Trokiranje računara

2

Trokiranje računara

offline
  • Pridružio: 30 Jul 2012
  • Poruke: 8

Izvinjvam se što te mučim ivance95.

OTL logfile created on: 02.08.2012 22:24:36 - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Documents and Settings\User\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000081A | Country: Serbia and Montenegro | Language: SRL | Date Format: dd.MM.yyyy

1022,73 Mb Total Physical Memory | 595,80 Mb Available Physical Memory | 58,26% Memory free
3,83 Gb Paging File | 3,22 Gb Available in Paging File | 84,12% Paging File free
Paging file location(s): C:\pagefile.sys 3000 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 27,49 Gb Total Space | 8,34 Gb Free Space | 30,34% Space Free | Partition Type: NTFS
Drive D: | 48,83 Gb Total Space | 32,52 Gb Free Space | 66,59% Space Free | Partition Type: NTFS

Computer Name: RACUNARPD | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.08.02 22:24:22 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\desktop\OTL.exe
PRC - [2012.07.31 07:36:16 | 001,229,848 | ---- | M] (Google Inc.) -- C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2012.07.10 01:38:53 | 004,777,856 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2012.07.05 22:07:00 | 000,161,704 | ---- | M] (Oracle Corporation) -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
PRC - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.06.27 11:35:38 | 003,335,016 | ---- | M] (Sevas-S) -- C:\Documents and Settings\User\Local Settings\Application Data\Sevas-S\YouTube to MP3 Converter\yt2mp3converter.exe
PRC - [2012.06.22 21:09:56 | 000,603,648 | ---- | M] (MyCity) -- C:\Program Files\MCShield\MCShieldRTM.exe
PRC - [2012.05.26 12:04:52 | 000,913,792 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
PRC - [2011.08.12 01:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2010.07.29 09:50:16 | 000,238,952 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2010.04.07 14:57:42 | 000,099,896 | ---- | M] (HP) -- C:\WINDOWS\system32\HPSIsvc.exe
PRC - [2006.05.12 11:16:50 | 000,072,704 | ---- | M] (Autodata Limited) -- C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
PRC - [2004.08.04 00:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2002.09.20 16:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


========== Modules (No Company Name) ==========

MOD - [2012.08.02 17:00:33 | 000,065,024 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
MOD - [2012.08.02 17:00:33 | 000,052,736 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll
MOD - [2012.08.02 16:17:03 | 000,117,760 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
MOD - [2012.08.02 16:17:02 | 000,052,224 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
MOD - [2012.07.31 07:36:14 | 000,442,392 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.60\ppgooglenaclpluginchrome.dll
MOD - [2012.07.31 07:36:13 | 012,235,288 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
MOD - [2012.07.31 07:36:12 | 003,997,720 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.60\pdf.dll
MOD - [2012.07.31 07:34:45 | 000,144,424 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.60\avutil-51.dll
MOD - [2012.07.31 07:34:43 | 000,266,792 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.60\avformat-54.dll
MOD - [2012.07.31 07:34:42 | 002,480,680 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.60\avcodec-54.dll
MOD - [2012.05.24 10:45:42 | 000,138,112 | ---- | M] () -- C:\Program Files\IObit\Advanced SystemCare 5\ASCv5ExtMenu.dll
MOD - [2011.04.21 16:54:40 | 000,347,024 | ---- | M] () -- C:\Program Files\IObit\Advanced SystemCare 5\madexcept_.bpl
MOD - [2011.04.21 16:54:40 | 000,179,088 | ---- | M] () -- C:\Program Files\IObit\Advanced SystemCare 5\madbasic_.bpl
MOD - [2011.04.21 16:54:40 | 000,046,480 | ---- | M] () -- C:\Program Files\IObit\Advanced SystemCare 5\maddisAsm_.bpl
MOD - [2010.03.04 17:55:34 | 000,147,456 | ---- | M] () -- C:\WINDOWS\system32\HP1100LM.DLL
MOD - [2010.03.04 17:55:14 | 000,069,632 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\HP1100PP.dll
MOD - [2008.09.16 20:18:06 | 000,132,608 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2004.08.04 00:56:44 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2004.08.04 00:56:44 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2003.09.16 02:19:48 | 000,010,240 | ---- | M] () -- C:\WINDOWS\system32\virport.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2012.07.27 15:32:43 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.07.05 22:07:00 | 000,161,704 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012.07.03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.05.26 12:04:52 | 000,913,792 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe -- (AdvancedSystemCareService5)
SRV - [2012.01.04 13:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011.08.12 01:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore.exe -- (!SASCORE)
SRV - [2010.07.29 09:50:16 | 000,238,952 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010.04.07 14:57:42 | 000,099,896 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPSIsvc.exe -- (HPSIService)
SRV - [2006.05.12 11:16:50 | 000,072,704 | ---- | M] (Autodata Limited) [Auto | Running] -- C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe -- (Autodata Limited License Service)
SRV - [2002.09.20 16:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default)


========== Driver Services (SafeList) ==========

DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before Last Install)
DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before First Install)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [File_System | Auto | Stopped] -- -- (StarOpen)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | Auto | Stopped] -- -- (pardrv)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\FreshDevices\FreshDiagnose\FreshIO.sys -- (FreshIO)
DRV - File not found [Kernel | Disabled | Unknown] -- C:\WINDOWS\System32\drivers\dwshd.sys -- (dwshd)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012.07.24 22:11:50 | 000,033,512 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2012.07.10 04:48:18 | 000,039,656 | ---- | M] (AnchorFree Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HssDrv.sys -- (HssDrv)
DRV - [2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011.12.23 17:39:47 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2011.11.01 10:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011.11.01 10:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011.11.01 10:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011.11.01 10:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2011.07.22 18:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011.07.12 23:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010.06.14 02:32:54 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010.04.27 04:25:16 | 000,123,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2010.04.27 04:25:16 | 000,098,432 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bbus.sys -- (ss_bbus)
DRV - [2010.04.27 04:25:16 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdfl.sys -- (ss_bmdfl)
DRV - [2010.03.06 01:40:57 | 000,017,408 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mvusbews.sys -- (mvusbews)
DRV - [2009.11.04 21:31:30 | 000,097,792 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ACEDRV05.sys -- (ACEDRV05)
DRV - [2009.11.04 18:12:29 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2008.08.26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007.04.23 16:54:50 | 000,100,488 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s115mgmt.sys -- (s115mgmt)
DRV - [2007.04.23 16:54:50 | 000,098,568 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s115obex.sys -- (s115obex)
DRV - [2007.04.23 16:54:48 | 000,108,680 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s115mdm.sys -- (s115mdm)
DRV - [2007.04.23 16:54:48 | 000,015,112 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s115mdfl.sys -- (s115mdfl)
DRV - [2007.04.23 16:54:46 | 000,083,208 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s115bus.sys -- (s115bus)
DRV - [2005.11.03 16:40:07 | 000,063,488 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfvfs02.sys -- (sfvfs02)
DRV - [2005.08.10 14:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfdrv01.sys -- (sfdrv01)
DRV - [2005.05.16 15:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfhlp02.sys -- (sfhlp02)
DRV - [2004.08.03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)
DRV - [2004.08.03 22:29:28 | 000,701,440 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004.06.28 10:06:26 | 000,061,840 | ---- | M] (Gemplus) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\GTwinUSB.sys -- (GTwinUSB)
DRV - [2002.10.15 00:00:00 | 000,101,431 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\IdeChnDr.sys -- (IdeChnDr)
DRV - [2002.10.15 00:00:00 | 000,013,891 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\IdeBusDr.sys -- (IdeBusDr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {56256A51-B582-467e-B8D4-7786EDA79AE0}
IE - HKLM\..\SearchScopes\{5150F126-A853-4DF8-9A46-64DDF1F118EB}: "URL" = downloads.phpnuke.org/en/index.php?rvs=google

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\..\SearchScopes,DefaultScope = {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
IE - HKCU\..\SearchScopes\${searchCLSID}: "URL" = search.yahoo.com/search?fr=megaup&p={searchTerms}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = tbsearch.ask.com/redirect?client=ie&tb=.....crm&q={searchTerms}&locale=en_EU
IE - HKCU\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" = crawler.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=66022
IE - HKCU\..\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}: "URL" = search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=64b8e0f2000000000000000000000000&tlver=1.4.19.19&affID=16553
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = google.com/search?ie=utf-8&oe=utf-8&rlz=1V4IPYX&q={searchTerms}
IE - HKCU\..\SearchScopes\{3DFC3AE5-1F9C-4923-B1A0-718214234671}: "URL" = google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\..\SearchScopes\{5150F126-A853-4DF8-9A46-64DDF1F118EB}: "URL" = downloads.phpnuke.org/en/index.php?rvs=google
IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = daemon-search.com/search?q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3072253
IE - HKCU\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = toolbar.ask.com/toolbarv/askRedirect?gct=&gc=1&q={searchTerms}&crm=1&toolbar=BLP
IE - HKCU\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
IE - HKCU\..\SearchScopes\Yahoo!: "URL" = us.search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=iobit-trans
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: File not found
FF - HKCU\Software\MozillaPlugins\@adobe.com/Acrobat,version=5.1: C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)



========== Chrome ==========

CHR - homepage: crawler.com/homepage.aspx?tbid=66022
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage: crawler.com/homepage.aspx?tbid=66022
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.60\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.60\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.60\pdf.dll
CHR - plugin: YouTube Downloader Npapi (Enabled) = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jnlpomffplbggocdfbghngdfkingkkpg\1.1.3_0\YouTubeDownloaderNpapi.dll
CHR - plugin: registryAccess (Enabled) = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aaaaoggiphohkihibdkcnhnokmkfmhnj\7.15.2.0_0\background/registryAccess.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Java(TM) Platform SE 7 U5 (Enabled) = C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = C:\WINDOWS\system32\npDeployJava1.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Google News = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dllkocilcinkggkchnjgegijklcililc\3.0_0\
CHR - Extension: World Time Buddy = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jdhpjomiingppeefgnohkiapmnaeakoj\7_0\
CHR - Extension: Youtube to MP3 Converter = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jnlpomffplbggocdfbghngdfkingkkpg\1.1.3_0\
CHR - Extension: View Background Image = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\knnjokagadbonknppgkjgjpiolcijbmg\0.3_0\
CHR - Extension: Aliens = C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nlikbchkiekphpifodoplneiphojchkb\1_0\

O1 HOSTS File: ([2012.08.02 12:38:36 | 000,000,736 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (YouTube to MP3 Converter) - {E71596B0-A83B-453D-82C1-4BE99947C65F} - C:\Documents and Settings\User\Local Settings\Application Data\Sevas-S\YouTube to MP3 Converter\BrowserExtensions\IE\YouTubeDownloaderExtension.dll (Sevas-S LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [MCShield Monitor] C:\Program Files\MCShield\MCShieldRTM.exe (MyCity)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} update.microsoft.com/microsoftupdate/v6.....3892068046 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.216.1.40 89.216.1.50
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8C9282B6-720B-407E-99F4-906A6E2F1803}: DhcpNameServer = 89.216.1.40 89.216.1.50
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002.01.01 00:01:27 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /r \??\FSmile
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (aswBoot.exe /M:1536175123)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012.08.02 22:24:21 | 000,597,504 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
[2012.08.02 20:26:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Downloads
[2012.08.02 20:25:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\New Folder
[2012.08.02 19:38:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Tracing
[2012.08.02 19:38:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\microsoft
[2012.08.02 16:15:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
[2012.08.02 16:15:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2012.08.02 16:14:06 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012.08.02 16:08:34 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2012.08.02 16:08:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Start Menu\Programs\HiJackThis
[2012.08.02 15:48:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\My Documents\RootRepeal
[2012.08.02 15:45:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\User\My Documents\My Videos
[2012.08.02 15:45:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\User\My Documents\My Pictures
[2012.08.02 15:45:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\User\My Documents\My Music
[2012.08.02 15:45:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites
[2012.08.02 15:45:43 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\User\My Documents\dds.pif
[2012.08.02 15:25:57 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\User\Recent
[2012.08.02 13:43:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Start Menu\Programs\Google Chrome
[2012.08.02 12:51:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Advanced SystemCare 5
[2012.08.01 14:57:31 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
[2012.08.01 14:57:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live
[2012.08.01 14:56:58 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2012.07.31 20:23:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\PCHealth
[2012.07.31 19:51:48 | 000,263,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\http.sys
[2012.07.31 19:42:28 | 000,021,376 | ---- | C] (IObit) -- C:\WINDOWS\System32\RegistryDefragBootTime.exe
[2012.07.31 13:53:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2012.07.31 13:53:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Canneverbe Limited
[2012.07.31 11:35:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\BITS
[2012.07.31 11:35:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\FlashgetSetup
[2012.07.31 10:59:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Ashampoo
[2012.07.31 10:58:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\ashampoo
[2012.07.31 10:58:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ashampoo
[2012.07.31 10:30:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2012.07.31 10:29:34 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2012.07.31 10:26:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2012.07.31 10:25:50 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2012.07.31 10:16:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Qualys
[2012.07.30 18:33:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\VS Revo Group
[2012.07.30 14:15:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\MCShield
[2012.07.30 14:15:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MCShield
[2012.07.30 14:15:15 | 000,000,000 | ---D | C] -- C:\Program Files\MCShield
[2012.07.30 13:03:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\IObit
[2012.07.26 13:43:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012.07.26 13:23:01 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012.07.26 13:05:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012.07.26 11:50:07 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012.07.26 11:40:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2012.07.26 02:25:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\Zezalice
[2012.07.26 01:46:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Sevas-S
[2012.07.26 01:18:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\Sevas-S
[2012.07.26 01:18:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\OpenCandy
[2012.07.25 18:19:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\Sun
[2012.07.25 17:39:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot_bak
[2012.07.25 17:27:51 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
[2012.07.25 17:27:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Oracle
[2012.07.25 17:26:44 | 000,227,760 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2012.07.25 17:26:12 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2012.07.25 17:26:11 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2012.07.25 17:07:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\GRETECH
[2012.07.25 17:05:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GOM Player
[2012.07.22 12:19:38 | 000,360,580 | ---- | C] (eSellerate Inc.) -- C:\WINDOWS\eSellerateEngine.dll
[2012.07.21 16:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Real
[2012.07.15 22:57:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\MPlayer
[2012.07.15 20:41:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
[2012.07.15 20:40:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\L&H
[2012.07.15 20:39:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2012.07.15 20:38:47 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync
[2012.07.14 14:15:55 | 000,000,000 | ---D | C] -- C:\Program Files\NTFS Undelete
[2012.07.13 00:26:35 | 000,123,648 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bmdm.sys
[2012.07.13 00:26:35 | 000,014,848 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bmdfl.sys
[2012.07.13 00:26:35 | 000,012,416 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bcmnt.sys
[2012.07.13 00:26:35 | 000,012,416 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bcm.sys
[2012.07.13 00:26:34 | 000,098,432 | ---- | C] (MCCI) -- C:\WINDOWS\System32\drivers\ss_bbus.sys
[2012.07.13 00:26:34 | 000,012,288 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bwhnt.sys
[2012.07.13 00:26:34 | 000,012,288 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bwh.sys
[2012.07.13 00:21:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2012.07.12 23:54:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Samsung_USB_Drivers
[2012.07.12 23:54:20 | 000,238,952 | ---- | C] (Teruten) -- C:\WINDOWS\System32\FsUsbExService.Exe
[2012.07.12 23:53:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Samsung
[2012.07.12 23:51:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Samsung New PC Studio
[2012.07.12 23:51:27 | 000,000,000 | ---D | C] -- C:\Program Files\MarkAny
[2012.07.12 23:48:29 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
[2012.07.12 10:02:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\panda2_0dn
[2012.07.10 04:48:18 | 000,039,656 | ---- | C] (AnchorFree Inc.) -- C:\WINDOWS\System32\drivers\HssDrv.sys
[2012.07.10 04:48:16 | 000,033,512 | ---- | C] (AnchorFree Inc) -- C:\WINDOWS\System32\drivers\taphss.sys
[2012.07.05 18:56:44 | 000,000,000 | ---D | C] -- C:\Program Files\intellidownload

========== Files - Modified Within 30 Days ==========

[2012.08.02 22:31:34 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.08.02 22:31:17 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012.08.02 22:31:10 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012.08.02 22:24:22 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
[2012.08.02 21:43:00 | 000,001,016 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-789336058-682003330-1911654220-1003UA.job
[2012.08.02 21:38:00 | 000,000,924 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.08.02 19:52:32 | 000,218,624 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.08.02 16:59:33 | 000,000,920 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.08.02 16:59:31 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-789336058-682003330-1911654220-1003.job
[2012.08.02 16:59:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.08.02 16:58:59 | 1072,484,352 | -HS- | M] () -- C:\hiberfil.sys
[2012.08.02 16:15:28 | 000,000,512 | ---- | M] () -- C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task 4b83e826-b66b-4c25-9bf1-1aac2c83c8c6.job
[2012.08.02 16:15:27 | 000,000,512 | ---- | M] () -- C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task a6a1b682-9ce2-4a4d-b479-0de486ead8f4.job
[2012.08.02 16:08:45 | 000,002,445 | ---- | M] () -- C:\Documents and Settings\User\My Documents\HiJackThis.lnk
[2012.08.02 15:48:17 | 000,464,491 | ---- | M] () -- C:\Documents and Settings\User\My Documents\RootRepeal.zip
[2012.08.02 15:45:44 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\User\My Documents\dds.pif
[2012.08.02 13:43:45 | 000,002,279 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Google Chrome.lnk
[2012.08.02 13:43:45 | 000,002,255 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012.08.02 13:43:00 | 000,000,964 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-789336058-682003330-1911654220-1003Core.job
[2012.08.02 13:08:01 | 000,000,874 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 5.lnk
[2012.08.02 12:38:36 | 000,000,736 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012.08.02 09:39:56 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.08.01 19:11:59 | 000,001,839 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Live Messenger.lnk
[2012.08.01 17:02:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-682003330-1911654220-1003.job
[2012.07.31 20:37:57 | 000,517,744 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.07.31 20:34:59 | 000,000,736 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.msn
[2012.07.31 20:32:45 | 000,538,858 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.07.31 20:32:45 | 000,092,120 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.07.31 19:12:04 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012.07.31 12:06:06 | 000,000,305 | ---- | M] () -- C:\WINDOWS\System32\secushr.dat
[2012.07.31 11:35:58 | 000,000,025 | ---- | M] () -- C:\WINDOWS\libem.INI
[2012.07.31 10:25:58 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012.07.26 11:50:18 | 000,000,339 | RHS- | M] () -- C:\boot.ini
[2012.07.25 23:36:40 | 000,000,396 | ---- | M] () -- C:\Documents and Settings\User\Desktop\SBB.lnk
[2012.07.25 17:25:16 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2012.07.25 17:25:16 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2012.07.25 17:06:05 | 000,000,874 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2012.07.24 22:11:50 | 000,033,512 | ---- | M] (AnchorFree Inc) -- C:\WINDOWS\System32\drivers\taphss.sys
[2012.07.24 17:57:37 | 000,000,904 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to cirilica-latinica-latinica-cirilica-konvertor.lnk
[2012.07.22 12:49:56 | 000,010,584 | ---- | M] () -- C:\Documents and Settings\User\Application Data\docXConverter (3).ini
[2012.07.22 12:26:55 | 000,000,132 | -H-- | M] () -- C:\Documents and Settings\User\Application Data\lakerda1967.sys
[2012.07.22 12:19:38 | 000,360,580 | ---- | M] (eSellerate Inc.) -- C:\WINDOWS\eSellerateEngine.dll
[2012.07.18 12:58:29 | 000,000,038 | ---- | M] () -- C:\WINDOWS\AviSplitter.INI
[2012.07.16 00:10:23 | 000,000,442 | RHS- | M] () -- C:\Documents and Settings\User\ntuser.pol
[2012.07.15 21:50:13 | 000,000,376 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2012.07.12 23:57:14 | 000,002,898 | ---- | M] () -- C:\aqua_bitmap.cpp
[2012.07.12 23:56:12 | 000,001,801 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung New PC Studio.lnk
[2012.07.12 23:53:46 | 000,002,528 | ---- | M] () -- C:\Documents and Settings\User\Application Data\$_hpcst$.hpc
[2012.07.12 23:53:36 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2012.07.10 04:48:18 | 000,039,656 | ---- | M] (AnchorFree Inc.) -- C:\WINDOWS\System32\drivers\HssDrv.sys
[2012.07.08 12:09:33 | 000,000,053 | ---- | M] () -- C:\WINDOWS\popcinfo.dat
[2012.07.08 11:09:39 | 000,001,188 | ---- | M] () -- C:\WINDOWS\WINCMD.INI
[2012.07.05 22:07:08 | 000,143,872 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2012.07.05 22:06:48 | 000,227,760 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2012.07.05 22:06:30 | 000,772,544 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npdeployJava1.dll
[2012.07.05 22:06:20 | 000,687,544 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll

========== Files Created - No Company Name ==========

[2012.08.02 16:15:28 | 000,000,512 | ---- | C] () -- C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task 4b83e826-b66b-4c25-9bf1-1aac2c83c8c6.job
[2012.08.02 16:15:27 | 000,000,512 | ---- | C] () -- C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task a6a1b682-9ce2-4a4d-b479-0de486ead8f4.job
[2012.08.02 16:08:34 | 000,002,445 | ---- | C] () -- C:\Documents and Settings\User\My Documents\HiJackThis.lnk
[2012.08.02 15:48:16 | 000,464,491 | ---- | C] () -- C:\Documents and Settings\User\My Documents\RootRepeal.zip
[2012.08.02 13:43:45 | 000,002,279 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Google Chrome.lnk
[2012.08.02 13:43:45 | 000,002,255 | ---- | C] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012.08.02 13:38:49 | 000,001,016 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-789336058-682003330-1911654220-1003UA.job
[2012.08.02 13:38:48 | 000,000,964 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-789336058-682003330-1911654220-1003Core.job
[2012.08.02 13:08:01 | 000,000,874 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 5.lnk
[2012.08.01 19:11:59 | 000,001,839 | ---- | C] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Live Messenger.lnk
[2012.08.01 15:28:05 | 000,002,563 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Excel.lnk
[2012.07.31 21:24:43 | 1072,484,352 | -HS- | C] () -- C:\hiberfil.sys
[2012.07.31 12:06:06 | 000,000,305 | ---- | C] () -- C:\WINDOWS\System32\secushr.dat
[2012.07.31 11:35:58 | 000,000,025 | ---- | C] () -- C:\WINDOWS\libem.INI
[2012.07.31 10:36:26 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012.07.31 10:25:58 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012.07.31 10:25:52 | 000,001,830 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2012.07.26 11:50:17 | 000,000,223 | ---- | C] () -- C:\Boot.bak
[2012.07.26 11:50:12 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012.07.25 23:36:39 | 000,000,396 | ---- | C] () -- C:\Documents and Settings\User\Desktop\SBB.lnk
[2012.07.25 17:06:05 | 000,000,874 | ---- | C] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk
[2012.07.22 12:19:38 | 000,000,132 | -H-- | C] () -- C:\Documents and Settings\User\Application Data\lakerda1967.sys
[2012.07.22 12:19:06 | 000,010,584 | ---- | C] () -- C:\Documents and Settings\User\Application Data\docXConverter (3).ini
[2012.07.21 16:34:52 | 000,000,276 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-789336058-682003330-1911654220-1003.job
[2012.07.21 16:34:50 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-682003330-1911654220-1003.job
[2012.07.15 22:36:16 | 000,000,904 | ---- | C] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to cirilica-latinica-latinica-cirilica-konvertor.lnk
[2012.07.12 23:57:14 | 000,002,898 | ---- | C] () -- C:\aqua_bitmap.cpp
[2012.07.12 23:56:12 | 000,001,801 | ---- | C] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung New PC Studio.lnk
[2012.07.12 23:54:20 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2012.07.12 23:54:20 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2012.07.12 23:53:46 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\User\Application Data\$_hpcst$.hpc
[2012.04.30 20:20:01 | 000,004,998 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\mtbjfghn.xbe
[2012.02.01 16:47:46 | 000,000,025 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2011.09.06 09:56:02 | 000,454,656 | ---- | C] () -- C:\WINDOWS\System32\PaintX.dll
[2011.09.06 09:56:02 | 000,157,696 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2011.09.06 09:56:02 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\vbpng.dll
[2011.09.06 09:56:02 | 000,072,192 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2011.08.05 21:56:01 | 000,000,193 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011.03.10 23:15:28 | 001,511,424 | ---- | C] () -- C:\WINDOWS\System32\HP1100SM.EXE
[2011.03.10 23:15:28 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\HP1100LM.DLL
[2011.03.10 23:14:10 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\mvusbews.dll
[2011.03.10 23:14:06 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\HP1100SMs.dll
[2011.03.10 23:13:53 | 000,284,160 | ---- | C] () -- C:\WINDOWS\System32\mvhlewsi.dll
[2011.02.22 23:09:02 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2011.02.04 13:28:55 | 000,758,018 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011.02.04 13:28:55 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010.10.21 22:07:21 | 000,000,026 | ---- | C] () -- C:\WINDOWS\WAR2R.INI
[2010.09.07 20:26:21 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2009.09.01 17:01:24 | 000,000,448 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2009.08.08 17:51:07 | 000,000,442 | RHS- | C] () -- C:\Documents and Settings\User\ntuser.pol
[2009.06.02 20:18:06 | 000,024,640 | ---- | C] () -- C:\Program Files\Common Files\security
[2009.03.27 20:43:14 | 000,000,034 | ---- | C] () -- C:\Documents and Settings\User\import.sw
[2009.03.27 20:41:59 | 000,000,091 | ---- | C] () -- C:\Documents and Settings\User\merc.sw
[2009.03.27 20:40:03 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\User\weapon.sw
[2009.03.27 20:39:12 | 000,000,030 | ---- | C] () -- C:\Documents and Settings\User\pilot.sw
[2009.02.23 19:21:27 | 000,000,002 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\_chk2024200
[2009.02.18 20:19:44 | 000,019,202 | ---- | C] () -- C:\Documents and Settings\User\game_save.sav
[2009.01.19 17:44:25 | 000,001,536 | ---- | C] () -- C:\Documents and Settings\User\SLOVA.TPS
[2009.01.19 17:44:25 | 000,001,280 | ---- | C] () -- C:\Documents and Settings\User\TEKSTOVI.TPS
[2009.01.19 17:44:25 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\User\Tekst.asm
[2008.12.28 16:58:23 | 000,000,162 | ---- | C] () -- C:\Documents and Settings\User\PressReaderConfig.xml
[2008.11.01 14:26:32 | 000,005,773 | ---- | C] () -- C:\Documents and Settings\User\DDP
[2008.08.30 18:59:47 | 000,218,624 | ---- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2002.07.01 16:13:30 | 000,000,218 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\databack.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >



mycity.rs/must-login.png

offline
  • Pridružio: 04 Jul 2011
  • Poruke: 5424

Arrow Tvoj problem nije prouzrokovan malware-om. Za dalju pomoć oko rešavanja problema obrati se u Windows potforum.


Arrow Preporucujem ti da instaliras Service Pack 3 za Windows XP tj. update-ujes svoj Operativni Sistem. Necu govoriti o njegovim prednostima u odnosu na Service Pack 2. Te informacije mozes naci na MS-ovom sajtu. Uglavnom, MS je 13.jula 2010 prekinuo podrsku za Service Pack 2 koji je instaliran na tvom racunaru.

Sta to znaci? Pogledaj link: http://windows.microsoft.com/en-US/windows/help/what-does-end-of-support-mean;

**** Ukoliko se odlucis na ovaj korak (instaliranje SP3), preporucujem ti da prethodno uradis backup svih bitnih podataka.



Ivance95 (AMF Tim)

Ko je trenutno na forumu
 

Ukupno su 785 korisnika na forumu :: 8 registrovanih, 1 sakriven i 776 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: amaterSRB, Djole, esx66, Lazarus, Parker, suton, uruk, zziko