OTL logfile created on: 2014-08-08 19:45:25 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 6,00 Gb Total Physical Memory | 2,63 Gb Available Physical Memory | 43,80% Memory free 12,00 Gb Paging File | 7,81 Gb Available in Paging File | 65,13% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 1000,00 Gb Total Space | 887,07 Gb Free Space | 88,71% Space Free | Partition Type: NTFS Drive D: | 862,92 Gb Total Space | 305,60 Gb Free Space | 35,41% Space Free | Partition Type: NTFS Computer Name: USER-NTT | User Name: User | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-08-08 19:22:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\User\Downloads\OTL.exe PRC - [2014-08-07 21:22:45 | 000,068,096 | ---- | M] () -- C:\Users\User\AppData\Local\TeamSpeak 3 Client\plugins\ts3overlay\InstallHook.exe PRC - [2014-08-06 10:37:26 | 003,600,728 | ---- | M] (Electronic Arts) -- C:\Program Files (x86)\Origin\Origin.exe PRC - [2014-08-06 10:37:26 | 001,821,552 | ---- | M] (Electronic Arts) -- C:\Program Files (x86)\Origin\OriginClientService.exe PRC - [2014-07-30 17:45:02 | 031,240,760 | ---- | M] (Electronic Arts) -- C:\Program Files (x86)\Origin Games\FIFA World\fifaworld.exe PRC - [2014-07-21 23:02:50 | 035,464,216 | ---- | M] (Dropbox, Inc.) -- C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe PRC - [2014-05-13 14:29:30 | 003,814,736 | ---- | M] (LogMeIn Inc.) -- C:\Program Files (x86)\LogMeIn Hamachiii\hamachi-2-ui.exe PRC - [2014-02-25 19:38:48 | 000,105,448 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe PRC - [2013-12-04 04:48:06 | 000,863,184 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe PRC - [2013-11-19 17:27:26 | 000,728,064 | ---- | M] () -- c:\ProgramData\QuickSet\Sk-Enhancer\Sk-Enhancer.exe PRC - [2013-10-30 19:50:57 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2013-07-27 10:42:15 | 001,028,896 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe PRC - [2013-07-27 10:36:26 | 001,889,568 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe PRC - [2013-06-21 05:15:56 | 000,413,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2011-01-10 14:49:20 | 000,014,848 | ---- | M] () -- C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe PRC - [2010-04-22 15:05:26 | 001,011,712 | ---- | M] (Gigabyte Technology CO., LTD.) -- C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe PRC - [2010-01-19 04:31:26 | 000,072,304 | R--- | M] () -- C:\Windows\SysWOW64\XSrvSetup.exe PRC - [2009-11-20 13:17:54 | 000,106,496 | ---- | M] (NEC Electronics Corporation) -- C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe PRC - [2009-10-15 14:06:46 | 000,223,464 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe PRC - [2009-10-15 14:06:42 | 000,375,000 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe PRC - [2009-10-13 16:39:46 | 000,114,688 | ---- | M] (Gigabyte Technology CO., LTD.) -- C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe PRC - [2009-06-17 16:13:06 | 000,068,136 | ---- | M] () -- C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe PRC - [2005-02-17 07:15:20 | 000,581,632 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-08-08 18:07:49 | 000,043,008 | ---- | M] () -- c:\users\user\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpbkav6g.dll MOD - [2014-08-07 21:22:45 | 000,068,096 | ---- | M] () -- C:\Users\User\AppData\Local\TeamSpeak 3 Client\plugins\ts3overlay\InstallHook.exe MOD - [2014-08-06 10:37:25 | 000,962,560 | ---- | M] () -- C:\Program Files (x86)\Origin\platforms\qwindows.dll MOD - [2014-08-06 10:37:12 | 000,302,592 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qtiff.dll MOD - [2014-08-06 10:37:12 | 000,261,632 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qmng.dll MOD - [2014-08-06 10:37:12 | 000,217,088 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qjpeg.dll MOD - [2014-08-06 10:37:12 | 000,025,088 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qico.dll MOD - [2014-08-06 10:37:12 | 000,024,064 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qgif.dll MOD - [2014-08-06 10:37:12 | 000,019,968 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qtga.dll MOD - [2014-08-06 10:37:12 | 000,018,944 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qwbmp.dll MOD - [2014-07-21 22:53:38 | 003,610,624 | ---- | M] () -- C:\Users\User\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll MOD - [2013-12-04 04:48:04 | 000,399,312 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll MOD - [2013-12-04 04:48:03 | 013,586,896 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll MOD - [2013-12-04 04:48:02 | 004,055,504 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll MOD - [2013-12-04 04:47:11 | 000,702,416 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libglesv2.dll MOD - [2013-12-04 04:47:11 | 000,099,792 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libegl.dll MOD - [2013-12-04 04:47:08 | 001,619,408 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll MOD - [2013-10-19 01:55:02 | 025,100,288 | ---- | M] () -- C:\Users\User\AppData\Roaming\Dropbox\bin\libcef.dll MOD - [2013-08-07 21:25:24 | 000,093,696 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll MOD - [2013-07-27 10:51:04 | 000,013,088 | ---- | M] () -- c:\progra~2\nvidia~1\nvstre~1\detoured.dll MOD - [2009-06-27 10:11:12 | 000,503,202 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\sqlite3.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2014-03-11 13:34:10 | 000,347,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV:[b]64bit:[/b] - [2014-03-11 13:34:10 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV:[b]64bit:[/b] - [2013-11-06 21:06:09 | 000,551,896 | ---- | M] (Protection Technology) [Auto | Stopped] -- C:\Windows\SysNative\appdrvrem01.exe -- (appdrvrem01) SRV:[b]64bit:[/b] - [2013-07-27 10:50:22 | 014,984,480 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc) SRV:[b]64bit:[/b] - [2013-05-27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:[b]64bit:[/b] - [2010-04-06 16:30:38 | 000,031,272 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\AppleChargerSrv.exe -- (AppleChargerSrv) SRV - [2014-07-18 20:13:20 | 000,009,216 | ---- | M] (Hi-Rez Studios) [Auto | Running] -- D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService) SRV - [2014-07-16 04:28:18 | 000,542,912 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2014-05-22 16:18:48 | 000,093,048 | ---- | M] (EasyAntiCheat Ltd) [On_Demand | Stopped] -- C:\Windows\SysWOW64\EasyAntiCheat.exe -- (EasyAntiCheat) SRV - [2014-05-13 14:29:26 | 002,228,048 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachiii\hamachi-2.exe -- (Hamachi2Svc) SRV - [2014-02-25 19:38:48 | 000,105,448 | ---- | M] (Razer Inc.) [Auto | Running] -- C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe -- (RzKLService) SRV - [2013-11-16 12:23:59 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\srvany.exe -- (KMService) SRV - [2013-10-30 19:50:57 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2013-10-23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2013-09-11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2013-07-27 10:36:26 | 001,889,568 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2013-06-26 18:33:36 | 000,088,424 | ---- | M] (Perfect World Entertainment Inc) [On_Demand | Stopped] -- D:\Gry\Perfect World Entertainment\Arc\ArcService.exe -- (ArcService) SRV - [2013-06-21 05:15:56 | 000,413,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2011-01-10 14:49:20 | 000,014,848 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe -- (DokanMounter) SRV - [2010-01-19 04:31:26 | 000,072,304 | R--- | M] () [Auto | Running] -- C:\Windows\SysWOW64\XSrvSetup.exe -- (JMB36X) SRV - [2009-10-15 14:06:46 | 000,223,464 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe -- (BCUService) SRV - [2009-10-13 16:39:46 | 000,114,688 | ---- | M] (Gigabyte Technology CO., LTD.) [Auto | Running] -- C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe -- (Smart TimeLock) SRV - [2009-06-17 16:13:06 | 000,068,136 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe -- (DES2 Service) SRV - [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2014-03-11 10:52:30 | 000,133,928 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:[b]64bit:[/b] - [2013-11-06 21:06:09 | 003,854,000 | ---- | M] (Protection Technology) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\appdrv01.sys -- (appdrv01) DRV:[b]64bit:[/b] - [2013-07-01 07:43:01 | 000,303,616 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:[b]64bit:[/b] - [2013-07-01 07:42:41 | 000,035,328 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:[b]64bit:[/b] - [2013-05-14 21:28:40 | 000,039,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible) DRV:[b]64bit:[/b] - [2013-02-25 07:27:45 | 000,194,848 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:[b]64bit:[/b] - [2012-03-01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2011-05-13 04:21:04 | 000,177,640 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm) DRV:[b]64bit:[/b] - [2011-05-13 04:21:04 | 000,146,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadserd.sys -- (ssadserd) DRV:[b]64bit:[/b] - [2011-05-13 04:21:02 | 000,157,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus) DRV:[b]64bit:[/b] - [2011-05-13 04:21:02 | 000,036,328 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadadb.sys -- (androidusb) DRV:[b]64bit:[/b] - [2011-05-13 04:21:02 | 000,016,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl) DRV:[b]64bit:[/b] - [2011-01-10 14:51:40 | 000,120,408 | ---- | M] (Windows (R) Win 7 DDK provider) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\dokan.sys -- (Dokan) DRV:[b]64bit:[/b] - [2010-11-20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010-11-20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010-05-24 11:02:34 | 000,065,808 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ifP52x64.sys -- (IFCoEVB) DRV:[b]64bit:[/b] - [2010-05-24 11:02:30 | 000,352,528 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ifM52x64.sys -- (IFCoEMP) DRV:[b]64bit:[/b] - [2010-04-22 15:08:14 | 000,021,544 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AppleCharger.sys -- (AppleCharger) DRV:[b]64bit:[/b] - [2010-04-07 20:57:04 | 000,074,296 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2010-04-07 20:57:04 | 000,029,240 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010-03-04 15:43:00 | 000,346,144 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2010-03-03 19:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:[b]64bit:[/b] - [2010-02-26 16:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd) DRV:[b]64bit:[/b] - [2010-01-27 10:58:38 | 000,115,312 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID) DRV:[b]64bit:[/b] - [2010-01-21 14:00:02 | 000,179,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iSSetup.sys -- (iSSetup) DRV:[b]64bit:[/b] - [2009-11-20 13:16:02 | 000,177,152 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) DRV:[b]64bit:[/b] - [2009-11-20 13:15:58 | 000,075,776 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) DRV:[b]64bit:[/b] - [2009-11-16 07:45:26 | 000,042,192 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qd262x64.sys -- (ioatdma2) DRV:[b]64bit:[/b] - [2009-11-16 07:45:22 | 000,040,144 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qd162x64.sys -- (ioatdma1) DRV:[b]64bit:[/b] - [2009-11-16 07:27:44 | 000,046,792 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ioatdma.sys -- (ioatdma) DRV:[b]64bit:[/b] - [2009-09-18 03:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) DRV:[b]64bit:[/b] - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009-07-14 02:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam) DRV:[b]64bit:[/b] - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2009-03-18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi) DRV:[b]64bit:[/b] - [2008-02-12 04:59:18 | 000,297,496 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\VMM.sys -- (vmm) DRV:[b]64bit:[/b] - [2008-02-05 02:50:42 | 000,079,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VMNetSrv.sys -- (VPCNetS2) DRV:[b]64bit:[/b] - [2007-03-20 17:03:58 | 000,056,320 | ---- | M] (Winbond Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wbondir.sys -- (wbondir) DRV - [2014-08-08 18:07:19 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\gdrv.sys -- (gdrv) DRV - [2014-02-03 21:38:16 | 000,030,528 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\GVTDrv64.sys -- (GVTDrv64) DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) DRV - [2003-09-06 15:37:22 | 000,062,656 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\SysWOW64\drivers\prohlp02.sys -- (prohlp02) DRV - [2003-09-06 14:27:06 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\SysWOW64\drivers\sfhlp01.sys -- (sfhlp01) DRV - [2003-09-06 14:25:52 | 000,051,744 | ---- | M] (Protection Technology) [Kernel | System | Stopped] -- C:\Windows\SysWOW64\drivers\prodrv06.sys -- (prodrv06) DRV - [2003-09-06 14:22:08 | 000,006,944 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\SysWOW64\drivers\prosync1.sys -- (prosync1) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/ IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.bing.com/search?q={searchTerms} IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/search?q={searchTerms} IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://start.qone8.com/web/?type=ds&ts=1382701688&from=cor&uid=_&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/ IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://start.qone8.com/web/?type=ds&ts=1382701688&from=cor&uid=_&q={searchTerms} IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.pur-esult.info/?l=1&q={searchTerms}&pid=724&r=2013/11/19&hid=1511377463245664931&lg=EN&cc=PL IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2496199684-987935729-1689624564-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKU\S-1-5-21-2496199684-987935729-1689624564-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.ntt.pl [binary data] IE - HKU\S-1-5-21-2496199684-987935729-1689624564-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://onet.pl/ IE - HKU\S-1-5-21-2496199684-987935729-1689624564-1000\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.) IE - HKU\S-1-5-21-2496199684-987935729-1689624564-1000\..\SearchScopes,DefaultScope = {0490FAD2-0AF4-4a9b-A26D-5061D4E4ED6B} IE - HKU\S-1-5-21-2496199684-987935729-1689624564-1000\..\SearchScopes\{0490FAD2-0AF4-4a9b-A26D-5061D4E4ED6B}: "URL" = http://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBD IE - HKU\S-1-5-21-2496199684-987935729-1689624564-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR IE - HKU\S-1-5-21-2496199684-987935729-1689624564-1000\..\SearchScopes\{53BCB2A7-15DE-47b6-B1A4-F7955F762B2A}: "URL" = http://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=1975384696&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=pl&q={searchTerms} IE - HKU\S-1-5-21-2496199684-987935729-1689624564-1000\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.pur-esult.info/?l=1&q={searchTerms}&pid=724&r=2013/11/19&hid=1511377463245664931&lg=EN&cc=PL IE - HKU\S-1-5-21-2496199684-987935729-1689624564-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.3.0: C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@perfectworld.com/npArcPlayNowPlugin: D:\Gry\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\User\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\User\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\User\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\User\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\User\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}, CHR - homepage: http://google.com/ CHR - Extension: Google Wallet = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\ O1 HOSTS File: ([2014-01-17 15:58:05 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL (Microsoft Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [Nvtmru] C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.) O4 - HKLM..\Run: [fst_pl_31] File not found O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachiii\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation) O4 - HKU\S-1-5-21-2496199684-987935729-1689624564-1000..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup File not found O4 - HKU\S-1-5-21-2496199684-987935729-1689624564-1001..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-2496199684-987935729-1689624564-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2496199684-987935729-1689624564-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2496199684-987935729-1689624564-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\S-1-5-21-2496199684-987935729-1689624564-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000 File not found O8:[b]64bit:[/b] - Extra context menu item: Wyślij &do programu OneNote - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Wyślij &do programu OneNote - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105 File not found O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{14E4D53A-88D0-4D85-89A1-00DC227EAB88}: DhcpNameServer = 8.8.8.8 8.8.4.4 O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O20:[b]64bit:[/b] - AppInit_DLLs: (c:\progra~1\nvidia~1\nvstre~1\rxinput.dll) - c:\Program Files\NVIDIA Corporation\NvStreamSrv\rxinput.dll (NVIDIA Corporation) O20 - AppInit_DLLs: (c:\progra~2\nvidia~1\nvstre~1\rxinput.dll) - c:\progra~2\nvidia~1\nvstre~1\rxinput.dll (NVIDIA Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = ComFile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-08-08 18:22:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AllSaver [2014-08-05 19:34:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AoC 1.0e Patch [2014-08-05 19:17:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Games [2014-08-04 08:28:42 | 000,000,000 | ---D | C] -- C:\ProgramData\AllSaver [2014-07-31 10:40:08 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server [2014-07-31 10:40:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RivaTuner Statistics Server [2014-07-31 10:36:02 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner [2014-07-31 10:35:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSI Afterburner [2014-07-30 20:12:08 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\ArcheAge [2014-07-30 20:12:08 | 000,000,000 | ---D | C] -- C:\ArcheAge [2014-07-25 13:23:49 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Glyph [2014-07-25 13:23:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph [2014-07-25 13:23:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Glyph [2014-07-25 13:05:26 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Razer_Inc [2014-07-25 13:05:13 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\Razer [2014-07-25 13:04:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer [2014-07-16 16:02:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Riot Games [2014-07-16 08:18:48 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Origin [2014-07-16 08:15:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Origin [2014-07-12 13:49:47 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\egzek [2014-07-11 15:05:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios [2014-07-11 09:48:46 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Awesomium [2014-07-11 09:48:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Hi-Rez Studios [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-08-08 19:40:00 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2496199684-987935729-1689624564-1000UA.job [2014-08-08 19:35:01 | 000,001,044 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2014-08-08 18:53:48 | 000,001,185 | ---- | M] () -- C:\Users\Public\Desktop\EA Sports FIFA World.lnk [2014-08-08 18:41:16 | 000,015,152 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2014-08-08 18:41:16 | 000,015,152 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2014-08-08 18:16:01 | 000,000,286 | ---- | M] () -- C:\Windows\tasks\bench-Updater removing.job [2014-08-08 18:07:19 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\Windows\gdrv.sys [2014-08-08 18:06:48 | 000,001,040 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2014-08-08 18:06:48 | 000,000,450 | -H-- | M] () -- C:\Windows\tasks\Sk-Enhancer-S-5902107913.job [2014-08-08 18:06:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2014-08-08 18:05:46 | 535,605,247 | -HS- | M] () -- C:\hiberfil.sys [2014-08-07 21:51:00 | 000,000,342 | ---- | M] () -- C:\Windows\tasks\bench-sys.job [2014-08-06 10:24:31 | 000,428,816 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2014-08-05 19:33:13 | 000,002,058 | ---- | M] () -- C:\Users\Public\Desktop\The Conquerors.lnk [2014-08-05 19:29:17 | 000,002,178 | ---- | M] () -- C:\Users\Public\Desktop\Age of Empires II.lnk [2014-08-05 15:40:00 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2496199684-987935729-1689624564-1000Core.job [2014-07-31 10:39:49 | 000,001,086 | ---- | M] () -- C:\Users\User\Desktop\MSI Afterburner.lnk [2014-07-26 12:25:52 | 001,669,190 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2014-07-26 12:25:52 | 000,741,800 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2014-07-26 12:25:52 | 000,654,630 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2014-07-26 12:25:52 | 000,156,414 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2014-07-26 12:25:52 | 000,122,502 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2014-07-26 12:19:54 | 005,355,458 | ---- | M] () -- C:\Users\User\Desktop\Enej - Vitre hnatyj.mp3 [2014-07-26 12:18:01 | 008,466,423 | ---- | M] () -- C:\Users\User\Desktop\happysad - Ojczyzna (official video).mp3 [2014-07-25 13:26:06 | 000,000,716 | ---- | M] () -- C:\Users\User\Desktop\Archeage Beta.lnk [2014-07-25 13:23:50 | 000,000,590 | ---- | M] () -- C:\Users\User\Desktop\Glyph.lnk [2014-07-25 11:26:53 | 000,001,048 | ---- | M] () -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-07-19 10:57:21 | 000,000,003 | ---- | M] () -- C:\Windows\SysNative\HRUPPROG.EXIT [2014-07-16 11:43:35 | 000,000,222 | ---- | M] () -- C:\Users\User\Desktop\Unturned.url [2014-07-16 08:15:59 | 000,000,979 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk [2014-07-12 11:34:58 | 000,461,824 | ---- | M] () -- C:\Windows\SysWow64\libfreetype-6.dll [2014-07-12 11:34:58 | 000,100,352 | ---- | M] () -- C:\Windows\SysWow64\zlib1.dll [2014-07-12 11:34:58 | 000,027,136 | ---- | M] () -- C:\Windows\SysWow64\SDL_ttf.dll [2014-07-12 11:28:22 | 000,328,192 | ---- | M] () -- C:\Windows\SysWow64\libFLAC-8.dll [2014-07-12 11:28:22 | 000,263,168 | ---- | M] () -- C:\Windows\SysWow64\libmikmod-2.dll [2014-07-12 11:28:22 | 000,209,408 | ---- | M] () -- C:\Windows\SysWow64\smpeg.dll [2014-07-12 11:28:22 | 000,163,840 | ---- | M] () -- C:\Windows\SysWow64\libvorbis-0.dll [2014-07-12 11:28:22 | 000,160,256 | ---- | M] () -- C:\Windows\SysWow64\SDL_mixer.dll [2014-07-12 11:28:22 | 000,036,352 | ---- | M] () -- C:\Windows\SysWow64\libvorbisfile-3.dll [2014-07-12 11:28:22 | 000,024,064 | ---- | M] () -- C:\Windows\SysWow64\libogg-0.dll [2014-07-12 11:26:35 | 000,408,064 | ---- | M] () -- C:\Windows\SysWow64\libtiff-5.dll [2014-07-12 11:26:35 | 000,204,288 | ---- | M] () -- C:\Windows\SysWow64\libjpeg-8.dll [2014-07-12 11:26:35 | 000,180,224 | ---- | M] () -- C:\Windows\SysWow64\libwebp-2.dll [2014-07-12 11:26:35 | 000,151,552 | ---- | M] () -- C:\Windows\SysWow64\libpng15-15.dll [2014-07-12 11:26:35 | 000,051,200 | ---- | M] () -- C:\Windows\SysWow64\SDL_image.dll [2014-07-11 16:54:50 | 000,001,568 | ---- | M] () -- C:\Users\User\Desktop\KSP.exe — skrót.lnk [2014-07-11 15:05:02 | 000,000,915 | ---- | M] () -- C:\Users\Public\Desktop\Smite.lnk [2014-07-11 15:05:02 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-08-05 19:33:13 | 000,002,058 | ---- | C] () -- C:\Users\Public\Desktop\The Conquerors.lnk [2014-08-05 19:29:17 | 000,002,178 | ---- | C] () -- C:\Users\Public\Desktop\Age of Empires II.lnk [2014-07-31 10:36:02 | 000,001,086 | ---- | C] () -- C:\Users\User\Desktop\MSI Afterburner.lnk [2014-07-31 10:35:13 | 029,444,696 | ---- | C] () -- C:\Users\User\Desktop\MSIAfterburnerSetup301.exe [2014-07-26 12:19:54 | 005,355,458 | ---- | C] () -- C:\Users\User\Desktop\Enej - Vitre hnatyj.mp3 [2014-07-26 12:17:35 | 008,466,423 | ---- | C] () -- C:\Users\User\Desktop\happysad - Ojczyzna (official video).mp3 [2014-07-25 13:26:06 | 000,000,716 | ---- | C] () -- C:\Users\User\Desktop\Archeage Beta.lnk [2014-07-25 13:23:50 | 000,000,590 | ---- | C] () -- C:\Users\User\Desktop\Glyph.lnk [2014-07-19 10:57:21 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\HRUPPROG.EXIT [2014-07-16 11:43:35 | 000,000,222 | ---- | C] () -- C:\Users\User\Desktop\Unturned.url [2014-07-16 08:26:43 | 000,001,185 | ---- | C] () -- C:\Users\Public\Desktop\EA Sports FIFA World.lnk [2014-07-16 08:15:59 | 000,000,979 | ---- | C] () -- C:\Users\Public\Desktop\Origin.lnk [2014-07-12 20:48:54 | 000,461,824 | ---- | C] () -- C:\Windows\SysWow64\libfreetype-6.dll [2014-07-12 20:48:54 | 000,408,064 | ---- | C] () -- C:\Windows\SysWow64\libtiff-5.dll [2014-07-12 20:48:54 | 000,328,192 | ---- | C] () -- C:\Windows\SysWow64\libFLAC-8.dll [2014-07-12 20:48:54 | 000,263,168 | ---- | C] () -- C:\Windows\SysWow64\libmikmod-2.dll [2014-07-12 20:48:54 | 000,209,408 | ---- | C] () -- C:\Windows\SysWow64\smpeg.dll [2014-07-12 20:48:54 | 000,204,288 | ---- | C] () -- C:\Windows\SysWow64\libjpeg-8.dll [2014-07-12 20:48:54 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\libwebp-2.dll [2014-07-12 20:48:54 | 000,163,840 | ---- | C] () -- C:\Windows\SysWow64\libvorbis-0.dll [2014-07-12 20:48:54 | 000,160,256 | ---- | C] () -- C:\Windows\SysWow64\SDL_mixer.dll [2014-07-12 20:48:54 | 000,151,552 | ---- | C] () -- C:\Windows\SysWow64\libpng15-15.dll [2014-07-12 20:48:54 | 000,100,352 | ---- | C] () -- C:\Windows\SysWow64\zlib1.dll [2014-07-12 20:48:54 | 000,051,200 | ---- | C] () -- C:\Windows\SysWow64\SDL_image.dll [2014-07-12 20:48:54 | 000,036,352 | ---- | C] () -- C:\Windows\SysWow64\libvorbisfile-3.dll [2014-07-12 20:48:54 | 000,027,136 | ---- | C] () -- C:\Windows\SysWow64\SDL_ttf.dll [2014-07-12 20:48:54 | 000,024,064 | ---- | C] () -- C:\Windows\SysWow64\libogg-0.dll [2014-07-11 16:54:50 | 000,001,568 | ---- | C] () -- C:\Users\User\Desktop\KSP.exe — skrót.lnk [2014-07-11 15:31:01 | 000,303,616 | ---- | C] () -- C:\Windows\SysWow64\SDL.dll [2014-07-11 15:05:02 | 000,000,915 | ---- | C] () -- C:\Users\Public\Desktop\Smite.lnk [2014-07-11 15:05:02 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk [2014-07-07 13:00:10 | 000,303,616 | ---- | C] () -- C:\Windows\SDL.dll [2014-03-28 16:28:39 | 000,034,816 | ---- | C] () -- C:\Users\User\AppData\Roaming\RZR_006016d94454bf923880d9f9962c.db [2014-01-15 21:13:43 | 000,000,266 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2013-12-04 15:22:28 | 000,001,031 | ---- | C] () -- C:\Users\User\AppData\Local\recently-used.xbel [2013-11-16 12:24:36 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe [2013-10-30 14:39:45 | 000,290,184 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2013-10-30 14:39:44 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2013-10-25 13:54:56 | 000,000,600 | ---- | C] () -- C:\Users\User\AppData\Local\PUTTY.RND [2013-10-07 20:39:49 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini [2013-08-13 21:35:52 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2013-08-13 21:35:52 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2013-08-13 21:35:52 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2013-08-13 21:35:52 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2013-08-13 21:35:52 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2013-08-13 21:25:01 | 000,000,004 | ---- | C] () -- C:\Users\User\AppData\Roaming\cache.ini [2013-07-08 17:15:54 | 001,644,808 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013-06-26 13:43:09 | 000,030,528 | ---- | C] () -- C:\Windows\GVTDrv64.sys [2013-06-26 13:34:18 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\CommCmd.dll [2013-06-26 13:25:14 | 000,072,304 | R--- | C] () -- C:\Windows\SysWow64\XSrvSetup.exe [2013-06-26 13:22:05 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini [2012-09-28 21:45:06 | 000,247,296 | ---- | C] () -- C:\Windows\SysWow64\rtvcvfw32.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2014-03-25 04:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2014-03-25 04:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2014-07-18 17:39:39 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\.minecraft [2013-06-30 12:06:00 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\.technic [2014-04-20 18:09:55 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\3909 [2014-05-27 16:44:52 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Audacity [2014-07-11 09:48:46 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Awesomium [2014-05-08 17:13:13 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Curse [2013-07-01 07:39:52 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DAEMON Tools Lite [2013-11-08 16:27:24 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Day 1 Studios [2013-09-26 20:00:19 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Dev-Cpp [2013-09-13 14:33:23 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Doublefine [2014-08-08 18:08:10 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Dropbox [2013-11-21 16:25:49 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\FileZilla [2013-09-11 17:58:01 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Firefly Studios [2014-01-21 20:38:02 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\GameRanger [2013-06-29 11:08:49 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\LolClient [2014-06-02 17:15:43 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Mirillis [2013-07-27 22:41:26 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\MKKE [2013-11-06 15:35:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Mount&Blade [2013-11-06 19:44:47 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Mount&Blade With Fire and Sword [2014-08-08 11:16:07 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Mumble [2014-03-07 20:49:20 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Need for Speed Most Wanted Black Edition [2014-08-08 18:56:40 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Origin [2013-06-28 21:18:56 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Riot Games [2013-07-18 11:31:28 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Rogue Legacy [2014-02-21 15:57:31 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\SPORE [2013-07-06 14:01:54 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TERA [2014-03-17 21:43:44 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\The Creative Assembly [2014-01-20 15:58:25 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Tibia [2013-09-12 17:36:28 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Trine2 [2014-08-08 18:18:02 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TS3Client [2014-02-02 21:10:23 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ts3overlay [2013-07-09 20:42:58 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TunkDesign [2014-08-05 21:14:48 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\uTorrent [2013-11-13 19:52:37 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Wargaming.net [2014-05-22 20:59:10 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\WizardWars [2014-04-07 21:23:32 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\WNR [2013-10-16 19:55:15 | 000,000,000 | -HSD | M] -- C:\Users\User\AppData\Roaming\wyUpdate AU [color=#E56717]========== Purity Check ==========[/color] < End of report >