И един мой познат има този проблем и ме помоли за помощ след малко ще пусна лога.
едит
<code>
OTL logfile created on: 15.12.2009 г. 22:16:50 - Run 1
OTL by OldTimer - Version 3.1.17.0 Folder = C:\Documents and Settings\User\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'
1,99 Gb Total Physical Memory | 1,36 Gb Available Physical Memory | 68,11% Memory free
3,84 Gb Paging File | 3,39 Gb Available in Paging File | 88,17% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29,29 Gb Total Space | 8,69 Gb Free Space | 29,66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: VENCI
Current User Name: User
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\navxphyxqdrwhshuprjb.exe ()
PRC - C:\Documents and Settings\User\Local Settings\Temp\cagtw.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
PRC - C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Technologies)
PRC - C:\Program Files\CyberLink\Shared Files\brs.exe (cyberlink)
PRC - C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
PRC - C:\Program Files\TeamViewer\Version4\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil_.exe (IVT Corporation.)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLSched.exe ()
PRC - C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapSvc.exe ()
PRC - C:\Program Files\Lenovo\ShuttleCenter\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\ATK Hotkey\HControl.exe (ATK0100)
PRC - C:\Program Files\ATK Hotkey\ATKOSD.exe ()
PRC - C:\Program Files\ATK Hotkey\WDC.exe ()
PRC - C:\Program Files\Lenovo\EnergyCut\utilty.exe (Lenovo(Beijing)Limited)
PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe (Lenovo (Beijing) Limited)
PRC - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\TeamViewer\Version4\TV.dll (TeamViewer GmbH)
MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)
MOD - C:\Program Files\Lenovo\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\WINDOWS\system32\serwvdrv.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\umdmxfrm.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Adobe LM Service) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe ()
SRV - (NMSAccessU) -- C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (CLSched) CyberLink Task Scheduler (CTS) -- C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLSched.exe ()
SRV - (CLCapSvc) CyberLink Background Capture Service (CBCS) -- C:\Program Files\Lenovo\ShuttleCenter\Kernel\TV\CLCapSvc.exe ()
SRV - (RichVideo) Cyberlink RichVideo Service(CRVS) -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (odserv) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (SQLWriter) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (MSSQL$SONY_MEDIAMGR2) SQL Server (SONY_MEDIAMGR2) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLBrowser) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (btwdins) -- C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (NBService) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (MSSQLServerADHelper) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - ({B154377D-700F-42cc-9474-23858FBDF4BD}) -- C:\Program Files\CyberLink\PowerDVD9\000.fcl (CyberLink Corp.)
DRV - (pcouffin) -- C:\WINDOWS\system32\drivers\pcouffin.sys (VSO Software)
DRV - (Partcsvciwm) -- C:\WINDOWS\system32\drivers\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Cam5607) -- C:\WINDOWS\system32\drivers\BisonC07.sys (Bison Electronics. Inc. )
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (MTsensor) -- C:\WINDOWS\system32\drivers\ATKACPI.sys ()
DRV - (ACPIVPC) -- C:\WINDOWS\system32\drivers\AcpiVpc.sys (Lenovo Corporation)
DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (ialm) -- C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (NETw4x32) Intel® -- C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (BlueletAudio) -- C:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation.)
DRV - (Btcsrusb) -- C:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation.)
DRV - (rismxdp) -- C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (BlueletSCOAudio) -- C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys (IVT Corporation.)
DRV - (BT) -- C:\WINDOWS\system32\drivers\btnetdrv.sys (IVT Corporation.)
DRV - (VHidMinidrv) -- C:\WINDOWS\system32\drivers\VHIDMini.sys (IVT Corporation.)
DRV - (BTHidMgr) -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation.)
DRV - (BTHidEnum) -- C:\WINDOWS\System32\Drivers\vbtenum.sys (IVT Corporation.)
DRV - (VcommMgr) -- C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation.)
DRV - (VComm) -- C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation.)
DRV - (rimmptsk) -- C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) -- C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (smserial) -- C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (BTNetFilter) -- C:\Program Files\IVT Corporation\BlueSoleil\device\Win2k\BTNetFilter.sys (IVT Corporation.)
DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ROOTMODEM) -- C:\WINDOWS\system32\drivers\rootmdm.sys (Microsoft Corporation)
DRV - (MODEMCSA) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-602162358-746137067-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-602162358-746137067-725345543-1003\S-1-5-21-602162358-746137067-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008.12.14 16:54:22 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009.12.15 21:10:46 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009.12.05 22:10:27 | 00,000,000 | ---D | M]
[2008.07.05 17:32:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2009.11.19 18:30:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\sx0vchhp.default\extensions
[2009.12.08 21:25:49 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [amghypfdvhuyisgsmne] C:\Documents and Settings\User\Local Settings\Temp\zizxlzmhwfpqxepy.exe ()
O4 - HKLM..\Run: [ATKHOTKEY] C:\Program Files\ATK Hotkey\Hcontrol.exe (ATK0100)
O4 - HKLM..\Run: [bDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe (cyberlink)
O4 - HKLM..\Run: [bluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [EnergyCut] C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe (Lenovo (Beijing) Limited)
O4 - HKLM..\Run: [EnergyUtility] C:\Program Files\Lenovo\EnergyCut\utilty.exe (Lenovo(Beijing)Limited)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Lenovo\ShuttleCenter\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PDVD9LanguageShortcut] C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [qwkfqbldpvcae] C:\WINDOWS\System32\pattjzolcnzcluhsll.exe ()
O4 - HKLM..\Run: [RemoteControl9] C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [sMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-602162358-746137067-725345543-1003..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\S-1-5-21-602162358-746137067-725345543-1003..\Run: [DriverCure] C:\Program Files\ParetoLogic\DriverCure\DriverCure.exe File not found
O4 - HKU\S-1-5-21-602162358-746137067-725345543-1003..\Run: [Power2GoExpress] File not found
O4 - HKU\S-1-5-21-602162358-746137067-725345543-1003..\Run: [qwkfqbldpvcae] C:\Documents and Settings\User\Local Settings\Temp\gqihwlzvlvgiqykum.exe ()
O4 - HKU\S-1-5-21-602162358-746137067-725345543-1003..\Run: [zizxlzmhwfpqxepy] C:\WINDOWS\System32\cqmpibttnbqwiukyuxqjb.exe ()
O4 - HKLM..\RunOnce: [pattjzolcnzcluhsll] C:\Documents and Settings\User\Local Settings\Temp\zizxlzmhwfpqxepy.exe ()
O4 - HKLM..\RunOnce: [rynjvhslyfnmrw] C:\WINDOWS\System32\gqihwlzvlvgiqykum.exe ()
O4 - HKU\S-1-5-21-602162358-746137067-725345543-1003..\RunOnce: [gqihwlzvlvgiqykum] C:\WINDOWS\System32\zizxlzmhwfpqxepy.exe ()
O4 - HKU\S-1-5-21-602162358-746137067-725345543-1003..\RunOnce: [rynjvhslyfnmrw] C:\Documents and Settings\User\Local Settings\Temp\cqmpibttnbqwiukyuxqjb.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: ucspcpbvjraagmw = zizxlzmhwfpqxepy.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: rwjdnxgxintq = C:\DOCUME~1\User\LOCALS~1\Temp\gqihwlzvlvgiqykum.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-602162358-746137067-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1
O7 - HKU\S-1-5-21-602162358-746137067-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.07.05 16:46:22 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009.12.15 21:40:08 | 00,000,836 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{2ca14044-4ab7-11dd-811a-806d6172696f}\Shell\AutoRun\command - "" = C:\uykdmvdtdhm.bat -- [2009.12.15 21:40:07 | 00,999,424 | RHS- | M] ()
O33 - MountPoints2\{2ca14044-4ab7-11dd-811a-806d6172696f}\Shell\explore\Command - "" = C:\ucspcpbvjraagmw.bat -- [2009.04.04 12:02:31 | 00,999,424 | RHS- | M] ()
O33 - MountPoints2\{2ca14044-4ab7-11dd-811a-806d6172696f}\Shell\open\Command - "" = C:\qwkfqbldpvcae.bat -- [2009.07.08 06:38:03 | 00,999,424 | RHS- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008.07.05 19:26:42 | 00,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - C:\WINDOWS\system32\irmon.dll (Microsoft Corporation)
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ==========
[2009.12.15 22:14:53 | 00,538,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
[2009.12.15 21:58:46 | 04,844,296 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\User\Desktop\mbam-setup.exe
[2009.12.15 21:34:39 | 00,000,000 | ---D | C] -- C:\Bluetooth
[2009.12.06 22:14:58 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2009.11.27 20:57:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\Аз бях екстрасенс
[2009.11.27 18:25:13 | 00,000,000 | ---D | C] -- C:\RATATOUILLE
[2009.11.19 17:04:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\New Folder
[2009.11.16 14:36:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\Trailers
[2009.11.16 14:11:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\HandBrake
[2009.11.16 14:11:15 | 00,000,000 | ---D | C] -- C:\Program Files\HandBrake
[2008.11.23 00:31:13 | 00,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\User\Application Data\pcouffin.sys
[2008.11.03 20:35:35 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008.10.30 00:42:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008.07.05 16:50:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008.07.05 16:46:20 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2009.12.15 22:18:29 | 00,002,402 | -H-- | M] () -- C:\WINDOWS\zcnfnvcradhcdejmxpxfmbknrmnotwhz.pwl
[2009.12.15 22:18:29 | 00,002,402 | -H-- | M] () -- C:\WINDOWS\System32\zcnfnvcradhcdejmxpxfmbknrmnotwhz.pwl
[2009.12.15 22:18:29 | 00,002,402 | -H-- | M] () -- C:\Program Files\zcnfnvcradhcdejmxpxfmbknrmnotwhz.pwl
[2009.12.15 22:18:29 | 00,002,402 | -H-- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\zcnfnvcradhcdejmxpxfmbknrmnotwhz.pwl
[2009.12.15 22:18:29 | 00,000,272 | -H-- | M] () -- C:\WINDOWS\System32\dwxfdbydcvparidwxfdbyd.vpa
[2009.12.15 22:18:29 | 00,000,272 | -H-- | M] () -- C:\WINDOWS\dwxfdbydcvparidwxfdbyd.vpa
[2009.12.15 22:18:29 | 00,000,272 | -H-- | M] () -- C:\Program Files\dwxfdbydcvparidwxfdbyd.vpa
[2009.12.15 22:18:29 | 00,000,272 | -H-- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\dwxfdbydcvparidwxfdbyd.vpa
[2009.12.15 22:18:24 | 00,001,320 | -H-- | M] () -- C:\WINDOWS\System32\qwkfqbldpvcaeiqwkfqbldpvcaeiqwkfqbl.pvc
[2009.12.15 22:18:24 | 00,001,320 | -H-- | M] () -- C:\WINDOWS\qwkfqbldpvcaeiqwkfqbldpvcaeiqwkfqbl.pvc
[2009.12.15 22:18:24 | 00,001,320 | -H-- | M] () -- C:\Program Files\qwkfqbldpvcaeiqwkfqbldpvcaeiqwkfqbl.pvc
[2009.12.15 22:18:24 | 00,001,320 | -H-- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\qwkfqbldpvcaeiqwkfqbldpvcaeiqwkfqbl.pvc
[2009.12.15 22:17:40 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\zizxlzmhwfpqxepy.exe
[2009.12.15 22:17:40 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\tifjdxqrmbrylypebfztmn.exe
[2009.12.15 22:17:40 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\pattjzolcnzcluhsll.exe
[2009.12.15 22:17:40 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\navxphyxqdrwhshuprjb.exe
[2009.12.15 22:17:40 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\gqihwlzvlvgiqykum.exe
[2009.12.15 22:17:40 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\cqmpibttnbqwiukyuxqjb.exe
[2009.12.15 22:17:40 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\amghypfdvhuyisgsmne.exe
[2009.12.15 22:15:48 | 04,456,448 | -H-- | M] () -- C:\Documents and Settings\User\NTUSER.DAT
[2009.12.15 22:14:57 | 00,538,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
[2009.12.15 21:55:38 | 04,844,296 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\User\Desktop\mbam-setup.exe
[2009.12.15 21:42:01 | 00,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009.12.15 21:40:08 | 00,000,836 | RHS- | M] () -- C:\autorun.inf
[2009.12.15 21:40:07 | 00,999,424 | RHS- | M] () -- C:\uykdmvdtdhm.bat
[2009.12.15 21:39:15 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\System32\zizxlzmhwfpqxepy.exe
[2009.12.15 21:39:15 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\System32\tifjdxqrmbrylypebfztmn.exe
[2009.12.15 21:39:15 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\System32\pattjzolcnzcluhsll.exe
[2009.12.15 21:39:15 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\System32\cqmpibttnbqwiukyuxqjb.exe
[2009.12.15 21:39:15 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\System32\amghypfdvhuyisgsmne.exe
[2009.12.15 21:39:10 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009.12.15 21:39:08 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009.12.15 21:38:24 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\User\ntuser.ini
[2009.12.15 21:36:11 | 00,000,203 | -H-- | M] () -- C:\WINDOWS\System32\rynjvhslyfnmrwfmbxjvgzmtbafktaplxjun.hpo
[2009.12.15 21:36:11 | 00,000,203 | -H-- | M] () -- C:\WINDOWS\rynjvhslyfnmrwfmbxjvgzmtbafktaplxjun.hpo
[2009.12.15 21:36:11 | 00,000,203 | -H-- | M] () -- C:\Program Files\rynjvhslyfnmrwfmbxjvgzmtbafktaplxjun.hpo
[2009.12.15 21:36:11 | 00,000,203 | -H-- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\rynjvhslyfnmrwfmbxjvgzmtbafktaplxjun.hpo
[2009.12.15 21:34:21 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\System32\gqihwlzvlvgiqykum.exe
[2009.12.15 21:33:18 | 04,809,296 | -H-- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\IconCache.db
[2009.12.15 21:22:16 | 00,999,424 | RHS- | M] () -- C:\WINDOWS\System32\navxphyxqdrwhshuprjb.exe
[2009.12.15 21:20:31 | 00,004,088 | -H-- | M] () -- C:\WINDOWS\uykdmvdtdhmikmswibktbrbfkgikqugzi.zpz
[2009.12.15 21:20:31 | 00,004,088 | -H-- | M] () -- C:\WINDOWS\System32\uykdmvdtdhmikmswibktbrbfkgikqugzi.zpz
[2009.12.15 21:20:31 | 00,004,088 | -H-- | M] () -- C:\Program Files\uykdmvdtdhmikmswibktbrbfkgikqugzi.zpz
[2009.12.15 21:20:31 | 00,004,088 | -H-- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\uykdmvdtdhmikmswibktbrbfkgikqugzi.zpz
[2009.12.15 21:00:54 | 00,479,398 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009.12.15 21:00:54 | 00,085,528 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009.12.15 21:00:53 | 00,575,012 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009.12.15 20:58:10 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009.12.15 20:50:45 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009.12.08 01:24:08 | 00,000,668 | ---- | M] () -- C:\Documents and Settings\User\Application Data\vso_ts_preview.xml
[2009.12.06 00:33:49 | 00,000,414 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Update Version2.job
[2009.12.04 18:00:00 | 00,000,440 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Registration.job
[2009.11.27 18:24:04 | 00,000,550 | ---- | M] () -- C:\Documents and Settings\User\Application Data\AutoGK.ini
[2009.11.19 17:12:51 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009.11.17 00:34:46 | 02,238,079 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Logo Infinity Black RGBth.psd
[2009.11.16 14:51:30 | 01,011,264 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009.11.16 14:11:17 | 00,000,694 | ---- | M] () -- C:\Documents and Settings\User\Desktop\HandBrake.lnk
[2009.11.16 14:10:56 | 06,529,156 | ---- | M] () -- C:\Documents and Settings\User\Desktop\HandBrake-0.9.3-Win_GUI.exe
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2009.12.15 21:20:52 | 00,000,836 | RHS- | C] () -- C:\autorun.inf
[2009.12.15 21:20:39 | 00,002,408 | -H-- | C] () -- C:\WINDOWS\zcnfnvcradhcdejmxpxfmbknrmnotwhz.pwl
[2009.12.15 21:20:39 | 00,002,408 | -H-- | C] () -- C:\WINDOWS\System32\zcnfnvcradhcdejmxpxfmbknrmnotwhz.pwl
[2009.12.15 21:20:39 | 00,002,408 | -H-- | C] () -- C:\Program Files\zcnfnvcradhcdejmxpxfmbknrmnotwhz.pwl
[2009.12.15 21:20:39 | 00,002,408 | -H-- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\zcnfnvcradhcdejmxpxfmbknrmnotwhz.pwl
[2009.12.15 21:20:39 | 00,001,320 | -H-- | C] () -- C:\WINDOWS\System32\qwkfqbldpvcaeiqwkfqbldpvcaeiqwkfqbl.pvc
[2009.12.15 21:20:39 | 00,001,320 | -H-- | C] () -- C:\WINDOWS\qwkfqbldpvcaeiqwkfqbldpvcaeiqwkfqbl.pvc
[2009.12.15 21:20:39 | 00,001,320 | -H-- | C] () -- C:\Program Files\qwkfqbldpvcaeiqwkfqbldpvcaeiqwkfqbl.pvc
[2009.12.15 21:20:39 | 00,001,320 | -H-- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\qwkfqbldpvcaeiqwkfqbldpvcaeiqwkfqbl.pvc
[2009.12.15 21:20:39 | 00,000,203 | -H-- | C] () -- C:\WINDOWS\System32\rynjvhslyfnmrwfmbxjvgzmtbafktaplxjun.hpo
[2009.12.15 21:20:39 | 00,000,203 | -H-- | C] () -- C:\WINDOWS\rynjvhslyfnmrwfmbxjvgzmtbafktaplxjun.hpo
[2009.12.15 21:20:39 | 00,000,203 | -H-- | C] () -- C:\Program Files\rynjvhslyfnmrwfmbxjvgzmtbafktaplxjun.hpo
[2009.12.15 21:20:39 | 00,000,203 | -H-- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\rynjvhslyfnmrwfmbxjvgzmtbafktaplxjun.hpo
[2009.12.15 21:20:31 | 00,004,088 | -H-- | C] () -- C:\WINDOWS\uykdmvdtdhmikmswibktbrbfkgikqugzi.zpz
[2009.12.15 21:20:31 | 00,004,088 | -H-- | C] () -- C:\WINDOWS\System32\uykdmvdtdhmikmswibktbrbfkgikqugzi.zpz
[2009.12.15 21:20:31 | 00,004,088 | -H-- | C] () -- C:\Program Files\uykdmvdtdhmikmswibktbrbfkgikqugzi.zpz
[2009.12.15 21:20:31 | 00,004,088 | -H-- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\uykdmvdtdhmikmswibktbrbfkgikqugzi.zpz
[2009.12.15 21:20:31 | 00,000,272 | -H-- | C] () -- C:\WINDOWS\System32\dwxfdbydcvparidwxfdbyd.vpa
[2009.12.15 21:20:31 | 00,000,272 | -H-- | C] () -- C:\WINDOWS\dwxfdbydcvparidwxfdbyd.vpa
[2009.12.15 21:20:31 | 00,000,272 | -H-- | C] () -- C:\Program Files\dwxfdbydcvparidwxfdbyd.vpa
[2009.12.15 21:20:31 | 00,000,272 | -H-- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\dwxfdbydcvparidwxfdbyd.vpa
[2009.12.15 21:20:20 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\tifjdxqrmbrylypebfztmn.exe
[2009.12.15 21:20:20 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\pattjzolcnzcluhsll.exe
[2009.12.15 21:20:20 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\navxphyxqdrwhshuprjb.exe
[2009.12.15 21:20:20 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\gqihwlzvlvgiqykum.exe
[2009.12.15 21:20:20 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\cqmpibttnbqwiukyuxqjb.exe
[2009.12.15 21:20:20 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\amghypfdvhuyisgsmne.exe
[2009.12.15 21:20:19 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\zizxlzmhwfpqxepy.exe
[2009.12.15 21:20:19 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\System32\zizxlzmhwfpqxepy.exe
[2009.12.15 21:20:19 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\System32\tifjdxqrmbrylypebfztmn.exe
[2009.12.15 21:20:19 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\System32\pattjzolcnzcluhsll.exe
[2009.12.15 21:20:19 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\System32\navxphyxqdrwhshuprjb.exe
[2009.12.15 21:20:19 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\System32\gqihwlzvlvgiqykum.exe
[2009.12.15 21:20:19 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\System32\cqmpibttnbqwiukyuxqjb.exe
[2009.12.15 21:20:19 | 00,999,424 | RHS- | C] () -- C:\WINDOWS\System32\amghypfdvhuyisgsmne.exe
[2009.11.17 00:34:42 | 02,238,079 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Logo Infinity Black RGBth.psd
[2009.11.16 14:11:17 | 00,000,694 | ---- | C] () -- C:\Documents and Settings\User\Desktop\HandBrake.lnk
[2009.11.16 14:10:31 | 06,529,156 | ---- | C] () -- C:\Documents and Settings\User\Desktop\HandBrake-0.9.3-Win_GUI.exe
[2009.06.23 23:14:45 | 00,000,150 | ---- | C] () -- C:\WINDOWS\AoADVDRipper.INI
[2008.11.23 00:31:35 | 00,000,668 | ---- | C] () -- C:\Documents and Settings\User\Application Data\vso_ts_preview.xml
[2008.11.23 00:31:27 | 00,000,034 | ---- | C] () -- C:\Documents and Settings\User\Application Data\pcouffin.log
[2008.11.23 00:31:13 | 00,087,608 | ---- | C] () -- C:\Documents and Settings\User\Application Data\inst.exe
[2008.11.23 00:31:13 | 00,007,887 | ---- | C] () -- C:\Documents and Settings\User\Application Data\pcouffin.cat
[2008.11.23 00:31:13 | 00,001,144 | ---- | C] () -- C:\Documents and Settings\User\Application Data\pcouffin.inf
[2008.09.18 22:50:52 | 00,012,288 | ---- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.09.01 15:31:24 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.07.05 18:27:41 | 00,000,550 | ---- | C] () -- C:\Documents and Settings\User\Application Data\AutoGK.ini
[2008.07.05 17:22:51 | 00,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2008.07.05 17:18:14 | 00,015,190 | ---- | C] () -- C:\WINDOWS\M3000Twn.ini
[2008.07.05 17:03:53 | 00,910,464 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll
[2008.07.05 17:03:53 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4847.dll
[2008.05.28 01:16:44 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\NormalizeDSP.dll
[2007.08.24 10:46:48 | 00,005,760 | ---- | C] () -- C:\WINDOWS\System32\drivers\ATKACPI.sys
[2007.07.25 15:24:28 | 00,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007.03.10 13:51:48 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2006.11.11 20:50:38 | 00,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2006.11.06 06:30:38 | 00,262,144 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2006.10.21 19:59:59 | 00,262,144 | ---- | C] () -- C:\WINDOWS\System32\Manipulate.dll
[2006.09.25 03:53:56 | 00,268,242 | ---- | C] () -- C:\WINDOWS\System32\erdmpg-parse.dll
[2006.09.25 03:53:44 | 02,518,779 | ---- | C] () -- C:\WINDOWS\System32\erdmpg-enc.dll
[2006.09.25 03:52:06 | 00,030,693 | ---- | C] () -- C:\WINDOWS\System32\erdmpg-int.dll
[2005.10.15 05:10:24 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\comLyricGetter.dll
[2005.02.17 10:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005.02.17 10:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2004.02.01 21:21:56 | 00,097,280 | ---- | C] () -- C:\WINDOWS\System32\Uncommon.dll
[2002.10.16 00:54:04 | 00,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2001.11.14 11:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
========== LOP Check ==========
[2008.11.11 16:44:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bitstream Font Navigator
[2009.01.29 22:42:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bluetooth
[2009.12.15 21:00:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverCure
[2008.07.05 17:46:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2009.05.14 15:59:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2008.07.05 19:35:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
[2009.11.05 00:27:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008.11.23 00:19:27 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{DE097E60-7F86-4350-B083-1F09B6906C92}
[2008.09.15 23:09:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Canneverbe_Limited
[2008.12.11 21:01:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\CoSoSys
[2009.05.14 16:00:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\DriverCure
[2008.07.05 17:47:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\ESET
[2008.07.05 19:57:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Publish Providers
[2008.07.05 19:57:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Sony
[2008.07.05 19:01:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Sony Setup
[2009.12.15 22:05:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\TeamViewer
[2009.12.15 22:12:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\uTorrent
[2009.12.08 00:31:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Vso
[2009.12.04 18:00:00 | 00,000,440 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Registration.job
[2009.12.06 00:33:49 | 00,000,414 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Update Version2.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
[2004.08.04 14:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008.04.14 02:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 02:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2004.08.04 14:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 02:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 02:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2004.08.04 14:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 02:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 02:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
< %SYSTEMDRIVE%\sceclt.dll /s /md5 >
< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >
< %SYSTEMDRIVE%\logevent.dll /s /md5 >
< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2004.08.03 21:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008.04.13 20:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.04 14:00:00 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2004.08.03 21:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys
< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >
< %SYSTEMDRIVE%\viasraid.sys /s /md5 >
< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2008.04.13 20:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >
< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >
< %SYSTEMDRIVE%\viamraid.sys /s /md5 >
< %SYSTEMDRIVE%\nvata.sys /s /md5 >
< %SYSTEMDRIVE%\nvgts.sys /s /md5 >
< %SYSTEMDRIVE%\explorer.exe /s /md5 >
[2008.04.14 02:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2007.06.13 13:26:03 | 01,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007.06.13 12:23:07 | 01,033,216 | ---- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004.08.04 14:00:00 | 01,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2008.04.14 02:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
< %SYSTEMDRIVE%\svchost.exe /s /md5 >
[2004.08.04 14:00:00 | 00,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2008.04.14 02:12:36 | 00,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 02:12:36 | 00,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\userinit.exe /s /md5 >
[2004.08.04 14:00:00 | 00,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008.04.14 02:12:38 | 00,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 02:12:38 | 00,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\qmgr.dll /s /md5 >
[2004.08.04 14:00:00 | 00,382,464 | ---- | M] (Microsoft Corporation) MD5=2C69EC7E5A311334D10DD95F338FCCEA -- C:\WINDOWS\$NtServicePackUninstall$\qmgr.dll
[2008.04.14 02:12:03 | 00,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\ServicePackFiles\i386\qmgr.dll
[2008.04.14 02:12:03 | 00,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\qmgr.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[2008.04.14 02:12:03 | 00,409,088 | ---- | M] (Microsoft Corporation) MD5=574738F61FCA2935F5265DC4E5691314 -- C:\WINDOWS\system32\bits\qmgr.dll
< %SYSTEMDRIVE%\ws2_32.dll /s /md5 >
[2004.08.04 14:00:00 | 00,082,944 | ---- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 02:12:10 | 00,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 02:12:10 | 00,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\proquota.exe /s /md5 >
[2004.08.04 14:00:00 | 00,050,176 | ---- | M] (Microsoft Corporation) MD5=4D9D45A4370E0C2AD00C362B7118E2A4 -- C:\WINDOWS\$NtServicePackUninstall$\proquota.exe
[2008.04.14 02:12:32 | 00,050,176 | ---- | M] (Microsoft Corporation) MD5=F6465A2EEF75468988A4FCF124148FA8 -- C:\WINDOWS\ServicePackFiles\i386\proquota.exe
[2008.04.14 02:12:32 | 00,050,176 | ---- | M] (Microsoft Corporation) MD5=F6465A2EEF75468988A4FCF124148FA8 -- C:\WINDOWS\system32\proquota.exe
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\iastorv.sys /s /md5 >
========== Alternate Data Streams ==========
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8CE646EE
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:30FD0CBD
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
< End of report >
</code>
В този случай, след инсталирането е изчезнала и ESET Smart Security. В директорията и има само два .dat файла