Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by Tommy (administrator) on STACJONARNY_DOM on 06-10-2013 11:32:07 Running from C:\Users\Tommy\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Dassault Systemes) C:\Program Files\Dassault Systemes\B18\win_b64\code\bin\CATSysDemon.exe () C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe () C:\Program Files (x86)\Samsung\USB Drivers\26_VIA_driver2\amd64\VIAService.exe (Autodesk, Inc.) C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe (Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Raxco Software, Inc.) C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe () C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Eugene Gavrilov) C:\Program Files\kX Audio Driver\3550\kxmixer.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe () C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Akamai Technologies, Inc.) C:\Users\Tommy\AppData\Local\Akamai\netsession_win.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Dassault Systèmes SolidWorks Corp.) C:\Program Files (x86)\Common Files\Menedżer instalacji SolidWorks\BackgroundDownloading\sldBgDwld.exe (Dropbox, Inc.) C:\Users\Tommy\AppData\Roaming\Dropbox\bin\Dropbox.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Akamai Technologies, Inc.) C:\Users\Tommy\AppData\Local\Akamai\netsession_win.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Spline Network,Inc.) C:\Program Files (x86)\InkSaver\x86\ISApExtSvc32.exe (Spline Network,Inc.) C:\Program Files (x86)\InkSaver\ISApExtSvc64.exe (Spline Network,Inc.) C:\Program Files (x86)\InkSaver\InkSaver.exe (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe () C:\Program Files (x86)\AVG Secure Search\vprot.exe (Spigot, Inc.) C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Spigot Inc) C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings64.exe (WebConnect) C:\Program Files (x86)\WebConnect\bin\utilWebConnect.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\loggingserver.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Raxco Software, Inc.) C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe (DealPly Technologies Ltd) C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe (OldTimer Tools) C:\Users\Tommy\Desktop\OTL.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [kX Mixer] - C:\Program Files\kX Audio Driver\3550\kxmixer.exe [677896 2009-09-18] (Eugene Gavrilov) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3521464 2012-05-30] (Samsung Electronics Co., Ltd.) HKCU\...\Run: [Gadu-Gadu] - C:\Program Files (x86)\Gadu-Gadu\gg.exe [2127296 2008-03-20] (Gadu-Gadu S.A.) HKCU\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-05-30] () HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Tommy\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [196608 2004-04-17] (InstallShield Software Corporation) HKCU\...\Run: [DAEMON Tools Lite] - "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20684656 2013-07-25] (Skype Technologies S.A.) MountPoints2: I - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\Autorun.exe MountPoints2: {2573ded5-2fb4-11e0-97ad-6c626dbb44eb} - I:\Autorun.exe MountPoints2: {3de07190-6279-11e2-a1b6-6c626dbb44eb} - I:\Monkey.exe MountPoints2: {7571b8a3-3c1d-11e0-b3d0-6c626dbb44eb} - K:\LaunchU3.exe -a MountPoints2: {8507f83c-52cd-11e0-bc48-6c626dbb44eb} - J:\LaunchU3.exe -a MountPoints2: {8507f88e-52cd-11e0-bc48-6c626dbb44eb} - I:\LaunchU3.exe -a HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2443376 2010-07-06] (VIA) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-07-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.) HKLM-x32\...\Run: [KiesHelper] - C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s HKLM-x32\...\Run: [InkSaver.ApExt32] - C:\Program Files (x86)\InkSaver\x86\ISApExtSvc32.exe [49688 2012-03-09] (Spline Network,Inc.) HKLM-x32\...\Run: [InkSaver.ApExt64] - C:\Program Files (x86)\InkSaver\ISApExtSvc64.exe [49176 2012-03-09] (Spline Network,Inc.) HKLM-x32\...\Run: [InkSaver] - C:\Program Files (x86)\InkSaver\InkSaver.exe [576536 2012-03-09] (Spline Network,Inc.) HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG Secure Search\vprot.exe [2404376 2013-10-01] () HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [SearchSettings] - C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe [1297728 2013-02-23] (Spigot, Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2013-09-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2013-09-03] (Adobe Systems Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-29] (Avira Operations GmbH & Co. KG) HKU\Gosia\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.) HKU\Gosia\...\Run: [ISUSPM Startup] - c:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [196608 2004-04-17] (InstallShield Software Corporation) HKU\Gosia\...\Run: [IncrediMail] - C:\Program Files (x86)\IncrediMail\bin\IncMail.exe [366024 2011-09-14] (IncrediMail, Ltd.) HKU\Piotr\...\Run: [IncrediMail] - C:\Program Files (x86)\IncrediMail\bin\IncMail.exe [366024 2011-09-14] (IncrediMail, Ltd.) HKU\Piotr\...\Run: [ISUSPM Startup] - c:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [196608 2004-04-17] (InstallShield Software Corporation) HKU\Piotr\...\Run: [TorrentStream] - C:\Users\Piotr\AppData\Roaming\TorrentStream\engine\tsengine.exe [27904 2013-09-27] () AppInit_DLLs-x32: c:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll [2704352 2013-10-01] () Startup: C:\Users\Piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Tommy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Tommy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) BootExecute: PDBoot.exeautocheck autochk * ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=F2C06C626DBB44EB&affID=119357&tt=230713_18215&tsp=4953 HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=F2C06C626DBB44EB&affID=119357&tt=230713_18215&tsp=4953 URLSearchHook: (No Name) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={F74FBBA5-998F-42C3-896E-711029D02B0C}&mid=54229efb7f5447d0b9f9bd2b2b5fad18-4b903e41a74b2c038535e5aacda8e6fccecb15d2&lang=pl&ds=xn011&pr=sa&d=2012-12-18 21:03:54&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://startsear.ch/?aff=1&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_btis2&mntrId=F2C06C626DBB44EB&affID=119357&tt=230713_18215&tsp=4953 SearchScopes: HKCU - {3DA92660-0E6B-46C0-B0C1-D80CA9932DC3} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={F74FBBA5-998F-42C3-896E-711029D02B0C}&mid=54229efb7f5447d0b9f9bd2b2b5fad18-4b903e41a74b2c038535e5aacda8e6fccecb15d2&lang=pl&ds=xn011&pr=sa&d=2012-12-18 21:03:54&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: WebConnect - {2316c625-b487-4410-a1a5-ff040b65245f} - C:\Program Files (x86)\WebConnect\WebConnectbho.dll (Web Connect) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: IE5BarLauncherBHO Class - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\17.0.1.12\AVG Secure Search_toolbar.dll (AVG Secure Search) BHO-x32: DealPly Shopping - {9cf699ca-2174-4ed8-bec1-ba82095edce0} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly) BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: No Name - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No File BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.21.5\bh\delta.dll (Delta-search.com) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - VShareToolBar - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\17.0.1.12\AVG Secure Search_toolbar.dll (AVG Secure Search) Toolbar: HKLM-x32 - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll (pdfforge GmbH) Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaTlbr.dll (Delta-search.com) Toolbar: HKCU - No Name - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - No File Toolbar: HKCU - No Name - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - No File DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll (AVG Secure Search) Tcpip\Parameters: [DhcpNameServer] 62.179.1.63 62.179.1.62 FireFox: ======== FF ProfilePath: C:\Users\Tommy\AppData\Roaming\Mozilla\Firefox\Profiles\7r5h5vtw.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.12\\npsitesafety.dll (AVG Technologies) FF Plugin-x32: @idsoftware.com/QuakeLive - C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=3 - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd) FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=9 - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml FF Extension: firefox - C:\Users\Tommy\AppData\Roaming\Mozilla\Firefox\Profiles\7r5h5vtw.default\Extensions\firefox@webconnect.co.xpi FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\17.0.1.12 FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\17.0.1.12 FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt Chrome: ======= CHR Extension: (DealPly Shopping) - C:\Users\Tommy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnmnhkgiphcaeefbaooconkceehicfi\3.5.0.0_0 CHR Extension: (Delta Toolbar) - C:\Users\Tommy\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.4_0 CHR Extension: (DealPly) - C:\Users\Tommy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje\3.5.3.0_0 CHR Extension: (WebConnect) - C:\Users\Tommy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieakfmpjhljbpbfpldjkddkjmmgjmgon\1.0.0_0 CHR Extension: (Skype Click to Call) - C:\Users\Tommy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.11.0.13348_0 CHR Extension: (AVG Secure Search) - C:\Users\Tommy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.5.0.2_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Tommy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Tommy\AppData\Roaming\BabSolution\CR\Delta.crx CHR HKLM-x32\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx CHR HKLM-x32\...\Chrome\Extension: [ieakfmpjhljbpbfpldjkddkjmmgjmgon] - C:\Program Files (x86)\WebConnect\ieakfmpjhljbpbfpldjkddkjmmgjmgon.crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\17.0.1.12\avg.crx ==================== Services (Whitelisted) ================= R2 Akamai; c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-29] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-29] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-29] (Avira Operations GmbH & Co. KG) R2 BBDemon; C:\Program Files\Dassault Systemes\B18\win_b64\code\bin\CATSysDemon.exe [48128 2007-07-03] (Dassault Systemes) R2 BitGuard; C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [3173856 2013-10-01] () R2 CDMA Device Service; C:\Program Files (x86)\Samsung\USB Drivers\26_VIA_driver2\amd64\VIAService.exe [159232 2011-08-02] () S2 dealplylive; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-08-24] (DealPly Technologies Ltd) S3 dealplylivem; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-08-24] (DealPly Technologies Ltd) R2 mitsijm2012; C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe [848704 2011-08-03] (Autodesk, Inc.) R2 PDAgent; C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe [1476360 2009-01-13] (Raxco Software, Inc.) S3 PDEngine; C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe [1471240 2009-01-13] (Raxco Software, Inc.) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) S2 Update WebConnect; C:\Program Files (x86)\WebConnect\updateWebConnect.exe [65320 2013-10-04] (WebConnect) R2 Util WebConnect; C:\Program Files (x86)\WebConnect\bin\utilWebConnect.exe [65320 2013-10-04] (WebConnect) R2 vToolbarUpdater17.0.12; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe [1734680 2013-10-01] (AVG Secure Search) ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-04-14] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-10-01] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-08-29] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-05] (Avira Operations GmbH & Co. KG) S3 COMMONFX.DLL; C:\Windows\System32\COMMONFX.DLL [151296 2007-04-12] (Creative Technology Ltd) S3 CT20XUT.DLL; C:\Windows\System32\CT20XUT.DLL [252712 2007-04-10] (Creative Technology Ltd.) S3 CTAUDFX.DLL; C:\Windows\System32\CTAUDFX.DLL [700200 2007-04-10] (Creative Technology Ltd) S3 CTEAPSFX.DLL; C:\Windows\System32\CTEAPSFX.DLL [219432 2007-04-10] (Creative Technology Ltd) S3 CTEDSPFX.DLL; C:\Windows\System32\CTEDSPFX.DLL [321832 2007-04-10] (Creative Technology Ltd) S3 CTEDSPIO.DLL; C:\Windows\System32\CTEDSPIO.DLL [190248 2007-04-10] (Creative Technology Ltd) S3 CTEDSPSY.DLL; C:\Windows\System32\CTEDSPSY.DLL [363304 2007-04-10] (Creative Technology Ltd) S3 CTERFXFX.DLL; C:\Windows\System32\CTERFXFX.DLL [142120 2007-04-10] (Creative Technology Ltd) S3 CTEXFIFX.DLL; C:\Windows\System32\CTEXFIFX.DLL [1571112 2007-04-10] (Creative Technology Ltd.) S3 CTHWIUT.DLL; C:\Windows\System32\CTHWIUT.DLL [123688 2007-04-10] (Creative Technology Ltd.) S3 CTSBLFX.DLL; C:\Windows\System32\CTSBLFX.DLL [681256 2007-04-10] (Creative Technology Ltd) R3 kxwdmdrv; C:\Windows\System32\drivers\kx.sys [765448 2009-09-18] (Eugene Gavrilov) S3 LGDDCDevice; C:\Program Files (x86)\LG Soft India\forteManager\bin\I2CDriver.sys [14336 2009-04-24] () S3 LGII2CDevice; C:\Program Files (x86)\LG Soft India\forteManager\bin\PII2CDriver.sys [18432 2009-04-24] () R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-04-14] () R0 speedfan; C:\Windows\SysWow64\speedfan.sys [14104 2007-02-07] (Windows (R) Server 2003 DDK provider) R0 speedfan; C:\Windows\SysWow64\speedfan.sys [14104 2007-02-07] (Windows (R) Server 2003 DDK provider) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [203320 2012-02-16] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 dgderdrv; System32\drivers\dgderdrv.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-06 11:31 - 2013-10-06 11:31 - 00000000 ____D C:\FRST 2013-10-06 11:29 - 2013-10-06 11:29 - 01954124 _____ (Farbar) C:\Users\Tommy\Desktop\FRST64.exe 2013-10-06 11:24 - 2013-10-06 11:24 - 00097374 _____ C:\Users\Tommy\Desktop\Extras.Txt 2013-10-06 11:23 - 2013-10-06 11:23 - 00363948 _____ C:\Users\Tommy\Desktop\OTL.Txt 2013-10-06 10:59 - 2013-10-06 10:59 - 99386337 _____ C:\Windows\SysWOW64\䖋” 2013-10-05 15:40 - 2013-10-05 15:40 - 00602112 _____ (OldTimer Tools) C:\Users\Tommy\Desktop\OTL.exe 2013-10-05 15:27 - 2013-10-05 15:27 - 00621568 _____ (Duplex Secure Ltd.) C:\Users\Tommy\Desktop\SPTDinst-v184-x64.exe 2013-10-05 15:04 - 2013-10-05 15:04 - 00000000 ____H C:\Users\Tommy\AppData\Local\BIT756D.tmp 2013-10-05 15:04 - 2013-10-05 15:04 - 00000000 _____ C:\Users\Tommy\AppData\Local\{DDBAED89-DA3E-452C-8613-209E8B448411} 2013-10-05 12:18 - 2013-10-05 12:18 - 00013824 _____ C:\Users\Piotr\Desktop\Chorobowe 2013.xls 2013-10-05 11:29 - 2013-10-05 11:29 - 00015178 _____ C:\Users\Piotr\Desktop\FBAA98CA8EF85DBE4A13C1216C27AA9159585109.torrent 2013-10-05 11:24 - 2013-10-05 11:59 - 105906176 _____ C:\Users\Piotr\Desktop\_Ask _Solid_Professor_.part02.rar 2013-10-04 19:57 - 2013-10-04 19:57 - 00000299 _____ C:\Users\Tommy\Desktop\MASA!!!!!!!!!.txt 2013-10-04 19:23 - 2013-10-04 19:24 - 00000000 ____D C:\Users\Tommy\Desktop\New folder 2013-10-04 16:20 - 2013-10-04 16:54 - 105906176 _____ C:\Users\Piotr\Desktop\_Ask _Solid_Professor_.part01.rar 2013-10-03 16:42 - 2013-10-05 11:01 - 99319274 _____ C:\Windows\SysWOW64\鰦œ 2013-10-01 13:53 - 2013-10-01 13:53 - 00000000 ____D C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-10-01 13:53 - 2013-10-01 13:53 - 00000000 ____D C:\Users\Tommy\AppData\Local\avgchrome 2013-09-30 22:16 - 2013-09-30 22:16 - 00001044 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cebe19ebb49445.job 2013-09-28 13:51 - 2013-10-01 21:28 - 00003728 _____ C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml 2013-09-26 19:12 - 2013-09-26 19:12 - 00000000 ____D C:\Users\Gosia\AppData\Roaming\File Scout 2013-09-26 18:20 - 2013-09-26 18:20 - 97961477 _____ C:\Windows\SysWOW64\ᛡƒ 2013-09-23 18:41 - 2013-09-23 18:41 - 00000000 ____D C:\Users\Tommy\Desktop\20130913-18 2013-09-22 16:48 - 2013-09-22 16:48 - 00002846 _____ C:\Windows\system32\lvcoinst.log 2013-09-22 16:48 - 2013-09-22 16:48 - 00000000 ____D C:\Program Files\Common Files\logishrd 2013-09-22 14:10 - 2013-09-22 14:10 - 00002035 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk 2013-09-22 13:37 - 2013-09-22 13:37 - 00000000 ____D C:\Users\Gosia\Desktop\Dokument_w_szkodzie_PL2013073005383 2013-09-17 20:27 - 2013-09-17 20:27 - 98008335 _____ C:\Windows\SysWOW64\ﻳ灢' 2013-09-16 18:10 - 2013-09-16 18:11 - 00000000 ____D C:\Users\Gosia\AppData\Local\{72530AF8-3B38-408A-B338-170A7670D985} 2013-09-16 18:08 - 2013-10-03 16:40 - 00000000 ____D C:\ProgramData\BitGuard 2013-09-16 18:08 - 2013-09-16 18:08 - 00000000 ____D C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-09-12 09:47 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 09:47 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 09:47 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-12 09:47 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 09:47 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 09:47 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 09:47 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 09:47 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 09:47 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 09:47 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 09:47 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-12 09:47 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-12 09:47 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-12 09:47 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-12 09:47 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-12 09:47 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-12 09:47 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-12 09:47 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-12 09:47 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-12 09:47 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-12 09:47 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-12 09:47 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-12 09:47 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-12 09:47 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-12 09:47 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-12 09:47 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-12 09:47 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-12 09:47 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 09:47 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-12 09:47 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-12 09:47 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-11 21:31 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 21:31 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-11 21:31 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-11 21:31 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-11 21:31 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-11 21:31 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-11 21:31 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-11 21:31 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-11 21:31 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-11 21:31 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-11 21:31 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-11 21:31 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-11 21:31 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-11 21:31 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-11 21:31 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-11 21:31 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-11 21:31 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-11 21:31 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-11 21:31 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-11 21:31 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-11 21:31 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-11 21:31 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 21:31 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-11 21:31 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-11 21:31 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-11 21:31 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-11 21:31 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-11 18:33 - 2013-09-11 18:33 - 00000000 ____D C:\Users\Gosia\AppData\Local\{6AF48282-FF8B-46E9-BCF3-3A9ADD81F133} 2013-09-10 21:47 - 2013-09-10 21:47 - 00000000 ____D C:\Users\Gosia\AppData\Local\{27C4FD09-7D87-4E6E-88EA-07037EBE99E2} 2013-09-10 20:12 - 2013-09-10 20:23 - 00000000 ____D C:\Users\Tommy\Desktop\WODOCIĄGI 2013-09-10 09:49 - 2013-09-10 17:31 - 96985259 _____ C:\Windows\SysWOW64\䋖烴O 2013-09-09 21:10 - 2013-09-09 21:11 - 00000000 ____D C:\Users\Gosia\AppData\Local\{49E00ABC-32A6-43C0-9E0A-C1B6E4F172AC} 2013-09-08 14:56 - 2013-09-09 18:10 - 96732368 _____ C:\Windows\SysWOW64\ꚹ⻊C 2013-09-06 22:47 - 2013-09-06 22:47 - 96470395 _____ C:\Windows\SysWOW64\뗹㌨W ==================== One Month Modified Files and Folders ======= 2013-10-06 11:31 - 2013-10-06 11:31 - 00000000 ____D C:\FRST 2013-10-06 11:29 - 2013-10-06 11:29 - 01954124 _____ (Farbar) C:\Users\Tommy\Desktop\FRST64.exe 2013-10-06 11:24 - 2013-10-06 11:24 - 00097374 _____ C:\Users\Tommy\Desktop\Extras.Txt 2013-10-06 11:23 - 2013-10-06 11:23 - 00363948 _____ C:\Users\Tommy\Desktop\OTL.Txt 2013-10-06 11:15 - 2009-07-14 06:45 - 00013648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-06 11:15 - 2009-07-14 06:45 - 00013648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-06 11:12 - 2011-02-01 16:32 - 01129603 _____ C:\Windows\WindowsUpdate.log 2013-10-06 11:08 - 2013-03-23 16:24 - 00000000 ____D C:\Users\Tommy\AppData\Roaming\Dropbox 2013-10-06 11:05 - 2009-07-14 06:51 - 00176104 _____ C:\Windows\setupact.log 2013-10-06 10:59 - 2013-10-06 10:59 - 99386337 _____ C:\Windows\SysWOW64\䖋” 2013-10-06 10:58 - 2013-08-24 22:39 - 00000000 ____D C:\Users\Tommy\AppData\Roaming\Skype 2013-10-06 10:58 - 2011-02-03 18:17 - 00000000 ____D C:\Users\Gosia 2013-10-05 15:46 - 2009-07-14 07:13 - 00779266 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-05 15:40 - 2013-10-05 15:40 - 00602112 _____ (OldTimer Tools) C:\Users\Tommy\Desktop\OTL.exe 2013-10-05 15:27 - 2013-10-05 15:27 - 00621568 _____ (Duplex Secure Ltd.) C:\Users\Tommy\Desktop\SPTDinst-v184-x64.exe 2013-10-05 15:04 - 2013-10-05 15:04 - 00000000 ____H C:\Users\Tommy\AppData\Local\BIT756D.tmp 2013-10-05 15:04 - 2013-10-05 15:04 - 00000000 _____ C:\Users\Tommy\AppData\Local\{DDBAED89-DA3E-452C-8613-209E8B448411} 2013-10-05 13:50 - 2013-03-23 17:40 - 00000000 ___RD C:\Users\Piotr\Dropbox 2013-10-05 13:50 - 2013-03-23 17:37 - 00000000 ____D C:\Users\Piotr\AppData\Roaming\Dropbox 2013-10-05 13:39 - 2011-03-29 18:29 - 00000000 ____D C:\Users\Piotr\AppData\Roaming\uTorrent 2013-10-05 12:18 - 2013-10-05 12:18 - 00013824 _____ C:\Users\Piotr\Desktop\Chorobowe 2013.xls 2013-10-05 11:59 - 2013-10-05 11:24 - 105906176 _____ C:\Users\Piotr\Desktop\_Ask _Solid_Professor_.part02.rar 2013-10-05 11:30 - 2013-04-30 20:47 - 00000000 ____D C:\Users\Piotr\AppData\Roaming\.Torrent Stream 2013-10-05 11:29 - 2013-10-05 11:29 - 00015178 _____ C:\Users\Piotr\Desktop\FBAA98CA8EF85DBE4A13C1216C27AA9159585109.torrent 2013-10-05 11:01 - 2013-10-03 16:42 - 99319274 _____ C:\Windows\SysWOW64\鰦œ 2013-10-05 00:03 - 2011-10-08 22:18 - 00015562 _____ C:\Users\Tommy\Desktop\pula.txt.txt 2013-10-04 19:57 - 2013-10-04 19:57 - 00000299 _____ C:\Users\Tommy\Desktop\MASA!!!!!!!!!.txt 2013-10-04 19:24 - 2013-10-04 19:23 - 00000000 ____D C:\Users\Tommy\Desktop\New folder 2013-10-04 16:54 - 2013-10-04 16:20 - 105906176 _____ C:\Users\Piotr\Desktop\_Ask _Solid_Professor_.part01.rar 2013-10-04 16:23 - 2011-02-04 19:22 - 00000000 ____D C:\Program Files (x86)\SpeedFan 2013-10-04 14:19 - 2013-02-25 00:14 - 00001179 _____ C:\Users\Tommy\Desktop\blast from the past.txt 2013-10-04 12:54 - 2013-08-24 22:37 - 00000000 ____D C:\Program Files (x86)\WebConnect 2013-10-03 16:40 - 2013-09-16 18:08 - 00000000 ____D C:\ProgramData\BitGuard 2013-10-03 16:40 - 2011-02-03 19:45 - 00054520 _____ C:\Windows\PFRO.log 2013-10-01 21:28 - 2013-09-28 13:51 - 00003728 _____ C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml 2013-10-01 21:28 - 2012-12-18 22:03 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2013-10-01 21:28 - 2012-12-18 22:03 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search 2013-10-01 13:53 - 2013-10-01 13:53 - 00000000 ____D C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-10-01 13:53 - 2013-10-01 13:53 - 00000000 ____D C:\Users\Tommy\AppData\Local\avgchrome 2013-09-30 22:16 - 2013-09-30 22:16 - 00001044 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cebe19ebb49445.job 2013-09-28 14:20 - 2012-12-21 18:45 - 00000000 ____D C:\Users\Tommy\AppData\Roaming\uTorrent 2013-09-28 13:52 - 2013-07-24 15:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-26 20:21 - 2013-01-10 10:05 - 00000000 ____D C:\Users\Tommy\Desktop\mp3 2013-09-26 20:14 - 2013-08-28 22:52 - 00000000 ____D C:\Users\Gosia\AppData\Roaming\Skype 2013-09-26 19:12 - 2013-09-26 19:12 - 00000000 ____D C:\Users\Gosia\AppData\Roaming\File Scout 2013-09-26 18:20 - 2013-09-26 18:20 - 97961477 _____ C:\Windows\SysWOW64\ᛡƒ 2013-09-25 08:43 - 2013-08-24 22:39 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-09-23 18:41 - 2013-09-23 18:41 - 00000000 ____D C:\Users\Tommy\Desktop\20130913-18 2013-09-22 16:48 - 2013-09-22 16:48 - 00002846 _____ C:\Windows\system32\lvcoinst.log 2013-09-22 16:48 - 2013-09-22 16:48 - 00000000 ____D C:\Program Files\Common Files\logishrd 2013-09-22 14:10 - 2013-09-22 14:10 - 00002035 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk 2013-09-22 13:37 - 2013-09-22 13:37 - 00000000 ____D C:\Users\Gosia\Desktop\Dokument_w_szkodzie_PL2013073005383 2013-09-21 18:54 - 2012-09-09 16:49 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-21 18:54 - 2012-06-23 16:32 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-21 18:54 - 2011-08-23 17:01 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-21 09:57 - 2011-02-01 16:33 - 00000000 ___RD C:\Users\Piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-21 09:57 - 2011-02-01 16:33 - 00000000 ___RD C:\Users\Piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-17 20:27 - 2013-09-17 20:27 - 98008335 _____ C:\Windows\SysWOW64\ﻳ灢' 2013-09-16 18:11 - 2013-09-16 18:10 - 00000000 ____D C:\Users\Gosia\AppData\Local\{72530AF8-3B38-408A-B338-170A7670D985} 2013-09-16 18:08 - 2013-09-16 18:08 - 00000000 ____D C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-09-16 18:08 - 2011-02-03 18:17 - 00000000 ___RD C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-16 18:08 - 2011-02-03 18:17 - 00000000 ___RD C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 10:07 - 2011-02-03 18:16 - 00000000 ___RD C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-12 10:07 - 2011-02-03 18:16 - 00000000 ___RD C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 10:06 - 2009-07-14 06:45 - 00428160 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 09:47 - 2013-07-16 15:44 - 00000000 ____D C:\Windows\system32\MRT 2013-09-12 09:44 - 2011-02-01 17:28 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-11 19:07 - 2012-12-18 22:03 - 00000000 ____D C:\ProgramData\AVG Secure Search 2013-09-11 18:33 - 2013-09-11 18:33 - 00000000 ____D C:\Users\Gosia\AppData\Local\{6AF48282-FF8B-46E9-BCF3-3A9ADD81F133} 2013-09-10 21:47 - 2013-09-10 21:47 - 00000000 ____D C:\Users\Gosia\AppData\Local\{27C4FD09-7D87-4E6E-88EA-07037EBE99E2} 2013-09-10 20:23 - 2013-09-10 20:12 - 00000000 ____D C:\Users\Tommy\Desktop\WODOCIĄGI 2013-09-10 17:31 - 2013-09-10 09:49 - 96985259 _____ C:\Windows\SysWOW64\䋖烴O 2013-09-09 21:11 - 2013-09-09 21:10 - 00000000 ____D C:\Users\Gosia\AppData\Local\{49E00ABC-32A6-43C0-9E0A-C1B6E4F172AC} 2013-09-09 18:10 - 2013-09-08 14:56 - 96732368 _____ C:\Windows\SysWOW64\ꚹ⻊C 2013-09-06 22:47 - 2013-09-06 22:47 - 96470395 _____ C:\Windows\SysWOW64\뗹㌨W 2013-09-06 17:29 - 2012-11-09 21:30 - 00000000 ____D C:\ProgramData\2DBoy 2013-09-06 16:01 - 2013-08-24 22:37 - 00000900 _____ C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job 2013-09-06 16:01 - 2013-05-31 20:30 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2013-09-06 15:58 - 2013-08-15 18:57 - 00003436 _____ C:\Windows\System32\Tasks\BrowserDefendert 2013-09-06 15:58 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-06 15:49 - 2013-09-05 21:04 - 96334488 _____ C:\Windows\SysWOW64\ꜙ詳 2013-09-06 15:49 - 2013-08-24 22:37 - 00000904 _____ C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job 2013-09-06 15:49 - 2013-08-24 22:37 - 00000290 _____ C:\Windows\Tasks\Dealply.job 2013-09-06 15:49 - 2012-05-06 18:58 - 00001046 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-06 00:29 - 2012-01-25 19:50 - 00025600 _____ C:\Users\Tommy\Desktop\sr.xls Files to move or delete: ==================== C:\Users\Tommy\CDBIDXL.DAT C:\Users\Tommy\NECDB.DAT C:\Users\Tommy\NETRKDB.DAT C:\Users\Tommy\TDBIDXL.DAT Some content of TEMP: ==================== C:\Users\Gosia\AppData\Local\Temp\AskSLib.dll C:\Users\Gosia\AppData\Local\Temp\setup_fsu_cid.exe C:\Users\Gosia\AppData\Local\Temp\sfamcc00001.dll C:\Users\Gosia\AppData\Local\Temp\sfareca00001.dll C:\Users\Piotr\AppData\Local\Temp\AcDeltree.exe C:\Users\Piotr\AppData\Local\Temp\AEV4A7F.exe C:\Users\Piotr\AppData\Local\Temp\AskSLib.dll C:\Users\Piotr\AppData\Local\Temp\BASSMOD.DLL C:\Users\Piotr\AppData\Local\Temp\bitool.dll C:\Users\Piotr\AppData\Local\Temp\DTLite4413-0173.exe C:\Users\Piotr\AppData\Local\Temp\DTLite4471-0335.exe C:\Users\Piotr\AppData\Local\Temp\FNP_ACT_InstallerCA.dll C:\Users\Piotr\AppData\Local\Temp\GLF2EE7.tmp.ConduitEngineSetup.exe C:\Users\Piotr\AppData\Local\Temp\IncrediMail_MediaBar_2.exe C:\Users\Piotr\AppData\Local\Temp\sfamcc00001.dll C:\Users\Piotr\AppData\Local\Temp\sfamcc00002.dll C:\Users\Piotr\AppData\Local\Temp\sfareca00001.dll C:\Users\Piotr\AppData\Local\Temp\_is92AD.exe C:\Users\Tommy\AppData\Local\Temp\AcDeltree.exe C:\Users\Tommy\AppData\Local\Temp\AskSLib.dll C:\Users\Tommy\AppData\Local\Temp\AVGInstaller.exe C:\Users\Tommy\AppData\Local\Temp\binkw32.dll C:\Users\Tommy\AppData\Local\Temp\chutil.dll C:\Users\Tommy\AppData\Local\Temp\comver.dll C:\Users\Tommy\AppData\Local\Temp\Core.dll C:\Users\Tommy\AppData\Local\Temp\drm_dialogs.dll C:\Users\Tommy\AppData\Local\Temp\drm_dyndata_7400009.dll C:\Users\Tommy\AppData\Local\Temp\drm_dyndata_7410004.dll C:\Users\Tommy\AppData\Local\Temp\Engine.dll C:\Users\Tommy\AppData\Local\Temp\gtapi.dll C:\Users\Tommy\AppData\Local\Temp\IFC23.dll C:\Users\Tommy\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe C:\Users\Tommy\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe C:\Users\Tommy\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe C:\Users\Tommy\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\Tommy\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Tommy\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Tommy\AppData\Local\Temp\msvci70.dll C:\Users\Tommy\AppData\Local\Temp\msvci70d.dll C:\Users\Tommy\AppData\Local\Temp\msvcirt.dll C:\Users\Tommy\AppData\Local\Temp\msvcp70.dll C:\Users\Tommy\AppData\Local\Temp\msvcp70d.dll C:\Users\Tommy\AppData\Local\Temp\msvcp71.dll C:\Users\Tommy\AppData\Local\Temp\msvcp71d.dll C:\Users\Tommy\AppData\Local\Temp\MSVCR70.dll C:\Users\Tommy\AppData\Local\Temp\MSVCR70d.dll C:\Users\Tommy\AppData\Local\Temp\MSVCR71.dll C:\Users\Tommy\AppData\Local\Temp\MSVCR71d.dll C:\Users\Tommy\AppData\Local\Temp\msvcr80.dll C:\Users\Tommy\AppData\Local\Temp\MSVCRt.dll C:\Users\Tommy\AppData\Local\Temp\nsoB443.tmp.ConduitEngineEmbbed.exe C:\Users\Tommy\AppData\Local\Temp\ogg.dll C:\Users\Tommy\AppData\Local\Temp\ogg_d.dll C:\Users\Tommy\AppData\Local\Temp\oi_{3E862E98-D5AF-4697-B060-9368D8D5FAFE}.exe C:\Users\Tommy\AppData\Local\Temp\rama_demo.exe C:\Users\Tommy\AppData\Local\Temp\Setup.exe C:\Users\Tommy\AppData\Local\Temp\sfamcc00001.dll C:\Users\Tommy\AppData\Local\Temp\sfamcc00002.dll C:\Users\Tommy\AppData\Local\Temp\sfamcc00003.dll C:\Users\Tommy\AppData\Local\Temp\sfamcc00004.dll C:\Users\Tommy\AppData\Local\Temp\sfamcc00005.dll C:\Users\Tommy\AppData\Local\Temp\sfamcc00006.dll C:\Users\Tommy\AppData\Local\Temp\sfamcc00007.dll C:\Users\Tommy\AppData\Local\Temp\sfamcc00008.dll C:\Users\Tommy\AppData\Local\Temp\sfareca00005.dll C:\Users\Tommy\AppData\Local\Temp\sfareca00006.dll C:\Users\Tommy\AppData\Local\Temp\sfareca00007.dll C:\Users\Tommy\AppData\Local\Temp\sfareca00008.dll C:\Users\Tommy\AppData\Local\Temp\sfextra.dll C:\Users\Tommy\AppData\Local\Temp\SimPack.exe C:\Users\Tommy\AppData\Local\Temp\sqlite3.dll C:\Users\Tommy\AppData\Local\Temp\tbInc0.dll C:\Users\Tommy\AppData\Local\Temp\ubi14C.tmp.exe C:\Users\Tommy\AppData\Local\Temp\ubi4F30.tmp.exe C:\Users\Tommy\AppData\Local\Temp\ubi79AE.tmp.exe C:\Users\Tommy\AppData\Local\Temp\ubiF2E0.tmp.exe C:\Users\Tommy\AppData\Local\Temp\ubiF3C2.tmp.exe C:\Users\Tommy\AppData\Local\Temp\vorbis.dll C:\Users\Tommy\AppData\Local\Temp\vorbisfile.dll C:\Users\Tommy\AppData\Local\Temp\vorbisfile_d.dll C:\Users\Tommy\AppData\Local\Temp\vorbis_d.dll C:\Users\Tommy\AppData\Local\Temp\Window.dll C:\Users\Tommy\AppData\Local\Temp\wuhgohcn.dll C:\Users\Tommy\AppData\Local\Temp\xmlUpdater.exe C:\Users\Tommy\AppData\Local\Temp\zlib1.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-01 18:26 ==================== End Of Log ============================