Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-01-2014 Ran by Admin (administrator) on DIEGO-LAPTOK on 07-01-2014 01:39:33 Running from F:\ Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe (Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe (pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe (pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe () C:\Windows\System32\PnkBstrA.exe (Autodesk, Inc.) C:\Program Files\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe (Adobe Systems Inc.) C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (PixArt Imaging Incorporation) C:\Windows\PixArt\Pac207\Monitor.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Akamai Technologies, Inc.) C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Akamai Technologies, Inc.) C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [nwiz] - nwiz.exe /installquiet HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NVHotkey] - rundll32.exe C:\Windows\system32\nvHotkey.dll,Start HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated) HKLM\...\Run: [ADSK DLMSession] - C:\Program Files\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [1641368 2013-02-01] (Autodesk, Inc.) HKLM\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [383424 2012-02-05] (Autodesk, Inc.) HKLM\...\Run: [] - [x] HKLM\...\Run: [Acrobat Assistant 8.0] - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe [640376 2008-10-01] (Adobe Systems Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [Monitor] - C:\Windows\PixArt\Pac207\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation) HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-27] (AVAST Software) HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKCU\...\Run: [AQQ] - C:\Program Files\WapSter\WapSter AQQ\AQQ.exe [8174592 2013-10-16] (AQQ Sp. z o.o.) HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Run: [NextLive] - C:\Windows\system32\rundll32.exe "C:\Users\Admin\AppData\Roaming\\nengine.dll",EntryPoint -m l HKCU\...\Policies\Explorer: [] MountPoints2: {34ddfa2e-2d20-11e3-a934-028037ec0200} - E:\autorun.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL ={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Microsoft\Internet Explorer\Main,Search Page ={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL ={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL ={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL ={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL ={searchTerms} BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll (pdfforge GmbH) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] Tcpip\..\Interfaces\{D38AD4CB-203D-4477-890B-B57A19DA248A}: [NameServer], FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\qtvp4u5i.default FF Plugin:,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin:,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: - disabled No File FF Plugin:,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin:,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin:,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: Update;version=3 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Update;version=9 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin:,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM\...\Firefox\Extensions: [] - C:\Program Files\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt FF HKLM\...\Firefox\Extensions: [] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ========================== Services (Whitelisted) ================= R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-27] (AVAST Software) R2 Credential Vault Host Control Service; C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [826312 2012-10-24] (Broadcom Corporation) R2 Credential Vault Host Storage; C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [31688 2012-10-24] (Broadcom Corporation) S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1044816 2013-10-06] (Flexera Software, Inc.) R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-10-05] () R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2014-01-07] (Cherished Technololgy LIMITED) ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2013-12-27] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [79720 2013-12-27] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49944 2013-12-27] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2013-12-27] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2013-12-27] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [64168 2013-12-27] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-12-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [180248 2013-12-27] () R3 cvusbdrv; C:\Windows\System32\Drivers\cvusbdrv.sys [41480 2012-10-24] (Broadcom Corporation) R3 d553bus; C:\Windows\System32\DRIVERS\d553bus.sys [281216 2008-12-19] (MCCI Corporation) R3 d553card; C:\Windows\System32\DRIVERS\d553card.sys [356352 2008-12-19] (MCCI Corporation) R3 d553gps; C:\Windows\System32\DRIVERS\d553gps.sys [77352 2009-01-08] (Dell) R3 d553mdfl; C:\Windows\System32\DRIVERS\d553mdfl.sys [14976 2008-12-19] (MCCI Corporation) R3 d553mdfl2; C:\Windows\System32\DRIVERS\d553mdfl2.sys [14976 2008-12-19] (MCCI Corporation) R3 d553mdm; C:\Windows\System32\DRIVERS\d553mdm.sys [365312 2008-12-19] (MCCI Corporation) R3 d553mdm2; C:\Windows\System32\DRIVERS\d553mdm2.sys [409216 2008-12-19] (MCCI Corporation) R3 d553nd5; C:\Windows\System32\DRIVERS\d553nd5.sys [25984 2008-12-19] (MCCI Corporation) R3 d553scard; C:\Windows\System32\DRIVERS\d553scard.sys [49192 2009-04-06] (Dell) R3 d553unic; C:\Windows\System32\DRIVERS\d553unic.sys [375424 2008-12-19] (MCCI Corporation) S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [507136 2006-12-05] (PixArt Imaging Inc.) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-07 01:38 - 2014-01-07 01:38 - 00000000 ____D C:\FRST 2014-01-07 00:54 - 2014-01-07 00:54 - 00001096 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-07 00:54 - 2014-01-07 00:54 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Mozilla 2014-01-07 00:54 - 2014-01-07 00:54 - 00000000 ____D C:\Users\Admin\AppData\Local\Mozilla 2014-01-07 00:54 - 2014-01-07 00:54 - 00000000 ____D C:\Program Files\Mozilla Firefox 2014-01-07 00:27 - 2014-01-07 00:28 - 00000000 ____D C:\Program Files\Free YouTube Downloader 2014-01-07 00:26 - 2014-01-07 01:01 - 00000000 ____D C:\Users\Admin\AppData\Roaming\ 2014-01-07 00:26 - 2014-01-07 00:27 - 00000000 ____D C:\Users\Admin\AppData\Local\Mobogenie 2014-01-07 00:26 - 2014-01-07 00:26 - 00000000 ____D C:\Users\Admin\Documents\Mobogenie 2014-01-07 00:26 - 2014-01-07 00:26 - 00000000 ____D C:\Users\Admin\AppData\Local\genienext 2014-01-07 00:26 - 2014-01-07 00:26 - 00000000 ____D C:\Users\Admin\.android 2014-01-07 00:26 - 2014-01-07 00:26 - 00000000 ____D C:\ProgramData\WPM 2014-01-07 00:26 - 2014-01-07 00:26 - 00000000 _____ C:\Users\Admin\daemonprocess.txt 2014-01-07 00:25 - 2014-01-07 00:27 - 00000000 ____D C:\Program Files\Mobogenie 2014-01-07 00:24 - 2014-01-07 00:24 - 00640864 _____ C:\Users\Admin\Downloads\FreeYouTubeDownloaderInstallerIC.exe 2014-01-04 18:01 - 2014-01-04 18:01 - 00043525 _____ C:\Users\Admin\Downloads\zdjecie_4702cb22a304d (1) 2014-01-04 18:01 - 2014-01-04 18:01 - 00043525 _____ C:\Users\Admin\Downloads\zdjecie_4702cb22a304d 2013-12-31 16:19 - 2013-12-31 16:23 - 13485616 _____ (Disc Soft Ltd) C:\Users\Admin\Downloads\DTLite4481-0347.exe 2013-12-27 15:44 - 2013-12-27 15:44 - 00000000 ____D C:\Users\Admin\AppData\Roaming\AVAST Software 2013-12-27 10:29 - 2013-12-27 15:49 - 00064168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2013-12-25 13:07 - 2013-12-25 13:07 - 00000000 ____D C:\Windows\PixArt 2013-12-24 23:48 - 2013-12-25 14:47 - 00000000 ____D C:\Users\Admin\Documents\Witcher 2 2013-12-24 23:48 - 2013-12-24 23:48 - 00000000 ____D C:\Users\Admin\AppData\Local\The Witcher 2 2013-12-24 23:48 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2013-12-24 23:48 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2013-12-24 23:48 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2013-12-24 23:48 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2013-12-24 23:48 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2013-12-24 23:48 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2013-12-24 23:48 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2013-12-24 23:48 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2013-12-24 23:48 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2013-12-24 23:48 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2013-12-24 23:48 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2013-12-24 23:48 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2013-12-24 23:48 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2013-12-24 23:48 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2013-12-24 23:48 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2013-12-24 23:48 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2013-12-24 23:48 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2013-12-24 23:48 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2013-12-24 23:48 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2013-12-24 23:48 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2013-12-24 23:48 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2013-12-24 23:48 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2013-12-24 23:48 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2013-12-24 23:48 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2013-12-24 23:48 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2013-12-24 23:48 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2013-12-24 23:48 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2013-12-24 23:48 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2013-12-24 23:48 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2013-12-24 23:48 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2013-12-24 23:48 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2013-12-24 23:48 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2013-12-24 23:48 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2013-12-24 23:48 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2013-12-24 23:48 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2013-12-24 23:48 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2013-12-24 23:48 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2013-12-24 23:48 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2013-12-24 23:48 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2013-12-24 23:48 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2013-12-24 23:48 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2013-12-24 23:48 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2013-12-24 23:48 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2013-12-24 23:48 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2013-12-24 23:48 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2013-12-24 23:48 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2013-12-24 23:48 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2013-12-24 23:48 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2013-12-24 23:48 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2013-12-24 23:48 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2013-12-24 23:48 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2013-12-24 23:48 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2013-12-24 23:48 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2013-12-24 23:48 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2013-12-24 23:48 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2013-12-24 23:48 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2013-12-24 23:48 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2013-12-24 23:48 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2013-12-24 23:48 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2013-12-24 23:48 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2013-12-24 23:48 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2013-12-24 23:48 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2013-12-24 23:48 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2013-12-24 23:48 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2013-12-24 23:48 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2013-12-24 23:48 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2013-12-24 23:48 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2013-12-24 23:48 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2013-12-24 23:48 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2013-12-24 23:48 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2013-12-24 23:48 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2013-12-24 23:48 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2013-12-24 23:48 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2013-12-24 23:48 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2013-12-24 23:48 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2013-12-24 23:48 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2013-12-24 23:48 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2013-12-24 23:48 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2013-12-24 23:48 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2013-12-24 23:48 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2013-12-24 23:48 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2013-12-24 23:48 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2013-12-24 23:47 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2013-12-24 23:47 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2013-12-24 23:47 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2013-12-24 23:47 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2013-12-24 23:47 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2013-12-24 23:47 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2013-12-24 23:47 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2013-12-24 23:47 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2013-12-24 23:47 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2013-12-24 23:41 - 2013-12-24 23:41 - 00000772 _____ C:\Users\Public\Desktop\Wiedźmin 2.lnk 2013-12-24 23:04 - 2013-12-25 14:05 - 00000000 ____D C:\Program Files\Wiedźmin 2 2013-12-17 21:14 - 2013-12-17 21:27 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Aha-soft 2013-12-13 03:04 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-13 03:04 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-13 03:04 - 2013-11-26 10:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-13 03:04 - 2013-11-26 09:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-13 03:04 - 2013-11-26 09:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-13 03:04 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-13 03:04 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-13 03:04 - 2013-11-26 09:36 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-13 03:04 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-13 03:04 - 2013-11-26 09:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-13 03:04 - 2013-11-26 09:29 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-13 03:04 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-13 03:04 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-13 03:04 - 2013-11-26 09:13 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-13 03:04 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-13 03:04 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-13 03:04 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-13 03:04 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-13 03:04 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 19:07 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-12 19:07 - 2013-10-30 02:27 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-12 19:07 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-12 19:07 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-12 19:07 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-12 19:07 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-12 19:07 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-12 19:07 - 2013-10-04 02:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-12 19:07 - 2013-10-04 02:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys ==================== One Month Modified Files and Folders ======= 2014-01-07 01:49 - 2013-10-04 19:22 - 00001034 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-07 01:38 - 2014-01-07 01:38 - 00000000 ____D C:\FRST 2014-01-07 01:22 - 2013-10-05 08:33 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-07 01:16 - 2013-09-30 05:03 - 01441074 _____ C:\Windows\WindowsUpdate.log 2014-01-07 01:01 - 2014-01-07 00:26 - 00000000 ____D C:\Users\Admin\AppData\Roaming\ 2014-01-07 01:00 - 2013-10-04 19:22 - 00001030 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-07 01:00 - 2010-11-20 22:48 - 00164182 _____ C:\Windows\PFRO.log 2014-01-07 01:00 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-07 01:00 - 2009-07-14 05:39 - 00041266 _____ C:\Windows\setupact.log 2014-01-07 00:59 - 2009-07-14 05:34 - 00017072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-07 00:59 - 2009-07-14 05:34 - 00017072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-07 00:54 - 2014-01-07 00:54 - 00001096 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-07 00:54 - 2014-01-07 00:54 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Mozilla 2014-01-07 00:54 - 2014-01-07 00:54 - 00000000 ____D C:\Users\Admin\AppData\Local\Mozilla 2014-01-07 00:54 - 2014-01-07 00:54 - 00000000 ____D C:\Program Files\Mozilla Firefox 2014-01-07 00:49 - 2013-10-04 19:22 - 00000000 ____D C:\Users\Admin\AppData\Local\Google 2014-01-07 00:49 - 2013-10-04 19:22 - 00000000 ____D C:\Program Files\Google 2014-01-07 00:28 - 2014-01-07 00:27 - 00000000 ____D C:\Program Files\Free YouTube Downloader 2014-01-07 00:28 - 2013-10-04 19:29 - 00000000 ___RD C:\Users\Admin\Desktop\Programy 2014-01-07 00:27 - 2014-01-07 00:26 - 00000000 ____D C:\Users\Admin\AppData\Local\Mobogenie 2014-01-07 00:27 - 2014-01-07 00:25 - 00000000 ____D C:\Program Files\Mobogenie 2014-01-07 00:26 - 2014-01-07 00:26 - 00000000 ____D C:\Users\Admin\Documents\Mobogenie 2014-01-07 00:26 - 2014-01-07 00:26 - 00000000 ____D C:\Users\Admin\AppData\Local\genienext 2014-01-07 00:26 - 2014-01-07 00:26 - 00000000 ____D C:\Users\Admin\.android 2014-01-07 00:26 - 2014-01-07 00:26 - 00000000 ____D C:\ProgramData\WPM 2014-01-07 00:26 - 2014-01-07 00:26 - 00000000 _____ C:\Users\Admin\daemonprocess.txt 2014-01-07 00:26 - 2013-10-06 17:12 - 00000000 ____D C:\Users\Admin\AppData\Local\cache 2014-01-07 00:26 - 2013-09-30 05:23 - 00000000 ____D C:\Users\Admin 2014-01-07 00:25 - 2013-09-30 05:23 - 00001637 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-07 00:24 - 2014-01-07 00:24 - 00640864 _____ C:\Users\Admin\Downloads\FreeYouTubeDownloaderInstallerIC.exe 2014-01-07 00:03 - 2011-04-12 06:08 - 00737980 _____ C:\Windows\system32\perfh015.dat 2014-01-07 00:03 - 2011-04-12 06:08 - 00154636 _____ C:\Windows\system32\perfc015.dat 2014-01-07 00:03 - 2010-11-20 22:01 - 01662556 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-06 13:34 - 2013-10-05 13:23 - 00282296 _____ C:\Windows\system32\PnkBstrB.xtr 2014-01-06 13:34 - 2013-10-05 01:39 - 00282296 _____ C:\Windows\system32\PnkBstrB.exe 2014-01-06 13:17 - 2013-10-05 01:40 - 00139648 _____ C:\Windows\system32\Drivers\PnkBstrK.sys 2014-01-06 13:17 - 2013-10-05 01:39 - 00282296 _____ C:\Windows\system32\PnkBstrB.ex0 2014-01-04 18:01 - 2014-01-04 18:01 - 00043525 _____ C:\Users\Admin\Downloads\zdjecie_4702cb22a304d (1) 2014-01-04 18:01 - 2014-01-04 18:01 - 00043525 _____ C:\Users\Admin\Downloads\zdjecie_4702cb22a304d 2014-01-04 15:54 - 2013-10-29 12:18 - 00000000 ____D C:\Users\Admin\Desktop\Zadanko beton 2014-01-04 00:16 - 2013-10-04 19:12 - 00000000 ___RD C:\Users\Admin\Desktop\STUDIA 2014-01-03 12:00 - 2013-12-04 09:51 - 00165076 _____ C:\Users\Admin\Desktop\Dom jednorodzinny.kstxe 2014-01-02 12:02 - 2013-10-04 20:07 - 00000000 ___RD C:\Users\Admin\Desktop\GUZIK 2014-01-02 00:54 - 2013-10-15 19:59 - 00000000 ____D C:\Users\Admin\AppData\Roaming\vlc 2014-01-01 17:23 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF 2013-12-31 16:23 - 2013-12-31 16:19 - 13485616 _____ (Disc Soft Ltd) C:\Users\Admin\Downloads\DTLite4481-0347.exe 2013-12-27 15:49 - 2013-12-27 10:29 - 00064168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2013-12-27 15:44 - 2013-12-27 15:44 - 00000000 ____D C:\Users\Admin\AppData\Roaming\AVAST Software 2013-12-27 10:29 - 2013-09-30 10:28 - 00775952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-12-27 10:29 - 2013-09-30 10:28 - 00410528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-12-27 10:29 - 2013-09-30 10:28 - 00270240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-12-27 10:29 - 2013-09-30 10:28 - 00180248 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-12-27 10:29 - 2013-09-30 10:28 - 00079720 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-12-27 10:29 - 2013-09-30 10:28 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-12-27 10:29 - 2013-09-30 10:28 - 00049944 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-12-27 10:29 - 2013-09-30 10:27 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-12-27 10:09 - 2013-09-30 10:26 - 00000000 ____D C:\ProgramData\AVAST Software 2013-12-27 10:08 - 2009-07-14 03:04 - 00002577 _____ C:\Windows\system32\config.nt 2013-12-27 10:05 - 2009-07-14 03:04 - 00000521 _____ C:\Windows\win.ini 2013-12-26 08:35 - 2009-07-14 05:53 - 00032522 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-25 19:38 - 2013-10-05 11:09 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Skype 2013-12-25 14:47 - 2013-12-24 23:48 - 00000000 ____D C:\Users\Admin\Documents\Witcher 2 2013-12-25 14:15 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-12-25 14:05 - 2013-12-24 23:04 - 00000000 ____D C:\Program Files\Wiedźmin 2 2013-12-25 13:10 - 2013-10-05 11:09 - 00000000 ___RD C:\Program Files\Skype 2013-12-25 13:10 - 2013-10-05 11:09 - 00000000 ____D C:\ProgramData\Skype 2013-12-25 13:07 - 2013-12-25 13:07 - 00000000 ____D C:\Windows\PixArt 2013-12-25 13:07 - 2009-07-14 05:52 - 00000000 ____D C:\Windows\twain_32 2013-12-24 23:48 - 2013-12-24 23:48 - 00000000 ____D C:\Users\Admin\AppData\Local\The Witcher 2 2013-12-24 23:41 - 2013-12-24 23:41 - 00000772 _____ C:\Users\Public\Desktop\Wiedźmin 2.lnk 2013-12-24 23:04 - 2013-11-20 09:23 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-12-19 14:11 - 2013-09-30 10:28 - 00056080 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-12-18 20:55 - 2013-10-08 21:29 - 00000000 ____D C:\Users\Admin\AppData\Local\Microsoft Help 2013-12-17 21:27 - 2013-12-17 21:14 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Aha-soft 2013-12-13 04:12 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2013-12-13 03:22 - 2009-07-14 05:33 - 00500880 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-13 03:20 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\pl-PL 2013-12-13 03:04 - 2013-10-08 21:28 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-13 03:03 - 2013-10-08 15:46 - 00000000 ____D C:\Windows\system32\MRT 2013-12-13 03:02 - 2013-10-08 15:46 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-11 18:22 - 2013-10-05 08:33 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-11 18:22 - 2013-10-05 08:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\AcDeltree.exe C:\Users\Admin\AppData\Local\Temp\AKTYWATOR WINDOWS 7 WSZYSTKIE WERSJE.eXe C:\Users\Admin\AppData\Local\Temp\bitool.dll C:\Users\Admin\AppData\Local\Temp\DLMGuardian.exe C:\Users\Admin\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Admin\AppData\Local\Temp\ose00000.exe C:\Users\Admin\AppData\Local\Temp\SRLDetectionLibrary5644115891606579528.dll C:\Users\Admin\AppData\Local\Temp\vlc-2.1.2-win32.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll [2010-11-20 22:29] - [2010-11-20 22:29] - 0811520 ____A (Microsoft Corporation) 8626F0C30D4E3564FFDD25C90F4426F1 C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-30 01:19 ==================== End Of Log ============================