Wrzucam logi z OTL:
OTL logfile created on: 2013-07-03 19:15:33 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = E:\Moje Dokumenty\Pobieranie 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 7,99 Gb Total Physical Memory | 6,40 Gb Available Physical Memory | 80,11% Memory free 9,99 Gb Paging File | 8,14 Gb Available in Paging File | 81,45% Paging File free Paging file location(s): e:\pagefile.sys 2048 2048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 30,07 Gb Total Space | 2,38 Gb Free Space | 7,92% Space Free | Partition Type: NTFS Drive D: | 292,96 Gb Total Space | 127,44 Gb Free Space | 43,50% Space Free | Partition Type: NTFS Drive E: | 34,17 Gb Total Space | 2,39 Gb Free Space | 6,99% Space Free | Partition Type: NTFS Drive F: | 146,48 Gb Total Space | 2,71 Gb Free Space | 1,85% Space Free | Partition Type: NTFS Drive G: | 360,21 Gb Total Space | 11,18 Gb Free Space | 3,10% Space Free | Partition Type: NTFS Drive H: | 97,69 Gb Total Space | 1,41 Gb Free Space | 1,44% Space Free | Partition Type: NTFS Computer Name: NM8615-KOMPUTER | User Name: nm 8615 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013-07-03 19:15:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\Moje dokumenty\Pobieranie\OTL.exe PRC - [2013-07-03 11:10:09 | 000,920,472 | ---- | M] (Mozilla Corporation) -- E:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2013-05-12 15:43:32 | 000,413,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2013-07-03 11:10:09 | 003,285,912 | ---- | M] () -- E:\Program Files (x86)\Mozilla Firefox\mozjs.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2012-10-19 14:12:06 | 001,090,560 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\PowerSoft Professional\PowerSoftService.exe -- (PowerSoft) SRV:[b]64bit:[/b] - [2009-07-14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:[b]64bit:[/b] - [2009-07-14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2013-06-26 21:11:23 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013-05-12 15:43:32 | 000,413,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2013-05-11 12:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2013-04-19 15:14:16 | 000,161,384 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- E:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2013-02-17 12:18:06 | 000,137,336 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service) SRV - [2012-10-10 22:23:42 | 001,258,856 | ---- | M] (NVIDIA Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012-07-23 16:18:42 | 000,383,128 | ---- | M] (BlueStack Systems, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe -- (BstHdLogRotatorSvc) SRV - [2012-07-23 16:18:16 | 000,395,416 | ---- | M] (BlueStack Systems, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\BlueStacks\HD-Service.exe -- (BstHdAndroidSvc) SRV - [2012-06-23 19:54:21 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service) SRV - [2012-06-22 19:16:12 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\DDLLicensing.exe -- (Creative Dolby Digital Live Pack Licensing Service) SRV - [2012-01-02 22:19:17 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service) SRV - [2011-06-07 14:33:38 | 000,155,648 | ---- | M] (Seagate Technology LLC) [Disabled | Stopped] -- E:\Program Files (x86)\Seagate\Seagate_Media\Sync\MediaAggreService.exe -- (FreeAgentTheater Service) SRV - [2011-03-02 17:20:58 | 000,224,256 | ---- | M] () [On_Demand | Stopped] -- E:\Program Files (x86)\GNU\GnuPG\dirmngr.exe -- (DirMngr) SRV - [2011-02-25 11:30:52 | 000,345,128 | ---- | M] (Marvell) [On_Demand | Stopped] -- C:\Program Files (x86)\Marvell\storage\svc\mvraidsvc.exe -- (Marvell Storage Management) SRV - [2010-12-28 15:44:54 | 000,294,912 | ---- | M] (Creative Technology Ltd) [On_Demand | Stopped] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService) SRV - [2010-09-02 04:47:48 | 000,024,645 | ---- | M] (Apache Software Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Marvell\storage\Apache2\bin\httpd.exe -- (MSUWebService) SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010-03-10 15:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2) SRV - [2010-02-19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009-07-07 14:48:44 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice) SRV - [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - File not found [Kernel | Auto | Stopped] -- C:\Windows\SysNative\ -- (MLPTDR_N) DRV:[b]64bit:[/b] - [2013-02-25 07:27:45 | 000,194,848 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:[b]64bit:[/b] - [2012-10-24 11:41:03 | 000,052,832 | ---- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\libusb0.sys -- (libusb0) DRV:[b]64bit:[/b] - [2012-09-12 16:20:04 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr) DRV:[b]64bit:[/b] - [2012-06-05 06:04:14 | 000,031,744 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\androidusb.sys -- (androidusb) DRV:[b]64bit:[/b] - [2012-05-06 02:49:57 | 000,231,376 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\truecrypt.sys -- (truecrypt) DRV:[b]64bit:[/b] - [2012-03-01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2012-01-07 18:17:32 | 000,303,616 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:[b]64bit:[/b] - [2012-01-07 18:17:32 | 000,035,328 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:[b]64bit:[/b] - [2011-12-15 19:35:09 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:[b]64bit:[/b] - [2011-08-22 21:26:46 | 001,561,688 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ha20x2k.sys -- (ha20x2k) DRV:[b]64bit:[/b] - [2011-08-22 21:25:30 | 001,417,304 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX.SYS) DRV:[b]64bit:[/b] - [2011-08-22 21:25:30 | 001,417,304 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX) DRV:[b]64bit:[/b] - [2011-08-22 21:25:16 | 000,094,808 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT.SYS) DRV:[b]64bit:[/b] - [2011-08-22 21:25:16 | 000,094,808 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT) DRV:[b]64bit:[/b] - [2011-08-22 21:25:06 | 000,202,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT.SYS) DRV:[b]64bit:[/b] - [2011-08-22 21:25:06 | 000,202,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT) DRV:[b]64bit:[/b] - [2011-08-10 17:40:58 | 000,052,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d) DRV:[b]64bit:[/b] - [2011-08-10 17:40:58 | 000,023,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nuidfltr.sys -- (NuidFltr) DRV:[b]64bit:[/b] - [2011-03-11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011-03-11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2011-02-14 08:08:24 | 000,024,880 | ---- | M] (Marvell Semiconductor Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mv91cons.sys -- (mv91cons) DRV:[b]64bit:[/b] - [2011-02-10 15:52:34 | 000,181,760 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) DRV:[b]64bit:[/b] - [2011-02-10 15:52:34 | 000,082,432 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) DRV:[b]64bit:[/b] - [2010-11-21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010-11-21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2010-03-18 20:52:18 | 000,295,000 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\haP17v2k.sys -- (hap17v2k) DRV:[b]64bit:[/b] - [2010-03-18 20:52:10 | 000,259,672 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\haP16v2k.sys -- (hap16v2k) DRV:[b]64bit:[/b] - [2010-03-18 20:52:02 | 001,360,984 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ha10kx2k.sys -- (ha10kx2k) DRV:[b]64bit:[/b] - [2010-03-18 20:51:50 | 000,147,544 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\emupia2k.sys -- (emupia) DRV:[b]64bit:[/b] - [2010-03-18 20:51:34 | 000,290,392 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctsfm2k.sys -- (ctsfm2k) DRV:[b]64bit:[/b] - [2010-03-18 20:51:26 | 000,016,984 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctprxy2k.sys -- (ctprxy2k) DRV:[b]64bit:[/b] - [2010-03-18 20:51:18 | 000,221,272 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctoss2k.sys -- (ossrv) DRV:[b]64bit:[/b] - [2010-03-18 20:50:52 | 000,866,264 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctaud2k.sys -- (ctaud2k) DRV:[b]64bit:[/b] - [2010-03-18 20:50:42 | 000,580,696 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctac32k.sys -- (ctac32k) DRV:[b]64bit:[/b] - [2010-03-18 20:40:10 | 000,141,912 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTERFXFX.sys -- (CTERFXFX.SYS) DRV:[b]64bit:[/b] - [2010-03-18 20:40:10 | 000,141,912 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTERFXFX.sys -- (CTERFXFX) DRV:[b]64bit:[/b] - [2010-03-18 20:40:02 | 000,681,048 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTSBLFX.sys -- (CTSBLFX.SYS) DRV:[b]64bit:[/b] - [2010-03-18 20:40:02 | 000,681,048 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTSBLFX.sys -- (CTSBLFX) DRV:[b]64bit:[/b] - [2010-03-18 20:39:54 | 000,706,648 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTAUDFX.sys -- (CTAUDFX.SYS) DRV:[b]64bit:[/b] - [2010-03-18 20:39:54 | 000,706,648 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTAUDFX.sys -- (CTAUDFX) DRV:[b]64bit:[/b] - [2010-03-18 20:39:44 | 000,158,808 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\COMMONFX.sys -- (COMMONFX.SYS) DRV:[b]64bit:[/b] - [2010-03-18 20:39:44 | 000,158,808 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\COMMONFX.sys -- (COMMONFX) DRV:[b]64bit:[/b] - [2009-10-05 17:34:00 | 001,542,656 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) DRV:[b]64bit:[/b] - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009-07-07 14:48:44 | 000,035,376 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\purendis.sys -- (purendis) DRV:[b]64bit:[/b] - [2009-07-07 14:48:44 | 000,033,328 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\pnarp.sys -- (pnarp) DRV:[b]64bit:[/b] - [2009-06-10 22:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7) DRV:[b]64bit:[/b] - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2008-11-04 20:21:08 | 000,098,144 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID) DRV:[b]64bit:[/b] - [2006-09-30 11:36:14 | 000,013,008 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\pstrip64.sys -- (PStrip64) DRV - [2012-09-17 18:39:10 | 000,013,728 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files (x86)\TRIXX MB\smtdrvr64.sys -- (SMTDrvr) DRV - [2012-07-23 16:18:42 | 000,072,856 | ---- | M] (BlueStack Systems) [Kernel | Auto | Running] -- C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys -- (BstHdDrv) DRV - [2012-06-30 15:59:35 | 000,019,952 | ---- | M] () [Kernel | On_Demand | Stopped] -- e:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys -- (RivaTuner64) DRV - [2011-02-25 05:57:34 | 000,014,376 | ---- | M] () [Kernel | On_Demand | Stopped] -- c:\Windows\SysWOW64\Mv_Process.sys -- (Mv_Process) DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1177817967-480693648-3998081089-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.claro-search.com/?affID=114506&tt=5112_1&babsrc=HP_clro&mntrId=94c3789d000000000000001a4d66f9c1 IE - HKU\S-1-5-21-1177817967-480693648-3998081089-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-1177817967-480693648-3998081089-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&r= IE - HKU\S-1-5-21-1177817967-480693648-3998081089-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.claro-search.com/?q={searchTerms}&affID=114506&tt=5112_1&babsrc=SP_clro&mntrId=94c3789d000000000000001a4d66f9c1 IE - HKU\S-1-5-21-1177817967-480693648-3998081089-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: e:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: F:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\nm 8615\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\nm 8615\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\nm 8615\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\opencandy.com/Ignite: C:\Users\nm 8615\AppData\Local\Ignite\npOCDM.1.1.4.0.dll (OpenCandy, Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: e:\Program Files\AVAST Software\Avast\WebRep\FF FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fmconverter@gmail.com: C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2012-10-03 12:23:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.1\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.1\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: E:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: E:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: e:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: e:\Program Files (x86)\Mozilla Firefox\plugins [2011-12-22 19:46:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\nm 8615\AppData\Roaming\mozilla\Extensions [2013-07-03 15:56:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\nm 8615\AppData\Roaming\mozilla\Firefox\Profiles\es\extensions [2013-07-03 15:56:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\nm 8615\AppData\Roaming\mozilla\Firefox\Profiles\es\extensions\ffxtlbr@babylon.com [2013-07-03 15:58:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\nm 8615\AppData\Roaming\mozilla\Firefox\Profiles\es\dom\extensions [2012-12-17 18:57:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\nm 8615\AppData\Roaming\mozilla\Firefox\Profiles\es\dom\extensions\staged [2013-07-03 15:58:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\nm 8615\AppData\Roaming\mozilla\Firefox\Profiles\es\firefox\extensions [2012-12-17 18:57:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\nm 8615\AppData\Roaming\mozilla\Firefox\Profiles\es\firefox\extensions\staged [2013-07-03 15:58:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\nm 8615\AppData\Roaming\mozilla\Firefox\Profiles\firefox-seo\extensions [color=#E56717]========== Chrome ==========[/color] CHR - Extension: No name found = C:\Users\nm 8615\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0\ CHR - Extension: No name found = C:\Users\nm 8615\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\14.0.2.14_0\ O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - e:\Program Files (x86)\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) O4:[b]64bit:[/b] - HKLM..\Run: [Windows Defender] File not found O4 - HKLM..\Run: [PowerSoft Professional] File not found O4 - HKLM..\Run: [Tutorials] File not found O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1177817967-480693648-3998081089-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSecurityTab = 0 O7 - HKU\S-1-5-21-1177817967-480693648-3998081089-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1177817967-480693648-3998081089-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0 O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - E:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O8:[b]64bit:[/b] - Extra context menu item: Subskrybuj w RSS Bandit - C:\Users\nm 8615\AppData\Roaming\RssBandit\iecontext_subscribebandit.htm () O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.) O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - E:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Subskrybuj w RSS Bandit - C:\Users\nm 8615\AppData\Roaming\RssBandit\iecontext_subscribebandit.htm () O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKU\S-1-5-21-1177817967-480693648-3998081089-1000\..Trusted Ranges: Range1 ([http] in Trusted sites) O15 - HKU\S-1-5-21-1177817967-480693648-3998081089-1000\..Trusted Ranges: Range1 ([https] in Trusted sites) O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2) O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab (Creative Software AutoUpdate 2) O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/ocx/110926/CTPID.cab (Creative Software AutoUpdate Support Package) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7BE7F933-E434-4A98-9B24-AE9D74D769D7}: DhcpNameServer = 62.21.99.95 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A342BD79-D7C3-4486-B0CD-E0FA4D86B410}: DhcpNameServer = 10.1.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D02F06A9-0B83-49C6-9F16-8C2878FBC36E}: NameServer = 192.168.4.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D16EF273-C2D2-446B-9305-3D0D2714B305}: DhcpNameServer = 10.1.1.1 O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\amd64\puresp4.dll (Cisco Systems, Inc.) O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2013-07-03 16:19:23 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{347815be-2741-11e1-b081-001a4d66f9c1}\Shell - "" = AutoRun O33 - MountPoints2\{347815be-2741-11e1-b081-001a4d66f9c1}\Shell\AutoRun\command - "" = J:\Autorun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013-07-03 19:13:34 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2013-07-03 16:18:42 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group [2013-07-03 16:08:53 | 031,367,776 | ---- | C] (Abelssoft ) -- E:\Moje Dokumenty\cryptbox.exe [2013-06-27 21:29:49 | 000,000,000 | ---D | C] -- C:\Users\nm 8615\Heaven [2013-06-27 16:16:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unigine [2013-06-27 15:00:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies [2013-06-27 14:32:35 | 027,775,776 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll [2013-06-27 14:32:35 | 025,256,224 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll [2013-06-27 14:32:35 | 021,096,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll [2013-06-27 14:32:35 | 017,560,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll [2013-06-27 14:32:35 | 015,143,904 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll [2013-06-27 14:32:35 | 009,233,688 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll [2013-06-27 14:32:35 | 007,682,960 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll [2013-06-27 14:32:35 | 007,641,832 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll [2013-06-27 14:32:35 | 006,324,360 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll [2013-06-27 14:32:35 | 002,942,240 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll [2013-06-27 14:32:35 | 002,754,336 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll [2013-06-27 14:32:35 | 002,363,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll [2013-06-27 14:32:35 | 002,002,720 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll [2013-06-27 14:32:35 | 001,832,224 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6432018.dll [2013-06-27 14:32:35 | 001,511,712 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6432018.dll [2013-06-27 14:32:35 | 001,510,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdagenco6420103.dll [2013-06-27 14:32:35 | 000,925,648 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvumdshim.dll [2013-06-27 14:32:35 | 000,550,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvFBC64.dll [2013-06-27 14:32:35 | 000,518,944 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFR64.dll [2013-06-27 14:32:35 | 000,443,168 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvFBC.dll [2013-06-27 14:32:35 | 000,432,416 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvEncodeAPI64.dll [2013-06-27 14:32:35 | 000,421,152 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFR.dll [2013-06-27 14:32:35 | 000,370,976 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvEncodeAPI.dll [2013-06-27 14:32:35 | 000,266,448 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvinitx.dll [2013-06-27 14:32:35 | 000,218,592 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglshim64.dll [2013-06-27 14:32:35 | 000,214,448 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvinit.dll [2013-06-27 14:32:35 | 000,194,848 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvhda64v.sys [2013-06-27 14:32:35 | 000,181,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglshim32.dll [2013-06-27 14:32:35 | 000,031,520 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdap64.dll [2013-06-27 14:00:27 | 000,000,000 | ---D | C] -- C:\Users\nm 8615\AppData\Local\Futuremark [2013-06-27 14:00:26 | 000,000,000 | ---D | C] -- E:\Moje Dokumenty\3DMark [2013-06-27 13:36:03 | 000,000,000 | ---D | C] -- E:\Moje Dokumenty\3DMark 11 [2013-06-26 20:23:34 | 000,000,000 | ---D | C] -- E:\desktop\smieci [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 E:\Moje Dokumenty\*.tmp files -> E:\Moje Dokumenty\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013-07-03 19:11:58 | 000,001,046 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013-07-03 19:11:50 | 000,000,354 | ---- | M] () -- C:\Windows\tasks\ROC_JAN2013_TB_rmv.job [2013-07-03 19:11:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013-07-03 16:24:02 | 000,034,960 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000001-00000000-00000000-00001102-00000004-00521102}.rfx [2013-07-03 16:24:02 | 000,034,960 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000001-00000000-00000000-00001102-00000004-00521102}.rfx [2013-07-03 16:24:02 | 000,028,848 | ---- | M] () -- C:\Windows\SysNative\BMXCtrlState-{00000001-00000000-00000000-00001102-00000004-00521102}.rfx [2013-07-03 16:24:02 | 000,028,848 | ---- | M] () -- C:\Windows\SysNative\BMXBkpCtrlState-{00000001-00000000-00000000-00001102-00000004-00521102}.rfx [2013-07-03 16:24:02 | 000,011,564 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000001-00000000-00000000-00001102-00000004-00521102}.rfx [2013-07-03 16:23:00 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1177817967-480693648-3998081089-1000UA.job [2013-07-03 16:19:23 | 000,000,000 | ---- | M] () -- C:\autoexec.bat [2013-07-03 16:11:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013-07-03 16:08:53 | 031,367,776 | ---- | M] (Abelssoft ) -- E:\Moje Dokumenty\cryptbox.exe [2013-07-03 16:04:09 | 000,310,953 | ---- | M] () -- E:\Moje Dokumenty\testerm.zip [2013-07-03 15:41:01 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013-07-03 15:31:00 | 000,001,066 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1177817967-480693648-3998081089-1000UA.job [2013-07-03 14:31:00 | 000,001,014 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1177817967-480693648-3998081089-1000Core.job [2013-07-03 10:30:23 | 000,032,032 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013-07-03 10:30:23 | 000,032,032 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013-07-03 10:19:08 | 001,609,586 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013-07-03 10:19:08 | 000,718,692 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2013-07-03 10:19:08 | 000,633,612 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013-07-03 10:19:08 | 000,146,540 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2013-07-03 10:19:08 | 000,114,474 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013-07-02 22:23:00 | 000,001,064 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1177817967-480693648-3998081089-1000Core.job [2013-07-02 15:16:14 | 001,065,984 | ---- | M] () -- C:\Users\nm 8615\AppData\Local\file__0.localstorage [2013-07-01 20:16:51 | 000,000,600 | ---- | M] () -- C:\Users\nm 8615\AppData\Roaming\winscp.rnd [2013-06-30 20:30:46 | 000,006,053 | ---- | M] () -- C:\Users\nm 8615\AppData\Roaming\.ptbt0 [2013-06-30 20:12:50 | 028,484,685 | ---- | M] () -- C:\Windows\IMG_8330-IMG_8333.jpg [2013-06-30 20:01:05 | 033,990,111 | ---- | M] () -- C:\Windows\IMG_7660-IMG_7662.jpg [2013-06-27 20:32:03 | 000,000,886 | ---- | M] () -- C:\Users\Public\Desktop\3DMark Vantage.lnk [2013-06-27 19:40:18 | 000,000,888 | ---- | M] () -- C:\Users\Public\Desktop\PCMark Vantage x64.lnk [2013-06-27 19:40:18 | 000,000,880 | ---- | M] () -- C:\Users\Public\Desktop\PCMark Vantage.lnk [2013-06-27 17:41:43 | 000,000,931 | ---- | M] () -- C:\Users\Public\Desktop\PCMark 7.lnk [2013-06-27 16:16:24 | 000,001,045 | ---- | M] () -- C:\Users\Public\Desktop\Heaven Benchmark 4.0.lnk [2013-06-27 14:59:47 | 001,584,420 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013-06-27 13:57:45 | 000,000,512 | ---- | M] () -- C:\Windows\SysWow64\za_mv_raid.ev [2013-06-27 13:57:34 | 000,027,648 | ---- | M] () -- C:\Windows\SysWow64\freqdb.db [2013-06-27 13:51:24 | 000,001,134 | ---- | M] () -- C:\Users\Public\Desktop\3DMark 11.lnk [2013-06-27 09:16:44 | 000,007,621 | ---- | M] () -- C:\Users\nm 8615\AppData\Local\resmon.resmoncfg [2013-06-26 22:07:42 | 000,000,869 | ---- | M] () -- C:\Users\Public\Desktop\3DMark.lnk [2013-06-26 21:11:23 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2013-06-26 21:11:23 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [1 E:\Moje Dokumenty\*.tmp files -> E:\Moje Dokumenty\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013-07-03 16:19:23 | 000,000,000 | ---- | C] () -- C:\autoexec.bat [2013-07-03 16:04:34 | 000,310,953 | ---- | C] () -- E:\Moje Dokumenty\testerm.zip [2013-06-30 20:30:46 | 000,006,053 | ---- | C] () -- C:\Users\nm 8615\AppData\Roaming\.ptbt0 [2013-06-30 20:11:19 | 028,484,685 | ---- | C] () -- C:\Windows\IMG_8330-IMG_8333.jpg [2013-06-30 19:56:03 | 033,990,111 | ---- | C] () -- C:\Windows\IMG_7660-IMG_7662.jpg [2013-06-27 21:29:33 | 001,065,984 | ---- | C] () -- C:\Users\nm 8615\AppData\Local\file__0.localstorage [2013-06-27 19:40:18 | 000,000,888 | ---- | C] () -- C:\Users\Public\Desktop\PCMark Vantage x64.lnk [2013-06-27 19:40:18 | 000,000,880 | ---- | C] () -- C:\Users\Public\Desktop\PCMark Vantage.lnk [2013-06-27 16:16:24 | 000,001,045 | ---- | C] () -- C:\Users\Public\Desktop\Heaven Benchmark 4.0.lnk [2013-06-27 14:32:35 | 000,020,536 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb [2013-06-27 13:51:24 | 000,001,134 | ---- | C] () -- C:\Users\Public\Desktop\3DMark 11.lnk [2013-06-26 22:07:42 | 000,000,869 | ---- | C] () -- C:\Users\Public\Desktop\3DMark.lnk [2013-05-25 10:19:12 | 000,016,402 | ---- | C] () -- C:\Users\nm 8615\AppData\Roaming\PStrip.bak [2013-05-03 16:35:58 | 000,016,402 | ---- | C] () -- C:\Users\nm 8615\AppData\Roaming\PStrip.ini [2012-12-26 16:22:44 | 000,000,132 | ---- | C] () -- C:\Users\nm 8615\AppData\Roaming\Adobe GIF Format CS5 Prefs [2012-12-23 01:04:14 | 000,000,133 | ---- | C] () -- C:\Windows\SysWow64\mvcli.ini [2012-10-24 11:41:04 | 000,000,406 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2012-09-15 21:48:53 | 000,001,456 | ---- | C] () -- C:\Users\nm 8615\AppData\Local\Adobe Save for Web 12.0 Prefs [2012-08-30 13:47:16 | 000,000,218 | ---- | C] () -- C:\Users\nm 8615\.recently-used.xbel [2012-07-04 22:55:11 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL [2012-07-04 22:55:11 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL [2012-06-23 19:48:53 | 000,010,752 | ---- | C] ( ) -- C:\Windows\SysWow64\a3d.dll [2012-06-22 19:08:23 | 000,002,560 | ---- | C] () -- C:\Windows\SysWow64\CtxfiRes.dll [2012-05-03 15:19:09 | 000,014,747 | ---- | C] () -- C:\Windows\MSTM64_N.INI [2012-05-03 15:19:09 | 000,011,521 | ---- | C] () -- C:\Windows\MSUM64_N.INI [2012-04-19 20:40:25 | 000,000,600 | ---- | C] () -- C:\Users\nm 8615\AppData\Local\PUTTY.RND [2012-04-09 02:09:27 | 000,004,096 | -H-- | C] () -- C:\Users\nm 8615\AppData\Local\keyfile3.drm [2012-04-09 00:29:28 | 001,584,420 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2012-03-22 18:16:23 | 000,000,132 | ---- | C] () -- C:\Users\nm 8615\AppData\Roaming\Adobe PNG Format CS5 Prefs [2012-03-13 14:50:57 | 000,707,504 | ---- | C] () -- C:\Users\nm 8615\AppData\Local\unins000.exe [2012-03-13 13:15:10 | 000,011,761 | ---- | C] () -- C:\Users\nm 8615\AppData\Local\unins000.msg [2012-03-13 13:15:10 | 000,005,821 | ---- | C] () -- C:\Users\nm 8615\AppData\Local\unins000.dat [2012-01-02 21:29:05 | 000,000,029 | ---- | C] () -- C:\Windows\sfbm.INI [2012-01-01 21:26:59 | 000,000,061 | ---- | C] () -- C:\Windows\sbwin.ini [2012-01-01 14:56:30 | 000,000,600 | ---- | C] () -- C:\Users\nm 8615\AppData\Roaming\winscp.rnd [2011-12-29 02:33:46 | 000,644,608 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2011-12-29 02:33:46 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll [2011-12-16 16:49:28 | 000,056,320 | ---- | C] () -- C:\Users\nm 8615\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-12-16 11:13:32 | 000,000,154 | ---- | C] () -- C:\Users\nm 8615\AppData\Roaming\burnaware.ini [2011-12-15 14:27:43 | 000,007,621 | ---- | C] () -- C:\Users\nm 8615\AppData\Local\resmon.resmoncfg [2011-09-28 05:34:47 | 000,000,038 | ---- | C] () -- C:\Windows\mvraidtray.ini [2010-07-03 07:09:16 | 000,012,477 | ---- | C] () -- C:\Users\nm 8615\AppData\Roaming\ShortcutSettings.xml [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012-06-09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2012-08-16 16:26:20 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\.wtw [2012-10-31 22:35:47 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Ashampoo [2011-09-28 04:24:27 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\ASUS WebStorage [2012-12-17 19:00:29 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Babylon [2011-12-20 00:07:47 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\BitTorrent [2011-12-16 20:46:48 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Canneverbe Limited [2012-12-17 19:03:02 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Claro [2012-01-05 21:38:39 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\DAEMON Tools Lite [2012-03-13 14:20:51 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1 [2012-04-19 16:16:11 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Echo Software [2013-02-11 02:17:37 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\EurekaLog [2012-05-03 15:15:09 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Foxit Software [2013-06-04 15:59:18 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\gnupg [2012-08-30 13:46:51 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\gtk-2.0 [2012-10-15 19:48:07 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Gzegzolka XP [2012-02-24 22:56:31 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\IrfanView [2012-04-19 16:24:26 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\JGsoft [2012-12-24 22:51:39 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Kalypso Media [2012-03-18 13:22:30 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\ldw_data [2011-12-16 10:07:05 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Leadertech [2012-07-09 17:36:29 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Leawo [2012-09-15 02:48:15 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Memeo [2012-02-14 23:27:56 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\NapiProjekt [2012-07-25 14:59:14 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Opera [2012-09-26 14:54:09 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\PandoraRecovery [2012-12-20 08:15:03 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\PerformerSoft [2012-04-29 13:52:18 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\PhotoScape [2013-04-08 21:28:11 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\RssBandit [2012-09-15 20:49:11 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 [2012-09-23 15:26:55 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\SystemNucleus [2012-07-09 17:37:16 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\tiger-k [2013-07-03 14:54:34 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Tropico 4 [2012-05-06 02:54:44 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\TrueCrypt [2012-03-20 23:02:07 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\Ulead Systems [2013-07-02 23:48:17 | 000,000,000 | ---D | M] -- C:\Users\nm 8615\AppData\Roaming\uTorrent [color=#E56717]========== Purity Check ==========[/color] < End of report >