Zrobione. FRST w załączniku.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-04-2015
Ran by Damian (administrator) on DAMIAN-PC on 21-04-2015 19:36:01
Running from c:\Users\Damian\Downloads
Loaded Profiles: Damian (Available profiles: Damian)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Polski (Polska)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
() C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
(Egis Incorporated) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
() C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan\Mcshield.exe
() C:\Acer\Mobility Center\MobilityService.exe
(McAfee, Inc.) C:\Program Files\McAfee\MPF\MpfSrv.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSK\msksrver.exe
(NewTech InfoSystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
() C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
() C:\Program Files\Cyberlink\Shared files\RichVideo.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\mcmscsvc.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan\mcsysmon.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(McAfee, Inc.) C:\Program Files\McAfee.com\Agent\mcagent.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
(Egis Incorporated) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
(Acer Inc.) C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
(CyberLink Corp.) C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
(CyberLink) C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
(Acer Corp.) C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(GG Network S.A.) C:\Users\Damian\AppData\Local\GG\Application\gghub.exe
(Sony Ericsson Mobile Communications AB) C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
(BitTorrent Inc.) C:\Users\Damian\AppData\Roaming\uTorrent\uTorrent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\WZQKPICK32.EXE
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(GG Network S.A.) C:\Users\Damian\AppData\Local\GG\Application\ggapp.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\mcuimgr.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(acer) C:\Program Files\Acer\Empowering Technology\NotificationCenter\Framework.NotificationCenter.exe
(Microsoft Corporation) C:\Windows\System32\mcbuilder.exe
(Acer Inc.) C:\Program Files\Acer\Acer VCM\acp2HID.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] = & gt; C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1037608 2008-02-22] (Synaptics, Inc.)
HKLM\...\Run: [mcagent_exe] = & gt; C:\Program Files\McAfee.com\Agent\mcagent.exe [582992 2007-08-03] (McAfee, Inc.)
HKLM\...\Run: [BkupTray] = & gt; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe [34040 2008-04-06] ()
HKLM\...\Run: [LManager] = & gt; C:\Program Files\Launch Manager\LManager.exe [809480 2008-07-25] (Dritek System Inc.)
HKLM\...\Run: [eAudio] = & gt; C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe [544768 2008-03-07] (Acer Incorporated)
HKLM\...\Run: [eDataSecurity Loader] = & gt; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [526896 2008-03-04] (Egis Incorporated)
HKLM\...\Run: [ePower_DMC] = & gt; C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [397312 2008-04-30] (Acer Inc.)
HKLM\...\Run: [ArcadeDeluxeAgent] = & gt; C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [147456 2008-04-10] (CyberLink Corp.)
HKLM\...\Run: [CLMLServer] = & gt; C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [167936 2008-04-10] (CyberLink)
HKLM\...\Run: [PlayMovie] = & gt; C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [167936 2008-04-18] (Acer Corp.)
HKLM\...\Run: [WarReg_PopUp] = & gt; C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe [303104 2008-01-29] (Acer Incorporated)
HKLM\...\Run: [Google Desktop Search] = & gt; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [24064 2013-06-23] (Google)
HKLM\...\Run: [BCSSync] = & gt; C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKU\S-1-5-21-32022331-3599712544-3739665941-1000\...\Run: [GG] = & gt; C:\Users\Damian\AppData\Local\GG\Application\gghub.exe [4078144 2015-04-01] (GG Network S.A.)
HKU\S-1-5-21-32022331-3599712544-3739665941-1000\...\Run: [Sony Ericsson PC Companion] = & gt; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [774144 2009-12-08] (Sony Ericsson Mobile Communications AB)
HKU\S-1-5-21-32022331-3599712544-3739665941-1000\...\Run: [CCleaner Monitoring] = & gt; C:\Program Files\CCleaner\CCleaner.exe [4811032 2014-09-26] (Piriform Ltd)
HKU\S-1-5-21-32022331-3599712544-3739665941-1000\...\Run: [uTorrent] = & gt; C:\Users\Damian\AppData\Roaming\uTorrent\uTorrent.exe [1270352 2014-04-29] (BitTorrent Inc.)
HKU\S-1-5-21-32022331-3599712544-3739665941-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-32022331-3599712544-3739665941-1000\...\MountPoints2: {37e17f05-60fb-11e4-9b70-001d72cc18ce} - G:\iLinker.exe
HKU\S-1-5-21-32022331-3599712544-3739665941-1000\...\MountPoints2: {40a3c645-e529-11e4-bb10-001d72cc18ce} - G:\SETUP.EXE
HKU\S-1-5-21-32022331-3599712544-3739665941-1000\...\MountPoints2: {45e1710d-f68d-11e2-ba1b-001d72cc18ce} - F:\Startme.exe
HKU\S-1-5-21-32022331-3599712544-3739665941-1000\Control Panel\Desktop\\SCRNSAVE.EXE - & gt; C:\Windows\system32\Acer.scr [83554304 2007-04-20] ()
AppInit_DLLs: c:\progra~1\google\google~1\goec62~1.dll = & gt; c:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [113664 2013-06-23] (Google)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk - & gt; C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk
ShortcutTarget: BTTray.lnk - & gt; C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
ShortcutTarget: WinZip Quick Pick.lnk - & gt; C:\Program Files\WinZip\WZQKPICK32.EXE (WinZip Computing, S.L.)
ShellIconOverlayIdentifiers: [egisPSDP] - & gt; {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} = & gt; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll (Egis Incorporated)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [.DEFAULT] = & gt; Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] = & gt; 127.0.0.1:8118
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=181 & d=20141008
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-32022331-3599712544-3739665941-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=181 & d=20141008
HKU\S-1-5-21-32022331-3599712544-3739665941-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://global.acer.com
SearchScopes: HKLM - & gt; {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=ie7 & q={searchTerms} & rls=com.microsoft:{language}:{referrer:source?} & ie={inputEncoding} & oe={outputEncoding} & rlz=1I7ACAW
SearchScopes: HKU\.DEFAULT - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - & gt; DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-32022331-3599712544-3739665941-1000 - & gt; {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=ie7 & q={searchTerms} & rls=com.microsoft:{language}:{referrer:source?} & ie={inputEncoding} & oe={outputEncoding} & rlz=1I7ACAW_plPL591
BHO: McAfee Phishing Filter - & gt; {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - & gt; c:\Program Files\McAfee\MSK\mcapbho.dll [2007-09-19] ()
BHO: Groove GFS Browser Helper - & gt; {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - & gt; C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - & gt; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - & gt; C:\Program Files\Java\jre7\bin\ssv.dll [2014-02-23] (Oracle Corporation)
BHO: scriptproxy - & gt; {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - & gt; C:\Program Files\McAfee\VirusScan\scriptsn.dll [2007-10-24] (McAfee, Inc.)
BHO: ShowBarObj Class - & gt; {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - & gt; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-03-04] (Egis)
BHO: Office Document Cache Handler - & gt; {B4F3A835-0E21-4959-BA22-42B3008E02FF} - & gt; C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - & gt; {DBC80044-A445-435b-BC74-9C25C1C588A9} - & gt; C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-02-23] (Oracle Corporation)
Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-03-04] (Egis Incorporated.)
Handler: ms-help - No CLSID Value - []
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Damian\AppData\Roaming\Mozilla\Firefox\Profiles\9j8n1x8g.default-1424279853508
FF Plugin: @adobe.com/FlashPlayer - & gt; C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - & gt; C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-02-23] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - & gt; C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-02-23] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - & gt; C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - & gt; C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - & gt; C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - & gt; C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-06-28]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 BUNAgentSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [16384 2008-03-03] (NewTech Infosystems, Inc.) [File not signed]
R2 CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [81504 2008-01-16] () [File not signed]
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1023728 2015-03-31] (Disc Soft Ltd)
R2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2008-03-21] () [File not signed]
S3 GoogleDesktopManager-080708-050100; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [24064 2013-06-23] (Google) [File not signed]
S2 KMService; C:\Windows\system32\srvany.exe [8192 2015-04-17] () [File not signed]
S3 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
R2 mcmscsvc; C:\Program Files\McAfee\MSC\mcmscsvc.exe [749904 2007-08-04] (McAfee, Inc.)
R2 McNASvc; c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe [2376992 2008-03-20] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [378184 2007-07-25] (McAfee, Inc.)
R2 McProxy; c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe [359248 2007-08-15] (McAfee, Inc.)
R2 McShield; C:\Program Files\McAfee\VirusScan\Mcshield.exe [144704 2007-07-24] (McAfee, Inc.)
R3 McSysmon; C:\Program Files\McAfee\VirusScan\mcsysmon.exe [695624 2007-07-25] (McAfee, Inc.)
R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-12-06] () [File not signed]
R2 MpfService; C:\Program Files\McAfee\MPF\MPFSrv.exe [856864 2007-07-18] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\McAfee\MSK\MskSrver.exe [23880 2007-08-24] (McAfee, Inc.)
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [131072 2008-04-04] () [File not signed]
R2 RichVideo; C:\Program Files\Cyberlink\Shared files\RichVideo.exe [272024 2007-01-09] ()
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [233472 2008-01-10] (Acer Incorporated) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 DrvAgent32; C:\Windows\system32\Drivers\DrvAgent32.sys [23456 2014-02-23] (Phoenix Technologies) [File not signed]
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [25104 2015-04-17] (Disc Soft Ltd)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [79304 2007-07-24] (McAfee, Inc.)
R3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [35240 2007-07-21] (McAfee, Inc.)
R1 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [201288 2007-07-21] (McAfee, Inc.)
S3 mferkdk; C:\Windows\System32\drivers\mferkdk.sys [33800 2007-07-24] (McAfee, Inc.)
R3 mfesmfk; C:\Windows\System32\drivers\mfesmfk.sys [40488 2007-07-21] (McAfee, Inc.)
R1 MPFP; C:\Windows\System32\Drivers\Mpfp.sys [125728 2007-07-13] (McAfee, Inc.)
R3 NETwNv32; C:\Windows\System32\DRIVERS\NETwNv32.sys [7346176 2011-11-01] (Intel Corporation)
R2 NTIPPKernel; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [122368 2008-01-16] (Cyberlink Corp.) [File not signed]
S3 s1039mdm; C:\Windows\System32\DRIVERS\s1039mdm.sys [124016 2009-11-19] (MCCI Corporation)
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [61424 2008-04-18] (Cyberlink Corp.)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-21 19:35 - 2015-04-21 19:36 - 00000000 ____D () C:\FRST
2015-04-21 19:09 - 2015-04-21 19:10 - 00000000 ____D () C:\Windows\system32\vi-VN
2015-04-21 19:09 - 2015-04-21 19:10 - 00000000 ____D () C:\Windows\system32\eu-ES
2015-04-21 19:09 - 2015-04-21 19:10 - 00000000 ____D () C:\Windows\system32\ca-ES
2015-04-21 19:00 - 2015-04-21 19:05 - 00010588 _____ () C:\Windows\setupact.log
2015-04-21 19:00 - 2015-04-21 19:00 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-21 17:54 - 2015-04-21 17:54 - 00000000 ____D () C:\Windows\system32\EventProviders
2015-04-20 18:31 - 2015-04-20 18:32 - 00000000 ____D () C:\Users\Damian\Desktop\Prez - przy
2015-04-20 18:31 - 2015-04-20 18:31 - 01179033 _____ () C:\Users\Damian\Downloads\Prez.zip
2015-04-20 18:11 - 2015-04-20 18:49 - 00000000 ____D () C:\Users\Damian\Desktop\Prezentacja - Ostateczna wersja
2015-04-20 18:03 - 2015-04-20 18:03 - 00125440 _____ () C:\Users\Damian\Downloads\MAPA MAGAZYN BBA1(1).xls
2015-04-20 17:47 - 2015-04-20 17:47 - 01344270 _____ () C:\Users\Damian\Downloads\Prezentacja.zip
2015-04-20 17:47 - 2015-04-20 17:47 - 00000000 ____D () C:\Users\Damian\Downloads\Prezentacja
2015-04-20 17:27 - 2015-04-21 17:41 - 00000000 ____D () C:\AdwCleaner
2015-04-20 14:34 - 2015-04-20 14:34 - 00054784 _____ () C:\Users\Damian\Downloads\Magazyn - 1 zmiana - kurierzy i tury wyjazdowe.xls
2015-04-20 14:26 - 2015-04-20 14:27 - 01112180 _____ () C:\Users\Damian\Downloads\Prezentacja - Połączenie.pptx
2015-04-19 18:36 - 2015-04-19 18:36 - 00000886 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2015-04-19 18:33 - 2015-04-19 18:33 - 00000327 _____ () C:\Users\Damian\Documents\obszar.xlw
2015-04-19 18:32 - 2015-04-19 18:36 - 00000000 ____D () C:\Program Files\GIMP 2
2015-04-19 18:32 - 2015-04-19 18:32 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\Lavasoft
2015-04-19 18:32 - 2015-04-19 18:32 - 00000000 ____D () C:\ProgramData\Lavasoft
2015-04-19 18:31 - 2015-04-19 18:32 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\{4F69BC4A-EB15-495A-9963-01FE65C9A267}
2015-04-19 18:30 - 2015-04-19 18:31 - 00425672 _____ () C:\Users\Damian\Downloads\gimp-2.8.14-setup-1.exe
2015-04-19 18:05 - 2015-04-19 18:05 - 00275825 _____ () C:\Users\Damian\Downloads\NOWY Magazyn II zm.xlsx
2015-04-19 18:05 - 2015-04-19 18:05 - 00145939 _____ () C:\Users\Damian\Downloads\NOWY Magazyn I zm.xlsx
2015-04-19 17:53 - 2015-04-19 17:53 - 00125440 _____ () C:\Users\Damian\Downloads\MAPA MAGAZYN BBA1.xls
2015-04-19 17:42 - 2015-04-19 17:46 - 498580680 _____ (Microsoft Corporation) C:\Users\Damian\Downloads\Windows6.0-KB948465-X86.exe
2015-04-19 16:14 - 2015-04-19 16:14 - 00305664 _____ (Secure By Design Inc.) C:\Users\Damian\Downloads\Ninite Foxit Reader Installer(1).exe
2015-04-19 16:12 - 2015-04-19 16:12 - 00305664 _____ (Secure By Design Inc.) C:\Users\Damian\Downloads\Ninite Foxit Reader Installer.exe
2015-04-19 15:58 - 2015-04-19 15:58 - 00041108 _____ () C:\Users\Damian\Downloads\Extras.Txt
2015-04-19 15:56 - 2015-04-19 15:56 - 00090414 _____ () C:\Users\Damian\Downloads\OTL.Txt
2015-04-19 15:28 - 2015-04-19 15:28 - 00602112 _____ (OldTimer Tools) C:\Users\Damian\Downloads\OTL.exe
2015-04-19 14:38 - 2015-04-19 15:05 - 00038130 _____ () C:\Users\Damian\Downloads\Addition.txt
2015-04-19 14:29 - 2015-04-21 19:36 - 00017775 _____ () C:\Users\Damian\Downloads\FRST.txt
2015-04-19 14:28 - 2015-04-19 14:28 - 01137664 _____ (Farbar) C:\Users\Damian\Downloads\FRST.exe
2015-04-19 14:14 - 2015-04-19 14:14 - 00000000 __RSH () C:\MSDOS.SYS
2015-04-19 14:14 - 2015-04-19 14:14 - 00000000 __RSH () C:\IO.SYS
2015-04-19 13:45 - 2015-04-19 13:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-19 13:45 - 2015-04-19 13:45 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-04-19 13:45 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-19 13:45 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-19 13:44 - 2015-04-19 13:46 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2015-04-19 13:43 - 2015-04-19 13:45 - 00000903 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-19 13:43 - 2015-04-19 13:45 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\Malwarebytes
2015-04-19 13:43 - 2015-04-19 13:45 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-19 13:43 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-04-19 13:42 - 2015-04-19 13:57 - 165739488 _____ () C:\Users\Damian\Downloads\8ph4d8og.exe
2015-04-19 13:42 - 2015-04-19 13:43 - 10847608 _____ (Malwarebytes Corporation ) C:\Users\Damian\Downloads\mbam-setup-1.60.0.1800.exe
2015-04-19 13:33 - 2015-04-21 19:13 - 00746488 _____ () C:\Windows\PFRO.log
2015-04-19 13:31 - 2015-04-19 13:31 - 00001069 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2015-04-19 13:31 - 2015-04-19 13:31 - 00000000 ____D () C:\Users\Damian\AppData\Local\VS Revo Group
2015-04-19 13:31 - 2015-04-19 13:31 - 00000000 ____D () C:\ProgramData\VS Revo Group
2015-04-19 13:31 - 2015-04-19 13:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2015-04-19 13:31 - 2015-04-19 13:31 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-04-19 13:31 - 2009-12-30 10:21 - 00027192 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2015-04-19 13:27 - 2015-04-19 13:31 - 10801480 _____ (VS Revo Group ) C:\Users\Damian\Downloads\RevoUninProSetup.exe
2015-04-19 10:11 - 2015-04-19 10:11 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2015-04-18 20:46 - 2015-04-18 20:46 - 00000000 _____ () C:\Users\Damian\Desktop\Nowy dokument tekstowy (5).txt
2015-04-18 18:04 - 2015-04-18 18:04 - 00057113 _____ () C:\Users\Damian\Downloads\do prezentacji - serwis kurierski bba1, bba2-1.pptx
2015-04-18 18:04 - 2015-04-18 18:04 - 00023264 _____ () C:\Users\Damian\Downloads\SzablonMagazynu.xlsx
2015-04-18 08:22 - 2015-04-18 08:22 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2015-04-18 08:22 - 2015-04-18 08:22 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2015-04-17 20:30 - 2015-04-17 20:31 - 01396803 _____ () C:\Users\Damian\Downloads\prezentacj środa.pptx
2015-04-17 20:30 - 2015-04-17 20:30 - 01468415 _____ () C:\Users\Damian\Downloads\TOR i TOZ.PPTX
2015-04-17 20:25 - 2015-04-17 20:25 - 00008192 _____ () C:\Windows\system32\srvany.exe
2015-04-17 20:05 - 2015-04-17 20:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2015-04-17 20:03 - 2015-04-17 20:03 - 00000000 ____D () C:\Program Files\Microsoft Synchronization Services
2015-04-17 20:02 - 2015-04-17 20:02 - 00000000 ____D () C:\Windows\PCHEALTH
2015-04-17 20:02 - 2015-04-17 20:02 - 00000000 ____D () C:\Program Files\Microsoft Sync Framework
2015-04-17 20:02 - 2015-04-17 20:02 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
2015-04-17 19:58 - 2015-04-17 19:58 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 8
2015-04-17 19:56 - 2015-04-17 19:56 - 00000000 ____D () C:\Users\Damian\AppData\Local\Microsoft Help
2015-04-17 19:56 - 2015-04-17 19:56 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services
2015-04-17 19:51 - 2015-04-18 13:21 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\DAEMON Tools Lite
2015-04-17 19:51 - 2015-04-17 19:52 - 00025104 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2015-04-17 19:51 - 2015-04-17 19:51 - 00001739 _____ () C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2015-04-17 19:51 - 2015-04-17 19:51 - 00000000 ____D () C:\Program Files\DAEMON Tools Lite
2015-04-17 19:50 - 2015-04-17 19:51 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite
2015-04-17 19:45 - 2015-04-17 19:45 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\WinRAR
2015-04-17 19:42 - 2015-04-17 19:42 - 00743120 _____ (Application ) C:\Users\Damian\Downloads\pobierz_Daemon_tools_lite_V5.0.1.exe
2015-04-17 19:38 - 2015-04-17 19:38 - 01709792 _____ (Disc Soft Ltd.) C:\Users\Damian\Downloads\DTLiteInstaller.exe
2015-04-17 19:35 - 2015-04-17 19:35 - 01709792 _____ (Disc Soft Ltd.) C:\Users\Damian\Downloads\DAEMON Tools Lite 5.0.1.0407 [1].exe
2015-04-17 19:34 - 2015-04-17 19:34 - 00716488 _____ (Software ) C:\Users\Damian\Downloads\DAEMON Tools Lite 5.0.1.0407.exe
2015-04-17 19:33 - 2015-04-17 19:33 - 00738232 _____ (Generic internet ) C:\Users\Damian\Downloads\DAEMON-Tools-Lite(12708)-dp.exe
2015-04-17 19:32 - 2015-04-17 19:32 - 01847888 _____ () C:\Users\Damian\Downloads\wrar521pl.exe
2015-04-17 19:32 - 2015-04-17 19:32 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-04-17 19:32 - 2015-04-17 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-04-17 19:32 - 2015-04-17 19:32 - 00000000 ____D () C:\Program Files\WinRAR
2015-04-17 19:29 - 2015-04-17 19:29 - 00000000 ____D () C:\Users\Damian\Desktop\Microsoft Office 2010 Professional Plus x32
2015-04-17 14:34 - 2015-04-21 17:41 - 00000027 _____ () C:\Windows\system32\MPFServiceFailureCount.txt
2015-04-17 14:29 - 2015-04-17 14:29 - 02217984 _____ () C:\Users\Damian\Downloads\adwcleaner_4.201.exe
2015-04-17 12:44 - 2015-04-17 12:44 - 00000000 ____D () C:\ProgramData\Microsoft Toolkit
2015-04-17 12:43 - 2015-04-17 12:43 - 00000625 _____ () C:\Users\Damian\Downloads\[kickass.to]microsoft.office.home.and.student.2007.activation.keys.torrent
2015-04-17 12:38 - 2015-04-17 12:38 - 00043960 _____ () C:\Users\Damian\Downloads\[kickass.to]microsoft.office.pro.2007.full.version.key.by.bgood577.wbrg.torrent
2015-04-17 12:26 - 2015-04-17 12:26 - 00000000 ____D () C:\Program Files\Alfasistem Memory
2015-04-17 12:25 - 2015-04-17 12:25 - 00214056 _____ (Jelbrus LLC) C:\Users\Damian\Downloads\microsoft_Office_Enterprise_2007_._Key__-_THADOGG.exe
2015-04-17 12:18 - 2015-04-20 18:16 - 00000000 ____D () C:\Users\Damian\Documents\7 i DPD
2015-04-05 10:01 - 2015-04-05 10:02 - 00000000 ____D () C:\Program Files\Mozilla Firefox
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-21 19:36 - 2013-07-13 18:17 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\uTorrent
2015-04-21 19:36 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\rescache
2015-04-21 19:33 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-21 19:20 - 2013-06-30 16:36 - 00000000 ____D () C:\Users\Damian\AppData\Roaming\GG
2015-04-21 19:20 - 2008-05-13 09:59 - 00672140 _____ () C:\Windows\system32\perfh015.dat
2015-04-21 19:20 - 2008-05-13 09:59 - 00130516 _____ () C:\Windows\system32\perfc015.dat
2015-04-21 19:20 - 2006-11-02 12:33 - 01495264 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-21 19:18 - 2013-06-23 17:18 - 00000953 _____ () C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-21 19:18 - 2013-06-23 17:18 - 00000919 _____ () C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2015-04-21 19:18 - 2013-06-23 17:09 - 01588799 _____ () C:\Windows\WindowsUpdate.log
2015-04-21 19:18 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-21 19:18 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-21 19:16 - 2013-06-23 17:39 - 00000000 _____ () C:\Windows\system32\LogConfigTemp.xml
2015-04-21 19:16 - 2008-05-13 00:11 - 00034126 _____ () C:\Windows\system32\Config.MPF
2015-04-21 19:15 - 2008-05-13 00:30 - 00000147 _____ () C:\Windows\system32\agent.log
2015-04-21 19:15 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-21 19:15 - 2006-11-02 14:47 - 00390512 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-04-21 19:12 - 2013-06-23 17:18 - 00000012 _____ () C:\Windows\bthservsdp.dat
2015-04-21 19:12 - 2006-11-02 15:01 - 00032544 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-21 19:10 - 2008-05-13 09:58 - 00000000 ____D () C:\Windows\system32\Drivers\pl-PL
2015-04-21 19:10 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\system32\XPSViewer
2015-04-21 19:10 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-04-21 19:10 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Photo Gallery
2015-04-21 19:10 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Journal
2015-04-21 19:10 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Defender
2015-04-21 19:10 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Collaboration
2015-04-21 19:10 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Calendar
2015-04-21 19:10 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Movie Maker
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\zh-TW
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\zh-CN
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\uk-UA
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\tr-TR
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\th-TH
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\sv-SE
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\SLUI
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\sl-SI
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\sk-SK
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\ru-RU
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\ro-RO
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\pt-PT
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\pt-BR
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\pl-PL
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\nl-NL
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\nb-NO
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\lv-LV
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\lt-LT
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\ko-KR
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\ja-JP
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\it-IT
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\hu-HU
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\hr-HR
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\he-IL
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\fr-FR
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\fi-FI
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\et-EE
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\el-GR
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\bg-BG
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\ar-SA
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\IME
2015-04-21 19:10 - 2006-11-02 13:18 - 00000000 ____D () C:\Program Files\Common Files\System
2015-04-21 19:01 - 2006-11-02 13:18 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-21 18:14 - 2015-02-18 19:32 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-19 16:09 - 2013-06-23 17:16 - 00000000 ____D () C:\Users\Damian
2015-04-19 16:09 - 2008-05-13 00:04 - 00000000 ____D () C:\Windows\ACER
2015-04-19 16:09 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\PLA
2015-04-19 16:02 - 2008-05-13 00:09 - 00000000 ____D () C:\ProgramData\McAfee
2015-04-19 16:02 - 2008-05-13 00:09 - 00000000 ____D () C:\Program Files\McAfee
2015-04-19 16:01 - 2013-06-26 17:27 - 00000000 ____D () C:\Users\Damian\AppData\Local\Adobe
2015-04-19 16:01 - 2008-04-30 09:25 - 00000000 ____D () C:\ProgramData\Adobe
2015-04-19 13:29 - 2013-08-02 06:37 - 00005632 _____ () C:\Users\Damian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-19 10:37 - 2013-06-23 17:18 - 00103992 _____ () C:\Users\Damian\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-19 10:33 - 2008-05-13 00:12 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-19 10:05 - 2006-11-02 12:23 - 00000219 _____ () C:\Windows\win.ini
2015-04-18 08:35 - 2013-08-12 19:38 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-04-18 08:13 - 2008-05-13 00:16 - 00001921 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2003.lnk
2015-04-18 08:13 - 2008-05-13 00:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works
2015-04-18 08:13 - 2008-05-13 00:14 - 00000000 ____D () C:\Program Files\Microsoft Works
2015-04-18 08:11 - 2013-08-12 19:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-04-17 20:19 - 2006-11-02 13:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-04-17 20:18 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\ShellNew
2015-04-17 20:05 - 2008-05-13 00:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-04-17 20:04 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\MSBuild
2015-04-17 20:02 - 2008-05-13 00:13 - 00000000 ____D () C:\Program Files\Microsoft.NET
2015-04-17 20:02 - 2008-05-13 00:12 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-04-16 14:24 - 2013-08-15 07:22 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-16 14:11 - 2006-11-02 12:24 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-04-15 18:14 - 2015-02-18 19:32 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-15 18:14 - 2015-02-18 19:32 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-06 07:49 - 2013-06-23 17:39 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-01 13:12 - 2013-06-30 16:36 - 00000000 ____D () C:\Users\Damian\AppData\Local\GG
==================== Files in the root of some directories =======
2013-06-24 13:47 - 2013-06-24 13:48 - 0000680 _____ () C:\Users\Damian\AppData\Local\d3d9caps.dat
2013-08-02 06:37 - 2015-04-19 13:29 - 0005632 _____ () C:\Users\Damian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-06-23 17:37 - 2013-06-23 17:37 - 0091992 _____ () C:\Users\Damian\AppData\Local\edsinstaller.txt-20130623.log
Some content of TEMP:
====================
C:\Users\Damian\AppData\Local\Temp\Quarantine.exe
C:\Users\Damian\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe = & gt; File is digitally signed
C:\Windows\system32\winlogon.exe = & gt; File is digitally signed
C:\Windows\system32\wininit.exe = & gt; File is digitally signed
C:\Windows\system32\svchost.exe = & gt; File is digitally signed
C:\Windows\system32\services.exe = & gt; File is digitally signed
C:\Windows\system32\User32.dll = & gt; File is digitally signed
C:\Windows\system32\userinit.exe = & gt; File is digitally signed
C:\Windows\system32\rpcss.dll = & gt; File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys = & gt; File is digitally signed
LastRegBack: 2015-04-21 19:20
==================== End Of Log ============================