Remciol
Nowy
Liczba postów: 7
|
Komputer włącza się 10-20 minut.
Witam, mam komputer od 2 lat, od jakiegoś roku mam problem z rozruchem komputera. Gdy go włączam wszystkie procesy związane z włączaniem przebiegają sprawnie, następnie bardzo długo jest napis 'Zapraszamy' (5 minut), następnie pojawia się czarny ekran, tak przez 5 minut, a potem przechodzi do pulpitu, i zanim mi się pulpit załaduje to mija kolejne 5 minut, łącznie około 20tu minut. Nie wiem czym to jest spowodowane.
Specyfikacja mojego komputera:
Procesor: AMD Phenom II X4 965 3,40 Ghz
Ram: 8 GB
System 64 bitowy
Gdzieś na forum przeczytałem żeby zeskanować komputer programem RSIT w celu uzyskania informacji, log ten przedstawia się następująco:
Kod:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Remik at 2015-03-24 13: 16: 25
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 9 GB (13%) free of 70 GB
Total RAM: 8154 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13: 16: 29, on 2015-03-24
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C: \Program Files\AVAST Software\Avast\AvastUI.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
D: \Pobieranie z Chrome\RSIT.exe
C: \Program Files (x86)\trend micro\Remik.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about: blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http: //go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about: blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about: blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http: //isearch.omiga-plus.com/web/?type=ds&ts=1419445834&from=cor&uid=WDCXWD5002AALX-00J37A0_WD-WMAYUL16806268062&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http: //isearch.omiga-plus.com/web/?type=ds&ts=1419445834&from=cor&uid=WDCXWD5002AALX-00J37A0_WD-WMAYUL16806268062&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about: blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C: \Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
F2 - REG: system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C: \Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C: \PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C: \Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C: \Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocnik logowania za pomocą konta Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C: \Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C: \PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C: \Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C: \Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C: \Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C: \Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\RunOnce: [SymInstallStub] C: \Windows\SysWOW64\Adobe\Shockwave 12\SymInstallStub.exe /partnerid=adobe /productlist=nss /staging=false /delay=5 /launchedby=3
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C: \Windows\System32\mctadmin.exe (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C: \Windows\System32\mctadmin.exe (User 'USŁUGA SIECIOWA')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res: //C: \Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res: //D: \PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Wyślij &do programu OneNote - res: //D: \PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C: \Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C: \Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C: \Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C: \Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c: \program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c: \program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O15 - Trusted Zone: http: //*.aeriagames.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http: //fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C: \PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C: \Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C: \Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C: \Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C: \Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C: \Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C: \Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C: \Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: avast! Antivirus - AVAST Software - C: \Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C: \Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C: \Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C: \Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Usługa Google Update (gupdate) (gupdate) - Google Inc. - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Usługa Google Update (gupdatem) (gupdatem) - Google Inc. - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C: \Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C: \Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C: \Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C: \Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C: \Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C: \Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C: \Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C: \Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C: \Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C: \Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C: \Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C: \Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: UI Assistant Service - Unknown owner - C: \Program Files (x86)\blueconnect\AssistantServices.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C: \Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update Faster Light - Unknown owner - C: \Program Files (x86)\Faster Light\updateFasterLight.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C: \Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C: \Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C: \Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C: \Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C: \Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C: \Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10743 bytes
======Scheduled tasks folder======
C: \Windows\tasks\avast! Emergency Update.job - C: \Program Files\AVAST Software\Avast\AvastEmUpdate.exe
C: \Windows\tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job - C: \Windows\TEMP\{84A298C5-02DA-4EC7-8033-C230F3CCD2AD}.exe --uninstall=1
C: \Windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job - C: \Windows\TEMP\{C8FD8911-23EE-45D2-BED5-F458EDFFEBFD}.exe --uninstall=1
C: \Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3955949626-2034052818-4075005931-1000Core.job - C: \Users\Remik\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
C: \Windows\tasks\GoogleUpdateTaskMachineCore1cf8e0bc175db89.job - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C: \Windows\tasks\GoogleUpdateTaskMachineCore1cfed9721f4610b.job - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C: \Windows\tasks\GoogleUpdateTaskMachineCore1cfff394434aaa.job - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C: \Windows\tasks\GoogleUpdateTaskMachineCore1d040b46633b925.job - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C: \Windows\tasks\GoogleUpdateTaskMachineUA.job - C: \Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C: \Windows\tasks\MegaCloud Backup.job - C: \Users\Remik\AppData\Roaming\MegaCloudBackup\MegaCloudBackup.exe /scheduler
C: \Windows\tasks\Norton Product Installer.job - C: \Windows\SysWOW64\Adobe\Shockwave 12\SymInstallStub.exe /partnerid=adobe /productlist=nss /staging=false /delay=0 /launchedby=2
C: \Windows\tasks\Norton Product InstallerIdle.job - C: \Windows\SysWOW64\Adobe\Shockwave 12\SymInstallStub.exe /partnerid=adobe /productlist=nss /staging=false /delay=0 /launchedby=4
C: \Windows\tasks\Opera N.job - C: \Program Files (x86)\Opera\launcher.exe
C: \Windows\tasks\ROC_JAN2013_TB_rmv.job - C: \Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe --uninstall=1
C: \Windows\tasks\RunOW.job - C: \Program Files (x86)\Overwolf\OverwolfLauncher.exe
=========Mozilla firefox=========
ProfilePath - C: \Users\Remik\AppData\Roaming\Mozilla\Firefox\Profiles\edcpdnl2.default
"wrc@avast.com"=C: \Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.189 Plugin
"Path"=C: \Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C: \Windows\SysWOW64\Adobe\Director\np32dsw_1212152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C: \Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C: \Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C: \Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C: \PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C: \PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C: \Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@ncsoft.com/Plugin]
"Description"=NCSOFT login launcher module for FireFox and Chrome
"Path"=C: \Program Files (x86)\plaync\NCPlugin\npncllm3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C: \Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C: \Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=D: \Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
C: \Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C: \Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C: \Program Files (x86)\Mozilla Firefox\searchplugins\
allegro-pl.xml
fbc-pl.xml
google.xml
merlin-pl.xml
pwn-pl.xml
wikipedia-pl.xml
wp-pl.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C: \Pro [2013-09-02 6583664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C: \PRO [2013-09-02 6583664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C: \Pro [2013-09-02 6583664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C: \Pro [2013-09-02 6583664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocnik logowania za pomocą konta Microsoft - C: \Pro [2013-09-02 6583664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C: \PRO [2013-09-02 6583664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C: \Pro [2013-09-02 6583664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C: \Pro [2013-09-02 6583664]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C: \Pro [2013-09-02 6583664]
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C: \Program Files (x86)\AMD AVT\bin\kdbsync.exe aml []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SymInstallStub"=C: \Windows\SysWOW64\Adobe\Shockwave 12\SymInstallStub.exe [2014-06-24 358752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C: \PRO [2013-09-02 6583664]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRecentDocsNetHood"=1
"NoDriveTypeAutoRun"=145
""=
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.vorbis"=vorbis.acm
"VIDC.FPS1"=frapsvid.dll
======File associations======
.js - edit - C: \Windows\System32\Notepad.exe %1
.js - open - C: \Windows\System32\WScript.exe "%1" %*
.scr - open - C: \Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 month======
2015-03-24 13: 16: 26 ----D---- C: \Program Files (x86)\trend micro
2015-03-24 13: 16: 25 ----D---- C: \rsit
2015-03-24 11: 47: 26 ----ASH---- C: \pagefile.sys
2015-03-24 01: 21: 18 ----SHD---- C: \Config.Msi
2015-03-18 20: 26: 30 ----D---- C: \Users\Remik\AppData\Roaming\Dropbox
2015-03-17 08: 58: 23 ----D---- C: \Users\Remik\AppData\Roaming\Just Aion Launcher
2015-02-25 21: 27: 39 ----D---- C: \Users\Remik\AppData\Roaming\OpenOffice
======List of files/folders modified in the last 1 month======
2015-03-24 13: 16: 28 ----D---- C: \Windows\Temp
2015-03-24 13: 16: 26 ----RD---- C: \Program Files (x86)
2015-03-24 13: 15: 07 ----D---- C: \Windows\pss
2015-03-24 12: 18: 30 ----D---- C: \Users\Remik\AppData\Roaming\Curse Client
2015-03-24 11: 49: 42 ----SHD---- C: \System Volume Information
2015-03-24 11: 47: 19 ----D---- C: \Windows\SysWOW64
2015-03-24 11: 47: 19 ----D---- C: \Windows\System32
2015-03-24 01: 47: 37 ----D---- C: \lisa
2015-03-24 01: 47: 19 ----D---- C: \Users\Remik\AppData\Roaming\uTorrent
2015-03-24 01: 36: 12 ----D---- C: \Windows\Tasks
2015-03-24 01: 35: 44 ----D---- C: \Windows\winsxs
2015-03-24 01: 35: 08 ----D---- C: \Windows\inf
2015-03-24 01: 30: 06 ----HD---- C: \Program Files (x86)\InstallShield Installation Information
2015-03-24 01: 29: 23 ----SHD---- C: \Windows\Installer
2015-03-24 01: 29: 23 ----HD---- C: \ProgramData
2015-03-24 01: 29: 06 ----RD---- C: \Program Files
2015-03-24 01: 26: 57 ----RSD---- C: \Windows\assembly
2015-03-24 01: 25: 05 ----D---- C: \Program Files (x86)\Google
2015-03-24 01: 23: 19 ----D---- C: \Program Files (x86)\LooksBuilder
2015-03-24 01: 22: 25 ----D---- C: \Program Files (x86)\GameforgeLive
2015-03-24 01: 21: 26 ----D---- C: \ProgramData\Apple
2015-03-24 01: 21: 26 ----D---- C: \Program Files (x86)\Common Files\Apple
2015-03-24 01: 20: 42 ----D---- C: \ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-03-24 01: 19: 38 ----D---- C: \Program Files (x86)\Common Files\Adobe
2015-03-24 01: 13: 34 ----D---- C: \ProgramData\Samsung
2015-03-24 01: 13: 18 ----D---- C: \Windows
2015-03-24 01: 07: 26 ----D---- C: \Windows\Help
2015-03-21 20: 06: 55 ----D---- C: \Program Files (x86)\Battle.net
2015-03-20 22: 19: 30 ----D---- C: \Windows\Minidump
2015-02-26 17: 17: 42 ----SD---- C: \Users\Remik\AppData\Roaming\Microsoft
2015-02-25 21: 25: 44 ----RSD---- C: \Windows\Fonts
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amd_sata;amd_sata; C: \Windows\system32\DRIVERS\amd_sata.sys []
R0 amd_xata;amd_xata; C: \Windows\system32\DRIVERS\amd_xata.sys []
R0 aswRvrt;aswRvrt; C: \Windows\SysWOW64\drivers\aswRvrt.sys []
R0 aswVmm;aswVmm; C: \Windows\SysWOW64\drivers\aswVmm.sys []
R0 JRAID;JRAID; C: \Windows\system32\DRIVERS\jraid.sys []
R0 pciide;pciide; C: \Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C: \Windows\System32\drivers\rdyboost.sys []
R0 sptd;sptd; C: \Windows\System32\Drivers\sptd.sys []
R1 aswRdr;aswRdr; C: \Windows\System32\Drivers\aswrdr2.sys []
R1 aswSnx;aswSnx; C: \Windows\SysWOW64\drivers\aswSnx.sys []
R1 aswSP;aswSP; C: \Windows\SysWOW64\drivers\aswSP.sys []
R1 aswTdi;avast! Network Shield Support; C: \Windows\SysWOW64\drivers\aswTdi.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C: \Windows\system32\drivers\csc.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C: \Windows\system32\DRIVERS\dtsoftbus01.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C: \Windows\system32\DRIVERS\vwififlt.sys []
R2 AODDriver4.1;AODDriver4.1; \?\C: \Pro [2013-09-02 6583664]
R2 aswFsBlk;aswFsBlk; C: \Windows\SysWOW64\drivers\aswFsBlk.sys []
R2 aswMonFlt;aswMonFlt; \?\C: \Windows\system32\drivers\aswMonFlt.sys []
R3 amdiox64;AMD IO Driver; C: \Windows\system32\DRIVERS\amdiox64.sys []
R3 amdkmdag;amdkmdag; C: \Windows\system32\DRIVERS\atikmdag.sys []
R3 amdkmdap;amdkmdap; C: \Windows\system32\DRIVERS\atikmpag.sys []
R3 asmthub3;ASMedia USB3 Hub Service; C: \Windows\system32\DRIVERS\asmthub3.sys []
R3 asmtxhci;ASMEDIA XHCI Service; C: \Windows\system32\DRIVERS\asmtxhci.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C: \Windows\system32\drivers\AtihdW76.sys []
R3 hamachi;Hamachi Network Interface; C: \Windows\system32\DRIVERS\hamachi.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C: \Windows\system32\drivers\RTKVHD64.sys []
R3 RTL8167;Realtek 8167 NT Driver; C: \Windows\system32\DRIVERS\Rt64win7.sys []
S3 1394hub;1394 Enabled Hub; C: \Windows\System32\svchost.exe [2009-07-14 20992]
S3 ALSysIO;ALSysIO; \?\C: \Users\Remik\AppData\Local\Temp\ALSysIO64.sys []
S3 dk;dk; \?\D: \AeriaGames\DKOnline\avital\dkol64.sys []
S3 dmvsc;dmvsc; C: \Windows\system32\drivers\dmvsc.sys []
S3 EagleX64;EagleX64; \?\C: \Windows\system32\drivers\EagleX64.sys []
S3 massfilter;ZTE Mass Storage Filter Driver; C: \Windows\system32\drivers\massfilter.sys []
S3 netr7364;Sterownik karty RT73 USB Wireless LAN dla systemu Vista; C: \Windows\system32\DRIVERS\netr7364.sys []
S3 NLNdisMP;NLNdisMP; C: \Windows\system32\DRIVERS\nlndis.sys []
S3 NLNdisPT;NetLimiter Ndis Protocol Service; C: \Windows\system32\DRIVERS\nlndis.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C: \Windows\System32\drivers\rdpdr.sys []
S3 s3cap;s3cap; C: \Windows\system32\drivers\vms3cap.sys []
S3 slb;slb; \?\D: \AeriaGames\ScarletBlade\avital\scarlb64.sys []
S3 storvsc;storvsc; C: \Windows\system32\drivers\storvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C: \Windows\system32\drivers\tsusbflt.sys []
S3 TsUsbGD;Remote Desktop Generic USB Device; C: \Windows\system32\drivers\TsUsbGD.sys []
S3 usb_rndisx;Karta USB RNDIS; C: \Windows\system32\DRIVERS\usb8023x.sys []
S3 vmbus;vmbus; C: \Windows\system32\drivers\vmbus.sys []
S3 VMBusHID;VMBusHID; C: \Windows\system32\drivers\VMBusHID.sys []
S3 WinUsb;SAMSUNG Android USB Driver; C: \Windows\system32\DRIVERS\WinUsb.sys []
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C: \Windows\system32\DRIVERS\ZTEusbmdm6k.sys []
S3 ZTEusbnmea;ZTE NMEA Port; C: \Windows\system32\DRIVERS\ZTEusbnmea.sys []
S3 ZTEusbser6k;ZTE Diagnostic Port; C: \Windows\system32\DRIVERS\ZTEusbser6k.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C: \Windows\system32\atiesrxx.exe []
R2 AMD FUEL Service;AMD FUEL Service; C: \Pro [2013-09-02 6583664]
R2 Autodesk Content Service;Autodesk Content Service; C: \Pro [2013-09-02 6583664]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C: \Windows\System32\svchost.exe [2009-07-14 20992]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C: \Pro [2013-09-02 6583664]
R2 LMIGuardianSvc;LMIGuardianSvc; C: \Pro [2013-09-02 6583664]
R2 PnkBstrA;PnkBstrA; C: \Windows\system32\PnkBstrA.exe [2013-01-31 76888]
R2 UI Assistant Service;UI Assistant Service; C: \Pro [2013-09-02 6583664]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C: \Pro [2013-09-02 6583664]
R3 osppsvc;Office Software Protection Platform; C: \Pro [2013-09-02 6583664]
S2 Apple Mobile Device;Apple Mobile Device; C: \Pro [2013-09-02 6583664]
S2 avast! Antivirus;avast! Antivirus; C: \Pro [2013-09-02 6583664]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C: \Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C: \Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Usługa Google Update (gupdate); C: \Pro [2013-09-02 6583664]
S2 SkypeUpdate;Skype Updater; C: \Pro [2013-09-02 6583664]
S2 Update Faster Light;Update Faster Light; C: \Pro [2013-09-02 6583664]
S3 AppMgmt;@appmgmts.dll,-3250; C: \Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;„Usługa stanu ASP.NET; C: \Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C: \Pro [2013-09-02 6583664]
S3 gupdatem;Usługa Google Update (gupdatem); C: \Pro [2013-09-02 6583664]
S3 gusvc;Google Updater Service; C: \Pro [2013-09-02 6583664]
S3 IDriverT;InstallDriver Table Manager; C: \Pro [2013-09-02 6583664]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; D: \Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
S3 npggsvc;nProtect GameGuard Service; C: \Windows\system32\GameMon.des [2013-10-30 5284208]
S3 ose64;Office 64 Source Engine; C: \Pro [2013-09-02 6583664]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C: \Windows\System32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C: \Pro [2013-09-02 6583664]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C: \Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C: \Windows\System32\svchost.exe [2009-07-14 20992]
S4 NetMsmqActivator;@C: \Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C: \Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C: \Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C: \Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C: \Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C: \Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 WindowsMangerProtect;WindowsMangerProtect Service; C: \Pro [2013-09-02 6583664]
-----------------EOF-----------------
Przeprowadziłem skan programem Malwarebytes, wykryło mi 250 plików które usunąłem. Nie wiem czy to ma znaczenie, ale średnio raz na miesiąc mam blue screena, czasem częściej, czasem rzadziej. Generalnie na kompie mam porządek, nie mam zawalonych dysków. Proszę o pomoc!
|
Remciol
Nowy
Liczba postów: 7
|
RE: Komputer włącza się 10-20 minut.
Kod:
OTL logfile created on: 2015-04-09 21: 11: 21 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = D: \Pobieranie z Chrome
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
7,96 Gb Total Physical Memory | 3,84 Gb Available Physical Memory | 48,27% Memory free
15,92 Gb Paging File | 10,91 Gb Available in Paging File | 68,49% Paging File free
Paging file location(s): ?: \pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C: \Windows | %ProgramFiles% = C: \Program Files (x86)
Drive C: | 68,26 Gb Total Space | 7,67 Gb Free Space | 11,24% Space Free | Partition Type: NTFS
Drive D: | 397,40 Gb Total Space | 194,31 Gb Free Space | 48,89% Space Free | Partition Type: NTFS
Computer Name: AMD-DRAGON | User Name: Remik | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2015-04-09 21: 11: 11 | 000,602,112 | ---- | M] (OldTimer Tools) -- D: \Pobieranie z Chrome\OTL.exe
PRC - [2015-04-08 20: 31: 05 | 003,800,568 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_patcher\releases\0.0.0.27\deploy\LoLPatcher.exe
PRC - [2015-04-08 20: 30: 47 | 002,324,472 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_launcher\releases\0.0.0.243\deploy\LoLLauncher.exe
PRC - [2015-04-07 23: 35: 27 | 007,169,072 | ---- | M] (Blizzard Entertainment) -- C: \ProgramData\Battle.net\Agent\Agent.3918\Agent.exe
PRC - [2015-04-07 03: 40: 48 | 010,103,344 | ---- | M] (Blizzard Entertainment) -- C: \Program Files (x86)\Battle.net\Battle.net.5669\Battle.net.exe
PRC - [2015-03-31 20: 23: 00 | 011,632,176 | ---- | M] () -- D: \Program Files\WoW\Hearthstone\Hearthstone.exe
PRC - [2015-03-30 23: 07: 57 | 000,809,288 | ---- | M] (Google Inc.) -- C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2015-02-13 12: 05: 00 | 003,037,736 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\gfl_client.exe
PRC - [2014-01-03 19: 04: 00 | 000,074,752 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_air_client\releases\0.0.1.139\deploy\LolClient.exe
PRC - [2014-01-03 18: 40: 38 | 001,294,336 | ---- | M] () -- D: \Riot Games\League of Legends\rads\system\rads_user_kernel.exe
PRC - [2013-08-30 09: 47: 34 | 004,858,968 | ---- | M] (AVAST Software) -- C: \Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013-08-30 09: 47: 33 | 000,046,808 | ---- | M] (AVAST Software) -- C: \Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013-01-31 17: 20: 30 | 000,076,888 | ---- | M] () -- C: \Windows\SysWOW64\PnkBstrA.exe
PRC - [2012-01-31 10: 46: 56 | 000,019,232 | ---- | M] (Autodesk, Inc.) -- C: \Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
PRC - [2010-08-02 19: 05: 40 | 000,247,152 | ---- | M] () -- C: \Program Files (x86)\blueconnect\AssistantServices.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2015-04-08 20: 31: 05 | 003,800,568 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_patcher\releases\0.0.0.27\deploy\LoLPatcher.exe
MOD - [2015-04-08 20: 31: 05 | 001,672,184 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_patcher\releases\0.0.0.27\deploy\RiotLauncher.dll
MOD - [2015-04-08 20: 30: 47 | 002,324,472 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_launcher\releases\0.0.0.243\deploy\LoLLauncher.exe
MOD - [2015-04-07 03: 40: 47 | 000,908,288 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\platforms\qwindows.dll
MOD - [2015-04-07 03: 40: 47 | 000,739,840 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\libGLESv2.dll
MOD - [2015-04-07 03: 40: 47 | 000,054,272 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\qml\QtQuick\Layouts\qquicklayoutsplugin.dll
MOD - [2015-04-07 03: 40: 47 | 000,010,240 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\qml\QtQuick.2\qtquick2plugin.dll
MOD - [2015-04-07 03: 40: 47 | 000,010,240 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\qml\QtQml\Models.2\modelsplugin.dll
MOD - [2015-04-07 03: 40: 46 | 026,065,408 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\libcef.dll
MOD - [2015-04-07 03: 40: 46 | 000,312,832 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\imageformats\qtiff.dll
MOD - [2015-04-07 03: 40: 46 | 000,225,792 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\imageformats\qmng.dll
MOD - [2015-04-07 03: 40: 46 | 000,205,312 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\imageformats\qjpeg.dll
MOD - [2015-04-07 03: 40: 46 | 000,130,048 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\libEGL.dll
MOD - [2015-04-07 03: 40: 46 | 000,021,504 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\imageformats\qico.dll
MOD - [2015-04-07 03: 40: 46 | 000,020,992 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\imageformats\qgif.dll
MOD - [2015-04-07 03: 40: 46 | 000,015,872 | ---- | M] () -- C: \Program Files (x86)\Battle.net\Battle.net.5669\imageformats\qsvg.dll
MOD - [2015-03-31 20: 23: 05 | 002,122,752 | ---- | M] () -- D: \Program Files\WoW\Hearthstone\Hearthstone_Data\Plugins\Connect.dll
MOD - [2015-03-31 20: 23: 04 | 000,029,184 | ---- | M] () -- D: \Program Files\WoW\Hearthstone\Hearthstone_Data\Plugins\PlayErrors32.dll
MOD - [2015-03-31 20: 23: 02 | 002,102,784 | ---- | M] () -- D: \Program Files\WoW\Hearthstone\Hearthstone_Data\Mono\mono.dll
MOD - [2015-03-31 20: 23: 00 | 011,632,176 | ---- | M] () -- D: \Program Files\WoW\Hearthstone\Hearthstone.exe
MOD - [2015-03-30 23: 07: 56 | 014,974,280 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\PepperFlash\pepflashplayer.dll
MOD - [2015-03-30 23: 07: 56 | 009,279,304 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\pdf.dll
MOD - [2015-03-30 23: 07: 54 | 001,174,856 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\libglesv2.dll
MOD - [2015-03-30 23: 07: 54 | 000,080,200 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\libegl.dll
MOD - [2015-02-13 12: 05: 00 | 003,037,736 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\gfl_client.exe
MOD - [2015-02-10 12: 13: 38 | 000,141,312 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\qjson.dll
MOD - [2014-10-16 00: 07: 29 | 016,832,176 | ---- | M] () -- C: \Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll
MOD - [2014-02-14 14: 19: 00 | 005,686,669 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\libtorrent.dll
MOD - [2014-02-14 13: 55: 56 | 000,530,432 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\log4qt.dll
MOD - [2014-02-14 12: 32: 30 | 000,097,659 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\libboost_system-mgw47-mt-1_53.dll
MOD - [2014-02-13 13: 33: 58 | 001,765,301 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\libgcrypt-11.dll
MOD - [2014-02-13 13: 33: 58 | 000,126,959 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\libgpg-error-0.dll
MOD - [2014-02-13 13: 32: 58 | 000,863,744 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\libstdc++-6.dll
MOD - [2014-02-13 13: 32: 58 | 000,088,064 | ---- | M] () -- C: \Program Files (x86)\GameforgeLive\libgcc_s_sjlj-1.dll
MOD - [2014-01-03 19: 04: 00 | 000,074,752 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_air_client\releases\0.0.1.139\deploy\LolClient.exe
MOD - [2014-01-03 18: 52: 12 | 004,774,248 | ---- | M] () -- D: \Riot Games\League of Legends\rads\projects\lol_air_client\releases\0.0.1.139\deploy\Adobe AIR\Versions\1.0\Resources\WebKit.dll
MOD - [2014-01-03 18: 40: 38 | 001,294,336 | ---- | M] () -- D: \Riot Games\League of Legends\rads\system\rads_user_kernel.exe
MOD - [2010-01-30 02: 41: 12 | 004,254,560 | ---- | M] () -- C: \PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
[color=#E56717]========== Services (SafeList) ==========[/color]
SRV: [b]64bit: [/b] - [2013-08-30 09: 47: 33 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C: \Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV: [b]64bit: [/b] - [2012-10-21 14: 33: 13 | 001,432,400 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C: \Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV: [b]64bit: [/b] - [2012-04-06 04: 16: 02 | 000,236,544 | ---- | M] (AMD) [Auto | Running] -- C: \Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV: [b]64bit: [/b] - [2012-04-05 21: 57: 34 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C: \Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV: [b]64bit: [/b] - [2009-07-14 03: 41: 27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C: \Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV: [b]64bit: [/b] - [2009-07-14 03: 40: 01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C: \Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2015-03-30 15: 29: 00 | 002,490,216 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C: \Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2015-03-30 15: 25: 28 | 000,417,552 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C: \Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2015-03-24 06: 22: 24 | 000,836,288 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C: \Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2015-03-17 07: 14: 08 | 001,080,120 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- D: \Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013-10-30 18: 54: 36 | 005,284,208 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C: \Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2013-10-23 09: 15: 08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C: \Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013-01-31 17: 20: 30 | 000,076,888 | ---- | M] () [Auto | Running] -- C: \Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012-01-31 10: 46: 56 | 000,019,232 | ---- | M] (Autodesk, Inc.) [Auto | Running] -- C: \Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe -- (Autodesk Content Service)
SRV - [2010-08-02 19: 05: 40 | 000,247,152 | ---- | M] () [Auto | Running] -- C: \Program Files (x86)\blueconnect\AssistantServices.exe -- (UI Assistant Service)
SRV - [2010-03-25 10: 41: 00 | 051,456,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- D: \Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010-03-18 13: 16: 28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C: \Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-06-10 23: 23: 09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C: \Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV: [b]64bit: [/b] - [2015-03-17 07: 15: 38 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV: [b]64bit: [/b] - [2015-03-17 07: 15: 24 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C: \Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV: [b]64bit: [/b] - [2014-12-01 13: 15: 07 | 001,031,392 | ---- | M] (AVAST Software) [File_System | System | Running] -- C: \Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 10 | 000,378,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 10 | 000,204,880 | ---- | M] () [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 10 | 000,072,016 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 10 | 000,065,336 | ---- | M] () [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 10 | 000,064,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 09 | 000,080,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C: \Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV: [b]64bit: [/b] - [2013-08-30 09: 48: 09 | 000,033,400 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C: \Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV: [b]64bit: [/b] - [2012-12-28 13: 56: 21 | 000,564,824 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV: [b]64bit: [/b] - [2012-05-14 18: 54: 47 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV: [b]64bit: [/b] - [2012-04-06 07: 22: 40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV: [b]64bit: [/b] - [2012-04-06 03: 10: 44 | 000,343,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV: [b]64bit: [/b] - [2012-03-05 16: 04: 30 | 000,053,888 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C: \Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.1)
DRV: [b]64bit: [/b] - [2012-02-23 14: 32: 04 | 000,095,760 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV: [b]64bit: [/b] - [2011-03-21 15: 22: 06 | 000,452,200 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV: [b]64bit: [/b] - [2011-03-04 07: 46: 20 | 000,078,976 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV: [b]64bit: [/b] - [2011-03-04 07: 46: 20 | 000,038,528 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV: [b]64bit: [/b] - [2011-02-24 10: 30: 50 | 000,389,608 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\asmtxhci.sys -- (asmtxhci)
DRV: [b]64bit: [/b] - [2011-02-24 10: 30: 50 | 000,126,952 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\asmthub3.sys -- (asmthub3)
DRV: [b]64bit: [/b] - [2010-11-25 05: 27: 42 | 000,120,408 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\jraid.sys -- (JRAID)
DRV: [b]64bit: [/b] - [2010-11-21 05: 24: 33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV: [b]64bit: [/b] - [2010-11-21 05: 23: 48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV: [b]64bit: [/b] - [2010-11-21 05: 23: 47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV: [b]64bit: [/b] - [2010-11-21 05: 23: 47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV: [b]64bit: [/b] - [2010-11-21 05: 23: 47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV: [b]64bit: [/b] - [2010-11-21 05: 23: 47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV: [b]64bit: [/b] - [2010-03-09 13: 09: 06 | 000,119,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV: [b]64bit: [/b] - [2010-03-09 13: 09: 06 | 000,119,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV: [b]64bit: [/b] - [2010-03-09 13: 09: 06 | 000,119,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV: [b]64bit: [/b] - [2010-03-09 13: 09: 06 | 000,011,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\massfilter.sys -- (massfilter)
DRV: [b]64bit: [/b] - [2010-02-18 09: 18: 24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV: [b]64bit: [/b] - [2009-07-14 03: 52: 20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV: [b]64bit: [/b] - [2009-07-14 03: 48: 04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV: [b]64bit: [/b] - [2009-07-14 03: 47: 48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C: \Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV: [b]64bit: [/b] - [2009-07-14 03: 45: 55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV: [b]64bit: [/b] - [2009-07-14 03: 39: 46 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\svchost.exe -- (1394hub)
DRV: [b]64bit: [/b] - [2009-07-14 02: 09: 50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV: [b]64bit: [/b] - [2009-06-10 22: 35: 38 | 000,707,072 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\netr7364.sys -- (netr7364)
DRV: [b]64bit: [/b] - [2009-06-10 22: 34: 33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV: [b]64bit: [/b] - [2009-06-10 22: 34: 28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV: [b]64bit: [/b] - [2009-06-10 22: 34: 23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV: [b]64bit: [/b] - [2009-06-10 22: 31: 59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV: [b]64bit: [/b] - [2009-03-18 18: 35: 42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2009-07-14 03: 19: 10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C: \Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about: blank
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about: blank
IE: [b]64bit: [/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE: [b]64bit: [/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http: //www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about: blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C: \Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about: blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http: //www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about: blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about: blank
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http: //www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..extensions.enabledAddons: faststartff%40gmail.com: 4.3.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D: 18.0.1
FF - user.js - File not found
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C: \Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll File not found
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D: \PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C: \Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C: \Windows\SysWOW64\Adobe\Director\np32dsw_1212152.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C: \Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C: \Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C: \Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C: \PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C: \PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331: C: \Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@ncsoft.com/Plugin: C: \Program Files (x86)\plaync\NCPlugin\npncllm3.dll File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C: \Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C: \Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: D: \Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C: \Users\Remik\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C: \Program Files\AVAST Software\Avast\WebRep\FF [2013-09-03 00: 30: 15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C: \Program Files (x86)\Mozilla Firefox\components [2013-02-04 21: 07: 00 | 000,000,000 | ---D | M]
[2013-02-04 21: 07: 17 | 000,000,000 | ---D | M] (No name found) -- C: \Users\Remik\AppData\Roaming\mozilla\Extensions
[2012-05-19 16: 00: 28 | 000,000,000 | ---D | M] (No name found) -- C: \Users\Remik\AppData\Roaming\mozilla\Firefox\extensions
[2012-05-19 16: 00: 28 | 000,000,000 | ---D | M] (BitTorrentBar Community Toolbar) -- C: \Users\Remik\AppData\Roaming\mozilla\Firefox\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2014-12-24 22: 16: 55 | 000,000,000 | ---D | M] (No name found) -- C: \Users\Remik\AppData\Roaming\mozilla\Firefox\Profiles\edcpdnl2.default\extensions
[2013-02-04 21: 07: 00 | 000,000,000 | ---D | M] (No name found) -- C: \Program Files (x86)\mozilla firefox\extensions
[2013-01-16 22: 10: 14 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C: \Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013-01-17 02: 46: 35 | 000,002,767 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml
[2013-01-17 02: 46: 35 | 000,001,406 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml
[2013-01-17 02: 46: 35 | 000,000,917 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml
[2013-01-17 02: 46: 35 | 000,000,858 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml
[2013-01-17 02: 46: 35 | 000,001,183 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml
[2013-01-17 02: 46: 35 | 000,001,683 | ---- | M] () -- C: \Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml
[color=#E56717]========== Chrome ==========[/color]
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C: \Program Files (x86)\Google\Chrome\Application\41.0.2272.118\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = D: \Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C: \PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C: \PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C: \Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: No name found = C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.12_0\
CHR - Extension: No name found = C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Extensions\enjonnlehciedbcidabdglnnihcncbml\3.0.6_0\
CHR - Extension: No name found = C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi\1.264.7_0\
CHR - Extension: No name found = C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.22_0\
CHR - Extension: No name found = C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm\3.0.9_0\
CHR - Extension: No name found = C: \Users\Remik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\
O1 HOSTS File: ([2012-05-10 02: 04: 35 | 000,000,864 | ---- | M]) - C: \Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 validation.sls.microsoft.com
O2: [b]64bit: [/b] - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C: \Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2: [b]64bit: [/b] - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D: \Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2: [b]64bit: [/b] - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D: \Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C: \PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C: \Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C: \Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C: \PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C: \Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3: [b]64bit: [/b] - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C: \Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C: \Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [AMD AVT] C: \Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avast] C: \Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\RunOnce: [SymInstallStub] C: \Windows\SysWOW64\Adobe\Shockwave 12\SymInstallStub.exe (Symantec Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O8: [b]64bit: [/b] - Extra context menu item: Add to Google Photos Screensa&ver - res: //C: \Windows\system32\GPhotos.scr/200 File not found
O8: [b]64bit: [/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - D: \Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8: [b]64bit: [/b] - Extra context menu item: Wyślij &do programu OneNote - D: \Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C: \Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - D: \Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Wyślij &do programu OneNote - D: \Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9: [b]64bit: [/b] - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D: \Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9: [b]64bit: [/b] - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D: \Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9: [b]64bit: [/b] - Extra Button: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D: \Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9: [b]64bit: [/b] - Extra 'Tools' menuitem : &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D: \Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13[b]64bit: [/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: 4game.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: aeriagames.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: aeriagames.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([https] in Trusted sites)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http: //fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6D86E966-B3E1-461C-82CC-458074808C2F}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DDBC8F60-2C00-4B27-AE25-90C7E62A9F62}: DhcpNameServer = 192.168.1.1
O18: [b]64bit: [/b] - Protocol\Handler\skype4com - No CLSID value found
O18: [b]64bit: [/b] - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C: \PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20: [b]64bit: [/b] - HKLM Winlogon: Shell - (explorer.exe) - C: \Windows\explorer.exe (Microsoft Corporation)
O20: [b]64bit: [/b] - HKLM Winlogon: UserInit - (C: \Windows\system32\userinit.exe) - C: \Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C: \Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C: \Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21: [b]64bit: [/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28: [b]64bit: [/b] - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D: \Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C: \PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013-10-28 12: 34: 19 | 000,000,000 | ---D | M] - C: \Autodesk -- [ NTFS ]
O33 - MountPoints2\{224f0dc5-9de4-11e1-b097-c860000527e3}\Shell - "" = AutoRun
O33 - MountPoints2\{224f0dc5-9de4-11e1-b097-c860000527e3}\Shell\AutoRun\command - "" = F: \Setup.exe
O33 - MountPoints2\{3cff2020-d3f3-11e1-a05f-c860000527e3}\Shell - "" = AutoRun
O33 - MountPoints2\{3cff2020-d3f3-11e1-a05f-c860000527e3}\Shell\AutoRun\command - "" = F: \Install.exe
O33 - MountPoints2\{6552aa80-9a32-11e1-8704-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{6552aa80-9a32-11e1-8704-806e6f6e6963}\Shell\AutoRun\command - "" = E: \CheckID.exe
O33 - MountPoints2\{7a79fa2d-fc10-11e1-923b-c860000527e3}\Shell - "" = AutoRun
O33 - MountPoints2\{7a79fa2d-fc10-11e1-923b-c860000527e3}\Shell\AutoRun\command - "" = F: \AutoRun.exe
O33 - MountPoints2\{af856866-c466-11e2-b288-c860000527e3}\Shell - "" = AutoRun
O33 - MountPoints2\{af856866-c466-11e2-b288-c860000527e3}\Shell\AutoRun\command - "" = G: \LaunchU3.exe -a
O33 - MountPoints2\{cfcc9b63-3311-11e3-b7db-c860000527e3}\Shell - "" = AutoRun
O33 - MountPoints2\{cfcc9b63-3311-11e3-b7db-c860000527e3}\Shell\AutoRun\command - "" = G: \iLinker.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35: [b]64bit: [/b] - HKLM\..comfile [open] -- "%1" %*
O35: [b]64bit: [/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37: [b]64bit: [/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37: [b]64bit: [/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv: UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv: ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2015-04-09 02: 43: 38 | 000,000,000 | ---D | C] -- C: \AdwCleaner
[2015-03-31 16: 04: 14 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2015-03-31 16: 04: 10 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\LogMeIn Hamachi
[2015-03-24 23: 25: 09 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\XAMPP
[2015-03-24 23: 22: 14 | 000,000,000 | ---D | C] -- C: \xampp
[2015-03-24 14: 20: 17 | 000,136,408 | ---- | C] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015-03-24 14: 20: 09 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2015-03-24 14: 20: 07 | 000,107,736 | ---- | C] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mbamchameleon.sys
[2015-03-24 14: 20: 07 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mwac.sys
[2015-03-24 14: 20: 07 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mbam.sys
[2015-03-24 14: 20: 07 | 000,000,000 | ---D | C] -- C: \ProgramData\Malwarebytes
[2015-03-24 14: 16: 26 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\trend micro
[2015-03-24 14: 16: 25 | 000,000,000 | ---D | C] -- C: \rsit
[2015-03-18 21: 27: 46 | 000,000,000 | ---D | C] -- C: \Users\Remik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2015-03-18 21: 26: 30 | 000,000,000 | ---D | C] -- C: \Users\Remik\AppData\Roaming\Dropbox
[2015-03-17 09: 58: 23 | 000,000,000 | ---D | C] -- C: \Users\Remik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Just Aion Launcher
[2015-03-17 09: 58: 23 | 000,000,000 | ---D | C] -- C: \Users\Remik\AppData\Roaming\Just Aion Launcher
[1 C: \Windows\*.tmp files -> C: \Windows\*.tmp -> ]
[1 C: \Users\Remik\Desktop\*.tmp files -> C: \Users\Remik\Desktop\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2015-04-09 13: 57: 52 | 000,021,280 | -H-- | M] () -- C: \Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015-04-09 13: 57: 52 | 000,021,280 | -H-- | M] () -- C: \Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015-04-09 13: 56: 04 | 001,662,064 | ---- | M] () -- C: \Windows\SysNative\PerfStringBackup.INI
[2015-04-09 13: 56: 04 | 000,737,616 | ---- | M] () -- C: \Windows\SysNative\perfh015.dat
[2015-04-09 13: 56: 04 | 000,651,824 | ---- | M] () -- C: \Windows\SysNative\perfh009.dat
[2015-04-09 13: 56: 04 | 000,154,304 | ---- | M] () -- C: \Windows\SysNative\perfc015.dat
[2015-04-09 13: 56: 04 | 000,120,756 | ---- | M] () -- C: \Windows\SysNative\perfc009.dat
[2015-04-09 13: 50: 59 | 000,000,532 | ---- | M] () -- C: \Windows\tasks\Norton Product Installer.job
[2015-04-09 13: 37: 47 | 000,067,584 | --S- | M] () -- C: \Windows\bootstat.dat
[2015-04-09 13: 37: 31 | 2117,951,487 | -HS- | M] () -- C: \hiberfil.sys
[2015-04-09 02: 59: 20 | 000,002,194 | ---- | M] () -- C: \Users\Remik\Desktop\Norton Product Installer.lnk
[2015-04-09 00: 11: 07 | 000,000,898 | ---- | M] () -- C: \Users\Public\Desktop\Hearthstone.lnk
[2015-03-30 15: 25: 00 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) -- C: \Windows\SysNative\hamachi.sys
[2015-03-29 19: 01: 19 | 616,736,130 | ---- | M] () -- C: \Windows\MEMORY.DMP
[2015-03-24 14: 20: 35 | 000,136,408 | ---- | M] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015-03-24 02: 36: 12 | 000,000,540 | -H-- | M] () -- C: \Windows\tasks\Norton Product InstallerIdle.job
[2015-03-17 23: 47: 10 | 000,000,770 | ---- | M] () -- C: \Users\Remik\Documents\aionmemo_fa48d296.dat
[2015-03-17 23: 42: 55 | 000,648,704 | ---- | M] () -- C: \Users\Remik\Desktop\Just Aion Launcher.exe
[2015-03-17 07: 15: 38 | 000,063,704 | ---- | M] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mwac.sys
[2015-03-17 07: 15: 28 | 000,107,736 | ---- | M] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mbamchameleon.sys
[2015-03-17 07: 15: 24 | 000,025,816 | ---- | M] (Malwarebytes Corporation) -- C: \Windows\SysNative\drivers\mbam.sys
[2015-03-16 21: 24: 26 | 000,344,064 | ---- | M] () -- C: \Users\Remik\Documents\Database4.accdb
[2015-03-16 21: 21: 24 | 000,753,664 | ---- | M] () -- C: \Users\Remik\Documents\Database3.accdb
[2015-03-16 21: 19: 06 | 001,052,672 | ---- | M] () -- C: \Users\Remik\Documents\Database1.accdb
[1 C: \Windows\*.tmp files -> C: \Windows\*.tmp -> ]
[1 C: \Users\Remik\Desktop\*.tmp files -> C: \Users\Remik\Desktop\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2015-04-09 02: 59: 19 | 000,002,194 | ---- | C] () -- C: \Users\Remik\Desktop\Norton Product Installer.lnk
[2015-03-24 13: 02: 06 | 000,002,224 | ---- | C] () -- C: \Users\Remik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton Product Installer.lnk
[2015-03-17 09: 58: 17 | 000,648,704 | ---- | C] () -- C: \Users\Remik\Desktop\Just Aion Launcher.exe
[2015-03-16 21: 24: 23 | 000,344,064 | ---- | C] () -- C: \Users\Remik\Documents\Database4.accdb
[2015-03-16 20: 44: 02 | 000,753,664 | ---- | C] () -- C: \Users\Remik\Documents\Database3.accdb
[2014-06-19 20: 49: 31 | 000,421,888 | ---- | C] () -- C: \Windows\SysWow64\lame_enc.dll
[2014-01-03 22: 00: 01 | 000,007,594 | ---- | C] () -- C: \Users\Remik\AppData\Local\Resmon.ResmonCfg
[2013-05-03 00: 21: 19 | 000,001,313 | ---- | C] () -- C: \Users\Remik\trelis
[2013-05-03 00: 20: 54 | 000,000,111 | ---- | C] () -- C: \Users\Remik\dle trelis
[2013-02-04 23: 22: 57 | 000,000,600 | ---- | C] () -- C: \Users\Remik\PUTTY.RND
[2012-12-28 14: 27: 26 | 000,001,024 | ---- | C] () -- C: \Users\Remik\.rnd
[2012-10-10 18: 46: 32 | 000,000,037 | -HS- | C] () -- C: \Users\Remik\AppData\Local\1754111884ee9ab5277ca00.95260103
[2012-09-18 17: 52: 50 | 060,898,540 | ---- | C] () -- C: \Users\Remik\AppData\Roaming\.minecraft.rar
[2012-09-17 16: 56: 42 | 000,000,054 | ---- | C] () -- C: \Users\Remik\AppData\Roaming\updater.cfg
[2012-05-13 03: 00: 36 | 000,003,072 | ---- | C] () -- C: \Users\Remik\AppData\Local\file__0.localstorage
[color=#E56717]========== ZeroAccess Check ==========[/color]
[2009-07-14 06: 55: 00 | 000,000,227 | RHS- | M] () -- C: \Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C: \Windows\SysNative\shell32.dll -- [2010-11-21 05: 23: 55 | 014,174,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010-11-21 05: 24: 02 | 012,872,192 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C: \Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03: 40: 51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 05: 24: 25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C: \Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03: 41: 56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 3996 bytes -> C: \Users\Remik\Desktop\Just Aion Launcher.exe: config
@Alternate Data Stream - 231 bytes -> C: \ProgramData\TEMP: 6BE50C2B
@Alternate Data Stream - 1138 bytes -> C: \Users\Remik\Desktop\Just Aion Launcher.exe: status
< End of report >
Przy autostarcie włącza mi się tylko system operacyjny i avast, bo tego drugiego nie mogłem wyłączyć z autostartu. Zastanawiam się nad odinstalowaniem tego, i instalacją jakiegoś innego antywirusa, albo nawet żyć bez niego, tylko korzystać z komputera z głową
Nie mogę wrzucić extras, bo jest za dużo znaków w poście, a jak robię drugi to i tak pojawia mi się jak w jednym, wrzucę jak ktoś mi tutaj odpisze
(Ten post był ostatnio modyfikowany: 09.04.2015 20:27 przez Remciol.)
09.04.2015 20:24
|