Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-10-2016 Ran by Foks (administrator) on DOM-PC (13-10-2016 13:29:21) Running from C:\Users\Foks\Desktop Loaded Profiles: Foks (Available Profiles: Foks) Platform: Microsoft® Windows Vista™ Home Premium (X86) Language: English (United States) Internet Explorer Version 7 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (SigmaTel, Inc.) C:\Windows\System32\stacsv.exe () C:\Windows\System32\WLTRYSVC.EXE (Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe (Dell Inc.) C:\Windows\System32\BCMWLTRY.EXE (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Dell Inc.) C:\Windows\System32\WLTRAY.EXE (Logitech Inc.) C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Akamai Technologies, Inc.) C:\Users\Foks\AppData\Local\Akamai\netsession_win.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\ieuser.exe (Akamai Technologies, Inc.) C:\Users\Foks\AppData\Local\Akamai\netsession_win.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1004136 2006-11-02] (Microsoft Corporation) HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Windows\system32\WLTRAY.exe [2183168 2007-10-09] (Dell Inc.) HKLM\...\Run: [LWS] => C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-11-11] (Logitech Inc.) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7408312 2016-06-27] (AVAST Software) HKLM\...\Run: [MSConfig] => C:\Windows\system32\msconfig.exe [222208 2006-11-02] (Microsoft Corporation) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2159104 2006-11-02] (Microsoft Corporation) HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2159104 2006-11-02] (Microsoft Corporation) HKU\S-1-5-21-2575280359-310499613-3284670713-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Foks\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.) HKU\S-1-5-21-2575280359-310499613-3284670713-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [201728 2006-11-02] (Microsoft Corporation) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-05-06] (AVAST Software) ShellIconOverlayIdentifiers: [GGDriveOverlay1] -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [2012-06-05] (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay2] -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [2012-06-05] (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay3] -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [2012-06-05] (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay4] -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [2012-06-05] (GG Network S.A.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{35C7C820-B6DD-4CD4-950C-10F6F4A3CFAC}: [DhcpNameServer] 89.101.160.5 89.101.160.4 Tcpip\..\Interfaces\{96560DC1-0CDB-40AA-8F56-25C5179903DF}: [DhcpNameServer] 192.168.0.1 ManualProxies: Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz= HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-2575280359-310499613-3284670713-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz= HKU\S-1-5-21-2575280359-310499613-3284670713-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM -> DefaultScope {1b31c9d2-7135-442b-bb93-7c002172adc6} URL = hxxps://uk.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_15_48_orgnl¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Die%26pa%3DHodor%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0DtDzy0CtByCyC0DyBtAtCzzzztN0D0Tzu0StCyEtByEtN1L2XzutAtFtCtAtFyBtFtAtN1L1Czu1M1Q1CtCyDtN1L1G1B1V1N2Y1L1Qzu2StC0FyEtC0AzzzytAtGtD0CtBtAtG0AtByDzytGtDzz0CzytGyEyEtA0FtCyDtC0FyDyDyEtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtCyE0F0C0EyBtCtGtB0DtA0EtGyEtD0F0CtG0ByC0AtBtGtC0CyD0EyCtC0EtA0E0A0BtA2QtN0A0LzuyE%26cr%3D2144159730%26a%3Dhdr_s_15_48_orgnl%26os%3DWindows%2BVista%2B(TM)%2BHome%2BPremium&p={searchTerms} SearchScopes: HKLM -> {1b31c9d2-7135-442b-bb93-7c002172adc6} URL = hxxps://uk.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_15_48_orgnl¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Die%26pa%3DHodor%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0DtDzy0CtByCyC0DyBtAtCzzzztN0D0Tzu0StCyEtByEtN1L2XzutAtFtCtAtFyBtFtAtN1L1Czu1M1Q1CtCyDtN1L1G1B1V1N2Y1L1Qzu2StC0FyEtC0AzzzytAtGtD0CtBtAtG0AtByDzytGtDzz0CzytGyEyEtA0FtCyDtC0FyDyDyEtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtCyE0F0C0EyBtCtGtB0DtA0EtGyEtD0F0CtG0ByC0AtBtGtC0CyD0EyCtC0EtA0E0A0BtA2QtN0A0LzuyE%26cr%3D2144159730%26a%3Dhdr_s_15_48_orgnl%26os%3DWindows%2BVista%2B(TM)%2BHome%2BPremium&p={searchTerms} SearchScopes: HKLM -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-21-2575280359-310499613-3284670713-1000 -> DefaultScope {1b31c9d2-7135-442b-bb93-7c002172adc6} URL = hxxps://uk.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_15_48_orgnl¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Die%26pa%3DHodor%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0DtDzy0CtByCyC0DyBtAtCzzzztN0D0Tzu0StCyEtByEtN1L2XzutAtFtCtAtFyBtFtAtN1L1Czu1M1Q1CtCyDtN1L1G1B1V1N2Y1L1Qzu2StC0FyEtC0AzzzytAtGtD0CtBtAtG0AtByDzytGtDzz0CzytGyEyEtA0FtCyDtC0FyDyDyEtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtCyE0F0C0EyBtCtGtB0DtA0EtGyEtD0F0CtG0ByC0AtBtGtC0CyD0EyCtC0EtA0E0A0BtA2QtN0A0LzuyE%26cr%3D2144159730%26a%3Dhdr_s_15_48_orgnl%26os%3DWindows%2BVista%2B(TM)%2BHome%2BPremium&p={searchTerms} SearchScopes: HKU\S-1-5-21-2575280359-310499613-3284670713-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2575280359-310499613-3284670713-1000 -> {1b31c9d2-7135-442b-bb93-7c002172adc6} URL = hxxps://uk.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_15_48_orgnl¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Die%26pa%3DHodor%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0DtDzy0CtByCyC0DyBtAtCzzzztN0D0Tzu0StCyEtByEtN1L2XzutAtFtCtAtFyBtFtAtN1L1Czu1M1Q1CtCyDtN1L1G1B1V1N2Y1L1Qzu2StC0FyEtC0AzzzytAtGtD0CtBtAtG0AtByDzytGtDzz0CzytGyEyEtA0FtCyDtC0FyDyDyEtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtCyE0F0C0EyBtCtGtB0DtA0EtGyEtD0F0CtG0ByC0AtBtGtC0CyD0EyCtC0EtA0E0A0BtA2QtN0A0LzuyE%26cr%3D2144159730%26a%3Dhdr_s_15_48_orgnl%26os%3DWindows%2BVista%2B(TM)%2BHome%2BPremium&p={searchTerms} SearchScopes: HKU\S-1-5-21-2575280359-310499613-3284670713-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-05-06] (AVAST Software) BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-06-08] (Microsoft Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2016-07-22] (Skype Technologies) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF DefaultProfile: 39gwetqf.default FF ProfilePath: C:\Users\Foks\AppData\Roaming\Mozilla\Firefox\Profiles\39gwetqf.default [2016-10-12] FF Extension: (Firefox Hotfix) - C:\Users\Foks\AppData\Roaming\Mozilla\Firefox\Profiles\39gwetqf.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-10-12] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: (Microsoft .NET Framework Assistant) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-04-21] [not signed] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-05-06] FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-05-06] FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.) Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxps://www.google.ie/?gws_rd=cr,ssl&ei=eLZVVuriMIqVsAG8-4wQ CHR StartupUrls: Default -> "hxxp://www.google.com/" CHR Profile: C:\Users\Foks\AppData\Local\Google\Chrome\User Data\Default [2016-10-13] CHR Extension: (Avast SafePrice) - C:\Users\Foks\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-09-12] CHR Extension: (Avast Online Security) - C:\Users\Foks\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-06-07] CHR Extension: (Skype) - C:\Users\Foks\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-09-23] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Foks\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-04] CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx [2014-08-04] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-05-06] CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09] ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-05-06] (AVAST Software) R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.) R2 STacSV; C:\Windows\system32\STacSV.exe [94208 2007-05-06] (SigmaTel, Inc.) R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [263272 2006-11-02] (Microsoft Corporation) R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [1921024 2007-10-09] (Dell Inc.) [File not signed] U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 61883; C:\Windows\System32\DRIVERS\61883.sys [45696 2006-11-02] (Microsoft Corporation) S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [67768 2016-09-07] (AVAST Software) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [32792 2016-05-06] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [35096 2016-05-06] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [91168 2016-05-06] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [64272 2016-05-06] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [58776 2016-05-06] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [815792 2016-05-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449640 2016-05-06] (AVAST Software) R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [187208 2016-05-06] (AVAST Software) S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [67216 2016-05-06] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [224616 2016-08-05] (AVAST Software) R3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl5.sys [1123328 2007-10-09] (Broadcom Corp.) R3 STHDA; C:\Windows\System32\drivers\stwrt.sys [326656 2007-05-06] (SigmaTel, Inc.) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-10-13 13:29 - 2016-10-13 13:30 - 00016884 _____ C:\Users\Foks\Desktop\FRST.txt 2016-10-13 13:28 - 2016-10-13 13:29 - 00000000 ____D C:\FRST 2016-10-13 13:27 - 2016-10-13 13:27 - 01757184 _____ (Farbar) C:\Users\Foks\Desktop\FRST.exe 2016-10-13 13:26 - 2016-10-13 13:26 - 01757184 _____ (Farbar) C:\Users\Foks\Downloads\Niepotwierdzony 300785.crdownload 2016-10-13 13:21 - 2016-10-13 13:21 - 00313366 _____ C:\Users\Foks\Downloads\WindowsUpdateDiagnostic.diagcab 2016-10-13 13:21 - 2016-10-13 13:21 - 00313366 _____ C:\Users\Foks\Downloads\WindowsUpdateDiagnostic (3).diagcab 2016-10-13 13:21 - 2016-10-13 13:21 - 00313366 _____ C:\Users\Foks\Downloads\WindowsUpdateDiagnostic (2).diagcab 2016-10-13 13:21 - 2016-10-13 13:21 - 00313366 _____ C:\Users\Foks\Downloads\WindowsUpdateDiagnostic (1).diagcab 2016-10-12 16:39 - 2016-10-12 16:50 - 570743456 _____ (Microsoft Corporation) C:\Users\Foks\Downloads\Niepotwierdzony 328176.crdownload 2016-10-12 15:54 - 2016-10-12 15:54 - 11432112 _____ (VS Revo Group ) C:\Users\Foks\Desktop\RevoUninProSetup (1).exe 2016-10-12 15:11 - 2016-10-12 15:11 - 00001610 _____ C:\Users\Foks\Desktop\Snipping Tool.lnk 2016-10-08 10:39 - 2016-10-08 10:39 - 00000477 _____ C:\Users\Foks\Desktop\moja zbieraninka - Shortcut.lnk 2016-10-01 20:39 - 2016-10-01 20:39 - 00143720 _____ C:\Windows\Minidump\Mini100116-01.dmp 2016-09-23 17:38 - 2016-09-23 17:38 - 00000000 ____D C:\Program Files\Common Files\Skype 2016-09-22 13:07 - 2016-09-22 13:07 - 00143720 _____ C:\Windows\Minidump\Mini092216-01.dmp 2016-09-21 08:36 - 2016-09-21 08:36 - 00000000 __SHD C:\found.002 2016-09-13 20:01 - 2016-09-13 20:01 - 05912256 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-10-13 13:01 - 2013-03-17 09:55 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-10-13 13:01 - 2013-02-11 00:19 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-10-13 12:49 - 2006-11-02 13:47 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2016-10-13 12:49 - 2006-11-02 13:47 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2016-10-13 10:56 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\inf 2016-10-13 10:56 - 2006-11-02 11:33 - 00716948 _____ C:\Windows\system32\PerfStringBackup.INI 2016-10-13 10:50 - 2013-02-11 00:19 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-10-13 10:50 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-10-12 19:21 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2016-10-12 18:20 - 2013-06-03 16:28 - 00039936 _____ C:\Users\Foks\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2016-10-12 16:23 - 2013-03-14 17:19 - 00000000 ____D C:\Users\Foks\AppData\Roaming\Real 2016-10-12 16:22 - 2013-03-14 17:20 - 00000000 ____D C:\Program Files\Real 2016-10-12 16:22 - 2013-03-14 17:17 - 00000000 ____D C:\ProgramData\Real 2016-10-12 16:21 - 2013-04-21 11:22 - 00000000 ____D C:\Program Files\Mozilla Firefox 2016-10-12 15:49 - 2013-03-14 19:21 - 00000000 ____D C:\ProgramData\Symantec 2016-10-12 15:49 - 2013-03-14 19:20 - 00000000 ____D C:\ProgramData\Norton 2016-10-12 15:40 - 2013-06-07 21:55 - 00000000 ____D C:\Users\Foks\AppData\Roaming\Azureus 2016-10-12 15:21 - 2016-04-02 11:05 - 00000000 ___SD C:\Users\Foks\AppData\LocalLow\Temp 2016-10-06 11:05 - 2015-05-30 11:22 - 00000000 ____D C:\Users\Foks\Desktop\zdjęcia z pulpitu 2016-10-06 11:03 - 2015-05-30 09:07 - 00000000 ___RD C:\Users\Foks\Desktop\ikonki 2016-10-05 20:41 - 2014-02-17 23:52 - 00000000 ____D C:\Users\Foks\Documents\Vuze Downloads 2016-10-01 20:39 - 2015-12-04 09:32 - 178646687 _____ C:\Windows\MEMORY.DMP 2016-10-01 20:39 - 2013-05-03 21:10 - 00000000 ____D C:\Windows\Minidump 2016-09-23 17:39 - 2013-02-18 12:19 - 00000000 ____D C:\Users\Foks\AppData\Roaming\Skype 2016-09-23 17:39 - 2013-02-18 12:18 - 00000000 ____D C:\ProgramData\Skype 2016-09-13 21:34 - 2013-10-05 11:04 - 00000000 ____D C:\ProgramData\AVG2014 2016-09-13 21:34 - 2013-04-19 21:40 - 00000000 ____D C:\ProgramData\MFAData 2016-09-13 21:25 - 2013-04-19 21:43 - 00000000 ___HD C:\$AVG 2016-09-13 20:02 - 2013-03-17 09:55 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2016-09-13 20:02 - 2013-03-17 09:55 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2016-09-13 20:02 - 2013-03-17 09:55 - 00000000 ____D C:\Windows\system32\Macromed ==================== Files in the root of some directories ======= 2016-03-14 21:32 - 2016-03-14 21:32 - 0024206 _____ () C:\Users\Foks\AppData\Roaming\UserTile.png 2014-07-30 20:45 - 2016-02-17 10:45 - 0000323 _____ () C:\Users\Foks\AppData\Roaming\WB.CFG 2016-05-17 08:25 - 2016-05-17 08:25 - 0000680 _____ () C:\Users\Foks\AppData\Local\d3d9caps.dat 2013-06-03 16:28 - 2016-10-12 18:20 - 0039936 _____ () C:\Users\Foks\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-03-26 09:17 - 2014-03-26 09:17 - 0000000 _____ () C:\Users\Foks\AppData\Local\{463FEF50-09DC-4C90-9395-A41DF4981DE9} 2014-07-18 08:11 - 2014-07-18 08:11 - 0000000 _____ () C:\Users\Foks\AppData\Local\{747F52ED-3A19-40D6-8B03-2AD61BB712D0} 2014-07-19 07:41 - 2014-07-19 07:41 - 0000000 _____ () C:\Users\Foks\AppData\Local\{FA00BD55-23B6-4CF9-BFB4-FD8694F8DB70} Some files in TEMP: ==================== C:\Users\Foks\AppData\Local\Temp\ggdrive-menu.exe C:\Users\Foks\AppData\Local\Temp\ggdrive-overlay.exe C:\Users\Foks\AppData\Local\Temp\i4jdel0.exe C:\Users\Foks\AppData\Local\Temp\installstats.exe C:\Users\Foks\AppData\Local\Temp\SkypeSetup.exe C:\Users\Foks\AppData\Local\Temp\sqlite3.dll C:\Users\Foks\AppData\Local\Temp\{08652845-8459-4C2E-B0C2-177475B959BD}-45.0.2454.99_45.0.2454.93_chrome_updater.exe C:\Users\Foks\AppData\Local\Temp\{1281A702-D8C5-42C6-865D-BE23EA567D46}-44.0.2403.155_chrome_installer.exe C:\Users\Foks\AppData\Local\Temp\{2441F8ED-FCE9-40AF-AE25-647CA8787181}-44.0.2403.157_chrome_installer.exe C:\Users\Foks\AppData\Local\Temp\{9F716B3C-FED3-4FB5-BB2F-0D15128D8840}-48.0.2564.97_chrome_installer.exe C:\Users\Foks\AppData\Local\Temp\{AD180133-91EB-40C9-BBED-E483163FF9BA}-43.0.2357.81_chrome_installer.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-10-13 10:56 ==================== End of FRST.txt ============================