Witam serdecznie, jestem amatorem w dziedzinie bezpieczeństwa mojego komputera. Mianowicie zatrzymałem się w rozwoju tej dyscypliny na instalacji Avasta. Obudziłem się dopiero gdy żona zaczęła narzekać, że podczas przeglądania stron wyskakuje jej milion reklam. Zainstalowałem spyhunter 4 i znalazł mi jakiegoś trojana oraz setki innych dziwnych szpiegów itp. Niestety ponieważ trzeba zapłacić za pełną wersję niczego nie jestem w stanie usunąć. Poza tym co jakiś czas miga jakieś okienko, które nie wie, co robi i co to jest w ogóle. Komputer też uruchamia się dość długo.
Na tej stronie znalazłem się przypadkowo i po przeczytaniu paru tematów stwierdziłem, że jest tu kilka osób, które chętnie pomagają innym. Mam nadzieję, że znajdzie się ktoś chętny do walki z moim zombi kompem.
W ostateczności jestem w stanie przeprowadzić format całego kompa, ale mam dodatkowy dysk ok 1,5 TB, na którym jest milion rzeczy bardziej lub mniej potrzebnych, a nie chciałbym się większości pozbywać (choć pewnie i tam porządek by się przydał) tylko ewentualnie przeskanować i wyczyścić go. Jaki antywirus polecacie, i co mam zrobić, żeby się tego całego dziadostwa pozbyć
Zrobiłem skan OTL
Raport z Ekstras wkleję jak ktoś się odezwie, bo za długi post wychodzi i nie pozwala mi wysłać
Pozdrawiam
Na tej stronie znalazłem się przypadkowo i po przeczytaniu paru tematów stwierdziłem, że jest tu kilka osób, które chętnie pomagają innym. Mam nadzieję, że znajdzie się ktoś chętny do walki z moim zombi kompem.
W ostateczności jestem w stanie przeprowadzić format całego kompa, ale mam dodatkowy dysk ok 1,5 TB, na którym jest milion rzeczy bardziej lub mniej potrzebnych, a nie chciałbym się większości pozbywać (choć pewnie i tam porządek by się przydał) tylko ewentualnie przeskanować i wyczyścić go. Jaki antywirus polecacie, i co mam zrobić, żeby się tego całego dziadostwa pozbyć
Zrobiłem skan OTL
Spoiler
OTL logfile created on: 2014-11-16 22:42:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Marszalek\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
3,25 Gb Total Physical Memory | 1,07 Gb Available Physical Memory | 33,04% Memory free
6,50 Gb Paging File | 3,01 Gb Available in Paging File | 46,41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 68,35 Gb Total Space | 19,44 Gb Free Space | 28,44% Space Free | Partition Type: NTFS
Drive D: | 132,07 Gb Total Space | 82,52 Gb Free Space | 62,48% Space Free | Partition Type: NTFS
Drive E: | 97,66 Gb Total Space | 47,18 Gb Free Space | 48,31% Space Free | Partition Type: NTFS
Drive I: | 1397,26 Gb Total Space | 413,50 Gb Free Space | 29,59% Space Free | Partition Type: NTFS
Computer Name: DOM | User Name: Marszalek | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014-11-16 22:40:51 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Marszalek\Downloads\OTL.exe
PRC - [2014-11-16 21:30:31 | 005,679,008 | ---- | M] (SkypEmoticons) -- C:\Users\Marszalek\AppData\Roaming\SkypEmoticons\SE.exe
PRC - [2014-11-16 21:23:11 | 006,873,072 | ---- | M] () -- C:\Users\MARSZA~1\AppData\Local\Temp\Install_14673\ytd.exe
PRC - [2014-11-16 19:10:04 | 003,224,064 | ---- | M] () -- C:\Program Files\ShopperPro\JSDriver\1.37.0.1406\jsdrv.exe
PRC - [2014-11-15 00:57:32 | 006,463,360 | ---- | M] (Enigma Software Group USA, LLC.) -- C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
PRC - [2014-11-15 00:57:29 | 000,770,944 | ---- | M] (Enigma Software Group USA, LLC.) -- C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
PRC - [2014-08-06 14:53:47 | 004,085,896 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014-08-06 14:53:23 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014-07-23 07:44:36 | 000,688,984 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Program Files\Garmin\Express Tray\ExpressTray.exe
PRC - [2014-07-23 07:44:16 | 000,438,616 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
PRC - [2014-06-05 03:19:38 | 000,093,040 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2014-06-05 03:19:36 | 000,248,176 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2014-04-09 14:13:04 | 000,279,456 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
PRC - [2014-02-25 07:29:58 | 000,353,792 | ---- | M] () -- C:\Users\Marszalek\AppData\Roaming\VOPackage\VOsrv.exe
PRC - [2013-12-21 07:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013-11-16 21:28:29 | 000,773,632 | ---- | M] () -- c:\ProgramData\Trusted Publisher\SW-Booster\SW-Booster.exe
PRC - [2011-08-03 12:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011-08-03 12:50:00 | 000,812,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2011-08-03 12:50:00 | 000,373,864 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2011-08-03 02:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011-06-09 12:06:06 | 000,507,624 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2009-10-30 11:25:08 | 000,415,960 | R--- | M] (cFos Software GmbH) -- C:\Program Files\Topos\cFosSpeed\spd.exe
PRC - [2009-10-30 11:25:04 | 000,977,624 | R--- | M] (cFos Software GmbH) -- C:\Program Files\Topos\cFosSpeed\cfosspeed.exe
PRC - [2009-07-29 10:19:42 | 000,356,352 | ---- | M] () -- C:\Windows\tsnpstd3.exe
PRC - [2009-07-14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009-07-14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2007-07-11 16:09:48 | 000,020,480 | ---- | M] () -- C:\Windows\FixCamera.exe
PRC - [2007-05-31 15:21:28 | 000,648,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdcBase.exe
PRC - [2007-05-10 13:18:26 | 000,835,584 | ---- | M] () -- C:\Windows\vsnpstd3.exe
========== Modules (No Company Name) ==========
MOD - [2014-11-16 21:23:11 | 006,873,072 | ---- | M] () -- C:\Users\MARSZA~1\AppData\Local\Temp\Install_14673\ytd.exe
MOD - [2014-11-16 19:10:04 | 003,224,064 | ---- | M] () -- C:\Program Files\ShopperPro\JSDriver\1.37.0.1406\jsdrv.exe
MOD - [2014-10-22 05:05:00 | 014,902,600 | ---- | M] () -- C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\PepperFlash\pepflashplayer.dll
MOD - [2014-10-22 05:04:57 | 008,910,664 | ---- | M] () -- C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\pdf.dll
MOD - [2014-10-22 05:04:51 | 001,042,760 | ---- | M] () -- C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\libglesv2.dll
MOD - [2014-10-22 05:04:49 | 000,211,272 | ---- | M] () -- C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\libegl.dll
MOD - [2014-10-22 05:04:48 | 001,681,224 | ---- | M] () -- C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\ffmpegsumo.dll
MOD - [2014-08-06 14:53:25 | 019,329,904 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014-08-06 14:53:24 | 000,301,152 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswProperty.dll
MOD - [2014-01-31 15:01:48 | 000,221,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\1a2ef04173bbfa62eb1296528a07adb7\System.ServiceProcess.ni.dll
MOD - [2014-01-31 15:01:47 | 001,152,512 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\4804945b91a54bb958d99d71317c88d6\System.ServiceModel.Discovery.ni.dll
MOD - [2014-01-31 15:01:47 | 000,373,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\7aff398879a30180adbc9f23872d6ed6\System.ServiceModel.Routing.ni.dll
MOD - [2014-01-31 15:01:45 | 001,547,776 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\88e2becebcce584a2b98c35ac3b4516a\System.ServiceModel.Activities.ni.dll
MOD - [2014-01-31 15:01:45 | 000,084,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\03414454aaccb4efd51aa572bf79fade\System.ServiceModel.Channels.ni.dll
MOD - [2014-01-31 15:01:43 | 018,127,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\9176c1a7d9a4af8cf94341fd26b104ce\System.ServiceModel.ni.dll
MOD - [2014-01-31 15:01:22 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\a6c6325e908cca648074d770e5d7371e\System.Management.ni.dll
MOD - [2014-01-31 15:01:20 | 001,077,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\575d69df74a1d994098d9bcf274b9562\System.IdentityModel.ni.dll
MOD - [2014-01-31 15:01:18 | 000,913,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\76808b6532373668ee95457279c44de9\System.DirectoryServices.AccountManagement.ni.dll
MOD - [2014-01-31 14:59:53 | 001,172,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\c6d52383f14e3adc6afaaf29db024f45\System.DirectoryServices.ni.dll
MOD - [2014-01-31 14:59:51 | 001,031,168 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\6d1630d02ce20dc93500da38b103e220\System.Runtime.DurableInstancing.ni.dll
MOD - [2014-01-31 14:59:50 | 002,657,792 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\a03e4ab9a1b3f56734bf5902b977981c\System.Runtime.Serialization.ni.dll
MOD - [2014-01-31 14:59:50 | 000,143,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\a72606feaebce8525f221cb4b0b96f3d\SMDiagnostics.ni.dll
MOD - [2014-01-31 14:59:48 | 000,393,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\4f7185e7bc8ff56a652ca501356cf98d\System.Xml.Linq.ni.dll
MOD - [2014-01-31 14:59:47 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\171d7a6c74a74fa4f742155c157f322a\System.Xaml.ni.dll
MOD - [2014-01-31 14:44:10 | 018,001,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\c8d279bca2d614816f66614a126bb8d9\PresentationFramework.ni.dll
MOD - [2014-01-31 14:43:56 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\f0fe367d990d6ce2b4c0b79a23ca9c10\PresentationCore.ni.dll
MOD - [2014-01-31 14:43:56 | 006,864,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\d9ac7a08828bee75790fedc5b3ad909a\System.Data.ni.dll
MOD - [2014-01-31 14:43:55 | 013,102,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\7dd7ca10c4314c8fcfd39b55cdb49ce1\System.Windows.Forms.ni.dll
MOD - [2014-01-31 14:43:51 | 007,053,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\6897ee3309ad13edf00a082a11cf5535\System.Core.ni.dll
MOD - [2014-01-31 14:43:48 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\9470d86204a9bafb04a3a8652a5c65b8\System.Xml.ni.dll
MOD - [2014-01-31 14:43:46 | 003,858,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\2e28b4ec7fc56196bc428b1f0bb56531\WindowsBase.ni.dll
MOD - [2014-01-31 14:43:46 | 001,653,248 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\188eaf34968fd321e4fb2046496090fa\System.Drawing.ni.dll
MOD - [2014-01-31 14:43:44 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\3230cdc86a08795a5ed94effd602ace5\System.Configuration.ni.dll
MOD - [2014-01-31 14:43:44 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\afe006d096b8ff0f1d3317e5ae67aa48\PresentationFramework.Aero.ni.dll
MOD - [2014-01-31 14:43:42 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\af264ee88b09d41f8a00e3b42afe724b\System.ni.dll
MOD - [2014-01-31 14:43:36 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\441fda1590ef311b4021510a76b768cb\mscorlib.ni.dll
MOD - [2009-07-29 10:19:42 | 000,356,352 | ---- | M] () -- C:\Windows\tsnpstd3.exe
MOD - [2008-09-16 19:18:06 | 000,132,608 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007-07-11 16:09:48 | 000,020,480 | ---- | M] () -- C:\Windows\FixCamera.exe
MOD - [2007-05-10 13:18:26 | 000,835,584 | ---- | M] () -- C:\Windows\vsnpstd3.exe
========== Services (SafeList) ==========
SRV - [2014-11-16 21:23:31 | 000,068,608 | ---- | M] (globalUpdate) [On_Demand | Stopped] -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe -- (globalUpdatem)
SRV - [2014-11-16 21:23:31 | 000,068,608 | ---- | M] (globalUpdate) [Auto | Stopped] -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe -- (globalUpdate)
SRV - [2014-11-15 00:57:29 | 000,770,944 | ---- | M] (Enigma Software Group USA, LLC.) [Auto | Running] -- C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe -- (SpyHunter 4 Service)
SRV - [2014-11-11 20:27:35 | 000,114,288 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014-10-06 19:03:23 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014-08-06 14:53:23 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2014-07-23 07:44:16 | 000,438,616 | ---- | M] (Garmin Ltd or its subsidiaries) [Auto | Running] -- C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe -- (Garmin Core Update Service)
SRV - [2014-06-05 03:19:38 | 000,093,040 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2014-04-09 14:12:50 | 000,235,696 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe -- (McComponentHostService)
SRV - [2014-02-25 07:29:58 | 000,353,792 | ---- | M] () [Auto | Running] -- C:\Users\Marszalek\AppData\Roaming\VOPackage\VOsrv.exe -- (VOsrv)
SRV - [2013-12-21 07:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011-08-03 12:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011-08-03 02:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009-10-30 11:25:08 | 000,415,960 | R--- | M] (cFos Software GmbH) [Auto | Running] -- C:\Program Files\Topos\cFosSpeed\spd.exe -- (cFosSpeedS)
SRV - [2009-07-14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009-07-14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009-07-14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007-05-31 15:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007-05-31 15:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\adiusbaw.sys -- (adiusbaw)
DRV - [2014-11-16 19:12:16 | 000,041,320 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files\ShopperPro\JSDriver\1.37.0.1406\jsdrv.sys -- (SPDRIVER_1.37.0.1406)
DRV - [2014-11-15 00:57:35 | 000,016,432 | ---- | M] (Enigma Software Group USA, LLC.) [Kernel | On_Demand | Running] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
DRV - [2014-11-15 00:57:32 | 000,019,984 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\EsgScanner.sys -- (EsgScanner)
DRV - [2014-08-06 14:53:45 | 000,414,520 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswsp.sys -- (aswSP)
DRV - [2014-08-06 14:53:27 | 000,779,536 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2014-08-06 14:53:27 | 000,192,352 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2014-08-06 14:53:27 | 000,071,944 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswstm.sys -- (aswStm)
DRV - [2014-08-06 14:53:26 | 000,081,768 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr)
DRV - [2014-08-06 14:53:26 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2014-08-06 14:53:26 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2014-08-06 14:53:26 | 000,024,184 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswHwid.sys -- (aswHwid)
DRV - [2013-12-19 14:11:31 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011-08-03 12:50:00 | 010,304,104 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009-12-21 16:30:30 | 000,043,520 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtTeam60.sys -- (TEAM)
DRV - [2009-12-21 16:30:30 | 000,043,520 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtTeam60.sys -- (RTTEAMPT)
DRV - [2009-10-30 11:25:12 | 000,872,152 | ---- | M] (cFos Software GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cfosspeed.sys -- (cFosSpeed)
DRV - [2009-07-20 03:26:40 | 000,027,648 | ---- | M] (Realtek ) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\RtNdPt60.sys -- (RtNdPt60)
DRV - [2009-07-17 17:30:20 | 010,551,040 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snpstd3.sys -- (SNPSTD3)
DRV - [2009-07-14 02:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009-07-14 02:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009-07-14 02:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009-07-14 00:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2009-07-14 00:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009-07-14 00:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2008-07-07 08:40:49 | 000,056,108 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2007-12-03 03:19:42 | 000,019,968 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtVlan60.sys -- (RTVLANPT)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.search-plaza.info/?pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69
IE - HKLM\..\SearchScopes,DefaultScope = {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.search-plaza.info/?l=1&q={searchTerms}&pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.search-plaza.info/?pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\..\SearchScopes,DefaultScope = {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\..\SearchScopes\{57379D6C-0051-4E5D-837E-809F5B1D9E96}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searcerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.search-plaza.info/?l=1&q={searchTerms}&pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1001\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: netvideohunter%40netvideohunter.com:1.16
FF - prefs.js..extensions.enabledAddons: fastdial%40telega.phpnet.us:4.12
FF - prefs.js..extensions.enabledAddons: ROUAILDE73397174%40UXGZI17268980.com:0.95.15
FF - prefs.js..extensions.enabledAddons: %7B64161300-e22b-11db-8314-0800200c9a66%7D:0.9.6.16
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.1
FF - prefs.js..extensions.enabledItems: fastdial@telega.phpnet.us:4.2.2
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.6.8
FF - prefs.js..extensions.enabledItems: wrc@avast.com:6.0.1289
FF - prefs.js..extensions.enabledItems: 2020Player_IKEA@2020Technologies.com:5.0.94.0
FF - prefs.js..browser.startup.homepage: "http://websearch.search-plaza.info/?pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69"
FF - prefs.js..browser.search.order.1: "WebSearch"
FF - prefs.js..browser.search.defaultenginename: "WebSearch"
FF - prefs.js..browser.search.selectedEngine: "WebSearch"
FF - prefs.js..browser.search.order.1,S: S", "WebSearch"
FF - prefs.js..browser.search.defaultenginename,S: S", "WebSearch"
FF - prefs.js..browser.search.selectedEngine,S: S", "WebSearch"
FF - prefs.js..keyword.URL: "http://websearch.search-plaza.info/?pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69&l=1&q="
FF - prefs.js..browser.search.defaulturl: "http://websearch.search-plaza.info/?pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69&l=1&q="
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10: C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4: C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Marszalek\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Marszalek\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-08-06 14:53:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014-11-11 20:27:31 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{e4f94d1e-2f53-401e-8885-681602c0ddd8}: C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
[2012-08-02 21:29:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Extensions
[2012-08-02 21:29:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2014-11-16 21:27:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions
[2013-09-17 12:51:24 | 000,000,000 | ---D | M] (Speed Dial) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2014-11-16 21:22:49 | 000,000,000 | ---D | M] (Shopper-Pro) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
[2014-11-16 21:24:33 | 000,000,000 | ---D | M] ("Ge-Force") -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\45633fba7e7d40fea9c29@9dc18447eea04021a325caf3.com
[2014-09-25 20:27:29 | 000,000,000 | ---D | M] (Fast Dial) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\fastdial@telega.phpnet.us
[2014-07-30 19:10:57 | 000,000,000 | ---D | M] ("NetVideoHunter") -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\netvideohunter@netvideohunter.com
[2014-10-20 22:51:00 | 000,000,000 | ---D | M] ("iWebar") -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\ROUAILDE73397174@UXGZI17268980.com
[2014-11-16 21:27:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\staged
[2014-11-16 21:24:43 | 000,000,000 | ---D | M] ("Sense") -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\warnerroberts@hotmail.com
[2014-11-16 21:24:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\45633fba7e7d40fea9c29@9dc18447eea04021a325caf3.com\extensionData
[2014-11-16 21:24:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\45633fba7e7d40fea9c29@9dc18447eea04021a325caf3.com\extensionData\plugins
[2014-11-16 21:24:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\45633fba7e7d40fea9c29@9dc18447eea04021a325caf3.com\extensionData\userCode
[2014-11-08 10:27:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData
[2014-11-08 10:27:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins
[2014-11-08 10:27:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\userCode
[2014-11-16 21:24:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\warnerroberts@hotmail.com\extensionData
[2014-11-16 21:24:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\warnerroberts@hotmail.com\extensionData\plugins
[2014-11-16 21:24:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\warnerroberts@hotmail.com\extensionData\userCode
[2014-11-16 21:29:52 | 000,000,651 | ---- | M] () -- C:\Users\Marszalek\AppData\Roaming\mozilla\firefox\profiles\b7i9atke.default\searchplugins\WebSearch.xml
[2014-11-11 20:27:31 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014-11-11 20:27:36 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011-09-15 09:31:31 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://websearch.search-plaza.info/?pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Battlefield Play4Free Updater (Enabled) = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.66.2_0\npBP4FUpdater.dll
CHR - plugin: Battlefield Play4Free Updater (Enabled) = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.66.2_0\BP4FUpdater.exe
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - default_search_provider: FB6FC777205A388E72F8FF0924DA6DBDBFE600D29ED5AB543F74BAEC17903C8D ()
CHR - default_search_provider: search_url = F88DC92D9C9237F48A5F9031EFC3E38CA483ACAEC0FE677BF4A74DC2D49F04FC
CHR - default_search_provider: suggest_url =
CHR - homepage: 3651E8BB2A4AD6ED2392ECFD137EA6878236542AB4B3A5921F15BE2A1F89BE58
CHR - Extension: YouTube = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Szukaj w Google = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.13.2_0\
CHR - Extension: Avast Online Security = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.0.2502.149_0\
CHR - Extension: Przycisk Pin It = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic\1.35_0\
CHR - Extension: Speed Dial 2 = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik\1.8.0_0\
CHR - Extension: Google Wallet = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009-06-10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll File not found
O2 - BHO: (Ge-Force) - {11111111-1111-1111-1111-110611191111} - C:\Program Files\Ge-Force\Ge-Force-bho.dll (iWebar)
O2 - BHO: (Sense) - {11111111-1111-1111-1111-110611191115} - C:\Program Files\Sense\Sense-bho.dll (Object Browser)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll File not found
O2 - BHO: (Shopper Pro) - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll (Goobzo Ltd.)
O2 - BHO: (GoSave) - {ce27b70d-c597-4234-990c-714fe9a26cba} - C:\Program Files\GoSave\KnrJJ3FaSgOStA.dll ()
O2 - BHO: (YoutubeAdBlocke) - {d8d1a487-d056-4194-b38f-011e9b1978da} - C:\Program Files\YoutubeAdBlocke\PRsq4H8NaaUgIQ.dll ()
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O4 - HKLM..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" File not found
O4 - HKLM..\Run: [Aimersoft Helper Compact.exe] C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe (AimerSoft)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [cFosSpeed] C:\Program Files\Topos\cFosSpeed\cfosspeed.exe (cFos Software GmbH)
O4 - HKLM..\Run: [FixCamera] C:\Windows\FixCamera.exe ()
O4 - HKLM..\Run: [snpstd3] C:\Windows\vsnpstd3.exe ()
O4 - HKLM..\Run: [SPDriver] C:\Program Files\ShopperPro\JSDriver\1.37.0.1406\jsdrv.exe ()
O4 - HKLM..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe ()
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [GarminExpressTrayApp] C:\Program Files\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKU\S-1-5-18..\Run: [GarminExpressTrayApp] C:\Program Files\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" File not found
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [GarminExpressTrayApp] C:\Program Files\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [LiveSupport] C:\Program Files\LiveSupport\LiveSupport.exe (PC Utilities Software Limited)
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe File not found
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [se] C:\Users\Marszalek\AppData\Roaming\SkypEmoticons\SE.exe (SkypEmoticons)
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [SPDriver] C:\Program Files\ShopperPro\JSDriver\1.37.0.1406\jsdrv.exe ()
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.66.2.cab (Battlefield Play4Free Updater)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{762A5530-EA23-4B18-99CC-ECA3F8782624}: DhcpNameServer = 192.168.1.1 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2014-08-15 20:25:44 | 000,368,769 | ---- | M] () - C:\AutoMapaSetupLog.txt -- [ NTFS ]
O32 - AutoRun File - [2009-02-27 00:57:36 | 000,000,120 | ---- | M] () - I:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\SETUP.EXE
O33 - MountPoints2\H\Shell\configure\command - "" = H:\SETUP.EXE
O33 - MountPoints2\H\Shell\install\command - "" = H:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014-11-16 21:30:46 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Roaming\Optimizer Pro
[2014-11-16 21:29:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LiveSupport
[2014-11-16 21:29:52 | 000,000,000 | ---D | C] -- C:\Program Files\LiveSupport
[2014-11-16 21:29:46 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Roaming\SkypEmoticons
[2014-11-16 21:29:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkypEmoticons
[2014-11-16 21:29:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
[2014-11-16 21:28:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Trusted Publisher
[2014-11-16 21:28:21 | 000,000,000 | ---D | C] -- C:\Program Files\DeltaFix
[2014-11-16 21:27:35 | 000,000,000 | ---D | C] -- C:\Program Files\YoutubeAdBlocke
[2014-11-16 21:27:20 | 000,000,000 | ---D | C] -- C:\Program Files\GoSave
[2014-11-16 21:27:11 | 000,000,000 | ---D | C] -- C:\ProgramData\10759222319475739118
[2014-11-16 21:26:44 | 000,000,000 | ---D | C] -- C:\ProgramData\kmopbknmgjjkldcpajmpmicdbjoaifpp
[2014-11-16 21:24:47 | 001,466,784 | ---- | C] (Object Browser) -- C:\Users\Marszalek\AppData\Roaming\ELEZD.exe
[2014-11-16 21:24:11 | 000,000,000 | ---D | C] -- C:\Program Files\0e1e6853-e2ae-46d4-a587-6456bc0b2683
[2014-11-16 21:24:00 | 000,000,000 | ---D | C] -- C:\Program Files\f7f5596e-1617-4d96-b4bc-fef24dd0a81a
[2014-11-16 21:23:42 | 001,940,896 | ---- | C] (Object Browser) -- C:\Users\Marszalek\AppData\Roaming\QIWHDL.exe
[2014-11-16 21:23:33 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Local\globalUpdate
[2014-11-16 21:23:33 | 000,000,000 | ---D | C] -- C:\Program Files\globalUpdate
[2014-11-16 21:23:30 | 000,000,000 | ---D | C] -- C:\Program Files\Sense
[2014-11-16 21:23:30 | 000,000,000 | ---D | C] -- C:\Program Files\Ge-Force
[2014-11-16 21:22:47 | 000,000,000 | ---D | C] -- C:\ProgramData\ShopperPro
[2014-11-16 21:22:45 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\ShopperPro
[2014-11-16 21:22:39 | 000,000,000 | ---D | C] -- C:\Program Files\ShopperPro
[2014-11-16 21:21:28 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Roaming\VOPackage
[2014-11-15 00:58:34 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Roaming\Enigma Software Group
[2014-11-15 00:58:30 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
[2014-11-15 00:58:17 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2014-11-15 00:57:25 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2014-11-11 20:27:30 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014-10-31 07:21:32 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\Desktop\Nowy folder (2)
[2014-10-27 11:41:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2014-10-21 23:35:45 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014-10-20 22:15:22 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2014-10-20 22:15:01 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Local\Installer
[2014-10-20 22:14:57 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Local\CrashRpt
[2014-10-20 22:11:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Users\Marszalek\AppData\Local\*.tmp files -> C:\Users\Marszalek\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014-11-16 22:47:26 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014-11-16 22:47:26 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014-11-16 22:24:00 | 000,005,832 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-6.job
[2014-11-16 22:24:00 | 000,005,826 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-6.job
[2014-11-16 22:02:00 | 000,001,074 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3997692141-2039178269-1593662184-1000UA.job
[2014-11-16 22:02:00 | 000,001,022 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3997692141-2039178269-1593662184-1000Core.job
[2014-11-16 22:02:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014-11-16 21:29:53 | 000,001,843 | ---- | M] () -- C:\Users\Marszalek\Desktop\LiveSupport.lnk
[2014-11-16 21:29:43 | 000,000,984 | ---- | M] () -- C:\Users\Marszalek\Desktop\Optimizer Pro.lnk
[2014-11-16 21:28:30 | 000,000,484 | -H-- | M] () -- C:\Windows\tasks\SW-Booster-S-792098896.job
[2014-11-16 21:28:07 | 000,000,952 | ---- | M] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
[2014-11-16 21:28:00 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
[2014-11-16 21:25:06 | 000,002,754 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-5_user.job
[2014-11-16 21:25:05 | 000,002,754 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-5.job
[2014-11-16 21:25:00 | 000,002,760 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-5_user.job
[2014-11-16 21:24:57 | 000,002,760 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-5.job
[2014-11-16 21:24:55 | 000,002,410 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-2.job
[2014-11-16 21:24:50 | 000,003,742 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-1.job
[2014-11-16 21:24:48 | 000,001,352 | ---- | M] () -- C:\Windows\tasks\ELEZD.job
[2014-11-16 21:24:47 | 001,466,784 | ---- | M] (Object Browser) -- C:\Users\Marszalek\AppData\Roaming\ELEZD.exe
[2014-11-16 21:24:47 | 000,002,416 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-2.job
[2014-11-16 21:24:39 | 000,003,754 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-1.job
[2014-11-16 21:24:32 | 000,004,458 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-4.job
[2014-11-16 21:24:20 | 000,004,464 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-4.job
[2014-11-16 21:24:14 | 000,005,482 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-7.job
[2014-11-16 21:24:02 | 000,005,488 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-7.job
[2014-11-16 21:23:51 | 000,005,148 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-11.job
[2014-11-16 21:23:46 | 000,001,354 | ---- | M] () -- C:\Windows\tasks\QIWHDL.job
[2014-11-16 21:23:42 | 001,940,896 | ---- | M] (Object Browser) -- C:\Users\Marszalek\AppData\Roaming\QIWHDL.exe
[2014-11-16 21:23:39 | 000,003,778 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-3.job
[2014-11-16 21:23:36 | 000,005,154 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-11.job
[2014-11-16 21:22:26 | 000,000,859 | ---- | M] () -- C:\Users\Marszalek\Desktop\Continue VuuPC Installation.lnk
[2014-11-16 20:53:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014-11-16 20:53:39 | 2616,057,856 | -HS- | M] () -- C:\hiberfil.sys
[2014-11-15 00:58:30 | 000,001,204 | ---- | M] () -- C:\Users\Marszalek\Desktop\SpyHunter.lnk
[2014-11-15 00:57:32 | 000,019,984 | ---- | M] () -- C:\Windows\System32\drivers\EsgScanner.sys
[2014-11-14 23:33:01 | 000,697,674 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2014-11-14 23:33:01 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014-11-14 23:33:01 | 000,134,784 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2014-11-14 23:33:01 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014-11-13 17:03:05 | 000,001,994 | ---- | M] () -- C:\Users\Marszalek\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2014-10-26 01:28:55 | 000,055,808 | ---- | M] () -- C:\Users\Marszalek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014-10-21 23:35:34 | 001,962,496 | ---- | M] () -- C:\Users\Marszalek\Desktop\adwcleaner_4.001.exe
[2014-10-21 22:15:33 | 000,001,379 | ---- | M] () -- C:\Users\Marszalek\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014-10-21 00:34:38 | 000,163,169 | ---- | M] () -- C:\Users\Marszalek\Desktop\kulka.jpg
[2014-10-20 22:17:57 | 000,002,125 | ---- | M] () -- C:\Users\Marszalek\Desktop\AppsHat.lnk
[2014-10-20 22:10:39 | 000,278,861 | ---- | M] () -- C:\Users\Marszalek\Desktop\vod.pl
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Users\Marszalek\AppData\Local\*.tmp files -> C:\Users\Marszalek\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014-11-16 21:29:53 | 000,001,843 | ---- | C] () -- C:\Users\Marszalek\Desktop\LiveSupport.lnk
[2014-11-16 21:29:43 | 000,000,984 | ---- | C] () -- C:\Users\Marszalek\Desktop\Optimizer Pro.lnk
[2014-11-16 21:28:29 | 000,000,484 | -H-- | C] () -- C:\Windows\tasks\SW-Booster-S-792098896.job
[2014-11-16 21:25:06 | 000,002,754 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-5_user.job
[2014-11-16 21:25:04 | 000,002,754 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-5.job
[2014-11-16 21:24:59 | 000,002,760 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-5_user.job
[2014-11-16 21:24:57 | 000,002,760 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-5.job
[2014-11-16 21:24:55 | 000,002,410 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-2.job
[2014-11-16 21:24:49 | 000,003,742 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-1.job
[2014-11-16 21:24:48 | 000,001,352 | ---- | C] () -- C:\Windows\tasks\ELEZD.job
[2014-11-16 21:24:46 | 000,002,416 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-2.job
[2014-11-16 21:24:37 | 000,003,754 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-1.job
[2014-11-16 21:24:30 | 000,004,458 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-4.job
[2014-11-16 21:24:19 | 000,004,464 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-4.job
[2014-11-16 21:24:15 | 000,005,826 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-6.job
[2014-11-16 21:24:12 | 000,005,482 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-7.job
[2014-11-16 21:24:03 | 000,005,832 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-6.job
[2014-11-16 21:24:00 | 000,005,488 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-7.job
[2014-11-16 21:23:46 | 000,005,148 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-11.job
[2014-11-16 21:23:43 | 000,001,354 | ---- | C] () -- C:\Windows\tasks\QIWHDL.job
[2014-11-16 21:23:41 | 000,000,952 | ---- | C] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
[2014-11-16 21:23:39 | 000,000,948 | ---- | C] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
[2014-11-16 21:23:34 | 000,005,154 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-11.job
[2014-11-16 21:23:34 | 000,003,778 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-3.job
[2014-11-16 21:22:26 | 000,000,859 | ---- | C] () -- C:\Users\Marszalek\Desktop\Continue VuuPC Installation.lnk
[2014-11-15 00:58:30 | 000,001,204 | ---- | C] () -- C:\Users\Marszalek\Desktop\SpyHunter.lnk
[2014-11-15 00:57:32 | 000,019,984 | ---- | C] () -- C:\Windows\System32\drivers\EsgScanner.sys
[2014-10-21 23:35:33 | 001,962,496 | ---- | C] () -- C:\Users\Marszalek\Desktop\adwcleaner_4.001.exe
[2014-10-21 00:33:37 | 000,163,169 | ---- | C] () -- C:\Users\Marszalek\Desktop\kulka.jpg
[2014-10-20 22:17:57 | 000,002,125 | ---- | C] () -- C:\Users\Marszalek\Desktop\AppsHat.lnk
[2014-10-20 22:11:37 | 000,001,367 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014-10-20 22:10:56 | 000,278,861 | ---- | C] () -- C:\Users\Marszalek\Desktop\vod.pl
[2014-09-01 09:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Marszalek\AppData\Roaming\ELEZD
[2014-09-01 09:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Marszalek\AppData\Roaming\QIWHDL
[2014-08-06 14:53:35 | 000,024,184 | ---- | C] () -- C:\Windows\System32\drivers\aswHwid.sys
[2014-01-28 17:06:35 | 000,002,244 | ---- | C] () -- C:\Windows\System32\ASOROSet.bin
[2014-01-28 13:30:45 | 000,000,044 | ---- | C] () -- C:\Users\Marszalek\AppData\Roaming\WB.CFG
[2014-01-15 10:29:01 | 000,192,352 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014-01-15 10:29:00 | 000,049,944 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2013-02-25 21:45:54 | 000,707,504 | ---- | C] () -- C:\Users\Marszalek\AppData\Local\unins000.exe
[2013-02-25 21:45:01 | 000,011,761 | ---- | C] () -- C:\Users\Marszalek\AppData\Local\unins000.msg
[2013-02-25 21:45:01 | 000,004,176 | ---- | C] () -- C:\Users\Marszalek\AppData\Local\unins000.dat
[2012-10-12 00:50:42 | 000,049,738 | ---- | C] () -- C:\Program Files\AutoMapa EU.md5
[2012-01-27 08:46:30 | 000,004,096 | -H-- | C] () -- C:\Users\Marszalek\AppData\Local\keyfile3.drm
[2011-08-10 14:35:03 | 000,055,808 | ---- | C] () -- C:\Users\Marszalek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2009-07-14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009-07-14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009-07-14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2014-06-12 12:44:10 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Garmin
[2014-06-12 12:44:10 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Garmin
[2011-07-23 22:18:59 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Ashampoo
[2014-01-15 10:34:31 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\AVAST Software
[2014-03-19 08:14:33 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Codeton
[2014-03-18 10:36:46 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2014-11-15 00:58:34 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Enigma Software Group
[2011-12-27 12:58:49 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Gadu-Gadu 10
[2014-01-31 14:48:56 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Garmin
[2012-01-02 16:38:16 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\GetRightToGo
[2011-08-02 14:17:18 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\OpenFM
[2011-07-16 01:12:11 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Opera
[2014-05-23 23:58:50 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Opera Software
[2014-11-16 21:30:46 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Optimizer Pro
[2012-04-03 10:22:24 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Patcher
[2012-11-23 13:40:48 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\PDFCreatorPackages
[2013-05-20 15:38:50 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\PITy2011
[2014-02-01 10:56:00 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Podatnik.info
[2012-08-02 21:29:51 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\TomTom
[2014-10-21 22:03:53 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\uTorrent
[2014-11-16 21:51:48 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\VOPackage
[2013-01-03 01:16:10 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\XMedia Recode
[2014-10-25 12:28:33 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\XnView
[2012-02-10 20:08:07 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\YFSoftware
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:56E2E879
< End of report >
OTL logfile created on: 2014-11-16 22:42:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Marszalek\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
3,25 Gb Total Physical Memory | 1,07 Gb Available Physical Memory | 33,04% Memory free
6,50 Gb Paging File | 3,01 Gb Available in Paging File | 46,41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 68,35 Gb Total Space | 19,44 Gb Free Space | 28,44% Space Free | Partition Type: NTFS
Drive D: | 132,07 Gb Total Space | 82,52 Gb Free Space | 62,48% Space Free | Partition Type: NTFS
Drive E: | 97,66 Gb Total Space | 47,18 Gb Free Space | 48,31% Space Free | Partition Type: NTFS
Drive I: | 1397,26 Gb Total Space | 413,50 Gb Free Space | 29,59% Space Free | Partition Type: NTFS
Computer Name: DOM | User Name: Marszalek | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014-11-16 22:40:51 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Marszalek\Downloads\OTL.exe
PRC - [2014-11-16 21:30:31 | 005,679,008 | ---- | M] (SkypEmoticons) -- C:\Users\Marszalek\AppData\Roaming\SkypEmoticons\SE.exe
PRC - [2014-11-16 21:23:11 | 006,873,072 | ---- | M] () -- C:\Users\MARSZA~1\AppData\Local\Temp\Install_14673\ytd.exe
PRC - [2014-11-16 19:10:04 | 003,224,064 | ---- | M] () -- C:\Program Files\ShopperPro\JSDriver\1.37.0.1406\jsdrv.exe
PRC - [2014-11-15 00:57:32 | 006,463,360 | ---- | M] (Enigma Software Group USA, LLC.) -- C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
PRC - [2014-11-15 00:57:29 | 000,770,944 | ---- | M] (Enigma Software Group USA, LLC.) -- C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
PRC - [2014-08-06 14:53:47 | 004,085,896 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014-08-06 14:53:23 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014-07-23 07:44:36 | 000,688,984 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Program Files\Garmin\Express Tray\ExpressTray.exe
PRC - [2014-07-23 07:44:16 | 000,438,616 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
PRC - [2014-06-05 03:19:38 | 000,093,040 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2014-06-05 03:19:36 | 000,248,176 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2014-04-09 14:13:04 | 000,279,456 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
PRC - [2014-02-25 07:29:58 | 000,353,792 | ---- | M] () -- C:\Users\Marszalek\AppData\Roaming\VOPackage\VOsrv.exe
PRC - [2013-12-21 07:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013-11-16 21:28:29 | 000,773,632 | ---- | M] () -- c:\ProgramData\Trusted Publisher\SW-Booster\SW-Booster.exe
PRC - [2011-08-03 12:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011-08-03 12:50:00 | 000,812,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2011-08-03 12:50:00 | 000,373,864 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2011-08-03 02:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011-06-09 12:06:06 | 000,507,624 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2009-10-30 11:25:08 | 000,415,960 | R--- | M] (cFos Software GmbH) -- C:\Program Files\Topos\cFosSpeed\spd.exe
PRC - [2009-10-30 11:25:04 | 000,977,624 | R--- | M] (cFos Software GmbH) -- C:\Program Files\Topos\cFosSpeed\cfosspeed.exe
PRC - [2009-07-29 10:19:42 | 000,356,352 | ---- | M] () -- C:\Windows\tsnpstd3.exe
PRC - [2009-07-14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009-07-14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2007-07-11 16:09:48 | 000,020,480 | ---- | M] () -- C:\Windows\FixCamera.exe
PRC - [2007-05-31 15:21:28 | 000,648,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdcBase.exe
PRC - [2007-05-10 13:18:26 | 000,835,584 | ---- | M] () -- C:\Windows\vsnpstd3.exe
========== Modules (No Company Name) ==========
MOD - [2014-11-16 21:23:11 | 006,873,072 | ---- | M] () -- C:\Users\MARSZA~1\AppData\Local\Temp\Install_14673\ytd.exe
MOD - [2014-11-16 19:10:04 | 003,224,064 | ---- | M] () -- C:\Program Files\ShopperPro\JSDriver\1.37.0.1406\jsdrv.exe
MOD - [2014-10-22 05:05:00 | 014,902,600 | ---- | M] () -- C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\PepperFlash\pepflashplayer.dll
MOD - [2014-10-22 05:04:57 | 008,910,664 | ---- | M] () -- C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\pdf.dll
MOD - [2014-10-22 05:04:51 | 001,042,760 | ---- | M] () -- C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\libglesv2.dll
MOD - [2014-10-22 05:04:49 | 000,211,272 | ---- | M] () -- C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\libegl.dll
MOD - [2014-10-22 05:04:48 | 001,681,224 | ---- | M] () -- C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\ffmpegsumo.dll
MOD - [2014-08-06 14:53:25 | 019,329,904 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014-08-06 14:53:24 | 000,301,152 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswProperty.dll
MOD - [2014-01-31 15:01:48 | 000,221,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\1a2ef04173bbfa62eb1296528a07adb7\System.ServiceProcess.ni.dll
MOD - [2014-01-31 15:01:47 | 001,152,512 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\4804945b91a54bb958d99d71317c88d6\System.ServiceModel.Discovery.ni.dll
MOD - [2014-01-31 15:01:47 | 000,373,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\7aff398879a30180adbc9f23872d6ed6\System.ServiceModel.Routing.ni.dll
MOD - [2014-01-31 15:01:45 | 001,547,776 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\88e2becebcce584a2b98c35ac3b4516a\System.ServiceModel.Activities.ni.dll
MOD - [2014-01-31 15:01:45 | 000,084,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\03414454aaccb4efd51aa572bf79fade\System.ServiceModel.Channels.ni.dll
MOD - [2014-01-31 15:01:43 | 018,127,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\9176c1a7d9a4af8cf94341fd26b104ce\System.ServiceModel.ni.dll
MOD - [2014-01-31 15:01:22 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\a6c6325e908cca648074d770e5d7371e\System.Management.ni.dll
MOD - [2014-01-31 15:01:20 | 001,077,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\575d69df74a1d994098d9bcf274b9562\System.IdentityModel.ni.dll
MOD - [2014-01-31 15:01:18 | 000,913,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\76808b6532373668ee95457279c44de9\System.DirectoryServices.AccountManagement.ni.dll
MOD - [2014-01-31 14:59:53 | 001,172,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.DirectorySer#\c6d52383f14e3adc6afaaf29db024f45\System.DirectoryServices.ni.dll
MOD - [2014-01-31 14:59:51 | 001,031,168 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\6d1630d02ce20dc93500da38b103e220\System.Runtime.DurableInstancing.ni.dll
MOD - [2014-01-31 14:59:50 | 002,657,792 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\a03e4ab9a1b3f56734bf5902b977981c\System.Runtime.Serialization.ni.dll
MOD - [2014-01-31 14:59:50 | 000,143,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\a72606feaebce8525f221cb4b0b96f3d\SMDiagnostics.ni.dll
MOD - [2014-01-31 14:59:48 | 000,393,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\4f7185e7bc8ff56a652ca501356cf98d\System.Xml.Linq.ni.dll
MOD - [2014-01-31 14:59:47 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\171d7a6c74a74fa4f742155c157f322a\System.Xaml.ni.dll
MOD - [2014-01-31 14:44:10 | 018,001,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\c8d279bca2d614816f66614a126bb8d9\PresentationFramework.ni.dll
MOD - [2014-01-31 14:43:56 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\f0fe367d990d6ce2b4c0b79a23ca9c10\PresentationCore.ni.dll
MOD - [2014-01-31 14:43:56 | 006,864,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\d9ac7a08828bee75790fedc5b3ad909a\System.Data.ni.dll
MOD - [2014-01-31 14:43:55 | 013,102,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\7dd7ca10c4314c8fcfd39b55cdb49ce1\System.Windows.Forms.ni.dll
MOD - [2014-01-31 14:43:51 | 007,053,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\6897ee3309ad13edf00a082a11cf5535\System.Core.ni.dll
MOD - [2014-01-31 14:43:48 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\9470d86204a9bafb04a3a8652a5c65b8\System.Xml.ni.dll
MOD - [2014-01-31 14:43:46 | 003,858,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\2e28b4ec7fc56196bc428b1f0bb56531\WindowsBase.ni.dll
MOD - [2014-01-31 14:43:46 | 001,653,248 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\188eaf34968fd321e4fb2046496090fa\System.Drawing.ni.dll
MOD - [2014-01-31 14:43:44 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\3230cdc86a08795a5ed94effd602ace5\System.Configuration.ni.dll
MOD - [2014-01-31 14:43:44 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\afe006d096b8ff0f1d3317e5ae67aa48\PresentationFramework.Aero.ni.dll
MOD - [2014-01-31 14:43:42 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\af264ee88b09d41f8a00e3b42afe724b\System.ni.dll
MOD - [2014-01-31 14:43:36 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\441fda1590ef311b4021510a76b768cb\mscorlib.ni.dll
MOD - [2009-07-29 10:19:42 | 000,356,352 | ---- | M] () -- C:\Windows\tsnpstd3.exe
MOD - [2008-09-16 19:18:06 | 000,132,608 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007-07-11 16:09:48 | 000,020,480 | ---- | M] () -- C:\Windows\FixCamera.exe
MOD - [2007-05-10 13:18:26 | 000,835,584 | ---- | M] () -- C:\Windows\vsnpstd3.exe
========== Services (SafeList) ==========
SRV - [2014-11-16 21:23:31 | 000,068,608 | ---- | M] (globalUpdate) [On_Demand | Stopped] -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe -- (globalUpdatem)
SRV - [2014-11-16 21:23:31 | 000,068,608 | ---- | M] (globalUpdate) [Auto | Stopped] -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe -- (globalUpdate)
SRV - [2014-11-15 00:57:29 | 000,770,944 | ---- | M] (Enigma Software Group USA, LLC.) [Auto | Running] -- C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe -- (SpyHunter 4 Service)
SRV - [2014-11-11 20:27:35 | 000,114,288 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014-10-06 19:03:23 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014-08-06 14:53:23 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2014-07-23 07:44:16 | 000,438,616 | ---- | M] (Garmin Ltd or its subsidiaries) [Auto | Running] -- C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe -- (Garmin Core Update Service)
SRV - [2014-06-05 03:19:38 | 000,093,040 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2014-04-09 14:12:50 | 000,235,696 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe -- (McComponentHostService)
SRV - [2014-02-25 07:29:58 | 000,353,792 | ---- | M] () [Auto | Running] -- C:\Users\Marszalek\AppData\Roaming\VOPackage\VOsrv.exe -- (VOsrv)
SRV - [2013-12-21 07:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011-08-03 12:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011-08-03 02:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009-10-30 11:25:08 | 000,415,960 | R--- | M] (cFos Software GmbH) [Auto | Running] -- C:\Program Files\Topos\cFosSpeed\spd.exe -- (cFosSpeedS)
SRV - [2009-07-14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009-07-14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009-07-14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007-05-31 15:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007-05-31 15:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\adiusbaw.sys -- (adiusbaw)
DRV - [2014-11-16 19:12:16 | 000,041,320 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files\ShopperPro\JSDriver\1.37.0.1406\jsdrv.sys -- (SPDRIVER_1.37.0.1406)
DRV - [2014-11-15 00:57:35 | 000,016,432 | ---- | M] (Enigma Software Group USA, LLC.) [Kernel | On_Demand | Running] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
DRV - [2014-11-15 00:57:32 | 000,019,984 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\EsgScanner.sys -- (EsgScanner)
DRV - [2014-08-06 14:53:45 | 000,414,520 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswsp.sys -- (aswSP)
DRV - [2014-08-06 14:53:27 | 000,779,536 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2014-08-06 14:53:27 | 000,192,352 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2014-08-06 14:53:27 | 000,071,944 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswstm.sys -- (aswStm)
DRV - [2014-08-06 14:53:26 | 000,081,768 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr)
DRV - [2014-08-06 14:53:26 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2014-08-06 14:53:26 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2014-08-06 14:53:26 | 000,024,184 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswHwid.sys -- (aswHwid)
DRV - [2013-12-19 14:11:31 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011-08-03 12:50:00 | 010,304,104 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009-12-21 16:30:30 | 000,043,520 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtTeam60.sys -- (TEAM)
DRV - [2009-12-21 16:30:30 | 000,043,520 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtTeam60.sys -- (RTTEAMPT)
DRV - [2009-10-30 11:25:12 | 000,872,152 | ---- | M] (cFos Software GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cfosspeed.sys -- (cFosSpeed)
DRV - [2009-07-20 03:26:40 | 000,027,648 | ---- | M] (Realtek ) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\RtNdPt60.sys -- (RtNdPt60)
DRV - [2009-07-17 17:30:20 | 010,551,040 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snpstd3.sys -- (SNPSTD3)
DRV - [2009-07-14 02:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009-07-14 02:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009-07-14 02:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009-07-14 00:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2009-07-14 00:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009-07-14 00:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2008-07-07 08:40:49 | 000,056,108 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2007-12-03 03:19:42 | 000,019,968 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtVlan60.sys -- (RTVLANPT)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.search-plaza.info/?pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69
IE - HKLM\..\SearchScopes,DefaultScope = {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.search-plaza.info/?l=1&q={searchTerms}&pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.search-plaza.info/?pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\..\SearchScopes,DefaultScope = {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\..\SearchScopes\{57379D6C-0051-4E5D-837E-809F5B1D9E96}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searcerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.search-plaza.info/?l=1&q={searchTerms}&pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1001\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3997692141-2039178269-1593662184-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: netvideohunter%40netvideohunter.com:1.16
FF - prefs.js..extensions.enabledAddons: fastdial%40telega.phpnet.us:4.12
FF - prefs.js..extensions.enabledAddons: ROUAILDE73397174%40UXGZI17268980.com:0.95.15
FF - prefs.js..extensions.enabledAddons: %7B64161300-e22b-11db-8314-0800200c9a66%7D:0.9.6.16
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.1
FF - prefs.js..extensions.enabledItems: fastdial@telega.phpnet.us:4.2.2
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.6.8
FF - prefs.js..extensions.enabledItems: wrc@avast.com:6.0.1289
FF - prefs.js..extensions.enabledItems: 2020Player_IKEA@2020Technologies.com:5.0.94.0
FF - prefs.js..browser.startup.homepage: "http://websearch.search-plaza.info/?pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69"
FF - prefs.js..browser.search.order.1: "WebSearch"
FF - prefs.js..browser.search.defaultenginename: "WebSearch"
FF - prefs.js..browser.search.selectedEngine: "WebSearch"
FF - prefs.js..browser.search.order.1,S: S", "WebSearch"
FF - prefs.js..browser.search.defaultenginename,S: S", "WebSearch"
FF - prefs.js..browser.search.selectedEngine,S: S", "WebSearch"
FF - prefs.js..keyword.URL: "http://websearch.search-plaza.info/?pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69&l=1&q="
FF - prefs.js..browser.search.defaulturl: "http://websearch.search-plaza.info/?pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69&l=1&q="
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10: C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4: C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Marszalek\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Marszalek\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-08-06 14:53:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014-11-11 20:27:31 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{e4f94d1e-2f53-401e-8885-681602c0ddd8}: C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
[2012-08-02 21:29:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Extensions
[2012-08-02 21:29:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2014-11-16 21:27:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions
[2013-09-17 12:51:24 | 000,000,000 | ---D | M] (Speed Dial) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2014-11-16 21:22:49 | 000,000,000 | ---D | M] (Shopper-Pro) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
[2014-11-16 21:24:33 | 000,000,000 | ---D | M] ("Ge-Force") -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\45633fba7e7d40fea9c29@9dc18447eea04021a325caf3.com
[2014-09-25 20:27:29 | 000,000,000 | ---D | M] (Fast Dial) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\fastdial@telega.phpnet.us
[2014-07-30 19:10:57 | 000,000,000 | ---D | M] ("NetVideoHunter") -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\netvideohunter@netvideohunter.com
[2014-10-20 22:51:00 | 000,000,000 | ---D | M] ("iWebar") -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\ROUAILDE73397174@UXGZI17268980.com
[2014-11-16 21:27:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\staged
[2014-11-16 21:24:43 | 000,000,000 | ---D | M] ("Sense") -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\warnerroberts@hotmail.com
[2014-11-16 21:24:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\45633fba7e7d40fea9c29@9dc18447eea04021a325caf3.com\extensionData
[2014-11-16 21:24:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\45633fba7e7d40fea9c29@9dc18447eea04021a325caf3.com\extensionData\plugins
[2014-11-16 21:24:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\45633fba7e7d40fea9c29@9dc18447eea04021a325caf3.com\extensionData\userCode
[2014-11-08 10:27:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData
[2014-11-08 10:27:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins
[2014-11-08 10:27:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\userCode
[2014-11-16 21:24:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\warnerroberts@hotmail.com\extensionData
[2014-11-16 21:24:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\warnerroberts@hotmail.com\extensionData\plugins
[2014-11-16 21:24:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marszalek\AppData\Roaming\mozilla\Firefox\Profiles\b7i9atke.default\extensions\warnerroberts@hotmail.com\extensionData\userCode
[2014-11-16 21:29:52 | 000,000,651 | ---- | M] () -- C:\Users\Marszalek\AppData\Roaming\mozilla\firefox\profiles\b7i9atke.default\searchplugins\WebSearch.xml
[2014-11-11 20:27:31 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014-11-11 20:27:36 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011-09-15 09:31:31 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://websearch.search-plaza.info/?pid=2583&r=2014/11/16&hid=11057869586550819800&lg=EN&cc=PL&unqvl=69
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Marszalek\AppData\Local\Google\Chrome\Application\38.0.2125.111\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Battlefield Play4Free Updater (Enabled) = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.66.2_0\npBP4FUpdater.dll
CHR - plugin: Battlefield Play4Free Updater (Enabled) = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei\1.0.66.2_0\BP4FUpdater.exe
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - default_search_provider: FB6FC777205A388E72F8FF0924DA6DBDBFE600D29ED5AB543F74BAEC17903C8D ()
CHR - default_search_provider: search_url = F88DC92D9C9237F48A5F9031EFC3E38CA483ACAEC0FE677BF4A74DC2D49F04FC
CHR - default_search_provider: suggest_url =
CHR - homepage: 3651E8BB2A4AD6ED2392ECFD137EA6878236542AB4B3A5921F15BE2A1F89BE58
CHR - Extension: YouTube = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Szukaj w Google = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.13.2_0\
CHR - Extension: Avast Online Security = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.0.2502.149_0\
CHR - Extension: Przycisk Pin It = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic\1.35_0\
CHR - Extension: Speed Dial 2 = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik\1.8.0_0\
CHR - Extension: Google Wallet = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\Marszalek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009-06-10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll File not found
O2 - BHO: (Ge-Force) - {11111111-1111-1111-1111-110611191111} - C:\Program Files\Ge-Force\Ge-Force-bho.dll (iWebar)
O2 - BHO: (Sense) - {11111111-1111-1111-1111-110611191115} - C:\Program Files\Sense\Sense-bho.dll (Object Browser)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll File not found
O2 - BHO: (Shopper Pro) - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll (Goobzo Ltd.)
O2 - BHO: (GoSave) - {ce27b70d-c597-4234-990c-714fe9a26cba} - C:\Program Files\GoSave\KnrJJ3FaSgOStA.dll ()
O2 - BHO: (YoutubeAdBlocke) - {d8d1a487-d056-4194-b38f-011e9b1978da} - C:\Program Files\YoutubeAdBlocke\PRsq4H8NaaUgIQ.dll ()
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O4 - HKLM..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" File not found
O4 - HKLM..\Run: [Aimersoft Helper Compact.exe] C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe (AimerSoft)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [cFosSpeed] C:\Program Files\Topos\cFosSpeed\cfosspeed.exe (cFos Software GmbH)
O4 - HKLM..\Run: [FixCamera] C:\Windows\FixCamera.exe ()
O4 - HKLM..\Run: [snpstd3] C:\Windows\vsnpstd3.exe ()
O4 - HKLM..\Run: [SPDriver] C:\Program Files\ShopperPro\JSDriver\1.37.0.1406\jsdrv.exe ()
O4 - HKLM..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe ()
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [GarminExpressTrayApp] C:\Program Files\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKU\S-1-5-18..\Run: [GarminExpressTrayApp] C:\Program Files\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" File not found
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [GarminExpressTrayApp] C:\Program Files\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [LiveSupport] C:\Program Files\LiveSupport\LiveSupport.exe (PC Utilities Software Limited)
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe File not found
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [se] C:\Users\Marszalek\AppData\Roaming\SkypEmoticons\SE.exe (SkypEmoticons)
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [SPDriver] C:\Program Files\ShopperPro\JSDriver\1.37.0.1406\jsdrv.exe ()
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1000..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3997692141-2039178269-1593662184-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.66.2.cab (Battlefield Play4Free Updater)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{762A5530-EA23-4B18-99CC-ECA3F8782624}: DhcpNameServer = 192.168.1.1 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2014-08-15 20:25:44 | 000,368,769 | ---- | M] () - C:\AutoMapaSetupLog.txt -- [ NTFS ]
O32 - AutoRun File - [2009-02-27 00:57:36 | 000,000,120 | ---- | M] () - I:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\SETUP.EXE
O33 - MountPoints2\H\Shell\configure\command - "" = H:\SETUP.EXE
O33 - MountPoints2\H\Shell\install\command - "" = H:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014-11-16 21:30:46 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Roaming\Optimizer Pro
[2014-11-16 21:29:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LiveSupport
[2014-11-16 21:29:52 | 000,000,000 | ---D | C] -- C:\Program Files\LiveSupport
[2014-11-16 21:29:46 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Roaming\SkypEmoticons
[2014-11-16 21:29:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkypEmoticons
[2014-11-16 21:29:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
[2014-11-16 21:28:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Trusted Publisher
[2014-11-16 21:28:21 | 000,000,000 | ---D | C] -- C:\Program Files\DeltaFix
[2014-11-16 21:27:35 | 000,000,000 | ---D | C] -- C:\Program Files\YoutubeAdBlocke
[2014-11-16 21:27:20 | 000,000,000 | ---D | C] -- C:\Program Files\GoSave
[2014-11-16 21:27:11 | 000,000,000 | ---D | C] -- C:\ProgramData\10759222319475739118
[2014-11-16 21:26:44 | 000,000,000 | ---D | C] -- C:\ProgramData\kmopbknmgjjkldcpajmpmicdbjoaifpp
[2014-11-16 21:24:47 | 001,466,784 | ---- | C] (Object Browser) -- C:\Users\Marszalek\AppData\Roaming\ELEZD.exe
[2014-11-16 21:24:11 | 000,000,000 | ---D | C] -- C:\Program Files\0e1e6853-e2ae-46d4-a587-6456bc0b2683
[2014-11-16 21:24:00 | 000,000,000 | ---D | C] -- C:\Program Files\f7f5596e-1617-4d96-b4bc-fef24dd0a81a
[2014-11-16 21:23:42 | 001,940,896 | ---- | C] (Object Browser) -- C:\Users\Marszalek\AppData\Roaming\QIWHDL.exe
[2014-11-16 21:23:33 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Local\globalUpdate
[2014-11-16 21:23:33 | 000,000,000 | ---D | C] -- C:\Program Files\globalUpdate
[2014-11-16 21:23:30 | 000,000,000 | ---D | C] -- C:\Program Files\Sense
[2014-11-16 21:23:30 | 000,000,000 | ---D | C] -- C:\Program Files\Ge-Force
[2014-11-16 21:22:47 | 000,000,000 | ---D | C] -- C:\ProgramData\ShopperPro
[2014-11-16 21:22:45 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\ShopperPro
[2014-11-16 21:22:39 | 000,000,000 | ---D | C] -- C:\Program Files\ShopperPro
[2014-11-16 21:21:28 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Roaming\VOPackage
[2014-11-15 00:58:34 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Roaming\Enigma Software Group
[2014-11-15 00:58:30 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
[2014-11-15 00:58:17 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2014-11-15 00:57:25 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2014-11-11 20:27:30 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014-10-31 07:21:32 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\Desktop\Nowy folder (2)
[2014-10-27 11:41:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2014-10-21 23:35:45 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014-10-20 22:15:22 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2014-10-20 22:15:01 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Local\Installer
[2014-10-20 22:14:57 | 000,000,000 | ---D | C] -- C:\Users\Marszalek\AppData\Local\CrashRpt
[2014-10-20 22:11:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Users\Marszalek\AppData\Local\*.tmp files -> C:\Users\Marszalek\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014-11-16 22:47:26 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014-11-16 22:47:26 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014-11-16 22:24:00 | 000,005,832 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-6.job
[2014-11-16 22:24:00 | 000,005,826 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-6.job
[2014-11-16 22:02:00 | 000,001,074 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3997692141-2039178269-1593662184-1000UA.job
[2014-11-16 22:02:00 | 000,001,022 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3997692141-2039178269-1593662184-1000Core.job
[2014-11-16 22:02:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014-11-16 21:29:53 | 000,001,843 | ---- | M] () -- C:\Users\Marszalek\Desktop\LiveSupport.lnk
[2014-11-16 21:29:43 | 000,000,984 | ---- | M] () -- C:\Users\Marszalek\Desktop\Optimizer Pro.lnk
[2014-11-16 21:28:30 | 000,000,484 | -H-- | M] () -- C:\Windows\tasks\SW-Booster-S-792098896.job
[2014-11-16 21:28:07 | 000,000,952 | ---- | M] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
[2014-11-16 21:28:00 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
[2014-11-16 21:25:06 | 000,002,754 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-5_user.job
[2014-11-16 21:25:05 | 000,002,754 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-5.job
[2014-11-16 21:25:00 | 000,002,760 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-5_user.job
[2014-11-16 21:24:57 | 000,002,760 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-5.job
[2014-11-16 21:24:55 | 000,002,410 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-2.job
[2014-11-16 21:24:50 | 000,003,742 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-1.job
[2014-11-16 21:24:48 | 000,001,352 | ---- | M] () -- C:\Windows\tasks\ELEZD.job
[2014-11-16 21:24:47 | 001,466,784 | ---- | M] (Object Browser) -- C:\Users\Marszalek\AppData\Roaming\ELEZD.exe
[2014-11-16 21:24:47 | 000,002,416 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-2.job
[2014-11-16 21:24:39 | 000,003,754 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-1.job
[2014-11-16 21:24:32 | 000,004,458 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-4.job
[2014-11-16 21:24:20 | 000,004,464 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-4.job
[2014-11-16 21:24:14 | 000,005,482 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-7.job
[2014-11-16 21:24:02 | 000,005,488 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-7.job
[2014-11-16 21:23:51 | 000,005,148 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-11.job
[2014-11-16 21:23:46 | 000,001,354 | ---- | M] () -- C:\Windows\tasks\QIWHDL.job
[2014-11-16 21:23:42 | 001,940,896 | ---- | M] (Object Browser) -- C:\Users\Marszalek\AppData\Roaming\QIWHDL.exe
[2014-11-16 21:23:39 | 000,003,778 | ---- | M] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-3.job
[2014-11-16 21:23:36 | 000,005,154 | ---- | M] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-11.job
[2014-11-16 21:22:26 | 000,000,859 | ---- | M] () -- C:\Users\Marszalek\Desktop\Continue VuuPC Installation.lnk
[2014-11-16 20:53:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014-11-16 20:53:39 | 2616,057,856 | -HS- | M] () -- C:\hiberfil.sys
[2014-11-15 00:58:30 | 000,001,204 | ---- | M] () -- C:\Users\Marszalek\Desktop\SpyHunter.lnk
[2014-11-15 00:57:32 | 000,019,984 | ---- | M] () -- C:\Windows\System32\drivers\EsgScanner.sys
[2014-11-14 23:33:01 | 000,697,674 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2014-11-14 23:33:01 | 000,615,810 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014-11-14 23:33:01 | 000,134,784 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2014-11-14 23:33:01 | 000,106,190 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014-11-13 17:03:05 | 000,001,994 | ---- | M] () -- C:\Users\Marszalek\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2014-10-26 01:28:55 | 000,055,808 | ---- | M] () -- C:\Users\Marszalek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014-10-21 23:35:34 | 001,962,496 | ---- | M] () -- C:\Users\Marszalek\Desktop\adwcleaner_4.001.exe
[2014-10-21 22:15:33 | 000,001,379 | ---- | M] () -- C:\Users\Marszalek\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014-10-21 00:34:38 | 000,163,169 | ---- | M] () -- C:\Users\Marszalek\Desktop\kulka.jpg
[2014-10-20 22:17:57 | 000,002,125 | ---- | M] () -- C:\Users\Marszalek\Desktop\AppsHat.lnk
[2014-10-20 22:10:39 | 000,278,861 | ---- | M] () -- C:\Users\Marszalek\Desktop\vod.pl
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Users\Marszalek\AppData\Local\*.tmp files -> C:\Users\Marszalek\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014-11-16 21:29:53 | 000,001,843 | ---- | C] () -- C:\Users\Marszalek\Desktop\LiveSupport.lnk
[2014-11-16 21:29:43 | 000,000,984 | ---- | C] () -- C:\Users\Marszalek\Desktop\Optimizer Pro.lnk
[2014-11-16 21:28:29 | 000,000,484 | -H-- | C] () -- C:\Windows\tasks\SW-Booster-S-792098896.job
[2014-11-16 21:25:06 | 000,002,754 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-5_user.job
[2014-11-16 21:25:04 | 000,002,754 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-5.job
[2014-11-16 21:24:59 | 000,002,760 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-5_user.job
[2014-11-16 21:24:57 | 000,002,760 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-5.job
[2014-11-16 21:24:55 | 000,002,410 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-2.job
[2014-11-16 21:24:49 | 000,003,742 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-1.job
[2014-11-16 21:24:48 | 000,001,352 | ---- | C] () -- C:\Windows\tasks\ELEZD.job
[2014-11-16 21:24:46 | 000,002,416 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-2.job
[2014-11-16 21:24:37 | 000,003,754 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-1.job
[2014-11-16 21:24:30 | 000,004,458 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-4.job
[2014-11-16 21:24:19 | 000,004,464 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-4.job
[2014-11-16 21:24:15 | 000,005,826 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-6.job
[2014-11-16 21:24:12 | 000,005,482 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-7.job
[2014-11-16 21:24:03 | 000,005,832 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-6.job
[2014-11-16 21:24:00 | 000,005,488 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-7.job
[2014-11-16 21:23:46 | 000,005,148 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-11.job
[2014-11-16 21:23:43 | 000,001,354 | ---- | C] () -- C:\Windows\tasks\QIWHDL.job
[2014-11-16 21:23:41 | 000,000,952 | ---- | C] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
[2014-11-16 21:23:39 | 000,000,948 | ---- | C] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
[2014-11-16 21:23:34 | 000,005,154 | ---- | C] () -- C:\Windows\tasks\d608622f-3caf-4dc7-8ffa-2a7eb30f7412-11.job
[2014-11-16 21:23:34 | 000,003,778 | ---- | C] () -- C:\Windows\tasks\a6a974f1-03ae-4552-830c-3ab5f40217fd-3.job
[2014-11-16 21:22:26 | 000,000,859 | ---- | C] () -- C:\Users\Marszalek\Desktop\Continue VuuPC Installation.lnk
[2014-11-15 00:58:30 | 000,001,204 | ---- | C] () -- C:\Users\Marszalek\Desktop\SpyHunter.lnk
[2014-11-15 00:57:32 | 000,019,984 | ---- | C] () -- C:\Windows\System32\drivers\EsgScanner.sys
[2014-10-21 23:35:33 | 001,962,496 | ---- | C] () -- C:\Users\Marszalek\Desktop\adwcleaner_4.001.exe
[2014-10-21 00:33:37 | 000,163,169 | ---- | C] () -- C:\Users\Marszalek\Desktop\kulka.jpg
[2014-10-20 22:17:57 | 000,002,125 | ---- | C] () -- C:\Users\Marszalek\Desktop\AppsHat.lnk
[2014-10-20 22:11:37 | 000,001,367 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014-10-20 22:10:56 | 000,278,861 | ---- | C] () -- C:\Users\Marszalek\Desktop\vod.pl
[2014-09-01 09:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Marszalek\AppData\Roaming\ELEZD
[2014-09-01 09:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Marszalek\AppData\Roaming\QIWHDL
[2014-08-06 14:53:35 | 000,024,184 | ---- | C] () -- C:\Windows\System32\drivers\aswHwid.sys
[2014-01-28 17:06:35 | 000,002,244 | ---- | C] () -- C:\Windows\System32\ASOROSet.bin
[2014-01-28 13:30:45 | 000,000,044 | ---- | C] () -- C:\Users\Marszalek\AppData\Roaming\WB.CFG
[2014-01-15 10:29:01 | 000,192,352 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2014-01-15 10:29:00 | 000,049,944 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
[2013-02-25 21:45:54 | 000,707,504 | ---- | C] () -- C:\Users\Marszalek\AppData\Local\unins000.exe
[2013-02-25 21:45:01 | 000,011,761 | ---- | C] () -- C:\Users\Marszalek\AppData\Local\unins000.msg
[2013-02-25 21:45:01 | 000,004,176 | ---- | C] () -- C:\Users\Marszalek\AppData\Local\unins000.dat
[2012-10-12 00:50:42 | 000,049,738 | ---- | C] () -- C:\Program Files\AutoMapa EU.md5
[2012-01-27 08:46:30 | 000,004,096 | -H-- | C] () -- C:\Users\Marszalek\AppData\Local\keyfile3.drm
[2011-08-10 14:35:03 | 000,055,808 | ---- | C] () -- C:\Users\Marszalek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2009-07-14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009-07-14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009-07-14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2014-06-12 12:44:10 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Garmin
[2014-06-12 12:44:10 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Garmin
[2011-07-23 22:18:59 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Ashampoo
[2014-01-15 10:34:31 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\AVAST Software
[2014-03-19 08:14:33 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Codeton
[2014-03-18 10:36:46 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2014-11-15 00:58:34 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Enigma Software Group
[2011-12-27 12:58:49 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Gadu-Gadu 10
[2014-01-31 14:48:56 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Garmin
[2012-01-02 16:38:16 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\GetRightToGo
[2011-08-02 14:17:18 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\OpenFM
[2011-07-16 01:12:11 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Opera
[2014-05-23 23:58:50 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Opera Software
[2014-11-16 21:30:46 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Optimizer Pro
[2012-04-03 10:22:24 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Patcher
[2012-11-23 13:40:48 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\PDFCreatorPackages
[2013-05-20 15:38:50 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\PITy2011
[2014-02-01 10:56:00 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\Podatnik.info
[2012-08-02 21:29:51 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\TomTom
[2014-10-21 22:03:53 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\uTorrent
[2014-11-16 21:51:48 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\VOPackage
[2013-01-03 01:16:10 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\XMedia Recode
[2014-10-25 12:28:33 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\XnView
[2012-02-10 20:08:07 | 000,000,000 | ---D | M] -- C:\Users\Marszalek\AppData\Roaming\YFSoftware
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:56E2E879
< End of report >
Raport z Ekstras wkleję jak ktoś się odezwie, bo za długi post wychodzi i nie pozwala mi wysłać
Pozdrawiam