Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-07-2014 Ran by Adrian (administrator) on ADRIAN on 04-07-2014 18:07:19 Running from C:\Users\Adrian\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polski (Polska) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ArtistScope Pty Ltd) C:\Program Files\Common Files\ArtistScope\CSHelper64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Creative Technology Ltd.) C:\Windows\V0350Mon.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () D:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe () D:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.212\deploy\LoLLauncher.exe () D:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.99\deploy\LolClient.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_125.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_125.exe () C:\Users\Adrian\Desktop\gmer.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM-x32\...\Run: [V0350Mon.exe] => C:\Windows\V0350Mon.exe [28672 2007-08-23] (Creative Technology Ltd.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [301568 2013-04-30] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== SearchScopes: HKLM-x32 - DefaultScope value is missing. BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\..\Interfaces\{125C4FAF-8776-4E90-A306-1BB7AC348470}: [NameServer]82.160.111.111,82.160.1.1,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1 FireFox: ======== FF ProfilePath: C:\Users\Adrian\AppData\Roaming\Mozilla\Firefox\Profiles\k2d45yrp.default-1388411162753 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.) FF Plugin-x32: @artistscope.com/ArtistScope Plugin - C:\Program Files (x86)\Common Files\ArtistScope\npArtistScope.dll (ArtistScope Pty Ltd) FF Plugin-x32: @artistscope.com/ArtistScope Plugin 5 - C:\Program Files (x86)\Common Files\ArtistScope\npArtistScope5.dll (ArtistScope Pty Ltd) FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: @artistscope.com/ArtistScope Plugin - C:\Program Files (x86)\Common Files\ArtistScope\npArtistScope.dll (ArtistScope Pty Ltd) FF Plugin HKCU: @artistscope.com/ArtistScope Plugin 5 - C:\Program Files (x86)\Common Files\ArtistScope\npArtistScope5.dll (ArtistScope Pty Ltd) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Adrian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Extension: Nervarien Stream - C:\Users\Adrian\AppData\Roaming\Mozilla\Firefox\Profiles\k2d45yrp.default-1388411162753\Extensions\a2ed01@wips.com [2014-07-03] FF Extension: NetVideoHunter - C:\Users\Adrian\AppData\Roaming\Mozilla\Firefox\Profiles\k2d45yrp.default-1388411162753\Extensions\netvideohunter@netvideohunter.com [2014-04-15] FF Extension: Adblock Plus - C:\Users\Adrian\AppData\Roaming\Mozilla\Firefox\Profiles\k2d45yrp.default-1388411162753\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-07-03] ==================== Services (Whitelisted) ================= R2 CSHelper; C:\Program Files\Common Files\ArtistScope\CSHelper64.exe [361552 2013-09-26] (ArtistScope Pty Ltd) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) ==================== Drivers (Whitelisted) ==================== S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.) S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.) S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93696 2013-04-23] (LG Electronics Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 cpudrv64; C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [17864 2011-06-02] () R1 CSDriver; C:\Program Files\Common Files\ArtistScope\CSDriver64.sys [61424 2013-09-26] () S3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [27648 2008-01-19] (Microsoft Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) S3 Ph3xIB64; C:\Windows\System32\DRIVERS\Ph3xIB64.sys [1627520 2009-06-10] (NXP Semiconductors) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-07-13] (Duplex Secure Ltd.) R3 VF0350Vfx; C:\Windows\System32\DRIVERS\V0350VFx.sys [12288 2007-03-05] (EyePower Games Pte. Ltd.) R3 VF0350Vid; C:\Windows\System32\DRIVERS\V0350Vid.sys [214976 2007-08-29] (Creative Technology Ltd.) S1 fixsrzjn; \??\C:\Windows\system32\drivers\fixsrzjn.sys [X] U3 uxldrpod; \??\C:\Users\Adrian\AppData\Local\Temp\uxldrpod.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-04 18:04 - 2014-07-04 18:04 - 00063576 _____ () C:\Users\Adrian\Desktop\OTL.Txt 2014-07-04 18:04 - 2014-07-04 18:04 - 00063178 _____ () C:\Users\Adrian\Desktop\Extras.Txt 2014-07-04 17:58 - 2014-07-04 17:58 - 00380416 _____ () C:\Users\Adrian\Desktop\gmer.exe 2014-07-04 17:54 - 2014-07-04 18:08 - 00008707 _____ () C:\Users\Adrian\Desktop\FRST.txt 2014-07-04 17:54 - 2014-07-04 17:54 - 00602112 _____ (OldTimer Tools) C:\Users\Adrian\Desktop\OTL.exe 2014-07-04 17:53 - 2014-07-04 17:53 - 02083840 _____ (Farbar) C:\Users\Adrian\Desktop\FRST64.exe 2014-07-04 10:22 - 2014-07-04 10:22 - 00112640 _____ () C:\Users\Adrian\Desktop\winbox.exe 2014-07-01 23:30 - 2014-07-01 23:30 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Adobe 2014-06-30 21:13 - 2014-07-02 17:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microids 2014-06-29 14:55 - 2014-06-29 14:55 - 00015883 _____ () C:\Windows\SysWOW64\hs_err_pid704.log 2014-06-27 00:10 - 2014-06-27 00:12 - 50969171 _____ () C:\Users\Adrian\Downloads\temple-run-2-1-9-1-en-android.apk 2014-06-24 16:21 - 2014-07-04 13:00 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\BoL 2014-06-22 21:15 - 2014-07-04 08:43 - 00000000 ____D () C:\Users\Adrian\Desktop\Library Updater 2014-06-18 18:26 - 2014-06-18 18:26 - 00003090 _____ () C:\Windows\System32\Tasks\{CD914594-C0E2-42EB-B67F-243EDBB5FB66} 2014-06-16 17:06 - 2014-06-16 17:06 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Mikrotik 2014-06-14 13:51 - 2014-06-14 14:38 - 00000000 ____D () C:\AdwCleaner 2014-06-14 13:51 - 2014-06-14 13:51 - 00000000 ___SD () C:\ComboFix 2014-06-14 12:38 - 2014-06-14 12:38 - 00009048 _____ () C:\ComboFix.txt 2014-06-14 12:29 - 2014-06-14 13:51 - 00000000 ____D () C:\Qoobox 2014-06-14 12:29 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-14 12:29 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-14 12:29 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-14 12:29 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-14 12:29 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-14 12:29 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-14 12:29 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-14 12:29 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-14 12:28 - 2014-06-14 12:28 - 00000000 ____D () C:\Windows\erdnt 2014-06-11 17:55 - 2014-06-11 18:50 - 00000000 __SHD () C:\Windows\SysWOW64\ITXWDS 2014-06-11 17:55 - 2014-06-11 18:29 - 00000000 ____D () C:\Users\Adrian\Documents\UCA 2014-06-11 17:54 - 2014-06-14 12:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-10 07:50 - 2014-07-04 16:17 - 00347262 _____ () C:\Windows\WindowsUpdate.log 2014-06-09 20:25 - 2014-06-10 19:23 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Google ==================== One Month Modified Files and Folders ======= 2014-07-04 18:08 - 2014-07-04 17:54 - 00008707 _____ () C:\Users\Adrian\Desktop\FRST.txt 2014-07-04 18:07 - 2014-03-24 22:53 - 00000000 ____D () C:\FRST 2014-07-04 18:04 - 2014-07-04 18:04 - 00063576 _____ () C:\Users\Adrian\Desktop\OTL.Txt 2014-07-04 18:04 - 2014-07-04 18:04 - 00063178 _____ () C:\Users\Adrian\Desktop\Extras.Txt 2014-07-04 17:58 - 2014-07-04 17:58 - 00380416 _____ () C:\Users\Adrian\Desktop\gmer.exe 2014-07-04 17:54 - 2014-07-04 17:54 - 00602112 _____ (OldTimer Tools) C:\Users\Adrian\Desktop\OTL.exe 2014-07-04 17:53 - 2014-07-04 17:53 - 02083840 _____ (Farbar) C:\Users\Adrian\Desktop\FRST64.exe 2014-07-04 17:15 - 2013-07-25 13:26 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-04 17:13 - 2013-12-22 12:26 - 00000000 ____D () C:\Users\Adrian\AppData\Local\PMB Files 2014-07-04 16:17 - 2014-06-10 07:50 - 00347262 _____ () C:\Windows\WindowsUpdate.log 2014-07-04 13:00 - 2014-06-24 16:21 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\BoL 2014-07-04 13:00 - 2014-04-19 16:41 - 00000000 ____D () C:\Users\Adrian\Desktop\BoL Studio 2014-07-04 10:48 - 2013-05-21 21:59 - 00003962 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{C2A6A923-AD5C-4B6B-B871-67A360EFAD24} 2014-07-04 10:22 - 2014-07-04 10:22 - 00112640 _____ () C:\Users\Adrian\Desktop\winbox.exe 2014-07-04 10:19 - 2014-05-08 17:41 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\foobar2000 2014-07-04 08:57 - 2013-12-22 12:26 - 00000000 ____D () C:\ProgramData\PMB Files 2014-07-04 08:44 - 2009-07-14 19:55 - 00737730 _____ () C:\Windows\system32\perfh015.dat 2014-07-04 08:44 - 2009-07-14 19:55 - 00154418 _____ () C:\Windows\system32\perfc015.dat 2014-07-04 08:44 - 2009-07-14 07:13 - 01662556 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-04 08:43 - 2014-06-22 21:15 - 00000000 ____D () C:\Users\Adrian\Desktop\Library Updater 2014-07-04 08:42 - 2009-07-14 06:45 - 00022784 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-04 08:42 - 2009-07-14 06:45 - 00022784 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-04 08:37 - 2013-04-29 23:14 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-04 08:37 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-03 18:56 - 2013-12-26 14:14 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-07-03 18:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-07-03 16:32 - 2013-04-29 15:37 - 00007607 _____ () C:\Users\Adrian\AppData\Local\Resmon.ResmonCfg 2014-07-02 20:52 - 2014-04-23 16:45 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MKJogo 2014-07-02 17:22 - 2014-06-30 21:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microids 2014-07-02 17:22 - 2013-05-09 21:12 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-07-01 23:30 - 2014-07-01 23:30 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Adobe 2014-07-01 23:21 - 2013-04-29 19:24 - 00000000 ____D () C:\Users\Adrian\AbiSuite 2014-07-01 10:02 - 2014-05-22 19:50 - 00000219 _____ () C:\Users\Adrian\Desktop\Dota 2.url 2014-06-30 21:23 - 2013-04-29 14:39 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-06-29 14:55 - 2014-06-29 14:55 - 00015883 _____ () C:\Windows\SysWOW64\hs_err_pid704.log 2014-06-28 23:49 - 2013-07-25 13:26 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-28 23:49 - 2013-07-25 13:26 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-28 23:49 - 2013-04-29 16:02 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-28 15:33 - 2013-05-11 18:00 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Skype 2014-06-27 00:12 - 2014-06-27 00:10 - 50969171 _____ () C:\Users\Adrian\Downloads\temple-run-2-1-9-1-en-android.apk 2014-06-23 22:09 - 2009-07-14 07:08 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-06-18 18:26 - 2014-06-18 18:26 - 00003090 _____ () C:\Windows\System32\Tasks\{CD914594-C0E2-42EB-B67F-243EDBB5FB66} 2014-06-18 15:53 - 2014-04-23 16:46 - 00000054 _____ () C:\Windows\JQHApp.dat 2014-06-17 21:37 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-06-16 17:06 - 2014-06-16 17:06 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Mikrotik 2014-06-14 23:17 - 2013-05-14 21:41 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Media Player Classic 2014-06-14 14:39 - 2013-04-28 22:01 - 00000000 ____D () C:\Windows\System32\Tasks\Games 2014-06-14 14:38 - 2014-06-14 13:51 - 00000000 ____D () C:\AdwCleaner 2014-06-14 13:51 - 2014-06-14 13:51 - 00000000 ___SD () C:\ComboFix 2014-06-14 13:51 - 2014-06-14 12:29 - 00000000 ____D () C:\Qoobox 2014-06-14 12:46 - 2013-04-28 21:37 - 00000000 ____D () C:\Users\Adrian 2014-06-14 12:45 - 2014-06-11 17:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-14 12:45 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-06-14 12:38 - 2014-06-14 12:38 - 00009048 _____ () C:\ComboFix.txt 2014-06-14 12:38 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-06-14 12:28 - 2014-06-14 12:28 - 00000000 ____D () C:\Windows\erdnt 2014-06-14 08:58 - 2014-06-01 12:35 - 00000000 ____D () C:\Users\Adrian\Documents\GTA San Andreas User Files 2014-06-12 01:00 - 2013-08-17 12:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-11 18:50 - 2014-06-11 17:55 - 00000000 __SHD () C:\Windows\SysWOW64\ITXWDS 2014-06-11 18:29 - 2014-06-11 17:55 - 00000000 ____D () C:\Users\Adrian\Documents\UCA 2014-06-10 19:24 - 2013-04-29 16:15 - 00000000 ____D () C:\Program Files (x86)\Google 2014-06-10 19:23 - 2014-06-09 20:25 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Google ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-01 10:56 ==================== End Of Log ============================