Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2014 Ran by Suomi (administrator) on SAMSUNG-R780 on 25-01-2014 15:49:32 Running from C:\Users\Kinga\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AMD) C:\Windows\System32\atieclxx.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe () C:\Program Files (x86)\Plus Internet\Plus Internet.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe () C:\Users\Kinga\Downloads\uw5xilhh.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2149160 2010-05-21] (Synaptics Incorporated) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11046504 2010-07-14] (Realtek Semiconductor) HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [206448 2012-10-30] (Kaspersky Lab ZAO) Winlogon\Notify\klogon: C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO) HKCU\...\Policies\system: [LogonHoursAction] 2 HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\PS 80\...\Policies\system: [LogonHoursAction] 2 HKU\PS 80\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=F65300A0C6000000&affID=119357&tsp=4970 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=F65300A0C6000000&affID=119357&tsp=4970 BHO: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll (Kaspersky Lab ZAO) BHO: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO) Toolbar: HKLM-x32 - No Name - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{CB0C6B80-5CB1-4874-AD02-C0795D03450A}: [NameServer]212.2.96.51 212.2.96.52 FireFox: ======== FF ProfilePath: C:\Users\Kinga\AppData\Roaming\Mozilla\Firefox\Profiles\03o36sdt.default FF user.js: detected! => C:\Users\Kinga\AppData\Roaming\Mozilla\Firefox\Profiles\03o36sdt.default\user.js FF Homepage: google.pl FF Keyword.URL: user_pref("keyword.URL", ""); FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Kinga\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Kinga\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Kinga\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Kinga\AppData\Roaming\Mozilla\Firefox\Profiles\03o36sdt.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Kinga\AppData\Roaming\Mozilla\Firefox\Profiles\03o36sdt.default\searchplugins\safeguard-secure-search.xml FF Extension: DownloadHelper - C:\Users\Kinga\AppData\Roaming\Mozilla\Firefox\Profiles\03o36sdt.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013-08-27] FF Extension: QuickStores-Toolbar - C:\Program Files (x86)\Mozilla Firefox\extensions\quickstores@quickstores.de [2013-12-12] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-12] FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru [2012-06-09] FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru FF Extension: Kaspersky Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru [2012-06-09] FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru [2012-06-09] Chrome: ======= CHR HomePage: CHR RestoreOnStartup: "tabs": { "use_vertical_tabs" CHR Plugin: (Shockwave Flash) - C:\Users\Kinga\AppData\Local\Google\Chrome\Application\32.0.1700.76\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\Kinga\AppData\Local\Google\Chrome\Application\32.0.1700.76\pdf.dll () CHR Plugin: (Chrome NaCl) - C:\Users\Kinga\AppData\Local\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Google Gears 0.5.33.0) - C:\Users\Kinga\AppData\Local\Google\Chrome\Application\32.0.1700.76\gears.dll No File CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.0.374_0\plugin/npABPlugin.dll (Kaspersky Lab ZAO) CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.0.477_0\plugin/npVKPlugin.dll (Kaspersky Lab ZAO) CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.0.477_0\plugin/npUrlAdvisor.dll (Kaspersky Lab ZAO) CHR Plugin: (Windows Genuine Advantage) - C:\Program Files (x86)\Mozilla Firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U5) - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Unity Player) - C:\Users\Kinga\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\windows\SysWOW64\npDeployJava1.dll No File CHR Plugin: (Default Plug-in) - default_plugin No File CHR Extension: (Dokumenty Google) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-23] CHR Extension: (Dysk Google) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-23] CHR Extension: (YouTube) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-23] CHR Extension: (Szukaj w Google) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-23] CHR Extension: (Kaspersky URL Advisor) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2012-08-24] CHR Extension: (Krople deszczu(Non-Aero)) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpagcfbbmlebfnkeogkigellbgmfkjfg [2013-09-17] CHR Extension: (Klawiatura wirtualna) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2012-08-24] CHR Extension: (Google Wallet) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31] CHR Extension: (Gmail) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-23] CHR Extension: (Blokowanie banerów) - C:\Users\Kinga\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2012-08-24] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ChromeExt\urladvisor.crx [2011-09-28] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ChromeExt\virtkbd.crx [2011-09-28] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ChromeExt\ab.crx [2011-09-28] ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [206448 2012-10-30] (Kaspersky Lab ZAO) R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-07] () ==================== Drivers (Whitelisted) ==================== R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [460888 2011-03-04] (Kaspersky Lab ZAO) R1 kl2; C:\Windows\System32\DRIVERS\kl2.sys [11864 2011-03-04] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [637272 2012-10-30] (Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29488 2011-03-10] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [22544 2009-11-02] (Kaspersky Lab) S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-11-15] (Windows (R) 2003 DDK 3790 provider) R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 MEMSWEEP2; \??\C:\windows\system32\2465.tmp [x] U3 kxtiiaob; \??\C:\Users\Kinga\AppData\Local\Temp\kxtiiaob.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-25 15:49 - 2014-01-25 15:50 - 00018208 _____ C:\Users\Kinga\Downloads\FRST.txt 2014-01-25 15:46 - 2014-01-25 15:46 - 00068568 _____ C:\Users\Kinga\Desktop\Extras.Txt 2014-01-25 15:43 - 2014-01-25 15:43 - 00136106 _____ C:\Users\Kinga\Desktop\OTL.Txt 2014-01-25 15:35 - 2014-01-25 15:35 - 00380416 _____ C:\Users\Kinga\Downloads\uw5xilhh.exe 2014-01-25 15:30 - 2014-01-25 15:30 - 02077696 _____ (Farbar) C:\Users\Kinga\Downloads\FRST64.exe 2014-01-25 15:30 - 2014-01-25 15:30 - 00000000 ____D C:\FRST 2014-01-25 15:23 - 2014-01-25 15:24 - 00602112 _____ (OldTimer Tools) C:\Users\Kinga\Downloads\OTL.exe 2014-01-25 02:41 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\windows\system32\IEUDINIT.EXE 2014-01-25 02:36 - 2014-01-25 02:36 - 23212032 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 17142784 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 12995584 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 11220992 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 05765120 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 04240384 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-01-25 02:36 - 2014-01-25 02:36 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-01-25 02:36 - 2014-01-25 02:36 - 02332160 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 02166272 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 01993728 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-01-25 02:36 - 2014-01-25 02:36 - 01926656 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-01-25 02:36 - 2014-01-25 02:36 - 01818112 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 01394176 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 01228800 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 01156608 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat 2014-01-25 02:36 - 2014-01-25 02:36 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2014-01-25 02:36 - 2014-01-25 02:36 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00523776 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2014-01-25 02:36 - 2014-01-25 02:36 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec 2014-01-25 02:36 - 2014-01-25 02:36 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00263376 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00244736 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00238288 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2014-01-25 02:36 - 2014-01-25 02:36 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx 2014-01-25 02:36 - 2014-01-25 02:36 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-01-25 02:34 - 2014-01-25 02:41 - 00010277 _____ C:\windows\IE11_main.log 2014-01-25 01:22 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe 2014-01-25 01:21 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll 2014-01-25 01:21 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe 2014-01-25 01:21 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe 2014-01-25 01:20 - 2014-01-25 01:21 - 00005175 _____ C:\windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-25 01:16 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll 2014-01-25 01:16 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL 2014-01-25 01:16 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL 2014-01-25 01:16 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll 2014-01-25 01:10 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys 2014-01-25 01:10 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys 2014-01-25 01:10 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys 2014-01-25 01:10 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys 2014-01-25 01:10 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys 2014-01-25 01:10 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys 2014-01-25 01:10 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys 2014-01-25 01:10 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys 2014-01-25 01:10 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2014-01-19 20:39 - 2014-01-19 20:48 - 00000000 ____D C:\Program Files (x86)\ScreenShooter 2014-01-19 20:39 - 2014-01-19 20:41 - 00000000 ____D C:\Users\Kinga\.screenshooter 2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\windows\SysWOW64\GPhotos.scr ==================== One Month Modified Files and Folders ======= 2014-01-25 15:50 - 2014-01-25 15:49 - 00018208 _____ C:\Users\Kinga\Downloads\FRST.txt 2014-01-25 15:49 - 2011-08-27 11:33 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2014-01-25 15:46 - 2014-01-25 15:46 - 00068568 _____ C:\Users\Kinga\Desktop\Extras.Txt 2014-01-25 15:44 - 2012-11-22 21:09 - 00000000 ____D C:\Users\Kinga\AppData\Roaming\GG 2014-01-25 15:43 - 2014-01-25 15:43 - 00136106 _____ C:\Users\Kinga\Desktop\OTL.Txt 2014-01-25 15:35 - 2014-01-25 15:35 - 00380416 _____ C:\Users\Kinga\Downloads\uw5xilhh.exe 2014-01-25 15:30 - 2014-01-25 15:30 - 02077696 _____ (Farbar) C:\Users\Kinga\Downloads\FRST64.exe 2014-01-25 15:30 - 2014-01-25 15:30 - 00000000 ____D C:\FRST 2014-01-25 15:25 - 2011-11-20 11:55 - 00000000 ____D C:\Users\Kinga\Downloads\Programy komputerowe 2014-01-25 15:24 - 2014-01-25 15:23 - 00602112 _____ (OldTimer Tools) C:\Users\Kinga\Downloads\OTL.exe 2014-01-25 15:23 - 2012-01-18 14:55 - 00001046 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-25 14:57 - 2013-03-23 15:59 - 00001058 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1842668911-658831082-982835230-1000UA.job 2014-01-25 14:19 - 2009-07-14 05:45 - 00014144 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-25 14:19 - 2009-07-14 05:45 - 00014144 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-25 13:09 - 2011-01-28 20:36 - 00000000 ____D C:\Program Files (x86)\English Translator 3 2014-01-25 12:45 - 2010-08-18 20:55 - 00740688 _____ C:\windows\system32\perfh015.dat 2014-01-25 12:45 - 2010-08-18 20:55 - 00156230 _____ C:\windows\system32\perfc015.dat 2014-01-25 12:45 - 2009-07-14 06:13 - 01670590 _____ C:\windows\system32\PerfStringBackup.INI 2014-01-25 11:33 - 2010-12-26 21:37 - 00000000 ____D C:\Users\Kinga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2014-01-25 11:32 - 2010-08-18 19:40 - 01448958 _____ C:\windows\WindowsUpdate.log 2014-01-25 11:29 - 2009-07-14 06:09 - 00000000 ____D C:\windows\System32\Tasks\WPD 2014-01-25 11:28 - 2012-01-18 14:55 - 00001042 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-25 11:28 - 2011-12-19 16:16 - 00065536 _____ C:\windows\system32\Ikeext.etl 2014-01-25 11:28 - 2011-11-18 19:41 - 00154212 _____ C:\windows\setupact.log 2014-01-25 11:28 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT 2014-01-25 04:15 - 2009-07-14 04:20 - 00000000 ____D C:\windows\tracing 2014-01-25 03:49 - 2013-12-04 19:47 - 00000000 ____D C:\Users\Kinga\Desktop\tv fi 2014-01-25 02:52 - 2010-12-26 22:04 - 00001393 _____ C:\Users\Kinga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-25 02:51 - 2011-11-19 12:12 - 00147714 _____ C:\windows\PFRO.log 2014-01-25 02:50 - 2009-07-14 04:20 - 00000000 ____D C:\windows\PolicyDefinitions 2014-01-25 02:45 - 2010-12-27 15:10 - 01635482 _____ C:\windows\SysWOW64\PerfStringBackup.INI 2014-01-25 02:41 - 2014-01-25 02:34 - 00010277 _____ C:\windows\IE11_main.log 2014-01-25 02:36 - 2014-01-25 02:36 - 23212032 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 17142784 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 12995584 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 11220992 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 05765120 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 04240384 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-01-25 02:36 - 2014-01-25 02:36 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-01-25 02:36 - 2014-01-25 02:36 - 02332160 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 02166272 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 01993728 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-01-25 02:36 - 2014-01-25 02:36 - 01926656 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-01-25 02:36 - 2014-01-25 02:36 - 01818112 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 01394176 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 01228800 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 01156608 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat 2014-01-25 02:36 - 2014-01-25 02:36 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2014-01-25 02:36 - 2014-01-25 02:36 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00523776 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2014-01-25 02:36 - 2014-01-25 02:36 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec 2014-01-25 02:36 - 2014-01-25 02:36 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00263376 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00244736 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00238288 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2014-01-25 02:36 - 2014-01-25 02:36 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx 2014-01-25 02:36 - 2014-01-25 02:36 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll 2014-01-25 02:36 - 2014-01-25 02:36 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe 2014-01-25 02:36 - 2014-01-25 02:36 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-01-25 02:22 - 2009-07-14 05:45 - 04932280 _____ C:\windows\system32\FNTCACHE.DAT 2014-01-25 01:50 - 2012-06-21 14:13 - 00000000 ____D C:\Users\Kinga\AppData\Local\Unity 2014-01-25 01:38 - 2010-12-26 21:43 - 00000000 ____D C:\Users\Kinga\AppData\Local\Adobe 2014-01-25 01:34 - 2013-08-10 01:31 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-01-25 01:34 - 2013-08-10 01:31 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-25 01:27 - 2010-12-27 18:37 - 00000000 ____D C:\Users\Kinga\AppData\Roaming\Skype 2014-01-25 01:23 - 2013-10-09 18:22 - 00000000 ____D C:\ProgramData\Oracle 2014-01-25 01:21 - 2014-01-25 01:20 - 00005175 _____ C:\windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-25 01:21 - 2013-10-09 18:21 - 00000000 ____D C:\Program Files (x86)\Java 2014-01-25 01:15 - 2013-07-16 12:18 - 00000000 ____D C:\windows\system32\MRT 2014-01-25 01:12 - 2011-04-14 17:15 - 86054176 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-01-21 22:34 - 2012-10-02 21:31 - 00000000 ____D C:\Users\Kinga\Desktop\ppl 2014-01-19 20:48 - 2014-01-19 20:39 - 00000000 ____D C:\Program Files (x86)\ScreenShooter 2014-01-19 20:41 - 2014-01-19 20:39 - 00000000 ____D C:\Users\Kinga\.screenshooter 2014-01-19 20:39 - 2010-12-26 21:37 - 00000000 ____D C:\Users\Kinga 2014-01-18 23:59 - 2011-09-13 18:26 - 00023552 ____H C:\Users\Kinga\Desktop\photothumb.db 2014-01-18 23:58 - 2011-10-24 21:40 - 00000000 ___HD C:\Users\Kinga\Desktop\.picasaoriginals 2014-01-12 13:48 - 2013-12-13 10:09 - 00000000 ____D C:\Users\Kinga\Desktop\dokum 2014-01-07 22:32 - 2011-02-24 19:16 - 00003397 ____H C:\Users\Kinga\Downloads\.picasa.ini 2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\windows\SysWOW64\GPhotos.scr 2014-01-05 19:32 - 2013-03-23 15:59 - 00001006 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1842668911-658831082-982835230-1000Core.job 2013-12-29 13:31 - 2013-03-15 17:49 - 00000000 ____D C:\Users\PS 80\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite 2013-12-28 13:25 - 2013-03-15 18:20 - 00000000 ____D C:\Users\PS 80\AppData\Local\Mozilla Files to move or delete: ==================== C:\ProgramData\PKP_DLdu.DAT C:\ProgramData\PKP_DLdw.DAT Some content of TEMP: ==================== C:\Users\Kinga\AppData\Local\Temp\DataCard_Setup64.exe C:\Users\Kinga\AppData\Local\Temp\firefoxjre_exe-1.exe C:\Users\Kinga\AppData\Local\Temp\firefoxjre_exe-2.exe C:\Users\Kinga\AppData\Local\Temp\firefoxjre_exe-3.exe C:\Users\Kinga\AppData\Local\Temp\firefoxjre_exe.exe C:\Users\Kinga\AppData\Local\Temp\gg10.upgr.exe C:\Users\Kinga\AppData\Local\Temp\ggdrive-menu.exe C:\Users\Kinga\AppData\Local\Temp\ggdrive-overlay.exe C:\Users\Kinga\AppData\Local\Temp\installstats.exe C:\Users\Kinga\AppData\Local\Temp\install_flashplayer11x64_mssa_aih.exe C:\Users\Kinga\AppData\Local\Temp\ipl46FE.tmp.exe C:\Users\Kinga\AppData\Local\Temp\jre-7u13-windows-i586-iftw.exe C:\Users\Kinga\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe C:\Users\Kinga\AppData\Local\Temp\jre-7u9-windows-i586-iftw.exe C:\Users\Kinga\AppData\Local\Temp\oi_{A3F4143E-C411-4B4F-8639-DE6DC5F15634}.exe C:\Users\Kinga\AppData\Local\Temp\QuickStores_Unlocker.exe C:\Users\Kinga\AppData\Local\Temp\ResetDevice.exe C:\Users\Kinga\AppData\Local\Temp\SkypeSetup.exe C:\Users\Kinga\AppData\Local\Temp\uninst1.exe C:\Users\Kinga\AppData\Local\Temp\UNINSTALL.EXE ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-19 14:46 ==================== End Of Log ============================