TA STRONA UŻYWA COOKIE. Dowiedz się więcej o celu ich używania i zmianie ustawień cookie w przeglądarce. Korzystając ze strony wyrażasz zgodę na używanie cookie, zgodnie z aktualnymi ustawieniami przeglądarki.
Od dnia 25.05.2018 r. na terenie Unii Europejskiej wchodzi w życie Rozporządzenie Parlamentu Europejskiego w sprawie ochrony danych osobowych. Prosimy o zapoznanie się z polityką prywatności oraz regulaminem serwisu  [X]

prosze o sprawdzenie logow

Logi, zabezpieczenie komputera, danych. Programy antywirusowe antyspyware, firewall itp.
Regulamin forum
1. Każdy temat powinien odzwierciedlać treść wątku.
2. W przypadku wklejania logów; należy je wykonać od razu przynajmniej z dwóch narzędzi: FRST oraz z GMER
3. Wszelkie logi proszę publikować na przeznaczonych do tego stronach a w poście wklejać tylko link.
4. Nie wskazane jest skracanie logów, należy wkleić cały - od początku, do końca.
5. Nie wskazane jest podczepianie się do tematów innych użytkowników - proszę założyć nowy temat w dziale Bezpieczeństwo, ułatwi to pomoc sprawdzającemu.
6. Osoby nie posiadające odpowiedniej wiedzy, nie powinny sprawdzać logów, ponieważ grozi to poważnym uszkodzeniem systemu lub aplikacji zainstalowanych na komputerze.
7. Należy dokładnie opisać problem, występujące objawy oraz wszelkie podjęte działania.
8. Każdy skrypt jest unikatowy, napisany dla każdego przypadku z osobna, więc nie może być stosowany przez innych.
9. W przypadku zamieszczenia zrzutu ekranu (screenshot'a) proszę korzystać z zewnętrznego serwisu oferującego hosting zdjęć.

prosze o sprawdzenie logow

Postprzez kamilek2707 » 19 Wrz 2018, 19:07

PostUA: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36


[code][/code]OTL logfile created on: 2018-09-19 18:32:39 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\ja\Downloads
64bit-Windows Vista Ultimate Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

4,00 Gb Total Physical Memory | 1,58 Gb Available Physical Memory | 39,44% Memory free
8,00 Gb Paging File | 5,29 Gb Available in Paging File | 66,11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 117,09 Gb Total Space | 80,87 Gb Free Space | 69,06% Space Free | Partition Type: NTFS
Drive D: | 180,90 Gb Total Space | 169,27 Gb Free Space | 93,57% Space Free | Partition Type: NTFS
Drive E: | 97,66 Gb Total Space | 97,57 Gb Free Space | 99,91% Space Free | Partition Type: NTFS
Drive F: | 146,48 Gb Total Space | 146,39 Gb Free Space | 99,93% Space Free | Partition Type: NTFS
Drive G: | 221,62 Gb Total Space | 220,58 Gb Free Space | 99,53% Space Free | Partition Type: NTFS

Computer Name: JA-KOMPUTER | User Name: ja | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2018-09-19 18:28:17 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\ja\Downloads\OTL_www.INSTALKI.pl.exe
PRC - [2018-09-19 16:22:22 | 000,915,853 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\bin\winlogon.exe
PRC - [2018-09-16 22:22:51 | 007,321,417 | ---- | M] () -- C:\Users\ja\AppData\Roaming\pwo6\svchost.exe
PRC - [2018-09-16 22:22:51 | 007,321,417 | ---- | M] () -- C:\Users\ja\AppData\Roaming\pwo6\svchost.exe
PRC - [2018-09-16 22:22:51 | 007,321,417 | ---- | M] () -- C:\Users\ja\AppData\Roaming\pwo6\svchost.exe
PRC - [2018-09-16 22:22:51 | 007,321,417 | ---- | M] () -- C:\Users\ja\AppData\Roaming\pwo6\svchost.exe
PRC - [2018-09-16 22:22:51 | 007,321,417 | ---- | M] () -- C:\Users\ja\AppData\Roaming\pwo6\svchost.exe
PRC - [2018-09-16 22:22:51 | 007,321,417 | ---- | M] () -- C:\Users\ja\AppData\Roaming\pwo6\svchost.exe
PRC - [2018-09-16 22:22:51 | 007,321,417 | ---- | M] () -- C:\Users\ja\AppData\Roaming\pwo6\svchost.exe
PRC - [2018-09-16 22:22:51 | 007,321,417 | ---- | M] () -- C:\Users\ja\AppData\Roaming\pwo6\svchost.exe
PRC - [2018-09-08 22:31:36 | 001,684,256 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
PRC - [2018-09-08 22:31:34 | 003,207,968 | ---- | M] (Valve Corporation) -- G:\steam\Steam.exe
PRC - [2018-09-08 20:38:16 | 000,288,848 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
PRC - [2018-08-24 14:03:14 | 008,112,464 | ---- | M] (Malwarebytes) -- C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
PRC - [2018-08-24 14:03:14 | 003,706,192 | ---- | M] (Malwarebytes) -- C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
PRC - [2016-11-14 14:30:58 | 002,397,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2016-11-14 14:30:58 | 001,879,488 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2016-11-14 11:45:38 | 000,426,040 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2018-09-19 16:22:22 | 000,915,853 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\bin\winlogon.exe
MOD - [2018-09-19 16:22:20 | 000,270,336 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\_ssl.pyd
MOD - [2018-09-19 16:22:20 | 000,112,128 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\pythoncom27.dll
MOD - [2018-09-19 16:22:20 | 000,107,008 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\_hashlib.pyd
MOD - [2018-09-19 16:22:20 | 000,072,192 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\win32com.shell.shell.pyd
MOD - [2018-09-19 16:22:20 | 000,052,736 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\pywintypes27.dll
MOD - [2018-09-19 16:22:20 | 000,043,520 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\win32gui.pyd
MOD - [2018-09-19 16:22:20 | 000,034,816 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\win32file.pyd
MOD - [2018-09-19 16:22:20 | 000,034,304 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\win32api.pyd
MOD - [2018-09-19 16:22:20 | 000,033,792 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\_ctypes.pyd
MOD - [2018-09-19 16:22:20 | 000,020,480 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\msgpack._unpacker.pyd
MOD - [2018-09-19 16:22:20 | 000,020,480 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\_socket.pyd
MOD - [2018-09-19 16:22:20 | 000,018,944 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\msgpack._packer.pyd
MOD - [2018-09-19 16:22:20 | 000,018,944 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\_psutil_mswindows.pyd
MOD - [2018-09-19 16:22:20 | 000,013,824 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\pyHook._cpyHook.pyd
MOD - [2018-09-19 16:22:20 | 000,013,312 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\_multiprocessing.pyd
MOD - [2018-09-19 16:22:20 | 000,009,728 | ---- | M] () -- C:\Users\ja\AppData\Local\Temp\_MEI23802\select.pyd
MOD - [2018-09-16 22:22:51 | 007,321,417 | ---- | M] () -- C:\Users\ja\AppData\Roaming\pwo6\svchost.exe
MOD - [2018-09-08 22:31:42 | 002,646,304 | ---- | M] () -- G:\steam\video.dll
MOD - [2018-09-08 22:31:36 | 001,015,584 | ---- | M] () -- G:\steam\bin\chromehtml.dll
MOD - [2018-09-05 22:14:34 | 000,876,320 | ---- | M] () -- G:\steam\SDL2.dll
MOD - [2017-12-20 03:43:50 | 005,137,696 | ---- | M] () -- G:\steam\libavcodec-57.dll
MOD - [2017-12-20 03:43:50 | 000,847,136 | ---- | M] () -- G:\steam\libavutil-55.dll
MOD - [2017-12-20 03:43:50 | 000,783,648 | ---- | M] () -- G:\steam\libswscale-4.dll
MOD - [2017-12-20 03:43:50 | 000,695,584 | ---- | M] () -- G:\steam\libavformat-57.dll
MOD - [2017-12-20 03:43:50 | 000,351,520 | ---- | M] () -- G:\steam\libavresample-3.dll
MOD - [2016-11-14 14:30:58 | 000,018,880 | ---- | M] () -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
MOD - [2016-09-01 03:02:12 | 004,969,248 | ---- | M] () -- G:\steam\v8.dll
MOD - [2016-09-01 03:02:06 | 001,563,936 | ---- | M] () -- G:\steam\icui18n.dll
MOD - [2016-09-01 03:02:06 | 001,195,296 | ---- | M] () -- G:\steam\icuuc.dll
MOD - [2016-07-05 00:17:58 | 000,266,560 | ---- | M] () -- G:\steam\openvr_api.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2018-09-19 17:54:48 | 000,675,736 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\WebAdvisor\servicehost.exe -- (McAfee WebAdvisor)
SRV:[b]64bit:[/b] - [2018-05-09 12:48:14 | 006,541,008 | ---- | M] (Malwarebytes) [Auto | Running] -- C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe -- (MBAMService)
SRV:[b]64bit:[/b] - [2016-11-14 14:30:58 | 003,632,576 | ---- | M] (NVIDIA Corporation) [On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe -- (NvStreamNetworkSvc)
SRV:[b]64bit:[/b] - [2016-11-14 14:30:58 | 002,521,024 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe -- (NvStreamSvc)
SRV:[b]64bit:[/b] - [2016-11-14 14:30:58 | 001,163,712 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService)
SRV:[b]64bit:[/b] - [2013-11-26 11:18:09 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2013-05-27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2009-07-14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2018-09-08 22:31:36 | 001,684,256 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2018-07-31 21:42:19 | 000,195,024 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2016-11-14 14:30:58 | 001,879,488 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2016-11-14 11:45:38 | 000,426,040 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2014-04-11 23:08:08 | 000,103,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2018-09-19 18:26:14 | 000,098,616 | ---- | M] (Malwarebytes) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebProtection)
DRV:[b]64bit:[/b] - [2018-09-19 18:15:15 | 000,052,328 | ---- | M] (Malwarebytes) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtection)
DRV:[b]64bit:[/b] - [2018-09-19 18:15:02 | 000,193,256 | ---- | M] (Malwarebytes) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\MbamChameleon.sys -- (MBAMChameleon)
DRV:[b]64bit:[/b] - [2018-09-19 18:15:02 | 000,117,472 | ---- | M] (Malwarebytes) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\farflt.sys -- (MBAMFarflt)
DRV:[b]64bit:[/b] - [2018-09-19 18:14:56 | 000,259,360 | ---- | M] (Malwarebytes) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV:[b]64bit:[/b] - [2018-09-19 17:54:48 | 000,111,976 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Program Files\McAfee\WebAdvisor\mfesapsn.sys -- (mfesapsn)
DRV:[b]64bit:[/b] - [2018-09-16 19:27:40 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:[b]64bit:[/b] - [2018-07-12 08:42:28 | 000,152,688 | ---- | M] (Malwarebytes) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mbae64.sys -- (ESProtectionDriver)
DRV:[b]64bit:[/b] - [2016-11-14 14:30:58 | 000,056,384 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:[b]64bit:[/b] - [2016-11-14 14:30:58 | 000,027,584 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV:[b]64bit:[/b] - [2012-08-23 16:12:16 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2012-08-23 16:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2012-08-23 16:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2012-08-23 16:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2012-03-01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2011-03-11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011-03-11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2010-11-21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:[b]64bit:[/b] - [2010-11-21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:[b]64bit:[/b] - [2010-11-21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2010-11-21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2009-11-25 21:06:02 | 001,276,928 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV:[b]64bit:[/b] - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009-06-10 22:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
DRV:[b]64bit:[/b] - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2012-12-29 22:59:38 | 000,028,664 | ---- | M] (Almico Software) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan)
DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.winclub.pl
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[color=#E56717]========== FireFox ==========[/color]

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\PROGRAM FILES\MCAFEE\WEBADVISOR\E10SSAFFPLG.XPI [2018-09-19 17:55:15 | 000,394,978 | ---- | M] ()
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 60.0\extensions\\Components: C:\PROGRAM FILES\MOZILLA THUNDERBIRD\COMPONENTS
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 60.0\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA THUNDERBIRD\PLUGINS
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\NativeMessagingHosts\siteadvisor.mcafee.chrome.extension\\: C:\PROGRAM FILES\MCAFEE\WEBADVISOR\WEBADVISOR.MCAFEE.FIREFOX.EXTENSION.JSON [2018-09-19 17:55:15 | 000,000,229 | ---- | M] ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2018-09-19 17:55:15 | 000,394,978 | ---- | M] ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\NativeMessagingHosts\siteadvisor.mcafee.chrome.extension\\: C:\Program Files\McAfee\WebAdvisor\webadvisor.mcafee.firefox.extension.json [2018-09-19 17:55:15 | 000,000,229 | ---- | M] ()

[2018-09-19 17:55:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ja\AppData\Roaming\mozilla\Extensions
[2018-09-19 17:55:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ja\AppData\Roaming\mozilla\SystemExtensionsDev

[color=#E56717]========== Chrome ==========[/color]

CHR - Extension: No name found = C:\Users\ja\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_1\
CHR - Extension: No name found = C:\Users\ja\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_1\
CHR - Extension: No name found = C:\Users\ja\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\ja\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_1\
CHR - Extension: No name found = C:\Users\ja\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\3.3.2_0\
CHR - Extension: No name found = C:\Users\ja\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_1\
CHR - Extension: No name found = C:\Users\ja\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\6.0.0.13089_0\
CHR - Extension: No name found = C:\Users\ja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\
CHR - Extension: No name found = C:\Users\ja\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabmeicndgkgfompmmdkijoamfleoadk\1.2.1_0\
CHR - Extension: No name found = C:\Users\ja\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_1\
CHR - Extension: No name found = C:\Users\ja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_1\
CHR - Extension: No name found = C:\Users\ja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6918.723.0.0_0\

O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (McAfee WebAdvisor) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\WebAdvisor\x64\ieplugin.dll (McAfee, Inc.)
O2 - BHO: (McAfee WebAdvisor) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\WebAdvisor\win32\ieplugin.dll (McAfee, Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [VIAAUD] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VIAAUD.exe File not found
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKCU..\Run: [DAEMON Tools Lite] G:\daemon tools\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [LoLReplay2] "G:\LoLReplay2\LoLReplay2.exe" File not found
O4 - HKCU..\Run: [Steam] G:\steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:[b]64bit:[/b] - Extra Button: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - C:\Program Files\McAfee\WebAdvisor\x64\ieplugin.dll (McAfee, Inc.)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - C:\Program Files\McAfee\WebAdvisor\x64\ieplugin.dll (McAfee, Inc.)
O9 - Extra Button: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - C:\Program Files\McAfee\WebAdvisor\win32\ieplugin.dll (McAfee, Inc.)
O9 - Extra 'Tools' menuitem : McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - C:\Program Files\McAfee\WebAdvisor\win32\ieplugin.dll (McAfee, Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ED2B9C99-D6B4-4DF3-AA3B-7CDDDA1181BD}: DhcpNameServer = 192.168.1.1
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{f49f658e-b9d3-11e8-b219-0025223f2e3d}\Shell - "" = AutoRun
O33 - MountPoints2\{f49f658e-b9d3-11e8-b219-0025223f2e3d}\Shell\AutoRun\command - "" = H:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2018-09-19 18:24:18 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\mbam
[2018-09-19 18:15:15 | 000,052,328 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbam.sys
[2018-09-19 18:15:02 | 000,193,256 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\MbamChameleon.sys
[2018-09-19 18:15:02 | 000,117,472 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\farflt.sys
[2018-09-19 18:15:02 | 000,098,616 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mwac.sys
[2018-09-19 18:14:56 | 000,259,360 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbamswissarmy.sys
[2018-09-19 18:14:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
[2018-09-19 18:14:38 | 000,152,688 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbae64.sys
[2018-09-19 18:14:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2018-09-19 18:14:30 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes
[2018-09-19 17:55:58 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\Mozilla
[2018-09-19 17:55:57 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\Thunderbird
[2018-09-19 17:55:57 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Thunderbird
[2018-09-19 17:55:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2018-09-19 17:55:46 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2018-09-19 17:54:46 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee
[2018-09-19 17:54:41 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2018-09-19 17:27:22 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\Correo
[2018-09-16 23:51:27 | 000,000,000 | ---D | C] -- C:\Users\ja\Desktop\Nowy folder
[2018-09-16 23:28:39 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\AChat
[2018-09-16 22:59:23 | 000,327,168 | ---- | C] (InstallShield Software Corporation) -- C:\Windows\IsUn0415.exe
[2018-09-16 22:22:51 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\pwo6
[2018-09-16 21:40:24 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Disc_Soft_Ltd
[2018-09-16 21:30:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Astroburn Lite
[2018-09-16 20:57:00 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\DAEMON Tools Images
[2018-09-16 19:56:53 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\IsolatedStorage
[2018-09-16 19:56:53 | 000,000,000 | ---D | C] -- C:\ProgramData\IsolatedStorage
[2018-09-16 19:56:50 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Solvusoft_Corporation
[2018-09-16 19:56:20 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\WinThruster
[2018-09-16 19:28:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2018-09-16 19:27:40 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2018-09-16 19:27:38 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\DAEMON Tools Lite
[2018-09-16 19:26:49 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2018-09-16 17:02:05 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2018-09-15 04:13:38 | 000,000,000 | ---D | C] -- C:\Users\ja\Documents\Mount&Blade Warband
[2018-09-15 04:13:38 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\Mount&Blade Warband
[2018-09-15 00:38:00 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\CrashDumps
[2018-09-15 00:34:38 | 000,000,000 | ---D | C] -- C:\Users\ja\Documents\My Games
[2018-09-15 00:15:35 | 002,605,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_40.dll
[2018-09-15 00:15:35 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_40.dll
[2018-09-15 00:15:35 | 000,519,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_40.dll
[2018-09-15 00:15:35 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_40.dll
[2018-09-15 00:15:32 | 005,631,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_40.dll
[2018-09-15 00:15:32 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_40.dll
[2018-09-14 22:15:57 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2018-09-12 21:39:16 | 000,000,000 | ---D | C] -- C:\Users\ja\Documents\LOLReplay
[2018-09-12 21:33:02 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-string-l1-1-0.dll
[2018-09-12 21:33:02 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-string-l1-1-0.dll
[2018-09-12 21:33:02 | 000,015,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-convert-l1-1-0.dll
[2018-09-12 21:33:02 | 000,014,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-2-0.dll
[2018-09-12 21:33:02 | 000,014,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-2-0.dll
[2018-09-12 21:33:02 | 000,013,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-filesystem-l1-1-0.dll
[2018-09-12 21:33:02 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-process-l1-1-0.dll
[2018-09-12 21:33:02 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-conio-l1-1-0.dll
[2018-09-12 21:33:02 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-conio-l1-1-0.dll
[2018-09-12 21:33:02 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-utility-l1-1-0.dll
[2018-09-12 21:33:02 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-2-0.dll
[2018-09-12 21:33:02 | 000,011,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l2-1-0.dll
[2018-09-12 21:33:02 | 000,011,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-timezone-l1-1-0.dll
[2018-09-12 21:33:02 | 000,011,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-timezone-l1-1-0.dll
[2018-09-12 21:33:02 | 000,011,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l2-1-0.dll
[2018-09-12 21:33:02 | 000,011,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l2-1-0.dll
[2018-09-12 21:33:01 | 000,984,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ucrtbase.dll
[2018-09-12 21:33:01 | 000,901,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ucrtbase.dll
[2018-09-12 21:33:01 | 000,066,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-private-l1-1-0.dll
[2018-09-12 21:33:01 | 000,063,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-private-l1-1-0.dll
[2018-09-12 21:33:01 | 000,022,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-math-l1-1-0.dll
[2018-09-12 21:33:01 | 000,020,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-math-l1-1-0.dll
[2018-09-12 21:33:01 | 000,019,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-multibyte-l1-1-0.dll
[2018-09-12 21:33:01 | 000,019,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-multibyte-l1-1-0.dll
[2018-09-12 21:33:01 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-stdio-l1-1-0.dll
[2018-09-12 21:33:01 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-stdio-l1-1-0.dll
[2018-09-12 21:33:01 | 000,016,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-runtime-l1-1-0.dll
[2018-09-12 21:33:01 | 000,016,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-runtime-l1-1-0.dll
[2018-09-12 21:33:01 | 000,015,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-convert-l1-1-0.dll
[2018-09-12 21:33:01 | 000,014,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-time-l1-1-0.dll
[2018-09-12 21:33:01 | 000,014,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-time-l1-1-0.dll
[2018-09-12 21:33:01 | 000,013,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-filesystem-l1-1-0.dll
[2018-09-12 21:33:01 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-process-l1-1-0.dll
[2018-09-12 21:33:01 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-heap-l1-1-0.dll
[2018-09-12 21:33:01 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-heap-l1-1-0.dll
[2018-09-12 21:33:01 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-utility-l1-1-0.dll
[2018-09-12 21:33:01 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-locale-l1-1-0.dll
[2018-09-12 21:33:01 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-locale-l1-1-0.dll
[2018-09-12 21:33:01 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-environment-l1-1-0.dll
[2018-09-12 21:33:01 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-environment-l1-1-0.dll
[2018-09-12 21:33:01 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-2-0.dll
[2018-09-12 21:33:01 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-1.dll
[2018-09-12 21:33:01 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-1.dll
[2018-09-12 21:33:01 | 000,011,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-eventing-provider-l1-1-0.dll
[2018-09-12 21:33:01 | 000,011,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-eventing-provider-l1-1-0.dll
[2018-09-12 21:33:01 | 000,011,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l2-1-0.dll
[2018-09-12 21:33:01 | 000,011,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-2-0.dll
[2018-09-12 21:33:01 | 000,011,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-2-0.dll
[2018-09-12 20:18:17 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Facebook
[2018-09-12 16:00:21 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\NVIDIA
[2018-09-12 15:59:54 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Steam
[2018-09-12 15:56:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2018-09-12 15:56:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2018-09-12 13:32:53 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\Skype
[2018-09-09 16:01:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Riot Games
[2018-09-06 21:03:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Licenses
[2018-09-06 21:03:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Engelmann Software
[2018-09-06 21:03:37 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Engelmann_Software
[2018-09-06 20:58:43 | 000,000,000 | ---D | C] -- C:\Program Files\Engelmann Software
[2018-09-06 18:29:52 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2018-09-06 03:14:55 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Mail.Ru
[2018-09-06 03:14:54 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\TablacusApp2
[2018-09-06 03:14:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Mail.Ru
[2018-09-05 21:56:17 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\Google
[2018-09-05 21:32:49 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Adobe
[2018-09-05 21:20:41 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Diagnostics
[2018-09-05 20:36:32 | 000,000,000 | ---D | C] -- C:\ProgramData\ByteFence
[2018-09-05 20:35:03 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\Macromedia
[2018-09-05 20:34:30 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2018-09-05 20:34:17 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2018-09-05 20:34:06 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Opera Software
[2018-09-05 20:33:50 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Programs
[2018-09-05 20:33:50 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\Opera Software
[2018-09-05 20:31:43 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Might & Magic Heroes Online
[2018-09-05 19:34:01 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Ubisoft Game Launcher
[2018-09-04 20:15:36 | 000,000,000 | ---D | C] -- C:\Users\ja\Documents\League of Legends
[2018-09-04 20:09:57 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\CEF
[2018-09-04 19:39:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2018-09-04 19:38:57 | 000,414,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\difxapi.dll
[2018-09-04 19:38:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VIA
[2018-09-04 19:38:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2018-09-04 19:38:33 | 001,276,928 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\drivers\viahduaa.sys
[2018-09-04 19:38:33 | 001,011,712 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\VIAPropPageExt.dll
[2018-09-04 19:38:33 | 000,601,088 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\VMAPO64.DLL
[2018-09-04 19:38:33 | 000,532,480 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\VIASysFx.dll
[2018-09-04 19:38:33 | 000,524,288 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysWow64\VMAPO32.DLL
[2018-09-04 19:38:33 | 000,242,176 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\Dts2APO.dll
[2018-09-04 19:38:33 | 000,193,024 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\ViaMicArrayAPO.dll
[2018-09-04 19:38:33 | 000,086,016 | ---- | C] (QSound Labs, Inc.) -- C:\Windows\SysNative\nQPropPageExt.dll
[2018-09-04 19:38:33 | 000,084,992 | ---- | C] (VIA Technologies, Inc.) -- C:\Windows\SysNative\Dts2PropPageExt.dll
[2018-09-04 19:38:33 | 000,082,432 | ---- | C] (QSound Labs, Inc.) -- C:\Windows\SysNative\nQAPO.dll
[2018-09-04 19:38:33 | 000,076,288 | ---- | C] (VIA Technologies,Inc.) -- C:\Windows\SysNative\ViaMicArrayPropPageExt.dll
[2018-09-04 19:38:33 | 000,072,704 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\VMWRP64.DLL
[2018-09-04 19:38:33 | 000,057,856 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\VMPPLD64.DLL
[2018-09-04 19:38:33 | 000,053,760 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\SysNative\VMPPCN64.DLL
[2018-09-04 19:35:45 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\NVIDIA Corporation
[2018-09-04 19:34:41 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\NVIDIA
[2018-09-04 19:34:40 | 001,767,712 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvspcap64.dll
[2018-09-04 19:34:40 | 001,756,560 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvspbridge64.dll
[2018-09-04 19:34:40 | 001,377,752 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvspcap.dll
[2018-09-04 19:34:40 | 001,316,136 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvspbridge.dll
[2018-09-04 19:34:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2018-09-04 19:34:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2018-09-04 19:33:49 | 000,615,992 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe
[2018-09-04 19:33:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2018-09-04 19:33:42 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2018-09-04 19:33:32 | 006,789,056 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll
[2018-09-04 19:33:32 | 003,528,128 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll
[2018-09-04 19:33:32 | 002,558,512 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll
[2018-09-04 19:33:32 | 000,384,888 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll
[2018-09-04 19:33:32 | 000,062,328 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll
[2018-09-04 19:33:21 | 000,082,488 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2018-09-04 19:33:21 | 000,067,520 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2018-09-04 19:33:13 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2018-09-04 19:32:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2018-09-04 19:31:39 | 031,523,384 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2018-09-04 19:31:39 | 024,208,440 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2018-09-04 19:31:39 | 018,634,216 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
[2018-09-04 19:31:39 | 016,128,720 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2018-09-04 19:31:39 | 014,497,712 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2018-09-04 19:31:39 | 013,915,720 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll
[2018-09-04 19:31:39 | 013,826,968 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2018-09-04 19:31:39 | 011,270,656 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll
[2018-09-04 19:31:39 | 011,208,312 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2018-09-04 19:31:39 | 004,253,240 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2018-09-04 19:31:39 | 003,995,192 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2018-09-04 19:31:39 | 001,908,272 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6434201.dll
[2018-09-04 19:31:39 | 001,557,552 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6434201.dll
[2018-09-04 19:31:39 | 000,951,232 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvIFR64.dll
[2018-09-04 19:31:39 | 000,913,856 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvIFR.dll
[2018-09-04 19:31:39 | 000,909,760 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\NvFBC64.dll
[2018-09-04 19:31:39 | 000,876,480 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\NvFBC.dll
[2018-09-04 19:31:39 | 000,114,744 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvaudcap64v.dll
[2018-09-04 19:31:39 | 000,104,512 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvaudcap32v.dll
[2018-09-04 19:31:39 | 000,056,384 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvvad64v.sys
[2018-09-04 19:31:38 | 023,000,000 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2018-09-04 19:31:38 | 015,301,056 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2018-09-04 19:31:38 | 003,207,824 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll
[2018-09-04 19:31:38 | 002,822,568 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2018-09-04 19:29:38 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2018-09-04 19:29:16 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2018-09-04 19:21:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2018-09-04 19:21:09 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2018-09-04 19:20:56 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2018-09-04 19:20:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpeedFan
[2018-09-04 19:19:30 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\ElevatedDiagnostics
[2018-09-04 19:18:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2018-09-04 19:17:58 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Google
[2018-09-04 19:17:34 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Apps
[2018-09-04 19:17:33 | 000,000,000 | ---D | C] -- C:\Users\ja\AppData\Local\Deployment
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2018-09-19 18:26:14 | 000,098,616 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\mwac.sys
[2018-09-19 18:15:15 | 000,052,328 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbam.sys
[2018-09-19 18:15:02 | 000,193,256 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\MbamChameleon.sys
[2018-09-19 18:15:02 | 000,117,472 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\farflt.sys
[2018-09-19 18:14:56 | 000,259,360 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbamswissarmy.sys
[2018-09-19 18:14:40 | 000,001,871 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2018-09-19 16:22:04 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2018-09-19 16:21:59 | 3220,676,608 | -HS- | M] () -- C:\hiberfil.sys
[2018-09-18 19:15:46 | 000,002,199 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2018-09-16 19:30:34 | 001,669,190 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2018-09-16 19:30:34 | 000,740,098 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat
[2018-09-16 19:30:34 | 000,653,930 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2018-09-16 19:30:34 | 000,155,672 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat
[2018-09-16 19:30:34 | 000,121,802 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2018-09-16 19:27:40 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2018-09-16 19:13:37 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2018-09-16 19:13:37 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2018-09-16 17:09:51 | 001,640,860 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2018-09-14 19:20:23 | 000,234,368 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2018-09-12 15:56:48 | 000,000,520 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2018-09-07 21:54:16 | 000,000,000 | -H-- | M] () -- C:\Users\ja\Documents\Default.rdp
[2018-09-04 21:04:58 | 000,007,605 | ---- | M] () -- C:\Users\ja\AppData\Local\resmon.resmoncfg
[2018-09-04 19:46:40 | 000,014,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\slwga.dll
[2018-09-04 19:46:40 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\slwga.dll
[2018-09-04 19:46:39 | 001,008,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\user32.dll
[2018-09-04 19:46:39 | 000,419,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\systemcpl.dll
[2018-09-04 19:20:55 | 000,000,045 | ---- | M] () -- C:\Windows\SysWow64\initdebug.nfo
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2018-09-19 18:14:40 | 000,001,871 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2018-09-19 17:55:49 | 000,000,990 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2018-09-12 15:56:48 | 000,000,520 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2018-09-08 20:38:49 | 000,002,240 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[2018-09-08 20:38:49 | 000,002,199 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2018-09-07 21:54:16 | 000,000,000 | -H-- | C] () -- C:\Users\ja\Documents\Default.rdp
[2018-09-04 21:04:16 | 000,007,605 | ---- | C] () -- C:\Users\ja\AppData\Local\resmon.resmoncfg
[2018-09-04 19:39:16 | 000,001,228 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk
[2018-09-04 19:34:41 | 000,112,168 | ---- | C] () -- C:\Windows\SysNative\NvRtmpStreamer64.dll
[2018-09-04 19:33:32 | 007,513,855 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin
[2018-09-04 19:31:39 | 000,026,157 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2018-09-04 19:20:54 | 000,000,045 | ---- | C] () -- C:\Windows\SysWow64\initdebug.nfo

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013-07-26 04:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013-07-26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >
kamilek2707
Forumowicz
Forumowicz
 
Posty: 1
Dołączenie: 19 Wrz 2018, 18:55

Re: prosze o sprawdzenie logow

Postprzez Illidan » 20 Wrz 2018, 01:24

PostUA: Mozilla/5.0 (Windows NT 6.2) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/69.0.3497.81 Safari/537.22 anonymized by Abelssoft 1240385445


Witaj
Log niekompletny, brakuje drugiego logu "Extras" i wykonane są już nie rozwijanym programem. Wykonaj proszę nowy zestaw logów ,programem "FRST", wykonaj wszystkie trzy logi jak w opisie i zamieść po kolei każdy na stronie "Pastebin", tu podaj linki do logów tylko:
https://sites.google.com/site/twierdzac ... i-wersja-2
Awatar użytkownika
Illidan
Zacny pisarz
Zacny pisarz
 
Posty: 1232
Dołączenie: 29 Paź 2017, 23:25
Miejscowość: Gliwice
Pochwały: 26


Powróć do Bezpieczeństwo

Kto jest na forum

Zarejestrowani użytkownicy: Brak zarejestrowanych użytkowników

cron