FRST_13-04-2015_21-19-16.txt

istartsurf - porblem z usunięciem

Hej, ADWcleaner nie podołał. Ponoć można to zrobić tylko za pomocą FRST, niestety nie umiem zrobić fixlisty. Załączam raporty. Z góry dzięki za pomoc


Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-04-2015
Ran by Paweł Marchwica (administrator) on CZEZWY on 13-04-2015 21:17:50
Running from C:\Users\Paweł Marchwica\Downloads
Loaded Profiles: Paweł Marchwica (Available profiles: Paweł Marchwica)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polski (Polska)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files\EslWire\service\WireHelperSvc.exe
(France Telecom SA) C:\Program Files (x86)\Common Files\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428950708-11B2-8000-CA29642E828C\insz9828.tmp
() C:\Windows\SysWOW64\srvany.exe
() C:\Windows\KMService.exe
() C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428802872-11B2-8000-CA29642E828C\cnsjE589.tmp
() C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428861374-11B2-8000-CA29642E828C\insrA778.tmp
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
() C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428856061-11B2-8000-CA29642E828C\insn33C0.tmp
() C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428802887-11B2-8000-CA29642E828C\snse1B56.tmp
() C:\Users\Paweł Marchwica\AppData\Roaming\F0AAD7C0-1428795485-11B2-8000-CA29642E828C\jnsi42FF.tmp
() C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
() C:\Users\Paweł Marchwica\AppData\Roaming\F0AAD7C0-1428795485-11B2-8000-CA29642E828C\nsy93E9.tmp
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\ProgramData\{7510238f-dd85-ebca-7510-0238fdd88e3f}\Vikings S03E08 HDTV x264-KILLERS [eztv].exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(IObit) C:\Program Files (x86)\IObit\Game Booster 3\gbtray.exe
() C:\Users\Paweł Marchwica\AppData\Local\Temp\nsr5EB6.tmp
() C:\Program Files (x86)\gmsd_pl_93\gmsd_pl_93.exe
() C:\Users\Paweł Marchwica\AppData\Local\gmsd_pl_93\upgmsd_pl_93.exe
(SoftBrain Technologies Ltd.) C:\Users\Paweł Marchwica\AppData\Local\SmartWeb\SmartWebHelper.exe
(SoftBrain Technologies Ltd.) C:\Users\Paweł Marchwica\AppData\Local\SmartWeb\SmartWebApp.exe
(SysTool PasSame LIMITED) C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
(XTab system) C:\Program Files (x86)\XTab\ProtectService.exe
(SearchProtect) C:\Program Files (x86)\XTab\CmdShell.exe
(XTab system) C:\Program Files (x86)\XTab\HPNotify.exe
(CC Corporation) C:\Program Files (x86)\IGS\CCL.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\Paweł Marchwica\AppData\Local\Temp\nshB23D.tmp
() C:\ProgramData\AppMgr3.01.5851619\AppMgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\ProgramData\AppMgr3.01.5851619\1\plugin.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\gmsd_pl_93\gmsd_pl_93.exe
(NVIDIA Corporation) C:\Users\Paweł Marchwica\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Hewlett Packard) C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [gmsd_pl_93] = & gt; C:\Program Files (x86)\gmsd_pl_93\gmsd_pl_93.exe [3982792 2015-04-13] ()
HKLM-x32\...\Run: [SmartWeb] = & gt; C:\Users\Paweł Marchwica\AppData\Local\SmartWeb\SmartWebHelper.exe [270368 2015-02-17] (SoftBrain Technologies Ltd.)
HKLM-x32\...\RunOnce: [upgmsd_pl_93.exe] = & gt; C:\Users\Paweł Marchwica\AppData\Local\gmsd_pl_93\upgmsd_pl_93.exe [3305928 2015-04-13] ()
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\RunOnce: [] = & gt; [X]
HKU\S-1-5-20\...\RunOnce: [] = & gt; [X]
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\Run: [ChomikBox] = & gt; C:\Program Files (x86)\ChomikBox\chomikbox.exe [6033408 2014-05-22] ( )
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\Run: [Badoo Desktop] = & gt; C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [1067280 2014-06-20] (Badoo)
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\Run: [ESL Wire] = & gt; C:\Program Files\EslWire\wire.exe [3771904 2014-12-09] (Turtle Entertainment GmbH)
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\Policies\Explorer: [NofolderOptions] 0
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\MountPoints2: {1bf5c20f-1f7d-11e2-9bf6-e8039aa73162} - E:\AutoRun.exe
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\MountPoints2: {298a29d5-af24-11e2-96e8-e8039aa73162} - F:\AutoRun.exe
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\MountPoints2: {298a29e7-af24-11e2-96e8-e8039aa73162} - F:\AutoRun.exe
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\MountPoints2: {2eb18b1c-a097-11e3-9388-e8039aa73162} - F:\AutoRun.exe
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\MountPoints2: {316dd648-5989-11e3-b8b7-e8039aa73162} - F:\LGAutoRun.exe
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\MountPoints2: {332760ee-4d4c-11e2-a2e3-e8039aa73162} - F:\NokiaPCIA_Autorun.exe
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\MountPoints2: {4775ae11-1f77-11e2-be19-e8039aa73162} - E:\AutoRun.exe
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\MountPoints2: {4775ae21-1f77-11e2-be19-e8039aa73162} - E:\AutoRun.exe
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\MountPoints2: {5b73a54d-a2d4-11e2-a389-e8039aa73162} - E:\MicroLauncher.exe
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\MountPoints2: {669c55a1-797e-11e3-a3eb-e8039aa73162} - F:\AutoRun.exe
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\MountPoints2: {f69cf111-617a-11e2-b7ee-e8039aa73162} - E:\AutoRun.exe
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\...\MountPoints2: {f8b38273-b1ce-11e3-a86d-e8039aa73162} - F:\MicroLauncher.exe
HKU\S-1-5-18\...\RunOnce: [] = & gt; [X]
AppInit_DLLs: C:\windows\system32\nvinitx.dll = & gt; C:\windows\system32\nvinitx.dll [168616 2013-09-05] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll = & gt; c:\windows\syswow64\nvinit.dll [141336 2013-09-05] (NVIDIA Corporation)
AppInit_DLLs-x32: ,C:\windows\SysWOW64\nvinit.dll = & gt; C:\windows\SysWOW64\nvinit.dll [141336 2013-09-05] (NVIDIA Corporation)
Startup: C:\Users\Paweł Marchwica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
ShortcutTarget: SmartWeb.lnk - & gt; C:\Users\Paweł Marchwica\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
Startup: C:\Users\Paweł Marchwica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Vikings S03E08 HDTV x264-KILLERS [eztv].lnk
ShortcutTarget: Vikings S03E08 HDTV x264-KILLERS [eztv].lnk - & gt; C:\ProgramData\{7510238f-dd85-ebca-7510-0238fdd88e3f}\Vikings S03E08 HDTV x264-KILLERS [eztv].exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction & lt; ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX
HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX
SearchScopes: HKLM - & gt; DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX & q={searchTerms}
SearchScopes: HKLM - & gt; {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX & q={searchTerms}
SearchScopes: HKLM-x32 - & gt; DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX & q={searchTerms}
SearchScopes: HKLM-x32 - & gt; {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX & q={searchTerms}
SearchScopes: HKU\.DEFAULT - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2104657585-1371390912-4140370265-1001 - & gt; DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.istartsurf.com/web/?utm_source=b & utm_medium=face & utm_campaign=install_ie & utm_content=ds & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX & ts=1428951870 & type=default & q={searchTerms}
SearchScopes: HKU\S-1-5-21-2104657585-1371390912-4140370265-1001 - & gt; {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.istartsurf.com/web/?utm_source=b & utm_medium=face & utm_campaign=install_ie & utm_content=ds & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX & ts=1428951870 & type=default & q={searchTerms}
SearchScopes: HKU\S-1-5-21-2104657585-1371390912-4140370265-1001 - & gt; {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.istartsurf.com/web/?utm_source=b & utm_medium=face & utm_campaign=install_ie & utm_content=ds & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX & ts=1428951870 & type=default & q={searchTerms}
SearchScopes: HKU\S-1-5-21-2104657585-1371390912-4140370265-1001 - & gt; {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?utm_source=b & utm_medium=face & utm_campaign=install_ie & utm_content=ds & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX & ts=1428951870 & type=default & q={searchTerms}
SearchScopes: HKU\S-1-5-21-2104657585-1371390912-4140370265-1001 - & gt; {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.istartsurf.com/web/?utm_source=b & utm_medium=face & utm_campaign=install_ie & utm_content=ds & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX & ts=1428951870 & type=default & q={searchTerms}
BHO: Groove GFS Browser Helper - & gt; {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - & gt; C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - & gt; {9030D464-4C02-4ABF-8ECC-5164760863C6} - & gt; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Office Document Cache Handler - & gt; {B4F3A835-0E21-4959-BA22-42B3008E02FF} - & gt; C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Browser Good 1.0.0.7 - & gt; {2dd0916f-60de-4413-8198-d3c9d9b959d1} - & gt; C:\Program Files (x86)\Browser Good\BrowserGoodbho.dll [2015-04-13] (Browser Good)
BHO-x32: IETabPage Class - & gt; {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - & gt; C:\Program Files (x86)\XTab\SupTab.dll [2015-04-02] (Thinknice Co. Limited)
BHO-x32: PDF Architect Helper - & gt; {3A2D5EBA-F86D-4BD3-A177-019765996711} - & gt; C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll [2013-04-08] (pdfforge GmbH)
BHO-x32: Groove GFS Browser Helper - & gt; {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - & gt; C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - & gt; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - & gt; C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-09-09] (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - & gt; {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - & gt; C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-02-13] (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper - & gt; {9030D464-4C02-4ABF-8ECC-5164760863C6} - & gt; C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Samsung BHO Class - & gt; {AA609D72-8482-4076-8991-8CDAE5B93BCB} - & gt; C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll [2010-10-25] ()
BHO-x32: Office Document Cache Handler - & gt; {B4F3A835-0E21-4959-BA22-42B3008E02FF} - & gt; C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: QUICKfind BHO Object - & gt; {C08DF07A-3E49-4E25-9AB0-D3882835F153} - & gt; C:\Program Files (x86)\IDM\QUICKfind\PlugIns\IEHelp.dll [2007-02-16] (IDM)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - & gt; {DBC80044-A445-435b-BC74-9C25C1C588A9} - & gt; C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-09-09] (Oracle Corporation)
Winsock: Catalog9 01 C:\windows\SysWOW64\CCL.dll [341696] (CC Corporation)
Winsock: Catalog9 02 C:\windows\SysWOW64\CCL.dll [341696] (CC Corporation)
Winsock: Catalog9 03 C:\windows\SysWOW64\CCL.dll [341696] (CC Corporation)
Winsock: Catalog9 04 C:\windows\SysWOW64\CCL.dll [341696] (CC Corporation)
Winsock: Catalog9 16 C:\windows\SysWOW64\CCL.dll [341696] (CC Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF Plugin: @microsoft.com/GENUINE - & gt; disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - & gt; c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - & gt; C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - & gt; C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - & gt; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - & gt; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 - & gt; C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-09] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 - & gt; C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-09-09] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - & gt; disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - & gt; c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - & gt; C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - & gt; C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - & gt; C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - & gt; C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - & gt; C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - & gt; C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - & gt; C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-07-19] (VideoLAN)
FF Plugin-x32: Adobe Reader - & gt; C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-08-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2104657585-1371390912-4140370265-1001: @Skype Limited.com/Facebook Video Calling Plugin - & gt; C:\Users\Paweł Marchwica\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2104657585-1371390912-4140370265-1001: @unity3d.com/UnityPlayer,version=1.0 - & gt; C:\Users\Paweł Marchwica\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-11-02] (Unity Technologies ApS)
FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-08-30]

Chrome:
=======
CHR HomePage: Default - & gt; hxxp://www.istartsurf.com/?type=hp & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX
CHR StartupUrls: Default - & gt; " hxxp://www.istartsurf.com/?type=hp & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX "
CHR DefaultSuggestURL: Default - & gt; {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient} & gs_ri={google:suggestRid} & xssi=t & q={searchTerms} & {google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Paweł Marchwica\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Paweł Marchwica\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-12]
CHR Extension: (Google Docs) - C:\Users\Paweł Marchwica\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-12]
CHR Extension: (Google Drive) - C:\Users\Paweł Marchwica\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-04-12]
CHR Extension: (YouTube) - C:\Users\Paweł Marchwica\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-04-12]
CHR Extension: (Google Search) - C:\Users\Paweł Marchwica\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-12]
CHR Extension: (Google Sheets) - C:\Users\Paweł Marchwica\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-12]
CHR Extension: (Google Wallet) - C:\Users\Paweł Marchwica\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Gmail) - C:\Users\Paweł Marchwica\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-12]
CHR HKLM-x32\...\Chrome\Extension: [aaaamnpffgnockjfnlelgnclclgfcllg] - C:\Users\Paweł Marchwica\AppData\Local\APN\GoogleCRXs\aaaamnpffgnockjfnlelgnclclgfcllg_7.17.3.0.crx [Not Found]
StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.istartsurf.com/?type=sc & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX

Opera:
=======
OPR Extension: (GoHDV11.04) - C:\Users\Paweł Marchwica\AppData\Roaming\Opera Software\Opera Stable\Extensions\bokijhalndhhhikpnaniimagniglonke [2015-04-12]
StartMenuInternet: (HKLM) OperaStable - c:\program files (x86)\opera\launcher.exe http://www.istartsurf.com/?type=sc & ts=1428951854 & from=face & uid=HitachiXHTS547550A9E384_J2110051JKEMZBJKEMZBX

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AppMgr3.01.5851619; C:\ProgramData\AppMgr3.01.5851619\AppMgr.exe [455928 2015-04-13] ()
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [106144 2012-02-13] (Atheros Commnucations) [File not signed]
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
R2 CCL; C:\Program Files (x86)\IGS\CCL.exe [1873960 2015-04-07] (CC Corporation) [File not signed]
R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [663056 2014-01-28] ()
R2 FTRTSVC; C:\Program Files (x86)\Common Files\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [90112 2009-10-14] (France Telecom SA) [File not signed]
S3 HP DS Service; C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [13824 2011-10-17] (Hewlett-Packard Company) [File not signed]
S2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [164864 2012-05-02] (HP) [File not signed]
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158816 2015-04-02] (XTab system)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-08] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-08] (Intel Corporation)
R2 kitecudi; C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428950708-11B2-8000-CA29642E828C\insz9828.tmp [84992 2015-04-13] () [File not signed]
R2 KMService; C:\windows\SysWOW64\srvany.exe [8192 2013-05-02] () [File not signed]
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [619776 2015-01-15] (Lenovo)
R2 livifumo; C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428802872-11B2-8000-CA29642E828C\cnsjE589.tmp [161280 2015-04-12] () [File not signed]
R2 mybehyzu; C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428861374-11B2-8000-CA29642E828C\insrA778.tmp [107008 2015-04-12] () [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [50688 2011-04-13] (Hewlett-Packard) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [66048 2011-04-13] (Hewlett-Packard) [File not signed]
R2 pudevufi; C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428856061-11B2-8000-CA29642E828C\insn33C0.tmp [107520 2015-04-12] () [File not signed]
R2 qesivopu; C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428802887-11B2-8000-CA29642E828C\snse1B56.tmp [154624 2015-04-12] () [File not signed]
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed]
R2 romenewy; C:\Users\Paweł Marchwica\AppData\Roaming\F0AAD7C0-1428795485-11B2-8000-CA29642E828C\jnsi42FF.tmp [113152 2015-04-12] () [File not signed]
S3 Samsung UPD Service2; C:\windows\System32\SUPDSvc2.exe [165456 2011-12-02] (Samsung Electronics)
R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [File not signed]
R2 syxuxevo; C:\Users\Paweł Marchwica\AppData\Roaming\F0AAD7C0-1428795485-11B2-8000-CA29642E828C\nsy93E9.tmp [140288 2015-04-13] () [File not signed]
S2 Util Browser Good; C:\Program Files (x86)\Browser Good\bin\utilBrowserGood.exe [411896 2015-04-13] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [493712 2015-04-13] (SysTool PasSame LIMITED)
R2 ZAtheros Bt & Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2012-02-13] (Atheros) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [45856 2013-05-21] (AVG Technologies)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-13 21:16 - 2015-04-13 21:16 - 00027883 _____ () C:\Users\Paweł Marchwica\Downloads\Addition (1).txt
2015-04-13 21:14 - 2015-04-13 21:15 - 00044129 _____ () C:\Users\Paweł Marchwica\Downloads\Addition.txt
2015-04-13 21:13 - 2015-04-13 21:18 - 00030203 _____ () C:\Users\Paweł Marchwica\Downloads\FRST.txt
2015-04-13 21:13 - 2015-04-13 21:17 - 00000000 ____D () C:\FRST
2015-04-13 21:12 - 2015-04-13 21:12 - 02096640 _____ (Farbar) C:\Users\Paweł Marchwica\Downloads\FRST64.exe
2015-04-13 21:08 - 2015-04-13 21:09 - 00000000 ____D () C:\ProgramData\AppMgr3.01.5851619
2015-04-13 21:08 - 2015-04-13 21:08 - 00000000 ____D () C:\Program Files (x86)\Browser Good
2015-04-13 21:06 - 2015-04-13 21:06 - 00001105 _____ () C:\Users\Paweł Marchwica\Desktop\Continue Live Installation.lnk
2015-04-13 21:04 - 2015-04-13 21:04 - 00004070 _____ () C:\windows\System32\Tasks\SmartWeb Upgrade Trigger Task
2015-04-13 21:04 - 2015-04-13 21:04 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\istartsurf
2015-04-13 21:04 - 2015-04-13 21:04 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\SmartWeb
2015-04-13 21:04 - 2015-04-13 21:04 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428959050-11B2-8000-CA29642E828C
2015-04-13 21:04 - 2015-04-13 21:04 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2015-04-13 21:04 - 2015-04-13 21:04 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
2015-04-13 21:04 - 2015-04-13 21:04 - 00000000 ____D () C:\Program Files (x86)\XTab
2015-04-13 21:04 - 2015-04-13 21:04 - 00000000 ____D () C:\Program Files (x86)\IGS
2015-04-13 21:03 - 2015-04-13 21:08 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\gmsd_pl_93
2015-04-13 21:03 - 2015-04-13 21:03 - 00000000 ____D () C:\Program Files (x86)\gmsd_pl_93
2015-04-13 20:08 - 2015-04-13 20:08 - 00003186 _____ () C:\windows\System32\Tasks\{07025907-1AD0-4496-8AED-608F068A73A0}
2015-04-13 20:03 - 2015-04-13 20:03 - 03109248 _____ (Enigma Software Group USA, LLC.) C:\Users\Paweł Marchwica\Downloads\SpyHunter-Installer (1).exe
2015-04-13 18:47 - 2015-04-13 18:48 - 03109248 _____ (Enigma Software Group USA, LLC.) C:\Users\Paweł Marchwica\Downloads\SpyHunter-Installer.exe
2015-04-13 18:47 - 2015-04-13 18:48 - 02042440 _____ (iS3, Inc.) C:\Users\Paweł Marchwica\Downloads\STOPzillaPRO_Downloader.exe
2015-04-13 18:45 - 2015-04-13 18:45 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428950708-11B2-8000-CA29642E828C
2015-04-12 18:05 - 2015-04-12 18:05 - 00613255 _____ (CMI Limited) C:\Users\Paweł Marchwica\AppData\Local\nsaBEAF.tmp
2015-04-12 17:56 - 2015-04-12 17:56 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428861374-11B2-8000-CA29642E828C
2015-04-12 17:13 - 2015-04-12 17:13 - 00613255 _____ (CMI Limited) C:\Users\Paweł Marchwica\AppData\Local\nsy740C.tmp
2015-04-12 17:13 - 2015-04-12 17:13 - 00000000 ____D () C:\windows\SysWOW64\Flash
2015-04-12 17:12 - 2015-04-12 17:12 - 01766912 _____ (Cinema PlusV12.04) C:\Users\Paweł Marchwica\AppData\Roaming\GKSWKV.exe
2015-04-12 17:12 - 2015-04-12 17:12 - 00001378 _____ () C:\windows\Tasks\GKSWKV.job
2015-04-12 17:12 - 2015-04-12 17:12 - 00000000 ____D () C:\Program Files (x86)\f4cc3080-22b6-4c31-b790-f74fc4d06953
2015-04-12 17:11 - 2015-04-12 17:11 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428858675-11B2-8000-CA29642E828C
2015-04-12 16:35 - 2015-04-12 16:35 - 02217984 _____ () C:\Users\Paweł Marchwica\Downloads\AdwCleaner.exe
2015-04-12 16:28 - 2015-04-13 20:32 - 00008736 _____ () C:\windows\SysWOW64\CCLOff.ini
2015-04-12 16:28 - 2015-04-13 20:32 - 00008736 _____ () C:\windows\system32\CCLOff.ini
2015-04-12 16:28 - 2015-04-07 17:43 - 00341696 _____ (CC Corporation) C:\windows\SysWOW64\CCL.dll
2015-04-12 16:27 - 2015-04-12 16:27 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428856061-11B2-8000-CA29642E828C
2015-04-12 05:14 - 2015-04-12 05:54 - 00000000 ____D () C:\windows\system32\log
2015-04-12 05:13 - 2015-04-12 05:13 - 00822120 _____ () C:\Users\Paweł Marchwica\Downloads\yet_another_cleaner_sk_7477955.exe
2015-04-12 04:39 - 2015-04-12 04:39 - 41840320 _____ (Microsoft Corporation) C:\Users\Paweł Marchwica\Downloads\windows-kb890830-x64-v5.22.exe
2015-04-12 01:41 - 2015-04-13 20:38 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428802887-11B2-8000-CA29642E828C
2015-04-12 01:41 - 2015-04-12 01:41 - 01872896 _____ (InstallMoonV11.04) C:\Users\Paweł Marchwica\AppData\Roaming\CAJHRG.exe
2015-04-12 01:41 - 2015-04-12 01:41 - 00008216 _____ () C:\windows\System32\Tasks\4f3d6b11-6625-41c5-86c1-8ced8ad6159d-11
2015-04-12 01:41 - 2015-04-12 01:41 - 00007526 _____ () C:\windows\System32\Tasks\4f3d6b11-6625-41c5-86c1-8ced8ad6159d-3
2015-04-12 01:41 - 2015-04-12 01:41 - 00001378 _____ () C:\windows\Tasks\CAJHRG.job
2015-04-12 01:41 - 2015-04-12 01:41 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428802872-11B2-8000-CA29642E828C
2015-04-12 01:40 - 2015-04-12 01:40 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\F0AAD7C0-1428795613-11B2-8000-CA29642E828C
2015-04-12 01:38 - 2015-04-13 18:31 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\F0AAD7C0-1428795485-11B2-8000-CA29642E828C
2015-04-12 01:38 - 2015-04-12 01:38 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\F0AAD7C0-1428802735-11B2-8000-CA29642E828C
2015-04-12 01:35 - 2015-04-13 20:32 - 00000446 _____ () C:\windows\Tasks\SpeeditUp Update.job
2015-04-12 01:35 - 2015-04-12 01:35 - 00003114 _____ () C:\windows\System32\Tasks\SpeeditUp Update
2015-04-12 01:35 - 2015-04-12 01:35 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf
2015-04-12 01:33 - 2015-04-12 01:35 - 2201030656 _____ () C:\Users\Paweł Marchwica\Downloads\Last.Knights.2015.D.WEB-DLRip.2100MB.uniongang.avi
2015-04-10 14:32 - 2015-04-12 01:43 - 00000000 ____D () C:\ProgramData\{7510238f-dd85-ebca-7510-0238fdd88e3f}
2015-03-27 16:52 - 2015-03-27 17:23 - 00000000 ____D () C:\Users\Paweł Marchwica\Desktop\Książka
2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Paweł Marchwica\AppData\Roaming\GKSWKV
2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Paweł Marchwica\AppData\Roaming\CAJHRG
2015-03-25 17:24 - 2015-03-25 17:27 - 00000000 ____D () C:\Users\Paweł Marchwica\Documents\Heroes of the Storm
2015-03-24 19:03 - 2015-03-24 19:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm
2015-03-24 17:47 - 2015-04-07 16:34 - 00000000 ____D () C:\Program Files (x86)\Heroes of the Storm
2015-03-14 22:35 - 2015-03-14 22:39 - 733929472 _____ () C:\Users\Paweł Marchwica\Downloads\Lissi na Lodzie - Dubbing PL.avi

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-13 21:05 - 2013-01-21 21:22 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\TS3Client
2015-04-13 21:05 - 2012-04-13 21:44 - 01104182 _____ () C:\windows\WindowsUpdate.log
2015-04-13 21:04 - 2014-08-03 14:29 - 00001176 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-04-13 21:04 - 2012-10-15 12:42 - 00001048 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-13 20:45 - 2014-02-04 19:17 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\Battle.net
2015-04-13 20:45 - 2012-10-26 18:38 - 00268465 _____ () C:\windows\setupact.log
2015-04-13 20:45 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-13 20:45 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-13 20:33 - 2015-01-16 20:51 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\ESL Wire Game Client
2015-04-13 20:33 - 2013-10-05 03:01 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\ChomikBox
2015-04-13 20:33 - 2013-10-05 03:01 - 00000000 ____D () C:\Users\Paweł Marchwica\.gstreamer-0.10
2015-04-13 20:32 - 2015-01-28 00:25 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder
2015-04-13 20:32 - 2014-09-08 23:13 - 00000000 ____D () C:\AdwCleaner
2015-04-13 20:32 - 2014-09-08 21:45 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks
2015-04-13 20:32 - 2013-06-04 21:29 - 00000350 _____ () C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2015-04-13 20:32 - 2013-04-13 09:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Orange
2015-04-13 20:32 - 2012-10-15 12:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-04-13 20:32 - 2012-10-15 12:42 - 00001044 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-13 20:32 - 2012-04-13 05:49 - 00000828 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2015-04-13 20:32 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-04-13 20:16 - 2012-04-13 21:16 - 00740688 _____ () C:\windows\system32\perfh015.dat
2015-04-13 20:16 - 2012-04-13 21:16 - 00156230 _____ () C:\windows\system32\perfc015.dat
2015-04-13 20:16 - 2009-07-14 07:13 - 01670590 _____ () C:\windows\system32\PerfStringBackup.INI
2015-04-13 20:11 - 2010-11-21 05:47 - 01905460 _____ () C:\windows\PFRO.log
2015-04-13 20:08 - 2012-10-15 14:49 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\vlc
2015-04-13 18:49 - 2012-10-15 12:15 - 00000000 ____D () C:\Users\Paweł Marchwica
2015-04-13 18:23 - 2013-07-08 21:18 - 00000968 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2104657585-1371390912-4140370265-1001UA.job
2015-04-13 18:08 - 2012-04-13 05:49 - 00000830 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2015-04-13 02:23 - 2013-07-08 21:18 - 00000946 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2104657585-1371390912-4140370265-1001Core.job
2015-04-12 19:49 - 2012-10-15 14:56 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\foobar2000
2015-04-12 17:12 - 2015-01-20 22:01 - 00000000 ____D () C:\Program Files (x86)\Advanced Tactical Center
2015-04-12 16:01 - 2014-02-12 21:24 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XVM LITE 5.0.3 conf by DjVirusPL 0.8.11 v1
2015-04-12 05:54 - 2009-07-14 07:08 - 00032608 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2015-04-12 05:39 - 2014-06-23 17:25 - 00000000 ____D () C:\Program Files (x86)\OBS
2015-04-12 05:25 - 2012-10-16 15:46 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\skypePM
2015-04-12 05:25 - 2012-10-16 15:04 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\Skype
2015-04-12 05:25 - 2012-10-15 17:56 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\Mumble
2015-04-12 05:25 - 2011-02-11 21:57 - 00000000 ____D () C:\windows\Panther
2015-04-12 05:25 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2015-04-12 01:35 - 2012-11-13 01:22 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Roaming\BitTorrent
2015-04-11 13:59 - 2014-02-04 19:17 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2015-04-09 19:08 - 2014-08-03 14:29 - 00003868 _____ () C:\windows\System32\Tasks\Opera scheduled Autoupdate 1407068978
2015-04-09 19:08 - 2014-08-03 14:29 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-04-04 18:40 - 2012-10-18 13:40 - 00000000 ____D () C:\Users\Paweł Marchwica\AppData\Local\CrashDumps
2015-04-03 15:49 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\NDF
2015-04-01 23:40 - 2014-02-08 01:36 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2015-03-25 17:25 - 2014-02-04 19:17 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2015-03-17 23:52 - 2012-08-30 17:20 - 00000000 ____D () C:\Muzyka
2015-03-17 11:57 - 2015-03-10 05:00 - 00000000 ____D () C:\windows\System32\Tasks\NCH Software
2015-03-15 08:44 - 2014-11-15 09:28 - 00000000 ____D () C:\Users\Paweł Marchwica\Desktop\Magisterium

==================== Files in the root of some directories =======

2015-03-26 21:14 - 2015-03-26 21:14 - 0005542 _____ () C:\Users\Paweł Marchwica\AppData\Roaming\CAJHRG
2015-04-12 01:41 - 2015-04-12 01:41 - 1872896 _____ (InstallMoonV11.04) C:\Users\Paweł Marchwica\AppData\Roaming\CAJHRG.exe
2015-03-26 21:14 - 2015-03-26 21:14 - 0005542 _____ () C:\Users\Paweł Marchwica\AppData\Roaming\GKSWKV
2015-04-12 17:12 - 2015-04-12 17:12 - 1766912 _____ (Cinema PlusV12.04) C:\Users\Paweł Marchwica\AppData\Roaming\GKSWKV.exe
2015-04-12 18:05 - 2015-04-12 18:05 - 0613255 _____ (CMI Limited) C:\Users\Paweł Marchwica\AppData\Local\nsaBEAF.tmp
2015-04-12 17:13 - 2015-04-12 17:13 - 0613255 _____ (CMI Limited) C:\Users\Paweł Marchwica\AppData\Local\nsy740C.tmp
2012-10-16 15:46 - 2012-10-16 15:46 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2012-04-13 07:04 - 2012-04-13 07:05 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2012-04-13 07:00 - 2012-04-13 07:00 - 0000113 _____ () C:\ProgramData\{34FBC7C4-CD31-4D93-A428-0E524EAC4586}.log
2012-04-13 07:02 - 2012-04-13 07:03 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2012-04-13 07:00 - 2012-04-13 07:02 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log
2012-04-13 07:03 - 2012-04-13 07:04 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log

Some content of TEMP:
====================
C:\Users\Paweł Marchwica\AppData\Local\Temp\3423CED5-F71C-3C59-4592-651D75B61FA5.dll
C:\Users\Paweł Marchwica\AppData\Local\Temp\3423CED5-F71C-3C59-4592-651D75B61FA5.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\3857.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\490A5A48-AD3F-122D-2ACA-99924F48741C.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\7461.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\8271.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\985C82A3-CA29-9620-FF86-E65D0CC29B09.dll
C:\Users\Paweł Marchwica\AppData\Local\Temp\985C82A3-CA29-9620-FF86-E65D0CC29B09.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\bitool.dll
C:\Users\Paweł Marchwica\AppData\Local\Temp\E6B0AA97-753E-3D5B-D302-2947B9057569.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\ebbcabfbdfcce.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\jue5BB1.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\jueDA57.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\jueE3C9.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\jueFC1A.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\last.knights.2015.web.dlrip__10924_i1496131021_il1865962.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\Quarantine.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\setup.exe
C:\Users\Paweł Marchwica\AppData\Local\Temp\sqlite3.dll
C:\Users\Paweł Marchwica\AppData\Local\Temp\Uninstall.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe = & gt; File is digitally signed
C:\Windows\System32\wininit.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\wininit.exe = & gt; File is digitally signed
C:\Windows\explorer.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\explorer.exe = & gt; File is digitally signed
C:\Windows\System32\svchost.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\svchost.exe = & gt; File is digitally signed
C:\Windows\System32\services.exe = & gt; File is digitally signed
C:\Windows\System32\User32.dll = & gt; File is digitally signed
C:\Windows\SysWOW64\User32.dll = & gt; File is digitally signed
C:\Windows\System32\userinit.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\userinit.exe = & gt; File is digitally signed
C:\Windows\System32\rpcss.dll = & gt; File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys = & gt; File is digitally signed


LastRegBack: 2015-03-18 05:15

==================== End Of Log ============================


Download file - link to post