OTL logfile created on: 2014-04-23 13:26:59 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\adam\Downloads\diagnostyka\OTL 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17041) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,73 Gb Total Physical Memory | 2,01 Gb Available Physical Memory | 53,84% Memory free 7,47 Gb Paging File | 5,72 Gb Available in Paging File | 76,61% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 149,04 Gb Total Space | 66,90 Gb Free Space | 44,89% Space Free | Partition Type: NTFS Drive D: | 148,65 Gb Total Space | 88,67 Gb Free Space | 59,65% Space Free | Partition Type: NTFS Drive S: | 14,16 Mb Total Space | 14,16 Mb Free Space | 100,00% Space Free | Partition Type: FAT Computer Name: ATTOSH | User Name: adam | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-04-23 13:13:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\adam\Downloads\diagnostyka\OTL\OTL.exe PRC - [2014-02-13 02:36:25 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2014-02-02 19:41:32 | 000,663,552 | ---- | M] (Miranda NG Team) -- C:\Zasoby\PortApps\Miranda\Miranda32.exe PRC - [2014-01-31 00:50:49 | 005,306,880 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\SkypeKit.exe PRC - [2012-11-09 03:17:14 | 001,433,200 | ---- | M] () -- C:\Zasoby\PortApps\DittoPortable\App\Ditto\Ditto.exe PRC - [2012-10-11 02:00:37 | 000,388,576 | ---- | M] (Mozilla Corporation) -- C:\Zasoby\PortApps\ThunderbirdPort\App\Thunderbird\thunderbird.exe PRC - [2011-12-25 23:26:34 | 000,178,584 | ---- | M] (PortableApps.com) -- C:\Zasoby\PortApps\ThunderbirdPort\ThunderbirdPortable.exe PRC - [2011-02-04 15:24:32 | 002,346,496 | ---- | M] () -- C:\Zasoby\PortApps\Rainlendar2\Rainlendar2.exe PRC - [2010-05-06 11:33:08 | 000,304,560 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe PRC - [2010-04-08 17:58:04 | 000,462,888 | R--- | M] (Ericsson AB) -- C:\Program Files (x86)\TOSHIBA\F3607gw Mobile Broadband Device\WMCore\mini_WMCore.exe PRC - [2010-03-03 15:42:02 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe PRC - [2010-03-03 15:41:58 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2009-07-28 21:26:42 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe PRC - [2009-03-10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-04-23 13:06:33 | 000,029,696 | ---- | M] () -- C:\Users\adam\AppData\Local\Temp\nsa93C8.tmp\registry.dll MOD - [2014-04-23 13:06:32 | 000,011,264 | ---- | M] () -- C:\Users\adam\AppData\Local\Temp\nsa93C8.tmp\System.dll MOD - [2014-04-23 13:06:32 | 000,008,704 | ---- | M] () -- C:\Users\adam\AppData\Local\Temp\nsa93C8.tmp\newadvsplash.dll MOD - [2014-02-13 02:36:39 | 003,578,992 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2014-02-02 19:41:12 | 000,009,216 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Core\StdEmail.dll MOD - [2014-02-02 19:41:10 | 000,036,352 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Core\StdUserInfo.dll MOD - [2014-02-02 19:41:08 | 000,052,736 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Core\StdFile.dll MOD - [2014-02-02 19:41:08 | 000,014,848 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Core\StdAuth.dll MOD - [2014-02-02 19:41:06 | 000,013,824 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Core\StdHelp.dll MOD - [2014-02-02 19:41:04 | 000,018,432 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Core\StdUrl.dll MOD - [2014-02-02 19:41:04 | 000,014,848 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Core\StdIdle.dll MOD - [2014-02-02 19:41:04 | 000,008,704 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Core\StdAutoAway.dll MOD - [2014-02-02 19:40:58 | 000,020,480 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Core\StdAway.dll MOD - [2014-02-02 19:40:58 | 000,010,240 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Core\StdUserOnline.dll MOD - [2014-02-02 19:39:44 | 000,033,280 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Core\StdCrypt.dll MOD - [2014-02-02 19:37:56 | 000,009,216 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\Restart.dll MOD - [2014-02-02 19:37:06 | 000,074,240 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\mir_core.dll MOD - [2014-02-02 19:35:48 | 000,187,904 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\Facebook.dll MOD - [2014-02-02 19:32:54 | 000,077,312 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Zlib.dll MOD - [2014-01-31 00:50:49 | 005,306,880 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\SkypeKit.exe MOD - [2014-01-29 20:25:38 | 005,836,800 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\Skype.dll MOD - [2014-01-29 20:23:46 | 000,167,936 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\Tlen.dll MOD - [2014-01-29 20:23:02 | 000,064,000 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\PluginUpdater.dll MOD - [2014-01-29 20:22:42 | 000,067,072 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\VersionInfo.dll MOD - [2014-01-29 20:22:40 | 000,108,032 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\DbEditorPP.dll MOD - [2014-01-29 20:22:22 | 000,051,200 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\CmdLine.dll MOD - [2014-01-29 20:20:52 | 000,139,264 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\Tipper.dll MOD - [2014-01-29 20:20:40 | 000,110,592 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\SmileyAdd.dll MOD - [2014-01-29 20:20:18 | 000,041,984 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\MenuEx.dll MOD - [2014-01-29 20:19:48 | 000,566,784 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\AdvaImg.dll MOD - [2014-01-29 20:19:46 | 000,280,576 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\Clist_nicer.dll MOD - [2014-01-29 20:19:22 | 000,301,568 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\IRC.dll MOD - [2014-01-29 20:18:54 | 000,056,832 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\ModernOpt.dll MOD - [2014-01-29 20:18:52 | 000,223,744 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\Scriver.dll MOD - [2014-01-29 20:18:50 | 000,053,248 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\Dbx_mmap.dll MOD - [2014-01-29 20:18:46 | 000,061,952 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\AVS.dll MOD - [2014-01-29 20:18:46 | 000,034,816 | ---- | M] () -- C:\Zasoby\PortApps\Miranda\Plugins\Import.dll MOD - [2012-11-09 03:17:14 | 001,433,200 | ---- | M] () -- C:\Zasoby\PortApps\DittoPortable\App\Ditto\Ditto.exe MOD - [2012-10-11 02:00:19 | 000,021,984 | ---- | M] () -- C:\Zasoby\PortApps\ThunderbirdPort\App\Thunderbird\nsldappr32v60.dll MOD - [2012-10-11 02:00:18 | 000,157,664 | ---- | M] () -- C:\Zasoby\PortApps\ThunderbirdPort\App\Thunderbird\nsldap32v60.dll MOD - [2012-10-11 02:00:14 | 002,111,456 | ---- | M] () -- C:\Zasoby\PortApps\ThunderbirdPort\App\Thunderbird\mozjs.dll MOD - [2011-02-04 15:24:38 | 000,195,584 | ---- | M] () -- C:\Zasoby\PortApps\Rainlendar2\plugins\iCalendarPlugin.dll MOD - [2011-02-04 15:24:32 | 002,346,496 | ---- | M] () -- C:\Zasoby\PortApps\Rainlendar2\Rainlendar2.exe MOD - [2010-12-12 12:58:14 | 000,502,784 | ---- | M] () -- C:\Zasoby\PortApps\Rainlendar2\wxmsw28u_xrc_vc_rny.dll MOD - [2010-12-12 12:58:00 | 000,131,584 | ---- | M] () -- C:\Zasoby\PortApps\Rainlendar2\wxbase28u_xml_vc_rny.dll MOD - [2010-12-12 12:57:56 | 000,485,376 | ---- | M] () -- C:\Zasoby\PortApps\Rainlendar2\wxmsw28u_html_vc_rny.dll MOD - [2010-12-12 12:57:44 | 000,707,584 | ---- | M] () -- C:\Zasoby\PortApps\Rainlendar2\wxmsw28u_adv_vc_rny.dll MOD - [2010-12-12 12:57:36 | 002,633,216 | ---- | M] () -- C:\Zasoby\PortApps\Rainlendar2\wxmsw28u_core_vc_rny.dll MOD - [2010-12-12 12:56:46 | 001,205,760 | ---- | M] () -- C:\Zasoby\PortApps\Rainlendar2\wxbase28u_vc_rny.dll MOD - [2010-05-23 20:20:08 | 000,012,288 | ---- | M] () -- C:\Zasoby\PortApps\Rainlendar2\lfs.dll MOD - [2010-05-23 20:20:04 | 000,126,976 | ---- | M] () -- C:\Zasoby\PortApps\Rainlendar2\lua51.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2014-03-11 12:34:10 | 000,347,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV:[b]64bit:[/b] - [2014-03-11 12:34:10 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV:[b]64bit:[/b] - [2014-03-06 10:29:14 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService) SRV:[b]64bit:[/b] - [2013-05-27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:[b]64bit:[/b] - [2010-05-25 21:08:30 | 000,489,384 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv) SRV:[b]64bit:[/b] - [2010-02-05 18:44:48 | 000,137,560 | ---- | M] (TOSHIBA Corporation) [On_Demand | Stopped] -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service) SRV:[b]64bit:[/b] - [2010-02-02 06:33:28 | 002,731,328 | ---- | M] (AuthenTec, Inc.) [Auto | Running] -- C:\Program Files\Fingerprint Sensor\ATService.exe -- (ATService) SRV:[b]64bit:[/b] - [2009-10-21 10:30:36 | 000,531,520 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\ThpSrv.exe -- (Thpsrv) SRV:[b]64bit:[/b] - [2009-07-14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2014-02-13 02:36:33 | 000,118,896 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013-09-11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010-04-12 11:45:00 | 000,196,976 | ---- | M] (TOSHIBA CORPORATION) [On_Demand | Stopped] -- C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service) SRV - [2010-04-08 17:58:04 | 000,462,888 | R--- | M] (Ericsson AB) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\F3607gw Mobile Broadband Device\WMCore\mini_WMCore.exe -- (WMCoreService) SRV - [2010-03-03 15:42:02 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2010-03-03 15:41:58 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2010-01-28 17:44:40 | 000,249,200 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe -- (cfWiMAXService) SRV - [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009-03-10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2014-03-11 09:52:30 | 000,133,928 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:[b]64bit:[/b] - [2014-01-22 09:52:10 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm) DRV:[b]64bit:[/b] - [2014-01-22 09:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus) DRV:[b]64bit:[/b] - [2013-12-02 20:45:42 | 000,017,280 | ---- | M] (Scott) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBDrv_AMD64.sys -- (usbUDisc) DRV:[b]64bit:[/b] - [2013-11-16 20:15:41 | 003,058,168 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX) DRV:[b]64bit:[/b] - [2013-10-02 04:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2013-07-24 17:02:55 | 000,034,816 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone) DRV:[b]64bit:[/b] - [2013-02-12 06:12:06 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx) DRV:[b]64bit:[/b] - [2012-08-23 16:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:[b]64bit:[/b] - [2012-03-01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2011-03-11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011-03-11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010-11-20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010-11-20 11:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus) DRV:[b]64bit:[/b] - [2010-07-28 22:10:42 | 010,610,400 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:[b]64bit:[/b] - [2010-05-20 04:31:36 | 000,770,152 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ATSwpWDF.sys -- (ATSwpWDF) DRV:[b]64bit:[/b] - [2010-04-29 07:55:42 | 000,032,768 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\androidusb.sys -- (androidusb) DRV:[b]64bit:[/b] - [2010-04-08 13:47:00 | 000,060,536 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tosrfusb.sys -- (Tosrfusb) DRV:[b]64bit:[/b] - [2010-04-07 11:51:00 | 000,214,248 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tosrfbd.sys -- (tosrfbd) DRV:[b]64bit:[/b] - [2010-03-24 14:55:56 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:[b]64bit:[/b] - [2010-03-23 18:39:00 | 000,063,488 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TosRfSnd.sys -- (TosRfSnd) DRV:[b]64bit:[/b] - [2010-03-19 17:39:00 | 000,081,920 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\risdpe64.sys -- (risdpcie) DRV:[b]64bit:[/b] - [2010-03-11 21:17:42 | 000,316,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:[b]64bit:[/b] - [2010-03-09 18:25:48 | 000,269,864 | ---- | M] (Ericsson AB) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WwanUsbMp64.sys -- (WwanUsbServ) DRV:[b]64bit:[/b] - [2010-03-03 12:30:30 | 000,030,248 | ---- | M] (Ericsson AB) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wwussf64.sys -- (ecnssndisfltr) DRV:[b]64bit:[/b] - [2010-03-03 12:30:30 | 000,026,664 | ---- | M] (Ericsson AB) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wwuss64.sys -- (ecnssndis) DRV:[b]64bit:[/b] - [2010-02-26 17:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd) DRV:[b]64bit:[/b] - [2010-02-24 11:10:18 | 000,181,248 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) DRV:[b]64bit:[/b] - [2010-02-24 11:10:16 | 000,078,336 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) DRV:[b]64bit:[/b] - [2010-02-03 07:38:30 | 000,271,872 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) DRV:[b]64bit:[/b] - [2010-01-14 15:59:36 | 000,295,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1k62x64.sys -- (e1kexpress) DRV:[b]64bit:[/b] - [2009-09-17 13:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) DRV:[b]64bit:[/b] - [2009-07-28 21:02:00 | 000,081,768 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tosrfcom.sys -- (Tosrfcom) DRV:[b]64bit:[/b] - [2009-07-24 12:33:00 | 000,026,472 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfnds.sys -- (tosrfnds) DRV:[b]64bit:[/b] - [2009-07-14 13:25:14 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ.SYS -- (TVALZ) DRV:[b]64bit:[/b] - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009-07-14 01:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM) DRV:[b]64bit:[/b] - [2009-07-13 23:12:00 | 000,019,824 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tosrfec.sys -- (tosrfec) DRV:[b]64bit:[/b] - [2009-07-10 16:53:22 | 000,096,296 | ---- | M] (Ericsson AB) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\t36wgps64.sys -- (t36wgps) DRV:[b]64bit:[/b] - [2009-06-29 17:16:20 | 000,014,784 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Thpevm.sys -- (Thpevm) DRV:[b]64bit:[/b] - [2009-06-29 11:25:22 | 000,034,880 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\thpdrv.sys -- (Thpdrv) DRV:[b]64bit:[/b] - [2009-06-26 13:51:58 | 000,432,640 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\t36gmdm.sys -- (t36gmdm) DRV:[b]64bit:[/b] - [2009-06-26 13:51:58 | 000,376,320 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\t36gmgmt.sys -- (t36gmgmt) DRV:[b]64bit:[/b] - [2009-06-26 13:51:56 | 000,329,216 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\t36gbus.sys -- (t36gbus) DRV:[b]64bit:[/b] - [2009-06-26 13:51:56 | 000,019,456 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\t36gmdfl.sys -- (t36gmdfl) DRV:[b]64bit:[/b] - [2009-06-22 18:06:38 | 000,035,008 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PGEffect.sys -- (PGEffect) DRV:[b]64bit:[/b] - [2009-06-20 04:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) DRV:[b]64bit:[/b] - [2009-06-19 11:00:00 | 000,094,336 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Tosrfhid.sys -- (Tosrfhid) DRV:[b]64bit:[/b] - [2009-06-19 10:59:00 | 000,050,664 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfbnp.sys -- (tosrfbnp) DRV:[b]64bit:[/b] - [2009-06-17 13:01:00 | 000,054,664 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tosporte.sys -- (tosporte) DRV:[b]64bit:[/b] - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2008-01-31 09:24:32 | 000,093,184 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ser2pl64.sys -- (Ser2pl) DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {CD8D7C85-9BA8-45AA-ABE5-69D99748FBCD} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{CD8D7C85-9BA8-45AA-ABE5-69D99748FBCD}: "URL" = http://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Value error. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Value error. IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-4012270732-424551172-1124687686-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com IE - HKU\S-1-5-21-4012270732-424551172-1124687686-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba.msn.com IE - HKU\S-1-5-21-4012270732-424551172-1124687686-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-4012270732-424551172-1124687686-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR IE - HKU\S-1-5-21-4012270732-424551172-1124687686-1001\..\SearchScopes\{50D12D25-7681-4C63-94D3-8AFCBDC731BF}: "URL" = http://www.amazon.co.uk/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibauk-win7-ie-search-21&index=blended&linkCode=ur2 IE - HKU\S-1-5-21-4012270732-424551172-1124687686-1001\..\SearchScopes\{D23D5FE2-845D-4427-A7B3-EDF9846DCE97}: "URL" = http://rover.ebay.com/rover/1/4908-44618-9400-8/4?satitle={searchTerms} IE - HKU\S-1-5-21-4012270732-424551172-1124687686-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1 FF - user.js - File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll File not found 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C1CA7765-44E4-452e-9D00-A04F3D434281}: FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C1CA7765-44E4-452e-9D00-A04F3D434281}: C:\Program Files\TOSHIBA\TFPU\FirefoxAddin [2013-12-21 01:13:35 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.1.1\extensions\\Components: C:\Zasoby\PortApps\ThunderbirdPort\App\thunderbird\components [2013-11-26 13:51:40 | 000,000,000 | ---D | M] [2014-02-06 23:21:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\adam\AppData\Roaming\mozilla\Extensions [2014-02-26 11:38:23 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions [2014-02-26 11:38:23 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (no name) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No CLSID value found. O2:[b]64bit:[/b] - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found. O2 - BHO: (TFPUPWDBankBHO Class) - {030AC7B6-E7EC-40F1-8FB2-C0FD344DE0B9} - C:\Program Files\TOSHIBA\TFPU\x86\TFPUPWDBankBHO.dll (TODO: ) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll () O4:[b]64bit:[/b] - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-4012270732-424551172-1124687686-1001..\Run: [Ditto] C:\Zasoby\PortApps\DittoPortable\App\Ditto\Ditto.exe () O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - Startup: C:\Users\adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\aThunderbirdP.lnk = C:\Zasoby\PortApps\ThunderbirdPort\ThunderbirdPortable.exe (PortableApps.com) O4 - Startup: C:\Users\adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DesktopOK.lnk = C:\Zasoby\PortApps\SoftwareOK\DesktopOK_x64\DesktopOK_x64.exe (Nenad Hrg SoftwareOK) O4 - Startup: C:\Users\adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\miranda.lnk = C:\Zasoby\PortApps\Miranda\Miranda32.exe (Miranda NG Team) O4 - Startup: C:\Users\adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainlendar.lnk = C:\Zasoby\PortApps\Rainlendar2\Rainlendar2.exe () O4 - Startup: C:\Users\adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\zzz Mozilla Firefox profile.lnk = C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 1 O7 - HKU\S-1-5-21-4012270732-424551172-1124687686-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-4012270732-424551172-1124687686-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000 File not found O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKU\S-1-5-21-4012270732-424551172-1124687686-1001\..Trusted Domains: homer ([]* in Zaufane witryny) O15 - HKU\S-1-5-21-4012270732-424551172-1124687686-1001\..Trusted Ranges: Range2 ([*] in Zaufane witryny) O15 - HKU\S-1-5-21-4012270732-424551172-1124687686-1001\..Trusted Ranges: Range3 ([*] in Zaufane witryny) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2523A6E9-B900-431E-94BC-A6109055DA59}: NameServer = 213.158.199.5 213.158.199.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60B13978-842E-40C8-8F09-A11A375ED361}: DhcpNameServer = 10.0.0.1 O18:[b]64bit:[/b] - Protocol\Handler\dssrequest - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\sacore - No CLSID value found O18 - Protocol\Handler\dssrequest - No CLSID value found O18 - Protocol\Handler\sacore - No CLSID value found O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-04-23 13:15:38 | 000,000,000 | ---D | C] -- C:\FRST [2014-04-23 11:15:28 | 000,000,000 | ---D | C] -- C:\Users\adam\Desktop\zelmer [2014-04-23 05:58:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Elaborate Bytes [2014-04-18 13:43:33 | 000,000,000 | ---D | C] -- C:\Users\adam\AppData\Roaming\inkscape [2014-04-17 00:29:11 | 000,000,000 | ---D | C] -- C:\Users\adam\AppData\Roaming\Thunderbird [2014-04-15 15:51:01 | 000,118,272 | ---- | C] (Zenographics, Inc.) -- C:\Windows\SysNative\ZLHP2600.DLL [2014-04-15 15:51:01 | 000,061,952 | ---- | C] (Zenographics, Inc.) -- C:\Windows\SysNative\zIMF.DLL [2014-04-15 15:51:01 | 000,049,664 | ---- | C] (Zenographics, Inc.) -- C:\Windows\SysNative\ZTAG.DLL [2014-04-15 15:51:00 | 000,127,488 | ---- | C] (Zenographics, Inc.) -- C:\Windows\SysNative\ZSPOOL.DLL [2014-04-10 03:25:33 | 000,190,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storport.sys [2014-04-10 03:25:33 | 000,027,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys [2014-04-10 03:25:33 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iologmsg.dll [2014-04-10 03:25:33 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iologmsg.dll [2014-04-10 03:25:31 | 001,163,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll [2014-04-10 03:25:31 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll [2014-04-10 03:25:31 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2014-04-10 03:25:30 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2014-04-10 03:25:30 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll [2014-04-10 03:25:30 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2014-04-10 03:25:30 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll [2014-04-10 03:25:30 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2014-04-10 03:25:30 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2014-04-10 03:25:30 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2014-04-10 03:01:04 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2014-04-10 03:01:04 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2014-04-10 03:01:02 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2014-04-10 03:00:54 | 000,586,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe [2014-04-10 03:00:54 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll [2014-04-10 03:00:54 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll [2014-04-10 03:00:53 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll [2014-04-10 03:00:52 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll [2014-04-10 03:00:52 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll [2014-04-10 03:00:52 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll [2014-04-10 03:00:51 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll [2014-04-10 03:00:51 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll [2014-04-10 03:00:50 | 000,628,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2014-04-10 03:00:49 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2014-04-10 03:00:49 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2014-04-10 03:00:49 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll [2014-04-10 03:00:49 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll [2014-04-10 03:00:49 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll [2014-04-10 03:00:49 | 000,032,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll [2014-04-10 03:00:46 | 000,846,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll [2014-04-10 03:00:46 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll [2014-04-10 03:00:46 | 000,592,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll [2014-04-10 03:00:46 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe [2014-04-10 03:00:46 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll [2014-04-10 03:00:46 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll [2014-04-10 03:00:45 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe [2014-04-10 03:00:42 | 001,967,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2014-04-10 03:00:41 | 002,043,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2014-04-10 03:00:38 | 005,784,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2014-04-04 13:06:38 | 000,000,000 | ---D | C] -- C:\Program Files\Recuva [2014-04-01 09:06:27 | 000,000,000 | ---D | C] -- C:\Users\adam\Desktop\creeper cw3 [2014-04-01 03:50:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Steam [2014-04-01 03:50:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Creeper World 3 Arc Eternal [2014-03-26 10:31:32 | 000,000,000 | ---D | C] -- C:\Users\adam\Desktop\zdjęcia rodzinne do zgrania lub sprawdzenia [5 C:\*.tmp files -> C:\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-04-23 13:13:24 | 000,020,368 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2014-04-23 13:13:24 | 000,020,368 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2014-04-23 13:10:38 | 001,669,190 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2014-04-23 13:10:38 | 000,740,348 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2014-04-23 13:10:38 | 000,654,140 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2014-04-23 13:10:38 | 000,155,890 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2014-04-23 13:10:38 | 000,122,012 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2014-04-23 13:06:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2014-04-23 13:06:05 | 3007,647,744 | -HS- | M] () -- C:\hiberfil.sys [2014-04-23 12:36:42 | 000,001,647 | ---- | M] () -- C:\Users\adam\Desktop\Advanced Uninstaller PRO 11.lnk [2014-04-18 13:44:29 | 000,000,738 | ---- | M] () -- C:\Users\adam\.recently-used.xbel [2014-04-17 14:37:41 | 000,012,447 | ---- | M] () -- C:\Users\adam\Desktop\spis lokali wojciecha 16 oficyna.ods [2014-04-16 09:42:52 | 000,001,042 | ---- | M] () -- C:\Users\adam\Desktop\Nowe działania.lnk [2014-04-14 09:37:12 | 002,160,997 | ---- | M] () -- C:\Users\adam\Desktop\skan potw. kwiecien.png [2014-04-11 14:06:14 | 000,901,343 | ---- | M] () -- C:\Users\adam\Desktop\Pilot Rolety Instrukcja.pdf [2014-04-03 03:01:02 | 000,002,155 | ---- | M] () -- C:\Windows\epplauncher.mif [2014-04-02 09:48:49 | 000,001,243 | ---- | M] () -- C:\Users\adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\zzz Mozilla Firefox profile.lnk [2014-03-31 22:12:34 | 000,001,243 | ---- | M] () -- C:\Users\adam\Desktop\zzz Mozilla Firefox profile.lnk [2014-03-27 05:05:57 | 000,083,658 | ---- | M] () -- C:\Users\adam\Desktop\Biuro Nieruchomości 2.jpg [2014-03-27 04:53:05 | 000,141,238 | ---- | M] () -- C:\Users\adam\Desktop\Biuro Nieruchomości 3.jpg [2014-03-27 04:49:09 | 000,106,471 | ---- | M] () -- C:\Users\adam\Desktop\Burg1.jpg [5 C:\*.tmp files -> C:\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-04-23 12:36:42 | 000,001,647 | ---- | C] () -- C:\Users\adam\Desktop\Advanced Uninstaller PRO 11.lnk [2014-04-18 13:44:29 | 000,000,738 | ---- | C] () -- C:\Users\adam\.recently-used.xbel [2014-04-17 14:09:17 | 000,012,447 | ---- | C] () -- C:\Users\adam\Desktop\spis lokali wojciecha 16 oficyna.ods [2014-04-16 09:41:55 | 000,001,042 | ---- | C] () -- C:\Users\adam\Desktop\Nowe działania.lnk [2014-04-15 15:51:01 | 000,805,928 | ---- | C] () -- C:\Windows\SysNative\hp2600n.img [2014-04-15 15:51:00 | 000,496,128 | ---- | C] () -- C:\Windows\SysNative\zSHP2600.EXE [2014-04-14 09:36:32 | 002,160,997 | ---- | C] () -- C:\Users\adam\Desktop\skan potw. kwiecien.png [2014-04-11 14:22:09 | 000,901,343 | ---- | C] () -- C:\Users\adam\Desktop\Pilot Rolety Instrukcja.pdf [2014-04-02 09:48:49 | 000,001,243 | ---- | C] () -- C:\Users\adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\zzz Mozilla Firefox profile.lnk [2014-03-31 22:12:05 | 000,001,243 | ---- | C] () -- C:\Users\adam\Desktop\zzz Mozilla Firefox profile.lnk [2014-03-27 04:53:05 | 000,141,238 | ---- | C] () -- C:\Users\adam\Desktop\Biuro Nieruchomości 3.jpg [2014-03-27 04:50:57 | 000,083,658 | ---- | C] () -- C:\Users\adam\Desktop\Biuro Nieruchomości 2.jpg [2014-03-27 04:49:08 | 000,106,471 | ---- | C] () -- C:\Users\adam\Desktop\Burg1.jpg [2013-12-26 17:15:25 | 000,000,057 | ---- | C] () -- C:\Program Files (x86)\GPACgpac_pl.m3u [2013-12-24 10:06:56 | 000,000,470 | RHS- | C] () -- C:\Users\adam\ntuser.pol [2013-12-04 12:09:58 | 000,051,576 | ---- | C] () -- C:\Windows\SysWow64\drvinstaller_IA64.exe [2013-12-04 12:09:58 | 000,034,168 | ---- | C] () -- C:\Windows\SysWow64\drvinstaller_X86.exe [2013-12-04 12:09:58 | 000,027,512 | ---- | C] () -- C:\Windows\SysWow64\drvinstaller_X64.exe [2013-12-04 12:09:57 | 000,233,538 | ---- | C] () -- C:\Windows\SysWow64\LangPlg.dll [2013-12-04 12:09:57 | 000,102,400 | ---- | C] () -- C:\Windows\SysWow64\KSDecode.dll [2013-12-04 12:09:57 | 000,094,208 | ---- | C] () -- C:\Windows\SysWow64\single.dll [2013-12-04 12:09:57 | 000,061,440 | ---- | C] () -- C:\Windows\SysWow64\sdata.dll [2013-12-04 12:09:57 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\ImgDecode.dll [2013-12-04 12:09:57 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\eFex.dll [2013-12-04 12:09:57 | 000,040,960 | ---- | C] () -- C:\Windows\SysWow64\Config.dll [2013-12-04 12:09:57 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\roottools.dll [2013-12-04 12:09:57 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\Phoenix_Fes.dll [2013-12-04 12:09:57 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\idfactory.dll [2013-12-04 12:09:57 | 000,032,768 | ---- | C] () -- C:\Windows\SysWow64\encode.dll [2013-12-04 12:09:57 | 000,032,768 | ---- | C] () -- C:\Windows\SysWow64\crc32.dll [2013-12-04 12:09:57 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\AwPluginVector.dll [2013-12-04 12:09:57 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\Phoenix_Elf.dll [2013-12-04 12:09:57 | 000,004,096 | ---- | C] () -- C:\Windows\SysWow64\LiveSuit.dat [2013-12-04 12:09:55 | 001,302,528 | ---- | C] () -- C:\Windows\SysWow64\LiveSuit.exe [2013-12-04 12:09:55 | 000,094,208 | ---- | C] () -- C:\Windows\SysWow64\APipe.dll [2013-12-04 12:09:55 | 000,061,440 | ---- | C] () -- C:\Windows\SysWow64\ACmd.dll [2013-12-04 12:09:54 | 000,307,200 | ---- | C] () -- C:\Windows\SysWow64\ZipModule.dll [2013-11-22 20:32:23 | 000,000,600 | ---- | C] () -- C:\Users\adam\AppData\Local\PUTTY.RND [2013-11-20 01:21:33 | 001,641,796 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013-11-19 01:10:26 | 000,007,603 | ---- | C] () -- C:\Users\adam\AppData\Local\resmon.resmoncfg [2013-11-16 20:22:28 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2013-07-26 04:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013-07-26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2013-11-18 16:49:07 | 000,000,000 | ---D | M] -- C:\Users\adam\AppData\Roaming\.mono [2014-04-01 03:57:39 | 000,000,000 | ---D | M] -- C:\Users\adam\AppData\Roaming\CreeperWorld3 [2014-04-18 13:43:33 | 000,000,000 | ---D | M] -- C:\Users\adam\AppData\Roaming\inkscape [2013-11-19 00:35:04 | 000,000,000 | ---D | M] -- C:\Users\adam\AppData\Roaming\LibreOffice [2013-12-20 23:11:05 | 000,000,000 | ---D | M] -- C:\Users\adam\AppData\Roaming\SoftGrid Client [2013-11-16 20:40:19 | 000,000,000 | ---D | M] -- C:\Users\adam\AppData\Roaming\TFPU [2014-04-17 03:52:00 | 000,000,000 | ---D | M] -- C:\Users\adam\AppData\Roaming\Thunderbird [2013-11-16 20:46:59 | 000,000,000 | ---D | M] -- C:\Users\adam\AppData\Roaming\Toshiba [2013-11-20 01:22:33 | 000,000,000 | ---D | M] -- C:\Users\adam\AppData\Roaming\TP [color=#E56717]========== Purity Check ==========[/color] < End of report >