.18 01:47:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OviInstallerCache
[2013.08.19 11:58:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2014.03.19 22:25:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PearlMountain
[2009.08.19 21:43:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2013.02.06 15:58:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2014.01.16 22:48:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2009.10.10 16:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2014.01.16 22:46:25 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
[2009.03.16 19:07:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\Acer
[2009.03.16 18:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\Acer GameZone Console
[2009.03.16 19:03:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\Super-Cow
[2009.08.17 15:32:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\SACore
[2010.03.31 00:03:39 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Martinka\Application Data\.#
[2009.03.16 19:07:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Acer
[2009.03.16 18:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Acer GameZone Console
[2012.10.13 01:49:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\COWON
[2012.04.06 15:16:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\DAEMON Tools Lite
[2012.04.06 15:16:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\DAEMON Tools Pro
[2012.04.14 17:35:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\ElevatedDiagnostics
[2009.08.17 15:37:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\eSobi
[2013.10.02 22:33:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\eTeks
[2014.02.25 20:16:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\ICQ
[2010.03.24 17:08:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\LimeWire
[2013.08.19 21:36:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Nokia
[2013.08.19 11:58:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\PC Suite
[2014.03.19 22:25:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\PearlMountain
[2014.01.16 22:39:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\rmi
[2009.08.18 01:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\SulusGames
[2009.08.18 15:31:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Super-Cow
[2009.09.09 21:59:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Template
[2011.06.17 00:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\TS3Client
[2014.01.16 22:47:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\TuneUp Software
[2010.03.27 23:10:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Zoner
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009.03.16 17:38:08 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2009.03.17 02:18:27 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2012.06.25 23:45:06 | 000,000,830 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012.10.25 19:21:38 | 000,000,280 | ---- | C] () -- C:\WINDOWS\Tasks\RMSchedule.job
[2012.11.29 21:59:39 | 000,000,976 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-963918322-3784137826-972506294-1005Core.job
[2012.11.29 21:59:39 | 000,001,028 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-963918322-3784137826-972506294-1005UA.job
[2014.02.09 23:32:52 | 000,000,924 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2014.02.09 23:32:52 | 000,000,928 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2014.03.11 09:01:13 | 000,000,222 | ---- | C] () -- C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
[2014.03.11 09:01:14 | 000,000,228 | ---- | C] () -- C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
< >
< MD5 for: AGP440.SYS >
[2008.04.14 14:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\i386\sp3.cab:AGP440.sys
[2008.04.14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\dllcache\agp440.sys
[2008.04.14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2008.04.14 14:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\i386\sp3.cab:atapi.sys
[2008.04.14 14:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008.04.14 14:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 14:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 14:00:00 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\i386\AUTOCHK.EXE
[2008.04.14 14:00:00 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\system32\autochk.exe
[2008.04.14 14:00:00 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\system32\dllcache\autochk.exe
< MD5 for: CDROM.SYS >
[2008.04.14 14:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\i386\sp3.cab:cdrom.sys
[2008.04.14 14:00:00 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\$NtUninstallKB932716-v2$\cdrom.sys
[2008.05.02 12:49:39 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\Documents and Settings\Martinka\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20140116T204533234375\gencdrom\cdrom.sys
[2008.05.02 12:49:39 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\Documents and Settings\Martinka\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20140116T204915437500\gencdrom\cdrom.sys
[2008.05.02 12:49:39 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\WINDOWS\Driver Cache\i386\cdrom.sys
[2008.05.02 12:49:39 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\WINDOWS\system32\dllcache\cdrom.sys
[2008.05.02 12:49:39 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2008.04.14 14:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=3D4E199942E29207970E04315D02AD3B -- C:\WINDOWS\system32\cryptsvc.dll
[2008.04.14 14:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=3D4E199942E29207970E04315D02AD3B -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 14:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008.04.14 14:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 14:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008.04.14 14:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2008.04.14 14:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\i386\sp3.cab:hal.dll
[2008.04.14 14:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\Documents and Settings\Martinka\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20140116T204533234375\acpiapic_mp\hal.dll
[2008.04.14 14:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\Documents and Settings\Martinka\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20140116T204915437500\acpiapic_mp\hal.dll
[2008.04.14 14:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2008.04.14 14:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\i386\sp3.cab:Changer.sys
< MD5 for: IASTOR.SYS >
[2008.04.15 11:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\ACER\Preload\Autorun\DRV\Intel IMSM 945GSE\f6flpy64\IaStor.sys
[2008.04.15 18:54:16 | 000,388,120 | ---- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008.04.15 11:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\ACER\Preload\Autorun\DRV\Intel IMSM 945GSE\f6flpy32\IaStor.sys
[2008.04.15 18:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Documents and Settings\Martinka\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20140116T204533234375\pci\ven_8086&dev_27c5&cc_0106\iaStor.sys
[2008.04.15 18:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Documents and Settings\Martinka\Local Settings\Application Data\SlimWare Utilities Inc\SlimDrivers\Backups\20140116T204915437500\pci\ven_8086&dev_27c5&cc_0106\iaStor.sys
[2008.04.15 18:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008.04.15 11:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\WINDOWS\OemDir\iaStor.sys
[2008.04.15 18:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\WINDOWS\system32\drivers\iaStor.sys
[2008.04.15 18:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\WINDOWS\system32\DRVSTORE\iaAHCI_E7EB69FF3449D216602D0D37A1D73969621673A9\iaStor.sys
[2008.04.15 11:53:44 | 000,312,344 | ---- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 -- C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\iaStor.sys
< MD5 for: ISAPNP.SYS >
[2008.04.14 14:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\i386\sp3.cab:isapnp.sys
[2008.04.14 14:00:00 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=05A299EC56E52649B1CF2FC52D20F2D7 -- C:\WINDOWS\system32\dllcache\isapnp.sys
[2008.04.14 14:00:00 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=05A299EC56E52649B1CF2FC52D20F2D7 -- C:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 14:00:00 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=05A299EC56E52649B1CF2FC52D20F2D7 -- C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\isapnp.sys
< MD5 for: LSASS.EXE >
[2008.04.14 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.14 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.14 14:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys
[2008.04.14 14:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2008.04.14 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008.04.14 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008.04.14 14:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 14:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2008.04.14 14:00:00 | 000,470,016 | ---- | M] (Microsoft Corporation) MD5=3C3393C92A73A3006C7B706DAC54A812 -- C:\i386\SYSTEM32\SMSS.EXE
[2008.04.14 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=5F816C1F539266D2D4C78694239DA0B5 -- C:\WINDOWS\system32\dllcache\smss.exe
[2008.04.14 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=5F816C1F539266D2D4C78694239DA0B5 -- C:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008.04.14 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.04.14 14:00:00 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 14:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 14:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2008.04.14 14:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 14:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.04.14 14:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2008.04.14 14:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[24 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\cd8435a280c0625210f26e284817e658\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\cd8435a280c0625210f26e284817e658\*.tmp -> ]
[34 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
[1 C:\WINDOWS\Temp\is-GIDO5.tmp\*.tmp files -> C:\WINDOWS\Temp\is-GIDO5.tmp\*.tmp -> ]
[1 C:\WINDOWS\Temp\is-MTS8Q.tmp\*.tmp files -> C:\WINDOWS\Temp\is-MTS8Q.tmp\*.tmp -> ]
[1 C:\WINDOWS\Temp\is-Q4FVA.tmp\*.tmp files -> C:\WINDOWS\Temp\is-Q4FVA.tmp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
[2012.07.25 01:10:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2010.07.10 23:53:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2010.11.11 19:33:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple
[2011.10.23 01:16:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009.03.16 18:27:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Atheros
[2013.08.06 11:39:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avira
[2014.01.16 22:46:25 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010.03.12 23:06:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2013.04.03 20:35:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eSobi
[2014.03.30 13:31:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2014.03.29 21:33:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012.04.18 22:30:30 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2014.03.14 17:48:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2012.09.20 23:17:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Mozilla
[2011.07.14 23:28:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Norton
[2011.02.19 15:05:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2013.08.18 01:47:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OviInstallerCache
[2013.08.19 11:58:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2014.03.19 22:25:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PearlMountain
[2009.08.19 21:43:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2014.03.05 00:12:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2011.06.10 01:15:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype Extras
[2011.03.20 14:40:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony Ericsson
[2010.08.05 23:33:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sun
[2013.02.06 15:58:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2014.01.16 22:48:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2009.08.17 17:41:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009.10.10 16:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2014.01.16 22:46:25 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
[2011.06.06 23:00:59 | 001,560,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Setup\{AC76BA86-7AD7-1051-7B44-AA1000000001}\setup.exe
[2010.02.08 22:25:16 | 098,302,544 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\OviInstallerCache\{927AA2A2-7631-4EA2-A1F9-252D27B9D0A2}\Nokia_Ovi_Suite_2_1_0_87_ALL.exe
[2013.08.18 01:47:47 | 000,050,000 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\OviInstallerCache\{927AA2A2-7631-4EA2-A1F9-252D27B9D0A2}\Installer\CommonCustomActions\pcswpc.exe
[2013.08.18 01:47:47 | 000,077,824 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\OviInstallerCache\{927AA2A2-7631-4EA2-A1F9-252D27B9D0A2}\Installer\CommonCustomActions\Run_XML6_SP1.exe
[2013.08.18 01:47:47 | 000,058,880 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\OviInstallerCache\{927AA2A2-7631-4EA2-A1F9-252D27B9D0A2}\Installer\CommonCustomActions\WMF11Runx64.exe
[2013.08.18 01:47:47 | 000,061,440 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\OviInstallerCache\{927AA2A2-7631-4EA2-A1F9-252D27B9D0A2}\Installer\CommonCustomActions\WMF11Runx86.exe
[2013.08.18 01:48:14 | 013,930,312 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\OviInstallerCache\{927AA2A2-7631-4EA2-A1F9-252D27B9D0A2}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
[2013.08.18 01:48:32 | 012,212,040 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\OviInstallerCache\{927AA2A2-7631-4EA2-A1F9-252D27B9D0A2}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
[2011.03.20 14:52:49 | 000,154,744 | ---- | M] (Sony Ericsson Mobile Communications) -- C:\Documents and Settings\All Users\Application Data\Sony Ericsson\Update Engine\configuration\org.eclipse.osgi\bundles\62\1\.cp\lib\win32\DeviceRemover.exe
[2011.03.20 14:40:32 | 000,158,840 | ---- | M] (Sony Ericsson Mobile Communications) -- C:\Documents and Settings\All Users\Application Data\Sony Ericsson\Update Engine\configuration\org.eclipse.osgi\bundles\64\1\.cp\lib\win32\DriverInstaller.exe
< %APPDATA%\*. >
[2010.03.31 00:03:39 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Martinka\Application Data\.#
[2009.03.16 19:07:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Acer
[2009.03.16 18:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Acer GameZone Console
[2013.12.23 03:21:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Adobe
[2009.11.06 16:58:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Apple Computer
[2013.08.06 11:48:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Avira
[2012.10.13 01:49:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\COWON
[2012.04.06 15:16:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\DAEMON Tools Lite
[2012.04.06 15:16:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\DAEMON Tools Pro
[2012.04.14 17:35:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\ElevatedDiagnostics
[2009.08.17 15:37:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\eSobi
[2013.10.02 22:33:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\eTeks
[2014.03.19 17:22:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Google
[2009.09.20 00:38:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Help
[2014.02.25 20:16:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\ICQ
[2009.03.16 17:38:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Identities
[2009.03.16 18:24:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\InstallShield
[2010.03.24 17:08:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\LimeWire
[2009.08.13 20:25:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Macromedia
[2010.07.24 18:49:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Malwarebytes
[2013.10.23 00:25:53 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Martinka\Application Data\Microsoft
[2010.09.17 22:05:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Mozilla
[2013.08.19 21:36:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Nokia
[2013.08.19 11:58:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\PC Suite
[2014.03.19 22:25:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\PearlMountain
[2014.01.16 22:39:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\rmi
[2013.12.05 01:18:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Skype
[2011.06.10 15:38:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\skypePM
[2009.08.18 01:25:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\SulusGames
[2009.08.24 16:59:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Sun
[2009.08.18 15:31:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Super-Cow
[2009.09.09 21:59:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Template
[2011.06.17 00:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\TS3Client
[2014.01.16 22:47:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\TuneUp Software
[2014.02.09 13:46:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\U3
[2009.12.27 01:33:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\WinRAR
[2010.03.27 23:10:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Martinka\Application Data\Zoner
< %APPDATA%\*.exe /s >
[2009.08.24 17:06:30 | 000,163,840 | ---- | M] (Mozilla Foundation) -- C:\Documents and Settings\Martinka\Application Data\LimeWire\browser\xulrunner\crashreporter.exe
[2009.08.24 17:06:36 | 000,196,608 | ---- | M] (Mozilla Foundation) -- C:\Documents and Settings\Martinka\Application Data\LimeWire\browser\xulrunner\updater.exe
[2009.08.24 17:06:37 | 000,014,848 | ---- | M] () -- C:\Documents and Settings\Martinka\Application Data\LimeWire\browser\xulrunner\xpcshell.exe
[2009.08.24 17:06:37 | 000,077,824 | ---- | M] (Mozilla Foundation) -- C:\Documents and Settings\Martinka\Application Data\LimeWire\browser\xulrunner\xpicleanup.exe
[2009.08.24 17:06:37 | 000,266,240 | ---- | M] (Mozilla Foundation) -- C:\Documents and Settings\Martinka\Application Data\LimeWire\browser\xulrunner\xpidl.exe
[2009.08.24 17:06:37 | 000,018,432 | ---- | M] () -- C:\Documents and Settings\Martinka\Application Data\LimeWire\browser\xulrunner\xpt_dump.exe
[2009.08.24 17:06:37 | 000,014,336 | ---- | M] () -- C:\Documents and Settings\Martinka\Application Data\LimeWire\browser\xulrunner\xpt_link.exe
[2009.08.24 17:06:39 | 000,073,728 | ---- | M] (Mozilla Foundation) -- C:\Documents and Settings\Martinka\Application Data\LimeWire\browser\xulrunner\xulrunner-stub.exe
[2009.08.24 17:06:39 | 000,102,400 | ---- | M] (Mozilla Foundation) -- C:\Documents and Settings\Martinka\Application Data\LimeWire\browser\xulrunner\xulrunner.exe
[2014.01.16 22:40:02 | 000,858,432 | ---- | M] (SlimWare Utilities, Inc.) -- C:\Documents and Settings\Martinka\Application Data\rmi\slimdrivers-2.2.32705.52095.exe
[2014.02.02 23:27:24 | 000,145,408 | ---- | M] () -- C:\Documents and Settings\Martinka\Application Data\Sun\Java\jre1.7.0_51\lzma.exe
[2007.10.23 10:27:20 | 000,110,592 | ---- | M] () -- C:\Documents and Settings\Martinka\Application Data\U3\temp\cleanup.exe
[2008.05.02 11:41:48 | 003,493,888 | -H-- | M] (SanDisk Corporation) -- C:\Documents and Settings\Martinka\Application Data\U3\temp\Launchpad Removal.exe
[2010.06.24 22:35:27 | 006,990,704 | ---- | M] (ZONER software ) -- C:\Documents and Settings\Martinka\Application Data\Zoner\NLMDB\product.0032\autoupdate.us\ZPS12_Update_Build09.exe
[2010.08.27 23:40:05 | 006,995,288 | ---- | M] (ZONER software ) -- C:\Documents and Settings\Martinka\Application Data\Zoner\NLMDB\product.0032\autoupdate.us\ZPS12_Update_Build10.exe
[2011.04.16 13:23:21 | 006,998,712 | ---- | M] (ZONER software ) -- C:\Documents and Settings\Martinka\Application Data\Zoner\NLMDB\product.0032\autoupdate.us\ZPS12_Update_Build12.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.03.12 23:07:10 | 000,691,696 | ---- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2009.03.16 18:28:50 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2009.03.16 18:28:50 | 001,064,960 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2009.03.16 18:28:50 | 000,905,216 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2014.04.04 20:14:26 | 000,077,858 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2014.04.04 20:14:26 | 000,477,494 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2014.04.04 20:14:25 | 000,566,072 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2014.04.03 21:01:43 | 000,001,158 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 14:00:00 | 000,015,360 | ---- | M] (Microsoft Corporation)
"StatBar" = C:\Program Files\Globe Software\StatBar\StatBar.exe -- [2003.07.25 02:40:06 | 000,335,872 | ---- | M] (Globe Software)
"Google Update" = "C:\Documents and Settings\Martinka\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c -- [2011.06.01 22:39:58 | 000,136,176 | ---- | M] (Google Inc.)
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< >
< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2014.04.04 20:27:28 | 000,000,512 | ---- | M] () MD5=67C4C9E788972000C1F719B704657DC6 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2002.05.30 18:16:22 | 000,013,160 | ---- | M] () -- \Program Files\Stronghold\gm\cracks.gm1
< *keygen* /s >
< *AntiWPA* /s >
< *loader* /s >
[2013.02.20 16:28:38 | 000,072,638 | ---- | M] () -- \Documents and Settings\All Users\Application Data\Skype\Apps\login\images\loader.gif
[2013.02.20 16:28:38 | 000,003,032 | ---- | M] () -- \Documents and Settings\All Users\Application Data\Skype\Apps\login\images\loader.png
[2013.11.11 15:39:40 | 000,006,012 | ---- | M] () -- \Documents and Settings\All Users\Application Data\Skype\Apps\login\images\normal\loader_15fps.gif
[2013.11.11 15:39:40 | 000,021,956 | ---- | M] () -- \Documents and Settings\All Users\Application Data\Skype\Apps\login\images\normal\loader_30fps.gif
[2013.02.20 16:28:38 | 000,009,772 | ---- | M] () -- \Documents and Settings\All Users\Application Data\Skype\Apps\login\images\retina\
loader@2x.png
[2009.08.24 17:06:29 | 000,002,713 | ---- | M] () -- \Documents and Settings\Martinka\Application Data\LimeWire\browser\xulrunner\components\uriloader.xpt
[2010.12.10 19:23:41 | 000,001,981 | ---- | M] () -- \Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Temp\scoped_dir_24962\CRX_INSTALL\FMLoader_Obfs.js
[2010.12.10 19:23:41 | 000,000,723 | ---- | M] () -- \Documents and Settings\Martinka\Local Settings\Application Data\Google\Chrome\User Data\Temp\scoped_dir_24962\CRX_INSTALL\img\ajax-loader.gif
[2008.04.14 14:00:00 | 000,017,419 | ---- | M] () -- \i386\DMLOADER.DL_
[2008.04.14 14:00:00 | 000,114,925 | ---- | M] () -- \i386\OSLOADER.EX_
[2008.04.14 14:00:00 | 000,132,513 | ---- | M] () -- \i386\OSLOADER.NT_
[2005.03.24 13:51:08 | 000,002,090 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge\Resources\en\_media\rssloader.swf
[2014.02.25 12:07:50 | 000,053,328 | ---- | M] () -- \Program Files\Avira\AntiVir Desktop\avwebloader.dll
[2014.02.25 12:07:50 | 000,566,352 | ---- | M] () -- \Program Files\Avira\AntiVir Desktop\avwebloader.exe
[2014.02.25 12:07:51 | 001,748,048 | ---- | M] () -- \Program Files\Avira\AntiVir Desktop\avwebloadergui.dll
[2005.03.16 19:16:50 | 000,113,664 | ---- | M] () -- \Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[2006.10.26 14:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.dll
[2006.10.26 14:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.tlb
[2011.12.19 18:50:09 | 000,005,795 | ---- | M] () -- \Program Files\ICQ7.5\imApp\theme\IMAGES\XtraPreloader\loader.jpg
[2011.12.19 18:50:10 | 000,004,180 | ---- | M] () -- \Program Files\ICQ7.5\imApp\theme\IMAGES\XtraPreloader\zlango-preloader.png
[2011.12.19 18:50:09 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.5\imApp\theme\MUICoreLib\xtraLoader.swf
[2011.12.19 18:51:50 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.5\Xtraz\icq\content\profile_lightboxs\preloader.html
[2011.02.28 16:28:04 | 000,001,702 | ---- | M] () -- \Program Files\Sony Ericsson\Update Engine\licenses\loaderbinarylegal.txt
[2008.02.25 08:05:22 | 000,856,064 | ---- | M] () -- \Program Files\The KMPlayer\ImLoader.dll
[2009.06.02 02:16:57 | 000,114,688 | ---- | M] () -- \Program Files\WinRAR\RarExtLoader.exe
[2010.04.29 15:12:38 | 000,673,160 | ---- | M] () -- \Program Files\Zoner\Photo Studio 12\Plugins\Facebook\ZPSFacebookUploader.exe
[2010.04.29 15:12:40 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 12\Plugins\Facebook\ZPSPluginLoader.exe
[2010.04.22 17:02:26 | 000,319,488 | ---- | M] () -- \Program Files\Zoner\Photo Studio 12\Plugins\Facebook\en\ZPSFacebookUploader.resources.dll
[2010.04.29 15:12:42 | 000,686,984 | ---- | M] () -- \Program Files\Zoner\Photo Studio 12\Plugins\Flickr\ZPSFlickrUploader.exe
[2010.04.29 15:12:42 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 12\Plugins\Flickr\ZPSPluginLoader.exe
[2010.04.22 15:49:30 | 000,323,584 | ---- | M] () -- \Program Files\Zoner\Photo Studio 12\Plugins\Flickr\en\ZPSFlickrUploader.resources.dll
[2010.02.20 18:20:10 | 000,082,784 | ---- | M] () -- \WINDOWS\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
[2014.03.31 16:04:59 | 000,024,920 | ---- | M] () -- \WINDOWS\Prefetch\ADOBE GAMMA LOADER.EXE-2926B5EA.pf
[2008.04.14 14:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[2011.02.02 15:31:20 | 000,012,532 | ---- | M] () -- \WINDOWS\system32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2008.04.14 14:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dllcache\dmloader.dll
< *minodlogin* /s >
< *tnod* /s >
[2011.09.06 22:58:59 | 000,000,654 | ---- | M] () -- \Documents and Settings\Martinka\Local Settings\Application Data\Ares\Data\DHTnodes.dat
< *AutoKMS* /s >
< *activator* /s >
< *serial* /s >
[2011.03.20 14:52:46 | 000,057,344 | ---- | M] () -- \Documents and Settings\All Users\Application Data\Sony Ericsson\Update Engine\configuration\org.eclipse.osgi\bundles\5\1\.cp\lib\serialio.dll
[2008.04.14 14:00:00 | 000,024,869 | ---- | M] () -- \i386\DPSERIAL.DL_
[2008.04.14 14:00:00 | 000,030,075 | ---- | M] () -- \i386\SERIAL.SY_
[2008.04.14 14:00:00 | 000,006,409 | ---- | M] () -- \i386\SERIALUI.DL_
[2012.09.27 01:12:26 | 000,970,752 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2011.02.28 16:26:12 | 000,026,761 | ---- | M] () -- \Program Files\Sony Ericsson\Update Engine\plugins\com.serialio.win32.x86_2.10.2.0.jar
[2011.02.28 16:26:12 | 000,049,506 | ---- | M] () -- \Program Files\Sony Ericsson\Update Engine\plugins\com.serialio_2.11.3.6.jar
[2011.02.28 16:28:24 | 000,002,235 | ---- | M] () -- \Program Files\Sony Ericsson\Update Engine\plugins\com.sonyericsson.cs.serialcommunication_2.11.3.6.jar
[2014.02.14 14:41:45 | 000,131,072 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2013.01.10 05:29:58 | 000,970,752 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2014.02.14 14:40:27 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\6c29ee2bedfe88dcd66993f1af135ad8\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.02.14 14:37:57 | 002,345,472 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\9860da66bf0219612908e7412b0a6e2e\System.Runtime.Serialization.ni.dll
[2013.08.15 19:51:18 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\a95e0af6fa5d2e8ffd5e0091f6513271\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2013.08.15 19:48:55 | 002,345,472 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\ba6670610621b25b1608e457ba0ef305\System.Runtime.Serialization.ni.dll
[2014.02.15 15:18:52 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\046c2851963b30d0e14194051c03de33\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2013.08.16 13:25:45 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\ad3522eafb95969623aeef7c389246bd\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2013.10.10 17:10:58 | 002,658,304 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\b5faab90a38802d89ccf6f9ac4bff440\System.Runtime.Serialization.ni.dll
[2014.02.15 15:18:36 | 002,658,304 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\fa954900a6cf3a095efadfa4c683a32c\System.Runtime.Serialization.ni.dll
[2010.03.18 13:16:28 | 001,026,936 | R--- | M] () -- \WINDOWS\Installer\$PatchCache$\Managed\5C1093C35543A0E32A41B090A305076A\4.0.30319\System.Runtime.Serialization.dll.x86
[2014.02.14 14:46:44 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2014.02.14 14:46:41 | 001,039,040 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2008.07.25 11:17:00 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2012.09.27 01:12:26 | 000,970,752 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2013.09.11 06:06:54 | 001,039,040 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2010.03.18 13:16:28 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2005.09.02 14:00:00 | 000,005,632 | ---- | M] () -- \WINDOWS\mui\FALLBACK\041b\SERIALUI.DLL.MUi
[2008.04.14 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dpserial.dll
[2008.04.14 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\serialui.dll
[2008.04.14 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dllcache\dpserial.dll
[2008.04.14 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\dllcache\serialui.dll
[2008.04.14 14:00:00 | 000,064,512 | ---- | M] () -- \WINDOWS\system32\drivers\serial.sys
< *w7lxe* /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4CF61E54
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:93C494CA
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9AB56A06
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4D066AD2
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AB689DEA
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7091055F
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:798A3728
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:94213A87
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ADE16379
< End of report >