Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-06-2014 02 Ran by DM (administrator) on DM-PC on 14-06-2014 17:43:04 Running from C:\Users\DM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZC9P93DS Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe () C:\Windows\SysWOW64\ASGT.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe (Wacom Technology, Corp.) C:\Windows\System32\Pen_Tablet.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\main.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (BitTorrent Inc.) C:\Users\DM\AppData\Roaming\BitTorrent\BitTorrent.exe (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1064224 2013-11-08] (NVIDIA Corporation) HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation) HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1743088 2014-05-22] (Bitdefender) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-04-23] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585048 2014-05-31] (Razer Inc.) HKU\.DEFAULT\...\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2014-05-22] (Bitdefender) HKU\.DEFAULT\...\Run: [Bitdefender Wallet] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-05-22] (Bitdefender) HKU\.DEFAULT\...\Run: [Bitdefender Wallet Application Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614744 2014-05-22] (Bitdefender) HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [301568 2013-08-29] (Microsoft Corporation) HKU\S-1-5-21-1818139271-3789548429-1232871354-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673696 2013-08-01] (Disc Soft Ltd) HKU\S-1-5-21-1818139271-3789548429-1232871354-1000\...\Run: [Bitdefender Wallet Application Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614744 2014-05-22] (Bitdefender) HKU\S-1-5-21-1818139271-3789548429-1232871354-1000\...\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2014-05-22] (Bitdefender) HKU\S-1-5-21-1818139271-3789548429-1232871354-1000\...\Run: [Bitdefender Wallet] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-05-22] (Bitdefender) HKU\S-1-5-21-1818139271-3789548429-1232871354-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-1818139271-3789548429-1232871354-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-1818139271-3789548429-1232871354-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1818139271-3789548429-1232871354-1000\...\MountPoints2: D - D:\SETUP.EXE HKU\S-1-5-21-1818139271-3789548429-1232871354-1000\...\MountPoints2: G - G:\Startme.exe HKU\S-1-5-21-1818139271-3789548429-1232871354-1000\...\MountPoints2: {3803ecca-13e3-11e3-8731-bc5ff472d03a} - G:\RZRSETUP.EXE HKU\S-1-5-21-1818139271-3789548429-1232871354-1000\...\MountPoints2: {f9664610-260f-11e3-9dc7-bc5ff472d03a} - G:\Startme.exe HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673696 2013-08-01] (Disc Soft Ltd) HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2014-05-22] (Bitdefender) HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\Run: [Bitdefender Wallet] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-05-22] (Bitdefender) HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\Run: [Bitdefender Wallet Application Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614744 2014-05-22] (Bitdefender) HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1561968 2013-04-23] (Samsung) HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\Run: [] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844144 2013-04-23] (Samsung) HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\MountPoints2: D - D:\SETUP.EXE HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\MountPoints2: G - G:\Startme.exe HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\MountPoints2: {3803ecca-13e3-11e3-8731-bc5ff472d03a} - G:\RZRSETUP.EXE HKU\S-1-5-21-1818139271-3789548429-1232871354-1068\...\MountPoints2: {f9664610-260f-11e3-9dc7-bc5ff472d03a} - G:\Startme.exe Startup: C:\Users\DM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {FF34E546-0A8B-4F9F-9908-923CEA78A438} URL = https://www.google.com/search?q={searchTerms} BHO: Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll (Bitdefender) BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll (Bitdefender) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks-x32: - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No File [ ] Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 62.179.1.61 62.179.1.63 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @wacom.com/wtPlugin,version=2.1.0.3 - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll (Adobe Systems, Inc.) FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.3 - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @nsroblox.roblox.com/launcher - C:\Program Files (x86)\Roblox\Versions\version-afc74353f06542bd\\NPRobloxProxy.dll ( ROBLOX Corporation) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\DM\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2014-02-04] FF HKLM-x32\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\ FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\ [] FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2014-02-04] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR Extension: (Magic Actions for YouTube™) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2014-05-18] CHR Extension: (From Dust) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\anelkojiepicmcldgnmkplocifmegpfj [2014-05-18] CHR Extension: (Dokumenty Google) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-21] CHR Extension: (Dysk Google) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-21] CHR Extension: (YouTube) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-21] CHR Extension: (Bitdefender Wallet) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccahoghmggldkcdjiebjkidpfongdfbl [2014-02-21] CHR Extension: (Szukaj w Google) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-21] CHR Extension: (AdBlock Premium) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\fndlhnanhedoklpdaacidomdnplcjcpj [2014-05-18] CHR Extension: (Youtube MP3 Converter) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\hglljpndoeopcpehilglkbnincooinnb [2014-05-18] CHR Extension: (tviggr) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmolgbmkhjnoekekdogckilbbedhdnoh [2014-05-18] CHR Extension: (Social Fixer for Facebook) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb [2014-05-18] CHR Extension: (Google Wallet) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-21] CHR Extension: (Gmail) - C:\Users\DM\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-21] CHR HKLM-x32\...\Chrome\Extension: [ccahoghmggldkcdjiebjkidpfongdfbl] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxcr.crx [2014-03-27] CHR HKLM-x32\...\Chrome\Extension: [hglljpndoeopcpehilglkbnincooinnb] - C:\Users\DM\AppData\Local\Flvto Plugin for Google Chrome\the_extension.crx [2013-08-30] ==================== Services (Whitelisted) ================= R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [File not signed] S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender\bdparentalservice.exe [77632 2013-11-21] (Bitdefender) S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2013-12-04] (Macrovision Europe Ltd.) [File not signed] R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] () S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] () R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-06-01] () R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [105448 2014-02-25] (Razer Inc.) R2 SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [94624 2013-07-08] (Bitdefender) R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [67320 2013-10-07] (Bitdefender) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-06-14] (VIA Technologies, Inc.) R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1526800 2014-05-22] (Bitdefender) R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [627992 2014-01-13] (Wacom Technology, Corp.) ==================== Drivers (Whitelisted) ==================== R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [893440 2013-12-02] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender) R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [635392 2013-12-02] (BitDefender) R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2014-05-22] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC) S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL) S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL) R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [76944 2012-04-17] (BitDefender) R3 dtscsibus; C:\Windows\System32\DRIVERS\dtscsibus.sys [29696 2013-09-02] (Disc Soft Ltd) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-08-30] (Disc Soft Ltd) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2012-06-22] () R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC) S3 h647906; C:\Windows\System32\drivers\h647906.sys [63856 2008-08-08] (Your Corporation) S3 h648101; C:\Windows\System32\drivers\h648101.sys [65776 2008-08-08] (Your Corporation) S3 h648103; C:\Windows\System32\drivers\h648103.sys [62960 2008-08-08] (Your Corporation) S3 hid7906; C:\Windows\SysWOW64\drivers\hid7906.sys [41272 2008-08-08] (Your Corporation) S3 hid8101; C:\Windows\SysWOW64\drivers\hid8101.sys [43192 2008-08-08] (Your Corporation) S3 hid8103; C:\Windows\SysWOW64\drivers\hid8103.sys [40856 2008-08-08] (Your Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [67152 2013-03-12] (Fuzhou Rockchip Electronics Co,Ltd.) S3 RZMAELSTROMVADService; C:\Windows\System32\drivers\RzMaelstromVAD.sys [32768 2014-05-23] (Windows (R) Win 7 DDK provider) R3 rzp1endpt; C:\Windows\System32\DRIVERS\rzp1endpt.sys [39080 2014-05-19] (Razer Inc) R3 rzvmouse; C:\Windows\System32\DRIVERS\rzvmouse.sys [31400 2014-05-19] (Razer Inc) S3 s1039bus; C:\Windows\System32\DRIVERS\s1039bus.sys [127600 2009-11-19] (MCCI Corporation) S3 s1039mdfl; C:\Windows\System32\DRIVERS\s1039mdfl.sys [19568 2009-11-19] (MCCI Corporation) S3 s1039mdm; C:\Windows\System32\DRIVERS\s1039mdm.sys [161904 2009-11-19] (MCCI Corporation) S3 s1039mgmt; C:\Windows\System32\DRIVERS\s1039mgmt.sys [141424 2009-11-19] (MCCI Corporation) S3 s1039nd5; C:\Windows\System32\DRIVERS\s1039nd5.sys [34416 2009-11-19] (MCCI Corporation) S3 s1039obex; C:\Windows\System32\DRIVERS\s1039obex.sys [137328 2009-11-19] (MCCI Corporation) S3 s1039unic; C:\Windows\System32\DRIVERS\s1039unic.sys [158320 2009-11-19] (MCCI Corporation) R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-08-07] (BitDefender S.R.L.) S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] S3 wacommousefilter; system32\DRIVERS\wacommousefilter.sys [X] S3 wacomvhid; system32\DRIVERS\wacomvhid.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-14 17:24 - 2014-06-14 17:43 - 00000000 ____D () C:\FRST 2014-06-14 17:15 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-14 17:15 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-14 02:12 - 2014-06-14 02:12 - 00000000 ____D () C:\ProgramData\bdch 2014-06-14 02:11 - 2014-06-14 02:11 - 00000000 ____D () C:\TDSSKiller_Quarantine 2014-06-14 01:18 - 2014-06-14 02:19 - 00000000 ____D () C:\Users\DM\AppData\Local\Adobe 2014-06-13 14:15 - 2014-06-14 02:16 - 00001439 _____ () C:\Windows\setupact.log 2014-06-13 14:15 - 2014-06-13 14:15 - 00000000 _____ () C:\Windows\setuperr.log 2014-06-12 21:24 - 2014-06-12 21:24 - 01333465 _____ () C:\Users\DM\Downloads\AdwCleaner.exe 2014-06-12 21:06 - 2014-06-12 21:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-06-12 21:05 - 2014-06-12 21:05 - 00918672 _____ (Google Inc.) C:\Users\DM\Downloads\ChromeSetup.exe 2014-06-11 21:41 - 2014-06-11 21:41 - 00000220 _____ () C:\Users\DM\Desktop\Sid Meier's Civilization V.url 2014-06-11 00:39 - 2014-06-11 00:39 - 00000000 ____D () C:\Users\DM\Downloads\Inception (2010) [1080p] 2014-06-09 04:13 - 2014-06-09 04:20 - 576666864 _____ () C:\Users\DM\Downloads\Top.Gear.15x04.HDTV.XviD-FoV.avi 2014-06-09 04:12 - 2014-06-09 04:12 - 00022540 _____ () C:\Users\DM\Downloads\[kickass.to]top.gear.15x04.hdtv.xvid.fov.eztv.torrent 2014-06-08 18:09 - 2013-03-12 04:05 - 00067152 _____ (Fuzhou Rockchip Electronics Co,Ltd.) C:\Windows\system32\Drivers\rockusb.sys 2014-06-08 17:54 - 2014-06-08 17:56 - 304178262 _____ () C:\Users\DM\Downloads\GCR83.2_GCR83.3_121114 (1).zip 2014-06-06 02:53 - 2014-06-06 02:53 - 00001805 _____ () C:\Users\DM\Desktop\SpaceEngineers.exe — skrót.lnk 2014-06-06 02:31 - 2014-06-06 02:32 - 132386757 _____ () C:\Users\DM\Downloads\SpaceEngineers_v01.031.012_to_v01.032.018 (1).7z 2014-06-06 02:25 - 2014-06-06 02:26 - 132386757 _____ () C:\Users\DM\Downloads\SpaceEngineers_v01.031.012_to_v01.032.018.7z 2014-06-06 02:23 - 2014-05-25 12:21 - 00000056 _____ () C:\Program Files (x86)\Read me!.txt 2014-06-06 02:23 - 2014-05-25 12:13 - 00000000 ____D () C:\Program Files (x86)\Keen Software House 2014-06-06 02:20 - 2014-06-06 02:22 - 586694452 _____ () C:\Users\DM\Downloads\SpaceEngineers 01.031.012.rar 2014-06-06 02:03 - 2014-06-06 02:03 - 00375351 _____ () C:\Users\DM\Downloads\Space.Engineers.Steamworks.Fix-RVTFiX (2).rar 2014-06-06 01:55 - 2014-06-06 01:55 - 135164724 _____ () C:\Users\DM\Downloads\SpaceEngineers_v01.031.009_to_v01.033.007.7z 2014-06-06 01:47 - 2014-06-06 01:48 - 82577517 _____ () C:\Users\DM\Downloads\SpaceEngineers_v01.031.009.004 2014-06-06 01:47 - 2014-06-06 01:47 - 104857600 _____ () C:\Users\DM\Downloads\SpaceEngineers_v01.031.009.003 2014-06-06 01:44 - 2014-06-06 01:44 - 104857600 _____ () C:\Users\DM\Downloads\SpaceEngineers_v01.031.009.002 2014-06-06 01:37 - 2014-06-06 01:37 - 00375351 _____ () C:\Users\DM\Downloads\Space.Engineers.Steamworks.Fix-RVTFiX (1).rar 2014-06-06 01:12 - 2014-06-06 01:12 - 00375351 _____ () C:\Users\DM\Downloads\Space.Engineers.Steamworks.Fix-RVTFiX.rar 2014-06-06 00:50 - 2014-06-06 00:50 - 00011306 _____ () C:\Users\DM\Downloads\[kickass.to]space.engineers.v01.023.013.x32.x64.w.online.crack.torrent 2014-06-05 18:24 - 2014-06-05 18:24 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-06-05 18:10 - 2013-06-21 14:06 - 27781920 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 21102368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 15144928 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 13411896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 11235104 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-06-05 18:10 - 2013-06-21 14:06 - 09239344 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 07687592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 07641832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 06324360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 02953504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 02777888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 02363680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 02002720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 01832224 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432049.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432049.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 00925648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 00572704 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 00570656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 00467232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 00465184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 00432928 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 00372000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 00266448 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 00218592 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 00214448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-06-05 18:10 - 2013-06-21 14:06 - 00181488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-06-05 18:10 - 2013-02-25 07:27 - 00194848 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-06-05 18:10 - 2013-02-25 07:27 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-06-05 18:07 - 2014-06-05 18:07 - 185568600 _____ (NVIDIA Corporation) C:\Users\DM\Downloads\320.49-desktop-win8-win7-winvista-64bit-english-whql.exe 2014-06-05 16:10 - 2014-06-14 16:57 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-05 16:10 - 2014-06-14 01:08 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-05 16:10 - 2014-06-14 01:08 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-05 16:10 - 2014-06-14 01:08 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-05 15:37 - 2014-06-05 15:38 - 00848048 _____ (Adobe Systems Incorporated) C:\Users\DM\Downloads\uninstall_flash_player.exe 2014-06-05 02:50 - 2014-06-12 21:48 - 00000000 ____D () C:\Windows\Minidump 2014-06-04 22:31 - 2014-06-04 22:31 - 00003848 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1377680623 2014-06-04 14:55 - 2014-06-14 17:22 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-04 09:54 - 2014-05-08 09:14 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-04 09:54 - 2014-05-08 08:37 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-04 09:54 - 2014-05-08 07:52 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-04 09:54 - 2014-05-08 07:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-04 09:54 - 2014-05-08 06:57 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-04 09:54 - 2014-05-08 06:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-03 23:03 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-06-03 23:03 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-06-03 23:01 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-06-03 23:01 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-06-03 23:01 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-06-03 23:01 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-06-03 23:01 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-06-03 23:01 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-06-03 23:01 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-06-03 23:01 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-06-03 23:01 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-06-03 23:01 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-06-03 23:01 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-06-03 23:01 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-06-03 23:01 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-06-03 23:01 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-06-03 23:01 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-06-03 23:01 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-06-03 23:01 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-06-03 23:01 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-06-03 23:01 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-06-03 23:01 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-06-03 23:01 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-06-03 23:01 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-06-03 23:01 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-06-03 23:01 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-06-03 23:01 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-06-03 23:01 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-06-03 23:01 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-06-03 23:01 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-06-03 23:01 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-06-03 23:01 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-06-03 23:01 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-06-03 23:01 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-06-03 23:01 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-06-03 23:01 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-06-03 23:01 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-06-03 23:01 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-06-03 23:01 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-06-03 23:01 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-06-03 23:01 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-06-03 23:01 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-06-03 23:01 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-06-03 21:14 - 2014-06-03 21:14 - 06209163 _____ () C:\Users\DM\Downloads\GCR83-2-3_CWM.zip 2014-06-03 16:41 - 2014-06-03 16:41 - 00000000 ____D () C:\ProgramData\RzMaelstromVAD_1.1.58.1854 2014-06-03 16:39 - 2014-06-03 16:39 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_rzudd_01009.Wdf 2014-06-03 16:38 - 2014-06-03 16:38 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_rzp1endpt_01009.Wdf 2014-06-03 16:34 - 2014-06-03 16:34 - 01725304 _____ (Razer Inc.) C:\Users\DM\Downloads\RazerSurroundInstaller_v2.00.10.exe 2014-06-01 23:14 - 2014-06-01 23:14 - 00000000 ____D () C:\Users\DM\Documents\Battlefield 3 2014-06-01 22:59 - 2014-06-01 22:59 - 02247960 _____ () C:\Users\DM\Downloads\battlelog-web-plugins_2.4.0_141.exe 2014-06-01 22:59 - 2014-06-01 22:59 - 00000000 ____D () C:\Users\DM\AppData\Local\ESN 2014-06-01 22:59 - 2014-06-01 22:59 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-06-01 21:51 - 2014-06-01 21:51 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk 2014-06-01 02:23 - 2014-06-01 02:23 - 00357728 _____ (Softonic) C:\Users\DM\Downloads\SoftonicDownloader_dla_windows-media-player-plugin.exe 2014-05-31 23:11 - 2014-06-14 01:04 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Tropico 5 2014-05-31 23:11 - 2014-05-31 23:11 - 00000978 _____ () C:\Users\DM\Desktop\Tropico 5.lnk 2014-05-31 23:11 - 2014-05-31 23:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tropico 5 2014-05-31 23:05 - 2014-05-31 23:07 - 00000000 ____D () C:\Program Files (x86)\Tropico 5 2014-05-30 14:51 - 2014-05-30 14:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-05-30 14:51 - 2014-05-07 15:02 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-05-30 14:51 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-05-30 14:51 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-05-30 14:51 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-05-30 14:50 - 2014-05-30 14:51 - 00004030 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log 2014-05-29 19:21 - 2014-05-29 19:21 - 00000000 ____D () C:\ProgramData\Orbit 2014-05-29 19:20 - 2014-05-29 19:20 - 00001262 _____ () C:\Users\DM\Desktop\Watch Dogs.lnk 2014-05-29 19:20 - 2014-05-29 19:20 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Watch Dogs 2014-05-29 19:20 - 2014-05-29 19:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics 2014-05-29 18:35 - 2014-05-29 18:35 - 00000000 ____D () C:\Program Files (x86)\R.G. Mechanics 2014-05-29 16:02 - 2014-05-29 16:02 - 00000000 ____D () C:\Users\DM\Downloads\Bitdefender Total Security 2014 x32 & x64 2014-05-29 07:32 - 2014-05-29 07:32 - 00080384 _____ (Razer Inc) C:\Windows\system32\RazerCoinstaller.dll 2014-05-26 04:08 - 2014-05-26 04:08 - 00011025 _____ () C:\Users\DM\Downloads\hijackthis.log 2014-05-26 04:07 - 2014-05-26 04:07 - 00388608 _____ (Trend Micro Inc.) C:\Users\DM\Downloads\HijackThis_2.0.4.exe 2014-05-26 04:06 - 2014-05-26 04:07 - 00707056 _____ () C:\Users\DM\Downloads\HijackThis(12030).exe 2014-05-26 01:32 - 2014-05-26 01:33 - 50290934 _____ () C:\Users\DM\Downloads\nsfw_ponies_v2_1_by_rubez2525-d78i41p (1).zip 2014-05-26 00:45 - 2014-05-26 00:46 - 50290934 _____ () C:\Users\DM\Downloads\nsfw_ponies_v2_1_by_rubez2525-d78i41p.zip 2014-05-26 00:40 - 2014-05-26 00:41 - 03520592 _____ () C:\Users\DM\Downloads\2_1_source_files_by_rubez2525-d78i7cx.zip 2014-05-25 15:33 - 2014-05-25 15:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Swiff Player 2014-05-25 15:33 - 2014-05-25 15:33 - 00000000 ____D () C:\Program Files (x86)\GlobFX 2014-05-25 15:24 - 2014-05-25 15:24 - 04494354 _____ (GlobFX Technologies ) C:\Users\DM\Downloads\SwiffPlayerSetup172.exe 2014-05-24 22:03 - 2014-05-24 22:07 - 00000000 ____D () C:\Users\DM\AppData\Local\Microsoft Games 2014-05-24 04:33 - 2014-05-24 04:33 - 00864256 _____ (Razer Inc) C:\Windows\SysWOW64\rzdevicedll.dll 2014-05-24 04:33 - 2014-05-24 04:33 - 00325120 _____ (Razer Inc) C:\Windows\SysWOW64\rzaudiodll.dll 2014-05-23 13:02 - 2014-05-23 13:02 - 00136704 _____ (Razer Inc.) C:\Windows\SysWOW64\RzVAD.dll 2014-05-23 12:34 - 2014-05-23 12:34 - 00032768 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\RzMaelstromVAD.sys 2014-05-23 12:31 - 2014-05-23 12:31 - 00245760 _____ (A-Volute) C:\Windows\system32\DriverInstallCACMD.exe 2014-05-23 12:31 - 2014-05-23 12:31 - 00069632 _____ (A-Volute) C:\Windows\system32\DriverInstallCA.dll 2014-05-20 15:56 - 2014-05-20 15:56 - 00001088 _____ () C:\Users\DM\Desktop\steam.txt.lnk 2014-05-19 08:47 - 2014-05-19 08:47 - 00155816 _____ (Razer Inc) C:\Windows\system32\Drivers\rzudd.sys 2014-05-19 08:47 - 2014-05-19 08:47 - 00039080 _____ (Razer Inc) C:\Windows\system32\Drivers\rzp1endpt.sys 2014-05-19 08:47 - 2014-05-19 08:47 - 00031400 _____ (Razer Inc) C:\Windows\system32\Drivers\rzvmouse.sys 2014-05-19 08:26 - 2014-05-19 08:26 - 00155136 _____ (Razer Inc) C:\Windows\SysWOW64\rztouchdll.dll 2014-05-19 08:26 - 2014-05-19 08:26 - 00117248 _____ (Razer Inc) C:\Windows\SysWOW64\rzdisplaydll.dll 2014-05-19 08:26 - 2014-05-19 08:26 - 00089088 _____ (Razer Inc) C:\Windows\SysWOW64\rzdevinfo.dll 2014-05-19 05:35 - 2014-05-19 05:36 - 00000000 _____ () C:\Windows\SysWOW64\Access.dat 2014-05-19 05:29 - 2014-05-19 05:29 - 00000000 ____D () C:\Users\DM\Documents\Tunngle 2014-05-17 15:40 - 2014-05-17 15:57 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Apple Computer 2014-05-17 15:38 - 2014-05-17 15:57 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-05-17 15:38 - 2014-05-17 15:53 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-05-17 15:37 - 2014-05-17 15:37 - 00000000 ____D () C:\Users\DM\AppData\Local\Apple 2014-05-17 15:37 - 2014-05-17 15:37 - 00000000 ____D () C:\ProgramData\Apple 2014-05-16 21:42 - 2014-06-05 16:10 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Macromedia 2014-05-16 18:43 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-16 15:02 - 2014-05-16 15:02 - 00000000 ____D () C:\ProgramData\Mozilla ==================== One Month Modified Files and Folders ======= 2014-06-14 17:45 - 2013-11-13 00:04 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-14 17:45 - 2013-08-28 14:03 - 00000000 ____D () C:\Users\DM\AppData\Local\Temp 2014-06-14 17:44 - 2013-08-28 14:03 - 01536459 _____ () C:\Windows\WindowsUpdate.log 2014-06-14 17:43 - 2014-06-14 17:24 - 00000000 ____D () C:\FRST 2014-06-14 17:43 - 2013-08-28 13:02 - 00000000 ____D () C:\Users\DM\AppData\Roaming\BitTorrent 2014-06-14 17:34 - 2014-04-26 22:56 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-06-14 17:29 - 2009-07-14 06:45 - 00025408 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-14 17:29 - 2009-07-14 06:45 - 00025408 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-14 17:22 - 2014-06-04 14:55 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-14 16:57 - 2014-06-05 16:10 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-14 16:52 - 2013-08-27 23:18 - 00001040 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-14 02:52 - 2013-08-27 23:18 - 00001036 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-14 02:50 - 2013-10-30 15:00 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-06-14 02:36 - 2013-09-29 12:47 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-06-14 02:36 - 2013-09-29 12:11 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-06-14 02:36 - 2013-09-29 12:11 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-06-14 02:33 - 2013-09-30 01:32 - 00000000 ____D () C:\Users\DM\AppData\Local\CrashDumps 2014-06-14 02:31 - 2014-03-28 14:52 - 00000000 ____D () C:\ProgramData\Origin 2014-06-14 02:31 - 2014-03-28 14:52 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-06-14 02:19 - 2014-06-14 01:18 - 00000000 ____D () C:\Users\DM\AppData\Local\Adobe 2014-06-14 02:16 - 2014-06-13 14:15 - 00001439 _____ () C:\Windows\setupact.log 2014-06-14 02:16 - 2013-08-27 23:31 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-06-14 02:16 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-14 02:12 - 2014-06-14 02:12 - 00000000 ____D () C:\ProgramData\bdch 2014-06-14 02:11 - 2014-06-14 02:11 - 00000000 ____D () C:\TDSSKiller_Quarantine 2014-06-14 01:28 - 2013-08-30 14:13 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Winamp 2014-06-14 01:20 - 2013-08-28 12:10 - 00743364 _____ () C:\Windows\system32\perfh015.dat 2014-06-14 01:20 - 2013-08-28 12:10 - 00156878 _____ () C:\Windows\system32\perfc015.dat 2014-06-14 01:20 - 2009-07-14 07:13 - 01678506 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-14 01:08 - 2014-06-05 16:10 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-14 01:08 - 2014-06-05 16:10 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-14 01:08 - 2014-06-05 16:10 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-14 01:06 - 2013-11-04 00:06 - 00000000 ____D () C:\Users\DM\Documents\FFOutput 2014-06-14 01:04 - 2014-05-31 23:11 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Tropico 5 2014-06-14 00:22 - 2014-01-22 10:07 - 00000000 ____D () C:\Users\DM\Desktop\Programy 2014-06-13 15:11 - 2013-08-28 13:04 - 00000000 ____D () C:\Users\DM\Desktop\Inne 2014-06-13 14:16 - 2009-07-14 06:45 - 05086560 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-06-13 14:15 - 2014-06-13 14:15 - 00000000 _____ () C:\Windows\setuperr.log 2014-06-13 02:07 - 2014-03-24 04:09 - 00000000 ____D () C:\Users\DM\AppData\Local\UpdateChecker 2014-06-13 02:01 - 2013-08-29 17:13 - 00000000 ____D () C:\Program Files (x86)\SpeedFan 2014-06-13 00:56 - 2013-10-08 16:56 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp 2014-06-12 23:42 - 2013-10-19 20:16 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Media Player Classic 2014-06-12 21:56 - 2013-10-22 18:32 - 00000000 ____D () C:\Program Files (x86)\Counter-Strike 1.6 2014-06-12 21:56 - 2013-10-15 22:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6 2014-06-12 21:48 - 2014-06-05 02:50 - 00000000 ____D () C:\Windows\Minidump 2014-06-12 21:48 - 2013-08-30 02:54 - 00000000 ____D () C:\Users\DM\AppData\Roaming\DAEMON Tools Lite 2014-06-12 21:45 - 2014-02-23 23:00 - 00000000 ____D () C:\Program Files\CCleaner 2014-06-12 21:24 - 2014-06-12 21:24 - 01333465 _____ () C:\Users\DM\Downloads\AdwCleaner.exe 2014-06-12 21:16 - 2013-08-31 04:31 - 00000000 ____D () C:\AdwCleaner 2014-06-12 21:06 - 2014-06-12 21:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-06-12 21:06 - 2013-08-27 23:18 - 00000000 ____D () C:\Program Files (x86)\Google 2014-06-12 21:05 - 2014-06-12 21:05 - 00918672 _____ (Google Inc.) C:\Users\DM\Downloads\ChromeSetup.exe 2014-06-11 21:41 - 2014-06-11 21:41 - 00000220 _____ () C:\Users\DM\Desktop\Sid Meier's Civilization V.url 2014-06-11 00:39 - 2014-06-11 00:39 - 00000000 ____D () C:\Users\DM\Downloads\Inception (2010) [1080p] 2014-06-09 22:34 - 2014-03-28 14:58 - 00000000 ____D () C:\Users\DM\AppData\Local\Origin 2014-06-09 04:20 - 2014-06-09 04:13 - 576666864 _____ () C:\Users\DM\Downloads\Top.Gear.15x04.HDTV.XviD-FoV.avi 2014-06-09 04:12 - 2014-06-09 04:12 - 00022540 _____ () C:\Users\DM\Downloads\[kickass.to]top.gear.15x04.hdtv.xvid.fov.eztv.torrent 2014-06-08 17:56 - 2014-06-08 17:54 - 304178262 _____ () C:\Users\DM\Downloads\GCR83.2_GCR83.3_121114 (1).zip 2014-06-08 11:13 - 2014-06-14 17:15 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-08 11:08 - 2014-06-14 17:15 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-06 02:53 - 2014-06-06 02:53 - 00001805 _____ () C:\Users\DM\Desktop\SpaceEngineers.exe — skrót.lnk 2014-06-06 02:32 - 2014-06-06 02:31 - 132386757 _____ () C:\Users\DM\Downloads\SpaceEngineers_v01.031.012_to_v01.032.018 (1).7z 2014-06-06 02:26 - 2014-06-06 02:25 - 132386757 _____ () C:\Users\DM\Downloads\SpaceEngineers_v01.031.012_to_v01.032.018.7z 2014-06-06 02:22 - 2014-06-06 02:20 - 586694452 _____ () C:\Users\DM\Downloads\SpaceEngineers 01.031.012.rar 2014-06-06 02:04 - 2013-12-06 00:39 - 00000000 ____D () C:\Users\DM\AppData\Roaming\SpaceEngineers 2014-06-06 02:03 - 2014-06-06 02:03 - 00375351 _____ () C:\Users\DM\Downloads\Space.Engineers.Steamworks.Fix-RVTFiX (2).rar 2014-06-06 01:55 - 2014-06-06 01:55 - 135164724 _____ () C:\Users\DM\Downloads\SpaceEngineers_v01.031.009_to_v01.033.007.7z 2014-06-06 01:48 - 2014-06-06 01:47 - 82577517 _____ () C:\Users\DM\Downloads\SpaceEngineers_v01.031.009.004 2014-06-06 01:47 - 2014-06-06 01:47 - 104857600 _____ () C:\Users\DM\Downloads\SpaceEngineers_v01.031.009.003 2014-06-06 01:44 - 2014-06-06 01:44 - 104857600 _____ () C:\Users\DM\Downloads\SpaceEngineers_v01.031.009.002 2014-06-06 01:37 - 2014-06-06 01:37 - 00375351 _____ () C:\Users\DM\Downloads\Space.Engineers.Steamworks.Fix-RVTFiX (1).rar 2014-06-06 01:15 - 2013-10-26 17:31 - 00000000 ___RD () C:\Users\DM\Dysk Google 2014-06-06 01:15 - 2013-08-28 13:04 - 00000000 ____D () C:\Users\DM\Desktop\Gry 2014-06-06 01:12 - 2014-06-06 01:12 - 00375351 _____ () C:\Users\DM\Downloads\Space.Engineers.Steamworks.Fix-RVTFiX.rar 2014-06-06 00:50 - 2014-06-06 00:50 - 00011306 _____ () C:\Users\DM\Downloads\[kickass.to]space.engineers.v01.023.013.x32.x64.w.online.crack.torrent 2014-06-05 18:24 - 2014-06-05 18:24 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-06-05 18:24 - 2013-08-28 10:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2014-06-05 18:24 - 2013-08-27 23:31 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-06-05 18:07 - 2014-06-05 18:07 - 185568600 _____ (NVIDIA Corporation) C:\Users\DM\Downloads\320.49-desktop-win8-win7-winvista-64bit-english-whql.exe 2014-06-05 16:10 - 2014-05-16 21:42 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Macromedia 2014-06-05 16:10 - 2013-08-28 11:34 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Adobe 2014-06-05 16:09 - 2013-08-28 11:32 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2014-06-05 15:38 - 2014-06-05 15:37 - 00848048 _____ (Adobe Systems Incorporated) C:\Users\DM\Downloads\uninstall_flash_player.exe 2014-06-05 03:49 - 2014-03-21 11:10 - 00000000 ____D () C:\Program Files (x86)\Razer 2014-06-04 22:31 - 2014-06-04 22:31 - 00003848 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1377680623 2014-06-04 22:31 - 2013-08-28 11:03 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-06-04 20:47 - 2013-08-28 14:09 - 00114664 _____ () C:\Users\DM\AppData\Local\GDIPFONTCACHEV1.DAT 2014-06-04 15:45 - 2013-08-28 14:03 - 00000000 ___RD () C:\Users\DM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-04 15:45 - 2013-08-28 14:03 - 00000000 ___RD () C:\Users\DM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-06-04 15:45 - 2013-08-28 14:03 - 00000000 ____D () C:\Users\DM 2014-06-04 15:45 - 2013-08-28 13:11 - 00000640 __RSH () C:\Users\DM\ntuser.pol 2014-06-04 09:44 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini 2014-06-04 09:35 - 2013-08-30 14:59 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-04 09:33 - 2013-08-30 14:59 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-06-03 21:14 - 2014-06-03 21:14 - 06209163 _____ () C:\Users\DM\Downloads\GCR83-2-3_CWM.zip 2014-06-03 16:41 - 2014-06-03 16:41 - 00000000 ____D () C:\ProgramData\RzMaelstromVAD_1.1.58.1854 2014-06-03 16:39 - 2014-06-03 16:39 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_rzudd_01009.Wdf 2014-06-03 16:38 - 2014-06-03 16:38 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_rzp1endpt_01009.Wdf 2014-06-03 16:36 - 2014-03-21 11:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer 2014-06-03 16:35 - 2014-03-21 11:16 - 00000000 ____D () C:\Users\DM\AppData\Local\Razer 2014-06-03 16:35 - 2014-03-21 11:10 - 00000000 ____D () C:\ProgramData\Razer 2014-06-03 16:34 - 2014-06-03 16:34 - 01725304 _____ (Razer Inc.) C:\Users\DM\Downloads\RazerSurroundInstaller_v2.00.10.exe 2014-06-01 23:30 - 2013-09-29 12:11 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2014-06-01 23:22 - 2014-03-28 14:58 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Origin 2014-06-01 23:14 - 2014-06-01 23:14 - 00000000 ____D () C:\Users\DM\Documents\Battlefield 3 2014-06-01 23:14 - 2013-09-29 12:46 - 00000000 ____D () C:\Users\DM\AppData\Local\PunkBuster 2014-06-01 22:59 - 2014-06-01 22:59 - 02247960 _____ () C:\Users\DM\Downloads\battlelog-web-plugins_2.4.0_141.exe 2014-06-01 22:59 - 2014-06-01 22:59 - 00000000 ____D () C:\Users\DM\AppData\Local\ESN 2014-06-01 22:59 - 2014-06-01 22:59 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-06-01 21:51 - 2014-06-01 21:51 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk 2014-06-01 21:51 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-06-01 20:57 - 2014-03-28 15:00 - 00000000 ____D () C:\Program Files (x86)\Origin Games 2014-06-01 02:23 - 2014-06-01 02:23 - 00357728 _____ (Softonic) C:\Users\DM\Downloads\SoftonicDownloader_dla_windows-media-player-plugin.exe 2014-05-31 23:11 - 2014-05-31 23:11 - 00000978 _____ () C:\Users\DM\Desktop\Tropico 5.lnk 2014-05-31 23:11 - 2014-05-31 23:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tropico 5 2014-05-31 23:07 - 2014-05-31 23:05 - 00000000 ____D () C:\Program Files (x86)\Tropico 5 2014-05-30 21:13 - 2013-08-30 03:06 - 00000000 ____D () C:\Users\DM\Documents\Euro Truck Simulator 2 2014-05-30 16:31 - 2014-03-24 04:04 - 00000000 ____D () C:\Program Files\Unlocker 2014-05-30 14:51 - 2014-05-30 14:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-05-30 14:51 - 2014-05-30 14:50 - 00004030 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log 2014-05-30 14:51 - 2013-10-19 16:39 - 00000000 ____D () C:\ProgramData\Oracle 2014-05-30 14:51 - 2013-08-27 23:24 - 00000000 ____D () C:\Program Files (x86)\Java 2014-05-30 14:05 - 2013-10-26 20:16 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-29 19:21 - 2014-05-29 19:21 - 00000000 ____D () C:\ProgramData\Orbit 2014-05-29 19:21 - 2013-10-13 20:52 - 00000000 ____D () C:\Users\DM\Documents\My Games 2014-05-29 19:20 - 2014-05-29 19:20 - 00001262 _____ () C:\Users\DM\Desktop\Watch Dogs.lnk 2014-05-29 19:20 - 2014-05-29 19:20 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Watch Dogs 2014-05-29 19:20 - 2014-05-29 19:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics 2014-05-29 18:35 - 2014-05-29 18:35 - 00000000 ____D () C:\Program Files (x86)\R.G. Mechanics 2014-05-29 16:06 - 2014-03-05 03:56 - 00000000 ____D () C:\Windows\pss 2014-05-29 16:02 - 2014-05-29 16:02 - 00000000 ____D () C:\Users\DM\Downloads\Bitdefender Total Security 2014 x32 & x64 2014-05-29 07:32 - 2014-05-29 07:32 - 00080384 _____ (Razer Inc) C:\Windows\system32\RazerCoinstaller.dll 2014-05-26 04:08 - 2014-05-26 04:08 - 00011025 _____ () C:\Users\DM\Downloads\hijackthis.log 2014-05-26 04:07 - 2014-05-26 04:07 - 00388608 _____ (Trend Micro Inc.) C:\Users\DM\Downloads\HijackThis_2.0.4.exe 2014-05-26 04:07 - 2014-05-26 04:06 - 00707056 _____ () C:\Users\DM\Downloads\HijackThis(12030).exe 2014-05-25 15:33 - 2014-05-25 15:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Swiff Player 2014-05-25 15:33 - 2014-05-25 15:33 - 00000000 ____D () C:\Program Files (x86)\GlobFX 2014-05-25 15:24 - 2014-05-25 15:24 - 04494354 _____ (GlobFX Technologies ) C:\Users\DM\Downloads\SwiffPlayerSetup172.exe 2014-05-25 12:21 - 2014-06-06 02:23 - 00000056 _____ () C:\Program Files (x86)\Read me!.txt 2014-05-25 12:13 - 2014-06-06 02:23 - 00000000 ____D () C:\Program Files (x86)\Keen Software House 2014-05-24 22:07 - 2014-05-24 22:03 - 00000000 ____D () C:\Users\DM\AppData\Local\Microsoft Games 2014-05-24 04:33 - 2014-05-24 04:33 - 00864256 _____ (Razer Inc) C:\Windows\SysWOW64\rzdevicedll.dll 2014-05-24 04:33 - 2014-05-24 04:33 - 00325120 _____ (Razer Inc) C:\Windows\SysWOW64\rzaudiodll.dll 2014-05-23 13:02 - 2014-05-23 13:02 - 00136704 _____ (Razer Inc.) C:\Windows\SysWOW64\RzVAD.dll 2014-05-23 12:34 - 2014-05-23 12:34 - 00032768 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\RzMaelstromVAD.sys 2014-05-23 12:31 - 2014-05-23 12:31 - 00245760 _____ (A-Volute) C:\Windows\system32\DriverInstallCACMD.exe 2014-05-23 12:31 - 2014-05-23 12:31 - 00069632 _____ (A-Volute) C:\Windows\system32\DriverInstallCA.dll 2014-05-20 15:56 - 2014-05-20 15:56 - 00001088 _____ () C:\Users\DM\Desktop\steam.txt.lnk 2014-05-19 15:07 - 2013-12-19 02:23 - 00000000 ____D () C:\Users\DM\Documents\OpenTTD 2014-05-19 08:47 - 2014-05-19 08:47 - 00155816 _____ (Razer Inc) C:\Windows\system32\Drivers\rzudd.sys 2014-05-19 08:47 - 2014-05-19 08:47 - 00039080 _____ (Razer Inc) C:\Windows\system32\Drivers\rzp1endpt.sys 2014-05-19 08:47 - 2014-05-19 08:47 - 00031400 _____ (Razer Inc) C:\Windows\system32\Drivers\rzvmouse.sys 2014-05-19 08:26 - 2014-05-19 08:26 - 00155136 _____ (Razer Inc) C:\Windows\SysWOW64\rztouchdll.dll 2014-05-19 08:26 - 2014-05-19 08:26 - 00117248 _____ (Razer Inc) C:\Windows\SysWOW64\rzdisplaydll.dll 2014-05-19 08:26 - 2014-05-19 08:26 - 00089088 _____ (Razer Inc) C:\Windows\SysWOW64\rzdevinfo.dll 2014-05-19 05:36 - 2014-05-19 05:35 - 00000000 _____ () C:\Windows\SysWOW64\Access.dat 2014-05-19 05:29 - 2014-05-19 05:29 - 00000000 ____D () C:\Users\DM\Documents\Tunngle 2014-05-19 04:45 - 2013-11-11 14:52 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-05-18 16:50 - 2013-11-28 04:11 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Mozilla 2014-05-17 15:57 - 2014-05-17 15:40 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Apple Computer 2014-05-17 15:57 - 2014-05-17 15:38 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-05-17 15:53 - 2014-05-17 15:38 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-05-17 15:37 - 2014-05-17 15:37 - 00000000 ____D () C:\Users\DM\AppData\Local\Apple 2014-05-17 15:37 - 2014-05-17 15:37 - 00000000 ____D () C:\ProgramData\Apple 2014-05-16 17:26 - 2013-10-26 20:15 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-05-16 15:03 - 2013-11-28 04:11 - 00000000 ____D () C:\Users\DM\AppData\Local\Mozilla 2014-05-16 15:02 - 2014-05-16 15:02 - 00000000 ____D () C:\ProgramData\Mozilla 2014-05-15 15:46 - 2013-08-29 14:17 - 00000000 ____D () C:\Users\DM\AppData\Roaming\Skype Some content of TEMP: ==================== C:\Users\DM\AppData\Local\Temp\Quarantine.exe C:\Users\DM\AppData\Local\Temp\sfamcc00001.dll C:\Users\DM\AppData\Local\Temp\{5DBFC437-F3DB-41FB-B230-0B60D415419A}.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-08 20:55 ==================== End Of Log ============================