Skocz do zawartości


Zdjęcie

Logi - Funkcje w programach nie działają + uber zamuł


  • Zamknięty Temat jest zamknięty
9 odpowiedzi w tym temacie

#1 Sup Sis feggit meggit xoxo

Sup Sis feggit meggit xoxo

    Początkujący

  • 11 postów

Napisano 16 03 2013 - 21:40

Po włączeniu kompa mam taki problem, że niektóre programy/aplikacje nie działają. Np po kliknięciu na ikonkę opery lub innych przeglądarek nie chcą się włączyć (wygląda to w ten sposób, że kółeczko obok kurosra sobie się kręci, ale mimo wszystko nie chce się włączyć). Foldery otwierają się bez problemu, dokumenty tekstowe też. Taki "odkurzacz" też działa, o grach nie ma co gadać. Największy problem jest z przeglądarkami. Żeby sprawdzić czy nie jest to po prostu wielki zamuł zostawiłem kompa na 30 minut po włączeniu (nic nie dotykałem po zalogowaniu się) i wciąż jest ten sam problem. Uwaga w trybie awaryjnym wszystko śmiga. Ten cały problem pojawił się z dnia na dzień.






Pierwszy log jest z RSIT x64
Logfile of random's system information tool 1.09 (written by random/random)
Run by dom at 2013-03-16 20:15:57
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 25 GB (12%) free of 200 GB
Total RAM: 4095 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:16:03, on 2013-03-16
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Safe mode with network support

Running processes:
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Users\dom\Desktop\OTL.exe
C:\Program Files\trend micro\dom.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = pl.v9.com/idg/idg_1342608838_220770
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}"]Babylon Search[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}"]Babylon Search[/url]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=hp&babsrc=lnkry_nt"]Babylon Search[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]MetroMSN.pl - MSN.pl - wydarzenia, styl życia, dom, pieniądze, rozrywka i gwiazdy,metro, Hotmail[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]Bing[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]Bing[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}"]Babylon Search[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}"]Babylon Search[/url]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
F2 - REG:system.ini: Shell=C:\PROGRA~3\Fh59IZN.bat
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: MediaBar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\ToolBar\imeshdtxmltbpi.dll
O2 - BHO: Linkury SmartbarEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - mscoree.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\IEBHO.dll
O2 - BHO: Zoomex - {67BF155D-7896-43A3-1C8B-B3F619E820B1} - C:\ProgramData\Zoomex\50fd51e662695.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: MediaBar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\ToolBar\imeshdtxmltbpi.dll
O3 - Toolbar: Linkury Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - mscoree.dll (file missing)
O3 - Toolbar: SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'USŁUGA SIECIOWA')
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{81022E93-1FC7-4565-916F-AB4D30895698}: NameServer = 62.179.1.62
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - (no file)
O20 - AppInit_DLLs: c:\progra~3\browse~1\23787~1.43\{16cdf~1\browse~1.dll c:\progra~3\browse~1\22643~1.41\{16cdf~1\browse~1.dll c:\progra~2\zoomex\sprote~1.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9572 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE 0x274
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
ctfmon.exe
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe"
"C:\Program Files (x86)\Opera\opera.exe"
"C:\Users\dom\Desktop\OTL.exe"
"C:\Users\dom\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\RMAutoUpdate.job
C:\Windows\tasks\RMSchedule.job
C:\Windows\tasks\ZoomExUpdaterTask{DAED68F5-436B-4787-8ECB-67A74F866FE0}.job

=========Mozilla firefox=========

ProfilePath - C:\Users\dom\AppData\Roaming\Mozilla\Firefox\Profiles\vty4knvd.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.146 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.13.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@mywebsearch.com/Plugin]
"Description"=My Web Search Plugin
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.146 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
allegro-pl.xml
fbc-pl.xml
google.xml
merlin-pl.xml
pwn-pl.xml
wikipedia-pl.xml
wp-pl.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}]
AVG Do Not Track - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll [2012-08-13 1393272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}]
Linkury SmartbarEngine - C:\Windows\system32\mscoree.dll [2010-11-05 444752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll [2012-06-24 1968248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{474597C5-AB09-49d6-A4D5-2E8D7341384E}]
UrlHelper Class - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll [2011-02-08 1057160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2012-10-02 5748928]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 77576]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{28387537-e3f9-4ed7-860c-11e69af4a8a0}]
MediaBar - C:\PROGRA~2\IMESHA~1\MediaBar\ToolBar\imeshdtxmltbpi.dll [2011-01-24 89008]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}]
Linkury SmartbarEngine - C:\Windows\system32\mscoree.dll [2010-11-05 444752]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll [2012-06-24 1417336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{474597C5-AB09-49d6-A4D5-2E8D7341384E}]
UrlHelper Class - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\IEBHO.dll [2011-02-08 721288]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67BF155D-7896-43A3-1C8B-B3F619E820B1}]
Zoomex - C:\ProgramData\Zoomex\50fd51e662695.dll [2013-01-21 120832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-02-06 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-10-02 4119744]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-02-06 170912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetPacks Browser Helper - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2012-07-04 1310040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} -
{ae07101b-46d4-4a98-af68-0333ea26e113} - Linkury Smartbar - C:\Windows\system32\mscoree.dll [2010-11-05 444752]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{07B18EA9-A523-4961-B6BB-170DE4475CCA}
{D4027C7F-154A-4066-A1AD-4243D8127440} -
{28387537-e3f9-4ed7-860c-11e69af4a8a0} - MediaBar - C:\PROGRA~2\IMESHA~1\MediaBar\ToolBar\imeshdtxmltbpi.dll [2011-01-24 89008]
{ae07101b-46d4-4a98-af68-0333ea26e113} - Linkury Smartbar - C:\Windows\system32\mscoree.dll [2010-11-05 444752]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetPacks Toolbar for Internet Explorer - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2012-07-04 1310040]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-01-08 18705664]
"ccleaner"=C:\Program Files\CCleaner\CCleaner64.exe [2012-06-22 5283680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
C:\Program Files (x86)\Ask.com\Updater\Updater.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_TRAY]
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe [2012-07-31 2596984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Browser Infrastructure Helper]
C:\Users\dom\AppData\Local\Smartbar\Application\Linkury.exe [2013-01-21 13824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2009-08-28 2252800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2012-06-27 1996200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar Search Scope Monitor]
C:\PROGRA~2\MYWEBS~1\bar\2.bin\m3SrchMn.exe /m=2 /w /h []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~2\MYWEBS~1\bar\2.bin\mwsoemon.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2013-03-07 3093624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor]
C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [2012-08-21 105120]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe [2012-05-29 115032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sweetpacks Communicator]
C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^dom^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^runctf.lnk]
C:\Users\dom\AppData\Local\Temp\dYSEvWR.exe,M1N1 []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
""= []
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe aml []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\datamngr.dll C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBuilder]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Audiosrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\drmkaud]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HDAudBus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MMCSS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{640167b4-59b0-47a6-b335-a6b3c0695aea}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AudioEndpointBuilder]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Audiosrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\drmkaud]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HdAudAddService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HDAudBus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MMCSS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96C-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{640167b4-59b0-47a6-b335-a6b3c0695aea}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcod64.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.XFR1"=xfcodec64.dll
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"MSVideo"=vfwwdm32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-03-16 20:09:31 ----A---- C:\Windows\system32\FNTCACHE.DAT
2013-03-16 20:09:18 ----A---- C:\Windows\ntbtlog.txt
2013-03-16 18:12:10 ----D---- C:\Users\dom\AppData\Roaming\Malwarebytes
2013-03-16 18:12:03 ----D---- C:\ProgramData\Malwarebytes
2013-03-16 18:12:03 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-03-16 18:12:03 ----A---- C:\Windows\system32\drivers\mbam.sys
2013-03-16 15:31:10 ----D---- C:\rsit
2013-03-16 15:31:10 ----D---- C:\Program Files\trend micro
2013-03-12 14:56:08 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-03-09 06:45:33 ----A---- C:\Windows\system32\win32k.sys
2013-03-09 06:45:29 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-03-09 06:45:29 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2013-03-09 06:45:26 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-03-09 06:45:25 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-03-09 06:45:25 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-03-07 18:22:31 ----D---- C:\ProgramData\PMB Files
2013-03-07 18:22:17 ----D---- C:\Program Files (x86)\Pando Networks

======List of files/folders modified in the last 1 month======

2013-03-16 20:09:57 ----D---- C:\Windows
2013-03-16 20:09:31 ----D---- C:\Windows\System32
2013-03-16 20:09:19 ----D---- C:\Windows\system32\config
2013-03-16 20:09:15 ----D---- C:\Program Files\Microsoft Silverlight
2013-03-16 20:09:14 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2013-03-16 19:56:40 ----RD---- C:\Program Files (x86)
2013-03-16 19:49:57 ----SHD---- C:\System Volume Information
2013-03-16 19:44:47 ----D---- C:\Windows\system32\catroot
2013-03-16 19:44:46 ----D---- C:\Windows\system32\catroot2
2013-03-16 19:43:29 ----D---- C:\Windows\winsxs
2013-03-16 19:43:15 ----SHD---- C:\Windows\Installer
2013-03-16 19:43:13 ----AD---- C:\Windows\Temp
2013-03-16 19:43:12 ----SHD---- C:\Config.Msi
2013-03-16 19:40:16 ----D---- C:\Windows\SoftwareDistribution
2013-03-16 19:37:18 ----D---- C:\Windows\system32\LogFiles
2013-03-16 19:26:01 ----D---- C:\Users\dom\AppData\Roaming\Skype
2013-03-16 18:12:03 ----HD---- C:\ProgramData
2013-03-16 18:12:03 ----D---- C:\Windows\system32\drivers
2013-03-16 18:08:32 ----D---- C:\Program Files (x86)\Opera
2013-03-16 15:31:10 ----RD---- C:\Program Files
2013-03-16 11:04:03 ----D---- C:\Windows\inf
2013-03-16 10:17:30 ----D---- C:\Windows\Microsoft.NET
2013-03-16 07:55:40 ----RSD---- C:\Windows\assembly
2013-03-16 07:48:43 ----SD---- C:\ProgramData\Microsoft
2013-03-15 19:16:59 ----D---- C:\Users\dom\AppData\Roaming\BitTorrent
2013-03-15 17:04:11 ----D---- C:\Windows\Prefetch
2013-03-15 14:19:08 ----D---- C:\Users\dom\AppData\Roaming\DAEMON Tools Lite
2013-03-15 14:18:07 ----D---- C:\Windows\debug
2013-03-15 13:52:50 ----D---- C:\Windows\SysWOW64
2013-03-15 06:36:33 ----D---- C:\ProgramData\Microsoft Help
2013-03-14 06:33:34 ----D---- C:\Windows\pss
2013-03-14 06:30:02 ----D---- C:\Windows\SYSWOW64\migration
2013-03-14 06:30:02 ----D---- C:\Windows\system32\migration
2013-03-14 06:30:02 ----D---- C:\Windows\AppPatch
2013-03-14 06:30:02 ----D---- C:\Program Files\Internet Explorer
2013-03-14 06:30:02 ----D---- C:\Program Files (x86)\Internet Explorer
2013-03-14 06:27:33 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-03-12 20:12:05 ----D---- C:\Program Files\Common Files
2013-03-12 17:18:54 ----D---- C:\ProgramData\BioWare
2013-03-12 17:11:43 ----D---- C:\ProgramData\InstallShield
2013-03-12 17:11:42 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-03-12 14:56:06 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-03-07 18:29:27 ----RD---- C:\Users
2013-03-07 18:19:33 ----D---- C:\Program Files (x86)\League of Legends
2013-03-07 18:12:51 ----D---- C:\Users\dom\AppData\Roaming\RenPy
2013-03-06 22:00:32 ----D---- C:\Windows\system32\wbem
2013-03-06 21:59:35 ----D---- C:\Windows\Tasks
2013-03-06 21:59:35 ----D---- C:\Windows\system32\wfp
2013-03-06 21:59:35 ----D---- C:\Windows\system32\DriverStore
2013-03-06 21:59:34 ----DC---- C:\Windows\system32\DRVSTORE
2013-03-06 21:59:34 ----D---- C:\Windows\system32\Tasks
2013-03-06 21:59:34 ----D---- C:\Windows\system32\CodeIntegrity
2013-03-06 21:59:32 ----D---- C:\Windows\Help
2013-03-06 21:59:26 ----D---- C:\Users\dom\AppData\Roaming\ijjigame
2013-03-06 21:59:25 ----D---- C:\Users\dom\AppData\Roaming\GG
2013-03-06 21:59:25 ----D---- C:\Users\dom\AppData\Roaming\Gadu-Gadu 10
2013-03-06 21:59:25 ----D---- C:\Users\dom\AppData\Roaming\FunnyGames
2013-03-06 21:59:25 ----D---- C:\Users\dom\AppData\Roaming\Downloaded Installations
2013-03-06 21:59:25 ----D---- C:\Users\dom\AppData\Roaming\Condusiv_Technologies
2013-03-06 21:59:21 ----D---- C:\Program Files\Condusiv Technologies
2013-03-06 21:59:21 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-03-06 21:59:19 ----D---- C:\Program Files (x86)\Diskeeper Setup Files
2013-03-06 21:59:04 ----D---- C:\Windows\registration

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2012-04-19 28480]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2012-01-31 36944]
R0 DKDFM;Device Filter Manager Driver; C:\Windows\system32\drivers\DKDFM.sys [2012-04-05 40752]
R0 DKTLFSMF;Telemetry File System Mini Filter Driver; C:\Windows\system32\drivers\DKTLFSMF.sys [2012-07-09 106832]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-11-27 564824]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2012-08-24 384352]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2012-09-04 31080]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-05-22 215040]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2009-08-17 1235968]
S1 appdrv01;Application Driver (01); C:\Windows\System32\Drivers\appdrv01.sys [2010-08-12 2715824]
S1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2012-07-26 291680]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2011-12-23 47696]
S3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
S3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-04 359936]
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-03-09 123408]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
S3 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2011-12-23 124496]
S3 AVGIDSFilter;AVGIDSFilter; C:\Windows\system32\DRIVERS\avgidsfiltera.sys [2011-12-23 29776]
S3 DKRtWrt;DKRtWrt; C:\Windows\system32\DRIVERS\DKRtWrt.sys [2012-06-18 52048]
S3 dump_wmimmc;dump_wmimmc; \??\C:\ijji\ENGLISH\AVA\Binaries\GameGuard\dump_wmimmc.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 ENTECH64;ENTECH64; \??\C:\Windows\system32\DRIVERS\ENTECH64.sys [2008-04-22 12744]
S3 LVUVC64;Logitech Webcam C160(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2011-04-01 4184672]
S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2012-12-14 24176]
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2005-01-02 4682]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-07 19456]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-11-07 57856]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
S2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-07-26 76888]
S2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S3 aspnet_state;„Usługa stanu ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-06-15 3583592]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-07 1255736]
S4 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-04 238080]
S4 appdrvrem01;Application Driver Auto Removal Service (01); C:\Windows\System32\appdrvrem01.exe [2010-08-12 551896]
S4 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2012-08-13 5167736]
S4 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288]
S4 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-06-27 2369960]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-03-07 115608]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [2012-08-21 794272]
S4 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000]
S4 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-01-29 541608]
S4 UMVPFSrv;UMVPFSrv; C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-04-01 428640]

-----------------EOF-----------------
Drugi z OTL
OTL logfile created on: 2013-03-16 20:15:52 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\dom\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 74,99% Memory free
8,00 Gb Paging File | 7,04 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 195,21 Gb Total Space | 24,29 Gb Free Space | 12,44% Space Free | Partition Type: NTFS
Drive D: | 146,39 Gb Total Space | 146,28 Gb Free Space | 99,92% Space Free | Partition Type: NTFS
Drive E: | 121,09 Gb Total Space | 120,99 Gb Free Space | 99,92% Space Free | Partition Type: NTFS

Computer Name: DOM-KOMPUTER | User Name: dom | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2013-03-16 14:41:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\dom\Desktop\OTL.exe
PRC - [2013-02-10 15:44:12 | 000,879,456 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\opera.exe
PRC - [2012-12-14 16:49:28 | 000,824,232 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2013-01-09 19:53:19 | 014,586,888 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2012-07-04 07:20:54 | 000,238,080 | ---- | M] (AMD) [Disabled | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:[b]64bit:[/b] - [2010-08-12 14:32:42 | 000,551,896 | ---- | M] (Protection Technology) [Disabled | Stopped] -- C:\Windows\SysNative\appdrvrem01.exe -- (appdrvrem01)
SRV - [2013-03-07 15:29:15 | 000,115,608 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013-01-29 16:58:21 | 000,541,608 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012-12-14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012-12-14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012-10-02 12:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Disabled | Stopped] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012-08-21 14:43:58 | 000,794,272 | ---- | M] (PC Tools) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2012-08-13 02:24:48 | 005,167,736 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2012-07-26 21:17:03 | 000,076,888 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012-06-27 11:29:24 | 002,369,960 | ---- | M] (LogMeIn Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2012-02-14 03:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011-04-01 04:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2010-06-15 16:19:03 | 003,583,592 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2012-12-14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:[b]64bit:[/b] - [2012-11-27 20:00:20 | 000,564,824 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:[b]64bit:[/b] - [2012-11-07 22:09:19 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2012-11-07 22:09:18 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2012-09-04 12:34:14 | 000,031,080 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:[b]64bit:[/b] - [2012-08-24 14:43:16 | 000,384,352 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:[b]64bit:[/b] - [2012-07-26 02:21:28 | 000,291,680 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:[b]64bit:[/b] - [2012-07-09 14:54:58 | 000,106,832 | ---- | M] (Condusiv Technologies) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\DKTLFSMF.sys -- (DKTLFSMF)
DRV:[b]64bit:[/b] - [2012-07-04 07:59:32 | 011,922,944 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:[b]64bit:[/b] - [2012-07-04 07:59:32 | 011,922,944 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:[b]64bit:[/b] - [2012-07-04 06:10:56 | 000,359,936 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:[b]64bit:[/b] - [2012-06-18 19:14:34 | 000,052,048 | ---- | M] (Condusiv Technologies) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\DKRtWrt.sys -- (DKRtWrt)
DRV:[b]64bit:[/b] - [2012-04-19 03:50:26 | 000,028,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:[b]64bit:[/b] - [2012-04-05 02:32:54 | 000,040,752 | ---- | M] (Condusiv Technologies) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\DKDFM.sys -- (DKDFM)
DRV:[b]64bit:[/b] - [2012-03-01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2012-02-23 13:32:04 | 000,095,760 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:[b]64bit:[/b] - [2012-01-31 03:46:48 | 000,036,944 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:[b]64bit:[/b] - [2011-12-23 12:32:14 | 000,047,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:[b]64bit:[/b] - [2011-12-23 12:32:04 | 000,029,776 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avgidsfiltera.sys -- (AVGIDSFilter)
DRV:[b]64bit:[/b] - [2011-12-23 12:31:58 | 000,124,496 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:[b]64bit:[/b] - [2011-04-01 04:07:54 | 004,184,672 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:[b]64bit:[/b] - [2011-03-11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011-03-11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2010-11-20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010-08-12 14:32:43 | 002,715,824 | ---- | M] (Protection Technology) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\appdrv01.sys -- (appdrv01)
DRV:[b]64bit:[/b] - [2010-03-09 11:21:42 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:[b]64bit:[/b] - [2009-08-17 12:20:46 | 001,235,968 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV:[b]64bit:[/b] - [2009-07-16 04:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:[b]64bit:[/b] - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2009-05-22 15:52:30 | 000,215,040 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2009-03-18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:[b]64bit:[/b] - [2008-04-22 07:53:36 | 000,012,744 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Entech64.sys -- (ENTECH64)
DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2005-01-02 04:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [url="http://searchfunmoods.com/?f=1&a=iron2&ir=iron2&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0E0CtBtC0DyEtD0DtBtA0EtN0D0Tzu0CtAyDtCtN1L2XzutBtFtBtFtCtFyEtDyB&cr=911712656"]Funmoods Search[/url]
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = [url="http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&ir=iron2&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0E0CtBtC0DyEtD0DtBtA0EtN0D0Tzu0CtAyDtCtN1L2XzutBtFtBtFtCtFyEtDyB&cr=911712656"]Funmoods Search[/url]
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = [url="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC"]{searchTerms} - Bing[/url]
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}: "URL" = [url="http://www.searchya.com/?q={searchTerms}&s=1&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0E0CtBtC0DyEtD0DtBtA0EtN0D0Tzu0CtBtAtDtN1L2XzutBtFtCtFtCtFtAtCtB&cr=2048707667"]Searchya Search[/url]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [url="http://www.google.com"]Google[/url]
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}"]Babylon Search[/url]
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = [url="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC"]{searchTerms} - Bing[/url]


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = [url="http://search.babylon.com/?affID=110809&tt=bandext_3312_8&babsrc=HP_ss&mntrId=44dbd23e00000000000000ffe5264df8"]Babylon Search[/url]
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = [url="http://search.babylon.com/?affID=110809&tt=bandext_3312_8&babsrc=HP_ss&mntrId=44dbd23e00000000000000ffe5264df8"]Babylon Search[/url]
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = [url="http://search.babylon.com/?affID=110809&tt=bandext_3312_8&babsrc=HP_ss&mntrId=44dbd23e00000000000000ffe5264df8"]Babylon Search[/url]
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = pl.v9.com/idg/idg_1342608838_220770
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}"]Babylon Search[/url]
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}"]Babylon Search[/url]
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=hp&babsrc=lnkry_nt"]Babylon Search[/url]
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}"]Babylon Search[/url]
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}"]Babylon Search[/url]
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes,Backup.Old.DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}"]Babylon Search[/url]
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = [url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"]{searchTerms} - Bing[/url]
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]



FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\dom\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\dom\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012-09-11 12:47:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013-03-12 14:56:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011-12-31 11:18:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dom\AppData\Roaming\mozilla\Extensions
[2012-12-16 22:15:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dom\AppData\Roaming\mozilla\Firefox\Profiles\afss4h8w.default\extensions
[2012-12-16 22:15:50 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Users\dom\AppData\Roaming\mozilla\Firefox\Profiles\afss4h8w.default\extensions\ffxtlbr@funmoods.com
[2012-08-17 19:07:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dom\AppData\Roaming\mozilla\Firefox\Profiles\afss4h8w.default\extensions\staged
[2012-02-05 14:46:21 | 000,000,000 | ---D | M] (@@toolbarname@@) -- C:\Users\dom\AppData\Roaming\mozilla\Firefox\Profiles\afss4h8w.default\extensions\toolbar@ask.com
[2012-12-16 22:15:49 | 000,000,777 | ---- | M] () -- C:\Users\dom\AppData\Roaming\mozilla\firefox\profiles\afss4h8w.default\searchplugins\Funmoods.xml
[2012-08-17 19:07:49 | 000,000,777 | ---- | M] () -- C:\Users\dom\AppData\Roaming\mozilla\firefox\profiles\afss4h8w.default\searchplugins\Search.xml
[2013-03-12 14:56:06 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012-11-01 22:49:00 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013-03-07 15:30:04 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013-03-07 17:48:47 | 000,002,980 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml
[2013-03-07 17:48:47 | 000,001,619 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml
[2013-03-07 17:48:47 | 000,001,130 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml
[2013-03-07 17:48:47 | 000,001,071 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml
[2013-03-07 17:48:47 | 000,001,396 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml
[2013-03-07 17:48:47 | 000,001,896 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml

[color=#E56717]========== Chrome ==========[/color]

CHR - homepage: [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=hp&babsrc=lnkry"]Babylon Search[/url]
CHR - default_search_provider: Web (Enabled)
CHR - default_search_provider: search_url = [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}"]Babylon Search[/url]
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: [url="http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=hp&babsrc=lnkry"]Babylon Search[/url]
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\Application\24.0.1312.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\Application\24.0.1312.56\pdf.dll
CHR - plugin: Babylon ToolBar (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.7_0\BabylonChromeToolBar.dll
CHR - plugin: GoogleChromeRemotePlugin (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\GoogleChromeRemotePlugin.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2210_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: ijji Auto Install Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\\npsitesafety.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: My Web Search Plugin Stub (Enabled) = C:\Program Files (x86)\MyWebSearch\bar\2.bin\NPMyWebS.dll
CHR - plugin: Google Update (Enabled) = C:\Users\dom\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - Extension: Linkury Smartbar = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\
CHR - Extension: Funmoods = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.1.3_0\
CHR - Extension: Zoomex = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bihgkpinpdipaabjllhocmhmicfnbmdl\1\
CHR - Extension: New Tab = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\7.0.19_0\
CHR - Extension: Ptasie Radio = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\gijligoemhhgfdldpnhfpbacahbjafpo\1.3_0\
CHR - Extension: SweetIM for Facebook = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0\
CHR - Extension: SweetPacks Chrome Extension = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.2_0\
CHR - Extension: Linkury Smartbar = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\
CHR - Extension: Funmoods = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.1.3_0\
CHR - Extension: Zoomex = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bihgkpinpdipaabjllhocmhmicfnbmdl\1\
CHR - Extension: New Tab = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\7.0.19_0\
CHR - Extension: Ptasie Radio = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\gijligoemhhgfdldpnhfpbacahbjafpo\1.3_0\
CHR - Extension: SweetIM for Facebook = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0\
CHR - Extension: SweetPacks Chrome Extension = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.2_0\

O1 HOSTS File: ([2009-06-10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:[b]64bit:[/b] - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:[b]64bit:[/b] - BHO: (UrlHelper Class) - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll (iMesh, Inc)
O2:[b]64bit:[/b] - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (MediaBar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\ToolBar\imeshdtxmltbpi.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (UrlHelper Class) - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\IEBHO.dll (iMesh, Inc)
O2 - BHO: (Zoomex) - {67BF155D-7896-43A3-1C8B-B3F619E820B1} - C:\ProgramData\Zoomex\50fd51e662695.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (MediaBar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\ToolBar\imeshdtxmltbpi.dll ()
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000..\Run: [ccleaner] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8:[b]64bit:[/b] - Extra context menu item: &Search - Reg Error: Value error. File not found
O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9:[b]64bit:[/b] - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9:[b]64bit:[/b] - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} [url="http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab"]http://java.sun.com/...indows-i586.cab[/url] (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{81022E93-1FC7-4565-916F-AB4D30895698}: NameServer = 62.179.1.62
O18:[b]64bit:[/b] - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:[b]64bit:[/b] - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:[b]64bit:[/b] - AppInit_DLLs: (C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\datamngr.dll) - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\datamngr.dll (iMesh, Inc)
O20:[b]64bit:[/b] - AppInit_DLLs: (C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll) - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll (iMesh, Inc)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\23787~1.43\{16cdf~1\browse~1.dll) - File not found
O20 - AppInit_DLLs: (c:\progra~3\browse~1\22643~1.41\{16cdf~1\browse~1.dll) - File not found
O20 - AppInit_DLLs: (c:\progra~2\zoomex\sprote~1.dll) - File not found
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (C:\PROGRA~3\Fh59IZN.bat) - C:\ProgramData\Fh59IZN.bat ()
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{11978c38-5a30-11e1-bd8e-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{11978c38-5a30-11e1-bd8e-806e6f6e6963}\Shell\AutoRun\command - "" = H:\autorun.exe -auto
O33 - MountPoints2\{1d900ee7-38cc-11e2-8536-e0cb4ec21d40}\Shell - "" = AutoRun
O33 - MountPoints2\{1d900ee7-38cc-11e2-8536-e0cb4ec21d40}\Shell\AutoRun\command - "" = G:\_AUTORUN\AUTORUN.EXE
O33 - MountPoints2\{9f2043ef-61a8-11df-beca-e0cb4ec21d40}\Shell - "" = AutoRun
O33 - MountPoints2\{9f2043ef-61a8-11df-beca-e0cb4ec21d40}\Shell\AutoRun\command - "" = G:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (autocheck C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2013-03-16 19:57:00 | 000,000,000 | ---D | C] -- C:\Users\dom\Desktop\Nowy folder
[2013-03-16 18:12:10 | 000,000,000 | ---D | C] -- C:\Users\dom\AppData\Roaming\Malwarebytes
[2013-03-16 18:12:03 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013-03-16 18:12:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013-03-16 18:12:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013-03-16 18:12:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013-03-16 18:11:50 | 000,000,000 | ---D | C] -- C:\Users\dom\AppData\Local\Programs
[2013-03-16 15:40:45 | 000,187,464 | ---- | C] (Webroot) -- C:\Users\dom\Documents\antizeroaccess.exe
[2013-03-16 15:31:10 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2013-03-16 15:31:10 | 000,000,000 | ---D | C] -- C:\rsit
[2013-03-16 15:12:42 | 000,688,992 | R--- | C] (Swearware) -- C:\Users\dom\Desktop\dds.com
[2013-03-16 14:41:27 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\dom\Desktop\OTL.exe
[2013-03-15 14:38:52 | 000,000,000 | ---D | C] -- C:\Users\dom\AppData\Local\Torch
[2013-03-15 14:38:40 | 001,159,144 | ---- | C] (Torch Media Inc.) -- C:\Users\dom\Desktop\TorchSetup.exe
[2013-03-14 22:18:32 | 000,000,000 | ---D | C] -- C:\Users\dom\Desktop\Windołsałkę ;-;
[2013-03-12 14:56:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2013-03-12 14:12:44 | 021,328,680 | ---- | C] (Mozilla) -- C:\Users\dom\Desktop\Firefox Setup 19.0.2.exe
[2013-03-09 06:45:29 | 000,288,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013-03-09 06:45:26 | 005,553,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2013-03-09 06:45:25 | 003,967,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2013-03-09 06:45:25 | 003,913,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2013-03-07 18:22:33 | 000,000,000 | ---D | C] -- C:\Users\dom\AppData\Local\PMB Files
[2013-03-07 18:22:31 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2013-03-07 18:22:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
[2013-03-07 18:21:51 | 000,000,000 | ---D | C] -- C:\Users\dom\.swt
[2011-12-15 09:21:43 | 002,161,160 | ---- | C] (DownVision ) -- C:\Users\dom\AppData\Local\setup.exe
[2011-06-03 15:44:52 | 029,451,264 | ---- | C] (Take-Two Interactive Software, Inc.) -- C:\Users\dom\Borderlands.exe
[2011-06-03 15:44:52 | 000,121,984 | ---- | C] (Valve Corporation) -- C:\Users\dom\steam_api.dll

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2013-03-16 20:22:48 | 005,242,880 | ---- | M] () -- C:\Users\dom\ntuser.dat
[2013-03-16 20:09:59 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2013-03-16 20:09:49 | 000,305,704 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013-03-16 20:09:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013-03-16 20:09:17 | 3220,480,000 | -HS- | M] () -- C:\hiberfil.sys
[2013-03-16 19:54:11 | 000,068,224 | ---- | M] () -- C:\Users\dom\AppData\Local\GDIPFONTCACHEV1.DAT
[2013-03-16 19:44:30 | 000,019,520 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013-03-16 19:44:29 | 000,019,520 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013-03-16 19:42:44 | 000,000,358 | -H-- | M] () -- C:\Windows\tasks\ZoomExUpdaterTask{DAED68F5-436B-4787-8ECB-67A74F866FE0}.job
[2013-03-16 19:42:44 | 000,000,280 | ---- | M] () -- C:\Windows\tasks\RMAutoUpdate.job
[2013-03-16 19:37:16 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2013-03-16 18:12:03 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013-03-16 18:08:24 | 000,430,184 | ---- | M] () -- C:\Users\dom\Documents\Malwarebytes-AntiMalware(13117).exe
[2013-03-16 15:40:45 | 000,187,464 | ---- | M] (Webroot) -- C:\Users\dom\Documents\antizeroaccess.exe
[2013-03-16 15:16:42 | 000,935,175 | ---- | M] () -- C:\Users\dom\Desktop\RSITx64.exe
[2013-03-16 15:12:42 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\dom\Desktop\dds.com
[2013-03-16 15:10:44 | 000,377,856 | ---- | M] () -- C:\Users\dom\Desktop\gmer.exe
[2013-03-16 14:41:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\dom\Desktop\OTL.exe
[2013-03-15 14:38:40 | 001,159,144 | ---- | M] (Torch Media Inc.) -- C:\Users\dom\Desktop\TorchSetup.exe
[2013-03-14 06:27:33 | 000,755,448 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat
[2013-03-14 06:27:33 | 000,668,018 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013-03-14 06:27:33 | 000,163,964 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat
[2013-03-14 06:27:33 | 000,127,950 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013-03-14 06:27:33 | 000,006,610 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013-03-13 20:34:38 | 000,282,014 | ---- | M] () -- C:\Users\dom\Desktop\quadełę.jpg
[2013-03-12 14:56:18 | 000,001,147 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013-03-12 14:12:57 | 021,328,680 | ---- | M] (Mozilla) -- C:\Users\dom\Desktop\Firefox Setup 19.0.2.exe
[2013-03-07 19:08:01 | 000,000,280 | ---- | M] () -- C:\Windows\tasks\RMSchedule.job
[2013-03-07 18:21:40 | 003,510,632 | ---- | M] () -- C:\Users\dom\Desktop\LeagueofLegends.exe

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2013-03-16 20:09:31 | 000,305,704 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013-03-16 19:54:11 | 000,068,224 | ---- | C] () -- C:\Users\dom\AppData\Local\GDIPFONTCACHEV1.DAT
[2013-03-16 18:12:03 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013-03-16 18:08:24 | 000,430,184 | ---- | C] () -- C:\Users\dom\Documents\Malwarebytes-AntiMalware(13117).exe
[2013-03-16 15:16:42 | 000,935,175 | ---- | C] () -- C:\Users\dom\Desktop\RSITx64.exe
[2013-03-16 15:10:44 | 000,377,856 | ---- | C] () -- C:\Users\dom\Desktop\gmer.exe
[2013-03-13 20:34:34 | 000,282,014 | ---- | C] () -- C:\Users\dom\Desktop\quadełę.jpg
[2013-03-12 14:56:18 | 000,001,159 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013-03-12 14:56:18 | 000,001,147 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013-03-07 18:21:39 | 003,510,632 | ---- | C] () -- C:\Users\dom\Desktop\LeagueofLegends.exe
[2013-02-06 20:53:18 | 000,003,150 | ---- | C] () -- C:\ProgramData\RWvESYd.js
[2013-02-06 20:53:18 | 000,000,153 | ---- | C] () -- C:\ProgramData\RWvESYd.reg
[2013-02-06 20:53:18 | 000,000,077 | ---- | C] () -- C:\ProgramData\RWvESYd.bat
[2013-02-06 20:40:54 | 000,003,149 | ---- | C] () -- C:\ProgramData\Fh59IZN.js
[2013-02-06 20:40:54 | 000,000,153 | ---- | C] () -- C:\ProgramData\Fh59IZN.reg
[2013-02-06 20:40:54 | 000,000,077 | ---- | C] () -- C:\ProgramData\Fh59IZN.bat
[2013-01-29 19:27:14 | 000,000,008 | ---- | C] () -- C:\Windows\313231.INI
[2013-01-26 01:14:46 | 000,524,288 | -HS- | C] () -- C:\Users\dom\ntuser.dat{5705bf44-6743-11e2-8a2b-e0cb4ec21d40}.TMContainer00000000000000000002.regtrans-ms
[2013-01-26 01:14:46 | 000,524,288 | -HS- | C] () -- C:\Users\dom\ntuser.dat{5705bf44-6743-11e2-8a2b-e0cb4ec21d40}.TMContainer00000000000000000001.regtrans-ms
[2013-01-26 01:14:46 | 000,065,536 | -HS- | C] () -- C:\Users\dom\ntuser.dat{5705bf44-6743-11e2-8a2b-e0cb4ec21d40}.TM.blf
[2012-11-15 21:20:14 | 000,000,741 | ---- | C] () -- C:\Users\dom\.recently-used.xbel
[2012-11-09 18:26:58 | 004,792,320 | ---- | C] () -- C:\Users\dom\ntuser.dat.iobit
[2012-11-07 21:59:00 | 005,242,880 | ---- | C] () -- C:\Users\dom\ntuser.dat
[2012-08-17 19:07:54 | 000,384,835 | ---- | C] () -- C:\Users\dom\AppData\Local\speeddial.crx
[2012-07-04 06:34:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012-07-04 06:34:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012-04-18 18:39:10 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012-03-16 14:42:18 | 000,524,288 | -HS- | C] () -- C:\Users\dom\ntuser.dat{bc2529e7-6f6d-11e1-87da-e0cb4ec21d40}.TMContainer00000000000000000002.regtrans-ms
[2012-03-16 14:42:18 | 000,524,288 | -HS- | C] () -- C:\Users\dom\ntuser.dat{bc2529e7-6f6d-11e1-87da-e0cb4ec21d40}.TMContainer00000000000000000001.regtrans-ms
[2012-03-16 14:42:18 | 000,065,536 | -HS- | C] () -- C:\Users\dom\ntuser.dat{bc2529e7-6f6d-11e1-87da-e0cb4ec21d40}.TM.blf
[2012-01-01 14:00:23 | 000,098,304 | ---- | C] () -- C:\Windows\SysWow64\redmonnt.dll
[2011-12-15 09:21:32 | 000,460,624 | ---- | C] () -- C:\Users\dom\AppData\Local\promo.exe
[2011-09-28 16:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011-09-12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011-07-09 21:21:59 | 000,000,026 | ---- | C] () -- C:\Windows\NeoSetup.INI
[2011-06-03 15:44:52 | 000,198,144 | ---- | C] () -- C:\Users\dom\rld.dll
[2011-06-03 15:44:52 | 000,037,752 | ---- | C] () -- C:\Users\dom\SetupHelper.exe
[2011-04-09 15:53:01 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat
[2011-04-01 04:07:02 | 010,877,272 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2011-04-01 04:07:02 | 000,102,744 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011-04-01 04:06:56 | 000,331,608 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2010-08-25 11:30:35 | 000,007,603 | ---- | C] () -- C:\Users\dom\AppData\Local\Resmon.ResmonCfg
[2010-08-09 16:25:09 | 000,000,091 | ---- | C] () -- C:\Users\dom\AppData\Local\fusioncache.dat
[2010-05-14 19:29:45 | 000,046,080 | ---- | C] () -- C:\Users\dom\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-05-07 11:54:54 | 000,524,288 | -HS- | C] () -- C:\Users\dom\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010-05-07 11:54:54 | 000,524,288 | -HS- | C] () -- C:\Users\dom\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010-05-07 11:54:54 | 000,065,536 | -HS- | C] () -- C:\Users\dom\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010-05-07 11:54:54 | 000,000,020 | -HS- | C] () -- C:\Users\dom\ntuser.ini

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012-06-09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== LOP Check ==========[/color]

[2012-07-07 09:24:17 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\.minecraft
[2013-01-21 15:20:06 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\.mono
[2013-01-21 20:02:00 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\.spoutcraft
[2012-02-18 16:24:38 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\AVG2012
[2011-12-15 14:07:08 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Babylon
[2013-03-15 19:16:59 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\BitTorrent
[2013-03-06 21:59:25 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Condusiv_Technologies
[2013-03-15 14:19:08 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\DAEMON Tools Lite
[2013-03-06 21:59:25 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Downloaded Installations
[2012-12-16 22:15:59 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Funmoods
[2013-03-06 21:59:25 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\FunnyGames
[2013-03-06 21:59:25 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Gadu-Gadu 10
[2013-03-06 21:59:25 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\GG
[2013-03-06 21:59:26 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\ijjigame
[2013-01-21 19:55:53 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\inkscape
[2012-11-15 20:12:55 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\IObit
[2010-09-01 19:46:20 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\LolClient
[2012-05-17 07:57:38 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\LolClient2
[2010-05-10 21:12:52 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Nowe Gadu-Gadu
[2012-11-27 19:59:23 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\OpenCandy
[2010-05-10 21:50:30 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\OpenFM
[2012-09-16 16:21:05 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Opera
[2012-03-08 20:29:05 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Origin
[2012-12-16 22:16:00 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\PDFCreatorPackages
[2013-03-07 18:12:51 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\RenPy
[2013-01-25 10:35:49 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\SplitMediaLabs
[2011-12-30 22:20:53 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Stykz
[2011-12-30 22:18:00 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Stykz Help
[2011-02-27 14:08:52 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\The Creative Assembly
[2010-08-24 19:55:02 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Touchstone
[2012-11-15 16:46:08 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\TS3Client
[2012-11-27 19:59:58 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\TuneUp Software
[2012-07-02 19:36:06 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Tunngle
[2010-08-09 11:21:59 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\W
[2010-08-09 10:44:45 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\wargaming.net

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 824041 bytes -> C:\Windows\Temp:temp
@Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:D1B5B4F1

< End of report >
Warto jeszcze wspomnieć, że nie działają te "zaawansowane" funkcje. Sam program może się otworzyć ale funkcje w nim zawarte nie działają np. w odkurzaczu albo ccleanerze, sam program się otwiera ale nie reaguje gdy chcę go użyć do skanowania.

Użytkownik pawel315 edytował ten post 16 03 2013 - 21:46
ogarnąłem temat

  • 0

#2 pawel315

pawel315

    Uzależniony od forum

  • 1 553 postów

Napisano 16 03 2013 - 21:56

Witaj.
Słynny UKASH gości dlaczego nie powiedziałeś o tym ? ( widzę jego pliki :) )
Odinstaluj:
Wszystko co ma w nazwie toolbar
MediaBar
Pandoo Media Booster
Uruchom OTL w okienku Własne opcje skanowania/skrypt wklej:
:OTL
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\datamngr.dll) - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\datamngr.dll (iMesh, Inc)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll) - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll (iMesh, Inc)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\23787~1.43\{16cdf~1\browse~1.dll) - File not found
O20 - AppInit_DLLs: (c:\progra~3\browse~1\22643~1.41\{16cdf~1\browse~1.dll) - File not found
O20 - AppInit_DLLs: (c:\progra~2\zoomex\sprote~1.dll) - File not found
O20 - HKLM Winlogon: Shell - (C:\PROGRA~3\Fh59IZN.bat) - C:\ProgramData\Fh59IZN.bat ()

:Files
C:\ProgramData\RWvESYd.js
C:\ProgramData\RWvESYd.reg
C:\ProgramData\RWvESYd.bat
C:\ProgramData\Fh59IZN.js
C:\ProgramData\Fh59IZN.reg
C:\ProgramData\Fh59IZN.bat
C:\Windows\313231.INI
C:\Users\dom\AppData\Local\promo.exe

:Commands
[emptytemp]





Kliknij Wykonaj skrypt daj log z usuwania.
Następnie:
  • Daj nowe logi z OTL'a (dwa logi, zaznacz opcje "Rejestr skan dodatkowy" na użyj filtrowania)


  • 0

#3 Sup Sis feggit meggit xoxo

Sup Sis feggit meggit xoxo

    Początkujący

  • 11 postów

Napisano 16 03 2013 - 23:08

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\datamngr.dll deleted successfully.
C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\datamngr.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll deleted successfully.
C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~3\browse~1\23787~1.43\{16cdf~1\browse~1.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~3\browse~1\22643~1.41\{16cdf~1\browse~1.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~2\zoomex\sprote~1.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\PROGRA~3\Fh59IZN.bat deleted successfully.
C:\ProgramData\Fh59IZN.bat moved successfully.
========== FILES ==========
C:\ProgramData\RWvESYd.js moved successfully.
C:\ProgramData\RWvESYd.reg moved successfully.
C:\ProgramData\RWvESYd.bat moved successfully.
C:\ProgramData\Fh59IZN.js moved successfully.
C:\ProgramData\Fh59IZN.reg moved successfully.
File\Folder C:\ProgramData\Fh59IZN.bat not found.
C:\Windows\313231.INI moved successfully.
File\Folder C:\Users\dom\AppData\Local\promo.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: AppData

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: dom
->Temp folder emptied: 1577475809 bytes
->Temporary Internet Files folder emptied: 1599694 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 12275304 bytes
->Google Chrome cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Opera cache emptied: 50106191 bytes
->Flash cache emptied: 5020 bytes

User: League of Legends

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2983772 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33928 bytes
RecycleBin emptied: 632960908 bytes

Total Files Cleaned = 2 172,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 03162013_213449

Files\Folders moved on Reboot...
C:\Users\dom\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Miałem wirusa "cyberprzestępczość department", ale po prostu odznaczyłem go z autostartu D: nie było to chyba najmadrzejsze rozwiązanie. Co do obecnej sytuacji to nadal jest kiszka plik tekstowy notatnika nie chce mi się nawet uruchomić (co prawda opera poszła, ale kilka razy już tak było, że da się włączyć operę tylko raz i jeżeli ją wyłącze to już nie uruchomie ponownie).

Plik tekstowy z tymi logami " nie odpowiada" wkleiłem zanim to się stało rzecz jasna. Reszta programów też nie chce się uruchomić. Mogę przykładowo wejść w mój komputer, co prawda nigdy nie pokaże mi zawartości czyli : dysk c, dysk d, dysk e. Ale mogę normalnie wejść w te zakładki po lewej. Nie wiem co mogę jeszcze dodać do opisu.

Skanuję jeszcze raz OTLem, zaraz wkleję logi.



W trybie awaryjnym wyszukiwarka plików nie znajduje wszystkich plików, które znajduje w normalnym trybie. W normalnym trybie nawet OTL nie chciał się włączyć, uruchomiłem kompa w awaryjnym, a oto logi.


OTL logfile created on: 2013-03-16 22:15:04 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\dom\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

4,00 Gb Total Physical Memory | 2,55 Gb Available Physical Memory | 63,66% Memory free
8,00 Gb Paging File | 6,55 Gb Available in Paging File | 81,97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 195,21 Gb Total Space | 26,11 Gb Free Space | 13,38% Space Free | Partition Type: NTFS
Drive D: | 146,39 Gb Total Space | 146,28 Gb Free Space | 99,92% Space Free | Partition Type: NTFS
Drive E: | 121,09 Gb Total Space | 120,99 Gb Free Space | 99,92% Space Free | Partition Type: NTFS

Computer Name: DOM-KOMPUTER | User Name: dom | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 14 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2013-03-16 14:41:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\dom\Desktop\OTL.exe
PRC - [2013-02-10 15:44:12 | 000,879,456 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\opera.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2013-01-09 19:53:19 | 014,586,888 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2012-07-04 07:20:54 | 000,238,080 | ---- | M] (AMD) [Disabled | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:[b]64bit:[/b] - [2010-08-12 14:32:42 | 000,551,896 | ---- | M] (Protection Technology) [Disabled | Stopped] -- C:\Windows\SysNative\appdrvrem01.exe -- (appdrvrem01)
SRV - [2013-03-07 15:29:15 | 000,115,608 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013-01-29 16:58:21 | 000,541,608 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012-12-14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012-12-14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012-10-02 12:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Disabled | Stopped] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012-08-21 14:43:58 | 000,794,272 | ---- | M] (PC Tools) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2012-08-13 02:24:48 | 005,167,736 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2012-07-26 21:17:03 | 000,076,888 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012-06-27 11:29:24 | 002,369,960 | ---- | M] (LogMeIn Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2012-02-14 03:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011-04-01 04:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2010-06-15 16:19:03 | 003,583,592 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2012-12-14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:[b]64bit:[/b] - [2012-11-27 20:00:20 | 000,564,824 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:[b]64bit:[/b] - [2012-11-07 22:09:19 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2012-11-07 22:09:18 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2012-09-04 12:34:14 | 000,031,080 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:[b]64bit:[/b] - [2012-08-24 14:43:16 | 000,384,352 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:[b]64bit:[/b] - [2012-07-26 02:21:28 | 000,291,680 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:[b]64bit:[/b] - [2012-07-09 14:54:58 | 000,106,832 | ---- | M] (Condusiv Technologies) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\DKTLFSMF.sys -- (DKTLFSMF)
DRV:[b]64bit:[/b] - [2012-07-04 07:59:32 | 011,922,944 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:[b]64bit:[/b] - [2012-07-04 07:59:32 | 011,922,944 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:[b]64bit:[/b] - [2012-07-04 06:10:56 | 000,359,936 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:[b]64bit:[/b] - [2012-06-18 19:14:34 | 000,052,048 | ---- | M] (Condusiv Technologies) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\DKRtWrt.sys -- (DKRtWrt)
DRV:[b]64bit:[/b] - [2012-04-19 03:50:26 | 000,028,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:[b]64bit:[/b] - [2012-04-05 02:32:54 | 000,040,752 | ---- | M] (Condusiv Technologies) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\DKDFM.sys -- (DKDFM)
DRV:[b]64bit:[/b] - [2012-03-01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2012-02-23 13:32:04 | 000,095,760 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:[b]64bit:[/b] - [2012-01-31 03:46:48 | 000,036,944 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:[b]64bit:[/b] - [2011-12-23 12:32:14 | 000,047,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:[b]64bit:[/b] - [2011-12-23 12:32:04 | 000,029,776 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avgidsfiltera.sys -- (AVGIDSFilter)
DRV:[b]64bit:[/b] - [2011-12-23 12:31:58 | 000,124,496 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:[b]64bit:[/b] - [2011-04-01 04:07:54 | 004,184,672 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:[b]64bit:[/b] - [2011-03-11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011-03-11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2010-11-20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010-08-12 14:32:43 | 002,715,824 | ---- | M] (Protection Technology) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\appdrv01.sys -- (appdrv01)
DRV:[b]64bit:[/b] - [2010-03-09 11:21:42 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:[b]64bit:[/b] - [2009-08-17 12:20:46 | 001,235,968 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV:[b]64bit:[/b] - [2009-07-16 04:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:[b]64bit:[/b] - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2009-05-22 15:52:30 | 000,215,040 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2009-03-18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:[b]64bit:[/b] - [2008-04-22 07:53:36 | 000,012,744 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Entech64.sys -- (ENTECH64)
DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2005-01-02 04:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchfunmoods.com/?f=1&a=iron2&ir=iron2&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0E0CtBtC0DyEtD0DtBtA0EtN0D0Tzu0CtAyDtCtN1L2XzutBtFtBtFtCtFyEtDyB&cr=911712656
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&ir=iron2&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0E0CtBtC0DyEtD0DtBtA0EtN0D0Tzu0CtAyDtCtN1L2XzutBtFtBtFtCtFyEtDyB&cr=911712656
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}: "URL" = http://www.searchya.com/?q={searchTerms}&s=1&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0E0CtBtC0DyEtD0DtBtA0EtN0D0Tzu0CtBtAtDtN1L2XzutBtFtCtFtCtFtAtCtB&cr=2048707667
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://search.babylon.com/?affID=110809&tt=bandext_3312_8&babsrc=HP_ss&mntrId=44dbd23e00000000000000ffe5264df8
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://search.babylon.com/?affID=110809&tt=bandext_3312_8&babsrc=HP_ss&mntrId=44dbd23e00000000000000ffe5264df8
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://search.babylon.com/?affID=110809&tt=bandext_3312_8&babsrc=HP_ss&mntrId=44dbd23e00000000000000ffe5264df8
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = pl.v9.com/idg/idg_1342608838_220770
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=hp&babsrc=lnkry_nt
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes,Backup.Old.DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]



FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\dom\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\dom\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012-09-11 12:47:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013-03-12 14:56:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011-12-31 11:18:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dom\AppData\Roaming\mozilla\Extensions
[2012-12-16 22:15:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dom\AppData\Roaming\mozilla\Firefox\Profiles\afss4h8w.default\extensions
[2012-12-16 22:15:50 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Users\dom\AppData\Roaming\mozilla\Firefox\Profiles\afss4h8w.default\extensions\ffxtlbr@funmoods.com
[2012-08-17 19:07:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dom\AppData\Roaming\mozilla\Firefox\Profiles\afss4h8w.default\extensions\staged
[2012-02-05 14:46:21 | 000,000,000 | ---D | M] (@@toolbarname@@) -- C:\Users\dom\AppData\Roaming\mozilla\Firefox\Profiles\afss4h8w.default\extensions\toolbar@ask.com
[2012-12-16 22:15:49 | 000,000,777 | ---- | M] () -- C:\Users\dom\AppData\Roaming\mozilla\firefox\profiles\afss4h8w.default\searchplugins\Funmoods.xml
[2012-08-17 19:07:49 | 000,000,777 | ---- | M] () -- C:\Users\dom\AppData\Roaming\mozilla\firefox\profiles\afss4h8w.default\searchplugins\Search.xml
[2013-03-12 14:56:06 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012-11-01 22:49:00 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013-03-07 15:30:04 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013-03-07 17:48:47 | 000,002,980 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml
[2013-03-07 17:48:47 | 000,001,619 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml
[2013-03-07 17:48:47 | 000,001,130 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml
[2013-03-07 17:48:47 | 000,001,071 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml
[2013-03-07 17:48:47 | 000,001,396 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml
[2013-03-07 17:48:47 | 000,001,896 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml

[color=#E56717]========== Chrome ==========[/color]

CHR - homepage: http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=hp&babsrc=lnkry
CHR - default_search_provider: Web (Enabled)
CHR - default_search_provider: search_url = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=hp&babsrc=lnkry
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\Application\24.0.1312.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\Application\24.0.1312.56\pdf.dll
CHR - plugin: Babylon ToolBar (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.7_0\BabylonChromeToolBar.dll
CHR - plugin: GoogleChromeRemotePlugin (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\GoogleChromeRemotePlugin.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2210_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: ijji Auto Install Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\\npsitesafety.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: My Web Search Plugin Stub (Enabled) = C:\Program Files (x86)\MyWebSearch\bar\2.bin\NPMyWebS.dll
CHR - plugin: Google Update (Enabled) = C:\Users\dom\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - Extension: Linkury Smartbar = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\
CHR - Extension: Funmoods = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.1.3_0\
CHR - Extension: Zoomex = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bihgkpinpdipaabjllhocmhmicfnbmdl\1\
CHR - Extension: New Tab = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\7.0.19_0\
CHR - Extension: Ptasie Radio = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\gijligoemhhgfdldpnhfpbacahbjafpo\1.3_0\
CHR - Extension: SweetIM for Facebook = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0\
CHR - Extension: SweetPacks Chrome Extension = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.2_0\
CHR - Extension: Linkury Smartbar = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\
CHR - Extension: Funmoods = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.1.3_0\
CHR - Extension: Zoomex = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\bihgkpinpdipaabjllhocmhmicfnbmdl\1\
CHR - Extension: New Tab = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\7.0.19_0\
CHR - Extension: Ptasie Radio = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\gijligoemhhgfdldpnhfpbacahbjafpo\1.3_0\
CHR - Extension: SweetIM for Facebook = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0\
CHR - Extension: SweetPacks Chrome Extension = C:\Users\dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.2_0\

O1 HOSTS File: ([2009-06-10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:[b]64bit:[/b] - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:[b]64bit:[/b] - BHO: (UrlHelper Class) - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll File not found
O2:[b]64bit:[/b] - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (MediaBar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\ToolBar\imeshdtxmltbpi.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (UrlHelper Class) - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\IEBHO.dll (iMesh, Inc)
O2 - BHO: (Zoomex) - {67BF155D-7896-43A3-1C8B-B3F619E820B1} - C:\ProgramData\Zoomex\50fd51e662695.dll ()
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (MediaBar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\ToolBar\imeshdtxmltbpi.dll ()
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000..\Run: [ccleaner] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8:[b]64bit:[/b] - Extra context menu item: &Search - Reg Error: Value error. File not found
O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9:[b]64bit:[/b] - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9:[b]64bit:[/b] - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{81022E93-1FC7-4565-916F-AB4D30895698}: NameServer = 62.179.1.62
O18:[b]64bit:[/b] - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:[b]64bit:[/b] - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{11978c38-5a30-11e1-bd8e-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{11978c38-5a30-11e1-bd8e-806e6f6e6963}\Shell\AutoRun\command - "" = H:\autorun.exe -auto
O33 - MountPoints2\{1d900ee7-38cc-11e2-8536-e0cb4ec21d40}\Shell - "" = AutoRun
O33 - MountPoints2\{1d900ee7-38cc-11e2-8536-e0cb4ec21d40}\Shell\AutoRun\command - "" = G:\_AUTORUN\AUTORUN.EXE
O33 - MountPoints2\{9f2043ef-61a8-11df-beca-e0cb4ec21d40}\Shell - "" = AutoRun
O33 - MountPoints2\{9f2043ef-61a8-11df-beca-e0cb4ec21d40}\Shell\AutoRun\command - "" = G:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (autocheck C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 14 Days ==========[/color]

[2013-03-16 21:34:49 | 000,000,000 | ---D | C] -- C:\_OTL
[2013-03-16 19:57:00 | 000,000,000 | ---D | C] -- C:\Users\dom\Desktop\Nowy folder
[2013-03-16 18:12:10 | 000,000,000 | ---D | C] -- C:\Users\dom\AppData\Roaming\Malwarebytes
[2013-03-16 18:12:03 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013-03-16 18:12:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013-03-16 18:12:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013-03-16 18:12:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013-03-16 18:11:50 | 000,000,000 | ---D | C] -- C:\Users\dom\AppData\Local\Programs
[2013-03-16 15:40:45 | 000,187,464 | ---- | C] (Webroot) -- C:\Users\dom\Documents\antizeroaccess.exe
[2013-03-16 15:31:10 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2013-03-16 15:31:10 | 000,000,000 | ---D | C] -- C:\rsit
[2013-03-16 15:12:42 | 000,688,992 | R--- | C] (Swearware) -- C:\Users\dom\Desktop\dds.com
[2013-03-16 14:41:27 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\dom\Desktop\OTL.exe
[2013-03-15 14:38:52 | 000,000,000 | ---D | C] -- C:\Users\dom\AppData\Local\Torch
[2013-03-15 14:38:40 | 001,159,144 | ---- | C] (Torch Media Inc.) -- C:\Users\dom\Desktop\TorchSetup.exe
[2013-03-14 22:18:32 | 000,000,000 | ---D | C] -- C:\Users\dom\Desktop\Windołsałkę ;-;
[2013-03-12 14:56:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2013-03-12 14:12:44 | 021,328,680 | ---- | C] (Mozilla) -- C:\Users\dom\Desktop\Firefox Setup 19.0.2.exe
[2013-03-09 06:45:29 | 000,288,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013-03-09 06:45:26 | 005,553,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2013-03-09 06:45:25 | 003,967,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2013-03-09 06:45:25 | 003,913,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2013-03-07 18:22:33 | 000,000,000 | ---D | C] -- C:\Users\dom\AppData\Local\PMB Files
[2013-03-07 18:22:31 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2013-03-07 18:22:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
[2013-03-07 18:21:51 | 000,000,000 | ---D | C] -- C:\Users\dom\.swt
[2011-12-15 09:21:43 | 002,161,160 | ---- | C] (DownVision ) -- C:\Users\dom\AppData\Local\setup.exe
[2011-06-03 15:44:52 | 029,451,264 | ---- | C] (Take-Two Interactive Software, Inc.) -- C:\Users\dom\Borderlands.exe
[2011-06-03 15:44:52 | 000,121,984 | ---- | C] (Valve Corporation) -- C:\Users\dom\steam_api.dll

[color=#E56717]========== Files - Modified Within 14 Days ==========[/color]

[2013-03-16 22:12:43 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2013-03-16 22:12:38 | 000,305,704 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013-03-16 22:12:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013-03-16 22:12:07 | 3220,480,000 | -HS- | M] () -- C:\hiberfil.sys
[2013-03-16 21:55:27 | 000,000,358 | -H-- | M] () -- C:\Windows\tasks\ZoomExUpdaterTask{DAED68F5-436B-4787-8ECB-67A74F866FE0}.job
[2013-03-16 21:55:27 | 000,000,280 | ---- | M] () -- C:\Windows\tasks\RMAutoUpdate.job
[2013-03-16 19:44:30 | 000,019,520 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013-03-16 19:44:29 | 000,019,520 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013-03-16 18:12:03 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013-03-16 18:08:24 | 000,430,184 | ---- | M] () -- C:\Users\dom\Documents\Malwarebytes-AntiMalware(13117).exe
[2013-03-16 15:40:45 | 000,187,464 | ---- | M] (Webroot) -- C:\Users\dom\Documents\antizeroaccess.exe
[2013-03-16 15:16:42 | 000,935,175 | ---- | M] () -- C:\Users\dom\Desktop\RSITx64.exe
[2013-03-16 15:12:42 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\dom\Desktop\dds.com
[2013-03-16 15:10:44 | 000,377,856 | ---- | M] () -- C:\Users\dom\Desktop\gmer.exe
[2013-03-16 14:41:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\dom\Desktop\OTL.exe
[2013-03-15 14:38:40 | 001,159,144 | ---- | M] (Torch Media Inc.) -- C:\Users\dom\Desktop\TorchSetup.exe
[2013-03-14 06:27:33 | 000,755,448 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat
[2013-03-14 06:27:33 | 000,668,018 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013-03-14 06:27:33 | 000,163,964 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat
[2013-03-14 06:27:33 | 000,127,950 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013-03-14 06:27:33 | 000,006,610 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013-03-13 20:34:38 | 000,282,014 | ---- | M] () -- C:\Users\dom\Desktop\quadełę.jpg
[2013-03-12 14:56:18 | 000,001,147 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013-03-12 14:12:57 | 021,328,680 | ---- | M] (Mozilla) -- C:\Users\dom\Desktop\Firefox Setup 19.0.2.exe
[2013-03-07 19:08:01 | 000,000,280 | ---- | M] () -- C:\Windows\tasks\RMSchedule.job
[2013-03-07 18:21:40 | 003,510,632 | ---- | M] () -- C:\Users\dom\Desktop\LeagueofLegends.exe

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2013-03-16 22:12:17 | 000,305,704 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013-03-16 18:12:03 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013-03-16 18:08:24 | 000,430,184 | ---- | C] () -- C:\Users\dom\Documents\Malwarebytes-AntiMalware(13117).exe
[2013-03-16 15:16:42 | 000,935,175 | ---- | C] () -- C:\Users\dom\Desktop\RSITx64.exe
[2013-03-16 15:10:44 | 000,377,856 | ---- | C] () -- C:\Users\dom\Desktop\gmer.exe
[2013-03-13 20:34:34 | 000,282,014 | ---- | C] () -- C:\Users\dom\Desktop\quadełę.jpg
[2013-03-12 14:56:18 | 000,001,159 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013-03-12 14:56:18 | 000,001,147 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013-03-07 18:21:39 | 003,510,632 | ---- | C] () -- C:\Users\dom\Desktop\LeagueofLegends.exe
[2012-11-15 21:20:14 | 000,000,741 | ---- | C] () -- C:\Users\dom\.recently-used.xbel
[2012-08-17 19:07:54 | 000,384,835 | ---- | C] () -- C:\Users\dom\AppData\Local\speeddial.crx
[2012-07-04 06:34:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012-07-04 06:34:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012-04-18 18:39:10 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012-01-01 14:00:23 | 000,098,304 | ---- | C] () -- C:\Windows\SysWow64\redmonnt.dll
[2011-09-28 16:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011-09-12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011-07-09 21:21:59 | 000,000,026 | ---- | C] () -- C:\Windows\NeoSetup.INI
[2011-06-03 15:44:52 | 000,198,144 | ---- | C] () -- C:\Users\dom\rld.dll
[2011-06-03 15:44:52 | 000,037,752 | ---- | C] () -- C:\Users\dom\SetupHelper.exe
[2011-04-09 15:53:01 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat
[2011-04-01 04:07:02 | 010,877,272 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2011-04-01 04:07:02 | 000,102,744 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011-04-01 04:06:56 | 000,331,608 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2010-08-25 11:30:35 | 000,007,603 | ---- | C] () -- C:\Users\dom\AppData\Local\Resmon.ResmonCfg
[2010-08-09 16:25:09 | 000,000,091 | ---- | C] () -- C:\Users\dom\AppData\Local\fusioncache.dat
[2010-05-14 19:29:45 | 000,046,080 | ---- | C] () -- C:\Users\dom\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012-06-09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== LOP Check ==========[/color]

[2012-07-07 09:24:17 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\.minecraft
[2013-01-21 15:20:06 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\.mono
[2013-01-21 20:02:00 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\.spoutcraft
[2012-02-18 16:24:38 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\AVG2012
[2011-12-15 14:07:08 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Babylon
[2013-03-15 19:16:59 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\BitTorrent
[2013-03-06 21:59:25 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Condusiv_Technologies
[2013-03-15 14:19:08 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\DAEMON Tools Lite
[2013-03-06 21:59:25 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Downloaded Installations
[2012-12-16 22:15:59 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Funmoods
[2013-03-06 21:59:25 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\FunnyGames
[2013-03-06 21:59:25 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Gadu-Gadu 10
[2013-03-06 21:59:25 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\GG
[2013-03-06 21:59:26 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\ijjigame
[2013-01-21 19:55:53 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\inkscape
[2012-11-15 20:12:55 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\IObit
[2010-09-01 19:46:20 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\LolClient
[2012-05-17 07:57:38 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\LolClient2
[2010-05-10 21:12:52 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Nowe Gadu-Gadu
[2012-11-27 19:59:23 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\OpenCandy
[2010-05-10 21:50:30 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\OpenFM
[2012-09-16 16:21:05 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Opera
[2012-03-08 20:29:05 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Origin
[2012-12-16 22:16:00 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\PDFCreatorPackages
[2013-03-07 18:12:51 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\RenPy
[2013-01-25 10:35:49 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\SplitMediaLabs
[2011-12-30 22:20:53 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Stykz
[2011-12-30 22:18:00 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Stykz Help
[2011-02-27 14:08:52 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\The Creative Assembly
[2010-08-24 19:55:02 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Touchstone
[2012-11-15 16:46:08 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\TS3Client
[2012-11-27 19:59:58 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\TuneUp Software
[2012-07-02 19:36:06 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\Tunngle
[2010-08-09 11:21:59 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\W
[2010-08-09 10:44:45 | 000,000,000 | ---D | M] -- C:\Users\dom\AppData\Roaming\wargaming.net

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 824041 bytes -> C:\Windows\Temp:temp
@Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:D1B5B4F1

< End of report >




drugi

OTL Extras logfile created on: 2013-03-16 22:15:04 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\dom\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

4,00 Gb Total Physical Memory | 2,55 Gb Available Physical Memory | 63,66% Memory free
8,00 Gb Paging File | 6,55 Gb Available in Paging File | 81,97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 195,21 Gb Total Space | 26,11 Gb Free Space | 13,38% Space Free | Partition Type: NTFS
Drive D: | 146,39 Gb Total Space | 146,28 Gb Free Space | 99,92% Space Free | Partition Type: NTFS
Drive E: | 121,09 Gb Total Space | 120,99 Gb Free Space | 99,92% Space Free | Partition Type: NTFS

Computer Name: DOM-KOMPUTER | User Name: dom | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 14 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)

[HKEY_USERS\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[color=#E56717]========== Security Center Settings ==========[/color]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 1
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 1
"EnableFirewall" = 1

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0016644C-598B-48F1-A6FF-B11BED9237F5}" = lport=6893 | protocol=17 | dir=in | name=league of legends launcher |
"{002A6323-48A5-4C9B-B273-0CCAAB0FAE94}" = lport=8393 | protocol=17 | dir=in | name=league of legends lobby |
"{078A26A0-F1F0-48CD-A66C-E45E2CFC75B9}" = lport=139 | protocol=6 | dir=in | app=system |
"{08B7686A-BBC2-4B3C-BB1F-9FE75F25F4BB}" = rport=10243 | protocol=6 | dir=out | app=system |
"{0972A2BF-E6EC-40D9-A41C-3A389E743468}" = lport=8394 | protocol=6 | dir=in | name=league of legends launcher |
"{0D9B69B6-48F0-42CA-B721-BDB5136AC154}" = lport=6910 | protocol=17 | dir=in | name=league of legends launcher |
"{1013396C-E02C-4082-85E5-00D5424B2091}" = lport=10243 | protocol=6 | dir=in | app=system |
"{10B3C0AE-83AF-412E-B6F6-CE438C939104}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{13A60FD0-A0D7-4239-811A-92379DE98E38}" = lport=6901 | protocol=6 | dir=in | name=league of legends launcher |
"{13B729E3-C942-41AD-98F0-5AF999D819A0}" = lport=8398 | protocol=17 | dir=in | name=league of legends launcher |
"{14C02A05-4256-4B64-97E1-EDFEEBD3EEA7}" = lport=6930 | protocol=17 | dir=in | name=league of legends launcher |
"{150478D0-44C4-4B40-86D3-B5093BF37F3D}" = lport=6924 | protocol=17 | dir=in | name=league of legends launcher |
"{16F6BE99-3A56-4CAA-8D70-85953245866C}" = lport=8396 | protocol=17 | dir=in | name=league of legends launcher |
"{17EB5F74-86F1-4E2A-825F-F3CF502EEAAF}" = lport=6977 | protocol=6 | dir=in | name=league of legends launcher |
"{1A2DB521-9344-4F9A-9516-D2777090F8CC}" = rport=137 | protocol=17 | dir=out | app=system |
"{292A26DB-8304-453A-8963-2F02FB4990B3}" = lport=6940 | protocol=17 | dir=in | name=league of legends launcher |
"{2B1D610F-A9F3-435D-839E-C5D03DC68063}" = lport=6940 | protocol=6 | dir=in | name=league of legends launcher |
"{2D57465A-514A-4E74-9880-401F4F636F39}" = lport=6926 | protocol=6 | dir=in | name=league of legends launcher |
"{2E0104CC-36BC-413E-9792-5985F3ABB5EE}" = lport=8394 | protocol=17 | dir=in | name=league of legends launcher |
"{2E410172-021D-4322-9506-1C64FF93F8A7}" = lport=6974 | protocol=17 | dir=in | name=league of legends launcher |
"{2F6CFA8B-474B-41A0-B8B0-2AA7E1D501B0}" = lport=6986 | protocol=6 | dir=in | name=league of legends launcher |
"{2F90C217-0A86-4FC7-8AC0-0D2B84B8609E}" = lport=6905 | protocol=6 | dir=in | name=league of legends launcher |
"{3461AE2F-8254-418D-B325-7B8D873F3A6A}" = lport=8395 | protocol=6 | dir=in | name=league of legends launcher |
"{356F1E33-DF99-4B42-A5BD-C60C5C9C9F8C}" = lport=6952 | protocol=17 | dir=in | name=league of legends launcher |
"{3767C6A6-A8F0-43B8-8EF8-4A86D2BF970C}" = lport=6900 | protocol=17 | dir=in | name=league of legends launcher |
"{3DB4848C-7B80-431F-A9A9-984B639469A9}" = lport=8395 | protocol=17 | dir=in | name=league of legends launcher |
"{3FD4D27E-38FA-4903-84E9-E6CC46040534}" = lport=6928 | protocol=17 | dir=in | name=league of legends launcher |
"{44E992C6-DF90-4014-9F32-7FFFCC016318}" = lport=6924 | protocol=6 | dir=in | name=league of legends launcher |
"{4729A298-893E-4C4B-A077-88B5DBD52461}" = lport=138 | protocol=17 | dir=in | app=system |
"{484A7171-9C25-458A-9D94-B5147FE62775}" = lport=6902 | protocol=6 | dir=in | name=league of legends launcher |
"{494E07C7-765F-4F46-A35D-40D54CFBC905}" = lport=6983 | protocol=17 | dir=in | name=league of legends launcher |
"{4992F8DE-49B8-4910-B144-BCC6A810D900}" = lport=6947 | protocol=6 | dir=in | name=league of legends launcher |
"{4C205D72-E140-4104-AA93-D6CAF0174157}" = lport=6977 | protocol=17 | dir=in | name=league of legends launcher |
"{527FD7A1-F6C1-4184-B280-50F41A11E5C7}" = lport=8397 | protocol=6 | dir=in | name=league of legends launcher |
"{5283B1BA-031C-4330-AFAA-47C6264C94B2}" = lport=8393 | protocol=6 | dir=in | name=league of legends lobby |
"{572B00EB-3FC7-498B-8B23-B5910CD58F01}" = lport=6954 | protocol=17 | dir=in | name=league of legends launcher |
"{57886E2B-98A9-45C9-90D6-888E1DC73288}" = lport=8395 | protocol=17 | dir=in | name=league of legends launcher |
"{5A22A692-E839-441A-8DFD-C095FD63AC9E}" = lport=8394 | protocol=17 | dir=in | name=league of legends launcher |
"{5AC77ED6-ED72-4ECD-87E9-3BD61846B181}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{61D2F8B1-6F46-4071-855B-7A5C2E28D27E}" = lport=6923 | protocol=6 | dir=in | name=league of legends launcher |
"{66D567D5-347A-4B2C-973E-3BC6C82B8F61}" = lport=6924 | protocol=17 | dir=in | name=league of legends launcher |
"{679EF9BE-D01A-47BE-9567-13237F4E2B5E}" = lport=6974 | protocol=6 | dir=in | name=league of legends launcher |
"{684834F8-B639-4805-8F15-497FE48E67D6}" = lport=8390 | protocol=17 | dir=in | name=league of legends game client |
"{6A273207-FC6C-4119-9243-79B568198F35}" = lport=6996 | protocol=17 | dir=in | name=league of legends launcher |
"{6ADAE1DB-B9D1-42B2-8370-70797BCF8185}" = lport=6930 | protocol=6 | dir=in | name=league of legends launcher |
"{6BD27CBD-B7B6-4882-BDC3-D8C1A5215F43}" = rport=138 | protocol=17 | dir=out | app=system |
"{6C399B8E-4EB2-45F6-9CB1-6CC011E6634B}" = lport=6952 | protocol=6 | dir=in | name=league of legends launcher |
"{7191D7BF-B715-4454-9C68-5E03CA1808B0}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{72BE62DF-F3BF-47F5-90F4-A2F8677D5CE4}" = lport=6924 | protocol=6 | dir=in | name=league of legends launcher |
"{733BC5BC-09F6-46AE-A0FB-8A37D41FD43E}" = lport=6903 | protocol=17 | dir=in | name=league of legends launcher |
"{7386C7A3-E451-4F9B-AB5C-1ABFD84684AF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{795C9229-8457-45EC-8C94-D4422F710091}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7CAB13FE-E005-40EB-9FE5-4EC6666A63A6}" = lport=6928 | protocol=6 | dir=in | name=league of legends launcher |
"{7EC6789C-6990-44D7-A07B-34FB8A29ECF1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8552FE84-FED1-4503-AF70-36A1657E4649}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{89B7C36D-0AEE-4134-866E-7E49665CC2EC}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8CE381F4-669C-4502-83E0-346E274B43DA}" = lport=6882 | protocol=6 | dir=in | name=league of legends launcher |
"{8F4E8090-0C86-4ECE-8E5E-337E1303DC77}" = lport=6893 | protocol=6 | dir=in | name=league of legends launcher |
"{8FB2AA35-D43B-4D7D-992F-02D4CE283C2A}" = lport=6893 | protocol=17 | dir=in | name=league of legends launcher |
"{92A9567A-A20F-487B-A729-DFD9EAF0841C}" = lport=6952 | protocol=6 | dir=in | name=league of legends launcher |
"{96A04C2C-16BC-4399-BE97-C3F48C607EF2}" = lport=6915 | protocol=17 | dir=in | name=league of legends launcher |
"{99C64E18-0EBD-4C44-9C37-6C0695920A6B}" = lport=6900 | protocol=6 | dir=in | name=league of legends launcher |
"{9C25DFF8-7D14-48FC-ADDA-8F5E6664C4AC}" = lport=6902 | protocol=17 | dir=in | name=league of legends launcher |
"{A6DCB6D2-E6AF-4691-87C0-7D456E0F6DC6}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{A94985D5-9825-4663-91DA-3E2955561798}" = lport=8397 | protocol=17 | dir=in | name=league of legends launcher |
"{AAF92AC4-DC35-4202-9C43-C6DD1B2E8DD1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{ABE0D138-1FE3-4D90-99C0-C016979EA498}" = lport=6952 | protocol=17 | dir=in | name=league of legends launcher |
"{AC8EBDED-A24D-4F79-A9B8-C04F50404602}" = lport=6926 | protocol=17 | dir=in | name=league of legends launcher |
"{AEF86A5C-75E3-48B4-827E-8007A81C2AE0}" = lport=6923 | protocol=17 | dir=in | name=league of legends launcher |
"{B328D4DE-C025-477A-B0B5-1769251B959E}" = lport=8395 | protocol=6 | dir=in | name=league of legends launcher |
"{BC9C65FB-5E4C-417F-BDA0-483618199CBE}" = lport=8398 | protocol=6 | dir=in | name=league of legends launcher |
"{C16A42EF-B9FE-4185-8AE2-D03851095668}" = lport=6893 | protocol=6 | dir=in | name=league of legends launcher |
"{C368AE71-5157-4990-803C-9D2BB01C247B}" = lport=6882 | protocol=17 | dir=in | name=league of legends launcher |
"{C5455B60-940E-4B2F-8A14-B9A75954685B}" = lport=6910 | protocol=6 | dir=in | name=league of legends launcher |
"{C5D6E323-0937-400F-9F62-F86412558978}" = lport=6954 | protocol=6 | dir=in | name=league of legends launcher |
"{C66EE685-2497-4FB8-92EA-EDB1C8072A07}" = lport=8394 | protocol=6 | dir=in | name=league of legends launcher |
"{CFF01348-C9BD-4CBA-B853-381F1B1838ED}" = lport=137 | protocol=17 | dir=in | app=system |
"{D063B329-6532-4115-9549-2CCAC0E6AAF9}" = lport=6915 | protocol=6 | dir=in | name=league of legends launcher |
"{D3FB9C7D-38A5-4C99-9F46-C699DFB2FDF6}" = lport=445 | protocol=6 | dir=in | app=system |
"{D72F4B3D-91CE-4E90-9992-E5C79F9309C5}" = lport=6997 | protocol=17 | dir=in | name=league of legends launcher |
"{D8799323-4966-47BD-9255-566E218A7025}" = lport=6997 | protocol=6 | dir=in | name=league of legends launcher |
"{DA42D433-5C31-461F-BCAB-643A37976158}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DA48BB8C-E563-4690-AD65-65AA531B5535}" = lport=6983 | protocol=6 | dir=in | name=league of legends launcher |
"{DC65ADDC-61C8-45CA-82B1-AF65EF3FFB04}" = lport=6903 | protocol=6 | dir=in | name=league of legends launcher |
"{DE85DC87-5222-4A52-A6F5-72353DDC001D}" = lport=8396 | protocol=17 | dir=in | name=league of legends launcher |
"{E04837F5-78AD-44D5-8BFD-396F26B1EA9E}" = lport=8390 | protocol=6 | dir=in | name=league of legends game client |
"{E2B7E077-F268-4B31-A0CB-128B365EFA91}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E4940D66-86B5-4194-97BA-99149C778EC8}" = rport=139 | protocol=6 | dir=out | app=system |
"{E600FDFC-1939-4BCB-AF67-16EA8C7940D2}" = lport=6996 | protocol=6 | dir=in | name=league of legends launcher |
"{E61E2022-3868-43BC-8F5D-B6054A0FC536}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E6B678D9-08AD-45A2-B3C4-1A3D8346EAFF}" = lport=8396 | protocol=6 | dir=in | name=league of legends launcher |
"{E6C7F695-E383-4435-A981-572408735FE0}" = rport=445 | protocol=6 | dir=out | app=system |
"{E894AF39-C4D5-41D8-BF34-E7DEEC709718}" = lport=6986 | protocol=17 | dir=in | name=league of legends launcher |
"{EA67997C-9E3D-45B4-94C9-124E9E180971}" = lport=6905 | protocol=17 | dir=in | name=league of legends launcher |
"{EAD0382D-45B8-4991-88C5-9AAF2FE1C90C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F8C2A45B-1190-4F91-9DB8-BB0B1C7923B1}" = lport=6947 | protocol=17 | dir=in | name=league of legends launcher |
"{F92BD74F-9B61-413A-AF4F-1517931D96F2}" = lport=6901 | protocol=17 | dir=in | name=league of legends launcher |
"{FB0A153C-19A9-4C17-B04E-BA2CE3DD30EC}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{FD81DC8A-5651-452A-83E1-321613E7ACDD}" = lport=8396 | protocol=6 | dir=in | name=league of legends launcher |

[color=#E56717]========== Vista Active Application Exception List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{011656CC-ED98-414F-8AF7-4665E0214F1D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{023B74D9-7BC5-4031-92B3-4D7E6F655ECC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{02C1B1F8-6EA2-4686-8293-D7E943AB1031}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{034C1C1C-B1D1-4512-AFE1-81170858B973}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{03AE044B-1643-4F1A-B15D-215D2C075773}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\medal of honor mp beta\mohmpupdater.exe |
"{04F4625F-376D-4AE7-B0F3-54100D72D7CE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{053594A8-5598-490D-A343-EF8CB54AE233}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{06143286-95A8-4FD3-B2D4-3D94DAEC21E9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{08D86548-BD7E-410D-9DC4-35E98A8210D6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{08E5A64B-41F1-4C1F-BD5F-294DAAD0E808}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0A6493DA-EA5A-475C-ADA8-1DC456D1DCEA}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{0AD54D5B-5FA6-4F03-ABD2-1487EB0030AA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0C92563A-7070-48AC-BDBB-5459FDBCB4AA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0CF30A13-DE2A-47E9-B28C-A218FF65EB64}" = protocol=6 | dir=in | app=c:\program files (x86)\mass effect\binaries\masseffect.exe |
"{0D2F8350-C3D9-488A-B9B7-937C9C144AED}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0D808DF2-A3C1-4BA4-A4B4-26D4B532EA31}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0E2EDDAB-72A4-4113-9025-3C0F2DF8DF68}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0E640703-A292-4683-8CC1-7BCD0F2FA400}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{10EFA1CF-6413-46C9-B089-178BB8454DD8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1163CC89-5D85-4D55-99DE-DBF888C21930}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{131CCEF4-27C5-42A5-A06D-8D948A657679}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1405C4CF-6545-4ED2-A277-83DC91605569}" = protocol=6 | dir=out | app=system |
"{160B7FE3-E19C-49AC-AFA6-86AE2BB29C06}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires online\spartan.exe |
"{16669756-71F4-44C2-9373-21014B98C1FF}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{182B0D8B-6403-4BB9-A3FD-B00976FE1131}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe |
"{196BE7D1-5C6A-4832-8644-84971E6F2149}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysisdedicatedserver.exe |
"{19D62088-B165-41E7-9EE1-0E5F51B0F3F2}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{19DA945B-B6F6-4DCC-8434-E10D23F46381}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{19E2E7E9-BF59-497B-B0ED-1A22B109946D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1A003D7A-FB75-47E3-BBCC-3944AA0242C8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1A1F7D91-247A-4726-B3A2-BD227050EF80}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysis.exe |
"{1B19D297-C2FF-474A-9D3C-65A233369FDC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1B73272F-5778-4208-B024-8B1FFAB6D39C}" = protocol=17 | dir=in | app=c:\program files (x86)\mass effect\binaries\masseffect.exe |
"{1D182A2A-B12F-4E2F-B942-415730B857D4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1D2ADF33-0D18-4383-BFB5-E318627683B9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1D8B5ECD-E925-49EE-B4F1-9DA932C24C57}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1DC3D5B5-A79A-45EB-9D38-368588F4F0D9}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{1EB15823-9808-49B6-B73E-EC8EB2D7A690}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1EE42463-AFD0-4D70-B894-93F4B593F8D2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1F394EA0-AFA5-4C32-9FD3-94607B3B8BD4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1FCABE3B-6A7E-4ECB-88D9-5CA6FEA76A86}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1FD86A3E-8879-4B36-BA97-E2C8BF1C1BCA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{226F44AE-1DB8-416B-8803-C12D264686CD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{228C8721-3AA9-4EED-8B67-643C3AF40E0E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{23EC5BBA-F7C1-4723-B1BC-0A3CB227B48C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{246FB350-7376-40D9-9F0F-7D4277F7A388}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2493F551-33D6-49E2-8827-9D6784623505}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{2561BDB7-A9AC-4B74-BFB5-88443A379458}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{25730708-C4CC-4AC0-B32C-BE6D663872E5}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
"{259F1657-1376-4DFA-9AB4-7E64DD1B45AC}" = protocol=17 | dir=in | app=c:\program files (x86)\mass effect\masseffectlauncher.exe |
"{25BA500C-B0F4-4E5C-B65C-8AB79261352C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{25DE59FE-6A82-4FEC-BFB7-CCAC5B79FEC0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{26BEFAAC-B2B3-4FBC-B07D-100104B2E3FD}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{27B10E20-B59D-4862-A391-1EF0EBD855E4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{28A90E4D-BEEA-48C8-9B5C-6E3A4BCBB9DE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2A28C572-2475-40B2-9BDD-56E3BA645CCA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2AC65942-C4F0-4037-97BE-ADDB14F0066A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2B9E389F-2C14-41F0-8A28-B3E4DE99F0C7}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{2CE32EA2-BDE5-4554-97C3-F3D70B1AA2B9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2D68FE70-0FED-4945-834D-45CFBE524371}" = protocol=58 | dir=in | app=system |
"{2E53DB6D-4AD7-41AF-AEBB-78F721625C67}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{2FB7C3C6-E745-4FE4-B7C0-E848E15E094C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{30A85F73-052E-4540-A876-14B7DE4641FD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{30FBD59C-57CC-42E9-8942-AE96D268DA52}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{32CA0F48-A171-4AC4-B67F-1CFC2740C39C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3413CC19-0A83-4073-91EB-8A5F57DC1062}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{357EA97A-FDEC-48BE-B085-BB4D5DC3DE8D}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\mass effect 3\binaries\win32\masseffect3.exe |
"{35C9DE1B-BF9F-42C5-B824-507F63AA5705}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{381D528F-3786-4350-A746-9A1A2604F085}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3AC6A579-3385-4362-A97D-BB85FCDE90B2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3BD88C22-42E9-472F-A2DE-234156EB9539}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3D546704-1A85-404A-89FA-E8C57E06649A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3E9736EA-503D-494E-8E49-E56BAD9C8200}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3F1A7F3A-9C0C-43A7-9292-D77D6A00784E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3F90B83C-8841-43E7-A35A-EDDA576368E0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4057C5C9-ACD4-40A3-9205-3E0B1A460D31}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4108946F-0E61-4623-8591-E051B7869F7F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4182B44E-698F-4EE1-A9D6-A0D1C1A03554}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{41D1E773-3740-4F28-AA72-F7DB56B00F15}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{42628495-84D3-4163-B91A-C57D3A9782D3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{42EAC026-3FA9-4ACB-B23C-4695A0D4F7DE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{44F6DAF3-2DA0-4912-8257-85634D97DC7D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{461DF7DC-905B-4040-9356-E74DF924E6F2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{466EC077-A09E-42D4-8BB5-5F0EC5A3D9B1}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysisdedicatedserver.exe |
"{46E57341-E42C-4894-9F55-B13A829B4081}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{48D4F65F-DD72-45FB-A35F-CE98BF510D48}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{49CB8DA9-7BBB-4991-A66A-441ED75B3415}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{49F14077-BAC3-42EA-8A95-063618DA939A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{4B7B7009-8010-4D1C-9DC6-71FC27FFED64}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4C3D754A-5D3B-4B68-8868-D100A52E9049}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{4C44A842-4611-431B-9712-3CC419FC93D6}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysis.exe |
"{4D770F33-D76F-464E-9E72-37B97D1052FF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{52D443E8-1CAC-4766-BC33-5D0FF51091D9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5332DEF2-7831-4802-A2B3-16D48E4D5130}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5495B808-19C0-4394-852C-5509FA22AA01}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{55C4237F-C7FE-46EB-BAEE-F525DBCF764C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{562CC623-619B-409C-969E-FC1A257905F8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{576EDACB-1552-4EB7-8E85-D86158E9AF49}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5888B166-329E-407E-9C66-A7EB7E17C223}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{58E2DFE0-8BE3-4150-80E6-77980AEBCA4C}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{59CF9458-FEAF-46BF-AB31-33A4DD709874}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5BDCAA50-27A7-4414-8590-F60C44BEC5D6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5E155AEC-BF05-4352-9CCC-B86CD0CAB142}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{5FDBCE1E-C56E-4E63-BE7D-5B282A1F89FB}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{5FF94FF9-5220-4B9D-98C7-6AEBF3E65613}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{61F15983-ADD6-4030-8B79-555461F08058}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{636310FA-2B73-4C60-8DC5-F070BD05C600}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{63AE2BFF-D808-4C28-8B1F-A2E158B4524B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{640D1DF6-0FBC-4B14-A6C6-7748647BF95D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{670133FC-5133-41E8-BA92-FA4EEC964160}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{67AE5CE1-0AB9-4928-AF4C-8D4739BBCFDB}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{6B32DA66-4A3E-4707-B127-AFDFDBCDBA1C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6B3B91AC-E571-42C0-9E83-CFD5EA886547}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6B4AE139-CB3F-4D00-9E9F-54113DDE7BC8}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{6BFA7CFC-9093-461E-93BF-15E596D03BFA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6C509417-9DC9-411E-920E-7C9CFF3CBD5A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6D0D2237-027F-4D86-81F4-F8808ED5D275}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6D78CE00-1B83-4ECC-9BD6-A13FCB92FB44}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysis.exe |
"{6E076CA6-2B66-4D6C-841A-E62707F4DD79}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7030C2CC-5B91-4715-8A3C-E2A61B56FF0E}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{716CDB2E-3AB7-432C-8D66-28B9B2E3AAD6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{72F420C1-7534-4812-B398-5251BB13342F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{74053E39-58B7-4AB2-A4A2-FD67B53DEE5B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{752263FF-CAEE-474C-9E3F-8F091E7D15D8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{75EB7A59-3A7D-4032-B1DA-BCB8BEB2E4E4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7748FA2A-33EB-42FF-B389-09437108A3D3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7C08D45E-8DD2-40E2-A4C2-BA71B19018F1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7D76FEC1-3277-4719-BB11-EB6D34B92B0F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7DAABD29-B0C9-4F32-A034-E535B7086725}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{7E1769DF-D4F3-47E4-B13E-85DC3E9AC8CB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7EA6A030-415E-49E8-9A52-FE497FAB5117}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{8160FE80-6775-40C2-AF10-D7C695C6BF0A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8162252F-6079-4C3E-828A-4C812F38E819}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{835CCF9D-A4F1-452D-9BC8-C45759718049}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{836CC0A0-4EEC-4F27-9AF6-82BF1C708FC8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{852E623B-5E32-40E9-8818-17A2BED597BE}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{892C4817-63C6-41E4-BEA1-5AC8093659ED}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{894D2534-FC1C-4F3E-8359-57A30C76E638}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{89B14E25-D054-477B-8843-0C4D4138CAAF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8AF037DC-CF98-4BAF-83C7-82CFBC0C728A}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{8BC4C007-3077-428D-AE13-7325899168B0}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{8E7D110D-8C78-465F-8B30-49C0B07D5C9C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8FC320B3-FC87-4ED4-8015-E5AD6A89CC83}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{91523587-B6C3-4E23-80AB-A63633E661DB}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{91C85B2C-A55D-4A6A-9E4E-6EEC18564CF3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{91F81E19-7B8E-4E82-ADBC-71DA5430296B}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{92EA9A46-DA40-4150-B883-74774E9BD748}" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"{93A631CE-A464-4891-8373-3E9AB4010CCB}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{9694B764-BD0A-4EFB-BBB4-3005288B6ACA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{96DBF15F-FB61-47D0-BDC7-29E15210710D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{97133948-1539-4A19-95BA-0CB1A387F408}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{99410668-9CB4-4996-A22E-CDA501A993E2}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
"{9A176235-CFF5-404B-A5AF-656949B5DC82}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9A2BFC42-867B-4493-BA69-87035BD7FE2A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9A2EB61D-CE66-49C4-B174-49F5197A299D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9BE45840-AE34-4485-B5B8-0722080916CC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9C86ED36-3735-42EA-9FF3-82E12CCF3B65}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9C948521-D4A8-49C7-B654-2387962F968D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9D35AACF-E83B-4C1E-826B-F1EF88486878}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9D455E2F-AEBD-4A09-A71B-6A1478B0CADF}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{9D9D98F7-0CAF-41C1-B88E-0F2652A489BE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A06943D1-A295-4454-B126-9804B0CB8330}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A0CE56EA-EB36-4DA7-9C48-3715BE8001AB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A0DADF05-EFC8-4E48-B6AD-CE0C6907B56F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A2C6755F-39FD-4D69-9FBB-EBD41ED43BBA}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{A3A9ACDE-F5FC-44FD-A309-7782C095180E}" = protocol=17 | dir=in | app=c:\program files (x86)\mass effect\binaries\masseffect.exe |
"{A4BD673F-C125-4D45-AFD5-F084D43BA5F4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A68913CF-BBD4-4588-9A2B-B2076A9F8F28}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A6C0BC50-3E3F-4937-85A1-EF0DA46AB83A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A70067E3-8E04-477F-A8BE-DC9E2EA5A7A6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A70F4D03-077A-4C47-86C5-281C372055A2}" = protocol=6 | dir=in | app=c:\program files (x86)\mass effect\binaries\masseffect.exe |
"{AA566393-A43F-4E27-8C2D-90204DC5D7B8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{ABDDA87B-01E8-4928-9134-3AD39D7FD112}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AC92FC90-C7D7-4132-AFEB-D0B0AEDFB732}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AEA8A7B4-205E-4938-A7A6-0009D94673A0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AF0B37AA-2A05-42CD-8320-426ECEBBA64B}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{B0EA37B3-9193-4022-9B5E-6C9B6016BFDF}" = protocol=17 | dir=in | app=c:\program files (x86)\mass effect\masseffectlauncher.exe |
"{B1F7AA42-FDD3-41EB-A191-061D93A742A4}" = protocol=6 | dir=in | app=c:\program files (x86)\gamigo\levelr\levelr.bin |
"{B29566D7-3F7C-48B6-8A79-344D2AECC52A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B2E48F87-E920-416D-ACC1-236B164B698F}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{B456A2BA-E569-44B5-8E6D-973854C82BA4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B4DEE884-E6DD-424F-A301-349FE586B8EA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B93F479B-9EBA-49DD-A85B-D2ED5D1EF719}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B9547246-36FB-4E67-9888-41CF87D6D4F7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B9B1008E-2930-45FF-B295-2D763F02F3A7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BA2EE8A2-52D9-4E2E-B1C3-C0BD523E8559}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe |
"{BBAC1F7F-2427-4745-A139-1FE48EB477B3}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{BC0A7A37-995F-4928-A862-6D0DE7B1D57A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{BD284450-49B6-4F41-8739-223D421EA498}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BD57E1AD-4840-491A-8032-E538A2C69137}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BD6B6614-E70C-4864-9769-3EAF59DA37B9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BD93B635-DEAF-4B34-A01F-153D036FE848}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BFA51A84-5705-42BF-9C18-4C5FC503D258}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires online\spartan.exe |
"{BFA8CE59-0599-4FC0-917C-EED421E8AB52}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{C11D6421-F87C-494A-8769-A9B87D6ED5B2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C1BFE6D1-F109-4255-9281-372D941EA12D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C359AB99-7FF4-4D07-992E-0CA79A81DAF7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C45BC510-1E8E-401E-BA01-0DF51E0DE18E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C66F2DAE-E4F3-4949-A909-AB01B47A12B5}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{C76B61FD-75D5-4524-844B-FD168973AD48}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CA9D24E4-4533-45E7-9FF2-AC431F59DA6B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CBD50E35-54C9-4F43-92C6-07635BC4856A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CD259569-9C23-49DE-AFC2-E285D91A7E84}" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"{CD6649AA-1106-4AAA-A6F8-229E4E0A5777}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CE6CB3A2-C34C-45B7-9EF2-31B8DD6F5FBA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CF153FFA-7BB3-4742-B2D0-24BC02D7B152}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D0625C33-B289-41EC-B355-F6A9718F3C2D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{D0C529A3-C1AC-4553-BE93-89FD84D101D4}" = protocol=6 | dir=in | app=c:\program files (x86)\mass effect\masseffectlauncher.exe |
"{D205CF57-E551-4894-A42C-640E1729E5D3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D5D55544-D306-495B-8544-E933D7260743}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D691B684-61C5-4C3C-A0CF-CD1DE2CC9CCD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D7375DC5-FDE8-4519-8E46-E1A6F9BD4B9C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D8272491-8205-4DFF-B525-A2C7D9240D8A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D8328A73-11FB-4442-BA51-9C8646118DBB}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\mass effect 3\binaries\win32\masseffect3.exe |
"{D85BF275-D00F-4E68-975A-32FD5DF97104}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D89F0D17-06B0-40B2-98BC-3387883AE241}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D971F505-FAA0-4018-8F45-4D1D0CCBD6A1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DACA1DD7-17C4-428F-BB21-0B3C9ED54874}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DB6BBDB9-A516-472A-A0D0-3DEB7E12957A}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\medal of honor mp beta\mohmpupdater.exe |
"{DE56ACCE-8746-4DC0-B74A-F4DD1D8092E8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DF1D384E-B21C-4A8D-A521-8A0EFAD70BD5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DFA26D26-7D6B-4B7A-9022-995B0015A47B}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysis.exe |
"{E21EB55B-E981-4B70-84ED-E23C01118046}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E56409C8-2F59-489B-8A2D-55AEAB654ED0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E5E59313-32FB-4D3B-8E26-C378644C28EE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E7A4B931-0DC8-4AEE-806F-C0C0C965D87C}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{E7CC5438-3339-4914-ACAF-8F7F7A777C33}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E83675EE-DB70-42B3-A9E9-36B85104320D}" = protocol=6 | dir=in | app=c:\program files (x86)\mass effect\masseffectlauncher.exe |
"{E8A59302-A02B-4ABA-ACA4-B27C3A0EB300}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{E9AE8846-5208-4ABC-9FEF-9ADA802CCA54}" = protocol=17 | dir=in | app=c:\program files (x86)\gamigo\levelr\levelr.bin |
"{EB590F97-3442-43BC-BC9A-96FCC3BE45DB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EBF43319-F390-405A-B722-7E08463E5479}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{ED630278-55A9-4C07-A1B9-6461B5D01ECE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EDB7DCEF-C54E-426B-9CB6-EECC60B56000}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F1935560-B4CA-425A-9B4E-B23C01571AF5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F764E29E-884F-4845-A0FE-89BCBBC80DA7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F7C112C3-80DE-452D-9831-F55E8401D2E9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F9247264-B7AA-42F8-9E65-7C6E4E26218A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F94E7D8B-87B9-475C-9796-777E4B1DD7F8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FAA4698C-2FD5-426A-9940-1D69B217D63D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FB70ECD8-6907-4FA0-AE10-8937AA9703F8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FC274AAC-97C2-431D-93B6-EC2FDD053EBB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FC3CF689-AA6D-40B9-9789-1CC5EC318E9D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FCBA9A6D-9923-426A-950F-5F079D9CDD3C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FD3AE91B-E1A0-4575-AE75-B6BA6A87512F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FEB18316-422C-4430-823F-D8CF26BCF072}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |

[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0ADCC771-E663-00D5-C381-C152F0F4D391}" = ATI AVIVO64 Codecs
"{0B6BFB17-AB5C-46A3-A448-E37ED088D9E1}" = ZoomEx
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{2C0222FA-7DBD-4AED-862B-1672848539F4}" = Diskeeper 12 Professional
"{344C0D46-2EF4-4BC8-AE03-3DACDA9B9485}" = AVG 2012
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{68CA3A47-3F7E-0E92-DC0D-5B0C02D9AFAD}" = ccc-utility64
"{6BB150E8-6CBB-5F8F-CAE7-BE21B2C92D31}" = AMD Accelerated Video Transcoding
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8E5DA9A6-7A9F-3A6F-BC5C-D6CBCA6A29C7}" = Microsoft .NET Framework 4 Extended PLK Language Pack
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007
"{914F7627-B645-9895-F723-BAEAAC865E75}" = AMD Catalyst Install Manager
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BF46C84D-1AC3-4CC3-A45C-EF6257B80984}" = AVG 2012
"{DA3372D5-F228-5C71-3FAC-177D4AEE8659}" = AMD Media Foundation Decoders
"{E6456858-8C0C-35CE-96B8-AFFCD205C9FC}" = AMD Drag and Drop Transcoding
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AVG" = AVG 2012
"CCleaner" = CCleaner
"PDF Creator" = PDF Creator
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"ZoomEx" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis(R)
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{03D45A4B-D7F5-C03E-1650-885756303D13}" = CCC Help Norwegian
"{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty(R) - World at War(TM) 1.6 Patch
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{108FAA6F-DEEE-48EA-B3A9-1C5EB2605A6B}" = PL
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}" = Mass Effect
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 25
"{26A24AE4-039D-4CA4-87B4-2F83217013FF}" = Java 7 Update 13
"{284E9E9A-D8BE-3588-D0BA-E9BB61970A1D}" = CCC Help Hungarian
"{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty(R) - World at War(TM) 1.2 Patch
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{30E18A93-982E-AF1B-D646-E8C5DAECA390}" = CCC Help French
"{386D8F37-336B-432E-9F13-ED421F4DD19B}" = FireArc Arcade
"{4021F8B5-E8BB-D0F9-AF28-4970013FAE3D}" = Catalyst Control Center
"{42AF51C0-4028-46CF-B616-FB1F75286457}" = A.V.A
"{442C760A-7359-466A-B492-E4FDD3262E9D}" = LevelR
"{470D66DF-B597-124E-EDCE-8B966AA5F230}" = CCC Help Portuguese
"{483924A6-52C5-9169-0280-14272D5FBA70}" = CCC Help Chinese Standard
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4D530FA3-9B89-4186-98B7-F51000008100}" = Age of Empires Online
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
"{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}" = FontNav
"{52B65911-1559-4ED5-9461-46957FDD48CD}" = Borderlands
"{534A31BD-20F4-46b0-85CE-09778379663C}" = Mass Effect™ 3
"{53820F89-063F-10D7-7457-06C201F4CBF0}" =
"{57AE1BE1-24E8-4169-D52C-ABE31BD91562}" = CCC Help Finnish
"{5B5745F7-23EF-9E5E-6689-512C9FA08222}" = CCC Help English
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{625031C9-E249-2A53-C282-C1E9872B211E}" = CCC Help Turkish
"{655E0B5A-7ADF-A052-587F-64F0E59B58E7}" = CCC Help Dutch
"{6C90C4C4-559D-4FE8-A4BF-37550E74D1FC}" = Bloodline Champions
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74437563-D720-0307-90FC-1C351B1041D7}" = Catalyst Control Center Localization All
"{750C87B8-AF19-4C3C-B791-50D9C83AE572}" = Call of Duty(R) - World at War(TM) 1.7 Patch
"{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2
"{7683B745-6060-41FD-AA75-0BBB383FEAD4}" = SweetIM for Messenger 3.7
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A4D10-821B-3FA5-52B0-F0FAEEDED9F4}" = CCC Help Czech
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BA14A92-C229-5E00-3ADE-8D22F81B849E}" = CCC Help German
"{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}" = CorelDRAW Graphics Suite X3
"{7FB413C8-3CAD-49F7-A67C-6EFEB4B04050}" = LogMeIn Hamachi
"{80A5B901-C7BD-D300-17BA-9E02F18EAB77}" = CCC Help Danish
"{82F505E6-5879-B30A-12B7-7795969D3BBB}" = CCC Help Polish
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83AA2913-C123-4146-85BD-AD8F93971D39}" = BabylonObjectInstaller
"{8476003F-6927-8393-C6F4-FAF47D61D00B}" = CCC Help Korean
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{89A2D79E-B3AD-A83A-795F-5645EFF922D3}" = CCC Help Greek
"{89C0F58F-9E5B-2B45-D9DF-7988A54BECA8}" = CCC Help Italian
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8B91D776-792D-F02B-DE43-BF398549C729}" = CCC Help Spanish
"{8F272838-BDD6-B433-D650-25E231AEFA8A}" = Catalyst Control Center InstallProxy
"{90120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007
"{90120000-0016-0415-0000-0000000FF1CE}_STANDARD_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007
"{90120000-0018-0415-0000-0000000FF1CE}_STANDARD_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007
"{90120000-001A-0415-0000-0000000FF1CE}_STANDARD_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007
"{90120000-001B-0415-0000-0000000FF1CE}_STANDARD_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_STANDARD_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARD_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007
"{90120000-001F-0415-0000-0000000FF1CE}_STANDARD_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_STANDARD_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0415-1000-0000000FF1CE}_STANDARD_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007
"{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007
"{90120000-006E-0415-0000-0000000FF1CE}_STANDARD_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{901DC58A-5C1B-4315-BA40-5AD3D3A463B9}" = REACTOR
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{9530AE42-DAE1-4619-9594-B23487285D17}" = NVIDIA PhysX
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{983BE967-28E9-5C78-8851-638DAC4AF66E}" = CCC Help Swedish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty(R) - World at War(TM) 1.4 Patch
"{A64479BE-7DB6-4B07-87B9-70AD85B7EAD2}" = Medal of Honor™ MP Beta
"{A707240D-18D3-07F4-AE2E-6AE76C220192}" = CCC Help Japanese
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.3
"{AEDFE02E-FDDB-40A5-B5A9-5F955A75693F}" = XSplit
"{AF37176A-78CA-545B-34EF-8B6A21514DD1}" = Adobe Help Manager
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B95AC87D-630B-603F-3F12-AA22B3BBA69C}" = CCC Help Chinese Traditional
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C3592426-531E-4110-911D-BFECE2CE284C}" = osu!
"{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty(R) - World at War(TM) 1.5 Patch
"{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}" = Internet Explorer Toolbar 4.6 by SweetPacks
"{C40C3C3D-97CF-44B5-836C-766E374464B3}" = 3DMark Vantage
"{C580908C-B3BA-4C19-BD60-16F02F272201}" = BattleForge™
"{C6B29F03-4D97-3B4E-D906-70958E6B1448}" = HydraVision
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDFF2306-D734-4C39-AF7F-2DA728D9BA72}" = Linkury Smartbar
"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM)
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{EB1C554C-5343-9A69-1B8C-666AF192CA19}" = CCC Help Russian
"{F0A209B7-7F85-4BDD-8F1F-B98EEAD9E04B}" = Wiedźmin 2
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F32D24DD-D787-10F9-D21E-BC3FAB3064CB}" = Catalyst Control Center Graphics Previews Common
"{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}" = Update Manager
"{F8D90583-7BB5-75A9-B23F-A353AD4674BC}" = CCC Help Thai
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"BitTorrent" = BitTorrent
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Help Manager
"DAEMON Tools Lite" = DAEMON Tools Lite
"Diablo III" = Diablo III
"E.M. Free Game Capture_is1" = E.M. Free Game Capture 2.31
"GFWL_{4D530FA3-9B89-4186-98B7-F51000008100}" = Age of Empires Online
"Guild Wars 2" = Guild Wars 2
"iMesh 1 MediaBar" = MediaBar
"InstallShield_{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty(R) - World at War(TM) 1.6 Patch
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platforma Menedżera urządzeń
"InstallShield_{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty(R) - World at War(TM) 1.2 Patch
"InstallShield_{750C87B8-AF19-4C3C-B791-50D9C83AE572}" = Call of Duty(R) - World at War(TM) 1.7 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty(R) - World at War(TM) 1.4 Patch
"InstallShield_{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty(R) - World at War(TM) 1.5 Patch
"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty(R) - World at War(TM)
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"LogMeIn Hamachi" = LogMeIn Hamachi
"LOLReplay" = LOLReplay
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.70.0.1100
"Might and Magic® VII" = Might and Magic® VII
"Mozilla Firefox 19.0.2 (x86 pl)" = Mozilla Firefox 19.0.2 (x86 pl)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MultiplayerMinecraft.pl 1.2.5" = MultiplayerMinecraft.pl 1.2.5
"Odkurzacz 13.2_is1" = Odkurzacz
"Opera 12.14.1738" = Opera 12.14
"Origin" = Origin
"searchya" = SearchYa! Web Search
"Shockwave" = Shockwave
"STANDARD" = Microsoft Office Standard 2007
"WinRAR archiver" = Archiwizator WinRAR

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0766aa94-b27a-4a73-92c7-8550f2e0c55b}" = Linkury Smartbar Engine
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
"Game Organizer" = EasyBits GO
"Google Chrome" = Google Chrome
"PDF Creator Packages" = PDF Creator Packages
"Video Converter" = Video Converter

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2013-03-15 12:03:31 | Computer Name = dom-Komputer | Source = Windows Search Service | ID = 9000
Description =

Error - 2013-03-15 12:03:31 | Computer Name = dom-Komputer | Source = Windows Search Service | ID = 7040
Description =

Error - 2013-03-15 12:03:31 | Computer Name = dom-Komputer | Source = Windows Search Service | ID = 9002
Description =

Error - 2013-03-15 12:03:31 | Computer Name = dom-Komputer | Source = Windows Search Service | ID = 3029
Description =

Error - 2013-03-15 12:03:32 | Computer Name = dom-Komputer | Source = Windows Search Service | ID = 3029
Description =

Error - 2013-03-15 12:03:32 | Computer Name = dom-Komputer | Source = Windows Search Service | ID = 3028
Description =

Error - 2013-03-15 12:03:32 | Computer Name = dom-Komputer | Source = Windows Search Service | ID = 3058
Description =

Error - 2013-03-15 12:03:32 | Computer Name = dom-Komputer | Source = Windows Search Service | ID = 7010
Description =

Error - 2013-03-15 12:03:32 | Computer Name = dom-Komputer | Source = Windows Search Service | ID = 7042
Description =

Error - 2013-03-15 14:20:09 | Computer Name = dom-Komputer | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "C:\Program Files (x86)\SplitMediaLabs\XSplit\XSplitBroadcasterSrc.exe".
Nie
można odnaleźć zestawu zależnego Native.XSplitBroadcaster.exe,type="win32",version="1.0.0.0".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.

[ System Events ]
Error - 2013-03-16 17:21:07 | Computer Name = dom-Komputer | Source = Service Control Manager | ID = 7001
Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie
można uruchomić z powodu następującego błędu: %%1068

Error - 2013-03-16 17:21:53 | Computer Name = dom-Komputer | Source = Service Control Manager | ID = 7001
Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie
można uruchomić z powodu następującego błędu: %%1068

Error - 2013-03-16 17:21:53 | Computer Name = dom-Komputer | Source = Service Control Manager | ID = 7001
Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie
można uruchomić z powodu następującego błędu: %%1068

Error - 2013-03-16 17:21:53 | Computer Name = dom-Komputer | Source = Service Control Manager | ID = 7001
Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie
można uruchomić z powodu następującego błędu: %%1068

Error - 2013-03-16 17:23:14 | Computer Name = dom-Komputer | Source = Service Control Manager | ID = 7001
Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie
można uruchomić z powodu następującego błędu: %%1068

Error - 2013-03-16 17:23:14 | Computer Name = dom-Komputer | Source = Service Control Manager | ID = 7001
Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie
można uruchomić z powodu następującego błędu: %%1068

Error - 2013-03-16 17:23:14 | Computer Name = dom-Komputer | Source = Service Control Manager | ID = 7001
Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie
można uruchomić z powodu następującego błędu: %%1068

Error - 2013-03-16 17:23:14 | Computer Name = dom-Komputer | Source = Service Control Manager | ID = 7001
Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie
można uruchomić z powodu następującego błędu: %%1068

Error - 2013-03-16 17:23:14 | Computer Name = dom-Komputer | Source = Service Control Manager | ID = 7001
Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie
można uruchomić z powodu następującego błędu: %%1068

Error - 2013-03-16 17:23:14 | Computer Name = dom-Komputer | Source = Service Control Manager | ID = 7001
Description = Usługa Przeglądarka komputera zależy od usługi Serwer, której nie
można uruchomić z powodu następującego błędu: %%1068


< End of report >

Użytkownik Sup Sis feggit meggit xoxo edytował ten post 16 03 2013 - 23:25

  • 0

#4 pawel315

pawel315

    Uzależniony od forum

  • 1 553 postów

Napisano 16 03 2013 - 23:19

Ok czekam na tego loga ( system jest zaśmiecony )
  • 0

#5 Sup Sis feggit meggit xoxo

Sup Sis feggit meggit xoxo

    Początkujący

  • 11 postów

Napisano 17 03 2013 - 00:02

Wysłałem już jako edit do poprzedniego posta (już mi się chyba skończył ;-;). Mam dużo pozostałości po źle odinstalowanych programach/grach. Bardzo często gdy chcę coś odinstalować pojawia się komunikat, że ten plik "jest otwarty w innym programie" i nie można go odinstalować co jest totalną bzdurą.
  • 0

#6 pawel315

pawel315

    Uzależniony od forum

  • 1 553 postów

Napisano 17 03 2013 - 11:00

To teraz:
Odinstaluj:
SearchYa! Web Search
MediaBar
Pando Media Booster
Ask Toolbar
BabylonObjectInstaller
SweetIM for Messenger 3.7
Uruchom OTL w okienku Własne opcje skanowania/skrypt wklej:
:OTL
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchfunmoods.com/?f=1&a=iron2&ir=iron2&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0E0CtBtC0DyEtD0DtBtA0EtN0D0Tzu0CtAyDtCtN1L2XzutBtFtBtFtCtFyEtDyB&cr=911712656
IE:64bit: - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&ir=iron2&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0E0CtBtC0DyEtD0DtBtA0EtN0D0Tzu0CtAyDtCtN1L2XzutBtFtBtFtCtFyEtDyB&cr=911712656
IE:64bit: - HKLM\..\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}: "URL" = http://www.searchya.com/?q={searchTerms}&s=1&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0E0CtBtC0DyEtD0DtBtA0EtN0D0Tzu0CtBtAtDtN1L2XzutBtFtCtFtCtFtAtCtB&cr=2048707667
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://search.babylon.com/?affID=110809&tt=bandext_3312_8&babsrc=HP_ss&mntrId=44dbd23e00000000000000ffe5264df8
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://search.babylon.com/?affID=110809&tt=bandext_3312_8&babsrc=HP_ss&mntrId=44dbd23e00000000000000ffe5264df8
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://search.babylon.com/?affID=110809&tt=bandext_3312_8&babsrc=HP_ss&mntrId=44dbd23e00000000000000ffe5264df8
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = pl.v9.com/idg/idg_1342608838_220770
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=hp&babsrc=lnkry_nt
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
CHR - homepage: http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=hp&babsrc=lnkry
CHR - default_search_provider: Web (Enabled)
CHR - default_search_provider: search_url = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=92d654ad-8e8a-48ea-8b5c-46abd9a276b4&affid=111583&searchtype=hp&babsrc=lnkry
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-3625104046-687358821-1933599865-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.

:Files
C:\Users\dom\Documents\antizeroaccess.exe
C:\Users\dom\AppData\Local\PMB Files
C:\ProgramData\PMB Files
C:\Users\dom\AppData\Local\setup.exe
C:\Windows\SysWow64\LogiDPP.dll
C:\Windows\SysWow64\LogiDPPApp.exe
C:\Users\dom\AppData\Roaming\Babylon
C:\Users\dom\AppData\Roaming\Funmoods

:Commands
[reboot]

Kliknij Wykonaj skrypt daj log z usuwania.
Następnie:

  • 0

#7 Sup Sis feggit meggit xoxo

Sup Sis feggit meggit xoxo

    Początkujący

  • 11 postów

Napisano 17 03 2013 - 16:51

Dziękuję za pomoc ale jak teraz na to wszystko patrzę, to nawet jeżeli udałoby się wyeliminować wszystkie problemy, usunąć wirusy to mam po prostu za dużo syfu na tym kompie. Zrobię formata.
  • 0

#8 bipiw

bipiw

    Zaawansowany użytkownik

  • 1 180 postów

Napisano 17 03 2013 - 17:04

Nie słusznie. Znaczna część z tego to po prostu Adware->syf, który instaluje się razem z innym oprogramowaniem, gdy nie odznaczy się 'jakiegoś ptaszka'(checkboxa). To co napisał paweł usunie te zbędne programy i komp powinien dobrze chodzić(zwłaszcza, że już poświęcił czas na zrobienie dla Ciebie instrukcji usuwania->wypadałoby poszanować pracę kolegi).

Użytkownik bipiw edytował ten post 17 03 2013 - 17:05

  • 0

#9 pawel315

pawel315

    Uzależniony od forum

  • 1 553 postów

Napisano 17 03 2013 - 20:14

Bipiw ma rację - głównie adware na twoim kompie to syf i mój powyższy post rozwiąże większość problemów, ale decyzja należy do Ciebie
  • 0

#10 Sup Sis feggit meggit xoxo

Sup Sis feggit meggit xoxo

    Początkujący

  • 11 postów

Napisano 18 03 2013 - 20:06

Przepraszam za marnowanie twojego czasu Pawle315, ale zrobiłem już format. Mam teraz problem z konfiguracją połączenia internetowego więc jeżeli będziesz chciał pomóc takiemu potworowi jakim jestem ( i umiał) to założyłem temat Połączenie sieciowe jest "ok" ale w praktyce nie działa. - Konfiguracja sieci i routery Forum

Użytkownik Sup Sis feggit meggit xoxo edytował ten post 18 03 2013 - 20:06

  • 0

Zobacz więcej tematów z tagiem: ;-;



Użytkownicy przeglądający ten temat: 0

0 użytkowników, 0 gości, 0 anonimowych