
JEstem tu nowa, witam serdecznie wszystkich forumowiczów, mam problemy z kompami dwoma w domu. Dzieci pewnie coś zbroiły i są zarażone wirusem niewykrywanym przez NOda i Gdatę.
Do wczoraj wyskakiwały Samoczynnie otwierające sie strony np. mktmobi.com lub scache.earozo.com....
Zapuściłam AdwCleaner i coś pousuwał, na razie jest Ok już się strony nie otwierają zaktualizowałam tez AdobeReadera oraz Jave.
Logi z OTLa dla mojego PC:
- Kod: Zaznacz wszystko
˙ţOTL logfile created on: 2013-01-08
08:21:37 - Run 2
OTL by OldTimer - Version 3.2.69.0
Folder = C:\Users\albert\Desktop
64bit- Professional Service Pack 1
(Version = 6.1.7601) - Type =
NTWorkstation
Internet Explorer (Version =
9.0.8112.16421)
Locale: 00000415 | Country: Polska |
Language: PLK | Date Format:
yyyy-MM-dd
4,00 Gb Total Physical Memory | 2,45
Gb Available Physical Memory | 61,19%
Memory free
8,00 Gb Paging File | 6,23 Gb
Available in Paging File | 77,87%
Paging File free
Paging file location(s):
?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% =
C:\Windows | %ProgramFiles% =
C:\Program Files (x86)
Drive C: | 195,21 Gb Total Space |
139,65 Gb Free Space | 71,54% Space
Free | Partition Type: NTFS
Drive D: | 270,44 Gb Total Space |
202,16 Gb Free Space | 74,75% Space
Free | Partition Type: NTFS
Computer Name: ALBERT-KOMPUTER | User
Name: albert | Logged in as
Administrator.
Boot Mode: Normal | Scan Mode: Current
user | Include 64bit Scans
Company Name Whitelist: Off | Skip
Microsoft Files: Off | No Company Name
Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes
(SafeList) ==========[/color]
PRC - [2013-01-08 00:08:19 |
000,602,112 | ---- | M] (OldTimer
Tools) --
C:\Users\albert\Desktop\OTL.exe
PRC - [2012-12-14 10:30:17 |
009,116,152 | ---- | M] (TeamViewer
GmbH) -- C:\Program Files
(x86)\TeamViewer\Version8\TeamViewer.exe
PRC - [2012-12-14 10:30:17 |
003,472,376 | ---- | M] (TeamViewer
GmbH) -- C:\Program Files
(x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2012-12-14 10:08:24 |
000,190,968 | ---- | M] (TeamViewer
GmbH) -- C:\Program Files
(x86)\TeamViewer\Version8\tv_w32.exe
PRC - [2012-11-16 14:24:44 |
000,913,184 | ---- | M] (ESET) --
C:\Program Files\ESET\ESET NOD32
Antivirus\x86\ekrn.exe
PRC - [2012-10-27 18:04:05 |
000,212,432 | ---- | M] (Google Inc.)
-- C:\Program Files
(x86)\Google\Update\1.3.21.123\GoogleCrashHandler.exe
PRC - [2012-10-02 13:15:38 |
000,382,824 | ---- | M] (NVIDIA
Corporation) -- C:\Program Files
(x86)\NVIDIA Corporation\3D
Vision\nvSCPAPISvr.exe
PRC - [2012-09-23 20:43:34 |
000,065,192 | ---- | M] (Adobe Systems
Incorporated) -- C:\Program Files
(x86)\Common
Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011-06-09 17:50:24 |
000,636,272 | ---- | M] (PIXELA
CORPORATION) -- C:\Program Files
(x86)\PIXELA\VideoBrowser\CameraMonitor.exe
PRC - [2006-12-19 10:30:26 |
000,081,920 | ---- | M] (Prolific
Technology Inc.) --
C:\Windows\SysWOW64\IoctlSvc.exe
[color=#E56717]========== Modules (No
Company Name) ==========[/color]
MOD - [2011-06-09 17:50:32 |
000,364,544 | ---- | M] () --
C:\Program Files
(x86)\PIXELA\VideoBrowser\pxl_m17n_tool.dll
[color=#E56717]========== Services
(SafeList) ==========[/color]
SRV:[b]64bit:[/b] - [2012-11-16
14:24:44 | 000,913,184 | ---- | M]
(ESET) [Auto | Running] -- C:\Program
Files\ESET\ESET NOD32
Antivirus\x86\ekrn.exe -- (ekrn)
SRV:[b]64bit:[/b] - [2012-04-16
21:28:26 | 001,038,088 | ---- | M]
(Acresso Software Inc.) [On_Demand |
Stopped] -- C:\Program Files\Common
Files\Macrovision Shared\FLEXnet
Publisher\FNPLicensingService64.exe --
(FLEXnet Licensing Service 64)
SRV:[b]64bit:[/b] - [2009-07-14
02:41:27 | 001,011,712 | ---- | M]
(Microsoft Corporation) [Auto |
Running] -- C:\Program Files\Windows
Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2009-07-14
02:40:01 | 000,193,536 | ---- | M]
(Microsoft Corporation) [On_Demand |
Stopped] --
C:\Windows\SysNative\appmgmts.dll --
(AppMgmt)
SRV - [2012-12-16 17:11:35 |
000,115,168 | ---- | M] (Mozilla
Foundation) [On_Demand | Stopped] --
C:\Program Files (x86)\Mozilla
Maintenance
Service\maintenanceservice.exe --
(MozillaMaintenance)
SRV - [2012-12-14 10:30:17 |
003,472,376 | ---- | M] (TeamViewer
GmbH) [Auto | Running] -- C:\Program
Files
(x86)\TeamViewer\Version8\TeamViewer_Service.exe
-- (TeamViewer8)
SRV - [2012-10-10 21:23:42 |
001,258,856 | ---- | M] (NVIDIA
Corporation) [Auto | Stopped] --
C:\Program Files (x86)\NVIDIA
Corporation\NVIDIA Update
Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012-10-02 13:15:38 |
000,382,824 | ---- | M] (NVIDIA
Corporation) [Auto | Running] --
C:\Program Files (x86)\NVIDIA
Corporation\3D Vision\nvSCPAPISvr.exe
-- (Stereo Service)
SRV - [2012-09-23 20:43:34 |
000,065,192 | ---- | M] (Adobe Systems
Incorporated) [Auto | Running] --
C:\Program Files (x86)\Common
Files\Adobe\ARM\1.0\armsvc.exe --
(AdobeARMservice)
SRV - [2012-04-16 21:28:22 |
000,655,624 | ---- | M] (Acresso
Software Inc.) [On_Demand | Stopped]
-- C:\Program Files (x86)\Common
Files\Macrovision Shared\FLEXnet
Publisher\FNPLicensingService.exe --
(FLEXnet Licensing Service)
SRV - [2010-03-18 13:16:28 |
000,130,384 | ---- | M] (Microsoft
Corporation) [Auto | Stopped] --
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
-- (clr_optimization_v4.0.30319_32)
SRV - [2009-06-10 22:23:09 |
000,066,384 | ---- | M] (Microsoft
Corporation) [Disabled | Stopped] --
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
-- (clr_optimization_v2.0.50727_32)
SRV - [2006-12-19 10:30:26 |
000,081,920 | ---- | M] (Prolific
Technology Inc.) [Auto | Running] --
C:\Windows\SysWOW64\IoctlSvc.exe --
(PLFlash DeviceIoControl Service)
[color=#E56717]========== Driver
Services (SafeList) ==========[/color]
DRV:[b]64bit:[/b] - [2012-11-28
18:49:00 | 000,035,112 | ---- | M]
(TeamViewer GmbH) [Kernel | On_Demand
| Running] --
C:\Windows\SysNative\drivers\teamviewervpn.sys
-- (teamviewervpn)
DRV:[b]64bit:[/b] - [2012-11-16
13:56:48 | 000,209,808 | ---- | M]
(ESET) [File_System | System |
Running] --
C:\Windows\SysNative\drivers\eamonm.sys
-- (eamonm)
DRV:[b]64bit:[/b] - [2012-03-14
07:40:04 | 000,137,144 | ---- | M]
(ESET) [Kernel | Auto | Running] --
C:\Windows\SysNative\drivers\epfwwfpr.sys
-- (epfwwfpr)
DRV:[b]64bit:[/b] - [2012-03-14
07:40:02 | 000,148,528 | ---- | M]
(ESET) [Kernel | System | Running] --
C:\Windows\SysNative\drivers\ehdrv.sys
-- (ehdrv)
DRV:[b]64bit:[/b] - [2012-03-01
07:46:16 | 000,023,408 | ---- | M]
(Microsoft Corporation) [Recognizer |
Boot | Unknown] --
C:\Windows\SysNative\drivers\fs_rec.sys
-- (Fs_Rec)
DRV:[b]64bit:[/b] - [2011-03-11
07:41:12 | 000,107,904 | ---- | M]
(Advanced Micro Devices) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\amdsata.sys
-- (amdsata)
DRV:[b]64bit:[/b] - [2011-03-11
07:41:12 | 000,027,008 | ---- | M]
(Advanced Micro Devices) [Kernel |
Boot | Running] --
C:\Windows\SysNative\drivers\amdxata.sys
-- (amdxata)
DRV:[b]64bit:[/b] - [2010-11-20
14:33:35 | 000,078,720 | ---- | M]
(Hewlett-Packard Company) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\HpSAMD.sys
-- (HpSAMD)
DRV:[b]64bit:[/b] - [2010-11-20
12:07:05 | 000,059,392 | ---- | M]
(Microsoft Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\TsUsbFlt.sys
-- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2009-07-14
02:52:20 | 000,194,128 | ---- | M]
(AMD Technologies Inc.) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\amdsbs.sys
-- (amdsbs)
DRV:[b]64bit:[/b] - [2009-07-14
02:48:04 | 000,065,600 | ---- | M]
(LSI Corporation) [Kernel | On_Demand
| Stopped] --
C:\Windows\SysNative\drivers\lsi_sas2.sys
-- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009-07-14
02:45:55 | 000,024,656 | ---- | M]
(Promise Technology) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\stexstor.sys
-- (stexstor)
DRV:[b]64bit:[/b] - [2009-06-10
21:35:42 | 000,187,392 | ---- | M]
(Realtek Corporation
) [Kernel |
On_Demand | Running] --
C:\Windows\SysNative\drivers\Rt64win7.sys
-- (RTL8167)
DRV:[b]64bit:[/b] - [2009-06-10
21:34:33 | 003,286,016 | ---- | M]
(Broadcom Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\evbda.sys
-- (ebdrv)
DRV:[b]64bit:[/b] - [2009-06-10
21:34:28 | 000,468,480 | ---- | M]
(Broadcom Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\bxvbda.sys
-- (b06bdrv)
DRV:[b]64bit:[/b] - [2009-06-10
21:34:23 | 000,270,848 | ---- | M]
(Broadcom Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\b57nd60a.sys
-- (b57nd60a)
DRV:[b]64bit:[/b] - [2009-06-10
21:31:59 | 000,031,232 | ---- | M]
(Hauppauge Computer Works, Inc.)
[Kernel | On_Demand | Stopped] --
C:\Windows\SysNative\drivers\hcw85cir.sys
-- (hcw85cir)
DRV:[b]64bit:[/b] - [2008-06-27
06:51:10 | 000,088,632 | ---- | M]
(Adobe Systems, Inc.) [Kernel | Auto |
Running] --
C:\Windows\SysNative\drivers\adfs.sys
-- (adfs)
DRV - [2009-07-14 02:19:10 |
000,019,008 | ---- | M] (Microsoft
Corporation) [File_System | On_Demand
| Stopped] --
C:\Windows\SysWOW64\drivers\wimmount.sys
-- (WIMMount)
DRV - [2008-08-14 06:57:42 |
000,074,720 | ---- | M] (Adobe
Systems, Inc.) [Kernel | Auto |
Running] --
C:\Windows\SysWow64\drivers\adfs.sys
-- (adfs)
[color=#E56717]========== Standard
Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet
Explorer ==========[/color]
IE:[b]64bit:[/b] -
HKLM\..\SearchScopes,DefaultScope =
IE:[b]64bit:[/b] -
HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:
"URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet
Explorer\Main,Default_Page_URL =
about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet
Explorer\Main,Local Page =
C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet
Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope
=
IE -
HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:
"URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet
Explorer\Main,Default_Page_URL =
about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet
Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,DefaultScope
=
IE -
HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:
"URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox
==========[/color]
FF -
prefs.js..browser.search.suggest.enabled:
false
FF -
prefs.js..browser.search.useDBForOrder:
true
FF -
prefs.js..browser.startup.homepage:
"about:blank"
FF -
prefs.js..extensions.enabledAddons:
%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:[b]64bit:[/b] -
HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:
C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll
File not found
FF:[b]64bit:[/b] -
HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2:
C:\Windows\system32\npDeployJava1.dll
File not found
FF:[b]64bit:[/b] -
HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2:
C:\Program
Files\Java\jre7\bin\plugin2\npjp2.dll
(Oracle Corporation)
FF:[b]64bit:[/b] -
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE:
disabled File not found
FF -
HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
()
FF -
HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0:
C:\Program Files
(x86)\Google\Picasa3\npPicasa3.dll
(Google, Inc.)
FF -
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE:
disabled File not found
FF -
HKLM\Software\MozillaPlugins\@nvidia.com/3DVision:
C:\Program Files (x86)\NVIDIA
Corporation\3D Vision\npnv3dv.dll
(NVIDIA Corporation)
FF -
HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming:
C:\Program Files (x86)\NVIDIA
Corporation\3D
Vision\npnv3dvstreaming.dll (NVIDIA
Corporation)
FF -
HKLM\Software\MozillaPlugins\@tools.google.com/Google
Update;version=3: C:\Program Files
(x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
(Google Inc.)
FF -
HKLM\Software\MozillaPlugins\@tools.google.com/Google
Update;version=9: C:\Program Files
(x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
(Google Inc.)
FF -
HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5:
C:\Program Files
(x86)\VideoLAN\VLC\npvlc.dll
(VideoLAN)
FF -
HKLM\Software\MozillaPlugins\Adobe
Reader: C:\Program Files
(x86)\Adobe\Reader
11.0\Reader\AIR\nppdf32.dll (Adobe
Systems Inc.)
FF -
HKEY_LOCAL_MACHINE\software\mozilla\Mozilla
Firefox 17.0.1\extensions\\Components:
C:\Program Files (x86)\Mozilla
Firefox\components [2012-12-16
17:11:36 | 000,000,000 | ---D | M]
FF -
HKEY_LOCAL_MACHINE\software\mozilla\Mozilla
Firefox 17.0.1\extensions\\Plugins:
C:\Program Files (x86)\Mozilla
Firefox\plugins
FF -
HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com:
C:\Program Files\ESET\ESET NOD32
Antivirus\Mozilla Thunderbird
[2013-01-07 23:59:50 | 000,000,000 |
---D | M]
[2012-01-12 20:54:06 | 000,000,000 |
---D | M] (No name found) --
C:\Users\albert\AppData\Roaming\mozilla\Extensions
[2013-01-07 23:44:15 | 000,000,000 |
---D | M] (No name found) --
C:\Users\albert\AppData\Roaming\mozilla\Firefox\Profiles\knwioh4u.default\extensions
[2013-01-07 15:56:38 | 000,001,300 |
---- | M] () --
C:\Users\albert\AppData\Roaming\mozilla\firefox\profiles\knwioh4u.default\searchplugins\claro.xml
[2012-11-12 15:23:51 | 000,000,000 |
---D | M] (No name found) --
C:\Program Files (x86)\mozilla
firefox\extensions
[2012-12-16 17:11:36 | 000,262,112 |
---- | M] (Mozilla Foundation) --
C:\Program Files (x86)\mozilla
firefox\components\browsercomps.dll
[2012-11-08 18:11:06 | 000,002,767 |
---- | M] () -- C:\Program Files
(x86)\mozilla
firefox\searchplugins\allegro-pl.xml
[2012-11-08 18:11:06 | 000,001,406 |
---- | M] () -- C:\Program Files
(x86)\mozilla
firefox\searchplugins\fbc-pl.xml
[2012-11-08 18:11:06 | 000,000,917 |
---- | M] () -- C:\Program Files
(x86)\mozilla
firefox\searchplugins\merlin-pl.xml
[2012-11-08 18:11:06 | 000,000,858 |
---- | M] () -- C:\Program Files
(x86)\mozilla
firefox\searchplugins\pwn-pl.xml
[2012-11-08 18:11:06 | 000,001,183 |
---- | M] () -- C:\Program Files
(x86)\mozilla
firefox\searchplugins\wikipedia-pl.xml
[2012-11-08 18:11:06 | 000,001,683 |
---- | M] () -- C:\Program Files
(x86)\mozilla
firefox\searchplugins\wp-pl.xml
[color=#E56717]========== Chrome
==========[/color]
CHR - default_search_provider: Claro
Search (Enabled)
CHR - default_search_provider:
search_url =
http://www.claro-search.com/?q={searchTerms}&affID=114506&tl=gkn487508&tt=0213_2&babsrc=SP_clro&mntrId=c260f53b00000000000000241d9f1c81
CHR - default_search_provider:
suggest_url =
{google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash
(Enabled) = C:\Program Files
(x86)\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop
Viewer (Enabled) =
internal-remoting-viewer
CHR - plugin: Native Client (Enabled)
= C:\Program Files
(x86)\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer
(Enabled) = C:\Program Files
(x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Picasa (Enabled) =
C:\Program Files
(x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled)
= C:\Program Files
(x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision
(Enabled) = C:\Program Files
(x86)\NVIDIA Corporation\3D
Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION
(Enabled) = C:\Program Files
(x86)\NVIDIA Corporation\3D
Vision\npnv3dvstreaming.dll
CHR - plugin: VLC Web Plugin (Enabled)
= C:\Program Files
(x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Shockwave Flash
(Enabled) =
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
O1 HOSTS File: ([2009-06-10 22:00:26 |
000,000,824 | ---- | M]) -
C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Java(tm)
Plug-In SSV Helper) -
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
- C:\Program
Files\Java\jre7\bin\ssv.dll (Oracle
Corporation)
O2:[b]64bit:[/b] - BHO: (Java(tm)
Plug-In 2 SSV Helper) -
{DBC80044-A445-435b-BC74-9C25C1C588A9}
- C:\Program
Files\Java\jre7\bin\jp2ssv.dll (Oracle
Corporation)
O2 - BHO: (no name) -
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
- No CLSID value found.
O2 - BHO: (no name) -
{DBC80044-A445-435b-BC74-9C25C1C588A9}
- No CLSID value found.
O4:[b]64bit:[/b] - HKLM..\Run: [egui]
C:\Program Files\ESET\ESET NOD32
Antivirus\egui.exe (ESET)
O4:[b]64bit:[/b] - HKLM..\Run:
[RTHDVCPL] C:\Program
Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor)
O4 - HKLM..\Run:
[AdobeCS4ServiceManager] C:\Program
Files (x86)\Common
Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
(Adobe Systems Incorporated)
O4 - HKLM..\Run: [NBKeyScan]
C:\Program Files (x86)\Nero\Nero8\Nero
BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKCU..\Run: [AdobeBridge] File
not found
O6 -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoActiveDesktop = 1
O6 -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoActiveDesktopChanges = 1
O6 -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
ConsentPromptBehaviorAdmin = 5
O6 -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
ConsentPromptBehaviorUser = 3
O8:[b]64bit:[/b] - Extra context menu
item: Add to Google Photos
Screensa&ver -
res://C:\Windows\system32\GPhotos.scr/200
File not found
O8:[b]64bit:[/b] - Extra context menu
item: E&ksportuj do programu
Microsoft Excel -
res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
File not found
O8 - Extra context menu item: Add to
Google Photos Screensa&ver -
C:\Windows\SysWow64\GPhotos.scr
(Google Inc.)
O8 - Extra context menu item:
E&ksportuj do programu Microsoft
Excel -
res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
File not found
O9 - Extra Button: Wy[lij do programu
OneNote -
{2670000A-7350-4f3c-8081-5663EE0C6C49}
-
C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
(Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Wy[lij
&do programu OneNote -
{2670000A-7350-4f3c-8081-5663EE0C6C49}
-
C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
(Microsoft Corporation)
O9 - Extra Button: Research -
{92780B25-18CC-41C8-B9BE-3C9C571A8263}
-
C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
(Microsoft Corporation)
O13[b]64bit:[/b] - gopher Prefix:
missing
O13 - gopher Prefix: missing
O16 - DPF:
{D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
(Shockwave Flash Object)
O17 -
HKLM\System\CCS\Services\Tcpip\Parameters:
DhcpNameServer = 192.168.1.1
O17 -
HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5D2CD91E-87DA-47BB-9B7A-9ED567772F57}:
DhcpNameServer = 192.168.1.1
O18:[b]64bit:[/b] -
Protocol\Handler\grooveLocalGWS - No
CLSID value found
O18:[b]64bit:[/b] -
Protocol\Handler\ms-help - No CLSID
value found
O18 - Protocol\Filter\text/xml
{807563E5-5146-11D5-A672-00B0D022E945}
-
C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
(Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon:
Shell - (explorer.exe) -
C:\Windows\explorer.exe (Microsoft
Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon:
UserInit -
(C:\Windows\system32\userinit.exe) -
C:\Windows\SysNative\userinit.exe
(Microsoft Corporation)
O20 - HKLM Winlogon: Shell -
(explorer.exe) -
C:\Windows\SysWow64\explorer.exe
(Microsoft Corporation)
O20 - HKLM Winlogon: UserInit -
(userinit.exe) -
C:\Windows\SysWow64\userinit.exe
(Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck -
{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- No CLSID value found.
O21 - SSODL: WebCheck -
{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 -
MountPoints2\{9c32c905-3d41-11e1-9936-806e6f6e6963}\Shell
- "" = AutoRun
O33 -
MountPoints2\{9c32c905-3d41-11e1-9936-806e6f6e6963}\Shell\AutoRun\command
- "" = E:\Launcher.exe
O34 - HKLM BootExecute: (autocheck
autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile
[open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile
[open] -- "%1" %*
O35 - HKLM\..comfile [open] --
"%1" %*
O35 - HKLM\..exefile [open] --
"%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ =
comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ =
exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] --
"%1" %*
O37 - HKLM\...exe [@ = exefile] --
"%1" %*
O38 - SubSystems\\Windows:
(ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows:
(ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows:
(ServerDll=sxssrv,4)
[color=#E56717]==========
Files/Folders - Created Within 30 Days
==========[/color]
[2013-01-08 08:12:23 | 001,081,320 |
---- | C] (Oracle Corporation) --
C:\Windows\SysNative\npDeployJava1.dll
[2013-01-08 08:12:23 | 000,959,976 |
---- | C] (Oracle Corporation) --
C:\Windows\SysNative\deployJava1.dll
[2013-01-08 08:12:23 | 000,308,200 |
---- | C] (Oracle Corporation) --
C:\Windows\SysNative\javaws.exe
[2013-01-08 08:12:16 | 000,188,392 |
---- | C] (Oracle Corporation) --
C:\Windows\SysNative\javaw.exe
[2013-01-08 08:12:16 | 000,188,392 |
---- | C] (Oracle Corporation) --
C:\Windows\SysNative\java.exe
[2013-01-08 08:12:16 | 000,108,008 |
---- | C] (Oracle Corporation) --
C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013-01-08 08:12:01 | 000,000,000 |
---D | C] -- C:\Program Files\Java
[2013-01-08 00:22:28 | 000,035,112 |
---- | C] (TeamViewer GmbH) --
C:\Windows\SysNative\drivers\teamviewervpn.sys
[2013-01-08 00:22:25 | 000,000,000 |
---D | C] -- C:\Program Files
(x86)\TeamViewer
[2013-01-08 00:18:48 | 000,602,112 |
---- | C] (OldTimer Tools) --
C:\Users\albert\Desktop\OTL.exe
[2013-01-08 00:03:23 | 000,000,000 |
---D | C] --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\CCleaner
[2013-01-08 00:03:21 | 000,000,000 |
---D | C] -- C:\Program Files\CCleaner
[2013-01-07 23:59:43 | 000,000,000 |
---D | C] --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\ESET
[2013-01-07 23:59:42 | 000,000,000 |
---D | C] -- C:\ProgramData\ESET
[2013-01-07 23:59:42 | 000,000,000 |
---D | C] -- C:\Program Files\ESET
[2013-01-07 23:29:53 | 000,000,000 |
---D | C] --
C:\Users\albert\AppData\Roaming\vlc
[2013-01-07 23:28:05 | 000,000,000 |
---D | C] --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\VideoLAN
[2013-01-07 17:05:59 | 000,000,000 |
---D | C] --
C:\Windows\SysNative\appmgmt
[2012-12-27 19:31:52 | 000,000,000 |
---D | C] --
C:\ProgramData\InstallShield
[2012-12-21 22:39:21 | 000,034,304 |
---- | C] (Adobe Systems) --
C:\Windows\SysWow64\atmlib.dll
[2012-12-21 22:39:20 | 000,046,080 |
---- | C] (Adobe Systems) --
C:\Windows\SysNative\atmlib.dll
[2012-12-21 22:39:18 | 000,367,616 |
---- | C] (Adobe Systems Incorporated)
-- C:\Windows\SysNative\atmfd.dll
[2012-12-21 22:39:17 | 000,295,424 |
---- | C] (Adobe Systems Incorporated)
-- C:\Windows\SysWow64\atmfd.dll
[2012-12-16 17:10:18 | 000,019,000 |
---- | C] (PerformerSoft LLC) --
C:\Windows\SysNative\roboot64.exe
[2012-12-13 03:02:37 | 000,096,768 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\mshtmled.dll
[2012-12-13 03:02:37 | 000,073,216 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\mshtmled.dll
[2012-12-13 03:02:36 | 000,248,320 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\ieui.dll
[2012-12-13 03:02:36 | 000,176,640 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\ieui.dll
[2012-12-13 03:02:36 | 000,173,056 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\ieUnatt.exe
[2012-12-13 03:02:35 | 000,237,056 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\url.dll
[2012-12-13 03:02:35 | 000,231,936 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\url.dll
[2012-12-13 03:02:35 | 000,142,848 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\ieUnatt.exe
[2012-12-13 03:02:33 | 002,312,704 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\jscript9.dll
[2012-12-13 03:02:33 | 001,494,528 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\inetcpl.cpl
[2012-12-13 03:02:33 | 001,427,968 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\inetcpl.cpl
[2012-12-13 03:02:33 | 000,729,088 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\msfeeds.dll
[2012-12-13 03:02:31 | 000,717,824 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\jscript.dll
[2012-12-13 03:02:30 | 000,816,640 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\jscript.dll
[2012-12-13 03:02:30 | 000,599,040 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\vbscript.dll
[2012-12-12 16:36:24 | 001,161,216 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\kernel32.dll
[2012-12-12 16:36:24 | 000,424,960 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\KernelBase.dll
[2012-12-12 16:36:23 | 000,338,432 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\conhost.exe
[2012-12-12 16:36:23 | 000,215,040 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\winsrv.dll
[2012-12-12 16:36:20 | 000,362,496 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\wow64win.dll
[2012-12-12 16:36:20 | 000,243,200 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\wow64.dll
[2012-12-12 16:36:20 | 000,025,600 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\setup16.exe
[2012-12-12 16:36:20 | 000,016,384 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\ntvdm64.dll
[2012-12-12 16:36:20 | 000,014,336 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\ntvdm64.dll
[2012-12-12 16:36:20 | 000,013,312 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\wow64cpu.dll
[2012-12-12 16:36:20 | 000,005,120 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\wow32.dll
[2012-12-12 16:36:16 | 000,007,680 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\instnm.exe
[2012-12-12 16:36:16 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012-12-12 16:36:16 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012-12-12 16:36:15 | 000,006,144 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012-12-12 16:36:15 | 000,005,120 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012-12-12 16:36:15 | 000,005,120 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012-12-12 16:36:15 | 000,004,608 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012-12-12 16:36:15 | 000,004,608 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012-12-12 16:36:15 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012-12-12 16:36:15 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012-12-12 16:36:15 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012-12-12 16:36:15 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012-12-12 16:36:15 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012-12-12 16:36:15 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012-12-12 16:36:15 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012-12-12 16:36:15 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012-12-12 16:36:15 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012-12-12 16:36:14 | 000,004,608 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012-12-12 16:36:14 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012-12-12 16:36:14 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012-12-12 16:36:14 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012-12-12 16:36:14 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012-12-12 16:36:14 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012-12-12 16:36:14 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012-12-12 16:36:14 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012-12-12 16:36:14 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012-12-12 16:36:14 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012-12-12 16:36:14 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012-12-12 16:36:14 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-12-12 16:36:14 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-12-12 16:36:14 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012-12-12 16:36:14 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012-12-12 16:36:14 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012-12-12 16:36:13 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012-12-12 16:36:13 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012-12-12 16:36:12 | 000,006,144 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012-12-12 16:36:12 | 000,004,608 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012-12-12 16:36:12 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012-12-12 16:36:12 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012-12-12 16:36:12 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012-12-12 16:36:12 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012-12-12 16:36:12 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012-12-12 16:36:12 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012-12-12 16:36:11 | 000,002,048 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\user.exe
[2012-12-12 16:35:50 | 000,478,208 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\dpnet.dll
[2012-12-12 16:35:50 | 000,376,832 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\dpnet.dll
[1 C:\Windows\*.tmp files ->
C:\Windows\*.tmp -> ]
[color=#E56717]========== Files -
Modified Within 30 Days
==========[/color]
[2013-01-08 08:16:11 | 000,002,023 |
---- | M] () --
C:\Users\Public\Desktop\Adobe Reader
XI.lnk
[2013-01-08 08:12:10 | 000,108,008 |
---- | M] (Oracle Corporation) --
C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013-01-08 08:12:04 | 000,308,200 |
---- | M] (Oracle Corporation) --
C:\Windows\SysNative\javaws.exe
[2013-01-08 08:12:04 | 000,188,392 |
---- | M] (Oracle Corporation) --
C:\Windows\SysNative\javaw.exe
[2013-01-08 08:12:04 | 000,188,392 |
---- | M] (Oracle Corporation) --
C:\Windows\SysNative\java.exe
[2013-01-08 08:12:03 | 001,081,320 |
---- | M] (Oracle Corporation) --
C:\Windows\SysNative\npDeployJava1.dll
[2013-01-08 08:12:03 | 000,959,976 |
---- | M] (Oracle Corporation) --
C:\Windows\SysNative\deployJava1.dll
[2013-01-08 08:09:00 | 000,001,048 |
---- | M] () --
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-01-08 07:29:13 | 000,067,584 |
--S- | M] () --
C:\Windows\bootstat.dat
[2013-01-08 00:08:19 | 000,602,112 |
---- | M] (OldTimer Tools) --
C:\Users\albert\Desktop\OTL.exe
[2013-01-08 00:03:23 | 000,000,826 |
---- | M] () --
C:\Users\Public\Desktop\CCleaner.lnk
[2013-01-08 00:01:26 | 001,549,932 |
---- | M] () --
C:\Windows\SysNative\PerfStringBackup.INI
[2013-01-08 00:01:26 | 000,697,896 |
---- | M] () --
C:\Windows\SysNative\perfh015.dat
[2013-01-08 00:01:26 | 000,616,032 |
---- | M] () --
C:\Windows\SysNative\perfh009.dat
[2013-01-08 00:01:26 | 000,135,006 |
---- | M] () --
C:\Windows\SysNative\perfc015.dat
[2013-01-08 00:01:26 | 000,106,412 |
---- | M] () --
C:\Windows\SysNative\perfc009.dat
[2013-01-07 23:55:10 | 000,001,044 |
---- | M] () --
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-01-07 23:54:53 | 3220,037,632 |
-HS- | M] () -- C:\hiberfil.sys
[2013-01-07 23:53:06 | 000,000,000 |
---- | M] () --
C:\Windows\SysWow64\config.nt
[2013-01-07 23:44:29 | 000,012,720 |
-H-- | M] () --
C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013-01-07 23:44:29 | 000,012,720 |
-H-- | M] () --
C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013-01-07 23:28:05 | 000,001,070 |
---- | M] () --
C:\Users\Public\Desktop\VLC media
player.lnk
[2013-01-07 22:32:40 | 003,027,144 |
---- | M] () --
C:\Windows\SysNative\FNTCACHE.DAT
[2012-12-16 18:11:22 | 000,046,080 |
---- | M] (Adobe Systems) --
C:\Windows\SysNative\atmlib.dll
[2012-12-16 15:45:03 | 000,367,616 |
---- | M] (Adobe Systems Incorporated)
-- C:\Windows\SysNative\atmfd.dll
[2012-12-16 15:13:28 | 000,295,424 |
---- | M] (Adobe Systems Incorporated)
-- C:\Windows\SysWow64\atmfd.dll
[2012-12-16 15:13:20 | 000,034,304 |
---- | M] (Adobe Systems) --
C:\Windows\SysWow64\atmlib.dll
[1 C:\Windows\*.tmp files ->
C:\Windows\*.tmp -> ]
[color=#E56717]========== Files
Created - No Company Name
==========[/color]
[2013-01-08 08:16:11 | 000,002,441 |
---- | C] () --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\Adobe Reader XI.lnk
[2013-01-08 08:16:11 | 000,002,023 |
---- | C] () --
C:\Users\Public\Desktop\Adobe Reader
XI.lnk
[2013-01-08 00:22:31 | 000,001,178 |
---- | C] () --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\TeamViewer 8 Host.lnk
[2013-01-08 00:03:23 | 000,000,826 |
---- | C] () --
C:\Users\Public\Desktop\CCleaner.lnk
[2013-01-07 23:28:05 | 000,001,070 |
---- | C] () --
C:\Users\Public\Desktop\VLC media
player.lnk
[2012-08-18 11:52:18 | 000,003,584 |
---- | C] () --
C:\Users\albert\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-03-12 15:13:12 | 000,000,069 |
---- | C] () --
C:\Windows\NeroDigital.ini
[2012-02-13 13:09:23 | 000,249,424 |
---- | C] () --
C:\Users\albert\AppData\Local\LT.SAV
[color=#E56717]========== ZeroAccess
Check ==========[/color]
[2009-07-14 05:55:00 | 000,000,227 |
RHS- | M] () --
C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
/64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
/64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
/64
"" =
C:\Windows\SysNative\shell32.dll --
[2012-06-09 06:43:10 | 014,172,672 |
---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" =
%SystemRoot%\system32\shell32.dll --
[2012-06-09 05:41:00 | 012,873,728 |
---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
/64
"" =
C:\Windows\SysNative\wbem\fastprox.dll
-- [2009-07-14 02:40:51 | 000,909,312
| ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" =
%systemroot%\system32\wbem\fastprox.dll
-- [2010-11-20 13:19:02 | 000,606,208
| ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
/64
"" =
C:\Windows\SysNative\wbem\wbemess.dll
-- [2009-07-14 02:41:56 | 000,505,856
| ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >
Oraz z LAptopa Sony Vaio:
- Kod: Zaznacz wszystko
˙ţOTL logfile created on: 2013-01-08
08:53:02 - Run 2
OTL by OldTimer - Version 3.2.69.0
Folder = C:\DOWNLOAD
64bit- Home Premium Edition Service
Pack 1 (Version = 6.1.7601) - Type =
NTWorkstation
Internet Explorer (Version =
9.0.8112.16421)
Locale: 00000415 | Country: Polska |
Language: PLK | Date Format:
yyyy-MM-dd
3,90 Gb Total Physical Memory | 1,57
Gb Available Physical Memory | 40,24%
Memory free
7,79 Gb Paging File | 4,90 Gb
Available in Paging File | 62,87%
Paging File free
Paging file location(s):
?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% =
C:\Windows | %ProgramFiles% =
C:\Program Files (x86)
Drive C: | 444,50 Gb Total Space |
377,34 Gb Free Space | 84,89% Space
Free | Partition Type: NTFS
Computer Name: ALBERT-VAIO | User
Name: ALBERT | Logged in as
Administrator.
Boot Mode: Normal | Scan Mode: Current
user | Include 64bit Scans
Company Name Whitelist: Off | Skip
Microsoft Files: Off | No Company Name
Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes
(SafeList) ==========[/color]
PRC - [2013-01-07 23:22:24 |
000,602,112 | ---- | M] (OldTimer
Tools) -- C:\DOWNLOAD\OTL.exe
PRC - [2012-12-14 10:30:17 |
009,116,152 | ---- | M] (TeamViewer
GmbH) -- C:\Program Files
(x86)\TeamViewer\Version8\TeamViewer.exe
PRC - [2012-12-14 10:30:17 |
003,472,376 | ---- | M] (TeamViewer
GmbH) -- C:\Program Files
(x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2012-12-14 10:08:24 |
000,190,968 | ---- | M] (TeamViewer
GmbH) -- C:\Program Files
(x86)\TeamViewer\Version8\tv_w32.exe
PRC - [2012-11-09 20:18:17 |
000,212,432 | ---- | M] (Google Inc.)
-- C:\Program Files
(x86)\Google\Update\1.3.21.123\GoogleCrashHandler.exe
PRC - [2012-09-23 20:43:34 |
000,065,192 | ---- | M] (Adobe Systems
Incorporated) -- C:\Program Files
(x86)\Common
Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012-05-29 00:54:30 |
000,054,464 | ---- | M] (Sony
Corporation) -- C:\Program
Files\Sony\VAIO Care\VCService.exe
PRC - [2012-02-23 17:35:18 |
000,182,200 | ---- | M] (Sony
Corporation) -- C:\Program Files
(x86)\Sony\VAIO Control
Center\VESMgrSub.exe
PRC - [2012-02-23 17:35:16 |
000,065,464 | ---- | M] (Sony
Corporation) -- C:\Program Files
(x86)\Sony\VAIO Control
Center\VESMgr.exe
PRC - [2012-02-23 09:16:25 |
000,291,608 | ---- | M] (Intel
Corporation) -- C:\Program Files
(x86)\Intel\Intel(R) USB 3.0
eXtensible Host Controller
Driver\Application\iusb3mon.exe
PRC - [2012-02-23 03:12:35 |
000,363,800 | ---- | M] (Intel
Corporation) -- C:\Program Files
(x86)\Intel\Intel(R) Management Engine
Components\UNS\UNS.exe
PRC - [2012-02-23 03:12:01 |
000,277,784 | ---- | M] (Intel
Corporation) -- C:\Program Files
(x86)\Intel\Intel(R) Management Engine
Components\LMS\LMS.exe
PRC - [2012-02-23 03:11:17 |
000,128,280 | ---- | M] () --
C:\Program Files (x86)\Intel\Intel(R)
Management Engine
Components\FWService\IntelMeFWService.exe
PRC - [2012-02-23 03:08:02 |
000,161,560 | ---- | M] (Intel
Corporation) -- C:\Program Files
(x86)\Intel\Intel(R) Management Engine
Components\DAL\Jhi_service.exe
PRC - [2012-02-21 12:41:12 |
000,473,960 | ---- | M] (Sony
Corporation) -- c:\Program Files
(x86)\Sony\PlayMemories
Home\PMBDeviceInfoProvider.exe
PRC - [2012-02-21 12:37:16 |
000,693,608 | ---- | M] (Sony
Corporation) -- C:\Program Files
(x86)\Sony\PlayMemories
Home\PMBVolumeWatcher.exe
PRC - [2012-01-18 23:40:48 |
005,536,440 | ---- | M] (iolo
technologies, LLC) -- C:\Program
Files\Sony\VAIO
Care\Iolo\ioloTools.exe
PRC - [2012-01-06 16:44:30 |
000,123,032 | ---- | M] (Sony
Corporation) -- C:\Program Files
(x86)\Common Files\Sony
Shared\SOHLib\SHTtray.exe
PRC - [2012-01-06 16:44:26 |
000,138,392 | ---- | M] (Sony
Corporation) -- C:\Program Files
(x86)\Common Files\Sony
Shared\SOHLib\SOHCImp.exe
PRC - [2011-12-29 16:10:08 |
000,960,160 | ---- | M] (Sony
Corporation) -- C:\Program Files
(x86)\Common Files\Sony Shared\VAIO
Content Folder Watcher\VCFw.exe
PRC - [2011-12-21 13:55:14 |
000,382,720 | ---- | M] (Sony
Corporation) -- C:\Program
Files\Sony\VCM Intelligent Network
Service Manager\VcmINSMgr.exe
PRC - [2011-12-21 13:15:06 |
000,550,128 | ---- | M] (Sony
Corporation) -- C:\Program
Files\Sony\VCM Intelligent Analyzing
Manager\VcmIAlzMgr.exe
PRC - [2011-12-19 19:16:50 |
001,104,208 | ---- | M] (Intel
Corporation) -- C:\Program Files
(x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2011-12-19 19:16:48 |
001,304,912 | ---- | M] (Intel
Corporation) -- C:\Program Files
(x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2011-12-19 19:16:44 |
001,014,096 | ---- | M] (Intel
Corporation) -- C:\Program Files
(x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2011-12-19 19:16:42 |
000,936,272 | ---- | M] (Intel
Corporation) -- C:\Program Files
(x86)\Intel\Bluetooth\btplayerctrl.exe
PRC - [2011-11-30 18:49:50 |
000,082,592 | ---- | M] (Sony of
America Corporation) -- C:\Program
Files\Sony\VAIO Care\listener.exe
PRC - [2011-11-29 20:04:56 |
000,013,592 | ---- | M] (Intel
Corporation) -- C:\Program Files
(x86)\Intel\Intel(R) Rapid Storage
Technology\IAStorDataMgrSvc.exe
PRC - [2011-11-29 20:04:54 |
000,284,440 | ---- | M] (Intel
Corporation) -- C:\Program Files
(x86)\Intel\Intel(R) Rapid Storage
Technology\IAStorIcon.exe
PRC - [2011-11-08 13:43:14 |
001,500,168 | ---- | M] (G Data
Software AG) -- C:\Program Files
(x86)\Common Files\G
Data\AVKProxy\AVKProxy.exe
PRC - [2011-11-08 13:43:08 |
001,616,392 | ---- | M] (G Data
Software AG) -- C:\Program Files
(x86)\G
Data\InternetSecurity\Firewall\GDFirewallTray.exe
PRC - [2011-10-28 14:36:11 |
000,457,536 | ---- | M] (G Data
Software AG) -- C:\Program Files
(x86)\Common Files\G
Data\GDScan\GDScan.exe
PRC - [2011-10-01 07:30:22 |
000,219,496 | ---- | M] (Microsoft
Corporation) -- C:\Program Files
(x86)\Microsoft Application
Virtualization Client\sftvsa.exe
PRC - [2011-10-01 07:30:18 |
000,508,776 | ---- | M] (Microsoft
Corporation) -- C:\Program Files
(x86)\Microsoft Application
Virtualization Client\sftlist.exe
PRC - [2011-09-20 16:57:56 |
000,060,552 | ---- | M] (Sony
Corporation) -- C:\Program Files
(x86)\Sony\ISB Utility\ISBMgr.exe
PRC - [2011-09-14 22:06:38 |
000,169,624 | ---- | M] (Adobe Systems
Incorporated) -- c:\Program Files
(x86)\Adobe\Elements 10
Organizer\PhotoshopElementsFileAgent.exe
PRC - [2011-06-17 15:43:56 |
000,409,608 | ---- | M] (G Data
Software AG) -- C:\Program Files
(x86)\G
Data\InternetSecurity\AVK\AVKService.exe
PRC - [2011-06-17 15:43:46 |
000,921,608 | ---- | M] (G Data
Software AG) -- C:\Program Files
(x86)\G
Data\InternetSecurity\AVKTray\AVKTray.exe
PRC - [2011-02-23 14:05:04 |
000,105,024 | ---- | M] (ArcSoft,
Inc.) -- C:\Program Files
(x86)\ArcSoft\Magic-i Visual Effects
2\uCamMonitor.exe
[color=#E56717]========== Modules (No
Company Name) ==========[/color]
MOD - [2012-11-17 23:28:19 |
000,487,424 | ---- | M] () --
C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\4a443c775f768ede71bde8e10f50ec0b\IAStorUtil.ni.dll
MOD - [2012-11-17 23:28:19 |
000,014,336 | ---- | M] () --
C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\e88f87e9200afb5ede994c89c92e22b8\IAStorCommon.ni.dll
MOD - [2012-11-17 16:07:34 |
011,833,344 | ---- | M] () --
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\03cfab5534482e8fc313ead6edc19100\System.Web.ni.dll
MOD - [2012-11-17 16:07:27 |
000,771,584 | ---- | M] () --
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll
MOD - [2012-11-17 16:06:46 |
012,436,480 | ---- | M] () --
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d040079bc7148afeca03c5abb6fc3c61\System.Windows.Forms.ni.dll
MOD - [2012-11-17 16:06:37 |
001,591,808 | ---- | M] () --
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\4e80768a2d88c7a333e43cbb7a6c0705\System.Drawing.ni.dll
MOD - [2012-11-17 16:06:21 |
003,347,968 | ---- | M] () --
C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\b311b783e1efaa9527f4c2c9680c44d1\WindowsBase.ni.dll
MOD - [2012-11-17 16:06:15 |
005,452,800 | ---- | M] () --
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\25e672ea505e50ab058258ac72a54f02\System.Xml.ni.dll
MOD - [2012-11-17 16:06:11 |
000,971,264 | ---- | M] () --
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c64ca3678261c8ffcd9e7efd1af6ed54\System.Configuration.ni.dll
MOD - [2012-11-17 16:06:10 |
007,988,736 | ---- | M] () --
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll
MOD - [2012-11-17 16:06:03 |
011,493,376 | ---- | M] () --
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll
MOD - [2011-12-19 15:40:56 |
000,347,136 | ---- | M] () --
C:\Program Files\Sony\VAIO
Care\Iolo\vosges.dll
MOD - [2011-12-07 03:12:36 |
000,032,768 | ---- | M] () --
C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_pl_b77a5c561934e089\System.Runtime.Remoting.resources.dll
MOD - [2010-11-13 03:03:49 |
000,311,296 | ---- | M] () --
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll
[color=#E56717]========== Services
(SafeList) ==========[/color]
SRV:[b]64bit:[/b] - [2012-05-29
00:54:30 | 000,054,464 | ---- | M]
(Sony Corporation) [On_Demand |
Running] -- C:\Program Files\Sony\VAIO
Care\VCService.exe -- (VCService)
SRV:[b]64bit:[/b] - [2012-05-10
17:44:34 | 001,259,104 | ---- | M]
(Sony Corporation) [On_Demand |
Running] -- C:\Program Files\Sony\VAIO
Update Common\VUAgent.exe -- (VUAgent)
SRV:[b]64bit:[/b] - [2012-03-19
08:35:06 | 000,235,520 | ---- | M]
(AMD) [Auto | Running] --
C:\Windows\SysNative\atiesrxx.exe --
(AMD External Events Utility)
SRV:[b]64bit:[/b] - [2012-02-02
22:29:52 | 000,628,448 | ---- | M]
(Intel(R) Corporation) [Auto |
Running] -- C:\Program
Files\Intel\iCLS Client\HeciServer.exe
-- (Intel(R)
SRV:[b]64bit:[/b] - [2012-01-15
23:59:44 | 000,978,056 | ---- | M]
(Sony Corporation) [Auto | Running] --
C:\Program Files\Sony\VAIO Smart
Network\VSNService.exe -- (VSNService)
SRV:[b]64bit:[/b] - [2012-01-11
17:34:44 | 000,135,952 | ---- | M]
(Intel(R) Corporation) [Auto |
Running] -- C:\Program
Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
-- (BTHSSecurityMgr)
SRV:[b]64bit:[/b] - [2012-01-10
13:45:32 | 000,535,688 | ---- | M]
(Sony Corporation) [Auto | Running] --
C:\Program Files\Sony\VAIO Power
Management\SPMService.exe -- (VAIO
Power Management)
SRV:[b]64bit:[/b] - [2012-01-09
05:19:34 | 000,659,968 | ---- | M]
(Intel Corporation) [Auto | Running]
-- C:\Program
Files\Intel\BluetoothHS\BTHSAmpPalService.exe
-- (AMPPALR3)
SRV:[b]64bit:[/b] - [2011-12-21
13:55:14 | 000,382,720 | ---- | M]
(Sony Corporation) [Auto | Running] --
C:\Program Files\Sony\VCM Intelligent
Network Service Manager\VcmINSMgr.exe
-- (VcmINSMgr)
SRV:[b]64bit:[/b] - [2011-12-21
13:15:06 | 000,550,128 | ---- | M]
(Sony Corporation) [Auto | Running] --
C:\Program Files\Sony\VCM Intelligent
Analyzing Manager\VcmIAlzMgr.exe --
(VcmIAlzMgr)
SRV:[b]64bit:[/b] - [2011-12-08
10:44:04 | 000,594,704 | ---- | M]
(IntelŽ Corporation) [Auto | Running]
-- C:\Program
Files\Intel\WiFi\bin\ZeroConfigService.exe
-- (ZeroConfigService)
SRV:[b]64bit:[/b] - [2011-12-08
10:43:56 | 000,273,168 | ---- | M] ()
[On_Demand | Stopped] -- C:\Program
Files\Intel\WiFi\bin\PanDhcpDns.exe --
(MyWiFiDHCPDNS)
SRV:[b]64bit:[/b] - [2011-12-08
10:43:48 | 000,618,256 | ---- | M]
(Intel(R) Corporation) [Auto |
Running] -- C:\Program
Files\Intel\WiFi\bin\EvtEng.exe --
(EvtEng)
SRV:[b]64bit:[/b] - [2011-12-08
10:43:44 | 000,148,752 | ---- | M]
(Intel(R) Corporation) [Auto |
Running] -- C:\Program Files\Common
Files\Intel\WirelessCommon\RegSrvc.exe
-- (RegSrvc)
SRV:[b]64bit:[/b] - [2011-12-01
10:04:56 | 000,289,952 | ---- | M]
(Sony Corporation) [On_Demand |
Running] -- C:\Program Files\Common
Files\Sony Shared\VAIO Entertainment
Platform\SPF\SpfService64.exe --
(SpfService)
SRV:[b]64bit:[/b] - [2011-11-30
18:49:50 | 000,260,768 | ---- | M]
(Sony Corporation) [Auto | Running] --
C:\Program Files\Sony\VAIO
Care\VCPerfService.exe --
(SampleCollector)
SRV:[b]64bit:[/b] - [2011-08-26
18:47:26 | 000,101,600 | ---- | M]
(Sony Corporation) [On_Demand |
Stopped] -- C:\Program Files\Common
Files\Sony
Shared\VcmXml\VcmXmlIfHelper64.exe --
(VcmXmlIfHelper)
SRV:[b]64bit:[/b] - [2010-09-22
18:10:10 | 000,057,184 | ---- | M]
(Microsoft Corporation) [Disabled |
Stopped] -- C:\Program Files\Windows
Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:[b]64bit:[/b] - [2009-07-14
02:41:27 | 001,011,712 | ---- | M]
(Microsoft Corporation) [Auto |
Running] -- C:\Program Files\Windows
Defender\MpSvc.dll -- (WinDefend)
SRV - [2012-12-14 10:30:17 |
003,472,376 | ---- | M] (TeamViewer
GmbH) [Auto | Running] -- C:\Program
Files
(x86)\TeamViewer\Version8\TeamViewer_Service.exe
-- (TeamViewer8)
SRV - [2012-12-13 18:25:21 |
000,250,808 | ---- | M] (Adobe Systems
Incorporated) [On_Demand | Stopped] --
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
-- (AdobeFlashPlayerUpdateSvc)
SRV - [2012-11-29 09:26:17 |
000,115,168 | ---- | M] (Mozilla
Foundation) [On_Demand | Stopped] --
C:\Program Files (x86)\Mozilla
Maintenance
Service\maintenanceservice.exe --
(MozillaMaintenance)
SRV - [2012-09-23 20:43:34 |
000,065,192 | ---- | M] (Adobe Systems
Incorporated) [Auto | Running] --
C:\Program Files (x86)\Common
Files\Adobe\ARM\1.0\armsvc.exe --
(AdobeARMservice)
SRV - [2012-07-13 12:28:36 |
000,160,944 | R--- | M] (Skype
Technologies) [Auto | Stopped] --
C:\Program Files
(x86)\Skype\Updater\Updater.exe --
(SkypeUpdate)
SRV - [2012-03-19 08:38:42 |
000,274,200 | ---- | M] (Intel
Corporation) [On_Demand | Stopped] --
C:\Windows\SysWOW64\IntelCpHeciSvc.exe
-- (cphs)
SRV - [2012-02-23 17:35:16 |
000,065,464 | ---- | M] (Sony
Corporation) [Auto | Running] --
C:\Program Files (x86)\Sony\VAIO
Control Center\VESMgr.exe -- (VAIO
Event Service)
SRV - [2012-02-23 03:12:35 |
000,363,800 | ---- | M] (Intel
Corporation) [Auto | Running] --
C:\Program Files (x86)\Intel\Intel(R)
Management Engine
Components\UNS\UNS.exe -- (UNS)
SRV - [2012-02-23 03:12:01 |
000,277,784 | ---- | M] (Intel
Corporation) [Auto | Running] --
C:\Program Files (x86)\Intel\Intel(R)
Management Engine
Components\LMS\LMS.exe -- (LMS)
SRV - [2012-02-23 03:11:17 |
000,128,280 | ---- | M] () [Auto |
Running] -- C:\Program Files
(x86)\Intel\Intel(R) Management Engine
Components\FWService\IntelMeFWService.exe
-- (Intel(R)
SRV - [2012-02-23 03:08:02 |
000,161,560 | ---- | M] (Intel
Corporation) [Auto | Running] --
C:\Program Files (x86)\Intel\Intel(R)
Management Engine
Components\DAL\Jhi_service.exe --
(jhi_service)
SRV - [2012-02-21 12:41:12 |
000,473,960 | ---- | M] (Sony
Corporation) [Auto | Running] --
c:\Program Files
(x86)\Sony\PlayMemories
Home\PMBDeviceInfoProvider.exe --
(PMBDeviceInfoProvider)
SRV - [2012-01-06 16:44:28 |
000,074,904 | ---- | M] (Sony
Corporation) [On_Demand | Stopped] --
C:\Program Files (x86)\Common
Files\Sony Shared\SOHLib\SOHDs.exe --
(SOHDs)
SRV - [2012-01-06 16:44:26 |
000,138,392 | ---- | M] (Sony
Corporation) [Auto | Running] --
C:\Program Files (x86)\Common
Files\Sony Shared\SOHLib\SOHCImp.exe
-- (SOHCImp)
SRV - [2011-12-29 16:10:08 |
000,960,160 | ---- | M] (Sony
Corporation) [Auto | Running] --
C:\Program Files (x86)\Common
Files\Sony Shared\VAIO Content Folder
Watcher\VCFw.exe -- (VCFw)
SRV - [2011-12-19 19:16:50 |
001,104,208 | ---- | M] (Intel
Corporation) [Auto | Running] --
C:\Program Files
(x86)\Intel\Bluetooth\obexsrv.exe --
(Bluetooth OBEX Service)
SRV - [2011-12-19 19:16:48 |
001,304,912 | ---- | M] (Intel
Corporation) [On_Demand | Running] --
C:\Program Files
(x86)\Intel\Bluetooth\mediasrv.exe --
(Bluetooth Media Service)
SRV - [2011-12-19 19:16:44 |
001,014,096 | ---- | M] (Intel
Corporation) [Auto | Running] --
C:\Program Files
(x86)\Intel\Bluetooth\devmonsrv.exe --
(Bluetooth Device Monitor)
SRV - [2011-11-29 20:04:56 |
000,013,592 | ---- | M] (Intel
Corporation) [Auto | Running] --
C:\Program Files (x86)\Intel\Intel(R)
Rapid Storage
Technology\IAStorDataMgrSvc.exe --
(IAStorDataMgrSvc)
SRV - [2011-11-08 13:43:14 |
001,500,168 | ---- | M] (G Data
Software AG) [Auto | Running] --
C:\Program Files (x86)\Common Files\G
Data\AVKProxy\AVKProxy.exe --
(AVKProxy)
SRV - [2011-10-28 14:36:11 |
000,457,536 | ---- | M] (G Data
Software AG) [On_Demand | Running] --
C:\Program Files (x86)\Common Files\G
Data\GDScan\GDScan.exe -- (GDScan)
SRV - [2011-10-28 02:41:08 |
002,191,808 | ---- | M] (G Data
Software AG) [Auto | Running] --
C:\Program Files (x86)\G
Data\InternetSecurity\AVK\AVKWCtlx64.exe
-- (AVKWCtl)
SRV - [2011-10-01 07:30:22 |
000,219,496 | ---- | M] (Microsoft
Corporation) [On_Demand | Running] --
C:\Program Files (x86)\Microsoft
Application Virtualization
Client\sftvsa.exe -- (sftvsa)
SRV - [2011-10-01 07:30:18 |
000,508,776 | ---- | M] (Microsoft
Corporation) [Auto | Running] --
C:\Program Files (x86)\Microsoft
Application Virtualization
Client\sftlist.exe -- (sftlist)
SRV - [2011-09-14 22:06:38 |
000,169,624 | ---- | M] (Adobe Systems
Incorporated) [Auto | Running] --
c:\Program Files (x86)\Adobe\Elements
10
Organizer\PhotoshopElementsFileAgent.exe
-- (AdobeActiveFileMonitor10.0)
SRV - [2011-08-10 13:21:10 |
001,556,816 | ---- | M] (G Data
Software AG) [On_Demand | Running] --
C:\Program Files (x86)\G
Data\InternetSecurity\Firewall\GDFwSvcx64.exe
-- (GDFwSvc)
SRV - [2011-06-17 15:43:56 |
000,409,608 | ---- | M] (G Data
Software AG) [Auto | Running] --
C:\Program Files (x86)\G
Data\InternetSecurity\AVK\AVKService.exe
-- (AVKService)
SRV - [2011-02-23 14:05:04 |
000,105,024 | ---- | M] (ArcSoft,
Inc.) [Auto | Running] -- C:\Program
Files (x86)\ArcSoft\Magic-i Visual
Effects 2\uCamMonitor.exe --
(uCamMonitor)
SRV - [2010-03-18 22:16:28 |
000,130,384 | ---- | M] (Microsoft
Corporation) [Auto | Stopped] --
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
-- (clr_optimization_v4.0.30319_32)
SRV - [2010-03-18 11:19:26 |
000,113,152 | ---- | M] (ArcSoft Inc.)
[On_Demand | Stopped] -- C:\Program
Files (x86)\Common
Files\ArcSoft\Connection
Service\Bin\ACService.exe --
(ACDaemon)
SRV - [2009-06-10 22:23:09 |
000,066,384 | ---- | M] (Microsoft
Corporation) [Disabled | Stopped] --
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
-- (clr_optimization_v2.0.50727_32)
[color=#E56717]========== Driver
Services (SafeList) ==========[/color]
DRV:[b]64bit:[/b] - [2012-12-28
17:31:52 | 000,106,488 | ---- | M] (G
Data Software) [Kernel | System |
Running] --
C:\Windows\SysNative\drivers\GRD.sys
-- (GRD)
DRV:[b]64bit:[/b] - [2012-11-28
18:49:00 | 000,035,112 | ---- | M]
(TeamViewer GmbH) [Kernel | On_Demand
| Running] --
C:\Windows\SysNative\drivers\teamviewervpn.sys
-- (teamviewervpn)
DRV:[b]64bit:[/b] - [2012-10-27
17:40:52 | 000,059,256 | ---- | M] (G
Data Software AG) [Kernel | On_Demand
| Running] --
C:\Windows\SysNative\drivers\PktIcpt.sys
-- (GDPkIcpt)
DRV:[b]64bit:[/b] - [2012-10-27
17:39:38 | 000,053,112 | ---- | M] (G
Data Software AG) [Kernel | System |
Running] --
C:\Windows\SysNative\drivers\HookCentre.sys
-- (HookCentre)
DRV:[b]64bit:[/b] - [2012-10-27
17:39:24 | 000,111,992 | ---- | M] (G
Data Software AG) [Kernel | System |
Running] --
C:\Windows\SysNative\drivers\MiniIcpt.sys
-- (GDMnIcpt)
DRV:[b]64bit:[/b] - [2012-10-27
17:39:24 | 000,065,912 | ---- | M] (G
Data Software AG) [Kernel | System |
Running] --
C:\Windows\SysNative\drivers\gdwfpcd64.sys
-- (gdwfpcd)
DRV:[b]64bit:[/b] - [2012-10-27
17:39:24 | 000,050,552 | ---- | M] (G
Data Software AG) [Kernel | Boot |
Running] --
C:\Windows\SysNative\drivers\GDBehave.sys
-- (GDBehave)
DRV:[b]64bit:[/b] - [2012-08-26
17:14:22 | 000,031,448 | ---- | M] (G
Data Software AG) [Kernel | On_Demand
| Stopped] --
C:\Windows\SysNative\drivers\GdNetMon64.sys
-- (GdNetMon)
DRV:[b]64bit:[/b] - [2012-04-12
18:41:36 | 000,568,600 | ---- | M]
(Intel Corporation) [Kernel | Boot |
Running] --
C:\Windows\SysNative\drivers\iaStor.sys
-- (iaStor)
DRV:[b]64bit:[/b] - [2012-03-19
09:10:14 | 000,031,872 | ---- | M]
(Advanced Micro Devices, Inc.) [Kernel
| Boot | Running] --
C:\Windows\SysNative\drivers\amdkmpfd.sys
-- (amdkmpfd)
DRV:[b]64bit:[/b] - [2012-03-19
08:53:55 | 014,652,768 | ---- | M]
(Intel Corporation) [Kernel |
On_Demand | Running] --
C:\Windows\SysNative\drivers\igdpmd64.sys
-- (intelkmd)
DRV:[b]64bit:[/b] - [2012-03-19
08:35:30 | 010,729,984 | ---- | M]
(Advanced Micro Devices, Inc.) [Kernel
| On_Demand | Running] --
C:\Windows\SysNative\drivers\atikmdag.sys
-- (amdkmdag)
DRV:[b]64bit:[/b] - [2012-03-19
08:35:30 | 000,328,192 | ---- | M]
(Advanced Micro Devices, Inc.) [Kernel
| On_Demand | Running] --
C:\Windows\SysNative\drivers\atikmpag.sys
-- (amdkmdap)
DRV:[b]64bit:[/b] - [2012-03-19
08:31:16 | 000,331,264 | ---- | M]
(Intel(R) Corporation) [Kernel |
On_Demand | Running] --
C:\Windows\SysNative\drivers\IntcDAud.sys
-- (IntcDAud)
DRV:[b]64bit:[/b] - [2012-03-01
07:46:16 | 000,023,408 | ---- | M]
(Microsoft Corporation) [Recognizer |
Boot | Unknown] --
C:\Windows\SysNative\drivers\fs_rec.sys
-- (Fs_Rec)
DRV:[b]64bit:[/b] - [2012-02-27
10:22:34 | 000,676,968 | ---- | M]
(Realtek
) [Kernel | On_Demand |
Running] --
C:\Windows\SysNative\drivers\Rt64win7.sys
-- (RTL8167)
DRV:[b]64bit:[/b] - [2012-02-24
04:05:30 | 000,421,648 | ---- | M]
(Synaptics Incorporated) [Kernel |
On_Demand | Running] --
C:\Windows\SysNative\drivers\SynTP.sys
-- (SynTP)
DRV:[b]64bit:[/b] - [2012-02-24
03:32:03 | 000,102,912 | ---- | M]
(REDC) [Kernel | Auto | Running] --
C:\Windows\SysNative\drivers\rimssne64.sys
-- (rimssne)
DRV:[b]64bit:[/b] - [2012-02-23
09:16:15 | 000,787,736 | ---- | M]
(Intel Corporation) [Kernel |
On_Demand | Running] --
C:\Windows\SysNative\drivers\iusb3xhc.sys
-- (iusb3xhc)
DRV:[b]64bit:[/b] - [2012-02-23
09:16:10 | 000,356,120 | ---- | M]
(Intel Corporation) [Kernel |
On_Demand | Running] --
C:\Windows\SysNative\drivers\iusb3hub.sys
-- (iusb3hub)
DRV:[b]64bit:[/b] - [2012-02-23
09:16:07 | 000,016,152 | ---- | M]
(Intel Corporation) [Kernel | Boot |
Running] --
C:\Windows\SysNative\drivers\iusb3hcs.sys
-- (iusb3hcs)
DRV:[b]64bit:[/b] - [2012-02-23
08:41:44 | 000,104,448 | ---- | M]
(REDC) [Kernel | Auto | Running] --
C:\Windows\SysNative\drivers\risdsnxc64.sys
-- (risdsnxc)
DRV:[b]64bit:[/b] - [2012-02-23
03:09:23 | 000,060,184 | ---- | M]
(Intel Corporation) [Kernel |
On_Demand | Running] --
C:\Windows\SysNative\drivers\HECIx64.sys
-- (MEIx64)
DRV:[b]64bit:[/b] - [2012-01-26
18:37:24 | 000,034,200 | ---- | M]
(Intel Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\intelaud.sys
-- (intaud_WaveExtensible)
DRV:[b]64bit:[/b] - [2012-01-26
18:37:24 | 000,025,496 | ---- | M]
(Intel Corporation) [Kernel |
On_Demand | Running] --
C:\Windows\SysNative\drivers\iwdbus.sys
-- (iwdbus)
DRV:[b]64bit:[/b] - [2012-01-16
10:01:14 | 000,014,336 | ---- | M]
(Sony Corporation) [Kernel | On_Demand
| Running] --
C:\Windows\SysNative\drivers\SFEP.sys
-- (SFEP)
DRV:[b]64bit:[/b] - [2012-01-09
05:13:12 | 000,195,584 | ---- | M]
(Windows (R) Win 7 DDK provider)
[Kernel | On_Demand | Stopped] --
C:\Windows\SysNative\drivers\AmpPal.sys
-- (AMPPALP)
DRV:[b]64bit:[/b] - [2012-01-09
05:13:12 | 000,195,584 | ---- | M]
(Windows (R) Win 7 DDK provider)
[Kernel | On_Demand | Running] --
C:\Windows\SysNative\drivers\AmpPal.sys
-- (AMPPAL)
DRV:[b]64bit:[/b] - [2012-01-09
01:44:44 | 011,416,576 | ---- | M]
(Intel Corporation) [Kernel |
On_Demand | Running] --
C:\Windows\SysNative\drivers\NETwNs64.sys
-- (NETwNs64)
DRV:[b]64bit:[/b] - [2011-12-14
14:26:56 | 000,060,416 | ---- | M]
(Intel Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\iBtFltCoex.sys
-- (ibtfltcoex)
DRV:[b]64bit:[/b] - [2011-12-13
11:26:20 | 000,747,008 | ---- | M]
(Intel Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\btmhsf.sys
-- (btmhsf)
DRV:[b]64bit:[/b] - [2011-12-13
11:26:18 | 000,094,720 | ---- | M]
(Intel Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\btmaux.sys
-- (btmaux)
DRV:[b]64bit:[/b] - [2011-10-01
07:30:22 | 000,022,376 | ---- | M]
(Microsoft Corporation) [Kernel |
On_Demand | Running] --
C:\Windows\SysNative\drivers\Sftvollh.sys
-- (Sftvol)
DRV:[b]64bit:[/b] - [2011-10-01
07:30:18 | 000,268,648 | ---- | M]
(Microsoft Corporation) [Kernel |
On_Demand | Running] --
C:\Windows\SysNative\drivers\Sftplaylh.sys
-- (Sftplay)
DRV:[b]64bit:[/b] - [2011-10-01
07:30:18 | 000,025,960 | ---- | M]
(Microsoft Corporation) [File_System |
On_Demand | Running] --
C:\Windows\SysNative\drivers\Sftredirlh.sys
-- (Sftredir)
DRV:[b]64bit:[/b] - [2011-10-01
07:30:10 | 000,764,264 | ---- | M]
(Microsoft Corporation) [Kernel |
On_Demand | Running] --
C:\Windows\SysNative\drivers\Sftfslh.sys
-- (Sftfs)
DRV:[b]64bit:[/b] - [2011-03-11
07:41:12 | 000,107,904 | ---- | M]
(Advanced Micro Devices) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\amdsata.sys
-- (amdsata)
DRV:[b]64bit:[/b] - [2011-03-11
07:41:12 | 000,027,008 | ---- | M]
(Advanced Micro Devices) [Kernel |
Boot | Running] --
C:\Windows\SysNative\drivers\amdxata.sys
-- (amdxata)
DRV:[b]64bit:[/b] - [2010-11-21
04:24:33 | 000,059,392 | ---- | M]
(Microsoft Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\TsUsbFlt.sys
-- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2010-11-21
04:23:47 | 000,109,056 | ---- | M]
(Microsoft Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\sdbus.sys
-- (sdbus)
DRV:[b]64bit:[/b] - [2010-11-21
04:23:47 | 000,078,720 | ---- | M]
(Hewlett-Packard Company) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\HpSAMD.sys
-- (HpSAMD)
DRV:[b]64bit:[/b] - [2010-11-21
04:23:47 | 000,031,232 | ---- | M]
(Microsoft Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\TsUsbGD.sys
-- (TsUsbGD)
DRV:[b]64bit:[/b] - [2010-03-19
03:00:00 | 000,055,856 | ---- | M]
(Sonic Solutions) [Kernel | Boot |
Running] --
C:\Windows\SysNative\drivers\PxHlpa64.sys
-- (PxHlpa64)
DRV:[b]64bit:[/b] - [2009-07-14
02:52:20 | 000,194,128 | ---- | M]
(AMD Technologies Inc.) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\amdsbs.sys
-- (amdsbs)
DRV:[b]64bit:[/b] - [2009-07-14
02:48:04 | 000,065,600 | ---- | M]
(LSI Corporation) [Kernel | On_Demand
| Stopped] --
C:\Windows\SysNative\drivers\lsi_sas2.sys
-- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009-07-14
02:45:55 | 000,024,656 | ---- | M]
(Promise Technology) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\stexstor.sys
-- (stexstor)
DRV:[b]64bit:[/b] - [2009-06-20
03:09:57 | 001,394,688 | ---- | M]
(Atheros Communications, Inc.) [Kernel
| On_Demand | Stopped] --
C:\Windows\SysNative\drivers\athrx.sys
-- (athr)
DRV:[b]64bit:[/b] - [2009-06-10
21:35:02 | 000,281,088 | ---- | M]
(Intel Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\e1y60x64.sys
-- (e1yexpress)
DRV:[b]64bit:[/b] - [2009-06-10
21:34:33 | 003,286,016 | ---- | M]
(Broadcom Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\evbda.sys
-- (ebdrv)
DRV:[b]64bit:[/b] - [2009-06-10
21:34:28 | 000,468,480 | ---- | M]
(Broadcom Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\bxvbda.sys
-- (b06bdrv)
DRV:[b]64bit:[/b] - [2009-06-10
21:34:23 | 000,270,848 | ---- | M]
(Broadcom Corporation) [Kernel |
On_Demand | Stopped] --
C:\Windows\SysNative\drivers\b57nd60a.sys
-- (b57nd60a)
DRV:[b]64bit:[/b] - [2009-06-10
21:31:59 | 000,031,232 | ---- | M]
(Hauppauge Computer Works, Inc.)
[Kernel | On_Demand | Stopped] --
C:\Windows\SysNative\drivers\hcw85cir.sys
-- (hcw85cir)
DRV:[b]64bit:[/b] - [2009-05-26
14:32:04 | 000,019,968 | ---- | M]
(ArcSoft, Inc.) [Kernel | On_Demand |
Running] --
C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys
-- (ArcSoftKsUFilter)
DRV - [2009-07-14 02:19:10 |
000,019,008 | ---- | M] (Microsoft
Corporation) [File_System | On_Demand
| Stopped] --
C:\Windows\SysWOW64\drivers\wimmount.sys
-- (WIMMount)
[color=#E56717]========== Standard
Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet
Explorer ==========[/color]
IE:[b]64bit:[/b] -
HKLM\..\SearchScopes,DefaultScope =
IE:[b]64bit:[/b] -
HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:
"URL" =
http://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet
Explorer\Main,Local Page =
C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet
Explorer\Main,Start Page =
http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope
=
IE -
HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}:
"URL" =
http://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://vaioportal.sony.eu
IE - HKCU\SOFTWARE\Microsoft\Internet
Explorer\Main,Default_Secondary_Page_URL
= http://sony.msn.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet
Explorer\Main,Start Page =
http://www.google.pl/
IE - HKCU\..\SearchScopes,DefaultScope
=
IE -
HKCU\..\SearchScopes\{E70A9C30-4272-4289-A7FB-EB4AF8AD70F2}:
"URL" =
http://search.softonic.com/INF00046/tb_v1?q={searchTerms}&SearchSource=4&cc=&r=755
IE -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings: "ProxyEnable" = 0
IE -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings: "ProxyOverride" =
<local>
[color=#E56717]========== FireFox
==========[/color]
FF -
prefs.js..browser.startup.homepage:
"www.google.pl"
FF -
prefs.js..extensions.enabledAddons:
%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - user.js - File not found
FF:[b]64bit:[/b] -
HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:
C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll
File not found
FF:[b]64bit:[/b] -
HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2:
C:\Windows\system32\npDeployJava1.dll
File not found
FF:[b]64bit:[/b] -
HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2:
C:\Program
Files\Java\jre7\bin\plugin2\npjp2.dll
(Oracle Corporation)
FF:[b]64bit:[/b] -
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE:
disabled File not found
FF:[b]64bit:[/b] -
HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect:
C:\Program Files (x86)\Common
Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
(Adobe Systems)
FF -
HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
()
FF -
HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel
WebAPI ipt;version=2.0.59: C:\Program
Files (x86)\Intel\Intel(R) Management
Engine
Components\IPT\npIntelWebAPIIPT.dll
(Intel Corporation)
FF -
HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel
WebAPI updater: C:\Program Files
(x86)\Intel\Intel(R) Management Engine
Components\IPT\npIntelWebAPIUpdater.dll
(Intel Corporation)
FF -
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE:
disabled File not found
FF -
HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0:
C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
(Microsoft Corporation)
FF -
HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922:
C:\Program Files (x86)\Windows
Live\Photo Gallery\NPWLPG.dll
(Microsoft Corporation)
FF -
HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513:
C:\Program Files (x86)\Windows
Live\Photo Gallery\NPWLPG.dll
(Microsoft Corporation)
FF -
HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00:
C:\Program Files
(x86)\Sony\PLAYSTATION Network
Downloader\nppsndl.dll (Sony Computer
Entertainment Inc.)
FF -
HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media
Go,version=1.0: C:\Program Files
(x86)\Sony\Media Go\npmediago.dll
(Sony Network Entertainment
International LLC)
FF -
HKLM\Software\MozillaPlugins\@tools.google.com/Google
Update;version=3: C:\Program Files
(x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
(Google Inc.)
FF -
HKLM\Software\MozillaPlugins\@tools.google.com/Google
Update;version=9: C:\Program Files
(x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
(Google Inc.)
FF -
HKLM\Software\MozillaPlugins\Adobe
Reader: C:\Program Files
(x86)\Adobe\Reader
11.0\Reader\AIR\nppdf32.dll (Adobe
Systems Inc.)
FF -
HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect:
C:\Program Files (x86)\Common
Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
(Adobe Systems)
FF -
HKEY_LOCAL_MACHINE\software\mozilla\Mozilla
Firefox 17.0.1\extensions\\Components:
C:\Program Files (x86)\Mozilla
Firefox\components [2013-01-03
21:50:53 | 000,000,000 | ---D | M]
FF -
HKEY_LOCAL_MACHINE\software\mozilla\Mozilla
Firefox 17.0.1\extensions\\Plugins:
C:\Program Files (x86)\Mozilla
Firefox\plugins
[2013-01-03 21:51:13 | 000,000,000 |
---D | M] (No name found) --
C:\Users\ALBERT\AppData\Roaming\mozilla\Extensions
[2013-01-03 23:40:56 | 000,000,000 |
---D | M] (No name found) --
C:\Users\ALBERT\AppData\Roaming\mozilla\Firefox\Profiles\9upoigsz.default\Extensions
[2013-01-03 21:50:53 | 000,000,000 |
---D | M] (No name found) --
C:\Program Files (x86)\Mozilla
Firefox\extensions
[2012-11-29 09:26:57 | 000,262,112 |
---- | M] (Mozilla Foundation) --
C:\Program Files (x86)\mozilla
firefox\components\browsercomps.dll
[2012-11-29 11:00:09 | 000,002,767 |
---- | M] () -- C:\Program Files
(x86)\mozilla
firefox\searchplugins\allegro-pl.xml
[2012-11-29 11:00:09 | 000,001,406 |
---- | M] () -- C:\Program Files
(x86)\mozilla
firefox\searchplugins\fbc-pl.xml
[2012-11-29 11:00:09 | 000,000,917 |
---- | M] () -- C:\Program Files
(x86)\mozilla
firefox\searchplugins\merlin-pl.xml
[2012-11-29 11:00:09 | 000,000,858 |
---- | M] () -- C:\Program Files
(x86)\mozilla
firefox\searchplugins\pwn-pl.xml
[2012-11-29 11:00:09 | 000,001,183 |
---- | M] () -- C:\Program Files
(x86)\mozilla
firefox\searchplugins\wikipedia-pl.xml
[2012-11-29 11:00:09 | 000,001,683 |
---- | M] () -- C:\Program Files
(x86)\mozilla
firefox\searchplugins\wp-pl.xml
[color=#E56717]========== Chrome
==========[/color]
CHR - homepage:
CHR - default_search_provider: Google
(Enabled)
CHR - default_search_provider:
search_url =
{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider:
suggest_url =
{google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage:
CHR - plugin: Shockwave Flash
(Enabled) = C:\Program Files
(x86)\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop
Viewer (Enabled) =
internal-remoting-viewer
CHR - plugin: Native Client (Enabled)
= C:\Program Files
(x86)\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer
(Enabled) = C:\Program Files
(x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Microsoft Office 2010
(Enabled) =
C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: AdobeAAMDetect (Enabled)
= C:\Program Files (x86)\Common
Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
CHR - plugin: Google Update (Enabled)
= C:\Program Files
(x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Intel\u00AE Identity
Protection Technology (Enabled) =
C:\Program Files (x86)\Intel\Intel(R)
Management Engine
Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel\u00AE Identity
Protection Technology (Enabled) =
C:\Program Files (x86)\Intel\Intel(R)
Management Engine
Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Media Go Detector
(Enabled) = C:\Program Files
(x86)\Sony\Media Go\npmediago.dll
CHR - plugin: PlayStation(R)Network
Downloader Check Plug-in (Enabled) =
C:\Program Files
(x86)\Sony\PLAYSTATION Network
Downloader\nppsndl.dll
CHR - plugin: Windows Live\u0099 Photo
Gallery (Enabled) = C:\Program Files
(x86)\Windows Live\Photo
Gallery\NPWLPG.dll
CHR - plugin: Shockwave Flash
(Enabled) =
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
CHR - Extension: Dysk Google =
C:\Users\ALBERT\AppData\Local\Google\Chrome\User
Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: Dysk Google =
C:\Users\ALBERT\AppData\Local\Google\Chrome\User
Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube =
C:\Users\ALBERT\AppData\Local\Google\Chrome\User
Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Szukaj w Google =
C:\Users\ALBERT\AppData\Local\Google\Chrome\User
Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail =
C:\Users\ALBERT\AppData\Local\Google\Chrome\User
Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009-06-10 22:00:26 |
000,000,824 | ---- | M]) -
C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (G Data
WebFilter) -
{0124123D-61B4-456f-AF86-78C53A0790C5}
- C:\Program Files (x86)\G
Data\InternetSecurity\WebFilter\AvkWebIEx64.dll
(G Data Software AG)
O2:[b]64bit:[/b] - BHO: (Java(tm)
Plug-In SSV Helper) -
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
- C:\Program
Files\Java\jre7\bin\ssv.dll (Oracle
Corporation)
O2:[b]64bit:[/b] - BHO: (Java(tm)
Plug-In 2 SSV Helper) -
{DBC80044-A445-435b-BC74-9C25C1C588A9}
- C:\Program
Files\Java\jre7\bin\jp2ssv.dll (Oracle
Corporation)
O2 - BHO: (G Data WebFilter) -
{0124123D-61B4-456f-AF86-78C53A0790C5}
- C:\Program Files (x86)\G
Data\InternetSecurity\WebFilter\AvkWebIE.dll
(G Data Software AG)
O2 - BHO: (G Data BankGuard) -
{BA3295CF-17ED-4F49-9E95-D999A0ADBFDC}
- C:\Program Files (x86)\Common
Files\G Data\AVKProxy\BanksafeBHO.dll
(G Data Software AG)
O2 - BHO: (no name) -
{DBC80044-A445-435b-BC74-9C25C1C588A9}
- No CLSID value found.
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (G
Data WebFilter) -
{0124123D-61B4-456f-AF86-78C53A0790C5}
- C:\Program Files (x86)\G
Data\InternetSecurity\WebFilter\AvkWebIEx64.dll
(G Data Software AG)
O3 - HKLM\..\Toolbar: (G Data
WebFilter) -
{0124123D-61B4-456f-AF86-78C53A0790C5}
- C:\Program Files (x86)\G
Data\InternetSecurity\WebFilter\AvkWebIE.dll
(G Data Software AG)
O4:[b]64bit:[/b] - HKLM..\Run:
[AdobeAAMUpdater-1.0] C:\Program Files
(x86)\Common
Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
(Adobe Systems Incorporated)
O4:[b]64bit:[/b] - HKLM..\Run:
[BTMTrayAgent] C:\Program Files
(x86)\Intel\Bluetooth\btmshell.dll
(Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run:
[HotKeysCmds]
C:\Windows\SysNative\hkcmd.exe (Intel
Corporation)
O4:[b]64bit:[/b] - HKLM..\Run:
[IgfxTray]
C:\Windows\SysNative\igfxtray.exe
(Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run:
[Persistence]
C:\Windows\SysNative\igfxpers.exe
(Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run:
[RtHDVBg] C:\Program
Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run:
[RtHDVBg_Dolby] C:\Program
Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor)
O4 - HKLM..\Run: [Dolby Home Theater
v4] C:\Program Files (x86)\Dolby Home
Theater v4\pcee4.exe (Dolby
Laboratories Inc.)
O4 - HKLM..\Run: [G Data AntiVirus
Tray Application] C:\Program Files
(x86)\G
Data\InternetSecurity\AVKTray\AVKTray.exe
(G Data Software AG)
O4 - HKLM..\Run: [GDFirewallTray]
C:\Program Files (x86)\G
Data\InternetSecurity\Firewall\GDFirewallTray.exe
(G Data Software AG)
O4 - HKLM..\Run: [IAStorIcon]
C:\Program Files (x86)\Intel\Intel(R)
Rapid Storage
Technology\IAStorIcon.exe (Intel
Corporation)
O4 - HKLM..\Run: [ISBMgr.exe]
C:\Program Files (x86)\Sony\ISB
Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher]
c:\Program Files
(x86)\Sony\PlayMemories
Home\PMBVolumeWatcher.exe (Sony
Corporation)
O4 - HKLM..\Run: [StartCCC] c:\Program
Files (x86)\ATI
Technologies\ATI.ACE\Core-Static\CLIStart.exe
(Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [USB3MON] C:\Program
Files (x86)\Intel\Intel(R) USB 3.0
eXtensible Host Controller
Driver\Application\iusb3mon.exe (Intel
Corporation)
O6 -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoActiveDesktop = 1
O6 -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoActiveDesktopChanges = 1
O6 -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
ConsentPromptBehaviorAdmin = 5
O6 -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
ConsentPromptBehaviorUser = 3
O9 - Extra Button: @C:\Program Files
(x86)\Evernote\Evernote\Resource.dll,-101
-
{A95fe080-8f5d-11d2-a20b-00aa003c157a}
- C:\Program Files
(x86)\Evernote\Evernote\EvernoteIE.dll
(Evernote Corp., 333 W Evelyn Ave.
Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem :
@C:\Program Files
(x86)\Evernote\Evernote\Resource.dll,-101
-
{A95fe080-8f5d-11d2-a20b-00aa003c157a}
- C:\Program Files
(x86)\Evernote\Evernote\EvernoteIE.dll
(Evernote Corp., 333 W Evelyn Ave.
Mountain View, CA 94041)
O13[b]64bit:[/b] - gopher Prefix:
missing
O13 - gopher Prefix: missing
O17 -
HKLM\System\CCS\Services\Tcpip\Parameters:
DhcpNameServer = 192.168.1.1
O17 -
HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6D75773C-6BFC-4C66-8BCE-A05D0971602B}:
DhcpNameServer = 192.168.1.1
O17 -
HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8265B95C-6AD1-474F-B539-C911652CC470}:
DhcpNameServer = 192.168.1.1
O18:[b]64bit:[/b] -
Protocol\Handler\livecall - No CLSID
value found
O18:[b]64bit:[/b] -
Protocol\Handler\msnim - No CLSID
value found
O18:[b]64bit:[/b] -
Protocol\Handler\skype4com - No CLSID
value found
O18:[b]64bit:[/b] -
Protocol\Handler\wlmailhtml - No CLSID
value found
O18:[b]64bit:[/b] -
Protocol\Handler\wlpg - No CLSID value
found
O18 - Protocol\Handler\skype4com
{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D}
- C:\Program Files (x86)\Common
Files\Skype\Skype4COM.dll (Skype
Technologies)
O20:[b]64bit:[/b] - HKLM Winlogon:
Shell - (explorer.exe) -
C:\Windows\explorer.exe (Microsoft
Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon:
UserInit -
(C:\Windows\system32\userinit.exe) -
C:\Windows\SysNative\userinit.exe
(Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon:
UserInit - (c:\program files (x86)\g
data\internetsecurity\avkkid\avkcks.exe)
- c:\Program Files (x86)\G
Data\InternetSecurity\AVKKid\AvkCKS.exe
()
O20 - HKLM Winlogon: Shell -
(explorer.exe) -
C:\Windows\SysWow64\explorer.exe
(Microsoft Corporation)
O20 - HKLM Winlogon: UserInit -
(userinit.exe) -
C:\Windows\SysWow64\userinit.exe
(Microsoft Corporation)
O20:[b]64bit:[/b] -
Winlogon\Notify\igfxcui: DllName -
(igfxdev.dll) -
C:\Windows\SysNative\igfxdev.dll
(Intel Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck -
{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- No CLSID value found.
O21 - SSODL: WebCheck -
{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck
autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile
[open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile
[open] -- "%1" %*
O35 - HKLM\..comfile [open] --
"%1" %*
O35 - HKLM\..exefile [open] --
"%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ =
comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ =
exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] --
"%1" %*
O37 - HKLM\...exe [@ = exefile] --
"%1" %*
O38 - SubSystems\\Windows:
(ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows:
(ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows:
(ServerDll=sxssrv,4)
[color=#E56717]==========
Files/Folders - Created Within 30 Days
==========[/color]
[2013-01-08 08:17:54 | 001,081,320 |
---- | C] (Oracle Corporation) --
C:\Windows\SysNative\npDeployJava1.dll
[2013-01-08 08:17:54 | 000,308,200 |
---- | C] (Oracle Corporation) --
C:\Windows\SysNative\javaws.exe
[2013-01-08 08:17:46 | 000,188,392 |
---- | C] (Oracle Corporation) --
C:\Windows\SysNative\javaw.exe
[2013-01-08 08:17:46 | 000,188,392 |
---- | C] (Oracle Corporation) --
C:\Windows\SysNative\java.exe
[2013-01-08 08:17:46 | 000,108,008 |
---- | C] (Oracle Corporation) --
C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013-01-08 08:17:12 | 000,000,000 |
---D | C] -- C:\Program Files\Java
[2013-01-08 00:34:36 | 000,000,000 |
RH-D | C] --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\VAIO Care
[2013-01-08 00:27:10 | 000,035,112 |
---- | C] (TeamViewer GmbH) --
C:\Windows\SysNative\drivers\teamviewervpn.sys
[2013-01-08 00:27:06 | 000,000,000 |
---D | C] -- C:\Program Files
(x86)\TeamViewer
[2013-01-08 00:23:19 | 000,000,000 |
---D | C] --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\Google Chrome
[2013-01-07 23:58:24 | 000,000,000 |
---D | C] --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\CCleaner
[2013-01-07 23:58:21 | 000,000,000 |
---D | C] -- C:\Program Files\CCleaner
[2013-01-07 23:50:03 | 000,000,000 |
---D | C] -- C:\DOWNLOAD
[2013-01-07 23:09:20 | 000,000,000 |
---D | C] --
C:\Users\ALBERT\AppData\Local\GHISLER
[2013-01-07 23:08:04 | 000,000,000 |
---D | C] --
C:\Users\ALBERT\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Total Commander
[2013-01-07 23:08:02 | 000,000,000 |
---D | C] -- C:\totalcmd
[2013-01-07 23:08:02 | 000,000,000 |
---D | C] --
C:\Users\ALBERT\AppData\Roaming\GHISLER
[2013-01-03 21:52:41 | 000,000,000 |
---D | C] --
C:\Users\ALBERT\AppData\Local\Macromedia
[2013-01-03 21:51:05 | 000,000,000 |
---D | C] --
C:\Users\ALBERT\AppData\Roaming\Mozilla
[2013-01-03 21:51:05 | 000,000,000 |
---D | C] --
C:\Users\ALBERT\AppData\Local\Mozilla
[2013-01-03 21:50:56 | 000,000,000 |
---D | C] -- C:\Program Files
(x86)\Mozilla Maintenance Service
[2013-01-03 21:50:56 | 000,000,000 |
---D | C] -- C:\ProgramData\Mozilla
[2012-12-28 17:31:52 | 000,106,488 |
---- | C] (G Data Software) --
C:\Windows\SysNative\drivers\GRD.sys
[2012-12-21 21:53:16 | 000,046,080 |
---- | C] (Adobe Systems) --
C:\Windows\SysNative\atmlib.dll
[2012-12-21 21:53:16 | 000,034,304 |
---- | C] (Adobe Systems) --
C:\Windows\SysWow64\atmlib.dll
[2012-12-21 21:53:15 | 000,367,616 |
---- | C] (Adobe Systems Incorporated)
-- C:\Windows\SysNative\atmfd.dll
[2012-12-21 21:53:14 | 000,295,424 |
---- | C] (Adobe Systems Incorporated)
-- C:\Windows\SysWow64\atmfd.dll
[2012-12-16 09:44:12 | 000,019,000 |
---- | C] (PerformerSoft LLC) --
C:\Windows\SysNative\roboot64.exe
[2012-12-16 09:43:51 | 000,000,000 |
---D | C] --
C:\Windows\SysWow64\searchplugins
[2012-12-16 09:43:51 | 000,000,000 |
---D | C] --
C:\Windows\SysWow64\Extensions
[2012-12-16 09:41:35 | 000,000,000 |
---D | C] -- C:\Program Files
(x86)\Mozilla Firefox
[2012-12-13 18:55:05 | 000,096,768 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\mshtmled.dll
[2012-12-13 18:55:05 | 000,073,216 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\mshtmled.dll
[2012-12-13 18:55:04 | 000,176,640 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\ieui.dll
[2012-12-13 18:55:03 | 000,248,320 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\ieui.dll
[2012-12-13 18:55:03 | 000,237,056 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\url.dll
[2012-12-13 18:55:03 | 000,231,936 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\url.dll
[2012-12-13 18:55:03 | 000,173,056 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\ieUnatt.exe
[2012-12-13 18:55:03 | 000,142,848 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\ieUnatt.exe
[2012-12-13 18:55:02 | 002,312,704 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\jscript9.dll
[2012-12-13 18:55:02 | 001,494,528 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\inetcpl.cpl
[2012-12-13 18:55:02 | 001,427,968 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\inetcpl.cpl
[2012-12-13 18:55:02 | 000,729,088 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\msfeeds.dll
[2012-12-13 18:55:00 | 000,816,640 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\jscript.dll
[2012-12-13 18:55:00 | 000,717,824 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\jscript.dll
[2012-12-13 18:55:00 | 000,599,040 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\vbscript.dll
[2012-12-13 18:01:00 | 000,424,960 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\KernelBase.dll
[2012-12-13 18:00:59 | 001,161,216 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\kernel32.dll
[2012-12-13 18:00:59 | 000,362,496 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\wow64win.dll
[2012-12-13 18:00:59 | 000,338,432 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\conhost.exe
[2012-12-13 18:00:59 | 000,243,200 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\wow64.dll
[2012-12-13 18:00:59 | 000,215,040 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\winsrv.dll
[2012-12-13 18:00:59 | 000,025,600 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\setup16.exe
[2012-12-13 18:00:59 | 000,016,384 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\ntvdm64.dll
[2012-12-13 18:00:59 | 000,014,336 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\ntvdm64.dll
[2012-12-13 18:00:59 | 000,013,312 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\wow64cpu.dll
[2012-12-13 18:00:59 | 000,007,680 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\instnm.exe
[2012-12-13 18:00:59 | 000,006,144 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012-12-13 18:00:59 | 000,005,120 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012-12-13 18:00:59 | 000,005,120 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012-12-13 18:00:59 | 000,005,120 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\wow32.dll
[2012-12-13 18:00:59 | 000,004,608 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012-12-13 18:00:59 | 000,004,608 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012-12-13 18:00:59 | 000,004,608 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012-12-13 18:00:59 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012-12-13 18:00:59 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012-12-13 18:00:59 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012-12-13 18:00:59 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012-12-13 18:00:59 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012-12-13 18:00:59 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012-12-13 18:00:59 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012-12-13 18:00:58 | 000,006,144 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012-12-13 18:00:58 | 000,004,608 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012-12-13 18:00:58 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012-12-13 18:00:58 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012-12-13 18:00:58 | 000,004,096 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,584 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012-12-13 18:00:58 | 000,003,072 |
-H-- | C] (Microsoft Corporation) --
C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012-12-13 18:00:58 | 000,002,048 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\user.exe
[2012-12-13 18:00:44 | 000,478,208 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysNative\dpnet.dll
[2012-12-13 18:00:44 | 000,376,832 |
---- | C] (Microsoft Corporation) --
C:\Windows\SysWow64\dpnet.dll
[1 C:\Windows\*.tmp files ->
C:\Windows\*.tmp -> ]
[color=#E56717]========== Files -
Modified Within 30 Days
==========[/color]
[2013-01-08 08:24:00 | 000,000,830 |
---- | M] () -- C:\Windows\tasks\Adobe
Flash Player Updater.job
[2013-01-08 08:23:46 | 000,001,979 |
---- | M] () --
C:\Users\Public\Desktop\Adobe Reader
XI.lnk
[2013-01-08 08:23:00 | 000,001,048 |
---- | M] () --
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-01-08 08:17:37 | 000,108,008 |
---- | M] (Oracle Corporation) --
C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013-01-08 08:17:31 | 000,308,200 |
---- | M] (Oracle Corporation) --
C:\Windows\SysNative\javaws.exe
[2013-01-08 08:17:31 | 000,188,392 |
---- | M] (Oracle Corporation) --
C:\Windows\SysNative\javaw.exe
[2013-01-08 08:17:29 | 000,188,392 |
---- | M] (Oracle Corporation) --
C:\Windows\SysNative\java.exe
[2013-01-08 08:17:24 | 001,081,320 |
---- | M] (Oracle Corporation) --
C:\Windows\SysNative\npDeployJava1.dll
[2013-01-08 08:17:24 | 000,959,976 |
---- | M] (Oracle Corporation) --
C:\Windows\SysNative\deployJava1.dll
[2013-01-08 01:33:43 | 000,939,455 |
---- | M] () --
C:\Windows\SysWow64\sig.bin
[2013-01-08 01:33:43 | 000,050,827 |
---- | M] () --
C:\Windows\SysWow64\nmp.map
[2013-01-08 00:33:13 | 000,021,200 |
-H-- | M] () --
C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013-01-08 00:33:13 | 000,021,200 |
-H-- | M] () --
C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013-01-08 00:23:25 | 000,002,255 |
---- | M] () --
C:\Users\ALBERT\Desktop\Google
Chrome.lnk
[2013-01-07 23:58:24 | 000,000,822 |
---- | M] () --
C:\Users\Public\Desktop\CCleaner.lnk
[2013-01-07 23:17:13 | 000,001,044 |
---- | M] () --
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-01-07 23:16:40 | 000,067,584 |
--S- | M] () --
C:\Windows\bootstat.dat
[2013-01-07 23:16:31 | 3138,428,928 |
-HS- | M] () -- C:\hiberfil.sys
[2013-01-07 23:00:09 | 000,306,368 |
---- | M] () --
C:\Windows\SysNative\FNTCACHE.DAT
[2012-12-28 19:08:55 | 000,001,518 |
---- | M] () --
C:\Users\Public\Desktop\Adobe
Application Manager.lnk
[2012-12-28 17:31:52 | 000,106,488 |
---- | M] (G Data Software) --
C:\Windows\SysNative\drivers\GRD.sys
[2012-12-16 18:11:22 | 000,046,080 |
---- | M] (Adobe Systems) --
C:\Windows\SysNative\atmlib.dll
[2012-12-16 15:45:03 | 000,367,616 |
---- | M] (Adobe Systems Incorporated)
-- C:\Windows\SysNative\atmfd.dll
[2012-12-16 15:13:28 | 000,295,424 |
---- | M] (Adobe Systems Incorporated)
-- C:\Windows\SysWow64\atmfd.dll
[2012-12-16 15:13:20 | 000,034,304 |
---- | M] (Adobe Systems) --
C:\Windows\SysWow64\atmlib.dll
[2012-12-13 18:25:19 | 000,697,272 |
---- | M] (Adobe Systems Incorporated)
--
C:\Windows\SysWow64\FlashPlayerApp.exe
[2012-12-13 18:25:19 | 000,073,656 |
---- | M] (Adobe Systems Incorporated)
--
C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[1 C:\Windows\*.tmp files ->
C:\Windows\*.tmp -> ]
[color=#E56717]========== Files
Created - No Company Name
==========[/color]
[2013-01-08 08:23:46 | 000,002,441 |
---- | C] () --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\Adobe Reader XI.lnk
[2013-01-08 08:23:46 | 000,001,979 |
---- | C] () --
C:\Users\Public\Desktop\Adobe Reader
XI.lnk
[2013-01-08 00:34:36 | 000,002,017 |
---- | C] () --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\VAIO Care.lnk
[2013-01-08 00:27:12 | 000,001,134 |
---- | C] () --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\TeamViewer 8 Host.lnk
[2013-01-08 00:23:25 | 000,002,255 |
---- | C] () --
C:\Users\ALBERT\Desktop\Google
Chrome.lnk
[2013-01-07 23:58:24 | 000,000,822 |
---- | C] () --
C:\Users\Public\Desktop\CCleaner.lnk
[2013-01-07 23:08:03 | 000,000,545 |
---- | C] () -- C:\Windows\UC.PIF
[2013-01-07 23:08:03 | 000,000,545 |
---- | C] () -- C:\Windows\RAR.PIF
[2013-01-07 23:08:03 | 000,000,545 |
---- | C] () -- C:\Windows\PKZIP.PIF
[2013-01-07 23:08:03 | 000,000,545 |
---- | C] () -- C:\Windows\PKUNZIP.PIF
[2013-01-07 23:08:03 | 000,000,545 |
---- | C] () -- C:\Windows\LHA.PIF
[2013-01-07 23:08:03 | 000,000,545 |
---- | C] () -- C:\Windows\ARJ.PIF
[2013-01-03 21:50:57 | 000,001,159 |
---- | C] () --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\Mozilla Firefox.lnk
[2012-12-28 19:08:55 | 000,001,530 |
---- | C] () --
C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\Adobe Application
Manager.lnk
[2012-12-28 19:08:55 | 000,001,518 |
---- | C] () --
C:\Users\Public\Desktop\Adobe
Application Manager.lnk
[2012-10-02 11:04:20 | 000,939,455 |
---- | C] () --
C:\Windows\SysWow64\sig.bin
[2012-08-17 22:51:00 | 000,004,608 |
---- | C] () --
C:\Users\ALBERT\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-06-01 08:43:50 | 000,074,703 |
---- | C] () --
C:\Windows\SysWow64\mfc45.dll
[2012-06-01 07:04:19 | 000,000,000 |
---- | C] () --
C:\Windows\ativpsrm.bin
[2012-06-01 06:57:55 | 000,003,917 |
---- | C] () --
C:\Windows\SysWow64\atipblup.dat
[2012-03-20 02:15:26 | 013,184,512 |
---- | C] () --
C:\Windows\SysWow64\ig4icd32.dll
[2012-03-20 02:15:26 | 000,963,912 |
---- | C] () --
C:\Windows\SysWow64\igkrng600.bin
[2012-03-20 02:15:26 | 000,261,208 |
---- | C] () --
C:\Windows\SysWow64\igfcg600m.bin
[2012-03-20 02:15:26 | 000,204,960 |
---- | C] () --
C:\Windows\SysWow64\ativvsvl.dat
[2012-03-20 02:15:26 | 000,157,152 |
---- | C] () --
C:\Windows\SysWow64\ativvsva.dat
[2012-03-20 02:15:26 | 000,145,804 |
---- | C] () --
C:\Windows\SysWow64\igcompkrng600.bin
[2012-03-20 02:15:26 | 000,058,880 |
---- | C] () --
C:\Windows\SysWow64\igdde32.dll
[2012-03-20 02:15:26 | 000,056,476 |
---- | C] () --
C:\Windows\SysWow64\ativvsny.dat
[2012-03-20 02:15:25 | 000,026,936 |
---- | C] () --
C:\Windows\SysWow64\ativvsnl.dat
[2012-03-20 02:15:25 | 000,003,917 |
---- | C] () --
C:\Windows\SysWow64\atipblag.dat
[2012-02-03 17:05:52 | 000,059,904 |
---- | C] () --
C:\Windows\SysWow64\OpenVideo.dll
[2012-02-03 17:05:40 | 000,054,784 |
---- | C] () --
C:\Windows\SysWow64\OVDecode.dll
[2012-02-02 22:08:26 | 000,001,536 |
---- | C] () --
C:\Windows\SysWow64\IusEventLog.dll
[2011-12-07 03:51:13 | 001,690,122 |
---- | C] () --
C:\Windows\SysWow64\PerfStringBackup.INI
[color=#E56717]========== ZeroAccess
Check ==========[/color]
[2009-07-14 05:55:00 | 000,000,227 |
RHS- | M] () --
C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
/64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
/64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
/64
"" =
C:\Windows\SysNative\shell32.dll --
[2012-06-09 06:43:10 | 014,172,672 |
---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" =
%SystemRoot%\system32\shell32.dll --
[2012-06-09 05:41:00 | 012,873,728 |
---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
/64
"" =
C:\Windows\SysNative\wbem\fastprox.dll
-- [2009-07-14 02:40:51 | 000,909,312
| ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" =
%systemroot%\system32\wbem\fastprox.dll
-- [2010-11-21 04:24:25 | 000,606,208
| ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
/64
"" =
C:\Windows\SysNative\wbem\wbemess.dll
-- [2009-07-14 02:41:56 | 000,505,856
| ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >
Obawiam sie ze pozostały jeszcze jakies smieci, prosze o pomoc.