Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-04-2016 Ran by Michael Jackson (administrator) on DESKTOP-PBETDGK (15-04-2016 18:09:55) Running from C:\Users\Michael Jackson\Desktop Loaded Profiles: Michael Jackson (Available Profiles: Michael Jackson) Platform: Windows 10 Enterprise (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (@ByELDI) C:\Program Files\KMSpico\Service_KMS.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\msoia.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe () C:\Program Files\EIZO\ColorNavigator 6\ColorNavigator 6.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe () C:\Program Files\EIZO\ColorNavigator 6\core\cn6_eacore.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (K2T.eu, Kaworu) C:\Program Files\K2T\WTW\wtw.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1794888 2015-08-20] (NVIDIA Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-08-20] (Realtek Semiconductor) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5595848 2015-07-08] (ESET) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-05-26] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3477640 2012-09-23] (Adobe Systems Inc.) HKU\S-1-5-21-3609454662-1413584907-928193442-1001\...\RunOnce: [Uninstall C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64" HKU\S-1-5-21-3609454662-1413584907-928193442-1001\...\RunOnce: [Uninstall C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64" HKU\S-1-5-21-3609454662-1413584907-928193442-1001\...\RunOnce: [Uninstall C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64" HKU\S-1-5-21-3609454662-1413584907-928193442-1001\...\RunOnce: [Uninstall C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.5951.0827] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.5951.0827" HKU\S-1-5-21-3609454662-1413584907-928193442-1001\...\RunOnce: [Uninstall C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64" HKU\S-1-5-21-3609454662-1413584907-928193442-1001\...\RunOnce: [Uninstall C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.6201.1019] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.6201.1019" HKU\S-1-5-21-3609454662-1413584907-928193442-1001\...\RunOnce: [Uninstall C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64" HKU\S-1-5-21-3609454662-1413584907-928193442-1001\...\RunOnce: [Uninstall C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.6281.1202] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.6281.1202" HKU\S-1-5-21-3609454662-1413584907-928193442-1001\...\RunOnce: [Uninstall C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64" HKU\S-1-5-21-3609454662-1413584907-928193442-1001\...\RunOnce: [Uninstall C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.6301.0127] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael Jackson\AppData\Local\Microsoft\OneDrive\17.3.6301.0127" Startup: C:\Users\Michael Jackson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ColorNavigator 6.lnk [2015-08-20] ShortcutTarget: ColorNavigator 6.lnk -> C:\Program Files\EIZO\ColorNavigator 6\ColorNavigator 6.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Winsock: Catalog5 01 C:\Windows\SysWOW64\napinsp.dll [54784 2015-07-10] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\napinsp.dll" Winsock: Catalog5 02 C:\Windows\SysWOW64\pnrpnsp.dll [70144 2015-07-10] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll" Winsock: Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [70144 2015-07-10] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll" Winsock: Catalog5 04 C:\Windows\SysWOW64\NLAapi.dll [64000 2015-07-10] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [306528 2015-07-10] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Winsock: Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [23552 2015-07-10] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\winrnr.dll" Tcpip\Parameters: [DhcpNameServer] 80.243.191.66 8.8.8.8 Tcpip\..\Interfaces\{c39e5ce8-aafb-4604-aa04-480efa2f9e21}: [DhcpNameServer] 80.243.191.66 8.8.8.8 Internet Explorer: ================== BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2016-04-03] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-04-03] (Microsoft Corporation) BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll [2015-12-24] (DVDVideoSoft Ltd.) BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25] (Eyeo GmbH) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2016-04-03] (Microsoft Corporation) BHO-x32: Adobe Acrobat Create PDF Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2016-04-03] (Microsoft Corporation) BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated) BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2012-09-23] (Adobe Systems Incorporated) Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-04-03] (Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-04-03] (Microsoft Corporation) Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-04-03] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-04-03] (Microsoft Corporation) Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-04-03] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-04-03] (Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-04-03] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-04-03] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Michael Jackson\AppData\Roaming\Mozilla\Firefox\Profiles\3pqxwyie.default-1449325836741 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll [2015-12-23] () FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-04-03] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-23] () FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-04-03] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2016-04-03] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-10-13] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-10-13] (NVIDIA Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2012-09-23] (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems) FF Extension: Adblock Plus - C:\Users\Michael Jackson\AppData\Roaming\Mozilla\Firefox\Profiles\3pqxwyie.default-1449325836741\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-24] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2016-02-24] [not signed] FF HKU\S-1-5-21-3609454662-1413584907-928193442-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2012-09-23] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2838768 2016-04-03] (Microsoft Corporation) R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [388968 2015-12-24] (Digital Wave Ltd.) R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1353720 2015-07-08] (ESET) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes) S3 ose64; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [242720 2016-04-02] (Microsoft Corporation) [File not signed] R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [734400 2015-08-15] (@ByELDI) [File not signed] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6942480 2016-03-02] (TeamViewer GmbH) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [255240 2015-07-14] (ESET) R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [251632 2015-07-14] (ESET) R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [178520 2015-07-14] (ESET) R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [168208 2015-07-14] (ESET) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115448 2013-11-21] (EZB Systems, Inc.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-04-15] (Malwarebytes) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation) S3 PortTalk; C:\Windows\SysWOW64\Drivers\PortTalk.sys [3567 2002-01-12] (Beyond Logic hxxp://www.beyondlogic.org) [File not signed] R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek ) S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] () S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation) S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-04-15 18:09 - 2016-04-15 18:10 - 00017371 _____ C:\Users\Michael Jackson\Desktop\FRST.txt 2016-04-15 18:04 - 2016-04-15 18:04 - 00016148 _____ C:\Windows\system32\DESKTOP-PBETDGK_Michael Jackson_HistoryPrediction.bin 2016-04-15 18:03 - 2016-04-15 18:03 - 00294952 _____ C:\Windows\Minidump\041516-21171-01.dmp 2016-04-15 17:50 - 2016-04-15 18:05 - 00000000 ____D C:\Users\Michael Jackson\Desktop\GMER 2016-04-15 17:48 - 2016-04-15 18:05 - 00000000 ____D C:\Users\Michael Jackson\Desktop\moje logi 2016-04-15 17:43 - 2016-04-15 17:44 - 00000000 ____D C:\Users\Michael Jackson\Desktop\FRST tutorial 2016-04-15 16:45 - 2016-04-15 16:53 - 00000790 _____ C:\Users\Michael Jackson\Desktop\trzeba te logi pokazac.txt 2016-04-15 15:29 - 2016-04-15 15:29 - 00000000 ____D C:\Users\Michael Jackson\Desktop\pliki kolesia z netu 2016-04-15 15:23 - 2016-04-15 18:09 - 00000000 ____D C:\FRST 2016-04-15 15:13 - 2016-04-15 15:13 - 02375168 _____ (Farbar) C:\Users\Michael Jackson\Desktop\FRST64.exe 2016-04-15 14:53 - 2016-04-15 16:41 - 00001334 _____ C:\Users\Michael Jackson\Desktop\moj tekst.txt 2016-04-15 14:41 - 2016-04-15 14:41 - 00000000 ____D C:\Users\Michael Jackson\Desktop\21-22 GROCHOCKI 2016-04-15 13:55 - 2016-04-15 18:04 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-04-15 13:54 - 2016-04-15 13:54 - 00001184 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2016-04-15 13:54 - 2016-04-15 13:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-04-15 13:54 - 2016-04-15 13:54 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-04-15 13:54 - 2016-04-15 13:54 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2016-04-15 13:54 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2016-04-15 13:54 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-04-15 13:54 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2016-04-15 13:15 - 2016-04-15 13:32 - 00000000 ____D C:\AdwCleaner 2016-04-15 13:10 - 2016-04-15 13:10 - 03677760 _____ C:\Users\Michael Jackson\Desktop\adwcleaner_5.111.exe 2016-04-15 13:06 - 2016-04-15 13:07 - 00000000 ____D C:\Users\Michael Jackson\Desktop\TORRENT 2016-04-15 10:15 - 2016-04-15 10:15 - 00000000 ____D C:\Users\Michael Jackson\Desktop\zdjecia wacek 2016-04-13 09:52 - 2016-04-13 12:49 - 00000000 ____D C:\Users\Michael Jackson\Desktop\ANON CIEKAWE 2016-04-13 00:53 - 2016-03-29 08:40 - 03587584 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys 2016-04-13 00:53 - 2016-03-29 08:40 - 01381376 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys 2016-04-13 00:53 - 2016-03-25 09:38 - 24593408 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-04-13 00:53 - 2016-03-25 09:25 - 12505600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-04-13 00:53 - 2016-03-25 09:14 - 07525376 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll 2016-04-13 00:53 - 2016-03-25 09:13 - 19325440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-04-13 00:53 - 2016-03-25 08:55 - 11263488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-04-13 00:53 - 2016-03-25 08:54 - 05457408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll 2016-04-13 00:53 - 2016-03-16 06:56 - 03467784 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll 2016-04-13 00:53 - 2016-03-16 06:56 - 01022664 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2016-04-13 00:53 - 2016-03-16 06:56 - 00861512 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2016-04-13 00:53 - 2016-03-16 06:55 - 02495768 _____ C:\Windows\system32\CoreUIComponents.dll 2016-04-13 00:53 - 2016-03-16 06:55 - 01951872 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-04-13 00:53 - 2016-03-16 06:55 - 01299032 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2016-04-13 00:53 - 2016-03-16 06:55 - 01127024 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2016-04-13 00:53 - 2016-03-16 06:55 - 00601344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2016-04-13 00:53 - 2016-03-16 06:54 - 00595016 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Shell.Broker.dll 2016-04-13 00:53 - 2016-03-16 06:47 - 22610328 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2016-04-13 00:53 - 2016-03-16 06:47 - 03622272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-04-13 00:53 - 2016-03-16 06:47 - 00801632 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe 2016-04-13 00:53 - 2016-03-16 06:46 - 00658568 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll 2016-04-13 00:53 - 2016-03-16 06:45 - 00140536 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe 2016-04-13 00:53 - 2016-03-16 06:41 - 00607416 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe 2016-04-13 00:53 - 2016-03-16 06:41 - 00208736 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll 2016-04-13 00:53 - 2016-03-16 06:39 - 00983904 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi 2016-04-13 00:53 - 2016-03-16 06:37 - 01010016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2016-04-13 00:53 - 2016-03-16 06:21 - 01767000 _____ C:\Windows\SysWOW64\CoreUIComponents.dll 2016-04-13 00:53 - 2016-03-16 06:21 - 01531888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-04-13 00:53 - 2016-03-16 06:11 - 21088728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2016-04-13 00:53 - 2016-03-16 06:11 - 02879024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-04-13 00:53 - 2016-03-16 06:11 - 00700256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe 2016-04-13 00:53 - 2016-03-16 06:08 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe 2016-04-13 00:53 - 2016-03-16 06:06 - 00181088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll 2016-04-13 00:53 - 2016-03-16 06:05 - 00539728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe 2016-04-13 00:53 - 2016-03-16 06:03 - 00911360 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll 2016-04-13 00:53 - 2016-03-16 06:03 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll 2016-04-13 00:53 - 2016-03-16 06:00 - 21859840 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll 2016-04-13 00:53 - 2016-03-16 05:56 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\PhoneCallHistoryApis.dll 2016-04-13 00:53 - 2016-03-16 05:56 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModelShim.dll 2016-04-13 00:53 - 2016-03-16 05:55 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\UserDataAccountApis.dll 2016-04-13 00:53 - 2016-03-16 05:55 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll 2016-04-13 00:53 - 2016-03-16 05:55 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\ExtrasXmlParser.dll 2016-04-13 00:53 - 2016-03-16 05:51 - 00348672 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll 2016-04-13 00:53 - 2016-03-16 05:51 - 00334848 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll 2016-04-13 00:53 - 2016-03-16 05:49 - 01416192 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-04-13 00:53 - 2016-03-16 05:49 - 00850432 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2016-04-13 00:53 - 2016-03-16 05:47 - 00856576 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll 2016-04-13 00:53 - 2016-03-16 05:47 - 00511488 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll 2016-04-13 00:53 - 2016-03-16 05:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll 2016-04-13 00:53 - 2016-03-16 05:46 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\fwpolicyiomgr.dll 2016-04-13 00:53 - 2016-03-16 05:44 - 01016832 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll 2016-04-13 00:53 - 2016-03-16 05:43 - 00573952 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.Desktop.dll 2016-04-13 00:53 - 2016-03-16 05:42 - 02180608 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll 2016-04-13 00:53 - 2016-03-16 05:42 - 01290240 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Shell.dll 2016-04-13 00:53 - 2016-03-16 05:42 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\shutdownux.dll 2016-04-13 00:53 - 2016-03-16 05:41 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-04-13 00:53 - 2016-03-16 05:40 - 00931840 _____ (Microsoft Corporation) C:\Windows\system32\AppxPackaging.dll 2016-04-13 00:53 - 2016-03-16 05:40 - 00322048 _____ (Microsoft Corporation) C:\Windows\system32\vaultsvc.dll 2016-04-13 00:53 - 2016-03-16 05:40 - 00280576 _____ (Microsoft Corporation) C:\Windows\system32\vaultcli.dll 2016-04-13 00:53 - 2016-03-16 05:40 - 00214528 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Scanners.dll 2016-04-13 00:53 - 2016-03-16 05:40 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\AppxSip.dll 2016-04-13 00:53 - 2016-03-16 05:40 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\AuthBroker.dll 2016-04-13 00:53 - 2016-03-16 05:40 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2016-04-13 00:53 - 2016-03-16 05:39 - 03363328 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2016-04-13 00:53 - 2016-03-16 05:39 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll 2016-04-13 00:53 - 2016-03-16 05:38 - 01423872 _____ (Microsoft Corporation) C:\Windows\system32\UserDataService.dll 2016-04-13 00:53 - 2016-03-16 05:37 - 01521664 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncProvider.dll 2016-04-13 00:53 - 2016-03-16 05:37 - 00856576 _____ (Microsoft Corporation) C:\Windows\system32\ContactApis.dll 2016-04-13 00:53 - 2016-03-16 05:37 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\ChatApis.dll 2016-04-13 00:53 - 2016-03-16 05:37 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentApis.dll 2016-04-13 00:53 - 2016-03-16 05:37 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\PimIndexMaintenance.dll 2016-04-13 00:53 - 2016-03-16 05:37 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\FontProvider.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 01205248 _____ (Microsoft Corporation) C:\Windows\system32\Unistore.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\EmailApis.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\ExSMime.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\deviceaccess.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\cemapi.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00195072 _____ (Microsoft Corporation) C:\Windows\system32\VCardParser.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\CallHistoryClient.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\wpninprc.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\POSyncServices.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\PimIndexMaintenanceClient.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\UserDataPlatformHelperUtil.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTypeHelperUtil.dll 2016-04-13 00:53 - 2016-03-16 05:36 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\UserDataLanguageUtil.dll 2016-04-13 00:53 - 2016-03-16 05:35 - 01794560 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll 2016-04-13 00:53 - 2016-03-16 05:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\AppxApplicabilityEngine.dll 2016-04-13 00:53 - 2016-03-16 05:35 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\PackageStateRoaming.dll 2016-04-13 00:53 - 2016-03-16 05:35 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll 2016-04-13 00:53 - 2016-03-16 05:35 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\dssvc.dll 2016-04-13 00:53 - 2016-03-16 05:34 - 01871872 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2016-04-13 00:53 - 2016-03-16 05:33 - 00670208 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll 2016-04-13 00:53 - 2016-03-16 05:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll 2016-04-13 00:53 - 2016-03-16 05:31 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataAccountApis.dll 2016-04-13 00:53 - 2016-03-16 05:31 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhoneCallHistoryApis.dll 2016-04-13 00:53 - 2016-03-16 05:31 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExtrasXmlParser.dll 2016-04-13 00:53 - 2016-03-16 05:28 - 00163328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwbase.dll 2016-04-13 00:53 - 2016-03-16 05:27 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll 2016-04-13 00:53 - 2016-03-16 05:24 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll 2016-04-13 00:53 - 2016-03-16 05:24 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwpolicyiomgr.dll 2016-04-13 00:53 - 2016-03-16 05:21 - 18796544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll 2016-04-13 00:53 - 2016-03-16 05:18 - 00104960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthBroker.dll 2016-04-13 00:53 - 2016-03-16 05:17 - 03680256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2016-04-13 00:53 - 2016-03-16 05:17 - 00842240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxPackaging.dll 2016-04-13 00:53 - 2016-03-16 05:17 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vaultcli.dll 2016-04-13 00:53 - 2016-03-16 05:17 - 00168448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Scanners.dll 2016-04-13 00:53 - 2016-03-16 05:17 - 00133120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxSip.dll 2016-04-13 00:53 - 2016-03-16 05:17 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2016-04-13 00:53 - 2016-03-16 05:16 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll 2016-04-13 00:53 - 2016-03-16 05:14 - 00625152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContactApis.dll 2016-04-13 00:53 - 2016-03-16 05:14 - 00579584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppointmentApis.dll 2016-04-13 00:53 - 2016-03-16 05:14 - 00557568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ChatApis.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00928256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Unistore.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00525312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EmailApis.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00223744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExSMime.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00201216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cemapi.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VCardParser.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00131072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CallHistoryClient.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00056320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\POSyncServices.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00055808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataPlatformHelperUtil.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00052736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PimIndexMaintenanceClient.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTypeHelperUtil.dll 2016-04-13 00:53 - 2016-03-16 05:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataLanguageUtil.dll 2016-04-13 00:53 - 2016-03-16 05:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PackageStateRoaming.dll 2016-04-13 00:53 - 2016-03-16 05:11 - 01594368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2016-04-13 00:53 - 2016-03-16 05:10 - 00295424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll 2016-04-13 00:52 - 2016-03-16 05:55 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\fwbase.dll 2016-04-13 00:52 - 2016-03-16 05:43 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll 2016-04-13 00:52 - 2016-03-16 05:40 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2016-04-13 00:52 - 2016-03-16 05:39 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\AppxSysprep.dll 2016-04-13 00:52 - 2016-03-16 05:24 - 00019456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll 2016-04-13 00:52 - 2016-03-16 05:20 - 00118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll 2016-04-13 00:52 - 2016-03-16 05:18 - 00768000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-04-12 21:30 - 2016-04-12 21:32 - 00000000 ____D C:\Users\Michael Jackson\Desktop\plaskostopie badanie 2016-04-12 21:06 - 2016-04-12 21:06 - 00000000 ____D C:\Program Files\Common Files\DESIGNER 2016-04-12 09:22 - 2016-04-12 09:23 - 00001854 _____ C:\Users\Michael Jackson\Desktop\Acrobat Distiller.lnk 2016-04-12 08:46 - 2016-04-15 17:44 - 00000000 ____D C:\Users\Michael Jackson\Desktop\L-FLEX 2016-04-11 21:22 - 2016-04-15 13:37 - 00000000 ____D C:\Users\Michael Jackson\AppData\Roaming\DMCache 2016-04-11 21:22 - 2016-04-11 21:22 - 00000000 ____D C:\Users\Michael Jackson\Downloads\Video 2016-04-11 21:22 - 2016-04-11 21:22 - 00000000 ____D C:\Users\Michael Jackson\Downloads\Compressed 2016-04-11 21:22 - 2016-04-11 21:22 - 00000000 ____D C:\ProgramData\IDM 2016-04-11 09:54 - 2016-04-11 10:37 - 00000000 ____D C:\Users\Michael Jackson\AppData\Roaming\TeamViewer 2016-04-11 09:54 - 2016-04-11 09:54 - 00001125 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk 2016-04-11 09:54 - 2016-04-11 09:54 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2016-04-10 11:27 - 2016-04-11 15:26 - 00000000 ____D C:\Users\Michael Jackson\Desktop\CZAS MIGAWKI Z REKI BEZ LAMPY - 1-60 - C6D + S50 1.4 ART 2016-04-09 14:33 - 2016-04-09 22:00 - 00000000 ____D C:\Users\Michael Jackson\Desktop\luxexpress bilety 2016-04-09 14:13 - 2016-04-15 18:03 - 00000000 ____D C:\Windows\Minidump 2016-04-09 14:13 - 2016-04-09 14:13 - 00294856 _____ C:\Windows\Minidump\040916-29187-01.dmp 2016-04-09 14:12 - 2016-04-15 18:03 - 714394924 _____ C:\Windows\MEMORY.DMP 2016-04-09 01:18 - 2016-04-11 14:25 - 00000000 ____D C:\Users\Michael Jackson\Desktop\alior kantor 2016-04-08 22:43 - 2016-04-08 22:43 - 00000797 _____ C:\Users\Michael Jackson\Desktop\Kopie 04 Kwiecien - Shortcut.lnk 2016-04-08 18:10 - 2016-04-08 22:15 - 00000573 _____ C:\Users\Michael Jackson\Desktop\zus internet - od stycznia 1999.txt 2016-04-08 12:39 - 2016-04-15 14:02 - 00000000 ____D C:\Users\Michael Jackson\Desktop\PINS - Aby uznać Twoją zniżkę, prosiy o okazanie kierowcy karty PINS przy wsiadanu do autokaru 2016-04-06 15:24 - 2016-04-11 15:01 - 00000000 ____D C:\Users\Michael Jackson\Desktop\BERLIN AUTA 2016-04-05 10:48 - 2016-04-05 21:50 - 00001909 _____ C:\Users\Michael Jackson\Desktop\KOSTIUMY WYPOZYCZALNIE.txt 2016-04-04 17:32 - 2016-04-05 20:02 - 00001733 _____ C:\Users\Michael Jackson\Desktop\TEATR JARACZA.txt 2016-04-02 13:31 - 2016-04-02 13:31 - 00000000 ____D C:\Users\Michael Jackson\Desktop\PIE 2016-04-01 18:16 - 2016-04-04 23:46 - 00000417 _____ C:\Users\Michael Jackson\Desktop\OLX - ODDAM.txt 2016-03-31 12:51 - 2016-04-01 14:43 - 00000000 ____D C:\Users\Michael Jackson\Desktop\dorota broclawska 2016-03-26 17:12 - 2016-03-26 17:31 - 00000221 _____ C:\Users\Michael Jackson\Desktop\bilety.txt 2016-03-26 16:03 - 2016-03-26 17:36 - 00000000 ____D C:\Users\Michael Jackson\Desktop\GDANSK 4 CZERWIEC 2016-03-23 13:13 - 2016-04-07 10:56 - 00000000 ____D C:\Users\Michael Jackson\Desktop\przepowiednie 2016-03-22 20:00 - 2016-03-23 19:57 - 00000000 ____D C:\Users\Michael Jackson\Desktop\Dennis L. Meadows - granice wzrostu 2016-03-22 19:57 - 2016-03-29 18:58 - 00000000 ____D C:\Users\Michael Jackson\Desktop\jak dobija sie gospodarke polska 2016-03-22 19:32 - 2016-03-22 19:32 - 00000000 ____D C:\Users\Michael Jackson\Desktop\KALENDARZ RYTUALOW 2016-03-21 14:01 - 2016-03-21 14:01 - 00000808 _____ C:\Users\Michael Jackson\Desktop\Filmy - dokumentelne.lnk 2016-03-19 03:08 - 2016-03-19 03:08 - 00000000 ____D C:\Users\Michael Jackson\Desktop\cielebias tematy 2016-03-18 01:42 - 2016-04-15 14:28 - 00000000 ____D C:\Users\Michael Jackson\AppData\Roaming\Opera Software 2016-03-18 01:42 - 2016-04-15 14:28 - 00000000 ____D C:\Users\Michael Jackson\AppData\Local\Opera Software 2016-03-18 01:42 - 2016-04-15 14:28 - 00000000 ____D C:\Program Files (x86)\Opera ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-04-15 18:07 - 2015-08-20 20:29 - 00875126 _____ C:\Windows\system32\PerfStringBackup.INI 2016-04-15 18:07 - 2015-07-10 13:02 - 00000000 ____D C:\Windows\INF 2016-04-15 18:04 - 2015-08-20 20:58 - 00000000 ____D C:\Users\Michael Jackson 2016-04-15 18:03 - 2015-08-20 21:06 - 00000000 ____D C:\ProgramData\NVIDIA 2016-04-15 18:03 - 2015-07-10 14:21 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-04-15 17:06 - 2015-10-25 14:41 - 00000000 ____D C:\Users\Michael Jackson\AppData\Roaming\vlc 2016-04-15 17:03 - 2015-09-29 20:55 - 00000000 ____D C:\Users\Michael Jackson\AppData\Local\CrashDumps 2016-04-15 16:59 - 2015-07-10 11:05 - 00524288 ___SH C:\Windows\system32\config\BBI 2016-04-15 16:21 - 2015-09-05 14:28 - 00000000 ____D C:\Users\Michael Jackson\AppData\LocalLow\Temp 2016-04-15 16:16 - 2015-08-21 19:32 - 00069491 _____ C:\Users\Michael Jackson\Desktop\LISTA.txt 2016-04-15 14:27 - 2015-12-26 15:41 - 00000000 ____D C:\Users\Michael Jackson\AppData\Local\Google 2016-04-15 14:27 - 2015-12-26 15:41 - 00000000 ____D C:\Program Files (x86)\Google 2016-04-15 14:21 - 2015-07-10 13:04 - 00000000 ___RD C:\Windows\PurchaseDialog 2016-04-15 13:31 - 2015-08-20 20:58 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-04-15 13:27 - 2015-07-10 14:20 - 00360616 _____ C:\Windows\system32\FNTCACHE.DAT 2016-04-15 13:26 - 2015-08-22 18:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-04-15 13:24 - 2015-07-10 11:05 - 00000000 ____D C:\Windows\SysWOW64\Dism 2016-04-15 13:18 - 2016-02-23 13:53 - 00000000 ____D C:\Users\Michael Jackson\Desktop\GDANSK 23 KWIECIEN 2016-04-15 12:21 - 2015-12-24 15:25 - 00002545 _____ C:\Users\Michael Jackson\Desktop\SCIAGAC jak dysk sie bedzie testowal dysk.txt 2016-04-15 12:03 - 2015-08-22 22:06 - 00000000 ____D C:\Users\Michael Jackson\AppData\Roaming\BitTorrent 2016-04-15 09:20 - 2015-08-21 00:10 - 00000000 ____D C:\Users\Michael Jackson\AppData\Local\Adobe 2016-04-14 23:34 - 2015-08-20 20:58 - 00000000 ____D C:\Users\Michael Jackson\AppData\Local\Packages 2016-04-14 23:18 - 2015-08-24 20:40 - 00000034 _____ C:\Users\Michael Jackson\AppData\Roaming\AdobeWLCMCache.dat 2016-04-14 12:46 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\AppReadiness 2016-04-13 09:26 - 2015-08-20 21:06 - 00000000 ____D C:\Windows\system32\MRT 2016-04-13 09:17 - 2015-08-20 21:06 - 135176864 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-04-13 09:17 - 2015-07-10 12:55 - 00000000 ____D C:\Windows\CbsTemp 2016-04-13 08:29 - 2015-07-10 13:04 - 00000000 ___HD C:\Program Files\WindowsApps 2016-04-12 21:06 - 2015-07-10 13:04 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2016-04-12 21:06 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2016-04-12 21:02 - 2015-08-24 21:16 - 00000000 ____D C:\Program Files\Microsoft Office 2016-04-12 14:51 - 2015-08-22 18:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-04-09 14:12 - 2015-08-22 18:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2016-04-07 12:53 - 2015-11-20 19:33 - 00000000 ____D C:\Users\Michael Jackson\Desktop\NOWE 2016-04-06 20:32 - 2015-10-05 21:34 - 00829944 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-04-06 20:32 - 2015-10-05 21:34 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-04-01 12:54 - 2016-03-06 02:59 - 00001927 _____ C:\Users\Michael Jackson\Desktop\SPOTKANIA.txt 2016-03-26 11:32 - 2016-01-16 15:12 - 00000000 ____D C:\Users\Michael Jackson\AppData\Roaming\DVDVideoSoft 2016-03-23 05:07 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files\Windows Portable Devices 2016-03-23 05:07 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files\Windows Multimedia Platform 2016-03-23 05:07 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices 2016-03-23 05:07 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2016-03-22 20:43 - 2015-12-03 22:16 - 00000000 ____D C:\Users\Michael Jackson\Desktop\bestie konca czasu - tematy 2016-03-22 16:57 - 2015-10-30 21:01 - 00001358 _____ C:\Users\Michael Jackson\Desktop\MEDIA NIEZALEZNE.txt 2016-03-19 03:05 - 2016-01-12 20:09 - 00000000 ____D C:\Users\Michael Jackson\Desktop\zeby wybielanie 2016-03-18 18:24 - 2015-09-26 14:23 - 00014540 _____ C:\Users\Michael Jackson\Desktop\LISTA - CIEKAWE.txt 2016-03-18 17:53 - 2016-02-11 19:06 - 00000000 ____D C:\Users\Michael Jackson\Desktop\INPOST reklamacja - IPR3101144 2016-03-17 00:18 - 2016-03-11 19:57 - 00000000 ____D C:\Users\Michael Jackson\Desktop\ISO C6D 2016-03-16 06:56 - 2015-07-10 15:20 - 00397270 __RSH C:\bootmgr ==================== Files in the root of some directories ======= 2015-08-24 20:40 - 2016-04-14 23:18 - 0000034 _____ () C:\Users\Michael Jackson\AppData\Roaming\AdobeWLCMCache.dat 2016-02-29 18:33 - 2016-02-29 18:34 - 238722213 _____ () C:\Users\Michael Jackson\AppData\Local\ACCCx3_5_1_209.zip.aamdownload 2016-02-29 18:33 - 2016-02-29 18:34 - 0002741 _____ () C:\Users\Michael Jackson\AppData\Local\ACCCx3_5_1_209.zip.aamdownload.aamd 2015-08-31 22:36 - 2015-09-24 22:34 - 0001456 _____ () C:\Users\Michael Jackson\AppData\Local\Adobe Save for Web 13.0 Prefs ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-04-11 17:55 ==================== End of FRST.txt ============================