Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:06-06-2014 Ran by Ania (administrator) on ANIA-KOMPUTER on 08-06-2014 19:40:34 Running from C:\Users\Ania\Desktop Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe () C:\Windows\System32\AsusService.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Secunia) C:\Program Files\Secunia\PSI\sua.exe (Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (ASUS) C:\Windows\AsScrPro.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (ASUSTeK Computer Inc.) C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (ASUSTeK Computer Inc.) C:\Program Files\EeePC\HotkeyService\HotkeyService.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (ASUS) C:\Program Files\EeePC\CapsHook\CapsHook.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (QFX Software Corporation) C:\Program Files\KeyScrambler\KeyScrambler.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1594664 2009-11-19] (Synaptics Incorporated) HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [83240 2009-11-19] (Synaptics Incorporated) HKLM\...\Run: [ASUS Screen Saver Protector] => C:\windows\AsScrPro.exe [3058304 2010-09-29] (ASUS) HKLM\...\Run: [HotkeyMon] => C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe [100328 2009-09-11] (ASUSTeK Computer Inc.) HKLM\...\Run: [HotkeyService] => C:\Program Files\EeePC\HotkeyService\HotkeyService.exe [1244592 2010-08-10] (ASUSTeK Computer Inc.) HKLM\...\Run: [CapsHook] => C:\Program Files\EeePC\CapsHook\CapsHook.exe [445344 2010-05-29] (ASUS) HKLM\...\Run: [GraphicsSwitch] => AsusSender.exe C:\Program Files\Asus\GraphicsSwitch\GPUStatusMonitor.exe HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9722472 2010-08-24] (Realtek Semiconductor) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-03] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [KeyScrambler] => C:\Program Files\KeyScrambler\keyscrambler.exe [508144 2013-11-14] (QFX Software Corporation) HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-21-3146292988-2315933456-2787739076-1001\...\Run: [Google Update] => C:\Users\Ania\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-03-20] (Google Inc.) HKU\S-1-5-21-3146292988-2315933456-2787739076-1001\...\Run: [KSS] => C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202328 2012-12-07] (Kaspersky Lab ZAO) HKU\S-1-5-21-3146292988-2315933456-2787739076-1001\...\MountPoints2: {052d2c62-4b67-11e0-ba68-bcaec5cfa5e2} - E:\AutoRun.exe HKU\S-1-5-21-3146292988-2315933456-2787739076-1001\...\MountPoints2: {052d2c72-4b67-11e0-ba68-bcaec5cfa5e2} - E:\AutoRun.exe HKU\S-1-5-21-3146292988-2315933456-2787739076-1001\...\MountPoints2: {052d2c8e-4b67-11e0-ba68-bcaec5cfa5e2} - E:\AutoRun.exe HKU\S-1-5-21-3146292988-2315933456-2787739076-1001\...\MountPoints2: {651d4140-5a48-11e0-b23a-bcaec5cfa5e2} - E:\AutoRun.exe AppInit_DLLs: c:\windows\system32\nvinit.dll => c:\windows\system32\nvinit.dll [102504 2010-08-04] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://eeepc.asus.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=6275BCAEC5CFA5E2&affID=119818&tt=250613_gr3&tsp=4925 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/PL/Core/Player/2020PlayerAX_IKEA_Win32.cab DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} http://kitchenplanner.ikea.com/PL/Core/Player/2020PlayerAX_Win32.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\1zm4tslr.default FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @caminova.com/DjVuPlugin - C:\Program Files\Caminova\Document Express DjVu Plug-in\npdjvu.dll (Caminova, Inc.) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Ania\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Ania\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF user.js: detected! => C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\1zm4tslr.default\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdjvu.dll (LizardTech) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\1zm4tslr.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\1zm4tslr.default\searchplugins\delta.xml FF Extension: Flash Video Downloader - Full HD Download - C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\1zm4tslr.default\Extensions\artur.dubovoy@gmail.com [2014-05-10] FF Extension: WOT - C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\1zm4tslr.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-27] FF Extension: DownloadHelper - C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\1zm4tslr.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-25] FF Extension: Adblock Plus - C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\1zm4tslr.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-06-30] Chrome: ======= CHR Extension: (Google Wallet) - C:\Users\Ania\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24] ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG) R2 AsusService; C:\Windows\System32\AsusService.exe [219136 2009-08-19] () R2 KSS; C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202328 2012-12-07] (Kaspersky Lab ZAO) S3 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1225312 2012-11-26] (Secunia) R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [659040 2012-11-26] (Secunia) ==================== Drivers (Whitelisted) ==================== R0 AiDriver; C:\windows\System32\DRIVERS\AiDriver.sys [13224 2010-05-20] (ASUSTek Computer Inc.) R1 AsUpIO; C:\windows\System32\drivers\AsUpIO.sys [11520 2010-03-31] () R2 avgntflt; C:\windows\System32\DRIVERS\avgntflt.sys [93528 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\windows\System32\DRIVERS\avipbb.sys [136216 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG) S3 btwampfl; C:\windows\System32\drivers\btwampfl.sys [293928 2010-05-21] (Broadcom Corporation.) R3 kbfiltr; C:\windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( ) R3 KeyScrambler; C:\windows\System32\drivers\keyscrambler.sys [209016 2013-05-31] (QFX Software Corporation) R0 nvpciflt; C:\windows\System32\DRIVERS\nvpciflt.sys [19656 2010-08-04] (NVIDIA Corporation) S3 OEM05Afx; C:\windows\system32\Drivers\OEM05Afx.sys [141376 2007-06-08] (Creative Technology Ltd.) S3 OEM05Vfx; C:\windows\System32\DRIVERS\OEM05Vfx.sys [7424 2007-03-05] (EyePower Games Pte. Ltd.) S3 OEM05Vid; C:\windows\System32\DRIVERS\OEM05Vid.sys [235616 2007-07-20] (Creative Technology Ltd.) S3 PSI; C:\windows\System32\DRIVERS\psi_mf.sys [15544 2010-09-01] (Secunia) R0 sptd; C:\windows\System32\Drivers\sptd.sys [466008 2013-09-29] (Duplex Secure Ltd.) R1 ssmdrv; C:\windows\System32\DRIVERS\ssmdrv.sys [28520 2013-03-03] (Avira GmbH) S3 tap0901; C:\windows\System32\DRIVERS\tap0901.sys [26624 2011-07-01] (The OpenVPN Project) S3 anvsnddrv; system32\drivers\anvsnddrv.sys [X] U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [204288 2010-03-24] (Huawei Technologies Co., Ltd.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-08 19:38 - 2014-06-08 19:40 - 00000000 ____D () C:\FRST 2014-06-06 19:50 - 2014-06-06 19:50 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-06-06 07:00 - 2014-06-06 07:00 - 00000812 _____ () C:\windows\PFRO.log 2014-06-05 21:52 - 2014-06-05 21:52 - 00001242 _____ () C:\Users\Public\Desktop\Freemake Video Converter.lnk 2014-06-05 21:52 - 2014-06-05 21:52 - 00000000 ____D () C:\Users\Ania\Documents\Freemake 2014-06-05 21:52 - 2014-06-05 21:52 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake 2014-06-05 21:52 - 2014-06-05 21:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake 2014-06-05 21:51 - 2014-06-05 21:52 - 00000000 ____D () C:\ProgramData\Freemake 2014-06-05 21:51 - 2014-06-05 21:52 - 00000000 ____D () C:\Program Files\Freemake 2014-06-03 20:56 - 2014-06-03 20:56 - 01123840 _____ (Karol Winnicki) C:\Users\Ania\Downloads\BESTplayer.exe 2014-06-03 08:05 - 2014-06-03 08:05 - 00000000 ____D () C:\Users\Ania\AppData\Local\ABBYY 2014-06-03 08:04 - 2014-06-03 08:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 6.0 Sprint 2014-06-03 08:04 - 2014-06-03 08:04 - 00002769 _____ () C:\Users\Ania\Desktop\ABBYY FineReader 6.0 Sprint.lnk 2014-06-03 08:03 - 2014-06-03 08:04 - 00000000 ____D () C:\Program Files\ABBYY FineReader 6.0 Sprint 2014-05-31 10:27 - 2014-06-08 11:50 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-05-23 22:55 - 2014-06-02 10:31 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-05-23 14:18 - 2014-05-23 14:20 - 294859178 _____ () C:\Users\Ania\Downloads\[prywatne] 2014-05-20 11:30 - 2014-05-20 11:30 - 00161608 _____ () C:\windows\Minidump\052014-19422-01.dmp 2014-05-15 20:40 - 2014-05-15 20:40 - 00048199 _____ () C:\Users\Ania\Downloads\[prywatne] 2014-05-14 12:21 - 2014-05-14 12:21 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-05-14 09:01 - 2014-05-09 09:06 - 00369664 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-05-14 09:01 - 2014-05-09 09:04 - 00302592 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-05-14 09:01 - 2014-04-12 04:15 - 00136640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys 2014-05-14 09:01 - 2014-04-12 04:15 - 00067520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys 2014-05-14 09:01 - 2014-04-12 04:12 - 00100352 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll 2014-05-14 09:01 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll 2014-05-14 09:01 - 2014-04-12 04:12 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll 2014-05-14 09:01 - 2014-04-12 04:11 - 01059840 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2014-05-14 09:01 - 2014-04-12 04:11 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe 2014-05-14 09:01 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe 2014-05-14 09:01 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2014-05-14 09:01 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00304128 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe 2014-05-14 09:01 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll 2014-05-14 09:01 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll 2014-05-14 09:00 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll 2014-05-12 07:59 - 2013-05-10 06:56 - 12625408 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL 2014-05-12 07:59 - 2013-05-10 06:56 - 11410432 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll 2014-05-12 00:50 - 2014-05-12 00:50 - 00001007 _____ () C:\Users\Ania\Desktop\Kaspersky Security Scan.lnk 2014-05-12 00:50 - 2014-05-12 00:50 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan 2014-05-12 00:49 - 2014-05-12 00:49 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-05-12 00:49 - 2014-05-12 00:49 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-05-12 00:33 - 2014-05-12 00:33 - 00187792 _____ (Kaspersky Lab) C:\Users\Ania\Downloads\kss12.0.1.340_pl.exe 2014-05-11 20:37 - 2014-05-11 20:37 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-11 14:34 - 2014-05-11 14:34 - 00001515 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-05-09 08:23 - 2014-06-08 17:21 - 00009968 _____ () C:\windows\setupact.log 2014-05-09 08:23 - 2014-05-09 08:23 - 00000000 _____ () C:\windows\setuperr.log ==================== One Month Modified Files and Folders ======= 2014-06-08 19:41 - 2011-03-10 21:30 - 00000000 ____D () C:\Users\Ania\AppData\Local\Temp 2014-06-08 19:40 - 2014-06-08 19:38 - 00000000 ____D () C:\FRST 2014-06-08 19:40 - 2012-06-22 15:49 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-06-08 19:37 - 2010-09-29 20:28 - 01672142 _____ () C:\windows\system32\PerfStringBackup.INI 2014-06-08 19:37 - 2009-06-20 21:25 - 00741140 _____ () C:\windows\system32\perfh015.dat 2014-06-08 19:37 - 2009-06-20 21:25 - 00156424 _____ () C:\windows\system32\perfc015.dat 2014-06-08 19:28 - 2009-07-14 06:34 - 00009920 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-08 19:28 - 2009-07-14 06:34 - 00009920 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-08 19:25 - 2012-07-20 08:28 - 00000930 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-06-08 18:44 - 2011-03-20 03:07 - 00001054 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3146292988-2315933456-2787739076-1001UA.job 2014-06-08 18:15 - 2011-03-11 09:00 - 01374411 _____ () C:\windows\WindowsUpdate.log 2014-06-08 17:21 - 2014-05-09 08:23 - 00009968 _____ () C:\windows\setupact.log 2014-06-08 17:21 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-06-08 11:50 - 2014-05-31 10:27 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-06-07 17:40 - 2011-03-17 14:28 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-06-06 19:50 - 2014-06-06 19:50 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-06-06 07:00 - 2014-06-06 07:00 - 00000812 _____ () C:\windows\PFRO.log 2014-06-05 21:52 - 2014-06-05 21:52 - 00001242 _____ () C:\Users\Public\Desktop\Freemake Video Converter.lnk 2014-06-05 21:52 - 2014-06-05 21:52 - 00000000 ____D () C:\Users\Ania\Documents\Freemake 2014-06-05 21:52 - 2014-06-05 21:52 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake 2014-06-05 21:52 - 2014-06-05 21:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake 2014-06-05 21:52 - 2014-06-05 21:51 - 00000000 ____D () C:\ProgramData\Freemake 2014-06-05 21:52 - 2014-06-05 21:51 - 00000000 ____D () C:\Program Files\Freemake 2014-06-05 09:44 - 2011-03-20 03:06 - 00001002 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3146292988-2315933456-2787739076-1001Core.job 2014-06-03 20:57 - 2011-04-07 21:57 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\BESTplayer 2014-06-03 20:56 - 2014-06-03 20:56 - 01123840 _____ (Karol Winnicki) C:\Users\Ania\Downloads\BESTplayer.exe 2014-06-03 20:56 - 2014-04-15 19:43 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\vlc 2014-06-03 20:50 - 2014-03-22 12:07 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-06-03 16:21 - 2013-12-07 22:44 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-06-03 14:10 - 2013-03-03 21:22 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys 2014-06-03 14:10 - 2013-03-03 21:22 - 00093528 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys 2014-06-03 08:11 - 2014-06-03 08:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 6.0 Sprint 2014-06-03 08:05 - 2014-06-03 08:05 - 00000000 ____D () C:\Users\Ania\AppData\Local\ABBYY 2014-06-03 08:04 - 2014-06-03 08:04 - 00002769 _____ () C:\Users\Ania\Desktop\ABBYY FineReader 6.0 Sprint.lnk 2014-06-03 08:04 - 2014-06-03 08:03 - 00000000 ____D () C:\Program Files\ABBYY FineReader 6.0 Sprint 2014-06-02 10:52 - 2013-10-07 13:12 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-06-02 10:31 - 2014-05-23 22:55 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-05-30 14:52 - 2014-02-10 11:56 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-05-30 12:58 - 2012-09-11 10:31 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-05-26 17:04 - 2013-12-03 09:45 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-05-23 14:20 - 2014-05-23 14:18 - 294859178 _____ () C:\Users\Ania\Downloads\[prywatne] 2014-05-20 11:30 - 2014-05-20 11:30 - 00161608 _____ () C:\windows\Minidump\052014-19422-01.dmp 2014-05-20 11:30 - 2011-05-15 20:13 - 00000000 ____D () C:\windows\Minidump 2014-05-19 10:11 - 2012-05-12 15:39 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-05-15 20:40 - 2014-05-15 20:40 - 00048199 _____ () C:\Users\Ania\Downloads\[prywatne] 2014-05-15 11:09 - 2013-02-19 12:13 - 00000000 ____D () C:\Users\Ania\Desktop\[prywatne] 2014-05-15 10:17 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\rescache 2014-05-15 10:00 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\Microsoft.NET 2014-05-14 18:44 - 2013-07-26 23:35 - 00000000 ____D () C:\windows\system32\MRT 2014-05-14 12:34 - 2014-05-06 11:06 - 00000000 ___SD () C:\windows\system32\CompatTel 2014-05-14 12:34 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\pl-PL 2014-05-14 12:27 - 2011-05-22 08:25 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-14 12:21 - 2014-05-14 12:21 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-05-14 12:15 - 2011-03-11 03:19 - 90547776 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-05-13 21:25 - 2012-06-30 12:14 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe 2014-05-13 21:25 - 2012-06-30 12:14 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl 2014-05-13 11:30 - 2009-07-14 06:53 - 00032604 _____ () C:\windows\Tasks\SCHEDLGU.TXT 2014-05-12 00:50 - 2014-05-12 00:50 - 00001007 _____ () C:\Users\Ania\Desktop\Kaspersky Security Scan.lnk 2014-05-12 00:50 - 2014-05-12 00:50 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan 2014-05-12 00:49 - 2014-05-12 00:49 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-05-12 00:49 - 2014-05-12 00:49 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-05-12 00:33 - 2014-05-12 00:33 - 00187792 _____ (Kaspersky Lab) C:\Users\Ania\Downloads\kss12.0.1.340_pl.exe 2014-05-12 00:16 - 2012-04-26 17:14 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-05-11 20:37 - 2014-05-11 20:37 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-11 14:34 - 2014-05-11 14:34 - 00001515 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-05-11 14:34 - 2009-07-26 23:40 - 00000000 ____D () C:\windows\panther 2014-05-11 14:31 - 2009-07-14 09:48 - 00000000 ____D () C:\windows\ShellNew 2014-05-11 14:31 - 2009-07-14 06:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-05-11 14:31 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-05-11 14:19 - 2011-03-11 02:01 - 00000000 ____D () C:\Program Files\CCleaner 2014-05-09 09:06 - 2014-05-14 09:01 - 00369664 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2014-05-09 09:04 - 2014-05-14 09:01 - 00302592 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2014-05-09 08:23 - 2014-05-09 08:23 - 00000000 _____ () C:\windows\setuperr.log Some content of TEMP: ==================== C:\Users\Ania\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\windows\explorer.exe => MD5 is legit C:\windows\system32\winlogon.exe => MD5 is legit C:\windows\system32\wininit.exe => MD5 is legit C:\windows\system32\svchost.exe => MD5 is legit C:\windows\system32\services.exe => MD5 is legit C:\windows\system32\User32.dll => MD5 is legit C:\windows\system32\userinit.exe => MD5 is legit C:\windows\system32\rpcss.dll => MD5 is legit C:\windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-06-08 10:27 ==================== End Of Log ============================