Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013 Ran by Ola Koszyk (administrator) on OLAKOSZYK on 14-10-2013 18:44:03 Running from C:\Users\Ola Koszyk\Desktop Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Polish Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE (ASUS) C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe () C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\WDC.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HControlUser] - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM\...\Run: [ATKMEDIA] - C:\Program Files\ASUS\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS) HKLM\...\Run: [ATKOSD2] - C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS) HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2029640 2009-05-14] (ESET) HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated) HKLM\...\Run: [hpqSRMon] - C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKCU\...\Run: [BitComet] - C:\Program Files\BitComet\BitComet.exe [12805888 2013-02-19] (www.BitComet.com) HKCU\...\Run: [GG] - C:\Users\Ola Koszyk\AppData\Local\GG\Application\gghub.exe [4009024 2013-09-16] (GG Network S.A.) HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-01-14] (Google Inc.) MountPoints2: {f5fe5ccd-3bb6-11e1-858e-806e6f6e6963} - F:\setup.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ SearchScopes: HKLM - DefaultScope value is missing. BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Chrome: ======= CHR RestoreOnStartup: "urls_to_restore_on_startup": null CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\30.0.1599.69\pdf.dll () CHR Plugin: (BitCometAgent) - C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll (BitComet) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Java(TM) Platform SE 7 U5) - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll () CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Extension: (Chrome In-App Payments service) - C:\Users\OLAKOS~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 ========================== Services (Whitelisted) ================= R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS) R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2010-12-28] (www.BitComet.com) S3 EhttpSrv; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [20680 2009-05-14] (ESET) R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [731840 2009-05-14] (ESET) R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () ==================== Drivers (Whitelisted) ==================== R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [239168 2012-01-10] (DT Soft Ltd) R2 eamon; C:\Windows\System32\DRIVERS\eamon.sys [114472 2009-05-14] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [107256 2009-05-14] (ESET) R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [93312 2009-05-14] (ESET) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2012-01-10] ( ) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [14392 2012-01-10] (ASUS) S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-14 18:42 - 2013-10-14 18:39 - 00448512 _____ (OldTimer Tools) C:\Users\Ola Koszyk\Desktop\TFC.exe 2013-10-14 18:40 - 2013-10-14 18:40 - 00006950 _____ C:\Users\Ola Koszyk\Desktop\AdwCleaner[S0].txt 2013-10-14 18:36 - 2013-10-14 18:38 - 00000000 ____D C:\AdwCleaner 2013-10-14 18:36 - 2013-10-14 18:34 - 01048960 _____ C:\Users\Ola Koszyk\Desktop\AdwCleaner.exe 2013-10-13 18:40 - 2013-10-13 18:40 - 00000632 _____ C:\Windows\PFRO.log 2013-10-12 19:29 - 2013-10-12 19:30 - 00007552 _____ C:\Users\Ola Koszyk\Desktop\gmer.txt 2013-10-12 18:54 - 2013-10-12 18:26 - 00377856 _____ C:\Users\Ola Koszyk\Desktop\gtd35n2v.exe 2013-10-12 18:53 - 2013-10-12 18:53 - 00017245 _____ C:\Users\Ola Koszyk\Desktop\Addition.txt 2013-10-12 18:51 - 2013-10-14 18:16 - 00000000 ____D C:\FRST 2013-10-12 18:51 - 2013-10-12 18:25 - 01087213 _____ (Farbar) C:\Users\Ola Koszyk\Desktop\FRST.exe 2013-10-12 18:49 - 2013-10-12 18:49 - 00052258 _____ C:\Users\Ola Koszyk\Desktop\Extras.Txt 2013-10-12 18:46 - 2013-10-12 18:46 - 00128748 _____ C:\Users\Ola Koszyk\Desktop\OTL.Txt 2013-10-12 18:28 - 2013-10-12 18:26 - 00602112 _____ (OldTimer Tools) C:\Users\Ola Koszyk\Desktop\OTL.exe 2013-09-16 18:24 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-16 18:24 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-16 18:24 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-16 18:24 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-16 18:24 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-16 18:24 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-16 18:02 - 2013-10-12 18:14 - 00000000 ____D C:\Users\Ola Koszyk\Desktop\Nowy folder 2013-09-16 17:53 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-16 17:53 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-16 17:53 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-16 17:53 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-16 17:53 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-16 17:53 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-16 17:53 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll ==================== One Month Modified Files and Folders ======= 2013-10-14 18:40 - 2013-10-14 18:40 - 00006950 _____ C:\Users\Ola Koszyk\Desktop\AdwCleaner[S0].txt 2013-10-14 18:40 - 2012-01-14 23:44 - 00001040 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-14 18:40 - 2012-01-10 22:43 - 00000000 ____D C:\Users\Ola Koszyk\AppData\Roaming\Mozilla 2013-10-14 18:39 - 2013-10-14 18:42 - 00448512 _____ (OldTimer Tools) C:\Users\Ola Koszyk\Desktop\TFC.exe 2013-10-14 18:39 - 2013-08-29 21:48 - 00002410 _____ C:\Windows\setupact.log 2013-10-14 18:39 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-14 18:38 - 2013-10-14 18:36 - 00000000 ____D C:\AdwCleaner 2013-10-14 18:38 - 2012-09-20 18:58 - 00000000 ____D C:\ProgramData\Uniblue 2013-10-14 18:38 - 2012-01-10 20:17 - 01885218 _____ C:\Windows\WindowsUpdate.log 2013-10-14 18:37 - 2012-01-15 00:01 - 00000000 ____D C:\Users\Ola Koszyk\AppData\Roaming\BitComet 2013-10-14 18:37 - 2012-01-10 20:58 - 01549932 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-14 18:37 - 2009-07-14 10:07 - 00698146 _____ C:\Windows\system32\perfh015.dat 2013-10-14 18:37 - 2009-07-14 10:07 - 00135224 _____ C:\Windows\system32\perfc015.dat 2013-10-14 18:34 - 2013-10-14 18:36 - 01048960 _____ C:\Users\Ola Koszyk\Desktop\AdwCleaner.exe 2013-10-14 18:32 - 2012-01-10 22:42 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-14 18:23 - 2012-11-24 12:40 - 00000000 ____D C:\Windows\system32\appmgmt 2013-10-14 18:22 - 2013-06-12 20:26 - 00000000 ____D C:\Users\Ola Koszyk\AppData\Roaming\GG 2013-10-14 18:16 - 2013-10-12 18:51 - 00000000 ____D C:\FRST 2013-10-14 18:16 - 2012-01-10 20:45 - 00000000 ____D C:\Users\Ola Koszyk 2013-10-13 18:49 - 2012-01-14 23:52 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-13 18:40 - 2013-10-13 18:40 - 00000632 _____ C:\Windows\PFRO.log 2013-10-12 20:05 - 2009-07-14 06:34 - 00010128 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-12 20:05 - 2009-07-14 06:34 - 00010128 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-12 19:30 - 2013-10-12 19:29 - 00007552 _____ C:\Users\Ola Koszyk\Desktop\gmer.txt 2013-10-12 18:53 - 2013-10-12 18:53 - 00017245 _____ C:\Users\Ola Koszyk\Desktop\Addition.txt 2013-10-12 18:49 - 2013-10-12 18:49 - 00052258 _____ C:\Users\Ola Koszyk\Desktop\Extras.Txt 2013-10-12 18:46 - 2013-10-12 18:46 - 00128748 _____ C:\Users\Ola Koszyk\Desktop\OTL.Txt 2013-10-12 18:26 - 2013-10-12 18:54 - 00377856 _____ C:\Users\Ola Koszyk\Desktop\gtd35n2v.exe 2013-10-12 18:26 - 2013-10-12 18:28 - 00602112 _____ (OldTimer Tools) C:\Users\Ola Koszyk\Desktop\OTL.exe 2013-10-12 18:25 - 2013-10-12 18:51 - 01087213 _____ (Farbar) C:\Users\Ola Koszyk\Desktop\FRST.exe 2013-10-12 18:18 - 2012-01-14 16:27 - 00811520 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2013-10-12 18:18 - 2012-01-14 16:26 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll 2013-10-12 18:18 - 2012-01-14 16:26 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll 2013-10-12 18:14 - 2013-09-16 18:02 - 00000000 ____D C:\Users\Ola Koszyk\Desktop\Nowy folder 2013-10-12 18:14 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\wfp 2013-10-12 18:13 - 2012-01-10 22:43 - 00000000 ____D C:\Users\Ola Koszyk\AppData\Local\Mozilla 2013-10-12 18:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration 2013-10-12 18:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-10-06 20:34 - 2012-01-10 20:13 - 00000000 ____D C:\Windows\Panther 2013-09-17 16:37 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-09-16 19:11 - 2013-06-12 20:26 - 00000000 ____D C:\Users\Ola Koszyk\AppData\Local\GG 2013-09-16 19:09 - 2009-07-14 06:33 - 00407824 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-16 19:07 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\pl-PL 2013-09-16 18:23 - 2013-08-15 11:15 - 00000000 ____D C:\Windows\system32\MRT 2013-09-16 18:21 - 2012-01-10 23:22 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-13 20:24 ==================== End Of Log ============================