Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-11-2014 01 Ran by SYSTEM on MININT-NP36PAR on 28-11-2014 09:34:08 Running from H:\komp\Palemoon_download Platform: Windows 7 Home Premium (X86) OS Language: English (United States) Internet Explorer Version 11 Boot Mode: Recovery The current controlset is ControlSet001 [b]ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.[/b] Tutorial for Farbar Recovery Scan Tool: ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8120864 2009-12-14] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated) HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1225944 2014-03-25] (COMODO) HKLM\...\RunOnce: [SRS4] => C:\Program Files\Samsung\Samsung Recovery Solution 4\InstallManager.exe [715264 2009-08-18] (SEC) HKU\dom\...\Run: [ISUSPM] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-10] (Macrovision Corporation) HKU\dom\...\Run: [f.lux] => C:\Users\dom\AppData\Local\FluxSoftware\Flux\flux.exe [1016712 2013-10-15] (Flux Software LLC) HKU\dom\...\Policies\system: [LogonHoursAction] 2 HKU\dom\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 Startup: C:\Users\dom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk ShortcutTarget: MagicDisc.lnk -> C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.) ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 c2cautoupdatesvc; c:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) S3 c2cpnrsvc; c:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) S2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5306504 2014-04-16] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [1663192 2014-03-25] (COMODO) S3 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) S3 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) S3 Motorola Device Manager; C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [137528 2013-11-15] (Motorola Mobility LLC) S3 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) S3 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19405768 2014-04-02] (NVIDIA Corporation) S3 OberonGameConsoleService; C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe [44312 2009-08-13] () S3 PST Service; c:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola) S3 RealNetworks Downloader Resolver Service; c:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] () S2 Rezip; C:\windows\SYSTEM32\Rezip.exe [311296 2009-03-05] () S3 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [247152 2009-07-07] () S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 awUSB; C:\Windows\System32\DRIVERS\USBDrv.sys [13824 2014-02-20] (Scott) S1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20072 2014-04-16] (COMODO) S1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [607168 2014-04-16] (COMODO) S1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [43728 2014-04-16] (COMODO) S1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [92656 2014-04-16] (COMODO) S3 LgBttPort; C:\Windows\System32\DRIVERS\lgbtport.sys [12160 2009-09-28] (LG Electronics Inc.) S3 lgbusenum; C:\Windows\System32\DRIVERS\lgbtbus.sys [10496 2009-09-28] (LG Electronics Inc.) S3 LGVMODEM; C:\Windows\System32\DRIVERS\lgvmodem.sys [12928 2009-09-28] (LG Electronics Inc.) S3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [114904 2014-11-25] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation) S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2014-03-21] (NVIDIA Corporation) S3 pwdrvio; C:\windows\system32\pwdrvio.sys [15688 2013-09-30] () S3 pwdspio; C:\windows\system32\pwdspio.sys [10320 2013-09-30] () S3 tapavpn; C:\Windows\System32\DRIVERS\tapavpn.sys [24320 2009-07-03] (Steganos GmbH) S3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] () ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-28 00:05 - 2009-11-05 20:07 - 01550952 _____ (NVIDIA Corporation) C:\Windows\System32\nvencodemft.dll 2014-11-28 00:05 - 2009-11-05 20:07 - 00592488 _____ (NVIDIA Corporation) C:\Windows\System32\nvuninst.exe 2014-11-28 00:05 - 2009-11-05 20:07 - 00592488 _____ (NVIDIA Corporation) C:\Windows\System32\nvudisp.exe 2014-11-28 00:05 - 2009-11-05 20:07 - 00285288 _____ (NVIDIA Corporation) C:\Windows\System32\nvdecodemft.dll 2014-11-28 00:05 - 2009-11-05 20:07 - 00174696 _____ (NVIDIA Corporation) C:\Windows\System32\nvcod174.dll 2014-11-28 00:05 - 2009-11-05 20:07 - 00174696 _____ (NVIDIA Corporation) C:\Windows\System32\nvcod.dll 2014-11-28 00:05 - 2009-11-05 20:07 - 00010984 _____ (NVIDIA Corporation) C:\Windows\System32\Drivers\nvBridge.kmd 2014-11-28 00:05 - 2009-11-04 15:16 - 01514088 _____ (NVIDIA Corporation) C:\Windows\System32\nvcpluir.dll 2014-11-28 00:05 - 2009-11-04 15:16 - 01190504 _____ (NVIDIA Corporation) C:\Windows\System32\nvcplui.exe 2014-11-28 00:05 - 2009-11-04 15:16 - 00420456 _____ (NVIDIA Corporation) C:\Windows\System32\nvcpl.cpl 2014-11-28 00:05 - 2009-11-04 15:15 - 06113896 _____ (NVIDIA Corporation) C:\Windows\System32\nvdispsr.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 04561512 _____ (NVIDIA Corporation) C:\Windows\System32\nvvitvsr.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 04557416 _____ (NVIDIA Corporation) C:\Windows\System32\nvgamesr.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 04045416 _____ (NVIDIA Corporation) C:\Windows\System32\nvvitvs.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 04029032 _____ (NVIDIA Corporation) C:\Windows\System32\nvdisps.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 03656296 _____ (NVIDIA Corporation) C:\Windows\System32\nvwssr.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 03533416 _____ (NVIDIA Corporation) C:\Windows\System32\nvgames.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 03127912 _____ (NVIDIA Corporation) C:\Windows\System32\nvwss.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 02861672 _____ (NVIDIA Corporation) C:\Windows\System32\nvmoblsr.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 01358440 _____ (NVIDIA Corporation) C:\Windows\System32\nvsvsr.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 01297000 _____ (NVIDIA Corporation) C:\Windows\System32\nvsvs.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 01288808 _____ (NVIDIA Corporation) C:\Windows\System32\nvmobls.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 00465512 _____ (NVIDIA Corporation) C:\Windows\System32\nvmccssr.dll 2014-11-28 00:05 - 2009-11-04 15:15 - 00195176 _____ (NVIDIA Corporation) C:\Windows\System32\nvmccss.dll 2014-11-28 00:05 - 2009-07-13 17:15 - 00606208 _____ (Microsoft Corporation) C:\Windows\System32\mstime.dll 2014-11-28 00:05 - 2009-07-13 17:15 - 00229376 _____ (Microsoft Corporation) C:\Windows\System32\ieaksie.dll 2014-11-28 00:05 - 2009-07-13 17:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\System32\ieakeng.dll 2014-11-28 00:05 - 2009-07-13 17:15 - 00018432 _____ (Microsoft Corporation) C:\Windows\System32\corpol.dll 2014-11-28 00:05 - 2009-07-13 17:14 - 00073216 _____ (Microsoft Corporation) C:\Windows\System32\admparse.dll 2014-11-28 00:05 - 2009-07-13 17:05 - 00163840 _____ (Microsoft Corporation) C:\Windows\System32\ieakui.dll 2014-11-28 00:05 - 2009-06-25 06:07 - 00485920 _____ (NVIDIA Corporation) C:\Windows\System32\nvuhda.exe 2014-11-28 00:05 - 2009-06-25 06:07 - 00151552 _____ (NVIDIA Corporation) C:\Windows\System32\nvcohda.dll 2014-11-28 00:05 - 2009-06-17 17:15 - 00214024 _____ (McAfee, Inc.) C:\Windows\System32\Drivers\mfehidk.sys 2014-11-28 00:05 - 2009-06-17 17:15 - 00079816 _____ (McAfee, Inc.) C:\Windows\System32\Drivers\mfeavfk.sys 2014-11-28 00:05 - 2009-06-17 17:15 - 00040552 _____ (McAfee, Inc.) C:\Windows\System32\Drivers\mfesmfk.sys 2014-11-28 00:05 - 2009-06-17 17:15 - 00035272 _____ (McAfee, Inc.) C:\Windows\System32\Drivers\mfebopk.sys 2014-11-28 00:05 - 2009-06-17 17:14 - 00034248 _____ (McAfee, Inc.) C:\Windows\System32\Drivers\mferkdk.sys 2014-11-28 00:05 - 2009-06-10 13:27 - 00000003 _____ () C:\Windows\System32\Drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf 2014-11-28 00:05 - 2009-04-08 21:23 - 00130424 _____ (McAfee, Inc.) C:\Windows\System32\Drivers\Mpfp.sys 2014-11-28 00:05 - 2006-07-24 01:50 - 00125744 _____ (Microsoft Corporation) C:\Windows\System32\MSSTDFMT.DLL 2014-11-28 00:05 - 2006-07-24 01:50 - 00039728 _____ (Microsoft Corporation) C:\Windows\System32\SCP32.DLL 2014-11-27 11:38 - 2014-11-27 22:25 - 261230421 _____ () C:\Windows\MEMORY.DMP 2014-11-26 10:30 - 2014-11-26 10:30 - 00000000 _____ () C:\Users\dom\defogger_reenable 2014-11-26 09:52 - 2014-11-28 09:34 - 00000000 ____D () C:\FRST 2014-11-26 09:03 - 2014-11-26 09:03 - 01110016 _____ (Farbar) C:\Users\dom\Downloads\FRST (1).exe 2014-11-26 08:59 - 2014-11-26 08:59 - 01110016 _____ (Farbar) C:\Users\dom\Downloads\FRST.exe 2014-11-25 15:22 - 2014-11-25 15:22 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-11-25 14:56 - 2014-03-09 13:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\System32\infocardapi.dll 2014-11-25 14:55 - 2014-06-30 14:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\System32\icardres.dll 2014-11-25 14:55 - 2014-06-05 22:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\System32\TsWpfWrp.exe 2014-11-25 14:55 - 2014-03-09 13:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\System32\icardagt.exe 2014-11-25 14:29 - 2014-11-25 14:27 - 01188194 ____R () C:\Users\dom\Desktop\ 2014-11-25 14:15 - 2014-06-18 14:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\System32\dfshim.dll 2014-11-25 14:15 - 2014-06-18 14:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\System32\mscorier.dll 2014-11-25 14:15 - 2014-06-18 14:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\System32\mscories.dll 2014-11-25 13:47 - 2014-11-25 13:47 - 00000079 _____ () C:\Windows\wininit.ini 2014-11-21 09:16 - 2014-11-26 13:32 - 00002135 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-11-20 08:56 - 2014-11-20 08:56 - 00010329 _____ () C:\Users\dom\Desktop\chrome_bookmarks_20.11.2014.html 2014-11-20 08:10 - 2014-11-25 13:50 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\MBAMSwissArmy.sys 2014-11-20 08:07 - 2014-11-20 08:07 - 19828376 _____ (Malwarebytes Corporation ) C:\mbam-setup- 2014-11-20 08:07 - 2014-11-20 08:07 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-11-20 08:07 - 2014-11-20 08:07 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-11-20 08:07 - 2014-11-20 08:07 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-11-20 08:07 - 2014-10-01 02:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamchameleon.sys 2014-11-20 08:07 - 2014-10-01 02:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mwac.sys 2014-11-20 08:07 - 2014-10-01 02:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2014-11-19 14:57 - 2014-11-19 14:57 - 00000000 ____D () C:\Users\dom\Documents\ProcAlyzer Dumps 2014-11-19 14:29 - 2014-11-19 14:29 - 46525608 _____ (Safer-Networking Ltd. ) C:\spybot-2.4.exe 2014-11-19 14:01 - 2014-11-26 08:27 - 00000179 _____ () C:\Windows\fileinfo.ini 2014-11-19 12:50 - 2014-11-19 12:53 - 00000000 ____D () C:\Program Files\Pale Moon 2014-11-19 10:33 - 2014-11-19 10:33 - 00000000 ____D () C:\Users\dom\Desktop\Stare dane programu Firefox 2014-11-19 09:01 - 2014-11-10 18:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll 2014-11-19 09:01 - 2014-11-10 18:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\System32\pku2u.dll 2014-11-19 06:16 - 2014-11-19 06:16 - 00000000 ____D () C:\Users\dom\AppData\Local\globalUpdate 2014-11-17 11:28 - 2014-11-17 11:28 - 00000000 __SHD () C:\Users\dom\AppData\Local\EmieBrowserModeList 2014-11-16 11:36 - 2014-11-27 08:32 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-11-15 11:44 - 2014-11-15 11:44 - 00000000 ____D () C:\Users\dom\AppData\Roaming\GameConsole 2014-11-15 11:44 - 2014-11-15 11:44 - 00000000 ____D () C:\Program Files\Common Files\SWF Studio 2014-11-14 09:16 - 2014-06-26 17:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2014-11-14 08:58 - 2014-10-13 17:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\System32\msi.dll 2014-11-14 08:58 - 2014-10-09 16:45 - 02379264 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2014-11-14 08:57 - 2014-11-07 11:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2014-11-14 08:57 - 2014-11-05 19:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2014-11-14 08:57 - 2014-11-05 19:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll 2014-11-14 08:57 - 2014-11-05 19:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2014-11-14 08:57 - 2014-11-05 19:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2014-11-14 08:57 - 2014-11-05 19:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll 2014-11-14 08:57 - 2014-11-05 19:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2014-11-14 08:57 - 2014-11-05 19:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll 2014-11-14 08:57 - 2014-11-05 19:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2014-11-14 08:57 - 2014-11-05 19:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2014-11-14 08:57 - 2014-11-05 19:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2014-11-14 08:57 - 2014-11-05 19:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2014-11-14 08:57 - 2014-11-05 18:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2014-11-14 08:57 - 2014-11-05 18:59 - 00102912 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe 2014-11-14 08:57 - 2014-11-05 18:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll 2014-11-14 08:57 - 2014-11-05 18:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2014-11-14 08:57 - 2014-11-05 18:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2014-11-14 08:57 - 2014-11-05 18:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll 2014-11-14 08:57 - 2014-11-05 18:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll 2014-11-14 08:57 - 2014-11-05 18:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2014-11-14 08:57 - 2014-11-05 18:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2014-11-14 08:57 - 2014-11-05 18:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2014-11-14 08:57 - 2014-11-05 18:22 - 00683008 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2014-11-14 08:57 - 2014-11-05 18:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2014-11-14 08:57 - 2014-11-05 18:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2014-11-14 08:57 - 2014-11-05 18:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2014-11-14 08:57 - 2014-11-05 18:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2014-11-14 08:57 - 2014-11-05 17:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2014-11-14 08:57 - 2014-11-05 17:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2014-11-14 08:57 - 2014-11-05 17:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2014-11-14 08:57 - 2014-10-17 17:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\System32\oleaut32.dll 2014-11-14 08:57 - 2014-10-13 17:56 - 00136632 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2014-11-14 08:57 - 2014-10-13 17:50 - 01059840 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll 2014-11-14 08:57 - 2014-10-13 17:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\System32\termsrv.dll 2014-11-14 08:57 - 2014-10-13 17:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll 2014-11-14 08:57 - 2014-10-13 17:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll 2014-11-14 08:57 - 2014-08-20 22:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2014-11-14 08:57 - 2014-08-20 22:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\msxml3r.dll 2014-11-14 08:56 - 2014-10-02 17:44 - 00475136 _____ (Microsoft Corporation) C:\Windows\System32\audiosrv.dll 2014-11-14 08:56 - 2014-10-02 17:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\System32\AUDIOKSE.dll 2014-11-14 08:56 - 2014-10-02 17:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\System32\AudioEng.dll 2014-11-14 08:56 - 2014-10-02 17:44 - 00275968 _____ (Microsoft Corporation) C:\Windows\System32\EncDump.dll 2014-11-14 08:56 - 2014-10-02 17:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\System32\AudioSes.dll 2014-11-14 08:56 - 2014-09-19 01:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll 2014-11-14 08:56 - 2014-09-19 01:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll 2014-11-14 08:56 - 2014-09-19 01:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2014-11-14 08:56 - 2014-09-19 01:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll 2014-11-14 08:56 - 2014-09-19 01:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll 2014-11-14 08:56 - 2014-09-19 01:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll 2014-11-14 08:56 - 2014-09-09 13:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll 2014-11-14 08:56 - 2014-09-03 21:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\System32\rastls.dll 2014-11-14 08:56 - 2014-08-11 17:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\System32\IMJP10K.DLL 2014-11-14 08:56 - 2014-07-16 17:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\System32\winsta.dll 2014-11-14 08:56 - 2014-07-16 17:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\System32\mstscax.dll 2014-11-14 08:56 - 2014-07-16 17:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\System32\mstsc.exe 2014-11-14 08:56 - 2014-07-16 17:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\System32\winlogon.exe 2014-11-14 08:56 - 2014-07-16 17:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\System32\aaclient.dll 2014-11-14 08:56 - 2014-07-16 17:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll 2014-11-14 08:56 - 2014-07-16 17:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2014-11-14 08:56 - 2014-07-16 17:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tssecsrv.sys 2014-11-14 08:56 - 2014-07-08 17:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\System32\KBDYAK.DLL 2014-11-14 08:56 - 2014-07-08 17:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\System32\KBDTAT.DLL 2014-11-14 08:56 - 2014-07-08 17:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\System32\KBDRU1.DLL 2014-11-14 08:56 - 2014-07-08 17:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\System32\KBDBASH.DLL 2014-11-14 08:56 - 2014-07-08 17:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\System32\KBDRU.DLL 2014-11-14 08:56 - 2014-07-08 14:30 - 00419992 _____ () C:\Windows\System32\locale.nls 2014-11-14 08:55 - 2014-09-24 17:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\System32\qdvd.dll 2014-11-14 08:54 - 2014-10-24 17:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\System32\packager.dll 2014-11-08 11:18 - 2014-11-08 15:31 - 1548550144 _____ () C:\The.Thirteenth.Floor.1999.PL.DVDRip.AC3.XviD-Xardas.avi 2014-11-08 11:15 - 2014-11-08 14:40 - 734765056 _____ () C:\Maleficent.2014.PLDUB.DVDRip.XviD-GR4PE.avi 2014-11-08 10:59 - 2014-11-08 13:38 - 1467887616 _____ () C:\Transformers.Age.of.Extinction.2014.PLDUB.BRRiP.XViD-K12.avi 2014-11-03 11:24 - 2014-11-03 11:24 - 00000000 __SHD () C:\Users\dom\AppData\Local\EmieUserList 2014-11-03 11:24 - 2014-11-03 11:24 - 00000000 __SHD () C:\Users\dom\AppData\Local\EmieSiteList 2014-11-03 11:06 - 2014-11-03 11:06 - 00000017 _____ () C:\Users\dom\AppData\Local\resmon.resmoncfg 2014-10-30 01:08 - 2014-10-30 01:08 - 00000000 ____D () C:\Users\dom\Desktop\AdventureCraft ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-28 00:06 - 2009-07-13 18:37 - 00000000 ____D () C:\Windows\System32\com 2014-11-28 00:06 - 2009-07-13 18:37 - 00000000 ____D () C:\Windows\IME 2014-11-27 14:24 - 2009-07-13 20:34 - 00003072 _____ () C:\Windows\System32\umstartup.etl 2014-11-27 11:05 - 2012-08-28 10:46 - 01474832 _____ () C:\Windows\System32\Drivers\sfi.dat 2014-11-27 10:33 - 2012-09-09 07:24 - 00000000 ____D () C:\TEMP 2014-11-27 09:18 - 2013-04-19 23:16 - 00000000 ____D () C:\_nowe 2014-11-27 08:47 - 2009-07-13 20:34 - 00014736 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-27 08:47 - 2009-07-13 20:34 - 00014736 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-27 08:40 - 2009-07-13 20:39 - 00236355 _____ () C:\Windows\setupact.log 2014-11-27 08:30 - 2009-12-11 03:17 - 00889006 _____ () C:\Windows\PFRO.log 2014-11-27 08:13 - 2012-08-28 09:36 - 00000000 ____D () C:\Program Files\Adobe 2014-11-27 08:13 - 2010-01-09 10:27 - 00000000 ____D () C:\ProgramData\Adobe 2014-11-27 08:11 - 2012-08-28 10:28 - 00000000 ____D () C:\Program Files\COMODO 2014-11-26 13:58 - 2009-12-10 16:35 - 00740348 _____ () C:\Windows\System32\perfh015.dat 2014-11-26 13:58 - 2009-12-10 16:35 - 00155890 _____ () C:\Windows\System32\perfc015.dat 2014-11-26 13:58 - 2009-07-26 12:06 - 01669190 _____ () C:\Windows\System32\PerfStringBackup.INI 2014-11-26 10:55 - 2009-07-13 18:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-11-26 10:30 - 2010-01-09 10:24 - 00000000 ____D () C:\users\dom 2014-11-25 15:50 - 2009-12-11 19:31 - 02063088 _____ () C:\Windows\WindowsUpdate.log 2014-11-25 15:50 - 2009-07-13 18:37 - 00000000 ____D () C:\Windows\System32\pl-PL 2014-11-25 15:41 - 2010-01-09 10:33 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-11-25 14:54 - 2009-07-13 18:04 - 00000510 _____ () C:\Windows\win.ini 2014-11-24 12:48 - 2014-04-10 11:43 - 00000000 ___HD () C:\VTRoot 2014-11-22 05:14 - 2014-04-10 11:43 - 00075302 _____ () C:\Windows\System32\Drivers\fvstore.dat 2014-11-22 04:49 - 2013-09-22 06:20 - 00000000 ____D () C:\Users\dom\AppData\Roaming\.minecraft 2014-11-21 09:18 - 2012-08-28 09:15 - 00000000 ____D () C:\Users\dom\AppData\Local\Google 2014-11-21 09:14 - 2013-06-18 12:01 - 00000000 ____D () C:\Program Files\Google 2014-11-20 08:45 - 2009-07-13 18:37 - 00000000 ____D () C:\Windows\schemas 2014-11-19 14:28 - 2013-12-08 05:24 - 00000000 ____D () C:\DAWID P 2014-11-18 10:46 - 2013-01-13 13:13 - 00000000 ____D () C:\Users\dom\AppData\Roaming\Notepad++ 2014-11-17 14:28 - 2014-08-31 11:49 - 00000000 ____D () C:\Users\dom\Documents\MapView 2014-11-17 14:27 - 2013-01-13 13:13 - 00000000 ____D () C:\Program Files\Notepad++ 2014-11-17 14:11 - 2012-10-22 12:46 - 00000000 ____D () C:\_tmp 2014-11-17 13:59 - 2012-08-28 11:08 - 00000000 ___HD () C:\VritualRoot 2014-11-17 04:31 - 2012-08-28 08:17 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-11-14 13:22 - 2009-07-13 18:37 - 00000000 ____D () C:\Windows\rescache 2014-11-14 11:03 - 2009-07-13 20:33 - 00425296 _____ () C:\Windows\System32\FNTCACHE.DAT 2014-11-14 09:14 - 2013-08-14 08:32 - 00000000 ____D () C:\Windows\System32\MRT 2014-11-11 11:29 - 2012-08-28 08:17 - 00000000 ____D () C:\Users\dom\AppData\Roaming\Mozilla 2014-11-09 03:39 - 2013-12-08 05:22 - 00000000 ____D () C:\weronika 2014-11-03 14:05 - 2012-08-28 09:49 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird 2014-11-03 11:11 - 2012-12-09 04:04 - 00000000 ____D () C:\Users\dom\Desktop\egzamin 2014-11-03 10:32 - 2009-07-13 18:37 - 00000000 ____D () C:\Windows\System32\NDF 2014-10-31 14:25 - 2012-08-29 12:48 - 100445232 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe ==================== Known DLLs (Whitelisted) ============ ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe [2014-11-14 08:56] - [2014-07-16 17:39] - 0304128 ____A (Microsoft Corporation) 52449FD429D6053B78AE564DEF303870 C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE Association (whitelisted) ============= ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 14% Total physical RAM: 3956.55 MB Available physical RAM: 3396.62 MB Total Pagefile: 3954.82 MB Available Pagefile: 3399.29 MB Total Virtual: 2047.88 MB Available Virtual: 1952.71 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:148.72 GB) (Free:18.42 GB) NTFS Drive e: () (Fixed) (Total:301.95 GB) (Free:63.07 GB) NTFS Drive f: (RECOVERY) (Fixed) (Total:15 GB) (Free:3.41 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive h: () (Removable) (Total:3.76 GB) (Free:1.87 GB) NTFS Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: () (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: E3598C4B) Partition 1: (Not Active) - (Size=15 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=148.7 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=301.9 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 3.8 GB) (Disk ID: 04DD5721) Partition 1: (Not Active) - (Size=3.8 GB) - (Type=07 NTFS) LastRegBack: 2014-11-25 13:22 ==================== End Of Log ============================