Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013 Ran by Szymon (administrator) on SZYMON-KOMPUTER on 10-11-2013 23:05:46 Running from C:\Users\Szymon\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIIME.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\WifiManager.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\dmhkcore.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\SmartSetting.exe (Intel Corporation) C:\windows\system32\igfxext.exe (Intel Corporation) C:\windows\system32\igfxsrvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (Intel Corporation) C:\windows\system32\hkcmd.exe (Intel Corporation) C:\windows\system32\igfxtray.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Control Center\EasySpeedUpManager.exe (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (BitTorrent Inc.) C:\Users\Szymon\AppData\Roaming\uTorrent\uTorrent.exe (OldTimer Tools) C:\Users\Szymon\Downloads\OTL.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11855976 2011-05-19] (Realtek Semiconductor) HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2588968 2012-10-13] (ELAN Microelectronics Corp.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [EPLTarget\P0000000000000001] - C:\Windows\System32\spool\drivers\x64\3\E_IATIIME.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION) MountPoints2: {48d0f46b-500b-11e2-9293-e8039a95a1b5} - F:\AutoRun.exe MountPoints2: {48d0f46d-500b-11e2-9293-e8039a95a1b5} - F:\AutoRun.exe MountPoints2: {48d0f47c-500b-11e2-9293-e8039a95a1b5} - F:\AutoRun.exe MountPoints2: {48d0f483-500b-11e2-9293-e8039a95a1b5} - F:\AutoRun.exe MountPoints2: {5f2709d9-c231-11e2-bb71-b8030542d6b8} - I:\autorun.exe MountPoints2: {e4a0beaa-c21d-11e2-9b7f-b8030542d6b8} - F:\Autorun.exe MountPoints2: {e4a0bedf-c21d-11e2-9b7f-b8030542d6b8} - G:\Autorun.exe MountPoints2: {e7f0f619-1c45-11e3-8028-b8030542d6b8} - G:\autorun.exe MountPoints2: {e7f0f632-1c45-11e3-8028-b8030542d6b8} - I:\setup.exe /autorun MountPoints2: {ecc0e542-e972-11e2-8b21-b8030542d6b8} - J:\AutoRun.exe MountPoints2: {ecc0e548-e972-11e2-8b21-b8030542d6b8} - J:\AutoRun.exe HKLM-x32\...\Run: [AvastUI.exe] - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-10] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1673680 2013-10-23] (APN) HKU\balblaniec\...\RunOnce: [FlashPlayerUpdate] - C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_224_Plugin.exe -update plugin HKU\UpdatusUser\...\RunOnce: [avg_spchecker] - "C:\Program Files (x86)\AVG\AVG9\Notification\SPChecker1.exe" /start AppInit_DLLs: c:\windows\system32\nvinitx.dll [226920 2011-03-07] (NVIDIA Corporation) AppInit_DLLs-x32: c:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll [ ] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie URLSearchHook: HKCU - (No Name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {5FD54E6B-8914-40F6-AA38-8FCE13F45489} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=YYYYYYYYPL&apn_uid=1B7FAEAA-70C1-41E0-B981-CD9EC53AEBEE&apn_sauid=78F500BA-3624-485D-904B-060257741D40 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear SearchScopes: HKCU - {AC42E18F-AD00-4ECF-B304-EA80C2D999AF} URL = http://www.bing.com/search?q={searchTerms}&r= SearchScopes: HKCU - {D0B62FE5-8FA3-4F7E-B727-A85E55D1A040} URL = http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll No File BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) BHO-x32: No Name - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No File BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Samsung BHO Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll () BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll No File Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - No Name - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No File Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKCU - No Name - {687578B9-7132-4A7A-80E4-30EE31099E03} - No File DPF: HKLM-x32 {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Szymon\AppData\Roaming\Mozilla\Firefox\Profiles\e5d26kaf.default FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Szymon\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Szymon\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\avg_igeared.xml FF Extension: BrowseFox - C:\Users\Szymon\AppData\Roaming\Mozilla\Firefox\Profiles\e5d26kaf.default\Extensions\firefox@browsefox.com FF Extension: FT Downloader - C:\Users\Szymon\AppData\Roaming\Mozilla\Firefox\Profiles\e5d26kaf.default\Extensions\ftd@ftd.com FF Extension: ftd - C:\Users\Szymon\AppData\Roaming\Mozilla\Firefox\Profiles\e5d26kaf.default\Extensions\ftd@ftd.com.xpi FF Extension: toolbar_AVIRA-V7 - C:\Users\Szymon\AppData\Roaming\Mozilla\Firefox\Profiles\e5d26kaf.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\Szymon\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh\25.62074_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Szymon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440392 2013-10-10] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-10] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1164360 2013-10-10] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.) S4 EpsonScanSvc; C:\windows\system32\EscSvc64.exe [135824 2011-12-11] (Seiko Epson Corporation) R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) S4 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) S4 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-23] () S3 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105856 2013-10-10] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-10-10] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-10] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [83160 2013-10-10] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-09-13] (Disc Soft Ltd) S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-03-13] (Windows (R) 2003 DDK 3790 provider) S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [x] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [x] S3 huawei_cdcecm; system32\DRIVERS\ew_jucdcecm.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-10 22:47 - 2013-11-10 22:47 - 00000000 ____D C:\Users\Szymon\Desktop\sesja z NataliaK 2013-11-10 21:25 - 2013-11-10 21:25 - 00049614 _____ C:\Users\Szymon\Desktop\08e0189a3d.jpeg 2013-11-10 19:53 - 2013-11-10 19:53 - 00000000 ____D C:\Users\Szymon\Desktop\don pedro foty 2013-11-10 09:16 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys 2013-11-10 09:16 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys 2013-11-10 09:16 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys 2013-11-10 09:16 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys 2013-11-10 09:16 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys 2013-11-10 09:16 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys 2013-11-10 09:16 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys 2013-11-07 16:50 - 2013-11-07 16:54 - 00000000 ____D C:\AdwCleaner 2013-11-07 16:37 - 2013-11-07 16:38 - 01073262 _____ C:\Users\Szymon\Downloads\AdwCleaner.exe 2013-11-06 20:39 - 2013-11-07 17:05 - 00606398 _____ C:\Users\Szymon\Downloads\avgremover.log 2013-11-06 20:39 - 2013-11-06 20:39 - 03529160 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Szymon\Downloads\avg_remover_stf_x86_2013_3341(1).exe 2013-11-06 20:36 - 2013-11-06 20:36 - 03529160 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Szymon\Downloads\avg_remover_stf_x86_2013_3341.exe 2013-11-06 18:12 - 2013-11-06 18:12 - 00000000 ____D C:\ProgramData\F-Secure-UninstallationTool 2013-11-06 18:08 - 2013-11-06 18:08 - 00883183 _____ C:\Users\Szymon\Downloads\UninstallationTool.zip 2013-11-06 17:52 - 2013-11-06 17:52 - 00000000 ____D C:\Users\Szymon\AppData\Roaming\Avira 2013-11-06 17:48 - 2013-11-06 17:48 - 00350080 _____ (AVAST Software) C:\Users\Szymon\Downloads\avastclear.exe 2013-11-06 17:48 - 2013-11-06 17:48 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2013-11-06 17:48 - 2013-11-06 17:48 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork 2013-11-06 17:47 - 2013-11-06 17:47 - 00002026 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-11-06 17:47 - 2013-11-06 17:47 - 00000000 ____D C:\ProgramData\Avira 2013-11-06 17:47 - 2013-11-06 17:47 - 00000000 ____D C:\ProgramData\APN 2013-11-06 17:47 - 2013-11-06 17:47 - 00000000 ____D C:\Program Files (x86)\Avira 2013-11-06 17:47 - 2013-10-10 19:14 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys 2013-11-06 17:47 - 2013-10-10 19:14 - 00105856 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys 2013-11-06 17:47 - 2013-10-10 19:14 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys 2013-11-06 17:47 - 2013-10-10 19:14 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys 2013-11-06 17:36 - 2013-11-06 17:40 - 123650800 _____ C:\Users\Szymon\Downloads\avira_free_antivirus_en.exe 2013-11-06 17:29 - 2013-11-06 17:29 - 01898232 _____ (Bleeping Computer, LLC) C:\Users\Szymon\Downloads\rkill.exe 2013-11-06 17:11 - 2013-11-06 17:11 - 00004041 _____ C:\Users\Szymon\Downloads\GMER.txt 2013-11-06 16:59 - 2013-11-06 16:59 - 00377856 _____ C:\Users\Szymon\Downloads\q0yn7n8l.exe 2013-11-06 16:57 - 2013-11-06 16:57 - 00377856 _____ C:\Users\Szymon\Downloads\znmngv1g.exe 2013-11-06 16:26 - 2013-11-06 16:57 - 00034759 _____ C:\Users\Szymon\Downloads\Addition.txt 2013-11-06 16:25 - 2013-11-06 16:25 - 00000000 ____D C:\FRST 2013-11-06 16:24 - 2013-11-06 16:24 - 01957098 _____ (Farbar) C:\Users\Szymon\Downloads\FRST64.exe 2013-11-06 16:07 - 2013-11-06 16:58 - 00145070 _____ C:\Users\Szymon\Downloads\Extras.Txt 2013-11-06 16:06 - 2013-11-06 16:14 - 00184616 _____ C:\Users\Szymon\Downloads\OTL.Txt 2013-11-06 15:56 - 2013-11-06 15:56 - 00602112 _____ (OldTimer Tools) C:\Users\Szymon\Downloads\OTL.exe 2013-11-06 15:18 - 2013-11-06 18:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-06 15:14 - 2013-11-06 15:14 - 05144303 _____ (Swearware) C:\Users\Szymon\Downloads\ComboFix.exe 2013-11-05 15:41 - 2013-11-05 15:42 - 00000000 ____D C:\Users\Szymon\Downloads\TMK aka PiekielnyR-Ice Kilka kartek LP 2013-11-05 15:40 - 2013-11-05 15:40 - 00021465 _____ C:\Users\Szymon\Downloads\[www.tnt24.info] TMK aka PiekielnyR-Ice Kilka kartek LP [2013][ Mp3@320kbps ][Stix93 ].torrent 2013-11-03 21:22 - 2013-11-03 21:22 - 00000000 ____D C:\Users\Szymon\Desktop\FERIE 2013 2013-11-03 20:35 - 2013-11-03 20:35 - 00000000 ____D C:\Users\Szymon\AppData\Local\{97BCA04A-68B7-4F35-B97A-9DC72B1011BE} 2013-11-03 20:02 - 2013-11-03 20:02 - 00003380 _____ C:\windows\System32\Tasks\Odkurzacz 2013-11-03 20:02 - 2013-11-03 20:02 - 00001019 _____ C:\Users\Szymon\Desktop\Odkurzacz.lnk 2013-11-03 20:02 - 2013-11-03 20:02 - 00000000 ____D C:\Program Files (x86)\Odkurzacz 2013-11-03 19:58 - 2013-11-03 19:58 - 03841551 _____ (FranmoSoftware ) C:\Users\Szymon\Downloads\odk13.4.0.1685setup(dobreprogramy.pl).exe 2013-11-03 19:57 - 2013-11-03 19:57 - 00685248 _____ C:\Users\Szymon\Downloads\Odkurzacz(12322).exe 2013-11-01 12:33 - 2013-11-01 12:33 - 00000000 ____D C:\Users\Szymon\AppData\Local\{57A311A6-937E-41D9-930D-7DCE558F0FE1} 2013-11-01 00:32 - 2013-11-01 00:32 - 00000000 ____D C:\Users\Szymon\AppData\Local\{9C5F4C3A-8249-4DBC-AEE4-35F1C6E46B88} 2013-10-31 15:36 - 2013-10-31 15:36 - 00000859 _____ C:\Users\Szymon\Desktop\µTorrent.lnk 2013-10-31 15:36 - 2013-10-31 15:36 - 00000839 _____ C:\Users\Szymon\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2013-10-31 15:33 - 2013-11-10 23:04 - 00000000 ____D C:\Users\Szymon\AppData\Roaming\uTorrent 2013-10-31 15:33 - 2013-11-10 22:35 - 00000292 _____ C:\windows\Tasks\FoxTab.job 2013-10-31 15:33 - 2013-10-31 15:33 - 00003248 _____ C:\windows\System32\Tasks\FoxTab 2013-10-31 15:33 - 2013-10-31 15:32 - 01141328 _____ (BitTorrent Inc.) C:\Users\Szymon\Downloads\utorrent(dobreprogramy.pl).exe 2013-10-31 14:28 - 2013-11-10 15:54 - 00000000 ____D C:\Users\Szymon\Desktop\zdjęcia 2013-10-30 13:29 - 2013-11-07 17:05 - 00000000 _____ C:\windows\SysWOW64\config.nt 2013-10-29 19:05 - 2013-10-29 19:05 - 00122482 _____ C:\Users\Szymon\Documents\plpl.xps 2013-10-29 19:02 - 2013-10-29 19:02 - 01330239 _____ C:\Users\Szymon\Documents\uhjk.xps 2013-10-29 18:44 - 2013-10-29 18:44 - 01330239 _____ C:\Users\Szymon\Documents\drukowanie.xps 2013-10-29 18:42 - 2013-10-29 18:42 - 00472449 _____ C:\Users\Szymon\Documents\ss.xps 2013-10-29 11:44 - 2013-10-29 11:44 - 00000000 ____D C:\Users\Szymon\AppData\Roaming\AVAST Software 2013-10-22 08:53 - 2013-10-22 08:53 - 00000000 _____ C:\windows\SysWOW64\sho9CE0.tmp 2013-10-20 00:06 - 2013-10-20 00:06 - 00114384 _____ C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-20 00:06 - 2013-10-20 00:06 - 00114384 _____ C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-20 00:06 - 2013-10-20 00:06 - 00000000 ____D C:\Users\Default\Documents\Visual Studio 2010 2013-10-20 00:06 - 2013-10-20 00:06 - 00000000 ____D C:\Users\Default User\Documents\Visual Studio 2010 2013-10-18 18:06 - 2009-07-22 09:17 - 00111640 _____ (Microsoft Corporation) C:\windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll 2013-10-18 18:06 - 2009-07-22 09:17 - 00079896 _____ (Microsoft Corporation) C:\windows\SysWOW64\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll 2013-10-18 18:06 - 2009-07-22 09:17 - 00078872 _____ (Microsoft Corporation) C:\windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll 2013-10-18 18:06 - 2009-07-22 09:17 - 00050200 _____ (Microsoft Corporation) C:\windows\SysWOW64\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll 2013-10-18 18:04 - 2013-10-18 18:04 - 00000000 ____D C:\windows\system32\RsFx 2013-10-18 18:03 - 2013-10-18 18:03 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 9.0 2013-10-18 18:03 - 2013-10-18 18:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 9.0 2013-10-18 18:02 - 2013-10-18 18:02 - 00000000 ____D C:\windows\SysWOW64\1033 2013-10-18 18:02 - 2013-10-18 18:02 - 00000000 ____D C:\windows\system32\1033 2013-10-18 17:49 - 2013-10-18 18:03 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2013-10-18 17:48 - 2013-10-18 18:04 - 00000000 ____D C:\Program Files\Microsoft SQL Server 2013-10-18 17:47 - 2013-10-18 17:47 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services 2013-10-18 17:47 - 2013-10-18 17:47 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-10-18 17:46 - 2013-10-18 17:46 - 00000000 ____D C:\Users\Szymon\Documents\Visual Studio 2010 2013-10-18 17:42 - 2013-10-18 17:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 10.0 2013-10-18 17:41 - 2013-10-18 17:41 - 00000000 ____D C:\windows\symbols 2013-10-18 17:41 - 2013-10-18 17:41 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0 2013-10-18 17:41 - 2013-10-18 17:41 - 00000000 ____D C:\Program Files\Microsoft Help Viewer 2013-10-18 17:41 - 2013-10-18 17:41 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs 2013-10-18 17:35 - 2013-10-18 17:35 - 03324232 _____ (Microsoft Corporation) C:\Users\Szymon\Downloads\vc_web.exe ==================== One Month Modified Files and Folders ======= 2013-11-10 23:04 - 2013-10-31 15:33 - 00000000 ____D C:\Users\Szymon\AppData\Roaming\uTorrent 2013-11-10 22:47 - 2013-11-10 22:47 - 00000000 ____D C:\Users\Szymon\Desktop\sesja z NataliaK 2013-11-10 22:41 - 2011-06-25 07:47 - 01318391 _____ C:\windows\WindowsUpdate.log 2013-11-10 22:35 - 2013-10-31 15:33 - 00000292 _____ C:\windows\Tasks\FoxTab.job 2013-11-10 22:35 - 2012-08-14 21:19 - 00000932 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3099691929-597136357-677967994-1002UA.job 2013-11-10 22:35 - 2012-06-14 21:59 - 00001048 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-10 21:25 - 2013-11-10 21:25 - 00049614 _____ C:\Users\Szymon\Desktop\08e0189a3d.jpeg 2013-11-10 19:54 - 2011-06-25 07:17 - 00810978 _____ C:\windows\system32\perfh015.dat 2013-11-10 19:54 - 2011-06-25 07:17 - 00183224 _____ C:\windows\system32\perfc015.dat 2013-11-10 19:54 - 2009-07-14 06:13 - 01870230 _____ C:\windows\system32\PerfStringBackup.INI 2013-11-10 19:53 - 2013-11-10 19:53 - 00000000 ____D C:\Users\Szymon\Desktop\don pedro foty 2013-11-10 18:42 - 2009-07-14 05:45 - 00021536 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-10 18:42 - 2009-07-14 05:45 - 00021536 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-10 18:36 - 2012-06-14 21:59 - 00001044 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-10 18:34 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT 2013-11-10 18:34 - 2009-07-14 05:51 - 00162853 _____ C:\windows\setupact.log 2013-11-10 17:09 - 2009-07-14 06:32 - 00000000 ____D C:\windows\system32\FxsTmp 2013-11-10 15:54 - 2013-10-31 14:28 - 00000000 ____D C:\Users\Szymon\Desktop\zdjęcia 2013-11-10 15:51 - 2013-02-15 12:10 - 00000000 ___HD C:\Users\Szymon\Desktop\.picasaoriginals 2013-11-10 13:34 - 2012-08-14 21:19 - 00000910 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3099691929-597136357-677967994-1002Core.job 2013-11-10 10:54 - 2013-09-29 12:21 - 00000000 ____D C:\Users\Szymon\Documents\Euro Truck Simulator 2 2013-11-10 09:51 - 2013-05-27 18:56 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-10 09:11 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\NDF 2013-11-07 17:05 - 2013-11-06 20:39 - 00606398 _____ C:\Users\Szymon\Downloads\avgremover.log 2013-11-07 17:05 - 2013-10-30 13:29 - 00000000 _____ C:\windows\SysWOW64\config.nt 2013-11-07 17:05 - 2013-01-13 14:44 - 00000000 ____D C:\ProgramData\AVAST Software 2013-11-07 16:59 - 2012-05-28 20:35 - 00000000 ____D C:\Users\Szymon\AppData\Roaming\GG 2013-11-07 16:54 - 2013-11-07 16:50 - 00000000 ____D C:\AdwCleaner 2013-11-07 16:53 - 2013-07-21 19:43 - 00001246 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-07 16:53 - 2013-06-05 08:34 - 00000999 _____ C:\Users\Szymon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-07 16:53 - 2012-10-20 18:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-07 16:53 - 2012-05-28 17:48 - 00001009 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-11-07 16:38 - 2013-11-07 16:37 - 01073262 _____ C:\Users\Szymon\Downloads\AdwCleaner.exe 2013-11-06 20:39 - 2013-11-06 20:39 - 03529160 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Szymon\Downloads\avg_remover_stf_x86_2013_3341(1).exe 2013-11-06 20:36 - 2013-11-06 20:36 - 03529160 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Szymon\Downloads\avg_remover_stf_x86_2013_3341.exe 2013-11-06 20:28 - 2012-05-28 20:35 - 00000000 ____D C:\Users\Szymon\AppData\Local\GG 2013-11-06 18:21 - 2013-01-13 18:25 - 00000000 ____D C:\Program Files (x86)\mmp 2013-11-06 18:20 - 2013-11-06 15:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-06 18:20 - 2013-01-13 18:22 - 00000000 ____D C:\ProgramData\f-secure 2013-11-06 18:12 - 2013-11-06 18:12 - 00000000 ____D C:\ProgramData\F-Secure-UninstallationTool 2013-11-06 18:08 - 2013-11-06 18:08 - 00883183 _____ C:\Users\Szymon\Downloads\UninstallationTool.zip 2013-11-06 17:52 - 2013-11-06 17:52 - 00000000 ____D C:\Users\Szymon\AppData\Roaming\Avira 2013-11-06 17:48 - 2013-11-06 17:48 - 00350080 _____ (AVAST Software) C:\Users\Szymon\Downloads\avastclear.exe 2013-11-06 17:48 - 2013-11-06 17:48 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2013-11-06 17:48 - 2013-11-06 17:48 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork 2013-11-06 17:47 - 2013-11-06 17:47 - 00002026 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-11-06 17:47 - 2013-11-06 17:47 - 00000000 ____D C:\ProgramData\Avira 2013-11-06 17:47 - 2013-11-06 17:47 - 00000000 ____D C:\ProgramData\APN 2013-11-06 17:47 - 2013-11-06 17:47 - 00000000 ____D C:\Program Files (x86)\Avira 2013-11-06 17:40 - 2013-11-06 17:36 - 123650800 _____ C:\Users\Szymon\Downloads\avira_free_antivirus_en.exe 2013-11-06 17:29 - 2013-11-06 17:29 - 01898232 _____ (Bleeping Computer, LLC) C:\Users\Szymon\Downloads\rkill.exe 2013-11-06 17:11 - 2013-11-06 17:11 - 00004041 _____ C:\Users\Szymon\Downloads\GMER.txt 2013-11-06 16:59 - 2013-11-06 16:59 - 00377856 _____ C:\Users\Szymon\Downloads\q0yn7n8l.exe 2013-11-06 16:58 - 2013-11-06 16:07 - 00145070 _____ C:\Users\Szymon\Downloads\Extras.Txt 2013-11-06 16:57 - 2013-11-06 16:57 - 00377856 _____ C:\Users\Szymon\Downloads\znmngv1g.exe 2013-11-06 16:57 - 2013-11-06 16:26 - 00034759 _____ C:\Users\Szymon\Downloads\Addition.txt 2013-11-06 16:25 - 2013-11-06 16:25 - 00000000 ____D C:\FRST 2013-11-06 16:24 - 2013-11-06 16:24 - 01957098 _____ (Farbar) C:\Users\Szymon\Downloads\FRST64.exe 2013-11-06 16:14 - 2013-11-06 16:06 - 00184616 _____ C:\Users\Szymon\Downloads\OTL.Txt 2013-11-06 15:56 - 2013-11-06 15:56 - 00602112 _____ (OldTimer Tools) C:\Users\Szymon\Downloads\OTL.exe 2013-11-06 15:19 - 2012-05-28 18:04 - 00000000 ____D C:\Users\Szymon\AppData\Local\Mozilla 2013-11-06 15:14 - 2013-11-06 15:14 - 05144303 _____ (Swearware) C:\Users\Szymon\Downloads\ComboFix.exe 2013-11-06 14:50 - 2012-06-11 15:28 - 00000000 ____D C:\Users\Szymon\AppData\Roaming\WildTangent 2013-11-06 14:50 - 2011-06-24 16:09 - 00000000 ____D C:\ProgramData\WildTangent 2013-11-06 01:18 - 2013-07-27 10:18 - 00000108 _____ C:\Users\Szymon\AppData\Roaming\WB.CFG 2013-11-06 01:18 - 2013-06-17 07:53 - 00000006 _____ C:\Users\Szymon\AppData\Roaming\WBPU-TTL.DAT 2013-11-05 15:42 - 2013-11-05 15:41 - 00000000 ____D C:\Users\Szymon\Downloads\TMK aka PiekielnyR-Ice Kilka kartek LP 2013-11-05 15:40 - 2013-11-05 15:40 - 00021465 _____ C:\Users\Szymon\Downloads\[www.tnt24.info] TMK aka PiekielnyR-Ice Kilka kartek LP [2013][ Mp3@320kbps ][Stix93 ].torrent 2013-11-03 21:22 - 2013-11-03 21:22 - 00000000 ____D C:\Users\Szymon\Desktop\FERIE 2013 2013-11-03 20:37 - 2012-05-29 22:08 - 00000000 ____D C:\Users\Szymon\AppData\Local\Windows Live 2013-11-03 20:35 - 2013-11-03 20:35 - 00000000 ____D C:\Users\Szymon\AppData\Local\{97BCA04A-68B7-4F35-B97A-9DC72B1011BE} 2013-11-03 20:35 - 2012-05-28 19:36 - 00000000 ____D C:\Users\Szymon\Tracing 2013-11-03 20:16 - 2013-07-07 20:24 - 00000000 ____D C:\Users\Gość 2013-11-03 20:16 - 2013-07-05 15:18 - 00000000 ____D C:\Users\balblaniec 2013-11-03 20:16 - 2013-02-02 16:26 - 00000000 ____D C:\Users\Szymon\Documents\Youcam 2013-11-03 20:16 - 2012-09-03 16:11 - 00000000 ____D C:\Users\Szymon\AppData\Roaming\skypePM 2013-11-03 20:16 - 2012-05-28 17:29 - 00000000 ____D C:\Users\Szymon 2013-11-03 20:16 - 2011-02-11 20:56 - 00000000 ____D C:\windows\Sec 2013-11-03 20:08 - 2012-05-28 17:36 - 00000000 ____D C:\ProgramData\Skype 2013-11-03 20:03 - 2012-10-02 19:31 - 00000000 ____D C:\windows\Minidump 2013-11-03 20:03 - 2012-06-05 08:48 - 00000000 ____D C:\Users\Szymon\AppData\Local\CrashDumps 2013-11-03 20:02 - 2013-11-03 20:02 - 00003380 _____ C:\windows\System32\Tasks\Odkurzacz 2013-11-03 20:02 - 2013-11-03 20:02 - 00001019 _____ C:\Users\Szymon\Desktop\Odkurzacz.lnk 2013-11-03 20:02 - 2013-11-03 20:02 - 00000000 ____D C:\Program Files (x86)\Odkurzacz 2013-11-03 19:58 - 2013-11-03 19:58 - 03841551 _____ (FranmoSoftware ) C:\Users\Szymon\Downloads\odk13.4.0.1685setup(dobreprogramy.pl).exe 2013-11-03 19:57 - 2013-11-03 19:57 - 00685248 _____ C:\Users\Szymon\Downloads\Odkurzacz(12322).exe 2013-11-03 19:38 - 2011-06-24 16:13 - 00000000 ____D C:\ProgramData\Norton 2013-11-03 10:06 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache 2013-11-01 12:33 - 2013-11-01 12:33 - 00000000 ____D C:\Users\Szymon\AppData\Local\{57A311A6-937E-41D9-930D-7DCE558F0FE1} 2013-11-01 10:27 - 2013-04-21 17:38 - 00000000 ____D C:\Program Files (x86)\FLVPlayer 2013-11-01 10:26 - 2013-05-29 15:18 - 00000000 ____D C:\Users\Szymon\AppData\Roaming\Zip Opener Packages 2013-11-01 00:32 - 2013-11-01 00:32 - 00000000 ____D C:\Users\Szymon\AppData\Local\{9C5F4C3A-8249-4DBC-AEE4-35F1C6E46B88} 2013-10-31 15:36 - 2013-10-31 15:36 - 00000859 _____ C:\Users\Szymon\Desktop\µTorrent.lnk 2013-10-31 15:36 - 2013-10-31 15:36 - 00000839 _____ C:\Users\Szymon\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2013-10-31 15:33 - 2013-10-31 15:33 - 00003248 _____ C:\windows\System32\Tasks\FoxTab 2013-10-31 15:32 - 2013-10-31 15:33 - 01141328 _____ (BitTorrent Inc.) C:\Users\Szymon\Downloads\utorrent(dobreprogramy.pl).exe 2013-10-31 14:29 - 2013-04-20 10:16 - 00000000 ____D C:\Users\Szymon\Desktop\Paulc 2013-10-30 11:34 - 2013-09-22 15:26 - 00000000 ____D C:\Program Files (x86)\AP Tuner 2013-10-29 19:05 - 2013-10-29 19:05 - 00122482 _____ C:\Users\Szymon\Documents\plpl.xps 2013-10-29 19:02 - 2013-10-29 19:02 - 01330239 _____ C:\Users\Szymon\Documents\uhjk.xps 2013-10-29 18:44 - 2013-10-29 18:44 - 01330239 _____ C:\Users\Szymon\Documents\drukowanie.xps 2013-10-29 18:42 - 2013-10-29 18:42 - 00472449 _____ C:\Users\Szymon\Documents\ss.xps 2013-10-29 11:44 - 2013-10-29 11:44 - 00000000 ____D C:\Users\Szymon\AppData\Roaming\AVAST Software 2013-10-29 10:18 - 2012-12-25 18:29 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\CrashDumps 2013-10-27 19:02 - 2012-06-04 11:18 - 00000000 ____D C:\Users\Szymon\AppData\Roaming\Skype 2013-10-24 16:12 - 2009-07-14 00:39 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\msimtf.dll 2013-10-24 13:05 - 2013-05-29 14:19 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-10-22 08:53 - 2013-10-22 08:53 - 00000000 _____ C:\windows\SysWOW64\sho9CE0.tmp 2013-10-22 08:53 - 2013-02-13 15:06 - 2720512895 _____ C:\windows\ih8.config.xml.log 2013-10-20 00:06 - 2013-10-20 00:06 - 00114384 _____ C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-20 00:06 - 2013-10-20 00:06 - 00114384 _____ C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-20 00:06 - 2013-10-20 00:06 - 00000000 ____D C:\Users\Default\Documents\Visual Studio 2010 2013-10-20 00:06 - 2013-10-20 00:06 - 00000000 ____D C:\Users\Default User\Documents\Visual Studio 2010 2013-10-18 18:04 - 2013-10-18 18:04 - 00000000 ____D C:\windows\system32\RsFx 2013-10-18 18:04 - 2013-10-18 17:48 - 00000000 ____D C:\Program Files\Microsoft SQL Server 2013-10-18 18:03 - 2013-10-18 18:03 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 9.0 2013-10-18 18:03 - 2013-10-18 18:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 9.0 2013-10-18 18:03 - 2013-10-18 17:49 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2013-10-18 18:03 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-10-18 18:02 - 2013-10-18 18:02 - 00000000 ____D C:\windows\SysWOW64\1033 2013-10-18 18:02 - 2013-10-18 18:02 - 00000000 ____D C:\windows\system32\1033 2013-10-18 17:47 - 2013-10-18 17:47 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services 2013-10-18 17:47 - 2013-10-18 17:47 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2013-10-18 17:46 - 2013-10-18 17:46 - 00000000 ____D C:\Users\Szymon\Documents\Visual Studio 2010 2013-10-18 17:43 - 2013-10-18 17:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 10.0 2013-10-18 17:42 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\MSBuild 2013-10-18 17:41 - 2013-10-18 17:41 - 00000000 ____D C:\windows\symbols 2013-10-18 17:41 - 2013-10-18 17:41 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 10.0 2013-10-18 17:41 - 2013-10-18 17:41 - 00000000 ____D C:\Program Files\Microsoft Help Viewer 2013-10-18 17:41 - 2013-10-18 17:41 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs 2013-10-18 17:35 - 2013-10-18 17:35 - 03324232 _____ (Microsoft Corporation) C:\Users\Szymon\Downloads\vc_web.exe 2013-10-16 09:38 - 2009-07-14 06:08 - 00032608 _____ C:\windows\Tasks\SCHEDLGU.TXT Files to move or delete: ==================== C:\Users\Szymon\TSM.exe Some content of TEMP: ==================== C:\Users\Szymon\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-10 20:21 ==================== End Of Log ============================