OTL logfile created on: 2014-10-27 22:05:17 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = D:\Pobrane 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17351) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 7,89 Gb Total Physical Memory | 6,25 Gb Available Physical Memory | 79,15% Memory free 9,14 Gb Paging File | 7,41 Gb Available in Paging File | 81,11% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 60,08 Gb Total Space | 21,66 Gb Free Space | 36,05% Space Free | Partition Type: NTFS Drive D: | 871,09 Gb Total Space | 759,70 Gb Free Space | 87,21% Space Free | Partition Type: NTFS Computer Name: KASIA-PC | User Name: Kasia | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-10-27 21:27:17 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Pobrane\OTL.exe PRC - [2014-10-13 18:40:12 | 001,870,000 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe PRC - [2014-09-25 15:21:11 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2014-08-02 19:21:01 | 004,085,896 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\avastui.exe PRC - [2014-07-10 17:02:17 | 000,358,968 | ---- | M] () -- C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe PRC - [2014-06-28 18:27:01 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2013-12-26 23:14:12 | 000,151,552 | ---- | M] () -- C:\Windows\KMService.exe PRC - [2013-12-26 23:14:12 | 000,008,192 | ---- | M] () -- C:\Windows\SysWOW64\srvany.exe PRC - [2013-09-04 07:53:54 | 000,390,616 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2013-09-04 07:53:52 | 000,169,432 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe PRC - [2013-08-30 21:18:16 | 000,015,720 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe PRC - [2013-08-26 14:18:50 | 001,157,496 | ---- | M] (Motorola Solutions, Inc.) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe PRC - [2013-08-26 14:18:28 | 001,137,016 | ---- | M] (Motorola Solutions, Inc.) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-10-13 18:40:12 | 016,825,520 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll MOD - [2014-09-25 15:21:10 | 003,715,184 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2014-06-28 18:27:02 | 019,329,904 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll MOD - [2014-06-28 18:27:01 | 000,301,152 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswProperty.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2014-09-12 19:25:34 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService) SRV:[b]64bit:[/b] - [2014-08-16 04:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify) SRV:[b]64bit:[/b] - [2014-08-16 01:58:35 | 000,287,744 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker) SRV:[b]64bit:[/b] - [2014-08-16 01:45:51 | 000,267,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure) SRV:[b]64bit:[/b] - [2014-07-24 08:28:58 | 001,600,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc) SRV:[b]64bit:[/b] - [2014-06-28 18:27:01 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV:[b]64bit:[/b] - [2014-05-20 23:33:44 | 000,314,696 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\igfxCUIService.exe -- (igfxCUIService1.0.0.0) SRV:[b]64bit:[/b] - [2014-04-06 12:20:36 | 000,201,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder) SRV:[b]64bit:[/b] - [2014-03-24 03:31:14 | 000,347,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc) SRV:[b]64bit:[/b] - [2014-03-24 03:31:14 | 000,023,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend) SRV:[b]64bit:[/b] - [2014-03-14 07:26:25 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc) SRV:[b]64bit:[/b] - [2014-03-08 06:41:25 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc) SRV:[b]64bit:[/b] - [2014-03-06 08:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon) SRV:[b]64bit:[/b] - [2014-02-22 16:53:10 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService) SRV:[b]64bit:[/b] - [2014-02-22 10:57:16 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM) SRV:[b]64bit:[/b] - [2014-02-22 10:26:58 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc) SRV:[b]64bit:[/b] - [2014-02-22 10:25:39 | 000,399,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService) SRV:[b]64bit:[/b] - [2014-02-22 10:23:58 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc) SRV:[b]64bit:[/b] - [2013-12-10 08:35:18 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness) SRV:[b]64bit:[/b] - [2013-08-30 21:18:16 | 000,015,720 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) SRV:[b]64bit:[/b] - [2013-08-26 19:08:08 | 000,246,488 | ---- | M] (Realtek Semiconductor) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe -- (RtkAudioService) SRV:[b]64bit:[/b] - [2013-08-26 19:07:38 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters) SRV:[b]64bit:[/b] - [2013-08-22 12:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC) SRV:[b]64bit:[/b] - [2013-08-22 12:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS) SRV:[b]64bit:[/b] - [2013-08-22 12:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc) SRV:[b]64bit:[/b] - [2013-08-22 12:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc) SRV:[b]64bit:[/b] - [2013-08-22 12:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc) SRV:[b]64bit:[/b] - [2013-08-22 11:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc) SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss) SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync) SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown) SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv) SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange) SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat) SRV:[b]64bit:[/b] - [2013-08-22 11:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface) SRV:[b]64bit:[/b] - [2013-08-22 11:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost) SRV:[b]64bit:[/b] - [2013-08-22 10:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum) SRV:[b]64bit:[/b] - [2013-08-22 10:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso) SRV:[b]64bit:[/b] - [2013-08-22 10:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker) SRV:[b]64bit:[/b] - [2013-08-22 10:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm) SRV:[b]64bit:[/b] - [2013-08-22 10:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService) SRV:[b]64bit:[/b] - [2013-08-22 10:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc) SRV:[b]64bit:[/b] - [2013-08-22 10:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc) SRV:[b]64bit:[/b] - [2013-08-22 10:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup) SRV:[b]64bit:[/b] - [2013-08-20 07:09:22 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:[b]64bit:[/b] - [2013-05-11 17:45:54 | 000,822,232 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe -- (Intel(R) SRV:[b]64bit:[/b] - [2013-05-11 17:45:38 | 000,733,696 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R) SRV - [2014-10-13 18:40:12 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014-09-25 15:21:10 | 000,114,288 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2014-08-16 04:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify) SRV - [2014-07-10 17:02:17 | 000,358,968 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe -- (ALDITALKVerbindungsassistent_Service) SRV - [2014-05-20 23:33:48 | 000,278,344 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs) SRV - [2014-03-14 07:10:16 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc) SRV - [2013-12-26 23:14:12 | 000,008,192 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\srvany.exe -- (KMService) SRV - [2013-09-18 22:38:44 | 000,157,128 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe -- (Intel(R) SRV - [2013-09-04 07:53:54 | 000,390,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2013-09-04 07:53:52 | 000,169,432 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service) SRV - [2013-08-26 14:18:50 | 001,157,496 | ---- | M] (Motorola Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service) SRV - [2013-08-26 14:18:28 | 001,137,016 | ---- | M] (Motorola Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor) SRV - [2013-08-22 04:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc) SRV - [2013-08-22 03:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost) SRV - [2013-02-04 17:43:22 | 000,155,824 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion) SRV - [2012-04-24 14:37:56 | 000,169,752 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe -- (ICCS) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2014-08-30 13:48:20 | 000,165,504 | ---- | M] (ITE ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IT9135BDA.sys -- (IT9135BDA) DRV:[b]64bit:[/b] - [2014-08-15 01:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101) DRV:[b]64bit:[/b] - [2014-07-24 16:28:38 | 000,468,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3) DRV:[b]64bit:[/b] - [2014-07-24 16:28:38 | 000,412,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport) DRV:[b]64bit:[/b] - [2014-07-24 12:42:22 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform) DRV:[b]64bit:[/b] - [2014-07-04 15:19:17 | 000,427,360 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsp.sys -- (aswSP) DRV:[b]64bit:[/b] - [2014-06-28 18:27:04 | 001,041,168 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx) DRV:[b]64bit:[/b] - [2014-06-28 18:27:04 | 000,224,896 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswVmm.sys -- (aswVmm) DRV:[b]64bit:[/b] - [2014-06-28 18:27:04 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr) DRV:[b]64bit:[/b] - [2014-06-28 18:27:04 | 000,092,008 | ---- | M] (AVAST Software) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm) DRV:[b]64bit:[/b] - [2014-06-28 18:27:04 | 000,079,184 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) DRV:[b]64bit:[/b] - [2014-06-28 18:27:04 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys -- (aswRvrt) DRV:[b]64bit:[/b] - [2014-06-28 18:27:04 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid) DRV:[b]64bit:[/b] - [2014-05-20 23:33:36 | 003,791,872 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:[b]64bit:[/b] - [2014-05-06 23:39:17 | 000,038,296 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible) DRV:[b]64bit:[/b] - [2014-05-06 23:39:17 | 000,027,032 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus) DRV:[b]64bit:[/b] - [2014-05-01 14:31:39 | 000,055,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr) DRV:[b]64bit:[/b] - [2014-03-24 03:30:57 | 000,257,880 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter) DRV:[b]64bit:[/b] - [2014-03-24 03:30:57 | 000,123,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv) DRV:[b]64bit:[/b] - [2014-03-24 03:27:03 | 000,035,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot) DRV:[b]64bit:[/b] - [2014-03-20 04:41:20 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS) DRV:[b]64bit:[/b] - [2014-03-13 13:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof) DRV:[b]64bit:[/b] - [2014-03-11 00:00:08 | 000,138,752 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbnet.sys -- (ewusbnet) DRV:[b]64bit:[/b] - [2014-03-11 00:00:08 | 000,121,600 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard) DRV:[b]64bit:[/b] - [2014-03-11 00:00:08 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV:[b]64bit:[/b] - [2014-03-10 22:23:05 | 000,027,760 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsemc.sys -- (ggsemc) DRV:[b]64bit:[/b] - [2014-03-10 22:23:05 | 000,014,448 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt) DRV:[b]64bit:[/b] - [2014-03-08 21:40:16 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS) DRV:[b]64bit:[/b] - [2014-02-22 17:00:25 | 000,236,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus) DRV:[b]64bit:[/b] - [2014-02-22 16:49:51 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI) DRV:[b]64bit:[/b] - [2014-02-22 16:49:49 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000) DRV:[b]64bit:[/b] - [2014-02-22 16:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor) DRV:[b]64bit:[/b] - [2014-02-22 16:44:13 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS) DRV:[b]64bit:[/b] - [2014-02-22 13:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender) DRV:[b]64bit:[/b] - [2013-12-15 00:05:23 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2) DRV:[b]64bit:[/b] - [2013-12-15 00:05:23 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc) DRV:[b]64bit:[/b] - [2013-12-15 00:05:23 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep) DRV:[b]64bit:[/b] - [2013-12-14 21:14:15 | 000,044,640 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\aswTap.sys -- (aswTap) DRV:[b]64bit:[/b] - [2013-12-04 19:41:54 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthLEEnum.sys -- (BthLEEnum) DRV:[b]64bit:[/b] - [2013-11-14 08:37:27 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme) DRV:[b]64bit:[/b] - [2013-11-14 08:31:22 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt) DRV:[b]64bit:[/b] - [2013-11-14 08:16:48 | 000,027,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:[b]64bit:[/b] - [2013-11-14 08:16:43 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt) DRV:[b]64bit:[/b] - [2013-10-01 10:25:24 | 000,449,528 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) DRV:[b]64bit:[/b] - [2013-09-05 16:37:40 | 001,390,904 | ---- | M] (Motorola Solutions, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf) DRV:[b]64bit:[/b] - [2013-09-04 07:53:52 | 000,099,288 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TeeDriverx64.sys -- (MEIx64) DRV:[b]64bit:[/b] - [2013-08-31 03:02:26 | 003,345,376 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwew00.sys -- (NETwNe64) DRV:[b]64bit:[/b] - [2013-08-30 21:18:02 | 000,644,968 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA) DRV:[b]64bit:[/b] - [2013-08-22 14:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv) DRV:[b]64bit:[/b] - [2013-08-22 14:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2013-08-22 13:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam) DRV:[b]64bit:[/b] - [2013-08-22 13:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex) DRV:[b]64bit:[/b] - [2013-08-22 13:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM) DRV:[b]64bit:[/b] - [2013-08-22 13:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis) DRV:[b]64bit:[/b] - [2013-08-22 13:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32) DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS) DRV:[b]64bit:[/b] - [2013-08-22 13:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2013-08-22 13:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3) DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX) DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware) DRV:[b]64bit:[/b] - [2013-08-22 13:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv) DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass) DRV:[b]64bit:[/b] - [2013-08-22 13:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2013-08-22 13:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID) DRV:[b]64bit:[/b] - [2013-08-22 13:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor) DRV:[b]64bit:[/b] - [2013-08-22 13:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci) DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx) DRV:[b]64bit:[/b] - [2013-08-22 13:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx) DRV:[b]64bit:[/b] - [2013-08-22 13:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI) DRV:[b]64bit:[/b] - [2013-08-22 13:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci) DRV:[b]64bit:[/b] - [2013-08-22 13:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr) DRV:[b]64bit:[/b] - [2013-08-22 12:39:58 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice) DRV:[b]64bit:[/b] - [2013-08-22 12:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache) DRV:[b]64bit:[/b] - [2013-08-22 12:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay) DRV:[b]64bit:[/b] - [2013-08-22 12:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo) DRV:[b]64bit:[/b] - [2013-08-22 12:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf) DRV:[b]64bit:[/b] - [2013-08-22 12:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime) DRV:[b]64bit:[/b] - [2013-08-22 12:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr) DRV:[b]64bit:[/b] - [2013-08-22 12:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg) DRV:[b]64bit:[/b] - [2013-08-22 12:38:30 | 000,131,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthA2DP.sys -- (BthA2DP) DRV:[b]64bit:[/b] - [2013-08-22 12:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic) DRV:[b]64bit:[/b] - [2013-08-22 12:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter) DRV:[b]64bit:[/b] - [2013-08-22 12:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig) DRV:[b]64bit:[/b] - [2013-08-22 12:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid) DRV:[b]64bit:[/b] - [2013-08-22 12:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd) DRV:[b]64bit:[/b] - [2013-08-22 12:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2013-08-22 12:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum) DRV:[b]64bit:[/b] - [2013-08-22 12:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2013-08-22 12:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c) DRV:[b]64bit:[/b] - [2013-08-22 12:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) DRV:[b]64bit:[/b] - [2013-08-22 12:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc) DRV:[b]64bit:[/b] - [2013-08-22 12:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus) DRV:[b]64bit:[/b] - [2013-08-22 12:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp) DRV:[b]64bit:[/b] - [2013-08-22 12:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu) DRV:[b]64bit:[/b] - [2013-08-22 09:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM) DRV:[b]64bit:[/b] - [2013-08-20 08:06:16 | 012,521,472 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:[b]64bit:[/b] - [2013-08-20 06:42:28 | 000,617,472 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:[b]64bit:[/b] - [2013-08-13 00:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2) DRV:[b]64bit:[/b] - [2013-08-11 22:54:36 | 000,524,016 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:[b]64bit:[/b] - [2013-08-11 22:54:36 | 000,034,544 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys -- (SmbDrvI) DRV:[b]64bit:[/b] - [2013-08-10 01:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV) DRV:[b]64bit:[/b] - [2013-07-30 19:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO) DRV:[b]64bit:[/b] - [2013-07-25 20:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C) DRV:[b]64bit:[/b] - [2013-07-22 18:56:48 | 000,140,600 | ---- | M] (Motorola Solutions, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux) DRV:[b]64bit:[/b] - [2013-07-15 15:29:12 | 000,329,944 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUVStor.sys -- (RSUSBVSTOR) DRV:[b]64bit:[/b] - [2013-06-21 17:35:14 | 000,816,344 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168) DRV:[b]64bit:[/b] - [2013-05-22 10:38:50 | 000,036,096 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdkmpfd.sys -- (amdkmpfd) DRV:[b]64bit:[/b] - [2013-04-23 13:24:26 | 000,069,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iBtFltCoex.sys -- (ibtfltcoex) DRV:[b]64bit:[/b] - [2013-02-21 14:20:36 | 000,081,408 | ---- | M] (MediaTek Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb2ser.sys -- (wdf_usb) DRV:[b]64bit:[/b] - [2012-12-13 02:49:54 | 000,208,896 | ---- | M] (MediaTek Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mtkmbim7_x64.sys -- (mtkmbim) DRV - [2014-06-19 03:44:16 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV - [2014-06-19 03:44:16 | 000,091,136 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\ew_jucdcacm.sys -- (huawei_cdcacm) DRV - [2014-06-19 03:44:16 | 000,085,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\ew_jubusenum.sys -- (huawei_enumerator) DRV - [2014-06-19 03:44:16 | 000,029,184 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl) DRV - [2014-06-19 03:44:16 | 000,013,952 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter) DRV - [2014-06-19 03:44:15 | 000,138,752 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\ewusbnet.sys -- (ewusbnet) DRV - [2014-06-19 03:44:15 | 000,121,600 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2012-12-29 21:59:38 | 000,028,664 | ---- | M] (Almico Software) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1776326940-536374368-3765355232-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/pl-pl/?ocid=iehp IE - HKU\S-1-5-21-1776326940-536374368-3765355232-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pl-PL IE - HKU\S-1-5-21-1776326940-536374368-3765355232-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C6 C6 55 30 17 F2 CF 01 [binary data] IE - HKU\S-1-5-21-1776326940-536374368-3765355232-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1776326940-536374368-3765355232-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 IE - HKU\S-1-5-21-1776326940-536374368-3765355232-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:32.0.3 FF - user.js - File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-06-28 18:27:07 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 28.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 28.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 30.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 30.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 32.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 32.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 32.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 32.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013-12-14 21:09:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kasia\AppData\Roaming\mozilla\Extensions [2014-10-21 18:50:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kasia\AppData\Roaming\mozilla\Firefox\Profiles\xjzo0k42.default\extensions [2014-10-21 18:50:05 | 000,979,610 | ---- | M] () (No name found) -- C:\Users\Kasia\AppData\Roaming\mozilla\firefox\profiles\xjzo0k42.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-09-25 15:21:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions [2014-09-25 15:21:11 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: (Enabled) CHR - default_search_provider: search_url = CHR - default_search_provider: suggest_url = CHR - plugin: Error reading preferences file CHR - Extension: Dokumenty Google = C:\Users\Kasia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\ CHR - Extension: Dysk Google = C:\Users\Kasia\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: YouTube = C:\Users\Kasia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ CHR - Extension: Szukaj w Google = C:\Users\Kasia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\ CHR - Extension: No name found = C:\Users\Kasia\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\14.0.0.4651_0\ CHR - Extension: No name found = C:\Users\Kasia\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\14.0.0.4873_0\ CHR - Extension: Google Wallet = C:\Users\Kasia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\ CHR - Extension: Gmail = C:\Users\Kasia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ CHR - Extension: No name found = C:\Users\Kasia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\14.0.0.4651_0\ O1 HOSTS File: ([2013-08-22 14:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found. O4:[b]64bit:[/b] - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll (Motorola Solutions, Inc.) O4:[b]64bit:[/b] - HKLM..\Run: [Logitech Download Assistant] C:\WINDOWS\SysNative\LogiLDA.dll (Logitech, Inc.) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg_PushButton] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKU\S-1-5-21-1776326940-536374368-3765355232-1001..\Run: [BlazeServoTool] C:\Program Files (x86)\BlazeVideo\BlazeHDTV 6.0\MediaDetector.exe (BlazeVideo Company) O4 - HKU\S-1-5-21-1776326940-536374368-3765355232-1001..\Run: [Sony PC Companion] C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (Sony) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O9:[b]64bit:[/b] - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard) O9:[b]64bit:[/b] - Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard) O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard) O9 - Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.63 62.179.1.62 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A80E483-A9C3-46B2-806C-218AEDCC4097}: DhcpNameServer = 62.179.1.63 62.179.1.62 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B7AFBD67-B713-42EB-B7AE-4AA84314DB76}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F7C06C86-3B6E-4D47-A145-551C4A1E3324}: DhcpNameServer = 62.179.1.63 62.179.1.62 O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation) O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - File not found O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O30 - LSA: Security Packages - (livessp) - File not found O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{0dc8971d-72a2-11e3-be7e-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{0dc8971d-72a2-11e3-be7e-68172995d58e}\Shell\AutoRun\command - "" = "G:\AutoRun.exe" O33 - MountPoints2\{0dc89a13-72a2-11e3-be7e-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{0dc89a13-72a2-11e3-be7e-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{0dc89a3d-72a2-11e3-be7e-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{0dc89a3d-72a2-11e3-be7e-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{0dc89c9a-72a2-11e3-be7e-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{0dc89c9a-72a2-11e3-be7e-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{0dc89cef-72a2-11e3-be7e-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{0dc89cef-72a2-11e3-be7e-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{14f39664-a2b6-11e3-be87-001e101f0d78}\Shell - "" = AutoRun O33 - MountPoints2\{14f39664-a2b6-11e3-be87-001e101f0d78}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{14f39685-a2b6-11e3-be87-001e101f0d78}\Shell - "" = AutoRun O33 - MountPoints2\{14f39685-a2b6-11e3-be87-001e101f0d78}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{211cd8a4-6e49-11e3-be7c-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{211cd8a4-6e49-11e3-be7c-68172995d58e}\Shell\AutoRun\command - "" = "F:\SETUP.EXE" O33 - MountPoints2\{211cd8a4-6e49-11e3-be7c-68172995d58e}\Shell\configure\command - "" = F:\SETUP.EXE O33 - MountPoints2\{211cd8a4-6e49-11e3-be7c-68172995d58e}\Shell\install\command - "" = F:\SETUP.EXE O33 - MountPoints2\{30152436-b807-11e3-be8b-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{30152436-b807-11e3-be8b-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{34e3d147-6e8b-11e3-be7e-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{34e3d147-6e8b-11e3-be7e-68172995d58e}\Shell\AutoRun\command - "" = "G:\AutoRun.exe" O33 - MountPoints2\{34e3e4f4-6e8b-11e3-be7e-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{34e3e4f4-6e8b-11e3-be7e-68172995d58e}\Shell\AutoRun\command - "" = "G:\AutoRun.exe" O33 - MountPoints2\{4c952f94-f579-11e3-be94-001e101f8a48}\Shell - "" = AutoRun O33 - MountPoints2\{4c952f94-f579-11e3-be94-001e101f8a48}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{4c952fbf-f579-11e3-be94-001e101f8a48}\Shell - "" = AutoRun O33 - MountPoints2\{4c952fbf-f579-11e3-be94-001e101f8a48}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{4c953060-f579-11e3-be94-001e101f8a48}\Shell - "" = AutoRun O33 - MountPoints2\{4c953060-f579-11e3-be94-001e101f8a48}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{564b57d3-81d8-11e3-be81-001e101ff868}\Shell - "" = AutoRun O33 - MountPoints2\{564b57d3-81d8-11e3-be81-001e101ff868}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{564b57f7-81d8-11e3-be81-001e101ff868}\Shell - "" = AutoRun O33 - MountPoints2\{564b57f7-81d8-11e3-be81-001e101ff868}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{68ffc7de-dcb4-11e3-be90-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{68ffc7de-dcb4-11e3-be90-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{68ffc7ff-dcb4-11e3-be90-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{68ffc7ff-dcb4-11e3-be90-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{68ffc826-dcb4-11e3-be90-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{68ffc826-dcb4-11e3-be90-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{68ffcb2b-dcb4-11e3-be90-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{68ffcb2b-dcb4-11e3-be90-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{68ffcb61-dcb4-11e3-be90-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{68ffcb61-dcb4-11e3-be90-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{68ffcb85-dcb4-11e3-be90-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{68ffcb85-dcb4-11e3-be90-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{68ffcc65-dcb4-11e3-be90-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{68ffcc65-dcb4-11e3-be90-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{703f277e-354a-11e4-be9f-74867a303533}\Shell - "" = AutoRun O33 - MountPoints2\{703f277e-354a-11e4-be9f-74867a303533}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{71156800-6be3-11e3-be7b-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{71156800-6be3-11e3-be7b-68172995d58e}\Shell\AutoRun\command - "" = "F:\AutoRun.exe" O33 - MountPoints2\{71156861-6be3-11e3-be7b-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{71156861-6be3-11e3-be7b-68172995d58e}\Shell\AutoRun\command - "" = "G:\AutoRun.exe" O33 - MountPoints2\{8c7afa35-b29c-11e3-be8a-001e101f0c5f}\Shell - "" = AutoRun O33 - MountPoints2\{8c7afa35-b29c-11e3-be8a-001e101f0c5f}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{8c7afa55-b29c-11e3-be8a-001e101f0c5f}\Shell - "" = AutoRun O33 - MountPoints2\{8c7afa55-b29c-11e3-be8a-001e101f0c5f}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{9ddc4368-1273-11e4-be96-001e101f8eed}\Shell - "" = AutoRun O33 - MountPoints2\{9ddc4368-1273-11e4-be96-001e101f8eed}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{9ddc4d96-1273-11e4-be96-001e101f8eed}\Shell - "" = AutoRun O33 - MountPoints2\{9ddc4d96-1273-11e4-be96-001e101f8eed}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{a43ab50f-a87d-11e3-be88-74867a303533}\Shell - "" = AutoRun O33 - MountPoints2\{a43ab50f-a87d-11e3-be88-74867a303533}\Shell\AutoRun\command - "" = "G:\Startme.exe" O33 - MountPoints2\{b1a843a8-871d-11e3-be81-001e101ff868}\Shell - "" = AutoRun O33 - MountPoints2\{b1a843a8-871d-11e3-be81-001e101ff868}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{b1a84525-871d-11e3-be81-001e101ff868}\Shell - "" = AutoRun O33 - MountPoints2\{b1a84525-871d-11e3-be81-001e101ff868}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{b1a85b30-871d-11e3-be81-001e101ff868}\Shell - "" = AutoRun O33 - MountPoints2\{b1a85b30-871d-11e3-be81-001e101ff868}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{b81a2a2a-4c92-11e4-bea0-001e101f1b9b}\Shell - "" = AutoRun O33 - MountPoints2\{b81a2a2a-4c92-11e4-bea0-001e101f1b9b}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{b81a3b2a-4c92-11e4-bea0-74867a303533}\Shell - "" = AutoRun O33 - MountPoints2\{b81a3b2a-4c92-11e4-bea0-74867a303533}\Shell\AutoRun\command - "" = "G:\.\StartModem.exe" O33 - MountPoints2\{bb31fc33-a8a3-11e3-be89-74867a303533}\Shell - "" = AutoRun O33 - MountPoints2\{bb31fc33-a8a3-11e3-be89-74867a303533}\Shell\AutoRun\command - "" = "G:\AutoRun.exe" O33 - MountPoints2\{bb31fc8c-a8a3-11e3-be89-74867a303533}\Shell - "" = AutoRun O33 - MountPoints2\{bb31fc8c-a8a3-11e3-be89-74867a303533}\Shell\AutoRun\command - "" = "G:\AutoRun.exe" O33 - MountPoints2\{bb320152-a8a3-11e3-be89-74867a303533}\Shell - "" = AutoRun O33 - MountPoints2\{bb320152-a8a3-11e3-be89-74867a303533}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{bb320536-a8a3-11e3-be89-74867a303533}\Shell - "" = AutoRun O33 - MountPoints2\{bb320536-a8a3-11e3-be89-74867a303533}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{c8497c35-7ad5-11e3-be80-68172995d58e}\Shell - "" = AutoRun O33 - MountPoints2\{c8497c35-7ad5-11e3-be80-68172995d58e}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{c8bf935b-9de9-11e3-be86-001e101fc2ed}\Shell - "" = AutoRun O33 - MountPoints2\{c8bf935b-9de9-11e3-be86-001e101fc2ed}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e49e8a-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e49e8a-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4a6c1-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4a6c1-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4a6e3-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4a6e3-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4a8fe-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4a8fe-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4a920-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4a920-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4aa72-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4aa72-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4ab70-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4ab70-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4ab93-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4ab93-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4abb8-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4abb8-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4ac14-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4ac14-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4ac4f-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4ac4f-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4af77-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4af77-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4af9b-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4af9b-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4afb9-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4afb9-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4afdd-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4afdd-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4b0a7-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4b0a7-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4b101-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4b101-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\AutoRun.exe" O33 - MountPoints2\{d2e4b145-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4b145-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\AutoRun.exe" O33 - MountPoints2\{d2e4b18a-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4b18a-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\AutoRun.exe" O33 - MountPoints2\{d2e4b1f1-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4b1f1-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4b2e0-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4b2e0-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d2e4b302-959f-11e3-be82-001e101f05a2}\Shell - "" = AutoRun O33 - MountPoints2\{d2e4b302-959f-11e3-be82-001e101f05a2}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d4a987e7-98b8-11e3-be83-001e101f5717}\Shell - "" = AutoRun O33 - MountPoints2\{d4a987e7-98b8-11e3-be83-001e101f5717}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d4a98dab-98b8-11e3-be83-001e101f5717}\Shell - "" = AutoRun O33 - MountPoints2\{d4a98dab-98b8-11e3-be83-001e101f5717}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d4a98dc1-98b8-11e3-be83-001e101f5717}\Shell - "" = AutoRun O33 - MountPoints2\{d4a98dc1-98b8-11e3-be83-001e101f5717}\Shell\AutoRun\command - "" = "G:\.\Autorun.exe" AUTORUN=1 O33 - MountPoints2\{d4a98ecc-98b8-11e3-be83-001e101f5717}\Shell - "" = AutoRun O33 - MountPoints2\{d4a98ecc-98b8-11e3-be83-001e101f5717}\Shell\AutoRun\command - "" = "G:\.\Autorun.exe" AUTORUN=1 O33 - MountPoints2\{d4a98efc-98b8-11e3-be83-001e101f5717}\Shell - "" = AutoRun O33 - MountPoints2\{d4a98efc-98b8-11e3-be83-001e101f5717}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{d4a990a8-98b8-11e3-be83-001e101f5717}\Shell - "" = AutoRun O33 - MountPoints2\{d4a990a8-98b8-11e3-be83-001e101f5717}\Shell\AutoRun\command - "" = "G:\.\Autorun.exe" AUTORUN=1 O33 - MountPoints2\{d4a990dd-98b8-11e3-be83-001e101f5717}\Shell - "" = AutoRun O33 - MountPoints2\{d4a990dd-98b8-11e3-be83-001e101f5717}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{ed9a80c1-9a55-11e3-be85-001e101ff555}\Shell - "" = AutoRun O33 - MountPoints2\{ed9a80c1-9a55-11e3-be85-001e101ff555}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{ed9a80ee-9a55-11e3-be85-001e101ff555}\Shell - "" = AutoRun O33 - MountPoints2\{ed9a80ee-9a55-11e3-be85-001e101ff555}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{fb7c5f26-f887-11e3-be94-001e101f8a48}\Shell - "" = AutoRun O33 - MountPoints2\{fb7c5f26-f887-11e3-be94-001e101f8a48}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{fc8efdfb-de94-11e3-be91-001e101f0dc8}\Shell - "" = AutoRun O33 - MountPoints2\{fc8efdfb-de94-11e3-be91-001e101f0dc8}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\{fc8f0475-de94-11e3-be91-001e101f0dc8}\Shell - "" = AutoRun O33 - MountPoints2\{fc8f0475-de94-11e3-be91-001e101f0dc8}\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O33 - MountPoints2\G\Shell - "" = AutoRun O33 - MountPoints2\G\Shell\AutoRun\command - "" = "G:\.\Setup.exe" AUTORUN=1 O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-10-27 21:22:39 | 000,000,000 | ---D | C] -- C:\FRST [2014-10-21 18:49:18 | 000,921,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll [2014-10-21 18:49:18 | 000,626,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll [2014-10-21 18:49:13 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winbici.dll [2014-10-21 18:48:59 | 000,839,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll [2014-10-21 18:48:59 | 000,672,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll [2014-10-21 18:48:58 | 001,702,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll [2014-10-21 18:48:58 | 000,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll [2014-10-21 18:48:58 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll [2014-10-21 18:48:58 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll [2014-10-21 18:48:58 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll [2014-10-21 18:48:58 | 000,054,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe [2014-10-21 18:48:58 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll [2014-10-21 18:48:57 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll [2014-10-21 18:48:57 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll [2014-10-21 18:48:57 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe [2014-10-21 18:48:57 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe [2014-10-21 18:48:11 | 005,829,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll [2014-10-21 18:48:00 | 002,108,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl [2014-10-21 18:48:00 | 000,731,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll [2014-10-21 18:47:59 | 002,017,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl [2014-10-21 18:47:58 | 000,710,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe [2014-10-21 18:47:55 | 000,289,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll [2014-10-21 18:47:55 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll [2014-10-21 18:47:55 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll [2014-10-21 18:47:54 | 000,775,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll [2014-10-21 18:47:54 | 000,758,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll [2014-10-21 18:47:54 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll [2014-10-21 18:47:54 | 000,547,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll [2014-10-21 18:47:54 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll [2014-10-21 18:47:54 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll [2014-10-21 18:47:39 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll [2014-10-21 18:47:39 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll [2014-10-21 18:47:36 | 000,590,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rastls.dll [2014-10-21 18:47:36 | 000,514,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rastls.dll [2014-10-21 18:47:35 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll [2014-10-21 18:47:35 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll [2014-10-21 18:47:34 | 000,527,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll [2014-10-21 18:47:29 | 002,779,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll [2014-10-15 21:22:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\D-Link Connection Manager [2014-10-15 21:22:17 | 001,919,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WdfCoinstaller01005.dll [2014-10-15 21:22:17 | 000,081,408 | ---- | C] (MediaTek Inc.) -- C:\WINDOWS\SysNative\drivers\usb2ser.sys [2014-10-15 21:22:15 | 000,103,424 | ---- | C] (Thesycon GmbH) -- C:\WINDOWS\SysWow64\MyDIT_GenClassCoInst.dll [2014-10-15 21:22:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\D-Link Connection Manager [2014-10-13 18:39:32 | 008,757,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll [2014-10-13 18:39:28 | 006,649,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll [2014-10-13 18:39:28 | 005,902,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll [2014-10-13 18:39:28 | 005,777,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll [2014-10-13 18:39:27 | 004,758,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncEngine.dll [2014-10-13 18:39:27 | 001,106,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll [2014-10-13 18:39:26 | 001,710,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll [2014-10-13 18:39:26 | 001,507,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\propsys.dll [2014-10-13 18:39:26 | 001,112,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll [2014-10-13 18:39:25 | 000,920,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll [2014-10-13 18:39:25 | 000,756,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll [2014-10-13 18:39:25 | 000,359,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Wldap32.dll [2014-10-13 18:39:24 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveTelemetry.dll [2014-10-13 18:39:24 | 000,287,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemEventsBrokerServer.dll [2014-10-13 18:39:23 | 001,120,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDrive.exe [2014-10-13 18:39:23 | 000,428,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS [2014-10-13 18:39:23 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ProximityService.dll [2014-10-13 18:39:23 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveShell.dll [2014-10-13 18:39:23 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pcsvDevice.dll [2014-10-13 18:39:23 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bisrv.dll [2014-10-13 18:39:23 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SkyDriveShell.dll [2014-10-13 18:39:23 | 000,249,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll [2014-10-13 18:39:23 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll [2014-10-13 18:39:23 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\httpprxm.dll [2014-10-13 18:39:23 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adhsvc.dll [2014-10-13 18:39:14 | 002,646,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll [2014-10-13 18:39:13 | 002,321,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll [2014-10-07 14:48:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hewlett-Packard [2014-10-07 14:48:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Visan [2014-10-07 14:48:37 | 000,000,000 | ---D | C] -- C:\ProgramData\HP Photo Creations [2014-10-07 14:48:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP Photo Creations [2014-10-07 14:48:23 | 000,000,000 | ---D | C] -- C:\Users\Kasia\AppData\Roaming\HpUpdate [2014-10-07 14:48:12 | 000,762,400 | ---- | C] (Hewlett-Packard Co.) -- C:\WINDOWS\SysNative\HPDiscoPMC211.dll [2014-10-07 14:48:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP [2014-10-07 14:46:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP [2014-10-07 14:46:50 | 000,000,000 | ---D | C] -- C:\Program Files\HP [2014-10-07 14:45:33 | 000,000,000 | ---D | C] -- C:\Users\Kasia\AppData\Local\HP [2014-10-07 14:45:12 | 000,000,000 | ---D | C] -- C:\ProgramData\HP [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-10-27 22:02:30 | 001,738,750 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI [2014-10-27 22:02:30 | 000,771,568 | ---- | M] () -- C:\WINDOWS\SysNative\perfh015.dat [2014-10-27 22:02:30 | 000,688,218 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat [2014-10-27 22:02:30 | 000,156,234 | ---- | M] () -- C:\WINDOWS\SysNative\perfc015.dat [2014-10-27 22:02:30 | 000,128,348 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat [2014-10-27 21:57:38 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2014-10-27 21:56:47 | 000,001,972 | ---- | M] () -- C:\Users\Kasia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - HP Deskjet 2540 series.lnk [2014-10-27 21:56:42 | 000,001,070 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2014-10-27 21:55:30 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys [2014-10-27 21:55:28 | 2482,483,199 | -HS- | M] () -- C:\hiberfil.sys [2014-10-27 21:30:00 | 000,001,074 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2014-10-27 21:24:00 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2014-10-22 21:08:15 | 000,411,352 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT [2014-10-22 19:32:28 | 000,002,175 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2014-10-15 22:28:29 | 000,001,536 | ---- | M] () -- C:\WINDOWS\SysWow64\RtkMsgs.dll [2014-10-15 21:23:27 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_usb2ser_01005.Wdf [2014-10-15 21:22:21 | 000,001,129 | ---- | M] () -- C:\Users\Public\Desktop\D-Link Connection Manager.lnk [2014-10-13 19:55:16 | 000,001,009 | ---- | M] () -- C:\Users\Public\Desktop\foobar2000.lnk [2014-10-09 23:16:51 | 000,678,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll [2014-10-08 23:09:34 | 000,275,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll [2014-10-07 14:48:37 | 000,001,969 | ---- | M] () -- C:\Users\Public\Desktop\HP Photo Creations.lnk [2014-10-07 14:48:11 | 000,002,238 | ---- | M] () -- C:\Users\Public\Desktop\HP Deskjet 2540 series.lnk [2014-10-07 14:48:11 | 000,001,185 | ---- | M] () -- C:\Users\Public\Desktop\Zakup materiałów eksploatacyjnych - HP Deskjet 2540 series.lnk [2014-10-07 14:45:57 | 000,000,057 | ---- | M] () -- C:\ProgramData\Ament.ini [2014-10-06 04:54:40 | 004,279,528 | ---- | M] () -- C:\Users\Kasia\Desktop\Dżem - Do kołyski (radio version).mp3 [2014-09-29 23:45:58 | 000,706,016 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe [2014-09-29 23:45:58 | 000,105,440 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-10-15 22:24:59 | 000,001,536 | ---- | C] () -- C:\WINDOWS\SysWow64\RtkMsgs.dll [2014-10-15 21:23:27 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_usb2ser_01005.Wdf [2014-10-15 21:22:21 | 000,001,129 | ---- | C] () -- C:\Users\Public\Desktop\D-Link Connection Manager.lnk [2014-10-13 18:39:23 | 000,388,729 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml [2014-10-07 14:52:28 | 000,001,972 | ---- | C] () -- C:\Users\Kasia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - HP Deskjet 2540 series.lnk [2014-10-07 14:48:37 | 000,001,969 | ---- | C] () -- C:\Users\Public\Desktop\HP Photo Creations.lnk [2014-10-07 14:48:11 | 000,002,238 | ---- | C] () -- C:\Users\Public\Desktop\HP Deskjet 2540 series.lnk [2014-10-07 14:48:11 | 000,001,185 | ---- | C] () -- C:\Users\Public\Desktop\Zakup materiałów eksploatacyjnych - HP Deskjet 2540 series.lnk [2014-10-07 14:45:57 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini [2014-10-06 04:54:54 | 004,279,528 | ---- | C] () -- C:\Users\Kasia\Desktop\Dżem - Do kołyski (radio version).mp3 [2014-08-30 13:49:51 | 000,000,014 | ---- | C] () -- C:\WINDOWS\SysWow64\SysInfo_6.dll [2014-05-20 23:33:38 | 000,348,088 | ---- | C] () -- C:\WINDOWS\SysWow64\igdmd32.dll [2014-05-20 23:33:32 | 000,183,808 | ---- | C] () -- C:\WINDOWS\SysWow64\igdde32.dll [2014-05-20 23:33:32 | 000,142,848 | ---- | C] () -- C:\WINDOWS\SysWow64\igdail32.dll [2014-04-15 17:44:30 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini [2014-03-10 18:51:49 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll [2013-12-26 23:14:47 | 000,151,552 | ---- | C] () -- C:\WINDOWS\KMService.exe [2013-12-26 23:14:47 | 000,008,192 | ---- | C] () -- C:\WINDOWS\SysWow64\srvany.exe [2013-12-15 12:35:55 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblup.dat [2013-12-15 12:29:11 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll [2013-12-15 12:22:44 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl [2013-12-15 12:20:09 | 001,762,308 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI [2013-12-15 06:38:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin [2013-09-26 19:02:38 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat [2013-09-26 19:02:38 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat [2013-09-26 19:02:36 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat [2013-09-26 19:02:18 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe [2013-09-26 19:02:18 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe [2013-08-22 16:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat [2013-08-22 16:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT [2013-08-22 15:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2013-08-22 08:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin [2013-08-22 04:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll [2013-08-22 00:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll [2013-08-22 00:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat [2013-08-19 13:55:30 | 000,038,912 | ---- | C] () -- C:\WINDOWS\SysWow64\kdbsdk32.dll [2013-05-11 17:17:52 | 000,001,536 | ---- | C] () -- C:\WINDOWS\SysWow64\IusEventLog.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2014-08-16 05:08:41 | 021,195,616 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2014-08-16 04:16:40 | 018,722,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013-08-22 10:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2013-08-22 03:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013-08-22 10:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2014-09-22 16:46:22 | 000,000,000 | ---D | M] -- C:\Users\Kasia\AppData\Roaming\ALDITALKVerbindungsassistent [2014-06-28 18:37:15 | 000,000,000 | ---D | M] -- C:\Users\Kasia\AppData\Roaming\AVAST Software [2013-12-26 22:40:00 | 000,000,000 | ---D | M] -- C:\Users\Kasia\AppData\Roaming\DAEMON Tools Lite [2014-06-28 18:55:25 | 000,000,000 | ---D | M] -- C:\Users\Kasia\AppData\Roaming\Dropbox [2014-06-28 18:55:24 | 000,000,000 | ---D | M] -- C:\Users\Kasia\AppData\Roaming\DropboxMaster [2014-10-13 21:01:54 | 000,000,000 | ---D | M] -- C:\Users\Kasia\AppData\Roaming\foobar2000 [2014-03-10 23:25:38 | 000,000,000 | ---D | M] -- C:\Users\Kasia\AppData\Roaming\Program Files (x86) [2014-01-26 15:53:34 | 000,000,000 | ---D | M] -- C:\Users\Kasia\AppData\Roaming\Temp [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Files - Unicode (All) ==========[/color] [2014-06-30 07:07:47 | 003,178,496 | ---- | M] ()(C:\WINDOWS\SysWow64\????????????????????????????????) -- C:\WINDOWS\SysWow64\㩣灜潲牧浡慤慴歜獡数獲祫氠扡慜灶㐱〮〮摜瑡屡潭畤敬彳湩敶瑮牯⹹慤 [2014-06-11 13:15:05 | 003,178,496 | ---- | C] ()(C:\WINDOWS\SysWow64\????????????????????????????????) -- C:\WINDOWS\SysWow64\㩣灜潲牧浡慤慴歜獡数獲祫氠扡慜灶㐱〮〮摜瑡屡潭畤敬彳湩敶瑮牯⹹慤 [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 237 bytes -> C:\Users\Kasia\SkyDrive:ms-properties < End of report >