Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by Tommy (administrator) on STACJONARNY_DOM on 14-10-2013 18:32:51 Running from C:\Users\Tommy\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Dassault Systemes) C:\Program Files\Dassault Systemes\B18\win_b64\code\bin\CATSysDemon.exe () C:\Program Files (x86)\Samsung\USB Drivers\26_VIA_driver2\amd64\VIAService.exe (Autodesk, Inc.) C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe (Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Raxco Software, Inc.) C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Eugene Gavrilov) C:\Program Files\kX Audio Driver\3550\kxmixer.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Raxco Software, Inc.) C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe (Raxco Software, Inc.) C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [kX Mixer] - C:\Program Files\kX Audio Driver\3550\kxmixer.exe [677896 2009-09-18] (Eugene Gavrilov) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3521464 2012-05-30] (Samsung Electronics Co., Ltd.) HKCU\...\Run: [Gadu-Gadu] - C:\Program Files (x86)\Gadu-Gadu\gg.exe [2127296 2008-03-20] (Gadu-Gadu S.A.) HKCU\...\Run: [KiesPDLR] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-05-30] () HKCU\...\Run: [Akamai NetSession Interface] - "C:\Users\Tommy\AppData\Local\Akamai\netsession_win.exe" HKCU\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [196608 2004-04-17] (InstallShield Software Corporation) HKCU\...\Run: [DAEMON Tools Lite] - "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20472992 2013-10-02] (Skype Technologies S.A.) MountPoints2: I - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\Autorun.exe MountPoints2: {2573ded5-2fb4-11e0-97ad-6c626dbb44eb} - I:\Autorun.exe MountPoints2: {3de07190-6279-11e2-a1b6-6c626dbb44eb} - I:\Monkey.exe MountPoints2: {7571b8a3-3c1d-11e0-b3d0-6c626dbb44eb} - K:\LaunchU3.exe -a MountPoints2: {8507f83c-52cd-11e0-bc48-6c626dbb44eb} - J:\LaunchU3.exe -a MountPoints2: {8507f88e-52cd-11e0-bc48-6c626dbb44eb} - I:\LaunchU3.exe -a HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2443376 2010-07-06] (VIA) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-07-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.) HKLM-x32\...\Run: [KiesHelper] - C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2013-09-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2013-09-03] (Adobe Systems Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-29] (Avira Operations GmbH & Co. KG) HKU\Gosia\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.) HKU\Gosia\...\Run: [ISUSPM Startup] - c:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [196608 2004-04-17] (InstallShield Software Corporation) HKU\Gosia\...\Run: [IncrediMail] - C:\Program Files (x86)\IncrediMail\bin\IncMail.exe [366024 2011-09-14] (IncrediMail, Ltd.) HKU\Piotr\...\Run: [IncrediMail] - C:\Program Files (x86)\IncrediMail\bin\IncMail.exe [366024 2011-09-14] (IncrediMail, Ltd.) HKU\Piotr\...\Run: [ISUSPM Startup] - c:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [196608 2004-04-17] (InstallShield Software Corporation) HKU\Piotr\...\Run: [TorrentStream] - C:\Users\Piotr\AppData\Roaming\TorrentStream\engine\tsengine.exe [27904 2013-09-27] () HKU\Piotr\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_8_800_168_Plugin.exe [815496 2013-09-21] (Adobe Systems Incorporated) Startup: C:\Users\Piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Tommy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Tommy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) BootExecute: PDBoot.exeautocheck autochk * ==================== Internet (Whitelisted) ==================== SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://startsear.ch/?aff=1&q={searchTerms} SearchScopes: HKCU - {3DA92660-0E6B-46C0-B0C1-D80CA9932DC3} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKCU - No Name - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - No File DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 62.179.1.63 62.179.1.62 FireFox: ======== FF ProfilePath: C:\Users\Tommy\AppData\Roaming\Mozilla\Firefox\Profiles\97u5n4q4.default-1381764047446 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @idsoftware.com/QuakeLive - C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.12\\npsitesafety.dll No File CHR Plugin: (DealPlyLive Update) - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) CHR Plugin: (QUAKE LIVE) - C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (Skype Click to Call) - C:\Users\Tommy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.13.0.13771_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Tommy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-29] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-29] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-29] (Avira Operations GmbH & Co. KG) R2 BBDemon; C:\Program Files\Dassault Systemes\B18\win_b64\code\bin\CATSysDemon.exe [48128 2007-07-03] (Dassault Systemes) R2 CDMA Device Service; C:\Program Files (x86)\Samsung\USB Drivers\26_VIA_driver2\amd64\VIAService.exe [159232 2011-08-02] () R2 mitsijm2012; C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe [848704 2011-08-03] (Autodesk, Inc.) R2 PDAgent; C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe [1476360 2009-01-13] (Raxco Software, Inc.) S3 PDEngine; C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe [1471240 2009-01-13] (Raxco Software, Inc.) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) S2 vToolbarUpdater17.0.12; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe [x] ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-04-14] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-10-01] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-08-29] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-05] (Avira Operations GmbH & Co. KG) S3 COMMONFX.DLL; C:\Windows\System32\COMMONFX.DLL [151296 2007-04-12] (Creative Technology Ltd) S3 CT20XUT.DLL; C:\Windows\System32\CT20XUT.DLL [252712 2007-04-10] (Creative Technology Ltd.) S3 CTAUDFX.DLL; C:\Windows\System32\CTAUDFX.DLL [700200 2007-04-10] (Creative Technology Ltd) S3 CTEAPSFX.DLL; C:\Windows\System32\CTEAPSFX.DLL [219432 2007-04-10] (Creative Technology Ltd) S3 CTEDSPFX.DLL; C:\Windows\System32\CTEDSPFX.DLL [321832 2007-04-10] (Creative Technology Ltd) S3 CTEDSPIO.DLL; C:\Windows\System32\CTEDSPIO.DLL [190248 2007-04-10] (Creative Technology Ltd) S3 CTEDSPSY.DLL; C:\Windows\System32\CTEDSPSY.DLL [363304 2007-04-10] (Creative Technology Ltd) S3 CTERFXFX.DLL; C:\Windows\System32\CTERFXFX.DLL [142120 2007-04-10] (Creative Technology Ltd) S3 CTEXFIFX.DLL; C:\Windows\System32\CTEXFIFX.DLL [1571112 2007-04-10] (Creative Technology Ltd.) S3 CTHWIUT.DLL; C:\Windows\System32\CTHWIUT.DLL [123688 2007-04-10] (Creative Technology Ltd.) S3 CTSBLFX.DLL; C:\Windows\System32\CTSBLFX.DLL [681256 2007-04-10] (Creative Technology Ltd) R3 kxwdmdrv; C:\Windows\System32\drivers\kx.sys [765448 2009-09-18] (Eugene Gavrilov) S3 LGDDCDevice; C:\Program Files (x86)\LG Soft India\forteManager\bin\I2CDriver.sys [14336 2009-04-24] () S3 LGII2CDevice; C:\Program Files (x86)\LG Soft India\forteManager\bin\PII2CDriver.sys [18432 2009-04-24] () R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-04-14] () R0 speedfan; C:\Windows\SysWow64\speedfan.sys [14104 2007-02-07] (Windows (R) Server 2003 DDK provider) R0 speedfan; C:\Windows\SysWow64\speedfan.sys [14104 2007-02-07] (Windows (R) Server 2003 DDK provider) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [203320 2012-02-16] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 dgderdrv; System32\drivers\dgderdrv.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-14 18:29 - 2013-10-14 18:29 - 00000000 ____D C:\Users\Tommy\Desktop\Skan 2013-10-14 18:03 - 2013-10-14 18:03 - 00448512 _____ (OldTimer Tools) C:\Users\Tommy\Desktop\TFC.exe 2013-10-14 17:49 - 2013-10-14 17:56 - 00000000 ____D C:\AdwCleaner 2013-10-14 17:48 - 2013-10-14 17:48 - 01048960 _____ C:\Users\Tommy\Desktop\AdwCleaner.exe 2013-10-14 17:20 - 2013-10-14 17:20 - 00000000 ____D C:\Users\Tommy\Desktop\Stare dane programu Firefox 2013-10-14 17:16 - 2013-10-14 17:16 - 00000000 _____ C:\Users\Tommy\Desktop\abc.html 2013-10-13 16:40 - 2013-10-14 12:35 - 100856651 _____ C:\Windows\SysWOW64\珙䰨‹ 2013-10-13 10:43 - 2013-09-04 14:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-13 10:43 - 2013-09-04 14:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-13 10:43 - 2013-09-04 14:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-13 10:43 - 2013-09-04 14:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-13 10:43 - 2013-09-04 14:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-13 10:43 - 2013-09-04 14:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-13 10:43 - 2013-09-04 14:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-12 23:10 - 2013-10-12 23:10 - 00000000 ____D C:\Users\Piotr\Desktop\New folder 2013-10-12 22:44 - 2013-10-12 22:44 - 100651105 _____ C:\Windows\SysWOW64\겑뙶™ 2013-10-12 00:34 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-12 00:34 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-12 00:34 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-12 00:34 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-12 00:34 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-12 00:34 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-12 00:34 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-12 00:34 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-12 00:34 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-12 00:34 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-12 00:34 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-12 00:34 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-12 00:34 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-12 00:34 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-12 00:34 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-12 00:34 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-12 00:34 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-12 00:34 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-12 00:34 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-12 00:34 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-12 00:34 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-12 00:34 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-12 00:34 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-12 00:33 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-12 00:33 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-12 00:33 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-12 00:33 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-12 00:33 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-12 00:33 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-12 00:33 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-12 00:33 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-11 12:25 - 2013-09-14 03:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-11 12:25 - 2013-09-08 04:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-11 12:25 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-11 12:25 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-11 12:25 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-11 12:25 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-11 12:25 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-11 12:25 - 2013-08-29 04:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-11 12:25 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-11 12:25 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-11 12:25 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-11 12:25 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-11 12:25 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-11 12:25 - 2013-08-29 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-11 12:25 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-11 12:25 - 2013-08-29 02:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-11 12:25 - 2013-08-29 02:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-11 12:25 - 2013-08-29 02:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-11 12:25 - 2013-08-29 02:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-11 12:25 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-11 12:25 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-11 12:25 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-11 12:25 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-11 12:25 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-11 12:25 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-11 12:25 - 2013-07-12 12:40 - 00109824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys 2013-10-11 12:25 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-11 12:25 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-11 12:25 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-11 12:25 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-11 12:25 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-11 12:25 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-11 12:25 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-11 12:25 - 2013-07-03 06:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-11 12:25 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-11 12:25 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-11 12:25 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-11 12:25 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-11 12:25 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-11 12:25 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-11 12:25 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-11 12:25 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-11 12:25 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-11 12:25 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-11 12:25 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-11 12:25 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-11 12:25 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-10 23:05 - 2013-10-11 12:13 - 100470597 _____ C:\Windows\SysWOW64\㛈덻ª 2013-10-09 22:48 - 2013-10-10 17:06 - 100267706 _____ C:\Windows\SysWOW64\㤭侃Œ 2013-10-09 16:48 - 2013-10-09 16:48 - 100146679 _____ C:\Windows\SysWOW64\ꁜ亚™ 2013-10-08 23:16 - 2013-10-08 23:16 - 00000000 ____D C:\Users\Tommy\Desktop\Technologia_Robot_Budowlanych 2013-10-08 20:12 - 2013-10-08 20:12 - 00000000 ____D C:\Users\Tommy\Documents\Autodesk 2013-10-08 20:11 - 2013-10-08 20:11 - 00002111 _____ C:\Users\Public\Desktop\Autodesk Robot Structural Analysis Professional 2013.lnk 2013-10-08 19:08 - 2013-10-08 19:08 - 00000948 _____ C:\Users\Tommy\Desktop\LMTOOLS Utility.lnk 2013-10-08 19:08 - 2013-10-08 19:08 - 00000000 ____D C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autodesk 2013-10-08 19:08 - 2013-10-08 19:08 - 00000000 ____D C:\Program Files\Autodesk Network License Manager 2013-10-08 13:54 - 2013-10-08 13:54 - 99859239 _____ C:\Windows\SysWOW64\꿼㦞 2013-10-07 18:20 - 2013-10-07 18:20 - 99717279 _____ C:\Windows\SysWOW64\빘㴵@ 2013-10-06 16:59 - 2013-10-07 08:49 - 99582406 _____ C:\Windows\SysWOW64\靼搡– 2013-10-06 11:41 - 2013-10-06 11:41 - 00377856 _____ C:\Users\Tommy\Desktop\llxtehlw.exe 2013-10-06 11:31 - 2013-10-06 11:31 - 00000000 ____D C:\FRST 2013-10-06 11:29 - 2013-10-06 11:29 - 01954124 _____ (Farbar) C:\Users\Tommy\Desktop\FRST64.exe 2013-10-06 10:59 - 2013-10-06 10:59 - 99386337 _____ C:\Windows\SysWOW64\䖋” 2013-10-05 15:40 - 2013-10-05 15:40 - 00602112 _____ (OldTimer Tools) C:\Users\Tommy\Desktop\OTL.exe 2013-10-05 15:27 - 2013-10-05 15:27 - 00621568 _____ (Duplex Secure Ltd.) C:\Users\Tommy\Desktop\SPTDinst-v184-x64.exe 2013-10-05 15:04 - 2013-10-05 15:04 - 00000000 ____H C:\Users\Tommy\AppData\Local\BIT756D.tmp 2013-10-05 15:04 - 2013-10-05 15:04 - 00000000 _____ C:\Users\Tommy\AppData\Local\{DDBAED89-DA3E-452C-8613-209E8B448411} 2013-10-05 12:18 - 2013-10-05 12:18 - 00013824 _____ C:\Users\Piotr\Desktop\Chorobowe 2013.xls 2013-10-05 11:29 - 2013-10-05 11:29 - 00015178 _____ C:\Users\Piotr\Desktop\FBAA98CA8EF85DBE4A13C1216C27AA9159585109.torrent 2013-10-04 19:57 - 2013-10-04 19:57 - 00000299 _____ C:\Users\Tommy\Desktop\MASA!!!!!!!!!.txt 2013-10-03 16:42 - 2013-10-05 11:01 - 99319274 _____ C:\Windows\SysWOW64\鰦œ 2013-10-01 13:53 - 2013-10-01 13:53 - 00000000 ____D C:\Users\Tommy\AppData\Local\avgchrome 2013-09-30 22:16 - 2013-09-30 22:16 - 00001044 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cebe19ebb49445.job 2013-09-26 18:20 - 2013-09-26 18:20 - 97961477 _____ C:\Windows\SysWOW64\ᛡƒ 2013-09-23 18:41 - 2013-09-23 18:41 - 00000000 ____D C:\Users\Tommy\Desktop\20130913-18 2013-09-22 16:48 - 2013-09-22 16:48 - 00002846 _____ C:\Windows\system32\lvcoinst.log 2013-09-22 16:48 - 2013-09-22 16:48 - 00000000 ____D C:\Program Files\Common Files\logishrd 2013-09-22 14:10 - 2013-09-22 14:10 - 00002035 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk 2013-09-22 13:37 - 2013-09-22 13:37 - 00000000 ____D C:\Users\Gosia\Desktop\Dokument_w_szkodzie_PL2013073005383 2013-09-17 20:27 - 2013-09-17 20:27 - 98008335 _____ C:\Windows\SysWOW64\ﻳ灢' 2013-09-16 18:10 - 2013-09-16 18:11 - 00000000 ____D C:\Users\Gosia\AppData\Local\{72530AF8-3B38-408A-B338-170A7670D985} ==================== One Month Modified Files and Folders ======= 2013-10-14 18:29 - 2013-10-14 18:29 - 00000000 ____D C:\Users\Tommy\Desktop\Skan 2013-10-14 18:17 - 2013-08-24 22:39 - 00000000 ____D C:\Users\Tommy\AppData\Roaming\Skype 2013-10-14 18:06 - 2009-07-14 06:45 - 00013648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-14 18:06 - 2009-07-14 06:45 - 00013648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-14 18:03 - 2013-10-14 18:03 - 00448512 _____ (OldTimer Tools) C:\Users\Tommy\Desktop\TFC.exe 2013-10-14 17:59 - 2013-03-23 16:24 - 00000000 ____D C:\Users\Tommy\AppData\Roaming\Dropbox 2013-10-14 17:57 - 2011-02-03 19:45 - 00065462 _____ C:\Windows\PFRO.log 2013-10-14 17:57 - 2009-07-14 06:51 - 00177448 _____ C:\Windows\setupact.log 2013-10-14 17:56 - 2013-10-14 17:49 - 00000000 ____D C:\AdwCleaner 2013-10-14 17:56 - 2011-02-01 16:32 - 01758611 _____ C:\Windows\WindowsUpdate.log 2013-10-14 17:48 - 2013-10-14 17:48 - 01048960 _____ C:\Users\Tommy\Desktop\AdwCleaner.exe 2013-10-14 17:20 - 2013-10-14 17:20 - 00000000 ____D C:\Users\Tommy\Desktop\Stare dane programu Firefox 2013-10-14 17:16 - 2013-10-14 17:16 - 00000000 _____ C:\Users\Tommy\Desktop\abc.html 2013-10-14 12:35 - 2013-10-13 16:40 - 100856651 _____ C:\Windows\SysWOW64\珙䰨‹ 2013-10-14 12:35 - 2013-08-24 22:39 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-10-14 12:35 - 2012-12-21 18:45 - 00000000 ____D C:\Users\Tommy\AppData\Roaming\uTorrent 2013-10-13 21:25 - 2011-10-08 22:18 - 00016060 _____ C:\Users\Tommy\Desktop\pula.txt.txt 2013-10-13 17:22 - 2013-08-24 22:38 - 00000000 ____D C:\ProgramData\Skype 2013-10-13 16:28 - 2011-02-04 19:22 - 00000000 ____D C:\Program Files (x86)\SpeedFan 2013-10-12 23:10 - 2013-10-12 23:10 - 00000000 ____D C:\Users\Piotr\Desktop\New folder 2013-10-12 23:06 - 2009-07-14 07:13 - 00779266 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-12 22:44 - 2013-10-12 22:44 - 100651105 _____ C:\Windows\SysWOW64\겑뙶™ 2013-10-12 13:05 - 2013-03-23 17:40 - 00000000 ___RD C:\Users\Piotr\Dropbox 2013-10-12 13:05 - 2013-03-23 17:37 - 00000000 ____D C:\Users\Piotr\AppData\Roaming\Dropbox 2013-10-12 13:04 - 2011-02-01 16:39 - 00128152 _____ C:\Users\Piotr\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-12 13:02 - 2009-07-14 06:45 - 00428784 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-12 00:32 - 2013-03-14 00:15 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 00:32 - 2013-03-14 00:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-12 00:32 - 2011-03-27 17:11 - 00764734 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-12 00:26 - 2013-07-16 15:44 - 00000000 ____D C:\Windows\system32\MRT 2013-10-12 00:24 - 2011-02-01 17:28 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-11 12:13 - 2013-10-10 23:05 - 100470597 _____ C:\Windows\SysWOW64\㛈덻ª 2013-10-10 17:06 - 2013-10-09 22:48 - 100267706 _____ C:\Windows\SysWOW64\㤭侃Œ 2013-10-09 21:17 - 2011-02-01 16:33 - 00000000 ____D C:\Users\Piotr 2013-10-09 19:32 - 2011-03-27 18:44 - 00000000 ____D C:\Users\Tommy\AppData\Roaming\Autodesk 2013-10-09 16:48 - 2013-10-09 16:48 - 100146679 _____ C:\Windows\SysWOW64\ꁜ亚™ 2013-10-08 23:16 - 2013-10-08 23:16 - 00000000 ____D C:\Users\Tommy\Desktop\Technologia_Robot_Budowlanych 2013-10-08 20:19 - 2011-02-03 18:17 - 00128152 _____ C:\Users\Tommy\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-08 20:16 - 2011-03-27 18:44 - 00000000 ____D C:\Users\Tommy\AppData\Local\Autodesk 2013-10-08 20:16 - 2011-03-20 17:01 - 00000000 ____D C:\ProgramData\Autodesk 2013-10-08 20:12 - 2013-10-08 20:12 - 00000000 ____D C:\Users\Tommy\Documents\Autodesk 2013-10-08 20:11 - 2013-10-08 20:11 - 00002111 _____ C:\Users\Public\Desktop\Autodesk Robot Structural Analysis Professional 2013.lnk 2013-10-08 20:07 - 2011-03-27 16:36 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared 2013-10-08 20:02 - 2011-02-04 18:07 - 00612128 _____ C:\Windows\DirectX.log 2013-10-08 19:58 - 2011-03-27 16:37 - 00000000 ____D C:\Program Files\Autodesk 2013-10-08 19:08 - 2013-10-08 19:08 - 00000948 _____ C:\Users\Tommy\Desktop\LMTOOLS Utility.lnk 2013-10-08 19:08 - 2013-10-08 19:08 - 00000000 ____D C:\Users\Tommy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autodesk 2013-10-08 19:08 - 2013-10-08 19:08 - 00000000 ____D C:\Program Files\Autodesk Network License Manager 2013-10-08 13:54 - 2013-10-08 13:54 - 99859239 _____ C:\Windows\SysWOW64\꿼㦞 2013-10-07 18:28 - 2011-02-03 23:59 - 00000000 ____D C:\Program Files (x86)\Gadu-Gadu 2013-10-07 18:20 - 2013-10-07 18:20 - 99717279 _____ C:\Windows\SysWOW64\빘㴵@ 2013-10-07 08:49 - 2013-10-06 16:59 - 99582406 _____ C:\Windows\SysWOW64\靼搡– 2013-10-06 16:24 - 2011-02-01 17:37 - 00000000 ____D C:\Program Files (x86)\Opera 2013-10-06 11:41 - 2013-10-06 11:41 - 00377856 _____ C:\Users\Tommy\Desktop\llxtehlw.exe 2013-10-06 11:31 - 2013-10-06 11:31 - 00000000 ____D C:\FRST 2013-10-06 11:29 - 2013-10-06 11:29 - 01954124 _____ (Farbar) C:\Users\Tommy\Desktop\FRST64.exe 2013-10-06 10:59 - 2013-10-06 10:59 - 99386337 _____ C:\Windows\SysWOW64\䖋” 2013-10-06 10:58 - 2011-02-03 18:17 - 00000000 ____D C:\Users\Gosia 2013-10-05 15:40 - 2013-10-05 15:40 - 00602112 _____ (OldTimer Tools) C:\Users\Tommy\Desktop\OTL.exe 2013-10-05 15:27 - 2013-10-05 15:27 - 00621568 _____ (Duplex Secure Ltd.) C:\Users\Tommy\Desktop\SPTDinst-v184-x64.exe 2013-10-05 15:04 - 2013-10-05 15:04 - 00000000 ____H C:\Users\Tommy\AppData\Local\BIT756D.tmp 2013-10-05 15:04 - 2013-10-05 15:04 - 00000000 _____ C:\Users\Tommy\AppData\Local\{DDBAED89-DA3E-452C-8613-209E8B448411} 2013-10-05 13:39 - 2011-03-29 18:29 - 00000000 ____D C:\Users\Piotr\AppData\Roaming\uTorrent 2013-10-05 12:18 - 2013-10-05 12:18 - 00013824 _____ C:\Users\Piotr\Desktop\Chorobowe 2013.xls 2013-10-05 11:30 - 2013-04-30 20:47 - 00000000 ____D C:\Users\Piotr\AppData\Roaming\.Torrent Stream 2013-10-05 11:29 - 2013-10-05 11:29 - 00015178 _____ C:\Users\Piotr\Desktop\FBAA98CA8EF85DBE4A13C1216C27AA9159585109.torrent 2013-10-05 11:01 - 2013-10-03 16:42 - 99319274 _____ C:\Windows\SysWOW64\鰦œ 2013-10-04 19:57 - 2013-10-04 19:57 - 00000299 _____ C:\Users\Tommy\Desktop\MASA!!!!!!!!!.txt 2013-10-04 14:19 - 2013-02-25 00:14 - 00001179 _____ C:\Users\Tommy\Desktop\blast from the past.txt 2013-10-01 21:28 - 2012-12-18 22:03 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2013-10-01 13:53 - 2013-10-01 13:53 - 00000000 ____D C:\Users\Tommy\AppData\Local\avgchrome 2013-09-30 22:16 - 2013-09-30 22:16 - 00001044 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cebe19ebb49445.job 2013-09-28 13:52 - 2013-07-24 15:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-26 20:21 - 2013-01-10 10:05 - 00000000 ____D C:\Users\Tommy\Desktop\mp3 2013-09-26 20:14 - 2013-08-28 22:52 - 00000000 ____D C:\Users\Gosia\AppData\Roaming\Skype 2013-09-26 18:20 - 2013-09-26 18:20 - 97961477 _____ C:\Windows\SysWOW64\ᛡƒ 2013-09-23 18:41 - 2013-09-23 18:41 - 00000000 ____D C:\Users\Tommy\Desktop\20130913-18 2013-09-23 01:28 - 2013-10-12 00:34 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-23 01:28 - 2013-10-12 00:33 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-23 01:27 - 2013-10-12 00:34 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-23 01:27 - 2013-10-12 00:34 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-23 01:27 - 2013-10-12 00:34 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-23 01:27 - 2013-10-12 00:34 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-23 01:27 - 2013-10-12 00:34 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-23 01:27 - 2013-10-12 00:34 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-23 01:27 - 2013-10-12 00:34 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-23 01:27 - 2013-10-12 00:34 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-23 01:27 - 2013-10-12 00:33 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-23 01:27 - 2013-10-12 00:33 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-23 01:27 - 2013-10-12 00:33 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-23 00:55 - 2013-10-12 00:34 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 00:55 - 2013-10-12 00:34 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 00:55 - 2013-10-12 00:33 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 00:54 - 2013-10-12 00:34 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 00:54 - 2013-10-12 00:34 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 00:54 - 2013-10-12 00:34 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 00:54 - 2013-10-12 00:34 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-23 00:54 - 2013-10-12 00:34 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-23 00:54 - 2013-10-12 00:34 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-23 00:54 - 2013-10-12 00:34 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-23 00:54 - 2013-10-12 00:34 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-23 00:54 - 2013-10-12 00:33 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 00:54 - 2013-10-12 00:33 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 00:54 - 2013-10-12 00:33 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-22 16:48 - 2013-09-22 16:48 - 00002846 _____ C:\Windows\system32\lvcoinst.log 2013-09-22 16:48 - 2013-09-22 16:48 - 00000000 ____D C:\Program Files\Common Files\logishrd 2013-09-22 14:10 - 2013-09-22 14:10 - 00002035 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk 2013-09-22 13:37 - 2013-09-22 13:37 - 00000000 ____D C:\Users\Gosia\Desktop\Dokument_w_szkodzie_PL2013073005383 2013-09-21 18:54 - 2012-09-09 16:49 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-21 18:54 - 2012-06-23 16:32 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-21 18:54 - 2011-08-23 17:01 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-21 09:57 - 2011-02-01 16:33 - 00000000 ___RD C:\Users\Piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-21 09:57 - 2011-02-01 16:33 - 00000000 ___RD C:\Users\Piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-21 05:38 - 2013-10-12 00:34 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-21 05:30 - 2013-10-12 00:34 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-21 04:48 - 2013-10-12 00:34 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-21 04:39 - 2013-10-12 00:34 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-17 20:27 - 2013-09-17 20:27 - 98008335 _____ C:\Windows\SysWOW64\ﻳ灢' 2013-09-16 18:11 - 2013-09-16 18:10 - 00000000 ____D C:\Users\Gosia\AppData\Local\{72530AF8-3B38-408A-B338-170A7670D985} 2013-09-16 18:08 - 2011-02-03 18:17 - 00000000 ___RD C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-16 18:08 - 2011-02-03 18:17 - 00000000 ___RD C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-14 03:10 - 2013-10-11 12:25 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys Files to move or delete: ==================== C:\Users\Tommy\CDBIDXL.DAT C:\Users\Tommy\NECDB.DAT C:\Users\Tommy\NETRKDB.DAT C:\Users\Tommy\TDBIDXL.DAT ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-01 18:26 ==================== End Of Log ============================