Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-04-2014 03 Ran by Patryk (administrator) on PATRYK-ASUS on 27-04-2014 16:25:09 Running from C:\Users\Patryk\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Windows\system32\mfevtps.exe (StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe (Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91_0\opera.exe () C:\Program Files (x86)\Opera\20.0.1387.91_0\opera_crashreporter.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe (Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91_0\opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12480616 2012-04-24] (Realtek Semiconductor) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2661672 2012-05-14] (ELAN Microelectronics Corp.) HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90832 2012-06-08] (ASUS) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-16] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-16] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-02-24] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-01-28] (McAfee, Inc.) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322208 2012-05-31] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174752 2012-05-31] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-20] (CyberLink) HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-01-28] (McAfee, Inc.) HKU\S-1-5-21-1109735758-1390704349-2981523167-1002\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.) ==================== Internet (Whitelisted) ==================== URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore FF Extension: No Name - C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012-02-24] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2012-02-24] FF HKLM-x32\...\Firefox\Extensions: [{B7082FAA-CB62-4872-9106-E42DD88EDE45}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2012-02-24] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: No Name - C:\Program Files\McAfee\MSK [2012-02-24] Chrome: ======= CHR Extension: (No Name) - C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ombmmloebnfnpehgjnmkcgoegfachobp [2014-04-09] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2014-04-12] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-03-22] (Advanced Micro Devices, Inc.) R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS) S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-28] (McAfee, Inc.) R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-01-28] (McAfee, Inc.) S3 McAWFwk; C:\Program Files\mcafee\msc\McAWFwk.exe [225216 2011-01-28] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.) S2 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-28] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [199008 2011-10-07] (McAfee, Inc.) R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1025712 2014-01-21] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-01-27] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [185792 2014-01-27] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) ==================== Drivers (Whitelisted) ==================== R3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-04-12] (Windows (R) Win 7 DDK provider) R3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [16512 2012-04-12] (Windows (R) Win 7 DDK provider) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70592 2014-01-27] (McAfee, Inc.) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R2 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [180272 2014-01-27] (McAfee, Inc.) U3 mfeapfk01; No ImagePath R2 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311600 2014-01-27] (McAfee, Inc.) U3 mfeavfk01; No ImagePath R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [520696 2014-01-27] (McAfee, Inc.) R2 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [783864 2014-01-27] (McAfee, Inc.) R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [422712 2014-01-21] (McAfee, Inc.) S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96592 2014-01-21] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [100904 2011-08-15] (McAfee, Inc.) R2 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [344688 2014-01-27] (McAfee, Inc.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2014-04-07] (Duplex Secure Ltd.) U3 akg087mk; C:\Windows\System32\Drivers\akg087mk.sys [0 ] (Advanced Micro Devices) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-27 16:24 - 2014-04-27 16:03 - 00010181 _____ () C:\Users\Patryk\Downloads\AdwCleaner[S0].txt 2014-04-27 16:24 - 2014-04-27 16:01 - 00012428 _____ () C:\Users\Patryk\Downloads\AdwCleaner[R0].txt 2014-04-27 16:13 - 2014-04-27 16:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-04-27 16:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-04-27 15:55 - 2014-04-27 15:55 - 01329501 _____ () C:\Users\Patryk\Downloads\adwcleaner.exe 2014-04-27 15:42 - 2014-04-27 16:07 - 00000352 _____ () C:\Users\Patryk\AppData\Roaming\sp_data.sys 2014-04-27 15:37 - 2014-04-27 15:37 - 00000000 _____ () C:\Users\Patryk\Desktop\Nowy dokument tekstowy.txt 2014-04-26 18:32 - 2014-04-26 18:32 - 00087138 _____ () C:\Users\Patryk\Downloads\Extras.Txt 2014-04-26 18:28 - 2014-04-26 18:28 - 00104774 _____ () C:\Users\Patryk\Downloads\OTL.Txt 2014-04-26 17:09 - 2014-04-26 17:30 - 00033997 _____ () C:\Users\Patryk\Downloads\Shortcut.txt 2014-04-26 17:04 - 2014-04-26 17:31 - 00034238 _____ () C:\Users\Patryk\Downloads\Addition.txt 2014-04-26 16:59 - 2014-04-27 16:27 - 00016265 _____ () C:\Users\Patryk\Downloads\FRST.txt 2014-04-26 16:53 - 2014-04-26 16:53 - 02061824 _____ (Farbar) C:\Users\Patryk\Downloads\FRST64.exe 2014-04-26 16:53 - 2014-04-26 16:53 - 00602112 _____ (OldTimer Tools) C:\Users\Patryk\Downloads\OTL.exe 2014-04-26 13:51 - 2014-04-27 16:25 - 00000000 ____D () C:\FRST 2014-04-22 04:20 - 2014-04-22 04:22 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Windows Live 2014-04-21 15:52 - 2014-04-26 16:40 - 00000000 ____D () C:\Program Files (x86)\IrfanView 2014-04-21 02:54 - 2014-04-26 16:40 - 00000000 ____D () C:\Program Files\WinPcap 2014-04-19 00:37 - 2014-04-19 00:37 - 00000000 __SHD () C:\Users\Patryk\AppData\Local\EmieUserList 2014-04-19 00:37 - 2014-04-19 00:37 - 00000000 __SHD () C:\Users\Patryk\AppData\Local\EmieSiteList 2014-04-12 20:16 - 2014-04-13 17:26 - 00000000 ____D () C:\Users\Patryk\AppData\Local\TempSW Katalog dla kopii zapasowych 2014-04-12 20:13 - 2014-04-12 20:13 - 00000000 ____D () C:\Users\Patryk\AppData\Local\SolidWorks 2014-04-12 19:46 - 2014-04-12 19:46 - 00000000 ____D () C:\Users\Patryk\Documents\SolidWorksComposer 2014-04-12 19:28 - 2014-04-12 19:28 - 00000000 ____D () C:\Users\Patryk\Documents\SolidWorks Visual Studio Tools for Applications 2014-04-12 19:28 - 2014-04-12 19:28 - 00000000 ____D () C:\Users\Patryk\AppData\Roaming\DassaultSystemes 2014-04-12 19:28 - 2014-04-12 19:28 - 00000000 ____D () C:\Users\Patryk\AppData\Local\DassaultSystemes 2014-04-12 18:04 - 2014-04-26 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro 2014-04-12 18:04 - 2014-04-12 18:04 - 00000000 ____D () C:\Users\Patryk\AppData\Local\VS Revo Group 2014-04-12 18:04 - 2014-04-12 18:04 - 00000000 ____D () C:\ProgramData\VS Revo Group 2014-04-12 18:04 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys 2014-04-12 18:03 - 2014-04-26 16:41 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-04-12 18:02 - 2014-04-12 18:02 - 10619688 _____ (VS Revo Group ) C:\Users\Patryk\Downloads\RevoUninProSetup.exe 2014-04-12 09:21 - 2014-04-12 09:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-04-12 02:13 - 2014-04-12 02:15 - 00000000 ____D () C:\Users\Patryk\AppData\Local\TempSWBackupDirectory 2014-04-12 02:04 - 2014-04-12 02:04 - 00003498 _____ () C:\Windows\System32\Tasks\{EB7936BF-CCC7-4939-BE43-6C98EDF3EAA9} 2014-04-12 01:48 - 2014-04-12 01:48 - 00000000 ____D () C:\Program Files (x86)\SiteAdvisor 2014-04-12 01:31 - 2012-12-10 11:11 - 00000000 ____D () C:\Users\Patryk\Downloads\McAfee Total Protection 2012 (Pelna Wersja Na 3 Kompurtery) 2014-04-11 20:46 - 2014-04-11 20:47 - 146161200 _____ () C:\Users\Patryk\Downloads\den2we3o.exe 2014-04-11 20:23 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-11 20:23 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-11 20:23 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-11 20:23 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-11 20:23 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-11 20:23 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-11 20:23 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-11 20:23 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-11 20:23 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-11 20:22 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-11 20:22 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-11 20:22 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-11 20:22 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-11 20:22 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-11 20:22 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-11 20:22 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-11 20:22 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-11 20:22 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-11 20:22 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-11 20:22 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-11 20:21 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-11 16:44 - 2014-04-12 09:21 - 00000000 ____D () C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2 2014-04-11 16:38 - 2014-04-12 09:18 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-04-11 14:16 - 2014-04-11 19:49 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-04-11 12:37 - 2014-04-11 12:38 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Windows Live Writer 2014-04-11 12:37 - 2014-04-11 12:37 - 00000000 ____D () C:\Users\Patryk\AppData\Roaming\Windows Live Writer 2014-04-07 19:06 - 2014-04-07 19:06 - 00000000 ____D () C:\Program Files\Bonjour 2014-04-07 19:06 - 2014-04-07 19:06 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2014-04-07 18:55 - 2014-04-07 18:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005 2014-04-07 17:29 - 2014-04-13 15:41 - 00000267 _____ () C:\Users\Patryk\Documents\ax_files.xml 2014-04-07 17:26 - 2014-04-07 17:26 - 00000000 ____D () C:\Users\Patryk\Documents\Alcohol 120% 2014-04-07 17:23 - 2014-04-26 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120% 2014-04-07 17:22 - 2014-04-26 16:41 - 00000000 ____D () C:\Program Files (x86)\Alcohol Soft 2014-04-07 17:07 - 2014-04-07 17:07 - 00564824 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys 2014-04-06 23:35 - 2014-04-06 23:35 - 00000000 ____D () C:\Users\Public\Virtual CDs 2014-04-06 23:30 - 2010-03-25 11:44 - 00223256 _____ (H+H Software GmbH) C:\Windows\system32\Drivers\vdrv1000.sys 2014-04-06 23:30 - 2009-07-09 11:24 - 00024088 _____ (H+H Software GmbH) C:\Windows\system32\Drivers\HH10Help.sys 2014-04-06 23:26 - 2014-04-06 23:36 - 00006615 _____ () C:\Windows\hhdrvi.log 2014-04-06 23:24 - 2008-06-17 09:22 - 00040464 _____ (H+H Software GmbH) C:\Windows\system32\Drivers\vcd10bus.sys 2014-04-06 01:04 - 2014-04-11 19:46 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Google 2014-04-05 01:54 - 2014-04-05 01:54 - 00003226 _____ () C:\Windows\System32\Tasks\{FF26F189-6A64-4976-AB23-28CF8BA39540} 2014-04-04 23:31 - 2014-04-27 16:03 - 00000000 ____D () C:\AdwCleaner 2014-04-04 12:35 - 2014-04-26 13:39 - 00000000 ____D () C:\Users\Patryk\Doctor Web 2014-04-04 11:58 - 2014-04-11 13:00 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-04 11:58 - 2014-04-04 11:58 - 00000000 ____D () C:\Users\Patryk\AppData\Roaming\Malwarebytes 2014-04-04 11:57 - 2014-04-05 00:08 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-04-03 18:28 - 2014-04-03 18:28 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0 2014-04-03 17:26 - 2014-04-03 17:26 - 00000000 ____D () C:\ProgramData\Simpoe 2014-04-03 16:23 - 2014-04-13 18:01 - 00000000 ____D () C:\Program Files\Common Files\SolidWorks Shared 2014-04-03 16:23 - 2014-04-03 16:23 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-03 16:19 - 2014-04-12 00:28 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 8 2014-04-03 16:17 - 2014-04-03 16:17 - 00000000 ____D () C:\ProgramData\Apple 2014-04-03 16:04 - 2014-04-03 16:04 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Microsoft Help 2014-04-03 16:03 - 2014-04-07 18:56 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-03 16:03 - 2014-04-07 18:53 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8 2014-04-03 15:59 - 2014-04-03 15:59 - 00000000 ____D () C:\Program Files (x86)\MSECache 2014-04-03 15:46 - 2014-04-07 17:45 - 00000000 ____D () C:\ProgramData\FLEXnet 2014-04-03 15:38 - 2014-04-13 17:24 - 00000000 ____D () C:\Users\Patryk\AppData\Roaming\SolidWorks 2014-04-03 00:43 - 2014-04-03 00:43 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Blizzard 2014-04-03 00:32 - 2014-04-13 03:06 - 00000000 ____D () C:\Program Files (x86)\Hearthstone 2014-04-03 00:32 - 2014-04-03 00:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone 2014-04-03 00:26 - 2014-04-03 00:26 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Blizzard Entertainment 2014-04-03 00:25 - 2014-04-26 22:49 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Battle.net 2014-04-03 00:25 - 2014-04-26 16:41 - 00000000 ____D () C:\Users\Patryk\AppData\Roaming\Battle.net 2014-04-03 00:24 - 2014-04-26 21:48 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-04-03 00:24 - 2014-04-03 00:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2014-04-03 00:24 - 2014-04-03 00:25 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment 2014-04-03 00:17 - 2014-04-03 00:17 - 07058728 _____ (Blizzard Entertainment) C:\Users\Patryk\Downloads\Hearthstone-Setup-plPL.exe 2014-04-03 00:17 - 2014-04-03 00:17 - 00000000 ____D () C:\ProgramData\Battle.net 2014-03-30 00:54 - 2014-03-30 00:54 - 00000000 ____D () C:\Users\Patryk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games ==================== One Month Modified Files and Folders ======= 2014-04-27 16:27 - 2014-04-26 16:59 - 00016265 _____ () C:\Users\Patryk\Downloads\FRST.txt 2014-04-27 16:25 - 2014-04-26 13:51 - 00000000 ____D () C:\FRST 2014-04-27 16:16 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-27 16:16 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-27 16:13 - 2014-04-27 16:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-04-27 16:13 - 2013-12-27 08:12 - 01403437 _____ () C:\Windows\WindowsUpdate.log 2014-04-27 16:07 - 2014-04-27 15:42 - 00000352 _____ () C:\Users\Patryk\AppData\Roaming\sp_data.sys 2014-04-27 16:06 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-27 16:06 - 2009-07-14 06:51 - 00057573 _____ () C:\Windows\setupact.log 2014-04-27 16:05 - 2012-02-24 12:48 - 00103890 _____ () C:\Windows\PFRO.log 2014-04-27 16:03 - 2014-04-27 16:24 - 00010181 _____ () C:\Users\Patryk\Downloads\AdwCleaner[S0].txt 2014-04-27 16:03 - 2014-04-04 23:31 - 00000000 ____D () C:\AdwCleaner 2014-04-27 16:01 - 2014-04-27 16:24 - 00012428 _____ () C:\Users\Patryk\Downloads\AdwCleaner[R0].txt 2014-04-27 15:59 - 2012-02-24 13:40 - 00000000 ____D () C:\Program Files (x86)\Google 2014-04-27 15:55 - 2014-04-27 15:55 - 01329501 _____ () C:\Users\Patryk\Downloads\adwcleaner.exe 2014-04-27 15:40 - 2013-12-27 00:48 - 00000000 ____D () C:\Users\Patryk 2014-04-27 15:37 - 2014-04-27 15:37 - 00000000 _____ () C:\Users\Patryk\Desktop\Nowy dokument tekstowy.txt 2014-04-26 22:49 - 2014-04-03 00:25 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Battle.net 2014-04-26 21:48 - 2014-04-03 00:24 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-04-26 19:03 - 2013-12-27 03:26 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-04-26 18:32 - 2014-04-26 18:32 - 00087138 _____ () C:\Users\Patryk\Downloads\Extras.Txt 2014-04-26 18:28 - 2014-04-26 18:28 - 00104774 _____ () C:\Users\Patryk\Downloads\OTL.Txt 2014-04-26 17:31 - 2014-04-26 17:04 - 00034238 _____ () C:\Users\Patryk\Downloads\Addition.txt 2014-04-26 17:30 - 2014-04-26 17:09 - 00033997 _____ () C:\Users\Patryk\Downloads\Shortcut.txt 2014-04-26 16:53 - 2014-04-26 16:53 - 02061824 _____ (Farbar) C:\Users\Patryk\Downloads\FRST64.exe 2014-04-26 16:53 - 2014-04-26 16:53 - 00602112 _____ (OldTimer Tools) C:\Users\Patryk\Downloads\OTL.exe 2014-04-26 16:43 - 2014-04-12 18:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro 2014-04-26 16:43 - 2014-04-07 17:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120% 2014-04-26 16:42 - 2009-07-14 05:20 - 00000000 __RSD () C:\Windows\Media 2014-04-26 16:42 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-26 16:41 - 2014-04-12 18:03 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-04-26 16:41 - 2014-04-07 17:22 - 00000000 ____D () C:\Program Files (x86)\Alcohol Soft 2014-04-26 16:41 - 2014-04-03 00:25 - 00000000 ____D () C:\Users\Patryk\AppData\Roaming\Battle.net 2014-04-26 16:41 - 2013-12-27 08:40 - 00000000 ____D () C:\ProgramData\P4G 2014-04-26 16:40 - 2014-04-21 15:52 - 00000000 ____D () C:\Program Files (x86)\IrfanView 2014-04-26 16:40 - 2014-04-21 02:54 - 00000000 ____D () C:\Program Files\WinPcap 2014-04-26 16:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-04-26 13:39 - 2014-04-04 12:35 - 00000000 ____D () C:\Users\Patryk\Doctor Web 2014-04-22 04:22 - 2014-04-22 04:20 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Windows Live 2014-04-19 02:46 - 2013-12-27 00:49 - 00064024 _____ () C:\Users\Patryk\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-19 00:37 - 2014-04-19 00:37 - 00000000 __SHD () C:\Users\Patryk\AppData\Local\EmieUserList 2014-04-19 00:37 - 2014-04-19 00:37 - 00000000 __SHD () C:\Users\Patryk\AppData\Local\EmieSiteList 2014-04-16 21:02 - 2009-07-14 06:45 - 00294296 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-13 18:09 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-13 18:01 - 2014-04-03 16:23 - 00000000 ____D () C:\Program Files\Common Files\SolidWorks Shared 2014-04-13 17:26 - 2014-04-12 20:16 - 00000000 ____D () C:\Users\Patryk\AppData\Local\TempSW Katalog dla kopii zapasowych 2014-04-13 17:24 - 2014-04-03 15:38 - 00000000 ____D () C:\Users\Patryk\AppData\Roaming\SolidWorks 2014-04-13 15:41 - 2014-04-07 17:29 - 00000267 _____ () C:\Users\Patryk\Documents\ax_files.xml 2014-04-13 03:06 - 2014-04-03 00:32 - 00000000 ____D () C:\Program Files (x86)\Hearthstone 2014-04-12 20:13 - 2014-04-12 20:13 - 00000000 ____D () C:\Users\Patryk\AppData\Local\SolidWorks 2014-04-12 19:46 - 2014-04-12 19:46 - 00000000 ____D () C:\Users\Patryk\Documents\SolidWorksComposer 2014-04-12 19:28 - 2014-04-12 19:28 - 00000000 ____D () C:\Users\Patryk\Documents\SolidWorks Visual Studio Tools for Applications 2014-04-12 19:28 - 2014-04-12 19:28 - 00000000 ____D () C:\Users\Patryk\AppData\Roaming\DassaultSystemes 2014-04-12 19:28 - 2014-04-12 19:28 - 00000000 ____D () C:\Users\Patryk\AppData\Local\DassaultSystemes 2014-04-12 18:04 - 2014-04-12 18:04 - 00000000 ____D () C:\Users\Patryk\AppData\Local\VS Revo Group 2014-04-12 18:04 - 2014-04-12 18:04 - 00000000 ____D () C:\ProgramData\VS Revo Group 2014-04-12 18:02 - 2014-04-12 18:02 - 10619688 _____ (VS Revo Group ) C:\Users\Patryk\Downloads\RevoUninProSetup.exe 2014-04-12 17:57 - 2009-07-14 07:08 - 00032590 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-12 11:43 - 2012-02-24 14:03 - 00000000 ____D () C:\Program Files (x86)\McAfee 2014-04-12 09:21 - 2014-04-12 09:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-04-12 09:21 - 2014-04-11 16:44 - 00000000 ____D () C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2 2014-04-12 09:18 - 2014-04-11 16:38 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-04-12 09:18 - 2012-02-24 13:41 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-04-12 04:09 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-12 02:15 - 2014-04-12 02:13 - 00000000 ____D () C:\Users\Patryk\AppData\Local\TempSWBackupDirectory 2014-04-12 02:06 - 2012-02-24 14:03 - 00000000 ____D () C:\ProgramData\McAfee 2014-04-12 02:04 - 2014-04-12 02:04 - 00003498 _____ () C:\Windows\System32\Tasks\{EB7936BF-CCC7-4939-BE43-6C98EDF3EAA9} 2014-04-12 01:48 - 2014-04-12 01:48 - 00000000 ____D () C:\Program Files (x86)\SiteAdvisor 2014-04-12 00:28 - 2014-04-03 16:19 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 8 2014-04-12 00:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-04-11 20:47 - 2014-04-11 20:46 - 146161200 _____ () C:\Users\Patryk\Downloads\den2we3o.exe 2014-04-11 20:02 - 2014-03-10 22:17 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Facebook 2014-04-11 20:02 - 2012-02-24 14:03 - 00000000 ____D () C:\Program Files\mcafee 2014-04-11 20:01 - 2012-02-24 14:03 - 00000000 ____D () C:\Program Files\mcafee.com 2014-04-11 20:01 - 2012-02-24 14:03 - 00000000 ____D () C:\Program Files\Common Files\mcafee 2014-04-11 19:54 - 2012-02-24 14:03 - 00000000 ____D () C:\Program Files (x86)\mcafee.com 2014-04-11 19:49 - 2014-04-11 14:16 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-04-11 19:46 - 2014-04-06 01:04 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Google 2014-04-11 13:00 - 2014-04-04 11:58 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-11 12:38 - 2014-04-11 12:37 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Windows Live Writer 2014-04-11 12:37 - 2014-04-11 12:37 - 00000000 ____D () C:\Users\Patryk\AppData\Roaming\Windows Live Writer 2014-04-08 15:51 - 2011-02-19 07:31 - 00740672 _____ () C:\Windows\system32\perfh015.dat 2014-04-08 15:51 - 2011-02-19 07:31 - 00156214 _____ () C:\Windows\system32\perfc015.dat 2014-04-08 15:51 - 2009-07-14 07:13 - 01670518 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-07 19:06 - 2014-04-07 19:06 - 00000000 ____D () C:\Program Files\Bonjour 2014-04-07 19:06 - 2014-04-07 19:06 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2014-04-07 18:56 - 2014-04-03 16:03 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-07 18:55 - 2014-04-07 18:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005 2014-04-07 18:55 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-04-07 18:53 - 2014-04-03 16:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8 2014-04-07 18:53 - 2012-02-24 13:30 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-04-07 17:45 - 2014-04-03 15:46 - 00000000 ____D () C:\ProgramData\FLEXnet 2014-04-07 17:26 - 2014-04-07 17:26 - 00000000 ____D () C:\Users\Patryk\Documents\Alcohol 120% 2014-04-07 17:07 - 2014-04-07 17:07 - 00564824 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys 2014-04-06 23:36 - 2014-04-06 23:26 - 00006615 _____ () C:\Windows\hhdrvi.log 2014-04-06 23:35 - 2014-04-06 23:35 - 00000000 ____D () C:\Users\Public\Virtual CDs 2014-04-06 23:28 - 2013-12-27 08:32 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-05 14:56 - 2014-03-16 14:58 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-04-05 03:00 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar 2014-04-05 02:59 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Sidebar 2014-04-05 02:59 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer 2014-04-05 02:59 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer 2014-04-05 02:59 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-04-05 02:58 - 2009-07-14 09:45 - 00000000 ____D () C:\Program Files\Windows Journal 2014-04-05 02:58 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Defender 2014-04-05 02:58 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\servicing 2014-04-05 02:58 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System 2014-04-05 02:57 - 2011-02-19 07:30 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer 2014-04-05 02:57 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\SysWOW64\winrm 2014-04-05 02:57 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\SysWOW64\WCN 2014-04-05 02:57 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\SysWOW64\slmgr 2014-04-05 02:57 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts 2014-04-05 02:57 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI 2014-04-05 02:57 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz 2014-04-05 02:57 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-04-05 02:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\com 2014-04-05 02:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\IME 2014-04-05 02:50 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\system32\winrm 2014-04-05 02:50 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\system32\WCN 2014-04-05 02:50 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\system32\slmgr 2014-04-05 02:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sysprep 2014-04-05 02:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\oobe 2014-04-05 02:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\MUI 2014-04-05 02:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\migwiz 2014-04-05 02:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism 2014-04-05 02:48 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts 2014-04-05 02:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\com 2014-04-05 01:54 - 2014-04-05 01:54 - 00003226 _____ () C:\Windows\System32\Tasks\{FF26F189-6A64-4976-AB23-28CF8BA39540} 2014-04-05 00:08 - 2014-04-04 11:57 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-04-05 00:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-04-04 12:21 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-04-04 11:58 - 2014-04-04 11:58 - 00000000 ____D () C:\Users\Patryk\AppData\Roaming\Malwarebytes 2014-04-03 18:28 - 2014-04-03 18:28 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0 2014-04-03 17:26 - 2014-04-03 17:26 - 00000000 ____D () C:\ProgramData\Simpoe 2014-04-03 16:23 - 2014-04-03 16:23 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-03 16:17 - 2014-04-03 16:17 - 00000000 ____D () C:\ProgramData\Apple 2014-04-03 16:04 - 2014-04-03 16:04 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Microsoft Help 2014-04-03 15:59 - 2014-04-03 15:59 - 00000000 ____D () C:\Program Files (x86)\MSECache 2014-04-03 00:43 - 2014-04-03 00:43 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Blizzard 2014-04-03 00:33 - 2014-04-03 00:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone 2014-04-03 00:26 - 2014-04-03 00:26 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Blizzard Entertainment 2014-04-03 00:25 - 2014-04-03 00:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2014-04-03 00:25 - 2014-04-03 00:24 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment 2014-04-03 00:17 - 2014-04-03 00:17 - 07058728 _____ (Blizzard Entertainment) C:\Users\Patryk\Downloads\Hearthstone-Setup-plPL.exe 2014-04-03 00:17 - 2014-04-03 00:17 - 00000000 ____D () C:\ProgramData\Battle.net 2014-03-31 03:16 - 2014-04-11 20:23 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-11 20:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-11 20:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-11 20:23 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-30 20:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\sl-SI 2014-03-30 20:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sl-SI 2014-03-30 20:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\sk-SK 2014-03-30 20:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sk-SK 2014-03-30 20:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\sr-Latn-CS 2014-03-30 20:23 - 2011-02-19 08:13 - 00000000 ____D () C:\Windows\sr-Latn-CS 2014-03-30 20:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS 2014-03-30 20:20 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\ro-RO 2014-03-30 20:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\ro-RO 2014-03-30 20:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\lv-LV 2014-03-30 20:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\lv-LV 2014-03-30 20:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\lt-LT 2014-03-30 20:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\lt-LT 2014-03-30 00:54 - 2014-03-30 00:54 - 00000000 ____D () C:\Users\Patryk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-03-29 14:44 - 2014-03-09 17:46 - 00000000 ____D () C:\Users\Patryk\AppData\Local\Microsoft Games Some content of TEMP: ==================== C:\Users\Patryk\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-23 20:32 ==================== End Of Log ============================