OTL logfile created on: 6/11/2014 2:47:46 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Krzysiek\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16866)
Locale: 00000409 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd
 
3.73 Gb Total Physical Memory | 1.34 Gb Available Physical Memory | 35.95% Memory free
7.46 Gb Paging File | 3.00 Gb Available in Paging File | 40.17% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 150.00 Gb Total Space | 17.28 Gb Free Space | 11.52% Space Free | Partition Type: NTFS
Drive E: | 300.66 Gb Total Space | 35.68 Gb Free Space | 11.87% Space Free | Partition Type: NTFS
 
Computer Name: KRZYSIEK-PC | User Name: Krzysiek | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
[color=#E56717]========== Processes (SafeList) ==========[/color]
 
PRC - [2014/06/11 12:31:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Krzysiek\Downloads\OTL_[www.programosy.pl].exe
PRC - [2014/06/06 17:40:15 | 003,890,208 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\avastui.exe
PRC - [2014/05/20 02:45:22 | 033,322,312 | ---- | M] (Dropbox, Inc.) -- C:\Users\Krzysiek\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2014/05/15 12:41:26 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2014/05/14 01:40:56 | 000,860,488 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/05/08 15:48:40 | 001,457,528 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
PRC - [2014/04/29 16:28:32 | 000,246,112 | ---- | M] () -- C:\ProgramData\PLAY ONLINE\OnlineUpdate\ouc.exe
PRC - [2014/04/25 09:14:09 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014/02/04 12:17:10 | 000,598,160 | ---- | M] (Irfan Skiljan) -- C:\Program Files (x86)\IrfanView\i_view32.exe
PRC - [2013/12/21 08:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/11/06 11:55:46 | 000,845,168 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2013/11/06 11:55:40 | 000,311,152 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
PRC - [2013/11/06 11:55:38 | 001,564,528 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe
PRC - [2013/03/22 07:07:18 | 000,093,072 | ---- | M] (TomTom) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2011/03/14 17:27:28 | 000,236,384 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
PRC - [2010/11/12 03:21:36 | 000,296,768 | ---- | M] (NTI Corporation) -- C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
 
 
[color=#E56717]========== Modules (No Company Name) ==========[/color]
 
MOD - [2014/06/11 10:27:26 | 000,043,008 | ---- | M] () -- c:\Users\Krzysiek\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplrnror.dll
MOD - [2014/05/15 12:41:23 | 003,839,088 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2014/05/15 11:25:51 | 000,805,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\04824fdbd5dce32530ba44ae012e4fb9\System.Runtime.Remoting.ni.dll
MOD - [2014/05/14 01:40:54 | 000,414,536 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppgooglenaclpluginchrome.dll
MOD - [2014/05/14 01:40:53 | 013,695,816 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll
MOD - [2014/05/14 01:40:50 | 004,217,672 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll
MOD - [2014/05/14 01:40:45 | 000,716,616 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libglesv2.dll
MOD - [2014/05/14 01:40:44 | 000,126,280 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libegl.dll
MOD - [2014/05/14 01:40:43 | 001,732,424 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ffmpegsumo.dll
MOD - [2014/02/13 17:45:01 | 000,223,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\f4354d6580fbb745c0c8acba382a7b84\System.ServiceProcess.ni.dll
MOD - [2014/02/13 17:44:27 | 001,889,792 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\3fe705796c6a41d4889d9001d1c56af8\System.Xaml.ni.dll
MOD - [2014/02/13 17:44:14 | 018,813,440 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\a4b45c44490c75bc2fb22780e7ef087d\PresentationFramework.ni.dll
MOD - [2014/02/13 17:43:24 | 011,025,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\a74542efbeb46445949a39026c501132\PresentationCore.ni.dll
MOD - [2014/02/13 17:42:54 | 003,950,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\acf97bfe2a931d4a47253b26b7218991\WindowsBase.ni.dll
MOD - [2014/02/13 17:42:37 | 007,662,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bada32953bb6b16a53d653eae23d78dc\System.Xml.ni.dll
MOD - [2014/02/13 17:42:35 | 006,990,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\dce99d8de14d8a015313db98c72552ee\System.Core.ni.dll
MOD - [2014/02/13 17:42:18 | 000,976,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\bbc48ec4245e502ae19b0601d3799c9e\System.Configuration.ni.dll
MOD - [2014/02/13 17:42:15 | 010,060,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ff26cc03e6d57d8abd13b990332e67c6\System.ni.dll
MOD - [2014/02/13 17:41:52 | 016,953,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll
MOD - [2014/01/03 03:09:26 | 003,610,624 | ---- | M] () -- C:\Users\Krzysiek\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2013/10/23 15:27:47 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2013/08/23 21:01:44 | 025,100,288 | ---- | M] () -- C:\Users\Krzysiek\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2012/12/18 21:08:32 | 014,588,632 | ---- | M] () -- C:\Program Files (x86)\Adobe\Reader 11.0\Reader\NPSWF32.dll
MOD - [2012/09/23 21:43:36 | 000,313,992 | ---- | M] () -- C:\Program Files (x86)\Adobe\Reader 11.0\Reader\sqlite.dll
MOD - [2010/11/12 03:22:22 | 000,465,640 | ---- | M] () -- C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
 
 
[color=#E56717]========== Services (SafeList) ==========[/color]
 
SRV:[b]64bit:[/b] - [2014/04/25 09:14:09 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:[b]64bit:[/b] - [2014/04/09 15:13:48 | 000,289,256 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe -- (McComponentHostService)
SRV:[b]64bit:[/b] - [2013/05/27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2011/01/31 22:55:14 | 000,244,624 | ---- | M] (Acer Incorporated) [Disabled | Stopped] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV:[b]64bit:[/b] - [2011/01/31 22:55:14 | 000,244,624 | ---- | M] (Acer Incorporated) [Disabled | Stopped] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Live Updater Service)
SRV:[b]64bit:[/b] - [2011/01/28 17:44:08 | 000,868,224 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV:[b]64bit:[/b] - [2010/11/19 01:14:36 | 000,354,304 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:[b]64bit:[/b] - [2010/11/09 15:55:50 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:[b]64bit:[/b] - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:[b]64bit:[/b] - [2010/06/17 14:23:36 | 000,194,496 | ---- | M] (Advanced Micro Devices) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe -- (AMD Reservation Manager)
SRV - [2014/05/14 13:10:39 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/04/29 16:28:32 | 000,246,112 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\PLAY ONLINE\UpdateDog\ouc.exe -- (PLAY ONLINE. RunOuc)
SRV - [2014/04/01 11:32:36 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/12/21 08:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/03/22 07:07:18 | 000,093,072 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2011/03/26 17:25:13 | 000,655,624 | ---- | M] (Acresso Software Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/03/14 17:27:34 | 000,346,976 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\HWDeviceService64.exe -- (HWDeviceService64.exe)
SRV - [2010/12/31 14:05:26 | 000,310,864 | ---- | M] (Dritek System Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2010/12/28 10:00:34 | 001,296,728 | ---- | M] (www.BitComet.com) [On_Demand | Stopped] -- C:\Program Files (x86)\BitComet\tools\BitCometService.exe -- (BITCOMET_HELPER_SERVICE)
SRV - [2010/11/12 03:21:52 | 000,257,344 | ---- | M] (NTI Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2010/09/28 04:09:54 | 000,172,912 | ---- | M] (Egis Technology Inc. ) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe -- (EgisTec Ticket Service)
SRV - [2010/06/02 01:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010/01/08 15:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
 
DRV:[b]64bit:[/b] - [2014/05/22 18:08:26 | 000,061,112 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}Gw64.sys -- ({0c0bb4a8-45a4-4685-9c1d-08d98af4b926}Gw64)
DRV:[b]64bit:[/b] - [2014/05/16 12:50:07 | 001,039,096 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsnx.sys -- (aswSnx)
DRV:[b]64bit:[/b] - [2014/05/16 12:50:07 | 000,423,240 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsp.sys -- (aswSP)
DRV:[b]64bit:[/b] - [2014/05/16 12:50:06 | 000,085,328 | ---- | M] (AVAST Software) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\aswstm.sys -- (aswStm)
DRV:[b]64bit:[/b] - [2014/04/29 16:28:40 | 000,229,376 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_juwwanecm.sys -- (huawei_wwanecm)
DRV:[b]64bit:[/b] - [2014/04/29 16:28:40 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV:[b]64bit:[/b] - [2014/04/29 16:28:40 | 000,104,448 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV:[b]64bit:[/b] - [2014/04/29 16:28:40 | 000,090,112 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV:[b]64bit:[/b] - [2014/04/29 16:28:40 | 000,030,720 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl)
DRV:[b]64bit:[/b] - [2014/04/29 16:28:40 | 000,013,952 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter)
DRV:[b]64bit:[/b] - [2014/04/29 16:28:39 | 000,439,808 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbwwan.sys -- (ewusbmbb)
DRV:[b]64bit:[/b] - [2014/04/29 16:28:39 | 000,225,920 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:[b]64bit:[/b] - [2014/04/25 09:14:35 | 000,208,416 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:[b]64bit:[/b] - [2014/04/25 09:14:35 | 000,079,184 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:[b]64bit:[/b] - [2014/04/25 09:14:35 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:[b]64bit:[/b] - [2014/04/25 09:14:34 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:[b]64bit:[/b] - [2014/04/25 09:14:33 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:[b]64bit:[/b] - [2013/08/21 06:31:40 | 000,204,568 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:[b]64bit:[/b] - [2013/08/21 06:31:40 | 000,103,576 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:[b]64bit:[/b] - [2013/05/09 10:59:06 | 000,022,600 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswKbd.sys -- (aswKbd)
DRV:[b]64bit:[/b] - [2012/08/23 16:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2012/08/23 16:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2012/03/01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2011/09/02 22:29:54 | 000,019,936 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdrvio.sys -- (pwdrvio)
DRV:[b]64bit:[/b] - [2011/09/02 22:29:52 | 000,013,280 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdspio.sys -- (pwdspio)
DRV:[b]64bit:[/b] - [2011/03/11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011/03/11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2011/01/17 19:26:11 | 000,062,584 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:[b]64bit:[/b] - [2011/01/17 19:26:11 | 000,022,912 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:[b]64bit:[/b] - [2011/01/17 19:26:11 | 000,020,328 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:[b]64bit:[/b] - [2011/01/11 09:01:32 | 001,495,680 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:[b]64bit:[/b] - [2010/11/20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010/11/17 01:04:32 | 000,115,216 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:[b]64bit:[/b] - [2010/11/12 08:23:40 | 000,138,024 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:[b]64bit:[/b] - [2010/11/09 16:34:04 | 008,013,312 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:[b]64bit:[/b] - [2010/11/09 15:18:54 | 000,287,232 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:[b]64bit:[/b] - [2010/09/27 09:24:44 | 000,076,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:[b]64bit:[/b] - [2010/07/09 05:51:50 | 000,017,408 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:[b]64bit:[/b] - [2010/06/17 11:18:28 | 000,246,376 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:[b]64bit:[/b] - [2010/05/11 12:11:38 | 002,229,608 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:[b]64bit:[/b] - [2010/04/28 22:43:20 | 000,038,528 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:[b]64bit:[/b] - [2010/04/20 04:35:14 | 000,018,432 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:[b]64bit:[/b] - [2010/02/18 18:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:[b]64bit:[/b] - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/07/14 02:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:[b]64bit:[/b] - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== Internet Explorer ==========[/color]
 
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.qone8.com/web/?type=ds&ts=1401721203&from=smt&uid=HitachiXHTS545050B9A300_110301PBN4031721MY5EX&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.qone8.com/web/?type=ds&ts=1401721203&from=smt&uid=HitachiXHTS545050B9A300_110301PBN4031721MY5EX&q={searchTerms}
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=1083&systemid=1&sr=0&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.qone8.com/web/?type=ds&ts=1401721203&from=smt&uid=HitachiXHTS545050B9A300_110301PBN4031721MY5EX&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.qone8.com/web/?type=ds&ts=1401721203&from=smt&uid=HitachiXHTS545050B9A300_110301PBN4031721MY5EX&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Value error.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.bing.com/search?q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/search?q={searchTerms}
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=396e22dc-fcb5-11e0-9c5b-1c7508f1eef0&q={searchTerms}
IE - HKLM\..\SearchScopes\{938220A1-F3DE-44B2-AE9A-E0BD29F87E07}: "URL" = http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=1083&systemid=1&sr=0&q={searchTerms}
IE - HKLM\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=396e22dc-fcb5-11e0-9c5b-1c7508f1eef0&q={searchTerms}
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = 
IE - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\..\SearchScopes\${searchCLSID}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=396e22dc-fcb5-11e0-9c5b-1c7508f1eef0&q={searchTerms}
IE - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=DABBEC55F953A8D7&affID=119357&tsp=4965
IE - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\..\SearchScopes\{5CF6BDB5-5982-4A11-995B-E070C8A73E72}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=396e22dc-fcb5-11e0-9c5b-1c7508f1eef0&q={searchTerms}
IE - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=1083&systemid=1&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\..\SearchScopes\{FED79978-32E3-4575-B917-14EB4BDDA4D7}: "URL" = http://www.daemon-search.com/search?q={searchTerms}
IE - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
[color=#E56717]========== FireFox ==========[/color]
 
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..extensions.enabledAddons: quick_start%40gmail.com:3.2.6
FF - prefs.js..extensions.enabledAddons: en-GB%40dictionaries.addons.mozilla.org:1.19.1
FF - prefs.js..extensions.enabledAddons: SignPlugin%40bph.pl:1.4.0.7
FF - prefs.js..extensions.enabledAddons: %7BB042753D-F57E-4e8e-A01B-7379A6D4CEFB%7D:1.35
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.22
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:9.0.2018.95
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
 
 
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.55.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@ganymede/GanymedeNetPlugin,version=1.0: C:\Program Files (x86)\Ganymede\Plugins\npganymedenet.dll ( )
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@photodex.com/PhotodexPresenter: C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll ( )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Krzysiek\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014/04/25 09:14:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/04/01 11:32:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/05/15 12:41:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.5.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.5.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{e4f94d1e-2f53-401e-8885-681602c0ddd8}: C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014/04/04 12:36:14 | 000,010,691 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Krzysiek\AppData\Roaming\IDM\idmmzcc5
 
[2013/11/14 15:40:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Extensions
[2012/05/07 14:28:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com
[2014/06/11 12:09:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\extensions
[2012/02/23 12:28:51 | 000,000,000 | ---D | M] (Wincore Mediabar) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\extensions\{28387537-e3f9-4ed7-860c-11e69af4a8a0}
[2011/12/06 00:32:14 | 000,000,000 | ---D | M] (VshareComplete - Speed up your search with your personal search suggestions tool) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\extensions\{3697b17c-b572-4862-a5e6-7f922c0f3403}
[2012/02/29 22:21:37 | 000,000,000 | ---D | M] (Searchqu Toolbar) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2013/05/13 19:54:10 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2014/03/26 16:19:15 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/02/19 17:25:20 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\extensions\DTToolbar@toolbarnet.com
[2012/06/06 17:32:16 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\extensions\en-GB@dictionaries.addons.mozilla.org
[2012/02/03 19:49:44 | 000,000,000 | ---D | M] (BPH Sign Plugin) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\extensions\SignPlugin@bph.pl
[2012/12/14 00:06:39 | 000,005,433 | ---- | M] () (No name found) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\extensions\50ca554076d81@50ca554076dba.com.xpi
[2013/08/04 20:36:34 | 000,224,035 | ---- | M] () (No name found) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[2011/11/27 14:21:30 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2013/08/05 20:15:29 | 000,006,507 | ---- | M] () -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\searchplugins\babylon.xml
[2012/02/29 22:21:26 | 000,002,519 | ---- | M] () -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\searchplugins\Search_Results.xml
[2012/02/04 20:46:35 | 000,000,792 | ---- | M] () -- C:\Users\Krzysiek\AppData\Roaming\Mozilla\Firefox\Profiles\5gvfr1u3.default\searchplugins\startsear.xml
[2014/04/01 11:32:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2014/04/01 11:32:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/05/15 12:41:32 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014/04/25 09:14:44 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
File not found (No name found) -- C:\USERS\KRZYSIEK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5GVFR1U3.DEFAULT\EXTENSIONS\QUICK_START@GMAIL.COM
[2012/01/12 10:58:30 | 000,917,816 | ---- | M] (BitComet) -- C:\Program Files (x86)\mozilla firefox\plugins\npBitCometAgent.dll
[2012/07/25 15:57:52 | 000,121,024 | ---- | M] ( ) -- C:\Program Files (x86)\mozilla firefox\plugins\npganymedenet.dll
[2011/10/27 15:45:50 | 000,083,456 | ---- | M] (LiveVDO ) -- C:\Program Files (x86)\mozilla firefox\plugins\npvsharetvplg.dll
 
[color=#E56717]========== Chrome  ==========[/color]
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Widevine Content Decryption Module (Enabled) = C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.1.377\_platform_specific\win_x86\widevinecdmadapter.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll
CHR - plugin: MicrosoftÂ® Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: BitCometAgent (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npBitCometAgent.dll
CHR - plugin: LiveVDO plug-in (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npvsharetvplg.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
CHR - plugin: GanymedeNet.Detector (Enabled) = C:\Program Files (x86)\Ganymede\Plugins\npganymedenet.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
CHR - plugin: Java Deployment Toolkit 7.0.450.18 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
CHR - plugin: Java(TM) Platform SE 7 U45 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll
CHR - plugin: Photodex Presenter Plugin (Enabled) = C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files (x86)\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows LiveÂ™ Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: McAfee Security Scanner + (Enabled) = C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll
CHR - Extension: Dysk Google = C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: McAfee Security Scan+ = C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh\3.8.141.12_0\
CHR - Extension: Szukaj w Google = C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Wallet = C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: LiveVDO plugin = C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp\1.3_0\
CHR - Extension: Gmail = C:\Users\Krzysiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (VshareComplete) - {08337871-0e50-4031-9110-3bd21ca3c065} - C:\Users\Krzysiek\AppData\Roaming\VshareComplete\64\VshareComplete64.dll (SimplyGen)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:[b]64bit:[/b] - BHO: (DataMngr) - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\BROWSE~1.DLL File not found
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No CLSID value found.
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:[b]64bit:[/b] - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O4:[b]64bit:[/b] - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:[b]64bit:[/b] - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3012411354-210655238-2944110317-1001..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKU\S-1-5-21-3012411354-210655238-2944110317-1001..\Run: [HP Officejet 6700 (NET)] C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKU\S-1-5-21-3012411354-210655238-2944110317-1001..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Krzysiek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Krzysiek\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O7 - HKU\S-1-5-21-3012411354-210655238-2944110317-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O8:[b]64bit:[/b] - Extra context menu item: &D&ownload &with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8:[b]64bit:[/b] - Extra context menu item: &D&ownload all with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: &D&ownload &with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D&ownload all with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:[b]64bit:[/b] - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 10.55.2)
O16:[b]64bit:[/b] - DPF: {CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_11-windows-i586.cab (Java Plug-in 1.7.0_11)
O16:[b]64bit:[/b] - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)
O16:[b]64bit:[/b] - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab (Java Plug-in 10.55.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1E08826C-01FB-4BB0-947E-DBBD281F9F1B}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3107AB16-8EC3-4C66-8D6E-217A26940DA0}: NameServer = 193.41.112.18 193.41.112.14
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{589049FA-EA8F-476C-BD9C-18BBE79AA383}: NameServer = 89.108.195.21 89.108.202.21
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8AA67417-1820-4A0C-AC50-CC8B36672D1A}: NameServer = 89.108.195.21 89.108.202.21
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O20:[b]64bit:[/b] - AppInit_DLLs: (C:\PROGRA~2\SupTab\SEARCH~2.DLL) -  File not found
O20 - AppInit_DLLs: (C:\PROGRA~2\SupTab\SEARCH~1.DLL) -  File not found
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (Userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\SysWOW64\Userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/12/18 16:41:33 | 000,000,000 | RHSD | M] - C:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/12/18 16:41:33 | 000,000,000 | RHSD | M] - E:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\{005b6cdd-d0b3-11e1-9cbe-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{005b6cdd-d0b3-11e1-9cbe-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{005b6cf9-d0b3-11e1-9cbe-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{005b6cf9-d0b3-11e1-9cbe-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{005b6d1d-d0b3-11e1-9cbe-1c7508f1eef0}\Shell - "" = AutoRun
O33 - MountPoints2\{005b6d1d-d0b3-11e1-9cbe-1c7508f1eef0}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{005b6d27-d0b3-11e1-9cbe-1c7508f1eef0}\Shell - "" = AutoRun
O33 - MountPoints2\{005b6d27-d0b3-11e1-9cbe-1c7508f1eef0}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{048d78ed-d798-11e3-9db2-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{048d78ed-d798-11e3-9db2-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{05718101-d181-11e1-88df-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{05718101-d181-11e1-88df-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{1993f15f-99e3-11e2-ac32-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{1993f15f-99e3-11e2-ac32-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{1993f189-99e3-11e2-ac32-1c7508f1eef0}\Shell - "" = AutoRun
O33 - MountPoints2\{1993f189-99e3-11e2-ac32-1c7508f1eef0}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{329cd5e5-5acf-11e1-9ec9-1c7508f1eef0}\Shell - "" = AutoRun
O33 - MountPoints2\{329cd5e5-5acf-11e1-9ec9-1c7508f1eef0}\Shell\AutoRun\command - "" = F:\setup.exe
O33 - MountPoints2\{34188e74-43cd-11e3-9237-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{34188e74-43cd-11e3-9237-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{492104b1-85ba-11e2-bcba-1c7508f1eef0}\Shell - "" = AutoRun
O33 - MountPoints2\{492104b1-85ba-11e2-bcba-1c7508f1eef0}\Shell\AutoRun\command - "" = F:\StartUp.exe
O33 - MountPoints2\{4ee2663f-aab7-11e3-9e13-f655f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{4ee2663f-aab7-11e3-9e13-f655f953a8d7}\Shell\AutoRun\command - "" = F:\StartUp.exe
O33 - MountPoints2\{534dbfba-d4ff-11e3-a25c-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{534dbfba-d4ff-11e3-a25c-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{5aaf44c9-1bc2-11e3-b93e-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{5aaf44c9-1bc2-11e3-b93e-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{789e5c0b-9ca1-11e2-b68b-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{789e5c0b-9ca1-11e2-b68b-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{7c6bbbc9-868e-11e3-bcb1-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{7c6bbbc9-868e-11e3-bcb1-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{7c6bbbe4-868e-11e3-bcb1-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{7c6bbbe4-868e-11e3-bcb1-ec55f953a8d7}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{7c6bbbf1-868e-11e3-bcb1-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{7c6bbbf1-868e-11e3-bcb1-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{7c6bbc05-868e-11e3-bcb1-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{7c6bbc05-868e-11e3-bcb1-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{86458910-8b4f-11e3-aba7-001e101fe5e1}\Shell - "" = AutoRun
O33 - MountPoints2\{86458910-8b4f-11e3-aba7-001e101fe5e1}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{86458914-8b4f-11e3-aba7-001e101fe5e1}\Shell - "" = AutoRun
O33 - MountPoints2\{86458914-8b4f-11e3-aba7-001e101fe5e1}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{8c9f94e9-ed4f-11e2-b82f-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{8c9f94e9-ed4f-11e2-b82f-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{92fcf7e9-1fb0-11e3-b3d0-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{92fcf7e9-1fb0-11e3-b3d0-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{997f1de7-ea0c-11e2-aea9-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{997f1de7-ea0c-11e2-aea9-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{997f1deb-ea0c-11e2-aea9-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{997f1deb-ea0c-11e2-aea9-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b95710cb-d24b-11e1-9755-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{b95710cb-d24b-11e1-9755-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b95710cf-d24b-11e1-9755-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{b95710cf-d24b-11e1-9755-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b95710de-d24b-11e1-9755-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{b95710de-d24b-11e1-9755-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b95710f1-d24b-11e1-9755-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{b95710f1-d24b-11e1-9755-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b957110c-d24b-11e1-9755-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{b957110c-d24b-11e1-9755-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b957110f-d24b-11e1-9755-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{b957110f-d24b-11e1-9755-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ba812c02-3f06-11e3-a4ba-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{ba812c02-3f06-11e3-a4ba-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ba812c05-3f06-11e3-a4ba-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{ba812c05-3f06-11e3-a4ba-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ba812c16-3f06-11e3-a4ba-1c7508f1eef0}\Shell - "" = AutoRun
O33 - MountPoints2\{ba812c16-3f06-11e3-a4ba-1c7508f1eef0}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ba812c18-3f06-11e3-a4ba-1c7508f1eef0}\Shell - "" = AutoRun
O33 - MountPoints2\{ba812c18-3f06-11e3-a4ba-1c7508f1eef0}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{cd55e57c-cfa9-11e3-a5e6-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{cd55e57c-cfa9-11e3-a5e6-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{cd55e5a6-cfa9-11e3-a5e6-1c7508f1eef0}\Shell - "" = AutoRun
O33 - MountPoints2\{cd55e5a6-cfa9-11e3-a5e6-1c7508f1eef0}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{dc439102-42ff-11e3-a2c3-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{dc439102-42ff-11e3-a2c3-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{e27d12ce-a11a-11e3-acf4-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{e27d12ce-a11a-11e3-acf4-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{e4a4484a-8cf3-11e3-bd88-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{e4a4484a-8cf3-11e3-bd88-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{e4a4484d-8cf3-11e3-bd88-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{e4a4484d-8cf3-11e3-bd88-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{e7824fce-2e5d-11e3-8f8f-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{e7824fce-2e5d-11e3-8f8f-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{e7824fd2-2e5d-11e3-8f8f-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{e7824fd2-2e5d-11e3-8f8f-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ebeac8c9-6606-11e1-8347-1c7508f1eef0}\Shell - "" = AutoRun
O33 - MountPoints2\{ebeac8c9-6606-11e1-8347-1c7508f1eef0}\Shell\AutoRun\command - "" = H:\Dexter_setup.exe
O33 - MountPoints2\{eeb6d129-4724-11e3-a850-ec55f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{eeb6d129-4724-11e3-a850-ec55f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{f7b612e6-2dfc-11e3-88f3-f655f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{f7b612e6-2dfc-11e3-88f3-f655f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{f7b61307-2dfc-11e3-88f3-f655f953a8d7}\Shell - "" = AutoRun
O33 - MountPoints2\{f7b61307-2dfc-11e3-88f3-f655f953a8d7}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\StartUp.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
 
[2014/06/06 17:23:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2014/06/06 17:23:48 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Local\WinZip
[2014/06/06 17:23:28 | 000,000,000 | ---D | C] -- C:\ProgramData\WinZip
[2014/06/06 17:23:22 | 000,000,000 | ---D | C] -- C:\Program Files\WinZip
[2014/06/06 17:23:03 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2014/06/02 18:07:51 | 000,061,112 | ---- | C] (StdLib) -- C:\Windows\SysNative\drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}Gw64.sys
[2014/06/02 17:03:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FM Software Studio
[2014/06/02 17:01:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\trolatunt
[2014/06/02 17:01:11 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsProtectManger
[2014/06/02 17:01:06 | 000,000,000 | ---D | C] -- C:\ProgramData\IePluginServices
[2014/06/02 17:01:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SupTab
[2014/06/02 17:00:45 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Roaming\qone8
[2014/06/02 16:58:53 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Local\TempDIR
[2014/06/02 16:27:23 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Roaming\DigitalSites
[2014/06/02 16:27:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Image Converter
[2014/06/02 16:21:41 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Roaming\Frau-Mann BT
[2014/06/02 16:20:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FM Software Studio
[2014/06/02 16:19:58 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Local\WorldofTanks
[2014/06/02 16:09:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\office Convert Pdf to Jpg Jpeg Tiff Free
[2014/06/02 16:09:06 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\tempdir
[2014/06/02 16:08:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\office Convert Pdf to Jpg Jpeg Tiff Free
[2014/05/28 16:02:26 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Roaming\Thunderbird
[2014/05/28 16:02:26 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Local\Thunderbird
[2014/05/28 15:37:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2014/05/28 14:18:33 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\Desktop\CONSE inwestycje
[2014/05/28 14:04:45 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Local\Skype
[2014/05/28 14:03:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014/05/28 14:03:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2014/05/28 14:03:43 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2014/05/28 12:51:57 | 000,000,000 | R--D | C] -- C:\Users\Krzysiek\Dropbox
[2014/05/28 12:50:55 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Roaming\DropboxMaster
[2014/05/28 12:50:13 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2014/05/28 12:48:09 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Roaming\Dropbox
[2014/05/28 12:32:30 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\Desktop\Profit
[2014/05/28 12:12:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
[2014/05/28 12:12:27 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan
[2014/05/26 12:51:21 | 000,000,000 | ---D | C] -- C:\Users\Krzysiek\AppData\Local\{FB96D2D2-689F-4A2C-BCF7-A56218F9FB06}
[2014/05/15 11:44:35 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014/05/15 11:44:32 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014/05/14 13:11:41 | 000,477,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2014/05/14 13:11:39 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2014/05/14 13:08:37 | 001,460,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2014/05/14 13:08:34 | 003,969,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2014/05/14 13:08:32 | 003,914,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2014/05/14 13:08:32 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2014/05/14 13:08:31 | 000,722,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\objsel.dll
[2014/05/14 13:08:30 | 005,550,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2014/05/14 13:08:28 | 000,538,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\objsel.dll
[2014/05/14 13:08:26 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2014/05/14 13:08:23 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dimsroam.dll
[2014/05/14 13:08:23 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dimsroam.dll
[2014/05/14 13:08:22 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cngprovider.dll
[2014/05/14 13:08:22 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adprovider.dll
[2014/05/14 13:08:22 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\capiprovider.dll
[2014/05/14 13:08:22 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpapiprovider.dll
[2014/05/14 13:08:22 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cngprovider.dll
[2014/05/14 13:08:22 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adprovider.dll
[2014/05/14 13:08:22 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\capiprovider.dll
[2014/05/14 13:08:22 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpapiprovider.dll
[2014/05/14 13:08:21 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2014/05/14 13:08:21 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wincredprovider.dll
[2014/05/14 13:08:21 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wincredprovider.dll
[2014/05/14 13:08:20 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2014/05/14 13:08:20 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
 
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
 
[2014/06/11 14:54:01 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/06/11 14:09:04 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/06/11 10:36:42 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/06/11 10:36:41 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/06/11 10:27:17 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/06/11 10:26:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/06/11 10:26:33 | 3003,305,984 | -HS- | M] () -- C:\hiberfil.sys
[2014/06/11 00:07:56 | 000,782,510 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/06/11 00:07:56 | 000,654,480 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/06/11 00:07:56 | 000,122,352 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/06/08 22:57:06 | 000,023,040 | ---- | M] () -- C:\Users\Krzysiek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/06/06 17:23:53 | 000,002,241 | ---- | M] () -- C:\Users\Public\Desktop\WinZip.lnk
[2014/06/02 18:37:31 | 000,000,304 | ---- | M] () -- C:\Windows\tasks\Digital Sites.job
[2014/06/02 18:27:58 | 000,002,219 | ---- | M] () -- C:\Users\Krzysiek\Desktop\Google Chrome.lnk
[2014/06/02 18:27:47 | 000,001,441 | ---- | M] () -- C:\Users\Krzysiek\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/06/02 17:29:08 | 000,000,040 | ---- | M] () -- C:\Users\Krzysiek\AppData\Roaming\WB.CFG
[2014/06/02 17:03:53 | 000,001,442 | ---- | M] () -- C:\Users\Krzysiek\Desktop\Free PDF To JPG.lnk
[2014/06/02 16:09:07 | 000,001,072 | ---- | M] () -- C:\Users\Krzysiek\Desktop\office Convert Pdf to Jpg Jpeg Tiff Free.lnk
[2014/05/29 12:38:32 | 000,023,590 | ---- | M] () -- C:\Users\Krzysiek\Desktop\plan 72m2.jpg
[2014/05/28 16:06:19 | 000,002,074 | ---- | M] () -- C:\Users\Krzysiek\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2014/05/28 15:37:28 | 000,002,050 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2014/05/28 14:03:48 | 000,002,517 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2014/05/28 12:51:57 | 000,001,049 | ---- | M] () -- C:\Users\Krzysiek\Desktop\Dropbox.lnk
[2014/05/28 12:51:09 | 000,001,059 | ---- | M] () -- C:\Users\Krzysiek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2014/05/28 12:50:54 | 000,000,261 | ---- | M] () -- C:\Windows\wininit.ini
[2014/05/28 12:12:42 | 000,001,895 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2014/05/28 12:12:42 | 000,001,895 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2014/05/22 18:08:26 | 000,061,112 | ---- | M] (StdLib) -- C:\Windows\SysNative\drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}Gw64.sys
[2014/05/16 12:50:07 | 001,039,096 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsnx.sys
[2014/05/16 12:50:07 | 000,423,240 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsp.sys
[2014/05/16 12:50:06 | 000,085,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswstm.sys
[2014/05/14 13:10:37 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014/05/14 13:10:37 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
 
[color=#E56717]========== Files Created - No Company Name ==========[/color]
 
[2014/06/06 17:23:53 | 000,002,241 | ---- | C] () -- C:\Users\Public\Desktop\WinZip.lnk
[2014/06/02 17:29:07 | 000,000,040 | ---- | C] () -- C:\Users\Krzysiek\AppData\Roaming\WB.CFG
[2014/06/02 17:03:53 | 000,001,442 | ---- | C] () -- C:\Users\Krzysiek\Desktop\Free PDF To JPG.lnk
[2014/06/02 16:27:25 | 000,000,304 | ---- | C] () -- C:\Windows\tasks\Digital Sites.job
[2014/06/02 16:09:07 | 000,001,072 | ---- | C] () -- C:\Users\Krzysiek\Desktop\office Convert Pdf to Jpg Jpeg Tiff Free.lnk
[2014/06/02 16:09:03 | 001,503,232 | ---- | C] () -- C:\Windows\SysWow64\ptj.exe
[2014/06/02 16:09:03 | 001,103,360 | ---- | C] () -- C:\Windows\SysWow64\cidfont.dll
[2014/06/02 16:09:00 | 004,369,408 | ---- | C] () -- C:\Windows\SysWow64\pdftk.exe
[2014/06/02 16:09:00 | 000,235,008 | ---- | C] () -- C:\Windows\SysWow64\office.exe
[2014/05/29 12:38:30 | 000,023,590 | ---- | C] () -- C:\Users\Krzysiek\Desktop\plan 72m2.jpg
[2014/05/28 15:37:28 | 000,002,074 | ---- | C] () -- C:\Users\Krzysiek\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2014/05/28 15:37:28 | 000,002,050 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2014/05/28 15:37:27 | 000,002,062 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2014/05/28 14:03:47 | 000,002,517 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2014/05/28 12:51:57 | 000,001,049 | ---- | C] () -- C:\Users\Krzysiek\Desktop\Dropbox.lnk
[2014/05/28 12:51:09 | 000,001,059 | ---- | C] () -- C:\Users\Krzysiek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2014/05/28 12:50:54 | 000,000,261 | ---- | C] () -- C:\Windows\wininit.ini
[2014/05/28 12:12:42 | 000,001,895 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2013/12/10 23:46:32 | 000,766,820 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/11/04 13:23:57 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2013/10/30 13:07:00 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2013/10/30 13:06:54 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2013/10/30 13:06:54 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013/10/30 13:06:54 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013/10/30 13:06:54 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2011/07/08 22:24:17 | 000,023,040 | ---- | C] () -- C:\Users\Krzysiek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/17 19:10:52 | 000,131,984 | ---- | C] () -- C:\ProgramData\FullRemove.exe
 
[color=#E56717]========== ZeroAccess Check ==========[/color]
 
[2009/07/14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/03/25 04:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/25 04:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
[color=#E56717]========== LOP Check ==========[/color]
 
[2013/10/25 16:31:54 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\AIMP
[2014/05/06 11:25:55 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\AIMP3
[2014/05/15 11:58:20 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\ARecEngine
[2012/02/19 19:26:57 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Artogon
[2011/08/27 23:23:31 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Ashampoo
[2013/10/23 16:13:53 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\AVAST Software
[2014/01/20 17:35:25 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\BitComet
[2013/01/01 15:03:12 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\CometPlayer
[2013/03/06 22:08:52 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\DAEMON Tools Lite
[2012/03/18 19:10:30 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\DDagiel
[2014/06/02 16:27:23 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\DigitalSites
[2012/02/19 18:45:13 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\DMCache
[2014/06/11 10:27:46 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Dropbox
[2014/06/11 10:27:38 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\DropboxMaster
[2014/06/02 16:21:41 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Frau-Mann BT
[2011/10/26 18:46:45 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Gadu-Gadu 10
[2013/01/08 22:08:46 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\GanymedeNet
[2012/05/18 21:44:34 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\gretl
[2011/07/07 11:55:38 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\IrfanView
[2011/10/17 23:14:36 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Leadertech
[2012/10/14 16:17:01 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Milestone
[2012/02/24 21:21:51 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\MusicNet
[2013/11/04 22:53:36 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Netscape
[2011/10/23 14:29:43 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\OpenFM
[2014/05/08 15:48:13 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\OpenOffice
[2011/09/03 18:56:50 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\OpenOffice.org
[2013/08/13 19:41:33 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Opera Software
[2013/10/12 21:12:21 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Oracle
[2011/07/03 15:16:49 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\PlayFirst
[2013/03/05 22:40:49 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\ProtectDISC
[2014/06/02 18:29:16 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\qone8
[2013/02/09 22:59:18 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Rovio
[2013/12/21 10:29:54 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Samsung
[2014/05/28 16:02:26 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Thunderbird
[2013/01/01 15:04:53 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\tigerplayer
[2012/05/07 14:28:50 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\TomTom
[2011/12/06 00:32:07 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\VshareComplete
[2012/02/19 16:30:40 | 000,000,000 | ---D | M] -- C:\Users\Krzysiek\AppData\Roaming\Windows Live Writer
 
[color=#E56717]========== Purity Check ==========[/color]
 
 
 
[color=#E56717]========== Alternate Data Streams ==========[/color]
 
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:93EB7685
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:4D066AD2
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:E36F5B57
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:E1F04E8D
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:1A60DE96
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:0B9176C0
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:798A3728

< End of report >
