16:11:17.858 Disk 0 Vendor: WDC_WD2500AAJB-00WGA0 00.02C01 Size: 238475MB BusType: 3
16:11:17.859 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-4
16:11:17.861 Disk 1 Vendor: WDC_WD5000AAKS-00A7B2 01.03B01 Size: 476940MB BusType: 11
16:11:17.953 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
16:11:17.959 Disk 1 Partition 2 00 07 HPFS/NTFS NTFS 99899 MB offset 206848
16:11:17.976 Disk 1 Partition 3 00 07 HPFS/NTFS NTFS 376938 MB offset 204800000
16:11:40.685 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS PCIIDEX.SYS msahci.sys srv.sys
16:11:40.698 5 ACPI.sys[8bca33d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0x85f5b908]
16:11:52.026 Disk 1 MBR has been saved successfully to "C:\Users\Adina\Desktop\MBR.dat"
16:11:52.039 The log file has been saved successfully to "C:\Users\Adina\Desktop\aswMBR.txt"
OTL logfile created on: 18.05.2014 16:12:46 - Run 6
OTL by OldTimer - Version 3.2.70.2 Folder = C:\Users\Adina\Desktop
Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17041)
Locale: 00000418 | Country: Romania | Language: ROM | Date Format: dd.MM.yyyy
3,30 Gb Total Physical Memory | 1,94 Gb Available Physical Memory | 58,67% Memory free
4,30 Gb Paging File | 2,62 Gb Available in Paging File | 60,83% Paging File free
Paging file location(s): c:\pagefile.sys 1024 3096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97,56 Gb Total Space | 23,62 Gb Free Space | 24,21% Space Free | Partition Type: NTFS
Drive D: | 368,10 Gb Total Space | 60,52 Gb Free Space | 16,44% Space Free | Partition Type: NTFS
Drive E: | 232,88 Gb Total Space | 173,11 Gb Free Space | 74,33% Space Free | Partition Type: NTFS
Drive H: | 2794,51 Gb Total Space | 2370,67 Gb Free Space | 84,83% Space Free | Partition Type: NTFS
Computer Name: ADINA-PC | User Name: Adina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014.05.18 15:53:12 | 000,601,088 | ---- | M] (OldTimer Tools) -- C:\Users\Adina\Desktop\OTL (1).exe
PRC - [2014.05.12 16:59:10 | 000,133,184 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2014.05.05 10:38:00 | 000,182,352 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
PRC - [2014.05.05 10:37:58 | 000,124,496 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
PRC - [2014.03.13 14:13:52 | 000,440,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2014.03.13 14:13:46 | 000,689,744 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2014.03.13 14:13:46 | 000,440,400 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2013.12.21 09:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013.12.18 16:57:21 | 000,431,672 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2013.07.03 08:10:29 | 000,846,288 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.11.23 05:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012.07.20 21:08:04 | 008,186,368 | ---- | M] () -- C:\xampp\mysql\bin\mysqld.exe
PRC - [2011.12.22 19:11:20 | 000,818,952 | ---- | M] (ABBYY) -- C:\Program Files\Common Files\ABBYY\FineReader\11.00\Licensing\CE\NetworkLicenseServer.exe
PRC - [2011.04.15 12:43:20 | 002,280,312 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2011.02.25 08:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2014.05.05 10:37:58 | 000,138,320 | ---- | M] () -- C:\Program Files\Avira\My Avira\Avira.OE.NativeCore.dll
MOD - [2014.05.05 10:37:52 | 000,049,744 | ---- | M] () -- C:\Users\Adina\AppData\Local\temp\avgnt.exe\Avira.OE.ExtApi.dll
MOD - [2014.02.14 02:48:35 | 000,260,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsForm0b574481#\1ab52f8951c2ab97592ec25830dd5165\WindowsFormsIntegration.ni.dll
MOD - [2014.02.14 02:47:43 | 019,693,056 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\24bf0c88c0465485f4b842df043b3f45\System.ServiceModel.ni.dll
MOD - [2014.02.14 02:47:17 | 002,997,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\1e5e19d119e04b93da3d45153abd60fd\System.IdentityModel.ni.dll
MOD - [2014.02.14 02:46:24 | 000,018,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\47e7fc401facd4a5d3f2237f16948f36\PresentationFramework-SystemXml.ni.dll
MOD - [2014.02.14 02:46:23 | 000,016,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio84a7b877#\af02d03484578dbc357d1df8d1b6fd01\PresentationFramework-SystemData.ni.dll
MOD - [2014.02.14 01:54:50 | 018,813,440 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\a4b45c44490c75bc2fb22780e7ef087d\PresentationFramework.ni.dll
MOD - [2014.02.14 01:54:35 | 001,889,792 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\3fe705796c6a41d4889d9001d1c56af8\System.Xaml.ni.dll
MOD - [2014.02.14 01:54:32 | 012,894,208 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f4f6ee0df2aa4189bf36e6335cb92761\System.Windows.Forms.ni.dll
MOD - [2014.02.14 01:54:30 | 007,409,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\6bbed231aec6fd82547e09474da0b2f9\System.Data.ni.dll
MOD - [2014.02.14 01:54:28 | 002,542,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\7e73e63cf4b8efdf41900b9576489e61\System.Data.Linq.ni.dll
MOD - [2014.02.14 01:54:25 | 011,025,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\a74542efbeb46445949a39026c501132\PresentationCore.ni.dll
MOD - [2014.02.14 01:54:22 | 002,825,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\f6d7bb59f318c130d68816a89335d05e\System.Runtime.Serialization.ni.dll
MOD - [2014.02.14 01:54:22 | 001,644,544 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\5cd2aee5e7c07227c694d89219688ab3\System.Drawing.ni.dll
MOD - [2014.02.14 01:54:20 | 000,806,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\34b53ecafa1d7ccc7ca961d722b5d983\System.ServiceModel.Internals.ni.dll
MOD - [2014.02.14 01:54:20 | 000,122,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\78652b7fa68ee058bff6a118c657f565\SMDiagnostics.ni.dll
MOD - [2014.02.14 01:54:15 | 006,990,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\dce99d8de14d8a015313db98c72552ee\System.Core.ni.dll
MOD - [2014.02.14 01:54:14 | 007,662,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bada32953bb6b16a53d653eae23d78dc\System.Xml.ni.dll
MOD - [2014.02.14 01:54:13 | 003,950,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\acf97bfe2a931d4a47253b26b7218991\WindowsBase.ni.dll
MOD - [2014.02.14 01:54:11 | 000,470,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\75f8bc4cf08030c4a53b6d5e0ae20046\PresentationFramework.Aero.ni.dll
MOD - [2014.02.14 01:54:08 | 000,976,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\bbc48ec4245e502ae19b0601d3799c9e\System.Configuration.ni.dll
MOD - [2014.02.14 01:54:07 | 000,223,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\f4354d6580fbb745c0c8acba382a7b84\System.ServiceProcess.ni.dll
MOD - [2014.02.14 01:54:06 | 010,060,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ff26cc03e6d57d8abd13b990332e67c6\System.ni.dll
MOD - [2014.02.14 01:54:02 | 000,147,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\4c8a153aa66fcd62db6fff269a2ef2b4\System.Numerics.ni.dll
MOD - [2014.02.14 01:54:00 | 016,953,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll
MOD - [2013.07.03 08:10:26 | 000,396,240 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\28.0.1500.71\ppgooglenaclpluginchrome.dll
MOD - [2013.07.03 08:10:23 | 004,052,944 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\28.0.1500.71\pdf.dll
MOD - [2013.07.03 08:09:27 | 000,601,552 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\28.0.1500.71\libglesv2.dll
MOD - [2013.07.03 08:09:26 | 000,123,344 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\28.0.1500.71\libegl.dll
MOD - [2013.07.03 08:09:23 | 001,597,392 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\28.0.1500.71\ffmpegsumo.dll
MOD - [2009.05.16 00:22:42 | 000,716,800 | ---- | M] () -- C:\Program Files\Samsung\Samsung PC Studio 7\PCSCM_Samsung.dll
MOD - [2008.12.06 01:41:50 | 000,619,008 | ---- | M] () -- C:\Program Files\Samsung\Samsung PC Studio 7\PhoneBrowser.dll
========== Services (SafeList) ==========
SRV - [2014.05.13 23:29:06 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014.05.12 16:59:10 | 000,133,184 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2014.05.11 09:30:07 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014.05.05 10:37:58 | 000,124,496 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe -- (Avira.OE.ServiceHost)
SRV - [2014.03.13 14:13:52 | 000,440,400 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2014.03.13 14:13:46 | 000,440,400 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2014.03.06 10:38:10 | 000,108,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2013.12.21 09:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013.10.23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.10.09 11:58:16 | 003,275,136 | ---- | M] (Skype Technologies S.A.) [Disabled | Stopped] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2013.05.27 07:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.11.03 20:58:48 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2012.08.18 13:38:26 | 000,022,016 | ---- | M] (Apache Software Foundation) [Auto | Stopped] -- C:\xampp\apache\bin\httpd.exe -- (Apache2.4)
SRV - [2012.07.20 21:08:04 | 008,186,368 | ---- | M] () [Auto | Start_Pending] -- C:\xampp\mysql\bin\mysqld.exe -- (mysql)
SRV - [2012.05.11 10:24:22 | 000,632,320 | ---- | M] (FileZilla Project) [Auto | Stopped] -- C:\xampp\FileZillaFTP\FileZillaServer.exe -- (FileZillaServer)
SRV - [2011.12.22 19:11:20 | 000,818,952 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files\Common Files\ABBYY\FineReader\11.00\Licensing\CE\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Corporate.11.0)
SRV - [2011.04.15 12:43:20 | 002,280,312 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.07.14 04:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009.07.14 04:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 04:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2008.11.11 09:38:06 | 000,620,544 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - File not found [Kernel | Boot | Stopped] -- C:\Windows\system32\drivers\PRSBDRVR.SYS -- (PRSBDRVR)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (gdrv)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\Adina\AppData\Local\Temp\aswMBR.sys -- (aswMBR)
DRV - File not found [Kernel | System | Stopped] -- system32\drivers\{0782648b-1717-4fef-ac58-8cb3ce03adb3}Gw.sys -- ({0782648b-1717-4fef-ac58-8cb3ce03adb3}Gw)
DRV - [2014.05.12 19:03:11 | 000,270,336 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud)
DRV - [2013.12.18 16:57:39 | 000,135,648 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2013.12.18 16:57:39 | 000,090,400 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2013.10.01 14:17:22 | 000,037,352 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\System32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2013.08.08 12:57:32 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2013.04.04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013.02.18 19:39:36 | 000,040,344 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stdriverx86.sys -- (stdriver)
DRV - [2012.08.23 17:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2012.08.23 17:40:25 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 15:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 15:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 15:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 12:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.11.20 12:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 12:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009.11.06 05:20:24 | 000,106,880 | ---- | M] (AnyDATA.NET INC.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\adusbser.sys -- (adusbser)
DRV - [2009.09.17 20:54:14 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (HECI)
DRV - [2009.02.12 15:11:24 | 000,022,312 | ---- | M] (EldoS Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\rsdrv.sys -- (ElRawDisk)
DRV - [2008.08.26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.01.10 20:34:44 | 000,005,120 | ---- | M] (Samsung Electronics) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\SSPORT.SYS -- (SSPORT)
DRV - [2007.05.02 16:32:34 | 000,135,680 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdsa.sys -- (nmwcdsa)
DRV - [2007.05.02 16:31:54 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdsacm.sys -- (nmwcdsacm)
DRV - [2007.05.02 16:31:54 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdsacj.sys -- (nmwcdsacj)
DRV - [2007.05.02 16:31:54 | 000,008,320 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdsac.sys -- (nmwcdsac)
DRV - [2004.10.18 16:02:20 | 000,049,152 | ---- | M] (DeviceGuys, Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\DGIVECP.SYS -- (DgiVecp)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ro-RO
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F0 D1 04 BB C5 6F CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=198484"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1211151.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.5.2: C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.5.2: C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.7: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@wolfram.com/Mathematica: C:\Program Files\Common Files\Wolfram Research\Browser\9.0.1.4092550\npmathplugin.dll (Wolfram Research, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\Adina\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll (Octoshape ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2014.05.16 06:54:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2014.05.11 09:30:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014.05.11 09:30:03 | 000,000,000 | ---D | M]
[2010.12.29 16:23:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Adina\AppData\Roaming\Mozilla\Extensions
[2014.05.18 16:06:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Adina\AppData\Roaming\Mozilla\Firefox\Profiles\e94gfn82.default\extensions
[2014.05.14 13:10:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Adina\AppData\Roaming\Mozilla\Firefox\Profiles\lev0xhsv.default\extensions
[2013.07.04 15:17:50 | 000,000,904 | ---- | M] () -- C:\Users\Adina\AppData\Roaming\Mozilla\Firefox\Profiles\e94gfn82.default\searchplugins\yahoo.xml
[2014.05.11 09:30:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2014.05.11 09:30:03 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2014.05.11 09:30:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014.05.11 09:30:02 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2014.05.11 09:30:08 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) -- C:\PROGRAM FILES\IOBIT APPS TOOLBAR\FF
[2014.05.16 06:54:12 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES\MCAFEE\SITEADVISOR
File not found (No name found) -- C:\USERS\ADINA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\E94GFN82.DEFAULT\EXTENSIONS\
[email protected]
[2011.09.16 12:26:02 | 001,825,680 | ---- | M] (Caminova, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdjvu.dll
[2012.06.28 18:42:00 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Adina\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.225\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.71\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.71\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: DjVu Plugin Viewer (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdjvu.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Adina\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.149\npGoogleUpdate3.dll
CHR - plugin: Java Platform SE 7 U25 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Adina\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.16 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - Extension: Advanced SystemCare Surfing Protection = C:\Users\Adina\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd\1.0.0_0\
CHR - Extension: YoWindow Weather = C:\Users\Adina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fanogbnclpilemkifpjeglokomebpnef\1.43_0\
CHR - Extension: SiteAdvisor = C:\Users\Adina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.65.135.1_0\
CHR - Extension: AdBlock = C:\Users\Adina\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.29_0\
CHR - Extension: Skype Click to Call = C:\Users\Adina\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\7.2.15747.10003_0\
O1 HOSTS File: ([2013.08.07 18:57:26 | 000,000,000 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Avira Systray] C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1F6421F5-384B-48E3-9DF6-F92AB8B726DF}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.11 00:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
========== Files/Folders - Created Within 30 Days ==========
[2014.05.18 16:10:00 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\Adina\Desktop\aswMBR.exe
[2014.05.18 16:05:40 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\Windows\System32\sqlite3.dll
[2014.05.18 16:04:44 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014.05.18 15:53:09 | 000,601,088 | ---- | C] (OldTimer Tools) -- C:\Users\Adina\Desktop\OTL (1).exe
[2014.05.16 15:44:05 | 000,000,000 | ---D | C] -- C:\Users\Adina\AppData\Roaming\DropboxMaster
[2014.05.15 12:45:44 | 000,000,000 | ---D | C] -- C:\SUPERDelete
[2014.05.14 15:46:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
[2014.05.14 15:46:58 | 000,000,000 | ---D | C] -- C:\Program Files\Recuva
[2014.05.14 14:44:25 | 000,022,312 | ---- | C] (EldoS Corporation) -- C:\Windows\System32\drivers\rsdrv.sys
[2014.05.14 13:52:45 | 002,724,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014.05.14 13:52:16 | 003,969,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2014.05.14 13:52:16 | 003,914,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2014.05.14 13:52:16 | 000,538,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\objsel.dll
[2014.05.14 13:52:15 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cngprovider.dll
[2014.05.14 13:52:15 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adprovider.dll
[2014.05.14 13:52:15 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\capiprovider.dll
[2014.05.14 13:52:15 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpapiprovider.dll
[2014.05.14 13:52:15 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dimsroam.dll
[2014.05.14 13:52:15 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wincredprovider.dll
[2014.05.14 13:52:15 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
[2014.05.14 13:00:40 | 000,000,000 | -HSD | C] -- C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
[2014.05.14 13:00:39 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2014.05.12 19:03:11 | 000,270,336 | ---- | C] (Intel® Corporation) -- C:\Windows\System32\drivers\IntcDAud.sys
[2014.05.12 19:02:09 | 000,000,000 | ---D | C] -- C:\Intel
[2014.05.12 19:00:41 | 008,196,080 | ---- | C] (Intel® Corporation) -- C:\Windows\System32\TVWSetup.exe
[2014.05.12 19:00:24 | 000,081,920 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxCoIn_v2993.dll
[2014.05.12 19:00:22 | 000,284,160 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrtrk.lrc
[2014.05.12 19:00:22 | 000,260,608 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxTMM.dll
[2014.05.12 19:00:21 | 000,284,672 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrsky.lrc
[2014.05.12 19:00:21 | 000,284,672 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrrus.lrc
[2014.05.12 19:00:21 | 000,284,672 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrrom.lrc
[2014.05.12 19:00:21 | 000,284,672 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrptg.lrc
[2014.05.12 19:00:21 | 000,284,160 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrsve.lrc
[2014.05.12 19:00:21 | 000,284,160 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrslv.lrc
[2014.05.12 19:00:21 | 000,284,160 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrptb.lrc
[2014.05.12 19:00:21 | 000,283,648 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrtha.lrc
[2014.05.12 19:00:20 | 000,284,672 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrplk.lrc
[2014.05.12 19:00:20 | 000,284,672 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrnld.lrc
[2014.05.12 19:00:20 | 000,284,672 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrita.lrc
[2014.05.12 19:00:20 | 000,284,160 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrnor.lrc
[2014.05.12 19:00:20 | 000,281,600 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrjpn.lrc
[2014.05.12 19:00:20 | 000,281,088 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrkor.lrc
[2014.05.12 19:00:19 | 000,285,184 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrfra.lrc
[2014.05.12 19:00:19 | 000,284,672 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrhrv.lrc
[2014.05.12 19:00:19 | 000,284,160 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrhun.lrc
[2014.05.12 19:00:19 | 000,284,160 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrfin.lrc
[2014.05.12 19:00:19 | 000,283,136 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrheb.lrc
[2014.05.12 19:00:18 | 000,285,184 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxresn.lrc
[2014.05.12 19:00:18 | 000,285,184 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrell.lrc
[2014.05.12 19:00:17 | 000,284,672 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrdeu.lrc
[2014.05.12 19:00:17 | 000,284,672 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrcsy.lrc
[2014.05.12 19:00:17 | 000,283,648 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrdan.lrc
[2014.05.12 19:00:17 | 000,283,136 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrara.lrc
[2014.05.12 19:00:17 | 000,280,576 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrcht.lrc
[2014.05.12 19:00:17 | 000,280,576 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxrchs.lrc
[2014.05.12 19:00:16 | 000,246,784 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxcmrt32.dll
[2014.05.12 19:00:16 | 000,130,048 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxdo.dll
[2014.05.12 19:00:16 | 000,120,320 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxcpl.cpl
[2014.05.12 19:00:16 | 000,024,576 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxexps.dll
[2014.05.12 19:00:15 | 002,191,872 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igfxcmjit32.dll
[2014.05.12 19:00:08 | 004,701,168 | ---- | C] (Intel Corporation) -- C:\Windows\System32\GfxUI.exe
[2014.05.12 19:00:07 | 000,147,456 | ---- | C] (Intel Corporation) -- C:\Windows\System32\gfxSrvc.dll
[2014.05.12 18:59:08 | 000,000,000 | ---D | C] -- C:\Windows\System32\RTCOM
[2014.05.12 18:58:33 | 001,783,056 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\WavesLib.dll
[2014.05.12 18:58:32 | 001,823,320 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\WavesGUILib.dll
[2014.05.12 18:58:32 | 001,379,760 | ---- | C] (TOSHIBA Corporation) -- C:\Windows\System32\tosade.dll
[2014.05.12 18:58:32 | 000,819,648 | ---- | C] (TOSHIBA Corporation) -- C:\Windows\System32\tadefxapo2.dll
[2014.05.12 18:58:32 | 000,140,528 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll
[2014.05.12 18:58:32 | 000,134,584 | ---- | C] (TOSHIBA Corporation) -- C:\Windows\System32\tadefxapo.dll
[2014.05.12 18:58:32 | 000,058,264 | ---- | C] (TOSHIBA CORPORATION.) -- C:\Windows\System32\TepeqAPO.dll
[2014.05.12 18:58:31 | 000,345,328 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll
[2014.05.12 18:58:31 | 000,185,584 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSHD.dll
[2014.05.12 18:58:31 | 000,173,296 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSHP360.dll
[2014.05.12 18:58:30 | 000,606,968 | ---- | C] (DTS, Inc.) -- C:\Windows\System32\sltech32.dll
[2014.05.12 18:58:30 | 000,219,896 | ---- | C] (TODO: <Company name>) -- C:\Windows\System32\slprp32.dll
[2014.05.12 18:58:29 | 000,964,856 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\slcnt32.dll
[2014.05.12 18:58:29 | 000,919,600 | ---- | C] (Sony Corporation) -- C:\Windows\System32\SFSS_APO.dll
[2014.05.12 18:58:29 | 000,827,128 | ---- | C] (DTS, Inc.) -- C:\Windows\System32\sl3apo32.dll
[2014.05.12 18:58:29 | 000,214,368 | ---- | C] (Synopsys, Inc.) -- C:\Windows\System32\SFNHK.dll
[2014.05.12 18:58:28 | 000,074,080 | ---- | C] (Synopsys, Inc.) -- C:\Windows\System32\SFCOM.dll
[2014.05.12 18:58:28 | 000,068,960 | ---- | C] (Synopsys, Inc.) -- C:\Windows\System32\SFAPO.dll
[2014.05.12 18:58:27 | 001,892,056 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RTSndMgr.cpl
[2014.05.12 18:58:26 | 002,559,192 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkPgExt.dll
[2014.05.12 18:58:25 | 000,915,160 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoInstII.dll
[2014.05.12 18:58:25 | 000,782,040 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkApoApi.dll
[2014.05.12 18:58:25 | 000,013,416 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoLDR.dll
[2014.05.12 18:58:24 | 002,467,544 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkAPO.dll
[2014.05.12 18:58:23 | 000,359,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEP32A.dll
[2014.05.12 18:58:23 | 000,170,840 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEED32A.dll
[2014.05.12 18:58:23 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEL32A.dll
[2014.05.12 18:58:23 | 000,064,856 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEG32A.dll
[2014.05.12 18:58:22 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DHT32.dll
[2014.05.12 18:58:22 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DAA32.dll
[2014.05.12 18:58:18 | 056,270,336 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RCoRes.dat
[2014.05.12 18:58:17 | 007,162,128 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEP32A.dll
[2014.05.12 18:58:17 | 000,352,016 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EED32A.dll
[2014.05.12 18:58:17 | 000,106,768 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEL32A.dll
[2014.05.12 18:58:17 | 000,091,920 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEA32A.dll
[2014.05.12 18:58:17 | 000,062,224 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEG32A.dll
[2014.05.12 18:58:16 | 005,088,008 | ---- | C] (Nahimic Inc) -- C:\Windows\System32\NAHIMICAPOlfx.dll
[2014.05.12 18:58:16 | 000,890,160 | ---- | C] (Nahimic Inc) -- C:\Windows\System32\NAHIMICAPOSettingsIPC.dll
[2014.05.12 18:58:16 | 000,852,016 | ---- | C] (Sony Corporation) -- C:\Windows\System32\MISS_APO.dll
[2014.05.12 18:58:15 | 000,509,184 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxVolumeSDAPO.dll
[2014.05.12 18:58:13 | 011,736,152 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxVoiceAPO30.dll
[2014.05.12 18:58:13 | 003,650,136 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioVnN.dll
[2014.05.12 18:58:13 | 000,948,336 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxSpeechAPO.dll
[2014.05.12 18:58:13 | 000,785,520 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxVoiceAPO20.dll
[2014.05.12 18:58:11 | 028,031,576 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioVnA.dll
[2014.05.12 18:58:10 | 001,687,128 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioRealtek2.dll
[2014.05.12 18:58:09 | 014,463,064 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioRealtek.dll
[2014.05.12 18:58:08 | 001,936,472 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioEQ.dll
[2014.05.12 18:58:08 | 001,266,776 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO60.dll
[2014.05.12 18:58:08 | 000,874,584 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPOShell.dll
[2014.05.12 18:58:07 | 001,143,408 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO50.dll
[2014.05.12 18:58:07 | 001,143,408 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO40.dll
[2014.05.12 18:58:07 | 000,509,184 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO30.dll
[2014.05.12 18:58:07 | 000,232,792 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO20.dll
[2014.05.12 18:58:07 | 000,132,368 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO.dll
[2014.05.12 18:58:06 | 000,357,712 | ---- | C] (Knowles Acoustics ) -- C:\Windows\System32\KAAPORT.dll
[2014.05.12 18:57:58 | 002,421,792 | ---- | C] (Fortemedia Corporation) -- C:\Windows\System32\FMAPO.dll
[2014.05.12 18:57:58 | 001,509,480 | ---- | C] (DTS) -- C:\Windows\System32\DTSS2SpeakerDLL.dll
[2014.05.12 18:57:58 | 000,631,400 | ---- | C] (DTS) -- C:\Windows\System32\DTSSymmetryDLL.dll
[2014.05.12 18:57:58 | 000,601,704 | ---- | C] (DTS) -- C:\Windows\System32\DTSVoiceClarityDLL.dll
[2014.05.12 18:57:58 | 000,426,944 | ---- | C] (DTS) -- C:\Windows\System32\DTSU2PLFX32.dll
[2014.05.12 18:57:58 | 000,403,392 | ---- | C] (DTS) -- C:\Windows\System32\DTSU2PGFX32.dll
[2014.05.12 18:57:58 | 000,346,048 | ---- | C] (DTS) -- C:\Windows\System32\DTSU2PREC32.dll
[2014.05.12 18:57:57 | 001,292,904 | ---- | C] (DTS) -- C:\Windows\System32\DTSS2HeadphoneDLL.dll
[2014.05.12 18:57:57 | 000,458,344 | ---- | C] (DTS) -- C:\Windows\System32\DTSNeoPCDLL.dll
[2014.05.12 18:57:57 | 000,389,736 | ---- | C] (DTS) -- C:\Windows\System32\DTSGainCompensatorDLL.dll
[2014.05.12 18:57:57 | 000,375,400 | ---- | C] (DTS) -- C:\Windows\System32\DTSLimiterDLL.dll
[2014.05.12 18:57:57 | 000,218,728 | ---- | C] (DTS) -- C:\Windows\System32\DTSGFXAPONS.dll
[2014.05.12 18:57:57 | 000,218,728 | ---- | C] (DTS) -- C:\Windows\System32\DTSGFXAPO.dll
[2014.05.12 18:57:57 | 000,218,216 | ---- | C] (DTS) -- C:\Windows\System32\DTSLFXAPO.dll
[2014.05.12 18:57:56 | 006,176,944 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\DDPP32A.dll
[2014.05.12 18:57:56 | 001,220,200 | ---- | C] (DTS) -- C:\Windows\System32\DTSBoostDLL.dll
[2014.05.12 18:57:56 | 000,654,952 | ---- | C] (DTS) -- C:\Windows\System32\DTSBassEnhancementDLL.dll
[2014.05.12 18:57:55 | 001,489,072 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\DDPD32A.dll
[2014.05.12 18:57:55 | 000,272,048 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\DDPO32A.dll
[2014.05.12 18:57:55 | 000,219,312 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\DDPA32.dll
[2014.05.12 18:57:55 | 000,092,584 | ---- | C] (Real Sound Lab SIA) -- C:\Windows\System32\CONEQMSAPOGUILibrary.dll
[2014.05.12 18:57:54 | 000,095,840 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTARen.dll
[2014.05.12 18:57:53 | 000,182,472 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTACap.dll
[2014.05.12 18:57:11 | 000,076,872 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\System32\RtNicProp32.dll
[2014.05.12 14:13:21 | 000,000,000 | ---D | C] -- C:\Users\Adina\.android
[2014.05.12 14:13:20 | 000,000,000 | ---D | C] -- C:\Users\Adina\AppData\Local\cache
[2014.05.11 12:02:53 | 000,000,000 | ---D | C] -- C:\Users\Adina\Desktop\Teza cu subiect unic sem II 2014 XI-XII
[2014.05.11 09:30:02 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014.05.09 22:59:34 | 000,000,000 | ---D | C] -- C:\Users\Adina\Desktop\zoo
[2014.05.03 08:38:16 | 000,000,000 | ---D | C] -- C:\Users\Adina\Desktop\Fise trimise pt. portofoliu personal 10 F, 10 H 2014
[2014.05.03 08:33:08 | 000,000,000 | ---D | C] -- C:\Users\Adina\Desktop\Diplome Haimovici nat. 2014
[2014.05.02 09:05:25 | 000,000,000 | ---D | C] -- C:\Users\Adina\Desktop\EXERCITII PT BAC din CULEGERE 1 RUXI
[2014.04.30 07:26:00 | 000,000,000 | ---D | C] -- C:\Users\Adina\Desktop\Anca Secasiu
[2014.04.30 07:25:41 | 000,000,000 | ---D | C] -- C:\Users\Adina\Desktop\cornel
[2014.04.29 21:47:49 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014.04.29 21:47:47 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2014.04.29 21:47:47 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2014.04.29 21:47:47 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollectorres.dll
[2014.04.29 21:47:46 | 000,524,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014.04.29 21:47:46 | 000,367,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2014.04.29 21:47:46 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014.04.29 21:47:45 | 000,592,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9diag.dll
[2014.04.29 21:47:45 | 000,575,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2014.04.29 21:47:45 | 000,244,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2014.04.29 21:47:45 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014.04.29 21:47:45 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2014.04.29 21:47:45 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwproxystub.dll
[2014.04.29 21:47:45 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2014.04.29 21:47:45 | 000,032,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\JavaScriptCollectionAgent.dll
[2014.04.29 21:47:44 | 000,646,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2014.04.29 21:47:44 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollector.exe
[2014.04.29 21:47:42 | 001,967,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014.04.29 21:47:40 | 004,254,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014.04.28 17:08:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2014.04.20 10:20:54 | 000,000,000 | ---D | C] -- C:\Users\Adina\Desktop\CEAC 2014
[2014.04.19 09:29:32 | 000,000,000 | ---D | C] -- C:\Users\Adina\Desktop\scoala altfel 2014
[2014.04.19 09:06:48 | 000,000,000 | ---D | C] -- C:\Users\Adina\Desktop\SUBIECTE ADMITERE POLITEHNICA
========== Files - Modified Within 30 Days ==========
[2014.05.18 16:10:12 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\Adina\Desktop\aswMBR.exe
[2014.05.18 16:08:35 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2014.05.18 16:07:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.05.18 16:07:40 | 2660,880,384 | -HS- | M] () -- C:\hiberfil.sys
[2014.05.18 16:07:05 | 000,019,040 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.05.18 16:07:05 | 000,019,040 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.05.18 16:04:23 | 001,325,827 | ---- | M] () -- C:\Users\Adina\Desktop\AdwCleaner.exe
[2014.05.18 15:53:12 | 000,601,088 | ---- | M] (OldTimer Tools) -- C:\Users\Adina\Desktop\OTL (1).exe
[2014.05.18 15:41:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.05.18 15:29:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.05.15 03:30:29 | 007,400,819 | ---- | M] () -- C:\Users\Adina\Desktop\SUBIECTE ADMITERE POLITEHNICA.rar
[2014.05.14 14:10:32 | 000,000,884 | RHS- | M] () -- C:\Users\Adina\ntuser.pol
[2014.05.13 23:29:06 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014.05.13 23:29:06 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014.05.12 20:54:52 | 000,002,673 | ---- | M] () -- C:\Users\Public\Desktop\FotoCanvas.lnk
[2014.05.12 19:03:11 | 000,270,336 | ---- | M] (Intel® Corporation) -- C:\Windows\System32\drivers\IntcDAud.sys
[2014.05.12 19:00:42 | 008,196,080 | ---- | M] (Intel® Corporation) -- C:\Windows\System32\TVWSetup.exe
[2014.05.12 19:00:24 | 000,081,920 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxCoIn_v2993.dll
[2014.05.12 19:00:24 | 000,076,472 | ---- | M] () -- C:\Windows\System32\iglhxs32.vp
[2014.05.12 19:00:22 | 000,284,160 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrtrk.lrc
[2014.05.12 19:00:22 | 000,260,608 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxTMM.dll
[2014.05.12 19:00:22 | 000,057,856 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.dll
[2014.05.12 19:00:21 | 000,284,672 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrsky.lrc
[2014.05.12 19:00:21 | 000,284,672 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrrus.lrc
[2014.05.12 19:00:21 | 000,284,672 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrrom.lrc
[2014.05.12 19:00:21 | 000,284,672 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrptg.lrc
[2014.05.12 19:00:21 | 000,284,160 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrsve.lrc
[2014.05.12 19:00:21 | 000,284,160 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrslv.lrc
[2014.05.12 19:00:21 | 000,284,160 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrptb.lrc
[2014.05.12 19:00:21 | 000,283,648 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrtha.lrc
[2014.05.12 19:00:20 | 000,284,672 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrplk.lrc
[2014.05.12 19:00:20 | 000,284,672 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrnld.lrc
[2014.05.12 19:00:20 | 000,284,672 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrita.lrc
[2014.05.12 19:00:20 | 000,284,160 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrnor.lrc
[2014.05.12 19:00:20 | 000,284,160 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrhun.lrc
[2014.05.12 19:00:20 | 000,281,600 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrjpn.lrc
[2014.05.12 19:00:20 | 000,281,088 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrkor.lrc
[2014.05.12 19:00:19 | 000,285,184 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrfra.lrc
[2014.05.12 19:00:19 | 000,284,672 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrhrv.lrc
[2014.05.12 19:00:19 | 000,284,160 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrfin.lrc
[2014.05.12 19:00:19 | 000,283,136 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrheb.lrc
[2014.05.12 19:00:18 | 009,030,656 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxress.dll
[2014.05.12 19:00:18 | 000,285,184 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxresn.lrc
[2014.05.12 19:00:18 | 000,285,184 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrell.lrc
[2014.05.12 19:00:17 | 000,306,688 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxpph.dll
[2014.05.12 19:00:17 | 000,284,672 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrdeu.lrc
[2014.05.12 19:00:17 | 000,284,672 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrcsy.lrc
[2014.05.12 19:00:17 | 000,283,648 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrdan.lrc
[2014.05.12 19:00:17 | 000,283,136 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrara.lrc
[2014.05.12 19:00:17 | 000,280,576 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrcht.lrc
[2014.05.12 19:00:17 | 000,280,576 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxrchs.lrc
[2014.05.12 19:00:16 | 000,246,784 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxcmrt32.dll
[2014.05.12 19:00:16 | 000,130,048 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxdo.dll
[2014.05.12 19:00:16 | 000,120,320 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxcpl.cpl
[2014.05.12 19:00:16 | 000,024,576 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxexps.dll
[2014.05.12 19:00:16 | 000,004,096 | ---- | M] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2014.05.12 19:00:15 | 002,191,872 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxcmjit32.dll
[2014.05.12 19:00:15 | 000,581,120 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igdumdx32.dll
[2014.05.12 19:00:14 | 006,324,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igdumd32.dll
[2014.05.12 19:00:12 | 007,988,224 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igd10umd32.dll
[2014.05.12 19:00:10 | 013,913,600 | ---- | M] () -- C:\Windows\System32\ig4icd32.dll
[2014.05.12 19:00:09 | 000,096,256 | ---- | M] (Intel Corporation) -- C:\Windows\System32\hccutils.dll
[2014.05.12 19:00:09 | 000,000,146 | ---- | M] () -- C:\Windows\System32\GfxUI.exe.config
[2014.05.12 19:00:08 | 004,701,168 | ---- | M] (Intel Corporation) -- C:\Windows\System32\GfxUI.exe
[2014.05.12 19:00:08 | 000,147,456 | ---- | M] (Intel Corporation) -- C:\Windows\System32\gfxSrvc.dll
[2014.05.12 19:00:06 | 000,136,603 | ---- | M] () -- C:\Windows\System32\Gfxres.ro-RO.resources
[2014.05.12 19:00:05 | 000,131,839 | ---- | M] () -- C:\Windows\System32\Gfxres.hr-HR.resources
[2014.05.12 19:00:05 | 000,124,052 | ---- | M] () -- C:\Windows\System32\Gfxres.en-US.resources
[2014.05.12 18:58:33 | 001,783,056 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\WavesLib.dll
[2014.05.12 18:58:32 | 001,823,320 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\WavesGUILib.dll
[2014.05.12 18:58:32 | 001,379,760 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\tosade.dll
[2014.05.12 18:58:32 | 000,819,648 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\tadefxapo2.dll
[2014.05.12 18:58:32 | 000,345,328 | ---- | M] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll
[2014.05.12 18:58:32 | 000,140,528 | ---- | M] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll
[2014.05.12 18:58:32 | 000,134,584 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\tadefxapo.dll
[2014.05.12 18:58:32 | 000,058,264 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Windows\System32\TepeqAPO.dll
[2014.05.12 18:58:31 | 000,185,584 | ---- | M] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSHD.dll
[2014.05.12 18:58:31 | 000,173,296 | ---- | M] (SRS Labs, Inc.) -- C:\Windows\System32\SRSHP360.dll
[2014.05.12 18:58:30 | 000,606,968 | ---- | M] (DTS, Inc.) -- C:\Windows\System32\sltech32.dll
[2014.05.12 18:58:30 | 000,219,896 | ---- | M] (TODO: <Company name>) -- C:\Windows\System32\slprp32.dll
[2014.05.12 18:58:29 | 000,964,856 | ---- | M] (SRS Labs, Inc.) -- C:\Windows\System32\slcnt32.dll
[2014.05.12 18:58:29 | 000,919,600 | ---- | M] (Sony Corporation) -- C:\Windows\System32\SFSS_APO.dll
[2014.05.12 18:58:29 | 000,827,128 | ---- | M] (DTS, Inc.) -- C:\Windows\System32\sl3apo32.dll
[2014.05.12 18:58:29 | 000,214,368 | ---- | M] (Synopsys, Inc.) -- C:\Windows\System32\SFNHK.dll
[2014.05.12 18:58:28 | 005,804,772 | ---- | M] () -- C:\Windows\System32\drivers\rtvienna.dat
[2014.05.12 18:58:28 | 000,074,080 | ---- | M] (Synopsys, Inc.) -- C:\Windows\System32\SFCOM.dll
[2014.05.12 18:58:28 | 000,068,960 | ---- | M] (Synopsys, Inc.) -- C:\Windows\System32\SFAPO.dll
[2014.05.12 18:58:27 | 001,892,056 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RTSndMgr.cpl
[2014.05.12 18:58:26 | 002,559,192 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkPgExt.dll
[2014.05.12 18:58:25 | 000,915,160 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoInstII.dll
[2014.05.12 18:58:25 | 000,782,040 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkApoApi.dll
[2014.05.12 18:58:25 | 000,013,416 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoLDR.dll
[2014.05.12 18:58:24 | 002,467,544 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkAPO.dll
[2014.05.12 18:58:23 | 000,359,768 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEP32A.dll
[2014.05.12 18:58:23 | 000,170,840 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEED32A.dll
[2014.05.12 18:58:23 | 000,078,680 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEL32A.dll
[2014.05.12 18:58:23 | 000,064,856 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEG32A.dll
[2014.05.12 18:58:22 | 000,757,301 | ---- | M] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2014.05.12 18:58:22 | 000,295,768 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DHT32.dll
[2014.05.12 18:58:22 | 000,295,768 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DAA32.dll
[2014.05.12 18:58:18 | 056,270,336 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RCoRes.dat
[2014.05.12 18:58:17 | 007,162,128 | ---- | M] (Dolby Laboratories) -- C:\Windows\System32\R4EEP32A.dll
[2014.05.12 18:58:17 | 000,352,016 | ---- | M] (Dolby Laboratories) -- C:\Windows\System32\R4EED32A.dll
[2014.05.12 18:58:17 | 000,106,768 | ---- | M] (Dolby Laboratories) -- C:\Windows\System32\R4EEL32A.dll
[2014.05.12 18:58:17 | 000,091,920 | ---- | M] (Dolby Laboratories) -- C:\Windows\System32\R4EEA32A.dll
[2014.05.12 18:58:17 | 000,062,224 | ---- | M] (Dolby Laboratories) -- C:\Windows\System32\R4EEG32A.dll
[2014.05.12 18:58:16 | 005,088,008 | ---- | M] (Nahimic Inc) -- C:\Windows\System32\NAHIMICAPOlfx.dll
[2014.05.12 18:58:16 | 000,890,160 | ---- | M] (Nahimic Inc) -- C:\Windows\System32\NAHIMICAPOSettingsIPC.dll
[2014.05.12 18:58:16 | 000,852,016 | ---- | M] (Sony Corporation) -- C:\Windows\System32\MISS_APO.dll
[2014.05.12 18:58:15 | 000,509,184 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxVolumeSDAPO.dll
[2014.05.12 18:58:14 | 011,736,152 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxVoiceAPO30.dll
[2014.05.12 18:58:13 | 003,650,136 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioVnN.dll
[2014.05.12 18:58:13 | 000,948,336 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxSpeechAPO.dll
[2014.05.12 18:58:13 | 000,785,520 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxVoiceAPO20.dll
[2014.05.12 18:58:11 | 028,031,576 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioVnA.dll
[2014.05.12 18:58:10 | 001,687,128 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioRealtek2.dll
[2014.05.12 18:58:09 | 014,463,064 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioRealtek.dll
[2014.05.12 18:58:08 | 001,936,472 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioEQ.dll
[2014.05.12 18:58:08 | 001,266,776 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO60.dll
[2014.05.12 18:58:08 | 000,874,584 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPOShell.dll
[2014.05.12 18:58:07 | 001,143,408 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO50.dll
[2014.05.12 18:58:07 | 001,143,408 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO40.dll
[2014.05.12 18:58:07 | 000,509,184 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO30.dll
[2014.05.12 18:58:07 | 000,232,792 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO20.dll
[2014.05.12 18:58:07 | 000,132,368 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO.dll
[2014.05.12 18:58:06 | 000,357,712 | ---- | M] (Knowles Acoustics ) -- C:\Windows\System32\KAAPORT.dll
[2014.05.12 18:57:58 | 002,421,792 | ---- | M] (Fortemedia Corporation) -- C:\Windows\System32\FMAPO.dll
[2014.05.12 18:57:58 | 001,509,480 | ---- | M] (DTS) -- C:\Windows\System32\DTSS2SpeakerDLL.dll
[2014.05.12 18:57:58 | 000,631,400 | ---- | M] (DTS) -- C:\Windows\System32\DTSSymmetryDLL.dll
[2014.05.12 18:57:58 | 000,601,704 | ---- | M] (DTS) -- C:\Windows\System32\DTSVoiceClarityDLL.dll
[2014.05.12 18:57:58 | 000,426,944 | ---- | M] (DTS) -- C:\Windows\System32\DTSU2PLFX32.dll
[2014.05.12 18:57:58 | 000,403,392 | ---- | M] (DTS) -- C:\Windows\System32\DTSU2PGFX32.dll
[2014.05.12 18:57:58 | 000,346,048 | ---- | M] (DTS) -- C:\Windows\System32\DTSU2PREC32.dll
[2014.05.12 18:57:57 | 001,292,904 | ---- | M] (DTS) -- C:\Windows\System32\DTSS2HeadphoneDLL.dll
[2014.05.12 18:57:57 | 000,458,344 | ---- | M] (DTS) -- C:\Windows\System32\DTSNeoPCDLL.dll
[2014.05.12 18:57:57 | 000,389,736 | ---- | M] (DTS) -- C:\Windows\System32\DTSGainCompensatorDLL.dll
[2014.05.12 18:57:57 | 000,375,400 | ---- | M] (DTS) -- C:\Windows\System32\DTSLimiterDLL.dll
[2014.05.12 18:57:57 | 000,218,728 | ---- | M] (DTS) -- C:\Windows\System32\DTSGFXAPONS.dll
[2014.05.12 18:57:57 | 000,218,728 | ---- | M] (DTS) -- C:\Windows\System32\DTSGFXAPO.dll
[2014.05.12 18:57:57 | 000,218,216 | ---- | M] (DTS) -- C:\Windows\System32\DTSLFXAPO.dll
[2014.05.12 18:57:56 | 006,176,944 | ---- | M] (Dolby Laboratories) -- C:\Windows\System32\DDPP32A.dll
[2014.05.12 18:57:56 | 001,220,200 | ---- | M] (DTS) -- C:\Windows\System32\DTSBoostDLL.dll
[2014.05.12 18:57:56 | 000,654,952 | ---- | M] (DTS) -- C:\Windows\System32\DTSBassEnhancementDLL.dll
[2014.05.12 18:57:55 | 001,489,072 | ---- | M] (Dolby Laboratories) -- C:\Windows\System32\DDPD32A.dll
[2014.05.12 18:57:55 | 000,272,048 | ---- | M] (Dolby Laboratories) -- C:\Windows\System32\DDPO32A.dll
[2014.05.12 18:57:55 | 000,219,312 | ---- | M] (Dolby Laboratories) -- C:\Windows\System32\DDPA32.dll
[2014.05.12 18:57:55 | 000,092,584 | ---- | M] (Real Sound Lab SIA) -- C:\Windows\System32\CONEQMSAPOGUILibrary.dll
[2014.05.12 18:57:54 | 000,502,584 | ---- | M] () -- C:\Windows\System32\audioLibVc.dll
[2014.05.12 18:57:54 | 000,095,840 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTARen.dll
[2014.05.12 18:57:53 | 000,188,696 | ---- | M] () -- C:\Windows\System32\AcpiServiceVnA.dll
[2014.05.12 18:57:53 | 000,182,472 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTACap.dll
[2014.05.12 18:57:11 | 000,100,896 | ---- | M] (Realtek Semiconductor Corporation) -- C:\Windows\System32\RTNUninst32.dll
[2014.05.12 18:57:11 | 000,076,872 | ---- | M] (Realtek Semiconductor Corporation) -- C:\Windows\System32\RtNicProp32.dll
[2014.05.12 14:29:29 | 000,000,266 | ---- | M] () -- C:\Windows\tasks\Uninstaller_SkipUac_Administrator.job
[2014.05.09 14:58:18 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1cf6b7df7503398.job
[2014.05.06 06:07:39 | 002,724,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014.05.05 20:12:22 | 000,748,684 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2014.05.05 20:12:22 | 000,665,304 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014.05.05 20:12:22 | 000,150,548 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2014.05.05 20:12:22 | 000,123,112 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014.04.30 07:02:34 | 000,041,848 | ---- | M] () -- C:\Users\Adina\Desktop\Teza11_semII_2014.pdf
[2014.04.28 17:09:25 | 000,000,973 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014.04.28 16:53:03 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2014.04.28 16:53:03 | 000,176,040 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2014.04.28 16:53:03 | 000,176,040 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2014.04.28 16:53:03 | 000,096,680 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
========== Files Created - No Company Name ==========
[2014.05.18 16:04:14 | 001,325,827 | ---- | C] () -- C:\Users\Adina\Desktop\AdwCleaner.exe
[2014.05.15 03:30:26 | 007,400,819 | ---- | C] () -- C:\Users\Adina\Desktop\SUBIECTE ADMITERE POLITEHNICA.rar
[2014.05.12 19:00:24 | 000,076,472 | ---- | C] () -- C:\Windows\System32\iglhxs32.vp
[2014.05.12 19:00:16 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2014.05.12 19:00:10 | 013,913,600 | ---- | C] () -- C:\Windows\System32\ig4icd32.dll
[2014.05.12 19:00:09 | 000,000,146 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2014.05.12 19:00:06 | 000,136,603 | ---- | C] () -- C:\Windows\System32\Gfxres.ro-RO.resources
[2014.05.12 19:00:05 | 000,131,839 | ---- | C] () -- C:\Windows\System32\Gfxres.hr-HR.resources
[2014.05.12 19:00:04 | 000,124,052 | ---- | C] () -- C:\Windows\System32\Gfxres.en-US.resources
[2014.05.12 18:58:27 | 005,804,772 | ---- | C] () -- C:\Windows\System32\drivers\rtvienna.dat
[2014.05.12 18:58:22 | 000,757,301 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2014.05.12 18:57:54 | 000,502,584 | ---- | C] () -- C:\Windows\System32\audioLibVc.dll
[2014.05.12 18:57:53 | 000,188,696 | ---- | C] () -- C:\Windows\System32\AcpiServiceVnA.dll
[2014.05.12 14:29:29 | 000,000,266 | ---- | C] () -- C:\Windows\tasks\Uninstaller_SkipUac_Administrator.job
[2014.05.09 14:58:18 | 000,000,882 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1cf6b7df7503398.job
[2014.04.30 07:02:33 | 000,041,848 | ---- | C] () -- C:\Users\Adina\Desktop\Teza11_semII_2014.pdf
[2014.04.17 21:39:19 | 000,038,434 | ---- | C] () -- C:\Users\Adina\AppData\Roaming\Microsoft Excel 97-2003.ADR
[2014.04.17 21:37:47 | 000,038,443 | ---- | C] () -- C:\Users\Adina\AppData\Roaming\Comma Separated Values (Windows).ADR
[2013.07.14 00:13:58 | 000,000,175 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys.sum
[2013.07.14 00:13:58 | 000,000,175 | ---- | C] () -- C:\Windows\System32\drivers\aswSP.sys.sum
[2013.07.14 00:13:58 | 000,000,175 | ---- | C] () -- C:\Windows\System32\drivers\aswSnx.sys.sum
[2013.07.05 05:31:20 | 000,000,031 | ---- | C] () -- C:\Windows\System32\wspspodsini.dll
[2013.07.05 05:28:42 | 000,000,530 | ---- | C] () -- C:\Windows\System32\tx14_ic.ini
[2013.07.05 05:27:58 | 000,000,884 | RHS- | C] () -- C:\Users\Adina\ntuser.pol
[2013.02.18 19:39:36 | 000,040,344 | ---- | C] () -- C:\Windows\System32\drivers\stdriverx86.sys
[2012.11.07 19:25:56 | 000,000,207 | ---- | C] () -- C:\Windows\tweaking.com-regbackup-ADINA-PC-Microsoft-Windows-7-Enterprise-(32-bit).dat
[2012.07.08 16:02:21 | 000,000,088 | ---- | C] () -- C:\Users\Adina\AppData\Roaming\usb.inf
[2011.12.15 22:30:41 | 000,000,000 | ---- | C] () -- C:\Users\Adina\AppData\Roaming\Filesystems
[2011.12.15 22:30:41 | 000,000,000 | ---- | C] () -- C:\Users\Adina\AppData\Roaming\External Build System
[2011.04.17 14:02:14 | 000,004,009 | ---- | C] () -- C:\Users\Adina\AppData\Local\iforex.config
[2011.03.26 22:06:40 | 000,033,134 | ---- | C] () -- C:\Users\Adina\AppData\Roaming\UserTile.png
[2011.02.19 15:57:07 | 000,023,552 | ---- | C] () -- C:\Users\Adina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.01.09 19:57:00 | 000,004,096 | ---- | C] () -- C:\Users\Adina\AppData\Local\keyfile3.drm
[2010.12.29 16:04:21 | 000,007,663 | ---- | C] () -- C:\Users\Adina\AppData\Local\Resmon.ResmonCfg
========== ZeroAccess Check ==========
[2009.07.14 07:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014.03.25 05:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\Windows\system32\wbem\fastprox.dll -- [2010.11.20 15:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\Windows\system32\wbem\wbemess.dll -- [2009.07.14 04:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Custom Scans ==========
========== Base Services ==========
SRV - [2009.07.14 04:14:53 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\aelupsvc.dll -- (AeLookupSvc)
SRV - [2013.02.27 07:49:16 | 000,047,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\appinfo.dll -- (Appinfo)
SRV - [2009.07.14 04:14:11 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\alg.exe -- (ALG)
SRV - [2010.11.20 15:20:58 | 000,585,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\qmgr.dll -- (BITS)
SRV - [2010.11.20 15:18:06 | 000,494,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\BFE.DLL -- (BFE)
SRV - [2014.04.12 05:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\lsass.exe -- (KeyIso)
SRV - [2009.07.14 04:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\es.dll -- (EventSystem)
SRV - [2012.07.05 00:14:34 | 000,102,912 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\browser.dll -- (Browser)
SRV - [2013.07.09 07:46:31 | 000,140,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cryptsvc.dll -- (CryptSvc)
SRV - [2010.11.20 15:21:03 | 000,376,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (DcomLaunch)
SRV - [2010.11.20 15:18:30 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2011.03.03 08:38:01 | 000,132,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dnsrslvr.dll -- (Dnscache)
SRV - [2009.07.14 04:15:13 | 000,098,304 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\eapsvc.dll -- (EapHost)
SRV - [2009.07.14 04:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\hidserv.dll -- (hidserv)
SRV - [2009.07.14 04:15:33 | 000,300,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess)
SRV - [2010.11.20 15:19:23 | 000,350,208 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV - [2009.07.14 04:16:15 | 000,313,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\swprv.dll -- (swprv)
SRV - [2009.07.14 04:15:41 | 000,049,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\mmcss.dll -- (MMCSS)
SRV - [2009.07.14 04:16:03 | 000,280,576 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netman.dll -- (Netman)
SRV - [2009.07.14 04:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netprofm.dll -- (netprofm)
SRV - [2010.11.20 15:20:30 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nlasvc.dll -- (NlaSvc)
SRV - [2009.07.14 04:16:11 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nsisvc.dll -- (nsi)
SRV - [2011.05.24 13:44:59 | 000,293,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpnpmgr.dll -- (PlugPlay)
SRV - [2012.02.11 08:37:49 | 000,317,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\spoolsv.exe -- (Spooler)
SRV - [2014.04.12 05:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV - [2009.07.14 04:16:12 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasauto.dll -- (RasAuto)
SRV - [2010.11.20 15:21:00 | 000,286,208 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\rasmans.dll -- (RasMan)
SRV - [2010.11.20 15:21:03 | 000,376,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (RpcSs)
SRV - [2009.07.14 04:16:13 | 000,021,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\seclogon.dll -- (seclogon)
SRV - [2014.04.12 05:11:22 | 000,022,528 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsass.exe -- (SamSs)
SRV - [2009.07.14 04:16:20 | 000,073,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wscsvc.dll -- (wscsvc)
SRV - [2010.11.20 15:21:26 | 000,168,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\srvsvc.dll -- (LanmanServer)
SRV - [2010.11.20 15:21:19 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV - [2010.11.20 15:21:05 | 000,750,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\schedsvc.dll -- (Schedule)
SRV - [2010.11.20 15:21:28 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\tapisrv.dll -- (TapiSrv)
SRV - [2009.07.14 04:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2012.05.01 07:44:12 | 000,164,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\profsvc.dll -- (ProfSvc)
SRV - [2010.11.20 15:17:51 | 001,025,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\VSSVC.exe -- (VSS)
SRV - [2010.11.20 15:18:05 | 000,473,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (Audiosrv)
SRV - [2010.11.20 15:18:05 | 000,473,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (AudioEndpointBuilder)
SRV - [2010.11.20 15:21:06 | 000,125,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sdrsvc.dll -- (SDRSVC)
SRV - [2013.05.27 07:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2010.11.20 15:21:35 | 001,086,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wevtsvc.dll -- (eventlog)
SRV - [2010.11.20 15:19:40 | 000,566,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\MPSSVC.dll -- (MpsSvc)
SRV - [2010.11.20 15:21:35 | 000,463,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wiaservc.dll -- (StiSvc)
No service found with a name of msiserver
SRV - [2009.07.14 04:16:19 | 000,168,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wbem\WMIsvc.dll -- (Winmgmt)
SRV - [2012.06.03 01:19:17 | 001,933,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wuaueng.dll -- (wuauserv)
SRV - [2010.11.20 15:18:34 | 000,214,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dot3svc.dll -- (dot3svc)
SRV - [2009.07.14 04:16:19 | 000,829,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wlansvc.dll -- (Wlansvc)
SRV - [2010.11.20 15:21:36 | 000,084,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wkssvc.dll -- (LanmanWorkstation)
< %SYSTEMDRIVE%\*.exe >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Windows7
Volume Serial Number is 80D0-7A6B
Directory of C:\
29.12.2010 15:50 <JUNCTION> Documents and Settings [..]
0 File(s) 0 bytes
Directory of C:\ProgramData
29.12.2010 15:50 <JUNCTION> Application Data [..]
29.12.2010 15:50 <JUNCTION> Desktop [..]
29.12.2010 15:50 <JUNCTION> Favorites [..]
29.12.2010 15:50 <JUNCTION> Start Menu [..]
29.12.2010 15:50 <JUNCTION> Templates [..]
0 File(s) 0 bytes
Directory of C:\Users
29.12.2010 15:50 <SYMLINKD> All Users [C:\ProgramData]
29.12.2010 15:50 <JUNCTION> Default User [..]
0 File(s) 0 bytes
Directory of C:\Users\Adina
29.12.2010 15:50 <JUNCTION> Application Data [C:\Users\Adina\AppData\Roaming]
29.12.2010 15:50 <JUNCTION> Cookies [C:\Users\Adina\AppData\Roaming\Microsoft\Windows\Cookies]
29.12.2010 15:50 <JUNCTION> Local Settings [C:\Users\Adina\AppData\Local]
29.12.2010 15:50 <JUNCTION> My Documents [C:\Users\Adina\Documents]
29.12.2010 15:50 <JUNCTION> NetHood [C:\Users\Adina\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
29.12.2010 15:50 <JUNCTION> PrintHood [C:\Users\Adina\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
29.12.2010 15:50 <JUNCTION> Recent [C:\Users\Adina\AppData\Roaming\Microsoft\Windows\Recent]
29.12.2010 15:50 <JUNCTION> SendTo [C:\Users\Adina\AppData\Roaming\Microsoft\Windows\SendTo]
29.12.2010 15:50 <JUNCTION> Start Menu [C:\Users\Adina\AppData\Roaming\Microsoft\Windows\Start Menu]
29.12.2010 15:50 <JUNCTION> Templates [C:\Users\Adina\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Adina\AppData\Local
29.12.2010 15:50 <JUNCTION> Application Data [C:\Users\Adina\AppData\Local]
29.12.2010 15:50 <JUNCTION> History [C:\Users\Adina\AppData\Local\Microsoft\Windows\History]
29.12.2010 15:50 <JUNCTION> Temporary Internet Files [C:\Users\Adina\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Adina\Documents
29.12.2010 15:50 <JUNCTION> My Music [C:\Users\Adina\Music]
29.12.2010 15:50 <JUNCTION> My Pictures [C:\Users\Adina\Pictures]
29.12.2010 15:50 <JUNCTION> My Videos [C:\Users\Adina\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Administrator
31.12.2010 02:16 <JUNCTION> Application Data [C:\Users\Administrator\AppData\Roaming]
31.12.2010 02:16 <JUNCTION> Cookies [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies]
31.12.2010 02:16 <JUNCTION> Local Settings [C:\Users\Administrator\AppData\Local]
31.12.2010 02:16 <JUNCTION> My Documents [C:\Users\Administrator\Documents]
31.12.2010 02:16 <JUNCTION> NetHood [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
31.12.2010 02:16 <JUNCTION> PrintHood [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
31.12.2010 02:16 <JUNCTION> Recent [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent]
31.12.2010 02:16 <JUNCTION> SendTo [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo]
31.12.2010 02:16 <JUNCTION> Start Menu [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu]
31.12.2010 02:16 <JUNCTION> Templates [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Administrator\AppData\Local
31.12.2010 02:16 <JUNCTION> Application Data [C:\Users\Administrator\AppData\Local]
31.12.2010 02:16 <JUNCTION> History [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History]
31.12.2010 02:16 <JUNCTION> Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Administrator\Documents
31.12.2010 02:16 <JUNCTION> My Music [C:\Users\Administrator\Music]
31.12.2010 02:16 <JUNCTION> My Pictures [C:\Users\Administrator\Pictures]
31.12.2010 02:16 <JUNCTION> My Videos [C:\Users\Administrator\Videos]
0 File(s) 0 bytes
Directory of C:\Users\All Users
29.12.2010 15:50 <JUNCTION> Application Data [..]
29.12.2010 15:50 <JUNCTION> Desktop [..]
29.12.2010 15:50 <JUNCTION> Favorites [..]
29.12.2010 15:50 <JUNCTION> Start Menu [..]
29.12.2010 15:50 <JUNCTION> Templates [..]
0 File(s) 0 bytes
Directory of C:\Users\Default
29.12.2010 15:50 <JUNCTION> Application Data [..]
29.12.2010 15:50 <JUNCTION> Local Settings [..]
29.12.2010 15:50 <JUNCTION> My Documents [..]
29.12.2010 15:50 <JUNCTION> NetHood [..]
29.12.2010 15:50 <JUNCTION> PrintHood [..]
29.12.2010 15:50 <JUNCTION> Recent [..]
29.12.2010 15:50 <JUNCTION> SendTo [..]
29.12.2010 15:50 <JUNCTION> Start Menu [..]
29.12.2010 15:50 <JUNCTION> Templates [..]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
29.12.2010 15:50 <JUNCTION> Application Data [..]
29.12.2010 15:50 <JUNCTION> History [..]
29.12.2010 15:50 <JUNCTION> Temporary Internet Files [..]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
29.12.2010 15:50 <JUNCTION> My Music [..]
29.12.2010 15:50 <JUNCTION> My Pictures [..]
29.12.2010 15:50 <JUNCTION> My Videos [..]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
29.12.2010 15:50 <JUNCTION> My Music [C:\Users\Public\Music]
29.12.2010 15:50 <JUNCTION> My Pictures [C:\Users\Public\Pictures]
29.12.2010 15:50 <JUNCTION> My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile
15.12.2011 22:31 <JUNCTION> Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
15.12.2011 22:31 <JUNCTION> Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
15.12.2011 22:31 <JUNCTION> My Documents [C:\Windows\system32\config\systemprofile\Documents]
15.12.2011 22:31 <JUNCTION> NetHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
15.12.2011 22:31 <JUNCTION> PrintHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
15.12.2011 22:31 <JUNCTION> Recent [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent]
15.12.2011 22:31 <JUNCTION> SendTo [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo]
15.12.2011 22:31 <JUNCTION> Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
15.12.2011 22:31 <JUNCTION> Templates [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\AppData\Local
15.12.2011 22:31 <JUNCTION> Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
15.12.2011 22:31 <JUNCTION> History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
15.12.2011 22:31 <JUNCTION> Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\Documents
15.12.2011 22:31 <JUNCTION> My Music [C:\Windows\system32\config\systemprofile\Music]
15.12.2011 22:31 <JUNCTION> My Pictures [C:\Windows\system32\config\systemprofile\Pictures]
15.12.2011 22:31 <JUNCTION> My Videos [C:\Windows\system32\config\systemprofile\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
78 Dir(s) 25.351.630.848 bytes free
< MD5 for: EXPLORER.EXE >
[2011.02.26 08:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010.11.20 15:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011.02.25 08:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\erdnt\cache\explorer.exe
[2011.02.25 08:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\explorer.exe
[2011.02.25 08:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
< MD5 for: SERVICES >
[2009.06.11 00:39:37 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\System32\drivers\etc\services
[2009.06.11 00:39:37 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
< MD5 for: SERVICES.ASFX >
[2013.09.05 17:04:32 | 000,002,537 | ---- | M] () MD5=12119C94DF8D736A53F6C331FD72D46E -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\sl_SI\Services\Services.asfx
[2013.09.05 17:04:20 | 000,002,491 | ---- | M] () MD5=137C7EE24F5411F53B8326B9B219FC66 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\nb_NO\Services\Services.asfx
[2013.09.05 17:04:32 | 000,002,646 | ---- | M] () MD5=1C24FB4029C5A7955E15B54B554F57EF -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\ro_RO\Services\Services.asfx
[2013.09.05 17:04:30 | 000,002,514 | ---- | M] () MD5=1DEE0ACF57AF9BCA6EF55DB87DE5177D -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\hr_HR\Services\Services.asfx
[2013.09.05 17:04:30 | 000,003,372 | ---- | M] () MD5=25FC40F1B20BA96E94362080824538BB -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\ru_RU\Services\Services.asfx
[2013.09.05 17:04:16 | 000,002,626 | ---- | M] () MD5=2FD7F2FDEF0BA1B3080372C092348748 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\nl_NL\Services\Services.asfx
[2013.09.05 17:04:12 | 000,002,531 | ---- | M] () MD5=3245B95570BB6FBB531E2FEDF48A75C0 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\it_IT\Services\Services.asfx
[2013.09.05 17:04:18 | 000,002,575 | ---- | M] () MD5=41E9C3CD70C83B6E2120F86B813E45D6 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\fi_FI\Services\Services.asfx
[2013.09.05 17:04:38 | 000,002,495 | ---- | M] () MD5=5023B9592E48988B41AE03208E6E11BF -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\eu_ES\Services\Services.asfx
[2013.09.05 17:04:22 | 000,002,651 | ---- | M] () MD5=529CE83F2FA3AB06251EAA5DB897D096 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\ko_KR\Services\Services.asfx
[2013.09.05 17:04:28 | 000,002,758 | ---- | M] () MD5=5BF29BD056628A88C25959BA80EE9BED -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\hu_HU\Services\Services.asfx
[2013.09.05 17:04:36 | 000,002,541 | ---- | M] () MD5=5EA0637B4A389696A7D809C3E9EC2EC7 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\ca_ES\Services\Services.asfx
[2013.09.05 17:04:34 | 000,003,262 | ---- | M] () MD5=67A74DCD86C142D2E6B4F1F16E5E1F2C -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\uk_UA\Services\Services.asfx
[2013.09.05 17:04:26 | 000,002,617 | ---- | M] () MD5=689F53EAA80054DF4BC686856E185035 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\cs_CZ\Services\Services.asfx
[2013.09.05 17:04:24 | 000,002,486 | ---- | M] () MD5=69DBB0C500BD18C1D0764FB0242ED213 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\zh_TW\Services\Services.asfx
[2013.09.05 17:04:34 | 000,002,638 | ---- | M] () MD5=71B6B0BD0214C789D3F301EE790A6D2F -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\sk_SK\Services\Services.asfx
[2013.09.05 17:04:14 | 000,002,554 | ---- | M] () MD5=74339E2CE2536875C3C678B0CAF6EC51 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\sv_SE\Services\Services.asfx
[2013.09.05 17:04:30 | 000,002,599 | ---- | M] () MD5=83107AFE70C6D6EEB7C079CCCCE406D7 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\tr_TR\Services\Services.asfx
[2013.09.05 17:04:12 | 000,002,849 | ---- | M] () MD5=86BBDCD8357F52C31C289EDEC9B158FF -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\ja_JP\Services\Services.asfx
[2012.09.23 20:43:54 | 000,002,488 | R--- | M] () MD5=B1468F053A250799FCE421BEC8AA9A57 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx
[2013.09.05 17:04:16 | 000,002,523 | ---- | M] () MD5=BFFD6506EABA593CF59568B43395B742 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\da_DK\Services\Services.asfx
[2013.09.05 17:04:14 | 000,002,544 | ---- | M] () MD5=E34F6F2011E6A981EE46105A813AA6B4 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\es_ES\Services\Services.asfx
[2013.09.05 17:04:24 | 000,002,455 | ---- | M] () MD5=E6A6F3449EDB55E0A8A4F98E4527964B -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\zh_CN\Services\Services.asfx
[2013.09.05 17:04:08 | 000,002,614 | ---- | M] () MD5=F1B43A488FA907619B1469F76373D812 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\fr_FR\Services\Services.asfx
[2013.09.05 17:04:22 | 000,002,586 | ---- | M] () MD5=F6CC4E1BC7DF8CA3D0EA34B84B83C1B0 -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\pt_BR\Services\Services.asfx
[2013.09.05 17:04:10 | 000,002,675 | ---- | M] () MD5=F9E81A4C2C84268EE7437424514D0D8D -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\de_DE\Services\Services.asfx
[2013.09.05 17:04:26 | 000,002,541 | ---- | M] () MD5=FDA0451B478CA4B92ECCBDC4C15D007C -- C:\Program Files\Adobe\Reader 11.0\Reader\Locale\pl_PL\Services\Services.asfx
< MD5 for: SERVICES.ASFX1 >
[2012.09.23 20:43:54 | 000,002,457 | R--- | M] () MD5=BE0958E015FED942FAD670540F2BCEC1 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx1
< MD5 for: SERVICES.ASFX10 >
[2012.09.23 20:43:56 | 000,002,543 | R--- | M] () MD5=C66A95C06294259E63522BBB0E8B3ED8 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx10
< MD5 for: SERVICES.ASFX11 >
[2012.09.23 20:43:48 | 000,002,628 | R--- | M] () MD5=8A84C89E1D2A0916D4464D5AD46FB8AC -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx11
< MD5 for: SERVICES.ASFX12 >
[2012.09.23 20:43:50 | 000,002,493 | R--- | M] () MD5=A8C9725DBFAA9DB585F9691060B1FFA3 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx12
< MD5 for: SERVICES.ASFX13 >
[2012.09.23 20:43:52 | 000,002,653 | R--- | M] () MD5=881E2DDB014FD5D09B84AA45F2E86077 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx13
< MD5 for: SERVICES.ASFX14 >
[2012.09.23 20:43:44 | 000,002,851 | R--- | M] () MD5=364469E5C8724EB95F2E142438C8CECF -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx14
< MD5 for: SERVICES.ASFX15 >
[2012.09.23 20:43:46 | 000,002,533 | R--- | M] () MD5=72E505C96C0A40BE1DFD0F5FB982F527 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx15
< MD5 for: SERVICES.ASFX16 >
[2012.09.23 20:43:56 | 000,002,760 | R--- | M] () MD5=69BCCC8BA799AD320C723B14DAE327EB -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx16
< MD5 for: SERVICES.ASFX17 >
[2012.09.23 20:44:00 | 000,002,516 | R--- | M] () MD5=9B850C525959D9F53CD576DEF11F6ED4 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx17
< MD5 for: SERVICES.ASFX18 >
[2012.09.23 20:43:42 | 000,002,616 | R--- | M] () MD5=939A97CCEC5E78C7D41262B21158D749 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx18
< MD5 for: SERVICES.ASFX19 >
[2012.09.23 20:43:50 | 000,002,577 | R--- | M] () MD5=4160D76537EB300F681419BEA7589192 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx19
< MD5 for: SERVICES.ASFX2 >
[2012.09.23 20:44:02 | 000,003,264 | R--- | M] () MD5=6A3669AC3D692776A76DB4C513B73718 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx2
< MD5 for: SERVICES.ASFX20 >
[2012.09.23 20:44:06 | 000,002,497 | R--- | M] () MD5=6ECF361623A3B738642C61790DF3BF73 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx20
< MD5 for: SERVICES.ASFX21 >
[2012.09.23 20:43:46 | 000,002,546 | R--- | M] () MD5=DE20C36CDD3208B4E8544397E551C40B -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx21
< MD5 for: SERVICES.ASFX22 >
[2012.09.23 20:43:44 | 000,002,677 | R--- | M] () MD5=22FEEF662B7E813F8547E1446EBC706B -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx22
< MD5 for: SERVICES.ASFX23 >
[2012.09.23 20:43:50 | 000,002,525 | R--- | M] () MD5=34EB1E120DAE2C8346BA3747D562355B -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx23
< MD5 for: SERVICES.ASFX24 >
[2012.09.23 20:43:54 | 000,002,619 | R--- | M] () MD5=2468CEF75419234DCA72F892392DFB6C -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx24
< MD5 for: SERVICES.ASFX25 >
[2012.09.23 20:44:04 | 000,002,543 | R--- | M] () MD5=C2EDC3B5BB19B6F41226433A889EFE48 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx25
< MD5 for: SERVICES.ASFX3 >
[2012.09.23 20:43:58 | 000,002,601 | R--- | M] () MD5=4E7A75C5564D7E08200E3B7F656BF227 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx3
< MD5 for: SERVICES.ASFX4 >
[2012.09.23 20:43:48 | 000,002,556 | R--- | M] () MD5=3BE849A0D8DEEF6E14BEC19D565A965D -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx4
< MD5 for: SERVICES.ASFX5 >
[2012.09.23 20:44:02 | 000,002,539 | R--- | M] () MD5=8DEA878E25C893461D45C8974160B559 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx5
< MD5 for: SERVICES.ASFX6 >
[2012.09.23 20:44:04 | 000,002,640 | R--- | M] () MD5=A86B5BD2B198C0870542D6478C3CC6BC -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx6
< MD5 for: SERVICES.ASFX7 >
[2012.09.23 20:43:58 | 000,003,374 | R--- | M] () MD5=7DE29C93BAEEB470EE77CF5C1B1C03A1 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx7
< MD5 for: SERVICES.ASFX8 >
[2012.09.23 20:44:02 | 000,002,648 | R--- | M] () MD5=0865ABFC40AE2C730EF33F0E29C2C780 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx8
< MD5 for: SERVICES.ASFX9 >
[2012.09.23 20:43:52 | 000,002,588 | R--- | M] () MD5=0D18AE3100D7B9D49DCB1CE1EABA21F7 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.asfx9
< MD5 for: SERVICES.CFG >
[2012.09.23 20:43:36 | 000,603,848 | R--- | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744BA0000000010\11.0.0\services.cfg
[2013.12.21 09:04:16 | 000,559,392 | ---- | M] () MD5=F9FBA73F44366AB3514BD1985707F178 -- C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.EXE >
[2009.07.14 04:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\erdnt\cache\services.exe
[2009.07.14 04:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\System32\services.exe
[2009.07.14 04:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009.07.14 05:03:06 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 -- C:\Windows\System32\en-US\services.exe.mui
[2009.07.14 05:03:06 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 -- C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui
[2009.07.13 19:41:32 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=13D87E1A0FCE47C4743C2DED1F569F52 -- C:\Windows\System32\ro-RO\services.exe.mui
[2009.07.13 19:41:32 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=13D87E1A0FCE47C4743C2DED1F569F52 -- C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_ro-ro_b08c6962d9d2fc09\services.exe.mui
[2009.07.13 19:47:16 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=665623741B4E3A3701871FCEFD1C9192 -- C:\Windows\System32\fr-FR\services.exe.mui
[2009.07.13 19:47:16 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=665623741B4E3A3701871FCEFD1C9192 -- C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_fr-fr_0c56701d7a41cb39\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009.07.14 07:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009.07.14 07:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009.06.11 00:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\System32\wbem\services.mof
[2009.06.11 00:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof
< MD5 for: SERVICES.MSC >
[2009.07.13 19:36:16 | 000,092,751 | ---- | M] () MD5=1E203CFA3C6C7661317793BEEBA3423B -- C:\Windows\System32\fr-FR\services.msc
[2009.07.13 19:36:16 | 000,092,751 | ---- | M] () MD5=1E203CFA3C6C7661317793BEEBA3423B -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_fr-fr_4698400950ab652c\services.msc
[2009.07.14 05:08:50 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\en-US\services.msc
[2009.06.11 00:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\services.msc
[2009.07.14 05:08:50 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009.06.11 00:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009.07.13 23:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009.07.13 23:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml
< MD5 for: SVCHOST.EXE >
[2009.07.14 04:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\erdnt\cache\svchost.exe
[2009.07.14 04:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009.07.14 04:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
< MD5 for: USERINIT.EXE >
[2010.11.20 15:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\erdnt\cache\userinit.exe
[2010.11.20 15:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010.11.20 15:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
< End of report >
I don't see the extras log and OTL program blocked after it generated the last log.