Majdanek utworzono 11 lipca 2013 utworzono 11 lipca 2013 Witam. Miałem dzisiaj problem z włączeniem komputera. Posiadam Windows 7 32-bit, przy okienku "Zapraszamy" czekałem kilka minut ale nie udało się ostatecznie włączyć. Wszedłem w tryb awaryjny. W msconfig.exe wyłączyłem dwie usługi : BrowserDefendert i InstallDriver Table Manager, ponieważ uważałem je za zbędne. Komputer włączył się w chwilę, ale dla pewności chcę zrobić skan. Extras.Txt [log] OTL Extras logfile created on: 2013-07-11 15:16:55 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Majdan\Desktop Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 1,81 Gb Available Physical Memory | 60,25% Memory free 5,99 Gb Paging File | 4,61 Gb Available in Paging File | 76,97% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 97,56 Gb Total Space | 56,69 Gb Free Space | 58,11% Space Free | Partition Type: NTFS Drive D: | 368,10 Gb Total Space | 253,59 Gb Free Space | 68,89% Space Free | Partition Type: NTFS Computer Name: MAJDANPC | User Name: Majdan | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days========== Extra Registry (SafeList) ==================== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" http [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software) https [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DisableUnicastResponsesToMulticastBroadcast" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0========== Authorized Applications List ==================== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01A32B32-DE5C-453E-BC98-FDA45EC90D37}" = lport=138 | protocol=17 | dir=in | app=system | "{045DACD4-845E-4BB9-9691-BCEE0C70E870}" = rport=138 | protocol=17 | dir=out | app=system | "{0D7B7171-2EDB-4A12-A77E-ECD8748B3F55}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{1852A73B-D19E-4F08-8819-274A144CC795}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{3BB9708B-F170-4052-AB0F-BA880C46192B}" = rport=137 | protocol=17 | dir=out | app=system | "{4D5618B3-2C64-4593-9F9E-2B4367487C05}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{55A8F5AC-92BA-4711-9645-76349A2944F3}" = rport=445 | protocol=6 | dir=out | app=system | "{59E72CD0-C6AD-4E60-AF75-D79293F418C5}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5BC21369-641D-47E3-B0C3-90664D665E26}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{608846D0-89E9-440F-88A5-AEE4C1051735}" = lport=80 | protocol=6 | dir=in | name=http | "{62BDD38D-BFFD-447C-B336-3C6C2C68AEC1}" = lport=4022 | protocol=6 | dir=in | name=sql service broker | "{6388F3CC-229B-45D4-80E5-E9C786EB36EA}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{67557B06-DF26-4E32-BEE1-ED4257AD1BE9}" = lport=137 | protocol=17 | dir=in | app=system | "{6A088F3C-C885-44DC-A9A0-69C558A8A503}" = lport=445 | protocol=6 | dir=in | app=system | "{6D05614F-A08A-44E0-A347-3CBCA9760075}" = lport=2382 | protocol=6 | dir=in | name=sql browser | "{7D85DB7A-D2A2-467B-824D-4F6E18A72CB3}" = lport=443 | protocol=6 | dir=in | name=ssl | "{7E0391FC-B603-4FE9-93C6-B1433FD335DC}" = lport=2869 | protocol=6 | dir=in | app=system | "{8FEF5802-9B02-416D-BDA8-15BD57592430}" = rport=139 | protocol=6 | dir=out | app=system | "{90C769DF-00DA-41B5-B1E7-6CFF0F571CF1}" = lport=17531 | protocol=6 | dir=in | name=sqlserver | "{932347AC-1D2C-4260-A5B4-CF0A81B57D47}" = lport=10243 | protocol=6 | dir=in | app=system | "{97D13CF8-0D5B-4677-B3B2-A2C92819154F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{992BAD16-A5C6-4F9E-9BDF-6536B821DF2E}" = rport=10243 | protocol=6 | dir=out | app=system | "{A2B27DDD-1DEA-4B7D-B439-E0A83CB7BC65}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{A41F8532-916F-449E-978E-EA559E5D0FE0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{AC51DD64-C8F3-4C91-AE49-8334958881DA}" = lport=135 | protocol=6 | dir=in | name=sql debugger/rpc | "{B99ABDD7-0C45-4BCA-BFED-20761E4DB3BB}" = lport=1434 | protocol=6 | dir=in | name=sql admin connection | "{C3CAF138-393B-46C8-B4A9-825DFD76F89C}" = lport=1433 | protocol=6 | dir=in | name=sqlserver | "{D2C5A692-6A34-4953-9A0B-0FD9EEC4C77B}" = lport=139 | protocol=6 | dir=in | app=system | "{D7EEA2B4-0138-42A2-9CB5-37448E981518}" = lport=2383 | protocol=6 | dir=in | name=analysis services | "{DD78DA30-D37F-4A99-A30D-CAE5C2AE7706}" = lport=1434 | protocol=17 | dir=in | name=sql browser | "{F993E778-9188-4BBB-808D-B28FEB95A750}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0A67BEBF-5B05-47EF-8E05-F10625AD48E5}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{0ECA36C0-B2A9-452E-8620-15B137D85C46}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe | "{11326CC4-251E-45BD-8A8E-F17BA3D88793}" = protocol=6 | dir=in | app=c:\program files\planit\edgecam 2013 r1\cam\tsadmin.exe | "{11F621C8-B4EC-4FD1-8C89-7ABA74AE0532}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{26182186-EDEC-4C79-9D56-AEF5A61ECD72}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe | "{400DBE45-6AA2-4B38-8775-34B21CC75D0E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\half-life\hl.exe | "{452E5703-05F5-4831-9AC7-B04BC8924226}" = protocol=6 | dir=in | app=c:\users\majdan\appdata\roaming\utorrent\utorrent.exe | "{50F6D983-BC98-4115-8625-524E0D199B71}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe | "{5AFA8396-FD39-480E-9EB6-AEFD969B8EBD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{62F643B4-880F-4906-87E5-3F8BC8410FE7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{63F3D6CF-1A18-4C0A-8504-A77B9BA19700}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{67E26B7B-6E10-4FA5-9391-9504A05DAECD}" = dir=in | app=c:\program files\skype\phone\skype.exe | "{7256C197-AA4E-45BA-B020-FB2BAD52DBB8}" = protocol=6 | dir=in | app=d:\gry\fifa 13\game\fifa13.exe | "{7ADF5DB9-8D9A-40D1-B511-659160D5E6CD}" = protocol=17 | dir=in | app=d:\gry\fifa 13\game\fifa13.exe | "{809B4C66-77F1-4D77-B944-627DB4A839A5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8E8FA1C4-1338-4A1B-98EF-1EB5A7AB02AD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\half-life\hl.exe | "{98DBBCA4-0A70-4BFA-B496-5356933015E5}" = protocol=17 | dir=in | app=c:\program files\planit\edgecam 2013 r1\cam\tsadmin.exe | "{9AF69CE5-CD11-40B4-8F4F-846AFD4E235D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{9F68486D-7726-4DEF-9B81-4056C1AAB696}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe | "{A065D216-E79C-46D6-918D-80AD718B7674}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{B0B52A59-C55F-42BA-9CB8-15C2898335B3}" = protocol=17 | dir=in | app=c:\users\majdan\appdata\roaming\utorrent\utorrent.exe | "{B112BCD3-3854-4CE3-9724-B1A04CC14C65}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{BD2447CF-063C-48BC-AA25-96B38A6DB4CC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{C892D948-55A6-4AD3-B336-FE50C2CED28A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{D26D1ADA-6A3B-4F2E-9C26-C8AD2DD1E4CE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{F0EC209B-7641-420E-87E4-090F63287294}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{F48B48FC-72A1-4140-B7A8-D4139C6403CA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{F4AAE921-CBC3-4CB7-8E9B-4BAEBE054509}" = protocol=6 | dir=out | app=system | "{FA34EA15-C54A-4C5A-985B-CADF1A0732E7}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "TCP Query User{1133B705-BF8C-4E9C-8A3F-9FF0D128C30F}D:\gry\football manager 2013 2\fm.exe" = protocol=6 | dir=in | app=d:\gry\football manager 2013 2\fm.exe | "TCP Query User{147DB590-3528-4E05-B0CA-A0BE3CF115E5}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "TCP Query User{AA5E40A3-7258-45C3-A25E-B33A5FA908CE}D:\gry\worms armageddon\wa.exe" = protocol=6 | dir=in | app=d:\gry\worms armageddon\wa.exe | "TCP Query User{C219030B-EC7E-4FA8-BF12-9A7070BEA76D}C:\program files\gadu-gadu 10\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "TCP Query User{D8F5F08C-097A-4674-98D2-0E0703DEA842}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=6 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "UDP Query User{4CE68A99-F361-43C6-897B-FB6633B0EA7D}D:\gry\football manager 2013 2\fm.exe" = protocol=17 | dir=in | app=d:\gry\football manager 2013 2\fm.exe | "UDP Query User{90440CB0-3573-4568-A729-DAF2E0849FF2}D:\gry\worms armageddon\wa.exe" = protocol=17 | dir=in | app=d:\gry\worms armageddon\wa.exe | "UDP Query User{9FDC0820-6FAF-435B-B41D-7A788B0D1CD0}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=17 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe | "UDP Query User{AB1672EF-8805-49EF-870A-CB8C56C3ED8E}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe | "UDP Query User{D284AC22-6AB3-4D8E-B95C-5337773B9C5B}C:\program files\gadu-gadu 10\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu 10\gg.exe |========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0309CEC2-A330-4871-844A-34A46166E0B5}" = EdgeCAM "{031D9000-D719-4D4A-AA21-6A3591ECC613}" = Edgecam 2013 R1 "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{04BDADD5-B981-49DB-90F0-DE11F19C50B4}_is1" = Football Manager 2013 wersja 13.3.3 "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended "{155F4A0E-76ED-45A2-91FB-FF2A2133C31A}" = Risen "{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = BrowserDefender "{310BC5E2-31AF-49BB-904D-E71EB93645DC}" = AI Suite "{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{3282FBE1-35FC-48D8-98CA-115A5EF1F9B4}" = NVIDIA PhysX "{3BDEDA44-E016-4643-A740-68618D8CCFA2}" = Microsoft SQL Server 2008 R2 RsFx Driver "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{47BE41E6-2F0F-4D17-9C2D-3850FFD9D405}" = Microsoft SQL Server VSS Writer "{4C9D82EB-9001-4E59-8F64-0BEEE5F4A30A}" = SQL Server 2008 R2 SP2 Database Engine Shared "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3 "{50BFDB3B-9CA8-477E-82FE-D3CD5F58F8C4}" = Dassault Systemes Software VC9 Prerequisites x86 "{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = SQL Server 2008 R2 SP2 Database Engine Services "{5C19E2DC-4CCF-3114-B40A-6E565987025F}" = Microsoft .NET Framework 4 Extended PLK Language Pack "{5CE55520-DA6D-473D-A1A2-71047C3A3BC5}" = Planit CLS 2013.10 "{604B2A5C-B1CE-45B2-ADCC-6B7C721AC3AC}" = LibreOffice 4.0.1.2 "{6550B835-EEE9-4593-A778-A6CBBEB39AC3}" = "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{7419AE1A-D1A5-4B24-BD78-C7ABCC26016F}" = Microsoft SQL Server 2008 R2 Setup (English) "{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{93998800-1608-403F-9A51-420A77D23C25}" = Sql Server Customer Experience Improvement Program "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9802A536-17E7-46EB-92FE-B8ADA1B23670}" = EdgeCAM Part Modeler V11.0 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A29E18C2-7AB1-4b6b-848C-5D5E2C85F0C0}" = FIFA 13 "{A5C6E3A4-46AE-458C-A767-0E8C7E25C152}" = BrowseToSave "{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.02) "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Sterownik 3D Vision 320.49 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 320.49 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 320.49 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.5 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Sterownik kontrolera 3D Vision 320.49 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.13.0604 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 4.11.9 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Sterownik dźwięku HD 1.3.24.2 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = SQL Server 2008 R2 SP2 Database Engine Services "{BF9BF038-FE03-429D-9B26-2FA0FD756052}" = Microsoft SQL Server Browser "{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}" = "{CACEA8C8-3D38-4F51-953D-1E6FC3346FEF}" = SQL Server 2008 R2 SP2 Common Files "{CC21B1F9-3C33-4B69-AA71-FB2309854079}" = Part Modeler 2013 R1 "{D441BD04-E548-4F8E-97A4-1B66135BAAA8}" = Microsoft SQL Server 2008 Setup Support Files "{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag "{EEB0EFE8-61EB-4C42-929A-CE25D3FBC0C6}" = Microsoft SQL Server 2008 R2 Native Client "{F021CC0C-21C3-4038-AA4A-6E3CBC669CE8}" = SQL Server 2008 R2 SP2 Database Engine Shared "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F48C6EA5-3B43-11D6-86A6-0050BA0259A2}" = ICatch (VI) PC Camera "{FC835376-FF3B-4CAA-83E0-2148B3FB7C98}" = SQL Server 2008 R2 SP2 Common Files "{FE77909E-B782-4554-A92A-4D887CEF0ACC}_is1" = ALLMediaServer "{FEA976C3-31DE-450C-88A5-2A70BDCF0C95}" = SolidLink 2013 R1 "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "AIMP3" = AIMP3 "ALL YouTube Downloader_is1" = ALL YouTube Downloader "ALLPlayer_is1" = ALLPlayer V5.X "Beat Up A Millionaire" = Beat Up A Millionaire "CCleaner" = CCleaner "Cole2k Media - Codec Pack" = Cole2k Media - Codec Pack (Advanced) 8.0.1 "DAEMON Tools Lite" = DAEMON Tools Lite "FormatFactory" = FormatFactory 3.0.1 "Fraps" = Fraps "FreeArc" = FreeArc 0.666 "Gadu-Gadu 10" = Gadu-Gadu 10 "ipla" = ipla 2.6.3 "KLiteCodecPack_is1" = K-Lite Codec Pack 6.2.0 (Basic) "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.75.0.1300 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended "Microsoft SQL Server 10" = Microsoft SQL Server 2008 R2 "Microsoft SQL Server 2008 R2" = Microsoft SQL Server 2008 R2 "MpcStar" = MpcStar 5.4 "NapiProjekt_is1" = NapiProjekt 2.0.0 (build 2151) "NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "OCCT" = OCCT 4.4.0 "Opera 12.16.1860" = Opera 12.16 "Rainbow Sentinel Driver" = Sentinel System Driver "SP_48c708f2" = "Steam App 10" = Counter-Strike "Steam App 207890" = Football Manager 2013 "Tombraider_is1" = Tombraider "uTorrent" = µTorrent "WheelMouse" = 2X-Office 7.80 "yowindow" = YoWindow========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-3327303803-1611631963-2319603381-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "ASUS AI Suite Packages" = ASUS AI Suite Packages========== Last 20 Event Log Errors ========== [ Application Events ] Error - 2013-07-11 09:10:11 | Computer Name = MajdanPC | Source = Windows Search Service | ID = 9000 Description = Error - 2013-07-11 09:10:11 | Computer Name = MajdanPC | Source = Windows Search Service | ID = 7040 Description = Error - 2013-07-11 09:10:11 | Computer Name = MajdanPC | Source = Windows Search Service | ID = 9002 Description = Error - 2013-07-11 09:10:12 | Computer Name = MajdanPC | Source = Windows Search Service | ID = 3029 Description = Error - 2013-07-11 09:10:13 | Computer Name = MajdanPC | Source = Windows Search Service | ID = 3029 Description = Error - 2013-07-11 09:10:13 | Computer Name = MajdanPC | Source = Windows Search Service | ID = 3028 Description = Error - 2013-07-11 09:10:13 | Computer Name = MajdanPC | Source = Windows Search Service | ID = 3058 Description = Error - 2013-07-11 09:10:13 | Computer Name = MajdanPC | Source = Windows Search Service | ID = 7010 Description = Error - 2013-07-11 09:10:13 | Computer Name = MajdanPC | Source = Windows Search Service | ID = 7042 Description = Error - 2013-07-11 09:11:13 | Computer Name = MajdanPC | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 2013-06-28 13:04:18 | Computer Name = MajdanPC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Sentinel z powodu następującego błędu: %%20 Error - 2013-06-29 06:55:53 | Computer Name = MajdanPC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Sentinel z powodu następującego błędu: %%20 Error - 2013-06-29 07:31:49 | Computer Name = MajdanPC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Sentinel z powodu następującego błędu: %%20 Error - 2013-06-29 12:12:26 | Computer Name = MajdanPC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Sentinel z powodu następującego błędu: %%20 Error - 2013-06-30 03:37:30 | Computer Name = MajdanPC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Sentinel z powodu następującego błędu: %%20 Error - 2013-06-30 06:50:23 | Computer Name = MajdanPC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Sentinel z powodu następującego błędu: %%20 Error - 2013-06-30 13:19:08 | Computer Name = MajdanPC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Sentinel z powodu następującego błędu: %%20 Error - 2013-07-01 04:59:54 | Computer Name = MajdanPC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Sentinel z powodu następującego błędu: %%20 Error - 2013-07-01 13:38:21 | Computer Name = MajdanPC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Sentinel z powodu następującego błędu: %%20 Error - 2013-07-01 14:39:06 | Computer Name = MajdanPC | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Sentinel z powodu następującego błędu: %%20 < End of report > [/log] OTL.Txt [log] OTL logfile created on: 2013-07-11 15:16:55 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Majdan\Desktop Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 1,81 Gb Available Physical Memory | 60,25% Memory free 5,99 Gb Paging File | 4,61 Gb Available in Paging File | 76,97% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 97,56 Gb Total Space | 56,69 Gb Free Space | 58,11% Space Free | Partition Type: NTFS Drive D: | 368,10 Gb Total Space | 253,59 Gb Free Space | 68,89% Space Free | Partition Type: NTFS Computer Name: MAJDANPC | User Name: Majdan | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days========== Processes (SafeList) ========== PRC - [2013-07-11 15:15:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Majdan\Desktop\OTL.exe PRC - [2013-07-06 21:57:45 | 000,879,456 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe PRC - [2013-06-21 11:52:52 | 000,875,296 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe PRC - [2013-06-21 11:52:51 | 001,821,984 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe PRC - [2013-06-21 05:15:56 | 000,413,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2013-05-16 16:44:05 | 001,012,000 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe PRC - [2013-05-16 16:38:39 | 001,826,592 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe PRC - [2013-05-16 16:38:28 | 001,213,216 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe PRC - [2013-03-01 16:13:14 | 001,705,416 | ---- | M] (AIMP DevTeam) -- C:\Program Files\AIMP3\AIMP3.exe PRC - [2013-01-08 10:40:56 | 002,610,896 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe PRC - [2012-12-18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012-10-09 13:12:24 | 001,417,216 | ---- | M] (Planit Software Limited) -- C:\Program Files\Common Files\Planit\2013.10\cls\cls.exe PRC - [2011-08-09 10:56:04 | 000,947,328 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\ASUS\AAHM\1.00.16\aaHMSvc.exe PRC - [2011-05-11 17:44:06 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010-11-20 23:29:19 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2010-11-20 23:29:07 | 000,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe PRC - [2010-01-13 18:39:32 | 000,630,400 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\ASUS\AASP\1.01.04\aaCenter.exe PRC - [2009-03-27 22:08:14 | 001,431,040 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe PRC - [2009-01-22 20:43:54 | 001,352,704 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\EnergySaving\PwSave.exe PRC - [2008-01-09 10:17:18 | 000,627,200 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe PRC - [2007-02-10 22:07:30 | 000,241,664 | ---- | M] (A4Tech Co.,Ltd.) -- C:\Program Files\A4Tech\Mouse\Amoumain.exe PRC - [2006-11-16 20:24:20 | 000,633,856 | ---- | M] (Pathtrace) -- C:\Program Files\EdgeCAM\Cam\edgecls.exe========== Modules (No Company Name) ========== MOD - [2013-06-12 00:52:33 | 016,033,160 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_7_700_224.dll MOD - [2013-05-23 11:09:01 | 002,521,040 | ---- | M] () -- c:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll MOD - [2013-03-02 22:55:41 | 014,415,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\246f1a5abb686b9dcdf22d3505b08cea\mscorlib.ni.dll MOD - [2013-03-01 16:13:15 | 000,220,672 | ---- | M] () -- C:\Program Files\AIMP3\Modules\MACDll.dll MOD - [2013-03-01 16:13:15 | 000,155,648 | ---- | M] () -- C:\Program Files\AIMP3\Modules\libFLAC.dll MOD - [2013-03-01 16:13:14 | 001,733,120 | ---- | M] () -- C:\Program Files\AIMP3\Modules\aimp_libvorbis.dll MOD - [2013-03-01 16:13:14 | 000,475,136 | ---- | M] () -- C:\Program Files\AIMP3\sqlite3.dll MOD - [2013-03-01 16:13:14 | 000,237,568 | ---- | M] () -- C:\Program Files\AIMP3\Plugins\OptimFROG.dll MOD - [2013-03-01 16:13:14 | 000,131,016 | ---- | M] () -- C:\Program Files\AIMP3\Plugins\PandemicAnalogMeter.dll MOD - [2013-03-01 16:13:14 | 000,058,824 | ---- | M] () -- C:\Program Files\AIMP3\Plugins\aimp_lastfm.dll MOD - [2013-03-01 16:13:14 | 000,026,624 | ---- | M] () -- C:\Program Files\AIMP3\Plugins\Aorta.svp MOD - [2012-12-03 22:43:06 | 000,037,376 | R--- | M] () -- C:\Program Files\Common Files\Planit\2013.10\Language\pl-PL\lic_res.dll MOD - [2012-12-03 22:43:06 | 000,029,696 | R--- | M] () -- C:\Program Files\Common Files\Planit\2013.10\Language\pl-PL\cls_res.dll MOD - [2012-10-09 13:08:18 | 000,339,968 | ---- | M] () -- C:\Program Files\Common Files\Planit\2013.10\cls\Utilities.dll MOD - [2012-10-09 13:07:58 | 000,055,808 | ---- | M] () -- C:\Program Files\Common Files\Planit\2013.10\cls\platform.dll MOD - [2009-09-30 12:33:08 | 000,024,576 | ---- | M] () -- C:\Windows\System32\AsIO.dll MOD - [2009-04-13 11:37:34 | 000,188,928 | ---- | M] () -- C:\Program Files\ASUS\AASP\1.01.04\aasp.dll MOD - [2009-03-27 22:08:14 | 001,431,040 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe MOD - [2009-01-22 20:43:54 | 001,352,704 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\EnergySaving\PwSave.exe MOD - [2009-01-22 20:43:54 | 000,409,088 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\EnergySaving\AnimationView.dll MOD - [2008-02-25 15:08:54 | 000,208,896 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiNap\AiNap.dll MOD - [2008-01-17 17:46:20 | 000,053,248 | ---- | M] () -- C:\Program Files\ASUS\AASP\1.01.04\cpuutil.dll MOD - [2008-01-09 10:17:18 | 000,627,200 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe MOD - [2007-01-03 22:25:56 | 000,008,704 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiNap\vvc.dll MOD - [2005-06-22 18:39:56 | 000,204,851 | ---- | M] () -- C:\Program Files\ASUS\AASP\1.01.04\PowerDll.dll========== Services (SafeList) ========== SRV - [2013-06-21 05:15:56 | 000,413,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2013-06-12 00:52:34 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013-06-07 00:06:24 | 000,543,656 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2013-05-23 11:09:59 | 002,827,728 | ---- | M] () [Disabled | Stopped] -- C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe -- (BrowserDefendert) SRV - [2013-05-16 16:38:39 | 001,826,592 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2013-03-01 23:28:33 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2013-02-28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012-12-18 21:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011-08-09 10:56:04 | 000,947,328 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Program Files\ASUS\AAHM\1.00.16\aaHMSvc.exe -- (asHmComSvc) SRV - [2009-07-14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009-07-14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009-07-14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009-07-14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)========== Driver Services (SafeList) ========== DRV - File not found [Kernel | System | Stopped] -- system32\DRIVERS\EIO.sys -- (EIO) DRV - [2013-06-21 14:02:43 | 009,069,344 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2013-06-15 15:12:58 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2013-06-15 15:12:57 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2013-03-01 22:20:29 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2013-02-25 07:27:46 | 000,154,400 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA) DRV - [2012-06-29 02:24:02 | 000,249,288 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\System32\drivers\RsFx0153.sys -- (RsFx0153) DRV - [2010-11-20 23:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010-11-20 23:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010-11-20 23:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc) DRV - [2010-11-20 23:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010-11-20 23:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010-11-20 23:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD) DRV - [2010-11-20 23:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010-11-20 23:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2010-08-24 15:31:08 | 000,011,456 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\AsIO.sys -- (AsIO) DRV - [2009-07-16 12:36:30 | 000,013,216 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor) DRV - [2009-07-14 01:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | System | Running] -- C:\Windows\System32\drivers\serial.sys -- (Serial) DRV - [2009-07-14 00:02:53 | 000,311,296 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7) DRV - [2007-09-10 08:50:56 | 000,457,984 | ---- | M] (PixArt Imaging Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PAC7302.SYS -- (PAC7302) DRV - [2007-02-10 23:55:50 | 000,013,824 | ---- | M] (A4Tech Co.,Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Amusbprt.sys -- (Amusbprt) DRV - [2007-02-10 02:04:50 | 000,014,336 | ---- | M] (A4Tech Co.,Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Amps2prt.sys -- (Amps2prt) DRV - [2007-01-24 17:46:48 | 000,008,704 | ---- | M] (A4Tech Co.,Ltd.) [Kernel | System | Running] -- C:\Windows\System32\drivers\Amfilter.sys -- (Amfilter) DRV - [2006-06-12 17:53:28 | 000,076,288 | ---- | M] (Rainbow Technologies, Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\SENTINEL.SYS -- (Sentinel) DRV - [2004-07-14 13:54:42 | 000,676,864 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hardlock.sys -- (Hardlock)========== Standard Registry (SafeList) ==================== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3327303803-1611631963-2319603381-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=4E620022151BE8DE&affID=119357&tsp=4939 IE - HKU\S-1-5-21-3327303803-1611631963-2319603381-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=4E620022151BE8DE&affID=119357&tsp=4939 IE - HKU\S-1-5-21-3327303803-1611631963-2319603381-1000\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-3327303803-1611631963-2319603381-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3327303803-1611631963-2319603381-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-3327303803-1611631963-2319603381-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=4E620022151BE8DE&affID=119357&tsp=4939 IE - HKU\S-1-5-21-3327303803-1611631963-2319603381-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) [2013-03-01 17:10:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Majdan\AppData\Roaming\mozilla\Extensions [2013-07-10 20:57:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions========== Chrome ========== CHR - Extension: No name found = C:\Users\Majdan\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdbbihlhhhlgjmoigeejldakgahjgpid\1\ CHR - Extension: No name found = C:\Users\Majdan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pffiomdhflpmcjlihjphhnffjgcogkmd\1\ O1 HOSTS File: ([2009-06-10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (ALLYouTubeDownloader) - {61DB16C5-B733-43F4-872E-B20DC9E72740} - C:\Program Files\ALLYouTubeDownloader\ALLYouTubeDownloader.dll (ALLCinema Ltd.) O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\Program Files\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) O4 - HKLM..\Run: [Ai Nap] C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe () O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe () O4 - HKLM..\Run: [CPU Power Monitor] C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe () O4 - HKLM..\Run: [Nvtmru] C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation) O4 - HKLM..\Run: [QFan Help] C:\Program Files\ASUS\AI Suite\QFan3\QFanHelp.exe () O4 - HKLM..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-3327303803-1611631963-2319603381-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - Startup: C:\Users\Majdan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cls — skrót.lnk = C:\Program Files\Common Files\Planit\2013.10\cls\cls.exe (Planit Software Limited) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\S-1-5-21-3327303803-1611631963-2319603381-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-3327303803-1611631963-2319603381-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKU\S-1-5-21-3327303803-1611631963-2319603381-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O13 - gopher Prefix: missing O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.113.224.36 217.113.224.134 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7B076471-C905-483B-88B6-9E2B311E1359}: DhcpNameServer = 217.113.224.36 217.113.224.134 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - AppInit_DLLs: (c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll () O20 - AppInit_DLLs: (c:\progra~1\browse~1\sprote~1.dll) - c:\Program Files\BrowseToSave\sprotector.dll () O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-06-10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)========== Files/Folders - Created Within 30 Days ========== [2013-07-11 15:18:15 | 000,000,000 | ---D | C] -- C:\Users\Majdan\Desktop\gmer [2013-07-11 15:15:29 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Majdan\Desktop\OTL.exe [2013-07-10 21:37:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS [2013-07-10 21:29:04 | 000,000,000 | ---D | C] -- C:\Users\Majdan\AppData\Roaming\0U1E1Q1T2Z1P0S2Z1T1C [2013-07-10 21:28:57 | 000,000,000 | ---D | C] -- C:\Users\Majdan\AppData\Roaming\Funmoods [2013-07-10 21:11:18 | 000,016,896 | ---- | C] (ASUS) -- C:\Windows\AsTaskSched.dll [2013-07-10 21:08:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MpcStar [2013-07-10 20:58:19 | 000,000,000 | ---D | C] -- C:\Windows\System32\searchplugins [2013-07-10 20:58:19 | 000,000,000 | ---D | C] -- C:\Windows\System32\Extensions [2013-07-10 20:58:19 | 000,000,000 | ---D | C] -- C:\Users\Majdan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender [2013-07-10 20:58:12 | 000,000,000 | ---D | C] -- C:\ProgramData\BrowserDefender [2013-07-10 20:57:11 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013-07-10 20:56:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon [2013-07-10 20:56:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer [2013-07-10 20:56:06 | 000,000,000 | ---D | C] -- C:\Users\Majdan\AppData\Roaming\Babylon [2013-07-09 10:46:19 | 000,000,000 | ---D | C] -- C:\Program Files\AGEIA Technologies [2013-07-09 10:43:46 | 021,102,368 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll [2013-07-09 10:43:46 | 017,560,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll [2013-07-09 10:43:46 | 009,069,344 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys [2013-07-09 10:43:46 | 007,687,592 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll [2013-07-09 10:43:46 | 006,324,360 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvopencl.dll [2013-07-09 10:43:46 | 002,777,888 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll [2013-07-09 10:43:46 | 002,002,720 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll [2013-07-09 10:43:46 | 001,024,288 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco3232049.dll [2013-07-09 10:43:46 | 000,893,728 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispgenco3232049.dll [2013-07-09 10:43:46 | 000,467,232 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\NvIFR.dll [2013-07-09 10:43:46 | 000,465,184 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\NvFBC.dll [2013-07-09 10:43:46 | 000,214,448 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvinit.dll [2013-07-09 10:43:46 | 000,181,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvoglshim32.dll [2013-06-27 12:46:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQUARE ENIX [2013-06-26 17:53:43 | 000,000,000 | ---D | C] -- C:\Users\Majdan\AppData\Roaming\ipla [2013-06-26 17:53:43 | 000,000,000 | ---D | C] -- C:\ProgramData\ipla [2013-06-26 17:53:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack [2013-06-26 17:53:41 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack [2013-06-26 17:52:53 | 000,000,000 | ---D | C] -- C:\ProgramData\RDRM [2013-06-26 17:52:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ipla [2013-06-26 17:52:38 | 000,000,000 | ---D | C] -- C:\Program Files\ipla [2013-06-26 17:52:28 | 001,060,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc71.dll [2013-06-21 05:16:02 | 000,566,048 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvStreaming.exe [2013-06-20 17:09:36 | 000,000,000 | ---D | C] -- C:\Users\Majdan\Documents\a [2013-06-16 15:19:11 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Sports Interactive [2013-06-16 15:19:11 | 000,000,000 | ---D | C] -- C:\Users\Majdan\Documents\Sports Interactive [2013-06-16 13:21:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Football Manager 2013 [2013-06-16 12:45:00 | 000,000,000 | ---D | C] -- C:\Users\Majdan\AppData\Local\Risen [2013-06-16 11:27:04 | 000,000,000 | ---D | C] -- C:\Users\Majdan\Documents\CPY_SAVES [2013-06-15 15:12:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard [2013-06-15 12:44:31 | 000,000,000 | ---D | C] -- C:\Program Files\Airline 69 II [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]========== Files - Modified Within 30 Days ========== [2013-07-11 15:15:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Majdan\Desktop\OTL.exe [2013-07-11 15:14:21 | 000,802,554 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2013-07-11 15:14:21 | 000,716,762 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2013-07-11 15:14:21 | 000,178,492 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2013-07-11 15:14:21 | 000,144,944 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2013-07-11 15:09:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013-07-11 15:09:20 | 2415,222,784 | -HS- | M] () -- C:\hiberfil.sys [2013-07-11 13:50:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013-07-10 21:11:18 | 000,016,896 | ---- | M] (ASUS) -- C:\Windows\AsTaskSched.dll [2013-07-10 21:08:37 | 000,000,953 | ---- | M] () -- C:\Users\Public\Desktop\MpcStar.lnk [2013-07-10 20:37:34 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2013-07-10 20:37:34 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2013-07-08 11:52:48 | 000,016,656 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013-07-08 11:52:47 | 000,016,656 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013-06-29 01:05:40 | 000,000,640 | RHS- | M] () -- C:\Users\Majdan\ntuser.pol [2013-06-27 12:46:33 | 000,000,708 | ---- | M] () -- C:\Users\Public\Desktop\Tombraider.lnk [2013-06-26 17:52:54 | 000,000,913 | ---- | M] () -- C:\Users\Public\Desktop\ipla.lnk [2013-06-26 17:52:28 | 001,060,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfc71.dll [2013-06-25 09:33:13 | 000,000,212 | ---- | M] () -- C:\Users\Majdan\Desktop\Counter-Strike.url [2013-06-21 14:02:43 | 021,102,368 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll [2013-06-21 14:02:43 | 017,560,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll [2013-06-21 14:02:43 | 013,411,896 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvwgf2um.dll [2013-06-21 14:02:43 | 012,427,240 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvd3dum.dll [2013-06-21 14:02:43 | 009,069,344 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys [2013-06-21 14:02:43 | 007,687,592 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll [2013-06-21 14:02:43 | 006,324,360 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvopencl.dll [2013-06-21 14:02:43 | 002,777,888 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll [2013-06-21 14:02:43 | 002,597,856 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvapi.dll [2013-06-21 14:02:43 | 002,002,720 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll [2013-06-21 14:02:43 | 001,024,288 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco3232049.dll [2013-06-21 14:02:43 | 000,925,648 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvumdshim.dll [2013-06-21 14:02:43 | 000,893,728 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvdispgenco3232049.dll [2013-06-21 14:02:43 | 000,467,232 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\NvIFR.dll [2013-06-21 14:02:43 | 000,465,184 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\NvFBC.dll [2013-06-21 14:02:43 | 000,214,448 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvinit.dll [2013-06-21 14:02:43 | 000,181,488 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvoglshim32.dll [2013-06-21 14:02:43 | 000,016,437 | ---- | M] () -- C:\Windows\System32\nvinfo.pb [2013-06-21 11:52:51 | 004,192,544 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcpl.dll [2013-06-21 11:52:51 | 003,045,664 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvsvc.dll [2013-06-21 11:52:48 | 002,555,168 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvsvcr.dll [2013-06-21 11:52:48 | 000,062,752 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvshext.dll [2013-06-21 11:52:47 | 000,223,008 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvmctray.dll [2013-06-21 05:16:02 | 000,566,048 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvStreaming.exe [2013-06-19 18:14:17 | 003,253,909 | ---- | M] () -- C:\Windows\System32\nvcoproc.bin [2013-06-16 22:53:01 | 000,000,000 | ---- | M] () -- C:\Windows\pcvcdvw.INI [2013-06-16 22:53:00 | 000,000,062 | ---- | M] () -- C:\Windows\pcvcdbr.INI [2013-06-16 13:21:40 | 000,000,753 | ---- | M] () -- C:\Users\Public\Desktop\Football Manager 2013.lnk [2013-06-15 15:13:06 | 000,000,354 | ---- | M] () -- C:\Users\Majdan\Desktop\Risen.lnk [2013-06-15 15:12:58 | 000,281,760 | ---- | M] () -- C:\Windows\System32\drivers\atksgt.sys [2013-06-15 15:12:57 | 000,025,888 | ---- | M] () -- C:\Windows\System32\drivers\lirsgt.sys [2013-06-12 15:34:00 | 018,200,824 | ---- | M] () -- C:\Users\Majdan\Documents\LG-E400_POL_UG_Web_V1.1_121221.pdf [2013-06-12 00:52:33 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2013-06-12 00:52:33 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2013-06-11 23:38:29 | 000,088,763 | ---- | M] () -- C:\Users\Majdan\Documents\b.pdf [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]========== Files Created - No Company Name ========== [2013-07-11 15:05:22 | 000,001,911 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\EdgeCLS11.00.lnk [2013-07-11 15:05:21 | 000,014,107 | ---- | C] () -- C:\Users\Majdan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cls — skrót.lnk [2013-07-10 21:37:31 | 000,011,832 | ---- | C] () -- C:\Windows\System32\drivers\AsInsHelp64.sys [2013-07-10 21:37:31 | 000,010,216 | ---- | C] () -- C:\Windows\System32\drivers\AsInsHelp32.sys [2013-07-10 21:08:37 | 000,000,953 | ---- | C] () -- C:\Users\Public\Desktop\MpcStar.lnk [2013-07-10 20:37:34 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS [2013-07-10 20:37:34 | 000,000,000 | RHS- | C] () -- C:\IO.SYS [2013-06-29 01:05:40 | 000,000,640 | RHS- | C] () -- C:\Users\Majdan\ntuser.pol [2013-06-27 12:46:33 | 000,000,708 | ---- | C] () -- C:\Users\Public\Desktop\Tombraider.lnk [2013-06-26 17:53:42 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll [2013-06-26 17:52:54 | 000,000,913 | ---- | C] () -- C:\Users\Public\Desktop\ipla.lnk [2013-06-25 09:33:13 | 000,000,212 | ---- | C] () -- C:\Users\Majdan\Desktop\Counter-Strike.url [2013-06-16 22:53:01 | 000,000,000 | ---- | C] () -- C:\Windows\pcvcdvw.INI [2013-06-16 22:53:00 | 000,000,062 | ---- | C] () -- C:\Windows\pcvcdbr.INI [2013-06-16 13:21:40 | 000,000,753 | ---- | C] () -- C:\Users\Public\Desktop\Football Manager 2013.lnk [2013-06-15 15:13:06 | 000,000,354 | ---- | C] () -- C:\Users\Majdan\Desktop\Risen.lnk [2013-06-15 15:12:58 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys [2013-06-15 15:12:57 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys [2013-06-12 15:25:38 | 018,200,824 | ---- | C] () -- C:\Users\Majdan\Documents\LG-E400_POL_UG_Web_V1.1_121221.pdf [2013-06-11 23:38:29 | 000,088,763 | ---- | C] () -- C:\Users\Majdan\Documents\b.pdf [2013-04-22 23:37:17 | 000,031,784 | ---- | C] () -- C:\Windows\Ascd_tmp.ini [2013-04-12 20:02:44 | 000,118,784 | ---- | C] () -- C:\Windows\ShowBmp.exe [2013-04-12 20:02:44 | 000,014,385 | ---- | C] () -- C:\Windows\Tw561a.ini [2013-04-12 20:02:44 | 000,000,081 | ---- | C] () -- C:\Windows\Setup8a.ini [2013-03-25 20:18:26 | 000,023,040 | ---- | C] () -- C:\Windows\System32\echelp.exe [2013-03-21 21:51:46 | 000,000,155 | ---- | C] () -- C:\Windows\peps.ini [2013-03-15 21:01:22 | 000,258,048 | ---- | C] () -- C:\Windows\System32\libFLAC.dll [2013-03-13 19:40:29 | 000,024,576 | ---- | C] () -- C:\Windows\System32\AsIO.dll [2013-03-13 19:40:29 | 000,011,456 | ---- | C] () -- C:\Windows\System32\drivers\AsIO.sys [2013-03-13 19:40:11 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini [2013-03-13 19:40:06 | 000,013,216 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys [2013-03-02 23:09:36 | 000,000,000 | ---- | C] () -- C:\Windows\Licenses.INI [2013-03-01 23:07:12 | 000,032,101 | ---- | C] () -- C:\Windows\Ascd_log.ini [2013-03-01 22:42:43 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat [2013-03-01 16:26:19 | 003,253,909 | ---- | C] () -- C:\Windows\System32\nvcoproc.bin [2012-09-15 17:16:46 | 000,039,904 | ---- | C] () -- C:\Windows\System32\dischandler.exe [2012-09-06 21:06:08 | 003,915,776 | ---- | C] () -- C:\Windows\System32\ffmpeg.dll [2012-09-06 21:05:16 | 000,112,640 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2012-09-06 21:04:38 | 000,271,360 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll [2012-09-06 21:04:18 | 000,157,184 | ---- | C] () -- C:\Windows\System32\ff_unrar.dll [2012-09-06 21:04:18 | 000,099,840 | ---- | C] () -- C:\Windows\System32\ff_wmv9.dll [2012-09-06 21:04:16 | 000,147,456 | ---- | C] () -- C:\Windows\System32\ff_libmad.dll [2012-09-06 21:04:14 | 001,525,760 | ---- | C] () -- C:\Windows\System32\ff_samplerate.dll [2012-09-06 21:04:14 | 000,211,968 | ---- | C] () -- C:\Windows\System32\ff_libdts.dll [2012-09-06 21:04:14 | 000,114,688 | ---- | C] () -- C:\Windows\System32\ff_liba52.dll [2012-09-06 21:04:12 | 000,330,240 | ---- | C] () -- C:\Windows\System32\ff_libfaad2.dll [2012-07-27 18:40:08 | 000,000,178 | ---- | C] () -- C:\Windows\System32\Formats.ini [2012-07-19 20:56:08 | 000,172,544 | ---- | C] () -- C:\Windows\System32\libbluray.dll [2012-07-19 20:56:02 | 006,894,331 | ---- | C] () -- C:\Windows\System32\avcodec-lav-54.dll [2012-07-19 20:56:02 | 001,111,581 | ---- | C] () -- C:\Windows\System32\avformat-lav-54.dll [2012-07-19 20:56:02 | 000,401,685 | ---- | C] () -- C:\Windows\System32\swscale-lav-2.dll [2012-07-19 20:56:02 | 000,232,895 | ---- | C] () -- C:\Windows\System32\avutil-lav-51.dll [2012-07-19 20:56:02 | 000,162,743 | ---- | C] () -- C:\Windows\System32\avfilter-lav-3.dll [2012-07-19 20:56:02 | 000,101,820 | ---- | C] () -- C:\Windows\System32\avresample-lav-0.dll [2012-06-17 23:15:04 | 000,198,144 | ---- | C] () -- C:\Windows\System32\spdif_test.exe [2012-06-17 23:14:58 | 000,097,792 | ---- | C] () -- C:\Windows\System32\ac3config.exe [2012-06-17 23:14:42 | 001,021,440 | ---- | C] () -- C:\Windows\System32\ac3filter_intl.dll [2012-05-13 00:42:16 | 001,272,320 | ---- | C] () -- C:\Windows\System32\avcodec-53.dll [2012-05-13 00:42:16 | 000,146,432 | ---- | C] () -- C:\Windows\System32\avutil-51.dll [2011-12-07 21:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\System32\Lagarith.dll [2011-09-08 16:00:52 | 000,150,528 | ---- | C] () -- C:\Windows\System32\mkx.dll [2011-09-08 16:00:48 | 000,142,336 | ---- | C] () -- C:\Windows\System32\mp4.dll [2011-09-08 16:00:42 | 000,123,392 | ---- | C] () -- C:\Windows\System32\ogm.dll [2011-09-08 16:00:38 | 000,249,856 | ---- | C] () -- C:\Windows\System32\dxr.dll [2011-09-08 16:00:34 | 000,113,152 | ---- | C] () -- C:\Windows\System32\dsmux.exe [2011-09-08 16:00:24 | 000,154,624 | ---- | C] () -- C:\Windows\System32\ts.dll [2011-09-08 16:00:10 | 000,137,728 | ---- | C] () -- C:\Windows\System32\mkv2vfr.exe [2011-09-08 16:00:06 | 000,358,400 | ---- | C] () -- C:\Windows\System32\gdsmux.exe [2011-09-08 15:59:54 | 000,080,384 | ---- | C] () -- C:\Windows\System32\mkzlib.dll [2011-09-08 15:59:52 | 000,024,576 | ---- | C] () -- C:\Windows\System32\mkunicode.dll========== ZeroAccess Check ========== [2009-07-14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2010-11-20 23:29:11 | 012,872,192 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 23:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both========== LOP Check ========== [2013-07-10 21:29:04 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\0U1E1Q1T2Z1P0S2Z1T1C [2013-07-11 15:20:20 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\AIMP3 [2013-03-09 11:47:30 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\Auslogics [2013-07-10 20:56:06 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\Babylon [2013-03-09 11:51:28 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\CometPlayer [2013-07-11 14:47:36 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\DAEMON Tools Lite [2013-03-25 20:19:47 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\DassaultSystemes [2013-03-01 17:41:22 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\eDownload [2013-05-30 11:37:02 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\FreeArc [2013-07-10 21:28:57 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\Funmoods [2013-03-01 18:07:55 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\Gadu-Gadu 10 [2013-03-01 17:16:00 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\GG [2013-07-09 22:19:27 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\ipla [2013-03-21 19:35:54 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\LibreOffice [2013-05-03 21:36:38 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\NapiProjekt [2013-06-06 20:02:52 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\Need for Speed World [2013-03-09 10:12:38 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\OpenFM [2013-03-01 15:53:09 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\Opera [2013-05-26 00:35:55 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\Origin [2013-03-08 11:40:50 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\Sports Interactive [2013-03-09 11:54:39 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\tigerplayer [2013-07-11 14:47:36 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\uTorrent [2013-05-02 12:12:01 | 000,000,000 | ---D | M] -- C:\Users\Majdan\AppData\Roaming\YoWindow========== Purity Check ========== < End of report > [/log] Gmer [log] GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-07-11 15:27:07 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-4 ST3500320AS rev.SD15 465,76GB Running: gmer.exe; Driver: C:\Users\Majdan\AppData\Local\Temp\uxloypob.sys ---- Kernel code sections - GMER 2.1 ---- .text ntoskrnl.exe!ZwSaveKey + 13CD 83075A09 1 Byte [06] .text ntoskrnl.exe!KiDispatchInterrupt + 5A2 83095512 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0xA1482300, 0x3B6D8, 0xE8000020] .text C:\Windows\system32\drivers\hardlock.sys section is writeable [0xA14C5400, 0x82482, 0xE8000020] .protect˙˙˙˙hardlockentry point in ".protect˙˙˙˙hardlockentry point in ".protect˙˙˙˙hardlockentry point in ".p" section [0xA1565420] C:\Windows\system32\drivers\hardlock.sys entry point in ".protect˙˙˙˙hardlockentry point in ".protect˙˙˙˙hardlockentry point in ".p" section [0xA1565420] .protect˙˙˙˙hardlockunknown last code section [0xA1565200, 0x5105, 0xE0000020] C:\Windows\system32\drivers\hardlock.sys unknown last code section [0xA1565200, 0x5105, 0xE0000020] .text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0xA1595300, 0x1BEE, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\wbem\wmiprvse.exe[388] USER32.dll!DialogBoxParamW 772C564A 5 Bytes JMP 753D4970 c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text C:\Program Files\Microsoft SQL Server\MSSQL10_50.ECSQLEXPRESS\MSSQL\Binn\sqlservr.exe[432] USER32.dll!DialogBoxParamW 772C564A 5 Bytes JMP 753D4970 c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text C:\Windows\system32\wininit.exe[448] USER32.dll!DialogBoxParamW 772C564A 5 Bytes JMP 753D4970 c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text C:\Windows\system32\winlogon.exe[488] USER32.dll!DialogBoxParamW 772C564A 5 Bytes JMP 753D4970 c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text C:\Windows\system32\services.exe[548] USER32.dll!DialogBoxParamW 772C564A 5 Bytes JMP 753D4970 c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll .text ... ---- User IAT/EAT - GMER 2.1 ---- IAT C:\Windows\system32\winlogon.exe[488] @ C:\Windows\system32\winlogon.exe [ntdll.dll!NtClose] [753DE470] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\winlogon.exe[488] @ C:\Windows\system32\winlogon.exe [KERNEL32.dll!LoadLibraryW] [753DA420] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtDeleteFile] [753DA6F0] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtQueryInformationFile] [753D9E10] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtSetInformationFile] [753DA740] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtDeleteKey] [753DE4F0] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtOpenKey] [753DE3B0] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtEnumerateKey] [753DE180] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtDeleteValueKey] [753DE540] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtSetValueKey] [753DE2D0] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtQueryValueKey] [753DE260] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtCreateKey] [753DE340] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtOpenFile] [753DA590] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtQueryKey] [753D9DD0] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\services.exe [ntdll.dll!NtClose] [753DE470] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [KERNEL32.dll!LoadLibraryW] [753DA420] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [KERNEL32.dll!LoadLibraryA] [753DA3D0] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [ntdll.dll!NtClose] [753DE470] c:\progra~2\browse~1\261339~1.144\{c16c1~1\browse~1.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73DB2437] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73D95600] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73D956BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73DB24B2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73DA8514] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73DA4CC8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73DA506F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73DA5144] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [73DA6671] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73DA826B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73DA87BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73DA901B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73DAE1BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll IAT C:\Windows\Explorer.EXE[1844] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73DA4BFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll ---- Devices - GMER 2.1 ---- AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys ---- EOF - GMER 2.1 ---- [/log]
Zayfi komentarz 11 lipca 2013 komentarz 11 lipca 2013 Odinstaluj Browser defender /BrowseToSave z panelu programów. Odnośnie tego to tu masz wątek, usługa systemowa Instalator modułow systemu Windows > domyslnie powinna być ustawiona na Ręcznym http://windows7forum.pl/wylaczenie-automatycznej-instalacji-sterownikow-8688-t Pobierz AdWCleaner i wykonaj nim skan > przedstaw raport http://general-changelog-team.fr/outils/289-adwcleaner 1
Majdanek komentarz 11 lipca 2013 Autor komentarz 11 lipca 2013 [log] # AdwCleaner v2.304 - Log utworzony 11/07/2013 o 16:30:56 # Aktualizacja 03/07/2013 przez Xplode # System operacyjny : Windows 7 Professional Service Pack 1 (32 bits) # Użytkownik : Majdan - MAJDANPC # Tryb uruchomienia : Normalny # Ścieżka : C:\Users\Majdan\Desktop\AdwCleaner.exe # Opcja [Szukaj] ***** [Usługi] ***** ***** [Pliki / Foldery] ***** Folder Znaleziono : C:\ProgramData\Babylon Folder Znaleziono : C:\ProgramData\Beroowse22suavee Folder Znaleziono : C:\ProgramData\boost_interprocess Folder Znaleziono : C:\ProgramData\BrowserDefender Folder Znaleziono : C:\ProgramData\InstallMate Folder Znaleziono : C:\ProgramData\SoftSafe Folder Znaleziono : C:\ProgramData\Tarma Installer Folder Znaleziono : C:\Users\Majdan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pffiomdhflpmcjlihjphhnffjgcogkmd Folder Znaleziono : C:\Users\Majdan\AppData\Roaming\Babylon Folder Znaleziono : C:\Users\Majdan\AppData\Roaming\eDownload Folder Znaleziono : C:\Users\Majdan\AppData\Roaming\Funmoods ***** [Rejestr] ***** Klucz Znaleziono : HKCU\Software\APN PIP Klucz Znaleziono : HKCU\Software\AppDataLow\SProtector Klucz Znaleziono : HKCU\Software\BabSolution Klucz Znaleziono : HKCU\Software\DataMngr Klucz Znaleziono : HKCU\Software\Funmoods Klucz Znaleziono : HKCU\Software\InstallCore Klucz Znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Klucz Znaleziono : HKCU\Software\UpdateStar Klucz Znaleziono : HKLM\SOFTWARE\5f53d8dbb139eb10 Klucz Znaleziono : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Klucz Znaleziono : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Klucz Znaleziono : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Klucz Znaleziono : HKLM\SOFTWARE\Classes\Prod.cap Klucz Znaleziono : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Klucz Znaleziono : HKLM\Software\DataMngr Klucz Znaleziono : HKLM\Software\InstallCore Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C87FC351-A80D-43E9-9A86-CF1E29DC443A} Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASAPI32 Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASMANCS Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32 Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Funmoods Klucz Znaleziono : HKLM\Software\PIP Klucz Znaleziono : HKLM\SOFTWARE\Software Klucz Znaleziono : HKLM\Software\SP Global Klucz Znaleziono : HKLM\Software\SProtector Klucz Znaleziono : HKLM\Software\Tarma Installer Klucz Znaleziono : HKU\S-1-5-21-3327303803-1611631963-2319603381-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} ***** [Przeglądarki Internetowe] ***** -\\ Internet Explorer v9.0.8112.16421 -\\ Google Chrome v [Nie udało się określić wersji] Plik : C:\Users\Majdan\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Plik w porządku. -\\ Opera v12.16.1860.0 Plik : C:\Users\Majdan\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] Plik w porządku. ************************* AdwCleaner[R1].txt - [3506 octets] - [11/07/2013 16:30:56] ########## EOF - C:\AdwCleaner[R1].txt - [3566 octets] ########## [/log]
Zayfi komentarz 11 lipca 2013 komentarz 11 lipca 2013 (edytowane) Zamknij wszystkie przeglądarki. Uruchom AdWCleaner i zastosuj opcję Usuń. Po usuwaniu, uruchom go ponownie zastosuj opcję Odinstaluj. Uruchom OTL i kliknij Sprzątanie. Wszystko. 1
Majdanek komentarz 11 lipca 2013 Autor komentarz 11 lipca 2013 A tą usługę InstallDriver Table Manager - Macrovision Corporation włączyć na nowo ?
Zayfi komentarz 11 lipca 2013 komentarz 11 lipca 2013 usługi właczasz w panelu usług start > polecenie uruchom > services.msc znajdź usługę i ustaw tryb uruchomienia na ręczny. jak bedzie coś nie tak wyłacz
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.