Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-12-2013 01 Ran by sony (administrator) on SONY-VAIO on 13-12-2013 16:34:42 Running from C:\Users\sony\Downloads Windows 7 Home Premium (X64) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgfws.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (France Telecom SA) C:\Program Files (x86)\Common Files\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSpt.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Somoto) C:\Users\sony\AppData\Local\FilesFrog Update Checker\update_checker.exe () C:\Users\sony\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe (Dropbox, Inc.) C:\Users\sony\AppData\Roaming\Dropbox\bin\Dropbox.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (France Telecom SA) C:\Program Files (x86)\CardDetector\ZTEMF192\CardDetector.exe (France Telecom) C:\Program Files (x86)\OrangeBS\BEWInternet-PL\Phonetools\SmsNotify.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Gadu-Gadu S.A.) C:\Program Files (x86)\Gadu-Gadu\gg.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10775584 2010-05-31] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-05-31] (Realtek Semiconductor) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [212480 2010-05-31] (Alps Electric Co., Ltd.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Gadu-Gadu] - C:\Program Files (x86)\Gadu-Gadu\gg.exe [2113536 2007-04-17] (Gadu-Gadu S.A.) HKCU\...\Run: [Mobile Partner] - C:\Program Files (x86)\MobileWiFi\MobileWiFi HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18672232 2013-02-28] (Skype Technologies S.A.) HKCU\...\Run: [SDP] - C:\Users\sony\AppData\Local\FilesFrog Update Checker\update_checker.exe [201808 2013-01-31] (Somoto) HKCU\...\Run: [AppsHat] - C:\Users\sony\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe [202752 2012-10-26] () HKCU\...\Run: [SpeedUpMyComputer] - C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe [2054776 2013-07-22] () HKCU\...\Run: [Facebook Update] - C:\Users\sony\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-09-26] (Facebook Inc.) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-02-09] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [BEWINTERNET-PLSessionManager] - C:\Program Files (x86)\OrangeBS\BEWInternet-PL\SessionManager\SessionManager.exe [140016 2011-02-23] (France Telecom SA) HKLM-x32\...\Run: [CardDetectorZTEMF192] - C:\Program Files (x86)\CardDetector\ZTEMF192\CardDetector.exe [290816 2011-02-23] (France Telecom SA) HKLM-x32\...\Run: [BEWINTERNET-PLSMSNotify] - C:\Program Files (x86)\OrangeBS\BEWInternet-PL\Phonetools\SmsNotify.exe [131072 2011-02-23] (France Telecom) HKLM-x32\...\Run: [NSU_agent] - C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe [190768 2012-02-28] () HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [SweetIM] - C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.) HKLM-x32\...\Run: [Sweetpacks Communicator] - C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.) Startup: C:\Users\sony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\sony\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) BootExecute: autocheck autochk * bootdelete ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=0AF54A0F6EDD5E91&affID=119357&tsp=5003 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000.10014&barid={4FA1B0AE-5CFC-11E2-8EAE-544249EC04F7} URLSearchHook: HKLM-x32 - Default Value = {FE69C007-C452-4d3e-86D2-1730DF8BC871} URLSearchHook: HKLM-x32 - SimilarSites - {FE69C007-C452-4d3e-86D2-1730DF8BC871} - C:\Program Files (x86)\SimilarSites\SimilarSites.dll (SimilarGroup) URLSearchHook: HKCU - Default Value = {FE69C007-C452-4d3e-86D2-1730DF8BC871} URLSearchHook: HKCU - SimilarSites - {FE69C007-C452-4d3e-86D2-1730DF8BC871} - C:\Program Files (x86)\SimilarSites\SimilarSites.dll (SimilarGroup) URLSearchHook: HKCU - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10014&barid={4FA1B0AE-5CFC-11E2-8EAE-544249EC04F7} SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.mocaflix.com/?l=1&q={searchTerms} SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10014&barid={4FA1B0AE-5CFC-11E2-8EAE-544249EC04F7} SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=0AF54A0F6EDD5E91&affID=119357&tsp=5003 SearchScopes: HKCU - {183B9556-6CB9-4E7A-BDCE-20EF570BF23B} URL = http://services.zinio.com/search?s={searchTerms}&rf=sonyslices SearchScopes: HKCU - {391379D3-1AA2-4482-9269-F5298F036798} URL = http://rover.ebay.com/rover/1//4?satitle={searchTerms} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.mocaflix.com/?l=1&q={searchTerms} SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10014&barid={4FA1B0AE-5CFC-11E2-8EAE-544249EC04F7} BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: MinibarBHO - {AA74D58F-ACD0-450D-A85E-6C04B171C044} - C:\Program Files (x86)\Minibar\Minibar.dll (KangoExtensions) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Shopping Suggestion. - {e7e8ed77-2fba-4ec6-bc07-65de4de6709f} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) Toolbar: HKLM-x32 - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) Toolbar: HKLM-x32 - SimilarSites - {FE69C007-C452-4d3e-86D2-1730DF8BC871} - C:\Program Files (x86)\SimilarSites\SimilarSites.dll (SimilarGroup) Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.) DPF: HKLM {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/PL/Core/Player/2020PlayerAX_IKEA_Win32.cab DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\sony\AppData\Roaming\Mozilla\Firefox\Profiles\nvftkoyj.default FF user.js: detected! => C:\Users\sony\AppData\Roaming\Mozilla\Firefox\Profiles\nvftkoyj.default\user.js FF Homepage: about:newtab|https://www.google.pl/ FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=6.0.12.450 - C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\sony\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\sony\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\sony\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\sony\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\sony\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\sony\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\sony\AppData\Roaming\Mozilla\Firefox\Profiles\nvftkoyj.default\searchplugins\sweetim.xml FF Extension: Download and Sa - C:\Users\sony\AppData\Roaming\Mozilla\Firefox\Profiles\nvftkoyj.default\Extensions\50c0bffb06dfa@50c0bffb06e34.com FF Extension: Bargain Workbench - C:\Users\sony\AppData\Roaming\Mozilla\Firefox\Profiles\nvftkoyj.default\Extensions\{8eaa2500-4118-4c33-9927-988702ba63bd} FF Extension: AppsHat - C:\Users\sony\AppData\Roaming\Mozilla\Firefox\Profiles\nvftkoyj.default\Extensions\{97A78363-B868-4B48-AC91-A783A31215AF} FF Extension: SimilarSites - C:\Users\sony\AppData\Roaming\Mozilla\Firefox\Profiles\nvftkoyj.default\Extensions\{E71B541F-5E72-5555-A47C-E47863195841} FF Extension: prefs - C:\Users\sony\AppData\Roaming\Mozilla\Firefox\Profiles\nvftkoyj.default\Extensions\{D394D188-BAC7-4e03-8FAF-389A4D7EC6F4}.xpi FF Extension: No Name - C:\Users\sony\AppData\Roaming\Mozilla\Firefox\Profiles\nvftkoyj.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Security\Mozilla Thunderbird FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Security\Mozilla Thunderbird Chrome: ======= CHR HomePage: https://www.google.pl/ CHR RestoreOnStartup: "hxxp://www.google.pl/" CHR DefaultSearchKeyword: google.pl CHR DefaultSearchProvider: Google CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultNewTabURL: {google:baseURL}_/chrome/newtab?{google:RLZ}{google:instantExtendedEnabledParameter}{google:ntpIsThemedParameter}ie={inputEncoding} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File CHR Plugin: (Skype Toolbars) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.7.0.8524_0\npSkypeChromePlugin.dll (Skype Technologies S.A.) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Google\Chrome\Application\plugins\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Google\Chrome\Application\plugins\nprpjplug.dll (RealNetworks, Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.290.11) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Google Talk Plugin) - C:\Users\sony\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\sony\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Extension: (New Tab) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd\9.4.4_0 CHR Extension: (YouTube) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1 CHR Extension: (Google Search) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1 CHR Extension: (Shopping Suggestion) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejbpjlaagejfakeobljhgplbgklgemll\1.0.0_0 CHR Extension: (AdBlock) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0 CHR Extension: (Similar Sites Pro) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\hidjnkeodmholilgafgdlgmgggbhnigl\3.5_0 CHR Extension: (Simplicity Stripes) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\leckphpgobkolbooijbhgaipnbaofojm\1.2_0 CHR Extension: (Skype Click to Call) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.7.0.8524_0 CHR Extension: (Download and Sa) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpgdenjkmdgijbjkcdkkejpkkpdigigi\7.1_0 CHR Extension: (Helper extension) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\nchpfiddbhbdnagofhkjlaiaejmkdcla\2.0_0 CHR Extension: (Google Wallet) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (https://www.google.pl/) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohlofpnkdicpncoooncmapjnhajmmmip\2013.7.15.35076_0 CHR Extension: (Gmail) - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM\...\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - C:\Users\sony\AppData\Local\newhb2.crx CHR HKLM-x32\...\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - C:\Users\sony\AppData\Local\newhb2.crx CHR HKLM-x32\...\Chrome\Extension: [hidjnkeodmholilgafgdlgmgggbhnigl] - C:\Users\sony\AppData\Roaming\SimilarSites\similarsites.crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx CHR HKLM-x32\...\Chrome\Extension: [mpgdenjkmdgijbjkcdkkejpkkpdigigi] - C:\ProgramData\Download and Sa\mpgdenjkmdgijbjkcdkkejpkkpdigigi.crx CHR HKLM-x32\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Users\sony\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 avgfws; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [1358944 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 FTRTSVC; C:\Program Files (x86)\Common Files\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [90112 2011-02-23] (France Telecom SA) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () S3 Remote Solver for Flow Simulation 2012; C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [113800 2011-12-09] (Mentor Graphics Corporation) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [252416 2010-05-25] (Sony Corporation) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2148664 2013-10-31] (AVG) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.) R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [36664 2013-10-31] (AVG) S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [851824 2010-06-17] (Sony Corporation) S3 VUAgent; C:\Program Files\Sony\VAIO Update 5\VUAgent.exe [1250160 2010-05-31] (Sony Corporation) S2 0282271352730771mcinstcleanup; C:\Users\Rick\AppData\Local\Temp\028227~1.EXE -cleanup -nolog [x] S2 ekrn; "C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe" [x] ==================== Drivers (Whitelisted) ==================== R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.) S3 hitmanpro36; C:\Windows\system32\drivers\hitmanpro36.sys [30496 2012-11-24] () S3 orange_zte_cdc_acm; C:\Windows\System32\DRIVERS\orange_zte_cdc_acm.sys [77312 2011-02-02] (ZTE) S3 orange_zte_cpo; C:\Windows\System32\DRIVERS\orange_zte_cpo.sys [14336 2011-02-02] (ZTE) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [11880 2012-07-04] (TuneUp Software) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 cpuz130; \??\C:\Users\sony\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x] U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2010-07-27] (Huawei Technologies Co., Ltd.) U4 WMCoreService; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-13 16:34 - 2013-12-13 16:35 - 00028749 _____ C:\Users\sony\Downloads\FRST.txt 2013-12-13 16:34 - 2013-12-13 16:34 - 00000000 ____D C:\FRST 2013-12-13 16:33 - 2013-12-13 16:33 - 01927462 _____ (Farbar) C:\Users\sony\Downloads\FRST64.exe 2013-12-13 16:31 - 2013-12-13 16:31 - 00079108 _____ C:\Users\sony\Desktop\Extras.Txt 2013-12-13 15:54 - 2013-12-13 15:54 - 00255958 _____ C:\Users\sony\Desktop\OTL.Txt 2013-12-13 15:54 - 2013-12-13 15:54 - 00079108 _____ C:\Users\sony\Downloads\Extras.Txt 2013-12-13 15:50 - 2013-12-13 15:50 - 00255958 _____ C:\Users\sony\Downloads\OTL.Txt 2013-12-13 15:29 - 2013-12-13 15:29 - 00602112 _____ (OldTimer Tools) C:\Users\sony\Downloads\OTL.com 2013-12-13 15:28 - 2013-12-13 15:28 - 00602112 _____ (OldTimer Tools) C:\Users\sony\Downloads\OTL.scr 2013-12-13 14:31 - 2013-12-13 14:31 - 00034281 _____ C:\ComboFix.txt 2013-12-13 13:36 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2013-12-13 13:36 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2013-12-13 13:36 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-12-13 13:36 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-12-13 13:36 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-12-13 13:36 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2013-12-13 13:36 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2013-12-13 13:36 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2013-12-13 13:31 - 2013-12-13 13:31 - 05154339 ____R (Swearware) C:\Users\sony\Downloads\ComboFix.exe 2013-12-13 13:26 - 2013-12-13 14:16 - 00000352 _____ C:\Windows\Tasks\AmiUpdXp.job 2013-12-13 13:26 - 2013-12-13 13:26 - 00003370 _____ C:\Windows\System32\Tasks\AmiUpdXp 2013-12-13 13:26 - 2013-12-13 13:26 - 00000000 ____D C:\Users\sony\AppData\Local\SwvUpdater 2013-12-13 13:26 - 2013-12-13 13:26 - 00000000 ____D C:\Program Files (x86)\Shopping Suggestion 2013-12-13 13:25 - 2013-12-13 13:25 - 00337448 _____ (Amônétízé Ltd) C:\Users\sony\Downloads\ComboFix__2594_il9695364.exe 2013-12-11 11:52 - 2013-12-11 11:52 - 03139584 _____ C:\Users\sony\Downloads\prezentacja torebka.ppt 2013-12-08 20:06 - 2013-12-08 20:06 - 01828158 _____ C:\Users\sony\Downloads\0r6hexg42s4w.bmp 2013-12-05 21:41 - 2013-12-05 21:41 - 00012482 _____ C:\Users\sony\Desktop\Mój komputer.lnk 2013-12-05 21:31 - 2013-12-05 21:31 - 00034816 _____ C:\Users\sony\Downloads\rachunek_zyskow_i_strat.xls 2013-12-05 18:59 - 2013-12-05 18:59 - 00021267 _____ C:\Users\sony\Downloads\Zeszyt1.xlsx 2013-11-30 19:25 - 2013-11-30 19:25 - 02474783 _____ ( ) C:\Users\sony\Downloads\doglick.exe 2013-11-29 17:32 - 2013-11-29 17:35 - 00004788 _____ C:\Users\sony\Downloads\kolo.MOD 2013-11-29 17:32 - 2013-11-29 17:32 - 00004782 _____ C:\Users\sony\Downloads\kolo.bak 2013-11-27 11:35 - 2013-11-27 11:35 - 00427008 _____ C:\Users\sony\Downloads\FMEA pps.ppt 2013-11-24 13:07 - 2013-11-24 13:07 - 00001311 _____ C:\Users\Public\Desktop\ProModel 7.5.LNK 2013-11-24 13:05 - 2013-11-24 13:05 - 00000000 ____D C:\ProgramData\ProModel 2013-11-24 13:05 - 2004-08-26 07:15 - 00667648 _____ (Graphics Server Technologies) C:\Windows\SysWOW64\gsprop32.dll 2013-11-24 13:05 - 2004-08-26 07:15 - 00659456 _____ (Graphics Server Technologies) C:\Windows\SysWOW64\Graphs32.ocx 2013-11-24 13:05 - 2004-08-26 07:15 - 00434176 _____ (Graphics Server Technologies) C:\Windows\SysWOW64\gsw32.exe 2013-11-24 13:05 - 2004-08-26 07:15 - 00253952 _____ (Graphics Server Technologies) C:\Windows\SysWOW64\gswag32.dll 2013-11-24 13:05 - 2004-08-26 07:15 - 00167936 _____ (Graphics Server Technologies) C:\Windows\SysWOW64\gswdll32.dll 2013-11-24 13:05 - 2004-08-04 06:00 - 01028096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.008 2013-11-24 13:05 - 2004-08-04 06:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.00A 2013-11-24 13:05 - 2004-08-04 06:00 - 00343040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.00D 2013-11-24 13:05 - 2004-08-04 06:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.00B 2013-11-24 13:05 - 2004-08-04 06:00 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.00C 2013-11-24 13:05 - 2004-08-04 06:00 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.00E 2013-11-24 13:05 - 2004-08-04 06:00 - 00003584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.007 2013-11-24 13:05 - 2004-02-23 01:00 - 01386496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.009 2013-11-24 13:05 - 2002-09-19 06:54 - 00310272 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\ltimg13n.dll 2013-11-24 13:05 - 2002-04-16 11:14 - 00416768 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LTKRN13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00341504 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFCMP13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00338944 _____ () C:\Windows\SysWOW64\LFFPX7.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00255488 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LTDIS13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00247808 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFJ2K13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00212992 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LVKRN13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00205312 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LTEFX13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00150016 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFPNG13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00136704 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LTFIL13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00128000 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFTIF13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00118784 _____ () C:\Windows\SysWOW64\LFKODAK.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00084480 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFFPX13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00073216 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFFAX13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00055296 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFPSD13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00047104 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFXPM13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00045056 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFXBM13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00037888 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFEPS13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00034816 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFGIF13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00031232 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFPNM13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00029696 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFBMP13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00028160 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFCLP13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00026112 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFPCX13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00023552 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFTGA13N.DLL 2013-11-24 13:05 - 2002-04-16 11:14 - 00019968 _____ (LEAD Technologies, Inc.) C:\Windows\SysWOW64\LFPCD13N.DLL 2013-11-24 13:05 - 2002-04-16 10:14 - 01683456 _____ C:\Windows\SysWOW64\Ltclr13n.dll 2013-11-24 13:04 - 2007-06-01 11:49 - 00322336 _____ (Blue Sky Software Corporation.) C:\Windows\SysWOW64\Roboex32.dll 2013-11-24 13:04 - 2003-10-30 15:48 - 00134144 _____ (Software FX, Inc.) C:\Windows\SysWOW64\SfxBar.dll 2013-11-24 13:04 - 2003-05-21 10:59 - 00607528 _____ (Software FX, Inc.) C:\Windows\SysWOW64\Cfx4032.ocx 2013-11-24 13:04 - 2003-02-27 12:33 - 00067584 _____ (Software FX, Inc.) C:\Windows\SysWOW64\Cfx4Data.dll 2013-11-24 13:04 - 2002-03-22 16:40 - 00489128 _____ (ComponentOne) C:\Windows\SysWOW64\Vsflex7.ocx 2013-11-24 13:03 - 2013-11-24 13:03 - 00000000 ____D C:\Users\sony\Documents\ProModel 2013-11-24 13:03 - 2013-11-24 13:03 - 00000000 ____D C:\Users\sony\AppData\Local\ProModel 2013-11-24 13:03 - 2007-06-11 11:22 - 00042272 _____ C:\Windows\SysWOW64\SK32W.DLL 2013-11-24 13:03 - 2000-12-07 12:45 - 00054784 _____ (Blue Sky Software Corporation.) C:\Windows\SysWOW64\INetWH32.dll 2013-11-24 13:02 - 2013-11-24 13:03 - 00000000 ____D C:\Program Files (x86)\ProModel Corporation 2013-11-24 13:02 - 2001-08-10 01:26 - 00278581 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.006 2013-11-24 13:02 - 2001-08-10 00:01 - 00252176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Msrd2x35.dll 2013-11-24 13:02 - 2001-08-09 22:54 - 00415504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrepl35.dll 2013-11-24 13:02 - 2001-08-09 22:53 - 01046288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet35.dll 2013-11-24 13:02 - 2001-08-09 22:50 - 00123664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSJINT35.DLL 2013-11-24 13:02 - 2001-08-09 22:50 - 00024848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSJTER35.DLL 2013-11-24 13:02 - 2001-03-13 14:53 - 00326656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.005 2013-11-24 13:02 - 2001-03-13 14:47 - 00598288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.000 2013-11-24 13:02 - 2001-03-13 14:47 - 00164112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.001 2013-11-24 13:02 - 2001-03-13 14:47 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.003 2013-11-24 13:02 - 2001-03-13 14:45 - 00147728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.002 2013-11-24 13:02 - 2000-08-20 21:00 - 01388544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\temp.004 2013-11-24 13:02 - 1999-09-09 22:06 - 00252688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSEXCL35.DLL 2013-11-24 13:02 - 1999-04-25 17:00 - 00368912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbar332.dll 2013-11-24 12:57 - 2013-11-24 12:59 - 143225443 _____ C:\Users\sony\Downloads\ProModel 7.5.rar 2013-11-24 12:31 - 2013-11-24 12:31 - 00000000 ____D C:\ProgramData\QuickSet 2013-11-15 22:28 - 2013-11-15 22:28 - 00003550 _____ C:\Users\sony\Desktop\przezroczysty.txt 2013-11-15 18:19 - 2013-11-15 18:19 - 00000000 ____D C:\Users\sony\AppData\Roaming\AVG2014 2013-11-15 18:16 - 2013-11-26 20:15 - 00000995 _____ C:\Users\Public\Desktop\AVG 2014.lnk 2013-11-15 18:13 - 2013-11-15 18:18 - 00000000 ____D C:\ProgramData\AVG2014 2013-11-15 17:45 - 2013-11-15 20:29 - 00000000 ____D C:\Users\sony\AppData\Local\Avg2014 2013-11-15 17:43 - 2013-10-31 17:24 - 00036664 _____ (AVG) C:\Windows\system32\uxtuneup.dll 2013-11-15 17:43 - 2013-10-31 17:24 - 00030008 _____ (AVG) C:\Windows\SysWOW64\uxtuneup.dll ==================== One Month Modified Files and Folders ======= 2013-12-13 16:35 - 2013-12-13 16:34 - 00028749 _____ C:\Users\sony\Downloads\FRST.txt 2013-12-13 16:34 - 2013-12-13 16:34 - 00000000 ____D C:\FRST 2013-12-13 16:33 - 2013-12-13 16:33 - 01927462 _____ (Farbar) C:\Users\sony\Downloads\FRST64.exe 2013-12-13 16:31 - 2013-12-13 16:31 - 00079108 _____ C:\Users\sony\Desktop\Extras.Txt 2013-12-13 16:21 - 2012-11-30 13:33 - 00135186 _____ C:\Windows\WindowsUpdate.log 2013-12-13 15:54 - 2013-12-13 15:54 - 00255958 _____ C:\Users\sony\Desktop\OTL.Txt 2013-12-13 15:54 - 2013-12-13 15:54 - 00079108 _____ C:\Users\sony\Downloads\Extras.Txt 2013-12-13 15:52 - 2010-07-28 13:38 - 00001062 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-13 15:50 - 2013-12-13 15:50 - 00255958 _____ C:\Users\sony\Downloads\OTL.Txt 2013-12-13 15:50 - 2011-12-15 20:58 - 00001054 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4233680346-135388955-4045965603-1000UA.job 2013-12-13 15:32 - 2011-10-31 10:13 - 00000000 ____D C:\Users\sony\AppData\Roaming\Skype 2013-12-13 15:29 - 2013-12-13 15:29 - 00602112 _____ (OldTimer Tools) C:\Users\sony\Downloads\OTL.com 2013-12-13 15:28 - 2013-12-13 15:28 - 00602112 _____ (OldTimer Tools) C:\Users\sony\Downloads\OTL.scr 2013-12-13 15:12 - 2012-11-20 12:36 - 00000000 ____D C:\ProgramData\MFAData 2013-12-13 14:52 - 2010-07-28 13:38 - 00001058 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-13 14:32 - 2012-06-06 16:49 - 00000000 ____D C:\Qoobox 2013-12-13 14:32 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2013-12-13 14:31 - 2013-12-13 14:31 - 00034281 _____ C:\ComboFix.txt 2013-12-13 14:26 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-13 14:26 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-13 14:25 - 2012-06-06 16:51 - 00000000 ____D C:\Windows\ERDNT 2013-12-13 14:17 - 2013-06-12 19:41 - 00000000 ___RD C:\Users\sony\Dropbox 2013-12-13 14:17 - 2013-06-12 19:33 - 00000000 ____D C:\Users\sony\AppData\Roaming\Dropbox 2013-12-13 14:16 - 2013-12-13 13:26 - 00000352 _____ C:\Windows\Tasks\AmiUpdXp.job 2013-12-13 14:16 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2013-12-13 14:15 - 2012-11-30 13:30 - 00017986 _____ C:\Windows\setupact.log 2013-12-13 14:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-13 14:14 - 2012-12-07 09:57 - 00013744 _____ C:\Windows\PFRO.log 2013-12-13 13:57 - 2013-09-26 21:52 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4233680346-135388955-4045965603-1000UA.job 2013-12-13 13:31 - 2013-12-13 13:31 - 05154339 ____R (Swearware) C:\Users\sony\Downloads\ComboFix.exe 2013-12-13 13:26 - 2013-12-13 13:26 - 00003370 _____ C:\Windows\System32\Tasks\AmiUpdXp 2013-12-13 13:26 - 2013-12-13 13:26 - 00000000 ____D C:\Users\sony\AppData\Local\SwvUpdater 2013-12-13 13:26 - 2013-12-13 13:26 - 00000000 ____D C:\Program Files (x86)\Shopping Suggestion 2013-12-13 13:25 - 2013-12-13 13:25 - 00337448 _____ (Amônétízé Ltd) C:\Users\sony\Downloads\ComboFix__2594_il9695364.exe 2013-12-13 12:51 - 2011-12-15 20:58 - 00001002 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4233680346-135388955-4045965603-1000Core.job 2013-12-12 22:57 - 2013-09-26 21:52 - 00000902 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4233680346-135388955-4045965603-1000Core.job 2013-12-12 22:19 - 2010-12-14 18:36 - 00003966 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{C13EBB6C-7784-4FAE-8C76-680C4DDF5916} 2013-12-12 21:42 - 2011-09-28 19:17 - 00000000 ____D C:\Users\sony\Desktop\szkoła 2013-12-12 18:11 - 2010-12-14 18:33 - 00000000 ____D C:\Users\sony\AppData\Roaming\Adobe 2013-12-12 18:11 - 2010-07-28 13:26 - 00000000 ____D C:\ProgramData\Adobe 2013-12-12 10:09 - 2012-10-22 16:47 - 00000000 ____D C:\Users\sony\Desktop\Różne 2013-12-11 12:13 - 2011-02-11 20:48 - 00000000 ____D C:\Users\sony\AppData\Roaming\SoftGrid Client 2013-12-11 11:52 - 2013-12-11 11:52 - 03139584 _____ C:\Users\sony\Downloads\prezentacja torebka.ppt 2013-12-10 18:11 - 2013-10-16 21:10 - 00000000 ____D C:\Users\sony\AppData\Local\TempSW Katalog dla kopii zapasowych 2013-12-08 20:06 - 2013-12-08 20:06 - 01828158 _____ C:\Users\sony\Downloads\0r6hexg42s4w.bmp 2013-12-07 10:45 - 2011-12-15 20:58 - 00004026 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4233680346-135388955-4045965603-1000UA 2013-12-07 10:45 - 2011-12-15 20:58 - 00003630 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4233680346-135388955-4045965603-1000Core 2013-12-06 19:54 - 2012-04-30 11:59 - 00000000 ____D C:\Users\sony\AppData\Roaming\Audacity 2013-12-05 21:41 - 2013-12-05 21:41 - 00012482 _____ C:\Users\sony\Desktop\Mój komputer.lnk 2013-12-05 21:31 - 2013-12-05 21:31 - 00034816 _____ C:\Users\sony\Downloads\rachunek_zyskow_i_strat.xls 2013-12-05 18:59 - 2013-12-05 18:59 - 00021267 _____ C:\Users\sony\Downloads\Zeszyt1.xlsx 2013-12-05 14:47 - 2010-07-28 13:38 - 00004058 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-05 14:47 - 2010-07-28 13:38 - 00003806 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-11-30 19:25 - 2013-11-30 19:25 - 02474783 _____ ( ) C:\Users\sony\Downloads\doglick.exe 2013-11-29 18:01 - 2013-10-16 19:42 - 00000000 ____D C:\Users\sony\AppData\Roaming\SolidWorks 2013-11-29 17:35 - 2013-11-29 17:32 - 00004788 _____ C:\Users\sony\Downloads\kolo.MOD 2013-11-29 17:32 - 2013-11-29 17:32 - 00004782 _____ C:\Users\sony\Downloads\kolo.bak 2013-11-27 11:35 - 2013-11-27 11:35 - 00427008 _____ C:\Users\sony\Downloads\FMEA pps.ppt 2013-11-26 20:15 - 2013-11-15 18:16 - 00000995 _____ C:\Users\Public\Desktop\AVG 2014.lnk 2013-11-26 20:12 - 2012-11-20 12:40 - 00000000 ____D C:\$AVG 2013-11-26 12:36 - 2013-09-12 13:42 - 00000111 _____ C:\Users\sony\AppData\Roaming\WB.CFG 2013-11-26 12:36 - 2013-09-12 13:42 - 00000006 _____ C:\Users\sony\AppData\Roaming\WBPU-TTL.DAT 2013-11-24 19:33 - 2010-07-21 01:14 - 00738660 _____ C:\Windows\system32\perfh015.dat 2013-11-24 19:33 - 2010-07-21 01:14 - 00155058 _____ C:\Windows\system32\perfc015.dat 2013-11-24 19:33 - 2009-07-14 06:13 - 01664926 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-24 13:07 - 2013-11-24 13:07 - 00001311 _____ C:\Users\Public\Desktop\ProModel 7.5.LNK 2013-11-24 13:05 - 2013-11-24 13:05 - 00000000 ____D C:\ProgramData\ProModel 2013-11-24 13:03 - 2013-11-24 13:03 - 00000000 ____D C:\Users\sony\Documents\ProModel 2013-11-24 13:03 - 2013-11-24 13:03 - 00000000 ____D C:\Users\sony\AppData\Local\ProModel 2013-11-24 13:03 - 2013-11-24 13:02 - 00000000 ____D C:\Program Files (x86)\ProModel Corporation 2013-11-24 12:59 - 2013-11-24 12:57 - 143225443 _____ C:\Users\sony\Downloads\ProModel 7.5.rar 2013-11-24 12:31 - 2013-11-24 12:31 - 00000000 ____D C:\ProgramData\QuickSet 2013-11-24 12:31 - 2012-12-06 16:53 - 00000000 ____D C:\ProgramData\InstallMate 2013-11-15 22:28 - 2013-11-15 22:28 - 00003550 _____ C:\Users\sony\Desktop\przezroczysty.txt 2013-11-15 20:29 - 2013-11-15 17:45 - 00000000 ____D C:\Users\sony\AppData\Local\Avg2014 2013-11-15 18:19 - 2013-11-15 18:19 - 00000000 ____D C:\Users\sony\AppData\Roaming\AVG2014 2013-11-15 18:18 - 2013-11-15 18:13 - 00000000 ____D C:\ProgramData\AVG2014 2013-11-15 18:18 - 2012-11-20 12:40 - 00000000 ____D C:\ProgramData\AVG2013 2013-11-15 18:18 - 2012-11-20 12:39 - 00000000 ____D C:\Program Files (x86)\AVG 2013-11-14 22:07 - 2009-07-14 05:45 - 00551160 _____ C:\Windows\system32\FNTCACHE.DAT ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2012-04-29 11:21 ==================== End Of Log ============================