Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-03-2014 Ran by user (administrator) on USER-PC on 08-03-2014 13:16:15 Running from C:\Users\user\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Polish Internet Explorer Version 9 Boot Mode: The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (The Within Network, LLC) C:\Windows\UnsignedThemesSvc.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe () C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2299176 2011-10-14] (Synaptics Incorporated) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10996368 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [323640 2009-11-24] ( Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [174872 2007-02-12] (Intel Corporation) HKLM\...\Run: [hpqSRMon] - C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [81920 2008-03-13] (Hewlett-Packard) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-1071776476-4060681110-2736522152-1000\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKU\S-1-5-21-1071776476-4060681110-2736522152-1000\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKU\S-1-5-21-1071776476-4060681110-2736522152-1000\...\Run: [ChomikBox] - C:\Program Files\ChomikBox\ChomikBox.exe [6017024 2014-02-12] ( ) HKU\S-1-5-21-1071776476-4060681110-2736522152-1000\...\RunOnce: [Report] - C:\AdwCleaner\AdwCleaner[S1].txt [1108 2014-03-08] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/ SearchScopes: HKLM - DefaultScope value is missing. BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 10.0.2.2 10.0.2.4 FireFox: ======== FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\svhhr2fi.default-1366323067869 FF NewTab: www.google.com FF SearchEngineOrder.1: Google FF SearchEngineOrder.3: Bing FF SelectedSearchEngine: Google FF Homepage: www.google.com FF Keyword.URL: https://www.google.com/search FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin: @real.com/nppl3260;version=16.0.1.18 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=16.0.1.18 - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2013-04-16] FF HKLM\...\Firefox\Extensions: [{DAC3F861-B30D-40dd-9166-F4E75327FAC7}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [] FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-05-02] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2013-04-16] Chrome: ======= CHR Extension: (Dokumenty Google) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-31] CHR Extension: (Dysk Google) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-31] CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-31] CHR Extension: (Szukaj w Google) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-31] CHR Extension: (RealDownloader) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-05-14] CHR Extension: (Google Wallet) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-19] CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-31] CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-03-06] ========================== Services (Whitelisted) ================= R2 CLCapSvc; C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe [262243 2007-04-23] () R2 CLSched; C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe [106593 2007-04-23] () R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-03-06] () R2 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [21096 2009-07-13] (The Within Network, LLC) ==================== Drivers (Whitelisted) ==================== R0 sptd; C:\Windows\System32\Drivers\sptd.sys [320120 2014-03-06] (Duplex Secure Ltd.) R2 uxpatch; C:\Windows\system32\drivers\uxpatch.sys [25448 2009-07-13] () S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [43904 2009-02-18] (Microsoft Corporation) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-08 12:59 - 2014-03-08 12:43 - 00003798 _____ () C:\Users\user\Documents\UPDATE.txt 2014-03-08 11:56 - 2014-03-08 11:56 - 00000000 ____D () C:\Users\user\AppData\Roaming\OpenOffice 2014-03-08 11:51 - 2014-03-08 11:51 - 00001007 _____ () C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk 2014-03-08 11:50 - 2014-03-08 11:50 - 00000000 ____D () C:\Program Files\OpenOffice 4 2014-03-08 11:47 - 2014-03-08 11:47 - 00162010 _____ () C:\Users\user\Downloads\DIAG_MATS_NETWORK_global.DiagCab 2014-03-08 11:30 - 2014-03-08 11:44 - 133661993 _____ () C:\Users\user\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_pl.exe 2014-03-08 11:13 - 2014-03-08 11:13 - 00347816 _____ (Microsoft Corporation) C:\Users\user\Downloads\MicrosoftFixit.wu.LB.1331770068167897.1.1.Run.exe 2014-03-08 10:34 - 2014-03-08 10:34 - 00448512 _____ (OldTimer Tools) C:\Users\user\Downloads\TFC.exe 2014-03-07 23:16 - 2014-03-08 10:28 - 00000000 ___DC () C:\AdwCleaner 2014-03-07 23:16 - 2014-03-07 23:16 - 01244192 _____ () C:\Users\user\Downloads\adwcleaner.exe 2014-03-06 23:57 - 2014-03-08 13:16 - 00000000 ___DC () C:\FRST 2014-03-06 23:17 - 2014-03-06 23:17 - 00000906 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-03-06 23:17 - 2014-03-06 23:17 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-03-06 23:17 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-06 23:16 - 2014-03-06 23:16 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-06 23:13 - 2014-03-06 23:14 - 00673248 _____ ( ) C:\Users\user\Downloads\Malwarebytes-AntiMalware(13117).exe 2014-03-06 22:59 - 2014-03-07 01:00 - 00522360 _____ (Duplex Secure Ltd.) C:\Users\user\Downloads\SPTDinst-v186-x86 (1).exe 2014-03-06 22:54 - 2014-03-06 22:54 - 00320120 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys 2014-03-06 11:06 - 2014-03-06 11:07 - 00000000 ____D () C:\Windows\system32\vi-VN 2014-03-06 11:06 - 2014-03-06 11:07 - 00000000 ____D () C:\Windows\system32\eu-ES 2014-03-06 11:06 - 2014-03-06 11:07 - 00000000 ____D () C:\Windows\system32\ca-ES 2014-03-06 11:06 - 2014-03-06 11:06 - 00000000 ____D () C:\Program Files\Windows Portable Devices 2014-03-06 08:25 - 2014-03-07 01:28 - 00360812 _____ () C:\Windows\PFRO.log 2014-03-06 07:56 - 2014-03-06 07:51 - 00000426 ____C () C:\AVScanner.ini 2014-03-05 23:23 - 2014-03-05 23:23 - 01528184 _____ (Microsoft Corporation) C:\Users\user\Downloads\GenuineCheck.exe 2014-03-05 21:26 - 2014-03-06 22:43 - 00000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2014-03-05 21:11 - 2014-03-05 21:11 - 00007580 _____ () C:\Users\user\Documents\Driver Analysis for USER-PC.html 2014-03-05 21:10 - 2014-03-05 21:10 - 00000000 ____D () C:\Users\user\AppData\Roaming\DeviceDoctorSoftware 2014-03-05 21:08 - 2014-03-05 21:10 - 14107008 _____ (Driver-Soft Inc. ) C:\Users\user\Downloads\drvgenpro.exe 2014-03-05 20:55 - 2014-03-05 21:08 - 100242441 _____ (Realtek Semiconductor Corp.) C:\Users\user\Downloads\32bit_Win7_Win8_Win81_R273.exe 2014-03-05 20:53 - 2014-03-06 22:44 - 00000000 ____D () C:\ProgramData\Soluto 2014-03-05 20:50 - 2014-03-05 20:50 - 00000000 _RSHC () C:\MSDOS.SYS 2014-03-05 20:50 - 2014-03-05 20:50 - 00000000 _RSHC () C:\IO.SYS 2014-03-05 20:49 - 2014-03-05 20:50 - 00000185 _____ () C:\Users\user\Downloads\123freesolitaire-v90-setup.exe 2014-03-02 22:57 - 2014-03-05 20:43 - 00000000 ____D () C:\Users\user\AppData\Roaming\Nico Mak Computing 2014-03-02 12:25 - 2014-03-02 12:25 - 00000299 _____ () C:\Users\user\Desktop\[Plik PDF]573 KB.URL 2014-03-02 12:06 - 2014-03-02 12:06 - 00587254 _____ () C:\Users\user\Downloads\3824691_2.pdf.part 2014-03-01 11:04 - 2014-03-01 11:05 - 00183312 _____ () C:\Windows\Minidump\Mini030114-01.dmp 2014-02-28 16:39 - 2014-02-28 16:39 - 00005400 ____N () C:\bootex.log 2014-02-28 15:38 - 2014-03-06 11:05 - 00014426 _____ () C:\Windows\setupact.log 2014-02-28 15:38 - 2014-02-28 15:38 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-25 11:33 - 2014-02-25 11:33 - 00160151 _____ () C:\Users\user\Downloads\karta-pokladowa 2014-02-23 15:37 - 2014-03-01 11:04 - 213122055 _____ () C:\Windows\MEMORY.DMP 2014-02-23 15:37 - 2014-02-23 15:37 - 00184720 _____ () C:\Windows\Minidump\Mini022314-01.dmp 2014-02-21 14:55 - 2014-02-21 15:00 - 00000000 ____D () C:\Users\user\Documents\PODANIA-WNIOSKI 2014-02-21 14:50 - 2014-03-07 21:19 - 00000000 ____D () C:\Users\user\Documents\PRACA 2014-02-21 14:40 - 2014-02-21 14:40 - 00000397 _____ () C:\Users\user\Desktop\Muzyka — skrót.lnk 2014-02-20 22:50 - 2014-02-20 22:50 - 00154336 _____ () C:\Users\user\Documents\cc_20140220_225007.reg 2014-02-20 15:25 - 2014-02-20 15:25 - 00000801 _____ () C:\Windows\wininit.ini 2014-02-20 14:06 - 2014-02-20 14:06 - 00000883 _____ () C:\Users\user\Desktop\Softonic.lnk 2014-02-20 14:06 - 2014-02-20 14:06 - 00000000 ____D () C:\Users\user\AppData\Local\CrashRpt 2014-02-19 14:56 - 2014-03-07 01:08 - 00000051 _____ () C:\Users\user\AppData\Roaming\mbam.context.scan 2014-02-19 12:52 - 2014-02-19 12:52 - 00000000 ____D () C:\Program Files\PC Connectivity Solution(31) 2014-02-19 10:30 - 2014-02-21 15:24 - 00000000 ____D () C:\Users\user\Documents\PITY 2014-02-19 10:25 - 2014-03-08 11:35 - 00000000 ____D () C:\Users\user\Documents\PREZENTACJE 2014-02-19 10:17 - 2013-04-08 17:28 - 00000325 _____ () C:\Users\user\Documents\Narzedzia diagnostyczne drukarek HP.url 2014-02-19 10:05 - 2014-03-04 14:21 - 00001977 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-02-19 09:56 - 2014-03-08 13:08 - 00001032 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-19 09:56 - 2014-03-08 11:08 - 00001028 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-19 09:40 - 2014-02-21 14:45 - 00000000 ____D () C:\Users\user\Documents\CV 2014-02-18 18:16 - 2014-02-18 18:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-02-13 03:12 - 2014-02-05 09:50 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 03:12 - 2014-02-05 09:48 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 03:12 - 2014-02-05 09:48 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 03:12 - 2014-02-05 09:48 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 03:12 - 2014-02-05 09:47 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 03:12 - 2014-02-05 09:47 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 03:12 - 2014-02-05 09:47 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-02-13 03:12 - 2014-02-05 09:46 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-13 03:11 - 2014-02-05 09:56 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 03:11 - 2014-02-05 09:53 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 03:11 - 2014-02-05 09:51 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 03:11 - 2014-02-05 09:49 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 03:11 - 2014-02-05 09:49 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-02-13 03:11 - 2014-02-05 09:48 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 03:11 - 2014-02-05 09:48 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-02-13 03:10 - 2014-02-05 09:58 - 12345344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-12 21:28 - 2013-12-05 03:12 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 20:49 - 2014-02-19 13:44 - 00000000 ___DC () C:\148bac5491b1585bf03fb28c60 ==================== One Month Modified Files and Folders ======= 2014-03-08 13:16 - 2014-03-06 23:57 - 00000000 ___DC () C:\FRST 2014-03-08 13:08 - 2014-02-19 09:56 - 00001032 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-08 12:43 - 2014-03-08 12:59 - 00003798 _____ () C:\Users\user\Documents\UPDATE.txt 2014-03-08 12:06 - 2006-11-02 13:52 - 01669118 _____ () C:\Windows\WindowsUpdate.log 2014-03-08 12:02 - 2012-06-25 17:29 - 00058632 _____ () C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-08 11:56 - 2014-03-08 11:56 - 00000000 ____D () C:\Users\user\AppData\Roaming\OpenOffice 2014-03-08 11:51 - 2014-03-08 11:51 - 00001007 _____ () C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk 2014-03-08 11:50 - 2014-03-08 11:50 - 00000000 ____D () C:\Program Files\OpenOffice 4 2014-03-08 11:49 - 2013-04-25 17:33 - 00000000 ____D () C:\Program Files\OpenOffice.org 3 2014-03-08 11:48 - 2006-11-02 12:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-03-08 11:47 - 2014-03-08 11:47 - 00162010 _____ () C:\Users\user\Downloads\DIAG_MATS_NETWORK_global.DiagCab 2014-03-08 11:44 - 2014-03-08 11:30 - 133661993 _____ () C:\Users\user\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_pl.exe 2014-03-08 11:35 - 2014-02-19 10:25 - 00000000 ____D () C:\Users\user\Documents\PREZENTACJE 2014-03-08 11:13 - 2014-03-08 11:13 - 00347816 _____ (Microsoft Corporation) C:\Users\user\Downloads\MicrosoftFixit.wu.LB.1331770068167897.1.1.Run.exe 2014-03-08 11:08 - 2014-02-19 09:56 - 00001028 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-08 10:43 - 2012-11-02 11:56 - 00000435 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-03-08 10:41 - 2012-06-26 06:09 - 00144366 _____ () C:\ProgramData\nvModes.001 2014-03-08 10:41 - 2012-06-25 20:53 - 00144366 _____ () C:\ProgramData\nvModes.dat 2014-03-08 10:41 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-08 10:40 - 2012-06-25 20:21 - 00001076 _____ () C:\Windows\bthservsdp.dat 2014-03-08 10:40 - 2006-11-02 14:01 - 00032530 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-08 10:34 - 2014-03-08 10:34 - 00448512 _____ (OldTimer Tools) C:\Users\user\Downloads\TFC.exe 2014-03-08 10:28 - 2014-03-07 23:16 - 00000000 ___DC () C:\AdwCleaner 2014-03-08 09:42 - 2013-06-04 14:52 - 00000000 ____D () C:\Users\user\AppData\Roaming\Spotify 2014-03-07 23:16 - 2014-03-07 23:16 - 01244192 _____ () C:\Users\user\Downloads\adwcleaner.exe 2014-03-07 21:29 - 2013-08-25 14:15 - 00000000 ____D () C:\Users\user\Downloads\NPDATA_PL 2014-03-07 21:19 - 2014-02-21 14:50 - 00000000 ____D () C:\Users\user\Documents\PRACA 2014-03-07 03:24 - 2012-10-11 19:20 - 00000000 ____D () C:\Users\user\AppData\Local\CrashDumps 2014-03-07 01:36 - 2006-12-05 06:22 - 00672140 _____ () C:\Windows\system32\perfh015.dat 2014-03-07 01:36 - 2006-12-05 06:22 - 00130516 _____ () C:\Windows\system32\perfc015.dat 2014-03-07 01:36 - 2006-11-02 11:33 - 01495264 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-07 01:28 - 2014-03-06 08:25 - 00360812 _____ () C:\Windows\PFRO.log 2014-03-07 01:28 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\twain_32 2014-03-07 01:08 - 2014-02-19 14:56 - 00000051 _____ () C:\Users\user\AppData\Roaming\mbam.context.scan 2014-03-07 01:00 - 2014-03-06 22:59 - 00522360 _____ (Duplex Secure Ltd.) C:\Users\user\Downloads\SPTDinst-v186-x86 (1).exe 2014-03-06 23:17 - 2014-03-06 23:17 - 00000906 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-03-06 23:17 - 2014-03-06 23:17 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-03-06 23:16 - 2014-03-06 23:16 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-06 23:14 - 2014-03-06 23:13 - 00673248 _____ ( ) C:\Users\user\Downloads\Malwarebytes-AntiMalware(13117).exe 2014-03-06 22:54 - 2014-03-06 22:54 - 00320120 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys 2014-03-06 22:44 - 2014-03-05 20:53 - 00000000 ____D () C:\ProgramData\Soluto 2014-03-06 22:43 - 2014-03-05 21:26 - 00000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2014-03-06 20:05 - 2006-11-02 13:47 - 00268600 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-06 16:21 - 2012-10-01 04:47 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-03-06 15:40 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\rescache 2014-03-06 11:48 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-03-06 11:07 - 2014-03-06 11:06 - 00000000 ____D () C:\Windows\system32\vi-VN 2014-03-06 11:07 - 2014-03-06 11:06 - 00000000 ____D () C:\Windows\system32\eu-ES 2014-03-06 11:07 - 2014-03-06 11:06 - 00000000 ____D () C:\Windows\system32\ca-ES 2014-03-06 11:07 - 2006-12-05 06:20 - 00000000 ____D () C:\Windows\system32\Drivers\pl-PL 2014-03-06 11:07 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\system32\XPSViewer 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\zh-TW 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\zh-HK 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\zh-CN 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\uk-UA 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\tr-TR 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\th-TH 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sv-SE 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\SLUI 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sl-SI 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\sk-SK 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ru-RU 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ro-RO 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\pt-PT 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\pt-BR 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\pl-PL 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\nl-NL 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\nb-NO 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\lv-LV 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\lt-LT 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ko-KR 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ja-JP 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\it-IT 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\hu-HU 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\hr-HR 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\he-IL 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\fr-FR 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\fi-FI 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\et-EE 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\el-GR 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\bg-BG 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\ar-SA 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers 2014-03-06 11:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\IME 2014-03-06 11:06 - 2014-03-06 11:06 - 00000000 ____D () C:\Program Files\Windows Portable Devices 2014-03-06 11:06 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Sidebar 2014-03-06 11:06 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Photo Gallery 2014-03-06 11:06 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Journal 2014-03-06 11:06 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Defender 2014-03-06 11:06 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Collaboration 2014-03-06 11:06 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Windows Calendar 2014-03-06 11:06 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Movie Maker 2014-03-06 11:06 - 2006-11-02 12:18 - 00000000 ____D () C:\Program Files\Common Files\System 2014-03-06 11:05 - 2014-02-28 15:38 - 00014426 _____ () C:\Windows\setupact.log 2014-03-06 11:04 - 2012-08-09 19:48 - 00000000 ____D () C:\Windows\system32\RTCOM 2014-03-06 08:26 - 2012-12-14 19:44 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-06 08:22 - 2006-11-02 12:18 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-03-06 07:51 - 2014-03-06 07:56 - 00000426 ____C () C:\AVScanner.ini 2014-03-06 07:33 - 2012-12-14 19:44 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-03-06 07:33 - 2012-12-14 19:44 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-03-06 07:30 - 2012-10-04 21:04 - 00000000 ____D () C:\Users\user\AppData\Local\Adobe 2014-03-05 23:23 - 2014-03-05 23:23 - 01528184 _____ (Microsoft Corporation) C:\Users\user\Downloads\GenuineCheck.exe 2014-03-05 21:11 - 2014-03-05 21:11 - 00007580 _____ () C:\Users\user\Documents\Driver Analysis for USER-PC.html 2014-03-05 21:10 - 2014-03-05 21:10 - 00000000 ____D () C:\Users\user\AppData\Roaming\DeviceDoctorSoftware 2014-03-05 21:10 - 2014-03-05 21:08 - 14107008 _____ (Driver-Soft Inc. ) C:\Users\user\Downloads\drvgenpro.exe 2014-03-05 21:08 - 2014-03-05 20:55 - 100242441 _____ (Realtek Semiconductor Corp.) C:\Users\user\Downloads\32bit_Win7_Win8_Win81_R273.exe 2014-03-05 20:50 - 2014-03-05 20:50 - 00000000 _RSHC () C:\MSDOS.SYS 2014-03-05 20:50 - 2014-03-05 20:50 - 00000000 _RSHC () C:\IO.SYS 2014-03-05 20:50 - 2014-03-05 20:49 - 00000185 _____ () C:\Users\user\Downloads\123freesolitaire-v90-setup.exe 2014-03-05 20:43 - 2014-03-02 22:57 - 00000000 ____D () C:\Users\user\AppData\Roaming\Nico Mak Computing 2014-03-05 19:56 - 2012-12-25 19:51 - 00000000 ____D () C:\Users\user\AppData\Local\ChomikBox 2014-03-05 19:28 - 2012-12-25 19:53 - 00000000 ____D () C:\Users\user\.gstreamer-0.10 2014-03-04 14:21 - 2014-02-19 10:05 - 00001977 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-03-02 22:19 - 2013-06-04 14:55 - 00000000 ____D () C:\Users\user\AppData\Local\Spotify 2014-03-02 12:25 - 2014-03-02 12:25 - 00000299 _____ () C:\Users\user\Desktop\[Plik PDF]573 KB.URL 2014-03-02 12:06 - 2014-03-02 12:06 - 00587254 _____ () C:\Users\user\Downloads\3824691_2.pdf.part 2014-03-01 11:05 - 2014-03-01 11:04 - 00183312 _____ () C:\Windows\Minidump\Mini030114-01.dmp 2014-03-01 11:04 - 2014-02-23 15:37 - 213122055 _____ () C:\Windows\MEMORY.DMP 2014-03-01 11:04 - 2013-01-22 00:07 - 00000000 ____D () C:\Windows\Minidump 2014-02-28 16:39 - 2014-02-28 16:39 - 00005400 ____N () C:\bootex.log 2014-02-28 16:11 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\Msdtc 2014-02-28 16:10 - 2013-05-02 18:38 - 00000000 ____D () C:\ProgramData\Real 2014-02-28 16:10 - 2013-04-16 20:08 - 00000000 ____D () C:\ProgramData\HP Product Assistant 2014-02-28 16:10 - 2012-06-26 13:40 - 00000000 ____D () C:\Users\user\AppData\Local\QuickPlay 2014-02-28 16:10 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\spool 2014-02-28 16:10 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\registration 2014-02-28 16:10 - 2006-11-02 11:22 - 42991616 _____ () C:\Windows\system32\config\components_previous 2014-02-28 16:10 - 2006-11-02 11:22 - 41156608 _____ () C:\Windows\system32\config\software_previous 2014-02-28 16:10 - 2006-11-02 11:22 - 34865152 _____ () C:\Windows\system32\config\system_previous 2014-02-28 16:10 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous 2014-02-28 16:10 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\default_previous 2014-02-28 16:10 - 2006-11-02 11:22 - 00020480 _____ () C:\Windows\system32\config\security_previous 2014-02-28 15:38 - 2014-02-28 15:38 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-25 11:33 - 2014-02-25 11:33 - 00160151 _____ () C:\Users\user\Downloads\karta-pokladowa 2014-02-24 21:03 - 2006-11-02 13:47 - 00005168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-24 21:03 - 2006-11-02 13:47 - 00005168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-24 09:23 - 2013-01-09 12:58 - 00000000 ____D () C:\Windows\pss 2014-02-23 15:37 - 2014-02-23 15:37 - 00184720 _____ () C:\Windows\Minidump\Mini022314-01.dmp 2014-02-21 15:24 - 2014-02-19 10:30 - 00000000 ____D () C:\Users\user\Documents\PITY 2014-02-21 15:00 - 2014-02-21 14:55 - 00000000 ____D () C:\Users\user\Documents\PODANIA-WNIOSKI 2014-02-21 14:45 - 2014-02-19 09:40 - 00000000 ____D () C:\Users\user\Documents\CV 2014-02-21 14:40 - 2014-02-21 14:40 - 00000397 _____ () C:\Users\user\Desktop\Muzyka — skrót.lnk 2014-02-20 22:50 - 2014-02-20 22:50 - 00154336 _____ () C:\Users\user\Documents\cc_20140220_225007.reg 2014-02-20 22:43 - 2012-06-25 17:53 - 00000000 ____D () C:\Windows\Panther 2014-02-20 15:25 - 2014-02-20 15:25 - 00000801 _____ () C:\Windows\wininit.ini 2014-02-20 14:06 - 2014-02-20 14:06 - 00000883 _____ () C:\Users\user\Desktop\Softonic.lnk 2014-02-20 14:06 - 2014-02-20 14:06 - 00000000 ____D () C:\Users\user\AppData\Local\CrashRpt 2014-02-20 13:48 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public 2014-02-20 10:03 - 2012-09-30 12:18 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-02-20 10:01 - 2012-08-06 19:20 - 00000000 ____D () C:\Users\user\AppData\Roaming\Skype 2014-02-20 01:00 - 2013-08-06 10:33 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-19 23:26 - 2006-11-02 13:37 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-02-19 23:02 - 2013-12-27 00:33 - 00000000 ____D () C:\Users\user\AppData\Roaming\MPC-HC 2014-02-19 16:22 - 2013-07-07 17:12 - 00000000 ____D () C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartupDisabled 2014-02-19 16:22 - 2012-12-26 13:55 - 00000000 ____D () C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2014-02-19 16:22 - 2012-10-05 10:48 - 00000000 ____D () C:\Program Files\Common Files\Nokia 2014-02-19 16:22 - 2012-10-05 10:39 - 00000000 ____D () C:\Program Files\PC Connectivity Solution 2014-02-19 16:22 - 2012-10-05 10:27 - 00000000 ____D () C:\Program Files\Nokia 2014-02-19 16:22 - 2012-09-01 16:28 - 00000000 ____D () C:\Users\user\AppData\Local\MicrosoftStore 2014-02-19 16:22 - 2012-06-25 17:29 - 00000000 ___RD () C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-02-19 16:22 - 2012-06-25 17:29 - 00000000 ___RD () C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-02-19 13:44 - 2014-02-12 20:49 - 00000000 ___DC () C:\148bac5491b1585bf03fb28c60 2014-02-19 12:52 - 2014-02-19 12:52 - 00000000 ____D () C:\Program Files\PC Connectivity Solution(31) 2014-02-19 10:31 - 2012-09-25 19:37 - 00000000 ____D () C:\Users\user\Documents\Moje zeskanowane obrazy 2014-02-19 10:03 - 2013-03-31 16:34 - 00000000 ____D () C:\Program Files\Google 2014-02-19 09:14 - 2006-11-02 11:23 - 00002577 _____ () C:\Windows\system32\config.nt 2014-02-19 08:52 - 2012-12-25 18:31 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-02-18 18:18 - 2014-02-18 18:16 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-02-12 21:16 - 2012-12-25 19:50 - 00000000 ____D () C:\Program Files\ChomikBox ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-08 10:58 ==================== End Of Log ============================