Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-05-2014 Ran by OEM (administrator) on OEM-KOMPUTER on 14-05-2014 19:23:58 Running from C:\Users\OEM\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 9 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\loggingserver.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (DT Soft Ltd) C:\Program Files (x86)\Daemon Tools Pro\DTShellHlp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.5\ScriptHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Windows\Temp\PowerMon\PowerMon.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Users\OEM\Downloads\sdgwxpdu.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2561560 2014-05-08] () HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-05-14] (AVAST Software) HKLM\...\Policies\Explorer: [3212083974] 0x504B0304C239B7F8068374BFB511000000400000E269F63D73594F6202C9694280CC96A28BBD63516FE3C2D5F7A2FF87AC3A990C3EC3B2ED7B07716237A0DFB1DFB651F67E31CB2E7649F98D5E55E9B25B1A579794989B176C357BDCC11226BD6ECB7DE8A63EA2165F6B31EAD6B0A2A96A6E9D04B9B39F194EF52D48B088D4B6597F685A70FF6912914F86D8235681747DA26CFD83223D3D248872C51095484634EBF976E4595F734BD35CAF42B38DCF9E878AF0BE0A5E84B22940F721E8BBCDCBAA3E53607359252DB16C0D6C38A142261BB4896D12A48C006CC3C21FDF717C155B2AF0375D2545EE286C2AECB2955206EF25C82DC686F7EB83BB3072E94E1E59254B11A2E3628E1D98E177375B54E682A1C77F986E1907FFCB784ACCACB124189751D7EBBAFC91D3A127F134A85E27F8C201D9082F621F5FFFAC09D2AAB94A62F90BD74D6C96A8DB6D42E4E98316449D202A4E24857673E2A50B7DFD9D5AF72A21A19A922ACC9675BA933A1C6AD4E0A11470FBB82EED7A79C5CA2DBB0BEC5B2B43BAA37373D3EF494726D7CF4A4AA8A3D6A5C206CED49148C0100BFA96B707BE91B855151D8DA8E0723DD1303325011B3951C9DF7B10E9B153BCED98376C4D7517F2E0E23A986914B2B0F978454441C47B5797D924CE9CD186D74D308099EE52F226E92DE6B50E4A0691F75CFA9CE733494B8CAFAEB4BE4C65F6C9DFFA34A3C2ED9D14F5844164BE79B7A90495290350177B03AEFA777FF519B624E3C75C219260AC447BBA9A6DB56F34B340A5F75837FAB3C33831A3BC39C2914AEB87A39545BD7ED52450EB7E94D5380E2BABCE3F8EE6E3CDC9D4ED54D9889D9DBD0DC879CAA2B121048A308A7F873252DAD24EA8F8911EA0A3B202DE930A9FC882CF1349FFE229016B2EBFD7821B8986D31DECCBC296BA54FD6D864C915F1D77AC0734D96FE0BA43A669FAB128026C7F90E9E1E0A7047F5A2378E4DE0966EB6C217B3483194B2B21A3FA8A1CBEF1D66A3FC8A5C863BCEA6157981A11449BAE3357F3287501CB9C24E0AFB156F5DDFD6855CD8B7B43FEABD9412C1C208B5DE2330C469A59DE5B490CC06BFD5A4900CB121EB967BC7185A9F00112A5B1E8D8028CA02B0F2B194AF03CC1E172B70C9B88643E3C064B5406CF184AD9EBA26736EF6FEB30DAC8BA400933A32A3C03230BD732FCBE16C4B3BDCC0B501616CE956D968B8DA68B4A9A64238601E81E78095961580431361A4DD9FE963D3CEBA5C21BBA416C1CC9D94BB842C25B2FD12C8BF42C35948272965A3FECF6E9B92D32D7E84A402A0B6214A412A23427E4852CE607FD9F7FF8559BBB96A9AE577DF0C19D108587D372470BE0D3E27ED61FEB442C2D65E55BAC81C2786CF6B837EEBC1B5AF35634B29FD5D96347B5F9C747C8A9A83E7CB3C188D9042F08FBD4EDEEBD65DE7C04B275B7FD74067A0AE3033752AA55A45A05355811416EA4A5101511E99305B700BD44742CBD6A9272B5CF4001505C4057866B57E4DE5EF0EE9F88B41986A80119C962594972011FC0C39B4A74B74747F5116D896A0EBCBB4387685672899AF54B80AE07008971EA1C997A898E33AAB769E4E52FBBEC97EBF199CE76454BADBD4EAB272F1D1CAABB3B49B3AAFC1E67D09EE8FEB0580E414EB45F3F0C25FE88872312FEC2341E7A6100B2E04ED25FCE13A146098DCE98446B2F3875ECB269A886795698619D337DA612F19BF8D4FE3028E79A26548128D1595AF0BF98FF320DC73D873F05EBD07C87CAE28DF067C00DE3E53CC77E801E1304192CA7BF78AB28DB40564328A108F9F0DDD8E1B0BAECCF16BF1DEB3CC5C4B5F5140F6B8A256E9128C203418AA3D93E3F08078977667DC02D830BB6869DE92F29A65AC6D2689D0A5A90887A8643119DC9A68B5B00BD59D45DA9D7ED5DAE6EE6DA6119243F77F51B263200F90ABBB61CCE9A951781EA2012A2C8D7200906439B08E7E76CF9C9536B2E6B560AFD7CBAA5044791EE17DED45ADFD9D359DAC0A9F4ED15BF2CB2EA9B12B7CB11B597CF2E6E750A6C636FE2C4B144F6FF43CCFFDDAE787BE160B0A8B4282B35A6AEECE165814E95CE7ADBE416EF4E51860CB4F5D50AF2A86AA4EE602A30AA54850E0CB4A38DC3A1C711B5D03B6A53EE102AC68E553D11E5FB3D0A8E0EF34266263CA4A3E0B76C55A92F75F921CD61A5363E5DB7737874D57C653D63457260B67B1DF330827B2921C29FDA0045BBE7404E40985039F7DB153F52B2C941A56E922DCFB60B89DBEE327ED6F5C1E438270F766A6ED1730FC581A4AEBCFE3B7726B27D6B092CF5A0B6954196CB4CC2788B8722338EE189D9E22692595F0D5B333B0F715CB8D94A08AFB631DBB1BE79A773E8F1A4EAF7220C24222DDA431B91D9175DFA0C6AE81E8C4C879D64446CF56FAEFE1487CA6739A776AEE42EF8BE40A612F95CDE3B1FEEAC1E1E41A24C92ED8B0152E247239E5A8BC903679CA8C7B94659AD5B1D10551F460D924FB60882FC90508C3723420F86F4CF100387E808133CC429883C0E3ACE91651C075CD19D106E0B437B0363048CA1FEAAF929B87AED90AFDE281EDCA0FA0CC7B5A7F03807FA5AC41B1ED73130EAC1117C631C1818142F24D420F6776CB53D4D0326B9FC3008C3CA03FC649D87D37FA617B74F2865C75298BED54B7D8DC676E2210374D8BF194AE2FEDA62B4798933C764CCDDF845330721FC21E68C0695CA73285103E22AE68DA440326DFEF9A80D17D0A7C3F920E7B0AA806EE9B7549ED9878B6CFB505AC69E8E8D3CFA718675764CFB03861D32AFAAE1D918BE87F6A9AC0D815C57AD3E167D642F5FCDDC25D4BA3AC3E67C26A4DEAA17797B3C0654F271EAAA442A71CBE19372ADCBDE3DF8B3FE491E5A76A79D1291A0DE317FFBF927F42782FA48270F2C969563B183A4B0112F3497DD3C2A423EC83498BDBAAC928910A9FB7FE5788E454C027A28F4A91AF2BF09E261F85B0EEE4F7929E63C4062496CB09534BB6D03FF69ED2915D0EA215B4FB3D1044E86EB87DFB4898BCBD50E5C4DDFBDB83B9410E1ADF91446C43C959E0E341D67A5A7EF8712586DE3B8B9C5B6F80F42F235BF68900EBFE6304BB0D9F67408B76201EC26180B4BD76500DE4F0DF86DF4A063AECECCA69DDF8A162B67A4B9800FA7570D5B551AC2703ADC0FFCED00650A96CD81EC4187B90C6B2140CE99C1937C40587EA72899897E628115BCAB73B3D9F425860B109A67347B8A121F65D0968D56A3DDE6B8171CEA61B08AE568B9D03C398977CE86F75055230EF370CABF67C9CF97C3223719555403F3E0BD2AF0E1E8742DECB05FADB0227F15D40EE2D6DC5A49FE1E6BC9E6CEDDE74294C3BB6FD5C5FEDFAD672DF1DFFD219BD8BC1EC39158EAB507998755F553441D01CD26A5501F6FB2DB4F3597510F85B93A542514C8013EEDBBFC913DCCE8B20A5759665BDFD9919EB22A89163D8656386D857C5BFC7C241C1D726CD94AB0F92D5B0FEFCF1D4ABDD26FBC6C17A4CCACF2D31E5E713059DE93C59D3B8D3E8D03B5D663F9DFADB03E093CB84FCF500A1F0E2E5BA1C9D81DB12CC799C6539AF0CC35682D95CB789C745A452BD8B38E6CF08E0579DA1AB43AD0858D0305F961B15A79C1090F4867040EA2BD36CF6512AAB44CE5A1098EFE039134F23BF057777FEF3E68E45827B0487924CAD4E5F0B1C3B4F5A0E3853B39640EB0782D78888FE92C3B68624E84FF6A5EDED87BE62D34CE858F34E5FFFBBA75F014DF0F648988B51A72DE1FF54D5C7A4B8ECB10C5E9EF51DE98C01EF8C406F9824A0C15A29E16B5A53E3643B0065A4263ECAE50D2CB976D3D2EA6255A65F1C6CC86167F1784A27B832037DB4CE1E262475334F3B2430F86C7A24456EEA82AB678ABA91BB4C0CC82C877B80B6D3574007257272C3E126C17A8B36AA8AA9431FF01BF658F82D8153EDDEA6804CDC564A3F5E9967B08FEEB823D3DB9356A4ACDD80E883CA58A1C661D01D145F80A3AB67E8036C0BAE1BB7BC43204EB0CF38214BC74A9AEF036A31D5A9C552D93A25C0E84057BCE5437B1634680D04A77472D631432D2BAA7A3ACD64220EFCF9E7848F8FD9801BEF7561A470A1822032160EB59EDC0F977882DCE4FB2872D89D27FF076DBA74A9672F86909956579C28853FA8DE7002CC8458D09256D42A39F1A4BDB6B56D36D51488E7368686E54C1BBBFFF48884E0D536BE362E59BD7F18329A4B82AED396E4F92865F594D0DA38F7CACE7A4603AF60C1A53BDFD19476094AAC6E4A8F31FC1257D48D03BB0EF515D8460B9441532C8B5043D0531D5881ADB6D997BB184FD8CAF4D8E6C759C3F7143B9E32BC7A0EC6234B68ADF4111CA1D136721438E5E6D7125D480CE982D84AEA7703B4010CD27867D6DDC5E0C970385196F020E48EDDB24C56972F9E61E6CC29C1712551583828F899534AACFFFC66F99999EA2BA2731D52A7FD2FA262A22B075DA52A5AA58F5B41AA9CDC9181406717F3F75E7C475090121966838125236E4DC6291AE3874968E8208B983AADB03CA60ACD935E6DA1B829407F70A77340E4439F22FDC2FC4218DE0F25D2F886C0AAEB693C2B23DB0EAB9953BF806C2173E0BC9D0D7EF0E763775BC1432FF48D6035B1214294C81B71CD98C42831014090CD99CB74929AE853F88132E559104D4FEA98AD40F17DA4100A909A6981BAD9EFB240A79520927AA12232A56F4D8893BFF92BFC2BD42CF3DC09BDC484DFDBA3A10C609186104CE33E3024F44000BE34814FF5DC9872D44B4157FB3A6655B985F6CC5EF4586F2ABFEE12DCBDB90181B396F95FE3213F094D1F3DD3D7FED800F4ED21290F613B62048E0FC1F1328D9F87A5653B489D36F727BE9D755523DEF0472F1C1D5AC90EE665379FF39D06E863C244890F5333A0B89B92022C1A8198029FE5F8C203B3DD211D4398958EE190108DD50B7850E20D8ABE2B927D53D28F3B8CA26BE81BC6B83C0E2B3B1DDA28066C63860CEA89DF82708EF21D4D36B84663E87B4385A3E37BD3FF1EB2BF64184C44723490669AF4DA092D45BA21A569A352E513D9A9B43E9CD4B812055822626EFC55F950009232B8B3BB2D63D44A8B0BD9BD4E84C5A724496A2326F63C97DBCB235366EC0CF6096B5F4988D073C34BD3A084130CEA8D6EE22E542B411C1E18599667B3FD6DDE0669AD82C85A1C10CA5862213CB1BB277E6C4F6564F20A9BCEA1B48170504C47235D78ED0A0441987C8C17D90D7B56CF487C46733BA4A6848FEC42B97CE4048F3C6D9C493322F052EF93F02F142B3940A10921BD15C911E7A97AA4A20DC383C62CD288D252BA937B3F60761E6653568A01241BB573664DE04811CF3F59B4C2D7E8A6C55DA16F468383456AA751697697397C2A5E5ABFA0F1099D80447D49DA509AA1347F3943EE9BAA1FDAD2A0E69410B34253AD4991282D0E952260F52AB9F02A3D00B37098CF60354424F862066E45E92AC475C99A00E7380766E589ABF66271619142795CF7A7FBD138A6CC5BD7E135122341D1F06EB5B436C59BE0ADEDC71BC03D7C63C16751AD56C69E36DECFE9E8214C719FCDF2E9FE2DC971F03C1C2AD6B6D368FE8B11D0389650C73D1C7E73708145FA05992A150E6A909656EA786E244BDF1CD71F4B0FD05B1335D703182FFA9D96C99108297B1FE327A83BF4F69D2A9C3D1EB73A9DD8CEE2B3220904AC31011FD6407A5BA427FACB46227FDEDB13D1CA6443DED3DC3B6CF06A59DC9B9226FBF357334ABF58412605FD206E7B6125FA19E5D68F75783FA08205B05C0A12D1830068317F6105958C4EB37BCB1BEAE6A401C267641AA58274A410D76B4D2A03E418020869B6886BB81964761B3FCD8EA68050AD6CFF99649CDE8FA53F04B0C96E271C0B092E24D81EA2D723775799E713EA9DA6967EF57AAAFE1C6732F2F047556027F021C65FC20C1C3BCB392ACF8FF7A9E14D9728A5AAACD255FC3866B041E9C96DCF592083D78C9E405DDD7991D2E2536D2EB1BA0F0ECE3DFB6A34C2665CFAC2D1850FD478F617FDD4E9DD4492C553BD375CFD33F4744D642006F3A5216A1FF7D73643ED751CAECDFDCB56247AA2F66FBCB8315DAAA86006A99E0350A72D5D5260D6BB77AC53CDD7ABACB859586C279B7FACDF076C922AC27F3E907FB3B4EC977CA634A28DF064162165222DCCE674DAB60A4E9D48E7FCEA267ABB1F8E0A2012AA6DB532A4CE74FBAF583E2C292FA1B56BE585D14EE073CDAFE3FC0C19050E698EC41B9D27F5DB41A779208118A5D3F8F74333B2AD2FE3CEE273BBFEA485EAD817EFFEDF1260C1A125070589B6F0F31984ED498CBD273E84A718F54C82CBC2747E678F8437DDE23C9EA3C877823034B7C70731C2D01CC09D11D3364E7945B6480B9B416ACB54CD1194B46C6D2E147619AC1C1FA915AF80A5098647247EBCF0449634F69C96AFC740BCE61993228183D98D0F85406D8FFD934 HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\Run: [Java] => %APPDATA%\Microsoft\jushed.exe HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\Run: [Google Update] => C:\Users\OEM\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-10-20] (Google Inc.) HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\Run: [Google Update*] => [X] <===== ATTENTION (ZeroAccess rootkit hidden path) HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\Daemon Tools Pro\DTAgent.exe [3035968 2012-02-02] (DT Soft Ltd) HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\MountPoints2: {187acdce-34bc-11e3-b32a-001fc6c32ab8} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL P:\autorun.bat HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\MountPoints2: {8d1dcc4e-41f1-11e2-859b-001fc6c32ab8} - I:\ZTE_Handset_USB_Driver.exe HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-05-11] (Microsoft Corporation) <==== ATTENTION Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (McAfee, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C&q={searchTerms} URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1390604799&from=cor&uid=395049983_397234_1C8C6C2C&q={searchTerms} SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={8DB11069-4C0C-4117-97CF-7EF746977CBC}&mid=0840d4a0772647d086d9d1568027c34b-54e456de474e5148b7a2012dcce6f966901e3107&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-04-14 16:36:30&v=18.0.5.292&pid=safeguard&sg=&sap=dsp&q={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search) Toolbar: HKCU - No Name - {4D594333-0076-A76A-76A7-7A786E7484D7} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.5\ViProtocol.dll (AVG Secure Search) Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Tcpip\..\Interfaces\{F9D184CC-5805-488C-A3D8-4CC4EEF71B82}: [NameServer]194.204.89.1,194.204.152.34 FireFox: ======== FF ProfilePath: C:\Users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\u54spn29.default-1381653775217 FF user.js: detected! => C:\Users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\u54spn29.default-1381653775217\user.js FF Homepage: hxxp://mysearch.avg.com?cid={8DB11069-4C0C-4117-97CF-7EF746977CBC}&mid=0840d4a0772647d086d9d1568027c34b-54e456de474e5148b7a2012dcce6f966901e3107&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-04-14 16:36:30&v=18.0.5.292&pid=safeguard&sg=&sap=hp FF Keyword.URL: user_pref("keyword.URL", ""); FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.5\\npsitesafety.dll No File FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.1483 - C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin-x32: @tools.bdupdater.com/BonanzaDealsLive Update;version=3 - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.bdupdater.com/BonanzaDealsLive Update;version=9 - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @onlive.com/OnLiveGameClientDetector,version=1.0.0 - C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll No File FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\OEM\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\OEM\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\OEM\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Users\OEM\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml FF Extension: No Name - C:\Users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\u54spn29.default-1381653775217\Extensions\jid1-0xtMKhXFEs4jIg@jetpack.xpi [2014-02-21] FF Extension: No Name - C:\Users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\u54spn29.default-1381653775217\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2014-03-19] FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.512 FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.512 [2014-05-08] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-14] FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird Chrome: ======= CHR HomePage: hxxp://mysearch.avg.com?cid={8DB11069-4C0C-4117-97CF-7EF746977CBC}&mid=0840d4a0772647d086d9d1568027c34b-54e456de474e5148b7a2012dcce6f966901e3107&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-04-14 16:36:30&v=18.1.5.512&pid=safeguard&sg=&sap=hp CHR RestoreOnStartup: "translate_accepted_count": { "de": 0, "en": 0, "ru": 0 }, "translate_blocked_languages": [ "pl" CHR StartupUrls: "hxxp://mysearch.avg.com?cid={8DB11069-4C0C-4117-97CF-7EF746977CBC}&mid=0840d4a0772647d086d9d1568027c34b-54e456de474e5148b7a2012dcce6f966901e3107&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-04-14 16:36:30&v=18.1.5.512&pid=safeguard&sg=&sap=hp" CHR Extension: (AVG SafeGuard) - C:\Users\OEM\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2014-05-08] CHR Extension: (Google Wallet) - C:\Users\OEM\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-01] CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\OEM\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-02-01] CHR HKLM-x32\...\Chrome\Extension: [dghncoeocefmhkhiphdgikkamjeglbfh] - C:\Program Files (x86)\mystarttb\chrome-newtab-search.crx [2014-02-01] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-05-14] CHR HKLM-x32\...\Chrome\Extension: [pkndmigholgfjlniaohblojbhgjbkakn] - C:\Users\OEM\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx [2014-05-14] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-14] (AVAST Software) S2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109048 2014-05-14] (AVAST Software) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-18] () S2 PowerMon; C:\Windows\Temp\PowerMon\PowerMon.exe [1958288 2013-10-11] () R2 vToolbarUpdater18.1.5; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe [1801752 2014-05-08] (AVG Secure Search) S2 ABConfSV; L:\ArcaVir\Common\ArcaConfSV.exe [X] S2 ABMainSV; L:\ArcaVir\ArcaVir\ArcaMainSV.exe [X] S2 ArcaRemoteService; L:\ArcaVir\ArcaAgent\ArcaRemoteSvc.exe [X] S2 AVBackup; L:\ArcaVir\ArcaTools\ArcaBackup\ArcaBackupService.exe [X] S2 AVTasks2; L:\ArcaVir\Common\ArcaTasksService.exe [X] S2 AVUpdate; L:\ArcaVir\ArcaUpdate\update.exe [X] S2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{91bfea6f-a31b-5e17-ffc7-599a0feb4b6c}\ \...\???\{91bfea6f-a31b-5e17-ffc7-599a0feb4b6c}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess) ==================== Drivers (Whitelisted) ==================== R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-05-14] () R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-05-14] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-05-14] (AVAST Software) R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [447888 2014-05-14] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-05-14] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-05-14] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-14] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-14] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-14] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-05-14] () R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-05-08] (AVG Technologies) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-16] (DT Soft Ltd) S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-03-20] () S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC) S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [18456 2012-04-16] (HandSet Incorporated) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] () S3 nocashio; C:\Windows\SysWOW64\drivers\nocashio.sys [4096 2013-08-09] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation) R3 V0520Vid; C:\Windows\System32\DRIVERS\V0520Vid.sys [280704 2011-09-02] (Creative Technology Ltd.) S3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [21504 2008-12-26] (Avnex) S3 zghsdiag; C:\Windows\System32\DRIVERS\zghsdiag.sys [129560 2012-02-24] (ZTE Incorporated) S3 ABFLT; \??\L:\ArcaVir\ArcaVir\ABFLT.sys [X] S3 ABWFP; \??\L:\ArcaVir\ArcaVir\ABWFP.sys [X] S3 ADIHdAudAddService; system32\drivers\ADIHdAud.sys [X] S3 dgderdrv; System32\drivers\dgderdrv.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X] U4 vsserv; S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] U3 uxriqpow; \??\C:\Users\OEM\AppData\Local\Temp\uxriqpow.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-14 19:23 - 2014-05-14 19:24 - 00032231 _____ () C:\Users\OEM\Downloads\FRST.txt 2014-05-14 19:22 - 2014-05-14 19:23 - 00000000 ____D () C:\FRST 2014-05-14 19:21 - 2014-05-14 19:21 - 00384862 _____ () C:\Users\OEM\Desktop\GMER.txt 2014-05-14 18:44 - 2014-05-14 18:44 - 00051756 _____ () C:\Users\OEM\Downloads\Extras.Txt 2014-05-14 18:41 - 2014-05-14 18:41 - 00155824 _____ () C:\Users\OEM\Downloads\OTL.Txt 2014-05-14 18:25 - 2014-05-14 18:25 - 00380416 _____ () C:\Users\OEM\Downloads\sdgwxpdu.exe 2014-05-14 18:19 - 2014-05-14 18:19 - 02066944 _____ (Farbar) C:\Users\OEM\Downloads\FRST64.exe 2014-05-14 18:18 - 2014-05-14 18:18 - 00602112 _____ (OldTimer Tools) C:\Users\OEM\Downloads\OTL.exe 2014-05-14 18:06 - 2014-05-14 18:06 - 00002986 _____ () C:\Windows\System32\Tasks\MSIAfterburner 2014-05-14 17:59 - 2014-05-14 18:02 - 00000000 ____D () C:\Users\Public\Desktop\CC Support 2014-05-14 17:48 - 2014-05-14 17:49 - 00000000 ____D () C:\Users\OEM\Desktop\Zapora 2014-05-14 17:29 - 2014-05-14 17:29 - 00002032 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-05-14 17:29 - 2014-05-14 17:29 - 00001972 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk 2014-05-14 17:29 - 2014-05-14 17:29 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\AVAST Software 2014-05-14 17:29 - 2014-05-14 17:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2014-05-14 17:28 - 2014-05-14 17:29 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-05-14 17:28 - 2014-05-14 17:27 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-05-14 17:28 - 2014-05-14 17:27 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2014-05-14 17:27 - 2014-05-14 17:27 - 00447888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys 2014-05-14 17:27 - 2014-05-14 17:27 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-05-14 17:27 - 2014-05-14 17:27 - 00000000 ____D () C:\Program Files\AVAST Software 2014-05-14 17:26 - 2014-05-14 17:26 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-05-12 19:58 - 2014-05-12 19:58 - 00081303 _____ () C:\Users\OEM\Desktop\Bez_nazwy.wma 2014-05-10 22:04 - 2014-05-10 22:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-10 00:19 - 2014-05-10 00:19 - 00000000 ____D () C:\Users\OEM\Desktop\fote 2014-05-09 18:39 - 2014-05-09 18:39 - 00000000 ____D () C:\ProgramData\PopCap Games 2014-05-08 23:24 - 2014-05-08 23:24 - 00000000 ____D () C:\ProgramData\AVG Secure Search 2014-05-06 15:51 - 2014-05-06 15:51 - 00000588 _____ () C:\Users\Public\Desktop\LauncherHERO.lnk 2014-05-04 15:25 - 2014-05-04 15:25 - 00000857 _____ () C:\Users\Public\Desktop\Play Euro Truck Simulator 2 Multiplayer.lnk 2014-05-04 15:25 - 2014-05-04 15:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Euro Truck Simulator 2 Multiplayer 2014-05-02 22:02 - 2014-05-02 22:02 - 00001143 _____ () C:\Users\OEM\Desktop\GG.lnk 2014-05-02 20:57 - 2014-05-12 16:50 - 00054156 ____H () C:\Windows\QTFont.qfn 2014-05-02 20:57 - 2014-05-02 20:57 - 00001409 _____ () C:\Windows\QTFont.for 2014-05-02 14:53 - 2014-05-02 14:55 - 00000000 ____D () C:\Users\Test\Documents\GTA San Andreas User Files 2014-05-02 14:27 - 2014-05-02 14:27 - 00000000 ____D () C:\Users\Test\AppData\Local\CrashDumps 2014-05-02 14:26 - 2014-05-02 14:26 - 00000000 ____D () C:\Users\Test\AppData\Roaming\NVIDIA 2014-05-02 14:24 - 2014-05-02 14:24 - 00002960 _____ () C:\Windows\System32\Tasks\{F042A921-964B-421E-B26B-92DF97F2C874} 2014-05-02 14:07 - 2014-05-02 15:11 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Skype 2014-05-02 14:07 - 2014-05-02 14:07 - 00000000 ____D () C:\Users\Test\AppData\Local\Skype 2014-05-01 15:15 - 2014-05-01 15:15 - 00000000 ____D () C:\Users\Test\Documents\gothic3 2014-05-01 13:49 - 2014-05-01 13:49 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Wargaming.net 2014-05-01 13:46 - 2014-05-01 13:46 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Adobe 2014-05-01 13:46 - 2014-05-01 13:46 - 00000000 ____D () C:\Users\Test\AppData\Local\AVG SafeGuard toolbar 2014-04-30 21:02 - 2014-04-30 21:02 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Wargaming.net 2014-04-29 18:45 - 2014-04-29 18:45 - 00000583 _____ () C:\Users\Public\Desktop\World of Tanks.lnk 2014-04-29 18:45 - 2014-04-29 18:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks 2014-04-26 18:25 - 2014-04-26 18:25 - 00001596 _____ () C:\Users\OEM\Desktop\Far Cry 2.lnk 2014-04-24 18:43 - 2014-04-24 18:44 - 11331489 _____ () C:\Users\OEM\Downloads\BestBeatEvaa - MRVLOG 0,5.mp4 2014-04-24 16:11 - 2014-04-24 16:11 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software 2014-04-24 16:11 - 2014-04-24 16:11 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\TuneUp Software 2014-04-22 20:09 - 2014-04-22 20:09 - 00000093 _____ () C:\Users\OEM\Downloads\listen.asx 2014-04-22 14:47 - 2014-04-22 14:47 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Oracle 2014-04-22 13:08 - 2014-04-22 13:08 - 00004129 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log 2014-04-22 13:08 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-04-22 13:08 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-04-22 13:08 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-04-22 13:08 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-04-21 20:47 - 2014-04-21 20:47 - 02269863 _____ () C:\Users\OEM\Downloads\forge-1.6.4-9.11.1.965-installer.jar 2014-04-19 20:30 - 2014-04-19 20:30 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\StunlockStudios 2014-04-19 13:32 - 2014-04-19 20:49 - 00000000 _____ () C:\dfu.log 2014-04-18 20:59 - 2014-04-18 20:59 - 00000202 _____ () C:\Users\OEM\Desktop\Tom Clancy's Ghost Recon Phantoms - EU.url 2014-04-18 16:35 - 2014-04-18 16:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 2014-04-18 16:35 - 2014-04-18 16:35 - 00000000 ____D () C:\Program Files\McAfee Security Scan 2014-04-18 16:26 - 2014-04-18 16:26 - 00000082 _____ () C:\Windows\mafosav.INI 2014-04-18 11:53 - 2014-04-18 11:53 - 00000188 _____ () C:\Windows\SysWOW64\debug.log 2014-04-14 16:46 - 2014-04-14 16:46 - 00683706 _____ () C:\Users\OEM\Downloads\ster_34009.rar 2014-04-14 16:39 - 2014-04-14 16:39 - 02420267 _____ (Macrovision Corporation) C:\Users\OEM\Downloads\setup.exe 2014-04-14 16:37 - 2014-05-09 17:55 - 00000000 ____D () C:\Users\OEM\AppData\Local\AVG SafeGuard toolbar 2014-04-14 16:36 - 2014-05-08 23:24 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-04-14 16:36 - 2014-04-14 16:36 - 00000000 ____D () C:\ProgramData\AVG Security Toolbar 2014-04-14 16:35 - 2014-05-08 23:24 - 00003750 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml 2014-04-14 16:35 - 2014-05-08 23:24 - 00000000 ____D () C:\Program Files (x86)\AVG SafeGuard toolbar 2014-04-14 16:35 - 2014-04-14 16:36 - 00000000 ____D () C:\ProgramData\AVG SafeGuard toolbar 2014-04-14 16:34 - 2014-04-21 00:13 - 00001975 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2014-04-14 16:34 - 2014-04-14 16:34 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-04-14 16:34 - 2014-04-14 16:34 - 00000000 ____D () C:\ProgramData\McAfee ==================== One Month Modified Files and Folders ======= 2014-05-14 19:24 - 2014-05-14 19:23 - 00032231 _____ () C:\Users\OEM\Downloads\FRST.txt 2014-05-14 19:23 - 2014-05-14 19:22 - 00000000 ____D () C:\FRST 2014-05-14 19:23 - 2013-10-20 18:55 - 00001050 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1948933813-2092389452-934283344-1000UA.job 2014-05-14 19:21 - 2014-05-14 19:21 - 00384862 _____ () C:\Users\OEM\Desktop\GMER.txt 2014-05-14 19:11 - 2013-10-19 16:06 - 00000920 _____ () C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job 2014-05-14 19:05 - 2013-11-16 22:23 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-14 19:05 - 2013-11-16 22:23 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-14 19:05 - 2012-12-07 16:27 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-14 19:05 - 2012-12-07 16:27 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-14 18:44 - 2014-05-14 18:44 - 00051756 _____ () C:\Users\OEM\Downloads\Extras.Txt 2014-05-14 18:41 - 2014-05-14 18:41 - 00155824 _____ () C:\Users\OEM\Downloads\OTL.Txt 2014-05-14 18:36 - 2012-12-31 20:45 - 00001042 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-14 18:25 - 2014-05-14 18:25 - 00380416 _____ () C:\Users\OEM\Downloads\sdgwxpdu.exe 2014-05-14 18:19 - 2014-05-14 18:19 - 02066944 _____ (Farbar) C:\Users\OEM\Downloads\FRST64.exe 2014-05-14 18:18 - 2014-05-14 18:18 - 00602112 _____ (OldTimer Tools) C:\Users\OEM\Downloads\OTL.exe 2014-05-14 18:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-05-14 18:06 - 2014-05-14 18:06 - 00002986 _____ () C:\Windows\System32\Tasks\MSIAfterburner 2014-05-14 18:05 - 2013-10-19 16:06 - 00000916 _____ () C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job 2014-05-14 18:05 - 2012-12-31 20:45 - 00001038 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-14 18:04 - 2013-09-07 12:43 - 00096172 _____ () C:\Windows\setupact.log 2014-05-14 18:04 - 2012-12-07 16:52 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-05-14 18:04 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-14 18:02 - 2014-05-14 17:59 - 00000000 ____D () C:\Users\Public\Desktop\CC Support 2014-05-14 17:54 - 2014-04-13 14:17 - 00000000 ____D () C:\ProgramData\MFAData 2014-05-14 17:54 - 2013-09-07 12:43 - 00714120 _____ () C:\Windows\PFRO.log 2014-05-14 17:52 - 2009-07-14 06:45 - 00016640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-14 17:52 - 2009-07-14 06:45 - 00016640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-14 17:49 - 2014-05-14 17:48 - 00000000 ____D () C:\Users\OEM\Desktop\Zapora 2014-05-14 17:29 - 2014-05-14 17:29 - 00002032 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-05-14 17:29 - 2014-05-14 17:29 - 00001972 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk 2014-05-14 17:29 - 2014-05-14 17:29 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\AVAST Software 2014-05-14 17:29 - 2014-05-14 17:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2014-05-14 17:29 - 2014-05-14 17:28 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-05-14 17:27 - 2014-05-14 17:28 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-05-14 17:27 - 2014-05-14 17:28 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2014-05-14 17:27 - 2014-05-14 17:27 - 00447888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys 2014-05-14 17:27 - 2014-05-14 17:27 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-05-14 17:27 - 2014-05-14 17:27 - 00000000 ____D () C:\Program Files\AVAST Software 2014-05-14 17:26 - 2014-05-14 17:26 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-05-14 00:57 - 2013-01-21 15:32 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\GG 2014-05-13 14:57 - 2012-12-07 15:55 - 01812965 _____ () C:\Windows\WindowsUpdate.log 2014-05-12 21:59 - 2011-02-04 19:20 - 00743042 _____ () C:\Windows\system32\perfh015.dat 2014-05-12 21:59 - 2011-02-04 19:20 - 00156524 _____ () C:\Windows\system32\perfc015.dat 2014-05-12 21:59 - 2009-07-14 07:13 - 01676610 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-12 21:55 - 2012-12-07 16:49 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Skype 2014-05-12 19:58 - 2014-05-12 19:58 - 00081303 _____ () C:\Users\OEM\Desktop\Bez_nazwy.wma 2014-05-12 16:50 - 2014-05-02 20:57 - 00054156 ____H () C:\Windows\QTFont.qfn 2014-05-12 15:09 - 2014-01-10 20:20 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Hamachi 2014-05-12 15:00 - 2014-04-05 21:52 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\.minecraft 2014-05-12 14:23 - 2013-10-20 18:55 - 00000998 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1948933813-2092389452-934283344-1000Core.job 2014-05-12 14:18 - 2012-12-07 16:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-11 12:23 - 2009-07-14 06:45 - 05066200 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-05-10 22:05 - 2014-05-10 22:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-10 21:22 - 2012-12-29 20:07 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Audacity 2014-05-10 20:31 - 2012-12-31 20:45 - 00004038 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-10 20:31 - 2012-12-31 20:45 - 00003786 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-10 14:41 - 2012-12-30 16:06 - 00000000 ____D () C:\Users\OEM\Documents\Camtasia Studio 2014-05-10 14:18 - 2013-10-20 18:55 - 00004020 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1948933813-2092389452-934283344-1000UA 2014-05-10 14:18 - 2013-10-20 18:55 - 00003624 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1948933813-2092389452-934283344-1000Core 2014-05-10 00:19 - 2014-05-10 00:19 - 00000000 ____D () C:\Users\OEM\Desktop\fote 2014-05-09 18:39 - 2014-05-09 18:39 - 00000000 ____D () C:\ProgramData\PopCap Games 2014-05-09 18:36 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-05-09 18:35 - 2013-10-03 22:38 - 00158236 _____ () C:\Windows\DirectX.log 2014-05-09 17:55 - 2014-04-14 16:37 - 00000000 ____D () C:\Users\OEM\AppData\Local\AVG SafeGuard toolbar 2014-05-08 23:24 - 2014-05-08 23:24 - 00000000 ____D () C:\ProgramData\AVG Secure Search 2014-05-08 23:24 - 2014-04-14 16:36 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-05-08 23:24 - 2014-04-14 16:35 - 00003750 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml 2014-05-08 23:24 - 2014-04-14 16:35 - 00000000 ____D () C:\Program Files (x86)\AVG SafeGuard toolbar 2014-05-08 20:23 - 2009-07-14 07:08 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-05-06 20:59 - 2013-10-11 12:17 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-05-06 15:51 - 2014-05-06 15:51 - 00000588 _____ () C:\Users\Public\Desktop\LauncherHERO.lnk 2014-05-06 15:51 - 2014-02-22 22:19 - 00000000 ____D () C:\Users\OEM\Desktop\Potrzebne KUBA G 2014-05-05 21:42 - 2013-12-03 18:09 - 00000000 ____D () C:\Users\OEM\Documents\gothic3 2014-05-04 21:16 - 2013-01-02 18:52 - 00000000 ____D () C:\Users\OEM\AppData\Local\CrashDumps 2014-05-04 15:34 - 2013-02-01 21:39 - 00000000 ____D () C:\Users\OEM\Documents\Euro Truck Simulator 2 2014-05-04 15:25 - 2014-05-04 15:25 - 00000857 _____ () C:\Users\Public\Desktop\Play Euro Truck Simulator 2 Multiplayer.lnk 2014-05-04 15:25 - 2014-05-04 15:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Euro Truck Simulator 2 Multiplayer 2014-05-02 23:27 - 2013-11-26 16:39 - 00000000 ____D () C:\Users\OEM\Desktop\Skuter 2014-05-02 22:02 - 2014-05-02 22:02 - 00001143 _____ () C:\Users\OEM\Desktop\GG.lnk 2014-05-02 20:57 - 2014-05-02 20:57 - 00001409 _____ () C:\Windows\QTFont.for 2014-05-02 15:11 - 2014-05-02 14:07 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Skype 2014-05-02 14:55 - 2014-05-02 14:53 - 00000000 ____D () C:\Users\Test\Documents\GTA San Andreas User Files 2014-05-02 14:55 - 2014-04-10 17:11 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-05-02 14:27 - 2014-05-02 14:27 - 00000000 ____D () C:\Users\Test\AppData\Local\CrashDumps 2014-05-02 14:26 - 2014-05-02 14:26 - 00000000 ____D () C:\Users\Test\AppData\Roaming\NVIDIA 2014-05-02 14:24 - 2014-05-02 14:24 - 00002960 _____ () C:\Windows\System32\Tasks\{F042A921-964B-421E-B26B-92DF97F2C874} 2014-05-02 14:07 - 2014-05-02 14:07 - 00000000 ____D () C:\Users\Test\AppData\Local\Skype 2014-05-01 21:56 - 2013-07-17 15:40 - 00000000 ____D () C:\ProgramData\Origin 2014-05-01 21:22 - 2013-07-24 15:32 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-05-01 21:22 - 2013-02-05 17:45 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-05-01 21:22 - 2013-02-05 17:45 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-05-01 16:17 - 2012-12-07 15:58 - 00125192 _____ () C:\Users\OEM\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-01 15:36 - 2012-12-08 12:04 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-05-01 15:15 - 2014-05-01 15:15 - 00000000 ____D () C:\Users\Test\Documents\gothic3 2014-05-01 13:49 - 2014-05-01 13:49 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Wargaming.net 2014-05-01 13:46 - 2014-05-01 13:46 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Adobe 2014-05-01 13:46 - 2014-05-01 13:46 - 00000000 ____D () C:\Users\Test\AppData\Local\AVG SafeGuard toolbar 2014-04-30 21:10 - 2012-12-13 17:38 - 00000069 _____ () C:\Windows\NeroDigital.ini 2014-04-30 21:02 - 2014-04-30 21:02 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Wargaming.net 2014-04-29 18:45 - 2014-04-29 18:45 - 00000583 _____ () C:\Users\Public\Desktop\World of Tanks.lnk 2014-04-29 18:45 - 2014-04-29 18:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks 2014-04-29 18:45 - 2012-12-13 21:56 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-04-27 23:15 - 2014-02-13 00:26 - 00000000 ____D () C:\Program Files (x86)\SAMSUNG 2014-04-27 23:15 - 2012-12-15 14:15 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Samsung 2014-04-27 23:15 - 2012-12-15 14:15 - 00000000 ____D () C:\Users\OEM\AppData\Local\Samsung 2014-04-27 23:15 - 2012-12-15 14:13 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-27 23:15 - 2012-12-15 14:11 - 00000000 ____D () C:\ProgramData\Samsung 2014-04-27 20:22 - 2013-01-21 15:32 - 00000000 ____D () C:\Users\OEM\AppData\Local\GG 2014-04-26 21:18 - 2013-12-26 20:10 - 00000000 ____D () C:\Users\OEM\Desktop\Foldery ;P 2014-04-26 19:39 - 2013-01-23 00:13 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\TS3Client 2014-04-26 18:25 - 2014-04-26 18:25 - 00001596 _____ () C:\Users\OEM\Desktop\Far Cry 2.lnk 2014-04-26 18:23 - 2013-12-20 20:44 - 00000000 ____D () C:\Users\OEM\AppData\Local\Ubisoft Game Launcher 2014-04-25 18:35 - 2014-03-12 18:42 - 00000000 ____D () C:\ProgramData\Ubisoft 2014-04-24 18:44 - 2014-04-24 18:43 - 11331489 _____ () C:\Users\OEM\Downloads\BestBeatEvaa - MRVLOG 0,5.mp4 2014-04-24 18:25 - 2014-01-10 19:40 - 00029696 ___SH () C:\Users\OEM\Documents\Thumbs.db 2014-04-24 18:25 - 2013-12-28 16:53 - 00001312 _____ () C:\Users\OEM\Documents\Default.sfvidcap 2014-04-24 16:11 - 2014-04-24 16:11 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software 2014-04-24 16:11 - 2014-04-24 16:11 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\TuneUp Software 2014-04-22 20:09 - 2014-04-22 20:09 - 00000093 _____ () C:\Users\OEM\Downloads\listen.asx 2014-04-22 14:47 - 2014-04-22 14:47 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Oracle 2014-04-22 13:08 - 2014-04-22 13:08 - 00004129 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log 2014-04-22 13:08 - 2013-10-20 16:44 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-22 13:08 - 2013-06-24 13:07 - 00000000 ____D () C:\Program Files (x86)\Java 2014-04-21 20:47 - 2014-04-21 20:47 - 02269863 _____ () C:\Users\OEM\Downloads\forge-1.6.4-9.11.1.965-installer.jar 2014-04-21 00:13 - 2014-04-14 16:34 - 00001975 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2014-04-19 21:45 - 2013-01-21 15:35 - 00000000 ___SD () C:\Users\OEM\GG dysk 2014-04-19 20:49 - 2014-04-19 13:32 - 00000000 _____ () C:\dfu.log 2014-04-19 20:30 - 2014-04-19 20:30 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\StunlockStudios 2014-04-18 22:11 - 2013-02-05 17:45 - 00000000 ____D () C:\Users\OEM\AppData\Local\PunkBuster 2014-04-18 22:09 - 2013-02-05 17:45 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2014-04-18 22:08 - 2014-03-21 20:26 - 00000000 ____D () C:\Users\OEM\AppData\Local\Ubisoft 2014-04-18 20:59 - 2014-04-18 20:59 - 00000202 _____ () C:\Users\OEM\Desktop\Tom Clancy's Ghost Recon Phantoms - EU.url 2014-04-18 20:59 - 2013-01-27 19:49 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-04-18 16:35 - 2014-04-18 16:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 2014-04-18 16:35 - 2014-04-18 16:35 - 00000000 ____D () C:\Program Files\McAfee Security Scan 2014-04-18 16:35 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-18 16:26 - 2014-04-18 16:26 - 00000082 _____ () C:\Windows\mafosav.INI 2014-04-18 12:44 - 2014-02-07 18:10 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-04-18 11:53 - 2014-04-18 11:53 - 00000188 _____ () C:\Windows\SysWOW64\debug.log 2014-04-18 01:42 - 2014-04-12 13:38 - 00000000 ____D () C:\Program Files (x86)\DSPRobotics 2014-04-14 20:13 - 2014-04-22 13:08 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-04-14 20:05 - 2014-04-22 13:08 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-04-14 20:05 - 2014-04-22 13:08 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-04-14 20:04 - 2014-04-22 13:08 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-04-14 16:46 - 2014-04-14 16:46 - 00683706 _____ () C:\Users\OEM\Downloads\ster_34009.rar 2014-04-14 16:39 - 2014-04-14 16:39 - 02420267 _____ (Macrovision Corporation) C:\Users\OEM\Downloads\setup.exe 2014-04-14 16:36 - 2014-04-14 16:36 - 00000000 ____D () C:\ProgramData\AVG Security Toolbar 2014-04-14 16:36 - 2014-04-14 16:35 - 00000000 ____D () C:\ProgramData\AVG SafeGuard toolbar 2014-04-14 16:35 - 2012-12-07 16:58 - 00000000 ____D () C:\Users\OEM\AppData\Local\Adobe 2014-04-14 16:34 - 2014-04-14 16:34 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-04-14 16:34 - 2014-04-14 16:34 - 00000000 ____D () C:\ProgramData\McAfee ZeroAccess: C:\Users\OEM\AppData\Local\Google\Desktop\Install ZeroAccess: C:\Program Files (x86)\Google\Desktop\Install Files to move or delete: ==================== C:\ProgramData\PKP_DLdu.DAT C:\ProgramData\PKP_DLdw.DAT Some content of TEMP: ==================== C:\Users\OEM\AppData\Local\Temp\078c2a5c7a21a90fc18bbf3905578d53.dll C:\Users\OEM\AppData\Local\Temp\7543b95efef9fa525e17def67e5b46d1.dll C:\Users\OEM\AppData\Local\Temp\AutoRun.exe C:\Users\OEM\AppData\Local\Temp\AutoRunGUI.dll C:\Users\OEM\AppData\Local\Temp\Fraps 3.5.5[A4].exe C:\Users\OEM\AppData\Local\Temp\gface_swap.exe C:\Users\OEM\AppData\Local\Temp\ggdrive-menu.exe C:\Users\OEM\AppData\Local\Temp\ggdrive-overlay.exe C:\Users\OEM\AppData\Local\Temp\GLF4275.tmp.dll C:\Users\OEM\AppData\Local\Temp\guninst.exe C:\Users\OEM\AppData\Local\Temp\hgcpl.exe C:\Users\OEM\AppData\Local\Temp\Ins1104.tmp.exe C:\Users\OEM\AppData\Local\Temp\installstats.exe C:\Users\OEM\AppData\Local\Temp\jansi-32-git-MCPC-Plus-jenkins-MCPC-Plus-35.dll C:\Users\OEM\AppData\Local\Temp\jansi-32-git-MCPC-Plus-jenkins-MCPC-Plus-37.dll C:\Users\OEM\AppData\Local\Temp\jansi-64-git-MCPC-Plus-jenkins-MCPC-Plus-32.dll C:\Users\OEM\AppData\Local\Temp\jansi-64-git-MCPC-Plus-jenkins-MCPC-Plus-37.dll C:\Users\OEM\AppData\Local\Temp\JDownloaderSetup_20140328132404912.exe C:\Users\OEM\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\OEM\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\OEM\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\OEM\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\OEM\AppData\Local\Temp\nvSCPAPI.dll C:\Users\OEM\AppData\Local\Temp\nvStereoApiI.dll C:\Users\OEM\AppData\Local\Temp\nvStInst.exe C:\Users\OEM\AppData\Local\Temp\Onlive_Updater_1385755801.exe C:\Users\OEM\AppData\Local\Temp\PrerequistesRemovalTool.exe C:\Users\OEM\AppData\Local\Temp\setupFlowStoneFL.exe C:\Users\OEM\AppData\Local\Temp\SetupUtil.exe C:\Users\OEM\AppData\Local\Temp\SkypeSetup.exe C:\Users\OEM\AppData\Local\Temp\sonarinst.exe C:\Users\OEM\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll C:\Users\OEM\AppData\Local\Temp\Tsu96B52728.dll C:\Users\OEM\AppData\Local\Temp\uninstall.0d87.exe C:\Users\OEM\AppData\Local\Temp\_is76E5.exe C:\Users\OEM\AppData\Local\Temp\_is88CE.exe C:\Users\OEM\AppData\Local\Temp\_is8AF2.exe C:\Users\OEM\AppData\Local\Temp\_isDC0C.exe C:\Users\OEM\AppData\Local\Temp\_isF64B.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender LastRegBack: 2014-04-10 17:09 ==================== End Of Log ============================