OTL logfile created on: 2014-03-16 16:14:31 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Szef\Desktop Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 0,91 Gb Available Physical Memory | 45,30% Memory free 4,00 Gb Paging File | 2,27 Gb Available in Paging File | 56,85% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 100,00 Gb Total Space | 70,85 Gb Free Space | 70,86% Space Free | Partition Type: NTFS Drive D: | 200,00 Gb Total Space | 171,89 Gb Free Space | 85,95% Space Free | Partition Type: NTFS Drive E: | 165,76 Gb Total Space | 92,20 Gb Free Space | 55,62% Space Free | Partition Type: NTFS Computer Name: SZEF-KOMPUTER | User Name: Szef | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-03-16 16:12:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Szef\Desktop\OTL.scr PRC - [2014-03-15 11:49:42 | 000,348,960 | ---- | M] () -- C:\Program Files\Mega Browse\updateMegaBrowse.exe PRC - [2014-03-15 11:16:36 | 000,348,960 | ---- | M] () -- C:\Program Files\Mega Browse\bin\utilMegaBrowse.exe PRC - [2014-03-12 21:30:53 | 001,863,560 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe PRC - [2014-03-08 21:22:53 | 003,767,096 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2014-03-08 21:22:53 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2014-03-08 21:22:46 | 000,113,704 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\afwServ.exe PRC - [2014-02-13 01:36:25 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2014-01-02 08:33:40 | 000,499,856 | ---- | M] (Cherished Technololgy LIMITED) -- C:\ProgramData\WPM\wprotectmanager.exe PRC - [2013-12-21 07:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2013-12-10 03:15:27 | 002,279,712 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe PRC - [2013-12-10 03:14:56 | 001,494,304 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe PRC - [2013-12-10 03:14:51 | 014,658,848 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe PRC - [2013-11-11 15:26:53 | 000,932,640 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe PRC - [2013-11-11 15:26:52 | 001,821,984 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe PRC - [2013-11-11 08:59:20 | 000,414,496 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2013-11-08 21:46:18 | 001,028,384 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe PRC - [2013-09-19 03:39:36 | 001,688,723 | ---- | M] () -- C:\Users\Szef\AppData\Roaming\minerd\bfgminer.exe PRC - [2013-07-14 00:27:17 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe PRC - [2013-07-14 00:22:28 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2013-04-15 10:50:34 | 000,337,432 | ---- | M] (Power Software Ltd) -- C:\Program Files\PowerISO\PWRISOVM.EXE PRC - [2013-03-14 02:13:19 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-03-16 15:35:13 | 000,398,112 | ---- | M] () -- C:\Program Files\Mega Browse\bin\MegaBrowse.BrowserFilter.Helper.dll MOD - [2014-03-12 21:30:52 | 016,276,872 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_12_0_0_77.dll MOD - [2014-03-08 21:22:54 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll MOD - [2014-02-13 01:36:39 | 003,578,992 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2013-09-19 03:39:36 | 001,688,723 | ---- | M] () -- C:\Users\Szef\AppData\Roaming\minerd\bfgminer.exe MOD - [2013-09-19 03:39:36 | 000,599,040 | ---- | M] () -- C:\Users\Szef\AppData\Roaming\minerd\backtrace.dll MOD - [2013-09-19 03:39:36 | 000,369,664 | ---- | M] () -- C:\Users\Szef\AppData\Roaming\minerd\libcurl-4.dll MOD - [2013-09-19 03:39:36 | 000,132,096 | ---- | M] () -- C:\Users\Szef\AppData\Roaming\minerd\libplibc-1.dll MOD - [2013-09-19 03:39:36 | 000,109,568 | ---- | M] () -- C:\Users\Szef\AppData\Roaming\minerd\zlib1.dll MOD - [2013-09-19 03:39:36 | 000,102,912 | ---- | M] () -- C:\Users\Szef\AppData\Roaming\minerd\pdcurses.dll MOD - [2013-09-19 03:39:36 | 000,082,944 | ---- | M] () -- C:\Users\Szef\AppData\Roaming\minerd\libmicrohttpd-10.dll MOD - [2013-09-19 03:39:36 | 000,052,736 | ---- | M] () -- C:\Users\Szef\AppData\Roaming\minerd\libjansson-4.dll MOD - [2013-09-19 03:39:36 | 000,044,781 | ---- | M] () -- C:\Users\Szef\AppData\Roaming\minerd\libblkmaker-0.1-0.dll MOD - [2013-09-19 03:39:36 | 000,040,717 | ---- | M] () -- C:\Users\Szef\AppData\Roaming\minerd\libblkmaker_jansson-0.1-0.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - [2014-03-15 11:49:42 | 000,348,960 | ---- | M] () [Auto | Running] -- C:\Program Files\Mega Browse\updateMegaBrowse.exe -- (Update Mega Browse) SRV - [2014-03-15 11:16:36 | 000,348,960 | ---- | M] () [Auto | Running] -- C:\Program Files\Mega Browse\bin\utilMegaBrowse.exe -- (Util Mega Browse) SRV - [2014-03-12 21:30:53 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014-03-08 21:22:53 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2014-03-08 21:22:46 | 000,113,704 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall) SRV - [2014-02-13 01:36:33 | 000,118,896 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2014-01-02 08:33:40 | 000,499,856 | ---- | M] (Cherished Technololgy LIMITED) [Auto | Running] -- C:\ProgramData\WPM\wprotectmanager.exe -- (Wpm) SRV - [2013-12-21 07:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2013-12-10 03:14:56 | 001,494,304 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService) SRV - [2013-12-10 03:14:51 | 014,658,848 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc) SRV - [2013-11-11 08:59:20 | 000,414,496 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2013-09-05 09:34:30 | 000,171,680 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2013-07-14 00:33:23 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009-07-14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009-07-14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\RimUsb.sys -- (RimUsb) DRV - [2014-03-08 21:23:32 | 000,265,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswndisflt.sys -- (aswNdisFlt) DRV - [2014-03-08 21:22:54 | 000,775,952 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2014-03-08 21:22:54 | 000,410,784 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP) DRV - [2014-03-08 21:22:54 | 000,180,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm) DRV - [2014-03-08 21:22:54 | 000,079,720 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr) DRV - [2014-03-08 21:22:54 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2014-03-08 21:22:54 | 000,064,168 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\aswStm.sys -- (aswStm) DRV - [2014-03-08 21:22:54 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt) DRV - [2014-03-08 21:22:49 | 000,026,136 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswKbd.sys -- (aswKbd) DRV - [2013-12-05 09:42:30 | 000,034,080 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvvad32v.sys -- (nvvad_WaveExtensible) DRV - [2013-12-03 17:30:28 | 000,015,528 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\amdkmafd.sys -- (amdkmafd) DRV - [2013-11-14 12:57:18 | 010,446,112 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2013-07-14 00:24:02 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2013-07-14 00:24:02 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD) DRV - [2013-07-14 00:24:02 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\terminpt.sys -- (terminpt) DRV - [2013-07-14 00:24:02 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV - [2013-04-15 10:50:32 | 000,113,608 | ---- | M] (Power Software Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu) DRV - [2010-11-20 22:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010-11-20 22:29:03 | 000,112,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tsusbhub.sys -- (tsusbhub) DRV - [2010-11-20 22:29:03 | 000,077,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Synth3dVsc.sys -- (Synth3dVsc) DRV - [2010-11-20 22:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc) DRV - [2010-11-20 22:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010-11-20 22:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010-11-20 22:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010-11-20 22:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2009-07-14 00:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | System | Running] -- C:\Windows\System32\drivers\serial.sys -- (Serial) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1388678471&from=wpm0102&uid=ST3500418AS_6VM41GTDXXXX6VM41GTD IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1388697779&from=wpm0102&uid=ST3500418AS_6VM41GTDXXXX6VM41GTD&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1388697779&from=wpm0102&uid=ST3500418AS_6VM41GTDXXXX6VM41GTD&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1388678471&from=wpm0102&uid=ST3500418AS_6VM41GTDXXXX6VM41GTD IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.delta-homes.com/web/?type=ds&ts=1388697779&from=wpm0102&uid=ST3500418AS_6VM41GTDXXXX6VM41GTD&q={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1380921896-1465908367-3806346790-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1388678471&from=wpm0102&uid=ST3500418AS_6VM41GTDXXXX6VM41GTD IE - HKU\S-1-5-21-1380921896-1465908367-3806346790-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve IE - HKU\S-1-5-21-1380921896-1465908367-3806346790-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1388678471&from=wpm0102&uid=ST3500418AS_6VM41GTDXXXX6VM41GTD IE - HKU\S-1-5-21-1380921896-1465908367-3806346790-1000\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86} IE - HKU\S-1-5-21-1380921896-1465908367-3806346790-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKU\S-1-5-21-1380921896-1465908367-3806346790-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.delta-homes.com/web/?type=ds&ts=1388697779&from=wpm0102&uid=ST3500418AS_6VM41GTDXXXX6VM41GTD&q={searchTerms} IE - HKU\S-1-5-21-1380921896-1465908367-3806346790-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-03-08 21:22:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014-03-16 15:46:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Szef\AppData\Roaming\mozilla\Extensions [2014-03-16 15:46:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions [2014-03-16 15:46:09 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} O1 HOSTS File: ([2009-06-10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) O4 - HKLM..\Run: [NvBackend] C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) O4 - HKLM..\Run: [Nvtmru] C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation) O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (Power Software Ltd) O4 - HKLM..\Run: [ShadowPlay] C:\Windows\System32\nvspcap.dll (NVIDIA Corporation) O4 - HKU\S-1-5-21-1380921896-1465908367-3806346790-1000..\Run: [minerd] C:\Users\Szef\AppData\Roaming\minerd\nircmd.exe (NirSoft) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{095EBD0D-4AB8-4DFF-9F08-55A6695858AF}: NameServer = 8.8.8.8,8.8.4.4 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\G\Shell - "" = AutoRun O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\GameLauncher.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-03-16 16:12:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Szef\Desktop\OTL.scr [2014-03-16 15:46:09 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service [2014-03-15 11:27:38 | 000,000,000 | ---D | C] -- C:\Users\Szef\AppData\Roaming\Pokeing [2014-03-14 21:51:20 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip [2014-03-09 22:30:41 | 000,000,000 | ---D | C] -- C:\Users\Szef\psoul [2014-03-08 21:24:10 | 000,000,000 | ---D | C] -- C:\Users\Szef\AppData\Roaming\AVAST Software [2014-03-08 21:23:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast [2014-03-08 21:23:00 | 000,775,952 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2014-03-08 21:23:00 | 000,410,784 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2014-03-08 21:23:00 | 000,064,168 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswStm.sys [2014-03-08 21:22:59 | 000,079,720 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys [2014-03-08 21:22:59 | 000,067,824 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2014-03-08 21:22:58 | 000,026,136 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys [2014-03-08 21:22:56 | 000,270,240 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2014-03-08 21:22:54 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2014-03-08 21:22:31 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2014-03-08 15:34:17 | 000,000,000 | ---D | C] -- C:\Program Files\Mega Browse [2014-03-08 12:23:27 | 000,000,000 | ---D | C] -- C:\Users\Szef\AppData\Roaming\JSPKM [2014-03-08 00:03:22 | 000,000,000 | ---D | C] -- C:\Users\Szef\Documents\Need for Speed World [2014-03-07 22:54:37 | 000,000,000 | ---D | C] -- C:\Users\Szef\AppData\Roaming\Need for Speed World [2014-03-07 21:25:06 | 000,000,000 | ---D | C] -- C:\Users\Szef\pxm [2014-03-07 20:38:20 | 000,000,000 | ---D | C] -- C:\Users\Szef\AppData\Local\Electronic_Arts_Inc [2014-03-07 20:37:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Electronic Arts [2014-02-28 18:50:45 | 000,000,000 | ---D | C] -- C:\Users\Szef\AppData\Roaming\ProtectDISC [2014-02-28 18:14:44 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll [2014-02-28 18:14:44 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll [2014-02-28 18:14:44 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll [2014-02-28 18:14:43 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll [2014-02-28 18:14:42 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll [2014-02-16 13:07:39 | 000,265,072 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswndisflt.sys [2014-02-15 13:24:06 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [1 C:\Users\Szef\Documents\*.tmp files -> C:\Users\Szef\Documents\*.tmp -> ] [1 C:\Users\Szef\AppData\Local\*.tmp files -> C:\Users\Szef\AppData\Local\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-03-16 16:12:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Szef\Desktop\OTL.scr [2014-03-16 16:05:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2014-03-16 15:52:00 | 000,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2014-03-16 15:40:30 | 000,024,648 | ---- | M] () -- C:\Users\Szef\Desktop\bookmarks-2014-03-16.json [2014-03-16 15:32:00 | 000,000,284 | ---- | M] () -- C:\Windows\tasks\FoxTab.job [2014-03-16 15:30:05 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2014-03-16 13:18:49 | 000,026,352 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2014-03-16 13:18:49 | 000,026,352 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2014-03-16 13:11:39 | 000,001,028 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2014-03-16 13:11:25 | 1609,424,896 | -HS- | M] () -- C:\hiberfil.sys [2014-03-12 21:30:53 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2014-03-12 21:30:53 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2014-03-08 21:23:32 | 000,265,072 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswndisflt.sys [2014-03-08 21:22:54 | 000,775,952 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2014-03-08 21:22:54 | 000,410,784 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2014-03-08 21:22:54 | 000,270,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2014-03-08 21:22:54 | 000,180,248 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys [2014-03-08 21:22:54 | 000,079,720 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys [2014-03-08 21:22:54 | 000,067,824 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2014-03-08 21:22:54 | 000,064,168 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswStm.sys [2014-03-08 21:22:54 | 000,049,944 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys [2014-03-08 21:22:54 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2014-03-08 21:22:49 | 000,026,136 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys [2014-03-01 13:18:16 | 000,045,199 | ---- | M] () -- C:\Users\Szef\Desktop\1966290_708460765870879_1423731079_o.jpg [2014-02-28 21:24:33 | 000,002,692 | ---- | M] () -- C:\Users\Szef\Desktop\ta.png [2014-02-28 18:50:47 | 000,004,096 | ---- | M] () -- C:\Users\Public\Documents\0000638F.LCS [1 C:\Users\Szef\Documents\*.tmp files -> C:\Users\Szef\Documents\*.tmp -> ] [1 C:\Users\Szef\AppData\Local\*.tmp files -> C:\Users\Szef\AppData\Local\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-03-16 15:46:10 | 000,001,121 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2014-03-16 15:40:29 | 000,024,648 | ---- | C] () -- C:\Users\Szef\Desktop\bookmarks-2014-03-16.json [2014-03-08 21:23:00 | 000,180,248 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys [2014-03-08 21:23:00 | 000,049,944 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys [2014-03-01 13:18:16 | 000,045,199 | ---- | C] () -- C:\Users\Szef\Desktop\1966290_708460765870879_1423731079_o.jpg [2014-02-28 18:50:47 | 000,004,096 | ---- | C] () -- C:\Users\Public\Documents\0000638F.LCS [2013-12-30 00:06:45 | 000,045,076 | ---- | C] () -- C:\Windows\War3Unin.dat [2013-12-08 18:10:42 | 000,217,176 | ---- | C] () -- C:\Windows\System32\unrar.dll [2013-12-06 15:31:12 | 000,122,884 | ---- | C] () -- C:\Windows\UnGins.exe [2013-12-03 17:24:26 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl [2013-12-03 17:23:39 | 005,681,192 | ---- | C] () -- C:\Windows\System32\drivers\rtvienna.dat [2013-12-03 17:23:39 | 000,502,584 | ---- | C] () -- C:\Windows\System32\audioLibVc.dll [2013-12-03 17:23:33 | 000,673,037 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT [2013-12-03 17:23:28 | 000,188,696 | ---- | C] () -- C:\Windows\System32\AcpiServiceVnA.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013-07-14 00:30:16 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 22:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2014-03-08 21:24:10 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\AVAST Software [2013-11-13 15:52:58 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\dclogs [2013-11-03 16:32:52 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\FoxTab [2013-12-06 15:09:25 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\GameRanger [2014-02-08 12:55:31 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\Grupa IMAGE [2014-03-08 12:24:46 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\JSPKM [2013-11-04 13:59:16 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\Milestone [2013-10-27 22:22:03 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\minerd [2013-12-08 18:11:00 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\MPC-HC [2013-11-13 13:54:20 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\MSDrvCfg [2013-08-28 21:30:16 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\NapiProjekt [2014-03-07 22:54:37 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\Need for Speed World [2014-02-21 14:45:16 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\newnext.me [2013-12-31 01:08:51 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\OpenCandy [2014-03-15 11:28:38 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\Pokeing [2013-09-18 16:15:08 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\PowerISO [2014-02-28 18:50:45 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\ProtectDISC [2014-03-09 22:28:35 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\PSoul [2013-12-28 13:37:17 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\pxgclient [2013-09-18 19:27:18 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\SPORE [2013-11-13 15:55:06 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\systweak [2013-10-29 16:17:21 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\Teeworlds [2014-03-15 19:04:36 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\Tibia [2014-03-08 22:24:57 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\uTorrent [2013-10-10 13:07:14 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\wargaming.net [2013-09-16 19:47:26 | 000,000,000 | ---D | M] -- C:\Users\Szef\AppData\Roaming\Youtube Downloader HD [color=#E56717]========== Purity Check ==========[/color] < End of report >