Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Система заразена с криптиращ вирус

Featured Replies

Няма нужда от ръчно почистване и нови логове. Щом програмата е стигнала до temp папките, значи тя е изпълнила всичко без почистването на temp папките.

Не е нужно да пускате пак скрипта или да стартирате FRST! Само намерете лог файла, който трябва да се е създал на мястото на fixlist.txt в папката в която се намира FRST.exe!

Ако го няма там тогава отворете C:\FRST\Logs и прикачете всички логове от папката!

 

 

Поздрави!

  • Отговори 51
  • Прегледи 4,9k
  • Създадено
  • Последен отговор
  • Автор

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-04-2015 02
Ran by User (administrator) on PC-FB227302206B on 24-04-2015 08:25:48
Running from H:\Documents and Settings\User\My Documents\Downloads
Loaded Profiles: User (Available profiles: User & Administrator)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(HP) H:\WINDOWS\system32\HPSIsvc.exe
(Hewlett-Packard Company) H:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Nero AG) H:\Program Files\Nero\Update\NASvc.exe
() H:\Program Files\CDBurnerXP\NMSAccessU.exe
(Skype Technologies S.A.) H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Mozilla Corporation) H:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) H:\Program Files\Mozilla Firefox\plugin-container.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\RunOnce: [*EmptyTemp] => cmd /c rd /q/s H:\FRST\Temp
Winlogon\Notify\igfxcui: H:\WINDOWS\system32\igfxsrvc.dll [2004-11-02] (Intel Corporation)
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: E - E:\Install.exe
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: {9eea6e54-11aa-11e2-ac0d-28107bbdacc7} - E:\KODAK_Software_Downloader.exe
HKU\S-1-5-18\...\RunOnce: [RunNarrator] => H:\WINDOWS\system32\Narrator.exe [53760 2008-04-14] (Microsoft Corporation)
Startup: H:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> H:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-20] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> H:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-20] (Oracle Corporation)
BHO: BHO_TIMELINEREMOVE.Bho -> {e7b9b609-19ad-40a4-a288-b300a3087465} -> H:\WINDOWS\system32\mscoree.dll [2010-03-18] (Microsoft Corporation)
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289583241062
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - H:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015
FF SelectedSearchEngine: Yahoo!
FF Homepage: https://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> H:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-20] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> H:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> H:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-20] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> h:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: Adobe Reader -> H:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1614895754-1645522239-1417001333-1003: @Skype Limited.com/Facebook Video Calling Plugin -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll [2012-10-12] (Skype Limited)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2012-01-12] (BitComet)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\google-dictionary-english-french.xml [2012-08-28]
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\wikipedia-franais-et-anglais.xml [2012-08-28]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\911bg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\pe-bg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml [2015-04-15]
FF Extension: United States English Spellchecker - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-05-19]
FF Extension: Dictionnaire français «Moderne» - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-01-08]
FF Extension: TimeLineRemove.Com - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-19]
FF Extension: Microsoft .NET Framework Assistant - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-11-14]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-20]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\trash [2012-08-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2015-04-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-11-12]
FF ExtraCheck: H:\Program Files\mozilla firefox\firefox.cfg [2015-01-15] <==== ATTENTION

Chrome:
=======
CHR Profile: H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Gmail) - H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-12]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 CCALib8; H:\Program Files\Canon\CAL\CALMAIN.exe [96341 2006-03-30] (Canon Inc.) [File not signed]
R3 hpqcxs08; H:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; H:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 LightScribeService; H:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-08-16] (Hewlett-Packard Company) [File not signed]
R2 NAUpdate; H:\Program Files\Nero\Update\NASvc.exe [573224 2011-01-26] (Nero AG)
R2 Net Driver HPZ12; H:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
R2 NMSAccess; H:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] ()
R2 Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Skype C2C Service; H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S2 WLSVC; H:\Program Files\D-Link\DWA-130 revE\WLSVC.exe [167936 2009-02-11] () [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AegisP; H:\WINDOWS\System32\DRIVERS\AegisP.sys [21361 2012-07-08] (Cisco Systems, Inc.) [File not signed]
S3 CCDECODE; H:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 HPZid412; H:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
S3 HPZipr12; H:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
S3 HPZius12; H:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
S3 NdisIP; H:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 rt2870; H:\WINDOWS\System32\DRIVERS\Drt2870.sys [829152 2010-05-06] (Ralink Technology, Corp.)
S3 rtl8139; H:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
R2 StarOpen; H:\WINDOWS\system32\Drivers\StarOpen.sys [5504 2009-11-12] () [File not signed]
R2 WLNdis50; H:\WINDOWS\System32\DRIVERS\wlndis50.sys [20480 2008-02-27] () [File not signed]
U1 WS2IFSL; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-21 18:51 - 2015-04-21 20:22 - 00000000 ____D () H:\Documents and Settings\User\Desktop\nik
2015-04-20 21:13 - 2015-04-20 21:13 - 00000104 _____ () H:\Documents and Settings\User\Desktop\Internet.lnk
2015-04-20 20:00 - 2015-04-20 20:00 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Sun
2015-04-20 19:49 - 2015-04-20 19:49 - 00000724 _____ () H:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
2015-04-20 19:26 - 2015-04-20 19:27 - 00031668 _____ () H:\Addition.txt
2015-04-20 19:25 - 2015-04-20 19:27 - 00040441 _____ () H:\FRST.txt
2015-04-20 19:24 - 2015-04-20 19:24 - 01139200 _____ (Farbar) H:\FRST.exe
2015-04-20 18:21 - 2015-04-20 19:40 - 00119512 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-04-20 18:21 - 2015-04-20 18:21 - 00000777 _____ () H:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-20 18:21 - 2015-04-14 09:37 - 00120024 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-04-20 18:21 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbam.sys
2015-04-20 18:17 - 2015-04-20 18:17 - 21546080 _____ (Malwarebytes Corporation ) H:\mbam-setup-consumer-2.1.6.1022.exe
2015-04-20 17:55 - 2015-04-21 20:17 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 5 - Историография - Ново време
2015-04-20 17:55 - 2015-04-20 19:49 - 00000000 ____D () H:\Program Files\Mozilla Firefox
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Program Files\Common Files\Skype
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 4 - Историография - Праистория и Античност
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 2 - Историография - Средновековие
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 1 - Източници и изворознание
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\snow queen tous
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\end2
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9outs
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9 end
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\29r
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2 outs
2015-04-20 16:49 - 2015-04-20 17:47 - 00000000 ____D () H:\Program Files\ShadowExplorer
2015-04-20 16:49 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ShadowExplorer
2015-04-20 09:49 - 2015-04-20 09:49 - 00008984 _____ () H:\Documents and Settings\User\Desktop\mbam1.txt
2015-04-20 09:46 - 2015-04-20 19:18 - 00004663 _____ () H:\Documents and Settings\User\Desktop\mbam.txt
2015-04-20 07:09 - 2015-04-24 08:25 - 00000000 ____D () H:\FRST
2015-04-18 23:18 - 2015-04-18 23:18 - 00008536 _____ () H:\Documents and Settings\Administrator\Desktop\mb scan.txt
2015-04-18 21:49 - 2015-04-20 18:21 - 00000000 ____D () H:\Program Files\Malwarebytes Anti-Malware
2015-04-18 21:30 - 2015-04-18 21:41 - 00003572 _____ () H:\Documents and Settings\Administrator\Desktop\Rkill.txt
2015-04-18 21:21 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Mozilla
2015-04-18 21:21 - 2015-04-18 21:21 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Macromedia
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Adobe
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Desktop\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 19:50 - 2015-04-18 23:16 - 00001324 _____ () H:\WINDOWS\system32\d3d9caps.dat
2015-04-12 01:28 - 2015-04-18 20:06 - 00113732 _____ () H:\Documents and Settings\User\Desktop\10470717_10152942390179635_5357236154732284632_n.jpg.ecc
2015-04-12 01:27 - 2015-04-18 20:06 - 00054468 _____ () H:\Documents and Settings\User\Desktop\11145571_10152958877974635_3339765670712915872_n.jpg.ecc
2015-04-05 12:26 - 2015-04-18 20:06 - 00090580 _____ () H:\Documents and Settings\User\Desktop\11138672_982700228409538_8855858409597611766_n.jpg.ecc
2015-04-04 01:57 - 2015-04-04 02:02 - 00000000 ____D () H:\Documents and Settings\User\My Documents\Attestation123
2015-04-04 01:56 - 2015-04-18 21:12 - 00381604 _____ () H:\Documents and Settings\User\Desktop\Attestation2.pdf.ecc
2015-04-03 14:06 - 2015-04-03 14:06 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\Hewlett-Packard
2015-04-01 15:28 - 2015-04-18 20:06 - 00038404 _____ () H:\Documents and Settings\User\Desktop\11096536_10153198374462173_1538024734260084523_n.jpg.ecc
2015-03-29 22:34 - 2015-04-18 20:06 - 00058036 _____ () H:\Documents and Settings\User\Desktop\10923243_823850137672875_4923851942726001590_n.jpg.ecc
2015-03-25 17:48 - 2015-04-20 16:10 - 00001748 _____ () H:\Documents and Settings\User\Desktop\doc_57.png.ecc
2015-03-25 15:31 - 2015-04-18 20:06 - 00061220 _____ () H:\Documents and Settings\User\Desktop\0cb712a19e742a9725b3c7cf78a6d908_600x460.jpg.ecc

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-24 08:25 - 2010-11-12 13:32 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Temp
2015-04-24 07:25 - 2010-11-12 13:31 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Temp
2015-04-24 07:16 - 2001-08-23 08:00 - 00002206 _____ () H:\WINDOWS\system32\wpa.dbl
2015-04-24 07:15 - 2010-11-12 13:18 - 01949850 _____ () H:\WINDOWS\WindowsUpdate.log
2015-04-24 07:14 - 2010-11-12 13:31 - 00000006 ____H () H:\WINDOWS\Tasks\SA.DAT
2015-04-24 07:14 - 2010-11-12 08:08 - 00000299 _____ () H:\WINDOWS\wiadebug.log
2015-04-24 07:14 - 2010-11-12 08:08 - 00000052 _____ () H:\WINDOWS\wiaservc.log
2015-04-24 05:57 - 2012-06-30 23:39 - 00001148 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003UA.job
2015-04-23 19:21 - 2013-12-07 23:22 - 00000000 ___RD () H:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
2015-04-23 19:21 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator
2015-04-23 19:19 - 2010-11-12 13:14 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Accessories
2015-04-23 17:57 - 2012-06-30 23:39 - 00001126 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003Core.job
2015-04-23 16:39 - 2013-10-26 17:49 - 00000000 ____D () H:\Documents and Settings\User\My Documents\AS-CV
2015-04-23 06:57 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Temp
2015-04-23 06:53 - 2010-11-12 13:28 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Temp
2015-04-23 06:52 - 2010-11-12 08:04 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Temp
2015-04-23 06:42 - 2013-10-26 16:34 - 00278076 _____ () H:\WINDOWS\setupapi.log
2015-04-23 05:47 - 2010-11-12 13:32 - 00000178 ___SH () H:\Documents and Settings\User\ntuser.ini
2015-04-23 05:47 - 2010-11-12 13:31 - 00031772 _____ () H:\WINDOWS\SchedLgU.Txt
2015-04-22 23:11 - 2013-10-27 02:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\moda
2015-04-21 20:23 - 2012-05-14 19:46 - 00002465 _____ () H:\Documents and Settings\All Users\Desktop\Nero StartSmart 10.lnk
2015-04-21 18:51 - 2014-02-15 20:44 - 00000000 ____D () H:\Documents and Settings\User\Desktop\sub.vvv
2015-04-21 08:27 - 2014-07-27 00:13 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-27
2015-04-21 08:26 - 2014-09-02 22:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-02
2015-04-21 08:26 - 2014-08-31 00:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-31
2015-04-21 08:25 - 2014-07-13 19:22 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-13
2015-04-21 08:25 - 2014-05-20 13:45 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-05-20
2015-04-21 08:24 - 2014-08-28 20:43 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-28
2015-04-21 08:14 - 2010-11-14 18:34 - 00000000 ____D () H:\WINDOWS\pss
2015-04-21 08:14 - 2001-08-23 08:00 - 00000630 _____ () H:\WINDOWS\win.ini
2015-04-21 08:14 - 2001-08-23 08:00 - 00000227 _____ () H:\WINDOWS\system.ini
2015-04-21 07:54 - 2012-02-11 11:47 - 00002265 _____ () H:\Documents and Settings\All Users\Desktop\Skype.lnk
2015-04-21 07:54 - 2010-11-13 00:51 - 00000000 ____D () H:\Documents and Settings\User\Application Data\Skype
2015-04-20 20:08 - 2013-10-25 16:28 - 00000000 ____D () H:\AdwCleaner
2015-04-20 20:04 - 2010-11-18 19:35 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\Adobe
2015-04-20 20:03 - 2012-04-18 22:24 - 00778416 _____ (Adobe Systems Incorporated) H:\WINDOWS\system32\FlashPlayerApp.exe
2015-04-20 20:03 - 2011-08-26 22:30 - 00142512 _____ (Adobe Systems Incorporated) H:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-04-20 20:00 - 2012-02-18 21:41 - 00000000 ____D () H:\Program Files\Java
2015-04-20 19:59 - 2014-10-24 10:30 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Oracle
2015-04-20 19:57 - 2013-03-23 10:04 - 00096680 _____ (Oracle Corporation) H:\WINDOWS\system32\WindowsAccessBridge.dll
2015-04-20 19:57 - 2012-02-18 21:41 - 00146432 _____ (Oracle Corporation) H:\WINDOWS\system32\javacpl.cpl
2015-04-20 19:55 - 2010-11-12 21:43 - 00000000 ____D () H:\Documents and Settings\User\My Documents\programi
2015-04-20 19:19 - 2012-10-01 06:03 - 00073960 _____ () H:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2015-04-20 19:13 - 2013-10-09 06:27 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2862335$
2015-04-20 18:12 - 2010-11-12 08:04 - 00615742 _____ () H:\WINDOWS\system32\PerfStringBackup.INI
2015-04-20 18:00 - 2013-10-26 16:35 - 00000986 _____ () H:\WINDOWS\setupact.log
2015-04-20 17:57 - 2010-11-12 08:03 - 00286904 _____ () H:\WINDOWS\system32\FNTCACHE.DAT
2015-04-20 17:56 - 2010-11-12 13:31 - 00000000 __SHD () H:\Documents and Settings\LocalService
2015-04-20 17:56 - 2010-11-12 13:28 - 00000000 __SHD () H:\Documents and Settings\NetworkService
2015-04-20 17:56 - 2010-11-12 13:16 - 00000000 ____D () H:\WINDOWS\Registration
2015-04-20 17:55 - 2015-01-24 14:35 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype(2)
2015-04-20 17:55 - 2013-01-08 20:29 - 00000000 ____D () H:\Documents and Settings\User\Application Data\BitTorrent
2015-04-20 17:55 - 2012-09-18 23:37 - 00000000 ___RD () H:\Program Files\Skype
2015-04-20 17:55 - 2012-05-03 16:07 - 00000000 ____D () H:\Program Files\Mozilla Maintenance Service
2015-04-20 17:53 - 2015-02-23 22:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\hyde
2015-04-20 17:53 - 2015-02-23 20:21 - 00000000 ____D () H:\Documents and Settings\User\Desktop\b est of me
2015-04-20 17:53 - 2015-02-23 20:18 - 00000000 ____D () H:\Documents and Settings\User\Desktop\New Folder(2)
2015-04-20 17:53 - 2015-02-23 20:16 - 00000000 ____D () H:\Documents and Settings\User\Desktop\j789
2015-04-20 17:53 - 2015-02-23 20:16 - 00000000 ____D () H:\Documents and Settings\User\Desktop\j456
2015-04-20 17:53 - 2015-02-23 20:14 - 00000000 ____D () H:\Documents and Settings\User\Desktop\New Folder
2015-04-20 17:52 - 2013-07-15 23:21 - 00000000 ____D () H:\WINDOWS\system32\MRT
2015-04-20 17:06 - 2013-11-23 04:02 - 00519776 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2015-04-20 17:06 - 2010-11-12 13:17 - 00000000 ____D () H:\WINDOWS\system32\Restore
2015-04-20 16:40 - 2014-03-30 13:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\18
2015-04-19 23:43 - 2014-09-08 19:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-08
2015-04-19 00:18 - 2014-06-08 20:04 - 00000000 ____D () H:\Documents and Settings\User\My Documents\sub1
2015-04-18 23:20 - 2011-11-11 00:38 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2641690$
2015-04-18 21:13 - 2014-09-27 00:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Jardine bothanique
2015-04-18 21:13 - 2013-11-30 17:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\disain
2015-04-18 21:13 - 2013-10-27 02:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\krasivo
2015-04-18 21:13 - 2013-05-28 07:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\inter
2015-04-18 21:12 - 2015-01-06 00:00 - 00040260 _____ () H:\Documents and Settings\User\Desktop\bride.and.prejudice.2004.dvdrip.xvid-endi(subsunacs.net).zip.ecc
2015-04-18 21:12 - 2014-08-17 17:03 - 16454852 _____ () H:\Documents and Settings\User\Desktop\attachments_2014_08_17.zip.ecc
2015-04-18 20:58 - 2014-09-27 18:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-27
2015-04-18 20:29 - 2014-09-18 22:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-18
2015-04-18 20:06 - 2015-02-06 23:20 - 00188836 _____ () H:\Documents and Settings\User\Desktop\1066517_4543673565274_2119997541_o.jpg.ecc
2015-04-18 20:06 - 2015-01-08 21:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2
2015-04-18 20:06 - 2014-03-30 13:14 - 00014372 _____ () H:\Documents and Settings\User\Desktop\17.torent.ecc
2015-04-18 20:05 - 2012-08-10 15:44 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\bdch
2015-04-18 20:05 - 2012-02-17 06:40 - 00000000 __SHD () H:\Documents and Settings\NetworkService\IETldCache
2015-04-18 20:05 - 2010-11-13 00:57 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
2015-04-18 20:04 - 2014-10-24 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Java
2015-04-18 20:04 - 2014-04-26 11:43 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\JustVoip
2015-04-18 20:04 - 2013-02-16 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ooVoo
2015-04-18 20:04 - 2013-01-08 20:32 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
2015-04-18 20:04 - 2012-11-11 03:32 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\bdch
2015-04-18 20:04 - 2012-11-07 00:51 - 00000000 ____D () H:\Documents and Settings\LocalService\Application Data\QuickScan
2015-04-18 20:04 - 2012-07-08 00:07 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\D-Link
2015-04-18 20:04 - 2012-06-27 17:08 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
2015-04-18 20:04 - 2012-06-19 18:28 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\TechSmith
2015-04-18 20:04 - 2011-12-19 00:57 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft Help
2015-04-18 20:04 - 2011-12-18 18:15 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
2015-04-18 20:04 - 2011-12-17 19:54 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\DVDVideoSoft
2015-04-18 20:04 - 2011-10-16 20:17 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
2015-04-18 20:04 - 2011-05-17 16:09 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Keyboard
2015-04-18 20:04 - 2011-02-07 22:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
2015-04-18 20:04 - 2011-02-06 00:33 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
2015-04-18 20:04 - 2011-01-16 21:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Nero
2015-04-18 20:04 - 2010-12-01 20:18 - 00000000 ___SD () H:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 3.1
2015-04-18 20:04 - 2010-11-25 17:10 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\HP
2015-04-18 20:04 - 2010-11-15 22:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\LightScribe Direct Disc Labeling
2015-04-18 20:04 - 2010-11-13 00:52 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Google
2015-04-18 20:04 - 2010-11-12 23:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\AVS4YOU
2015-04-18 20:04 - 2010-11-12 22:16 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
2015-04-18 20:04 - 2010-11-12 21:42 - 00000000 __SHD () H:\Documents and Settings\LocalService\IETldCache
2015-04-18 20:04 - 2010-11-12 13:18 - 00000000 __SHD () H:\Documents and Settings\All Users\DRM
2015-04-18 20:04 - 2010-11-12 13:18 - 00000000 ___RD () H:\Documents and Settings\Default User\Start Menu\Programs\Accessories
2015-04-18 20:04 - 2010-11-12 13:16 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Games
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 __SHD () H:\Documents and Settings\Administrator\IETldCache
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft Help
2015-04-18 20:03 - 2011-01-16 21:24 - 00000000 ____D () H:\bb6fadc9d2f25f3b2953e5d2
2015-04-18 20:03 - 2010-11-12 02:18 - 00000000 ____D () H:\d688a5c03ea38202645f5bc01eeb02
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\a812a3d6-ecc8-4750-9477-c631757694a4.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\92c937b0-dfc0-4b6d-a16f-6fc079dec2a3.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\4e28d2f5-abaf-40c7-a2d7-f3a7ad9a45ff.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\0feed571-1be8-4bc1-8ccd-82480f9105ff.dmp.ecc
2015-04-18 19:20 - 2012-09-17 19:42 - 00029492 _____ () H:\.pdf.ecc
2015-04-18 19:20 - 2012-07-29 22:31 - 00465764 _____ () H:\112.pdf.ecc
2015-04-18 19:20 - 2012-02-28 14:22 - 00000000 ____D () H:\54c3cb947aef816ceabdedb8f7
2015-04-18 19:20 - 2012-02-11 14:34 - 00000000 ____D () H:\128b39739a3c8290c766a9
2015-04-18 19:20 - 2012-02-06 22:14 - 00000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1
2015-04-18 19:20 - 2012-02-01 15:45 - 00000000 ____D () H:\94677e1b4707d7452aa83d9d21
2015-04-17 23:45 - 2014-01-11 01:48 - 00000000 ____D () H:\Documents and Settings\User\My Documents\subtitle
2015-04-05 15:36 - 2014-06-08 18:50 - 00000000 ____D () H:\Documents and Settings\User\Desktop\l5678
2015-04-05 12:31 - 2012-06-15 14:53 - 00270848 ___SH () H:\Documents and Settings\User\Desktop\Thumbs.db
2015-04-03 15:46 - 2012-06-17 20:14 - 00000000 ____D () H:\Documents and Settings\User\My Documents\attestation

==================== Files in the root of some directories =======

2010-11-12 22:29 - 2015-01-14 18:38 - 0088064 _____ () H:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

H:\WINDOWS\explorer.exe => File is digitally signed
H:\WINDOWS\system32\winlogon.exe => File is digitally signed
H:\WINDOWS\system32\svchost.exe => File is digitally signed
H:\WINDOWS\system32\services.exe => File is digitally signed
H:\WINDOWS\system32\User32.dll => File is digitally signed
H:\WINDOWS\system32\userinit.exe => File is digitally signed
H:\WINDOWS\system32\rpcss.dll => File is digitally signed
H:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

 

==================== End Of Log ============================

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-04-2015 01
Ran by User (administrator) on PC-FB227302206B on 24-04-2015 08:09:05
Running from H:\Documents and Settings\User\My Documents\Downloads
Loaded Profiles: User (Available profiles: User & Administrator)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(HP) H:\WINDOWS\system32\HPSIsvc.exe
(Hewlett-Packard Company) H:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Nero AG) H:\Program Files\Nero\Update\NASvc.exe
() H:\Program Files\CDBurnerXP\NMSAccessU.exe
(Skype Technologies S.A.) H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Mozilla Corporation) H:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) H:\Program Files\Mozilla Firefox\plugin-container.exe
(Mozilla Corporation) H:\Program Files\Mozilla Firefox\plugin-container.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\RunOnce: [*EmptyTemp] => cmd /c rd /q/s H:\FRST\Temp
Winlogon\Notify\igfxcui: H:\WINDOWS\system32\igfxsrvc.dll [2004-11-02] (Intel Corporation)
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: E - E:\Install.exe
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: {9eea6e54-11aa-11e2-ac0d-28107bbdacc7} - E:\KODAK_Software_Downloader.exe
HKU\S-1-5-18\...\RunOnce: [RunNarrator] => H:\WINDOWS\system32\Narrator.exe [53760 2008-04-14] (Microsoft Corporation)
Startup: H:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> H:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-20] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> H:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-20] (Oracle Corporation)
BHO: BHO_TIMELINEREMOVE.Bho -> {e7b9b609-19ad-40a4-a288-b300a3087465} -> H:\WINDOWS\system32\mscoree.dll [2010-03-18] (Microsoft Corporation)
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289583241062
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - H:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015
FF SelectedSearchEngine: Yahoo!
FF Homepage: https://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> H:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-20] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> H:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> H:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-20] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> h:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: Adobe Reader -> H:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1614895754-1645522239-1417001333-1003: @Skype Limited.com/Facebook Video Calling Plugin -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll [2012-10-12] (Skype Limited)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2012-01-12] (BitComet)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\google-dictionary-english-french.xml [2012-08-28]
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\wikipedia-franais-et-anglais.xml [2012-08-28]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\911bg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\pe-bg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml [2015-04-15]
FF Extension: United States English Spellchecker - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-05-19]
FF Extension: Dictionnaire français «Moderne» - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-01-08]
FF Extension: TimeLineRemove.Com - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-19]
FF Extension: Microsoft .NET Framework Assistant - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-11-14]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-20]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\trash [2012-08-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2015-04-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-11-12]
FF ExtraCheck: H:\Program Files\mozilla firefox\firefox.cfg [2015-01-15] <==== ATTENTION

Chrome:
=======
CHR Profile: H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Gmail) - H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-12]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 CCALib8; H:\Program Files\Canon\CAL\CALMAIN.exe [96341 2006-03-30] (Canon Inc.) [File not signed]
R3 hpqcxs08; H:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; H:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 LightScribeService; H:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-08-16] (Hewlett-Packard Company) [File not signed]
R2 NAUpdate; H:\Program Files\Nero\Update\NASvc.exe [573224 2011-01-26] (Nero AG)
R2 Net Driver HPZ12; H:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
R2 NMSAccess; H:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] ()
R2 Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Skype C2C Service; H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S2 WLSVC; H:\Program Files\D-Link\DWA-130 revE\WLSVC.exe [167936 2009-02-11] () [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AegisP; H:\WINDOWS\System32\DRIVERS\AegisP.sys [21361 2012-07-08] (Cisco Systems, Inc.) [File not signed]
S3 CCDECODE; H:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 HPZid412; H:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
S3 HPZipr12; H:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
S3 HPZius12; H:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
S3 NdisIP; H:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 rt2870; H:\WINDOWS\System32\DRIVERS\Drt2870.sys [829152 2010-05-06] (Ralink Technology, Corp.)
S3 rtl8139; H:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
R2 StarOpen; H:\WINDOWS\system32\Drivers\StarOpen.sys [5504 2009-11-12] () [File not signed]
R2 WLNdis50; H:\WINDOWS\System32\DRIVERS\wlndis50.sys [20480 2008-02-27] () [File not signed]
U1 WS2IFSL; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-21 18:51 - 2015-04-21 20:22 - 00000000 ____D () H:\Documents and Settings\User\Desktop\nik
2015-04-20 21:13 - 2015-04-20 21:13 - 00000104 _____ () H:\Documents and Settings\User\Desktop\Internet.lnk
2015-04-20 20:00 - 2015-04-20 20:00 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Sun
2015-04-20 19:49 - 2015-04-20 19:49 - 00000724 _____ () H:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
2015-04-20 19:26 - 2015-04-20 19:27 - 00031668 _____ () H:\Addition.txt
2015-04-20 19:25 - 2015-04-20 19:27 - 00040441 _____ () H:\FRST.txt
2015-04-20 19:24 - 2015-04-20 19:24 - 01139200 _____ (Farbar) H:\FRST.exe
2015-04-20 18:21 - 2015-04-20 19:40 - 00119512 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-04-20 18:21 - 2015-04-20 18:21 - 00000777 _____ () H:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-20 18:21 - 2015-04-14 09:37 - 00120024 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-04-20 18:21 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbam.sys
2015-04-20 18:17 - 2015-04-20 18:17 - 21546080 _____ (Malwarebytes Corporation ) H:\mbam-setup-consumer-2.1.6.1022.exe
2015-04-20 17:55 - 2015-04-21 20:17 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 5 - Историография - Ново време
2015-04-20 17:55 - 2015-04-20 19:49 - 00000000 ____D () H:\Program Files\Mozilla Firefox
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Program Files\Common Files\Skype
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 4 - Историография - Праистория и Античност
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 2 - Историография - Средновековие
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 1 - Източници и изворознание
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\snow queen tous
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\end2
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9outs
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9 end
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\29r
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2 outs
2015-04-20 16:49 - 2015-04-20 17:47 - 00000000 ____D () H:\Program Files\ShadowExplorer
2015-04-20 16:49 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ShadowExplorer
2015-04-20 09:49 - 2015-04-20 09:49 - 00008984 _____ () H:\Documents and Settings\User\Desktop\mbam1.txt
2015-04-20 09:46 - 2015-04-20 19:18 - 00004663 _____ () H:\Documents and Settings\User\Desktop\mbam.txt
2015-04-20 07:09 - 2015-04-24 08:09 - 00000000 ____D () H:\FRST
2015-04-18 23:18 - 2015-04-18 23:18 - 00008536 _____ () H:\Documents and Settings\Administrator\Desktop\mb scan.txt
2015-04-18 21:49 - 2015-04-20 18:21 - 00000000 ____D () H:\Program Files\Malwarebytes Anti-Malware
2015-04-18 21:30 - 2015-04-18 21:41 - 00003572 _____ () H:\Documents and Settings\Administrator\Desktop\Rkill.txt
2015-04-18 21:21 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Mozilla
2015-04-18 21:21 - 2015-04-18 21:21 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Macromedia
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Adobe
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Desktop\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 19:50 - 2015-04-18 23:16 - 00001324 _____ () H:\WINDOWS\system32\d3d9caps.dat
2015-04-12 01:28 - 2015-04-18 20:06 - 00113732 _____ () H:\Documents and Settings\User\Desktop\10470717_10152942390179635_5357236154732284632_n.jpg.ecc
2015-04-12 01:27 - 2015-04-18 20:06 - 00054468 _____ () H:\Documents and Settings\User\Desktop\11145571_10152958877974635_3339765670712915872_n.jpg.ecc
2015-04-05 12:26 - 2015-04-18 20:06 - 00090580 _____ () H:\Documents and Settings\User\Desktop\11138672_982700228409538_8855858409597611766_n.jpg.ecc
2015-04-04 01:57 - 2015-04-04 02:02 - 00000000 ____D () H:\Documents and Settings\User\My Documents\Attestation123
2015-04-04 01:56 - 2015-04-18 21:12 - 00381604 _____ () H:\Documents and Settings\User\Desktop\Attestation2.pdf.ecc
2015-04-03 14:06 - 2015-04-03 14:06 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\Hewlett-Packard
2015-04-01 15:28 - 2015-04-18 20:06 - 00038404 _____ () H:\Documents and Settings\User\Desktop\11096536_10153198374462173_1538024734260084523_n.jpg.ecc
2015-03-29 22:34 - 2015-04-18 20:06 - 00058036 _____ () H:\Documents and Settings\User\Desktop\10923243_823850137672875_4923851942726001590_n.jpg.ecc
2015-03-25 17:48 - 2015-04-20 16:10 - 00001748 _____ () H:\Documents and Settings\User\Desktop\doc_57.png.ecc
2015-03-25 15:31 - 2015-04-18 20:06 - 00061220 _____ () H:\Documents and Settings\User\Desktop\0cb712a19e742a9725b3c7cf78a6d908_600x460.jpg.ecc

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-24 08:09 - 2010-11-12 13:32 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Temp
2015-04-24 07:25 - 2010-11-12 13:31 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Temp
2015-04-24 07:16 - 2001-08-23 08:00 - 00002206 _____ () H:\WINDOWS\system32\wpa.dbl
2015-04-24 07:15 - 2010-11-12 13:18 - 01949850 _____ () H:\WINDOWS\WindowsUpdate.log
2015-04-24 07:14 - 2010-11-12 13:31 - 00000006 ____H () H:\WINDOWS\Tasks\SA.DAT
2015-04-24 07:14 - 2010-11-12 08:08 - 00000299 _____ () H:\WINDOWS\wiadebug.log
2015-04-24 07:14 - 2010-11-12 08:08 - 00000052 _____ () H:\WINDOWS\wiaservc.log
2015-04-24 05:57 - 2012-06-30 23:39 - 00001148 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003UA.job
2015-04-23 19:21 - 2013-12-07 23:22 - 00000000 ___RD () H:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
2015-04-23 19:21 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator
2015-04-23 19:19 - 2010-11-12 13:14 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Accessories
2015-04-23 17:57 - 2012-06-30 23:39 - 00001126 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003Core.job
2015-04-23 16:39 - 2013-10-26 17:49 - 00000000 ____D () H:\Documents and Settings\User\My Documents\AS-CV
2015-04-23 06:57 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Temp
2015-04-23 06:53 - 2010-11-12 13:28 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Temp
2015-04-23 06:52 - 2010-11-12 08:04 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Temp
2015-04-23 06:42 - 2013-10-26 16:34 - 00278076 _____ () H:\WINDOWS\setupapi.log
2015-04-23 05:47 - 2010-11-12 13:32 - 00000178 ___SH () H:\Documents and Settings\User\ntuser.ini
2015-04-23 05:47 - 2010-11-12 13:31 - 00031772 _____ () H:\WINDOWS\SchedLgU.Txt
2015-04-22 23:11 - 2013-10-27 02:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\moda
2015-04-21 20:23 - 2012-05-14 19:46 - 00002465 _____ () H:\Documents and Settings\All Users\Desktop\Nero StartSmart 10.lnk
2015-04-21 18:51 - 2014-02-15 20:44 - 00000000 ____D () H:\Documents and Settings\User\Desktop\sub.vvv
2015-04-21 08:27 - 2014-07-27 00:13 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-27
2015-04-21 08:26 - 2014-09-02 22:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-02
2015-04-21 08:26 - 2014-08-31 00:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-31
2015-04-21 08:25 - 2014-07-13 19:22 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-13
2015-04-21 08:25 - 2014-05-20 13:45 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-05-20
2015-04-21 08:24 - 2014-08-28 20:43 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-28
2015-04-21 08:14 - 2001-08-23 08:00 - 00000630 _____ () H:\WINDOWS\win.ini
2015-04-21 08:14 - 2001-08-23 08:00 - 00000227 _____ () H:\WINDOWS\system.ini
2015-04-21 07:54 - 2012-02-11 11:47 - 00002265 _____ () H:\Documents and Settings\All Users\Desktop\Skype.lnk
2015-04-21 07:54 - 2010-11-13 00:51 - 00000000 ____D () H:\Documents and Settings\User\Application Data\Skype
2015-04-20 20:08 - 2013-10-25 16:28 - 00000000 ____D () H:\AdwCleaner
2015-04-20 20:04 - 2010-11-18 19:35 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\Adobe
2015-04-20 20:03 - 2012-04-18 22:24 - 00778416 _____ (Adobe Systems Incorporated) H:\WINDOWS\system32\FlashPlayerApp.exe
2015-04-20 20:03 - 2011-08-26 22:30 - 00142512 _____ (Adobe Systems Incorporated) H:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-04-20 20:00 - 2012-02-18 21:41 - 00000000 ____D () H:\Program Files\Java
2015-04-20 19:59 - 2014-10-24 10:30 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Oracle
2015-04-20 19:57 - 2013-03-23 10:04 - 00096680 _____ (Oracle Corporation) H:\WINDOWS\system32\WindowsAccessBridge.dll
2015-04-20 19:57 - 2012-02-18 21:41 - 00146432 _____ (Oracle Corporation) H:\WINDOWS\system32\javacpl.cpl
2015-04-20 19:55 - 2010-11-12 21:43 - 00000000 ____D () H:\Documents and Settings\User\My Documents\programi
2015-04-20 19:19 - 2012-10-01 06:03 - 00073960 _____ () H:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2015-04-20 19:13 - 2013-10-09 06:27 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2862335$
2015-04-20 18:12 - 2010-11-12 08:04 - 00615742 _____ () H:\WINDOWS\system32\PerfStringBackup.INI
2015-04-20 18:00 - 2013-10-26 16:35 - 00000986 _____ () H:\WINDOWS\setupact.log
2015-04-20 17:57 - 2010-11-12 08:03 - 00286904 _____ () H:\WINDOWS\system32\FNTCACHE.DAT
2015-04-20 17:56 - 2010-11-12 13:31 - 00000000 __SHD () H:\Documents and Settings\LocalService
2015-04-20 17:56 - 2010-11-12 13:28 - 00000000 __SHD () H:\Documents and Settings\NetworkService
2015-04-20 17:56 - 2010-11-12 13:16 - 00000000 ____D () H:\WINDOWS\Registration
2015-04-20 17:55 - 2015-01-24 14:35 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype(2)
2015-04-20 17:55 - 2013-01-08 20:29 - 00000000 ____D () H:\Documents and Settings\User\Application Data\BitTorrent
2015-04-20 17:55 - 2012-09-18 23:37 - 00000000 ___RD () H:\Program Files\Skype
2015-04-20 17:55 - 2012-05-03 16:07 - 00000000 ____D () H:\Program Files\Mozilla Maintenance Service
2015-04-20 17:53 - 2015-02-23 22:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\hyde
2015-04-20 17:53 - 2015-02-23 20:21 - 00000000 ____D () H:\Documents and Settings\User\Desktop\b est of me
2015-04-20 17:53 - 2015-02-23 20:18 - 00000000 ____D () H:\Documents and Settings\User\Desktop\New Folder(2)
2015-04-20 17:53 - 2015-02-23 20:16 - 00000000 ____D () H:\Documents and Settings\User\Desktop\j789
2015-04-20 17:53 - 2015-02-23 20:16 - 00000000 ____D () H:\Documents and Settings\User\Desktop\j456
2015-04-20 17:53 - 2015-02-23 20:14 - 00000000 ____D () H:\Documents and Settings\User\Desktop\New Folder
2015-04-20 17:52 - 2013-07-15 23:21 - 00000000 ____D () H:\WINDOWS\system32\MRT
2015-04-20 17:06 - 2013-11-23 04:02 - 00519776 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2015-04-20 17:06 - 2010-11-12 13:17 - 00000000 ____D () H:\WINDOWS\system32\Restore
2015-04-20 16:40 - 2014-03-30 13:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\18
2015-04-19 23:43 - 2014-09-08 19:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-08
2015-04-19 00:18 - 2014-06-08 20:04 - 00000000 ____D () H:\Documents and Settings\User\My Documents\sub1
2015-04-18 23:20 - 2011-11-11 00:38 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2641690$
2015-04-18 21:13 - 2014-09-27 00:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Jardine bothanique
2015-04-18 21:13 - 2013-11-30 17:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\disain
2015-04-18 21:13 - 2013-10-27 02:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\krasivo
2015-04-18 21:13 - 2013-05-28 07:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\inter
2015-04-18 21:12 - 2015-01-06 00:00 - 00040260 _____ () H:\Documents and Settings\User\Desktop\bride.and.prejudice.2004.dvdrip.xvid-endi(subsunacs.net).zip.ecc
2015-04-18 21:12 - 2014-08-17 17:03 - 16454852 _____ () H:\Documents and Settings\User\Desktop\attachments_2014_08_17.zip.ecc
2015-04-18 20:58 - 2014-09-27 18:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-27
2015-04-18 20:29 - 2014-09-18 22:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-18
2015-04-18 20:06 - 2015-02-06 23:20 - 00188836 _____ () H:\Documents and Settings\User\Desktop\1066517_4543673565274_2119997541_o.jpg.ecc
2015-04-18 20:06 - 2015-01-08 21:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2
2015-04-18 20:06 - 2014-03-30 13:14 - 00014372 _____ () H:\Documents and Settings\User\Desktop\17.torent.ecc
2015-04-18 20:05 - 2012-08-10 15:44 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\bdch
2015-04-18 20:05 - 2012-02-17 06:40 - 00000000 __SHD () H:\Documents and Settings\NetworkService\IETldCache
2015-04-18 20:05 - 2010-11-13 00:57 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
2015-04-18 20:04 - 2014-10-24 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Java
2015-04-18 20:04 - 2014-04-26 11:43 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\JustVoip
2015-04-18 20:04 - 2013-02-16 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ooVoo
2015-04-18 20:04 - 2013-01-08 20:32 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
2015-04-18 20:04 - 2012-11-11 03:32 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\bdch
2015-04-18 20:04 - 2012-11-07 00:51 - 00000000 ____D () H:\Documents and Settings\LocalService\Application Data\QuickScan
2015-04-18 20:04 - 2012-07-08 00:07 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\D-Link
2015-04-18 20:04 - 2012-06-27 17:08 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
2015-04-18 20:04 - 2012-06-19 18:28 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\TechSmith
2015-04-18 20:04 - 2011-12-19 00:57 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft Help
2015-04-18 20:04 - 2011-12-18 18:15 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
2015-04-18 20:04 - 2011-12-17 19:54 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\DVDVideoSoft
2015-04-18 20:04 - 2011-10-16 20:17 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
2015-04-18 20:04 - 2011-05-17 16:09 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Keyboard
2015-04-18 20:04 - 2011-02-07 22:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
2015-04-18 20:04 - 2011-02-06 00:33 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
2015-04-18 20:04 - 2011-01-16 21:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Nero
2015-04-18 20:04 - 2010-12-01 20:18 - 00000000 ___SD () H:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 3.1
2015-04-18 20:04 - 2010-11-25 17:10 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\HP
2015-04-18 20:04 - 2010-11-15 22:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\LightScribe Direct Disc Labeling
2015-04-18 20:04 - 2010-11-13 00:52 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Google
2015-04-18 20:04 - 2010-11-12 23:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\AVS4YOU
2015-04-18 20:04 - 2010-11-12 22:16 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
2015-04-18 20:04 - 2010-11-12 21:42 - 00000000 __SHD () H:\Documents and Settings\LocalService\IETldCache
2015-04-18 20:04 - 2010-11-12 13:18 - 00000000 __SHD () H:\Documents and Settings\All Users\DRM
2015-04-18 20:04 - 2010-11-12 13:18 - 00000000 ___RD () H:\Documents and Settings\Default User\Start Menu\Programs\Accessories
2015-04-18 20:04 - 2010-11-12 13:16 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Games
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 __SHD () H:\Documents and Settings\Administrator\IETldCache
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft Help
2015-04-18 20:03 - 2011-01-16 21:24 - 00000000 ____D () H:\bb6fadc9d2f25f3b2953e5d2
2015-04-18 20:03 - 2010-11-12 02:18 - 00000000 ____D () H:\d688a5c03ea38202645f5bc01eeb02
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\a812a3d6-ecc8-4750-9477-c631757694a4.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\92c937b0-dfc0-4b6d-a16f-6fc079dec2a3.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\4e28d2f5-abaf-40c7-a2d7-f3a7ad9a45ff.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\0feed571-1be8-4bc1-8ccd-82480f9105ff.dmp.ecc
2015-04-18 19:20 - 2012-09-17 19:42 - 00029492 _____ () H:\.pdf.ecc
2015-04-18 19:20 - 2012-07-29 22:31 - 00465764 _____ () H:\112.pdf.ecc
2015-04-18 19:20 - 2012-02-28 14:22 - 00000000 ____D () H:\54c3cb947aef816ceabdedb8f7
2015-04-18 19:20 - 2012-02-11 14:34 - 00000000 ____D () H:\128b39739a3c8290c766a9
2015-04-18 19:20 - 2012-02-06 22:14 - 00000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1
2015-04-18 19:20 - 2012-02-01 15:45 - 00000000 ____D () H:\94677e1b4707d7452aa83d9d21
2015-04-17 23:45 - 2014-01-11 01:48 - 00000000 ____D () H:\Documents and Settings\User\My Documents\subtitle
2015-04-05 15:36 - 2014-06-08 18:50 - 00000000 ____D () H:\Documents and Settings\User\Desktop\l5678
2015-04-05 12:31 - 2012-06-15 14:53 - 00270848 ___SH () H:\Documents and Settings\User\Desktop\Thumbs.db
2015-04-03 15:46 - 2012-06-17 20:14 - 00000000 ____D () H:\Documents and Settings\User\My Documents\attestation

==================== Files in the root of some directories =======

2010-11-12 22:29 - 2015-01-14 18:38 - 0088064 _____ () H:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

H:\WINDOWS\explorer.exe => File is digitally signed
H:\WINDOWS\system32\winlogon.exe => File is digitally signed
H:\WINDOWS\system32\svchost.exe => File is digitally signed
H:\WINDOWS\system32\services.exe => File is digitally signed
H:\WINDOWS\system32\User32.dll => File is digitally signed
H:\WINDOWS\system32\userinit.exe => File is digitally signed
H:\WINDOWS\system32\rpcss.dll => File is digitally signed
H:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================


 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-04-2015 01
Ran by User (administrator) on PC-FB227302206B on 24-04-2015 08:03:50
Running from H:\Documents and Settings\User\My Documents\Downloads
Loaded Profiles: User (Available profiles: User & Administrator)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(HP) H:\WINDOWS\system32\HPSIsvc.exe
(Hewlett-Packard Company) H:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Nero AG) H:\Program Files\Nero\Update\NASvc.exe
() H:\Program Files\CDBurnerXP\NMSAccessU.exe
(Skype Technologies S.A.) H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\RunOnce: [*EmptyTemp] => cmd /c rd /q/s H:\FRST\Temp
Winlogon\Notify\igfxcui: H:\WINDOWS\system32\igfxsrvc.dll [2004-11-02] (Intel Corporation)
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: E - E:\Install.exe
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: {9eea6e54-11aa-11e2-ac0d-28107bbdacc7} - E:\KODAK_Software_Downloader.exe
HKU\S-1-5-18\...\RunOnce: [RunNarrator] => H:\WINDOWS\system32\Narrator.exe [53760 2008-04-14] (Microsoft Corporation)
Startup: H:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> H:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-20] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> H:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-20] (Oracle Corporation)
BHO: BHO_TIMELINEREMOVE.Bho -> {e7b9b609-19ad-40a4-a288-b300a3087465} -> H:\WINDOWS\system32\mscoree.dll [2010-03-18] (Microsoft Corporation)
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289583241062
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - H:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015
FF SelectedSearchEngine: Yahoo!
FF Homepage: https://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> H:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-20] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> H:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> H:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-20] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> h:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: Adobe Reader -> H:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1614895754-1645522239-1417001333-1003: @Skype Limited.com/Facebook Video Calling Plugin -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll [2012-10-12] (Skype Limited)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2012-01-12] (BitComet)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\google-dictionary-english-french.xml [2012-08-28]
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\wikipedia-franais-et-anglais.xml [2012-08-28]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\911bg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\pe-bg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml [2015-04-15]
FF Extension: United States English Spellchecker - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-05-19]
FF Extension: Dictionnaire français «Moderne» - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-01-08]
FF Extension: TimeLineRemove.Com - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-19]
FF Extension: Microsoft .NET Framework Assistant - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-11-14]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-20]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\trash [2012-08-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2015-04-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-11-12]
FF ExtraCheck: H:\Program Files\mozilla firefox\firefox.cfg [2015-01-15] <==== ATTENTION

Chrome:
=======
CHR Profile: H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Gmail) - H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-12]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 CCALib8; H:\Program Files\Canon\CAL\CALMAIN.exe [96341 2006-03-30] (Canon Inc.) [File not signed]
R3 hpqcxs08; H:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; H:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 LightScribeService; H:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-08-16] (Hewlett-Packard Company) [File not signed]
R2 NAUpdate; H:\Program Files\Nero\Update\NASvc.exe [573224 2011-01-26] (Nero AG)
R2 Net Driver HPZ12; H:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
R2 NMSAccess; H:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] ()
R2 Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Skype C2C Service; H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S2 WLSVC; H:\Program Files\D-Link\DWA-130 revE\WLSVC.exe [167936 2009-02-11] () [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AegisP; H:\WINDOWS\System32\DRIVERS\AegisP.sys [21361 2012-07-08] (Cisco Systems, Inc.) [File not signed]
S3 CCDECODE; H:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 HPZid412; H:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
S3 HPZipr12; H:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
S3 HPZius12; H:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
S3 NdisIP; H:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 rt2870; H:\WINDOWS\System32\DRIVERS\Drt2870.sys [829152 2010-05-06] (Ralink Technology, Corp.)
S3 rtl8139; H:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
R2 StarOpen; H:\WINDOWS\system32\Drivers\StarOpen.sys [5504 2009-11-12] () [File not signed]
R2 WLNdis50; H:\WINDOWS\System32\DRIVERS\wlndis50.sys [20480 2008-02-27] () [File not signed]
U1 WS2IFSL; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-21 18:51 - 2015-04-21 20:22 - 00000000 ____D () H:\Documents and Settings\User\Desktop\nik
2015-04-20 21:13 - 2015-04-20 21:13 - 00000104 _____ () H:\Documents and Settings\User\Desktop\Internet.lnk
2015-04-20 20:00 - 2015-04-20 20:00 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Sun
2015-04-20 19:49 - 2015-04-20 19:49 - 00000724 _____ () H:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
2015-04-20 19:26 - 2015-04-20 19:27 - 00031668 _____ () H:\Addition.txt
2015-04-20 19:25 - 2015-04-20 19:27 - 00040441 _____ () H:\FRST.txt
2015-04-20 19:24 - 2015-04-20 19:24 - 01139200 _____ (Farbar) H:\FRST.exe
2015-04-20 18:21 - 2015-04-20 19:40 - 00119512 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-04-20 18:21 - 2015-04-20 18:21 - 00000777 _____ () H:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-20 18:21 - 2015-04-14 09:37 - 00120024 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-04-20 18:21 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbam.sys
2015-04-20 18:17 - 2015-04-20 18:17 - 21546080 _____ (Malwarebytes Corporation ) H:\mbam-setup-consumer-2.1.6.1022.exe
2015-04-20 17:55 - 2015-04-21 20:17 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 5 - Историография - Ново време
2015-04-20 17:55 - 2015-04-20 19:49 - 00000000 ____D () H:\Program Files\Mozilla Firefox
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Program Files\Common Files\Skype
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 4 - Историография - Праистория и Античност
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 2 - Историография - Средновековие
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 1 - Източници и изворознание
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\snow queen tous
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\end2
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9outs
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9 end
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\29r
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2 outs
2015-04-20 16:49 - 2015-04-20 17:47 - 00000000 ____D () H:\Program Files\ShadowExplorer
2015-04-20 16:49 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ShadowExplorer
2015-04-20 09:49 - 2015-04-20 09:49 - 00008984 _____ () H:\Documents and Settings\User\Desktop\mbam1.txt
2015-04-20 09:46 - 2015-04-20 19:18 - 00004663 _____ () H:\Documents and Settings\User\Desktop\mbam.txt
2015-04-20 07:09 - 2015-04-24 08:03 - 00000000 ____D () H:\FRST
2015-04-18 23:18 - 2015-04-18 23:18 - 00008536 _____ () H:\Documents and Settings\Administrator\Desktop\mb scan.txt
2015-04-18 21:49 - 2015-04-20 18:21 - 00000000 ____D () H:\Program Files\Malwarebytes Anti-Malware
2015-04-18 21:30 - 2015-04-18 21:41 - 00003572 _____ () H:\Documents and Settings\Administrator\Desktop\Rkill.txt
2015-04-18 21:21 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Mozilla
2015-04-18 21:21 - 2015-04-18 21:21 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Macromedia
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Adobe
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Desktop\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 19:50 - 2015-04-18 23:16 - 00001324 _____ () H:\WINDOWS\system32\d3d9caps.dat
2015-04-12 01:28 - 2015-04-18 20:06 - 00113732 _____ () H:\Documents and Settings\User\Desktop\10470717_10152942390179635_5357236154732284632_n.jpg.ecc
2015-04-12 01:27 - 2015-04-18 20:06 - 00054468 _____ () H:\Documents and Settings\User\Desktop\11145571_10152958877974635_3339765670712915872_n.jpg.ecc
2015-04-05 12:26 - 2015-04-18 20:06 - 00090580 _____ () H:\Documents and Settings\User\Desktop\11138672_982700228409538_8855858409597611766_n.jpg.ecc
2015-04-04 01:57 - 2015-04-04 02:02 - 00000000 ____D () H:\Documents and Settings\User\My Documents\Attestation123
2015-04-04 01:56 - 2015-04-18 21:12 - 00381604 _____ () H:\Documents and Settings\User\Desktop\Attestation2.pdf.ecc
2015-04-03 14:06 - 2015-04-03 14:06 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\Hewlett-Packard
2015-04-01 15:28 - 2015-04-18 20:06 - 00038404 _____ () H:\Documents and Settings\User\Desktop\11096536_10153198374462173_1538024734260084523_n.jpg.ecc
2015-03-29 22:34 - 2015-04-18 20:06 - 00058036 _____ () H:\Documents and Settings\User\Desktop\10923243_823850137672875_4923851942726001590_n.jpg.ecc
2015-03-25 17:48 - 2015-04-20 16:10 - 00001748 _____ () H:\Documents and Settings\User\Desktop\doc_57.png.ecc
2015-03-25 15:31 - 2015-04-18 20:06 - 00061220 _____ () H:\Documents and Settings\User\Desktop\0cb712a19e742a9725b3c7cf78a6d908_600x460.jpg.ecc

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-24 08:04 - 2010-11-12 13:32 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Temp
2015-04-24 07:25 - 2010-11-12 13:31 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Temp
2015-04-24 07:16 - 2001-08-23 08:00 - 00002206 _____ () H:\WINDOWS\system32\wpa.dbl
2015-04-24 07:15 - 2010-11-12 13:18 - 01949850 _____ () H:\WINDOWS\WindowsUpdate.log
2015-04-24 07:14 - 2010-11-12 13:31 - 00000006 ____H () H:\WINDOWS\Tasks\SA.DAT
2015-04-24 07:14 - 2010-11-12 08:08 - 00000299 _____ () H:\WINDOWS\wiadebug.log
2015-04-24 07:14 - 2010-11-12 08:08 - 00000052 _____ () H:\WINDOWS\wiaservc.log
2015-04-24 05:57 - 2012-06-30 23:39 - 00001148 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003UA.job
2015-04-23 19:21 - 2013-12-07 23:22 - 00000000 ___RD () H:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
2015-04-23 19:21 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator
2015-04-23 19:19 - 2010-11-12 13:14 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Accessories
2015-04-23 17:57 - 2012-06-30 23:39 - 00001126 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003Core.job
2015-04-23 16:39 - 2013-10-26 17:49 - 00000000 ____D () H:\Documents and Settings\User\My Documents\AS-CV
2015-04-23 06:57 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Temp
2015-04-23 06:53 - 2010-11-12 13:28 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Temp
2015-04-23 06:52 - 2010-11-12 08:04 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Temp
2015-04-23 06:42 - 2013-10-26 16:34 - 00278076 _____ () H:\WINDOWS\setupapi.log
2015-04-23 05:47 - 2010-11-12 13:32 - 00000178 ___SH () H:\Documents and Settings\User\ntuser.ini
2015-04-23 05:47 - 2010-11-12 13:31 - 00031772 _____ () H:\WINDOWS\SchedLgU.Txt
2015-04-22 23:11 - 2013-10-27 02:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\moda
2015-04-21 20:23 - 2012-05-14 19:46 - 00002465 _____ () H:\Documents and Settings\All Users\Desktop\Nero StartSmart 10.lnk
2015-04-21 18:51 - 2014-02-15 20:44 - 00000000 ____D () H:\Documents and Settings\User\Desktop\sub.vvv
2015-04-21 08:27 - 2014-07-27 00:13 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-27
2015-04-21 08:26 - 2014-09-02 22:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-02
2015-04-21 08:26 - 2014-08-31 00:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-31
2015-04-21 08:25 - 2014-07-13 19:22 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-13
2015-04-21 08:25 - 2014-05-20 13:45 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-05-20
2015-04-21 08:24 - 2014-08-28 20:43 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-28
2015-04-21 08:14 - 2001-08-23 08:00 - 00000630 _____ () H:\WINDOWS\win.ini
2015-04-21 08:14 - 2001-08-23 08:00 - 00000227 _____ () H:\WINDOWS\system.ini
2015-04-21 07:54 - 2012-02-11 11:47 - 00002265 _____ () H:\Documents and Settings\All Users\Desktop\Skype.lnk
2015-04-21 07:54 - 2010-11-13 00:51 - 00000000 ____D () H:\Documents and Settings\User\Application Data\Skype
2015-04-20 20:08 - 2013-10-25 16:28 - 00000000 ____D () H:\AdwCleaner
2015-04-20 20:04 - 2010-11-18 19:35 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\Adobe
2015-04-20 20:03 - 2012-04-18 22:24 - 00778416 _____ (Adobe Systems Incorporated) H:\WINDOWS\system32\FlashPlayerApp.exe
2015-04-20 20:03 - 2011-08-26 22:30 - 00142512 _____ (Adobe Systems Incorporated) H:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-04-20 20:00 - 2012-02-18 21:41 - 00000000 ____D () H:\Program Files\Java
2015-04-20 19:59 - 2014-10-24 10:30 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Oracle
2015-04-20 19:57 - 2013-03-23 10:04 - 00096680 _____ (Oracle Corporation) H:\WINDOWS\system32\WindowsAccessBridge.dll
2015-04-20 19:57 - 2012-02-18 21:41 - 00146432 _____ (Oracle Corporation) H:\WINDOWS\system32\javacpl.cpl
2015-04-20 19:55 - 2010-11-12 21:43 - 00000000 ____D () H:\Documents and Settings\User\My Documents\programi
2015-04-20 19:19 - 2012-10-01 06:03 - 00073960 _____ () H:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2015-04-20 19:13 - 2013-10-09 06:27 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2862335$
2015-04-20 18:12 - 2010-11-12 08:04 - 00615742 _____ () H:\WINDOWS\system32\PerfStringBackup.INI
2015-04-20 18:00 - 2013-10-26 16:35 - 00000986 _____ () H:\WINDOWS\setupact.log
2015-04-20 17:57 - 2010-11-12 08:03 - 00286904 _____ () H:\WINDOWS\system32\FNTCACHE.DAT
2015-04-20 17:56 - 2010-11-12 13:31 - 00000000 __SHD () H:\Documents and Settings\LocalService
2015-04-20 17:56 - 2010-11-12 13:28 - 00000000 __SHD () H:\Documents and Settings\NetworkService
2015-04-20 17:56 - 2010-11-12 13:16 - 00000000 ____D () H:\WINDOWS\Registration
2015-04-20 17:55 - 2015-01-24 14:35 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype(2)
2015-04-20 17:55 - 2013-01-08 20:29 - 00000000 ____D () H:\Documents and Settings\User\Application Data\BitTorrent
2015-04-20 17:55 - 2012-09-18 23:37 - 00000000 ___RD () H:\Program Files\Skype
2015-04-20 17:55 - 2012-05-03 16:07 - 00000000 ____D () H:\Program Files\Mozilla Maintenance Service
2015-04-20 17:53 - 2015-02-23 22:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\hyde
2015-04-20 17:53 - 2015-02-23 20:21 - 00000000 ____D () H:\Documents and Settings\User\Desktop\b est of me
2015-04-20 17:53 - 2015-02-23 20:18 - 00000000 ____D () H:\Documents and Settings\User\Desktop\New Folder(2)
2015-04-20 17:53 - 2015-02-23 20:16 - 00000000 ____D () H:\Documents and Settings\User\Desktop\j789
2015-04-20 17:53 - 2015-02-23 20:16 - 00000000 ____D () H:\Documents and Settings\User\Desktop\j456
2015-04-20 17:53 - 2015-02-23 20:14 - 00000000 ____D () H:\Documents and Settings\User\Desktop\New Folder
2015-04-20 17:52 - 2013-07-15 23:21 - 00000000 ____D () H:\WINDOWS\system32\MRT
2015-04-20 17:06 - 2013-11-23 04:02 - 00519776 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2015-04-20 17:06 - 2010-11-12 13:17 - 00000000 ____D () H:\WINDOWS\system32\Restore
2015-04-20 16:40 - 2014-03-30 13:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\18
2015-04-19 23:43 - 2014-09-08 19:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-08
2015-04-19 00:18 - 2014-06-08 20:04 - 00000000 ____D () H:\Documents and Settings\User\My Documents\sub1
2015-04-18 23:20 - 2011-11-11 00:38 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2641690$
2015-04-18 21:13 - 2014-09-27 00:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Jardine bothanique
2015-04-18 21:13 - 2013-11-30 17:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\disain
2015-04-18 21:13 - 2013-10-27 02:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\krasivo
2015-04-18 21:13 - 2013-05-28 07:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\inter
2015-04-18 21:12 - 2015-01-06 00:00 - 00040260 _____ () H:\Documents and Settings\User\Desktop\bride.and.prejudice.2004.dvdrip.xvid-endi(subsunacs.net).zip.ecc
2015-04-18 21:12 - 2014-08-17 17:03 - 16454852 _____ () H:\Documents and Settings\User\Desktop\attachments_2014_08_17.zip.ecc
2015-04-18 20:58 - 2014-09-27 18:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-27
2015-04-18 20:29 - 2014-09-18 22:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-18
2015-04-18 20:06 - 2015-02-06 23:20 - 00188836 _____ () H:\Documents and Settings\User\Desktop\1066517_4543673565274_2119997541_o.jpg.ecc
2015-04-18 20:06 - 2015-01-08 21:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2
2015-04-18 20:06 - 2014-03-30 13:14 - 00014372 _____ () H:\Documents and Settings\User\Desktop\17.torent.ecc
2015-04-18 20:05 - 2012-08-10 15:44 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\bdch
2015-04-18 20:05 - 2012-02-17 06:40 - 00000000 __SHD () H:\Documents and Settings\NetworkService\IETldCache
2015-04-18 20:05 - 2010-11-13 00:57 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
2015-04-18 20:04 - 2014-10-24 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Java
2015-04-18 20:04 - 2014-04-26 11:43 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\JustVoip
2015-04-18 20:04 - 2013-02-16 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ooVoo
2015-04-18 20:04 - 2013-01-08 20:32 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
2015-04-18 20:04 - 2012-11-11 03:32 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\bdch
2015-04-18 20:04 - 2012-11-07 00:51 - 00000000 ____D () H:\Documents and Settings\LocalService\Application Data\QuickScan
2015-04-18 20:04 - 2012-07-08 00:07 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\D-Link
2015-04-18 20:04 - 2012-06-27 17:08 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
2015-04-18 20:04 - 2012-06-19 18:28 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\TechSmith
2015-04-18 20:04 - 2011-12-19 00:57 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft Help
2015-04-18 20:04 - 2011-12-18 18:15 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
2015-04-18 20:04 - 2011-12-17 19:54 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\DVDVideoSoft
2015-04-18 20:04 - 2011-10-16 20:17 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
2015-04-18 20:04 - 2011-05-17 16:09 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Keyboard
2015-04-18 20:04 - 2011-02-07 22:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
2015-04-18 20:04 - 2011-02-06 00:33 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
2015-04-18 20:04 - 2011-01-16 21:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Nero
2015-04-18 20:04 - 2010-12-01 20:18 - 00000000 ___SD () H:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 3.1
2015-04-18 20:04 - 2010-11-25 17:10 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\HP
2015-04-18 20:04 - 2010-11-15 22:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\LightScribe Direct Disc Labeling
2015-04-18 20:04 - 2010-11-13 00:52 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Google
2015-04-18 20:04 - 2010-11-12 23:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\AVS4YOU
2015-04-18 20:04 - 2010-11-12 22:16 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
2015-04-18 20:04 - 2010-11-12 21:42 - 00000000 __SHD () H:\Documents and Settings\LocalService\IETldCache
2015-04-18 20:04 - 2010-11-12 13:18 - 00000000 __SHD () H:\Documents and Settings\All Users\DRM
2015-04-18 20:04 - 2010-11-12 13:18 - 00000000 ___RD () H:\Documents and Settings\Default User\Start Menu\Programs\Accessories
2015-04-18 20:04 - 2010-11-12 13:16 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Games
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 __SHD () H:\Documents and Settings\Administrator\IETldCache
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft Help
2015-04-18 20:03 - 2011-01-16 21:24 - 00000000 ____D () H:\bb6fadc9d2f25f3b2953e5d2
2015-04-18 20:03 - 2010-11-12 02:18 - 00000000 ____D () H:\d688a5c03ea38202645f5bc01eeb02
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\a812a3d6-ecc8-4750-9477-c631757694a4.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\92c937b0-dfc0-4b6d-a16f-6fc079dec2a3.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\4e28d2f5-abaf-40c7-a2d7-f3a7ad9a45ff.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\0feed571-1be8-4bc1-8ccd-82480f9105ff.dmp.ecc
2015-04-18 19:20 - 2012-09-17 19:42 - 00029492 _____ () H:\.pdf.ecc
2015-04-18 19:20 - 2012-07-29 22:31 - 00465764 _____ () H:\112.pdf.ecc
2015-04-18 19:20 - 2012-02-28 14:22 - 00000000 ____D () H:\54c3cb947aef816ceabdedb8f7
2015-04-18 19:20 - 2012-02-11 14:34 - 00000000 ____D () H:\128b39739a3c8290c766a9
2015-04-18 19:20 - 2012-02-06 22:14 - 00000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1
2015-04-18 19:20 - 2012-02-01 15:45 - 00000000 ____D () H:\94677e1b4707d7452aa83d9d21
2015-04-17 23:45 - 2014-01-11 01:48 - 00000000 ____D () H:\Documents and Settings\User\My Documents\subtitle
2015-04-05 15:36 - 2014-06-08 18:50 - 00000000 ____D () H:\Documents and Settings\User\Desktop\l5678
2015-04-05 12:31 - 2012-06-15 14:53 - 00270848 ___SH () H:\Documents and Settings\User\Desktop\Thumbs.db
2015-04-03 15:46 - 2012-06-17 20:14 - 00000000 ____D () H:\Documents and Settings\User\My Documents\attestation

==================== Files in the root of some directories =======

2010-11-12 22:29 - 2015-01-14 18:38 - 0088064 _____ () H:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

H:\WINDOWS\explorer.exe => File is digitally signed
H:\WINDOWS\system32\winlogon.exe => File is digitally signed
H:\WINDOWS\system32\svchost.exe => File is digitally signed
H:\WINDOWS\system32\services.exe => File is digitally signed
H:\WINDOWS\system32\User32.dll => File is digitally signed
H:\WINDOWS\system32\userinit.exe => File is digitally signed
H:\WINDOWS\system32\rpcss.dll => File is digitally signed
H:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================

 

 

 

 

 

 

 

 

 

 

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-04-2015
Ran by User (administrator) on PC-FB227302206B on 20-04-2015 19:25:36
Running from H:\
Loaded Profiles: User (Available profiles: User & Administrator)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(HP) H:\WINDOWS\system32\HPSIsvc.exe
(Hewlett-Packard Company) H:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Nero AG) H:\Program Files\Nero\Update\NASvc.exe
() H:\Program Files\CDBurnerXP\NMSAccessU.exe
(Skype Technologies S.A.) H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Microsoft Corporation) H:\WINDOWS\system32\wscntfy.exe
(Microsoft Corporation) H:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) H:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) H:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

Winlogon\Notify\crypt32chain: H:\WINDOWS\system32\crypt32.dll [2013-10-07] (Microsoft Corporation)
Winlogon\Notify\cryptnet: H:\WINDOWS\system32\cryptnet.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\cscdll: H:\WINDOWS\system32\cscdll.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\igfxcui: H:\WINDOWS\system32\igfxsrvc.dll [2004-11-02] (Intel Corporation)
Winlogon\Notify\ScCertProp: H:\WINDOWS\system32\wlnotify.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\Schedule: H:\WINDOWS\system32\wlnotify.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\sclgntfy: H:\WINDOWS\system32\sclgntfy.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\SensLogn: H:\WINDOWS\system32\WlNotify.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\termsrv: H:\WINDOWS\system32\wlnotify.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\WgaLogon: H:\WINDOWS\system32\WgaLogon.dll [2009-03-10] (Microsoft Corporation)
Winlogon\Notify\wlballoon: H:\WINDOWS\system32\wlnotify.dll [2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: E - E:\Install.exe
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: {9eea6e54-11aa-11e2-ac0d-28107bbdacc7} - E:\KODAK_Software_Downloader.exe
HKU\S-1-5-18\...\RunOnce: [RunNarrator] => H:\WINDOWS\system32\Narrator.exe [53760 2008-04-14] (Microsoft Corporation)
Startup: H:\Documents and Settings\Administrator\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()
Startup: H:\Documents and Settings\All Users\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()
Startup: H:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
URLSearchHook: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 - (No Name) - {2877A654-1C9F-4cb5-8438-16022B2FDD9C} -  No File
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "H:\Program Files\YoutubeDownloader.org\YouTubeDownloader\index.htm" <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 -> {0097EC7C-F4EB-4CB9-9D3B-AAE8ADF495C9} URL =
SearchScopes: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 -> {7479720C-8CF4-43A4-8C91-74F7AD68A389} URL =
SearchScopes: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 -> {E081D2FE-7439-4CBB-BC99-992158614ED4} URL =
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> H:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2014-10-24] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> H:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-10-24] (Oracle Corporation)
BHO: BHO_TIMELINEREMOVE.Bho -> {e7b9b609-19ad-40a4-a288-b300a3087465} -> H:\WINDOWS\system32\mscoree.dll [2010-03-18] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289583241062
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - H:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015
FF SelectedSearchEngine: Yahoo!
FF Homepage: https://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> H:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll [2014-10-24] ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> H:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-10-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin -> H:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-10-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> H:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-10-24] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> h:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: Adobe Reader -> H:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1614895754-1645522239-1417001333-1003: @Skype Limited.com/Facebook Video Calling Plugin -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll [2012-10-12] (Skype Limited)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2012-01-12] (BitComet)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\google-dictionary-english-french.xml [2012-08-28]
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\wikipedia-franais-et-anglais.xml [2012-08-28]
FF Extension: United States English Spellchecker - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-05-19]
FF Extension: Dictionnaire français «Moderne» - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-01-08]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-19]
FF Extension: ALOT Toolbar - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-04-19]
FF Extension: Microsoft .NET Framework Assistant - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-11-14]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-20]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\trash [2012-08-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2015-04-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-11-12]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - H:\Program Files\Bitdefender\Bitdefender 2012\bdtbext
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015\extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7} [Not Found]
FF ExtraCheck: H:\Program Files\mozilla firefox\firefox.cfg [2015-01-15] <==== ATTENTION

Chrome:
=======
CHR Profile: H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Gmail) - H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-12]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 CCALib8; H:\Program Files\Canon\CAL\CALMAIN.exe [96341 2006-03-30] (Canon Inc.) [File not signed]
R3 hpqcxs08; H:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; H:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
S2 JavaQuickStarterService; H:\Program Files\Java\jre7\bin\jqs.exe [170912 2013-03-23] (Oracle Corporation)
R2 LightScribeService; H:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-08-16] (Hewlett-Packard Company) [File not signed]
R2 NAUpdate; H:\Program Files\Nero\Update\NASvc.exe [573224 2011-01-26] (Nero AG)
R2 Net Driver HPZ12; H:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
R2 NMSAccess; H:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] ()
R2 Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Skype C2C Service; H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S2 WLSVC; H:\Program Files\D-Link\DWA-130 revE\WLSVC.exe [167936 2009-02-11] () [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AegisP; H:\WINDOWS\System32\DRIVERS\AegisP.sys [21361 2012-07-08] (Cisco Systems, Inc.) [File not signed]
S3 CCDECODE; H:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 HPZid412; H:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
S3 HPZipr12; H:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
S3 HPZius12; H:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
S3 NdisIP; H:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 rt2870; H:\WINDOWS\System32\DRIVERS\Drt2870.sys [829152 2010-05-06] (Ralink Technology, Corp.)
S3 rtl8139; H:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
R2 StarOpen; H:\WINDOWS\system32\Drivers\StarOpen.sys [5504 2009-11-12] () [File not signed]
R2 WLNdis50; H:\WINDOWS\System32\DRIVERS\wlndis50.sys [20480 2008-02-27] () [File not signed]
U1 WS2IFSL; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-20 19:25 - 2015-04-20 19:26 - 00013673 _____ () H:\FRST.txt
2015-04-20 19:24 - 2015-04-20 19:24 - 01139200 _____ (Farbar) H:\FRST.exe
2015-04-20 18:21 - 2015-04-20 19:17 - 00119512 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-04-20 18:21 - 2015-04-20 18:21 - 00000777 _____ () H:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-20 18:21 - 2015-04-14 09:37 - 00120024 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-04-20 18:21 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbam.sys
2015-04-20 18:17 - 2015-04-20 18:17 - 21546080 _____ (Malwarebytes Corporation ) H:\mbam-setup-consumer-2.1.6.1022.exe
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Program Files\Mozilla Firefox
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Program Files\Common Files\Skype
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 5 - Историография - Ново време
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 4 - Историография - Праистория и Античност
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 2 - Историография - Средновековие
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 1 - Източници и изворознание
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\snow queen tous
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\end2
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9outs
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9end 2outsFait
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9 end
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\29r
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2 outs
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Sun
2015-04-20 16:49 - 2015-04-20 17:47 - 00000000 ____D () H:\Program Files\ShadowExplorer
2015-04-20 16:49 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ShadowExplorer
2015-04-20 09:49 - 2015-04-20 09:49 - 00008984 _____ () H:\Documents and Settings\User\Desktop\mbam1.txt
2015-04-20 09:46 - 2015-04-20 19:18 - 00004663 _____ () H:\Documents and Settings\User\Desktop\mbam.txt
2015-04-20 07:09 - 2015-04-20 19:25 - 00000000 ____D () H:\FRST
2015-04-18 23:18 - 2015-04-18 23:18 - 00008536 _____ () H:\Documents and Settings\Administrator\Desktop\mb scan.txt
2015-04-18 21:49 - 2015-04-20 18:21 - 00000000 ____D () H:\Program Files\Malwarebytes Anti-Malware
2015-04-18 21:30 - 2015-04-18 21:41 - 00003572 _____ () H:\Documents and Settings\Administrator\Desktop\Rkill.txt
2015-04-18 21:21 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Mozilla
2015-04-18 21:21 - 2015-04-18 21:21 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Macromedia
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Adobe
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\User\AppData\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\LocalService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Desktop\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\All Users\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\All Users\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\All Users\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Desktop\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 19:50 - 2015-04-18 23:16 - 00001324 _____ () H:\WINDOWS\system32\d3d9caps.dat
2015-04-18 19:20 - 2015-04-18 21:13 - 01592102 _____ () H:\Documents and Settings\User\Application Data\log.html
2015-04-18 19:20 - 2015-04-18 20:00 - 00000232 _____ () H:\Documents and Settings\User\My Documents\RECOVERY_KEY.TXT
2015-04-18 19:20 - 2015-04-18 19:20 - 00000752 _____ () H:\Documents and Settings\User\Application Data\key.dat
2015-04-18 18:58 - 2015-04-20 17:47 - 00000000 ___HD () H:\Documents and Settings\All Users\Application Data\{B6F1BED8-A80E-4513-86C2-4F7968A2433C}
2015-04-18 18:58 - 2015-04-18 18:58 - 00408600 _____ () H:\Documents and Settings\User\Local Settings\Application Data\znilrcjwzi.dat
2015-04-12 01:28 - 2015-04-18 20:06 - 00113732 _____ () H:\Documents and Settings\User\Desktop\10470717_10152942390179635_5357236154732284632_n.jpg.ecc
2015-04-12 01:27 - 2015-04-18 20:06 - 00054468 _____ () H:\Documents and Settings\User\Desktop\11145571_10152958877974635_3339765670712915872_n.jpg.ecc
2015-04-05 12:26 - 2015-04-18 20:06 - 00090580 _____ () H:\Documents and Settings\User\Desktop\11138672_982700228409538_8855858409597611766_n.jpg.ecc
2015-04-04 01:57 - 2015-04-04 02:02 - 00000000 ____D () H:\Documents and Settings\User\My Documents\Attestation123
2015-04-04 01:56 - 2015-04-18 21:12 - 00381604 _____ () H:\Documents and Settings\User\Desktop\Attestation2.pdf.ecc
2015-04-03 14:06 - 2015-04-03 14:06 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\Hewlett-Packard
2015-04-01 15:28 - 2015-04-18 20:06 - 00038404 _____ () H:\Documents and Settings\User\Desktop\11096536_10153198374462173_1538024734260084523_n.jpg.ecc
2015-03-29 22:34 - 2015-04-18 20:06 - 00058036 _____ () H:\Documents and Settings\User\Desktop\10923243_823850137672875_4923851942726001590_n.jpg.ecc
2015-03-25 17:48 - 2015-04-20 16:10 - 00001748 _____ () H:\Documents and Settings\User\Desktop\doc_57.png.ecc
2015-03-25 15:31 - 2015-04-18 20:06 - 00061220 _____ () H:\Documents and Settings\User\Desktop\0cb712a19e742a9725b3c7cf78a6d908_600x460.jpg.ecc

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-20 19:26 - 2010-11-12 13:32 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Temp
2015-04-20 19:19 - 2012-10-01 06:03 - 00073960 _____ () H:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2015-04-20 19:15 - 2001-08-23 08:00 - 00002206 _____ () H:\WINDOWS\system32\wpa.dbl
2015-04-20 19:14 - 2010-11-12 13:18 - 01932669 _____ () H:\WINDOWS\WindowsUpdate.log
2015-04-20 19:13 - 2015-01-14 14:50 - 00000220 _____ () H:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-04-20 19:13 - 2013-10-09 06:27 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2862335$
2015-04-20 19:13 - 2010-11-12 13:31 - 00000006 ____H () H:\WINDOWS\Tasks\SA.DAT
2015-04-20 19:13 - 2010-11-12 08:08 - 00000300 _____ () H:\WINDOWS\wiadebug.log
2015-04-20 19:13 - 2010-11-12 08:08 - 00000052 _____ () H:\WINDOWS\wiaservc.log
2015-04-20 19:12 - 2010-11-12 13:32 - 00000178 ___SH () H:\Documents and Settings\User\ntuser.ini
2015-04-20 19:12 - 2010-11-12 13:31 - 00032490 _____ () H:\WINDOWS\SchedLgU.Txt
2015-04-20 18:13 - 2012-04-18 22:24 - 00000830 _____ () H:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-04-20 18:12 - 2010-11-12 08:04 - 00615742 _____ () H:\WINDOWS\system32\PerfStringBackup.INI
2015-04-20 18:00 - 2013-10-26 16:35 - 00000986 _____ () H:\WINDOWS\setupact.log
2015-04-20 18:00 - 2013-10-26 16:34 - 00277602 _____ () H:\WINDOWS\setupapi.log
2015-04-20 17:57 - 2010-11-12 08:03 - 00286904 _____ () H:\WINDOWS\system32\FNTCACHE.DAT
2015-04-20 17:56 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator
2015-04-20 17:56 - 2010-11-12 13:31 - 00000000 __SHD () H:\Documents and Settings\LocalService
2015-04-20 17:56 - 2010-11-12 13:28 - 00000000 __SHD () H:\Documents and Settings\NetworkService
2015-04-20 17:56 - 2010-11-12 13:16 - 00000000 ____D () H:\WINDOWS\Registration
2015-04-20 17:55 - 2015-01-24 14:35 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype(2)
2015-04-20 17:55 - 2013-01-08 20:29 - 00000000 ____D () H:\Documents and Settings\User\Application Data\BitTorrent
2015-04-20 17:55 - 2012-09-18 23:37 - 00000000 ___RD () H:\Program Files\Skype
2015-04-20 17:55 - 2012-05-03 16:07 - 00000000 ____D () H:\Program Files\Mozilla Maintenance Service
2015-04-20 17:53 - 2015-02-23 22:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\hyde
2015-04-20 17:53 - 2015-02-23 20:21 - 00000000 ____D () H:\Documents and Settings\User\Desktop\b est of me
2015-04-20 17:53 - 2015-02-23 20:18 - 00000000 ____D () H:\Documents and Settings\User\Desktop\New Folder(2)
2015-04-20 17:53 - 2015-02-23 20:16 - 00000000 ____D () H:\Documents and Settings\User\Desktop\j789
2015-04-20 17:53 - 2015-02-23 20:16 - 00000000 ____D () H:\Documents and Settings\User\Desktop\j456
2015-04-20 17:53 - 2015-02-23 20:14 - 00000000 ____D () H:\Documents and Settings\User\Desktop\New Folder
2015-04-20 17:52 - 2013-07-15 23:21 - 00000000 ____D () H:\WINDOWS\system32\MRT
2015-04-20 17:46 - 2014-12-13 23:36 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\YTD YouTube Downloader & Converter
2015-04-20 17:06 - 2013-11-23 04:02 - 00519776 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2015-04-20 17:06 - 2010-11-12 13:17 - 00000000 ____D () H:\WINDOWS\system32\Restore
2015-04-20 16:40 - 2014-03-30 13:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\18
2015-04-20 14:57 - 2012-06-30 23:39 - 00001148 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003UA.job
2015-04-19 23:43 - 2014-09-08 19:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-08
2015-04-19 17:57 - 2012-06-30 23:39 - 00001126 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003Core.job
2015-04-19 08:57 - 2010-11-13 00:51 - 00000000 ____D () H:\Documents and Settings\User\Application Data\Skype
2015-04-19 00:18 - 2014-06-08 20:04 - 00000000 ____D () H:\Documents and Settings\User\My Documents\sub1
2015-04-18 23:26 - 2012-02-18 21:41 - 00000000 ____D () H:\Program Files\Java
2015-04-18 23:20 - 2011-11-11 00:38 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2641690$
2015-04-18 23:17 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Temp
2015-04-18 21:13 - 2014-09-27 00:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Jardine bothanique
2015-04-18 21:13 - 2013-11-30 17:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\disain
2015-04-18 21:13 - 2013-10-27 02:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\krasivo
2015-04-18 21:13 - 2013-05-28 07:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\inter
2015-04-18 21:12 - 2015-01-06 00:00 - 00040260 _____ () H:\Documents and Settings\User\Desktop\bride.and.prejudice.2004.dvdrip.xvid-endi(subsunacs.net).zip.ecc
2015-04-18 21:12 - 2014-08-17 17:03 - 16454852 _____ () H:\Documents and Settings\User\Desktop\attachments_2014_08_17.zip.ecc
2015-04-18 20:58 - 2014-09-27 18:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-27
2015-04-18 20:29 - 2014-09-18 22:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-18
2015-04-18 20:21 - 2014-09-02 22:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-02
2015-04-18 20:21 - 2014-08-31 00:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-31
2015-04-18 20:17 - 2014-08-28 20:43 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-28
2015-04-18 20:14 - 2014-07-27 00:13 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-27
2015-04-18 20:10 - 2014-07-13 19:22 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-13
2015-04-18 20:10 - 2014-05-20 13:45 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-05-20
2015-04-18 20:06 - 2015-02-06 23:20 - 00188836 _____ () H:\Documents and Settings\User\Desktop\1066517_4543673565274_2119997541_o.jpg.ecc
2015-04-18 20:06 - 2015-01-08 21:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2
2015-04-18 20:06 - 2014-03-30 13:14 - 00014372 _____ () H:\Documents and Settings\User\Desktop\17.torent.ecc
2015-04-18 20:05 - 2012-08-10 15:44 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\bdch
2015-04-18 20:05 - 2012-02-17 06:40 - 00000000 __SHD () H:\Documents and Settings\NetworkService\IETldCache
2015-04-18 20:05 - 2010-11-13 00:57 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
2015-04-18 20:05 - 2010-11-12 13:31 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Temp
2015-04-18 20:05 - 2010-11-12 13:28 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Temp
2015-04-18 20:04 - 2014-10-24 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Java
2015-04-18 20:04 - 2014-04-26 11:43 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\JustVoip
2015-04-18 20:04 - 2013-02-16 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ooVoo
2015-04-18 20:04 - 2013-01-08 20:32 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
2015-04-18 20:04 - 2012-11-11 03:32 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\bdch
2015-04-18 20:04 - 2012-11-07 00:51 - 00000000 ____D () H:\Documents and Settings\LocalService\Application Data\QuickScan
2015-04-18 20:04 - 2012-07-08 00:07 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\D-Link
2015-04-18 20:04 - 2012-06-27 17:08 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
2015-04-18 20:04 - 2012-06-19 18:28 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\TechSmith
2015-04-18 20:04 - 2011-12-19 00:57 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft Help
2015-04-18 20:04 - 2011-12-18 18:15 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
2015-04-18 20:04 - 2011-12-17 19:54 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\DVDVideoSoft
2015-04-18 20:04 - 2011-10-16 20:17 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
2015-04-18 20:04 - 2011-08-30 22:30 - 00000000 ____D () H:\Documents and Settings\LocalService\Application Data\McAfee
2015-04-18 20:04 - 2011-05-17 16:09 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Keyboard
2015-04-18 20:04 - 2011-02-07 22:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
2015-04-18 20:04 - 2011-02-06 00:33 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
2015-04-18 20:04 - 2011-01-16 21:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Nero
2015-04-18 20:04 - 2010-12-01 20:18 - 00000000 ___SD () H:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 3.1
2015-04-18 20:04 - 2010-11-25 17:10 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\HP
2015-04-18 20:04 - 2010-11-15 22:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\LightScribe Direct Disc Labeling
2015-04-18 20:04 - 2010-11-13 00:52 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Google
2015-04-18 20:04 - 2010-11-12 23:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\AVS4YOU
2015-04-18 20:04 - 2010-11-12 22:16 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
2015-04-18 20:04 - 2010-11-12 21:42 - 00000000 __SHD () H:\Documents and Settings\LocalService\IETldCache
2015-04-18 20:04 - 2010-11-12 13:18 - 00000000 __SHD () H:\Documents and Settings\All Users\DRM
2015-04-18 20:04 - 2010-11-12 13:18 - 00000000 ___RD () H:\Documents and Settings\Default User\Start Menu\Programs\Accessories
2015-04-18 20:04 - 2010-11-12 13:16 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Games
2015-04-18 20:04 - 2010-11-12 13:14 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Accessories
2015-04-18 20:04 - 2010-11-12 08:04 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Temp
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 __SHD () H:\Documents and Settings\Administrator\IETldCache
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 ___RD () H:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft Help
2015-04-18 20:03 - 2013-10-25 16:28 - 00000000 ____D () H:\AdwCleaner
2015-04-18 20:03 - 2011-01-16 21:24 - 00000000 ____D () H:\bb6fadc9d2f25f3b2953e5d2
2015-04-18 20:03 - 2010-11-12 02:18 - 00000000 ____D () H:\d688a5c03ea38202645f5bc01eeb02
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\a812a3d6-ecc8-4750-9477-c631757694a4.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\92c937b0-dfc0-4b6d-a16f-6fc079dec2a3.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\4e28d2f5-abaf-40c7-a2d7-f3a7ad9a45ff.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\0feed571-1be8-4bc1-8ccd-82480f9105ff.dmp.ecc
2015-04-18 19:20 - 2012-09-17 19:42 - 00029492 _____ () H:\.pdf.ecc
2015-04-18 19:20 - 2012-07-29 22:31 - 00465764 _____ () H:\112.pdf.ecc
2015-04-18 19:20 - 2012-02-28 14:22 - 00000000 ____D () H:\54c3cb947aef816ceabdedb8f7
2015-04-18 19:20 - 2012-02-11 14:34 - 00000000 ____D () H:\128b39739a3c8290c766a9
2015-04-18 19:20 - 2012-02-06 22:14 - 00000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1
2015-04-18 19:20 - 2012-02-01 15:45 - 00000000 ____D () H:\94677e1b4707d7452aa83d9d21
2015-04-17 23:45 - 2014-01-11 01:48 - 00000000 ____D () H:\Documents and Settings\User\My Documents\subtitle
2015-04-16 22:55 - 2013-10-27 02:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\moda
2015-04-09 09:57 - 2013-10-26 17:49 - 00000000 ____D () H:\Documents and Settings\User\My Documents\AS-CV
2015-04-08 21:24 - 2015-01-14 14:50 - 00000214 _____ () H:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2015-04-05 15:36 - 2014-06-08 18:50 - 00000000 ____D () H:\Documents and Settings\User\Desktop\l5678
2015-04-05 12:31 - 2012-06-15 14:53 - 00270848 ___SH () H:\Documents and Settings\User\Desktop\Thumbs.db
2015-04-03 15:46 - 2012-06-17 20:14 - 00000000 ____D () H:\Documents and Settings\User\My Documents\attestation

==================== Files in the root of some directories =======

2010-03-29 19:40 - 2010-03-29 19:40 - 0100256 _____ () H:\Program Files\Common Files\LinkInstaller.exe
2015-04-18 19:20 - 2015-04-18 19:20 - 0000752 _____ () H:\Documents and Settings\User\Application Data\key.dat
2015-04-18 19:20 - 2015-04-18 21:13 - 1592102 _____ () H:\Documents and Settings\User\Application Data\log.html
2015-04-18 19:14 - 2015-04-18 19:14 - 0000000 _____ () H:\Documents and Settings\User\Local Settings\Application Data\cfktrgymlq.png
2010-11-12 22:29 - 2015-01-14 18:38 - 0088064 _____ () H:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-18 18:58 - 2015-04-18 18:58 - 0000032 _____ () H:\Documents and Settings\User\Local Settings\Application Data\dxhrfporqd.png
2015-04-18 20:04 - 2015-04-18 20:04 - 0000000 _____ () H:\Documents and Settings\User\Local Settings\Application Data\lhjuankaye.png
2015-04-18 19:04 - 2015-04-18 19:04 - 0000000 _____ () H:\Documents and Settings\User\Local Settings\Application Data\qrxghktvvs.png
2015-04-18 18:58 - 2015-04-18 18:58 - 0408600 _____ () H:\Documents and Settings\User\Local Settings\Application Data\znilrcjwzi.dat
2015-04-18 20:04 - 2015-04-18 20:04 - 0002674 _____ () H:\Documents and Settings\All Users\HELP_RESTORE_FILES.txt

Some content of TEMP:
====================
H:\Documents and Settings\User\Local Settings\Temp\AskSLib.dll
H:\Documents and Settings\User\Local Settings\Temp\BitLord_1.1.exe
H:\Documents and Settings\User\Local Settings\Temp\diskchk.exe
H:\Documents and Settings\User\Local Settings\Temp\optprosetup.exe
H:\Documents and Settings\User\Local Settings\Temp\Quarantine.exe
H:\Documents and Settings\User\Local Settings\Temp\SendMsg.dll
H:\Documents and Settings\User\Local Settings\Temp\siinst.exe
H:\Documents and Settings\User\Local Settings\Temp\SkypeSetup.exe
H:\Documents and Settings\User\Local Settings\Temp\sqlite3.dll
H:\Documents and Settings\User\Local Settings\Temp\strings.dll
H:\Documents and Settings\User\Local Settings\Temp\System.Data.SQLite.dll
H:\Documents and Settings\User\Local Settings\Temp\System.Data.SQLite20ccc755-7273-417a-a366-6af02459ebf7.dll
H:\Documents and Settings\User\Local Settings\Temp\System.Data.SQLite4861596c-befa-4147-9df0-c56b68bdffa8.dll
H:\Documents and Settings\User\Local Settings\Temp\System.Data.SQLite5d1b4f7f-f4f5-4f6d-8c35-08c3bd127c77.dll
H:\Documents and Settings\User\Local Settings\Temp\System.Data.SQLiteb3ec0307-67e0-486b-a521-b228e2313e2d.dll
H:\Documents and Settings\User\Local Settings\Temp\tbVisu.dll
H:\Documents and Settings\User\Local Settings\Temp\uttB9A.tmp.exe
H:\Documents and Settings\User\Local Settings\Temp\uttE4F.tmp.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

H:\WINDOWS\explorer.exe => File is digitally signed
H:\WINDOWS\system32\winlogon.exe => File is digitally signed
H:\WINDOWS\system32\svchost.exe => File is digitally signed
H:\WINDOWS\system32\services.exe => File is digitally signed
H:\WINDOWS\system32\User32.dll => File is digitally signed
H:\WINDOWS\system32\userinit.exe => File is digitally signed
H:\WINDOWS\system32\rpcss.dll => File is digitally signed
H:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================


Scan result

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-04-2015 01
Ran by User (administrator) on PC-FB227302206B on 20-04-2015 07:09:32
Running from H:\Documents and Settings\User\My Documents\Downloads
Loaded Profiles: User (Available profiles: User & Administrator)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(HP) H:\WINDOWS\system32\HPSIsvc.exe
(Hewlett-Packard Company) H:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Nero AG) H:\Program Files\Nero\Update\NASvc.exe
() H:\Program Files\CDBurnerXP\NMSAccessU.exe
(Skype Technologies S.A.) H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Microsoft Corporation) H:\WINDOWS\system32\wscntfy.exe
(Mozilla Corporation) H:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) H:\Program Files\Mozilla Firefox\plugin-container.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

Winlogon\Notify\crypt32chain: H:\WINDOWS\system32\crypt32.dll [2013-10-07] (Microsoft Corporation)
Winlogon\Notify\cryptnet: H:\WINDOWS\system32\cryptnet.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\cscdll: H:\WINDOWS\system32\cscdll.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\igfxcui: H:\WINDOWS\system32\igfxsrvc.dll [2004-11-02] (Intel Corporation)
Winlogon\Notify\ScCertProp: H:\WINDOWS\system32\wlnotify.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\Schedule: H:\WINDOWS\system32\wlnotify.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\sclgntfy: H:\WINDOWS\system32\sclgntfy.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\SensLogn: H:\WINDOWS\system32\WlNotify.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\termsrv: H:\WINDOWS\system32\wlnotify.dll [2008-04-14] (Microsoft Corporation)
Winlogon\Notify\WgaLogon: H:\WINDOWS\system32\WgaLogon.dll [2009-03-10] (Microsoft Corporation)
Winlogon\Notify\wlballoon: H:\WINDOWS\system32\wlnotify.dll [2008-04-14] (Microsoft Corporation)
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: {9eea6e54-11aa-11e2-ac0d-28107bbdacc7} - E:\KODAK_Software_Downloader.exe
HKU\S-1-5-18\...\RunOnce: [RunNarrator] => H:\WINDOWS\system32\Narrator.exe [53760 2008-04-14] (Microsoft Corporation)
Startup: H:\Documents and Settings\Administrator\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()
Startup: H:\Documents and Settings\All Users\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()
Startup: H:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
URLSearchHook: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 - (No Name) - {2877A654-1C9F-4cb5-8438-16022B2FDD9C} -  No File
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "H:\Program Files\YoutubeDownloader.org\YouTubeDownloader\index.htm" <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 -> {0097EC7C-F4EB-4CB9-9D3B-AAE8ADF495C9} URL =
SearchScopes: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 -> {7479720C-8CF4-43A4-8C91-74F7AD68A389} URL =
SearchScopes: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 -> {E081D2FE-7439-4CBB-BC99-992158614ED4} URL =
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> H:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2014-10-24] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> H:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-10-24] (Oracle Corporation)
BHO: BHO_TIMELINEREMOVE.Bho -> {e7b9b609-19ad-40a4-a288-b300a3087465} -> H:\WINDOWS\system32\mscoree.dll [2010-03-18] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289583241062
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - H:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015
FF SelectedSearchEngine: Yahoo!
FF Homepage: https://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> H:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll [2014-10-24] ()
FF Plugin: @java.com/DTPlugin,version=10.17.2 -> H:\WINDOWS\system32\npDeployJava1.dll [2013-03-23] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> H:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-10-24] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> h:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: Adobe Reader -> H:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1614895754-1645522239-1417001333-1003: @Skype Limited.com/Facebook Video Calling Plugin -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll [2012-10-12] (Skype Limited)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2012-01-12] (BitComet)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\google-dictionary-english-french.xml [2012-08-28]
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\wikipedia-franais-et-anglais.xml [2012-08-28]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\911bg.xml [2014-10-11]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml [2014-10-11]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\pe-bg.xml [2014-10-11]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml [2014-10-11]
FF Extension: United States English Spellchecker - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-05-19]
FF Extension: Dictionnaire français «Moderne» - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-01-08]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-19]
FF Extension: ALOT Toolbar - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-04-19]
FF Extension: Microsoft .NET Framework Assistant - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-11-14]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-20]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\trash [2012-08-20]
FF Extension: Skype Click to Call - H:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-06]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2015-04-06]
FF Extension: Skype Click to Call - H:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-06]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-11-12]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - H:\Program Files\Bitdefender\Bitdefender 2012\bdtbext
FF ExtraCheck: H:\Program Files\mozilla firefox\firefox.cfg [2015-04-06] <==== ATTENTION

Chrome:
=======
CHR Profile: H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Gmail) - H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-12]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 CCALib8; H:\Program Files\Canon\CAL\CALMAIN.exe [96341 2006-03-30] (Canon Inc.) [File not signed]
R3 hpqcxs08; H:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; H:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
S2 HPSupportSolutionsFrameworkService; H:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)
R2 LightScribeService; H:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-08-16] (Hewlett-Packard Company) [File not signed]
S2 MBAMService; H:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 NAUpdate; H:\Program Files\Nero\Update\NASvc.exe [573224 2011-01-26] (Nero AG)
R2 Net Driver HPZ12; H:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
R2 NMSAccess; H:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] ()
R2 Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Skype C2C Service; H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S2 WLSVC; H:\Program Files\D-Link\DWA-130 revE\WLSVC.exe [167936 2009-02-11] () [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AegisP; H:\WINDOWS\System32\DRIVERS\AegisP.sys [21361 2012-07-08] (Cisco Systems, Inc.) [File not signed]
S3 CCDECODE; H:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 HPZid412; H:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
S3 HPZipr12; H:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
S3 HPZius12; H:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
R3 MBAMProtector; H:\WINDOWS\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
S3 MBAMSwissArmy; H:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [119512 2015-04-19] (Malwarebytes Corporation)
S3 NdisIP; H:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 rt2870; H:\WINDOWS\System32\DRIVERS\Drt2870.sys [829152 2010-05-06] (Ralink Technology, Corp.)
S3 rtl8139; H:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
R2 StarOpen; H:\WINDOWS\system32\Drivers\StarOpen.sys [5504 2009-11-12] () [File not signed]
R2 WLNdis50; H:\WINDOWS\System32\DRIVERS\wlndis50.sys [20480 2008-02-27] () [File not signed]
U1 WS2IFSL; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-20 07:09 - 2015-04-20 07:09 - 00000000 ____D () H:\FRST
2015-04-18 23:25 - 2013-03-23 10:04 - 00861088 _____ (Oracle Corporation) H:\WINDOWS\system32\npDeployJava1.dll
2015-04-18 23:25 - 2013-03-23 10:04 - 00782240 _____ (Oracle Corporation) H:\WINDOWS\system32\deployJava1.dll
2015-04-18 23:18 - 2015-04-18 23:18 - 00008536 _____ () H:\Documents and Settings\Administrator\Desktop\mb scan.txt
2015-04-18 21:50 - 2015-04-19 23:52 - 00119512 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-04-18 21:49 - 2015-04-18 21:50 - 00000777 _____ () H:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-18 21:49 - 2015-04-18 21:49 - 00000000 ____D () H:\Program Files\Malwarebytes Anti-Malware
2015-04-18 21:49 - 2015-03-17 06:15 - 00120024 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-04-18 21:49 - 2015-03-17 06:15 - 00023256 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbam.sys
2015-04-18 21:30 - 2015-04-18 21:41 - 00003572 _____ () H:\Documents and Settings\Administrator\Desktop\Rkill.txt
2015-04-18 21:21 - 2015-04-18 21:21 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
2015-04-18 21:21 - 2015-04-18 21:21 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Mozilla
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Macromedia
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Adobe
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\User\AppData\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\LocalService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Desktop\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\All Users\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\All Users\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\All Users\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\All Users\Desktop\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Desktop\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 19:50 - 2015-04-18 23:16 - 00001324 _____ () H:\WINDOWS\system32\d3d9caps.dat
2015-04-18 19:20 - 2015-04-18 21:13 - 01592102 _____ () H:\Documents and Settings\User\Application Data\log.html
2015-04-18 19:20 - 2015-04-18 20:00 - 00000232 _____ () H:\Documents and Settings\User\My Documents\RECOVERY_KEY.TXT
2015-04-18 19:20 - 2015-04-18 19:20 - 00000752 _____ () H:\Documents and Settings\User\Application Data\key.dat
2015-04-18 18:58 - 2015-04-18 23:20 - 00000000 ___HD () H:\Documents and Settings\All Users\Application Data\{B6F1BED8-A80E-4513-86C2-4F7968A2433C}
2015-04-18 18:58 - 2015-04-18 18:58 - 00408600 _____ () H:\Documents and Settings\User\Local Settings\Application Data\znilrcjwzi.dat
2015-04-12 01:28 - 2015-04-18 20:06 - 00113732 _____ () H:\Documents and Settings\User\Desktop\10470717_10152942390179635_5357236154732284632_n.jpg.ecc
2015-04-12 01:27 - 2015-04-18 20:06 - 00054468 _____ () H:\Documents and Settings\User\Desktop\11145571_10152958877974635_3339765670712915872_n.jpg.ecc
2015-04-06 16:32 - 2015-04-06 16:32 - 00000000 ____D () H:\Program Files\Mozilla Firefox
2015-04-05 12:26 - 2015-04-18 20:06 - 00090580 _____ () H:\Documents and Settings\User\Desktop\11138672_982700228409538_8855858409597611766_n.jpg.ecc
2015-04-04 01:57 - 2015-04-04 02:02 - 00000000 ____D () H:\Documents and Settings\User\My Documents\Attestation123
2015-04-04 01:56 - 2015-04-18 21:12 - 00381604 _____ () H:\Documents and Settings\User\Desktop\Attestation2.pdf.ecc
2015-04-03 14:06 - 2015-04-03 14:06 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\Hewlett-Packard
2015-04-01 15:28 - 2015-04-18 20:06 - 00038404 _____ () H:\Documents and Settings\User\Desktop\11096536_10153198374462173_1538024734260084523_n.jpg.ecc
2015-03-29 22:34 - 2015-04-18 20:06 - 00058036 _____ () H:\Documents and Settings\User\Desktop\10923243_823850137672875_4923851942726001590_n.jpg.ecc
2015-03-25 17:48 - 2015-04-18 21:13 - 00001748 _____ () H:\Documents and Settings\User\Desktop\doc_57.png.ecc
2015-03-25 15:31 - 2015-04-18 20:06 - 00061220 _____ () H:\Documents and Settings\User\Desktop\0cb712a19e742a9725b3c7cf78a6d908_600x460.jpg.ecc

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-20 07:10 - 2010-11-12 13:32 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Temp
2015-04-20 06:54 - 2001-08-23 08:00 - 00002206 _____ () H:\WINDOWS\system32\wpa.dbl
2015-04-20 06:53 - 2010-11-12 13:18 - 01916684 _____ () H:\WINDOWS\WindowsUpdate.log
2015-04-20 06:53 - 2010-11-12 08:08 - 00000300 _____ () H:\WINDOWS\wiadebug.log
2015-04-20 06:53 - 2010-11-12 08:08 - 00000052 _____ () H:\WINDOWS\wiaservc.log
2015-04-20 06:52 - 2015-01-14 14:50 - 00000220 _____ () H:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-04-20 06:52 - 2010-11-12 13:31 - 00000006 ____H () H:\WINDOWS\Tasks\SA.DAT
2015-04-19 23:59 - 2013-11-23 04:02 - 00519776 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2015-04-19 23:59 - 2010-11-12 13:32 - 00000178 ___SH () H:\Documents and Settings\User\ntuser.ini
2015-04-19 23:59 - 2010-11-12 13:31 - 00032490 _____ () H:\WINDOWS\SchedLgU.Txt
2015-04-19 23:57 - 2012-06-30 23:39 - 00001148 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003UA.job
2015-04-19 23:45 - 2010-12-04 00:12 - 00000069 _____ () H:\WINDOWS\NeroDigital.ini
2015-04-19 23:43 - 2014-09-08 19:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-08
2015-04-19 23:28 - 2013-12-07 23:22 - 00000178 ___SH () H:\Documents and Settings\Administrator\ntuser.ini
2015-04-19 22:13 - 2012-04-18 22:24 - 00000830 _____ () H:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-04-19 17:57 - 2012-06-30 23:39 - 00001126 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003Core.job
2015-04-19 17:16 - 2013-10-26 16:34 - 00258358 _____ () H:\WINDOWS\setupapi.log
2015-04-19 08:57 - 2010-11-13 00:51 - 00000000 ____D () H:\Documents and Settings\User\Application Data\Skype
2015-04-19 07:53 - 2012-02-11 11:47 - 00002265 _____ () H:\Documents and Settings\All Users\Desktop\Skype.lnk
2015-04-19 02:28 - 2013-01-08 20:29 - 00000000 ____D () H:\Documents and Settings\User\Application Data\BitTorrent
2015-04-19 00:18 - 2014-06-08 20:04 - 00000000 ____D () H:\Documents and Settings\User\My Documents\sub1
2015-04-18 23:26 - 2012-02-18 21:41 - 00000000 ____D () H:\Program Files\Java
2015-04-18 23:20 - 2011-11-11 00:38 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2641690$
2015-04-18 23:19 - 2014-12-13 23:36 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\YTD YouTube Downloader & Converter
2015-04-18 23:17 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Temp
2015-04-18 21:16 - 2013-12-07 23:22 - 00001108 __RSH () H:\Documents and Settings\Administrator\ntuser.pol
2015-04-18 21:16 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator
2015-04-18 21:13 - 2014-09-27 00:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Jardine bothanique
2015-04-18 21:13 - 2013-11-30 17:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\disain
2015-04-18 21:13 - 2013-10-27 02:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\krasivo
2015-04-18 21:13 - 2013-05-28 07:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\inter
2015-04-18 21:12 - 2015-01-06 00:00 - 00040260 _____ () H:\Documents and Settings\User\Desktop\bride.and.prejudice.2004.dvdrip.xvid-endi(subsunacs.net).zip.ecc
2015-04-18 21:12 - 2014-08-17 17:03 - 16454852 _____ () H:\Documents and Settings\User\Desktop\attachments_2014_08_17.zip.ecc
2015-04-18 20:58 - 2014-09-27 18:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-27
2015-04-18 20:29 - 2014-09-18 22:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-18
2015-04-18 20:21 - 2014-09-02 22:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-02
2015-04-18 20:21 - 2014-08-31 00:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-31
2015-04-18 20:17 - 2014-08-28 20:43 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-28
2015-04-18 20:14 - 2014-07-27 00:13 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-27
2015-04-18 20:10 - 2014-07-13 19:22 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-13
2015-04-18 20:10 - 2014-05-20 13:45 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-05-20
2015-04-18 20:06 - 2015-02-06 23:20 - 00188836 _____ () H:\Documents and Settings\User\Desktop\1066517_4543673565274_2119997541_o.jpg.ecc
2015-04-18 20:06 - 2015-01-08 21:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2
2015-04-18 20:06 - 2014-03-30 13:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\18
2015-04-18 20:05 - 2012-08-10 15:44 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\bdch
2015-04-18 20:05 - 2012-02-17 06:40 - 00000000 __SHD () H:\Documents and Settings\NetworkService\IETldCache
2015-04-18 20:05 - 2010-11-13 00:57 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
2015-04-18 20:05 - 2010-11-12 13:31 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Temp
2015-04-18 20:05 - 2010-11-12 13:28 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Temp
2015-04-18 20:04 - 2015-01-24 14:35 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype
2015-04-18 20:04 - 2014-10-24 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Java
2015-04-18 20:04 - 2014-04-26 11:43 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\JustVoip
2015-04-18 20:04 - 2013-02-16 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ooVoo
2015-04-18 20:04 - 2013-01-08 20:32 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
2015-04-18 20:04 - 2012-11-11 03:32 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\bdch
2015-04-18 20:04 - 2012-11-07 00:51 - 00000000 ____D () H:\Documents and Settings\LocalService\Application Data\QuickScan
2015-04-18 20:04 - 2012-07-08 00:07 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\D-Link
2015-04-18 20:04 - 2012-06-27 17:08 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
2015-04-18 20:04 - 2012-06-19 18:28 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\TechSmith
2015-04-18 20:04 - 2011-12-19 00:57 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft Help
2015-04-18 20:04 - 2011-12-18 18:15 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
2015-04-18 20:04 - 2011-12-17 19:54 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\DVDVideoSoft
2015-04-18 20:04 - 2011-10-16 20:17 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
2015-04-18 20:04 - 2011-08-30 22:30 - 00000000 ____D () H:\Documents and Settings\LocalService\Application Data\McAfee
2015-04-18 20:04 - 2011-05-17 16:09 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Keyboard
2015-04-18 20:04 - 2011-02-07 22:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
2015-04-18 20:04 - 2011-02-06 00:33 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
2015-04-18 20:04 - 2011-01-16 21:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Nero
2015-04-18 20:04 - 2010-12-01 20:18 - 00000000 ___SD () H:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 3.1
2015-04-18 20:04 - 2010-11-25 17:10 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\HP
2015-04-18 20:04 - 2010-11-15 22:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\LightScribe Direct Disc Labeling
2015-04-18 20:04 - 2010-11-13 00:52 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Google
2015-04-18 20:04 - 2010-11-12 23:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\AVS4YOU
2015-04-18 20:04 - 2010-11-12 22:16 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
2015-04-18 20:04 - 2010-11-12 21:42 - 00000000 __SHD () H:\Documents and Settings\LocalService\IETldCache
2015-04-18 20:04 - 2010-11-12 13:18 - 00000000 __SHD () H:\Documents and Settings\All Users\DRM
2015-04-18 20:04 - 2010-11-12 13:18 - 00000000 ___RD () H:\Documents and Settings\Default User\Start Menu\Programs\Accessories
2015-04-18 20:04 - 2010-11-12 13:16 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Games
2015-04-18 20:04 - 2010-11-12 13:14 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Accessories
2015-04-18 20:04 - 2010-11-12 08:04 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Temp
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 __SHD () H:\Documents and Settings\Administrator\IETldCache
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 ___RD () H:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft Help
2015-04-18 20:03 - 2013-10-25 16:28 - 00000000 ____D () H:\AdwCleaner
2015-04-18 20:03 - 2011-01-16 21:24 - 00000000 ____D () H:\bb6fadc9d2f25f3b2953e5d2
2015-04-18 20:03 - 2010-11-12 02:18 - 00000000 ____D () H:\d688a5c03ea38202645f5bc01eeb02
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\a812a3d6-ecc8-4750-9477-c631757694a4.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\92c937b0-dfc0-4b6d-a16f-6fc079dec2a3.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\4e28d2f5-abaf-40c7-a2d7-f3a7ad9a45ff.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\0feed571-1be8-4bc1-8ccd-82480f9105ff.dmp.ecc
2015-04-18 19:20 - 2012-09-17 19:42 - 00029492 _____ () H:\.pdf.ecc
2015-04-18 19:20 - 2012-07-29 22:31 - 00465764 _____ () H:\112.pdf.ecc
2015-04-18 19:20 - 2012-02-28 14:22 - 00000000 ____D () H:\54c3cb947aef816ceabdedb8f7
2015-04-18 19:20 - 2012-02-11 14:34 - 00000000 ____D () H:\128b39739a3c8290c766a9
2015-04-18 19:20 - 2012-02-06 22:14 - 00000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1
2015-04-18 19:20 - 2012-02-01 15:45 - 00000000 ____D () H:\94677e1b4707d7452aa83d9d21
2015-04-17 23:45 - 2014-01-11 01:48 - 00000000 ____D () H:\Documents and Settings\User\My Documents\subtitle
2015-04-16 22:55 - 2013-10-27 02:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\moda
2015-04-09 09:57 - 2013-10-26 17:49 - 00000000 ____D () H:\Documents and Settings\User\My Documents\AS-CV
2015-04-08 21:24 - 2015-01-14 14:50 - 00000214 _____ () H:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2015-04-07 08:06 - 2012-05-03 16:07 - 00000000 ____D () H:\Program Files\Mozilla Maintenance Service
2015-04-05 15:36 - 2014-06-08 18:50 - 00000000 ____D () H:\Documents and Settings\User\Desktop\l5678
2015-04-05 12:31 - 2012-06-15 14:53 - 00270848 ___SH () H:\Documents and Settings\User\Desktop\Thumbs.db
2015-04-04 10:05 - 2010-11-12 08:03 - 00291680 _____ () H:\WINDOWS\system32\FNTCACHE.DAT
2015-04-03 15:46 - 2012-06-17 20:14 - 00000000 ____D () H:\Documents and Settings\User\My Documents\attestation
2015-04-03 14:10 - 2012-10-01 06:03 - 00075088 _____ () H:\WINDOWS\system32\GDIPFONTCACHEV1.DAT

==================== Files in the root of some directories =======

2010-03-29 19:40 - 2010-03-29 19:40 - 0100256 _____ () H:\Program Files\Common Files\LinkInstaller.exe
2015-04-18 19:20 - 2015-04-18 19:20 - 0000752 _____ () H:\Documents and Settings\User\Application Data\key.dat
2015-04-18 19:20 - 2015-04-18 21:13 - 1592102 _____ () H:\Documents and Settings\User\Application Data\log.html
2015-04-18 19:14 - 2015-04-18 19:14 - 0000000 _____ () H:\Documents and Settings\User\Local Settings\Application Data\cfktrgymlq.png
2010-11-12 22:29 - 2015-01-14 18:38 - 0088064 _____ () H:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-18 18:58 - 2015-04-18 18:58 - 0000032 _____ () H:\Documents and Settings\User\Local Settings\Application Data\dxhrfporqd.png
2015-04-18 20:04 - 2015-04-18 20:04 - 0000000 _____ () H:\Documents and Settings\User\Local Settings\Application Data\lhjuankaye.png
2015-04-18 19:04 - 2015-04-18 19:04 - 0000000 _____ () H:\Documents and Settings\User\Local Settings\Application Data\qrxghktvvs.png
2015-04-18 18:58 - 2015-04-18 18:58 - 0408600 _____ () H:\Documents and Settings\User\Local Settings\Application Data\znilrcjwzi.dat
2015-04-18 20:04 - 2015-04-18 20:04 - 0002674 _____ () H:\Documents and Settings\All Users\HELP_RESTORE_FILES.txt

Some content of TEMP:
====================
H:\Documents and Settings\User\Local Settings\Temp\AskSLib.dll
H:\Documents and Settings\User\Local Settings\Temp\BitLord_1.1.exe
H:\Documents and Settings\User\Local Settings\Temp\diskchk.exe
H:\Documents and Settings\User\Local Settings\Temp\optprosetup.exe
H:\Documents and Settings\User\Local Settings\Temp\Quarantine.exe
H:\Documents and Settings\User\Local Settings\Temp\SendMsg.dll
H:\Documents and Settings\User\Local Settings\Temp\siinst.exe
H:\Documents and Settings\User\Local Settings\Temp\SkypeSetup.exe
H:\Documents and Settings\User\Local Settings\Temp\sqlite3.dll
H:\Documents and Settings\User\Local Settings\Temp\strings.dll
H:\Documents and Settings\User\Local Settings\Temp\System.Data.SQLite.dll
H:\Documents and Settings\User\Local Settings\Temp\System.Data.SQLite20ccc755-7273-417a-a366-6af02459ebf7.dll
H:\Documents and Settings\User\Local Settings\Temp\System.Data.SQLite4861596c-befa-4147-9df0-c56b68bdffa8.dll
H:\Documents and Settings\User\Local Settings\Temp\System.Data.SQLite5d1b4f7f-f4f5-4f6d-8c35-08c3bd127c77.dll
H:\Documents and Settings\User\Local Settings\Temp\System.Data.SQLiteb3ec0307-67e0-486b-a521-b228e2313e2d.dll
H:\Documents and Settings\User\Local Settings\Temp\tbVisu.dll
H:\Documents and Settings\User\Local Settings\Temp\uttB9A.tmp.exe
H:\Documents and Settings\User\Local Settings\Temp\uttE4F.tmp.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

H:\WINDOWS\explorer.exe => File is digitally signed
H:\WINDOWS\system32\winlogon.exe => File is digitally signed
H:\WINDOWS\system32\svchost.exe => File is digitally signed
H:\WINDOWS\system32\services.exe => File is digitally signed
H:\WINDOWS\system32\User32.dll => File is digitally signed
H:\WINDOWS\system32\userinit.exe => File is digitally signed
H:\WINDOWS\system32\rpcss.dll => File is digitally signed
H:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================

  • Автор

За съжаление това е всичко във папката

 

nb6nig.jpg

 

 

лог файл има един ама той е във папката Downloads


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 22-04-2015 01
Ran by User at 2015-04-24 08:02:32 Run:11
Running from H:\Documents and Settings\User\My Documents\Downloads
Loaded Profiles: User (Available profiles: User & Administrator)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
start
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
URLSearchHook: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 - (No Name) - {2877A654-1C9F-4cb5-8438-16022B2FDD9C} -  No File
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "H:\Program Files\YoutubeDownloader.org\YouTubeDownloader\index.htm" <======= ATTENTION
H:\Program Files\YoutubeDownloader.org
SearchScopes: HKU\.DEFAULT -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 -> {0097EC7C-F4EB-4CB9-9D3B-AAE8ADF495C9} URL =
SearchScopes: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 -> {7479720C-8CF4-43A4-8C91-74F7AD68A389} URL =
SearchScopes: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 -> {E081D2FE-7439-4CBB-BC99-992158614ED4} URL =
Toolbar: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
FF Extension: ALOT Toolbar - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-04-19]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - H:\Program Files\Bitdefender\Bitdefender 2012\bdtbext
H:\Program Files\Bitdefender
Folder: C:\Program Files (x86)\Mozilla Firefox\browser\defaults
cmd: type "H:\Program Files\mozilla firefox\firefox.cfg"
cmd: type "H:\Program Files\mozilla firefox\my.cfg"
CMD: del /F /Q /S "H:\HELP_RESTORE_FILES.txt"
CMD: del /F /Q /S "H:\*.ecc"
2015-04-18 19:20 - 2015-04-18 21:13 - 01592102 _____ () H:\Documents and Settings\User\Application Data\log.html
2015-04-18 19:20 - 2015-04-18 20:00 - 00000232 _____ () H:\Documents and Settings\User\My Documents\RECOVERY_KEY.TXT
2015-04-18 19:20 - 2015-04-18 19:20 - 00000752 _____ () H:\Documents and Settings\User\Application Data\key.dat
2015-04-18 18:58 - 2015-04-18 23:20 - 00000000 ___HD () H:\Documents and Settings\All Users\Application Data\{B6F1BED8-A80E-4513-86C2-4F7968A2433C}
2015-04-18 18:58 - 2015-04-18 18:58 - 00408600 _____ () H:\Documents and Settings\User\Local Settings\Application Data\znilrcjwzi.dat
Folder: H:\bb6fadc9d2f25f3b2953e5d2
Folder: H:\d688a5c03ea38202645f5bc01eeb02
Folder: H:\54c3cb947aef816ceabdedb8f7
Folder: H:\128b39739a3c8290c766a9
Folder: H:\7feea7b9257e7026c75c0547bf2f4da1
Folder: H:\94677e1b4707d7452aa83d9d21
2015-04-18 23:19 - 2014-12-13 23:36 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\YTD YouTube Downloader & Converter
2010-03-29 19:40 - 2010-03-29 19:40 - 0100256 _____ () H:\Program Files\Common Files\LinkInstaller.exe
2015-04-18 19:14 - 2015-04-18 19:14 - 0000000 _____ () H:\Documents and Settings\User\Local Settings\Application Data\cfktrgymlq.png
2015-04-18 18:58 - 2015-04-18 18:58 - 0000032 _____ () H:\Documents and Settings\User\Local Settings\Application Data\dxhrfporqd.png
2015-04-18 20:04 - 2015-04-18 20:04 - 0000000 _____ () H:\Documents and Settings\User\Local Settings\Application Data\lhjuankaye.png
2015-04-18 19:04 - 2015-04-18 19:04 - 0000000 _____ () H:\Documents and Settings\User\Local Settings\Application Data\qrxghktvvs.png
Task: H:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => H:\WINDOWS\system32\xp_eos.exe
Task: H:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => H:\WINDOWS\system32\xp_eos.exe
H:\WINDOWS\system32\xp_eos.exe
AlternateDataStreams: H:\WINDOWS\system32\muweb.dll:BDU
AlternateDataStreams: H:\WINDOWS\system32\wuweb.dll:BDU
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BDAgent" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BitDefender Antiphishing Helper" /f
EmptyTemp:
end
*****************

HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\{2877A654-1C9F-4cb5-8438-16022B2FDD9C} => Value not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\Tabs => Value was restored successfully.
"H:\Program Files\YoutubeDownloader.org" => File/Directory not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0097EC7C-F4EB-4CB9-9D3B-AAE8ADF495C9} => Key not found.
HKCR\CLSID\{0097EC7C-F4EB-4CB9-9D3B-AAE8ADF495C9} => Key not found.
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7479720C-8CF4-43A4-8C91-74F7AD68A389} => Key not found.
HKCR\CLSID\{7479720C-8CF4-43A4-8C91-74F7AD68A389} => Key not found.
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E081D2FE-7439-4CBB-BC99-992158614ED4} => Key not found.
HKCR\CLSID\{E081D2FE-7439-4CBB-BC99-992158614ED4} => Key not found.
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value not found.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found.
H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] => not found.
HKLM\Software\Mozilla\Thunderbird\Extensions\\[email protected] => Value not found.
"H:\Program Files\Bitdefender" => File/Directory not found.

========================= Folder: C:\Program Files (x86)\Mozilla Firefox\browser\defaults ========================

Directory Not Found

=========  type "H:\Program Files\mozilla firefox\firefox.cfg" =========


========= End of CMD: =========


=========  type "H:\Program Files\mozilla firefox\my.cfg" =========


========= End of CMD: =========


=========  del /F /Q /S "H:\HELP_RESTORE_FILES.txt" =========


========= End of CMD: =========


=========  del /F /Q /S "H:\*.ecc" =========


========= End of CMD: =========

"H:\Documents and Settings\User\Application Data\log.html" => File/Directory not found.
"H:\Documents and Settings\User\My Documents\RECOVERY_KEY.TXT" => File/Directory not found.
"H:\Documents and Settings\User\Application Data\key.dat" => File/Directory not found.
"H:\Documents and Settings\All Users\Application Data\{B6F1BED8-A80E-4513-86C2-4F7968A2433C}" => File/Directory not found.
"H:\Documents and Settings\User\Local Settings\Application Data\znilrcjwzi.dat" => File/Directory not found.

========================= Folder: H:\bb6fadc9d2f25f3b2953e5d2 ========================

2011-01-16 21:25 - 2011-01-16 21:25 - 0000788 ____H () H:\bb6fadc9d2f25f3b2953e5d2\$shtdwn$.req
2009-07-12 08:30 - 2015-04-18 20:03 - 0003908 _____ () H:\bb6fadc9d2f25f3b2953e5d2\eula.1028.txt.ecc
2009-07-12 08:30 - 2015-04-18 20:03 - 0015492 _____ () H:\bb6fadc9d2f25f3b2953e5d2\eula.1031.txt.ecc
2009-07-12 08:30 - 2015-04-18 20:03 - 0010068 _____ () H:\bb6fadc9d2f25f3b2953e5d2\eula.1033.txt.ecc
2009-07-12 08:30 - 2015-04-18 20:03 - 0012308 _____ () H:\bb6fadc9d2f25f3b2953e5d2\eula.1036.txt.ecc
2009-07-12 08:30 - 2015-04-18 20:03 - 0013972 _____ () H:\bb6fadc9d2f25f3b2953e5d2\eula.1040.txt.ecc
2009-07-12 08:30 - 2015-04-18 20:03 - 0005812 _____ () H:\bb6fadc9d2f25f3b2953e5d2\eula.1041.txt.ecc
2009-07-12 08:30 - 2015-04-18 20:03 - 0006020 _____ () H:\bb6fadc9d2f25f3b2953e5d2\eula.1042.txt.ecc
2009-07-12 08:30 - 2015-04-18 20:03 - 0014020 _____ () H:\bb6fadc9d2f25f3b2953e5d2\eula.1049.txt.ecc
2009-07-12 08:30 - 2015-04-18 20:03 - 0003908 _____ () H:\bb6fadc9d2f25f3b2953e5d2\eula.2052.txt.ecc
2009-07-12 08:30 - 2015-04-18 20:03 - 0012996 _____ () H:\bb6fadc9d2f25f3b2953e5d2\eula.3082.txt.ecc
2009-07-12 08:30 - 2009-07-12 08:30 - 0001110 _____ () H:\bb6fadc9d2f25f3b2953e5d2\globdata.ini
2015-04-18 20:03 - 2015-04-18 20:03 - 0002674 _____ () H:\bb6fadc9d2f25f3b2953e5d2\HELP_RESTORE_FILES.txt
2009-07-12 04:55 - 2009-07-12 04:55 - 0560464 _____ (Microsoft Corporation) H:\bb6fadc9d2f25f3b2953e5d2\install.exe
2009-07-12 08:30 - 2009-07-12 08:30 - 0000841 _____ () H:\bb6fadc9d2f25f3b2953e5d2\install.ini
2009-07-12 07:18 - 2009-07-12 07:18 - 0073040 _____ (Microsoft Corporation) H:\bb6fadc9d2f25f3b2953e5d2\install.res.1028.dll
2009-07-12 06:55 - 2009-07-12 06:55 - 0093008 _____ (Microsoft Corporation) H:\bb6fadc9d2f25f3b2953e5d2\install.res.1031.dll
2009-07-12 13:11 - 2009-07-12 13:11 - 0087904 _____ (Microsoft Corporation) H:\bb6fadc9d2f25f3b2953e5d2\install.res.1033.dll
2009-07-12 06:11 - 2009-07-12 06:11 - 0094048 _____ (Microsoft Corporation) H:\bb6fadc9d2f25f3b2953e5d2\install.res.1036.dll
2009-07-12 05:49 - 2009-07-12 05:49 - 0091984 _____ (Microsoft Corporation) H:\bb6fadc9d2f25f3b2953e5d2\install.res.1040.dll
2009-07-12 08:09 - 2009-07-12 08:09 - 0078160 _____ (Microsoft Corporation) H:\bb6fadc9d2f25f3b2953e5d2\install.res.1041.dll
2009-07-12 05:27 - 2009-07-12 05:27 - 0076640 _____ (Microsoft Corporation) H:\bb6fadc9d2f25f3b2953e5d2\install.res.1042.dll
2009-07-12 04:55 - 2009-07-12 04:55 - 0089936 _____ (Корпорация Майкрософт) H:\bb6fadc9d2f25f3b2953e5d2\install.res.1049.dll
2009-07-12 07:40 - 2009-07-12 07:40 - 0072528 _____ (Microsoft Corporation) H:\bb6fadc9d2f25f3b2953e5d2\install.res.2052.dll
2009-07-12 06:33 - 2009-07-12 06:33 - 0093024 _____ (Microsoft Corporation) H:\bb6fadc9d2f25f3b2953e5d2\install.res.3082.dll
2009-07-12 13:13 - 2009-07-12 13:13 - 3829316 _____ () H:\bb6fadc9d2f25f3b2953e5d2\vc_red.cab
2009-07-12 13:16 - 2009-07-12 13:16 - 0223232 _____ () H:\bb6fadc9d2f25f3b2953e5d2\vc_red.msi
2009-07-12 08:30 - 2009-07-12 08:30 - 0005686 _____ () H:\bb6fadc9d2f25f3b2953e5d2\vcredist.bmp

====== End of Folder: ======


========================= Folder: H:\d688a5c03ea38202645f5bc01eeb02 ========================

2015-04-18 20:03 - 2015-04-18 20:03 - 0002674 _____ () H:\d688a5c03ea38202645f5bc01eeb02\HELP_RESTORE_FILES.txt
2010-11-12 02:18 - 2015-04-18 20:03 - 0000000 ____D () H:\d688a5c03ea38202645f5bc01eeb02\amd64
2010-11-12 02:18 - 2008-07-06 08:06 - 0147456 ____N (Microsoft Corporation) H:\d688a5c03ea38202645f5bc01eeb02\amd64\filterpipelineprintproc.dll
2015-04-18 20:03 - 2015-04-18 20:03 - 0002674 _____ () H:\d688a5c03ea38202645f5bc01eeb02\amd64\HELP_RESTORE_FILES.txt
2010-11-12 02:18 - 2008-07-06 08:06 - 0010929 ____N () H:\d688a5c03ea38202645f5bc01eeb02\amd64\msxpsdrv.cat
2010-11-12 02:18 - 2008-06-19 01:33 - 0002204 ____N () H:\d688a5c03ea38202645f5bc01eeb02\amd64\msxpsdrv.inf
2008-06-19 12:03 - 2008-06-19 12:03 - 0000073 ____N () H:\d688a5c03ea38202645f5bc01eeb02\amd64\msxpsinc.gpd
2010-11-12 02:18 - 2008-06-19 01:33 - 0000072 ____N () H:\d688a5c03ea38202645f5bc01eeb02\amd64\msxpsinc.ppd
2010-11-12 02:18 - 2008-07-06 08:06 - 0748032 ____N (Microsoft Corporation) H:\d688a5c03ea38202645f5bc01eeb02\amd64\mxdwdrv.dll
2008-07-06 18:36 - 2008-07-06 18:36 - 2936832 ____N (Microsoft Corporation) H:\d688a5c03ea38202645f5bc01eeb02\amd64\xpssvcs.dll
2010-11-12 02:18 - 2015-04-18 20:03 - 0000000 ____D () H:\d688a5c03ea38202645f5bc01eeb02\i386
2010-11-12 02:18 - 2008-07-06 08:06 - 0089088 ____N (Microsoft Corporation) H:\d688a5c03ea38202645f5bc01eeb02\i386\filterpipelineprintproc.dll
2015-04-18 20:03 - 2015-04-18 20:03 - 0002674 _____ () H:\d688a5c03ea38202645f5bc01eeb02\i386\HELP_RESTORE_FILES.txt
2010-11-12 02:18 - 2008-07-06 08:06 - 0010929 ____N () H:\d688a5c03ea38202645f5bc01eeb02\i386\msxpsdrv.cat
2010-11-12 02:18 - 2008-06-19 01:33 - 0002204 ____N () H:\d688a5c03ea38202645f5bc01eeb02\i386\msxpsdrv.inf
2010-11-12 02:18 - 2008-06-19 12:03 - 0000073 ____N () H:\d688a5c03ea38202645f5bc01eeb02\i386\msxpsinc.gpd
2010-11-12 02:18 - 2008-06-19 01:33 - 0000072 ____N () H:\d688a5c03ea38202645f5bc01eeb02\i386\msxpsinc.ppd
2010-11-12 02:18 - 2008-07-06 08:06 - 0765440 ____N (Microsoft Corporation) H:\d688a5c03ea38202645f5bc01eeb02\i386\mxdwdrv.dll
2010-11-12 02:18 - 2008-07-06 08:06 - 1676288 ____N (Microsoft Corporation) H:\d688a5c03ea38202645f5bc01eeb02\i386\xpssvcs.dll

====== End of Folder: ======


========================= Folder: H:\54c3cb947aef816ceabdedb8f7 ========================

2012-02-28 14:22 - 2012-02-28 14:22 - 0000788 ____H () H:\54c3cb947aef816ceabdedb8f7\$shtdwn$.req
2011-12-25 06:30 - 2011-12-25 06:30 - 0015616 _____ () H:\54c3cb947aef816ceabdedb8f7\DHtmlHeader.html
2011-12-25 06:30 - 2011-12-25 06:30 - 0007306 _____ () H:\54c3cb947aef816ceabdedb8f7\header.bmp
2015-04-18 19:20 - 2015-04-18 20:00 - 0002674 _____ () H:\54c3cb947aef816ceabdedb8f7\HELP_RESTORE_FILES.txt
2011-12-25 06:40 - 2011-12-25 06:40 - 0322840 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\HotFixInstaller.exe
2011-12-25 06:40 - 2011-12-25 06:40 - 0819200 _____ () H:\54c3cb947aef816ceabdedb8f7\NDP35SP1-KB2657424.msp
2011-12-25 06:30 - 2011-12-25 06:30 - 0003580 _____ () H:\54c3cb947aef816ceabdedb8f7\ParameterInfo.xml
2011-12-25 06:30 - 2011-12-25 06:30 - 0110348 _____ () H:\54c3cb947aef816ceabdedb8f7\watermark.bmp
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1025
2011-12-25 06:30 - 2011-12-25 06:30 - 0076237 _____ () H:\54c3cb947aef816ceabdedb8f7\1025\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013088 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1025\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1028
2011-12-25 06:30 - 2011-12-25 06:30 - 0037119 _____ () H:\54c3cb947aef816ceabdedb8f7\1028\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0012064 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1028\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1029
2011-12-25 06:30 - 2011-12-25 06:30 - 0074519 _____ () H:\54c3cb947aef816ceabdedb8f7\1029\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013600 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1029\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1030
2011-12-25 06:30 - 2011-12-25 06:30 - 0076465 _____ () H:\54c3cb947aef816ceabdedb8f7\1030\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013600 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1030\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1031
2011-12-25 06:30 - 2011-12-25 06:30 - 0116656 _____ () H:\54c3cb947aef816ceabdedb8f7\1031\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0014112 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1031\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1032
2011-12-25 06:30 - 2011-12-25 06:30 - 0078951 _____ () H:\54c3cb947aef816ceabdedb8f7\1032\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0014112 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1032\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1033
2011-12-25 06:30 - 2011-12-25 06:30 - 0100363 _____ () H:\54c3cb947aef816ceabdedb8f7\1033\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013600 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1033\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1035
2011-12-25 06:30 - 2011-12-25 06:30 - 0075533 _____ () H:\54c3cb947aef816ceabdedb8f7\1035\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1035\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1036
2011-12-25 06:30 - 2011-12-25 06:30 - 0127060 _____ () H:\54c3cb947aef816ceabdedb8f7\1036\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0014112 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1036\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1037
2011-12-25 06:30 - 2011-12-25 06:30 - 0059647 _____ () H:\54c3cb947aef816ceabdedb8f7\1037\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013088 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1037\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1038
2011-12-25 06:30 - 2011-12-25 06:30 - 0067624 _____ () H:\54c3cb947aef816ceabdedb8f7\1038\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1038\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1040
2011-12-25 06:30 - 2011-12-25 06:30 - 0115589 _____ () H:\54c3cb947aef816ceabdedb8f7\1040\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1040\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1041
2011-12-25 06:30 - 2011-12-25 06:30 - 0104768 _____ () H:\54c3cb947aef816ceabdedb8f7\1041\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0012576 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1041\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1042
2011-12-25 06:30 - 2011-12-25 06:30 - 0147711 _____ () H:\54c3cb947aef816ceabdedb8f7\1042\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0012576 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1042\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1043
2011-12-25 06:30 - 2011-12-25 06:30 - 0076257 _____ () H:\54c3cb947aef816ceabdedb8f7\1043\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1043\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1044
2011-12-25 06:30 - 2011-12-25 06:30 - 0073305 _____ () H:\54c3cb947aef816ceabdedb8f7\1044\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1044\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1045
2011-12-25 06:30 - 2011-12-25 06:30 - 0073386 _____ () H:\54c3cb947aef816ceabdedb8f7\1045\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0014112 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1045\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1046
2011-12-25 06:30 - 2011-12-25 06:30 - 0097721 _____ () H:\54c3cb947aef816ceabdedb8f7\1046\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1046\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1049
2011-12-25 06:30 - 2011-12-25 06:30 - 0141033 _____ () H:\54c3cb947aef816ceabdedb8f7\1049\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Корпорация Майкрософт) H:\54c3cb947aef816ceabdedb8f7\1049\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1053
2011-12-25 06:30 - 2011-12-25 06:30 - 0076556 _____ () H:\54c3cb947aef816ceabdedb8f7\1053\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1053\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\1055
2011-12-25 06:30 - 2011-12-25 06:30 - 0077193 _____ () H:\54c3cb947aef816ceabdedb8f7\1055\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\1055\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\2052
2011-12-25 06:30 - 2011-12-25 06:30 - 0102032 _____ () H:\54c3cb947aef816ceabdedb8f7\2052\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0012064 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\2052\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\2070
2011-12-25 06:30 - 2011-12-25 06:30 - 0076519 _____ () H:\54c3cb947aef816ceabdedb8f7\2070\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\2070\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\3076
2011-12-25 06:30 - 2011-12-25 06:30 - 0037119 _____ () H:\54c3cb947aef816ceabdedb8f7\3076\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0012064 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\3076\HotFixInstallerUI.dll
2012-02-28 14:22 - 2012-02-28 14:22 - 0000000 ____D () H:\54c3cb947aef816ceabdedb8f7\3082
2011-12-25 06:30 - 2011-12-25 06:30 - 0094271 _____ () H:\54c3cb947aef816ceabdedb8f7\3082\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0014112 _____ (Microsoft Corporation) H:\54c3cb947aef816ceabdedb8f7\3082\HotFixInstallerUI.dll

====== End of Folder: ======


========================= Folder: H:\128b39739a3c8290c766a9 ========================

2012-02-11 14:34 - 2012-02-11 14:34 - 0000788 ____H () H:\128b39739a3c8290c766a9\$shtdwn$.req
2011-12-25 06:30 - 2011-12-25 06:30 - 0015616 _____ () H:\128b39739a3c8290c766a9\DHtmlHeader.html
2011-12-25 06:30 - 2011-12-25 06:30 - 0007306 _____ () H:\128b39739a3c8290c766a9\header.bmp
2015-04-18 19:20 - 2015-04-18 20:00 - 0002674 _____ () H:\128b39739a3c8290c766a9\HELP_RESTORE_FILES.txt
2011-12-25 06:40 - 2011-12-25 06:40 - 0322840 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\HotFixInstaller.exe
2011-12-25 06:40 - 2011-12-25 06:40 - 0819200 _____ () H:\128b39739a3c8290c766a9\NDP35SP1-KB2657424.msp
2011-12-25 06:30 - 2011-12-25 06:30 - 0003580 _____ () H:\128b39739a3c8290c766a9\ParameterInfo.xml
2011-12-25 06:30 - 2011-12-25 06:30 - 0110348 _____ () H:\128b39739a3c8290c766a9\watermark.bmp
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1025
2011-12-25 06:30 - 2011-12-25 06:30 - 0076237 _____ () H:\128b39739a3c8290c766a9\1025\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013088 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1025\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1028
2011-12-25 06:30 - 2011-12-25 06:30 - 0037119 _____ () H:\128b39739a3c8290c766a9\1028\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0012064 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1028\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1029
2011-12-25 06:30 - 2011-12-25 06:30 - 0074519 _____ () H:\128b39739a3c8290c766a9\1029\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013600 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1029\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1030
2011-12-25 06:30 - 2011-12-25 06:30 - 0076465 _____ () H:\128b39739a3c8290c766a9\1030\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013600 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1030\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1031
2011-12-25 06:30 - 2011-12-25 06:30 - 0116656 _____ () H:\128b39739a3c8290c766a9\1031\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0014112 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1031\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1032
2011-12-25 06:30 - 2011-12-25 06:30 - 0078951 _____ () H:\128b39739a3c8290c766a9\1032\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0014112 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1032\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1033
2011-12-25 06:30 - 2011-12-25 06:30 - 0100363 _____ () H:\128b39739a3c8290c766a9\1033\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013600 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1033\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1035
2011-12-25 06:30 - 2011-12-25 06:30 - 0075533 _____ () H:\128b39739a3c8290c766a9\1035\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1035\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1036
2011-12-25 06:30 - 2011-12-25 06:30 - 0127060 _____ () H:\128b39739a3c8290c766a9\1036\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0014112 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1036\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1037
2011-12-25 06:30 - 2011-12-25 06:30 - 0059647 _____ () H:\128b39739a3c8290c766a9\1037\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013088 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1037\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1038
2011-12-25 06:30 - 2011-12-25 06:30 - 0067624 _____ () H:\128b39739a3c8290c766a9\1038\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1038\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1040
2011-12-25 06:30 - 2011-12-25 06:30 - 0115589 _____ () H:\128b39739a3c8290c766a9\1040\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1040\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1041
2011-12-25 06:30 - 2011-12-25 06:30 - 0104768 _____ () H:\128b39739a3c8290c766a9\1041\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0012576 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1041\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1042
2011-12-25 06:30 - 2011-12-25 06:30 - 0147711 _____ () H:\128b39739a3c8290c766a9\1042\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0012576 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1042\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1043
2011-12-25 06:30 - 2011-12-25 06:30 - 0076257 _____ () H:\128b39739a3c8290c766a9\1043\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1043\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1044
2011-12-25 06:30 - 2011-12-25 06:30 - 0073305 _____ () H:\128b39739a3c8290c766a9\1044\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1044\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1045
2011-12-25 06:30 - 2011-12-25 06:30 - 0073386 _____ () H:\128b39739a3c8290c766a9\1045\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0014112 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1045\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1046
2011-12-25 06:30 - 2011-12-25 06:30 - 0097721 _____ () H:\128b39739a3c8290c766a9\1046\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1046\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1049
2011-12-25 06:30 - 2011-12-25 06:30 - 0141033 _____ () H:\128b39739a3c8290c766a9\1049\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Корпорация Майкрософт) H:\128b39739a3c8290c766a9\1049\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1053
2011-12-25 06:30 - 2011-12-25 06:30 - 0076556 _____ () H:\128b39739a3c8290c766a9\1053\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1053\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\1055
2011-12-25 06:30 - 2011-12-25 06:30 - 0077193 _____ () H:\128b39739a3c8290c766a9\1055\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\1055\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\2052
2011-12-25 06:30 - 2011-12-25 06:30 - 0102032 _____ () H:\128b39739a3c8290c766a9\2052\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0012064 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\2052\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\2070
2011-12-25 06:30 - 2011-12-25 06:30 - 0076519 _____ () H:\128b39739a3c8290c766a9\2070\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\2070\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\3076
2011-12-25 06:30 - 2011-12-25 06:30 - 0037119 _____ () H:\128b39739a3c8290c766a9\3076\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0012064 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\3076\HotFixInstallerUI.dll
2012-02-11 14:34 - 2012-02-11 14:34 - 0000000 ____D () H:\128b39739a3c8290c766a9\3082
2011-12-25 06:30 - 2011-12-25 06:30 - 0094271 _____ () H:\128b39739a3c8290c766a9\3082\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0014112 _____ (Microsoft Corporation) H:\128b39739a3c8290c766a9\3082\HotFixInstallerUI.dll

====== End of Folder: ======


========================= Folder: H:\7feea7b9257e7026c75c0547bf2f4da1 ========================

2012-02-06 22:14 - 2012-02-06 22:14 - 0000788 ____H () H:\7feea7b9257e7026c75c0547bf2f4da1\$shtdwn$.req
2011-12-25 06:30 - 2011-12-25 06:30 - 0015616 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\DHtmlHeader.html
2011-12-25 06:30 - 2011-12-25 06:30 - 0007306 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\header.bmp
2015-04-18 19:20 - 2015-04-18 20:00 - 0002674 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\HELP_RESTORE_FILES.txt
2011-12-25 06:40 - 2011-12-25 06:40 - 0322840 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\HotFixInstaller.exe
2011-12-25 06:40 - 2011-12-25 06:40 - 0819200 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\NDP35SP1-KB2657424.msp
2011-12-25 06:30 - 2011-12-25 06:30 - 0003580 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\ParameterInfo.xml
2011-12-25 06:30 - 2011-12-25 06:30 - 0110348 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\watermark.bmp
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1025
2011-12-25 06:30 - 2011-12-25 06:30 - 0076237 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1025\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013088 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1025\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1028
2011-12-25 06:30 - 2011-12-25 06:30 - 0037119 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1028\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0012064 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1028\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1029
2011-12-25 06:30 - 2011-12-25 06:30 - 0074519 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1029\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013600 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1029\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1030
2011-12-25 06:30 - 2011-12-25 06:30 - 0076465 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1030\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013600 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1030\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1031
2011-12-25 06:30 - 2011-12-25 06:30 - 0116656 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1031\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0014112 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1031\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1032
2011-12-25 06:30 - 2011-12-25 06:30 - 0078951 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1032\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0014112 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1032\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1033
2011-12-25 06:30 - 2011-12-25 06:30 - 0100363 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1033\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013600 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1033\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1035
2011-12-25 06:30 - 2011-12-25 06:30 - 0075533 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1035\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1035\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1036
2011-12-25 06:30 - 2011-12-25 06:30 - 0127060 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1036\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0014112 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1036\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1037
2011-12-25 06:30 - 2011-12-25 06:30 - 0059647 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1037\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013088 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1037\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1038
2011-12-25 06:30 - 2011-12-25 06:30 - 0067624 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1038\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1038\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1040
2011-12-25 06:30 - 2011-12-25 06:30 - 0115589 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1040\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1040\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1041
2011-12-25 06:30 - 2011-12-25 06:30 - 0104768 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1041\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0012576 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1041\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1042
2011-12-25 06:30 - 2011-12-25 06:30 - 0147711 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1042\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0012576 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1042\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1043
2011-12-25 06:30 - 2011-12-25 06:30 - 0076257 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1043\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1043\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1044
2011-12-25 06:30 - 2011-12-25 06:30 - 0073305 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1044\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1044\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1045
2011-12-25 06:30 - 2011-12-25 06:30 - 0073386 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1045\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0014112 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1045\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1046
2011-12-25 06:30 - 2011-12-25 06:30 - 0097721 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1046\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1046\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1049
2011-12-25 06:30 - 2011-12-25 06:30 - 0141033 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1049\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Корпорация Майкрософт) H:\7feea7b9257e7026c75c0547bf2f4da1\1049\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1053
2011-12-25 06:30 - 2011-12-25 06:30 - 0076556 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1053\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1053\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\1055
2011-12-25 06:30 - 2011-12-25 06:30 - 0077193 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\1055\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\1055\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\2052
2011-12-25 06:30 - 2011-12-25 06:30 - 0102032 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\2052\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0012064 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\2052\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\2070
2011-12-25 06:30 - 2011-12-25 06:30 - 0076519 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\2070\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\2070\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\3076
2011-12-25 06:30 - 2011-12-25 06:30 - 0037119 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\3076\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0012064 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\3076\HotFixInstallerUI.dll
2012-02-06 22:14 - 2012-02-06 22:14 - 0000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1\3082
2011-12-25 06:30 - 2011-12-25 06:30 - 0094271 _____ () H:\7feea7b9257e7026c75c0547bf2f4da1\3082\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0014112 _____ (Microsoft Corporation) H:\7feea7b9257e7026c75c0547bf2f4da1\3082\HotFixInstallerUI.dll

====== End of Folder: ======


========================= Folder: H:\94677e1b4707d7452aa83d9d21 ========================

2012-02-01 15:45 - 2012-02-01 15:45 - 0000788 ____H () H:\94677e1b4707d7452aa83d9d21\$shtdwn$.req
2011-12-25 06:30 - 2011-12-25 06:30 - 0015616 _____ () H:\94677e1b4707d7452aa83d9d21\DHtmlHeader.html
2011-12-25 06:30 - 2011-12-25 06:30 - 0007306 _____ () H:\94677e1b4707d7452aa83d9d21\header.bmp
2015-04-18 19:20 - 2015-04-18 20:00 - 0002674 _____ () H:\94677e1b4707d7452aa83d9d21\HELP_RESTORE_FILES.txt
2011-12-25 06:40 - 2011-12-25 06:40 - 0322840 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\HotFixInstaller.exe
2011-12-25 06:40 - 2011-12-25 06:40 - 0819200 _____ () H:\94677e1b4707d7452aa83d9d21\NDP35SP1-KB2657424.msp
2011-12-25 06:30 - 2011-12-25 06:30 - 0003580 _____ () H:\94677e1b4707d7452aa83d9d21\ParameterInfo.xml
2011-12-25 06:30 - 2011-12-25 06:30 - 0110348 _____ () H:\94677e1b4707d7452aa83d9d21\watermark.bmp
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1025
2011-12-25 06:30 - 2011-12-25 06:30 - 0076237 _____ () H:\94677e1b4707d7452aa83d9d21\1025\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013088 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1025\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1028
2011-12-25 06:30 - 2011-12-25 06:30 - 0037119 _____ () H:\94677e1b4707d7452aa83d9d21\1028\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0012064 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1028\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1029
2011-12-25 06:30 - 2011-12-25 06:30 - 0074519 _____ () H:\94677e1b4707d7452aa83d9d21\1029\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013600 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1029\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1030
2011-12-25 06:30 - 2011-12-25 06:30 - 0076465 _____ () H:\94677e1b4707d7452aa83d9d21\1030\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013600 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1030\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1031
2011-12-25 06:30 - 2011-12-25 06:30 - 0116656 _____ () H:\94677e1b4707d7452aa83d9d21\1031\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0014112 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1031\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1032
2011-12-25 06:30 - 2011-12-25 06:30 - 0078951 _____ () H:\94677e1b4707d7452aa83d9d21\1032\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0014112 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1032\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1033
2011-12-25 06:30 - 2011-12-25 06:30 - 0100363 _____ () H:\94677e1b4707d7452aa83d9d21\1033\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0013600 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1033\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1035
2011-12-25 06:30 - 2011-12-25 06:30 - 0075533 _____ () H:\94677e1b4707d7452aa83d9d21\1035\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1035\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1036
2011-12-25 06:30 - 2011-12-25 06:30 - 0127060 _____ () H:\94677e1b4707d7452aa83d9d21\1036\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0014112 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1036\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1037
2011-12-25 06:30 - 2011-12-25 06:30 - 0059647 _____ () H:\94677e1b4707d7452aa83d9d21\1037\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013088 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1037\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1038
2011-12-25 06:30 - 2011-12-25 06:30 - 0067624 _____ () H:\94677e1b4707d7452aa83d9d21\1038\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1038\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1040
2011-12-25 06:30 - 2011-12-25 06:30 - 0115589 _____ () H:\94677e1b4707d7452aa83d9d21\1040\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1040\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1041
2011-12-25 06:30 - 2011-12-25 06:30 - 0104768 _____ () H:\94677e1b4707d7452aa83d9d21\1041\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0012576 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1041\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1042
2011-12-25 06:30 - 2011-12-25 06:30 - 0147711 _____ () H:\94677e1b4707d7452aa83d9d21\1042\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0012576 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1042\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1043
2011-12-25 06:30 - 2011-12-25 06:30 - 0076257 _____ () H:\94677e1b4707d7452aa83d9d21\1043\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1043\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1044
2011-12-25 06:30 - 2011-12-25 06:30 - 0073305 _____ () H:\94677e1b4707d7452aa83d9d21\1044\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1044\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1045
2011-12-25 06:30 - 2011-12-25 06:30 - 0073386 _____ () H:\94677e1b4707d7452aa83d9d21\1045\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0014112 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1045\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1046
2011-12-25 06:30 - 2011-12-25 06:30 - 0097721 _____ () H:\94677e1b4707d7452aa83d9d21\1046\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1046\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1049
2011-12-25 06:30 - 2011-12-25 06:30 - 0141033 _____ () H:\94677e1b4707d7452aa83d9d21\1049\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Корпорация Майкрософт) H:\94677e1b4707d7452aa83d9d21\1049\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1053
2011-12-25 06:30 - 2011-12-25 06:30 - 0076556 _____ () H:\94677e1b4707d7452aa83d9d21\1053\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1053\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\1055
2011-12-25 06:30 - 2011-12-25 06:30 - 0077193 _____ () H:\94677e1b4707d7452aa83d9d21\1055\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\1055\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\2052
2011-12-25 06:30 - 2011-12-25 06:30 - 0102032 _____ () H:\94677e1b4707d7452aa83d9d21\2052\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0012064 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\2052\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\2070
2011-12-25 06:30 - 2011-12-25 06:30 - 0076519 _____ () H:\94677e1b4707d7452aa83d9d21\2070\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0013600 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\2070\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\3076
2011-12-25 06:30 - 2011-12-25 06:30 - 0037119 _____ () H:\94677e1b4707d7452aa83d9d21\3076\eula.rtf
2011-12-25 06:40 - 2011-12-25 06:40 - 0012064 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\3076\HotFixInstallerUI.dll
2012-02-01 15:45 - 2012-02-01 15:45 - 0000000 ____D () H:\94677e1b4707d7452aa83d9d21\3082
2011-12-25 06:30 - 2011-12-25 06:30 - 0094271 _____ () H:\94677e1b4707d7452aa83d9d21\3082\eula.rtf
2011-12-25 06:41 - 2011-12-25 06:41 - 0014112 _____ (Microsoft Corporation) H:\94677e1b4707d7452aa83d9d21\3082\HotFixInstallerUI.dll

====== End of Folder: ======

"H:\Documents and Settings\All Users\Application Data\YTD YouTube Downloader & Converter" => File/Directory not found.
"H:\Program Files\Common Files\LinkInstaller.exe" => File/Directory not found.
"H:\Documents and Settings\User\Local Settings\Application Data\cfktrgymlq.png" => File/Directory not found.
"H:\Documents and Settings\User\Local Settings\Application Data\dxhrfporqd.png" => File/Directory not found.
"H:\Documents and Settings\User\Local Settings\Application Data\lhjuankaye.png" => File/Directory not found.
"H:\Documents and Settings\User\Local Settings\Application Data\qrxghktvvs.png" => File/Directory not found.
H:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job not found.
H:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job not found.
"H:\WINDOWS\system32\xp_eos.exe" => File/Directory not found.
"H:\WINDOWS\system32\muweb.dll" => ":BDU" ADS not found.
"H:\WINDOWS\system32\wuweb.dll" => ":BDU" ADS not found.

========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BDAgent" /f =========


Error:  The system was unable to find the specified registry key or value


========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BitDefender Antiphishing Helper" /f =========


Error:  The system was unable to find the specified registry key or value


========= End of Reg: =========
 

Ок, значи сте го презаписали с нов файл (при опит за повторно изпълнение за скрипта) и явно затова в него всичко вече е липсващо. Това е добре и означава, че сме почистили добре системата.

Ок, сега вече можете да сканирате отново с FRST (уверете се, че има отметка пред Addition.txt преди да натиснете бутона Scan) и публикувайте свежите логове. Нека да проверим и с поне една антивирусна програма:

 

  • Моля изтеглете и стартирайте изпълнимия файл от линка отдолу:
    ESET OnlineScan
  • Сложете отметката предesetAcceptTerms.png
  • Натиснете бутона esetStart.png.
  • Сложете отметката пред Enable detection of potentially unwanted applications.
  • Сега кликнете на Advanced Settings и се уверете, че опцията Remove found threats не е маркирана, а следните са маркирани:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
    • Изберете сега бутона Change и изберете само Operating memory и дял C:\

fhSji42.png

 

  • Натиснете бутона Start.
  • ESET ще започне да сваля и инсталира актуализации за вирусните дефиниции и след това ще започне да сканира компютъра. Бъдете търпеливи, защото процеса е бавен и може да отнеме доста време.
  • След като проверката приключи натиснете бутонаesetListThreats.png
  • Сега натиснете бутона esetExport.png, и запазете файла на десктопа с име по избор като например (ESETScan.txt). Копирайте резултата в следващия си коментар.
  • Натиснете бутона esetBack.png и след това натиснете бутона esetFinish.png за да затворите приложението.
  • Автор

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-04-2015 02
Ran by User (administrator) on PC-FB227302206B on 24-04-2015 10:16:09
Running from H:\Documents and Settings\User\My Documents\Downloads
Loaded Profiles: User (Available profiles: User & Administrator)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(HP) H:\WINDOWS\system32\HPSIsvc.exe
(Hewlett-Packard Company) H:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Nero AG) H:\Program Files\Nero\Update\NASvc.exe
() H:\Program Files\CDBurnerXP\NMSAccessU.exe
(Skype Technologies S.A.) H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Mozilla Corporation) H:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) H:\Program Files\Mozilla Firefox\plugin-container.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\RunOnce: [*EmptyTemp] => cmd /c rd /q/s H:\FRST\Temp
Winlogon\Notify\igfxcui: H:\WINDOWS\system32\igfxsrvc.dll [2004-11-02] (Intel Corporation)
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: E - E:\Install.exe
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: {9eea6e54-11aa-11e2-ac0d-28107bbdacc7} - E:\KODAK_Software_Downloader.exe
HKU\S-1-5-18\...\RunOnce: [RunNarrator] => H:\WINDOWS\system32\Narrator.exe [53760 2008-04-14] (Microsoft Corporation)
Startup: H:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> H:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-20] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> H:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-20] (Oracle Corporation)
BHO: BHO_TIMELINEREMOVE.Bho -> {e7b9b609-19ad-40a4-a288-b300a3087465} -> H:\WINDOWS\system32\mscoree.dll [2010-03-18] (Microsoft Corporation)
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289583241062
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - H:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015
FF SelectedSearchEngine: Yahoo!
FF Homepage: https://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> H:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-20] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> H:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> H:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-20] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> h:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: Adobe Reader -> H:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1614895754-1645522239-1417001333-1003: @Skype Limited.com/Facebook Video Calling Plugin -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll [2012-10-12] (Skype Limited)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2012-01-12] (BitComet)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\google-dictionary-english-french.xml [2012-08-28]
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\wikipedia-franais-et-anglais.xml [2012-08-28]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\911bg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\pe-bg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml [2015-04-15]
FF Extension: United States English Spellchecker - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-05-19]
FF Extension: Dictionnaire français «Moderne» - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-01-08]
FF Extension: TimeLineRemove.Com - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-19]
FF Extension: Microsoft .NET Framework Assistant - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-11-14]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-20]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\trash [2012-08-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2015-04-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-11-12]
FF ExtraCheck: H:\Program Files\mozilla firefox\firefox.cfg [2015-01-15] <==== ATTENTION

Chrome:
=======
CHR Profile: H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Gmail) - H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-12]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 CCALib8; H:\Program Files\Canon\CAL\CALMAIN.exe [96341 2006-03-30] (Canon Inc.) [File not signed]
R3 hpqcxs08; H:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; H:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 LightScribeService; H:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-08-16] (Hewlett-Packard Company) [File not signed]
R2 NAUpdate; H:\Program Files\Nero\Update\NASvc.exe [573224 2011-01-26] (Nero AG)
R2 Net Driver HPZ12; H:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
R2 NMSAccess; H:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] ()
R2 Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Skype C2C Service; H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S2 WLSVC; H:\Program Files\D-Link\DWA-130 revE\WLSVC.exe [167936 2009-02-11] () [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AegisP; H:\WINDOWS\System32\DRIVERS\AegisP.sys [21361 2012-07-08] (Cisco Systems, Inc.) [File not signed]
S3 CCDECODE; H:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 HPZid412; H:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
S3 HPZipr12; H:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
S3 HPZius12; H:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
S3 NdisIP; H:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 rt2870; H:\WINDOWS\System32\DRIVERS\Drt2870.sys [829152 2010-05-06] (Ralink Technology, Corp.)
S3 rtl8139; H:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
R2 StarOpen; H:\WINDOWS\system32\Drivers\StarOpen.sys [5504 2009-11-12] () [File not signed]
R2 WLNdis50; H:\WINDOWS\System32\DRIVERS\wlndis50.sys [20480 2008-02-27] () [File not signed]
U1 WS2IFSL; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-24 10:15 - 2015-04-24 10:16 - 00000000 ____D () H:\FRST
2015-04-21 18:51 - 2015-04-21 20:22 - 00000000 ____D () H:\Documents and Settings\User\Desktop\nik
2015-04-20 21:13 - 2015-04-20 21:13 - 00000104 _____ () H:\Documents and Settings\User\Desktop\Internet.lnk
2015-04-20 20:00 - 2015-04-20 20:00 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Sun
2015-04-20 19:49 - 2015-04-20 19:49 - 00000724 _____ () H:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
2015-04-20 19:26 - 2015-04-20 19:27 - 00031668 _____ () H:\Addition.txt
2015-04-20 18:21 - 2015-04-20 19:40 - 00119512 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-04-20 18:21 - 2015-04-20 18:21 - 00000777 _____ () H:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-20 18:21 - 2015-04-14 09:37 - 00120024 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-04-20 18:21 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbam.sys
2015-04-20 18:17 - 2015-04-20 18:17 - 21546080 _____ (Malwarebytes Corporation ) H:\mbam-setup-consumer-2.1.6.1022.exe
2015-04-20 17:55 - 2015-04-21 20:17 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 5 - Историография - Ново време
2015-04-20 17:55 - 2015-04-20 19:49 - 00000000 ____D () H:\Program Files\Mozilla Firefox
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Program Files\Common Files\Skype
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 4 - Историография - Праистория и Античност
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 2 - Историография - Средновековие
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 1 - Източници и изворознание
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\snow queen tous
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\end2
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9outs
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9 end
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\29r
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2 outs
2015-04-20 16:49 - 2015-04-20 17:47 - 00000000 ____D () H:\Program Files\ShadowExplorer
2015-04-20 16:49 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ShadowExplorer
2015-04-20 09:49 - 2015-04-20 09:49 - 00008984 _____ () H:\Documents and Settings\User\Desktop\mbam1.txt
2015-04-20 09:46 - 2015-04-20 19:18 - 00004663 _____ () H:\Documents and Settings\User\Desktop\mbam.txt
2015-04-18 23:18 - 2015-04-18 23:18 - 00008536 _____ () H:\Documents and Settings\Administrator\Desktop\mb scan.txt
2015-04-18 21:49 - 2015-04-20 18:21 - 00000000 ____D () H:\Program Files\Malwarebytes Anti-Malware
2015-04-18 21:30 - 2015-04-18 21:41 - 00003572 _____ () H:\Documents and Settings\Administrator\Desktop\Rkill.txt
2015-04-18 21:21 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Mozilla
2015-04-18 21:21 - 2015-04-18 21:21 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Macromedia
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Adobe
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\NetworkService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:05 - 2015-04-18 20:05 - 00002674 _____ () H:\Documents and Settings\LocalService\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Desktop\HELP_RESTORE_FILES.txt
2015-04-18 20:04 - 2015-04-18 20:04 - 00002674 _____ () H:\Documents and Settings\Default User\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 20:03 - 2015-04-18 20:03 - 00002674 _____ () H:\Documents and Settings\Administrator\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 19:50 - 2015-04-18 23:16 - 00001324 _____ () H:\WINDOWS\system32\d3d9caps.dat
2015-04-12 01:28 - 2015-04-18 20:06 - 00113732 _____ () H:\Documents and Settings\User\Desktop\10470717_10152942390179635_5357236154732284632_n.jpg.ecc
2015-04-12 01:27 - 2015-04-18 20:06 - 00054468 _____ () H:\Documents and Settings\User\Desktop\11145571_10152958877974635_3339765670712915872_n.jpg.ecc
2015-04-05 12:26 - 2015-04-18 20:06 - 00090580 _____ () H:\Documents and Settings\User\Desktop\11138672_982700228409538_8855858409597611766_n.jpg.ecc
2015-04-04 01:57 - 2015-04-04 02:02 - 00000000 ____D () H:\Documents and Settings\User\My Documents\Attestation123
2015-04-04 01:56 - 2015-04-18 21:12 - 00381604 _____ () H:\Documents and Settings\User\Desktop\Attestation2.pdf.ecc
2015-04-03 14:06 - 2015-04-03 14:06 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\Hewlett-Packard
2015-04-01 15:28 - 2015-04-18 20:06 - 00038404 _____ () H:\Documents and Settings\User\Desktop\11096536_10153198374462173_1538024734260084523_n.jpg.ecc
2015-03-29 22:34 - 2015-04-18 20:06 - 00058036 _____ () H:\Documents and Settings\User\Desktop\10923243_823850137672875_4923851942726001590_n.jpg.ecc
2015-03-25 17:48 - 2015-04-20 16:10 - 00001748 _____ () H:\Documents and Settings\User\Desktop\doc_57.png.ecc
2015-03-25 15:31 - 2015-04-18 20:06 - 00061220 _____ () H:\Documents and Settings\User\Desktop\0cb712a19e742a9725b3c7cf78a6d908_600x460.jpg.ecc

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-24 10:16 - 2010-11-12 13:32 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Temp
2015-04-24 08:57 - 2012-06-30 23:39 - 00001148 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003UA.job
2015-04-24 07:25 - 2010-11-12 13:31 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Temp
2015-04-24 07:16 - 2001-08-23 08:00 - 00002206 _____ () H:\WINDOWS\system32\wpa.dbl
2015-04-24 07:15 - 2010-11-12 13:18 - 01949850 _____ () H:\WINDOWS\WindowsUpdate.log
2015-04-24 07:14 - 2010-11-12 13:31 - 00000006 ____H () H:\WINDOWS\Tasks\SA.DAT
2015-04-24 07:14 - 2010-11-12 08:08 - 00000299 _____ () H:\WINDOWS\wiadebug.log
2015-04-24 07:14 - 2010-11-12 08:08 - 00000052 _____ () H:\WINDOWS\wiaservc.log
2015-04-23 19:21 - 2013-12-07 23:22 - 00000000 ___RD () H:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
2015-04-23 19:21 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator
2015-04-23 19:19 - 2010-11-12 13:14 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Accessories
2015-04-23 17:57 - 2012-06-30 23:39 - 00001126 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003Core.job
2015-04-23 16:39 - 2013-10-26 17:49 - 00000000 ____D () H:\Documents and Settings\User\My Documents\AS-CV
2015-04-23 06:57 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Temp
2015-04-23 06:53 - 2010-11-12 13:28 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Temp
2015-04-23 06:52 - 2010-11-12 08:04 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Temp
2015-04-23 06:42 - 2013-10-26 16:34 - 00278076 _____ () H:\WINDOWS\setupapi.log
2015-04-23 05:47 - 2010-11-12 13:32 - 00000178 ___SH () H:\Documents and Settings\User\ntuser.ini
2015-04-23 05:47 - 2010-11-12 13:31 - 00031772 _____ () H:\WINDOWS\SchedLgU.Txt
2015-04-22 23:11 - 2013-10-27 02:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\moda
2015-04-21 20:23 - 2012-05-14 19:46 - 00002465 _____ () H:\Documents and Settings\All Users\Desktop\Nero StartSmart 10.lnk
2015-04-21 18:51 - 2014-02-15 20:44 - 00000000 ____D () H:\Documents and Settings\User\Desktop\sub.vvv
2015-04-21 08:27 - 2014-07-27 00:13 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-27
2015-04-21 08:26 - 2014-09-02 22:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-02
2015-04-21 08:26 - 2014-08-31 00:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-31
2015-04-21 08:25 - 2014-07-13 19:22 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-13
2015-04-21 08:25 - 2014-05-20 13:45 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-05-20
2015-04-21 08:24 - 2014-08-28 20:43 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-28
2015-04-21 08:14 - 2010-11-14 18:34 - 00000000 ____D () H:\WINDOWS\pss
2015-04-21 08:14 - 2001-08-23 08:00 - 00000630 _____ () H:\WINDOWS\win.ini
2015-04-21 08:14 - 2001-08-23 08:00 - 00000227 _____ () H:\WINDOWS\system.ini
2015-04-21 07:54 - 2012-02-11 11:47 - 00002265 _____ () H:\Documents and Settings\All Users\Desktop\Skype.lnk
2015-04-21 07:54 - 2010-11-13 00:51 - 00000000 ____D () H:\Documents and Settings\User\Application Data\Skype
2015-04-20 20:08 - 2013-10-25 16:28 - 00000000 ____D () H:\AdwCleaner
2015-04-20 20:04 - 2010-11-18 19:35 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\Adobe
2015-04-20 20:03 - 2012-04-18 22:24 - 00778416 _____ (Adobe Systems Incorporated) H:\WINDOWS\system32\FlashPlayerApp.exe
2015-04-20 20:03 - 2011-08-26 22:30 - 00142512 _____ (Adobe Systems Incorporated) H:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-04-20 20:00 - 2012-02-18 21:41 - 00000000 ____D () H:\Program Files\Java
2015-04-20 19:59 - 2014-10-24 10:30 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Oracle
2015-04-20 19:57 - 2013-03-23 10:04 - 00096680 _____ (Oracle Corporation) H:\WINDOWS\system32\WindowsAccessBridge.dll
2015-04-20 19:57 - 2012-02-18 21:41 - 00146432 _____ (Oracle Corporation) H:\WINDOWS\system32\javacpl.cpl
2015-04-20 19:55 - 2010-11-12 21:43 - 00000000 ____D () H:\Documents and Settings\User\My Documents\programi
2015-04-20 19:19 - 2012-10-01 06:03 - 00073960 _____ () H:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2015-04-20 19:13 - 2013-10-09 06:27 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2862335$
2015-04-20 18:12 - 2010-11-12 08:04 - 00615742 _____ () H:\WINDOWS\system32\PerfStringBackup.INI
2015-04-20 18:00 - 2013-10-26 16:35 - 00000986 _____ () H:\WINDOWS\setupact.log
2015-04-20 17:57 - 2010-11-12 08:03 - 00286904 _____ () H:\WINDOWS\system32\FNTCACHE.DAT
2015-04-20 17:56 - 2010-11-12 13:31 - 00000000 __SHD () H:\Documents and Settings\LocalService
2015-04-20 17:56 - 2010-11-12 13:28 - 00000000 __SHD () H:\Documents and Settings\NetworkService
2015-04-20 17:56 - 2010-11-12 13:16 - 00000000 ____D () H:\WINDOWS\Registration
2015-04-20 17:55 - 2015-01-24 14:35 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype(2)
2015-04-20 17:55 - 2013-01-08 20:29 - 00000000 ____D () H:\Documents and Settings\User\Application Data\BitTorrent
2015-04-20 17:55 - 2012-09-18 23:37 - 00000000 ___RD () H:\Program Files\Skype
2015-04-20 17:55 - 2012-05-03 16:07 - 00000000 ____D () H:\Program Files\Mozilla Maintenance Service
2015-04-20 17:53 - 2015-02-23 22:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\hyde
2015-04-20 17:53 - 2015-02-23 20:21 - 00000000 ____D () H:\Documents and Settings\User\Desktop\b est of me
2015-04-20 17:53 - 2015-02-23 20:18 - 00000000 ____D () H:\Documents and Settings\User\Desktop\New Folder(2)
2015-04-20 17:53 - 2015-02-23 20:16 - 00000000 ____D () H:\Documents and Settings\User\Desktop\j789
2015-04-20 17:53 - 2015-02-23 20:16 - 00000000 ____D () H:\Documents and Settings\User\Desktop\j456
2015-04-20 17:53 - 2015-02-23 20:14 - 00000000 ____D () H:\Documents and Settings\User\Desktop\New Folder
2015-04-20 17:52 - 2013-07-15 23:21 - 00000000 ____D () H:\WINDOWS\system32\MRT
2015-04-20 17:06 - 2013-11-23 04:02 - 00519776 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2015-04-20 17:06 - 2010-11-12 13:17 - 00000000 ____D () H:\WINDOWS\system32\Restore
2015-04-20 16:40 - 2014-03-30 13:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\18
2015-04-19 23:43 - 2014-09-08 19:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-08
2015-04-19 00:18 - 2014-06-08 20:04 - 00000000 ____D () H:\Documents and Settings\User\My Documents\sub1
2015-04-18 23:20 - 2011-11-11 00:38 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2641690$
2015-04-18 21:13 - 2014-09-27 00:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Jardine bothanique
2015-04-18 21:13 - 2013-11-30 17:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\disain
2015-04-18 21:13 - 2013-10-27 02:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\krasivo
2015-04-18 21:13 - 2013-05-28 07:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\inter
2015-04-18 21:12 - 2015-01-06 00:00 - 00040260 _____ () H:\Documents and Settings\User\Desktop\bride.and.prejudice.2004.dvdrip.xvid-endi(subsunacs.net).zip.ecc
2015-04-18 21:12 - 2014-08-17 17:03 - 16454852 _____ () H:\Documents and Settings\User\Desktop\attachments_2014_08_17.zip.ecc
2015-04-18 20:58 - 2014-09-27 18:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-27
2015-04-18 20:29 - 2014-09-18 22:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-18
2015-04-18 20:06 - 2015-02-06 23:20 - 00188836 _____ () H:\Documents and Settings\User\Desktop\1066517_4543673565274_2119997541_o.jpg.ecc
2015-04-18 20:06 - 2015-01-08 21:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2
2015-04-18 20:06 - 2014-03-30 13:14 - 00014372 _____ () H:\Documents and Settings\User\Desktop\17.torent.ecc
2015-04-18 20:05 - 2012-08-10 15:44 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\bdch
2015-04-18 20:05 - 2012-02-17 06:40 - 00000000 __SHD () H:\Documents and Settings\NetworkService\IETldCache
2015-04-18 20:05 - 2010-11-13 00:57 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
2015-04-18 20:04 - 2014-10-24 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Java
2015-04-18 20:04 - 2014-04-26 11:43 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\JustVoip
2015-04-18 20:04 - 2013-02-16 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ooVoo
2015-04-18 20:04 - 2013-01-08 20:32 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
2015-04-18 20:04 - 2012-11-11 03:32 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\bdch
2015-04-18 20:04 - 2012-11-07 00:51 - 00000000 ____D () H:\Documents and Settings\LocalService\Application Data\QuickScan
2015-04-18 20:04 - 2012-07-08 00:07 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\D-Link
2015-04-18 20:04 - 2012-06-27 17:08 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
2015-04-18 20:04 - 2012-06-19 18:28 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\TechSmith
2015-04-18 20:04 - 2011-12-19 00:57 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft Help
2015-04-18 20:04 - 2011-12-18 18:15 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
2015-04-18 20:04 - 2011-12-17 19:54 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\DVDVideoSoft
2015-04-18 20:04 - 2011-10-16 20:17 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
2015-04-18 20:04 - 2011-05-17 16:09 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Keyboard
2015-04-18 20:04 - 2011-02-07 22:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
2015-04-18 20:04 - 2011-02-06 00:33 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
2015-04-18 20:04 - 2011-01-16 21:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Nero
2015-04-18 20:04 - 2010-12-01 20:18 - 00000000 ___SD () H:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 3.1
2015-04-18 20:04 - 2010-11-25 17:10 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\HP
2015-04-18 20:04 - 2010-11-15 22:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\LightScribe Direct Disc Labeling
2015-04-18 20:04 - 2010-11-13 00:52 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Google
2015-04-18 20:04 - 2010-11-12 23:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\AVS4YOU
2015-04-18 20:04 - 2010-11-12 22:16 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
2015-04-18 20:04 - 2010-11-12 21:42 - 00000000 __SHD () H:\Documents and Settings\LocalService\IETldCache
2015-04-18 20:04 - 2010-11-12 13:18 - 00000000 __SHD () H:\Documents and Settings\All Users\DRM
2015-04-18 20:04 - 2010-11-12 13:18 - 00000000 ___RD () H:\Documents and Settings\Default User\Start Menu\Programs\Accessories
2015-04-18 20:04 - 2010-11-12 13:16 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Games
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 __SHD () H:\Documents and Settings\Administrator\IETldCache
2015-04-18 20:03 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft Help
2015-04-18 20:03 - 2011-01-16 21:24 - 00000000 ____D () H:\bb6fadc9d2f25f3b2953e5d2
2015-04-18 20:03 - 2010-11-12 02:18 - 00000000 ____D () H:\d688a5c03ea38202645f5bc01eeb02
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\a812a3d6-ecc8-4750-9477-c631757694a4.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\92c937b0-dfc0-4b6d-a16f-6fc079dec2a3.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\4e28d2f5-abaf-40c7-a2d7-f3a7ad9a45ff.dmp.ecc
2015-04-18 19:20 - 2013-09-21 01:37 - 00024068 _____ () H:\0feed571-1be8-4bc1-8ccd-82480f9105ff.dmp.ecc
2015-04-18 19:20 - 2012-09-17 19:42 - 00029492 _____ () H:\.pdf.ecc
2015-04-18 19:20 - 2012-07-29 22:31 - 00465764 _____ () H:\112.pdf.ecc
2015-04-18 19:20 - 2012-02-28 14:22 - 00000000 ____D () H:\54c3cb947aef816ceabdedb8f7
2015-04-18 19:20 - 2012-02-11 14:34 - 00000000 ____D () H:\128b39739a3c8290c766a9
2015-04-18 19:20 - 2012-02-06 22:14 - 00000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1
2015-04-18 19:20 - 2012-02-01 15:45 - 00000000 ____D () H:\94677e1b4707d7452aa83d9d21
2015-04-17 23:45 - 2014-01-11 01:48 - 00000000 ____D () H:\Documents and Settings\User\My Documents\subtitle
2015-04-05 15:36 - 2014-06-08 18:50 - 00000000 ____D () H:\Documents and Settings\User\Desktop\l5678
2015-04-05 12:31 - 2012-06-15 14:53 - 00270848 ___SH () H:\Documents and Settings\User\Desktop\Thumbs.db
2015-04-03 15:46 - 2012-06-17 20:14 - 00000000 ____D () H:\Documents and Settings\User\My Documents\attestation

==================== Files in the root of some directories =======

2010-11-12 22:29 - 2015-01-14 18:38 - 0088064 _____ () H:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

H:\WINDOWS\explorer.exe => File is digitally signed
H:\WINDOWS\system32\winlogon.exe => File is digitally signed
H:\WINDOWS\system32\svchost.exe => File is digitally signed
H:\WINDOWS\system32\services.exe => File is digitally signed
H:\WINDOWS\system32\User32.dll => File is digitally signed
H:\WINDOWS\system32\userinit.exe => File is digitally signed
H:\WINDOWS\system32\rpcss.dll => File is digitally signed
H:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-04-2015 02
Ran by User at 2015-04-24 10:17:04
Running from H:\Documents and Settings\User\My Documents\Downloads
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1614895754-1645522239-1417001333-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
ASPNET (S-1-5-21-1614895754-1645522239-1417001333-1004 - Limited - Enabled)
Guest (S-1-5-21-1614895754-1645522239-1417001333-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-1614895754-1645522239-1417001333-1000 - Limited - Disabled)
SUPPORT_388945a0 (S-1-5-21-1614895754-1645522239-1417001333-1002 - Limited - Disabled)
User (S-1-5-21-1614895754-1645522239-1417001333-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\User

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)


==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

32 Bit HP CIO Components Installer (Version: 1.0.0 - Hewlett-Packard) Hidden
7-Zip 9.21 (HKLM\...\{23170F69-40C1-2701-0921-000001000000}) (Version: 9.21.00.0 - Igor Pavlov)
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.223 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) - Français (HKLM\...\{AC76BA86-7AD7-1036-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\Akamai) (Version:  - Akamai Technologies, Inc)
AVS Video Converter 6 (HKLM\...\AVS4YOU Video Converter 6_is1) (Version:  - Online Media Technologies Ltd.)
AVS4YOU Software Navigator 1.3 (HKLM\...\AVS4YOU Software Navigator_is1) (Version:  - Online Media Technologies Ltd.)
BitLord 1.1 (HKLM\...\BitLord) (Version: 1.1 - www.bitlord.com)
BitTorrent (HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\BitTorrent) (Version: 7.9.2.34312 - BitTorrent Inc.)
BSPlayer (HKLM\...\BSPlayer1) (Version:  - )
BufferChm (Version: 100.0.170.000 - Hewlett-Packard) Hidden
Canon Camera Access Library (HKLM\...\CAL) (Version: 8.3.0.1 - )
Canon Camera Support Core Library (HKLM\...\CSCLIB) (Version: 7.3.1.6 - )
Canon Camera Window DC_DV 5 for ZoomBrowser EX (HKLM\...\CameraWindowDVC5) (Version: 5.4.5.17 - )
Canon Camera Window DC_DV 6 for ZoomBrowser EX (HKLM\...\CameraWindowDVC6) (Version: 6.4.0.9 - )
Canon Camera Window MC 6 for ZoomBrowser EX (HKLM\...\CameraWindowMC) (Version: 6.3.0.8 - )
Canon G.726 WMP-Decoder (HKLM\...\Canon G.726 WMP-Decoder) (Version: 1.1.0.4 - )
Canon MovieEdit Task for ZoomBrowser EX (HKLM\...\MovieEditTask) (Version: 2.4.0.14 - )
Canon RAW Image Task for ZoomBrowser EX (HKLM\...\RAW Image Task) (Version: 2.5.0.8 - )
Canon RemoteCapture Task for ZoomBrowser EX (HKLM\...\RemoteCaptureTask) (Version: 1.7.0.8 - )
Canon Utilities EOS Utility (HKLM\...\EOS Utility) (Version: 1.1.0.8 - )
Canon Utilities PhotoStitch (HKLM\...\PhotoStitch) (Version: 3.1.19.43 - )
Canon Utilities ZoomBrowser EX (HKLM\...\ZoomBrowser EX) (Version: 5.8.0.74 - )
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.0.2838 - CDBurnerXP)
Copy (Version: 100.0.170.000 - Hewlett-Packard) Hidden
CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Data Fax SoftModem with SmartCP (HKLM\...\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1) (Version:  - )
Destination Component (Version: 100.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (Version: 100.0.190.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
DJ_AIO_03_F4200_ProductContext (Version: 100.0.215.000 - Hewlett-Packard) Hidden
DJ_AIO_03_F4200_Software (Version: 100.0.206.000 - Hewlett-Packard) Hidden
DJ_AIO_03_F4200_Software_Min (Version: 100.0.213.000 - Hewlett-Packard) Hidden
D-Link DWA-130 Wireless N USB Adapter (HKLM\...\{6F6F39E3-D24D-4EEE-9AEA-DEDAF991385D}) (Version:  - D-Link)
eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
F4200 (Version: 100.0.206.000 - Hewlett-Packard) Hidden
F4200_Help (Version: 100.0.206.000 - Hewlett-Packard) Hidden
Facebook Video Calling 1.2.0.287 (HKLM\...\{B92C5909-1D37-4C51-8397-A28BB28E5DC3}) (Version: 1.2.287 - Skype Limited)
GPBaseService (Version: 100.0.187.000 - Hewlett-Packard) Hidden
High-Definition Video Playback (Version: 7.1.13400.42.0 - Nero AG) Hidden
HP Customer Participation Program 10.0 (HKLM\...\HPExtendedCapabilities) (Version: 10.0 - HP)
HP Deskjet F4200 All-In-One Driver Software 10.0 Rel .3 (HKLM\...\{AE9A67F9-ADF1-4a44-BAB5-C1DB302B37A2}) (Version: 10.0 - HP)
HP Imaging Device Functions 10.0 (HKLM\...\HP Imaging Device Functions) (Version: 10.0 - HP)
HP LaserJet Professional P1100-P1560-P1600 Series (HKLM\...\HP LaserJet Professional P1100-P1560-P1600 Series) (Version:  - )
HP Photosmart Essential 2.5 (HKLM\...\HP Photosmart Essential) (Version: 2.5 - HP)
HP Smart Web Printing (HKLM\...\HP Smart Web Printing) (Version: 3.5 - HP)
HP Solution Center 10.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 10.0 - HP)
HP Update (HKLM\...\{11B83AD3-7A46-4C2E-A568-9505981D4C6F}) (Version: 4.000.007.003 - Hewlett-Packard)
HPProductAssistant (Version: 100.0.170.000 - Hewlett-Packard) Hidden
ImagXpress (Version: 7.0.74.0 - Nero AG) Hidden
Intel® Graphics Media Accelerator Driver (HKLM\...\{8A708DD8-A5E6-11D4-A706-000629E95E20}) (Version:  - )
Java 8 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
JavaFX 2.1.1 (HKLM\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Jing (HKLM\...\{7AB01508-C2B2-43C8-8B44-514801E7CCC9}) (Version: 2.6.12032.1 - TechSmith Corporation)
JustVoip (HKLM\...\JustVoip_is1) (Version: 4.12 build 704 - Finarea S.A. Switzerland)
K-Lite Codec Pack 4.1.7 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 4.1.7 - )
Korean Fonts Support For Adobe Reader X (HKLM\...\{AC76BA86-7AD7-5670-0000-A00000000003}) (Version: 10.0.0 - Adobe Systems Incorporated)
LightScribe System Software (HKLM\...\{705B639E-FAAF-40D7-AD58-C445321C7C3F}) (Version: 1.18.18.1 - LightScribe)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MarketResearch (Version: 100.0.170.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version:  - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30730 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Base Smart Card Cryptographic Service Provider Package (HKLM\...\KB909520) (Version:  - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft IntelliType Pro 6.2 (HKLM\...\{345112D9-0930-4A68-AB71-A831BA5DE7AA}) (Version: 6.20.182.0 - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (HKLM\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version:  - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 37.0.2 (x86 bg) (HKLM\...\Mozilla Firefox 37.0.2 (x86 bg)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 32.0.3 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero BurnLite 10 (HKLM\...\{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}) (Version: 10.0.10600 - Nero AG)
Nero BurnLite 10 (HKLM\...\{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}) (Version: 10.0.10500.5.100 - Nero AG)
Nero BurnRights 10 (HKLM\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.0.11300.14.100 - Nero AG)
Nero CoverDesigner 10 (HKLM\...\{FCF00A6E-FB58-477A-ABE9-232907105521}) (Version: 5.0.11200.16.100 - Nero AG)
Nero DiscSpeed 10 (HKLM\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.0.11400.18.100 - Nero AG)
Nero Express 10 (HKLM\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.0.12300.23.100 - Nero AG)
Nero InfoTool 10 (HKLM\...\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.0.11400.15.100 - Nero AG)
Nero MediaHub 10 (HKLM\...\{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}) (Version: 1.0.14800.28.100 - Nero AG)
Nero Multimedia Suite 10 (HKLM\...\{277C1559-4CF7-44FF-8D07-98AA9C13AABD}) (Version: 10.5.10500 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM\...\{7D0A13FA-56BC-4755-8BAF-45A69BA6A5C8}) (Version: 10.0.10300 - Nero AG)
Nero StartSmart 10 (HKLM\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.0.12600.30.100 - Nero AG)
Nero Update (HKLM\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.10400.26.0 - Nero AG)
NetZero Internet and Voice Offer (HKLM\...\{8BBA35B6-E1A9-4FE0-892B-8F7980584D52}) (Version: 2.0 - )
ooVoo (HKLM\...\{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}) (Version: 3.5.6046 - ooVoo LLC.)
OpenOffice.org 3.1 (HKLM\...\{E6B87DC4-2B3D-4483-ADFF-E483BF718991}) (Version: 3.1.9399 - OpenOffice.org)
PDFConverter Desktop (HKLM\...\PDFConverter Desktop_is1) (Version:  - Baltsoft Software)
PSSWCORE (Version: 2.02.0000 - Hewlett-Packard) Hidden
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version:  - )
SA Dictionary 2008 Beta 4 (HKLM\...\{055A5AF0-9FEB-440D-B00A-18935C7C171C}) (Version: 6.6.12 - Stefan Angelov)
Scan (Version: 10.0.0.0 - Hewlett-Packard) Hidden
Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
Skype™ 6.14 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
SmartWebPrintingOC (Version: 100.0.189.000 - Hewlett-Packard) Hidden
SolutionCenter (Version: 100.0.175.000 - Hewlett-Packard) Hidden
Status (Version: 100.0.175.000 - Hewlett-Packard) Hidden
TimeLineRemove 0.9 (HKLM\...\TimeLineRemove_is1) (Version: 0.9 - TimeLineRemove)
Toolbox (Version: 100.0.170.000 - Hewlett-Packard) Hidden
TrayApp (Version: 100.0.170.000 - Hewlett-Packard) Hidden
UnloadSupport (Version: 10.0.0 - Hewlett-Packard) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VideoToolkit01 (Version: 100.0.128.000 - Hewlett-Packard) Hidden
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
WebReg (Version: 100.0.170.000 - Hewlett-Packard) Hidden
Windows Genuine Advantage Notifications (KB905474) (HKLM\...\WgaNotify) (Version: 1.9.0040.0 - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version:  - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Management Framework Core (HKLM\...\KB968930) (Version:  - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version:  - )
Windows Media Player 11 (HKLM\...\Windows Media Player) (Version:  - )
WinRAR archiver (HKLM\...\WinRAR archiver) (Version:  - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

==================== Restore Points  =========================

24-01-2015 20:10:16 System Checkpoint
25-01-2015 21:30:16 System Checkpoint
26-01-2015 21:45:39 System Checkpoint
27-01-2015 22:21:27 System Checkpoint
28-01-2015 23:07:46 System Checkpoint
29-01-2015 23:17:56 System Checkpoint
31-01-2015 01:44:54 System Checkpoint
01-02-2015 03:25:45 System Checkpoint
02-02-2015 16:53:02 System Checkpoint
03-02-2015 20:59:01 System Checkpoint
04-02-2015 21:34:04 System Checkpoint
05-02-2015 21:48:23 System Checkpoint
06-02-2015 21:56:58 System Checkpoint
08-02-2015 00:41:33 System Checkpoint
10-02-2015 16:45:23 System Checkpoint
11-02-2015 17:12:57 System Checkpoint
12-02-2015 19:11:03 System Checkpoint
13-02-2015 20:38:49 System Checkpoint
15-02-2015 00:39:36 System Checkpoint
16-02-2015 15:26:05 System Checkpoint
17-02-2015 16:06:44 System Checkpoint
18-02-2015 16:38:13 System Checkpoint
19-02-2015 16:51:08 System Checkpoint
20-02-2015 16:55:55 System Checkpoint
21-02-2015 21:13:39 System Checkpoint
22-02-2015 21:57:51 System Checkpoint
23-02-2015 22:55:45 System Checkpoint
24-02-2015 23:50:53 System Checkpoint
26-02-2015 17:01:13 System Checkpoint
27-02-2015 18:28:09 System Checkpoint
28-02-2015 19:21:55 System Checkpoint
01-03-2015 20:07:38 System Checkpoint
02-03-2015 22:06:30 System Checkpoint
04-03-2015 17:30:18 System Checkpoint
05-03-2015 17:56:16 System Checkpoint
07-03-2015 00:40:13 System Checkpoint
08-03-2015 15:43:48 System Checkpoint
09-03-2015 16:23:53 System Checkpoint
10-03-2015 00:31:25 Software Distribution Service 3.0
10-03-2015 23:00:41 Software Distribution Service 3.0
10-03-2015 23:41:26 Software Distribution Service 3.0
11-03-2015 23:00:19 Software Distribution Service 3.0
12-03-2015 00:49:00 Software Distribution Service 3.0
12-03-2015 23:00:16 Software Distribution Service 3.0
13-03-2015 00:09:23 Software Distribution Service 3.0
13-03-2015 06:00:06 Software Distribution Service 3.0
13-03-2015 18:59:07 Software Distribution Service 3.0
13-03-2015 23:00:17 Software Distribution Service 3.0
13-03-2015 23:58:13 Software Distribution Service 3.0
14-03-2015 23:00:24 Software Distribution Service 3.0
15-03-2015 01:32:03 Software Distribution Service 3.0
15-03-2015 20:15:11 Software Distribution Service 3.0
15-03-2015 20:17:47 Software Distribution Service 3.0
15-03-2015 20:20:54 Software Distribution Service 3.0
16-03-2015 20:49:59 System Checkpoint
17-03-2015 21:32:52 System Checkpoint
18-03-2015 22:44:40 System Checkpoint
19-03-2015 22:57:06 System Checkpoint
21-03-2015 07:21:55 System Checkpoint
22-03-2015 09:37:22 System Checkpoint
23-03-2015 16:59:03 System Checkpoint
24-03-2015 20:21:29 System Checkpoint
25-03-2015 20:34:42 System Checkpoint
26-03-2015 20:42:21 System Checkpoint
27-03-2015 20:44:05 System Checkpoint
28-03-2015 21:51:56 System Checkpoint
29-03-2015 22:09:07 System Checkpoint
30-03-2015 22:23:50 System Checkpoint
31-03-2015 22:24:52 System Checkpoint
01-04-2015 22:51:26 System Checkpoint
03-04-2015 12:08:04 System Checkpoint
03-04-2015 14:04:57 Installed HP Support Solutions Framework
04-04-2015 14:34:37 System Checkpoint
05-04-2015 15:29:17 System Checkpoint
06-04-2015 15:39:03 System Checkpoint
07-04-2015 17:04:20 System Checkpoint
08-04-2015 17:07:01 System Checkpoint
09-04-2015 18:07:29 System Checkpoint
10-04-2015 19:03:28 System Checkpoint
11-04-2015 19:58:04 System Checkpoint
12-04-2015 20:52:38 System Checkpoint
13-04-2015 21:11:42 System Checkpoint
15-04-2015 15:50:06 System Checkpoint
16-04-2015 17:18:28 System Checkpoint
17-04-2015 17:56:00 System Checkpoint
18-04-2015 23:25:05 Removed Java 7 Update 17
18-04-2015 23:26:00 Removed Java 6 Update 31
20-04-2015 07:25:35 System Checkpoint
20-04-2015 17:06:16 Restore Operation
20-04-2015 17:14:43 Restore Operation
20-04-2015 17:28:11 Restore Operation
20-04-2015 17:42:53 Restore Operation
20-04-2015 19:58:36 Removed Java 7 Update 17
20-04-2015 19:59:41 Removed Java 6 Update 31
20-04-2015 20:00:54 Removed Java 8 Update 25
21-04-2015 21:16:05 System Checkpoint
22-04-2015 21:35:43 System Checkpoint
23-04-2015 21:44:37 System Checkpoint

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2001-08-23 08:00 - 2013-01-02 21:48 - 00000764 ____A H:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1       localhost
127.0.0.1 activate.adobe.com


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003Core.job => H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe
Task: H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003UA.job => H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe
Task: H:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IType_exe.job => H:\Program Files\Microsoft IntelliType Pro\itype.exe

==================== Loaded Modules (whitelisted) ==============

2011-11-12 18:48 - 2010-10-14 11:04 - 00151552 _____ () H:\WINDOWS\system32\HP1100LM.DLL
2011-11-12 18:48 - 2010-10-14 11:04 - 00069632 _____ () H:\WINDOWS\System32\spool\PRTPROCS\W32X86\HP1100PP.DLL
2012-03-27 18:24 - 2010-03-04 22:38 - 00071096 _____ () H:\Program Files\CDBurnerXP\NMSAccessU.exe
2010-11-12 22:16 - 2010-03-15 12:28 - 00141824 _____ () H:\Program Files\WinRAR\rarext.dll
2012-10-30 17:48 - 2008-10-22 17:07 - 00982016 _____ () H:\Program Files\PDFConverterDesktop\PDFConverterShell.dll
2012-08-20 06:24 - 2012-06-06 23:26 - 00016384 _____ () H:\Program Files\TimeLineRemove\0.9\TimeLineRemove.dll
2015-04-20 20:03 - 2015-04-20 20:03 - 16863920 _____ () H:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: H:\Documents and Settings\User\Desktop\doc_57.png.ecc:SummaryInformation
AlternateDataStreams: H:\Documents and Settings\User\Desktop\doc_57.png.ecc:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\google.com -> hxxp://www.google.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.0.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: H:^Documents and Settings^All Users^Start Menu^Programs^Startup^HELP_RESTORE_FILES.txt => H:\WINDOWS\pss\HELP_RESTORE_FILES.txtCommon Startup
MSCONFIG\startupfolder: H:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => H:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
MSCONFIG\startupfolder: H:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk => H:\WINDOWS\pss\Windows Search.lnkCommon Startup
MSCONFIG\startupfolder: H:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless Connection Manager.lnk => H:\WINDOWS\pss\Wireless Connection Manager.lnkCommon Startup
MSCONFIG\startupfolder: H:^Documents and Settings^User^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk => H:\WINDOWS\pss\OpenOffice.org 3.1.lnkStartup
MSCONFIG\startupreg: Adobe ARM => "H:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "H:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: Akamai NetSession Interface => "H:\Documents and Settings\User\Local Settings\Application Data\Akamai\netsession_win.exe"
MSCONFIG\startupreg: Alcmtr => ALCMTR.EXE
MSCONFIG\startupreg: AlcWzrd => ALCWZRD.EXE
MSCONFIG\startupreg: BitTorrent => "H:\Program Files\BitTorrent\BitTorrent.exe"  /MINIMIZED
MSCONFIG\startupreg: ctfmon.exe => H:\WINDOWS\system32\ctfmon.exe
MSCONFIG\startupreg: Facebook Update => "H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: HotKeysCmds => H:\WINDOWS\system32\hkcmd.exe
MSCONFIG\startupreg: HP Software Update => H:\Program Files\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: hpqSRMon => H:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
MSCONFIG\startupreg: IgfxTray => H:\WINDOWS\system32\igfxtray.exe
MSCONFIG\startupreg: itype => "H:\Program Files\Microsoft IntelliType Pro\itype.exe"
MSCONFIG\startupreg: JustVoip => "H:\Program Files\JustVoip.com\JustVoip\JustVoip.exe" -nosplash -minimized
MSCONFIG\startupreg: LightScribe Control Panel => H:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
MSCONFIG\startupreg: MSMSGS => "H:\Program Files\Messenger\msmsgs.exe" /background
MSCONFIG\startupreg: NBAgent => "H:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
MSCONFIG\startupreg: ooVoo.exe => H:\Program Files\ooVoo\oovoo.exe /minimized
MSCONFIG\startupreg: Skype => "H:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SoundMan => SOUNDMAN.EXE
MSCONFIG\startupreg: SunJavaUpdateSched => "H:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: swg => "H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: UserFaultCheck => %systemroot%\system32\dumprep 0 -u
MSCONFIG\startupreg: VX3000 => H:\WINDOWS\vVX3000.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/24/2015 09:21:39 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 37.0.2.5583, faulting module mozalloc.dll, version 37.0.2.5583, fault address 0x00001aa1.
Processing media-specific event for [plugin-container.exe!ws!]

Error: (04/24/2015 08:23:22 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x0740f6d5.
Processing media-specific event for [explorer.exe!ws!]

Error: (04/24/2015 07:25:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application frst.exe, version 22.4.2015.1, faulting module frst.exe, version 22.4.2015.1, fault address 0x0001f3d0.
Processing media-specific event for [frst.exe!ws!]

Error: (04/24/2015 07:11:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application frst.exe, version 22.4.2015.1, faulting module frst.exe, version 22.4.2015.1, fault address 0x0001f3f6.
Processing media-specific event for [frst.exe!ws!]

Error: (04/23/2015 07:29:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version 0.0.0.0, fault address 0x089cf6d5.
Processing media-specific event for [explorer.exe!ws!]

Error: (04/20/2015 07:13:46 PM) (Source: JavaQuickStarterService) (EventID: 1) (User: )
Description: Unable to open H:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf: No such file or directory

Error: (04/20/2015 06:02:15 PM) (Source: LoadPerf) (EventID: 3001) (User: )
Description: The performance counter name string value in the registry is incorrectly
formatted. The bogus string is 17996, the bogus index value is the first
DWORD in Data section while the last valid index values are the second and
third DWORD in Data section.

Error: (04/20/2015 06:02:12 PM) (Source: LoadPerf) (EventID: 3011) (User: )
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The
Error code is the first DWORD in Data section.

Error: (04/20/2015 06:02:12 PM) (Source: LoadPerf) (EventID: 3001) (User: )
Description: The performance counter name string value in the registry is incorrectly
formatted. The bogus string is 17996, the bogus index value is the first
DWORD in Data section while the last valid index values are the second and
third DWORD in Data section.

Error: (04/20/2015 05:57:53 PM) (Source: JavaQuickStarterService) (EventID: 1) (User: )
Description: Unable to open H:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf: No such file or directory


System errors:
=============
Error: (04/24/2015 07:16:14 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The HP CUE DeviceDiscovery Service service hung on starting.

Error: (04/23/2015 06:42:31 AM) (Source: 0) (EventID: 2000) (User: )
Description: \Device\LanmanServer

Error: (04/23/2015 06:42:31 AM) (Source: 0) (EventID: 2000) (User: )
Description: \Device\LanmanServer

Error: (04/23/2015 06:41:22 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The HP CUE DeviceDiscovery Service service hung on starting.

Error: (04/22/2015 06:19:49 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The HP CUE DeviceDiscovery Service service hung on starting.

Error: (04/21/2015 07:54:46 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The HP CUE DeviceDiscovery Service service hung on starting.

Error: (04/20/2015 08:11:23 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The HP CUE DeviceDiscovery Service service hung on starting.

Error: (04/20/2015 08:08:28 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The HP SI Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 1000 milliseconds: Restart the service.

Error: (04/20/2015 08:08:26 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Installer service terminated unexpectedly.  It has done this 1 time(s).

Error: (04/20/2015 08:08:26 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Application Layer Gateway Service service terminated unexpectedly.  It has done this 1 time(s).


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Processor:  Intel® Pentium® 4 CPU 3.00GHz
Percentage of memory in use: 36%
Total physical RAM: 2039.29 MB
Available physical RAM: 1290.68 MB
Total Pagefile: 2642.18 MB
Available Pagefile: 2111.01 MB
Total Virtual: 2047.88 MB
Available Virtual: 1938.24 MB

==================== Drives ================================

Drive h: () (Fixed) (Total:465.75 GB) (Free:207.87 GB) NTFS ==>[Drive with boot components (Windows XP)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: B829B829)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End Of Log ============================

==================== End Of Log ============================

  • Автор

H:\$RECYCLE.BIN\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\$RECYCLE.BIN\S-1-5-21-3718270677-4290495217-167408065-1000\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\128b39739a3c8290c766a9\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\54c3cb947aef816ceabdedb8f7\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\7feea7b9257e7026c75c0547bf2f4da1\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\94677e1b4707d7452aa83d9d21\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Backup\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Backup\H\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Backup\H\Documents and Settings\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Backup\H\Documents and Settings\User\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Backup\H\Documents and Settings\User\Application Data\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Backup\H\Documents and Settings\User\Application Data\Mozilla\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Backup\H\Documents and Settings\User\Application Data\Mozilla\Firefox\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Backup\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Backup\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7tfrbo8u.default-1345498643375\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Backup\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Backup\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Backup\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\boost_interprocess\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\boost_interprocess\40E7CAFC2AADCD01\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\Conduit\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\Conduit\IE\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\Conduit\IE\CT3287811\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\Conduit\IE\CT3287811\UninstallerUI.exe.vir    Win32/Toolbar.Conduit.AJ potentially unwanted application
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\ParetoLogic\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\ParetoLogic\RegCure Pro\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Communicator\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Communicator\conf\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\conf\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\conf\users\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\data\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\data\Bars\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\data\Bars\Default\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\data\Bars\Default\100\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\data\Bars\Default\200\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\data\Bars\Default\400\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\data\contentdb\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\data\packages\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\data\packages\FailDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\update\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Messenger\update\sweetimsetup.exe.vir    a variant of Win32/SweetIM.L potentially unwanted application
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Toolbars\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Toolbars\Internet Explorer\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\Application Data\SweetIM\Toolbars\Internet Explorer\cache\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\All Users\VisualBee\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\AppData\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\AppData\LocalLow\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\AppData\LocalLow\DataMngr\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\AskToolbar\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DefaultTab\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DefaultTab\defaulttab\DefaultTabBHO.dll.vir    a variant of Win32/Toolbar.DefaultTab.B potentially unwanted application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DefaultTab\defaulttab\DefaultTabStart.exe.vir    a variant of Win32/Toolbar.DefaultTab.B potentially unwanted application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DefaultTab\defaulttab\DefaultTabStart64.exe.vir    Win64/Toolbar.DefaultTab.B potentially unwanted application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DefaultTab\defaulttab\defaulttabuninstaller.exe.vir    Win32/Toolbar.DefaultTab.E potentially unwanted application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DefaultTab\defaulttab\DefaultTabWrap.dll.vir    a variant of Win32/Toolbar.DefaultTab.B potentially unwanted application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DefaultTab\defaulttab\DefaultTabWrap64.dll.vir    Win64/Toolbar.DefaultTab.B potentially unwanted application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DefaultTab\defaulttab\DTChk.exe.vir    Win32/Toolbar.DefaultTab.F potentially unwanted application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DefaultTab\defaulttab\dtupdate.exe.vir    Win32/Toolbar.DefaultTab.A potentially unwanted application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DefaultTab\defaulttab\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DefaultTab\defaulttab\uninstalldt.exe.vir    a variant of Win32/Toolbar.DefaultTab.E potentially unwanted application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DefaultTab\defaulttab\update.exe.vir    a variant of Win32/Toolbar.DefaultTab.F potentially unwanted application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\DriverCure\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\dvdvideosoftiehelpers\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\eType\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\ExpressFiles\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7tfrbo8u.default-1345498643375\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7tfrbo8u.default-1345498643375\Extensions\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7tfrbo8u.default-1345498643375\Extensions\staged\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7tfrbo8u.default-1345498643375\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7tfrbo8u.default-1345498643375\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}\chrome\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7tfrbo8u.default-1345498643375\searchplugins\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015\Extensions\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015\Extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015\Extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015\Extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\content\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}\chrome\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Conduit\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Conduit\alert\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Conduit\alert\Dialogs\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Conduit\alert\Dialogs\AppNotificationDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Conduit\alert\Dialogs\AppNotificationDialog\Images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitCommon\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitCommon\alert\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitCommon\alert\Dialogs\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitCommon\alert\Dialogs\AppNotificationDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitCommon\alert\Dialogs\AppNotificationDialog\Images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitCommon\alert\Dialogs\AppNotificationDialog\Images\dark\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitCommon\alert\Dialogs\AppNotificationDialog\Images\light\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitCommon\modules\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitCommon\modules\3.13.0.6\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\apps\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\Dialogs\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\Dialogs\AddedAppDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\Dialogs\DefualtImages\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\Dialogs\DetectedAppDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\Dialogs\EngineFirstTimeDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\Dialogs\SearchProtectorDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\Dialogs\ToolbarFirstTimeDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\Dialogs\ToolbarFirstTimeDialog\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\Dialogs\ToolbarUntrustedAppsApprovalDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\Dialogs\UntrustedAddedAppDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\Dialogs\UntrustedAppApprovalDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\ConduitEngine\Dialogs\UntrustedAppPendingDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\Dialogs\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\Dialogs\AddedAppDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\Dialogs\DefualtImages\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\Dialogs\DetectedAppDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\Dialogs\EngineFirstTimeDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\Dialogs\SearchProtectorDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\Dialogs\ToolbarFirstTimeDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\Dialogs\ToolbarFirstTimeDialog\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\Dialogs\ToolbarUntrustedAppsApprovalDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\Dialogs\UntrustedAddedAppDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\Dialogs\UntrustedAppApprovalDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\Dialogs\UntrustedAppPendingDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\externalmenu\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\MyStuffComponents\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\radio\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT2856415\weather\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\apps\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\AddedAppDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\DefualtImages\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\DetectedAppDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\EngineFirstTimeDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\NewSearchProtectorDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\NewSearchProtectorDialog\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\SearchProtectorBubbleDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\SearchProtectorBubbleDialog\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\SearchProtectorDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\SearchProtectorDialog\Images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\SearchProtectorRetakeoverDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\SearchProtectorRetakeoverDialog\Images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\ToolbarFirstTimeDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\ToolbarFirstTimeDialog\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\ToolbarUntrustedAppsApprovalDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\UntrustedAddedAppDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\UntrustedAppApprovalDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\Dialogs\UntrustedAppPendingDialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\emailnotifier\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\radio\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3131886\weather\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3196716\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\CT3196716\toolbarImages\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\components\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\defaults\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\DualPackage\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\lib\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\META-INF\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\searchplugin\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\staged\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\content\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\content\issigned.exe.vir    a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\content\NeroApplicationManager.exe.vir    a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\skin\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\temp\askToolbar.exe.vir    a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\temp\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\temp\ff-config.Fri-05-Aug-2011-20-37-03-GMT\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\temp\ff-config.Fri-10-Jun-2011-18-47-27-GMT\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\temp\ff-config.Fri-23-Sep-2011-01-22-16-GMT\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\temp\ff-config.Mon-07-Feb-2011-22-25-42-GMT\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\temp\ff-config.Sat-15-Oct-2011-21-35-04-GMT\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\temp\ff-config.Sat-26-Nov-2011-02-22-01-GMT\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\temp\ff-config.Sun-06-Feb-2011-05-06-04-GMT\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\temp\ff-config.Tue-08-Nov-2011-10-47-07-GMT\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\temp\ff-config.Tue-22-Mar-2011-01-50-34-GMT\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\chrome\temp\ff-config.Wed-01-Jun-2011-02-35-05-GMT\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\datastore\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\defaults\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\defaults\preferences\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected]\logs\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{22e03916-85c5-44b0-8dc9-1830c11238d9}\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{22e03916-85c5-44b0-8dc9-1830c11238d9}\chrome\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{22e03916-85c5-44b0-8dc9-1830c11238d9}\components\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{22e03916-85c5-44b0-8dc9-1830c11238d9}\defaults\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{22e03916-85c5-44b0-8dc9-1830c11238d9}\META-INF\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{22e03916-85c5-44b0-8dc9-1830c11238d9}\modules\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{22e03916-85c5-44b0-8dc9-1830c11238d9}\Plugins\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{22e03916-85c5-44b0-8dc9-1830c11238d9}\searchplugin\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}\chrome\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\aboutBox\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\aboutBox\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\aboutBox\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ac\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ac\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ac\img\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ac\res\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\api\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\features\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\features\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\features\js\resources\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\myStuffDialogs\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\options\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\options\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\options\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\options\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\options\js\resources\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\searchProtector\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\searchProtector\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ui\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ui\dlg\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ui\dlg\ftd\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ui\dlg\ftd\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ui\gadgetFrame\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ui\gf\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ui\gf\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ui\gf\img\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ui\menu\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ui\menu\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ui\menu\img\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\ui\menu\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\404\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\APPLICATION_BUTTON\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\APPLICATION_BUTTON\Js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\APPLICATION_BUTTON\resources\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\EMAIL_NOTIFIER\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\EMAIL_NOTIFIER\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\EMAIL_NOTIFIER\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\EMAIL_NOTIFIER\js\plugins\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\HIGHLIGHTER\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\HIGHLIGHTER\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\HIGHLIGHTER\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\MULTI_RSS\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\MULTI_RSS\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\MULTI_RSS\img\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\MULTI_RSS\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\MULTI_RSS\js\resources\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\NOTIFICATION\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\NOTIFICATION\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\NOTIFICATION\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\NOTIFICATION\images\dark\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\NOTIFICATION\images\light\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\NOTIFICATION\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\Optimizer\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\Optimizer\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\PRICE_GONG\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\PRICE_GONG\agreement\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\PRICE_GONG\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\PRICE_GONG\css\custom-theme\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\PRICE_GONG\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\PRICE_GONG\menu_dlg\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\RADIO_PLAYER\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\RADIO_PLAYER\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\RADIO_PLAYER\css\custom-theme\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\RADIO_PLAYER\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\RADIO_PLAYER\js\resources\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\SEARCH\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\SEARCH\buildSettings\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\SEARCH\Css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\SEARCH\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\SEARCH\resources\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\SEARCH\view\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\SEARCH\view\script\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\SEARCH\view\style\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\SEARCH\view\style\rsx\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\SEARCH_IN_NEW_TAB\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TESTER_BCAPI\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TESTER_BCAPI\autoTest\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TESTER_BCAPI\autoTest\lib\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TESTER_BCAPI\autoTest\spec\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TESTER_BCAPI\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TESTER_EMBEDDED\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TESTER_EMBEDDED\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TESTER_POPUP\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TESTER_POPUP\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TWITTER\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TWITTER\img\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TWITTER\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\TWITTER\resources\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\WEATHER\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\WEATHER\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\al\wa\WEATHER\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\core\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\lib\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\content\tb\sl\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\chrome\CT3196716\skin\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\defaults\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\defaults\preferences\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\lib\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\META-INF\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\modules\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}\Plugins\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\components\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\defaults\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\META-INF\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\modules\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\Plugins\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\searchplugin\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\searchplugins\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\CT3287811\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\staged\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\logic\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\logic\uninstall\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\logic\uninstall\dialog\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\logic\uninstall\dialog\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\logic\uninstall\dialog\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\logic\uninstall\dialog\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\aboutBox\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\aboutBox\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\aboutBox\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ac\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ac\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ac\img\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ac\res\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\api\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\msd\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\options\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\options\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\options\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\options\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\options\js\resources\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\sp\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\sp\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\sp\spbd\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\sp\spbd\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\sp\spsd\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\sp\spsd\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\dlg\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\dlg\ftd\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\dlg\ftd\images\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\gadgetFrame\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\gf\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\gf\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\gf\img\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\gf\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\menu\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\menu\css\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\menu\img\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\ui\menu\js\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\wa\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan
H:\AdwCleaner\Quarantine\H\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\{53c4024f-5a2e-4f2a-b33e-e8784d730938}\Chrome\CT3287811\content\tb\al\wa\APPLICATION_BUTTON\HELP_RESTORE_FILES.txt    Win32/Filecoder.EM trojan


H

 

 

Изтеглете edit-text.giffixlist.txt и го запазете в папката от която стартирахте FRST.exe.

Рестартирайте системата си в Safe Mode!
Стартирайте FRST.exe и натиснете бутона Fix веднъж!
След като приключи, ако ви поиска рестарт - съгласете се. След рестарта публикувайте лог файла - fixlog.txt, който ще се създаде след работата на програмата.
 
Внимание: Скрипта е създаден за текущата система. Да не се ползва за други системи с подобни проблеми!

  • Автор

Благодаря че все още ми помагаш.
Такаааа...пак стана нещо не както трябва.

Абе още малко и ще настигна  оная сапунка , ква беше тя ....аа Дързост и красота.

Значи в SAVE MODE не стана. Не мога да стигна до работния плот. Почва да изрежда разните си файлове стига до system32\drivers\mup или pum или нещо подобно и там запецва и не мърда. Няколко пъти го рестартирах...същата работа. Като стигне до драйвърите и запецва.

Накрая се принудих да пусна в Normal Mode...Търси около половин час файловете от фикслиста. Накрая ми даде съобщение че ги е изтрило успешно

Fixlog.zip

Странно, защото FRST е предвиден да може да работи и под Safe Mode, а аз исках там, защото очевидно нещо (може би вашата антивирусна) му пречеше да си свърши работата. :)

Както и да е. Важното е, че имаме напредък. Сега изтрийте папките C:\FRST\Quarantine и C:\adwcleaner.

След това изпразнете Recycle Bin-a и направете нова последна проверка с FRST като се уверите, че има отметка и пред Addition.txt и след това публикувайте двата лог файла. :)

  • Автор

Извинявам се за комодото, че не дочаках края на процедурата, но някои хора нямаха търпение да си ползват компа, та се принудих да го сложа за да не нахълта друг бацил.

 

 

 

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-04-2015 02
Ran by User (administrator) on PC-FB227302206B on 25-04-2015 07:32:55
Running from H:\Documents and Settings\User\My Documents\Downloads
Loaded Profiles: User (Available profiles: User & Administrator)
Platform: Microsoft Windows XP Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Comodo Security Solutions, Inc.) H:\Program Files\Common Files\COMODO\launcher_service.exe
(COMODO) H:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe
(Comodo) H:\Program Files\Comodo\Chromodo\chromodo_updater.exe
(Comodo Security Solutions, Inc.) H:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(HP) H:\WINDOWS\system32\HPSIsvc.exe
(Hewlett-Packard Company) H:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Nero AG) H:\Program Files\Nero\Update\NASvc.exe
() H:\Program Files\CDBurnerXP\NMSAccessU.exe
(Comodo Security Solutions, Inc.) H:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(COMODO) H:\Program Files\Comodo\COMODO Internet Security\CisTray.exe
(Skype Technologies S.A.) H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Comodo Security Solutions, Inc.) H:\Program Files\Comodo\GeekBuddy\unit_manager.exe
(Comodo Security Solutions, Inc.) H:\Program Files\Comodo\GeekBuddy\unit.exe
(Microsoft Corporation) H:\WINDOWS\system32\wbem\unsecapp.exe
(COMODO) H:\Program Files\Comodo\COMODO Internet Security\cis.exe
(COMODO) H:\Program Files\Comodo\COMODO Internet Security\cavwp.exe
(COMODO) H:\Program Files\Comodo\COMODO Internet Security\cmdvirth.exe
(Comodo Security Solutions, Inc.) H:\Program Files\Common Files\COMODO\launcher_service.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [COMODO Internet Security] => H:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1359064 2015-04-01] (COMODO)
HKLM\...\Run: [MSConfig] => H:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [169984 2008-04-14] (Microsoft Corporation)
Winlogon\Notify\igfxcui: H:\WINDOWS\system32\igfxsrvc.dll [2004-11-02] (Intel Corporation)
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: E - E:\Install.exe
HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\MountPoints2: {9eea6e54-11aa-11e2-ac0d-28107bbdacc7} - E:\KODAK_Software_Downloader.exe
HKU\S-1-5-18\...\RunOnce: [RunNarrator] => H:\WINDOWS\system32\Narrator.exe [53760 2008-04-14] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> H:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-20] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> H:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-20] (Oracle Corporation)
BHO: BHO_TIMELINEREMOVE.Bho -> {e7b9b609-19ad-40a4-a288-b300a3087465} -> H:\WINDOWS\system32\mscoree.dll [2010-03-18] (Microsoft Corporation)
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289583241062
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - H:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\itlpmt2j.default-1382884611015
FF SelectedSearchEngine: Yahoo!
FF Homepage: https://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> H:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-20] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> H:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> H:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-20] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> h:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: Adobe Reader -> H:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1614895754-1645522239-1417001333-1003: @Skype Limited.com/Facebook Video Calling Plugin -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll [2012-10-12] (Skype Limited)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2012-01-12] (BitComet)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: H:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\google-dictionary-english-french.xml [2012-08-28]
FF SearchPlugin: H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\searchplugins\wikipedia-franais-et-anglais.xml [2012-08-28]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\911bg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\pe-bg.xml [2015-04-15]
FF SearchPlugin: H:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml [2015-04-15]
FF Extension: United States English Spellchecker - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-05-19]
FF Extension: Dictionnaire français «Moderne» - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\[email protected] [2012-01-08]
FF Extension: TimeLineRemove.Com - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-19]
FF Extension: Microsoft .NET Framework Assistant - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\rzhxznhq.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-11-14]
FF Extension: No Name - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xiu0mynf.default-1345511166140\Extensions\jid0-YxzrUsJ0WOiOaU89TngAzLcIs18@jetpack [2012-08-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2015-04-20]
FF Extension: No Name - H:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-11-12]

Chrome:
=======
CHR Profile: H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Gmail) - H:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-12]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U4 CCALib8; H:\Program Files\Canon\CAL\CALMAIN.exe [96341 2006-03-30] (Canon Inc.) [File not signed]
U2 ChromodoUpdater; H:\Program Files\Comodo\Chromodo\chromodo_updater.exe [2306248 2015-03-26] (Comodo)
R2 CLPSLauncher; H:\Program Files\Common Files\COMODO\launcher_service.exe [70864 2014-09-17] (Comodo Security Solutions, Inc.)
U2 CmdAgent; H:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [4351816 2015-04-01] (COMODO)
U3 cmdvirth; H:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [1664728 2015-04-01] (COMODO)
U2 GeekBuddyRSP; H:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-09-17] (Comodo Security Solutions, Inc.)
U3 hpqcxs08; H:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
U2 hpqddsvc; H:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
U2 LightScribeService; H:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-08-16] (Hewlett-Packard Company) [File not signed]
U2 NAUpdate; H:\Program Files\Nero\Update\NASvc.exe [573224 2011-01-26] (Nero AG)
U2 Net Driver HPZ12; H:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
U2 NMSAccess; H:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] ()
U2 Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
U2 Skype C2C Service; H:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
U2 WLSVC; H:\Program Files\D-Link\DWA-130 revE\WLSVC.exe [167936 2009-02-11] () [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U2 AegisP; H:\WINDOWS\System32\DRIVERS\AegisP.sys [21361 2012-07-08] (Cisco Systems, Inc.) [File not signed]
U3 CCDECODE; H:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
U1 cmderd; H:\WINDOWS\System32\DRIVERS\cmderd.sys [15576 2015-04-01] (COMODO)
U1 cmdGuard; H:\WINDOWS\System32\DRIVERS\cmdguard.sys [627032 2015-04-01] (COMODO)
U1 cmdHlp; H:\WINDOWS\System32\DRIVERS\cmdhlp.sys [29912 2015-04-01] (COMODO)
U3 HPZid412; H:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
U3 HPZipr12; H:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
U3 HPZius12; H:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
U0 Inspect; H:\WINDOWS\System32\DRIVERS\inspect.sys [105688 2015-04-01] (COMODO)
U3 NdisIP; H:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
U3 rt2870; H:\WINDOWS\System32\DRIVERS\Drt2870.sys [829152 2010-05-06] (Ralink Technology, Corp.)
U3 rtl8139; H:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-13] (Realtek Semiconductor Corporation)
U2 StarOpen; H:\WINDOWS\system32\Drivers\StarOpen.sys [5504 2009-11-12] () [File not signed]
U2 WLNdis50; H:\WINDOWS\System32\DRIVERS\wlndis50.sys [20480 2008-02-27] () [File not signed]
U1 WS2IFSL; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-24 20:44 - 2015-04-24 20:44 - 00036608 _____ () H:\Documents and Settings\User\Desktop\Fixlog.zip
2015-04-24 18:46 - 2015-04-25 07:32 - 00413392 _____ () H:\WINDOWS\system32\Drivers\fvstore.dat
2015-04-24 18:46 - 2015-04-24 18:46 - 00000000 ___HD () H:\VTRoot
2015-04-24 17:37 - 2015-04-24 17:37 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\COMODO
2015-04-24 17:32 - 2015-04-24 17:37 - 00024328 _____ (COMODO CA Limited) H:\WINDOWS\system32\certsentry.dll
2015-04-24 17:32 - 2015-04-24 17:37 - 00024296 _____ (COMODO CA Limited) H:\WINDOWS\system32\certsentry.exe
2015-04-24 17:32 - 2015-04-24 17:37 - 00000266 _____ () H:\WINDOWS\Tasks\COMODO CertSentry Updater.job
2015-04-24 17:31 - 2015-04-25 07:24 - 00000440 _____ () H:\WINDOWS\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job
2015-04-24 17:31 - 2015-04-25 07:05 - 00000440 _____ () H:\WINDOWS\Tasks\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9}.job
2015-04-24 17:31 - 2015-04-25 06:55 - 00000440 _____ () H:\WINDOWS\Tasks\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}.job
2015-04-24 17:31 - 2015-04-25 06:47 - 00000440 _____ () H:\WINDOWS\Tasks\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22}.job
2015-04-24 17:29 - 2015-04-25 07:27 - 00201345 _____ () H:\WINDOWS\system32\Drivers\sfi.dat
2015-04-24 17:24 - 2015-04-24 17:24 - 00001679 _____ () H:\Documents and Settings\All Users\Desktop\COMODO Antivirus.lnk
2015-04-24 17:23 - 2015-04-24 17:23 - 00065536 _____ () H:\WINDOWS\system32\config\COMODO I.evt
2015-04-24 17:23 - 2015-04-24 17:23 - 00001780 _____ () H:\Documents and Settings\All Users\Desktop\GeekBuddy.lnk
2015-04-24 17:23 - 2015-04-24 17:23 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Shared Space
2015-04-24 17:22 - 2015-04-24 17:32 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\COMODO
2015-04-24 17:22 - 2015-04-24 17:31 - 00000000 ____D () H:\Program Files\Comodo
2015-04-24 17:22 - 2015-04-24 17:24 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Comodo
2015-04-24 17:22 - 2015-04-24 17:22 - 00000775 _____ () H:\Documents and Settings\All Users\Desktop\Internet (Chromodo).lnk
2015-04-24 17:22 - 2015-04-24 17:22 - 00000000 ____D () H:\Program Files\Common Files\COMODO
2015-04-24 17:21 - 2015-04-24 17:21 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Comodo Downloader
2015-04-24 17:18 - 2015-04-24 17:31 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Comodo
2015-04-24 10:22 - 2015-04-24 10:22 - 00000000 ____D () H:\Program Files\ESET
2015-04-24 10:16 - 2015-04-24 10:17 - 00034679 _____ () H:\Documents and Settings\User\Desktop\FRST.txt
2015-04-24 10:15 - 2015-04-25 06:54 - 00000000 ____D () H:\FRST
2015-04-21 18:51 - 2015-04-21 20:22 - 00000000 ____D () H:\Documents and Settings\User\Desktop\nik
2015-04-20 21:13 - 2015-04-20 21:13 - 00000104 _____ () H:\Documents and Settings\User\Desktop\Internet.lnk
2015-04-20 20:00 - 2015-04-20 20:00 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Sun
2015-04-20 19:49 - 2015-04-20 19:49 - 00000724 _____ () H:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
2015-04-20 19:26 - 2015-04-20 19:27 - 00031668 _____ () H:\Addition.txt
2015-04-20 18:21 - 2015-04-20 19:40 - 00119512 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-04-20 18:21 - 2015-04-20 18:21 - 00000777 _____ () H:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-20 18:21 - 2015-04-14 09:37 - 00120024 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-04-20 18:21 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) H:\WINDOWS\system32\Drivers\mbam.sys
2015-04-20 18:17 - 2015-04-20 18:17 - 21546080 _____ (Malwarebytes Corporation ) H:\mbam-setup-consumer-2.1.6.1022.exe
2015-04-20 17:55 - 2015-04-24 18:57 - 00000000 ____D () H:\Program Files\Mozilla Firefox
2015-04-20 17:55 - 2015-04-21 20:17 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 5 - Историография - Ново време
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Program Files\Common Files\Skype
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 4 - Историография - Праистория и Античност
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 2 - Историография - Средновековие
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Исторически книги на български. Част 1 - Източници и изворознание
2015-04-20 17:55 - 2015-04-20 17:55 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\snow queen tous
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\end2
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9outs
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9 end
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\9
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\29r
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2 outs
2015-04-20 16:49 - 2015-04-20 17:47 - 00000000 ____D () H:\Program Files\ShadowExplorer
2015-04-20 16:49 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ShadowExplorer
2015-04-18 23:18 - 2015-04-18 23:18 - 00008536 _____ () H:\Documents and Settings\Administrator\Desktop\mb scan.txt
2015-04-18 21:49 - 2015-04-20 18:21 - 00000000 ____D () H:\Program Files\Malwarebytes Anti-Malware
2015-04-18 21:30 - 2015-04-18 21:41 - 00003572 _____ () H:\Documents and Settings\Administrator\Desktop\Rkill.txt
2015-04-18 21:21 - 2015-04-20 17:47 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Mozilla
2015-04-18 21:21 - 2015-04-18 21:21 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Macromedia
2015-04-18 21:18 - 2015-04-18 21:18 - 00000000 ____D () H:\Documents and Settings\Administrator\Application Data\Adobe
2015-04-18 19:50 - 2015-04-18 23:16 - 00001324 _____ () H:\WINDOWS\system32\d3d9caps.dat
2015-04-04 01:57 - 2015-04-04 02:02 - 00000000 ____D () H:\Documents and Settings\User\My Documents\Attestation123
2015-04-03 14:06 - 2015-04-03 14:06 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\Hewlett-Packard
2015-04-01 18:48 - 2015-04-01 18:48 - 00627032 _____ (COMODO) H:\WINDOWS\system32\Drivers\cmdGuard.sys
2015-04-01 18:48 - 2015-04-01 18:48 - 00444472 _____ (COMODO) H:\WINDOWS\system32\guard32.dll
2015-04-01 18:48 - 2015-04-01 18:48 - 00105688 _____ (COMODO) H:\WINDOWS\system32\Drivers\inspect.sys
2015-04-01 18:48 - 2015-04-01 18:48 - 00033520 _____ (COMODO) H:\WINDOWS\system32\cmdcsr.dll
2015-04-01 18:48 - 2015-04-01 18:48 - 00029912 _____ (COMODO) H:\WINDOWS\system32\Drivers\cmdhlp.sys
2015-04-01 18:48 - 2015-04-01 18:48 - 00015576 _____ (COMODO) H:\WINDOWS\system32\Drivers\cmderd.sys
2015-04-01 18:45 - 2015-04-01 18:45 - 00288472 _____ (COMODO) H:\WINDOWS\system32\cmdvrt32.dll
2015-04-01 18:45 - 2015-04-01 18:45 - 00040664 _____ (COMODO) H:\WINDOWS\system32\cmdkbd32.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-25 06:52 - 2010-11-14 18:34 - 00000000 ____D () H:\WINDOWS\pss
2015-04-25 06:52 - 2001-08-23 08:00 - 00000630 _____ () H:\WINDOWS\win.ini
2015-04-25 06:52 - 2001-08-23 08:00 - 00000227 _____ () H:\WINDOWS\system.ini
2015-04-25 06:47 - 2010-11-12 13:18 - 01961264 _____ () H:\WINDOWS\WindowsUpdate.log
2015-04-25 06:47 - 2001-08-23 08:00 - 00002206 _____ () H:\WINDOWS\system32\wpa.dbl
2015-04-25 06:46 - 2010-11-12 13:32 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Temp
2015-04-25 06:46 - 2010-11-12 13:31 - 00000006 ____H () H:\WINDOWS\Tasks\SA.DAT
2015-04-25 06:46 - 2010-11-12 08:08 - 00000300 _____ () H:\WINDOWS\wiadebug.log
2015-04-25 06:46 - 2010-11-12 08:08 - 00000052 _____ () H:\WINDOWS\wiaservc.log
2015-04-24 23:57 - 2012-06-30 23:39 - 00001148 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003UA.job
2015-04-24 23:33 - 2010-11-12 13:31 - 00032570 _____ () H:\WINDOWS\SchedLgU.Txt
2015-04-24 21:10 - 2013-10-27 02:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\moda
2015-04-24 20:21 - 2012-03-27 18:21 - 00000000 ____D () H:\Program Files\cd dvd burner11
2015-04-24 20:21 - 2010-11-12 21:43 - 00000000 ____D () H:\Documents and Settings\User\My Documents\programi
2015-04-24 20:21 - 2010-11-12 13:32 - 00000178 ___SH () H:\Documents and Settings\User\ntuser.ini
2015-04-24 20:19 - 2014-09-27 18:29 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-27
2015-04-24 20:19 - 2014-09-27 00:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\Jardine bothanique
2015-04-24 20:19 - 2014-09-18 22:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-18
2015-04-24 20:19 - 2014-09-08 19:47 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-08
2015-04-24 20:19 - 2014-09-02 22:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-09-02
2015-04-24 20:19 - 2014-08-31 00:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-31
2015-04-24 20:19 - 2014-08-28 20:43 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-08-28
2015-04-24 20:19 - 2014-07-27 00:13 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-27
2015-04-24 20:19 - 2014-07-13 19:22 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-07-13
2015-04-24 20:19 - 2014-05-20 13:45 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2014-05-20
2015-04-24 20:19 - 2013-11-30 17:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\disain
2015-04-24 20:19 - 2013-10-27 02:05 - 00000000 ____D () H:\Documents and Settings\User\Desktop\krasivo
2015-04-24 20:19 - 2013-05-28 07:26 - 00000000 ____D () H:\Documents and Settings\User\Desktop\inter
2015-04-24 20:17 - 2011-01-16 21:24 - 00000000 ____D () H:\bb6fadc9d2f25f3b2953e5d2
2015-04-24 18:57 - 2015-02-23 22:59 - 00000000 ____D () H:\Documents and Settings\User\Desktop\hyde
2015-04-24 18:57 - 2015-02-23 20:21 - 00000000 ____D () H:\Documents and Settings\User\Desktop\b est of me
2015-04-24 18:57 - 2015-02-23 20:18 - 00000000 ____D () H:\Documents and Settings\User\Desktop\New Folder(2)
2015-04-24 18:57 - 2015-02-23 20:16 - 00000000 ____D () H:\Documents and Settings\User\Desktop\j789
2015-04-24 18:57 - 2015-02-23 20:16 - 00000000 ____D () H:\Documents and Settings\User\Desktop\j456
2015-04-24 18:57 - 2015-02-23 20:14 - 00000000 ____D () H:\Documents and Settings\User\Desktop\New Folder
2015-04-24 18:57 - 2015-01-24 14:35 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Skype(2)
2015-04-24 18:57 - 2015-01-08 21:35 - 00000000 ____D () H:\Documents and Settings\User\Desktop\2
2015-04-24 18:57 - 2015-01-08 21:12 - 00000000 ____D () H:\Documents and Settings\User\Desktop\blue
2015-04-24 18:57 - 2015-01-07 20:37 - 00000000 ____D () H:\Documents and Settings\User\Desktop\hidden moon
2015-04-24 18:57 - 2015-01-05 23:09 - 00000000 ____D () H:\Documents and Settings\User\Desktop\fi123
2015-04-24 18:57 - 2015-01-05 23:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\fi1
2015-04-24 18:57 - 2014-10-24 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Java
2015-04-24 18:57 - 2014-04-26 11:43 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\JustVoip
2015-04-24 18:57 - 2014-03-30 13:07 - 00000000 ____D () H:\Documents and Settings\User\Desktop\18
2015-04-24 18:57 - 2013-12-07 23:22 - 00000000 __SHD () H:\Documents and Settings\Administrator\IETldCache
2015-04-24 18:57 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft Help
2015-04-24 18:57 - 2013-02-16 10:31 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\ooVoo
2015-04-24 18:57 - 2013-01-08 20:32 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
2015-04-24 18:57 - 2012-11-11 03:32 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\bdch
2015-04-24 18:57 - 2012-11-07 00:51 - 00000000 ____D () H:\Documents and Settings\LocalService\Application Data\QuickScan
2015-04-24 18:57 - 2012-08-10 15:44 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\bdch
2015-04-24 18:57 - 2012-07-08 00:07 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\D-Link
2015-04-24 18:57 - 2012-06-27 17:08 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
2015-04-24 18:57 - 2012-06-19 18:28 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\TechSmith
2015-04-24 18:57 - 2012-02-28 14:22 - 00000000 ____D () H:\54c3cb947aef816ceabdedb8f7
2015-04-24 18:57 - 2012-02-17 06:40 - 00000000 __SHD () H:\Documents and Settings\NetworkService\IETldCache
2015-04-24 18:57 - 2012-02-11 14:34 - 00000000 ____D () H:\128b39739a3c8290c766a9
2015-04-24 18:57 - 2012-02-06 22:14 - 00000000 ____D () H:\7feea7b9257e7026c75c0547bf2f4da1
2015-04-24 18:57 - 2012-02-01 15:45 - 00000000 ____D () H:\94677e1b4707d7452aa83d9d21
2015-04-24 18:57 - 2011-12-19 00:57 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft Help
2015-04-24 18:57 - 2011-12-18 18:15 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
2015-04-24 18:57 - 2011-12-17 19:54 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\DVDVideoSoft
2015-04-24 18:57 - 2011-10-16 20:17 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
2015-04-24 18:57 - 2011-05-17 16:09 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Keyboard
2015-04-24 18:57 - 2011-02-07 22:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
2015-04-24 18:57 - 2011-02-06 00:33 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
2015-04-24 18:57 - 2011-01-16 21:39 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\Nero
2015-04-24 18:57 - 2010-12-01 20:18 - 00000000 ___SD () H:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 3.1
2015-04-24 18:57 - 2010-11-25 17:10 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\HP
2015-04-24 18:57 - 2010-11-15 22:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\LightScribe Direct Disc Labeling
2015-04-24 18:57 - 2010-11-13 00:57 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
2015-04-24 18:57 - 2010-11-13 00:52 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Application Data\Google
2015-04-24 18:57 - 2010-11-12 23:38 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\AVS4YOU
2015-04-24 18:57 - 2010-11-12 22:16 - 00000000 ____D () H:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
2015-04-24 18:57 - 2010-11-12 21:42 - 00000000 __SHD () H:\Documents and Settings\LocalService\IETldCache
2015-04-24 18:57 - 2010-11-12 13:31 - 00000000 __SHD () H:\Documents and Settings\LocalService
2015-04-24 18:57 - 2010-11-12 13:28 - 00000000 __SHD () H:\Documents and Settings\NetworkService
2015-04-24 18:57 - 2010-11-12 13:18 - 00000000 __SHD () H:\Documents and Settings\All Users\DRM
2015-04-24 18:57 - 2010-11-12 13:18 - 00000000 ___RD () H:\Documents and Settings\Default User\Start Menu\Programs\Accessories
2015-04-24 18:57 - 2010-11-12 13:16 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Games
2015-04-24 18:57 - 2010-11-12 02:18 - 00000000 ____D () H:\d688a5c03ea38202645f5bc01eeb02
2015-04-24 17:57 - 2012-06-30 23:39 - 00001126 _____ () H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003Core.job
2015-04-24 14:04 - 2014-06-11 17:06 - 00000000 ____D () H:\Documents and Settings\User\Desktop\s.q.3.4
2015-04-24 07:25 - 2010-11-12 13:31 - 00000000 ____D () H:\Documents and Settings\LocalService\Local Settings\Temp
2015-04-23 19:21 - 2013-12-07 23:22 - 00000000 ___RD () H:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
2015-04-23 19:21 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator
2015-04-23 19:19 - 2010-11-12 13:14 - 00000000 ___RD () H:\Documents and Settings\All Users\Start Menu\Programs\Accessories
2015-04-23 16:39 - 2013-10-26 17:49 - 00000000 ____D () H:\Documents and Settings\User\My Documents\AS-CV
2015-04-23 06:57 - 2013-12-07 23:22 - 00000000 ____D () H:\Documents and Settings\Administrator\Local Settings\Temp
2015-04-23 06:53 - 2010-11-12 13:28 - 00000000 ____D () H:\Documents and Settings\NetworkService\Local Settings\Temp
2015-04-23 06:52 - 2010-11-12 08:04 - 00000000 ____D () H:\Documents and Settings\Default User\Local Settings\Temp
2015-04-23 06:42 - 2013-10-26 16:34 - 00278076 _____ () H:\WINDOWS\setupapi.log
2015-04-21 20:23 - 2012-05-14 19:46 - 00002465 _____ () H:\Documents and Settings\All Users\Desktop\Nero StartSmart 10.lnk
2015-04-21 18:51 - 2014-02-15 20:44 - 00000000 ____D () H:\Documents and Settings\User\Desktop\sub.vvv
2015-04-21 07:54 - 2012-02-11 11:47 - 00002265 _____ () H:\Documents and Settings\All Users\Desktop\Skype.lnk
2015-04-21 07:54 - 2010-11-13 00:51 - 00000000 ____D () H:\Documents and Settings\User\Application Data\Skype
2015-04-20 20:04 - 2010-11-18 19:35 - 00000000 ____D () H:\Documents and Settings\User\Local Settings\Application Data\Adobe
2015-04-20 20:03 - 2012-04-18 22:24 - 00778416 _____ (Adobe Systems Incorporated) H:\WINDOWS\system32\FlashPlayerApp.exe
2015-04-20 20:03 - 2011-08-26 22:30 - 00142512 _____ (Adobe Systems Incorporated) H:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-04-20 20:00 - 2012-02-18 21:41 - 00000000 ____D () H:\Program Files\Java
2015-04-20 19:59 - 2014-10-24 10:30 - 00000000 ____D () H:\Documents and Settings\All Users\Application Data\Oracle
2015-04-20 19:57 - 2013-03-23 10:04 - 00096680 _____ (Oracle Corporation) H:\WINDOWS\system32\WindowsAccessBridge.dll
2015-04-20 19:57 - 2012-02-18 21:41 - 00146432 _____ (Oracle Corporation) H:\WINDOWS\system32\javacpl.cpl
2015-04-20 19:19 - 2012-10-01 06:03 - 00073960 _____ () H:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2015-04-20 19:13 - 2013-10-09 06:27 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2862335$
2015-04-20 18:12 - 2010-11-12 08:04 - 00615742 _____ () H:\WINDOWS\system32\PerfStringBackup.INI
2015-04-20 18:00 - 2013-10-26 16:35 - 00000986 _____ () H:\WINDOWS\setupact.log
2015-04-20 17:57 - 2010-11-12 08:03 - 00286904 _____ () H:\WINDOWS\system32\FNTCACHE.DAT
2015-04-20 17:56 - 2010-11-12 13:16 - 00000000 ____D () H:\WINDOWS\Registration
2015-04-20 17:55 - 2013-01-08 20:29 - 00000000 ____D () H:\Documents and Settings\User\Application Data\BitTorrent
2015-04-20 17:55 - 2012-09-18 23:37 - 00000000 ___RD () H:\Program Files\Skype
2015-04-20 17:55 - 2012-05-03 16:07 - 00000000 ____D () H:\Program Files\Mozilla Maintenance Service
2015-04-20 17:52 - 2013-07-15 23:21 - 00000000 ____D () H:\WINDOWS\system32\MRT
2015-04-20 17:06 - 2013-11-23 04:02 - 00519776 _____ () H:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2015-04-20 17:06 - 2010-11-12 13:17 - 00000000 ____D () H:\WINDOWS\system32\Restore
2015-04-19 00:18 - 2014-06-08 20:04 - 00000000 ____D () H:\Documents and Settings\User\My Documents\sub1
2015-04-18 23:20 - 2011-11-11 00:38 - 00000000 __HDC () H:\WINDOWS\$NtUninstallKB2641690$
2015-04-17 23:45 - 2014-01-11 01:48 - 00000000 ____D () H:\Documents and Settings\User\My Documents\subtitle
2015-04-05 15:36 - 2014-06-08 18:50 - 00000000 ____D () H:\Documents and Settings\User\Desktop\l5678
2015-04-05 12:31 - 2012-06-15 14:53 - 00270848 ___SH () H:\Documents and Settings\User\Desktop\Thumbs.db
2015-04-03 15:46 - 2012-06-17 20:14 - 00000000 ____D () H:\Documents and Settings\User\My Documents\attestation

==================== Files in the root of some directories =======

2010-11-12 22:29 - 2015-01-14 18:38 - 0088064 _____ () H:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

H:\WINDOWS\explorer.exe => File is digitally signed
H:\WINDOWS\system32\winlogon.exe => File is digitally signed
H:\WINDOWS\system32\svchost.exe => File is digitally signed
H:\WINDOWS\system32\services.exe => File is digitally signed
H:\WINDOWS\system32\User32.dll => File is digitally signed
H:\WINDOWS\system32\userinit.exe => File is digitally signed
H:\WINDOWS\system32\rpcss.dll => File is digitally signed
H:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-04-2015 02
Ran by User at 2015-04-25 07:34:58
Running from H:\Documents and Settings\User\My Documents\Downloads
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1614895754-1645522239-1417001333-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
ASPNET (S-1-5-21-1614895754-1645522239-1417001333-1004 - Limited - Enabled)
Guest (S-1-5-21-1614895754-1645522239-1417001333-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-1614895754-1645522239-1417001333-1000 - Limited - Disabled)
SUPPORT_388945a0 (S-1-5-21-1614895754-1645522239-1417001333-1002 - Limited - Disabled)
User (S-1-5-21-1614895754-1645522239-1417001333-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\User

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)


==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

32 Bit HP CIO Components Installer (Version: 1.0.0 - Hewlett-Packard) Hidden
7-Zip 9.21 (HKLM\...\{23170F69-40C1-2701-0921-000001000000}) (Version: 9.21.00.0 - Igor Pavlov)
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.223 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) - Français (HKLM\...\{AC76BA86-7AD7-1036-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\Akamai) (Version:  - Akamai Technologies, Inc)
AVS Video Converter 6 (HKLM\...\AVS4YOU Video Converter 6_is1) (Version:  - Online Media Technologies Ltd.)
AVS4YOU Software Navigator 1.3 (HKLM\...\AVS4YOU Software Navigator_is1) (Version:  - Online Media Technologies Ltd.)
BitLord 1.1 (HKLM\...\BitLord) (Version: 1.1 - www.bitlord.com)
BitTorrent (HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\...\BitTorrent) (Version: 7.9.2.34312 - BitTorrent Inc.)
BSPlayer (HKLM\...\BSPlayer1) (Version:  - )
BufferChm (Version: 100.0.170.000 - Hewlett-Packard) Hidden
Canon Camera Access Library (HKLM\...\CAL) (Version: 8.3.0.1 - )
Canon Camera Support Core Library (HKLM\...\CSCLIB) (Version: 7.3.1.6 - )
Canon Camera Window DC_DV 5 for ZoomBrowser EX (HKLM\...\CameraWindowDVC5) (Version: 5.4.5.17 - )
Canon Camera Window DC_DV 6 for ZoomBrowser EX (HKLM\...\CameraWindowDVC6) (Version: 6.4.0.9 - )
Canon Camera Window MC 6 for ZoomBrowser EX (HKLM\...\CameraWindowMC) (Version: 6.3.0.8 - )
Canon G.726 WMP-Decoder (HKLM\...\Canon G.726 WMP-Decoder) (Version: 1.1.0.4 - )
Canon MovieEdit Task for ZoomBrowser EX (HKLM\...\MovieEditTask) (Version: 2.4.0.14 - )
Canon RAW Image Task for ZoomBrowser EX (HKLM\...\RAW Image Task) (Version: 2.5.0.8 - )
Canon RemoteCapture Task for ZoomBrowser EX (HKLM\...\RemoteCaptureTask) (Version: 1.7.0.8 - )
Canon Utilities EOS Utility (HKLM\...\EOS Utility) (Version: 1.1.0.8 - )
Canon Utilities PhotoStitch (HKLM\...\PhotoStitch) (Version: 3.1.19.43 - )
Canon Utilities ZoomBrowser EX (HKLM\...\ZoomBrowser EX) (Version: 5.8.0.74 - )
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.0.2838 - CDBurnerXP)
Chromodo (HKLM\...\Chromodo) (Version: 36.7.0.8 - Comodo)
COMODO Antivirus (HKLM\...\{73830292-868E-4C82-9AF5-CCFE2047B6A3}) (Version: 8.2.0.4508 - COMODO Security Solutions Inc.)
Copy (Version: 100.0.170.000 - Hewlett-Packard) Hidden
CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Data Fax SoftModem with SmartCP (HKLM\...\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1) (Version:  - )
Destination Component (Version: 100.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (Version: 100.0.190.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
DJ_AIO_03_F4200_ProductContext (Version: 100.0.215.000 - Hewlett-Packard) Hidden
DJ_AIO_03_F4200_Software (Version: 100.0.206.000 - Hewlett-Packard) Hidden
DJ_AIO_03_F4200_Software_Min (Version: 100.0.213.000 - Hewlett-Packard) Hidden
D-Link DWA-130 Wireless N USB Adapter (HKLM\...\{6F6F39E3-D24D-4EEE-9AEA-DEDAF991385D}) (Version:  - D-Link)
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version:  - )
eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
F4200 (Version: 100.0.206.000 - Hewlett-Packard) Hidden
F4200_Help (Version: 100.0.206.000 - Hewlett-Packard) Hidden
Facebook Video Calling 1.2.0.287 (HKLM\...\{B92C5909-1D37-4C51-8397-A28BB28E5DC3}) (Version: 1.2.287 - Skype Limited)
GeekBuddy (HKLM\...\{D456E320-F256-4FBB-B73A-B617BFC77DEA}) (Version: 4.13.120 - Comodo Security Solutions Inc)
GPBaseService (Version: 100.0.187.000 - Hewlett-Packard) Hidden
High-Definition Video Playback (Version: 7.1.13400.42.0 - Nero AG) Hidden
HP Customer Participation Program 10.0 (HKLM\...\HPExtendedCapabilities) (Version: 10.0 - HP)
HP Deskjet F4200 All-In-One Driver Software 10.0 Rel .3 (HKLM\...\{AE9A67F9-ADF1-4a44-BAB5-C1DB302B37A2}) (Version: 10.0 - HP)
HP Imaging Device Functions 10.0 (HKLM\...\HP Imaging Device Functions) (Version: 10.0 - HP)
HP LaserJet Professional P1100-P1560-P1600 Series (HKLM\...\HP LaserJet Professional P1100-P1560-P1600 Series) (Version:  - )
HP Photosmart Essential 2.5 (HKLM\...\HP Photosmart Essential) (Version: 2.5 - HP)
HP Smart Web Printing (HKLM\...\HP Smart Web Printing) (Version: 3.5 - HP)
HP Solution Center 10.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 10.0 - HP)
HP Update (HKLM\...\{11B83AD3-7A46-4C2E-A568-9505981D4C6F}) (Version: 4.000.007.003 - Hewlett-Packard)
HPProductAssistant (Version: 100.0.170.000 - Hewlett-Packard) Hidden
ImagXpress (Version: 7.0.74.0 - Nero AG) Hidden
Intel® Graphics Media Accelerator Driver (HKLM\...\{8A708DD8-A5E6-11D4-A706-000629E95E20}) (Version:  - )
Java 8 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
JavaFX 2.1.1 (HKLM\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Jing (HKLM\...\{7AB01508-C2B2-43C8-8B44-514801E7CCC9}) (Version: 2.6.12032.1 - TechSmith Corporation)
JustVoip (HKLM\...\JustVoip_is1) (Version: 4.12 build 704 - Finarea S.A. Switzerland)
K-Lite Codec Pack 4.1.7 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 4.1.7 - )
Korean Fonts Support For Adobe Reader X (HKLM\...\{AC76BA86-7AD7-5670-0000-A00000000003}) (Version: 10.0.0 - Adobe Systems Incorporated)
LightScribe System Software (HKLM\...\{705B639E-FAAF-40D7-AD58-C445321C7C3F}) (Version: 1.18.18.1 - LightScribe)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MarketResearch (Version: 100.0.170.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version:  - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30730 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Base Smart Card Cryptographic Service Provider Package (HKLM\...\KB909520) (Version:  - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft IntelliType Pro 6.2 (HKLM\...\{345112D9-0930-4A68-AB71-A831BA5DE7AA}) (Version: 6.20.182.0 - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (HKLM\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version:  - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 37.0.2 (x86 bg) (HKLM\...\Mozilla Firefox 37.0.2 (x86 bg)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 32.0.3 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero BurnLite 10 (HKLM\...\{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}) (Version: 10.0.10600 - Nero AG)
Nero BurnLite 10 (HKLM\...\{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}) (Version: 10.0.10500.5.100 - Nero AG)
Nero BurnRights 10 (HKLM\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.0.11300.14.100 - Nero AG)
Nero CoverDesigner 10 (HKLM\...\{FCF00A6E-FB58-477A-ABE9-232907105521}) (Version: 5.0.11200.16.100 - Nero AG)
Nero DiscSpeed 10 (HKLM\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.0.11400.18.100 - Nero AG)
Nero Express 10 (HKLM\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.0.12300.23.100 - Nero AG)
Nero InfoTool 10 (HKLM\...\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.0.11400.15.100 - Nero AG)
Nero MediaHub 10 (HKLM\...\{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}) (Version: 1.0.14800.28.100 - Nero AG)
Nero Multimedia Suite 10 (HKLM\...\{277C1559-4CF7-44FF-8D07-98AA9C13AABD}) (Version: 10.5.10500 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM\...\{7D0A13FA-56BC-4755-8BAF-45A69BA6A5C8}) (Version: 10.0.10300 - Nero AG)
Nero StartSmart 10 (HKLM\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.0.12600.30.100 - Nero AG)
Nero Update (HKLM\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.10400.26.0 - Nero AG)
NetZero Internet and Voice Offer (HKLM\...\{8BBA35B6-E1A9-4FE0-892B-8F7980584D52}) (Version: 2.0 - )
ooVoo (HKLM\...\{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}) (Version: 3.5.6046 - ooVoo LLC.)
OpenOffice.org 3.1 (HKLM\...\{E6B87DC4-2B3D-4483-ADFF-E483BF718991}) (Version: 3.1.9399 - OpenOffice.org)
PDFConverter Desktop (HKLM\...\PDFConverter Desktop_is1) (Version:  - Baltsoft Software)
PSSWCORE (Version: 2.02.0000 - Hewlett-Packard) Hidden
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version:  - )
SA Dictionary 2008 Beta 4 (HKLM\...\{055A5AF0-9FEB-440D-B00A-18935C7C171C}) (Version: 6.6.12 - Stefan Angelov)
Scan (Version: 10.0.0.0 - Hewlett-Packard) Hidden
Skype Click to Call (HKLM\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
Skype™ 6.14 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
SmartWebPrintingOC (Version: 100.0.189.000 - Hewlett-Packard) Hidden
SolutionCenter (Version: 100.0.175.000 - Hewlett-Packard) Hidden
Status (Version: 100.0.175.000 - Hewlett-Packard) Hidden
TimeLineRemove 0.9 (HKLM\...\TimeLineRemove_is1) (Version: 0.9 - TimeLineRemove)
Toolbox (Version: 100.0.170.000 - Hewlett-Packard) Hidden
TrayApp (Version: 100.0.170.000 - Hewlett-Packard) Hidden
UnloadSupport (Version: 10.0.0 - Hewlett-Packard) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VideoToolkit01 (Version: 100.0.128.000 - Hewlett-Packard) Hidden
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
WebReg (Version: 100.0.170.000 - Hewlett-Packard) Hidden
Windows Genuine Advantage Notifications (KB905474) (HKLM\...\WgaNotify) (Version: 1.9.0040.0 - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version:  - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Management Framework Core (HKLM\...\KB968930) (Version:  - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version:  - )
Windows Media Player 11 (HKLM\...\Windows Media Player) (Version:  - )
WinRAR archiver (HKLM\...\WinRAR archiver) (Version:  - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-1645522239-1417001333-1003_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

==================== Restore Points  =========================

Could not list restore points.
Check "winmgmt" service or repair WMI.


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2001-08-23 08:00 - 2013-01-02 21:48 - 00000764 ____A H:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1       localhost
127.0.0.1 activate.adobe.com


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: H:\WINDOWS\Tasks\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9}.job => H:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe
Task: H:\WINDOWS\Tasks\COMODO CertSentry Updater.job => H:\WINDOWS\system32\certsentry.exe
Task: H:\WINDOWS\Tasks\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22}.job => H:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe
Task: H:\WINDOWS\Tasks\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}.job => H:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe
Task: H:\WINDOWS\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job => H:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe
Task: H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003Core.job => H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe
Task: H:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1614895754-1645522239-1417001333-1003UA.job => H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe
Task: H:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IType_exe.job => H:\Program Files\Microsoft IntelliType Pro\itype.exe

==================== Loaded Modules (whitelisted) ==============

2011-11-12 18:48 - 2010-10-14 11:04 - 00151552 _____ () H:\WINDOWS\system32\HP1100LM.DLL
2011-11-12 18:48 - 2010-10-14 11:04 - 00069632 _____ () H:\WINDOWS\System32\spool\PRTPROCS\W32X86\HP1100PP.DLL
2012-08-20 06:24 - 2012-06-06 23:26 - 00016384 _____ () H:\Program Files\TimeLineRemove\0.9\TimeLineRemove.dll
2010-11-12 22:16 - 2010-03-15 12:28 - 00141824 _____ () H:\Program Files\WinRAR\rarext.dll
2012-03-27 18:24 - 2010-03-04 22:38 - 00071096 _____ () H:\Program Files\CDBurnerXP\NMSAccessU.exe
2014-09-17 06:40 - 2014-09-17 06:40 - 00976080 _____ () H:\Program Files\Comodo\GeekBuddy\QtNetwork4.dll
2014-09-17 06:40 - 2014-09-17 06:40 - 02254544 _____ () H:\Program Files\Comodo\GeekBuddy\QtCore4.dll
2014-09-17 06:40 - 2014-09-17 06:40 - 08024784 _____ () H:\Program Files\Comodo\GeekBuddy\QtGui4.dll
2014-09-17 06:40 - 2014-09-17 06:40 - 00032976 _____ () H:\Program Files\Comodo\GeekBuddy\imageformats\qgif4.dll
2014-09-17 06:40 - 2014-09-17 06:40 - 01299664 _____ () H:\Program Files\Comodo\GeekBuddy\QtScript4.dll
2015-01-08 23:02 - 2015-01-08 23:02 - 00061152 _____ () H:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: H:\WINDOWS\system32\certsentry.exe:$CmdTcID

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1614895754-1645522239-1417001333-1003\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.0.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: H:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => H:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
MSCONFIG\startupfolder: H:^Documents and Settings^All Users^Start Menu^Programs^Startup^Start GeekBuddy.lnk => H:\WINDOWS\pss\Start GeekBuddy.lnkCommon Startup
MSCONFIG\startupfolder: H:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk => H:\WINDOWS\pss\Windows Search.lnkCommon Startup
MSCONFIG\startupfolder: H:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless Connection Manager.lnk => H:\WINDOWS\pss\Wireless Connection Manager.lnkCommon Startup
MSCONFIG\startupfolder: H:^Documents and Settings^User^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk => H:\WINDOWS\pss\OpenOffice.org 3.1.lnkStartup
MSCONFIG\startupreg: Adobe ARM => "H:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "H:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: Akamai NetSession Interface => "H:\Documents and Settings\User\Local Settings\Application Data\Akamai\netsession_win.exe"
MSCONFIG\startupreg: Alcmtr => ALCMTR.EXE
MSCONFIG\startupreg: AlcWzrd => ALCWZRD.EXE
MSCONFIG\startupreg: BitTorrent => "H:\Program Files\BitTorrent\BitTorrent.exe"  /MINIMIZED
MSCONFIG\startupreg: ctfmon.exe => H:\WINDOWS\system32\ctfmon.exe
MSCONFIG\startupreg: Facebook Update => "H:\Documents and Settings\User\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: HotKeysCmds => H:\WINDOWS\system32\hkcmd.exe
MSCONFIG\startupreg: HP Software Update => H:\Program Files\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: hpqSRMon => H:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
MSCONFIG\startupreg: IgfxTray => H:\WINDOWS\system32\igfxtray.exe
MSCONFIG\startupreg: itype => "H:\Program Files\Microsoft IntelliType Pro\itype.exe"
MSCONFIG\startupreg: JustVoip => "H:\Program Files\JustVoip.com\JustVoip\JustVoip.exe" -nosplash -minimized
MSCONFIG\startupreg: LightScribe Control Panel => H:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
MSCONFIG\startupreg: MSMSGS => "H:\Program Files\Messenger\msmsgs.exe" /background
MSCONFIG\startupreg: NBAgent => "H:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
MSCONFIG\startupreg: ooVoo.exe => H:\Program Files\ooVoo\oovoo.exe /minimized
MSCONFIG\startupreg: Skype => "H:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SoundMan => SOUNDMAN.EXE
MSCONFIG\startupreg: SunJavaUpdateSched => "H:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: swg => "H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: tvncontrol => "H:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave
MSCONFIG\startupreg: UserFaultCheck => %systemroot%\system32\dumprep 0 -u
MSCONFIG\startupreg: VX3000 => H:\WINDOWS\vVX3000.exe

==================== Faulty Device Manager Devices =============

Could not list Devices. Check "winmgmt" service or repair WMI.


==================== Event log errors: =========================

Could not start eventlog service, could not read events.

System error 123 has occurred.

The filename, directory name, or volume label syntax is incorrect.


==================== Memory info ===========================

Processor:  Intel® Pentium® 4 CPU 3.00GHz
Percentage of memory in use: 34%
Total physical RAM: 2039.29 MB
Available physical RAM: 1334.19 MB
Total Pagefile: 2642.07 MB
Available Pagefile: 1973.89 MB
Total Virtual: 2047.88 MB
Available Virtual: 1949.08 MB

==================== Drives ================================

Drive d: (MyDisc) (CDROM) (Total:3.5 GB) (Free:0 GB) UDF
Drive h: () (Fixed) (Total:465.75 GB) (Free:221.94 GB) NTFS ==>[Drive with boot components (Windows XP)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: B829B829)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Редактирано от julienalexandrov (преглед на промените)

Системата вече е чиста. Comodo е супер, но съветвам да деинсталирате GeekBuddy, който се е качил заедно с него.

Почти сме готови. Трябва да поправим WMI услугата.

 

Моля изтеглете програмата Windows Repair (all in one) от тук

Кликнете с десен бутон върху иконата на програмата и изберете "Run As Administrator".
 
Отидете до стъпка 3 и натиснете бутона Check.

Ако се окаже, че е необходима проверка на диска тогава натиснете бутона Do It. Ще се наложи да рестартирате компютъра.

4ljsUjO.jpg

След като проверката приключи отидете на Стъпка 4: и стартирайте System File Check натискайки бутона Do It:

yzmb8Pa.jpg


След като проверката приключи отидете до Стъпка 5 и създайте нова точка за възстановяване на системата и бекъп на текущото състояние на регистрите...
 
Под 1.Registry Backup натиснете бутона Backup.
Под 2.System Restore натиснете бутона Create.

60p53Ct.jpg


Сега вече отидете до Start Repairs и натиснете бутона Start.
 
76G7OMh.jpg
 
Сложете отметки пред Repair WMI и премахнете останалите:

 

и сложете отметка пред Restart/Shutdown System When Finished => Restart System и натиснете бутона Start.
 
N1qOYNx.jpg
 
НЕ използвайте компютъра докато се извършват поправките.
 
След като всички приключи, компютъра ще се рестартира.
Архивирайте всички логове от папката
32-bit systems - C:Program Files\Tweaking.com\Windows Repair (All in One)\Logs
и качете архива на следния адрес => http://file.bg и публикувайте линка към архива в следващия си коментар.
 

Направете и нова проверка с FRST след това като не забравите да сложите отметка пред Addition.txt

Поздрави!

  • Автор

file.bg не действа, може би щото не съм в БГ в момента.

 

Hа трeтата стъпка ми иска инсталационния диск за да копира някакви фаилове.
Пробвах със няколко различни версии на Win XP но ми дава съобщение че не е търсения диск.

Това се получаваше някъде около 20 пъти. Т.е. около 20 повредени \липсващио файла не са поправени в трeтата стъпка.

 

Windows Repair

 

The following services are dependent on the Windows Management Instrumentation service.
Stopping the Windows Management Instrumentation service will also stop these services.

   Security Center
   Windows Firewall/Internet Connection Sharing (ICS)

The Security Center service is stopping.
The Security Center service was stopped successfully.


The Windows Firewall/Internet Connection Sharing (ICS) service was stopped successfully.

The Windows Management Instrumentation service is stopping.
The Windows Management Instrumentation service was stopped successfully.

The system cannot find the path specified.
The system cannot find the path specified.
Deleted file - H:\WINDOWS\System32\Wbem\Repository\$WinMgmt.CFG
Deleted file - H:\WINDOWS\System32\Wbem\Repository\FS\INDEX.BTR
Deleted file - H:\WINDOWS\System32\Wbem\Repository\FS\INDEX.MAP
Deleted file - H:\WINDOWS\System32\Wbem\Repository\FS\MAPPING.VER
Deleted file - H:\WINDOWS\System32\Wbem\Repository\FS\MAPPING1.MAP
Deleted file - H:\WINDOWS\System32\Wbem\Repository\FS\MAPPING2.MAP
Deleted file - H:\WINDOWS\System32\Wbem\Repository\FS\OBJECTS.DATA
Deleted file - H:\WINDOWS\System32\Wbem\Repository\FS\OBJECTS.MAP
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\0549A61352ABEB3304DBE0A297BA60E5.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\0658283C1BA2DF2A73D5E2F0162C6C99.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\0A69832342BA5EA7679060F30D1DDBF5.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\0C9DC490FBC45BAD963AA9661A8E358F.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\1100390C6DC958518910703D1C48AB0B.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\17A51225D522F96812D2AC316C1D42BE.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\1E833D82861B6E5A2F12AC241B96E491.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\1F991579F2BB5D3DBC5CC49D85B813F8.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\2041EF6204D18CB47463D128F7A313A2.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\24BBC84488552D3903B64002AA9A8A33.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\2FDE6CA19CD8979049780146A8CC3520.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\307B35DD4B93AD4EBB53DFE09D7E4A7C.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\30E63E0B3EFA5FEEF64FAA54B64F6181.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\31EB91E00AEBD3FC9B396ABF0EEE109A.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\36C06411C08DE55B7CC1A3D858ADF6A4.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\380EC1B2491F09D3551F70A037B3D210.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\39225D510F4252CE48FF9B7126C9887B.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\397BEA5F7EB7B1135AE8CB3F5AF35FA1.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\3BA788143E584BE51F1B1113744190CF.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\3DE6F6886D4E9FC0059D6089DCBC6D66.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\3EECD8D2063025B97A3EC05754209C8A.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\452673145DDA3BFA36D6D6CCEE61FBD2.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\492672B989A9F5AA43907D773A0264A9.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\4B3E6F9AEEB49E0604247E05D8008305.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\4F045FB737836F6C7C75D0390C2C184D.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\50EE8927DEB7CFB266EF7F65A4876D70.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\5571173F9FA0E94370F638404A8DAFF4.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\56C7616A37A02C8604B979FE0218DF25.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\594022891EA76AA6E1EBF35EA5E204EC.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\5CB17D105F6C58271623DE3ACF33D686.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\5E1CA554F636B03E4DF12EE036ACC377.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\6A041F2F2D0E2A8648B426202E1204CB.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\6B575598AB465F11BE7E216F093B8947.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\72832F919EC9BC796C08144B31F31514.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\7510E49B02F1F85FCC71431D57F31C19.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\7C36AF8CE7C2943CFBE0925EA833F107.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\8470F21C96DD5164F980C6FE61784AEC.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\8B8A02019332100D55D6F9D2FE70C504.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\8BE8CE6E65884CDB26F811278B86F318.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\90A93AA857132379D4572A01B6A4CD89.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\91AD264A47E3ABCB00E6CEEEAC3B5044.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\91B76E8FAE926D2871B4D742467122B3.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\9EB1D83AAFEC22D0386B502B800DFE7F.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\A1EC6C76EEC9632FC4009B16E093DB57.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\A224CCD51CBC9E18FFCA7AB49729D8DB.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\A3AB152AB96337FFB2259A7DA93C06C4.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\A420E83A89930EFEC7D4EDEE7352CD29.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\A79141DA2B6AA2BB2C695F7B49964BE5.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\AA25DAC4932C37EA631E1DC1F059F10F.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\AEBA7B1BC7F3CA1A76A6D54FD4FAAE00.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\B30E5BE8A8D47702B798DDEFD6482664.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\BCA6712D4686492A4DCABA1F28F8B8FA.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\BE067936BC878F04E72109753574E95F.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\C1FAFF4E3934ADB25449DC0932475C39.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\C2A538925D24F363CDDDD2A8337BB050.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\C545317B00C19FB7A84DB4B5ECCF60E5.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\D1D7D733661EBC6738C1D338548B4C5F.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\D23F8AAE2694664A95AA6B01F60B904E.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\D8F965C0D4F208FAC812A45A192B3AC9.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\E429CF3D6253C49181B874D41C4AFBC4.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\E6CCCD540DEEA860F1216D81B1EACF89.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\E749A3EEAE0D3D635F761108FBEF9126.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\E9BEDADD06EBC99EDC98AE963208691C.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\F016A17BC260C75E10C27AA9E3B6924B.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\F096D591F4D0E4B2F6AEA0785507EB09.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\F24A81453FB81BF90E68364CDBBE301B.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\F43BF205A6FCB83E5B63B4F4E68689A5.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\FE31EF66CD8DD1EB06BB55BA34833789.mof
Deleted file - H:\WINDOWS\System32\Wbem\AutoRecover\FFFD394A32B05E095E5BB1A865387201.mof
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\av.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\program files\common files\microsoft shared\msinfo\oinfop12.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\microsoft.net\framework\v1.1.4322\aspnet.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\microsoft.net\framework\v2.0.50727\adonetdiag.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\microsoft.net\framework\v2.0.50727\aspnet.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\microsoft.net\framework\v2.0.50727\clr.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\microsoft.net\framework\v3.0\windows communication foundation\servicemodel.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\microsoft.net\framework\v3.5\mof\servicemodel35.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\microsoft.net\framework\v4.0.30319\adonetdiag.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\microsoft.net\framework\v4.0.30319\aspnet.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\microsoft.net\framework\v4.0.30319\clr.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\microsoft.net\framework\v4.0.30319\mof\servicemodel.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\microsoft.net\framework\v4.0.30319\mof\servicemodel35.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\winrmprov.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\msdtc\trace\msdtctr.mof
h:\windows\system32\msdtc\trace\msdtctr.mof (5): error SYNTAX 0X8004400a: Unexpected token at file scope


Compiler returned error 0x8004400aMicrosoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\cimwin32.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\cli.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\cliegaliases.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\cmdevtgprov.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\dgnet.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\dsprov.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\evntrprv.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\fconprov.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\fevprov.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\hnetcfg.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\ieinfo5.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\krnlprov.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\licwmi.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\msi.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\napclientprov.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\napclientschema.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\ncprov.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\ntevt.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\outlook_01cb92af5d6cbfb2.mof
MOF file has been successfully parsed
Storing data in the repository...
An error occurred while creating object 1 defined on lines 31 - 163:
0X80041002 Class, instance, or property 'Win32_PerfRawData' was not found.
Compiler returned error 0x80041001Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\outlook_01cca64d48719e40.mof
MOF file has been successfully parsed
Storing data in the repository...
An error occurred while creating object 1 defined on lines 31 - 163:
0X80041002 Class, instance, or property 'Win32_PerfRawData' was not found.
Compiler returned error 0x80041001Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\outlook_01ccc32e0770f23a.mof
MOF file has been successfully parsed
Storing data in the repository...
An error occurred while creating object 1 defined on lines 31 - 163:
0X80041002 Class, instance, or property 'Win32_PerfRawData' was not found.
Compiler returned error 0x80041001Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\policman.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\regevent.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\rsop.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\scersop.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\scm.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\scrcons.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\secrcw32.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\smtpcons.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\sr.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\subscrpt.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\system.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\tmplprov.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\trnsprov.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\tscfgwmi.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\updprov.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wbemcons.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\whqlprov.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmi.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmipcima.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmipdskq.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmipicmp.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmipiprt.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmipjobj.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmipsess.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmitimep.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wscenter.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wsmauto.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\cimwin32.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\cliegaliases.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\dsprov.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\fconprov.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\fevprov.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\krnlprov.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\licwmi.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\msi.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\ncprov.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\ntevt.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\policman.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\regevent.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\rsop.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\scrcons.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\secrcw32.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\smtpcons.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\tmplprov.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\trnsprov.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\tscfgwmi.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\updprov.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wbemcons.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmi.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmipcima.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmipdskq.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmipicmp.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmipiprt.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmipjobj.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmipsess.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\system32\wbem\wmitimep.mfl
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\wbem\msfeeds.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!
Microsoft ® 32-bit MOF Compiler Version 5.1.2600.5512
Copyright © Microsoft Corp. 1997-2001. All rights reserved.
Parsing MOF file: h:\windows\wbem\msfeedsbs.mof
MOF file has been successfully parsed
Storing data in the repository...
Done!

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.

H:\Documents and Settings\User\Desktop>CD /D H:\

H:\>set path=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem

H:\>chkdsk H:
The type of the file system is NTFS.

WARNING!  F parameter not specified.
Running CHKDSK in read-only mode.

CHKDSK is verifying files (stage 1 of 3)...
0 percent completed.               
1 percent completed.                            
100 percent completed.               
File verification completed.
CHKDSK is verifying indexes (stage 2 of 3)...
0 percent completed.               
1 percent completed.                             
100 percent completed.               
Index verification completed.
CHKDSK is recovering lost files.
Recovering orphaned file SAFEBR~1 (12508) into directory file 2651.
Recovering orphaned file safebrowsing-to_delete (12508) into directory file 2651.
CHKDSK is verifying security descriptors (stage 3 of 3)...
0 percent completed.               
1 percent completed.   

                          
100 percent completed.               
Security descriptor verification completed.
CHKDSK is verifying Usn Journal...
Usn Journal verification completed.
Correcting errors in the master file table's (MFT) BITMAP attribute.
Correcting errors in the Volume Bitmap.
Windows found problems with the file system.
Run CHKDSK with the /F (fix) option to correct these.

 488375968 KB total disk space.
 254477152 KB in 391358 files.
    272028 KB in 259296 indexes.
        16 KB in bad sectors.
    957740 KB in use by the system.
     65536 KB occupied by the log file.
 232669032 KB available on disk.

      4096 bytes in each allocation unit.
 122093992 total allocation units on disk.
  58167258 allocation units available on disk.
 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.

H:\Documents and Settings\User\Desktop>CD /D H:\

H:\>set path=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem

H:\>chkdsk H:
The type of the file system is NTFS.

WARNING!  F parameter not specified.
Running CHKDSK in read-only mode.

CHKDSK is verifying files (stage 1 of 3)...
100 percent completed.               
File verification completed.
CHKDSK is verifying indexes (stage 2 of 3)...
100 percent completed.               
Index verification completed.
CHKDSK is recovering lost files.
Recovering orphaned file SAFEBR~1 (12508) into directory file 2651.
Recovering orphaned file safebrowsing-to_delete (12508) into directory file 2651.
CHKDSK is verifying security descriptors (stage 3 of 3)...
100 percent completed.               
Security descriptor verification completed.
CHKDSK is verifying Usn Journal...
Usn Journal verification completed.
Correcting errors in the master file table's (MFT) BITMAP attribute.
Correcting errors in the Volume Bitmap.
Windows found problems with the file system.
Run CHKDSK with the /F (fix) option to correct these.

 488375968 KB total disk space.
 254477152 KB in 391358 files.
    272028 KB in 259296 indexes.
        16 KB in bad sectors.
957740 KB in use by the system.
     65536 KB occupied by the log file.
 232669032 KB available on disk.

      4096 bytes in each allocation unit.
 122093992 total allocation units on disk.
58167258 allocation units available on disk.

H:\>

Редактирано от julienalexandrov (преглед на промените)

Може би нямате същата версия на Windows XP с точния сервизен пакет (ако диска ви е бил с Service Pack 2 и впоследствие сте обновили до Service Pack 3, то диска няма да ви свърши работа).

Друг вариант е ако езиковата версия на диска се различава с тази на инсталираната (ако диска е с испанска версия на Windows XP, дори и с правилния сервизен пакет, но на компютъра е инсталирана английската версия) то пак няма да е получи. Иначе да, моя грешка. От няколко месеца file.bg отново не работи. Качете файловете на dox.bg, че нещо не можах да ги сваля от линковете в горния ви коментар.
 

Не забравяйте и това:
 

 

Направете и нова проверка с FRST след това като не забравите да сложите отметка пред Addition.txt

 

Искам да видя дали поправките са минали успешно. :)

 

Поздрави!

  • Автор

Извинявам се за закъснението ама много проблеми ми се струпаха напоследък.
В по-горния пост съм сложил директно резултатите от Windows Repair

 

На FRST имам леки затруднения, в смисъл проверката минава и и казва така и така  фаиловете са в същата пака откъдето е FRST, но като проверя там няма нищо. Търсих ги навсякъде, не мога да ги открия. Пуснах пак тeста , посочих му къде да ги запази и пак нищо. Накрая ги копирах като  WORD документ обаче идват твърде големи и не мога да ги кача директно във форума.  Някакви идеи.
 

http://dox.bg/files/dw?a=ca1b03b21f

 

http://dox.bg/files/dw?a=f11bb8de58

Редактирано от julienalexandrov (преглед на промените)

Изтеглете и стартирайте следния файл => winmgmt.reg. Изберете YES на диалоговия прозорец.

Колкото до проблема на FRST - изтеглете последната му версия оттук и опитайте с нея. Сложете отметка пред Addition.txt и публикувайте само този лог.

  • Автор

winmgmt ми иписва че влязъл успешно в регистрите. Друго нямаше.Това ли трябваше да стане.

След инстала на FRST ми даде една грешка ( то и на по-предните сканове пак ми я даваше )

 

2uer3ie.jpg

 

 

Пак ги няма никъде логовете от FRST сканирането.

Изхитрих го този път. Просто копирах съдържанието oт Addition и го пейстнах в един друг текст файл И му дадох save.

123.txt

Това не е грешка на FRST, а на инструмента за бекъп, който използва Erunt. Но така или иначе не трябва да я дава под XP.

Просто Операционната ви система е тотално омазана. WMI услугата все оше е повредена, а тя е доста важна за работата на Windows.

Добре ще е ако можете да намерите правилния инсталационен диск на Windows и да изпълните командата => Start => run => въведете CMD.exe и натиснете Enter => в конзолата въведете sfc /scannow => изчакайте да приключи и командата да с копира читави копия на системните файлове и да замести прецаканите системни файлове.

После ще го мислим. Направете след командата и нова проверка с FRST и публикувайте новия Addition.txt лог файл.

  • Автор

За съжаление Уина е инсталиран 2009 някъде от един колега който вече не работи при мен. Моите копия съм ги копирал от оригинални инсталационни дискове на MS, но явно нещо се разминават.

Ами освен компа да остане така докогато изкара, пък после една десятка u ....

 

Благодаря ти много за всичко. Както казах по-рано един формат е къде къде по-лесно и бързо но някои неща не зависят от мен.

Проблема е, че Windows XP е доста стара ОС и по-трудно се поправя. В Windows 7/8 са вкарани редица подобрения, които улесняват процеса. Все пак толкова лесно няма да се дадем.

 

 

СТЪПКА 1

 

 

rkill.png

  • Отворете следния сайт и изтеглете RKill.exe и ги запазете на вашия десктоп.
  • Стартирате програмата с двоен клик върху файла и изчакайте търпеливо.
  • След приключване на проверката ще се генерира лог файл с извършените процедури.
  • Прикачете лог файла в следващия си пост.

 

 

СТЪПКА 2

 

 

icon1337952077.png
Моля изтеглете Farbar Service Scanner и я стартирайте.

 

  • Сложете всички отметки и натиснете бутона "Scan".
  • Ще се създаде лог файл с името (FSS.txt) в папката откъдето стартирате инструмента.
  • Прикачете лог файла в следващия си пост.

 

 

СТЪПКА 3

 

Моля изтеглете и стартирайте WMIDiag.exe
Съгласете се с лицензионното споразумение.
Натиснете "Browse..." и изберете Desktop-a като място където да разархивирате файловете.
Ще се разархивират 3 файла. Намерете и стартирайте файла WMIDiag.vbs. Ако се появи предупредително предупреждение просто натиснете ОК.

Сега ще се наложи да изчакате около 10-20 мин (през които ще изглежда, че нищо не се случва, но не е така...скрипта ще си работи във фонов режим).
След като приключи ще се отвори лог файл. Моля прикрепете съдържанието му в следващия си коментар.
 

 

Поздрави!

  • Автор

Малко ми е неудобно след толкова усилия време и труд хвърлени от твоя страна, и знам че няма въобще да ти хареса това,  но съпружеското тяло е доволно от сегашното състояние на машината и е съгласна да я използва така в това състояние

Знам че се стараеш да изпипваш нещата докрай и може би ще се обидиш и ще го приемеш като неблагодарност, но вече ни е съвестно да ти губим времето със нашия проблем.

Благодарим ти за всичко от сърце.

Няма проблеми. Реално Windows-a вече е почистен и може да се работи и така с него. Просто имаше някои неща за поправка, които беше добре да се поправят, но не е фатално и да не се. :)

За да премахнем използваните от нас неща можете да използвате инструкциите от тази ви тема (коментар номер 11 от PatchMyPC надолу).

 

Иначе друго, което е добре да направите за финал е пълна проверка с CHKDSK, защото сега видях, че диска има проблеми от бързата CHKDSK проверка, която сте публикували на предишната страница.

 

Отворете Start => Run => въведете CMD.exe и натиснете Enter. Въведете командата: chkdsk c: /x /f /r => натиснете Enter (има празно място {интервал} между chkdsk и c: и /x и /f и /r).

 

Съгласете се с Y на диалоговия прозорец. Рестартирайте компютъра и би трябвало проверката да започне.След това вижте какви са били резултатите.

 

Рапорта от проверката ще намерите тук: Отворете Start => Run => въведете eventvwr.msc => натиснете Enter. => Разгънете Аpplication => и намерете събитието с името WinLogon и Event 1001 и го отворете.

 

checkdisk1.png

 

Kопирайте рапорта в следващия си пост.

 

checkdisk2.png

 

Поздрави!

  • Автор

Все пак толкова лесно няма да се дадем.

 

СТЪПКА 1

 

 

Rkill 2.7.0 by Lawrence Abrams (Grinler)

http://www.bleepingcomputer.com/

Copyright 2008-2015 BleepingComputer.com

More Information about Rkill can be found at this link:

 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 05/01/2015 09:16:42 AM in x86 mode.

Windows Version: Microsoft Windows XP Service Pack 3

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * H:\WINDOWS\system32\HPSIsvc.exe (PID: 2516) [WD-HEUR]

1 proccess terminated!

Checking Registry for malware related settings:

 * No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

 * Reparse Point/Junctions Found (Most likely legitimate)!

     * H:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a => H:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492 [Dir]

     * H:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35 => H:\WINDOWS\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5 [Dir]

Checking Windows Service Integrity:

 * No issues found.

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * HOSTS file entries found:

  127.0.0.1       localhost

Program finished at: 05/01/2015 09:17:23 AM

Execution time: 0 hours(s), 0 minute(s), and 41 seconds(s)

СТЪПКА 2

 

Farbar Service Scanner Version: 17-01-2015

Ran by User (administrator) on 01-05-2015 at 09:29:32

Running from "H:\Documents and Settings\User\My Documents\Downloads"

Microsoft Windows XP Professional Service Pack 3 (X86)

Boot Mode: Normal

****************************************************************

Internet Services:

============

Connection Status:

==============

Localhost is accessible.

LAN connected.

Google IP is accessible.

Google.com is accessible.

Yahoo.com is accessible.

Other Services:

==============

File Check:

========

H:\WINDOWS\system32\dhcpcsvc.dll => File is digitally signed

H:\WINDOWS\system32\Drivers\afd.sys => File is digitally signed

H:\WINDOWS\system32\Drivers\netbt.sys => File is digitally signed

H:\WINDOWS\system32\Drivers\tcpip.sys => File is digitally signed

H:\WINDOWS\system32\Drivers\ipsec.sys => File is digitally signed

H:\WINDOWS\system32\dnsrslvr.dll => File is digitally signed

H:\WINDOWS\system32\svchost.exe => File is digitally signed

H:\WINDOWS\system32\rpcss.dll => File is digitally signed

H:\WINDOWS\system32\services.exe => File is digitally signed

Extra List:

=======

AegisP(9) cmdHlp(12) Gpc(3) IPSec(5) NetBT(5) PSched(7) Tcpip(4)

0x080000000500000003000000040000000C0000000A000000060000000700000009000000

IpSec Tag value is correct.

**** End of log ****

СТЪПКА 3

Моля изтеглете и стартирайте WMIDiag.exe

 

изтеглям от дадения линк, само че в свойства на иконата не е  wmidiag.exe а е win32 cabinet self-extractor

след двоен клик за да стартирам файла ми отваря едно прозорче със wmidiag.exe is not a valid win32 application

 

system requirements win 7 and up

За да премахнем използваните от нас неща

 

след OTC-то останаха eset, shadow explorer, FRST, winmgmt и rkill които премахнах ръчно

На Farbar Service Scanner май не сте сложили всички отметки преди сканирането.

Повторете проверката. Пропуснете WMIDiag (явно е само за 7 и нагоре).

Добре е да направите и проверката за грешки с CHKDSK, както съм описал.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.