Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013 Ran by Marcin (administrator) on MARCIN-PC on 03-11-2013 14:40:39 Running from C:\Users\Marcin\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Polish Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe (ABBYY) C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\Home\NetworkLicenseServer.exe (Agere Systems) C:\Windows\system32\agrsmsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe (Brio) C:\Program Files\FolderSize\FolderSizeSvc.exe (Teruten) C:\Windows\system32\FsUsbExService.Exe (Garmin Ltd or its subsidiaries) C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe () C:\Windows\SYSTEM32\Rezip.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\tv_w32.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (Ask) C:\Program Files\Ask.com\Updater\Updater.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe () C:\Program Files\Nokia\Nokia Internet Modem\NokiaInternetModem_AppStart.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Nokia) C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Garmin Ltd or its subsidiaries) C:\Program Files\Garmin\Express Tray\ExpressTray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Learnpulse) C:\Users\Marcin\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Inzone Software Limited) C:\Program Files\iPrint\iPrint.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE (Microsoft Corporation) C:\Windows\system32\conime.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Microsoft Corporation) C:\Windows\system32\wuauclt.exe (Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2009-03-12] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6814240 2009-02-13] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1049896 2008-08-28] (Synaptics, Inc.) HKLM\...\Run: [UCam_Menu] - C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [2145000 2010-04-07] (ESET) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-02-13] (Realtek Semiconductor Corp.) HKLM\...\Run: [] - [x] HKLM\...\Run: [ApnUpdater] - C:\Program Files\Ask.com\Updater\Updater.exe [1648264 2013-04-25] (Ask) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [NokiaInternetModem_AppStart.exe] - C:\Program Files\Nokia\Nokia Internet Modem\NokiaInternetModem_AppStart.exe [142464 2011-07-08] () HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [2238704 2013-02-21] (Logitech, Inc.) HKCU\...\Run: [] - [x] HKCU\...\Run: [NokiaSuite.exe] - C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe [1086376 2012-08-03] (Nokia) HKCU\...\Run: [iCloudServices] - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-04-05] (Apple Inc.) HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-04-05] (Apple Inc.) HKCU\...\Run: [com.apple.dav.bookmarks.daemon] - C:\Program Files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe [59720 2013-04-05] (Apple Inc.) HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files\Garmin\Express Tray\ExpressTray.exe [1098072 2013-03-27] (Garmin Ltd or its subsidiaries) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [Screenpresso] - C:\Users\Marcin\AppData\Local\Learnpulse\Screenpresso\Screenpresso.exe [8646160 2013-10-06] (Learnpulse) MountPoints2: {2d147ff4-be95-11e1-a31c-002454097108} - H:\LaunchU3.exe -a MountPoints2: {5c54caa8-d370-11e1-9539-002454097108} - F:\AutoRun.exe MountPoints2: {6cf16e56-27f0-11e2-a19a-d505f5e37ebb} - F:\Setup.exe MountPoints2: {89ffbc81-f468-11e1-acab-002454097108} - F:\AutoRun.exe MountPoints2: {89ffbc82-f468-11e1-acab-002454097108} - F:\AutoRun.exe MountPoints2: {93bc2409-b6b2-11e1-b30f-b0076c836812} - F:\AutoRun.exe MountPoints2: {ae84accc-b4dd-11e1-95cd-002454097108} - F:\AutoRun.exe MountPoints2: {ae84acfd-b4dd-11e1-95cd-002454097108} - F:\AutoRun.exe HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Gość\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Iwona\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter Startup: C:\Users\Marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk ShortcutTarget: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== ProxyServer: proxy.kozminski.edu.pl:8080 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&userid=EB_USER_ID&ctid=CT2481033&SSPV=TB_IESB20 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?brand=SMSN&bmod=SMSN HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn URLSearchHook: HKLM - Ashampoo_PO Toolbar - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Users\Marcin\AppData\LocalLow\CT2481033\ldrtbAsha.dll () URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) URLSearchHook: HKCU - Ashampoo_PO Toolbar - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Users\Marcin\AppData\LocalLow\CT2481033\ldrtbAsha.dll () SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=112555&babsrc=SP_ss&mntrId=6c7feca8000000000000001e65981edc SearchScopes: HKCU - {43E7BC24-937D-4160-BEA9-D882AE32BF28} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033&CUI=UN15930264491361421&SSPV=TB_IESB20 SearchScopes: HKCU - {76A50F67-9997-4231-ABC8-E192E8D8E6B6} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=78787D7C-739A-4FEB-B07D-76D466AC5DEB&apn_sauid=CB349633-85BF-4E16-BD3E-01CE91FDA107 BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Marcin\AppData\Roaming\Complitly\Complitly.dll (SimplyGen) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) BHO: Ashampoo_PO Toolbar - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Users\Marcin\AppData\LocalLow\CT2481033\ldrtbAsha.dll () BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM - Ashampoo_PO Toolbar - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Users\Marcin\AppData\LocalLow\CT2481033\ldrtbAsha.dll () Toolbar: HKCU - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKCU - Ashampoo_PO Toolbar - {D43723AE-1AE1-4A25-A6A4-BF0929273CAB} - C:\Users\Marcin\AppData\LocalLow\CT2481033\ldrtbAsha.dll () Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default FF user.js: detected! => C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\user.js FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Google FF Homepage: www.aaausg.pl FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @garmin.com/GpsControl - C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\searchplugins\ashampoo-po-customized-web-search.xml FF SearchPlugin: C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\searchplugins\askcom.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml FF Extension: Vividas player plugin - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\player@vividas.com FF Extension: Ask Toolbar - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\toolbar@ask.com FF Extension: Kompas - Tłumacz i Słownik Języka Angielskiego 7.0 (Firefox 1.5-3.x) - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\trenpl7ff@kompas.info.pl FF Extension: Garmin Communicator - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} FF Extension: Complitly - Speed up your search with your personal search suggestions tool - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516} FF Extension: EPUBReader - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F} FF Extension: DownloadHelper - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: Page Speed - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97} FF Extension: firebug - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\firebug@software.joehewitt.com.xpi FF Extension: newtabgoogle - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\newtabgoogle@graememcc.co.uk.xpi FF Extension: p24ext - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\p24ext@przelewy24.pl.xpi FF Extension: defaults - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi FF Extension: Adblock Plus - C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\dbfe9nhq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKLM\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 ========================== Services (Whitelisted) ================= R2 ABBYY.Licensing.FineReader.Home.10.0; C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\Home\NetworkLicenseServer.exe [814344 2010-07-21] (ABBYY) S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [33560 2010-04-07] (ESET) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [810120 2010-04-07] (ESET) R2 FolderSize; C:\Program Files\FolderSize\FolderSizeSvc.exe [116224 2010-04-06] (Brio) S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-09-26] (Freemake) R2 Garmin Core Update Service; C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [185688 2013-03-27] (Garmin Ltd or its subsidiaries) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 Rezip; C:\Windows\SYSTEM32\Rezip.exe [311296 2009-03-05] () R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.) R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1729336 2013-10-11] (TuneUp Software) R2 yksvc; C:\Windows\System32\ykx32mpcoinst.dll [282624 2009-01-30] (Marvell) ==================== Drivers (Whitelisted) ==================== R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [133512 2010-04-07] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [114984 2010-04-07] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [134488 2010-04-07] (ESET) R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [32584 2010-04-07] (ESET) R2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [41312 2010-04-07] (ESET) R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36608 2009-03-31] () R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2006-11-14] (SAMSUNG ELECTRONICS CO., LTD.) R3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [30984 2013-01-03] (Logitech, Inc.) S3 nokia_usb_modem_cdc_acm; C:\Windows\System32\DRIVERS\nokia_usb_modem_cdc_acm.sys [67968 2011-06-22] (Nokia) S3 nokia_usb_modem_cdc_ecm; C:\Windows\System32\DRIVERS\nokia_usb_modem_cdc_ecm.sys [32896 2011-06-22] (Nokia) S3 nokia_usb_modem_ecm_enum; C:\Windows\System32\DRIVERS\nokia_usb_modem_ecm_enum.sys [47488 2011-06-22] (Nokia) S3 nokia_usb_modem_ecm_enum_filter; C:\Windows\System32\DRIVERS\nokia_usb_modem_ecm_enum_filter.sys [47488 2011-06-22] (Nokia) S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [90112 2009-03-20] (MCCI) S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14976 2009-03-20] (MCCI Corporation) S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [121856 2009-03-20] (MCCI Corporation) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-11-16] (TuneUp Software) S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-03 14:27 - 2013-11-03 14:27 - 00377856 _____ C:\Users\Marcin\Downloads\nn62w4c1.exe 2013-11-03 14:15 - 2013-11-03 14:15 - 00143640 _____ C:\Windows\Minidump\Mini110313-01.dmp 2013-11-03 14:13 - 2013-11-03 14:13 - 00259584 _____ (OldTimer Tools) C:\Users\Marcin\Downloads\OTH.exe 2013-11-03 14:13 - 2013-11-03 14:13 - 00025635 _____ C:\Users\Marcin\Downloads\Addition.txt 2013-11-03 14:10 - 2013-11-03 14:10 - 00000000 ____D C:\FRST 2013-11-03 14:07 - 2013-11-03 14:08 - 00602112 _____ (OldTimer Tools) C:\Users\Marcin\Downloads\OTL.exe 2013-11-03 14:07 - 2013-11-03 14:07 - 01089445 _____ (Farbar) C:\Users\Marcin\Downloads\FRST.exe 2013-11-02 05:11 - 2009-03-03 05:38 - 00671232 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2013-11-02 05:11 - 2009-03-03 05:37 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\ieencode.dll 2013-11-02 05:11 - 2009-01-09 04:03 - 00213640 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfehidk.sys 2013-11-02 05:11 - 2009-01-09 04:03 - 00079304 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfeavfk.sys 2013-11-02 05:11 - 2009-01-09 04:03 - 00040552 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mfesmfk.sys 2013-11-02 05:11 - 2009-01-09 04:03 - 00034216 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\mferkdk.sys 2013-11-02 05:11 - 2009-01-09 04:03 - 00000000 _____ C:\Windows\system32\Drivers\mfebopk.sys 2013-11-02 05:11 - 2008-10-23 05:08 - 00130424 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\Mpfp.sys 2013-11-02 05:11 - 2008-01-21 03:24 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\extmgr.dll 2013-11-02 05:11 - 2008-01-21 03:24 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\WsmProv.dll 2013-11-02 05:11 - 2008-01-21 03:24 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll 2013-11-02 05:11 - 2008-01-21 03:24 - 00001536 _____ (Microsoft Corporation) C:\Windows\system32\WsmCl.dll 2013-11-02 05:11 - 2008-01-21 03:23 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vsp1cln.exe 2013-11-02 05:11 - 2008-01-21 03:23 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01007_Inbox_Critical.Wdf 2013-11-01 15:52 - 2013-11-01 15:52 - 00417792 _____ (ALK) C:\Users\Marcin\Downloads\PROXY-POL-2.exe 2013-11-01 15:51 - 2013-11-01 15:51 - 00403456 _____ (ALK) C:\Users\Marcin\Downloads\Proxy_Bazy_Danych_Biblioteki.exe 2013-10-30 23:29 - 2013-10-30 23:30 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-28 02:03 - 2012-01-01 22:07 - 00000000 ____D C:\Users\Marcin\Desktop\insist_rel 2013-10-28 02:02 - 2013-10-28 02:01 - 00899501 _____ C:\Users\Marcin\Downloads\insist_rel_1.0.0.zip 2013-10-27 23:35 - 2013-10-27 23:35 - 00000053 _____ C:\Users\Marcin\Desktop\google4359dc3850381357.html 2013-10-27 21:42 - 2013-10-27 21:42 - 00012762 _____ C:\Users\Marcin\AppData\Local\recently-used.xbel 2013-10-26 20:26 - 2013-10-26 20:26 - 00406869 _____ C:\Users\Marcin\Downloads\myInvision_3.0.zip 2013-10-26 19:29 - 2013-10-26 19:35 - 00000000 ____D C:\Users\Marcin\Desktop\DOKTORAT 2013-10-26 18:43 - 2013-10-26 18:52 - 00000000 ____D C:\Users\Marcin\Desktop\REGULAMIN BEZTV 2013-10-26 17:06 - 2013-10-26 17:06 - 00046902 _____ C:\Users\Marcin\Downloads\update_3.0.12-RC3_to_3.0.12.zip 2013-10-26 17:01 - 2013-10-26 17:06 - 00000000 ____D C:\Users\Marcin\Desktop\APGRADE FORUM 2013-10-26 16:47 - 2013-10-26 16:47 - 00262511 _____ C:\Users\Marcin\Downloads\phpBB-3.0.12-RC3_to_3.0.12.zip 2013-10-26 11:07 - 2013-10-26 11:07 - 00000000 ____D C:\Users\Marcin\Documents\Notesy programu OneNote 2013-10-21 23:18 - 2013-10-21 23:27 - 358951544 _____ (Incomedia s.r.l. ) C:\Users\Marcin\Downloads\wsx5_pro(1).exe 2013-10-21 15:38 - 2013-10-21 23:09 - 00000000 ____D C:\Program Files\Mozilla Thunderbird 2013-10-21 01:34 - 2013-10-11 15:48 - 00030520 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2013-10-21 01:34 - 2013-10-11 15:48 - 00022328 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2013-10-21 01:31 - 2013-10-21 01:31 - 00001883 _____ C:\Users\Public\Desktop\TuneUp Konserwacja 1 kliknięciem.lnk 2013-10-21 01:31 - 2013-10-21 01:31 - 00001869 _____ C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk 2013-10-21 01:31 - 2013-10-11 15:48 - 00032568 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2013-10-21 01:30 - 2013-10-21 01:33 - 00000000 ____D C:\Program Files\TuneUp Utilities 2013 2013-10-21 01:14 - 2013-10-21 23:23 - 00000956 _____ C:\Users\Public\Desktop\WebSite X5 Professional 10.lnk 2013-10-21 01:12 - 2013-10-21 23:23 - 00000000 ____D C:\Program Files\WebSite X5 v10 - Professional 2013-10-21 01:04 - 2013-10-21 01:04 - 28716896 _____ (TuneUp Software) C:\Users\Marcin\Downloads\TuneUpUtilities2013_pl-PL.exe 2013-10-21 01:04 - 2013-10-21 01:04 - 28716896 _____ (TuneUp Software) C:\Users\Marcin\Downloads\TuneUpUtilities2013_pl-PL(1).exe 2013-10-21 00:58 - 2013-10-21 01:09 - 358951544 _____ (Incomedia s.r.l. ) C:\Users\Marcin\Downloads\wsx5_pro.exe 2013-10-16 21:53 - 2013-10-16 21:55 - 263821086 _____ C:\Users\Marcin\Downloads\P1090765.MOV 2013-10-16 15:01 - 2013-10-16 15:01 - 00036480 _____ C:\Users\Marcin\Downloads\minecraft_elephant.zip 2013-10-15 23:37 - 2013-10-15 23:37 - 00143640 _____ C:\Windows\Minidump\Mini101613-01.dmp 2013-10-14 20:20 - 2013-10-14 20:20 - 00050592 _____ C:\Users\Marcin\AppData\Local\Tempupdater_pol.dll 2013-10-14 19:51 - 2013-10-14 19:51 - 00037971 _____ C:\Users\Marcin\Desktop\51,104403,13005413.html 2013-10-11 18:22 - 2013-10-11 18:22 - 00143640 _____ C:\Windows\Minidump\Mini101113-01.dmp 2013-10-11 07:02 - 2013-09-22 11:29 - 12336128 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-11 07:02 - 2013-09-22 11:22 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-11 07:02 - 2013-09-22 11:22 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-11 07:02 - 2013-09-22 11:14 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-10-11 07:02 - 2013-09-22 11:13 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-11 07:02 - 2013-09-22 11:13 - 01104896 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-11 07:02 - 2013-09-22 11:12 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-10-11 07:02 - 2013-09-22 11:09 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-11 07:02 - 2013-09-22 11:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-10-11 07:02 - 2013-09-22 11:07 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-11 07:02 - 2013-09-22 11:06 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-10-11 07:02 - 2013-09-22 11:05 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-11 07:02 - 2013-09-22 11:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-11 07:02 - 2013-09-22 11:03 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-11 07:02 - 2013-09-22 11:03 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-10-11 07:02 - 2013-09-22 10:59 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-10 07:49 - 2013-08-29 08:56 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys 2013-10-10 07:49 - 2013-08-29 08:36 - 02050048 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-10 07:49 - 2013-08-27 03:47 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-10-10 07:49 - 2013-08-27 03:47 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-10-10 07:49 - 2013-08-27 03:47 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-10-10 07:49 - 2013-08-27 03:47 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-10-10 07:49 - 2013-08-27 02:52 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-10-10 07:49 - 2013-08-27 02:50 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-10-10 07:49 - 2013-08-27 02:32 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-10-10 07:49 - 2013-08-27 02:28 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-10-10 07:49 - 2013-08-27 02:28 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-10-10 07:49 - 2013-08-01 04:16 - 00638400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-10 07:49 - 2013-08-01 03:49 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-10-10 07:49 - 2013-07-20 11:44 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-10 07:49 - 2013-07-12 10:04 - 00134272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-10 07:49 - 2013-07-04 05:21 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-10 07:49 - 2013-07-03 03:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-10 07:49 - 2013-07-03 03:10 - 00025472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-10 07:49 - 2013-06-29 03:07 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-10 07:49 - 2013-06-29 03:07 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-10 07:49 - 2013-06-29 03:07 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-10 07:49 - 2013-06-29 03:06 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-10 07:49 - 2013-06-27 00:01 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-10 07:49 - 2013-06-04 05:16 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-10 07:49 - 2013-06-04 02:49 - 00293376 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-10 07:49 - 2011-05-05 14:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-10 07:49 - 2011-05-05 14:54 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-04 18:35 - 2013-10-04 18:35 - 01551008 _____ (Skype Technologies S.A.) C:\Users\Marcin\Downloads\SkypeSetup.exe ==================== One Month Modified Files and Folders ======= 2013-11-03 14:38 - 2009-06-25 17:00 - 01812667 _____ C:\Windows\WindowsUpdate.log 2013-11-03 14:27 - 2013-11-03 14:27 - 00377856 _____ C:\Users\Marcin\Downloads\nn62w4c1.exe 2013-11-03 14:16 - 2006-11-02 13:47 - 02394584 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-03 14:16 - 2006-11-02 13:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-03 14:15 - 2013-11-03 14:15 - 00143640 _____ C:\Windows\Minidump\Mini110313-01.dmp 2013-11-03 14:15 - 2012-07-10 11:58 - 432529522 _____ C:\Windows\MEMORY.DMP 2013-11-03 14:15 - 2012-07-10 11:58 - 00000000 ____D C:\Windows\Minidump 2013-11-03 14:15 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-03 14:15 - 2006-11-02 13:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-03 14:13 - 2013-11-03 14:13 - 00259584 _____ (OldTimer Tools) C:\Users\Marcin\Downloads\OTH.exe 2013-11-03 14:13 - 2013-11-03 14:13 - 00025635 _____ C:\Users\Marcin\Downloads\Addition.txt 2013-11-03 14:10 - 2013-11-03 14:10 - 00000000 ____D C:\FRST 2013-11-03 14:09 - 2012-07-17 00:56 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-03 14:08 - 2013-11-03 14:07 - 00602112 _____ (OldTimer Tools) C:\Users\Marcin\Downloads\OTL.exe 2013-11-03 14:07 - 2013-11-03 14:07 - 01089445 _____ (Farbar) C:\Users\Marcin\Downloads\FRST.exe 2013-11-03 10:32 - 2012-06-14 00:30 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-11-01 15:52 - 2013-11-01 15:52 - 00417792 _____ (ALK) C:\Users\Marcin\Downloads\PROXY-POL-2.exe 2013-11-01 15:51 - 2013-11-01 15:51 - 00403456 _____ (ALK) C:\Users\Marcin\Downloads\Proxy_Bazy_Danych_Biblioteki.exe 2013-11-01 11:57 - 2009-06-24 09:11 - 00758932 _____ C:\Windows\system32\perfh015.dat 2013-11-01 11:57 - 2009-06-24 09:11 - 00167700 _____ C:\Windows\system32\perfc015.dat 2013-11-01 11:57 - 2006-11-02 11:33 - 01739298 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-01 11:53 - 2010-01-24 17:27 - 00000000 ____D C:\Users\Marcin 2013-11-01 11:49 - 2008-01-21 03:47 - 01057428 _____ C:\Windows\PFRO.log 2013-10-31 00:20 - 2012-06-21 13:11 - 00000000 ____D C:\Users\Marcin\AppData\Roaming\HpUpdate 2013-10-31 00:20 - 2010-01-24 17:33 - 00000000 ____D C:\Users\Marcin\AppData\Local\Microsoft Help 2013-10-30 23:30 - 2013-10-30 23:29 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-30 19:04 - 2012-08-13 00:49 - 00000000 ____D C:\Users\Iwona 2013-10-30 19:04 - 2010-01-25 12:52 - 00000000 ____D C:\Users\Gość 2013-10-30 19:04 - 2006-11-02 11:22 - 60555264 _____ C:\Windows\system32\config\software_previous 2013-10-30 19:04 - 2006-11-02 11:22 - 28311552 _____ C:\Windows\system32\config\system_previous 2013-10-30 19:03 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\spool 2013-10-30 19:03 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\Msdtc 2013-10-30 19:03 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\registration 2013-10-30 19:00 - 2006-11-02 11:22 - 50855936 _____ C:\Windows\system32\config\components_previous 2013-10-30 19:00 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\sam_previous 2013-10-30 00:53 - 2006-11-02 11:22 - 00524288 _____ C:\Windows\system32\config\default_previous 2013-10-30 00:53 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\security_previous 2013-10-28 04:17 - 2009-06-25 17:01 - 00000012 _____ C:\Windows\bthservsdp.dat 2013-10-28 04:17 - 2006-11-02 14:01 - 00032514 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-28 03:10 - 2013-01-27 17:24 - 00000000 ____D C:\Users\Marcin\Desktop\FORUM BEZ TV 2013-10-28 02:01 - 2013-10-28 02:02 - 00899501 _____ C:\Users\Marcin\Downloads\insist_rel_1.0.0.zip 2013-10-27 23:35 - 2013-10-27 23:35 - 00000053 _____ C:\Users\Marcin\Desktop\google4359dc3850381357.html 2013-10-27 21:42 - 2013-10-27 21:42 - 00012762 _____ C:\Users\Marcin\AppData\Local\recently-used.xbel 2013-10-27 21:42 - 2012-07-15 10:15 - 00000000 ____D C:\Users\Marcin\.gimp-2.8 2013-10-27 20:00 - 2013-09-29 16:10 - 00000000 ____D C:\Users\Marcin\Desktop\AAA STRONA 2013-10-26 20:26 - 2013-10-26 20:26 - 00406869 _____ C:\Users\Marcin\Downloads\myInvision_3.0.zip 2013-10-26 19:35 - 2013-10-26 19:29 - 00000000 ____D C:\Users\Marcin\Desktop\DOKTORAT 2013-10-26 18:52 - 2013-10-26 18:43 - 00000000 ____D C:\Users\Marcin\Desktop\REGULAMIN BEZTV 2013-10-26 17:06 - 2013-10-26 17:06 - 00046902 _____ C:\Users\Marcin\Downloads\update_3.0.12-RC3_to_3.0.12.zip 2013-10-26 17:06 - 2013-10-26 17:01 - 00000000 ____D C:\Users\Marcin\Desktop\APGRADE FORUM 2013-10-26 16:47 - 2013-10-26 16:47 - 00262511 _____ C:\Users\Marcin\Downloads\phpBB-3.0.12-RC3_to_3.0.12.zip 2013-10-26 11:07 - 2013-10-26 11:07 - 00000000 ____D C:\Users\Marcin\Documents\Notesy programu OneNote 2013-10-22 01:26 - 2013-09-30 20:17 - 00000000 ____D C:\Users\Marcin\Desktop\aaaorg.pl - support 2013-10-21 23:27 - 2013-10-21 23:18 - 358951544 _____ (Incomedia s.r.l. ) C:\Users\Marcin\Downloads\wsx5_pro(1).exe 2013-10-21 23:27 - 2012-06-12 23:38 - 00000000 ____D C:\Users\Marcin\Documents\Incomedia 2013-10-21 23:23 - 2013-10-21 01:14 - 00000956 _____ C:\Users\Public\Desktop\WebSite X5 Professional 10.lnk 2013-10-21 23:23 - 2013-10-21 01:12 - 00000000 ____D C:\Program Files\WebSite X5 v10 - Professional 2013-10-21 23:09 - 2013-10-21 15:38 - 00000000 ____D C:\Program Files\Mozilla Thunderbird 2013-10-21 01:41 - 2012-12-03 21:11 - 00000000 __SHD C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} 2013-10-21 01:33 - 2013-10-21 01:30 - 00000000 ____D C:\Program Files\TuneUp Utilities 2013 2013-10-21 01:31 - 2013-10-21 01:31 - 00001883 _____ C:\Users\Public\Desktop\TuneUp Konserwacja 1 kliknięciem.lnk 2013-10-21 01:31 - 2013-10-21 01:31 - 00001869 _____ C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk 2013-10-21 01:29 - 2012-12-03 21:11 - 00000000 ____D C:\ProgramData\TuneUp Software 2013-10-21 01:14 - 2012-06-12 23:38 - 00000000 ____D C:\Users\Marcin\AppData\Local\Incomedia 2013-10-21 01:09 - 2013-10-21 00:58 - 358951544 _____ (Incomedia s.r.l. ) C:\Users\Marcin\Downloads\wsx5_pro.exe 2013-10-21 01:04 - 2013-10-21 01:04 - 28716896 _____ (TuneUp Software) C:\Users\Marcin\Downloads\TuneUpUtilities2013_pl-PL.exe 2013-10-21 01:04 - 2013-10-21 01:04 - 28716896 _____ (TuneUp Software) C:\Users\Marcin\Downloads\TuneUpUtilities2013_pl-PL(1).exe 2013-10-16 21:55 - 2013-10-16 21:53 - 263821086 _____ C:\Users\Marcin\Downloads\P1090765.MOV 2013-10-16 15:01 - 2013-10-16 15:01 - 00036480 _____ C:\Users\Marcin\Downloads\minecraft_elephant.zip 2013-10-16 07:47 - 2013-09-29 22:33 - 00000000 ____D C:\Users\Marcin\Desktop\PREZENTACJA AAAORG.PL 2013-10-15 23:37 - 2013-10-15 23:37 - 00143640 _____ C:\Windows\Minidump\Mini101613-01.dmp 2013-10-15 09:54 - 2013-07-19 20:33 - 00000000 ____D C:\Users\Marcin\Desktop\SZKOŁA SURFINGU 2013-10-15 09:54 - 2013-01-27 17:18 - 00000000 ____D C:\Users\Marcin\Desktop\INNE 2013-10-15 09:52 - 2013-04-07 21:23 - 00000000 ____D C:\Users\Marcin\Desktop\STUDIA DOKTORANCKIE 2013-10-15 09:49 - 2013-08-24 13:05 - 00000000 ____D C:\Users\Marcin\Desktop\EGZAMIN 2013-10-15 08:55 - 2012-07-25 17:06 - 00000000 ____D C:\Users\Marcin\Documents\My Scans 2013-10-14 20:26 - 2012-07-15 10:33 - 00000000 ____D C:\Users\Marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pixelplan 2013-10-14 20:20 - 2013-10-14 20:20 - 00050592 _____ C:\Users\Marcin\AppData\Local\Tempupdater_pol.dll 2013-10-14 19:51 - 2013-10-14 19:51 - 00037971 _____ C:\Users\Marcin\Desktop\51,104403,13005413.html 2013-10-11 18:22 - 2013-10-11 18:22 - 00143640 _____ C:\Windows\Minidump\Mini101113-01.dmp 2013-10-11 15:48 - 2013-10-21 01:34 - 00030520 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2013-10-11 15:48 - 2013-10-21 01:34 - 00022328 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2013-10-11 15:48 - 2013-10-21 01:31 - 00032568 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2013-10-11 07:35 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-10-11 07:26 - 2012-06-14 00:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-11 07:22 - 2013-04-14 18:22 - 00016400 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2013-10-11 07:22 - 2013-04-14 18:22 - 00003448 _____ C:\Windows\LkmdfCoInst.log 2013-10-11 07:19 - 2010-01-24 17:33 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-10-11 07:15 - 2013-08-14 09:08 - 00000000 ____D C:\Windows\system32\MRT 2013-10-11 07:07 - 2006-11-02 11:24 - 78106760 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-10-10 11:47 - 2013-08-11 19:35 - 00000000 ____D C:\Users\Marcin\Desktop\ACADEMY OF INNOVATION 2013-10-09 07:09 - 2012-06-17 21:35 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-10-09 07:09 - 2012-06-17 21:35 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-10-08 21:44 - 2012-09-03 17:25 - 00000000 ____D C:\Users\Marcin\AppData\Roaming\Skype 2013-10-07 01:32 - 2013-09-29 21:47 - 00000000 ____D C:\Users\Marcin\Desktop\GALERIA DE POMPADOUR 2013-10-04 18:35 - 2013-10-04 18:35 - 01551008 _____ (Skype Technologies S.A.) C:\Users\Marcin\Downloads\SkypeSetup.exe Some content of TEMP: ==================== C:\Users\Gość\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe C:\Users\Iwona\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe C:\Users\Marcin\AppData\Local\Temp\NOSEventMessages.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-03 14:23 ==================== End Of Log ============================