Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013 Ran by Marta (administrator) on 04-07-2013 14:31:22 Running from C:\Users\Marta\Desktop\Programy Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Advanced Micro Devices, Inc.) c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Sony Corporation) c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe (ALLCinema) C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe (Spotify Ltd) C:\Users\Marta\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Advanced Micro Devices Inc.) c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update Common\VUAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAdmin.exe (Sony Corporation) C:\Program Files\Sony\VAIO Improvement\vim.exe (Sony Corporation) C:\Program Files\Sony\VAIO Improvement\vim.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SONYAPO [1158248 2012-04-12] (Realtek Semiconductor) HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [1021056 2012-03-29] (Atheros Communications) HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [801408 2012-03-29] (Atheros Commnucations) HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2890000 2012-04-12] (Synaptics Incorporated) HKLM\...\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1497816 2013-06-18] (COMODO) HKCU\...\Run: [ALLUpdate] "C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep" [2991616 2012-10-08] (ALLCinema) HKCU\...\Run: [Spotify Web Helper] "C:\Users\Marta\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1105408 2013-05-02] (Spotify Ltd) HKLM-x32\...\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [343168 2012-03-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [60552 2011-09-20] (Sony Corporation) HKLM-x32\...\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [693608 2012-02-21] (Sony Corporation) HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-02-20] (Apple Inc.) HKLM-x32\...\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin [611712 2008-08-14] (Adobe Systems Incorporated) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: IplexToALLPlayer - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\PROGRA~2\ALLPLA~1\Iplex\IPLEXT~1.DLL (ALLCinema Ltd.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 7.0.10.8) - C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll (Oracle Corporation) CHR Plugin: (Java(TM) Platform SE 7 U1) - C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Media Go Detector) - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC) CHR Plugin: (PlayStation(R)Network Downloader Check Plug-in) - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) CHR Plugin: (Windows Live0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (PDF-XChange Viewer) - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll No File CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AMD FUEL Service; c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-03-06] (Advanced Micro Devices, Inc.) R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6181504 2013-06-18] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [158936 2013-06-18] (COMODO) S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [112256 2012-03-21] (Atheros Communication Inc.) R2 PMBDeviceInfoProvider; c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [473960 2012-02-21] (Sony Corporation) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [260768 2011-11-30] (Sony Corporation) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [163456 2012-03-29] (Atheros) ==================== Drivers (Whitelisted) ==================== S3 Andbus; C:\Windows\System32\DRIVERS\lgandbus64.sys [19456 2010-01-25] (LG Electronics Inc.) S3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag64.sys [27648 2010-01-25] (LG Electronics Inc.) S3 AndGps; C:\Windows\System32\DRIVERS\lgandgps64.sys [27136 2010-01-25] (LG Electronics Inc.) S3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem64.sys [33792 2010-01-25] (LG Electronics Inc.) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2013-06-18] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [708632 2013-06-18] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [48360 2013-06-18] (COMODO) R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [96800 2013-06-18] (COMODO) S3 lehidmini; C:\Windows\system32\drivers\leath_hid.sys [36608 2012-03-29] (Atheros) S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver.sys [21264 2012-04-12] (Synaptics Incorporated) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-04 13:54 - 2013-07-04 13:55 - 00007187 ____A C:\AdwCleaner[S1].txt 2013-07-04 11:30 - 2013-07-04 13:55 - 00000000 ____D C:\Users\Marta\Downloads\Soup_download 2013-07-04 11:28 - 2013-07-04 11:28 - 00000696 ____A C:\Users\Marta\Desktop\Biblioteki.lnk 2013-07-04 11:06 - 2013-07-04 11:06 - 00000000 ____D C:\Users\Marta\AppData\Local\{BF8D1CBF-1A30-4702-9E34-9B3366962FE7} 2013-07-04 11:06 - 2013-07-04 11:06 - 00000000 ____D C:\Users\Marta\AppData\Local\{1647FFDA-83B4-48BF-9EE5-C7FC16243081} 2013-07-04 10:54 - 2013-07-04 14:31 - 00000000 ___RD C:\Users\Marta\Desktop\Programy 2013-07-04 09:56 - 2013-07-04 13:51 - 00000000 ____D C:\FRST 2013-07-04 02:30 - 2013-07-04 02:30 - 00000000 ____D C:\Program Files\CCleaner 2013-07-04 02:04 - 2013-07-04 02:32 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-07-04 01:28 - 2013-07-04 01:28 - 00038583 ____A C:\ComboFix.txt 2013-07-04 00:02 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-07-04 00:02 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-07-04 00:02 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-07-04 00:02 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-07-04 00:02 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-07-04 00:02 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-07-04 00:02 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-07-04 00:02 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-07-03 23:58 - 2013-07-04 01:28 - 00000000 ____D C:\Qoobox 2013-07-03 23:56 - 2013-07-04 01:20 - 00000000 ____D C:\Windows\erdnt 2013-07-03 23:19 - 2013-07-03 23:19 - 00000000 ____A C:\autoexec.bat 2013-07-03 21:38 - 2013-07-04 01:34 - 00028226 ____A C:\Windows\System32\Drivers\fvstore.dat 2013-07-03 21:38 - 2013-07-03 21:38 - 00000000 ___HD C:\VTRoot 2013-07-03 20:33 - 2013-07-03 20:33 - 00001888 ____A C:\Users\Public\Desktop\COMODO Internet Security.lnk 2013-07-03 20:32 - 2013-07-04 14:27 - 01474832 ____A C:\Windows\System32\Drivers\sfi.dat 2013-07-03 20:31 - 2013-07-03 20:33 - 00000000 ___SD C:\ProgramData\Shared Space 2013-07-03 20:31 - 2013-07-03 20:33 - 00000000 ____D C:\ProgramData\Comodo 2013-07-03 20:31 - 2013-07-03 20:31 - 00000000 ____D C:\ProgramData\Comodo Downloader 2013-07-03 20:31 - 2013-07-03 20:31 - 00000000 ____D C:\Program Files\COMODO 2013-06-23 22:25 - 2013-05-28 15:05 - 00163328 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerUpdateService.exe 2013-06-18 16:16 - 2013-06-18 16:16 - 00708632 ____A (COMODO) C:\Windows\System32\Drivers\cmdguard.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00096800 ____A (COMODO) C:\Windows\System32\Drivers\inspect.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00048360 ____A (COMODO) C:\Windows\System32\Drivers\cmdhlp.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00023168 ____A (COMODO) C:\Windows\System32\Drivers\cmderd.sys 2013-06-18 16:15 - 2013-06-18 16:15 - 00437688 ____A (COMODO) C:\Windows\System32\guard64.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00348584 ____A (COMODO) C:\Windows\SysWOW64\guard32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00344792 ____A (COMODO) C:\Windows\System32\cmdvrt64.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00278232 ____A (COMODO) C:\Windows\SysWOW64\cmdvrt32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00045784 ____A (COMODO) C:\Windows\System32\cmdkbd64.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00043216 ____A (COMODO) C:\Windows\System32\cmdcsr.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00040664 ____A (COMODO) C:\Windows\SysWOW64\cmdkbd32.dll 2013-06-18 03:01 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-18 03:01 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-18 03:01 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-18 03:01 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-18 03:01 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-18 03:01 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-18 03:01 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-18 03:01 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-18 03:01 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-18 03:01 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-18 03:01 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-18 03:01 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-13 03:03 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-13 03:03 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-13 03:03 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-13 03:03 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-13 03:03 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-13 03:03 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-13 03:03 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-13 03:03 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-13 03:03 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-13 03:03 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-13 03:03 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-13 03:03 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-13 03:03 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-12 16:55 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll 2013-06-12 16:55 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-06-12 16:55 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-12 16:55 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-12 16:55 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-12 16:54 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-12 16:54 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-12 16:54 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-12 16:54 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-12 16:54 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-12 16:54 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-12 16:54 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-12 16:54 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-12 16:54 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-12 16:54 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-12 16:54 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-12 16:54 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-12 16:53 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-12 16:53 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-08 18:24 - 2013-06-08 18:24 - 00001097 ____A C:\Users\Marta\Desktop\Adobe Photoshop CS4.lnk 2013-06-08 17:44 - 2013-06-08 17:44 - 00000000 ____D C:\ProgramData\FLEXnet 2013-06-08 17:22 - 2013-06-08 17:22 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-06-08 17:20 - 2013-06-08 17:20 - 00001805 ____A C:\Users\Marta\Desktop\Opera.lnk 2013-06-08 17:20 - 2013-06-08 17:20 - 00000000 ____D C:\Program Files (x86)\Adobe Media Player 2013-06-08 17:09 - 2013-06-08 17:38 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-06-08 17:09 - 2013-06-08 17:09 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared 2013-06-08 12:31 - 2013-06-08 12:31 - 00023027 ____A C:\Users\Marta\AppData\Local\recently-used.xbel 2013-06-07 18:50 - 2013-06-07 18:50 - 00108004 ___AH C:\Windows\SysWOW64\mlfcache.dat 2013-06-07 18:47 - 2013-06-07 18:48 - 00000000 ____D C:\Program Files (x86)\Safari 2013-06-07 18:44 - 2013-06-07 18:44 - 00000000 ____D C:\Users\Marta\AppData\Local\Downloaded Installations 2013-06-07 15:48 - 2013-06-07 15:48 - 00000000 ____D C:\Program Files (x86)\Opera 2013-06-06 19:46 - 2013-06-06 19:46 - 00000000 ____D C:\Users\Marta\AppData\Local\SlimWare Utilities Inc 2013-06-06 19:45 - 2013-06-06 19:47 - 00000000 ____D C:\Program Files (x86)\SlimComputer ==================== One Month Modified Files and Folders ======= 2013-07-04 14:31 - 2013-07-04 10:54 - 00000000 ___RD C:\Users\Marta\Desktop\Programy 2013-07-04 14:27 - 2013-07-03 20:32 - 01474832 ____A C:\Windows\System32\Drivers\sfi.dat 2013-07-04 14:20 - 2013-05-25 15:15 - 00001046 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-04 14:19 - 2012-05-08 07:39 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-04 14:06 - 2009-07-14 06:45 - 00020928 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-04 14:06 - 2009-07-14 06:45 - 00020928 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-04 14:05 - 2012-05-08 07:39 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-07-04 14:05 - 2012-05-08 07:39 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-07-04 14:02 - 2012-10-12 17:54 - 01185742 ____A C:\Windows\WindowsUpdate.log 2013-07-04 13:57 - 2013-05-25 15:15 - 00001042 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-04 13:57 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-04 13:57 - 2009-07-14 06:51 - 00070529 ____A C:\Windows\setupact.log 2013-07-04 13:55 - 2013-07-04 13:54 - 00007187 ____A C:\AdwCleaner[S1].txt 2013-07-04 13:55 - 2013-07-04 11:30 - 00000000 ____D C:\Users\Marta\Downloads\Soup_download 2013-07-04 13:51 - 2013-07-04 09:56 - 00000000 ____D C:\FRST 2013-07-04 12:05 - 2010-11-21 05:47 - 00038354 ____A C:\Windows\PFRO.log 2013-07-04 11:28 - 2013-07-04 11:28 - 00000696 ____A C:\Users\Marta\Desktop\Biblioteki.lnk 2013-07-04 11:27 - 2012-10-14 13:15 - 00000000 ___RD C:\Users\Marta\Desktop\STUDIA 2013-07-04 11:18 - 2012-10-14 15:41 - 00000000 ____D C:\Users\Marta\Desktop\SŁOWO 2013-07-04 11:12 - 2013-04-19 12:14 - 00000000 ____D C:\Users\Marta\Desktop\ZDJĘCIA 2013-07-04 11:11 - 2013-05-05 14:54 - 00000000 ____D C:\Users\Marta\Desktop\kampania 2013-07-04 11:06 - 2013-07-04 11:06 - 00000000 ____D C:\Users\Marta\AppData\Local\{BF8D1CBF-1A30-4702-9E34-9B3366962FE7} 2013-07-04 11:06 - 2013-07-04 11:06 - 00000000 ____D C:\Users\Marta\AppData\Local\{1647FFDA-83B4-48BF-9EE5-C7FC16243081} 2013-07-04 11:02 - 2012-10-12 19:54 - 00000000 ____D C:\Users\Marta\Documents\WebCam Media 2013-07-04 02:32 - 2013-07-04 02:04 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-07-04 02:30 - 2013-07-04 02:30 - 00000000 ____D C:\Program Files\CCleaner 2013-07-04 01:34 - 2013-07-03 21:38 - 00028226 ____A C:\Windows\System32\Drivers\fvstore.dat 2013-07-04 01:31 - 2012-11-01 19:31 - 00000000 ____D C:\Users\Marta\AppData\Roaming\uTorrent 2013-07-04 01:28 - 2013-07-04 01:28 - 00038583 ____A C:\ComboFix.txt 2013-07-04 01:28 - 2013-07-03 23:58 - 00000000 ____D C:\Qoobox 2013-07-04 01:20 - 2013-07-03 23:56 - 00000000 ____D C:\Windows\erdnt 2013-07-04 01:17 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-07-03 23:19 - 2013-07-03 23:19 - 00000000 ____A C:\autoexec.bat 2013-07-03 23:11 - 2013-03-08 22:28 - 00000000 ____D C:\Users\Marta\AppData\Local\ChomikBox 2013-07-03 21:38 - 2013-07-03 21:38 - 00000000 ___HD C:\VTRoot 2013-07-03 20:33 - 2013-07-03 20:33 - 00001888 ____A C:\Users\Public\Desktop\COMODO Internet Security.lnk 2013-07-03 20:33 - 2013-07-03 20:31 - 00000000 ___SD C:\ProgramData\Shared Space 2013-07-03 20:33 - 2013-07-03 20:31 - 00000000 ____D C:\ProgramData\Comodo 2013-07-03 20:31 - 2013-07-03 20:31 - 00000000 ____D C:\ProgramData\Comodo Downloader 2013-07-03 20:31 - 2013-07-03 20:31 - 00000000 ____D C:\Program Files\COMODO 2013-07-03 20:06 - 2013-03-08 22:29 - 00000000 ____D C:\Users\Marta\.gstreamer-0.10 2013-07-03 19:47 - 2009-07-14 07:08 - 00032574 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-03 19:26 - 2012-10-18 10:02 - 00000000 ____D C:\Users\Marta\AppData\Roaming\AIMP3 2013-06-29 14:57 - 2012-10-18 09:23 - 00000000 ____D C:\Users\Marta\AppData\Local\Last.fm 2013-06-28 15:04 - 2011-12-07 04:14 - 02193164 ____A C:\Windows\System32\perfh015.dat 2013-06-28 15:04 - 2011-12-07 04:14 - 00663342 ____A C:\Windows\System32\perfc015.dat 2013-06-28 15:04 - 2009-07-14 07:13 - 00006484 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-24 00:28 - 2013-05-25 15:16 - 00002143 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-06-18 16:16 - 2013-06-18 16:16 - 00708632 ____A (COMODO) C:\Windows\System32\Drivers\cmdguard.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00096800 ____A (COMODO) C:\Windows\System32\Drivers\inspect.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00048360 ____A (COMODO) C:\Windows\System32\Drivers\cmdhlp.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00023168 ____A (COMODO) C:\Windows\System32\Drivers\cmderd.sys 2013-06-18 16:15 - 2013-06-18 16:15 - 00437688 ____A (COMODO) C:\Windows\System32\guard64.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00348584 ____A (COMODO) C:\Windows\SysWOW64\guard32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00344792 ____A (COMODO) C:\Windows\System32\cmdvrt64.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00278232 ____A (COMODO) C:\Windows\SysWOW64\cmdvrt32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00045784 ____A (COMODO) C:\Windows\System32\cmdkbd64.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00043216 ____A (COMODO) C:\Windows\System32\cmdcsr.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00040664 ____A (COMODO) C:\Windows\SysWOW64\cmdkbd32.dll 2013-06-18 03:21 - 2012-10-14 13:10 - 00000000 ____D C:\Users\Marta\AppData\Roaming\SoftGrid Client 2013-06-13 04:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-06-08 18:49 - 2012-11-01 19:34 - 00000000 ____D C:\Program Files (x86)\uTorrent 2013-06-08 18:36 - 2012-12-09 22:17 - 00000000 ____D C:\Program Files\Adobe 2013-06-08 18:24 - 2013-06-08 18:24 - 00001097 ____A C:\Users\Marta\Desktop\Adobe Photoshop CS4.lnk 2013-06-08 18:23 - 2012-10-13 18:14 - 00000000 ____D C:\Users\Marta\AppData\Local\Adobe 2013-06-08 18:17 - 2012-10-22 11:53 - 00000000 ____D C:\Users\Marta\AppData\Local\CrashDumps 2013-06-08 18:14 - 2012-10-12 18:07 - 00000000 ____D C:\Users\Marta\AppData\Roaming\Adobe 2013-06-08 18:13 - 2009-07-14 06:45 - 04909112 ____A C:\Windows\System32\FNTCACHE.DAT 2013-06-08 17:44 - 2013-06-08 17:44 - 00000000 ____D C:\ProgramData\FLEXnet 2013-06-08 17:44 - 2012-10-12 18:00 - 00075184 ____A C:\Users\Marta\AppData\Local\GDIPFONTCACHEV1.DAT 2013-06-08 17:38 - 2013-06-08 17:09 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-06-08 17:34 - 2012-05-08 07:38 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-06-08 17:33 - 2012-05-08 07:38 - 00000000 ____D C:\ProgramData\Adobe 2013-06-08 17:22 - 2013-06-08 17:22 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-06-08 17:20 - 2013-06-08 17:20 - 00001805 ____A C:\Users\Marta\Desktop\Opera.lnk 2013-06-08 17:20 - 2013-06-08 17:20 - 00000000 ____D C:\Program Files (x86)\Adobe Media Player 2013-06-08 17:20 - 2013-01-10 21:10 - 00000000 ____D C:\Users\Marta\.gimp-2.8 2013-06-08 17:09 - 2013-06-08 17:09 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared 2013-06-08 16:08 - 2013-06-18 03:01 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-08 16:07 - 2013-06-18 03:01 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-08 16:06 - 2013-06-18 03:01 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-08 16:06 - 2013-06-18 03:01 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-08 16:06 - 2013-06-18 03:01 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-08 14:28 - 2013-06-18 03:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-08 13:42 - 2013-06-18 03:01 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-08 13:40 - 2013-06-18 03:01 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-08 13:40 - 2013-06-18 03:01 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-08 13:40 - 2013-06-18 03:01 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-08 13:40 - 2013-06-18 03:01 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-08 13:13 - 2013-06-18 03:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-08 12:31 - 2013-06-08 12:31 - 00023027 ____A C:\Users\Marta\AppData\Local\recently-used.xbel 2013-06-07 20:40 - 2012-10-12 19:22 - 00000000 ____D C:\Users\Marta\AppData\Local\Google 2013-06-07 18:52 - 2013-04-19 12:25 - 00000000 ____D C:\Users\Marta\AppData\Local\Apple Computer 2013-06-07 18:50 - 2013-06-07 18:50 - 00108004 ___AH C:\Windows\SysWOW64\mlfcache.dat 2013-06-07 18:49 - 2013-04-19 12:25 - 00000000 ____D C:\Users\Marta\AppData\Roaming\Apple Computer 2013-06-07 18:48 - 2013-06-07 18:47 - 00000000 ____D C:\Program Files (x86)\Safari 2013-06-07 18:44 - 2013-06-07 18:44 - 00000000 ____D C:\Users\Marta\AppData\Local\Downloaded Installations 2013-06-07 15:49 - 2013-02-08 23:00 - 00000000 ____D C:\Users\Marta\AppData\Roaming\Opera 2013-06-07 15:49 - 2013-02-08 23:00 - 00000000 ____D C:\Users\Marta\AppData\Local\Opera 2013-06-07 15:48 - 2013-06-07 15:48 - 00000000 ____D C:\Program Files (x86)\Opera 2013-06-07 15:13 - 2013-02-08 22:59 - 00000000 ____D C:\Program Files\Opera x64 2013-06-07 14:58 - 2012-05-08 07:11 - 00000000 ____D C:\Program Files (x86)\Sony 2013-06-07 14:58 - 2012-05-08 07:01 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-06-07 14:58 - 2012-05-08 06:52 - 00000000 ____D C:\ProgramData\Sony Corporation 2013-06-06 20:00 - 2012-05-08 08:10 - 00000000 ____D C:\Program Files (x86)\WildGames 2013-06-06 19:55 - 2012-11-01 15:01 - 00000000 ____D C:\Users\Marta\AppData\Roaming\WildTangent 2013-06-06 19:55 - 2012-05-08 08:09 - 00000000 ____D C:\ProgramData\WildTangent 2013-06-06 19:47 - 2013-06-06 19:45 - 00000000 ____D C:\Program Files (x86)\SlimComputer 2013-06-06 19:46 - 2013-06-06 19:46 - 00000000 ____D C:\Users\Marta\AppData\Local\SlimWare Utilities Inc 2013-06-05 00:16 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-26 02:16 ==================== End Of Log ============================