Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-04-2014 Ran by seb (administrator) on SEB-PC on 13-04-2014 22:55:10 Running from C:\Users\seb\Downloads Microsoft Windows 7 Ultimate (X86) OS Language: English(US) Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Boot Camp\Bootcamp.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Windows\system32\AppleOSSMgr.exe (Apple Inc.) C:\Windows\system32\AppleTimeSrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe () C:\Program Files\LPT\srpts.exe (Skype Technologies) C:\Program Files\Skype\Updater\Updater.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe () C:\Program Files\LPT\srptm.exe (Somoto) C:\Users\seb\AppData\Local\FilesFrog Update Checker\update_checker.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Farbar) C:\Users\seb\Downloads\FRST(2).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apple_KbdMgr] => C:\Program Files\Boot Camp\Bootcamp.exe [526208 2011-06-29] (Apple Inc.) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [3744552 2011-11-28] (AVAST Software) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKU\S-1-5-19\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1173504 2009-07-14] (Microsoft Corporation) HKU\S-1-5-20\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1173504 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-2410551141-814857211-113848530-1000\...\Run: [Komunikator] => C:\Program Files\Tlen.pl\tlen.exe HKU\S-1-5-21-2410551141-814857211-113848530-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-2410551141-814857211-113848530-1000\...\Run: [ChomikBox] => C:\Program Files\ChomikBox\chomikbox.exe HKU\S-1-5-21-2410551141-814857211-113848530-1000\...\Run: [LiveSupport] => "C:\Program Files\LiveSupport\LiveSupport.exe" /noshow /log ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?p=mKO_AwFzXIpYRaxo67ounJhqib0rXFhtLLIHmXcfrN_YrlKmIMMmL36uP71ylMOLLFSRijAADIFooWZGvDFWAYiDsOvKHqZ0ShTzMRD3RAJ03e_AntzwEgXsh2PUlDT_f_LFA0luYlMpRw,,&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?p=mKO_AwFzXIpYRaxo67ounJhqib0rXFhtLLIHmXcfrN_YrlKmIMMmL36uP71ylMOLLFSRijAADIFooWZGvDFWAYiDsOvKHqZ0ShTzMRD3RAJ03e_AntzwEgXsh2PUlDT_f_LFA0luYlMpRw,,&q={searchTerms} SearchScopes: HKLM - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRaxo67ounJhqib0rXFhtLLIHmXcfrN_YrlKmIMMmL36uP71ylMOLLFSRijAADIFooWZGvDFWAYiDsOvKHqZ0ShTzMRD3RAJ03e_AntzwEgXsh2PUlDT_f_LFA0luYlMpRw,,&q={searchTerms} SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRaxo67ounJhqib0rXFhtLLIHmXcfrN_YrlKmIMMmL36uP71ylMOLLFSRijAADIFooWZGvDFWAYiDsOvKHqZ0ShTzMRD3RAJ03e_AntzwEgXsh2PUlDT_f_LFA0luYlMpRw,,&q={searchTerms} SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRaxo67ounJhqib0rXFhtLLIHmXcfrN_YrlKmIMMmL36uP71ylMOLLFSRijAADIFooWZGvDFWAYiDsOvKHqZ0ShTzMRD3RAJ03e_AntzwEgXsh2PUlDT_f_LFA0luYlMpRw,,&q={searchTerms} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRaxo67ounJhqib0rXFhtLLIHmXcfrN_YrlKmIMMmL36uP71ylMOLLFSRijAADIFooWZGvDFWAYiDsOvKHqZ0ShTzMRD3RAJ03e_AntzwEgXsh2PUlDT_f_LFA0luYlMpRw,,&q={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 FireFox: ======== FF ProfilePath: C:\Users\seb\AppData\Roaming\Mozilla\Firefox\Profiles\kgyvow17.default-1397056163264 FF DefaultSearchEngine: Web Search FF SelectedSearchEngine: Web Search FF Homepage: hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRaxo67ounJhqib0rXFhtLLIHmXcfrN_YrlKmIMMmL36uP71ylMOLLFSRijAADIFkVzMqCcxhlHKbI0wfcSFsxayc0RIW8Y7zFg-0sOD_Tp6ICQuH-n1YauH92qdMoUNkW-Osuw,, FF Keyword.URL: hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRaxo67ounJhqib0rXFhtLLIHmXcfrN_YrlKmIMMmL36uP71ylMOLLFSRijAADIFooWZGvDFWAYiDsOvKHqY_2c8_8CIkC4P4gzJISJv-Z4Y6eAz-Ys-P6VImAbP_BCTYcM53mA,,&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\seb\AppData\Roaming\Mozilla\Firefox\Profiles\kgyvow17.default-1397056163264\searchplugins\Web Search.xml FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-04-03] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-04-03] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-04-03] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! WebRep - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-12-29] ========================== Services (Whitelisted) ================= R2 AppleOSSMgr; C:\Windows\system32\AppleOSSMgr.exe [194432 2011-06-29] () R2 AppleTimeSrv; C:\Windows\system32\AppleTimeSrv.exe [100224 2011-06-29] (Apple Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44768 2011-11-28] (AVAST Software) R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation) R2 LPTSystemUpdater; C:\Program Files\LPT\srpts.exe [37408 2014-03-24] () ==================== Drivers (Whitelisted) ==================== R3 acpials; C:\Windows\System32\DRIVERS\acpials.sys [7680 2009-07-14] (Microsoft Corporation) R3 applebmt; C:\Windows\System32\DRIVERS\applebmt.sys [34304 2011-06-03] (Apple Inc.) R3 AppleBtBc; C:\Windows\System32\DRIVERS\AppleBtBc.sys [18560 2011-03-25] (Apple Inc.) R0 AppleHFS; C:\Windows\system32\Drivers\AppleHFS.sys [49664 2011-06-13] (Apple Inc.) R0 AppleMNT; C:\Windows\system32\Drivers\AppleMNT.sys [6784 2011-06-13] (Apple Inc.) R3 applemtm; C:\Windows\System32\DRIVERS\applemtm.sys [10880 2011-03-25] (Apple Inc.) R3 applemtp; C:\Windows\System32\DRIVERS\applemtp.sys [29824 2011-03-25] (Apple Inc.) R2 aswFsBlk; C:\Windows\system32\Drivers\aswFsBlk.sys [20568 2011-11-28] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [55128 2011-11-28] (AVAST Software) R1 aswRdr; C:\Windows\system32\Drivers\aswRdr.sys [34392 2011-11-28] (AVAST Software) R1 aswSnx; C:\Windows\system32\Drivers\aswSnx.sys [435032 2011-11-28] (AVAST Software) R1 aswSP; C:\Windows\system32\Drivers\aswSP.sys [314456 2011-11-28] (AVAST Software) R1 aswTdi; C:\Windows\system32\Drivers\aswTdi.sys [52952 2011-11-28] (AVAST Software) R3 CirrusFilter; C:\Windows\System32\DRIVERS\CS420x86.sys [14336 2011-06-13] (Cirrus Logic) R3 IRRemoteFlt; C:\Windows\System32\DRIVERS\IRFilter.sys [16512 2011-03-25] (Apple Inc.) R2 KeyAgent; C:\Windows\system32\drivers\KeyAgent.sys [6528 2011-06-15] (Apple Inc.) R3 KeyMagic; C:\Windows\System32\DRIVERS\KeyMagic.sys [26624 2011-05-26] (Apple Inc.) R2 MacHALDriver; C:\Windows\system32\drivers\MacHALDriver.sys [12928 2011-03-25] (Apple Inc.) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-13 22:54 - 2014-04-13 22:54 - 01146368 _____ (Farbar) C:\Users\seb\Downloads\FRST(2).exe 2014-04-13 22:48 - 2014-04-13 22:48 - 00008041 _____ () C:\Users\seb\Downloads\Addition.txt 2014-04-13 22:47 - 2014-04-13 22:55 - 00012749 _____ () C:\Users\seb\Downloads\FRST.txt 2014-04-13 22:46 - 2014-04-13 22:46 - 01146368 _____ (Farbar) C:\Users\seb\Downloads\FRST(1).exe 2014-04-13 22:44 - 2014-04-13 22:47 - 00000000 ____D () C:\FRST 2014-04-13 22:44 - 2014-04-13 22:44 - 01146368 _____ (Farbar) C:\Users\seb\Downloads\FRST.exe 2014-04-13 21:05 - 2014-04-06 21:42 - 00000000 ____D () C:\Program Files\iSafe 2014-04-13 21:01 - 2014-04-13 21:01 - 00000000 ____D () C:\Users\seb\AppData\Roaming\iSafe 2014-04-13 20:52 - 2014-04-13 20:52 - 295056970 _____ () C:\Windows\MEMORY.DMP 2014-04-13 20:52 - 2014-04-13 20:52 - 00156984 _____ () C:\Windows\Minidump\041314-30872-01.dmp 2014-04-13 20:52 - 2014-04-13 20:52 - 00000000 ____D () C:\Windows\Minidump 2014-04-13 20:25 - 2014-04-13 20:25 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-04-13 20:24 - 2014-04-13 22:15 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP 2014-04-13 20:24 - 2014-04-13 20:24 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard 2014-04-13 20:23 - 2014-04-13 20:23 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\seb\Downloads\SpyHunter-Installer.exe 2014-04-07 21:15 - 2014-04-06 21:42 - 00000000 ____D () C:\Users\seb\Desktop\Stare dane programu Firefox 2014-04-06 13:56 - 2014-04-13 22:22 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-06 13:56 - 2014-04-06 13:56 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-04-06 13:56 - 2014-04-06 13:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-04-06 13:05 - 2014-04-06 16:34 - 00000000 ____D () C:\Program Files\LPT 2014-04-06 13:04 - 2014-04-06 13:04 - 00236928 _____ () C:\Users\seb\Downloads\Adobe_Flash_Player-11_8_800_175_downloader-3LRiBEbS.exe 2014-04-06 13:04 - 2014-04-06 13:04 - 00000000 ____D () C:\Users\seb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker 2014-04-06 13:04 - 2014-04-06 13:04 - 00000000 ____D () C:\Users\seb\AppData\Local\FilesFrog Update Checker 2014-04-06 12:05 - 2014-04-06 12:11 - 00000000 ____D () C:\Users\seb\Desktop\Stein pa stein 2014-04-06 12:00 - 2014-04-13 21:49 - 00000000 ____D () C:\Users\seb\AppData\Local\ChomikBox 2014-04-06 12:00 - 2014-04-13 21:49 - 00000000 ____D () C:\Users\seb\.gstreamer-0.10 2014-04-06 11:58 - 2014-04-06 11:58 - 28266496 _____ () C:\Users\seb\Downloads\ChomikBox.msi 2014-04-05 17:21 - 2014-04-05 17:24 - 00000000 ____D () C:\Users\seb\AppData\Roaming\Apple Computer 2014-04-05 17:21 - 2014-04-05 17:21 - 00001761 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-04-05 17:21 - 2014-04-05 17:21 - 00000000 ____D () C:\Users\seb\AppData\Local\Apple Computer 2014-04-05 17:21 - 2012-08-21 13:01 - 00026840 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2014-04-05 17:20 - 2014-04-05 17:21 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-04-05 17:20 - 2014-04-05 17:21 - 00000000 ____D () C:\Program Files\iTunes 2014-04-05 17:20 - 2014-04-05 17:20 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-04-05 17:20 - 2014-04-05 17:20 - 00000000 ____D () C:\Program Files\iPod 2014-04-05 17:19 - 2014-04-05 17:20 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-04-05 17:19 - 2014-04-05 17:19 - 00000000 ____D () C:\Program Files\Bonjour 2014-04-05 17:17 - 2014-04-05 17:18 - 137699152 _____ (Apple Inc.) C:\Users\seb\Downloads\iTunesSetup.exe 2014-04-05 17:15 - 2014-04-05 17:16 - 00000000 ____D () C:\Users\seb\Desktop\cd2 2014-04-05 17:14 - 2014-04-05 17:15 - 00000000 ____D () C:\Users\seb\Desktop\cd1 2014-04-03 18:13 - 2014-04-03 18:13 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-03-25 18:36 - 2014-03-25 18:36 - 00005163 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-03-25 18:36 - 2013-12-18 22:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-03-25 18:36 - 2013-12-18 22:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-03-25 18:36 - 2013-12-18 22:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-03-25 18:36 - 2013-12-18 22:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-03-25 18:34 - 2014-03-25 18:34 - 00921000 _____ (Oracle Corporation) C:\Users\seb\Downloads\jxpiinstall(1).exe 2014-03-24 16:32 - 2014-03-24 16:32 - 00000000 ____D () C:\Users\seb\AppData\Local\Skype 2014-03-24 16:31 - 2014-03-24 16:31 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-24 16:31 - 2014-03-24 16:31 - 00000000 ____D () C:\Program Files\Common Files\Skype ==================== One Month Modified Files and Folders ======= 2014-04-13 22:55 - 2014-04-13 22:47 - 00012749 _____ () C:\Users\seb\Downloads\FRST.txt 2014-04-13 22:55 - 2011-12-29 16:42 - 00000292 _____ () C:\Windows\Tasks\AutoKMS.job 2014-04-13 22:54 - 2014-04-13 22:54 - 01146368 _____ (Farbar) C:\Users\seb\Downloads\FRST(2).exe 2014-04-13 22:54 - 2012-01-19 19:14 - 00000000 ____D () C:\Users\seb\AppData\Roaming\Skype 2014-04-13 22:54 - 2011-12-29 16:42 - 00151552 _____ () C:\Windows\KMSEmulator.exe 2014-04-13 22:53 - 2011-12-28 23:13 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-13 22:48 - 2014-04-13 22:48 - 00008041 _____ () C:\Users\seb\Downloads\Addition.txt 2014-04-13 22:47 - 2014-04-13 22:44 - 00000000 ____D () C:\FRST 2014-04-13 22:46 - 2014-04-13 22:46 - 01146368 _____ (Farbar) C:\Users\seb\Downloads\FRST(1).exe 2014-04-13 22:44 - 2014-04-13 22:44 - 01146368 _____ (Farbar) C:\Users\seb\Downloads\FRST.exe 2014-04-13 22:41 - 2009-07-14 06:34 - 00014192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-13 22:41 - 2009-07-14 06:34 - 00014192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-13 22:38 - 2012-02-07 18:42 - 00001030 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-13 22:22 - 2014-04-06 13:56 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-13 22:15 - 2014-04-13 20:24 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP 2014-04-13 21:52 - 2011-12-29 16:21 - 00691160 _____ () C:\Windows\system32\perfh015.dat 2014-04-13 21:52 - 2011-12-29 16:21 - 00132622 _____ () C:\Windows\system32\perfc015.dat 2014-04-13 21:52 - 2011-12-28 23:16 - 01532096 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-13 21:51 - 2011-12-28 22:53 - 01514447 _____ () C:\Windows\WindowsUpdate.log 2014-04-13 21:49 - 2014-04-06 12:00 - 00000000 ____D () C:\Users\seb\AppData\Local\ChomikBox 2014-04-13 21:49 - 2014-04-06 12:00 - 00000000 ____D () C:\Users\seb\.gstreamer-0.10 2014-04-13 21:01 - 2014-04-13 21:01 - 00000000 ____D () C:\Users\seb\AppData\Roaming\iSafe 2014-04-13 20:53 - 2012-02-07 18:42 - 00001026 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-13 20:53 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-13 20:52 - 2014-04-13 20:52 - 295056970 _____ () C:\Windows\MEMORY.DMP 2014-04-13 20:52 - 2014-04-13 20:52 - 00156984 _____ () C:\Windows\Minidump\041314-30872-01.dmp 2014-04-13 20:52 - 2014-04-13 20:52 - 00000000 ____D () C:\Windows\Minidump 2014-04-13 20:52 - 2009-07-14 06:39 - 00045392 _____ () C:\Windows\setupact.log 2014-04-13 20:25 - 2014-04-13 20:25 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-04-13 20:24 - 2014-04-13 20:24 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard 2014-04-13 20:23 - 2014-04-13 20:23 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\seb\Downloads\SpyHunter-Installer.exe 2014-04-13 19:47 - 2011-12-28 22:59 - 00000000 ____D () C:\Users\seb 2014-04-13 19:47 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp 2014-04-06 21:42 - 2014-04-13 21:05 - 00000000 ____D () C:\Program Files\iSafe 2014-04-06 21:42 - 2014-04-07 21:15 - 00000000 ____D () C:\Users\seb\Desktop\Stare dane programu Firefox 2014-04-06 21:42 - 2011-12-29 16:42 - 00000000 ____D () C:\Windows\AutoKMS 2014-04-06 21:42 - 2011-12-29 16:38 - 00000000 ____D () C:\Windows\system32\Macromed 2014-04-06 21:42 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration 2014-04-06 16:34 - 2014-04-06 13:05 - 00000000 ____D () C:\Program Files\LPT 2014-04-06 13:56 - 2014-04-06 13:56 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-04-06 13:56 - 2014-04-06 13:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-04-06 13:09 - 2012-02-07 18:41 - 00000000 ____D () C:\Program Files\Adobe 2014-04-06 13:04 - 2014-04-06 13:04 - 00236928 _____ () C:\Users\seb\Downloads\Adobe_Flash_Player-11_8_800_175_downloader-3LRiBEbS.exe 2014-04-06 13:04 - 2014-04-06 13:04 - 00000000 ____D () C:\Users\seb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker 2014-04-06 13:04 - 2014-04-06 13:04 - 00000000 ____D () C:\Users\seb\AppData\Local\FilesFrog Update Checker 2014-04-06 12:11 - 2014-04-06 12:05 - 00000000 ____D () C:\Users\seb\Desktop\Stein pa stein 2014-04-06 11:58 - 2014-04-06 11:58 - 28266496 _____ () C:\Users\seb\Downloads\ChomikBox.msi 2014-04-06 11:19 - 2009-07-14 06:53 - 00032610 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-06 11:18 - 2011-12-28 23:21 - 00006100 _____ () C:\Windows\PFRO.log 2014-04-05 17:24 - 2014-04-05 17:21 - 00000000 ____D () C:\Users\seb\AppData\Roaming\Apple Computer 2014-04-05 17:21 - 2014-04-05 17:21 - 00001761 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-04-05 17:21 - 2014-04-05 17:21 - 00000000 ____D () C:\Users\seb\AppData\Local\Apple Computer 2014-04-05 17:21 - 2014-04-05 17:20 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-04-05 17:21 - 2014-04-05 17:20 - 00000000 ____D () C:\Program Files\iTunes 2014-04-05 17:20 - 2014-04-05 17:20 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-04-05 17:20 - 2014-04-05 17:20 - 00000000 ____D () C:\Program Files\iPod 2014-04-05 17:20 - 2014-04-05 17:19 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-04-05 17:20 - 2011-12-28 23:12 - 00000000 ____D () C:\ProgramData\Apple 2014-04-05 17:19 - 2014-04-05 17:19 - 00000000 ____D () C:\Program Files\Bonjour 2014-04-05 17:18 - 2014-04-05 17:17 - 137699152 _____ (Apple Inc.) C:\Users\seb\Downloads\iTunesSetup.exe 2014-04-05 17:16 - 2014-04-05 17:15 - 00000000 ____D () C:\Users\seb\Desktop\cd2 2014-04-05 17:15 - 2014-04-05 17:14 - 00000000 ____D () C:\Users\seb\Desktop\cd1 2014-04-04 16:31 - 2013-08-18 16:37 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-04-03 18:13 - 2014-04-03 18:13 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-03-25 18:37 - 2013-10-18 12:37 - 00000000 ____D () C:\ProgramData\Oracle 2014-03-25 18:36 - 2014-03-25 18:36 - 00005163 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-03-25 18:36 - 2013-08-18 11:54 - 00000000 ____D () C:\Program Files\Java 2014-03-25 18:34 - 2014-03-25 18:34 - 00921000 _____ (Oracle Corporation) C:\Users\seb\Downloads\jxpiinstall(1).exe 2014-03-25 18:17 - 2012-01-19 19:14 - 00000000 ___RD () C:\Program Files\Skype 2014-03-24 16:32 - 2014-03-24 16:32 - 00000000 ____D () C:\Users\seb\AppData\Local\Skype 2014-03-24 16:31 - 2014-03-24 16:31 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-03-24 16:31 - 2014-03-24 16:31 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-03-24 16:31 - 2012-01-19 19:14 - 00000000 ____D () C:\ProgramData\Skype Some content of TEMP: ==================== C:\Users\seb\AppData\Local\Temp\7-zip.dll C:\Users\seb\AppData\Local\Temp\7z.dll C:\Users\seb\AppData\Local\Temp\7z.exe C:\Users\seb\AppData\Local\Temp\ApnStub.exe C:\Users\seb\AppData\Local\Temp\GoogleToolbarInstaller_en32_signed.exe C:\Users\seb\AppData\Local\Temp\Installer.exe C:\Users\seb\AppData\Local\Temp\install_flash_player_11_plugin.exe C:\Users\seb\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe C:\Users\seb\AppData\Local\Temp\LiveSupport_setup.exe C:\Users\seb\AppData\Local\Temp\OptimizerPro.exe C:\Users\seb\AppData\Local\Temp\setup.exe C:\Users\seb\AppData\Local\Temp\SHSetup.exe C:\Users\seb\AppData\Local\Temp\SkypeSetup.exe C:\Users\seb\AppData\Local\Temp\uninst1.exe C:\Users\seb\AppData\Local\Temp\UpdateCheckerSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-13 13:20 ==================== End Of Log ============================