Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL logfile created on: 2015-08-12 00:06:11 - Run 1
- OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Marta\Downloads
- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
- Internet Explorer (Version = 9.11.9600.17914)
- Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
- 2,75 Gb Total Physical Memory | 1,46 Gb Available Physical Memory | 53,25% Memory free
- 5,49 Gb Paging File | 3,88 Gb Available in Paging File | 70,64% Paging File free
- Paging file location(s): ?:\pagefile.sys [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
- Drive C: | 108,24 Gb Total Space | 70,89 Gb Free Space | 65,49% Space Free | Partition Type: NTFS
- Drive D: | 357,42 Gb Total Space | 357,32 Gb Free Space | 99,97% Space Free | Partition Type: NTFS
- Computer Name: MARTA-KOMPUTER | User Name: Marta | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: All users
- Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
- [color=#E56717]========== Processes (SafeList) ==========[/color]
- PRC - [2015-08-12 00:02:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Marta\Downloads\OTL (1).exe
- PRC - [2015-07-31 08:19:29 | 000,813,896 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
- PRC - [2015-07-15 21:47:39 | 000,245,576 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.28.1\GoogleCrashHandler.exe
- PRC - [2015-07-06 18:41:55 | 000,965,640 | ---- | M] (百度在线网络技术(北京)有限公司) -- C:\Program Files\Baidu\BaiduSd\4.0.0.6697\BaiduSdUpdate.exe
- PRC - [2015-06-18 08:39:50 | 001,133,880 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
- PRC - [2015-06-18 08:39:46 | 001,871,160 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
- PRC - [2015-06-18 08:39:34 | 006,554,424 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
- PRC - [2015-06-17 09:21:07 | 000,355,296 | ---- | M] (Tencent) -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\QQPCTray.exe
- PRC - [2015-06-17 09:21:07 | 000,297,608 | ---- | M] (Tencent) -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\QQPCRTP.exe
- PRC - [2015-06-08 08:03:22 | 000,805,896 | ---- | M] (百度在线网络技术(北京)有限公司) -- C:\Program Files\Baidu\BaiduSd\4.0.0.6697\BaiduSdSvc.exe
- PRC - [2015-06-08 08:03:06 | 000,064,008 | ---- | M] (百度在线网络技术(北京)有限公司) -- C:\Program Files\Common Files\Baidu\BaiduHips\1.2.0.751\BaiduHips.exe
- PRC - [2015-05-08 21:49:04 | 006,369,048 | ---- | M] (Piriform Ltd) -- C:\Program Files\CCleaner\CCleaner.exe
- PRC - [2015-05-07 23:21:06 | 000,406,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\GWX\GWX.exe
- PRC - [2013-05-11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
- PRC - [2012-11-23 04:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
- PRC - [2012-05-20 17:46:42 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
- PRC - [2010-01-13 22:04:26 | 000,372,736 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
- PRC - [2010-01-13 22:03:56 | 000,172,032 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
- [color=#E56717]========== Modules (No Company Name) ==========[/color]
- MOD - [2015-07-31 08:19:27 | 001,405,768 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\44.0.2403.130\libglesv2.dll
- MOD - [2015-07-31 08:19:27 | 000,081,224 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\44.0.2403.130\libegl.dll
- MOD - [2015-06-17 09:21:17 | 000,194,912 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\xImage.dll
- MOD - [2015-06-17 09:21:17 | 000,088,416 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\zlib.dll
- MOD - [2015-06-17 09:21:16 | 000,100,704 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\tinyxml.dll
- MOD - [2015-06-17 09:21:16 | 000,092,184 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\xGraphic32.dll
- MOD - [2015-06-17 09:21:14 | 000,481,632 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\sqlite.dll
- MOD - [2015-06-17 09:21:14 | 000,268,640 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\plugins\StartupMgr\SoftMon.dll
- MOD - [2015-06-17 09:21:14 | 000,203,104 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\QQFileFlt.dll
- MOD - [2015-06-17 09:21:10 | 000,285,024 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\libjpegturbo.dll
- MOD - [2015-06-17 09:21:10 | 000,158,048 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\libpng.dll
- MOD - [2015-06-17 09:21:10 | 000,137,568 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\libexpatw.dll
- MOD - [2015-06-17 09:21:10 | 000,076,128 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\MemDefrag.dll
- MOD - [2015-06-17 09:21:10 | 000,018,784 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\oDayProtect.dll
- MOD - [2015-06-17 09:21:10 | 000,014,176 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\jgIOStub.dll
- MOD - [2015-06-17 09:21:09 | 000,045,920 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\jgImage.dll
- MOD - [2015-06-17 09:21:08 | 000,342,040 | ---- | M] () -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\arkGraphic.dll
- MOD - [2015-06-08 08:02:08 | 000,404,360 | ---- | M] () -- C:\Program Files\Baidu\BaiduSd\4.0.0.6697\BDMCommon.dll
- MOD - [2015-06-08 08:02:08 | 000,154,504 | ---- | M] () -- C:\Program Files\Baidu\BaiduSd\4.0.0.6697\BDKVDownloadProtect.dll
- MOD - [2015-05-08 20:50:20 | 000,061,440 | ---- | M] () -- C:\Program Files\CCleaner\Lang\lang-1045.dll
- [color=#E56717]========== Services (SafeList) ==========[/color]
- SRV - File not found [Auto | Stopped] -- C:\Program Files\Rising\RSD\RsMgrSvc.exe -- (RsMgrSvc)
- SRV - [2015-06-26 13:02:56 | 000,235,696 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.11.149\McCHSvc.exe -- (McComponentHostService)
- SRV - [2015-06-19 20:13:19 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
- SRV - [2015-06-18 08:39:50 | 001,133,880 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
- SRV - [2015-06-18 08:39:46 | 001,871,160 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
- SRV - [2015-06-17 09:21:07 | 000,297,608 | ---- | M] (Tencent) [Auto | Running] -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\QQPCRTP.exe -- (QQPCRTP)
- SRV - [2015-06-08 08:03:22 | 000,805,896 | ---- | M] (百度在线网络技术(北京)有限公司) [Auto | Running] -- C:\Program Files\Baidu\BaiduSd\4.0.0.6697\BaiduSdSvc.exe -- (BDKVRTP)
- SRV - [2015-06-08 08:03:06 | 000,064,008 | ---- | M] (百度在线网络技术(北京)有限公司) [Auto | Running] -- C:\Program Files\Common Files\Baidu\BaiduHips\1.2.0.751\BaiduHips.exe -- (BaiduHips)
- SRV - [2015-05-25 20:01:45 | 000,853,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\diagtrack.dll -- (DiagTrack)
- SRV - [2013-06-25 09:42:49 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
- SRV - [2013-05-27 06:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
- SRV - [2013-05-11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
- SRV - [2010-01-13 22:03:56 | 000,172,032 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
- SRV - [2009-07-14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
- [color=#E56717]========== Driver Services (SafeList) ==========[/color]
- DRV - File not found [Kernel | Auto | Stopped] -- C:\Windows\system32\drivers\protreg.sys -- (rsdsys)
- DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Marta\AppData\Local\Temp\ehdrv.sys -- (eapihdrv)
- DRV - [2015-08-12 00:02:34 | 000,098,520 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
- DRV - [2015-08-12 00:01:56 | 000,030,392 | ---- | M] (Tencent) [Kernel | On_Demand | Running] -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\TS888.sys -- (TS888)
- DRV - [2015-08-05 23:14:20 | 000,135,816 | ---- | M] (Baidu) [Kernel | System | Running] -- C:\Windows\System32\drivers\BDDefense.sys -- (BDDefense)
- DRV - [2015-06-18 08:41:54 | 000,051,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mwac.sys -- (MBAMWebAccessControl)
- DRV - [2015-06-18 08:41:36 | 000,023,256 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
- DRV - [2015-06-17 09:21:17 | 000,204,920 | ---- | M] (电脑管家) [Kernel | System | Running] -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\TSKsp.sys -- (TSKSP)
- DRV - [2015-06-17 09:21:17 | 000,150,072 | ---- | M] (电脑管家) [File_System | System | Running] -- C:\Windows\System32\drivers\TFsFlt.sys -- (TFsFlt)
- DRV - [2015-06-17 09:21:17 | 000,138,552 | ---- | M] (Tencent Technology(Shenzhen) Company Limited) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\TAOKernel.sys -- (TAOKernelDriver)
- DRV - [2015-06-17 09:21:17 | 000,124,792 | ---- | M] (电脑管家) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TsFltMgr.sys -- (TsFltMgr)
- DRV - [2015-06-17 09:21:17 | 000,108,472 | ---- | M] (电脑管家) [File_System | Auto | Running] -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\QQSysMon.sys -- (QQSysMon)
- DRV - [2015-06-17 09:21:17 | 000,101,560 | ---- | M] (电脑管家) [Kernel | System | Running] -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\TSSysKit.sys -- (TSSysKit)
- DRV - [2015-06-17 09:21:17 | 000,077,016 | ---- | M] (Tencent) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\TAOAccelerator.sys -- (TAOAccelerator)
- DRV - [2015-06-17 09:21:17 | 000,062,392 | ---- | M] (Tencent) [Kernel | System | Running] -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\QMUdisk.sys -- (QMUdisk)
- DRV - [2015-06-17 09:21:17 | 000,049,464 | ---- | M] () [Kernel | System | Running] -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\QMIEProtect.sys -- (QMIEProtect)
- DRV - [2015-06-17 09:21:17 | 000,043,448 | ---- | M] (电脑管家) [Kernel | System | Running] -- C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\tscpm.sys -- (TSCPM)
- DRV - [2015-06-17 09:21:17 | 000,014,008 | ---- | M] (Tencent) [Kernel | System | Running] -- C:\Windows\System32\drivers\TSDefenseBt.sys -- (TSDefenseBt)
- DRV - [2015-06-08 08:03:24 | 000,169,672 | ---- | M] (Baidu) [Kernel | System | Running] -- C:\Windows\System32\drivers\bd0005.sys -- (bd0005)
- DRV - [2015-06-08 08:03:22 | 000,145,224 | ---- | M] (Baidu Technology) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\BDArKit.SYS -- (BDArKit)
- DRV - [2015-06-08 08:03:22 | 000,059,720 | ---- | M] (Baidu) [File_System | System | Running] -- C:\Windows\System32\drivers\bd0003.sys -- (bd0003)
- DRV - [2015-06-08 08:03:08 | 000,168,392 | ---- | M] (Baidu) [Kernel | System | Running] -- C:\Windows\System32\drivers\bd0002.sys -- (bd0002)
- DRV - [2015-06-08 08:03:08 | 000,086,344 | ---- | M] (Baidu) [Kernel | System | Running] -- C:\Windows\System32\drivers\bd0001.sys -- (bd0001)
- DRV - [2010-11-20 23:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
- DRV - [2010-11-20 23:29:03 | 000,130,432 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mpio.sys -- (mpio)
- DRV - [2010-11-20 23:29:03 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
- DRV - [2010-11-20 23:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
- DRV - [2010-01-28 09:33:30 | 000,100,352 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService)
- DRV - [2010-01-13 22:25:18 | 005,281,792 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atipmdag.sys -- (amdkmdag)
- DRV - [2010-01-13 21:10:44 | 000,149,504 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
- DRV - [2009-07-14 01:11:04 | 000,053,760 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\intelppm.sys -- (intelppm)
- DRV - [2009-05-05 09:00:28 | 000,014,392 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie)
- DRV - [2008-07-10 15:29:58 | 000,101,632 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
- [color=#E56717]========== Standard Registry (SafeList) ==========[/color]
- [color=#E56717]========== Internet Explorer ==========[/color]
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
- IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
- IE - HKLM\..\URLSearchHook: - No CLSID value found
- IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
- IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKU\S-1-5-21-117117196-327422274-3945288870-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
- IE - HKU\S-1-5-21-117117196-327422274-3945288870-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
- IE - HKU\S-1-5-21-117117196-327422274-3945288870-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
- IE - HKU\S-1-5-21-117117196-327422274-3945288870-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
- IE - HKU\S-1-5-21-117117196-327422274-3945288870-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
- [color=#E56717]========== FireFox ==========[/color]
- FF - prefs.js..browser.search.countryCode: "PL"
- FF - prefs.js..browser.search.highlightCount: 4
- FF - prefs.js..browser.search.isUS: false
- FF - prefs.js..browser.search.region: "PL"
- FF - prefs.js..browser.search.searchengine.desc: "this is my first firefox searchEngine"
- FF - prefs.js..browser.search.searchengine.ptid: "cor"
- FF - prefs.js..browser.search.searchengine.uid: "TOSHIBAXMQ01ABD050_62SWT1F1TXX62SWT1F1T"
- FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:38.0.5
- FF - user.js - File not found
- FF - HKLM\Software\MozillaPlugins\@baidu.com/BaiduExpert-npplugin: C:\Users\Marta\AppData\Roaming\Baidu\BDWebAdapter\3.0.331.0\npBDExNP.dll (百度在线网络技术(北京)有限公司)
- FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
- FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll ( Microsoft Corporation)
- FF - HKLM\Software\MozillaPlugins\@qq.com/npAndroidAssistant: C:\Program Files\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll File not found
- FF - HKLM\Software\MozillaPlugins\@rising.com.cn/nprising: File not found
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
- FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
- FF - HKCU\Software\MozillaPlugins\@rising.com.cn/nprising: File not found
- FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Marta\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 39.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
- FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 39.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
- [2014-08-31 21:12:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marta\AppData\Roaming\mozilla\Extensions
- [2015-08-11 23:19:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marta\AppData\Roaming\mozilla\Firefox\Profiles\jgj23zdr.default\extensions
- [2015-06-11 16:20:55 | 000,000,000 | ---D | M] (Search Enginer) -- C:\Users\Marta\AppData\Roaming\mozilla\Firefox\Profiles\jgj23zdr.default\extensions\1434032438_xpi
- [2015-06-11 16:20:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marta\AppData\Roaming\mozilla\Firefox\Profilesjgj23zdr.default\extensions
- [2015-06-11 16:20:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marta\AppData\Roaming\mozilla\Firefox\Profilesjgj23zdr.default\extensions\staged
- [2015-06-11 16:58:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
- [2015-08-11 23:42:07 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- [2015-07-15 00:01:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\updated\browser\extensions
- [2015-07-15 00:01:28 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\updated\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- [color=#E56717]========== Chrome ==========[/color]
- CHR - Extension: No name found = C:\Users\Marta\AppData\Local\Google\Chrome\User Data\Default\Extensions\deoeenbkoccjaefmmhpmlegngdjohdcm\0.1_0\
- CHR - Extension: No name found = C:\Users\Marta\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.2.0_0\
- CHR - Extension: No name found = C:\Users\Marta\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch\3.1_0\
- O1 HOSTS File: ([2015-07-23 20:17:33 | 000,000,854 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
- O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
- O2 - BHO: (WebGuardBHO) - {1B2639A9-EE25-4AE7-A2E3-B308F08125C4} - C:\Program Files\Baidu\BaiduSd\4.0.0.6697\WebGuardBHO.dll (百度在线网络技术(北京)有限公司)
- O4 - HKLM..\Run: [ QQPCTray] C:\Program Files\Tencent\QQPCMgr\10.9.16350.226\QQPCTray.exe (Tencent)
- O4 - HKU\S-1-5-21-117117196-327422274-3945288870-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
- O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
- O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
- O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
- O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE/3000 File not found
- O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll/105 File not found
- O13 - gopher Prefix: missing
- O15 - HKU\S-1-5-21-117117196-327422274-3945288870-1000\..Trusted Domains: baidu.com ([]http in Zaufane witryny)
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{35D1AF14-D59D-4ABD-B0F8-8DEC5E2E8AAB}: DhcpNameServer = 87.99.33.5 192.168.0.1
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9961D035-E347-4463-875F-6BFCC87231D5}: DhcpNameServer = 192.168.1.1
- O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
- O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
- O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
- O32 - HKLM CDRom: AutoRun - 1
- O32 - AutoRun File - [2009-06-10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
- O34 - HKLM BootExecute: (autocheck autochk *)
- O35 - HKLM\..comfile [open] -- "%1" %*
- O35 - HKLM\..exefile [open] -- "%1" %*
- O37 - HKLM\...com [@ = comfile] -- "%1" %*
- O37 - HKLM\...exe [@ = exefile] -- "%1" %*
- O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
- O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
- O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
- [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
- [2015-08-11 10:24:11 | 000,098,520 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
- [2015-08-11 10:24:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
- [2015-08-11 10:23:59 | 000,094,936 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamchameleon.sys
- [2015-08-11 10:23:58 | 000,051,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mwac.sys
- [2015-08-11 10:23:58 | 000,023,256 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
- [2015-08-11 10:23:58 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
- [2015-08-11 10:23:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
- [2015-08-11 09:18:06 | 000,000,000 | ---D | C] -- C:\Windows\pss
- [2015-08-11 09:15:20 | 000,077,016 | ---- | C] (Tencent) -- C:\Windows\System32\drivers\TAOAccelerator.sys
- [2015-08-11 09:15:19 | 000,138,552 | ---- | C] (Tencent Technology(Shenzhen) Company Limited) -- C:\Windows\System32\drivers\TAOKernel.sys
- [2015-08-11 09:15:10 | 000,030,392 | ---- | C] (Tencent) -- C:\Windows\System32\drivers\TS888.sys
- [2015-08-11 09:15:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Tencent
- [2015-08-11 09:14:00 | 000,000,000 | ---D | C] -- C:\ProgramData\TXQMPC
- [2015-08-07 17:19:41 | 000,000,000 | ---D | C] -- C:\Users\Marta\AppData\Roaming\Tencent
- [2015-07-29 13:16:46 | 000,000,000 | ---D | C] -- C:\Users\Marta\Desktop\Chorwacja 23- 30.07.15
- [2015-07-27 09:15:14 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
- [2015-07-27 09:05:37 | 002,383,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
- [2015-07-27 09:05:22 | 001,805,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authui.dll
- [2015-07-27 09:05:22 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msihnd.dll
- [2015-07-27 09:05:22 | 000,101,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
- [2015-07-27 09:05:22 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msimsg.dll
- [2015-07-27 09:05:14 | 000,299,008 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
- [2015-07-27 09:05:14 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
- [2015-07-27 09:05:14 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
- [2015-07-27 09:05:14 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dciman32.dll
- [2015-07-27 09:05:11 | 002,943,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
- [2015-07-27 09:05:11 | 000,566,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
- [2015-07-27 09:05:11 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
- [2015-07-27 09:05:11 | 000,093,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
- [2015-07-27 09:05:11 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinSetupUI.dll
- [2015-07-27 09:05:11 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
- [2015-07-27 09:05:11 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
- [2015-07-27 09:05:11 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
- [2015-07-27 09:05:11 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wu.upgrade.ps.dll
- [2015-07-27 09:05:06 | 000,932,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aeinv.dll
- [2015-07-27 09:05:06 | 000,924,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appraiser.dll
- [2015-07-27 09:05:06 | 000,628,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\invagent.dll
- [2015-07-27 09:05:06 | 000,587,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\generaltel.dll
- [2015-07-27 09:05:06 | 000,342,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\devinv.dll
- [2015-07-27 09:05:06 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aepdu.dll
- [2015-07-27 09:05:06 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\acmigration.dll
- [2015-07-27 09:05:06 | 000,015,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CompatTelRunner.exe
- [2015-07-27 09:05:00 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
- [2015-07-27 09:04:59 | 000,686,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adtschema.dll
- [2015-07-27 09:04:59 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msaudite.dll
- [2015-07-27 09:04:59 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msobjs.dll
- [2015-07-27 09:04:59 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\auditpol.exe
- [2015-07-27 09:04:59 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
- [2015-07-27 03:16:48 | 002,724,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
- [2015-07-27 03:16:47 | 000,479,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
- [2015-07-27 03:16:11 | 000,210,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cewmdm.dll
- [2015-07-27 03:07:08 | 004,520,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
- [2015-07-27 03:07:07 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9diag.dll
- [2015-07-27 03:06:49 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollector.exe
- [2015-07-27 03:06:49 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\JavaScriptCollectionAgent.dll
- [2015-07-27 03:06:49 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwproxystub.dll
- [2015-07-27 03:06:48 | 000,685,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
- [2015-07-27 03:06:48 | 000,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
- [2015-07-27 03:06:48 | 000,342,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
- [2015-07-27 03:06:48 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
- [2015-07-27 03:06:47 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
- [2015-07-27 03:06:47 | 000,689,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
- [2015-07-27 03:06:47 | 000,418,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
- [2015-07-27 03:06:47 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
- [2015-07-27 03:06:47 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
- [2015-07-27 03:06:45 | 002,052,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
- [2015-07-27 03:06:45 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
- [2015-07-27 03:06:45 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
- [2015-07-27 03:06:43 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollectorres.dll
- [2015-07-27 03:06:42 | 000,285,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
- [2015-07-27 03:06:39 | 000,341,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
- [2015-07-27 03:06:38 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll
- [2015-07-27 03:06:38 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MshtmlDac.dll
- [2015-07-23 20:17:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
- [2015-07-23 20:17:23 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan
- [2015-07-21 17:29:24 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
- [2015-07-21 00:07:15 | 000,000,000 | ---D | C] -- C:\Users\Marta\AppData\Local\Opera Software
- [2015-07-21 00:07:14 | 000,000,000 | ---D | C] -- C:\Users\Marta\AppData\Roaming\Opera Software
- [2015-07-21 00:06:23 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
- [2015-07-20 23:57:41 | 000,000,000 | ---D | C] -- C:\Users\Marta\Desktop\mama
- [2015-07-18 16:12:27 | 000,145,224 | ---- | C] (Baidu Technology) -- C:\Windows\System32\drivers\BDArKit.SYS
- [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
- [2015-08-12 00:09:42 | 000,028,352 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- [2015-08-12 00:09:42 | 000,028,352 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- [2015-08-12 00:02:34 | 000,098,520 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
- [2015-08-12 00:01:56 | 000,030,392 | ---- | M] (Tencent) -- C:\Windows\System32\drivers\TS888.sys
- [2015-08-12 00:01:49 | 000,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
- [2015-08-12 00:01:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
- [2015-08-12 00:01:04 | 2211,397,632 | -HS- | M] () -- C:\hiberfil.sys
- [2015-08-11 23:49:23 | 000,451,904 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
- [2015-08-11 10:52:46 | 000,021,747 | ---- | M] () -- C:\Users\Marta\Desktop\rachunki.ods
- [2015-08-11 10:24:03 | 000,001,060 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
- [2015-08-11 09:40:20 | 001,125,041 | ---- | M] () -- C:\Users\Marta\Desktop\baidu2.png
- [2015-08-11 09:21:05 | 000,362,140 | ---- | M] () -- C:\Users\Marta\Desktop\baidu jeden.png
- [2015-08-11 00:52:08 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-117117196-327422274-3945288870-1000Core.job
- [2015-08-06 20:45:55 | 000,002,135 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
- [2015-08-05 23:14:20 | 000,135,816 | ---- | M] (Baidu) -- C:\Windows\System32\drivers\BDDefense.sys
- [2015-07-31 08:22:37 | 000,050,937 | ---- | M] () -- C:\Users\Marta\Desktop\11822572_1612540952328705_7820695393318305985_n.jpg
- [2015-07-30 00:09:39 | 000,739,932 | ---- | M] () -- C:\Windows\System32\perfh015.dat
- [2015-07-30 00:09:39 | 000,653,724 | ---- | M] () -- C:\Windows\System32\perfh009.dat
- [2015-07-30 00:09:39 | 000,155,474 | ---- | M] () -- C:\Windows\System32\perfc015.dat
- [2015-07-30 00:09:39 | 000,121,596 | ---- | M] () -- C:\Windows\System32\perfc009.dat
- [2015-07-29 13:26:24 | 002,056,693 | ---- | M] () -- C:\Users\Marta\Desktop\DSC04463.JPG
- [2015-07-28 11:09:56 | 000,056,985 | ---- | M] () -- C:\Users\Marta\Desktop\10994043_1568038686789481_571214640996350745_n.jpg
- [2015-07-27 10:45:58 | 000,097,631 | ---- | M] () -- C:\Users\Marta\Desktop\20130630_022226.jpg
- [2015-07-27 06:31:56 | 002,173,029 | ---- | M] () -- C:\Users\Marta\Desktop\DSC04468.JPG
- [2015-07-27 02:00:50 | 002,262,083 | ---- | M] () -- C:\Users\Marta\Desktop\DSC04424.JPG
- [2015-07-25 22:47:10 | 001,669,113 | ---- | M] () -- C:\Users\Marta\Desktop\WP_20150725_014.jpg
- [2015-07-23 20:17:31 | 000,002,015 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
- [2015-07-21 20:54:18 | 001,201,755 | ---- | M] () -- C:\Users\Marta\Desktop\WP_20150721_019.jpg
- [2015-07-21 20:48:14 | 001,131,684 | ---- | M] () -- C:\Users\Marta\Desktop\WP_20150721_008.jpg
- [2015-07-21 17:29:27 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
- [2015-07-21 00:06:31 | 000,002,351 | ---- | M] () -- C:\Users\Marta\Desktop\Flvto YouTube Downloader.lnk
- [2015-07-15 21:47:56 | 000,001,036 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
- [2015-07-15 04:55:37 | 000,070,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
- [2015-07-15 04:55:35 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dciman32.dll
- [2015-07-15 04:55:32 | 000,034,304 | ---- | M] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
- [2015-07-15 03:52:35 | 000,299,008 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
- [color=#E56717]========== Files Created - No Company Name ==========[/color]
- [2015-08-11 23:49:05 | 000,451,904 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
- [2015-08-11 10:24:03 | 000,001,060 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
- [2015-08-11 09:40:20 | 001,125,041 | ---- | C] () -- C:\Users\Marta\Desktop\baidu2.png
- [2015-08-11 09:21:04 | 000,362,140 | ---- | C] () -- C:\Users\Marta\Desktop\baidu jeden.png
- [2015-07-31 08:22:32 | 000,050,937 | ---- | C] () -- C:\Users\Marta\Desktop\11822572_1612540952328705_7820695393318305985_n.jpg
- [2015-07-29 13:34:18 | 002,173,029 | ---- | C] () -- C:\Users\Marta\Desktop\DSC04468.JPG
- [2015-07-29 13:33:58 | 002,056,693 | ---- | C] () -- C:\Users\Marta\Desktop\DSC04463.JPG
- [2015-07-29 13:32:44 | 002,262,083 | ---- | C] () -- C:\Users\Marta\Desktop\DSC04424.JPG
- [2015-07-28 11:09:55 | 000,056,985 | ---- | C] () -- C:\Users\Marta\Desktop\10994043_1568038686789481_571214640996350745_n.jpg
- [2015-07-27 10:45:54 | 000,097,631 | ---- | C] () -- C:\Users\Marta\Desktop\20130630_022226.jpg
- [2015-07-27 09:40:30 | 001,669,113 | ---- | C] () -- C:\Users\Marta\Desktop\WP_20150725_014.jpg
- [2015-07-21 22:46:49 | 001,201,755 | ---- | C] () -- C:\Users\Marta\Desktop\WP_20150721_019.jpg
- [2015-07-21 22:46:08 | 001,131,684 | ---- | C] () -- C:\Users\Marta\Desktop\WP_20150721_008.jpg
- [2015-07-21 17:29:27 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
- [2015-07-21 00:06:31 | 000,002,186 | ---- | C] () -- C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flvto YouTube Downloader.lnk
- [2015-07-21 00:06:31 | 000,001,323 | ---- | C] () -- C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Uninstall Flvto YouTube Downloader.lnk
- [2015-06-17 09:54:03 | 000,182,328 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
- [2013-06-24 22:01:35 | 000,000,437 | ---- | C] () -- C:\Users\Marta\Desktop.lnk
- [color=#E56717]========== ZeroAccess Check ==========[/color]
- [2009-07-14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
- [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
- "" = %SystemRoot%\system32\shell32.dll -- [2015-02-13 07:26:18 | 012,875,264 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Apartment
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
- "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 23:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Free
- [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
- "" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
- "ThreadingModel" = Both
- [color=#E56717]========== LOP Check ==========[/color]
- [2015-08-05 09:16:14 | 000,000,000 | ---D | M] -- C:\Users\Marta\AppData\Roaming\Baidu
- [2015-06-17 17:12:18 | 000,000,000 | ---D | M] -- C:\Users\Marta\AppData\Roaming\BavMini
- [2015-03-26 12:22:55 | 000,000,000 | ---D | M] -- C:\Users\Marta\AppData\Roaming\FlvtoConverter
- [2014-07-04 14:32:45 | 000,000,000 | ---D | M] -- C:\Users\Marta\AppData\Roaming\iPlus
- [2015-06-12 10:35:56 | 000,000,000 | ---D | M] -- C:\Users\Marta\AppData\Roaming\OpenOffice
- [2015-07-21 00:07:14 | 000,000,000 | ---D | M] -- C:\Users\Marta\AppData\Roaming\Opera Software
- [2015-08-11 11:14:56 | 000,000,000 | ---D | M] -- C:\Users\Marta\AppData\Roaming\Tencent
- [color=#E56717]========== Purity Check ==========[/color]
- [color=#E56717]========== Files - Unicode (All) ==========[/color]
- (C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????) -- C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
- (C:\ProgramData\Microsoft\Windows\Start Menu\Programs\????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement