Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-02-2014 01 Ran by user (administrator) on USER-HP on 22-02-2014 12:48:44 Running from C:\Users\user.user-HP\Downloads Windows 7 Home Premium (X64) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (McAfee, Inc.) c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe (IDT, Inc.) C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe (Hewlett-Packard) C:\windows\system32\Hpservice.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (DigitalPersona, Inc.) c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (DigitalPersona, Inc.) c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Andrea Electronics Corporation) C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe (LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Adobe Systems, Inc.) C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe () C:\Program Files (x86)\Winamp\winampa.exe (Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Hewlett-Packard Development Company, L.P) c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe (DigitalPersona, Inc.) c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (Hewlett-Packard Company) c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe (Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (ArcSoft, Inc.) C:\windows\system\uArcCapture.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (McAfee, Inc.) c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Macrovision Europe Ltd.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\audiosrv.exe (Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe (Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2010-06-04] (Synaptics Incorporated) HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard) HKLM\...\Run: [BTMTrayAgent] - C:\Program Files\Motorola\Bluetooth\btmshell.dll [24783624 2010-06-11] (Motorola, Inc.) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-03-17] (IDT, Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation) HKLM-x32\...\Run: [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe [563736 2009-10-23] (PDF Complete Inc) HKLM-x32\...\Run: [File Sanitizer] - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [11265536 2009-12-12] (Hewlett-Packard) HKLM-x32\...\Run: [DTRun] - c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [518656 2009-11-19] (ArcSoft Inc.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2012-01-18] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-07] (AVAST Software) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\Winampa.exe [10752 2002-03-20] () HKLM-x32\...\Run: [fst_pl_14] - [X] HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe, Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X] HKU\S-1-5-21-2844552966-4208945487-3739291654-1002\...\Run: [ALLUpdate] - "C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep" HKU\S-1-5-21-2844552966-4208945487-3739291654-1002\...\Run: [AdobeBridge] - C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe [12002664 2011-06-09] (Adobe Systems, Inc.) HKU\S-1-5-21-2844552966-4208945487-3739291654-1002\...\MountPoints2: {4d2a859f-fb3d-11e0-8069-93a0415370d1} - H:\AutoRun.exe HKU\S-1-5-21-2844552966-4208945487-3739291654-1002\...\MountPoints2: {4d2a85b0-fb3d-11e0-8069-93a0415370d1} - H:\AutoRun.exe HKU\S-1-5-21-2844552966-4208945487-3739291654-1002\...\MountPoints2: {4d2a85c3-fb3d-11e0-8069-93a0415370d1} - H:\AutoRun.exe HKU\S-1-5-21-2844552966-4208945487-3739291654-1002\...\MountPoints2: {e920894c-077c-11e1-9732-927b97914ed1} - H:\LaunchU3.exe -a Lsa: [Notification Packages] DPPassFilter scecli ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.meid.pl HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {91A76996-614B-4663-AB9E-58A5FB2CC8A4} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: File Sanitizer for HP ProtectTools - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard) BHO-x32: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Tcpip\Parameters: [DhcpNameServer] 10.150.0.1 192.168.20.1 FireFox: ======== FF ProfilePath: C:\Users\user.user-HP\AppData\Roaming\Mozilla\Firefox\Profiles\c5cutaco.default FF DefaultSearchEngine: Wyszukiwarka filmów w YouTube FF SelectedSearchEngine: Wyszukiwarka filmów w YouTube FF Homepage: google.pl FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_34 - C:\windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\user.user-HP\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npVividasPlayer.dll ( ) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\user.user-HP\AppData\Roaming\Mozilla\Firefox\Profiles\c5cutaco.default\searchplugins\wyszukiwarka-filmw-w-youtube.xml FF Extension: 20-20 3D Viewer - IKEA - C:\Users\user.user-HP\AppData\Roaming\Mozilla\Firefox\Profiles\c5cutaco.default\Extensions\2020Player_IKEA@2020Technologies.com [2013-11-16] FF Extension: Webosave - C:\Users\user.user-HP\AppData\Roaming\Mozilla\Firefox\Profiles\c5cutaco.default\Extensions\hyuy-aafx@xjkcpc.net [2014-02-12] FF Extension: AddThis - C:\Users\user.user-HP\AppData\Roaming\Mozilla\Firefox\Profiles\c5cutaco.default\Extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79} [2013-03-30] FF Extension: SquirrelWeb - C:\Users\user.user-HP\AppData\Roaming\Mozilla\Firefox\Profiles\c5cutaco.default\Extensions\firefox@squirrelweb.org.xpi [2013-11-19] FF Extension: Torntv 3 - C:\Users\user.user-HP\AppData\Roaming\Mozilla\Firefox\Profiles\c5cutaco.default\Extensions\trtv3@trtv.com.xpi [2013-06-30] FF Extension: Address Bar Search - C:\Users\user.user-HP\AppData\Roaming\Mozilla\Firefox\Profiles\c5cutaco.default\Extensions\{badea1ae-72ed-4f6a-8c37-4db9a4ac7bc9}.xpi [2013-10-26] FF Extension: Adblock Plus - C:\Users\user.user-HP\AppData\Roaming\Mozilla\Firefox\Profiles\c5cutaco.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-02] FF Extension: BonanzaDeals - C:\Users\user.user-HP\AppData\Roaming\Mozilla\Firefox\Profiles\c5cutaco.default\Extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca}.xpi [2013-12-29] FF Extension: Blokowanie banerów - C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak [2014-02-19] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA} [2014-02-15] FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\ FF Extension: DigitalPersona Extension - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\ [] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-11-14] Chrome: ======= CHR Extension: (Docs) - C:\Users\user.user-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-28] CHR Extension: (Google Drive) - C:\Users\user.user-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-28] CHR Extension: (YouTube) - C:\Users\user.user-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-28] CHR Extension: (Google Search) - C:\Users\user.user-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-28] CHR Extension: (avast! Online Security) - C:\Users\user.user-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-12-15] CHR Extension: (BonanzaDeals) - C:\Users\user.user-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj [2013-12-28] CHR Extension: (Slick Savings) - C:\Users\user.user-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk [2013-11-28] CHR Extension: (Google Wallet) - C:\Users\user.user-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-15] CHR Extension: (uTorrentControl2) - C:\Users\user.user-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc [2013-11-28] CHR Extension: (Gmail) - C:\Users\user.user-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-28] CHR Extension: (Webosave) - C:\Users\user.user-HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppboodkodgmgeohdnfoocppcfdfdljib [2014-02-12] CHR HKCU\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\user.user-HP\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [2012-04-17] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-20] CHR HKLM-x32\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\user.user-HP\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [2012-04-17] ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AESTFilters; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-07] (AVAST Software) R3 DEBridge; c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [704512 2009-12-16] (McAfee, Inc.) R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [462088 2009-11-25] (DigitalPersona, Inc.) S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [362040 2009-11-17] (Hewlett-Packard Ltd) R2 HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [36864 2009-11-18] (Hewlett-Packard Development Company, L.P) R2 HpFkCryptService; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [281192 2009-12-16] (McAfee, Inc.) R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company) R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [635416 2009-10-23] (PDF Complete Inc) R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe [244736 2010-03-17] (IDT, Inc.) R2 uArcCapture; C:\windows\system\uArcCapture.exe [506472 2009-12-04] (ArcSoft, Inc.) ==================== Drivers (Whitelisted) ==================== R3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [32640 2009-12-04] (ArcSoft, Inc.) R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [78648 2014-02-07] (AVAST Software) R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [92544 2013-11-20] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-20] () R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1038072 2014-02-07] (AVAST Software) R1 aswSP; C:\windows\system32\drivers\aswSP.sys [421704 2014-02-07] (AVAST Software) R3 aswStm; C:\windows\system32\drivers\aswStm.sys [80184 2014-02-07] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-30] () S3 btmaudio; C:\Windows\System32\drivers\btmaud.sys [42496 2010-05-20] (Motorola, Inc.) S3 BTMMODEM; C:\Windows\System32\DRIVERS\btmcom.sys [52736 2010-04-10] (Motorola, Inc.) S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [40760 2009-10-21] (Hewlett-Packard Development Company L.P.) R1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [58184 2009-12-16] (McAfee, Inc.) R1 RsvLock; C:\Windows\SysWow64\Drivers\RsvLock.sys [40088 2009-12-16] (McAfee, Inc.) R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [89216 2009-12-22] (Realtek Semiconductor Corp.) R0 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [56648 2009-12-16] () R0 SafeBoot; C:\Windows\SysWow64\Drivers\SafeBoot.sys [110520 2009-12-16] (McAfee, Inc.) R0 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [60160 2009-06-04] (McAfee, Inc.) R0 SbAlg; C:\Windows\SysWow64\Drivers\SbAlg.sys [51800 2009-12-16] (McAfee, Inc.) R0 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [15688 2009-12-16] (McAfee, Inc.) R0 SbFsLock; C:\Windows\SysWow64\Drivers\SbFsLock.sys [13256 2009-12-16] (McAfee, Inc.) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-22 12:48 - 2014-02-22 12:48 - 00042735 _____ () C:\Users\user.user-HP\Desktop\FRST.txt 2014-02-22 12:47 - 2014-02-22 12:48 - 00023880 _____ () C:\Users\user.user-HP\Downloads\FRST.txt 2014-02-22 12:47 - 2014-02-22 12:47 - 00000000 ____D () C:\Users\user.user-HP\Downloads\FRST-OlderVersion 2014-02-22 12:40 - 2014-02-22 12:40 - 00191862 _____ () C:\Users\user.user-HP\Desktop\OTL.Txt 2014-02-22 12:39 - 2014-02-22 12:39 - 00191862 _____ () C:\Users\user.user-HP\Downloads\OTL.Txt 2014-02-22 12:31 - 2014-02-22 12:31 - 00001304 _____ () C:\Users\user.user-HP\Desktop\AdwCleaner[R6].txt 2014-02-21 21:19 - 2014-02-22 12:48 - 00000000 ____D () C:\FRST 2014-02-21 21:18 - 2014-02-22 12:47 - 02154496 _____ (Farbar) C:\Users\user.user-HP\Downloads\FRST64.exe 2014-02-21 21:16 - 2014-02-22 12:46 - 00000000 ____D () C:\Program Files (x86)\trend micro 2014-02-21 21:16 - 2014-02-21 21:38 - 00000000 ____D () C:\rsit 2014-02-21 21:15 - 2014-02-21 21:15 - 00781383 _____ () C:\Users\user.user-HP\Downloads\RSIT.exe 2014-02-21 17:37 - 2014-02-21 17:37 - 00000000 ____D () C:\_OTL 2014-02-21 17:24 - 2014-02-21 17:24 - 00602112 _____ (OldTimer Tools) C:\Users\user.user-HP\Downloads\OTL.exe 2014-02-21 15:43 - 2014-02-21 15:43 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-21 13:02 - 2014-02-21 15:25 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-02-21 13:02 - 2014-02-21 13:02 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-02-21 12:24 - 2014-02-21 12:53 - 00000000 ____D () C:\Users\user.user-HP\Downloads\Kaspersky Internet Security 2014 14.0.0.5448d Final+Trail Reset 2014-02-21 11:35 - 2014-02-21 13:36 - 00000000 ____D () C:\Users\user.user-HP\Desktop\Kajagoogoo 2014-02-21 11:33 - 2014-02-21 11:34 - 00000000 ____D () C:\Users\user.user-HP\Desktop\Tango in the Night 2014-02-20 15:14 - 2014-02-20 20:42 - 00000000 ____D () C:\Users\user.user-HP\Downloads\Supernatural (1977) 2014-02-19 18:13 - 2014-02-21 15:38 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files 2014-02-19 17:59 - 2014-02-22 12:30 - 00000000 ____D () C:\AdwCleaner 2014-02-19 17:58 - 2014-02-19 17:59 - 01241888 _____ () C:\Users\user.user-HP\Downloads\AdwCleaner.exe 2014-02-15 15:08 - 2014-02-15 15:08 - 00000000 _____ () C:\autoexec.bat 2014-02-15 15:05 - 2014-02-15 15:05 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-02-15 15:03 - 2014-02-15 15:03 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\user.user-HP\Downloads\SpyHunter-Installer.exe 2014-02-15 12:44 - 2014-02-15 14:51 - 00000000 ____D () C:\Users\user.user-HP\Downloads\Breaking Bad Season 1 2014-02-15 09:39 - 2014-02-15 09:39 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-14 18:51 - 2014-02-14 20:34 - 00000000 ____D () C:\Users\user.user-HP\Downloads\Thor.The.Dark.World.2013.HDRip.XviD-AQOS 2014-02-14 18:47 - 2014-02-14 20:34 - 00000000 ____D () C:\Users\user.user-HP\Downloads\Thor (2011) DVDRip XviD-MAXSPEED 2014-02-13 14:49 - 2014-02-13 14:49 - 00000000 _____ () C:\Users\user.user-HP\AppData\Local\{085A0BED-39F1-40F3-A6B2-8EBF1F7664BF} 2014-02-13 12:56 - 2014-02-13 19:01 - 00000000 ____D () C:\Users\user.user-HP\Downloads\Captain America The First Avenger (2011) DVDRip XviD-MAXSPEED 2014-02-12 20:14 - 2014-02-12 20:14 - 00000837 _____ () C:\Users\user.user-HP\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\user.user-HP\AppData\Local\Torch 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\user.user-HP\AppData\Local\Comodo 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Gość\AppData\Local\Torch 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Gość\AppData\Local\Google 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Gość\AppData\Local\Comodo 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Gość 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Administrator 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\ProgramData\InstallMate 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\ProgramData\ca685fbbe3b093c 2014-02-09 21:57 - 2014-02-09 21:57 - 00001689 _____ () C:\Users\user.user-HP\Desktop\toto.m3u 2014-02-05 21:52 - 2014-02-05 21:53 - 05034634 _____ () C:\Users\user.user-HP\Desktop\pierwsze kroki Alusia.avi 2014-02-02 20:25 - 2014-02-04 12:14 - 00000000 ____D () C:\Users\user.user-HP\Desktop\jasiek 2014-02-02 20:10 - 2014-02-02 20:10 - 00302632 _____ () C:\Users\user.user-HP\Downloads\wysyłanie_wiadomości_email_cam00082_cam00085_cam00087_cam000.zip 2014-01-31 11:12 - 2014-01-31 11:12 - 00000000 ____D () C:\Users\user.user-HP\AppData\Roaming\e-Deklaracje 2014-01-30 18:38 - 2014-01-30 18:38 - 00037566 _____ () C:\Users\user.user-HP\Downloads\popticsoneextras_regular.zip 2014-01-29 22:45 - 2014-01-29 22:45 - 00138083 _____ () C:\Users\user.user-HP\Downloads\free-css-drop-down-menu_v1.3.zip 2014-01-29 12:01 - 2014-02-13 14:25 - 00000000 ____D () C:\Users\user.user-HP\Desktop\hereinabove 2014-01-29 11:59 - 2014-01-29 12:00 - 00683077 _____ () C:\Users\user.user-HP\Downloads\hereinabove.zip ==================== One Month Modified Files and Folders ======= 2014-02-22 12:48 - 2014-02-22 12:48 - 00042735 _____ () C:\Users\user.user-HP\Desktop\FRST.txt 2014-02-22 12:48 - 2014-02-22 12:47 - 00023880 _____ () C:\Users\user.user-HP\Downloads\FRST.txt 2014-02-22 12:48 - 2014-02-21 21:19 - 00000000 ____D () C:\FRST 2014-02-22 12:47 - 2014-02-22 12:47 - 00000000 ____D () C:\Users\user.user-HP\Downloads\FRST-OlderVersion 2014-02-22 12:47 - 2014-02-21 21:18 - 02154496 _____ (Farbar) C:\Users\user.user-HP\Downloads\FRST64.exe 2014-02-22 12:46 - 2014-02-21 21:16 - 00000000 ____D () C:\Program Files (x86)\trend micro 2014-02-22 12:40 - 2014-02-22 12:40 - 00191862 _____ () C:\Users\user.user-HP\Desktop\OTL.Txt 2014-02-22 12:39 - 2014-02-22 12:39 - 00191862 _____ () C:\Users\user.user-HP\Downloads\OTL.Txt 2014-02-22 12:31 - 2014-02-22 12:31 - 00001304 _____ () C:\Users\user.user-HP\Desktop\AdwCleaner[R6].txt 2014-02-22 12:30 - 2014-02-19 17:59 - 00000000 ____D () C:\AdwCleaner 2014-02-22 12:13 - 2011-12-07 08:59 - 00001044 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-22 12:10 - 2012-11-13 14:33 - 00000930 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-02-22 11:55 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\tracing 2014-02-22 11:27 - 2009-07-14 05:45 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-22 11:27 - 2009-07-14 05:45 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-22 11:22 - 2010-12-27 16:34 - 01852368 _____ () C:\windows\WindowsUpdate.log 2014-02-22 10:17 - 2013-03-06 19:19 - 00065536 _____ () C:\windows\system32\Ikeext.etl 2014-02-22 10:17 - 2010-09-03 15:56 - 00000000 ____D () C:\ProgramData\HPQLOG 2014-02-22 10:16 - 2011-12-07 08:59 - 00001040 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-22 10:16 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-02-22 10:16 - 2009-07-14 05:51 - 00150156 _____ () C:\windows\setupact.log 2014-02-22 00:19 - 2012-02-02 18:56 - 00001065 _____ () C:\windows\winamp.ini 2014-02-21 23:56 - 2011-10-20 22:54 - 00003958 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{92BE77D6-ED99-445E-BBE4-E3B829C84704} 2014-02-21 22:36 - 2013-10-23 20:46 - 00000000 ____D () C:\Users\user.user-HP\Desktop\BAJKI DO SŁUCHANIA 2014-02-21 22:36 - 2012-01-01 14:21 - 00000000 ____D () C:\Users\user.user-HP\AppData\Roaming\uTorrent 2014-02-21 21:51 - 2013-01-15 15:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-02-21 21:51 - 2011-12-07 08:58 - 00000000 ____D () C:\Users\user.user-HP\AppData\Local\Google 2014-02-21 21:38 - 2014-02-21 21:16 - 00000000 ____D () C:\rsit 2014-02-21 21:15 - 2014-02-21 21:15 - 00781383 _____ () C:\Users\user.user-HP\Downloads\RSIT.exe 2014-02-21 21:10 - 2012-08-23 20:32 - 00000000 ____D () C:\Users\user.user-HP\AppData\Roaming\Mozilla 2014-02-21 21:08 - 2014-01-13 18:00 - 00000000 ____D () C:\Users\user.user-HP\Desktop\seriale 2014-02-21 18:06 - 2010-09-03 16:38 - 00172928 _____ () C:\windows\PFRO.log 2014-02-21 17:37 - 2014-02-21 17:37 - 00000000 ____D () C:\_OTL 2014-02-21 17:24 - 2014-02-21 17:24 - 00602112 _____ (OldTimer Tools) C:\Users\user.user-HP\Downloads\OTL.exe 2014-02-21 15:43 - 2014-02-21 15:43 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-21 15:42 - 2012-11-14 22:28 - 00003924 _____ () C:\windows\System32\Tasks\avast! Emergency Update 2014-02-21 15:40 - 2011-07-15 20:47 - 00000000 ____D () C:\Users\user.user-HP 2014-02-21 15:38 - 2014-02-19 18:13 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files 2014-02-21 15:38 - 2013-12-28 15:13 - 00000000 ____D () C:\Users\user.user-HP\AppData\Roaming\newnext.me 2014-02-21 15:38 - 2011-12-30 17:20 - 00000000 ____D () C:\Users\user.user-HP\AppData\Roaming\NapiProjekt 2014-02-21 15:38 - 2011-11-27 20:06 - 00000000 ____D () C:\windows\system32\Macromed 2014-02-21 15:38 - 2011-11-21 08:47 - 00000000 ___RD () C:\Users\user.user-HP\Desktop\download 2014-02-21 15:38 - 2011-07-18 20:42 - 00000000 ____D () C:\Users\user.user-HP\AppData\Roaming\IrfanView 2014-02-21 15:38 - 2011-07-18 18:59 - 00000000 ____D () C:\Users\user.user-HP\AppData\Roaming\GHISLER 2014-02-21 15:38 - 2011-07-15 22:10 - 00000000 ____D () C:\Program Files (x86)\Winamp 2014-02-21 15:38 - 2010-12-27 16:34 - 00000000 ____D () C:\ProgramData\FLEXnet 2014-02-21 15:38 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\registration 2014-02-21 15:25 - 2014-02-21 13:02 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-02-21 13:36 - 2014-02-21 11:35 - 00000000 ____D () C:\Users\user.user-HP\Desktop\Kajagoogoo 2014-02-21 13:02 - 2014-02-21 13:02 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-02-21 12:53 - 2014-02-21 12:24 - 00000000 ____D () C:\Users\user.user-HP\Downloads\Kaspersky Internet Security 2014 14.0.0.5448d Final+Trail Reset 2014-02-21 11:34 - 2014-02-21 11:33 - 00000000 ____D () C:\Users\user.user-HP\Desktop\Tango in the Night 2014-02-20 20:42 - 2014-02-20 15:14 - 00000000 ____D () C:\Users\user.user-HP\Downloads\Supernatural (1977) 2014-02-19 17:59 - 2014-02-19 17:58 - 01241888 _____ () C:\Users\user.user-HP\Downloads\AdwCleaner.exe 2014-02-16 20:03 - 2010-09-03 15:59 - 00688272 _____ () C:\windows\system32\perfh015.dat 2014-02-16 20:03 - 2010-09-03 15:59 - 00131568 _____ () C:\windows\system32\perfc015.dat 2014-02-16 20:03 - 2009-07-14 06:13 - 01524924 _____ () C:\windows\system32\PerfStringBackup.INI 2014-02-15 15:15 - 2012-08-23 20:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-15 15:08 - 2014-02-15 15:08 - 00000000 _____ () C:\autoexec.bat 2014-02-15 15:05 - 2014-02-15 15:05 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-02-15 15:03 - 2014-02-15 15:03 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\user.user-HP\Downloads\SpyHunter-Installer.exe 2014-02-15 14:51 - 2014-02-15 12:44 - 00000000 ____D () C:\Users\user.user-HP\Downloads\Breaking Bad Season 1 2014-02-15 09:39 - 2014-02-15 09:39 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-15 00:33 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\NDF 2014-02-14 20:34 - 2014-02-14 18:51 - 00000000 ____D () C:\Users\user.user-HP\Downloads\Thor.The.Dark.World.2013.HDRip.XviD-AQOS 2014-02-14 20:34 - 2014-02-14 18:47 - 00000000 ____D () C:\Users\user.user-HP\Downloads\Thor (2011) DVDRip XviD-MAXSPEED 2014-02-14 00:08 - 2011-12-07 08:59 - 00004040 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-14 00:08 - 2011-12-07 08:59 - 00003788 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-13 19:01 - 2014-02-13 12:56 - 00000000 ____D () C:\Users\user.user-HP\Downloads\Captain America The First Avenger (2011) DVDRip XviD-MAXSPEED 2014-02-13 16:04 - 2011-11-20 00:50 - 00000000 ____D () C:\Users\user.user-HP\AppData\Roaming\vlc 2014-02-13 14:49 - 2014-02-13 14:49 - 00000000 _____ () C:\Users\user.user-HP\AppData\Local\{085A0BED-39F1-40F3-A6B2-8EBF1F7664BF} 2014-02-13 14:25 - 2014-01-29 12:01 - 00000000 ____D () C:\Users\user.user-HP\Desktop\hereinabove 2014-02-12 20:14 - 2014-02-12 20:14 - 00000837 _____ () C:\Users\user.user-HP\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2014-02-12 20:14 - 2012-01-01 14:22 - 00000000 ____D () C:\Program Files (x86)\uTorrent 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\user.user-HP\AppData\Local\Torch 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\user.user-HP\AppData\Local\Comodo 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Gość\AppData\Local\Torch 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Gość\AppData\Local\Google 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Gość\AppData\Local\Comodo 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Gość 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\Users\Administrator 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\ProgramData\InstallMate 2014-02-12 20:06 - 2014-02-12 20:06 - 00000000 ____D () C:\ProgramData\ca685fbbe3b093c 2014-02-10 13:42 - 2013-05-01 20:10 - 00000000 ____D () C:\Users\user.user-HP\Desktop\Mazowsze 2014-02-09 21:57 - 2014-02-09 21:57 - 00001689 _____ () C:\Users\user.user-HP\Desktop\toto.m3u 2014-02-08 17:06 - 2011-07-25 19:42 - 00103936 _____ () C:\Users\user.user-HP\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-02-07 15:20 - 2013-12-30 14:31 - 00080184 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys 2014-02-07 15:20 - 2012-11-14 22:28 - 01038072 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys 2014-02-07 15:20 - 2012-11-14 22:28 - 00421704 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys 2014-02-07 15:20 - 2012-11-14 22:28 - 00078648 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2014-02-07 15:20 - 2012-11-14 22:28 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-02-07 15:20 - 2012-09-12 19:09 - 00334136 _____ (AVAST Software) C:\windows\system32\aswBoot.exe 2014-02-07 12:09 - 2013-08-27 16:10 - 00000000 ___RD () C:\Users\user.user-HP\Desktop\folder_______Bogdanka 2014-02-06 16:46 - 2013-01-08 20:36 - 00000000 ____D () C:\Users\user.user-HP\Desktop\Aleksander ur.2013.01.06__ godz. 2.35 2014-02-05 21:53 - 2014-02-05 21:52 - 05034634 _____ () C:\Users\user.user-HP\Desktop\pierwsze kroki Alusia.avi 2014-02-05 11:10 - 2012-11-13 14:33 - 00003868 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-02-05 11:10 - 2012-03-31 06:50 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-02-05 11:10 - 2011-09-15 20:06 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-04 12:14 - 2014-02-02 20:25 - 00000000 ____D () C:\Users\user.user-HP\Desktop\jasiek 2014-02-02 20:10 - 2014-02-02 20:10 - 00302632 _____ () C:\Users\user.user-HP\Downloads\wysyłanie_wiadomości_email_cam00082_cam00085_cam00087_cam000.zip 2014-01-31 11:12 - 2014-01-31 11:12 - 00000000 ____D () C:\Users\user.user-HP\AppData\Roaming\e-Deklaracje 2014-01-31 11:11 - 2014-01-16 13:59 - 00000403 _____ () C:\Users\user.user-HP\Desktop\klucz do netu.txt 2014-01-30 18:38 - 2014-01-30 18:38 - 00037566 _____ () C:\Users\user.user-HP\Downloads\popticsoneextras_regular.zip 2014-01-29 22:45 - 2014-01-29 22:45 - 00138083 _____ () C:\Users\user.user-HP\Downloads\free-css-drop-down-menu_v1.3.zip 2014-01-29 16:20 - 2011-11-17 20:36 - 00000132 _____ () C:\Users\user.user-HP\AppData\Roaming\Adobe PNG Format CS5 Prefs 2014-01-29 12:00 - 2014-01-29 11:59 - 00683077 _____ () C:\Users\user.user-HP\Downloads\hereinabove.zip 2014-01-28 09:03 - 2012-02-20 09:09 - 00000000 ____D () C:\Users\user.user-HP\Desktop\z dysku różne 2014-01-24 16:08 - 2012-03-05 10:23 - 00000000 ____D () C:\Users\user.user-HP\Desktop\temeplatki 2014-01-24 11:37 - 2014-01-12 15:43 - 00000000 ____D () C:\Users\user.user-HP\Desktop\izo 2014-01-23 17:02 - 2011-12-14 18:59 - 00002672 ___SH () C:\ProgramData\KGyGaAvL.sys 2014-01-23 17:02 - 2011-12-14 18:59 - 00000088 __RSH () C:\ProgramData\811C423BE8.sys 2014-01-23 17:02 - 2011-12-14 18:59 - 00000000 ____D () C:\Users\user.user-HP\AppData\Roaming\CorelHomeOffice ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-18 00:36 ==================== End Of Log ============================