Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-02-2014 01 Ran by Przemek (administrator) on PRZEMEK-PC on 25-02-2014 13:44:40 Running from C:\Users\Przemek\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 10 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe () C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Foxit Corporation) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe (Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWlan.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe (H+H Software GmbH) C:\Program Files\Phantom Drive\VBurnSecs64.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe (H+H Software GmbH) C:\Program Files\Phantom Drive\vbtray64.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe (O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodtray.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe (Panda Security) C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [itype] - C:\Program Files\Microsoft IntelliType Pro\itype.exe [1860496 2011-04-13] (Microsoft Corporation) HKLM\...\Run: [VBTray] - C:\Program Files\Phantom Drive\vbtray64.exe [1064280 2010-12-07] (H+H Software GmbH) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7406392 2012-11-29] (Logitech Inc.) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13662936 2013-10-24] (Realtek Semiconductor) HKLM\...\Run: [Bdagent] - C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1737920 2014-01-27] (Bitdefender) HKLM\...\Run: [OODefragTray] - C:\Program Files\OO Software\Defrag\oodtray.exe [7074088 2013-10-23] (O&O Software GmbH) HKU\.DEFAULT\...\Run: [Bitdefender Wallet Agent] - C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [567888 2014-02-07] (Bitdefender) HKU\.DEFAULT\...\Run: [Bitdefender Wallet] - C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1001536 2014-02-07] (Bitdefender) HKU\.DEFAULT\...\Run: [Bitdefender Wallet Application Agent] - C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614232 2014-02-07] (Bitdefender) HKU\S-1-5-21-1487543532-575357134-2409244344-1000\...\Run: [Bitdefender Wallet Agent] - C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [567888 2014-02-07] (Bitdefender) HKU\S-1-5-21-1487543532-575357134-2409244344-1000\...\Run: [Bitdefender Wallet Application Agent] - C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614232 2014-02-07] (Bitdefender) HKU\S-1-5-21-1487543532-575357134-2409244344-1000\...\Policies\Explorer: [NoViewContextMenu] 0 IFEO\taskmgr.exe: [Debugger] "C:\PROGRAMY\PROCEXP.EXE" ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {572F492A-8B15-4530-9CCB-265B3B495DCC} URL = http://www.google.com/search?hl=pl&q={searchTerms} SearchScopes: HKCU - {572F492A-8B15-4530-9CCB-265B3B495DCC} URL = http://www.google.com/search?hl=pl&q={searchTerms} BHO-x32: Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll (Bitdefender) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Przemek\AppData\Roaming\Mozilla\Firefox\Profiles\q25gd0md.default-1372251732014 FF Homepage: hxxp://www.fixitpc.pl/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1209149.dll (Adobe Systems, Inc.) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Przemek\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Przemek\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Extension: Flagfox - C:\Users\Przemek\AppData\Roaming\Mozilla\Firefox\Profiles\q25gd0md.default-1372251732014\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} [2014-01-11] FF Extension: WOT - C:\Users\Przemek\AppData\Roaming\Mozilla\Firefox\Profiles\q25gd0md.default-1372251732014\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-28] FF Extension: NoScript - C:\Users\Przemek\AppData\Roaming\Mozilla\Firefox\Profiles\q25gd0md.default-1372251732014\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-06-26] FF Extension: Adblock Plus - C:\Users\Przemek\AppData\Roaming\Mozilla\Firefox\Profiles\q25gd0md.default-1372251732014\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-26] FF Extension: BetterPrivacy - C:\Users\Przemek\AppData\Roaming\Mozilla\Firefox\Profiles\q25gd0md.default-1372251732014\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013-06-26] FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2013-06-30] FF HKLM-x32\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\ FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\ [] FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2013-06-30] Chrome: ======= CHR HomePage: hxxp://www.fixitpc.pl/ CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.1.376\_platform_specific\win_x86\widevinecdmadapter.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\Przemek\AppData\Local\Google\Chrome\Application\32.0.1700.107\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Przemek\AppData\Local\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Przemek\AppData\Local\Google\Chrome\Application\32.0.1700.107\pdf.dll () CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Foxit Reader Plugin for Mozilla) - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Java(TM) Platform SE 7 U45) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Bitdefender 2014) - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxnp.dll (Bitdefender) CHR Plugin: (Google Update) - C:\Users\Przemek\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll No File CHR Extension: (WOT) - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2012-02-16] CHR Extension: (YouTube) - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-02-16] CHR Extension: (Bitdefender Wallet) - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccahoghmggldkcdjiebjkidpfongdfbl [2013-07-03] CHR Extension: (Adblock Plus) - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2012-02-16] CHR Extension: (Szukaj w Google) - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-02-16] CHR Extension: (Google Wallet) - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-28] CHR Extension: (Gmail) - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-02-16] CHR HKLM-x32\...\Chrome\Extension: [ccahoghmggldkcdjiebjkidpfongdfbl] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxcr.crx [2014-02-07] ==================== Services (Whitelisted) ================= S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender\bdparentalservice.exe [77632 2013-11-28] (Bitdefender) R2 DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [11776 2010-07-05] () R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [239680 2014-02-19] (Foxit Corporation) R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2572072 2013-10-23] (O&O Software GmbH) S4 PuranDefrag; C:\Windows\system32\PuranDefragS.exe [292736 2013-01-17] (Puran Software) R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2009-07-10] (Realtek) R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [67320 2013-10-16] (Bitdefender) R2 VBurnSecs; C:\Program Files\Phantom Drive\VBurnSecs64.exe [397144 2010-12-07] (H+H Software GmbH) R2 vsserv; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1507248 2014-01-27] (Bitdefender) ==================== Drivers (Whitelisted) ==================== S3 adiusbaw; C:\Windows\System32\DRIVERS\adiusbawx64.sys [169496 2007-02-07] (Analog Devices Inc.) S3 adiusbaw; C:\Windows\SysWOW64\DRIVERS\adiusbawx64.sys [169496 2007-02-07] (Analog Devices Inc.) S3 ampa; C:\Windows\system32\ampa.sys [17008 2013-11-29] () S3 ampa; C:\Windows\SysWOW64\ampa.sys [17008 2013-11-29] () R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [893440 2014-01-27] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender) R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [635392 2014-01-27] (BitDefender) R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2013-02-22] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC) S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-09-26] (Bitdefender SRL) S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-28] (BitDefender SRL) R2 Dokan; C:\Windows\system32\drivers\dokan.sys [106888 2010-07-06] (Windows (R) Win 7 DDK provider) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-02-24] (Disc Soft Ltd) S2 ELOADER; C:\Windows\System32\Drivers\adildrx64.sys [58264 2007-02-07] (Analog Deivces) S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] () S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [14920 2013-03-07] () S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] () S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] () R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [55960 2012-06-02] () R1 GSVDRIVE; C:\Windows\System32\DRIVERS\GSVDRIVE.sys [30816 2012-11-15] (GiliSoft International LLC.) R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-09-26] (BitDefender LLC) R2 inpoutx64; C:\Windows\System32\Drivers\inpoutx64.sys [15008 2013-10-29] (Highresolution Enterprises [www.highrez.co.uk]) S4 IObitUnlocker; C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlocker.sys [36568 2013-09-30] (IObit) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66360 2012-10-02] (Logitech Inc.) S3 MDA_NTDRV; C:\Windows\system32\MDA_NTDRV.sys [21208 2013-02-25] () S3 MHIKEY10; C:\Windows\System32\Drivers\MHIKEY10x64.sys [60288 2010-09-15] (Generic USB smartcard reader) R2 NPF; C:\Windows\system32\drivers\npf.sys [35344 2012-11-16] (CACE Technologies, Inc.) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] () R2 SCDEmu; C:\Windows\SysWOW64\drivers\scdemu.sys [125376 2012-02-09] (Power Software Ltd) S3 SIVDriver; C:\Windows\system32\Drivers\SIVX64.sys [99392 2010-11-14] (Ray Hinchliffe) S3 SliceDisk5; C:\Program Files\A-FF Find and Mount\slicedisk-x64.sys [31824 2011-02-25] (Atola) S4 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2010-11-26] () R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-09-26] (BitDefender S.R.L.) R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [102664 2013-12-12] () R1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [25992 2013-12-12] () R1 Uim_IM; C:\Windows\System32\DRIVERS\uim_im.sys [700680 2013-12-12] () R1 Uim_VIM; C:\Windows\System32\Drivers\uim_vimx64.sys [390224 2012-10-31] (Paragon) R1 usedisk; C:\Windows\System32\DRIVERS\usedisk.sys [29208 2013-10-13] (Gili Soft INC.) R1 vburn1000; C:\Windows\System32\DRIVERS\vburn1000.sys [221720 2012-06-24] (H+H Software GmbH) R3 vburnbus; C:\Windows\System32\DRIVERS\vburnbus.sys [40464 2012-06-24] (H+H Software GmbH) R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [141920 2013-12-09] (Acronis) R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [223744 2013-03-19] (VIA Technologies, Inc.) R2 WinisoCDBus; C:\Windows\System32\drivers\WinisoCDBus.sys [204032 2014-01-23] (WinISO.com) R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [301256 2013-01-03] (VIA Technologies, Inc.) U3 usbaudio; U3 UsbScan; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-25 13:44 - 2014-02-25 13:44 - 00018574 _____ () C:\Users\Przemek\Desktop\FRST.txt 2014-02-25 13:44 - 2014-02-25 13:44 - 00000000 ____D () C:\FRST 2014-02-25 13:43 - 2014-02-25 13:43 - 00112258 _____ () C:\Users\Przemek\Desktop\OTL.Txt 2014-02-25 13:43 - 2014-02-25 13:43 - 00038788 _____ () C:\Users\Przemek\Desktop\Extras.Txt 2014-02-25 13:35 - 2014-02-25 13:35 - 00602112 _____ (OldTimer Tools) C:\Users\Przemek\Desktop\OTL.exe 2014-02-25 13:34 - 2014-02-25 13:34 - 02156032 _____ (Farbar) C:\Users\Przemek\Desktop\FRST64.exe 2014-02-24 20:48 - 2014-02-24 20:48 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys 2014-02-24 20:43 - 2014-02-24 20:43 - 00001132 _____ () C:\Windows\PFRO.log 2014-02-24 20:42 - 2014-02-25 12:46 - 00002396 _____ () C:\Windows\Tasks\Plus-HD-7.6-validator.job 2014-02-24 20:42 - 2014-02-25 12:46 - 00002330 _____ () C:\Windows\Tasks\Plus-HD-7.6-firefoxinstaller.job 2014-02-24 20:42 - 2014-02-24 20:42 - 00005426 _____ () C:\Windows\System32\Tasks\Plus-HD-7.6-validator 2014-02-24 20:42 - 2014-02-24 20:42 - 00001958 _____ () C:\Users\Public\Desktop\DAEMON Tools Lite.lnk 2014-02-24 20:42 - 2014-02-24 20:42 - 00000000 ____D () C:\Program Files (x86)\Plus-HD-7.6 2014-02-24 20:41 - 2014-02-24 20:48 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite 2014-02-24 20:26 - 2014-02-25 12:46 - 00000336 _____ () C:\Windows\setupact.log 2014-02-24 20:26 - 2014-02-24 20:26 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-24 12:31 - 2014-02-25 12:49 - 00055823 _____ () C:\Windows\WindowsUpdate.log 2014-02-21 12:31 - 2014-02-21 12:31 - 00000000 ____D () C:\Users\Przemek\Documents\PDF2Text Output 2014-02-20 17:02 - 2014-02-20 17:02 - 00000000 ____D () C:\Users\Przemek\Desktop\ISOburn.org 2014-02-20 16:32 - 2014-02-20 16:32 - 00002064 _____ () C:\Users\Public\Desktop\Foxit Reader.lnk 2014-02-14 11:20 - 2014-02-14 11:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-13 15:54 - 2014-02-13 15:54 - 00000000 ____D () C:\Program Files (x86)\SoftOrbits Photo Retoucher 2014-02-11 19:14 - 2013-11-27 00:29 - 05693440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-02-11 19:14 - 2013-11-26 23:49 - 06573056 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-02-11 19:07 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-02-11 19:07 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-02-11 19:07 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-02-11 19:07 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-02-11 19:07 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-02-11 19:07 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-02-11 19:07 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-02-11 19:07 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-02-11 19:07 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-02-11 19:07 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-02-11 19:07 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-02-11 19:07 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-02-11 19:07 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-02-11 19:07 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-02-11 19:07 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2014-02-11 19:07 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-02-11 19:03 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-11 19:03 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-11 19:03 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-11 19:03 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-11 19:03 - 2013-12-10 03:28 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-11 19:03 - 2013-12-10 03:02 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-11 19:03 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-11 19:03 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-11 19:03 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-11 19:03 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-11 19:03 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-11 19:03 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-11 19:03 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-11 19:03 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-11 19:03 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-11 19:03 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-11 19:03 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-11 19:03 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-11 19:03 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-11 19:03 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-11 19:03 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-11 19:03 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-11 19:03 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-11 19:03 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-11 19:03 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-11 19:03 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-11 19:03 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-11 19:03 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-11 19:03 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-11 19:03 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-11 19:03 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-02-11 19:03 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-02-11 12:33 - 2014-02-11 12:33 - 00000000 ____D () C:\Windows\SysWOW64\Adobe 2014-02-06 12:30 - 2014-02-06 12:30 - 00000000 ____D () C:\Users\Przemek\Documents\FormatFactory 2014-02-06 12:25 - 2014-02-06 12:25 - 00000000 ____D () C:\Users\Przemek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2014-02-05 10:13 - 2014-02-05 10:13 - 00680448 _____ () C:\Windows\system32\ndm-fre.exe 2014-01-28 10:36 - 2014-01-28 10:36 - 00000000 ____D () C:\RegBackup ==================== One Month Modified Files and Folders ======= 2014-02-25 13:44 - 2014-02-25 13:44 - 00018574 _____ () C:\Users\Przemek\Desktop\FRST.txt 2014-02-25 13:44 - 2014-02-25 13:44 - 00000000 ____D () C:\FRST 2014-02-25 13:43 - 2014-02-25 13:43 - 00112258 _____ () C:\Users\Przemek\Desktop\OTL.Txt 2014-02-25 13:43 - 2014-02-25 13:43 - 00038788 _____ () C:\Users\Przemek\Desktop\Extras.Txt 2014-02-25 13:35 - 2014-02-25 13:35 - 00602112 _____ (OldTimer Tools) C:\Users\Przemek\Desktop\OTL.exe 2014-02-25 13:34 - 2014-02-25 13:34 - 02156032 _____ (Farbar) C:\Users\Przemek\Desktop\FRST64.exe 2014-02-25 12:53 - 2009-07-14 05:45 - 00022784 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-25 12:53 - 2009-07-14 05:45 - 00022784 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-25 12:50 - 2009-07-14 18:55 - 00740890 _____ () C:\Windows\system32\perfh015.dat 2014-02-25 12:50 - 2009-07-14 18:55 - 00156206 _____ () C:\Windows\system32\perfc015.dat 2014-02-25 12:50 - 2009-07-14 06:13 - 01672142 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-25 12:49 - 2014-02-24 12:31 - 00055823 _____ () C:\Windows\WindowsUpdate.log 2014-02-25 12:46 - 2014-02-24 20:42 - 00002396 _____ () C:\Windows\Tasks\Plus-HD-7.6-validator.job 2014-02-25 12:46 - 2014-02-24 20:42 - 00002330 _____ () C:\Windows\Tasks\Plus-HD-7.6-firefoxinstaller.job 2014-02-25 12:46 - 2014-02-24 20:26 - 00000336 _____ () C:\Windows\setupact.log 2014-02-25 12:46 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-24 20:48 - 2014-02-24 20:48 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys 2014-02-24 20:48 - 2014-02-24 20:41 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite 2014-02-24 20:45 - 2011-06-05 09:35 - 00000000 ____D () C:\Users\Przemek\AppData\Roaming\DAEMON Tools Lite 2014-02-24 20:43 - 2014-02-24 20:43 - 00001132 _____ () C:\Windows\PFRO.log 2014-02-24 20:42 - 2014-02-24 20:42 - 00005426 _____ () C:\Windows\System32\Tasks\Plus-HD-7.6-validator 2014-02-24 20:42 - 2014-02-24 20:42 - 00001958 _____ () C:\Users\Public\Desktop\DAEMON Tools Lite.lnk 2014-02-24 20:42 - 2014-02-24 20:42 - 00000000 ____D () C:\Program Files (x86)\Plus-HD-7.6 2014-02-24 20:26 - 2014-02-24 20:26 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-24 17:46 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-02-24 17:28 - 2014-01-24 21:39 - 00000000 ____D () C:\Users\Przemek\AppData\Local\CrashDumps 2014-02-21 14:14 - 2011-07-02 08:55 - 00000000 ____D () C:\Users\Przemek\Desktop\USBDeview 2014-02-21 12:31 - 2014-02-21 12:31 - 00000000 ____D () C:\Users\Przemek\Documents\PDF2Text Output 2014-02-20 17:05 - 2011-07-01 19:29 - 00000000 ____D () C:\PROGRAMY 2014-02-20 17:02 - 2014-02-20 17:02 - 00000000 ____D () C:\Users\Przemek\Desktop\ISOburn.org 2014-02-20 17:02 - 2012-06-30 23:05 - 00058408 _____ () C:\Users\Przemek\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-20 16:32 - 2014-02-20 16:32 - 00002064 _____ () C:\Users\Public\Desktop\Foxit Reader.lnk 2014-02-20 16:29 - 2013-02-07 22:50 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-20 16:29 - 2013-02-07 22:50 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-20 12:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2014-02-18 23:14 - 2013-12-12 11:37 - 00001024 ____H () C:\AMTAG.BIN 2014-02-18 23:14 - 2013-12-12 11:36 - 00000000 ____D () C:\Program Files (x86)\AOMEI Partition Assistant Pro Edition 5.5 2014-02-18 13:49 - 2012-12-21 07:18 - 00448512 _____ (OldTimer Tools) C:\Users\Przemek\Desktop\TFC.exe 2014-02-16 01:32 - 2011-11-28 01:33 - 00000000 ____D () C:\Users\Przemek\AppData\Roaming\SoftGrid Client 2014-02-15 21:55 - 2012-08-23 09:24 - 00000000 ____D () C:\Program Files (x86)\iCare Card Recovery Pro 2014-02-14 16:38 - 2012-04-23 07:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-14 12:43 - 2011-07-01 13:40 - 00000000 ____D () C:\Users\Przemek\AppData\Roaming\Mozilla 2014-02-14 11:20 - 2014-02-14 11:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-13 15:57 - 2011-11-20 00:09 - 00000000 ____D () C:\Users\Przemek\Desktop\skroty programow 2014-02-13 15:54 - 2014-02-13 15:54 - 00000000 ____D () C:\Program Files (x86)\SoftOrbits Photo Retoucher 2014-02-11 19:08 - 2013-09-10 18:55 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-11 19:07 - 2011-06-04 09:19 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-11 19:04 - 2011-11-28 01:22 - 01643812 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-11 12:58 - 2012-10-31 08:17 - 00000000 ____D () C:\Users\Przemek\Desktop\TEXT 2014-02-11 12:33 - 2014-02-11 12:33 - 00000000 ____D () C:\Windows\SysWOW64\Adobe 2014-02-11 12:33 - 2011-06-03 19:04 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2014-02-06 12:30 - 2014-02-06 12:30 - 00000000 ____D () C:\Users\Przemek\Documents\FormatFactory 2014-02-06 12:25 - 2014-02-06 12:25 - 00000000 ____D () C:\Users\Przemek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2014-02-06 11:30 - 2013-04-02 09:27 - 00000000 ____D () C:\TWEAKING_com 2014-02-05 10:13 - 2014-02-05 10:13 - 00680448 _____ () C:\Windows\system32\ndm-fre.exe 2014-02-04 10:16 - 2009-07-14 06:08 - 00032604 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-03 20:11 - 2012-02-16 16:53 - 00002344 _____ () C:\Users\Przemek\Desktop\Google Chrome.lnk 2014-02-03 10:44 - 2012-01-01 08:07 - 00000000 ____D () C:\Users\Przemek\AppData\Roaming\AIMP3 2014-01-29 11:24 - 2009-07-14 03:34 - 60715008 _____ () C:\Windows\system32\config\software.old 2014-01-29 11:24 - 2009-07-14 03:34 - 23592960 _____ () C:\Windows\system32\config\system.old 2014-01-29 11:24 - 2009-07-14 03:34 - 00643072 _____ () C:\Windows\system32\config\default.old 2014-01-29 11:24 - 2009-07-14 03:34 - 00061440 _____ () C:\Windows\system32\config\sam.old 2014-01-29 11:24 - 2009-07-14 03:34 - 00032768 _____ () C:\Windows\system32\config\security.old 2014-01-29 11:23 - 2011-06-03 17:39 - 00000000 ____D () C:\Users\Przemek 2014-01-28 10:52 - 2013-12-16 13:22 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-01-28 10:36 - 2014-01-28 10:36 - 00000000 ____D () C:\RegBackup 2014-01-27 17:17 - 2013-06-30 21:49 - 00893440 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys 2014-01-27 17:17 - 2013-06-30 21:49 - 00635392 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys Some content of TEMP: ==================== C:\Users\Przemek\AppData\Local\Temp\bitool.dll C:\Users\Przemek\AppData\Local\Temp\plus-hd-7-6.exe C:\Users\Przemek\AppData\Local\Temp\SpeedUpMyComputer.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-16 19:24 ==================== End Of Log ============================