Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-10-2013 Ran by Janek (administrator) on JANEK-NOTEBOOK on 31-10-2013 13:43:25 Running from C:\Users\Janek\Desktop Windows 7 Ultimate (X64) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Autodesk, Inc.) C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe (Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe (Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\loggingserver.exe (Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\DataProxy.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Autodesk, Inc.) C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe (Vimicro) C:\Program Files (x86)\USB Camera\VM331_STI.EXE ( ) C:\Program Files (x86)\LockKey\LockKey.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe () C:\Program Files (x86)\AVG Secure Search\vprot.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2864016 2012-08-08] (ELAN Microelectronics Corp.) HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8071680 2012-12-11] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [6193152 2012-12-11] (Lenovo(beijing) Limited) HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd) HKCU\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1081224 2013-02-05] (Autodesk, Inc.) HKCU\...\Policies\Explorer: [] HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-21] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [Dolby Advanced Audio v2] - C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [507744 2011-12-20] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [331BigDog] - C:\Program Files (x86)\USB Camera\VM331_STI.EXE [548864 2011-11-24] (Vimicro) HKLM-x32\...\Run: [LockKey] - C:\Program Files (x86)\LockKey\LockKey.exe [337776 2011-08-25] ( ) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG Secure Search\vprot.exe [2404376 2013-10-01] () HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKU\UpdatusUser\...\Run: [AVG-Secure-Search-Update_JUNE2013_TB] - C:\Program Files (x86)\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe [1266712 2013-06-03] (AVG Secure Search) AppInit_DLLs: c:\PROGRA~3\BitGuard\271769~1.27\{C16C1~1\loader.dll c:\Windows\System32\nvinitx.dll [97280 2009-07-14] () AppInit_DLLs-x32: c:\PROGRA~3\BitGuard\271769~1.27\{C16C1~1\BitGuard.dll [2735584 2013-10-22] () Lsa: [Notification Packages] scecli C:\Program Files\Lenovo\Bluetooth Software\BtwProximityCP.dll ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.idg.pl/start HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.22find.com/newtab?utm_source=b&utm_medium=prs&from=prs&uid=ST1000LM024XHN-M101MBB_S2U5JACCA28662&ts=1362419811 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A028C0143DD4807F&affID=119357&tsp=5012 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.22find.com/web/?utm_source=b&utm_medium=prs&from=prs&uid=ST1000LM024XHN-M101MBB_S2U5JACCA28662&ts=1362419813 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={1335E23F-D9BB-4A3B-B42F-EB56FE046309}&mid=0028c198fa91415d9ad7f5511f902596-7013a3bda34ea410c23a47e6af72c9f18f827ae6&lang=pl&ds=ik011&pr=&d=2012-12-23 18:47:31&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} SearchScopes: HKCU - ŰźĆîZ§’2ąŢpv¨IÍá*X(Ž2s(ŰÎŔJşÔÓµť± vË°!×—(äĽ48иpatm6ęo^Mp`Ëő÷_iŁw˜ľ!„Áű†x˘8€ŮjŔ˙ţ ´Ń;áa´[¦†8 ş~ŹRŮxśňÜ8'Ł-)x­ä­ URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\17.0.1.12\AVG Secure Search_toolbar.dll (AVG Secure Search) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\17.0.1.12\AVG Secure Search_toolbar.dll (AVG Secure Search) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll (AVG Secure Search) Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 192.168.1.251 Chrome: ======= CHR HomePage: \r\nhxxp://www.idg.pl/start\r\n CHR Extension: (Google Drive) - C:\Users\Janek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Janek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Janek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (avast! Online Security) - C:\Users\Janek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Janek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Deezer) - C:\Users\Janek\AppData\Local\Google\Chrome\User Data\Default\Extensions\npfkoakaabdallkcdbpkkhfilkkngakh\1.3.2_0 CHR Extension: (Gmail) - C:\Users\Janek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [ijblflkdjdopkpdgllkmlbgcffjbnfda] - C:\Users\Janek\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\17.0.1.12\avg.crx ==================== Services (Whitelisted) ================= R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.) S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2010-12-28] (www.BitComet.com) R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [945440 2012-02-01] (Broadcom Corporation.) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-29] (Intel Corporation) S2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2013-10-08] () R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 mitsijm2012; C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe [848184 2010-12-08] (Autodesk, Inc.) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () R2 vToolbarUpdater17.0.12; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe [1734680 2013-10-01] (AVG Secure Search) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-10-01] (AVG Technologies) S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2012-02-02] (Broadcom Corporation.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-11] (DT Soft Ltd) R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104048 2012-03-02] (Qualcomm Atheros Co., Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [952832 2011-12-06] (Vimicro Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-31 13:42 - 2013-10-31 13:42 - 00000000 ____D C:\FRST 2013-10-31 13:12 - 2013-10-31 13:13 - 01956614 _____ (Farbar) C:\Users\Janek\Desktop\FRST64.exe 2013-10-31 13:11 - 2013-10-31 13:11 - 00602112 _____ (OldTimer Tools) C:\Users\Janek\Desktop\OTL (1).exe 2013-10-31 13:10 - 2013-10-31 13:10 - 00602112 _____ (OldTimer Tools) C:\Users\Janek\Desktop\OTL.exe 2013-10-31 13:00 - 2013-10-31 13:07 - 127231689 _____ (Igor Pavlov) C:\Users\Janek\Desktop\OTLPENet.exe 2013-10-30 18:46 - 2013-10-30 19:01 - 280908168 _____ (Lenovo Group ) C:\Users\Janek\Desktop\0lto15ww.exe 2013-10-30 17:11 - 2013-10-31 13:11 - 00000288 _____ C:\Windows\Tasks\FoxTab.job 2013-10-30 17:11 - 2013-10-30 17:11 - 00003240 _____ C:\Windows\System32\Tasks\FoxTab 2013-10-30 17:11 - 2013-10-30 17:11 - 00000000 ____D C:\Users\Janek\Downloads\gmer 2013-10-30 17:11 - 2013-10-30 17:11 - 00000000 ____D C:\Users\Janek\AppData\Roaming\FoxTab 2013-10-30 16:56 - 2013-10-30 17:11 - 149980136 _____ (Lenovo Group ) C:\Users\Janek\Desktop\Niepotwierdzony 112168.crdownload 2013-10-30 16:32 - 2013-10-30 16:32 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2013-10-30 16:32 - 2013-10-30 16:32 - 00000000 ____D C:\Users\Janek\AppData\Roaming\Malwarebytes 2013-10-30 16:32 - 2013-10-30 16:32 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-30 16:32 - 2013-10-30 16:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-30 16:32 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-30 16:28 - 2013-10-30 16:28 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Janek\Desktop\mbam-setup-1.75.0.1300 (1).exe 2013-10-30 16:18 - 2013-10-30 16:18 - 00022996 _____ C:\ComboFix.txt 2013-10-30 14:14 - 2013-10-30 14:14 - 00000000 ____D C:\TDSSKiller_Quarantine 2013-10-30 14:13 - 2013-10-30 14:13 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\Janek\Desktop\tdsskiller_3.0.0.14.exe 2013-10-30 08:23 - 2013-10-30 14:15 - 00003420 _____ C:\Windows\System32\Tasks\BitGuard 2013-10-30 08:22 - 2013-10-30 08:22 - 844038934 _____ C:\Windows\MEMORY.DMP 2013-10-30 08:22 - 2013-10-30 08:22 - 00724416 _____ C:\Windows\Minidump\103013-20638-01.dmp 2013-10-30 08:22 - 2013-10-30 08:22 - 00000000 ____D C:\Windows\Minidump 2013-10-29 23:46 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2013-10-29 23:46 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2013-10-29 23:46 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-10-29 23:46 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-10-29 23:46 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-10-29 23:46 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2013-10-29 23:46 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2013-10-29 23:46 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2013-10-29 23:45 - 2013-10-30 16:18 - 00000000 ____D C:\Qoobox 2013-10-29 23:45 - 2013-10-30 00:10 - 00000000 ____D C:\Windows\erdnt 2013-10-29 23:44 - 2013-10-30 06:31 - 05137879 ____R (Swearware) C:\Users\Janek\Desktop\ComboFix.exe 2013-10-29 23:41 - 2013-10-29 23:41 - 00000000 ____D C:\Users\Janek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-10-29 22:41 - 2013-10-29 22:41 - 00000000 ____D C:\Users\Janek\Documents\Splashtop Whiteboard 2013-10-29 22:41 - 2013-10-29 22:41 - 00000000 ____D C:\Users\Janek\Documents\Splashtop Presenter 2013-10-29 22:40 - 2013-10-29 22:45 - 00000000 ____D C:\Windows\system32\appmgmt 2013-10-29 20:20 - 2013-10-29 20:20 - 00000000 ____D C:\Users\Janek\AppData\Local\HTRI 2013-10-29 20:11 - 2013-10-29 20:11 - 00000000 ____D C:\ProgramData\HTRI 2013-10-29 20:09 - 2013-10-29 20:09 - 00000000 ____D C:\Users\Janek\AppData\Local\SafeNet Sentinel 2013-10-29 20:09 - 2013-10-29 20:09 - 00000000 ____D C:\ProgramData\SafeNet Sentinel 2013-10-29 20:06 - 2013-10-30 00:36 - 00000000 ____D C:\Program Files (x86)\HTRI 2013-10-29 20:04 - 2013-10-29 20:04 - 00000000 ____D C:\Users\Janek\Desktop\HXS7R 2013-10-29 16:29 - 2013-10-29 16:29 - 00000000 ____D C:\Users\Janek\Desktop\HTRI.Xchanger.Suite.6.00 2013-10-29 16:23 - 2013-10-29 22:43 - 00000000 ____D C:\Program Files (x86)\Dowwnnload keeeper 2013-10-29 16:18 - 2013-10-29 16:18 - 00000000 ____D C:\ProgramData\WinterSoft 2013-10-29 11:54 - 2013-10-30 00:36 - 00000000 ____D C:\Program Files (x86)\SearchNewTab 2013-10-29 11:53 - 2013-10-29 22:46 - 00000000 ____D C:\Program Files (x86)\WebSearch 2013-10-29 11:53 - 2013-10-29 22:46 - 00000000 ____D C:\Program Files (x86)\Ss.Helper 2013-10-29 11:52 - 2013-10-30 00:36 - 00000000 ____D C:\Program Files (x86)\Download keepeer 2013-10-29 11:51 - 2013-10-29 16:28 - 00000000 ____D C:\ProgramData\InstallMate 2013-10-24 21:08 - 2013-10-30 00:36 - 00000000 ____D C:\Users\Janek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Urządzenia interfejsu Bluetooth 2013-10-23 21:21 - 2013-10-23 21:54 - 00000000 ____D C:\Users\Janek\AppData\Roaming\LyX2.0 2013-10-23 21:21 - 2013-10-23 21:21 - 00000000 ____D C:\Users\Janek\AppData\Roaming\MiKTeX 2013-10-23 19:01 - 2013-10-23 19:01 - 00000000 ____D C:\Users\Janek\AppData\Local\MiKTeX 2013-10-23 18:51 - 2013-10-23 18:51 - 00000000 ____D C:\ProgramData\MiKTeX 2013-10-23 18:49 - 2013-10-23 18:50 - 00000000 ____D C:\Program Files (x86)\MiKTeX 2.9 2013-10-23 18:46 - 2013-10-30 00:36 - 00000000 ____D C:\Program Files (x86)\LyX 2.0 2013-10-22 09:20 - 2013-10-22 09:20 - 00000000 ____D C:\ProgramData\Oracle 2013-10-21 12:46 - 2013-10-21 12:46 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-10-21 11:50 - 2013-10-21 11:50 - 00000000 ____D C:\Users\Janek\.android 2013-10-18 06:40 - 2013-10-28 17:49 - 00000000 ____D C:\Users\Janek\Desktop\Metsa 2013-10-16 22:40 - 2013-10-16 22:40 - 00000000 ___SD C:\Users\Janek\Documents\Moje źródła danych 2013-10-15 10:50 - 2013-10-30 16:53 - 00000000 ____D C:\Users\Janek\Documents\Pliki programu Outlook 2013-10-14 19:57 - 2013-10-14 19:57 - 00000000 ____D C:\Users\Janek\Documents\Inventor Server x64 AutoCAD 2012 Language Pack - Polski 2013-10-10 18:04 - 2013-10-10 18:04 - 00000984 _____ C:\Users\Janek\AppData\Local\recently-used.xbel 2013-10-10 17:00 - 2013-10-10 17:03 - 01409024 _____ C:\Users\Janek\Documents\Zadania.accdb 2013-10-10 15:57 - 2013-10-10 15:58 - 00000000 ____D C:\Users\Janek\Documents\maya 2013-10-08 08:00 - 2013-10-08 19:55 - 00008192 _____ C:\Windows\SysWOW64\srvany.exe 2013-10-04 16:40 - 2013-10-04 16:40 - 00006792 _____ C:\Users\Janek\Koparka.ipj 2013-10-04 16:40 - 2013-10-04 16:40 - 00000000 ____D C:\Users\Janek\OldVersions 2013-10-04 09:18 - 2013-10-16 22:10 - 00000000 ____D C:\Users\Janek\Desktop\CAD ==================== One Month Modified Files and Folders ======= 2013-10-31 13:42 - 2013-10-31 13:42 - 00000000 ____D C:\FRST 2013-10-31 13:13 - 2013-10-31 13:12 - 01956614 _____ (Farbar) C:\Users\Janek\Desktop\FRST64.exe 2013-10-31 13:11 - 2013-10-31 13:11 - 00602112 _____ (OldTimer Tools) C:\Users\Janek\Desktop\OTL (1).exe 2013-10-31 13:11 - 2013-10-30 17:11 - 00000288 _____ C:\Windows\Tasks\FoxTab.job 2013-10-31 13:11 - 2012-12-11 01:41 - 00001046 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-31 13:10 - 2013-10-31 13:10 - 00602112 _____ (OldTimer Tools) C:\Users\Janek\Desktop\OTL.exe 2013-10-31 13:07 - 2013-10-31 13:00 - 127231689 _____ (Igor Pavlov) C:\Users\Janek\Desktop\OTLPENet.exe 2013-10-31 13:04 - 2009-07-14 05:45 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-31 13:04 - 2009-07-14 05:45 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-31 13:01 - 2012-12-13 23:27 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-31 13:01 - 2009-07-14 18:55 - 00748030 _____ C:\Windows\system32\perfh015.dat 2013-10-31 13:01 - 2009-07-14 18:55 - 00160564 _____ C:\Windows\system32\perfc015.dat 2013-10-31 13:01 - 2009-07-14 06:13 - 01693022 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-31 13:00 - 2012-12-10 23:33 - 01989045 _____ C:\Windows\WindowsUpdate.log 2013-10-31 12:56 - 2013-01-13 23:58 - 00000440 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-10-31 12:56 - 2012-12-11 01:41 - 00001042 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-31 12:56 - 2012-12-11 00:18 - 00043796 _____ C:\Windows\PFRO.log 2013-10-31 12:56 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-31 12:56 - 2009-07-14 05:51 - 00110586 _____ C:\Windows\setupact.log 2013-10-30 19:01 - 2013-10-30 18:46 - 280908168 _____ (Lenovo Group ) C:\Users\Janek\Desktop\0lto15ww.exe 2013-10-30 17:11 - 2013-10-30 17:11 - 00003240 _____ C:\Windows\System32\Tasks\FoxTab 2013-10-30 17:11 - 2013-10-30 17:11 - 00000000 ____D C:\Users\Janek\Downloads\gmer 2013-10-30 17:11 - 2013-10-30 17:11 - 00000000 ____D C:\Users\Janek\AppData\Roaming\FoxTab 2013-10-30 17:11 - 2013-10-30 16:56 - 149980136 _____ (Lenovo Group ) C:\Users\Janek\Desktop\Niepotwierdzony 112168.crdownload 2013-10-30 16:53 - 2013-10-15 10:50 - 00000000 ____D C:\Users\Janek\Documents\Pliki programu Outlook 2013-10-30 16:40 - 2013-09-21 19:20 - 00000000 ____D C:\ProgramData\DSearchLink 2013-10-30 16:32 - 2013-10-30 16:32 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2013-10-30 16:32 - 2013-10-30 16:32 - 00000000 ____D C:\Users\Janek\AppData\Roaming\Malwarebytes 2013-10-30 16:32 - 2013-10-30 16:32 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-30 16:32 - 2013-10-30 16:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-30 16:28 - 2013-10-30 16:28 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Janek\Desktop\mbam-setup-1.75.0.1300 (1).exe 2013-10-30 16:18 - 2013-10-30 16:18 - 00022996 _____ C:\ComboFix.txt 2013-10-30 16:18 - 2013-10-29 23:45 - 00000000 ____D C:\Qoobox 2013-10-30 16:15 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2013-10-30 14:22 - 2012-12-11 01:26 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-10-30 14:15 - 2013-10-30 08:23 - 00003420 _____ C:\Windows\System32\Tasks\BitGuard 2013-10-30 14:14 - 2013-10-30 14:14 - 00000000 ____D C:\TDSSKiller_Quarantine 2013-10-30 14:13 - 2013-10-30 14:13 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\Janek\Desktop\tdsskiller_3.0.0.14.exe 2013-10-30 08:22 - 2013-10-30 08:22 - 844038934 _____ C:\Windows\MEMORY.DMP 2013-10-30 08:22 - 2013-10-30 08:22 - 00724416 _____ C:\Windows\Minidump\103013-20638-01.dmp 2013-10-30 08:22 - 2013-10-30 08:22 - 00000000 ____D C:\Windows\Minidump 2013-10-30 06:31 - 2013-10-29 23:44 - 05137879 ____R (Swearware) C:\Users\Janek\Desktop\ComboFix.exe 2013-10-30 06:26 - 2013-09-21 19:21 - 00000000 ____D C:\ProgramData\BitGuard 2013-10-30 00:36 - 2013-10-29 20:06 - 00000000 ____D C:\Program Files (x86)\HTRI 2013-10-30 00:36 - 2013-10-29 11:54 - 00000000 ____D C:\Program Files (x86)\SearchNewTab 2013-10-30 00:36 - 2013-10-29 11:52 - 00000000 ____D C:\Program Files (x86)\Download keepeer 2013-10-30 00:36 - 2013-10-24 21:08 - 00000000 ____D C:\Users\Janek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Urządzenia interfejsu Bluetooth 2013-10-30 00:36 - 2013-10-23 18:46 - 00000000 ____D C:\Program Files (x86)\LyX 2.0 2013-10-30 00:36 - 2013-04-04 03:12 - 00000000 ____D C:\Users\Janek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unified Remote 2013-10-30 00:36 - 2013-04-04 03:12 - 00000000 ____D C:\Program Files (x86)\Unified Remote 2013-10-30 00:36 - 2013-04-04 02:51 - 00000000 ____D C:\ProgramData\Splashtop 2013-10-30 00:36 - 2013-04-04 02:51 - 00000000 ____D C:\Program Files (x86)\Splashtop 2013-10-30 00:36 - 2013-03-04 18:57 - 00000000 ____D C:\Users\Janek\AppData\Roaming\IrfanView 2013-10-30 00:36 - 2012-12-11 00:21 - 00000000 ____D C:\Users\Janek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo 2013-10-30 00:36 - 2012-12-10 23:47 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-10-30 00:36 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-10-30 00:36 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\security 2013-10-30 00:36 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2013-10-30 00:36 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\AppCompat 2013-10-30 00:35 - 2013-09-21 20:09 - 00000000 ____D C:\Users\Janek\AppData\Roaming\abgx360 2013-10-30 00:34 - 2013-03-12 22:34 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-30 00:13 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2013-10-30 00:10 - 2013-10-29 23:45 - 00000000 ____D C:\Windows\erdnt 2013-10-29 23:43 - 2012-12-11 01:26 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-10-29 23:41 - 2013-10-29 23:41 - 00000000 ____D C:\Users\Janek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-10-29 23:38 - 2012-12-10 23:37 - 00000000 ____D C:\Users\Janek 2013-10-29 22:46 - 2013-10-29 11:53 - 00000000 ____D C:\Program Files (x86)\WebSearch 2013-10-29 22:46 - 2013-10-29 11:53 - 00000000 ____D C:\Program Files (x86)\Ss.Helper 2013-10-29 22:45 - 2013-10-29 22:40 - 00000000 ____D C:\Windows\system32\appmgmt 2013-10-29 22:43 - 2013-10-29 16:23 - 00000000 ____D C:\Program Files (x86)\Dowwnnload keeeper 2013-10-29 22:41 - 2013-10-29 22:41 - 00000000 ____D C:\Users\Janek\Documents\Splashtop Whiteboard 2013-10-29 22:41 - 2013-10-29 22:41 - 00000000 ____D C:\Users\Janek\Documents\Splashtop Presenter 2013-10-29 20:20 - 2013-10-29 20:20 - 00000000 ____D C:\Users\Janek\AppData\Local\HTRI 2013-10-29 20:11 - 2013-10-29 20:11 - 00000000 ____D C:\ProgramData\HTRI 2013-10-29 20:09 - 2013-10-29 20:09 - 00000000 ____D C:\Users\Janek\AppData\Local\SafeNet Sentinel 2013-10-29 20:09 - 2013-10-29 20:09 - 00000000 ____D C:\ProgramData\SafeNet Sentinel 2013-10-29 20:04 - 2013-10-29 20:04 - 00000000 ____D C:\Users\Janek\Desktop\HXS7R 2013-10-29 16:29 - 2013-10-29 16:29 - 00000000 ____D C:\Users\Janek\Desktop\HTRI.Xchanger.Suite.6.00 2013-10-29 16:28 - 2013-10-29 11:51 - 00000000 ____D C:\ProgramData\InstallMate 2013-10-29 16:18 - 2013-10-29 16:18 - 00000000 ____D C:\ProgramData\WinterSoft 2013-10-28 17:49 - 2013-10-18 06:40 - 00000000 ____D C:\Users\Janek\Desktop\Metsa 2013-10-23 21:54 - 2013-10-23 21:21 - 00000000 ____D C:\Users\Janek\AppData\Roaming\LyX2.0 2013-10-23 21:21 - 2013-10-23 21:21 - 00000000 ____D C:\Users\Janek\AppData\Roaming\MiKTeX 2013-10-23 19:01 - 2013-10-23 19:01 - 00000000 ____D C:\Users\Janek\AppData\Local\MiKTeX 2013-10-23 18:51 - 2013-10-23 18:51 - 00000000 ____D C:\ProgramData\MiKTeX 2013-10-23 18:50 - 2013-10-23 18:49 - 00000000 ____D C:\Program Files (x86)\MiKTeX 2.9 2013-10-22 09:20 - 2013-10-22 09:20 - 00000000 ____D C:\ProgramData\Oracle 2013-10-21 22:17 - 2012-12-11 02:44 - 00000000 ____D C:\Users\Janek\AppData\Roaming\DAEMON Tools Lite 2013-10-21 12:46 - 2013-10-21 12:46 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-10-21 11:50 - 2013-10-21 11:50 - 00000000 ____D C:\Users\Janek\.android 2013-10-16 22:57 - 2012-12-11 14:29 - 00000000 ____D C:\Users\Janek\AppData\Local\Microsoft Help 2013-10-16 22:40 - 2013-10-16 22:40 - 00000000 ___SD C:\Users\Janek\Documents\Moje źródła danych 2013-10-16 22:10 - 2013-10-04 09:18 - 00000000 ____D C:\Users\Janek\Desktop\CAD 2013-10-16 21:11 - 2013-01-31 21:50 - 00000000 ____D C:\Users\Janek\AppData\Local\cache 2013-10-15 09:08 - 2009-07-14 05:45 - 00524624 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-14 19:58 - 2012-12-11 00:19 - 00158824 _____ C:\Users\Janek\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-14 19:57 - 2013-10-14 19:57 - 00000000 ____D C:\Users\Janek\Documents\Inventor Server x64 AutoCAD 2012 Language Pack - Polski 2013-10-14 19:57 - 2013-01-31 21:29 - 00000000 ____D C:\ProgramData\Autodesk 2013-10-14 19:56 - 2013-01-31 21:40 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared 2013-10-14 19:53 - 2013-01-31 21:41 - 00000000 ____D C:\Users\Janek\AppData\Local\Autodesk 2013-10-14 19:53 - 2013-01-31 21:40 - 00000000 ____D C:\Program Files\Autodesk 2013-10-14 19:53 - 2013-01-31 21:29 - 00000000 ____D C:\Users\Janek\AppData\Roaming\Autodesk 2013-10-14 19:51 - 2013-01-08 22:15 - 00032721 _____ C:\Windows\DirectX.log 2013-10-14 19:51 - 2012-12-11 00:16 - 01669160 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-14 19:14 - 2013-01-31 21:24 - 00000000 ____D C:\Autodesk 2013-10-12 11:06 - 2012-12-11 01:41 - 00004042 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-12 11:06 - 2012-12-11 01:41 - 00003790 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-10 21:33 - 2012-12-11 02:13 - 00000000 ____D C:\Users\Janek\.gimp-2.8 2013-10-10 18:04 - 2013-10-10 18:04 - 00000984 _____ C:\Users\Janek\AppData\Local\recently-used.xbel 2013-10-10 17:11 - 2013-06-20 22:31 - 00000000 ____D C:\Users\Public\Documents\Autodesk 2013-10-10 17:03 - 2013-10-10 17:00 - 01409024 _____ C:\Users\Janek\Documents\Zadania.accdb 2013-10-10 15:58 - 2013-10-10 15:57 - 00000000 ____D C:\Users\Janek\Documents\maya 2013-10-10 15:42 - 2012-12-10 23:53 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-10 15:42 - 2012-12-10 23:52 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-10-08 23:02 - 2012-12-13 23:27 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-08 23:02 - 2012-12-13 23:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-08 23:02 - 2012-12-13 23:27 - 00003868 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-08 20:35 - 2013-06-20 22:34 - 00000000 ____D C:\Users\Janek\Documents\Inventor 2013-10-08 19:55 - 2013-10-08 08:00 - 00008192 _____ C:\Windows\SysWOW64\srvany.exe 2013-10-04 16:40 - 2013-10-04 16:40 - 00006792 _____ C:\Users\Janek\Koparka.ipj 2013-10-04 16:40 - 2013-10-04 16:40 - 00000000 ____D C:\Users\Janek\OldVersions 2013-10-04 10:16 - 2013-06-20 22:38 - 00000000 ____D C:\Users\Janek\coverage 2013-10-04 09:23 - 2013-02-10 23:11 - 00000000 ____D C:\Users\Janek\AppData\Roaming\BitComet 2013-10-01 22:00 - 2012-12-23 18:47 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2013-10-01 22:00 - 2012-12-23 18:47 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search Some content of TEMP: ==================== C:\Users\Janek\AppData\Local\Temp\56295uninstall.exe C:\Users\Janek\AppData\Local\Temp\Sqlite3.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-21 00:51 ==================== End Of Log ============================