Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 2015-05-06 08:30:02 - Run 1
- OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Tomek\Desktop\Programy
- 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
- Internet Explorer (Version = 8.0.7601.17514)
- Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
- 7,96 Gb Total Physical Memory | 6,00 Gb Available Physical Memory | 75,33% Memory free
- 15,93 Gb Paging File | 13,26 Gb Available in Paging File | 83,26% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
- Drive C: | 195,09 Gb Total Space | 112,55 Gb Free Space | 57,69% Space Free | Partition Type: NTFS
- Drive D: | 736,33 Gb Total Space | 596,15 Gb Free Space | 80,96% Space Free | Partition Type: NTFS
- Computer Name: TOMEK-KOMPUTER | User Name: Tomek | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
- Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2015-05-06 08:24:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Tomek\Desktop\Programy\OTL.exe
- PRC - [2015-04-28 04:07:36 | 000,812,872 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- PRC - [2015-04-15 13:17:20 | 003,745,232 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2015\avgui.exe
- PRC - [2015-04-15 13:10:56 | 000,311,792 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
- PRC - [2015-04-14 01:44:34 | 002,889,408 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\Steam.exe
- PRC - [2015-04-14 01:44:34 | 001,543,872 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
- PRC - [2015-04-14 01:44:34 | 000,836,288 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
- PRC - [2015-01-10 00:27:57 | 000,410,768 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
- PRC - [2014-12-13 02:12:55 | 002,531,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
- PRC - [2014-12-13 02:12:52 | 001,701,520 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
- PRC - [2013-09-04 19:21:42 | 002,112,000 | ---- | M] () -- C:\Program Files (x86)\screenSHU\screenSHU.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2015-04-28 04:07:35 | 014,980,424 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\PepperFlash\pepflashplayer.dll
- MOD - [2015-04-28 04:07:34 | 001,252,680 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libglesv2.dll
- MOD - [2015-04-28 04:07:33 | 000,080,712 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libegl.dll
- MOD - [2015-04-14 01:44:46 | 002,371,776 | ---- | M] () -- C:\Program Files (x86)\Steam\video.dll
- MOD - [2015-04-14 01:44:34 | 000,702,656 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.DLL
- MOD - [2015-03-10 08:37:24 | 000,775,680 | ---- | M] () -- C:\Program Files (x86)\Steam\SDL2.dll
- MOD - [2015-02-25 03:58:34 | 034,641,288 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll
- MOD - [2014-12-02 02:29:50 | 005,002,752 | ---- | M] () -- C:\Program Files (x86)\Steam\v8.dll
- MOD - [2014-12-02 02:29:34 | 001,612,800 | ---- | M] () -- C:\Program Files (x86)\Steam\icui18n.dll
- MOD - [2014-12-02 02:29:34 | 001,210,368 | ---- | M] () -- C:\Program Files (x86)\Steam\icuuc.dll
- MOD - [2014-12-01 23:31:16 | 002,396,672 | ---- | M] () -- C:\Program Files (x86)\Steam\libavcodec-56.dll
- MOD - [2014-12-01 23:31:16 | 000,485,888 | ---- | M] () -- C:\Program Files (x86)\Steam\libswscale-3.dll
- MOD - [2014-12-01 23:31:16 | 000,479,744 | ---- | M] () -- C:\Program Files (x86)\Steam\libavformat-56.dll
- MOD - [2014-12-01 23:31:16 | 000,442,880 | ---- | M] () -- C:\Program Files (x86)\Steam\libavutil-54.dll
- MOD - [2014-12-01 23:31:16 | 000,332,800 | ---- | M] () -- C:\Program Files (x86)\Steam\libavresample-2.dll
- MOD - [2013-09-04 19:21:42 | 002,112,000 | ---- | M] () -- C:\Program Files (x86)\screenSHU\screenSHU.exe
- MOD - [2011-06-08 09:32:26 | 000,011,362 | ---- | M] () -- C:\Program Files (x86)\screenSHU\mingwm10.dll
- MOD - [2011-06-08 09:32:24 | 000,043,008 | ---- | M] () -- C:\Program Files (x86)\screenSHU\libgcc_s_dw2-1.dll
- [color=#E56717]========== Services (SafeList) ==========[/color]
- SRV:[b]64bit:[/b] - [2014-12-13 02:12:52 | 001,148,560 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService)
- SRV:[b]64bit:[/b] - [2014-12-13 02:12:51 | 019,823,248 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc)
- SRV:[b]64bit:[/b] - [2009-07-14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
- SRV - [2015-04-15 13:21:40 | 003,438,032 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe -- (AVGIDSAgent)
- SRV - [2015-04-15 13:16:38 | 001,517,480 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files (x86)\AVG\AVG2015\avgfws.exe -- (avgfws)
- SRV - [2015-04-15 13:10:56 | 000,311,792 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe -- (avgwd)
- SRV - [2015-04-14 01:44:34 | 000,836,288 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
- SRV - [2015-04-06 08:50:39 | 001,930,608 | ---- | M] (Electronic Arts) [On_Demand | Stopped] -- C:\Program Files (x86)\Origin\OriginClientService.exe -- (Origin Client Service)
- SRV - [2015-01-10 00:27:57 | 000,410,768 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
- SRV - [2014-12-13 02:12:52 | 001,701,520 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
- SRV - [2010-03-18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
- SRV - [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV:[b]64bit:[/b] - [2015-04-15 13:06:02 | 000,256,992 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
- DRV:[b]64bit:[/b] - [2015-04-09 14:11:14 | 000,284,128 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
- DRV:[b]64bit:[/b] - [2015-04-07 12:39:26 | 000,291,296 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
- DRV:[b]64bit:[/b] - [2015-04-03 09:34:12 | 000,137,184 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
- DRV:[b]64bit:[/b] - [2015-03-20 12:20:42 | 000,067,040 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgfwd6a.sys -- (Avgfwfd)
- DRV:[b]64bit:[/b] - [2015-03-20 12:18:18 | 000,040,928 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
- DRV:[b]64bit:[/b] - [2015-03-11 12:16:06 | 000,162,784 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
- DRV:[b]64bit:[/b] - [2015-03-11 12:13:36 | 000,344,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
- DRV:[b]64bit:[/b] - [2015-03-11 12:13:28 | 000,213,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
- DRV:[b]64bit:[/b] - [2015-01-13 06:15:56 | 000,195,728 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
- DRV:[b]64bit:[/b] - [2014-12-13 02:12:51 | 000,019,600 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
- DRV:[b]64bit:[/b] - [2014-11-22 12:46:30 | 000,038,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
- DRV:[b]64bit:[/b] - [2013-06-28 15:49:20 | 001,930,240 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athurx.sys -- (athur)
- DRV:[b]64bit:[/b] - [2010-11-21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
- DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
- DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
- DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
- DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
- DRV:[b]64bit:[/b] - [2010-10-26 12:08:08 | 000,406,632 | ---- | M] (Realtek ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
- DRV:[b]64bit:[/b] - [2009-08-21 02:52:10 | 000,079,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
- DRV:[b]64bit:[/b] - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
- DRV:[b]64bit:[/b] - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
- DRV:[b]64bit:[/b] - [2009-07-14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
- DRV:[b]64bit:[/b] - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
- DRV:[b]64bit:[/b] - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
- DRV:[b]64bit:[/b] - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
- DRV:[b]64bit:[/b] - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
- DRV:[b]64bit:[/b] - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
- DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKU\S-1-5-21-2717955575-1209764645-2442554728-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKU\S-1-5-21-2717955575-1209764645-2442554728-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
- IE - HKU\S-1-5-21-2717955575-1209764645-2442554728-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
- FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
- [color=#E56717]========== Chrome ==========[/color]
- CHR - plugin: Error reading preferences file
- CHR - Extension: No name found = C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
- CHR - Extension: No name found = C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
- CHR - Extension: No name found = C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\
- CHR - Extension: No name found = C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
- CHR - Extension: No name found = C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.12_0\
- CHR - Extension: No name found = C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\
- CHR - Extension: No name found = C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
- CHR - Extension: No name found = C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.22_0\
- CHR - Extension: No name found = C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik\2.2015.427.11450_0\
- CHR - Extension: No name found = C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\
- CHR - Extension: No name found = C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\opjonmehjfmkejjifhhknofdnacklmjk\2_0\
- CHR - Extension: No name found = C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
- O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
- O4:[b]64bit:[/b] - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
- O4:[b]64bit:[/b] - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
- O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2015\avgui.exe (AVG Technologies CZ, s.r.o.)
- O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
- O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
- O4 - HKU\S-1-5-21-2717955575-1209764645-2442554728-1000..\Run: [screenSHU] C:\Program Files (x86)\screenSHU\screenSHU.exe ()
- O4 - HKU\S-1-5-21-2717955575-1209764645-2442554728-1000..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
- O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
- O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
- O4 - Startup: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dying Light-RELOADED.lnk = File not found
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O13[b]64bit:[/b] - gopher Prefix: missing
- O13 - gopher Prefix: missing
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{43AC542A-95E0-4D4F-9C31-01C1BAFB6189}: DhcpNameServer = 192.168.0.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C69CC8DF-CC1B-40EF-948E-315CEC1DE15E}: DhcpNameServer = 192.168.0.1
- O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
- O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O32 - HKLM CDRom: AutoRun - 1
- O33 - MountPoints2\{f79bf944-b338-11e4-82fa-f09476a3f108}\Shell - "" = AutoRun
- O33 - MountPoints2\{f79bf944-b338-11e4-82fa-f09476a3f108}\Shell\AutoRun\command - "" = G:\LG_PC_Programs.exe
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
- O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
- O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
- O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
- O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2015-05-06 08:28:32 | 000,000,000 | ---D | C] -- C:\Users\Tomek\Desktop\Programy
- [2015-05-06 08:27:00 | 000,000,000 | ---D | C] -- C:\Users\Tomek\Desktop\FRST
- [2015-05-04 16:02:47 | 000,000,000 | ---D | C] -- C:\Users\Tomek\AppData\Roaming\OpenOffice
- [2015-05-04 16:02:36 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
- [2015-05-04 16:02:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenOffice 4
- [2015-05-04 15:59:32 | 000,000,000 | ---D | C] -- C:\Users\Tomek\Desktop\OpenOffice 4.1.1 (pl) Installation Files
- [2015-04-27 16:09:22 | 000,000,000 | ---D | C] -- C:\Users\Tomek\Desktop\101_FUJI
- [2015-04-26 08:37:44 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
- [2015-04-26 08:37:13 | 000,000,000 | ---D | C] -- C:\adb
- [2015-04-26 08:01:27 | 000,000,000 | ---D | C] -- C:\Users\Tomek\.android
- [2015-04-20 13:23:54 | 000,000,000 | ---D | C] -- C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
- [2015-04-20 13:23:53 | 000,000,000 | ---D | C] -- C:\Users\Tomek\Documents\VirtualDJ
- [2015-04-20 13:23:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VirtualDJ
- [2015-04-15 13:06:02 | 000,256,992 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys
- [2015-04-12 02:43:48 | 000,000,000 | ---D | C] -- C:\Users\Tomek\Desktop\Inari-2015
- [2015-04-11 01:01:18 | 000,000,000 | ---D | C] -- C:\Users\Tomek\AppData\Roaming\TS3Client
- [2015-04-11 01:01:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
- [2015-04-11 01:01:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamSpeak 3 Client
- [2015-04-09 14:11:14 | 000,284,128 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys
- [2015-04-08 15:30:20 | 000,000,000 | ---D | C] -- C:\Users\Tomek\AppData\Local\Blizzard
- [2015-04-07 23:09:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
- [2015-04-07 23:09:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hearthstone
- [2015-04-07 12:39:26 | 000,291,296 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgtdia.sys
- [2015-04-07 07:01:58 | 000,000,000 | ---D | C] -- C:\Users\Tomek\Documents\Heroes of the Storm
- [2015-04-07 02:15:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm
- [2015-04-06 14:50:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Heroes of the Storm
- [2015-04-06 14:48:07 | 000,000,000 | ---D | C] -- C:\Users\Tomek\AppData\Local\Blizzard Entertainment
- [2015-04-06 14:48:01 | 000,000,000 | ---D | C] -- C:\Users\Tomek\AppData\Roaming\Battle.net
- [2015-04-06 14:48:01 | 000,000,000 | ---D | C] -- C:\Users\Tomek\AppData\Local\Battle.net
- [2015-04-06 14:47:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
- [2015-04-06 14:47:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
- [2015-04-06 14:47:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Battle.net
- [2015-04-06 13:05:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Battle.net
- [2015-04-06 10:01:02 | 000,000,000 | ---D | C] -- C:\Users\Tomek\Documents\Electronic Arts
- [2015-04-06 09:13:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Sims 4
- [2015-04-06 09:13:44 | 000,447,752 | ---- | C] (On2.com) -- C:\Windows\SysWow64\vp6vfw.dll
- [2015-04-06 09:12:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2015-05-06 08:10:00 | 000,001,046 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
- [2015-05-06 08:06:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2015-05-06 06:23:46 | 000,028,128 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- [2015-05-06 06:23:46 | 000,028,128 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- [2015-05-06 06:17:50 | 000,001,042 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
- [2015-05-06 06:17:41 | 000,001,964 | ---- | M] () -- C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - HP Deskjet 3520 series.lnk
- [2015-05-06 06:16:32 | 2119,004,159 | -HS- | M] () -- C:\hiberfil.sys
- [2015-05-05 16:56:57 | 000,292,904 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
- [2015-05-04 16:02:36 | 000,001,142 | ---- | M] () -- C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk
- [2015-05-04 15:34:16 | 000,737,242 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat
- [2015-05-04 15:34:16 | 000,659,618 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
- [2015-05-04 15:34:16 | 000,153,930 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat
- [2015-05-04 15:34:16 | 000,128,166 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
- [2015-05-04 15:34:15 | 000,889,244 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
- [2015-05-02 13:12:20 | 000,002,189 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
- [2015-04-26 07:59:42 | 001,812,875 | ---- | M] () -- C:\Users\Tomek\Desktop\ioroot.zip
- [2015-04-26 07:47:45 | 000,578,239 | ---- | M] () -- C:\Users\Tomek\Desktop\Pattern_Password_disable.zip
- [2015-04-23 15:57:41 | 002,992,743 | ---- | M] () -- C:\Users\Tomek\Desktop\Sean&Bobo x A Billion Robots - Sick.mp3
- [2015-04-23 15:53:22 | 003,901,805 | ---- | M] () -- C:\Users\Tomek\Desktop\MOTi - Valencia (Original Mix).mp3
- [2015-04-23 15:48:10 | 003,437,454 | ---- | M] () -- C:\Users\Tomek\Desktop\POPEK MONSTER - DIRTY DIANA (MICHAEL JACKSON REMIX) - MATHEO PRODUCTION.mp3
- [2015-04-20 13:37:08 | 003,018,239 | ---- | M] () -- C:\Users\Tomek\Desktop\Gang Albanii - Królowie życia.mp3
- [2015-04-20 13:36:41 | 003,202,977 | ---- | M] () -- C:\Users\Tomek\Desktop\09. KRÓLEWNA ŚCIEŻKA [PROD. @KGR].mp3
- [2015-04-20 13:34:52 | 002,163,094 | ---- | M] () -- C:\Users\Tomek\Desktop\02. SPYTASZ OD JAK DAWNA [PROD. @THISISLOUIEKIETLON].mp3
- [2015-04-20 13:33:30 | 003,866,278 | ---- | M] () -- C:\Users\Tomek\Desktop\LANCER - BO TA MAŁA (OFFICIAL VIDEO) DISCO POLO NOWOŚĆ 2015 !!!.mp3
- [2015-04-20 13:24:26 | 003,145,716 | ---- | M] () -- C:\Users\Tomek\Desktop\Diadem - Dawaj maleńka, nie przestawaj (Official Video).mp3
- [2015-04-20 13:24:00 | 000,000,954 | ---- | M] () -- C:\Users\Tomek\Desktop\VirtualDJ 8.lnk
- [2015-04-19 14:02:32 | 000,000,995 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2015.lnk
- [2015-04-15 13:06:02 | 000,256,992 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys
- [2015-04-12 02:37:54 | 1099,800,512 | ---- | M] () -- C:\Users\Tomek\Desktop\Inari-2015.rar
- [2015-04-11 01:01:15 | 000,001,166 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
- [2015-04-09 14:11:14 | 000,284,128 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys
- [2015-04-07 23:09:40 | 000,001,185 | ---- | M] () -- C:\Users\Public\Desktop\Hearthstone.lnk
- [2015-04-07 12:39:26 | 000,291,296 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgtdia.sys
- [2015-04-07 02:15:25 | 000,001,211 | ---- | M] () -- C:\Users\Public\Desktop\Heroes of the Storm.lnk
- [2015-04-06 14:47:57 | 000,001,148 | ---- | M] () -- C:\Users\Public\Desktop\Battle.net.lnk
- [2015-04-06 12:54:15 | 000,055,831 | ---- | M] () -- C:\Users\Tomek\Desktop\tumblr_nkhahk2F481rpwm80o1_250.png
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2015-05-04 16:02:36 | 000,001,142 | ---- | C] () -- C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk
- [2015-05-04 14:55:38 | 733,791,351 | ---- | C] () -- C:\Users\Tomek\Desktop\Bog nie umarł - God's Not Dead (2014).avi
- [2015-04-26 07:55:26 | 001,812,875 | ---- | C] () -- C:\Users\Tomek\Desktop\ioroot.zip
- [2015-04-26 07:46:14 | 000,578,239 | ---- | C] () -- C:\Users\Tomek\Desktop\Pattern_Password_disable.zip
- [2015-04-23 15:57:17 | 002,992,743 | ---- | C] () -- C:\Users\Tomek\Desktop\Sean&Bobo x A Billion Robots - Sick.mp3
- [2015-04-23 15:53:09 | 003,901,805 | ---- | C] () -- C:\Users\Tomek\Desktop\MOTi - Valencia (Original Mix).mp3
- [2015-04-23 15:47:53 | 003,437,454 | ---- | C] () -- C:\Users\Tomek\Desktop\POPEK MONSTER - DIRTY DIANA (MICHAEL JACKSON REMIX) - MATHEO PRODUCTION.mp3
- [2015-04-20 13:36:51 | 003,018,239 | ---- | C] () -- C:\Users\Tomek\Desktop\Gang Albanii - Królowie życia.mp3
- [2015-04-20 13:35:51 | 003,202,977 | ---- | C] () -- C:\Users\Tomek\Desktop\09. KRÓLEWNA ŚCIEŻKA [PROD. @KGR].mp3
- [2015-04-20 13:34:18 | 002,163,094 | ---- | C] () -- C:\Users\Tomek\Desktop\02. SPYTASZ OD JAK DAWNA [PROD. @THISISLOUIEKIETLON].mp3
- [2015-04-20 13:33:09 | 003,866,278 | ---- | C] () -- C:\Users\Tomek\Desktop\LANCER - BO TA MAŁA (OFFICIAL VIDEO) DISCO POLO NOWOŚĆ 2015 !!!.mp3
- [2015-04-20 13:24:00 | 000,000,954 | ---- | C] () -- C:\Users\Tomek\Desktop\VirtualDJ 8.lnk
- [2015-04-20 13:23:49 | 003,145,716 | ---- | C] () -- C:\Users\Tomek\Desktop\Diadem - Dawaj maleńka, nie przestawaj (Official Video).mp3
- [2015-04-12 02:43:06 | 1099,800,512 | ---- | C] () -- C:\Users\Tomek\Desktop\Inari-2015.rar
- [2015-04-11 01:01:15 | 000,001,166 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
- [2015-04-07 23:09:40 | 000,001,185 | ---- | C] () -- C:\Users\Public\Desktop\Hearthstone.lnk
- [2015-04-07 02:15:25 | 000,001,211 | ---- | C] () -- C:\Users\Public\Desktop\Heroes of the Storm.lnk
- [2015-04-06 14:47:57 | 000,001,148 | ---- | C] () -- C:\Users\Public\Desktop\Battle.net.lnk
- [2015-04-06 12:54:14 | 000,055,831 | ---- | C] () -- C:\Users\Tomek\Desktop\tumblr_nkhahk2F481rpwm80o1_250.png
- [2015-03-20 10:51:52 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
- [2015-02-13 06:40:49 | 001,636,610 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
- [color=#E56717]========== ZeroAccess Check ==========[/color]
- [2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
- [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
- [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
- "" = C:\Windows\SysNative\shell32.dll -- [2010-11-21 05:23:55 | 014,174,208 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- "" = %SystemRoot%\system32\shell32.dll -- [2010-11-21 05:24:02 | 012,872,192 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
- "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
- "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Both
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
- [color=#E56717]========== LOP Check ==========[/color]
- [2015-03-14 13:25:52 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
- [2015-03-14 13:25:52 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
- [2015-04-24 20:40:38 | 000,000,000 | ---D | M] -- C:\Users\Haha xD\AppData\Roaming\AVG2015
- [2015-03-14 13:25:52 | 000,000,000 | ---D | M] -- C:\Users\Haha xD\AppData\Roaming\TuneUp Software
- [2015-02-13 07:38:59 | 000,000,000 | ---D | M] -- C:\Users\Tomek\AppData\Roaming\AVG2015
- [2015-04-06 14:49:04 | 000,000,000 | ---D | M] -- C:\Users\Tomek\AppData\Roaming\Battle.net
- [2015-02-14 00:20:55 | 000,000,000 | ---D | M] -- C:\Users\Tomek\AppData\Roaming\Electronic Arts
- [2015-02-14 03:34:34 | 000,000,000 | ---D | M] -- C:\Users\Tomek\AppData\Roaming\Need for Speed World
- [2015-05-04 16:02:47 | 000,000,000 | ---D | M] -- C:\Users\Tomek\AppData\Roaming\OpenOffice
- [2015-02-13 23:23:28 | 000,000,000 | ---D | M] -- C:\Users\Tomek\AppData\Roaming\Origin
- [2015-04-25 01:00:19 | 000,000,000 | ---D | M] -- C:\Users\Tomek\AppData\Roaming\TS3Client
- [color=#E56717]========== Purity Check ==========[/color]
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment