Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-05-2014 Ran by Samsung (administrator) on SAMSUNGWIN7 on 22-05-2014 16:25:32 Running from C:\Users\Samsung\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe () C:\Windows\Installer\{C42B45D6-DBDC-961F-0AB1-379EEA91BFFD}\syshost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe (Dimagi) C:\Users\Samsung\AppData\Local\Temp\Buij\evvi.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Easy Support Center\SSCKbdHk.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12558440 2011-07-12] (Realtek Semiconductor) HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [10357008 2011-10-18] (Intel Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2784552 2011-05-13] (Synaptics Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [aaaaaaaa] => C:\windows\SysWOW64\aaaaaaaa.exe [173056 2014-05-21] (Trifecta Technologies) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-392818877-1939927122-1532879338-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [449760 2013-10-31] (Sony) HKU\S-1-5-21-392818877-1939927122-1532879338-1001\...\Run: [Evvi] => C:\Users\Samsung\AppData\Local\Temp\Buij\evvi.exe [652800 2012-10-19] (Dimagi) <===== ATTENTION HKU\S-1-5-21-392818877-1939927122-1532879338-1001\...\Run: [aaaaaaaa] => C:\Users\Samsung\aaaaaaaa.exe [173056 2014-05-21] (Trifecta Technologies) HKU\S-1-5-21-392818877-1939927122-1532879338-1001\...\MountPoints2: {5e3a9f01-4d4c-11e3-981f-b803058059e8} - F:\Startme.exe AppInit_DLLs: c:\windows\system32\nvinitx.dll => c:\windows\system32\nvinitx.dll [226920 2011-06-05] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 37.59.8.25 178.33.118.171 FireFox: ======== Chrome: ======= CHR HomePage: CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Samsung\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Extension: (Dokumenty Google) - C:\Users\Samsung\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-22] CHR Extension: (Dysk Google) - C:\Users\Samsung\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-22] CHR Extension: (YouTube) - C:\Users\Samsung\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-22] CHR Extension: (Szukaj w Google) - C:\Users\Samsung\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-22] CHR Extension: (Google Wallet) - C:\Users\Samsung\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-06] CHR Extension: (Gmail) - C:\Users\Samsung\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-22] ==================== Services (Whitelisted) ================= Locked "173ac4b2719b9b72" service could not be unlocked. <===== ATTENTION S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () R2 syshost32; C:\windows\Installer\{C42B45D6-DBDC-961F-0AB1-379EEA91BFFD}\syshost.exe [62464 2014-05-21] () ==================== Drivers (Whitelisted) ==================== S3 1394ohci; C:\Windows\system32\drivers\1394ohci.sys [229888 2010-11-21] () U5 173ac4b2719b9b72; C:\Windows\System32\Drivers\173ac4b2719b9b72.sys [63936 2014-05-21] () <===== ATTENTION Necurs Rootkit? R0 ACPI; C:\Windows\System32\drivers\ACPI.sys [334208 2010-11-21] () S3 AcpiPmi; C:\Windows\system32\drivers\acpipmi.sys [12800 2010-11-21] () S3 adp94xx; C:\Windows\system32\drivers\adp94xx.sys [491088 2009-07-14] () S3 adpahci; C:\Windows\system32\drivers\adpahci.sys [339536 2009-07-14] () S3 adpu320; C:\Windows\system32\drivers\adpu320.sys [182864 2009-07-14] () R1 AFD; C:\Windows\system32\drivers\afd.sys [497152 2013-09-28] () S3 agp440; C:\Windows\system32\drivers\agp440.sys [61008 2009-07-14] () S3 aliide; C:\Windows\system32\drivers\aliide.sys [15440 2009-07-14] () S3 amdide; C:\Windows\system32\drivers\amdide.sys [15440 2009-07-14] () S3 AmdK8; C:\Windows\system32\drivers\amdk8.sys [64512 2009-07-14] () S3 AmdPPM; C:\Windows\system32\drivers\amdppm.sys [60928 2009-07-14] () S3 amdsata; C:\Windows\system32\drivers\amdsata.sys [107904 2011-03-11] () S3 amdsbs; C:\Windows\system32\drivers\amdsbs.sys [194128 2009-07-14] () R0 amdxata; C:\Windows\System32\drivers\amdxata.sys [27008 2011-03-11] () R3 AMPPAL; C:\Windows\System32\DRIVERS\AMPPAL.sys [299008 2011-09-15] () S3 AMPPALP; C:\Windows\System32\DRIVERS\amppal.sys [299008 2011-09-15] () S3 AppID; C:\Windows\system32\drivers\appid.sys [61440 2010-11-21] () S3 arc; C:\Windows\system32\drivers\arc.sys [87632 2009-07-14] () S3 arcsas; C:\Windows\system32\drivers\arcsas.sys [97856 2009-07-14] () R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] () S2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] () R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-28] () R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-28] () R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] () R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-28] () S3 AsyncMac; C:\Windows\System32\DRIVERS\asyncmac.sys [23040 2009-07-14] () R0 atapi; C:\Windows\System32\drivers\atapi.sys [24128 2009-07-14] () S3 b06bdrv; C:\Windows\system32\drivers\bxvbda.sys [468480 2009-06-10] () S3 b57nd60a; C:\Windows\System32\DRIVERS\b57nd60a.sys [270848 2009-06-10] () U5 BattC; C:\Windows\System32\Drivers\BattC.sys [28240 2009-07-14] () R1 Beep; C:\Windows\System32\Drivers\Beep.sys [6656 2009-07-14] () R1 blbdrive; C:\Windows\System32\DRIVERS\blbdrive.sys [45056 2009-07-14] () R3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [90624 2011-02-23] () S3 BrFiltLo; C:\Windows\system32\drivers\BrFiltLo.sys [18432 2009-06-10] () S3 BrFiltUp; C:\Windows\system32\drivers\BrFiltUp.sys [8704 2009-06-10] () S3 Brserid; C:\Windows\System32\Drivers\Brserid.sys [286720 2009-07-14] () S3 BrSerWdm; C:\Windows\System32\Drivers\BrSerWdm.sys [47104 2009-06-10] () S3 BrUsbMdm; C:\Windows\System32\Drivers\BrUsbMdm.sys [14976 2009-06-10] () S3 BrUsbSer; C:\Windows\System32\Drivers\BrUsbSer.sys [14720 2009-06-10] () S3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [289704 2011-07-06] () R3 BthEnum; C:\Windows\system32\drivers\BthEnum.sys [41984 2009-07-14] () S3 BTHMODEM; C:\Windows\system32\drivers\bthmodem.sys [72192 2009-07-14] () R3 BthPan; C:\Windows\System32\DRIVERS\bthpan.sys [118784 2009-07-14] () S3 BTHPORT; C:\Windows\System32\Drivers\BTHport.sys [552960 2012-07-06] () R3 BTHUSB; C:\Windows\System32\Drivers\BTHUSB.sys [80384 2011-04-28] () R3 btmaudio; C:\Windows\System32\drivers\btmaud.sys [51712 2011-05-19] () R3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [53760 2011-08-29] () R3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [288768 2011-10-10] () S4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [92160 2009-07-14] () R1 cdrom; C:\Windows\System32\DRIVERS\cdrom.sys [147456 2010-11-21] () S3 circlass; C:\Windows\system32\drivers\circlass.sys [45568 2009-07-14] () R0 CLFS; C:\Windows\System32\CLFS.sys [367696 2009-07-14] () R3 clwvd; C:\Windows\System32\DRIVERS\clwvd.sys [31216 2011-08-17] () R3 CmBatt; C:\Windows\System32\DRIVERS\CmBatt.sys [17664 2009-07-14] () S3 cmdide; C:\Windows\system32\drivers\cmdide.sys [17488 2009-07-14] () R0 CNG; C:\Windows\System32\Drivers\cng.sys [458712 2013-07-04] () R0 Compbatt; C:\Windows\System32\DRIVERS\compbatt.sys [21584 2009-07-14] () R3 CompositeBus; C:\Windows\System32\DRIVERS\CompositeBus.sys [38912 2010-11-21] () S4 crcdisk; C:\Windows\system32\drivers\crcdisk.sys [24144 2009-07-14] () R1 DfsC; C:\Windows\System32\Drivers\dfsc.sys [102400 2010-11-21] () R1 discache; C:\Windows\System32\drivers\discache.sys [40448 2009-07-14] () R0 Disk; C:\Windows\System32\drivers\disk.sys [73280 2009-07-14] () S3 drmkaud; C:\Windows\system32\drivers\drmkaud.sys [5632 2009-07-14] () R3 DXGKrnl; C:\Windows\System32\drivers\dxgkrnl.sys [983488 2013-08-01] () S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] () S3 elxstor; C:\Windows\system32\drivers\elxstor.sys [530496 2009-07-14] () S3 ErrDev; C:\Windows\system32\drivers\errdev.sys [9728 2009-07-14] () S3 exfat; C:\Windows\System32\Drivers\exfat.sys [195072 2009-07-14] () S3 fastfat; C:\Windows\System32\Drivers\fastfat.sys [204800 2009-07-14] () S3 fdc; C:\Windows\system32\drivers\fdc.sys [29696 2009-07-14] () R0 FileInfo; C:\Windows\System32\drivers\fileinfo.sys [70224 2009-07-14] () S3 Filetrace; C:\Windows\System32\drivers\filetrace.sys [34304 2009-07-14] () S3 flpydisk; C:\Windows\system32\drivers\flpydisk.sys [24576 2009-07-14] () R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [289664 2010-11-21] () S3 FsDepends; C:\Windows\System32\drivers\FsDepends.sys [55376 2009-07-14] () U0 Fs_Rec; C:\Windows\System32\Drivers\Fs_Rec.sys [23408 2012-03-01] () R0 fvevol; C:\Windows\System32\DRIVERS\fvevol.sys [223752 2013-01-24] () S3 gagp30kx; C:\Windows\system32\drivers\gagp30kx.sys [65088 2009-07-14] () S3 hcw85cir; C:\Windows\system32\drivers\hcw85cir.sys [31232 2009-06-10] () S3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [350208 2010-11-21] () R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [122368 2010-11-21] () S3 HidBatt; C:\Windows\system32\drivers\HidBatt.sys [26624 2009-07-14] () S3 HidBth; C:\Windows\system32\drivers\hidbth.sys [100864 2009-07-14] () S3 HidIr; C:\Windows\system32\drivers\hidir.sys [46592 2009-07-14] () R3 HidUsb; C:\Windows\system32\drivers\hidusb.sys [30208 2010-11-21] () S3 HpSAMD; C:\Windows\system32\drivers\HpSAMD.sys [78720 2010-11-21] () R3 HTTP; C:\Windows\System32\drivers\HTTP.sys [753664 2010-11-21] () R0 hwpolicy; C:\Windows\System32\drivers\hwpolicy.sys [14720 2010-11-21] () R3 i8042prt; C:\Windows\System32\DRIVERS\i8042prt.sys [105472 2009-07-14] () R0 iaStor; C:\Windows\System32\DRIVERS\iaStor.sys [439320 2011-02-18] () S3 iaStorV; C:\Windows\system32\drivers\iaStorV.sys [410496 2011-03-11] () R3 iBtFltCoex; C:\Windows\System32\DRIVERS\iBtFltCoex.sys [59904 2011-10-11] () R3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [12256512 2010-12-16] () S3 iirsp; C:\Windows\system32\drivers\iirsp.sys [44112 2009-07-14] () R3 IntcAzAudAddService; C:\Windows\System32\drivers\RTKVHD64.sys [2917096 2011-07-12] () R3 IntcDAud; C:\Windows\System32\DRIVERS\IntcDAud.sys [317440 2010-10-14] () S3 intelide; C:\Windows\system32\drivers\intelide.sys [16960 2009-07-14] () R3 intelppm; C:\Windows\System32\DRIVERS\intelppm.sys [62464 2009-07-14] () S3 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [82944 2010-11-21] () S3 IPMIDRV; C:\Windows\system32\drivers\IPMIDrv.sys [78848 2010-11-21] () S3 IPNAT; C:\Windows\System32\drivers\ipnat.sys [116224 2009-07-14] () S3 IRENUM; C:\Windows\System32\drivers\irenum.sys [17920 2009-07-14] () S3 isapnp; C:\Windows\system32\drivers\isapnp.sys [20544 2009-07-14] () S3 iScsiPrt; C:\Windows\system32\drivers\msiscsi.sys [274880 2014-02-04] () R3 kbdclass; C:\Windows\System32\DRIVERS\kbdclass.sys [50768 2009-07-14] () S3 kbdhid; C:\Windows\system32\drivers\kbdhid.sys [33280 2010-11-21] () R0 KSecDD; C:\Windows\System32\Drivers\ksecdd.sys [95680 2014-04-12] () R0 KSecPkg; C:\Windows\System32\Drivers\ksecpkg.sys [155072 2014-04-12] () R3 ksthunk; C:\Windows\system32\drivers\ksthunk.sys [20992 2009-07-14] () R2 lltdio; C:\Windows\System32\DRIVERS\lltdio.sys [60928 2009-07-14] () S3 LSI_FC; C:\Windows\system32\drivers\lsi_fc.sys [114752 2009-07-14] () S3 LSI_SAS; C:\Windows\system32\drivers\lsi_sas.sys [106560 2009-07-14] () S3 LSI_SAS2; C:\Windows\system32\drivers\lsi_sas2.sys [65600 2009-07-14] () S3 LSI_SCSI; C:\Windows\system32\drivers\lsi_scsi.sys [115776 2009-07-14] () R2 luafv; C:\Windows\system32\drivers\luafv.sys [113152 2009-07-14] () S3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-10] () S3 megasas; C:\Windows\system32\drivers\megasas.sys [35392 2009-07-14] () S3 MegaSR; C:\Windows\system32\drivers\MegaSR.sys [284736 2009-07-14] () R3 MEIx64; C:\Windows\System32\DRIVERS\HECIx64.sys [56344 2010-10-20] () S3 Modem; C:\Windows\System32\drivers\modem.sys [40448 2009-07-14] () R3 monitor; C:\Windows\System32\DRIVERS\monitor.sys [30208 2009-07-14] () R3 mouclass; C:\Windows\System32\DRIVERS\mouclass.sys [49216 2009-07-14] () R3 mouhid; C:\Windows\System32\DRIVERS\mouhid.sys [31232 2009-07-14] () R0 mountmgr; C:\Windows\System32\drivers\mountmgr.sys [94592 2010-11-21] () S3 mpio; C:\Windows\system32\drivers\mpio.sys [155008 2010-11-21] () R3 mpsdrv; C:\Windows\System32\drivers\mpsdrv.sys [77312 2009-07-14] () S3 MRxDAV; C:\Windows\system32\drivers\mrxdav.sys [140800 2013-07-04] () R3 mrxsmb; C:\Windows\System32\DRIVERS\mrxsmb.sys [158208 2011-04-27] () R3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [288768 2011-07-09] () R3 mrxsmb20; C:\Windows\System32\DRIVERS\mrxsmb20.sys [128000 2011-04-27] () R0 msahci; C:\Windows\System32\drivers\msahci.sys [31104 2010-11-21] () S3 msdsm; C:\Windows\system32\drivers\msdsm.sys [140672 2010-11-21] () R1 Msfs; C:\Windows\System32\Drivers\Msfs.sys [26112 2009-07-14] () S3 mshidkmdf; C:\Windows\System32\drivers\mshidkmdf.sys [8192 2009-07-14] () R0 msisadrv; C:\Windows\System32\drivers\msisadrv.sys [15424 2009-07-14] () S3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [11136 2009-07-14] () S3 MSPCLOCK; C:\Windows\System32\drivers\MSPCLOCK.sys [7168 2009-07-14] () S3 MSPQM; C:\Windows\System32\drivers\MSPQM.sys [6784 2009-07-14] () S3 MsRPC; C:\Windows\System32\Drivers\MsRPC.sys [366976 2010-11-21] () R1 mssmbios; C:\Windows\System32\DRIVERS\mssmbios.sys [32320 2009-07-14] () S3 MSTEE; C:\Windows\System32\drivers\MSTEE.sys [8064 2009-07-14] () S3 MTConfig; C:\Windows\system32\drivers\MTConfig.sys [15360 2009-07-14] () R0 Mup; C:\Windows\System32\Drivers\mup.sys [60496 2009-07-14] () R3 NativeWifiP; C:\Windows\System32\DRIVERS\nwifi.sys [318976 2009-07-14] () R0 NDIS; C:\Windows\System32\drivers\ndis.sys [950128 2012-08-22] () S3 NdisCap; C:\Windows\System32\DRIVERS\ndiscap.sys [35328 2009-07-14] () R3 NdisTapi; C:\Windows\System32\DRIVERS\ndistapi.sys [24064 2009-07-14] () R3 Ndisuio; C:\Windows\System32\DRIVERS\ndisuio.sys [56832 2010-11-21] () R3 NdisWan; C:\Windows\System32\DRIVERS\ndiswan.sys [164352 2010-11-21] () R3 NDProxy; C:\Windows\System32\Drivers\NDProxy.sys [57856 2010-11-21] () R1 NetBIOS; C:\Windows\System32\DRIVERS\netbios.sys [44544 2009-07-14] () R1 NetBT; C:\Windows\System32\DRIVERS\netbt.sys [261632 2010-11-21] () R3 NETwNs64; C:\Windows\System32\DRIVERS\NETwNs64.sys [8604672 2011-09-17] () S3 nfrd960; C:\Windows\system32\drivers\nfrd960.sys [51264 2009-07-14] () R1 Npfs; C:\Windows\System32\Drivers\Npfs.sys [44032 2009-07-14] () R1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [24576 2009-07-14] () R3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1684928 2014-01-24] () R1 Null; C:\Windows\System32\Drivers\Null.sys [6144 2009-07-14] () R3 nvlddmkm; C:\Windows\System32\DRIVERS\nvlddmkm.sys [13076328 2011-06-05] () R0 nvpciflt; C:\Windows\System32\DRIVERS\nvpciflt.sys [25960 2011-06-05] () S3 nvraid; C:\Windows\system32\drivers\nvraid.sys [148352 2011-03-11] () S3 nvstor; C:\Windows\system32\drivers\nvstor.sys [166272 2011-03-11] () S3 nv_agp; C:\Windows\system32\drivers\nv_agp.sys [122960 2009-07-14] () S3 ohci1394; C:\Windows\system32\drivers\ohci1394.sys [72832 2009-07-14] () S3 Parport; C:\Windows\system32\drivers\parport.sys [97280 2009-07-14] () R0 partmgr; C:\Windows\System32\drivers\partmgr.sys [75120 2012-03-17] () R0 pci; C:\Windows\System32\drivers\pci.sys [184704 2010-11-21] () S3 pciide; C:\Windows\system32\drivers\pciide.sys [12352 2009-07-14] () S3 pcmcia; C:\Windows\system32\drivers\pcmcia.sys [220752 2009-07-14] () R0 pcw; C:\Windows\System32\drivers\pcw.sys [50768 2009-07-14] () R2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [651264 2009-07-14] () R3 PptpMiniport; C:\Windows\System32\DRIVERS\raspptp.sys [111104 2010-11-21] () S3 Processor; C:\Windows\system32\drivers\processr.sys [60416 2009-07-14] () R1 Psched; C:\Windows\System32\DRIVERS\pacer.sys [131584 2010-11-21] () S3 ql2300; C:\Windows\system32\drivers\ql2300.sys [1524816 2009-07-14] () S3 ql40xx; C:\Windows\system32\drivers\ql40xx.sys [128592 2009-07-14] () S3 QWAVEdrv; C:\Windows\system32\drivers\qwavedrv.sys [46592 2009-07-14] () S3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [14848 2009-07-14] () R3 RasAgileVpn; C:\Windows\System32\DRIVERS\AgileVpn.sys [60416 2009-07-14] () R3 Rasl2tp; C:\Windows\System32\DRIVERS\rasl2tp.sys [129536 2010-11-21] () R3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [92672 2009-07-14] () R3 RasSstp; C:\Windows\System32\DRIVERS\rassstp.sys [83968 2009-07-14] () R1 rdbss; C:\Windows\System32\DRIVERS\rdbss.sys [309248 2010-11-21] () S3 rdpbus; C:\Windows\system32\drivers\rdpbus.sys [24064 2009-07-14] () R1 RDPCDD; C:\Windows\System32\DRIVERS\RDPCDD.sys [7680 2009-07-14] () R1 RDPENCDD; C:\Windows\System32\drivers\rdpencdd.sys [7680 2009-07-14] () R1 RDPREFMP; C:\Windows\System32\drivers\rdprefmp.sys [8192 2009-07-14] () S3 RDPWD; C:\Windows\System32\Drivers\RDPWD.sys [210944 2012-04-28] () R0 rdyboost; C:\Windows\System32\drivers\rdyboost.sys [213888 2010-11-21] () R3 RFCOMM; C:\Windows\System32\DRIVERS\rfcomm.sys [158720 2009-07-14] () R2 rspndr; C:\Windows\System32\DRIVERS\rspndr.sys [76800 2009-07-14] () R3 RTL8167; C:\Windows\System32\DRIVERS\Rt64win7.sys [471144 2011-04-22] () S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-04-13] () R1 SABI; C:\windows\system32\Drivers\SABI.sys [13824 2011-07-30] () S3 sbp2port; C:\Windows\system32\drivers\sbp2port.sys [103808 2010-11-21] () S3 scfilter; C:\Windows\System32\DRIVERS\scfilter.sys [29696 2010-11-21] () R2 secdrv; C:\Windows\System32\Drivers\secdrv.sys [23040 2009-06-10] () S3 Serenum; C:\Windows\system32\drivers\serenum.sys [23552 2009-07-14] () S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] () S3 sermouse; C:\Windows\system32\drivers\sermouse.sys [26624 2009-07-14] () S3 sffdisk; C:\Windows\system32\drivers\sffdisk.sys [14336 2009-07-14] () S3 sffp_mmc; C:\Windows\system32\drivers\sffp_mmc.sys [13824 2009-07-14] () S3 sffp_sd; C:\Windows\system32\drivers\sffp_sd.sys [14336 2010-11-21] () S3 sfloppy; C:\Windows\system32\drivers\sfloppy.sys [16896 2009-07-14] () R2 SGDrv; C:\Windows\System32\DRIVERS\SGdrv64.sys [7680 2011-04-11] () S3 SiSRaid2; C:\Windows\system32\drivers\SiSRaid2.sys [43584 2009-07-14] () S3 SiSRaid4; C:\Windows\system32\drivers\sisraid4.sys [80464 2009-07-14] () S3 Smb; C:\Windows\System32\DRIVERS\smb.sys [93184 2009-07-14] () R0 spldr; C:\Windows\System32\Drivers\spldr.sys [19008 2009-07-14] () R3 srv; C:\Windows\System32\DRIVERS\srv.sys [467456 2011-04-29] () R3 srv2; C:\Windows\System32\DRIVERS\srv2.sys [410112 2011-04-29] () R3 srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [168448 2011-04-29] () S3 stexstor; C:\Windows\system32\drivers\stexstor.sys [24656 2009-07-14] () R3 swenum; C:\Windows\System32\DRIVERS\swenum.sys [12496 2009-07-14] () R3 SynTP; C:\Windows\System32\DRIVERS\SynTP.sys [1440816 2011-05-13] () R0 Tcpip; C:\Windows\System32\drivers\tcpip.sys [1903552 2013-09-08] () S3 TCPIP6; C:\Windows\System32\DRIVERS\tcpip.sys [1903552 2013-09-08] () R2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [45568 2012-10-03] () S3 TDPIPE; C:\Windows\System32\drivers\tdpipe.sys [15872 2009-07-14] () S3 TDTCP; C:\Windows\System32\drivers\tdtcp.sys [23552 2012-02-17] () R1 tdx; C:\Windows\System32\DRIVERS\tdx.sys [119296 2010-11-21] () R1 TermDD; C:\Windows\System32\DRIVERS\termdd.sys [63360 2010-11-21] () S3 tssecsrv; C:\Windows\System32\DRIVERS\tssecsrv.sys [39936 2013-06-15] () S3 TsUsbFlt; C:\Windows\System32\drivers\tsusbflt.sys [59392 2010-11-21] () S3 TsUsbGD; C:\Windows\system32\drivers\TsUsbGD.sys [31232 2010-11-21] () R3 tunnel; C:\Windows\System32\DRIVERS\tunnel.sys [125440 2010-11-21] () S3 uagp35; C:\Windows\system32\drivers\uagp35.sys [64080 2009-07-14] () S4 udfs; C:\Windows\System32\DRIVERS\udfs.sys [328192 2010-11-21] () S3 uliagpkx; C:\Windows\system32\drivers\uliagpkx.sys [64592 2009-07-14] () R3 umbus; C:\Windows\System32\DRIVERS\umbus.sys [48640 2010-11-21] () S3 UmPass; C:\Windows\system32\drivers\umpass.sys [9728 2009-07-14] () R3 usbccgp; C:\Windows\System32\DRIVERS\usbccgp.sys [99840 2013-11-27] () S3 usbcir; C:\Windows\system32\drivers\usbcir.sys [100864 2013-07-12] () R3 usbehci; C:\Windows\system32\drivers\usbehci.sys [53248 2013-11-27] () R3 usbhub; C:\Windows\System32\DRIVERS\usbhub.sys [343040 2013-11-27] () S3 usbohci; C:\Windows\system32\drivers\usbohci.sys [25600 2013-11-27] () S3 usbprint; C:\Windows\system32\drivers\usbprint.sys [25088 2009-07-14] () S3 USBSTOR; C:\Windows\System32\DRIVERS\USBSTOR.SYS [91648 2011-03-11] () S3 usbuhci; C:\Windows\system32\drivers\usbuhci.sys [30720 2013-11-27] () R3 usbvideo; C:\Windows\System32\Drivers\usbvideo.sys [185344 2013-07-12] () R2 VBoxDrv; C:\Program Files (x86)\YouWave Android\vb\VBoxDrv.sys [202592 2011-11-20] () R0 vdrvroot; C:\Windows\System32\drivers\vdrvroot.sys [36432 2009-07-14] () S3 vga; C:\Windows\System32\DRIVERS\vgapnp.sys [29184 2009-07-14] () R1 VgaSave; C:\Windows\System32\drivers\vga.sys [29184 2009-07-14] () S3 vhdmp; C:\Windows\system32\drivers\vhdmp.sys [215936 2010-11-21] () S3 viaide; C:\Windows\system32\drivers\viaide.sys [17488 2009-07-14] () R0 volmgr; C:\Windows\System32\drivers\volmgr.sys [71552 2010-11-21] () R0 volmgrx; C:\Windows\System32\drivers\volmgrx.sys [363392 2010-11-21] () R0 volsnap; C:\Windows\System32\drivers\volsnap.sys [296320 2011-02-25] () S3 vsmraid; C:\Windows\system32\drivers\vsmraid.sys [161872 2009-07-14] () R3 vwifibus; C:\Windows\System32\DRIVERS\vwifibus.sys [24576 2009-07-14] () R1 vwififlt; C:\Windows\System32\DRIVERS\vwififlt.sys [60416 2011-01-25] () R3 vwifimp; C:\Windows\System32\DRIVERS\vwifimp.sys [18432 2011-01-25] () S3 WacomPen; C:\Windows\system32\drivers\wacompen.sys [27776 2009-07-14] () S3 WANARP; C:\Windows\System32\DRIVERS\wanarp.sys [88576 2010-11-21] () R1 Wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [88576 2010-11-21] () S3 Wd; C:\Windows\system32\drivers\wd.sys [21056 2009-07-14] () R0 Wdf01000; C:\Windows\System32\drivers\Wdf01000.sys [785624 2013-06-26] () R1 WfpLwf; C:\Windows\System32\DRIVERS\wfplwf.sys [12800 2009-07-14] () S3 WIMMount; C:\Windows\System32\drivers\wimmount.sys [22096 2009-07-14] () S3 WinUsb; C:\Windows\System32\DRIVERS\WinUsb.sys [41984 2010-11-21] () S3 WmiAcpi; C:\Windows\system32\drivers\wmiacpi.sys [14336 2009-07-14] () S4 ws2ifsl; C:\Windows\system32\drivers\ws2ifsl.sys [21504 2009-07-14] () S3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [87040 2012-07-26] () S3 WUDFRd; C:\Windows\System32\DRIVERS\WUDFRd.sys [198656 2012-07-26] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-22 16:25 - 2014-05-22 16:25 - 00030690 _____ () C:\Users\Samsung\Desktop\FRST.txt 2014-05-22 16:24 - 2014-05-22 16:24 - 01326389 _____ () C:\Users\Samsung\Downloads\adwcleaner_3.210 (1).exe 2014-05-22 16:23 - 2014-05-22 16:23 - 00005066 _____ () C:\Users\Samsung\Desktop\AdwCleaner[S0].txt 2014-05-22 16:20 - 2014-05-22 16:20 - 00000000 ____D () C:\AdwCleaner 2014-05-22 16:20 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll 2014-05-22 16:19 - 2014-05-22 16:19 - 01326389 _____ () C:\Users\Samsung\Downloads\adwcleaner_3.210.exe 2014-05-22 16:00 - 2014-05-22 16:00 - 00000000 ____D () C:\Users\Samsung\Desktop\FRST-OlderVersion 2014-05-22 10:26 - 2014-05-22 10:26 - 00002261 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-05-22 10:26 - 2014-05-22 10:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-05-22 10:21 - 2014-05-22 10:21 - 00918672 _____ (Google Inc.) C:\Users\Samsung\Downloads\ChromeSetup.exe 2014-05-22 10:18 - 2014-05-22 10:18 - 00130560 _____ (Igor Pavlov) C:\Users\Samsung\Downloads\setup.exe 2014-05-21 23:24 - 2014-05-21 23:24 - 00173056 _____ (Trifecta Technologies) C:\windows\SysWOW64\aaaaaaaa.exe 2014-05-21 23:24 - 2014-05-21 23:24 - 00173056 _____ (Trifecta Technologies) C:\Users\Samsung\aaaaaaaa.exe 2014-05-21 23:22 - 2014-05-21 23:22 - 00090112 _____ () C:\Users\Samsung\Downloads\setup (2).exe 2014-05-21 08:57 - 2014-05-21 08:57 - 00063936 _____ () C:\windows\system32\Drivers\173ac4b2719b9b72.sys 2014-05-17 19:08 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-05-17 19:08 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-05-17 19:08 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-05-17 19:08 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-05-17 19:08 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-05-17 19:08 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-05-15 20:36 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-05-15 20:36 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-05-15 20:36 - 2014-04-12 04:22 - 00155072 _____ () C:\windows\system32\Drivers\ksecpkg.sys 2014-05-15 20:36 - 2014-04-12 04:22 - 00095680 _____ () C:\windows\system32\Drivers\ksecdd.sys 2014-05-15 20:36 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2014-05-15 20:36 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll 2014-05-15 20:36 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe 2014-05-15 20:36 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll 2014-05-15 20:36 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll 2014-05-15 20:36 - 2014-03-04 11:47 - 05550016 _____ () C:\windows\system32\ntoskrnl.exe 2014-05-15 20:36 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll 2014-05-15 20:36 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll 2014-05-15 20:36 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll 2014-05-15 20:36 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2014-05-15 20:36 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll 2014-05-15 20:36 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll 2014-05-15 20:36 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll 2014-05-15 20:36 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll 2014-05-15 20:36 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe 2014-05-15 20:36 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll 2014-05-15 20:36 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll 2014-05-15 20:36 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll 2014-05-15 20:36 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll 2014-05-15 20:36 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll 2014-05-15 20:36 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe 2014-05-15 20:36 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe 2014-05-15 20:36 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll 2014-05-15 20:36 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\windows\SysWOW64\objsel.dll 2014-05-15 20:36 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll 2014-05-15 20:36 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll 2014-05-15 20:36 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll 2014-05-15 20:36 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll 2014-05-15 20:36 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\cngprovider.dll 2014-05-15 20:36 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\windows\SysWOW64\adprovider.dll 2014-05-15 20:36 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\capiprovider.dll 2014-05-15 20:36 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpapiprovider.dll 2014-05-15 20:36 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\dimsroam.dll 2014-05-15 20:36 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wincredprovider.dll 2014-05-15 20:36 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll 2014-05-15 20:35 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll 2014-05-15 20:35 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll 2014-05-15 20:35 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll 2014-05-15 20:35 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll 2014-05-15 20:35 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll 2014-05-15 20:35 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll 2014-05-06 08:50 - 2014-05-17 20:43 - 00000000 ___SD () C:\windows\system32\CompatTel 2014-05-04 22:01 - 2014-05-04 22:01 - 00000000 ____D () C:\Users\Samsung\AppData\Local\TB 2014-04-26 14:52 - 2014-04-26 14:52 - 00090798 _____ () C:\Users\Samsung\Downloads\Extras.Txt 2014-04-26 14:52 - 2014-04-26 14:52 - 00074958 _____ () C:\Users\Samsung\Downloads\OTL.Txt1.txt 2014-04-26 14:51 - 2014-04-26 14:51 - 00074958 _____ () C:\Users\Samsung\Downloads\OTL.Txt 2014-04-26 14:42 - 2014-04-26 14:42 - 00000000 _____ () C:\Users\Samsung\Desktop\Nowy dokument tekstowy.txt 2014-04-26 12:55 - 2014-04-26 12:56 - 00602112 _____ (OldTimer Tools) C:\Users\Samsung\Downloads\OTL.scr 2014-04-26 12:31 - 2014-04-26 12:31 - 00368705 _____ () C:\Users\Samsung\Downloads\gm.zip 2014-04-26 12:30 - 2014-04-26 12:32 - 00038597 _____ () C:\Users\Samsung\Downloads\Addition.txt 2014-04-26 12:29 - 2014-04-26 12:32 - 00045074 _____ () C:\Users\Samsung\Downloads\FRST.txt 2014-04-26 12:28 - 2014-05-22 16:25 - 00000000 ____D () C:\FRST 2014-04-26 12:27 - 2014-05-22 16:00 - 02067456 _____ (Farbar) C:\Users\Samsung\Desktop\FRST64.exe 2014-04-26 12:24 - 2014-05-10 09:45 - 00119512 _____ () C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-26 12:24 - 2014-04-26 12:24 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-04-26 12:24 - 2014-04-26 12:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-04-26 12:24 - 2014-04-26 12:24 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-26 12:24 - 2014-04-26 12:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-04-26 12:24 - 2014-04-03 09:51 - 00088280 _____ () C:\windows\system32\Drivers\mbamchameleon.sys 2014-04-26 12:24 - 2014-04-03 09:51 - 00063192 _____ () C:\windows\system32\Drivers\mwac.sys 2014-04-26 12:24 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-04-26 12:23 - 2014-04-26 12:32 - 00046331 _____ () C:\Users\Samsung\Downloads\Shortcut.txt 2014-04-26 12:22 - 2014-04-26 15:02 - 00000000 ____D () C:\Users\Samsung\Desktop\WYNIKI SKANU 2014-04-26 12:22 - 2014-04-26 12:23 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Samsung\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-26 12:21 - 2014-04-26 12:21 - 00047487 _____ () C:\Users\Samsung\Downloads\mbam.txt ==================== One Month Modified Files and Folders ======= 2014-05-22 16:25 - 2014-05-22 16:25 - 00030690 _____ () C:\Users\Samsung\Desktop\FRST.txt 2014-05-22 16:25 - 2014-04-26 12:28 - 00000000 ____D () C:\FRST 2014-05-22 16:24 - 2014-05-22 16:24 - 01326389 _____ () C:\Users\Samsung\Downloads\adwcleaner_3.210 (1).exe 2014-05-22 16:23 - 2014-05-22 16:23 - 00005066 _____ () C:\Users\Samsung\Desktop\AdwCleaner[S0].txt 2014-05-22 16:23 - 2013-02-28 15:10 - 00000000 ____D () C:\Users\Samsung\AppData\Local\CrashDumps 2014-05-22 16:22 - 2013-06-21 14:45 - 00001046 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-22 16:22 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-05-22 16:21 - 2010-11-21 05:47 - 00808552 _____ () C:\windows\PFRO.log 2014-05-22 16:21 - 2009-07-14 06:51 - 00097358 _____ () C:\windows\setupact.log 2014-05-22 16:20 - 2014-05-22 16:20 - 00000000 ____D () C:\AdwCleaner 2014-05-22 16:19 - 2014-05-22 16:19 - 01326389 _____ () C:\Users\Samsung\Downloads\adwcleaner_3.210.exe 2014-05-22 16:09 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-22 16:09 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-22 16:08 - 2013-06-21 14:45 - 00001050 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-22 16:00 - 2014-05-22 16:00 - 00000000 ____D () C:\Users\Samsung\Desktop\FRST-OlderVersion 2014-05-22 16:00 - 2014-04-26 12:27 - 02067456 _____ (Farbar) C:\Users\Samsung\Desktop\FRST64.exe 2014-05-22 16:00 - 2012-10-13 17:11 - 00001705 _____ () C:\Users\Samsung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-22 10:39 - 2013-09-13 14:31 - 00000930 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-05-22 10:26 - 2014-05-22 10:26 - 00002261 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-05-22 10:26 - 2014-05-22 10:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-05-22 10:25 - 2013-06-21 14:45 - 00000000 ____D () C:\Program Files (x86)\Google 2014-05-22 10:21 - 2014-05-22 10:21 - 00918672 _____ (Google Inc.) C:\Users\Samsung\Downloads\ChromeSetup.exe 2014-05-22 10:18 - 2014-05-22 10:18 - 00130560 _____ (Igor Pavlov) C:\Users\Samsung\Downloads\setup.exe 2014-05-21 23:24 - 2014-05-21 23:24 - 00173056 _____ (Trifecta Technologies) C:\windows\SysWOW64\aaaaaaaa.exe 2014-05-21 23:24 - 2014-05-21 23:24 - 00173056 _____ (Trifecta Technologies) C:\Users\Samsung\aaaaaaaa.exe 2014-05-21 23:24 - 2012-10-13 17:04 - 00000000 ____D () C:\Users\Samsung 2014-05-21 23:22 - 2014-05-21 23:22 - 00090112 _____ () C:\Users\Samsung\Downloads\setup (2).exe 2014-05-21 08:59 - 2013-06-21 14:45 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update 2014-05-21 08:57 - 2014-05-21 08:57 - 00063936 _____ () C:\windows\system32\Drivers\173ac4b2719b9b72.sys 2014-05-21 08:56 - 2012-01-10 06:35 - 01937575 _____ () C:\windows\WindowsUpdate.log 2014-05-17 20:46 - 2012-10-13 17:11 - 00000000 ___RD () C:\Users\Samsung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-17 20:46 - 2012-10-13 17:11 - 00000000 ___RD () C:\Users\Samsung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-17 20:43 - 2014-05-06 08:50 - 00000000 ___SD () C:\windows\system32\CompatTel 2014-05-16 18:00 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\NDF 2014-05-16 17:43 - 2013-04-01 13:47 - 93223848 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-05-15 19:50 - 2013-09-13 14:31 - 00003868 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-05-15 19:50 - 2013-03-29 13:00 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-05-15 19:50 - 2013-03-29 13:00 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-10 13:39 - 2012-01-10 06:18 - 00744192 _____ () C:\windows\system32\perfh015.dat 2014-05-10 13:39 - 2012-01-10 06:18 - 00158076 _____ () C:\windows\system32\perfc015.dat 2014-05-10 13:39 - 2009-07-14 07:13 - 01680660 _____ () C:\windows\system32\PerfStringBackup.INI 2014-05-10 09:45 - 2014-04-26 12:24 - 00119512 _____ () C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-09 08:14 - 2014-05-15 20:36 - 00477184 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-05-09 08:11 - 2014-05-15 20:36 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-05-08 22:32 - 2014-04-08 10:48 - 00110080 ___SH () C:\Users\Samsung\Desktop\Thumbs.db 2014-05-07 23:03 - 2013-06-21 14:45 - 00004046 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-07 23:03 - 2013-06-21 14:45 - 00003794 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-06 06:40 - 2014-05-17 19:08 - 23544320 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-05-06 06:17 - 2014-05-17 19:08 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-05-06 05:25 - 2014-05-17 19:08 - 17382912 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-05-06 05:07 - 2014-05-17 19:08 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-05-06 05:00 - 2014-05-17 19:08 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-05-06 04:10 - 2014-05-17 19:08 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-05-05 22:58 - 2013-06-21 14:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2014-05-04 22:01 - 2014-05-04 22:01 - 00000000 ____D () C:\Users\Samsung\AppData\Local\TB 2014-05-04 12:26 - 2011-02-11 21:56 - 00000000 ____D () C:\windows\Sec 2014-05-01 15:53 - 2014-03-04 20:32 - 00000000 ____D () C:\Users\Samsung\Desktop\zdjj 2014-05-01 15:53 - 2014-01-20 20:18 - 00000000 ____D () C:\Users\Samsung\Desktop\audi 2014-05-01 15:53 - 2013-12-18 13:21 - 00000000 ____D () C:\Users\Samsung\Desktop\ja 2014-05-01 15:53 - 2013-07-25 16:04 - 00000000 ____D () C:\Users\Samsung\Desktop\m, 2014-04-26 16:34 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache 2014-04-26 15:02 - 2014-04-26 12:22 - 00000000 ____D () C:\Users\Samsung\Desktop\WYNIKI SKANU 2014-04-26 14:52 - 2014-04-26 14:52 - 00090798 _____ () C:\Users\Samsung\Downloads\Extras.Txt 2014-04-26 14:52 - 2014-04-26 14:52 - 00074958 _____ () C:\Users\Samsung\Downloads\OTL.Txt1.txt 2014-04-26 14:51 - 2014-04-26 14:51 - 00074958 _____ () C:\Users\Samsung\Downloads\OTL.Txt 2014-04-26 14:42 - 2014-04-26 14:42 - 00000000 _____ () C:\Users\Samsung\Desktop\Nowy dokument tekstowy.txt 2014-04-26 12:56 - 2014-04-26 12:55 - 00602112 _____ (OldTimer Tools) C:\Users\Samsung\Downloads\OTL.scr 2014-04-26 12:32 - 2014-04-26 12:30 - 00038597 _____ () C:\Users\Samsung\Downloads\Addition.txt 2014-04-26 12:32 - 2014-04-26 12:29 - 00045074 _____ () C:\Users\Samsung\Downloads\FRST.txt 2014-04-26 12:32 - 2014-04-26 12:23 - 00046331 _____ () C:\Users\Samsung\Downloads\Shortcut.txt 2014-04-26 12:31 - 2014-04-26 12:31 - 00368705 _____ () C:\Users\Samsung\Downloads\gm.zip 2014-04-26 12:24 - 2014-04-26 12:24 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-04-26 12:24 - 2014-04-26 12:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-04-26 12:24 - 2014-04-26 12:24 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-26 12:24 - 2014-04-26 12:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-04-26 12:23 - 2014-04-26 12:22 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Samsung\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-26 12:21 - 2014-04-26 12:21 - 00047487 _____ () C:\Users\Samsung\Downloads\mbam.txt Files to move or delete: ==================== C:\Users\Samsung\AppData\Local\Temp\Buij\evvi.exe C:\Users\Samsung\aaaaaaaa.exe Some content of TEMP: ==================== C:\Users\Samsung\AppData\Local\Temp\922199.exe C:\Users\Samsung\AppData\Local\Temp\cabex.dll C:\Users\Samsung\AppData\Local\Temp\ggdrive-menu.exe C:\Users\Samsung\AppData\Local\Temp\ggdrive-overlay.exe C:\Users\Samsung\AppData\Local\Temp\ggsetup1362919965.exe C:\Users\Samsung\AppData\Local\Temp\installstats.exe C:\Users\Samsung\AppData\Local\Temp\ipl5B87.tmp.exe C:\Users\Samsung\AppData\Local\Temp\iplC6D7.tmp.exe C:\Users\Samsung\AppData\Local\Temp\Quarantine.exe C:\Users\Samsung\AppData\Local\Temp\unelevate.exe C:\Users\Samsung\AppData\Local\Temp\uninst1.exe C:\Users\Samsung\AppData\Local\Temp\uttFBB0.tmp.exe C:\Users\Samsung\AppData\Local\Temp\VARemove.exe C:\Users\Samsung\AppData\Local\Temp\yta_bu12_setup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys [2012-01-09 14:03] - [2011-02-25 08:25] - 0296320 ____A () D41D8CD98F00B204E9800998ECF8427E C:\Windows\System32\Drivers\volsnap.sys No Company Name <===== ATTENTION! testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION! LastRegBack: 2014-04-26 16:21 ==================== End Of Log ============================