Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-10-2014 01 Ran by Merix (administrator) on MERIX-KOMPUTER on 08-10-2014 20:09:54 Running from C:\Users\Merix\Downloads Loaded Profile: Merix (Available profiles: Merix) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polski (Polska) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (AMD) C:\Windows\System32\atieclxx.exe (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe ( ) C:\Windows\System32\lxeacoms.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe () C:\Program Files (x86)\Kilgray\memoQserver40\MemoQ Server Manager.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\HDD Password Tool\TosExtSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE () C:\Program Files (x86)\Lexmark S300-S400 Series\lxeamon.exe () C:\Program Files (x86)\Lexmark S300-S400 Series\ezprint.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\HDD Password Tool\TosExtCtrl.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (SDL) C:\Program Files (x86)\SDL\SDL MultiTerm\MultiTerm8\MultiTerm Widget.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (SDL International) C:\Program Files (x86)\SDL International\SDL Trados Synergy 2007\Synergy.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe () C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\BCMWLTRY.EXE (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\Merix\Downloads\FRST64 (2).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [QuickSet] => C:\Program Files\Dell\QuickSet\QuickSet.exe [3179288 2010-01-06] (Dell Inc.) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-06-18] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2010-03-17] (Synaptics Incorporated) HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5712896 2010-02-03] (Dell Inc.) HKLM\...\Run: [lxeamon.exe] => C:\Program Files (x86)\Lexmark S300-S400 Series\lxeamon.exe [770728 2011-01-24] () HKLM\...\Run: [EzPrint] => C:\Program Files (x86)\Lexmark S300-S400 Series\ezprint.exe [148280 2011-01-24] () HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-06-08] (Intel Corporation) HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [409744 2009-06-24] (Creative Technology Ltd) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-06-02] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [498160 2009-12-15] () HKLM-x32\...\Run: [Lexmark S300-S400 Series] => C:\Program Files (x86)\Lexmark S300-S400 Series\fm3032.exe [316072 2011-01-24] () HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296056 2012-05-27] (RealNetworks, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-30] (AVAST Software) HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] => C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe [559616 2011-10-05] (Dell) HKU\S-1-5-21-3302502354-795164464-2874845416-1001\...\Run: [ISUSPM] => "C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe" -scheduler (the data entry has 27 more characters). HKU\S-1-5-21-3302502354-795164464-2874845416-1001\...\Run: [Google Update] => C:\Users\Merix\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-03-20] (Google Inc.) HKU\S-1-5-21-3302502354-795164464-2874845416-1001\...\MountPoints2: E - E:\AutoRun.exe /s HKU\S-1-5-21-3302502354-795164464-2874845416-1001\...\MountPoints2: F - F:\AutoRun.exe /s HKU\S-1-5-21-3302502354-795164464-2874845416-1001\...\MountPoints2: {4a74ae6f-2027-11e2-b7eb-f04da28dcedf} - E:\AutoRun.exe /s HKU\S-1-5-21-3302502354-795164464-2874845416-1001\...\MountPoints2: {faae46e6-a92d-11e2-b7f6-1c659d2d6300} - E:\AutoRun.exe /s Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HDD Password Tool.lnk ShortcutTarget: HDD Password Tool.lnk -> C:\Program Files (x86)\TOSHIBA\HDD Password Tool\TosExtCtrl.exe (TOSHIBA CORPORATION) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SDL MultiTerm 2009 Widget.lnk ShortcutTarget: SDL MultiTerm 2009 Widget.lnk -> C:\Program Files (x86)\SDL\SDL MultiTerm\MultiTerm8\MultiTerm Widget.exe (SDL) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SDL Trados 2007 Speed Launcher.lnk ShortcutTarget: SDL Trados 2007 Speed Launcher.lnk -> C:\Program Files (x86)\SDL International\SDL Trados Synergy 2007\Synergy.exe (SDL International) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pl.msn.com/?ocid=U218DHP&pc=U218 BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Pomocnik logowania za pomocą identyfikatora Windows Live -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1 FireFox: ======== FF ProfilePath: C:\Users\Merix\AppData\Roaming\Mozilla\Firefox\Profiles\yjlyvean.default-1412789250852 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll () FF Plugin: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=15.0.4.53 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprjplug;version=15.0.4.53 -> c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.4.53 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version=15.0.4.53 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin -> C:\Users\Merix\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin -> C:\Users\Merix\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\Merix\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\Merix\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Users\Merix\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Merix\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-09-07] FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-10-27] Chrome: ======= CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Merix\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.5.671\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\pdf.dll () CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (Google Update) - C:\Users\Merix\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Google Talk Plugin) - C:\Users\Merix\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Merix\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealJukebox NS Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Download Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) CHR Profile: C:\Users\Merix\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Dokumenty Google) - C:\Users\Merix\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-13] CHR Extension: (Dysk Google) - C:\Users\Merix\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-13] CHR Extension: (YouTube) - C:\Users\Merix\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-13] CHR Extension: (Szukaj w Google) - C:\Users\Merix\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-13] CHR Extension: (avast! Online Security) - C:\Users\Merix\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-06-30] CHR Extension: (Google Wallet) - C:\Users\Merix\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-13] CHR Extension: (Gmail) - C:\Users\Merix\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-13] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-06-29] CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2011-10-27] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-29] (AVAST Software) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [647680 2011-09-27] (Macrovision Europe Ltd.) [File not signed] S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed] S2 lxeaCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\lxeaserv.exe [45736 2010-04-14] (Lexmark International, Inc.) R2 lxea_device; C:\Windows\system32\lxeacoms.exe [1052328 2010-04-14] ( ) R2 lxea_device; C:\Windows\SysWOW64\lxeacoms.exe [598696 2010-04-14] ( ) S2 MSSQL$MEMOQSERVER; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MEMOQSERVER\MSSQL\Binn\sqlservr.exe [43040096 2011-06-17] (Microsoft Corporation) S4 SQLAgent$MEMOQSERVER; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.MEMOQSERVER\MSSQL\Binn\SQLAGENT.EXE [370016 2011-06-17] (Microsoft Corporation) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] R2 TosExtSvc; C:\Program Files (x86)\TOSHIBA\HDD Password Tool\TosExtSvc.exe [1629560 2012-08-19] (TOSHIBA CORPORATION) R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [5088256 2010-02-03] (Dell Inc.) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-29] () R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [28504 2012-02-23] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-29] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-06-29] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-29] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-06-29] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-04] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-06-29] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-06-29] () R0 TosExt; C:\Windows\System32\Drivers\TosExt.sys [25976 2012-08-19] (TOSHIBA Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-08 20:05 - 2014-10-08 20:05 - 02109952 _____ (Farbar) C:\Users\Merix\Downloads\FRST64 (2).exe 2014-10-08 19:45 - 2014-10-08 19:45 - 00022674 _____ () C:\Users\Merix\Desktop\AdwCleaner[S0].txt 2014-10-08 19:42 - 2014-10-08 19:42 - 00000000 _____ () C:\Windows\SysWOW64\sho87D5.tmp 2014-10-08 19:35 - 2014-10-08 19:35 - 01375089 _____ () C:\Users\Merix\Downloads\adwcleaner_3.311.exe 2014-10-08 19:27 - 2014-10-08 19:27 - 00000000 ____D () C:\Users\Merix\Desktop\Stare dane programu Firefox 2014-10-08 19:07 - 2014-10-08 19:07 - 00004366 _____ () C:\Users\Merix\Desktop\fixlist.txt 2014-10-08 18:02 - 2014-10-08 18:02 - 00051519 _____ () C:\Users\Merix\Desktop\Addition.txt 2014-10-08 18:02 - 2014-10-08 18:02 - 00050360 _____ () C:\Users\Merix\Desktop\FRST.txt 2014-10-08 18:01 - 2014-10-08 18:01 - 00074476 _____ () C:\Users\Merix\Desktop\Shortcut.txt 2014-10-08 17:49 - 2014-10-08 17:49 - 02109952 _____ (Farbar) C:\Users\Merix\Downloads\FRST64 (1).exe 2014-10-08 17:48 - 2014-10-08 17:48 - 00151494 _____ () C:\Users\Merix\Desktop\OTL.Txt 2014-10-08 12:58 - 2014-10-08 12:58 - 00602112 _____ (OldTimer Tools) C:\Users\Merix\Downloads\OTL (1).exe 2014-10-08 05:48 - 2014-10-08 05:48 - 00000000 __SHD () C:\found.005 2014-10-07 21:12 - 2014-10-07 21:12 - 00001298 _____ () C:\Users\Merix\AppData\Roaming\Microsoft\Windows\Start Menu\Legend Online.lnk 2014-10-07 21:11 - 2014-10-07 21:11 - 00372050 _____ () C:\Users\Merix\Downloads\LegendOnline(pl)1.1.zip 2014-10-07 20:29 - 2014-10-07 20:29 - 00000000 ____D () C:\Program Files (x86)\Badosoft 2014-10-07 18:37 - 2014-10-07 18:38 - 00000000 ____D () C:\8abc62a0be65793de617e4 2014-10-07 18:35 - 2014-10-07 18:37 - 00000000 ____D () C:\29e479d6cc479d2cbf40 2014-10-07 18:33 - 2014-10-07 18:35 - 00000000 ____D () C:\e302b9c9fa2d985124d6a2fb 2014-10-07 15:52 - 2014-10-07 15:53 - 00000000 ____D () C:\719b194f91daed15b9f1 2014-10-07 15:49 - 2014-10-07 15:51 - 00000000 ____D () C:\3e39c06956eb4185df90d1021fc83e 2014-10-07 15:47 - 2014-10-07 15:49 - 00000000 ____D () C:\38e28df617e2cd03ee 2014-10-07 15:17 - 2014-10-07 15:18 - 00000000 ____D () C:\c726160cfc78cbd710ff671576f4a6d1 2014-10-07 15:01 - 2014-10-07 15:01 - 00000000 ____D () C:\ee009d0af9347b49863c7c59ac7f9f 2014-10-04 03:06 - 2014-10-04 03:07 - 00000000 ____D () C:\e6c72d7f2ca5583909ddceb13a383f 2014-10-04 03:03 - 2014-10-04 03:05 - 00000000 ____D () C:\b8478af5a91f3c92f2 2014-10-03 10:40 - 2014-10-03 10:40 - 00000000 _____ () C:\Users\Merix\Downloads\fwdfwd.zip 2014-10-03 07:02 - 2014-09-25 04:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-10-03 07:02 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2014-10-01 02:40 - 2014-10-01 02:40 - 00000000 ____D () C:\eacff8cad64b4499897c14 2014-10-01 02:38 - 2014-10-01 02:39 - 00000000 ____D () C:\789bc61cecbac7eeef 2014-09-30 02:50 - 2014-09-30 02:50 - 00000000 ____D () C:\f48b80cb49aaaf7d9189d8552e 2014-09-30 02:49 - 2014-09-30 02:50 - 00000000 ____D () C:\a91e6442c826e68c8c9e 2014-09-28 20:23 - 2014-09-28 20:23 - 00000000 ____D () C:\d5ac85fc08c1489f6ed620c2fd5b 2014-09-28 20:21 - 2014-09-28 20:23 - 00000000 ____D () C:\96c6f2ac12b6c8a7fe9242d8f90b39 2014-09-28 20:20 - 2014-09-28 20:21 - 00000000 ____D () C:\cbf1f7bd6ebdc85d5e6492aa 2014-09-28 18:02 - 2014-09-28 18:02 - 30014480 _____ (TeamSpeak Systems GmbH) C:\Users\Merix\Downloads\TeamSpeak3-Client-win64-3.0.16.exe 2014-09-28 16:29 - 2014-09-28 16:29 - 06240683 _____ () C:\Users\Merix\Downloads\fwdrezdjcia.zip 2014-09-28 16:28 - 2014-09-28 16:30 - 00000000 ____D () C:\Users\Merix\Desktop\TEGOROCZNE ZBIORY 2014-09-28 13:29 - 2014-09-28 13:29 - 00000000 ____D () C:\2f452883aa2da075d822ceedd01e30fd 2014-09-28 13:28 - 2014-09-28 13:29 - 00000000 ____D () C:\b1bf310fc3ca5bb53ce4 2014-09-28 13:26 - 2014-09-28 13:28 - 00000000 ____D () C:\1efa778480f196bb42c7382d9ba71b 2014-09-28 02:39 - 2014-09-28 02:39 - 00000000 ____D () C:\a8774fe4c0d6e0aef1 2014-09-28 02:37 - 2014-09-28 02:38 - 00000000 ____D () C:\7df81371e46d537e03bdde14694b 2014-09-28 02:36 - 2014-09-28 02:37 - 00000000 ____D () C:\19cbb867c2416f10bdaa 2014-09-26 22:17 - 2014-09-26 22:17 - 00000000 ____D () C:\1c139686e7af413c20d7b6238e 2014-09-26 22:15 - 2014-09-26 22:16 - 00000000 ____D () C:\8e05d1c55ebbbbac17de17cca15115 2014-09-26 02:50 - 2014-09-26 02:50 - 00000000 ____D () C:\13e1e036152f7f1abf9c5485 2014-09-26 02:49 - 2014-09-26 02:50 - 00000000 ____D () C:\b887179874c59fe5cf 2014-09-25 13:38 - 2014-09-26 02:41 - 00000000 ____D () C:\Users\Merix\Documents\ASCOT 2014-09-25 03:06 - 2014-09-25 03:06 - 00000000 ____D () C:\ea3e2ae6187a320008ba7e 2014-09-25 03:04 - 2014-09-25 03:05 - 00000000 ____D () C:\825294d8be26f1f099f6d7 2014-09-24 16:12 - 2014-09-24 16:12 - 00000000 ____D () C:\afe4c0fbfc2d1034d236cc39560e6b0c 2014-09-24 16:09 - 2014-09-24 16:11 - 00000000 ____D () C:\1ac113f0907279a74e2639 2014-09-24 10:45 - 2014-09-10 00:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-09-24 10:45 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-09-24 02:23 - 2014-09-24 02:24 - 00000000 ____D () C:\a60d7e9212f5ab125dab66ddea20fb 2014-09-23 20:36 - 2014-09-23 20:39 - 00000000 ____D () C:\Users\Merix\Desktop\DO WYSYŁKI 2014-09-23 19:27 - 2014-09-23 20:36 - 00005389 _____ () C:\Users\Merix\Desktop\PLIK DO TLUMACZENIA_j. polski_Teraz Energia sp. z o.o..docx_pl-PL_en-GB.sdlproj 2014-09-23 07:17 - 2014-09-23 07:17 - 00000000 ____D () C:\Users\Merix\Desktop\PLIK DO TLUMACZENIA_j. polski_Teraz Energia sp. z o.o..docx_pl-PL_en-GB.ProjectFiles 2014-09-23 01:50 - 2014-09-23 01:50 - 00000000 ____D () C:\63b2be0e4a34e244f986dcb1 2014-09-23 01:46 - 2014-09-23 01:48 - 00000000 ____D () C:\6614f0df3a5ca4ba8690d47d4b8112 2014-09-22 15:04 - 2014-10-08 19:44 - 00000376 _____ () C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Merix.job 2014-09-22 15:04 - 2014-10-08 15:19 - 00002968 _____ () C:\Windows\System32\Tasks\ReclaimerUpdateXML_Merix 2014-09-22 15:04 - 2014-10-08 15:19 - 00000366 _____ () C:\Windows\Tasks\ReclaimerUpdateXML_Merix.job 2014-09-22 15:04 - 2014-10-05 11:11 - 00002972 _____ () C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Merix 2014-09-22 15:04 - 2014-10-05 11:11 - 00000370 _____ () C:\Windows\Tasks\ReclaimerUpdateFiles_Merix.job 2014-09-22 15:04 - 2014-09-22 15:04 - 00003624 _____ () C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Merix 2014-09-22 15:04 - 2014-09-22 15:04 - 00002676 _____ () C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Merix 2014-09-21 02:44 - 2014-09-21 02:44 - 00000000 ____D () C:\84fd45e0da18ff0e1d7f5578f0 2014-09-21 02:43 - 2014-09-21 02:44 - 00000000 ____D () C:\3721f983f3c90c9fe219e823f8bd1915 2014-09-20 16:32 - 2014-09-20 16:32 - 00000000 ____D () C:\17e6579b4dab8ef7c793c85e77eb257e 2014-09-20 16:30 - 2014-09-20 16:31 - 00000000 ____D () C:\32b71fe306dd532fc63eac 2014-09-20 03:54 - 2014-09-20 03:54 - 00000000 ____D () C:\27c275e8d74b8cbbc9b2340ee46b8282 2014-09-20 03:53 - 2014-09-20 03:54 - 00000000 ____D () C:\64d3435fd38e72fe1dc5238464 2014-09-20 03:07 - 2014-09-20 03:08 - 00000000 ____D () C:\c4ee00b50fb4737d202f192aff 2014-09-20 03:05 - 2014-09-20 03:06 - 00000000 ____D () C:\bf33da7d6745921c31bff638bf4c473a 2014-09-20 03:03 - 2014-09-20 03:05 - 00000000 ____D () C:\980b5ec4524a326f46 2014-09-19 03:50 - 2014-09-19 03:51 - 00000000 ____D () C:\05af5163d422a031a74bc1eee9a0 2014-09-18 16:42 - 2014-09-18 16:43 - 00000000 ____D () C:\42d575fcb15c50dbd566ec 2014-09-18 16:41 - 2014-09-18 16:42 - 00000000 ____D () C:\260e529194132682f2929a24fbc2d1 2014-09-18 16:39 - 2014-09-18 16:41 - 00000000 ____D () C:\35b86be8bd61c80cae62c1989688 2014-09-18 11:49 - 2014-09-18 11:49 - 00601987 _____ () C:\Users\Merix\Downloads\fwdexportjabek.zip 2014-09-18 09:24 - 2014-09-18 09:24 - 00941580 _____ () C:\Users\Merix\Downloads\price list 17 09 2014_FCA_CIF MERSIN ( na Kurdystan).xlsx 2014-09-18 01:31 - 2014-09-18 01:32 - 00000000 ____D () C:\5be727b732a18ffad285b20e 2014-09-18 01:28 - 2014-09-18 01:30 - 00000000 ____D () C:\98246a79bd1cf1ddaf 2014-09-17 10:17 - 2014-09-17 10:17 - 00002517 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-09-17 10:17 - 2014-09-17 10:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-09-16 17:44 - 2014-09-16 17:44 - 00939710 _____ () C:\Users\Merix\Downloads\price list 16 06 2014_FAC_CIF MERSIN ( na Kurdystan).xlsx 2014-09-15 18:22 - 2014-09-15 18:22 - 00000000 ____D () C:\Users\Merix\AppData\Local\{8FA172F3-E6D7-4E96-9B9F-6F472A717652} 2014-09-15 02:01 - 2014-09-15 02:01 - 00000000 ____D () C:\2883f00acb4a5d9793 2014-09-15 02:00 - 2014-09-15 02:01 - 00000000 ____D () C:\94622dc48f107ca91179df5562 2014-09-15 01:58 - 2014-09-15 02:00 - 00000000 ____D () C:\dcd3780a5e58f1a58c649913ba 2014-09-13 19:56 - 2014-09-13 19:56 - 00000000 ____D () C:\0cf9049aa8e07771ff661d417c 2014-09-13 19:54 - 2014-09-13 19:55 - 00000000 ____D () C:\08dbb28a2d69d903ab 2014-09-13 02:56 - 2014-09-13 02:57 - 00000000 ____D () C:\13b4896f663997fd05f2ffa1 2014-09-13 02:53 - 2014-09-13 02:55 - 00000000 ____D () C:\a1b8ec303b6797649325 2014-09-12 08:48 - 2014-09-12 08:48 - 00000000 ____D () C:\6f5d1ec8960fae795f4fde5054ae23fb 2014-09-12 08:47 - 2014-09-12 08:47 - 00000000 ____D () C:\7e46f57d90b593c6732c97bdcc4042 2014-09-12 08:45 - 2014-09-12 08:46 - 00000000 ____D () C:\5eddcce0319d7a61630ec46999b8db 2014-09-11 12:40 - 2014-08-19 00:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-09-11 12:40 - 2014-08-19 00:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-09-11 12:40 - 2014-08-19 00:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-09-11 12:40 - 2014-08-19 00:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-09-11 12:40 - 2014-08-19 00:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-09-11 12:40 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-09-11 12:40 - 2014-08-18 23:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-09-11 12:40 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-09-11 12:40 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-09-11 12:39 - 2014-08-19 20:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-09-11 12:39 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-09-11 12:39 - 2014-08-19 01:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-09-11 12:39 - 2014-08-19 00:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-09-11 12:39 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-09-11 12:39 - 2014-08-19 00:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-09-11 12:39 - 2014-08-19 00:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-09-11 12:39 - 2014-08-19 00:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-09-11 12:39 - 2014-08-19 00:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-09-11 12:39 - 2014-08-19 00:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-09-11 12:39 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-09-11 12:39 - 2014-08-19 00:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-09-11 12:39 - 2014-08-19 00:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-09-11 12:39 - 2014-08-19 00:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-09-11 12:39 - 2014-08-18 23:56 - 00000000 _____ () C:\Windows\system32\MsSpellCheckingFacility.exe 2014-09-11 12:39 - 2014-08-18 23:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-09-11 12:39 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-09-11 12:39 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-09-11 12:39 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-09-11 12:39 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-09-11 12:39 - 2014-08-18 23:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-09-11 12:39 - 2014-08-18 23:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-09-11 12:39 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-09-11 12:39 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-09-11 12:39 - 2014-08-18 23:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-09-11 12:39 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-09-11 12:39 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-09-11 12:39 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-09-11 12:39 - 2014-08-18 23:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-09-11 12:39 - 2014-08-18 23:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-09-11 12:39 - 2014-08-18 23:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-09-11 12:39 - 2014-08-18 23:23 - 00000000 _____ () C:\Windows\system32\mshtmlmedia.dll 2014-09-11 12:39 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-09-11 12:39 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-09-11 12:39 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-09-11 12:39 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-09-11 12:39 - 2014-08-18 23:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-09-11 12:39 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-09-11 12:39 - 2014-08-18 23:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-09-11 12:39 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-09-11 12:39 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-09-11 12:39 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-09-11 12:39 - 2014-08-18 22:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-09-11 12:39 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-09-11 12:39 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-09-11 12:39 - 2014-08-18 22:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-09-11 12:39 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-09-11 12:35 - 2014-09-11 12:38 - 00000000 ____D () C:\ce6b258f48e4ddd7f3f7f97b7489e3 2014-09-11 01:47 - 2014-09-11 01:47 - 00000000 ____D () C:\1358da8024f54ff604df1b09 2014-09-11 01:46 - 2014-06-27 04:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-09-11 01:46 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2014-09-10 09:59 - 2014-08-01 13:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-09-10 09:59 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-09-10 09:58 - 2014-09-05 04:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-09-10 09:58 - 2014-09-05 04:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-09-10 09:58 - 2014-07-07 04:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-09-10 09:58 - 2014-07-07 04:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-09-10 09:58 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-09-10 09:58 - 2014-07-07 03:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-09-10 09:58 - 2014-07-07 03:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-09-10 09:58 - 2014-06-24 05:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-09-10 09:58 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-08 20:10 - 2014-07-09 11:48 - 00000000 ____D () C:\FRST 2014-10-08 20:10 - 2011-04-21 20:16 - 00001046 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-08 20:09 - 2014-07-09 11:50 - 00024221 _____ () C:\Users\Merix\Downloads\FRST.txt 2014-10-08 19:53 - 2012-05-20 22:35 - 00001058 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3302502354-795164464-2874845416-1001UA.job 2014-10-08 19:52 - 2009-07-14 06:45 - 00022704 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-08 19:52 - 2009-07-14 06:45 - 00022704 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-08 19:44 - 2011-09-10 21:16 - 00190644 _____ () C:\ProgramData\lxeascan.log 2014-10-08 19:44 - 2011-02-20 18:34 - 00000000 ____D () C:\Users\Default\AppData\Local\SoftThinks 2014-10-08 19:44 - 2011-02-20 18:34 - 00000000 ____D () C:\Users\Default User\AppData\Local\SoftThinks 2014-10-08 19:44 - 2010-09-07 20:29 - 00000000 ____D () C:\Program Files (x86)\Dell DataSafe Local Backup 2014-10-08 19:43 - 2014-07-10 11:01 - 00006888 _____ () C:\Windows\setupact.log 2014-10-08 19:43 - 2012-03-02 22:29 - 00065536 _____ () C:\Windows\system32\Ikeext.etl 2014-10-08 19:43 - 2011-04-21 20:16 - 00001042 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-08 19:43 - 2010-09-07 20:26 - 00404966 _____ () C:\Windows\PFRO.log 2014-10-08 19:43 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-08 19:42 - 2010-09-07 19:22 - 01346169 _____ () C:\Windows\WindowsUpdate.log 2014-10-08 19:41 - 2014-07-09 15:05 - 00000000 ____D () C:\AdwCleaner 2014-10-08 19:32 - 2012-03-30 11:12 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-08 19:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing 2014-10-08 19:16 - 2014-08-04 00:52 - 00167936 ___SH () C:\Users\Merix\Desktop\Thumbs.db 2014-10-08 19:14 - 2014-06-18 14:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-10-08 18:48 - 2011-04-21 20:15 - 00000000 ____D () C:\Users\Merix\AppData\Roaming\Skype 2014-10-08 18:01 - 2014-07-09 11:55 - 00074476 _____ () C:\Users\Merix\Downloads\Shortcut.txt 2014-10-08 18:01 - 2014-07-09 11:52 - 00051519 _____ () C:\Users\Merix\Downloads\Addition.txt 2014-10-08 16:53 - 2012-05-20 22:35 - 00001006 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3302502354-795164464-2874845416-1001Core.job 2014-10-08 13:32 - 2014-07-08 17:12 - 00151494 _____ () C:\Users\Merix\Downloads\OTL.Txt 2014-10-08 12:15 - 2014-08-29 10:47 - 00000000 ____D () C:\Users\Merix\AppData\Local\Adobe 2014-10-08 12:13 - 2012-03-30 11:12 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-10-08 12:13 - 2012-03-30 11:12 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-10-08 12:13 - 2011-05-29 23:51 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-10-08 05:30 - 2011-02-22 22:16 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-10-07 22:54 - 2012-04-06 20:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Formularze IPS 2014-10-07 22:54 - 2012-04-06 20:56 - 00000000 ____D () C:\Program Files (x86)\PITy 2014-10-07 22:11 - 2013-03-11 16:47 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-10-07 21:11 - 2010-09-07 20:03 - 00000000 ____D () C:\Program Files (x86)\Creative 2014-10-07 21:11 - 2010-09-07 19:53 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-10-07 15:08 - 2013-05-21 10:48 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-10-07 15:03 - 2011-02-20 18:30 - 00000000 ____D () C:\Users\Merix 2014-10-07 15:01 - 2013-07-23 13:32 - 00000000 ____D () C:\Windows\system32\MRT 2014-09-26 02:42 - 2014-07-29 17:49 - 00000000 ____D () C:\Users\Merix\Documents\POLESIE SP J 2014-09-25 15:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-09-23 20:36 - 2013-10-15 16:16 - 00000000 ____D () C:\Users\Merix\Documents\E+H 2014-09-23 20:36 - 2013-02-27 03:54 - 00000000 ____D () C:\Users\Merix\Documents\WARBUD 2014-09-18 16:35 - 2014-07-30 16:05 - 00000000 ____D () C:\Users\Merix\Documents\MOKATE 2014-09-17 10:17 - 2014-05-17 19:45 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-09-17 10:17 - 2010-09-07 20:31 - 00000000 ____D () C:\ProgramData\Skype 2014-09-16 13:16 - 2014-08-02 14:45 - 00000000 ____D () C:\Users\Merix\Documents\KAZACHSTAN 2014-09-15 09:06 - 2011-09-07 21:50 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-09-11 01:46 - 2014-05-13 22:21 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-09-09 12:42 - 2011-09-10 21:17 - 00000000 ____D () C:\ProgramData\Lx_cats Some content of TEMP: ==================== C:\Users\Merix\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-08 14:28 ==================== End Of Log ============================