My Avast IS keeps blocking every 5-10 minutes Trojan Win64:Sirefef-A, Rootkit Win32:Sirefef-AO and also keeps blocking some url with .cn address.
I tried running MBAM which had found and deleted trojan but it's still there. Full scans by Avast also didn't help.
Here is log from OTL:
OTL logfile created on: 11.07.2012 16:55:30 - Run 2
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Valeriy\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000419 | Country: Россия | Language: RUS | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 1,39 Gb Available Physical Memory | 46,46% Memory free
6,19 Gb Paging File | 4,29 Gb Available in Paging File | 69,30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 290,91 Gb Total Space | 27,70 Gb Free Space | 9,52% Space Free | Partition Type: NTFS
Drive D: | 7,17 Gb Total Space | 0,00 Gb Free Space | 0,02% Space Free | Partition Type: NTFS
Computer Name: VALERIY | User Name: Valeriy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.07.10 22:31:22 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Valeriy\Downloads\OTL.exe
PRC - [2012.07.03 18:21:30 | 004,273,976 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012.07.03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.07.03 18:21:27 | 000,133,912 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2012.06.27 11:58:22 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.06.27 11:58:22 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.06.23 07:08:18 | 001,535,176 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe
PRC - [2012.06.20 17:16:48 | 000,400,352 | ---- | M] (Mozilla Messaging) -- C:\Program Files\Mozilla Thunderbird\thunderbird.exe
PRC - [2012.06.15 00:20:13 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012.05.12 07:23:54 | 000,880,496 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
PRC - [2011.11.18 03:39:10 | 000,105,472 | ---- | M] (Nike) -- C:\Program Files\Nike\Nike+ Connect\Nike+ Connect daemon.exe
PRC - [2011.10.19 01:33:48 | 000,640,264 | ---- | M] (ABBYY (BIT Software)) -- C:\Program Files\ABBYY Lingvo x5\LvAgent.exe
PRC - [2011.05.17 21:23:49 | 000,816,904 | ---- | M] (ABBYY) -- C:\Program Files\Common Files\ABBYY\Lingvo\15.0\Licensing\NetworkLicenseServer.exe
PRC - [2011.01.28 07:15:33 | 000,066,048 | ---- | M] (PostgreSQL Global Development Group) -- c:\postgreSQL\bin\pg_ctl.exe
PRC - [2011.01.28 07:13:43 | 004,538,368 | ---- | M] (PostgreSQL Global Development Group) -- c:\postgreSQL\bin\postgres.exe
PRC - [2011.01.06 09:04:56 | 000,181,192 | ---- | M] () -- C:\Program Files\Daum\PotPlayer\PotPlayerMini.exe
PRC - [2010.01.24 23:00:00 | 003,520,256 | ---- | M] (Ghisler Software GmbH) -- C:\Program Files\Total Commander\Totalcmd.exe
PRC - [2009.07.21 21:33:32 | 000,458,844 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2009.07.21 21:33:32 | 000,221,266 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\stacsv.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.08.22 15:32:06 | 000,361,808 | ---- | M] () -- C:\Windows\SMINST\BLService.exe
PRC - [2008.04.15 15:54:42 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008.04.15 15:54:40 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008.02.20 21:10:12 | 000,619,832 | ---- | M] (Apple Inc.) -- C:\Program Files\DVD or CD Sharing\ODSAgent.exe
PRC - [2008.02.12 22:05:54 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\AEstSrv.exe
PRC - [2007.12.11 10:15:04 | 000,012,800 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
========== Modules (No Company Name) ==========
MOD - [2012.07.10 15:42:27 | 000,836,608 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\version.dll
MOD - [2012.06.23 07:08:18 | 009,459,912 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_262.dll
MOD - [2012.06.20 17:16:52 | 001,977,312 | ---- | M] () -- C:\Program Files\Mozilla Thunderbird\mozjs.dll
MOD - [2012.06.20 17:16:51 | 000,162,784 | ---- | M] () -- C:\Program Files\Mozilla Thunderbird\nsldap32v60.dll
MOD - [2012.06.20 17:16:51 | 000,021,984 | ---- | M] () -- C:\Program Files\Mozilla Thunderbird\nsldappr32v60.dll
MOD - [2012.06.15 00:20:15 | 002,042,848 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012.03.16 16:23:42 | 000,008,192 | ---- | M] () -- C:\Users\Valeriy\AppData\Roaming\Thunderbird\Profiles\pzfe9tkw.default\extensions\[email protected]\lib\tray_x86-msvc.dll
MOD - [2012.02.22 11:58:12 | 008,296,448 | ---- | M] () -- C:\Program Files\Daum\PotPlayer\ffcodec.dll
MOD - [2011.11.02 00:26:32 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.11.02 00:26:12 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.01.06 09:04:56 | 000,181,192 | ---- | M] () -- C:\Program Files\Daum\PotPlayer\PotPlayerMini.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe -- (Roxio Upnp Server 9)
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe -- (Roxio UPnP Renderer 9)
SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\ABBYY\Lingvo\14.0\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.Lingvo.Desktop.14.0)
SRV - [2012.07.08 07:54:08 | 000,116,720 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012.07.03 18:21:27 | 000,133,912 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
SRV - [2012.07.03 13:19:28 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.06.27 11:58:22 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.06.23 07:08:18 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2011.05.17 21:23:49 | 000,816,904 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files\Common Files\ABBYY\Lingvo\15.0\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.Lingvo.Desktop.15.0)
SRV - [2011.01.28 07:15:33 | 000,066,048 | ---- | M] (PostgreSQL Global Development Group) [Auto | Running] -- c:\postgreSQL\bin\pg_ctl.exe -- (postgresql-8.4)
SRV - [2010.03.18 13:16:28 | 000,753,504 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2009.07.21 21:33:32 | 000,221,266 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\stacsv.exe -- (STacSV)
SRV - [2009.04.11 08:27:31 | 002,092,544 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\Windows\System32\dfsr.exe -- (DFSR)
SRV - [2008.08.22 15:32:06 | 000,361,808 | ---- | M] () [Auto | Running] -- C:\Windows\SMINST\BLService.exe -- (Recovery Service for Windows)
SRV - [2008.04.15 15:54:42 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2008.03.26 16:27:52 | 000,595,248 | ---- | M] (Validity Sensors, Inc.) [Disabled | Stopped] -- C:\Windows\System32\vfsFPService.exe -- (vfsFPService)
SRV - [2008.03.12 17:24:52 | 000,302,144 | ---- | M] (DigitalPersona, Inc.) [Disabled | Stopped] -- C:\Program Files\DigitalPersona\Bin\DpHostW.exe -- (DpHost)
SRV - [2008.02.12 22:05:54 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\AEstSrv.exe -- (AESTFilters)
SRV - [2007.12.11 10:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vmnetadapter.sys -- (VMnetAdapter)
DRV - File not found [Kernel | Boot | Stopped] -- system32\DRIVERS\vmci.sys -- (vmci)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\usbser_lowerflt.sys -- (upperdev)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\UIUSYS.SYS -- (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\RimUsb.sys -- (RimUsb)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\pccsmcfd.sys -- (pccsmcfd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [2009/04/03 20:21:53] [Kernel | Auto | Stopped] -- C:\Program Files\CyberLink\PowerDVD9\000.fcl -- ({B154377D-700F-42cc-9474-23858FBDF4BD})
DRV - [2012.07.03 18:21:54 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012.07.03 18:21:53 | 000,721,000 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012.07.03 18:21:53 | 000,353,688 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012.07.03 18:21:53 | 000,202,928 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdis2.sys -- (aswNdis2)
DRV - [2012.07.03 18:21:53 | 000,057,656 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2012.07.03 18:21:53 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012.07.03 18:21:53 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.07.03 18:21:53 | 000,018,544 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswKbd.sys -- (aswKbd)
DRV - [2012.07.03 18:21:52 | 000,113,776 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswFW.sys -- (aswFW)
DRV - [2012.06.27 22:33:54 | 000,012,112 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdis.sys -- (aswNdis)
DRV - [2012.06.27 11:58:24 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011.12.18 19:19:24 | 000,038,944 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\cdrbsdrv.sys -- (cdrbsdrv)
DRV - [2011.12.09 16:35:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)) WsAudio_DeviceS(5)
DRV - [2011.12.09 16:35:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)) WsAudio_DeviceS(4)
DRV - [2011.12.09 16:35:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)) WsAudio_DeviceS(3)
DRV - [2011.12.09 16:35:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)) WsAudio_DeviceS(2)
DRV - [2011.12.09 16:35:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)) WsAudio_DeviceS(1)
DRV - [2011.09.21 17:18:53 | 000,443,448 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2011.03.22 02:25:30 | 000,023,608 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DrmRAudio.sys -- (DrmRAudio)
DRV - [2010.09.02 23:36:25 | 000,037,920 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2010.07.29 12:31:26 | 000,032,608 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2010.03.25 19:09:38 | 000,113,664 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2010.03.25 19:09:38 | 000,103,168 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010.03.25 19:09:38 | 000,101,120 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbfake.sys -- (hwusbfake)
DRV - [2010.02.25 16:51:02 | 000,025,216 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tap0901.sys -- (tap0901)
DRV - [2009.10.03 05:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009.07.21 21:33:32 | 000,409,088 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2009.06.26 21:55:12 | 000,066,080 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2008.11.21 20:53:40 | 001,204,128 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008.10.24 15:31:42 | 000,009,216 | ---- | M] (SNEG) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FStarForce.sys -- (FStarForce)
DRV - [2008.04.15 12:05:08 | 000,118,784 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008.04.01 13:14:10 | 000,081,296 | ---- | M] (JMicron Technology Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\jmcr.sys -- (JMCR)
DRV - [2008.03.27 10:12:12 | 000,024,424 | ---- | M] (Hewlett-Packard Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hpdskflt.sys -- (hpdskflt)
DRV - [2008.03.27 10:11:34 | 000,034,664 | ---- | M] (Hewlett-Packard Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Accelerometer.sys -- (Accelerometer)
DRV - [2008.03.26 16:28:08 | 000,040,752 | ---- | M] (Validity Sensors, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vfs101x.sys -- (vfs101x)
DRV - [2008.01.24 15:23:12 | 000,052,736 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\enecir.sys -- (enecir)
DRV - [2007.07.11 08:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid)
DRV - [2007.06.18 15:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2006.11.02 09:30:56 | 000,429,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm60x32.sys -- (NVENETFD)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec....60&pvid=6.2.1.5
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...avilion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec....60&pvid=6.2.1.5
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {576E3DB8-8BD3-47C9-A4C2-6A7A1A2C1127}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRC
IE - HKCU\..\SearchScopes\{576E3DB8-8BD3-47C9-A4C2-6A7A1A2C1127}: "URL" = http://www.google.ru...
IE - HKCU\..\SearchScopes\{F3EA7F57-D2E2-4F52-821E-09BF8DB8321C}: "URL" = http://ru.wikipedia....i/{searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "https://www.google.com/"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012.07.10 16:13:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.07.08 18:19:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012.06.20 17:16:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2012.07.08 18:23:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Valeriy\AppData\Roaming\mozilla\Extensions
[2010.02.21 10:09:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Valeriy\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.07.08 18:23:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Valeriy\AppData\Roaming\mozilla\Firefox\Profiles\d9g98dwa.default\extensions
[2012.07.08 18:23:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Valeriy\AppData\Roaming\mozilla\Firefox\Profiles\d9g98dwa.default\extensions\{B5F5E8D3-AE31-49A1-AC42-78B7B1CC5CDC}
[2012.07.09 18:34:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Valeriy\AppData\Roaming\mozilla\Firefox\Profiles\gxedmpxl.default\extensions
[2012.07.08 18:19:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.07.09 12:30:21 | 000,525,327 | ---- | M] () (No name found) -- C:\USERS\VALERIY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GXEDMPXL.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
[2012.07.08 18:46:56 | 000,018,786 | ---- | M] () (No name found) -- C:\USERS\VALERIY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GXEDMPXL.DEFAULT\EXTENSIONS\{B5F5E8D3-AE31-49A1-AC42-78B7B1CC5CDC}.XPI
[2012.06.15 00:20:49 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.06.15 00:19:40 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.06.15 00:19:40 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2009.09.29 08:28:45 | 000,000,791 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Lingvo Launcher] C:\Program Files\ABBYY Lingvo x5\LvAgent.exe (ABBYY (BIT Software))
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Nike+ Connect] C:\Program Files\Nike\Nike+ Connect\Nike+ Connect daemon.exe (Nike)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Общие DVD или CD] C:\Program Files\DVD or CD Sharing\ODSAgent.exe (Apple Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: &Экспорт в Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Добавить в Анти-Баннер - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm File not found
O8 - Extra context menu item: Отправить изображение на &устройство Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Отправить страницу на &устройство Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: fulltiltpoker.com ([cashier] https in Надежные узлы)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{885442AB-3279-4777-A836-29458CF34CE0}: DhcpNameServer = 192.168.0.1 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0cfb0dfb-0d36-11e1-a802-be905bc9cd0f}\Shell - "" = AutoRun
O33 - MountPoints2\{0cfb0dfb-0d36-11e1-a802-be905bc9cd0f}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{0cfb0e3a-0d36-11e1-a802-e87ec9c227ee}\Shell - "" = AutoRun
O33 - MountPoints2\{0cfb0e3a-0d36-11e1-a802-e87ec9c227ee}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{3366069a-bdbe-11df-a6db-89ccb1301e09}\Shell - "" = AutoRun
O33 - MountPoints2\{3366069a-bdbe-11df-a6db-89ccb1301e09}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{9d1ef74f-fdb3-11dd-8a94-001e68d6d35a}\Shell - "" = AutoRun
O33 - MountPoints2\{9d1ef74f-fdb3-11dd-8a94-001e68d6d35a}\Shell\AutoRun\command - "" = F:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012.07.10 16:15:19 | 000,353,688 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2012.07.10 16:15:19 | 000,021,256 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2012.07.10 16:15:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2012.07.10 16:15:18 | 000,113,776 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
[2012.07.10 16:13:46 | 000,721,000 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2012.07.10 16:13:46 | 000,202,928 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
[2012.07.10 16:13:46 | 000,057,656 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2012.07.10 16:13:46 | 000,054,232 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2012.07.10 16:13:46 | 000,035,928 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2012.07.10 16:12:54 | 000,012,112 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswNdis.sys
[2012.07.10 16:12:52 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2012.07.10 15:37:56 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012.07.10 14:59:16 | 000,018,544 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys
[2012.07.10 14:57:43 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.07.10 14:56:49 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012.07.10 14:34:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Puran Defrag
[2012.07.10 14:34:03 | 000,000,000 | ---D | C] -- C:\Program Files\Puran Defrag
[2012.07.10 13:10:49 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.07.09 13:58:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2012.07.09 13:58:37 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2012.07.08 18:19:00 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012.07.07 15:05:52 | 000,000,000 | ---D | C] -- C:\Users\Valeriy\AppData\Roaming\Media Player Classic
[2012.06.26 20:27:39 | 000,000,000 | ---D | C] -- C:\Users\Valeriy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AP Tuner 3.08
[2012.06.26 20:27:38 | 000,000,000 | ---D | C] -- C:\Program Files\AP Tuner
[2012.06.23 08:56:34 | 000,000,000 | ---D | C] -- C:\Users\Valeriy\AppData\Local\Macromedia
[2012.06.17 10:09:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012.06.17 10:07:42 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012.06.17 10:07:40 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012.06.17 09:51:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012.06.17 09:50:58 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2008.12.31 10:37:56 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Valeriy\AppData\Roaming\pcouffin.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.07.11 16:51:17 | 000,151,456 | ---- | M] () -- C:\Users\Valeriy\Documents\TPV Virtual - Informe de Compra.pdf
[2012.07.11 15:19:23 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.11 15:19:23 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.11 07:19:40 | 000,673,354 | ---- | M] () -- C:\ProgramData\nvModes.001
[2012.07.11 07:19:32 | 000,673,354 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2012.07.11 07:19:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.11 07:18:43 | 3218,296,832 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.10 22:38:30 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.07.10 16:15:19 | 000,001,829 | ---- | M] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012.07.10 16:13:46 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2012.07.09 12:59:02 | 000,196,608 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2012.07.08 18:19:03 | 000,000,870 | ---- | M] () -- C:\Users\Valeriy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012.07.08 18:08:40 | 000,006,606 | ---- | M] () -- C:\Users\Valeriy\Documents\cc_20120708_180837.reg
[2012.07.03 18:21:54 | 000,054,232 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2012.07.03 18:21:53 | 000,721,000 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2012.07.03 18:21:53 | 000,353,688 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2012.07.03 18:21:53 | 000,202,928 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
[2012.07.03 18:21:53 | 000,057,656 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2012.07.03 18:21:53 | 000,035,928 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2012.07.03 18:21:53 | 000,021,256 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2012.07.03 18:21:53 | 000,018,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys
[2012.07.03 18:21:52 | 000,113,776 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
[2012.07.03 18:21:32 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.07.03 18:21:28 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2012.06.27 22:33:54 | 000,012,112 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswNdis.sys
[2012.06.27 11:58:24 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.06.23 22:05:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.06.17 16:33:49 | 000,704,000 | ---- | M] () -- C:\Windows\System32\perfh019.dat
[2012.06.17 16:33:49 | 000,635,056 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.06.17 16:33:49 | 000,147,146 | ---- | M] () -- C:\Windows\System32\perfc019.dat
[2012.06.17 16:33:49 | 000,119,622 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.06.17 10:09:23 | 000,001,664 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.06.13 16:35:16 | 000,446,184 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.07.11 16:51:15 | 000,151,456 | ---- | C] () -- C:\Users\Valeriy\Documents\TPV Virtual - Informe de Compra.pdf
[2012.07.10 16:34:41 | 3218,296,832 | -HS- | C] () -- C:\hiberfil.sys
[2012.07.10 16:15:19 | 000,001,829 | ---- | C] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012.07.09 12:28:42 | 000,001,696 | ---- | C] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\U\00000001.@
[2012.07.08 18:19:02 | 000,000,870 | ---- | C] () -- C:\Users\Valeriy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012.07.08 18:19:02 | 000,000,858 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.07.08 18:08:38 | 000,006,606 | ---- | C] () -- C:\Users\Valeriy\Documents\cc_20120708_180837.reg
[2012.06.17 10:09:23 | 000,001,664 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012.03.17 14:40:03 | 000,000,000 | ---- | C] () -- C:\Windows\graphedt.INI
[2012.01.11 08:43:13 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\@
[2012.01.11 08:43:13 | 000,002,048 | -HS- | C] () -- C:\Users\Valeriy\AppData\Local\{ff24043d-55f8-5ce9-a20a-8337d9b4b888}\@
[2011.12.18 19:15:36 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2011.11.13 14:57:39 | 000,000,256 | ---- | C] () -- C:\Windows\System32\pool.bin
[2011.06.09 15:04:19 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2011.04.19 08:33:58 | 000,488,448 | ---- | C] () -- C:\Windows\System32\apdfprintmon.dll
[2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011.04.04 10:03:19 | 000,163,948 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2010.12.09 15:02:31 | 000,021,821 | ---- | C] () -- C:\Windows\cscmondump.bin
[2010.12.09 14:48:59 | 000,663,392 | ---- | C] () -- C:\Windows\System32\drivers\sfi.dat
[2010.02.28 20:10:13 | 000,000,036 | ---- | C] () -- C:\Users\Valeriy\AppData\Local\housecall.guid.cache
[2010.02.17 19:12:03 | 000,000,045 | ---- | C] () -- C:\Users\Valeriy\AppData\Local\machpro.dat
[2010.01.20 10:09:44 | 000,000,164 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2009.10.11 12:37:25 | 000,005,104 | ---- | C] () -- C:\ProgramData\ojvzdisj.xda
[2009.03.27 18:07:35 | 000,000,632 | RHS- | C] () -- C:\Users\Valeriy\ntuser.pol
[2009.03.27 16:46:48 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009.02.24 17:43:18 | 000,007,808 | ---- | C] () -- C:\Users\Valeriy\AppData\Local\d3d9caps.dat
[2009.01.01 13:08:38 | 000,074,752 | ---- | C] () -- C:\Users\Valeriy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.12.31 10:56:59 | 000,001,057 | ---- | C] () -- C:\Users\Valeriy\AppData\Roaming\vso_ts_preview.xml
[2008.12.31 10:37:56 | 000,087,608 | ---- | C] () -- C:\Users\Valeriy\AppData\Roaming\inst.exe
[2008.12.31 10:37:56 | 000,007,887 | ---- | C] () -- C:\Users\Valeriy\AppData\Roaming\pcouffin.cat
[2008.12.31 10:37:56 | 000,001,144 | ---- | C] () -- C:\Users\Valeriy\AppData\Roaming\pcouffin.inf
[2008.12.27 22:32:53 | 000,000,032 | ---- | C] () -- C:\ProgramData\ezsid.dat
[2008.09.14 23:46:08 | 000,673,354 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2008.09.14 23:46:08 | 000,673,354 | ---- | C] () -- C:\ProgramData\nvModes.001
========== LOP Check ==========
[2012.03.17 21:27:48 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\Acronis
[2010.02.04 19:19:38 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\BITS
[2011.12.16 13:57:04 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\DAEMON Tools Lite
[2008.12.26 19:25:17 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\DigitalPersona
[2010.02.12 07:11:57 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\DMCache
[2011.12.18 19:58:30 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\EAC
[2009.03.31 14:30:20 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\ESET
[2012.07.09 22:38:54 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\foobar2000
[2011.03.28 09:31:43 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\HEM Data
[2012.05.12 15:40:16 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\HoldemManager
[2011.12.19 13:11:36 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\ImgBurn
[2011.07.23 13:33:00 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\InfraRecorder
[2011.12.17 13:06:08 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\IObit
[2010.02.25 15:24:21 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\KeePass
[2011.12.18 21:24:49 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\LEAPS
[2011.07.23 11:00:55 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\Notepad++
[2010.05.12 16:10:55 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\OpenOffice.org
[2010.02.08 12:37:40 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\postgresql
[2012.06.21 13:27:03 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\PotPlayerMini
[2011.04.18 10:50:57 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\QuickScan
[2011.11.13 14:57:31 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\Research In Motion
[2011.02.20 10:39:18 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\Roaming
[2011.07.28 11:18:41 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\Softland
[2011.06.09 09:16:38 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\SumatraPDF
[2011.11.21 13:32:07 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\TeamViewer
[2010.09.20 10:39:41 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\Thinstall
[2010.02.21 10:09:15 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\Thunderbird
[2011.04.18 19:48:27 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\UDC Profiles
[2010.10.19 07:24:36 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\Uniblue
[2012.07.11 17:12:50 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\uTorrent
[2011.11.12 16:08:32 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\Vodafone
[2012.04.15 09:41:05 | 000,000,000 | ---D | M] -- C:\Users\Valeriy\AppData\Roaming\Vso
[2012.07.10 22:38:31 | 000,032,574 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:ECF54A0E
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:6B9ADB51
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:8CEFE51A
< End of report >
Thank you!