Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:11-05-2014 01 Ran by biuro3 (administrator) on BIURO3-KOMPUTER on 13-05-2014 17:46:30 Running from C:\Users\biuro3\Downloads Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Polish Internet Explorer Version 9 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe (AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe (Omnitec) C:\Program Files\Omnitec\GestHotel\GestHotel_TCPIP.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (GlavSoft LLC.) C:\Program Files\TightVNC\tvnserver.exe (Hewlett-Packard Company) C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Omnitec) C:\Program Files\Omnitec\GestHotel\GestHotel_TCPIP.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (CobianSoft, Luis Cobian) C:\Program Files\Cobian Backup 10\cbVSCService.exe (Luis Cobian, CobianSoft) C:\Program Files\Cobian Backup 10\cbService.exe (HP) C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe (Fujitsu Technology Solutions) C:\Program Files\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe (GlavSoft LLC.) C:\Program Files\TightVNC\tvnserver.exe (Omnitec) C:\Program Files\Omnitec\GestHotel\hotel.exe () C:\Users\Public\Program Files\LabF.com\WinaXe\xserver.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [] => [X] HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [3873704 2014-05-08] (AVAST Software) HKLM\...\Run: [GestHotel_TCPIP] => C:\Program Files\Omnitec\GestHotel\GestHotel_TCPIP.exe [307200 2010-09-13] (Omnitec) HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [tvncontrol] => C:\Program Files\TightVNC\tvnserver.exe [1690096 2013-07-19] (GlavSoft LLC.) HKLM\...\Run: [ToolboxFX] => C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe [58936 2010-10-25] (Hewlett-Packard Company) HKLM\...\Run: [HP LaserJet Professional M1530 MFP Series Fax] => C:\Program Files\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe [2459192 2010-08-24] (Hewlett-Packard Company) HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) HKU\S-1-5-21-1186817230-2738156246-924290788-1000\...\MountPoints2: {1ee309d3-66ff-11e0-990b-0019998b69d5} - D:\LaunchU3.exe -a HKU\S-1-5-21-1186817230-2738156246-924290788-1000\...\MountPoints2: {6bd7aa53-0453-11e2-a74c-0019998b69d5} - F:\OpenFiles.exe HKU\S-1-5-21-1186817230-2738156246-924290788-1000\...\MountPoints2: {743d7ac8-0ab4-11e0-b4b0-0019998b69d5} - D:\LaunchU3.exe -a HKU\S-1-5-21-1186817230-2738156246-924290788-1000\...\MountPoints2: {98a7d837-3f51-11e0-a349-0019998b69d5} - D:\AutoRun.exe HKU\S-1-5-21-1186817230-2738156246-924290788-1000\...\MountPoints2: {e61dc587-3f9e-11e2-a1d5-0019998b69d5} - F:\WM0453F.exe HKU\S-1-5-21-1186817230-2738156246-924290788-1000\...\MountPoints2: {f3e88701-9a60-11e1-ae1f-0019998b69d5} - D:\LaunchU3.exe -a Startup: C:\Users\biuro3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GestHotel_TCPIP — skrót.lnk ShortcutTarget: GestHotel_TCPIP — skrót.lnk -> C:\Program Files\Omnitec\GestHotel\GestHotel_TCPIP.exe (Omnitec) Startup: C:\Users\biuro3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk ShortcutTarget: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup\LaunchCenter.lnk ShortcutTarget: LaunchCenter.lnk -> C:\Program Files\Fujitsu\LaunchCenter\LaunchCenter.exe (Fujitsu Technology Solutions) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup\LaunchCenter.lnk ShortcutTarget: LaunchCenter.lnk -> C:\Program Files\Fujitsu\LaunchCenter\LaunchCenter.exe (Fujitsu Technology Solutions) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.google.com/ig/redirectdomain?brand=FTSF&bmod=FTSF SearchScopes: HKLM - DefaultScope value is missing. BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: {03EC4525-6918-4674-9EFF-738EEB3E189F} http://192.168.10.32:2023/plusviewer.cab DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://vssl-pro.accor.com/dana-cached/sc/JuniperSetupClient.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Tcpip\..\Interfaces\{4806989B-BF4F-4D59-8E4B-D32661004A64}: [NameServer]8.8.8.8,192.168.10.1 FireFox: ======== FF ProfilePath: C:\Users\biuro3\AppData\Roaming\Mozilla\Firefox\Profiles\ys1h80zt.default FF user.js: detected! => C:\Users\biuro3\AppData\Roaming\Mozilla\Firefox\Profiles\ys1h80zt.default\user.js FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Extension: DOwnSavve - C:\Users\biuro3\AppData\Roaming\Mozilla\Firefox\Profiles\ys1h80zt.default\Extensions\arr9y@ujwltbkmzdmrw.net [2014-02-28] FF Extension: WattcHItNioeAds - C:\Users\biuro3\AppData\Roaming\Mozilla\Firefox\Profiles\ys1h80zt.default\Extensions\cleeov@zmvj-eeuo.edu [2014-01-31] FF Extension: G Data WebFilter - C:\Program Files\Mozilla Firefox\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE} [2014-05-11] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012-06-06] Chrome: ======= CHR Extension: (WattcHItNioeAds) - C:\Users\biuro3\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiinpoglcbdeaanhnikkilefiikjcoff [2014-01-31] CHR Extension: (Google Wallet) - C:\Users\biuro3\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2014-05-08] (AVAST Software) R2 cbVSCService; C:\Program Files\Cobian Backup 10\cbVSCService.exe [67584 2010-09-23] (CobianSoft, Luis Cobian) R2 CobianBackup10; C:\Program Files\Cobian Backup 10\cbService.exe [1125376 2010-09-23] (Luis Cobian, CobianSoft) R2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [145920 2010-10-25] (HP) R2 TestHandler; C:\Program Files\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe [341264 2009-02-19] (Fujitsu Technology Solutions) R2 tvnserver; C:\Program Files\TightVNC\tvnserver.exe [1690096 2013-07-19] (GlavSoft LLC.) S2 UTSCSI; C:\Windows\system32\UTSCSI.EXE [0 2011-03-10] () ==================== Drivers (Whitelisted) ==================== R3 ACR120; C:\Windows\System32\Drivers\acr120.sys [29440 2010-01-28] (Advanced Card Systems Ltd.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-05-08] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-05-08] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-05-08] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-05-08] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [776976 2014-05-08] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [411552 2014-05-08] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [67776 2014-05-08] (AVAST Software) R1 aswTdi; C:\Windows\system32\Drivers\aswTdi.sys [56080 2013-12-19] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180632 2014-05-08] () S3 BtUsb; C:\Windows\System32\Drivers\btUsb.sys [26902 2006-05-06] (Be-Tech) S3 HPFXBULK; C:\Windows\System32\drivers\hpfxbulk.sys [17432 2007-07-16] (Hewlett Packard) S3 HPFXFAX; C:\Windows\System32\drivers\hpfxfax.sys [20504 2007-07-16] (Hewlett Packard) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [320120 2014-01-12] (Duplex Secure Ltd.) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [184192 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr)) R1 {9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw; C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw.sys [52920 2014-05-07] (StdLib) U3 awxdipog; \??\C:\Users\biuro3\AppData\Local\Temp\awxdipog.sys [X] ========================== Drivers MD5 ======================= C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit C:\Windows\System32\Drivers\acr120.sys E59D93E689B9CCBC8CAFA6440BC6DE96 C:\Windows\system32\DRIVERS\adp94xx.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\adpahci.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\adpu320.sys ==> MD5 is legit C:\Windows\system32\drivers\afd.sys F81BB7E487EDCEAB630A7EE66CF23913 C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\djsvs.sys ==> MD5 is legit C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdagp.sys ==> MD5 is legit C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdk8.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdppm.sys ==> MD5 is legit C:\Windows\system32\drivers\amdsata.sys D320BF87125326F996D4904FE24300FC C:\Windows\system32\DRIVERS\amdsbs.sys ==> MD5 is legit C:\Windows\System32\drivers\amdxata.sys 46387FB17B086D16DEA267D5BE23A2F2 C:\Windows\system32\drivers\appid.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\arc.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\arcsas.sys ==> MD5 is legit C:\Windows\system32\drivers\aswHwid.sys 4D6C6E0505A8E5A0656DCB223497D37C C:\Windows\system32\drivers\aswMonFlt.sys 1A2CC93BBD77C2D95A7567938D7D7239 C:\Windows\system32\drivers\aswRdr2.sys 9A646294396BBCDF29CF1CB4B1B0D68B C:\Windows\system32\Drivers\aswRvrt.sys 24B3BDA01DB3A704E33A5266C7B52DAF C:\Windows\system32\drivers\aswSnx.sys A148A36F871BFDBF80654D28D6B59FAE C:\Windows\system32\drivers\aswSP.sys EBD3B15E2E01EE94BA5262FAFC691A8E C:\Windows\system32\drivers\aswStm.sys E458D8D20AF6FE3F4784C18E8A1F02C3 C:\Windows\system32\Drivers\aswTdi.sys 71B22453B4CE84A4A4B28833ECA7EB18 C:\Windows\system32\Drivers\aswVmm.sys B2D7EE52633CA8831DDAFCA81C2D46C3 C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit C:\Windows\System32\drivers\atapi.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\bxvbdx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57nd60x.sys ==> MD5 is legit C:\Windows\system32\Drivers\Beep.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\BrFiltLo.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\BrFiltUp.sys ==> MD5 is legit C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\bthmodem.sys ==> MD5 is legit C:\Windows\System32\Drivers\btUsb.sys 2EDF00BDE176FA8AFCC63B9797AC8E83 C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\circlass.sys ==> MD5 is legit C:\Windows\System32\CLFS.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\CmBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit C:\Windows\System32\Drivers\cng.sys 85449EEBE8F8EBD6481EFBF0F352B4EB C:\Windows\system32\DRIVERS\compbatt.sys ==> MD5 is legit C:\Windows\system32\drivers\CompositeBus.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\crcdisk.sys ==> MD5 is legit C:\Windows\System32\drivers\csc.sys ==> MD5 is legit C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit C:\Windows\system32\Drivers\DgiVecp.sys 770471DE2550820FEEB7E5D24BF2E273 C:\Windows\System32\DRIVERS\ssudbus.sys EDF7F8387C2072205ABCF105F14B13B4 C:\Windows\System32\drivers\discache.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\disk.sys ==> MD5 is legit C:\Windows\system32\drivers\drmkaud.sys ==> MD5 is legit C:\Windows\System32\drivers\dxgkrnl.sys 71BC35067CABC02C9453AEAA42B2E43E C:\Windows\system32\DRIVERS\evbdx.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\elxstor.sys ==> MD5 is legit C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit C:\Windows\system32\Drivers\exfat.sys ==> MD5 is legit C:\Windows\system32\Drivers\fastfat.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\fdc.sys ==> MD5 is legit C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\flpydisk.sys ==> MD5 is legitB C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit C:\Windows\system32\Drivers\Fs_Rec.sys 7DAE5EBCC80E45D3253F4923DC424D05 C:\Windows\System32\DRIVERS\fvevol.sys E306A24D9694C724FA2491278BF50FDB C:\Windows\system32\DRIVERS\gagp30kx.sys ==> MD5 is legit C:\Windows\System32\drivers\GEARAspiWDM.sys 5DC17164F66380CBFEFD895C18467773 C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit C:\Windows\system32\drivers\HdAudio.sys A5EF29D5315111C80A5C1ABAD14C8972 C:\Windows\system32\drivers\HDAudBus.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\HidBatt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\hidbth.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\hidir.sys ==> MD5 is legit C:\Windows\system32\drivers\hidusb.sys ==> MD5 is legit C:\Windows\System32\drivers\hpfxbulk.sys 299683D4C8AAA3F6F5D5D226A1782A6E C:\Windows\System32\drivers\hpfxfax.sys F728DB73A87231E27B6BA34D71CE2EDB C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit C:\Windows\system32\drivers\iaStorV.sys 5CD5F9A5444E6CDCB0AC89BD62D8B76E C:\Windows\System32\DRIVERS\igdkmd32.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\iirsp.sys ==> MD5 is legit C:\Windows\System32\drivers\RTKVHDA.sys 2A4EB3167A071A67D3F56E94663544EC C:\Windows\System32\drivers\IntcHdmi.sys 5CF0990FC1F6676F7B00366AB224DA92 C:\Windows\System32\drivers\intelide.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit C:\Windows\system32\drivers\msiscsi.sys EB34CE31FABD4DC4343FD2AD16D2CAF9 C:\Windows\system32\drivers\kbdclass.sys ==> MD5 is legit C:\Windows\system32\drivers\kbdhid.sys ==> MD5 is legit C:\Windows\System32\Drivers\ksecdd.sys F286830298323272260332D6ABC905C1 C:\Windows\System32\Drivers\ksecpkg.sys D7C760D57B1656DD748B9E4AB6CB5A51 C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_fc.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_sas.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_sas2.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_scsi.sys ==> MD5 is legit C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\megasas.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\MegaSR.sys ==> MD5 is legit C:\Windows\System32\drivers\modem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\mrxdav.sys 21F4B24ACFC79A483515BD986DD9043F C:\Windows\System32\DRIVERS\mrxsmb.sys 5D16C921E3671636C0EBA3BBAAC5FD25 C:\Windows\System32\DRIVERS\mrxsmb10.sys 6D17A4791ACA19328C685D256349FEFC C:\Windows\System32\DRIVERS\mrxsmb20.sys B81F204D146000BE76651A50670A5E9E C:\Windows\system32\drivers\msahci.sys ==> MD5 is legit C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit C:\Windows\system32\Drivers\Msfs.sys ==> MD5 is legit C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit C:\Windows\system32\Drivers\MsRPC.sys ==> MD5 is legit C:\Windows\system32\drivers\mssmbios.sys ==> MD5 is legit C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\MTConfig.sys ==> MD5 is legit C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit C:\Windows\System32\drivers\ndis.sys 8C9C922D71F1CD4DEF73F186416B7896 C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit C:\Windows\system32\Drivers\NDProxy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\nfrd960.sys ==> MD5 is legit C:\Windows\system32\Drivers\Npfs.sys ==> MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit C:\Windows\system32\Drivers\Ntfs.sys C8DFF8D07755A66C7A4A738930F0FEAC C:\Windows\system32\Drivers\Null.sys ==> MD5 is legit C:\Windows\system32\drivers\nvraid.sys B3E25EE28883877076E0E1FF877D02E0 C:\Windows\system32\drivers\nvstor.sys 4380E59A170D88C4F1022EFF6719A8A4 C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\parport.sys ==> MD5 is legit C:\Windows\System32\drivers\partmgr.sys 3F34A1B4C5F6475F320C275E63AFCE9B C:\Windows\System32\DRIVERS\parvdm.sys ==> MD5 is legit C:\Windows\System32\drivers\pci.sys ==> MD5 is legit C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\pcmcia.sys ==> MD5 is legit C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\processr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\ql2300.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\ql40xx.sys ==> MD5 is legit C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdpbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpdr.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit C:\Windows\system32\Drivers\RDPWD.sys F031683E6D1FEA157ABB2FF260B51E61 C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit C:\Windows\System32\Drivers\RimUsb.sys 0F6756EF8BDA6DFA7BE50465C83132BB C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Rt86win7.sys 5283B9A27FF230F2FF70D92451FF409A C:\Windows\system32\drivers\vms3cap.sys ==> MD5 is legit C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit C:\Windows\system32\Drivers\secdrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\serenum.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\serial.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sermouse.sys ==> MD5 is legit C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sfloppy.sys ==> MD5 is legit C:\Windows\system32\drivers\sisagp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\SiSRaid2.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sisraid4.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit C:\Windows\system32\Drivers\spldr.sys ==> MD5 is legit C:\Windows\System32\Drivers\sptd.sys CBEAEA2729985BFB260641AB424E0166 C:\Windows\System32\DRIVERS\srv.sys E4C2764065D66EA1D2D3EBC28FE99C46 C:\Windows\System32\DRIVERS\srv2.sys 03F0545BD8D4C77FA0AE1CEEDFCC71AB C:\Windows\System32\DRIVERS\srvnet.sys BE6BD660CAA6F291AE06A718A4FA8ABC C:\Windows\system32\Drivers\SSPORT.sys EF3458337D7341A05169CEFC73709264 C:\Windows\System32\DRIVERS\ssudmdm.sys 585FDB94DB04AC1C56298D1FD1F1389E C:\Windows\System32\DRIVERS\ssudserd.sys E0B86430E0B26C10B355B9E590FD25E0 C:\Windows\System32\DRIVERS\ss_bus.sys 54946449A0EB74915A4BB34F7EE51A5A C:\Windows\System32\DRIVERS\ss_mdfl.sys 4450BC0B2E9D7D9B90E3C3DE4EA00A78 C:\Windows\System32\DRIVERS\ss_mdm.sys 30B8D0DD01EAD1243F329CAF7D7D1517 C:\Windows\system32\DRIVERS\stexstor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\serscan.sys EDB05BD63148796F23EA78506404A538 C:\Windows\System32\drivers\vmstorfl.sys ==> MD5 is legit C:\Windows\system32\drivers\storvsc.sys ==> MD5 is legit C:\Windows\system32\drivers\swenum.sys ==> MD5 is legit C:\Windows\System32\drivers\tcpip.sys CA59F7C570AF70BC174F477CFE2D9EE3 C:\Windows\System32\DRIVERS\tcpip.sys CA59F7C570AF70BC174F477CFE2D9EE3 C:\Windows\System32\drivers\tcpipreg.sys 3EEBD3BD93DA46A26E89893C7AB2FF3B C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit C:\Windows\System32\drivers\tdtcp.sys 2C2C5AFE7EE4F620D69C23C0617651A8 C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit C:\Windows\system32\drivers\termdd.sys ==> MD5 is legit C:\Windows\System32\drivers\tpm.sys 5AD05191DC8B444A7BA4D79B76C42A30 C:\Windows\System32\DRIVERS\tssecsrv.sys B37B08F2E5EEB1A37E448E09BACE1101 C:\Windows\System32\drivers\tsusbflt.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\uagp35.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit C:\Windows\system32\drivers\umbus.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\umpass.sys ==> MD5 is legit C:\Windows\system32\drivers\usbccgp.sys 0803FBA9FE829D61AE26EC0BCC910C46 C:\Windows\system32\drivers\usbcir.sys 2352AB5F9F8F097BF9D41D5A4718A041 C:\Windows\System32\DRIVERS\usbehci.sys D40855F89B69305140BBD7E9A3BA2DA6 C:\Windows\System32\DRIVERS\usbhub.sys EDF2DF71C4F1E13A6AC75F5224DE655A C:\Windows\system32\drivers\usbohci.sys 9828C8D14CC2676421778F0DE638CF97 C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbscan.sys FC6B21DB4B5B398AB93DBE59CBF11036 C:\Windows\system32\drivers\usbser.sys 007C0C8D5B01D82ACEB70431D15083F6 C:\Windows\System32\DRIVERS\USBSTOR.SYS F991AB9CC6B908DB552166768176896A C:\Windows\System32\DRIVERS\usbuhci.sys 800AABFD625EEFF899F7E5496BDE37AB C:\Windows\System32\DRIVERS\usb8023x.sys AF77716205C97E902E6C5B78DECE2CCA C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit C:\Windows\System32\drivers\vga.sys ==> MD5 is legit C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit C:\Windows\system32\drivers\viaagp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\viac7.sys ==> MD5 is legit C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit C:\Windows\System32\drivers\vmbus.sys ==> MD5 is legit C:\Windows\system32\drivers\VMBusHID.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\vsmraid.sys ==> MD5 is legit C:\Windows\System32\drivers\vwifibus.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\wacompen.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\wd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wdcsam.sys D6EFAF429FD30C5DF613D220E344CCE7 C:\Windows\System32\drivers\Wdf01000.sys 25944D2CC49E0A6C581D02A74B7D6645 C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\WinUsb.sys A67E5F9A400F3BD1BE3D80613B45F708 C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\WSDPrint.sys 553F6CCD7C58EB98D4A8FBDAF283D7A9 C:\Windows\System32\drivers\WudfPf.sys 06E6F32C8D0A3F66D956F57B43A2E070 C:\Windows\System32\DRIVERS\WUDFRd.sys 867C301E8B790040AE9CF6486E8041DF C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw.sys 5A981D420033A8CD449767FD935B9120 ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-13 17:46 - 2014-05-13 17:48 - 00029633 _____ () C:\Users\biuro3\Downloads\FRST.txt 2014-05-13 17:46 - 2014-05-13 17:46 - 00380416 _____ () C:\Users\biuro3\Downloads\nbrkwcrs.exe 2014-05-13 17:45 - 2014-05-13 17:46 - 00000000 ____D () C:\FRST 2014-05-13 17:44 - 2014-05-13 17:44 - 01056256 _____ (Farbar) C:\Users\biuro3\Downloads\FRST.exe 2014-05-13 17:43 - 2014-05-13 17:43 - 00000000 ____D () C:\Users\biuro3\Desktop\raporty 2014-05-13 17:40 - 2014-05-13 17:40 - 00060786 _____ () C:\Users\biuro3\Downloads\Extras.Txt 2014-05-13 17:38 - 2014-05-13 17:38 - 00243714 _____ () C:\Users\biuro3\Downloads\OTL.Txt 2014-05-13 17:25 - 2014-05-13 17:25 - 00602112 _____ (OldTimer Tools) C:\Users\biuro3\Downloads\OTL.exe 2014-05-13 09:00 - 2014-05-13 09:00 - 00000165 ____H () C:\Users\biuro3\Desktop\~$baza klubów fitnes.xlsx 2014-05-13 05:52 - 2014-05-13 05:52 - 00036864 _____ () C:\Users\biuro3\Desktop\report.operation.20140513-20140513 P. Adam Lesiński.xls 2014-05-11 23:47 - 2014-05-11 23:47 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-11 16:30 - 2014-05-11 16:30 - 00000000 ____D () C:\Users\biuro3\AppData\Roaming\Juniper Networks 2014-05-10 00:02 - 2014-05-10 06:37 - 00000000 ____D () C:\Users\biuro3\Desktop\GASTRO 2014-05-09 23:14 - 2014-05-13 01:31 - 00000896 _____ () C:\Windows\setupact.log 2014-05-09 23:14 - 2014-05-09 23:14 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-09 22:47 - 2014-05-09 22:47 - 06083031 _____ () C:\Users\biuro3\Downloads\TableNumbers_Ruffled (1).zip 2014-05-09 22:46 - 2014-05-09 22:47 - 06083031 _____ () C:\Users\biuro3\Downloads\TableNumbers_Ruffled.zip 2014-05-09 18:55 - 2014-05-12 14:11 - 00037449 _____ () C:\Users\biuro3\Desktop\baza klubów fitnes.xlsx 2014-05-09 12:09 - 2014-05-12 15:42 - 00000000 __SHD () C:\Users\biuro3\AppData\Roaming\.# 2014-05-09 12:09 - 2014-05-09 12:09 - 00000000 ____D () C:\Program Files\Common Files\SWF Studio 2014-05-09 10:04 - 2014-05-09 10:04 - 00002050 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk 2014-05-09 10:04 - 2014-05-09 10:04 - 00002038 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk 2014-05-09 10:04 - 2014-05-09 10:04 - 00000000 ____D () C:\Users\biuro3\AppData\Roaming\Thunderbird 2014-05-09 10:04 - 2014-05-09 10:04 - 00000000 ____D () C:\Users\biuro3\AppData\Local\Thunderbird 2014-05-09 10:04 - 2014-05-09 10:04 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird 2014-05-09 10:01 - 2014-04-24 06:06 - 00000426 _____ () C:\AVScanner.ini 2014-05-09 09:52 - 2014-05-09 09:53 - 01315565 ____N () C:\Users\biuro3\Downloads\AdwCleaner.exe 2014-05-09 09:43 - 2014-05-09 09:52 - 22856956 ____N (Mozilla) C:\Users\biuro3\Downloads\Thunderbird Setup 24.5.0 (1).exe 2014-05-08 23:15 - 2014-05-08 23:15 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-05-08 23:15 - 2014-05-08 23:15 - 00024184 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-05-08 22:49 - 2014-05-07 16:06 - 00052920 _____ (StdLib) C:\Windows\system32\Drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw.sys 2014-05-08 21:56 - 2014-05-08 21:56 - 26900321 ____N () C:\Users\biuro3\Downloads\konferencyjne (1).rar 2014-05-08 21:22 - 2014-05-08 21:22 - 00000000 ____D () C:\Users\biuro3\Documents\Ashampoo Burning Studio 2014 2014-05-08 21:17 - 2014-05-08 21:17 - 00001267 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk 2014-05-08 21:15 - 2014-05-08 21:15 - 91956656 ____N (Ashampoo GmbH & Co. KG ) C:\Users\biuro3\Downloads\ashampoo_burning_studio_2014_12.0.5_15396.exe 2014-05-08 21:13 - 2014-05-08 21:13 - 00702752 ____N () C:\Users\biuro3\Downloads\Ashampoo-Burning-Studio(12487).exe 2014-05-08 18:28 - 2014-05-08 18:28 - 26900321 ____N () C:\Users\biuro3\Downloads\konferencyjne.rar 2014-05-08 11:19 - 2014-05-08 11:19 - 00050688 ____N () C:\Users\biuro3\Desktop\karta pracy.xls 2014-05-07 18:37 - 2014-05-13 08:24 - 00204800 ____N () C:\Users\biuro3\Desktop\Recepcja 2014 (3).xls 2014-05-07 16:43 - 2014-05-07 16:56 - 00000000 ____D () C:\Users\biuro3\AppData\Roaming\HpUpdate 2014-05-07 16:43 - 2014-05-07 16:43 - 00000000 ____D () C:\Users\Public\Documents\HP_LaserJet_Fax_0_6 2014-05-07 16:41 - 2014-05-07 16:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SnadBoy's Revelation v2 2014-05-07 16:41 - 2014-05-07 16:41 - 00000000 ____D () C:\Program Files\SnadBoy's Revelation v2 2014-05-07 16:40 - 2014-05-07 16:40 - 00217666 ____N () C:\Users\biuro3\Downloads\RevelationV2.zip 2014-05-07 16:37 - 2014-05-07 16:37 - 00001160 _____ () C:\Users\Public\Desktop\HP LJ M1530 Scan.lnk 2014-05-07 16:37 - 2014-05-07 16:37 - 00000926 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rejestracja programu I.R.I.S. OCR.lnk 2014-05-07 16:37 - 2014-05-07 16:37 - 00000000 ____D () C:\Users\biuro3\AppData\Roaming\Hewlett-Packard Company 2014-05-07 16:36 - 2014-05-07 16:36 - 00001336 _____ () C:\Users\Public\Desktop\HP LaserJet Professional M1530 MFP Series - Centrum pomocy i szkolenia.lnk 2014-05-07 16:34 - 2014-05-07 16:34 - 00000000 ____D () C:\Users\biuro3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP 2014-05-07 16:28 - 2010-12-14 10:27 - 00238080 _____ (Hewlett-Packard) C:\Windows\system32\hpbcoins32.dll 2014-05-07 16:28 - 2010-12-14 10:26 - 00755256 _____ (Hewlett-Packard) C:\Windows\system32\hpxp1530.dll 2014-05-07 16:28 - 2010-12-14 10:26 - 00751160 _____ (Hewlett-Packard) C:\Windows\system32\hpptsp06.dll 2014-05-07 16:28 - 2010-12-14 10:26 - 00187960 _____ (Hewlett Packard) C:\Windows\system32\hppscancoins32.dll 2014-05-07 16:28 - 2010-12-14 10:26 - 00003211 _____ () C:\Windows\system32\hppls1530.spf 2014-05-07 16:28 - 2010-09-23 14:05 - 00176128 _____ (Hewlett-Packard Corporation) C:\Windows\system32\hpcpn101.dll 2014-05-07 14:50 - 2014-05-08 21:20 - 00000000 ____D () C:\Users\biuro3\Desktop\DO teczek 2014-05-07 09:16 - 2014-05-07 11:10 - 01170944 ____N () C:\Users\biuro3\Desktop\raport sprzedaży2014 krystian.xls 2014-05-03 19:25 - 2014-05-13 14:37 - 00499200 ____N () C:\Users\biuro3\Desktop\kalendarz cen 01 2014-31 12 2015 akt 3 05 2014.xls 2014-05-03 03:01 - 2014-04-29 12:28 - 12347392 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-03 03:01 - 2014-04-29 12:07 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-30 03:01 - 2014-04-30 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-30 02:54 - 2014-04-14 04:11 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-30 02:54 - 2014-04-14 04:07 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-29 23:09 - 2014-05-01 03:23 - 00000000 ____D () C:\Users\biuro3\Desktop\Faktury pro-formy 2014-04-24 21:44 - 2014-04-24 21:44 - 00009002 ____N () C:\Users\biuro3\Desktop\cc_20140424_214356.reg 2014-04-20 05:15 - 2014-04-20 05:15 - 00000847 ____N () C:\Users\biuro3\Desktop\Rehabilitacja — skrót.lnk 2014-04-19 12:12 - 2014-04-19 12:12 - 00519003 ____N () C:\Users\biuro3\Desktop\SIWZ_wraz_zaYYcznikami_2.zip 2014-04-18 09:52 - 2014-04-18 09:52 - 00019655 ____N () C:\Users\biuro3\Desktop\bryczki 19.04.2014.xlsx 2014-04-16 19:10 - 2014-04-16 19:10 - 01110476 ____N () C:\Users\biuro3\Downloads\7z920.exe 2014-04-16 19:10 - 2014-04-16 19:10 - 01110476 ____N () C:\Users\biuro3\Downloads\7z920 (1).exe 2014-04-16 19:10 - 2014-04-16 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2014-04-16 19:10 - 2014-04-16 19:10 - 00000000 ____D () C:\Program Files\7-Zip 2014-04-16 17:47 - 2014-04-16 17:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyFinder 2014-04-16 17:47 - 2014-04-16 17:47 - 00000000 ____D () C:\Program Files\Magical Jelly Bean 2014-04-16 17:46 - 2014-04-16 17:46 - 01199848 ____N (Magical Jelly Bean ) C:\Users\biuro3\Downloads\KeyFinderInstaller.exe 2014-04-16 17:31 - 2014-04-16 17:31 - 00001392 ____N () C:\Users\biuro3\Desktop\cc_20140416_173112.reg 2014-04-14 23:59 - 2014-04-14 23:59 - 00001422 ____N () C:\Users\biuro3\Desktop\PRACOWNICY!!!! ma być w jednym folderze — skrót.lnk 2014-04-14 10:00 - 2014-04-14 10:00 - 00000000 ____D () C:\ProgramData\TightVNC 2014-04-14 10:00 - 2014-04-14 10:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TightVNC ==================== One Month Modified Files and Folders ======= 2014-05-13 17:48 - 2014-05-13 17:46 - 00029633 _____ () C:\Users\biuro3\Downloads\FRST.txt 2014-05-13 17:46 - 2014-05-13 17:46 - 00380416 _____ () C:\Users\biuro3\Downloads\nbrkwcrs.exe 2014-05-13 17:46 - 2014-05-13 17:45 - 00000000 ____D () C:\FRST 2014-05-13 17:44 - 2014-05-13 17:44 - 01056256 _____ (Farbar) C:\Users\biuro3\Downloads\FRST.exe 2014-05-13 17:43 - 2014-05-13 17:43 - 00000000 ____D () C:\Users\biuro3\Desktop\raporty 2014-05-13 17:40 - 2014-05-13 17:40 - 00060786 _____ () C:\Users\biuro3\Downloads\Extras.Txt 2014-05-13 17:38 - 2014-05-13 17:38 - 00243714 _____ () C:\Users\biuro3\Downloads\OTL.Txt 2014-05-13 17:34 - 2013-07-16 17:52 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-13 17:28 - 2010-09-17 12:56 - 00001036 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-13 17:25 - 2014-05-13 17:25 - 00602112 _____ (OldTimer Tools) C:\Users\biuro3\Downloads\OTL.exe 2014-05-13 16:15 - 2014-01-14 05:43 - 00021528 _____ () C:\Users\biuro3\Desktop\POCZTA WYCHODZĄCA.xlsx 2014-05-13 14:37 - 2014-05-03 19:25 - 00499200 ____N () C:\Users\biuro3\Desktop\kalendarz cen 01 2014-31 12 2015 akt 3 05 2014.xls 2014-05-13 12:11 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp 2014-05-13 12:10 - 2009-08-21 00:20 - 00006432 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-13 12:10 - 2009-08-07 18:03 - 07666118 _____ () C:\Windows\system32\perfh015.dat 2014-05-13 12:10 - 2009-08-07 18:03 - 02506232 _____ () C:\Windows\system32\perfc015.dat 2014-05-13 10:32 - 2010-09-17 21:47 - 01768919 _____ () C:\Windows\WindowsUpdate.log 2014-05-13 09:00 - 2014-05-13 09:00 - 00000165 ____H () C:\Users\biuro3\Desktop\~$baza klubów fitnes.xlsx 2014-05-13 08:24 - 2014-05-07 18:37 - 00204800 ____N () C:\Users\biuro3\Desktop\Recepcja 2014 (3).xls 2014-05-13 08:00 - 2014-01-23 15:39 - 00000000 ____D () C:\Users\biuro3\Desktop\Mercure 2014-05-13 05:52 - 2014-05-13 05:52 - 00036864 _____ () C:\Users\biuro3\Desktop\report.operation.20140513-20140513 P. Adam Lesiński.xls 2014-05-13 01:31 - 2014-05-09 23:14 - 00000896 _____ () C:\Windows\setupact.log 2014-05-13 01:12 - 2013-12-02 09:25 - 00395502 _____ () C:\Users\biuro3\Desktop\PICK-UP Maj.xlsx 2014-05-13 00:48 - 2014-03-31 18:32 - 00000000 ____D () C:\Users\biuro3\Desktop\zbierane maile i telefony 2014-05-12 20:28 - 2010-09-17 12:56 - 00001032 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-12 15:42 - 2014-05-09 12:09 - 00000000 __SHD () C:\Users\biuro3\AppData\Roaming\.# 2014-05-12 15:14 - 2014-01-09 20:10 - 00100880 _____ () C:\Users\biuro3\Desktop\Godziny pracownicy KWIECEIŃ.xlsx 2014-05-12 14:11 - 2014-05-09 18:55 - 00037449 _____ () C:\Users\biuro3\Desktop\baza klubów fitnes.xlsx 2014-05-11 23:47 - 2014-05-11 23:47 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-11 16:30 - 2014-05-11 16:30 - 00000000 ____D () C:\Users\biuro3\AppData\Roaming\Juniper Networks 2014-05-10 06:37 - 2014-05-10 00:02 - 00000000 ____D () C:\Users\biuro3\Desktop\GASTRO 2014-05-09 23:14 - 2014-05-09 23:14 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-09 22:47 - 2014-05-09 22:47 - 06083031 _____ () C:\Users\biuro3\Downloads\TableNumbers_Ruffled (1).zip 2014-05-09 22:47 - 2014-05-09 22:46 - 06083031 _____ () C:\Users\biuro3\Downloads\TableNumbers_Ruffled.zip 2014-05-09 12:09 - 2014-05-09 12:09 - 00000000 ____D () C:\Program Files\Common Files\SWF Studio 2014-05-09 10:04 - 2014-05-09 10:04 - 00002050 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk 2014-05-09 10:04 - 2014-05-09 10:04 - 00002038 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk 2014-05-09 10:04 - 2014-05-09 10:04 - 00000000 ____D () C:\Users\biuro3\AppData\Roaming\Thunderbird 2014-05-09 10:04 - 2014-05-09 10:04 - 00000000 ____D () C:\Users\biuro3\AppData\Local\Thunderbird 2014-05-09 10:04 - 2014-05-09 10:04 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird 2014-05-09 10:04 - 2012-04-26 06:44 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-05-09 09:53 - 2014-05-09 09:52 - 01315565 ____N () C:\Users\biuro3\Downloads\AdwCleaner.exe 2014-05-09 09:52 - 2014-05-09 09:43 - 22856956 ____N (Mozilla) C:\Users\biuro3\Downloads\Thunderbird Setup 24.5.0 (1).exe 2014-05-09 04:52 - 2009-07-14 04:04 - 00000615 _____ () C:\Windows\win.ini 2014-05-09 00:29 - 2009-07-14 06:34 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-09 00:29 - 2009-07-14 06:34 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-09 00:21 - 2013-06-08 07:02 - 00000350 _____ () C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job 2014-05-09 00:21 - 2013-06-03 01:16 - 00000350 _____ () C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2014-05-09 00:21 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-08 23:16 - 2014-04-09 00:54 - 00002064 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-05-08 23:15 - 2014-05-08 23:15 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-05-08 23:15 - 2014-05-08 23:15 - 00024184 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-05-08 23:15 - 2014-01-14 18:44 - 00067776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-05-08 23:15 - 2013-03-22 15:47 - 00180632 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-05-08 23:15 - 2013-03-22 15:47 - 00049944 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-05-08 23:15 - 2012-06-14 14:25 - 00776976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-05-08 23:15 - 2012-06-14 14:25 - 00081768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-05-08 23:15 - 2011-10-21 00:22 - 00411552 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-05-08 23:15 - 2011-10-21 00:22 - 00271264 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-05-08 23:15 - 2011-10-21 00:22 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-05-08 21:56 - 2014-05-08 21:56 - 26900321 ____N () C:\Users\biuro3\Downloads\konferencyjne (1).rar 2014-05-08 21:22 - 2014-05-08 21:22 - 00000000 ____D () C:\Users\biuro3\Documents\Ashampoo Burning Studio 2014 2014-05-08 21:20 - 2014-05-07 14:50 - 00000000 ____D () C:\Users\biuro3\Desktop\DO teczek 2014-05-08 21:18 - 2014-01-12 03:03 - 00000000 ____D () C:\Users\biuro3\AppData\Roaming\Ashampoo 2014-05-08 21:17 - 2014-05-08 21:17 - 00001267 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk 2014-05-08 21:17 - 2014-01-12 03:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo 2014-05-08 21:16 - 2014-01-12 03:02 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-05-08 21:16 - 2014-01-12 03:02 - 00000000 ____D () C:\Program Files\Ashampoo 2014-05-08 21:15 - 2014-05-08 21:15 - 91956656 ____N (Ashampoo GmbH & Co. KG ) C:\Users\biuro3\Downloads\ashampoo_burning_studio_2014_12.0.5_15396.exe 2014-05-08 21:13 - 2014-05-08 21:13 - 00702752 ____N () C:\Users\biuro3\Downloads\Ashampoo-Burning-Studio(12487).exe 2014-05-08 18:28 - 2014-05-08 18:28 - 26900321 ____N () C:\Users\biuro3\Downloads\konferencyjne.rar 2014-05-08 11:19 - 2014-05-08 11:19 - 00050688 ____N () C:\Users\biuro3\Desktop\karta pracy.xls 2014-05-08 01:15 - 2013-09-19 21:18 - 00000000 ____D () C:\Users\biuro3\AppData\Local\HP 2014-05-07 16:56 - 2014-05-07 16:43 - 00000000 ____D () C:\Users\biuro3\AppData\Roaming\HpUpdate 2014-05-07 16:43 - 2014-05-07 16:43 - 00000000 ____D () C:\Users\Public\Documents\HP_LaserJet_Fax_0_6 2014-05-07 16:43 - 2013-06-12 08:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2014-05-07 16:43 - 2013-06-12 08:35 - 00000000 ____D () C:\Program Files\HP 2014-05-07 16:43 - 2013-06-12 07:51 - 00000000 ____D () C:\ProgramData\HP 2014-05-07 16:41 - 2014-05-07 16:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SnadBoy's Revelation v2 2014-05-07 16:41 - 2014-05-07 16:41 - 00000000 ____D () C:\Program Files\SnadBoy's Revelation v2 2014-05-07 16:40 - 2014-05-07 16:40 - 00217666 ____N () C:\Users\biuro3\Downloads\RevelationV2.zip 2014-05-07 16:38 - 2013-06-12 08:50 - 00000608 ___SH () C:\Windows\system32\winzvprt5.sys 2014-05-07 16:38 - 2013-06-12 08:50 - 00000230 _____ () C:\Windows\system32\hppfaxprinter5.ini 2014-05-07 16:37 - 2014-05-07 16:37 - 00001160 _____ () C:\Users\Public\Desktop\HP LJ M1530 Scan.lnk 2014-05-07 16:37 - 2014-05-07 16:37 - 00000926 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rejestracja programu I.R.I.S. OCR.lnk 2014-05-07 16:37 - 2014-05-07 16:37 - 00000000 ____D () C:\Users\biuro3\AppData\Roaming\Hewlett-Packard Company 2014-05-07 16:37 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\twain_32 2014-05-07 16:36 - 2014-05-07 16:36 - 00001336 _____ () C:\Users\Public\Desktop\HP LaserJet Professional M1530 MFP Series - Centrum pomocy i szkolenia.lnk 2014-05-07 16:36 - 2013-06-12 08:49 - 00000121 _____ () C:\Windows\system32\msiexec.log 2014-05-07 16:34 - 2014-05-07 16:34 - 00000000 ____D () C:\Users\biuro3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP 2014-05-07 16:06 - 2014-05-08 22:49 - 00052920 _____ (StdLib) C:\Windows\system32\Drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw.sys 2014-05-07 11:10 - 2014-05-07 09:16 - 01170944 ____N () C:\Users\biuro3\Desktop\raport sprzedaży2014 krystian.xls 2014-05-02 05:44 - 2013-07-17 15:36 - 00000000 ___RD () C:\Users\biuro3\Desktop\Portierzy, techniczni 2014-05-01 03:23 - 2014-04-29 23:09 - 00000000 ____D () C:\Users\biuro3\Desktop\Faktury pro-formy 2014-05-01 03:23 - 2014-03-19 23:42 - 00006584 ___SH () C:\Users\biuro3\Desktop\Spis treści programu OneNote.onetoc2 2014-04-30 03:01 - 2014-04-30 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-29 12:28 - 2014-05-03 03:01 - 12347392 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-29 12:07 - 2014-05-03 03:01 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-29 11:34 - 2012-03-29 19:45 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-04-29 11:34 - 2011-06-08 22:34 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-04-28 18:18 - 2013-04-17 13:17 - 00062464 ____N () C:\Users\biuro3\Desktop\Rzeczy zagubione i znalezione.xls 2014-04-24 22:16 - 2011-01-20 14:39 - 00051060 ____N () C:\Users\biuro3\Desktop\SPIS KART LOJALNOŚCIOWYCH.xlsx 2014-04-24 21:44 - 2014-04-24 21:44 - 00009002 ____N () C:\Users\biuro3\Desktop\cc_20140424_214356.reg 2014-04-24 06:06 - 2014-05-09 10:01 - 00000426 _____ () C:\AVScanner.ini 2014-04-24 05:34 - 2010-09-17 13:00 - 00000000 ____D () C:\Users\biuro3\AppData\Local\Adobe 2014-04-23 19:26 - 2013-08-26 17:06 - 00000000 ___RD () C:\Users\biuro3\Desktop\Do druku- szlaki rowerowe itd 2014-04-20 05:15 - 2014-04-20 05:15 - 00000847 ____N () C:\Users\biuro3\Desktop\Rehabilitacja — skrót.lnk 2014-04-20 05:14 - 2014-03-15 21:59 - 00000000 ____D () C:\Users\biuro3\Desktop\Meeting Plenner, WESELA ITP 2014-04-19 12:12 - 2014-04-19 12:12 - 00519003 ____N () C:\Users\biuro3\Desktop\SIWZ_wraz_zaYYcznikami_2.zip 2014-04-18 09:52 - 2014-04-18 09:52 - 00019655 ____N () C:\Users\biuro3\Desktop\bryczki 19.04.2014.xlsx 2014-04-18 03:36 - 2011-08-11 10:00 - 00000000 ____D () C:\Program Files\WinRAR 2014-04-16 19:10 - 2014-04-16 19:10 - 01110476 ____N () C:\Users\biuro3\Downloads\7z920.exe 2014-04-16 19:10 - 2014-04-16 19:10 - 01110476 ____N () C:\Users\biuro3\Downloads\7z920 (1).exe 2014-04-16 19:10 - 2014-04-16 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2014-04-16 19:10 - 2014-04-16 19:10 - 00000000 ____D () C:\Program Files\7-Zip 2014-04-16 17:47 - 2014-04-16 17:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyFinder 2014-04-16 17:47 - 2014-04-16 17:47 - 00000000 ____D () C:\Program Files\Magical Jelly Bean 2014-04-16 17:46 - 2014-04-16 17:46 - 01199848 ____N (Magical Jelly Bean ) C:\Users\biuro3\Downloads\KeyFinderInstaller.exe 2014-04-16 17:39 - 2010-10-06 19:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xerox Phaser 3300MFP 2014-04-16 17:38 - 2013-08-07 11:57 - 00000000 ____D () C:\Program Files\Hostless Modem 2014-04-16 17:31 - 2014-04-16 17:31 - 00001392 ____N () C:\Users\biuro3\Desktop\cc_20140416_173112.reg 2014-04-15 00:03 - 2013-11-27 17:54 - 00000000 ____D () C:\Z pulpitu nie usuwac 2014-04-14 23:59 - 2014-04-14 23:59 - 00001422 ____N () C:\Users\biuro3\Desktop\PRACOWNICY!!!! ma być w jednym folderze — skrót.lnk 2014-04-14 10:00 - 2014-04-14 10:00 - 00000000 ____D () C:\ProgramData\TightVNC 2014-04-14 10:00 - 2014-04-14 10:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TightVNC 2014-04-14 10:00 - 2010-10-12 15:09 - 00000000 ____D () C:\Program Files\TightVNC 2014-04-14 04:11 - 2014-04-30 02:54 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-14 04:07 - 2014-04-30 02:54 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll Some content of TEMP: ==================== C:\Users\biuro3\AppData\Local\Temp\61rwfkas.dll C:\Users\biuro3\AppData\Local\Temp\BackupSetup.exe C:\Users\biuro3\AppData\Local\Temp\vcredist_x86.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 11:58 ==================== End Of Log ============================