Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013 Ran by Marta (administrator) on 04-07-2013 09:57:14 Running from C:\Users\Marta\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Advanced Micro Devices, Inc.) c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Sony Corporation) c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe (Spotify Ltd) C:\Users\Marta\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Advanced Micro Devices Inc.) c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update Common\VUAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAdmin.exe (Sony Corporation) C:\Program Files\Sony\VAIO Improvement\vim.exe (Sony Corporation) C:\Program Files\Sony\VAIO Improvement\vim.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (OldTimer Tools) C:\Users\Marta\Desktop\OTL.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SONYAPO [1158248 2012-04-12] (Realtek Semiconductor) HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [1021056 2012-03-29] (Atheros Communications) HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [801408 2012-03-29] (Atheros Commnucations) HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2890000 2012-04-12] (Synaptics Incorporated) HKLM\...\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1497816 2013-06-18] (COMODO) HKCU\...\Run: [ALLUpdate] "C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep" [2991616 2012-10-08] (ALLCinema) HKCU\...\Run: [Spotify Web Helper] "C:\Users\Marta\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1105408 2013-05-02] (Spotify Ltd) HKCU\...\Run: [Yontoo Desktop] "C:\Users\Marta\AppData\Roaming\Yontoo\YontooDesktop.exe" [42784 2013-05-01] (Yontoo LLC) HKCU\...\Run: [GoogleChromeAutoLaunch_FEFEFDA8D5F235DE80C0731778E9C6D5] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window [825808 2013-06-15] (Google Inc.) HKLM-x32\...\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [343168 2012-03-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [60552 2011-09-20] (Sony Corporation) HKLM-x32\...\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [693608 2012-02-21] (Sony Corporation) HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-02-20] (Apple Inc.) HKLM-x32\...\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin [611712 2008-08-14] (Adobe Systems Incorporated) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=121845&babsrc=HP_ss_gin2g&mntrId=2AD1A64BF5C886AF HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.pu-results.info/?l=1&q={searchTerms}&pid=34&r=2013/02/22&hid=420275175&lg=EN&cc=PL HKCU SearchScopes: DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=121845&babsrc=SP_ss_gin2g&mntrId=2AD1A64BF5C886AF SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=121845&babsrc=SP_ss_gin2g&mntrId=2AD1A64BF5C886AF SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.pu-results.info/?l=1&q={searchTerms}&pid=34&r=2013/02/22&hid=420275175&lg=EN&cc=PL BHO: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Marta\AppData\Roaming\Complitly\64\Complitly64.dll (SimplyGen) BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20121012191417.dll No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Marta\AppData\Roaming\Complitly\Complitly.dll (SimplyGen) BHO-x32: Browse2save - {776339FC-C55F-E3A8-67CD-1F793A747BA6} - C:\ProgramData\Browse2save\5127616505498.dll No File BHO-x32: SelectionLinks - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - C:\Program Files (x86)\OApps\SelectionLinks.dll No File BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20121012191418.dll No File BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: IplexToALLPlayer - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\PROGRA~2\ALLPLA~1\Iplex\IPLEXT~1.DLL (ALLCinema Ltd.) BHO-x32: Yontoo - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] C:\Program Files (x86)\Common Files\McAfee\SystemCore FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK Chrome: ======= CHR Extension: (Select Links App) - C:\Users\Marta\AppData\Local\Google\Chrome\User Data\Default\Extensions\anogenbiecegmkpcfmpjmmmopmhpijim\4.3_0 ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AMD FUEL Service; c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-03-06] (Advanced Micro Devices, Inc.) R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6181504 2013-06-18] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [158936 2013-06-18] (COMODO) S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [112256 2012-03-21] (Atheros Communication Inc.) R2 PMBDeviceInfoProvider; c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [473960 2012-02-21] (Sony Corporation) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [260768 2011-11-30] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) S4 Yontoo Desktop Updater; C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe [23552 2013-05-01] (Microsoft) R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [163456 2012-03-29] (Atheros) S2 BrowserProtect; C:\ProgramData\BrowserProtect\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [x] S2 SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [x] ==================== Drivers (Whitelisted) ==================== S3 Andbus; C:\Windows\System32\DRIVERS\lgandbus64.sys [19456 2010-01-25] (LG Electronics Inc.) S3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag64.sys [27648 2010-01-25] (LG Electronics Inc.) S3 AndGps; C:\Windows\System32\DRIVERS\lgandgps64.sys [27136 2010-01-25] (LG Electronics Inc.) S3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem64.sys [33792 2010-01-25] (LG Electronics Inc.) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2013-06-18] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [708632 2013-06-18] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [48360 2013-06-18] (COMODO) R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [96800 2013-06-18] (COMODO) S3 lehidmini; C:\Windows\system32\drivers\leath_hid.sys [36608 2012-03-29] (Atheros) S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver.sys [21264 2012-04-12] (Synaptics Incorporated) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [x] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [x] S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-04 09:56 - 2013-07-04 09:56 - 00000000 ____D C:\FRST 2013-07-04 09:53 - 2013-07-04 09:53 - 01934636 ____A (Farbar) C:\Users\Marta\Desktop\FRST64.exe 2013-07-04 09:46 - 2013-07-04 09:46 - 00602112 ____A (OldTimer Tools) C:\Users\Marta\Desktop\OTL.exe 2013-07-04 02:30 - 2013-07-04 02:30 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-07-04 02:30 - 2013-07-04 02:30 - 00000000 ____D C:\Program Files\CCleaner 2013-07-04 02:27 - 2013-07-04 02:27 - 00001228 ____A C:\Users\Marta\Downloads\Revo Uninstaller.lnk 2013-07-04 02:04 - 2013-07-04 02:27 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-07-04 01:28 - 2013-07-04 01:28 - 00038583 ____A C:\ComboFix.txt 2013-07-04 00:02 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-07-04 00:02 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-07-04 00:02 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-07-04 00:02 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-07-04 00:02 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-07-04 00:02 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-07-04 00:02 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-07-04 00:02 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-07-03 23:58 - 2013-07-04 01:28 - 00000000 ____D C:\Qoobox 2013-07-03 23:56 - 2013-07-04 01:20 - 00000000 ____D C:\Windows\erdnt 2013-07-03 23:19 - 2013-07-03 23:19 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-07-03 23:19 - 2013-07-03 23:19 - 00000000 ____A C:\autoexec.bat 2013-07-03 23:17 - 2013-07-04 01:50 - 00000000 ____D C:\Windows\BCD5545077AC4347B24F654B1189F8D4.TMP 2013-07-03 21:38 - 2013-07-04 01:34 - 00028226 ____A C:\Windows\System32\Drivers\fvstore.dat 2013-07-03 21:38 - 2013-07-03 21:38 - 00000000 ___HD C:\VTRoot 2013-07-03 20:33 - 2013-07-03 20:33 - 00001888 ____A C:\Users\Public\Desktop\COMODO Internet Security.lnk 2013-07-03 20:32 - 2013-07-04 09:55 - 00880160 ____A C:\Windows\System32\Drivers\sfi.dat 2013-07-03 20:31 - 2013-07-03 20:33 - 00000000 ___SD C:\ProgramData\Shared Space 2013-07-03 20:31 - 2013-07-03 20:33 - 00000000 ____D C:\ProgramData\Comodo 2013-07-03 20:31 - 2013-07-03 20:31 - 00000000 ____D C:\ProgramData\Comodo Downloader 2013-07-03 20:31 - 2013-07-03 20:31 - 00000000 ____D C:\Program Files\COMODO 2013-07-01 22:24 - 2013-07-01 22:24 - 00015814 ____A C:\Users\Marta\Downloads\3534_9c31_500.jpeg 2013-06-27 10:39 - 2013-06-27 10:39 - 00033135 ____A C:\Users\Marta\Documents\0881_e2ae_480.jpeg 2013-06-23 22:25 - 2013-05-28 15:05 - 00163328 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerUpdateService.exe 2013-06-23 22:24 - 2013-06-23 22:24 - 00000000 ____D C:\Users\Marta\AppData\Roaming\File Scout 2013-06-18 16:16 - 2013-06-18 16:16 - 00708632 ____A (COMODO) C:\Windows\System32\Drivers\cmdguard.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00096800 ____A (COMODO) C:\Windows\System32\Drivers\inspect.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00048360 ____A (COMODO) C:\Windows\System32\Drivers\cmdhlp.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00023168 ____A (COMODO) C:\Windows\System32\Drivers\cmderd.sys 2013-06-18 16:15 - 2013-06-18 16:15 - 00437688 ____A (COMODO) C:\Windows\System32\guard64.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00348584 ____A (COMODO) C:\Windows\SysWOW64\guard32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00344792 ____A (COMODO) C:\Windows\System32\cmdvrt64.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00278232 ____A (COMODO) C:\Windows\SysWOW64\cmdvrt32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00045784 ____A (COMODO) C:\Windows\System32\cmdkbd64.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00043216 ____A (COMODO) C:\Windows\System32\cmdcsr.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00040664 ____A (COMODO) C:\Windows\SysWOW64\cmdkbd32.dll 2013-06-18 03:01 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-18 03:01 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-18 03:01 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-18 03:01 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-18 03:01 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-18 03:01 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-18 03:01 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-18 03:01 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-18 03:01 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-18 03:01 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-18 03:01 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-18 03:01 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-13 03:03 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-13 03:03 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-13 03:03 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-13 03:03 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-13 03:03 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-13 03:03 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-13 03:03 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-13 03:03 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-13 03:03 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-13 03:03 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-13 03:03 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-13 03:03 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-12 16:55 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll 2013-06-12 16:55 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-06-12 16:55 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-12 16:55 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-12 16:55 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-12 16:54 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-12 16:54 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-12 16:54 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-12 16:54 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-12 16:54 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-12 16:54 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-12 16:54 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-12 16:54 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-12 16:54 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-12 16:54 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-12 16:54 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-12 16:54 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-12 16:53 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-12 16:53 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-08 18:24 - 2013-06-08 18:24 - 00001097 ____A C:\Users\Marta\Desktop\Adobe Photoshop CS4.lnk 2013-06-08 17:45 - 2013-06-08 17:45 - 00000000 ____D C:\Users\Marta\Documents\Adobe Scripts 2013-06-08 17:44 - 2013-06-08 17:44 - 00000000 ____D C:\ProgramData\FLEXnet 2013-06-08 17:22 - 2013-06-08 17:22 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-06-08 17:20 - 2013-06-08 17:20 - 00001805 ____A C:\Users\Marta\Desktop\Opera.lnk 2013-06-08 17:20 - 2013-06-08 17:20 - 00000000 ____D C:\Program Files (x86)\Adobe Media Player 2013-06-08 17:09 - 2013-06-08 17:38 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-06-08 17:09 - 2013-06-08 17:09 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared 2013-06-08 16:52 - 2013-06-08 16:52 - 00000000 ____D C:\Users\Marta\Documents\Adobe Photoshop CS4 + Keygen 2013-06-08 16:01 - 2013-06-08 16:34 - 1339820827 ____A C:\Users\Marta\Downloads\Adobe Photoshop CS4 + Keygen.rar 2013-06-08 12:31 - 2013-06-08 12:31 - 00023027 ____A C:\Users\Marta\AppData\Local\recently-used.xbel 2013-06-07 20:29 - 2013-06-07 20:29 - 00609336 ____A C:\Users\Marta\Downloads\setup.exe 2013-06-07 18:50 - 2013-06-07 18:50 - 00108004 ___AH C:\Windows\SysWOW64\mlfcache.dat 2013-06-07 18:47 - 2013-06-07 18:48 - 00000000 ____D C:\Program Files (x86)\Safari 2013-06-07 18:45 - 2013-06-07 18:45 - 00064293 ____A C:\Users\Marta\Documents\bookmarks_07.06.2013.html 2013-06-07 18:44 - 2013-06-07 18:44 - 00000000 ____D C:\Users\Marta\AppData\Local\Downloaded Installations 2013-06-07 18:43 - 2013-06-07 18:43 - 38494576 ____A (Apple Inc.) C:\Users\Marta\Downloads\SafariSetup.exe 2013-06-07 18:41 - 2013-06-07 18:41 - 00607816 ____A C:\Users\Marta\Downloads\Safari(13196).exe 2013-06-07 17:34 - 2013-06-07 17:34 - 00382331 ____A C:\Users\Marta\Downloads\1.3.2 (1) (2).crx 2013-06-07 17:31 - 2013-06-07 17:31 - 00382331 ____A C:\Users\Marta\Downloads\Niepotwierdzony 684217.crdownload 2013-06-07 17:31 - 2013-06-07 17:31 - 00382331 ____A C:\Users\Marta\Downloads\1.3.2 (1) (1).crx 2013-06-07 17:27 - 2013-06-07 17:27 - 00382331 ____A C:\Users\Marta\Downloads\1.3.2.crx 2013-06-07 16:31 - 2013-06-07 16:31 - 00003522 ____A C:\Users\Marta\Downloads\1370615499_359.data 2013-06-07 15:48 - 2013-06-07 15:48 - 00000000 ____D C:\Program Files (x86)\Opera 2013-06-07 15:46 - 2013-06-07 15:46 - 13168216 ____A (Opera Software ASA) C:\Users\Marta\Downloads\Opera_1215_int_Setup.exe 2013-06-07 12:54 - 2013-06-07 12:55 - 02499652 ____A C:\Users\Marta\Downloads\retoryka.rar 2013-06-06 19:46 - 2013-06-06 19:46 - 00000000 ____D C:\Users\Marta\AppData\Local\SlimWare Utilities Inc 2013-06-06 19:45 - 2013-06-06 19:47 - 00000000 ____D C:\Program Files (x86)\SlimComputer 2013-06-06 19:45 - 2013-06-06 19:45 - 00002469 ____A C:\Users\Public\Desktop\SlimComputer.lnk ==================== One Month Modified Files and Folders ======= 2013-07-04 09:56 - 2013-07-04 09:56 - 00000000 ____D C:\FRST 2013-07-04 09:55 - 2013-07-03 20:32 - 00880160 ____A C:\Windows\System32\Drivers\sfi.dat 2013-07-04 09:53 - 2013-07-04 09:53 - 01934636 ____A (Farbar) C:\Users\Marta\Desktop\FRST64.exe 2013-07-04 09:46 - 2013-07-04 09:46 - 00602112 ____A (OldTimer Tools) C:\Users\Marta\Desktop\OTL.exe 2013-07-04 09:25 - 2013-05-25 15:15 - 00001046 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-04 09:25 - 2012-05-08 07:39 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-04 02:32 - 2013-07-04 02:04 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-07-04 02:30 - 2013-07-04 02:30 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-07-04 02:30 - 2013-07-04 02:30 - 00000000 ____D C:\Program Files\CCleaner 2013-07-04 02:27 - 2013-07-04 02:27 - 00001228 ____A C:\Users\Marta\Downloads\Revo Uninstaller.lnk 2013-07-04 01:59 - 2013-05-03 17:54 - 00000000 ____D C:\Program Files (x86)\Yontoo 2013-07-04 01:50 - 2013-07-03 23:17 - 00000000 ____D C:\Windows\BCD5545077AC4347B24F654B1189F8D4.TMP 2013-07-04 01:46 - 2013-02-22 14:17 - 00000000 ____D C:\ProgramData\InstallMate 2013-07-04 01:44 - 2009-07-14 06:45 - 00020928 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-04 01:44 - 2009-07-14 06:45 - 00020928 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-04 01:41 - 2012-10-12 17:54 - 01162208 ____A C:\Windows\WindowsUpdate.log 2013-07-04 01:36 - 2013-05-03 17:54 - 00000000 ____D C:\Users\Marta\AppData\Roaming\Yontoo 2013-07-04 01:35 - 2013-05-25 15:15 - 00001042 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-04 01:35 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-04 01:35 - 2009-07-14 06:51 - 00070305 ____A C:\Windows\setupact.log 2013-07-04 01:34 - 2013-07-03 21:38 - 00028226 ____A C:\Windows\System32\Drivers\fvstore.dat 2013-07-04 01:34 - 2010-11-21 05:47 - 00037110 ____A C:\Windows\PFRO.log 2013-07-04 01:31 - 2012-11-01 19:31 - 00000000 ____D C:\Users\Marta\AppData\Roaming\uTorrent 2013-07-04 01:28 - 2013-07-04 01:28 - 00038583 ____A C:\ComboFix.txt 2013-07-04 01:28 - 2013-07-03 23:58 - 00000000 ____D C:\Qoobox 2013-07-04 01:20 - 2013-07-03 23:56 - 00000000 ____D C:\Windows\erdnt 2013-07-04 01:17 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-07-03 23:19 - 2013-07-03 23:19 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-07-03 23:19 - 2013-07-03 23:19 - 00000000 ____A C:\autoexec.bat 2013-07-03 23:11 - 2013-03-08 22:28 - 00000000 ____D C:\Users\Marta\AppData\Local\ChomikBox 2013-07-03 21:38 - 2013-07-03 21:38 - 00000000 ___HD C:\VTRoot 2013-07-03 21:25 - 2012-10-14 15:41 - 00000000 ____D C:\Users\Marta\Desktop\SŁOWO 2013-07-03 20:33 - 2013-07-03 20:33 - 00001888 ____A C:\Users\Public\Desktop\COMODO Internet Security.lnk 2013-07-03 20:33 - 2013-07-03 20:31 - 00000000 ___SD C:\ProgramData\Shared Space 2013-07-03 20:33 - 2013-07-03 20:31 - 00000000 ____D C:\ProgramData\Comodo 2013-07-03 20:31 - 2013-07-03 20:31 - 00000000 ____D C:\ProgramData\Comodo Downloader 2013-07-03 20:31 - 2013-07-03 20:31 - 00000000 ____D C:\Program Files\COMODO 2013-07-03 20:06 - 2013-03-08 22:29 - 00000000 ____D C:\Users\Marta\.gstreamer-0.10 2013-07-03 20:05 - 2012-05-08 07:17 - 00000000 ____D C:\ProgramData\McAfee 2013-07-03 19:47 - 2009-07-14 07:08 - 00032574 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-03 19:26 - 2012-10-18 10:02 - 00000000 ____D C:\Users\Marta\AppData\Roaming\AIMP3 2013-07-01 22:24 - 2013-07-01 22:24 - 00015814 ____A C:\Users\Marta\Downloads\3534_9c31_500.jpeg 2013-06-29 14:57 - 2012-10-18 09:23 - 00000000 ____D C:\Users\Marta\AppData\Local\Last.fm 2013-06-28 15:04 - 2011-12-07 04:14 - 02193164 ____A C:\Windows\System32\perfh015.dat 2013-06-28 15:04 - 2011-12-07 04:14 - 00663342 ____A C:\Windows\System32\perfc015.dat 2013-06-28 15:04 - 2009-07-14 07:13 - 00006484 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-27 13:55 - 2013-06-01 16:31 - 00000000 ____D C:\Users\Marta\Desktop\semestr II 2013-06-27 10:39 - 2013-06-27 10:39 - 00033135 ____A C:\Users\Marta\Documents\0881_e2ae_480.jpeg 2013-06-26 19:41 - 2012-10-14 13:15 - 00000000 ___RD C:\Users\Marta\Desktop\STUDIA 2013-06-24 00:28 - 2013-05-25 15:16 - 00002143 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-06-23 22:24 - 2013-06-23 22:24 - 00000000 ____D C:\Users\Marta\AppData\Roaming\File Scout 2013-06-18 16:16 - 2013-06-18 16:16 - 00708632 ____A (COMODO) C:\Windows\System32\Drivers\cmdguard.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00096800 ____A (COMODO) C:\Windows\System32\Drivers\inspect.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00048360 ____A (COMODO) C:\Windows\System32\Drivers\cmdhlp.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00023168 ____A (COMODO) C:\Windows\System32\Drivers\cmderd.sys 2013-06-18 16:15 - 2013-06-18 16:15 - 00437688 ____A (COMODO) C:\Windows\System32\guard64.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00348584 ____A (COMODO) C:\Windows\SysWOW64\guard32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00344792 ____A (COMODO) C:\Windows\System32\cmdvrt64.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00278232 ____A (COMODO) C:\Windows\SysWOW64\cmdvrt32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00045784 ____A (COMODO) C:\Windows\System32\cmdkbd64.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00043216 ____A (COMODO) C:\Windows\System32\cmdcsr.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00040664 ____A (COMODO) C:\Windows\SysWOW64\cmdkbd32.dll 2013-06-18 03:21 - 2012-10-14 13:10 - 00000000 ____D C:\Users\Marta\AppData\Roaming\SoftGrid Client 2013-06-13 04:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-06-12 20:20 - 2012-05-08 07:39 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-12 20:20 - 2012-05-08 07:39 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-08 18:49 - 2012-11-01 19:34 - 00000000 ____D C:\Program Files (x86)\uTorrent 2013-06-08 18:36 - 2012-12-09 22:17 - 00000000 ____D C:\Program Files\Adobe 2013-06-08 18:24 - 2013-06-08 18:24 - 00001097 ____A C:\Users\Marta\Desktop\Adobe Photoshop CS4.lnk 2013-06-08 18:23 - 2012-10-13 18:14 - 00000000 ____D C:\Users\Marta\AppData\Local\Adobe 2013-06-08 18:17 - 2012-10-22 11:53 - 00000000 ____D C:\Users\Marta\AppData\Local\CrashDumps 2013-06-08 18:14 - 2012-10-12 18:07 - 00000000 ____D C:\Users\Marta\AppData\Roaming\Adobe 2013-06-08 18:13 - 2013-03-08 00:18 - 00000000 ____D C:\ProgramData\BrowserProtect 2013-06-08 18:13 - 2009-07-14 06:45 - 04909112 ____A C:\Windows\System32\FNTCACHE.DAT 2013-06-08 17:45 - 2013-06-08 17:45 - 00000000 ____D C:\Users\Marta\Documents\Adobe Scripts 2013-06-08 17:44 - 2013-06-08 17:44 - 00000000 ____D C:\ProgramData\FLEXnet 2013-06-08 17:44 - 2012-10-12 18:00 - 00075184 ____A C:\Users\Marta\AppData\Local\GDIPFONTCACHEV1.DAT 2013-06-08 17:38 - 2013-06-08 17:09 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-06-08 17:34 - 2012-05-08 07:38 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-06-08 17:33 - 2012-05-08 07:38 - 00000000 ____D C:\ProgramData\Adobe 2013-06-08 17:22 - 2013-06-08 17:22 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-06-08 17:20 - 2013-06-08 17:20 - 00001805 ____A C:\Users\Marta\Desktop\Opera.lnk 2013-06-08 17:20 - 2013-06-08 17:20 - 00000000 ____D C:\Program Files (x86)\Adobe Media Player 2013-06-08 17:20 - 2013-01-10 21:10 - 00000000 ____D C:\Users\Marta\.gimp-2.8 2013-06-08 17:09 - 2013-06-08 17:09 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared 2013-06-08 16:52 - 2013-06-08 16:52 - 00000000 ____D C:\Users\Marta\Documents\Adobe Photoshop CS4 + Keygen 2013-06-08 16:34 - 2013-06-08 16:01 - 1339820827 ____A C:\Users\Marta\Downloads\Adobe Photoshop CS4 + Keygen.rar 2013-06-08 16:08 - 2013-06-18 03:01 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-08 16:07 - 2013-06-18 03:01 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-08 16:06 - 2013-06-18 03:01 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-08 16:06 - 2013-06-18 03:01 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-08 16:06 - 2013-06-18 03:01 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-08 14:28 - 2013-06-18 03:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-08 13:42 - 2013-06-18 03:01 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-08 13:40 - 2013-06-18 03:01 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-08 13:40 - 2013-06-18 03:01 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-08 13:40 - 2013-06-18 03:01 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-08 13:40 - 2013-06-18 03:01 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-08 13:13 - 2013-06-18 03:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-08 12:31 - 2013-06-08 12:31 - 00023027 ____A C:\Users\Marta\AppData\Local\recently-used.xbel 2013-06-07 20:40 - 2012-10-12 19:22 - 00000000 ____D C:\Users\Marta\AppData\Local\Google 2013-06-07 20:29 - 2013-06-07 20:29 - 00609336 ____A C:\Users\Marta\Downloads\setup.exe 2013-06-07 18:52 - 2013-04-19 12:25 - 00000000 ____D C:\Users\Marta\AppData\Local\Apple Computer 2013-06-07 18:50 - 2013-06-07 18:50 - 00108004 ___AH C:\Windows\SysWOW64\mlfcache.dat 2013-06-07 18:49 - 2013-04-19 12:25 - 00000000 ____D C:\Users\Marta\AppData\Roaming\Apple Computer 2013-06-07 18:48 - 2013-06-07 18:47 - 00000000 ____D C:\Program Files (x86)\Safari 2013-06-07 18:45 - 2013-06-07 18:45 - 00064293 ____A C:\Users\Marta\Documents\bookmarks_07.06.2013.html 2013-06-07 18:44 - 2013-06-07 18:44 - 00000000 ____D C:\Users\Marta\AppData\Local\Downloaded Installations 2013-06-07 18:43 - 2013-06-07 18:43 - 38494576 ____A (Apple Inc.) C:\Users\Marta\Downloads\SafariSetup.exe 2013-06-07 18:41 - 2013-06-07 18:41 - 00607816 ____A C:\Users\Marta\Downloads\Safari(13196).exe 2013-06-07 17:34 - 2013-06-07 17:34 - 00382331 ____A C:\Users\Marta\Downloads\1.3.2 (1) (2).crx 2013-06-07 17:31 - 2013-06-07 17:31 - 00382331 ____A C:\Users\Marta\Downloads\Niepotwierdzony 684217.crdownload 2013-06-07 17:31 - 2013-06-07 17:31 - 00382331 ____A C:\Users\Marta\Downloads\1.3.2 (1) (1).crx 2013-06-07 17:27 - 2013-06-07 17:27 - 00382331 ____A C:\Users\Marta\Downloads\1.3.2.crx 2013-06-07 16:31 - 2013-06-07 16:31 - 00003522 ____A C:\Users\Marta\Downloads\1370615499_359.data 2013-06-07 15:49 - 2013-02-08 23:00 - 00000000 ____D C:\Users\Marta\AppData\Roaming\Opera 2013-06-07 15:49 - 2013-02-08 23:00 - 00000000 ____D C:\Users\Marta\AppData\Local\Opera 2013-06-07 15:48 - 2013-06-07 15:48 - 00000000 ____D C:\Program Files (x86)\Opera 2013-06-07 15:46 - 2013-06-07 15:46 - 13168216 ____A (Opera Software ASA) C:\Users\Marta\Downloads\Opera_1215_int_Setup.exe 2013-06-07 15:13 - 2013-02-08 22:59 - 00000000 ____D C:\Program Files\Opera x64 2013-06-07 14:58 - 2012-05-08 07:11 - 00000000 ____D C:\Program Files (x86)\Sony 2013-06-07 14:58 - 2012-05-08 07:01 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-06-07 14:58 - 2012-05-08 06:52 - 00000000 ____D C:\ProgramData\Sony Corporation 2013-06-07 12:55 - 2013-06-07 12:54 - 02499652 ____A C:\Users\Marta\Downloads\retoryka.rar 2013-06-06 20:00 - 2012-05-08 08:10 - 00000000 ____D C:\Program Files (x86)\WildGames 2013-06-06 19:55 - 2012-11-01 15:01 - 00000000 ____D C:\Users\Marta\AppData\Roaming\WildTangent 2013-06-06 19:55 - 2012-05-08 08:09 - 00000000 ____D C:\ProgramData\WildTangent 2013-06-06 19:47 - 2013-06-06 19:45 - 00000000 ____D C:\Program Files (x86)\SlimComputer 2013-06-06 19:46 - 2013-06-06 19:46 - 00000000 ____D C:\Users\Marta\AppData\Local\SlimWare Utilities Inc 2013-06-06 19:45 - 2013-06-06 19:45 - 00002469 ____A C:\Users\Public\Desktop\SlimComputer.lnk 2013-06-05 00:16 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-26 02:16 ==================== End Of Log ============================