Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-10-2014 Ran by Toshiba (administrator) on TOSHIBA-TOSH on 13-10-2014 15:27:54 Running from C:\Users\Toshiba\Desktop Loaded Profiles: Toshiba & UpdatusUser (Available profiles: Toshiba & UpdatusUser) Platform: Windows 7 Home Premium (X64) OS Language: Polski (Polska) Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (Dassault Systemes) D:\Programy\B20\intel_a\code\bin\CATSysDemon.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Solid Documents, LLC) C:\Program Files (x86)\SolidDocuments\Solid Converter PDF\SCPDF\SolidConverterPDFServicex64.exe (TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe (AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe (TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation.) C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe () C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Redefine Sp z o.o.) C:\Program Files (x86)\ipla\ipla.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Autodesk, Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe (Dassault Systèmes SolidWorks Corp.) D:\SolidWorks\Solid Works2013\sldworks_fs.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (Google Inc.) C:\Users\Toshiba\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Toshiba\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Google Inc.) C:\Users\Toshiba\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2009-08-03] (TOSHIBA Corporation) HKLM\...\Run: [ThpSrv] => C:\Windows\system32\thpsrv /logon HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [35160 2009-08-06] (TOSHIBA Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7982112 2009-08-03] (Realtek Semiconductor) HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [497504 2009-08-21] (TOSHIBA Corporation) HKLM\...\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation) HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [909624 2009-08-05] (TOSHIBA Corporation) HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [711000 2009-08-04] (TOSHIBA Corporation) HKLM\...\Run: [HDMICtrlMan] => C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe [1032536 2009-08-03] (TOSHIBA Corporation.) HKLM\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [415680 2012-02-06] (Autodesk, Inc.) HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-10-18] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [HWSetup] => C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [423936 2009-06-02] (TOSHIBA Electronics, Inc.) HKLM-x32\...\Run: [KeNotify] => C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34088 2009-01-13] (TOSHIBA CORPORATION) HKLM-x32\...\Run: [TUSBSleepChargeSrv] => C:\Program Files (x86)\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe [252288 2009-07-02] (TOSHIBA) HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296056 2012-04-16] (RealNetworks, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [3521424 2012-03-31] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [ADSK DLMSession] => C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [1632216 2012-07-23] (Autodesk, Inc.) HKU\S-1-5-21-2754264385-1261652437-1540506145-1000\...\Run: [KiesHelper] => C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe [954256 2012-03-31] (Samsung) HKU\S-1-5-21-2754264385-1261652437-1540506145-1000\...\Run: [KiesPDLR] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21392 2012-03-31] () HKU\S-1-5-21-2754264385-1261652437-1540506145-1000\...\Run: [ALLUpdate] => C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [2991616 2012-10-09] (ALLCinema) HKU\S-1-5-21-2754264385-1261652437-1540506145-1000\...\Run: [IPLA!] => C:\Program Files (x86)\ipla\ipla.exe [21370976 2014-07-21] (Redefine Sp z o.o.) HKU\S-1-5-21-2754264385-1261652437-1540506145-1000\...\Run: [EADM] => D:\Gry\Origin\Origin.exe [3600216 2014-09-16] (Electronic Arts) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks 2013 Fast Start.lnk ShortcutTarget: SolidWorks 2013 Fast Start.lnk -> C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe (Flexera Software, Inc.) ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {E9B91B8B-7B9C-404D-8195-97652674605A} URL = http://www.amazon.co.uk/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibauk-win7-ie-search-21&index=blended&linkCode=ur2 SearchScopes: HKCU - {F7F9D926-BE68-47C2-892F-BBF6A153BAC2} URL = http://rover.ebay.com/rover/1/710-44557-9400-9/4?satitle={searchTerms} BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO-x32: ALLYouTubeDownloader -> {61DB16C5-B733-43F4-872E-B20DC9E72740} -> C:\Program Files (x86)\ALLYouTubeDownloader\ALLYouTubeDownloader.dll (ALLCinema Ltd.) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: IplexToALLPlayer -> {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} -> C:\Program Files (x86)\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash4/cabs/swflash.cab Tcpip\Parameters: [DhcpNameServer] 62.179.1.63 62.179.1.62 FireFox: ======== FF ProfilePath: C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\68wcotjf.default-1413206614925 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.5.669\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Toshiba\AppData\Local\Google\Chrome\Application\36.0.1985.143\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Toshiba\AppData\Local\Google\Chrome\Application\36.0.1985.143\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Toshiba\AppData\Local\Google\Chrome\Application\36.0.1985.143\pdf.dll () CHR Plugin: (Microsoft Office 2013) - C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc) CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) CHR Profile: C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Dysk Google) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-05] CHR Extension: (AdBlock) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-09-30] CHR Extension: (IE Tab) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2014-06-23] CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2013-05-25] CHR Extension: (Google Wallet) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-30] CHR Extension: (cosstminn) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppahdjodapkenchnkapleieealnolggi [2014-08-18] CHR Extension: (cosstminn) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppahdjodapkenchnkapleieealnolggi\2.0 [2014-08-18] CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2012-04-16] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.) R2 BBDemon; D:\Programy\B20\intel_a\code\bin\CATSysDemon.exe [36864 2010-01-09] (Dassault Systemes) [File not signed] S3 CoordinatorServiceHost; D:\SolidWorks\Solid Works2013\swScheduler\DTSCoordinatorService.exe [77352 2013-10-01] (Dassault Systèmes SolidWorks Corp.) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15122208 2013-10-18] (NVIDIA Corporation) R2 SCPDFReadSpool; C:\Program Files (x86)\SolidDocuments\Solid Converter PDF\SCPDF\SolidConverterPDFServicex64.exe [209920 2011-10-21] (Solid Documents, LLC) [File not signed] S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2012-04-02] (SolidWorks) [File not signed] R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2183992 2014-03-22] (AVG) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 LUMDriver; C:\Windows\system32\drivers\LUMDriver.sys [24848 2008-01-02] (IBM) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) S3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [416768 2009-06-10] (Realtek Semiconductor Corporation ) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-02-10] (TuneUp Software) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-13 15:23 - 2014-10-13 15:23 - 00000000 ____D () C:\Users\Toshiba\Desktop\Stare dane programu Firefox 2014-10-12 18:33 - 2014-10-12 18:33 - 00000264 _____ () C:\Users\Toshiba\Desktop\defogger.txt 2014-10-12 18:16 - 2014-10-12 18:17 - 00000528 _____ () C:\Users\Toshiba\Desktop\defogger_disable.txt.log 2014-10-12 18:16 - 2014-10-12 18:16 - 00050477 _____ () C:\Users\Toshiba\Desktop\Defogger.exe 2014-10-12 18:16 - 2014-10-12 18:16 - 00000000 _____ () C:\Users\Toshiba\defogger_reenable 2014-10-12 18:13 - 2014-10-12 18:13 - 00380416 _____ () C:\Users\Toshiba\Desktop\mu1ien19.exe 2014-10-12 17:54 - 2014-10-12 17:54 - 00094998 _____ () C:\Users\Toshiba\Desktop\Extras.Txt 2014-10-12 17:52 - 2014-10-12 17:52 - 00126854 _____ () C:\Users\Toshiba\Desktop\OTL.Txt 2014-10-12 17:42 - 2014-10-12 17:42 - 00118641 _____ () C:\Users\Toshiba\Desktop\Shortcut.txt 2014-10-12 17:41 - 2014-10-12 17:42 - 00045394 _____ () C:\Users\Toshiba\Desktop\Addition.txt 2014-10-12 17:41 - 2014-10-12 17:41 - 00380416 _____ () C:\Users\Toshiba\Desktop\891fz7gh.exe 2014-10-12 17:40 - 2014-10-12 17:40 - 00602112 _____ (OldTimer Tools) C:\Users\Toshiba\Desktop\OTL.exe 2014-10-12 17:39 - 2014-10-13 15:28 - 00016695 _____ () C:\Users\Toshiba\Desktop\FRST.txt 2014-10-12 17:39 - 2014-10-13 15:27 - 00000000 ____D () C:\FRST 2014-10-12 17:38 - 2014-10-12 17:39 - 02110464 _____ (Farbar) C:\Users\Toshiba\Desktop\FRST64.exe 2014-10-12 17:24 - 2014-10-12 17:24 - 00623224 _____ (Duplex Secure Ltd.) C:\Users\Toshiba\Desktop\SPTDinst-v186-x64.exe 2014-10-06 14:34 - 2014-10-06 14:34 - 00002762 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2014-10-04 22:32 - 2014-10-04 22:32 - 00002222 _____ () C:\Users\Public\Desktop\AVG Konserwacja 1 kliknięciem.lnk 2014-10-04 22:32 - 2014-10-04 22:32 - 00002192 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2014.lnk 2014-10-04 22:32 - 2014-10-04 22:32 - 00002180 _____ () C:\Users\Public\Desktop\AVG PC TuneUp 2014.lnk 2014-10-04 22:32 - 2014-10-04 22:32 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\AVG 2014-10-04 22:32 - 2014-10-04 22:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2014 2014-10-04 22:32 - 2014-10-04 22:32 - 00000000 ____D () C:\Program Files (x86)\AVG 2014-10-04 22:32 - 2014-03-22 22:09 - 00040248 _____ (AVG) C:\Windows\system32\TURegOpt.exe 2014-10-04 22:32 - 2014-03-22 22:09 - 00029496 _____ (AVG) C:\Windows\system32\authuitu.dll 2014-10-04 22:32 - 2014-03-22 22:09 - 00025400 _____ (AVG) C:\Windows\SysWOW64\authuitu.dll 2014-10-04 22:31 - 2014-10-04 23:26 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\vlc 2014-10-04 22:30 - 2014-10-04 22:30 - 00001011 _____ () C:\Users\Toshiba\Desktop\NapiProjekt.lnk 2014-10-04 22:30 - 2014-10-04 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt 2014-10-04 22:30 - 2014-10-04 22:30 - 00000000 ____D () C:\Program Files (x86)\NapiProjekt 2014-10-04 22:29 - 2014-10-04 22:29 - 24658468 _____ () C:\Users\Toshiba\Downloads\vlc-2.1.5-win64.exe 2014-10-04 22:29 - 2014-10-04 22:29 - 00000878 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-10-04 22:29 - 2014-10-04 22:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2014-10-04 22:29 - 2014-10-04 22:29 - 00000000 ____D () C:\Program Files\VideoLAN 2014-10-04 22:28 - 2014-10-04 22:28 - 00753704 _____ ( ) C:\Users\Toshiba\Desktop\pobierz_vlc-2.1.5-win64.exe 2014-10-04 22:26 - 2014-10-04 22:26 - 09989013 _____ ( ) C:\Users\Toshiba\Downloads\NapiProjektBuild_2.2.0.2399.exe 2014-10-04 22:26 - 2014-10-04 22:26 - 00753704 _____ ( ) C:\Users\Toshiba\Desktop\pobierz-NapiProjektBuild_2.2.0.2399.exe 2014-10-04 22:26 - 2014-10-04 22:26 - 00747456 _____ ( ) C:\Users\Toshiba\Desktop\Niepotwierdzony 126793.crdownload 2014-10-03 10:35 - 2014-10-03 10:35 - 540073488 _____ () C:\Windows\MEMORY.DMP 2014-10-03 10:35 - 2014-10-03 10:35 - 00290944 _____ () C:\Windows\Minidump\100314-25677-01.dmp 2014-09-30 20:40 - 2014-09-30 20:40 - 00290952 _____ () C:\Windows\Minidump\093014-20732-01.dmp 2014-09-30 18:55 - 2014-09-30 18:55 - 00000000 ____D () C:\Users\Toshiba\Desktop\Nowy folder 2014-09-30 18:52 - 2014-09-20 09:30 - 00000388 _____ () C:\Users\Toshiba\Desktop\instalacja składów fifa 14.txt 2014-09-30 18:52 - 2014-09-20 09:24 - 03292580 _____ () C:\Users\Toshiba\Desktop\Squads 20140920092436#Sklady DeMo and ikerek1111 2014-09-28 18:14 - 2014-08-10 20:25 - 240268907 _____ (PesCups.Ru ) C:\Users\Toshiba\Desktop\FIFA14Update7.1.exe 2014-09-28 17:10 - 2014-09-02 18:20 - 00000000 ____D () C:\Users\Toshiba\Desktop\trf.02.09.2014 2014-09-28 17:07 - 2014-09-28 18:13 - 240268990 _____ () C:\Users\Toshiba\Desktop\FIFA 14-Update v. 7.1 by PesCups.Ru.rar 2014-09-28 16:56 - 2014-09-12 00:37 - 00000000 ____D () C:\Users\Toshiba\Desktop\Squads+fix 2014-09-28 16:55 - 2014-09-28 16:55 - 06537320 _____ () C:\Users\Toshiba\Desktop\Squads+fix5^itsVario.com.rar 2014-09-17 16:45 - 2014-10-06 14:04 - 00001368 _____ () C:\Users\Toshiba\Desktop\Wyczyść rejestr za darmo!.lnk 2014-09-16 21:38 - 2014-09-16 21:38 - 00000000 ____D () C:\Users\Toshiba\restore 2014-09-16 20:11 - 2014-09-16 21:04 - 00000000 ____D () C:\Users\Toshiba\Desktop\djęcia 2014-09-16 19:53 - 2014-10-12 18:33 - 00000000 ____D () C:\ProgramData\tmp 2014-09-16 19:53 - 2014-09-23 17:05 - 00000000 ____D () C:\ProgramData\hps 2014-09-16 19:52 - 2014-09-16 19:52 - 00001279 _____ () C:\Users\Public\Desktop\Moja cewe fotoksiazka.lnk 2014-09-16 19:52 - 2014-09-16 19:52 - 00001264 _____ () C:\Users\Public\Desktop\CEWE-Podglad Zdjec.lnk 2014-09-16 19:52 - 2014-09-16 19:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Moja cewe fotoksiazka 2014-09-16 19:48 - 2014-09-16 19:48 - 00000000 ____D () C:\Program Files (x86)\CeWe Color 2014-09-16 19:47 - 2014-09-16 19:47 - 01639888 _____ () C:\Users\Toshiba\Desktop\setup_Moja_cewe_fotoksiazka.exe 2014-09-15 15:24 - 2014-09-15 15:24 - 02953056 _____ () C:\Users\Toshiba\Desktop\Semestr 1415 Zimowy.zip ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-13 15:20 - 2009-09-23 10:54 - 00000000 ____D () C:\Program Files (x86)\Java 2014-10-13 15:19 - 2009-07-14 06:45 - 00016304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-13 15:19 - 2009-07-14 06:45 - 00016304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-13 15:18 - 2014-06-16 14:18 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\DM 2014-10-13 15:17 - 2014-08-18 12:15 - 00000000 ____D () C:\Support 2014-10-13 15:16 - 2010-12-08 17:12 - 01351350 _____ () C:\Windows\WindowsUpdate.log 2014-10-13 15:15 - 2013-10-15 14:32 - 00000000 ____D () C:\ProgramData\Origin 2014-10-13 15:10 - 2011-10-06 20:17 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\ipla 2014-10-13 15:08 - 2014-08-18 12:14 - 00000008 __RSH () C:\ProgramData\ntuser.pol 2014-10-13 15:07 - 2009-09-23 11:03 - 01775796 _____ () C:\Windows\PFRO.log 2014-10-13 15:07 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-13 15:07 - 2009-07-14 06:51 - 00205457 _____ () C:\Windows\setupact.log 2014-10-13 14:59 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-10-13 14:57 - 2014-04-08 19:32 - 00001344 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-10-13 14:57 - 2014-04-08 19:32 - 00001332 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-10-13 14:57 - 2012-05-24 10:56 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-13 14:57 - 2012-02-06 14:24 - 00002610 _____ () C:\Users\Toshiba\Desktop\Google Chrome.lnk 2014-10-13 14:57 - 2012-02-06 14:24 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-10-13 14:57 - 2010-12-08 17:42 - 00001668 _____ () C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-10-13 14:57 - 2010-12-08 17:42 - 00001642 _____ () C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-10-12 21:40 - 2013-10-15 14:37 - 00000000 ____D () C:\Users\Toshiba\Documents\FIFA 14 2014-10-12 21:12 - 2009-07-14 07:08 - 00032594 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-10-12 18:23 - 2010-12-25 17:41 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\CrashDumps 2014-10-12 18:16 - 2010-12-08 17:38 - 00000000 ____D () C:\Users\Toshiba 2014-10-09 10:26 - 2010-12-08 17:47 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\Google 2014-10-06 14:05 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-10-05 21:59 - 2012-10-03 13:32 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\BitTorrent 2014-10-05 17:12 - 2013-06-09 10:38 - 01450980 _____ () C:\Windows\SysWOW64\debug.log 2014-10-04 22:31 - 2014-04-05 18:17 - 00000000 __SHD () C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} 2014-10-04 22:25 - 2012-06-04 16:20 - 00000000 ____D () C:\Program Files (x86)\VideoLAN 2014-10-04 22:24 - 2010-12-24 17:16 - 00000000 ____D () C:\Program Files (x86)\NAPI-PROJEKT 2014-10-03 10:35 - 2012-10-27 17:21 - 00000000 ____D () C:\Windows\Minidump 2014-09-26 18:10 - 2014-06-16 14:20 - 00003880 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1402921238 2014-09-26 18:10 - 2014-06-16 14:20 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-09-26 18:09 - 2012-05-24 10:56 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-09-26 18:09 - 2012-05-24 10:56 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-09-26 18:09 - 2011-12-20 23:51 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-09-23 20:35 - 2012-04-16 09:00 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-09-16 19:44 - 2014-01-03 14:48 - 00000000 ____D () C:\Users\Toshiba\Desktop\film-sob 2014-09-15 21:22 - 2013-03-24 21:42 - 00003352 _____ () C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2754264385-1261652437-1540506145-1000 2014-09-15 21:22 - 2013-03-24 21:42 - 00003222 _____ () C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2754264385-1261652437-1540506145-1000 2014-09-14 08:57 - 2009-07-14 06:45 - 00520520 _____ () C:\Windows\system32\FNTCACHE.DAT Some content of TEMP: ==================== C:\Users\Toshiba\AppData\Local\Temp\bi_cleaner.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-02 11:46 ==================== End Of Log ============================