File mstime.dll received on 2010.07.27 13:22:51 (UTC)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Съжелявам за късния отговор..,но бях в отпуск.Продължавам по стъпките
Result: 0/42 (0%)
Loading server information...
Your file is queued in position: 5.
Estimated start time is between 78 and 112 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.
You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:
Antivirus Version Last Update Result
AhnLab-V3 2010.07.27.00 2010.07.26 -
AntiVir 8.2.4.26 2010.07.27 -
Antiy-AVL 2.0.3.7 2010.07.26 -
Authentium 5.2.0.5 2010.07.27 -
Avast 4.8.1351.0 2010.07.26 -
Avast5 5.0.332.0 2010.07.26 -
AVG 9.0.0.851 2010.07.27 -
BitDefender 7.2 2010.07.27 -
CAT-QuickHeal 11.00 2010.07.27 -
ClamAV 0.96.0.3-git 2010.07.27 -
Comodo 5556 2010.07.27 -
DrWeb 5.0.2.03300 2010.07.27 -
Emsisoft 5.0.0.34 2010.07.27 -
eSafe 7.0.17.0 2010.07.26 -
eTrust-Vet 36.1.7742 2010.07.27 -
F-Prot 4.6.1.107 2010.07.27 -
F-Secure 9.0.15370.0 2010.07.27 -
Fortinet 4.1.143.0 2010.07.24 -
GData 21 2010.07.27 -
Ikarus T3.1.1.84.0 2010.07.27 -
Jiangmin 13.0.900 2010.07.26 -
Kaspersky 7.0.0.125 2010.07.27 -
McAfee 5.400.0.1158 2010.07.27 -
McAfee-GW-Edition 2010.1 2010.07.27 -
Microsoft 1.6004 2010.07.27 -
NOD32 5316 2010.07.27 -
Norman 6.05.11 2010.07.27 -
nProtect 2010-07-27.01 2010.07.27 -
Panda 10.0.2.7 2010.07.27 -
PCTools 7.0.3.5 2010.07.27 -
Prevx 3.0 2010.07.27 -
Rising 22.58.01.04 2010.07.27 -
Sophos 4.55.0 2010.07.27 -
Sunbelt 6647 2010.07.27 -
SUPERAntiSpyware 4.40.0.1006 2010.07.27 -
Symantec 20101.1.1.7 2010.07.27 -
TheHacker 6.5.2.1.326 2010.07.27 -
TrendMicro 9.120.0.1004 2010.07.27 -
TrendMicro-HouseCall 9.120.0.1004 2010.07.27 -
VBA32 3.12.12.6 2010.07.27 -
ViRobot 2010.7.24.3958 2010.07.27 -
VirusBuster 5.0.27.0 2010.07.27 -
Additional information
File size: 532480 bytes
MD5...: e1a5918bd11d7d68f7770728182ea519
SHA1..: 2f5efa266b635a0b3eb87aa204c196fb0633dedf
SHA256: c8a833861cb508746eea69fe78a27155c6af9875eb31b003e5e246c2cbe4176f
ssdeep: 12288:GOJ2a0rcULOZRQMgqGC54DYhCG+drQOSqDLIpAeIfo:vEa0rcULOZRQFqd
4DYL+d8OvNe4
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x1382b
timedatestamp.....: 0x4802a182 (Mon Apr 14 00:12:50 2008)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x6eb21 0x6ec00 6.57 d1fb23b932c0a4aa49f7044f16439026
.orpc 0x70000 0x6b 0x200 1.75 9e2de71f8f7cdf4e1673ec8e5e292cfe
.data 0x71000 0x1e28 0x1c00 3.25 aed3ec88fecf3f145c0c1a61e48984c3
.rsrc 0x73000 0x91a0 0x9200 4.50 4f1413445b21ef205875dcb65c3fe0d7
.reloc 0x7d000 0x7eb2 0x8000 6.04 11c9d2cf857262edbc0869889e0f6d4f
( 12 imports )
> msvcrt.dll: __dllonexit, bsearch, _itow, wcscmp, _adjust_fdiv, malloc, _onexit, free, memmove, _wtoi, ceil, floor, _ftol, _HUGE, wcslen, _initterm, _except_handler3
> KERNEL32.dll: SetUnhandledExceptionFilter, GetProcessHeap, FreeLibraryAndExitThread, SetEvent, WaitForMultipleObjectsEx, CreateThread, GetProcAddress, GetVersionExA, WaitForSingleObjectEx, GlobalFree, GlobalHandle, GlobalSize, GlobalReAlloc, UnhandledExceptionFilter, IsBadReadPtr, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, VirtualFree, VirtualAlloc, HeapReAlloc, HeapFree, HeapAlloc, SetFilePointer, WriteFile, GetTimeZoneInformation, GetSystemTime, SystemTimeToFileTime, IsBadWritePtr, InterlockedExchange, ReadFile, GetLocalTime, DisableThreadLibraryCalls, HeapDestroy, lstrlenW, lstrcpyW, GetUserDefaultLCID, InterlockedDecrement, InterlockedIncrement, GetFileSize, FreeLibrary, GlobalAlloc, GlobalLock, GlobalUnlock, lstrcatW, CloseHandle, GetCurrentProcess, GetCurrentThreadId, lstrlenA, MultiByteToWideChar, DeleteCriticalSection, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, GetLastError
> USER32.dll: wsprintfA, ReleaseCapture, TranslateMessage, CopyRect, SetRectEmpty, FillRect, SetTimer, KillTimer, MsgWaitForMultipleObjects, GetSystemMetrics, DestroyWindow, wsprintfW, MapWindowPoints, GetDC, ReleaseDC, SetRect, IntersectRect, EqualRect
> GDI32.dll: BitBlt, DeleteObject, DeleteDC, GetDeviceCaps, CreateDIBSection, GetPaletteEntries, CreateSolidBrush, StretchBlt, SetTextColor, SetBkColor, CreateCompatibleDC, CreateCompatibleBitmap, SelectObject, SetPixel, GetPixel, SetStretchBltMode
> ADVAPI32.dll: RegCloseKey
> ole32.dll: CoTaskMemFree, CoTaskMemAlloc, CoInitializeEx, CoUninitialize, StringFromCLSID, ProgIDFromCLSID, CoCreateInstance, CoMarshalInterThreadInterfaceInStream, CoGetInterfaceAndReleaseStream, OleRun, StringFromGUID2
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> urlmon.dll: CoInternetCombineUrl, FindMimeFromData, URLDownloadToCacheFileW, CoGetClassObjectFromURL, CreateAsyncBindCtx, CompatFlagsFromClsid
> WININET.dll: InternetGetConnectedStateExW, InternetCombineUrlW, InternetCrackUrlW
> DDRAW.dll: DirectDrawCreate
> SHLWAPI.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, StrCmpIW, PathAppendW, StrCmpNIW, StrStrIW, PathFindExtensionW, PathFileExistsW, StrCatW, StrCpyW, PathFindFileNameW, StrCpyNW, StrCSpnIW, StrStrW, StrCmpW, wvnsprintfW, wnsprintfW, StrSpnW, StrNCatW, StrRChrW, StrCmpNW, StrCatBuffW, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> RPCRT4.dll: CStdStubBuffer_IsIIDSupported, CStdStubBuffer_CountRefs, CStdStubBuffer_Invoke, CStdStubBuffer_Disconnect, CStdStubBuffer_Connect, CStdStubBuffer_AddRef, CStdStubBuffer_QueryInterface, CStdStubBuffer_DebugServerQueryInterface, IUnknown_Release_Proxy, IUnknown_AddRef_Proxy, IUnknown_QueryInterface_Proxy, NdrCStdStubBuffer_Release, NdrOleAllocate, CStdStubBuffer_DebugServerRelease, NdrDllUnregisterProxy, NdrDllRegisterProxy, NdrDllGetClassObject, NdrDllCanUnloadNow, NdrOleFree
( 5 exports )
DllCanUnloadNow, DllEnumClassObjects, DllGetClassObject, DllRegisterServer, DllUnregisterServer
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Windows OCX File (85.9%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
DOS Executable Generic (1.3%)
sigcheck:
publisher....: Microsoft Corporation
copyright....: © Microsoft Corporation. All rights reserved.
product......: Microsoft_ Windows_ Operating System
description..: Microsoft ® Timed Interactive Multimedia Extensions to HTML
original name: MSTIME.DLL
internal name: MSTIME
file version.: 6.00.2900.5512 (xpsp.080413-2105)
comments.....: n/a
signers......: -
signing date.: -
OTL logfile created on: 27/07/2010 16:40:25 - Run 2
OTL by OldTimer - Version 3.2.8.1 Folder = C:\Documents and Settings\User\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd/MM/yyyy
998.00 Mb Total Physical Memory | 395.00 Mb Available Physical Memory | 40.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1500 3000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.54 Gb Total Space | 11.50 Gb Free Space | 58.87% Space Free | Partition Type: NTFS
Drive D: | 54.99 Gb Total Space | 26.27 Gb Free Space | 47.77% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NEC-8EBEED200FC
Current User Name: User
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/07/09 14:10:36 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
PRC - [2010/06/30 14:52:22 | 000,836,464 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2010/06/28 23:57:18 | 002,837,864 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/06/28 23:57:15 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/06/20 05:06:46 | 000,349,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe
PRC - [2010/06/10 09:13:05 | 000,116,104 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\ramaint.exe
PRC - [2010/06/10 09:12:39 | 000,378,248 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardian.exe
PRC - [2008/06/10 20:26:28 | 000,222,456 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2008/04/14 03:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/12/03 08:59:52 | 000,037,376 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe
PRC - [2007/08/03 16:09:34 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2007/08/03 16:09:34 | 000,063,040 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2006/07/29 12:20:34 | 000,098,304 | R--- | M] (Intel) -- C:\Program Files\Intel\AMT\LMS.exe
PRC - [2002/05/19 10:24:00 | 000,095,232 | ---- | M] () -- C:\Program Files\Datecs\FlexType 2K\FType2K.exe
PRC - [2001/01/25 15:07:54 | 000,225,353 | ---- | M] (Quazar Software GmbH) -- C:\Program Files\UPS\Upsman\www\ServiceDriver.exe
========== Modules (SafeList) ==========
MOD - [2010/07/09 14:10:36 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
MOD - [2008/04/14 03:12:06 | 000,075,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spoolss.dll
MOD - [2008/04/14 03:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
MOD - [2006/07/26 02:01:10 | 000,100,544 | ---- | M] (KYOCERA MITA Corporation) -- C:\WINDOWS\system32\KMPJLMN.DLL
MOD - [2002/04/23 01:17:06 | 000,045,056 | ---- | M] () -- C:\WINDOWS\system32\newdll.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2010/06/28 23:57:15 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010/06/28 23:57:15 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010/06/28 23:57:15 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/06/10 09:13:05 | 000,116,104 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\RaMaint.exe -- (LMIMaint)
SRV - [2008/06/10 20:26:28 | 000,222,456 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2007/08/03 16:09:34 | 000,063,040 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
SRV - [2006/07/29 12:20:34 | 000,098,304 | R--- | M] (Intel) [Auto | Running] -- C:\Program Files\Intel\AMT\LMS.exe -- (LMS) Intel®
SRV - [2006/07/22 02:28:22 | 002,768,982 | ---- | M] (Generex GmbH) [Auto | Stopped] -- C:\Program Files\UPS\Upsman\upsman.exe -- (UPSMan)
SRV - [2001/01/25 15:07:54 | 000,225,353 | ---- | M] (Quazar Software GmbH) [Auto | Running] -- C:\Program Files\UPS\Upsman\www\ServiceDriver.exe -- (qHTTPs)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\nod32drv.sys -- (nod32drv)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\68.tmp -- (MEMSWEEP2)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\User\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010/06/28 23:37:52 | 000,046,672 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010/06/28 23:37:30 | 000,165,456 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010/06/28 23:33:13 | 000,023,376 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010/06/28 23:32:45 | 000,100,176 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010/06/28 23:32:33 | 000,017,744 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/06/28 23:32:16 | 000,028,880 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2010/06/10 09:12:43 | 000,083,360 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2010/05/10 21:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 21:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2008/10/20 09:11:02 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2008/04/13 19:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008/02/28 15:31:50 | 000,012,856 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo)
DRV - [2006/11/01 12:39:16 | 000,246,680 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1e5132.sys -- (e1express) Intel®
DRV - [2006/07/24 17:15:04 | 004,353,024 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/07/21 15:12:00 | 001,095,968 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2006/06/19 15:18:56 | 000,043,264 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (HECI) Intel®
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://mail30.abv.bg/app/j/box.jsp?fid=10|about:blank"
FF - prefs.js..network.proxy.type: 2
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/30 16:40:08 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/02 09:03:40 | 000,000,000 | ---D | M]
[2009/04/07 13:02:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2009/04/07 13:02:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\x93nprk2.default\extensions
[2009/04/07 13:01:55 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/07/09 16:52:04 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKCU\..\Toolbar\ShellBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [skyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKCU..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\Program Files\Datecs\FlexType 2K\FType2K.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Open in new background tab - C:\Program Files\Windows Live Toolbar\Components\en-in\msntabres.dll.mui (Microsoft Corporation)
O8 - Extra context menu item: Open in new foreground tab - C:\Program Files\Windows Live Toolbar\Components\en-in\msntabres.dll.mui (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/12/05 19:46:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: aux - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)
========== Files/Folders - Created Within 30 Days ==========
[2010/07/26 12:43:54 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/07/20 09:24:52 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/07/09 16:54:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010/07/09 16:48:22 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/07/09 16:46:49 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/07/09 16:46:49 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/07/09 16:46:49 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/07/09 16:46:49 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/07/09 16:46:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/07/09 16:46:30 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/07/09 16:21:19 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/07/09 14:10:32 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
[2010/07/09 12:01:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
[2010/07/09 12:01:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/07/09 12:01:03 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/07/09 11:57:03 | 009,070,816 | ---- | C] (SUPERAntiSpyware.com) -- C:\Documents and Settings\User\Desktop\SUPERAntiSpyware.exe
[2010/07/09 10:41:01 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos
[2010/07/08 16:32:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Malwarebytes
[2010/07/08 16:32:16 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/08 16:32:13 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/08 16:32:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/07/08 16:32:12 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/07 14:25:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\WinRAR
[2010/07/02 14:16:32 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\User\PrivacIE
[2010/07/02 14:16:27 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\User\IECompatCache
[2010/07/02 13:40:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\My Documents\Backups
[2010/07/02 13:24:20 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2010/07/02 13:24:19 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2010/07/02 13:24:18 | 001,985,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2010/07/02 13:24:17 | 011,076,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2010/07/02 13:24:16 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/07/02 13:23:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2010/07/02 13:21:58 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ieencode.dll
[2010/07/02 13:21:58 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieencode.dll
[2010/07/01 09:45:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/07/01 09:40:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\Temp
[2010/07/01 09:40:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/07/01 09:40:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\Google
[2010/07/01 09:40:44 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2010/06/29 09:07:41 | 000,038,848 | ---- | C] (ALWIL Software) -- C:\WINDOWS\avastSS.scr
========== Files - Modified Within 30 Days ==========
[2010/07/27 15:47:00 | 000,000,252 | ---- | M] () -- C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2010/07/27 15:45:00 | 000,001,040 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/27 14:18:02 | 000,046,265 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Letter9166-126-27.07.2010-AdmistrativniNarushenia.pdf
[2010/07/27 10:58:48 | 008,126,464 | ---- | M] () -- C:\Documents and Settings\User\NTUSER.DAT
[2010/07/27 09:45:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/26 14:50:52 | 002,285,750 | ---- | M] () -- C:\Documents and Settings\User\My Documents\protokol1-1.tif
[2010/07/26 14:50:40 | 002,285,750 | ---- | M] () -- C:\Documents and Settings\User\My Documents\protokol2-1.tif
[2010/07/26 12:43:12 | 000,001,091 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Microsoft Outlook Web Access - Agro.url
[2010/07/26 09:07:22 | 000,473,088 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Copy of National reserve_2010 - 2011_MZH1_raboten_10_07-10_sled_dim__Zapov_okon_sled_ODZ.XLS
[2010/07/26 08:58:45 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/26 08:58:20 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/07/26 08:58:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/07/22 10:47:05 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\User\ntuser.ini
[2010/07/09 16:52:15 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/07/09 16:52:04 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/07/09 16:48:27 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/07/09 16:40:01 | 003,728,667 | R--- | M] () -- C:\Documents and Settings\User\Desktop\ff2.exe
[2010/07/09 15:59:47 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Метереологична станция.doc
[2010/07/09 14:10:36 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
[2010/07/09 12:48:21 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\User\Desktop\ОБЛАСТ ДОБРИЧ.doc
[2010/07/09 12:46:41 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\User\My Documents\ОБЛАСТ ДОБРИЧ.doc
[2010/07/09 12:01:09 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/07/09 11:57:52 | 009,070,816 | ---- | M] (SUPERAntiSpyware.com) -- C:\Documents and Settings\User\Desktop\SUPERAntiSpyware.exe
[2010/07/09 11:55:05 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/07/09 11:54:59 | 000,036,352 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/09 10:40:31 | 001,376,832 | ---- | M] () -- C:\Documents and Settings\User\Desktop\sar_15_sfx.exe
[2010/07/09 09:56:23 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\User\Desktop\за гери.doc
[2010/07/09 09:25:53 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\User\Desktop\dds.scr
[2010/07/09 09:21:12 | 000,867,892 | ---- | M] () -- C:\Documents and Settings\User\Desktop\SecurityCheck.exe
[2010/07/09 08:59:29 | 000,002,497 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Microsoft Office Word 2003.lnk
[2010/07/08 16:04:37 | 000,001,891 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/07/07 15:37:19 | 000,010,752 | ---- | M] () -- C:\YIEL10-Incoherence_Data.xls
[2010/07/06 14:03:09 | 000,000,492 | ---- | M] () -- C:\Documents and Settings\User\My Documents\spider.sav
[2010/07/06 13:06:56 | 009,646,080 | ---- | M] () -- C:\DECIDEV2.01.MDB
[2010/07/06 10:21:14 | 000,000,610 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/07/05 11:09:12 | 000,002,495 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Microsoft Office Excel 2003.lnk
[2010/07/02 16:35:33 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/02 13:37:59 | 000,102,400 | ---- | M] () -- C:\Documents and Settings\User\My Documents\db1.mdb
[2010/06/29 09:07:43 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/06/28 23:57:33 | 000,038,848 | ---- | M] (ALWIL Software) -- C:\WINDOWS\avastSS.scr
[2010/06/28 23:57:12 | 000,165,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010/06/28 23:37:52 | 000,046,672 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/06/28 23:37:30 | 000,165,456 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010/06/28 23:33:13 | 000,023,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/06/28 23:32:45 | 000,100,176 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/06/28 23:32:42 | 000,094,544 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010/06/28 23:32:33 | 000,017,744 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/06/28 23:32:16 | 000,028,880 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/06/28 16:02:56 | 000,358,914 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/28 16:02:56 | 000,314,508 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/28 16:02:56 | 000,040,836 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
========== Files Created - No Company Name ==========
[2010/07/27 14:16:14 | 000,046,265 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Letter9166-126-27.07.2010-AdmistrativniNarushenia.pdf
[2010/07/26 14:50:51 | 002,285,750 | ---- | C] () -- C:\Documents and Settings\User\My Documents\protokol1-1.tif
[2010/07/26 14:50:39 | 002,285,750 | ---- | C] () -- C:\Documents and Settings\User\My Documents\protokol2-1.tif
[2010/07/26 12:43:12 | 000,001,091 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Microsoft Outlook Web Access - Agro.url
[2010/07/26 09:13:33 | 000,473,088 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Copy of National reserve_2010 - 2011_MZH1_raboten_10_07-10_sled_dim__Zapov_okon_sled_ODZ.XLS
[2010/07/09 16:48:27 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/07/09 16:48:25 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/07/09 16:46:49 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/07/09 16:46:49 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/07/09 16:46:49 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/07/09 16:46:49 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/07/09 16:46:49 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/07/09 16:39:50 | 003,728,667 | R--- | C] () -- C:\Documents and Settings\User\Desktop\ff2.exe
[2010/07/09 15:51:41 | 000,020,992 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Метереологична станция.doc
[2010/07/09 12:48:21 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\User\Desktop\ОБЛАСТ ДОБРИЧ.doc
[2010/07/09 12:46:41 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\User\My Documents\ОБЛАСТ ДОБРИЧ.doc
[2010/07/09 12:01:09 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/07/09 10:40:29 | 001,376,832 | ---- | C] () -- C:\Documents and Settings\User\Desktop\sar_15_sfx.exe
[2010/07/09 09:56:23 | 000,020,480 | ---- | C] () -- C:\Documents and Settings\User\Desktop\за гери.doc
[2010/07/09 09:25:33 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\User\Desktop\dds.scr
[2010/07/09 09:21:10 | 000,867,892 | ---- | C] () -- C:\Documents and Settings\User\Desktop\SecurityCheck.exe
[2010/07/06 14:03:09 | 000,000,492 | ---- | C] () -- C:\Documents and Settings\User\My Documents\spider.sav
[2010/07/05 10:53:48 | 000,010,752 | ---- | C] () -- C:\YIEL10-Incoherence_Data.xls
[2010/07/01 09:40:52 | 000,001,040 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/01 09:40:51 | 000,001,036 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2008/10/07 15:06:18 | 000,000,048 | ---- | C] () -- C:\WINDOWS\scmate.ini
[2008/04/08 11:47:04 | 000,000,322 | ---- | C] () -- C:\WINDOWS\SWWATER.INI
[2008/01/17 15:03:18 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\newdll.dll
[2008/01/10 16:54:02 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/12/05 20:39:23 | 000,192,512 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4642.dll
[2007/12/05 20:39:22 | 000,348,880 | R--- | C] () -- C:\WINDOWS\System32\igmedkrn.dll
[2007/12/05 20:36:44 | 000,143,360 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2007/12/05 20:33:07 | 000,000,508 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/12/05 16:26:02 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2007/12/05 19:46:50 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2008/01/01 22:25:43 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010/07/09 16:48:27 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2010/07/09 16:54:02 | 000,015,767 | ---- | M] () -- C:\ComboFix.txt
[2007/12/05 19:46:50 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/07/06 13:06:56 | 009,646,080 | ---- | M] () -- C:\DECIDEV2.01.MDB
[2007/12/05 19:46:50 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2007/12/05 19:46:50 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2007/12/05 20:17:01 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/07/21 11:32:17 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/07/26 08:58:04 | 1572,864,000 | -HS- | M] () -- C:\pagefile.sys
[2010/07/07 15:37:19 | 000,010,752 | ---- | M] () -- C:\YIEL10-Incoherence_Data.xls
< %systemroot%\*. /mp /s >
< %systemroot%\*.scr >
[2010/06/28 23:57:33 | 000,038,848 | ---- | M] (ALWIL Software) -- C:\WINDOWS\avastSS.scr
< %systemroot%\*._sy >
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2007/12/05 19:46:35 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\system32\*.jpg >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2010/06/10 09:12:42 | 000,053,632 | ---- | M] (LogMeIn, Inc.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/04/09 13:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/14 03:11:52 | 000,357,888 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2008/04/14 03:11:52 | 000,205,312 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
[2008/04/14 03:12:00 | 000,532,480 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\mstime.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2007/12/04 21:33:41 | 000,090,112 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2007/12/04 21:33:41 | 000,630,784 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2007/12/04 21:33:40 | 000,421,888 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\mstime.dll /md5 >
[2008/04/14 03:12:00 | 000,532,480 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\mstime.dll
< End of report >