Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:12-08-2015 Ran by Michał (administrator) on MICHAŁ-PC (13-08-2015 16:08:46) Running from C:\Users\Michał\Downloads Loaded Profiles: Michał (Available Profiles: Michał) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: Polski (Polska) Internet Explorer Version 9 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (BitTorrent Inc.) C:\Users\Michał\AppData\Roaming\uTorrent\uTorrent.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (GG Network S.A.) C:\Users\Michał\AppData\Local\GG\Application\gghub.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (GG Network S.A.) C:\Users\Michał\AppData\Local\GG\Application\ggapp.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (GG Network S.A.) C:\Users\Michał\AppData\Local\GG\Application\ggdrive\ggdrive.exe (Electronic Arts) C:\Program Files\Origin\Origin.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\tv_w32.exe (OrdinarySoft) C:\Program Files\Start Menu X\StartMenuX.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Desktop.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\Michał\Downloads\FRST (1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12336856 2015-07-15] (Realtek Semiconductor) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5088456 2015-01-28] (ESET) HKLM\...\Run: [TP-LINK USB Printer Controller] => C:\Program Files\TP-LINK\USB Printer Controller\USB Printer Controller.exe [4226048 2012-09-21] () HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0 HKU\S-1-5-21-716823362-3114543324-878493675-1000\...\Run: [StartMenuX] => C:\Program Files\Start Menu X\StartMenuX.exe [5296960 2014-11-08] (OrdinarySoft) HKU\S-1-5-21-716823362-3114543324-878493675-1000\...\Run: [uTorrent] => C:\Users\Michał\AppData\Roaming\uTorrent\uTorrent.exe [1693024 2015-08-02] (BitTorrent Inc.) HKU\S-1-5-21-716823362-3114543324-878493675-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31682144 2015-03-25] (Skype Technologies S.A.) HKU\S-1-5-21-716823362-3114543324-878493675-1000\...\Run: [GG] => C:\Users\Michał\AppData\Local\GG\Application\gghub.exe [4078144 2015-06-17] (GG Network S.A.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-716823362-3114543324-878493675-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-716823362-3114543324-878493675-1000 -> {AF75D331-4163-451E-A7F2-075F59C51C79} URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&q={searchTerms}&src=IE-SearchBox BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-07-15] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-15] (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2008-03-27] (Hewlett-Packard Co.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0 Tcpip\..\Interfaces\{2CD7A4D3-BE73-4980-A027-8A8CDD9DB8ED}: [DhcpNameServer] 192.168.1.1 0.0.0.0 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] () FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-15] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-15] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-09-01] FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2013-09-06] FF HKU\S-1-5-21-716823362-3114543324-878493675-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 Chrome: ======= CHR Profile: C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-28] CHR Extension: (Google Docs) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-28] CHR Extension: (Google Drive) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-28] CHR Extension: (Skype Calling) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2015-08-03] CHR Extension: (YouTube) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-28] CHR Extension: (Google Search) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-28] CHR Extension: (Google Sheets) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-28] CHR Extension: (Google Mail Checker) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-12-28] CHR Extension: (Chrome Web Store Payments) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-28] CHR Extension: (Gmail) - C:\Users\Michał\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-28] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1349576 2015-01-28] (ESET) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2008-03-25] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [135168 2008-03-25] (Hewlett-Packard Co.) [File not signed] S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed] U2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [2007048 2015-07-26] (Electronic Arts) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed] R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5611280 2015-08-07] (TeamViewer GmbH) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [43296 2014-12-15] (AVG Technologies) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [193464 2015-02-23] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [135808 2015-02-23] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [176448 2015-02-23] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [37928 2015-02-23] (ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [51824 2015-02-23] (ESET) S3 gdrv; C:\Windows\gdrv.sys [16608 2013-09-04] (Windows (R) 2000 DDK provider) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2014-12-22] (REALiX(tm)) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project) R3 TPLINKUDSMBus; C:\Windows\System32\drivers\TplinkUDSMBus.sys [88576 2012-09-21] (Windows (R) Codename Longhorn DDK provider) S3 TplinkUDSTcpBus; C:\Windows\System32\drivers\TplinkUDSTcpBus.sys [151296 2012-09-21] (Windows (R) Codename Longhorn DDK provider) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-08-13 16:08 - 2015-08-13 16:08 - 01677824 _____ (Farbar) C:\Users\Michał\Downloads\FRST (1).exe 2015-08-13 15:34 - 2015-08-13 15:37 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-08-13 15:33 - 2015-08-13 15:36 - 00000899 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2015-08-13 15:33 - 2015-08-13 15:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-08-13 15:33 - 2015-08-13 15:36 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware 2015-08-13 15:33 - 2015-08-13 15:33 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-08-13 15:33 - 2015-06-18 09:47 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-08-13 15:33 - 2015-06-18 09:47 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-08-13 15:33 - 2015-06-18 09:47 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-08-13 14:57 - 2015-08-13 15:09 - 733480960 _____ C:\Users\Michał\Downloads\The Longest Ride (2015) PL.BRRip.XviD-OzW.avi 2015-08-12 19:02 - 2015-08-12 19:02 - 02248704 _____ C:\Users\Michał\Downloads\AdwCleaner.exe 2015-08-12 18:58 - 2015-08-12 18:59 - 21545336 _____ (Malwarebytes Corporation ) C:\Users\Michał\Desktop\mbam-setup-sem-2.1.6.1022.exe 2015-08-12 18:43 - 2015-08-12 18:44 - 00030195 _____ C:\Users\Michał\Downloads\Addition.txt 2015-08-12 18:42 - 2015-08-13 16:08 - 00013056 _____ C:\Users\Michał\Downloads\FRST.txt 2015-08-12 18:41 - 2015-08-12 18:41 - 01676288 _____ (Farbar) C:\Users\Michał\Downloads\FRST.exe 2015-08-12 18:01 - 2015-08-12 18:05 - 00002425 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2015-08-12 18:01 - 2015-08-12 18:01 - 00001892 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2015-08-12 17:59 - 2015-08-12 18:00 - 38966928 _____ (Adobe Systems Incorporated) C:\Users\Michał\Downloads\AdbeRdr11000_pl_PL.exe 2015-08-12 17:57 - 2015-07-15 23:04 - 00273504 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2015-08-12 15:48 - 2015-07-21 22:55 - 01206192 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-08-12 15:48 - 2015-07-21 18:07 - 03605440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-08-12 15:48 - 2015-07-21 18:07 - 03553216 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-08-12 15:48 - 2015-07-21 18:07 - 00140224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ecache.sys 2015-08-12 15:48 - 2015-07-21 18:07 - 00056256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2015-08-12 15:48 - 2015-07-21 18:03 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\emdmgmt.dll 2015-08-12 15:48 - 2015-07-21 18:03 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-08-12 15:48 - 2015-07-21 18:03 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2015-08-12 15:46 - 2015-07-31 21:27 - 00103120 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-08-12 15:46 - 2015-07-09 16:20 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2015-08-12 15:45 - 2015-07-10 21:37 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2015-08-12 15:43 - 2015-07-11 17:56 - 11587584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-08-12 15:36 - 2015-07-18 18:03 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll 2015-08-12 15:35 - 2015-07-10 21:37 - 01402368 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2015-08-12 15:35 - 2015-07-10 21:37 - 01253376 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2015-08-12 15:34 - 2015-08-01 00:08 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-08-12 15:34 - 2015-07-31 23:46 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2015-08-12 15:34 - 2015-07-31 23:46 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2015-08-12 15:34 - 2015-07-31 23:46 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2015-08-12 15:34 - 2015-07-31 23:46 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2015-08-12 15:34 - 2015-07-31 22:41 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2015-08-12 15:34 - 2015-07-31 22:40 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2015-08-12 15:34 - 2015-07-31 22:35 - 00682496 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2015-08-12 15:34 - 2015-07-31 22:33 - 02066944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-08-12 15:34 - 2015-07-31 22:33 - 01072640 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2015-08-12 15:34 - 2015-07-31 22:33 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2015-08-12 15:34 - 2015-07-31 22:33 - 00297472 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-08-12 15:33 - 2015-07-01 17:57 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2015-08-12 15:32 - 2015-07-09 16:25 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe 2015-08-12 15:32 - 2015-07-09 16:25 - 00151040 _____ (Microsoft Corporation) C:\Windows\notepad.exe 2015-08-12 12:47 - 2015-07-22 22:54 - 12386816 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-08-12 12:47 - 2015-07-22 22:54 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-08-12 12:47 - 2015-07-22 22:51 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-08-12 12:47 - 2015-07-22 22:47 - 09751040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-08-12 12:47 - 2015-07-22 22:46 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-08-12 12:47 - 2015-07-22 22:46 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-08-12 12:47 - 2015-07-22 22:45 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-08-12 12:47 - 2015-07-22 22:45 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2015-08-12 12:47 - 2015-07-22 22:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-08-12 12:47 - 2015-07-22 22:44 - 01804288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-08-12 12:47 - 2015-07-22 22:44 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-08-12 12:47 - 2015-07-22 22:44 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-08-12 12:47 - 2015-07-22 22:44 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-08-12 12:47 - 2015-07-22 22:44 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-08-12 12:47 - 2015-07-22 22:43 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-08-12 12:47 - 2015-07-22 22:43 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-08-12 12:47 - 2015-07-22 22:43 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-08-12 12:47 - 2015-07-22 22:43 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-08-12 12:47 - 2015-07-22 22:43 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2015-08-12 12:47 - 2015-07-22 22:43 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2015-08-12 12:47 - 2015-07-22 22:43 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2015-08-12 12:47 - 2015-07-22 22:42 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-08-05 00:03 - 2015-08-05 00:03 - 00877152 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll 2015-08-05 00:03 - 2015-08-05 00:03 - 00538208 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll 2015-07-20 16:51 - 2012-09-21 09:46 - 00088576 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\Drivers\TplinkUDSMBus.sys 2015-07-20 16:51 - 2012-09-21 09:43 - 00151296 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\Drivers\TplinkUDSTcpBus.sys 2015-07-20 16:50 - 2015-07-20 16:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK 2015-07-20 16:50 - 2015-07-20 16:50 - 00000000 ____D C:\Program Files\TP-LINK 2015-07-20 15:20 - 2015-08-13 16:08 - 00000000 ____D C:\FRST 2015-07-16 23:37 - 2015-07-16 23:37 - 00000000 ____D C:\Users\Michał\AppData\Roaming\ESET 2015-07-16 23:28 - 2015-07-16 23:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET 2015-07-16 23:28 - 2015-07-16 23:28 - 00000000 ____D C:\ProgramData\ESET 2015-07-16 23:28 - 2015-07-16 23:28 - 00000000 ____D C:\Program Files\ESET 2015-07-15 23:37 - 2015-07-15 23:37 - 00000943 _____ C:\Users\Michał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GG.lnk 2015-07-15 23:37 - 2015-07-15 23:37 - 00000935 _____ C:\Users\Michał\Desktop\GG.lnk 2015-07-15 23:31 - 2015-07-15 23:31 - 00002489 _____ C:\Users\Public\Desktop\Skype.lnk 2015-07-15 23:31 - 2015-07-15 23:31 - 00000000 ____D C:\ProgramData\Skype 2015-07-15 23:31 - 2015-07-15 23:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-07-15 23:31 - 2015-07-15 23:31 - 00000000 ____D C:\Program Files\Common Files\Skype 2015-07-15 23:29 - 2015-07-15 23:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-07-15 23:27 - 2015-08-12 17:32 - 00001036 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-15 23:27 - 2015-08-12 16:18 - 00001032 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-15 22:31 - 2015-07-03 18:04 - 01316864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2015-07-15 22:31 - 2015-06-17 18:50 - 02264576 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2015-07-15 22:31 - 2015-06-17 17:09 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2015-07-15 22:31 - 2015-06-12 18:01 - 00298496 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-07-15 22:19 - 2015-05-31 10:11 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll 2015-07-15 22:18 - 2015-06-27 18:03 - 00783872 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-07-15 22:18 - 2015-06-27 18:02 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-07-15 22:18 - 2015-06-27 18:02 - 00218112 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-07-15 22:18 - 2015-06-27 18:01 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-07-15 22:18 - 2015-06-27 16:21 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2015-07-15 22:18 - 2015-06-27 16:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-07-15 22:18 - 2015-06-12 15:13 - 00440768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-07-15 22:18 - 2015-01-09 02:17 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-07-15 21:58 - 2015-07-15 21:58 - 00000000 ____D C:\Windows\system32\DAX2 2015-07-15 21:56 - 2015-07-15 21:56 - 03522264 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHDA.sys 2015-07-15 21:56 - 2015-07-15 21:56 - 02637528 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSndMgr.cpl 2015-07-15 21:56 - 2015-07-15 21:56 - 02394328 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll 2015-07-15 21:56 - 2015-07-15 21:56 - 01708248 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInstII.dll 2015-07-15 21:55 - 2015-07-15 21:55 - 11899824 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO30.dll 2015-07-15 21:55 - 2015-07-15 21:55 - 05073344 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV2apo.dll 2015-07-15 21:55 - 2015-07-15 21:55 - 02862488 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT 2015-07-15 21:55 - 2015-07-15 21:55 - 02820120 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll 2015-07-15 21:55 - 2015-07-15 21:55 - 01861976 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv211.dll 2015-07-15 21:55 - 2015-07-15 21:55 - 01782616 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv201.dll 2015-07-15 21:55 - 2015-07-15 21:55 - 01490960 _____ (Conexant Systems Inc.) C:\Windows\system32\CX32APO.dll 2015-07-15 21:55 - 2015-07-15 21:55 - 01160112 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO60.dll 2015-07-15 21:55 - 2015-07-15 21:55 - 01010096 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO50.dll 2015-07-15 21:55 - 2015-07-15 21:55 - 00973232 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO40.dll 2015-07-15 21:55 - 2015-07-15 21:55 - 00850264 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOProp.dll 2015-07-15 21:55 - 2015-07-15 21:55 - 00818096 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO20.dll 2015-07-15 21:55 - 2015-07-15 21:55 - 00294744 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2API.dll 2015-07-15 19:24 - 2015-07-15 19:38 - 00000754 _____ C:\Users\Michał\Desktop\TP-LINK Modem Router Settings.txt 2015-07-15 14:53 - 2015-07-15 14:53 - 00000000 ____D C:\Users\Michał\AppData\Local\TuneUp Software ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-08-13 16:08 - 2013-09-01 16:59 - 00000000 ____D C:\Users\Michał\AppData\Roaming\uTorrent 2015-08-13 15:20 - 2006-11-02 14:47 - 00004576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-08-13 15:20 - 2006-11-02 14:47 - 00004576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-08-13 11:28 - 2014-09-28 18:35 - 00000000 ____D C:\ProgramData\Origin 2015-08-13 11:28 - 2008-01-21 03:35 - 01405336 _____ C:\Windows\WindowsUpdate.log 2015-08-13 11:23 - 2014-09-14 19:17 - 00000000 ____D C:\Users\Michał\AppData\Roaming\GG 2015-08-13 11:20 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-08-12 23:31 - 2006-11-02 15:01 - 00032610 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2015-08-12 19:03 - 2013-09-20 21:47 - 00000000 ____D C:\AdwCleaner 2015-08-12 18:11 - 2015-07-07 19:24 - 00923010 _____ C:\Windows\PFRO.log 2015-08-12 18:01 - 2015-04-15 15:58 - 00000000 ____D C:\Program Files\Common Files\Adobe 2015-08-12 18:01 - 2013-09-06 19:22 - 00000000 ____D C:\Program Files\Adobe 2015-08-12 18:01 - 2013-09-06 19:21 - 00000000 ____D C:\ProgramData\Adobe 2015-08-12 17:57 - 2014-12-22 12:35 - 00000000 ____D C:\Program Files\Java 2015-08-12 17:53 - 2013-09-01 14:48 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2015-08-12 17:43 - 2013-09-01 16:01 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-08-12 17:27 - 2013-09-01 16:01 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-08-12 17:27 - 2013-09-01 16:01 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-08-12 16:41 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2015-08-12 16:32 - 2014-12-31 16:14 - 00000840 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2015-08-12 16:32 - 2014-12-31 16:14 - 00000828 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk 2015-08-12 16:32 - 2014-12-31 16:14 - 00000000 ____D C:\Program Files\TeamViewer 2015-08-12 16:15 - 2015-06-17 11:31 - 00274680 _____ C:\Windows\system32\FNTCACHE.DAT 2015-08-12 16:13 - 2013-09-22 15:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2015-08-12 16:12 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2015-08-12 15:49 - 2013-10-26 12:04 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-08-12 15:48 - 2013-09-22 15:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-08-12 15:42 - 2013-09-01 16:47 - 00000000 ____D C:\Windows\system32\MRT 2015-08-12 15:37 - 2006-11-02 12:24 - 129304528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2015-08-09 18:51 - 2014-05-14 23:05 - 00000000 ____D C:\Users\Michał\AppData\Local\CrashDumps 2015-08-06 18:25 - 2008-01-21 08:24 - 01616086 _____ C:\Windows\system32\PerfStringBackup.INI 2015-08-06 18:25 - 2008-01-21 08:24 - 00702924 _____ C:\Windows\system32\perfh015.dat 2015-08-06 18:25 - 2008-01-21 08:24 - 00147696 _____ C:\Windows\system32\perfc015.dat 2015-08-06 16:28 - 2013-09-01 15:51 - 00000000 ____D C:\Users\Michał\AppData\Roaming\ProcessLasso 2015-08-06 16:28 - 2013-09-01 15:51 - 00000000 ____D C:\Program Files\Process Lasso 2015-08-05 10:41 - 2015-07-08 19:53 - 00000000 ____D C:\Users\Michał\AppData\Roaming\Skype 2015-08-03 11:58 - 2013-10-26 12:09 - 00002625 _____ C:\Users\Michał\Desktop\Microsoft Office Word 2007.lnk 2015-08-02 18:57 - 2012-09-26 13:22 - 00000000 ____D C:\Users\Michał\Desktop\ZDJĘCIA 2015-08-02 16:34 - 2013-09-02 14:08 - 00000000 ____D C:\ProgramData\Zoom Player 2015-07-26 12:37 - 2014-09-28 18:34 - 00000000 ____D C:\Program Files\Origin 2015-07-24 20:47 - 2014-12-22 11:49 - 00001927 _____ C:\Users\Public\Desktop\Driver Booster 2.lnk 2015-07-24 20:46 - 2014-08-17 15:29 - 00000000 ____D C:\ProgramData\Package Cache 2015-07-24 20:34 - 2014-12-22 11:49 - 00000000 ____D C:\ProgramData\ProductData 2015-07-24 20:32 - 2014-12-22 11:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2 2015-07-22 22:49 - 2015-01-29 18:51 - 00000000 ____D C:\Program Files\FreeTime 2015-07-20 16:51 - 2013-09-01 14:44 - 00000000 ____D C:\Users\Michał 2015-07-17 23:19 - 2013-09-01 18:07 - 00104448 _____ C:\Users\Michał\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-07-16 23:37 - 2013-12-15 20:03 - 00000000 ____D C:\Users\Michał\AppData\Local\ESET 2015-07-15 23:37 - 2014-09-14 19:17 - 00000000 ____D C:\Users\Michał\AppData\Local\GG 2015-07-15 23:31 - 2015-07-08 19:53 - 00000000 ___RD C:\Program Files\Skype 2015-07-15 23:28 - 2013-09-01 15:01 - 00000000 ____D C:\Program Files\Google 2015-07-15 23:20 - 2013-12-16 21:15 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2015-07-15 23:04 - 2014-12-22 12:35 - 00191584 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2015-07-15 23:04 - 2014-12-22 12:35 - 00190560 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2015-07-15 23:04 - 2014-12-22 12:35 - 00096352 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2015-07-15 22:46 - 2013-12-31 17:50 - 00000000 ____D C:\Users\Michał\AppData\Roaming\.minecraft 2015-07-15 22:34 - 2013-09-01 14:54 - 00000000 ____D C:\Windows\system32\RTCOM 2015-07-15 22:00 - 2014-03-12 21:48 - 00000000 ____D C:\Program Files\Common Files\Adobe AIR 2015-07-15 21:55 - 2014-12-22 12:23 - 02585816 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO.dll 2015-07-15 21:32 - 2006-11-02 12:22 - 92274688 _____ C:\Windows\system32\config\system_previous 2015-07-15 21:32 - 2006-11-02 12:22 - 47710208 _____ C:\Windows\system32\config\software_previous 2015-07-15 21:32 - 2006-11-02 12:22 - 41680896 _____ C:\Windows\system32\config\components_previous 2015-07-15 21:32 - 2006-11-02 12:22 - 00524288 _____ C:\Windows\system32\config\default_previous 2015-07-15 21:32 - 2006-11-02 12:22 - 00053248 _____ C:\Windows\system32\config\sam_previous 2015-07-15 21:32 - 2006-11-02 12:22 - 00020480 _____ C:\Windows\system32\config\security_previous 2015-07-15 21:31 - 2014-03-16 12:43 - 00000000 ____D C:\Users\Michał\AppData\Roaming\Winamp 2015-07-15 21:31 - 2014-02-03 21:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YoWindow 2015-07-15 21:31 - 2014-02-03 21:42 - 00000000 ____D C:\Program Files\YoWindow 2015-07-15 21:31 - 2013-09-01 16:16 - 00000000 ____D C:\Users\Michał\AppData\Local\PrivaZer 2015-07-15 21:31 - 2006-11-02 13:18 - 00000000 __RSD C:\Windows\Media 2015-07-15 21:31 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\spool 2015-07-15 21:30 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\registration 2015-07-15 19:58 - 2015-07-08 19:41 - 00000000 ____D C:\Program Files\NirSoft 2015-07-15 14:57 - 2015-07-10 23:10 - 00000000 ____D C:\Program Files\TuneUp Utilities 2014 ==================== Files in the root of some directories ======= 2013-09-20 10:43 - 2013-09-20 11:18 - 0000000 _____ () C:\Users\Michał\AppData\Roaming\bitlord_log.txt 2013-10-13 16:07 - 2013-10-14 15:07 - 0000088 _____ () C:\Users\Michał\AppData\Roaming\WB.CFG 2013-09-01 14:44 - 2015-05-30 19:54 - 0002032 _____ () C:\Users\Michał\AppData\Local\d3d9caps.dat 2013-09-01 18:07 - 2015-07-17 23:19 - 0104448 _____ () C:\Users\Michał\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-11-28 00:08 - 2014-11-28 00:09 - 0000600 _____ () C:\Users\Michał\AppData\Local\PUTTY.RND 2014-01-19 13:58 - 2014-01-19 13:58 - 0017408 _____ () C:\Users\Michał\AppData\Local\WebpageIcons.db 2014-12-22 12:28 - 2014-12-22 12:28 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2013-09-26 15:21 - 2013-09-26 15:21 - 0000438 _____ () C:\ProgramData\fontcacheev1.dat 2013-09-05 20:20 - 2013-09-05 20:20 - 0000100 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc Some files in TEMP: ==================== C:\Users\Michał\AppData\Local\Temp\Quarantine.exe C:\Users\Michał\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-08-13 11:33 ==================== End of log ============================