Kod:
OTL logfile created on: 2015-03-08 01: 30: 14 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C: \Users\Armwrestling\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17207)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
4,00 Gb Total Physical Memory | 1,96 Gb Available Physical Memory | 49,01% Memory free
8,00 Gb Paging File | 5,85 Gb Available in Paging File | 73,11% Paging File free
Paging file location(s): ?: \pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C: \Windows | %ProgramFiles% = C: \Program Files (x86)
Drive C: | 80,00 Gb Total Space | 34,87 Gb Free Space | 43,59% Space Free | Partition Type: NTFS
Drive D: | 425,00 Gb Total Space | 243,35 Gb Free Space | 57,26% Space Free | Partition Type: NTFS
Drive E: | 426,41 Gb Total Space | 51,71 Gb Free Space | 12,13% Space Free | Partition Type: NTFS
Drive G: | 14,94 Gb Total Space | 7,99 Gb Free Space | 53,48% Space Free | Partition Type: NTFS
Computer Name: SHREK | User Name: Armwrestling | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2015-03-08 01: 28: 27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C: \Users\Armwrestling\Downloads\OTL.exe
PRC - [2015-02-07 14: 10: 41 | 001,880,752 | ---- | M] (Adobe Systems, Inc.) -- C: \Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
PRC - [2015-01-26 20: 05: 56 | 000,338,032 | ---- | M] (Mozilla Corporation) -- C: \Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2014-11-11 00: 25: 09 | 000,076,152 | ---- | M] () -- C: \Windows\SysWOW64\PnkBstrA.exe
PRC - [2008-11-18 12: 15: 30 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C: \Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2015-02-07 14: 10: 41 | 016,852,144 | ---- | M] () -- C: \Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
MOD - [2015-01-26 20: 05: 55 | 003,925,104 | ---- | M] () -- C: \Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2009-03-26 13: 46: 42 | 000,148,480 | ---- | M] () -- C: \Windows\SysWOW64\APOMngr.DLL
MOD - [2009-02-06 17: 52: 24 | 000,073,728 | ---- | M] () -- C: \Windows\SysWOW64\CmdRtr.DLL
[color=#E56717]========== Services (SafeList) ==========[/color]
SRV: [b]64bit: [/b] - [2014-07-11 10: 10: 12 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C: \Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV: [b]64bit: [/b] - [2014-07-10 17: 49: 37 | 001,616,896 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C: \Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV: [b]64bit: [/b] - [2014-07-10 17: 46: 13 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C: \Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV: [b]64bit: [/b] - [2009-07-14 02: 40: 01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C: \Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2015-01-28 22: 28: 45 | 001,910,128 | ---- | M] (Electronic Arts) [On_Demand | Stopped] -- C: \Program Files (x86)\Origin\OriginClientService.exe -- (Origin Client Service)
SRV - [2015-01-26 20: 05: 55 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C: \Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014-11-18 21: 23: 34 | 000,833,728 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C: \Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014-11-11 00: 25: 09 | 000,076,152 | ---- | M] () [Auto | Running] -- C: \Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2014-08-03 16: 02: 34 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C: \Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2014-07-02 18: 44: 41 | 000,411,936 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C: \Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2014-04-11 22: 08: 08 | 000,103,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C: \Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2014-04-03 19: 21: 48 | 000,315,008 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C: \Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2009-06-10 22: 23: 09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C: \Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008-11-18 12: 15: 30 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C: \Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV: [b]64bit: [/b] - [2014-09-03 16: 06: 37 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV: [b]64bit: [/b] - [2014-07-10 17: 44: 53 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV: [b]64bit: [/b] - [2014-07-10 17: 44: 53 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV: [b]64bit: [/b] - [2014-07-10 17: 38: 35 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C: \Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV: [b]64bit: [/b] - [2014-07-10 17: 36: 34 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV: [b]64bit: [/b] - [2014-07-10 17: 36: 34 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV: [b]64bit: [/b] - [2014-07-10 17: 33: 40 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV: [b]64bit: [/b] - [2014-07-10 17: 33: 40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV: [b]64bit: [/b] - [2014-05-02 15: 07: 06 | 000,672,104 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV: [b]64bit: [/b] - [2014-05-02 15: 07: 04 | 000,028,008 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\iaStorF.sys -- (iaStorF)
DRV: [b]64bit: [/b] - [2011-09-29 10: 30: 34 | 000,646,248 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV: [b]64bit: [/b] - [2010-11-21 04: 23: 48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV: [b]64bit: [/b] - [2010-11-21 04: 23: 48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV: [b]64bit: [/b] - [2010-11-21 04: 23: 48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV: [b]64bit: [/b] - [2010-11-21 04: 23: 47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV: [b]64bit: [/b] - [2009-12-30 09: 21: 26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
DRV: [b]64bit: [/b] - [2009-08-13 21: 10: 18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV: [b]64bit: [/b] - [2009-07-14 02: 52: 20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV: [b]64bit: [/b] - [2009-07-14 02: 48: 04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV: [b]64bit: [/b] - [2009-07-14 02: 45: 55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV: [b]64bit: [/b] - [2009-07-14 01: 01: 09 | 000,679,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\xnacc.sys -- (xnacc)
DRV: [b]64bit: [/b] - [2009-06-10 21: 34: 33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV: [b]64bit: [/b] - [2009-06-10 21: 34: 28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV: [b]64bit: [/b] - [2009-06-10 21: 34: 23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV: [b]64bit: [/b] - [2009-06-10 21: 31: 59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV: [b]64bit: [/b] - [2009-04-21 13: 12: 50 | 001,288,192 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\P17.sys -- (P17)
DRV - [2009-07-14 02: 19: 10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C: \Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http: //www.google.com
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE: [b]64bit: [/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE: [b]64bit: [/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http: //www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C: \Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http: //www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http: //www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http: //www.google.pl/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8C 0E 16 88 39 AF CF 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {9C833882-489A-442C-931E-55166DBD4AEC}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http: //www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{9C833882-489A-442C-931E-55166DBD4AEC}: "URL" = https: //www.google.com/search?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.search.hiddenOneOffs: "Allegro,Wikipedia (pl)"
FF - prefs.js..browser.search.highlightCount: 0
FF - prefs.js..browser.search.isUS: false
FF - prefs.js..browser.startup.homepage: "chrome: //fastdial/content/fastdial.html"
FF - prefs.js..extensions.enabledAddons: %7Bce7e73df-6a44-4028-8079-5927a588c948%7D: 1.1.2
FF - prefs.js..extensions.enabledAddons: fastdial%40telega.phpnet.us: 4.12
FF - prefs.js..extensions.enabledAddons: brief%40mozdev.org: 1.7.3
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D: 2.3
FF - prefs.js..extensions.enabledAddons: secureLogin%40blueimp.net: 1.0.6
FF - prefs.js..extensions.enabledAddons: %7B455D905A-D37C-4643-A9E2-F6FEFAA0424A%7D: 0.8.17
FF - prefs.js..extensions.enabledAddons: netvideohunter%40netvideohunter.com: 1.17
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D: 35.0.1
FF - user.js - File not found
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C: \Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll File not found
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.5.1: C: \Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\[url=http: //windows7forum.pl/microsoft-33418-u]Microsoft[/url].com/NpCtrl,version=1.0: C: \Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C: \Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.5.1: C: \Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.25.2: C: \Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2: C: \Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\[url=http: //windows7forum.pl/microsoft-33418-u]Microsoft[/url].com/NpCtrl,version=1.0: C: \Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C: \Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C: \Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C: \Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C: \Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Components: C: \Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Plugins: C: \Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Components: C: \Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Plugins: C: \Program Files (x86)\Mozilla Firefox\plugins
[2014-08-03 18: 00: 04 | 000,000,000 | ---D | M] (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\Extensions
[2015-03-07 20: 42: 46 | 000,000,000 | ---D | M] (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\Firefox\Profiles\ce8j0zs7.default\extensions
[2014-09-23 16: 18: 34 | 000,000,000 | ---D | M] (Fast Dial) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\Firefox\Profiles\ce8j0zs7.default\extensions\fastdial@telega.phpnet.us
[2015-03-06 16: 56: 35 | 000,000,000 | ---D | M] ("NetVideoHunter") -- C: \Users\Armwrestling\AppData\Roaming\mozilla\Firefox\Profiles\ce8j0zs7.default\extensions\netvideohunter@netvideohunter.com
[2014-08-03 21: 33: 27 | 000,000,000 | ---D | M] (LastPass) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\Firefox\Profiles\ce8j0zs7.default\extensions\support@lastpass.com
[2014-10-06 23: 04: 12 | 000,244,979 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\brief@mozdev.org.xpi
[2015-01-13 21: 26: 44 | 000,127,486 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\elemhidehelper@adblockplus.org.xpi
[2015-02-06 19: 10: 25 | 002,558,942 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\firebug@software.joehewitt.com.xpi
[2014-08-03 21: 33: 44 | 000,067,503 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\firefox-autofill@googlegroups.com.xpi
[2014-08-03 21: 32: 47 | 000,077,652 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\giorgio@gilestro.tk.xpi
[2015-01-28 19: 26: 37 | 000,060,432 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\jid0-G6461UajDjhNAwSukoedlkhD0XA@jetpack.xpi
[2014-08-03 21: 33: 47 | 000,667,234 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\jid1-cwbvBTE216jjpg@jetpack.xpi
[2015-02-18 20: 20: 32 | 000,020,158 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\jid1-HAV2inXAnQPIeA@jetpack.xpi
[2014-11-10 23: 38: 29 | 000,121,573 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\secureLogin@blueimp.net.xpi
[2014-08-03 21: 33: 34 | 000,001,552 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\unseen@tangrs.xpi
[2015-01-28 23: 50: 28 | 000,065,568 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}.xpi
[2015-02-26 21: 07: 48 | 000,120,672 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi
[2014-08-06 18: 02: 43 | 000,073,612 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\{ce7e73df-6a44-4028-8079-5927a588c948}.xpi
[2015-02-07 19: 14: 11 | 000,985,112 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014-10-29 22: 33: 24 | 000,304,000 | ---- | M] () (No name found) -- C: \Users\Armwrestling\AppData\Roaming\mozilla\firefox\profiles\ce8j0zs7.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2015-01-26 20: 05: 51 | 000,000,000 | ---D | M] (No name found) -- C: \Program Files (x86)\mozilla firefox\browser\extensions
[2015-01-26 20: 05: 56 | 000,000,000 | ---D | M] (Default) -- C: \Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[color=#E56717]========== Chrome ==========[/color]
CHR - default_search_provider: (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C: \Users\Armwrestling\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C: \Users\Armwrestling\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\
CHR - Extension: No name found = C: \Users\Armwrestling\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
CHR - Extension: No name found = C: \Users\Armwrestling\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C: \Users\Armwrestling\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo\3.10.3_0\
CHR - Extension: No name found = C: \Users\Armwrestling\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18.1_0\
CHR - Extension: No name found = C: \Users\Armwrestling\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\3.1.91_0\
CHR - Extension: No name found = C: \Users\Armwrestling\AppData\Local\Google\Chrome\User Data\Default\Extensions\iggnaiafdfnjpjanhfndcafhdiampgpb\2.1.5_0\
CHR - Extension: No name found = C: \Users\Armwrestling\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\
CHR - Extension: No name found = C: \Users\Armwrestling\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8_0\
O1 HOSTS File: ([2015-01-23 17: 16: 57 | 000,001,114 | ---- | M]) - C: \Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 mirillis.com
O1 - Hosts: 127.0.0.1 ns386119.ovh.net
O1 - Hosts: 127.0.0.1 mirillis.pl
O1 - Hosts: 127.0.0.1 www.mirillis.com
O1 - Hosts: 127.0.0.1 serwer2.paka-service.com
O1 - Hosts: 127.0.0.1 actiponrecorder.com
O1 - Hosts: 127.0.0.1 static.gadu-gadu.pl
O1 - Hosts: 127.0.0.1 adserver.gadu-gadu.pl
O1 - Hosts: 96.8.113.203 karachan.org
O1 - Hosts: 96.8.113.203 www.karachan.org
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C: \Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C: \Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [P17RunE] C: \Windows\SysWow64\P17RunE.dll (Creative Technology Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O13[b]64bit: [/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http: //ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http: //ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http: //ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 171.25.182.2 171.25.182.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{101361F9-115F-42AE-8034-2272B3AC5E23}: DhcpNameServer = 171.25.182.2 171.25.182.1
O20: [b]64bit: [/b] - HKLM Winlogon: Shell - (explorer.exe) - C: \Windows\explorer.exe (Microsoft Corporation)
O20: [b]64bit: [/b] - HKLM Winlogon: UserInit - (C: \Windows\system32\userinit.exe) - C: \Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C: \Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C: \Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21: [b]64bit: [/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk /k: I /k: J *)
O35: [b]64bit: [/b] - HKLM\..comfile [open] -- "%1" %*
O35: [b]64bit: [/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37: [b]64bit: [/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37: [b]64bit: [/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv: UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv: ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2015-03-07 20: 22: 01 | 000,000,000 | ---D | C] -- C: \AdwCleaner
[2015-03-07 15: 49: 59 | 000,000,000 | ---D | C] -- C: \FRST
[2015-03-06 17: 17: 29 | 000,000,000 | ---D | C] -- C: \Users\Armwrestling\AppData\Local\ElevatedDiagnostics
[2015-02-07 11: 17: 00 | 000,000,000 | ---D | C] -- C: \Users\Public\Documents\NativeFus_Log
[2015-02-07 11: 16: 55 | 000,000,000 | ---D | C] -- C: \Users\Armwrestling\Documents\SelfMV
[2015-02-07 11: 16: 53 | 000,000,000 | ---D | C] -- C: \Users\Armwrestling\Documents\samsung
[2015-02-07 11: 16: 51 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2015-02-07 11: 16: 46 | 000,000,000 | ---D | C] -- C: \Users\Armwrestling\AppData\Roaming\Samsung
[2015-02-07 11: 16: 45 | 000,144,664 | ---- | C] (MAPILab Ltd. & Add-in Express Ltd.) -- C: \Windows\SysWow64\secman.dll
[2015-02-07 11: 16: 39 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\Samsung
[1 C: \Windows\*.tmp files -> C: \Windows\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2015-03-08 01: 31: 49 | 000,026,576 | -H-- | M] () -- C: \Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015-03-08 01: 31: 49 | 000,026,576 | -H-- | M] () -- C: \Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015-03-08 01: 25: 00 | 000,001,048 | ---- | M] () -- C: \Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015-03-08 01: 23: 27 | 000,001,044 | ---- | M] () -- C: \Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015-03-08 01: 23: 18 | 000,067,584 | --S- | M] () -- C: \Windows\bootstat.dat
[2015-03-08 01: 23: 16 | 3220,033,536 | -HS- | M] () -- C: \hiberfil.sys
[2015-03-07 20: 46: 22 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015-03-07 13: 04: 31 | 001,668,226 | ---- | M] () -- C: \Windows\SysNative\PerfStringBackup.INI
[2015-03-07 13: 04: 31 | 000,739,694 | ---- | M] () -- C: \Windows\SysNative\perfh015.dat
[2015-03-07 13: 04: 31 | 000,653,526 | ---- | M] () -- C: \Windows\SysNative\perfh009.dat
[2015-03-07 13: 04: 31 | 000,155,268 | ---- | M] () -- C: \Windows\SysNative\perfc015.dat
[2015-03-07 13: 04: 31 | 000,121,398 | ---- | M] () -- C: \Windows\SysNative\perfc009.dat
[2015-02-07 14: 10: 41 | 000,701,616 | ---- | M] (Adobe Systems Incorporated) -- C: \Windows\SysWow64\FlashPlayerApp.exe
[2015-02-07 14: 10: 41 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C: \Windows\SysWow64\FlashPlayerCPLApp.cpl
[2015-02-07 11: 14: 13 | 000,137,456 | ---- | M] () -- C: \Users\Armwrestling\Desktop\Bez tytułu.png
[2015-02-07 10: 54: 08 | 000,000,000 | -H-- | M] () -- C: \Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[1 C: \Windows\*.tmp files -> C: \Windows\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2015-02-07 10: 54: 08 | 000,000,000 | -H-- | C] () -- C: \Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2014-11-11 00: 19: 59 | 000,280,904 | ---- | C] () -- C: \Windows\SysWow64\PnkBstrB.exe
[2014-11-11 00: 19: 58 | 000,076,152 | ---- | C] () -- C: \Windows\SysWow64\PnkBstrA.exe
[2014-11-11 00: 19: 57 | 002,580,552 | ---- | C] () -- C: \Windows\SysWow64\pbsvc.exe
[2014-08-21 23: 09: 19 | 000,641,024 | ---- | C] () -- C: \Windows\SysWow64\ficvdec_x86.dll
[2014-08-03 18: 14: 46 | 000,216,064 | ---- | C] ( ) -- C: \Windows\SysWow64\lagarith.dll
[2014-08-03 18: 14: 45 | 000,650,752 | ---- | C] () -- C: \Windows\SysWow64\xvidcore.dll
[2014-08-03 18: 14: 45 | 000,243,200 | ---- | C] () -- C: \Windows\SysWow64\xvidvfw.dll
[2014-08-03 18: 14: 44 | 000,218,200 | ---- | C] () -- C: \Windows\SysWow64\unrar.dll
[2014-08-03 18: 14: 42 | 000,112,640 | ---- | C] () -- C: \Windows\SysWow64\ff_vfw.dll
[2014-08-03 16: 02: 05 | 000,148,480 | ---- | C] () -- C: \Windows\SysWow64\APOMngr.DLL
[2014-08-03 16: 02: 05 | 000,073,728 | ---- | C] () -- C: \Windows\SysWow64\CmdRtr.DLL
[2014-07-11 09: 43: 05 | 001,606,314 | ---- | C] () -- C: \Windows\SysWow64\PerfStringBackup.INI
[color=#E56717]========== ZeroAccess Check ==========[/color]
[2009-07-14 05: 55: 00 | 000,000,227 | RHS- | M] () -- C: \Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C: \Windows\SysNative\shell32.dll -- [2014-07-10 17: 51: 43 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014-07-10 17: 51: 43 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C: \Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02: 40: 51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 04: 24: 25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C: \Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02: 41: 56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >
Wziąłem jeszcze przeczyściłem wszystko Wise Registry Cleanerem.