Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Suchy (administrator) on SUCHY-KOMPUTER on 05-04-2014 17:37:35 Running from C:\Users\Suchy\Downloads Windows 7 Professional (X64) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE (AMD) C:\Windows\system32\atieclxx.exe (Check Point Software Technologies LTD) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (BitTorrent Inc.) C:\Users\Suchy\AppData\Roaming\uTorrent\uTorrent.exe (Check Point Software Technologies LTD) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe (Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe () C:\Program Files (x86)\Mobogenie\DaemonProcess.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (OldTimer Tools) C:\Users\Suchy\Downloads\OTL.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [ZoneAlarm] - C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [73832 2013-10-26] (Check Point Software Technologies LTD) HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [738496 2013-10-18] () HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.) HKU\S-1-5-21-1210199573-2582141901-3500968515-1001\...\Run: [uTorrent] - C:\Users\Suchy\AppData\Roaming\uTorrent\uTorrent.exe [905296 2014-01-24] (BitTorrent Inc.) HKU\S-1-5-21-1210199573-2582141901-3500968515-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-1210199573-2582141901-3500968515-1001\...\MountPoints2: {372938fa-67d8-11e3-9c03-0023545b66f2} - F:\setup.exe ==================== Internet (Whitelisted) ==================== StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {EE24D42D-6A62-4C55-8EBA-A71624B405DC} URL = http://search.zonealarm.com/search?src=sp&tbid=goughGA&Lan=en&q={searchTerms}&gu=5606eb9bec594ba5ad02d5d96ec68f44&tu=10G9z00Au2C01g0&sku=&tstsId=&ver=&&r=904 BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Zonealarm Helper Object - {2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C} - C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.22.0\bh\zonealarm.dll (Check Point Software Technologies LTD) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM-x32 - ZoneAlarm Security Toolbar - {438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59} - C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.22.0\zonealarmTlbr.dll (Check Point Software Technologies LTD) Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 82.139.8.40 95.160.170.92 88.156.222.92 FireFox: ======== FF ProfilePath: C:\Users\Suchy\AppData\Roaming\Mozilla\Firefox\Profiles\rebyzkkp.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-01-12] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-01-12] Chrome: ======= CHR Extension: (Dokumenty Google) - C:\Users\Suchy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-07] CHR Extension: (Dysk Google) - C:\Users\Suchy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-07] CHR Extension: (YouTube) - C:\Users\Suchy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-07] CHR Extension: (Szukaj w Google) - C:\Users\Suchy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-07] CHR Extension: (Google Wallet) - C:\Users\Suchy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-07] CHR Extension: (Gmail) - C:\Users\Suchy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-07] ==================== Services (Whitelisted) ================= S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-25] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [121424 2014-03-25] (Avira Operations GmbH & Co. KG) S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2013-11-18] (BitRaider, LLC) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-10-23] (Overwolf Ltd) R2 RzOvlMon; C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe [32960 2014-02-21] (Razer, Inc.) R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [2445816 2013-10-26] (Check Point Software Technologies LTD) R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [50704 2013-10-15] (Check Point Software Technologies, Ltd.) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-02-25] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-02-25] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2013-11-07] (BitRaider) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-18] (Disc Soft Ltd) R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [7717984 2013-07-17] (Kaspersky Lab ZAO) U5 klflt; C:\Windows\System32\Drivers\klflt.sys [90208 2013-10-09] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [489568 2013-10-09] (Kaspersky Lab ZAO) R3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-02-21] (Razer, Inc.) R0 RzFilter; C:\Windows\System32\drivers\RzFilter.sys [74432 2014-02-21] (Razer, Inc.) R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [454168 2013-10-23] (Check Point Software Technologies LTD) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-05 17:36 - 2014-04-05 17:36 - 00025877 _____ () C:\Users\Suchy\Downloads\Addition.txt 2014-04-05 17:35 - 2014-04-05 17:37 - 00009498 _____ () C:\Users\Suchy\Downloads\FRST.txt 2014-04-05 17:35 - 2014-04-05 17:37 - 00000000 ____D () C:\FRST 2014-04-05 17:35 - 2014-04-05 17:35 - 00602112 _____ (OldTimer Tools) C:\Users\Suchy\Downloads\OTL.exe 2014-04-05 17:34 - 2014-04-05 17:34 - 02157056 _____ (Farbar) C:\Users\Suchy\Downloads\FRST64.exe 2014-04-04 18:35 - 2014-04-04 18:35 - 00000000 ____D () C:\Users\Suchy\AppData\Local\CrashRpt 2014-04-04 18:35 - 2014-04-04 18:35 - 00000000 ____D () C:\ProgramData\Steam 2014-04-04 18:34 - 2014-04-04 18:34 - 00000000 ____D () C:\Total War Rome II 2014-04-04 18:30 - 2014-04-04 18:31 - 00018473 _____ () C:\Windows\DirectX.log 2014-04-04 18:28 - 2014-04-04 18:28 - 00000489 _____ () C:\Users\Public\Desktop\Total War ROME II.lnk 2014-04-04 18:27 - 2014-04-04 18:27 - 04473353 _____ () C:\Users\Suchy\Downloads\R2-TW-GEMv42-HD-eFX_installer.zip 2014-04-04 16:09 - 2014-03-27 19:31 - 4128692224 _____ () C:\rld-towaroiihatg.iso 2014-04-02 02:26 - 2014-04-02 02:29 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-02 02:23 - 2014-04-02 02:23 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-04-02 02:23 - 2014-04-02 02:23 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-02 02:23 - 2014-04-02 02:23 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-04-02 02:23 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-02 02:23 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-02 02:23 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 02:22 - 2014-04-02 02:22 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Suchy\Downloads\mbam-setup-2.0.0.1000.exe 2014-04-01 01:34 - 2014-04-01 01:35 - 00000000 ____D () C:\Users\Suchy\AppData\Roaming\rmi 2014-04-01 01:32 - 2014-04-02 11:52 - 00007318 _____ () C:\Windows\PFRO.log 2014-04-01 01:31 - 2014-04-01 01:31 - 00061173 _____ () C:\Windows\SysWOW64\CCCInstall_201404010131329431.log 2014-03-31 23:29 - 2014-03-31 23:29 - 00000000 ____D () C:\Program Files\CPUID 2014-03-31 23:13 - 2014-03-31 23:13 - 00000000 ____D () C:\ProgramData\ATI 2014-03-31 23:10 - 2014-03-31 23:10 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-03-31 23:06 - 2014-03-31 23:06 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2014-03-31 23:01 - 2014-03-31 23:08 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-03-31 22:58 - 2014-04-05 16:01 - 00001817 _____ () C:\Windows\setupact.log 2014-03-31 22:58 - 2014-03-31 22:58 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-31 22:57 - 2014-04-05 16:04 - 00099140 _____ () C:\Windows\WindowsUpdate.log 2014-03-31 22:52 - 2014-03-31 22:52 - 00060328 _____ () C:\Windows\SysWOW64\CCCInstall_201403312252256323.log 2014-03-31 22:01 - 2014-03-31 22:57 - 00000000 ____D () C:\Users\Suchy\AppData\Local\CrashDumps 2014-03-31 18:15 - 2014-02-25 11:41 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-03-31 18:15 - 2014-02-25 11:41 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-03-31 18:15 - 2014-02-25 11:41 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-03-31 18:13 - 2014-04-01 02:20 - 00000000 ____D () C:\ProgramData\Avira 2014-03-31 18:13 - 2014-04-01 02:20 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-03-31 18:13 - 2014-03-31 18:13 - 04413904 _____ (Avira Operations GmbH & Co. KG) C:\Users\Suchy\Downloads\avira_en_av___ws.exe 2014-03-31 18:13 - 2014-03-31 18:13 - 00001133 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-03-31 18:01 - 2014-03-31 19:01 - 00218745 _____ () C:\Users\Suchy\Downloads\Antivirus_Free_Edition_x64.exe 2014-03-31 18:01 - 2014-03-31 18:01 - 00162208 _____ () C:\Users\Suchy\Downloads\Antivirus_Free_Edition.exe 2014-03-31 17:25 - 2014-03-31 17:25 - 03532779 _____ (Ainvo Group ) C:\Users\Suchy\Downloads\ainvo-memory-cleaner-setup.exe 2014-03-31 17:25 - 2014-03-31 17:25 - 00001027 _____ () C:\Users\Public\Desktop\Ainvo Memory Cleaner.lnk 2014-03-31 17:25 - 2014-03-31 17:25 - 00000000 ____D () C:\Program Files\Ainvo 2014-03-31 17:18 - 2014-03-31 17:18 - 00000097 _____ () C:\Users\Public\sdelevURL.tmp 2014-03-31 17:18 - 2014-03-31 17:18 - 00000000 _____ () C:\Users\Public\sdelev.tmp 2014-03-31 11:44 - 2014-03-31 23:39 - 00034816 _____ () C:\Users\Suchy\AppData\Roaming\RZR_0060c80348a4b76ec30b7f0da6e8.db 2014-03-31 03:27 - 2014-03-31 03:27 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-03-31 03:26 - 2014-03-31 03:26 - 02347384 _____ (ESET) C:\Users\Suchy\Downloads\esetsmartinstaller_plk.exe 2014-03-30 13:10 - 2014-03-31 11:43 - 00034816 _____ () C:\Users\Suchy\AppData\Roaming\RZR_0060c2f3437da516952dea148aac.db 2014-03-30 13:02 - 2014-03-30 13:02 - 00000000 ____D () C:\Users\Suchy\AppData\Local\Razer 2014-03-30 13:00 - 2014-03-30 13:00 - 00001250 _____ () C:\Users\Public\Desktop\Razer Comms.lnk 2014-03-30 12:59 - 2014-03-30 12:59 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_RzFilter_01009.Wdf 2014-03-30 12:59 - 2014-03-30 12:59 - 00000000 ____D () C:\Windows\Razer Core 2014-03-30 12:59 - 2014-03-30 12:59 - 00000000 ____D () C:\ProgramData\Razer 2014-03-30 12:59 - 2014-03-30 12:59 - 00000000 ____D () C:\Program Files (x86)\Razer 2014-03-30 12:59 - 2014-02-21 07:04 - 00129472 _____ (Razer, Inc.) C:\Windows\system32\Drivers\RzDxgk.sys 2014-03-30 12:59 - 2014-02-21 07:04 - 00074432 _____ (Razer, Inc.) C:\Windows\system32\Drivers\RzFilter.sys 2014-03-30 12:56 - 2014-03-30 12:57 - 46652256 _____ (Razer Inc.) C:\Users\Suchy\Downloads\RazerComms1.83.11.exe 2014-03-29 13:32 - 2014-03-29 13:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-27 04:30 - 2014-03-27 04:34 - 392722101 _____ () C:\Users\Suchy\Downloads\InstallOpenGeneral.exe 2014-03-22 13:18 - 2014-03-22 13:18 - 00000611 _____ () C:\Users\Public\Desktop\World of Tanks - Common Test.lnk 2014-03-22 13:17 - 2014-03-22 13:17 - 10983288 _____ (Wargaming.net ) C:\Users\Suchy\Downloads\WoT_internet_install_ct(1).exe 2014-03-21 14:43 - 2014-03-28 14:15 - 05292054 _____ () C:\Users\Suchy\Desktop\Nowy obraz mapy bitowej (3).bmp 2014-03-21 03:36 - 2014-03-20 18:58 - 72500829 _____ () C:\Users\Suchy\Desktop\HRMOD Gun Sounds v1.8621.rar 2014-03-20 18:56 - 2014-03-20 18:58 - 72500829 _____ () C:\Users\Suchy\Downloads\HRMOD Gun Sounds v1.8621.rar 2014-03-20 18:56 - 2014-03-20 18:56 - 01028510 _____ () C:\Users\Suchy\Downloads\Ingame_Clock_811_int.zip 2014-03-20 18:56 - 2014-03-20 18:56 - 00160286 _____ () C:\Users\Suchy\Downloads\damage_stickers_Ins_FX_invert.zip 2014-03-20 18:56 - 2014-03-20 18:56 - 00017747 _____ () C:\Users\Suchy\Downloads\DamageIndicator_DIKEY93.zip 2014-03-20 18:56 - 2014-03-20 18:56 - 00004556 _____ () C:\Users\Suchy\Downloads\NoScopeShadow_0811_test1.zip 2014-03-16 18:16 - 2014-03-16 18:16 - 00000000 ____D () C:\Users\Suchy\AppData\Local\Smellyriver 2014-03-16 18:15 - 2014-03-16 18:16 - 00000000 ____D () C:\Users\Suchy\Desktop\wota 2014-03-15 01:04 - 2014-03-15 01:04 - 00061173 _____ () C:\Windows\SysWOW64\CCCInstall_201403150004359761.log 2014-03-15 01:02 - 2014-03-15 01:02 - 00000000 ____D () C:\Program Files\AMD 2014-03-15 00:50 - 2014-03-15 00:50 - 00060328 _____ () C:\Windows\SysWOW64\CCCInstall_201403142350066281.log 2014-03-15 00:39 - 2014-03-15 00:39 - 03441528 _____ (Solvusoft Corporation ) C:\Users\Suchy\Downloads\AMD_Radeon_HD_6850_Aktualizacja_sterownika_03-2014.exe 2014-03-15 00:36 - 2014-03-15 00:38 - 212753896 _____ (Advanced Micro Devices, Inc.) C:\Users\Suchy\Downloads\13-12_win7_win8_64_dd_ccc_whql.exe 2014-03-14 17:51 - 2014-03-14 17:51 - 00061173 _____ () C:\Windows\SysWOW64\CCCInstall_201403141651378248.log 2014-03-14 17:38 - 2014-03-14 17:38 - 00060328 _____ () C:\Windows\SysWOW64\CCCInstall_201403141638153232.log 2014-03-14 17:26 - 2014-04-01 02:20 - 00000000 ____D () C:\Windows\pss 2014-03-14 17:23 - 2014-03-14 17:23 - 04765152 _____ (Piriform Ltd) C:\Users\Suchy\Downloads\ccsetup411.exe 2014-03-14 17:23 - 2014-03-14 17:23 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-03-14 17:23 - 2014-03-14 17:23 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-03-14 17:23 - 2014-03-14 17:23 - 00000000 ____D () C:\Program Files\CCleaner 2014-03-12 19:18 - 2014-03-12 19:18 - 00000000 ____D () C:\Users\Suchy\AppData\Roaming\BESTplayer 2014-03-12 19:17 - 2014-03-12 19:17 - 01123840 _____ (Karol Winnicki) C:\Users\Suchy\Desktop\BESTplayer.exe 2014-03-11 09:55 - 2014-03-11 09:55 - 00013870 _____ () C:\Users\Suchy\Desktop\pismo.odt ==================== One Month Modified Files and Folders ======= 2014-04-05 17:37 - 2014-04-05 17:35 - 00009498 _____ () C:\Users\Suchy\Downloads\FRST.txt 2014-04-05 17:37 - 2014-04-05 17:35 - 00000000 ____D () C:\FRST 2014-04-05 17:36 - 2014-04-05 17:36 - 00025877 _____ () C:\Users\Suchy\Downloads\Addition.txt 2014-04-05 17:35 - 2014-04-05 17:35 - 00602112 _____ (OldTimer Tools) C:\Users\Suchy\Downloads\OTL.exe 2014-04-05 17:34 - 2014-04-05 17:34 - 02157056 _____ (Farbar) C:\Users\Suchy\Downloads\FRST64.exe 2014-04-05 17:33 - 2013-11-07 18:11 - 00001046 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-05 17:33 - 2009-07-14 06:45 - 00009792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-05 17:33 - 2009-07-14 06:45 - 00009792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-05 17:32 - 2013-11-08 21:12 - 00000000 ____D () C:\Users\Suchy\AppData\Roaming\uTorrent 2014-04-05 17:06 - 2013-11-07 17:49 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-05 16:04 - 2014-03-31 22:57 - 00099140 _____ () C:\Windows\WindowsUpdate.log 2014-04-05 16:01 - 2014-03-31 22:58 - 00001817 _____ () C:\Windows\setupact.log 2014-04-05 16:01 - 2013-11-07 18:11 - 00001042 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-05 16:01 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-05 15:58 - 2013-12-18 18:05 - 00019903 _____ () C:\Users\Suchy\daemonprocess.txt 2014-04-05 15:46 - 2013-11-30 17:59 - 00007655 _____ () C:\Users\Suchy\AppData\Local\resmon.resmoncfg 2014-04-05 15:42 - 2014-03-04 02:07 - 03368682 _____ () C:\Users\Suchy\Desktop\Nowy obraz mapy bitowej.bmp 2014-04-05 04:18 - 2013-11-07 17:53 - 00000000 ____D () C:\Users\Suchy\AppData\Roaming\TS3Client 2014-04-04 20:46 - 2002-01-04 01:59 - 00000000 ____D () C:\Users\Suchy 2014-04-04 18:35 - 2014-04-04 18:35 - 00000000 ____D () C:\Users\Suchy\AppData\Local\CrashRpt 2014-04-04 18:35 - 2014-04-04 18:35 - 00000000 ____D () C:\ProgramData\Steam 2014-04-04 18:34 - 2014-04-04 18:34 - 00000000 ____D () C:\Total War Rome II 2014-04-04 18:31 - 2014-04-04 18:30 - 00018473 _____ () C:\Windows\DirectX.log 2014-04-04 18:28 - 2014-04-04 18:28 - 00000489 _____ () C:\Users\Public\Desktop\Total War ROME II.lnk 2014-04-04 18:27 - 2014-04-04 18:27 - 04473353 _____ () C:\Users\Suchy\Downloads\R2-TW-GEMv42-HD-eFX_installer.zip 2014-04-03 20:51 - 2013-11-08 22:05 - 00000000 ____D () C:\Users\Suchy\AppData\Roaming\vlc 2014-04-02 21:44 - 2013-11-07 17:24 - 00000000 ____D () C:\Users\Suchy\AppData\Local\DoNotTrackPlus 2014-04-02 11:52 - 2014-04-01 01:32 - 00007318 _____ () C:\Windows\PFRO.log 2014-04-02 09:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system 2014-04-02 02:29 - 2014-04-02 02:26 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-02 02:23 - 2014-04-02 02:23 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-04-02 02:23 - 2014-04-02 02:23 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-02 02:23 - 2014-04-02 02:23 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-04-02 02:22 - 2014-04-02 02:22 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Suchy\Downloads\mbam-setup-2.0.0.1000.exe 2014-04-01 02:20 - 2014-03-31 18:13 - 00000000 ____D () C:\ProgramData\Avira 2014-04-01 02:20 - 2014-03-31 18:13 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-04-01 02:20 - 2014-03-14 17:26 - 00000000 ____D () C:\Windows\pss 2014-04-01 02:20 - 2013-11-07 17:48 - 00000000 ____D () C:\ProgramData\BitRaider 2014-04-01 02:20 - 2013-11-07 17:20 - 00000000 ____D () C:\ProgramData\Package Cache 2014-04-01 02:20 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-04-01 01:35 - 2014-04-01 01:34 - 00000000 ____D () C:\Users\Suchy\AppData\Roaming\rmi 2014-04-01 01:35 - 2013-11-07 18:42 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-04-01 01:31 - 2014-04-01 01:31 - 00061173 _____ () C:\Windows\SysWOW64\CCCInstall_201404010131329431.log 2014-04-01 01:27 - 2013-11-07 17:24 - 01640128 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-04-01 01:27 - 2009-07-14 19:55 - 00739720 _____ () C:\Windows\system32\perfh015.dat 2014-04-01 01:27 - 2009-07-14 19:55 - 00155294 _____ () C:\Windows\system32\perfc015.dat 2014-04-01 01:27 - 2009-07-14 07:13 - 01640128 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-31 23:39 - 2014-03-31 11:44 - 00034816 _____ () C:\Users\Suchy\AppData\Roaming\RZR_0060c80348a4b76ec30b7f0da6e8.db 2014-03-31 23:29 - 2014-03-31 23:29 - 00000000 ____D () C:\Program Files\CPUID 2014-03-31 23:13 - 2014-03-31 23:13 - 00000000 ____D () C:\ProgramData\ATI 2014-03-31 23:10 - 2014-03-31 23:10 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-03-31 23:10 - 2013-11-07 17:28 - 00000000 ____D () C:\ProgramData\AMD 2014-03-31 23:08 - 2014-03-31 23:01 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-03-31 23:06 - 2014-03-31 23:06 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2014-03-31 22:58 - 2014-03-31 22:58 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-31 22:57 - 2014-03-31 22:01 - 00000000 ____D () C:\Users\Suchy\AppData\Local\CrashDumps 2014-03-31 22:52 - 2014-03-31 22:52 - 00060328 _____ () C:\Windows\SysWOW64\CCCInstall_201403312252256323.log 2014-03-31 19:01 - 2014-03-31 18:01 - 00218745 _____ () C:\Users\Suchy\Downloads\Antivirus_Free_Edition_x64.exe 2014-03-31 18:13 - 2014-03-31 18:13 - 04413904 _____ (Avira Operations GmbH & Co. KG) C:\Users\Suchy\Downloads\avira_en_av___ws.exe 2014-03-31 18:13 - 2014-03-31 18:13 - 00001133 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-03-31 18:01 - 2014-03-31 18:01 - 00162208 _____ () C:\Users\Suchy\Downloads\Antivirus_Free_Edition.exe 2014-03-31 17:25 - 2014-03-31 17:25 - 03532779 _____ (Ainvo Group ) C:\Users\Suchy\Downloads\ainvo-memory-cleaner-setup.exe 2014-03-31 17:25 - 2014-03-31 17:25 - 00001027 _____ () C:\Users\Public\Desktop\Ainvo Memory Cleaner.lnk 2014-03-31 17:25 - 2014-03-31 17:25 - 00000000 ____D () C:\Program Files\Ainvo 2014-03-31 17:18 - 2014-03-31 17:18 - 00000097 _____ () C:\Users\Public\sdelevURL.tmp 2014-03-31 17:18 - 2014-03-31 17:18 - 00000000 _____ () C:\Users\Public\sdelev.tmp 2014-03-31 11:43 - 2014-03-30 13:10 - 00034816 _____ () C:\Users\Suchy\AppData\Roaming\RZR_0060c2f3437da516952dea148aac.db 2014-03-31 03:27 - 2014-03-31 03:27 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-03-31 03:26 - 2014-03-31 03:26 - 02347384 _____ (ESET) C:\Users\Suchy\Downloads\esetsmartinstaller_plk.exe 2014-03-30 21:39 - 2013-11-07 17:03 - 00000000 ____D () C:\ProgramData\MFAData 2014-03-30 17:40 - 2002-01-04 01:59 - 00000000 ____D () C:\Users\Suchy\AppData\Local\VirtualStore 2014-03-30 13:02 - 2014-03-30 13:02 - 00000000 ____D () C:\Users\Suchy\AppData\Local\Razer 2014-03-30 13:02 - 2013-11-07 16:53 - 00066288 _____ () C:\Users\Suchy\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-30 13:02 - 2009-07-14 06:45 - 00298048 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-30 13:00 - 2014-03-30 13:00 - 00001250 _____ () C:\Users\Public\Desktop\Razer Comms.lnk 2014-03-30 12:59 - 2014-03-30 12:59 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_RzFilter_01009.Wdf 2014-03-30 12:59 - 2014-03-30 12:59 - 00000000 ____D () C:\Windows\Razer Core 2014-03-30 12:59 - 2014-03-30 12:59 - 00000000 ____D () C:\ProgramData\Razer 2014-03-30 12:59 - 2014-03-30 12:59 - 00000000 ____D () C:\Program Files (x86)\Razer 2014-03-30 12:57 - 2014-03-30 12:56 - 46652256 _____ (Razer Inc.) C:\Users\Suchy\Downloads\RazerComms1.83.11.exe 2014-03-30 05:02 - 2013-11-07 17:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 13:32 - 2014-03-29 13:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-28 14:15 - 2014-03-21 14:43 - 05292054 _____ () C:\Users\Suchy\Desktop\Nowy obraz mapy bitowej (3).bmp 2014-03-27 19:31 - 2014-04-04 16:09 - 4128692224 _____ () C:\rld-towaroiihatg.iso 2014-03-27 04:34 - 2014-03-27 04:30 - 392722101 _____ () C:\Users\Suchy\Downloads\InstallOpenGeneral.exe 2014-03-26 11:28 - 2013-11-07 18:11 - 00004042 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-26 11:28 - 2013-11-07 18:11 - 00003790 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-26 01:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-03-22 13:18 - 2014-03-22 13:18 - 00000611 _____ () C:\Users\Public\Desktop\World of Tanks - Common Test.lnk 2014-03-22 13:17 - 2014-03-22 13:17 - 10983288 _____ (Wargaming.net ) C:\Users\Suchy\Downloads\WoT_internet_install_ct(1).exe 2014-03-20 18:58 - 2014-03-21 03:36 - 72500829 _____ () C:\Users\Suchy\Desktop\HRMOD Gun Sounds v1.8621.rar 2014-03-20 18:58 - 2014-03-20 18:56 - 72500829 _____ () C:\Users\Suchy\Downloads\HRMOD Gun Sounds v1.8621.rar 2014-03-20 18:56 - 2014-03-20 18:56 - 01028510 _____ () C:\Users\Suchy\Downloads\Ingame_Clock_811_int.zip 2014-03-20 18:56 - 2014-03-20 18:56 - 00160286 _____ () C:\Users\Suchy\Downloads\damage_stickers_Ins_FX_invert.zip 2014-03-20 18:56 - 2014-03-20 18:56 - 00017747 _____ () C:\Users\Suchy\Downloads\DamageIndicator_DIKEY93.zip 2014-03-20 18:56 - 2014-03-20 18:56 - 00004556 _____ () C:\Users\Suchy\Downloads\NoScopeShadow_0811_test1.zip 2014-03-16 20:28 - 2014-02-04 16:26 - 00000000 ____D () C:\Users\Suchy\Desktop\OpenOffice 4.0.1 (pl) Installation Files 2014-03-16 18:16 - 2014-03-16 18:16 - 00000000 ____D () C:\Users\Suchy\AppData\Local\Smellyriver 2014-03-16 18:16 - 2014-03-16 18:15 - 00000000 ____D () C:\Users\Suchy\Desktop\wota 2014-03-15 01:04 - 2014-03-15 01:04 - 00061173 _____ () C:\Windows\SysWOW64\CCCInstall_201403150004359761.log 2014-03-15 01:02 - 2014-03-15 01:02 - 00000000 ____D () C:\Program Files\AMD 2014-03-15 00:50 - 2014-03-15 00:50 - 00060328 _____ () C:\Windows\SysWOW64\CCCInstall_201403142350066281.log 2014-03-15 00:39 - 2014-03-15 00:39 - 03441528 _____ (Solvusoft Corporation ) C:\Users\Suchy\Downloads\AMD_Radeon_HD_6850_Aktualizacja_sterownika_03-2014.exe 2014-03-15 00:38 - 2014-03-15 00:36 - 212753896 _____ (Advanced Micro Devices, Inc.) C:\Users\Suchy\Downloads\13-12_win7_win8_64_dd_ccc_whql.exe 2014-03-14 17:51 - 2014-03-14 17:51 - 00061173 _____ () C:\Windows\SysWOW64\CCCInstall_201403141651378248.log 2014-03-14 17:38 - 2014-03-14 17:38 - 00060328 _____ () C:\Windows\SysWOW64\CCCInstall_201403141638153232.log 2014-03-14 17:29 - 2013-11-28 19:19 - 00008409 ____H () C:\Windows\SysWOW64\BTImages.dat 2014-03-14 17:25 - 2013-12-18 18:06 - 00000000 ____D () C:\Users\Suchy\AppData\Roaming\DAEMON Tools Lite 2014-03-14 17:25 - 2013-11-07 19:37 - 00000000 ____D () C:\Windows\Minidump 2014-03-14 17:25 - 2002-01-04 01:49 - 00000000 ____D () C:\Windows\Panther 2014-03-14 17:23 - 2014-03-14 17:23 - 04765152 _____ (Piriform Ltd) C:\Users\Suchy\Downloads\ccsetup411.exe 2014-03-14 17:23 - 2014-03-14 17:23 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-03-14 17:23 - 2014-03-14 17:23 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-03-14 17:23 - 2014-03-14 17:23 - 00000000 ____D () C:\Program Files\CCleaner 2014-03-12 19:18 - 2014-03-12 19:18 - 00000000 ____D () C:\Users\Suchy\AppData\Roaming\BESTplayer 2014-03-12 19:17 - 2014-03-12 19:17 - 01123840 _____ (Karol Winnicki) C:\Users\Suchy\Desktop\BESTplayer.exe 2014-03-12 19:06 - 2013-11-07 17:49 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 19:06 - 2013-11-07 17:49 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-12 19:06 - 2013-11-07 17:49 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-11 09:55 - 2014-03-11 09:55 - 00013870 _____ () C:\Users\Suchy\Desktop\pismo.odt 2014-03-10 20:26 - 2009-07-14 07:08 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT Some content of TEMP: ==================== C:\Users\Suchy\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-31 19:51 ==================== End Of Log ============================