OTL logfile created on: 12.09.2013 12:11:10 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Siedlecki Kacper\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,95 Gb Total Physical Memory | 3,63 Gb Available Physical Memory | 45,65% Memory free 15,91 Gb Paging File | 9,94 Gb Available in Paging File | 62,52% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 1362,24 Gb Total Space | 1057,04 Gb Free Space | 77,60% Space Free | Partition Type: NTFS Drive Q: | 500,00 Gb Total Space | 485,31 Gb Free Space | 97,06% Space Free | Partition Type: NTFS Computer Name: SIEDLECKIKACPER | User Name: Siedlecki Kacper | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013.09.12 12:04:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Siedlecki Kacper\Downloads\OTL.exe PRC - [2013.09.11 13:09:01 | 009,580,520 | ---- | M] (TeamSpeak Systems GmbH) -- C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe PRC - [2013.09.06 22:55:40 | 000,565,672 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe PRC - [2013.09.06 22:55:38 | 001,811,368 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\Steam.exe PRC - [2013.09.03 10:40:43 | 000,084,024 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe PRC - [2013.09.03 10:40:35 | 000,347,192 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe PRC - [2013.09.03 10:40:35 | 000,108,088 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe PRC - [2013.09.02 22:35:59 | 000,829,392 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe PRC - [2013.08.15 11:09:30 | 000,606,040 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe PRC - [2013.07.26 12:11:20 | 002,847,696 | ---- | M] () -- C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe PRC - [2013.07.16 13:22:52 | 000,071,680 | ---- | M] (Razer USA Ltd) -- C:\ProgramData\Razer\SwitchBlade\RzSBHelper.exe PRC - [2013.07.12 16:31:41 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2013.07.09 11:18:22 | 001,932,800 | ---- | M] (Razer Inc.) -- C:\ProgramData\Razer\SwitchBlade\DeathStalker\Razer\1068AAE3-6299-4086-A7F6-0600F5F1D1E5\RzHome.exe PRC - [2013.06.17 10:32:32 | 001,984,000 | ---- | M] (Razer USA Ltd) -- C:\Program Files (x86)\Razer\SwitchBlade\RzAppManager.exe PRC - [2013.06.04 14:28:24 | 000,559,744 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxgame.exe PRC - [2013.04.18 04:38:48 | 000,218,112 | ---- | M] (Razer Inc) -- C:\ProgramData\Razer\SwitchBlade\Apps\Razer\945749A0-B4C2-4EB5-A93E-44DC10FDAF4D\RzWidget.exe PRC - [2013.01.16 22:25:39 | 003,093,624 | ---- | M] () -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe PRC - [2012.12.18 07:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012.08.28 09:07:58 | 001,260,032 | ---- | M] (Razer USA Ltd) -- C:\ProgramData\Razer\SwitchBlade\Apps\Razer\65BFE244-2354-4E41-ADC9-CCF6BE3B5F75\RzFPS\RzFPS.exe PRC - [2012.06.28 14:50:30 | 000,695,448 | ---- | M] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\BrowserCompanion\tcbhn.exe PRC - [2011.11.03 14:08:46 | 000,381,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2011.11.01 13:11:52 | 000,014,152 | ---- | M] (Alienware) -- C:\Programme\Alienware\Command Center\AWCCApplicationWatcher32.exe PRC - [2011.11.01 13:05:20 | 000,068,936 | ---- | M] (Alienware) -- C:\Programme\Alienware\Command Center\AlienwareAlienFXController.exe PRC - [2011.11.01 13:00:56 | 000,016,200 | ---- | M] (Alienware) -- C:\Programme\Alienware\Command Center\AlienFusionController.exe PRC - [2011.10.12 23:53:02 | 000,007,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe PRC - [2011.10.12 23:52:54 | 000,286,720 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorIcon.exe PRC - [2010.11.17 12:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe PRC - [2009.04.07 10:13:10 | 000,673,616 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe PRC - [2007.11.20 17:53:36 | 000,147,456 | ---- | M] (Razer USA Ltd.) -- C:\Program Files (x86)\Razer\Lycosa\razerhid.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2013.09.11 13:09:01 | 000,555,496 | ---- | M] () -- C:\Program Files (x86)\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll MOD - [2013.09.11 13:09:01 | 000,431,080 | ---- | M] () -- C:\Program Files (x86)\TeamSpeak 3 Client\plugins\clientquery_plugin.dll MOD - [2013.09.11 13:09:01 | 000,237,032 | ---- | M] () -- C:\Program Files (x86)\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win32.dll MOD - [2013.09.11 13:09:01 | 000,230,376 | ---- | M] () -- C:\Program Files (x86)\TeamSpeak 3 Client\soundbackends\directsound_win32.dll MOD - [2013.09.11 13:09:01 | 000,159,208 | ---- | M] () -- C:\Program Files (x86)\TeamSpeak 3 Client\plugins\appscanner_plugin.dll MOD - [2013.09.06 22:55:40 | 001,120,680 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.DLL MOD - [2013.09.02 22:35:56 | 000,410,576 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll MOD - [2013.09.02 22:35:55 | 013,599,184 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll MOD - [2013.09.02 22:35:54 | 004,053,456 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\pdf.dll MOD - [2013.09.02 22:35:04 | 000,709,584 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\libglesv2.dll MOD - [2013.09.02 22:35:03 | 000,099,792 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\libegl.dll MOD - [2013.09.02 22:35:01 | 001,604,560 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ffmpegsumo.dll MOD - [2013.08.22 00:18:28 | 000,687,104 | ---- | M] () -- C:\Program Files (x86)\Steam\SDL2.dll MOD - [2013.08.15 16:52:35 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\6c422db78c17838c3eb9f9fcc01ca63f\System.Management.ni.dll MOD - [2013.08.15 16:50:56 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\900d7d45b5a5498cbb97c36409f0afe1\System.Runtime.Remoting.ni.dll MOD - [2013.08.15 16:50:53 | 001,021,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\d82770dc4e5fee30ca8a7244bf7f613a\System.Runtime.DurableInstancing.ni.dll MOD - [2013.08.15 16:50:53 | 000,143,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\af7d7a2e47e0ac57b4f0fe5e0c1cda9a\SMDiagnostics.ni.dll MOD - [2013.08.15 16:50:52 | 002,647,552 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\420022aad3481c670eb86a4ca72d5b43\System.Runtime.Serialization.ni.dll MOD - [2013.08.15 16:50:51 | 000,393,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\c389533f1477363803e53dce01560d12\System.Xml.Linq.ni.dll MOD - [2013.08.15 16:50:50 | 001,801,728 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\4d277a8481c203a35c58bd277a2e71df\System.Xaml.ni.dll MOD - [2013.08.15 16:50:41 | 001,358,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\b17d6ac0dd3c231637c5a185036fa712\System.WorkflowServices.ni.dll MOD - [2013.08.15 16:50:25 | 001,707,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\46619ea8f875655e97d456ccbdaddcad\System.ServiceModel.Web.ni.dll MOD - [2013.08.15 16:49:14 | 001,084,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\d61ab89a936105f967dfff0295a76c6a\System.IdentityModel.ni.dll MOD - [2013.08.15 16:49:13 | 002,347,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\e043ad64456256a8ee5b934e227d9782\System.Runtime.Serialization.ni.dll MOD - [2013.08.15 16:49:12 | 017,477,632 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\706fd3714565f692fe19d3a023787fe8\System.ServiceModel.ni.dll MOD - [2013.08.15 16:49:12 | 000,256,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\1327ad2637aab17189c5461fbf30dc19\SMDiagnostics.ni.dll MOD - [2013.08.15 16:48:58 | 000,335,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\bd65ab415c009d987e5f0c59e9ae4a61\IAStorUtil.ni.dll MOD - [2013.08.15 09:51:40 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\40b43527d6fdbeb6e905a7b6123f3a42\System.Web.ni.dll MOD - [2013.08.15 09:51:10 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\28ea347a952d20959ac6ae02d7457d39\System.Windows.Forms.ni.dll MOD - [2013.08.15 09:51:05 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5aa44bce7933e4de09d935848f868a4b\System.Drawing.ni.dll MOD - [2013.08.15 09:50:41 | 005,464,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\09db78d6068543df01862a023aca785a\System.Xml.ni.dll MOD - [2013.08.15 09:50:38 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\8f7d83126a3cf283e5ac97f2d6d99f12\System.Configuration.ni.dll MOD - [2013.08.15 09:50:36 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5d22a30e587e2cac106b81fb351e7c08\System.ni.dll MOD - [2013.08.15 00:25:26 | 018,003,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\56a1feb800860a3bc5d8a45ee92a77ec\PresentationFramework.ni.dll MOD - [2013.08.15 00:25:18 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\001aeb860d7f2ba416e0fedc606fee98\PresentationCore.ni.dll MOD - [2013.08.15 00:25:16 | 006,817,280 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\8fefdc1ecedf91a104b084c7d8200bde\System.Data.ni.dll MOD - [2013.08.15 00:25:15 | 013,199,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\1a3b614a84244ea5fa4147b5cf007333\System.Windows.Forms.ni.dll MOD - [2013.08.15 00:25:13 | 007,070,720 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\c25ede0d0127774c504c4fc41d4de273\System.Core.ni.dll MOD - [2013.08.15 00:25:12 | 005,628,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\884bcbd22130ebeb1211bc7bcc3910c9\System.Xml.ni.dll MOD - [2013.08.15 00:25:12 | 003,858,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\b3ed31a444f444325ddb64b290ed2f1e\WindowsBase.ni.dll MOD - [2013.08.15 00:25:10 | 001,667,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\3a3fc0216674bdea0be809b305517c98\System.Drawing.ni.dll MOD - [2013.08.15 00:25:10 | 001,014,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\df40dab689e9d8febfb943599ba79f8d\System.Configuration.ni.dll MOD - [2013.08.15 00:25:10 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\228b114c79c5d9024bdb4cc580e32c09\PresentationFramework.Aero.ni.dll MOD - [2013.08.15 00:25:09 | 009,099,776 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\de853615c8224ba5d9aa9b76276c6d98\System.ni.dll MOD - [2013.08.07 21:31:06 | 020,625,832 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll MOD - [2013.07.26 12:11:20 | 002,847,696 | ---- | M] () -- C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe MOD - [2013.07.11 19:46:53 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgrSvcInt#\91055e1b69ebe2f880a59e5d66aa3941\IAStorDataMgrSvcInterfaces.ni.dll MOD - [2013.07.11 19:46:51 | 000,032,256 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\d125676428d42fdd364238bf6809c9ac\IAStorCommon.ni.dll MOD - [2013.07.11 09:55:31 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll MOD - [2013.07.11 02:12:22 | 000,145,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\cfbc74c91b44af85d10b272ae5c70d5a\System.Numerics.ni.dll MOD - [2013.07.11 02:12:21 | 014,416,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\cf58670896c5313b9b52f026f4455a5d\mscorlib.ni.dll MOD - [2013.06.15 01:49:12 | 001,100,800 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avcodec-53.dll MOD - [2013.06.15 01:49:12 | 000,192,000 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avformat-53.dll MOD - [2013.06.15 01:49:12 | 000,124,416 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avutil-51.dll MOD - [2013.06.04 14:29:00 | 000,965,248 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxworld.dll MOD - [2013.06.04 14:29:00 | 000,387,712 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxtool.dll MOD - [2013.06.04 14:28:52 | 001,022,592 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxterrain.dll MOD - [2013.06.04 14:28:52 | 000,334,464 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxspecial.dll MOD - [2013.06.04 14:28:50 | 001,489,536 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxsound.dll MOD - [2013.06.04 14:28:50 | 000,506,496 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxrender.dll MOD - [2013.06.04 14:28:46 | 000,244,352 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxnet2.dll MOD - [2013.06.04 14:28:46 | 000,203,392 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxpackage.dll MOD - [2013.06.04 14:28:42 | 000,387,712 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxmodeladv.dll MOD - [2013.06.04 14:28:40 | 001,768,064 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxgui.dll MOD - [2013.06.04 14:28:40 | 000,248,448 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxmodel.dll MOD - [2013.06.04 14:28:38 | 010,316,416 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxgamelogic.dll MOD - [2013.06.04 14:28:38 | 002,566,784 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxgnugo.dll MOD - [2013.06.04 14:28:32 | 001,137,280 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxcli.dll MOD - [2013.06.04 14:28:32 | 000,625,280 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxcore.dll MOD - [2013.06.04 14:28:24 | 000,559,744 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\fxgame.exe MOD - [2013.05.05 09:28:08 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Diagnostics.ServiceModelSink\3.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Diagnostics.ServiceModelSink.dll MOD - [2013.01.24 13:16:54 | 001,050,112 | ---- | M] () -- c:\progra~2\easylife\sprote~1.dll MOD - [2013.01.24 13:16:54 | 001,050,112 | ---- | M] () -- c:\progra~2\browse~2\sprote~1.dll MOD - [2013.01.16 22:25:39 | 003,093,624 | ---- | M] () -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe MOD - [2012.12.20 14:08:15 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration.resources\2.0.0.0_de_b03f5f7f11d50a3a\System.Configuration.resources.dll MOD - [2012.11.02 08:55:52 | 002,555,904 | ---- | M] () -- C:\Windows\SysWOW64\QQPYEngine.dll MOD - [2012.08.25 06:43:54 | 000,014,336 | ---- | M] () -- C:\ProgramData\Razer\SwitchBlade\Apps\Razer\65BFE244-2354-4E41-ADC9-CCF6BE3B5F75\RzFPS\FPSClient.dll MOD - [2012.08.07 15:22:56 | 000,575,728 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\httpinforequest.dll MOD - [2012.08.07 15:22:54 | 000,701,800 | ---- | M] () -- Q:\gPotato\Age of Wulin\bin\gpkitclt.dll MOD - [2012.06.28 14:50:30 | 000,695,448 | ---- | M] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\BrowserCompanion\tcbhn.exe MOD - [2012.01.17 06:18:55 | 000,315,392 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll MOD - [2010.11.25 00:44:02 | 000,375,280 | ---- | M] () -- c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll MOD - [2010.11.21 08:49:35 | 000,491,520 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.ServiceModel.resources\3.0.0.0_de_b77a5c561934e089\System.ServiceModel.resources.dll MOD - [2010.11.17 12:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe MOD - [2009.03.12 16:45:32 | 000,135,168 | ---- | M] () -- C:\PROGRA~2\EPSONS~1\EVENTM~1\ASSIST~1\SCANAS~1\SCANEN~1.DLL MOD - [2008.11.21 14:58:42 | 000,057,344 | ---- | M] () -- C:\PROGRA~2\EPSONS~1\EVENTM~1\ASSIST~1\SCANAS~1\SATWAIN.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2013.07.09 14:44:16 | 000,117,760 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\mmci32.exe -- (InfEefaultInstall) SRV:[b]64bit:[/b] - [2013.07.07 23:53:21 | 000,121,856 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\GFilterSvc.exe -- (GFilterSvc) SRV:[b]64bit:[/b] - [2007.11.08 01:11:22 | 004,466,688 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe -- (msvsmon90) SRV - [2013.09.06 22:55:40 | 000,565,672 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2013.09.03 10:40:43 | 000,084,024 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2013.09.03 10:40:35 | 000,108,088 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2013.08.28 23:57:43 | 000,009,216 | ---- | M] (Hi-Rez Studios) [Auto | Paused] -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService) SRV - [2013.07.26 12:11:20 | 002,847,696 | ---- | M] () [Auto | Running] -- C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe -- (BrowserDefendert) SRV - [2013.07.15 11:21:07 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013.07.12 16:31:41 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2013.07.07 23:53:19 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Users\Siedlecki Kacper\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe -- (SearchAnonymizer) SRV - [2013.07.04 10:23:17 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013.06.21 09:53:36 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2013.01.02 10:43:18 | 000,031,744 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe -- (SrvUpdater) SRV - [2012.12.18 07:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012.12.16 19:37:24 | 005,124,464 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc) SRV - [2012.07.17 16:14:44 | 002,292,480 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc) SRV - [2011.11.21 19:46:40 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Programme\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters) SRV - [2011.11.03 14:08:46 | 000,381,248 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2011.11.01 13:01:02 | 000,014,664 | ---- | M] (Alienware) [Auto | Running] -- C:\Programme\Alienware\Command Center\AlienFusionService.exe -- (AlienFusionService) SRV - [2011.10.12 23:53:02 | 000,007,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) SRV - [2010.12.13 15:37:16 | 000,194,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft LifeCam\MSCamS64.exe -- (MSCamSvc) SRV - [2010.11.25 07:34:18 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12) SRV - [2010.11.25 07:33:18 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM) SRV - [2010.03.18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010.02.19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2007.12.17 05:00:00 | 000,163,840 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE -- (EPSON_EB_RPCV4_01) SRV - [2007.01.11 05:02:00 | 000,126,464 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE -- (EPSON_PM_RPCV4_01) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2013.09.03 10:40:45 | 000,132,088 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb) DRV:[b]64bit:[/b] - [2013.09.03 10:40:45 | 000,105,344 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt) DRV:[b]64bit:[/b] - [2013.08.21 09:34:32 | 000,141,496 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzudd.sys -- (rzudd) DRV:[b]64bit:[/b] - [2013.08.20 10:41:46 | 000,021,176 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzhnet.sys -- (rzhnet) DRV:[b]64bit:[/b] - [2013.08.20 10:41:44 | 000,039,096 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzendpt.sys -- (rzendpt) DRV:[b]64bit:[/b] - [2013.04.25 03:24:02 | 000,455,992 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:[b]64bit:[/b] - [2013.03.27 13:41:51 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr) DRV:[b]64bit:[/b] - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2012.01.17 06:19:00 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2012.01.17 06:19:00 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2011.11.15 11:14:02 | 000,126,464 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RzSynapse.sys -- (RzSynapse) DRV:[b]64bit:[/b] - [2011.11.03 04:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:[b]64bit:[/b] - [2011.10.13 00:44:02 | 000,023,832 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF) DRV:[b]64bit:[/b] - [2011.10.13 00:44:00 | 000,562,456 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA) DRV:[b]64bit:[/b] - [2011.09.22 06:49:56 | 000,056,600 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:[b]64bit:[/b] - [2011.09.15 21:15:00 | 000,216,064 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rusb3xhc.sys -- (rusb3xhc) DRV:[b]64bit:[/b] - [2011.09.15 21:14:58 | 000,100,352 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rusb3hub.sys -- (rusb3hub) DRV:[b]64bit:[/b] - [2011.07.08 01:21:28 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:[b]64bit:[/b] - [2011.06.11 01:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2011.05.04 14:24:14 | 000,007,680 | ---- | M] (Dell/Alienware) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mio.sys -- (mio) DRV:[b]64bit:[/b] - [2010.12.13 15:37:18 | 000,036,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nx6000.sys -- (MSHUSBVideo) DRV:[b]64bit:[/b] - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{01bd49d7-c76b-4310-8beb-14d7e5f322c6}: "URL" = http://search.easylifeapp.com/?q={searchTerms}&pid=356&src=ie2&r=2013/03/05&hid=3642042442&lg=EN&cc=DE IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.de/alienware IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=121845&babsrc=HP_ss_din2g&mntrId=D6E6F04DA2DE55B6 IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..\SearchScopes\{01bd49d7-c76b-4310-8beb-14d7e5f322c6}: "URL" = http://search.easylifeapp.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E656173796C6966656170702E636F6D2F3F713D7B7365617263685465726D737D267069643D333536267372633D69653226723D323031332F30332F3035266869643D33363432303432343432266C673D454E2663633D4445&st={searchTerms}&clid=8ee5688e-3218-44aa-8b1a-42101b50b5b6&pid=freewarede&k=0 IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com.anonymize-me.de/?anonymto=687474703A2F2F7365617263682E626162796C6F6E2E636F6D2F3F713D7B7365617263685465726D737D2661666649443D313231383435266261627372633D53505F73735F64696E3267266D6E747249643D44364536463034444132444535354236&st={searchTerms}&clid=8ee5688e-3218-44aa-8b1a-42101b50b5b6&pid=freewarede&k=0 IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..\SearchScopes\{114E4637-307C-44D3-81FB-9D8A1F249C76}: "URL" = http://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=8ee5688e-3218-44aa-8b1a-42101b50b5b6&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..\SearchScopes\{2811F386-29A1-4623-8A46-FC9AB9A77128}: "URL" = http://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=8ee5688e-3218-44aa-8b1a-42101b50b5b6&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..\SearchScopes\{79B292D1-DFD4-42E8-A046-066961932879}: "URL" = http://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=8ee5688e-3218-44aa-8b1a-42101b50b5b6&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..\SearchScopes\{ACCB2940-834B-4F17-BB2D-3D7A1C3D0E10}: "URL" = http://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=8ee5688e-3218-44aa-8b1a-42101b50b5b6&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..\SearchScopes\{BF241C73-9FD1-4819-894A-579808CD8F8D}: "URL" = http://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=8ee5688e-3218-44aa-8b1a-42101b50b5b6&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..\SearchScopes\{D1019FE0-E767-4B7E-9B6E-47A14C15668F}: "URL" = http://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=8ee5688e-3218-44aa-8b1a-42101b50b5b6&pid=freewarede&mode=bounce&k=0 IE - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename,S: S", "EasyLife" FF - prefs.js..browser.search.defaultthis.engineName: "" FF - prefs.js..browser.search.defaulturl: "http://search.easylifeapp.com/?pid=356&src=ff2&r=2013/03/05&hid=3642042442&lg=EN&cc=DE&l=1&q=" FF - prefs.js..browser.search.order.1: "" FF - prefs.js..browser.search.order.1,S: S", "EasyLife" FF - prefs.js..browser.search.selectedEngine: "Delta Search" FF - prefs.js..browser.search.selectedEngine,S: S", "EasyLife" FF - prefs.js..browser.startup.homepage: "https://www.google.de/webhp?hl=de&complete=0" FF - prefs.js..extensions.enabledAddons: gmailnoads%40mywebber.com:3.9.1 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0 FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "EasyLife" FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "EasyLife" FF - prefs.js..browser.startup.homepage: "http://search.easylifeapp.com/?pid=356&src=ff1&r=2013/03/05&hid=3642042442&lg=EN&cc=DE" FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.easylifeapp.com/?pid=356&src=ff2&r=2013/03/05&hid=3642042442&lg=EN&cc=DE&l=1&q=" FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\autolyrics@man-soft.net: C:\Program Files (x86)\AutoLyrics\FF\ [2013.04.27 08:28:14 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Users\Siedlecki Kacper\AppData\Roaming\Mozilla\Firefox\Profiles\ar9a3nc5.default\extensions\firejump@firejump.net FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.01.16 21:08:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\Extensions [2013.07.17 13:38:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\Firefox\Profiles\ar9a3nc5.default\extensions [2013.01.16 22:01:38 | 000,021,861 | ---- | M] () (No name found) -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\firefox\profiles\ar9a3nc5.default\extensions\gmailnoads@mywebber.com.xpi [2013.05.09 18:09:47 | 000,870,680 | ---- | M] () (No name found) -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\firefox\profiles\ar9a3nc5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013.07.07 23:53:21 | 000,006,546 | ---- | M] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\firefox\profiles\ar9a3nc5.default\searchplugins\babylon.xml [2013.07.07 23:53:21 | 000,006,546 | ---- | M] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\firefox\profiles\ar9a3nc5.default\searchplugins\BrowserDefender.xml [2013.06.06 20:31:57 | 000,001,294 | ---- | M] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\firefox\profiles\ar9a3nc5.default\searchplugins\delta.xml [2013.07.07 23:53:21 | 000,000,951 | ---- | M] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\firefox\profiles\ar9a3nc5.default\searchplugins\EasyLife.xml [2013.07.07 23:53:21 | 000,001,870 | ---- | M] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\firefox\profiles\ar9a3nc5.default\searchplugins\{013306E9-8E5D-42A4-B4C6-7142563437B3}.xml [2013.07.07 23:53:21 | 000,001,094 | ---- | M] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\firefox\profiles\ar9a3nc5.default\searchplugins\{07BFF356-753E-4741-A48D-EA2CD5285BC1}.xml [2013.07.07 23:53:21 | 000,002,522 | ---- | M] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\firefox\profiles\ar9a3nc5.default\searchplugins\{409DE950-1F95-4DE1-9985-5059BA680BC8}.xml [2013.07.07 23:53:21 | 000,002,077 | ---- | M] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\firefox\profiles\ar9a3nc5.default\searchplugins\{5F6E55CE-3BE8-4FE2-B988-BFA204C3A52C}.xml [2013.07.07 23:53:21 | 000,002,188 | ---- | M] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\firefox\profiles\ar9a3nc5.default\searchplugins\{840A007B-7298-4422-B90A-7B1DD6FC85E4}.xml [2013.07.07 23:53:21 | 000,024,039 | ---- | M] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\mozilla\firefox\profiles\ar9a3nc5.default\searchplugins\{C1B342B6-8522-46C6-923E-22B634510E8C}.xml [2013.06.05 20:02:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\Extensions [2013.05.24 12:56:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions [2013.07.04 10:23:17 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [color=#E56717]========== Chrome ==========[/color] CHR - homepage: https://www.google.de/webhp?hl=de&complete=0 CHR - Extension: No name found = C:\Users\Siedlecki Kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\ CHR - Extension: No name found = C:\Users\Siedlecki Kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: No name found = C:\Users\Siedlecki Kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ CHR - Extension: No name found = C:\Users\Siedlecki Kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.5_0\ CHR - Extension: No name found = C:\Users\Siedlecki Kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\ CHR - Extension: No name found = C:\Users\Siedlecki Kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.6_0\ CHR - Extension: No name found = C:\Users\Siedlecki Kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\ CHR - Extension: No name found = C:\Users\Siedlecki Kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\ CHR - Extension: No name found = C:\Users\Siedlecki Kacper\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (Browser Companion Helper) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files (x86)\BrowserCompanion\jsloader.dll ( ) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Browser Companion Helper Verifier) - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll ( ) O2 - BHO: (DealPly) - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly Technologies Ltd) O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.21.5\bh\delta.dll (Delta-search.com) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaTlbr.dll (Delta-search.com) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4:[b]64bit:[/b] - HKLM..\Run: [] File not found O4:[b]64bit:[/b] - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:[b]64bit:[/b] - HKLM..\Run: [Command Center Controllers] C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe (Alienware) O4:[b]64bit:[/b] - HKLM..\Run: [Ocs_SM] C:\Users\Siedlecki Kacper\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe (Dell, Inc.) O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe () O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [EEventManager] C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe (SEIKO EPSON CORPORATION) O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [LifeCam] C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation) O4 - HKLM..\Run: [Lycosa] C:\Program Files (x86)\Razer\Lycosa\razerhid.exe (Razer USA Ltd.) O4 - HKLM..\Run: [Razer Synapse] C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.) O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKU\Default User..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-2808523232-594759356-3141665527-1000..\Run: [AdobeBridge] File not found O4 - HKU\S-1-5-21-2808523232-594759356-3141665527-1000..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent File not found O4 - HKU\S-1-5-21-2808523232-594759356-3141665527-1000..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe () O4 - HKU\Default User..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - Startup: C:\Users\Siedlecki Kacper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tcbhn.lnk = C:\Users\Siedlecki Kacper\AppData\Roaming\BrowserCompanion\tcbhn.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [binary data] O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites) O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in ) O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in ) O15 - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKU\S-1-5-21-2808523232-594759356-3141665527-1000\..Trusted Domains: sony.com ([]* in Trusted sites) O16:[b]64bit:[/b] - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27) O16:[b]64bit:[/b] - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27) O16:[b]64bit:[/b] - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 80.78.160.2 80.78.162.2 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BF297B74-D6A1-40EA-AAA5-475E20498AD8}: DhcpNameServer = 80.78.160.2 80.78.162.2 O18:[b]64bit:[/b] - Protocol\Handler\base64 - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\chrome - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\prox - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\base64 {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd) O18 - Protocol\Handler\chrome {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd) O18 - Protocol\Handler\prox {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O20 - AppInit_DLLs: (c:\progra~2\browse~2\sprote~1.dll) - c:\progra~2\browse~2\sprote~1.dll () O20 - AppInit_DLLs: (c:\progra~2\easylife\sprote~1.dll) - c:\progra~2\easylife\sprote~1.dll () O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013.09.12 11:51:40 | 000,000,000 | ---D | C] -- C:\FRST [2013.09.04 23:09:31 | 000,000,000 | ---D | C] -- C:\Users\Siedlecki Kacper\Documents\WBGames [2013.09.03 11:18:36 | 000,000,000 | ---D | C] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Origin [2013.09.03 11:17:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin [2013.08.31 12:15:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gPotato [2013.08.31 12:15:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\gPotato [2013.08.29 19:46:04 | 000,000,000 | ---D | C] -- C:\Users\Siedlecki Kacper\AppData\Local\DM [2013.08.29 06:29:54 | 000,796,672 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzdevicedll.dll [2013.08.26 13:37:27 | 000,000,000 | ---D | C] -- C:\Users\Siedlecki Kacper\AppData\Roaming\TeamViewer [2013.08.21 09:34:32 | 000,141,496 | ---- | C] (Razer Inc) -- C:\Windows\SysNative\drivers\rzudd.sys [2013.08.20 10:41:46 | 000,021,176 | ---- | C] (Razer Inc) -- C:\Windows\SysNative\drivers\rzhnet.sys [2013.08.20 10:41:44 | 000,039,096 | ---- | C] (Razer Inc) -- C:\Windows\SysNative\drivers\rzendpt.sys [2013.08.20 10:35:02 | 000,154,112 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rztouchdll.dll [2013.08.20 10:35:02 | 000,057,344 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzdevinfo.dll [2013.08.20 10:34:58 | 000,117,248 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzdisplaydll.dll [2013.08.20 10:34:56 | 000,296,448 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzaudiodll.dll [2013.08.19 01:03:18 | 000,000,000 | ---D | C] -- C:\Users\Siedlecki Kacper\AppData\Local\Warframe [2013.08.15 00:25:43 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2013.08.15 00:25:42 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2013.08.15 00:25:42 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll [2013.08.15 00:25:42 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll [2013.08.15 00:25:42 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe [2013.08.15 00:25:42 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe [2013.08.15 00:25:42 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll [2013.08.15 00:25:42 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll [2013.08.15 00:25:42 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe [2013.08.15 00:25:42 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll [2013.08.15 00:25:42 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll [2013.08.15 00:25:41 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2013.08.15 00:25:40 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2013.08.15 00:25:40 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2013.08.15 00:25:40 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2013.08.15 00:21:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT [2013.08.14 19:05:33 | 001,472,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll [2013.08.14 19:05:33 | 000,224,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll [2013.08.14 19:05:33 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll [2013.08.14 19:05:04 | 001,888,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL [2013.08.14 19:05:04 | 001,620,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL [2013.08.14 19:05:04 | 001,217,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll [2013.08.14 19:05:03 | 003,913,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2013.08.14 19:05:01 | 005,550,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2013.08.14 19:05:01 | 003,968,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2013.08.14 19:05:00 | 001,732,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll [2013.08.14 19:05:00 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2013.08.14 19:05:00 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2013.08.14 19:05:00 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2013.08.14 19:05:00 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2013.08.14 19:05:00 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2013.08.14 19:05:00 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013.09.12 09:49:06 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.09.12 09:49:06 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.09.12 09:41:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.09.12 09:41:13 | 2110,107,647 | -HS- | M] () -- C:\hiberfil.sys [2013.09.11 15:53:37 | 000,856,619 | ---- | M] () -- C:\Users\Siedlecki Kacper\Desktop\IMGP0826.JPG [2013.09.11 15:52:44 | 001,074,721 | ---- | M] () -- C:\Users\Siedlecki Kacper\Desktop\IMGP0918.JPG [2013.09.08 11:48:37 | 000,000,497 | ---- | M] () -- C:\Users\Public\Desktop\Age of Wulin.lnk [2013.09.07 17:57:55 | 000,291,128 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr [2013.09.07 17:57:55 | 000,291,128 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe [2013.09.04 13:38:41 | 000,291,128 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0 [2013.09.03 21:01:57 | 000,002,185 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2013.09.03 10:46:55 | 001,615,978 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.09.03 10:46:55 | 000,697,674 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.09.03 10:46:55 | 000,652,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.09.03 10:46:55 | 000,148,468 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.09.03 10:46:55 | 000,121,422 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.09.03 10:40:45 | 000,132,088 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys [2013.09.03 10:40:45 | 000,105,344 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys [2013.09.03 10:40:45 | 000,081,112 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avnetflt.sys [2013.08.31 13:13:11 | 000,000,409 | ---- | M] () -- C:\attach.ini [2013.08.31 13:01:49 | 000,000,236 | ---- | M] () -- C:\mapui.ini [2013.08.29 06:29:54 | 000,796,672 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzdevicedll.dll [2013.08.21 09:34:32 | 000,141,496 | ---- | M] (Razer Inc) -- C:\Windows\SysNative\drivers\rzudd.sys [2013.08.20 10:41:46 | 000,021,176 | ---- | M] (Razer Inc) -- C:\Windows\SysNative\drivers\rzhnet.sys [2013.08.20 10:41:44 | 000,039,096 | ---- | M] (Razer Inc) -- C:\Windows\SysNative\drivers\rzendpt.sys [2013.08.20 10:35:02 | 000,154,112 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rztouchdll.dll [2013.08.20 10:35:02 | 000,057,344 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzdevinfo.dll [2013.08.20 10:34:58 | 000,117,248 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzdisplaydll.dll [2013.08.20 10:34:56 | 000,296,448 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzaudiodll.dll [2013.08.15 09:55:31 | 000,001,482 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RazerFPSStartup.lnk [2013.08.15 09:55:18 | 000,000,885 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RazerStartUp.lnk [2013.08.14 15:20:44 | 000,000,298 | -H-- | M] () -- C:\Windows\tasks\Microsoft_Hardware_Launch_LcBuddy_exe.job [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013.09.11 15:52:30 | 001,074,721 | ---- | C] () -- C:\Users\Siedlecki Kacper\Desktop\IMGP0918.JPG [2013.09.11 15:51:45 | 000,856,619 | ---- | C] () -- C:\Users\Siedlecki Kacper\Desktop\IMGP0826.JPG [2013.09.08 11:48:37 | 000,000,497 | ---- | C] () -- C:\Users\Public\Desktop\Age of Wulin.lnk [2013.08.31 12:31:44 | 000,000,409 | ---- | C] () -- C:\attach.ini [2013.08.31 12:30:45 | 000,000,236 | ---- | C] () -- C:\mapui.ini [2013.08.14 15:20:44 | 000,000,298 | -H-- | C] () -- C:\Windows\tasks\Microsoft_Hardware_Launch_LcBuddy_exe.job [2013.07.07 23:53:27 | 000,338,432 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll [2013.07.07 23:44:46 | 000,081,408 | ---- | C] () -- C:\Windows\cadkasdeinst01.exe [2013.06.05 21:10:12 | 000,291,128 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2013.06.05 21:10:12 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2013.03.04 22:23:24 | 000,003,584 | ---- | C] () -- C:\Users\Siedlecki Kacper\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2013.03.04 22:18:31 | 000,005,917 | ---- | C] () -- C:\Users\Siedlecki Kacper\AppData\Local\recently-used.xbel [2013.02.27 18:11:24 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2013.02.27 18:11:24 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2013.02.27 17:45:33 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI [2013.02.18 13:25:31 | 000,000,048 | ---- | C] () -- C:\Windows\WININIT.INI [2013.01.25 08:11:16 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2013.01.21 19:53:11 | 000,073,220 | ---- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat [2013.01.21 19:53:11 | 000,031,053 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat [2013.01.21 19:53:11 | 000,029,114 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat [2013.01.21 19:53:11 | 000,027,417 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat [2013.01.21 19:53:11 | 000,021,021 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat [2013.01.21 19:53:11 | 000,015,670 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat [2013.01.21 19:53:11 | 000,013,280 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat [2013.01.21 19:53:11 | 000,010,673 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat [2013.01.21 19:53:11 | 000,004,943 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat [2013.01.21 19:53:11 | 000,001,140 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat [2013.01.21 19:53:11 | 000,001,140 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat [2013.01.21 19:53:11 | 000,001,137 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat [2013.01.21 19:53:11 | 000,001,130 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat [2013.01.21 19:53:11 | 000,001,130 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat [2013.01.21 19:53:11 | 000,001,104 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat [2013.01.21 19:53:11 | 000,000,097 | ---- | C] () -- C:\Windows\SysWow64\PICSDK.ini [2013.01.20 16:59:42 | 000,000,600 | ---- | C] () -- C:\Users\Siedlecki Kacper\AppData\Roaming\winscp.rnd [2013.01.20 16:55:26 | 000,000,600 | ---- | C] () -- C:\Users\Siedlecki Kacper\AppData\Local\PUTTY.RND [2013.01.11 10:16:52 | 004,336,640 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll [2012.11.02 08:55:52 | 002,555,904 | ---- | C] () -- C:\Windows\SysWow64\QQPYEngine.dll [2012.07.03 03:28:06 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2012.05.22 01:28:58 | 000,155,648 | ---- | C] () -- C:\Windows\SysWow64\mlc.dll [2011.12.08 06:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll [2011.11.03 14:09:00 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe [color=#E56717]========== ZeroAccess Check ==========[/color] [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2013.04.06 13:50:58 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Audacity [2013.07.24 16:12:56 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Awesomium [2013.06.05 20:02:11 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\BabSolution [2013.06.05 20:01:54 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Babylon [2013.09.12 09:41:54 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\BrowserCompanion [2013.07.07 23:44:51 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\CAD-KAS [2013.03.09 14:12:38 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2013.02.23 17:10:22 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\DAEMON Tools Lite [2013.01.21 19:35:21 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\DealPly [2013.06.05 20:02:07 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Delta [2013.07.07 23:53:20 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\DesktopIconForAmazon [2013.07.07 23:54:00 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Downloaded Installations [2013.04.14 09:48:06 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Dwarfs [2013.03.05 16:39:17 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\EAC [2013.01.22 18:10:19 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Epson [2013.03.23 12:37:32 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\ExpressFiles [2013.07.07 23:55:07 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\FileOpen [2013.06.24 20:48:26 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\fizzy [2013.02.25 21:53:23 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\FreeVideoConverter [2013.02.24 15:05:30 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\GameRanger [2013.01.16 21:52:52 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Leadertech [2013.01.17 00:20:36 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\LolClient [2013.07.26 16:27:08 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\MKKE [2013.07.07 23:55:07 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Nitro [2013.06.01 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\OBS [2013.07.07 23:53:19 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\OCS [2013.07.07 23:53:21 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Opera [2013.09.03 11:26:43 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Origin [2013.03.09 23:30:15 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\PACE Anti-Piracy [2013.01.24 23:43:14 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Publish Providers [2013.02.27 17:49:39 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Shark007 [2013.01.25 00:11:20 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Sony [2013.01.20 10:38:53 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Subversion [2013.07.30 10:56:07 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Synaptics [2013.08.26 13:42:51 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\TeamViewer [2013.07.10 21:24:54 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\TERA [2013.09.12 09:44:10 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\TS3Client [2013.04.21 18:00:29 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Ubisoft [2013.03.23 12:40:27 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\uTorrent [2013.02.27 17:49:06 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\Win7codecs [2013.04.19 19:01:30 | 000,000,000 | -HSD | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\wyUpdate AU [2013.01.21 20:13:45 | 000,000,000 | ---D | M] -- C:\Users\Siedlecki Kacper\AppData\Roaming\xm1 [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Files - Unicode (All) ==========[/color] [2013.09.12 09:42:17 | 097,238,077 | ---- | M] ()(C:\Windows\SysWow64\???²) -- C:\Windows\SysWow64\纄∤² [2013.09.12 09:42:17 | 097,238,077 | ---- | C] ()(C:\Windows\SysWow64\???²) -- C:\Windows\SysWow64\纄∤² [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 943 bytes -> C:\Users\Siedlecki Kacper\AppData\Local\h7ZfgQBNt:Cw2PfIidzjDrDv3Vjg @Alternate Data Stream - 192 bytes -> C:\Windows:nlsPreferences < End of report >