Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-02-2014 Ran by Gracz (administrator) on BARTEK on 18-02-2014 18:00:14 Running from C:\Users\Gracz\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Microsoft Corporation) c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (AMD) C:\Windows\system32\atiesrxx.exe (Sandboxie Holdings, LLC) D:\Programy\sandboxie\SbieSvc.exe (AMD) C:\Windows\system32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Hi-Rez Studios) D:\Gry\smite\HiPatchService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe () C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\Grid64.exe () D:\Programy\Icecast2 Win32\icecastService.exe (Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (LogMeIn Inc.) D:\Programy\hamaczi\hamachi-2.exe (LogMeIn, Inc.) D:\Programy\hamaczi\LMIGuardianSvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (GG Network S.A.) D:\Programy\Nowe Gadu-Gadu\Gadu-Gadu 10\gg.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Valve Corporation) D:\Gry\Steam\Steam.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1436736 2011-06-15] (Microsoft Corporation) HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - D:\Programy\hamaczi\hamachi-2-ui.exe [3813712 2014-02-04] (LogMeIn Inc.) HKU\S-1-5-21-3946822230-4172360099-737459869-1000\...\Run: [DAEMON Tools Lite] - D:\Programy\DAEMON Tools Lite\DTLite.exe [3671872 2012-04-17] (DT Soft Ltd) HKU\S-1-5-21-3946822230-4172360099-737459869-1000\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2011-01-12] (AMD) HKU\S-1-5-21-3946822230-4172360099-737459869-1000\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Gracz\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKU\S-1-5-21-3946822230-4172360099-737459869-1000\...\Run: [Grid] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe [401408 2011-01-12] () HKU\S-1-5-21-3946822230-4172360099-737459869-1000\...\Run: [SandboxieControl] - D:\Programy\sandboxie\SbieCtrl.exe [759496 2014-01-17] (Sandboxie Holdings, LLC) HKU\S-1-5-21-3946822230-4172360099-737459869-1000\...\MountPoints2: {a0d12da5-4232-11e3-be12-50e549d30afd} - F:\LGAutoRun.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchingissme.info/?unqvl=23 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchfunmoods.com/?f=1&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyDtD0EyDyEzy0DtAtD0A0F0D0Ezz0EzztN0D0Tzu0CtAtAtDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1224569118 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchingissme.info/?unqvl=23 URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. URLSearchHook: HKCU - (No Name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyDtD0EyDyEzy0DtAtD0A0F0D0Ezz0EzztN0D0Tzu0CtAtAtDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1224569118 SearchScopes: HKLM - {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyDtD0EyDyEzy0DtAtD0A0F0D0Ezz0EzztN0D0Tzu0CtAtAtDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1224569118 SearchScopes: HKLM-x32 - DefaultScope {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyDtD0EyDyEzy0DtAtD0A0F0D0Ezz0EzztN0D0Tzu0CtAtAtDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1224569118 SearchScopes: HKLM-x32 - {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyDtD0EyDyEzy0DtAtD0A0F0D0Ezz0EzztN0D0Tzu0CtAtAtDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1224569118 SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchingissme.info/?unqvl=23&l=1&q={searchTerms} SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10002&barid={1845925A-21E7-11E2-99DA-50E549D30AFD} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerms}&affID=119535&tt=070313_9105&babsrc=SP_ss&mntrId=e099e8e8000000000000000000000000 SearchScopes: HKCU - {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyDtD0EyDyEzy0DtAtD0A0F0D0Ezz0EzztN0D0Tzu0CtAtAtDtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1224569118 SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchingissme.info/?unqvl=23&l=1&q={searchTerms} SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10002&barid={1845925A-21E7-11E2-99DA-50E549D30AFD} BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jreu29\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jr6 2\bin\ssv.dll (Sun Microsystems, Inc.) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jr6 2\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM-x32 - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Toolbar: HKCU - No Name - {00000000-5736-4205-0008-F7ED0776FB27} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Chrome: ======= CHR HomePage: hxxp://www.google.pl/ CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\pdf.dll () CHR Plugin: (QuickTime Plug-in 7.7.2) - D:\Programy\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - D:\Programy\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - D:\Programy\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - D:\Programy\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - D:\Programy\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - D:\Programy\QuickTime\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - D:\Programy\QuickTime\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jr6 2\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) CHR Plugin: (SOE Web Installer) - C:\Users\Gracz\AppData\LocalLow\Sony Online Entertainment\npsoe.dll () CHR Plugin: (Unity Player) - C:\Users\Gracz\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File CHR Extension: (Dysk Google) - C:\Users\Gracz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-29] CHR Extension: (YouTube) - C:\Users\Gracz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-29] CHR Extension: (Szukaj w Google) - C:\Users\Gracz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-29] CHR Extension: (AdBlock) - C:\Users\Gracz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-08-29] CHR Extension: (Google Wallet) - C:\Users\Gracz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29] CHR Extension: (Gmail) - C:\Users\Gracz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-29] CHR HKLM\...\Chrome\Extension: [bbjciahceamgodcoidkjpchnokgfpphh] - C:\Users\Gracz\AppData\Local\funmoods.crx [2012-11-25] CHR HKLM\...\Chrome\Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C:\Users\Gracz\AppData\Local\funmoods-speeddial_sf.crx [2012-11-25] CHR HKCU\...\Chrome\Extension: [bbjciahceamgodcoidkjpchnokgfpphh] - C:\Users\Gracz\AppData\Local\funmoods.crx [2012-11-25] CHR HKCU\...\Chrome\Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C:\Users\Gracz\AppData\Local\funmoods-speeddial_sf.crx [2012-11-25] CHR HKLM-x32\...\Chrome\Extension: [bbjciahceamgodcoidkjpchnokgfpphh] - C:\Users\Gracz\AppData\Local\funmoods.crx [2012-11-25] CHR HKLM-x32\...\Chrome\Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C:\Users\Gracz\AppData\Local\funmoods-speeddial_sf.crx [2012-11-25] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-28] (Advanced Micro Devices, Inc.) R2 Hamachi2Svc; D:\Programy\hamaczi\hamachi-2.exe [2222416 2014-02-04] (LogMeIn Inc.) U2 HiPatchService; D:\Gry\smite\HiPatchService.exe [9216 2013-11-26] (Hi-Rez Studios) R2 Icecast-trunk; D:\Programy\Icecast2 Win32\icecastService.exe [417792 2008-05-24] () R2 MsMpSvc; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [12784 2011-04-27] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [288272 2011-04-27] (Microsoft Corporation) S4 NMSAccess; C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] () S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4703728 2012-11-15] (INCA Internet Co., Ltd.) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2013-11-17] () R2 SbieSvc; D:\Programy\sandboxie\SbieSvc.exe [187592 2014-01-17] (Sandboxie Holdings, LLC) ==================== Drivers (Whitelisted) ==================== S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [303616 2012-06-01] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-04-21] (DT Soft Ltd) S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [35328 2012-06-01] () R1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [189440 2011-04-18] (Microsoft Corporation) R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [84864 2011-04-27] (Microsoft Corporation) R3 SbieDrv; D:\Programy\sandboxie\SbieDrv.sys [202600 2014-01-17] (Sandboxie Holdings, LLC) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10535040 2007-04-03] (Sonix Co. Ltd.) R3 SNPSTD3; C:\Windows\SysWOW64\DRIVERS\snpstd3.sys [10246144 2007-04-03] (Sonix Co. Ltd.) S3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [5504 2009-11-12] () S3 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [7168 2009-11-12] () S3 ALSysIO; \??\C:\Users\Gracz\AppData\Local\Temp\ALSysIO64.sys [X] S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] R4 eamonm; system32\DRIVERS\eamonm.sys [X] R4 ehdrv; system32\DRIVERS\ehdrv.sys [X] S3 gdrv; \??\C:\Windows\gdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-18 18:00 - 2014-02-18 18:00 - 00017497 _____ () C:\Users\Gracz\Desktop\FRST.txt 2014-02-18 17:59 - 2014-02-18 18:00 - 00000000 ____D () C:\FRST 2014-02-18 17:57 - 2014-02-18 17:57 - 00602112 _____ (OldTimer Tools) C:\Users\Gracz\Desktop\OTL.scr 2014-02-18 17:55 - 2014-02-18 17:55 - 02152448 _____ (Farbar) C:\Users\Gracz\Desktop\FRST64.exe 2014-02-18 17:28 - 2014-02-18 17:28 - 00000000 ____D () C:\Users\Gracz\AppData\Local\ESET 2014-02-17 17:15 - 2014-02-17 18:01 - 00001277 _____ () C:\Users\Gracz\Desktop\Nowy dokument tekstowy.txt 2014-02-16 15:12 - 2014-02-16 15:12 - 00000781 _____ () C:\Users\Gracz\Desktop\Counter-Strike 1.6.lnk 2014-02-16 15:12 - 2014-02-16 15:12 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6 2014-02-14 21:54 - 2014-02-14 21:54 - 00071106 _____ () C:\Users\Gracz\Documents\ODSZKODOWANIE.exe 2014-02-14 21:41 - 2014-02-14 21:41 - 00068752 _____ () C:\Users\Gracz\Documents\PREDKOSCiDROGA.exe 2014-02-07 12:47 - 2014-02-07 12:47 - 00272374 _____ () C:\Users\Gracz\AppData\Local\recently-used.xbel 2014-02-06 13:28 - 2014-02-06 13:28 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Natural Selection 2 2014-02-06 11:33 - 2014-02-06 11:33 - 00000000 ____D () C:\Users\Gracz\AppData\Local\My Games 2014-02-04 17:02 - 2014-02-04 17:02 - 00000000 __SHD () C:\ProgramData\DSS 2014-02-04 17:01 - 2014-02-05 20:54 - 00000000 ____D () C:\Program Files (x86)\BRS 2014-02-04 17:01 - 2011-09-05 20:57 - 01306624 _____ (Blue Ripple Sound Limited) C:\Windows\SysWOW64\rapture3d_oal.dll 2014-02-01 13:46 - 2014-02-01 13:46 - 00000000 ___RD () C:\Sandbox 2014-02-01 13:45 - 2014-02-16 19:12 - 00001630 _____ () C:\Windows\Sandboxie.ini 2014-01-31 18:51 - 2014-01-31 18:51 - 00000724 _____ () C:\Users\Public\Desktop\FL Studio 11.lnk 2014-01-31 18:51 - 2014-01-31 18:51 - 00000000 ____D () C:\Users\Gracz\Documents\Image-Line 2014-01-31 18:51 - 2014-01-31 18:51 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line 2014-01-31 18:51 - 2014-01-31 18:51 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Image-Line 2014-01-31 18:51 - 2014-01-31 18:51 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\FlowStone 2014-01-31 18:51 - 2014-01-31 18:51 - 00000000 ____D () C:\Program Files\Image-Line 2014-01-31 18:51 - 2014-01-31 18:51 - 00000000 ____D () C:\Program Files (x86)\DSPRobotics 2014-01-31 18:51 - 2013-03-12 11:47 - 01431552 _____ (Propellerhead Software AB) C:\Windows\SysWOW64\rewire.dll 2014-01-31 18:51 - 2009-09-15 10:14 - 01554944 _____ (HMS http://hp.vector.co.jp/authors/VA012897/) C:\Windows\SysWOW64\vorbis.acm 2014-01-31 18:41 - 2014-01-31 18:41 - 00000000 ____D () C:\Program Files (x86)\Image-Line 2014-01-28 18:46 - 2014-01-28 18:46 - 00001335 _____ () C:\Users\Gracz\Desktop\CorelDRW — skrót.lnk 2014-01-28 00:07 - 2014-01-28 00:07 - 00000000 ____D () C:\Users\Gracz\AppData\Local\ORPALIS 2014-01-27 14:30 - 2009-03-18 17:35 - 00033856 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys 2014-01-26 17:28 - 2014-01-26 17:28 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\PDF Writer 2014-01-26 17:28 - 2013-09-01 11:59 - 01103872 _____ () C:\Windows\SysWOW64\CBLCtlsU.ocx 2014-01-26 17:28 - 2013-07-13 11:15 - 00805376 _____ () C:\Windows\SysWOW64\EditCtlsU.ocx 2014-01-26 17:28 - 2013-07-12 21:57 - 00539648 _____ () C:\Windows\SysWOW64\LblCtlsU.ocx 2014-01-26 17:28 - 2013-04-05 12:55 - 00476160 _____ () C:\Windows\SysWOW64\TabStripCtlU.ocx 2014-01-26 17:28 - 2013-03-28 22:13 - 00645632 _____ () C:\Windows\SysWOW64\BtnCtlsU.ocx 2014-01-26 17:28 - 2013-03-03 13:37 - 01061888 _____ () C:\Windows\SysWOW64\ExLvwU.ocx 2014-01-26 17:28 - 1999-05-06 23:00 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.OCX 2014-01-25 13:10 - 2014-02-05 12:55 - 00000000 ____D () C:\Users\Gracz\AppData\Local\gtk-2.0 2014-01-25 13:00 - 2014-01-25 13:00 - 00000740 _____ () C:\Users\Public\Desktop\GIMP 2.lnk 2014-01-25 12:50 - 2014-01-25 12:50 - 90396104 _____ (The GIMP Team ) C:\Users\Gracz\Downloads\gimp-2.8.10-setup(dobreprogramy.pl).exe 2014-01-24 17:24 - 2014-01-24 17:24 - 00000000 ____D () C:\Users\Public\Documents\Corel 2014-01-24 17:17 - 2014-01-24 17:17 - 00000000 ____D () C:\Users\Gracz\Documents\Moje palety 2014-01-24 17:03 - 2014-01-24 17:10 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Corel 2014-01-24 17:03 - 2014-01-24 17:03 - 00000000 ____D () C:\ProgramData\Protexis 2014-01-24 17:01 - 2014-01-27 23:34 - 00000000 ____D () C:\Users\Gracz\Documents\Corel 2014-01-24 17:01 - 2014-01-24 17:01 - 00000000 ____D () C:\Users\Gracz\Documents\Visual Studio 2008 2014-01-24 17:00 - 2014-01-24 17:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 9.0 2014-01-24 17:00 - 2014-01-24 17:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft SDKs 2014-01-24 16:59 - 2014-01-24 17:30 - 00000000 ____D () C:\ProgramData\Corel 2014-01-24 16:53 - 2014-01-24 17:28 - 00000000 ____D () C:\ProgramData\CorelDRAW Graphics Suite X6 2014-01-21 18:23 - 2014-01-21 18:23 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\PDAppFlex 2014-01-21 18:22 - 2014-01-21 18:23 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-01-21 18:01 - 2014-01-24 17:57 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-01-19 18:22 - 2014-02-14 16:15 - 00000171 _____ () C:\Windows\icecast2.ini 2014-01-19 17:57 - 2014-01-19 17:57 - 00000703 _____ () C:\Users\Gracz\Desktop\Icecast2 Win32.lnk ==================== One Month Modified Files and Folders ======= 2014-02-18 18:00 - 2014-02-18 18:00 - 00017497 _____ () C:\Users\Gracz\Desktop\FRST.txt 2014-02-18 18:00 - 2014-02-18 17:59 - 00000000 ____D () C:\FRST 2014-02-18 17:57 - 2014-02-18 17:57 - 00602112 _____ (OldTimer Tools) C:\Users\Gracz\Desktop\OTL.scr 2014-02-18 17:55 - 2014-02-18 17:55 - 02152448 _____ (Farbar) C:\Users\Gracz\Desktop\FRST64.exe 2014-02-18 17:47 - 2013-08-29 19:26 - 00001046 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-18 17:29 - 2013-04-12 16:28 - 00000000 ____D () C:\ProgramData\Browise2save 2014-02-18 17:28 - 2014-02-18 17:28 - 00000000 ____D () C:\Users\Gracz\AppData\Local\ESET 2014-02-18 17:16 - 2012-04-20 21:37 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Skype 2014-02-18 17:15 - 2013-06-29 18:22 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-18 17:07 - 2013-04-05 21:44 - 00000000 ____D () C:\Users\Gracz\AppData\Local\LogMeIn Hamachi 2014-02-18 15:31 - 2009-07-14 05:45 - 00031280 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-18 15:31 - 2009-07-14 05:45 - 00031280 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-18 15:28 - 2012-12-26 02:38 - 00000000 ____D () C:\Users\Gracz\Documents\Pliki programu Outlook 2014-02-18 15:28 - 2011-04-12 14:21 - 10002052 _____ () C:\Windows\system32\perfh015.dat 2014-02-18 15:28 - 2011-04-12 14:21 - 03322452 _____ () C:\Windows\system32\perfc015.dat 2014-02-18 15:28 - 2009-07-14 06:13 - 00006688 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-18 15:27 - 2012-04-18 16:12 - 01686609 _____ () C:\Windows\WindowsUpdate.log 2014-02-18 15:24 - 2013-12-26 16:58 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\newnext.me 2014-02-18 15:24 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing 2014-02-18 15:23 - 2013-08-29 19:26 - 00001042 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-18 15:23 - 2013-08-29 18:13 - 00039481 _____ () C:\Windows\setupact.log 2014-02-18 15:23 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-17 18:01 - 2014-02-17 17:15 - 00001277 _____ () C:\Users\Gracz\Desktop\Nowy dokument tekstowy.txt 2014-02-17 17:43 - 2012-10-19 22:38 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Gadu-Gadu 10 2014-02-16 19:12 - 2014-02-01 13:45 - 00001630 _____ () C:\Windows\Sandboxie.ini 2014-02-16 19:06 - 2013-03-29 01:06 - 00000000 ____D () C:\Users\Gracz\AppData\Local\CrashDumps 2014-02-16 15:12 - 2014-02-16 15:12 - 00000781 _____ () C:\Users\Gracz\Desktop\Counter-Strike 1.6.lnk 2014-02-16 15:12 - 2014-02-16 15:12 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6 2014-02-15 13:17 - 2009-07-14 03:34 - 00001146 _____ () C:\Windows\win.ini 2014-02-14 21:54 - 2014-02-14 21:54 - 00071106 _____ () C:\Users\Gracz\Documents\ODSZKODOWANIE.exe 2014-02-14 21:41 - 2014-02-14 21:41 - 00068752 _____ () C:\Users\Gracz\Documents\PREDKOSCiDROGA.exe 2014-02-14 16:15 - 2014-01-19 18:22 - 00000171 _____ () C:\Windows\icecast2.ini 2014-02-14 13:22 - 2012-04-20 17:12 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\TS3Client 2014-02-14 11:38 - 2013-05-12 17:04 - 00230424 _____ () C:\img2-001.raw 2014-02-07 13:05 - 2012-04-25 14:52 - 00280856 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-02-07 13:05 - 2012-04-25 14:52 - 00280856 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-02-07 12:47 - 2014-02-07 12:47 - 00272374 _____ () C:\Users\Gracz\AppData\Local\recently-used.xbel 2014-02-07 12:47 - 2013-05-02 14:28 - 00000000 ____D () C:\Users\Gracz\.gimp-2.8 2014-02-06 23:15 - 2013-06-29 18:22 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-06 23:15 - 2013-03-19 13:45 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-06 23:15 - 2012-04-18 16:51 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-06 13:28 - 2014-02-06 13:28 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Natural Selection 2 2014-02-06 11:33 - 2014-02-06 11:33 - 00000000 ____D () C:\Users\Gracz\AppData\Local\My Games 2014-02-06 11:32 - 2013-09-11 09:11 - 00108206 _____ () C:\Windows\DirectX.log 2014-02-06 11:32 - 2012-04-18 17:21 - 00000000 ____D () C:\Users\Gracz\Documents\My Games 2014-02-06 00:42 - 2013-08-29 19:26 - 00004042 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-06 00:42 - 2013-08-29 19:26 - 00003790 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-05 20:54 - 2014-02-04 17:01 - 00000000 ____D () C:\Program Files (x86)\BRS 2014-02-05 20:54 - 2012-04-18 17:21 - 00000000 ____D () C:\ProgramData\Codemasters 2014-02-05 20:53 - 2012-04-18 16:54 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2014-02-05 20:53 - 2012-04-18 16:54 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2014-02-05 12:55 - 2014-01-25 13:10 - 00000000 ____D () C:\Users\Gracz\AppData\Local\gtk-2.0 2014-02-04 17:22 - 2012-05-27 14:20 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Audacity 2014-02-04 17:02 - 2014-02-04 17:02 - 00000000 __SHD () C:\ProgramData\DSS 2014-02-04 09:45 - 2013-08-29 19:27 - 00002198 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-02-03 19:19 - 2014-01-10 15:39 - 00000000 ____D () C:\Users\Gracz\.VirtualBox 2014-02-01 13:46 - 2014-02-01 13:46 - 00000000 ___RD () C:\Sandbox 2014-02-01 11:04 - 2013-08-29 18:13 - 00033232 _____ () C:\Windows\PFRO.log 2014-01-31 18:51 - 2014-01-31 18:51 - 00000724 _____ () C:\Users\Public\Desktop\FL Studio 11.lnk 2014-01-31 18:51 - 2014-01-31 18:51 - 00000000 ____D () C:\Users\Gracz\Documents\Image-Line 2014-01-31 18:51 - 2014-01-31 18:51 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line 2014-01-31 18:51 - 2014-01-31 18:51 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Image-Line 2014-01-31 18:51 - 2014-01-31 18:51 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\FlowStone 2014-01-31 18:51 - 2014-01-31 18:51 - 00000000 ____D () C:\Program Files\Image-Line 2014-01-31 18:51 - 2014-01-31 18:51 - 00000000 ____D () C:\Program Files (x86)\DSPRobotics 2014-01-31 18:51 - 2014-01-18 00:13 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2 2014-01-31 18:41 - 2014-01-31 18:41 - 00000000 ____D () C:\Program Files (x86)\Image-Line 2014-01-28 18:46 - 2014-01-28 18:46 - 00001335 _____ () C:\Users\Gracz\Desktop\CorelDRW — skrót.lnk 2014-01-28 00:07 - 2014-01-28 00:07 - 00000000 ____D () C:\Users\Gracz\AppData\Local\ORPALIS 2014-01-28 00:05 - 2012-09-12 13:27 - 00000000 ____D () C:\Users\Gracz\AppData\Local\Downloaded Installations 2014-01-27 23:34 - 2014-01-24 17:01 - 00000000 ____D () C:\Users\Gracz\Documents\Corel 2014-01-26 17:28 - 2014-01-26 17:28 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\PDF Writer 2014-01-26 10:52 - 2009-07-14 05:45 - 05255656 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-25 15:26 - 2012-04-18 16:32 - 00167488 _____ () C:\Users\Gracz\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-25 13:00 - 2014-01-25 13:00 - 00000740 _____ () C:\Users\Public\Desktop\GIMP 2.lnk 2014-01-25 12:50 - 2014-01-25 12:50 - 90396104 _____ (The GIMP Team ) C:\Users\Gracz\Downloads\gimp-2.8.10-setup(dobreprogramy.pl).exe 2014-01-24 18:11 - 2012-04-18 17:18 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Adobe 2014-01-24 18:11 - 2012-04-18 16:48 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-01-24 17:59 - 2012-04-18 16:48 - 00000000 ____D () C:\ProgramData\Adobe 2014-01-24 17:57 - 2014-01-21 18:01 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-01-24 17:30 - 2014-01-24 16:59 - 00000000 ____D () C:\ProgramData\Corel 2014-01-24 17:28 - 2014-01-24 16:53 - 00000000 ____D () C:\ProgramData\CorelDRAW Graphics Suite X6 2014-01-24 17:27 - 2012-10-29 19:35 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-01-24 17:24 - 2014-01-24 17:24 - 00000000 ____D () C:\Users\Public\Documents\Corel 2014-01-24 17:18 - 2013-12-14 20:49 - 00000020 _____ () C:\Windows\capsys184523.log 2014-01-24 17:17 - 2014-01-24 17:17 - 00000000 ____D () C:\Users\Gracz\Documents\Moje palety 2014-01-24 17:10 - 2014-01-24 17:03 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\Corel 2014-01-24 17:03 - 2014-01-24 17:03 - 00000000 ____D () C:\ProgramData\Protexis 2014-01-24 17:01 - 2014-01-24 17:01 - 00000000 ____D () C:\Users\Gracz\Documents\Visual Studio 2008 2014-01-24 17:00 - 2014-01-24 17:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 9.0 2014-01-24 17:00 - 2014-01-24 17:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft SDKs 2014-01-24 15:08 - 2012-04-18 17:18 - 00000000 ____D () C:\Users\Gracz\AppData\Local\Adobe 2014-01-21 18:23 - 2014-01-21 18:23 - 00000000 ____D () C:\Users\Gracz\AppData\Roaming\PDAppFlex 2014-01-21 18:23 - 2014-01-21 18:22 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-01-19 19:24 - 2013-07-10 09:12 - 00000000 ____D () C:\Users\Gracz\Documents\Movie Studio Platinum 12.0 Projekty 2014-01-19 19:00 - 2014-01-13 16:34 - 00000000 ____D () C:\Users\Gracz\Documents\Traktor3 2014-01-19 17:57 - 2014-01-19 17:57 - 00000703 _____ () C:\Users\Gracz\Desktop\Icecast2 Win32.lnk 2014-01-19 08:33 - 2010-11-21 04:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe Files to move or delete: ==================== C:\ProgramData\pmt_0piot.pad Some content of TEMP: ==================== C:\Users\Gracz\AppData\Local\Temp\Creative Cloud Helper.exe C:\Users\Gracz\AppData\Local\Temp\drm_dyndata_7380015.dll C:\Users\Gracz\AppData\Local\Temp\drm_dyndata_7400006.dll C:\Users\Gracz\AppData\Local\Temp\dsp_ipp.dll C:\Users\Gracz\AppData\Local\Temp\gg10.upgr.exe C:\Users\Gracz\AppData\Local\Temp\InstHelper.exe C:\Users\Gracz\AppData\Local\Temp\ltdesPGBMvkJzvBWRwWq.DLL C:\Users\Gracz\AppData\Local\Temp\qjPIEZTFYvoiatniaKOl.DLL C:\Users\Gracz\AppData\Local\Temp\rYOkdqrwScWaZHdZNiTp.DLL C:\Users\Gracz\AppData\Local\Temp\SkypeSetup.exe C:\Users\Gracz\AppData\Local\Temp\sonarinst.exe C:\Users\Gracz\AppData\Local\Temp\SRLDetectionLibrary4167724617516266120.dll C:\Users\Gracz\AppData\Local\Temp\ubiD99D.tmp.exe C:\Users\Gracz\AppData\Local\Temp\XzJKLIcpfVmBCDPdxBwz.DLL ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-09 20:06 ==================== End Of Log ============================