Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-03-2014 Ran by Micha (administrator) on MICHAL on 05-03-2014 19:40:38 Running from C:\Users\Micha\Desktop Windows 8 Pro (X64) OS Language: Polish Internet Explorer Version 10 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\SysWOW64\PnkBstrA.exe (StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (BitTorrent, Inc.) C:\Program Files (x86)\uTorrent\uTorrent.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE (Flux Software LLC) C:\Users\Micha\AppData\Local\FluxSoftware\Flux\flux.exe (Murray Hurps Corp Pty Ltd) C:\Program Files (x86)\Ad Muncher\AdMunch.exe (Murray Hurps Corp Pty Ltd) C:\Program Files (x86)\Ad Muncher\AdMunch64.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Google Inc.) C:\Users\Micha\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\splwow64.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-03] (NVIDIA Corporation) HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-03-22] (Intel Corporation) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Bonus.SSR.FR11] - C:\Program Files (x86)\ABBYY FineReader 11\Bonus.ScreenshotReader.exe [1364496 2013-06-28] (ABBYY Production LLC) HKU\S-1-5-21-3405716737-3648264401-3583100290-1001\...\Run: [Google Update] - C:\Users\Micha\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-05-26] (Google Inc.) HKU\S-1-5-21-3405716737-3648264401-3583100290-1001\...\Run: [uTorrent] - C:\Program Files (x86)\uTorrent\uTorrent.exe [1022352 2013-05-26] (BitTorrent, Inc.) HKU\S-1-5-21-3405716737-3648264401-3583100290-1001\...\Run: [AlcoholAutomount] - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) HKU\S-1-5-21-3405716737-3648264401-3583100290-1001\...\Run: [F.lux] - C:\Users\Micha\AppData\Local\FluxSoftware\Flux\flux.exe [1016712 2013-10-16] (Flux Software LLC) HKU\S-1-5-21-3405716737-3648264401-3583100290-1001\...\Run: [Ad Muncher] - C:\Program Files (x86)\Ad Muncher\AdMunch.exe [535752 2013-11-19] (Murray Hurps Corp Pty Ltd) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE1A36C71385ACE01 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerms}&affID=119816&tt=gc_&babsrc=SP_ss&mntrId=0A8910BF48BD2099 BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 5.15.151.143 8.8.8.8 Chrome: ======= CHR HomePage: CHR Extension: (Dokumenty Google) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-05-26] CHR Extension: (Dysk Google) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-26] CHR Extension: (YouTube) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-05-26] CHR Extension: (Adblock Plus) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-11-25] CHR Extension: (Szukaj w Google) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-05-26] CHR Extension: (TinEye Reverse Image Search) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2013-05-26] CHR Extension: (Google Wallet) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (Gmail) - C:\Users\Micha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-05-26] ==================== Services (Whitelisted) ================= S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1329304 2012-11-26] (ESET) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-20] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-08-25] () S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider) S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [211344 2012-10-08] (ESET) R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [149592 2012-10-08] (ESET) R2 epfw; C:\Windows\system32\DRIVERS\epfw.sys [189208 2012-10-08] (ESET) R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [59440 2012-10-08] (ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [57904 2012-11-28] (ESET) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-03-20] (Intel Corporation) S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-05 19:40 - 2014-03-05 19:40 - 00011814 _____ () C:\Users\Micha\Desktop\FRST.txt 2014-03-05 19:38 - 2014-03-05 19:38 - 00113360 _____ () C:\Users\Micha\Desktop\OTL.Txt 2014-03-05 19:37 - 2014-03-05 19:40 - 00000000 ____D () C:\FRST 2014-03-05 19:31 - 2014-03-05 19:31 - 02157056 _____ (Farbar) C:\Users\Micha\Desktop\FRST64.exe 2014-03-05 19:24 - 2014-03-05 19:24 - 00602112 _____ (OldTimer Tools) C:\Users\Micha\Desktop\OTL.exe 2014-03-04 18:10 - 2014-03-05 13:21 - 00000000 ____D () C:\Users\Public\Documents\PITy 2014-03-04 18:10 - 2014-03-04 18:10 - 00001008 _____ () C:\Users\Micha\Desktop\PITy roczne.lnk 2014-03-04 18:10 - 2014-03-04 18:10 - 00000000 ____D () C:\ProgramData\PITy 2014-03-04 18:10 - 2014-03-04 18:10 - 00000000 ____D () C:\Program Files (x86)\ProgramPITy 2014-02-27 09:51 - 2014-03-05 14:53 - 00001572 _____ () C:\Windows\PFRO.log 2014-02-14 10:01 - 2014-03-05 19:06 - 00001072 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405716737-3648264401-3583100290-1001UA1cf29635244cc12.job 2014-02-14 10:01 - 2014-02-14 10:01 - 00004018 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3405716737-3648264401-3583100290-1001UA1cf29635244cc12 2014-02-12 08:28 - 2014-02-01 10:20 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-12 08:28 - 2014-02-01 10:19 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-12 08:28 - 2014-02-01 10:19 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-12 08:28 - 2014-02-01 10:19 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-02-12 08:28 - 2014-02-01 10:19 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-02-12 08:28 - 2014-02-01 10:18 - 19274240 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-12 08:28 - 2014-02-01 10:18 - 15403520 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-12 08:28 - 2014-02-01 10:18 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-02-12 08:28 - 2014-02-01 10:18 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-12 08:28 - 2014-02-01 10:18 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-12 08:28 - 2014-02-01 10:18 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-02-12 08:28 - 2014-02-01 10:18 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-12 08:28 - 2014-02-01 10:18 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-12 08:28 - 2014-02-01 10:18 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-12 08:28 - 2014-02-01 08:58 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-12 08:28 - 2014-02-01 08:58 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-12 08:28 - 2014-02-01 08:58 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-02-12 08:28 - 2014-02-01 08:57 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-12 08:28 - 2014-02-01 08:57 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-12 08:28 - 2014-02-01 08:57 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-12 08:28 - 2014-02-01 08:57 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-02-12 08:28 - 2014-02-01 08:57 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-12 08:28 - 2014-02-01 08:57 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-12 08:28 - 2014-02-01 08:57 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-12 08:28 - 2014-02-01 08:40 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-12 08:28 - 2014-02-01 08:34 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-12 08:28 - 2014-02-01 06:08 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-02-12 08:28 - 2013-12-09 01:45 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-12 08:28 - 2013-12-09 00:59 - 00600064 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-12 08:28 - 2013-12-05 00:43 - 01845248 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 08:28 - 2013-12-05 00:37 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 08:28 - 2013-11-27 01:19 - 00385614 _____ () C:\Windows\system32\ApnDatabase.xml 2014-02-12 08:28 - 2013-11-26 00:17 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2014-02-12 08:28 - 2013-11-01 06:53 - 02232664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-02-12 08:27 - 2014-02-01 10:18 - 03960320 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-12 08:27 - 2014-02-01 10:18 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-12 08:27 - 2014-02-01 08:57 - 14359040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-12 08:27 - 2014-02-01 08:57 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-12 08:27 - 2014-02-01 08:57 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-12 08:27 - 2014-02-01 08:57 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-02-12 08:27 - 2013-12-05 00:43 - 00583680 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 08:27 - 2013-12-05 00:37 - 00451072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-12 08:25 - 2014-01-13 00:30 - 02238976 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 08:25 - 2014-01-13 00:30 - 02032640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 08:25 - 2013-11-20 01:15 - 03842560 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-12 08:25 - 2013-11-20 00:57 - 03288576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll ==================== One Month Modified Files and Folders ======= 2014-03-05 19:40 - 2014-03-05 19:40 - 00011814 _____ () C:\Users\Micha\Desktop\FRST.txt 2014-03-05 19:40 - 2014-03-05 19:37 - 00000000 ____D () C:\FRST 2014-03-05 19:40 - 2013-05-26 19:02 - 00000000 ____D () C:\Users\Micha\AppData\Roaming\uTorrent 2014-03-05 19:38 - 2014-03-05 19:38 - 00113360 _____ () C:\Users\Micha\Desktop\OTL.Txt 2014-03-05 19:37 - 2013-09-06 18:16 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-05 19:37 - 2012-07-26 10:51 - 03199936 _____ () C:\Windows\system32\perfh015.dat 2014-03-05 19:37 - 2012-07-26 10:51 - 00969986 _____ () C:\Windows\system32\perfc015.dat 2014-03-05 19:37 - 2012-07-26 08:28 - 00005640 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-05 19:31 - 2014-03-05 19:31 - 02157056 _____ (Farbar) C:\Users\Micha\Desktop\FRST64.exe 2014-03-05 19:24 - 2014-03-05 19:24 - 00602112 _____ (OldTimer Tools) C:\Users\Micha\Desktop\OTL.exe 2014-03-05 19:19 - 2013-05-26 18:47 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3405716737-3648264401-3583100290-1001 2014-03-05 19:18 - 2013-12-19 18:06 - 00001070 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cefcdcafdfc4b8.job 2014-03-05 19:14 - 2013-12-19 18:01 - 00001056 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-05 19:14 - 2013-05-26 18:50 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-03-05 19:14 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-05 19:06 - 2014-02-14 10:01 - 00001072 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405716737-3648264401-3583100290-1001UA1cf29635244cc12.job 2014-03-05 19:05 - 2013-11-23 09:34 - 01488126 _____ () C:\Windows\WindowsUpdate.log 2014-03-05 19:00 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru 2014-03-05 14:53 - 2014-02-27 09:51 - 00001572 _____ () C:\Windows\PFRO.log 2014-03-05 14:05 - 2013-05-26 19:36 - 00000000 ____D () C:\Users\Micha\AppData\Roaming\vlc 2014-03-05 13:21 - 2014-03-04 18:10 - 00000000 ____D () C:\Users\Public\Documents\PITy 2014-03-05 10:06 - 2013-07-04 10:49 - 00001020 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405716737-3648264401-3583100290-1001Core1ce789bcbb6f6aa.job 2014-03-04 18:10 - 2014-03-04 18:10 - 00001008 _____ () C:\Users\Micha\Desktop\PITy roczne.lnk 2014-03-04 18:10 - 2014-03-04 18:10 - 00000000 ____D () C:\ProgramData\PITy 2014-03-04 18:10 - 2014-03-04 18:10 - 00000000 ____D () C:\Program Files (x86)\ProgramPITy 2014-03-03 09:16 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-03-01 18:36 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-02-27 09:51 - 2013-08-25 13:51 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-02-26 16:04 - 2013-07-16 15:33 - 00000000 ____D () C:\ProgramData\Origin 2014-02-26 16:02 - 2013-08-25 13:39 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-02-26 16:02 - 2013-05-30 15:56 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-02-26 16:02 - 2013-05-30 15:52 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-02-26 15:03 - 2013-07-16 15:33 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-02-21 08:37 - 2013-09-06 18:16 - 00003818 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-18 14:13 - 2013-12-19 18:06 - 00004042 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1cefcdcafdfc4b8 2014-02-18 14:13 - 2013-12-19 18:01 - 00003796 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-17 23:03 - 2013-11-14 09:37 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-17 23:03 - 2013-11-14 09:37 - 00078304 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-17 09:26 - 2013-07-12 09:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-17 09:23 - 2013-05-27 19:03 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-14 10:01 - 2014-02-14 10:01 - 00004018 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3405716737-3648264401-3583100290-1001UA1cf29635244cc12 2014-02-14 10:01 - 2013-07-04 10:49 - 00003638 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3405716737-3648264401-3583100290-1001Core1ce789bcbb6f6aa 2014-02-13 09:56 - 2013-12-31 19:35 - 00000444 _____ () C:\Users\Micha\.swfinfo 2014-02-12 18:00 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\rescache 2014-02-09 18:51 - 2013-06-20 07:57 - 00001070 _____ () C:\Users\Public\Desktop\VLC media player.lnk Some content of TEMP: ==================== C:\Users\Micha\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Micha\AppData\Local\Temp\sonarinst.exe C:\Users\Micha\AppData\Local\Temp\vlc-2.1.2-win64.exe C:\Users\Micha\AppData\Local\Temp\vlc-2.1.3-win32.exe C:\Users\Micha\AppData\Local\Temp\wtw-update.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-26 09:56 ==================== End Of Log ============================