Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-05-2013 Ran by SYSTEM on 28-05-2013 23:13:33 Running from E:\ Windows 7 Professional N Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 9 Boot Mode: Recovery The current controlset is ControlSet002 [b]ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.[/b] ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [9962016 2010-01-15] (Realtek Semiconductor) HKLM\...\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4366704 2009-09-01] (Lenovo(beijing) Limited) HKLM\...\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [5825536 2009-08-19] (Lenovo (Beijing) Limited) HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1853736 2009-09-24] (Synaptics Incorporated) Winlogon\Notify\klogon: %SystemRoot%\System32\klogon.dll (Kaspersky Lab ZAO) HKLM-x32\...\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [352976 2013-03-30] (Kaspersky Lab ZAO) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [926896 2012-09-23] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.) HKU\Tomek\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" [399736 2013-03-30] (BitTorrent, Inc.) HKU\Tomek\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3673728 2012-11-06] (DT Soft Ltd) HKU\Tomek\...\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount [75624 2012-01-05] (Alcohol Soft Development Team) HKU\Tomek\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized [14940040 2010-10-11] (Skype Technologies S.A.) HKU\Tomek\...\Winlogon: [Shell] explorer.exe,C:\Users\Tomek\AppData\Roaming\skype.dat [106496 2011-11-17] () <==== ATTENTION AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll,C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll [72376 2010-07-01] (Kaspersky Lab ZAO) Startup: C:\ProgramData\Start Menu\Programs\Startup\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Start Menu\Programs\Startup\CLS 2010.10.lnk ShortcutTarget: CLS 2010.10.lnk -> C:\Windows\Installer\{32941B29-1D13-4237-88AD-90B9A588E7EA}\NewShortcut11.70787B93_F30E_4877_AFB6_34DDA9EE532D.exe (Acresso Software Inc.) Startup: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> (No File) ==================== Services (Whitelisted) ================= S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [352976 2013-03-30] (Kaspersky Lab ZAO) S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) S2 mitsijm2012; C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe [848184 2010-12-08] (Autodesk, Inc.) S2 MSSQL$ECSQLEXPRESS; C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S3 DSO20901; C:\Windows\System32\Drivers\DSO2090AMD641.sys [27952 2010-01-26] (Hantek) S3 DSO20902; C:\Windows\System32\Drivers\DSO2090AMD642.SYS [46256 2010-01-26] (Hantek) S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-03-30] (DT Soft Ltd) S2 Hardlock; C:\Windows\SysWow64\drivers\hardlock.sys [676864 2004-07-14] (Aladdin Knowledge Systems) S3 jlink; C:\Windows\System32\Drivers\jlinkx64.sys [32984 2012-04-12] (SEGGER Microcontroller Systeme GmbH) S0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [460888 2010-06-09] (Kaspersky Lab ZAO) S1 kl2; C:\Windows\System32\DRIVERS\kl2.sys [11864 2010-06-09] (Kaspersky Lab ZAO) S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [556120 2013-03-30] (Kaspersky Lab) S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [27736 2010-04-22] (Kaspersky Lab ZAO) S3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [22544 2009-11-02] (Kaspersky Lab) S3 LVUSBS64; C:\Windows\System32\drivers\LVUSBS64.sys [58400 2007-03-06] (Labtec Inc.) S3 PID_0928; C:\Windows\System32\DRIVERS\LV561V64.SYS [468000 2007-03-06] (Labtec Inc.) S2 Sentinel; C:\Windows\SysWow64\Drivers\SENTINEL.SYS [76288 2009-10-05] (Rainbow Technologies, Inc.) S0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-03-30] (Duplex Secure Ltd.) S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [106256 2013-03-15] (Oracle Corporation) S3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [266752 2012-08-26] (Jungo) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-05-29 00:47 - 2013-05-29 00:47 - 00000000 ____D C:\Windows\Microsoft Antimalware 2013-05-28 23:12 - 2013-05-28 23:12 - 00000000 ____D C:\FRST 2013-05-28 21:18 - 2013-05-28 21:18 - 00000000 __SHD C:\found.000 2013-05-28 17:23 - 2013-05-28 22:06 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0 2013-05-28 11:57 - 2013-05-28 20:32 - 00000004 ____A C:\Users\Tomek\AppData\Roaming\skype.ini 2013-05-28 11:52 - 2013-05-28 11:52 - 00000000 ____D C:\Windows\Sun 2013-05-28 11:49 - 2013-05-28 11:49 - 00000000 ____D C:\Users\Tomek\Qt 2013-05-28 11:41 - 2013-05-28 11:41 - 00000006 ____A C:\Users\Tomek\Downloads\test.qrc 2013-05-28 11:36 - 2013-05-28 11:49 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\QtProject 2013-05-28 10:21 - 2013-05-28 11:02 - 00000000 ____D C:\Qt 2013-05-27 21:42 - 2013-05-27 22:05 - 00000000 ____D C:\Users\Tomek\Downloads\Black.Swan.2010.720p.BRRip.XviD.AC3-ViSiON 2013-05-27 15:13 - 2013-05-27 15:18 - 332706008 ____A C:\Users\Tomek\Downloads\qt-win-opensource-4.8.4-mingw.exe 2013-05-27 15:12 - 2013-05-27 15:12 - 55028400 ____A C:\Users\Tomek\Downloads\qt-creator-windows-opensource-2.7.1.exe 2013-05-25 10:33 - 2013-05-25 10:34 - 00000000 ____D C:\Users\Tomek\Downloads\WebcamViewer V1.0 2013-05-25 10:33 - 2013-05-25 10:33 - 00183327 ____A C:\Users\Tomek\Downloads\WebcamViewer V1.0.zip 2013-05-24 21:59 - 2013-05-24 21:59 - 01430522 ____A (Artur Sikora ) C:\Users\Tomek\Downloads\subedit_b4072_install.exe 2013-05-24 21:57 - 2013-05-24 21:57 - 01297460 ____A ( ) C:\Users\Tomek\Downloads\Napiprojekt 1.0.6.2 (pobiera napisy).exe 2013-05-24 21:57 - 2013-05-24 21:57 - 00000976 ____A C:\Users\Tomek\Desktop\Napi-projekt.lnk 2013-05-24 21:56 - 2013-05-24 21:56 - 00761896 ____A () C:\Users\Tomek\Downloads\napiprojekt_idg_downloader_24476_pc.exe 2013-05-24 21:54 - 2013-05-24 21:55 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\EurekaLog 2013-05-24 21:54 - 2013-05-24 21:54 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\NapiProjekt 2013-05-24 21:48 - 2013-05-24 21:54 - 00000000 ____D C:\Users\Tomek\Downloads\21 Grams (2003) 2013-05-24 11:47 - 2013-05-25 10:35 - 00005729 ____A C:\Windows\System32\lvcoinst.log 2013-05-24 11:47 - 2007-03-06 16:54 - 00527136 ____A (Labtec Inc.) C:\Windows\SysWOW64\LVUI2RC.dll 2013-05-24 11:47 - 2007-03-06 16:54 - 00215840 ____A (Labtec Inc.) C:\Windows\SysWOW64\LVUI2.dll 2013-05-24 11:47 - 2007-03-06 16:52 - 00366368 ____A (Labtec Inc.) C:\Windows\System32\LVUIRC64.dll 2013-05-24 11:47 - 2007-03-06 16:52 - 00139040 ____A (Labtec Inc.) C:\Windows\System32\LVUI64.dll 2013-05-24 11:47 - 2007-03-06 16:52 - 00058400 ____A (Labtec Inc.) C:\Windows\System32\Drivers\LVUSBS64.sys 2013-05-24 11:47 - 2007-03-06 16:50 - 00264992 ____A (Labtec Inc.) C:\Windows\SysWOW64\lvcodec2.dll 2013-05-24 11:47 - 2007-03-06 16:49 - 00309024 ____A (Labtec Inc.) C:\Windows\System32\lvcod64.dll 2013-05-24 11:47 - 2007-03-06 16:49 - 00099104 ____A (Labtec Inc.) C:\Windows\System32\lvco1051.dll 2013-05-24 11:47 - 2007-03-06 16:48 - 00468000 ____A (Labtec Inc.) C:\Windows\System32\Drivers\LV561V64.sys 2013-05-24 11:47 - 2007-03-06 15:03 - 00013398 ____A C:\Windows\System32\Repository.reg 2013-05-24 11:47 - 2007-03-06 15:02 - 00051370 ____A C:\Windows\System32\lvcoin64.ini 2013-05-23 19:55 - 2013-05-23 19:55 - 03729256 ____A (foobar2000.org) C:\Users\Tomek\Downloads\foobar2000_v1.2.6.exe 2013-05-21 17:59 - 2013-05-21 18:06 - 12778981 ____A C:\Users\Tomek\Downloads\DSO2090USB.rar 2013-05-21 17:58 - 2013-05-21 17:58 - 00132130 ____A C:\Users\Tomek\Downloads\DSO2090.zip 2013-05-21 12:18 - 2013-05-21 12:18 - 00040052 ____A C:\Users\Tomek\Desktop\GenericI2C_1.002_19.02.2013.PEupd 2013-05-21 11:43 - 2013-05-21 11:43 - 00027619 ____A C:\Users\Tomek\Desktop\GenericSWI2C_1.002_04.12.2012.PEupd 2013-05-20 18:28 - 2013-05-20 18:29 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\Termite 2013-05-20 18:28 - 2013-05-20 18:28 - 00235695 ____A C:\Users\Tomek\Downloads\termite-3.0.exe 2013-05-20 16:12 - 2013-05-20 16:12 - 00000000 ____D C:\Users\Tomek\workspace - Kopia 2013-05-18 14:37 - 2013-05-18 14:37 - 00000000 ____D C:\Program Files (x86)\SecureW2 2013-05-18 14:34 - 2013-03-04 10:29 - 00718909 ____A C:\Users\Tomek\Downloads\SecureW2_113_W7_Vista_pwr.wroc.pl.exe 2013-05-18 10:36 - 2013-05-18 10:36 - 00000000 ____D C:\Users\Tomek\Desktop\vision_2 (skopiowane w 02) 2013-05-18 10:16 - 2013-05-18 10:16 - 00000000 ____D C:\ProgramData\Reprise 2013-05-18 10:11 - 2013-05-18 10:11 - 00000000 ____D C:\Users\Tomek\.mplabcomm 2013-05-18 10:10 - 2013-05-18 10:10 - 00000000 ____D C:\Users\Tomek\MPLABXProjects 2013-05-18 10:10 - 2013-05-18 10:10 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\.mplab_ide 2013-05-18 10:10 - 2013-05-18 10:10 - 00000000 ____D C:\Users\Tomek\.netbeans 2013-05-18 09:06 - 2013-05-18 09:06 - 00002822 ____A C:\Users\Public\Desktop\MPLAB IPE.lnk 2013-05-18 09:06 - 2012-09-24 16:44 - 00151552 ____A (Microchip Technology, Inc.) C:\Windows\SysWOW64\SerialAccessLink.dll 2013-05-18 09:06 - 2011-08-29 23:36 - 00098304 ____A (Microchip Technology, Inc.) C:\Windows\SysWOW64\mchpwinusbdevice.exe 2013-05-18 09:06 - 2011-07-18 17:34 - 04389441 ____A C:\Windows\SysWOW64\USBAccessLink.dll 2013-05-18 09:06 - 2011-06-22 00:06 - 00000016 ____A C:\Windows\SysWOW64\mchpdefport 2013-05-18 09:05 - 2013-05-18 09:06 - 00002352 ____A C:\Users\Public\Desktop\MPLAB driver switcher.lnk 2013-05-18 09:05 - 2013-05-18 09:06 - 00002288 ____A C:\Users\Public\Desktop\MPLAB X IDE v1.51.lnk 2013-05-18 09:05 - 2012-09-24 16:44 - 00083456 ____A C:\Windows\System32\SerialAccessLink.dll 2013-05-18 09:05 - 2011-10-17 22:32 - 00105472 ____A (Microchip Technology, Inc.) C:\Windows\System32\mchpwinusbdevice64.exe 2013-05-18 09:05 - 2011-10-17 21:47 - 00161792 ____A (Microchip Technology, Inc.) C:\Windows\System32\USBAccessLink.dll 2013-05-18 09:05 - 2011-06-22 00:06 - 00000016 ____A C:\Windows\System32\mchpdefport 2013-05-18 08:57 - 2013-05-18 09:04 - 00000000 ____D C:\Program Files (x86)\Microchip 2013-05-18 08:57 - 2013-05-17 22:41 - 00015374 ____A C:\Users\Tomek\Downloads\Rudy_104v1_1.zip 2013-05-18 08:57 - 2012-11-21 03:24 - 172531921 ____A (Microchip) C:\Users\Tomek\Downloads\xc8-v1_11-win.exe 2013-05-18 08:57 - 2012-11-21 03:20 - 327192220 ____A (Microchip) C:\Users\Tomek\Downloads\mplabx-ide-v1_51-windows-installer.exe 2013-05-18 08:56 - 2013-05-18 08:56 - 00000000 ____D C:\ProgramData\Microchip 2013-05-17 09:54 - 2013-05-17 09:54 - 00000000 ____D C:\Users\Tomek\Downloads\CDM 2.08.28 WHQL Certified 2013-05-17 09:54 - 2013-01-22 13:25 - 00085864 ____A (FTDI Ltd.) C:\Windows\System32\Drivers\ftser2k.sys 2013-05-17 09:54 - 2013-01-22 13:25 - 00076648 ____A (FTDI Ltd.) C:\Windows\System32\Drivers\ftdibus.sys 2013-05-17 09:54 - 2013-01-22 13:25 - 00065896 ____A (FTDI Ltd.) C:\Windows\System32\ftcserco.dll 2013-05-17 09:54 - 2013-01-22 13:25 - 00055656 ____A (FTDI Ltd.) C:\Windows\System32\ftserui2.dll 2013-05-17 09:54 - 2013-01-18 14:54 - 00257384 ____A (FTDI Ltd.) C:\Windows\System32\ftd2xx.dll 2013-05-17 09:54 - 2013-01-18 14:54 - 00219496 ____A (FTDI Ltd.) C:\Windows\SysWOW64\ftd2xx.dll 2013-05-17 09:54 - 2013-01-18 14:54 - 00215400 ____A (FTDI Ltd.) C:\Windows\System32\FTLang.dll 2013-05-17 09:54 - 2013-01-18 14:54 - 00109416 ____A (FTDI Ltd.) C:\Windows\System32\ftbusui.dll 2013-05-17 09:53 - 2013-05-17 09:53 - 01386698 ____A C:\Users\Tomek\Downloads\CDM 2.08.28 WHQL Certified.zip 2013-05-16 19:19 - 2009-07-14 13:21 - 01721576 ____A (Microsoft Corporation) C:\Windows\System32\WdfCoInstaller01009.dll 2013-05-14 16:14 - 2013-05-14 16:14 - 00000000 ____A C:\Users\Tomek\.sam-ba.historysource 2013-05-14 16:13 - 2013-05-14 16:13 - 00000181 ____A C:\Users\Tomek\_sam-ba.rc 2013-05-14 15:09 - 2012-04-12 17:44 - 00032984 ____A (SEGGER Microcontroller Systeme GmbH) C:\Windows\System32\Drivers\jlinkx64.sys 2013-05-14 09:16 - 2013-05-14 09:16 - 00000000 ____D C:\Users\Tomek\Desktop\kis_2011_32 2013-05-14 09:16 - 2012-09-08 00:19 - 00000000 ____D C:\Users\Tomek\Desktop\kis_2011_64 2013-05-14 09:13 - 2013-05-14 09:16 - 00000000 ____D C:\Users\Tomek\Downloads\kis2011_11.0.2.556EN-US+trial_reset_via_registry-x64-x32 2013-05-14 09:12 - 2013-05-14 09:13 - 115701802 ____A C:\Users\Tomek\Downloads\kis2011_11.0.2.556EN-US+trial_reset_via_registry-x64-x32.zip 2013-05-14 09:09 - 2013-05-14 09:09 - 00018686 ____A C:\Users\Tomek\Desktop\KasperskyRestartTrial.reg 2013-05-14 02:15 - 2013-05-21 12:18 - 00000000 ____D C:\ProgramData\Processor Expert 2013-05-14 02:05 - 2013-05-14 02:05 - 00000021 ___SH C:\Windows\WINPROD.DLL 2013-05-14 02:04 - 2013-05-22 11:04 - 00000000 ____D C:\Users\Tomek\.codewarrior 2013-05-14 02:04 - 2013-05-20 02:18 - 00000000 ____D C:\Users\Tomek\workspace 2013-05-14 01:48 - 2013-05-22 01:44 - 00000000 ____D C:\ProgramData\boost_interprocess 2013-05-14 01:43 - 2013-05-20 16:18 - 00000000 ____D C:\Freescale 2013-05-14 01:36 - 2013-05-14 01:41 - 00000000 ____D C:\Users\Tomek\Downloads\CW for MCU10.4 2013-05-13 02:10 - 2012-11-09 12:31 - 00055221 ____A C:\Users\Tomek\Desktop\sterownik liniowy DE.hex 2013-05-07 02:13 - 2013-05-07 02:13 - 00000000 ____D C:\Users\PUR\Desktop\CoSIK 2013-05-07 02:13 - 2013-05-07 02:13 - 00000000 ____D C:\users\PUR 2013-05-06 20:43 - 2013-05-06 20:43 - 00002025 ____A C:\Users\Public\Desktop\SketchUp 8.lnk 2013-05-06 20:43 - 2013-05-06 20:43 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\Google 2013-05-06 20:43 - 2013-05-06 20:43 - 00000000 ____D C:\ProgramData\Google 2013-05-06 20:43 - 2013-05-06 20:43 - 00000000 ____D C:\Program Files (x86)\Google 2013-05-06 20:42 - 2013-05-06 20:42 - 35800192 ____A (Trimble Navigation Limited) C:\Users\Tomek\Downloads\sketchupwen.exe 2013-05-06 09:36 - 2013-05-24 22:00 - 00587952 ____A (Artur Sikora ) C:\Users\Tomek\Downloads\subedit-vistawmppatch.exe 2013-05-06 09:35 - 2013-05-06 09:35 - 02885598 ____A C:\Users\Tomek\Desktop\Film_Scan_1000_Pro_Kinnstuck.wmv 2013-05-06 09:08 - 2013-05-06 09:08 - 00000993 ____A C:\Users\UpdatusUser\Desktop\Texmaker.lnk 2013-05-06 09:08 - 2013-05-06 09:08 - 00000993 ____A C:\Users\Tomek\Desktop\Texmaker.lnk 2013-05-06 09:08 - 2013-05-06 09:08 - 00000000 ____D C:\Program Files (x86)\Texmaker 2013-05-06 08:47 - 2013-05-06 09:06 - 00000308 ____A C:\Users\Tomek\Documents\a.tex 2013-05-06 08:46 - 2013-05-07 02:40 - 00000000 ____D C:\Users\Tomek\Documents\textest 2013-05-06 02:48 - 2013-05-06 02:59 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\xm1 2013-05-06 02:42 - 2013-05-06 02:42 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\MiKTeX 2013-05-06 02:42 - 2013-05-06 02:42 - 00000000 ____D C:\Users\Tomek\AppData\Local\MiKTeX 2013-05-06 02:33 - 2013-05-06 02:33 - 00251469 ____A C:\Users\Tomek\Downloads\Raport_-_schemat_i_projekt_plytki_PCB.rar 2013-05-06 02:29 - 2013-05-06 02:29 - 00000000 ____D C:\ProgramData\MiKTeX 2013-05-06 02:27 - 2013-05-06 02:28 - 00000000 ____D C:\Program Files\MiKTeX 2.9 2013-05-06 02:03 - 2013-05-06 02:07 - 48116012 ____A C:\Users\Tomek\Downloads\texmakerwin32_install.exe 2013-05-06 02:01 - 2013-05-06 02:01 - 163789064 ____A (MiKTeX.org) C:\Users\Tomek\Downloads\basic-miktex-2.9.4813-x64.exe 2013-05-05 16:00 - 2013-05-05 16:00 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WinUSB_01009.Wdf 2013-05-05 15:57 - 2013-05-05 15:57 - 00002324 ____A C:\Users\Public\Desktop\STM32 ST-LINK Utility.lnk 2013-05-05 15:57 - 2013-05-05 15:57 - 00000000 ____D C:\Windows\Downloaded Installations 2013-05-05 15:57 - 2013-05-05 15:57 - 00000000 ____D C:\Program Files (x86)\STMicroelectronics 2013-05-05 15:56 - 2013-05-05 15:56 - 00000000 ____D C:\Users\Tomek\Downloads\stsw-link004(1) 2013-05-05 15:55 - 2013-05-05 15:56 - 23949527 ____A C:\Users\Tomek\Downloads\stsw-link004(1).zip 2013-05-05 15:54 - 2013-05-05 15:55 - 23946194 ____A C:\Users\Tomek\Downloads\stsw-link004.zip 2013-05-05 15:53 - 2009-07-14 06:37 - 01002728 ____A (Microsoft Corporation) C:\Windows\System32\winusbcoinstaller2.dll 2013-05-05 15:52 - 2013-05-05 15:52 - 00000000 ____D C:\Users\Tomek\Downloads\st-link_v2_usbdriver(1) 2013-05-05 15:48 - 2013-05-05 15:52 - 10426328 ____A C:\Users\Tomek\Downloads\st-link_v2_usbdriver(1).zip 2013-05-05 15:45 - 2013-05-05 15:49 - 10408324 ____A C:\Users\Tomek\Downloads\st-link_v2_usbdriver.zip 2013-05-02 15:52 - 2013-05-02 15:52 - 00000000 ____D C:\Users\Tomek\AppData\Local\GHISLER 2013-05-02 15:16 - 2013-05-02 15:33 - 00000000 ____D C:\Users\Tomek\Desktop\Moje 2013-05-02 15:13 - 2013-05-02 15:14 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\GHISLER 2013-05-02 15:13 - 2013-05-02 15:13 - 04329488 ____A (Ghisler Software GmbH) C:\Users\Tomek\Downloads\tcm801x64_[www.programosy.pl].exe 2013-05-02 15:13 - 2013-05-02 15:13 - 00000000 ____D C:\totalcmd 2013-05-02 12:02 - 2013-05-02 12:25 - 00000327 ____A C:\Users\Tomek\Documents\rzut.m 2013-04-30 13:29 - 2013-04-30 13:29 - 00001664 ____A C:\Users\Tomek\Desktop\krecz.txt 2013-04-29 23:43 - 2013-04-29 23:43 - 01155785 ____A C:\Users\Tomek\Downloads\Trial Reset Kaspersky_2011.rar 2013-04-29 23:43 - 2013-04-29 23:43 - 00000000 ____D C:\Users\Tomek\Downloads\Trial Reset Kaspersky_2011 ==================== One Month Modified Files and Folders ======= 2013-05-29 00:47 - 2013-05-29 00:47 - 00000000 ____D C:\Windows\Microsoft Antimalware 2013-05-28 23:12 - 2013-05-28 23:12 - 00000000 ____D C:\FRST 2013-05-28 22:06 - 2013-05-28 17:23 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0 2013-05-28 21:18 - 2013-05-28 21:18 - 00000000 __SHD C:\found.000 2013-05-28 20:37 - 2013-03-30 10:04 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-05-28 20:37 - 2013-03-30 10:01 - 00000000 ____D C:\ProgramData\NVIDIA 2013-05-28 20:37 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-05-28 20:37 - 2009-07-14 05:56 - 00032028 ____A C:\Windows\setupact.log 2013-05-28 20:36 - 2013-03-30 09:45 - 01204926 ____A C:\Windows\WindowsUpdate.log 2013-05-28 20:36 - 2009-07-14 05:50 - 00020144 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-05-28 20:36 - 2009-07-14 05:50 - 00020144 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-05-28 20:32 - 2013-05-28 11:57 - 00000004 ____A C:\Users\Tomek\AppData\Roaming\skype.ini 2013-05-28 20:32 - 2013-03-30 10:09 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\uTorrent 2013-05-28 20:32 - 2013-03-30 09:53 - 00000089 ____A C:\AtmApInit.txt 2013-05-28 20:27 - 2011-04-12 13:11 - 00788286 ____A C:\Windows\System32\perfh015.dat 2013-05-28 20:27 - 2011-04-12 13:11 - 00173904 ____A C:\Windows\System32\perfc015.dat 2013-05-28 20:27 - 2009-07-14 06:12 - 01803982 ____A C:\Windows\System32\PerfStringBackup.INI 2013-05-28 12:09 - 2013-03-30 23:11 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\Skype 2013-05-28 11:52 - 2013-05-28 11:52 - 00000000 ____D C:\Windows\Sun 2013-05-28 11:49 - 2013-05-28 11:49 - 00000000 ____D C:\Users\Tomek\Qt 2013-05-28 11:49 - 2013-05-28 11:36 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\QtProject 2013-05-28 11:49 - 2013-03-30 09:45 - 00000000 ____D C:\users\Tomek 2013-05-28 11:41 - 2013-05-28 11:41 - 00000006 ____A C:\Users\Tomek\Downloads\test.qrc 2013-05-28 11:02 - 2013-05-28 10:21 - 00000000 ____D C:\Qt 2013-05-28 10:10 - 2013-03-30 10:20 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\Dropbox 2013-05-27 22:05 - 2013-05-27 21:42 - 00000000 ____D C:\Users\Tomek\Downloads\Black.Swan.2010.720p.BRRip.XviD.AC3-ViSiON 2013-05-27 21:31 - 2013-04-12 01:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-05-27 15:18 - 2013-05-27 15:13 - 332706008 ____A C:\Users\Tomek\Downloads\qt-win-opensource-4.8.4-mingw.exe 2013-05-27 15:12 - 2013-05-27 15:12 - 55028400 ____A C:\Users\Tomek\Downloads\qt-creator-windows-opensource-2.7.1.exe 2013-05-26 01:27 - 2013-04-04 19:14 - 00000000 __RAD C:\Users\Tomek\Dropbox 2013-05-25 10:43 - 2013-04-19 20:50 - 00000000 ____D C:\Program Files (x86)\Termite 2013-05-25 10:35 - 2013-05-24 11:47 - 00005729 ____A C:\Windows\System32\lvcoinst.log 2013-05-25 10:34 - 2013-05-25 10:33 - 00000000 ____D C:\Users\Tomek\Downloads\WebcamViewer V1.0 2013-05-25 10:33 - 2013-05-25 10:33 - 00183327 ____A C:\Users\Tomek\Downloads\WebcamViewer V1.0.zip 2013-05-24 22:00 - 2013-05-06 09:36 - 00587952 ____A (Artur Sikora ) C:\Users\Tomek\Downloads\subedit-vistawmppatch.exe 2013-05-24 22:00 - 2013-03-30 10:10 - 00001126 ____A C:\Users\Tomek\Desktop\SubEdit-Player.lnk 2013-05-24 22:00 - 2013-03-30 10:10 - 00000000 ____D C:\Program Files (x86)\SubEdit-Player 2013-05-24 21:59 - 2013-05-24 21:59 - 01430522 ____A (Artur Sikora ) C:\Users\Tomek\Downloads\subedit_b4072_install.exe 2013-05-24 21:58 - 2013-03-30 10:15 - 00000000 ____D C:\Program Files (x86)\NapiProjekt 2013-05-24 21:57 - 2013-05-24 21:57 - 01297460 ____A ( ) C:\Users\Tomek\Downloads\Napiprojekt 1.0.6.2 (pobiera napisy).exe 2013-05-24 21:57 - 2013-05-24 21:57 - 00000976 ____A C:\Users\Tomek\Desktop\Napi-projekt.lnk 2013-05-24 21:56 - 2013-05-24 21:56 - 00761896 ____A () C:\Users\Tomek\Downloads\napiprojekt_idg_downloader_24476_pc.exe 2013-05-24 21:55 - 2013-05-24 21:54 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\EurekaLog 2013-05-24 21:54 - 2013-05-24 21:54 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\NapiProjekt 2013-05-24 21:54 - 2013-05-24 21:48 - 00000000 ____D C:\Users\Tomek\Downloads\21 Grams (2003) 2013-05-24 18:40 - 2013-03-30 12:11 - 00000000 ____D C:\Users\Tomek\Documents\Corel 2013-05-24 01:58 - 2013-04-17 05:58 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\foobar2000 2013-05-23 19:55 - 2013-05-23 19:55 - 03729256 ____A (foobar2000.org) C:\Users\Tomek\Downloads\foobar2000_v1.2.6.exe 2013-05-23 19:55 - 2013-04-17 05:58 - 00001035 ____A C:\Users\Public\Desktop\foobar2000.lnk 2013-05-23 19:55 - 2013-04-17 05:58 - 00000000 ____D C:\Program Files (x86)\foobar2000 2013-05-23 19:55 - 2013-03-30 10:41 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\AIMP3 2013-05-23 03:16 - 2013-03-30 10:37 - 01821784 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2013-05-22 11:04 - 2013-05-14 02:04 - 00000000 ____D C:\Users\Tomek\.codewarrior 2013-05-22 01:44 - 2013-05-14 01:48 - 00000000 ____D C:\ProgramData\boost_interprocess 2013-05-21 18:06 - 2013-05-21 17:59 - 12778981 ____A C:\Users\Tomek\Downloads\DSO2090USB.rar 2013-05-21 17:58 - 2013-05-21 17:58 - 00132130 ____A C:\Users\Tomek\Downloads\DSO2090.zip 2013-05-21 12:18 - 2013-05-21 12:18 - 00040052 ____A C:\Users\Tomek\Desktop\GenericI2C_1.002_19.02.2013.PEupd 2013-05-21 12:18 - 2013-05-14 02:15 - 00000000 ____D C:\ProgramData\Processor Expert 2013-05-21 11:43 - 2013-05-21 11:43 - 00027619 ____A C:\Users\Tomek\Desktop\GenericSWI2C_1.002_04.12.2012.PEupd 2013-05-20 18:29 - 2013-05-20 18:28 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\Termite 2013-05-20 18:28 - 2013-05-20 18:28 - 00235695 ____A C:\Users\Tomek\Downloads\termite-3.0.exe 2013-05-20 16:41 - 2013-03-30 10:43 - 00007594 ____A C:\Users\Tomek\AppData\Local\Resmon.ResmonCfg 2013-05-20 16:32 - 2013-03-30 09:50 - 00138612 ____A C:\Windows\DPINST.LOG 2013-05-20 16:18 - 2013-05-14 01:43 - 00000000 ____D C:\Freescale 2013-05-20 16:12 - 2013-05-20 16:12 - 00000000 ____D C:\Users\Tomek\workspace - Kopia 2013-05-20 15:40 - 2009-07-14 06:38 - 00000000 ____D C:\Windows\System32\FxsTmp 2013-05-20 02:18 - 2013-05-14 02:04 - 00000000 ____D C:\Users\Tomek\workspace 2013-05-18 14:37 - 2013-05-18 14:37 - 00000000 ____D C:\Program Files (x86)\SecureW2 2013-05-18 14:37 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\tracing 2013-05-18 12:46 - 2013-03-30 09:51 - 00000000 ____D C:\Users\Tomek\Documents\Bluetooth Exchange Folder 2013-05-18 10:36 - 2013-05-18 10:36 - 00000000 ____D C:\Users\Tomek\Desktop\vision_2 (skopiowane w 02) 2013-05-18 10:16 - 2013-05-18 10:16 - 00000000 ____D C:\ProgramData\Reprise 2013-05-18 10:11 - 2013-05-18 10:11 - 00000000 ____D C:\Users\Tomek\.mplabcomm 2013-05-18 10:10 - 2013-05-18 10:10 - 00000000 ____D C:\Users\Tomek\MPLABXProjects 2013-05-18 10:10 - 2013-05-18 10:10 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\.mplab_ide 2013-05-18 10:10 - 2013-05-18 10:10 - 00000000 ____D C:\Users\Tomek\.netbeans 2013-05-18 09:06 - 2013-05-18 09:06 - 00002822 ____A C:\Users\Public\Desktop\MPLAB IPE.lnk 2013-05-18 09:06 - 2013-05-18 09:05 - 00002352 ____A C:\Users\Public\Desktop\MPLAB driver switcher.lnk 2013-05-18 09:06 - 2013-05-18 09:05 - 00002288 ____A C:\Users\Public\Desktop\MPLAB X IDE v1.51.lnk 2013-05-18 09:04 - 2013-05-18 08:57 - 00000000 ____D C:\Program Files (x86)\Microchip 2013-05-18 08:56 - 2013-05-18 08:56 - 00000000 ____D C:\ProgramData\Microchip 2013-05-17 22:41 - 2013-05-18 08:57 - 00015374 ____A C:\Users\Tomek\Downloads\Rudy_104v1_1.zip 2013-05-17 09:54 - 2013-05-17 09:54 - 00000000 ____D C:\Users\Tomek\Downloads\CDM 2.08.28 WHQL Certified 2013-05-17 09:53 - 2013-05-17 09:53 - 01386698 ____A C:\Users\Tomek\Downloads\CDM 2.08.28 WHQL Certified.zip 2013-05-14 16:14 - 2013-05-14 16:14 - 00000000 ____A C:\Users\Tomek\.sam-ba.historysource 2013-05-14 16:13 - 2013-05-14 16:13 - 00000181 ____A C:\Users\Tomek\_sam-ba.rc 2013-05-14 16:04 - 2013-03-30 10:42 - 00000000 ____D C:\Program Files (x86)\Atmel 2013-05-14 15:17 - 2013-04-05 10:42 - 00000000 ____D C:\Program Files (x86)\SEGGER 2013-05-14 15:09 - 2013-03-30 09:53 - 00000000 ____D C:\Program Files\DIFX 2013-05-14 14:52 - 2013-04-02 21:53 - 00000000 ____D C:\Users\Tomek\Documents\takietam 2013-05-14 09:32 - 2013-04-08 20:47 - 00000000 ____D C:\Users\Tomek\.VirtualBox 2013-05-14 09:16 - 2013-05-14 09:16 - 00000000 ____D C:\Users\Tomek\Desktop\kis_2011_32 2013-05-14 09:16 - 2013-05-14 09:13 - 00000000 ____D C:\Users\Tomek\Downloads\kis2011_11.0.2.556EN-US+trial_reset_via_registry-x64-x32 2013-05-14 09:13 - 2013-05-14 09:12 - 115701802 ____A C:\Users\Tomek\Downloads\kis2011_11.0.2.556EN-US+trial_reset_via_registry-x64-x32.zip 2013-05-14 09:09 - 2013-05-14 09:09 - 00018686 ____A C:\Users\Tomek\Desktop\KasperskyRestartTrial.reg 2013-05-14 02:05 - 2013-05-14 02:05 - 00000021 ___SH C:\Windows\WINPROD.DLL 2013-05-14 02:03 - 2013-04-19 20:11 - 00000000 ____D C:\PEMicro 2013-05-14 01:41 - 2013-05-14 01:36 - 00000000 ____D C:\Users\Tomek\Downloads\CW for MCU10.4 2013-05-13 02:05 - 2013-03-31 22:48 - 00000000 ____D C:\Users\Tomek\Documents\KoNaR 2013-05-08 01:39 - 2013-03-30 22:34 - 00000000 ____D C:\Users\Tomek\Documents\Altium 2013-05-07 07:45 - 2013-03-31 16:53 - 00000000 ____D C:\Users\Tomek\Documents\Inventor 2013-05-07 02:40 - 2013-05-06 08:46 - 00000000 ____D C:\Users\Tomek\Documents\textest 2013-05-07 02:13 - 2013-05-07 02:13 - 00000000 ____D C:\Users\PUR\Desktop\CoSIK 2013-05-07 02:13 - 2013-05-07 02:13 - 00000000 ____D C:\users\PUR 2013-05-06 20:43 - 2013-05-06 20:43 - 00002025 ____A C:\Users\Public\Desktop\SketchUp 8.lnk 2013-05-06 20:43 - 2013-05-06 20:43 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\Google 2013-05-06 20:43 - 2013-05-06 20:43 - 00000000 ____D C:\ProgramData\Google 2013-05-06 20:43 - 2013-05-06 20:43 - 00000000 ____D C:\Program Files (x86)\Google 2013-05-06 20:42 - 2013-05-06 20:42 - 35800192 ____A (Trimble Navigation Limited) C:\Users\Tomek\Downloads\sketchupwen.exe 2013-05-06 09:35 - 2013-05-06 09:35 - 02885598 ____A C:\Users\Tomek\Desktop\Film_Scan_1000_Pro_Kinnstuck.wmv 2013-05-06 09:08 - 2013-05-06 09:08 - 00000993 ____A C:\Users\UpdatusUser\Desktop\Texmaker.lnk 2013-05-06 09:08 - 2013-05-06 09:08 - 00000993 ____A C:\Users\Tomek\Desktop\Texmaker.lnk 2013-05-06 09:08 - 2013-05-06 09:08 - 00000000 ____D C:\Program Files (x86)\Texmaker 2013-05-06 09:06 - 2013-05-06 08:47 - 00000308 ____A C:\Users\Tomek\Documents\a.tex 2013-05-06 02:59 - 2013-05-06 02:48 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\xm1 2013-05-06 02:42 - 2013-05-06 02:42 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\MiKTeX 2013-05-06 02:42 - 2013-05-06 02:42 - 00000000 ____D C:\Users\Tomek\AppData\Local\MiKTeX 2013-05-06 02:33 - 2013-05-06 02:33 - 00251469 ____A C:\Users\Tomek\Downloads\Raport_-_schemat_i_projekt_plytki_PCB.rar 2013-05-06 02:29 - 2013-05-06 02:29 - 00000000 ____D C:\ProgramData\MiKTeX 2013-05-06 02:28 - 2013-05-06 02:27 - 00000000 ____D C:\Program Files\MiKTeX 2.9 2013-05-06 02:07 - 2013-05-06 02:03 - 48116012 ____A C:\Users\Tomek\Downloads\texmakerwin32_install.exe 2013-05-06 02:01 - 2013-05-06 02:01 - 163789064 ____A (MiKTeX.org) C:\Users\Tomek\Downloads\basic-miktex-2.9.4813-x64.exe 2013-05-05 16:00 - 2013-05-05 16:00 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WinUSB_01009.Wdf 2013-05-05 15:57 - 2013-05-05 15:57 - 00002324 ____A C:\Users\Public\Desktop\STM32 ST-LINK Utility.lnk 2013-05-05 15:57 - 2013-05-05 15:57 - 00000000 ____D C:\Windows\Downloaded Installations 2013-05-05 15:57 - 2013-05-05 15:57 - 00000000 ____D C:\Program Files (x86)\STMicroelectronics 2013-05-05 15:57 - 2013-03-30 09:49 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-05-05 15:56 - 2013-05-05 15:56 - 00000000 ____D C:\Users\Tomek\Downloads\stsw-link004(1) 2013-05-05 15:56 - 2013-05-05 15:55 - 23949527 ____A C:\Users\Tomek\Downloads\stsw-link004(1).zip 2013-05-05 15:55 - 2013-05-05 15:54 - 23946194 ____A C:\Users\Tomek\Downloads\stsw-link004.zip 2013-05-05 15:52 - 2013-05-05 15:52 - 00000000 ____D C:\Users\Tomek\Downloads\st-link_v2_usbdriver(1) 2013-05-05 15:52 - 2013-05-05 15:48 - 10426328 ____A C:\Users\Tomek\Downloads\st-link_v2_usbdriver(1).zip 2013-05-05 15:49 - 2013-05-05 15:45 - 10408324 ____A C:\Users\Tomek\Downloads\st-link_v2_usbdriver.zip 2013-05-02 15:52 - 2013-05-02 15:52 - 00000000 ____D C:\Users\Tomek\AppData\Local\GHISLER 2013-05-02 15:33 - 2013-05-02 15:16 - 00000000 ____D C:\Users\Tomek\Desktop\Moje 2013-05-02 15:14 - 2013-05-02 15:13 - 00000000 ____D C:\Users\Tomek\AppData\Roaming\GHISLER 2013-05-02 15:13 - 2013-05-02 15:13 - 04329488 ____A (Ghisler Software GmbH) C:\Users\Tomek\Downloads\tcm801x64_[www.programosy.pl].exe 2013-05-02 15:13 - 2013-05-02 15:13 - 00000000 ____D C:\totalcmd 2013-05-02 12:25 - 2013-05-02 12:02 - 00000327 ____A C:\Users\Tomek\Documents\rzut.m 2013-04-30 13:29 - 2013-04-30 13:29 - 00001664 ____A C:\Users\Tomek\Desktop\krecz.txt 2013-04-29 23:43 - 2013-04-29 23:43 - 01155785 ____A C:\Users\Tomek\Downloads\Trial Reset Kaspersky_2011.rar 2013-04-29 23:43 - 2013-04-29 23:43 - 00000000 ____D C:\Users\Tomek\Downloads\Trial Reset Kaspersky_2011 Other Malware: =========== C:\Users\Tomek\AppData\Roaming\skype.dat C:\Users\Tomek\AppData\Roaming\skype.ini ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 11% Total physical RAM: 6006.91 MB Available physical RAM: 5315.6 MB Total Pagefile: 6005.11 MB Available Pagefile: 5312.2 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:119.24 GB) (Free:3.12 GB) NTFS (Disk=0 Partition=1) ==>[Drive with boot components (obtained from BCD)] Drive e: (KRD10) (Removable) (Total:7.6 GB) (Free:6.97 GB) FAT32 (Disk=1 Partition=1) Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: EDFD68D1) Partition 1: (Active) - (Size=119 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 8 GB) (Disk ID: CAD4EBEA) Partition 4: (Active) - (Size=8 GB) - (Type=0B) Last Boot: 2013-05-24 12:08 ==================== End Of Log ============================