Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-04-2014 01 Ran by Andrzej (administrator) on KOMPUTER on 26-04-2014 09:19:44 Running from C:\Users\Andrzej\Downloads Windows 7 Ultimate Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe () C:\Windows\SysWOW64\srvany.exe () C:\Windows\KMService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler64.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\system32\prevhost.exe (Microsoft Corporation) C:\Windows\system32\wbem\WMIADAP.EXE ==================== Registry (Whitelisted) ================== Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKU\S-1-5-21-832274295-3953399043-1981563008-1000\...\Run: [LG LinkAir] => [X] HKU\S-1-5-21-832274295-3953399043-1981563008-1000\...\MountPoints2: E - E:\AutoRun.exe HKU\S-1-5-21-832274295-3953399043-1981563008-1000\...\MountPoints2: {2e66bfb8-bd10-11e1-b66c-001167c36e22} - E:\AutoRun.exe HKU\S-1-5-21-832274295-3953399043-1981563008-1000\...\MountPoints2: {524b1f1b-0fa0-11e2-a5bf-001e101fabdd} - E:\AutoRun.exe HKU\S-1-5-21-832274295-3953399043-1981563008-1000\...\MountPoints2: {9ed397c0-f1d5-11e2-9217-001167c36e22} - F:\LGAutoRun.exe HKU\S-1-5-21-832274295-3953399043-1981563008-1000\...\MountPoints2: {e44305ab-bd32-11e1-af0c-001e101f2500} - F:\AutoRun.exe AppInit_DLLs-x32: c:\windows\syswow64\guard32.dll => c:\windows\syswow64\guard32.dll [363504 2014-03-25] (COMODO) Startup: C:\Users\konto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk ShortcutTarget: Facebook Messenger.lnk -> C:\Users\konto\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (Facebook) ==================== Internet (Whitelisted) ==================== StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Logitech Flow Scroll - {E11DB59D-5008-42ff-9069-535843BC0BE1} - C:\Program Files\Logitech\FlowScroll\LogiSmooth.dll (Logitech, Inc.) BHO-x32: HistoryTriggerBHO Class - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics) BHO-x32: No Name - {6F91A936-734D-4EE7-9320-50718870285D} - No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Logitech Flow Scroll - {E11DB59D-5008-42ff-9069-535843BC0BE1} - C:\Program Files\Logitech\FlowScroll\32-bit\LogiSmooth.dll (Logitech, Inc.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/ocx/110926/CTPID.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{1C92D3E9-427B-403C-BAD1-DB793299532A}: [NameServer]156.154.70.22,156.154.71.22 FireFox: ======== FF ProfilePath: C:\Users\Andrzej\AppData\Roaming\Mozilla\Firefox\Profiles\vw7kez8s.default-1398495676674 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_35 - C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-04-11] FF HKLM-x32\...\Firefox\Extensions: [{5D3F3872-91E9-4d59-AD9F-AA174A3145DD}] - C:\Program Files\Logitech\FlowScroll\LogiSmoothFirefoxExt FF Extension: Logitech Flow Scroll - C:\Program Files\Logitech\FlowScroll\LogiSmoothFirefoxExt [2012-05-06] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR StartupUrls: "https://www.google.pl/" CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll () CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.8) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Battlelog Game Launcher) - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB) CHR Plugin: (Battlelog Game Launcher) - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 6 U35) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () CHR Plugin: (Java Deployment Toolkit 6.0.350.10) - C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Extension: (Dysk Google) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-04-28] CHR Extension: (YouTube) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-04-28] CHR Extension: (Szukaj w Google) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-04-28] CHR Extension: (NPSignPlugin EPUAP) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkmkpnjoioaielnmocemighdcejngela [2014-03-12] CHR Extension: (AdBlock) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-10-26] CHR Extension: (Google Wallet) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (Gmail) - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-04-28] CHR HKLM-x32\...\Chrome\Extension: [fkmkpnjoioaielnmocemighdcejngela] - C:\Users\Andrzej\AppData\Local\Google\Chrome\User Data\Default\Extensions\EpuapSign.crx [2012-11-08] CHR HKLM-x32\...\Chrome\Extension: [geooogfhpjdpeiphckpbgkhpbeobcaoi] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx [2012-05-06] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11] ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S2 AODService; C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe [137584 2014-01-08] () S4 BlueSoleil Hid Service; C:\Program Files (x86)\IVT Corporation\BlueSoleil\BTNtService.exe [166520 2007-12-27] () R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation) R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6817544 2014-04-16] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2264280 2014-03-25] (COMODO) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () S4 Internet w Cyfrowym Polsacie. RunOuc; C:\Program Files (x86)\Internet w Cyfrowym Polsacie\UpdateDog\ouc.exe [246112 2014-03-23] () R2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2012-12-06] () S3 MSSQL$SONY_MEDIAMGR2; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29178224 2007-02-10] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16941856 2014-02-05] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-02-15] () S4 Start BT in service; C:\Program Files (x86)\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [51816 2007-12-27] () S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH) ==================== Drivers (Whitelisted) ==================== S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2012-07-03] (Google Inc) S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2012-07-03] (LG Electronics Inc.) S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2012-07-03] (LG Electronics Inc.) R2 AODDriver4.3.0; C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [59624 2014-01-08] (Advanced Micro Devices) R3 BlueletAudio; C:\Windows\System32\DRIVERS\blueletaudio.sys [37896 2007-06-24] (IVT Corporation.) R3 BlueletAudio; C:\Windows\SysWOW64\DRIVERS\blueletaudio.sys [37896 2007-06-24] (IVT Corporation.) R3 BlueletSCOAudio; C:\Windows\System32\DRIVERS\BlueletSCOAudio.sys [37384 2007-06-24] (IVT Corporation.) R3 BlueletSCOAudio; C:\Windows\SysWOW64\DRIVERS\BlueletSCOAudio.sys [37384 2007-06-24] (IVT Corporation.) R3 BT; C:\Windows\System32\DRIVERS\btnetdrv.sys [25360 2007-03-05] (IVT Corporation.) R3 BT; C:\Windows\SysWOW64\DRIVERS\btnetdrv.sys [25360 2007-03-05] (IVT Corporation.) S3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [47368 2007-06-24] (IVT Corporation.) S3 Btcsrusb; C:\Windows\SysWOW64\Drivers\btcusb.sys [47368 2007-06-24] (IVT Corporation.) R0 BTHidEnum; C:\Windows\System32\Drivers\vbtenum.sys [24976 2007-03-05] (IVT Corporation.) R0 BTHidEnum; C:\Windows\SysWOW64\Drivers\vbtenum.sys [24976 2007-03-05] (IVT Corporation.) R0 BTHidMgr; C:\Windows\System32\Drivers\BTHidMgr.sys [49680 2007-03-05] (IVT Corporation.) R0 BTHidMgr; C:\Windows\SysWOW64\Drivers\BTHidMgr.sys [49680 2007-03-05] (IVT Corporation.) R1 cdrblock; C:\Windows\System32\DRIVERS\cdrblock.sys [34360 2008-05-30] (Canopus Co,. Ltd.) S1 CFRMD; C:\Windows\SysWOW64\DRIVERS\CFRMD.sys [37976 2012-09-03] (Windows (R) Win 7 DDK provider) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2014-04-16] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [738472 2014-04-16] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [48360 2014-04-16] (COMODO) S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-06-09] (Samsung Electronics Co., Ltd.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-06] (DT Soft Ltd) R3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [81984 2010-10-28] (Fresco Logic) R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [105552 2014-04-16] (COMODO) R3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [165504 2012-07-22] (ITE ) R3 LgBttPort; C:\Windows\System32\DRIVERS\lgbtpt64.sys [16384 2009-09-29] (LG Electronics Inc.) R3 lgbusenum; C:\Windows\System32\DRIVERS\lgbtbs64.sys [14848 2009-09-29] (LG Electronics Inc.) R3 LGVMODEM; C:\Windows\System32\DRIVERS\lgvmdm64.sys [17408 2009-09-29] (LG Electronics Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) S3 PPJoyBus; C:\Windows\System32\DRIVERS\PPJoyBus64.sys [20024 2010-02-20] (Deon van der Westhuysen) S3 PPortJoystick; C:\Windows\System32\DRIVERS\PPortJoy64.sys [39992 2010-02-20] (Deon van der Westhuysen) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 VComm; C:\Windows\System32\DRIVERS\VComm.sys [47120 2007-03-05] (IVT Corporation.) R3 VComm; C:\Windows\SysWOW64\DRIVERS\VComm.sys [47120 2007-03-05] (IVT Corporation.) R3 VcommMgr; C:\Windows\System32\Drivers\VcommMgr.sys [63248 2007-03-05] (IVT Corporation.) R3 VcommMgr; C:\Windows\SysWOW64\Drivers\VcommMgr.sys [63248 2007-03-05] (IVT Corporation.) S3 VHidMinidrv; C:\Windows\System32\drivers\VHIDMini.sys [23184 2007-03-05] (IVT Corporation.) S3 VHidMinidrv; C:\Windows\SysWOW64\drivers\VHIDMini.sys [23184 2007-03-05] (IVT Corporation.) S3 vjoy; C:\Windows\System32\DRIVERS\vjoy.sys [36824 2012-10-31] (Shaul Eizikovich) S3 X86BDA; C:\Windows\System32\DRIVERS\OEMDrv.sys [268416 2011-06-08] ( ) S3 andnetndis; system32\DRIVERS\lgandnetndis64.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 TDPIPE; system32\drivers\tdpipe.sys [X] S3 TDTCP; system32\drivers\tdtcp.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-26 09:19 - 2014-04-26 09:20 - 00021962 _____ () C:\Users\Andrzej\Downloads\FRST.txt 2014-04-26 09:18 - 2014-04-26 09:18 - 00000000 ____D () C:\Users\Andrzej\Downloads\FRST-OlderVersion 2014-04-26 09:12 - 2014-04-26 09:12 - 00448512 _____ (OldTimer Tools) C:\Users\Andrzej\Downloads\TFC.exe 2014-04-26 09:01 - 2014-04-26 09:01 - 00000000 ____D () C:\Users\Andrzej\Desktop\Stare dane programu Firefox 2014-04-26 08:42 - 2014-04-26 08:42 - 00002260 _____ () C:\Users\Andrzej\Desktop\FIX.REG 2014-04-26 08:41 - 2014-04-26 08:41 - 00000000 _____ () C:\Users\Andrzej\Desktop\Nowy dokument tekstowy (2).txt 2014-04-25 21:26 - 2014-04-25 21:26 - 00009422 _____ () C:\Users\Andrzej\1.log 2014-04-25 20:33 - 2014-04-26 09:19 - 00000000 ____D () C:\Users\Andrzej\Desktop\logi 2014-04-25 20:33 - 2014-04-26 09:19 - 00000000 ____D () C:\FRST 2014-04-25 20:03 - 2014-04-25 20:03 - 00602112 _____ (OldTimer Tools) C:\Users\Andrzej\Downloads\OTL.exe 2014-04-25 20:03 - 2014-04-25 20:03 - 00380416 _____ () C:\Users\Andrzej\Downloads\mrnp874q.exe 2014-04-25 20:02 - 2014-04-26 09:18 - 02061824 _____ (Farbar) C:\Users\Andrzej\Downloads\FRST64.exe 2014-04-25 19:01 - 2014-04-21 16:58 - 00000426 _____ () C:\AVScanner.ini 2014-04-25 16:08 - 2014-04-26 09:02 - 00000000 ____D () C:\Program Files\PCDApp 2014-04-25 16:06 - 2014-04-25 16:06 - 00000000 ____D () C:\Users\Andrzej\AppData\Local\41 2014-04-23 20:19 - 2014-04-23 20:19 - 00000235 _____ () C:\Windows\LkmdfCoInst.log 2014-04-20 15:08 - 2014-04-20 15:08 - 02005070 _____ () C:\Users\Andrzej\Downloads\e-DeklaracjeDesktop.air 2014-04-20 15:08 - 2014-04-20 15:08 - 00000883 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-Deklaracje.lnk 2014-04-20 15:08 - 2014-04-20 15:08 - 00000871 _____ () C:\Users\Public\Desktop\e-Deklaracje.lnk 2014-04-20 15:08 - 2014-04-20 15:08 - 00000000 ____D () C:\Users\Andrzej\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1 2014-04-20 15:08 - 2014-04-20 15:08 - 00000000 ____D () C:\Users\Andrzej\AppData\Roaming\e-Deklaracje 2014-04-20 15:08 - 2014-04-20 15:08 - 00000000 ____D () C:\Program Files (x86)\e-Deklaracje 2014-04-20 15:07 - 2014-04-20 15:07 - 18134016 _____ (Adobe Systems Inc.) C:\Users\Andrzej\Downloads\AdobeAIRInstaller.exe 2014-04-20 15:07 - 2014-04-20 15:07 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia 2014-04-20 15:07 - 2014-04-20 15:07 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia 2014-04-20 14:39 - 2014-04-20 15:19 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-04-20 14:39 - 2014-04-20 14:39 - 00001979 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk 2014-04-20 14:36 - 2014-04-20 14:36 - 00067394 _____ () C:\Users\Andrzej\Downloads\detail.htm 2014-04-20 14:35 - 2014-04-20 14:35 - 02682880 _____ () C:\Users\Andrzej\Downloads\AdbeRdrSecUpd11005.msp 2014-04-20 14:25 - 2014-04-20 14:25 - 01308632 _____ (Ministerstwo Finansów ) C:\Users\Andrzej\Downloads\e-Deklaracje-wtyczka (1).exe 2014-04-20 14:25 - 2014-04-20 14:25 - 00707504 _____ () C:\Users\Andrzej\AppData\Local\unins000.exe 2014-04-20 14:24 - 2014-04-20 14:26 - 00011761 _____ () C:\Users\Andrzej\AppData\Local\unins000.msg 2014-04-20 14:24 - 2014-04-20 14:26 - 00005978 _____ () C:\Users\Andrzej\AppData\Local\unins000.dat 2014-04-20 14:24 - 2014-04-20 14:24 - 01308632 _____ (Ministerstwo Finansów ) C:\Users\Andrzej\Downloads\e-Deklaracje-wtyczka.exe 2014-04-06 11:20 - 2014-04-06 11:20 - 00053248 _____ () C:\Users\Andrzej\Desktop\opengl32.dll 2014-04-05 21:16 - 2014-04-05 21:16 - 00000820 _____ () C:\Users\Andrzej\Desktop\Counter Strike 1.6.lnk 2014-04-05 21:16 - 2014-04-05 21:16 - 00000000 ____D () C:\Users\Andrzej\Desktop\Nowy folder (2) 2014-04-05 21:16 - 2014-04-05 21:16 - 00000000 ____D () C:\Users\Andrzej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter Strike 1.6 2014-04-05 21:14 - 2014-04-05 21:14 - 00000000 ____D () C:\Gry 2014-04-05 21:09 - 2014-04-05 21:14 - 270447855 _____ (CS 1.6 ) C:\Users\Andrzej\Downloads\Counter Strike 1.6.exe 2014-04-05 21:06 - 2014-04-05 21:06 - 00091083 _____ () C:\Users\Andrzej\Downloads\aim cs -_-Dadley-_-.rar 2014-04-03 09:12 - 2014-04-03 09:13 - 00000000 ____D () C:\Users\konto\Desktop\mama,., 2014-03-27 08:29 - 2014-03-27 08:29 - 00000000 __SHD () C:\found.001 ==================== One Month Modified Files and Folders ======= 2014-04-26 09:20 - 2014-04-26 09:19 - 00021962 _____ () C:\Users\Andrzej\Downloads\FRST.txt 2014-04-26 09:19 - 2014-04-25 20:33 - 00000000 ____D () C:\Users\Andrzej\Desktop\logi 2014-04-26 09:19 - 2014-04-25 20:33 - 00000000 ____D () C:\FRST 2014-04-26 09:18 - 2014-04-26 09:18 - 00000000 ____D () C:\Users\Andrzej\Downloads\FRST-OlderVersion 2014-04-26 09:18 - 2014-04-25 20:02 - 02061824 _____ (Farbar) C:\Users\Andrzej\Downloads\FRST64.exe 2014-04-26 09:18 - 2012-05-05 20:30 - 01725988 _____ () C:\Windows\WindowsUpdate.log 2014-04-26 09:15 - 2014-03-04 14:21 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-26 09:15 - 2014-02-16 23:22 - 00016044 _____ () C:\Windows\setupact.log 2014-04-26 09:15 - 2012-09-27 20:43 - 00001046 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-26 09:15 - 2012-07-21 16:21 - 00000096 _____ () C:\monitor.log 2014-04-26 09:15 - 2009-07-14 07:08 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-26 09:15 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-26 09:14 - 2013-06-09 22:52 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat 2014-04-26 09:14 - 2009-07-14 06:45 - 00020368 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-26 09:14 - 2009-07-14 06:45 - 00020368 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-26 09:12 - 2014-04-26 09:12 - 00448512 _____ (OldTimer Tools) C:\Users\Andrzej\Downloads\TFC.exe 2014-04-26 09:02 - 2014-04-25 16:08 - 00000000 ____D () C:\Program Files\PCDApp 2014-04-26 09:01 - 2014-04-26 09:01 - 00000000 ____D () C:\Users\Andrzej\Desktop\Stare dane programu Firefox 2014-04-26 08:59 - 2009-07-14 19:55 - 00786402 _____ () C:\Windows\system32\perfh015.dat 2014-04-26 08:59 - 2009-07-14 19:55 - 00173150 _____ () C:\Windows\system32\perfc015.dat 2014-04-26 08:59 - 2009-07-14 07:13 - 01800132 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-26 08:53 - 2012-05-06 17:26 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-26 08:50 - 2013-06-08 10:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-04-26 08:42 - 2014-04-26 08:42 - 00002260 _____ () C:\Users\Andrzej\Desktop\FIX.REG 2014-04-26 08:41 - 2014-04-26 08:41 - 00000000 _____ () C:\Users\Andrzej\Desktop\Nowy dokument tekstowy (2).txt 2014-04-26 08:40 - 2012-09-27 20:43 - 00001050 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-26 08:35 - 2012-07-14 15:27 - 00000000 ____D () C:\Users\Andrzej\AppData\Roaming\vlc 2014-04-26 06:42 - 2012-05-28 15:23 - 00001078 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-832274295-3953399043-1981563008-1004UA.job 2014-04-25 21:26 - 2014-04-25 21:26 - 00009422 _____ () C:\Users\Andrzej\1.log 2014-04-25 21:26 - 2012-05-05 21:28 - 00000000 ____D () C:\Users\Andrzej 2014-04-25 20:03 - 2014-04-25 20:03 - 00602112 _____ (OldTimer Tools) C:\Users\Andrzej\Downloads\OTL.exe 2014-04-25 20:03 - 2014-04-25 20:03 - 00380416 _____ () C:\Users\Andrzej\Downloads\mrnp874q.exe 2014-04-25 19:27 - 2014-02-17 16:48 - 00000000 ____D () C:\AdwCleaner 2014-04-25 19:09 - 2014-02-17 16:47 - 01365865 _____ () C:\Users\Andrzej\Downloads\adwcleaner.exe 2014-04-25 19:03 - 2014-03-19 18:36 - 00006844 _____ () C:\Windows\PFRO.log 2014-04-25 19:02 - 2012-05-05 23:27 - 00000000 ____D () C:\ProgramData\Origin 2014-04-25 19:01 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-25 18:36 - 2014-02-12 23:40 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-04-25 18:36 - 2012-05-06 14:56 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-04-25 18:32 - 2012-05-05 23:57 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-04-25 18:31 - 2012-05-05 23:26 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-04-25 16:06 - 2014-04-25 16:06 - 00000000 ____D () C:\Users\Andrzej\AppData\Local\41 2014-04-25 11:42 - 2012-05-07 14:08 - 00000000 ____D () C:\Users\konto\AppData\Roaming\GG 2014-04-25 09:42 - 2012-05-28 15:23 - 00001056 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-832274295-3953399043-1981563008-1004Core.job 2014-04-24 16:06 - 2014-02-13 20:47 - 00000000 _____ () C:\Windows\SysWOW64\Access.dat 2014-04-24 16:06 - 2013-06-19 20:15 - 00052424 _____ () C:\Windows\system32\Drivers\fvstore.dat 2014-04-24 16:05 - 2012-05-07 06:50 - 00000000 ____D () C:\Users\konto\AppData\Local\VirtualStore 2014-04-24 13:26 - 2013-06-09 22:52 - 00000000 ____D () C:\Windows\System32\Tasks\COMODO 2014-04-23 20:19 - 2014-04-23 20:19 - 00000235 _____ () C:\Windows\LkmdfCoInst.log 2014-04-23 20:19 - 2012-05-06 14:26 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2014-04-21 16:58 - 2014-04-25 19:01 - 00000426 _____ () C:\AVScanner.ini 2014-04-20 15:19 - 2014-04-20 14:39 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-04-20 15:09 - 2012-05-12 18:09 - 00000000 ____D () C:\ProgramData\Adobe 2014-04-20 15:08 - 2014-04-20 15:08 - 02005070 _____ () C:\Users\Andrzej\Downloads\e-DeklaracjeDesktop.air 2014-04-20 15:08 - 2014-04-20 15:08 - 00000883 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-Deklaracje.lnk 2014-04-20 15:08 - 2014-04-20 15:08 - 00000871 _____ () C:\Users\Public\Desktop\e-Deklaracje.lnk 2014-04-20 15:08 - 2014-04-20 15:08 - 00000000 ____D () C:\Users\Andrzej\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1 2014-04-20 15:08 - 2014-04-20 15:08 - 00000000 ____D () C:\Users\Andrzej\AppData\Roaming\e-Deklaracje 2014-04-20 15:08 - 2014-04-20 15:08 - 00000000 ____D () C:\Program Files (x86)\e-Deklaracje 2014-04-20 15:07 - 2014-04-20 15:07 - 18134016 _____ (Adobe Systems Inc.) C:\Users\Andrzej\Downloads\AdobeAIRInstaller.exe 2014-04-20 15:07 - 2014-04-20 15:07 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia 2014-04-20 15:07 - 2014-04-20 15:07 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia 2014-04-20 15:07 - 2012-05-12 18:12 - 00000000 ____D () C:\Users\Andrzej\AppData\Local\Adobe 2014-04-20 15:07 - 2012-05-12 18:12 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-04-20 15:07 - 2012-05-06 17:28 - 00000000 ____D () C:\Users\Andrzej\AppData\Roaming\Adobe 2014-04-20 14:39 - 2014-04-20 14:39 - 00001979 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk 2014-04-20 14:36 - 2014-04-20 14:36 - 00067394 _____ () C:\Users\Andrzej\Downloads\detail.htm 2014-04-20 14:35 - 2014-04-20 14:35 - 02682880 _____ () C:\Users\Andrzej\Downloads\AdbeRdrSecUpd11005.msp 2014-04-20 14:26 - 2014-04-20 14:24 - 00011761 _____ () C:\Users\Andrzej\AppData\Local\unins000.msg 2014-04-20 14:26 - 2014-04-20 14:24 - 00005978 _____ () C:\Users\Andrzej\AppData\Local\unins000.dat 2014-04-20 14:25 - 2014-04-20 14:25 - 01308632 _____ (Ministerstwo Finansów ) C:\Users\Andrzej\Downloads\e-Deklaracje-wtyczka (1).exe 2014-04-20 14:25 - 2014-04-20 14:25 - 00707504 _____ () C:\Users\Andrzej\AppData\Local\unins000.exe 2014-04-20 14:24 - 2014-04-20 14:24 - 01308632 _____ (Ministerstwo Finansów ) C:\Users\Andrzej\Downloads\e-Deklaracje-wtyczka.exe 2014-04-19 10:28 - 2012-05-06 19:56 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-04-16 23:12 - 2013-04-25 11:05 - 00105552 _____ (COMODO) C:\Windows\system32\Drivers\inspect.sys 2014-04-16 23:12 - 2013-04-15 18:38 - 00738472 _____ (COMODO) C:\Windows\system32\Drivers\cmdguard.sys 2014-04-16 23:12 - 2013-04-15 18:38 - 00048360 _____ (COMODO) C:\Windows\system32\Drivers\cmdhlp.sys 2014-04-16 23:12 - 2013-04-15 18:38 - 00023168 _____ (COMODO) C:\Windows\system32\Drivers\cmderd.sys 2014-04-15 06:50 - 2012-05-19 02:12 - 00000000 ____D () C:\Users\Andrzej\AppData\Roaming\uTorrent 2014-04-12 07:55 - 2013-02-08 14:52 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-04-08 13:10 - 2012-05-07 14:08 - 00000000 ____D () C:\Users\konto\AppData\Local\GG 2014-04-06 11:20 - 2014-04-06 11:20 - 00053248 _____ () C:\Users\Andrzej\Desktop\opengl32.dll 2014-04-05 21:16 - 2014-04-05 21:16 - 00000820 _____ () C:\Users\Andrzej\Desktop\Counter Strike 1.6.lnk 2014-04-05 21:16 - 2014-04-05 21:16 - 00000000 ____D () C:\Users\Andrzej\Desktop\Nowy folder (2) 2014-04-05 21:16 - 2014-04-05 21:16 - 00000000 ____D () C:\Users\Andrzej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter Strike 1.6 2014-04-05 21:14 - 2014-04-05 21:14 - 00000000 ____D () C:\Gry 2014-04-05 21:14 - 2014-04-05 21:09 - 270447855 _____ (CS 1.6 ) C:\Users\Andrzej\Downloads\Counter Strike 1.6.exe 2014-04-05 21:06 - 2014-04-05 21:06 - 00091083 _____ () C:\Users\Andrzej\Downloads\aim cs -_-Dadley-_-.rar 2014-04-03 09:13 - 2014-04-03 09:12 - 00000000 ____D () C:\Users\konto\Desktop\mama,., 2014-04-03 09:11 - 2012-05-28 15:51 - 00000000 ___RD () C:\Users\konto\Desktop\Amanda 2014-03-27 08:35 - 2012-09-27 20:43 - 00004046 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-27 08:35 - 2012-09-27 20:43 - 00003794 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-27 08:29 - 2014-03-27 08:29 - 00000000 __SHD () C:\found.001 ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-19 00:35 ==================== End Of Log ============================