Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-11-2013 01 Ran by Hubert (administrator) on DOM-KOMPUTER on 22-11-2013 23:44:28 Running from D:\Hubert\Pobierane Windows 7 Ultimate Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (AMD) C:\Windows\system32\atiesrxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AMD) C:\Windows\system32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (cFos Software GmbH) C:\Program Files (x86)\cFosSpeed\spd.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Malwarebytes Corporation) D:\Programy\Malwarebytes' Anti-Malware\mbamscheduler.exe (SoftPerfect Research) D:\Programy\NetWorx\networx.exe (Malwarebytes Corporation) D:\Programy\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) D:\Programy\Malwarebytes' Anti-Malware\mbamgui.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe (cFos Software GmbH) C:\Program Files (x86)\cFosSpeed\cfosspeed.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Program Files (x86)\Anti-Vibrate Oscar Editor\OscarEditor.exe () C:\Users\Hubert\AppData\Roaming\ACEStream\engine\ace_engine.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe () D:\Programy\HTC\HTC Sync 3.0\htcUPCTLoader.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe () C:\Users\Hubert\AppData\Roaming\ACEStream\updater\ace_update.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [NetWorx] - D:\Programy\NetWorx\networx.exe [4770192 2012-11-24] (SoftPerfect Research) HKLM\...\Run: [COMODO Internet Security] - C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1612504 2013-11-11] (COMODO) HKLM\...\Run: [cFosSpeed] - C:\Program Files (x86)\cFosSpeed\cfosspeed.exe [1587040 2013-04-19] (cFos Software GmbH) HKCU\...\Run: [OscarEditor] - C:\Program Files (x86)\Anti-Vibrate Oscar Editor\OscarEditor.exe [2636800 2010-07-22] () HKCU\...\Run: [AceStream] - C:\Users\Hubert\AppData\Roaming\ACEStream\engine\ace_engine.exe [27904 2013-11-07] () HKCU\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-02-14] (AMD) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [630912 2012-05-04] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [495616 2012-07-27] (MSI) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM-x32\...\Run: [NeroCheck] - C:\Windows\system32\NeroCheck.exe HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKLM-x32\...\Run: [hpqSRMon] - C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\...\Run: [HTC Sync Loader] - D:\Programy\HTC\HTC Sync 3.0\htcUPCTLoader.exe [659456 2013-05-13] () HKLM-x32\...\Run: [Wondershare Helper Compact.exe] - C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1679360 2012-02-28] (Wondershare) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\Dom\...\Run: [DAEMON Tools Lite] - D:\Programy\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd) ==================== Internet (Whitelisted) ==================== StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=as1212&chnl=as1212&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0EtAyD0CyEyC0EtCtCzz0FtN0D0Tzu0CtAtAyDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1551001325 SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=as1212&chnl=as1212&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0EtAyD0CyEyC0EtCtCzz0FtN0D0Tzu0CtAtAyDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1551001325 SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - D:\Programy\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: No Name - {EF7BD87A-8024-11E2-F316-F3E56188709B} - No File BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office12\GR469A~1.DLL [2210608 2006-10-27] (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\..\Interfaces\{0287A2A4-5A66-41FD-910C-9FA8F2F4FC94}: [NameServer]217.17.34.10 217.17.34.68 Tcpip\..\Interfaces\{8118FD10-78CA-4F99-8C25-9FEB1EC1DEB8}: [NameServer]156.154.70.22,156.154.71.22 FireFox: ======== FF ProfilePath: C:\Users\Hubert\AppData\Roaming\Mozilla\Firefox\Profiles\y75fd307.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - D:\Programy\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @veetle.com/vbp;version=0.9.18 - D:\Programy\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 - D:\Programy\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - D:\Programy\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @acestream.net/acestreamplugin,version=2.1.5.3 - C:\Users\Hubert\AppData\Roaming\ACEStream\player\npace_plugin.dll (Innovative Digital Technologies) FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [magicplayer@torrentstream.org] - C:\Users\Hubert\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org FF Extension: TS Magic Player - C:\Users\Hubert\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org FF StartMenuInternet: FIREFOX.EXE - D:\Programy\Mozilla Firefox\firefox.exe Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll () CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - D:\Programy\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation) CHR Plugin: (Shockwave for Director) - D:\Programy\Mozilla Firefox\plugins\np32dsw.dll (Adobe Systems, Inc.) CHR Plugin: (vShare.tv plug-in) - D:\Programy\Mozilla Firefox\plugins\npvsharetvplg.dll (vShare.tv ) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Plugin: (Picasa) - D:\Programy\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Extension: (Sopcast Toolbar) - C:\Users\Hubert\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaajccikcnncidhbokfncpooceanool\26.60999_0 CHR Extension: (Google Docs) - C:\Users\Hubert\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Hubert\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Hubert\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Hubert\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Google Wallet) - C:\Users\Hubert\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (Gmail) - C:\Users\Hubert\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [aaaajccikcnncidhbokfncpooceanool] - C:\ProgramData\AskPartnerNetwork\Toolbar\SPCV7\CRX\ToolbarCR.crx CHR HKLM-x32\...\Chrome\Extension: [dnnajmlhehgnkclpdlggknanmcplloej] - C:\Program Files (x86)\PutLockerDownloader\PutLockerDownloader10.crx CHR HKLM-x32\...\Chrome\Extension: [kpionmjnkbpcdpcflammlgllecmejgjj] - C:\Program Files (x86)\vShare.tv plugin\vshareplg.crx CHR HKLM-x32\...\Chrome\Extension: [nbmafkdmkkckhggblphicnnhlgljnoje] - C:\Program Files (x86)\TornTV.com\torn2_10.crx ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-05-04] (Advanced Micro Devices, Inc.) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [164816 2013-08-16] (APN LLC.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 cFosSpeedS; C:\Program Files (x86)\cFosSpeed\spd.exe [480096 2013-04-19] (cFos Software GmbH) R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6254152 2013-10-20] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [164056 2013-09-24] (COMODO) R2 MBAMScheduler; D:\Programy\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; D:\Programy\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [136704 2012-06-29] (MSI) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () ==================== Drivers (Whitelisted) ==================== R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2011-11-13] (Advanced Micro Devices) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-07-24] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-07-24] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-07-24] () R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2013-09-24] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [709144 2013-11-14] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [48872 2013-09-24] (COMODO) R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-11-30] (DT Soft Ltd) R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [96800 2013-09-24] (COMODO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [14136 2010-01-18] (MSI) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-10-26] (Duplex Secure Ltd.) R3 WsAudioDevice_383S(1); C:\Windows\System32\drivers\WsAudioDevice_383S(1).sys [29288 2013-05-30] (Wondershare) U3 amuj6tuy; C:\Windows\System32\Drivers\amuj6tuy.sys [0 ] (Advanced Micro Devices) S3 DUMeterDrv; \??\D:\Programy\DU Meter\DUMETR64.SYS [x] S3 MSICDSetup; \??\E:\CDriver64.sys [x] S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-22 23:43 - 2013-11-22 23:43 - 00000000 ____D C:\FRST 2013-11-22 17:15 - 2013-11-22 17:15 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1 2013-11-21 13:14 - 2013-11-21 13:14 - 00001229 _____ C:\Users\Hubert\Desktop\cFosSpeed Calibration.lnk 2013-11-21 13:12 - 2013-11-21 13:12 - 00001399 _____ C:\Users\Hubert\Desktop\Funkcje cFosSpeed.lnk 2013-11-21 13:12 - 2013-11-21 13:12 - 00000000 ____D C:\Program Files (x86)\cFosSpeed 2013-11-21 13:12 - 2013-04-19 16:46 - 01736544 _____ (cFos Software GmbH) C:\Windows\system32\Drivers\cfosspeed6.sys 2013-11-21 13:11 - 2013-11-21 13:11 - 00000000 ____D C:\Users\Hubert\AppData\Local\cFos 2013-11-21 13:11 - 2013-11-21 13:11 - 00000000 ____D C:\ProgramData\cFos 2013-11-21 10:52 - 2013-11-22 20:58 - 00000392 _____ C:\Windows\setupact.log 2013-11-21 10:52 - 2013-11-21 10:52 - 00000000 _____ C:\Windows\setuperr.log 2013-11-18 21:28 - 2013-11-18 21:44 - 00000000 ____D C:\Users\Hubert\Desktop\system 2013-11-16 20:48 - 2013-11-16 20:13 - 00004110 _____ C:\Users\Hubert\Desktop\WC Saturday A - 20.00 CE(S)T 2013-11-16 Val di Fiemme HS106 Competition Final Results.txt 2013-11-16 20:48 - 2013-11-16 20:12 - 00003835 _____ C:\Users\Hubert\Desktop\WC Saturday A - 20.00 CE(S)T 2013-11-16 Kuopio HS127 Competition Final Results.txt 2013-11-14 21:31 - 2013-11-14 21:49 - 111121461 _____ C:\Users\Hubert\Desktop\5.flv 2013-11-14 21:14 - 2013-11-14 21:14 - 00000861 _____ C:\Users\Hubert\Desktop\SmartPixel.lnk 2013-11-14 21:14 - 2013-11-14 21:14 - 00000861 _____ C:\Users\Dom\Desktop\SmartPixel.lnk 2013-11-14 21:14 - 2013-11-14 21:14 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartPixel 2013-11-11 18:25 - 2013-11-11 18:25 - 00003140 _____ C:\Windows\System32\Tasks\{A729F0E6-DA3A-4978-B999-CEBD7A057FB9} 2013-11-11 17:58 - 2013-11-11 17:58 - 00000000 ____D C:\Users\Hubert\Desktop\Układ Nerwowy 2013-11-11 14:45 - 2013-11-11 14:45 - 00000000 ____D C:\Users\Hubert\Documents\deluxesj2 2013-11-11 14:34 - 2013-11-11 14:34 - 00000000 ____D C:\Users\Hubert\Documents\Deluxe Ski Jump 4 2013-11-11 14:33 - 2013-11-22 21:21 - 00000000 ____D C:\Program Files\DSJ 4144 2013-11-09 16:28 - 2013-11-22 16:07 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\.ACEStream 2013-11-09 16:28 - 2013-11-09 16:29 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\ACEStream 2013-11-09 16:28 - 2013-11-09 16:28 - 00001994 _____ C:\Users\Hubert\Desktop\Ace Player.lnk 2013-11-09 16:28 - 2013-11-09 16:28 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Stream Media 2013-11-09 16:27 - 2013-11-09 16:27 - 58265760 _____ C:\Users\Hubert\Downloads\Ace_Stream_Media_2.1.5.3_by_Wiziwig_tv.exe 2013-11-05 19:50 - 2013-11-05 19:50 - 00001145 _____ C:\Users\Hubert\Desktop\Anti-Vibrate Oscar Editor.lnk 2013-10-31 17:06 - 2013-10-31 17:06 - 00000000 ____D C:\Users\Hubert\Downloads\ChomikBox 2013-10-31 17:05 - 2013-11-16 14:54 - 00000000 ____D C:\Users\Hubert\AppData\Local\ChomikBox 2013-10-31 17:05 - 2013-11-16 14:51 - 00000000 ____D C:\Users\Hubert\.gstreamer-0.10 2013-10-31 17:05 - 2013-10-31 17:05 - 00000662 _____ C:\Users\Public\Desktop\ChomikBox.lnk 2013-10-31 17:05 - 2013-10-31 17:05 - 00000000 ____D C:\Program Files (x86)\ChomikBox 2013-10-31 16:32 - 2013-10-31 16:32 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\NapiProjekt 2013-10-30 18:31 - 2013-10-30 18:31 - 00000675 _____ C:\Users\Hubert\Desktop\WinRAR.lnk 2013-10-30 18:30 - 2013-10-30 18:30 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-10-29 18:11 - 2013-10-29 18:11 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\OpenFM 2013-10-26 20:07 - 2013-10-26 20:07 - 00000722 _____ C:\Users\Hubert\Desktop\Skoki Narciarskie 2006.lnk 2013-10-26 19:35 - 2013-10-26 19:35 - 00002978 _____ C:\Windows\System32\Tasks\{703496F3-1E7B-4941-9510-98CFE96AA361} 2013-10-26 19:34 - 2013-10-26 19:34 - 00002978 _____ C:\Windows\System32\Tasks\{8CAC3329-76D9-4C53-B7DF-9B70376B9348} 2013-10-26 19:30 - 2013-10-26 19:30 - 00000000 ____D C:\Users\Public\Documents\DAEMON Tools Images 2013-10-26 19:26 - 2013-10-26 19:26 - 00564824 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys 2013-10-26 18:02 - 2013-10-26 18:02 - 00003046 _____ C:\Windows\System32\Tasks\{59EC1C5D-76BB-4998-B9B7-2B8A36F3710E} 2013-10-26 17:59 - 2013-10-26 20:25 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\DAEMON Tools Lite ==================== One Month Modified Files and Folders ======= 2013-11-22 23:43 - 2013-11-22 23:43 - 00000000 ____D C:\FRST 2013-11-22 23:20 - 2013-09-27 21:04 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\GG 2013-11-22 23:14 - 2012-11-30 21:06 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-22 23:13 - 2012-11-30 22:25 - 00001042 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-22 22:17 - 2013-09-27 21:06 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\AIMP3 2013-11-22 21:21 - 2013-11-11 14:33 - 00000000 ____D C:\Program Files\DSJ 4144 2013-11-22 21:21 - 2013-09-27 21:02 - 00000788 _____ C:\Users\Hubert\Desktop\DSJ4.lnk 2013-11-22 21:07 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-22 21:07 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-22 21:03 - 2013-04-26 10:48 - 01429126 _____ C:\Windows\WindowsUpdate.log 2013-11-22 21:00 - 2013-09-27 21:21 - 00000440 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-11-22 21:00 - 2013-09-27 20:51 - 00000000 ____D C:\Users\Hubert\AppData\Local\Htc 2013-11-22 20:59 - 2012-11-30 22:25 - 00001038 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-22 20:58 - 2013-11-21 10:52 - 00000392 _____ C:\Windows\setupact.log 2013-11-22 20:58 - 2013-01-25 15:07 - 00000354 _____ C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job 2013-11-22 20:58 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-22 17:17 - 2011-02-04 18:55 - 00739694 _____ C:\Windows\system32\perfh015.dat 2013-11-22 17:17 - 2011-02-04 18:55 - 00155268 _____ C:\Windows\system32\perfc015.dat 2013-11-22 17:17 - 2009-07-14 06:13 - 01668226 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-22 17:16 - 2013-09-27 20:51 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\HTC 2013-11-22 17:15 - 2013-11-22 17:15 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1 2013-11-22 16:07 - 2013-11-09 16:28 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\.ACEStream 2013-11-21 13:31 - 2013-10-05 15:18 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\Media Player Classic 2013-11-21 13:14 - 2013-11-21 13:14 - 00001229 _____ C:\Users\Hubert\Desktop\cFosSpeed Calibration.lnk 2013-11-21 13:12 - 2013-11-21 13:12 - 00001399 _____ C:\Users\Hubert\Desktop\Funkcje cFosSpeed.lnk 2013-11-21 13:12 - 2013-11-21 13:12 - 00000000 ____D C:\Program Files (x86)\cFosSpeed 2013-11-21 13:11 - 2013-11-21 13:11 - 00000000 ____D C:\Users\Hubert\AppData\Local\cFos 2013-11-21 13:11 - 2013-11-21 13:11 - 00000000 ____D C:\ProgramData\cFos 2013-11-21 10:52 - 2013-11-21 10:52 - 00000000 _____ C:\Windows\setuperr.log 2013-11-20 18:59 - 2013-10-12 19:44 - 00000000 ____D C:\Users\Hubert\AppData\Local\CrashDumps 2013-11-18 21:44 - 2013-11-18 21:28 - 00000000 ____D C:\Users\Hubert\Desktop\system 2013-11-16 20:13 - 2013-11-16 20:48 - 00004110 _____ C:\Users\Hubert\Desktop\WC Saturday A - 20.00 CE(S)T 2013-11-16 Val di Fiemme HS106 Competition Final Results.txt 2013-11-16 20:12 - 2013-11-16 20:48 - 00003835 _____ C:\Users\Hubert\Desktop\WC Saturday A - 20.00 CE(S)T 2013-11-16 Kuopio HS127 Competition Final Results.txt 2013-11-16 19:40 - 2013-10-01 19:56 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\Skype 2013-11-16 15:00 - 2013-09-27 22:18 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\Mp3tag 2013-11-16 14:54 - 2013-10-31 17:05 - 00000000 ____D C:\Users\Hubert\AppData\Local\ChomikBox 2013-11-16 14:51 - 2013-10-31 17:05 - 00000000 ____D C:\Users\Hubert\.gstreamer-0.10 2013-11-14 22:27 - 2013-10-14 12:49 - 00000000 ____D C:\Users\Hubert\Documents\Camtasia Studio 2013-11-14 21:49 - 2013-11-14 21:31 - 111121461 _____ C:\Users\Hubert\Desktop\5.flv 2013-11-14 21:14 - 2013-11-14 21:14 - 00000861 _____ C:\Users\Hubert\Desktop\SmartPixel.lnk 2013-11-14 21:14 - 2013-11-14 21:14 - 00000861 _____ C:\Users\Dom\Desktop\SmartPixel.lnk 2013-11-14 21:14 - 2013-11-14 21:14 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartPixel 2013-11-14 12:38 - 2013-01-24 21:43 - 00043216 _____ (COMODO) C:\Windows\system32\cmdcsr.dll 2013-11-14 12:38 - 2013-01-16 18:51 - 00709144 _____ (COMODO) C:\Windows\system32\Drivers\cmdguard.sys 2013-11-12 17:17 - 2013-09-13 19:03 - 00001838 _____ C:\Users\Public\Desktop\COMODO Firewall.lnk 2013-11-12 16:16 - 2012-11-30 15:36 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-11 18:25 - 2013-11-11 18:25 - 00003140 _____ C:\Windows\System32\Tasks\{A729F0E6-DA3A-4978-B999-CEBD7A057FB9} 2013-11-11 17:58 - 2013-11-11 17:58 - 00000000 ____D C:\Users\Hubert\Desktop\Układ Nerwowy 2013-11-11 14:45 - 2013-11-11 14:45 - 00000000 ____D C:\Users\Hubert\Documents\deluxesj2 2013-11-11 14:34 - 2013-11-11 14:34 - 00000000 ____D C:\Users\Hubert\Documents\Deluxe Ski Jump 4 2013-11-11 10:10 - 2012-11-30 22:34 - 00000000 ____D C:\Users\Dom\AppData\Roaming\AIMP3 2013-11-11 10:01 - 2013-07-23 11:09 - 00000000 ____D C:\Users\Dom\AppData\Local\Htc 2013-11-11 09:54 - 2013-01-16 16:15 - 00003974 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{EF2983C9-F691-47C0-981A-F8061353100E} 2013-11-10 21:23 - 2013-10-12 19:44 - 00000000 ____D C:\Users\Hubert\Documents\FIFA 14 2013-11-10 17:55 - 2013-09-27 21:04 - 00000000 ____D C:\Users\Hubert\AppData\Local\GG 2013-11-09 23:49 - 2013-06-11 15:07 - 00000000 ____D C:\Users\Dom\AppData\Roaming\GG 2013-11-09 23:01 - 2013-03-26 16:57 - 00000000 ____D C:\Users\Dom\AppData\Roaming\vlc 2013-11-09 23:00 - 2013-02-08 14:53 - 00000000 ____D C:\Users\Dom\AppData\Roaming\Media Player Classic 2013-11-09 16:29 - 2013-11-09 16:28 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\ACEStream 2013-11-09 16:28 - 2013-11-09 16:28 - 00001994 _____ C:\Users\Hubert\Desktop\Ace Player.lnk 2013-11-09 16:28 - 2013-11-09 16:28 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Stream Media 2013-11-09 16:27 - 2013-11-09 16:27 - 58265760 _____ C:\Users\Hubert\Downloads\Ace_Stream_Media_2.1.5.3_by_Wiziwig_tv.exe 2013-11-09 16:27 - 2013-10-05 17:03 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\vlc 2013-11-05 19:50 - 2013-11-05 19:50 - 00001145 _____ C:\Users\Hubert\Desktop\Anti-Vibrate Oscar Editor.lnk 2013-11-05 19:48 - 2012-11-30 22:42 - 00000000 ___RD C:\Program Files (x86)\Anti-Vibrate Oscar Editor 2013-11-05 19:48 - 2012-11-30 22:24 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-11-05 19:46 - 2012-11-30 22:41 - 00000000 ____D C:\Program Files (x86)\OscarX7H 2013-11-05 19:31 - 2012-11-30 23:15 - 00000000 ____D C:\Users\Dom\.gstreamer-0.10 2013-11-05 19:16 - 2013-09-27 20:49 - 00000000 ____D C:\Users\Hubert\AppData\Local\VirtualStore 2013-11-03 17:27 - 2013-02-16 12:05 - 00000000 ____D C:\Program Files (x86)\Steam 2013-11-03 15:58 - 2013-10-18 16:39 - 00000000 ____D C:\Users\Hubert\Documents\Euro Truck Simulator 2 2013-10-31 17:06 - 2013-10-31 17:06 - 00000000 ____D C:\Users\Hubert\Downloads\ChomikBox 2013-10-31 17:05 - 2013-10-31 17:05 - 00000662 _____ C:\Users\Public\Desktop\ChomikBox.lnk 2013-10-31 17:05 - 2013-10-31 17:05 - 00000000 ____D C:\Program Files (x86)\ChomikBox 2013-10-31 17:05 - 2013-09-27 20:48 - 00000000 ____D C:\Users\Hubert 2013-10-31 16:32 - 2013-10-31 16:32 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\NapiProjekt 2013-10-30 20:56 - 2013-10-18 16:39 - 00000000 ____D C:\Users\Hubert\Documents\Euro Truck Simulator 2u 2013-10-30 18:31 - 2013-10-30 18:31 - 00000675 _____ C:\Users\Hubert\Desktop\WinRAR.lnk 2013-10-30 18:30 - 2013-10-30 18:30 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-10-29 18:11 - 2013-10-29 18:11 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\OpenFM 2013-10-26 20:25 - 2013-10-26 17:59 - 00000000 ____D C:\Users\Hubert\AppData\Roaming\DAEMON Tools Lite 2013-10-26 20:07 - 2013-10-26 20:07 - 00000722 _____ C:\Users\Hubert\Desktop\Skoki Narciarskie 2006.lnk 2013-10-26 19:35 - 2013-10-26 19:35 - 00002978 _____ C:\Windows\System32\Tasks\{703496F3-1E7B-4941-9510-98CFE96AA361} 2013-10-26 19:34 - 2013-10-26 19:34 - 00002978 _____ C:\Windows\System32\Tasks\{8CAC3329-76D9-4C53-B7DF-9B70376B9348} 2013-10-26 19:30 - 2013-10-26 19:30 - 00000000 ____D C:\Users\Public\Documents\DAEMON Tools Images 2013-10-26 19:26 - 2013-10-26 19:26 - 00564824 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys 2013-10-26 18:02 - 2013-10-26 18:02 - 00003046 _____ C:\Windows\System32\Tasks\{59EC1C5D-76BB-4998-B9B7-2B8A36F3710E} Files to move or delete: ==================== C:\Users\Dom\VideoConverterSetup.exe C:\Users\Dom\AppData\Roaming\Origin C:\Users\Hubert\AppData\Roaming\Origin ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-09 14:14 ==================== End Of Log ============================