Scan result of Farbar Recovery Scan Tool Version: 09-07-2012 Ran by SYSTEM at 10-07-2012 20:43:14 Running from O:\ Windows 7 Home Premium (X64) OS Language: Polish The current controlset is ControlSet002 ========================== Registry (Whitelisted) ============= HKLM\...\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [1680976 2010-10-29] (Logitech, Inc.) HKLM\...\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe [x] HKLM\...\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3508624 2012-02-22] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun [114688 2008-12-24] (Brother Industries, Ltd.) HKLM-x32\...\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN [2621440 2010-02-09] (Brother Industries, Ltd.) HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-29] () HKU\Wojtek\...\Run: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] () HKU\Wojtek\...\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21416 2012-03-19] () HKU\Wojtek\...\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s [943504 2012-02-22] (Samsung) HKU\Wojtek\...\Run: [Google Update] "C:\Users\Wojtek\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-10-25] (Google Inc.) HKU\Wojtek\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17417392 2012-07-03] (Skype Technologies S.A.) HKU\Wojtek\...\Run: [sppuinotify] C:\Users\Wojtek\AppData\Local\Microsoft\Windows\3376\sppuinotify.exe [51200 2012-07-10] () Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Startup: C:\Users\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) ==================== Services (Whitelisted) ====== 3 Autodesk Licensing Service; "C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe" [79360 2011-08-11] (Autodesk) 3 BrYNSvc; "C:\Program Files (x86)\Browny02\BrYNSvc.exe" [245760 2010-01-25] (Brother Industries, Ltd.) 2 CDMA Device Service; C:\Program Files (x86)\Samsung\USB Drivers\26_VIA_driver2\amd64\VIAService.exe [159232 2011-08-02] () 2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation) 2 MSSQL$AUTODESKVAULT; "C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sAUTODESKVAULT [29293408 2010-12-10] (Microsoft Corporation) 3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation) 2 RapiMgr; C:\Windows\WindowsMobile\rapimgr.dll [225672 2007-05-31] (Microsoft Corporation) 2 WcesComm; C:\Windows\WindowsMobile\wcescomm.dll [443784 2007-05-31] (Microsoft Corporation) 2 mitsijm2012; "C:\--==AAProgram filesAA==--\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe" [x] ========================== Drivers (Whitelisted) ============= 3 CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfoX64.sys [18128 2007-09-25] () ========================== NetSvcs (Whitelisted) =========== ============ One Month Created Files and Folders ============== 2012-07-11 01:25 - 2012-07-11 01:32 - 00074524 ____A C:\OTL.Txt 2012-07-10 20:42 - 2012-07-10 20:43 - 00000000 ____D C:\FRST 2012-07-10 16:32 - 2012-07-10 16:32 - 00000000 ____D C:\Users\Wojtek\AppData\Roaming\hellomoto 2012-07-10 06:46 - 2012-07-10 06:46 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{7B805395-7F5C-4949-850D-8D253C71BA56} 2012-07-10 06:45 - 2012-07-10 06:46 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{74E20832-DC0C-4E3F-A5E5-36165F9C44D0} 2012-07-09 05:31 - 2012-07-09 05:31 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{2E0C9B5E-92BA-4A8D-809F-8C56E8D295CA} 2012-07-09 05:31 - 2012-07-09 05:31 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{0BC76444-49C7-494B-AABE-AB83FD0AF36E} 2012-07-07 07:21 - 2012-07-07 07:21 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{594A7C15-C521-4544-AC98-5A0D214910E4} 2012-07-07 07:21 - 2012-07-07 07:21 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{135E59B3-D2CA-4DF1-B834-6803C98C8EEC} 2012-07-06 06:02 - 2012-07-06 06:02 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{CDE15B01-8A69-43DF-99CD-C7F8A0BCAF2A} 2012-07-06 06:02 - 2012-07-06 06:02 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{B0AA5790-4A29-4943-B3FF-6B0506446353} 2012-07-05 06:45 - 2012-07-05 06:45 - 00000257 ____A C:\Users\Wojtek\Desktop\RMF FM.pls 2012-07-05 06:16 - 2012-07-05 06:16 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{E8A20D95-D5C2-45F7-B668-4701B0ED2107} 2012-07-05 06:16 - 2012-07-05 06:16 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{9FD3AE33-93DA-4D89-ABD1-131B3DFE57CA} 2012-07-04 06:57 - 2012-07-04 06:58 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{3FD41A45-3BF1-47F7-AF58-BA3D82AB05DC} 2012-07-04 06:57 - 2012-07-04 06:57 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{DE554BC0-D2A8-4DFE-B0C8-70A39BADC9E6} 2012-07-03 05:38 - 2012-07-03 05:38 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{1F17518C-67B4-4FB4-815D-DD6B3CFBDCAB} 2012-07-03 05:38 - 2012-07-03 05:38 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{0780F42C-6F89-43F8-B63A-E47C4D91CA71} 2012-07-02 07:01 - 2012-07-02 07:01 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{355FD22B-2D1E-4A94-9436-ABD6923C22D5} 2012-07-02 07:00 - 2012-07-02 07:01 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{50B7A08A-B5E3-4CF2-BB77-4397C2E05F9E} 2012-06-30 07:12 - 2012-06-30 07:13 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{D216EC6E-FADD-4747-B379-948677C6E211} 2012-06-30 07:12 - 2012-06-30 07:12 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{5A81A5CA-9A42-42D2-A26D-449141C94830} 2012-06-29 06:26 - 2012-06-29 06:26 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{838F15F2-75FA-405F-BA2B-00B8C694B91B} 2012-06-29 06:26 - 2012-06-29 06:26 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{4B145903-E42C-44C3-82B3-7A8258D59295} 2012-06-28 06:26 - 2012-06-28 06:26 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{C2B3F8A0-26B2-4399-8C6F-45CE1B9FF025} 2012-06-28 06:26 - 2012-06-28 06:26 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{A5D4D48A-22DB-4537-897A-7C9689839832} 2012-06-27 06:07 - 2012-06-27 06:08 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{A4F73E39-C547-47A1-9C42-E16CB5350308} 2012-06-27 06:07 - 2012-06-27 06:07 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{D8EA0E42-DA64-449D-A550-E975F85B2FE1} 2012-06-26 07:02 - 2012-06-26 07:02 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{9BEDB71F-DF21-4E77-87A0-E8CFF4C6D75E} 2012-06-26 07:02 - 2012-06-26 07:02 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{69C789E9-C28B-47D7-AFA8-65F2B67D6F22} 2012-06-25 08:54 - 2012-06-25 08:54 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{9E71FA54-D049-4C11-9E5F-310D697C8384} 2012-06-25 08:54 - 2012-06-25 08:54 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{75D61147-BF9F-401B-9A3A-41B62A5054E1} 2012-06-22 09:52 - 2012-06-22 09:52 - 00000000 ____D C:\Users\Wojtek\Desktop\journey_2_the_mysterious_island_n24_pl_59127 2012-06-22 06:45 - 2012-06-22 06:45 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{64AD7AC7-B2F1-4A1C-B6C8-F9B9F429BB8A} 2012-06-22 06:44 - 2012-06-22 06:45 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{4C40C844-9842-4F27-BBF6-297B853A1152} 2012-06-21 07:16 - 2012-06-21 07:17 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{E830AFBA-0147-42A5-905B-8D09408E6366} 2012-06-21 07:16 - 2012-06-21 07:16 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{20EA65D7-C831-4764-9EA2-39FBEDADF83D} 2012-06-21 06:46 - 2012-06-02 23:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-21 06:46 - 2012-06-02 23:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-21 06:46 - 2012-06-02 23:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-21 06:46 - 2012-06-02 23:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-21 06:46 - 2012-06-02 23:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-21 06:46 - 2012-06-02 23:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-21 06:46 - 2012-06-02 23:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-21 06:46 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-21 06:46 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-06-21 06:44 - 2012-06-21 06:44 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{BAA0A312-ECFF-4BF6-A5DA-A5F14CF9995D} 2012-06-20 10:04 - 2012-06-20 10:05 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{15572D85-33D5-48F7-8725-40B2A8A2F9E7} 2012-06-20 10:04 - 2012-06-20 10:04 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{E10F8563-A330-4CBB-9E6E-2A2EAD7E8071} 2012-06-19 09:54 - 2012-06-19 09:54 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{057448EC-4C4D-4EA5-9988-C9FAE467D126} 2012-06-19 09:53 - 2012-06-19 09:54 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{1F31DB59-0AFC-4A7C-811F-229C0F95288D} 2012-06-18 07:06 - 2012-06-18 07:06 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{ABE8C84F-A36C-4653-BB85-38CC3A3FC377} 2012-06-18 07:06 - 2012-06-18 07:06 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{A6427922-BD31-410F-94AB-42AF90A12AE2} 2012-06-15 06:05 - 2012-06-15 06:05 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{C5FD1DB9-30AD-4DF0-90E1-5B2A319E278F} 2012-06-15 06:05 - 2012-06-15 06:05 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{46F4952C-86AA-4E88-8A45-77D3EAEB9AF2} 2012-06-14 06:31 - 2012-06-14 06:31 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{24824973-70DE-4E7C-BFB5-DE0423045C4C} 2012-06-14 06:31 - 2012-06-14 06:31 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{16A7B010-7E38-4D28-918C-BEAA6A655C4D} 2012-06-13 13:41 - 2012-05-18 03:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-06-13 13:41 - 2012-05-18 03:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-06-13 13:41 - 2012-05-18 03:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-06-13 13:41 - 2012-05-18 02:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-06-13 13:41 - 2012-05-18 02:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-06-13 13:41 - 2012-05-18 02:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-06-13 13:41 - 2012-05-18 02:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-06-13 13:41 - 2012-05-18 02:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-06-13 13:41 - 2012-05-18 02:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-06-13 13:41 - 2012-05-18 02:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-06-13 13:41 - 2012-05-18 02:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-06-13 13:41 - 2012-05-18 02:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-06-13 13:41 - 2012-05-18 02:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-06-13 13:41 - 2012-05-18 02:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-06-13 13:41 - 2012-05-18 00:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-06-13 13:41 - 2012-05-17 23:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-06-13 13:41 - 2012-05-17 23:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-06-13 13:41 - 2012-05-17 23:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-06-13 13:41 - 2012-05-17 23:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-06-13 13:41 - 2012-05-17 23:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-06-13 13:41 - 2012-05-17 23:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-06-13 13:41 - 2012-05-17 23:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-06-13 13:41 - 2012-05-17 23:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-06-13 13:41 - 2012-05-17 23:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-06-13 13:41 - 2012-05-17 23:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-06-13 13:41 - 2012-05-17 23:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-06-13 13:41 - 2012-05-17 23:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-06-13 13:41 - 2012-05-17 23:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-06-13 06:39 - 2012-05-15 02:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-06-13 06:39 - 2012-05-04 12:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-06-13 06:39 - 2012-05-04 11:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2012-06-13 06:39 - 2012-05-04 11:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2012-06-13 06:39 - 2012-05-01 06:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll 2012-06-13 06:39 - 2012-04-28 04:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2012-06-13 06:39 - 2012-04-26 06:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll 2012-06-13 06:39 - 2012-04-26 06:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll 2012-06-13 06:39 - 2012-04-26 06:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe 2012-06-13 06:39 - 2012-04-24 06:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2012-06-13 06:39 - 2012-04-24 06:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2012-06-13 06:39 - 2012-04-24 06:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2012-06-13 06:39 - 2012-04-24 05:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2012-06-13 06:39 - 2012-04-24 05:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2012-06-13 06:39 - 2012-04-24 05:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2012-06-13 06:39 - 2012-04-07 13:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll 2012-06-13 06:39 - 2012-04-07 12:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2012-06-13 06:37 - 2012-06-13 06:37 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{9E3B9855-4945-447F-9A46-27A3E6AB5CDC} 2012-06-13 06:37 - 2012-06-13 06:37 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{43BA40A7-A212-438C-9670-3D068C7BF12F} 2012-06-12 06:34 - 2012-06-12 06:34 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{5267EA42-FCC2-4776-A891-9902DC636751} 2012-06-12 06:34 - 2012-06-12 06:34 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{4A76BB4B-B390-4C3A-A12A-D39B97838404} 2012-06-11 05:51 - 2012-06-11 05:52 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{39A13C37-BBBA-4252-8BF5-8B314839879D} 2012-06-11 05:51 - 2012-06-11 05:51 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{039431DF-A355-41AF-9572-CE739A30B1BF} 2012-06-10 12:06 - 2012-06-10 12:06 - 00158176 ____A () C:\Users\Wojtek\Desktop\DVDShrink_downloader_by_DVDShrink.exe 2012-06-10 11:58 - 2012-06-10 11:58 - 00001031 ____A C:\Users\UpdatusUser\Desktop\DVD2one V2.lnk 2012-06-10 11:58 - 2012-06-10 11:58 - 00000000 ____D C:\Program Files (x86)\DVD2one V2 2012-06-10 11:01 - 2012-06-10 11:01 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{9CCA430D-50D6-4F2D-B803-2CA6734564F8} 2012-06-10 11:01 - 2012-06-10 11:01 - 00000000 ____D C:\Users\Wojtek\AppData\Local\{4583720A-0DBE-4E84-B590-D7F025E00D63} ============ 3 Months Modified Files ======================== 2012-07-11 01:32 - 2012-07-11 01:32 - 00035004 ____A C:\Extras.Txt 2012-07-11 01:32 - 2012-07-11 01:25 - 00074524 ____A C:\OTL.Txt 2012-07-10 18:01 - 2011-06-20 20:08 - 01548812 ____A C:\Windows\WindowsUpdate.log 2012-07-10 18:01 - 2009-07-14 05:45 - 00013776 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-07-10 18:01 - 2009-07-14 05:45 - 00013776 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-07-10 17:56 - 2012-05-29 05:56 - 00002520 ____A C:\Windows\setupact.log 2012-07-10 17:56 - 2011-09-15 07:35 - 00001044 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-07-10 17:56 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-07-10 16:32 - 2011-12-12 16:17 - 00001062 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1967453799-1416478534-2370897250-1001UA.job 2012-07-10 15:55 - 2011-09-15 07:35 - 00001048 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-07-10 06:32 - 2011-12-12 16:17 - 00001010 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1967453799-1416478534-2370897250-1001Core.job 2012-07-09 05:28 - 2009-07-14 06:08 - 00032604 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-07-05 06:45 - 2012-07-05 06:45 - 00000257 ____A C:\Users\Wojtek\Desktop\RMF FM.pls 2012-06-14 06:28 - 2009-07-14 05:45 - 00338048 ____A C:\Windows\System32\FNTCACHE.DAT 2012-06-13 13:50 - 2009-07-14 18:55 - 00787408 ____A C:\Windows\System32\perfh015.dat 2012-06-13 13:50 - 2009-07-14 18:55 - 00174110 ____A C:\Windows\System32\perfc015.dat 2012-06-13 13:50 - 2009-07-14 06:13 - 01823602 ____A C:\Windows\System32\PerfStringBackup.INI 2012-06-13 13:47 - 2011-06-20 20:51 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-06-11 05:50 - 2012-04-04 06:30 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-06-11 05:50 - 2011-06-20 21:18 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-06-10 12:06 - 2012-06-10 12:06 - 00158176 ____A () C:\Users\Wojtek\Desktop\DVDShrink_downloader_by_DVDShrink.exe 2012-06-10 11:58 - 2012-06-10 11:58 - 00001031 ____A C:\Users\UpdatusUser\Desktop\DVD2one V2.lnk 2012-06-10 10:47 - 2012-04-20 06:44 - 00001028 ____A C:\Users\Wojtek\Desktop\Dropbox.lnk 2012-06-02 23:19 - 2012-06-21 06:46 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-02 23:19 - 2012-06-21 06:46 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-02 23:19 - 2012-06-21 06:46 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-02 23:19 - 2012-06-21 06:46 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-02 23:19 - 2012-06-21 06:46 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-02 23:15 - 2012-06-21 06:46 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-02 23:15 - 2012-06-21 06:46 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-02 14:19 - 2012-06-21 06:46 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-02 14:15 - 2012-06-21 06:46 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-05-30 18:33 - 2012-05-30 18:33 - 17181648 ____A (ashampoo GmbH & Co. KG ) C:\Users\Wojtek\Desktop\ashampoo_burning_studio_6_free_6.80_4312.exe 2012-05-29 05:56 - 2012-05-29 05:56 - 00000000 ____A C:\Windows\setuperr.log 2012-05-29 05:56 - 2011-06-21 07:33 - 00012926 ____A C:\Windows\PFRO.log 2012-05-28 05:56 - 2012-05-28 05:56 - 00081488 ____A (AppWork UG (haftungsbeschränkt)) C:\Users\Wojtek\Desktop\WebInstaller.exe 2012-05-18 03:47 - 2012-06-13 13:41 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-05-18 03:16 - 2012-06-13 13:41 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-05-18 03:06 - 2012-06-13 13:41 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-05-18 02:59 - 2012-06-13 13:41 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-05-18 02:59 - 2012-06-13 13:41 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-05-18 02:58 - 2012-06-13 13:41 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-05-18 02:58 - 2012-06-13 13:41 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-05-18 02:56 - 2012-06-13 13:41 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-05-18 02:55 - 2012-06-13 13:41 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-05-18 02:55 - 2012-06-13 13:41 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-05-18 02:54 - 2012-06-13 13:41 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-05-18 02:51 - 2012-06-13 13:41 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-05-18 02:51 - 2012-06-13 13:41 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-05-18 02:47 - 2012-06-13 13:41 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-05-18 00:11 - 2012-06-13 13:41 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-05-17 23:48 - 2012-06-13 13:41 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-05-17 23:45 - 2012-06-13 13:41 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-05-17 23:36 - 2012-06-13 13:41 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-05-17 23:35 - 2012-06-13 13:41 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-05-17 23:35 - 2012-06-13 13:41 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-05-17 23:33 - 2012-06-13 13:41 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-05-17 23:31 - 2012-06-13 13:41 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-05-17 23:29 - 2012-06-13 13:41 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-05-17 23:29 - 2012-06-13 13:41 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-05-17 23:27 - 2012-06-13 13:41 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-05-17 23:25 - 2012-06-13 13:41 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-05-17 23:24 - 2012-06-13 13:41 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-05-17 23:20 - 2012-06-13 13:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-05-15 02:32 - 2012-06-13 06:39 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-05-04 12:06 - 2012-06-13 06:39 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-05-04 11:03 - 2012-06-13 06:39 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2012-05-04 11:03 - 2012-06-13 06:39 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2012-05-04 09:14 - 2012-05-04 09:13 - 00000268 ____A C:\Users\Wojtek\Desktop\MediaCoder-x64-0.8.12.5240.zip 2012-05-02 08:18 - 2011-06-20 21:26 - 00001912 ____A C:\Windows\epplauncher.mif 2012-05-02 08:18 - 2011-06-20 21:25 - 01823498 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2012-05-01 06:40 - 2012-06-13 06:39 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll 2012-04-28 04:55 - 2012-06-13 06:39 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2012-04-26 06:41 - 2012-06-13 06:39 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll 2012-04-26 06:41 - 2012-06-13 06:39 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll 2012-04-26 06:34 - 2012-06-13 06:39 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe 2012-04-24 06:37 - 2012-06-13 06:39 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2012-04-24 06:37 - 2012-06-13 06:39 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2012-04-24 06:37 - 2012-06-13 06:39 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2012-04-24 05:36 - 2012-06-13 06:39 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2012-04-24 05:36 - 2012-06-13 06:39 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2012-04-24 05:36 - 2012-06-13 06:39 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2012-04-20 15:48 - 2012-04-20 15:48 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe 2012-04-20 15:48 - 2012-04-20 15:48 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe 2012-04-20 15:48 - 2012-04-20 15:48 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe 2012-04-20 15:48 - 2011-06-20 21:37 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll 2012-04-13 06:30 - 2011-08-11 07:46 - 00041952 ____A C:\Windows\DirectX.log ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ========================= Memory info ====================== Percentage of memory in use: 11% Total physical RAM: 6142.49 MB Available physical RAM: 5428.13 MB Total Pagefile: 6140.64 MB Available Pagefile: 5417.27 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB ======================= Partitions ========================= 2 Drive c: (System) (Fixed) (Total:48.83 GB) (Free:5.29 GB) NTFS ==>[Drive with boot components (obtained from BCD)] 3 Drive d: (Dane#4) (Fixed) (Total:117.19 GB) (Free:34.5 GB) NTFS 4 Drive e: (Dane#2) (Fixed) (Total:139 GB) (Free:65.76 GB) NTFS 5 Drive f: (Dane#3) (Fixed) (Total:138.94 GB) (Free:27.44 GB) NTFS 6 Drive g: (Video) (Fixed) (Total:115.69 GB) (Free:9.42 GB) NTFS 7 Drive h: (Dane#1) (Fixed) (Total:139 GB) (Free:91.27 GB) NTFS 14 Drive o: () (Removable) (Total:3.82 GB) (Free:0.87 GB) FAT32 15 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Nr dysku Stan Rozmiar Wolne Dyn GPT -------- ------------- ------- ------- --- --- Dysk 0 Online 465 GB 1024 KB Dysk 1 Online 232 GB 1024 KB Dysk 2 Brak no˜nika 0 B 0 B Dysk 3 Brak no˜nika 0 B 0 B Dysk 4 Brak no˜nika 0 B 0 B Dysk 5 Brak no˜nika 0 B 0 B Dysk 6 Online 3919 MB 0 B Partitions of Disk 0: =============== Partycja ### Typ Rozmiar Przesuni©cie ------------- ---------------- ------- ------------ Partycja 1 Podstawowy 48 GB 31 KB Partycja 2 Podstawowy 138 GB 48 GB Partycja 0 Rozszerzony 277 GB 187 GB Partycja 3 Logiczny 138 GB 187 GB Partycja 4 Logiczny 138 GB 326 GB ================================================================================== Disk: 0 Partycja 1 Typ : 07 Ukryta : Nie Aktywna : Tak Przesuni©cie w bajtach: 32256 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 2 C System NTFS Partycja 48 GB Zdrowy ================================================================================== Disk: 0 Partycja 2 Typ : 07 Ukryta : Nie Aktywna : Nie Przesuni©cie w bajtach: 52427934720 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 3 H Dane#1 NTFS Partycja 138 GB Zdrowy ================================================================================== Disk: 0 Partycja 3 Typ : 07 Ukryta : Nie Aktywna : Nie Przesuni©cie w bajtach: 201675672576 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 4 E Dane#2 NTFS Partycja 138 GB Zdrowy ================================================================================== Disk: 0 Partycja 4 Typ : 07 Ukryta : Nie Aktywna : Nie Przesuni©cie w bajtach: 350923378176 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 5 F Dane#3 NTFS Partycja 138 GB Zdrowy ================================================================================== Partitions of Disk 1: =============== Partycja ### Typ Rozmiar Przesuni©cie ------------- ---------------- ------- ------------ Partycja 1 Podstawowy 117 GB 31 KB Partycja 0 Rozszerzony 115 GB 117 GB Partycja 2 Logiczny 115 GB 117 GB ================================================================================== Disk: 1 Partycja 1 Typ : 07 Ukryta : Nie Aktywna : Tak Przesuni©cie w bajtach: 32256 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 6 D Dane#4 NTFS Partycja 117 GB Zdrowy ================================================================================== Disk: 1 Partycja 2 Typ : 07 Ukryta : Nie Aktywna : Nie Przesuni©cie w bajtach: 125830365696 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 7 G Video NTFS Partycja 115 GB Zdrowy ================================================================================== Partitions of Disk 6: =============== Partycja ### Typ Rozmiar Przesuni©cie ------------- ---------------- ------- ------------ Partycja 1 Podstawowy 3919 MB 31 KB ================================================================================== Disk: 6 Partycja 1 Typ : 0B Ukryta : Nie Aktywna : Tak Przesuni©cie w bajtach: 32256 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 12 O FAT32 Wymienny 3919 MB Zdrowy ================================================================================== ========================================================== Last Boot: 2012-07-09 07:28 ======================= End Of Log ==========================