OTL logfile created on: 2014-03-16 11:31:34 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Renia\Downloads Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19272) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,75 Gb Total Physical Memory | 0,97 Gb Available Physical Memory | 55,76% Memory free 3,74 Gb Paging File | 3,05 Gb Available in Paging File | 81,51% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 30,00 Gb Total Space | 3,00 Gb Free Space | 9,99% Space Free | Partition Type: NTFS Drive D: | 117,04 Gb Total Space | 35,11 Gb Free Space | 30,00% Space Free | Partition Type: NTFS Computer Name: HOMEPC | User Name: Renia | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-03-16 09:57:37 | 003,767,096 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2014-03-15 22:24:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Renia\Downloads\OTL.exe PRC - [2014-02-24 15:49:25 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2013-04-04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe PRC - [2009-04-11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009-04-11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2008-06-24 15:06:06 | 001,840,424 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe PRC - [2008-02-29 22:13:12 | 000,307,200 | ---- | M] (Fujitsu Siemens Computers) -- C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe PRC - [2008-01-21 03:33:00 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe PRC - [2007-08-15 01:41:54 | 000,650,752 | ---- | M] (ITE Tech Inc.) -- C:\Program Files\FSC\Wireless Utility\WirelessSelector.exe PRC - [2007-08-13 13:47:38 | 000,364,544 | ---- | M] () -- C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe PRC - [2007-05-09 10:46:46 | 000,835,584 | ---- | M] () -- C:\Windows\vsnp325.exe PRC - [2007-04-21 09:30:54 | 000,270,336 | ---- | M] () -- C:\Windows\tsnp325.exe PRC - [2006-10-25 20:11:46 | 000,061,440 | ---- | M] (Sigmatel) -- C:\Windows\system\w98eject.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-03-16 09:57:42 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll MOD - [2014-02-24 15:49:22 | 003,578,992 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2007-08-13 13:47:38 | 000,364,544 | ---- | M] () -- C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe MOD - [2007-05-09 10:46:46 | 000,835,584 | ---- | M] () -- C:\Windows\vsnp325.exe MOD - [2007-04-21 09:30:54 | 000,270,336 | ---- | M] () -- C:\Windows\tsnp325.exe [color=#E56717]========== Services (SafeList) ==========[/color] SRV - [2014-03-16 09:57:37 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Stopped] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2014-03-13 00:18:17 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014-02-24 15:49:23 | 000,118,896 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013-04-04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2013-04-04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2009-10-07 09:21:14 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv) SRV - [2009-10-07 09:16:50 | 000,472,280 | ---- | M] (ESET) [Disabled | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn) SRV - [2008-02-29 22:13:12 | 000,307,200 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler) SRV - [2008-01-21 03:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | Boot | Stopped] -- System32\drivers\SMR410.SYS -- (SMR410) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) DRV - [2014-03-16 09:57:46 | 000,775,952 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2014-03-16 09:57:46 | 000,410,784 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP) DRV - [2014-03-16 09:57:46 | 000,180,248 | ---- | M] () [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm) DRV - [2014-03-16 09:57:46 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2014-03-16 09:57:46 | 000,057,672 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2014-03-16 09:57:46 | 000,054,832 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2014-03-16 09:57:46 | 000,049,944 | ---- | M] () [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt) DRV - [2014-03-15 16:07:16 | 000,376,920 | ---- | M] (Symantec Corporation) [Kernel | System | Stopped] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl) DRV - [2013-07-04 09:40:47 | 000,037,440 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Stopped] -- C:\Windows\System32\drivers\PsBoot.sys -- (PsBoot) DRV - [2013-04-04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012-05-01 15:03:49 | 000,180,736 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpwd.sys -- (RDPWD) DRV - [2012-03-30 13:39:11 | 000,905,600 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\tcpip.sys -- (Tcpip6) DRV - [2012-03-30 13:39:11 | 000,905,600 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\tcpip.sys -- (Tcpip) DRV - [2012-03-21 00:28:50 | 000,053,120 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\partmgr.sys -- (partmgr) DRV - [2011-11-17 07:48:37 | 000,440,192 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecdd.sys -- (KSecDD) DRV - [2011-07-06 16:31:47 | 000,214,016 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mrxsmb10.sys -- (mrxsmb10) DRV - [2011-04-29 14:25:10 | 000,146,432 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\srv2.sys -- (srv2) DRV - [2011-04-29 14:25:09 | 000,102,400 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\srvnet.sys -- (srvnet) DRV - [2011-04-29 14:24:42 | 000,079,872 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mrxsmb20.sys -- (mrxsmb20) DRV - [2011-04-29 14:24:40 | 000,106,496 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mrxsmb.sys -- (mrxsmb) DRV - [2011-02-18 15:03:32 | 000,305,152 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\DRIVERS\srv.sys -- (srv) DRV - [2010-02-18 12:28:13 | 000,025,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\tunnel.sys -- (tunnel) DRV - [2009-12-08 18:26:18 | 000,030,720 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\tcpipreg.sys -- (tcpipreg) DRV - [2009-10-07 09:18:36 | 000,035,168 | ---- | M] () [Kernel | System | Stopped] -- C:\Windows\System32\drivers\epfwtdir.sys -- (epfwtdir) DRV - [2009-10-07 09:12:22 | 000,054,184 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\easdrv.sys -- (easdrv) DRV - [2009-10-07 09:11:10 | 000,040,824 | ---- | M] (ESET) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\eamon.sys -- (eamon) DRV - [2009-04-11 07:33:03 | 000,292,840 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\volmgrx.sys -- (volmgrx) DRV - [2009-04-11 07:32:55 | 000,226,280 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\volsnap.sys -- (volsnap) DRV - [2009-04-11 07:32:55 | 000,149,480 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pci.sys -- (pci) DRV - [2009-04-11 07:32:52 | 000,053,224 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\termdd.sys -- (TermDD) DRV - [2009-04-11 07:32:49 | 001,083,880 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\ntfs.sys -- (Ntfs) DRV - [2009-04-11 07:32:49 | 000,527,848 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ndis.sys -- (NDIS) DRV - [2009-04-11 07:32:49 | 000,014,312 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pciide.sys -- (pciide) DRV - [2009-04-11 07:32:46 | 000,161,752 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\msrpc.sys -- (MsRPC) DRV - [2009-04-11 07:32:31 | 000,048,104 | ---- | M] () [File_System | Boot | Running] -- C:\Windows\System32\Drivers\mup.sys -- (Mup) DRV - [2009-04-11 05:46:40 | 000,069,120 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\rassstp.sys -- (RasSstp) DRV - [2009-04-11 05:46:32 | 000,121,344 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\ndiswan.sys -- (NdisWan) DRV - [2009-04-11 05:46:30 | 000,041,472 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\raspppoe.sys -- (RasPppoe) DRV - [2009-04-11 05:45:56 | 000,072,192 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\tdx.sys -- (tdx) DRV - [2009-04-11 05:45:51 | 000,072,192 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\pacer.sys -- (PSched) DRV - [2009-04-11 05:45:37 | 000,185,856 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\netbt.sys -- (netbt) DRV - [2009-04-11 05:45:22 | 000,066,560 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\smb.sys -- (Smb) DRV - [2009-04-11 05:43:28 | 000,148,480 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\nwifi.sys -- (NativeWifiP) DRV - [2009-04-11 05:43:16 | 000,196,096 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\usbhub.sys -- (usbhub) DRV - [2009-04-11 05:43:12 | 000,148,992 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\rfcomm.sys -- (RFCOMM) DRV - [2009-04-11 05:42:55 | 000,065,536 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\USBSTOR.SYS -- (USBSTOR) DRV - [2009-04-11 05:42:52 | 000,039,936 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\usbehci.sys -- (usbehci) DRV - [2009-04-11 05:42:52 | 000,019,456 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\usbohci.sys -- (usbohci) DRV - [2009-04-11 05:38:40 | 000,017,408 | ---- | M] () [Kernel | System | Stopped] -- C:\Windows\System32\DRIVERS\kbdhid.sys -- (kbdhid) DRV - [2009-04-11 05:14:40 | 000,114,688 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mrxdav.sys -- (MRxDAV) DRV - [2009-04-11 05:14:29 | 000,225,280 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\DRIVERS\rdbss.sys -- (rdbss) DRV - [2009-04-11 05:14:01 | 000,035,328 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\npfs.sys -- (Npfs) DRV - [2009-04-11 05:13:59 | 000,226,816 | ---- | M] () [File_System | Disabled | Stopped] -- C:\Windows\System32\DRIVERS\udfs.sys -- (udfs) DRV - [2009-01-13 09:45:00 | 000,954,368 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2008-10-09 15:42:42 | 000,017,408 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\KMWDFILTER.sys -- (KMWDFILTER) DRV - [2008-09-22 15:59:23 | 000,028,728 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\msahci.sys -- (msahci) DRV - [2008-01-21 03:34:49 | 000,023,552 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\tssecsrv.sys -- (tssecsrv) DRV - [2008-01-21 03:34:48 | 000,083,328 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\WUDFRd.sys -- (WUDFRd) DRV - [2008-01-21 03:34:45 | 000,031,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\modem.sys -- (Modem) DRV - [2008-01-21 03:34:44 | 000,076,288 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\rasl2tp.sys -- (Rasl2tp) DRV - [2008-01-21 03:34:44 | 000,062,976 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\raspptp.sys -- (PptpMiniport) DRV - [2008-01-21 03:34:44 | 000,016,896 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\ndisuio.sys -- (Ndisuio) DRV - [2008-01-21 03:34:39 | 000,025,088 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\vga.sys -- (VgaSave) DRV - [2008-01-21 03:34:39 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MSKSSRV.sys -- (MSKSSRV) DRV - [2008-01-21 03:34:39 | 000,006,016 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MSTEE.sys -- (MSTEE) DRV - [2008-01-21 03:34:39 | 000,005,888 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MSPCLOCK.sys -- (MSPCLOCK) DRV - [2008-01-21 03:34:39 | 000,005,504 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MSPQM.sys -- (MSPQM) DRV - [2008-01-21 03:34:38 | 000,006,144 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\rdpencdd.sys -- (RDPENCDD) DRV - [2008-01-21 03:34:35 | 000,064,000 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mpsdrv.sys -- (mpsdrv) DRV - [2008-01-21 03:34:35 | 000,016,384 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\nsiproxy.sys -- (nsiproxy) DRV - [2008-01-21 03:34:35 | 000,015,872 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ws2ifsl.sys -- (ws2ifsl) DRV - [2008-01-21 03:34:22 | 000,084,480 | ---- | M] () [File_System | Auto | Running] -- C:\Windows\System32\drivers\luafv.sys -- (luafv) DRV - [2008-01-21 03:34:21 | 000,060,416 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\DRIVERS\rspndr.sys -- (rspndr) DRV - [2008-01-21 03:34:21 | 000,047,104 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\DRIVERS\lltdio.sys -- (lltdio) DRV - [2008-01-21 03:34:06 | 000,062,464 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\wanarp.sys -- (Wanarpv6) DRV - [2008-01-21 03:34:06 | 000,062,464 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\wanarp.sys -- (Wanarp) DRV - [2008-01-21 03:34:06 | 000,049,664 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ndproxy.sys -- (NDProxy) DRV - [2008-01-21 03:34:06 | 000,020,992 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\ndistapi.sys -- (NdisTapi) DRV - [2008-01-21 03:34:06 | 000,015,360 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\tunmp.sys -- (tunmp) DRV - [2008-01-21 03:34:01 | 000,035,840 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\DRIVERS\netbios.sys -- (NetBIOS) DRV - [2008-01-21 03:34:00 | 000,011,776 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\rasacd.sys -- (RasAcd) DRV - [2008-01-21 03:33:48 | 000,021,048 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\spldr.sys -- (spldr) DRV - [2008-01-21 03:33:45 | 000,029,184 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tdtcp.sys -- (TDTCP) DRV - [2008-01-21 03:33:45 | 000,017,920 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tdpipe.sys -- (TDPIPE) DRV - [2008-01-21 03:33:42 | 000,006,144 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\RDPCDD.sys -- (RDPCDD) DRV - [2008-01-21 03:33:23 | 000,503,864 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\Wdf01000.sys -- (Wdf01000) DRV - [2008-01-21 03:33:23 | 000,022,528 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\msfs.sys -- (Msfs) DRV - [2008-01-21 03:33:22 | 000,004,608 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\null.sys -- (Null) DRV - [2008-01-21 03:33:14 | 000,057,400 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mountmgr.sys -- (MountMgr) DRV - [2008-01-21 03:32:58 | 000,031,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\qwavedrv.sys -- (QWAVEdrv) DRV - [2008-01-21 03:32:50 | 000,022,072 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\wd.sys -- (Wd) DRV - [2008-01-21 03:32:49 | 000,035,384 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\kbdclass.sys -- (kbdclass) DRV - [2008-01-21 03:32:49 | 000,013,312 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sffdisk.sys -- (sffdisk) DRV - [2008-01-21 03:32:49 | 000,012,288 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sffp_mmc.sys -- (sffp_mmc) DRV - [2008-01-21 03:32:49 | 000,011,776 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sffp_sd.sys -- (sffp_sd) DRV - [2008-01-21 03:32:48 | 000,034,816 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\umbus.sys -- (umbus) DRV - [2008-01-21 03:32:47 | 000,094,776 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\msdsm.sys -- (msdsm) DRV - [2008-01-21 03:32:47 | 000,059,448 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\DRIVERS\uagp35.sys -- (uagp35) DRV - [2008-01-21 03:32:47 | 000,041,984 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\monitor.sys -- (monitor) DRV - [2008-01-21 03:32:47 | 000,039,936 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\wpdusb.sys -- (WpdUsb) DRV - [2008-01-21 03:32:45 | 000,105,016 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\mpio.sys -- (mpio) DRV - [2008-01-21 03:32:45 | 000,073,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\usbccgp.sys -- (usbccgp) DRV - [2008-01-21 03:32:45 | 000,034,360 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\DRIVERS\mouclass.sys -- (mouclass) DRV - [2008-01-21 03:32:45 | 000,019,968 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sermouse.sys -- (sermouse) DRV - [2008-01-21 03:32:45 | 000,015,872 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\mouhid.sys -- (mouhid) DRV - [2008-01-21 03:32:24 | 000,023,552 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\DRIVERS\usbuhci.sys -- (usbuhci) DRV - [2008-01-21 03:32:23 | 000,026,112 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\vgapnp.sys -- (vga) DRV - [2008-01-21 03:32:22 | 000,248,832 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\rdpdr.sys -- (rdpdr) DRV - [2008-01-21 03:32:22 | 000,109,112 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nv_agp.sys -- (nv_agp) DRV - [2008-01-21 03:32:22 | 000,083,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\serial.sys -- (Serial) DRV - [2008-01-21 03:32:22 | 000,079,360 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\parport.sys -- (Parport) DRV - [2008-01-21 03:32:22 | 000,060,984 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\uliagpkx.sys -- (uliagpkx) DRV - [2008-01-21 03:32:22 | 000,056,888 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\viaagp.sys -- (viaagp) DRV - [2008-01-21 03:32:22 | 000,052,792 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\volmgr.sys -- (volmgr) DRV - [2008-01-21 03:32:22 | 000,031,288 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\mssmbios.sys -- (mssmbios) DRV - [2008-01-21 03:32:22 | 000,017,920 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\serenum.sys -- (Serenum) DRV - [2008-01-21 03:32:22 | 000,016,440 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\msisadrv.sys -- (msisadrv) DRV - [2008-01-21 03:32:22 | 000,015,288 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\swenum.sys -- (swenum) DRV - [2008-01-21 03:32:22 | 000,008,704 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\DRIVERS\parvdm.sys -- (Parvdm) DRV - [2008-01-21 03:32:21 | 000,041,472 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\viac7.sys -- (ViaC7) DRV - [2008-01-21 03:32:21 | 000,040,960 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\processr.sys -- (Processor) DRV - [2008-01-21 03:32:21 | 000,011,264 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\wmiacpi.sys -- (WmiAcpi) DRV - [2007-09-18 04:09:36 | 000,452,968 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\SISGRKMD.sys -- (SiS6350) DRV - [2007-07-30 02:00:56 | 000,014,168 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\zntport.sys -- (zntport) DRV - [2007-07-04 10:04:54 | 000,047,616 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\DRIVERS\SiSGB6.sys -- (SiSGbeLH) DRV - [2007-05-07 18:38:22 | 010,343,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\snp325.sys -- (SNP325) DRV - [2007-02-07 16:50:32 | 000,118,552 | ---- | M] (Analog Devices Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\adiusbaw.sys -- (adiusbaw) DRV - [2007-02-07 16:50:14 | 000,056,088 | ---- | M] (Analog Deivces) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\adildr.sys -- (ELOADER) DRV - [2007-01-24 17:08:06 | 000,056,184 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\DRIVERS\SISAGPX.sys -- (SISAGP) DRV - [2006-12-13 17:52:50 | 000,020,992 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\motmodem.sys -- (motmodem) DRV - [2006-11-02 10:51:12 | 000,167,528 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\pcmcia.sys -- (pcmcia) DRV - [2006-11-02 10:50:16 | 000,076,392 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sbp2port.sys -- (sbp2port) DRV - [2006-11-02 10:14:58 | 000,018,944 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\usbprint.sys -- (usbprint) DRV - [2006-11-02 10:04:35 | 000,878,080 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\peauth.sys -- (PEAUTH) DRV - [2006-11-02 09:55:16 | 000,062,080 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\ohci1394.sys -- (ohci1394) DRV - [2006-11-02 09:55:09 | 000,068,608 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\usbcir.sys -- (usbcir) DRV - [2006-11-02 09:52:52 | 000,020,608 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\wacompen.sys -- (WacomPen) DRV - [2006-11-02 09:51:40 | 000,013,312 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sfloppy.sys -- (sfloppy) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.fujitsu-siemens.com/index2 IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1121969253-750732130-2290038854-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.fujitsu-siemens.com/index2 IE - HKU\S-1-5-21-1121969253-750732130-2290038854-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/ IE - HKU\S-1-5-21-1121969253-750732130-2290038854-1001\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-1121969253-750732130-2290038854-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1121969253-750732130-2290038854-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-1121969253-750732130-2290038854-1001\..\SearchScopes\{72D39A6F-3EBE-462E-87A2-02E5FE7C9296}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=C9AE0582-ABAC-47E5-9463-81616EA02411&apn_sauid=35A77B34-C649-43E0-999D-3A69AF267BF8 IE - HKU\S-1-5-21-1121969253-750732130-2290038854-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultengine: "Google" FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.selectedEngine: "Ask.com" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.google.pl/" FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.21 FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:9.0.2013.75 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.4 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..keyword.URL: "http://www.google.com/cse?cx=partner-pub-5528014799800033:cevktqnfrvl&ie=ISO-8859-1&q=" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\VistaCodecPack\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-03-16 09:57:47 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2014-02-24 15:48:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014-02-24 15:48:55 | 000,000,000 | ---D | M] [2008-11-30 20:52:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Renia\AppData\Roaming\mozilla\Extensions [2013-09-27 11:42:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Renia\AppData\Roaming\mozilla\Firefox\Profiles\7c8eh2bo.default\extensions [2011-03-26 15:01:50 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Renia\AppData\Roaming\mozilla\Firefox\Profiles\7c8eh2bo.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2013-08-28 10:30:35 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Renia\AppData\Roaming\mozilla\Firefox\Profiles\7c8eh2bo.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-02-24 15:48:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2014-02-24 15:48:49 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-02-24 15:48:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-02-24 15:48:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions [2014-02-24 15:49:28 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2014-03-16 09:57:47 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2011-03-16 14:19:26 | 000,180,896 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npVividasPlayer.dll O1 HOSTS File: ([2014-03-15 21:54:59 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKU\S-1-5-21-1121969253-750732130-2290038854-1001\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET) O4 - HKLM..\Run: [snp325] C:\Windows\vsnp325.exe () O4 - HKLM..\Run: [TouchPadHotKey] C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe () O4 - HKLM..\Run: [tsnp325] C:\Windows\tsnp325.exe () O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-1121969253-750732130-2290038854-1001..\Run: [ALLUpdate] C:\Program Files\ALLPlayer\ALLUpdate.exe () O4 - HKU\S-1-5-21-1121969253-750732130-2290038854-1001..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\S-1-5-21-1121969253-750732130-2290038854-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O13 - gopher Prefix: missing O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4D2CEC3C-5029-4823-95CD-CBE225536285}: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\Renia\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg O24 - Desktop BackupWallPaper: C:\Users\Renia\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-03-16 11:21:12 | 000,000,000 | ---D | C] -- C:\FRST [2014-03-16 09:59:33 | 000,000,000 | ---D | C] -- C:\Users\Renia\AppData\Roaming\AVAST Software [2014-03-16 09:58:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast [2014-03-16 09:57:51 | 000,057,672 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2014-03-16 09:57:50 | 000,775,952 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2014-03-16 09:57:50 | 000,410,784 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2014-03-16 09:57:49 | 000,067,824 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2014-03-16 09:57:49 | 000,054,832 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2014-03-16 09:57:47 | 000,270,240 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2014-03-16 09:57:44 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2014-03-16 09:55:44 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2014-03-16 09:48:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Odkurzacz [2014-03-16 09:48:19 | 000,000,000 | ---D | C] -- C:\Program Files\Odkurzacz [2014-03-16 02:26:57 | 000,000,000 | ---D | C] -- C:\Users\Renia\AppData\Local\NPE [2014-03-16 01:53:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared [2014-03-16 01:48:25 | 000,410,784 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\stxfijek.sys [2014-03-16 00:41:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab [2014-03-16 00:15:25 | 000,000,000 | ---D | C] -- C:\Users\Renia\Doctor Web [2014-03-15 23:59:20 | 000,410,784 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\nyxdoesk.sys [2014-03-15 22:51:38 | 000,410,784 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\tlklfdqf.sys [2014-03-15 20:53:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton [2014-03-15 20:51:51 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller [2014-03-15 20:12:57 | 004,375,224 | ---- | C] (F-Secure Corporation) -- C:\Users\Renia\Desktop\F-SecureOnlineScanner.exe [2014-03-15 20:09:39 | 000,000,000 | ---D | C] -- C:\Program Files\SkanerOnline [2014-03-15 18:25:56 | 000,000,000 | ---D | C] -- C:\Users\Renia\AppData\Roaming\Malwarebytes [2014-03-15 18:25:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2014-03-15 18:25:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2014-03-15 18:25:41 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2014-03-15 18:25:41 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2014-03-15 18:20:57 | 000,037,440 | ---- | C] (Panda Security, S.L.) -- C:\Windows\System32\drivers\PsBoot.sys [2014-03-15 15:58:47 | 000,000,000 | ---D | C] -- C:\Users\Renia\AppData\Roaming\Panda Security [2014-03-15 15:57:27 | 000,000,000 | ---D | C] -- C:\Program Files\Panda Security [2014-03-15 15:31:14 | 000,410,784 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\lswhkyhp.sys [2014-03-15 15:21:36 | 000,410,784 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\krynsszl.sys [2014-03-15 15:21:35 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software [2014-03-15 15:09:35 | 000,000,000 | ---D | C] -- C:\Users\Renia\Desktop\ESET NOD32 Antivirus 5.0.95.0 [PL] [32-64 bit] [2014-02-24 15:48:46 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [1 C:\*.tmp files -> C:\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-03-16 11:20:13 | 000,001,356 | ---- | M] () -- C:\Users\Renia\AppData\Local\d3d9caps.dat [2014-03-16 11:18:31 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2014-03-16 11:18:31 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2014-03-16 11:18:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2014-03-16 10:18:15 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2014-03-16 09:58:26 | 000,001,879 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2014-03-16 09:57:46 | 000,775,952 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2014-03-16 09:57:46 | 000,410,784 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2014-03-16 09:57:46 | 000,180,248 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys [2014-03-16 09:57:46 | 000,067,824 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2014-03-16 09:57:46 | 000,057,672 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2014-03-16 09:57:46 | 000,054,832 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2014-03-16 09:57:46 | 000,049,944 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys [2014-03-16 09:57:44 | 000,270,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2014-03-16 09:57:44 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2014-03-16 09:48:22 | 000,000,862 | ---- | M] () -- C:\Users\Renia\Desktop\Odkurzacz.lnk [2014-03-16 01:48:25 | 000,410,784 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\stxfijek.sys [2014-03-15 23:59:20 | 000,410,784 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\nyxdoesk.sys [2014-03-15 23:54:27 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2014-03-15 23:23:21 | 000,000,552 | ---- | M] () -- C:\Users\Renia\AppData\Local\d3d8caps.dat [2014-03-15 22:51:38 | 000,410,784 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\tlklfdqf.sys [2014-03-15 22:21:38 | 000,387,416 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2014-03-15 21:54:59 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts [2014-03-15 21:06:34 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini [2014-03-15 21:06:25 | 000,127,488 | ---- | M] () -- C:\Users\Renia\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2014-03-15 20:13:09 | 004,375,224 | ---- | M] (F-Secure Corporation) -- C:\Users\Renia\Desktop\F-SecureOnlineScanner.exe [2014-03-15 18:25:42 | 000,000,912 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2014-03-15 15:31:14 | 000,410,784 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\lswhkyhp.sys [2014-03-15 15:21:36 | 000,410,784 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\krynsszl.sys [2014-03-13 00:18:16 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2014-03-13 00:18:16 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2014-03-06 13:23:40 | 000,056,192 | ---- | M] () -- C:\Windows\System32\drivers\2e7c80c788dd5602.sys [1 C:\*.tmp files -> C:\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-03-16 09:58:26 | 000,001,879 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2014-03-16 09:57:51 | 000,180,248 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys [2014-03-16 09:57:50 | 000,049,944 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys [2014-03-16 09:48:22 | 000,000,862 | ---- | C] () -- C:\Users\Renia\Desktop\Odkurzacz.lnk [2014-03-15 23:23:21 | 000,000,552 | ---- | C] () -- C:\Users\Renia\AppData\Local\d3d8caps.dat [2014-03-15 22:31:56 | 000,001,356 | ---- | C] () -- C:\Users\Renia\AppData\Local\d3d9caps.dat [2014-03-15 18:25:42 | 000,000,912 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2014-03-06 13:23:40 | 000,056,192 | ---- | C] () -- C:\Windows\System32\drivers\2e7c80c788dd5602.sys [2013-02-11 09:26:57 | 000,459,776 | ---- | C] () -- C:\Windows\System32\converter.dll [2012-06-13 18:10:45 | 000,012,800 | ---- | C] () -- C:\Windows\System32\drivers\fs_rec.sys [2012-06-13 18:01:34 | 000,180,736 | ---- | C] () -- C:\Windows\System32\drivers\rdpwd.sys [2012-06-13 17:59:06 | 000,905,600 | ---- | C] () -- C:\Windows\System32\drivers\tcpip.sys [2012-06-13 17:59:00 | 000,440,192 | ---- | C] () -- C:\Windows\System32\drivers\ksecdd.sys [2012-06-13 17:58:54 | 000,214,016 | ---- | C] () -- C:\Windows\System32\drivers\mrxsmb10.sys [2012-06-13 17:58:54 | 000,079,872 | ---- | C] () -- C:\Windows\System32\drivers\mrxsmb20.sys [2012-06-13 17:58:53 | 000,106,496 | ---- | C] () -- C:\Windows\System32\drivers\mrxsmb.sys [2012-06-13 17:58:51 | 000,508,416 | ---- | C] () -- C:\Windows\System32\drivers\bthport.sys [2012-06-13 17:58:50 | 000,030,208 | ---- | C] () -- C:\Windows\System32\drivers\BTHUSB.SYS [2012-06-13 17:58:34 | 002,045,440 | ---- | C] () -- C:\Windows\System32\win32k.sys [2012-06-13 17:58:26 | 000,146,432 | ---- | C] () -- C:\Windows\System32\drivers\srv2.sys [2012-06-13 17:58:26 | 000,102,400 | ---- | C] () -- C:\Windows\System32\drivers\srvnet.sys [2012-06-13 17:58:18 | 003,602,816 | ---- | C] () -- C:\Windows\System32\ntkrnlpa.exe [2012-06-13 17:57:48 | 000,273,408 | ---- | C] () -- C:\Windows\System32\drivers\afd.sys [2012-06-13 17:57:40 | 000,049,152 | ---- | C] () -- C:\Windows\System32\csrsrv.dll [2012-06-13 17:57:37 | 000,075,264 | ---- | C] () -- C:\Windows\System32\drivers\dfsc.sys [2012-06-13 17:57:28 | 000,053,120 | ---- | C] () -- C:\Windows\System32\drivers\partmgr.sys [2008-12-26 16:52:08 | 000,127,488 | ---- | C] () -- C:\Users\Renia\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [color=#E56717]========== ZeroAccess Check ==========[/color] [2006-11-02 13:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2011-01-21 17:35:22 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009-04-11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009-04-11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2009-03-15 16:14:04 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\Ashampoo [2009-05-14 21:12:28 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\AutoUpdate [2011-05-25 23:53:07 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\EurekaLog [2010-04-12 14:27:34 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\IrfanView [2012-01-15 21:20:22 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\Kamerzysta [2011-05-28 20:15:15 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\MfcEmbed [2009-06-13 00:45:03 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\Opera [2009-10-18 22:00:41 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\PlusOffice [2011-10-07 22:32:23 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\Rovio [2010-04-05 04:07:21 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\uTorrent [2014-03-16 09:59:33 | 000,000,000 | ---D | M] -- C:\Users\Renia\AppData\Roaming\AVAST Software [2008-11-30 20:58:54 | 000,000,000 | ---D | M] -- C:\Users\Renia\AppData\Roaming\Gadu-Gadu [2009-04-11 19:53:18 | 000,000,000 | ---D | M] -- C:\Users\Renia\AppData\Roaming\IrfanView [2013-02-24 11:30:32 | 000,000,000 | ---D | M] -- C:\Users\Renia\AppData\Roaming\MfcEmbed [2014-03-15 20:53:01 | 000,000,000 | ---D | M] -- C:\Users\Renia\AppData\Roaming\Panda Security [2009-11-10 10:04:37 | 000,000,000 | ---D | M] -- C:\Users\Renia\AppData\Roaming\PlusOffice [2011-10-08 11:05:14 | 000,000,000 | ---D | M] -- C:\Users\Renia\AppData\Roaming\Rovio [2010-01-27 22:01:28 | 000,000,000 | ---D | M] -- C:\Users\Renia\AppData\Roaming\VistaCodecs [color=#E56717]========== Purity Check ==========[/color] < End of report >