Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2014 01 Ran by Kuba (administrator) on LAPTOP_TITOL on 12-01-2014 22:20:16 Running from C:\Users\Kuba\Desktop Windows 8.1 (X64) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe (IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe () C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Tablet Driver) C:\Windows\System32\drivers\WTSrv.exe (IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (SoftPerfect Research) C:\Program Files\NetWorx\networx.exe (wifimouse.necta.us) C:\Program Files (x86)\MouseServer\MouseServer.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Dropbox, Inc.) C:\Users\Kuba\AppData\Roaming\Dropbox\bin\Dropbox.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Tablet Driver) C:\Windows\SysWOW64\WTClient.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\System32\WWAHost.exe (Microsoft Corporation) C:\Windows\WinStore\WSHost.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-08-23] (IDT, Inc.) HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\System32\LogiLDA.dll [3933496 2012-09-20] (Logitech, Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3053808 2014-01-03] (Synaptics Incorporated) HKLM\...\Run: [NetWorx] - C:\Program Files\NetWorx\networx.exe [5018832 2013-10-23] (SoftPerfect Research) HKLM-x32\...\Run: [CLVirtualDrive] - C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491320 2012-07-26] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [580512 2012-07-09] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [HP CoolSense] - C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1342008 2011-08-26] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [BtTray] - C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [379904 2013-01-10] (IVT Corporation) HKLM-x32\...\Run: [WTClient] - C:\Windows\SysWOW64\WTClient.exe [40960 2007-04-11] (Tablet Driver) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2013-12-12] (Hewlett-Packard) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [MouseServer] - C:\Program Files (x86)\MouseServer\MouseServer.exe [244736 2013-08-26] (wifimouse.necta.us) MountPoints2: {6b45118c-6275-11e2-be82-28924a54362b} - "H:\LaunchU3.exe" -a MountPoints2: {8c3a63b1-48bc-11e3-824f-e67754097d91} - "D:\AutoRun.exe" HKU\Gość\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516608 2013-08-22] (Microsoft Corporation) Startup: C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Kuba\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe www.google.pl SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM - {49F1323A-CF62-4EE2-8082-99AC15605FC9} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {49F1323A-CF62-4EE2-8082-99AC15605FC9} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Microsoft Web Test Recorder 12.0 Helper - {432dd630-7e03-4c97-9d62-b99f52df4fc2} - F:\Programowanie\Visual Ultimate\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] 62.179.1.63 62.179.1.62 FireFox: ======== FF ProfilePath: C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\m9befa56.default FF NewTab: user_pref("browser.newtab.url", ""); FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @t.garena.com/garenatalk - F:\Programy\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF Extension: Iplex to ALLPlayer - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\m9befa56.default\Extensions\IplextoALL@ALLPlayer.org.xpi [2013-02-04] FF Extension: Transferuj.pl - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\m9befa56.default\Extensions\trtransferfill@transferuj.pl.xpi [2013-02-08] FF Extension: ALLYouTubeDownloader - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\m9befa56.default\Extensions\YouTubetoALL@ALLPlayer.org.xpi [2013-03-01] FF Extension: Adblock Plus - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\m9befa56.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-09] FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn\ [] FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFF [2013-10-10] Chrome: ======= CHR HomePage: hxxp://www.google.pl/ CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Microsoft Office 2013) - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2013) - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Shockwave for Director) - C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) CHR Extension: (Google Docs) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 [2013-09-03] CHR Extension: (Google Drive) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 [2013-08-24] CHR Extension: (YouTube) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 [2013-08-24] CHR Extension: (Google Search) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 [2013-08-24] CHR Extension: (Norton Identity Protection) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.5.2_0 [2013-12-13] CHR Extension: (Google Wallet) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 [2014-01-09] CHR Extension: (Gmail) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 [2013-08-24] CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\Exts\Chrome.crx [2013-12-11] ==================== Services (Whitelisted) ================= U2 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1619704 2013-03-26] (IVT Corporation) U3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [138752 2013-01-10] (IVT Corporation) U3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2014-01-05] (Microsoft Corporation) U3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2013-08-22] (Microsoft Corporation) U2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () U2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation) U2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) U2 Mobile Partner. RunOuc; C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe [655744 2012-09-22] () U2 MsDtsServer100; C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [210784 2010-04-03] (Microsoft Corporation) U2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) U2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation) U2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-11-02] (Microsoft Corporation) U4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) U3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) U3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-04] (Microsoft Corporation) U3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-11-08] (Microsoft Corporation) U3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) U3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) U2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2013-12-03] (Cherished Technololgy LIMITED) ==================== Drivers (Whitelisted) ==================== U0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) U3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) U3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\BASHDefs\20131218.001\BHDrvx64.sys [1526488 2013-12-18] (Symantec Corporation) U3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation) U4 BthAvrcpTg; U4 BthHFEnum; U4 bthhfhid; U3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [56904 2012-07-19] (Ralink Corporation) U3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation) U3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [49584 2013-03-25] (Ralink Corporation) U3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation) U1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) U3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-21] (Symantec Corporation) U3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-21] (Symantec Corporation) U3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) U3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) U0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) U3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\IPSDefs\20140110.001\IDSvia64.sys [521944 2013-12-13] (Symantec Corporation) U0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) U0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) U3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20140111.005\ENG64.SYS [126040 2013-08-29] (Symantec Corporation) U3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20140111.005\EX64.SYS [2099288 2013-08-29] (Symantec Corporation) U3 NdisImPlatformMp; C:\Windows\system32\DRIVERS\NdisImPlatform.sys [124928 2013-08-22] (Microsoft Corporation) U3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) U3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) U1 networx; C:\Windows\System32\drivers\networx.sys [43512 2013-10-21] (NetFilterSDK.com) U3 NPF; C:\Windows\System32\drivers\NPF.sys [35344 2012-09-22] (CACE Technologies, Inc.) U3 NPF; C:\Windows\SysWOW64\drivers\NPF.sys [35344 2012-09-22] (CACE Technologies, Inc.) U3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) U3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.) U3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1149232 2013-03-09] (Ralink Technology, Corp.) U3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation) U3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) U3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-24] (Synaptics Incorporated) U3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2014-01-03] (Synaptics Incorporated) U3 SRTSP; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation) U3 SRTSPX; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation) U0 stornvme; C:\Windows\System32\drivers\stornvme.sys [56672 2013-08-22] (Microsoft Corporation) U3 SymDS; C:\Windows\system32\drivers\NISx64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation) U3 SymEFA; C:\Windows\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation) U0 SymELAM; C:\Windows\System32\drivers\NISx64\1404000.028\SymELAM.sys [23448 2012-06-20] (Symantec Corporation) U3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-19] (Symantec Corporation) U3 SymIRON; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation) U1 SymNetS; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation) U3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) U3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) U3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.) U2 sbapifs; system32\DRIVERS\sbapifs.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-12 22:20 - 2014-01-12 22:20 - 00028350 _____ C:\Users\Kuba\Desktop\FRST.txt 2014-01-12 22:19 - 2014-01-12 22:19 - 00121048 _____ C:\Users\Kuba\Desktop\Extras.Txt 2014-01-12 21:49 - 2014-01-12 22:20 - 00000000 ____D C:\Users\Kuba\Desktop\Nowy folder (4) 2014-01-12 21:46 - 2014-01-12 21:42 - 00688992 _____ (Swearware) C:\Users\Kuba\Desktop\dds.com 2014-01-12 21:46 - 2014-01-12 21:42 - 00602112 _____ (OldTimer Tools) C:\Users\Kuba\Desktop\OTL.exe 2014-01-12 21:45 - 2014-01-12 21:45 - 00000000 ____D C:\FRST 2014-01-12 21:43 - 2014-01-12 21:43 - 02075136 _____ (Farbar) C:\Users\Kuba\Desktop\FRST64.exe 2014-01-12 21:43 - 2014-01-12 21:43 - 00259584 _____ (OldTimer Tools) C:\Users\Kuba\Desktop\OTH.exe 2014-01-12 17:19 - 2014-01-12 17:19 - 00001108 _____ C:\WINDOWS\PFRO.log 2014-01-12 17:10 - 2014-01-12 21:11 - 00000000 ____D C:\Users\Kuba\Desktop\fixpc 2014-01-12 16:28 - 2014-01-12 16:36 - 01059264 _____ C:\Users\Kuba\Downloads\install_flashplayer11x32_mssd_aaa_aih.exe 2014-01-12 16:23 - 2014-01-12 16:31 - 12988600 _____ (Microsoft Corporation) C:\Users\Kuba\Downloads\Silverlight_x64.exe 2014-01-12 16:03 - 2014-01-12 21:05 - 00000309 _____ C:\WINDOWS\setupact.log 2014-01-12 16:03 - 2014-01-12 16:03 - 00000000 _____ C:\WINDOWS\setuperr.log 2014-01-12 15:51 - 2014-01-12 22:03 - 00367542 _____ C:\WINDOWS\WindowsUpdate.log 2014-01-11 20:57 - 2014-01-12 16:19 - 00000000 ____D C:\Users\Kuba\Desktop\MINING 2014-01-09 17:41 - 2014-01-09 17:41 - 00001020 _____ C:\Users\Gość\Desktop\Hard Disk Wipe Tool.lnk 2014-01-09 17:41 - 2014-01-09 17:41 - 00000000 ____D C:\Program Files (x86)\HDDGURU FreeWipe Tool 2014-01-09 15:57 - 2014-01-09 16:20 - 117180214 _____ C:\Users\Kuba\Desktop\1240436.mp4 2014-01-09 15:17 - 2014-01-09 15:17 - 00000000 ____D C:\Users\Default\Documents\Visual Studio 2008 2014-01-09 15:17 - 2014-01-09 15:17 - 00000000 ____D C:\Users\Default User\Documents\Visual Studio 2008 2014-01-08 12:31 - 2014-01-08 18:39 - 00000000 ____D C:\Users\Kuba\Documents\SQL Server Management Studio 2014-01-08 12:31 - 2014-01-08 12:31 - 00000000 ____D C:\Users\Kuba\Documents\Integration Services Script Component 2014-01-08 12:28 - 2014-01-08 12:28 - 00000000 ____D C:\Users\Kuba\Documents\Integration Services Script Task 2014-01-08 12:27 - 2014-01-08 12:27 - 00000000 ____D C:\Program Files\Microsoft Analysis Services 2014-01-08 12:27 - 2014-01-08 12:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services 2014-01-08 12:20 - 2014-01-08 12:20 - 00000000 ____D C:\Users\Kuba\Documents\Visual Studio 2008 2014-01-08 12:14 - 2014-01-08 18:29 - 00000000 ____D C:\Users\Kuba\Documents\Visual Studio 2005 2014-01-07 18:01 - 2014-01-07 18:08 - 00000000 ____D C:\Users\Kuba\Documents\GitHub 2014-01-07 18:00 - 2014-01-07 18:00 - 00000000 ____D C:\Users\Kuba\.ssh 2014-01-07 17:59 - 2014-01-07 22:17 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\GitHub 2014-01-07 17:59 - 2014-01-07 22:17 - 00000000 ____D C:\Users\Kuba\AppData\Local\GitHub 2014-01-07 17:59 - 2014-01-07 17:59 - 00002219 _____ C:\Users\Kuba\Desktop\Git Shell.lnk 2014-01-07 17:59 - 2014-01-07 17:59 - 00000308 _____ C:\Users\Kuba\Desktop\GitHub.appref-ms 2014-01-07 17:59 - 2014-01-07 17:59 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub, Inc 2014-01-06 22:47 - 2014-01-07 22:17 - 00000000 ____D C:\Users\Kuba\AppData\Local\Deployment 2014-01-06 22:47 - 2014-01-06 22:47 - 00000000 ____D C:\Users\Kuba\AppData\Local\Apps\2.0 2014-01-06 21:39 - 2014-01-06 21:39 - 00000000 ____D C:\ProgramData\Microsoft Visual Studio 2014-01-06 11:32 - 2014-01-06 11:32 - 00000000 ____D C:\ProgramData\SoftPerfect 2014-01-06 11:32 - 2014-01-06 11:32 - 00000000 ____D C:\Program Files\NetWorx 2014-01-06 11:32 - 2013-10-21 20:11 - 00043512 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\networx.sys 2014-01-06 00:20 - 2014-01-06 00:20 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bitcoin 2014-01-05 23:24 - 2014-01-05 23:24 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\NuGet 2014-01-05 20:14 - 2014-01-06 22:51 - 00000000 ____D C:\Users\Kuba\Documents\Visual Studio 2013 2014-01-05 20:11 - 2014-01-05 20:11 - 00000000 ____D C:\Program Files\Microsoft Identity Extensions 2014-01-05 20:11 - 2014-01-05 20:11 - 00000000 ____D C:\Program Files (x86)\Workflow Manager Tools 2014-01-05 20:11 - 2014-01-05 20:11 - 00000000 ____D C:\Program Files (x86)\Open XML SDK 2014-01-05 20:10 - 2014-01-05 20:10 - 00000000 ____D C:\Program Files\Windows Identity Foundation 2014-01-05 20:03 - 2014-01-05 20:03 - 00000000 ____D C:\Program Files\Application Verifier 2014-01-05 20:03 - 2014-01-05 20:03 - 00000000 ____D C:\Program Files (x86)\Application Verifier 2014-01-05 20:02 - 2014-01-05 20:02 - 00000000 ____D C:\ProgramData\Windows App Certification Kit 2014-01-05 19:44 - 2014-01-05 19:44 - 00000000 ____D C:\ProgramData\PreEmptive Solutions 2014-01-05 19:42 - 2014-01-05 19:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 12.0 2014-01-05 19:42 - 2014-01-05 19:42 - 00000000 ____D C:\Program Files (x86)\Axence 2014-01-05 19:39 - 2014-01-05 19:42 - 00000000 ____D C:\Program Files (x86)\Microsoft ASP.NET 2014-01-05 19:38 - 2014-01-05 19:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Web Tools 2014-01-05 19:37 - 2014-01-05 19:37 - 00000000 ____D C:\Program Files\IIS Express 2014-01-05 19:37 - 2014-01-05 19:37 - 00000000 ____D C:\Program Files (x86)\IIS Express 2014-01-05 19:36 - 2014-01-05 19:36 - 00000000 ____D C:\ProgramData\NuGet 2014-01-05 19:36 - 2014-01-05 19:36 - 00000000 ____D C:\Program Files (x86)\NuGet 2014-01-05 19:35 - 2014-01-05 19:35 - 00000000 ____D C:\Program Files (x86)\Microsoft WCF Data Services 2014-01-05 19:34 - 2014-01-05 19:34 - 00000000 ____D C:\Program Files\IIS 2014-01-05 19:34 - 2014-01-05 19:34 - 00000000 ____D C:\Program Files (x86)\IIS 2014-01-05 19:30 - 2014-01-05 19:30 - 00000000 ____D C:\Users\Kuba\AppData\Local\Microsoft_Corporation 2014-01-05 19:26 - 2014-01-05 19:52 - 00000000 ____D C:\Program Files (x86)\Windows Kits 2014-01-05 19:26 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll 2014-01-05 19:16 - 2014-01-05 19:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Help Viewer 2014-01-05 19:16 - 2014-01-05 19:16 - 00000000 ____D C:\Program Files (x86)\HTML Help Workshop 2014-01-05 18:40 - 2014-01-05 18:40 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_SensorsSimulatorDriver_01_11_00.Wdf 2014-01-05 18:40 - 2014-01-05 18:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 11.0 2014-01-05 18:39 - 2014-01-05 18:39 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 12.0 2014-01-05 18:34 - 2014-01-05 20:13 - 00000000 ____D C:\ProgramData\Package Cache 2014-01-05 18:31 - 2014-01-05 18:31 - 00000000 ____D C:\Users\Kuba\Downloads\Visual Studio Ultimate 2013 32-bit - Web Installer (English) 2014-01-05 17:56 - 2014-01-12 14:52 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Bitcoin 2014-01-05 16:36 - 2014-01-05 16:36 - 11687960 _____ (Bitcoin project) C:\Users\Kuba\Desktop\bitcoin-0.8.6-win32-setup.exe 2014-01-05 14:23 - 2014-01-05 14:23 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\e-academy Inc 2014-01-05 14:23 - 2014-01-05 14:23 - 00000000 ____D C:\Users\Kuba\AppData\Local\e-academy Inc 2014-01-04 10:10 - 2014-01-04 10:10 - 00000000 _____ C:\Users\Kuba\Desktop\Nowy dokument tekstowy.txt 2014-01-03 23:36 - 2014-01-03 23:36 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\PDAppFlex 2014-01-03 18:13 - 2014-01-03 18:12 - 01060080 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynCOM.dll 2014-01-03 18:13 - 2014-01-03 18:12 - 00544496 _____ (Synaptics Incorporated) C:\WINDOWS\SysWOW64\SynCom.dll 2014-01-03 18:13 - 2014-01-03 18:12 - 00495856 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\SynTP.sys 2014-01-03 18:13 - 2014-01-03 18:12 - 00264432 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynTPAPI.dll 2014-01-03 18:13 - 2014-01-03 18:12 - 00192240 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynTPCo18.dll 2014-01-03 18:13 - 2014-01-03 18:12 - 00151280 _____ (Synaptics Incorporated) C:\WINDOWS\SysWOW64\SynTPCom.dll 2014-01-03 18:13 - 2014-01-03 18:12 - 00033008 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\Smb_driver_Intel.sys 2014-01-03 18:12 - 2014-01-03 18:12 - 00000000 ____D C:\Users\Kuba\Downloads\TeamViewerPortable_pl 2014-01-03 18:11 - 2014-01-03 18:11 - 11498668 _____ C:\Users\Kuba\Downloads\TeamViewerPortable_pl.zip 2014-01-03 13:46 - 2014-01-03 15:22 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\DogeCoin 2014-01-03 13:46 - 2014-01-03 13:46 - 00000000 ____D C:\ProgramData\boost_interprocess 2014-01-02 13:22 - 2014-01-12 15:16 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Litecoin 2014-01-02 13:22 - 2014-01-02 13:22 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Litecoin 2014-01-02 13:22 - 2014-01-02 13:22 - 00000000 ____D C:\Program Files (x86)\Litecoin 2013-12-30 17:32 - 2013-12-30 17:32 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-12-30 17:25 - 2013-12-30 17:25 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2013-12-30 17:25 - 2013-12-30 17:25 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2013-12-29 02:17 - 2013-12-29 02:17 - 00000000 ____D C:\Users\Kuba\Documents\PKR 2013-12-29 01:45 - 2013-12-29 01:45 - 02353240 _____ (PKR Ltd) C:\Users\Kuba\Desktop\pkrinstall.exe 2013-12-21 17:40 - 2013-12-21 17:40 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Internet Security 2013-12-16 12:41 - 2013-12-29 10:40 - 00000000 ____D C:\Users\Kuba\AppData\Local\PokerStars.EU 2013-12-16 12:41 - 2013-12-16 12:41 - 00001120 _____ C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\PokerStars.eu.lnk 2013-12-16 12:41 - 2013-12-16 12:41 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerStars.EU 2013-12-16 12:40 - 2013-12-16 12:46 - 00000000 ____D C:\Program Files (x86)\PokerStars.EU 2013-12-15 18:08 - 2013-11-12 00:41 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-12-15 18:08 - 2013-11-12 00:40 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-12-15 18:08 - 2013-11-12 00:27 - 00701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2013-12-15 18:08 - 2013-11-12 00:24 - 00840704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2013-12-15 18:08 - 2013-11-11 03:48 - 00039768 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys 2013-12-15 18:08 - 2013-11-09 12:55 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2013-12-15 18:08 - 2013-11-09 07:37 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe 2013-12-15 18:08 - 2013-11-09 06:56 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe 2013-12-15 18:08 - 2013-11-08 11:26 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll 2013-12-15 18:08 - 2013-11-08 05:43 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2013-12-15 18:08 - 2013-11-08 05:28 - 13177344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2013-12-15 18:08 - 2013-11-08 05:26 - 11674624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2013-12-15 18:08 - 2013-11-08 05:16 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll 2013-12-15 18:08 - 2013-11-08 05:15 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2013-12-15 18:08 - 2013-11-08 04:41 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2013-12-15 18:08 - 2013-11-08 04:14 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2013-12-15 18:08 - 2013-11-05 15:19 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2013-12-15 18:08 - 2013-11-05 15:03 - 00637952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2013-12-15 18:08 - 2013-11-05 14:57 - 00479744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2013-12-15 18:08 - 2013-11-05 14:33 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2013-12-15 18:08 - 2013-11-05 14:32 - 00744448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2013-12-15 18:08 - 2013-11-04 18:13 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2013-12-15 18:08 - 2013-11-04 14:07 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll 2013-12-15 18:08 - 2013-11-04 12:50 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2013-12-15 18:08 - 2013-11-04 11:32 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll 2013-12-15 18:08 - 2013-11-04 03:28 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll 2013-12-15 18:08 - 2013-11-04 02:30 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2013-12-15 18:08 - 2013-11-01 12:39 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2013-12-15 18:08 - 2013-11-01 07:08 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll 2013-12-15 18:08 - 2013-11-01 06:57 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll 2013-12-15 18:08 - 2013-10-31 01:58 - 00372568 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys 2013-12-15 18:08 - 2013-10-31 01:42 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2013-12-15 18:08 - 2013-10-31 01:33 - 01642016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2013-12-15 18:08 - 2013-10-31 01:33 - 01506680 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2013-12-15 18:08 - 2013-10-31 01:33 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2013-12-15 18:08 - 2013-10-31 01:33 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2013-12-15 18:08 - 2013-10-26 02:54 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys 2013-12-15 18:08 - 2013-10-24 10:31 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll 2013-12-15 18:08 - 2013-10-24 10:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll 2013-12-15 18:08 - 2013-10-17 12:21 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2013-12-15 18:08 - 2013-10-17 11:36 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2013-12-15 18:08 - 2013-10-10 12:53 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2013-12-15 18:08 - 2013-10-10 12:21 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2013-12-15 18:08 - 2013-10-05 15:21 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2013-12-15 18:08 - 2013-10-05 15:21 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2013-12-15 18:08 - 2013-10-05 13:05 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2013-12-15 18:08 - 2013-10-05 13:05 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2013-12-15 18:07 - 2013-11-08 05:07 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll 2013-12-15 18:07 - 2013-11-04 18:13 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2013-12-13 10:48 - 2013-12-13 11:10 - 00000000 ____D C:\Users\Kuba\visualparadigm 2013-12-13 10:45 - 2013-12-13 10:47 - 00000000 ____D C:\Program Files\Visual Paradigm for UML 10.2 ==================== One Month Modified Files and Folders ======= 2014-01-12 22:20 - 2014-01-12 22:20 - 00028350 _____ C:\Users\Kuba\Desktop\FRST.txt 2014-01-12 22:20 - 2014-01-12 21:49 - 00000000 ____D C:\Users\Kuba\Desktop\Nowy folder (4) 2014-01-12 22:19 - 2014-01-12 22:19 - 00121048 _____ C:\Users\Kuba\Desktop\Extras.Txt 2014-01-12 22:14 - 2013-03-05 21:25 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-01-12 22:08 - 2013-09-30 05:15 - 02032228 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2014-01-12 22:08 - 2013-09-30 05:00 - 00880442 _____ C:\WINDOWS\system32\perfh015.dat 2014-01-12 22:08 - 2013-09-30 05:00 - 00199400 _____ C:\WINDOWS\system32\perfc015.dat 2014-01-12 22:08 - 2012-12-20 18:11 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-359351017-3853102907-156484211-1001 2014-01-12 22:03 - 2014-01-12 15:51 - 00367542 _____ C:\WINDOWS\WindowsUpdate.log 2014-01-12 22:03 - 2013-08-24 20:39 - 00001066 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-12 22:03 - 2013-01-01 20:20 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Dropbox 2014-01-12 22:02 - 2013-08-23 19:01 - 00003620 _____ C:\WINDOWS\SysWOW64\LOCALSERVICE.INI 2014-01-12 22:02 - 2013-08-23 19:01 - 00000043 _____ C:\WINDOWS\SysWOW64\LOCALDEVICE.INI 2014-01-12 22:02 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2014-01-12 22:02 - 2013-03-22 09:00 - 00000983 _____ C:\WINDOWS\SysWOW64\bscs.ini 2014-01-12 21:45 - 2014-01-12 21:45 - 00000000 ____D C:\FRST 2014-01-12 21:43 - 2014-01-12 21:43 - 02075136 _____ (Farbar) C:\Users\Kuba\Desktop\FRST64.exe 2014-01-12 21:43 - 2014-01-12 21:43 - 00259584 _____ (OldTimer Tools) C:\Users\Kuba\Desktop\OTH.exe 2014-01-12 21:42 - 2014-01-12 21:46 - 00688992 _____ (Swearware) C:\Users\Kuba\Desktop\dds.com 2014-01-12 21:42 - 2014-01-12 21:46 - 00602112 _____ (OldTimer Tools) C:\Users\Kuba\Desktop\OTL.exe 2014-01-12 21:29 - 2013-11-08 22:35 - 00000000 ____D C:\Users\Kuba 2014-01-12 21:28 - 2012-12-31 18:51 - 00000000 _____ C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-01-12 21:28 - 2012-12-21 17:54 - 00000052 _____ C:\WINDOWS\SysWOW64\DOErrors.log 2014-01-12 21:23 - 2013-11-13 21:20 - 00000000 __RDO C:\Users\Kuba\SkyDrive 2014-01-12 21:21 - 2013-01-01 20:23 - 00000000 ___RD C:\Users\Kuba\Dropbox 2014-01-12 21:11 - 2014-01-12 17:10 - 00000000 ____D C:\Users\Kuba\Desktop\fixpc 2014-01-12 21:05 - 2014-01-12 16:03 - 00000309 _____ C:\WINDOWS\setupact.log 2014-01-12 21:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru 2014-01-12 20:55 - 2013-08-24 20:39 - 00001070 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-12 19:38 - 2013-06-28 22:29 - 00000000 ____D C:\Users\Kuba\.VirtualBox 2014-01-12 19:32 - 2013-06-28 22:37 - 00000000 ____D C:\Users\Kuba\VirtualBox VMs 2014-01-12 19:24 - 2013-11-04 19:17 - 1134050816 _____ C:\Users\Kuba\Desktop\XP_PL_SP3_bdsql.vhd 2014-01-12 19:12 - 2013-01-06 03:07 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Winamp 2014-01-12 17:19 - 2014-01-12 17:19 - 00001108 _____ C:\WINDOWS\PFRO.log 2014-01-12 16:36 - 2014-01-12 16:28 - 01059264 _____ C:\Users\Kuba\Downloads\install_flashplayer11x32_mssd_aaa_aih.exe 2014-01-12 16:31 - 2014-01-12 16:23 - 12988600 _____ (Microsoft Corporation) C:\Users\Kuba\Downloads\Silverlight_x64.exe 2014-01-12 16:19 - 2014-01-11 20:57 - 00000000 ____D C:\Users\Kuba\Desktop\MINING 2014-01-12 16:03 - 2014-01-12 16:03 - 00000000 _____ C:\WINDOWS\setuperr.log 2014-01-12 15:57 - 2013-08-22 14:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2014-01-12 15:43 - 2013-11-15 19:33 - 00003996 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{58287F86-2B1B-481C-B062-3A06DA569345} 2014-01-12 15:41 - 2013-11-13 21:17 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\DAEMON Tools Lite 2014-01-12 15:41 - 2013-11-08 22:26 - 00000000 ___DC C:\WINDOWS\Panther 2014-01-12 15:41 - 2012-12-30 18:08 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\BitTorrent 2014-01-12 15:40 - 2013-11-09 11:47 - 00000000 ____D C:\WINDOWS\Minidump 2014-01-12 15:40 - 2013-09-04 13:59 - 00000000 ____D C:\Users\Kuba\AppData\Local\CrashDumps 2014-01-12 15:38 - 2013-01-26 17:48 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs 2014-01-12 15:16 - 2014-01-02 13:22 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Litecoin 2014-01-12 14:52 - 2014-01-05 17:56 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Bitcoin 2014-01-12 14:19 - 2013-11-30 12:12 - 00003166 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForKuba 2014-01-12 14:19 - 2013-11-30 12:12 - 00000354 _____ C:\WINDOWS\Tasks\HPCeeScheduleForKuba.job 2014-01-11 13:57 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\NDF 2014-01-10 18:51 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness 2014-01-09 17:41 - 2014-01-09 17:41 - 00001020 _____ C:\Users\Gość\Desktop\Hard Disk Wipe Tool.lnk 2014-01-09 17:41 - 2014-01-09 17:41 - 00000000 ____D C:\Program Files (x86)\HDDGURU FreeWipe Tool 2014-01-09 16:42 - 2013-03-17 11:01 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\vlc 2014-01-09 16:20 - 2014-01-09 15:57 - 117180214 _____ C:\Users\Kuba\Desktop\1240436.mp4 2014-01-09 15:17 - 2014-01-09 15:17 - 00000000 ____D C:\Users\Default\Documents\Visual Studio 2008 2014-01-09 15:17 - 2014-01-09 15:17 - 00000000 ____D C:\Users\Default User\Documents\Visual Studio 2008 2014-01-09 15:17 - 2013-01-03 18:03 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-08 18:39 - 2014-01-08 12:31 - 00000000 ____D C:\Users\Kuba\Documents\SQL Server Management Studio 2014-01-08 18:29 - 2014-01-08 12:14 - 00000000 ____D C:\Users\Kuba\Documents\Visual Studio 2005 2014-01-08 18:29 - 2013-01-03 18:04 - 00000000 ____D C:\Users\Kuba\AppData\Local\Microsoft Help 2014-01-08 16:25 - 2012-12-20 18:03 - 00000000 ____D C:\Users\Kuba\AppData\Local\Packages 2014-01-08 12:31 - 2014-01-08 12:31 - 00000000 ____D C:\Users\Kuba\Documents\Integration Services Script Component 2014-01-08 12:28 - 2014-01-08 12:28 - 00000000 ____D C:\Users\Kuba\Documents\Integration Services Script Task 2014-01-08 12:27 - 2014-01-08 12:27 - 00000000 ____D C:\Program Files\Microsoft Analysis Services 2014-01-08 12:27 - 2014-01-08 12:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services 2014-01-08 12:20 - 2014-01-08 12:20 - 00000000 ____D C:\Users\Kuba\Documents\Visual Studio 2008 2014-01-08 12:18 - 2013-01-26 17:57 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 9.0 2014-01-08 12:16 - 2013-01-03 21:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2014-01-08 12:12 - 2013-01-26 17:56 - 00000000 ____D C:\WINDOWS\SysWOW64\1033 2014-01-08 12:12 - 2013-01-26 17:56 - 00000000 ____D C:\WINDOWS\system32\1033 2014-01-08 12:11 - 2013-01-26 17:54 - 00000000 ____D C:\Program Files\Microsoft SQL Server 2014-01-08 12:11 - 2013-01-26 17:50 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2014-01-08 10:40 - 2012-12-20 19:44 - 00007602 _____ C:\Users\Kuba\AppData\Local\Resmon.ResmonCfg 2014-01-07 22:17 - 2014-01-07 17:59 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\GitHub 2014-01-07 22:17 - 2014-01-07 17:59 - 00000000 ____D C:\Users\Kuba\AppData\Local\GitHub 2014-01-07 22:17 - 2014-01-06 22:47 - 00000000 ____D C:\Users\Kuba\AppData\Local\Deployment 2014-01-07 18:08 - 2014-01-07 18:01 - 00000000 ____D C:\Users\Kuba\Documents\GitHub 2014-01-07 18:00 - 2014-01-07 18:00 - 00000000 ____D C:\Users\Kuba\.ssh 2014-01-07 17:59 - 2014-01-07 17:59 - 00002219 _____ C:\Users\Kuba\Desktop\Git Shell.lnk 2014-01-07 17:59 - 2014-01-07 17:59 - 00000308 _____ C:\Users\Kuba\Desktop\GitHub.appref-ms 2014-01-07 17:59 - 2014-01-07 17:59 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub, Inc 2014-01-07 17:20 - 2013-01-01 20:21 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-07 17:20 - 2012-12-20 18:05 - 00000000 ___RD C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-06 22:51 - 2014-01-05 20:14 - 00000000 ____D C:\Users\Kuba\Documents\Visual Studio 2013 2014-01-06 22:47 - 2014-01-06 22:47 - 00000000 ____D C:\Users\Kuba\AppData\Local\Apps\2.0 2014-01-06 21:39 - 2014-01-06 21:39 - 00000000 ____D C:\ProgramData\Microsoft Visual Studio 2014-01-06 11:38 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM 2014-01-06 11:35 - 2013-08-22 15:44 - 00499000 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2014-01-06 11:32 - 2014-01-06 11:32 - 00000000 ____D C:\ProgramData\SoftPerfect 2014-01-06 11:32 - 2014-01-06 11:32 - 00000000 ____D C:\Program Files\NetWorx 2014-01-06 02:16 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache 2014-01-06 00:20 - 2014-01-06 00:20 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bitcoin 2014-01-05 23:24 - 2014-01-05 23:24 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\NuGet 2014-01-05 20:13 - 2014-01-05 18:34 - 00000000 ____D C:\ProgramData\Package Cache 2014-01-05 20:11 - 2014-01-05 20:11 - 00000000 ____D C:\Program Files\Microsoft Identity Extensions 2014-01-05 20:11 - 2014-01-05 20:11 - 00000000 ____D C:\Program Files (x86)\Workflow Manager Tools 2014-01-05 20:11 - 2014-01-05 20:11 - 00000000 ____D C:\Program Files (x86)\Open XML SDK 2014-01-05 20:11 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2014-01-05 20:10 - 2014-01-05 20:10 - 00000000 ____D C:\Program Files\Windows Identity Foundation 2014-01-05 20:07 - 2013-01-26 17:50 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2014-01-05 20:07 - 2012-09-02 09:47 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2014-01-05 20:03 - 2014-01-05 20:03 - 00000000 ____D C:\Program Files\Application Verifier 2014-01-05 20:03 - 2014-01-05 20:03 - 00000000 ____D C:\Program Files (x86)\Application Verifier 2014-01-05 20:02 - 2014-01-05 20:02 - 00000000 ____D C:\ProgramData\Windows App Certification Kit 2014-01-05 19:52 - 2014-01-05 19:26 - 00000000 ____D C:\Program Files (x86)\Windows Kits 2014-01-05 19:44 - 2014-01-05 19:44 - 00000000 ____D C:\ProgramData\PreEmptive Solutions 2014-01-05 19:43 - 2013-11-08 22:20 - 00000000 ____D C:\Program Files\MSBuild 2014-01-05 19:42 - 2014-01-05 19:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 12.0 2014-01-05 19:42 - 2014-01-05 19:42 - 00000000 ____D C:\Program Files (x86)\Axence 2014-01-05 19:42 - 2014-01-05 19:39 - 00000000 ____D C:\Program Files (x86)\Microsoft ASP.NET 2014-01-05 19:38 - 2014-01-05 19:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Web Tools 2014-01-05 19:37 - 2014-01-05 19:37 - 00000000 ____D C:\Program Files\IIS Express 2014-01-05 19:37 - 2014-01-05 19:37 - 00000000 ____D C:\Program Files (x86)\IIS Express 2014-01-05 19:36 - 2014-01-05 19:36 - 00000000 ____D C:\ProgramData\NuGet 2014-01-05 19:36 - 2014-01-05 19:36 - 00000000 ____D C:\Program Files (x86)\NuGet 2014-01-05 19:35 - 2014-01-05 19:35 - 00000000 ____D C:\Program Files (x86)\Microsoft WCF Data Services 2014-01-05 19:34 - 2014-01-05 19:34 - 00000000 ____D C:\Program Files\IIS 2014-01-05 19:34 - 2014-01-05 19:34 - 00000000 ____D C:\Program Files (x86)\IIS 2014-01-05 19:30 - 2014-01-05 19:30 - 00000000 ____D C:\Users\Kuba\AppData\Local\Microsoft_Corporation 2014-01-05 19:16 - 2014-01-05 19:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Help Viewer 2014-01-05 19:16 - 2014-01-05 19:16 - 00000000 ____D C:\Program Files (x86)\HTML Help Workshop 2014-01-05 18:40 - 2014-01-05 18:40 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_SensorsSimulatorDriver_01_11_00.Wdf 2014-01-05 18:40 - 2014-01-05 18:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 11.0 2014-01-05 18:39 - 2014-01-05 18:39 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 12.0 2014-01-05 18:38 - 2013-01-12 07:57 - 00000000 ____D C:\ProgramData\Adobe 2014-01-05 18:38 - 2012-12-20 18:05 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Adobe 2014-01-05 18:37 - 2013-11-08 22:20 - 00000000 ____D C:\Program Files (x86)\MSBuild 2014-01-05 18:37 - 2013-01-12 12:05 - 00000000 ____D C:\Program Files (x86)\Adobe 2014-01-05 18:36 - 2013-01-12 07:58 - 00000000 ____D C:\Users\Kuba\AppData\Local\Adobe 2014-01-05 18:31 - 2014-01-05 18:31 - 00000000 ____D C:\Users\Kuba\Downloads\Visual Studio Ultimate 2013 32-bit - Web Installer (English) 2014-01-05 16:36 - 2014-01-05 16:36 - 11687960 _____ (Bitcoin project) C:\Users\Kuba\Desktop\bitcoin-0.8.6-win32-setup.exe 2014-01-05 14:23 - 2014-01-05 14:23 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\e-academy Inc 2014-01-05 14:23 - 2014-01-05 14:23 - 00000000 ____D C:\Users\Kuba\AppData\Local\e-academy Inc 2014-01-05 13:59 - 2013-01-26 17:49 - 00000000 ____D C:\Users\Kuba\Documents\Visual Studio 2010 2014-01-04 10:10 - 2014-01-04 10:10 - 00000000 _____ C:\Users\Kuba\Desktop\Nowy dokument tekstowy.txt 2014-01-03 23:36 - 2014-01-03 23:36 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\PDAppFlex 2014-01-03 18:13 - 2012-08-04 01:02 - 00000000 ____D C:\SWSetup 2014-01-03 18:12 - 2014-01-03 18:13 - 01060080 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynCOM.dll 2014-01-03 18:12 - 2014-01-03 18:13 - 00544496 _____ (Synaptics Incorporated) C:\WINDOWS\SysWOW64\SynCom.dll 2014-01-03 18:12 - 2014-01-03 18:13 - 00495856 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\SynTP.sys 2014-01-03 18:12 - 2014-01-03 18:13 - 00264432 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynTPAPI.dll 2014-01-03 18:12 - 2014-01-03 18:13 - 00192240 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynTPCo18.dll 2014-01-03 18:12 - 2014-01-03 18:13 - 00151280 _____ (Synaptics Incorporated) C:\WINDOWS\SysWOW64\SynTPCom.dll 2014-01-03 18:12 - 2014-01-03 18:13 - 00033008 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\Smb_driver_Intel.sys 2014-01-03 18:12 - 2014-01-03 18:12 - 00000000 ____D C:\Users\Kuba\Downloads\TeamViewerPortable_pl 2014-01-03 18:11 - 2014-01-03 18:11 - 11498668 _____ C:\Users\Kuba\Downloads\TeamViewerPortable_pl.zip 2014-01-03 15:22 - 2014-01-03 13:46 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\DogeCoin 2014-01-03 13:46 - 2014-01-03 13:46 - 00000000 ____D C:\ProgramData\boost_interprocess 2014-01-02 13:22 - 2014-01-02 13:22 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Litecoin 2014-01-02 13:22 - 2014-01-02 13:22 - 00000000 ____D C:\Program Files (x86)\Litecoin 2013-12-30 17:32 - 2013-12-30 17:32 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-12-30 17:25 - 2013-12-30 17:25 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2013-12-30 17:25 - 2013-12-30 17:25 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2013-12-29 10:40 - 2013-12-16 12:41 - 00000000 ____D C:\Users\Kuba\AppData\Local\PokerStars.EU 2013-12-29 02:17 - 2013-12-29 02:17 - 00000000 ____D C:\Users\Kuba\Documents\PKR 2013-12-29 01:45 - 2013-12-29 01:45 - 02353240 _____ (PKR Ltd) C:\Users\Kuba\Desktop\pkrinstall.exe 2013-12-28 20:35 - 2012-09-02 09:39 - 00000000 ____D C:\Program Files (x86)\CyberLink 2013-12-28 20:03 - 2012-09-02 09:35 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard 2013-12-28 19:17 - 2012-09-13 04:52 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-12-25 11:15 - 2012-07-26 09:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2013-12-21 17:40 - 2013-12-21 17:40 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Internet Security 2013-12-21 15:33 - 2012-09-13 05:25 - 00003234 _____ C:\WINDOWS\System32\Tasks\Norton WSC Integration 2013-12-20 16:00 - 2013-08-22 16:36 - 00000000 ___RD C:\WINDOWS\ToastData 2013-12-20 16:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore 2013-12-20 16:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\MediaViewer 2013-12-20 16:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\FileManager 2013-12-20 16:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Camera 2013-12-20 10:56 - 2013-08-24 20:39 - 00000000 ____D C:\Program Files (x86)\Google 2013-12-18 07:59 - 2013-07-14 19:34 - 00000000 ____D C:\WINDOWS\system32\MRT 2013-12-18 07:57 - 2012-12-21 23:46 - 90708896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2013-12-17 10:49 - 2013-02-17 19:35 - 00000000 ____D C:\Program Files\Microsoft Office 15 2013-12-16 12:46 - 2013-12-16 12:40 - 00000000 ____D C:\Program Files (x86)\PokerStars.EU 2013-12-16 12:41 - 2013-12-16 12:41 - 00001120 _____ C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\PokerStars.eu.lnk 2013-12-16 12:41 - 2013-12-16 12:41 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerStars.EU 2013-12-13 17:31 - 2012-12-20 18:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-13 11:10 - 2013-12-13 10:48 - 00000000 ____D C:\Users\Kuba\visualparadigm 2013-12-13 10:47 - 2013-12-13 10:45 - 00000000 ____D C:\Program Files\Visual Paradigm for UML 10.2 2013-12-13 10:44 - 2013-10-24 22:19 - 00000000 ____D C:\Users\Kuba\Desktop\Szkołą Files to move or delete: ==================== C:\Users\Kuba\CS_1.6_Portable.exe Some content of TEMP: ==================== C:\Users\Kuba\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-12 19:48 ==================== End Of Log ============================