Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-07-2014 ([color=red]ATTENTION: ====> FRST version is 95 days old and could be outdated[/color]) Ran by Damian (administrator) on DAMIAN-KOMPUTER on 24-10-2014 13:46:02 Running from C:\Users\Damian\Downloads Platform: Windows 7 Professional N Service Pack 1 (X64) OS Language: Polski (Polska) Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (THOMSON Telecom Belgium) C:\Program Files (x86)\Thomson\ST330\service\st330service.exe (AMD) C:\Windows\System32\atieclxx.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Windows\svchost.exe (Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (AQQ Sp. z o.o.) C:\Program Files\WapSter\WapSter AQQ\AQQ.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3510 series\Bin\ScanToPCActivationApp.exe (BitTorrent Inc.) C:\Users\Damian\AppData\Roaming\uTorrent\uTorrent.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Dropbox, Inc.) C:\Users\Damian\AppData\Roaming\Dropbox\bin\Dropbox.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe () C:\Users\Damian\AppData\Local\winlogon.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe () C:\Users\Damian\AppData\Local\services.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3510 series\Bin\HPNetworkCommunicatorCom.exe () C:\Users\Damian\AppData\Local\lsass.exe (Curse) C:\Users\Damian\AppData\Local\Apps\2.0\WXN7P6OG.78C\K7YQ9WPJ.3RN\curs..tion_9e9e83ddf3ed3ead_0005.0001_36a9b62a0ea0a2ec\CurseClient.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE (Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE (Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Alexander Roshal) C:\Program Files\wr\WinRAR.exe () C:\Users\Damian\AppData\Local\Temp\Rar$EXa0.055\gmer.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Users\Damian\AppData\Local\inetinfo.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585560 2014-06-23] (Razer Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Bron-Spizaetus] => C:\Windows\ShellNew\sempalong.exe [42675 2011-03-08] () HKLM-x32\...\Winlogon: [Shell] Explorer.exe "C:\Windows\eksplorasi.exe" [42675 ] () <=== ATTENTION HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-2171216393-590708924-378717732-1000\...\Run: [AQQ] => C:\Program Files\WapSter\WapSter AQQ\AQQ.exe [13138944 2014-04-22] (AQQ Sp. z o.o.) HKU\S-1-5-21-2171216393-590708924-378717732-1000\...\Run: [HP Deskjet 3510 series (NET)] => C:\Program Files\HP\HP Deskjet 3510 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-2171216393-590708924-378717732-1000\...\Run: [DAEMON Tools Lite] => D:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-2171216393-590708924-378717732-1000\...\Run: [uTorrent] => C:\Users\Damian\AppData\Roaming\uTorrent\uTorrent.exe [1918032 2014-10-07] (BitTorrent Inc.) HKU\S-1-5-21-2171216393-590708924-378717732-1000\...\Run: [GoogleChromeAutoLaunch_3F2E34BF7A244698209604940BA7FE5B] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [854344 2014-10-10] (Google Inc.) HKU\S-1-5-21-2171216393-590708924-378717732-1000\...\Run: [Tok-Cirrhatus] => C:\Users\Damian\AppData\Local\smss.exe [42675 2011-03-08] () HKU\S-1-5-21-2171216393-590708924-378717732-1000\...\Policies\system: [DisableRegistryTools] 1 HKU\S-1-5-21-2171216393-590708924-378717732-1000\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-21-2171216393-590708924-378717732-1000\...\Policies\Explorer: [] HKU\S-1-5-21-2171216393-590708924-378717732-1000\...\Policies\Explorer: [NoFolderOptions] 1 HKU\S-1-5-21-2171216393-590708924-378717732-1000\...\MountPoints2: F - F:\Autorun.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hpoddt01.exe.lnk ShortcutTarget: hpoddt01.exe.lnk -> C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard) Startup: C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () Startup: C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Damian\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif () Startup: C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - HP Deskjet 3510 series (sieć).lnk ShortcutTarget: Powiadomienia monitorowania tuszu - HP Deskjet 3510 series (sieć).lnk -> C:\Program Files\HP\HP Deskjet 3510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ShellIconOverlayIdentifiers: "DropboxExt1" -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: "DropboxExt2" -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: "DropboxExt3" -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: "DropboxExt4" -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: "DropboxExt5" -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: "DropboxExt6" -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: "DropboxExt7" -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: "DropboxExt8" -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: "DropboxExt1" -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: "DropboxExt2" -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: "DropboxExt3" -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: "DropboxExt4" -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: "DropboxExt5" -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: "DropboxExt6" -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: "DropboxExt7" -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: "DropboxExt8" -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/pl-pl/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE5ED41A13AE6CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pl StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - DefaultScope value is missing. BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: IplexToALLPlayer -> {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} -> D:\Program Files\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) Hosts: Hosts file not detected in the default directory Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-15] CHR Extension: (Google Drive) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-15] CHR Extension: (YouTube) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-15] CHR Extension: (Last updated at $time$ on $date$) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-12-15] CHR Extension: (Google Search) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-15] CHR Extension: (Weather) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fapbbpdnlcmiolkdfjnnjhabmcndadad [2013-12-15] CHR Extension: (Click&Clean) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2013-12-15] CHR Extension: (AdBlock) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-15] CHR Extension: (Wolfram|Alpha (Official)) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\icncamkooinmbehmkeilcccmoljfkdhp [2013-12-15] CHR Extension: (Calculator) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdkgihpbaofhkiliohfepioflkkbapao [2013-12-15] CHR Extension: (Auto HD For YouTube™) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2013-12-15] CHR Extension: (Google Mail Checker) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2013-12-15] CHR Extension: (Quick Note) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok [2013-12-15] CHR Extension: (Google Wallet) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-15] CHR Extension: (Click&Clean App) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2013-12-15] CHR Extension: (World of Warcraft Cataclysm Theme) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfgblfjiipppmcbapnpmcfkhhgpbgbfc [2013-12-15] CHR Extension: (Gmail) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-15] ==================== Services (Whitelisted) ================= S2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153000 2013-12-15] (Google Inc.) [File not signed] S3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153000 2013-12-15] (Google Inc.) [File not signed] R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-05-31] () R2 PowerManager; C:\Windows\svchost.exe [36352 2001-08-24] (Microsoft Corporation) [File not signed] R2 RzOvlMon; C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe [32960 2014-04-18] (Razer, Inc.) R2 st330service; C:\Program Files (x86)/Thomson/ST330/service/st330service.exe [389215 2014-07-23] (THOMSON Telecom Belgium) [File not signed] S3 OracleRemExecServiceV2; C:\Users\Damian\AppData\Local\Temp\\oraremservicev2\RemoteExecService.exe [X] ==================== Drivers (Whitelisted) ==================== S0 AFS; C:\Windows\SysWow64\Drivers\AFS.sys [77004 2014-09-04] (Oak Technology Inc.) [File not signed] R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-15] (Disc Soft Ltd) S3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-04-11] (Razer, Inc.) R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39080 2014-05-19] (Razer Inc) S1 RzFilter; C:\Windows\system32\drivers\RzFilter.sys [74432 2014-04-11] (Razer, Inc.) R3 rzmpos; C:\Windows\System32\DRIVERS\rzmpos.sys [34984 2014-05-19] (Razer Inc) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 ST330; C:\Windows\System32\DRIVERS\st330.sys [47616 2014-07-23] (THOMSON Telecom Belgium) S3 STBUS; C:\Windows\System32\DRIVERS\stbus.sys [24576 2014-07-23] (THOMSON Telecom Belgium) S3 STETH; C:\Windows\System32\DRIVERS\steth.sys [58880 2014-07-23] (THOMSON Telecom Belgium) R3 UsbAudio10; C:\Windows\System32\drivers\ViaUsbAudio.sys [106128 2012-10-24] (VIA Technologies, Inc.) U3 awrdrpog; \??\C:\Users\Damian\AppData\Local\Temp\awrdrpog.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-10-24 13:46 - 2014-10-24 13:46 - 00027375 _____ () C:\Users\Damian\AppData\Local\Update.12.Bron.Tok.bin 2014-10-24 13:46 - 2014-10-24 13:46 - 00016804 _____ () C:\Users\Damian\Downloads\FRST.txt 2014-10-24 13:45 - 2014-10-24 13:46 - 00000000 ____D () C:\FRST 2014-10-24 13:45 - 2014-10-24 13:45 - 02090496 _____ (Farbar) C:\Users\Damian\Downloads\FRST64.exe 2014-10-24 13:44 - 2014-10-24 13:44 - 00370943 _____ () C:\Users\Damian\Downloads\gmer.zip 2014-10-24 13:29 - 2014-10-24 13:29 - 00027375 _____ () C:\Users\Damian\AppData\Local\Bron.tok.A12.em.bin 2014-10-24 13:11 - 2014-10-24 13:11 - 00092334 _____ () C:\Users\Damian\Downloads\Extras.Txt 2014-10-24 13:11 - 2014-10-24 13:11 - 00092268 _____ () C:\Users\Damian\Downloads\OTL.Txt 2014-10-24 13:07 - 2014-10-24 13:07 - 00602112 _____ (OldTimer Tools) C:\Users\Damian\Downloads\OTL.exe 2014-10-24 00:00 - 2014-10-24 00:00 - 00000000 ____D () C:\Users\Damian\AppData\Local\Bron.tok-12-24 2014-10-23 20:50 - 2014-10-23 20:50 - 00000000 ____D () C:\Users\Damian\AppData\Local\Bron.tok-12-23 2014-10-23 20:24 - 2014-10-23 20:24 - 00001470 _____ () C:\Users\Damian\Downloads\Susanna Clarke - Jonathan Strange i Pan Norrell [PL] [ pdf][Torrenty.org].torrent 2014-10-23 19:50 - 2014-10-23 19:50 - 00000000 ____D () C:\Program Files\AMD 2014-10-23 19:50 - 2014-10-23 19:50 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-10-23 19:48 - 2014-10-23 19:48 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-10-23 18:06 - 2014-10-23 18:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III 2014-10-23 16:59 - 2014-10-24 12:34 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-10-23 16:59 - 2014-10-23 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2014-10-23 16:54 - 2014-10-23 16:54 - 00000000 ____D () C:\ProgramData\Battle.net 2014-10-19 23:22 - 2014-10-19 23:22 - 00060112 _____ () C:\Windows\SysWOW64\CCCInstall_201410192322004898.log 2014-10-19 23:17 - 2014-10-19 23:17 - 00060957 _____ () C:\Windows\SysWOW64\CCCInstall_201410192317096608.log 2014-10-19 23:09 - 2014-10-19 23:09 - 00005626 _____ () C:\Windows\SysWOW64\CCCInstall_201410192309507296.log 2014-10-19 22:50 - 2014-10-19 22:50 - 00031650 _____ () C:\Users\Damian\Downloads\PS3.zip 2014-10-18 12:36 - 2014-10-18 12:36 - 00056376 _____ () C:\Windows\SysWOW64\CCCInstall_201410181236135340.log 2014-10-18 12:35 - 2014-10-23 19:45 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2014-10-18 12:22 - 2014-10-18 12:29 - 286430647 _____ () C:\Users\Damian\Downloads\amd-catalyst-14-9-win7-win8.1-64bit-dd-ccc-whql_635476736775153188.zip 2014-10-16 19:53 - 2014-10-16 19:53 - 00399239 _____ () C:\Users\Damian\Downloads\DBM-MoP-Mods-r9.zip 2014-10-15 11:51 - 2014-10-15 11:51 - 00155698 _____ () C:\Users\Damian\Downloads\AskMrRobot-2.zip 2014-10-14 16:30 - 2014-10-14 16:30 - 00021402 _____ () C:\Users\Damian\Downloads\helloWorld.zip 2014-10-14 13:00 - 2014-10-14 13:00 - 00000000 ____D () C:\Users\Damian\Documents\GitHub 2014-10-14 12:59 - 2014-10-14 12:59 - 00000000 ____D () C:\Users\Damian\.ssh 2014-10-14 12:58 - 2014-10-14 13:45 - 00000000 ____D () C:\Users\Damian\AppData\Local\GitHub 2014-10-14 12:58 - 2014-10-14 12:58 - 00002141 _____ () C:\Users\Damian\Desktop\Git Shell.lnk 2014-10-14 12:58 - 2014-10-14 12:58 - 00000308 _____ () C:\Users\Damian\Desktop\GitHub.appref-ms 2014-10-14 12:58 - 2014-10-14 12:58 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub, Inc 2014-10-14 12:58 - 2014-10-14 12:58 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\GitHub 2014-10-14 12:56 - 2014-10-14 12:57 - 00712288 _____ () C:\Users\Damian\Downloads\GitHubSetup.exe 2014-10-13 19:36 - 2014-10-13 19:36 - 00002339 _____ () C:\Users\Damian\Desktop\The Walking Dead Season 2.lnk 2014-10-13 19:36 - 2014-10-13 19:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GMT-MAX.ORG 2014-10-13 19:32 - 2014-10-13 19:32 - 00000000 ____D () C:\Program Files (x86)\GMT-MAX.ORG 2014-10-13 12:04 - 2014-10-13 12:05 - 00000000 ____D () C:\Users\Damian\vpworkspace 2014-10-13 12:04 - 2014-10-13 12:05 - 00000000 ____D () C:\Users\Damian\visualparadigm 2014-10-13 12:04 - 2014-10-13 12:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Paradigm 2014-10-12 16:23 - 2014-10-12 16:23 - 00032559 _____ () C:\Users\Damian\Downloads\monsterv2.zip 2014-10-12 15:43 - 2014-10-12 15:43 - 00032417 _____ () C:\Users\Damian\Downloads\hello.zip 2014-10-12 15:21 - 2014-10-19 17:39 - 00000000 ____D () C:\Users\Damian\Documents\NetBeansProjects 2014-10-12 15:20 - 2014-10-12 15:20 - 02464750 _____ () C:\Users\Damian\Downloads\umbrello-1.5.8.tar.bz2 2014-10-12 15:14 - 2014-10-12 15:14 - 00000000 ____D () C:\Program Files\glassfish-4.1 2014-10-12 15:14 - 2014-10-12 15:14 - 00000000 ____D () C:\Program Files\Apache Software Foundation 2014-10-12 15:12 - 2014-10-12 15:12 - 00002035 _____ () C:\Users\Public\Desktop\NetBeans IDE 8.0.1.lnk 2014-10-12 15:12 - 2014-10-12 15:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetBeans 2014-10-12 15:10 - 2014-10-19 23:23 - 00000000 ____D () C:\Program Files\NetBeans 8.0.1 2014-10-12 14:32 - 2014-10-12 14:32 - 10528628 _____ () C:\Users\Damian\Downloads\apache-tomcat-8.0.14-windows-x64.zip 2014-10-12 14:19 - 2014-10-12 14:19 - 00000000 ____D () C:\Users\Damian\.netbeans-derby 2014-10-10 21:37 - 2014-10-10 21:37 - 00001741 _____ () C:\Users\Damian\Downloads\0bb322be94d3feec75cacf60e5881becc3c3d421.zip 2014-10-08 15:09 - 2014-10-08 15:09 - 03209812 _____ () C:\Users\Damian\Downloads\androidfiletransfer.dmg 2014-10-07 19:56 - 2014-10-07 19:56 - 00000814 _____ () C:\Users\Damian\Desktop\µTorrent.lnk 2014-10-07 19:55 - 2014-10-07 19:56 - 01954384 _____ (BitTorrent Inc.) C:\Users\Damian\Downloads\uTorrent.exe 2014-10-07 18:03 - 2014-10-07 18:04 - 181484960 _____ (Oracle Corporation) C:\Users\Damian\Downloads\jdk-8u20-windows-x64.exe 2014-10-07 13:25 - 2014-10-07 13:25 - 00000000 ____D () C:\Users\Damian\Downloads\Windows 7 Professional N with Service Pack 1 (x64) - DVD (Polish) 2014-10-07 12:59 - 2014-10-07 13:25 - 00005608 _____ () C:\Users\Damian\Downloads\SecureDownloadManager.log 2014-10-07 12:58 - 2014-10-07 12:58 - 00003147 _____ () C:\Users\Damian\Desktop\Shortcut to SecureDownloadManager.exe.lnk 2014-10-07 12:58 - 2014-10-07 12:58 - 00000183 _____ () C:\Users\Damian\Downloads\100168748089.sdx 2014-10-07 12:58 - 2014-10-07 12:58 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\e-academy Inc 2014-10-07 12:58 - 2014-10-07 12:58 - 00000000 ____D () C:\Users\Damian\AppData\Local\e-academy Inc 2014-10-07 12:57 - 2014-10-07 12:57 - 00775168 _____ () C:\Users\Damian\Downloads\SDM_EN.msi 2014-10-05 14:02 - 2014-10-05 14:02 - 00000000 ____D () C:\Users\Damian\Documents\WB Games 2014-10-05 14:02 - 2014-10-05 14:02 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\Steam 2014-10-05 13:44 - 2014-10-05 13:44 - 00001274 _____ () C:\Users\Damian\Desktop\Middle Earth Shadow of Mordor.lnk 2014-10-05 13:44 - 2014-10-05 13:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Middle Earth Shadow of Mordor 2014-10-05 13:14 - 2014-10-05 13:44 - 00000000 ____D () C:\Program Files (x86)\Middle Earth Shadow of Mordor 2014-10-05 12:38 - 2014-10-05 12:38 - 00000101 _____ () C:\Windows\system32\Drivers\etc\hosts.new 2014-10-05 12:38 - 2014-10-05 12:38 - 00000000 ____D () C:\Users\Damian\Downloads\backups 2014-10-05 12:30 - 2014-10-23 19:42 - 00009271 _____ () C:\Users\Damian\Downloads\hijackthis.log 2014-10-05 12:30 - 2014-10-05 12:30 - 00424960 _____ (Trend Micro Inc.) C:\Users\Damian\Downloads\HijackThis.exe 2014-10-05 12:30 - 2014-10-05 12:30 - 00388608 _____ (Trend Micro Inc.) C:\Users\Damian\Downloads\HijackThis (1).exe 2014-10-03 13:50 - 2014-10-03 14:27 - 911114606 _____ () C:\Users\Damian\Documents\klax_coppy.mp4 2014-10-03 13:45 - 2014-10-03 13:45 - 00336736 _____ () C:\Users\Damian\Downloads\meishi-smile-pale-skeets-remix.sfk 2014-10-03 13:44 - 2014-10-03 13:44 - 43093194 _____ () C:\Users\Damian\Downloads\meishi-smile-pale-skeets-remix.wav 2014-10-03 13:30 - 2014-10-03 13:30 - 00479048 _____ () C:\Users\Damian\Downloads\Hurtdeer - A Closer Green Skyline.mp3.sfk 2014-10-03 13:30 - 2014-10-03 13:30 - 00401792 _____ () C:\Users\Damian\Downloads\16 Masta Blasta 2.0.mp3.sfk 2014-10-02 20:46 - 2010-01-05 18:39 - 00107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll 2014-10-02 20:46 - 2009-12-03 11:27 - 00074272 _____ () C:\Windows\system32\RtNicProp64.dll 2014-10-02 20:42 - 2014-10-02 20:42 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\InstallShield 2014-10-02 20:42 - 2014-10-02 20:42 - 00000000 ____D () C:\ProgramData\Intel 2014-10-02 20:42 - 2014-10-02 20:42 - 00000000 ____D () C:\Program Files\Intel 2014-10-02 20:42 - 2012-02-21 12:10 - 00015128 _____ () C:\Windows\system32\Drivers\IntelMEFWVer.dll 2014-10-02 20:42 - 2011-11-10 01:04 - 00060184 _____ (Intel Corporation) C:\Windows\system32\Drivers\HECIx64.sys 2014-09-30 18:23 - 2014-09-30 18:33 - 00974120 _____ () C:\Users\Damian\Documents\Klaxxi.mp4.sfk 2014-09-30 18:17 - 2014-09-30 18:17 - 373513540 _____ () C:\Users\Damian\Documents\Klaxxi.mp4 2014-09-30 18:11 - 2014-09-30 18:11 - 00749323 _____ () C:\Users\Damian\Downloads\YoutubeGetDownloader.jar 2014-09-29 20:15 - 2014-09-29 20:15 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll 2014-09-29 20:15 - 2014-09-29 20:15 - 00000000 ____D () C:\Users\Damian\AppData\Local\Electronic Arts 2014-09-29 20:13 - 2014-09-29 20:13 - 00002069 _____ () C:\Users\Public\Desktop\Dead Space™.lnk 2014-09-29 20:09 - 2014-09-29 20:09 - 00000000 ____D () C:\Users\Damian\Documents\Electronic Arts 2014-09-29 20:09 - 2014-09-29 20:09 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts ==================== One Month Modified Files and Folders ======= 2014-10-24 13:46 - 2014-10-24 13:46 - 00027375 _____ () C:\Users\Damian\AppData\Local\Update.12.Bron.Tok.bin 2014-10-24 13:46 - 2014-10-24 13:46 - 00016804 _____ () C:\Users\Damian\Downloads\FRST.txt 2014-10-24 13:46 - 2014-10-24 13:45 - 00000000 ____D () C:\FRST 2014-10-24 13:45 - 2014-10-24 13:45 - 02090496 _____ (Farbar) C:\Users\Damian\Downloads\FRST64.exe 2014-10-24 13:44 - 2014-10-24 13:44 - 00370943 _____ () C:\Users\Damian\Downloads\gmer.zip 2014-10-24 13:42 - 2013-12-15 14:34 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\uTorrent 2014-10-24 13:29 - 2014-10-24 13:29 - 00027375 _____ () C:\Users\Damian\AppData\Local\Bron.tok.A12.em.bin 2014-10-24 13:24 - 2013-12-15 13:37 - 00001048 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-24 13:24 - 2009-07-14 06:50 - 00019920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-24 13:24 - 2009-07-14 06:50 - 00019920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-24 13:20 - 2013-12-15 13:20 - 01521235 _____ () C:\Windows\WindowsUpdate.log 2014-10-24 13:18 - 2013-12-15 13:37 - 00000000 ____D () C:\Users\Damian\AppData\Local\Deployment 2014-10-24 13:17 - 2013-12-15 14:53 - 00000000 ___RD () C:\Users\Damian\Dropbox 2014-10-24 13:17 - 2013-12-15 14:49 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\Dropbox 2014-10-24 13:17 - 2013-12-15 13:37 - 00001044 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-24 13:17 - 2010-11-21 05:47 - 00464500 _____ () C:\Windows\PFRO.log 2014-10-24 13:17 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-24 13:17 - 2009-07-14 06:56 - 00132083 _____ () C:\Windows\setupact.log 2014-10-24 13:11 - 2014-10-24 13:11 - 00092334 _____ () C:\Users\Damian\Downloads\Extras.Txt 2014-10-24 13:11 - 2014-10-24 13:11 - 00092268 _____ () C:\Users\Damian\Downloads\OTL.Txt 2014-10-24 13:07 - 2014-10-24 13:07 - 00602112 _____ (OldTimer Tools) C:\Users\Damian\Downloads\OTL.exe 2014-10-24 13:05 - 2014-01-18 00:05 - 00000000 ____D () C:\Users\Damian\AppData\Local\Battle.net 2014-10-24 13:05 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PLA 2014-10-24 13:02 - 2014-07-02 23:29 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-24 12:34 - 2014-10-23 16:59 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-10-24 01:12 - 2014-08-06 21:42 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\Skype 2014-10-24 00:15 - 2014-08-10 21:24 - 00000000 ____D () C:\Users\Damian\Documents\Assassin's Creed IV Black Flag 2014-10-24 00:15 - 2014-06-30 22:38 - 00000000 ____D () C:\Users\Damian\Documents\Anki 2014-10-24 00:15 - 2014-06-08 23:51 - 00000000 ____D () C:\Users\Damian\Documents\do photoshopa 2014-10-24 00:15 - 2014-03-08 18:07 - 00000000 ____D () C:\Users\Damian\Documents\Thief 2014-10-24 00:15 - 2013-12-15 16:38 - 00000000 ____D () C:\Users\Damian\Documents\Diablo III 2014-10-24 00:09 - 2011-04-12 14:21 - 00000000 ____D () C:\Windows\ShellNew 2014-10-24 00:07 - 2014-03-18 22:34 - 00000000 ____D () C:\Windows\pss 2014-10-24 00:00 - 2014-10-24 00:00 - 00000000 ____D () C:\Users\Damian\AppData\Local\Bron.tok-12-24 2014-10-23 21:25 - 2014-03-18 19:50 - 00000000 ____D () C:\Users\Damian\AppData\Local\Loc.Mail.Bron.Tok 2014-10-23 21:14 - 2014-04-13 14:35 - 00000000 ____D () C:\work 2014-10-23 20:50 - 2014-10-23 20:50 - 00000000 ____D () C:\Users\Damian\AppData\Local\Bron.tok-12-23 2014-10-23 20:24 - 2014-10-23 20:24 - 00001470 _____ () C:\Users\Damian\Downloads\Susanna Clarke - Jonathan Strange i Pan Norrell [PL] [ pdf][Torrenty.org].torrent 2014-10-23 19:50 - 2014-10-23 19:50 - 00000000 ____D () C:\Program Files\AMD 2014-10-23 19:50 - 2014-10-23 19:50 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-10-23 19:50 - 2013-12-15 13:29 - 00000000 ____D () C:\ProgramData\AMD 2014-10-23 19:48 - 2014-10-23 19:48 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-10-23 19:45 - 2014-10-18 12:35 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2014-10-23 19:42 - 2014-10-05 12:30 - 00009271 _____ () C:\Users\Damian\Downloads\hijackthis.log 2014-10-23 18:06 - 2014-10-23 18:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III 2014-10-23 18:06 - 2013-12-15 15:57 - 00000787 _____ () C:\Users\Public\Desktop\Diablo III.lnk 2014-10-23 16:59 - 2014-10-23 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2014-10-23 16:59 - 2014-01-18 00:04 - 00001144 _____ () C:\Users\Public\Desktop\Battle.net.lnk 2014-10-23 16:59 - 2013-12-15 14:16 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment 2014-10-23 16:54 - 2014-10-23 16:54 - 00000000 ____D () C:\ProgramData\Battle.net 2014-10-23 16:48 - 2013-12-17 19:14 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\AIMP3 2014-10-22 22:31 - 2013-12-15 21:39 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\TS3Client 2014-10-22 00:19 - 2013-12-15 13:37 - 00004044 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-10-22 00:19 - 2013-12-15 13:37 - 00003792 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-10-19 23:23 - 2014-10-12 15:10 - 00000000 ____D () C:\Program Files\NetBeans 8.0.1 2014-10-19 23:22 - 2014-10-19 23:22 - 00060112 _____ () C:\Windows\SysWOW64\CCCInstall_201410192322004898.log 2014-10-19 23:17 - 2014-10-19 23:17 - 00060957 _____ () C:\Windows\SysWOW64\CCCInstall_201410192317096608.log 2014-10-19 23:15 - 2013-12-15 15:17 - 01652878 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-10-19 23:15 - 2011-04-12 14:11 - 00744458 _____ () C:\Windows\system32\perfh015.dat 2014-10-19 23:15 - 2011-04-12 14:11 - 00157214 _____ () C:\Windows\system32\perfc015.dat 2014-10-19 23:15 - 2009-07-14 07:12 - 01652878 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-10-19 23:13 - 2014-03-16 21:29 - 00000000 ____D () C:\Program Files\ATI 2014-10-19 23:09 - 2014-10-19 23:09 - 00005626 _____ () C:\Windows\SysWOW64\CCCInstall_201410192309507296.log 2014-10-19 23:01 - 2013-12-15 22:22 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\CodeBlocks 2014-10-19 22:50 - 2014-10-19 22:50 - 00031650 _____ () C:\Users\Damian\Downloads\PS3.zip 2014-10-19 17:39 - 2014-10-12 15:21 - 00000000 ____D () C:\Users\Damian\Documents\NetBeansProjects 2014-10-18 12:36 - 2014-10-18 12:36 - 00056376 _____ () C:\Windows\SysWOW64\CCCInstall_201410181236135340.log 2014-10-18 12:30 - 2014-03-16 21:28 - 00000000 ____D () C:\AMD 2014-10-18 12:29 - 2014-10-18 12:22 - 286430647 _____ () C:\Users\Damian\Downloads\amd-catalyst-14-9-win7-win8.1-64bit-dd-ccc-whql_635476736775153188.zip 2014-10-18 12:21 - 2014-01-17 17:47 - 634597593 _____ () C:\Windows\MEMORY.DMP 2014-10-18 12:21 - 2014-01-17 17:47 - 00000000 ____D () C:\Windows\Minidump 2014-10-18 12:18 - 2013-12-15 13:38 - 00002189 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-10-18 11:54 - 2013-12-15 13:19 - 00000000 ____D () C:\Users\Damian 2014-10-17 19:51 - 2013-12-15 14:10 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\SkypeKit 2014-10-16 19:53 - 2014-10-16 19:53 - 00399239 _____ () C:\Users\Damian\Downloads\DBM-MoP-Mods-r9.zip 2014-10-15 11:51 - 2014-10-15 11:51 - 00155698 _____ () C:\Users\Damian\Downloads\AskMrRobot-2.zip 2014-10-14 16:30 - 2014-10-14 16:30 - 00021402 _____ () C:\Users\Damian\Downloads\helloWorld.zip 2014-10-14 13:45 - 2014-10-14 12:58 - 00000000 ____D () C:\Users\Damian\AppData\Local\GitHub 2014-10-14 13:00 - 2014-10-14 13:00 - 00000000 ____D () C:\Users\Damian\Documents\GitHub 2014-10-14 12:59 - 2014-10-14 12:59 - 00000000 ____D () C:\Users\Damian\.ssh 2014-10-14 12:58 - 2014-10-14 12:58 - 00002141 _____ () C:\Users\Damian\Desktop\Git Shell.lnk 2014-10-14 12:58 - 2014-10-14 12:58 - 00000308 _____ () C:\Users\Damian\Desktop\GitHub.appref-ms 2014-10-14 12:58 - 2014-10-14 12:58 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub, Inc 2014-10-14 12:58 - 2014-10-14 12:58 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\GitHub 2014-10-14 12:57 - 2014-10-14 12:56 - 00712288 _____ () C:\Users\Damian\Downloads\GitHubSetup.exe 2014-10-13 19:36 - 2014-10-13 19:36 - 00002339 _____ () C:\Users\Damian\Desktop\The Walking Dead Season 2.lnk 2014-10-13 19:36 - 2014-10-13 19:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GMT-MAX.ORG 2014-10-13 19:32 - 2014-10-13 19:32 - 00000000 ____D () C:\Program Files (x86)\GMT-MAX.ORG 2014-10-13 12:05 - 2014-10-13 12:04 - 00000000 ____D () C:\Users\Damian\vpworkspace 2014-10-13 12:05 - 2014-10-13 12:04 - 00000000 ____D () C:\Users\Damian\visualparadigm 2014-10-13 12:04 - 2014-10-13 12:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Paradigm 2014-10-12 20:26 - 2014-01-17 22:00 - 00000000 ____D () C:\Users\Damian\AppData\Local\Eclipse 2014-10-12 16:23 - 2014-10-12 16:23 - 00032559 _____ () C:\Users\Damian\Downloads\monsterv2.zip 2014-10-12 15:43 - 2014-10-12 15:43 - 00032417 _____ () C:\Users\Damian\Downloads\hello.zip 2014-10-12 15:20 - 2014-10-12 15:20 - 02464750 _____ () C:\Users\Damian\Downloads\umbrello-1.5.8.tar.bz2 2014-10-12 15:20 - 2014-06-08 23:10 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\NetBeans 2014-10-12 15:18 - 2014-06-08 23:04 - 00000000 ____D () C:\Users\Damian\.nbi 2014-10-12 15:14 - 2014-10-12 15:14 - 00000000 ____D () C:\Program Files\glassfish-4.1 2014-10-12 15:14 - 2014-10-12 15:14 - 00000000 ____D () C:\Program Files\Apache Software Foundation 2014-10-12 15:12 - 2014-10-12 15:12 - 00002035 _____ () C:\Users\Public\Desktop\NetBeans IDE 8.0.1.lnk 2014-10-12 15:12 - 2014-10-12 15:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetBeans 2014-10-12 14:32 - 2014-10-12 14:32 - 10528628 _____ () C:\Users\Damian\Downloads\apache-tomcat-8.0.14-windows-x64.zip 2014-10-12 14:19 - 2014-10-12 14:19 - 00000000 ____D () C:\Users\Damian\.netbeans-derby 2014-10-10 21:37 - 2014-10-10 21:37 - 00001741 _____ () C:\Users\Damian\Downloads\0bb322be94d3feec75cacf60e5881becc3c3d421.zip 2014-10-08 15:09 - 2014-10-08 15:09 - 03209812 _____ () C:\Users\Damian\Downloads\androidfiletransfer.dmg 2014-10-07 19:56 - 2014-10-07 19:56 - 00000814 _____ () C:\Users\Damian\Desktop\µTorrent.lnk 2014-10-07 19:56 - 2014-10-07 19:55 - 01954384 _____ (BitTorrent Inc.) C:\Users\Damian\Downloads\uTorrent.exe 2014-10-07 18:04 - 2014-10-07 18:03 - 181484960 _____ (Oracle Corporation) C:\Users\Damian\Downloads\jdk-8u20-windows-x64.exe 2014-10-07 13:25 - 2014-10-07 13:25 - 00000000 ____D () C:\Users\Damian\Downloads\Windows 7 Professional N with Service Pack 1 (x64) - DVD (Polish) 2014-10-07 13:25 - 2014-10-07 12:59 - 00005608 _____ () C:\Users\Damian\Downloads\SecureDownloadManager.log 2014-10-07 12:58 - 2014-10-07 12:58 - 00003147 _____ () C:\Users\Damian\Desktop\Shortcut to SecureDownloadManager.exe.lnk 2014-10-07 12:58 - 2014-10-07 12:58 - 00000183 _____ () C:\Users\Damian\Downloads\100168748089.sdx 2014-10-07 12:58 - 2014-10-07 12:58 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\e-academy Inc 2014-10-07 12:58 - 2014-10-07 12:58 - 00000000 ____D () C:\Users\Damian\AppData\Local\e-academy Inc 2014-10-07 12:57 - 2014-10-07 12:57 - 00775168 _____ () C:\Users\Damian\Downloads\SDM_EN.msi 2014-10-06 16:31 - 2014-06-08 00:44 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\OBS 2014-10-06 16:25 - 2014-06-08 00:44 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-10-05 14:02 - 2014-10-05 14:02 - 00000000 ____D () C:\Users\Damian\Documents\WB Games 2014-10-05 14:02 - 2014-10-05 14:02 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\Steam 2014-10-05 13:44 - 2014-10-05 13:44 - 00001274 _____ () C:\Users\Damian\Desktop\Middle Earth Shadow of Mordor.lnk 2014-10-05 13:44 - 2014-10-05 13:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Middle Earth Shadow of Mordor 2014-10-05 13:44 - 2014-10-05 13:14 - 00000000 ____D () C:\Program Files (x86)\Middle Earth Shadow of Mordor 2014-10-05 12:38 - 2014-10-05 12:38 - 00000101 _____ () C:\Windows\system32\Drivers\etc\hosts.new 2014-10-05 12:38 - 2014-10-05 12:38 - 00000000 ____D () C:\Users\Damian\Downloads\backups 2014-10-05 12:30 - 2014-10-05 12:30 - 00424960 _____ (Trend Micro Inc.) C:\Users\Damian\Downloads\HijackThis.exe 2014-10-05 12:30 - 2014-10-05 12:30 - 00388608 _____ (Trend Micro Inc.) C:\Users\Damian\Downloads\HijackThis (1).exe 2014-10-03 14:27 - 2014-10-03 13:50 - 911114606 _____ () C:\Users\Damian\Documents\klax_coppy.mp4 2014-10-03 13:45 - 2014-10-03 13:45 - 00336736 _____ () C:\Users\Damian\Downloads\meishi-smile-pale-skeets-remix.sfk 2014-10-03 13:44 - 2014-10-03 13:44 - 43093194 _____ () C:\Users\Damian\Downloads\meishi-smile-pale-skeets-remix.wav 2014-10-03 13:30 - 2014-10-03 13:30 - 00479048 _____ () C:\Users\Damian\Downloads\Hurtdeer - A Closer Green Skyline.mp3.sfk 2014-10-03 13:30 - 2014-10-03 13:30 - 00401792 _____ () C:\Users\Damian\Downloads\16 Masta Blasta 2.0.mp3.sfk 2014-10-02 20:46 - 2013-12-15 13:21 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-10-02 20:46 - 2013-12-15 13:21 - 00000000 ____D () C:\Program Files (x86)\Realtek 2014-10-02 20:42 - 2014-10-02 20:42 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\InstallShield 2014-10-02 20:42 - 2014-10-02 20:42 - 00000000 ____D () C:\ProgramData\Intel 2014-10-02 20:42 - 2014-10-02 20:42 - 00000000 ____D () C:\Program Files\Intel 2014-10-02 20:42 - 2013-12-21 00:29 - 00000000 ____D () C:\Program Files (x86)\Intel 2014-10-02 20:40 - 2013-12-15 13:21 - 00000000 ___HD () C:\Program Files (x86)\Temp 2014-09-30 18:33 - 2014-09-30 18:23 - 00974120 _____ () C:\Users\Damian\Documents\Klaxxi.mp4.sfk 2014-09-30 18:17 - 2014-09-30 18:17 - 373513540 _____ () C:\Users\Damian\Documents\Klaxxi.mp4 2014-09-30 18:11 - 2014-09-30 18:11 - 00749323 _____ () C:\Users\Damian\Downloads\YoutubeGetDownloader.jar 2014-09-29 20:15 - 2014-09-29 20:15 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll 2014-09-29 20:15 - 2014-09-29 20:15 - 00000000 ____D () C:\Users\Damian\AppData\Local\Electronic Arts 2014-09-29 20:13 - 2014-09-29 20:13 - 00002069 _____ () C:\Users\Public\Desktop\Dead Space™.lnk 2014-09-29 20:13 - 2009-07-14 07:38 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-09-29 20:09 - 2014-09-29 20:09 - 00000000 ____D () C:\Users\Damian\Documents\Electronic Arts 2014-09-29 20:09 - 2014-09-29 20:09 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-09-29 20:09 - 2013-12-15 14:05 - 00102408 _____ () C:\Windows\DirectX.log 2014-09-29 20:07 - 2013-12-18 16:39 - 00000000 ____D () C:\Program Files (x86)\O22y Inc 2014-09-29 11:46 - 2014-07-23 20:53 - 00002302 _____ () C:\Users\Damian\Desktop\League of Legends — skrót.lnk C:\Windows\svchost.exe ATTENTION ====> Check for partition/boot infection. Files to move or delete: ==================== C:\ProgramData\hpothb07.dat C:\Users\Damian\hpothb07.dat C:\Users\Default\hpothb07.dat C:\Users\Public\hpothb07.dat Some content of TEMP: ==================== C:\Users\Damian\AppData\Local\Temp\AIMP3.exe C:\Users\Damian\AppData\Local\Temp\Battle.net.exe C:\Users\Damian\AppData\Local\Temp\chrome.exe C:\Users\Damian\AppData\Local\Temp\drm_dyndata_7380007.dll C:\Users\Damian\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp2tfw0h.dll C:\Users\Damian\AppData\Local\Temp\javaws.exe C:\Users\Damian\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\Damian\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe C:\Users\Damian\AppData\Local\Temp\League of Legends.exe C:\Users\Damian\AppData\Local\Temp\LoLLauncher.exe C:\Users\Damian\AppData\Local\Temp\mpc-hc.exe C:\Users\Damian\AppData\Local\Temp\qt-mt332.dll C:\Users\Damian\AppData\Local\Temp\qt-mt337.dll C:\Users\Damian\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll C:\Users\Damian\AppData\Local\Temp\ubi5C73.tmp.exe C:\Users\Damian\AppData\Local\Temp\Uninstall.exe C:\Users\Damian\AppData\Local\Temp\vcredist_x86.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-07 14:08 ==================== End Of Log ============================