Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-02-2014 01 Ran by Stopa (administrator) on STOPA-KOMPUTER on 25-02-2014 23:12:36 Running from C:\Users\Stopa\Desktop Microsoft Windows 7 Ultimate (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Safe Mode (with Networking) The only official download link for FRST: Download link for 32-Bit version: Download link for 64-Bit Version: Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: ==================== Processes (Whitelisted) ================= (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [1812264 2010-11-12] (ELAN Microelectronics Corp.) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-05-24] (Advanced Micro Devices, Inc.) HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [714120 2011-01-28] (Acer Incorporated) HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.) HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [3521424 2012-04-27] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [CloneCDTray] - C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-29] (SlySoft, Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-12-23] (DivX, LLC) HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-11-15] () HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\Run: [KiesHelper] - C:\Program Files\Samsung\Kies\KiesHelper.exe [955280 2012-04-27] (Samsung) HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\Run: [KiesPDLR] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21416 2012-05-23] () HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\Run: [GG] - C:\Users\Stopa\AppData\Local\GG\Application\gghub.exe [4047424 2013-12-11] (GG Network S.A.) HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\Run: [Java] - cmd /c cd %APPDATA%\AutoIt3 & AutoIt3.exe soundmng.txt HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\MountPoints2: {e3363d06-15e0-11e2-a340-dc0ea14e705f} - F:\samos.exe HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\MountPoints2: {e9cb8dd3-220f-11e3-bd23-005056c00008} - H:\AutoRun.exe HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\MountPoints2: {e9cb8ddd-220f-11e3-bd23-005056c00008} - H:\AutoRun.exe HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\MountPoints2: {f90f42ce-2f54-11e3-80e7-dc0ea14e705f} - H:\AutoRun.exe HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\MountPoints2: {f90f42d7-2f54-11e3-80e7-dc0ea14e705f} - H:\AutoRun.exe HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\MountPoints2: {f90f42ee-2f54-11e3-80e7-dc0ea14e705f} - H:\AutoRun.exe HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\MountPoints2: {fa986ee5-dd9a-11e2-a019-005056c00008} - H:\AutoRun.exe HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\MountPoints2: {fa986ef2-dd9a-11e2-a019-005056c00008} - H:\AutoRun.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Restore = SearchScopes: HKCU - DefaultScope {0388404D-6072-4CEB-B521-8F090FEAEE57} URL ={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=PL&install_date=20120210&user_guid=1EF21B380FAC4E03B27A7F934BC6B717&machine_id=55a7822bc13fc6cfa98475c1f9f52aa6&browser=IE&os=win&os_version=6.1-x86-SP0&iesrc={referrer:source} SearchScopes: HKCU - {0388404D-6072-4CEB-B521-8F090FEAEE57} URL ={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=PL&install_date=20120210&user_guid=1EF21B380FAC4E03B27A7F934BC6B717&machine_id=55a7822bc13fc6cfa98475c1f9f52aa6&browser=IE&os=win&os_version=6.1-x86-SP0&iesrc={referrer:source} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Blog This in Windows Live - {2adefb8e-b923-35e6-86e2-2b7841f5d2a2} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: {68282C51-9459-467B-95BF-3C0E89627E55} DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [94208] (Apple Computer, Inc.) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Profiles\h5vku87d.default FF user.js: detected! => C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Profiles\h5vku87d.default\user.js FF DefaultSearchEngine: Yahoo FF SearchEngineOrder.1: Search the web (Babylon) FF SelectedSearchEngine: Google FF Homepage: FF Keyword.URL: hxxp:// FF Plugin: - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin: VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin:,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin:,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin:,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin:,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin:,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin:,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: Update;version=3 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Update;version=9 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin:,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Profiles\h5vku87d.default\searchplugins\Foxtab Web Search.xml FF SearchPlugin: C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Profiles\h5vku87d.default\searchplugins\yahoo-zugo.xml FF Extension: DivX Web Player - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Profiles\h5vku87d.default\Extensions\ [2012-02-06] FF Extension: Noia 4 Theme Manager - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Profiles\h5vku87d.default\Extensions\Noia4Options@ArisT2.xpi [2012-02-06] FF Extension: FindRight - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Profiles\h5vku87d.default\Extensions\{42e50651-9669-456e-9081-d5a836274274}.xpi [2014-02-24] FF Extension: Easy YouTube Video Downloader - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Profiles\h5vku87d.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi [2012-02-06] FF Extension: Adblock Plus - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Profiles\h5vku87d.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-02-06] FF Extension: Noia 4 - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Profiles\h5vku87d.default\Extensions\{faf13420-5e24-11e0-80e3-0800200c9a66}.xpi [2013-06-02] FF HKLM\...\Firefox\Extensions: [] - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix FF Extension: Mozilla hotfix - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix [2013-02-06] FF HKCU\...\Firefox\Extensions: [] - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix FF Extension: Mozilla hotfix - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix [2013-02-06] Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\33.0.1750.117\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\33.0.1750.117\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Winamp Application Detector) - C:\Program Files\Mozilla Firefox\plugins\npwachk.dll No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll No File CHR Extension: (Google Wallet) - C:\Users\Stopa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-20] CHR Extension: (Late Night) - C:\Users\Stopa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgbdhkpacgdhfabeceekiafonfkipohm [2013-05-12] ========================== Services (Whitelisted) ================= S2 Crypkey License; C:\Windows\system32\crypserv.exe [122880 2008-05-08] (CrypKey (Canada) Ltd.) S2 CxAudMsg; C:\Windows\system32\CxAudMsg32.exe [190592 2010-12-17] (Conexant Systems Inc.) S2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [734592 2011-01-28] (Acer Incorporated) S2 KMService; C:\Windows\system32\srvany.exe [8192 2012-03-24] () S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [232288 2012-03-12] () ==================== Drivers (Whitelisted) ==================== S3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-16] (SlySoft, Inc.) S1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [24232 2009-02-17] (Elaborate Bytes AG) R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [116008 2010-11-12] (ELAN Microelectronics Corp.) S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [65896 2013-07-25] (FTDI Ltd.) S1 ISODrive; C:\Program Files\UltraISO\drivers\ISODrive.sys [82320 2010-01-29] (EZB Systems, Inc.) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S1 NetworkX; C:\Windows\system32\ckldrv.sys [21638 2008-08-22] () S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 Ser2pl; system32\DRIVERS\ser2pl.sys [X] S3 Ser2plx86; system32\DRIVERS\ser2pl.sys [X] S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnet; system32\DRIVERS\ZTEusbnet.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] U3 mbr; \??\C:\Users\Stopa\AppData\Local\Temp\mbr.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-25 23:12 - 2014-02-25 23:13 - 00014698 _____ () C:\Users\Stopa\Desktop\FRST.txt 2014-02-25 23:11 - 2014-02-25 23:12 - 00000000 ____D () C:\FRST 2014-02-25 23:11 - 2014-02-25 23:11 - 01144320 _____ (Farbar) C:\Users\Stopa\Desktop\FRST (2).exe 2014-02-25 23:11 - 2014-02-25 23:11 - 01144320 _____ (Farbar) C:\Users\Stopa\Desktop\FRST (1).exe 2014-02-25 23:09 - 2014-02-25 23:09 - 01144320 _____ (Farbar) C:\Users\Stopa\Desktop\FRST.exe 2014-02-25 22:59 - 2014-02-25 23:00 - 00000000 ____D () C:\Users\Stopa\Desktop\logi 2014-02-25 22:57 - 2014-02-25 22:58 - 00688992 ____R (Swearware) C:\Users\Stopa\Desktop\dds (1).com 2014-02-25 22:57 - 2014-02-25 22:57 - 00688992 _____ (Swearware) C:\Users\Stopa\Desktop\ 2014-02-25 22:26 - 2014-02-25 22:27 - 00602112 _____ (OldTimer Tools) C:\Users\Stopa\Desktop\OTL (1).exe 2014-02-25 20:34 - 2014-02-25 20:34 - 00000000 ____D () C:\Program Files\ESET 2014-02-25 18:57 - 2014-02-25 18:57 - 00001027 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-02-25 18:57 - 2014-02-25 18:57 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\Malwarebytes 2014-02-25 18:57 - 2014-02-25 18:57 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-25 18:57 - 2014-02-25 18:57 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-25 18:57 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-25 18:52 - 2014-02-25 22:28 - 00007548 _____ () C:\Windows\PFRO.log 2014-02-25 15:23 - 2014-02-25 15:24 - 32091648 _____ (GTAPOLSKA.PL & PLProjekt) C:\Users\Stopa\Desktop\GTA IV Spolszczenie 100% (napisy PL).exe 2014-02-25 10:57 - 2014-02-25 10:57 - 00000000 _____ () C:\Users\Stopa\Desktop\126356.txt 2014-02-24 21:17 - 2014-02-24 21:39 - 00000000 ____D () C:\Users\Stopa\Desktop\Nowy folder 2014-02-23 15:52 - 2014-02-23 15:52 - 00000000 _____ () C:\Users\Stopa\Desktop\Nowy dokument tekstowy (2).txt 2014-02-23 13:48 - 2014-02-23 13:48 - 00000992 _____ () C:\Users\Public\Desktop\DivX Player.lnk 2014-02-23 13:47 - 2014-02-23 13:49 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\DivX 2014-02-23 13:46 - 2014-02-23 13:48 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared 2014-02-23 13:45 - 2014-02-23 13:48 - 00000000 ____D () C:\Program Files\DivX 2014-02-23 13:45 - 2014-02-23 13:45 - 00000000 _____ () C:\END 2014-02-23 13:44 - 2014-02-23 13:48 - 00000000 ____D () C:\ProgramData\DivX 2014-02-23 13:43 - 2014-02-24 15:41 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\AutoIt3 2014-02-23 13:43 - 2014-02-23 13:43 - 42012493 _____ () C:\Users\Stopa\AppData\Roaming\launcher.exe 2014-02-21 19:24 - 2014-02-21 19:24 - 00005163 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-02-21 19:24 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-02-21 19:24 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-02-21 19:24 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-02-21 19:24 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-02-20 18:04 - 2014-02-20 18:04 - 00000044 _____ () C:\Users\Stopa\Desktop\Nowy dokument tekstowy.txt 2014-02-18 21:18 - 2014-02-24 21:15 - 00000000 ____D () C:\Users\Stopa\Desktop\fotki od michała 2014-02-14 21:52 - 2014-02-14 21:52 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\MPC-HC 2014-02-14 21:49 - 2014-02-14 21:49 - 27795416 _____ ( ) C:\Users\Stopa\Desktop\ 2014-02-14 21:36 - 2014-02-14 21:36 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\Applian FLV and Media Player 2014-02-14 21:30 - 2014-02-14 21:30 - 00000000 ____D () C:\Program Files\Applian Technologies 2014-02-14 21:29 - 2014-02-14 21:33 - 00000000 ____D () C:\Program Files\Smart PC Cleaner 2014-02-14 21:29 - 2014-02-14 21:29 - 00000000 ____D () C:\Users\Stopa\Qtrax 2014-02-14 21:28 - 2014-02-14 21:28 - 01958688 _____ (Applian Technologies Inc.) C:\Users\Stopa\Downloads\FLVPlayerSetupStubMDV.exe 2014-02-12 17:13 - 2014-02-12 17:17 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\vlc 2014-02-12 17:13 - 2014-02-12 17:13 - 00000430 _____ () C:\Users\Stopa\.swfinfo 2014-02-12 17:10 - 2014-02-12 17:10 - 00000000 ____D () C:\Program Files\VideoLAN 2014-02-01 12:22 - 2014-02-01 15:59 - 00000000 ____D () C:\Users\Stopa\AppData\Local\Apps\Windows 7 USB DVD Download Tool 2014-02-01 12:22 - 2014-02-01 12:22 - 00002508 _____ () C:\Users\Stopa\Desktop\Windows 7 USB DVD Download Tool.lnk 2014-02-01 12:22 - 2014-02-01 12:22 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool 2014-02-01 12:20 - 2014-02-01 12:20 - 02721168 _____ (Microsoft Corporation) C:\Users\Stopa\Downloads\Windows7-USB-DVD-tool.exe 2014-02-01 11:01 - 2014-02-01 11:01 - 00000925 _____ () C:\Users\Public\Desktop\UltraISO.lnk 2014-02-01 11:01 - 2014-02-01 11:01 - 00000000 ____D () C:\Users\Stopa\Documents\My ISO Files 2014-02-01 11:01 - 2014-02-01 11:01 - 00000000 ____D () C:\Program Files\UltraISO 2014-02-01 11:01 - 2014-02-01 11:01 - 00000000 ____D () C:\Program Files\Common Files\EZB Systems 2014-01-31 21:12 - 2014-01-31 21:29 - 00001676 _____ () C:\Users\Stopa\opis auta i fotki forum.txt ==================== One Month Modified Files and Folders ======= 2014-02-25 23:13 - 2014-02-25 23:12 - 00014698 _____ () C:\Users\Stopa\Desktop\FRST.txt 2014-02-25 23:12 - 2014-02-25 23:11 - 00000000 ____D () C:\FRST 2014-02-25 23:11 - 2014-02-25 23:11 - 01144320 _____ (Farbar) C:\Users\Stopa\Desktop\FRST (2).exe 2014-02-25 23:11 - 2014-02-25 23:11 - 01144320 _____ (Farbar) C:\Users\Stopa\Desktop\FRST (1).exe 2014-02-25 23:09 - 2014-02-25 23:09 - 01144320 _____ (Farbar) C:\Users\Stopa\Desktop\FRST.exe 2014-02-25 23:00 - 2014-02-25 22:59 - 00000000 ____D () C:\Users\Stopa\Desktop\logi 2014-02-25 22:58 - 2014-02-25 22:57 - 00688992 ____R (Swearware) C:\Users\Stopa\Desktop\dds (1).com 2014-02-25 22:57 - 2014-02-25 22:57 - 00688992 _____ (Swearware) C:\Users\Stopa\Desktop\ 2014-02-25 22:36 - 2012-02-06 20:26 - 00006524 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-25 22:36 - 2009-07-14 09:07 - 06317572 _____ () C:\Windows\system32\perfh015.dat 2014-02-25 22:36 - 2009-07-14 09:07 - 02102242 _____ () C:\Windows\system32\perfc015.dat 2014-02-25 22:31 - 2012-02-07 03:07 - 01547643 _____ () C:\Windows\WindowsUpdate.log 2014-02-25 22:31 - 2009-07-14 05:34 - 00010208 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-25 22:31 - 2009-07-14 05:34 - 00010208 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-25 22:28 - 2014-02-25 18:52 - 00007548 _____ () C:\Windows\PFRO.log 2014-02-25 22:28 - 2013-12-29 10:16 - 00008928 _____ () C:\Windows\error.log 2014-02-25 22:28 - 2013-12-29 10:15 - 00005604 _____ () C:\Windows\setupact.log 2014-02-25 22:28 - 2013-12-29 10:15 - 00002808 _____ () C:\Windows\errord.log 2014-02-25 22:28 - 2013-06-14 11:44 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\GG 2014-02-25 22:28 - 2012-04-28 23:01 - 00001030 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-25 22:28 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-25 22:27 - 2014-02-25 22:26 - 00602112 _____ (OldTimer Tools) C:\Users\Stopa\Desktop\OTL (1).exe 2014-02-25 21:24 - 2012-03-26 16:35 - 00000000 ____D () C:\Users\Stopa\Documents\Pliki programu Outlook 2014-02-25 20:34 - 2014-02-25 20:34 - 00000000 ____D () C:\Program Files\ESET 2014-02-25 20:32 - 2012-10-22 19:03 - 00000000 ____D () C:\Program Files\SkanerOnline 2014-02-25 20:24 - 2009-07-14 09:28 - 00000000 ____D () C:\Windows\ShellNew 2014-02-25 18:57 - 2014-02-25 18:57 - 00001027 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-02-25 18:57 - 2014-02-25 18:57 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\Malwarebytes 2014-02-25 18:57 - 2014-02-25 18:57 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-25 18:57 - 2014-02-25 18:57 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-25 18:19 - 2012-02-06 21:23 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\uTorrent 2014-02-25 17:45 - 2012-04-28 23:01 - 00001034 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-25 17:38 - 2012-05-02 10:25 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-25 15:24 - 2014-02-25 15:23 - 32091648 _____ (GTAPOLSKA.PL & PLProjekt) C:\Users\Stopa\Desktop\GTA IV Spolszczenie 100% (napisy PL).exe 2014-02-25 10:57 - 2014-02-25 10:57 - 00000000 _____ () C:\Users\Stopa\Desktop\126356.txt 2014-02-24 21:39 - 2014-02-24 21:17 - 00000000 ____D () C:\Users\Stopa\Desktop\Nowy folder 2014-02-24 21:15 - 2014-02-18 21:18 - 00000000 ____D () C:\Users\Stopa\Desktop\fotki od michała 2014-02-24 15:41 - 2014-02-23 13:43 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\AutoIt3 2014-02-23 15:52 - 2014-02-23 15:52 - 00000000 _____ () C:\Users\Stopa\Desktop\Nowy dokument tekstowy (2).txt 2014-02-23 13:49 - 2014-02-23 13:47 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\DivX 2014-02-23 13:48 - 2014-02-23 13:48 - 00000992 _____ () C:\Users\Public\Desktop\DivX Player.lnk 2014-02-23 13:48 - 2014-02-23 13:46 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared 2014-02-23 13:48 - 2014-02-23 13:45 - 00000000 ____D () C:\Program Files\DivX 2014-02-23 13:48 - 2014-02-23 13:44 - 00000000 ____D () C:\ProgramData\DivX 2014-02-23 13:45 - 2014-02-23 13:45 - 00000000 _____ () C:\END 2014-02-23 13:43 - 2014-02-23 13:43 - 42012493 _____ () C:\Users\Stopa\AppData\Roaming\launcher.exe 2014-02-22 13:01 - 2013-03-24 08:28 - 00002095 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-02-21 19:38 - 2012-05-02 10:25 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-21 19:38 - 2012-02-06 22:19 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-21 19:24 - 2014-02-21 19:24 - 00005163 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-02-21 19:24 - 2013-11-15 22:34 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-21 19:24 - 2013-06-27 14:42 - 00000000 ____D () C:\Program Files\Java 2014-02-20 18:04 - 2014-02-20 18:04 - 00000044 _____ () C:\Users\Stopa\Desktop\Nowy dokument tekstowy.txt 2014-02-14 21:52 - 2014-02-14 21:52 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\MPC-HC 2014-02-14 21:51 - 2012-02-10 08:43 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack 2014-02-14 21:50 - 2013-08-15 21:23 - 00000000 ____D () C:\Program Files\Total Video Converter 2014-02-14 21:49 - 2014-02-14 21:49 - 27795416 _____ ( ) C:\Users\Stopa\Desktop\ 2014-02-14 21:37 - 2012-02-06 21:35 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\BESTplayer 2014-02-14 21:36 - 2014-02-14 21:36 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\Applian FLV and Media Player 2014-02-14 21:33 - 2014-02-14 21:29 - 00000000 ____D () C:\Program Files\Smart PC Cleaner 2014-02-14 21:33 - 2013-10-12 15:39 - 00000000 ____D () C:\Program Files\Multiecuscan 2014-02-14 21:33 - 2013-01-09 19:18 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-02-14 21:30 - 2014-02-14 21:30 - 00000000 ____D () C:\Program Files\Applian Technologies 2014-02-14 21:29 - 2014-02-14 21:29 - 00000000 ____D () C:\Users\Stopa\Qtrax 2014-02-14 21:29 - 2012-02-06 20:19 - 00000000 ____D () C:\Users\Stopa 2014-02-14 21:28 - 2014-02-14 21:28 - 01958688 _____ (Applian Technologies Inc.) C:\Users\Stopa\Downloads\FLVPlayerSetupStubMDV.exe 2014-02-12 17:17 - 2014-02-12 17:13 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\vlc 2014-02-12 17:13 - 2014-02-12 17:13 - 00000430 _____ () C:\Users\Stopa\.swfinfo 2014-02-12 17:10 - 2014-02-12 17:10 - 00000000 ____D () C:\Program Files\VideoLAN 2014-02-07 14:22 - 2009-07-14 05:53 - 00032604 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-04 20:29 - 2013-04-06 16:37 - 00001565 _____ () C:\Users\Stopa\wskaźniki forum.txt 2014-02-01 17:25 - 2012-02-06 21:17 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\Adobe 2014-02-01 15:59 - 2014-02-01 12:22 - 00000000 ____D () C:\Users\Stopa\AppData\Local\Apps\Windows 7 USB DVD Download Tool 2014-02-01 12:22 - 2014-02-01 12:22 - 00002508 _____ () C:\Users\Stopa\Desktop\Windows 7 USB DVD Download Tool.lnk 2014-02-01 12:22 - 2014-02-01 12:22 - 00000000 ____D () C:\Users\Stopa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool 2014-02-01 12:20 - 2014-02-01 12:20 - 02721168 _____ (Microsoft Corporation) C:\Users\Stopa\Downloads\Windows7-USB-DVD-tool.exe 2014-02-01 11:01 - 2014-02-01 11:01 - 00000925 _____ () C:\Users\Public\Desktop\UltraISO.lnk 2014-02-01 11:01 - 2014-02-01 11:01 - 00000000 ____D () C:\Users\Stopa\Documents\My ISO Files 2014-02-01 11:01 - 2014-02-01 11:01 - 00000000 ____D () C:\Program Files\UltraISO 2014-02-01 11:01 - 2014-02-01 11:01 - 00000000 ____D () C:\Program Files\Common Files\EZB Systems 2014-01-31 21:29 - 2014-01-31 21:12 - 00001676 _____ () C:\Users\Stopa\opis auta i fotki forum.txt Some content of TEMP: ==================== C:\Users\Stopa\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-18 16:22 ==================== End Of Log ============================