Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-07-2013 Ran by antoni (administrator) on 11-07-2013 19:44:29 Running from G:\ Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: Polish Internet Explorer Version 7 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Apple Computer, Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) c:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe (Lenovo Group Limited) C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Lenovo(beijing) Limited) C:\Program Files\Lenovo\Energy Management\utility.exe (Lenovo (Beijing) Limited) C:\Program Files\Lenovo\Energy Management\Energy Management.exe () C:\Program Files\Lenovo\VeriFaceIII\PManage.exe () C:\Windows\system32\PnkBstrA.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\System32\IgrsSvcs.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Lenovo Group Limited) C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe () C:\Program Files\Wireless 5-Mode Oscar Editor\OscarEditor.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Broadcom Corporation.) c:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe (Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation) C:\Windows\system32\schtasks.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\system32\wuauclt.exe (Microsoft Corporation) C:\Windows\system32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - %ProgramFiles%\Windows Defender\MSASCui.exe -hide [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [EnergyUtility] - C:\Program Files\Lenovo\Energy Management\utility.exe [5207880 2008-05-22] (Lenovo(beijing) Limited) HKLM\...\Run: [Energy Management] - C:\Program Files\Lenovo\Energy Management\Energy Management.exe [8824648 2008-05-22] (Lenovo (Beijing) Limited) HKLM\...\Run: [VeriFaceManager] - C:\Program Files\Lenovo\VeriFaceIII\PManage.exe [2916352 2008-08-17] () HKLM\...\Run: [Adobe Reader Speed Launcher] - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1111336 2008-05-29] (Synaptics, Inc.) HKLM\...\Run: [Windows Mobile Device Center] - %windir%\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4273976 2012-07-03] (AVAST Software) HKLM\...\Run: [RaidCall] - C:\Program Files\RaidCall\raidcall.exe [3423928 2013-05-06] (RAIDCALL.COM) HKCU\...\Run: [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1233920 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [Google Update] - "C:\Users\antoni\AppData\Local\Google\Update\GoogleUpdate.exe" /c [135664 2009-12-03] (Google Inc.) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2423752 2011-02-18] (SUPERAntiSpyware.com) HKCU\...\Run: [OscarXG] - "C:\Program Files\Wireless 5-Mode Oscar Editor\OscarEditor.exe" Minimum [3515904 2011-09-02] () HKCU\...\Run: [DAEMON Tools Lite] - "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [3672640 2013-03-14] (Disc Soft Ltd) MountPoints2: {e5239356-99ee-11e2-babf-fa1c3ccc4a17} - F:\Autorun.exe HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter [ 2008-01-21] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter [ 2008-01-21] (Microsoft Corporation) Startup: C:\ProgramData\Start Menu\Programs\Startup\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&FORM=LENIE SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {52876F44-3DA1-4ED1-89DB-D03E43FE6E5F} URL = http://www.google.pl/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Pomocnik rejestracji usługi Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [94208] (Apple Computer, Inc.) FireFox: ======== FF ProfilePath: C:\Users\antoni\AppData\Roaming\Mozilla\Firefox\Profiles\qq9cssiw.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @raidcall.en/RCplugin - C:\Users\antoni\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall) FF Plugin: @real.com/nppl3260;version=6.0.12.450 - C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin HKCU: @nsroblox.roblox.com/launcher - C:\Users\antoni\AppData\Local\Roblox\Versions\version-1ff4978f36a64477\\NPRobloxProxy.dll ( ROBLOX Corporation) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\antoni\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\antoni\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml FF Extension: No Name - C:\Users\antoni\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! WebRep - C:\Program Files\AVAST Software\Avast\WebRep\FF FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\antoni\AppData\Local\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\antoni\AppData\Local\Google\Chrome\Application\27.0.1453.116\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\antoni\AppData\Local\Google\Chrome\Application\27.0.1453.116\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.150.3) - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U15) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Users\antoni\AppData\Local\Google\Chrome\Application\plugins\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Version Plugin) - C:\Users\antoni\AppData\Local\Google\Chrome\Application\plugins\nprpjplug.dll (RealNetworks, Inc.) CHR Plugin: (Google Update) - C:\Users\antoni\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Roblox Launcher Plugin) - C:\Users\antoni\AppData\Local\Roblox\Versions\version-d2e4e6e567c64738\\NPRobloxProxy.dll No File CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR StartMenuInternet: Google Chrome - "C:\Users\antoni\AppData\Local\Google\Chrome\Application\chrome.exe" ========================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44808 2012-07-03] (AVAST Software) R2 btwdins; c:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe [522792 2008-05-14] (Broadcom Corporation.) R2 IGRS; C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe [32768 2008-02-14] (Lenovo Group Limited) S3 IncSvc; C:\Program Files\Lenovo\ReadyComm\IncSvc.dll [469504 2007-05-12] (Lenovo Group Limited) S3 MSSQL$MSSMLBIZ; c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75136 2013-01-03] () S3 PS_MDP; C:\Program Files\Lenovo\ReadyComm\PS_MDP.dll [270336 2007-04-11] (Lenovo Group Limited) R2 ReadyComm.DirectRouter; C:\Program Files\Lenovo\ReadyComm\common\router.dll [98304 2008-02-15] (Lenovo Group Limited) R2 System_Repair_UpdateMonitor; C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe [430080 2008-04-24] (Lenovo Group Limited) ==================== Drivers (Whitelisted) ==================== R3 ACPIVPC; C:\Windows\System32\DRIVERS\AcpiVpc.sys [21520 2009-05-19] (Lenovo Corporation) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [21256 2012-07-03] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [57656 2012-07-03] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [35928 2012-07-03] (AVAST Software) R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [721000 2012-07-03] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [353688 2012-07-03] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [54232 2012-07-03] (AVAST Software) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-04-01] (DT Soft Ltd) R1 funfrm; C:\Windows\System32\Drivers\funfrm.sys [44544 2008-08-17] () S3 hwusbfake; C:\Windows\System32\DRIVERS\ewusbfake.sys [103040 2009-08-04] (Huawei Technologies Co., Ltd.) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12872 2010-02-17] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67656 2010-05-10] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1747200 2008-05-23] () R3 vhidmini; C:\Windows\System32\DRIVERS\ITEhidCIR.sys [10880 2008-01-24] (ITE Tech. Inc. ) R0 Wdkbdmou; C:\Windows\System32\DRIVERS\Wdkbdmou.sys [8832 2008-05-22] () R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [8832 2008-05-22] (Windows (R) Codename Longhorn DDK provider) S3 WSVD; C:\Windows\system32\drivers\WSVD.sys [81192 2008-01-10] (CyberLink) S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NVHDA; system32\drivers\nvhda32v.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-11 19:44 - 2013-07-11 19:44 - 00000000 ____D C:\FRST 2013-07-11 19:03 - 2013-07-11 19:04 - 00004874 ____A C:\AdwCleaner[S1].txt 2013-07-11 18:52 - 2013-07-11 18:52 - 00003060 ____A C:\Windows\DPINST.LOG 2013-06-16 12:33 - 2013-06-16 12:34 - 00138712 ____A C:\Windows\Minidump\Mini061613-01.dmp 2013-06-16 11:42 - 2013-05-28 15:05 - 00163328 ____A (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerUpdateService.exe ==================== One Month Modified Files and Folders ======= 2013-07-11 19:44 - 2013-07-11 19:44 - 00000000 ____D C:\FRST 2013-07-11 19:21 - 2012-07-29 17:00 - 00000930 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-11 19:13 - 2009-06-22 15:34 - 00001356 ____A C:\Users\antoni\AppData\Local\d3d9caps.dat 2013-07-11 19:13 - 2006-11-02 14:47 - 00003344 ___AH C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-11 19:13 - 2006-11-02 14:47 - 00003344 ___AH C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-11 19:11 - 2008-08-17 12:10 - 00718992 ____A C:\Windows\system32\perfh015.dat 2013-07-11 19:11 - 2008-08-17 12:10 - 00148552 ____A C:\Windows\system32\perfc015.dat 2013-07-11 19:11 - 2006-11-02 12:33 - 01629322 ____A C:\Windows\system32\PerfStringBackup.INI 2013-07-11 19:10 - 2010-08-09 12:06 - 01474107 ____A C:\Windows\WindowsUpdate.log 2013-07-11 19:06 - 2008-08-17 13:53 - 00000056 __ASH C:\_PartitionInfo 2013-07-11 19:06 - 2008-08-17 13:52 - 03958049 ____A C:\FaceProv.log 2013-07-11 19:05 - 2006-11-02 15:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-11 19:04 - 2013-07-11 19:03 - 00004874 ____A C:\AdwCleaner[S1].txt 2013-07-11 19:04 - 2008-08-17 12:17 - 00000836 ____A C:\Windows\bthservsdp.dat 2013-07-11 19:04 - 2006-11-02 15:01 - 00032528 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-11 19:01 - 2009-12-03 12:10 - 00001062 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1040673368-2128650150-2888634519-1004UA.job 2013-07-11 18:58 - 2011-09-26 15:46 - 00011460 ____A C:\Windows\PFRO.log 2013-07-11 18:58 - 2008-08-17 13:17 - 00000000 ____D C:\ProgramData\NVIDIA 2013-07-11 18:52 - 2013-07-11 18:52 - 00003060 ____A C:\Windows\DPINST.LOG 2013-07-11 18:12 - 2010-01-09 02:51 - 00000000 ____D C:\Program Files\Veoh Networks 2013-07-11 17:47 - 2011-11-08 22:15 - 00003734 ____A C:\Windows\setupact.log 2013-07-02 12:42 - 2009-01-07 22:31 - 00001040 ____A C:\Windows\system32\ICAutoUpdate.log.bak 2013-07-01 20:01 - 2009-12-03 12:10 - 00001010 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1040673368-2128650150-2888634519-1004Core.job 2013-06-29 17:05 - 2009-12-03 12:14 - 00002047 ____A C:\Users\antoni\Desktop\Google Chrome.lnk 2013-06-16 12:34 - 2013-06-16 12:33 - 00138712 ____A C:\Windows\Minidump\Mini061613-01.dmp 2013-06-16 12:33 - 2011-12-04 22:22 - 377940883 ____A C:\Windows\MEMORY.DMP 2013-06-16 12:33 - 2009-11-27 19:35 - 00000000 ____D C:\Windows\Minidump 2013-06-13 03:03 - 2006-11-02 12:24 - 73381792 ____A (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-06-12 16:21 - 2012-07-29 17:00 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-06-12 16:21 - 2012-07-29 17:00 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-11 19:12 ==================== End Of Log ============================