OTL logfile created on: 2014-12-11 13:45:21 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Destroy666\Desktop\Bezpieczeństwo 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17420) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 8,00 Gb Total Physical Memory | 1,50 Gb Available Physical Memory | 18,79% Memory free 15,99 Gb Paging File | 1,18 Gb Available in Paging File | 7,38% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 111,50 Gb Total Space | 6,04 Gb Free Space | 5,42% Space Free | Partition Type: NTFS Drive D: | 931,51 Gb Total Space | 878,42 Gb Free Space | 94,30% Space Free | Partition Type: NTFS Drive G: | 954,05 Mb Total Space | 331,25 Mb Free Space | 34,72% Space Free | Partition Type: FAT Computer Name: AKTOTOTAKI | User Name: Destroy666 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-12-11 13:43:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Destroy666\Desktop\Bezpieczeństwo\OTL.exe PRC - [2014-11-28 18:22:44 | 005,419,792 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe PRC - [2014-11-28 18:22:43 | 016,289,040 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\TeamViewer.exe PRC - [2014-11-26 10:35:00 | 000,599,944 | ---- | M] (Autodesk Inc.) -- C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe PRC - [2014-11-25 07:39:27 | 000,856,904 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe PRC - [2014-11-25 02:33:53 | 000,119,592 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\nexon_runtime.exe PRC - [2014-11-18 00:52:09 | 010,393,696 | ---- | M] (GitHub, Inc.) -- C:\Users\Destroy666\AppData\Local\Apps\2.0\A79BRVQT.4RX\WZ668WAJ.981\gith..tion_317444273a93ac29_0002.0006_322e607d54d660d4\GitHub.exe PRC - [2014-11-16 17:10:45 | 000,230,792 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe PRC - [2014-11-12 21:46:08 | 000,409,800 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2014-11-06 18:08:04 | 002,464,072 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe PRC - [2014-11-06 18:07:54 | 001,795,912 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe PRC - [2014-10-28 16:15:34 | 000,244,448 | ---- | M] (Foxit Software Inc.) -- C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe PRC - [2014-10-21 17:52:24 | 022,869,088 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Drive\googledrivesync.exe PRC - [2014-10-16 10:15:38 | 011,880,448 | ---- | M] (FileZilla Project) -- C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe PRC - [2014-10-01 22:44:05 | 000,295,936 | ---- | M] () -- C:\Users\Destroy666\AppData\Local\GitHub\PortableGit_ed44d00daa128db527396557813e7b68709ed0e2\bin\ssh-agent.exe PRC - [2014-09-29 11:03:20 | 000,514,048 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe PRC - [2014-09-29 11:03:18 | 000,246,112 | ---- | M] () -- C:\ProgramData\PLAY ONLINE\OnlineUpdate\ouc.exe PRC - [2014-09-07 22:50:36 | 002,404,352 | ---- | M] (Don HO don.h@free.fr) -- C:\Program Files (x86)\Notepad++\notepad++.exe PRC - [2014-09-04 13:50:58 | 000,840,592 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe PRC - [2014-09-04 04:50:26 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2014-08-20 12:38:07 | 001,137,166 | ---- | M] () -- C:\ProgramData\WinSTAT\data\winhost32.exe PRC - [2014-08-20 12:36:20 | 001,460,224 | -HS- | M] (Microsoft® Corporation) -- C:\ProgramData\WinSTAT\WinSTAT.exe PRC - [2014-08-20 09:30:35 | 000,596,992 | ---- | M] () -- C:\Program Files (x86)\Git\git-cheetah\..\bin\sh.exe PRC - [2014-08-20 09:30:35 | 000,596,992 | ---- | M] () -- C:\Program Files (x86)\Git\bin\sh.exe PRC - [2014-08-20 07:14:05 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2014-07-22 16:15:56 | 002,694,040 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe PRC - [2014-07-03 05:25:22 | 000,490,360 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe PRC - [2014-06-27 10:52:26 | 002,088,408 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe PRC - [2014-06-24 09:42:12 | 004,101,576 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe PRC - [2014-06-24 09:41:42 | 001,738,168 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe PRC - [2014-06-14 14:18:18 | 016,814,080 | ---- | M] () -- C:\lazarus\lazarus.exe PRC - [2014-04-25 13:12:20 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe PRC - [2014-03-16 13:07:28 | 000,022,016 | ---- | M] (Apache Software Foundation) -- c:\XAMPP\apache\bin\httpd.exe PRC - [2014-03-16 13:07:28 | 000,022,016 | ---- | M] (Apache Software Foundation) -- C:\XAMPP\apache\bin\httpd.exe PRC - [2014-02-19 05:06:04 | 000,769,904 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe PRC - [2014-01-27 13:05:54 | 000,773,968 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe PRC - [2014-01-14 16:54:56 | 010,966,528 | ---- | M] () -- c:\XAMPP\mysql\bin\mysqld.exe PRC - [2013-06-17 10:42:31 | 002,569,216 | ---- | M] () -- C:\XAMPP\xampp-control.exe PRC - [2012-09-28 12:50:46 | 003,598,848 | ---- | M] () -- C:\lazarus\mingw\i386-win32\bin\gdb.exe PRC - [2011-03-14 16:27:28 | 000,236,384 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe PRC - [2010-11-21 04:24:03 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cmd.exe PRC - [2009-01-13 08:46:22 | 001,169,920 | ---- | M] (Huw Millington) -- C:\Program Files (x86)\Windows Grep\grep32.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-11-25 07:39:25 | 014,910,280 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\PepperFlash\pepflashplayer.dll MOD - [2014-11-25 07:39:24 | 009,009,480 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\pdf.dll MOD - [2014-11-25 07:39:20 | 001,077,064 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libglesv2.dll MOD - [2014-11-25 07:39:18 | 000,211,272 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libegl.dll MOD - [2014-11-25 07:39:17 | 001,677,128 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\ffmpegsumo.dll MOD - [2014-11-25 02:33:53 | 000,119,592 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\nexon_runtime.exe MOD - [2014-11-20 09:37:59 | 001,175,040 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\wx._core_.pyd MOD - [2014-11-20 09:37:59 | 001,160,704 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\_ssl.pyd MOD - [2014-11-20 09:37:59 | 001,062,400 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\wx._controls_.pyd MOD - [2014-11-20 09:37:59 | 000,811,008 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\wx._windows_.pyd MOD - [2014-11-20 09:37:59 | 000,805,888 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\wx._gdi_.pyd MOD - [2014-11-20 09:37:59 | 000,735,232 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\wx._misc_.pyd MOD - [2014-11-20 09:37:59 | 000,713,216 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\_hashlib.pyd MOD - [2014-11-20 09:37:59 | 000,686,080 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\unicodedata.pyd MOD - [2014-11-20 09:37:59 | 000,557,056 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\pysqlite2._sqlite.pyd MOD - [2014-11-20 09:37:59 | 000,525,640 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\windows._lib_cacheinvalidation.pyd MOD - [2014-11-20 09:37:59 | 000,364,544 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\pythoncom27.dll MOD - [2014-11-20 09:37:59 | 000,320,512 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32com.shell.shell.pyd MOD - [2014-11-20 09:37:59 | 000,167,936 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32gui.pyd MOD - [2014-11-20 09:37:59 | 000,128,512 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\_elementtree.pyd MOD - [2014-11-20 09:37:59 | 000,127,488 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\pyexpat.pyd MOD - [2014-11-20 09:37:59 | 000,122,368 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\wx._wizard.pyd MOD - [2014-11-20 09:37:59 | 000,119,808 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32file.pyd MOD - [2014-11-20 09:37:59 | 000,110,080 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\pywintypes27.dll MOD - [2014-11-20 09:37:59 | 000,108,544 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32security.pyd MOD - [2014-11-20 09:37:59 | 000,098,816 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32api.pyd MOD - [2014-11-20 09:37:59 | 000,087,552 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\_ctypes.pyd MOD - [2014-11-20 09:37:59 | 000,078,336 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\wx._animate.pyd MOD - [2014-11-20 09:37:59 | 000,070,656 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\wx._html2.pyd MOD - [2014-11-20 09:37:59 | 000,045,568 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\_socket.pyd MOD - [2014-11-20 09:37:59 | 000,038,912 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32inet.pyd MOD - [2014-11-20 09:37:59 | 000,027,136 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\_multiprocessing.pyd MOD - [2014-11-20 09:37:59 | 000,025,600 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32pdh.pyd MOD - [2014-11-20 09:37:59 | 000,024,064 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32pipe.pyd MOD - [2014-11-20 09:37:59 | 000,022,528 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32ts.pyd MOD - [2014-11-20 09:37:59 | 000,018,432 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32event.pyd MOD - [2014-11-20 09:37:59 | 000,017,408 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32profile.pyd MOD - [2014-11-20 09:37:59 | 000,011,264 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32crypt.pyd MOD - [2014-11-20 09:37:59 | 000,010,240 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\select.pyd MOD - [2014-11-20 09:37:59 | 000,007,168 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\hashobjs_ext.pyd MOD - [2014-11-20 09:37:58 | 000,035,840 | ---- | M] () -- C:\Users\DESTRO~1\AppData\Local\Temp\_MEI45602\win32process.pyd MOD - [2014-11-18 23:21:04 | 000,718,848 | ---- | M] () -- C:\Users\Destroy666\AppData\Local\Apps\2.0\A79BRVQT.4RX\WZ668WAJ.981\gith..tion_317444273a93ac29_0002.0006_322e607d54d660d4\git2-69db893.DLL MOD - [2014-11-18 23:21:04 | 000,612,664 | ---- | M] () -- C:\Users\Destroy666\AppData\Local\Apps\2.0\A79BRVQT.4RX\WZ668WAJ.981\gith..tion_317444273a93ac29_0002.0006_322e607d54d660d4\sqlite3.DLL MOD - [2014-10-16 02:20:37 | 019,547,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\3d1acd5d42efed17d6c6ce2836a7403e\System.ServiceModel.ni.dll MOD - [2014-10-16 02:20:27 | 000,522,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net.Http\e1987cca3aae6d9273092a729ea4ba71\System.Net.Http.ni.dll MOD - [2014-10-16 02:20:03 | 000,016,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\9e42fe7c83345249b5dde1693d1bf8b5\PresentationFramework-SystemXml.ni.dll MOD - [2014-10-16 02:20:03 | 000,012,288 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio4b37ff64#\92edcd808511b7f4b642f922f8ebc31c\PresentationFramework-SystemXmlLinq.ni.dll MOD - [2014-10-16 02:20:02 | 000,023,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio84a6349c#\fe9d914c8af2b4fb61e078e8816d273a\PresentationFramework-SystemCore.ni.dll MOD - [2014-10-16 02:20:02 | 000,017,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1da2af67#\dce7f2e79a5a443accd3d404731a67ef\PresentationFramework-SystemDrawing.ni.dll MOD - [2014-10-16 02:20:02 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio84a7b877#\825c2900a23128a2fd3de768abc9b023\PresentationFramework-SystemData.ni.dll MOD - [2014-10-16 02:17:53 | 001,033,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Compba577418#\277ac466da7add095f06cf9ce9b1d9d3\System.ComponentModel.Composition.ni.dll MOD - [2014-10-16 02:17:35 | 000,236,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Comp46f2b404#\59001268ed702a79bb7495201d107e3f\System.ComponentModel.DataAnnotations.ni.dll MOD - [2014-10-16 02:17:24 | 002,803,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\ad1a5e8488b493088c4317191604dc81\System.Runtime.Serialization.ni.dll MOD - [2014-10-16 02:17:23 | 000,392,704 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\dc6525681fbd6d2b2f1a66db7031f527\System.Xml.Linq.ni.dll MOD - [2014-10-16 02:16:08 | 001,853,440 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Deployment\31cd19affb5ba38bfd4e4f5b23032619\System.Deployment.ni.dll MOD - [2014-10-16 02:16:07 | 000,728,576 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Security\04e83031fac311abf5a1d3db9e095859\System.Security.ni.dll MOD - [2014-10-16 02:11:14 | 018,753,024 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\d747bc7ada99b5060484e3095274c9d0\PresentationFramework.ni.dll MOD - [2014-10-16 02:11:05 | 011,014,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\b96f42b103d3455036bbeb8fee037931\PresentationCore.ni.dll MOD - [2014-10-16 02:11:03 | 007,386,624 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\5b51c6c31291676944903acbbf711d8d\System.Data.ni.dll MOD - [2014-10-16 02:11:02 | 012,895,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\bcc9a98d4cae057c7278f80d56836140\System.Windows.Forms.ni.dll MOD - [2014-10-16 02:11:00 | 007,787,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\a4066040e82329538bec1a194a222d93\System.Xml.ni.dll MOD - [2014-10-16 02:11:00 | 006,982,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\32282378a8280af393b626510cf4a5b9\System.Core.ni.dll MOD - [2014-10-16 02:10:58 | 003,904,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\96ef38bc80d4e36e0812ee749f90f435\WindowsBase.ni.dll MOD - [2014-10-16 02:10:58 | 001,873,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\b743aed31731aa473e125bb63f43b3f4\System.Xaml.ni.dll MOD - [2014-10-16 02:10:56 | 001,639,936 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\53d0b6fa2fc28f7d50f84999fc2a1bbf\System.Drawing.ni.dll MOD - [2014-10-16 02:10:56 | 000,458,240 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\5e3e26e6c81809aab854ea76a884fde2\PresentationFramework.Aero.ni.dll MOD - [2014-10-16 02:10:55 | 010,069,504 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\d18e2115a3270f89663fce831547f534\System.ni.dll MOD - [2014-10-16 02:10:55 | 001,169,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\82f6179063c1d1fa69f57c4d59a850a8\System.Management.ni.dll MOD - [2014-10-16 02:10:55 | 000,967,680 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\8b7f1232264c4795152f77a2434c02ab\System.Configuration.ni.dll MOD - [2014-10-01 22:44:05 | 000,295,936 | ---- | M] () -- C:\Users\Destroy666\AppData\Local\GitHub\PortableGit_ed44d00daa128db527396557813e7b68709ed0e2\bin\ssh-agent.exe MOD - [2014-09-29 11:03:20 | 000,514,048 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe MOD - [2014-09-29 11:03:18 | 009,515,520 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\QtGui4.dll MOD - [2014-09-29 11:03:18 | 002,415,104 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\QtCore4.dll MOD - [2014-09-29 11:03:18 | 001,148,416 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\QtNetwork4.dll MOD - [2014-09-29 11:03:18 | 001,101,824 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\NDISAPI.dll MOD - [2014-09-29 11:03:18 | 001,077,248 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\AddrBookPlugin.dll MOD - [2014-09-29 11:03:18 | 000,808,960 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\SMSUIPlugin.dll MOD - [2014-09-29 11:03:18 | 000,739,328 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\AddrBookUIPlugin.dll MOD - [2014-09-29 11:03:18 | 000,670,720 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\SmsAppPlugin.dll MOD - [2014-09-29 11:03:18 | 000,550,400 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\CallAppPlugin.dll MOD - [2014-09-29 11:03:18 | 000,547,840 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\CallLogSrvPlugin.dll MOD - [2014-09-29 11:03:18 | 000,545,280 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\PluginContainer.dll MOD - [2014-09-29 11:03:18 | 000,495,104 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\DeviceMgrUIPlugin.dll MOD - [2014-09-29 11:03:18 | 000,483,328 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\NetInfoUIExPlugin.dll MOD - [2014-09-29 11:03:18 | 000,428,032 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\core.dll MOD - [2014-09-29 11:03:18 | 000,427,008 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\DialupUIPlugin.dll MOD - [2014-09-29 11:03:18 | 000,384,512 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\USSDUIPlugin.dll MOD - [2014-09-29 11:03:18 | 000,381,952 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\Proxy.DLL MOD - [2014-09-29 11:03:18 | 000,370,176 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\plugins\imageformats\qtiff4.dll MOD - [2014-09-29 11:03:18 | 000,350,720 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\plugins\imageformats\qmng4.dll MOD - [2014-09-29 11:03:18 | 000,338,432 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\DeviceAppPlugin.dll MOD - [2014-09-29 11:03:18 | 000,334,848 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\MainpagePlugin.dll MOD - [2014-09-29 11:03:18 | 000,333,312 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\NetConnectPlugin.dll MOD - [2014-09-29 11:03:18 | 000,308,224 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\StatusBarMgrPlugin.dll MOD - [2014-09-29 11:03:18 | 000,301,056 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\DeviceSrvPlugin.dll MOD - [2014-09-29 11:03:18 | 000,278,528 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\NetInfoSrvPlugin.dll MOD - [2014-09-29 11:03:18 | 000,269,824 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\LiveUpdateInterface.DLL MOD - [2014-09-29 11:03:18 | 000,264,704 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\AddrBookSrvPlugin.dll MOD - [2014-09-29 11:03:18 | 000,261,632 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\sdk.dll MOD - [2014-09-29 11:03:18 | 000,249,344 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\MenuMgrPlugin.dll MOD - [2014-09-29 11:03:18 | 000,240,128 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\ToolBarMgrPlugin.dll MOD - [2014-09-29 11:03:18 | 000,238,080 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\AtCodec.dll MOD - [2014-09-29 11:03:18 | 000,235,008 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\NetSrvPlugin.dll MOD - [2014-09-29 11:03:18 | 000,218,112 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\Common.dll MOD - [2014-09-29 11:03:18 | 000,217,600 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\SmsSrvPlugin.dll MOD - [2014-09-29 11:03:18 | 000,211,968 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\DialUpPlugin.dll MOD - [2014-09-29 11:03:18 | 000,192,000 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\plugins\imageformats\qjpeg4.dll MOD - [2014-09-29 11:03:18 | 000,190,464 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\XFramePlugin.dll MOD - [2014-09-29 11:03:18 | 000,180,224 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\NDISPlugin.dll MOD - [2014-09-29 11:03:18 | 000,176,128 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\CallSrvPlugin.dll MOD - [2014-09-29 11:03:18 | 000,159,232 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\XCodec.dll MOD - [2014-09-29 11:03:18 | 000,158,720 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\NetConnectSrvPlugin.dll MOD - [2014-09-29 11:03:18 | 000,157,184 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\DataServicePlugin.dll MOD - [2014-09-29 11:03:18 | 000,156,672 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\STKSrvPlugin.dll MOD - [2014-09-29 11:03:18 | 000,142,336 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\USSDSrvPlugin.dll MOD - [2014-09-29 11:03:18 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\Trace.dll MOD - [2014-09-29 11:03:18 | 000,133,120 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\OSDialup.dll MOD - [2014-09-29 11:03:18 | 000,131,072 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\OSNDIS.dll MOD - [2014-09-29 11:03:18 | 000,123,392 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\ATR2SMgr.dll MOD - [2014-09-29 11:03:18 | 000,118,272 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\LayoutPlugin.dll MOD - [2014-09-29 11:03:18 | 000,106,496 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\Win7Support.dll MOD - [2014-09-29 11:03:18 | 000,101,376 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\OSAdapt.dll MOD - [2014-09-29 11:03:18 | 000,093,184 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\NotifyServicePlugin.dll MOD - [2014-09-29 11:03:18 | 000,082,944 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\plugins\imageformats\qgif4.dll MOD - [2014-09-29 11:03:18 | 000,081,920 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\plugins\imageformats\qico4.dll MOD - [2014-09-29 11:03:18 | 000,065,536 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\OSPowerMgr.dll MOD - [2014-09-29 11:03:18 | 000,062,976 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\OSCall.dll MOD - [2014-09-29 11:03:18 | 000,043,008 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\libgcc_s_dw2-1.dll MOD - [2014-09-29 11:03:18 | 000,011,362 | ---- | M] () -- C:\Program Files (x86)\PLAY ONLINE\mingwm10.dll MOD - [2014-09-27 02:26:40 | 000,091,792 | ---- | M] () -- C:\Users\Destroy666\AppData\Local\GitHub\PortableGit_ed44d00daa128db527396557813e7b68709ed0e2\bin\msys-z.dll MOD - [2014-09-24 15:39:44 | 000,118,784 | ---- | M] () -- C:\Program Files (x86)\Notepad++\plugins\NppQCP.dll MOD - [2014-09-24 15:39:30 | 000,204,800 | ---- | M] () -- C:\Program Files (x86)\Notepad++\plugins\ComparePlugin.dll MOD - [2014-09-06 17:44:46 | 000,035,328 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll MOD - [2014-09-04 13:52:12 | 000,019,968 | ---- | M] () -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\pl_PL\acrotray.pol MOD - [2014-09-03 01:03:53 | 000,018,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime\a5d5b495ed4752c3b73b5d1938ee9a78\System.Runtime.ni.dll MOD - [2014-09-03 01:03:53 | 000,009,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Thre7bb2aad0#\9db7dab1c0f96ffbce166ca11071f7a1\System.Threading.Tasks.ni.dll MOD - [2014-09-03 01:03:53 | 000,008,704 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Threading\4b925df23c49f7739afb59433c0a5394\System.Threading.ni.dll MOD - [2014-09-03 01:03:53 | 000,008,704 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt1e58aa76#\64439ff92b19728d343afc857b145718\System.Runtime.Extensions.ni.dll MOD - [2014-09-03 01:03:53 | 000,008,704 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Reflection\b81a703e1f50365d6cf4c9c95a9930eb\System.Reflection.ni.dll MOD - [2014-09-03 01:03:53 | 000,008,704 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Collections\24a4c7b82b483cc3b5ab8e587593482a\System.Collections.ni.dll MOD - [2014-09-03 01:03:53 | 000,008,192 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Linq\bd4b5b1e66e80332a1f081f634e6cf40\System.Linq.ni.dll MOD - [2014-09-02 22:29:31 | 000,188,416 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\232495ea0368dada2d208c51f0e5349c\UIAutomationTypes.ni.dll MOD - [2014-09-02 22:29:31 | 000,098,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\94c5cba998f28affea3889fcdf99d66c\UIAutomationProvider.ni.dll MOD - [2014-09-02 22:29:27 | 000,146,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\de2a832558f95db343e443c365bd3575\System.Numerics.ni.dll MOD - [2014-09-02 20:40:48 | 017,207,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d1265d6159ea876f9d63ea4c1361b587\mscorlib.ni.dll MOD - [2014-08-20 09:30:35 | 000,596,992 | ---- | M] () -- C:\Program Files (x86)\Git\git-cheetah\..\bin\sh.exe MOD - [2014-08-20 09:30:35 | 000,596,992 | ---- | M] () -- C:\Program Files (x86)\Git\bin\sh.exe MOD - [2014-08-12 17:56:44 | 000,076,648 | ---- | M] () -- C:\Program Files\TortoiseGit\bin\zlib132_tgit.dll MOD - [2014-08-12 17:56:42 | 000,592,232 | ---- | M] () -- C:\Program Files\TortoiseGit\bin\libgit232_tgit.dll MOD - [2014-08-10 14:40:22 | 000,065,792 | ---- | M] () -- C:\Program Files\TortoiseSVN\bin\TortoiseStub32.dll MOD - [2014-08-08 20:00:26 | 000,127,488 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\bin\pyexpat.pyd MOD - [2014-08-08 20:00:26 | 000,036,352 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\bin\_psutil_mswindows.pyd MOD - [2014-08-08 20:00:25 | 000,899,584 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\bin\_ssl.pyd MOD - [2014-08-08 20:00:25 | 000,686,080 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\bin\unicodedata.pyd MOD - [2014-08-08 20:00:25 | 000,358,400 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\bin\_hashlib.pyd MOD - [2014-08-08 20:00:25 | 000,128,512 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\bin\_elementtree.pyd MOD - [2014-08-08 20:00:25 | 000,087,552 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\bin\_ctypes.pyd MOD - [2014-08-08 20:00:25 | 000,044,544 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\bin\_socket.pyd MOD - [2014-08-08 20:00:25 | 000,027,136 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\bin\_multiprocessing.pyd MOD - [2014-08-08 20:00:25 | 000,010,240 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\bin\select.pyd MOD - [2014-07-03 05:45:40 | 032,733,056 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\libcef.dll MOD - [2014-07-03 05:45:40 | 000,742,784 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\libglesv2.dll MOD - [2014-07-03 05:45:40 | 000,136,576 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\libegl.dll MOD - [2014-06-14 14:18:18 | 016,814,080 | ---- | M] () -- C:\lazarus\lazarus.exe MOD - [2014-05-24 17:41:24 | 000,892,416 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\libstdc++-6.dll MOD - [2014-05-24 17:41:24 | 000,091,648 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\libgcc_s_sjlj-1.dll MOD - [2014-05-13 11:04:48 | 000,167,768 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl MOD - [2014-05-13 11:04:46 | 000,109,400 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl MOD - [2014-05-13 11:04:42 | 000,416,600 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl MOD - [2014-04-09 00:21:08 | 000,128,512 | ---- | M] () -- C:\XAMPP\php\libpq.dll MOD - [2014-03-11 21:01:40 | 000,217,600 | ---- | M] () -- c:\XAMPP\apache\bin\pcre.dll MOD - [2014-01-14 16:54:56 | 010,966,528 | ---- | M] () -- c:\XAMPP\mysql\bin\mysqld.exe MOD - [2014-01-07 00:42:32 | 001,611,264 | ---- | M] () -- C:\Program Files (x86)\Notepad++\plugins\NppFTP.dll MOD - [2013-12-11 22:02:47 | 000,160,256 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\bin\modules\tray\mxwin.pyd MOD - [2013-11-21 20:16:40 | 000,030,720 | ---- | M] () -- C:\Program Files (x86)\Nexon\Nexon Launcher\bin\modules\tray\Nexon.Mantis.Client.Resources.dll MOD - [2013-06-17 10:42:31 | 002,569,216 | ---- | M] () -- C:\XAMPP\xampp-control.exe MOD - [2012-09-28 12:50:46 | 003,598,848 | ---- | M] () -- C:\lazarus\mingw\i386-win32\bin\gdb.exe MOD - [2011-07-18 22:07:28 | 000,014,336 | ---- | M] () -- C:\Program Files (x86)\Notepad++\plugins\NppExport.dll MOD - [2010-11-26 14:06:46 | 000,165,513 | ---- | M] () -- C:\lazarus\mingw\i386-win32\bin\libexpat-1.dll MOD - [1997-02-27 01:00:00 | 000,021,504 | ---- | M] () -- C:\Program Files (x86)\Windows Grep\CIO32.DLL MOD - [1997-02-27 01:00:00 | 000,020,480 | ---- | M] () -- C:\Program Files (x86)\Windows Grep\REGEXP32.DLL [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2014-11-06 18:07:54 | 001,148,744 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService) SRV:[b]64bit:[/b] - [2014-11-06 18:07:49 | 019,819,848 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc) SRV:[b]64bit:[/b] - [2014-11-06 04:30:08 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService) SRV:[b]64bit:[/b] - [2014-09-04 11:43:20 | 001,357,104 | ---- | M] (Flexera Software LLC) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe -- (FlexNet Licensing Service 64) SRV:[b]64bit:[/b] - [2014-08-22 14:14:34 | 000,368,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV:[b]64bit:[/b] - [2014-08-22 14:14:34 | 000,023,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV:[b]64bit:[/b] - [2014-08-14 04:47:05 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:[b]64bit:[/b] - [2014-08-14 04:43:43 | 000,350,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\inetsrv\ftpsvc.dll -- (ftpsvc) SRV:[b]64bit:[/b] - [2013-11-11 17:09:08 | 003,783,736 | ---- | M] (Perforce Software Inc.) [Auto | Running] -- C:\Program Files\Perforce\Server\p4s.exe -- (Perforce) SRV:[b]64bit:[/b] - [2011-09-15 05:19:54 | 000,086,016 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Autodesk\3ds Max Design 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe -- (mi-raysat_3dsmax2015_64) SRV:[b]64bit:[/b] - [2010-04-06 15:30:38 | 000,031,272 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\AppleChargerSrv.exe -- (AppleChargerSrv) SRV:[b]64bit:[/b] - [2009-07-14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2014-12-11 07:42:47 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014-11-28 18:22:44 | 005,419,792 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe -- (TeamViewer) SRV - [2014-11-26 17:40:36 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2014-11-26 10:35:00 | 000,599,944 | ---- | M] (Autodesk Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe -- (AdAppMgrSvc) SRV - [2014-11-12 21:46:08 | 000,409,800 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2014-11-06 18:07:54 | 001,795,912 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService) SRV - [2014-10-28 16:15:34 | 000,244,448 | ---- | M] (Foxit Software Inc.) [Auto | Running] -- C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe -- (FoxitCloudUpdateService) SRV - [2014-09-29 11:03:18 | 000,246,112 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\PLAY ONLINE\UpdateDog\ouc.exe -- (PLAY ONLINE. RunOuc) SRV - [2014-09-16 22:10:54 | 000,569,024 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2014-09-04 04:50:26 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2014-08-20 07:14:05 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2014-08-14 04:52:57 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2014-07-22 20:17:28 | 000,089,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe -- (VsEtwService120) SRV - [2014-04-11 22:08:08 | 000,103,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2014-04-03 19:21:48 | 000,315,008 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2014-01-27 13:05:54 | 000,773,968 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) SRV - [2013-02-04 17:43:22 | 000,155,824 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion) SRV - [2011-03-14 16:27:34 | 000,346,976 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\HWDeviceService64.exe -- (HWDeviceService64.exe) SRV - [2010-11-21 04:24:51 | 000,397,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS) SRV - [2010-11-21 04:24:51 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc) SRV - [2010-02-19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2014-11-24 12:07:02 | 000,141,440 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys -- (VBoxNetAdp) DRV:[b]64bit:[/b] - [2014-11-06 18:07:49 | 000,019,784 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms) DRV:[b]64bit:[/b] - [2014-10-03 20:23:02 | 000,038,216 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible) DRV:[b]64bit:[/b] - [2014-09-29 11:03:18 | 000,421,376 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbwwan.sys -- (ewusbmbb) DRV:[b]64bit:[/b] - [2014-09-29 11:03:18 | 000,222,464 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard) DRV:[b]64bit:[/b] - [2014-09-29 11:03:18 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV:[b]64bit:[/b] - [2014-09-29 11:03:18 | 000,086,016 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator) DRV:[b]64bit:[/b] - [2014-09-17 05:51:20 | 000,197,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:[b]64bit:[/b] - [2014-09-04 04:06:47 | 000,030,424 | ---- | M] (Sony Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsomc.sys -- (ggsomc) DRV:[b]64bit:[/b] - [2014-09-04 04:06:47 | 000,016,088 | ---- | M] (Sony Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt) DRV:[b]64bit:[/b] - [2014-08-14 04:42:13 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2014-07-17 17:05:06 | 000,125,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:[b]64bit:[/b] - [2013-10-02 03:22:44 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2013-10-02 03:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2013-07-24 16:02:55 | 000,034,816 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone) DRV:[b]64bit:[/b] - [2013-03-04 13:24:27 | 000,040,344 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO) DRV:[b]64bit:[/b] - [2012-10-25 08:01:20 | 000,022,680 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AppleCharger.sys -- (AppleCharger) DRV:[b]64bit:[/b] - [2012-10-11 08:36:54 | 001,579,520 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) DRV:[b]64bit:[/b] - [2012-08-23 15:12:16 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt) DRV:[b]64bit:[/b] - [2012-08-23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:[b]64bit:[/b] - [2012-07-19 10:14:28 | 000,110,744 | ---- | M] (Qualcomm Atheros Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) DRV:[b]64bit:[/b] - [2011-11-03 02:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:[b]64bit:[/b] - [2011-03-11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011-03-11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) DRV:[b]64bit:[/b] - [2010-11-21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV - [2014-09-27 00:37:57 | 000,025,640 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv) DRV - [2013-03-14 13:36:18 | 000,017,160 | ---- | M] (XFire) [File_System | On_Demand | Running] -- C:\Program Files (x86)\Xfire2\XFDriver64.sys -- (XFDriver64) DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) DRV - [2002-01-12 16:30:34 | 000,003,567 | ---- | M] (Beyond Logic http://www.beyondlogic.org) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\PortTalk.sys -- (PortTalk) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:Tabs IE - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BB BC 68 AE 4D C9 CF 01 [binary data] IE - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 IE - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.1.1 FF - user.js - File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\MICROS~4\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1214154.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files (x86)\MIF5BA~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\Program Files (x86)\Common Files\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Destroy666\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2014-08-24 23:40:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014-10-31 10:40:03 | 000,000,000 | ---D | M] [2014-08-19 13:14:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Destroy666\AppData\Roaming\mozilla\Extensions [2014-10-26 21:56:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Destroy666\AppData\Roaming\mozilla\Firefox\Profiles\r6wfsi8r.default\extensions [2014-08-21 23:52:12 | 000,414,727 | ---- | M] () (No name found) -- C:\Users\Destroy666\AppData\Roaming\mozilla\firefox\profiles\r6wfsi8r.default\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2014-10-26 21:56:46 | 000,979,610 | ---- | M] () (No name found) -- C:\Users\Destroy666\AppData\Roaming\mozilla\firefox\profiles\r6wfsi8r.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-12-08 08:02:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions [2014-12-08 08:02:49 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2014-01-21 19:07:48 | 000,034,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: () CHR - default_search_provider: search_url = CHR - default_search_provider: suggest_url = CHR - plugin: Error reading preferences file CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\alelhddbbhepgpmgidjdcjakblofbmce\3.7.21_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\3.0.0.20_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.8_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhgpkiiipkgmckicafkhcihkcldbdeej\1.9.0_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\faminaibgiklngmfpfbhmokfmnglamcm\0.14.2.2_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.14.4_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\khpcanbeojalbkpgpmjpdkjnkfcgfkhb\1.3.6_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.8_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfkgmnnajiljnolcgolmmgnecgldgeld\0.17.14_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh\3.2_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.7_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\nimiijnfibipcogbklbghpjdnhjfneoi\1.3_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\6.2.6_0\ CHR - Extension: No name found = C:\Users\Destroy666\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2014-08-24 23:30:15 | 000,002,812 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 192.150.14.69 O1 - Hosts: 127.0.0.1 192.150.18.101 O1 - Hosts: 127.0.0.1 192.150.18.108 O1 - Hosts: 127.0.0.1 192.150.22.40 O1 - Hosts: 127.0.0.1 192.150.8.100 O1 - Hosts: 127.0.0.1 192.150.8.118 O1 - Hosts: 127.0.0.1 209-34-83-73.ood.opsource.net O1 - Hosts: 127.0.0.1 3dns-1.adobe.com O1 - Hosts: 127.0.0.1 3dns-2.adobe.com O1 - Hosts: 127.0.0.1 3dns-2.adobe.com O1 - Hosts: 127.0.0.1 3dns-3.adobe.com O1 - Hosts: 127.0.0.1 3dns-3.adobe.com O1 - Hosts: 127.0.0.1 3dns-4.adobe.com O1 - Hosts: 127.0.0.1 3dns.adobe.com O1 - Hosts: 127.0.0.1 activate-sea.adobe.com O1 - Hosts: 127.0.0.1 activate-sea.adobe.com O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com O1 - Hosts: 127.0.0.1 activate.adobe.com O1 - Hosts: 127.0.0.1 activate.adobe.com O1 - Hosts: 127.0.0.1 activate.wip.adobe.com O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com O1 - Hosts: 127.0.0.1 activate.wip2.adobe.com O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com O1 - Hosts: 40 more lines... O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Evernote extension) - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\MIF5BA~1\Office15\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\MIF5BA~1\Office15\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O4:[b]64bit:[/b] - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:[b]64bit:[/b] - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:[b]64bit:[/b] - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [ADSKAppManager] C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe (Autodesk Inc.) O4 - HKLM..\Run: [Andy] C:\Program Files\Andy\HandyAndy.exe () O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Dominik Reichl) O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000..\Run: [AdobeBridge] File not found O4 - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd) O4 - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000..\Run: [GoogleChromeAutoLaunch_609358DFCF638B6D3844E8AADD52BE06] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) O4 - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000..\Run: [GoogleDriveSync] C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google) O4 - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000..\Run: [Mobile Partner] C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe () O4 - HKU\S-1-5-21-3771943680-3238516612-2783291097-1000..\Run: [Windows(R) Statistics Service] C:\ProgramData\WinSTAT\WinSTAT.exe (Microsoft® Corporation) O4 - HKLM..\RunOnce: [GBTUpd] C:\Program Files (x86)\GIGABYTE\UpdManager\PreRun.exe (PreRun) O4 - HKLM..\RunOnce: [NSIS.Library.RegTool.v3] C:\Program Files (x86)\FileZilla FTP Client\NSIS.Library.RegTool.v3.{F42F401B-F931-45F2-9EF1-0EBEE2297E8E}.exe () O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - Startup: C:\Users\Destroy666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Destroy666\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O4 - Startup: C:\Users\Destroy666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WinSTAT.exe (Microsoft® Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O8:[b]64bit:[/b] - Extra context menu item: Clip Image - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4 File not found O8:[b]64bit:[/b] - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3 File not found O8:[b]64bit:[/b] - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1 File not found O8:[b]64bit:[/b] - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 File not found O8:[b]64bit:[/b] - Extra context menu item: Dołącz do istniejącego pliku PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:[b]64bit:[/b] - Extra context menu item: Dołącz obiekt docelowy łącza do istniejącego pliku PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:[b]64bit:[/b] - Extra context menu item: Konwertuj do Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:[b]64bit:[/b] - Extra context menu item: Konwertuj obiekt docelowy łącza na plik Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:[b]64bit:[/b] - Extra context menu item: New Note - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html () O8:[b]64bit:[/b] - Extra context menu item: Nowa notatka - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html () O8:[b]64bit:[/b] - Extra context menu item: Wytnij obraz - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4 File not found O8:[b]64bit:[/b] - Extra context menu item: Wytnij tę stronę - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1 File not found O8:[b]64bit:[/b] - Extra context menu item: Wytnij zakładkę - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0 File not found O8:[b]64bit:[/b] - Extra context menu item: Wytnij zaznaczenie - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3 File not found O8 - Extra context menu item: Clip Image - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4 File not found O8 - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3 File not found O8 - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1 File not found O8 - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 File not found O8 - Extra context menu item: Dołącz do istniejącego pliku PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Dołącz obiekt docelowy łącza do istniejącego pliku PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Konwertuj do Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Konwertuj obiekt docelowy łącza na plik Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: New Note - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html () O8 - Extra context menu item: Nowa notatka - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html () O8 - Extra context menu item: Wytnij obraz - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4 File not found O8 - Extra context menu item: Wytnij tę stronę - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1 File not found O8 - Extra context menu item: Wytnij zakładkę - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0 File not found O8 - Extra context menu item: Wytnij zaznaczenie - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3 File not found O9:[b]64bit:[/b] - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\AddNote.html () O9:[b]64bit:[/b] - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\AddNote.html () O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html () O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html () O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} http://download.gigabyte.com.tw/object/Dldrv.ocx (Dldrv2 Control) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 157.158.3.1 157.158.3.2 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3205A913-6B11-4DDD-89D8-6B9FDDBD5DBD}: NameServer = 193.41.112.14 193.41.112.18 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{34BC744E-D5F1-417C-BBD8-6FD61FEA90F3}: NameServer = 193.41.112.18 193.41.112.14 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3D238789-F486-4794-A74E-B0F47A1F3614}: DhcpNameServer = 157.158.3.1 157.158.3.2 O18 - Protocol\Handler\ms-help - No CLSID value found O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{25099b18-32ef-11e4-9b93-74d43575c7fd}\Shell - "" = AutoRun O33 - MountPoints2\{25099b18-32ef-11e4-9b93-74d43575c7fd}\Shell\AutoRun\command - "" = H:\SETUP.EXE O33 - MountPoints2\{25099b18-32ef-11e4-9b93-74d43575c7fd}\Shell\configure\command - "" = H:\SETUP.EXE O33 - MountPoints2\{25099b18-32ef-11e4-9b93-74d43575c7fd}\Shell\install\command - "" = H:\SETUP.EXE O33 - MountPoints2\{37c71b50-62ca-11e4-9727-c04a00091a60}\Shell - "" = AutoRun O33 - MountPoints2\{37c71b50-62ca-11e4-9727-c04a00091a60}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{45bbcd1b-47bd-11e4-9302-c04a00091a60}\Shell - "" = AutoRun O33 - MountPoints2\{45bbcd1b-47bd-11e4-9302-c04a00091a60}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{45bbcd27-47bd-11e4-9302-c04a00091a60}\Shell - "" = AutoRun O33 - MountPoints2\{45bbcd27-47bd-11e4-9302-c04a00091a60}\Shell\AutoRun\command - "" = G:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-12-11 07:44:08 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2014-12-10 17:26:43 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSManMigrationPlugin.dll [2014-12-10 17:26:43 | 000,310,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmWmiPl.dll [2014-12-10 17:26:43 | 000,266,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSManHTTPConfig.exe [2014-12-10 17:26:43 | 000,181,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmAuto.dll [2014-12-10 17:26:43 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\charmap.exe [2014-12-10 17:26:43 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\charmap.exe [2014-12-10 17:26:42 | 000,248,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManMigrationPlugin.dll [2014-12-10 17:26:42 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmWmiPl.dll [2014-12-10 17:26:42 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManHTTPConfig.exe [2014-12-10 17:26:42 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmAuto.dll [2014-12-10 07:29:04 | 000,000,000 | ---D | C] -- C:\Users\Destroy666\AppData\Local\ElevatedDiagnostics [2014-12-08 08:04:07 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype [2014-12-08 08:04:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2014-12-08 08:04:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype [2014-12-08 08:03:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader [2014-12-07 00:22:44 | 000,000,000 | ---D | C] -- C:\Users\Destroy666\AppData\Local\TeamViewer [2014-12-07 00:14:42 | 000,000,000 | ---D | C] -- C:\Users\Destroy666\AppData\Roaming\TeamViewer [2014-12-05 13:49:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox [2014-12-05 13:49:12 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle [2014-12-05 13:38:47 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour [2014-12-05 13:38:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour [2014-12-05 13:38:46 | 000,000,000 | ---D | C] -- C:\Users\Destroy666\VirtualBox VMs [2014-12-05 13:38:34 | 000,000,000 | ---D | C] -- C:\Users\Destroy666\AppData\Roaming\Andy [2014-12-05 13:38:34 | 000,000,000 | ---D | C] -- C:\Users\Destroy666\Andy [2014-12-05 13:38:34 | 000,000,000 | ---D | C] -- C:\Users\Destroy666\.VirtualBox [2014-12-05 13:38:33 | 000,000,000 | ---D | C] -- C:\Users\Destroy666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Andy [2014-12-05 13:37:47 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE [2014-12-05 13:37:18 | 000,000,000 | ---D | C] -- C:\Program Files\AndyOfflineInstaller [2014-12-05 13:30:50 | 000,000,000 | ---D | C] -- C:\Program Files\Andy [2014-12-01 19:28:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam [2014-12-01 19:28:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam [2014-12-01 19:28:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam [2014-12-01 19:10:39 | 000,000,000 | ---D | C] -- C:\Users\Destroy666\AppData\Roaming\Opera [2014-12-01 19:10:39 | 000,000,000 | ---D | C] -- C:\Users\Destroy666\AppData\Local\Opera [2014-12-01 19:10:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera x64 [2014-12-01 19:10:37 | 000,000,000 | ---D | C] -- C:\Program Files\Opera x64 [2014-11-29 23:23:19 | 000,000,000 | ---D | C] -- C:\Users\Destroy666\Documents\Niestandardowe szablony pakietu Office [2014-11-27 21:39:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote [2014-11-27 21:39:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Evernote [2014-11-27 20:22:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent [2014-11-24 12:07:02 | 000,141,440 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys [2014-11-22 22:36:11 | 000,000,000 | -HSD | C] -- C:\Users\Destroy666\AppData\Local\EmieBrowserModeList [2014-11-19 02:03:23 | 000,615,624 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe [2014-11-19 02:01:58 | 031,893,136 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll [2014-11-19 02:01:58 | 024,557,712 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll [2014-11-19 02:01:58 | 020,922,512 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll [2014-11-19 02:01:58 | 019,966,344 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll [2014-11-19 02:01:58 | 017,259,664 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll [2014-11-19 02:01:58 | 014,032,984 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll [2014-11-19 02:01:58 | 013,944,952 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll [2014-11-19 02:01:58 | 011,397,744 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll [2014-11-19 02:01:58 | 011,336,432 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll [2014-11-19 02:01:58 | 004,292,416 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll [2014-11-19 02:01:58 | 004,011,208 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll [2014-11-19 02:01:58 | 001,876,296 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6434475.dll [2014-11-19 02:01:58 | 001,540,424 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6434475.dll [2014-11-19 02:01:58 | 000,964,928 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFR64.dll [2014-11-19 02:01:58 | 000,935,240 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvFBC64.dll [2014-11-19 02:01:58 | 000,923,792 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFR.dll [2014-11-19 02:01:58 | 000,900,928 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvFBC.dll [2014-11-19 02:01:58 | 000,871,648 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvumdshim.dll [2014-11-19 02:01:58 | 000,500,880 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvEncodeAPI64.dll [2014-11-19 02:01:58 | 000,418,112 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvEncodeAPI.dll [2014-11-19 02:01:58 | 000,393,024 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFROpenGL.dll [2014-11-19 02:01:58 | 000,352,016 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglshim64.dll [2014-11-19 02:01:58 | 000,348,304 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFROpenGL.dll [2014-11-19 02:01:58 | 000,303,600 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglshim32.dll [2014-11-19 02:01:58 | 000,174,856 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvinitx.dll [2014-11-19 02:01:58 | 000,156,840 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvinit.dll [2014-11-18 20:47:50 | 001,691,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FM20.DLL [2014-11-15 00:09:13 | 000,000,000 | ---D | C] -- C:\Users\Destroy666\Documents\Navicat [2014-11-15 00:01:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremiumSoft [2014-11-15 00:01:24 | 000,000,000 | ---D | C] -- C:\Program Files\PremiumSoft [2014-11-12 16:30:21 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll [2014-11-12 16:30:21 | 000,304,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll [2014-11-12 16:30:21 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll [2014-11-12 16:30:19 | 001,460,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll [2014-11-12 16:30:19 | 000,681,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll [2014-11-12 16:30:19 | 000,681,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll [2014-11-12 16:30:19 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msaudite.dll [2014-11-12 16:30:19 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msaudite.dll [2014-11-12 16:30:17 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe [2014-11-12 16:30:17 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2014-11-12 16:30:17 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll [2014-11-12 16:30:17 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll [2014-11-12 16:30:17 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll [2014-11-12 16:30:16 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe [2014-11-12 16:30:16 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll [2014-11-12 16:30:16 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll [2014-11-12 16:30:16 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll [2014-11-12 16:30:15 | 002,051,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2014-11-12 16:30:15 | 000,708,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll [2014-11-12 16:30:15 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll [2014-11-12 16:30:14 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe [2014-11-12 16:30:14 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2014-11-12 16:30:14 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll [2014-11-12 16:30:14 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2014-11-12 16:30:14 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll [2014-11-12 16:30:14 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2014-11-12 16:30:14 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll [2014-11-12 16:30:13 | 002,124,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2014-11-12 16:30:13 | 000,799,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll [2014-11-12 16:30:13 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll [2014-11-12 16:30:12 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll [2014-11-12 16:30:12 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll [2014-11-12 16:30:12 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll [2014-11-12 16:30:12 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2014-11-12 16:30:12 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll [2014-11-12 16:30:11 | 006,040,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2014-11-12 16:30:11 | 001,359,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll [2014-11-12 16:30:11 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll [2014-11-12 16:30:11 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2014-11-12 16:30:11 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2014-11-12 16:30:10 | 000,580,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2014-11-12 16:30:10 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll [2014-11-12 16:30:10 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll [2014-11-12 16:25:20 | 000,878,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IMJP10K.DLL [2014-11-12 16:25:20 | 000,701,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IMJP10K.DLL [2014-11-12 16:25:20 | 000,500,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll [2014-11-12 16:25:20 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll [2014-11-12 16:25:20 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll [2014-11-12 16:25:19 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AUDIOKSE.dll [2014-11-12 16:25:19 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll [2014-11-12 16:25:19 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll [2014-11-12 16:25:19 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDump.dll [2014-11-12 16:25:18 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll [2014-11-12 16:25:13 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll [2014-11-12 16:25:13 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll [2014-11-12 16:25:11 | 003,241,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll [2014-11-12 16:25:08 | 000,861,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll [1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-12-11 13:16:11 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2014-12-11 13:04:05 | 000,268,952 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr [2014-12-11 13:04:05 | 000,268,952 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe [2014-12-11 12:52:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2014-12-11 09:17:37 | 000,268,952 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0 [2014-12-11 07:42:47 | 000,701,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2014-12-11 07:42:47 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2014-12-11 07:42:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2014-12-10 18:26:12 | 000,026,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2014-12-10 18:26:12 | 000,026,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2014-12-10 17:16:00 | 000,001,044 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2014-12-09 16:09:02 | 001,868,848 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2014-12-09 16:09:02 | 000,814,418 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2014-12-09 16:09:02 | 000,720,510 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2014-12-09 16:09:02 | 000,187,362 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2014-12-09 16:09:02 | 000,144,982 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2014-11-27 21:21:14 | 000,001,064 | ---- | M] () -- C:\Users\Destroy666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-11-26 21:56:30 | 000,002,207 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2014-11-24 12:07:02 | 000,141,440 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys [2014-11-21 06:54:02 | 000,063,704 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys [2014-11-21 06:53:52 | 000,093,400 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys [2014-11-21 06:53:48 | 000,025,816 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2014-11-20 09:37:43 | 2145,558,527 | -HS- | M] () -- C:\hiberfil.sys [2014-11-20 03:48:39 | 005,054,200 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2014-11-18 20:47:50 | 001,691,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\FM20.DLL [2014-11-13 01:20:36 | 031,893,136 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll [2014-11-13 01:20:36 | 024,557,712 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll [2014-11-13 01:20:36 | 020,986,592 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll [2014-11-13 01:20:36 | 020,922,512 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll [2014-11-13 01:20:36 | 019,966,344 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll [2014-11-13 01:20:36 | 018,514,616 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll [2014-11-13 01:20:36 | 017,259,664 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll [2014-11-13 01:20:36 | 016,884,632 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll [2014-11-13 01:20:36 | 014,032,984 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll [2014-11-13 01:20:36 | 013,944,952 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll [2014-11-13 01:20:36 | 011,397,744 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll [2014-11-13 01:20:36 | 011,336,432 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll [2014-11-13 01:20:36 | 004,292,416 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll [2014-11-13 01:20:36 | 004,011,208 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll [2014-11-13 01:20:36 | 003,262,784 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll [2014-11-13 01:20:36 | 002,874,456 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll [2014-11-13 01:20:36 | 001,876,296 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6434475.dll [2014-11-13 01:20:36 | 001,540,424 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6434475.dll [2014-11-13 01:20:36 | 000,989,056 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvumdshimx.dll [2014-11-13 01:20:36 | 000,964,928 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFR64.dll [2014-11-13 01:20:36 | 000,935,240 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\NvFBC64.dll [2014-11-13 01:20:36 | 000,923,792 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFR.dll [2014-11-13 01:20:36 | 000,900,928 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvFBC.dll [2014-11-13 01:20:36 | 000,871,648 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvumdshim.dll [2014-11-13 01:20:36 | 000,500,880 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvEncodeAPI64.dll [2014-11-13 01:20:36 | 000,418,112 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvEncodeAPI.dll [2014-11-13 01:20:36 | 000,393,024 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFROpenGL.dll [2014-11-13 01:20:36 | 000,352,016 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglshim64.dll [2014-11-13 01:20:36 | 000,348,304 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFROpenGL.dll [2014-11-13 01:20:36 | 000,303,600 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglshim32.dll [2014-11-13 01:20:36 | 000,174,856 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvinitx.dll [2014-11-13 01:20:36 | 000,156,840 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvinit.dll [2014-11-13 01:20:36 | 000,074,056 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll [2014-11-13 01:20:36 | 000,059,592 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll [2014-11-13 01:20:36 | 000,027,094 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb [2014-11-12 22:56:45 | 006,897,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll [2014-11-12 22:56:45 | 003,534,152 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll [2014-11-12 22:56:42 | 002,559,808 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll [2014-11-12 22:56:42 | 000,386,368 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll [2014-11-12 22:56:42 | 000,062,608 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll [2014-11-12 21:46:11 | 000,615,624 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe [1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-12-06 04:53:32 | 000,000,989 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk [2014-12-01 19:10:38 | 000,001,843 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera 12.17 1863.lnk [2014-11-27 21:21:14 | 000,001,064 | ---- | C] () -- C:\Users\Destroy666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-11-15 00:01:27 | 001,988,096 | ---- | C] () -- C:\Windows\SysNative\libmysql_e.dll [2014-10-09 18:20:36 | 000,005,171 | ---- | C] () -- C:\Windows\PSPICEEV.INI [2014-10-09 18:20:35 | 000,176,128 | ---- | C] () -- C:\Windows\SysWow64\lffax60n.dll [2014-10-09 18:20:35 | 000,141,824 | ---- | C] () -- C:\Windows\SysWow64\lfcmp60n.dll [2014-10-09 18:20:35 | 000,110,080 | ---- | C] () -- C:\Windows\SysWow64\lfpng60n.dll [2014-10-09 18:20:35 | 000,046,080 | ---- | C] () -- C:\Windows\SysWow64\lftif60n.dll [2014-10-09 18:20:35 | 000,043,008 | ---- | C] () -- C:\Windows\SysWow64\ltfil60n.dll [2014-10-09 18:20:35 | 000,023,552 | ---- | C] () -- C:\Windows\SysWow64\lfpcx60n.dll [2014-10-09 18:20:35 | 000,022,528 | ---- | C] () -- C:\Windows\SysWow64\lfpct60n.dll [2014-10-09 18:20:35 | 000,022,528 | ---- | C] () -- C:\Windows\SysWow64\lfeps60n.dll [2014-10-09 18:20:35 | 000,022,016 | ---- | C] () -- C:\Windows\SysWow64\lfbmp60n.dll [2014-10-09 18:20:35 | 000,020,480 | ---- | C] () -- C:\Windows\SysWow64\lfpsd60n.dll [2014-10-09 18:20:35 | 000,019,968 | ---- | C] () -- C:\Windows\SysWow64\lftga60n.dll [2014-10-09 18:20:35 | 000,019,456 | ---- | C] () -- C:\Windows\SysWow64\lfwpg60n.dll [2014-10-09 18:20:35 | 000,019,456 | ---- | C] () -- C:\Windows\SysWow64\lfwmf60n.dll [2014-10-09 18:20:35 | 000,018,432 | ---- | C] () -- C:\Windows\SysWow64\lfmsp60n.dll [2014-10-09 18:20:35 | 000,017,920 | ---- | C] () -- C:\Windows\SysWow64\lfmac60n.dll [2014-10-09 18:20:35 | 000,017,920 | ---- | C] () -- C:\Windows\SysWow64\implode.dll [2014-09-28 02:24:38 | 000,001,068 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2014-09-24 23:09:57 | 000,000,132 | ---- | C] () -- C:\Users\Destroy666\AppData\Roaming\Preferencje formatu BMP CS6 firmy Adobe [2014-09-19 00:49:50 | 000,000,828 | ---- | C] () -- C:\Users\Destroy666\_viminfo [2014-08-24 23:36:25 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI [2014-08-20 09:04:12 | 000,000,061 | ---- | C] () -- C:\Users\Destroy666\.gitconfig [2014-08-19 17:50:39 | 000,268,952 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2014-08-19 17:50:39 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2014-08-19 17:50:38 | 000,682,280 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe [2014-08-19 16:56:29 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini [2014-08-19 15:37:11 | 000,218,712 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2014-08-15 15:33:56 | 001,831,994 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013-05-28 21:22:48 | 000,641,024 | ---- | C] () -- C:\Windows\SysWow64\ficvdec_x86.dll [2012-12-28 22:04:22 | 000,036,352 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2014-08-14 04:56:46 | 014,175,744 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2014-08-14 04:56:46 | 012,874,240 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2014-09-02 23:11:55 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\AIMP3 [2014-12-05 13:38:34 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Andy [2014-09-02 22:35:45 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Audacity [2014-09-04 12:08:40 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Autodesk [2014-09-04 04:44:30 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Blender Foundation [2014-09-03 05:44:42 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\chc [2014-09-03 05:44:42 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2014-09-24 16:44:14 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\com.adobe.dmp.contentviewer [2014-08-19 15:42:30 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Dropbox [2014-12-11 08:10:48 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\FileZilla [2014-09-29 17:21:49 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Foxit Software [2014-11-18 23:21:04 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\GitHub [2014-09-30 14:34:55 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\gnupg [2014-11-15 17:32:21 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\KeePass [2014-10-24 20:49:04 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Mirillis [2014-09-02 23:12:17 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\MPC-HC [2014-08-22 12:01:21 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\NexonLauncher [2014-09-24 15:41:23 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Notepad++ [2014-09-03 01:32:11 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\NuGet [2014-08-20 21:45:40 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\OpenOffice [2014-12-01 19:10:39 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Opera [2014-08-21 09:30:47 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Opera Software [2014-08-24 23:36:25 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\PACE Anti-Piracy [2014-09-03 15:29:46 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Publish Providers [2014-08-20 19:56:05 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\qBittorrent [2014-08-22 13:33:22 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Shooter [2014-09-03 15:29:45 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Sony [2014-08-24 23:37:07 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 [2014-09-02 22:36:10 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Sublime Text 2 [2014-09-24 16:39:14 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Subversion [2014-12-07 00:50:20 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\TeamViewer [2014-08-19 12:23:57 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\TP-LINK [2014-11-04 23:23:51 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\TS3Client [2014-08-20 11:45:55 | 000,000,000 | ---D | M] -- C:\Users\Destroy666\AppData\Roaming\Unity [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 1252 bytes -> C:\Users\Destroy666\AppData\Local\ceCqHlPRq2YI:P1InSS0IDEIfp07ji @Alternate Data Stream - 1184 bytes -> C:\Program Files\Common Files\System:mwohuCDHCSzLa8j3Hmc1 @Alternate Data Stream - 1082 bytes -> C:\Users\Destroy666\AppData\Local\VHJ15K94HG:CKxrnk1McVxSnQKFtat3O6 @Alternate Data Stream - 1034 bytes -> C:\ProgramData\Microsoft:BAIsBmcBvWHv2y57ApazY @Alternate Data Stream - 1003 bytes -> C:\ProgramData\Microsoft:cKWQfLnEC6GFs49NkyFBrI < End of report >