Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-05-2014 Ran by OEM (administrator) on OEM-KOMPUTER on 16-05-2014 10:17:42 Running from C:\Users\OEM\Desktop\FRST Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 9 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (DT Soft Ltd) C:\Program Files (x86)\Daemon Tools Pro\DTShellHlp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-05-14] (AVAST Software) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\Run: [Google Update] => C:\Users\OEM\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-10-20] (Google Inc.) HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\Daemon Tools Pro\DTAgent.exe [3035968 2012-02-02] (DT Soft Ltd) HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-1948933813-2092389452-934283344-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{F9D184CC-5805-488C-A3D8-4CC4EEF71B82}: [NameServer]194.204.89.1,194.204.152.34 FireFox: ======== FF ProfilePath: C:\Users\OEM\AppData\Roaming\Mozilla\Firefox\Profiles\63mggyjx.default-1400226917378 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.1483 - C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\OEM\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\OEM\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\OEM\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Users\OEM\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation) FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-14] Chrome: ======= CHR HomePage: CHR RestoreOnStartup: "translate_accepted_count": { "de": 0, "en": 0, "ru": 0 }, "translate_blocked_languages": [ "pl" CHR Plugin: (Widevine Content Decryption Module) - C:\Users\OEM\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll () CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Users\OEM\AppData\Roaming\Mozilla\plugins\np-mswmp.dll (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Battlelog Game Launcher) - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB) CHR Plugin: (Battlelog Game Launcher) - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (Java Deployment Toolkit 7.0.550.14) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Java(TM) Platform SE 7 U55) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Unity Player) - C:\Users\OEM\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Google Update) - C:\Users\OEM\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () CHR Extension: (Google Wallet) - C:\Users\OEM\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-01] CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\OEM\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-02-01] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-05-14] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-14] (AVAST Software) S2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109048 2014-05-14] (AVAST Software) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-18] () ==================== Drivers (Whitelisted) ==================== R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-05-14] () R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-05-14] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-05-14] (AVAST Software) R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [447888 2014-05-15] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-05-14] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-05-14] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-15] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-15] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-15] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-05-14] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-16] (DT Soft Ltd) S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-03-20] () S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC) S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [18456 2012-04-16] (HandSet Incorporated) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] () S3 nocashio; C:\Windows\SysWOW64\drivers\nocashio.sys [4096 2013-08-09] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation) R3 V0520Vid; C:\Windows\System32\DRIVERS\V0520Vid.sys [280704 2011-09-02] (Creative Technology Ltd.) S3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [21504 2008-12-26] (Avnex) S3 zghsdiag; C:\Windows\System32\DRIVERS\zghsdiag.sys [129560 2012-02-24] (ZTE Incorporated) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-16 10:09 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-16 10:04 - 2014-05-16 10:04 - 00048478 _____ () C:\Users\OEM\Desktop\Preferences 2014-05-16 09:52 - 2014-05-16 09:52 - 00000000 ____D () C:\Users\OEM\Desktop\FSS 2014-05-16 09:50 - 2014-05-16 09:58 - 00000000 ____D () C:\Users\OEM\Desktop\ADW Cleaner 2014-05-16 09:50 - 2014-05-16 09:52 - 00000000 ____D () C:\Users\OEM\Desktop\OTL 2014-05-16 09:50 - 2014-05-16 09:52 - 00000000 ____D () C:\Users\OEM\Desktop\GMER 2014-05-15 20:50 - 2014-05-15 20:50 - 00000060 _____ () C:\Users\OEM\Desktop\artura.txt 2014-05-15 20:49 - 2014-04-18 16:35 - 00000426 _____ () C:\AVScanner.ini 2014-05-15 20:48 - 2014-05-16 10:17 - 00000000 ____D () C:\Users\OEM\Desktop\FRST 2014-05-14 19:22 - 2014-05-16 10:17 - 00000000 ____D () C:\FRST 2014-05-14 18:06 - 2014-05-16 10:14 - 00002986 _____ () C:\Windows\System32\Tasks\MSIAfterburner 2014-05-14 17:59 - 2014-05-14 18:02 - 00000000 ____D () C:\Users\Public\Desktop\CC Support 2014-05-14 17:29 - 2014-05-16 09:52 - 00002076 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-05-14 17:29 - 2014-05-16 09:52 - 00002016 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk 2014-05-14 17:29 - 2014-05-14 17:29 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\AVAST Software 2014-05-14 17:29 - 2014-05-14 17:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2014-05-14 17:28 - 2014-05-15 20:43 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2014-05-14 17:28 - 2014-05-15 20:43 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2014-05-14 17:28 - 2014-05-15 20:43 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-05-14 17:28 - 2014-05-14 17:29 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-05-14 17:28 - 2014-05-14 17:27 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1400179427943 2014-05-14 17:28 - 2014-05-14 17:27 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1400179427943 2014-05-14 17:28 - 2014-05-14 17:27 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-05-14 17:28 - 2014-05-14 17:27 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-05-14 17:28 - 2014-05-14 17:27 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2014-05-14 17:27 - 2014-05-15 20:43 - 00447888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswndisflt.sys 2014-05-14 17:27 - 2014-05-14 17:27 - 00447888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswndisflt.sys.1400179427943 2014-05-14 17:27 - 2014-05-14 17:27 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-05-14 17:27 - 2014-05-14 17:27 - 00000000 ____D () C:\Program Files\AVAST Software 2014-05-14 17:26 - 2014-05-14 17:26 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-05-12 19:58 - 2014-05-12 19:58 - 00081303 _____ () C:\Users\OEM\Desktop\Bez_nazwy.wma 2014-05-10 22:04 - 2014-05-10 22:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-10 00:19 - 2014-05-10 00:19 - 00000000 ____D () C:\Users\OEM\Desktop\fote 2014-05-09 18:39 - 2014-05-09 18:39 - 00000000 ____D () C:\ProgramData\PopCap Games 2014-05-06 15:51 - 2014-05-06 15:51 - 00000588 _____ () C:\Users\Public\Desktop\LauncherHERO.lnk 2014-05-04 15:25 - 2014-05-04 15:25 - 00000857 _____ () C:\Users\Public\Desktop\Play Euro Truck Simulator 2 Multiplayer.lnk 2014-05-04 15:25 - 2014-05-04 15:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Euro Truck Simulator 2 Multiplayer 2014-05-02 22:02 - 2014-05-02 22:02 - 00001143 _____ () C:\Users\OEM\Desktop\GG.lnk 2014-05-02 20:57 - 2014-05-12 16:50 - 00054156 ____H () C:\Windows\QTFont.qfn 2014-05-02 20:57 - 2014-05-02 20:57 - 00001409 _____ () C:\Windows\QTFont.for 2014-05-02 14:53 - 2014-05-02 14:55 - 00000000 ____D () C:\Users\Test\Documents\GTA San Andreas User Files 2014-05-02 14:27 - 2014-05-02 14:27 - 00000000 ____D () C:\Users\Test\AppData\Local\CrashDumps 2014-05-02 14:26 - 2014-05-02 14:26 - 00000000 ____D () C:\Users\Test\AppData\Roaming\NVIDIA 2014-05-02 14:07 - 2014-05-02 15:11 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Skype 2014-05-02 14:07 - 2014-05-02 14:07 - 00000000 ____D () C:\Users\Test\AppData\Local\Skype 2014-05-01 15:15 - 2014-05-01 15:15 - 00000000 ____D () C:\Users\Test\Documents\gothic3 2014-05-01 13:49 - 2014-05-01 13:49 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Wargaming.net 2014-05-01 13:46 - 2014-05-01 13:46 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Adobe 2014-04-30 21:02 - 2014-04-30 21:02 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Wargaming.net 2014-04-29 18:45 - 2014-04-29 18:45 - 00000583 _____ () C:\Users\Public\Desktop\World of Tanks.lnk 2014-04-29 18:45 - 2014-04-29 18:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks 2014-04-26 18:25 - 2014-04-26 18:25 - 00001596 _____ () C:\Users\OEM\Desktop\Far Cry 2.lnk 2014-04-24 18:43 - 2014-04-24 18:44 - 11331489 _____ () C:\Users\OEM\Downloads\BestBeatEvaa - MRVLOG 0,5.mp4 2014-04-24 16:11 - 2014-04-24 16:11 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software 2014-04-24 16:11 - 2014-04-24 16:11 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\TuneUp Software 2014-04-22 14:47 - 2014-04-22 14:47 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Oracle 2014-04-22 13:08 - 2014-04-22 13:08 - 00004129 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log 2014-04-22 13:08 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-04-22 13:08 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-04-22 13:08 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-04-22 13:08 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-04-21 20:47 - 2014-04-21 20:47 - 02269863 _____ () C:\Users\OEM\Downloads\forge-1.6.4-9.11.1.965-installer.jar 2014-04-19 20:30 - 2014-04-19 20:30 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\StunlockStudios 2014-04-19 13:32 - 2014-04-19 20:49 - 00000000 _____ () C:\dfu.log 2014-04-18 20:59 - 2014-04-18 20:59 - 00000202 _____ () C:\Users\OEM\Desktop\Tom Clancy's Ghost Recon Phantoms - EU.url 2014-04-18 16:26 - 2014-04-18 16:26 - 00000082 _____ () C:\Windows\mafosav.INI 2014-04-18 11:53 - 2014-04-18 11:53 - 00000188 _____ () C:\Windows\SysWOW64\debug.log ==================== One Month Modified Files and Folders ======= 2014-05-16 10:17 - 2014-05-15 20:48 - 00000000 ____D () C:\Users\OEM\Desktop\FRST 2014-05-16 10:17 - 2014-05-14 19:22 - 00000000 ____D () C:\FRST 2014-05-16 10:14 - 2014-05-14 18:06 - 00002986 _____ () C:\Windows\System32\Tasks\MSIAfterburner 2014-05-16 10:14 - 2013-09-07 12:43 - 00097012 _____ () C:\Windows\setupact.log 2014-05-16 10:14 - 2012-12-31 20:45 - 00001038 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-16 10:14 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-16 10:13 - 2013-09-07 12:43 - 00715670 _____ () C:\Windows\PFRO.log 2014-05-16 10:13 - 2012-12-07 16:52 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-05-16 10:10 - 2013-08-22 16:27 - 00000000 ____D () C:\AdwCleaner 2014-05-16 10:05 - 2013-11-16 22:23 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-16 10:04 - 2014-05-16 10:04 - 00048478 _____ () C:\Users\OEM\Desktop\Preferences 2014-05-16 10:04 - 2013-03-29 17:29 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch 2014-05-16 10:04 - 2012-12-11 20:02 - 00000000 ____D () C:\Program Files (x86)\Google 2014-05-16 10:04 - 2012-12-08 11:57 - 00000000 ____D () C:\Users\OEM\AppData\Local\Google 2014-05-16 10:04 - 2012-12-07 16:47 - 00001239 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-05-16 10:04 - 2012-12-07 15:56 - 00001354 _____ () C:\Users\OEM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-16 09:58 - 2014-05-16 09:50 - 00000000 ____D () C:\Users\OEM\Desktop\ADW Cleaner 2014-05-16 09:52 - 2014-05-16 09:52 - 00000000 ____D () C:\Users\OEM\Desktop\FSS 2014-05-16 09:52 - 2014-05-16 09:50 - 00000000 ____D () C:\Users\OEM\Desktop\OTL 2014-05-16 09:52 - 2014-05-16 09:50 - 00000000 ____D () C:\Users\OEM\Desktop\GMER 2014-05-16 09:52 - 2014-05-14 17:29 - 00002076 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-05-16 09:52 - 2014-05-14 17:29 - 00002016 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk 2014-05-16 09:40 - 2012-12-31 20:45 - 00001042 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-16 01:05 - 2013-01-21 15:32 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\GG 2014-05-16 00:23 - 2013-10-20 18:55 - 00001050 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1948933813-2092389452-934283344-1000UA.job 2014-05-15 21:38 - 2013-01-17 18:02 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-15 20:50 - 2014-05-15 20:50 - 00000060 _____ () C:\Users\OEM\Desktop\artura.txt 2014-05-15 20:49 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-15 20:43 - 2014-05-14 17:28 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2014-05-15 20:43 - 2014-05-14 17:28 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2014-05-15 20:43 - 2014-05-14 17:28 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-05-15 20:43 - 2014-05-14 17:27 - 00447888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswndisflt.sys 2014-05-14 23:32 - 2013-10-11 12:17 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-05-14 20:44 - 2012-12-07 15:55 - 01813950 _____ () C:\Windows\WindowsUpdate.log 2014-05-14 20:23 - 2009-07-14 06:45 - 00016640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-14 20:23 - 2009-07-14 06:45 - 00016640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-14 19:05 - 2013-11-16 22:23 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-14 19:05 - 2012-12-07 16:27 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-14 19:05 - 2012-12-07 16:27 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-14 18:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-05-14 18:02 - 2014-05-14 17:59 - 00000000 ____D () C:\Users\Public\Desktop\CC Support 2014-05-14 17:54 - 2014-04-13 14:17 - 00000000 ____D () C:\ProgramData\MFAData 2014-05-14 17:29 - 2014-05-14 17:29 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\AVAST Software 2014-05-14 17:29 - 2014-05-14 17:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2014-05-14 17:29 - 2014-05-14 17:28 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-05-14 17:27 - 2014-05-14 17:28 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1400179427943 2014-05-14 17:27 - 2014-05-14 17:28 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1400179427943 2014-05-14 17:27 - 2014-05-14 17:28 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-05-14 17:27 - 2014-05-14 17:28 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-05-14 17:27 - 2014-05-14 17:28 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2014-05-14 17:27 - 2014-05-14 17:27 - 00447888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswndisflt.sys.1400179427943 2014-05-14 17:27 - 2014-05-14 17:27 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-05-14 17:27 - 2014-05-14 17:27 - 00000000 ____D () C:\Program Files\AVAST Software 2014-05-14 17:26 - 2014-05-14 17:26 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-05-12 21:59 - 2011-02-04 19:20 - 00743042 _____ () C:\Windows\system32\perfh015.dat 2014-05-12 21:59 - 2011-02-04 19:20 - 00156524 _____ () C:\Windows\system32\perfc015.dat 2014-05-12 21:59 - 2009-07-14 07:13 - 01676610 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-12 21:55 - 2012-12-07 16:49 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Skype 2014-05-12 19:58 - 2014-05-12 19:58 - 00081303 _____ () C:\Users\OEM\Desktop\Bez_nazwy.wma 2014-05-12 16:50 - 2014-05-02 20:57 - 00054156 ____H () C:\Windows\QTFont.qfn 2014-05-12 15:09 - 2014-01-10 20:20 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Hamachi 2014-05-12 15:00 - 2014-04-05 21:52 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\.minecraft 2014-05-12 14:23 - 2013-10-20 18:55 - 00000998 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1948933813-2092389452-934283344-1000Core.job 2014-05-12 14:18 - 2012-12-07 16:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-11 12:23 - 2009-07-14 06:45 - 05066200 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-05-10 22:05 - 2014-05-10 22:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-10 21:22 - 2012-12-29 20:07 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Audacity 2014-05-10 20:31 - 2012-12-31 20:45 - 00004038 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-10 20:31 - 2012-12-31 20:45 - 00003786 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-10 14:41 - 2012-12-30 16:06 - 00000000 ____D () C:\Users\OEM\Documents\Camtasia Studio 2014-05-10 14:18 - 2013-10-20 18:55 - 00004020 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1948933813-2092389452-934283344-1000UA 2014-05-10 14:18 - 2013-10-20 18:55 - 00003624 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1948933813-2092389452-934283344-1000Core 2014-05-10 00:19 - 2014-05-10 00:19 - 00000000 ____D () C:\Users\OEM\Desktop\fote 2014-05-09 18:39 - 2014-05-09 18:39 - 00000000 ____D () C:\ProgramData\PopCap Games 2014-05-09 18:36 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-05-09 18:35 - 2013-10-03 22:38 - 00158236 _____ () C:\Windows\DirectX.log 2014-05-08 20:23 - 2009-07-14 07:08 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-05-06 15:51 - 2014-05-06 15:51 - 00000588 _____ () C:\Users\Public\Desktop\LauncherHERO.lnk 2014-05-06 15:51 - 2014-02-22 22:19 - 00000000 ____D () C:\Users\OEM\Desktop\Potrzebne 2014-05-05 21:42 - 2013-12-03 18:09 - 00000000 ____D () C:\Users\OEM\Documents\gothic3 2014-05-04 21:16 - 2013-01-02 18:52 - 00000000 ____D () C:\Users\OEM\AppData\Local\CrashDumps 2014-05-04 15:34 - 2013-02-01 21:39 - 00000000 ____D () C:\Users\OEM\Documents\Euro Truck Simulator 2 2014-05-04 15:25 - 2014-05-04 15:25 - 00000857 _____ () C:\Users\Public\Desktop\Play Euro Truck Simulator 2 Multiplayer.lnk 2014-05-04 15:25 - 2014-05-04 15:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Euro Truck Simulator 2 Multiplayer 2014-05-02 23:27 - 2013-11-26 16:39 - 00000000 ____D () C:\Users\OEM\Desktop\Skuter 2014-05-02 22:02 - 2014-05-02 22:02 - 00001143 _____ () C:\Users\OEM\Desktop\GG.lnk 2014-05-02 20:57 - 2014-05-02 20:57 - 00001409 _____ () C:\Windows\QTFont.for 2014-05-02 15:11 - 2014-05-02 14:07 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Skype 2014-05-02 14:55 - 2014-05-02 14:53 - 00000000 ____D () C:\Users\Test\Documents\GTA San Andreas User Files 2014-05-02 14:55 - 2014-04-10 17:11 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-05-02 14:27 - 2014-05-02 14:27 - 00000000 ____D () C:\Users\Test\AppData\Local\CrashDumps 2014-05-02 14:26 - 2014-05-02 14:26 - 00000000 ____D () C:\Users\Test\AppData\Roaming\NVIDIA 2014-05-02 14:07 - 2014-05-02 14:07 - 00000000 ____D () C:\Users\Test\AppData\Local\Skype 2014-05-01 21:56 - 2013-07-17 15:40 - 00000000 ____D () C:\ProgramData\Origin 2014-05-01 21:22 - 2013-07-24 15:32 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-05-01 21:22 - 2013-02-05 17:45 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-05-01 21:22 - 2013-02-05 17:45 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-05-01 16:17 - 2012-12-07 15:58 - 00125192 _____ () C:\Users\OEM\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-01 15:36 - 2012-12-08 12:04 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-05-01 15:15 - 2014-05-01 15:15 - 00000000 ____D () C:\Users\Test\Documents\gothic3 2014-05-01 13:49 - 2014-05-01 13:49 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Wargaming.net 2014-05-01 13:46 - 2014-05-01 13:46 - 00000000 ____D () C:\Users\Test\AppData\Roaming\Adobe 2014-04-30 21:10 - 2012-12-13 17:38 - 00000069 _____ () C:\Windows\NeroDigital.ini 2014-04-30 21:02 - 2014-04-30 21:02 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Wargaming.net 2014-04-29 18:45 - 2014-04-29 18:45 - 00000583 _____ () C:\Users\Public\Desktop\World of Tanks.lnk 2014-04-29 18:45 - 2014-04-29 18:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks 2014-04-29 18:45 - 2012-12-13 21:56 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-04-27 23:15 - 2014-02-13 00:26 - 00000000 ____D () C:\Program Files (x86)\SAMSUNG 2014-04-27 23:15 - 2012-12-15 14:15 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Samsung 2014-04-27 23:15 - 2012-12-15 14:15 - 00000000 ____D () C:\Users\OEM\AppData\Local\Samsung 2014-04-27 23:15 - 2012-12-15 14:13 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-27 23:15 - 2012-12-15 14:11 - 00000000 ____D () C:\ProgramData\Samsung 2014-04-27 20:22 - 2013-01-21 15:32 - 00000000 ____D () C:\Users\OEM\AppData\Local\GG 2014-04-26 21:18 - 2013-12-26 20:10 - 00000000 ____D () C:\Users\OEM\Desktop\Foldery ;P 2014-04-26 19:39 - 2013-01-23 00:13 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\TS3Client 2014-04-26 18:25 - 2014-04-26 18:25 - 00001596 _____ () C:\Users\OEM\Desktop\Far Cry 2.lnk 2014-04-26 18:23 - 2013-12-20 20:44 - 00000000 ____D () C:\Users\OEM\AppData\Local\Ubisoft Game Launcher 2014-04-25 18:35 - 2014-03-12 18:42 - 00000000 ____D () C:\ProgramData\Ubisoft 2014-04-24 18:44 - 2014-04-24 18:43 - 11331489 _____ () C:\Users\OEM\Downloads\BestBeatEvaa - MRVLOG 0,5.mp4 2014-04-24 18:25 - 2014-01-10 19:40 - 00029696 ___SH () C:\Users\OEM\Documents\Thumbs.db 2014-04-24 18:25 - 2013-12-28 16:53 - 00001312 _____ () C:\Users\OEM\Documents\Default.sfvidcap 2014-04-24 16:11 - 2014-04-24 16:11 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software 2014-04-24 16:11 - 2014-04-24 16:11 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\TuneUp Software 2014-04-22 14:47 - 2014-04-22 14:47 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Oracle 2014-04-22 13:08 - 2014-04-22 13:08 - 00004129 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log 2014-04-22 13:08 - 2013-10-20 16:44 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-22 13:08 - 2013-06-24 13:07 - 00000000 ____D () C:\Program Files (x86)\Java 2014-04-21 20:47 - 2014-04-21 20:47 - 02269863 _____ () C:\Users\OEM\Downloads\forge-1.6.4-9.11.1.965-installer.jar 2014-04-19 21:45 - 2013-01-21 15:35 - 00000000 ___SD () C:\Users\OEM\GG dysk 2014-04-19 20:49 - 2014-04-19 13:32 - 00000000 _____ () C:\dfu.log 2014-04-19 20:30 - 2014-04-19 20:30 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\StunlockStudios 2014-04-18 22:11 - 2013-02-05 17:45 - 00000000 ____D () C:\Users\OEM\AppData\Local\PunkBuster 2014-04-18 22:09 - 2013-02-05 17:45 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2014-04-18 22:08 - 2014-03-21 20:26 - 00000000 ____D () C:\Users\OEM\AppData\Local\Ubisoft 2014-04-18 20:59 - 2014-04-18 20:59 - 00000202 _____ () C:\Users\OEM\Desktop\Tom Clancy's Ghost Recon Phantoms - EU.url 2014-04-18 20:59 - 2013-01-27 19:49 - 00000000 ____D () C:\Users\OEM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-04-18 16:35 - 2014-05-15 20:49 - 00000426 _____ () C:\AVScanner.ini 2014-04-18 16:26 - 2014-04-18 16:26 - 00000082 _____ () C:\Windows\mafosav.INI 2014-04-18 12:44 - 2014-02-07 18:10 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-04-18 11:53 - 2014-04-18 11:53 - 00000188 _____ () C:\Windows\SysWOW64\debug.log 2014-04-18 01:42 - 2014-04-12 13:38 - 00000000 ____D () C:\Program Files (x86)\DSPRobotics Files to move or delete: ==================== C:\ProgramData\PKP_DLdu.DAT C:\ProgramData\PKP_DLdw.DAT Some content of TEMP: ==================== C:\Users\OEM\AppData\Local\Temp\078c2a5c7a21a90fc18bbf3905578d53.dll C:\Users\OEM\AppData\Local\Temp\7543b95efef9fa525e17def67e5b46d1.dll C:\Users\OEM\AppData\Local\Temp\AutoRun.exe C:\Users\OEM\AppData\Local\Temp\AutoRunGUI.dll C:\Users\OEM\AppData\Local\Temp\Fraps 3.5.5[A4].exe C:\Users\OEM\AppData\Local\Temp\gface_swap.exe C:\Users\OEM\AppData\Local\Temp\ggdrive-menu.exe C:\Users\OEM\AppData\Local\Temp\ggdrive-overlay.exe C:\Users\OEM\AppData\Local\Temp\GLF4275.tmp.dll C:\Users\OEM\AppData\Local\Temp\guninst.exe C:\Users\OEM\AppData\Local\Temp\hgcpl.exe C:\Users\OEM\AppData\Local\Temp\Ins1104.tmp.exe C:\Users\OEM\AppData\Local\Temp\installstats.exe C:\Users\OEM\AppData\Local\Temp\jansi-32-git-MCPC-Plus-jenkins-MCPC-Plus-35.dll C:\Users\OEM\AppData\Local\Temp\jansi-32-git-MCPC-Plus-jenkins-MCPC-Plus-37.dll C:\Users\OEM\AppData\Local\Temp\jansi-64-git-MCPC-Plus-jenkins-MCPC-Plus-32.dll C:\Users\OEM\AppData\Local\Temp\jansi-64-git-MCPC-Plus-jenkins-MCPC-Plus-37.dll C:\Users\OEM\AppData\Local\Temp\JDownloaderSetup_20140328132404912.exe C:\Users\OEM\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\OEM\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\OEM\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\OEM\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\OEM\AppData\Local\Temp\nvSCPAPI.dll C:\Users\OEM\AppData\Local\Temp\nvStereoApiI.dll C:\Users\OEM\AppData\Local\Temp\nvStInst.exe C:\Users\OEM\AppData\Local\Temp\Onlive_Updater_1385755801.exe C:\Users\OEM\AppData\Local\Temp\PrerequistesRemovalTool.exe C:\Users\OEM\AppData\Local\Temp\Quarantine.exe C:\Users\OEM\AppData\Local\Temp\setupFlowStoneFL.exe C:\Users\OEM\AppData\Local\Temp\SetupUtil.exe C:\Users\OEM\AppData\Local\Temp\SkypeSetup.exe C:\Users\OEM\AppData\Local\Temp\sonarinst.exe C:\Users\OEM\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll C:\Users\OEM\AppData\Local\Temp\Tsu96B52728.dll C:\Users\OEM\AppData\Local\Temp\uninstall.0d87.exe C:\Users\OEM\AppData\Local\Temp\_is76E5.exe C:\Users\OEM\AppData\Local\Temp\_is88CE.exe C:\Users\OEM\AppData\Local\Temp\_is8AF2.exe C:\Users\OEM\AppData\Local\Temp\_isDC0C.exe C:\Users\OEM\AppData\Local\Temp\_isF64B.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-10 17:09 ==================== End Of Log ============================