Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-03-2015 Ran by Joanna (administrator) on LENOVO-PC on 03-03-2015 10:44:39 Running from C:\Users\Joanna\Downloads Loaded Profiles: Joanna (Available profiles: Joanna) Platform: Windows 8.1 Connected (X64) OS Language: Polski (Polska) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (AMD) C:\Windows\System32\atiesrxx.exe (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe () C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe (Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe (Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17031_none_fa50b3979b1bcb4a\TiWorker.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (Realtek semiconductor) C:\Windows\RTFTrack.exe (Lenovo) C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe () C:\Program Files\Lenovo\iMController\AutoUpdate.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] () HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-04] (Conexant Systems, Inc.) HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [216064 2014-01-06] (Realtek Semiconductor Corporation) HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [6340312 2014-02-27] (Realtek semiconductor) HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-10-20] (Lenovo) HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-10-20] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2014-10-20] (Lenovo(beijing) Limited) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-04-18] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-03-02] (AVAST Software) HKU\S-1-5-21-4029550288-3409309739-2083469317-1002\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [457728 2014-03-18] (Microsoft Corporation) ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll (Hightail Inc.) ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll (Hightail Inc.) ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll (Hightail Inc.) ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll (Hightail Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll (Hightail Inc.) ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll (Hightail Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-4029550288-3409309739-2083469317-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-4029550288-3409309739-2083469317-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB HKU\S-1-5-21-4029550288-3409309739-2083469317-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com HKU\S-1-5-21-4029550288-3409309739-2083469317-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com SearchScopes: HKU\S-1-5-21-4029550288-3409309739-2083469317-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms} SearchScopes: HKU\S-1-5-21-4029550288-3409309739-2083469317-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms} BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 62.21.99.94 62.21.99.95 FireFox: ======== FF ProfilePath: C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\as1vn4mx.default-1425375000444 FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-03-02] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-18] (Advanced Micro Devices, Inc.) [File not signed] R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-03-02] (AVAST Software) R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [84992 2014-01-22] () [File not signed] R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo) R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-21] (LENOVO INCORPORATED.) R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-10-20] (Lenovo(beijing) Limited) S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1663880 2014-05-06] () R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [38896 2014-02-17] (Lenovo(beijing) Limited) R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-10-20] (Lenovo) S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2014-10-20] (Lenovo) R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] () R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1026432 2015-03-02] (Enigma Software Group USA, LLC.) R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51712 2014-02-24] (Advanced Micro Devices, Inc.) R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-10-20] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) S2 0094501425373793mcinstcleanup; C:\Users\Joanna\AppData\Local\Temp\009450~1.EXE -cleanup -nolog [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [85704 2014-02-24] (Advanced Micro Devices, Inc. ) R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-12] (Advanced Micro Devices, Inc.) R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [230088 2014-02-24] (Advanced Micro Devices, Inc. ) R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [224992 2013-11-01] (AppEx Networks Corporation) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-03-02] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [87912 2015-03-02] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-03-02] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-03-02] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-03-02] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-03-02] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-03-02] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-03-02] () R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation) S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider) S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-03-02] () S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation) R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-04-15] (Realtek Semiconductor Corporation) R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [9109720 2014-02-27] (Realtek Semiconductor Corp.) R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3410136 2014-04-11] (Realtek Semiconductor Corporation ) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-03 10:40 - 2015-03-03 10:40 - 00012782 _____ () C:\WINDOWS\PFRO.log 2015-03-03 10:32 - 2015-03-03 10:32 - 00000605 _____ () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRST.lnk 2015-03-03 10:30 - 2015-03-03 10:30 - 00000000 ____D () C:\Users\Joanna\Desktop\Stare dane programu Firefox 2015-03-02 21:15 - 2015-03-03 10:39 - 01281579 _____ () C:\WINDOWS\WindowsUpdate.log 2015-03-02 20:55 - 2015-03-03 10:11 - 00000784 _____ () C:\WINDOWS\setupact.log 2015-03-02 20:55 - 2015-03-02 20:55 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2015-03-02 20:55 - 2015-03-02 20:55 - 00000000 _____ () C:\WINDOWS\setuperr.log 2015-03-02 20:03 - 2015-03-02 20:03 - 00031095 _____ () C:\Users\Joanna\Downloads\Shortcut.txt 2015-03-02 20:00 - 2015-03-02 20:03 - 00020596 _____ () C:\Users\Joanna\Downloads\Addition.txt 2015-03-02 19:57 - 2015-03-03 10:44 - 00014637 _____ () C:\Users\Joanna\Downloads\FRST.txt 2015-03-02 19:56 - 2015-03-03 10:44 - 00000000 ____D () C:\FRST 2015-03-02 19:55 - 2015-03-02 19:55 - 02092544 _____ (Farbar) C:\Users\Joanna\Downloads\FRST64.exe 2015-03-02 19:21 - 2015-03-02 19:22 - 00000000 ____D () C:\ProgramData\RpData 2015-03-02 19:21 - 2015-03-02 19:21 - 00000000 ____D () C:\Users\Public\Documents\Baidu 2015-03-02 19:21 - 2015-03-02 19:21 - 00000000 ____D () C:\ProgramData\Baidu 2015-03-02 17:49 - 2015-03-02 17:49 - 00000000 _____ () C:\autoexec.bat 2015-03-02 17:48 - 2015-03-02 17:48 - 00003332 _____ () C:\WINDOWS\System32\Tasks\SpyHunter4Startup 2015-03-02 17:48 - 2015-03-02 17:48 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\Enigma Software Group 2015-03-02 17:47 - 2015-03-02 17:48 - 00000000 ____D () C:\sh4ldr 2015-03-02 17:46 - 2015-03-02 17:46 - 00022704 _____ () C:\WINDOWS\system32\Drivers\EsgScanner.sys 2015-03-02 17:46 - 2015-03-02 17:46 - 00000000 ____D () C:\Program Files\Enigma Software Group 2015-03-02 16:44 - 2015-03-02 16:44 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\AVAST Software 2015-03-02 16:34 - 2015-03-02 16:34 - 00001991 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-03-02 16:34 - 2015-03-02 16:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2015-03-02 16:32 - 2015-03-02 16:33 - 01050432 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys 2015-03-02 16:32 - 2015-03-02 16:33 - 00087912 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys 2015-03-02 16:32 - 2015-03-02 16:32 - 00436624 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2015-03-02 16:32 - 2015-03-02 16:32 - 00364512 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2015-03-02 16:32 - 2015-03-02 16:32 - 00267632 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys 2015-03-02 16:32 - 2015-03-02 16:32 - 00116728 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys 2015-03-02 16:32 - 2015-03-02 16:32 - 00093568 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2015-03-02 16:32 - 2015-03-02 16:32 - 00065776 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys 2015-03-02 16:32 - 2015-03-02 16:32 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr 2015-03-02 16:32 - 2015-03-02 16:32 - 00029208 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys 2015-03-02 16:32 - 2015-03-02 16:32 - 00003924 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update 2015-03-02 16:30 - 2015-03-02 16:30 - 00000000 ____D () C:\Program Files\AVAST Software 2015-03-02 16:28 - 2015-03-02 16:30 - 00000000 ____D () C:\ProgramData\AVAST Software 2015-03-02 16:28 - 2015-03-02 16:28 - 05006864 _____ (AVAST Software) C:\Users\Joanna\Downloads\avast_free_antivirus_setup_online.exe 2015-03-02 15:44 - 2015-03-02 15:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-03-02 13:37 - 2015-03-02 13:37 - 00000000 ____D () C:\Users\Joanna\Documents\efile-backup 2015-03-02 13:03 - 2015-03-02 13:31 - 00000000 ____D () C:\Users\Joanna\Documents\efile 2015-03-02 13:03 - 2015-03-02 13:03 - 00003986 _____ () C:\WINDOWS\System32\Tasks\e-pity2015_styczen 2015-03-02 13:03 - 2015-03-02 13:03 - 00003986 _____ () C:\WINDOWS\System32\Tasks\e-pity2015_kwiecien 2015-03-02 13:03 - 2015-03-02 13:03 - 00001212 _____ () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\e-pity 2014 - program, pity roczne, e-deklaracje.lnk 2015-03-02 13:03 - 2015-03-02 13:03 - 00001182 _____ () C:\Users\Joanna\Desktop\e-pity 2014 - program, pity roczne, e-deklaracje.lnk 2015-03-02 13:03 - 2015-03-02 13:03 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\com.efile.epity2014 2015-03-02 13:03 - 2015-03-02 13:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-pity 2015-03-02 13:02 - 2015-03-02 13:02 - 23395608 _____ (e-file sp. z o.o. ) C:\Users\Joanna\Desktop\setup_e-pity2014.exe 2015-03-02 13:02 - 2015-03-02 13:02 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\fillUp 2015-03-02 13:02 - 2015-03-02 13:02 - 00000000 ____D () C:\Program Files (x86)\e-file 2015-03-02 11:38 - 2015-03-02 11:38 - 00000000 ____D () C:\Users\Joanna\AppData\Local\CyberLink 2015-03-02 11:37 - 2015-03-03 10:42 - 00072704 ___SH () C:\Users\Joanna\Desktop\Thumbs.db 2015-03-02 10:48 - 2014-11-10 00:19 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2015-03-02 10:48 - 2014-11-10 00:19 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2015-03-02 10:48 - 2014-11-10 00:18 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll 2015-03-02 10:48 - 2014-11-10 00:18 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll 2015-03-02 10:48 - 2014-09-10 07:25 - 00474432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys 2015-03-02 10:48 - 2014-09-08 04:07 - 02497344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2015-03-02 10:48 - 2014-09-08 04:07 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 2015-03-02 10:48 - 2014-09-07 23:08 - 00389176 _____ () C:\WINDOWS\system32\ApnDatabase.xml 2015-03-02 10:48 - 2014-09-04 23:30 - 00822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2015-03-02 10:48 - 2014-09-04 23:21 - 01053184 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2015-03-02 10:48 - 2014-09-04 04:15 - 00561416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2015-03-02 10:48 - 2014-09-04 04:14 - 00177472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2015-03-02 10:48 - 2014-09-04 04:05 - 00836176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2015-03-02 10:48 - 2014-09-04 03:22 - 00670384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2015-03-02 10:48 - 2014-09-04 02:19 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2015-03-02 10:48 - 2014-09-04 02:01 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll 2015-03-02 10:48 - 2014-09-04 01:45 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2015-03-02 10:48 - 2014-09-04 01:41 - 01420288 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2015-03-02 10:48 - 2014-09-04 01:36 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2015-03-02 10:48 - 2014-09-04 01:32 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll 2015-03-02 10:48 - 2014-09-04 01:15 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2015-03-02 10:48 - 2014-09-04 01:10 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll 2015-03-02 10:48 - 2014-09-04 00:57 - 00921600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2015-03-02 10:48 - 2014-09-04 00:49 - 00626688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2015-03-02 10:48 - 2014-08-31 01:17 - 00148800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS 2015-03-02 10:48 - 2014-08-31 01:15 - 21197152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2015-03-02 10:48 - 2014-08-30 23:59 - 18723112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2015-03-02 10:48 - 2014-08-30 23:05 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll 2015-03-02 10:48 - 2014-08-30 22:58 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSAPI.dll 2015-03-02 10:48 - 2014-08-30 22:04 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2015-03-02 10:48 - 2014-08-30 21:53 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSAPI.dll 2015-03-02 10:48 - 2014-08-30 21:17 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2015-03-02 10:48 - 2014-08-28 03:55 - 07484224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2015-03-02 10:48 - 2014-08-28 01:21 - 02480128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 2015-03-02 10:48 - 2014-08-28 01:06 - 02030592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll 2015-03-02 10:48 - 2014-08-23 06:14 - 13424128 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2015-03-02 10:48 - 2014-08-23 06:04 - 11820544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2015-03-02 10:48 - 2014-08-23 05:50 - 02714112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll 2015-03-02 10:48 - 2014-08-02 01:51 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll 2015-03-02 10:48 - 2014-08-02 01:35 - 00485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll 2015-03-02 10:48 - 2014-07-24 12:22 - 00308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll 2015-03-02 10:48 - 2014-07-24 10:53 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnntfy.dll 2015-03-02 10:48 - 2014-07-24 10:13 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnntfy.dll 2015-03-02 10:48 - 2014-07-24 09:20 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll 2015-03-02 10:48 - 2014-07-24 09:08 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll 2015-03-02 10:48 - 2014-07-24 08:49 - 00263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll 2015-03-02 10:48 - 2014-07-24 08:43 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll 2015-03-02 10:48 - 2014-05-29 08:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 2015-03-02 10:48 - 2014-05-29 07:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll 2015-03-02 10:48 - 2014-05-13 08:01 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\BulkOperationHost.exe 2015-03-02 10:48 - 2014-03-06 07:27 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll 2015-03-02 10:47 - 2014-07-24 04:20 - 00875688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll 2015-03-02 10:47 - 2014-07-24 04:20 - 00869544 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll 2015-03-02 10:47 - 2014-05-31 11:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2015-03-02 10:47 - 2014-05-31 11:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2015-03-02 10:47 - 2014-05-31 04:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2015-03-02 10:47 - 2014-05-31 04:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2015-03-02 10:47 - 2014-05-31 04:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2015-03-02 10:47 - 2014-05-31 04:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2015-03-02 10:47 - 2014-05-31 03:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2015-03-02 10:47 - 2014-05-31 03:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2015-03-02 10:47 - 2014-05-31 03:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2015-03-02 10:47 - 2014-05-31 03:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2015-03-02 10:47 - 2014-05-31 03:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2015-03-02 10:47 - 2014-05-31 03:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2015-03-02 10:47 - 2014-05-31 03:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2015-03-02 10:47 - 2014-04-11 09:25 - 00419928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2015-03-02 10:47 - 2014-04-11 07:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2015-03-02 10:47 - 2014-04-11 06:53 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe 2015-03-02 10:47 - 2014-04-11 06:22 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2015-02-28 15:04 - 2015-02-28 15:04 - 00000000 ____D () C:\Users\Joanna\AppData\Local\Lenovo 2015-02-28 14:28 - 2015-02-28 14:28 - 00000000 ____D () C:\Users\Joanna\Documents\Fax 2015-02-28 13:08 - 2015-03-02 19:34 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\Skype 2015-02-28 13:08 - 2015-02-28 13:08 - 00000000 ____D () C:\Users\Joanna\AppData\Local\Skype 2015-02-28 13:08 - 2015-02-28 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-02-28 13:07 - 2015-02-28 13:08 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-02-28 13:07 - 2015-02-28 13:08 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-02-28 13:07 - 2015-02-28 13:08 - 00000000 ____D () C:\ProgramData\Skype 2015-02-28 13:06 - 2015-02-28 13:06 - 01548384 _____ (Skype Technologies S.A.) C:\Users\Joanna\Downloads\SkypeSetup.exe 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Public\Documents\Moje wideo 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Public\Documents\Moje obrazy 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Public\Documents\Moja muzyka 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default\Ustawienia lokalne 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default\Szablony 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default\Moje dokumenty 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default\Menu Start 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default\Documents\Moje wideo 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default\Documents\Moje obrazy 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default\Documents\Moja muzyka 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default\Dane aplikacji 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Historia 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Dane aplikacji 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default User\Documents\Moje wideo 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default User\Documents\Moje obrazy 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default User\Documents\Moja muzyka 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Historia 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Dane aplikacji 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\ProgramData\Szablony 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\ProgramData\Pulpit 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programy 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\ProgramData\Menu Start 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\ProgramData\Dokumenty 2015-02-28 00:06 - 2015-02-28 00:06 - 00000000 _SHDL () C:\ProgramData\Dane aplikacji 2015-02-27 22:10 - 2015-02-27 22:10 - 00000000 ____D () C:\Users\Public\Pokki 2015-02-27 22:07 - 2015-02-27 22:07 - 00000000 ____D () C:\Users\Joanna\AppData\Local\Macromedia 2015-02-27 22:03 - 2015-02-28 14:35 - 00000000 ____D () C:\Users\Joanna\AppData\Local\Adobe 2015-02-27 21:54 - 2015-03-02 16:45 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\LSC 2015-02-27 21:54 - 2015-02-27 21:54 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_ldiagio_uefi_01009.Wdf 2015-02-27 21:53 - 2015-02-27 21:54 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\Mozilla 2015-02-27 21:53 - 2015-02-27 21:54 - 00000000 ____D () C:\Users\Joanna\AppData\Local\Mozilla 2015-02-27 21:53 - 2015-02-27 21:53 - 00001186 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-02-27 21:53 - 2015-02-27 21:53 - 00001174 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-02-27 21:53 - 2015-02-27 21:53 - 00000000 ____D () C:\ProgramData\Mozilla 2015-02-27 21:53 - 2015-02-27 21:53 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-02-27 21:53 - 2015-02-27 21:53 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-02-27 21:52 - 2015-02-27 21:52 - 00243496 _____ () C:\Users\Joanna\Downloads\Firefox Setup Stub 36.0 (1).exe 2015-02-27 21:51 - 2015-02-27 21:51 - 00243496 _____ () C:\Users\Joanna\Downloads\Firefox Setup Stub 36.0.exe 2015-02-27 21:50 - 2015-03-03 10:34 - 00003992 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{F6BD3171-94B9-4A48-AED8-7128BAED58F5} 2015-02-27 21:50 - 2015-03-03 10:26 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4029550288-3409309739-2083469317-1002 2015-02-27 21:50 - 2015-02-27 21:50 - 00000000 __SHD () C:\Users\Joanna\AppData\Local\EmieUserList 2015-02-27 21:50 - 2015-02-27 21:50 - 00000000 __SHD () C:\Users\Joanna\AppData\Local\EmieSiteList 2015-02-27 21:48 - 2015-03-03 10:46 - 00000000 __RDO () C:\Users\Joanna\OneDrive 2015-02-27 21:47 - 2015-02-27 21:47 - 00000000 ____D () C:\Users\Joanna\AppData\Local\AMD 2015-02-27 21:46 - 2015-02-27 21:46 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\ATI 2015-02-27 21:46 - 2015-02-27 21:46 - 00000000 ____D () C:\Users\Joanna\AppData\Local\ATI 2015-02-27 21:46 - 2015-02-27 21:46 - 00000000 ____D () C:\ProgramData\ATI 2015-02-27 21:45 - 2015-02-27 22:03 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\Hightail for Lenovo 2015-02-27 21:45 - 2015-02-27 21:45 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo 2015-02-27 21:44 - 2015-03-03 10:41 - 00031075 _____ () C:\Users\Joanna\AppData\Local\BTServer.log 2015-02-27 21:44 - 2015-02-28 14:35 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\Adobe 2015-02-27 21:44 - 2015-02-28 14:17 - 00000000 ____D () C:\Users\Joanna\AppData\Local\Packages 2015-02-27 21:44 - 2015-02-27 21:44 - 00001465 _____ () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-02-27 21:44 - 2015-02-27 21:44 - 00001264 _____ () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BTServer Toasts App.lnk 2015-02-27 21:44 - 2015-02-27 21:44 - 00000000 ____D () C:\Users\Joanna\Documents\My Bluetooth 2015-02-27 21:44 - 2015-02-27 21:44 - 00000000 ____D () C:\Users\Joanna\AppData\Local\VirtualStore 2015-02-27 21:43 - 2015-03-02 17:48 - 00000000 ____D () C:\Users\Joanna 2015-02-27 21:43 - 2015-02-27 21:43 - 00000020 ___SH () C:\Users\Joanna\ntuser.ini 2015-02-27 21:43 - 2015-02-27 21:43 - 00000000 _SHDL () C:\Users\Joanna\Ustawienia lokalne 2015-02-27 21:43 - 2015-02-27 21:43 - 00000000 _SHDL () C:\Users\Joanna\Szablony 2015-02-27 21:43 - 2015-02-27 21:43 - 00000000 _SHDL () C:\Users\Joanna\Moje dokumenty 2015-02-27 21:43 - 2015-02-27 21:43 - 00000000 _SHDL () C:\Users\Joanna\Menu Start 2015-02-27 21:43 - 2015-02-27 21:43 - 00000000 _SHDL () C:\Users\Joanna\Documents\Moje wideo 2015-02-27 21:43 - 2015-02-27 21:43 - 00000000 _SHDL () C:\Users\Joanna\Documents\Moje obrazy 2015-02-27 21:43 - 2015-02-27 21:43 - 00000000 _SHDL () C:\Users\Joanna\Documents\Moja muzyka 2015-02-27 21:43 - 2015-02-27 21:43 - 00000000 _SHDL () C:\Users\Joanna\Dane aplikacji 2015-02-27 21:43 - 2015-02-27 21:43 - 00000000 _SHDL () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2015-02-27 21:43 - 2015-02-27 21:43 - 00000000 _SHDL () C:\Users\Joanna\AppData\Local\Historia 2015-02-27 21:43 - 2015-02-27 21:43 - 00000000 _SHDL () C:\Users\Joanna\AppData\Local\Dane aplikacji 2015-02-27 21:43 - 2014-10-20 20:23 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\Macromedia 2015-02-27 21:43 - 2014-10-20 20:16 - 00000187 _____ () C:\Users\Joanna\Desktop\Google Play Music.url 2015-02-27 21:43 - 2014-10-20 20:16 - 00000126 _____ () C:\Users\Joanna\Desktop\Adobe Photo Offer.url 2015-02-27 21:43 - 2014-03-26 11:21 - 00000190 _____ () C:\Users\Joanna\Desktop\FREE CALLS with Voxox.url 2015-02-27 21:43 - 2014-03-18 11:06 - 00000000 ___RD () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-02-27 21:43 - 2014-03-18 11:06 - 00000000 ___RD () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2015-02-27 21:43 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-02-27 21:43 - 2013-08-22 16:36 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-03 10:41 - 2013-08-22 16:20 - 00000000 ____D () C:\WINDOWS\CbsTemp 2015-03-03 10:41 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-03-03 10:40 - 2014-10-20 20:18 - 00000000 ____D () C:\Program Files\Common Files\McAfee 2015-03-03 10:40 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2015-03-03 10:37 - 2014-10-20 20:27 - 00002560 _____ () C:\WINDOWS\system32\VfService.trf 2015-03-03 10:37 - 2014-10-20 19:43 - 00125358 _____ () C:\Users\Public\CAFADEBUG.log 2015-03-03 10:13 - 2014-10-20 20:18 - 00000000 ____D () C:\ProgramData\McAfee 2015-03-03 10:12 - 2013-08-22 16:36 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP 2015-03-03 10:04 - 2014-10-21 05:18 - 00807160 _____ () C:\WINDOWS\system32\perfh015.dat 2015-03-03 10:04 - 2014-10-21 05:18 - 00163478 _____ () C:\WINDOWS\system32\perfc015.dat 2015-03-03 10:04 - 2014-03-18 10:53 - 01825074 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-03-03 10:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2015-03-02 19:34 - 2014-10-20 20:16 - 00000000 ____D () C:\WINDOWS\Downloaded Installations 2015-03-02 19:24 - 2014-04-02 18:34 - 00000000 ____D () C:\WINDOWS\Panther 2015-03-02 19:23 - 2013-08-22 16:36 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy 2015-03-02 19:23 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\GroupPolicy 2015-03-02 19:09 - 2014-10-20 19:40 - 00264572 _____ () C:\WINDOWS\SysWOW64\rootpa.e2e 2015-03-02 19:05 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2015-03-02 19:05 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel 2015-03-02 19:05 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\MediaViewer 2015-03-02 19:05 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\FileManager 2015-03-02 19:05 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Camera 2015-03-02 16:59 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2015-03-02 16:18 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Performance 2015-03-02 16:17 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\WinStore 2015-03-02 11:37 - 2014-10-20 20:27 - 00000000 ____D () C:\ProgramData\CyberLink 2015-03-02 10:54 - 2014-10-20 20:18 - 00000000 ____D () C:\Program Files (x86)\McAfee 2015-03-02 10:53 - 2014-10-20 20:16 - 00000000 ____D () C:\Program Files (x86)\Lenovo 2015-02-28 14:32 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\restore 2015-02-28 03:35 - 2014-10-20 20:28 - 00009576 _____ () C:\WINDOWS\SysWOW64\VisualDiscovery.ini 2015-02-28 03:35 - 2014-10-20 20:28 - 00004720 _____ () C:\WINDOWS\SysWOW64\VisualDiscoveryOff.ini 2015-02-28 03:35 - 2014-10-20 20:28 - 00004720 _____ () C:\WINDOWS\system32\VisualDiscoveryOff.ini 2015-02-28 03:24 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache 2015-02-28 00:06 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows NT 2015-02-28 00:06 - 2013-08-22 14:36 - 00000000 ___HD () C:\Users\Default 2015-02-28 00:05 - 2013-08-22 15:44 - 00346680 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2015-02-27 21:51 - 2014-10-20 20:16 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Lenovo 2015-02-27 21:50 - 2014-10-20 20:17 - 00000000 ____D () C:\ProgramData\Lenovo 2015-02-27 21:46 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM ==================== Files in the root of some directories ======= 2015-02-27 21:44 - 2015-03-03 10:41 - 0031075 _____ () C:\Users\Joanna\AppData\Local\BTServer.log 2014-10-20 19:42 - 2014-10-20 19:42 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-20 19:23 ==================== End Of Log ============================