Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:2-08-2014 Ran by Biuro (administrator) on YFC on 05-08-2014 14:59:35 Running from C:\Documents and Settings\Biuro\My Documents\Pobrane Platform: Microsoft Windows XP Professional Service Pack 2 (X86) OS Language: English (United States) Internet Explorer Version 6 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) () C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe (Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe (Intel Corporation) C:\Program Files\Intel\AMT\atchk.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe () C:\Program Files\360\Total Security\safemon\QHSafeTray.exe (Intel Corporation) C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation) C:\Program Files\Intel\AMT\atchksrv.exe (Intel) C:\Program Files\Intel\AMT\LMS.exe (Common Group) C:\WINDOWS\twain_32\S6U12BX\WATCH.exe (Intel) C:\Program Files\Intel\AMT\UNS.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Farbar) C:\Documents and Settings\Biuro\My Documents\Pobrane\FRST(1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Watch.lnk ShortcutTarget: Watch.lnk -> C:\WINDOWS\twain_32\S6U12BX\WATCH.exe (Common Group) Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Watch.lnk ShortcutTarget: Watch.lnk -> C:\WINDOWS\twain_32\S6U12BX\WATCH.exe (Common Group) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 5.175.225.136 8.8.8.8 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Biuro\Application Data\Mozilla\Firefox\Profiles\uwo42e64.default FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Extension: United States English Spellchecker - C:\Documents and Settings\Biuro\Application Data\Mozilla\Firefox\Profiles\uwo42e64.default\Extensions\en-US@dictionaries.addons.mozilla.org [2013-12-31] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-01-02] Chrome: ======= CHR HomePage: CHR Extension: (Google Docs) - C:\Documents and Settings\Biuro\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-10] CHR Extension: (Google Drive) - C:\Documents and Settings\Biuro\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-10] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Documents and Settings\Biuro\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-12] CHR Extension: (YouTube) - C:\Documents and Settings\Biuro\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-10] CHR Extension: (Google Search) - C:\Documents and Settings\Biuro\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-10] CHR Extension: (Google Wallet) - C:\Documents and Settings\Biuro\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-10] CHR Extension: (Gmail) - C:\Documents and Settings\Biuro\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-10] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ASFAgent; C:\Program Files\Intel\ASF Agent\ASFAgent.exe [133968 2007-01-23] (Intel Corporation) R2 atchksrv; C:\Program Files\Intel\AMT\atchksrv.exe [176128 2009-12-01] (Intel Corporation) [File not signed] R2 LMS; C:\Program Files\Intel\AMT\LMS.exe [102400 2009-12-01] (Intel) [File not signed] R2 QHActiveDefense; C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe [617072 2014-07-16] () R2 UNS; C:\Program Files\Intel\AMT\UNS.exe [2519040 2009-12-01] (Intel) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 360AntiHacker; C:\WINDOWS\System32\Drivers\360AntiHacker.sys [88136 2014-07-16] (360.cn) R3 360AvFlt; C:\WINDOWS\System32\DRIVERS\360AvFlt.sys [65608 2014-07-16] (360.cn) R1 360Box; C:\WINDOWS\System32\DRIVERS\360Box.sys [202312 2014-07-16] (360.cn) R1 360SelfProtection; C:\WINDOWS\System32\drivers\360SelfProtection.sys [174536 2014-07-16] (360安全中心) S3 AsfAlrt; C:\WINDOWS\system32\Drivers\AsfAlrt.sys [42832 2007-01-23] (Intel Corporation) R1 BAPIDRV; C:\WINDOWS\System32\DRIVERS\BAPIDRV.sys [165968 2014-07-16] (Qihu 360 Software Co., Ltd.) S0 cercsr6; C:\WINDOWS\system32\Drivers\cercsr6.sys [39904 2005-03-22] (Adaptec, Inc.) [File not signed] R1 EfiMon; C:\WINDOWS\System32\Drivers\Efimon.sys [23752 2014-07-16] (360安全中心) S3 GT680x; C:\WINDOWS\System32\DRIVERS\GT680x.SYS [17524 2000-08-18] ( ) [File not signed] R0 HookPort; C:\WINDOWS\System32\Drivers\Hookport.sys [54856 2014-07-16] (360安全中心) R1 qutmdserv; C:\WINDOWS\system32\drivers\qutmdrv.sys [257352 2014-07-16] (360.cn) S3 Secdrv; C:\WINDOWS\System32\DRIVERS\secdrv.sys [27440 2004-08-04] () S3 catchme; \??\C:\DOCUME~1\Biuro\LOCALS~1\Temp\catchme.sys [X] S4 IntelIde; No ImagePath U5 Sdbus; C:\Windows\System32\Drivers\Sdbus.sys [78720 2007-11-22] (Microsoft Corporation) S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-05 14:44 - 2014-08-05 14:44 - 00266208 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-08-05 14:42 - 2014-08-05 14:42 - 00000453 _____ () C:\Documents and Settings\Biuro\Desktop\linki.txt 2014-08-05 14:38 - 2014-08-05 14:38 - 00000673 _____ () C:\WINDOWS\setupapi.log 2014-07-31 18:51 - 2014-08-05 14:59 - 00000000 ____D () C:\FRST 2014-07-31 18:43 - 2014-08-05 14:51 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-07-31 18:43 - 2014-08-05 14:51 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-07-31 18:43 - 2014-07-31 18:43 - 00000000 ____N () C:\WINDOWS\Sti_Trace.log 2014-07-31 18:41 - 2014-07-31 18:41 - 00000000 __SHD () C:\Documents and Settings\All Users.WINDOWS\Application Data\360Quarant 2014-07-31 18:41 - 2014-07-31 18:41 - 00000000 __SHD () C:\Documents and Settings\All Users.WINDOWS\Application Data\360Quarant 2014-07-31 18:29 - 2014-07-31 18:40 - 00006137 _____ () C:\Documents and Settings\Biuro\Desktop\jak usunąć.txt 2014-07-31 18:20 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll 2014-07-31 18:20 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll 2014-07-31 18:20 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll 2014-07-31 18:20 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll 2014-07-31 18:20 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll 2014-07-31 18:20 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll 2014-07-31 18:20 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll 2014-07-31 18:20 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll 2014-07-31 18:20 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll 2014-07-31 18:20 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll 2014-07-31 18:20 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll 2014-07-31 18:20 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll 2014-07-31 18:20 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll 2014-07-31 18:20 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll 2014-07-31 18:20 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll 2014-07-31 18:20 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll 2014-07-31 18:20 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll 2014-07-31 18:20 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll 2014-07-31 18:20 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll 2014-07-31 18:19 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll 2014-07-31 18:19 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll 2014-07-31 18:19 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll 2014-07-31 18:19 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll 2014-07-31 18:19 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll 2014-07-31 18:19 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll 2014-07-31 18:19 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll 2014-07-31 18:19 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll 2014-07-31 18:19 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll 2014-07-31 18:19 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll 2014-07-31 18:19 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll 2014-07-31 18:19 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll 2014-07-31 18:19 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll 2014-07-31 18:19 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll 2014-07-31 18:19 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll 2014-07-31 18:19 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll 2014-07-31 18:19 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll 2014-07-31 18:19 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll 2014-07-31 18:19 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll 2014-07-31 18:19 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll 2014-07-31 18:19 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll 2014-07-31 18:19 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll 2014-07-31 18:19 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll 2014-07-31 18:19 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll 2014-07-31 18:19 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll 2014-07-31 18:19 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll 2014-07-31 18:19 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll 2014-07-31 18:19 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll 2014-07-31 18:19 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll 2014-07-31 18:19 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll 2014-07-31 18:19 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll 2014-07-31 18:19 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll 2014-07-31 18:19 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll 2014-07-31 18:19 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll 2014-07-31 18:19 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll 2014-07-31 18:19 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll 2014-07-31 18:19 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll 2014-07-31 18:19 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll 2014-07-31 18:19 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll 2014-07-31 18:19 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll 2014-07-31 18:19 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll 2014-07-31 18:19 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll 2014-07-31 18:19 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll 2014-07-31 18:19 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll 2014-07-31 18:19 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll 2014-07-31 18:19 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll 2014-07-31 18:19 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll 2014-07-31 18:19 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll 2014-07-31 18:19 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll 2014-07-31 18:19 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll 2014-07-31 18:19 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll 2014-07-31 18:19 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll 2014-07-31 18:19 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll 2014-07-31 18:19 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll 2014-07-31 18:19 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll 2014-07-31 18:19 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll 2014-07-31 18:19 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll 2014-07-31 18:19 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll 2014-07-31 18:19 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll 2014-07-31 18:19 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll 2014-07-31 18:18 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll 2014-07-31 18:18 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll 2014-07-31 18:18 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll 2014-07-31 18:18 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll 2014-07-31 18:18 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll 2014-07-31 18:18 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll 2014-07-31 18:18 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll 2014-07-31 18:18 - 2005-12-05 18:07 - 00061136 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput9_1_0.dll 2014-07-31 18:18 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll 2014-07-31 18:18 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll 2014-07-31 18:18 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll 2014-07-31 18:18 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll 2014-07-31 18:13 - 2014-07-31 18:16 - 00000000 ____D () C:\DirectX 2014-07-31 18:02 - 2014-08-05 14:59 - 00000000 ____D () C:\Documents and Settings\Biuro\Local Settings\temp 2014-07-31 18:02 - 2014-07-31 18:02 - 00009777 _____ () C:\ComboFix.txt 2014-07-31 18:02 - 2014-07-31 18:02 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\temp 2014-07-31 18:02 - 2014-07-31 18:02 - 00000000 ____D () C:\Documents and Settings\LocalService\Local Settings\temp 2014-07-31 18:02 - 2014-07-31 18:02 - 00000000 ____D () C:\Documents and Settings\Ewa\Local Settings\temp 2014-07-31 18:02 - 2014-07-31 18:02 - 00000000 ____D () C:\Documents and Settings\Admin\Local Settings\temp 2014-07-31 17:58 - 2014-07-31 17:58 - 00000000 _RSHD () C:\cmdcons 2014-07-31 17:58 - 2013-10-31 20:15 - 00000211 _____ () C:\Boot.bak 2014-07-31 17:58 - 2004-08-03 23:00 - 00262400 __RSH () C:\cmldr 2014-07-31 17:56 - 2011-06-26 08:45 - 00256000 _____ () C:\WINDOWS\PEV.exe 2014-07-31 17:56 - 2010-11-07 19:20 - 00208896 _____ () C:\WINDOWS\MBR.exe 2014-07-31 17:56 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe 2014-07-31 17:56 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe 2014-07-31 17:56 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe 2014-07-31 17:56 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe 2014-07-31 17:56 - 2000-08-31 02:00 - 00098816 _____ () C:\WINDOWS\sed.exe 2014-07-31 17:56 - 2000-08-31 02:00 - 00080412 _____ () C:\WINDOWS\grep.exe 2014-07-31 17:56 - 2000-08-31 02:00 - 00068096 _____ () C:\WINDOWS\zip.exe 2014-07-31 17:55 - 2014-07-31 18:02 - 00000000 ____D () C:\Qoobox 2014-07-31 17:54 - 2014-07-31 18:02 - 00000000 ____D () C:\WINDOWS\erdnt 2014-07-31 17:52 - 2014-08-05 14:57 - 00026924 _____ () C:\WINDOWS\WindowsUpdate.log 2014-07-31 17:47 - 2014-07-31 17:49 - 00000000 ____D () C:\AdwCleaner 2014-07-31 17:31 - 2014-06-01 17:18 - 92708840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-07-31 17:21 - 2014-07-31 17:27 - 00000000 ___HD () C:\WINDOWS\msdownld.tmp 2014-07-31 17:09 - 2009-11-27 18:37 - 00048128 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iyuv_32.dll 2014-07-31 17:09 - 2009-11-27 18:37 - 00008704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tsbyuv.dll 2014-07-31 17:08 - 2009-11-27 19:33 - 00017920 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msyuv.dll 2014-07-31 16:59 - 2014-07-31 16:59 - 00000000 ____D () C:\WINDOWS\ServicePackFiles 2014-07-31 16:55 - 2008-07-30 11:44 - 00455936 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mrxsmb.sys 2014-07-31 16:51 - 2014-07-31 16:51 - 00000065 _____ () C:\Documents and Settings\Biuro\Desktop\szamba.txt 2014-07-31 16:47 - 2007-11-22 13:43 - 00078720 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sdbus.sys 2014-07-31 16:47 - 2007-11-22 13:23 - 00012032 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sffdisk.sys 2014-07-31 16:47 - 2007-11-22 13:23 - 00011008 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sffp_sd.sys 2014-07-31 16:47 - 2007-11-22 13:23 - 00010240 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sffp_mmc.sys 2014-07-31 16:47 - 2007-11-22 13:23 - 00010240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sffp_mmc.sys 2014-07-31 16:39 - 2006-06-01 20:47 - 00163840 ____C (America Online) C:\WINDOWS\system32\dllcache\jgdw400.dll 2014-07-31 16:39 - 2006-06-01 20:47 - 00027648 ____C (Johnson-Grace Company) C:\WINDOWS\system32\dllcache\jgpl400.dll 2014-07-31 16:38 - 2006-03-17 02:38 - 00028672 ____N (Microsoft Corporation) C:\WINDOWS\system32\verclsid.exe 2014-07-31 16:35 - 2010-08-13 14:46 - 00353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsp3res.dll 2014-07-31 16:33 - 2014-07-31 17:30 - 00000000 ___HD () C:\WINDOWS\$hf_mig$ 2014-07-31 16:29 - 2014-07-31 17:31 - 00000066 _____ () C:\Documents and Settings\Biuro\Desktop\wirus.txt 2014-07-31 16:09 - 2014-07-31 16:09 - 00000683 _____ () C:\Documents and Settings\Biuro\Desktop\Shortcut to mbam.lnk 2014-07-31 15:47 - 2014-07-31 18:04 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-07-31 15:23 - 2014-07-31 15:23 - 00000000 __SHD () C:\WINDOWS\CSC 2014-07-31 15:14 - 2014-07-31 15:59 - 00000000 ____D () C:\WINDOWS\455F074C814E4520B69B5584BD90400C.TMP 2014-07-31 15:14 - 2014-07-31 15:14 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-07-31 15:14 - 2014-07-31 15:14 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard 2014-07-31 15:11 - 2014-07-31 16:09 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-07-31 15:11 - 2014-07-31 15:11 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes 2014-07-31 15:11 - 2014-07-31 15:11 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes 2014-07-31 15:11 - 2014-05-12 07:26 - 00053208 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-07-31 15:11 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-07-31 15:08 - 2014-07-31 15:08 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-07-31 14:50 - 2014-07-31 18:41 - 00000000 ____D () C:\$360Section 2014-07-31 14:50 - 2014-07-31 17:43 - 00000000 __SHD () C:\Documents and Settings\Biuro\Application Data\360Quarant 2014-07-31 14:49 - 2014-07-31 14:49 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy 2014-07-31 14:48 - 2014-07-31 14:48 - 00000000 ____D () C:\Documents and Settings\LocalService\Application Data\360safe 2014-07-31 14:47 - 2014-08-05 14:52 - 00000000 ____D () C:\Documents and Settings\Biuro\Application Data\360WD 2014-07-31 14:47 - 2014-07-31 14:48 - 00000000 ____D () C:\WINDOWS\Tasks\360Disabled 2014-07-31 14:47 - 2014-07-31 14:48 - 00000000 ____D () C:\Documents and Settings\Biuro\Application Data\360safe 2014-07-31 14:47 - 2014-07-31 14:47 - 00000802 _____ () C:\Documents and Settings\Biuro\Desktop\360 Total Security.lnk 2014-07-31 14:47 - 2014-07-31 14:47 - 00000000 _RSHD () C:\360SANDBOX 2014-07-31 14:47 - 2014-07-31 14:47 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\360 Security Center 2014-07-31 14:47 - 2014-07-31 14:47 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\360 Security Center 2014-07-31 14:47 - 2014-07-31 14:47 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Application Data\360safe 2014-07-31 14:47 - 2014-07-31 14:47 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Application Data\360safe 2014-07-31 14:47 - 2014-07-16 07:47 - 00257352 _____ (360.cn) C:\WINDOWS\system32\Drivers\qutmdrv.sys 2014-07-31 14:47 - 2014-07-16 07:47 - 00202312 _____ (360.cn) C:\WINDOWS\system32\Drivers\360Box.sys 2014-07-31 14:47 - 2014-07-16 07:47 - 00174536 _____ (360安全中心) C:\WINDOWS\system32\Drivers\360SelfProtection.sys 2014-07-31 14:47 - 2014-07-16 07:47 - 00165968 _____ (Qihu 360 Software Co., Ltd.) C:\WINDOWS\system32\Drivers\BAPIDRV.SYS 2014-07-31 14:47 - 2014-07-16 07:47 - 00088136 _____ (360.cn) C:\WINDOWS\system32\Drivers\360AntiHacker.sys 2014-07-31 14:47 - 2014-07-16 07:47 - 00065608 _____ (360.cn) C:\WINDOWS\system32\Drivers\360AvFlt.sys 2014-07-31 14:47 - 2014-07-16 07:47 - 00054856 _____ (360安全中心) C:\WINDOWS\system32\Drivers\hookport.sys 2014-07-31 14:47 - 2014-07-16 07:47 - 00023752 _____ (360安全中心) C:\WINDOWS\system32\Drivers\efimon.sys 2014-07-31 14:46 - 2014-07-31 14:46 - 00000000 ____D () C:\Program Files\360 2014-07-31 12:55 - 2014-08-05 14:59 - 00000000 ____D () C:\Documents and Settings\Biuro\My Documents\Pobrane ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-05 14:59 - 2014-07-31 18:51 - 00000000 ____D () C:\FRST 2014-08-05 14:59 - 2014-07-31 18:02 - 00000000 ____D () C:\Documents and Settings\Biuro\Local Settings\temp 2014-08-05 14:59 - 2014-07-31 12:55 - 00000000 ____D () C:\Documents and Settings\Biuro\My Documents\Pobrane 2014-08-05 14:57 - 2014-07-31 17:52 - 00026924 _____ () C:\WINDOWS\WindowsUpdate.log 2014-08-05 14:52 - 2014-07-31 14:47 - 00000000 ____D () C:\Documents and Settings\Biuro\Application Data\360WD 2014-08-05 14:51 - 2014-07-31 18:43 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-08-05 14:51 - 2014-07-31 18:43 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-08-05 14:51 - 2013-10-31 20:23 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-08-05 14:50 - 2013-11-14 12:19 - 00000178 ___SH () C:\Documents and Settings\Biuro\ntuser.ini 2014-08-05 14:50 - 2013-10-31 20:23 - 00032652 _____ () C:\WINDOWS\SchedLgU.Txt 2014-08-05 14:44 - 2014-08-05 14:44 - 00266208 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-08-05 14:43 - 2013-11-14 12:19 - 00000000 ____D () C:\Documents and Settings\Biuro 2014-08-05 14:42 - 2014-08-05 14:42 - 00000453 _____ () C:\Documents and Settings\Biuro\Desktop\linki.txt 2014-08-05 14:38 - 2014-08-05 14:38 - 00000673 _____ () C:\WINDOWS\setupapi.log 2014-08-05 11:52 - 2013-10-31 20:22 - 00000000 __SHD () C:\Documents and Settings\NetworkService 2014-08-05 11:32 - 2014-01-02 11:10 - 00000000 ____D () C:\WINDOWS\Microsoft.NET 2014-08-05 11:03 - 2013-10-31 21:11 - 00512960 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-08-05 10:59 - 2004-08-04 14:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl 2014-07-31 18:43 - 2014-07-31 18:43 - 00000000 ____N () C:\WINDOWS\Sti_Trace.log 2014-07-31 18:41 - 2014-07-31 18:41 - 00000000 __SHD () C:\Documents and Settings\All Users.WINDOWS\Application Data\360Quarant 2014-07-31 18:41 - 2014-07-31 18:41 - 00000000 __SHD () C:\Documents and Settings\All Users.WINDOWS\Application Data\360Quarant 2014-07-31 18:41 - 2014-07-31 14:50 - 00000000 ____D () C:\$360Section 2014-07-31 18:40 - 2014-07-31 18:29 - 00006137 _____ () C:\Documents and Settings\Biuro\Desktop\jak usunąć.txt 2014-07-31 18:30 - 2013-11-07 15:18 - 00000664 _____ () C:\WINDOWS\system32\d3d9caps.dat 2014-07-31 18:20 - 2013-10-31 19:46 - 00000000 ____D () C:\WINDOWS\system32\DirectX 2014-07-31 18:16 - 2014-07-31 18:13 - 00000000 ____D () C:\DirectX 2014-07-31 18:04 - 2014-07-31 15:47 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-07-31 18:02 - 2014-07-31 18:02 - 00009777 _____ () C:\ComboFix.txt 2014-07-31 18:02 - 2014-07-31 18:02 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\temp 2014-07-31 18:02 - 2014-07-31 18:02 - 00000000 ____D () C:\Documents and Settings\LocalService\Local Settings\temp 2014-07-31 18:02 - 2014-07-31 18:02 - 00000000 ____D () C:\Documents and Settings\Ewa\Local Settings\temp 2014-07-31 18:02 - 2014-07-31 18:02 - 00000000 ____D () C:\Documents and Settings\Admin\Local Settings\temp 2014-07-31 18:02 - 2014-07-31 17:55 - 00000000 ____D () C:\Qoobox 2014-07-31 18:02 - 2014-07-31 17:54 - 00000000 ____D () C:\WINDOWS\erdnt 2014-07-31 18:02 - 2013-10-31 20:23 - 00000000 __SHD () C:\Documents and Settings\LocalService 2014-07-31 18:01 - 2004-08-04 14:00 - 00000227 _____ () C:\WINDOWS\system.ini 2014-07-31 17:58 - 2014-07-31 17:58 - 00000000 _RSHD () C:\cmdcons 2014-07-31 17:58 - 2013-10-31 20:26 - 00000327 __RSH () C:\boot.ini 2014-07-31 17:49 - 2014-07-31 17:47 - 00000000 ____D () C:\AdwCleaner 2014-07-31 17:43 - 2014-07-31 14:50 - 00000000 __SHD () C:\Documents and Settings\Biuro\Application Data\360Quarant 2014-07-31 17:37 - 2013-10-31 20:21 - 00000000 ____D () C:\WINDOWS\security 2014-07-31 17:35 - 2013-10-31 20:21 - 00000000 ____D () C:\WINDOWS\msagent 2014-07-31 17:35 - 2013-10-31 19:45 - 00000000 ____D () C:\Program Files\Messenger 2014-07-31 17:31 - 2014-07-31 16:29 - 00000066 _____ () C:\Documents and Settings\Biuro\Desktop\wirus.txt 2014-07-31 17:30 - 2014-07-31 16:33 - 00000000 ___HD () C:\WINDOWS\$hf_mig$ 2014-07-31 17:27 - 2014-07-31 17:21 - 00000000 ___HD () C:\WINDOWS\msdownld.tmp 2014-07-31 17:24 - 2013-10-31 19:46 - 00000000 ____D () C:\Program Files\Movie Maker 2014-07-31 17:18 - 2014-01-14 11:04 - 00009216 _____ () C:\Documents and Settings\Biuro\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-31 17:15 - 2013-10-31 19:45 - 00000000 ____D () C:\Program Files\Outlook Express 2014-07-31 16:59 - 2014-07-31 16:59 - 00000000 ____D () C:\WINDOWS\ServicePackFiles 2014-07-31 16:53 - 2013-11-07 16:42 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help 2014-07-31 16:53 - 2013-11-07 16:42 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help 2014-07-31 16:51 - 2014-07-31 16:51 - 00000065 _____ () C:\Documents and Settings\Biuro\Desktop\szamba.txt 2014-07-31 16:47 - 2013-10-31 19:45 - 00000000 ____D () C:\Program Files\Common Files\System 2014-07-31 16:24 - 2014-01-02 11:15 - 00000000 ____D () C:\Documents and Settings\Biuro\Local Settings\Application Data\Deployment 2014-07-31 16:09 - 2014-07-31 16:09 - 00000683 _____ () C:\Documents and Settings\Biuro\Desktop\Shortcut to mbam.lnk 2014-07-31 16:09 - 2014-07-31 15:11 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-07-31 15:59 - 2014-07-31 15:14 - 00000000 ____D () C:\WINDOWS\455F074C814E4520B69B5584BD90400C.TMP 2014-07-31 15:56 - 2014-01-02 10:57 - 00000000 __HDC () C:\WINDOWS\$MSI31Uninstall_KB893803v2$ 2014-07-31 15:56 - 2013-11-07 14:15 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-07-31 15:30 - 2013-12-02 12:29 - 00001599 _____ () C:\Documents and Settings\Ewa\Start Menu\Programs\Remote Assistance.lnk 2014-07-31 15:30 - 2013-11-14 12:19 - 00001599 _____ () C:\Documents and Settings\Biuro\Start Menu\Programs\Remote Assistance.lnk 2014-07-31 15:30 - 2013-10-31 20:20 - 00001599 _____ () C:\Documents and Settings\Default User.WINDOWS\Start Menu\Programs\Remote Assistance.lnk 2014-07-31 15:30 - 2013-10-31 19:48 - 00001599 _____ () C:\Documents and Settings\Default User\Start Menu\Programs\Remote Assistance.lnk 2014-07-31 15:26 - 2013-10-31 20:25 - 00001599 _____ () C:\Documents and Settings\Admin\Start Menu\Programs\Remote Assistance.lnk 2014-07-31 15:26 - 2013-10-31 20:20 - 00001607 _____ () C:\Documents and Settings\All Users.WINDOWS\Start Menu\Set Program Access and Defaults.lnk 2014-07-31 15:26 - 2013-10-31 20:20 - 00001607 _____ () C:\Documents and Settings\All Users.WINDOWS\Start Menu\Set Program Access and Defaults.lnk 2014-07-31 15:26 - 2013-10-31 20:20 - 00001507 _____ () C:\Documents and Settings\All Users.WINDOWS\Start Menu\Windows Update.lnk 2014-07-31 15:26 - 2013-10-31 20:20 - 00001507 _____ () C:\Documents and Settings\All Users.WINDOWS\Start Menu\Windows Update.lnk 2014-07-31 15:23 - 2014-07-31 15:23 - 00000000 __SHD () C:\WINDOWS\CSC 2014-07-31 15:14 - 2014-07-31 15:14 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-07-31 15:14 - 2014-07-31 15:14 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard 2014-07-31 15:11 - 2014-07-31 15:11 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes 2014-07-31 15:11 - 2014-07-31 15:11 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes 2014-07-31 15:08 - 2014-07-31 15:08 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-07-31 14:49 - 2014-07-31 14:49 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy 2014-07-31 14:48 - 2014-07-31 14:48 - 00000000 ____D () C:\Documents and Settings\LocalService\Application Data\360safe 2014-07-31 14:48 - 2014-07-31 14:47 - 00000000 ____D () C:\WINDOWS\Tasks\360Disabled 2014-07-31 14:48 - 2014-07-31 14:47 - 00000000 ____D () C:\Documents and Settings\Biuro\Application Data\360safe 2014-07-31 14:47 - 2014-07-31 14:47 - 00000802 _____ () C:\Documents and Settings\Biuro\Desktop\360 Total Security.lnk 2014-07-31 14:47 - 2014-07-31 14:47 - 00000000 _RSHD () C:\360SANDBOX 2014-07-31 14:47 - 2014-07-31 14:47 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\360 Security Center 2014-07-31 14:47 - 2014-07-31 14:47 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\360 Security Center 2014-07-31 14:47 - 2014-07-31 14:47 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Application Data\360safe 2014-07-31 14:47 - 2014-07-31 14:47 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Application Data\360safe 2014-07-31 14:46 - 2014-07-31 14:46 - 00000000 ____D () C:\Program Files\360 2014-07-31 14:44 - 2013-11-14 12:45 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Application Data\AVAST Software 2014-07-31 14:44 - 2013-11-14 12:45 - 00000000 ____D () C:\Documents and Settings\All Users.WINDOWS\Application Data\AVAST Software 2014-07-16 07:47 - 2014-07-31 14:47 - 00257352 _____ (360.cn) C:\WINDOWS\system32\Drivers\qutmdrv.sys 2014-07-16 07:47 - 2014-07-31 14:47 - 00202312 _____ (360.cn) C:\WINDOWS\system32\Drivers\360Box.sys 2014-07-16 07:47 - 2014-07-31 14:47 - 00174536 _____ (360安全中心) C:\WINDOWS\system32\Drivers\360SelfProtection.sys 2014-07-16 07:47 - 2014-07-31 14:47 - 00165968 _____ (Qihu 360 Software Co., Ltd.) C:\WINDOWS\system32\Drivers\BAPIDRV.SYS 2014-07-16 07:47 - 2014-07-31 14:47 - 00088136 _____ (360.cn) C:\WINDOWS\system32\Drivers\360AntiHacker.sys 2014-07-16 07:47 - 2014-07-31 14:47 - 00065608 _____ (360.cn) C:\WINDOWS\system32\Drivers\360AvFlt.sys 2014-07-16 07:47 - 2014-07-31 14:47 - 00054856 _____ (360安全中心) C:\WINDOWS\system32\Drivers\hookport.sys 2014-07-16 07:47 - 2014-07-31 14:47 - 00023752 _____ (360安全中心) C:\WINDOWS\system32\Drivers\efimon.sys 2014-07-15 14:26 - 2013-11-07 14:24 - 00699056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2014-07-15 14:26 - 2013-11-07 14:24 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================