Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-01-2015 01
- Ran by intel (administrator) on INTEL-PC on 25-01-2015 00:37:54
- Running from C:\Users\intel\Downloads
- Loaded Profiles: intel (Available profiles: intel & ja & Gość)
- Platform: Microsoft Windows Embedded 8.1 Industry Pro (X86) OS Language: Polski (Polska)
- Internet Explorer Version 11 (Default browser: FF)
- Boot Mode: Normal
- Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Processes (Whitelisted) =================
- (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
- (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgrsx.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgcsrvx.exe
- (AMD) C:\Windows\System32\atiesrxx.exe
- (AMD) C:\Windows\System32\atieclxx.exe
- (Stardock Software, Inc) C:\Program Files\Stardock\ModernMix\MMixSrv.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgfws.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgidsagent.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe
- (BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-LogRotatorService.exe
- (BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-UpdaterService.exe
- (Microsoft Corporation) C:\Windows\System32\dasHost.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgnsx.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgemcx.exe
- (A-Volute) C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe
- (SoftEther VPN Project at University of Tsukuba, Japan.) D:\Program Files\SoftEther VPN Client\vpnclient.exe
- (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
- (AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe
- () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\loggingserver.exe
- (Microsoft Corporation) C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_9e0ce1b7e2d9567e\TiWorker.exe
- (Stardock Software, Inc) C:\Program Files\Stardock\ModernMix\MMix_32.exe
- (Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe
- (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
- (Skillbrains) C:\Program Files\Skillbrains\lightshot\5.2.0.17\Lightshot.exe
- (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgui.exe
- (Flux Software LLC) C:\Users\intel\AppData\Local\FluxSoftware\Flux\flux.exe
- (Spotify Ltd) C:\Users\intel\AppData\Roaming\Spotify\spotify.exe
- (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
- () C:\Users\intel\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
- () C:\Users\intel\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
- () C:\Users\intel\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
- () C:\Users\intel\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
- (Mozilla Corporation) D:\Program Files\Mozilla Firefox\firefox.exe
- () C:\Users\intel\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
- () C:\Users\intel\Desktop\gmer.exe
- (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
- () C:\Users\intel\Desktop\gmer.exe
- ==================== Registry (Whitelisted) ==================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- HKLM\...\Run: [] => [X]
- HKLM\...\Run: [Lightshot] => C:\Program Files\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
- HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3667472 2014-12-18] (AVG Technologies CZ, s.r.o.)
- HKU\S-1-5-21-398107741-305064594-4114302982-1000\...\Run: [f.lux] => C:\Users\intel\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
- HKU\S-1-5-21-398107741-305064594-4114302982-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd)
- HKU\S-1-5-21-398107741-305064594-4114302982-1000\...\Run: [Spotify] => C:\Users\intel\AppData\Roaming\Spotify\spotify.exe [6737976 2014-12-05] (Spotify Ltd)
- HKU\S-1-5-21-398107741-305064594-4114302982-1000\...\Run: [uTorrent] => C:\Users\intel\AppData\Roaming\uTorrent\uTorrent.exe [1385808 2014-11-21] (BitTorrent Inc.)
- HKU\S-1-5-21-398107741-305064594-4114302982-1000\...\MountPoints2: {98511db8-3590-11e4-9717-50465da46e73} - "H:\this_war_of_mine_drmfree.exe"
- ==================== Internet (Whitelisted) ====================
- (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
- HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
- HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
- HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
- HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
- HKU\S-1-5-21-398107741-305064594-4114302982-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
- SearchScopes: HKU\S-1-5-21-398107741-305064594-4114302982-1000 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={D1BB726F-B5F7-4352-AD79-63CA89FA7586}&mid=69497f4d731e47d2b499810f1b408780-b9456f5f489cf2b5ab7e9a69594962f9319db14a&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-09-18 19:21:05&v=18.1.9.799&pid=safeguard&sg=&sap=dsp&q={searchTerms}
- SearchScopes: HKU\S-1-5-21-398107741-305064594-4114302982-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={D1BB726F-B5F7-4352-AD79-63CA89FA7586}&mid=69497f4d731e47d2b499810f1b408780-b9456f5f489cf2b5ab7e9a69594962f9319db14a&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-09-18 19:21:05&v=18.1.9.799&pid=safeguard&sg=&sap=dsp&q={searchTerms}
- BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\java\bin\ssv.dll (Oracle Corporation)
- BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\java\bin\jp2ssv.dll (Oracle Corporation)
- Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search)
- Tcpip\Parameters: [DhcpNameServer] 192.168.1.20
- Tcpip\..\Interfaces\{17A2A7FF-0990-42D8-926C-A287E008D152}: [NameServer] 31.31.78.39,78.47.34.12
- FireFox:
- ========
- FF ProfilePath: C:\Users\intel\AppData\Roaming\Mozilla\Firefox\Profiles\kpcl5v61.default-1420746925245
- FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_287.dll ()
- FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll No File
- FF Plugin: @java.com/DTPlugin,version=11.25.2 -> D:\java\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
- FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> D:\java\bin\plugin2\npjp2.dll (Oracle Corporation)
- FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
- FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
- FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
- FF Plugin: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
- FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
- FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
- FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
- FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
- FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
- FF Plugin HKU\S-1-5-21-398107741-305064594-4114302982-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
- FF Extension: Magic Actions for YouTube™ - C:\Users\intel\AppData\Roaming\Mozilla\Firefox\Profiles\kpcl5v61.default-1420746925245\Extensions\[email protected] [2015-01-19]
- FF Extension: Reddit Enhancement Suite - C:\Users\intel\AppData\Roaming\Mozilla\Firefox\Profiles\kpcl5v61.default-1420746925245\Extensions\[email protected] [2015-01-18]
- FF Extension: Enhanced Steam - C:\Users\intel\AppData\Roaming\Mozilla\Firefox\Profiles\kpcl5v61.default-1420746925245\Extensions\[email protected] [2015-01-18]
- FF Extension: μ Adblock - C:\Users\intel\AppData\Roaming\Mozilla\Firefox\Profiles\kpcl5v61.default-1420746925245\Extensions\[email protected] [2015-01-20]
- FF Extension: Adblock Plus - C:\Users\intel\AppData\Roaming\Mozilla\Firefox\Profiles\kpcl5v61.default-1420746925245\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-16]
- FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Fiddler2\FiddlerHook
- FF Extension: FiddlerHook - C:\Program Files\Fiddler2\FiddlerHook [2014-09-10]
- FF HKU\S-1-5-21-398107741-305064594-4114302982-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
- FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
- StartMenuInternet: FIREFOX.EXE - C:\Program Files\Nightly\firefox.exe
- Chrome:
- =======
- CHR HomePage: Default -> hxxp://www.google.com/
- CHR StartupUrls: Default -> "hxxp://www.google.com/", "hxxp://websearch.simplesearches.info/?pid=298&r=2013/08/14&hid=3316920267&lg=EN&cc=PL&unqvl=31", "hxxp://www.google.com", "https://mysearch.avg.com?cid={D1BB726F-B5F7-4352-AD79-63CA89FA7586}&mid=69497f4d731e47d2b499810f1b408780-b9456f5f489cf2b5ab7e9a69594962f9319db14a&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-09-18 19:21:05&v=18.1.9.799&pid=safeguard&sg=&sap=hp"
- CHR Profile: C:\Users\intel\AppData\Local\Google\Chrome\User Data\Default
- CHR Extension: (LoungeDestroyer) - C:\Users\intel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2015-01-22]
- CHR Extension: (Google Wallet) - C:\Users\intel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-15]
- CHR HKLM\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - No Path
- ========================== Services (Whitelisted) =================
- (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
- R2 avgfws; C:\Program Files\AVG\AVG2015\avgfws.exe [1486664 2014-12-18] (AVG Technologies CZ, s.r.o.)
- R2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3432976 2014-12-18] (AVG Technologies CZ, s.r.o.)
- R2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [298080 2014-12-18] (AVG Technologies CZ, s.r.o.)
- S2 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [409304 2014-09-16] (BlueStack Systems, Inc.)
- R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [384728 2014-09-16] (BlueStack Systems, Inc.)
- R2 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [777944 2014-09-16] (BlueStack Systems, Inc.)
- S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2014-09-06] (Microsoft Corporation)
- S3 fussvc; C:\Program Files\Windows Kits\8.1\App Certification Kit\fussvc.exe [140800 2013-08-21] (Microsoft Corporation) [File not signed]
- U2 HPSLPSVC; C:\Users\intel\AppData\Local\Temp\7zS1A0F\hpslpsvc32.dll [701288 2013-07-19] (Hewlett-Packard Co.)
- R2 ModernMix; C:\Program Files\Stardock\ModernMix\MMixSrv.exe [74864 2013-02-28] (Stardock Software, Inc)
- S4 OkayFreedom VPN Starter Service; C:\Program Files\OkayFreedom\OkayFreedomService.exe [324024 2014-12-12] (Steganos Software GmbH)
- S4 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [66872 2014-12-03] ()
- S4 PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [103736 2014-12-03] ()
- S2 Razer Game Scanner Service; C:\Program Files\Razer\Razer Services\GSS\GameScannerService.exe [186048 2014-12-09] ()
- R2 RzMaelstromVADStreamingService; C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe [3672576 2014-06-09] (A-Volute) [File not signed]
- S3 ScDeviceEnum; C:\WINDOWS\System32\ScDeviceEnum.dll [105472 2013-08-22] (Microsoft Corporation)
- R2 SEVPNCLIENT; d:\Program Files\SoftEther VPN Client\vpnclient.exe [3544632 2014-09-19] (SoftEther VPN Project at University of Tsukuba, Japan.)
- S3 Te.Service; C:\Program Files\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [91136 2013-08-21] (Microsoft Corporation) [File not signed]
- S3 VsEtwService120; D:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [71344 2013-10-05] (Microsoft Corporation)
- R2 vToolbarUpdater18.1.9; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-09-18] (AVG Secure Search)
- S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [288128 2014-09-22] (Microsoft Corporation)
- S3 WEPHOSTSVC; C:\WINDOWS\system32\wephostsvc.dll [20992 2013-08-22] (Microsoft Corporation)
- S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22192 2014-09-22] (Microsoft Corporation)
- S3 workfolderssvc; C:\WINDOWS\system32\workfolderssvc.dll [1222144 2014-07-24] (Microsoft Corporation)
- S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]
- ==================== Drivers (Whitelisted) ====================
- (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
- S0 Avgbootx; C:\WINDOWS\System32\DRIVERS\avgbootx.sys [17424 2013-09-04] (AVG Technologies CZ, s.r.o.)
- R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [121624 2014-06-18] (AVG Technologies CZ, s.r.o.)
- R1 Avgfwfd; C:\WINDOWS\system32\DRIVERS\avgfwd6x.sys [47928 2013-09-26] (AVG Technologies CZ, s.r.o.)
- R1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdriverx.sys [208152 2014-12-08] (AVG Technologies CZ, s.r.o.)
- R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [154904 2014-11-18] (AVG Technologies CZ, s.r.o.)
- R1 AVGIDSShim; C:\WINDOWS\system32\DRIVERS\avgidsshimw8x.sys [21272 2014-06-18] (AVG Technologies CZ, s.r.o.)
- R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [192792 2014-08-28] (AVG Technologies CZ, s.r.o.)
- R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [230680 2014-07-18] (AVG Technologies CZ, s.r.o.)
- R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [98584 2014-10-05] (AVG Technologies CZ, s.r.o.)
- R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [27416 2014-06-18] (AVG Technologies CZ, s.r.o.)
- R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [42784 2014-09-18] (AVG Technologies)
- R1 Avgwfpx; C:\WINDOWS\system32\DRIVERS\avgwfpx.sys [207128 2014-09-24] (AVG Technologies CZ, s.r.o.)
- R1 BasicRender; C:\WINDOWS\System32\drivers\BasicRender.sys [25600 2014-03-18] (Microsoft Corporation)
- R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [112344 2014-09-16] (BlueStack Systems)
- S3 CEDRIVER60; C:\Program Files\Cheat Engine 6.4\dbk32.sys [82880 2014-06-20] ()
- R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [243128 2014-09-06] (Disc Soft Ltd)
- R3 EuMusDesignVirtualAudioCableWdm; C:\WINDOWS\system32\DRIVERS\vrtaucbl.sys [42496 2009-05-15] (Eugene V. Muzychenko) [File not signed]
- S3 GPIO; C:\WINDOWS\System32\drivers\iaiogpio.sys [22016 2013-07-23] (Intel Corporation)
- R3 hidusbf; C:\WINDOWS\system32\DRIVERS\hidusbf.sys [5536 2014-10-19] (SweetLow)
- R3 MEI; C:\WINDOWS\System32\drivers\HECI.sys [41088 2010-10-19] (Intel Corporation)
- R3 Neo_VPN; C:\WINDOWS\system32\DRIVERS\Neo_VPN.sys [26208 2014-09-19] (SoftEther VPN Project at University of Tsukuba, Japan.)
- R2 NPF; C:\WINDOWS\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
- S3 pwdrvio; C:\WINDOWS\system32\pwdrvio.sys [15688 2013-09-30] ()
- S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [10320 2013-09-30] ()
- R3 RZMAELSTROMVADService; C:\WINDOWS\system32\drivers\RzMaelstromVAD.sys [25088 2014-06-09] (Windows (R) Win 7 DDK provider)
- R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [20416 2014-12-09] (Razer, Inc.)
- R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [97088 2014-12-10] (Razer, Inc.)
- R1 SeLow; C:\WINDOWS\system32\DRIVERS\SeLow_x86.sys [30816 2014-09-19] (SoftEther VPN Project at University of Tsukuba, Japan.)
- R3 SensorsSimulatorDriver; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [188416 2014-05-31] (Microsoft Corporation)
- R3 tap0901; C:\WINDOWS\system32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
- R3 VCSVADHWSer; C:\WINDOWS\system32\DRIVERS\vcsvad.sys [17792 2008-12-26] (Avnex)
- S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [84800 2014-09-22] (Microsoft Corporation)
- R0 Wof; C:\WINDOWS\system32\Drivers\Wof.sys [138584 2014-03-13] (Microsoft Corporation)
- R3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [188416 2014-05-31] (Microsoft Corporation)
- R3 pglcrpow; C:\pglcrpow.sys [104960 2015-01-25] (GMER) [File not signed]
- S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [X]
- U5 SEE; C:\Windows\System32\Drivers\SEE.sys [43104 2014-09-19] (SoftEther VPN Project at University of Tsukuba, Japan.)
- ==================== NetSvcs (Whitelisted) ===================
- (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
- ==================== One Month Created Files and Folders ========
- (If an entry is included in the fixlist, the file\folder will be moved.)
- 2015-01-25 00:37 - 2015-01-25 00:37 - 00104960 _____ (GMER) C:\pglcrpow.sys
- 2015-01-25 00:37 - 2015-01-25 00:37 - 00000000 ____D () C:\Users\intel\Downloads\FRST-OlderVersion
- 2015-01-25 00:34 - 2015-01-25 00:34 - 00149840 _____ () C:\WINDOWS\Minidump\012515-110140-01.dmp
- 2015-01-25 00:29 - 2015-01-25 00:37 - 00018093 _____ () C:\Users\intel\Downloads\FRST.txt
- 2015-01-25 00:28 - 2015-01-25 00:37 - 01120768 _____ (Farbar) C:\Users\intel\Downloads\FRST.exe
- 2015-01-25 00:28 - 2015-01-25 00:37 - 00000000 ____D () C:\FRST
- 2015-01-25 00:28 - 2015-01-25 00:28 - 00370943 _____ () C:\Users\intel\Downloads\gmer.zip
- 2015-01-25 00:24 - 2015-01-25 00:24 - 00121623 _____ () C:\Users\intel\Downloads\Silent Runners(1).zip
- 2015-01-25 00:21 - 2015-01-25 00:21 - 00121623 _____ () C:\Users\intel\Downloads\Silent Runners.zip
- 2015-01-25 00:20 - 2015-01-25 00:21 - 00000000 ____D () C:\Users\intel\Downloads\backups
- 2015-01-25 00:18 - 2015-01-25 00:24 - 00006349 _____ () C:\Users\intel\Downloads\hijackthis.log
- 2015-01-25 00:18 - 2015-01-25 00:18 - 00388608 _____ (Trend Micro Inc.) C:\Users\intel\Downloads\HijackThis_www.INSTALKI.pl.exe
- 2015-01-25 00:07 - 2015-01-25 00:07 - 00000979 _____ () C:\Users\Public\Desktop\NetWhistler.lnk
- 2015-01-25 00:07 - 2015-01-25 00:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetWhistler
- 2015-01-25 00:07 - 2015-01-25 00:07 - 00000000 ____D () C:\Program Files\NetWhistler
- 2015-01-25 00:05 - 2015-01-25 00:05 - 01333678 _____ () C:\Users\intel\Downloads\nw101win32.zip
- 2015-01-25 00:00 - 2015-01-25 00:00 - 00372552 _____ () C:\Users\intel\Downloads\SoftonicDownloader_for_namebench.exe
- 2015-01-24 23:58 - 2015-01-24 23:58 - 00013874 _____ () C:\Users\intel\Downloads\namebench_downloader-Q5k8Mp1dU.exe
- 2015-01-24 13:54 - 2015-01-25 00:33 - 00000696 _____ () C:\WINDOWS\setupact.log
- 2015-01-24 13:54 - 2015-01-24 13:54 - 00000000 _____ () C:\WINDOWS\setuperr.log
- 2015-01-24 10:38 - 2015-01-24 10:38 - 01672294 _____ () C:\Users\ja\Downloads\rzeka-norwegia-gory.jpeg
- 2015-01-23 23:23 - 2015-01-23 23:23 - 00000000 ____D () C:\Users\intel\Downloads\rufus_files
- 2015-01-23 23:22 - 2015-01-23 23:22 - 01370230 _____ () C:\Users\intel\Desktop\BOOTX64.efi
- 2015-01-23 23:21 - 2015-01-23 23:21 - 00826246 _____ () C:\Users\intel\Desktop\grubx64.efi
- 2015-01-23 23:20 - 2015-01-23 23:51 - 00000408 __RSH () C:\ProgramData\ntuser.pol
- 2015-01-23 23:19 - 2015-01-23 23:19 - 00640424 _____ (Akeo Consulting (http://akeo.ie)) C:\Users\intel\Downloads\rufus-1.4.12.exe
- 2015-01-22 19:56 - 2015-01-22 19:56 - 00029000 _____ () C:\Users\intel\Documents\cc_20150122_195648.reg
- 2015-01-22 19:43 - 2015-01-22 19:43 - 00001013 _____ () C:\Users\Public\Desktop\CCleaner.lnk
- 2015-01-22 19:42 - 2015-01-22 19:42 - 05317104 _____ (Piriform Ltd) C:\Users\intel\Downloads\ccsetup501.exe
- 2015-01-20 22:20 - 2015-01-20 22:20 - 00214242 _____ () C:\Users\intel\Downloads\SweetFX-Configurator_standalone_with_SweetFX_1.5.1.7z
- 2015-01-20 22:20 - 2013-10-01 01:55 - 00000000 ____D () C:\Users\intel\Desktop\SweetFX Configurator
- 2015-01-20 22:16 - 2015-01-20 22:16 - 00268163 _____ () C:\Users\intel\Downloads\SaturationTogglerv1.2.zip
- 2015-01-20 22:15 - 2015-01-20 22:23 - 22126232 _____ (Razer Inc. ) C:\Users\intel\Downloads\RazerCortexSetup_5.2.22.0.exe
- 2015-01-20 21:59 - 2015-01-20 22:11 - 00000000 ____D () C:\Users\intel\Downloads\The Official UK TOP 40 Singles Chart (11 Jan 2015) ~AryaN_L33T~[GloDLS]
- 2015-01-20 21:58 - 2015-01-20 21:59 - 00000000 ____D () C:\Users\intel\Downloads\Joey Bada$$ - B4.DA.$$ (Explicit Version) [2015] {CBR MP3 - 320 kbps}
- 2015-01-20 21:10 - 2015-01-20 21:10 - 00000692 _____ () C:\Users\intel\Downloads\CHScript.zip
- 2015-01-20 15:58 - 2015-01-20 15:58 - 00002747 _____ () C:\Users\intel\Desktop\autoexec.cfg
- 2015-01-19 20:57 - 2015-01-24 18:54 - 00000000 ____D () C:\Users\ja\Desktop\PREZENTACJA
- 2015-01-19 20:09 - 2015-01-19 20:09 - 00000875 _____ () C:\Users\ja\Desktop\Pobrane — skrót.lnk
- 2015-01-19 16:02 - 2015-01-19 16:02 - 00003759 _____ () C:\Users\intel\Downloads\VMScript_by_TrilluXe.zip
- 2015-01-17 21:11 - 2015-01-17 21:11 - 01188194 _____ () C:\Users\intel\Downloads\ProcessExplorer.zip
- 2015-01-17 20:54 - 2015-01-17 20:54 - 00007633 _____ () C:\Users\intel\AppData\Local\Resmon.ResmonCfg
- 2015-01-16 23:19 - 2015-01-16 23:19 - 01725304 _____ (Razer Inc.) C:\Users\intel\Downloads\RazerSurroundInstaller_v2.00.10.exe
- 2015-01-16 23:13 - 2014-12-10 21:43 - 00097088 _____ (Razer, Inc.) C:\WINDOWS\system32\Drivers\rzpnk.sys
- 2015-01-16 23:12 - 2014-12-09 23:21 - 00020416 _____ (Razer, Inc.) C:\WINDOWS\system32\Drivers\rzpmgrk.sys
- 2015-01-16 15:29 - 2015-01-16 15:29 - 00180227 _____ () C:\Users\intel\Downloads\deception1.zip
- 2015-01-13 20:10 - 2014-12-19 06:46 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
- 2015-01-13 20:10 - 2014-12-12 02:34 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
- 2015-01-13 20:10 - 2014-12-12 01:46 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
- 2015-01-13 20:10 - 2014-12-09 04:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
- 2015-01-13 20:10 - 2014-12-08 20:46 - 00485544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
- 2015-01-13 20:10 - 2014-12-08 20:46 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
- 2015-01-13 20:10 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
- 2015-01-13 20:10 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
- 2015-01-13 20:10 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
- 2015-01-13 20:10 - 2014-12-06 03:36 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
- 2015-01-13 20:10 - 2014-12-06 02:28 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
- 2015-01-13 20:10 - 2014-12-06 02:23 - 00194048 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
- 2015-01-13 20:10 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
- 2015-01-13 20:10 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
- 2015-01-13 20:10 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
- 2015-01-13 20:10 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
- 2015-01-13 20:10 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
- 2015-01-13 20:10 - 2014-10-29 04:07 - 00213336 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
- 2015-01-13 20:10 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
- 2015-01-13 20:10 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
- 2015-01-13 20:10 - 2014-10-29 01:49 - 00694272 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
- 2015-01-08 20:55 - 2015-01-08 20:55 - 00000000 ____D () C:\Users\intel\Desktop\Stare dane programu Firefox
- 2015-01-08 17:13 - 2015-01-08 17:13 - 00200589 _____ () C:\Users\ja\Downloads\Kopia+20141230+Próbny+sprawdzian+Analiza+Część+1+p_(1).xlsx
- 2015-01-08 17:09 - 2015-01-08 17:09 - 00200589 _____ () C:\Users\ja\Downloads\Kopia+20141230+Próbny+sprawdzian+Analiza+Część+1+p (3).xlsx
- 2015-01-08 17:09 - 2015-01-08 17:09 - 00200589 _____ () C:\Users\ja\Downloads\Kopia+20141230+Próbny+sprawdzian+Analiza+Część+1+p (2).xlsx
- 2015-01-08 17:08 - 2015-01-08 17:08 - 00169168 _____ () C:\Users\ja\Downloads\PROBNY_SPRAWDZIAN_final (2).xlsx
- 2015-01-08 17:05 - 2015-01-08 17:05 - 00169168 _____ () C:\Users\ja\Downloads\PROBNY_SPRAWDZIAN_final (1).xlsx
- 2015-01-08 17:00 - 2015-01-08 17:00 - 00200589 _____ () C:\Users\ja\Downloads\Kopia+20141230+Próbny+sprawdzian+Analiza+Część+1+p (1).xlsx
- 2015-01-08 16:59 - 2015-01-08 16:59 - 00200589 _____ () C:\Users\ja\Downloads\Kopia+20141230+Próbny+sprawdzian+Analiza+Część+1+p.xlsx
- 2015-01-08 14:31 - 2015-01-08 14:31 - 00000199 _____ () C:\Users\intel\Desktop\Counter-Strike Global Offensive.url
- 2015-01-06 11:54 - 2015-01-06 11:54 - 06093781 _____ () C:\Users\intel\Desktop\Desktop.rar
- 2015-01-05 14:21 - 2015-01-05 14:21 - 00004296 _____ () C:\Users\intel\Downloads\irish Pro Config.rar
- 2015-01-05 14:21 - 2014-12-16 20:35 - 00000000 ____D () C:\Users\intel\Desktop\.irish Pro Config
- 2015-01-05 10:06 - 2015-01-05 10:06 - 00000000 ____D () C:\Users\intel\AppData\Local\CrashRpt
- 2015-01-05 08:49 - 2015-01-05 08:49 - 00000202 _____ () C:\Users\intel\Desktop\The Way of Life.url
- 2015-01-04 21:25 - 2015-01-04 21:25 - 00001255 _____ () C:\Users\Public\Desktop\MiniTool Partition Wizard Home Edition.lnk
- 2015-01-04 21:25 - 2015-01-04 21:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard Home Edition 8.1.1
- 2015-01-04 21:25 - 2015-01-04 21:25 - 00000000 ____D () C:\Program Files\MiniTool Partition Wizard Home Edition 8.1.1
- 2015-01-04 21:25 - 2013-09-30 16:26 - 02881848 _____ () C:\WINDOWS\system32\pwNative.exe
- 2015-01-04 21:25 - 2013-09-30 16:26 - 00015688 ____N () C:\WINDOWS\system32\pwdrvio.sys
- 2015-01-04 21:25 - 2013-09-30 16:26 - 00010320 ____N () C:\WINDOWS\system32\pwdspio.sys
- 2015-01-04 21:23 - 2015-01-04 21:24 - 20772800 _____ (MiniTool Solution Ltd. ) C:\Users\ja\Downloads\pwhe8.exe
- 2015-01-04 18:04 - 2015-01-04 20:08 - 1034944512 _____ () C:\Users\intel\Downloads\ubuntu-14.04.1-desktop-i386.iso
- 2015-01-04 18:02 - 2015-01-04 18:02 - 01088893 _____ (pendrivelinux.com) C:\Users\intel\Downloads\Universal-USB-Installer-1.9.5.8.exe
- 2015-01-04 17:54 - 2015-01-10 16:43 - 00000000 ____D () C:\Users\intel\AppData\Local\wf-launcher
- 2015-01-04 17:54 - 2015-01-10 16:43 - 00000000 ____D () C:\ProgramData\GFACE
- 2015-01-04 17:54 - 2015-01-04 17:59 - 31722776 _____ (EaseUS ) C:\Users\intel\Downloads\epm_trial.exe
- 2015-01-04 17:43 - 2015-01-04 17:44 - 06142086 _____ (LinuxLive USB Creator) C:\Users\intel\Downloads\LinuxLive USB Creator 2.9.1.exe
- 2015-01-04 13:49 - 2015-01-04 13:49 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
- 2015-01-03 21:36 - 2015-01-03 21:36 - 00143642 _____ () C:\Users\intel\Downloads\flll11Crackbycf.zip
- 2015-01-03 21:29 - 2015-01-13 17:44 - 00000000 ____D () C:\Users\intel\Desktop\steamParser
- 2015-01-03 10:29 - 2015-01-03 10:29 - 00000202 _____ () C:\Users\intel\Desktop\Warface.url
- 2015-01-02 15:19 - 2015-01-02 15:19 - 00001208 _____ () C:\Users\ja\Desktop\Photoshop — skrót.lnk
- 2015-01-02 15:18 - 2015-01-02 15:18 - 00000000 ____D () C:\Users\ja\AppData\Roaming\TrueCrypt
- 2015-01-02 15:06 - 2015-01-02 15:06 - 00060477 _____ () C:\Users\intel\Downloads\The_Interview_2014.The.Interview.2014.1080p.WEB-DL.AAC2.0.H264-RARBG.en(1).zip
- 2015-01-02 14:48 - 2015-01-02 14:48 - 00106968 _____ () C:\Users\intel\Desktop\wywiadzesloncem2.txt
- 2015-01-02 14:27 - 2015-01-02 14:28 - 09989013 _____ ( ) C:\Users\intel\Downloads\NapiProjektBuild_2.2.0.2399(dobreprogramy.pl).exe
- 2015-01-02 13:23 - 2015-01-02 13:26 - 00000000 ____D () C:\Users\intel\Downloads\gcf1
- 2015-01-02 13:23 - 2015-01-02 13:25 - 00000000 ____D () C:\Users\intel\Downloads\gcf2
- 2015-01-02 13:21 - 2015-01-02 13:21 - 00000000 ____D () C:\Users\intel\Downloads\CS_2k9
- 2015-01-02 11:23 - 2015-01-02 12:01 - 180840695 _____ () C:\Users\intel\Downloads\gcf1.rar
- 2015-01-02 11:23 - 2015-01-02 11:59 - 157371663 _____ () C:\Users\intel\Downloads\CS_2k9.part2.rar
- 2015-01-02 11:23 - 2015-01-02 11:54 - 140000743 _____ () C:\Users\intel\Downloads\gcf2.rar
- 2015-01-02 11:22 - 2015-01-02 11:58 - 178257920 _____ () C:\Users\intel\Downloads\CS_2k9.part1.rar
- 2015-01-02 11:16 - 2015-01-02 11:16 - 00020144 _____ () C:\Users\intel\Downloads\advvac3pr00f.rar
- 2015-01-02 11:16 - 2013-08-29 09:28 - 00000000 ____D () C:\Users\intel\Desktop\1337
- 2015-01-02 10:53 - 2015-01-02 10:53 - 00000000 ____D () C:\Users\intel\Desktop\cgminer-3.7.2-windows
- 2015-01-02 10:35 - 2015-01-02 10:37 - 03278409 _____ () C:\Users\intel\Downloads\cgminer-3.7.2-windows.zip
- 2015-01-02 10:30 - 2015-01-02 10:30 - 00000000 ____D () C:\Users\intel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dogecoin Core
- 2015-01-02 10:30 - 2015-01-02 10:30 - 00000000 ____D () C:\Program Files\Dogecoin
- 2015-01-02 10:22 - 2015-01-02 10:30 - 12505854 _____ (Dogecoin project) C:\Users\intel\Downloads\dogecoin-1.8.1-win32-setup.exe
- 2015-01-01 21:04 - 2015-01-01 21:04 - 00060477 _____ () C:\Users\intel\Downloads\The_Interview_2014.The.Interview.2014.1080p.WEB-DL.AAC2.0.H264-RARBG.en.zip
- 2015-01-01 19:12 - 2015-01-01 19:12 - 00000775 _____ () C:\Users\intel\Desktop\ASIO4ALL v2 Instruction Manual.lnk
- 2015-01-01 19:12 - 2015-01-01 19:12 - 00000000 ____D () C:\Users\intel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
- 2015-01-01 19:05 - 2015-01-01 19:05 - 00000913 _____ () C:\Users\intel\Desktop\FL Studio 11.lnk
- 2015-01-01 19:05 - 2015-01-01 19:05 - 00000000 ____D () C:\Users\intel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
- 2015-01-01 19:05 - 2015-01-01 19:05 - 00000000 ____D () C:\Program Files\DSPRobotics
- 2015-01-01 19:05 - 2015-01-01 19:05 - 00000000 ____D () C:\Program Files\Common Files\Propellerhead Software
- 2015-01-01 19:01 - 2015-01-01 19:05 - 00000000 ____D () C:\Program Files\Image-Line
- 2015-01-01 19:00 - 2015-01-01 19:01 - 00000000 ____D () C:\Users\intel\Desktop\Image-Line.FL.Studio.Producer.Edition.v11.1.1.Incl.Keygen-R2R
- 2015-01-01 18:00 - 2015-01-06 11:54 - 00000000 ____D () C:\Users\intel\Desktop\TheMatematykaning
- 2015-01-01 18:00 - 2014-12-17 16:20 - 00000000 ____D () C:\Users\intel\Desktop\Arkusz VIII
- 2015-01-01 18:00 - 2014-12-17 16:19 - 00000000 ____D () C:\Users\intel\Desktop\Arkusz I
- 2015-01-01 17:57 - 2015-01-01 18:41 - 370392521 _____ () C:\Users\intel\Downloads\fl-studio-producer-edition-11.1.1.rar
- 2015-01-01 17:57 - 2015-01-01 17:59 - 06097669 _____ () C:\Users\intel\Downloads\OneDrive-2015-01-01.zip
- 2015-01-01 09:44 - 2015-01-01 09:44 - 00000000 ____D () C:\Users\Guest.intel-PC\Documents\Lightshot
- 2014-12-31 12:41 - 2014-12-31 12:41 - 00558136 _____ () C:\Users\intel\Downloads\cshacked.pl External Software.rar
- 2014-12-31 12:41 - 2014-08-24 20:36 - 00000000 ____D () C:\Users\intel\Desktop\External Software
- 2014-12-30 13:47 - 2015-01-19 16:52 - 00000000 ____D () C:\Users\Guest.intel-PC\AppData\Roaming\Steganos VPN
- 2014-12-30 13:47 - 2015-01-01 08:02 - 00000000 ____D () C:\Users\Guest.intel-PC\AppData\Roaming\Steganos
- 2014-12-29 21:06 - 2014-12-29 21:06 - 00000000 ____D () C:\ProgramData\TEMP
- 2014-12-29 21:06 - 2014-12-29 21:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Repair PSD
- 2014-12-29 21:04 - 2014-12-29 21:05 - 08765112 _____ ( ) C:\Users\intel\Downloads\repairphotoshop-psd.exe
- 2014-12-29 20:19 - 2014-12-29 20:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
- 2014-12-29 20:19 - 2014-12-29 20:19 - 00000000 ____D () C:\Program Files\Recuva
- 2014-12-29 20:18 - 2014-12-29 20:19 - 04210920 _____ (Piriform Ltd) C:\Users\intel\Downloads\rcsetup151.exe
- 2014-12-29 17:22 - 2014-12-29 17:22 - 00000494 _____ () C:\Users\intel\Desktop\Dysk lokalny (G).lnk
- 2014-12-29 17:21 - 2014-12-29 17:21 - 00001100 _____ () C:\Users\intel\Desktop\hl — skrót.lnk
- 2014-12-29 15:39 - 2014-12-29 16:15 - 00000000 ____D () C:\Users\intel\AppData\Roaming\TS3Client
- 2014-12-29 15:38 - 2014-12-29 15:38 - 00000851 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
- 2014-12-29 15:38 - 2014-12-29 15:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
- 2014-12-29 13:19 - 2014-12-29 13:19 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive
- 2014-12-29 13:15 - 2014-12-29 13:15 - 00000000 ____D () C:\Users\intel\AppData\Local\Windows Live
- 2014-12-29 13:15 - 2014-12-29 13:15 - 00000000 ____D () C:\Program Files\Common Files\Windows Live
- 2014-12-27 09:09 - 2015-01-24 15:47 - 00000000 ____D () C:\Users\ja\AppData\Roaming\Steganos VPN
- 2014-12-27 09:09 - 2014-12-28 13:29 - 00000000 ____D () C:\Users\ja\AppData\Roaming\Steganos
- 2014-12-26 18:45 - 2014-12-29 12:36 - 00000000 ____D () C:\Users\intel\Desktop\micspamsounds
- 2014-12-26 13:06 - 2014-12-26 13:06 - 00307626 _____ () C:\Users\ja\Downloads\Bestplayer Z Lektorem_10924_i10201181_il345.exe
- 2014-12-26 00:35 - 2014-12-26 00:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom
- 2014-12-26 00:34 - 2015-01-25 00:14 - 00000000 ____D () C:\Users\intel\AppData\Roaming\Steganos VPN
- 2014-12-26 00:34 - 2014-12-26 00:34 - 00000000 ____D () C:\Users\intel\AppData\Roaming\Steganos Updates
- 2014-12-26 00:33 - 2014-12-27 09:52 - 00000000 ____D () C:\Users\intel\AppData\Roaming\Steganos
- 2014-12-26 00:33 - 2014-12-26 00:35 - 00000000 ____D () C:\Program Files\OkayFreedom
- 2014-12-26 00:33 - 2014-12-26 00:33 - 00000000 ____D () C:\Program Files\Common Files\Steganos
- ==================== One Month Modified Files and Folders =======
- (If an entry is included in the fixlist, the file\folder will be moved.)
- 2015-01-25 00:38 - 2014-09-06 07:47 - 00000000 __RDO () C:\Users\intel\OneDrive
- 2015-01-25 00:37 - 2014-09-12 18:49 - 01961739 _____ () C:\WINDOWS\WindowsUpdate.log
- 2015-01-25 00:36 - 2014-09-08 17:14 - 00000000 ____D () C:\Users\intel\AppData\Roaming\uTorrent
- 2015-01-25 00:36 - 2014-09-06 18:36 - 00000000 ____D () C:\Users\intel\AppData\Roaming\Spotify
- 2015-01-25 00:34 - 2014-09-28 09:20 - 00000000 ____D () C:\WINDOWS\Minidump
- 2015-01-25 00:33 - 2013-08-22 08:23 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
- 2015-01-25 00:30 - 2014-01-28 18:36 - 00380416 _____ () C:\Users\intel\Desktop\gmer.exe
- 2015-01-25 00:27 - 2013-08-22 09:17 - 00000000 ____D () C:\WINDOWS\AppReadiness
- 2015-01-25 00:22 - 2013-04-26 08:23 - 00513136 _____ () C:\Users\intel\Desktop\Silent Runners.vbs
- 2015-01-25 00:17 - 2014-09-06 07:40 - 00000000 ____D () C:\Users\ja
- 2015-01-25 00:15 - 2014-09-06 18:38 - 00000000 ____D () C:\Users\intel\AppData\Local\Spotify
- 2015-01-25 00:13 - 2014-09-06 07:41 - 00000000 ____D () C:\Users\intel
- 2015-01-25 00:05 - 2014-09-15 19:15 - 00000000 ____D () C:\ProgramData\MFAData
- 2015-01-25 00:05 - 2005-05-13 11:04 - 01785637 _____ () C:\Users\intel\Desktop\nw101win32.exe
- 2015-01-25 00:00 - 2013-08-22 09:17 - 00000000 ____D () C:\WINDOWS\system32\sru
- 2015-01-25 00:00 - 2013-08-22 07:21 - 00000000 ___RD () C:\Users\Public
- 2015-01-24 20:38 - 2014-04-01 14:56 - 00000000 ____D () C:\Users\intel\.VirtualBox
- 2015-01-24 19:22 - 2014-04-01 17:03 - 00000000 ____D () C:\Users\intel\VirtualBox VMs
- 2015-01-24 13:56 - 2014-09-06 08:04 - 00000000 ____D () C:\Program Files\Common Files\Steam
- 2015-01-24 11:28 - 2014-03-01 18:27 - 00000000 ____D () C:\Recovery
- 2015-01-23 23:23 - 2014-03-18 08:53 - 01933330 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
- 2015-01-23 23:23 - 2014-03-18 08:29 - 00844494 _____ () C:\WINDOWS\system32\perfh015.dat
- 2015-01-23 23:23 - 2014-03-18 08:29 - 00181970 _____ () C:\WINDOWS\system32\perfc015.dat
- 2015-01-23 23:20 - 2013-08-22 09:17 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy
- 2015-01-23 14:37 - 2013-08-22 09:05 - 00000000 ____D () C:\WINDOWS\CbsTemp
- 2015-01-23 14:35 - 2013-08-22 07:13 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
- 2015-01-22 19:49 - 2014-09-06 09:12 - 00000000 ____D () C:\Users\intel\AppData\Roaming\DAEMON Tools Lite
- 2015-01-22 19:48 - 2014-09-15 15:15 - 00000000 ____D () C:\Users\intel\AppData\Roaming\FileZilla
- 2015-01-22 19:43 - 2014-09-12 18:21 - 00000000 ____D () C:\Program Files\CCleaner
- 2015-01-22 18:46 - 2014-09-07 08:41 - 00000000 ____D () C:\Users\intel\AppData\Local\Battle.net
- 2015-01-21 15:13 - 2013-08-22 09:17 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
- 2015-01-20 22:16 - 2014-06-19 16:36 - 00548352 _____ (KEMiCZA) C:\Users\intel\Desktop\Saturation Toggler.exe
- 2015-01-20 22:16 - 2014-06-19 00:40 - 00219136 _____ () C:\Users\intel\Desktop\DigitalVibrance.dll
- 2015-01-18 21:06 - 2014-11-14 16:53 - 00000000 ____D () C:\Users\intel\AppData\Local\Warframe
- 2015-01-17 21:12 - 2014-09-11 08:57 - 02480312 _____ (Sysinternals - www.sysinternals.com) C:\Users\intel\Desktop\procexp.exe
- 2015-01-17 21:12 - 2014-08-05 08:24 - 00072154 _____ () C:\Users\intel\Desktop\procexp.chm
- 2015-01-17 21:12 - 2014-08-05 08:24 - 00007005 _____ () C:\Users\intel\Desktop\Eula.txt
- 2015-01-17 10:28 - 2013-08-22 08:22 - 00482016 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
- 2015-01-16 23:13 - 2014-09-30 15:08 - 00000000 ____D () C:\ProgramData\Razer
- 2015-01-16 23:12 - 2014-09-30 15:14 - 00000000 ____D () C:\Program Files\Razer
- 2015-01-16 23:11 - 2014-09-30 15:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
- 2015-01-13 17:44 - 2014-09-13 09:36 - 00000000 ____D () C:\Users\intel\AppData\Roaming\CodeBlocks
- 2015-01-09 13:47 - 2014-09-15 19:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
- 2015-01-08 14:31 - 2014-09-12 17:54 - 00000000 ____D () C:\Users\intel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
- 2015-01-06 01:08 - 2013-08-22 09:18 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
- 2015-01-06 01:08 - 2013-08-22 09:18 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
- 2015-01-03 21:37 - 2014-11-20 18:55 - 00141633 _____ () C:\Users\intel\Desktop\Patch-Fl studio 11.1.1.zip
- 2015-01-03 21:37 - 2014-11-20 18:53 - 00000661 _____ () C:\Users\intel\Desktop\How to Install.txt
- 2015-01-03 21:37 - 2014-11-20 18:52 - 00001650 _____ () C:\Users\intel\Desktop\Important Read Me First.txt
- 2015-01-03 21:23 - 2014-03-15 10:44 - 00000000 ____D () C:\Users\intel\Documents\Visual Studio 2013
- 2015-01-03 21:21 - 2014-09-06 10:49 - 00000000 ____D () C:\Users\intel\AppData\Roaming\VisualAssist
- 2015-01-02 15:17 - 2014-11-07 22:57 - 00000000 ____D () C:\Users\intel\AppData\Roaming\vlc
- 2015-01-02 15:07 - 2014-12-25 10:44 - 00162054 _____ () C:\Users\intel\Desktop\The Interview.The.Interview.2014.1080p.WEB-DL.AAC2.0.H264-RARBG.en.srt
- 2015-01-01 18:00 - 2014-12-21 12:59 - 01152487 _____ () C:\Users\intel\Desktop\TheMatematykaning II.zip
- 2015-01-01 18:00 - 2014-12-17 15:46 - 04944918 _____ () C:\Users\intel\Desktop\TheMatematykaning.zip
- 2014-12-31 21:39 - 2014-12-24 21:01 - 00000000 ____D () C:\Users\intel\Desktop\HLDJ
- 2014-12-30 15:05 - 2014-09-06 07:40 - 00000000 ____D () C:\Users\Guest.intel-PC
- 2014-12-30 08:24 - 2014-09-08 19:36 - 00000000 ____D () C:\Users\Guest.intel-PC\AppData\Roaming\Adobe
- 2014-12-29 19:26 - 2014-09-14 19:33 - 00000000 ____D () C:\Users\intel\Documents\Outlook Files
- 2014-12-29 16:00 - 2014-09-20 12:06 - 00000000 ____D () C:\Users\intel\AppData\Roaming\TrueCrypt
- 2014-12-29 15:57 - 2014-12-24 20:32 - 00000000 ____D () C:\Users\intel\AppData\Roaming\foobar2000
- 2014-12-29 11:24 - 2014-09-20 12:06 - 00231760 _____ (TrueCrypt Foundation) C:\WINDOWS\system32\Drivers\truecrypt.sys
- ==================== Files in the root of some directories =======
- 2014-12-03 09:22 - 2014-12-03 09:22 - 0022328 _____ () C:\Users\intel\AppData\Roaming\PnkBstrK.sys
- 2015-01-17 20:54 - 2015-01-17 20:54 - 0007633 _____ () C:\Users\intel\AppData\Local\Resmon.ResmonCfg
- 2014-09-06 10:25 - 2014-09-06 10:25 - 0000003 _____ () C:\Users\intel\AppData\Local\updater.log
- 2014-09-06 10:25 - 2014-12-18 15:05 - 0000413 _____ () C:\Users\intel\AppData\Local\UserProducts.xml
- ==================== Bamital & volsnap Check =================
- (There is no automatic fix for files that do not pass verification.)
- C:\WINDOWS\explorer.exe => File is digitally signed
- C:\WINDOWS\system32\winlogon.exe => File is digitally signed
- C:\WINDOWS\system32\wininit.exe => File is digitally signed
- C:\WINDOWS\system32\svchost.exe => File is digitally signed
- C:\WINDOWS\system32\services.exe => File is digitally signed
- C:\WINDOWS\system32\User32.dll => File is digitally signed
- C:\WINDOWS\system32\userinit.exe => File is digitally signed
- C:\WINDOWS\system32\rpcss.dll => File is digitally signed
- C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
- LastRegBack: 2015-01-21 15:08
- ==================== End Of Log ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement