GriX Napisano Grudzień 30, 2014 Zgłoś Share Napisano Grudzień 30, 2014 Witam! Dzisiaj zauważyłem, że folder moje obrazy zmienił lokalizacje z dysku d na c. W opcjach tego folderu zniknęła też opcja "lokalizacja" Gdy chciałem sprawdzić uprawnienia do folderu, zobaczyłem dziwne konto. Skanowanie Comodo Internet Security oraz Malwarebytes nic nie znalazło.Log z OTL:OTL logfile created on: 2014-12-29 18:49:55 - Run 1OTL by OldTimer - Version 3.2.69.0 Folder = D:\Users\Konrad\Downloads64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstationInternet Explorer (Version = 9.11.9600.17501)Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd7,96 Gb Total Physical Memory | 4,73 Gb Available Physical Memory | 59,43% Memory free27,87 Gb Paging File | 23,82 Gb Available in Paging File | 85,46% Paging File freePaging file location(s): c:\pagefile.sys 0 0d:\pagefile.sys 12232 12232 [binary data]%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)Drive C: | 111,69 Gb Total Space | 59,25 Gb Free Space | 53,05% Space Free | Partition Type: NTFSDrive D: | 931,51 Gb Total Space | 744,77 Gb Free Space | 79,95% Space Free | Partition Type: NTFSComputer Name: KONRAD-KOMPUTER | User Name: Konrad | Logged in as Administrator.Boot Mode: Normal | Scan Mode: Current user | Include 64bit ScansCompany Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days========== Processes (SafeList) ==========PRC - [2014-12-29 18:49:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Users\Konrad\Downloads\OTL.exePRC - [2014-11-09 12:55:12 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exePRC - [2011-09-23 17:37:42 | 000,641,832 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exePRC - [2007-09-02 13:58:52 | 000,495,616 | ---- | M] () -- D:\Program Files\RocketDock\RocketDock.exe========== Modules (No Company Name) ==========MOD - [2014-09-25 10:26:13 | 000,081,056 | ---- | M] () -- C:\Users\Konrad\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\LoggingPlatform.DLLMOD - [2007-09-02 13:58:52 | 000,495,616 | ---- | M] () -- D:\Program Files\RocketDock\RocketDock.exeMOD - [2007-09-02 13:57:36 | 000,069,632 | ---- | M] () -- D:\Program Files\RocketDock\RocketDock.dll========== Services (SafeList) ==========SRV:64bit: - [2014-12-23 10:22:52 | 000,244,736 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)SRV:64bit: - [2014-11-22 03:35:29 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)SRV:64bit: - [2014-11-09 13:30:15 | 000,076,152 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\PnkBstrA.exe -- (PnkBstrA)SRV:64bit: - [2013-05-27 06:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)SRV:64bit: - [2012-02-09 15:26:48 | 000,133,632 | ---- | M] () [Auto | Running] -- C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe -- (ISCTAgent)SRV - [2014-12-18 14:33:49 | 001,903,472 | ---- | M] (Electronic Arts) [On_Demand | Stopped] -- D:\Program Files\Origin\OriginClientService.exe -- (Origin Client Service)SRV - [2014-12-09 01:20:21 | 007,618,952 | ---- | M] (COMODO) [Auto | Running] -- D:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)SRV - [2014-12-09 01:20:03 | 002,265,304 | ---- | M] (COMODO) [On_Demand | Stopped] -- D:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe -- (cmdvirth)SRV - [2014-11-18 21:23:34 | 000,833,728 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)SRV - [2014-11-09 12:55:12 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)SRV - [2014-09-08 21:20:39 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)SRV - [2014-09-02 15:29:50 | 000,614,624 | ---- | M] (Futuremark) [On_Demand | Stopped] -- C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)SRV - [2014-03-20 23:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)SRV - [2013-09-11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)SRV - [2011-09-23 17:37:42 | 000,641,832 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)========== Driver Services (SafeList) ==========DRV:64bit: - [2014-12-29 18:24:04 | 000,034,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WPRO_41_2001.sys -- (WPRO_41_2001)DRV:64bit: - [2014-12-25 14:53:36 | 000,022,016 | ---- | M] (Siliten) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\KbFilter_FlexDef3x.sys -- (KbFilter_Kb_FlexDef3x)DRV:64bit: - [2014-12-23 10:23:16 | 000,094,720 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)DRV:64bit: - [2014-12-23 10:22:52 | 018,959,360 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)DRV:64bit: - [2014-12-23 10:22:52 | 000,589,312 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)DRV:64bit: - [2014-12-09 01:20:32 | 000,020,184 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\SysNative\drivers\cmderd.sys -- (cmderd)DRV:64bit: - [2014-08-13 18:20:24 | 000,038,400 | ---- | M] (SteelSeries ApS) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sshid.sys -- (sshid)DRV:64bit: - [2014-08-13 18:20:24 | 000,008,704 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hidkmdf.sys -- (hidkmdf)DRV:64bit: - [2014-03-14 09:01:48 | 000,145,184 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)DRV:64bit: - [2014-01-22 07:52:10 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)DRV:64bit: - [2014-01-22 07:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)DRV:64bit: - [2013-10-02 03:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)DRV:64bit: - [2013-08-11 15:03:24 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)DRV:64bit: - [2012-08-23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)DRV:64bit: - [2012-03-01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)DRV:64bit: - [2012-02-09 15:24:16 | 000,044,992 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ISCTD64.sys -- (ISCT)DRV:64bit: - [2012-02-09 15:24:16 | 000,025,536 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\imsevent.sys -- (imsevent)DRV:64bit: - [2012-02-09 15:24:14 | 000,025,536 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ikbevent.sys -- (ikbevent)DRV:64bit: - [2011-03-11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)DRV:64bit: - [2011-03-11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)DRV:64bit: - [2011-02-08 12:30:52 | 000,064,512 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronXHCI.sys -- (EtronXHCI)DRV:64bit: - [2011-02-08 12:30:52 | 000,039,936 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronHub3.sys -- (EtronHub3)DRV:64bit: - [2010-11-20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)DRV:64bit: - [2010-11-05 22:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)DRV:64bit: - [2010-10-19 22:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)DRV:64bit: - [2010-06-23 16:10:56 | 000,344,680 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)DRV:64bit: - [2009-08-13 21:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)DRV:64bit: - [2009-07-31 02:40:32 | 000,025,600 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\XENfiltv.sys -- (XENfiltv)DRV:64bit: - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)DRV:64bit: - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)DRV:64bit: - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)DRV:64bit: - [2009-07-14 01:00:13 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Dot4Scan.sys -- (Dot4Scan)DRV:64bit: - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)DRV:64bit: - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)DRV:64bit: - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)DRV:64bit: - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)DRV - [2013-03-14 13:36:18 | 000,017,160 | ---- | M] (XFire) [File_System | On_Demand | Stopped] -- C:\Program Files (x86)\Xfire2\XFDriver64.sys -- (XFDriver64)DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)========== Standard Registry (SafeList) ==================== Internet Explorer ==========IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htmIE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRCIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = localhost:8080========== FireFox ==========FF:64bit: - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.5.0: File not foundFF:64bit: - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.5.1: C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB)FF:64bit: - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.6.2: C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll (EA Digital Illusions CE AB)FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.25.2: C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2: C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not foundFF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.3.1: File not foundFF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.5.0: File not foundFF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.5.1: C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.6.2: C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll (EA Digital Illusions CE AB)FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: File not foundFF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.60.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.60.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not foundFF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)[2013-08-11 14:29:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Konrad\AppData\Roaming\mozilla\Extensions========== Chrome ==========CHR - default_search_provider: (Enabled)CHR - default_search_provider: search_url =CHR - default_search_provider: suggest_url =CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dllCHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewerCHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dllCHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dllCHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dllCHR - Extension: No name found = C:\Users\Konrad\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif\6.8.3_0\CHR - Extension: No name found = C:\Users\Konrad\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\CHR - Extension: No name found = C:\Users\Konrad\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\CHR - Extension: No name found = C:\Users\Konrad\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\CHR - Extension: No name found = C:\Users\Konrad\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.8_0\CHR - Extension: No name found = C:\Users\Konrad\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\CHR - Extension: No name found = C:\Users\Konrad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\CHR - Extension: No name found = C:\Users\Konrad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nonjdcjchghhkdoolnlbekcfllmednbl\5.6_0\CHR - Extension: No name found = C:\Users\Konrad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\O1 HOSTS File: ([2009-06-10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hostsO2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL (Microsoft Corporation)O2 - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL (Microsoft Corporation)O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)O4:64bit: - HKLM..\Run: [COMODO Internet Security] D:\Program Files\COMODO\COMODO Internet Security\cistray.exe (COMODO)O4 - HKCU..\Run: [Clock Widget (HTC Home)] D:\Program Files\HTC Home\Clock.exe ()O4 - HKCU..\Run: [RocketDock] D:\Program Files\RocketDock\RocketDock.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1O8:64bit: - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 File not foundO8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 File not foundO1364bit: - gopher Prefix: missingO13 - gopher Prefix: missingO17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DA3A1EA2-69A5-418E-8428-A9D2298885B2}: DhcpNameServer = 192.168.1.1O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DA3A1EA2-69A5-418E-8428-A9D2298885B2}: NameServer = 194.204.152.34O18:64bit: - Protocol\Handler\msdaipp - No CLSID value foundO18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value foundO18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value foundO18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)O18 - Protocol\Handler\ms-help - No CLSID value foundO20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.O32 - HKLM CDRom: AutoRun - 1O33 - MountPoints2\{ab77f3ce-127b-11e4-82f1-806e6f6e6963}\Shell - "" = AutoRunO33 - MountPoints2\{ab77f3ce-127b-11e4-82f1-806e6f6e6963}\Shell\AutoRun\command - "" = E:\cda_menu.exeO34 - HKLM BootExecute: (autocheck autochk *)O35:64bit: - HKLM\..comfile [open] -- "%1" %*O35:64bit: - HKLM\..exefile [open] -- "%1" %*O35 - HKLM\..comfile [open] -- "%1" %*O35 - HKLM\..exefile [open] -- "%1" %*O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*O37 - HKLM\...com [@ = comfile] -- "%1" %*O37 - HKLM\...exe [@ = exefile] -- "%1" %*O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)========== Files/Folders - Created Within 30 Days ==========[2014-12-29 17:05:08 | 000,000,000 | -H-D | C] -- C:\AdwCleaner[2014-12-29 16:26:27 | 000,000,000 | ---D | C] -- C:\Users\Konrad\AppData\Roaming\DxO Labs[2014-12-29 16:25:38 | 000,000,000 | ---D | C] -- C:\Users\Konrad\AppData\Local\DxO_Labs[2014-12-29 16:25:19 | 000,000,000 | ---D | C] -- C:\ProgramData\DxO Labs[2014-12-29 13:30:27 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Sports Interactive[2014-12-29 13:30:27 | 000,000,000 | ---D | C] -- C:\Users\Konrad\AppData\Local\Sports Interactive[2014-12-28 15:06:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IQ Publishing[2014-12-28 14:48:33 | 000,000,000 | ---D | C] -- d:\Users\Konrad\Documents\Hydrophobia[2014-12-28 14:45:00 | 000,000,000 | ---D | C] -- d:\Users\Konrad\Documents\Drakensang_TRoT[2014-12-23 19:17:05 | 000,000,000 | ---D | C] -- C:\Users\Konrad\AppData\Local\G2D3D11Launcher[2014-12-23 10:26:22 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI[2014-12-23 10:23:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT[2014-12-23 10:23:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies[2014-12-23 10:23:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center[2014-12-23 10:23:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD[2014-12-23 10:19:30 | 000,000,000 | ---D | C] -- C:\Program Files\AMD[2014-12-22 12:59:52 | 000,000,000 | ---D | C] -- d:\Users\Konrad\Documents\GTA San Andreas User Files[2014-12-18 18:10:19 | 000,000,000 | -HSD | C] -- C:\Users\Konrad\AppData\Local\EmieBrowserModeList[2014-12-18 14:33:01 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe[2014-12-18 14:33:01 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe[2014-12-12 15:37:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo Downloader[2014-12-10 17:40:54 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appraiser[2014-12-10 16:27:28 | 004,121,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll[2014-12-10 16:27:28 | 003,209,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll[2014-12-10 16:27:15 | 000,718,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe[2014-12-10 16:27:15 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe[2014-12-10 16:27:15 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll[2014-12-10 16:27:15 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll[2014-12-10 16:27:15 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll[2014-12-10 16:27:15 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll[2014-12-10 16:27:15 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll[2014-12-10 16:27:14 | 002,052,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl[2014-12-10 16:27:14 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll[2014-12-10 16:27:14 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll[2014-12-10 16:27:14 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll[2014-12-10 16:27:14 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll[2014-12-10 16:27:14 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll[2014-12-10 16:27:14 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll[2014-12-10 16:27:13 | 002,125,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl[2014-12-10 16:27:13 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll[2014-12-10 16:27:13 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe[2014-12-10 16:27:13 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll[2014-12-10 16:27:13 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll[2014-12-10 16:27:13 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll[2014-12-10 16:27:13 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll[2014-12-10 16:27:13 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll[2014-12-10 16:27:12 | 001,359,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll[2014-12-10 16:27:12 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll[2014-12-10 16:27:12 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll[2014-12-10 16:27:12 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll[2014-12-10 16:27:12 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll[2014-12-10 16:27:12 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll[2014-12-10 16:27:11 | 006,039,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll[2014-12-10 16:27:11 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll[2014-12-10 16:27:11 | 000,580,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll[2014-12-10 16:27:11 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll[2014-12-10 16:27:11 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll[2014-12-10 16:26:04 | 001,232,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aitstatic.exe[2014-12-10 16:26:04 | 001,083,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll[2014-12-10 16:26:04 | 000,830,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appraiser.dll[2014-12-10 16:26:04 | 000,741,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\invagent.dll[2014-12-10 16:26:04 | 000,413,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll[2014-12-10 16:26:04 | 000,396,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\devinv.dll[2014-12-10 16:26:04 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepic.dll[2014-12-10 16:26:03 | 000,227,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll[2014-12-10 16:26:02 | 001,424,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll[2014-12-10 16:26:02 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\charmap.exe[2014-12-10 16:26:02 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\charmap.exe[2014-12-10 16:25:40 | 000,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSManMigrationPlugin.dll[2014-12-10 16:25:40 | 000,310,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmWmiPl.dll[2014-12-10 16:25:40 | 000,266,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSManHTTPConfig.exe[2014-12-10 16:25:40 | 000,248,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManMigrationPlugin.dll[2014-12-10 16:25:40 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmWmiPl.dll[2014-12-10 16:25:40 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManHTTPConfig.exe[2014-12-10 16:25:40 | 000,181,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmAuto.dll[2014-12-10 16:25:40 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmAuto.dll[2014-12-04 14:32:26 | 000,000,000 | ---D | C] -- C:\Users\Konrad\AppData\Roaming\MAXON[2014-11-05 15:37:42 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Konrad\AppData\Roaming\pcouffin.sys[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ][1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]========== Files - Modified Within 30 Days ==========[2014-12-29 18:46:35 | 000,042,472 | ---- | M] () -- d:\Users\Konrad\Desktop\Bez tytułu.png[2014-12-29 18:45:42 | 000,023,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0[2014-12-29 18:45:42 | 000,023,376 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0[2014-12-29 18:43:59 | 001,474,832 | ---- | M] () -- C:\Windows\SysNative\drivers\sfi.dat[2014-12-29 18:30:56 | 001,836,858 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI[2014-12-29 18:30:56 | 000,848,826 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat[2014-12-29 18:30:56 | 000,653,930 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat[2014-12-29 18:30:56 | 000,212,208 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat[2014-12-29 18:30:56 | 000,121,802 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat[2014-12-29 18:26:31 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys[2014-12-29 18:24:05 | 000,001,044 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job[2014-12-29 18:24:04 | 000,034,752 | ---- | M] () -- C:\Windows\SysNative\drivers\WPRO_41_2001.sys[2014-12-29 18:24:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat[2014-12-29 18:17:21 | 000,001,001 | ---- | M] () -- C:\Users\Konrad\Pliki.lnk[2014-12-29 18:09:43 | 000,000,985 | ---- | M] () -- C:\Users\Konrad\Gry.lnk[2014-12-29 18:02:54 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job[2014-12-28 19:43:50 | 000,009,687 | ---- | M] () -- C:\Users\Konrad\AppData\Local\recently-used.xbel[2014-12-25 14:53:36 | 000,022,016 | ---- | M] (Siliten) -- C:\Windows\SysNative\drivers\KbFilter_FlexDef3x.sys[2014-12-23 10:23:16 | 000,110,080 | ---- | M] (Advanced Micro Devices) -- C:\Windows\SysNative\DelayAPO.dll[2014-12-23 10:23:16 | 000,094,720 | ---- | M] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\AtihdW76.sys[2014-12-23 10:22:52 | 040,987,136 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\amdocl.dll[2014-12-23 10:22:52 | 023,621,632 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysWow64\atioglxx.dll[2014-12-23 10:22:52 | 018,959,360 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\atikmdag.sys[2014-12-23 10:22:52 | 015,716,352 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticaldd64.dll[2014-12-23 10:22:52 | 007,558,816 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiumdva.dll[2014-12-23 10:22:52 | 005,837,312 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\amdmantle64.dll[2014-12-23 10:22:52 | 004,590,592 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\amdmantle32.dll[2014-12-23 10:22:52 | 001,214,976 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atiadlxx.dll[2014-12-23 10:22:52 | 000,903,168 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysWow64\atiadlxy.dll[2014-12-23 10:22:52 | 000,843,776 | ---- | M] (AMD) -- C:\Windows\SysNative\coinst_14.50.dll[2014-12-23 10:22:52 | 000,774,656 | ---- | M] (AMD) -- C:\Windows\SysNative\atieclxx.exe[2014-12-23 10:22:52 | 000,589,312 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\atikmpag.sys[2014-12-23 10:22:52 | 000,367,104 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atiapfxx.exe[2014-12-23 10:22:52 | 000,294,600 | ---- | M] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\amdacpksd.sys[2014-12-23 10:22:52 | 000,244,736 | ---- | M] (AMD) -- C:\Windows\SysNative\atiesrxx.exe[2014-12-23 10:22:52 | 000,133,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atigktxx.dll[2014-12-23 10:22:52 | 000,126,848 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiuxpag.dll[2014-12-23 10:22:52 | 000,098,816 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\OpenVideo64.dll[2014-12-23 10:22:52 | 000,091,648 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\mantleaxl64.dll[2014-12-23 10:22:52 | 000,089,088 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atisamu64.dll[2014-12-23 10:22:52 | 000,086,528 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\OVDecode64.dll[2014-12-23 10:22:52 | 000,085,504 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\mantleaxl32.dll[2014-12-23 10:22:52 | 000,083,456 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\OpenVideo.dll[2014-12-23 10:22:52 | 000,069,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiglpxx.dll[2014-12-23 10:22:52 | 000,069,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiglpxx.dll[2014-12-23 10:22:52 | 000,065,024 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll[2014-12-23 10:22:52 | 000,062,464 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticalrt64.dll[2014-12-23 10:22:52 | 000,058,880 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll[2014-12-23 10:22:52 | 000,055,808 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticalcl64.dll[2014-12-23 10:22:52 | 000,031,232 | ---- | M] (AMD) -- C:\Windows\SysNative\atimuixx.dll[2014-12-23 10:22:51 | 028,354,560 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atio6axx.dll[2014-12-23 10:22:51 | 014,302,208 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticaldd.dll[2014-12-23 10:22:51 | 011,076,784 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atidxx64.dll[2014-12-23 10:22:51 | 009,401,480 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atidxx32.dll[2014-12-23 10:22:51 | 008,379,720 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiumd6a.dll[2014-12-23 10:22:51 | 008,369,408 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiumd64.dll[2014-12-23 10:22:51 | 007,077,776 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiumdag.dll[2014-12-23 10:22:51 | 001,348,928 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\aticfx64.dll[2014-12-23 10:22:51 | 001,127,496 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\aticfx32.dll[2014-12-23 10:22:51 | 000,442,368 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atidemgy.dll[2014-12-23 10:22:51 | 000,190,976 | ---- | M] (AMD) -- C:\Windows\SysNative\atitmm64.dll[2014-12-23 10:22:51 | 000,146,944 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atig6txx.dll[2014-12-23 10:22:51 | 000,144,328 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiuxp64.dll[2014-12-23 10:22:51 | 000,128,384 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\amdhcp64.dll[2014-12-23 10:22:51 | 000,127,488 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\mantle64.dll[2014-12-23 10:22:51 | 000,118,096 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysWow64\amdhcp32.dll[2014-12-23 10:22:51 | 000,118,096 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiu9p64.dll[2014-12-23 10:22:51 | 000,113,664 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\mantle32.dll[2014-12-23 10:22:51 | 000,100,032 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiu9pag.dll[2014-12-23 10:22:51 | 000,095,744 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\amdave64.dll[2014-12-23 10:22:51 | 000,090,112 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\amdave32.dll[2014-12-23 10:22:51 | 000,080,896 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atisamu32.dll[2014-12-23 10:22:51 | 000,078,432 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atimpc64.dll[2014-12-23 10:22:51 | 000,078,432 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\amdpcom64.dll[2014-12-23 10:22:51 | 000,075,264 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atig6pxx.dll[2014-12-23 10:22:51 | 000,073,216 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\OVDecode.dll[2014-12-23 10:22:51 | 000,071,704 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atimpc32.dll[2014-12-23 10:22:51 | 000,071,704 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\amdpcom32.dll[2014-12-23 10:22:51 | 000,052,224 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticalrt.dll[2014-12-23 10:22:51 | 000,049,664 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\amdmmcl6.dll[2014-12-23 10:22:51 | 000,049,152 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticalcl.dll[2014-12-23 10:22:51 | 000,043,520 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\ati2erec.dll[2014-12-23 10:22:51 | 000,038,912 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\amdmmcl.dll[2014-12-23 10:19:49 | 000,235,008 | ---- | M] () -- C:\Windows\SysNative\clinfo.exe[2014-12-21 20:40:08 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr[2014-12-21 20:40:08 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe[2014-12-18 14:33:01 | 000,144,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe[2014-12-18 14:33:01 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe[2014-12-16 18:25:43 | 000,348,928 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0[2014-12-12 15:39:14 | 000,007,384 | ---- | M] () -- C:\Windows\SysNative\drivers\fvstore.dat[2014-12-09 21:03:30 | 000,002,189 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk[2014-12-09 01:20:32 | 000,020,184 | ---- | M] (COMODO) -- C:\Windows\SysNative\drivers\cmderd.sys[2014-12-09 01:20:21 | 000,040,736 | ---- | M] (COMODO) -- C:\Windows\SysNative\cmdcsr.dll[2014-12-09 01:20:20 | 000,437,792 | ---- | M] (COMODO) -- C:\Windows\SysNative\guard64.dll[2014-12-09 01:20:20 | 000,352,272 | ---- | M] (COMODO) -- C:\Windows\SysWow64\guard32.dll[2014-12-09 01:20:16 | 000,354,520 | ---- | M] (COMODO) -- C:\Windows\SysNative\cmdvrt64.dll[2014-12-09 01:20:14 | 000,045,784 | ---- | M] (COMODO) -- C:\Windows\SysNative\cmdkbd64.dll[2014-12-09 01:20:11 | 000,286,424 | ---- | M] (COMODO) -- C:\Windows\SysWow64\cmdvrt32.dll[2014-12-09 01:20:09 | 000,040,664 | ---- | M] (COMODO) -- C:\Windows\SysWow64\cmdkbd32.dll[2014-12-04 19:10:13 | 000,000,000 | ---- | M] () -- C:\Users\Konrad\AppData\Local\{59384046-3B4C-4FDB-95E1-B6001A55FF37}[2014-12-04 03:50:55 | 000,413,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll[2014-12-04 03:50:45 | 000,741,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\invagent.dll[2014-12-04 03:50:40 | 000,396,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\devinv.dll[2014-12-04 03:50:38 | 000,830,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\appraiser.dll[2014-12-04 03:50:37 | 000,227,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll[2014-12-04 03:50:37 | 000,192,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aepic.dll[2014-12-04 03:44:48 | 001,083,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll[2014-12-02 00:28:44 | 001,232,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aitstatic.exe[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ][1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]========== Files Created - No Company Name ==========[2014-12-29 18:46:35 | 000,042,472 | ---- | C] () -- d:\Users\Konrad\Desktop\Bez tytułu.png[2014-12-28 19:43:50 | 000,009,687 | ---- | C] () -- C:\Users\Konrad\AppData\Local\recently-used.xbel[2014-12-04 19:09:48 | 000,000,000 | ---- | C] () -- C:\Users\Konrad\AppData\Local\{59384046-3B4C-4FDB-95E1-B6001A55FF37}[2014-11-20 21:35:00 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll[2014-11-05 15:37:54 | 000,000,671 | ---- | C] () -- C:\Users\Konrad\AppData\Roaming\vso_ts_preview.xml[2014-11-05 15:37:42 | 000,099,384 | ---- | C] () -- C:\Users\Konrad\AppData\Roaming\inst.exe[2014-11-05 15:37:42 | 000,007,859 | ---- | C] () -- C:\Users\Konrad\AppData\Roaming\pcouffin.cat[2014-11-05 15:37:42 | 000,001,167 | ---- | C] () -- C:\Users\Konrad\AppData\Roaming\pcouffin.inf[2014-08-15 16:49:04 | 000,644,608 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll[2014-08-15 16:49:04 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll[2014-07-14 21:02:36 | 000,006,656 | ---- | C] () -- C:\Users\Konrad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2014-07-13 14:00:38 | 000,000,000 | ---- | C] () -- C:\Windows\HPMProp.INI[2014-05-18 17:32:07 | 000,000,000 | ---- | C] () -- C:\Users\Konrad\AppData\Local\{F9292C7F-139A-4388-8E6A-C3870EDEFBBC}[2014-03-29 17:08:43 | 000,000,412 | ---- | C] () -- C:\Windows\ODBC.INI[2014-02-19 15:46:03 | 000,641,024 | ---- | C] () -- C:\Windows\SysWow64\ficvdec_x86.dll[2013-12-03 15:21:20 | 000,007,598 | ---- | C] () -- C:\Users\Konrad\AppData\Local\resmon.resmoncfg[2013-11-19 14:51:00 | 000,000,022 | ---- | C] () -- C:\Windows\GPU-Z.INI[2013-08-22 10:44:29 | 000,280,904 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe[2013-08-22 10:44:28 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe[2013-08-11 16:51:51 | 000,000,902 | ---- | C] () -- C:\Users\Konrad\Programy.lnk[2013-08-11 16:51:27 | 000,001,001 | ---- | C] () -- C:\Users\Konrad\Pliki.lnk[2013-08-11 16:50:41 | 000,000,985 | ---- | C] () -- C:\Users\Konrad\Gry.lnk[2013-08-11 16:13:58 | 000,000,077 | ---- | C] () -- C:\Windows\wininit.ini[2013-08-11 10:21:54 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin[2013-08-11 10:18:04 | 001,640,860 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI[2013-07-24 01:19:00 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe[2013-07-24 01:18:58 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe[2013-07-24 00:22:44 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat[2013-07-24 00:22:44 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat========== ZeroAccess Check ==========[2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32][HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32][HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64"" = C:\Windows\SysNative\shell32.dll -- [2014-06-25 03:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Apartment[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]"" = %SystemRoot%\system32\shell32.dll -- [2014-06-25 02:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Apartment[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Free[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Free[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Both[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]========== Alternate Data Streams ==========@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\PnkBstrB.xtr:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\PnkBstrB.exe:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\PnkBstrB.ex0:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\OVDecode.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\OpenVideo.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\OpenCL.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\mantleaxl32.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\mantle32.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\ieUnatt.exe:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\atiuxpag.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\atiumdva.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\atiumdag.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\atiu9pag.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\atisamu32.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\atioglxx.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\atimpc32.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\atiglpxx.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\atigktxx.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\atidxx32.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\aticfx32.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\aticalrt.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\aticaldd.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\aticalcl.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\atiadlxy.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\amdpcom32.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\amdocl.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\amdmmcl.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\amdmantle32.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\amdhcp32.dll:$CmdTcID@Alternate Data Stream - 64 bytes -> C:\Windows\SysWow64\amdave32.dll:$CmdTcID< End of report > Link do komentarza Udostępnij na innych stronach More sharing options...
Sevard Napisano Grudzień 30, 2014 Zgłoś Share Napisano Grudzień 30, 2014 Tym dziwnym kontem za bardzo bym się nie przejmował. Najpewniej jakaś pozostałość po jakimś starym koncie lub konto stworzone przez jakiś program, którego używasz.Jesteś pewien, że katalog Moje obrazy się przeniósł? Być może na C po prostu została jego kopia.Jeśli jesteś pewien, że to ten katalog, to spróbuj go przenieść według tego poradnika.Jeśli jesteś w grupie domowej, to jest możliwe, że coś go blokuje w miejscu. W poradniku wyżej jest opisane jak sobie z tym poradzić. Link do komentarza Udostępnij na innych stronach More sharing options...