Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-05-2014 01 Ran by USER (administrator) on USER-KOMPUTER on 08-05-2014 16:15:44 Running from C:\Users\USER\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 10 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.5.0.28\ccsvchst.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.5.0.28\ccsvchst.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe (RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe (RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\ToolbarUpdater.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\loggingserver.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe () C:\ComboFix\PEV.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe () C:\Program Files (x86)\Opera\21.0.1432.57\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe (Opera Software) C:\Program Files (x86)\Opera\21.0.1432.57\opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [900704 2013-03-15] (Conexant Systems, Inc.) HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [NCUpdateHelper] => C:\Program Files (x86)\NCWest\NCLauncher\NCUpdateHelper.exe [528360 2014-03-12] (NCSOFT Corporation) HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Secure Search\vprot.exe [2557976 2014-04-27] () Winlogon\Notify\igfxcui: igfxdev.dll [X] Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKLM\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-4182412675-3485890804-2187180611-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1775808 2014-05-07] (Valve Corporation) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [174296 2014-03-04] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [148016 2014-03-04] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={C7D2CCC3-9753-46CB-913C-A0C49B1F5FB5}&mid=c724f24da5c247d2a11cf5b4141566f4-6c9cad5da9784333906a8a77eb2c5a412f9e33c3&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-01-14 18:08:09&v=17.2.0.38&pid=avg&sg=&sap=dsp&q={searchTerms} BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.5.0.28\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.5.0.28\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\18.1.0.443\AVG Secure Search_toolbar.dll (AVG Secure Search) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\18.1.0.443\AVG Secure Search_toolbar.dll (AVG Secure Search) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.5.0.28\coIEPlg.dll (Symantec Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.0\ViProtocol.dll (AVG Secure Search) Tcpip\Parameters: [DhcpNameServer] 82.139.8.40 95.160.170.92 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.0\\npsitesafety.dll No File FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\IPSFF [2014-02-10] FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\coFFPlgn\ [] ==================== Services (Whitelisted) ================= S4 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [227456 2013-01-25] (Qualcomm Atheros Commnucations) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-11-21] (Intel Corporation) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-17] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation) S4 MaConfigAgent; C:\Program Files\ma-config.com\MaConfigAgent.exe [2818888 2014-02-24] (CybelSoft) R2 N360; C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.5.0.28\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation) S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4702568 2012-10-24] (INCA Internet Co., Ltd.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-29] () R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2099512 2013-08-30] (AVG) R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [107624 2014-05-08] (RaMMicHaeL) R2 vToolbarUpdater18.1.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\ToolbarUpdater.exe [1801240 2014-04-27] (AVG Secure Search) S4 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-01-25] (Atheros) ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2014-02-10] () R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-04-27] (AVG Technologies) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\BASHDefs\20140409.001\BHDrvx64.sys [1525976 2014-03-19] (Symantec Corporation) R3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2013-01-25] (Qualcomm Atheros) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1405000.01C\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2014-02-09] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2014-04-22] (Symantec Corporation) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-11-21] (Intel Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\IPSDefs\20140507.001\IDSvia64.sys [525016 2014-03-29] (Symantec Corporation) R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [129224 2013-07-18] (Qualcomm Atheros Co., Ltd.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2014-02-10] () S3 ma-config_amd64; C:\Program Files\ma-config.com\Drivers\ma-config_amd64.sys [17568 2014-02-24] (CybelSoft) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20140507.022\ENG64.SYS [126040 2014-04-22] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.4.0.40\Definitions\VirusDefs\20140507.022\EX64.SYS [2099288 2014-04-22] (Symantec Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2014-01-05] (Duplex Secure Ltd.) R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1405000.01C\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1405000.01C\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\1405000.01C\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1405000.01C\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2014-02-10] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1405000.01C\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1405000.01C\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2013-08-21] (TuneUp Software) R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [1045248 2013-03-01] (Vimicro Corporation) U3 a8cvnxoj; C:\Windows\System32\Drivers\a8cvnxoj.sys [0 ] (Microsoft Corporation) S2 sbapifs; system32\DRIVERS\sbapifs.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-08 16:16 - 2014-05-08 16:16 - 00602112 _____ (OldTimer Tools) C:\Users\USER\Desktop\OTL.scr 2014-05-08 16:16 - 2014-05-08 16:16 - 00602112 _____ (OldTimer Tools) C:\Users\USER\Desktop\OTL.exe 2014-05-08 16:16 - 2014-05-08 16:16 - 00602112 _____ (OldTimer Tools) C:\Users\USER\Desktop\OTL.com 2014-05-08 16:15 - 2014-05-08 16:16 - 00018806 _____ () C:\Users\USER\Desktop\FRST.txt 2014-05-08 16:14 - 2014-05-08 16:15 - 00000000 ____D () C:\FRST 2014-05-08 16:13 - 2014-05-08 16:13 - 02063872 _____ (Farbar) C:\Users\USER\Desktop\FRST64.exe 2014-05-08 15:50 - 2014-05-08 15:50 - 00035347 _____ () C:\ComboFix.txt 2014-05-08 14:55 - 2014-05-08 15:51 - 00000000 ____D () C:\ComboFix 2014-05-08 14:55 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-05-08 14:55 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-05-08 14:55 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-05-08 14:55 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-05-08 14:55 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-05-08 14:55 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-05-08 14:55 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-05-08 14:55 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-05-08 14:50 - 2014-05-08 15:51 - 00000000 ____D () C:\Qoobox 2014-05-08 14:49 - 2014-05-08 15:46 - 00000000 ____D () C:\Windows\erdnt 2014-05-08 14:48 - 2014-05-08 14:48 - 00001023 _____ () C:\Users\Public\Desktop\Unchecky.lnk 2014-05-08 14:48 - 2014-05-08 14:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky 2014-05-08 14:48 - 2014-05-08 14:48 - 00000000 ____D () C:\Program Files (x86)\Unchecky 2014-05-08 14:47 - 2014-05-08 14:47 - 00002971 _____ () C:\Users\USER\Desktop\HiJackThis.lnk 2014-05-08 14:47 - 2014-05-08 14:47 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis 2014-05-08 14:47 - 2014-05-08 14:47 - 00000000 ____D () C:\Program Files (x86)\Trend Micro 2014-05-08 14:46 - 2014-05-08 14:46 - 05200039 ____R (Swearware) C:\Users\USER\Desktop\ComboFix.exe 2014-05-08 14:46 - 2014-05-08 14:46 - 01402880 _____ () C:\Users\USER\Desktop\HiJackThis.msi 2014-05-08 14:46 - 2014-05-08 14:46 - 00694968 _____ (RaMMicHaeL) C:\Users\USER\Desktop\unchecky_setup.exe 2014-05-08 14:18 - 2014-05-08 14:19 - 00000000 ____D () C:\Users\USER\AppData\Local\MetaGeek,_LLC 2014-05-08 14:14 - 2014-05-08 14:14 - 00002489 _____ () C:\Users\Public\Desktop\inSSIDer Home.lnk 2014-05-08 14:14 - 2014-05-08 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MetaGeek 2014-05-08 14:14 - 2014-05-08 14:14 - 00000000 ____D () C:\Program Files (x86)\MetaGeek 2014-05-08 14:08 - 2014-05-08 14:10 - 04767744 _____ () C:\Users\USER\Desktop\inSSIDer-installer_www.INSTALKI.pl.msi 2014-05-05 11:56 - 2014-05-05 11:56 - 00000000 ____D () C:\Windows\System32\Tasks\Norton 360 2014-05-05 11:48 - 2014-05-05 11:48 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-04 20:35 - 2014-04-29 16:14 - 19275264 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-04 20:35 - 2014-04-29 14:47 - 14357504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-04 20:35 - 2014-04-29 14:36 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-04 20:35 - 2014-04-29 14:25 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-04 20:33 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-04 20:33 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-30 16:29 - 2014-04-30 16:29 - 00000000 ____D () C:\Users\USER\AppData\Local\Win7UI 2014-04-29 20:57 - 2014-04-29 20:57 - 00000000 ____D () C:\Users\USER\AppData\Local\Arktos Entertainment 2014-04-29 20:54 - 2014-05-08 11:11 - 00291128 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-04-29 20:53 - 2014-05-08 11:11 - 00291128 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-04-29 20:53 - 2014-05-08 10:44 - 00291128 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-04-29 20:53 - 2014-04-29 20:53 - 00000000 ____D () C:\Users\USER\AppData\Local\PunkBuster 2014-04-29 20:53 - 2014-04-29 20:53 - 00000000 ____D () C:\Users\USER\AppData\Local\Arktos 2014-04-29 20:52 - 2014-04-29 20:52 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2014-04-29 20:50 - 2014-04-29 20:50 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-04-29 16:31 - 2014-04-29 16:31 - 00000000 _____ () C:\Users\USER\Desktop\wyzwanie.txt 2014-04-29 14:23 - 2014-04-29 14:23 - 00000000 ____D () C:\Users\USER\Documents\Arktos 2014-04-29 14:23 - 2014-04-29 14:23 - 00000000 ____D () C:\Users\USER\AppData\Local\CrashRpt 2014-04-28 15:30 - 2014-04-28 15:30 - 00000180 _____ () C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2014-04-27 20:33 - 2014-04-27 20:33 - 00000219 _____ () C:\Users\USER\Desktop\Dota 2.url 2014-04-27 19:53 - 2014-05-08 16:13 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-04-27 19:53 - 2014-04-27 19:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2014-04-27 18:50 - 2014-04-27 18:50 - 00000000 ____D () C:\ProgramData\AVG Secure Search 2014-04-22 20:44 - 2014-03-21 21:43 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-04-22 20:44 - 2014-03-21 21:43 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-04-17 07:48 - 2014-04-17 07:48 - 00000451 _____ () C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat 2014-04-17 07:48 - 2014-04-17 07:48 - 00000244 _____ () C:\Windows\system32\{86F549EB-A66B-4D6C-958D-CDDD66410751}.bat 2014-04-16 19:24 - 2014-04-16 19:24 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-04-14 14:53 - 2013-12-10 01:27 - 00100312 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverx64.sys 2014-04-14 13:03 - 2014-04-14 13:26 - 00000000 ____D () C:\Users\USER\Documents\FIFA 13 2014-04-13 21:43 - 2014-04-13 22:28 - 00000000 ____D () C:\Program Files (x86)\VstPlugins 2014-04-10 16:13 - 2014-04-10 16:13 - 00000582 _____ () C:\Users\USER\Desktop\BaronReplays.lnk 2014-04-10 16:13 - 2014-04-10 16:13 - 00000000 ____D () C:\Users\USER\AppData\Local\Ahri.tw 2014-04-10 16:12 - 2014-04-10 16:13 - 00000000 ____D () C:\Users\USER\Desktop\BaronReplays 2014-04-10 09:00 - 2014-05-08 16:13 - 00367329 ____N () C:\Windows\WindowsUpdate.log 2014-04-09 11:48 - 2014-03-13 08:33 - 02238976 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-09 11:48 - 2014-03-13 08:33 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-09 11:48 - 2014-03-13 08:33 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-09 11:48 - 2014-03-13 08:32 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-09 11:48 - 2014-03-13 08:32 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-04-09 11:48 - 2014-03-13 08:32 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-09 11:48 - 2014-03-13 08:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-09 11:48 - 2014-03-13 08:32 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-09 11:48 - 2014-03-13 08:31 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-09 11:48 - 2014-03-13 08:31 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-09 11:48 - 2014-03-13 08:31 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-09 11:48 - 2014-03-13 08:31 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-04-09 11:48 - 2014-03-13 08:31 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-09 11:48 - 2014-03-13 08:31 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-09 11:48 - 2014-03-13 07:10 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-09 11:48 - 2014-03-13 07:10 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-09 11:48 - 2014-03-13 07:09 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-09 11:48 - 2014-03-13 07:09 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-09 11:48 - 2014-03-13 07:09 - 02049536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-09 11:48 - 2014-03-13 07:09 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-04-09 11:48 - 2014-03-13 07:09 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-09 11:48 - 2014-03-13 07:09 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-09 11:48 - 2014-03-13 07:09 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-09 11:48 - 2014-03-13 07:09 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-04-09 11:48 - 2014-03-13 07:09 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-09 11:48 - 2014-03-13 07:09 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-09 11:48 - 2014-03-13 07:09 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-09 11:48 - 2014-03-13 05:59 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-04-09 11:48 - 2014-03-13 05:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-04-09 11:47 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 11:47 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 11:47 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 11:47 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 11:47 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 11:45 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 11:45 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 11:45 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 11:45 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 11:45 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 11:45 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 11:45 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 11:45 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 11:45 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 11:45 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 11:45 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 11:45 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-08 10:23 - 2014-04-08 10:23 - 00000000 ____D () C:\Users\USER\AppData\Local\Electronic Arts 2014-04-08 09:51 - 2014-04-08 09:51 - 00003000 _____ () C:\Windows\System32\Tasks\{BD282B4A-9548-4516-B813-C5C1A54674A9} 2014-04-08 09:49 - 2014-04-08 09:49 - 00003000 _____ () C:\Windows\System32\Tasks\{A590B05B-5BEB-47C0-9648-2913B7E0CAB3} 2014-04-08 08:37 - 2003-05-23 13:28 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2014-04-08 08:37 - 2003-05-23 13:28 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2014-04-08 08:27 - 2003-05-23 13:28 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll ==================== One Month Modified Files and Folders ======= 2014-05-08 16:16 - 2014-05-08 16:16 - 00602112 _____ (OldTimer Tools) C:\Users\USER\Desktop\OTL.scr 2014-05-08 16:16 - 2014-05-08 16:16 - 00602112 _____ (OldTimer Tools) C:\Users\USER\Desktop\OTL.exe 2014-05-08 16:16 - 2014-05-08 16:16 - 00602112 _____ (OldTimer Tools) C:\Users\USER\Desktop\OTL.com 2014-05-08 16:16 - 2014-05-08 16:15 - 00018806 _____ () C:\Users\USER\Desktop\FRST.txt 2014-05-08 16:15 - 2014-05-08 16:14 - 00000000 ____D () C:\FRST 2014-05-08 16:15 - 2014-01-03 09:33 - 00000000 ____D () C:\Users\USER\Documents\Backup Reg 2014-05-08 16:13 - 2014-05-08 16:13 - 02063872 _____ (Farbar) C:\Users\USER\Desktop\FRST64.exe 2014-05-08 16:13 - 2014-04-27 19:53 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-05-08 16:13 - 2014-04-10 09:00 - 00367329 ____N () C:\Windows\WindowsUpdate.log 2014-05-08 16:03 - 2014-02-04 20:42 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-08 15:51 - 2014-05-08 14:55 - 00000000 ____D () C:\ComboFix 2014-05-08 15:51 - 2014-05-08 14:50 - 00000000 ____D () C:\Qoobox 2014-05-08 15:51 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-05-08 15:50 - 2014-05-08 15:50 - 00035347 _____ () C:\ComboFix.txt 2014-05-08 15:46 - 2014-05-08 14:49 - 00000000 ____D () C:\Windows\erdnt 2014-05-08 15:41 - 2011-04-12 15:21 - 00741710 _____ () C:\Windows\system32\perfh015.dat 2014-05-08 15:41 - 2011-04-12 15:21 - 00156750 _____ () C:\Windows\system32\perfc015.dat 2014-05-08 15:41 - 2009-07-14 07:13 - 01673940 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-08 15:37 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-05-08 15:36 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-08 15:35 - 2014-01-02 16:43 - 07863408 _____ () C:\Users\Public\CAFADEBUG.log 2014-05-08 14:48 - 2014-05-08 14:48 - 00001023 _____ () C:\Users\Public\Desktop\Unchecky.lnk 2014-05-08 14:48 - 2014-05-08 14:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky 2014-05-08 14:48 - 2014-05-08 14:48 - 00000000 ____D () C:\Program Files (x86)\Unchecky 2014-05-08 14:47 - 2014-05-08 14:47 - 00002971 _____ () C:\Users\USER\Desktop\HiJackThis.lnk 2014-05-08 14:47 - 2014-05-08 14:47 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis 2014-05-08 14:47 - 2014-05-08 14:47 - 00000000 ____D () C:\Program Files (x86)\Trend Micro 2014-05-08 14:46 - 2014-05-08 14:46 - 05200039 ____R (Swearware) C:\Users\USER\Desktop\ComboFix.exe 2014-05-08 14:46 - 2014-05-08 14:46 - 01402880 _____ () C:\Users\USER\Desktop\HiJackThis.msi 2014-05-08 14:46 - 2014-05-08 14:46 - 00694968 _____ (RaMMicHaeL) C:\Users\USER\Desktop\unchecky_setup.exe 2014-05-08 14:19 - 2014-05-08 14:18 - 00000000 ____D () C:\Users\USER\AppData\Local\MetaGeek,_LLC 2014-05-08 14:14 - 2014-05-08 14:14 - 00002489 _____ () C:\Users\Public\Desktop\inSSIDer Home.lnk 2014-05-08 14:14 - 2014-05-08 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MetaGeek 2014-05-08 14:14 - 2014-05-08 14:14 - 00000000 ____D () C:\Program Files (x86)\MetaGeek 2014-05-08 14:10 - 2014-05-08 14:08 - 04767744 _____ () C:\Users\USER\Desktop\inSSIDer-installer_www.INSTALKI.pl.msi 2014-05-08 11:11 - 2014-04-29 20:54 - 00291128 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-05-08 11:11 - 2014-04-29 20:53 - 00291128 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-05-08 11:04 - 2009-07-14 06:45 - 00016640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-08 11:04 - 2009-07-14 06:45 - 00016640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-08 11:02 - 2014-01-03 09:32 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-05-08 11:00 - 2014-01-03 13:38 - 00000000 ____D () C:\Windows\pss 2014-05-08 11:00 - 2014-01-02 15:16 - 00000000 ___RD () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-08 10:59 - 2014-01-20 09:23 - 00000000 ____D () C:\Users\USER\AppData\Roaming\AIMP3 2014-05-08 10:59 - 2014-01-07 17:58 - 00000000 ____D () C:\Users\USER\AppData\Roaming\uTorrent 2014-05-08 10:59 - 2014-01-04 20:19 - 00000000 ____D () C:\Users\USER\AppData\Roaming\TS3Client 2014-05-08 10:59 - 2014-01-04 01:48 - 00000000 ____D () C:\Users\USER\AppData\Local\CrashDumps 2014-05-08 10:44 - 2014-04-29 20:53 - 00291128 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-05-08 09:35 - 2014-02-11 12:18 - 00000000 ____D () C:\Users\USER\AppData\Local\PMB Files 2014-05-08 06:29 - 2014-02-11 12:18 - 00000000 ____D () C:\ProgramData\PMB Files 2014-05-07 07:24 - 2014-01-02 17:00 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-05-06 21:10 - 2014-01-07 11:00 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Skype 2014-05-05 11:56 - 2014-05-05 11:56 - 00000000 ____D () C:\Windows\System32\Tasks\Norton 360 2014-05-05 11:51 - 2014-02-17 22:35 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Atheros 2014-05-05 11:51 - 2014-01-02 16:19 - 00000000 ____D () C:\Users\USER\Documents\Bluetooth Folder 2014-05-05 11:50 - 2014-02-10 09:01 - 00003238 _____ () C:\Windows\System32\Tasks\Norton WSC Integration 2014-05-05 11:50 - 2014-02-10 08:59 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 Premier Edition 2014-05-05 11:50 - 2014-02-10 08:59 - 00000000 ____D () C:\Windows\system32\Drivers\N360x64 2014-05-05 11:48 - 2014-05-05 11:48 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-30 23:20 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-30 16:29 - 2014-04-30 16:29 - 00000000 ____D () C:\Users\USER\AppData\Local\Win7UI 2014-04-29 21:19 - 2009-07-14 04:34 - 78118912 _____ () C:\Windows\system32\config\SOFTWARE_tureg_old 2014-04-29 21:19 - 2009-07-14 04:34 - 18612224 _____ () C:\Windows\system32\config\SYSTEM_tureg_old 2014-04-29 21:19 - 2009-07-14 04:34 - 00024576 _____ () C:\Windows\system32\config\SECURITY_tureg_old 2014-04-29 20:57 - 2014-04-29 20:57 - 00000000 ____D () C:\Users\USER\AppData\Local\Arktos Entertainment 2014-04-29 20:53 - 2014-04-29 20:53 - 00000000 ____D () C:\Users\USER\AppData\Local\PunkBuster 2014-04-29 20:53 - 2014-04-29 20:53 - 00000000 ____D () C:\Users\USER\AppData\Local\Arktos 2014-04-29 20:52 - 2014-04-29 20:52 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2014-04-29 20:50 - 2014-04-29 20:50 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-04-29 18:38 - 2014-01-01 09:41 - 00000000 ____D () C:\Users\USER\AppData\Roaming\.minecraft 2014-04-29 16:38 - 2009-07-14 04:34 - 04980736 _____ () C:\Windows\system32\config\DEFAULT_tureg_old 2014-04-29 16:31 - 2014-04-29 16:31 - 00000000 _____ () C:\Users\USER\Desktop\wyzwanie.txt 2014-04-29 16:14 - 2014-05-04 20:35 - 19275264 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-29 14:47 - 2014-05-04 20:35 - 14357504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-29 14:36 - 2014-05-04 20:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-29 14:25 - 2014-05-04 20:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-29 14:23 - 2014-04-29 14:23 - 00000000 ____D () C:\Users\USER\Documents\Arktos 2014-04-29 14:23 - 2014-04-29 14:23 - 00000000 ____D () C:\Users\USER\AppData\Local\CrashRpt 2014-04-29 12:04 - 2009-07-14 04:34 - 23068672 _____ () C:\Windows\system32\config\COMPONENTS_tureg_old 2014-04-29 07:25 - 2009-07-14 04:34 - 00024576 _____ () C:\Windows\system32\config\SAM_tureg_old 2014-04-28 20:03 - 2014-02-04 20:42 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-28 20:03 - 2014-01-02 16:30 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-28 20:03 - 2014-01-02 16:30 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-28 15:30 - 2014-04-28 15:30 - 00000180 _____ () C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2014-04-27 20:57 - 2014-01-08 16:21 - 00000000 ____D () C:\Users\USER\Desktop\Nowy folder 2014-04-27 20:33 - 2014-04-27 20:33 - 00000219 _____ () C:\Users\USER\Desktop\Dota 2.url 2014-04-27 19:53 - 2014-04-27 19:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2014-04-27 18:50 - 2014-04-27 18:50 - 00000000 ____D () C:\ProgramData\AVG Secure Search 2014-04-27 18:50 - 2014-01-14 19:07 - 00000000 ____D () C:\Program Files (x86)\AVG Secure Search 2014-04-27 18:49 - 2014-01-14 19:08 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-04-22 20:47 - 2014-01-02 16:16 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-22 20:46 - 2014-01-08 15:50 - 00000000 ____D () C:\Users\USER\AppData\Local\NVIDIA Corporation 2014-04-22 20:46 - 2014-01-03 13:56 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-04-17 07:48 - 2014-04-17 07:48 - 00000451 _____ () C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat 2014-04-17 07:48 - 2014-04-17 07:48 - 00000244 _____ () C:\Windows\system32\{86F549EB-A66B-4D6C-958D-CDDD66410751}.bat 2014-04-17 07:48 - 2014-01-02 18:16 - 00015354 _____ () C:\Windows\system32\results.xml 2014-04-17 07:47 - 2014-03-12 13:49 - 00000000 ____D () C:\Windows\SysWOW64\NV 2014-04-17 07:47 - 2014-03-12 13:49 - 00000000 ____D () C:\Windows\system32\NV 2014-04-16 19:24 - 2014-04-16 19:24 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-04-16 19:24 - 2014-01-03 09:32 - 00000000 ____D () C:\Program Files\CCleaner 2014-04-16 19:17 - 2014-01-20 14:39 - 00000000 ____D () C:\Users\USER\AppData\Local\Battle.net 2014-04-16 19:16 - 2014-01-20 14:38 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-04-14 14:56 - 2014-01-02 16:08 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2014-04-14 13:51 - 2014-01-02 21:31 - 00000000 ____D () C:\Users\USER\AppData\Local\Adobe 2014-04-14 13:26 - 2014-04-14 13:03 - 00000000 ____D () C:\Users\USER\Documents\FIFA 13 2014-04-14 12:30 - 2014-01-05 17:15 - 00000000 ____D () C:\Users\USER\AppData\Roaming\DAEMON Tools Lite 2014-04-14 04:24 - 2014-05-04 20:33 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-14 04:19 - 2014-05-04 20:33 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-13 22:59 - 2014-04-05 21:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bethesda Softworks 2014-04-13 22:28 - 2014-04-13 21:43 - 00000000 ____D () C:\Program Files (x86)\VstPlugins 2014-04-10 19:55 - 2014-01-03 09:46 - 00000000 ____D () C:\ProgramData\Adobe 2014-04-10 16:13 - 2014-04-10 16:13 - 00000582 _____ () C:\Users\USER\Desktop\BaronReplays.lnk 2014-04-10 16:13 - 2014-04-10 16:13 - 00000000 ____D () C:\Users\USER\AppData\Local\Ahri.tw 2014-04-10 16:13 - 2014-04-10 16:12 - 00000000 ____D () C:\Users\USER\Desktop\BaronReplays 2014-04-10 08:58 - 2014-03-05 21:48 - 00000000 ____D () C:\Users\USER\Desktop\Giery 2014-04-09 23:12 - 2014-04-03 09:11 - 00003006 _____ () C:\Windows\System32\Tasks\{854B76BC-6B45-4627-8FC7-B4DA6FAB2AD8} 2014-04-09 23:12 - 2014-04-03 09:10 - 00002996 _____ () C:\Windows\System32\Tasks\{02506623-AB56-41D5-AF55-5BB10284AE2E} 2014-04-09 23:10 - 2014-01-02 15:59 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-09 23:10 - 2014-01-02 15:11 - 00000000 ____D () C:\Windows\Panther 2014-04-09 11:57 - 2014-01-10 18:30 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-09 11:56 - 2014-01-05 17:55 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 11:51 - 2014-01-05 17:55 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-08 10:23 - 2014-04-08 10:23 - 00000000 ____D () C:\Users\USER\AppData\Local\Electronic Arts 2014-04-08 10:22 - 2014-02-03 15:14 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-04-08 10:18 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-08 10:15 - 2014-01-29 12:43 - 00000000 ____D () C:\Users\USER\Documents\My Games 2014-04-08 10:15 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-04-08 10:08 - 2014-02-10 18:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games 2014-04-08 09:51 - 2014-04-08 09:51 - 00003000 _____ () C:\Windows\System32\Tasks\{BD282B4A-9548-4516-B813-C5C1A54674A9} 2014-04-08 09:49 - 2014-04-08 09:49 - 00003000 _____ () C:\Windows\System32\Tasks\{A590B05B-5BEB-47C0-9648-2913B7E0CAB3} ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-30 23:13 ==================== End Of Log ============================