Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-09-2013 Ran by ADI-CAR (administrator) on ADI-CAR_1 on 19-09-2013 16:52:39 Running from F:\ Windows 7 Professional Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (ESET) C:\Program Files\ESET Smart Security\x86\ekrn.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.INSERTGT\MSSQL\Binn\sqlservr.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (ESET) C:\Program Files\ESET Smart Security\egui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) C:\Windows\system32\PrintIsolationHost.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6468712 2012-03-20] (Realtek Semiconductor) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [egui] - C:\Program Files\ESET Smart Security\egui.exe [4081008 2012-03-07] (ESET) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) MountPoints2: {451f75c7-3641-11e2-a182-806e6f6e6963} - E:\Bin\ASSETUP.exe HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-26] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 ==================== Services (Whitelisted) ================= R2 ekrn; C:\Program Files\ESET Smart Security\x86\ekrn.exe [913144 2012-03-07] (ESET) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-06] (Intel Corporation) R2 MSSQL$INSERTGT; C:\Program Files\Microsoft SQL Server\MSSQL10_50.INSERTGT\MSSQL\Binn\sqlservr.exe [62111072 2011-06-17] (Microsoft Corporation) S4 SQLAgent$INSERTGT; C:\Program Files\Microsoft SQL Server\MSSQL10_50.INSERTGT\MSSQL\Binn\SQLAGENT.EXE [431456 2011-06-17] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [209768 2012-03-14] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [148528 2012-03-14] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [187632 2012-03-14] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [38288 2012-03-14] (ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62496 2012-03-14] (ESET) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-18 23:44 - 2013-09-18 23:44 - 00000000 ____D C:\FRST 2013-09-17 21:04 - 2013-09-17 21:04 - 34204160 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309172104.iar 2013-09-17 21:04 - 2013-09-17 21:04 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309172104.i01 2013-09-16 20:13 - 2013-09-16 20:13 - 34200064 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309162013.iar 2013-09-16 20:13 - 2013-09-16 20:13 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309162013.i01 2013-09-12 20:16 - 2013-09-12 20:16 - 34182144 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309122016.iar 2013-09-12 20:16 - 2013-09-12 20:16 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309122016.i01 2013-09-11 20:42 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-11 20:42 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-11 20:42 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-11 20:42 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-11 20:42 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-11 20:42 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-11 20:42 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-11 20:42 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-11 20:42 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-11 20:42 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-11 20:42 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-11 20:42 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-11 20:42 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-11 20:42 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-11 20:42 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-11 20:42 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-11 20:42 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-11 20:42 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-11 20:42 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-11 20:42 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-11 20:42 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-11 20:42 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-11 20:42 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-11 20:42 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-11 20:42 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-11 20:42 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-11 20:42 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-11 20:42 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-11 20:42 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-11 20:42 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-11 20:42 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-11 07:34 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 07:34 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-11 07:34 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-11 07:34 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-11 07:34 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-11 07:34 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-11 07:34 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-11 07:34 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-11 07:34 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-11 07:34 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-11 07:34 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-11 07:34 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-11 07:34 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-11 07:34 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-11 07:34 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-11 07:34 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-11 07:34 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-11 07:34 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-11 07:34 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-11 07:34 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-11 07:34 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-11 07:34 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 07:34 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-11 07:34 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-11 07:34 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-11 07:34 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-11 07:34 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-10 22:06 - 2013-09-10 22:06 - 34176000 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309102206.iar 2013-09-10 22:06 - 2013-09-10 22:06 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309102206.i01 2013-09-10 20:04 - 2013-09-10 20:04 - 34174976 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309102004.iar 2013-09-10 20:04 - 2013-09-10 20:04 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309102004.i01 2013-09-09 19:01 - 2013-09-09 19:01 - 34173440 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309091901.iar 2013-09-09 19:01 - 2013-09-09 19:01 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309091901.i01 2013-09-05 12:38 - 2013-09-05 12:38 - 34165248 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309051238.iar 2013-09-05 12:38 - 2013-09-05 12:38 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309051238.i01 2013-09-03 21:01 - 2013-09-03 21:01 - 34155520 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309032101.iar 2013-09-03 21:01 - 2013-09-03 21:01 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309032101.i01 2013-09-02 20:56 - 2013-09-02 20:56 - 34148864 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309022056.iar 2013-09-02 20:56 - 2013-09-02 20:56 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309022056.i01 2013-09-01 11:39 - 2013-09-01 11:39 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309011138.i01 2013-09-01 11:38 - 2013-09-01 11:39 - 34148864 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309011138.iar 2013-08-29 18:43 - 2013-08-29 18:43 - 34132992 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308291842.iar 2013-08-29 18:43 - 2013-08-29 18:43 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308291842.i01 2013-08-26 20:34 - 2013-08-26 20:34 - 34123264 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308262034.iar 2013-08-26 20:34 - 2013-08-26 20:34 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308262034.i01 2013-08-23 22:51 - 2013-08-23 22:51 - 34110464 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308232251.iar 2013-08-23 22:51 - 2013-08-23 22:51 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308232251.i01 2013-08-22 18:16 - 2013-08-22 18:16 - 34105344 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308221816.iar 2013-08-22 18:16 - 2013-08-22 18:16 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308221816.i01 2013-08-22 15:53 - 2013-09-06 13:59 - 00001375 _____ C:\Users\ADI-CAR\Desktop\przesyłki - numery listów.txt 2013-08-21 19:54 - 2013-08-21 19:54 - 34097664 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308211954.iar 2013-08-21 19:54 - 2013-08-21 19:54 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308211954.i01 2013-08-21 15:24 - 2013-08-21 15:24 - 34095616 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308211524.iar 2013-08-21 15:24 - 2013-08-21 15:24 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308211524.i01 2013-08-20 21:23 - 2013-08-20 21:23 - 34090496 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308202123.iar 2013-08-20 21:23 - 2013-08-20 21:23 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308202123.i01 ==================== One Month Modified Files and Folders ======= 2013-09-19 16:51 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-19 16:51 - 2009-07-14 06:51 - 00036700 _____ C:\Windows\setupact.log 2013-09-19 04:33 - 2012-11-24 16:17 - 01408595 _____ C:\Windows\WindowsUpdate.log 2013-09-18 23:44 - 2013-09-18 23:44 - 00000000 ____D C:\FRST 2013-09-18 23:44 - 2011-04-12 15:21 - 00818826 _____ C:\Windows\system32\perfh015.dat 2013-09-18 23:44 - 2011-04-12 15:21 - 00184156 _____ C:\Windows\system32\perfc015.dat 2013-09-18 23:44 - 2009-07-14 07:13 - 01879926 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-18 23:19 - 2009-07-14 06:45 - 00022080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-18 23:19 - 2009-07-14 06:45 - 00022080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-18 12:37 - 2012-11-25 17:36 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-17 21:04 - 2013-09-17 21:04 - 34204160 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309172104.iar 2013-09-17 21:04 - 2013-09-17 21:04 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309172104.i01 2013-09-16 20:13 - 2013-09-16 20:13 - 34200064 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309162013.iar 2013-09-16 20:13 - 2013-09-16 20:13 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309162013.i01 2013-09-13 09:14 - 2012-11-25 17:36 - 00003868 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-13 09:13 - 2012-11-25 17:36 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-13 09:13 - 2012-11-25 17:36 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-12 20:16 - 2013-09-12 20:16 - 34182144 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309122016.iar 2013-09-12 20:16 - 2013-09-12 20:16 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309122016.i01 2013-09-12 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-12 06:29 - 2012-11-24 19:45 - 00000000 ____D C:\Program Files (x86)\Adobe Reader 11.0 2013-09-12 06:26 - 2012-11-24 16:26 - 00000000 ___RD C:\Users\ADI-CAR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-12 06:26 - 2012-11-24 16:26 - 00000000 ___RD C:\Users\ADI-CAR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 06:26 - 2009-07-14 06:45 - 00351544 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 06:23 - 2010-11-21 05:47 - 00052202 _____ C:\Windows\PFRO.log 2013-09-11 20:42 - 2013-07-13 21:34 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 20:41 - 2012-11-24 20:23 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-11 20:41 - 2012-11-24 19:10 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-10 22:06 - 2013-09-10 22:06 - 34176000 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309102206.iar 2013-09-10 22:06 - 2013-09-10 22:06 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309102206.i01 2013-09-10 20:04 - 2013-09-10 20:04 - 34174976 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309102004.iar 2013-09-10 20:04 - 2013-09-10 20:04 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309102004.i01 2013-09-09 19:01 - 2013-09-09 19:01 - 34173440 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309091901.iar 2013-09-09 19:01 - 2013-09-09 19:01 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309091901.i01 2013-09-06 13:59 - 2013-08-22 15:53 - 00001375 _____ C:\Users\ADI-CAR\Desktop\przesyłki - numery listów.txt 2013-09-05 12:38 - 2013-09-05 12:38 - 34165248 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309051238.iar 2013-09-05 12:38 - 2013-09-05 12:38 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309051238.i01 2013-09-05 09:43 - 2013-07-11 14:04 - 00000000 ____D C:\Users\ADI-CAR\Desktop\MONIKA 2013-09-03 21:01 - 2013-09-03 21:01 - 34155520 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309032101.iar 2013-09-03 21:01 - 2013-09-03 21:01 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309032101.i01 2013-09-02 20:56 - 2013-09-02 20:56 - 34148864 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309022056.iar 2013-09-02 20:56 - 2013-09-02 20:56 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309022056.i01 2013-09-01 11:39 - 2013-09-01 11:39 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309011138.i01 2013-09-01 11:39 - 2013-09-01 11:38 - 34148864 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201309011138.iar 2013-08-29 18:43 - 2013-08-29 18:43 - 34132992 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308291842.iar 2013-08-29 18:43 - 2013-08-29 18:43 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308291842.i01 2013-08-26 20:34 - 2013-08-26 20:34 - 34123264 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308262034.iar 2013-08-26 20:34 - 2013-08-26 20:34 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308262034.i01 2013-08-23 22:51 - 2013-08-23 22:51 - 34110464 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308232251.iar 2013-08-23 22:51 - 2013-08-23 22:51 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308232251.i01 2013-08-22 18:16 - 2013-08-22 18:16 - 34105344 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308221816.iar 2013-08-22 18:16 - 2013-08-22 18:16 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308221816.i01 2013-08-21 19:54 - 2013-08-21 19:54 - 34097664 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308211954.iar 2013-08-21 19:54 - 2013-08-21 19:54 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308211954.i01 2013-08-21 15:24 - 2013-08-21 15:24 - 34095616 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308211524.iar 2013-08-21 15:24 - 2013-08-21 15:24 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308211524.i01 2013-08-20 21:23 - 2013-08-20 21:23 - 34090496 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308202123.iar 2013-08-20 21:23 - 2013-08-20 21:23 - 00010752 _____ C:\Users\ADI-CAR\Documents\ADI_CAR_Ma_gorzata_D_browska_201308202123.i01 ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-11 08:02 ==================== End Of Log ============================