[code] HitmanPro www.hitmanpro.com Computer name . . . . : JACEK-PC Windows . . . . . . . : User name . . . . . . : Jacek-PC\Jacek UAC . . . . . . . . . : Enabled License . . . . . . . : Free Scan date . . . . . . : 2015-12-12 21:28:58 Scan mode . . . . . . : Normal Scan duration . . . . : 4m 58s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 0 Traces . . . . . . . : 14 Objects scanned . . . : 1 251 351 Files scanned . . . . : 47 444 Remnants scanned . . : 280 223 files / 923 684 keys Suspicious files ____________________________________________________________ C:\FRST\FRST.exe Size . . . . . . . : 1 720 320 bytes Age . . . . . . . : 1.5 days (2015-12-11 08:55:52) Entropy . . . . . : 7.5 SHA-256 . . . . . : B1E92BC3FC04C3D5009C2C38F5997872096364F07E74ACA9323E5115744C155F Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Potential Unwanted Programs _________________________________________________ HKLM\SOFTWARE\Microsoft\Tracing\SoftonicAssistant_v0-1-6_RASAPI32\ (Softonic) HKLM\SOFTWARE\Microsoft\Tracing\SoftonicAssistant_v0-1-6_RASMANCS\ (Softonic) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{444785F1-DE89-4295-863A-D46C3A781394}\ (IQIYI) HKLM\SOFTWARE\Systweak\ (AdvSysProtector) HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B} (Claro) HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC} (Claro) HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B} (Claro) HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC} (Claro) HKU\S-1-5-21-1679813524-3586070068-693276116-1000\Software\AppDataLow\Software\SmartBar\ (Conduit) HKU\S-1-5-21-1679813524-3586070068-693276116-1000\Software\systweak\ (AdvSysProtector) Cookies _____________________________________________________________________ C:\Users\Jacek\AppData\Roaming\Mozilla\Firefox\Profiles\yjh9ixf4.default-1449868033425\cookies.sqlite:atdmt.com C:\Users\Jacek\AppData\Roaming\Mozilla\Firefox\Profiles\yjh9ixf4.default-1449868033425\cookies.sqlite:doubleclick.net C:\Users\Jacek\AppData\Roaming\Mozilla\Firefox\Profiles\yjh9ixf4.default-1449868033425\cookies.sqlite:liverail.com [/code]