Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01 Ran by RAFAŁ (administrator) on RAFAŁ-KOMPUTER on 24-03-2014 11:24:48 Running from C:\Users\RAFAŁ\Downloads Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= () C:\Program Files\TheBestDeals-soft\TheBestDeals_wd.exe () C:\Program Files\LPT\srpts.exe (Symantec Corporation) C:\Program Files\Norton 360\Engine\21.1.0.18\N360.exe (Symantec Corporation) C:\Program Files\Norton 360\Engine\21.1.0.18\N360.exe () C:\Program Files\TheBestDeals-soft\TheBestDeals157.exe (Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio.exe (BitTorrent Inc.) C:\Users\RAFAŁ\AppData\Roaming\uTorrent\uTorrent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKU\S-1-5-21-3917470218-3083872301-685111015-1000\...\Run: [uTorrent] - C:\Users\RAFAŁ\AppData\Roaming\uTorrent\uTorrent.exe [1340496 2014-01-03] (BitTorrent Inc.) HKU\S-1-5-21-3917470218-3083872301-685111015-1000\...\Run: [Browser Infrastructure Helper] - C:\Users\RAFAŁ\AppData\Local\Smartbar\Application\Smartbar.exe startup GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: http=127.0.0.1:13828 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZOkiLMwdFQEJrUk3vOJHxcUskZ7eil02H3ZB0_O-oeNFZJc2R6-FeVi1LbBdoBsBZfH7pJbqfe1xfZI0CjrR0RIkRJ1SjeoC_JWSQIt9D_dIfgDIuu2w1FysT-26M-Qs_WTomAaUifLFw,,&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://feed.snapdo.com/?p=mko_awfzxipyrbpgr6jn_c9okvk3v9bhmt-ikvs3edgjlbaternaqxyyyjdxlfk6ezokilmwdfqejruk3vojhxcuskz7eil02h3zb0_o-oenfzjc2r6-fevi1lbbdobsbzfh7pjbqfe1xfzeioie1qew1qz5dklddgccvitktm7uxdfcpqm87ik6lp_6zwm6ne8oeujllvg0gw,, HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF7E7452BA708CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZOkiLMwdFQEJrUk3vOJHxcUskZ7eil02H3ZB0_O-oeNFZJc2R6-FeVi1LbBdoBsBZfH7pJbqfe1xfZI0CjrR0RIkRJ1SjeoC_JWSQIt9D_dIfgDIuu2w1FysT-26M-Qs_WTomAaUifLFw,,&q={searchTerms} SearchScopes: HKLM - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = BHO: media enhance - {11111111-1111-1111-1111-110411411150} - C:\Program Files\media enhance\media enhance-bho.dll (freeven) BHO: free ven - {11111111-1111-1111-1111-110511161180} - C:\Program Files\free ven\free ven-bho.dll (freeven) BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\21.1.0.18\coIEPlg.dll (Symantec Corporation) BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\21.1.0.18\IPS\IPSBHO.DLL (Symantec Corporation) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\21.1.0.18\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\21.1.0.18\coIEPlg.dll (Symantec Corporation) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 Chrome: ======= CHR DefaultSearchKeyword: search.snapdo.com CHR DefaultSearchProvider: Web CHR DefaultSearchURL: http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZOkiLMwdFQEJrUk3vOJHxcUskZ7eil02H3ZB0_O-oeNFZJc2R6-FeVi1LbBdoBsBZfH7pJbqfe1xfZI0CjrR0RIkRJ1SjeoC_JWSQIt9D_dIfgDIuu2w1FysT-26M-Qs_WTomAaUifLFw,,&q={searchTerms} CHR DefaultNewTabURL: CHR Extension: (media enhance) - C:\Users\RAFAŁ\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo [2014-03-24] CHR Extension: (Norton Identity Protection) - C:\Users\RAFAŁ\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2014-01-03] CHR Extension: (Google Wallet) - C:\Users\RAFAŁ\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-03] CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files\Norton 360\Engine\21.1.0.18\Exts\Chrome.crx [2014-01-21] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ========================== Services (Whitelisted) ================= R2 LPTSystemUpdater; C:\Program Files\LPT\srpts.exe [32288 2014-02-09] () R2 N360; C:\Program Files\Norton 360\Engine\21.1.0.18\N360.exe [264360 2013-10-08] (Symantec Corporation) R2 TheBestDeals; C:\Program Files\TheBestDeals-soft\TheBestDeals157.exe [195584 2014-03-21] () S3 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [480624 2009-09-16] (Sony Corporation) R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1020976 2013-08-01] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R1 BHDrvx86; C:\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20140121.001\BHDrvx86.sys [1098968 2013-12-18] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360\1501000.012\ccSetx86.sys [127064 2013-09-26] (Symantec Corporation) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2014-01-03] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2014-01-03] (Symantec Corporation) R1 IDSVix86; C:\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20140131.001\IDSvix86.sys [394456 2014-01-20] (Symantec Corporation) S3 NAVENG; C:\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20140202.003\NAVENG.SYS [93272 2014-02-01] (Symantec Corporation) S3 NAVEX15; C:\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20140202.003\NAVEX15.SYS [1612376 2014-02-01] (Symantec Corporation) S3 SRTSP; C:\Windows\system32\drivers\N360\1501000.012\SRTSP.SYS [651352 2013-09-27] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360\1501000.012\SRTSPX.SYS [32344 2013-09-10] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360\1501000.012\SYMDS.SYS [367704 2013-09-10] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360\1501000.012\SYMEFA.SYS [935512 2013-09-27] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142936 2014-01-03] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360\1501000.012\Ironx86.SYS [206936 2013-09-27] (Symantec Corporation) R1 SymNetS; C:\Windows\system32\drivers\N360\1501000.012\SYMNETS.SYS [446552 2013-09-26] (Symantec Corporation) S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-24 11:24 - 2014-03-24 11:25 - 00008406 _____ () C:\Users\RAFAŁ\Downloads\FRST.txt 2014-03-24 11:19 - 2014-03-24 11:24 - 00000000 ____D () C:\FRST 2014-03-24 11:16 - 2014-03-24 11:16 - 01145856 _____ (Farbar) C:\Users\RAFAŁ\Downloads\FRST.exe 2014-03-24 10:47 - 2014-03-24 11:15 - 00000000 ____D () C:\Users\RAFAŁ\Desktop\Chrzest Alanka 2014-03-23 12:25 - 2014-03-23 12:25 - 00002983 _____ () C:\AdwCleaner[S1].txt 2014-03-23 10:49 - 2014-03-23 10:49 - 00002873 _____ () C:\AdwCleaner[R2].txt 2014-03-22 22:55 - 2014-03-23 11:26 - 00000000 ____D () C:\Users\RAFAŁ\Desktop\Zdjęcia 2014-03-22 21:23 - 2014-03-22 21:23 - 00368705 _____ () C:\Users\RAFAŁ\Downloads\gm.zip 2014-03-22 21:14 - 2014-03-23 12:32 - 00000000 ____D () C:\Users\RAFAŁ\Desktop\log 2014-03-22 21:00 - 2014-03-22 21:01 - 00575488 _____ (OldTimer Tools) C:\Users\RAFAŁ\Desktop\OTL_3.2.17.3.exe 2014-03-22 20:58 - 2014-03-22 20:59 - 00002815 _____ () C:\AdwCleaner[R1].txt 2014-03-22 20:58 - 2014-03-22 20:58 - 00632049 _____ () C:\Users\RAFAŁ\Desktop\adwcleaner.exe 2014-03-22 20:55 - 2014-03-22 20:55 - 01949184 _____ () C:\Users\RAFAŁ\Downloads\AdwCleaner.pl 3.021.exe 2014-03-22 01:17 - 2014-03-22 01:17 - 00000000 ____D () C:\Program Files\STOPzilla! 2014-03-22 01:15 - 2014-03-22 01:15 - 00000000 ____D () C:\Users\RAFAŁ\AppData\Roaming\WinRAR 2014-03-22 01:15 - 2014-03-22 01:15 - 00000000 ____D () C:\Program Files\WinRAR 2014-03-22 01:14 - 2014-03-22 01:15 - 01439010 _____ () C:\Users\RAFAŁ\Downloads\Win Rar 3.92 FULL PL.exe 2014-03-22 01:13 - 2014-03-22 01:13 - 00370656 _____ () C:\Users\RAFAŁ\Downloads\Player Setup.exe 2014-03-21 19:48 - 2014-03-21 20:28 - 00001095 _____ () C:\Users\RAFAŁ\Desktop\Continue VuuPC Installation.lnk 2014-03-21 19:33 - 2014-03-24 10:46 - 00001578 _____ () C:\Windows\Tasks\media enhance-updater.job 2014-03-21 19:33 - 2014-03-22 19:33 - 00000366 _____ () C:\Windows\Tasks\APSnotifierPP2.job 2014-03-21 19:33 - 2014-03-22 08:03 - 00000366 _____ () C:\Windows\Tasks\APSnotifierPP3.job 2014-03-21 19:33 - 2014-03-21 20:06 - 00000368 _____ () C:\Windows\Tasks\APSnotifierPP1.job 2014-03-21 19:33 - 2014-03-21 19:33 - 00000320 _____ () C:\Users\RAFAŁ\AppData\Roaming\aps.uninstall.scan.results 2014-03-21 19:32 - 2014-03-24 10:46 - 00003088 _____ () C:\Windows\Tasks\media enhance-chromeinstaller.job 2014-03-21 19:32 - 2014-03-24 10:46 - 00001498 _____ () C:\Windows\Tasks\free ven-updater.job 2014-03-21 19:32 - 2014-03-24 10:45 - 00002350 _____ () C:\Windows\Tasks\media enhance-firefoxinstaller.job 2014-03-21 19:32 - 2014-03-24 10:45 - 00001534 _____ () C:\Windows\Tasks\media enhance-codedownloader.job 2014-03-21 19:32 - 2014-03-24 10:45 - 00001432 _____ () C:\Windows\Tasks\media enhance-enabler.job 2014-03-21 19:32 - 2014-03-21 19:34 - 00000000 ____D () C:\Program Files\LPT 2014-03-21 19:32 - 2014-03-21 19:33 - 00000000 ____D () C:\Program Files\media enhance 2014-03-21 19:32 - 2014-03-21 19:32 - 00000000 ____D () C:\Users\RAFAŁ\Documents\Optimizer Pro 2014-03-21 19:31 - 2014-03-24 10:48 - 00000380 _____ () C:\Windows\Tasks\The Best Deals Update.job 2014-03-21 19:31 - 2014-03-24 10:46 - 00003068 _____ () C:\Windows\Tasks\free ven-chromeinstaller.job 2014-03-21 19:31 - 2014-03-24 10:46 - 00002242 _____ () C:\Windows\Tasks\free ven-firefoxinstaller.job 2014-03-21 19:31 - 2014-03-24 10:45 - 00001454 _____ () C:\Windows\Tasks\free ven-codedownloader.job 2014-03-21 19:31 - 2014-03-24 10:45 - 00001352 _____ () C:\Windows\Tasks\free ven-enabler.job 2014-03-21 19:31 - 2014-03-24 10:45 - 00000384 _____ () C:\Windows\Tasks\The Best Deals_wd.job 2014-03-21 19:31 - 2014-03-21 19:31 - 01172736 _____ (AnyProtect.com) C:\Users\RAFAŁ\AppData\Local\nsu81A6.tmp 2014-03-21 19:31 - 2014-03-21 19:31 - 00000472 __RSH () C:\ProgramData\ntuser.pol 2014-03-21 19:31 - 2014-03-21 19:31 - 00000000 ____D () C:\Users\RAFAŁ\AppData\Local\LPT 2014-03-21 19:31 - 2014-03-21 19:31 - 00000000 ____D () C:\Program Files\TheBestDeals-soft 2014-03-21 19:29 - 2014-03-21 19:29 - 00320512 _____ () C:\Users\RAFAŁ\Downloads\Java.exe 2014-02-27 09:01 - 2014-02-27 09:01 - 00000000 ____D () C:\Users\RAFAŁ\AppData\Local\Skype 2014-02-27 09:00 - 2014-02-27 09:00 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-02-27 09:00 - 2014-02-27 09:00 - 00000000 ___RD () C:\Program Files\Skype 2014-02-27 09:00 - 2014-02-27 09:00 - 00000000 ____D () C:\Program Files\Common Files\Skype ==================== One Month Modified Files and Folders ======= 2014-03-24 11:25 - 2014-03-24 11:24 - 00008406 _____ () C:\Users\RAFAŁ\Downloads\FRST.txt 2014-03-24 11:24 - 2014-03-24 11:19 - 00000000 ____D () C:\FRST 2014-03-24 11:24 - 2009-07-14 04:34 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-24 11:24 - 2009-07-14 04:34 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-24 11:21 - 2014-01-03 21:06 - 00000000 ____D () C:\Users\RAFAŁ\AppData\Roaming\uTorrent 2014-03-24 11:16 - 2014-03-24 11:16 - 01145856 _____ (Farbar) C:\Users\RAFAŁ\Downloads\FRST.exe 2014-03-24 11:16 - 2014-01-03 06:26 - 00485577 _____ () C:\Windows\WindowsUpdate.log 2014-03-24 11:15 - 2014-03-24 10:47 - 00000000 ____D () C:\Users\RAFAŁ\Desktop\Chrzest Alanka 2014-03-24 10:48 - 2014-03-21 19:31 - 00000380 _____ () C:\Windows\Tasks\The Best Deals Update.job 2014-03-24 10:46 - 2014-03-21 19:33 - 00001578 _____ () C:\Windows\Tasks\media enhance-updater.job 2014-03-24 10:46 - 2014-03-21 19:32 - 00003088 _____ () C:\Windows\Tasks\media enhance-chromeinstaller.job 2014-03-24 10:46 - 2014-03-21 19:32 - 00001498 _____ () C:\Windows\Tasks\free ven-updater.job 2014-03-24 10:46 - 2014-03-21 19:31 - 00003068 _____ () C:\Windows\Tasks\free ven-chromeinstaller.job 2014-03-24 10:46 - 2014-03-21 19:31 - 00002242 _____ () C:\Windows\Tasks\free ven-firefoxinstaller.job 2014-03-24 10:45 - 2014-03-21 19:32 - 00002350 _____ () C:\Windows\Tasks\media enhance-firefoxinstaller.job 2014-03-24 10:45 - 2014-03-21 19:32 - 00001534 _____ () C:\Windows\Tasks\media enhance-codedownloader.job 2014-03-24 10:45 - 2014-03-21 19:32 - 00001432 _____ () C:\Windows\Tasks\media enhance-enabler.job 2014-03-24 10:45 - 2014-03-21 19:31 - 00001454 _____ () C:\Windows\Tasks\free ven-codedownloader.job 2014-03-24 10:45 - 2014-03-21 19:31 - 00001352 _____ () C:\Windows\Tasks\free ven-enabler.job 2014-03-24 10:45 - 2014-03-21 19:31 - 00000384 _____ () C:\Windows\Tasks\The Best Deals_wd.job 2014-03-24 10:45 - 2014-01-03 17:15 - 00001030 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-24 10:45 - 2009-07-14 04:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-24 10:45 - 2009-07-14 04:39 - 00038146 _____ () C:\Windows\setupact.log 2014-03-23 19:32 - 2014-01-03 17:15 - 00001034 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-23 12:32 - 2014-03-22 21:14 - 00000000 ____D () C:\Users\RAFAŁ\Desktop\log 2014-03-23 12:25 - 2014-03-23 12:25 - 00002983 _____ () C:\AdwCleaner[S1].txt 2014-03-23 11:26 - 2014-03-22 22:55 - 00000000 ____D () C:\Users\RAFAŁ\Desktop\Zdjęcia 2014-03-23 10:49 - 2014-03-23 10:49 - 00002873 _____ () C:\AdwCleaner[R2].txt 2014-03-22 21:23 - 2014-03-22 21:23 - 00368705 _____ () C:\Users\RAFAŁ\Downloads\gm.zip 2014-03-22 21:01 - 2014-03-22 21:00 - 00575488 _____ (OldTimer Tools) C:\Users\RAFAŁ\Desktop\OTL_3.2.17.3.exe 2014-03-22 20:59 - 2014-03-22 20:58 - 00002815 _____ () C:\AdwCleaner[R1].txt 2014-03-22 20:58 - 2014-03-22 20:58 - 00632049 _____ () C:\Users\RAFAŁ\Desktop\adwcleaner.exe 2014-03-22 20:55 - 2014-03-22 20:55 - 01949184 _____ () C:\Users\RAFAŁ\Downloads\AdwCleaner.pl 3.021.exe 2014-03-22 19:33 - 2014-03-21 19:33 - 00000366 _____ () C:\Windows\Tasks\APSnotifierPP2.job 2014-03-22 08:03 - 2014-03-21 19:33 - 00000366 _____ () C:\Windows\Tasks\APSnotifierPP3.job 2014-03-22 08:02 - 2010-11-20 21:48 - 00031230 _____ () C:\Windows\PFRO.log 2014-03-22 01:23 - 2014-01-03 20:55 - 00000000 ____D () C:\Users\RAFAŁ\AppData\Roaming\Skype 2014-03-22 01:17 - 2014-03-22 01:17 - 00000000 ____D () C:\Program Files\STOPzilla! 2014-03-22 01:15 - 2014-03-22 01:15 - 00000000 ____D () C:\Users\RAFAŁ\AppData\Roaming\WinRAR 2014-03-22 01:15 - 2014-03-22 01:15 - 00000000 ____D () C:\Program Files\WinRAR 2014-03-22 01:15 - 2014-03-22 01:14 - 01439010 _____ () C:\Users\RAFAŁ\Downloads\Win Rar 3.92 FULL PL.exe 2014-03-22 01:13 - 2014-03-22 01:13 - 00370656 _____ () C:\Users\RAFAŁ\Downloads\Player Setup.exe 2014-03-21 20:28 - 2014-03-21 19:48 - 00001095 _____ () C:\Users\RAFAŁ\Desktop\Continue VuuPC Installation.lnk 2014-03-21 20:06 - 2014-03-21 19:33 - 00000368 _____ () C:\Windows\Tasks\APSnotifierPP1.job 2014-03-21 19:34 - 2014-03-21 19:32 - 00000000 ____D () C:\Program Files\LPT 2014-03-21 19:33 - 2014-03-21 19:33 - 00000320 _____ () C:\Users\RAFAŁ\AppData\Roaming\aps.uninstall.scan.results 2014-03-21 19:33 - 2014-03-21 19:32 - 00000000 ____D () C:\Program Files\media enhance 2014-03-21 19:32 - 2014-03-21 19:32 - 00000000 ____D () C:\Users\RAFAŁ\Documents\Optimizer Pro 2014-03-21 19:31 - 2014-03-21 19:31 - 01172736 _____ (AnyProtect.com) C:\Users\RAFAŁ\AppData\Local\nsu81A6.tmp 2014-03-21 19:31 - 2014-03-21 19:31 - 00000472 __RSH () C:\ProgramData\ntuser.pol 2014-03-21 19:31 - 2014-03-21 19:31 - 00000000 ____D () C:\Users\RAFAŁ\AppData\Local\LPT 2014-03-21 19:31 - 2014-03-21 19:31 - 00000000 ____D () C:\Program Files\TheBestDeals-soft 2014-03-21 19:31 - 2009-07-14 02:37 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-03-21 19:29 - 2014-03-21 19:29 - 00320512 _____ () C:\Users\RAFAŁ\Downloads\Java.exe 2014-03-19 22:21 - 2011-04-12 05:08 - 00687828 _____ () C:\Windows\system32\perfh015.dat 2014-03-19 22:21 - 2011-04-12 05:08 - 00131382 _____ () C:\Windows\system32\perfc015.dat 2014-03-19 22:21 - 2010-11-20 21:01 - 01523412 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-15 08:36 - 2014-01-03 17:15 - 00002135 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-02-27 09:01 - 2014-02-27 09:01 - 00000000 ____D () C:\Users\RAFAŁ\AppData\Local\Skype 2014-02-27 09:00 - 2014-02-27 09:00 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-02-27 09:00 - 2014-02-27 09:00 - 00000000 ___RD () C:\Program Files\Skype 2014-02-27 09:00 - 2014-02-27 09:00 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-02-27 09:00 - 2014-01-03 20:54 - 00000000 ____D () C:\ProgramData\Skype Some content of TEMP: ==================== C:\Users\RAFAŁ\AppData\Local\Temp\BackupSetup.exe C:\Users\RAFAŁ\AppData\Local\Temp\Quarantine.exe C:\Users\RAFAŁ\AppData\Local\Temp\shelper.exe C:\Users\RAFAŁ\AppData\Local\Temp\vcredist_x86.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-20 10:06 ==================== End Of Log ============================