izbacuje msixni32.dll problem

izbacuje msixni32.dll problem

offline
  • Pridružio: 25 Apr 2012
  • Poruke: 139

Evo sta mi izbaci kad se podigne sitem.

Imam Windows 7 Enterprise 64,anti virus Microsoft Security Essentials

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10615
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Potrebno je da ispratiš uputstvo i postaviš tražene izvještaje.

http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

offline
  • Pridružio: 25 Apr 2012
  • Poruke: 139

OTL logfile created on: 9/18/2012 5:56:30 PM - Run 1
OTL by OldTimer - Version 3.2.63.0 Folder = C:\Users\Share\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.07 Gb Available Physical Memory | 75.89% Memory free
16.00 Gb Paging File | 14.10 Gb Available in Paging File | 88.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 59.53 Gb Total Space | 11.17 Gb Free Space | 18.76% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 232.21 Gb Free Space | 24.93% Space Free | Partition Type: NTFS
Drive E: | 1.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 69.25 Gb Total Space | 29.34 Gb Free Space | 42.37% Space Free | Partition Type: NTFS

Computer Name: SHARE-PC | User Name: Share | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found --
PRC - [2012/09/18 17:56:03 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\Share\Desktop\OTL.exe
PRC - [2012/08/30 23:08:12 | 000,874,896 | ---- | M] (Opera Software) -- F:\opera.exe
PRC - [2012/08/24 13:01:40 | 002,735,528 | ---- | M] (TeamViewer GmbH) -- F:\Version7\TeamViewer_Service.exe
PRC - [2012/08/18 18:20:45 | 000,608,256 | ---- | M] () -- C:\ProgramData\InstallBrainService\ibsvc.exe
PRC - [2012/08/13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012/07/27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/03 00:07:50 | 000,554,176 | ---- | M] () -- C:\ProgramData\IBUpdaterService\ibsvc.exe
PRC - [2012/03/23 14:25:24 | 000,087,040 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe


========== Modules (No Company Name) ==========

MOD - [2012/08/30 23:08:13 | 000,783,360 | ---- | M] () -- F:\gstreamer\gstreamer.dll
MOD - [2012/08/30 23:08:13 | 000,316,928 | ---- | M] () -- F:\gstreamer\plugins\gstoggdec.dll
MOD - [2012/08/30 23:08:13 | 000,276,480 | ---- | M] () -- F:\gstreamer\plugins\gstwebmdec.dll
MOD - [2012/08/30 23:08:13 | 000,168,448 | ---- | M] () -- F:\gstreamer\plugins\gstffmpegcolorspace.dll
MOD - [2012/08/30 23:08:13 | 000,099,840 | ---- | M] () -- F:\gstreamer\plugins\gstcoreplugins.dll
MOD - [2012/08/30 23:08:13 | 000,098,816 | ---- | M] () -- F:\gstreamer\plugins\gstaudioresample.dll
MOD - [2012/08/30 23:08:13 | 000,098,816 | ---- | M] () -- F:\gstreamer\plugins\gstaudioconvert.dll
MOD - [2012/08/30 23:08:13 | 000,078,336 | ---- | M] () -- F:\gstreamer\plugins\gstwavparse.dll
MOD - [2012/08/30 23:08:13 | 000,076,800 | ---- | M] () -- F:\gstreamer\plugins\gstdirectsound.dll
MOD - [2012/08/30 23:08:13 | 000,068,608 | ---- | M] () -- F:\gstreamer\plugins\gstdecodebin2.dll
MOD - [2012/08/30 23:08:13 | 000,064,000 | ---- | M] () -- F:\gstreamer\plugins\gstautodetect.dll
MOD - [2012/08/30 23:08:13 | 000,046,592 | ---- | M] () -- F:\gstreamer\plugins\gstwaveform.dll
MOD - [2012/08/30 23:08:13 | 000,045,568 | ---- | M] () -- F:\gstreamer\plugins\gsttypefindfunctions.dll
MOD - [2012/08/28 17:11:19 | 009,813,704 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2011/11/10 05:11:32 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011/11/09 22:08:52 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/08/28 17:11:19 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/08/24 13:01:40 | 002,735,528 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- F:\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012/08/18 18:20:45 | 000,608,256 | ---- | M] () [Auto | Running] -- C:\ProgramData\InstallBrainService\ibsvc.exe -- (InstallBrainService)
SRV - [2012/08/13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/07/27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/03 00:07:50 | 000,554,176 | ---- | M] () [Auto | Running] -- C:\ProgramData\IBUpdaterService\ibsvc.exe -- (IBUpdaterService)
SRV - [2012/06/07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- F:\skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/23 14:25:24 | 000,087,040 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2011/10/12 18:14:14 | 002,072,896 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010/03/18 22:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/08/21 00:43:40 | 000,059,256 | ---- | M] (G Data Software AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PktIcpt.sys -- (GDPkIcpt)
DRV:64bit: - [2012/05/19 23:37:05 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/03/02 16:02:00 | 000,034,304 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandmodem64.sys -- (ANDModem)
DRV:64bit: - [2012/03/02 16:02:00 | 000,027,648 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lganddiag64.sys -- (AndDiag)
DRV:64bit: - [2012/03/02 16:02:00 | 000,027,136 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandgps64.sys -- (AndGps)
DRV:64bit: - [2012/03/02 16:02:00 | 000,019,456 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandbus64.sys -- (Andbus)
DRV:64bit: - [2011/12/16 17:53:01 | 000,035,112 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV:64bit: - [2011/11/10 05:45:30 | 010,567,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/11/10 04:12:44 | 000,325,632 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011/10/17 19:40:50 | 000,093,712 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011/06/24 06:31:02 | 000,055,424 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.01)
DRV:64bit: - [2011/03/11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/12/02 12:44:48 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV:64bit: - [2010/11/21 05:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/11/21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2010/11/21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2010/11/21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/21 05:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2010/11/21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/06/25 16:08:10 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
DRV:64bit: - [2010/02/18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2010/01/07 03:20:22 | 000,448,512 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL8187.sys -- (RTL8187)
DRV:64bit: - [2009/11/02 18:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/05 05:20:26 | 000,114,192 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009/05/05 00:30:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie)
DRV:64bit: - [2006/09/19 14:43:54 | 000,018,224 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2011/09/22 13:08:26 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = facebook.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 01 78 8D EA 06 36 CD 01 [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{945FDAF7-1123-462D-9DC8-CDF13960267D}: "URL" = websearch.ask.com/redirect?client=ie&tb.....=kw&q={searchTerms}&locale=&apn_ptnrs=^AAA&apn_dtid=^YYYYYY^YY^ME&apn_uid=7EF75774-8C0C-4EEF-A1FC-6A38A499B98B&apn_sauid=289373D0-7082-4C1B-9DA0-41FBB14FE3A7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: F:\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)


[2012/07/29 11:29:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Share\AppData\Roaming\Mozilla\Firefox\Profiles\extensions
[2012/07/29 11:29:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Share\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions
[2012/07/21 17:51:07 | 000,000,000 | ---D | M] (OneClickDownloader) -- C:\Users\Share\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com
[2012/07/29 11:29:25 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Share\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/06/28 18:39:00 | 000,221,407 | ---- | M] () (No name found) -- C:\Users\Share\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\gophoto@gophoto.it.xpi

O1 HOSTS File: ([2012/05/20 14:41:13 | 000,000,864 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 validation.sls.microsoft.com
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - F:\skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKCU..\Run: [MSIDLL] C:\Windows\SysWOW64\rundll32.exe msixni32.dll,wYSrwr File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 [2012/09/04 19:05:47 | 000,000,000 | ---D | M]
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - F:\Office12\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Share\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - F:\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Share\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - F:\skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\Office12\REFIEBAR.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} support.asus.com/select/asusTek_sys_ctrl3.cab (asusTek_sysctrl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D3EAEE7-7CFF-4272-B9D2-BC354547CCE7}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - F:\skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/18 17:56:02 | 000,600,576 | ---- | C] (OldTimer Tools) -- C:\Users\Share\Desktop\OTL.exe
[2012/09/18 17:40:53 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012/09/18 17:40:53 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012/09/18 17:40:52 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012/09/18 17:40:51 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012/09/18 17:40:51 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2012/09/18 17:40:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/09/18 17:40:07 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/09/18 17:33:51 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/09/13 18:47:52 | 000,655,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr90.dll
[2012/09/13 18:47:52 | 000,568,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp90.dll
[2012/09/13 18:47:52 | 000,224,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcm90.dll
[2012/09/13 18:47:42 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml4a.dll
[2012/09/13 18:47:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LGMobile Support Tool
[2012/09/13 18:47:33 | 000,000,000 | ---D | C] -- C:\ProgramData\LGMOBILEAX
[2012/09/13 18:46:45 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Local\LG Electronics
[2012/09/13 18:46:40 | 000,000,000 | ---D | C] -- D:\My Documents\LG OSP
[2012/09/13 18:46:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LG On-Screen Phone
[2012/09/13 18:45:50 | 000,034,304 | ---- | C] (LG Electronics Inc.) -- C:\Windows\SysNative\drivers\lgandmodem64.sys
[2012/09/13 18:45:50 | 000,027,648 | ---- | C] (LG Electronics Inc.) -- C:\Windows\SysNative\drivers\lganddiag64.sys
[2012/09/13 18:45:50 | 000,027,136 | ---- | C] (LG Electronics Inc.) -- C:\Windows\SysNative\drivers\lgandgps64.sys
[2012/09/13 18:45:50 | 000,019,456 | ---- | C] (LG Electronics Inc.) -- C:\Windows\SysNative\drivers\lgandbus64.sys
[2012/09/13 18:45:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LG Electronics
[2012/09/12 23:20:08 | 000,000,000 | -HSD | C] -- C:\ProgramData\DSS
[2012/09/12 23:18:44 | 000,000,000 | ---D | C] -- D:\My Documents\FIFA 13
[2012/09/12 23:18:12 | 000,000,000 | ---D | C] -- D:\My Documents\FIFA 13 Demo
[2012/09/12 23:17:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2012/09/12 23:14:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012/09/12 20:09:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com
[2012/09/10 19:20:37 | 000,000,000 | ---D | C] -- D:\My Documents\My Photos
[2012/09/10 19:20:37 | 000,000,000 | ---D | C] -- D:\My Documents\My Documents
[2012/09/10 18:59:41 | 000,000,000 | ---D | C] -- C:\ruu_log
[2012/09/10 18:59:13 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2012/09/10 18:58:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC Sync
[2012/09/10 18:50:01 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Local\Htc
[2012/09/10 18:49:52 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Roaming\HTC
[2012/09/10 18:49:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC
[2012/09/10 18:49:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spirent Communications
[2012/09/10 18:49:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HTC
[2012/09/10 18:48:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2012/09/08 19:10:39 | 000,000,000 | ---D | C] -- C:\Users\Share\Desktop\LG
[2012/09/08 19:00:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/09/08 19:00:31 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/09/06 18:08:00 | 000,449,024 | ---- | C] (RAD Game Tools, Inc.) -- C:\Windows\SysWow64\mss32.dll
[2012/09/06 17:39:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Skype
[2012/09/04 22:29:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\The KMPlayer
[2012/09/04 22:23:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Ask
[2012/09/04 20:13:26 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Roaming\ImgBurn
[2012/09/04 19:57:37 | 000,154,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WimFltr.sys
[2012/09/04 18:57:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\nLite
[2012/09/04 18:57:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\nLite
[2012/09/04 18:50:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirtuallTek
[2012/09/04 18:50:21 | 000,000,000 | ---D | C] -- C:\ProgramData\VirtuallTek
[2012/09/04 18:50:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VirtuallTek
[2012/09/04 12:41:52 | 000,000,000 | ---D | C] -- C:\Users\Share\Desktop\2
[2012/09/04 08:22:03 | 000,106,648 | ---- | C] (G Data Software) -- C:\Windows\SysNative\drivers\GRD.sys
[2012/09/03 23:37:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\{7CD4105B-4B96-420C-A16E-7289B2DD604C}
[2012/09/03 23:37:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RT 7 Lite
[2012/08/31 14:00:21 | 000,000,000 | ---D | C] -- C:\Users\Share\Desktop\zikamu
[2012/08/26 21:33:53 | 000,000,000 | ---D | C] -- C:\Users\Share\temp
[2012/08/26 21:33:53 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Roaming\TeamViewer
[2012/08/24 19:26:28 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Roaming\vlc
[2012/08/22 11:18:45 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Roaming\Systweak
[2012/08/22 11:18:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RegClean Pro
[2012/08/21 15:37:05 | 000,000,000 | ---D | C] -- C:\ProgramData\KONAMI
[2012/08/21 12:56:00 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Local\Ilivid Player
[2012/08/21 11:37:12 | 000,000,000 | ---D | C] -- C:\CS6
[2012/08/21 00:43:40 | 000,059,256 | ---- | C] (G Data Software AG) -- C:\Windows\SysNative\drivers\PktIcpt.sys
[2012/08/20 23:53:13 | 000,106,224 | ---- | C] (G Data Software) -- C:\Windows\SysWow64\drivers\GRD.sys
[2012/08/20 23:52:37 | 000,050,552 | ---- | C] (G Data Software AG) -- C:\Windows\SysNative\drivers\GDBehave.sys
[2012/08/20 23:52:12 | 000,110,968 | ---- | C] (G Data Software AG) -- C:\Windows\SysNative\drivers\MiniIcpt.sys
[2012/08/20 23:52:12 | 000,065,912 | ---- | C] (G Data Software AG) -- C:\Windows\SysNative\drivers\gdwfpcd64.sys
[2012/08/20 23:52:07 | 000,000,000 | ---D | C] -- C:\ProgramData\G DATA
[2012/08/20 23:52:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\G Data
[2012/08/20 23:52:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\G Data
[2012/08/20 23:51:42 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Local\Downloaded Installations

========== Files - Modified Within 30 Days ==========

[2012/09/18 17:56:03 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\Share\Desktop\OTL.exe
[2012/09/18 17:46:35 | 000,026,176 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 17:46:35 | 000,026,176 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 17:40:15 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/09/18 17:40:09 | 000,743,066 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/09/18 17:40:09 | 000,626,040 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/09/18 17:40:09 | 000,107,316 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/09/18 17:38:15 | 000,103,295 | ---- | M] () -- C:\Users\Share\Desktop\Untitled.jpg
[2012/09/18 17:23:21 | 000,726,316 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/18 17:19:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/18 17:19:10 | 2146,836,479 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/17 23:09:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/17 21:57:24 | 000,797,867 | ---- | M] () -- C:\Windows\SysWow64\sig.bin
[2012/09/17 21:57:24 | 000,044,153 | ---- | M] () -- C:\Windows\SysWow64\nmp.map
[2012/09/16 01:09:13 | 000,000,849 | ---- | M] () -- C:\Users\Share\Desktop\pes2012.lnk
[2012/09/15 16:16:03 | 000,002,413 | ---- | M] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2012/09/13 18:47:52 | 000,000,831 | ---- | M] () -- C:\Users\Share\Desktop\LGMobile Support Tool.lnk
[2012/09/13 18:46:26 | 000,001,235 | ---- | M] () -- C:\Users\Public\Desktop\LG On-Screen Phone.lnk
[2012/09/11 17:54:37 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/09 09:07:23 | 000,349,696 | ---- | M] () -- C:\Windows\Mss32.dll
[2012/09/08 19:07:09 | 000,017,386 | ---- | M] () -- D:\My Documents\cc_20120908_190705.reg
[2012/09/06 18:08:05 | 000,449,024 | ---- | M] (RAD Game Tools, Inc.) -- C:\Windows\SysWow64\mss32.dll
[2012/09/04 22:29:15 | 000,001,039 | ---- | M] () -- C:\Users\Share\Desktop\KMPlayer.lnk
[2012/09/04 18:57:18 | 000,000,967 | ---- | M] () -- C:\Users\Share\Desktop\nLite.lnk
[2012/09/04 18:54:35 | 000,001,094 | ---- | M] () -- C:\Users\Share\Desktop\Add-On Maker.lnk
[2012/09/04 08:22:03 | 000,106,648 | ---- | M] (G Data Software) -- C:\Windows\SysNative\drivers\GRD.sys
[2012/09/04 00:18:32 | 000,014,839 | ---- | M] () -- C:\Users\Share\127484719148d62f0a76162.gif
[2012/09/03 23:37:24 | 000,000,968 | ---- | M] () -- C:\Users\Share\Application Data\Microsoft\Internet Explorer\Quick Launch\RT 7 Lite.lnk
[2012/09/03 23:37:24 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\RT 7 Lite.lnk
[2012/08/29 19:07:26 | 000,000,556 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012/08/28 17:11:19 | 000,696,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/08/28 17:11:19 | 000,073,416 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/08/24 22:41:34 | 001,332,322 | ---- | M] () -- C:\Users\Share\Desktop\Flayer MD.jpg
[2012/08/22 09:58:03 | 005,036,536 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/08/21 15:21:34 | 000,000,132 | ---- | M] () -- C:\Users\Share\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2012/08/21 11:41:19 | 000,000,841 | ---- | M] () -- C:\Users\Share\Desktop\Adobe Photoshop CS6 (64 Bit).lnk
[2012/08/21 00:43:40 | 000,059,256 | ---- | M] (G Data Software AG) -- C:\Windows\SysNative\drivers\PktIcpt.sys
[2012/08/21 00:43:24 | 000,110,968 | ---- | M] (G Data Software AG) -- C:\Windows\SysNative\drivers\MiniIcpt.sys
[2012/08/21 00:43:24 | 000,065,912 | ---- | M] (G Data Software AG) -- C:\Windows\SysNative\drivers\gdwfpcd64.sys
[2012/08/21 00:43:24 | 000,050,552 | ---- | M] (G Data Software AG) -- C:\Windows\SysNative\drivers\GDBehave.sys
[2012/08/21 00:21:54 | 000,106,224 | ---- | M] (G Data Software) -- C:\Windows\SysWow64\drivers\GRD.sys

========== Files Created - No Company Name ==========

[2012/09/18 17:40:10 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/09/18 17:19:54 | 000,103,295 | ---- | C] () -- C:\Users\Share\Desktop\Untitled.jpg
[2012/09/17 21:57:21 | 000,797,867 | ---- | C] () -- C:\Windows\SysWow64\sig.bin
[2012/09/17 21:57:21 | 000,044,153 | ---- | C] () -- C:\Windows\SysWow64\nmp.map
[2012/09/13 18:47:52 | 000,000,831 | ---- | C] () -- C:\Users\Share\Desktop\LGMobile Support Tool.lnk
[2012/09/13 18:47:42 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\CommonDL.dll
[2012/09/13 18:47:42 | 000,002,413 | ---- | C] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2012/09/13 18:46:26 | 000,001,235 | ---- | C] () -- C:\Users\Public\Desktop\LG On-Screen Phone.lnk
[2012/09/09 09:09:27 | 000,349,696 | ---- | C] () -- C:\Windows\Mss32.dll
[2012/09/08 19:07:07 | 000,017,386 | ---- | C] () -- D:\My Documents\cc_20120908_190705.reg
[2012/09/08 19:00:32 | 000,000,866 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/04 22:29:15 | 000,001,039 | ---- | C] () -- C:\Users\Share\Desktop\KMPlayer.lnk
[2012/09/04 18:57:18 | 000,000,967 | ---- | C] () -- C:\Users\Share\Desktop\nLite.lnk
[2012/09/04 18:54:35 | 000,001,094 | ---- | C] () -- C:\Users\Share\Desktop\Add-On Maker.lnk
[2012/09/04 00:18:32 | 000,014,839 | ---- | C] () -- C:\Users\Share\127484719148d62f0a76162.gif
[2012/09/03 23:37:24 | 000,000,968 | ---- | C] () -- C:\Users\Share\Application Data\Microsoft\Internet Explorer\Quick Launch\RT 7 Lite.lnk
[2012/09/03 23:37:24 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\RT 7 Lite.lnk
[2012/08/29 19:07:26 | 000,000,556 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012/08/29 19:07:26 | 000,000,556 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012/08/21 15:41:38 | 000,000,849 | ---- | C] () -- C:\Users\Share\Desktop\pes2012.lnk
[2012/08/21 15:14:22 | 000,000,132 | ---- | C] () -- C:\Users\Share\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2012/08/21 11:41:02 | 000,000,841 | ---- | C] () -- C:\Users\Share\Desktop\Adobe Photoshop CS6 (64 Bit).lnk
[2012/08/21 11:40:27 | 000,000,853 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk
[2012/08/21 11:40:15 | 000,000,790 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk
[2012/08/21 11:40:00 | 000,000,815 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
[2012/08/21 11:39:53 | 000,000,752 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk
[2012/08/21 11:39:12 | 000,000,936 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
[2012/08/21 11:39:10 | 000,001,523 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
[2012/08/17 14:31:37 | 000,995,360 | ---- | C] () -- C:\Users\Share\manchester_united_by_mancuniaresident-d3f0fe8.jpg
[2012/07/17 18:50:54 | 000,361,339 | ---- | C] () -- C:\Users\Share\crvena-zvezda-2011.png
[2012/07/03 18:37:41 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012/07/02 23:08:13 | 002,255,315 | ---- | C] () -- C:\Users\Share\crvenazvezda1.png
[2012/06/30 18:46:47 | 000,064,292 | ---- | C] () -- C:\Users\Share\logo.png
[2012/05/21 20:14:58 | 000,000,132 | ---- | C] () -- C:\Users\Share\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/05/20 14:25:34 | 000,015,872 | ---- | C] () -- C:\Windows\AsTaskSched.dll
[2012/05/20 14:25:33 | 000,001,746 | ---- | C] () -- C:\Windows\Language_trs.ini
[2012/05/19 23:53:49 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012/05/19 23:45:30 | 000,743,066 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/05/19 23:41:33 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2012/05/19 23:41:33 | 000,013,368 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2012/05/19 23:41:32 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2012/05/19 23:41:32 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2012/05/19 23:37:36 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/11/10 04:36:06 | 000,204,960 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2011/11/10 04:36:06 | 000,157,152 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011/11/09 22:39:44 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll
[2011/11/09 22:39:32 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/09/13 01:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009/07/14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

< End of report >






mycity.rs/must-login.png

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Pozdrav, sasash


Korak 1.

Na racunaru imas ostatke G Data Antivirusa, preuzmi ovaj fajl, pokreni, klikni na Select All, a zatim na Delete. Nakon toga restartuj racunar...



Korak 2.

Ponovo pokreni program OTL dvoklikom na ikonu.

U bijeli okvir prozora gdje piše Custom Scans/Fixes iskopirati sljedeći tekst:

:OTL
O4 - HKCU..\Run: [MSIDLL] C:\Windows\SysWOW64\rundll32.exe msixni32.dll,wYSrwr File not found

:Commands
[emptytemp]



Klikni taster Run Fix;

Izvještaj koji dobiješ iskopiraj ovde u poruci.



Korak 3.


Dvoklikom pokreni OTL.

Štikliraj opciju Scan All Users.
U beli okvir prozora gde piše Custom Scans/Fixes iskopiraj sledeći tekst:

CREATERESTOREPOINT
%SYSTEMDRIVE%\*.exe
/md5start
services.exe
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
C:\Windows\assembly\Desktop.ini /md5
%systemdrive%\$Recycle.Bin|@;true;true;true
C:\$Recycle.Bin\S-1-5-18 /s
C:\$Recycle.Bin\S-1-5-21-1862684139-277524484-329249885-1000 /s



Klikni RunScan i pričekaj da se skeniranje završi.
Iskopiraj sadržaj OTL.txt izveštaja u temu na forumu.

offline
  • Pridružio: 25 Apr 2012
  • Poruke: 139

mycity.rs/must-login.png



OTL logfile created on: 9/18/2012 11:47:23 PM - Run 2
OTL by OldTimer - Version 3.2.63.0 Folder = C:\Users\Share\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.67 Gb Available Physical Memory | 83.39% Memory free
16.00 Gb Paging File | 14.35 Gb Available in Paging File | 89.69% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 59.53 Gb Total Space | 11.61 Gb Free Space | 19.50% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 230.42 Gb Free Space | 24.74% Space Free | Partition Type: NTFS
Drive E: | 1.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 69.25 Gb Total Space | 29.33 Gb Free Space | 42.36% Space Free | Partition Type: NTFS

Computer Name: SHARE-PC | User Name: Share | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/09/18 17:56:03 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\Share\Desktop\OTL.exe
PRC - [2012/08/30 23:08:12 | 000,874,896 | ---- | M] (Opera Software) -- F:\opera.exe
PRC - [2012/08/24 13:01:40 | 002,735,528 | ---- | M] (TeamViewer GmbH) -- F:\Version7\TeamViewer_Service.exe
PRC - [2012/08/18 18:20:45 | 000,608,256 | ---- | M] () -- C:\ProgramData\InstallBrainService\ibsvc.exe
PRC - [2012/08/13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012/07/27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/03 00:07:50 | 000,554,176 | ---- | M] () -- C:\ProgramData\IBUpdaterService\ibsvc.exe
PRC - [2012/06/07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) -- F:\skype\Updater\Updater.exe
PRC - [2012/04/17 15:05:00 | 000,651,264 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
PRC - [2012/03/23 14:25:24 | 000,087,040 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe


========== Modules (No Company Name) ==========

MOD - [2012/08/28 17:11:19 | 009,813,704 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
MOD - [2012/04/17 15:05:00 | 001,515,520 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\Maps\R66Api.dll
MOD - [2012/04/17 15:05:00 | 000,651,264 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
MOD - [2012/04/17 15:05:00 | 000,559,244 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.7.dll
MOD - [2012/04/17 15:05:00 | 000,516,599 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.dll
MOD - [2012/04/17 15:05:00 | 000,389,120 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetect.dll
MOD - [2012/04/17 15:05:00 | 000,172,032 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetectLegend.dll
MOD - [2012/04/17 15:05:00 | 000,151,552 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDisk.dll
MOD - [2012/04/17 15:05:00 | 000,103,936 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\OutputLog.dll
MOD - [2012/04/17 15:05:00 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\fdHttpd.dll
MOD - [2012/01/04 04:51:03 | 003,190,784 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
MOD - [2012/01/04 04:50:59 | 004,550,656 | ---- | M] () -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
MOD - [2010/11/21 05:24:32 | 000,425,984 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
MOD - [2010/11/21 05:24:08 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2010/11/21 05:23:48 | 002,048,000 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2011/11/10 05:11:32 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011/11/09 22:08:52 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/08/28 17:11:19 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/08/24 13:01:40 | 002,735,528 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- F:\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012/08/18 18:20:45 | 000,608,256 | ---- | M] () [Auto | Running] -- C:\ProgramData\InstallBrainService\ibsvc.exe -- (InstallBrainService)
SRV - [2012/08/13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/07/27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/03 00:07:50 | 000,554,176 | ---- | M] () [Auto | Running] -- C:\ProgramData\IBUpdaterService\ibsvc.exe -- (IBUpdaterService)
SRV - [2012/06/07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Running] -- F:\skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/23 14:25:24 | 000,087,040 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2011/10/12 18:14:14 | 002,072,896 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010/03/18 22:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/05/19 23:37:05 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/03/02 16:02:00 | 000,034,304 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandmodem64.sys -- (ANDModem)
DRV:64bit: - [2012/03/02 16:02:00 | 000,027,648 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lganddiag64.sys -- (AndDiag)
DRV:64bit: - [2012/03/02 16:02:00 | 000,027,136 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandgps64.sys -- (AndGps)
DRV:64bit: - [2012/03/02 16:02:00 | 000,019,456 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandbus64.sys -- (Andbus)
DRV:64bit: - [2012/03/01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/12/16 17:53:01 | 000,035,112 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV:64bit: - [2011/11/10 05:45:30 | 010,567,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/11/10 04:12:44 | 000,325,632 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011/10/17 19:40:50 | 000,093,712 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011/06/24 06:31:02 | 000,055,424 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.01)
DRV:64bit: - [2011/03/11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/12/02 12:44:48 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV:64bit: - [2010/11/21 05:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/11/21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2010/11/21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2010/11/21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/21 05:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2010/11/21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/06/25 16:08:10 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
DRV:64bit: - [2010/02/18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2010/01/07 03:20:22 | 000,448,512 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL8187.sys -- (RTL8187)
DRV:64bit: - [2009/11/02 18:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/05 05:20:26 | 000,114,192 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009/05/05 00:30:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie)
DRV:64bit: - [2006/09/19 14:43:54 | 000,018,224 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2011/09/22 13:08:26 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1339588484-2641093231-4029372845-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = facebook.com/
IE - HKU\S-1-5-21-1339588484-2641093231-4029372845-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1339588484-2641093231-4029372845-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKU\S-1-5-21-1339588484-2641093231-4029372845-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 01 78 8D EA 06 36 CD 01 [binary data]
IE - HKU\S-1-5-21-1339588484-2641093231-4029372845-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-1339588484-2641093231-4029372845-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1339588484-2641093231-4029372845-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1339588484-2641093231-4029372845-1000\..\SearchScopes\{945FDAF7-1123-462D-9DC8-CDF13960267D}: "URL" = websearch.ask.com/redirect?client=ie&tb.....=kw&q={searchTerms}&locale=&apn_ptnrs=^AAA&apn_dtid=^YYYYYY^YY^ME&apn_uid=7EF75774-8C0C-4EEF-A1FC-6A38A499B98B&apn_sauid=289373D0-7082-4C1B-9DA0-41FBB14FE3A7
IE - HKU\S-1-5-21-1339588484-2641093231-4029372845-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: F:\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)


[2012/07/29 11:29:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Share\AppData\Roaming\Mozilla\Firefox\Profiles\extensions
[2012/07/29 11:29:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Share\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions
[2012/07/21 17:51:07 | 000,000,000 | ---D | M] (OneClickDownloader) -- C:\Users\Share\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com
[2012/07/29 11:29:25 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Share\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/06/28 18:39:00 | 000,221,407 | ---- | M] () (No name found) -- C:\Users\Share\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\gophoto@gophoto.it.xpi

O1 HOSTS File: ([2012/05/20 14:41:13 | 000,000,864 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 validation.sls.microsoft.com
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - F:\skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 [2012/09/18 19:07:14 | 000,000,000 | ---D | M]
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - F:\Office12\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Share\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - F:\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Share\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - F:\skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\Office12\REFIEBAR.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} support.asus.com/select/asusTek_sys_ctrl3.cab (asusTek_sysctrl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D3EAEE7-7CFF-4272-B9D2-BC354547CCE7}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - F:\skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
System Restore Service not available.

========== Files/Folders - Created Within 30 Days ==========

[2012/09/18 23:44:26 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/09/18 18:59:30 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/09/18 18:59:29 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/09/18 18:59:29 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/09/18 18:59:29 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/09/18 18:59:28 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/09/18 18:59:28 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/09/18 18:59:28 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/09/18 18:59:28 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/09/18 18:59:27 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/09/18 18:59:27 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/09/18 18:59:27 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/09/18 18:59:26 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/09/18 18:59:26 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/09/18 18:56:19 | 000,220,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2012/09/18 18:56:19 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imagehlp.dll
[2012/09/18 18:56:19 | 000,023,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fs_rec.sys
[2012/09/18 17:56:02 | 000,600,576 | ---- | C] (OldTimer Tools) -- C:\Users\Share\Desktop\OTL.exe
[2012/09/18 17:50:42 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2012/09/18 17:50:42 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2012/09/18 17:50:42 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2012/09/18 17:50:41 | 000,376,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
[2012/09/18 17:50:41 | 000,288,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2012/09/18 17:50:41 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2012/09/18 17:50:41 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2012/09/18 17:50:39 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012/09/18 17:50:39 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012/09/18 17:50:39 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012/09/18 17:50:38 | 001,112,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
[2012/09/18 17:50:37 | 001,462,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2012/09/18 17:50:37 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2012/09/18 17:50:34 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netapi32.dll
[2012/09/18 17:50:34 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browcli.dll
[2012/09/18 17:50:34 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\browcli.dll
[2012/09/18 17:50:33 | 000,956,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll
[2012/09/18 17:50:16 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdosys.dll
[2012/09/18 17:50:15 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdosys.dll
[2012/09/18 17:40:53 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2012/09/18 17:40:53 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2012/09/18 17:40:52 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2012/09/18 17:40:51 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2012/09/18 17:40:51 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2012/09/18 17:40:51 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2012/09/18 17:40:51 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2012/09/18 17:40:51 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2012/09/18 17:40:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/09/18 17:40:07 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/09/18 17:33:51 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/09/13 18:47:52 | 000,655,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr90.dll
[2012/09/13 18:47:52 | 000,568,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp90.dll
[2012/09/13 18:47:52 | 000,224,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcm90.dll
[2012/09/13 18:47:42 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml4a.dll
[2012/09/13 18:47:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LGMobile Support Tool
[2012/09/13 18:47:33 | 000,000,000 | ---D | C] -- C:\ProgramData\LGMOBILEAX
[2012/09/13 18:46:45 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Local\LG Electronics
[2012/09/13 18:46:40 | 000,000,000 | ---D | C] -- D:\My Documents\LG OSP
[2012/09/13 18:46:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LG On-Screen Phone
[2012/09/13 18:45:50 | 000,034,304 | ---- | C] (LG Electronics Inc.) -- C:\Windows\SysNative\drivers\lgandmodem64.sys
[2012/09/13 18:45:50 | 000,027,648 | ---- | C] (LG Electronics Inc.) -- C:\Windows\SysNative\drivers\lganddiag64.sys
[2012/09/13 18:45:50 | 000,027,136 | ---- | C] (LG Electronics Inc.) -- C:\Windows\SysNative\drivers\lgandgps64.sys
[2012/09/13 18:45:50 | 000,019,456 | ---- | C] (LG Electronics Inc.) -- C:\Windows\SysNative\drivers\lgandbus64.sys
[2012/09/13 18:45:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LG Electronics
[2012/09/12 23:20:08 | 000,000,000 | -HSD | C] -- C:\ProgramData\DSS
[2012/09/12 23:18:44 | 000,000,000 | ---D | C] -- D:\My Documents\FIFA 13
[2012/09/12 23:18:12 | 000,000,000 | ---D | C] -- D:\My Documents\FIFA 13 Demo
[2012/09/12 23:17:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2012/09/12 23:14:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012/09/12 20:09:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com
[2012/09/10 19:20:37 | 000,000,000 | ---D | C] -- D:\My Documents\My Photos
[2012/09/10 19:20:37 | 000,000,000 | ---D | C] -- D:\My Documents\My Documents
[2012/09/10 18:59:41 | 000,000,000 | ---D | C] -- C:\ruu_log
[2012/09/10 18:59:13 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2012/09/10 18:58:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC Sync
[2012/09/10 18:50:01 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Local\Htc
[2012/09/10 18:49:52 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Roaming\HTC
[2012/09/10 18:49:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC
[2012/09/10 18:49:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spirent Communications
[2012/09/10 18:49:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HTC
[2012/09/10 18:48:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2012/09/08 19:10:39 | 000,000,000 | ---D | C] -- C:\Users\Share\Desktop\LG
[2012/09/08 19:00:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/09/08 19:00:31 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/09/06 18:08:00 | 000,449,024 | ---- | C] (RAD Game Tools, Inc.) -- C:\Windows\SysWow64\mss32.dll
[2012/09/06 17:39:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Skype
[2012/09/04 22:29:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\The KMPlayer
[2012/09/04 22:23:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Ask
[2012/09/04 20:13:26 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Roaming\ImgBurn
[2012/09/04 19:57:37 | 000,154,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WimFltr.sys
[2012/09/04 18:57:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\nLite
[2012/09/04 18:57:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\nLite
[2012/09/04 18:50:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirtuallTek
[2012/09/04 18:50:21 | 000,000,000 | ---D | C] -- C:\ProgramData\VirtuallTek
[2012/09/04 18:50:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VirtuallTek
[2012/09/04 12:41:52 | 000,000,000 | ---D | C] -- C:\Users\Share\Desktop\2
[2012/09/04 08:22:03 | 000,106,648 | ---- | C] (G Data Software) -- C:\Windows\SysNative\drivers\GRD.sys
[2012/09/03 23:37:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\{7CD4105B-4B96-420C-A16E-7289B2DD604C}
[2012/09/03 23:37:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RT 7 Lite
[2012/08/31 14:00:21 | 000,000,000 | ---D | C] -- C:\Users\Share\Desktop\zikamu
[2012/08/26 21:33:53 | 000,000,000 | ---D | C] -- C:\Users\Share\temp
[2012/08/26 21:33:53 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Roaming\TeamViewer
[2012/08/24 19:26:28 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Roaming\vlc
[2012/08/22 11:18:45 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Roaming\Systweak
[2012/08/22 11:18:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RegClean Pro
[2012/08/21 15:37:05 | 000,000,000 | ---D | C] -- C:\ProgramData\KONAMI
[2012/08/21 12:56:00 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Local\Ilivid Player
[2012/08/21 11:37:12 | 000,000,000 | ---D | C] -- C:\CS6
[2012/08/21 00:43:40 | 000,059,256 | ---- | C] (G Data Software AG) -- C:\Windows\SysNative\drivers\PktIcpt.sys
[2012/08/20 23:52:07 | 000,000,000 | ---D | C] -- C:\ProgramData\G DATA
[2012/08/20 23:52:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\G Data
[2012/08/20 23:51:42 | 000,000,000 | ---D | C] -- C:\Users\Share\AppData\Local\Downloaded Installations

========== Files - Modified Within 30 Days ==========

[2012/09/18 23:45:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/18 23:45:29 | 2146,836,479 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/18 23:45:01 | 000,026,176 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 23:45:01 | 000,026,176 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 23:42:50 | 005,033,824 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/09/18 23:41:09 | 000,403,968 | ---- | M] () -- C:\Users\Share\Desktop\AVCleaner_int.exe
[2012/09/18 23:09:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/18 19:04:56 | 000,743,278 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/18 19:04:56 | 000,626,040 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/09/18 19:04:56 | 000,107,316 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/09/18 17:56:03 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\Share\Desktop\OTL.exe
[2012/09/18 17:40:15 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/09/18 17:40:09 | 000,743,066 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/09/18 17:38:15 | 000,103,295 | ---- | M] () -- C:\Users\Share\Desktop\Untitled.jpg
[2012/09/17 21:57:24 | 000,797,867 | ---- | M] () -- C:\Windows\SysWow64\sig.bin
[2012/09/17 21:57:24 | 000,044,153 | ---- | M] () -- C:\Windows\SysWow64\nmp.map
[2012/09/16 01:09:13 | 000,000,849 | ---- | M] () -- C:\Users\Share\Desktop\pes2012.lnk
[2012/09/15 16:16:03 | 000,002,413 | ---- | M] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2012/09/13 18:47:52 | 000,000,831 | ---- | M] () -- C:\Users\Share\Desktop\LGMobile Support Tool.lnk
[2012/09/13 18:46:26 | 000,001,235 | ---- | M] () -- C:\Users\Public\Desktop\LG On-Screen Phone.lnk
[2012/09/11 17:54:37 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/09 09:07:23 | 000,349,696 | ---- | M] () -- C:\Windows\Mss32.dll
[2012/09/08 19:07:09 | 000,017,386 | ---- | M] () -- D:\My Documents\cc_20120908_190705.reg
[2012/09/06 18:08:05 | 000,449,024 | ---- | M] (RAD Game Tools, Inc.) -- C:\Windows\SysWow64\mss32.dll
[2012/09/04 22:29:15 | 000,001,039 | ---- | M] () -- C:\Users\Share\Desktop\KMPlayer.lnk
[2012/09/04 18:57:18 | 000,000,967 | ---- | M] () -- C:\Users\Share\Desktop\nLite.lnk
[2012/09/04 18:54:35 | 000,001,094 | ---- | M] () -- C:\Users\Share\Desktop\Add-On Maker.lnk
[2012/09/04 08:22:03 | 000,106,648 | ---- | M] (G Data Software) -- C:\Windows\SysNative\drivers\GRD.sys
[2012/09/04 00:18:32 | 000,014,839 | ---- | M] () -- C:\Users\Share\127484719148d62f0a76162.gif
[2012/09/03 23:37:24 | 000,000,968 | ---- | M] () -- C:\Users\Share\Application Data\Microsoft\Internet Explorer\Quick Launch\RT 7 Lite.lnk
[2012/09/03 23:37:24 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\RT 7 Lite.lnk
[2012/08/29 19:07:26 | 000,000,556 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012/08/28 17:11:19 | 000,696,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/08/28 17:11:19 | 000,073,416 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/08/24 22:41:34 | 001,332,322 | ---- | M] () -- C:\Users\Share\Desktop\Flayer MD.jpg
[2012/08/22 20:12:40 | 000,376,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
[2012/08/22 20:12:33 | 000,288,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2012/08/21 15:21:34 | 000,000,132 | ---- | M] () -- C:\Users\Share\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2012/08/21 11:41:19 | 000,000,841 | ---- | M] () -- C:\Users\Share\Desktop\Adobe Photoshop CS6 (64 Bit).lnk
[2012/08/21 00:43:40 | 000,059,256 | ---- | M] (G Data Software AG) -- C:\Windows\SysNative\drivers\PktIcpt.sys

========== Files Created - No Company Name ==========

[2012/09/18 23:41:09 | 000,403,968 | ---- | C] () -- C:\Users\Share\Desktop\AVCleaner_int.exe
[2012/09/18 17:40:10 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/09/18 17:19:54 | 000,103,295 | ---- | C] () -- C:\Users\Share\Desktop\Untitled.jpg
[2012/09/17 21:57:21 | 000,797,867 | ---- | C] () -- C:\Windows\SysWow64\sig.bin
[2012/09/17 21:57:21 | 000,044,153 | ---- | C] () -- C:\Windows\SysWow64\nmp.map
[2012/09/13 18:47:52 | 000,000,831 | ---- | C] () -- C:\Users\Share\Desktop\LGMobile Support Tool.lnk
[2012/09/13 18:47:42 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\CommonDL.dll
[2012/09/13 18:47:42 | 000,002,413 | ---- | C] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2012/09/13 18:46:26 | 000,001,235 | ---- | C] () -- C:\Users\Public\Desktop\LG On-Screen Phone.lnk
[2012/09/09 09:09:27 | 000,349,696 | ---- | C] () -- C:\Windows\Mss32.dll
[2012/09/08 19:07:07 | 000,017,386 | ---- | C] () -- D:\My Documents\cc_20120908_190705.reg
[2012/09/08 19:00:32 | 000,000,866 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/04 22:29:15 | 000,001,039 | ---- | C] () -- C:\Users\Share\Desktop\KMPlayer.lnk
[2012/09/04 18:57:18 | 000,000,967 | ---- | C] () -- C:\Users\Share\Desktop\nLite.lnk
[2012/09/04 18:54:35 | 000,001,094 | ---- | C] () -- C:\Users\Share\Desktop\Add-On Maker.lnk
[2012/09/04 00:18:32 | 000,014,839 | ---- | C] () -- C:\Users\Share\127484719148d62f0a76162.gif
[2012/09/03 23:37:24 | 000,000,968 | ---- | C] () -- C:\Users\Share\Application Data\Microsoft\Internet Explorer\Quick Launch\RT 7 Lite.lnk
[2012/09/03 23:37:24 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\RT 7 Lite.lnk
[2012/08/29 19:07:26 | 000,000,556 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012/08/29 19:07:26 | 000,000,556 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012/08/21 15:41:38 | 000,000,849 | ---- | C] () -- C:\Users\Share\Desktop\pes2012.lnk
[2012/08/21 15:14:22 | 000,000,132 | ---- | C] () -- C:\Users\Share\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2012/08/21 11:41:02 | 000,000,841 | ---- | C] () -- C:\Users\Share\Desktop\Adobe Photoshop CS6 (64 Bit).lnk
[2012/08/21 11:40:27 | 000,000,853 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk
[2012/08/21 11:40:15 | 000,000,790 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk
[2012/08/21 11:40:00 | 000,000,815 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
[2012/08/21 11:39:53 | 000,000,752 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk
[2012/08/21 11:39:12 | 000,000,936 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
[2012/08/21 11:39:10 | 000,001,523 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
[2012/08/17 14:31:37 | 000,995,360 | ---- | C] () -- C:\Users\Share\manchester_united_by_mancuniaresident-d3f0fe8.jpg
[2012/07/17 18:50:54 | 000,361,339 | ---- | C] () -- C:\Users\Share\crvena-zvezda-2011.png
[2012/07/03 18:37:41 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012/07/02 23:08:13 | 002,255,315 | ---- | C] () -- C:\Users\Share\crvenazvezda1.png
[2012/06/30 18:46:47 | 000,064,292 | ---- | C] () -- C:\Users\Share\logo.png
[2012/05/21 20:14:58 | 000,000,132 | ---- | C] () -- C:\Users\Share\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/05/20 14:25:34 | 000,015,872 | ---- | C] () -- C:\Windows\AsTaskSched.dll
[2012/05/20 14:25:33 | 000,001,746 | ---- | C] () -- C:\Windows\Language_trs.ini
[2012/05/19 23:53:49 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012/05/19 23:45:30 | 000,743,066 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/05/19 23:41:33 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2012/05/19 23:41:33 | 000,013,368 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2012/05/19 23:41:32 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2012/05/19 23:41:32 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2012/05/19 23:37:36 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/11/10 04:36:06 | 000,204,960 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2011/11/10 04:36:06 | 000,157,152 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011/11/09 22:39:44 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll
[2011/11/09 22:39:32 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/09/13 01:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009/07/14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 07:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/02/25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 08:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/21 05:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/02/25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/21 05:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/14 03:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009/07/14 03:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009/07/14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009/07/14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010/11/21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010/11/21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< C:\Windows\assembly\Desktop.ini /md5 >
[2009/07/14 06:55:00 | 000,000,227 | RHS- | M] () MD5=F7F759A5CD40BC52172E83486B6DE404 -- C:\Windows\assembly\Desktop.ini

< %systemdrive%\$Recycle.Bin|@;true;true;true >

< C:\$Recycle.Bin\S-1-5-18 /s >

< C:\$Recycle.Bin\S-1-5-21-1862684139-277524484-329249885-1000 /s >

< End of report >




mycity.rs/must-login.png

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Arrow Kakvo je sada stanje, imas li nekih problema?

offline
  • Pridružio: 25 Apr 2012
  • Poruke: 139

TwinHeadedEagle ::Arrow Kakvo je sada stanje, imas li nekih problema?

Evo pisem sa posla,sinoc sam ga par puta restartovao i nije vise izbacivao onu gresku radi extra,hvala punoo.

Jos jedno pitanje koja je tvoja preporuka za Antivirus,naravno free za Win 7?

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

To bi bilo to, komp je cist sto se malware-a tice. Pozeljno je da ispratis sledece korake/preporuke Smile


Arrow Ponovo pokreni OTL i klikni na CleanUp. Sacekaj da se proces deinstalacije zavrsii. Ostale koriscene programe mozes rucno obrisati.


Arrow Sto se tice free antivirusa, mozes izabrati neki od sledecih, moj favorit je Microsoft Security Essentials, mada bilo koji da izaberes dodje ti na isto Smile

Microsoft Security Essentials
avast! Free Antivirus
Avira Free Antivirus
Panda Antivirus Free
AVG Free

Takodje prelistaj malo i ove teme...

Aplikacija-za-sigurno-surfovanje-Vas-mozak Arrow
http://www.mycity.rs/Zastita/Aplikacija-za-sigurno-surfovanje-Vas-mozak.html

Izbor besplatnog antivirusa Arrow
http://www.mycity.rs/Zastitni-programi/Izbor-besplatnog-antivirusa.html

Najbolji-antivirus-po-vasem-misljenju Arrow
http://www.mycity.rs/Zastitni-programi/Najbolji-an.....jenju.html



Arrow Preporučujem da za zaštitu USB memorijskih uredjaja koristiš MCShield v2. Nema nikakve veze sa AntiVirus-om tj. nece ometati njegov rad, a pokazao se kao jedan od najboljih vidova zaštite od malware-a koji se prenosi putem USB mem. uređaja. Skineš, instaliraš, ubodeš USB mem. uređaj, izvrši se skeniranje nakon čega dobiješ obaveštenje da je uređaj čist (ukoliko je stvarno tako); ili dobiješ log u kome vidiš informacije o malware-u koji je nađen i obrisan.


Home Page MCShield-a ::Anti-Malware Tool:: v2: http://amf.mycity.rs/mcshield/

Više o MCShield-u možeš saznati u ovim temama:
v1: http://www.mycity.rs/MyCity-Laboratorija/MCShield.html
v2: http://www.mycity.rs/MyCity-Laboratorija/MCShield-v2.html




Arrow Obavezno poseti temu "Testirajte da li vam je pretraživač ranjiv", pročitaj i isprati link koji stoji u njoj.
Link do teme je: http://www.mycity.rs/Web-browseri/Testirajte-da-li.....anjiv.html



Arrow Takođe, isprati i temu "Kako izbeći i ukloniti toolbar-ove" , pročitaj i isprati korake u njoj. Link do teme je: http://www.mycity.rs/Zastita/Kako-izbeci-i-ukloniti-toolbar-ove.html



TwinHeadedEagle (AMF Tim)

Ko je trenutno na forumu
 

Ukupno su 418 korisnika na forumu :: 14 registrovanih, 0 sakrivenih i 404 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: benne, Dorcolac, Konda, MikeHammer, oddsock, Ognjen D., raketaš, scimitar19, shaja1, Taso, Trpe Grozni, vathra, voja64, vrag81