
Jeśli nie odpowiadam od razu w temacie, to znaczy że mam życie poza internetem. Uszanuj mój dobrowolnie poświęcony czas i nie oczekuj wszystkiego natychmiast. Jeśli nie odpowiadam przez 48 godzin, przyślij PW.
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Users\ACER\AppData\Local\Temp\ose00000.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvCplDaemon] => C:\Windows\system32\NvCpl.dll [16334880 2009-07-28] (NVIDIA Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1808168 2009-06-18] (Synaptics Incorporated)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8060960 2009-08-05] (Realtek Semiconductor)
HKU\S-1-5-21-650615087-400821380-3474875620-1000\...\Run: [GoogleChromeAutoLaunch_65E5181ECE61BC684C401CB8CBBA7B70] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488 2014-04-30] (Google Inc.)
HKU\S-1-5-21-650615087-400821380-3474875620-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-650615087-400821380-3474875620-1000\...\MountPoints2: {56eb0773-a9ef-11e3-88c3-001f1695c0ba} - F:\AutoRun.exe
HKU\S-1-5-21-650615087-400821380-3474875620-1000\...\MountPoints2: {a8274169-baf7-11e3-912a-001f1695c0ba} - F:\AutoRun.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.pl/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {5471CEF9-5B7E-436E-A076-D52C3A17AF4C} URL = https://www.google.com/search?q={searchTerms}
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.7.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/AuthorwarePlayer - C:\Windows\system32\Macromed\AUTHORWA\np32asw.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1206147.dll No File
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
Chrome:
=======
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-20]
CHR Extension: (Top Eleven) - C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljphpjlafmmdmegmfbkacafhbegjfkkn [2014-05-04]
CHR Extension: (Google Wallet) - C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-13]
==================== Services (Whitelisted) =================
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
==================== Drivers (Whitelisted) ====================
R3 hidshim; C:\Windows\System32\DRIVERS\hidshim.sys [6656 2009-07-21] (Windows (R) Win 7 DDK provider)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-18] (Malwarebytes Corporation)
R3 nuvotonhidgeneric; C:\Windows\System32\DRIVERS\nuvotonhidgeneric.sys [25088 2009-07-21] (Nuvoton Technology Corporation)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [113952 2014-02-25] (Oracle Corporation)
U3 DfSdkS;
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-05-2014
Ran by ACER at 2014-05-18 18:11:30
Running from C:\Users\ACER\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
7-Zip 9.30 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0930-000001000000}) (Version: 9.30.00.0 - Igor Pavlov)
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.206 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.206 - Adobe Systems Incorporated)
Adobe Shockwave Player + Authorware Web Player (HKLM-x32\...\Adobe Shockwave Player + Authorware Web Player) (Version: v12.0.6.147 - Adobe Systems, Inc.)
AIMP3 (HKLM-x32\...\AIMP3) (Version: v3.55.1324, 15.11.2013 - AIMP DevTeam)
BurnAware Free 6.8 (HKLM-x32\...\BurnAware Free) (Version: 6.8 - Burnaware Technologies)
CCleaner (HKLM\...\CCleaner) (Version: 4.13 - Piriform)
Foxit Reader 6.1.1.1025 (HKLM\...\Foxit Reader) (Version: v 6.1.1.1025 - oszone.net)
Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden
Lagarith Lossless Codec (1.3.27) (HKLM-x32\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version: - )
Malwarebytes Anti-Malware wersja 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - x64 8.0.50727.42 False (Version: 8.0.50727.42 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable - x64 8.0.51011 False (Version: 8.0.51011 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable - x64 8.0.56336 False (Version: 8.0.56336 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable - x64 8.0.58298 False (Version: 8.0.58298 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable - x64 8.0.59192 False (Version: 8.0.59192 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable - x64 8.0.61000 (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - x86 8.0.50727.42 False (x32 Version: 8.0.50727.42 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable - x86 8.0.51011 False (x32 Version: 8.0.51011 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable - x86 8.0.56336 False (x32 Version: 8.0.56336 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable - x86 8.0.58299 False (x32 Version: 8.0.58299 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable - x86 8.0.59193 False (x32 Version: 8.0.59193 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001 (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 False (Version: 9.0.21022 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.0 False (Version: 9.0.21022 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.218 False (Version: 9.0.21022.218 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30411 False (Version: 9.0.30411 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 False (Version: 9.0.30729 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 False (Version: 9.0.30729 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4048 False (Version: 9.0.30729.4048 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 False (Version: 9.0.30729.4148 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.5570 False (Version: 9.0.30729.5570 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 False (x32 Version: 9.0.21022 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.0 False (x32 Version: 9.0.21022 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 False (x32 Version: 9.0.21022.218 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 False (x32 Version: 9.0.30411 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.30319 False (Version: 10.0.30319 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 False (x32 Version: 11.0.50727.1 - Корпорация Майкрософт) Hidden
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 False (x32 Version: 11.0.51106.1 - Корпорация Майкрософт) Hidden
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 False (x32 Version: 11.0.60610.1 - Корпорация Майкрософт) Hidden
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 False (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 False (Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 False (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 False (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 False (Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 False (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{51adbf11-493f-431c-a862-967a0fae2944}) (Version: 12.0.21005.1 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}) (Version: 12.0.21005.1 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Nuvoton EC Generic HID Driver (HKLM-x32\...\{92975DF9-EA36-4F36-A9AC-D412BC1D709E}) (Version: 8.80.1001 - Nuvoton Technology Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation)
Pakiet sterowników systemu Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0) (HKLM\...\FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D) (Version: 08/22/2008 7.0.0.0 - Nokia)
PC Connectivity Solution (HKLM-x32\...\{A2AA4204-C05A-4013-888A-AD153139297F}) (Version: 11.5.29.0 - Nokia)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5911 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7100.30093 - Realtek Semiconductor Corp.)
SAM CoDeC Pack (HKLM\...\SAM CoDeC Pack) (Version: 5.30 - http://www.SamLab.ws)
Skype™ 6.13 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.13.104 - Skype Technologies S.A.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 13.2.2.0 - Synaptics Incorporated)
TT1260 Driver (HKLM-x32\...\{A89EDEFA-785E-4A7D-B9C8-87FFE175D005}) (Version: 1.0.0.17 - LITEON)
Ut Video Codec Suite (HKLM\...\utvideo_is1) (Version: 13.3.0 - UMEZAWA Takeshi)
uTorrent (HKLM-x32\...\uTorrent) (Version: - )
x264vfw - H.264/MPEG-4 AVC codec (remove only) (HKLM-x32\...\x264vfw) (Version: - )
x264vfw - H.264/MPEG-4 AVC codec for x64 (remove only) (HKLM-x32\...\x264vfw64) (Version: - )
Xvid MPEG-4 Video Codec (HKLM\...\Xvid_is1) (Version: - )
Xvid MPEG-4 Video Codec (HKLM-x32\...\Xvid_is1) (Version: - )
==================== Restore Points =========================
10-05-2014 11:20:12 Removed FIFA 09 Demo
11-05-2014 07:54:38 Installed Microsoft Office Word Viewer 2003
13-05-2014 12:23:55 avast! antivirus system restore point
18-05-2014 15:30:11 Removed LogMeIn Hamachi
18-05-2014 16:00:57 Removed Acer System Information
18-05-2014 16:01:45 Usunięto: Nokia Connectivity Cable Driver
18-05-2014 16:02:20 Removed Nokia Software Updater.
18-05-2014 16:06:30 Removed Microsoft Office Word Viewer 2003
18-05-2014 16:07:12 Removed Oracle VM VirtualBox 4.3.8
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {5DDCB463-CB83-46BB-9CAC-647A37E7E432} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-13] (Google Inc.)
Task: {6A9D1426-5434-4E4E-82CE-C24F9591109F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-13] (Google Inc.)
Task: {C6D7174D-16AB-4B77-86E3-CA006BEC267C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-02] (Adobe Systems Incorporated)
Task: {F7730BAF-DACF-4E17-B8C6-0231D398DBCA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-04-17] (Piriform Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-04-17 22:46 - 2014-04-17 22:46 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1045.dll
2014-04-30 21:19 - 2014-04-30 05:42 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.86\libglesv2.dll
2014-04-30 21:19 - 2014-04-30 05:42 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.86\libegl.dll
2014-04-30 21:19 - 2014-04-30 05:43 - 04217672 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.86\pdf.dll
2014-04-30 21:19 - 2014-04-30 05:43 - 00414536 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.86\ppGoogleNaClPluginChrome.dll
2014-04-30 21:19 - 2014-04-30 05:42 - 01732424 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.86\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== Disabled items from MSCONFIG ==============
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: GoogleChromeAutoLaunch_65E5181ECE61BC684C401CB8CBBA7B70 => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (05/18/2014 06:07:12 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
.
Error: (05/18/2014 06:07:12 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
.
Error: (05/18/2014 06:06:30 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
.
Error: (05/18/2014 06:06:30 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
.
Error: (05/18/2014 06:02:20 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
.
Error: (05/18/2014 06:02:20 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
.
Error: (05/18/2014 06:01:45 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
.
Error: (05/18/2014 06:01:45 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
.
Error: (05/18/2014 06:00:57 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
.
Error: (05/18/2014 06:00:57 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez Usługi kryptograficzne nie powiodło się.
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
.
System errors:
=============
Error: (05/18/2014 05:42:45 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa LiveUpdate niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.
Error: (05/18/2014 04:17:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa LiveUpdate niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.
Error: (05/18/2014 02:29:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa LiveUpdate niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.
Error: (05/18/2014 11:29:29 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa LiveUpdate niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.
Error: (05/18/2014 09:07:50 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa LiveUpdate niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.
Error: (05/17/2014 08:27:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa LiveUpdate niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.
Error: (05/17/2014 07:25:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa LiveUpdate niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.
Error: (05/17/2014 01:37:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa LiveUpdate niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.
Error: (05/17/2014 11:57:14 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa LiveUpdate niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.
Error: (05/17/2014 10:21:15 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa LiveUpdate niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.
Microsoft Office Sessions:
=========================
Error: (05/18/2014 06:07:12 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
Error: (05/18/2014 06:07:12 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
Error: (05/18/2014 06:06:30 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
Error: (05/18/2014 06:06:30 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
Error: (05/18/2014 06:02:20 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
Error: (05/18/2014 06:02:20 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
Error: (05/18/2014 06:01:45 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
Error: (05/18/2014 06:01:45 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
Error: (05/18/2014 06:00:57 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
Error: (05/18/2014 06:00:57 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
System Error:
Parametr jest niepoprawny.
==================== Memory info ===========================
Percentage of memory in use: 33%
Total physical RAM: 4090.88 MB
Available physical RAM: 2719.35 MB
Total Pagefile: 8179.89 MB
Available Pagefile: 6608.75 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:153.29 GB) (Free:98.35 GB) NTFS
Drive d: () (Fixed) (Total:79.49 GB) (Free:70.98 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 0D633394)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=153 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=79 GB) - (Type=07 NTFS)
==================== End Of Log ============================
FRST.TXT
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-05-2014
Ran by ACER (administrator) on 8730G on 18-05-2014 19:57:29
Running from C:\Users\ACER\Downloads
Platform: Windows 7 Ultimate (X64) OS Language: Polish
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvCplDaemon] => C:\Windows\system32\NvCpl.dll [16334880 2009-07-28] (NVIDIA Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1808168 2009-06-18] (Synaptics Incorporated)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8060960 2009-08-05] (Realtek Semiconductor)
HKU\S-1-5-21-650615087-400821380-3474875620-1000\...\Run: [GoogleChromeAutoLaunch_65E5181ECE61BC684C401CB8CBBA7B70] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488 2014-04-30] (Google Inc.)
HKU\S-1-5-21-650615087-400821380-3474875620-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-650615087-400821380-3474875620-1000\...\MountPoints2: {56eb0773-a9ef-11e3-88c3-001f1695c0ba} - F:\AutoRun.exe
HKU\S-1-5-21-650615087-400821380-3474875620-1000\...\MountPoints2: {a8274169-baf7-11e3-912a-001f1695c0ba} - F:\AutoRun.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.pl/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {5471CEF9-5B7E-436E-A076-D52C3A17AF4C} URL = https://www.google.com/search?q={searchTerms}
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.7.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/AuthorwarePlayer - C:\Windows\system32\Macromed\AUTHORWA\np32asw.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1206147.dll No File
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
Chrome:
=======
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-20]
CHR Extension: (Top Eleven) - C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljphpjlafmmdmegmfbkacafhbegjfkkn [2014-05-04]
CHR Extension: (Google Wallet) - C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-13]
==================== Services (Whitelisted) =================
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
==================== Drivers (Whitelisted) ====================
R3 hidshim; C:\Windows\System32\DRIVERS\hidshim.sys [6656 2009-07-21] (Windows (R) Win 7 DDK provider)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-18] (Malwarebytes Corporation)
R3 nuvotonhidgeneric; C:\Windows\System32\DRIVERS\nuvotonhidgeneric.sys [25088 2009-07-21] (Nuvoton Technology Corporation)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [113952 2014-02-25] (Oracle Corporation)
U3 DfSdkS;
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-18 18:11 - 2014-05-18 18:11 - 00021609 _____ () C:\Users\ACER\Downloads\Addition.txt
2014-05-18 18:10 - 2014-05-18 19:57 - 00000000 ____D () C:\FRST
2014-05-18 18:10 - 2014-05-18 18:10 - 02067456 _____ (Farbar) C:\Users\ACER\Downloads\FRST64.exe
2014-05-18 17:49 - 2014-05-18 17:49 - 00707056 _____ () C:\Users\ACER\Downloads\CCleaner(13061) (2).exe
2014-05-18 17:48 - 2014-05-18 18:04 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-05-18 17:48 - 2014-05-18 17:48 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-05-18 17:48 - 2014-05-18 17:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-05-18 17:48 - 2014-05-18 17:48 - 00000000 ____D () C:\Program Files\CCleaner
2014-05-18 17:46 - 2014-05-18 17:46 - 04745984 _____ (Piriform Ltd) C:\Users\ACER\Downloads\ccsetup413.exe
2014-05-18 17:45 - 2014-05-18 17:45 - 00707056 _____ () C:\Users\ACER\Downloads\CCleaner(13061) (1).exe
2014-05-18 17:40 - 2014-05-18 17:40 - 00001871 _____ () C:\Users\ACER\Desktop\adw.txt
2014-05-18 17:38 - 2014-05-18 17:39 - 01325827 _____ () C:\Users\ACER\Downloads\AdwCleaner.pl 3.208.exe
2014-05-18 17:27 - 2014-05-18 17:28 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-18 17:27 - 2014-05-18 17:27 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-18 17:27 - 2014-05-18 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-18 17:27 - 2014-05-18 17:27 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-18 17:27 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-18 17:27 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-18 17:27 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-18 17:25 - 2014-05-18 17:25 - 00034165 _____ () C:\Users\ACER\Downloads\FRST (1).txt
2014-05-18 17:24 - 2014-05-18 17:25 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\ACER\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-16 13:42 - 2014-05-16 13:43 - 10971424 _____ (SurfRight B.V.) C:\Users\ACER\Downloads\HitmanPro_x64.exe
2014-05-13 14:16 - 2014-05-13 14:16 - 00000000 ____D () C:\Users\ACER\AppData\Roaming\SFBot
2014-05-13 14:15 - 2014-05-13 14:15 - 00000000 ____D () C:\Users\ACER\Desktop\sfbot
2014-05-13 14:13 - 2014-05-13 14:14 - 08393419 _____ () C:\Users\ACER\Downloads\SFBot_v2.1.0.zip
2014-05-11 09:54 - 2014-05-11 09:54 - 00000000 ____D () C:\Program Files (x86)\MSECache
2014-05-11 09:46 - 2014-05-11 09:49 - 25685128 _____ (Microsoft Corporation) C:\Users\ACER\Downloads\wordview_en-us.exe
2014-05-10 15:58 - 2006-09-13 19:58 - 00724992 ____N (Electronic Arts Inc.) C:\Users\ACER\Desktop\AutoRun.exe
2014-05-10 15:58 - 2006-09-13 19:58 - 00593920 ____N (Electronic Arts Inc.) C:\Users\ACER\Desktop\AutoRunGUI.dll
2014-05-10 15:58 - 2006-09-13 19:58 - 00344064 ____N (Electronic Arts Inc.) C:\Users\ACER\Desktop\eauninstall.exe
2014-05-10 15:58 - 2006-09-13 19:58 - 00024777 ____N () C:\Users\ACER\Desktop\config.dat
2014-05-10 15:58 - 2006-09-13 19:58 - 00003623 ____N () C:\Users\ACER\Desktop\common_filelist.txt
2014-05-10 15:58 - 2006-09-13 16:51 - 00000000 ____D () C:\Users\ACER\Desktop\DirectX
2014-05-10 15:58 - 2006-09-13 16:51 - 00000000 ____D () C:\Users\ACER\Desktop\AutoRun
2014-05-10 15:58 - 2006-09-13 16:50 - 00000080 ____N () C:\Users\ACER\Desktop\ComputerGames.txt
2014-05-10 12:46 - 2014-05-10 17:13 - 00000000 ____D () C:\Users\ACER\Desktop\alocale
2014-05-10 12:46 - 2014-05-10 16:01 - 00000000 ____D () C:\Users\ACER\Documents\FIFA 07 Demo
2014-05-10 12:46 - 2006-09-13 19:58 - 04952064 ____N () C:\Users\ACER\Desktop\fifa07 demo.exe
2014-05-10 12:46 - 2006-09-13 16:51 - 00000000 ____D () C:\Users\ACER\Desktop\data
2014-05-10 12:01 - 2014-05-10 12:45 - 589636571 _____ () C:\Users\ACER\Desktop\fifa07_demo.zip
2014-05-09 21:00 - 2014-05-09 21:00 - 01316991 _____ () C:\Users\ACER\Downloads\AdwCleaner.pl 3.207.exe
2014-05-09 20:42 - 2014-05-09 20:42 - 00000180 _____ () C:\Users\ACER\Downloads\debug.log
2014-05-09 18:30 - 2014-05-09 18:30 - 00000000 ____D () C:\Users\ACER\Documents\FIFA 09 Demo
2014-05-09 18:29 - 2014-05-09 18:29 - 00000000 ____D () C:\Program Files (x86)\EA Sports
2014-05-09 18:26 - 2014-05-09 18:27 - 00000000 ____D () C:\FIFA 09 Demo
2014-05-08 20:15 - 2014-05-08 20:16 - 06212704 _____ (TeamViewer GmbH) C:\Users\ACER\Downloads\TeamViewer_Setup_pl.exe
2014-05-08 14:13 - 2014-05-08 14:13 - 03498400 _____ (TeamViewer GmbH) C:\Users\ACER\Downloads\TeamViewerQS.exe
2014-05-04 12:51 - 2014-05-18 19:57 - 00007018 _____ () C:\Users\ACER\Downloads\FRST.txt
2014-05-04 12:47 - 2014-05-18 17:40 - 00000000 ____D () C:\AdwCleaner
2014-05-04 12:47 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-04 12:46 - 2014-05-04 12:46 - 01310283 _____ () C:\Users\ACER\Downloads\AdwCleaner.exe
2014-05-02 11:00 - 2014-05-02 11:00 - 00000000 ____D () C:\Users\ACER\AppData\Roaming\PC Suite
2014-05-02 11:00 - 2014-05-02 11:00 - 00000000 ____D () C:\Program Files\DIFX
2014-05-02 11:00 - 2014-05-02 11:00 - 00000000 ____D () C:\Program Files (x86)\PC Connectivity Solution
2014-05-02 11:00 - 2014-05-02 11:00 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-05-02 11:00 - 2008-08-28 11:44 - 00025600 _____ (Nokia) C:\Windows\system32\Drivers\pccsmcfdx64.sys
2014-05-02 10:59 - 2014-05-02 10:59 - 00000000 ____D () C:\Users\ACER\AppData\Local\Nokia
2014-05-02 10:57 - 2014-05-02 10:57 - 00000000 ____D () C:\ProgramData\Installations
2014-05-02 10:49 - 2014-05-02 10:57 - 50285192 _____ () C:\Users\ACER\Downloads\NokiaSoftwareUpdaterSetup_PL.exe
2014-05-02 10:49 - 2014-05-02 10:49 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ccdcmbx64_01009.Wdf
2014-05-01 20:30 - 2014-05-01 20:30 - 00000000 ____D () C:\ifx
2014-05-01 20:26 - 2014-05-01 20:26 - 00000000 ____D () C:\LGT375
2014-05-01 20:25 - 2014-05-01 20:25 - 00003126 _____ () C:\Windows\System32\Tasks\{6F61A3CC-22BA-4FD0-84EC-57C65815B2C7}
2014-05-01 20:22 - 2014-05-01 20:33 - 00002411 _____ () C:\Windows\SysWOW64\lgAxconfig.ini
2014-05-01 20:22 - 2011-05-06 10:37 - 00655872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr90.dll
2014-05-01 20:22 - 2011-05-06 10:37 - 00568832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp90.dll
2014-05-01 20:22 - 2011-05-06 10:37 - 00224768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcm90.dll
2014-05-01 20:22 - 2010-03-13 21:15 - 04342088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100.dll
2014-05-01 20:22 - 2010-03-13 21:15 - 00770384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
2014-05-01 20:22 - 2010-03-13 21:15 - 00421200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
2014-05-01 20:22 - 2006-04-30 05:33 - 00053248 _____ () C:\Windows\SysWOW64\CommonDL.dll
2014-05-01 20:22 - 2005-09-29 22:39 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml4a.dll
2014-05-01 20:19 - 2014-05-18 18:08 - 00000000 ____D () C:\ProgramData\LGMOBILEAX
2014-05-01 19:27 - 2014-05-01 20:25 - 00000000 ____D () C:\Program Files (x86)\Samsung
2014-05-01 19:25 - 2014-05-01 19:31 - 75397136 _____ (Samsung Electronics Co., Ltd.) C:\Users\ACER\Downloads\KiesSetup (1).exe
2014-05-01 18:27 - 2014-05-18 19:27 - 00323489 _____ () C:\Windows\WindowsUpdate.log
2014-05-01 18:26 - 2014-05-09 14:51 - 00058016 _____ () C:\Users\ACER\AppData\Local\GDIPFONTCACHEV1.DAT
2014-05-01 18:06 - 2014-05-01 18:06 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-05-01 18:02 - 2014-05-01 18:06 - 34298432 _____ (Ashampoo GmbH & Co. KG ) C:\Users\ACER\Downloads\ashampoo_winoptimizer_11_e11.00.30_sm.exe
2014-05-01 18:00 - 2014-05-01 18:01 - 08509840 _____ (WiseCleaner.com ) C:\Users\ACER\Downloads\WiseCare365.exe
2014-05-01 17:58 - 2014-05-01 17:59 - 04746120 _____ (Piriform Ltd) C:\Users\ACER\Downloads\ccsetup413pro.exe
2014-05-01 17:58 - 2014-05-01 17:58 - 03841551 _____ (FranmoSoftware ) C:\Users\ACER\Downloads\odk13.4.0.1685setup(dobreprogramy.pl).exe
2014-05-01 11:06 - 2014-04-11 10:39 - 00015944 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssduwh.sys
2014-05-01 10:51 - 2014-05-01 11:07 - 00000000 ____D () C:\Users\ACER\Documents\SelfMV
2014-05-01 10:43 - 2014-05-01 10:49 - 41310112 _____ (Samsung Electronics Co., Ltd.) C:\Users\ACER\Downloads\Kies3Setup.exe
2014-05-01 10:30 - 2014-05-18 18:01 - 00000000 ____D () C:\Program Files (x86)\MyFree Codec
2014-05-01 09:31 - 2014-05-01 20:10 - 02416640 _____ () C:\Users\ACER\AppData\Roaming\bflusb.dll
2014-05-01 09:31 - 2014-05-01 20:10 - 02265088 _____ () C:\Users\ACER\AppData\Roaming\bfluart.dll
2014-05-01 09:31 - 2014-05-01 20:10 - 02248704 _____ () C:\Users\ACER\AppData\Roaming\bfldongle.dll
2014-05-01 09:31 - 2014-05-01 20:10 - 02171392 _____ () C:\Users\ACER\AppData\Roaming\bfldb.dll
2014-05-01 09:31 - 2014-05-01 20:10 - 00004366 _____ () C:\Users\ACER\AppData\Roaming\C
2014-05-01 09:27 - 2014-05-01 09:27 - 00000000 ____D () C:\Users\Public\Documents\CrashDump
2014-05-01 09:23 - 2014-05-01 09:23 - 00000000 ____D () C:\Users\Public\Documents\NativeFus_Log
2014-05-01 09:22 - 2014-05-01 20:25 - 00000000 ____D () C:\Users\ACER\AppData\Roaming\Samsung
2014-05-01 09:22 - 2014-05-01 20:25 - 00000000 ____D () C:\Users\ACER\AppData\Local\Samsung
2014-05-01 09:22 - 2014-05-01 09:22 - 00000000 ____D () C:\Users\ACER\Documents\samsung
2014-05-01 09:21 - 2014-01-23 18:23 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll
2014-05-01 09:21 - 2014-01-23 18:23 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\Windows\SysWOW64\secman.dll
2014-05-01 09:20 - 2014-05-01 20:25 - 00000000 ____D () C:\ProgramData\Samsung
2014-05-01 09:13 - 2014-05-01 09:19 - 75397136 _____ (Samsung Electronics Co., Ltd.) C:\Users\ACER\Downloads\KiesSetup.exe
2014-04-30 20:27 - 2014-04-30 20:28 - 04461232 _____ (AVG Technologies) C:\Users\ACER\Downloads\avg_free_stb_all_2014_4336_ppc1.exe
2014-04-26 20:42 - 2014-04-26 20:42 - 04954736 _____ (Microsoft Corporation) C:\Users\ACER\Downloads\WindowsUpgradeAssistant.exe
2014-04-24 11:19 - 2014-04-24 11:34 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-04-23 10:28 - 2014-04-23 10:28 - 00000000 ____D () C:\Program Files (x86)\LG Electronics
2014-04-23 10:25 - 2014-04-23 10:27 - 11412680 _____ (LG Electronics) C:\Users\ACER\Downloads\LGUnitedMobileDriver_S50MAN310AP22_ML_WHQL_Ver_3.10.1.exe
2014-04-23 10:25 - 2014-04-23 10:25 - 00261208 _____ (LG Electronics) C:\Users\ACER\Downloads\B2CAppSetup.exe
2014-04-21 08:03 - 2014-04-21 08:03 - 04787368 _____ (Piriform Ltd) C:\Users\ACER\Downloads\ccsetup412.exe
2014-04-20 18:56 - 2014-04-20 18:56 - 00700824 _____ () C:\Users\ACER\Downloads\CCleaner(13061).exe
2014-04-20 12:02 - 2014-04-20 12:03 - 00000000 ____D () C:\Users\ACER\AppData\Roaming\Dropbox
2014-04-19 19:54 - 2014-04-26 14:12 - 00000000 ____D () C:\OEM
==================== One Month Modified Files and Folders =======
2014-05-18 19:57 - 2014-05-18 18:10 - 00000000 ____D () C:\FRST
2014-05-18 19:57 - 2014-05-04 12:51 - 00007018 _____ () C:\Users\ACER\Downloads\FRST.txt
2014-05-18 19:27 - 2014-05-01 18:27 - 00323489 _____ () C:\Windows\WindowsUpdate.log
2014-05-18 18:11 - 2014-05-18 18:11 - 00021609 _____ () C:\Users\ACER\Downloads\Addition.txt
2014-05-18 18:10 - 2014-05-18 18:10 - 02067456 _____ (Farbar) C:\Users\ACER\Downloads\FRST64.exe
2014-05-18 18:08 - 2014-05-01 20:19 - 00000000 ____D () C:\ProgramData\LGMOBILEAX
2014-05-18 18:04 - 2014-05-18 17:48 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-05-18 18:01 - 2014-05-01 10:30 - 00000000 ____D () C:\Program Files (x86)\MyFree Codec
2014-05-18 17:58 - 2014-02-14 09:08 - 00000000 ____D () C:\Windows\Minidump
2014-05-18 17:58 - 2014-02-13 12:50 - 00000000 ____D () C:\Users\ACER\AppData\Roaming\AIMP3
2014-05-18 17:49 - 2014-05-18 17:49 - 00707056 _____ () C:\Users\ACER\Downloads\CCleaner(13061) (2).exe
2014-05-18 17:48 - 2014-05-18 17:48 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-05-18 17:48 - 2014-05-18 17:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-05-18 17:48 - 2014-05-18 17:48 - 00000000 ____D () C:\Program Files\CCleaner
2014-05-18 17:48 - 2009-07-14 06:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-18 17:48 - 2009-07-14 06:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-18 17:46 - 2014-05-18 17:46 - 04745984 _____ (Piriform Ltd) C:\Users\ACER\Downloads\ccsetup413.exe
2014-05-18 17:45 - 2014-05-18 17:45 - 00707056 _____ () C:\Users\ACER\Downloads\CCleaner(13061) (1).exe
2014-05-18 17:41 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-18 17:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\schemas
2014-05-18 17:40 - 2014-05-18 17:40 - 00001871 _____ () C:\Users\ACER\Desktop\adw.txt
2014-05-18 17:40 - 2014-05-04 12:47 - 00000000 ____D () C:\AdwCleaner
2014-05-18 17:39 - 2014-05-18 17:38 - 01325827 _____ () C:\Users\ACER\Downloads\AdwCleaner.pl 3.208.exe
2014-05-18 17:28 - 2014-05-18 17:27 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-18 17:27 - 2014-05-18 17:27 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-18 17:27 - 2014-05-18 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-18 17:27 - 2014-05-18 17:27 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-18 17:25 - 2014-05-18 17:25 - 00034165 _____ () C:\Users\ACER\Downloads\FRST (1).txt
2014-05-18 17:25 - 2014-05-18 17:24 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\ACER\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-17 15:34 - 2014-02-13 12:17 - 00001413 _____ () C:\Users\ACER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-16 13:43 - 2014-05-16 13:42 - 10971424 _____ (SurfRight B.V.) C:\Users\ACER\Downloads\HitmanPro_x64.exe
2014-05-13 14:25 - 2014-02-16 08:56 - 00000000 ____D () C:\avast! sandbox
2014-05-13 14:25 - 2014-02-13 15:12 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-05-13 14:16 - 2014-05-13 14:16 - 00000000 ____D () C:\Users\ACER\AppData\Roaming\SFBot
2014-05-13 14:15 - 2014-05-13 14:15 - 00000000 ____D () C:\Users\ACER\Desktop\sfbot
2014-05-13 14:14 - 2014-05-13 14:13 - 08393419 _____ () C:\Users\ACER\Downloads\SFBot_v2.1.0.zip
2014-05-11 09:54 - 2014-05-11 09:54 - 00000000 ____D () C:\Program Files (x86)\MSECache
2014-05-11 09:49 - 2014-05-11 09:46 - 25685128 _____ (Microsoft Corporation) C:\Users\ACER\Downloads\wordview_en-us.exe
2014-05-10 17:13 - 2014-05-10 12:46 - 00000000 ____D () C:\Users\ACER\Desktop\alocale
2014-05-10 16:01 - 2014-05-10 12:46 - 00000000 ____D () C:\Users\ACER\Documents\FIFA 07 Demo
2014-05-10 12:45 - 2014-05-10 12:01 - 589636571 _____ () C:\Users\ACER\Desktop\fifa07_demo.zip
2014-05-10 12:42 - 2014-02-13 20:08 - 00000000 ____D () C:\Users\ACER\AppData\Local\Microsoft Games
2014-05-09 21:00 - 2014-05-09 21:00 - 01316991 _____ () C:\Users\ACER\Downloads\AdwCleaner.pl 3.207.exe
2014-05-09 20:53 - 2014-02-13 12:17 - 00000000 ____D () C:\Users\ACER
2014-05-09 20:52 - 2014-02-13 12:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
2014-05-09 20:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-05-09 20:42 - 2014-05-09 20:42 - 00000180 _____ () C:\Users\ACER\Downloads\debug.log
2014-05-09 19:57 - 2009-07-14 20:09 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-05-09 18:30 - 2014-05-09 18:30 - 00000000 ____D () C:\Users\ACER\Documents\FIFA 09 Demo
2014-05-09 18:29 - 2014-05-09 18:29 - 00000000 ____D () C:\Program Files (x86)\EA Sports
2014-05-09 18:27 - 2014-05-09 18:26 - 00000000 ____D () C:\FIFA 09 Demo
2014-05-09 14:51 - 2014-05-01 18:26 - 00058016 _____ () C:\Users\ACER\AppData\Local\GDIPFONTCACHEV1.DAT
2014-05-09 14:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-09 06:41 - 2009-07-14 06:45 - 00276200 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-05-08 20:16 - 2014-05-08 20:15 - 06212704 _____ (TeamViewer GmbH) C:\Users\ACER\Downloads\TeamViewer_Setup_pl.exe
2014-05-08 14:27 - 2014-03-01 17:07 - 00000000 ____D () C:\Users\ACER\.VirtualBox
2014-05-08 14:17 - 2014-02-21 20:41 - 00000000 ____D () C:\Users\ACER\AppData\Roaming\TeamViewer
2014-05-08 14:13 - 2014-05-08 14:13 - 03498400 _____ (TeamViewer GmbH) C:\Users\ACER\Downloads\TeamViewerQS.exe
2014-05-07 16:10 - 2009-07-14 19:55 - 00687828 _____ () C:\Windows\system32\perfh015.dat
2014-05-07 16:10 - 2009-07-14 19:55 - 00131382 _____ () C:\Windows\system32\perfc015.dat
2014-05-07 16:10 - 2009-07-14 07:13 - 01523412 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-04 12:46 - 2014-05-04 12:46 - 01310283 _____ () C:\Users\ACER\Downloads\AdwCleaner.exe
2014-05-02 16:23 - 2014-02-16 10:35 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-02 12:31 - 2014-02-16 10:33 - 00000000 ____D () C:\Users\ACER\AppData\Local\Adobe
2014-05-02 12:30 - 2014-02-16 10:35 - 00003870 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-02 12:30 - 2014-02-13 12:47 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-02 12:30 - 2014-02-13 12:47 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-02 11:00 - 2014-05-02 11:00 - 00000000 ____D () C:\Users\ACER\AppData\Roaming\PC Suite
2014-05-02 11:00 - 2014-05-02 11:00 - 00000000 ____D () C:\Program Files\DIFX
2014-05-02 11:00 - 2014-05-02 11:00 - 00000000 ____D () C:\Program Files (x86)\PC Connectivity Solution
2014-05-02 11:00 - 2014-05-02 11:00 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-05-02 10:59 - 2014-05-02 10:59 - 00000000 ____D () C:\Users\ACER\AppData\Local\Nokia
2014-05-02 10:57 - 2014-05-02 10:57 - 00000000 ____D () C:\ProgramData\Installations
2014-05-02 10:57 - 2014-05-02 10:49 - 50285192 _____ () C:\Users\ACER\Downloads\NokiaSoftwareUpdaterSetup_PL.exe
2014-05-02 10:49 - 2014-05-02 10:49 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ccdcmbx64_01009.Wdf
2014-05-01 20:33 - 2014-05-01 20:22 - 00002411 _____ () C:\Windows\SysWOW64\lgAxconfig.ini
2014-05-01 20:30 - 2014-05-01 20:30 - 00000000 ____D () C:\ifx
2014-05-01 20:26 - 2014-05-01 20:26 - 00000000 ____D () C:\LGT375
2014-05-01 20:25 - 2014-05-01 20:25 - 00003126 _____ () C:\Windows\System32\Tasks\{6F61A3CC-22BA-4FD0-84EC-57C65815B2C7}
2014-05-01 20:25 - 2014-05-01 19:27 - 00000000 ____D () C:\Program Files (x86)\Samsung
2014-05-01 20:25 - 2014-05-01 09:22 - 00000000 ____D () C:\Users\ACER\AppData\Roaming\Samsung
2014-05-01 20:25 - 2014-05-01 09:22 - 00000000 ____D () C:\Users\ACER\AppData\Local\Samsung
2014-05-01 20:25 - 2014-05-01 09:20 - 00000000 ____D () C:\ProgramData\Samsung
2014-05-01 20:25 - 2014-02-13 14:18 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-01 20:10 - 2014-05-01 09:31 - 02416640 _____ () C:\Users\ACER\AppData\Roaming\bflusb.dll
2014-05-01 20:10 - 2014-05-01 09:31 - 02265088 _____ () C:\Users\ACER\AppData\Roaming\bfluart.dll
2014-05-01 20:10 - 2014-05-01 09:31 - 02248704 _____ () C:\Users\ACER\AppData\Roaming\bfldongle.dll
2014-05-01 20:10 - 2014-05-01 09:31 - 02171392 _____ () C:\Users\ACER\AppData\Roaming\bfldb.dll
2014-05-01 20:10 - 2014-05-01 09:31 - 00004366 _____ () C:\Users\ACER\AppData\Roaming\C
2014-05-01 19:31 - 2014-05-01 19:25 - 75397136 _____ (Samsung Electronics Co., Ltd.) C:\Users\ACER\Downloads\KiesSetup (1).exe
2014-05-01 18:25 - 2014-04-13 18:05 - 00001044 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-01 18:25 - 2014-04-13 18:05 - 00001040 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-01 18:11 - 2014-04-13 18:05 - 00004052 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-01 18:11 - 2014-04-13 18:05 - 00003800 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-01 18:11 - 2014-02-13 12:50 - 00000000 ____D () C:\Program Files (x86)\BurnAware Free
2014-05-01 18:10 - 2014-02-13 18:22 - 00000000 ____D () C:\ProgramData\Skype
2014-05-01 18:06 - 2014-05-01 18:06 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-05-01 18:06 - 2014-05-01 18:02 - 34298432 _____ (Ashampoo GmbH & Co. KG ) C:\Users\ACER\Downloads\ashampoo_winoptimizer_11_e11.00.30_sm.exe
2014-05-01 18:01 - 2014-05-01 18:00 - 08509840 _____ (WiseCleaner.com ) C:\Users\ACER\Downloads\WiseCare365.exe
2014-05-01 17:59 - 2014-05-01 17:58 - 04746120 _____ (Piriform Ltd) C:\Users\ACER\Downloads\ccsetup413pro.exe
2014-05-01 17:58 - 2014-05-01 17:58 - 03841551 _____ (FranmoSoftware ) C:\Users\ACER\Downloads\odk13.4.0.1685setup(dobreprogramy.pl).exe
2014-05-01 11:07 - 2014-05-01 10:51 - 00000000 ____D () C:\Users\ACER\Documents\SelfMV
2014-05-01 10:49 - 2014-05-01 10:43 - 41310112 _____ (Samsung Electronics Co., Ltd.) C:\Users\ACER\Downloads\Kies3Setup.exe
2014-05-01 09:27 - 2014-05-01 09:27 - 00000000 ____D () C:\Users\Public\Documents\CrashDump
2014-05-01 09:23 - 2014-05-01 09:23 - 00000000 ____D () C:\Users\Public\Documents\NativeFus_Log
2014-05-01 09:22 - 2014-05-01 09:22 - 00000000 ____D () C:\Users\ACER\Documents\samsung
2014-05-01 09:19 - 2014-05-01 09:13 - 75397136 _____ (Samsung Electronics Co., Ltd.) C:\Users\ACER\Downloads\KiesSetup.exe
2014-05-01 09:19 - 2014-04-04 11:18 - 00000000 ____D () C:\Users\ACER\AppData\Local\Downloaded Installations
2014-04-30 21:19 - 2014-04-13 18:09 - 00002189 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-30 20:28 - 2014-04-30 20:27 - 04461232 _____ (AVG Technologies) C:\Users\ACER\Downloads\avg_free_stb_all_2014_4336_ppc1.exe
2014-04-29 16:31 - 2014-02-13 18:22 - 00000000 ____D () C:\Users\ACER\AppData\Roaming\Skype
2014-04-26 20:42 - 2014-04-26 20:42 - 04954736 _____ (Microsoft Corporation) C:\Users\ACER\Downloads\WindowsUpgradeAssistant.exe
2014-04-26 14:21 - 2014-04-13 18:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-04-26 14:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help
2014-04-26 14:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat
2014-04-26 14:12 - 2014-04-19 19:54 - 00000000 ____D () C:\OEM
2014-04-24 13:35 - 2014-03-31 13:29 - 00000000 ____D () C:\Users\ACER\AppData\Local\AVG
2014-04-24 11:34 - 2014-04-24 11:19 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-04-24 11:19 - 2014-03-06 17:56 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-23 10:28 - 2014-04-23 10:28 - 00000000 ____D () C:\Program Files (x86)\LG Electronics
2014-04-23 10:27 - 2014-04-23 10:25 - 11412680 _____ (LG Electronics) C:\Users\ACER\Downloads\LGUnitedMobileDriver_S50MAN310AP22_ML_WHQL_Ver_3.10.1.exe
2014-04-23 10:25 - 2014-04-23 10:25 - 00261208 _____ (LG Electronics) C:\Users\ACER\Downloads\B2CAppSetup.exe
2014-04-21 08:03 - 2014-04-21 08:03 - 04787368 _____ (Piriform Ltd) C:\Users\ACER\Downloads\ccsetup412.exe
2014-04-20 18:56 - 2014-04-20 18:56 - 00700824 _____ () C:\Users\ACER\Downloads\CCleaner(13061).exe
2014-04-20 12:03 - 2014-04-20 12:02 - 00000000 ____D () C:\Users\ACER\AppData\Roaming\Dropbox
2014-04-19 08:19 - 2009-07-14 07:08 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-04-19 08:19 - 2009-07-14 07:08 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU(39).TXT
2014-04-19 08:19 - 2009-07-14 07:08 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU(322).TXT
Some content of TEMP:
====================
C:\Users\ACER\AppData\Local\Temp\ose00000.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-09 08:33
==================== End Of Log ============================
# AdwCleaner v3.205 - Log utworzony 04/05/2014 o 12:47:07
# Aktualizacja 28/04/2014 przez Xplode
# System operacyjny : Windows 7 Ultimate (64 bits)
# Użytkownik : ACER - 8730G
# Ścieżka : C:\Users\ACER\Downloads\AdwCleaner.exe
# Opcja : Szukaj
***** [ Usługi ] *****
***** [ Pliki / Foldery ] *****
Folder Znaleziono : C:\Program Files (x86)\Common Files\Spigot
Folder Znaleziono : C:\Program Files (x86)\GreenTree Applications
Folder Znaleziono : C:\Program Files (x86)\MyPC Backup
Folder Znaleziono : C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Folder Znaleziono : C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Folder Znaleziono : C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp
Folder Znaleziono : C:\Users\ACER\AppData\Local\Slick Savings
Folder Znaleziono : C:\Users\ACER\AppData\Roaming\Slick Savings
***** [ Skróty ] *****
***** [ Rejestr ] *****
Klucz Znaleziono : HKCU\Software\AppDataLow\Software\Search Settings
Klucz Znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Klucz Znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Klucz Znaleziono : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Klucz Znaleziono : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Klucz Znaleziono : HKLM\SOFTWARE\Classes\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Klucz Znaleziono : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Klucz Znaleziono : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Klucz Znaleziono : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Klucz Znaleziono : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Klucz Znaleziono : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Klucz Znaleziono : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Klucz Znaleziono : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Klucz Znaleziono : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Klucz Znaleziono : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Klucz Znaleziono : HKLM\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Klucz Znaleziono : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Klucz Znaleziono : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}
Klucz Znaleziono : [x64] HKLM\SOFTWARE\Classes\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Klucz Znaleziono : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Klucz Znaleziono : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Klucz Znaleziono : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Klucz Znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Wartość Znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Slick Savings]
Wartość Znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}]
***** [ Przeglądarki internetowe ] *****
-\\ Internet Explorer v9.0.8112.16533
-\\ Google Chrome v35.0.1916.86
[ Plik : C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\preferences ]
# AdwCleaner v3.207 - Log utworzony 09/05/2014 o 21:01:10
# Aktualizacja 05/05/2014 przez Xplode
# System operacyjny : Windows 7 Ultimate (64 bits)
# Użytkownik : ACER - 8730G
# Ścieżka : C:\Users\ACER\Downloads\AdwCleaner.pl 3.207.exe
# Opcja : Szukaj
***** [ Usługi ] *****
Usługa Znaleziono : F06DEFF2-5B9C-490D-910F-35D3A9119622
Usługa Znaleziono : F06DEFF2-5B9C-490D-910F-35D3A91196222
Usługa Znaleziono : SystemkService
***** [ Pliki / Foldery ] *****
Folder Znaleziono : C:\Program Files (x86)\Settings Manager
Folder Znaleziono : C:\ProgramData\systemk
***** [ Skróty ] *****
***** [ Rejestr ] *****
Klucz Znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Klucz Znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Klucz Znaleziono : HKCU\Software\Softonic
Klucz Znaleziono : HKCU\Software\SystemK
Klucz Znaleziono : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Klucz Znaleziono : [x64] HKCU\Software\Softonic
Klucz Znaleziono : [x64] HKCU\Software\SystemK
Klucz Znaleziono : HKLM\SOFTWARE\Classes\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_fifa-06_RASAPI32
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_fifa-06_RASMANCS
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_fifa-09_RASAPI32
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_fifa-09_RASMANCS
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Settings Manager
Klucz Znaleziono : HKLM\Software\SystemK
Klucz Znaleziono : [x64] HKLM\SOFTWARE\Classes\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}
Klucz Znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Klucz Znaleziono : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}
Wartość Znaleziono : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Wartość Znaleziono : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Wartość Znaleziono : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Wartość Znaleziono : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Wartość Znaleziono : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64]
Wartość Znaleziono : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x86]
***** [ Przeglądarki internetowe ] *****
-\\ Internet Explorer v9.0.8112.16533
-\\ Google Chrome v35.0.1916.86
[ Plik : C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Znaleziono [Search Provider] : hxxp://www.softonic.pl/s/{searchTerms}
Znaleziono [Search Provider] : hxxp://www.default-search.net/search?sid=476&aid=175&itype=a&ver=12521&tm=342&src=ds&p={searchTerms}
*************************
AdwCleaner[R1].txt - [4022 octets] - [04/05/2014 12:47:07]
AdwCleaner[R2].txt - [6037 octets] - [09/05/2014 21:01:10]
AdwCleaner[S1].txt - [4010 octets] - [04/05/2014 12:48:26]
########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [6157 octets] ##########
# AdwCleaner v3.208 - Log utworzony 18/05/2014 o 17:39:24
# Aktualizacja 11/05/2014 przez Xplode
# System operacyjny : Windows 7 Ultimate (64 bits)
# Użytkownik : ACER - 8730G
# Ścieżka : C:\Users\ACER\Downloads\AdwCleaner.pl 3.208.exe
# Opcja : Szukaj
***** [ Usługi ] *****
***** [ Pliki / Foldery ] *****
Folder Znaleziono : C:\ProgramData\systemk
***** [ Skróty ] *****
***** [ Rejestr ] *****
Klucz Znaleziono : HKCU\Software\Softonic
Klucz Znaleziono : [x64] HKCU\Software\Softonic
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_fifa-07_RASAPI32
Klucz Znaleziono : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_fifa-07_RASMANCS
Wartość Znaleziono : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Wartość Znaleziono : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Wartość Znaleziono : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Wartość Znaleziono : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Wartość Znaleziono : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64]
Wartość Znaleziono : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x86]
***** [ Przeglądarki internetowe ] *****
-\\ Internet Explorer v9.0.8112.16533
-\\ Google Chrome v35.0.1916.86
[ Plik : C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R1].txt - [4022 octets] - [04/05/2014 12:47:07]
AdwCleaner[R2].txt - [6261 octets] - [09/05/2014 21:01:10]
AdwCleaner[R3].txt - [1607 octets] - [18/05/2014 17:39:24]
AdwCleaner[S1].txt - [4010 octets] - [04/05/2014 12:48:26]
AdwCleaner[S2].txt - [5772 octets] - [09/05/2014 21:01:59]
########## EOF - C:\AdwCleaner\AdwCleaner[R3].txt - [1787 octets] ##########
***** [ Usługi ] *****
***** [ Pliki / Foldery ] *****
Folder Usunięto : C:\Program Files (x86)\GreenTree Applications
Folder Usunięto : C:\Program Files (x86)\MyPC Backup
Folder Usunięto : C:\Program Files (x86)\Common Files\Spigot
Folder Usunięto : C:\Users\ACER\AppData\Local\Slick Savings
Folder Usunięto : C:\Users\ACER\AppData\Roaming\Slick Savings
Folder Usunięto : C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Folder Usunięto : C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Folder Usunięto : C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp
***** [ Skróty ] *****
***** [ Rejestr ] *****
Klucz Usunięto : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Klucz Usunięto : HKLM\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Klucz Usunięto : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Klucz Usunięto : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
Wartość Usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Slick Savings]
Klucz Usunięto : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Klucz Usunięto : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Klucz Usunięto : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Klucz Usunięto : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Klucz Usunięto : HKLM\SOFTWARE\Classes\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Klucz Usunięto : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Klucz Usunięto : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Klucz Usunięto : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Klucz Usunięto : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Klucz Usunięto : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Klucz Usunięto : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Klucz Usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Klucz Usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Klucz Usunięto : [x64] HKLM\SOFTWARE\Classes\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Klucz Usunięto : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Klucz Usunięto : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Klucz Usunięto : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Klucz Usunięto : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Wartość Usunięto : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}]
Klucz Usunięto : HKCU\Software\AppDataLow\Software\Search Settings
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}
***** [ Przeglądarki internetowe ] *****
-\\ Internet Explorer v9.0.8112.16533
-\\ Google Chrome v35.0.1916.86
[ Plik : C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R1].txt - [4022 octets] - [04/05/2014 12:47:07]
AdwCleaner[S1].txt - [3846 octets] - [04/05/2014 12:48:26]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3906 octets] ##########
# AdwCleaner v3.207 - Log utworzony 09/05/2014 o 21:01:59
# Aktualizacja 05/05/2014 przez Xplode
# System operacyjny : Windows 7 Ultimate (64 bits)
# Użytkownik : ACER - 8730G
# Ścieżka : C:\Users\ACER\Downloads\AdwCleaner.pl 3.207.exe
# Opcja : Usuń
***** [ Usługi ] *****
[#] Usługa Usunięto : F06DEFF2-5B9C-490D-910F-35D3A91196222
[#] Usługa Usunięto : SystemkService
***** [ Pliki / Foldery ] *****
[!] Folder Usunięto : C:\ProgramData\systemk
[!] Folder Usunięto : C:\Program Files (x86)\Settings Manager
***** [ Skróty ] *****
***** [ Rejestr ] *****
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Wartość Usunięto : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Wartość Usunięto : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Wartość Usunięto : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Wartość Usunięto : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_fifa-06_RASAPI32
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_fifa-06_RASMANCS
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_fifa-09_RASAPI32
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_fifa-09_RASMANCS
Klucz Usunięto : HKLM\SOFTWARE\Classes\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}
Klucz Usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Klucz Usunięto : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Klucz Usunięto : [x64] HKLM\SOFTWARE\Classes\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}
Klucz Usunięto : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}
Klucz Usunięto : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Klucz Usunięto : HKCU\Software\Softonic
Klucz Usunięto : HKCU\Software\SystemK
Klucz Usunięto : HKLM\Software\SystemK
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Settings Manager
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
***** [ Przeglądarki internetowe ] *****
-\\ Internet Explorer v9.0.8112.16533
-\\ Google Chrome v35.0.1916.86
[ Plik : C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Usunięto [Search Provider] : hxxp://www.softonic.pl/s/{searchTerms}
Usunięto [Search Provider] : hxxp://www.default-search.net/search?sid=476&aid=175&itype=a&ver=12521&tm=342&src=ds&p={searchTerms}
*************************
AdwCleaner[R1].txt - [4022 octets] - [04/05/2014 12:47:07]
AdwCleaner[R2].txt - [6261 octets] - [09/05/2014 21:01:10]
AdwCleaner[S1].txt - [4010 octets] - [04/05/2014 12:48:26]
AdwCleaner[S2].txt - [5620 octets] - [09/05/2014 21:01:59]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [5680 octets] ##########
# AdwCleaner v3.208 - Log utworzony 18/05/2014 o 17:40:28
# Aktualizacja 11/05/2014 przez Xplode
# System operacyjny : Windows 7 Ultimate (64 bits)
# Użytkownik : ACER - 8730G
# Ścieżka : C:\Users\ACER\Downloads\AdwCleaner.pl 3.208.exe
# Opcja : Usuń
***** [ Usługi ] *****
***** [ Pliki / Foldery ] *****
Folder Usunięto : C:\ProgramData\systemk
***** [ Skróty ] *****
***** [ Rejestr ] *****
Wartość Usunięto : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Wartość Usunięto : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Wartość Usunięto : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Wartość Usunięto : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_fifa-07_RASAPI32
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_fifa-07_RASMANCS
Klucz Usunięto : HKCU\Software\Softonic
***** [ Przeglądarki internetowe ] *****
-\\ Internet Explorer v9.0.8112.16533
-\\ Google Chrome v35.0.1916.86
[ Plik : C:\Users\ACER\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Usunięto [Search Provider] : hxxp://www.softonic.pl/s/{searchTerms}
*************************
AdwCleaner[R1].txt - [4022 octets] - [04/05/2014 12:47:07]
AdwCleaner[R2].txt - [6261 octets] - [09/05/2014 21:01:10]
AdwCleaner[R3].txt - [1871 octets] - [18/05/2014 17:39:24]
AdwCleaner[S1].txt - [4010 octets] - [04/05/2014 12:48:26]
AdwCleaner[S2].txt - [5772 octets] - [09/05/2014 21:01:59]
AdwCleaner[S3].txt - [1605 octets] - [18/05/2014 17:40:28]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1665 octets] ##########
alwarebytes Anti-Malware
http://www.malwarebytes.org
Data skanu: 2014-05-19
Czas skanu: 15:15:33
Raport: log.txt
Administrator: Tak
Wersja: 2.00.1.1004
Baza danych malware: v2014.05.19.04
Baza danych rootkitów: v2014.03.27.01
Licencja: Darmowy
Ochrona przeciw malware: Wyłączony
Ochrona przeciw szkodliwymi stronami: Wyłączony
Chameleon: Wyłączony
System operacyjny: Windows 7
Procesor: x64
System plików: NTFS
Użytkownik: ACER
Typ skanu: Skanowanie w poszukiwaniu zagrożeń
Wynik: Zakończono
Objekty zeskanowane: 247378
Minęło: 7 min, 49 s
Pamięć: Włączony
Autostart: Włączony
System plików: Włączony
Archiwa: Włączony
Rootkity: Wyłączony
Shuriken: Włączony
PNP: Włączony
PNM: Włączony
Procesy: 0
(No malicious items detected)
Moduły: 0
(No malicious items detected)
Klucze rejestru: 0
(No malicious items detected)
Wartości rejestru: 0
(No malicious items detected)
Dane rejestru: 0
(No malicious items detected)
Foldery: 0
(No malicious items detected)
Pliki: 0
(No malicious items detected)
Sektory fizyczne: 0
(No malicious items detected)
(end)
Malwarebytes Anti-Malware
http://www.malwarebytes.org
Data skanu: 2014-05-18
Czas skanu: 17:38:28
Raport: log mbm.txt
Administrator: Tak
Wersja: 2.00.1.1004
Baza danych malware: v2014.05.18.04
Baza danych rootkitów: v2014.03.27.01
Licencja: Darmowy
Ochrona przeciw malware: Wyłączony
Ochrona przeciw szkodliwymi stronami: Wyłączony
Chameleon: Wyłączony
System operacyjny: Windows 7
Procesor: x64
System plików: NTFS
Użytkownik: ACER
Typ skanu: Skanowanie w poszukiwaniu zagrożeń
Wynik: Zakończono
Objekty zeskanowane: 247998
Minęło: 9 min, 15 s
Pamięć: Włączony
Autostart: Włączony
System plików: Włączony
Archiwa: Włączony
Rootkity: Wyłączony
Shuriken: Włączony
PNP: Włączony
PNM: Włączony
Procesy: 0
(No malicious items detected)
Moduły: 0
(No malicious items detected)
Klucze rejestru: 1
PUP.Optional.Softonic.A, HKU\S-1-5-21-650615087-400821380-3474875620-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Dodano do kwarantanny, [5d7fa5ada2d950e6c4376f1c17eb639d],
Wartości rejestru: 0
(No malicious items detected)
Dane rejestru: 0
(No malicious items detected)
Foldery: 0
(No malicious items detected)
Pliki: 4
PUP.Optional.AztecMedia.A, C:\Users\ACER\AppData\Local\Temp\nsf9206.tmp\Helper.dll, Dodano do kwarantanny, [ac30f65c86f5999d0cf1410034d0ff01],
PUP.Optional.AztecMedia.A, C:\Users\ACER\AppData\Local\Temp\nsf9206.tmp\Starter.exe, Dodano do kwarantanny, [8f4db59d6a11082eb33b3e03b84cbe42],
PUP.Optional.Softonic.A, C:\Users\ACER\Downloads\SoftonicDownloader_dla_fifa-07.exe, Dodano do kwarantanny, [9d3fc78b0a719d99fac7110e917060a0],
PUP.Optional.Softonic.A, C:\Users\ACER\Downloads\SoftonicDownloader_dla_fifa-09.exe, Dodano do kwarantanny, [8953cd8554273303269bf7287988b34d],
Sektory fizyczne: 0
(No malicious items detected)
(end)
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 14 gości