Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-09-2013 Ran by Aleksandra (administrator) on ALEKSANDRA-VAIO on 24-09-2013 19:41:43 Running from C:\Users\Aleksandra\Desktop\lekarstwo Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (337 Technology Limited.) C:\Program Files (x86)\Desk 365\deskSvc.exe (Taiwan Shui Mu Chih Ching Technology Limited.) C:\Program Files (x86)\WinZipper\winzipersvc.exe (Wsys Co., Ltd.) C:\ProgramData\eSafe\eGdpSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Opera Software) C:\Program Files (x86)\Opera\16.0.1196.73_0\opera.exe () C:\Program Files (x86)\Opera\16.0.1196.73_0\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\16.0.1196.73_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\16.0.1196.73_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\16.0.1196.73_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\16.0.1196.73_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\16.0.1196.73_0\opera.exe (Opera Software) C:\Program Files (x86)\Opera\16.0.1196.73_0\opera.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (OldTimer Tools) C:\Users\Aleksandra\Desktop\lekarstwo\OTL.com (Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE (Sony Corporation) C:\Program Files\Sony\VAIO Improvement Validation\viv.exe () C:\Users\Aleksandra\Desktop\lekarstwo\VuuPC_Setup.exe (VuuPC Limited) C:\Users\ALEKSA~1\AppData\Local\Temp\is45637729\3024867_stp\ClickMeInSetup.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe () C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe () C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe (ClickMeIn Limited) C:\Program Files (x86)\VuuPC\Connectivity.exe (ClickMeIn Limited) C:\Program Files (x86)\VuuPC\remoteengine.exe (ClickMeIn Limited) C:\Program Files (x86)\VuuPC\RemoteEngineHelper.exe (ClickMeIn Limited) C:\Program Files (x86)\VuuPC\RemoteEngineHelper.exe (ClickMeIn Limited) C:\Users\ALEKSA~1\AppData\Local\Temp\nse57D2.tmp.exe () C:\Users\ALEKSA~1\AppData\Local\Temp\nse738F.tmp.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-13] (Adobe Systems Incorporated) HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1356240 2013-07-18] (Microsoft Corporation) HKLM-x32\...\RunOnce: [aswAhAScr.dll] - "C:\Program Files\AVAST Software\Avast\aswRegSvr.exe" "C:\Program Files\AVAST Software\Avast\AhAScr.dll" [140544 2013-03-07] (AVAST Software) HKLM-x32\...\RunOnce: [aswasOutExt.dll] - "C:\Program Files\AVAST Software\Avast\aswRegSvr.exe" "C:\Program Files\AVAST Software\Avast\asOutExt.dll" [302736 2013-03-07] (AVAST Software) HKLM-x32\...\RunOnce: [aswasOutExt64.dll] - "C:\Program Files\AVAST Software\Avast\aswRegSvr64.exe" "C:\Program Files\AVAST Software\Avast\asOutExt64.dll" [477848 2013-03-07] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [NTRedirect] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Aleksandra\AppData\Roaming\BabSolution\Shared\enhancedNT.dll",Run HKCU\...\Run: [Pokki] - C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform HKCU\...\Policies\system: [LogonHoursAction] 2 HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 MountPoints2: {1b9fddd0-52c6-11e2-a5cf-806e6f6e6963} - D:\AutoRun.exe MountPoints2: {1b9fddea-52c6-11e2-a5cf-5453edaa27ba} - D:\AutoRun.exe MountPoints2: {89e8e4f5-3624-11e2-af90-5453edaa27ba} - D:\AutoRun.exe MountPoints2: {89e8e4f9-3624-11e2-af90-5453edaa27ba} - D:\AutoRun.exe MountPoints2: {a70c63c9-66fa-11e2-87a6-5453edaa27ba} - D:\Startme.exe MountPoints2: {edcfe411-36de-11e2-8669-5453edaa27ba} - D:\AutoRun.exe MountPoints2: {edcfe413-36de-11e2-8669-5453edaa27ba} - D:\AutoRun.exe MountPoints2: {edcfe415-36de-11e2-8669-5453edaa27ba} - D:\AutoRun.exe HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-23] (Intel Corporation) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4767304 2013-03-07] (AVAST Software) HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-09-03] (Adobe Systems Incorporated) HKU\Gość\...\Run: [Desk 365] - "C:\Program Files (x86)\Desk 365\desk365.exe" /autorun HKU\tulinek\...\Policies\system: [LogonHoursAction] 2 HKU\tulinek\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 AppInit_DLLs: [0 ] () AppInit_DLLs-x32: c:\progra~3\bitguard\261673~1.238\{c16c1~1\bitguard.dll [2700768 2013-09-10] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchgol.com/?babsrc=HP_ss&mntrId=246C84A6C809C5D2&affID=119357&tsp=5015 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HitachiXHTS547564A9E384_J2180053FEDBWDFEDBWDX&ts=1377183266 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://sony.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.searchgol.com/?babsrc=HP_ss&mntrId=246C84A6C809C5D2&affID=119357&tsp=5015 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HitachiXHTS547564A9E384_J2180053FEDBWDFEDBWDX&ts=1377183266 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HitachiXHTS547564A9E384_J2180053FEDBWDFEDBWDX&ts=1377183266 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HitachiXHTS547564A9E384_J2180053FEDBWDFEDBWDX&ts=1377183266 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HitachiXHTS547564A9E384_J2180053FEDBWDFEDBWDX&ts=1377183266 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://en.v9.com/?utm_source=b&utm_medium=update&from=update&uid=HitachiXHTS547564A9E384_J2180053FEDBWDFEDBWDX&ts=1369918397 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=vltnew&from=vltnew&uid=HitachiXHTS547564A9E384_J2180053FEDBWDFEDBWDX&ts=6029426 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=vltnew&from=vltnew&uid=HitachiXHTS547564A9E384_J2180053FEDBWDFEDBWDX&ts=6029426 SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=vltnew&from=vltnew&uid=HitachiXHTS547564A9E384_J2180053FEDBWDFEDBWDX&ts=6029426 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=vltnew&from=vltnew&uid=HitachiXHTS547564A9E384_J2180053FEDBWDFEDBWDX&ts=6029426 SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=vltnew&from=vltnew&uid=HitachiXHTS547564A9E384_J2180053FEDBWDFEDBWDX&ts=6029426 SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=246C84A6C809C5D2&affID=119357&tsp=5015 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=vltnew&from=vltnew&uid=HitachiXHTS547564A9E384_J2180053FEDBWDFEDBWDX&ts=6029426 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {CA175166-A4A3-4B55-88BC-774F956D627D} URL = http://search.aol.pl/aol/search?s_it=tb50winamp&q={searchTerms} BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.24.6\bh\delta.dll (Delta-search.com) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO-x32: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File BHO-x32: BonanzaDeals - {fe063412-bea4-4d76-8ed3-183be6220d17} - C:\Program Files (x86)\BonanzaDeals\BonanzaDealsIE.dll (BonanzaDeals) Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.24.6\deltaTlbr.dll (Delta-search.com) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 62.21.99.95 Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (BonanzaDeals) - C:\Users\ALEKSA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0 CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Aleksandra\AppData\Roaming\BabSolution\CR\Delta.crx CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - \User Data\Default\Extensions\newtab.crx ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [45248 2013-03-07] (AVAST Software) S2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [137960 2013-08-30] (AVAST Software) R2 BitGuard; C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [2845152 2013-09-10] () S2 bonanzadealslive; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-09-24] (BonanzaDeals) S3 bonanzadealslivem; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-09-24] (BonanzaDeals) R2 desksvc; C:\Program Files (x86)\Desk 365\deskSvc.exe [424016 2013-09-07] (337 Technology Limited.) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-23] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-23] (Intel Corporation) S3 McComponentHostServiceSony; C:\Program Files (x86)\Sony\MSS\3.0.271\McCHSvc.exe [237328 2012-03-30] (McAfee, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2013-07-18] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-07-18] (Microsoft Corporation) R2 RemoteEngineService; C:\Program Files (x86)\VuuPC\remoteengine.exe [2967568 2013-09-19] (ClickMeIn Limited) S3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1359408 2013-03-26] (Sony Corporation) R2 VuuPCConnectivity; C:\Program Files (x86)\VuuPC\Connectivity.exe [4747280 2013-09-19] (ClickMeIn Limited) R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [424104 2013-08-22] (Taiwan Shui Mu Chih Ching Technology Limited.) R2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [303680 2013-08-22] (Wsys Co., Ltd.) S2 KMService; C:\Windows\system32\srvany.exe [x] ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [31872 2012-03-19] (Advanced Micro Devices, Inc.) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software) S1 aswFW; C:\Windows\system32\drivers\aswFW.sys [131232 2013-08-30] (AVAST Software) S1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software) R0 aswNdis; C:\Windows\System32\DRIVERS\aswNdis.sys [12368 2013-07-17] (ALWIL Software) R0 aswNdis2; C:\Windows\System32\drivers\aswNdis2.sys [270824 2013-08-30] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software) S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] () R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation) R2 rimssne; C:\Windows\System32\DRIVERS\rimssne64.sys [102912 2012-02-24] (REDC) R2 risdsnxc; C:\Windows\System32\DRIVERS\risdsnxc64.sys [104448 2012-02-23] (REDC) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-10-14] (Duplex Secure Ltd.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-24 19:43 - 2013-09-24 19:43 - 00001050 _____ C:\Users\Public\Desktop\RegClean Pro.lnk 2013-09-24 19:43 - 2013-09-24 19:43 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\systweak 2013-09-24 19:42 - 2013-09-24 19:42 - 00003030 _____ C:\Windows\System32\Tasks\Lyrmix Update 2013-09-24 19:42 - 2013-09-24 19:42 - 00000372 _____ C:\Windows\Tasks\Lyrmix Update.job 2013-09-24 19:42 - 2013-09-24 19:42 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\ConvertAd 2013-09-24 19:41 - 2013-09-24 19:41 - 00001144 _____ C:\Users\Aleksandra\Desktop\My VuuPC.lnk 2013-09-24 19:41 - 2013-09-24 19:41 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VuuPC 2013-09-24 19:41 - 2013-09-24 19:41 - 00000000 ____D C:\FRST 2013-09-24 19:40 - 2013-09-24 19:43 - 00003418 _____ C:\Windows\System32\Tasks\EPUpdater 2013-09-24 19:40 - 2013-09-24 19:40 - 00003930 _____ C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA 2013-09-24 19:40 - 2013-09-24 19:40 - 00003678 _____ C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore 2013-09-24 19:40 - 2013-09-24 19:40 - 00003396 _____ C:\Windows\System32\Tasks\BonanzaDealsUpdate 2013-09-24 19:40 - 2013-09-24 19:40 - 00003314 _____ C:\Windows\System32\Tasks\VuuPCUpdate 2013-09-24 19:40 - 2013-09-24 19:40 - 00003128 _____ C:\Windows\System32\Tasks\VuuPCUpdateLogin 2013-09-24 19:40 - 2013-09-24 19:40 - 00000934 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job 2013-09-24 19:40 - 2013-09-24 19:40 - 00000930 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job 2013-09-24 19:40 - 2013-09-24 19:40 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-09-24 19:40 - 2013-09-24 19:40 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\BonanzaDealsLive 2013-09-24 19:40 - 2013-09-24 19:40 - 00000000 ____D C:\ProgramData\BonanzaDealsLive 2013-09-24 19:40 - 2013-09-24 19:40 - 00000000 ____D C:\ProgramData\BitGuard 2013-09-24 19:40 - 2013-09-24 19:40 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive 2013-09-24 19:39 - 2013-09-24 19:41 - 00000000 ____D C:\Program Files (x86)\VuuPC 2013-09-24 19:39 - 2013-09-24 19:39 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals 2013-09-24 19:39 - 2013-09-24 19:39 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals 2013-09-24 19:38 - 2013-09-24 19:38 - 00001123 _____ C:\Users\Aleksandra\Desktop\Continue VuuPC Installation.lnk 2013-09-24 19:34 - 2013-08-30 09:48 - 00270824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdis2.sys 2013-09-24 19:34 - 2013-08-30 09:48 - 00131232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFW.sys 2013-09-24 19:34 - 2013-08-30 09:48 - 00022600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2013-09-24 19:34 - 2013-07-17 11:17 - 00012368 _____ (ALWIL Software) C:\Windows\system32\Drivers\aswNdis.sys 2013-09-24 19:31 - 2013-09-24 19:40 - 00000000 ____D C:\Users\Aleksandra\Desktop\lekarstwo 2013-09-24 19:25 - 2013-09-24 19:25 - 00001912 _____ C:\Windows\epplauncher.mif 2013-09-24 19:25 - 2013-09-24 19:25 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-09-24 19:24 - 2013-09-24 19:25 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-09-24 19:24 - 2013-09-24 19:25 - 00000000 ____D C:\03d2594c6221ef3c532e2c45 2013-09-24 19:24 - 2013-09-24 19:24 - 13840576 _____ (Microsoft Corporation) C:\Users\Aleksandra\Downloads\mseinstall.exe 2013-09-24 19:21 - 2013-09-24 19:21 - 00621568 _____ (Duplex Secure Ltd.) C:\Users\Aleksandra\Downloads\SPTDinst-v184-x64.exe 2013-09-23 19:02 - 2013-09-23 19:02 - 00001167 _____ C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GG.lnk 2013-09-22 19:59 - 2013-09-22 22:36 - 00000000 ____D C:\Users\Aleksandra\Desktop\logo 2013-09-22 19:30 - 2013-09-22 19:30 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\PDAppFlex 2013-09-22 19:16 - 2013-09-22 19:16 - 00000000 ____D C:\ProgramData\ALM 2013-09-22 18:45 - 2013-09-22 18:45 - 00001070 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2013-09-22 18:40 - 2013-09-22 18:40 - 03867000 _____ (Adobe Systems Incorporated) C:\Users\Aleksandra\Downloads\CreativeCloudSet-Up (1).exe 2013-09-22 18:36 - 2013-09-22 18:36 - 03867000 _____ (Adobe Systems Incorporated) C:\Users\Aleksandra\Downloads\CreativeCloudSet-Up.exe 2013-09-20 23:31 - 2013-09-24 19:09 - 00002740 _____ C:\Windows\System32\Tasks\AutoKMSDaily 2013-09-20 00:14 - 2013-09-20 00:14 - 00000045 ____H C:\Users\Aleksandra\Downloads\.picasa.ini 2013-09-17 12:53 - 2013-09-17 12:53 - 00000000 ____D C:\Users\Aleksandra\Desktop\a 2013-09-17 00:51 - 2013-09-17 00:51 - 00002324 _____ C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Goodgame Big Farm.lnk 2013-09-17 00:50 - 2013-09-18 01:27 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\Pokki 2013-09-17 00:50 - 2013-09-17 00:50 - 00002121 _____ C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk 2013-09-17 00:50 - 2013-09-17 00:50 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki 2013-09-17 00:49 - 2013-09-17 00:49 - 00098255 _____ C:\Users\Aleksandra\Documents\o.m3u 2013-09-17 00:46 - 2013-09-17 00:46 - 00001270 _____ C:\Users\tulinek\Desktop\50 FREE MP3s +1 Free Audiobook!.lnk 2013-09-17 00:46 - 2013-09-17 00:46 - 00001270 _____ C:\Users\Gość\Desktop\50 FREE MP3s +1 Free Audiobook!.lnk 2013-09-17 00:44 - 2013-09-17 00:44 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\OpenCandy 2013-09-15 19:55 - 2013-09-24 18:42 - 00008194 _____ C:\Windows\PFRO.log 2013-09-15 15:05 - 2013-09-15 15:06 - 00000000 ____D C:\Users\Aleksandra\Desktop\HALINA SIKA 2013-09-14 15:23 - 2013-09-24 19:09 - 00005688 _____ C:\Windows\AutoKMS.log 2013-09-14 15:20 - 2013-09-22 19:31 - 00150208 _____ C:\Users\Aleksandra\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-14 15:16 - 2013-09-24 19:05 - 00001322 _____ C:\Windows\setupact.log 2013-09-14 15:16 - 2013-09-23 18:35 - 05217248 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-14 15:16 - 2013-09-14 15:16 - 00000000 _____ C:\Windows\setuperr.log 2013-09-13 16:47 - 2013-09-13 16:47 - 00043272 _____ C:\Users\Aleksandra\Downloads\RAPORTY DLA SZCZEPANA.xlsx 2013-09-13 07:41 - 2013-09-13 07:41 - 00001922 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk 2013-09-12 14:15 - 2013-09-12 14:15 - 00058188 _____ C:\Users\Aleksandra\Desktop\Opera 12 Notes.html 2013-09-12 14:15 - 2013-09-12 14:15 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Opera Software 2013-09-12 14:15 - 2013-09-12 14:15 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\Opera Software 2013-09-12 07:42 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 07:42 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 07:42 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-12 07:42 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 07:42 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 07:42 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 07:42 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 07:42 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 07:42 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 07:42 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 07:42 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-12 07:42 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-12 07:42 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-12 07:42 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-12 07:42 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-12 07:42 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-12 07:42 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-12 07:42 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-12 07:42 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-12 07:42 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-12 07:42 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-12 07:42 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-12 07:42 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-12 07:42 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-12 07:42 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-12 07:42 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-12 07:42 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-12 07:42 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 07:42 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-12 07:42 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-12 07:42 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-11 07:52 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-11 07:52 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-11 07:52 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-11 07:52 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-11 07:52 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-11 07:52 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-11 07:52 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-11 07:52 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-11 07:52 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-11 07:52 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-11 07:52 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-11 07:52 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-11 07:52 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-11 07:52 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-11 07:52 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 07:52 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-11 07:52 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-11 07:52 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-11 07:51 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 07:51 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-11 07:51 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 07:51 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-11 07:51 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-11 07:51 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-11 07:51 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-11 07:51 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-11 07:51 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-11 07:51 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 07:51 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 07:51 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-11 07:51 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-11 07:51 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-11 07:51 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-11 07:51 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-03 21:03 - 2013-09-03 21:03 - 00239766 _____ C:\Users\Aleksandra\Documents\1.m3u 2013-08-30 11:08 - 2013-08-30 11:09 - 00000000 ____D C:\Users\tulinek\AppData\Roaming\Desk 365 ==================== One Month Modified Files and Folders ======= 2013-09-24 19:43 - 2013-09-24 19:43 - 00001050 _____ C:\Users\Public\Desktop\RegClean Pro.lnk 2013-09-24 19:43 - 2013-09-24 19:43 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\systweak 2013-09-24 19:43 - 2013-09-24 19:40 - 00003418 _____ C:\Windows\System32\Tasks\EPUpdater 2013-09-24 19:42 - 2013-09-24 19:42 - 00003030 _____ C:\Windows\System32\Tasks\Lyrmix Update 2013-09-24 19:42 - 2013-09-24 19:42 - 00000372 _____ C:\Windows\Tasks\Lyrmix Update.job 2013-09-24 19:42 - 2013-09-24 19:42 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\ConvertAd 2013-09-24 19:42 - 2012-09-25 07:56 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-09-24 19:41 - 2013-09-24 19:41 - 00001144 _____ C:\Users\Aleksandra\Desktop\My VuuPC.lnk 2013-09-24 19:41 - 2013-09-24 19:41 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VuuPC 2013-09-24 19:41 - 2013-09-24 19:41 - 00000000 ____D C:\FRST 2013-09-24 19:41 - 2013-09-24 19:39 - 00000000 ____D C:\Program Files (x86)\VuuPC 2013-09-24 19:40 - 2013-09-24 19:40 - 00003930 _____ C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA 2013-09-24 19:40 - 2013-09-24 19:40 - 00003678 _____ C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore 2013-09-24 19:40 - 2013-09-24 19:40 - 00003396 _____ C:\Windows\System32\Tasks\BonanzaDealsUpdate 2013-09-24 19:40 - 2013-09-24 19:40 - 00003314 _____ C:\Windows\System32\Tasks\VuuPCUpdate 2013-09-24 19:40 - 2013-09-24 19:40 - 00003128 _____ C:\Windows\System32\Tasks\VuuPCUpdateLogin 2013-09-24 19:40 - 2013-09-24 19:40 - 00000934 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job 2013-09-24 19:40 - 2013-09-24 19:40 - 00000930 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job 2013-09-24 19:40 - 2013-09-24 19:40 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-09-24 19:40 - 2013-09-24 19:40 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\BonanzaDealsLive 2013-09-24 19:40 - 2013-09-24 19:40 - 00000000 ____D C:\ProgramData\BonanzaDealsLive 2013-09-24 19:40 - 2013-09-24 19:40 - 00000000 ____D C:\ProgramData\BitGuard 2013-09-24 19:40 - 2013-09-24 19:40 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive 2013-09-24 19:40 - 2013-09-24 19:31 - 00000000 ____D C:\Users\Aleksandra\Desktop\lekarstwo 2013-09-24 19:39 - 2013-09-24 19:39 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals 2013-09-24 19:39 - 2013-09-24 19:39 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals 2013-09-24 19:39 - 2013-02-22 16:28 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\Google 2013-09-24 19:38 - 2013-09-24 19:38 - 00001123 _____ C:\Users\Aleksandra\Desktop\Continue VuuPC Installation.lnk 2013-09-24 19:34 - 2013-04-19 16:18 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-09-24 19:34 - 2013-02-20 18:05 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-09-24 19:33 - 2013-03-29 08:23 - 01264026 _____ C:\Windows\WindowsUpdate.log 2013-09-24 19:26 - 2013-02-22 22:07 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-24 19:25 - 2013-09-24 19:25 - 00001912 _____ C:\Windows\epplauncher.mif 2013-09-24 19:25 - 2013-09-24 19:25 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-09-24 19:25 - 2013-09-24 19:24 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-09-24 19:25 - 2013-09-24 19:24 - 00000000 ____D C:\03d2594c6221ef3c532e2c45 2013-09-24 19:24 - 2013-09-24 19:24 - 13840576 _____ (Microsoft Corporation) C:\Users\Aleksandra\Downloads\mseinstall.exe 2013-09-24 19:22 - 2009-07-14 06:45 - 00021200 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-24 19:22 - 2009-07-14 06:45 - 00021200 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-24 19:21 - 2013-09-24 19:21 - 00621568 _____ (Duplex Secure Ltd.) C:\Users\Aleksandra\Downloads\SPTDinst-v184-x64.exe 2013-09-24 19:13 - 2013-04-18 16:17 - 00000000 ____D C:\ProgramData\eSafe 2013-09-24 19:13 - 2012-09-24 17:55 - 00000000 ____D C:\Program Files (x86)\Opera 2013-09-24 19:11 - 2012-09-24 16:03 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\Adobe 2013-09-24 19:10 - 2012-09-26 15:26 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Skype 2013-09-24 19:09 - 2013-09-20 23:31 - 00002740 _____ C:\Windows\System32\Tasks\AutoKMSDaily 2013-09-24 19:09 - 2013-09-14 15:23 - 00005688 _____ C:\Windows\AutoKMS.log 2013-09-24 19:09 - 2013-08-22 16:54 - 00000000 ____D C:\Program Files (x86)\WinZipper 2013-09-24 19:09 - 2013-04-18 16:17 - 00000000 ____D C:\Program Files (x86)\Desk 365 2013-09-24 19:09 - 2013-01-09 14:18 - 00000210 _____ C:\Windows\Tasks\AutoKMS.job 2013-09-24 19:09 - 2013-01-09 14:18 - 00000202 _____ C:\Windows\Tasks\AutoKMSDaily.job 2013-09-24 19:06 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-24 19:05 - 2013-09-14 15:16 - 00001322 _____ C:\Windows\setupact.log 2013-09-24 18:44 - 2012-09-24 18:00 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\GG 2013-09-24 18:42 - 2013-09-15 19:55 - 00008194 _____ C:\Windows\PFRO.log 2013-09-24 05:05 - 2012-12-26 14:11 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\Last.fm 2013-09-24 04:11 - 2012-09-29 07:19 - 00004014 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{EB26F8AB-901E-4B90-A71C-04F62F0A471E} 2013-09-23 19:11 - 2012-10-28 13:01 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-09-23 19:02 - 2013-09-23 19:02 - 00001167 _____ C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GG.lnk 2013-09-23 19:02 - 2012-09-24 18:00 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\GG 2013-09-23 19:00 - 2013-02-01 20:37 - 00000000 ____D C:\Users\Aleksandra\Downloads\programy 2013-09-23 18:35 - 2013-09-14 15:16 - 05217248 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-22 22:36 - 2013-09-22 19:59 - 00000000 ____D C:\Users\Aleksandra\Desktop\logo 2013-09-22 19:33 - 2012-09-27 20:17 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-09-22 19:32 - 2012-09-24 17:23 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Adobe 2013-09-22 19:31 - 2013-09-14 15:20 - 00150208 _____ C:\Users\Aleksandra\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-22 19:30 - 2013-09-22 19:30 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\PDAppFlex 2013-09-22 19:17 - 2012-08-19 01:56 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-09-22 19:16 - 2013-09-22 19:16 - 00000000 ____D C:\ProgramData\ALM 2013-09-22 19:15 - 2013-01-29 18:33 - 00000000 ____D C:\Program Files\Adobe 2013-09-22 19:09 - 2012-08-19 01:43 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-09-22 18:45 - 2013-09-22 18:45 - 00001070 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2013-09-22 18:40 - 2013-09-22 18:40 - 03867000 _____ (Adobe Systems Incorporated) C:\Users\Aleksandra\Downloads\CreativeCloudSet-Up (1).exe 2013-09-22 18:36 - 2013-09-22 18:36 - 03867000 _____ (Adobe Systems Incorporated) C:\Users\Aleksandra\Downloads\CreativeCloudSet-Up.exe 2013-09-22 12:51 - 2012-09-28 08:48 - 00000000 ___RD C:\Users\Aleksandra\Desktop\olutek 2013-09-21 00:02 - 2009-07-14 07:08 - 00032604 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-20 00:14 - 2013-09-20 00:14 - 00000045 ____H C:\Users\Aleksandra\Downloads\.picasa.ini 2013-09-18 10:07 - 2013-06-30 11:28 - 00000000 ____D C:\Users\Aleksandra\Desktop\chill 2013-09-18 01:27 - 2013-09-17 00:50 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\Pokki 2013-09-17 12:53 - 2013-09-17 12:53 - 00000000 ____D C:\Users\Aleksandra\Desktop\a 2013-09-17 00:51 - 2013-09-17 00:51 - 00002324 _____ C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Goodgame Big Farm.lnk 2013-09-17 00:50 - 2013-09-17 00:50 - 00002121 _____ C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk 2013-09-17 00:50 - 2013-09-17 00:50 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki 2013-09-17 00:49 - 2013-09-17 00:49 - 00098255 _____ C:\Users\Aleksandra\Documents\o.m3u 2013-09-17 00:46 - 2013-09-17 00:46 - 00001270 _____ C:\Users\tulinek\Desktop\50 FREE MP3s +1 Free Audiobook!.lnk 2013-09-17 00:46 - 2013-09-17 00:46 - 00001270 _____ C:\Users\Gość\Desktop\50 FREE MP3s +1 Free Audiobook!.lnk 2013-09-17 00:44 - 2013-09-17 00:44 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\OpenCandy 2013-09-16 10:39 - 2011-12-07 04:14 - 01876512 _____ C:\Windows\system32\perfh015.dat 2013-09-16 10:39 - 2011-12-07 04:14 - 00552648 _____ C:\Windows\system32\perfc015.dat 2013-09-16 10:39 - 2009-07-14 07:13 - 00006256 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-15 15:45 - 2012-10-28 13:01 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Winamp 2013-09-15 15:06 - 2013-09-15 15:05 - 00000000 ____D C:\Users\Aleksandra\Desktop\HALINA SIKA 2013-09-14 15:16 - 2013-09-14 15:16 - 00000000 _____ C:\Windows\setuperr.log 2013-09-14 08:31 - 2011-12-07 01:41 - 00000000 ____D C:\Windows\Panther 2013-09-13 16:47 - 2013-09-13 16:47 - 00043272 _____ C:\Users\Aleksandra\Downloads\RAPORTY DLA SZCZEPANA.xlsx 2013-09-13 07:41 - 2013-09-13 07:41 - 00001922 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk 2013-09-13 07:40 - 2012-08-19 01:04 - 00000000 ____D C:\Program Files (x86)\Dolby Home Theater v4 2013-09-13 07:39 - 2013-07-07 11:36 - 00000000 ____D C:\Program Files (x86)\Time Organizer 2013-09-12 20:48 - 2013-07-07 11:36 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Time Organizer 2013-09-12 14:15 - 2013-09-12 14:15 - 00058188 _____ C:\Users\Aleksandra\Desktop\Opera 12 Notes.html 2013-09-12 14:15 - 2013-09-12 14:15 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\Opera Software 2013-09-12 14:15 - 2013-09-12 14:15 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\Opera Software 2013-09-12 14:10 - 2012-09-24 16:03 - 00000000 ___RD C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-12 14:10 - 2012-09-24 16:03 - 00000000 ___RD C:\Users\Aleksandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 11:20 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-12 07:42 - 2013-08-14 04:41 - 00000000 ____D C:\Windows\system32\MRT 2013-09-12 07:39 - 2012-10-16 14:28 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-12 07:39 - 2012-09-26 14:50 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-11 07:43 - 2012-10-22 07:39 - 00000000 ____D C:\Update 2013-09-10 20:26 - 2013-02-22 22:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-10 20:26 - 2013-02-22 22:07 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-10 20:26 - 2013-02-22 22:07 - 00003868 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-10 09:51 - 2012-08-19 01:14 - 00000000 ____D C:\Windows\System32\Tasks\Sony Corporation 2013-09-09 13:42 - 2012-11-15 12:43 - 00000000 ____D C:\Users\Aleksandra\AppData\Local\ChomikBox 2013-09-09 13:40 - 2012-11-15 12:43 - 00000000 ____D C:\Users\Aleksandra\.gstreamer-0.10 2013-09-05 16:32 - 2013-08-15 11:50 - 00000000 ____D C:\Users\Aleksandra\Desktop\f 2013-09-04 09:38 - 2012-12-26 14:11 - 00000000 ____D C:\Program Files (x86)\Last.fm 2013-09-03 21:03 - 2013-09-03 21:03 - 00239766 _____ C:\Users\Aleksandra\Documents\1.m3u 2013-09-03 15:50 - 2013-01-24 16:46 - 00000000 ____D C:\Users\Aleksandra\Desktop\folder 2013-08-30 11:13 - 2013-06-21 13:25 - 00000000 ____D C:\Users\tulinek\AppData\Local\Sony Corporation 2013-08-30 11:11 - 2013-06-21 13:25 - 00000000 ____D C:\Users\tulinek\AppData\Roaming\Sony Corporation 2013-08-30 11:09 - 2013-08-30 11:08 - 00000000 ____D C:\Users\tulinek\AppData\Roaming\Desk 365 2013-08-30 09:48 - 2013-09-24 19:34 - 00270824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdis2.sys 2013-08-30 09:48 - 2013-09-24 19:34 - 00131232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFW.sys 2013-08-30 09:48 - 2013-09-24 19:34 - 00022600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2013-08-30 09:48 - 2013-04-19 16:18 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-30 09:48 - 2013-04-19 16:18 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-30 09:48 - 2013-04-19 16:18 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-30 09:48 - 2013-04-19 16:18 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-08-30 09:48 - 2013-04-19 16:18 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-08-30 09:48 - 2013-04-19 16:18 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-08-30 09:48 - 2013-04-19 16:18 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-08-30 09:48 - 2013-04-19 16:18 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-08-30 09:47 - 2013-04-19 16:17 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-08-30 09:47 - 2013-02-20 18:05 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-08-26 10:48 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-08-26 00:13 - 2013-08-22 16:54 - 00000000 ____D C:\Users\Aleksandra\AppData\Roaming\WinZipper 2013-08-25 00:07 - 2013-08-15 12:23 - 00000000 ____D C:\Users\Aleksandra\Documents\Movie Studio Platinum 12.0 Projekty Some content of TEMP: ==================== C:\Users\Aleksandra\AppData\Local\Temp\Creative Cloud Helper.exe C:\Users\Aleksandra\AppData\Local\Temp\ICReinstall_nsa5C1F.tmp.exe C:\Users\Aleksandra\AppData\Local\Temp\ICReinstall_VuuPC_Setup.exe C:\Users\Aleksandra\AppData\Local\Temp\nsa5C1F.tmp.exe C:\Users\Aleksandra\AppData\Local\Temp\nse57D2.tmp.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll [2010-11-21 05:24] - [2010-11-21 05:24] - 1008640 ____A (Microsoft Corporation) 8D0F86272C524052236761CABF6E7AFE C:\Windows\SysWOW64\User32.dll [2013-01-09 14:05] - [2013-01-09 14:06] - 0833024 ____A (Microsoft Corporation) E01EBE6A0C7B306763667FDC60A0B25A C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-21 01:34 ==================== End Of Log ============================