
winlogon.exe;
OTS logfile created on: 2014-05-19 21:07:29 - Run 1
OTS by OldTimer - Version 3.1.47.2 Folder = C:\Users\ja\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17041)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 51,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 50,55 Gb Total Space | 19,78 Gb Free Space | 39,13% Space Free | Partition Type: NTFS
Drive D: | 288,09 Gb Total Space | 208,41 Gb Free Space | 72,34% Space Free | Partition Type: NTFS
Drive E: | 288,09 Gb Total Space | 191,75 Gb Free Space | 66,56% Space Free | Partition Type: NTFS
Drive F: | 304,69 Gb Total Space | 214,39 Gb Free Space | 70,36% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JA-KOMPUTER
Current User Name: ja
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - Safe List]
ots.exe -> C:\Users\ja\Desktop\OTS.exe -> [2014-05-19 21:06:33 | 000,646,656 | ---- | M] (OldTimer Tools)
opera_crashreporter.exe -> C:\Program Files (x86)\Opera\21.0.1432.67\opera_crashreporter.exe -> [2014-05-12 07:51:50 | 001,397,880 | ---- | M] ()
opera.exe -> C:\Program Files (x86)\Opera\21.0.1432.67\opera.exe -> [2014-05-12 07:51:48 | 045,754,488 | ---- | M] (Opera Software)
avastui.exe -> C:\Program Files\AVAST Software\Avast\AvastUI.exe -> [2014-05-02 19:35:26 | 003,873,704 | ---- | M] (AVAST Software)
avastsvc.exe -> C:\Program Files\AVAST Software\Avast\AvastSvc.exe -> [2014-05-02 19:35:23 | 000,050,344 | ---- | M] (AVAST Software)
armsvc.exe -> C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -> [2013-12-21 08:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated)
iastoricon.exe -> C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe -> [2013-04-30 12:25:22 | 000,286,704 | ---- | M] (Intel Corporation)
iastordatamgrsvc.exe -> C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -> [2013-04-30 12:25:22 | 000,015,344 | ---- | M] (Intel Corporation)
iusb3mon.exe -> C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe -> [2013-04-26 04:25:54 | 000,292,848 | R--- | M] (Intel Corporation)
lms.exe -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -> [2013-04-11 15:30:58 | 000,366,552 | ---- | M] (Intel Corporation)
jhi_service.exe -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -> [2013-04-11 15:30:22 | 000,169,432 | ---- | M] (Intel Corporation)
usb3monitor.exe -> C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe -> [2011-07-12 16:14:26 | 000,331,776 | ---- | M] (VIA Technologies, Inc.)
bluetoothheadsetproxy.exe -> D:\Programy Files\Bluetooth\BluetoothHeadsetProxy.exe -> [2011-01-24 14:28:10 | 000,013,600 | ---- | M] (Broadcom Corporation.)
brmfcmon.exe -> C:\Program Files (x86)\Brother\Brmfcmon\BrMfcMon.exe -> [2009-03-30 16:00:54 | 000,221,184 | ---- | M] (Brother Industries, Ltd.)
[Modules - No Company Name]
npswf32_13_0_0_214.dll -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll -> [2014-05-13 22:22:15 | 016,361,136 | ---- | M] ()
libglesv2.dll -> C:\Program Files (x86)\Opera\21.0.1432.67\libGLESv2.dll -> [2014-05-12 07:51:55 | 000,877,688 | ---- | M] ()
libegl.dll -> C:\Program Files (x86)\Opera\21.0.1432.67\libEGL.dll -> [2014-05-12 07:51:54 | 000,135,800 | ---- | M] ()
ffmpegsumo.dll -> C:\Program Files (x86)\Opera\21.0.1432.67\ffmpegsumo.dll -> [2014-05-12 07:51:52 | 000,957,048 | ---- | M] ()
opera_crashreporter.exe -> C:\Program Files (x86)\Opera\21.0.1432.67\opera_crashreporter.exe -> [2014-05-12 07:51:50 | 001,397,880 | ---- | M] ()
system.servicemodel.web.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servf73e6522#\0bedc417d3c5dcb1c9a5f15dd733c556\System.ServiceModel.Web.ni.dll -> [2014-02-28 18:26:21 | 001,091,072 | ---- | M] ()
system.servicemodel.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\24bf0c88c0465485f4b842df043b3f45\System.ServiceModel.ni.dll -> [2014-02-28 18:26:17 | 019,693,056 | ---- | M] ()
system.identitymodel.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\1e5e19d119e04b93da3d45153abd60fd\System.IdentityModel.ni.dll -> [2014-02-28 18:26:03 | 002,997,760 | ---- | M] ()
system.windows.forms.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f4f6ee0df2aa4189bf36e6335cb92761\System.Windows.Forms.ni.dll -> [2014-02-28 01:03:23 | 012,894,208 | ---- | M] ()
system.xaml.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\3fe705796c6a41d4889d9001d1c56af8\System.Xaml.ni.dll -> [2014-02-28 01:03:21 | 001,889,792 | ---- | M] ()
system.drawing.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\5cd2aee5e7c07227c694d89219688ab3\System.Drawing.ni.dll -> [2014-02-28 01:03:16 | 001,644,544 | ---- | M] ()
system.servicemodel.internals.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\34b53ecafa1d7ccc7ca961d722b5d983\System.ServiceModel.Internals.ni.dll -> [2014-02-28 01:03:15 | 000,806,400 | ---- | M] ()
smdiagnostics.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\78652b7fa68ee058bff6a118c657f565\SMDiagnostics.ni.dll -> [2014-02-28 01:03:15 | 000,122,880 | ---- | M] ()
system.xml.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bada32953bb6b16a53d653eae23d78dc\System.Xml.ni.dll -> [2014-02-28 01:03:13 | 007,662,080 | ---- | M] ()
system.core.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\dce99d8de14d8a015313db98c72552ee\System.Core.ni.dll -> [2014-02-28 01:03:13 | 006,990,336 | ---- | M] ()
system.runtime.serialization.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\f6d7bb59f318c130d68816a89335d05e\System.Runtime.Serialization.ni.dll -> [2014-02-28 01:03:13 | 002,825,216 | ---- | M] ()
system.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ff26cc03e6d57d8abd13b990332e67c6\System.ni.dll -> [2014-02-28 01:03:09 | 010,060,800 | ---- | M] ()
system.configuration.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\bbc48ec4245e502ae19b0601d3799c9e\System.Configuration.ni.dll -> [2014-02-28 01:03:09 | 000,976,384 | ---- | M] ()
mscorlib.ni.dll -> C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll -> [2014-02-28 01:03:05 | 016,953,856 | ---- | M] ()
libcef.dll -> C:\Program Files\AVAST Software\Avast\libcef.dll -> [2013-12-13 22:44:26 | 019,336,120 | ---- | M] ()
brlogapi.dll -> C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll -> [2009-02-27 17:38:20 | 000,139,264 | R--- | M] ()
[Win32 Services - Safe List]
64bit-(avast! Antivirus) [Auto | Running] -> C:\Program Files\AVAST Software\Avast\AvastSvc.exe -> [2014-05-02 19:35:23 | 000,050,344 | ---- | M] (AVAST Software)
64bit-(IEEtwCollectorService) [On_Demand | Stopped] -> C:\Windows\SysNative\IEEtwCollector.exe -> [2014-03-06 10:29:14 | 000,111,616 | ---- | M] (Microsoft Corporation)
64bit-(WinDefend) [Auto | Running] -> C:\Program Files\Windows Defender\MpSvc.dll -> [2013-05-27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation)
64bit-(IAStorDataMgrSvc) [Auto | Running] -> C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -> [2013-04-30 12:25:22 | 000,015,344 | ---- | M] (Intel Corporation)
64bit-(Intel(R) Capability Licensing Service TCP IP Interface) [On_Demand | Stopped] -> C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe -> [2013-02-13 12:47:04 | 000,820,184 | ---- | M] (Intel(R) Corporation)
64bit-(Intel(R) Capability Licensing Service Interface) [Auto | Running] -> C:\Program Files\Intel\iCLS Client\HeciServer.exe -> [2013-02-13 12:46:48 | 000,731,648 | ---- | M] (Intel(R) Corporation)
64bit-(AppMgmt) [On_Demand | Stopped] -> C:\Windows\SysNative\appmgmts.dll -> [2009-07-14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation)
(AdobeFlashPlayerUpdateSvc) Adobe Flash Player Update Service [On_Demand | Stopped] -> C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -> [2014-05-13 22:22:16 | 000,257,712 | ---- | M] (Adobe Systems Incorporated)
(MozillaMaintenance) Mozilla Maintenance Service [On_Demand | Stopped] -> C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -> [2014-05-10 16:26:23 | 000,119,408 | ---- | M] (Mozilla Foundation)
(AdobeARMservice) Adobe Acrobat Update Service [Auto | Running] -> C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -> [2013-12-21 08:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated)
(cphs) Intel(R) Content Protection HECI Service [On_Demand | Stopped] -> C:\Windows\SysWOW64\IntelCpHeciSvc.exe -> [2013-11-19 04:21:53 | 000,279,024 | ---- | M] (Intel Corporation)
(SkypeUpdate) Skype Updater [Auto | Stopped] -> C:\Program Files (x86)\Skype\Updater\Updater.exe -> [2013-10-23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies)
(clr_optimization_v4.0.30319_32) Microsoft .NET Framework NGEN v4.0.30319_X86 [Auto | Stopped] -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -> [2013-09-11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation)
(LMS) Intel(R) Management and Security Application Local Management Service [Auto | Running] -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -> [2013-04-11 15:30:58 | 000,366,552 | ---- | M] (Intel Corporation)
(jhi_service) Intel(R) Dynamic Application Loader Host Interface Service [Auto | Running] -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -> [2013-04-11 15:30:22 | 000,169,432 | ---- | M] (Intel Corporation)
(btwdins) Bluetooth Service [Auto | Running] -> D:\Programy Files\Bluetooth\btwdins.exe -> [2011-01-24 14:28:10 | 000,915,232 | ---- | M] (Broadcom Corporation.)
(clr_optimization_v2.0.50727_32) Microsoft .NET Framework NGEN v2.0.50727_X86 [Disabled | Stopped] -> C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation)
[Driver Services - Safe List]
64bit-(aswSnx) aswSnx [File_System | System | Running] -> C:\Windows\SysNative\drivers\aswsnx.sys -> [2014-05-15 20:29:17 | 001,039,096 | ---- | M] (AVAST Software)
64bit-(aswSP) aswSP [File_System | System | Running] -> C:\Windows\SysNative\drivers\aswsp.sys -> [2014-05-15 20:29:17 | 000,423,240 | ---- | M] (AVAST Software)
64bit-(aswStm) aswStm [Kernel | Auto | Stopped] -> C:\Windows\SysNative\drivers\aswstm.sys -> [2014-05-15 20:29:16 | 000,085,328 | ---- | M] (AVAST Software)
64bit-(aswVmm) avast! VM Monitor [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\aswVmm.sys -> [2014-05-02 19:36:01 | 000,208,416 | ---- | M] ()
64bit-(aswMonFlt) aswMonFlt [File_System | Auto | Running] -> C:\Windows\SysNative\drivers\aswMonFlt.sys -> [2014-05-02 19:36:01 | 000,079,184 | ---- | M] (AVAST Software)
64bit-(aswRvrt) avast! Revert [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\aswRvrt.sys -> [2014-05-02 19:36:01 | 000,065,776 | ---- | M] ()
64bit-(aswHwid) avast! HardwareID [Kernel | Auto | Running] -> C:\Windows\SysNative\drivers\aswHwid.sys -> [2014-05-02 19:36:01 | 000,029,208 | ---- | M] ()
64bit-(aswRdr) aswRdr [Kernel | System | Running] -> C:\Windows\SysNative\drivers\aswRdr2.sys -> [2014-05-02 19:35:59 | 000,093,568 | ---- | M] (AVAST Software)
64bit-(IntcDAud) Audio dla wyświetlaczy Intel(R) [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\IntcDAud.sys -> [2013-11-13 17:39:30 | 000,449,496 | ---- | M] (Intel(R) Corporation)
64bit-(igfx) igfx [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\igdkmd64.sys -> [2013-11-13 17:34:47 | 004,208,640 | ---- | M] (Intel Corporation)
64bit-(usbser) USB Modem Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\usbser.sys -> [2013-08-29 03:29:52 | 000,033,280 | ---- | M] (Microsoft Corporation)
64bit-(iaStorA) iaStorA [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\iaStorA.sys -> [2013-04-30 12:25:00 | 000,677,360 | ---- | M] (Intel Corporation)
64bit-(iaStorF) iaStorF [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\iaStorF.sys -> [2013-04-30 12:25:00 | 000,028,656 | ---- | M] (Intel Corporation)
64bit-(iusb3hcs) Sterownik przełącznika kontrolera hosta Intel(R) USB 3.0 [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\iusb3hcs.sys -> [2013-04-26 04:24:58 | 000,020,464 | ---- | M] (Intel Corporation)
64bit-(iusb3xhc) Sterownik kontrolera hosta Intel(R) USB 3.0 eXtensible [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\iusb3xhc.sys -> [2013-04-26 04:24:56 | 000,786,416 | ---- | M] (Intel Corporation)
64bit-(iusb3hub) Sterownik koncentratora Intel(R) USB 3.0 [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\iusb3hub.sys -> [2013-04-26 04:24:56 | 000,368,112 | ---- | M] (Intel Corporation)
64bit-(MEIx64) Intel(R) Management Engine Interface [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\HECIx64.sys -> [2013-04-11 15:30:22 | 000,064,624 | ---- | M] (Intel Corporation)
64bit-(VUSB3HUB) VIA USB 3 Root Hub Service [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\ViaHub3.sys -> [2013-03-19 17:04:36 | 000,223,744 | ---- | M] (VIA Technologies, Inc.)
64bit-(xhcdrv) VIA USB eXtensible Host Controller Service [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\xhcdrv.sys -> [2013-03-19 17:04:30 | 000,295,424 | ---- | M] (VIA Technologies, Inc.)
64bit-(RTL8167) Realtek 8167 NT Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\Rt64win7.sys -> [2012-10-25 11:20:28 | 000,769,168 | ---- | M] (Realtek )
64bit-(amdsata) amdsata [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\amdsata.sys -> [2011-03-11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices)
64bit-(amdxata) amdxata [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\amdxata.sys -> [2011-03-11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices)
64bit-(RdpVideoMiniport) Remote Desktop Video Miniport Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\rdpvideominiport.sys -> [2010-11-20 13:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation)
64bit-(HpSAMD) HpSAMD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\HpSAMD.sys -> [2010-11-20 06:33:36 | 000,078,720 | ---- | M] (Hewlett-Packard Company)
64bit-(TsUsbFlt) TsUsbFlt [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\TsUsbFlt.sys -> [2010-11-20 04:07:06 | 000,059,392 | ---- | M] (Microsoft Corporation)
64bit-(btusbflt) Bluetooth USB Filter [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\btusbflt.sys -> [2010-04-09 00:11:12 | 000,054,824 | ---- | M] (Broadcom Corporation.)
64bit-(btwaudio) Urz¹dzenie dŸwiêkowe Bluetooth [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\btwaudio.sys -> [2010-01-15 14:23:20 | 000,098,344 | ---- | M] (Broadcom Corporation.)
64bit-(btwavdt) Bluetooth AVDT Service [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\btwavdt.sys -> [2010-01-15 14:23:14 | 000,132,648 | ---- | M] (Broadcom Corporation.)
64bit-(btwrchid) btwrchid [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\btwrchid.sys -> [2010-01-15 14:23:10 | 000,021,288 | ---- | M] (Broadcom Corporation.)
64bit-(amdsbs) amdsbs [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\amdsbs.sys -> [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.)
64bit-(LSI_SAS2) LSI_SAS2 [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\lsi_sas2.sys -> [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation)
64bit-(stexstor) stexstor [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\stexstor.sys -> [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology)
64bit-(ebdrv) Broadcom NetXtreme II 10 GigE VBD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\evbda.sys -> [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation)
64bit-(b06bdrv) Broadcom NetXtreme II VBD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\bxvbda.sys -> [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation)
64bit-(b57nd60a) Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\b57nd60a.sys -> [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation)
64bit-(hcw85cir) Hauppauge Consumer Infrared Receiver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\hcw85cir.sys -> [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.)
64bit-(btwl2cap) Bluetooth L2CAP Service [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\btwl2cap.sys -> [2009-04-07 15:33:08 | 000,035,104 | ---- | M] (Broadcom Corporation.)
(WIMMount) WIMMount [File_System | On_Demand | Stopped] -> C:\Windows\SysWOW64\drivers\wimmount.sys -> [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation)
[Registry - Safe List]
< 64bit-Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\Windows\SysWOW64\blank.htm ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\] > -> ->
HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\: Main\\"Start Page" -> http://msn.gazeta.pl/msn/0,0.html?pc=UP97&ocid=UP97DHP ->
HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\: "ProxyEnable" -> 0 ->
< FireFox Settings [Prefs.js] > -> C:\Users\ja\AppData\Roaming\Mozilla\FireFox\Profiles\nzel01wv.default\prefs.js ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions -> ->
HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com -> C:\Program Files\AVAST Software\Avast\WebRep\FF [C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF] -> [2014-05-02 19:36:05 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 29.0.1\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS ->
HKLM\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS ->
< FireFox Extensions [User Folders] > ->
-> C:\Users\ja\AppData\Roaming\mozilla\Extensions -> [2014-04-18 17:22:25 | 000,000,000 | ---D | M]
-> C:\Users\ja\AppData\Roaming\mozilla\Firefox\Profiles\nzel01wv.default\extensions -> [2014-05-02 19:15:47 | 000,000,000 | ---D | M]
< FireFox Extensions [Program Folders] > ->
-> C:\Program Files (x86)\Mozilla Firefox\browser\extensions -> [2014-05-10 16:26:17 | 000,000,000 | ---D | M]
Default -> C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2014-05-10 16:26:25 | 000,000,000 | ---D | M]
< HOSTS File > ([2014-05-18 16:18:19 | 000,000,027 | ---- | M] - 1 lines) -> C:\Windows\SysNative\Drivers\etc\hosts ->
Reset Hosts
127.0.0.1 localhost
< 64bit-BHO's [HKEY_LOCAL_MACHINE] > -> 64bit-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} [HKLM] -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [avast! Online Security] -> [2014-05-02 19:35:18 | 000,581,824 | ---- | M] (AVAST Software)
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> D:\Programy Files\Jawa\bin\ssv.dll [Java(tm) Plug-In SSV Helper] -> [2014-04-14 20:11:29 | 000,462,760 | ---- | M] (Oracle Corporation)
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} [HKLM] -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [avast! Online Security] -> [2014-05-02 19:35:17 | 000,436,600 | ---- | M] (AVAST Software)
{B4F3A835-0E21-4959-BA22-42B3008E02FF} [HKLM] -> D:\Programy Files\word2010\Office14\URLREDIR.DLL [Office Document Cache Handler] -> [2010-02-28 03:20:14 | 000,561,552 | ---- | M] (Microsoft Corporation)
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> D:\Programy Files\Jawa\bin\jp2ssv.dll [Java(tm) Plug-In 2 SSV Helper] -> [2014-04-14 20:07:46 | 000,171,944 | ---- | M] (Oracle Corporation)
< 64bit-Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< 64bit-Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"HotKeysCmds" -> C:\Windows\SysNative\hkcmd.exe ["C:\Windows\system32\hkcmd.exe"] -> [2013-11-19 04:21:48 | 000,771,056 | ---- | M] (Intel Corporation)
"IAStorIcon" -> C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe ["C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60] -> [2013-04-30 12:27:00 | 000,036,352 | ---- | M] (Intel Corporation)
"IgfxTray" -> C:\Windows\SysNative\igfxtray.exe ["C:\Windows\system32\igfxtray.exe"] -> [2013-11-19 04:21:51 | 000,391,152 | ---- | M] (Intel Corporation)
"Persistence" -> C:\Windows\SysNative\igfxpers.exe ["C:\Windows\system32\igfxpers.exe"] -> [2013-11-19 04:21:49 | 000,770,032 | ---- | M] (Intel Corporation)
"RtHDVCpl" -> C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s] -> [2013-02-26 16:16:50 | 013,423,688 | ---- | M] (Realtek Semiconductor)
"VIAxHCUtl" -> C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe [C:\Program Files\VIA XHCI UASP Utility\usb3Monitor] -> [2011-07-12 16:14:26 | 000,331,776 | ---- | M] (VIA Technologies, Inc.)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"AvastUI.exe" -> C:\Program Files\AVAST Software\Avast\AvastUI.exe ["C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui] -> [2014-05-02 19:35:26 | 003,873,704 | ---- | M] (AVAST Software)
"ControlCenter3" -> C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun] -> [2008-12-24 11:26:54 | 000,114,688 | ---- | M] (Brother Industries, Ltd.)
"USB3MON" -> C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe ["C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"] -> [2013-04-26 04:25:54 | 000,292,848 | R--- | M] (Intel Corporation)
< Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< Software Policy Settings [HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000] > -> HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDrives" -> [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"ConsentPromptBehaviorAdmin" -> [0] -> File not found
\\"ConsentPromptBehaviorUser" -> [3] -> File not found
\\"EnableLUA" -> [0] -> File not found
\\"PromptOnSecureDesktop" -> [0] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000] > -> HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
\\"NoDrives" -> [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000] > -> HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< 64bit-Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\] > -> HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&ksportuj do programu Microsoft Excel -> D:\Programy Files\word2010\Office14\EXCEL.EXE [res://D:\PROGRA~1\word2010\Office14\EXCEL.EXE/3000] -> [2010-03-13 15:53:52 | 020,753,760 | ---- | M] (Microsoft Corporation)
Wyślij obraz do urządzenia &Bluetooth... -> D:\Programy Files\Bluetooth\btsendto_ie_ctx.htm [D:\Programy Files\Bluetooth\btsendto_ie_ctx.htm] -> [2008-12-10 11:36:32 | 000,001,430 | ---- | M] ()
Wyślij stronę do urządzenia &Bluetooth... -> D:\Programy Files\Bluetooth\btsendto_ie.htm [D:\Programy Files\Bluetooth\btsendto_ie.htm] -> [2009-08-28 19:17:14 | 000,004,037 | ---- | M] ()
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\] > -> HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&ksportuj do programu Microsoft Excel -> D:\Programy Files\word2010\Office14\EXCEL.EXE [res://D:\PROGRA~1\word2010\Office14\EXCEL.EXE/3000] -> [2010-03-13 15:53:52 | 020,753,760 | ---- | M] (Microsoft Corporation)
Wyślij obraz do urządzenia &Bluetooth... -> D:\Programy Files\Bluetooth\btsendto_ie_ctx.htm [D:\Programy Files\Bluetooth\btsendto_ie_ctx.htm] -> [2008-12-10 11:36:32 | 000,001,430 | ---- | M] ()
Wyślij stronę do urządzenia &Bluetooth... -> D:\Programy Files\Bluetooth\btsendto_ie.htm [D:\Programy Files\Bluetooth\btsendto_ie.htm] -> [2009-08-28 19:17:14 | 000,004,037 | ---- | M] ()
< 64bit-Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{CCA281CA-C863-46ef-9331-5C8D4460577F}:D:\Programy Files\Bluetooth\btsendto_ie.htm [HKLM] -> D:\Programy Files\Bluetooth\btsendto_ie.htm [Button: @D:\Programy Files\Bluetooth\btrez.dll,-4015] -> [2009-08-28 19:17:14 | 000,004,037 | ---- | M] ()
{CCA281CA-C863-46ef-9331-5C8D4460577F}:D:\Programy Files\Bluetooth\btsendto_ie.htm [HKLM] -> D:\Programy Files\Bluetooth\btsendto_ie.htm [Menu: @D:\Programy Files\Bluetooth\btrez.dll,-12650] -> [2009-08-28 19:17:14 | 000,004,037 | ---- | M] ()
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{CCA281CA-C863-46ef-9331-5C8D4460577F}:D:\Programy Files\Bluetooth\btsendto_ie.htm [HKLM] -> D:\Programy Files\Bluetooth\btsendto_ie.htm [Button: Wyślij do interfejsu Bluetooth] -> [2009-08-28 19:17:14 | 000,004,037 | ---- | M] ()
{CCA281CA-C863-46ef-9331-5C8D4460577F}:D:\Programy Files\Bluetooth\btsendto_ie.htm [HKLM] -> D:\Programy Files\Bluetooth\btsendto_ie.htm [Menu: Wyślij do urządzenia &Bluetooth...] -> [2009-08-28 19:17:14 | 000,004,037 | ---- | M] ()
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\] > -> HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\Software\Microsoft\Internet Explorer\Extensions\ ->
64bit-CmdMapping\\"{CCA281CA-C863-46ef-9331-5C8D4460577F}" [HKLM] -> [@D:\Programy Files\Bluetooth\btrez.dll,-4015;Wyślij do interfejsu Bluetooth] -> File not found
CmdMapping\\"{CCA281CA-C863-46ef-9331-5C8D4460577F}" [HKLM] -> @D:\Programy Files\Bluetooth\btrez.dll,-4015 [Wyślij do interfejsu Bluetooth;@D:\Programy Files\Bluetooth\btrez.dll,-4015;Wyślij do interfejsu Bluetooth] -> File not found
< 64bit-Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
< 64bit-Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< 64bit-Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< 64bit-Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\] > -> HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\] > -> HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.1.1 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{81AD5B6C-36DD-4DAC-8D04-BAD0CF330341}\\DhcpNameServer -> 192.168.1.1 (Realtek PCIe GBE Family Controller) ->
< 64bit-Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
64bit-*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> C:\Windows\explorer.exe -> [2011-02-25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
64bit-*UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit ->
C:\Windows\system32\userinit.exe -> C:\Windows\SysNative\userinit.exe -> [2010-11-20 06:25:26 | 000,030,720 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
64bit-*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
SystemPropertiesPerformance.exe -> C:\Windows\SysNative\SystemPropertiesPerformance.exe -> [2009-07-14 03:39:47 | 000,082,432 | ---- | M] (Microsoft Corporation)
/pagefile -> -> File not found
*MultiFile Done* -> ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2011-02-25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
*UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit ->
C:\Windows\system32\userinit.exe -> C:\Windows\SysWOW64\userinit.exe -> [2010-11-20 05:17:50 | 000,026,624 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
/pagefile -> -> File not found
*MultiFile Done* -> ->
< 64bit-Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
igfxcui -> C:\Windows\SysNative\igfxdev.dll -> [2013-11-13 17:34:42 | 000,624,640 | ---- | M] (Intel Corporation)
< 64bit-SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad ->
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck] -> File not found
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad ->
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck] -> File not found
< Vista Public Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications ->
< Vista Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications ->
< Vista Active Firewall Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules ->
{005A9446-CA87-4002-A99D-904D00110459} -> rport=2177 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31257 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{2254E1FC-4EDC-4C12-8FEC-8440C349C9BE} -> rport=137 | profile=public | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28523 | app=system |
{30B2DD3E-906D-4097-B678-AAF85CCCF138} -> lport=2177 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31253 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{404830C0-A5E1-4965-AB4A-FF2E32936CDD} -> lport=1900 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31269 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv |
{452E4258-57B1-47E8-9BC4-2777B360548A} -> lport=445 | profile=public | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28511 | app=system |
{5A24A53F-C67D-42BE-A4CB-D4F4B8B555E7} -> rport=5355 | profile=public | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28550 | app=%systemroot%\system32\svchost.exe | svc=dnscache |
{6D968723-4E2B-4A4F-AE93-17DB9A738506} -> lport=10243 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31285 | app=system |
{7F9DD15C-AD0C-4A6A-A591-245C25F9C690} -> rport=10243 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31289 | app=system |
{80A976EE-FB1A-4E1A-A24F-2F4D4B0FC4BF} -> rport=445 | profile=public | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-28515 | app=system |
{8B2CB9BD-F1EE-4534-9DED-83BC49D432F4} -> lport=2869 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31277 | app=system |
{A3E3C355-6E61-4ACE-974B-D87F3C7DC92D} -> rport=5355 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28550 | app=%systemroot%\system32\svchost.exe | svc=dnscache |
{A3F4EEED-A1F3-40E4-A11D-A3A54C7447FF} -> lport=5355 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28548 | app=%systemroot%\system32\svchost.exe | svc=dnscache |
{A46C9382-C7E5-4F64-91E8-59E04C3843E8} -> rport=2177 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31265 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{B9937DA6-762B-41F4-A18C-5D4360AC3CBE} -> rport=1900 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31273 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv |
{BB0B0383-4DA8-4CFA-8372-A48ADF8EDC80} -> lport=139 | profile=public | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28503 | app=system |
{BC64E274-070D-4855-A2C8-2F6D7650E84B} -> lport=138 | profile=public | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28527 | app=system |
{BF80EE67-0D0F-4747-B93A-BE418AEDC9C4} -> rport=138 | profile=public | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28531 | app=system |
{D36A8F71-C970-4E3B-8328-B6029B488A39} -> rport=139 | profile=public | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-28507 | app=system |
{D96E6898-1FAF-4C8B-8839-56C6FAF8CA82} -> lport=rpc | profile=public | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28535 | app=%systemroot%\system32\spoolsv.exe | svc=spooler |
{DB4ECAFC-D62A-4464-8161-353F616FE4FE} -> lport=137 | profile=public | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28519 | app=system |
{DCF4E33C-B1BE-4A98-A753-40A126BD2D52} -> lport=2177 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31261 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{F4BB757E-11F4-476F-817F-E525FEDE5ECF} -> lport=5355 | profile=public | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28548 | app=%systemroot%\system32\svchost.exe | svc=dnscache |
{F8D903A3-D016-457D-B487-5252C1E068CD} -> lport=rpc-epmap | profile=public | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28539 | svc=rpcss |
< Vista Active Application Exception Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules ->
{0160D382-FFD0-4619-8F60-28AE0E3A5F3A} -> profile=public | protocol=6 | dir=in | action=allow | name=tom clancy's splinter cell® blacklist™ dx9 | app=d:\games\scbl\src\system\blacklist_game.exe |
{05AE4189-7088-4F7C-8E41-E12B2B353BF5} -> profile=public | protocol=17 | dir=in | action=allow | name=tom clancy's splinter cell® blacklist™ gameupdate | app=d:\games\scbl\src\system\gu.exe |
{07588D75-36CE-4324-A309-4C7E79FD73BA} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31309 | app=%programfiles%\windows media player\wmpnetwk.exe |
{24013C20-8E63-4F48-BEB4-26457CB1EA4C} -> profile=public | protocol=58 | dir=in | action=allow | name=@firewallapi.dll,-28545 |
{2D683A8D-3B98-44C8-AC63-3DE9EAB00EC2} -> profile=public | protocol=6 | dir=in | action=allow | name=aliens vs. predator (dx9) | app=d:\programy files\aliens vs. predator\avp.exe |
{2E01E5C5-F66A-48B7-8762-05EC944F0EF6} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31297 | app=%programfiles%\windows media player\wmplayer.exe |
{2E58C3BE-D3CD-4D0E-A159-DB25059FBF3D} -> dir=in | action=allow | name=skype | app=c:\program files (x86)\skype\phone\skype.exe |
{2EFB486D-61DC-4BA6-AD89-9F8D9AE91EEA} -> profile=public | protocol=6 | dir=in | action=allow | name=aliens vs. predator (dx11) | app=d:\programy files\aliens vs. predator\avp_dx11.exe |
{3B55A73B-A62D-47B9-B4BA-7F0D4B6CDEBF} -> protocol=6 | dir=in | action=allow | name=μtorrent (tcp-in) | app=c:\users\ja\appdata\roaming\utorrent\utorrent.exe |
{4BAC2442-0703-4D32-928F-DE5F818CCD52} -> profile=public | protocol=1 | dir=in | action=allow | name=@firewallapi.dll,-28543 |
{4BE8478B-892E-4CF8-B4E7-552F6E261F0B} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31007 | app=%programfiles%\windows media player\wmplayer.exe |
{514899F3-CC2D-4A51-8D9E-ECE29BFC1337} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31281 | app=system |
{524C6980-6DEC-4AE5-8775-B285A754483B} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31317 | app=%programfiles%\windows media player\wmpnetwk.exe |
{568E5DAD-2A71-4E13-9E1E-BB95BFB6360D} -> profile=public | protocol=17 | dir=in | action=allow | name=aliens vs. predator (dx9) | app=d:\programy files\aliens vs. predator\avp.exe |
{5A5B9D74-24B5-425E-9761-B6305E99FFA5} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31301 | app=%programfiles%\windows media player\wmplayer.exe |
{5E03A7D6-72F7-49D5-B050-3C292BD6F519} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31293 | app=%programfiles%\windows media player\wmplayer.exe |
{639628BF-AD82-460A-9309-951372A4537A} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31025 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{74BB22D2-4CAB-4B74-AAFB-44998E78CF12} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31003 | app=%programfiles%\windows media player\wmplayer.exe |
{7DC6FD44-81CF-498B-B6C0-01568B972668} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31023 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{80B4742F-D86C-4581-ABB1-A571CBE0298F} -> profile=public | protocol=1 | dir=out | action=allow | name=@firewallapi.dll,-28544 |
{86D267B4-E04E-48E5-A969-82965ED89567} -> profile=public | protocol=17 | dir=in | action=allow | name=aliens vs. predator (dx11) | app=d:\programy files\aliens vs. predator\avp_dx11.exe |
{8E273029-A99A-4B43-B245-6AA4144FD23F} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31011 | app=%programfiles%\windows media player\wmplayer.exe |
{9962B3E6-FC62-4173-BCDB-BB9DBC2649F2} -> profile=public | protocol=17 | dir=in | action=allow | name=tom clancy's splinter cell® blacklist™ dx9 | app=d:\games\scbl\src\system\blacklist_game.exe |
{9CA70082-3A26-4DFA-919C-2AE2EE6B1FC8} -> profile=public | protocol=6 | dir=in | action=allow | name=tom clancy's splinter cell® blacklist™ gameupdate | app=d:\games\scbl\src\system\gu.exe |
{A4828A33-BF6A-4275-A7FA-1173FA9D09EC} -> profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31313 | app=%programfiles%\windows media player\wmpnetwk.exe |
{A60DB168-B92E-40DD-A24E-9E450508F95E} -> protocol=17 | dir=in | action=allow | name=μtorrent (udp-in) | app=c:\users\ja\appdata\roaming\utorrent\utorrent.exe |
{A8816454-7124-4674-85AD-406A77325596} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31305 | app=%programfiles%\windows media player\wmpnetwk.exe |
{AA4D1677-0452-46BE-9DCE-D4A6947A6320} -> profile=public | protocol=17 | dir=in | action=allow | name=tom clancy's splinter cell® blacklist™ dx11 | app=d:\games\scbl\src\system\blacklist_dx11_game.exe |
{B88ED7A0-7E8F-4835-8F99-69240D56FB41} -> profile=public | protocol=58 | dir=out | action=allow | name=@firewallapi.dll,-28546 |
{CF7AE937-7B17-47E9-B338-2881C5293441} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31024 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{D401EC4F-B918-47B9-8F1D-0F28BC35F205} -> profile=public | protocol=6 | dir=in | action=allow | name=tom clancy's splinter cell® blacklist™ launcher | app=d:\games\scbl\blacklist_launcher.exe |
{F0AC5111-824F-48DB-8430-F7DEC7F3C09D} -> profile=public | protocol=6 | dir=in | action=allow | name=blizzard launcher | app=f:\gry\starcraft ii\starcraft ii.exe |
{F9297350-67DD-4ED0-9EAB-1948145F60A2} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31321 | app=%systemroot%\system32\svchost.exe | svc=upnphost |
{FC84B1A0-4C4D-4D3A-B674-0CC8E2064537} -> profile=public | protocol=6 | dir=in | action=allow | name=tom clancy's splinter cell® blacklist™ dx11 | app=d:\games\scbl\src\system\blacklist_dx11_game.exe |
{FEDE6E12-EF4C-476E-B785-E50BEAC4E1AE} -> profile=public | protocol=17 | dir=in | action=allow | name=tom clancy's splinter cell® blacklist™ launcher | app=d:\games\scbl\blacklist_launcher.exe |
{FF24FD1C-C80F-445B-B877-B12A0D71F5B9} -> profile=public | protocol=17 | dir=in | action=allow | name=blizzard launcher | app=f:\gry\starcraft ii\starcraft ii.exe |
TCP Query User{06E92BB6-E39B-4C54-B4E0-7F90197935F5}F:\gry\wot\worldoftanks.exe -> profile=private | protocol=6 | dir=in | action=allow | name=world of tanks | app=f:\gry\wot\worldoftanks.exe |
TCP Query User{0F7D8B0E-F43F-47DF-B3C8-C98C30934D1D}F:\gry\outlast\binaries\win64\olgame_r.exe -> profile=private | protocol=6 | dir=in | action=block | name=outlast | app=f:\gry\outlast\binaries\win64\olgame_r.exe |
TCP Query User{132E35B7-0E91-4FA2-818A-BC7E121CC694}C:\users\ja\appdata\roaming\utorrent\utorrent.exe -> profile=private | protocol=6 | dir=in | action=allow | name=utorrent.exe | app=c:\users\ja\appdata\roaming\utorrent\utorrent.exe |
TCP Query User{1BC9DB21-26E2-43E7-A1E1-AFCA3044553D}F:\gry\starcraft ii\versions\base21029\sc2.exe -> profile=public | protocol=6 | dir=in | action=block | name=starcraft ii | app=f:\gry\starcraft ii\versions\base21029\sc2.exe |
TCP Query User{26EEBEF2-8423-40EA-A91A-2CAB1195314A}F:\gry\wot\worldoftanks.exe -> profile=public | protocol=6 | dir=in | action=allow | name=world of tanks | app=f:\gry\wot\worldoftanks.exe |
TCP Query User{297F7DA5-E440-4BB1-86DA-3DFE857BE3B1}F:\gry\wot\wotlauncher.exe -> profile=private | protocol=6 | dir=in | action=allow | name=world of tanks launcher | app=f:\gry\wot\wotlauncher.exe |
TCP Query User{40F16490-C270-414A-AB4D-3EAD49AC7F95}F:\gry\starcraft ii\support\blizzarddownloader.exe -> profile=public | protocol=6 | dir=in | action=block | name=blizzard downloader | app=f:\gry\starcraft ii\support\blizzarddownloader.exe |
TCP Query User{4EA0374A-80CA-4429-812F-D0AF6182D4D8}D:\games\company of heroes 2\reliccoh2.exe -> profile=private | protocol=6 | dir=in | action=block | name=company of heroes 2 | app=d:\games\company of heroes 2\reliccoh2.exe |
TCP Query User{73A02C7F-D994-407F-BA86-DA89E861E70C}C:\program files (x86)\skype\phone\skype.exe -> profile=private | protocol=6 | dir=in | action=allow | name=skype | app=c:\program files (x86)\skype\phone\skype.exe |
TCP Query User{8884BD82-96D8-4B72-A45B-9E9A149AA340}F:\gry\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe -> profile=public | protocol=6 | dir=in | action=block | name=blizzard downloader | app=f:\gry\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
TCP Query User{9E0DCB81-8D97-4367-9586-F246CAAF3994}C:\users\ja\appdata\roaming\utorrent\utorrent.exe -> profile=public | protocol=6 | dir=in | action=allow | name=utorrent.exe | app=c:\users\ja\appdata\roaming\utorrent\utorrent.exe |
TCP Query User{9EA5FF6E-1B87-4C9F-A426-2693F16C209D}F:\gry\outlast\binaries\win64\olgame.exe -> profile=private | protocol=6 | dir=in | action=allow | name=outlast | app=f:\gry\outlast\binaries\win64\olgame.exe |
TCP Query User{C65CD6B8-05CA-41E0-B6F5-4DF53BE8BF32}F:\gry\wot\wotlauncher.exe -> profile=public | protocol=6 | dir=in | action=allow | name=world of tanks launcher | app=f:\gry\wot\wotlauncher.exe |
TCP Query User{C79AFDD9-9872-4AC7-A1D9-0AB152DC21E2}D:\programy files\bf2\bfbc2game.exe -> profile=private | protocol=6 | dir=in | action=allow | name=battlefield: bad company™ 2 | app=d:\programy files\bf2\bfbc2game.exe |
TCP Query User{F6FE58C2-2880-4371-A45E-A3B544A0B900}D:\programy files\bf2\bfbc2game.exe -> profile=public | protocol=6 | dir=in | action=allow | name=battlefield: bad company™ 2 | app=d:\programy files\bf2\bfbc2game.exe |
UDP Query User{0465FBB7-0564-42DF-99FB-460E0B8A4F44}C:\users\ja\appdata\roaming\utorrent\utorrent.exe -> profile=private | protocol=17 | dir=in | action=allow | name=utorrent.exe | app=c:\users\ja\appdata\roaming\utorrent\utorrent.exe |
UDP Query User{1D35F85E-A686-45AD-981F-3A559E3F2973}C:\users\ja\appdata\roaming\utorrent\utorrent.exe -> profile=public | protocol=17 | dir=in | action=allow | name=utorrent.exe | app=c:\users\ja\appdata\roaming\utorrent\utorrent.exe |
UDP Query User{21E5C3E9-0D07-4A05-B3DF-3C9855607BE4}F:\gry\wot\worldoftanks.exe -> profile=public | protocol=17 | dir=in | action=allow | name=world of tanks | app=f:\gry\wot\worldoftanks.exe |
UDP Query User{2920C2CD-24DA-459F-8304-0C02149B2E4E}F:\gry\outlast\binaries\win64\olgame.exe -> profile=private | protocol=17 | dir=in | action=allow | name=outlast | app=f:\gry\outlast\binaries\win64\olgame.exe |
UDP Query User{4B4B166E-FDF2-4B73-AFBF-3836F99DBA23}F:\gry\outlast\binaries\win64\olgame_r.exe -> profile=private | protocol=17 | dir=in | action=block | name=outlast | app=f:\gry\outlast\binaries\win64\olgame_r.exe |
UDP Query User{5A5ADE0C-86B4-4BFA-A2FE-71F4CB55F0BD}D:\programy files\bf2\bfbc2game.exe -> profile=public | protocol=17 | dir=in | action=allow | name=battlefield: bad company™ 2 | app=d:\programy files\bf2\bfbc2game.exe |
UDP Query User{5F937841-24C8-4B65-9E08-59C4C77E82EC}F:\gry\wot\worldoftanks.exe -> profile=private | protocol=17 | dir=in | action=allow | name=world of tanks | app=f:\gry\wot\worldoftanks.exe |
UDP Query User{648ACBA7-4762-4083-AB79-9DB83C311522}F:\gry\wot\wotlauncher.exe -> profile=private | protocol=17 | dir=in | action=allow | name=world of tanks launcher | app=f:\gry\wot\wotlauncher.exe |
UDP Query User{6A2CEC82-E57D-4498-8149-BF524C3A5758}D:\programy files\bf2\bfbc2game.exe -> profile=private | protocol=17 | dir=in | action=allow | name=battlefield: bad company™ 2 | app=d:\programy files\bf2\bfbc2game.exe |
UDP Query User{8BABF3E0-5996-4EAB-BFC3-0FE4B2A126F3}F:\gry\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe -> profile=public | protocol=17 | dir=in | action=block | name=blizzard downloader | app=f:\gry\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
UDP Query User{90D93C69-8D5F-45D6-A2BB-1B57529736CE}F:\gry\wot\wotlauncher.exe -> profile=public | protocol=17 | dir=in | action=allow | name=world of tanks launcher | app=f:\gry\wot\wotlauncher.exe |
UDP Query User{AF88525A-C712-4B59-9734-DE156B008786}F:\gry\starcraft ii\support\blizzarddownloader.exe -> profile=public | protocol=17 | dir=in | action=block | name=blizzard downloader | app=f:\gry\starcraft ii\support\blizzarddownloader.exe |
UDP Query User{B509CB65-533C-4838-BC07-AA6D0B7BA5AE}F:\gry\starcraft ii\versions\base21029\sc2.exe -> profile=public | protocol=17 | dir=in | action=block | name=starcraft ii | app=f:\gry\starcraft ii\versions\base21029\sc2.exe |
UDP Query User{BF30F1A8-04A1-4282-9110-94DDEDB151D8}D:\games\company of heroes 2\reliccoh2.exe -> profile=private | protocol=17 | dir=in | action=block | name=company of heroes 2 | app=d:\games\company of heroes 2\reliccoh2.exe |
UDP Query User{C2484833-8736-45B3-A16F-47D4A7CD16A5}C:\program files (x86)\skype\phone\skype.exe -> profile=private | protocol=17 | dir=in | action=allow | name=skype | app=c:\program files (x86)\skype\phone\skype.exe |
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> Sterownik stacji dysków CD-ROM ->
"ImagePath" -> C:\Windows\SysNative\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2010-11-20 02:19:22 | 000,147,456 | ---- | M] (Microsoft Corporation)
< Drives with AutoRun files > -> ->
C:\autoexec.bat [] -> C:\autoexec.bat [ NTFS ] -> [2014-02-17 16:54:31 | 000,000,000 | ---- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
64bit-comfile [open] -> "%1" %*
64bit-exefile [open] -> "%1" %*
comfile [open] -> "%1" %* ->
exefile [open] -> "%1" %* ->
< 64bit-File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.com [@ = ComFile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.com [@ = ComFile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
[Registry - Additional Scans - Safe List]
< 64bit-File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.bat [@ = batfile] -> "%1" %* ->
.cmd [@ = cmdfile] -> "%1" %* ->
.com [@ = ComFile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
.hta [@ = htafile] -> "%1" %* ->
.html [@ = OperaStable] -> C:\Program Files (x86)\Opera\Launcher.exe -> [2014-05-12 07:51:47 | 000,468,088 | ---- | M] (Opera Software)
.url [@ = InternetShortcut] -> C:\Windows\SysNative\rundll32.exe -> [2009-07-14 03:39:31 | 000,045,568 | ---- | M] (Microsoft Corporation)
.pif [@ = piffile] -> "%1" %* ->
.scr [@ = scrfile] -> "%1" /S ->
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.bat [@ = batfile] -> "%1" %* ->
.cmd [@ = cmdfile] -> "%1" %* ->
.com [@ = ComFile] -> "%1" %* ->
.cpl [@ = cplfile] -> C:\Windows\SysWow64\control.exe -> [2009-07-14 03:14:15 | 000,113,152 | ---- | M] (Microsoft Corporation)
.exe [@ = exefile] -> "%1" %* ->
.hta [@ = htafile] -> "%1" %* ->
.html [@ = OperaStable] -> C:\Program Files (x86)\Opera\Launcher.exe -> [2014-05-12 07:51:47 | 000,468,088 | ---- | M] (Opera Software)
.pif [@ = piffile] -> "%1" %* ->
.scr [@ = scrfile] -> "%1" /S ->
< File Associations - Select to Repair > -> HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\SOFTWARE\Classes\<extension>\ ->
.html [@ = OperaStable] -> C:\Program Files (x86)\Opera\Launcher.exe -> [2014-05-12 07:51:47 | 000,468,088 | ---- | M] (Opera Software)
< 64bit-Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
ms-help:{314111c7-a502-11d2-bbca-00c04f8ec294} [HKLM] -> Reg Error: Key error.[Reg Error: Key error.] -> File not found
skype4com:{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} [HKLM] -> Reg Error: Key error.[Reg Error: Key error.] -> File not found
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
skype4com:{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} [HKLM] -> C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll[IEProtocolHandler Class] -> [2013-02-26 16:38:30 | 001,996,392 | R--- | M] (Skype Technologies)
< 64bit-Security Center Settings > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center ->
64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
\\"cval" -> [1] -> File not found
\\"FirewallDisableNotify" -> [0] -> File not found
\\"AntiVirusDisableNotify" -> [0] -> File not found
\\"UpdatesDisableNotify" -> [0] -> File not found
64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> ->
64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\ -> ->
64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
\Svc\\"VistaSp1" -> [28 4D B2 76 41 04 CA 01 [binary data]] -> File not found
\Svc\\"AntiVirusOverride" -> [0] -> File not found
\Svc\\"AntiSpywareOverride" -> [0] -> File not found
\Svc\\"FirewallOverride" -> [0] -> File not found
64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol\ -> ->
< 64bit-Windows Firewall Group Policy Settings > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall ->
64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ -> ->
64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\ -> ->
< Security Center Settings > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\ -> ->
< System Restore User Settings > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore ->
"DisableSR" -> 0 ->
< Windows Firewall Group Policy Settings > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall ->
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\ -> ->
< Windows DomainProfile Firewall Policy Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
\\"EnableFirewall" -> [1] -> File not found
\\"DisableNotifications" -> [0] -> File not found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Logging\ -> ->
< Windows StandardProfile Firewall Policy Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
\\"EnableFirewall" -> [1] -> File not found
\\"DisableNotifications" -> [0] -> File not found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging\ -> ->
< Windows StandardProfile GloballyOpenPorts Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List ->
< Default Protocols [HKEY_LOCAL_MACHINE\] - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
knownfolder -> 0 = Computer (Not a Default Protocol) ->
ldap -> 4 = Restricted sites (Not a Default Protocol) ->
news -> 4 = Restricted sites (Not a Default Protocol) ->
nntp -> 4 = Restricted sites (Not a Default Protocol) ->
oecmd -> 4 = Restricted sites (Not a Default Protocol) ->
snews -> 4 = Restricted sites (Not a Default Protocol) ->
< Default Protocols [HKEY_USERS\S-1-5-19\] - Select to Repair > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
@ivt -> @ivt protocol not assigned ->
file -> file protocol not assigned ->
ftp -> ftp protocol not assigned ->
http -> http protocol not assigned ->
https -> https protocol not assigned ->
shell -> shell protocol not assigned ->
< Default Protocols [HKEY_USERS\S-1-5-20\] - Select to Repair > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
@ivt -> @ivt protocol not assigned ->
file -> file protocol not assigned ->
ftp -> ftp protocol not assigned ->
http -> http protocol not assigned ->
https -> https protocol not assigned ->
shell -> shell protocol not assigned ->
< Default Protocols [HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\] - Select to Repair > -> HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
knownfolder -> 0 = Computer (Not a Default Protocol) ->
< 64bit-Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->
{1D8E6291-B0D5-35EC-8441-6616F567A0F7} -> Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
{409CB30E-E457-4008-9B1A-ED1B9EA21140} -> Intel(R) Rapid Storage Technology
{44B72151-611E-429D-9765-9BA093D7E48A} -> Intel® Trusted Connect Service Client
{45F1F774-38B4-3CC3-BAAF-051E6D19E48E} -> Microsoft .NET Framework 4.5.1 (PLK)
{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc} -> Microsoft Visual C++ 2005 Redistributable (x64)
{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} -> Microsoft .NET Framework 4.5.1
{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} -> Microsoft Silverlight
{90140000-002A-0000-1000-0000000FF1CE} -> Microsoft Office Office 64-bit Components 2010
{90140000-002A-0415-1000-0000000FF1CE} -> Microsoft Office Shared 64-bit MUI (Polish) 2010
{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033 -> Microsoft .NET Framework 4.5.1
{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045 -> Microsoft .NET Framework 4.5.1 (Polski)
{9E9D49A4-1DF4-4138-B7DB-5D87A893088E} -> ThinkPad Bluetooth with Enhanced Data Rate Software
{E83FDB2A-C81C-403D-8FD3-A816A89AF80C} -> Intel(R) Rapid Storage Technology
3BA80AB4C7E9F8497C115C844953A3D4BEB84D21 -> Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800)
CPUID HWMonitor_is1 -> CPUID HWMonitor 1.22
DE7217D2A8B057F15EC6E52329FDAB84231521E8 -> Windows Driver Package - Broadcom (BTHUSB) Bluetooth (04/08/2010 6.3.5.430)
VLC media player -> VLC media player 2.1.3
< Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->
{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1 -> World of Tanks
{1F1C2DFC-2D24-3E06-BCB8-725134ADF989} -> Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
{20D4A895-748C-4D88-871C-FDB1695B0169} -> Platform
{240C3DDD-C5E9-4029-9DF7-95650D040CF2} -> Intel(R) USB 3.0 eXtensible Host Controller Driver
{26A24AE4-039D-4CA4-87B4-2F83217045FF} -> Java 7 Update 55
{3AC8457C-0385-4BEA-A959-E095F05D6D67} -> Battlefield: Bad Company™ 2
{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C} -> FIFA 11
{4A03706F-666A-4037-7777-5F2748764D10} -> Java Auto Updater
{5454083B-1308-4485-BF17-111000028701} -> Grand Theft Auto: Episodes from Liberty City
{5454083B-1308-4485-BF17-111000028702} -> Grand Theft Auto: Episodes from Liberty City
{5DE67937-45D5-45E4-923C-0B7F7EC929A7} -> League of Legends
{65153EA5-8B6E-43B6-857B-C6E4FC25798A} -> Intel(R) Management Engine Components
{7299052b-02a4-4627-81f2-1818da5d550d} -> Microsoft Visual C++ 2005 Redistributable
{76285C16-411A-488A-BCE3-C83CB933D8CF} -> Battlefield 3™
{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7} -> Skype™ 6.14
{837b34e3-7c30-493c-8f6a-2b0f04e2912c} -> Microsoft Visual C++ 2005 Redistributable
{8833FFB6-5B0C-4764-81AA-06DFEED9A476} -> Realtek Ethernet Controller Driver
{8B922CF8-8A6C-41CE-A858-F1755D7F5D29} -> NVIDIA PhysX
{90140000-0011-0000-0000-0000000FF1CE} -> Microsoft Office Professional Plus 2010
{90140000-0015-0415-0000-0000000FF1CE} -> Microsoft Office Access MUI (Polish) 2010
{90140000-0016-0415-0000-0000000FF1CE} -> Microsoft Office Excel MUI (Polish) 2010
{90140000-0018-0415-0000-0000000FF1CE} -> Microsoft Office PowerPoint MUI (Polish) 2010
{90140000-0019-0415-0000-0000000FF1CE} -> Microsoft Office Publisher MUI (Polish) 2010
{90140000-001A-0415-0000-0000000FF1CE} -> Microsoft Office Outlook MUI (Polish) 2010
{90140000-001B-0415-0000-0000000FF1CE} -> Microsoft Office Word MUI (Polish) 2010
{90140000-001F-0407-0000-0000000FF1CE} -> Microsoft Office Proof (German) 2010
{90140000-001F-0409-0000-0000000FF1CE} -> Microsoft Office Proof (English) 2010
{90140000-001F-0415-0000-0000000FF1CE} -> Microsoft Office Proof (Polish) 2010
{90140000-002C-0415-0000-0000000FF1CE} -> Microsoft Office Proofing (Polish) 2010
{90140000-0044-0415-0000-0000000FF1CE} -> Microsoft Office InfoPath MUI (Polish) 2010
{90140000-006E-0415-0000-0000000FF1CE} -> Microsoft Office Shared MUI (Polish) 2010
{90140000-00A1-0415-0000-0000000FF1CE} -> Microsoft Office OneNote MUI (Polish) 2010
{90140000-00BA-0415-0000-0000000FF1CE} -> Microsoft Office Groove MUI (Polish) 2010
{91B33C97-0FBA-74AE-E802-D782F5C8AA89}_is1 -> Ashampoo Burning Studio 2013 v.11.0.6
{9A25302D-30C0-39D9-BD6F-21E6EC160475} -> Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
{9BE518E6-ECC6-35A9-88E4-87755C07200F} -> Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E} -> Brother MFL-Pro Suite DCP-135C
{A6356F2F-D3E1-4D83-9AA2-72871DD0C298} -> Tom Clancy's Splinter Cell® Blacklist™
{AC76BA86-7AD7-1045-7B44-AB0000000001} -> Adobe Reader XI (11.0.07) - Polish
{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} -> Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} -> Intel(R) Processor Graphics
{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} -> Realtek High Definition Audio Driver
{FCB3772C-B7D0-4933-B1A9-3707EBACC573} -> Intel(R) SDK for OpenCL - CPU Only Runtime Package
{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4} -> Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Adobe Flash Player ActiveX -> Adobe Flash Player 13 ActiveX
Adobe Flash Player Plugin -> Adobe Flash Player 13 Plugin
avast -> avast! Free Antivirus
Fraps -> Fraps
InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169} -> VIA Platforma Menedżera urządzeń
League of Legends 3.0.1 -> League of Legends
Mozilla Firefox 29.0.1 (x86 pl) -> Mozilla Firefox 29.0.1 (x86 pl)
MozillaMaintenanceService -> Mozilla Maintenance Service
Office14.PROPLUS -> Microsoft Office Professional Plus 2010
Opera 21.0.1432.67 -> Opera Stable 21.0.1432.67
Q29tcGFueW9mSGVyb2VzMg==_is1 -> Company of Heroes 2
TeamSpeak 3 Client -> TeamSpeak 3 Client
Tomb Raider - Game Of The Year Edition_is1 -> Tomb Raider - Game Of The Year Edition
WinRAR archiver -> Archiwizator WinRAR
< Uninstall List [HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\] > -> HKEY_USERS\S-1-5-21-1363661271-760379814-3891206274-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->
GameRanger -> GameRanger
GG -> GG
ModPack by DjVirusPL FULL 0.8.11 v4 -> ModPack by DjVirusPL FULL 0.8.11 v4
uTorrent -> µTorrent
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
[Files/Folders - Created Within 30 Days]
OTS.exe -> C:\Users\ja\Desktop\OTS.exe -> [2014-05-19 21:06:30 | 000,646,656 | ---- | C] (OldTimer Tools)
tdsskiller.exe -> C:\Users\ja\Desktop\tdsskiller.exe -> [2014-05-19 21:01:23 | 004,164,448 | ---- | C] (Kaspersky Lab ZAO)
Nowy folder -> C:\Users\ja\Desktop\Nowy folder -> [2014-05-19 15:53:22 | 000,000,000 | ---D | C]
Sun -> C:\Windows\Sun -> [2014-05-18 22:47:34 | 000,000,000 | ---D | C]
FRST -> C:\FRST -> [2014-05-18 21:44:52 | 000,000,000 | ---D | C]
FRST64.exe -> C:\Users\ja\Desktop\FRST64.exe -> [2014-05-18 21:19:54 | 002,067,456 | ---- | C] (Farbar)
$RECYCLE.BIN -> C:\$RECYCLE.BIN -> [2014-05-18 16:24:00 | 000,000,000 | -HSD | C]
SWREG.exe -> C:\Windows\SWREG.exe -> [2014-05-18 16:09:00 | 000,518,144 | ---- | C] (SteelWerX)
SWSC.exe -> C:\Windows\SWSC.exe -> [2014-05-18 16:09:00 | 000,406,528 | ---- | C] (SteelWerX)
NIRCMD.exe -> C:\Windows\NIRCMD.exe -> [2014-05-18 16:09:00 | 000,060,416 | ---- | C] (NirSoft)
Qoobox -> C:\Qoobox -> [2014-05-18 16:08:55 | 000,000,000 | ---D | C]
erdnt -> C:\Windows\erdnt -> [2014-05-18 16:08:45 | 000,000,000 | ---D | C]
OTL_[www.programosy.pl].exe -> C:\Users\ja\Desktop\OTL_[www.programosy.pl].exe -> [2014-05-16 16:51:48 | 000,602,112 | ---- | C] (OldTimer Tools)
mshtmled.dll -> C:\Windows\SysNative\mshtmled.dll -> [2014-05-14 23:14:20 | 000,084,992 | ---- | C] (Microsoft Corporation)
mshtmled.dll -> C:\Windows\SysWow64\mshtmled.dll -> [2014-05-14 23:14:20 | 000,069,632 | ---- | C] (Microsoft Corporation)
aepdu.dll -> C:\Windows\SysNative\aepdu.dll -> [2014-05-14 21:16:36 | 000,477,184 | ---- | C] (Microsoft Corporation)
aeinv.dll -> C:\Windows\SysNative\aeinv.dll -> [2014-05-14 21:16:35 | 000,424,448 | ---- | C] (Microsoft Corporation)
lsasrv.dll -> C:\Windows\SysNative\lsasrv.dll -> [2014-05-14 21:16:22 | 001,460,736 | ---- | C] (Microsoft Corporation)
ntkrnlpa.exe -> C:\Windows\SysWow64\ntkrnlpa.exe -> [2014-05-14 21:16:21 | 003,969,984 | ---- | C] (Microsoft Corporation)
ntoskrnl.exe -> C:\Windows\SysWow64\ntoskrnl.exe -> [2014-05-14 21:16:21 | 003,914,176 | ---- | C] (Microsoft Corporation)
winlogon.exe -> C:\Windows\SysNative\winlogon.exe -> [2014-05-14 21:16:21 | 000,455,168 | ---- | C] (Microsoft Corporation)
ntoskrnl.exe -> C:\Windows\SysNative\ntoskrnl.exe -> [2014-05-14 21:16:20 | 005,550,016 | ---- | C] (Microsoft Corporation)
objsel.dll -> C:\Windows\SysNative\objsel.dll -> [2014-05-14 21:16:20 | 000,722,944 | ---- | C] (Microsoft Corporation)
objsel.dll -> C:\Windows\SysWow64\objsel.dll -> [2014-05-14 21:16:19 | 000,538,112 | ---- | C] (Microsoft Corporation)
KernelBase.dll -> C:\Windows\SysNative\KernelBase.dll -> [2014-05-14 21:16:18 | 000,424,960 | ---- | C] (Microsoft Corporation)
cngprovider.dll -> C:\Windows\SysNative\cngprovider.dll -> [2014-05-14 21:16:17 | 000,057,344 | ---- | C] (Microsoft Corporation)
adprovider.dll -> C:\Windows\SysNative\adprovider.dll -> [2014-05-14 21:16:17 | 000,056,832 | ---- | C] (Microsoft Corporation)
capiprovider.dll -> C:\Windows\SysNative\capiprovider.dll -> [2014-05-14 21:16:17 | 000,053,760 | ---- | C] (Microsoft Corporation)
dpapiprovider.dll -> C:\Windows\SysNative\dpapiprovider.dll -> [2014-05-14 21:16:17 | 000,052,736 | ---- | C] (Microsoft Corporation)
cngprovider.dll -> C:\Windows\SysWow64\cngprovider.dll -> [2014-05-14 21:16:17 | 000,051,200 | ---- | C] (Microsoft Corporation)
adprovider.dll -> C:\Windows\SysWow64\adprovider.dll -> [2014-05-14 21:16:17 | 000,049,664 | ---- | C] (Microsoft Corporation)
capiprovider.dll -> C:\Windows\SysWow64\capiprovider.dll -> [2014-05-14 21:16:17 | 000,048,128 | ---- | C] (Microsoft Corporation)
dpapiprovider.dll -> C:\Windows\SysWow64\dpapiprovider.dll -> [2014-05-14 21:16:17 | 000,047,616 | ---- | C] (Microsoft Corporation)
dimsroam.dll -> C:\Windows\SysNative\dimsroam.dll -> [2014-05-14 21:16:17 | 000,044,544 | ---- | C] (Microsoft Corporation)
dimsroam.dll -> C:\Windows\SysWow64\dimsroam.dll -> [2014-05-14 21:16:17 | 000,036,864 | ---- | C] (Microsoft Corporation)
sspicli.dll -> C:\Windows\SysNative\sspicli.dll -> [2014-05-14 21:16:16 | 000,136,192 | ---- | C] (Microsoft Corporation)
wincredprovider.dll -> C:\Windows\SysNative\wincredprovider.dll -> [2014-05-14 21:16:15 | 000,039,936 | ---- | C] (Microsoft Corporation)
wincredprovider.dll -> C:\Windows\SysWow64\wincredprovider.dll -> [2014-05-14 21:16:15 | 000,035,328 | ---- | C] (Microsoft Corporation)
sspisrv.dll -> C:\Windows\SysNative\sspisrv.dll -> [2014-05-14 21:16:14 | 000,029,184 | ---- | C] (Microsoft Corporation)
secur32.dll -> C:\Windows\SysNative\secur32.dll -> [2014-05-14 21:16:14 | 000,028,160 | ---- | C] (Microsoft Corporation)
FlashPlayerInstaller.exe -> C:\Windows\SysWow64\FlashPlayerInstaller.exe -> [2014-05-13 22:22:09 | 017,938,608 | ---- | C] (Adobe Systems Incorporated)
Mozilla Firefox -> C:\Program Files (x86)\Mozilla Firefox -> [2014-05-10 16:26:16 | 000,000,000 | ---D | C]
Urządzenia interfejsu Bluetooth -> C:\Users\ja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Urządzenia interfejsu Bluetooth -> [2014-05-10 16:23:01 | 000,000,000 | ---D | C]
Intel -> C:\Program Files (x86)\Common Files\Intel -> [2014-05-06 21:49:34 | 000,000,000 | ---D | C]
igdkmd64.sys -> C:\Windows\SysNative\drivers\igdkmd64.sys -> [2014-05-06 21:47:48 | 004,208,640 | ---- | C] (Intel Corporation)
IntcDAud.sys -> C:\Windows\SysNative\drivers\IntcDAud.sys -> [2014-05-06 21:47:48 | 000,449,496 | ---- | C] (Intel(R) Corporation)
IntelOpenCL64.dll -> C:\Windows\SysNative\IntelOpenCL64.dll -> [2014-05-06 21:47:48 | 000,241,664 | ---- | C] (Intel Corporation)
IntelOpenCL32.dll -> C:\Windows\SysWow64\IntelOpenCL32.dll -> [2014-05-06 21:47:47 | 000,193,536 | ---- | C] (Intel Corporation)
MetroIntelGenericUIFramework.dll -> C:\Windows\SysNative\MetroIntelGenericUIFramework.dll -> [2014-05-06 21:47:46 | 004,067,328 | ---- | C] (Intel Corporation)
igdumdim64.dll -> C:\Windows\SysNative\igdumdim64.dll -> [2014-05-06 21:47:45 | 012,148,224 | ---- | C] (Intel Corporation)
igfxcmjit64.dll -> C:\Windows\SysNative\igfxcmjit64.dll -> [2014-05-06 21:47:45 | 002,065,920 | ---- | C] (Intel Corporation)
igfxcmjit32.dll -> C:\Windows\SysWow64\igfxcmjit32.dll -> [2014-05-06 21:47:45 | 001,815,040 | ---- | C] (Intel Corporation)
iglhsip64.dll -> C:\Windows\SysNative\iglhsip64.dll -> [2014-05-06 21:47:45 | 001,127,424 | ---- | C] (Intel Corporation)
iglhsip32.dll -> C:\Windows\SysWow64\iglhsip32.dll -> [2014-05-06 21:47:45 | 001,123,328 | ---- | C] (Intel Corporation)
igfxpph.dll -> C:\Windows\SysNative\igfxpph.dll -> [2014-05-06 21:47:45 | 000,548,864 | ---- | C] (Intel Corporation)
igfxdv32.dll -> C:\Windows\SysWow64\igfxdv32.dll -> [2014-05-06 21:47:45 | 000,493,056 | ---- | C] (Intel Corporation)
igfxTMM.dll -> C:\Windows\SysNative\igfxTMM.dll -> [2014-05-06 21:47:45 | 000,345,600 | ---- | C] (Intel Corporation)
igfxdo.dll -> C:\Windows\SysNative\igfxdo.dll -> [2014-05-06 21:47:45 | 000,243,712 | ---- | C] (Intel Corporation)
iglhcp64.dll -> C:\Windows\SysNative\iglhcp64.dll -> [2014-05-06 21:47:45 | 000,214,528 | ---- | C] (Intel Corporation)
igfxCoIn_v3355.dll -> C:\Windows\SysNative\igfxCoIn_v3355.dll -> [2014-05-06 21:47:45 | 000,182,784 | ---- | C] (Intel Corporation)
iglhcp32.dll -> C:\Windows\SysWow64\iglhcp32.dll -> [2014-05-06 21:47:45 | 000,179,712 | ---- | C] (Intel Corporation)
igfxcmrt64.dll -> C:\Windows\SysNative\igfxcmrt64.dll -> [2014-05-06 21:47:45 | 000,160,768 | ---- | C] (Intel Corporation)
igfx11cmrt64.dll -> C:\Windows\SysNative\igfx11cmrt64.dll -> [2014-05-06 21:47:45 | 000,153,088 | ---- | C] (Intel Corporation)
igfxcmrt32.dll -> C:\Windows\SysWow64\igfxcmrt32.dll -> [2014-05-06 21:47:45 | 000,135,680 | ---- | C] (Intel Corporation)
igfx11cmrt32.dll -> C:\Windows\SysWow64\igfx11cmrt32.dll -> [2014-05-06 21:47:45 | 000,131,584 | ---- | C] (Intel Corporation)
igfxexps.dll -> C:\Windows\SysNative\igfxexps.dll -> [2014-05-06 21:47:45 | 000,029,696 | ---- | C] (Intel Corporation)
igfxexps32.dll -> C:\Windows\SysWow64\igfxexps32.dll -> [2014-05-06 21:47:45 | 000,025,600 | ---- | C] (Intel Corporation)
igdfcl64.dll -> C:\Windows\SysNative\igdfcl64.dll -> [2014-05-06 21:47:44 | 025,948,160 | ---- | C] (Intel Corporation)
igdfcl32.dll -> C:\Windows\SysWow64\igdfcl32.dll -> [2014-05-06 21:47:44 | 020,921,344 | ---- | C] (Intel Corporation)
igdrcl64.dll -> C:\Windows\SysNative\igdrcl64.dll -> [2014-05-06 21:47:44 | 003,202,048 | ---- | C] (Intel Corporation)
igdrcl32.dll -> C:\Windows\SysWow64\igdrcl32.dll -> [2014-05-06 21:47:44 | 002,876,416 | ---- | C] (Intel Corporation)
igdbcl64.dll -> C:\Windows\SysNative\igdbcl64.dll -> [2014-05-06 21:47:44 | 000,329,216 | ---- | C] (Intel Corporation)
igdbcl32.dll -> C:\Windows\SysWow64\igdbcl32.dll -> [2014-05-06 21:47:44 | 000,290,816 | ---- | C] (Intel Corporation)
igd10iumd32.dll -> C:\Windows\SysWow64\igd10iumd32.dll -> [2014-05-06 21:47:43 | 013,241,856 | ---- | C] (Intel Corporation)
ig75icd64.dll -> C:\Windows\SysNative\ig75icd64.dll -> [2014-05-06 21:47:43 | 007,852,544 | ---- | C] (Intel Corporation)
ig75icd32.dll -> C:\Windows\SysWow64\ig75icd32.dll -> [2014-05-06 21:47:43 | 006,211,584 | ---- | C] (Intel Corporation)
GfxUIEx.exe -> C:\Windows\SysNative\GfxUIEx.exe -> [2014-05-06 21:47:42 | 007,594,992 | ---- | C] (Intel Corporation)
igfxstarter.exe -> C:\Windows\SysNative\igfxstarter.exe -> [2014-05-06 21:47:42 | 000,906,224 | ---- | C] (Intel Corporation)
igfxsrvc.exe -> C:\Windows\SysNative\igfxsrvc.exe -> [2014-05-06 21:47:42 | 000,845,296 | ---- | C] (Intel Corporation)
hkcmd.exe -> C:\Windows\SysNative\hkcmd.exe -> [2014-05-06 21:47:42 | 000,771,056 | ---- | C] (Intel Corporation)
igfxpers.exe -> C:\Windows\SysNative\igfxpers.exe -> [2014-05-06 21:47:42 | 000,770,032 | ---- | C] (Intel Corporation)
GfxUIHotKeyMenu.exe -> C:\Windows\SysNative\GfxUIHotKeyMenu.exe -> [2014-05-06 21:47:42 | 000,754,672 | ---- | C] (Intel Corporation)
DPTopologyApp.exe -> C:\Windows\SysNative\DPTopologyApp.exe -> [2014-05-06 21:47:42 | 000,530,928 | ---- | C] (Intel Corporation)
igfxext.exe -> C:\Windows\SysNative\igfxext.exe -> [2014-05-06 21:47:42 | 000,397,808 | ---- | C] (Intel Corporation)
CustomModeApp.exe -> C:\Windows\SysNative\CustomModeApp.exe -> [2014-05-06 21:47:42 | 000,396,784 | ---- | C] (Intel Corporation)
igfxtray.exe -> C:\Windows\SysNative\igfxtray.exe -> [2014-05-06 21:47:42 | 000,391,152 | ---- | C] (Intel Corporation)
IntelCpHeciSvc.exe -> C:\Windows\SysWow64\IntelCpHeciSvc.exe -> [2014-05-06 21:47:42 | 000,279,024 | ---- | C] (Intel Corporation)
gfxSrvc.dll -> C:\Windows\SysNative\gfxSrvc.dll -> [2014-05-06 21:47:42 | 000,194,048 | ---- | C] (Intel Corporation)
difx64.exe -> C:\Windows\SysNative\difx64.exe -> [2014-05-06 21:47:42 | 000,153,072 | ---- | C] (Intel Corporation)
igfxrell.lrc -> C:\Windows\SysNative\igfxrell.lrc -> [2014-05-06 21:47:41 | 000,527,872 | ---- | C] (Intel Corporation)
igfxrplk.lrc -> C:\Windows\SysNative\igfxrplk.lrc -> [2014-05-06 21:47:41 | 000,527,360 | ---- | C] (Intel Corporation)
igfxrfra.lrc -> C:\Windows\SysNative\igfxrfra.lrc -> [2014-05-06 21:47:41 | 000,527,360 | ---- | C] (Intel Corporation)
igfxresn.lrc -> C:\Windows\SysNative\igfxresn.lrc -> [2014-05-06 21:47:41 | 000,527,360 | ---- | C] (Intel Corporation)
igfxrrus.lrc -> C:\Windows\SysNative\igfxrrus.lrc -> [2014-05-06 21:47:41 | 000,526,848 | ---- | C] (Intel Corporation)
igfxrdeu.lrc -> C:\Windows\SysNative\igfxrdeu.lrc -> [2014-05-06 21:47:41 | 000,526,848 | ---- | C] (Intel Corporation)
igfxrrom.lrc -> C:\Windows\SysNative\igfxrrom.lrc -> [2014-05-06 21:47:41 | 000,526,336 | ---- | C] (Intel Corporation)
igfxrnld.lrc -> C:\Windows\SysNative\igfxrnld.lrc -> [2014-05-06 21:47:41 | 000,526,336 | ---- | C] (Intel Corporation)
igfxrita.lrc -> C:\Windows\SysNative\igfxrita.lrc -> [2014-05-06 21:47:41 | 000,526,336 | ---- | C] (Intel Corporation)
igfxrsky.lrc -> C:\Windows\SysNative\igfxrsky.lrc -> [2014-05-06 21:47:41 | 000,525,824 | ---- | C] (Intel Corporation)
igfxrptg.lrc -> C:\Windows\SysNative\igfxrptg.lrc -> [2014-05-06 21:47:41 | 000,525,824 | ---- | C] (Intel Corporation)
igfxrhun.lrc -> C:\Windows\SysNative\igfxrhun.lrc -> [2014-05-06 21:47:41 | 000,525,824 | ---- | C] (Intel Corporation)
igfxrhrv.lrc -> C:\Windows\SysNative\igfxrhrv.lrc -> [2014-05-06 21:47:41 | 000,525,824 | ---- | C] (Intel Corporation)
igfxrcsy.lrc -> C:\Windows\SysNative\igfxrcsy.lrc -> [2014-05-06 21:47:41 | 000,525,824 | ---- | C] (Intel Corporation)
igfxrsve.lrc -> C:\Windows\SysNative\igfxrsve.lrc -> [2014-05-06 21:47:41 | 000,525,312 | ---- | C] (Intel Corporation)
igfxrslv.lrc -> C:\Windows\SysNative\igfxrslv.lrc -> [2014-05-06 21:47:41 | 000,525,312 | ---- | C] (Intel Corporation)
igfxrfin.lrc -> C:\Windows\SysNative\igfxrfin.lrc -> [2014-05-06 21:47:41 | 000,525,312 | ---- | C] (Intel Corporation)
igfxrtrk.lrc -> C:\Windows\SysNative\igfxrtrk.lrc -> [2014-05-06 21:47:41 | 000,524,800 | ---- | C] (Intel Corporation)
igfxrptb.lrc -> C:\Windows\SysNative\igfxrptb.lrc -> [2014-05-06 21:47:41 | 000,524,800 | ---- | C] (Intel Corporation)
igfxrnor.lrc -> C:\Windows\SysNative\igfxrnor.lrc -> [2014-05-06 21:47:41 | 000,524,288 | ---- | C] (Intel Corporation)
igfxrdan.lrc -> C:\Windows\SysNative\igfxrdan.lrc -> [2014-05-06 21:47:41 | 000,524,288 | ---- | C] (Intel Corporation)
igfxrtha.lrc -> C:\Windows\SysNative\igfxrtha.lrc -> [2014-05-06 21:47:41 | 000,523,776 | ---- | C] (Intel Corporation)
igfxrheb.lrc -> C:\Windows\SysNative\igfxrheb.lrc -> [2014-05-06 21:47:41 | 000,522,240 | ---- | C] (Intel Corporation)
igfxrara.lrc -> C:\Windows\SysNative\igfxrara.lrc -> [2014-05-06 21:47:41 | 000,521,728 | ---- | C] (Intel Corporation)
igfxrjpn.lrc -> C:\Windows\SysNative\igfxrjpn.lrc -> [2014-05-06 21:47:41 | 000,517,632 | ---- | C] (Intel Corporation)
igfxrkor.lrc -> C:\Windows\SysNative\igfxrkor.lrc -> [2014-05-06 21:47:41 | 000,516,096 | ---- | C] (Intel Corporation)
igfxrcht.lrc -> C:\Windows\SysNative\igfxrcht.lrc -> [2014-05-06 21:47:41 | 000,514,048 | ---- | C] (Intel Corporation)
igfxrchs.lrc -> C:\Windows\SysNative\igfxrchs.lrc -> [2014-05-06 21:47:41 | 000,513,536 | ---- | C] (Intel Corporation)
igfxrenu.lrc -> C:\Windows\SysNative\igfxrenu.lrc -> [2014-05-06 21:47:41 | 000,371,200 | ---- | C] (Intel Corporation)
igfxcpl.cpl -> C:\Windows\SysNative\igfxcpl.cpl -> [2014-05-06 21:47:41 | 000,279,040 | ---- | C] (Intel Corporation)
CompatTel -> C:\Windows\SysNative\CompatTel -> [2014-05-06 15:58:00 | 000,000,000 | --SD | C]
avastSS.scr -> C:\Windows\avastSS.scr -> [2014-05-02 19:35:55 | 000,043,152 | ---- | C] (AVAST Software)
sqlite3.dll -> C:\Windows\SysWow64\sqlite3.dll -> [2014-05-02 19:14:28 | 000,536,576 | ---- | C] (SQLite Development Team)
javaws.exe -> C:\Windows\SysWow64\javaws.exe -> [2014-05-01 12:43:00 | 000,264,616 | ---- | C] (Oracle Corporation)
javaw.exe -> C:\Windows\SysWow64\javaw.exe -> [2014-05-01 12:42:57 | 000,175,528 | ---- | C] (Oracle Corporation)
java.exe -> C:\Windows\SysWow64\java.exe -> [2014-05-01 12:42:57 | 000,175,016 | ---- | C] (Oracle Corporation)
WindowsAccessBridge-32.dll -> C:\Windows\SysWow64\WindowsAccessBridge-32.dll -> [2014-05-01 12:42:57 | 000,096,168 | ---- | C] (Oracle Corporation)
Java -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java -> [2014-05-01 12:42:57 | 000,000,000 | ---D | C]
[Files/Folders - Modified Within 30 Days]
Adobe Flash Player Updater.job -> C:\Windows\tasks\Adobe Flash Player Updater.job -> [2014-05-19 21:10:00 | 000,000,930 | ---- | M] ()
OTS.exe -> C:\Users\ja\Desktop\OTS.exe -> [2014-05-19 21:06:33 | 000,646,656 | ---- | M] (OldTimer Tools)
tdsskiller.exe -> C:\Users\ja\Desktop\tdsskiller.exe -> [2014-05-19 21:01:28 | 004,164,448 | ---- | M] (Kaspersky Lab ZAO)
7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 -> [2014-05-19 20:09:14 | 000,010,240 | -H-- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 -> [2014-05-19 20:09:14 | 000,010,240 | -H-- | M] ()
PerfStringBackup.INI -> C:\Windows\SysNative\PerfStringBackup.INI -> [2014-05-19 20:07:58 | 001,672,612 | ---- | M] ()
perfh015.dat -> C:\Windows\SysNative\perfh015.dat -> [2014-05-19 20:07:58 | 000,741,136 | ---- | M] ()
perfh009.dat -> C:\Windows\SysNative\perfh009.dat -> [2014-05-19 20:07:58 | 000,654,968 | ---- | M] ()
perfc015.dat -> C:\Windows\SysNative\perfc015.dat -> [2014-05-19 20:07:58 | 000,156,208 | ---- | M] ()
perfc009.dat -> C:\Windows\SysNative\perfc009.dat -> [2014-05-19 20:07:58 | 000,122,338 | ---- | M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2014-05-19 20:01:45 | 000,067,584 | --S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2014-05-19 20:01:41 | 3131,191,296 | -HS- | M] ()
MAMED_KHALIDOV_vs 1111.avi -> C:\Users\ja\Desktop\MAMED_KHALIDOV_vs 1111.avi -> [2014-05-19 16:23:10 | 046,959,384 | ---- | M] ()
MAMED KHALIDOV vs. MAIQUEL JOSE FALCAO GONCALVES (FULL FIGHT) (17.05.2014).webm -> C:\Users\ja\Desktop\MAMED KHALIDOV vs. MAIQUEL JOSE FALCAO GONCALVES (FULL FIGHT) (17.05.2014).webm -> [2014-05-18 22:49:30 | 034,630,267 | ---- | M] ()
FRST64.exe -> C:\Users\ja\Desktop\FRST64.exe -> [2014-05-18 21:20:03 | 002,067,456 | ---- | M] (Farbar)
hosts -> C:\Windows\SysNative\drivers\etc\hosts -> [2014-05-18 16:18:19 | 000,000,027 | ---- | M] ()
OTL_[www.programosy.pl].exe -> C:\Users\ja\Desktop\OTL_[www.programosy.pl].exe -> [2014-05-16 16:51:48 | 000,602,112 | ---- | M] (OldTimer Tools)
ol2rhi6j.exe -> C:\Users\ja\Desktop\ol2rhi6j.exe -> [2014-05-16 16:25:38 | 000,380,416 | ---- | M] ()
aswsnx.sys -> C:\Windows\SysNative\drivers\aswsnx.sys -> [2014-05-15 20:29:17 | 001,039,096 | ---- | M] (AVAST Software)
aswsp.sys -> C:\Windows\SysNative\drivers\aswsp.sys -> [2014-05-15 20:29:17 | 000,423,240 | ---- | M] (AVAST Software)
aswstm.sys -> C:\Windows\SysNative\drivers\aswstm.sys -> [2014-05-15 20:29:16 | 000,085,328 | ---- | M] (AVAST Software)
FlashPlayerApp.exe -> C:\Windows\SysWow64\FlashPlayerApp.exe -> [2014-05-13 22:22:16 | 000,692,400 | ---- | M] (Adobe Systems Incorporated)
FlashPlayerCPLApp.cpl -> C:\Windows\SysWow64\FlashPlayerCPLApp.cpl -> [2014-05-13 22:22:15 | 000,070,832 | ---- | M] (Adobe Systems Incorporated)
FlashPlayerInstaller.exe -> C:\Windows\SysWow64\FlashPlayerInstaller.exe -> [2014-05-13 22:22:09 | 017,938,608 | ---- | M] (Adobe Systems Incorporated)
aepdu.dll -> C:\Windows\SysNative\aepdu.dll -> [2014-05-09 08:14:03 | 000,477,184 | ---- | M] (Microsoft Corporation)
aeinv.dll -> C:\Windows\SysNative\aeinv.dll -> [2014-05-09 08:11:23 | 000,424,448 | ---- | M] (Microsoft Corporation)
results.xml -> C:\Windows\SysNative\results.xml -> [2014-05-06 21:57:40 | 000,015,496 | ---- | M] ()
mshtmled.dll -> C:\Windows\SysNative\mshtmled.dll -> [2014-05-06 05:00:47 | 000,084,992 | ---- | M] (Microsoft Corporation)
mshtmled.dll -> C:\Windows\SysWow64\mshtmled.dll -> [2014-05-06 04:10:52 | 000,069,632 | ---- | M] (Microsoft Corporation)
avast! Free Antivirus.lnk -> C:\Users\Public\Desktop\avast! Free Antivirus.lnk -> [2014-05-04 19:51:54 | 000,002,010 | ---- | M] ()
CPUID HWMonitor.lnk -> C:\Users\Public\Desktop\CPUID HWMonitor.lnk -> [2014-05-04 19:51:54 | 000,000,974 | ---- | M] ()
VLC media player.lnk -> C:\Users\Public\Desktop\VLC media player.lnk -> [2014-05-04 19:51:54 | 000,000,915 | ---- | M] ()
aswsnx.sys.1400178556095 -> C:\Windows\SysNative\drivers\aswsnx.sys.1400178556095 -> [2014-05-02 19:36:01 | 001,039,096 | ---- | M] (AVAST Software)
aswsp.sys.1400178556095 -> C:\Windows\SysNative\drivers\aswsp.sys.1400178556095 -> [2014-05-02 19:36:01 | 000,423,240 | ---- | M] (AVAST Software)
aswBoot.exe -> C:\Windows\SysNative\aswBoot.exe -> [2014-05-02 19:36:01 | 000,334,648 | ---- | M] (AVAST Software)
aswVmm.sys -> C:\Windows\SysNative\drivers\aswVmm.sys -> [2014-05-02 19:36:01 | 000,208,416 | ---- | M] ()
aswMonFlt.sys -> C:\Windows\SysNative\drivers\aswMonFlt.sys -> [2014-05-02 19:36:01 | 000,079,184 | ---- | M] (AVAST Software)
aswRvrt.sys -> C:\Windows\SysNative\drivers\aswRvrt.sys -> [2014-05-02 19:36:01 | 000,065,776 | ---- | M] ()
aswHwid.sys -> C:\Windows\SysNative\drivers\aswHwid.sys -> [2014-05-02 19:36:01 | 000,029,208 | ---- | M] ()
aswRdr2.sys -> C:\Windows\SysNative\drivers\aswRdr2.sys -> [2014-05-02 19:35:59 | 000,093,568 | ---- | M] (AVAST Software)
avastSS.scr -> C:\Windows\avastSS.scr -> [2014-05-02 19:35:55 | 000,043,152 | ---- | M] (AVAST Software)
AdwCleaner.exe -> C:\Users\ja\Desktop\AdwCleaner.exe -> [2014-05-02 19:13:44 | 001,310,621 | ---- | M] ()
[Files - No Company Name]
MAMED_KHALIDOV_vs 1111.avi -> C:\Users\ja\Desktop\MAMED_KHALIDOV_vs 1111.avi -> [2014-05-19 16:21:49 | 046,959,384 | ---- | C] ()
MAMED KHALIDOV vs. MAIQUEL JOSE FALCAO GONCALVES (FULL FIGHT) (17.05.2014).webm -> C:\Users\ja\Desktop\MAMED KHALIDOV vs. MAIQUEL JOSE FALCAO GONCALVES (FULL FIGHT) (17.05.2014).webm -> [2014-05-18 22:48:12 | 034,630,267 | ---- | C] ()
PEV.exe -> C:\Windows\PEV.exe -> [2014-05-18 16:09:00 | 000,256,000 | ---- | C] ()
MBR.exe -> C:\Windows\MBR.exe -> [2014-05-18 16:09:00 | 000,208,896 | ---- | C] ()
sed.exe -> C:\Windows\sed.exe -> [2014-05-18 16:09:00 | 000,098,816 | ---- | C] ()
grep.exe -> C:\Windows\grep.exe -> [2014-05-18 16:09:00 | 000,080,412 | ---- | C] ()
zip.exe -> C:\Windows\zip.exe -> [2014-05-18 16:09:00 | 000,068,096 | ---- | C] ()
ol2rhi6j.exe -> C:\Users\ja\Desktop\ol2rhi6j.exe -> [2014-05-16 16:25:37 | 000,380,416 | ---- | C] ()
results.xml -> C:\Windows\SysNative\results.xml -> [2014-05-06 21:57:40 | 000,015,496 | ---- | C] ()
IGFXDEVLib.dll -> C:\Windows\SysNative\IGFXDEVLib.dll -> [2014-05-06 21:47:45 | 000,012,288 | ---- | C] ( )
igdmd64.dll -> C:\Windows\SysNative\igdmd64.dll -> [2014-05-06 21:47:44 | 000,347,136 | ---- | C] ()
igdmd32.dll -> C:\Windows\SysWow64\igdmd32.dll -> [2014-05-06 21:47:44 | 000,280,064 | ---- | C] ()
igdde64.dll -> C:\Windows\SysNative\igdde64.dll -> [2014-05-06 21:47:44 | 000,222,208 | ---- | C] ()
igdde32.dll -> C:\Windows\SysWow64\igdde32.dll -> [2014-05-06 21:47:44 | 000,182,272 | ---- | C] ()
igdail64.dll -> C:\Windows\SysNative\igdail64.dll -> [2014-05-06 21:47:44 | 000,160,256 | ---- | C] ()
igdail32.dll -> C:\Windows\SysWow64\igdail32.dll -> [2014-05-06 21:47:44 | 000,142,848 | ---- | C] ()
GfxRes.dll -> C:\Windows\SysNative\GfxRes.dll -> [2014-05-06 21:47:42 | 002,384,896 | ---- | C] ()
iglhxs64.vp -> C:\Windows\SysNative\iglhxs64.vp -> [2014-05-06 21:47:42 | 000,002,932 | ---- | C] ()
Gfxres.th-TH.resources -> C:\Windows\SysNative\Gfxres.th-TH.resources -> [2014-05-06 21:47:41 | 000,266,841 | ---- | C] ()
Gfxres.el-GR.resources -> C:\Windows\SysNative\Gfxres.el-GR.resources -> [2014-05-06 21:47:41 | 000,253,021 | ---- | C] ()
Gfxres.ru-RU.resources -> C:\Windows\SysNative\Gfxres.ru-RU.resources -> [2014-05-06 21:47:41 | 000,234,948 | ---- | C] ()
Gfxres.ar-SA.resources -> C:\Windows\SysNative\Gfxres.ar-SA.resources -> [2014-05-06 21:47:41 | 000,200,948 | ---- | C] ()
Gfxres.ja-JP.resources -> C:\Windows\SysNative\Gfxres.ja-JP.resources -> [2014-05-06 21:47:41 | 000,198,502 | ---- | C] ()
Gfxres.he-IL.resources -> C:\Windows\SysNative\Gfxres.he-IL.resources -> [2014-05-06 21:47:41 | 000,192,523 | ---- | C] ()
Gfxres.ko-KR.resources -> C:\Windows\SysNative\Gfxres.ko-KR.resources -> [2014-05-06 21:47:41 | 000,180,852 | ---- | C] ()
Gfxres.it-IT.resources -> C:\Windows\SysNative\Gfxres.it-IT.resources -> [2014-05-06 21:47:41 | 000,180,758 | ---- | C] ()
Gfxres.es-ES.resources -> C:\Windows\SysNative\Gfxres.es-ES.resources -> [2014-05-06 21:47:41 | 000,178,398 | ---- | C] ()
Gfxres.fr-FR.resources -> C:\Windows\SysNative\Gfxres.fr-FR.resources -> [2014-05-06 21:47:41 | 000,178,118 | ---- | C] ()
Gfxres.de-DE.resources -> C:\Windows\SysNative\Gfxres.de-DE.resources -> [2014-05-06 21:47:41 | 000,178,103 | ---- | C] ()
Gfxres.ro-RO.resources -> C:\Windows\SysNative\Gfxres.ro-RO.resources -> [2014-05-06 21:47:41 | 000,176,743 | ---- | C] ()
Gfxres.hu-HU.resources -> C:\Windows\SysNative\Gfxres.hu-HU.resources -> [2014-05-06 21:47:41 | 000,175,734 | ---- | C] ()
Gfxres.tr-TR.resources -> C:\Windows\SysNative\Gfxres.tr-TR.resources -> [2014-05-06 21:47:41 | 000,175,481 | ---- | C] ()
Gfxres.pl-PL.resources -> C:\Windows\SysNative\Gfxres.pl-PL.resources -> [2014-05-06 21:47:41 | 000,175,231 | ---- | C] ()
Gfxres.nl-NL.resources -> C:\Windows\SysNative\Gfxres.nl-NL.resources -> [2014-05-06 21:47:41 | 000,175,005 | ---- | C] ()
Gfxres.pt-BR.resources -> C:\Windows\SysNative\Gfxres.pt-BR.resources -> [2014-05-06 21:47:41 | 000,174,216 | ---- | C] ()
Gfxres.fi-FI.resources -> C:\Windows\SysNative\Gfxres.fi-FI.resources -> [2014-05-06 21:47:41 | 000,173,582 | ---- | C] ()
Gfxres.sk-SK.resources -> C:\Windows\SysNative\Gfxres.sk-SK.resources -> [2014-05-06 21:47:41 | 000,173,251 | ---- | C] ()
Gfxres.sv-SE.resources -> C:\Windows\SysNative\Gfxres.sv-SE.resources -> [2014-05-06 21:47:41 | 000,173,071 | ---- | C] ()
Gfxres.pt-PT.resources -> C:\Windows\SysNative\Gfxres.pt-PT.resources -> [2014-05-06 21:47:41 | 000,172,778 | ---- | C] ()
Gfxres.cs-CZ.resources -> C:\Windows\SysNative\Gfxres.cs-CZ.resources -> [2014-05-06 21:47:41 | 000,172,518 | ---- | C] ()
Gfxres.hr-HR.resources -> C:\Windows\SysNative\Gfxres.hr-HR.resources -> [2014-05-06 21:47:41 | 000,171,658 | ---- | C] ()
Gfxres.sl-SI.resources -> C:\Windows\SysNative\Gfxres.sl-SI.resources -> [2014-05-06 21:47:41 | 000,168,169 | ---- | C] ()
Gfxres.nb-NO.resources -> C:\Windows\SysNative\Gfxres.nb-NO.resources -> [2014-05-06 21:47:41 | 000,166,889 | ---- | C] ()
Gfxres.da-DK.resources -> C:\Windows\SysNative\Gfxres.da-DK.resources -> [2014-05-06 21:47:41 | 000,166,210 | ---- | C] ()
Gfxres.en-US.resources -> C:\Windows\SysNative\Gfxres.en-US.resources -> [2014-05-06 21:47:41 | 000,161,534 | ---- | C] ()
Gfxres.zh-TW.resources -> C:\Windows\SysNative\Gfxres.zh-TW.resources -> [2014-05-06 21:47:41 | 000,154,816 | ---- | C] ()
Gfxres.zh-CN.resources -> C:\Windows\SysNative\Gfxres.zh-CN.resources -> [2014-05-06 21:47:41 | 000,153,043 | ---- | C] ()
aswHwid.sys -> C:\Windows\SysNative\drivers\aswHwid.sys -> [2014-05-02 19:36:09 | 000,029,208 | ---- | C] ()
AdwCleaner.exe -> C:\Users\ja\Desktop\AdwCleaner.exe -> [2014-05-02 19:13:27 | 001,310,621 | ---- | C] ()
BRWMARK.INI -> C:\Windows\BRWMARK.INI -> [2013-11-28 20:31:36 | 000,000,404 | ---- | C] ()
BRPP2KA.INI -> C:\Windows\BRPP2KA.INI -> [2013-11-28 20:31:36 | 000,000,027 | ---- | C] ()
PnkBstrA.exe -> C:\Windows\SysWow64\PnkBstrA.exe -> [2013-09-27 20:49:16 | 000,075,064 | ---- | C] ()
PerfStringBackup.INI -> C:\Windows\SysWow64\PerfStringBackup.INI -> [2013-09-27 03:32:23 | 001,644,158 | ---- | C] ()
GSetup.ini -> C:\Windows\GSetup.ini -> [2013-09-27 03:15:27 | 000,000,010 | ---- | C] ()
IusEventLog.dll -> C:\Windows\SysWow64\IusEventLog.dll -> [2013-02-13 12:27:54 | 000,001,536 | ---- | C] ()
< End of report >
kamos1602 napisał(a):A spróbuj skorzystać z programu adwcleaner, on usuwa takie rzeczy
Win32:Sality napisał(a):No nie wierzę. Kolejny @#$%^&*, drugi w tym temacie,
Anonymous0 oraz kamos1602:
Uwierzcie mi, że wiem więcej o AdwCleanerze i o tym co robi i jak robi niż wy i połowa tego forum razem wzięta. Jakby się dało problem rozwiązać tym narzędziem, to już dawno by był rozwiązany. Ponieważ się nie da, bo go NIE WIDZĘ, dlatego grzebię i szukam. Jeśli uważacie, że się mylę, to chętie oddam Wam prowadzenie pomocy. To samo tyczy się przyszłych chętnych polecania narzędzi nie mając nawet pojęcia co oznaczają generowane przez nich raporty.
tomek510@op.pl,
albo nie widzę czegoś bardzo oczywistego, albo nie wiem co jest grane. Naprawdę.
Zainstaluj rozszerzenie do Chorome'a/FireFoxa o nazwie Web of Trust. Spróbuj się dostać na blokowaną stronę i zobacz, czy wyświetli on komunikat o zainfekowanej witrynie.
Będę jeszcze raz leciał przez wszystkie te raporty, może coś znajdę.
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 6 gości