Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Malware infected work pc [Solved]


  • This topic is locked This topic is locked

#1
Andreib18

Andreib18

    Member

  • Member
  • PipPipPip
  • 100 posts

Hello it's me again ... This pc is from work and i cannot format it because it contains large ammount of data.if i search something with usb or start an adb command pc restarts and al folder containt an extra data folder .otl log:

OTL logfile created on: 8/4/2014 9:50:46 AM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Documents and Settings\Radu Mamii\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.99 Gb Total Physical Memory | 2.06 Gb Available Physical Memory | 68.77% Memory free
4.83 Gb Paging File | 4.02 Gb Available in Paging File | 83.25% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 488.28 Gb Total Space | 147.17 Gb Free Space | 30.14% Space Free | Partition Type: NTFS
Drive D: | 443.22 Gb Total Space | 11.13 Gb Free Space | 2.51% Space Free | Partition Type: NTFS
 
Computer Name: SERVICE-429D9B2 | User Name: Radu Mamii | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/08/04 09:50:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Radu Mamii\Desktop\OTL.exe
PRC - [2014/07/15 12:24:50 | 000,860,488 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2014/06/27 09:59:26 | 000,366,904 | ---- | M] (Power Software Ltd) -- C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2014/05/07 15:00:32 | 000,182,696 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2014/05/07 13:01:30 | 001,324,544 | ---- | M] (Research In Motion Limited) -- C:\Program Files\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe
PRC - [2014/05/07 12:53:28 | 000,389,632 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe
PRC - [2014/05/06 17:16:56 | 000,107,816 | ---- | M] () -- C:\WINDOWS\system32\FLSDEVCP.EXE
PRC - [2014/01/21 14:41:16 | 000,585,728 | ---- | M] (BlackBerry Limited) -- C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
PRC - [2013/11/06 04:55:46 | 000,845,168 | ---- | M] (Samsung) -- C:\Program Files\SAMSUNG\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2013/10/17 16:41:16 | 000,821,600 | ---- | M] () -- C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
PRC - [2013/09/02 10:51:38 | 000,087,368 | ---- | M] (Nero AG) -- C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
PRC - [2013/04/18 12:06:42 | 000,737,616 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2013/04/18 12:06:32 | 000,179,024 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2013/04/18 12:06:26 | 000,127,312 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2012/12/07 17:26:56 | 000,167,424 | ---- | M] () -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2012/05/25 04:25:02 | 006,595,928 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2011/10/31 09:07:55 | 000,048,128 | R--- | M] (Mobile Leader Co.,Ltd.) -- C:\WINDOWS\system32\ScsiCommandService2.exe
PRC - [2011/08/05 12:29:56 | 000,057,056 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Zune\ZuneBusEnum.exe
PRC - [2010/03/05 12:50:19 | 000,047,616 | R--- | M] (Mobile Leader Co.,Ltd.) -- C:\WINDOWS\system32\LGScsiCommandService.exe
PRC - [2010/02/27 02:25:16 | 000,044,401 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\winlogon.exe
PRC - [2010/02/27 02:25:16 | 000,044,401 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\services.exe
PRC - [2010/02/27 02:25:16 | 000,044,401 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\lsass.exe
PRC - [2008/08/21 15:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/08/21 15:00:00 | 000,017,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ping.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/07/15 12:24:48 | 000,353,096 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\36.0.1985.125\ppgooglenaclpluginchrome.dll
MOD - [2014/07/15 12:24:44 | 008,537,928 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\36.0.1985.125\pdf.dll
MOD - [2014/07/15 12:24:35 | 001,732,936 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll
MOD - [2014/05/06 17:16:56 | 000,107,816 | ---- | M] () -- C:\WINDOWS\system32\FLSDEVCP.EXE
MOD - [2014/02/12 21:58:32 | 000,073,544 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014/02/12 21:58:10 | 001,044,808 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2013/10/17 16:43:40 | 000,223,592 | ---- | M] () -- C:\Program Files\HTC\HTC Sync Manager\DevConnMon.dll
MOD - [2013/10/17 16:42:24 | 000,129,376 | ---- | M] () -- C:\Program Files\HTC\HTC Sync Manager\zlib1.dll
MOD - [2013/10/17 16:41:16 | 000,821,600 | ---- | M] () -- C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
MOD - [2013/10/17 16:40:52 | 000,080,248 | ---- | M] () -- C:\Program Files\HTC\HTC Sync Manager\NInstallerHelper.dll
MOD - [2013/10/17 16:40:34 | 000,044,392 | ---- | M] () -- C:\Program Files\HTC\HTC Sync Manager\NAdvLog.dll
MOD - [2013/10/17 16:40:32 | 000,036,216 | ---- | M] () -- C:\Program Files\HTC\HTC Sync Manager\NFileCacheDBAccess.dll
MOD - [2013/10/17 16:40:28 | 000,607,376 | ---- | M] () -- C:\Program Files\HTC\HTC Sync Manager\sqlite3.dll
MOD - [2013/10/17 16:40:06 | 000,031,080 | ---- | M] () -- C:\Program Files\HTC\HTC Sync Manager\DbAccess.dll
MOD - [2013/01/02 09:49:10 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2012/12/07 17:26:56 | 000,167,424 | ---- | M] () -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
MOD - [2012/05/25 04:25:00 | 000,921,600 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2012/05/25 04:25:00 | 000,078,336 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\pcre.dll
MOD - [2010/02/27 02:25:16 | 000,044,401 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\winlogon.exe
MOD - [2010/02/27 02:25:16 | 000,044,401 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\services.exe
MOD - [2010/02/27 02:25:16 | 000,044,401 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\lsass.exe
MOD - [2009/05/16 00:22:42 | 000,716,800 | ---- | M] () -- C:\Program Files\SAMSUNG\Samsung PC Studio 7\PCSCM_Samsung.dll
MOD - [2008/12/06 01:38:50 | 000,619,008 | ---- | M] () -- C:\Program Files\SAMSUNG\Samsung PC Studio 7\PhoneBrowser.dll
MOD - [2008/08/21 15:00:00 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2008/08/21 15:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2006/09/10 20:46:38 | 000,020,776 | ---- | M] () -- C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll
 
 
========== Services (SafeList) ==========
 
SRV - [2014/07/09 11:32:06 | 000,262,320 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/05/07 15:00:32 | 000,182,696 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2014/05/07 13:01:30 | 001,324,544 | ---- | M] (Research In Motion Limited) [Auto | Running] -- C:\Program Files\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe -- (RIM Tunnel Service)
SRV - [2014/05/07 12:53:28 | 000,389,632 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe -- (RIM MDNS)
SRV - [2014/02/13 03:36:33 | 000,118,896 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/01/21 14:41:16 | 000,585,728 | ---- | M] (BlackBerry Limited) [On_Demand | Running] -- C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe -- (BlackBerry Device Manager)
SRV - [2013/09/02 10:51:38 | 000,087,368 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe -- (HTCMonitorService)
SRV - [2013/04/18 12:06:42 | 000,737,616 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2012/12/07 17:26:56 | 000,167,424 | ---- | M] () [Auto | Running] -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2011/10/31 09:07:55 | 000,048,128 | R--- | M] (Mobile Leader Co.,Ltd.) [Auto | Running] -- C:\WINDOWS\system32\ScsiCommandService2.exe -- (ScsiCommandService2)
SRV - [2011/08/05 12:30:02 | 000,444,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV - [2011/08/05 12:30:02 | 000,268,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV - [2011/08/05 12:29:56 | 006,363,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV - [2011/08/05 12:29:56 | 000,057,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Zune\ZuneBusEnum.exe -- (ZuneBusEnum)
SRV - [2010/03/05 12:50:19 | 000,047,616 | R--- | M] (Mobile Leader Co.,Ltd.) [Auto | Running] -- C:\WINDOWS\system32\LGScsiCommandService.exe -- (LGScsiCommandService)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - [2014/06/27 09:59:18 | 000,116,320 | ---- | M] (Power Software Ltd) [Kernel | System | Running] -- C:\windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2014/05/19 19:31:41 | 000,006,784 | ---- | M] (UniversalBox) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ubnredir.sys -- (UBNRedir)
DRV - [2014/05/07 12:41:04 | 000,012,800 | ---- | M] (Research in Motion Limited) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimvndis.sys -- (rimvndis)
DRV - [2014/05/06 17:16:58 | 000,035,226 | ---- | M] (Data Encryption Systems Limited) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\flsvcom.sys -- (FLSVCOM)
DRV - [2014/05/06 17:16:58 | 000,008,344 | ---- | M] (Data Encryption Systems Limited) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\flsser.sys -- (FLSSER)
DRV - [2014/05/06 17:16:57 | 000,016,314 | ---- | M] (Data Encryption Systems Limited) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\flspar.sys -- (FLSPAR)
DRV - [2014/05/06 17:16:57 | 000,014,272 | ---- | M] (Data Encryption Systems Limited) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\flsiface.sys -- (FLSIFACE)
DRV - [2014/05/06 17:16:52 | 000,033,404 | ---- | M] (Data Encryption Systems Limited) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fle5wnnt.sys -- (FLE5WNNT)
DRV - [2013/08/21 07:31:38 | 000,182,680 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudserd.sys -- (ssudserd)
DRV - [2013/08/21 07:31:38 | 000,182,680 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudobex.sys -- (ssudobex)
DRV - [2013/08/21 07:31:38 | 000,182,680 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2013/08/21 07:31:38 | 000,084,248 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2013/08/21 07:31:38 | 000,080,664 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudrmnetmp.sys -- (ssudrmnetmp)
DRV - [2013/08/21 07:31:38 | 000,060,184 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudrmnet.sys -- (ssudrmnet)
DRV - [2013/08/21 07:31:30 | 000,016,384 | ---- | M] (Intel Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\FlashUSB.sys -- (FlashUSB)
DRV - [2013/07/25 16:53:46 | 000,018,944 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\netaapl.sys -- (Netaapl)
DRV - [2013/05/02 07:23:50 | 000,153,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2013/05/02 07:23:50 | 000,136,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus)
DRV - [2013/05/02 07:23:50 | 000,017,864 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2013/05/02 07:23:42 | 000,153,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2013/05/02 07:23:42 | 000,136,904 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2013/05/02 07:23:42 | 000,130,248 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadserd.sys -- (ssadserd)
DRV - [2013/05/02 07:23:42 | 000,032,064 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadadb.sys -- (androidusb)
DRV - [2013/05/02 07:23:42 | 000,017,864 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2013/04/04 12:35:49 | 000,021,888 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\eps2kt1.sys -- (token)
DRV - [2013/04/04 12:35:49 | 000,012,800 | ---- | M] (OEM) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smccard.sys -- (R5BaseSmc)
DRV - [2013/04/02 17:09:13 | 000,007,808 | ---- | M] (UniversalBox) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\ubnd.sys -- (UBND)
DRV - [2013/01/23 11:31:52 | 000,137,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2013/01/23 11:31:52 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2013/01/23 11:31:50 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2013/01/23 11:31:50 | 000,018,560 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2013/01/23 11:31:50 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2013/01/23 11:31:50 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2012/12/07 18:27:50 | 000,021,248 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\htcnprot.sys -- (htcnprot)
DRV - [2012/10/17 15:53:46 | 000,019,072 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2012/09/27 14:44:03 | 000,073,096 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftser2k.sys -- (FTSER2K)
DRV - [2012/09/04 13:42:16 | 000,107,776 | ---- | M] (HS Coporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ghsser.sys -- (ghsser)
DRV - [2012/07/04 14:47:00 | 000,070,400 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgandnetndis.sys -- (andnetndis)
DRV - [2012/07/03 12:56:00 | 000,025,856 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgandnetadb.sys -- (andnetadb)
DRV - [2012/07/03 12:43:00 | 000,027,776 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgandnetmodem.sys -- (ANDNetModem)
DRV - [2012/07/03 12:43:00 | 000,023,040 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgandnetdiag.sys -- (AndNetDiag)
DRV - [2012/06/20 11:51:34 | 000,017,672 | ---- | M] (HandSet Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\massfilter_hs.sys -- (massfilter_hs)
DRV - [2012/04/13 13:42:06 | 000,117,248 | ---- | M] (Spreadtrum Communication Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SciU2S.sys -- (SciU2S)
DRV - [2012/03/02 17:03:00 | 000,025,216 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2012/03/02 17:03:00 | 000,020,864 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2012/03/02 17:03:00 | 000,020,096 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbgps.sys -- (UsbGps)
DRV - [2012/03/02 17:03:00 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2012/03/02 17:02:00 | 000,025,088 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgandmodem.sys -- (ANDModem)
DRV - [2012/03/02 17:02:00 | 000,020,736 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lganddiag.sys -- (AndDiag)
DRV - [2012/03/02 17:02:00 | 000,020,096 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgandgps.sys -- (AndGps)
DRV - [2012/03/02 17:02:00 | 000,014,336 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgandbus.sys -- (Andbus)
DRV - [2011/11/09 12:30:42 | 000,108,160 | ---- | M] (TCL Communicate Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\qcusbser.sys -- (qcusbser)
DRV - [2011/05/13 09:07:28 | 000,041,344 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bcmvcp.sys -- (BRCM)
DRV - [2011/03/09 16:37:46 | 000,033,792 | ---- | M] (Texas Instruments Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\csstusb.sys -- (CSSTUSB)
DRV - [2011/03/01 20:36:54 | 000,037,184 | ---- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cyclonebox.sys -- (cyclonebox)
DRV - [2010/04/27 05:25:16 | 000,123,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2010/04/27 05:25:16 | 000,100,224 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bserd.sys -- (ss_bserd)
DRV - [2010/04/27 05:25:16 | 000,098,432 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bbus.sys -- (ss_bbus)
DRV - [2010/04/27 05:25:16 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdfl.sys -- (ss_bmdfl)
DRV - [2010/04/27 05:25:14 | 000,132,608 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_mdm.sys -- (ssm_mdm)
DRV - [2010/04/27 05:25:14 | 000,104,448 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_bus.sys -- (ssm_bus)
DRV - [2010/04/27 05:25:14 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_mdfl.sys -- (ssm_mdfl)
DRV - [2010/04/27 05:25:12 | 000,123,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdm.sys -- (ss_mdm)
DRV - [2010/04/27 05:25:12 | 000,098,560 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bus.sys -- (ss_bus)
DRV - [2010/04/27 05:25:12 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV - [2010/04/27 05:25:08 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbsa.sys -- (nmwcdsa)
DRV - [2010/04/13 20:40:48 | 000,017,152 | ---- | M] (GSM Dream Team) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dreambox.sys -- (DreamBox)
DRV - [2010/02/11 15:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2010/02/03 15:31:26 | 000,012,416 | ---- | M] (NXP Semiconductors) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\52xdfu.sys -- (DFU)
DRV - [2009/10/22 16:11:14 | 000,057,800 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2009/10/21 11:22:32 | 001,425,280 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009/07/22 11:08:40 | 000,062,080 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mstrgen.sys -- (mstrgen)
DRV - [2009/07/13 16:51:12 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\winusb.sys -- (WinUSB)
DRV - [2009/06/10 15:49:32 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2009/05/25 15:21:28 | 000,142,336 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2009/04/05 23:13:52 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2009/04/05 23:13:52 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ggflt.sys -- (ggflt)
DRV - [2007/06/25 11:43:38 | 000,098,344 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s117obex.sys -- (s117obex)
DRV - [2007/06/25 11:43:36 | 000,108,456 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s117mdm.sys -- (s117mdm)
DRV - [2007/06/25 11:43:36 | 000,100,264 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s117mgmt.sys -- (s117mgmt)
DRV - [2007/06/25 11:43:36 | 000,098,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s117unic.sys -- (s117unic)
DRV - [2007/06/25 11:43:36 | 000,022,952 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s117nd5.sys -- (s117nd5)
DRV - [2007/06/25 11:43:26 | 000,014,888 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s117mdfl.sys -- (s117mdfl)
DRV - [2007/06/25 11:43:22 | 000,082,984 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s117bus.sys -- (s117bus)
DRV - [2006/12/28 19:44:44 | 000,084,992 | R--- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtiHdAud.sys -- (HdAudAddService)
DRV - [2006/05/19 10:23:00 | 000,018,880 | ---- | M] (Axalto) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\egate.sys -- (Egatecard)
DRV - [2006/05/19 10:23:00 | 000,015,328 | ---- | M] (Axalto) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\egatebus.sys -- (Egatebus)
DRV - [2006/05/19 10:23:00 | 000,013,440 | ---- | M] (Axalto) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\egaterdr.sys -- (Egaterdr)
DRV - [2006/02/26 18:02:50 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004/03/25 16:29:22 | 000,024,144 | ---- | M] (SHARP Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbgx_2.sys -- (USBSHGX)
DRV - [2004/03/02 18:06:36 | 000,010,240 | ---- | M] (SHARP Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gxdlusb.sys -- (gxdlusb)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRC
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-299502267-115176313-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ro/
IE - HKU\S-1-5-21-299502267-115176313-682003330-1003\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKU\S-1-5-21-299502267-115176313-682003330-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-299502267-115176313-682003330-1003\..\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}: "URL" = http://www.trovi.com...rchTerms}&SSPV=
IE - HKU\S-1-5-21-299502267-115176313-682003330-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKU\S-1-5-21-299502267-115176313-682003330-1003\..\SearchScopes\{2E22C5E0-253F-4AF3-BCA7-02F476B9E955}: "URL" = http://websearch.ask...E5-1DF470ED5518
IE - HKU\S-1-5-21-299502267-115176313-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-299502267-115176313-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.60.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.60.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
 
[2014/06/21 13:43:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Radu Mamii\Application Data\Mozilla\Extensions
[2014/06/21 13:51:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Radu Mamii\Application Data\Mozilla\Firefox\Profiles\j7hu8h2q.default\extensions
[2014/07/12 09:40:54 | 000,000,643 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Application Data\Mozilla\Firefox\Profiles\j7hu8h2q.default\searchplugins\trovi-search.xml
[2013/04/02 16:18:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2014/06/21 13:42:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014/06/21 13:42:57 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\36.0.1985.125\pdf.dll
CHR - plugin: Microsoft DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - Extension: Google Docs = C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: Google Drive = C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: YouTube = C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Adblock Plus = C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Wallet = C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2014/07/07 09:20:21 | 000,012,393 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR...l4/strict.dtd">
O1 - Hosts: <html lang='en'>
O1 - Hosts: <head>
O1 - Hosts:             <meta name="description" content="Yahoo! GeoCities offers you a free web site and all the tools you need to build a dynamic site. Features include easy-to-use site building tools, online help, web site statistics, secure and reliable hosting, and an intuitive control panel.">
O1 - Hosts:             <title>Yahoo! GeoCities: Get a web site with easy-to-use site building tools.</title>
O1 - Hosts: <link rel="stylesheet" type="text/css" media="all" href="http://l.yimg.com/a/lib/smbiz/css/geocities_84954.css"> 
O1 - Hosts: <style>
O1 - Hosts: h1 { line-height:30px;height:30px; padding-left:15px; font-weight:bold;font-size:1.6em;color:#1f296a;}
O1 - Hosts: .services li { margin-left:1.0em; padding-left:0.5em; background:url("http://l.yimg.com/a/...ullet_3x3_1.gif") no-repeat 0 0.5em; margin-bottom:0.5em;margin-left:1.5em;margin-right:0.5em;width:6em}
O1 - Hosts: .services li {float:left; width:17em; font-size:116%;margin-top:0.8em}
O1 - Hosts:  .services {  font-size:116%; padding-bottom:20px }
O1 - Hosts: .learnmore a {color:#2882DE;font-size:16px}
O1 - Hosts: .image_web  {float:right; margin:15px 0 0 15px}
O1 - Hosts: p {margin:20px;font-size:1em;}
O1 - Hosts: h2 {margin:20px 0 0 20px;color:#1F296;font-weight:bold;font-size:1.25em;color:#1f296a;}
O1 - Hosts: h3 {margin:20px;color:#1F296;font-weight:bold;font-size:1.15em;color:#1f296a;}
O1 - Hosts: li.rule {border-top:solid 1px #DBE1E6;}
O1 - Hosts: </style>
O1 - Hosts: </head>
O1 - Hosts: <body>
O1 - Hosts: <!-- following code added by server. PLEASE REMOVE -->
O1 - Hosts: <!-- preceding code added by server. PLEASE REMOVE -->
O1 - Hosts:  <div class="ez-mw" style ="height:900px;width:905px">
O1 - Hosts:     <div class="ez-wri ez-oh" style="width:900px">
O1 - Hosts: 90 more lines...
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [Bron-Spizaetus] C:\WINDOWS\ShellNew\RakyatKelaparan.exe ()
O4 - HKLM..\Run: [FLSDeviceControlPanel] C:\WINDOWS\system32\FLSDEVCP.EXE ()
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (Power Software Ltd)
O4 - HKU\.DEFAULT..\Run: [Samsung.PCSync] C:\Program Files\Samsung\Samsung PC Studio 7\PcSync2.exe (Nokia)
O4 - HKU\.DEFAULT..\Run: [Tok-Cirrhatus]  File not found
O4 - HKU\.DEFAULT..\Run: [Tok-Cirrhatus-1860] C:\Documents and Settings\NetworkService\Local Settings\Application Data\br4743on.exe ()
O4 - HKU\S-1-5-18..\Run: [Samsung.PCSync] C:\Program Files\Samsung\Samsung PC Studio 7\PcSync2.exe (Nokia)
O4 - HKU\S-1-5-18..\Run: [Tok-Cirrhatus]  File not found
O4 - HKU\S-1-5-18..\Run: [Tok-Cirrhatus-1860] C:\Documents and Settings\NetworkService\Local Settings\Application Data\br4743on.exe ()
O4 - HKU\S-1-5-21-299502267-115176313-682003330-1003..\Run: [] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKU\S-1-5-21-299502267-115176313-682003330-1003..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKU\S-1-5-21-299502267-115176313-682003330-1003..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKU\S-1-5-21-299502267-115176313-682003330-1003..\Run: [Tok-Cirrhatus]  File not found
O4 - HKU\S-1-5-21-299502267-115176313-682003330-1003..\Run: [Tok-Cirrhatus-3543] C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br8109on.exe ()
O4 - Startup: C:\Documents and Settings\NetworkService\Start Menu\Programs\Startup\Empty.pif ()
O4 - Startup: C:\Documents and Settings\Radu Mamii\Start Menu\Programs\Startup\Empty.pif ()
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-299502267-115176313-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-299502267-115176313-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKU\S-1-5-21-299502267-115176313-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9CB882B8-1AF2-44E8-AB43-6B51E07EDA86}: DhcpNameServer = 193.231.242.2 193.226.60.2
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - ("C:\WINDOWS\KesenjanganSosial.exe") - C:\WINDOWS\KesenjanganSosial.exe ()
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O31 - SafeBoot: AlternateShell - cmd-brontok.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{076eb344-92ef-11e3-b171-0298f9328801}\Shell - "" = AutoRun
O33 - MountPoints2\{076eb344-92ef-11e3-b171-0298f9328801}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{076eb344-92ef-11e3-b171-0298f9328801}\Shell\AutoRun\command - "" = F:\LGAutoRun.exe
O33 - MountPoints2\{076eb356-92ef-11e3-b171-0298f9328801}\Shell - "" = AutoRun
O33 - MountPoints2\{076eb356-92ef-11e3-b171-0298f9328801}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{076eb356-92ef-11e3-b171-0298f9328801}\Shell\AutoRun\command - "" = F:\LGAutoRun.exe
O33 - MountPoints2\{156b969f-0be8-11e3-b072-0208fd748701}\Shell - "" = AutoRun
O33 - MountPoints2\{156b969f-0be8-11e3-b072-0208fd748701}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{156b969f-0be8-11e3-b072-0208fd748701}\Shell\AutoRun\command - "" = F:\XTC-Clip_PLUS.exe
O33 - MountPoints2\{1e86c291-5b50-11e3-b109-02a81c228801}\Shell - "" = AutoRun
O33 - MountPoints2\{1e86c291-5b50-11e3-b109-02a81c228801}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1e86c291-5b50-11e3-b109-02a81c228801}\Shell\AutoRun\command - "" = F:\NokiaPCIA_Autorun.exe
O33 - MountPoints2\{36f85459-d67b-11e3-b1e1-02d885a28801}\Shell - "" = AutoRun
O33 - MountPoints2\{36f85459-d67b-11e3-b1e1-02d885a28801}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{36f85459-d67b-11e3-b1e1-02d885a28801}\Shell\AutoRun\command - "" = F:\LG_PC_Programs.exe
O33 - MountPoints2\{531d4e92-b0a2-11e2-afe5-002354cb06b4}\Shell - "" = AutoRun
O33 - MountPoints2\{531d4e92-b0a2-11e2-afe5-002354cb06b4}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{531d4e92-b0a2-11e2-afe5-002354cb06b4}\Shell\AutoRun\command - "" = F:\Autorun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2066.1.9B05 PID_0083
O33 - MountPoints2\{78a79f28-c39c-11e3-b1c9-0230ae878801}\Shell - "" = AutoRun
O33 - MountPoints2\{78a79f28-c39c-11e3-b1c9-0230ae878801}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{78a79f28-c39c-11e3-b1c9-0230ae878801}\Shell\AutoRun\command - "" = F:\LGAutoRun.exe
O33 - MountPoints2\{ca2c0f60-e237-11e2-b02d-02c8e0508701}\Shell - "" = AutoRun
O33 - MountPoints2\{ca2c0f60-e237-11e2-b02d-02c8e0508701}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ca2c0f60-e237-11e2-b02d-02c8e0508701}\Shell\AutoRun\command - "" = F:\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2088.1.A01B06 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B}
O33 - MountPoints2\{cf93d1f7-0e44-11e4-b248-02a05d5b8901}\Shell - "" = AutoRun
O33 - MountPoints2\{cf93d1f7-0e44-11e4-b248-02a05d5b8901}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cf93d1f7-0e44-11e4-b248-02a05d5b8901}\Shell\AutoRun\command - "" = G:\LG_PC_Programs.exe
O33 - MountPoints2\{d6adc743-6234-11e3-b123-0258c31f8801}\Shell - "" = AutoRun
O33 - MountPoints2\{d6adc743-6234-11e3-b123-0258c31f8801}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d6adc743-6234-11e3-b123-0258c31f8801}\Shell\AutoRun\command - "" = F:\HTC_Sync_Manager_PC.exe
O33 - MountPoints2\{d8d1f7f7-b8ab-11e2-aff0-002354cb06b4}\Shell - "" = AutoRun
O33 - MountPoints2\{d8d1f7f7-b8ab-11e2-aff0-002354cb06b4}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d8d1f7f7-b8ab-11e2-aff0-002354cb06b4}\Shell\AutoRun\command - "" = F:\VTP_Manager.exe
O33 - MountPoints2\{d8d1f7f8-b8ab-11e2-aff0-002354cb06b4}\Shell - "" = AutoRun
O33 - MountPoints2\{d8d1f7f8-b8ab-11e2-aff0-002354cb06b4}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d8d1f7f8-b8ab-11e2-aff0-002354cb06b4}\Shell\AutoRun\command - "" = F:\LGAutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/08/04 09:50:36 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Radu Mamii\Desktop\OTL.exe
[2014/08/04 09:25:18 | 000,000,000 | ---D | C] -- C:\windows\LastGood
[2014/08/04 09:23:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-4
[2014/08/01 14:54:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Desktop\i747 root
[2014/08/01 11:03:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-1
[2014/08/01 09:34:43 | 000,038,912 | ---- | C] (SOFTWIN) -- C:\Documents and Settings\Radu Mamii\Desktop\AntiBrontokA-en.exe
[2014/08/01 09:31:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-1
[2014/07/31 09:46:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-31
[2014/07/30 11:03:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-30
[2014/07/30 10:12:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-30
[2014/07/29 10:55:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Desktop\N8-00
[2014/07/29 09:28:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-29
[2014/07/28 11:03:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-28
[2014/07/28 09:24:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-28
[2014/07/26 10:33:47 | 000,000,000 | ---D | C] -- C:\usb_driver
[2014/07/26 10:16:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-26
[2014/07/25 11:03:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-25
[2014/07/25 09:38:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-25
[2014/07/24 11:03:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-24
[2014/07/24 09:03:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-24
[2014/07/23 11:03:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-23
[2014/07/23 09:12:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-23
[2014/07/22 17:08:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-22
[2014/07/22 09:23:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-22
[2014/07/21 11:03:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-21
[2014/07/21 09:37:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-21
[2014/07/19 11:03:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-19
[2014/07/19 09:56:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-19
[2014/07/18 09:29:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-18
[2014/07/17 11:03:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-17
[2014/07/17 09:35:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-17
[2014/07/16 09:23:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-16
[2014/07/15 09:27:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-15
[2014/07/14 17:08:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\PowerISO
[2014/07/14 17:08:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-14
[2014/07/14 09:50:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\My Documents\BLACKBERRY-3B51
[2014/07/14 09:35:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-14
[2014/07/12 09:59:00 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2014/07/12 09:56:02 | 004,181,856 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Radu Mamii\Desktop\tdsskiller.exe
[2014/07/12 09:40:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Application Data\PowerISO
[2014/07/12 09:39:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\PowerISO
[2014/07/12 09:39:30 | 000,000,000 | ---D | C] -- C:\Program Files\PowerISO
[2014/07/12 09:38:37 | 002,876,504 | ---- | C] (Power Software Ltd) -- C:\Documents and Settings\Radu Mamii\Desktop\PowerISO6.exe
[2014/07/12 09:35:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-12
[2014/07/11 17:38:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Desktop\i9000
[2014/07/11 11:03:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-11
[2014/07/11 09:54:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-11
[2014/07/10 19:27:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-10
[2014/07/10 13:23:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\My Documents\lili
[2014/07/09 10:21:20 | 000,000,000 | ---D | C] -- C:\Avenger
[2014/07/09 10:03:54 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\MBAMSwissArmy.sys
[2014/07/09 10:03:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/07/09 10:03:45 | 000,053,208 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamchameleon.sys
[2014/07/09 10:03:45 | 000,023,256 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2014/07/09 10:03:45 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2014/07/09 10:03:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2014/07/09 10:00:06 | 017,292,760 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Documents and Settings\Radu Mamii\Desktop\mbam-setup-2.0.2.1012.exe
[2014/07/07 11:10:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Ok-SendMail-Bron-tok
[2014/07/07 11:09:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Loc.Mail.Bron.Tok
[2014/07/07 11:03:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2014/07/07 11:03:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Identities
[2014/07/07 09:27:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Ok-SendMail-Bron-tok
[2014/07/07 09:25:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Loc.Mail.Bron.Tok
[2014/07/05 10:54:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radu Mamii\Desktop\asha 200 apa
[3 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014/08/04 09:50:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Radu Mamii\Desktop\OTL.exe
[2014/08/04 09:45:35 | 000,012,393 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok.A16.em.bin
[2014/08/04 09:37:22 | 000,000,894 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/08/04 09:32:15 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2014/08/04 09:27:34 | 000,496,146 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2014/08/04 09:27:34 | 000,085,338 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2014/08/04 09:23:45 | 000,000,420 | ---- | M] () -- C:\windows\tasks\At2.job
[2014/08/04 09:23:45 | 000,000,420 | ---- | M] () -- C:\windows\tasks\At1.job
[2014/08/04 09:23:42 | 000,013,646 | ---- | M] () -- C:\windows\System32\wpa.dbl
[2014/08/04 09:23:30 | 000,000,890 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/08/04 09:23:30 | 000,000,232 | ---- | M] () -- C:\windows\tasks\Microsoft Windows XP End of Service Notification Logon.job
[2014/08/04 09:23:27 | 000,002,048 | --S- | M] () -- C:\windows\bootstat.dat
[2014/08/01 09:34:44 | 000,038,912 | ---- | M] (SOFTWIN) -- C:\Documents and Settings\Radu Mamii\Desktop\AntiBrontokA-en.exe
[2014/08/01 09:32:54 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\MBAMSwissArmy.sys
[2014/07/30 17:38:16 | 000,000,284 | ---- | M] () -- C:\windows\tasks\AppleSoftwareUpdate.job
[2014/07/18 14:42:45 | 000,001,856 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2014/07/18 10:30:06 | 000,000,865 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Desktop\Octoplus LG Tool.lnk
[2014/07/14 09:49:38 | 000,016,695 | ---- | M] () -- C:\ads_err.adt
[2014/07/14 09:49:38 | 000,003,072 | ---- | M] () -- C:\ads_err.adi
[2014/07/12 09:56:51 | 004,181,856 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Radu Mamii\Desktop\tdsskiller.exe
[2014/07/12 09:39:43 | 000,000,743 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2014/07/12 09:39:08 | 002,876,504 | ---- | M] (Power Software Ltd) -- C:\Documents and Settings\Radu Mamii\Desktop\PowerISO6.exe
[2014/07/12 09:38:12 | 000,016,853 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Desktop\Windows 7 Ultimate with SP1 X64 Genuine Untouched ISO Including Windows7 USB DVD Tool and Loader (1).torrent
[2014/07/12 09:37:40 | 000,016,853 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Desktop\Windows 7 Ultimate with SP1 X64 Genuine Untouched ISO Including Windows7 USB DVD Tool and Loader.torrent
[2014/07/11 10:57:22 | 000,001,485 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox BEST.lnk
[2014/07/11 10:36:37 | 000,000,805 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Activator.lnk
[2014/07/11 10:36:37 | 000,000,671 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Application Data\Microsoft\Internet Explorer\Quick Launch\SPT.lnk
[2014/07/11 10:36:37 | 000,000,653 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SPT.lnk
[2014/07/11 10:21:29 | 000,000,919 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Application Data\Microsoft\Internet Explorer\Quick Launch\Octoplus Suite.lnk
[2014/07/11 10:21:28 | 000,000,901 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Desktop\Octoplus Suite.lnk
[2014/07/11 10:20:38 | 000,000,925 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Desktop\Octoplus Samsung Tool.lnk
[2014/07/09 10:03:48 | 000,000,820 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2014/07/09 10:00:45 | 017,292,760 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Documents and Settings\Radu Mamii\Desktop\mbam-setup-2.0.2.1012.exe
[2014/07/08 15:14:38 | 000,000,226 | ---- | M] () -- C:\windows\tasks\Microsoft Windows XP End of Service Notification Monthly.job
[2014/07/08 10:17:52 | 006,726,888 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Desktop\Nikkfurie de La Caution-The A La Menthe (OST Ocean's 11).mp3
[2014/07/07 12:08:27 | 000,001,573 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox PinFinder.lnk
[2014/07/07 12:08:27 | 000,001,501 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox Shell.lnk
[2014/07/07 12:08:27 | 000,001,433 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox Documentation.lnk
[2014/07/07 12:08:27 | 000,001,289 | ---- | M] () -- C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox.lnk
[2014/07/07 09:20:21 | 000,012,393 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts
[3 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014/08/04 09:45:35 | 000,012,393 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok.A16.em.bin
[2014/08/04 09:32:06 | 000,012,393 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Update.16.Bron.Tok.bin
[2014/08/01 19:57:24 | 000,012,393 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Update.16.Bron.Tok.bin
[2014/08/01 18:48:58 | 000,012,393 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok.A16.em.bin
[2014/07/12 09:39:43 | 000,000,743 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2014/07/12 09:38:12 | 000,016,853 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Desktop\Windows 7 Ultimate with SP1 X64 Genuine Untouched ISO Including Windows7 USB DVD Tool and Loader (1).torrent
[2014/07/12 09:37:39 | 000,016,853 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Desktop\Windows 7 Ultimate with SP1 X64 Genuine Untouched ISO Including Windows7 USB DVD Tool and Loader.torrent
[2014/07/09 10:03:48 | 000,000,820 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2014/07/08 10:17:51 | 006,726,888 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Desktop\Nikkfurie de La Caution-The A La Menthe (OST Ocean's 11).mp3
[2014/07/07 12:10:09 | 000,001,485 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox BEST.lnk
[2014/07/07 12:08:27 | 000,001,573 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox PinFinder.lnk
[2014/07/07 12:08:27 | 000,001,501 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox Shell.lnk
[2014/07/07 12:08:27 | 000,001,433 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox Documentation.lnk
[2014/07/05 15:59:29 | 000,000,420 | ---- | C] () -- C:\windows\tasks\At2.job
[2014/07/05 15:59:29 | 000,000,420 | ---- | C] () -- C:\windows\tasks\At1.job
[2014/05/06 17:16:57 | 000,004,430 | ---- | C] () -- C:\windows\System32\flsinst.ini
[2014/05/06 17:16:56 | 000,107,816 | ---- | C] () -- C:\windows\System32\FLSDEVCP.EXE
[2014/05/06 17:16:50 | 001,994,752 | ---- | C] () -- C:\windows\System32\FLSINST.DLL
[2014/04/26 09:32:51 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Application Data\winscp.rnd
[2013/11/01 16:28:40 | 000,000,064 | ---- | C] () -- C:\windows\FLS1.INI
[2013/10/23 19:53:31 | 002,150,744 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2013/10/10 13:07:49 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2013/09/25 14:55:01 | 000,000,010 | ---- | C] () -- C:\windows\WININIT.INI
[2013/09/17 14:36:38 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/01 13:20:29 | 000,584,584 | ---- | C] () -- C:\windows\adb.exe
[2013/05/29 12:48:50 | 000,031,557 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Application Data\Comma Separated Values (Windows).ADR
[2013/05/29 12:46:21 | 000,031,553 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Application Data\Comma Separated Values (DOS).ADR
[2013/05/21 16:11:50 | 000,159,200 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Application Data\CrashRpt1402.dll
[2013/04/17 12:20:19 | 000,041,344 | ---- | C] () -- C:\windows\System32\drivers\bcmvcp.sys
[2013/04/09 20:09:17 | 003,924,318 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-299502267-115176313-682003330-1003-0.dat
[2013/04/09 20:09:16 | 000,302,890 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2013/04/06 10:09:28 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Application Data\$_hpcst$.hpc
[2013/04/04 12:35:49 | 000,021,888 | ---- | C] () -- C:\windows\System32\drivers\eps2kt1.sys
[2013/04/04 12:35:49 | 000,004,608 | ---- | C] () -- C:\windows\System32\R5CoInst.dll
[2013/04/03 21:36:52 | 000,003,072 | ---- | C] () -- C:\windows\System32\iacenc.dll
[2013/04/02 16:58:14 | 000,004,161 | ---- | C] () -- C:\windows\ODBCINST.INI
[2013/04/02 16:57:05 | 000,281,336 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2013/04/02 16:07:04 | 000,005,810 | ---- | C] () -- C:\windows\System32\drivers\ASACPI.sys
[2013/04/02 15:00:25 | 000,354,816 | ---- | C] () -- C:\windows\System32\psisdecd.dll
[2013/04/02 14:52:54 | 000,001,769 | ---- | C] () -- C:\windows\Language_trs.ini
[2013/04/02 14:52:18 | 000,073,728 | ---- | C] () -- C:\windows\System32\RtNicProp32.dll
[2013/04/02 14:16:48 | 000,002,048 | --S- | C] () -- C:\windows\bootstat.dat
[2013/04/02 14:12:03 | 000,021,640 | ---- | C] () -- C:\windows\System32\emptyregdb.dat
[2013/02/07 11:33:33 | 000,015,048 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\NetMailTmp.bin
[2013/02/07 11:33:33 | 000,015,048 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\NetMailTmp.bin
[2013/02/05 17:52:54 | 000,030,568 | ---- | C] () -- C:\windows\MusiccityDownload.exe
[2013/02/05 17:52:50 | 000,974,848 | ---- | C] () -- C:\windows\System32\cis-2.4.dll
[2013/02/05 17:52:50 | 000,081,920 | ---- | C] () -- C:\windows\System32\issacapi_bs-2.3.dll
[2013/02/05 17:52:50 | 000,065,536 | ---- | C] () -- C:\windows\System32\issacapi_pe-2.3.dll
[2013/02/05 17:52:50 | 000,057,344 | ---- | C] () -- C:\windows\System32\issacapi_se-2.3.dll
[2012/11/19 12:16:23 | 000,044,401 | -H-- | C] () -- C:\windows\KesenjanganSosial.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\winlogon.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\winlogon.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\smss.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\smss.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\services.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\services.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\lsass.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\lsass.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\inetinfo.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\inetinfo.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\csrss.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\csrss.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\windows\System32\cmd-brontok.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br8109on.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br4743on.exe
[2012/11/19 12:16:23 | 000,044,401 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\br4743on.exe
 
========== ZeroAccess Check ==========
 
[2013/04/02 14:58:57 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/08/21 15:00:00 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 15:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/08/21 15:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2014/06/04 11:42:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/09/17 14:49:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Applications
[2013/06/24 10:27:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ask
[2013/04/02 16:18:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Babylon
[2013/05/28 13:20:57 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2013/10/10 12:41:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HTC
[2013/12/02 16:06:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2013/10/10 12:40:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motorola
[2014/05/06 17:45:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
[2013/04/02 17:54:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache
[2013/11/02 09:43:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Package Cache
[2013/04/08 10:34:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2013/05/16 11:36:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2013/04/02 18:37:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2013/08/27 16:48:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SP_FT_Logs
[2013/05/22 19:30:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2013/05/28 13:21:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2013/08/19 13:31:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Wondershare
[2013/05/28 13:20:57 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2013/05/28 13:37:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\TuneUp Software
[2014/07/14 17:08:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\PowerISO
[2013/04/02 16:18:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\Babylon
[2013/07/20 10:26:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\DiskAid
[2014/01/31 15:08:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\HTC
[2013/10/10 12:41:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\HTC Sync
[2013/10/24 09:52:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2014/02/05 15:56:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\mgyun
[2013/11/01 16:25:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\Nokia
[2013/05/13 13:36:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\Nokia Suite
[2013/10/10 13:12:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\Outlook
[2014/07/29 12:23:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\PC Suite
[2014/07/12 09:40:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\PowerISO
[2013/10/24 14:51:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\redsn0w
[2013/04/08 17:39:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\Research In Motion
[2013/12/11 13:50:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\Samsung
[2013/04/02 16:38:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\TeamViewer
[2013/05/28 13:21:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\TuneUp Software
[2014/07/12 10:02:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\uTorrent
[2013/04/10 20:18:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\Windows Search
[2014/05/28 14:45:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\XCPCSync.OEM
[2013/08/23 17:54:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\XTC-Clip
[2014/05/19 13:36:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radu Mamii\Application Data\ZJMedia
 
========== Purity Check ==========
 
 
 
< End of report >
 

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Obviously your work does not believe in security as there is no apparent antivirus, you appear to have had a brontok worm since 2010, various Trojans since 2012 Brontok has been updating itself though as it has the 2012 version as well. Personally I would no longer treat this system as secure you have probably had a lot of data stolen from it.

Do you have an IT department ?

I can attempt to clean this but I can give no guarantee that it will ever be safe.

How do you wish to proceed
  • 0

#3
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts

We cannot format it  because we have importand data ,i work here from a year so not my fault :) I want to try to clean them ...also .. at work i have 3 pc's ,2 infected and 1 recently formatted but now i move a phone from infected to clean and the 3 rd computer just got infected .Should I create new topics with the other 2 or post in this thread? Also after that i'll install an av , i think avira to be more easy to monitor the pc's .


  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

OK lets get to cleaning this may be a lengthy process. As this is a worm you will need to keep the computers isolated from each other

I will give you a programme which I will ask you to install on all computers to prevent any transfer of malware by USB/Phone


INSTALL ON ALL SYSTEMS

Download MCShield to your desktop and install
It will initially run a scan and show the result as a toaster by the system clock
Then in the control centre select scanner and tick unhide items on flash drives
mcshield%20unhide.JPG
Plug in the drive and McShield will start a scan

I will then clean one at a time, are the different computers named or shall we work by numbers ? I am easy with whichever way you choose


FIRST SYSTEM

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    http://img.photobuck...claimer_ENG.png

    NSIS_extraction.png
    • When finished, it shall produce a log for you.
    • Please include the C:\ComboFix.txt in your next reply.
    •  
    Notes:
    1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

    3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


    Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

THEN

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Select additions at the bottom
  • Press Scan button.
    frst.JPG
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please attach both logs generated.

  • 0

#5
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts

After run combofix  stays a couple of seconds and rstarts without any log.log for frst:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:2-08-2014
Ran by Radu Mamii (administrator) on SERVICE-429D9B2 on 04-08-2014 21:55:18
Running from C:\Documents and Settings\Radu Mamii\Desktop
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Nero AG) C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Mobile Leader Co.,Ltd.) C:\WINDOWS\system32\LGScsiCommandService.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Apple Inc.) C:\Program Files\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe
(Mobile Leader Co.,Ltd.) C:\WINDOWS\system32\ScsiCommandService2.exe
(Microsoft Corporation) C:\Program Files\Zune\ZuneBusEnum.exe
() C:\WINDOWS\system32\FLSDEVCP.EXE
(Research In Motion Limited) C:\Program Files\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe
(Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(Yahoo! Inc.) C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe
(Microsoft Corporation) C:\Program Files\Microsoft ActiveSync\wcescomm.exe
(Nokia) C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
(Samsung) C:\Program Files\SAMSUNG\Kies\External\FirmwareUpdate\KiesPDLR.exe
() C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
(MyCity) C:\Program Files\MCShield\MCShieldRTM.exe
(Microsoft Corporation) C:\PROGRA~1\MI3AA1~1\rapimgr.exe
() C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\winlogon.exe
() C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\services.exe
(Yahoo! Inc.) C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe
() C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\lsass.exe
(BlackBerry Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
(SPT Team) C:\Program Files\SPT\SPT.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Winlogon: [Shell] Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe" [x ] ()
HKU\.DEFAULT\...\Run: [Samsung.PCSync] => C:\Program Files\Samsung\Samsung PC Studio 7\PcSync2.exe [1294336 2009-06-04] (Nokia)
HKU\.DEFAULT\...\Run: [Tok-Cirrhatus-1860] => C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br4743on.exe [44401 2010-02-27] ()
HKU\.DEFAULT\...\Run: [Tok-Cirrhatus] => C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br4743on.exe [44401 2010-02-27] ()
HKU\.DEFAULT\...\Policies\system: [DisableRegistryTools] 1
HKU\.DEFAULT\...\Policies\system: [DisableCMD] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoFolderOptions] 1
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Run: [Messenger (Yahoo!)] => C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.)
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Run: [H/PC Connection Agent] => C:\Program Files\Microsoft ActiveSync\wcescomm.exe [1964840 2006-09-10] (Microsoft Corporation)
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Run: [PC Suite Tray] => C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Run: [] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-11-06] (Samsung)
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Run: [Tok-Cirrhatus-3543] => C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br8109on.exe [44401 2010-02-27] ()
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Run: [Tok-Cirrhatus] => C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br8109on.exe [44401 2010-02-27] ()
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Run: [MCShield Monitor] => C:\Program Files\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Policies\system: [DisableRegistryTools] 1
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Policies\Explorer: [NoFolderOptions] 1
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\MountPoints2: {076eb344-92ef-11e3-b171-0298f9328801} - F:\LGAutoRun.exe
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\MountPoints2: {076eb356-92ef-11e3-b171-0298f9328801} - F:\LGAutoRun.exe
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\MountPoints2: {156b969f-0be8-11e3-b072-0208fd748701} - F:\XTC-Clip_PLUS.exe
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\MountPoints2: {1e86c291-5b50-11e3-b109-02a81c228801} - F:\NokiaPCIA_Autorun.exe
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\MountPoints2: {36f85459-d67b-11e3-b1e1-02d885a28801} - F:\LG_PC_Programs.exe
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\MountPoints2: {531d4e92-b0a2-11e2-afe5-002354cb06b4} - F:\Autorun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2066.1.9B05 PID_0083
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\MountPoints2: {78a79f28-c39c-11e3-b1c9-0230ae878801} - F:\LGAutoRun.exe
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\MountPoints2: {ca2c0f60-e237-11e2-b02d-02c8e0508701} - F:\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2088.1.A01B06 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B}
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\MountPoints2: {cf93d1f7-0e44-11e4-b248-02a05d5b8901} - G:\LG_PC_Programs.exe
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\MountPoints2: {d6adc743-6234-11e3-b123-0258c31f8801} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\MountPoints2: {d8d1f7f7-b8ab-11e2-aff0-002354cb06b4} - F:\VTP_Manager.exe
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\MountPoints2: {d8d1f7f8-b8ab-11e2-aff0-002354cb06b4} - F:\LGAutoRun.exe
Startup: C:\Documents and Settings\NetworkService\Start Menu\Programs\Startup\Empty.pif ()
Startup: C:\Documents and Settings\Radu Mamii\Start Menu\Programs\Startup\Empty.pif ()
AlternateShell: cmd-brontok.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ro/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
URLSearchHook: HKCU - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} -  No File
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com...rchTerms}&SSPV=
SearchScopes: HKCU - {2E22C5E0-253F-4AF3-BCA7-02F476B9E955} URL = http://websearch.ask...E5-1DF470ED5518
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\windows\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\windows\system32\SHELL32.dll (Microsoft Corporation)
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
 
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Radu Mamii\Application Data\Mozilla\Firefox\Profiles\j7hu8h2q.default
FF Homepage: about:home
FF SelectedSearchEngine: Google
FF NewTab: about:newtab
FF DefaultSearchEngine: Google
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nokia.com/EnablerPlugin -> C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Documents and Settings\Radu Mamii\Application Data\Mozilla\Firefox\Profiles\j7hu8h2q.default\searchplugins\trovi-search.xml
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-04-04]
 
Chrome: 
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: ""
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\36.0.1985.125\pdf.dll ()
CHR Plugin: (Microsoft DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Extension: (Google Docs) - C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-04-02]
CHR Extension: (Google Drive) - C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-04-02]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-23]
CHR Extension: (YouTube) - C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-04-02]
CHR Extension: (Adblock Plus) - C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-08-22]
CHR Extension: (Google Search) - C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-04-02]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Gmail) - C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-04-02]
CHR Extension: (Extutil) - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B [2014-07-12]
CHR Extension: (Managera) - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42 [2014-07-12]
CHR HKLM\...\Chrome\Extension: [bbffdhejhaoiflnpooogkckfdcmmjppn] - C:\Program Files\FTDownloader.com\FTDownloader10.crx [2014-07-12]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 6to4; C:\windows\System32\6to4svc.dll [100864 2010-02-12] (Microsoft Corporation) [File not signed]
S4 Alerter; C:\windows\system32\alrsvc.dll [17408 2008-08-21] (Microsoft Corporation) [File not signed]
R3 ALG; C:\windows\System32\alg.exe [44544 2008-08-21] (Microsoft Corporation) [File not signed]
S3 AppMgmt; C:\windows\System32\appmgmts.dll [167936 2008-08-21] (Microsoft Corporation) [File not signed]
R2 AudioSrv; C:\windows\System32\audiosrv.dll [42496 2008-08-21] (Microsoft Corporation) [File not signed]
S3 BITS; C:\WINDOWS\system32\qmgr.dll [409088 2008-08-21] (Microsoft Corporation) [File not signed]
R3 BlackBerry Device Manager; C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [585728 2014-01-21] (BlackBerry Limited) [File not signed]
R2 Browser; C:\windows\System32\browser.dll [78336 2012-07-06] (Microsoft Corporation) [File not signed]
S3 CiSvc; C:\windows\system32\cisvc.exe [5632 2008-08-21] (Microsoft Corporation) [File not signed]
S4 ClipSrv; C:\windows\system32\clipsrv.exe [33280 2008-08-21] (Microsoft Corporation) [File not signed]
S3 COMSysApp; C:\WINDOWS\system32\dllhost.exe [5120 2008-08-21] (Microsoft Corporation) [File not signed]
R2 CryptSvc; C:\windows\System32\cryptsvc.dll [62464 2008-08-21] (Microsoft Corporation) [File not signed]
R2 DcomLaunch; C:\windows\system32\rpcss.dll [401408 2009-02-09] (Microsoft Corporation) [File not signed]
R2 Dhcp; C:\windows\System32\dhcpcsvc.dll [126976 2008-08-21] (Microsoft Corporation) [File not signed]
S3 dmadmin; C:\windows\System32\dmadmin.exe [224768 2008-08-21] (Microsoft Corp., Veritas Software) [File not signed]
R2 dmserver; C:\windows\System32\dmserver.dll [23552 2008-08-21] (Microsoft Corp.) [File not signed]
R2 Dnscache; C:\windows\System32\dnsrslvr.dll [45568 2009-04-20] (Microsoft Corporation) [File not signed]
S3 Dot3svc; C:\windows\System32\dot3svc.dll [132096 2008-08-21] (Microsoft Corporation) [File not signed]
S3 EapHost; C:\windows\System32\eapsvc.dll [33792 2008-08-21] (Microsoft Corporation) [File not signed]
R2 ERSvc; C:\windows\System32\ersvc.dll [23040 2008-08-21] (Microsoft Corporation) [File not signed]
R2 Eventlog; C:\windows\system32\services.exe [110592 2009-02-06] (Microsoft Corporation) [File not signed]
R3 EventSystem; C:\WINDOWS\system32\es.dll [253952 2008-07-07] (Microsoft Corporation) [File not signed]
R3 FastUserSwitchingCompatibility; C:\windows\System32\shsvcs.dll [135168 2009-07-28] (Microsoft Corporation) [File not signed]
R2 helpsvc; C:\windows\PCHealth\HelpCtr\Binaries\pchsvc.dll [38400 2008-08-21] (Microsoft Corporation) [File not signed]
R2 HidServ; C:\windows\System32\hidserv.dll [21504 2008-04-14] (Microsoft Corporation) [File not signed]
S3 hkmsvc; C:\windows\System32\kmsvc.dll [61440 2008-08-21] (Microsoft Corporation) [File not signed]
R2 HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-09-02] (Nero AG)
R3 HTTPFilter; C:\windows\System32\w3ssl.dll [15872 2008-08-21] (Microsoft Corporation) [File not signed]
S3 ImapiService; C:\WINDOWS\system32\imapi.exe [150528 2008-08-21] (Microsoft Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-05-07] (Oracle Corporation)
R2 LanmanServer; C:\windows\System32\srvsvc.dll [99840 2010-08-27] (Microsoft Corporation) [File not signed]
R2 lanmanworkstation; C:\windows\System32\wkssvc.dll [132096 2009-06-10] (Microsoft Corporation) [File not signed]
R2 LGScsiCommandService; C:\WINDOWS\system32\LGScsiCommandService.exe [47616 2010-03-05] (Mobile Leader Co.,Ltd.) [File not signed]
R2 LmHosts; C:\windows\System32\lmhsvc.dll [13824 2008-08-21] (Microsoft Corporation) [File not signed]
S4 Messenger; C:\windows\System32\msgsvc.dll [33792 2008-08-21] (Microsoft Corporation) [File not signed]
S3 mnmsrvc; C:\WINDOWS\system32\mnmsrvc.exe [32768 2008-08-21] (Microsoft Corporation) [File not signed]
S3 MSDTC; C:\WINDOWS\system32\msdtc.exe [6144 2008-08-21] (Microsoft Corporation) [File not signed]
S3 MSIServer; C:\windows\System32\msiexec.exe [78848 2008-08-21] (Microsoft Corporation) [File not signed]
S3 napagent; C:\windows\System32\qagentrt.dll [291328 2008-08-21] (Microsoft Corporation) [File not signed]
S4 NetDDE; C:\windows\system32\netdde.exe [111104 2008-08-21] (Microsoft Corporation) [File not signed]
S4 NetDDEdsdm; C:\windows\system32\netdde.exe [111104 2008-08-21] (Microsoft Corporation) [File not signed]
S3 Netlogon; C:\windows\system32\lsass.exe [13312 2008-08-21] (Microsoft Corporation) [File not signed]
R3 Netman; C:\windows\System32\netman.dll [198144 2008-08-21] (Microsoft Corporation) [File not signed]
R3 Nla; C:\windows\System32\mswsock.dll [245248 2008-06-20] (Microsoft Corporation) [File not signed]
S3 NtLmSsp; C:\windows\system32\lsass.exe [13312 2008-08-21] (Microsoft Corporation) [File not signed]
S3 NtmsSvc; C:\windows\system32\ntmssvc.dll [435200 2008-08-21] (Microsoft Corporation) [File not signed]
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
R2 PlugPlay; C:\windows\system32\services.exe [110592 2009-02-06] (Microsoft Corporation) [File not signed]
R2 PolicyAgent; C:\windows\system32\lsass.exe [13312 2008-08-21] (Microsoft Corporation) [File not signed]
R2 ProtectedStorage; C:\windows\system32\lsass.exe [13312 2008-08-21] (Microsoft Corporation) [File not signed]
S3 RasAuto; C:\windows\System32\rasauto.dll [88576 2008-08-21] (Microsoft Corporation) [File not signed]
R3 RasMan; C:\windows\System32\rasmans.dll [186368 2008-08-21] (Microsoft Corporation) [File not signed]
S3 RDSessMgr; C:\WINDOWS\system32\sessmgr.exe [141312 2008-08-21] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\windows\System32\mprdim.dll [53248 2008-08-21] (Microsoft Corporation) [File not signed]
R2 RemoteRegistry; C:\windows\system32\regsvc.dll [59904 2008-08-21] (Microsoft Corporation) [File not signed]
R2 RIM MDNS; C:\Program Files\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe [389632 2014-05-07] (Apple Inc.) [File not signed]
R2 RIM Tunnel Service; C:\Program Files\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe [1324544 2014-05-07] (Research In Motion Limited) [File not signed]
S3 RpcLocator; C:\windows\system32\locator.exe [75264 2008-08-21] (Microsoft Corporation) [File not signed]
R2 RpcSs; C:\windows\system32\rpcss.dll [401408 2009-02-09] (Microsoft Corporation) [File not signed]
S3 RSVP; C:\windows\system32\rsvp.exe [132608 2008-08-21] (Microsoft Corporation) [File not signed]
R2 SamSs; C:\windows\system32\lsass.exe [13312 2008-08-21] (Microsoft Corporation) [File not signed]
R2 SCardSvr; C:\windows\System32\SCardSvr.exe [95744 2008-08-21] (Microsoft Corporation) [File not signed]
R2 Schedule; C:\windows\system32\schedsvc.dll [192512 2008-08-21] (Microsoft Corporation) [File not signed]
R2 ScsiCommandService2; C:\windows\system32\ScsiCommandService2.exe [48128 2011-10-31] (Mobile Leader Co.,Ltd.) [File not signed]
R2 seclogon; C:\windows\System32\seclogon.dll [18944 2008-08-21] (Microsoft Corporation) [File not signed]
R2 SENS; C:\windows\system32\sens.dll [39424 2008-08-21] (Microsoft Corporation) [File not signed]
R2 SharedAccess; C:\windows\System32\ipnathlp.dll [331264 2008-08-21] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\windows\System32\shsvcs.dll [135168 2009-07-28] (Microsoft Corporation) [File not signed]
R2 Spooler; C:\windows\system32\spoolsv.exe [58880 2010-08-17] (Microsoft Corporation) [File not signed]
R2 srservice; C:\WINDOWS\system32\srsvc.dll [171008 2008-08-21] (Microsoft Corporation) [File not signed]
R3 SSDPSRV; C:\windows\System32\ssdpsrv.dll [71680 2008-08-21] (Microsoft Corporation) [File not signed]
R2 stisvc; C:\windows\system32\wiaservc.dll [333824 2008-08-21] (Microsoft Corporation) [File not signed]
S3 SwPrv; C:\WINDOWS\system32\dllhost.exe [5120 2008-08-21] (Microsoft Corporation) [File not signed]
S3 SysmonLog; C:\windows\system32\smlogsvc.exe [89600 2008-08-21] (Microsoft Corporation) [File not signed]
R3 TapiSrv; C:\windows\System32\tapisrv.dll [249856 2008-08-21] (Microsoft Corporation) [File not signed]
R3 TermService; C:\windows\System32\termsrv.dll [295424 2008-08-21] (Microsoft Corporation) [File not signed]
R2 Themes; C:\windows\System32\shsvcs.dll [135168 2009-07-28] (Microsoft Corporation) [File not signed]
S4 TlntSvr; C:\WINDOWS\system32\tlntsvr.exe [73216 2008-08-21] (Microsoft Corporation) [File not signed]
R2 TrkWks; C:\windows\system32\trkwks.dll [90112 2008-08-21] (Microsoft Corporation) [File not signed]
S3 upnphost; C:\windows\System32\upnphost.dll [185856 2008-08-21] (Microsoft Corporation) [File not signed]
S3 UPS; C:\windows\System32\ups.exe [18432 2008-08-21] (Microsoft Corporation) [File not signed]
S3 VSS; C:\windows\System32\vssvc.exe [289792 2008-08-21] (Microsoft Corporation) [File not signed]
R2 W32Time; C:\WINDOWS\system32\w32time.dll [175104 2008-08-21] (Microsoft Corporation) [File not signed]
R2 WebClient; C:\windows\System32\webclnt.dll [68096 2008-08-21] (Microsoft Corporation) [File not signed]
R2 winmgmt; C:\windows\system32\wbem\WMIsvc.dll [144896 2008-08-21] (Microsoft Corporation) [File not signed]
S3 Wmi; C:\windows\System32\advapi32.dll [617472 2009-02-09] (Microsoft Corporation) [File not signed]
S3 WmiApSrv; C:\WINDOWS\system32\wbem\wmiapsrv.exe [126464 2008-08-21] (Microsoft Corporation) [File not signed]
R2 wscsvc; C:\windows\system32\wscsvc.dll [80896 2008-08-21] (Microsoft Corporation) [File not signed]
R2 wuauserv; C:\WINDOWS\system32\wuauserv.dll [6656 2008-08-21] (Microsoft Corporation) [File not signed]
R2 WudfSvc; C:\windows\System32\WUDFSvc.dll [64512 2009-07-13] (Microsoft Corporation) [File not signed]
R2 WZCSVC; C:\windows\System32\wzcsvc.dll [483840 2008-08-21] (Microsoft Corporation) [File not signed]
S3 xmlprov; C:\windows\System32\xmlprov.dll [129024 2008-08-21] (Microsoft Corporation) [File not signed]
R2 ZuneBusEnum; c:\Program Files\Zune\ZuneBusEnum.exe [57056 2011-08-05] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 ACPI; C:\windows\System32\DRIVERS\ACPI.sys [187776 2008-08-21] (Microsoft Corporation) [File not signed]
S4 ACPIEC; C:\windows\system32\Drivers\ACPIEC.sys [11648 2008-08-21] (Microsoft Corporation) [File not signed]
S3 aec; C:\windows\System32\drivers\aec.sys [142592 2008-04-13] (Microsoft Corporation) [File not signed]
R1 AFD; C:\windows\System32\drivers\afd.sys [138496 2011-08-17] (Microsoft Corporation) [File not signed]
S3 Andbus; C:\windows\System32\DRIVERS\lgandbus.sys [14336 2012-03-02] (LG Electronics Inc.)
S3 AndDiag; C:\windows\System32\DRIVERS\lganddiag.sys [20736 2012-03-02] (LG Electronics Inc.)
S3 AndGps; C:\windows\System32\DRIVERS\lgandgps.sys [20096 2012-03-02] (LG Electronics Inc.)
S3 ANDModem; C:\windows\System32\DRIVERS\lgandmodem.sys [25088 2012-03-02] (LG Electronics Inc.)
S3 andnetadb; C:\windows\System32\Drivers\lgandnetadb.sys [25856 2012-07-03] (Google Inc)
S3 AndNetDiag; C:\windows\System32\DRIVERS\lgandnetdiag.sys [23040 2012-07-03] (LG Electronics Inc.)
S3 ANDNetModem; C:\windows\System32\DRIVERS\lgandnetmodem.sys [27776 2012-07-03] (LG Electronics Inc.)
S3 andnetndis; C:\windows\System32\DRIVERS\lgandnetndis.sys [70400 2012-07-04] (LG Electronics Inc.)
S3 AsyncMac; C:\windows\System32\DRIVERS\asyncmac.sys [14336 2008-08-21] (Microsoft Corporation) [File not signed]
R0 atapi; C:\windows\System32\DRIVERS\atapi.sys [96512 2008-04-14] (Microsoft Corporation) [File not signed]
S3 Atmarpc; C:\windows\System32\DRIVERS\atmarpc.sys [59904 2008-08-21] (Microsoft Corporation) [File not signed]
R3 audstub; C:\windows\System32\DRIVERS\audstub.sys [3072 2001-08-17] (Microsoft Corporation) [File not signed]
R1 Beep; C:\windows\system32\Drivers\Beep.sys [4224 2008-08-21] (Microsoft Corporation) [File not signed]
S3 BRCM; C:\windows\System32\Drivers\bcmvcp.sys [41344 2011-05-13] () [File not signed]
S4 cbidf2k; C:\windows\system32\Drivers\cbidf2k.sys [13952 2008-08-21] (Microsoft Corporation) [File not signed]
S1 Cdaudio; C:\windows\system32\Drivers\Cdaudio.sys [18688 2008-08-21] (Microsoft Corporation) [File not signed]
R4 Cdfs; C:\windows\system32\Drivers\Cdfs.sys [63744 2008-08-21] (Microsoft Corporation) [File not signed]
R1 Cdrom; C:\windows\System32\DRIVERS\cdrom.sys [62976 2008-05-02] (Microsoft Corporation) [File not signed]
S3 CSSTUSB; C:\windows\System32\DRIVERS\csstusb.sys [33792 2011-03-09] (Texas Instruments Inc.) [File not signed]
S3 cyclonebox; C:\windows\System32\DRIVERS\cyclonebox.sys [37184 2011-03-01] (http://libusb-win32.sourceforge.net)
S3 DFU; C:\windows\System32\DRIVERS\52xdfu.sys [12416 2010-02-03] (NXP Semiconductors) [File not signed]
R0 Disk; C:\windows\System32\DRIVERS\disk.sys [36352 2008-04-14] (Microsoft Corporation) [File not signed]
S4 dmboot; C:\windows\System32\drivers\dmboot.sys [799744 2008-08-21] (Microsoft Corp., Veritas Software) [File not signed]
R0 dmio; C:\windows\System32\drivers\dmio.sys [153344 2008-08-21] (Microsoft Corp., Veritas Software) [File not signed]
R0 dmload; C:\windows\System32\drivers\dmload.sys [5888 2008-08-21] (Microsoft Corp., Veritas Software.) [File not signed]
S3 DMusic; C:\windows\System32\drivers\DMusic.sys [52864 2008-04-14] (Microsoft Corporation) [File not signed]
R3 DreamBox; C:\windows\System32\DRIVERS\DREAMBOX.sys [17152 2010-04-13] (GSM Dream Team) [File not signed]
S3 drmkaud; C:\windows\System32\drivers\drmkaud.sys [2944 2008-04-14] (Microsoft Corporation) [File not signed]
R3 Egatebus; C:\windows\System32\drivers\egatebus.sys [15328 2006-05-19] (Axalto) [File not signed]
R3 Egatecard; C:\windows\System32\Drivers\egate.sys [18880 2006-05-19] (Axalto) [File not signed]
R3 Egaterdr; C:\windows\System32\drivers\egaterdr.sys [13440 2006-05-19] (Axalto) [File not signed]
R4 Fastfat; C:\windows\system32\Drivers\Fastfat.sys [143744 2008-08-21] (Microsoft Corporation) [File not signed]
R3 Fdc; C:\windows\System32\DRIVERS\fdc.sys [27392 2008-04-14] (Microsoft Corporation) [File not signed]
R1 Fips; C:\windows\system32\Drivers\Fips.sys [44544 2008-08-21] (Microsoft Corporation) [File not signed]
S3 FlashUSB; C:\windows\System32\DRIVERS\FlashUSB.sys [16384 2013-08-21] (Intel Mobile Communications)
R2 FLE5WNNT; C:\windows\System32\Drivers\fle5wnnt.sys [33404 2014-05-06] (Data Encryption Systems Limited) [File not signed]
R3 Flpydisk; C:\windows\System32\DRIVERS\flpydisk.sys [20480 2008-04-14] (Microsoft Corporation) [File not signed]
R2 FLSIFACE; C:\windows\System32\Drivers\flsiface.sys [14272 2014-05-06] (Data Encryption Systems Limited) [File not signed]
R2 FLSPAR; C:\windows\System32\Drivers\flspar.sys [16314 2014-05-06] (Data Encryption Systems Limited) [File not signed]
R2 FLSSER; C:\windows\System32\Drivers\flsser.sys [8344 2014-05-06] (Data Encryption Systems Limited) [File not signed]
R2 FLSVCOM; C:\windows\System32\Drivers\flsvcom.sys [35226 2014-05-06] (Data Encryption Systems Limited) [File not signed]
R0 FltMgr; C:\windows\System32\DRIVERS\fltMgr.sys [129792 2008-08-21] (Microsoft Corporation) [File not signed]
U1 Fs_Rec; C:\windows\system32\Drivers\Fs_Rec.sys [7936 2008-08-21] (Microsoft Corporation) [File not signed]
R3 FTDIBUS; C:\windows\System32\drivers\ftdibus.sys [57800 2009-10-22] (FTDI Ltd.)
R0 Ftdisk; C:\windows\System32\DRIVERS\ftdisk.sys [125056 2008-08-21] (Microsoft Corporation) [File not signed]
S3 ghsser; C:\windows\System32\DRIVERS\ghsser.sys [107776 2012-09-04] (HS Coporation) [File not signed]
R3 Gpc; C:\windows\System32\DRIVERS\msgpc.sys [35072 2008-08-21] (Microsoft Corporation) [File not signed]
S3 gxdlusb; C:\windows\System32\DRIVERS\gxdlusb.sys [10240 2004-03-02] (SHARP Corporation) [File not signed]
S3 HdAudAddService; C:\windows\System32\drivers\AtiHdAud.sys [84992 2006-12-28] (ATI Research Inc.) [File not signed]
R3 HDAudBus; C:\windows\System32\DRIVERS\HDAudBus.sys [144384 2008-08-21] (Windows ® Server 2003 DDK provider) [File not signed]
S3 hidusb; C:\windows\System32\DRIVERS\hidusb.sys [10368 2008-04-14] (Microsoft Corporation) [File not signed]
R3 HTTP; C:\windows\System32\Drivers\HTTP.sys [265728 2009-10-20] (Microsoft Corporation) [File not signed]
R1 i8042prt; C:\windows\System32\DRIVERS\i8042prt.sys [52480 2008-08-21] (Microsoft Corporation) [File not signed]
R1 Imapi; C:\windows\System32\DRIVERS\imapi.sys [42112 2008-04-14] (Microsoft Corporation) [File not signed]
R1 intelppm; C:\windows\System32\DRIVERS\intelppm.sys [36352 2008-08-21] (Microsoft Corporation) [File not signed]
R3 Ip6Fw; C:\windows\System32\DRIVERS\Ip6Fw.sys [36608 2008-08-21] (Microsoft Corporation) [File not signed]
S3 IpFilterDriver; C:\windows\System32\DRIVERS\ipfltdrv.sys [32896 2008-08-21] (Microsoft Corporation) [File not signed]
S3 IpInIp; C:\windows\System32\DRIVERS\ipinip.sys [20864 2008-08-21] (Microsoft Corporation) [File not signed]
R3 IpNat; C:\windows\System32\DRIVERS\ipnat.sys [152832 2008-08-21] (Microsoft Corporation) [File not signed]
R1 IPSec; C:\windows\System32\DRIVERS\ipsec.sys [75264 2008-08-21] (Microsoft Corporation) [File not signed]
S3 IRENUM; C:\windows\System32\DRIVERS\irenum.sys [11264 2008-08-21] (Microsoft Corporation) [File not signed]
R0 isapnp; C:\windows\System32\DRIVERS\isapnp.sys [37248 2008-04-14] (Microsoft Corporation) [File not signed]
R1 Kbdclass; C:\windows\System32\DRIVERS\kbdclass.sys [24576 2008-04-14] (Microsoft Corporation) [File not signed]
S1 kbdhid; C:\windows\System32\DRIVERS\kbdhid.sys [14592 2008-04-14] (Microsoft Corporation) [File not signed]
R3 kmixer; C:\windows\System32\drivers\kmixer.sys [172416 2008-04-14] (Microsoft Corporation) [File not signed]
R0 KSecDD; C:\windows\system32\Drivers\KSecDD.sys [92928 2009-06-24] (Microsoft Corporation) [File not signed]
R1 mnmdd; C:\windows\system32\Drivers\mnmdd.sys [4224 2008-08-21] (Microsoft Corporation) [File not signed]
R3 Modem; C:\windows\system32\Drivers\Modem.sys [30080 2008-08-21] (Microsoft Corporation) [File not signed]
R1 Mouclass; C:\windows\System32\DRIVERS\mouclass.sys [23040 2008-04-14] (Microsoft Corporation) [File not signed]
R0 MountMgr; C:\windows\system32\Drivers\MountMgr.sys [42368 2008-08-21] (Microsoft Corporation) [File not signed]
R3 MRxDAV; C:\windows\System32\DRIVERS\mrxdav.sys [180608 2008-08-21] (Microsoft Corporation) [File not signed]
R1 MRxSmb; C:\windows\System32\DRIVERS\mrxsmb.sys [456320 2011-07-15] (Microsoft Corporation) [File not signed]
R1 Msfs; C:\windows\system32\Drivers\Msfs.sys [19072 2008-08-21] (Microsoft Corporation) [File not signed]
S3 MSKSSRV; C:\windows\System32\drivers\MSKSSRV.sys [7552 2008-04-14] (Microsoft Corporation) [File not signed]
S3 MSPCLOCK; C:\windows\System32\drivers\MSPCLOCK.sys [5376 2008-04-14] (Microsoft Corporation) [File not signed]
S3 MSPQM; C:\windows\System32\drivers\MSPQM.sys [4992 2008-04-14] (Microsoft Corporation) [File not signed]
R3 mssmbios; C:\windows\System32\DRIVERS\mssmbios.sys [15488 2008-08-21] (Microsoft Corporation) [File not signed]
S3 mstrgen; C:\windows\System32\DRIVERS\mstrgen.sys [62080 2009-07-22] (MCCI)
R3 MTsensor; C:\windows\System32\DRIVERS\ASACPI.sys [5810 2006-02-26] () [File not signed]
R0 Mup; C:\windows\system32\Drivers\Mup.sys [105472 2011-04-21] (Microsoft Corporation) [File not signed]
R0 NDIS; C:\windows\system32\Drivers\NDIS.sys [182656 2008-08-21] (Microsoft Corporation) [File not signed]
R3 NdisTapi; C:\windows\System32\DRIVERS\ndistapi.sys [10496 2011-07-08] (Microsoft Corporation) [File not signed]
R3 Ndisuio; C:\windows\System32\DRIVERS\ndisuio.sys [14592 2008-08-21] (Microsoft Corporation) [File not signed]
R3 NdisWan; C:\windows\System32\DRIVERS\ndiswan.sys [91520 2008-08-21] (Microsoft Corporation) [File not signed]
R1 NetBIOS; C:\windows\System32\DRIVERS\netbios.sys [34688 2008-08-21] (Microsoft Corporation) [File not signed]
R1 NetBT; C:\windows\System32\DRIVERS\netbt.sys [162816 2008-08-21] (Microsoft Corporation) [File not signed]
S3 nmwcdsa; C:\windows\System32\drivers\ccdcmbsa.sys [18176 2010-04-27] (Nokia)
S3 NOKIA_3806_PHONE; C:\windows\System32\DRIVERS\NOKIA_3806_PHONE.sys [101120 2009-01-15] (QUALCOMM Incorporated)
R1 Npfs; C:\windows\system32\Drivers\Npfs.sys [30848 2008-08-21] (Microsoft Corporation) [File not signed]
R4 Ntfs; C:\windows\system32\Drivers\Ntfs.sys [574976 2008-08-21] (Microsoft Corporation) [File not signed]
R1 Null; C:\windows\system32\Drivers\Null.sys [2944 2008-08-21] (Microsoft Corporation) [File not signed]
S3 NwlnkFlt; C:\windows\System32\DRIVERS\nwlnkflt.sys [12416 2008-08-21] (Microsoft Corporation) [File not signed]
S3 NwlnkFwd; C:\windows\System32\DRIVERS\nwlnkfwd.sys [32512 2008-08-21] (Microsoft Corporation) [File not signed]
R3 Parport; C:\windows\System32\DRIVERS\parport.sys [80128 2008-08-21] (Microsoft Corporation) [File not signed]
R0 PartMgr; C:\windows\system32\Drivers\PartMgr.sys [19712 2008-08-21] (Microsoft Corporation) [File not signed]
R2 ParVdm; C:\windows\system32\Drivers\ParVdm.sys [6784 2008-08-21] (Microsoft Corporation) [File not signed]
R0 PCI; C:\windows\System32\DRIVERS\pci.sys [68224 2008-04-14] (Microsoft Corporation) [File not signed]
R0 PCIIde; C:\windows\System32\DRIVERS\pciide.sys [3328 2001-08-17] (Microsoft Corporation) [File not signed]
S4 Pcmcia; C:\windows\system32\Drivers\Pcmcia.sys [120192 2008-08-21] (Microsoft Corporation) [File not signed]
R3 PptpMiniport; C:\windows\System32\DRIVERS\raspptp.sys [48384 2008-08-21] (Microsoft Corporation) [File not signed]
R3 PSched; C:\windows\System32\DRIVERS\psched.sys [69120 2008-08-21] (Microsoft Corporation) [File not signed]
R3 Ptilink; C:\windows\System32\DRIVERS\ptilink.sys [17792 2008-08-21] (Parallel Technologies, Inc.) [File not signed]
S3 qcusbser; C:\windows\System32\DRIVERS\qcusbser.sys [108160 2011-11-09] (TCL Communicate Incorporated) [File not signed]
R3 R5BaseSmc; C:\windows\System32\DRIVERS\smccard.sys [12800 2013-04-04] (OEM) [File not signed]
R1 RasAcd; C:\windows\System32\DRIVERS\rasacd.sys [8832 2008-08-21] (Microsoft Corporation) [File not signed]
R3 Rasl2tp; C:\windows\System32\DRIVERS\rasl2tp.sys [51328 2008-08-21] (Microsoft Corporation) [File not signed]
R3 RasPppoe; C:\windows\System32\DRIVERS\raspppoe.sys [41472 2008-08-21] (Microsoft Corporation) [File not signed]
R3 Raspti; C:\windows\System32\DRIVERS\raspti.sys [16512 2008-08-21] (Microsoft Corporation) [File not signed]
R1 Rdbss; C:\windows\System32\DRIVERS\rdbss.sys [175744 2008-08-21] (Microsoft Corporation) [File not signed]
R1 RDPCDD; C:\windows\System32\DRIVERS\RDPCDD.sys [4224 2008-08-21] (Microsoft Corporation) [File not signed]
R3 rdpdr; C:\windows\System32\DRIVERS\rdpdr.sys [196224 2008-04-14] (Microsoft Corporation) [File not signed]
S3 RDPWD; C:\windows\system32\Drivers\RDPWD.sys [139784 2012-07-04] (Microsoft Corporation) [File not signed]
R1 redbook; C:\windows\System32\DRIVERS\redbook.sys [57600 2008-04-14] (Microsoft Corporation) [File not signed]
S3 RimUsb; C:\windows\System32\Drivers\RimUsb.sys [68096 2013-12-02] (BlackBerry Limited)
R3 rimvndis; C:\windows\System32\Drivers\rimvndis.sys [12800 2014-05-07] (Research in Motion Limited)
R3 ROOTMODEM; C:\windows\System32\Drivers\RootMdm.sys [5888 2008-08-21] (Microsoft Corporation) [File not signed]
R3 RTLE8023xp; C:\windows\System32\DRIVERS\Rtenicxp.sys [142336 2009-05-25] (Realtek Semiconductor Corporation                           ) [File not signed]
S3 s117bus; C:\windows\System32\DRIVERS\s117bus.sys [82984 2007-06-25] (MCCI Corporation)
S3 s117mdfl; C:\windows\System32\DRIVERS\s117mdfl.sys [14888 2007-06-25] (MCCI Corporation)
S3 s117mdm; C:\windows\System32\DRIVERS\s117mdm.sys [108456 2007-06-25] (MCCI Corporation)
S3 s117mgmt; C:\windows\System32\DRIVERS\s117mgmt.sys [100264 2007-06-25] (MCCI Corporation)
S3 s117nd5; C:\windows\System32\DRIVERS\s117nd5.sys [22952 2007-06-25] (MCCI Corporation)
S3 s117obex; C:\windows\System32\DRIVERS\s117obex.sys [98344 2007-06-25] (MCCI Corporation)
S3 s117unic; C:\windows\System32\DRIVERS\s117unic.sys [98856 2007-06-25] (MCCI Corporation)
R1 SCDEmu; C:\windows\system32\Drivers\SCDEmu.sys [116320 2014-06-27] (Power Software Ltd)
S3 SciU2S; C:\windows\System32\DRIVERS\SciU2S.sys [117248 2012-04-13] (Spreadtrum Communication Inc.) [File not signed]
S3 Secdrv; C:\windows\System32\DRIVERS\secdrv.sys [20480 2008-08-21] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
R3 serenum; C:\windows\System32\DRIVERS\serenum.sys [15744 2008-04-14] (Microsoft Corporation) [File not signed]
R1 Serial; C:\windows\System32\DRIVERS\serial.sys [64512 2008-08-21] (Microsoft Corporation) [File not signed]
S3 sermouse; C:\windows\System32\DRIVERS\sermouse.sys [17664 2001-08-17] (Microsoft Corporation) [File not signed]
S1 Sfloppy; C:\windows\system32\Drivers\Sfloppy.sys [11392 2008-08-21] (Microsoft Corporation) [File not signed]
S3 splitter; C:\windows\System32\drivers\splitter.sys [6272 2008-04-14] (Microsoft Corporation) [File not signed]
R0 sr; C:\windows\System32\DRIVERS\sr.sys [73472 2008-08-21] (Microsoft Corporation) [File not signed]
R3 Srv; C:\windows\System32\DRIVERS\srv.sys [357888 2011-02-17] (Microsoft Corporation) [File not signed]
S3 ssm_bus; C:\windows\System32\DRIVERS\ssm_bus.sys [104448 2010-04-27] (MCCI Corporation)
S3 ssm_mdfl; C:\windows\System32\DRIVERS\ssm_mdfl.sys [14848 2010-04-27] (MCCI Corporation)
S3 ssm_mdm; C:\windows\System32\DRIVERS\ssm_mdm.sys [132608 2010-04-27] (MCCI Corporation)
S3 ssudobex; C:\windows\System32\DRIVERS\ssudobex.sys [182680 2013-08-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssudrmnet; C:\windows\System32\DRIVERS\ssudrmnet.sys [60184 2013-08-21] (DEVGURU Co., LTD.)
S3 ssudrmnetmp; C:\windows\System32\DRIVERS\ssudrmnetmp.sys [80664 2013-08-21] (DEVGURU Co., LTD.)
S3 ssudserd; C:\windows\System32\DRIVERS\ssudserd.sys [182680 2013-08-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ss_bbus; C:\windows\System32\DRIVERS\ss_bbus.sys [98432 2010-04-27] (MCCI)
S3 ss_bmdfl; C:\windows\System32\DRIVERS\ss_bmdfl.sys [14848 2010-04-27] (MCCI Corporation)
S3 ss_bmdm; C:\windows\System32\DRIVERS\ss_bmdm.sys [123648 2010-04-27] (MCCI Corporation)
S3 ss_bserd; C:\windows\System32\DRIVERS\ss_bserd.sys [100224 2010-04-27] (MCCI Corporation)
R3 swenum; C:\windows\System32\DRIVERS\swenum.sys [4352 2008-08-21] (Microsoft Corporation) [File not signed]
S3 swmidi; C:\windows\System32\drivers\swmidi.sys [56576 2008-04-14] (Microsoft Corporation) [File not signed]
R3 sysaudio; C:\windows\System32\drivers\sysaudio.sys [60800 2008-04-14] (Microsoft Corporation) [File not signed]
R1 Tcpip; C:\windows\System32\DRIVERS\tcpip.sys [361600 2008-06-20] (Microsoft Corporation) [File not signed]
R1 Tcpip6; C:\windows\System32\DRIVERS\tcpip6.sys [226880 2010-02-11] (Microsoft Corporation) [File not signed]
S3 TDPIPE; C:\windows\system32\Drivers\TDPIPE.sys [12040 2008-08-21] (Microsoft Corporation) [File not signed]
S3 TDTCP; C:\windows\system32\Drivers\TDTCP.sys [21896 2008-08-21] (Microsoft Corporation) [File not signed]
R1 TermDD; C:\windows\System32\DRIVERS\termdd.sys [40840 2008-04-14] (Microsoft Corporation) [File not signed]
R3 token; C:\windows\System32\DRIVERS\eps2kt1.sys [21888 2013-04-04] () [File not signed]
R3 tunmp; C:\windows\System32\DRIVERS\tunmp.sys [12288 2008-08-21] (Microsoft Corporation) [File not signed]
R0 UBND; C:\windows\System32\DRIVERS\ubnd.sys [7808 2013-04-02] (UniversalBox) [File not signed]
S3 UBNRedir; C:\windows\System32\DRIVERS\ubnredir.sys [6784 2014-05-19] (UniversalBox) [File not signed]
S4 Udfs; C:\windows\system32\Drivers\Udfs.sys [66048 2008-08-21] (Microsoft Corporation) [File not signed]
R3 Update; C:\windows\System32\DRIVERS\update.sys [384768 2008-08-21] (Microsoft Corporation) [File not signed]
S3 usbbus; C:\windows\System32\DRIVERS\lgusbbus.sys [13056 2012-03-02] (LG Electronics Inc.)
S3 UsbDiag; C:\windows\System32\DRIVERS\lgusbdiag.sys [20864 2012-03-02] (LG Electronics Inc.)
S3 UsbGps; C:\windows\System32\DRIVERS\lgusbgps.sys [20096 2012-03-02] (LG Electronics Inc.)
R3 usbhub; C:\windows\System32\DRIVERS\usbhub.sys [59520 2008-04-14] (Microsoft Corporation) [File not signed]
S3 USBModem; C:\windows\System32\DRIVERS\lgusbmodem.sys [25216 2012-03-02] (LG Electronics Inc.)
S3 USBSHGX; C:\windows\System32\DRIVERS\usbgx_2.sys [24144 2004-03-25] (SHARP Corporation.) [File not signed]
S3 USBSTOR; C:\windows\System32\DRIVERS\USBSTOR.SYS [26368 2008-04-14] (Microsoft Corporation) [File not signed]
R3 usbuhci; C:\windows\System32\DRIVERS\usbuhci.sys [20608 2008-04-14] (Microsoft Corporation) [File not signed]
S3 usb_rndisx; C:\windows\System32\DRIVERS\usb8023x.sys [12928 2013-02-12] (Microsoft Corporation) [File not signed]
R1 VgaSave; C:\windows\System32\drivers\vga.sys [20992 2008-08-21] (Microsoft Corporation) [File not signed]
R3 VIAHdAudAddService; C:\windows\System32\drivers\viahduaa.sys [1425280 2009-10-21] (VIA Technologies, Inc.) [File not signed]
R0 VolSnap; C:\windows\system32\Drivers\VolSnap.sys [52352 2008-08-21] (Microsoft Corporation) [File not signed]
R3 Wanarp; C:\windows\System32\DRIVERS\wanarp.sys [34560 2008-08-21] (Microsoft Corporation) [File not signed]
R3 wdmaud; C:\windows\System32\drivers\wdmaud.sys [83072 2008-04-14] (Microsoft Corporation) [File not signed]
S3 WinUSB; C:\windows\System32\DRIVERS\WinUSB.sys [34944 2009-07-13] (Microsoft Corporation) [File not signed]
R0 WudfPf; C:\windows\System32\DRIVERS\WudfPf.sys [91904 2009-07-13] (Microsoft Corporation) [File not signed]
S3 WudfRd; C:\windows\System32\DRIVERS\wudfrd.sys [132224 2009-07-13] (Microsoft Corporation) [File not signed]
R2 zumbus; C:\windows\System32\DRIVERS\zumbus.sys [41472 2011-08-05] (Microsoft Corporation)
S4 IntelIde; No ImagePath
U1 WS2IFSL; 
 
==================== NetSvcs (Whitelisted) ===================
 
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-04 21:55 - 2014-08-04 21:55 - 00045578 _____ () C:\Documents and Settings\Radu Mamii\Desktop\FRST.txt
2014-08-04 21:55 - 2014-08-04 21:55 - 00000000 ____D () C:\FRST
2014-08-04 21:54 - 2014-08-04 21:54 - 01084928 _____ (Farbar) C:\Documents and Settings\Radu Mamii\Desktop\FRST.exe
2014-08-04 21:53 - 2014-08-04 21:53 - 00000000 ____D () C:\windows\LastGood
2014-08-04 21:18 - 2014-08-04 21:21 - 00000000 ___SD () C:\32788R22FWJFW
2014-08-04 21:18 - 2014-08-04 21:18 - 00000000 ____D () C:\windows\erdnt
2014-08-04 21:17 - 2014-08-04 21:18 - 05566616 ____R (Swearware) C:\Documents and Settings\Radu Mamii\Desktop\ComboFix.exe
2014-08-04 21:10 - 2014-08-04 21:26 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MCShield
2014-08-04 21:10 - 2014-08-04 21:10 - 02856736 _____ (MyCity) C:\Documents and Settings\Radu Mamii\Desktop\MCShield-Setup.exe
2014-08-04 21:10 - 2014-08-04 21:10 - 00000000 ____D () C:\Program Files\MCShield
2014-08-04 21:10 - 2014-08-04 21:10 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\MCShield
2014-08-04 09:54 - 2014-08-04 09:54 - 00144562 _____ () C:\Documents and Settings\Radu Mamii\Desktop\OTL.Txt
2014-08-04 09:54 - 2014-08-04 09:54 - 00074338 _____ () C:\Documents and Settings\Radu Mamii\Desktop\Extras.Txt
2014-08-04 09:50 - 2014-08-04 09:50 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Radu Mamii\Desktop\OTL.exe
2014-08-04 09:25 - 2014-08-04 21:53 - 03624871 _____ () C:\windows\setupapi.log
2014-08-04 09:25 - 2014-08-04 17:21 - 01644067 _____ () C:\windows\setupapi.log.52.old
2014-08-04 09:23 - 2014-08-04 09:23 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-4
2014-08-01 19:57 - 2014-08-01 19:57 - 00012393 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Update.16.Bron.Tok.bin
2014-08-01 18:48 - 2014-08-01 18:48 - 00012393 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok.A16.em.bin
2014-08-01 14:54 - 2014-08-01 15:50 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Desktop\i747 root
2014-08-01 14:35 - 2014-08-01 14:40 - 00000525 _____ () C:\windows\egatedrv-coinstall.log
2014-08-01 14:18 - 2014-08-01 14:18 - 00000034 _____ () C:\Documents and Settings\Radu Mamii\Desktop\i747.txt
2014-08-01 11:03 - 2014-08-01 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-1
2014-08-01 09:34 - 2014-08-01 09:34 - 00038912 _____ (SOFTWIN) C:\Documents and Settings\Radu Mamii\Desktop\AntiBrontokA-en.exe
2014-08-01 09:33 - 2014-08-04 09:23 - 03437510 _____ () C:\windows\setupapi.log.51.old
2014-08-01 09:33 - 2014-08-01 14:58 - 07079242 _____ () C:\windows\setupapi.log.50.old
2014-08-01 09:33 - 2014-08-01 14:19 - 01516615 _____ () C:\windows\setupapi.log.49.old
2014-08-01 09:31 - 2014-08-01 09:31 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-1
2014-07-31 09:46 - 2014-07-31 09:46 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-31
2014-07-30 11:03 - 2014-07-30 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-30
2014-07-30 10:14 - 2014-08-01 09:31 - 03474731 _____ () C:\windows\setupapi.log.48.old
2014-07-30 10:14 - 2014-07-31 13:27 - 01558093 _____ () C:\windows\setupapi.log.47.old
2014-07-30 10:14 - 2014-07-30 16:08 - 01537650 _____ () C:\windows\setupapi.log.46.old
2014-07-30 10:12 - 2014-07-30 10:12 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-30
2014-07-29 10:55 - 2014-07-29 10:55 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Desktop\N8-00
2014-07-29 09:28 - 2014-07-29 09:28 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-29
2014-07-28 11:03 - 2014-07-28 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-28
2014-07-28 09:24 - 2014-07-28 09:24 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-28
2014-07-26 10:33 - 2014-07-26 10:33 - 00000000 ____D () C:\usb_driver
2014-07-26 10:18 - 2014-07-30 10:12 - 01674740 _____ () C:\windows\setupapi.log.45.old
2014-07-26 10:18 - 2014-07-28 18:19 - 01843929 _____ () C:\windows\setupapi.log.44.old
2014-07-26 10:16 - 2014-07-26 10:16 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-26
2014-07-25 11:03 - 2014-07-25 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-25
2014-07-25 09:40 - 2014-07-26 10:16 - 03406189 _____ () C:\windows\setupapi.log.43.old
2014-07-25 09:40 - 2014-07-25 17:38 - 01528208 _____ () C:\windows\setupapi.log.42.old
2014-07-25 09:38 - 2014-07-25 09:38 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-25
2014-07-24 11:03 - 2014-07-24 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-24
2014-07-24 09:05 - 2014-07-25 09:38 - 01511734 _____ () C:\windows\setupapi.log.41.old
2014-07-24 09:03 - 2014-07-24 09:03 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-24
2014-07-23 11:03 - 2014-07-23 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-23
2014-07-23 09:14 - 2014-07-24 09:03 - 03368904 _____ () C:\windows\setupapi.log.40.old
2014-07-23 09:14 - 2014-07-23 17:22 - 01509179 _____ () C:\windows\setupapi.log.39.old
2014-07-23 09:12 - 2014-07-23 09:12 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-23
2014-07-22 17:08 - 2014-07-22 17:08 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-22
2014-07-22 09:24 - 2014-07-23 09:13 - 01547890 _____ () C:\windows\setupapi.log.38.old
2014-07-22 09:23 - 2014-07-22 09:23 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-22
2014-07-21 11:03 - 2014-07-21 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-21
2014-07-21 09:39 - 2014-07-22 09:23 - 03393158 _____ () C:\windows\setupapi.log.37.old
2014-07-21 09:39 - 2014-07-21 18:46 - 01490163 _____ () C:\windows\setupapi.log.36.old
2014-07-21 09:37 - 2014-07-21 09:37 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-21
2014-07-19 11:03 - 2014-07-19 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-19
2014-07-19 09:58 - 2014-07-21 09:37 - 01465825 _____ () C:\windows\setupapi.log.35.old
2014-07-19 09:56 - 2014-07-19 09:56 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-19
2014-07-18 09:29 - 2014-07-18 09:29 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-18
2014-07-17 11:03 - 2014-07-17 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-17
2014-07-17 09:35 - 2014-07-17 09:35 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-17
2014-07-16 09:23 - 2014-07-16 09:23 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-16
2014-07-15 09:27 - 2014-07-15 09:27 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-15
2014-07-14 17:08 - 2014-07-14 17:08 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-14
2014-07-14 17:08 - 2014-07-14 17:08 - 00000000 ____D () C:\Documents and Settings\NetworkService\Application Data\PowerISO
2014-07-14 09:50 - 2014-07-14 09:50 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\My Documents\BLACKBERRY-3B51
2014-07-14 09:37 - 2014-07-19 09:56 - 03115240 _____ () C:\windows\setupapi.log.34.old
2014-07-14 09:37 - 2014-07-17 09:35 - 01445053 _____ () C:\windows\setupapi.log.33.old
2014-07-14 09:37 - 2014-07-16 09:23 - 01554022 _____ () C:\windows\setupapi.log.32.old
2014-07-14 09:37 - 2014-07-14 19:47 - 01464214 _____ () C:\windows\setupapi.log.31.old
2014-07-14 09:35 - 2014-07-14 09:35 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-14
2014-07-12 09:59 - 2014-07-12 09:59 - 00000000 ____D () C:\TDSSKiller_Quarantine
2014-07-12 09:56 - 2014-07-12 09:56 - 04181856 _____ (Kaspersky Lab ZAO) C:\Documents and Settings\Radu Mamii\Desktop\tdsskiller.exe
2014-07-12 09:40 - 2014-07-12 09:40 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Application Data\PowerISO
2014-07-12 09:39 - 2014-07-12 09:39 - 00000743 _____ () C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
2014-07-12 09:39 - 2014-07-12 09:39 - 00000000 ____D () C:\Program Files\PowerISO
2014-07-12 09:39 - 2014-07-12 09:39 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\PowerISO
2014-07-12 09:38 - 2014-07-12 09:39 - 02876504 _____ (Power Software Ltd) C:\Documents and Settings\Radu Mamii\Desktop\PowerISO6.exe
2014-07-12 09:38 - 2014-07-12 09:38 - 00016853 _____ () C:\Documents and Settings\Radu Mamii\Desktop\Windows 7 Ultimate with SP1 X64 Genuine Untouched ISO Including Windows7 USB DVD Tool and Loader (1).torrent
2014-07-12 09:37 - 2014-07-12 09:37 - 00016853 _____ () C:\Documents and Settings\Radu Mamii\Desktop\Windows 7 Ultimate with SP1 X64 Genuine Untouched ISO Including Windows7 USB DVD Tool and Loader.torrent
2014-07-12 09:35 - 2014-07-12 09:35 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-12
2014-07-11 17:38 - 2014-07-11 18:15 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Desktop\i9000
2014-07-11 13:03 - 2014-07-11 13:03 - 00012393 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\ListHost16.txt
2014-07-11 11:03 - 2014-07-11 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-11
2014-07-11 09:56 - 2014-07-14 09:35 - 03378906 _____ () C:\windows\setupapi.log.30.old
2014-07-11 09:56 - 2014-07-11 15:08 - 01504964 _____ () C:\windows\setupapi.log.29.old
2014-07-11 09:54 - 2014-07-11 09:54 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-11
2014-07-10 19:27 - 2014-07-10 19:27 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-10
2014-07-10 13:23 - 2014-07-10 13:23 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\My Documents\lili
2014-07-09 10:21 - 2014-07-09 10:21 - 00000000 ____D () C:\Avenger
2014-07-09 10:03 - 2014-08-01 09:32 - 00110296 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-09 10:03 - 2014-07-09 10:03 - 00000820 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-09 10:03 - 2014-07-09 10:03 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-09 10:03 - 2014-07-09 10:03 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-09 10:03 - 2014-07-09 10:03 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2014-07-09 10:03 - 2014-05-12 07:26 - 00053208 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-07-09 10:03 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-07-09 10:00 - 2014-07-09 10:00 - 17292760 _____ (Malwarebytes Corporation ) C:\Documents and Settings\Radu Mamii\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-08 09:21 - 2014-07-11 09:54 - 03304055 _____ () C:\windows\setupapi.log.28.old
2014-07-08 09:21 - 2014-07-10 17:56 - 03293676 _____ () C:\windows\setupapi.log.27.old
2014-07-08 09:21 - 2014-07-10 17:46 - 03411873 _____ () C:\windows\setupapi.log.26.old
2014-07-08 09:21 - 2014-07-09 10:28 - 01431658 _____ () C:\windows\setupapi.log.25.old
2014-07-08 09:21 - 2014-07-09 09:33 - 03270164 _____ () C:\windows\setupapi.log.24.old
2014-07-08 09:21 - 2014-07-08 17:43 - 01464336 _____ () C:\windows\setupapi.log.23.old
2014-07-07 12:10 - 2014-07-11 10:57 - 00001485 _____ () C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox BEST.lnk
2014-07-07 12:08 - 2014-07-07 12:08 - 00001573 _____ () C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox PinFinder.lnk
2014-07-07 12:08 - 2014-07-07 12:08 - 00001501 _____ () C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox Shell.lnk
2014-07-07 12:08 - 2014-07-07 12:08 - 00001433 _____ () C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox Documentation.lnk
2014-07-07 11:10 - 2014-07-07 11:10 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Ok-SendMail-Bron-tok
2014-07-07 11:09 - 2014-07-28 12:02 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Loc.Mail.Bron.Tok
2014-07-07 11:09 - 2014-07-07 11:09 - 00000051 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Kosong.Bron.Tok.txt
2014-07-07 11:03 - 2014-07-07 11:03 - 00000846 _____ () C:\Documents and Settings\NetworkService\Start Menu\Programs\Internet Explorer.lnk
2014-07-07 11:03 - 2014-07-07 11:03 - 00000781 _____ () C:\Documents and Settings\NetworkService\Start Menu\Programs\Outlook Express.lnk
2014-07-07 11:03 - 2014-07-07 11:03 - 00000000 ___RD () C:\Documents and Settings\NetworkService\Start Menu\Programs\Accessories
2014-07-07 11:03 - 2014-07-07 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
2014-07-07 09:27 - 2014-07-07 09:27 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Ok-SendMail-Bron-tok
2014-07-07 09:25 - 2014-08-04 21:41 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Loc.Mail.Bron.Tok
2014-07-07 09:25 - 2014-07-07 09:25 - 00000051 _____ () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Kosong.Bron.Tok.txt
2014-07-07 09:20 - 2014-07-07 09:20 - 00012393 _____ () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\ListHost16.txt
2014-07-05 15:59 - 2014-08-04 21:26 - 00000420 _____ () C:\windows\Tasks\At2.job
2014-07-05 15:59 - 2014-08-04 21:26 - 00000420 _____ () C:\windows\Tasks\At1.job
2014-07-05 10:54 - 2014-07-05 10:54 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Desktop\asha 200 apa
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-04 21:55 - 2014-08-04 21:55 - 00045578 _____ () C:\Documents and Settings\Radu Mamii\Desktop\FRST.txt
2014-08-04 21:55 - 2014-08-04 21:55 - 00000000 ____D () C:\FRST
2014-08-04 21:55 - 2013-04-02 14:37 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Temp
2014-08-04 21:54 - 2014-08-04 21:54 - 01084928 _____ (Farbar) C:\Documents and Settings\Radu Mamii\Desktop\FRST.exe
2014-08-04 21:53 - 2014-08-04 21:53 - 00000000 ____D () C:\windows\LastGood
2014-08-04 21:53 - 2014-08-04 09:25 - 03624871 _____ () C:\windows\setupapi.log
2014-08-04 21:41 - 2014-07-07 09:25 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Loc.Mail.Bron.Tok
2014-08-04 21:37 - 2013-04-02 15:39 - 00000894 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-04 21:32 - 2013-04-02 16:14 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-08-04 21:30 - 2013-04-02 16:58 - 00593520 _____ () C:\windows\system32\PerfStringBackup.INI
2014-08-04 21:27 - 2013-04-02 14:13 - 01758255 _____ () C:\windows\WindowsUpdate.log
2014-08-04 21:26 - 2014-08-04 21:10 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MCShield
2014-08-04 21:26 - 2014-07-05 15:59 - 00000420 _____ () C:\windows\Tasks\At2.job
2014-08-04 21:26 - 2014-07-05 15:59 - 00000420 _____ () C:\windows\Tasks\At1.job
2014-08-04 21:26 - 2014-03-20 10:26 - 00000232 _____ () C:\windows\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2014-08-04 21:26 - 2013-10-10 12:40 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\HTC MediaHub
2014-08-04 21:26 - 2013-04-02 17:00 - 00000159 _____ () C:\windows\wiadebug.log
2014-08-04 21:26 - 2013-04-02 17:00 - 00000048 _____ () C:\windows\wiaservc.log
2014-08-04 21:26 - 2013-04-02 15:39 - 00000890 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-04 21:26 - 2013-04-02 14:36 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-08-04 21:26 - 2008-08-21 15:00 - 00013646 _____ () C:\windows\system32\wpa.dbl
2014-08-04 21:25 - 2013-04-02 14:37 - 00000178 ___SH () C:\Documents and Settings\Radu Mamii\ntuser.ini
2014-08-04 21:25 - 2013-04-02 14:36 - 00032542 _____ () C:\windows\SchedLgU.Txt
2014-08-04 21:21 - 2014-08-04 21:18 - 00000000 ___SD () C:\32788R22FWJFW
2014-08-04 21:18 - 2014-08-04 21:18 - 00000000 ____D () C:\windows\erdnt
2014-08-04 21:18 - 2014-08-04 21:17 - 05566616 ____R (Swearware) C:\Documents and Settings\Radu Mamii\Desktop\ComboFix.exe
2014-08-04 21:10 - 2014-08-04 21:10 - 02856736 _____ (MyCity) C:\Documents and Settings\Radu Mamii\Desktop\MCShield-Setup.exe
2014-08-04 21:10 - 2014-08-04 21:10 - 00000000 ____D () C:\Program Files\MCShield
2014-08-04 21:10 - 2014-08-04 21:10 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\MCShield
2014-08-04 20:38 - 2014-06-26 12:03 - 00288236 _____ () C:\windows\setupact.log
2014-08-04 20:12 - 2014-06-05 09:40 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Desktop\R E C U P E R A  R I
2014-08-04 20:11 - 2013-04-02 17:56 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Application Data\PC Suite
2014-08-04 20:01 - 2013-04-09 20:09 - 03924318 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-299502267-115176313-682003330-1003-0.dat
2014-08-04 20:01 - 2013-04-09 20:09 - 00302890 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2014-08-04 17:22 - 2013-12-11 13:50 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\My Documents\SelfMV
2014-08-04 17:21 - 2014-08-04 09:25 - 01644067 _____ () C:\windows\setupapi.log.52.old
2014-08-04 09:54 - 2014-08-04 09:54 - 00144562 _____ () C:\Documents and Settings\Radu Mamii\Desktop\OTL.Txt
2014-08-04 09:54 - 2014-08-04 09:54 - 00074338 _____ () C:\Documents and Settings\Radu Mamii\Desktop\Extras.Txt
2014-08-04 09:50 - 2014-08-04 09:50 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Radu Mamii\Desktop\OTL.exe
2014-08-04 09:23 - 2014-08-04 09:23 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-4
2014-08-04 09:23 - 2014-08-01 09:33 - 03437510 _____ () C:\windows\setupapi.log.51.old
2014-08-01 19:57 - 2014-08-01 19:57 - 00012393 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Update.16.Bron.Tok.bin
2014-08-01 18:48 - 2014-08-01 18:48 - 00012393 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok.A16.em.bin
2014-08-01 15:50 - 2014-08-01 14:54 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Desktop\i747 root
2014-08-01 14:58 - 2014-08-01 09:33 - 07079242 _____ () C:\windows\setupapi.log.50.old
2014-08-01 14:40 - 2014-08-01 14:35 - 00000525 _____ () C:\windows\egatedrv-coinstall.log
2014-08-01 14:19 - 2014-08-01 09:33 - 01516615 _____ () C:\windows\setupapi.log.49.old
2014-08-01 14:18 - 2014-08-01 14:18 - 00000034 _____ () C:\Documents and Settings\Radu Mamii\Desktop\i747.txt
2014-08-01 11:03 - 2014-08-01 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-1
2014-08-01 09:34 - 2014-08-01 09:34 - 00038912 _____ (SOFTWIN) C:\Documents and Settings\Radu Mamii\Desktop\AntiBrontokA-en.exe
2014-08-01 09:32 - 2014-07-09 10:03 - 00110296 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-01 09:31 - 2014-08-01 09:31 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-1
2014-08-01 09:31 - 2014-07-30 10:14 - 03474731 _____ () C:\windows\setupapi.log.48.old
2014-07-31 13:27 - 2014-07-30 10:14 - 01558093 _____ () C:\windows\setupapi.log.47.old
2014-07-31 09:46 - 2014-07-31 09:46 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-31
2014-07-30 17:38 - 2014-03-15 16:45 - 00000284 _____ () C:\windows\Tasks\AppleSoftwareUpdate.job
2014-07-30 16:08 - 2014-07-30 10:14 - 01537650 _____ () C:\windows\setupapi.log.46.old
2014-07-30 11:03 - 2014-07-30 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-30
2014-07-30 10:12 - 2014-07-30 10:12 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-30
2014-07-30 10:12 - 2014-07-26 10:18 - 01674740 _____ () C:\windows\setupapi.log.45.old
2014-07-29 10:55 - 2014-07-29 10:55 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Desktop\N8-00
2014-07-29 09:28 - 2014-07-29 09:28 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-29
2014-07-28 18:19 - 2014-07-26 10:18 - 01843929 _____ () C:\windows\setupapi.log.44.old
2014-07-28 12:02 - 2014-07-07 11:09 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Loc.Mail.Bron.Tok
2014-07-28 11:03 - 2014-07-28 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-28
2014-07-28 09:24 - 2014-07-28 09:24 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-28
2014-07-26 10:33 - 2014-07-26 10:33 - 00000000 ____D () C:\usb_driver
2014-07-26 10:16 - 2014-07-26 10:16 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-26
2014-07-26 10:16 - 2014-07-25 09:40 - 03406189 _____ () C:\windows\setupapi.log.43.old
2014-07-25 17:38 - 2014-07-25 09:40 - 01528208 _____ () C:\windows\setupapi.log.42.old
2014-07-25 11:03 - 2014-07-25 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-25
2014-07-25 10:00 - 2013-04-02 16:18 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-25 09:43 - 2013-04-02 16:19 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
2014-07-25 09:38 - 2014-07-25 09:38 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-25
2014-07-25 09:38 - 2014-07-24 09:05 - 01511734 _____ () C:\windows\setupapi.log.41.old
2014-07-24 11:03 - 2014-07-24 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-24
2014-07-24 09:03 - 2014-07-24 09:03 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-24
2014-07-24 09:03 - 2014-07-23 09:14 - 03368904 _____ () C:\windows\setupapi.log.40.old
2014-07-23 18:19 - 2013-04-03 21:45 - 00000000 ____D () C:\Program Files\Cyclone Box
2014-07-23 17:22 - 2014-07-23 09:14 - 01509179 _____ () C:\windows\setupapi.log.39.old
2014-07-23 11:03 - 2014-07-23 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-23
2014-07-23 09:13 - 2014-07-22 09:24 - 01547890 _____ () C:\windows\setupapi.log.38.old
2014-07-23 09:12 - 2014-07-23 09:12 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-23
2014-07-22 17:08 - 2014-07-22 17:08 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-22
2014-07-22 09:23 - 2014-07-22 09:23 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-22
2014-07-22 09:23 - 2014-07-21 09:39 - 03393158 _____ () C:\windows\setupapi.log.37.old
2014-07-21 18:51 - 2013-04-02 14:53 - 00000000 ____D () C:\windows\system32\ReinstallBackups
2014-07-21 18:46 - 2014-07-21 09:39 - 01490163 _____ () C:\windows\setupapi.log.36.old
2014-07-21 11:03 - 2014-07-21 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-21
2014-07-21 09:37 - 2014-07-21 09:37 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-21
2014-07-21 09:37 - 2014-07-19 09:58 - 01465825 _____ () C:\windows\setupapi.log.35.old
2014-07-19 11:03 - 2014-07-19 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-19
2014-07-19 09:56 - 2014-07-19 09:56 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-19
2014-07-19 09:56 - 2014-07-14 09:37 - 03115240 _____ () C:\windows\setupapi.log.34.old
2014-07-18 14:42 - 2013-04-02 15:39 - 00001856 _____ () C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2014-07-18 10:30 - 2014-06-28 10:50 - 00000865 _____ () C:\Documents and Settings\Radu Mamii\Desktop\Octoplus LG Tool.lnk
2014-07-18 09:29 - 2014-07-18 09:29 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-18
2014-07-17 11:03 - 2014-07-17 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-17
2014-07-17 09:35 - 2014-07-17 09:35 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-17
2014-07-17 09:35 - 2014-07-14 09:37 - 01445053 _____ () C:\windows\setupapi.log.33.old
2014-07-16 09:23 - 2014-07-16 09:23 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-16
2014-07-16 09:23 - 2014-07-14 09:37 - 01554022 _____ () C:\windows\setupapi.log.32.old
2014-07-15 20:24 - 2013-10-23 19:53 - 02150744 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2014-07-15 19:16 - 2013-04-08 17:38 - 00006930 _____ () C:\Documents and Settings\Radu Mamii\Application Data\Rim.DesktopHelper.Exception.log
2014-07-15 19:16 - 2013-04-08 17:38 - 00006853 _____ () C:\Documents and Settings\Radu Mamii\Application Data\Rim.Desktop.Exception.log
2014-07-15 09:27 - 2014-07-15 09:27 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-15
2014-07-14 19:47 - 2014-07-14 09:37 - 01464214 _____ () C:\windows\setupapi.log.31.old
2014-07-14 17:08 - 2014-07-14 17:08 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-14
2014-07-14 17:08 - 2014-07-14 17:08 - 00000000 ____D () C:\Documents and Settings\NetworkService\Application Data\PowerISO
2014-07-14 09:50 - 2014-07-14 09:50 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\My Documents\BLACKBERRY-3B51
2014-07-14 09:49 - 2014-05-28 14:45 - 00016695 _____ () C:\ads_err.adt
2014-07-14 09:49 - 2014-05-28 14:45 - 00003072 _____ () C:\ads_err.adi
2014-07-14 09:35 - 2014-07-14 09:35 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-14
2014-07-14 09:35 - 2014-07-11 09:56 - 03378906 _____ () C:\windows\setupapi.log.30.old
2014-07-12 10:04 - 2013-04-03 17:12 - 00000000 ____D () C:\windows\SHELLNEW
2014-07-12 10:02 - 2013-04-02 15:48 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Application Data\uTorrent
2014-07-12 09:59 - 2014-07-12 09:59 - 00000000 ____D () C:\TDSSKiller_Quarantine
2014-07-12 09:56 - 2014-07-12 09:56 - 04181856 _____ (Kaspersky Lab ZAO) C:\Documents and Settings\Radu Mamii\Desktop\tdsskiller.exe
2014-07-12 09:40 - 2014-07-12 09:40 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Application Data\PowerISO
2014-07-12 09:39 - 2014-07-12 09:39 - 00000743 _____ () C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
2014-07-12 09:39 - 2014-07-12 09:39 - 00000000 ____D () C:\Program Files\PowerISO
2014-07-12 09:39 - 2014-07-12 09:39 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\PowerISO
2014-07-12 09:39 - 2014-07-12 09:38 - 02876504 _____ (Power Software Ltd) C:\Documents and Settings\Radu Mamii\Desktop\PowerISO6.exe
2014-07-12 09:38 - 2014-07-12 09:38 - 00016853 _____ () C:\Documents and Settings\Radu Mamii\Desktop\Windows 7 Ultimate with SP1 X64 Genuine Untouched ISO Including Windows7 USB DVD Tool and Loader (1).torrent
2014-07-12 09:37 - 2014-07-12 09:37 - 00016853 _____ () C:\Documents and Settings\Radu Mamii\Desktop\Windows 7 Ultimate with SP1 X64 Genuine Untouched ISO Including Windows7 USB DVD Tool and Loader.torrent
2014-07-12 09:35 - 2014-07-12 09:35 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-12
2014-07-11 18:15 - 2014-07-11 17:38 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Desktop\i9000
2014-07-11 15:08 - 2014-07-11 09:56 - 01504964 _____ () C:\windows\setupapi.log.29.old
2014-07-11 13:03 - 2014-07-11 13:03 - 00012393 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\ListHost16.txt
2014-07-11 11:03 - 2014-07-11 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-11
2014-07-11 10:57 - 2014-07-07 12:10 - 00001485 _____ () C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox BEST.lnk
2014-07-11 10:36 - 2013-04-06 10:08 - 00000805 _____ () C:\Documents and Settings\All Users\Desktop\Activator.lnk
2014-07-11 10:36 - 2013-04-06 10:08 - 00000653 _____ () C:\Documents and Settings\All Users\Desktop\SPT.lnk
2014-07-11 10:36 - 2013-04-06 10:08 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\SPT
2014-07-11 10:36 - 2013-04-06 10:06 - 00000000 ____D () C:\Program Files\SPT
2014-07-11 10:21 - 2014-03-08 15:07 - 00000901 _____ () C:\Documents and Settings\Radu Mamii\Desktop\Octoplus Suite.lnk
2014-07-11 10:20 - 2014-03-01 12:46 - 00000925 _____ () C:\Documents and Settings\Radu Mamii\Desktop\Octoplus Samsung Tool.lnk
2014-07-11 09:54 - 2014-07-11 09:54 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-11
2014-07-11 09:54 - 2014-07-08 09:21 - 03304055 _____ () C:\windows\setupapi.log.28.old
2014-07-10 19:27 - 2014-07-10 19:27 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-10
2014-07-10 17:56 - 2014-07-08 09:21 - 03293676 _____ () C:\windows\setupapi.log.27.old
2014-07-10 17:46 - 2014-07-08 09:21 - 03411873 _____ () C:\windows\setupapi.log.26.old
2014-07-10 13:23 - 2014-07-10 13:23 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\My Documents\lili
2014-07-10 09:43 - 2013-04-02 16:04 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Microsoft Help
2014-07-09 11:32 - 2013-04-02 16:14 - 00699056 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2014-07-09 11:32 - 2013-04-02 16:14 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2014-07-09 10:28 - 2014-07-08 09:21 - 01431658 _____ () C:\windows\setupapi.log.25.old
2014-07-09 10:21 - 2014-07-09 10:21 - 00000000 ____D () C:\Avenger
2014-07-09 10:21 - 2014-02-13 21:57 - 00000000 __HDC () C:\windows\$NtUninstallKB2916036$
2014-07-09 10:03 - 2014-07-09 10:03 - 00000820 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-09 10:03 - 2014-07-09 10:03 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-09 10:03 - 2014-07-09 10:03 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-09 10:03 - 2014-07-09 10:03 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2014-07-09 10:00 - 2014-07-09 10:00 - 17292760 _____ (Malwarebytes Corporation ) C:\Documents and Settings\Radu Mamii\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-09 09:33 - 2014-07-08 09:21 - 03270164 _____ () C:\windows\setupapi.log.24.old
2014-07-08 17:43 - 2014-07-08 09:21 - 01464336 _____ () C:\windows\setupapi.log.23.old
2014-07-08 15:14 - 2014-03-20 10:26 - 00000226 _____ () C:\windows\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2014-07-08 09:19 - 2014-07-02 09:24 - 01534048 _____ () C:\windows\setupapi.log.22.old
2014-07-07 12:10 - 2013-04-04 12:13 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Start Menu\Programs\InfinityBox
2014-07-07 12:08 - 2014-07-07 12:08 - 00001573 _____ () C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox PinFinder.lnk
2014-07-07 12:08 - 2014-07-07 12:08 - 00001501 _____ () C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox Shell.lnk
2014-07-07 12:08 - 2014-07-07 12:08 - 00001433 _____ () C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox Documentation.lnk
2014-07-07 12:08 - 2014-06-12 12:50 - 00001289 _____ () C:\Documents and Settings\Radu Mamii\Desktop\InfinityBox.lnk
2014-07-07 12:08 - 2013-04-04 12:13 - 00000000 ____D () C:\InfinityBox
2014-07-07 11:38 - 2014-06-20 15:16 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Desktop\i9500 radu
2014-07-07 11:10 - 2014-07-07 11:10 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Ok-SendMail-Bron-tok
2014-07-07 11:09 - 2014-07-07 11:09 - 00000051 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Kosong.Bron.Tok.txt
2014-07-07 11:03 - 2014-07-07 11:03 - 00000846 _____ () C:\Documents and Settings\NetworkService\Start Menu\Programs\Internet Explorer.lnk
2014-07-07 11:03 - 2014-07-07 11:03 - 00000781 _____ () C:\Documents and Settings\NetworkService\Start Menu\Programs\Outlook Express.lnk
2014-07-07 11:03 - 2014-07-07 11:03 - 00000000 ___RD () C:\Documents and Settings\NetworkService\Start Menu\Programs\Accessories
2014-07-07 11:03 - 2014-07-07 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
2014-07-07 11:03 - 2013-04-02 14:18 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2014-07-07 09:44 - 2013-11-08 18:17 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\My Documents\poza luci
2014-07-07 09:44 - 2013-10-31 11:46 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\My Documents\GT-I9300_JTAGarabic
2014-07-07 09:27 - 2014-07-07 09:27 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Ok-SendMail-Bron-tok
2014-07-07 09:25 - 2014-07-07 09:25 - 00000051 _____ () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Kosong.Bron.Tok.txt
2014-07-07 09:20 - 2014-07-07 09:20 - 00012393 _____ () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\ListHost16.txt
2014-07-07 09:20 - 2014-07-02 09:24 - 03225106 _____ () C:\windows\setupapi.log.21.old
2014-07-05 15:56 - 2014-07-02 09:24 - 01513166 _____ () C:\windows\setupapi.log.20.old
2014-07-05 10:54 - 2014-07-05 10:54 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Desktop\asha 200 apa
 
Files to move or delete:
====================
C:\Windows\Tasks\At1.job
C:\Windows\Tasks\At2.job
 
 
Some content of TEMP:
====================
C:\Documents and Settings\NetworkService\Local Settings\Temp\mpam-c8d1f710.exe
C:\Documents and Settings\Radu Mamii\Local Settings\Temp\NEventMessages.dll
C:\Documents and Settings\Radu Mamii\Local Settings\Temp\NOSEventMessages.dll
C:\Documents and Settings\Radu Mamii\Local Settings\Temp\nsf3D.exe
C:\Documents and Settings\Radu Mamii\Local Settings\Temp\nsh40.exe
C:\Documents and Settings\Radu Mamii\Local Settings\Temp\nsn46.exe
C:\Documents and Settings\Radu Mamii\Local Settings\Temp\nsv4C.exe
C:\Documents and Settings\Radu Mamii\Local Settings\Temp\nsz3A.exe
C:\Documents and Settings\Radu Mamii\Local Settings\Temp\nsz49.exe
C:\Documents and Settings\Radu Mamii\Local Settings\Temp\nsz54.exe
C:\Documents and Settings\Radu Mamii\Local Settings\Temp\sp-downloader.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\explorer.exe => MD5 is legit
C:\windows\system32\winlogon.exe => MD5 is legit
C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\system32\services.exe => MD5 is legit
C:\windows\system32\User32.dll => MD5 is legit
C:\windows\system32\userinit.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit
C:\windows\system32\Drivers\volsnap.sys => MD5 is legit
 
==================== End Of Log ============================
 
 
 
 
addi:
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version:2-08-2014
Ran by Radu Mamii at 2014-08-04 21:55:55
Running from C:\Documents and Settings\Radu Mamii\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKCU\...\uTorrent) (Version: 3.4.1.31395 - BitTorrent Inc.)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.8.0.870 - Adobe Systems Incorporated)
Adobe AIR (Version: 3.8.0.870 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
AIDA64 Extreme Edition v2.00 (HKLM\...\AIDA64 Extreme Edition_is1) (Version: 2.00 - FinalWire Ltd.)
Apple Application Support (HKLM\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AVIVO (Version: 9.14.0.60504 - ATI Technologies Inc.) Hidden
BBSAK (HKLM\...\{B23F12D4-17DE-453A-B1F4-55E501FE0EBF}) (Version: 1.9.2 - JMT Labs)
BlackBerry Desktop Software 7.1 (HKLM\...\BlackBerry_Desktop) (Version: 7.1.0.41 - Research In Motion Ltd.)
BlackBerry Desktop Software 7.1 (Version: 7.1.0.41 - Research In Motion Ltd.) Hidden
BlackBerry Device Software Updater (HKLM\...\{5BF3423C-4397-4FE3-A318-C9850EA24CB3}) (Version: 8.0.0.46 - Research In Motion Ltd)
BlackBerry Device Software v4.5.0 for the BlackBerry 8310 smartphone (HKLM\...\{CE63492A-9097-4C95-8B7C-CADBF3DFCECA}) (Version: 4.5.0.37 (Platform 2.7.0.55) - Research In Motion Ltd.)
BlackBerry Device Software v5.0.0 for the BlackBerry 8520 smartphone (HKLM\...\{A1BE9BF9-6136-479A-967C-C26C2FEA8876}) (Version: 5.0.0.681 (Platform 5.2.0.67) - Research In Motion Ltd.)
BlackBerry Device Software v6.0.0 for the BlackBerry 9800 smartphone (HKLM\...\{558574F9-C0E8-4F6E-8E70-C9B74E811F00}) (Version: 6.0.0.284 (Platform 6.4.0.120) - Research In Motion Ltd.)
BlackBerry Device Software v6.0.0 for the BlackBerry 9800 smartphone (HKLM\...\{567CB700-5A44-4E5B-8E1A-112FA825644F}) (Version: 6.0.0.747 (Platform 6.6.0.249) - Research In Motion Ltd.)
BlackBerry Link (HKLM\...\BlackBerry_10_Desktop) (Version: 1.2.3.48 - BlackBerry Ltd.)
BlackBerry Link (Version: 1.2.3.48 - BlackBerry Ltd.) Hidden
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform)
Cyclone Box (HKLM\...\{B2B38BE9-031A-49C2-9ABC-7043DB04E7C9}_is1) (Version:  - Cyclone Box Team)
DiskAid 5.46 (HKLM\...\DiskAid_is1) (Version: 5.46 - DigiDNA)
DreamBox 3.30 (HKLM\...\DreamBox_is1) (Version:  - )
DriverTools 1.0 (HKLM\...\DriverTools) (Version: 1.0 - Huawei Technologies Co.,Ltd)
FLS-4 Driver Installation (HKLM\...\FLSINST) (Version:  - )
Fuse Drivers FPS-xx (HKLM\...\{97610367-01D9-4A75-B998-1E698A406155}) (Version: 11.37.0 - Nokia)
Google Chrome (HKLM\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
Handset USB Driver (HKLM\...\{D2D77DC2-8299-11D1-8949-444553540000}_is1) (Version: 5.2088.1.A01B06 - )
HTC BMP USB Driver (HKLM\...\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
HTC Driver Installer (HKLM\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.8.0.002 - HTC Corporation)
HTC Sync (HKLM\...\{CBDAE89D-8ABD-4DC5-9309-C2C58696B371}) (Version: 3.3.63 - HTC Corporation)
HTC Sync Manager (HKLM\...\{368E4EF8-E840-40EE-A224-50B8D1DC2B12}) (Version: 2.3.32.0 - HTC)
InfinityBox (remove only) (HKLM\...\InfinityBox) (Version:  - )
InfinityBox BEST (HKLM\...\InfinityBox BEST) (Version:  - )
InfinityBox Shell (HKLM\...\InfinityBox Shell) (Version:  - )
Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version:  - Intel Corporation)
iPhone Folders (HKLM\...\{53DA6CFE-7CDE-4F72-9E23-39AAC686DE17}) (Version: 1.0.32 - Redart)
IPTInstaller (HKLM\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.8 - HTC)
iTunes (HKLM\...\{0718A90E-93AA-49AF-A4FE-0165ACD91DF0}) (Version: 11.2.2.3 - Apple Inc.)
Java 7 Update 60 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.600 - Oracle)
Java Auto Updater (Version: 2.1.60.19 - Oracle, Inc.) Hidden
LG SP USB Driver (HKLM\...\{E2AE8456-CCFE-46C0-8629-71CC507660FC}) (Version: 2.0.0.0000 - LG Electronics)
LG United Mobile Drivers (HKLM\...\{5DB849D6-9392-4FB7-9ABB-87ED433152E5}) (Version: 3.8.1 - LG Electronics)
Lumia UEFI Blue Driver (HKLM\...\{65824591-C476-4D9F-AF1F-6C7E6AFA7D39}) (Version: 1.1.4.1406 - Nokia)
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
MCCI®Firmware Update Driver for MTK (HKLM\...\{13E92303-C1AC-4012-9E22-54EACBF54888}) (Version: 1.00.0000 - MCCI)
MCShield ::Anti-Malware Tool:: (HKLM\...\MCShield) (Version: 3.0.5.28 - MyCity)
Medusa Box Software 1.9.8 (HKLM\...\Medusa Box Software_is1) (Version: 1.9.8 - Medusa team)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft ActiveSync (HKLM\...\{7BEB2120-A08C-46EA-906A-9ADAF57B3763}) (Version: 4.5.5059.0 - Microsoft Corporation)
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 (Version:  - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (Version:  - Microsoft) Hidden
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Software Update for Web Folders  (English) 12 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft User-Mode Driver Framework Feature Pack 1.9 (HKLM\...\Wudf01009) (Version:  - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft WinUsb 1.0 (HKLM\...\winusb0100) (Version:  - Microsoft Corporation)
Microsoft WinUsb 2.0 (HKLM\...\winusb0200) (Version:  - Microsoft Corporation)
Microsoft_VC100_CRT_SP1_x86 (Version: 10.0.40219.1 - Nokia) Hidden
Mozilla Firefox 27.0.1 (x86 en-US) (HKLM\...\Mozilla Firefox 27.0.1 (x86 en-US)) (Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla)
MSVC80_x86 (Version: 1.0.1.0 - Nokia) Hidden
MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 6.0 Parser (HKLM\...\{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}) (Version: 6.10.1129.0 - Microsoft Corporation)
MyFreeCodec (HKCU\...\MyFreeCodec) (Version:  - )
NOKIA 3806 USB DRIVER Ver:1.5 (HKLM\...\{6AE35C55-F02A-41EE-B694-8F2706FE4819}) (Version: 2.00.0000 - NOKIA)
Nokia Care Suite PST 5.0 (HKLM\...\{D9F57981-6774-4EDE-8C51-B7F9D940C046}) (Version: 5.1.83.1414 - Nokia)
Nokia Connectivity Cable Driver (HKLM\...\{D4BF151C-70A8-4CE2-906F-4173A575BAD9}) (Version: 7.1.182.0 - Nokia)
Nokia Data Package Manager (HKLM\...\{DDF5E5B0-6F7B-4CEE-A3E5-655BD71067DB}) (Version: 2013.7.5 - Nokia)
Nokia Firmware RH-125 (HKLM\...\{FC89ACAC-EC28-4BA8-9235-A17FF84ED072}) (Version: 07.00 - Nokia)
Nokia Firmware RH-64 (HKLM\...\{B702B2A6-0FEB-4995-B0BE-01DB366CEE35}) (Version: 22.00 - Nokia)
Nokia Firmware RM-123 'Not specifiedEMEA_APAC_ALL' (HKLM\...\{E0EB953C-FC81-4909-BA3E-F32BF7AFE8CF}) (Version: 205.0 - Nokia)
Nokia Firmware RM-170 emea (HKLM\...\{C28688C8-BD4B-4DCD-9F5E-8BE8DAD5EF2F}) (Version: 6.0 - Nokia)
Nokia Firmware RM-242 'GLOBAL Data Package' (HKLM\...\{287CF71F-D79C-4326-A84C-005435BA46CA}) (Version: 18.0 - Nokia)
Nokia Firmware RM-249 (HKLM\...\{7BF58C36-BCF1-49E6-88C3-ED193C5D74BB}) (Version: 5.00 - Nokia)
Nokia Firmware RM-298 (HKLM\...\{C0132EC6-927C-41B7-8315-C8212BEC4154}) (Version: 10.13 - Nokia)
Nokia Firmware RM-340 (HKLM\...\{DEF64AA7-41F6-417C-BB1A-3415580C4BA0}) (Version: 02.33 - Nokia)
Nokia Firmware RM-362 (HKLM\...\{5011C195-6511-11DC-8314-0800200C9A66}) (Version: 7.00 - Nokia)
Nokia Firmware RM-392 (HKLM\...\{DFA63835-1DB7-437E-A975-48657D75A624}) (Version: 5.00 - Nokia)
Nokia Firmware RM-512 'DP20_08.20' (HKLM\...\{64749549-C5EF-40E0-8521-825D3D927D62}) (Version: 8.0 - Nokia)
Nokia Firmware RM-519 'DP20_09.55' (HKLM\...\{187C1455-7B99-4ECE-8BE8-6E2E8273207F}) (Version: 12.0 - Nokia)
Nokia Firmware RM-590 'DP20_10.20' (HKLM\...\{17C662E2-FAAA-4A52-9118-A17781F1AE7F}) (Version: 12.0 - Nokia)
Nokia Firmware RM-614 'DP20_08.70' (HKLM\...\{D9DAD90E-C77D-439C-9FD1-F73148C49AEA}) (Version: 21.00 - Nokia)
Nokia Firmware RM-635 'DP20_10.65' (HKLM\...\{A79AAF32-8C6A-11DE-B1E4-CAC755D89593}) (Version: 16.00 - Nokia)
Nokia Firmware RM-709 'DP20_08.75' (HKLM\...\{31E8980E-789A-40AD-884E-9E918395C05D}) (Version: 16.00 - Nokia)
Nokia Firmware RM-776 'DP20_07.32' (HKLM\...\{B2FF8412-1AEA-4206-8FDD-98F432BD628B}) (Version: 3.00 - Nokia)
Nokia Firmware RM-78 'mcusw06.43' (HKLM\...\{852AA1DF-5FE3-4C0D-AC07-6AFD055BCA87}) (Version: 345.0 - Nokia)
Nokia Firmware RX-51 CARE (HKLM\...\{0ECB8237-482A-43EA-8CAA-FD2E00D3A066}) (Version: 16.0 - Nokia)
Nokia PC Suite (HKLM\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia)
Nokia PC Suite (Version: 7.1.180.94 - Nokia) Hidden
Nokia Software Updater for Retail (HKLM\...\{71E91384-39AB-4798-94ED-408ECC51E1B4}) (Version: 4.2.1 - Nokia)
Nokia Suite (HKLM\...\Nokia Suite) (Version: 3.8.48.0 - Nokia)
Nokia Suite (Version: 3.8.48.0 - Nokia) Hidden
Octoplus Suite 1.2.8.1 (HKLM\...\Octoplus Suite_is1) (Version: 1.2.8.1 - Octoplus team)
Octoplus/Octopus box LG software 1.6.3 (HKLM\...\Octoplus box LG software_is1) (Version:  - Octoplus team)
Octopus Box Samsung software 1.6.1 (HKLM\...\Octoplus Box Samsung software_is1) (Version:  - Octoplus team)
Octopus Box Samsung software 1.8.6 (HKLM\...\Octopus Box Samsung software_is1) (Version:  - Octopus team)
Octopus box software 2.4.5 (HKLM\...\Octopus box LG software_is1) (Version:  - Octopus team)
Octopus Suite 1.1.6 (HKLM\...\Octopus Suite_is1) (Version: 1.1.6 - Octopus team)
OMAPFlash (HKLM\...\{497A3C2A-737B-4392-93E4-4B571CFBAB75}) (Version: 1.0.0 - Texas Instruments)
PC Connectivity Solution (HKLM\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia)
PL-2303 USB-to-Serial (HKLM\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.3.0 - Prolific Technology INC)
Platform (Version: 1.34 - VIA Technologies, Inc.) Hidden
PowerISO (HKLM\...\PowerISO) (Version: 6.0 - Power Software Ltd)
QuickTime 7 (HKLM\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
REALTEK GbE & FE Ethernet PCI-E NIC Driver (HKLM\...\{C9BED750-1211-4480-B1A5-718A3BE15525}) (Version: 1.23.0000 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 5.10.0.5680 - Realtek Semiconductor Corp.)
RIM USB Driver 4.1.0 (HKLM\...\{E815686F-7FB8-4DE5-B2C8-37F8FF2DDE5E}) (Version: 4.1.0.2 - Research In Motion Limited)
RM-166 Phone Data Package (HKLM\...\{CBF08AA3-7D59-4614-9D45-ADEA7A184D2F}) (Version:  - )
RM-72 Phone Data Package  (HKLM\...\{82B35290-EA26-49DD-8851-B635CB0DA36B}) (Version:  - )
RM-76 Phone Data Package (HKLM\...\{4B82A839-10DF-4E6F-A563-59D908E09473}) (Version:  - )
RM-92 Phone Data Package EMEA Prd (HKLM\...\{229A8FEC-D03B-41CD-A184-40AE7DA58A47}) (Version: 18.0 - Nokia)
ROOT´óʦ (HKLM\...\{1295E43F-382A-4CB2-9E0F-079C0D7401BB}_is1) (Version: 1.7.8.7753 - ÉîÛÚÐÅÒ¼ÍøÂçÓÐÏÞ¹«Ë¾)
s4unlocker (HKLM\...\{BFCC608A-702C-4D92-BCAD-4770377E21EB}) (Version: 1.00.0000 - s4 unlocker)
Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.5.2.13021_10 - Samsung Electronics Co., Ltd.)
Samsung Kies (Version: 2.5.2.13021_10 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14024.11 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (Version: 3.2.14024.11 - Samsung Electronics Co., Ltd.) Hidden
Samsung PC Studio 7 (HKLM\...\Samsung PC Studio 7) (Version: 7.2.24.9 - Samsung)
Samsung PC Studio 7 (Version: 7.2.24.9 - Samsung) Hidden
Samsung Story Album Viewer (HKLM\...\InstallShield_{698BBAD8-B116-495D-B879-0F07A533E57F}) (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.)
Samsung Story Album Viewer (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.24.0 - SAMSUNG Electronics Co., Ltd.)
SHARP GSM GPRS USB Driver Ver2.0.0 (HKLM\...\InstallShield_{3D4B89AC-B4B3-47D4-8CEE-85390508F3D6}) (Version: 2.00.0002 - SHARP)
SHARP GSM GPRS USB Driver Ver2.0.0 (Version: 2.00.0002 - SHARP) Hidden
SPTBOX Deluxe 18.1.8 (HKLM\...\{062DF687-EF02-4566-8F8C-5D95FFC9F2A5}_is1) (Version:  - SPT Team)
The GX15 Upgrading Tool (HKLM\...\{2A9366F7-45BE-4C96-9D9D-1BE7E3D79349}) (Version: 1.0.0.0 - SHARP)
UniversalBox (HKLM\...\UniversalBox3.0.0.2941) (Version: 3.0.0.2941 - UniversalBox)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2883030) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{F5DCAB53-C2FD-4E5A-8C83-0F37485E5E89}) (Version:  - Microsoft)
Update for Windows XP (KB2345886) (HKLM\...\KB2345886) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2661254-v2) (HKLM\...\KB2661254-v2) (Version: 2 - Microsoft Corporation)
Update for Windows XP (KB2736233) (HKLM\...\KB2736233) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2749655) (HKLM\...\KB2749655) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2863058) (HKLM\...\KB2863058) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2904266) (HKLM\...\KB2904266) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2934207) (HKLM\...\KB2934207) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB898461) (HKLM\...\KB898461) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB951978) (HKLM\...\KB951978) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB955759) (HKLM\...\KB955759) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB968389) (HKLM\...\KB968389) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB971029) (HKLM\...\KB971029) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB973815) (HKLM\...\KB973815) (Version: 1 - Microsoft Corporation)
USB Serial Port Driver (x86) (HKLM\...\{18800668-6583-4E75-ACDB-583DBB9E5F08}) (Version: 2013.30.0.313 - Nokia)
VIA Platform Device Manager (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Driver Package - Cyclone Box Team (usbser) Ports  (03/01/2011 1.0.0.1) (HKLM\...\3AED542E463364CD3F5FFB0F678398D56EDE3B5A) (Version: 03/01/2011 1.0.0.1 - Cyclone Box Team)
Windows Driver Package - FTDI CDM Driver Package - Bus/D2XX Driver (04/10/2012 2.08.24) (HKLM\...\4C8545EEB6143B6AD3858B5D1E0AEE76040B1435) (Version: 04/10/2012 2.08.24 - FTDI)
Windows Driver Package - FTDI CDM Driver Package - VCP Driver (04/10/2012 2.08.24) (HKLM\...\6849F67BACD4DA5A5B9D46803E6850D0BE8B3826) (Version: 04/10/2012 2.08.24 - FTDI)
Windows Driver Package - Nokia Modem  (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia)
Windows Driver Package - Nokia Modem  (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia)
Windows Driver Package - Nokia pccsmcfd “LegacyDriver”  (05/31/2012 7.1.2.0) (HKLM\...\17D063A0A9F5D5A225B76B1D9BCB5ADBE85C8382) (Version: 05/31/2012 7.1.2.0 - Nokia)
Windows Driver Package - Sony Ericsson (WinUSB) sa0101UsbDeviceClass  (03/05/2010 2.0.0010.00002) (HKLM\...\CD73A687A16E6998FD4B0E03106923EF6E7BE0AC) (Version: 03/05/2010 2.0.0010.00002 - Sony Ericsson)
Windows Driver Package - Sony Ericsson Mobile Communications (ggsemc) USB  (02/22/2011 2.2.0.5) (HKLM\...\552F499C400E44850820F2525C7611BF677CAB6E) (Version: 02/22/2011 2.2.0.5 - Sony Ericsson Mobile Communications)
Windows Driver Package - UniversalBox Driver package (10/22/2009 2.06.00) (HKLM\...\A7CE1A1AE0C4652C93078FB4489630E9C2E5B9DB) (Version: 10/22/2009 2.06.00 - UniversalBox)
Windows Genuine Advantage Notifications (KB905474) (HKLM\...\WgaNotify) (Version: 1.9.0040.0 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version:  - )
Windows Media Format 11 runtime (Version:  - Microsoft Corporation) Hidden
Windows Media Player 11 (HKLM\...\Windows Media Player) (Version:  - )
Windows Media Player 11 (Version:  - Microsoft Corporation) Hidden
Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
WinRAR 4.20 (32-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WinUsb CoInstallers (HKLM\...\{B7D4B08A-9D89-4369-B51C-92CF8C03D2F8}) (Version: 1.1.8.1406 - Nokia)
WinUSB Compatible ID Drivers (HKLM\...\{C97989C1-551F-4F41-A069-2A49567FD36B}) (Version: 1.1.6.1416 - Nokia)
WinUSB Drivers ext (HKLM\...\{0ED6AC75-474D-4511-B198-05B8C99F6B8B}) (Version: 1.1.7.1416 - Nokia)
WinUSB Drivers x86 (HKLM\...\{7E46D946-1FF8-4D36-9BE2-8A01E9B0108E}) (Version: 2013.10.0.295 - Nokia)
WinUSB Drivers x86 ext (HKLM\...\{A1143086-B1F0-4002-BE5B-6C464CF01125}) (Version: 2013.30.1.314 - Nokia)
Wondershare Dr.Fone for iOS(Build 3.0.0.88) (HKLM\...\{A26F8BBD-EC10-4bdc-8AD8-F146825A8A63}_is1) (Version: 3.0.0.88 - Wondershare Software Co.,Ltd.)
Yahoo! Messenger (HKLM\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
ZTE Handset USB Driver (HKLM\...\{01D42BF0-ED08-463f-8A28-99EB6FEE962B}) (Version:  - ZTE Corporation)
Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation)
Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-299502267-115176313-682003330-1003_Classes\CLSID\{326787D9-37B9-47A6-B539-EE13E7B04B8B}\InprocServer32 -> C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\devicemanagerproperties.dll (Research In Motion Limited)
CustomCLSID: HKU\S-1-5-21-299502267-115176313-682003330-1003_Classes\CLSID\{47F64EC4-1AD6-4168-9D4C-00F3842F7CFB}\InprocServer32 -> C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\DeviceManagerProperties.dll (Research In Motion Limited)
CustomCLSID: HKU\S-1-5-21-299502267-115176313-682003330-1003_Classes\CLSID\{82D1C283-A637-4A07-B1EC-8C7AE661EAF1}\InprocServer32 -> C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\devicemanagerproperties.dll (Research In Motion Limited)
CustomCLSID: HKU\S-1-5-21-299502267-115176313-682003330-1003_Classes\CLSID\{C8992C14-DF59-4518-808F-CCFBB5850282}\InprocServer32 -> C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\devicemanagerproperties.dll (Research In Motion Limited)
CustomCLSID: HKU\S-1-5-21-299502267-115176313-682003330-1003_Classes\CLSID\{EB59852D-B38E-4A4C-94BA-6731836E5538}\InprocServer32 -> C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\DeviceManagerProperties.dll (Research In Motion Limited)
 
==================== Restore Points  =========================
 
21-06-2014 15:19:45 Software Distribution Service 3.0
22-06-2014 16:22:31 System Checkpoint
23-06-2014 06:32:32 Software Distribution Service 3.0
23-06-2014 08:27:28 Unsigned driver install
23-06-2014 10:01:26 Unsigned driver install
23-06-2014 12:43:19 Unsigned driver install
23-06-2014 12:59:39 Unsigned driver install
23-06-2014 14:12:56 Unsigned driver install
23-06-2014 16:53:33 Software Distribution Service 3.0
24-06-2014 08:31:35 Unsigned driver install
24-06-2014 11:28:34 Unsigned driver install
24-06-2014 12:33:00 Unsigned driver install
25-06-2014 06:18:29 Software Distribution Service 3.0
25-06-2014 06:21:58 Unsigned driver install
25-06-2014 06:22:42 Unsigned driver install
25-06-2014 07:03:04 Unsigned driver install
25-06-2014 07:10:50 Unsigned driver install
25-06-2014 07:18:00 Unsigned driver install
25-06-2014 07:57:05 Unsigned driver install
25-06-2014 08:18:35 Installed Windows XP winusb0100.
25-06-2014 08:24:53 Installed Windows XP winusb0100.
25-06-2014 09:10:12 Installed Windows XP winusb0100.
25-06-2014 09:26:03 Unsigned driver install
25-06-2014 10:01:52 Installed Windows XP winusb0100.
25-06-2014 10:13:33 Unsigned driver install
25-06-2014 10:37:24 Installed Windows XP winusb0100.
25-06-2014 10:39:12 Unsigned driver install
25-06-2014 11:01:59 Unsigned driver install
25-06-2014 12:59:09 Unsigned driver install
25-06-2014 14:51:16 Unsigned driver install
25-06-2014 15:46:16 Software Distribution Service 3.0
26-06-2014 06:37:39 Software Distribution Service 3.0
26-06-2014 07:06:06 Unsigned driver install
26-06-2014 09:03:28 Unsigned driver install
26-06-2014 09:49:25 Installed Windows XP winusb0100.
26-06-2014 09:49:40 Unsigned driver install
26-06-2014 10:18:09 Unsigned driver install
26-06-2014 12:11:05 Unsigned driver install
26-06-2014 14:36:07 Installed Windows XP winusb0100.
26-06-2014 17:06:18 Unsigned driver install
26-06-2014 17:16:05 Unsigned driver install
26-06-2014 17:33:45 Software Distribution Service 3.0
27-06-2014 07:12:15 Unsigned driver install
27-06-2014 07:47:25 Unsigned driver install
27-06-2014 08:05:46 Unsigned driver install
27-06-2014 08:23:06 Unsigned driver install
27-06-2014 08:31:12 Unsigned driver install
27-06-2014 08:40:14 Unsigned driver install
27-06-2014 08:47:45 Unsigned driver install
27-06-2014 12:25:41 Unsigned driver install
27-06-2014 16:09:24 Software Distribution Service 3.0
28-06-2014 09:29:13 Unsigned driver install
28-06-2014 09:31:54 Unsigned driver install
28-06-2014 09:55:27 Installed Windows XP winusb0100.
28-06-2014 09:55:56 Unsigned driver install
28-06-2014 10:43:22 Unsigned driver install
30-06-2014 06:13:14 Software Distribution Service 3.0
30-06-2014 07:24:56 Installed Windows XP winusb0100.
30-06-2014 08:27:37 Unsigned driver install
30-06-2014 08:37:49 Unsigned driver install
01-07-2014 06:29:08 Software Distribution Service 3.0
01-07-2014 08:12:13 Unsigned driver install
01-07-2014 13:10:59 Unsigned driver install
02-07-2014 06:24:15 Software Distribution Service 3.0
02-07-2014 07:07:30 Unsigned driver install
02-07-2014 12:32:22 Unsigned driver install
02-07-2014 13:57:02 Installed Windows XP winusb0100.
02-07-2014 14:37:41 Unsigned driver install
02-07-2014 16:30:56 Software Distribution Service 3.0
03-07-2014 10:32:49 Unsigned driver install
03-07-2014 10:34:17 Unsigned driver install
03-07-2014 14:44:55 Unsigned driver install
03-07-2014 16:38:45 Software Distribution Service 3.0
04-07-2014 07:11:10 Unsigned driver install
04-07-2014 07:20:29 Unsigned driver install
04-07-2014 09:51:26 Unsigned driver install
04-07-2014 12:58:22 Unsigned driver install
04-07-2014 14:04:00 Unsigned driver install
04-07-2014 14:45:18 Unsigned driver install
04-07-2014 16:55:42 Software Distribution Service 3.0
05-07-2014 07:20:30 Unsigned driver install
05-07-2014 07:49:20 Unsigned driver install
05-07-2014 07:55:33 Unsigned driver install
05-07-2014 13:03:47 Installed Windows XP winusb0100.
07-07-2014 06:21:24 Software Distribution Service 3.0
07-07-2014 09:44:35 Unsigned driver install
07-07-2014 10:18:56 Unsigned driver install
07-07-2014 13:52:44 Unsigned driver install
07-07-2014 15:52:09 Unsigned driver install
07-07-2014 15:55:57 Unsigned driver install
08-07-2014 06:21:27 Software Distribution Service 3.0
08-07-2014 13:57:31 Unsigned driver install
08-07-2014 14:43:27 Unsigned driver install
09-07-2014 06:34:25 Software Distribution Service 3.0
09-07-2014 07:27:52 Unsigned driver install
09-07-2014 10:32:12 Unsigned driver install
09-07-2014 15:43:12 Unsigned driver install
10-07-2014 06:42:48 Software Distribution Service 3.0
10-07-2014 10:22:51 Unsigned driver install
10-07-2014 12:39:22 Unsigned driver install
10-07-2014 12:40:20 Unsigned driver install
10-07-2014 14:11:45 Unsigned driver install
10-07-2014 14:52:37 Installed Windows XP winusb0100.
10-07-2014 15:02:42 Installed Windows XP winusb0100.
10-07-2014 15:46:00 Unsigned driver install
10-07-2014 16:25:15 Unsigned driver install
11-07-2014 06:56:12 Software Distribution Service 3.0
11-07-2014 11:02:21 Unsigned driver install
11-07-2014 12:00:25 Unsigned driver install
11-07-2014 12:07:35 Unsigned driver install
11-07-2014 13:47:19 Unsigned driver install
11-07-2014 14:23:22 Unsigned driver install
11-07-2014 14:33:14 Unsigned driver install
14-07-2014 06:36:54 Software Distribution Service 3.0
14-07-2014 06:49:13 Unsigned driver install
14-07-2014 07:23:01 Unsigned driver install
14-07-2014 16:52:26 Software Distribution Service 3.0
15-07-2014 09:02:52 Unsigned driver install
15-07-2014 11:22:40 Unsigned driver install
15-07-2014 14:36:45 Unsigned driver install
15-07-2014 14:39:01 Unsigned driver install
16-07-2014 06:25:47 Software Distribution Service 3.0
17-07-2014 06:37:08 Software Distribution Service 3.0
17-07-2014 10:49:27 Unsigned driver install
17-07-2014 10:51:34 Unsigned driver install
17-07-2014 11:05:11 Unsigned driver install
17-07-2014 11:30:18 Unsigned driver install
17-07-2014 11:56:52 Unsigned driver install
18-07-2014 06:30:29 Software Distribution Service 3.0
18-07-2014 07:10:16 Unsigned driver install
18-07-2014 08:16:58 Unsigned driver install
18-07-2014 09:35:00 Unsigned driver install
19-07-2014 06:57:48 Software Distribution Service 3.0
21-07-2014 06:38:44 Software Distribution Service 3.0
21-07-2014 15:09:25 Unsigned driver install
21-07-2014 15:41:16 Unsigned driver install
21-07-2014 15:58:35 Unsigned driver install
22-07-2014 06:24:24 Software Distribution Service 3.0
22-07-2014 06:41:48 Unsigned driver install
22-07-2014 08:01:57 Unsigned driver install
22-07-2014 08:55:43 Unsigned driver install
22-07-2014 10:06:18 Unsigned driver install
22-07-2014 13:27:58 Unsigned driver install
23-07-2014 06:14:11 Software Distribution Service 3.0
23-07-2014 09:31:16 Unsigned driver install
23-07-2014 09:44:11 Unsigned driver install
23-07-2014 14:22:06 Unsigned driver install
24-07-2014 06:05:09 Software Distribution Service 3.0
24-07-2014 06:28:28 Unsigned driver install
25-07-2014 06:40:19 Software Distribution Service 3.0
25-07-2014 12:20:46 Unsigned driver install
25-07-2014 12:49:32 Unsigned driver install
25-07-2014 14:37:28 Unsigned driver install
26-07-2014 07:17:54 Software Distribution Service 3.0
28-07-2014 06:25:35 Software Distribution Service 3.0
28-07-2014 09:58:18 Unsigned driver install
28-07-2014 10:40:57 Unsigned driver install
28-07-2014 10:42:23 Unsigned driver install
28-07-2014 16:30:01 Software Distribution Service 3.0
29-07-2014 07:48:31 Unsigned driver install
29-07-2014 07:53:34 Unsigned driver install
29-07-2014 08:38:50 Unsigned driver install
29-07-2014 09:22:50 Unsigned driver install
29-07-2014 09:25:53 Unsigned driver install
29-07-2014 11:36:38 Unsigned driver install
29-07-2014 12:18:41 Unsigned driver install
29-07-2014 15:35:45 Unsigned driver install
29-07-2014 15:43:02 Unsigned driver install
30-07-2014 07:14:02 Software Distribution Service 3.0
30-07-2014 08:51:00 Unsigned driver install
30-07-2014 12:46:21 Unsigned driver install
30-07-2014 17:09:08 Software Distribution Service 3.0
31-07-2014 07:39:46 Unsigned driver install
31-07-2014 10:18:38 Unsigned driver install
31-07-2014 10:27:33 Unsigned driver install
31-07-2014 15:02:47 Unsigned driver install
01-08-2014 06:32:43 Software Distribution Service 3.0
01-08-2014 11:26:16 Installed Windows XP winusb0100.
01-08-2014 11:41:16 Installed Windows XP winusb0100.
01-08-2014 11:57:33 Unsigned driver install
04-08-2014 06:24:56 Software Distribution Service 3.0
04-08-2014 07:39:36 Unsigned driver install
04-08-2014 09:00:41 Unsigned driver install
04-08-2014 12:43:47 Unsigned driver install
04-08-2014 13:15:31 Unsigned driver install
04-08-2014 13:48:19 Unsigned driver install
04-08-2014 14:28:56 Installed Windows XP winusb0100.
04-08-2014 16:11:42 Unsigned driver install
04-08-2014 16:20:53 Unsigned driver install
04-08-2014 16:24:09 Unsigned driver install
04-08-2014 16:25:57 Unsigned driver install
04-08-2014 16:59:38 Unsigned driver install
04-08-2014 17:08:09 Unsigned driver install
04-08-2014 17:38:50 Unsigned driver install
04-08-2014 18:53:08 Unsigned driver install
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2014-07-07 09:20 - 2014-07-07 09:20 - 00012393 ____A C:\windows\system32\Drivers\etc\hosts
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR...l4/strict.dtd">
<html lang='en'>
<head>
            <meta name="description" content="Yahoo! GeoCities offers you a free web site and all the tools you need to build a dynamic site. Features include easy-to-use site building tools, online help, web site statistics, secure and reliable hosting, and an intuitive control panel.">
            <title>Yahoo! GeoCities: Get a web site with easy-to-use site building tools.</title>
<link rel="stylesheet" type="text/css" media="all" href="http://l.yimg.com/a/...ities_84954.css"> <style>
h1 { line-height:30px;height:30px; padding-left:15px; font-weight:bold;font-size:1.6em;color:#1f296a;}
.services li { margin-left:1.0em; padding-left:0.5em; background:url("http://l.yimg.com/a/...ullet_3x3_1.gif") no-repeat 0 0.5em; margin-bottom:0.5em;margin-left:1.5em;margin-right:0.5em;width:6em}
.services li {float:left; width:17em; font-size:116%;margin-top:0.8em}
 .services {  font-size:116%; padding-bottom:20px }
.learnmore a {color:#2882DE;font-size:16px}
.image_web  {float:right; margin:15px 0 0 15px}
p {margin:20px;font-size:1em;}
h2 {margin:20px 0 0 20px;color:#1F296;font-weight:bold;font-size:1.25em;color:#1f296a;}
h3 {margin:20px;color:#1F296;font-weight:bold;font-size:1.15em;color:#1f296a;}
li.rule {border-top:solid 1px #DBE1E6;}
</style>
</head>
<body>
<!-- following code added by server. PLEASE REMOVE -->
<!-- preceding code added by server. PLEASE REMOVE -->
 <div class="ez-mw" style ="height:900px;width:905px">
    <div class="ez-wri ez-oh" style="width:900px">
    <div class="ez-box">  <link type="text/css" rel="stylesheet" href="http://l.yimg.com/a/...uh-1.0.28.css">
            <style type="text/css">
                div#headerblock div{font-family:arial;}
                #ygma{position:relative;z-index:99999;}
                #ygma #ygma-search input{width:200px;}
                #ygma #ygma-search{width:400px;}
            </style>
    <li class="me3"><a href="http://us.ard.yahoo..../SIG=11hjute28/*http://help.yahoo.com/l/us/yahoo/geocities/" target="_top" title="Yahoo! Help Central">Help</a></li>    </ul></div><div id="ygmapromo"><a style="font-weight:bold;" id="ygmaie8" href="http://us.ard.yahoo.com/SIG=15vud5jbf/M=650008.13445975.13532322.12832737/D=smallbiz/S=2023010636:HPRM2/Y=YAHOO/EXP=1252098025/L=j.Ah_9j8aIuVH8pzSp2qoCg9z37hF0qhY8gACN48/B=0Qw4Atj8a20-/J=1252090825225621/K=pmFpaSqI9UgVSmAu3nNNgw/A=5706923/R=0/SIG=117bakia1/*http://toolbar.yahoo.com/?.cpdl=ushdl" target="_top">Get Yahoo! Toolbar<abbr title="Yahoo! Toolbar"></abbr></a>    <script language=javascript>
        if(window.yzq_d==null)window.yzq_d=new Object();
        window.yzq_d['0Qw4Atj8a20-']='&U=13hn349r9%2fN%3d0Qw4Atj8a20-%2fC%3d650008.13445975.13532322.12832737%2fD%3dHPRM2%2fB%3d5706923%2fV%3d1';
    </script>    <noscript><img width=1 height=1 alt="" src="http://us.bc.yahoo.c...2/B=5706923/V=1"></noscript></div>    <div id="pa"><div id="pa-wrapper"><ul id="pa2-nav" class="sp"><li class="pa1 sp"><a class="sp" href="http://us.ard.yahoo.com/SIG=15uqalioe/M=650008.13654021.13693393.13153902/D=smallbiz/S=2023010636:HEAD/Y=YAHOO/EXP=1252098025/L=j.Ah_9j8aIuVH8pzSp2qoCg9z37hF0qhY8gACN48/B=zgw4Atj8a20-/J=1252090825225621/K=pmFpaSqI9UgVSmAu3nNNgw/A=5836006/R=8/SIG=10jmd0d5u/*http://yahoo.com/" title="Yahoo!" target="_top">Yahoo!</a></li><li class="pa2 sp"><a class="sp" href="http://us.ard.yahoo.com/SIG=15uqalioe/M=650008.13654021.13693393.13153902/D=smallbiz/S=2023010636:HEAD/Y=YAHOO/EXP=1252098025/L=j.Ah_9j8aIuVH8pzSp2qoCg9z37hF0qhY8gACN48/B=zgw4Atj8a20-/J=1252090825225621/K=pmFpaSqI9UgVSmAu3nNNgw/A=5836006/R=9/SIG=10n3m6b64/*http://mail.yahoo.com" title="Yahoo! Mail" target="_top">Mail</a></li></ul><div id="pa-left" class="sp"></div><ul id="pa-nav" class="sp"><li class="pa3 sp"><a class="sp" href="http://us.ard.yahoo.com/SIG=15uqalioe/M=650008.13654021.13693393.13153902/D=smallbiz/S=2023010636:HEAD/Y=YAHOO/EXP=1252098025/L=j.Ah_9j8aIuVH8pzSp2qoCg9z37hF0qhY8gACN48/B=zgw4Atj8a20-/J=1252090825225621/K=pmFpaSqI9UgVSmAu3nNNgw/A=5836006/R=10/SIG=10l2nj3k8/*http://my.yahoo.com" title="My Yahoo!" target="_top">My Yahoo!</a></li><li class="pa4 sp"><a class="sp" href="http://us.ard.yahoo.com/SIG=15uqalioe/M=650008.13654021.13693393.13153902/D=smallbiz/S=2023010636:HEAD/Y=YAHOO/EXP=1252098025/L=j.Ah_9j8aIuVH8pzSp2qoCg9z37hF0qhY8gACN48/B=zgw4Atj8a20-/J=1252090825225621/K=pmFpaSqI9UgVSmAu3nNNgw/A=5836006/R=11/SIG=10niob72s/*http://news.yahoo.com" title="Yahoo! News" target="_top">News</a></li><li class="pa5 sp"><a class="sp" href="http://us.ard.yahoo.com/SIG=15uqalioe/M=650008.13654021.13693393.13153902/D=smallbiz/S=2023010636:HEAD/Y=YAHOO/EXP=1252098025/L=j.Ah_9j8aIuVH8pzSp2qoCg9z37hF0qhY8gACN48/B=zgw4Atj8a20-/J=1252090825225621/K=pmFpaSqI9UgVSmAu3nNNgw/A=5836006/R=12/SIG=10q40gpus/*http://finance.yahoo.com" title="Yahoo! Finance" target="_top">Finance</a></li><li class="pa6 sp"><a class="sp" href="http://us.ard.yahoo.com/SIG=15uqalioe/M=650008.13654021.13693393.13153902/D=smallbiz/S=2023010636:HEAD/Y=YAHOO/EXP=1252098025/L=j.Ah_9j8aIuVH8pzSp2qoCg9z37hF0qhY8gACN48/B=zgw4Atj8a20-/J=1252090825225621/K=pmFpaSqI9UgVSmAu3nNNgw/A=5836006/R=13/SIG=10pcalhda/*http://sports.yahoo.com" title="Yahoo! Sports" target="_top">Sports</a></li></ul><div id="pa-right" class="sp"></div></div></div></div><div id="yahoo" class="ygmaclr"><div id="ygmabot"><a id="ygmalogo" href="http://us.ard.yahoo.com/SIG=15uqalioe/M=650008.13654021.13693393.13153902/D=smallbiz/S=2023010636:HEAD/Y=YAHOO/EXP=1252098025/L=j.Ah_9j8aIuVH8pzSp2qoCg9z37hF0qhY8gACN48/B=zgw4Atj8a20-/J=1252090825225621/K=pmFpaSqI9UgVSmAu3nNNgw/A=5836006/R=14/SIG=110k0lq1s/*http://smallbusiness.yahoo.com" target="_top"><img id="ygmalogoimg" width="265" height="33" src="http://l.yimg.com/a/i/us/geo/b/geo_ma_p_us_1.gif" alt="Yahoo! Small Business"></a></div><div id="ygma-search"><form class="ygmaclr" id="sf" action="http://search.yahoo.com/search" method="GET"><fieldset><span class="ygma-search-wrapper" role="application"><input class="sp" type="text" id="ygmasearchInput" name="p" value="Search" onblur="if (this.value == ''){this.value='Search';this.style.color='#999';this.style.fontWeight='normal';}" onfocus="if (this.value == 'Search'){this.value='';this.style.color='#000';this.style.fontWeight='bold';}" maxlength="100" autocomplete="off" /><input type="hidden" id="fr" name="fr" value="ush-smbizc" /><div id="sat"></div></span><span class="ygma-search-wrapper"><span class="btn sp"><span class="first-child"><button name="ygmasrchbtn" id="ygmasrchbtn" value="Web Search" type="submit">Web Search </button></span></span></span></fieldset></form></div></div></div></div></div><script charset="utf-8" type="text/javascript" src="http://l.yimg.com/a/lib/uh/15/js/uh-1.0.20.js"></script>    <script language=javascript>
        if(window.yzq_d==null)window.yzq_d=new Object();
        window.yzq_d['zgw4Atj8a20-']='&U=13gmetml2%2fN%3dzgw4Atj8a20-%2fC%3d650008.13654021.13693393.13153902%2fD%3dHEAD%2fB%3d5836006%2fV%3d1';
    </script>
   
    </div>
    </div>
    <div class="ez-wr" style="width:898px;margin-top:1.5em">
        <Div class="ez-l2a" id="wrapper">
            <div class="ez-l2a-1 " style="width:898px">
                <div class="ez-box">    
                    <div class="ez-wr" >
                     <div class="ez-box" style="width:898px">
                              <h1>Sorry, the GeoCities web site you were trying to reach is no longer available.</h1>
                    </div>
                </div>
                <div class="ez-wr">
                    <div class="ez-box" id="boxyahoourls">    
               <p> GeoCities has closed, but there's a lot more to explore on Yahoo!</p>
                   <h2>Visit one of these popular Yahoo! sites:</h2>
                   <ul class= "services">
                            <li><a href="http://mail.yahoo.com">Yahoo! Mail</a></li>
                            <li><a href="http://smallbusiness....com/webhosting">Web Hosting</a></li>
                            <li><a href="http://news.yahoo.co...">News</a></li>
                            <li><a href="http://games.yahoo.c...>Games</a></li>
                           <li><a href="http://sports.yahoo.com/">Sports</a>   </li>
                          <li><a href="http://movies.yahoo....Movies</a></li>
                           <li><a href="http://finance.yahoo...inance</a></li>
                           <li><a href="http://maps.yahoo.co...">Maps</a></li>
                         </ul>                    </div>
                    <li class="rule"><!----></li> 
    <p>The GeoCities site you were looking for may have been preserved in the Internet Archive's Wayback Machine. To find out, <a href="http://www.archive.org/web/web.php" target="_blank">visit Archive.org</a> and enter the site's web address in the field provided.</p>
                    <li class="rule"><!----></li> 
                </div>
                </div>
            </div>    </div>    <div class="ez-wr">
       <div class="ez-box" style="text-align:center; margin-top:25px;"> 
       <font size="-2" face="verdana">Copyright &copy; 2009 <a href="http://yahoo.com/">Yahoo!</a> Inc. All rights reserved.
       <ul>
       <li style="display:inline;"><a target="_top" href="http://privacy.yahoo...privacy/us/geo/">Privacy Policy</a></li> -       <li style="display:inline;"><a target="_top" href="http://docs.yahoo.com/info/copyright/copyright.html">Copyright Policy</a></li> -
       <li style="display:inline;"><a target="_top" href="http://docs.yahoo.co...">Guidelines</a
       ></li> -
       <li style="display:inline;"><a target="_top" href="http://smallbusiness...com/tos/tos.php">Terms of Service
       </a></li> -
       <li style="display:inline;"><a target="_top" href="http://help.yahoo.co...">Help</a></li>
       </ul>       </font> 
       </div> 
        
    </div> </div>
</body>
</html> 
<!-- text below generated by server. PLEASE REMOVE --></object></layer></div></span></style></noscript></table></script></applet>
<IMG SRC="http://geo.yahoo.com...4714029&f=us-w4" ALT=1 WIDTH=1 HEIGHT=1>
 
==================== Scheduled Tasks (whitelisted) =============
 
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\windows\Tasks\At1.job => ?
Task: C:\windows\Tasks\At2.job => ?
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\windows\system32\xp_eos.exe
Task: C:\windows\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\windows\system32\xp_eos.exe
 
==================== Loaded Modules (whitelisted) =============
 
2008-12-06 01:38 - 2008-12-06 01:38 - 00619008 _____ () C:\Program Files\Samsung\Samsung PC Studio 7\phonebrowser.dll
2009-05-16 00:22 - 2009-05-16 00:22 - 00716800 _____ () C:\Program Files\Samsung\Samsung PC Studio 7\PCSCM_Samsung.dll
2014-02-12 21:58 - 2014-02-12 21:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 21:58 - 2014-02-12 21:58 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-10-17 16:40 - 2013-10-17 16:40 - 00031080 _____ () C:\Program Files\HTC\HTC Sync Manager\DbAccess.dll
2013-10-17 16:40 - 2013-10-17 16:40 - 00607376 _____ () C:\Program Files\HTC\HTC Sync Manager\sqlite3.dll
2013-10-17 16:40 - 2013-10-17 16:40 - 00044392 _____ () C:\Program Files\HTC\HTC Sync Manager\NAdvLog.dll
2013-10-17 16:40 - 2013-10-17 16:40 - 00036216 _____ () C:\Program Files\HTC\HTC Sync Manager\NFileCacheDBAccess.dll
2013-10-17 16:40 - 2013-10-17 16:40 - 00080248 _____ () C:\Program Files\HTC\HTC Sync Manager\ninstallerhelper.dll
2013-10-17 16:42 - 2013-10-17 16:42 - 00129376 _____ () C:\Program Files\HTC\HTC Sync Manager\zlib1.dll
2013-10-17 16:43 - 2013-10-17 16:43 - 00223592 _____ () C:\Program Files\HTC\HTC Sync Manager\DevConnMon.dll
2013-10-10 12:39 - 2012-12-07 17:26 - 00167424 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
2014-05-06 17:16 - 2014-05-06 17:16 - 00107816 _____ () C:\windows\system32\FLSDEVCP.EXE
2013-04-02 16:28 - 2012-05-25 04:25 - 00921600 _____ () C:\Program Files\Yahoo!\Messenger\yui.dll
2013-04-02 16:28 - 2012-05-25 04:25 - 00078336 _____ () C:\Program Files\Yahoo!\Messenger\pcre.dll
2008-08-21 15:00 - 2013-01-02 09:49 - 01292288 _____ () C:\WINDOWS\system32\quartz.dll
2008-08-21 15:00 - 2008-08-21 15:00 - 00059904 _____ () C:\WINDOWS\system32\devenum.dll
2008-08-21 15:00 - 2008-08-21 15:00 - 00014336 _____ () C:\windows\system32\msdmo.dll
2006-09-10 20:46 - 2006-09-10 20:46 - 00020776 _____ () C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll
2012-06-26 13:11 - 2012-06-26 13:11 - 02302040 _____ () C:\Program Files\Nokia\Nokia PC Suite 7\QtCore4.dll
2012-06-26 13:11 - 2012-06-26 13:11 - 08197208 _____ () C:\Program Files\Nokia\Nokia PC Suite 7\QtGui4.dll
2012-06-26 13:11 - 2012-06-26 13:11 - 00345688 _____ () C:\Program Files\Nokia\Nokia PC Suite 7\QtXml4.dll
2012-06-26 13:10 - 2012-06-26 13:10 - 00202328 _____ () C:\Program Files\Nokia\Nokia PC Suite 7\imageformats\qjpeg4.dll
2012-06-26 13:10 - 2012-06-26 13:10 - 00027736 _____ () C:\Program Files\Nokia\Nokia PC Suite 7\imageformats\qsvg4.dll
2012-06-26 13:11 - 2012-06-26 13:11 - 00282200 _____ () C:\Program Files\Nokia\Nokia PC Suite 7\QtSvg4.dll
2013-10-17 16:41 - 2013-10-17 16:41 - 00821600 _____ () C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
2012-11-19 12:16 - 2010-02-27 02:25 - 00044401 ____N () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\winlogon.exe
2012-11-19 12:16 - 2010-02-27 02:25 - 00044401 _____ () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\services.exe
2012-11-19 12:16 - 2010-02-27 02:25 - 00044401 _____ () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\lsass.exe
2014-07-18 14:42 - 2014-07-15 12:24 - 08537928 _____ () C:\Program Files\Google\Chrome\Application\36.0.1985.125\pdf.dll
2014-07-18 14:42 - 2014-07-15 12:24 - 00353096 _____ () C:\Program Files\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll
2014-07-18 14:42 - 2014-07-15 12:24 - 01732936 _____ () C:\Program Files\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot => "AlternateShell"="cmd-brontok.exe"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\83511949.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\83511949.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BlackBerryLink.exe => "C:\Program Files\Research In Motion\BlackBerry Link\BlackBerryLink.exe" /minimize
MSCONFIG\startupreg: ctfmon.exe => C:\windows\system32\ctfmon.exe
MSCONFIG\startupreg: DriverToolkit => "C:\Program Files\DriverToolkit\DriverToolkit.exe" --autorun
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: H/PC Connection Agent => "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
MSCONFIG\startupreg: HDAudDeck => C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
MSCONFIG\startupreg: HotKeysCmds => C:\WINDOWS\system32\hkcmd.exe
MSCONFIG\startupreg: HTC Sync Loader => "C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
MSCONFIG\startupreg: IgfxTray => C:\WINDOWS\system32\igfxtray.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: KiesAirMessage => C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
MSCONFIG\startupreg: KiesPreload => C:\Program Files\Samsung\Kies\Kies.exe /preload
MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: MSMSGS => "C:\Program Files\Messenger\msmsgs.exe" /background
MSCONFIG\startupreg: NokiaSuite.exe => C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray
MSCONFIG\startupreg: PC Suite Tray => "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
MSCONFIG\startupreg: Persistence => C:\WINDOWS\system32\igfxpers.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RIM PeerManager => "C:\Program Files\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe"
MSCONFIG\startupreg: RIMBBLaunchAgent.exe => C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
MSCONFIG\startupreg: S60 PC Suite Tray => "C:\Program Files\SAMSUNG\Samsung PC Studio 7\PCSuite.exe" -onlytray
MSCONFIG\startupreg: StartCCC => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: uTorrent => "C:\Documents and Settings\Radu Mamii\Application Data\uTorrent\uTorrent.exe"
MSCONFIG\startupreg: Zune Launcher => "c:\Program Files\Zune\ZuneLauncher.exe"
 
==================== Faulty Device Manager Devices =============
 
Name: Nokia 8800e-1
Description: Nokia 8800e-1
Class Guid: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Manufacturer: Nokia
Service: WUDFRd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Nokia 201
Description: Nokia Windows Portable Device Driver
Class Guid: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Manufacturer: Nokia
Service: WUDFRd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Nokia E71
Description: Nokia Windows Portable Device Driver
Class Guid: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Manufacturer: Nokia
Service: WUDFRd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Nokia 201
Description: Nokia Windows Portable Device Driver
Class Guid: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Manufacturer: Nokia
Service: WUDFRd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Nokia C3-01.5
Description: Nokia Windows Portable Device Driver
Class Guid: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Manufacturer: Nokia
Service: WUDFRd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/04/2014 08:01:13 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application SPT.exe, version 18.1.8.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error: (08/04/2014 11:43:14 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application Odin3 v3.09.exe, version 2013.5.24.1, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error: (07/29/2014 06:57:55 PM) (Source: .NET Runtime 4.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 kies.exe, P2 1.0.0.1521, P3 5279a14e, P4 devicevideo, P5 1.0.0.176, P6 5279a0e7, P7 5e, P8 ae, P9 clr20r30, P10 clr20r31.
 
Error: (07/23/2014 06:15:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application Cyclone.exe, version 1.0.1.1155, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error: (07/23/2014 06:12:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application cyclone.exe, version 1.0.1.1155, faulting module , version 0.0.0.0, fault address 0x00000000.
Processing media-specific event for [cyclone.exe!ws!]
 
Error: (07/21/2014 05:58:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application Odin3-v3.07.exe, version 3.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error: (07/21/2014 05:40:33 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application Cyclone.exe, version 1.0.1.1155, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error: (07/14/2014 01:59:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application Cyclone.exe, version 1.0.1.1155, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error: (07/14/2014 10:01:06 AM) (Source: RIM MDNS) (EventID: 100) (User: )
Description: 208: ERROR: read_msg errno 10053 (An established connection was aborted by the software in your host machine.)
 
Error: (07/14/2014 10:01:06 AM) (Source: RIM MDNS) (EventID: 100) (User: )
Description: ERROR: mDNSPlatformReadTCP - recv: 10053
 
 
System errors:
=============
Error: (08/04/2014 09:26:25 PM) (Source: Dhcp) (EventID: 1000) (User: )
Description: Your computer has lost the lease to its IP address 192.168.2.41 on the
Network Card with network address 002354CB06B4.
 
Error: (08/04/2014 09:23:20 PM) (Source: Dhcp) (EventID: 1000) (User: )
Description: Your computer has lost the lease to its IP address 192.168.2.41 on the
Network Card with network address 002354CB06B4.
 
Error: (08/04/2014 09:20:30 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Apple Mobile Device service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (08/04/2014 08:02:41 PM) (Source: Dhcp) (EventID: 1000) (User: )
Description: Your computer has lost the lease to its IP address 192.168.2.41 on the
Network Card with network address 002354CB06B4.
 
Error: (08/04/2014 07:19:31 PM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'FT SCR2000 0' rejected IOCTL GET_ATTRIBUTE: The request is not supported.
 
Error: (08/04/2014 07:19:30 PM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Axalto e-gate 0' rejected IOCTL GET_ATTRIBUTE: The request is not supported.
 
Error: (08/04/2014 07:18:05 PM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'FT SCR2000 0' rejected IOCTL GET_ATTRIBUTE: The request is not supported.
 
Error: (08/04/2014 07:18:04 PM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Axalto e-gate 0' rejected IOCTL GET_ATTRIBUTE: The request is not supported.
 
Error: (08/04/2014 07:16:58 PM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'FT SCR2000 0' rejected IOCTL GET_ATTRIBUTE: The request is not supported.
 
Error: (08/04/2014 07:16:56 PM) (Source: SCardSvr) (EventID: 610) (User: )
Description: Smart Card Reader 'Axalto e-gate 0' rejected IOCTL GET_ATTRIBUTE: The request is not supported.
 
 
Microsoft Office Sessions:
=========================
 
==================== Memory info =========================== 
 
Percentage of memory in use: 34%
Total physical RAM: 3062.11 MB
Available physical RAM: 2012.82 MB
Total Pagefile: 4948 MB
Available Pagefile: 4075.68 MB
Total Virtual: 2047.88 MB
Available Virtual: 1920.87 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:488.28 GB) (Free:138.64 GB) NTFS
Drive d: () (Fixed) (Total:443.22 GB) (Free:10.82 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 932 GB) (Disk ID: 8E91D08A)
Partition 1: (Active) - (Size=488 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=443 GB) - (Type=OF Extended)
 
==================== End Of Log ============================

  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
There is a bit too much to try and remove manually so I will use a trial of Kaspersky pure

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

HKLM\...\Winlogon: [Shell] Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe" [x ] ()
HKU\.DEFAULT\...\Run: [Tok-Cirrhatus-1860] => C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br4743on.exe [44401 2010-02-27] ()
HKU\.DEFAULT\...\Run: [Tok-Cirrhatus] => C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br4743on.exe [44401 2010-02-27] ()
HKU\.DEFAULT\...\Policies\system: [DisableRegistryTools] 1
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Run: [Tok-Cirrhatus-3543] => C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br8109on.exe [44401 2010-02-27] ()
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Run: [Tok-Cirrhatus] => C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br8109on.exe [44401 2010-02-27] ()
2014-08-04 09:23 - 2014-08-04 09:23 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-4
2014-08-01 19:57 - 2014-08-01 19:57 - 00012393 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Update.16.Bron.Tok.bin
2014-08-01 18:48 - 2014-08-01 18:48 - 00012393 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok.A16.em.bin
2014-08-01 11:03 - 2014-08-01 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-1
2014-08-01 09:34 - 2014-08-01 09:34 - 00038912 _____ (SOFTWIN) C:\Documents and Settings\Radu Mamii\Desktop\AntiBrontokA-en.exe
2014-08-01 09:31 - 2014-08-01 09:31 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-1
2014-07-31 09:46 - 2014-07-31 09:46 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-31
2014-07-30 11:03 - 2014-07-30 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-30
2014-07-30 10:12 - 2014-07-30 10:12 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-30
2014-07-29 09:28 - 2014-07-29 09:28 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-29
2014-07-28 11:03 - 2014-07-28 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-28
2014-07-28 09:24 - 2014-07-28 09:24 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-28
2014-07-26 10:16 - 2014-07-26 10:16 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-26
2014-07-25 11:03 - 2014-07-25 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-25
C:\windows\Tasks\At*.job
Task: C:\windows\Tasks\At1.job => ?
Task: C:\windows\Tasks\At2.job => ?
CMD: bitsadmin /reset /allusers
CMD: DEL %TEMP%\*.* /F /S /Q
CMD: RD /S /Q %TEMP%
REBOOT:


Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

RUN THE FOLLOWING PROGRAMME ON ALL SYSTEMS

Could you download and run Kaspersky pure trial from here http://www.kaspersky...ree-trials/pure

Once Kaspersky has installed you will see this screen

kas1.JPG

Select scan and allow it to update

report.JPG

Once the scan has completed and it has removed any threats select report on the top right

Click detailed report and post that here.

detail.JPG
  • 0

#7
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts

OK.I posted as soon as I get to work .... and have some time..


  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

The scans will probably take a while for each system so be prepared for that


  • 0

#9
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts

Is pretty hard because now are over capacity w phones ..i think after 19


  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

The problem is, if it is not tackled now it will get worse  and you could lose everything


  • 0

Advertisements


#11
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts

This is the fix log and i'l let this pc for now in case of some customers and the 2nd and 3rd pc is currently scanning with kaspersky pure 

 

  Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:2-08-2014

Ran by Radu Mamii at 2014-08-05 09:26:05 Run:1
Running from C:\Documents and Settings\Radu Mamii\Desktop
Boot Mode: Normal
 
==============================================
 
Content of fixlist:
*****************
HKLM\...\Winlogon: [Shell] Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe" [x ] ()
HKU\.DEFAULT\...\Run: [Tok-Cirrhatus-1860] => C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br4743on.exe [44401 2010-02-27] ()
HKU\.DEFAULT\...\Run: [Tok-Cirrhatus] => C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br4743on.exe [44401 2010-02-27] ()
HKU\.DEFAULT\...\Policies\system: [DisableRegistryTools] 1
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Run: [Tok-Cirrhatus-3543] => C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br8109on.exe [44401 2010-02-27] ()
HKU\S-1-5-21-299502267-115176313-682003330-1003\...\Run: [Tok-Cirrhatus] => C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\br8109on.exe [44401 2010-02-27] ()
2014-08-04 09:23 - 2014-08-04 09:23 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-4
2014-08-01 19:57 - 2014-08-01 19:57 - 00012393 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Update.16.Bron.Tok.bin
2014-08-01 18:48 - 2014-08-01 18:48 - 00012393 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok.A16.em.bin
2014-08-01 11:03 - 2014-08-01 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-1
2014-08-01 09:34 - 2014-08-01 09:34 - 00038912 _____ (SOFTWIN) C:\Documents and Settings\Radu Mamii\Desktop\AntiBrontokA-en.exe
2014-08-01 09:31 - 2014-08-01 09:31 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-1
2014-07-31 09:46 - 2014-07-31 09:46 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-31
2014-07-30 11:03 - 2014-07-30 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-30
2014-07-30 10:12 - 2014-07-30 10:12 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-30
2014-07-29 09:28 - 2014-07-29 09:28 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-29
2014-07-28 11:03 - 2014-07-28 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-28
2014-07-28 09:24 - 2014-07-28 09:24 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-28
2014-07-26 10:16 - 2014-07-26 10:16 - 00000000 ____D () C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-26
2014-07-25 11:03 - 2014-07-25 11:03 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-25
C:\windows\Tasks\At*.job
Task: C:\windows\Tasks\At1.job => ?
Task: C:\windows\Tasks\At2.job => ?
CMD: bitsadmin /reset /allusers
CMD: DEL %TEMP%\*.* /F /S /Q
CMD: RD /S /Q %TEMP%
REBOOT:
*****************
 
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value was restored successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\Tok-Cirrhatus-1860 => value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\Tok-Cirrhatus => value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableRegistryTools => value deleted successfully.
HKU\S-1-5-21-299502267-115176313-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Tok-Cirrhatus-3543 => value deleted successfully.
HKU\S-1-5-21-299502267-115176313-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Tok-Cirrhatus => value deleted successfully.
C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-4 => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Update.16.Bron.Tok.bin => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok.A16.em.bin => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-1 => Moved successfully.
C:\Documents and Settings\Radu Mamii\Desktop\AntiBrontokA-en.exe => Moved successfully.
C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-1 => Moved successfully.
C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-31 => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-30 => Moved successfully.
C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-30 => Moved successfully.
C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-29 => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-28 => Moved successfully.
C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-28 => Moved successfully.
C:\Documents and Settings\Radu Mamii\Local Settings\Application Data\Bron.tok-16-26 => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok-16-25 => Moved successfully.
C:\windows\Tasks\At*.job => Moved successfully.
C:\windows\Tasks\At1.job not found.
C:\windows\Tasks\At2.job not found.
 
=========  bitsadmin /reset /allusers =========
 
'bitsadmin' is not recognized as an internal or external command,
operable program or batch file.
 
========= End of CMD: =========
 
 
=========  DEL %TEMP%\*.* /F /S /Q =========
 
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\2c824662902b6aa9dd00442dfde5876b.dat
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\A7C73B.dmp
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\adb.log
The process cannot access the file because it is being used by another process.
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\addonscheck.xml
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\AdobeARM.log
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\B1F5CC.dmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\BBLink_Install.log
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\C3EE91.dmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\CalendarViewLog.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\chrome_installer.log
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\DalMeasurementFile2.log
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\dkdlqmdlrkqt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\dw.log
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\EE89BC.dmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\emoticats.bmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbA5.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbA6.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbA7.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbA8.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbA9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbAA.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbAB.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbAC.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbAD.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbAE.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbAF.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbB0.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbB1.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbB2.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\evbB3.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\flickr.bmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\IMT9.xml
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\IMTA.xml
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\IMTB.xml
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\inet.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\JavaDeployReg.log
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\jusched.log
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\LGAutoRun_C.Log
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\LGAutoRun_G.Log
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Loader-(2014-07-03).log
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Loader-(2014-07-15).log
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\log3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\mgyun_driver_32_4.zip
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\MMCULog2.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\NEventMessages.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\NGLALog.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\NOSEventMessages.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nse53.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsf3D.exe
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsf3D.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsh2F.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsh40.exe
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsh40.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsj39.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsn29.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsn46.exe
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsn46.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsv4C.exe
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsv4C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsz3A.exe
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsz3A.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsz49.exe
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsz49.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsz54.exe
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsz54.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\ourworld.bmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\pcsuitecheck_new.xml
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Perflib_Perfdata_138.dat
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Perflib_Perfdata_23c.dat
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Perflib_Perfdata_27c.dat
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Perflib_Perfdata_2d0.dat
The process cannot access the file because it is being used by another process.
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Perflib_Perfdata_348.dat
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Perflib_Perfdata_894.dat
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\pool.bin
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\qtsingleapp-NokiaO-b889-0-lockfile
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\ras10B.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\ras207.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\sp-downloader.exe
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\ssdkdlqmdlrkqt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\sszlrkqt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\thethread.bmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\TmpLink_655361.adi
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\TmpLink_655361.adt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\TmpLink_720897.adi
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\TmpLink_720897.adt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\TmpLink_720898.adi
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\TmpLink_720898.adt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\WCESCOMM.LOG
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\WCESLog.log
The process cannot access the file because it is being used by another process.
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\WcesView.log
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPC52.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPC52.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCE6.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCE6.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCE7.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCE7.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCE8.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCE8.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCE9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCE9.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCEA.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCEA.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCEB.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCEB.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCED.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCED.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCEE.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCEE.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCEF.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCEF.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF0.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF0.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF1.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF1.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF2.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF2.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF3.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF3.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF4.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF4.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF5.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF5.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF6.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF6.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF7.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\XPCF7.tmp.jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\ymsgr2
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\zlrkqt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF1126.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF11E5.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF15BE.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF15E9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF169C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF16BE.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF1732.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF1751.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF1875.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF187B.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF1943.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF1B1A.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF1B3F.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF1C64.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF1CE0.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF1D2F.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF2160.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF219B.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF21A9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF2373.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF244A.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF250C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF2646.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF27B3.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF27D0.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF28B9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF2A1.tmp
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF2C96.tmp
The process cannot access the file because it is being used by another process.
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF2CB7.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF2CCE.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF3322.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF34D0.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF370E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF3C20.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF3E73.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF3EE.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF3F58.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF4241.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF436F.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF456E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF4599.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF4623.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF482E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF48B8.tmp
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF48BB.tmp
The process cannot access the file because it is being used by another process.
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF49A2.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF530F.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF533.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF5390.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF542A.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF54D3.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF54D9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF550B.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF554E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF567C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF57B8.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF594.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF5980.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF5AC9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF5EA6.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF60C3.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF638.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF656C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF6851.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF6C21.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF6D26.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF6D3B.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF6DA.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF6DB6.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF6DE0.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF6E57.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF6ED0.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF704C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF714F.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF74C8.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF74D.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF7550.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF7933.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF7946.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF7B98.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF7BEF.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF7E8E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF8021.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF8150.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF8203.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF837E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF89AE.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF8AD8.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF8C8D.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF8C9B.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF8DA0.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF8F1.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF8F38.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF9089.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF90CF.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF9110.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF96B1.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF97F1.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF9837.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF986E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF995C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF9A6B.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF9A77.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF9A7C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF9C2E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF9E00.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF9E5A.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF9F5B.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFA286.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFA2FB.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFA37F.tmp
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFA42B.tmp
The process cannot access the file because it is being used by another process.
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFA5DE.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFA6B7.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFA6BF.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFA915.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFAAF0.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFAB19.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFABD7.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFAC06.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFAD60.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFAF76.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFAF81.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFB094.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFB0EA.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFB15C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFB184.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFB1B7.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFB3CC.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFB73F.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFB79C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFB8F5.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFB92F.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFBAF9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFBB75.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFBC4A.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFBC60.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFBC6A.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFBC88.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFBC9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFBC91.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFBC9E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFBEA8.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFBF44.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFBFD9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFC0.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFC3D4.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFC3F9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFC42C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFC823.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFC9BB.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFC9EB.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFC9FC.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFCC66.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFCD01.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFCD70.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFD1FB.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFD270.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFD29.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFD335.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFD68F.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFD7E9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFD818.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFD93A.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFD93B.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFDA93.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFDB64.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFDBDA.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFDBEF.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFDC45.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFDC84.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFDE98.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFDEA9.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFDFB4.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFE124.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFE18E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFE355.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFE54C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFE65E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFE6BA.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFE6BF.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFE6FA.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFE831.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFE911.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFE913.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFEADE.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFEB10.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFEBA7.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFED17.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFEEB7.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFEF71.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFF32B.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFF34.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFF3D2.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFF45C.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFF672.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFF799.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFF969.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFFA1.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFFC0.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFFDC3.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFFE00.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFFE1E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFFE7E.tmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\cs.js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\manifest.json
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\0EY8S956.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\0T9IDCJK.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\0X5FZKXU.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\0Z5OEXIR.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\10K427KV.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\1C5CXF6S.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\241EEXKN.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\2ZAQDUFO.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\5240N414.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\52NVVW1B.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\6OQIMNKP.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\6Q2MBVU0.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\6WI4W10M.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\735QMELW.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\7VDXL81F.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\8K86TTEX.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\8U2F86Z8.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\C9HCF3KJ.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\CBD29A4U.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\CRV3EQTX.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\CVVLTYKZ.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\FUVFX96A.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\H3Q7JI5L.txt
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\index.dat
The process cannot access the file because it is being used by another process.
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\K6AQAWK6.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\KEI21I1C.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\LB5RNRN6.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\LQ2ASOPH.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\M40WIEZ3.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\MDRBVSTB.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\MVWWSY1U.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\PSMP9PJ0.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\T8GHSBPJ.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\UDTE0LIM.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\VU65R15Y.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\VWN1UVBE.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\WPX0BRW7.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\Z6XAR84W.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\bk.js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\cs.js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\manifest.json
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\G\config.ini
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\G\LG_PC_Programs.exe
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\G\P5_LGPsLvDlChk.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\G\Progress.avi
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\G\SendScsiCmd.dll
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\History\History.IE5\index.dat
The process cannot access the file because it is being used by another process.
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\KiesLiveupdateTemp\PluginHost.xml
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\mgyun_driver_32_4\androidwinusb86.cat
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\mgyun_driver_32_4\android_winusb.inf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\mgyun_driver_32_4\i386\WdfCoInstaller01009.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\mgyun_driver_32_4\i386\winusbcoinstaller2.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\mgyun_driver_32_4\i386\WUDFUpdate_01009.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nCommsTempNokia\Nokia Sans Wide Bold v3.1.ttf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nCommsTempNokia\Nokia Sans Wide BolIta v3.1.ttf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nCommsTempNokia\Nokia Sans Wide Italic v3.1.ttf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nCommsTempNokia\Nokia Sans Wide v3.1.ttf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nCommsTempNokia\Nokia Standard Multi Bold v2.1.ttf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nCommsTempNokia\Nokia Standard Multi v2.1.ttf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\NGLATempNokia\Nokia Sans Wide Bold v3.1.ttf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\NGLATempNokia\Nokia Sans Wide BolIta v3.1.ttf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\NGLATempNokia\Nokia Sans Wide Italic v3.1.ttf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\NGLATempNokia\Nokia Sans Wide v3.1.ttf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsw58.tmp\ExecCmd.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsw58.tmp\nsExec.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsw58.tmp\NSISdl.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsw58.tmp\System.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsw58.tmp\UserInfo.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsw58.tmp\XP.mac
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsx5.tmp\NSISdl.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsx5.tmp\System.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsx5.tmp\UserInfo.dll
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\nsx5.tmp\XP.mac
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\aleft_icon.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\CloseButton.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\engineer.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\firmware_phone_fac_icon.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\firmware_phone_icon.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\firmware_popup_backup.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\firmware_popup_reinstall.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\firmware_popup_warning.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\firmware_ready.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\firmware_upgrade_icon.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\phone_01_icon.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\phone_01_icon_dim.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\PNG_FrameBottom.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\PNG_FrameLeft.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\PNG_FrameLeftBottomCorner.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\PNG_FrameRight.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\PNG_FrameRightBottomCorner.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\PNG_icon_kies.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\PNG_Line.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\PNG_Messenger_Body.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\PNG_Messenger_Close.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\PNG_NotiBox_Body.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\popup_border_top_center.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\popup_border_top_left.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\res\Popup_border_top_right.png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Root\autoupdate\config
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Root\autoupdate\vroot_1896286208_cid1000_7ba70783.exe
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat
The process cannot access the file because it is being used by another process.
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\1-1x1[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\28s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\30s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\adchoice_1[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\andronic_1980[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\andronic_1980[2].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\a_081610[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\beaconCAK9NARK.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\beacon[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\beacon[2].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\beacon[3].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\ce17a1bf6968774577417839df26070[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_adCA3B70MT.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_adCA4CCQ40.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_adCA9PIWJL.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_adCAJN2J60.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_adCAK1CPAQ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_ad[10].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_ad[11].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_ad[1].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_ad[2].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_ad[3].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_ad[4].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_ad[5].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_ad[6].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_ad[7].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_ad[8].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\client_ad[9].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\e79bfb3e77c855f1248d138376224d83[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\ebStdBannerEx[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-idCA3S73IL
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-idCA6OJ867
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-idCAQIGRD8
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-idCASBZYQ5
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-id[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-id[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-id[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-id[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-id[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-id[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-id[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-id[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\get-user-id[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\glossyberry[1].css
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\impCA0FCI0Z
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\impCA1S6BU7
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\impCA1Y1Z3R
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\impCA2A2U20
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\impCA2A3X92
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\impCA54JKU4
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\impCAHNQOXF
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\impCAO7C6W8
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\impCARN0ZQV
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\impCAWJ0E9R
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\impCAZKRDK6
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\imp[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\imp[11]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\imp[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\imp[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\imp[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\imp[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\imp[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\imp[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\imp[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\imp[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\imp[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\insider_msg_yahoo_com[10].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\menuarodwn8_dim_1[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\niftybase_2013092518[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1FZV0HI7\nopic_32[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\5f93d6bba8148fbd959030d1584af627[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\8da21aa2-f254-4fc8-90ff-edc67dde169f[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\beacon[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\beacon[2].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\beacon[3].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\beacon[4].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCA02TOJ6.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCA5QU8OH.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCA613L18.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCA7KFQQ2.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCAA7RHTQ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCABOM1C3.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCAFKRADU.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCAFZ89AQ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCAGEK3O0.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCAHFU7MH.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCAL4O64I.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCASAMF3S.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCAT1RYPQ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCAU3T3SN.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCAX14T9F.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCAXHT782.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_adCAXIXWYB.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_ad[10].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_ad[11].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_ad[1].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_ad[2].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_ad[3].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_ad[4].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_ad[5].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_ad[6].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_ad[7].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_ad[8].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\client_ad[9].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\combo[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\edac36896d9e004a172c09f9271e6a77[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\get-user-idCABC5NU3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\get-user-idCAX930IH
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\get-user-id[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\get-user-id[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\get-user-id[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\get-user-id[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\get-user-id[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\get-user-id[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\get-user-id[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\get-user-id[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\get-user-id[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\get-user-id[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\impCA6DUDW3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\impCA9267J8
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\impCADSVU36
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\impCAON1O5C
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\impCAS28D5A
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\imp[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\imp[11]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\imp[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\imp[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\imp[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\imp[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\imp[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\imp[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\imp[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\imp[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\imp[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\insider_msg_yahoo_com[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\insider_msg_yahoo_com[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\newstabs2[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\swfobject[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\yql[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\1MQT52RF\yql[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\1860112a4949b681958bcd6d0745a0a1[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\23_352898CheckPARAM_br1_300x250_rom_yahoo[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\26s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\29_325694MonthlyWager_br1_300x250_rom_yahoo[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\32s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\33s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\34s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\4-300x250-1[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\57411bf0-1178-11e4-b7fb-bb65bb152563_rom-in-finlanda[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\6e8c9294dee1d86c1113115d17985fa8[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\6e8c9294dee1d86c1113115d17985fa8[2].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\772002f0-1bd8-11e4-a1ed-41cb6b598c55_tunelul-iubirii-romania[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\92_326455TradingQuiz_br1_300x250_rom_yahoo[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\adchoice_1[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\andronic_1980[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\andronic_1980[2].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\andronic_1980[3].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\andronic_1980[4].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\andronic_1980[5].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\andronic_1980[6].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\Avion_malaysian_cu_295_de-446875df9818622d3de87aef2b5e6e59[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\b3f1a756d8eb4cc4e796960c674e99c5[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beaconCA0QY5AZ.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beaconCA2NKSI6.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beaconCAF6N2P0.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beaconCAVKNM0X.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beaconCAY9DZKG.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beaconCAZ7C0H4.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beaconCAZWL2XM.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beacon[10].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beacon[11].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beacon[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beacon[2].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beacon[3].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beacon[4].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beacon[5].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beacon[6].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beacon[7].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beacon[8].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\beacon[9].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA0CUZL6.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA11EOKB.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA1H1SHE.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA2A9WP5.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA2U6ZXK.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA2YF7LJ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA3H0DYH.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA4BAOM8.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA4H8NPD.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA4NO0W8.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA5F71J2.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA5I4UAV.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA5L1QXV.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA5SBVOE.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA5W5UK3.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA6J3R9M.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA76YUPG.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA7OLP11.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA8PQKBD.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA92N40Y.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA9AQSW6.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCA9OZ8VE.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCABGG4HX.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCABIKTPD.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCABK8WV7.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAC33AF5.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCACFP0XC.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCACQMVOF.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCADGW9N4.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCADHHOO8.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCADR5WQS.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAEF54E3.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAEHNWMR.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAEQY84N.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAF6CYDV.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAGBUDWI.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAH9BILB.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAHFCRKW.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAIDQBVW.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAK6ZQDV.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAKM9BHQ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAKVNCL2.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAKX3ZF3.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAL2CDUN.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAL685GQ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAL8JPKO.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCALO0C9S.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAM2BY3U.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAMJ9BQE.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAN79TGW.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAO98U8M.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAP304TR.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAQN94AU.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAQTCDM1.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAR6UCCP.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCARR5144.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAS6WIVT.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCATQ218K.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAUH4L3Q.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAUUH871.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAW48MZF.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAWCATEA.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAWDBC9Q.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAX8BSO5.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_adCAYMF9SS.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_ad[10].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_ad[11].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_ad[1].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_ad[2].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_ad[3].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_ad[4].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_ad[5].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_ad[6].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_ad[7].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_ad[8].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\client_ad[9].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\combo[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\combo[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\d4fb6bb0-06bd-11e4-84e4-7bad2e2e2d6d_litoral-ucraina[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\d7466f60-0aea-11e4-b8ca-355fda9239b4_gotze[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\e7d9027a1a9dcdcc014ac56afa8795a1[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\EXCLUSIV_VIDEO_Fata_din_Suceava-ffef7d854dc3ca5af859c17c2b20b39c[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\f02181ea9963a14637f04fbb695c4e19[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\fed8fcc0-0840-11e4-bf1d-27ce0a14fde2_Longyearbyen4[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\f[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\f[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\f[3].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\gaarf-tools[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCA1ZZJ45
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCA25WTKW
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCA2PFIPU
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCA76ISTN
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCA97GDPC
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCA9M24QT
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCA9W5W5K
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAAIYK05
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAAVFWGX
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAD5AQMM
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAD9NCLS
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAEP1AKC
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAGI67B3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAJ1AJIK
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAM8FDTK
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAMK50GT
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAOTXXEV
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAOYYTV0
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAP3UUQL
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCARM18JC
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAS2XCWX
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-idCAY9WEUF
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-id[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-id[11]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-id[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-id[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-id[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-id[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-id[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-id[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-id[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-id[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\get-user-id[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA08A68L
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA08OS0X
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA2N5QAB
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA2WSAL8
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA4EN76J
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA4MMMW4
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA4Y7BHR
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA52AM92
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA7IQ9DQ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA7TQOE7
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA8T01P2
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA8Z3LFV
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA91M2HV
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA9N6232
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCA9W0BLA
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAAS0O8H
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAC3CA0G
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCACG0I50
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAF59WZW
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAKT4PJF
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAN33EZ8
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAP9EWFF
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAQBPHCW
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAQLSC1O
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAR08YL4
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCARZSEBW
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCASHX2GI
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCASZGL99
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCATI5GXB
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAUAQKIA
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAULTG1Y
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAV34B2I
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAVHKO7Y
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAVLPUNF
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAVZ7ZY0
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAW1MYXC
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAW44CLE
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAYFN07D
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAYUS7HI
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAYY4Z9R
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAZJE9EB
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\impCAZM7L0H
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\imp[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\imp[11]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\imp[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\imp[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\imp[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\imp[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\imp[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\imp[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\imp[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\imp[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\imp[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\insider_msg_yahoo_com[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\insider_msg_yahoo_com[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\insider_msg_yahoo_com[3].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\insider_msg_yahoo_com[4].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\insider_msg_yahoo_com[6].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\menuarodwn8_dim_1[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\Pe_calea_ferat___cu_160-da72b4bdcbf4566f9b85d425935d3dba[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\DB1HL3DF\st[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\12s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\29s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\43091390-13ee-11e4-8bfd-bbaf027bfa5d_richis-case-6[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\6e8c9294dee1d86c1113115d17985fa8[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\6e8c9294dee1d86c1113115d17985fa8[2].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\6e8c9294dee1d86c1113115d17985fa8[3].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\6e8c9294dee1d86c1113115d17985fa8[4].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\6e8c9294dee1d86c1113115d17985fa8[5].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\6e8c9294dee1d86c1113115d17985fa8[6].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\6e8c9294dee1d86c1113115d17985fa8[7].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\75_339517ForexCorner25_br1_300x250_rom_yahoo[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\78817420-04e1-11e4-be2a-931320e464ea_output_WqRCfJ[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\79_325694MonthlyWager_br1_300x250_rom_yahoo[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\83944059-1583-485b-aea9-8a29162f0308[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\8ebf045db1495a62ab0f48da96d76fba[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\af26ff6e2f5fc9978e1ce38c4348bd75[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\andronic_1980[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\andronic_1980[2].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\andronic_1980[3].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\andronic_1980[4].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\andronic_1980[5].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\andronic_1980[6].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\andronic_1980[7].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\andronic_1980[8].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\andronic_1980[9].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\anim_loading_sm_082208[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beaconCA2NLKIG.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beaconCA491XNT.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beaconCAH7Z2Q1.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beaconCAUQBQBC.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beacon[10].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beacon[11].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beacon[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beacon[2].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beacon[3].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beacon[4].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beacon[5].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beacon[6].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beacon[7].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beacon[8].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\beacon[9].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\cd997920-1356-11e4-b02d-19948352e035_151107502[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\clientad_rotator_090324[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA07G5RB.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA0Y3T22.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA1OUH1U.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA1ZYAYJ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA2QOABW.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA3FOU0N.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA3XLBXR.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA55RPLS.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA5M332X.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA5W6AKJ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA6DTAFW.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA77OLUH.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA8FKYD1.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA8K8877.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCA9OR4JU.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAATU13S.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAB806C3.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCABCZGHD.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCACHNOTS.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCACJ2WJL.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCADQ8LYU.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAEKQAG3.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAFBO69M.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAG2X2OH.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAG4H7ON.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAG4SHIW.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAGPJ5NX.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAHHKH4L.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAHY6WJE.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAK7W979.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCANJ2ACB.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCANL5PVB.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCANOX5HK.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCANPRKXV.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAT2A5E4.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAULB4PW.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAVICIAD.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAWAX89V.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAXCJ3KA.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAXPT6QB.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAXZGOAS.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAYGZHVU.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAYH3SZG.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_adCAZOGDJV.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_ad[10].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_ad[11].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_ad[1].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_ad[2].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_ad[3].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_ad[4].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_ad[5].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_ad[6].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_ad[7].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_ad[8].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\client_ad[9].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\d8850a20-0cbc-11e4-b3c2-799060b5f1f6_cet5-rockedro[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\flashwrite_1_2[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA07VYAM
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA09DQON
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA0L237L
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA1LCSSL
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA1NILIF
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA2BL8HY
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA2WWFIM
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA356V3W
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA3V0C7Y
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA4AE31Q
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA4FLNLR
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA5B267N
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA5OH59T
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA7H5NLN
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA7RYNRR
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA86CB12
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCA9OC6ZD
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCADWAZTX
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAE1B5IO
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAE7WF96
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAEID7FD
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAG41I6H
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAGUN1IX
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAHMDRQ4
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAHOSRNU
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAIE27ZP
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAJCXK0D
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAKQNPZY
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAKSZ5PA
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCALFHYR0
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAMIQSGS
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAMYB8U7
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAOYUW6G
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAPRKIYL
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAQDJILK
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAQJCCUM
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCARMH9CK
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCARQD1X5
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCASYNHT3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAUCI0FF
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAVZW29B
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAW28I7Q
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAWRNI0F
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAWVYU03
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAYVC9I2
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-idCAYXJSYL
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-id[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-id[11]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-id[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-id[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-id[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-id[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-id[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-id[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-id[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-id[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\get-user-id[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\glossyberry[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCA08DYAW
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCA0BR92K
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCA3M7O8X
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCA50AJB5
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCA6WB556
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCA6ZW8K3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCA7O7C1O
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCA8MG7WY
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAA0H131
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAAV4176
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAAWGXJU
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAB6E1RB
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCABLZP7Q
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCADB4IG2
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCADWDN3I
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAFE6ET5
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAFOAUZI
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAFZ7RWV
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAGAWUP3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAIERFM4
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAIO8O8L
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAJ75IOT
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAJZP9J7
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAK2V85R
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAKTL3P2
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAKXV9JD
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCANG2WAO
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAPR7NRQ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAPRLEEL
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAQ322A6
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAQICUH5
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAQIY6YO
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAQZR318
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCARN81OA
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAS9NXW5
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCATEHP0I
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAXZ8FWV
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAYAKBJK
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAYSYOJ6
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAZAUEAB
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\impCAZZZ5JW
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\imp[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\imp[11]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\imp[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\imp[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\imp[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\imp[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\imp[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\imp[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\imp[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\imp[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\imp[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\insider_msg_yahoo_com[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\insider_msg_yahoo_com[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\insider_msg_yahoo_com[3].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\insider_msg_yahoo_com[4].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\insider_msg_yahoo_com[5].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\notification[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\smiley_16px[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\st[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\st[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\st[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\user-match[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\user-match[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\user-match[3].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\vitality[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\yahoo_frontpage_ro-RO_s_f_w_bestfit_frontpage[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\NJXKKXGX\yql[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\01_326453TradingQuiz_br1_300x250_rom_yahoo[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\042a7b90-0c1f-11e4-88a8-bdfa50b74c88_casap6-main[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\04ec8a00-170a-11e4-9872-35992cf4a54c_187442341[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\0995f3f0-090b-11e4-9a6a-9517bb8fcab0_david7[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\1790fa40-03a2-11e4-9f73-b9b349a5ba97_c1-colibita-paul-gabriel-pasztor-Flickr-w[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\1dcad16edbf68736fd6b518d1bbc4d94[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\1dcad16edbf68736fd6b518d1bbc4d94[2].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\2-130327_kcoRO_300x250_V01_mn[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\253cbfb0-01c9-11e4-b143-6f7cfbea20ba_457025749[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\27s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\31s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\6e8c9294dee1d86c1113115d17985fa8[10].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\6e8c9294dee1d86c1113115d17985fa8[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\6e8c9294dee1d86c1113115d17985fa8[2].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\6e8c9294dee1d86c1113115d17985fa8[3].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\6e8c9294dee1d86c1113115d17985fa8[4].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\6e8c9294dee1d86c1113115d17985fa8[5].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\6e8c9294dee1d86c1113115d17985fa8[6].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\6e8c9294dee1d86c1113115d17985fa8[7].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\6e8c9294dee1d86c1113115d17985fa8[8].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\6e8c9294dee1d86c1113115d17985fa8[9].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\andronic_1980[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\andronic_1980[2].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\andronic_1980[3].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\andronic_1980[4].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\andronic_1980[5].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\andronic_1980[6].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\b3f1a756d8eb4cc4e796960c674e99c5[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beaconCA5U6PW1.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beaconCA88X9OS.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beacon[10].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beacon[11].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beacon[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beacon[2].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beacon[3].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beacon[4].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beacon[5].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beacon[6].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beacon[7].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beacon[8].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\beacon[9].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\carousel_091007[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA08ONJ4.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA0BQZAN.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA0MFJK1.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA12GPRT.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA2DAKN3.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA3BIWK0.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA40SF8K.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA64SF07.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA6R3T58.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA6Z2MZE.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA8M8OFI.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA98IW1N.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCA99KLPR.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAAMX65M.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAAXYCPB.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCABDCFGP.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCABU1NYK.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCABW2GYS.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCADXE95L.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAE66PVX.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAF0EZL9.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAG5JAOI.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAGC5QWR.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAGTOII3.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAI86KRM.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAJX1GXF.php
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAKDNPTW.php
The process cannot access the file because it is being used by another process.
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAKEGZI8.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAKKSW08.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAKZXCUM.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAMJN0MX.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAN32ZF4.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAO98LLX.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAP7W477.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCARTRLTS.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCATD10FU.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCATEH4T3.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCATQURBE.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAVDVUW0.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAX9GUZQ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAYKTN5M.php
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAYWJSHA.php
The process cannot access the file because it is being used by another process.
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAZ21GD0.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAZ8JJ87.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_adCAZF6Y1Y.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_ad[10].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_ad[11].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_ad[1].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_ad[2].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_ad[3].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_ad[4].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_ad[5].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_ad[6].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_ad[7].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_ad[8].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\client_ad[9].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\combo[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\e79bfb3e77c855f1248d138376224d83[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\fdddaaa90f0511c9c99b5e09510e2afc[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\f[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\f[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA0575CX
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA0TNESE
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA2EPP37
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA2XHTPE
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA3JDFW8
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA5R4N6B
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA5ZZ4BU
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA6SZH68
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA6VHYNU
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA7F1ZOJ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA8JZ3TY
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA8P19NZ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCA9EODB3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCABECDJH
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCACXZDFM
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAD3AKD7
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAEK42T3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAER7JSS
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAF113KQ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAGANJ8F
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAGBKY4F
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAH515YT
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAHIZ2P6
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAJ4QU3H
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAMZTEUQ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCANV6DT4
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAOB7D08
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAOLA3NW
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCARLBS3H
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCASD8RSX
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAT1TMKL
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAT2XF8P
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAT7B51O
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAVW421K
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAX5MEEC
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAYL2HS8
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAYLGMXQ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-idCAZOGR41
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-id[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-id[11]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-id[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-id[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-id[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-id[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-id[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-id[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-id[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-id[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\get-user-id[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\glossyberry[1].css
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCA05DP3S
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCA10CW1N
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCA1F1VGD
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCA1TNER2
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCA26OV36
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCA2KQT1L
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCA3TFHN8
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCA44I329
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCA4YXYH3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCA8OITHW
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCA9VKY5L
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAAF3V0I
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCABKN1S6
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAC0FKVQ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCACJ0SQ7
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAD1KM4D
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCADY692H
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAFCLVAM
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAG8O4SS
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAI9B364
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAKHFMH7
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAO0TXGZ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAOG3DL9
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAOIMSVT
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAPM5089
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCARLGKDB
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCARPLD3T
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAS2ZOG6
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAS867EA
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCASMM3IE
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCASTD4GD
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAT0MCW4
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCATGGHHK
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAUHQB2R
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAUT1DQM
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAW5ZHF7
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAXP6WGP
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAZ1BO0Q
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\impCAZAED15
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\imp[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\imp[11]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\imp[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\imp[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\imp[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\imp[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\imp[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\imp[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\imp[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\imp[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\imp[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\insider_msg_yahoo_com[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\insider_msg_yahoo_com[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\insider_msg_yahoo_com[3].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\insider_msg_yahoo_com[4].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\insider_msg_yahoo_com[5].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\insider_msg_yahoo_com[6].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\insider_msg_yahoo_com[7].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\insider_msg_yahoo_com[8].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\insider_msg_yahoo_com[9].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\niftybase_2013090315[1].css
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\nopic_32[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\notification[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\Orfanii_care__i-au__nvins_destinul-da714833ef145eb4158ce9f2784c92a7[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\st[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\st[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\user-match[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\user-match[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\user-match[3].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\user-match[4].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\user-match[5].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OJW38YT6\yahoo-dom-event[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\24s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\32s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\34s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\39s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\3aa556f0-fde1-11e3-8043-0367e363bd23_178249622[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\54a2a175-78a9-4263-bdff-137702a3608c[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\70a9a814477254d3027c8c924525a54f[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\adb80a30-fcfa-11e3-848b-7f9d2cc3dc99_casa-la-marginea-orasului[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\andronic_1980[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\andronic_1980[2].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\anim_loading_sm_082208[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\b082bd63-6029-47c7-bf45-84ca518156b2[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\beaconCA2SN40X.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\beaconCAZDGDG8.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\beacon[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\beacon[2].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\beacon[3].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\beacon[4].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\carousel_091007[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_adCA19ETMZ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_adCA6RUO9S.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_adCAL5TFGC.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_adCAPZP7V6.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_adCAX6L03X.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_ad[10].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_ad[1].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_ad[2].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_ad[3].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_ad[4].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_ad[5].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_ad[6].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_ad[7].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_ad[8].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\client_ad[9].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\e7d9027a1a9dcdcc014ac56afa8795a1[2].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\gaarf-tools[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCA36M3WM
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCAD4S8Q7
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCAEXMKT2
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCAF652S8
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCAHX9YD5
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCAISLP48
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCAK0ECYK
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCAN382KH
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCANL1RR3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCAOQFH75
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCAPSS4RO
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCAQH1ZXA
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCATWNBBS
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-idCAXZ0DJ6
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-id[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-id[11]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-id[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-id[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-id[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-id[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-id[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-id[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-id[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-id[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\get-user-id[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\gr10-swfo22_201105121000[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\impCA0WU726
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\imp[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\imp[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\imp[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\imp[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\imp[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\imp[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\imp[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\imp[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\imp[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\insider_msg_yahoo_com[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\insider_msg_yahoo_com[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\niftybase_2013090315[1].css
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\PNL__i_PDL_sus_in__mpreun_-55009daa9e4932294b705355d24d16fc[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\smiley_16px[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\st[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\V25VWNGW\ylc_1.9[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\03_339517ForexCorner25_br1_300x250_rom_yahoo[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\28s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\30s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\37c4c000-0b39-11e4-bca5-7f4f59517739_Clipboard01[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\37_325694MonthlyWager_br1_300x250_rom_yahoo[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\38eaa920-154f-11e4-95dd-b1a138952248_paine[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\38s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\39s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\3f155a10-1631-11e4-9b79-3f7672e25167_ciuperci[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\42152900-073d-11e4-8f75-0f836b6d354a_96493165[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\55_325694MonthlyWager_br1_300x250_rom_yahoo[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\6e8c9294dee1d86c1113115d17985fa8[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\6e8c9294dee1d86c1113115d17985fa8[2].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\6e8c9294dee1d86c1113115d17985fa8[3].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\6e8c9294dee1d86c1113115d17985fa8[4].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\6e8c9294dee1d86c1113115d17985fa8[5].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\7233a9164a0331f7b0d287ef60b14cc3[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\75_339517ForexCorner25_br1_300x250_rom_yahoo[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\79_325694MonthlyWager_br1_300x250_rom_yahoo[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\andronic_1980[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\andronic_1980[2].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\andronic_1980[3].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\andronic_1980[4].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\andronic_1980[5].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\andronic_1980[6].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\andronic_1980[7].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beaconCA78LFU2.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beaconCAG9LLKB.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beaconCAGFU2L5.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beaconCAJU9L3W.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beaconCAVF10QX.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beaconCAXKCIOU.gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beacon[10].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beacon[11].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beacon[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beacon[2].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beacon[3].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beacon[4].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beacon[5].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beacon[6].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beacon[7].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beacon[8].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\beacon[9].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCA1XINK1.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCA29NZJN.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCA2YN4JH.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCA54CCTA.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCA5ZK275.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCA63KWTD.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCA67L94J.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCA6R6Q5B.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCA7T39A1.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCA8GGH0Z.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCA8LAQYA.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAA6BV0Y.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAAP8QXU.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCABM6PFY.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCABQ5N4S.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAC07SM1.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCACSACI0.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCADMZHPA.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCADR40ZD.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAE27H6F.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAEEQDI8.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAETS5T5.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAF1ZJEK.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAFF77AX.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAFGDQ2T.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAFKAYVS.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAG7ILUE.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAGYQTLZ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAHF0DUT.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAHNLEXP.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAHP5VOP.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAI4YWK0.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAIPHWJG.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAJ2RW8J.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAJDWARP.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAKZ3MIE.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAMISB4S.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAOJDARA.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAOWFXK9.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCASBN41R.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCASLWHHE.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCASZRVIY.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAT83N6N.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAUT0OWQ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAV2ZM7P.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAVMN4BN.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAVSL20R.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAX5GI3I.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAXVB08J.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAYQ4J97.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAZ7GCFE.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_adCAZNXOUW.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_ad[10].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_ad[11].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_ad[1].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_ad[2].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_ad[3].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_ad[4].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_ad[5].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_ad[6].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_ad[7].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_ad[8].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\client_ad[9].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\Delta_Dun_rii_i-a_cucerit_pe-23b99f2aaf05c1baec088653393827d2[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\eb809550-0ef0-11e4-9c42-cbf5f3e0dfd0_bazin-olimpic[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\ebStdBannerEx[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\ebStdBannerEx[2].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\f[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA0K2WTS
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA0N6GFU
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA0YGY53
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA18WYD0
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA19F7QT
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA2JOD7X
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA39VG2U
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA3ZP9KY
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA7DNQY1
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA7OOBAB
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA7Q7IL6
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA92UK2V
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCA9EFYM5
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAAJU84M
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAAKCT3L
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAAQQAEF
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAC9ZBP5
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAE1SWL4
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAEWGVB7
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAFZFT7X
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAGLFFCN
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAHQEF88
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAIS9ID3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAJGSNMJ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAK41KLD
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAKW0DY6
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCALEC2XN
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCALENXO3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCALZBXF9
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCANH4UH8
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCANJJ4HO
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAOEOL58
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAOYP2ER
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAPL2BI7
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAQQ7CTQ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCARWZD51
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCATBSDXU
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCATYZJN2
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAUD6W4L
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAUQJIQD
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAVEWH9X
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAW024X4
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAW04S7V
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAW13XM7
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAW9E2GK
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAY8UXQJ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-idCAZ0B9M3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-id[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-id[11]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-id[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-id[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-id[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-id[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-id[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-id[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-id[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-id[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\get-user-id[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\gr10-swfo22_201105121000[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\hlp12_1[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCA2VIBOZ
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCA32NJCI
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCA6GF3O8
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCA6IH08A
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCA6M1W72
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCA7HJV7P
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCA7JQKVI
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCA98X90U
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCACE7BUR
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCADI1NRB
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCAF0MYGU
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCAFLRUO8
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCAIT8DEX
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCAJ3X0XW
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCAKDY4VX
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCAOAWL3A
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCAOCNHO6
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCAPQOGF3
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCAQML7K5
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCAULDVH5
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\impCAVDKI43
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\imp[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\imp[11]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\imp[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\imp[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\imp[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\imp[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\imp[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\imp[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\imp[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\imp[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\imp[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\insider_msg_yahoo_com[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\insider_msg_yahoo_com[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\insider_msg_yahoo_com[3].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\insider_msg_yahoo_com[4].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\insider_msg_yahoo_com[5].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\insider_msg_yahoo_com[6].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\insider_msg_yahoo_com[7].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\insider_msg_yahoo_com[8].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\mentarozmarinlamai[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\newstabs2[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\niftybase_2013092518[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\r[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\st[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\user-match[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\user-match[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\user-match[3].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\user-match[4].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\user-match[5].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\user-match[6].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\vitality[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\YP0LSI8B\ylc_1.9[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\11s[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\29ddc340-ff51-11e3-996d-874724bee77b_castel[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\32c465a0-0090-11e4-b322-3164d872c850_890493-001[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\3707c09a6c1588cdb6372325518bcbcb[1].swf
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\andronic_1980[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\andronic_1980[9].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\beacon[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\beacon[2].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\beacon[9].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\c4459da0-005e-11e4-b16c-9325cc2391e9_centru-SPA-turda[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\clientad_rotator_090324[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\clientad_rotator_090324[2].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCA2P7K9M.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCA3MQU32.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCA5WN2JI.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCA6I8XRG.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCA6V01E1.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCA7NHKYN.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCA7QDRZL.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCA7XJNY6.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCA9KAU1N.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCAFO65EJ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCAHC5FBZ.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCAIGRKP9.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCAM4HMN4.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCAW7IV31.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCAWHL1T5.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_adCAXIXE33.php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_ad[10].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_ad[11].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_ad[1].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_ad[2].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_ad[3].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_ad[4].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_ad[5].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_ad[6].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_ad[7].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_ad[8].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\client_ad[9].php
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\combo[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\combo[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\e7d9027a1a9dcdcc014ac56afa8795a1[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\get-user-idCAE75764
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\get-user-id[10]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\get-user-id[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\get-user-id[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\get-user-id[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\get-user-id[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\get-user-id[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\get-user-id[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\get-user-id[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\get-user-id[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\get-user-id[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\glossyberry[1].png
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\hlp12_1[1].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\impCA2OTQJG
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\impCATJ1K4U
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\imp[1]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\imp[2]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\imp[3]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\imp[4]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\imp[5]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\imp[6]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\imp[7]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\imp[8]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\imp[9]
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\insider_msg_yahoo_com[1].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\insider_msg_yahoo_com[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\notification[1].jpg
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\vitality[2].txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\yahoo-dom-event[1].js
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\ZMD37VOC\yahoo_frontpage_ro-RO_s_f_w_bestfit_frontpage[2].gif
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\WERce22.dir00\appcompat.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\WERce22.dir00\manifest.txt
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\WERce22.dir00\SPT.exe.hdmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\WERce22.dir00\SPT.exe.mdmp
Deleted file - C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\{D5878294-C113-43c5-A24F-FC333C52015A}\D5878294-C113-43c5-A24F-FC333C52015A.xml
 
========= End of CMD: =========
 
 
=========  RD /S /Q %TEMP% =========
 
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\adb.log - The process cannot access the file because it is being used by another process.
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Cookies\index.dat - The process cannot access the file because it is being used by another process.
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\etilqs_PEoOh4eQmoiQWtU - The process cannot access the file because it is being used by another process.
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\History\History.IE5\index.dat - The process cannot access the file because it is being used by another process.
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\History\History.IE5\MSHIST~3\index.dat - The process cannot access the file because it is being used by another process.
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\Perflib_Perfdata_2d0.dat - The process cannot access the file because it is being used by another process.
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\TEMPOR~1\Content.IE5\index.dat - The process cannot access the file because it is being used by another process.
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\TEMPOR~1\Content.IE5\OJW38YT6\client_adCAKDNPTW.php - The process cannot access the file because it is being used by another process.
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\TEMPOR~1\Content.IE5\OJW38YT6\client_adCAYWJSHA.php - The process cannot access the file because it is being used by another process.
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\WCESLog.log - The process cannot access the file because it is being used by another process.
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF2C96.tmp - The process cannot access the file because it is being used by another process.
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DF48BB.tmp - The process cannot access the file because it is being used by another process.
C:\DOCUME~1\RADUMA~1\LOCALS~1\Temp\~DFA42B.tmp - The process cannot access the file because it is being used by another process.
 
========= End of CMD: =========
 
 
 
The system needed a reboot. 
 
==== End of Fixlog ====

  • 0

#12
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts

The first log finished from the 3rd pc that got infected yesterday 

 

copy1.exe c:\users\radu\appdata\roaming\‎ 8/5/2014 12:08:28 AM PDM:Trojan.Win32.Bazon.a
eb4b40a5d7e90fb7bb1aadd5beab440b.exe c:\Users\Radu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\‎ 8/5/2014 12:10:28 AM Trojan.MSIL.Zapchast.cyok

  • 0

#13
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts

LOg from 2nd computer is over :

 

Deleted A0126424.exe D:\System Volume Information\_restore{05D2C16F-7B40-4D0E-B78C-A9B83C8035B7}\RP638\? 8/5/2014 1:41:06 PM UDS:DangerousObject.Multi.Generic
Deleted A0126426.exe D:\System Volume Information\_restore{05D2C16F-7B40-4D0E-B78C-A9B83C8035B7}\RP638\? 8/5/2014 1:41:05 PM UDS:DangerousObject.Multi.Generic
Deleted A0126425.exe D:\System Volume Information\_restore{05D2C16F-7B40-4D0E-B78C-A9B83C8035B7}\RP638\? 8/5/2014 1:40:59 PM UDS:DangerousObject.Multi.Generic
Deleted setool2g.exe D:\Boxuri Originale\Setool Box\Installer\v0.915036\v0.915036.rar//? 8/5/2014 1:32:24 PM Virus.Win32.Induc.b
Disinfected v0.915036.rar D:\Boxuri Originale\Setool Box\Installer\v0.915036\? 8/5/2014 1:32:24 PM v0.915036.rar
Disinfected v0.915016.rar D:\Boxuri Originale\Setool Box\Installer\v0.915016\? 8/5/2014 1:31:26 PM v0.915016.rar
Deleted setool2g.exe D:\Boxuri Originale\Setool Box\Installer\v0.915016\v0.915016.rar//? 8/5/2014 1:31:26 PM Trojan.Win32.Midgare.atac
Deleted data0312 D:\Boxuri Originale\Lgtool Box\Installer\lgetool_236.exe//? 8/5/2014 12:38:17 PM Trojan-Downloader.Win32.VB.hflj
Deleted lgetool_236.exe D:\Boxuri Originale\Lgtool Box\Installer\? 8/5/2014 12:38:17 PM lgetool_236.exe
Deleted data0277 D:\Boxuri Originale\Lgtool Box\Installer\lgetool_222.exe//? 8/5/2014 12:38:01 PM Trojan-Downloader.Win32.VB.hbyk
Deleted lgetool_222.exe D:\Boxuri Originale\Lgtool Box\Installer\? 8/5/2014 12:38:01 PM lgetool_222.exe
Deleted DriverSetup.exe D:\Boxuri Originale\Furious Box\Installer\Pack 7\usb_driver_U8810-U8815-Y300\? 8/5/2014 12:37:33 PM UDS:DangerousObject.Multi.Generic
Deleted OTZFlasher.exe D:\Boxuri Originale\Furious Box\Installer\Pack 6\OTZFlasher_v1.0.0.1395\? 8/5/2014 12:37:15 PM HEUR:Trojan.Win32.Generic
Deleted DriverSetup.exe D:\Boxuri Originale\Furious Box\Installer\Pack 7\Huawei_usb_driver_2.0.6.601\? 8/5/2014 12:37:14 PM UDS:DangerousObject.Multi.Generic
Deleted OTZFlasher.exe D:\Boxuri Originale\Furious Box\Installer\Pack 6\OTZFlasher_v1.0.0.1395.rar//? 8/5/2014 12:36:54 PM HEUR:Trojan.Win32.Generic
Disinfected OTZFlasher_v1.0.0.1395.rar D:\Boxuri Originale\Furious Box\Installer\Pack 6\? 8/5/2014 12:36:54 PM OTZFlasher_v1.0.0.1395.rar
Deleted DriverSetup.exe D:\Boxuri Originale\Furious Box\Drivers\Huawei\usb_driver_U8810-U8815\? 8/5/2014 12:33:06 PM UDS:DangerousObject.Multi.Generic
Deleted sgtool.exe c:\Program Files\SgTool\? 8/5/2014 12:09:05 PM Trojan-Downloader.Win32.VB.hflj
Deleted Compal_Tool_v12.exe C:\Documents and Settings\Radu\My Documents\Downloads\USB_SMART_FULL_free-gsm-unlock.com\USB-SMART-FULLY-CRACKED\Motorola\Compal_Tool\Compal Tool\? 8/5/2014 11:48:58 AM UDS:DangerousObject.Multi.Generic
Deleted AutoRun.exe C:\IM2 TEMP\? 8/5/2014 11:48:56 AM Trojan.Win32.Cosmu.bgba
Deleted Alcatel.exe C:\Documents and Settings\Radu\My Documents\Downloads\USB_SMART_FULL_free-gsm-unlock.com\USB-SMART-FULLY-CRACKED\Alcatel\? 8/5/2014 11:48:32 AM Trojan-Downloader.Win32.Agent.fhae
Detected; not processed samsung_too.exe C:\Documents and Settings\Radu\My Documents\Downloads\USB_SMART_FULL_free-gsm-unlock.com.rar//USB-SMART-FULLY-CRACKED\USB SMART - SAMSUNG FREE\USB SMART - SAMSUNG FREE.part1.rar//? 8/5/2014 11:47:38 AM Packed.Win32.CryptExe.gen
Deleted Alcatel.exe C:\Documents and Settings\Radu\My Documents\Downloads\USB_SMART_FULL_free-gsm-unlock.com.rar//USB-SMART-FULLY-CRACKED\Alcatel\? 8/5/2014 11:47:24 AM Trojan-Downloader.Win32.Agent.fhae
Deleted 00000000 C:\Documents and Settings\Radu\Local Settings\Application Data\Google\Chrome\User Data\Default\File System\001\t\00\? 8/5/2014 11:20:41 AM 00000000
Deleted data0005 C:\Documents and Settings\Radu\Local Settings\Application Data\Google\Chrome\User Data\Default\File System\001\t\00\00000000//? 8/5/2014 11:20:41 AM Trojan.Win32.AntiFW.a

  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK for each system now could I have an FRST log

Please label each one with a unique name/number

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Select additions at the bottom
  • Press Scan button.
    frst.JPG
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please attach both logs generated.

  • 0

#15
Andreib18

Andreib18

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 100 posts

Frst on 2nd pc ...the first one is at 80 from morning

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:2-08-2014
Ran by Radu (administrator) on RADU-CEL-FRUMOS on 05-08-2014 16:36:27
Running from C:\Documents and Settings\Radu\My Documents\Downloads
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(VIA Technologies, Inc.) C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
() C:\Program Files\MD Touch Mini\MD Touch MiniUIExec.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(BlackBerry Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
(Microsoft Corporation) C:\Program Files\Microsoft ActiveSync\wcescomm.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
(Microsoft Corporation) C:\PROGRA~1\MI3AA1~1\rapimgr.exe
(Sony) C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe
(Nokia) C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
(MyCity) C:\Program Files\MCShield\MCShieldRTM.exe
() C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Infowatch) C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
(Teruten) C:\WINDOWS\system32\FsUsbExService.Exe
() C:\Program Files\MD Touch Mini\MD Touch MiniAssistantServices.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Mobile Leader Co.,Ltd.) C:\WINDOWS\system32\ScsiCommandService2.exe
() C:\Program Files\Tftpd32_SE\tftpd32_svc.exe
(Microsoft Corporation) C:\Program Files\Zune\ZuneBusEnum.exe
(BlackBerry Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
Winlogon\Notify\klogon: C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
HKU\.DEFAULT\...\Run: [H/PC Connection Agent] => C:\Program Files\Microsoft ActiveSync\wcescomm.exe [1289000 2006-11-13] (Microsoft Corporation)
HKU\.DEFAULT\...\Run: [DWQueuedReporting] => C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [434080 2011-07-27] (Microsoft Corporation)
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\Run: [Messenger (Yahoo!)] => C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [5252408 2010-06-01] (Yahoo! Inc.)
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\Run: [KiesAirMessage] => C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\Run: [H/PC Connection Agent] => C:\Program Files\Microsoft ActiveSync\wcescomm.exe [1289000 2006-11-13] (Microsoft Corporation)
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\Run: [AutoStartNPSAgent] => C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [95576 2010-07-04] (Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\Run: [Sony PC Companion] => C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [466656 2014-05-23] (Sony)
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\Run: [PC Suite Tray] => C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\Run: [MCShield Monitor] => C:\Program Files\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {0529434f-a056-11e3-a219-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {06f9131c-be48-11e3-a24e-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {06f91322-be48-11e3-a24e-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {0aaa7a9b-2f47-11e3-a159-002354d040e6} - F:\VFPcAssistant.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {10362dac-2f4e-11e3-a15a-002354d040e6} - F:\VFPcAssistant.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {14369999-9d26-11e3-a214-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {18130e8d-dd9f-11e3-a273-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {18130e94-dd9f-11e3-a273-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {1bc6958a-fd1d-11e3-a2a2-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {1bc6958d-fd1d-11e3-a2a2-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {25d96a92-f074-11e3-a28d-002354d040e6} - F:\LGAutoRun.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {25f6400d-d5b6-11e3-a269-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {25f64013-d5b6-11e3-a269-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {263e4c9c-b0cd-11e2-a8fa-002354d040e6} - F:\Autorun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2066.1.9B05 PID_0083
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {26acd2cb-7cf6-11e3-a1e7-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {2a4c9a8b-074b-11e4-a2b1-002354d040e6} - F:\Startme.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {2dd273d3-84f0-11e3-a1f6-002354d040e6} - F:\QsSetup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {2dd273d6-84f0-11e3-a1f6-002354d040e6} - F:\QsSetup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {3a20b230-00ec-11e3-a10a-002354d040e6} - F:\Setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {40459c15-02cd-11e4-a2ab-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {428321ae-715f-11e3-a1d4-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {445af57c-8336-11e3-a1ef-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {4663c148-9a10-11e3-a211-002354d040e6} - F:\LGAutoRun.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {4d8eebe9-8286-11e3-a1ee-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {567d0dd1-e574-11e3-a27c-002354d040e6} - F:\AutoRun.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {567d0dd2-e574-11e3-a27c-002354d040e6} - F:\AutoRun.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {68e79dd1-694c-11e3-a1c7-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {77ebdcf4-8352-11e3-a1f0-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {82ccf554-7863-11e3-a1e0-002354d040e6} - H:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {82ccf55d-7863-11e3-a1e0-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {8741c7ae-4929-11e3-a186-002354d040e6} - F:\AutoRun.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {8e042e2b-76d3-11e3-a1d5-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {998b64ca-bfcb-11e3-a250-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {998b64cd-bfcb-11e3-a250-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {a05a1eb3-a2a4-11e3-a21b-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {a0bea1fe-b8b4-11e3-a249-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {a0bea204-b8b4-11e3-a249-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {a1d0b56c-d754-11e3-a26b-002354d040e6} - F:\Startme.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {a6b66b12-c39e-11e3-a254-002354d040e6} - F:\LGAutoRun.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {b1a070fd-d4f4-11e3-a268-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {b1a07103-d4f4-11e3-a268-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {b2228462-0bed-11e4-a2bc-002354d040e6} - F:\LGAutoRun.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {b7136560-2688-11e3-a14b-002354d040e6} - F:\seamlessKeyLauncher.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {b8f9c410-027e-11e4-a2aa-002354d040e6} - F:\LGAutoRun.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {b987226c-abff-11e2-a8f3-002354d040e6} - F:\XTC-Clip_PLUS.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {ba354a48-f87a-11e3-a29c-002354d040e6} - F:\Startme.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {bedc8f3e-1ea3-11e3-a13a-002354d040e6} - F:\LGAutoRun.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {e9a6bdb4-93b8-11e3-a209-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {ee519d18-b330-11e3-a23c-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {ee519d1e-b330-11e3-a23c-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {ee9619b0-d43c-11e3-a265-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {ee9619b6-d43c-11e3-a265-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {ee9619bc-d43c-11e3-a265-002354d040e6} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {eeebac2e-6efd-11e3-a1d1-002354d040e6} - F:\setup.exe
HKU\S-1-5-21-436374069-682003330-1595356748-1003\...\MountPoints2: {fd564fc4-2a96-11e3-a151-002354d040e6} - F:\Lenovo_USB_Driver.exe
ShellIconOverlayIdentifiers: KAVOverlayIcon -> {dd230880-495a-11d1-b064-008048ec2fc5} => C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\shellex.dll (Kaspersky Lab ZAO)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ro/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204
DPF: {6ABE4BC3-7253-418E-85E8-F334A73154D3} http://gsmserver.com...p/SmartClip.cab
DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} http://download.micr...loadManager.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 193.231.242.2 193.226.60.2
 
FireFox:
========
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin: @Microsoft.com/DownloadManager,version=1.1 -> C:\WINDOWS\ ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: sony.com/MediaGoDetector - C:\Program Files\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-04-15]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[email protected]
FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[email protected] [2014-08-05]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[email protected]
FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[email protected] [2014-08-05]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[email protected]
FF Extension: Gevaarlijke websiteblokkering - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[email protected] [2014-08-05]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[email protected]
FF Extension: Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[email protected] [2014-08-05]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[email protected]
FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[email protected] [2014-08-05]
 
Chrome: 
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\36.0.1985.125\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Extension: (Google Docs) - C:\Documents and Settings\Radu\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-04-12]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Documents and Settings\Radu\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-28]
CHR Extension: (Kaspersky URL Advisor) - C:\Documents and Settings\Radu\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-08-05]
CHR Extension: (Safe Money) - C:\Documents and Settings\Radu\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-08-05]
CHR Extension: (Content Blocker) - C:\Documents and Settings\Radu\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-08-05]
CHR Extension: (Virtual Keyboard) - C:\Documents and Settings\Radu\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-08-05]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Radu\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24]
CHR Extension: (Anti-Banner) - C:\Documents and Settings\Radu\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-08-05]
CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\urladvisor.crx [2013-11-11]
CHR HKLM\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\online_banking_chrome.crx [2013-11-11]
CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\content_blocker_chrome.crx [2013-11-11]
CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\virtkbd.crx [2013-11-11]
CHR HKLM\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\ab.crx [2013-11-11]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [356128 2013-11-11] (Kaspersky Lab ZAO)
R3 BlackBerry Device Manager; C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [585728 2014-01-21] (BlackBerry Limited) [File not signed]
R2 CSObjectsSrv; C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [818888 2013-09-25] (Infowatch)
R2 MD Touch MiniUI Assistant Service; C:\Program Files\MD Touch Mini\MD Touch MiniAssistantServices.exe [242688 2010-06-30] () [File not signed]
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
R2 ScsiCommandService2; C:\WINDOWS\system32\ScsiCommandService2.exe [48128 2011-10-31] (Mobile Leader Co.,Ltd.) [File not signed]
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
R2 Tftpd32_svc; C:\Program Files\Tftpd32_SE\tftpd32_svc.exe [160256 2011-05-08] () [File not signed]
R2 ZuneBusEnum; C:\Program Files\Zune\ZuneBusEnum.exe [57056 2011-08-05] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 a016bus; C:\WINDOWS\System32\DRIVERS\a016bus.sys [83880 2008-01-18] (MCCI Corporation)
S3 a016mdfl; C:\WINDOWS\System32\DRIVERS\a016mdfl.sys [15016 2008-01-18] (MCCI Corporation)
S3 a016mdm; C:\WINDOWS\System32\DRIVERS\a016mdm.sys [110504 2008-01-18] (MCCI Corporation)
S3 a016mgmt; C:\WINDOWS\System32\DRIVERS\a016mgmt.sys [104488 2008-01-18] (MCCI Corporation)
S3 a016obex; C:\WINDOWS\System32\DRIVERS\a016obex.sys [100648 2008-01-18] (MCCI Corporation)
S3 Andbus; C:\WINDOWS\System32\DRIVERS\lgandbus.sys [14336 2012-03-02] (LG Electronics Inc.)
S3 AndDiag; C:\WINDOWS\System32\DRIVERS\lganddiag.sys [20736 2012-03-02] (LG Electronics Inc.)
S3 AndGps; C:\WINDOWS\System32\DRIVERS\lgandgps.sys [20096 2012-03-02] (LG Electronics Inc.)
S3 ANDModem; C:\WINDOWS\System32\DRIVERS\lgandmodem.sys [25088 2012-03-02] (LG Electronics Inc.)
S3 andnetadb; C:\WINDOWS\System32\Drivers\lgandnetadb.sys [25856 2013-04-18] (Google Inc)
S3 AndNetDiag; C:\WINDOWS\System32\DRIVERS\lgandnetdiag.sys [23168 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\WINDOWS\System32\DRIVERS\lgandnetmodem.sys [27776 2013-06-28] (LG Electronics Inc.)
S3 andnetndis; C:\WINDOWS\System32\DRIVERS\lgandnetndis.sys [70656 2013-04-23] (LG Electronics Inc.)
S3 androidusb; C:\WINDOWS\System32\Drivers\lgandadb.sys [25728 2012-03-02] (Google Inc)
R1 AsIO; C:\WINDOWS\System32\drivers\AsIO.sys [12400 2007-12-17] ()
S3 awUSB; C:\WINDOWS\System32\DRIVERS\USBDrv.sys [13824 2013-10-02] (Scott)
S3 bsusbser; C:\WINDOWS\System32\DRIVERS\bsusbser.sys [99456 2008-01-23] (QUALCOMM Incorporated)
R3 clipusb; C:\WINDOWS\System32\DRIVERS\clipusb.sys [11776 2007-12-12] (GSMServer) [File not signed]
S3 coolpadusbser; C:\WINDOWS\System32\DRIVERS\CP_USBSER.SYS [201216 2012-05-30] (QUALCOMM Incorporated)
R0 CSCrySec; C:\WINDOWS\System32\DRIVERS\CSCrySec.sys [88632 2011-06-02] (Infowatch)
R1 CSVirtualDiskDrv; C:\WINDOWS\System32\DRIVERS\CSVirtualDiskDrv.sys [39736 2011-06-02] (Infowatch)
S3 dmtoolusb; C:\WINDOWS\System32\Drivers\dmtoolusb.sys [18304 2007-06-25] (Windows ® 2000 DDK provider) [File not signed]
R3 Egatebus; C:\WINDOWS\System32\drivers\egatebus.sys [15328 2006-05-19] (Axalto)
R3 Egatecard; C:\WINDOWS\System32\Drivers\egate.sys [18880 2006-05-19] (Axalto)
R3 Egaterdr; C:\WINDOWS\System32\drivers\egaterdr.sys [13440 2006-05-19] (Axalto)
S3 FlashUSB; C:\WINDOWS\System32\DRIVERS\FlashUSB.sys [16384 2013-06-21] (Intel Mobile Communications)
R3 FsUsbExDisk; C:\WINDOWS\system32\FsUsbExDisk.SYS [36608 2010-06-14] () [File not signed]
R3 FTDIBUS; C:\WINDOWS\System32\drivers\ftdibus.sys [57800 2010-03-28] (FTDI Ltd.)
S3 ggsomc; C:\WINDOWS\System32\DRIVERS\ggsomc.sys [26328 2014-07-03] (Sony Mobile Communications)
S3 ghsdiag; C:\WINDOWS\System32\DRIVERS\ghsdiag.sys [113432 2011-03-28] (ZTE Incorporated)
S3 ghsnmea; C:\WINDOWS\System32\DRIVERS\ghsnmea.sys [113432 2011-03-28] (ZTE Incorporated)
S3 INQ1usbser; C:\WINDOWS\System32\DRIVERS\INQ1usbser.sys [103680 2008-03-20] (AMOI Incorporated)
R0 kl1; C:\WINDOWS\System32\DRIVERS\kl1.sys [135776 2014-08-05] (Kaspersky Lab ZAO)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [595008 2014-08-05] (Kaspersky Lab ZAO)
R3 klim5; C:\WINDOWS\System32\DRIVERS\klim5.sys [35672 2012-06-27] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\WINDOWS\System32\DRIVERS\klkbdflt.sys [24160 2013-11-11] (Kaspersky Lab ZAO)
R3 klmouflt; C:\WINDOWS\System32\DRIVERS\klmouflt.sys [24672 2013-11-11] (Kaspersky Lab ZAO)
R1 kltdi; C:\WINDOWS\System32\DRIVERS\kltdi.sys [44000 2013-11-11] (Kaspersky Lab ZAO)
R1 kneps; C:\WINDOWS\System32\DRIVERS\kneps.sys [145040 2013-11-11] (Kaspersky Lab ZAO)
R3 LgBttPort; C:\WINDOWS\System32\DRIVERS\lgbtport.sys [12032 2009-06-19] (LG Electronics Inc.)
R3 lgbusenum; C:\WINDOWS\System32\DRIVERS\lgbtbus.sys [10496 2009-06-19] (LG Electronics Inc.)
R3 LGVMODEM; C:\WINDOWS\System32\DRIVERS\lgvmodem.sys [12928 2009-06-19] (LG Electronics Inc.)
R3 libusb0; C:\WINDOWS\System32\DRIVERS\libusb0.sys [42592 2012-01-17] (http://libusb-win32.sourceforge.net)
S3 massfilter_hs; C:\WINDOWS\System32\DRIVERS\massfilter_hs.sys [9728 2010-06-17] (ZTE Incorporated)
S3 MobileAdapter; C:\WINDOWS\System32\DRIVERS\hmvmdm.sys [88960 2007-03-27] (Huawei Technologies Co., Ltd.)
S3 monfilt; C:\WINDOWS\System32\drivers\monfilt.sys [1389056 2008-02-14] (Creative Technology Ltd.)
S3 motandroidusb; C:\WINDOWS\System32\Drivers\motoandroid.sys [25856 2009-07-10] (Motorola)
S3 MotDev; C:\WINDOWS\System32\DRIVERS\motodrv.sys [42752 2012-10-22] (Motorola Inc)
S3 motport; C:\WINDOWS\System32\DRIVERS\motport.sys [24064 2011-03-31] (Motorola)
R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 pneteth; C:\WINDOWS\System32\DRIVERS\pneteth.sys [13440 2011-11-25] (June Fabrics Technology Inc.) [File not signed]
S3 qcserxp; C:\WINDOWS\System32\DRIVERS\qcserxp.sys [103424 2009-01-24] (QUALCOMM Incorporated)
S3 qcusbmdm6k; C:\WINDOWS\System32\DRIVERS\qcusbmdm6k.sys [65024 2007-10-03] (QUALCOMM Incorporated) [File not signed]
S3 qcusbnet; C:\WINDOWS\System32\DRIVERS\qcusbnet.sys [418304 2011-10-13] (QUALCOMM Incorporated)
S3 qcusbnmea; C:\WINDOWS\System32\DRIVERS\qcusbnmea.sys [65024 2007-10-03] (QUALCOMM Incorporated) [File not signed]
S3 qcusbpcsync; C:\WINDOWS\System32\DRIVERS\qcusbpcsync.sys [65024 2007-10-03] (QUALCOMM Incorporated) [File not signed]
S3 qcusbser; C:\WINDOWS\System32\DRIVERS\qcusbser.sys [105984 2009-08-14] (QUALCOMM Incorporated)
S3 qcusbser6k; C:\WINDOWS\System32\DRIVERS\qcusbser6k.sys [65024 2007-10-03] (QUALCOMM Incorporated) [File not signed]
S3 RimUsb; C:\WINDOWS\System32\Drivers\RimUsb.sys [68096 2013-12-02] (BlackBerry Limited)
S3 s0017bus; C:\WINDOWS\System32\DRIVERS\s0017bus.sys [86824 2008-10-21] (MCCI Corporation)
S3 s0017mdfl; C:\WINDOWS\System32\DRIVERS\s0017mdfl.sys [15016 2008-10-21] (MCCI Corporation)
S3 s0017mdm; C:\WINDOWS\System32\DRIVERS\s0017mdm.sys [114600 2008-10-21] (MCCI Corporation)
S3 s0017mgmt; C:\WINDOWS\System32\DRIVERS\s0017mgmt.sys [108328 2008-10-21] (MCCI Corporation)
S3 s0017nd5; C:\WINDOWS\System32\DRIVERS\s0017nd5.sys [26024 2008-10-21] (MCCI Corporation)
S3 s0017obex; C:\WINDOWS\System32\DRIVERS\s0017obex.sys [104616 2008-10-21] (MCCI Corporation)
S3 s0017unic; C:\WINDOWS\System32\DRIVERS\s0017unic.sys [109736 2008-10-21] (MCCI Corporation)
S3 s916bus; C:\WINDOWS\System32\DRIVERS\s916bus.sys [83496 2007-11-02] (MCCI Corporation)
S3 s916mdfl; C:\WINDOWS\System32\DRIVERS\s916mdfl.sys [15016 2007-11-02] (MCCI Corporation)
S3 s916mdm; C:\WINDOWS\System32\DRIVERS\s916mdm.sys [109992 2007-11-02] (MCCI Corporation)
S3 s916mgmt; C:\WINDOWS\System32\DRIVERS\s916mgmt.sys [103976 2007-11-02] (MCCI Corporation)
S3 s916obex; C:\WINDOWS\System32\DRIVERS\s916obex.sys [100008 2007-11-02] (MCCI Corporation)
S3 SciU2S; C:\WINDOWS\System32\DRIVERS\SciU2S.sys [117248 2013-09-26] (Spreadtrum Communication Inc.) [File not signed]
S3 se3ebus; C:\WINDOWS\System32\DRIVERS\se3ebus.sys [83080 2007-04-10] (MCCI Corporation)
S3 se3emdfl; C:\WINDOWS\System32\DRIVERS\se3emdfl.sys [15112 2007-04-10] (MCCI Corporation)
S3 se3emdm; C:\WINDOWS\System32\DRIVERS\se3emdm.sys [108552 2007-04-10] (MCCI Corporation)
S3 se3emgmt; C:\WINDOWS\System32\DRIVERS\se3emgmt.sys [100360 2007-04-10] (MCCI Corporation)
S3 se3eobex; C:\WINDOWS\System32\DRIVERS\se3eobex.sys [98568 2007-04-10] (MCCI Corporation)
R0 sfdrv01a; C:\WINDOWS\System32\drivers\sfdrv01a.sys [63352 2006-07-05] (Protection Technology (StarForce))
S3 smhwser; C:\WINDOWS\System32\DRIVERS\smhwser.sys [108032 2010-02-04] (QUALCOMM Incorporated)
S3 ssudobex; C:\WINDOWS\System32\DRIVERS\ssudobex.sys [182680 2013-08-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssudserd; C:\WINDOWS\System32\DRIVERS\ssudserd.sys [182680 2013-08-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ss_bbus; C:\WINDOWS\System32\DRIVERS\ss_bbus.sys [98432 2010-04-27] (MCCI)
S3 ss_bmdfl; C:\WINDOWS\System32\DRIVERS\ss_bmdfl.sys [14848 2010-04-27] (MCCI Corporation)
S3 ss_bmdm; C:\WINDOWS\System32\DRIVERS\ss_bmdm.sys [123648 2010-04-27] (MCCI Corporation)
S3 ss_bserd; C:\WINDOWS\System32\DRIVERS\ss_bserd.sys [100224 2010-04-27] (MCCI Corporation)
S3 SzCCID; C:\WINDOWS\System32\DRIVERS\SzCCID.sys [26112 2011-11-21] (Generic)
S3 TF1D091010; C:\WINDOWS\System32\DRIVERS\TF1D091010.sys [99968 2008-02-01] (TechFaith Wireless Technology Limited.)
S3 usbbus; C:\WINDOWS\System32\DRIVERS\lgusbbus.sys [13056 2010-01-21] (LG Electronics Inc.)
S3 UsbDiag; C:\WINDOWS\System32\DRIVERS\lgusbdiag.sys [20864 2010-01-21] (LG Electronics Inc.)
S3 USBModem; C:\WINDOWS\System32\DRIVERS\lgusbmodem.sys [24960 2010-01-21] (LG Electronics Inc.)
S3 usbUDisc; C:\WINDOWS\System32\DRIVERS\USBDrv.sys [13824 2013-10-02] (Scott)
R3 VIAHdAudAddService; C:\WINDOWS\System32\drivers\viahduaa.sys [1425280 2009-10-21] (VIA Technologies, Inc.)
S3 w810bus; C:\WINDOWS\System32\DRIVERS\w810bus.sys [58288 2005-10-07] (MCCI)
S3 w810mdfl; C:\WINDOWS\System32\DRIVERS\w810mdfl.sys [8336 2005-10-07] (MCCI)
S3 w810mdm; C:\WINDOWS\System32\DRIVERS\w810mdm.sys [94064 2005-10-07] (MCCI)
S3 w810mgmt; C:\WINDOWS\System32\DRIVERS\w810mgmt.sys [85408 2005-10-07] (MCCI)
S3 w810obex; C:\WINDOWS\System32\DRIVERS\w810obex.sys [83344 2005-10-07] (MCCI)
S3 wdf_usb; C:\WINDOWS\System32\drivers\usb2ser.sys [58112 2011-05-18] (MediaTek Inc.) [File not signed]
S3 zghsdiag; C:\WINDOWS\System32\DRIVERS\zghsdiag.sys [113688 2011-08-22] (ZTE Incorporated)
S3 zghsmdm; C:\WINDOWS\System32\DRIVERS\zghsmdm.sys [113688 2011-08-22] (ZTE Incorporated)
S3 zghsnmea; C:\WINDOWS\System32\DRIVERS\zghsnmea.sys [113688 2011-08-22] (ZTE Incorporated)
R2 zumbus; C:\WINDOWS\System32\DRIVERS\zumbus.sys [41472 2011-08-05] (Microsoft Corporation)
U2 CertPropSvc; 
S4 IntelIde; No ImagePath
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74336 2014-08-05] (Kaspersky Lab ZAO)
S3 ntportio; \??\C:\Documents and Settings\Radu\My Documents\Downloads\USB_SMART_FULL_free-gsm-unlock.com\USB-SMART-FULLY-CRACKED\Sony-Ericsson\ntportio.sys [X]
U1 WS2IFSL; 
 
==================== NetSvcs (Whitelisted) ===================
 
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-05 16:36 - 2014-08-05 16:36 - 00000000 ____D () C:\FRST
2014-08-05 09:32 - 2014-08-05 09:32 - 00000000 __SHD () C:\Documents and Settings\NetworkService\IETldCache
2014-08-05 09:32 - 2014-08-05 09:32 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Kaspersky PURE 3.0
2014-08-05 09:31 - 2014-08-05 16:28 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2014-08-05 09:31 - 2014-08-05 09:31 - 00000000 ____D () C:\Program Files\Kaspersky Lab
2014-08-05 09:31 - 2014-08-05 09:31 - 00000000 ____D () C:\Program Files\Common Files\InfoWatch
2014-08-05 09:31 - 2011-06-02 14:39 - 00088632 _____ (Infowatch) C:\WINDOWS\system32\Drivers\CSCrySec.sys
2014-08-05 09:31 - 2011-06-02 14:39 - 00039736 _____ (Infowatch) C:\WINDOWS\system32\Drivers\CSVirtualDiskDrv.sys
2014-08-05 09:30 - 2014-08-05 10:13 - 00595008 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys
2014-08-05 09:30 - 2014-08-05 10:13 - 00074336 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys
2014-08-04 21:26 - 2014-08-05 14:00 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MCShield
2014-08-04 21:26 - 2014-08-04 21:26 - 00000000 ____D () C:\Program Files\MCShield
2014-08-04 21:26 - 2014-08-04 21:26 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\MCShield
2014-08-04 11:04 - 2014-08-04 11:22 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\4 catre 5
2014-08-04 10:46 - 2014-08-04 10:47 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\lt15
2014-07-14 12:53 - 2014-07-14 13:36 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\New Folder (3)
2014-07-14 12:03 - 2014-07-14 12:06 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\New Folder (2)
2014-07-12 12:25 - 2014-07-12 12:26 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\New Folder
2014-07-12 10:10 - 2014-07-12 10:11 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\contacte
2014-07-10 11:49 - 2014-07-10 12:29 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\catre iphone
2014-07-09 10:34 - 2014-07-09 10:35 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-07-09 10:32 - 2014-07-09 10:32 - 00000777 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-09 10:32 - 2014-07-09 10:32 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-09 10:32 - 2014-07-09 10:32 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-09 10:32 - 2014-07-09 10:32 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2014-07-09 10:32 - 2014-05-12 07:26 - 00053208 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-07-09 10:32 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-05 16:36 - 2014-08-05 16:36 - 00000000 ____D () C:\FRST
2014-08-05 16:36 - 2013-04-10 20:46 - 00000000 ____D () C:\Documents and Settings\Radu\Local Settings\Temp
2014-08-05 16:28 - 2014-08-05 09:31 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2014-08-05 16:13 - 2013-04-16 18:24 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-08-05 15:39 - 2013-04-12 15:49 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-05 15:39 - 2013-04-12 15:49 - 00000878 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-05 14:04 - 2013-04-10 23:05 - 00513832 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-08-05 14:02 - 2013-04-10 20:36 - 01614266 _____ () C:\WINDOWS\WindowsUpdate.log
2014-08-05 14:00 - 2014-08-04 21:26 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MCShield
2014-08-05 14:00 - 2014-06-20 16:22 - 01313022 _____ () C:\WINDOWS\setupapi.log
2014-08-05 14:00 - 2014-03-14 10:27 - 00000220 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2014-08-05 14:00 - 2013-04-10 23:07 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-08-05 14:00 - 2013-04-10 23:07 - 00000048 _____ () C:\WINDOWS\wiaservc.log
2014-08-05 14:00 - 2013-04-10 20:44 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-08-05 14:00 - 2008-08-21 15:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl
2014-08-05 13:58 - 2013-04-10 20:46 - 00000178 ___SH () C:\Documents and Settings\Radu\ntuser.ini
2014-08-05 13:58 - 2013-04-10 20:44 - 00032636 _____ () C:\WINDOWS\SchedLgU.Txt
2014-08-05 12:25 - 2013-04-19 13:07 - 00000000 ____D () C:\Program Files\SgTool
2014-08-05 10:13 - 2014-08-05 09:30 - 00595008 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys
2014-08-05 10:13 - 2014-08-05 09:30 - 00074336 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys
2014-08-05 10:13 - 2013-11-11 19:25 - 00135776 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kl1.sys
2014-08-05 09:32 - 2014-08-05 09:32 - 00000000 __SHD () C:\Documents and Settings\NetworkService\IETldCache
2014-08-05 09:32 - 2014-08-05 09:32 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Kaspersky PURE 3.0
2014-08-05 09:32 - 2013-04-10 20:40 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2014-08-05 09:31 - 2014-08-05 09:31 - 00000000 ____D () C:\Program Files\Kaspersky Lab
2014-08-05 09:31 - 2014-08-05 09:31 - 00000000 ____D () C:\Program Files\Common Files\InfoWatch
2014-08-04 21:26 - 2014-08-04 21:26 - 00000000 ____D () C:\Program Files\MCShield
2014-08-04 21:26 - 2014-08-04 21:26 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\MCShield
2014-08-04 12:16 - 2014-04-02 14:46 - 00269869 _____ () C:\WINDOWS\setupact.log
2014-08-04 11:22 - 2014-08-04 11:04 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\4 catre 5
2014-08-04 10:47 - 2014-08-04 10:46 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\lt15
2014-07-25 14:46 - 2013-10-15 15:32 - 03646624 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2014-07-25 13:59 - 2013-04-15 10:51 - 00022084 _____ () C:\Documents and Settings\Radu\Application Data\Rim.Desktop.Exception.log
2014-07-25 13:59 - 2013-04-15 10:51 - 00008239 _____ () C:\Documents and Settings\Radu\Application Data\Rim.DesktopHelper.Exception.log
2014-07-24 15:04 - 2014-07-03 12:41 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Sony Mobile
2014-07-24 15:04 - 2013-04-12 16:34 - 00000000 ____D () C:\Program Files\Sony Mobile
2014-07-22 10:42 - 2013-04-12 15:51 - 00001813 _____ () C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2014-07-19 13:47 - 2013-09-02 15:18 - 00000000 ____D () C:\Documents and Settings\Radu\My Documents\SelfMV
2014-07-18 15:43 - 2014-04-01 10:40 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\recuperari
2014-07-16 10:14 - 2014-04-12 10:28 - 00009842 _____ () C:\WINDOWS\egatedrv-coinstall.log
2014-07-16 10:08 - 2014-06-20 16:22 - 01836793 _____ () C:\WINDOWS\setupapi.log.17.old
2014-07-14 13:36 - 2014-07-14 12:53 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\New Folder (3)
2014-07-14 12:06 - 2014-07-14 12:03 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\New Folder (2)
2014-07-12 12:26 - 2014-07-12 12:25 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\New Folder
2014-07-12 12:24 - 2013-12-17 12:19 - 00000000 ____D () C:\Documents and Settings\Radu\Application Data\PC Suite
2014-07-12 10:11 - 2014-07-12 10:10 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\contacte
2014-07-10 12:29 - 2014-07-10 11:49 - 00000000 ____D () C:\Documents and Settings\Radu\Desktop\catre iphone
2014-07-10 11:55 - 2013-08-16 03:04 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-07-10 11:50 - 2013-04-13 12:49 - 93585272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-07-10 11:50 - 2013-04-12 13:43 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Microsoft Help
2014-07-09 16:13 - 2013-04-16 18:24 - 00699056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-07-09 16:13 - 2013-04-16 18:24 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-07-09 13:35 - 2014-05-05 19:05 - 00857472 _____ () C:\WINDOWS\DPINST.LOG
2014-07-09 13:33 - 2014-06-10 14:49 - 00001739 _____ () C:\Documents and Settings\All Users\Desktop\Sony PC Companion 2.1.lnk
2014-07-09 13:33 - 2014-06-10 14:49 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Sony
2014-07-09 13:33 - 2013-04-12 14:12 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-07-09 10:46 - 2013-04-12 13:43 - 00000000 ____D () C:\WINDOWS\SHELLNEW
2014-07-09 10:35 - 2014-07-09 10:34 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-07-09 10:32 - 2014-07-09 10:32 - 00000777 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-09 10:32 - 2014-07-09 10:32 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-09 10:32 - 2014-07-09 10:32 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-09 10:32 - 2014-07-09 10:32 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2014-07-08 15:00 - 2014-03-14 10:27 - 00000214 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
 
Files to move or delete:
====================
C:\Documents and Settings\Radu\ACmd.dll
C:\Documents and Settings\Radu\APipe.dll
C:\Documents and Settings\Radu\AwPluginVector.dll
C:\Documents and Settings\Radu\Config.dll
C:\Documents and Settings\Radu\crc32.dll
C:\Documents and Settings\Radu\drvinstaller_IA64.exe
C:\Documents and Settings\Radu\drvinstaller_X64.exe
C:\Documents and Settings\Radu\drvinstaller_X86.exe
C:\Documents and Settings\Radu\eFex.dll
C:\Documents and Settings\Radu\encode.dll
C:\Documents and Settings\Radu\idfactory.dll
C:\Documents and Settings\Radu\ImgDecode.dll
C:\Documents and Settings\Radu\KSDecode.dll
C:\Documents and Settings\Radu\LangPlg.dll
C:\Documents and Settings\Radu\LiveSuit.dat
C:\Documents and Settings\Radu\LiveSuit.exe
C:\Documents and Settings\Radu\Phoenix_Elf.dll
C:\Documents and Settings\Radu\Phoenix_Fes.dll
C:\Documents and Settings\Radu\roottools.dll
C:\Documents and Settings\Radu\sdata.dll
C:\Documents and Settings\Radu\single.dll
C:\Documents and Settings\Radu\ZipModule.dll
 
 
Some content of TEMP:
====================
C:\Documents and Settings\Radu\Local Settings\Temp\Execute2App.exe
C:\Documents and Settings\Radu\Local Settings\Temp\GdiPlus.dll
C:\Documents and Settings\Radu\Local Settings\Temp\InstallerMessageBox.exe
C:\Documents and Settings\Radu\Local Settings\Temp\msvcp90.dll
C:\Documents and Settings\Radu\Local Settings\Temp\msvcr90.dll
C:\Documents and Settings\Radu\Local Settings\Temp\NPSInstallerProxy.exe
C:\Documents and Settings\Radu\Local Settings\Temp\NPSInstallerProxyMessageBoxHookDll.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
==================== End Of Log ============================
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version:2-08-2014
Ran by Radu at 2014-08-05 16:37:14
Running from C:\Documents and Settings\Radu\My Documents\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Kaspersky PURE 3.0 (Disabled - Up to date) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky PURE 3.0 (Disabled) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.7.0.1530 - Adobe Systems Incorporated)
Adobe AIR (Version: 3.7.0.1530 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader X (10.1.8) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.8 - Adobe Systems Incorporated)
AIDA64 Extreme Edition v2.00 (HKLM\...\AIDA64 Extreme Edition_is1) (Version: 2.00 - FinalWire Ltd.)
Apple Application Support (HKLM\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
BlackBerry Desktop Software 7.1 (HKLM\...\BlackBerry_Desktop) (Version: 7.1.0.41 - Research In Motion Ltd.)
BlackBerry Desktop Software 7.1 (Version: 7.1.0.41 - Research In Motion Ltd.) Hidden
BlackBerry Device Software Updater (HKLM\...\{E31C1E19-81D2-40C0-BE40-30A2A54E9C27}) (Version: 8.0.0.50 - Research In Motion Ltd)
BlackBerry Device Software v5.0.0 for the BlackBerry 8900 smartphone (HKLM\...\{156EB53E-4B38-4D54-BD82-7C6E083AA1C0}) (Version: 5.0.0.681 (Platform 5.2.0.67) - Research In Motion Ltd.)
BlackBerry Device Software v7.1.0 for the BlackBerry 9360 smartphone (HKLM\...\{F14866D4-B384-4F5F-98C7-FB25A787B147}) (Version: 7.1.0.1047 (Platform 9.6.0.160) - Research In Motion Ltd.)
BlackBerry Device Software v7.1.0 for the BlackBerry 9900 smartphone (HKLM\...\{AF8E1C70-27D1-4F71-9111-D07585391042}) (Version: 7.1.0.428 (Platform 5.1.0.338) - Research In Motion Ltd.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
coolpadusbdriver (HKLM\...\InstallShield_{FA9F22FA-DE0A-4DB7-9EEE-E2737047D611}) (Version: 1.00.0000 - yulong)
coolpadusbdriver (Version: 1.00.0000 - yulong) Hidden
FURIOUS GOLD (29.06.2008) (HKLM\...\{5760FB23-F911-425C-A8BF-DFA7A0B0E003}_is1) (Version:  - FuriouSTeaM)
Google Chrome (HKLM\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
Gordon's Gate Flash Driver 3.0.0.1 (HKLM\...\Gordon's Gate Flash Driver) (Version: 3.0.0.1 - Sony Mobile Communications AB)
INQ1 Modem (HKLM\...\{65F6D129-8EB6-4DC1-A5C0-E5EB1C6755AB}) (Version: 1.10.0000 - amoi)
Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version:  - Intel Corporation)
IPTInstaller (HKLM\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC)
iTunes (HKLM\...\{0718A90E-93AA-49AF-A4FE-0165ACD91DF0}) (Version: 11.2.2.3 - Apple Inc.)
Kaspersky PURE 3.0 (HKLM\...\InstallWIX_{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}) (Version: 13.0.2.558 - Kaspersky Lab)
Kaspersky PURE 3.0 (Version: 13.0.2.558 - Kaspersky Lab) Hidden
Lenovo USB driver (HKLM\...\Lenovo USB Driver_is1) (Version: V1.0 - Lenovo)
LG Bluetooth Drivers (HKLM\...\{F59A3B93-6C1C-4C3E-BCC4-4897490E2963}) (Version: 1.0 - LG Electronics)
LG MC USB U330 driver (HKLM\...\{ABD7DBE3-E344-4BCA-B8AD-4360494DD1D9}) (Version: 1.0.0.0000 - LG Electronics)
LG PC Suite (HKLM\...\LG PC Suite) (Version: 5.3.06.20130913 - LG Electronics)
LG SP USB Driver (HKLM\...\{E2AE8456-CCFE-46C0-8629-71CC507660FC}) (Version: 1.0 - LG Electronics)
LG United Mobile Driver (HKLM\...\{2A3A4BD6-6CE0-4E2A-80D2-1D0FF6ACBFBA}) (Version: 3.10.1.0 - LG Electronics)
LG USB Modem Driver (HKLM\...\{C3ABE126-2BB2-4246-BFE1-6797679B3579}) (Version: 4.9.7 - LG Electronics)
LG USB Modem Driver-MDMS (HKLM\...\{4B141C08-51E5-4224-81BD-5FC967195734}) (Version: 2.0 - LG Electronics)
LG USB WML Modem Driver (HKLM\...\{FBA0CA60-8BF2-4381-B819-74F020E165A9}) (Version: 1.0 - LG Electronics)
LGE GSM Device Driver OMAPV1030 (HKLM\...\{C2979637-6A5A-4CF3-876C-AA2F199E3750}) (Version: 1.0.0.0000 - LG Electronics)
LGE Tool 2.36 (HKLM\...\LGE Tool_is1) (Version:  - LGETool.com)
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
MCShield ::Anti-Malware Tool:: (HKLM\...\MCShield) (Version: 3.0.5.28 - MyCity)
MD Touch Mini (HKLM\...\{72FD5F2E-1F7A-4E9B-8838-29E842E178CD}) (Version: 2.0.3.0 - ZTE)
Media Go (HKLM\...\{F66C4A41-C3A8-4523-AB6C-BAA1DB38305C}) (Version: 2.7.357 - Sony)
Media Go Network Downloader (HKLM\...\{5562F05F-908C-4F15-9B3C-98D5FD32DCAB}) (Version: 1.5.19.0 - Sony)
Media Go Video Playback Engine 2.4.127.12060 (HKLM\...\{7C5AEEE1-6D7C-8922-4548-7BF9096077EC}) (Version: 2.4.127.12060 - Sony)
MICRO-BOX Driver Pack (HKLM\...\MICRO-BOX Driver Pack_is1) (Version: 1.0 - MICRO-BOX Team)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft ActiveSync (HKLM\...\{99052DB7-9592-4522-A558-5417BBAD48EE}) (Version: 4.5.5096.0 - Microsoft Corporation)
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Download Manager (HKLM\...\{654977DB-0001-0002-0001-EABD228DDE8B}) (Version: 1.2.1 - Microsoft Corporation)
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 (Version:  - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (Version:  - Microsoft) Hidden
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Software Update for Web Folders  (English) 12 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft User-Mode Driver Framework Feature Pack 1.9 (HKLM\...\Wudf01009) (Version:  - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft WinUsb 1.0 (HKLM\...\winusb0100) (Version:  - Microsoft Corporation)
Microsoft WinUsb 2.0 (HKLM\...\winusb0200) (Version:  - Microsoft Corporation)
Motorola Mobile Drivers Installation 5.1.0 (HKLM\...\{C35CCBEB-5A54-4DD8-9EC8-110F2A8154B3}) (Version: 5.1.0 - Motorola Inc.)
MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Nokia Connectivity Cable Driver (HKLM\...\{A57025CC-5F2E-4D01-B387-06DB10500D43}) (Version: 7.1.78.0 - Nokia)
Nokia PC Suite (HKLM\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia)
Nokia PC Suite (Version: 7.1.180.94 - Nokia) Hidden
PC Connectivity Solution (HKLM\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia)
PC Tools (HKLM\...\{395AB8C5-F3A8-4380-8718-7A11EC5829D4}) (Version: 1.00.0000 - SimTech)
Platform (Version: 1.34 - VIA Technologies, Inc.) Hidden
QuickTime 7 (HKLM\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
REALTEK GbE & FE Ethernet PCI-E NIC Driver (HKLM\...\{C9BED750-1211-4480-B1A5-718A3BE15525}) (Version: 1.23.0000 - Realtek)
Samsung Kies (HKLM\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.0.13064_2 - Samsung Electronics Co., Ltd.)
Samsung Kies (Version: 2.6.0.13064_2 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14034.17 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (Version: 3.2.14034.17 - Samsung Electronics Co., Ltd.) Hidden
Samsung New PC Studio (HKLM\...\InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
Samsung New PC Studio (Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.650.0 - SAMSUNG Electronics Co., Ltd.)
SCout (HKLM\...\{1049CADB-7346-4D7D-85E5-9F7FFFE13D16}) (Version: 2.11.0000 - GsmServer)
SmartMoto (HKLM\...\{935C0E2B-CCC7-4424-ADB3-5A27D527F1D6}) (Version: 2.00 - GsmServer)
Sony Mobile Update Engine (HKLM\...\Update Engine) (Version: 2.14.10.201407111005 - Sony Mobile Communications AB)
Sony PC Companion 2.10.211 (HKLM\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.211 - Sony)
Tftpd32 Service Edition (remove only) (HKLM\...\Tftpd32_SE) (Version:  - )
Uninstall LG PC Suite III (HKLM\...\{D94BA408-F110-488B-A65E-3AE7945F79E6}_is1) (Version:  - LG Electronics)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2883030) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{F5DCAB53-C2FD-4E5A-8C83-0F37485E5E89}) (Version:  - Microsoft)
Update for Windows Internet Explorer 8 (KB2598845) (HKLM\...\KB2598845-IE8) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2345886) (HKLM\...\KB2345886) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2467659) (HKLM\...\KB2467659) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2661254-v2) (HKLM\...\KB2661254-v2) (Version: 2 - Microsoft Corporation)
Update for Windows XP (KB2736233) (HKLM\...\KB2736233) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2749655) (HKLM\...\KB2749655) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2863058) (HKLM\...\KB2863058) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2904266) (HKLM\...\KB2904266) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2934207) (HKLM\...\KB2934207) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB898461) (HKLM\...\KB898461) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB951978) (Version: 1 - Microsoft Corporation) Hidden
Update for Windows XP (KB955759) (HKLM\...\KB955759) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB968389) (HKLM\...\KB968389) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB971029) (HKLM\...\KB971029) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB973815) (HKLM\...\KB973815) (Version: 1 - Microsoft Corporation)
VIA Platform Device Manager (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
WellPhone XT (HKLM\...\{10C9FF8B-3053-46B7-ABD2-4DE5C003D55F}) (Version: 3.7.671.33 - SmartCom)
Windows Driver Package - Acer (WUDFRd) WPD  (01/01/2012 5.2.5326.4762) (HKLM\...\9C647CC82F4C5DE3F3FC22FD3DE138FB6210DEB7) (Version: 01/01/2012 5.2.5326.4762 - Acer)
Windows Driver Package - ACER Incorporated (qcusbser) Modem  (01/01/2012 2.0.6.6) (HKLM\...\1567F843307C9FD0E3FF0516E53B917ADEA16C16) (Version: 01/01/2012 2.0.6.6 - ACER Incorporated)
Windows Driver Package - ACER Incorporated (qcusbser) Ports  (01/01/2012 2.0.6.6) (HKLM\...\5C77E0A696001C3B2A686947C17C6D792ADDEC75) (Version: 01/01/2012 2.0.6.6 - ACER Incorporated)
Windows Driver Package - Acer USB Driver Disk (qcusbnet) Net  (01/01/2012 1.0.6.9) (HKLM\...\FF61EF26E5380A71752C035B2AC7037CB9C9C1DB) (Version: 01/01/2012 1.0.6.9 - Acer USB Driver Disk)
Windows Driver Package - Acer, Inc (androidusb) USB  (01/01/2012 1.0.0010.00000) (HKLM\...\4026E26223836F109A2C4DAC43CAA7DF7B3DE92F) (Version: 01/01/2012 1.0.0010.00000 - Acer, Inc)
Windows Driver Package - Amoi Incorporated (INQ1usbser) Modem  (01/01/2007 2.0.5.0) (HKLM\...\75F6C4F084A18C2A71179397570DD3BE34BA2679) (Version: 01/01/2007 2.0.5.0 - Amoi Incorporated)
Windows Driver Package - Amoi Incorporated (INQ1usbser) Ports  (01/01/2007 2.0.5.0) (HKLM\...\3448AA55E35CFBCE2DBCEED25E4046660049CDBD) (Version: 01/01/2007 2.0.5.0 - Amoi Incorporated)
Windows Driver Package - Axalto (Egatebus) Egatebus 04/25/2006 3.00.06.00 (HKLM\...\egatebus_449dc5008b546b56468d3eb6cecae8f772aa0e0d) (Version: 3.00.06.00 - Axalto)
Windows Driver Package - Axalto (Egatecard) Egatecard 04/25/2006 3.00.06.00 (HKLM\...\egate_9d41b0b3107bb72f8259dcd0c32c2d480b995c0f) (Version: 3.00.06.00 - Axalto)
Windows Driver Package - Axalto (Egaterdr) SmartCardReader 04/25/2006 3.00.06.00 (HKLM\...\egaterdr_8fc61af4f82219450b0b9365c141462c012ca11a) (Version: 3.00.06.00 - Axalto)
Windows Driver Package - Coolpad Incorporated (coolpadusbser) Modem  (05/28/2012 2.0.9.6) (HKLM\...\0B0E5833CBB5347E7D0F6F6EB01E659276D4B806) (Version: 05/28/2012 2.0.9.6 - Coolpad Incorporated)
Windows Driver Package - Coolpad Incorporated (coolpadusbser) Ports  (05/28/2012 2.0.9.6) (HKLM\...\7BA3C2BB7ED737CD76047F0DB39EA3C3B6909441) (Version: 05/28/2012 2.0.9.6 - Coolpad Incorporated)
Windows Driver Package - Coolpad WPD  (10/10/2008 1.0.0.0) (HKLM\...\FFD0B23F592D919382F8162F7423BAEF161B179F) (Version: 10/10/2008 1.0.0.0 - Coolpad)
Windows Driver Package - Linux Developer Community Net  (01/01/2012 5.1.2600.2781) (HKLM\...\EBECEBEB48B5CDA21428431E1F40F889A4F4A3D2) (Version: 01/01/2012 5.1.2600.2781 - Linux Developer Community)
Windows Driver Package - Nokia Modem  (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia)
Windows Driver Package - Nokia Modem  (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia)
Windows Driver Package - Nokia pccsmcfd “LegacyDriver”  (05/31/2012 7.1.2.0) (HKLM\...\17D063A0A9F5D5A225B76B1D9BCB5ADBE85C8382) (Version: 05/31/2012 7.1.2.0 - Nokia)
Windows Driver Package - Sony Ericsson Mobile Communications (ggsemc) USB  (05/04/2010 2.2.0.5) (HKLM\...\107F1D316CC09E17C1103A85BA671188E585FA76) (Version: 05/04/2010 2.2.0.5 - Sony Ericsson Mobile Communications)
Windows Driver Package - Sony Ericsson Mobile Communications AB (zebrbus) USB  (12/26/2007 4.40.6.0) (HKLM\...\AFCC6BDFC2FB2718653394000206D98BECAAC196) (Version: 12/26/2007 4.40.6.0 - Sony Ericsson Mobile Communications AB)
Windows Driver Package - Sony Ericsson Mobile Communications AB (zebrceb) System  (12/26/2007 4.40.6.0) (HKLM\...\C1C66E8B6A1F5FEA6A4BD682014FA9E74B9B3D21) (Version: 12/26/2007 4.40.6.0 - Sony Ericsson Mobile Communications AB)
Windows Driver Package - Sony Ericsson Mobile Communications AB (zebrmdm) Modem  (12/26/2007 4.40.6.0) (HKLM\...\54EA2ABFB38AEA1D8808B8D08E68201B9FDB025A) (Version: 12/26/2007 4.40.6.0 - Sony Ericsson Mobile Communications AB)
Windows Driver Package - Sony Ericsson Mobile Communications AB (zebrmdm) Ports  (12/26/2007 4.40.6.0) (HKLM\...\2F93E6B0EC1639D421A9CCD8C06539D70A2C9D8D) (Version: 12/26/2007 4.40.6.0 - Sony Ericsson Mobile Communications AB)
Windows Driver Package - Sony Ericsson Mobile Communications AB (zebrmdm) Ports  (12/26/2007 4.40.6.0) (HKLM\...\3038F810531A3119D8408813AB675523F4BD5634) (Version: 12/26/2007 4.40.6.0 - Sony Ericsson Mobile Communications AB)
Windows Driver Package - Sony Ericsson Mobile Communications AB (zebrmdmc) USB  (12/26/2007 4.40.6.0) (HKLM\...\3B65F5281FAC2BDEC493E64B8E5BDC43DE0B94A6) (Version: 12/26/2007 4.40.6.0 - Sony Ericsson Mobile Communications AB)
Windows Driver Package - Sony Ericsson Mobile Communications AB (zebrobex) Ports  (12/26/2007 4.40.6.0) (HKLM\...\59A2AFF064B823BE53673BEE04D1F520823F56F5) (Version: 12/26/2007 4.40.6.0 - Sony Ericsson Mobile Communications AB)
Windows Driver Package - Sony Ericsson Mobile Communications AB (zebrsce) Ports  (12/26/2007 4.40.6.0) (HKLM\...\F33D7CFC00F5F23AB61B26F60D76965B226EB223) (Version: 12/26/2007 4.40.6.0 - Sony Ericsson Mobile Communications AB)
Windows Driver Package - Sony Ericsson Mobile Communications AB USB  (12/26/2007 4.40.6.0) (HKLM\...\E505647D47DAF2622883E65DD8BF04C393FDCDCB) (Version: 12/26/2007 4.40.6.0 - Sony Ericsson Mobile Communications AB)
Windows Driver Package - Spreadtrum (SciCmpst) Ports  (02/15/2011 1.5.6.1) (HKLM\...\B6AAE7158C952C97E77091B70DAAAC12A9554D3E) (Version: 02/15/2011 1.5.6.1 - Spreadtrum)
Windows Driver Package - Yulong, Inc. (WinUSB) AndroidUsbDeviceClass  (12/06/2010 4.0.0000.00000) (HKLM\...\7D35F404F513E27213239A84CA8116BA6BA4003E) (Version: 12/06/2010 4.0.0000.00000 - Yulong, Inc.)
Windows Genuine Advantage Notifications (KB905474) (HKLM\...\WgaNotify) (Version: 1.9.0040.0 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version:  - )
Windows Media Format 11 runtime (Version:  - Microsoft Corporation) Hidden
Windows Media Player 11 (HKLM\...\Windows Media Player) (Version:  - )
Windows Media Player 11 (Version:  - Microsoft Corporation) Hidden
Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
WinRAR archiver (HKLM\...\WinRAR archiver) (Version:  - )
Yahoo! Messenger (HKLM\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
ZTE Handset USB Driver (HKLM\...\{01D42BF0-ED08-463f-8A28-99EB6FEE962B}) (Version:  - ZTE Corporation)
ZTE Handset USB Driver (HKLM\...\{D2D77DC2-8299-11D1-8949-444553540000}_is1) (Version: 5.2066.1.A10B01 - ZTE Corporation)
Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation)
Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{0BE35200-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> C:\Program Files\GsmServer\SCout\units\mtk\mtk42.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{0BE35201-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> C:\Program Files\GsmServer\SCout\units\mtk\mtk42.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{0BE35202-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> C:\Program Files\GsmServer\SCout\units\mtk\mtk42.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{24067A30-29FE-44DC-8938-5D968A9A48F3}\InprocServer32 -> C:\Program Files\GsmServer\SCout\units\chimei\CommPortSvr.dll ()
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{326787D9-37B9-47A6-B539-EE13E7B04B8B}\InprocServer32 -> C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\devicemanagerproperties.dll (Research In Motion Limited)
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{3E4D2B26-0103-412C-92E7-34B1D2FA5CFB}\InprocServer32 -> C:\Program Files\GsmServer\SCout\units\chimei\DownloadCmp.dll ()
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{47F64EC4-1AD6-4168-9D4C-00F3842F7CFB}\InprocServer32 -> C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\DeviceManagerProperties.dll (Research In Motion Limited)
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{56C8F385-EF59-4CFD-B8E4-0DA9407C7C95}\InprocServer32 -> C:\Program Files\GsmServer\SCout\units\compal_cdma3\DownLoader.ocx ()
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{56C8F386-EF59-4CFD-B8E4-0DA9407C7C95}\InprocServer32 -> C:\Program Files\GsmServer\SCout\units\compal_cdma3\DownLoader.ocx ()
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{6CC833D0-D8EC-481C-8FE2-E97DED3383B1}\InprocServer32 -> C:\Program Files\GsmServer\SCout\units\chimei\ErrMapSvr.dll ()
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{82D1C283-A637-4A07-B1EC-8C7AE661EAF1}\InprocServer32 -> C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\devicemanagerproperties.dll (Research In Motion Limited)
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{A66CE2B7-E56E-4497-BBC5-2152F274915E}\InprocServer32 -> C:\Program Files\GsmServer\SCout\units\chimei\UsbSvr.dll ()
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{C8992C14-DF59-4518-808F-CCFBB5850282}\InprocServer32 -> C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\devicemanagerproperties.dll (Research In Motion Limited)
CustomCLSID: HKU\S-1-5-21-436374069-682003330-1595356748-1003_Classes\CLSID\{EB59852D-B38E-4a4c-94BA-6731836E5538}\InprocServer32 -> C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\DeviceManagerProperties.dll (Research In Motion Limited)
 
==================== Restore Points  =========================
 
09-07-2014 15:58:08 System Checkpoint
10-07-2014 08:49:53 Software Distribution Service 3.0
10-07-2014 12:14:17 Unsigned driver install
11-07-2014 12:14:28 System Checkpoint
14-07-2014 11:18:54 System Checkpoint
14-07-2014 14:39:37 Installed Windows XP winusb0100.
15-07-2014 15:03:57 System Checkpoint
15-07-2014 16:36:42 Unsigned driver install
16-07-2014 07:14:48 Installed Windows XP winusb0100.
16-07-2014 11:38:32 Unsigned driver install
17-07-2014 11:56:59 System Checkpoint
18-07-2014 15:39:33 System Checkpoint
21-07-2014 07:45:02 System Checkpoint
22-07-2014 07:46:32 System Checkpoint
22-07-2014 08:41:34 Unsigned driver install
23-07-2014 10:44:08 System Checkpoint
24-07-2014 11:00:46 System Checkpoint
24-07-2014 12:04:33 Installed Sony Mobile Drivers
28-07-2014 09:17:34 System Checkpoint
30-07-2014 11:26:33 System Checkpoint
31-07-2014 14:20:26 System Checkpoint
04-08-2014 18:44:30 System Checkpoint
05-08-2014 06:31:12 First Restore Point
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2008-08-21 15:00 - 2013-12-05 10:50 - 00000744 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
 
==================== Scheduled Tasks (whitelisted) =============
 
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
 
==================== Loaded Modules (whitelisted) =============
 
2013-09-26 13:00 - 2009-02-05 09:27 - 00066512 _____ () C:\Program Files\Common Files\SmartCom\DragnDropCopyHook.dll
2013-08-09 15:07 - 2010-07-16 09:25 - 00133120 _____ () C:\Program Files\MD Touch Mini\MD Touch MiniUIExec.exe
2014-02-12 21:58 - 2014-02-12 21:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 21:58 - 2014-02-12 21:58 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2012-12-20 18:19 - 2012-12-20 18:19 - 00479752 _____ () C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\dblite.dll
2012-12-20 18:20 - 2012-12-20 18:20 - 00068616 _____ () C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\QtWebKit\qmlwebkitplugin4.dll
2014-06-10 14:49 - 2012-04-30 11:57 - 00039936 _____ () C:\Program Files\Sony\Sony PC Companion\TMonitorAPI.dll
2014-06-10 14:49 - 2013-09-13 11:02 - 00208896 _____ () C:\Program Files\Sony\Sony PC Companion\MExplorer.dll
2013-06-11 09:31 - 2013-06-11 09:31 - 00090112 _____ () C:\Program Files\Sony\Sony PC Companion\CalEngine.dll
2012-04-04 14:33 - 2012-04-04 14:33 - 00139776 _____ () C:\Program Files\Sony\Sony PC Companion\CAgdLNotes.dll
2013-01-08 17:02 - 2013-01-08 17:02 - 00163840 _____ () C:\Program Files\Sony\Sony PC Companion\CAgdOutlook.dll
2012-07-26 11:51 - 2012-07-26 11:51 - 00208896 _____ () C:\Program Files\Sony\Sony PC Companion\VistaCalendar.dll
2014-06-10 14:49 - 2010-01-11 16:44 - 00053248 _____ () C:\Program Files\Sony\Sony PC Companion\VObject.dll
2011-01-05 15:01 - 2011-01-05 15:01 - 00053248 _____ () C:\Program Files\Sony\Sony PC Companion\PimNotes.dll
2011-07-07 14:54 - 2011-07-07 14:54 - 00233984 _____ () C:\Program Files\Sony\Sony PC Companion\Report.dll
2014-06-10 14:49 - 2013-05-20 12:58 - 00620718 _____ () C:\Program Files\Sony\Sony PC Companion\sqlite3.dll
2014-06-12 10:19 - 2014-06-12 10:19 - 00643584 _____ () C:\Program Files\Sony\Sony PC Companion\PhoneUpdate.dll
2012-06-26 14:11 - 2012-06-26 14:11 - 02302040 _____ () C:\Program Files\Nokia\Nokia PC Suite 7\QtCore4.dll
2012-06-26 14:11 - 2012-06-26 14:11 - 08197208 _____ () C:\Program Files\Nokia\Nokia PC Suite 7\QtGui4.dll
2012-06-26 14:11 - 2012-06-26 14:11 - 00345688 _____ () C:\Program Files\Nokia\Nokia PC Suite 7\QtXml4.dll
2012-06-26 14:10 - 2012-06-26 14:10 - 00202328 _____ () C:\Program Files\Nokia\Nokia PC Suite 7\imageformats\qjpeg4.dll
2012-06-26 14:10 - 2012-06-26 14:10 - 00027736 _____ () C:\Program Files\Nokia\Nokia PC Suite 7\imageformats\qsvg4.dll
2012-06-26 14:11 - 2012-06-26 14:11 - 00282200 _____ () C:\Program Files\Nokia\Nokia PC Suite 7\QtSvg4.dll
2014-06-10 14:49 - 2013-10-31 12:35 - 00070880 _____ () C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
2012-12-20 18:19 - 2012-12-20 18:19 - 01310728 _____ () C:\Program Files\Kaspersky Lab\Kaspersky PURE 3.0\kpcengine.2.2.dll
2013-08-09 15:07 - 2010-06-30 19:02 - 00242688 _____ () C:\Program Files\MD Touch Mini\MD Touch MiniAssistantServices.exe
2013-10-17 15:27 - 2013-10-17 15:27 - 00166912 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
2011-05-08 01:04 - 2011-05-08 01:04 - 00160256 _____ () C:\Program Files\Tftpd32_SE\tftpd32_svc.exe
2013-04-12 13:51 - 2010-06-01 10:17 - 00929792 _____ () C:\Program Files\Yahoo!\Messenger\yui.dll
2008-08-21 15:00 - 2008-08-21 15:00 - 00059904 _____ () C:\WINDOWS\system32\devenum.dll
2008-08-21 15:00 - 2008-08-21 15:00 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll
2014-07-22 10:42 - 2014-07-15 12:24 - 08537928 _____ () C:\Program Files\Google\Chrome\Application\36.0.1985.125\pdf.dll
2014-07-22 10:42 - 2014-07-15 12:24 - 00353096 _____ () C:\Program Files\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll
2014-07-22 10:42 - 2014-07-15 12:24 - 01732936 _____ () C:\Program Files\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupreg: H/PC Connection Agent => "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
MSCONFIG\startupreg: KiesPreload => C:\Program Files\Samsung\Kies\Kies.exe /preload
MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: PC Suite Tray => "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
MSCONFIG\startupreg: RIMBBLaunchAgent.exe => C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
 
==================== Faulty Device Manager Devices =============
 
Name: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
Description: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
Class Guid: {4D36E96B-E325-11CE-BFC1-08002BE10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: Nokia 6300
Description: Nokia Windows Portable Device Driver
Class Guid: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Manufacturer: Nokia
Service: WUDFRd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Nokia 200
Description: Nokia Windows Portable Device Driver
Class Guid: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Manufacturer: Nokia
Service: WUDFRd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Nokia 6500c
Description: Nokia Windows Portable Device Driver
Class Guid: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Manufacturer: Nokia
Service: WUDFRd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: C2-06
Description: Nokia Windows Portable Device Driver
Class Guid: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Manufacturer: Nokia
Service: WUDFRd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Nokia 201
Description: Nokia 201
Class Guid: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Manufacturer: Nokia
Service: WUDFRd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/05/2014 10:13:47 AM) (Source: MsiInstaller) (EventID: 1023) (User: NT AUTHORITY)
Description: Product: Kaspersky PURE 3.0 - Update 'Kaspersky PURE 3.0 (Patch f)' could not be installed. Error code 1603. Additional information is available in the log file C:\WINDOWS\TEMP\MSIfdd0d.LOG.
 
Error: (08/05/2014 10:13:47 AM) (Source: MsiInstaller) (EventID: 1013) (User: NT AUTHORITY)
Description: Application: Kaspersky PURE 3.0 -- You must reboot your computer before proceeding with the installation.
 
Error: (07/02/2014 05:41:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application explorer.exe, version 6.0.2900.5512, faulting module ntdll.dll, version 5.1.2600.6055, fault address 0x00011780.
Processing media-specific event for [explorer.exe!ws!]
 
Error: (07/01/2014 03:52:11 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 rim.desktop.exe, P2 7.1.0.41, P3 51390cf9, P4 rim.desktop.datasync.pisynchfacade, P5 7.1.0.38, P6 51391cda, P7 ff, P8 25, P9 clr20r30, P10 clr20r31.
 
Error: (06/24/2014 10:50:20 AM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 rim.desktop.exe, P2 7.1.0.41, P3 51390cf9, P4 rim.desktop.datasync.pisynchfacade, P5 7.1.0.38, P6 51391cda, P7 ff, P8 25, P9 clr20r30, P10 clr20r31.
 
Error: (06/18/2014 06:03:21 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 rim.desktop.exe, P2 7.1.0.41, P3 51390cf9, P4 rim.desktop.datasync.pisynchfacade, P5 7.1.0.38, P6 51391cda, P7 ff, P8 25, P9 clr20r30, P10 clr20r31.
 
Error: (06/12/2014 00:36:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application amdo.exe, version 1.0.0.8793, faulting module unknown, version 0.0.0.0, fault address 0x033404fa.
Processing media-specific event for [amdo.exe!ws!]
 
Error: (05/19/2014 07:36:44 PM) (Source: .NET Runtime 2.0 Error Reporting) (EventID: 5000) (User: )
Description: EventType clr20r3, P1 kies.exe, P2 1.0.0.1521, P3 52a83550, P4 mscorlib, P5 2.0.0.0, P6 5266e591, P7 f4f, P8 7, P9 clr20r30, P10 clr20r31.
 
Error: (04/30/2014 06:00:14 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application LGETool.exe, version 2.36.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
 
Error: (04/17/2014 11:04:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application explorer.exe, version 6.0.2900.5512, faulting module portabledevicetypes.dll, version 5.2.5721.5262, fault address 0x0000794c.
Processing media-specific event for [explorer.exe!ws!]
 
 
System errors:
=============
Error: (08/05/2014 02:00:23 PM) (Source: 0) (EventID: 55) (User: )
Description: D:
 
Error: (08/05/2014 02:00:23 PM) (Source: 0) (EventID: 55) (User: )
Description: D:
 
Error: (08/05/2014 09:23:10 AM) (Source: 0) (EventID: 55) (User: )
Description: D:
 
Error: (08/05/2014 09:23:10 AM) (Source: 0) (EventID: 55) (User: )
Description: D:
 
Error: (08/04/2014 09:25:03 PM) (Source: 0) (EventID: 55) (User: )
Description: D:
 
Error: (08/04/2014 09:25:03 PM) (Source: 0) (EventID: 55) (User: )
Description: D:
 
Error: (08/04/2014 05:43:54 PM) (Source: DCOM) (EventID: 10010) (User: RADU-CEL-FRUMOS)
Description: The server {063D34A4-BF84-4B8D-B699-E8CA06504DDE} did not register with DCOM within the required timeout.
 
Error: (08/04/2014 05:43:26 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The iPod Service service terminated with the following error: 
%%2147549465
 
Error: (08/04/2014 05:43:16 PM) (Source: 0) (EventID: 55) (User: )
Description: D:
 
Error: (08/04/2014 05:43:16 PM) (Source: 0) (EventID: 55) (User: )
Description: D:
 
 
Microsoft Office Sessions:
=========================
 
==================== Memory info =========================== 
 
Percentage of memory in use: 51%
Total physical RAM: 2038.11 MB
Available physical RAM: 998.29 MB
Total Pagefile: 3925.85 MB
Available Pagefile: 3042.85 MB
Total Virtual: 2047.88 MB
Available Virtual: 1931.66 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:117.19 GB) (Free:42.6 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:180.89 GB) (Free:104.42 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 298 GB) (Disk ID: 43A0439F)
Partition 1: (Active) - (Size=117 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=181 GB) - (Type=OF Extended)
 Could not read MBR for disk 1.
 
==================== End Of Log ============================

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP