Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-04-2014 Ran by Ania (administrator) on ANIA-PC on 20-04-2014 00:22:21 Running from C:\Users\Ania\Desktop\Nowy folder Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: Polish Internet Explorer Version 7 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe (AVAST Software) D:\AVAST Software\Avast\AvastSvc.exe (Agere Systems) C:\Windows\system32\agrsmsvc.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (Sony Corporation) D:\Programy\sony\PMBDeviceInfoProvider.exe (Toshiba Europe GmbH) C:\Program Files\Toshiba TEMPRO\TempoSVC.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA CORPORATION) c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Toshiba) C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\NDSTray.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (TOSHIBA Corporation.) C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\SmoothView\SmoothView.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sony Corporation) D:\Programy\sony\PMBVolumeWatcher.exe (AVAST Software) D:\AVAST Software\Avast\AvastUI.exe (TOSHIBA) C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe (TOSHIBA Corporation.) C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Mozilla Corporation) D:\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\system32\wuauclt.exe (Mozilla Corporation) D:\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Microsoft Corporation) C:\Windows\system32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1348904 2008-08-14] (Synaptics, Inc.) HKLM\...\Run: [NDSTray.exe] => NDSTray.exe HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2008-01-21] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6037504 2008-04-08] (Realtek Semiconductor) HKLM\...\Run: [HDMICtrlMan] => C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe [716800 2008-04-26] (TOSHIBA Corporation.) HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [431456 2008-01-17] (TOSHIBA Corporation) HKLM\...\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [54608 2007-10-31] (TOSHIBA Corporation) HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [509816 2008-01-25] (TOSHIBA Corporation) HKLM\...\Run: [Toshiba Registration] => C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe [574864 2008-01-11] (Toshiba) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [hpqSRMon] => [X] HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [PMBVolumeWatcher] => D:\Programy\sony\PMBVolumeWatcher.exe [2534936 2014-02-24] (Sony Corporation) HKLM\...\Run: [AvastUI.exe] => D:\AVAST Software\Avast\AvastUI.exe [3854640 2014-03-19] (AVAST Software) HKLM\...\Run: [cfFncEnabler.exe] => cfFncEnabler.exe Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-1288835223-963482569-2430470763-1000\...\Run: [TOSCDSPD] => C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [430080 2008-04-24] (TOSHIBA) HKU\S-1-5-21-1288835223-963482569-2430470763-1000\...\MountPoints2: {44a3d4f4-9270-11e2-9df0-00215d6309aa} - G:\Toshiba\Launcher\start.exe Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA; HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA; HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA; SearchScopes: HKLM - DefaultScope {A03A5F55-3E3D-4D28-B20A-0A22C4250965} URL = http://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA; SearchScopes: HKLM - {A03A5F55-3E3D-4D28-B20A-0A22C4250965} URL = http://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA; SearchScopes: HKCU - DefaultScope {A03A5F55-3E3D-4D28-B20A-0A22C4250965} URL = http://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA; SearchScopes: HKCU - {A03A5F55-3E3D-4D28-B20A-0A22C4250965} URL = http://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA; BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\kshtbp47.default FF Homepage: www.pajacyk.pl FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @parallelgraphics.com/Cortona - C:\Program Files\Common Files\ParallelGraphics\Cortona\npcortona.dll (ParallelGraphics) FF Plugin: @videolan.org/vlc,version=2.0.8 - D:\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Ania\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Extension: Adblock Plus - C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\kshtbp47.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-03-22] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - D:\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - D:\AVAST Software\Avast\WebRep\FF [2013-03-22] FF StartMenuInternet: FIREFOX.EXE - D:\Mozilla Firefox\firefox.exe ========================== Services (Whitelisted) ================= R2 avast! Antivirus; D:\AVAST Software\Avast\AvastSvc.exe [50344 2014-03-19] (AVAST Software) R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2008-04-17] (TOSHIBA CORPORATION) R2 PMBDeviceInfoProvider; D:\Programy\sony\PMBDeviceInfoProvider.exe [481816 2014-02-24] (Sony Corporation) R3 SmartFaceVWatchSrv; C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe [73728 2008-04-24] (Toshiba) R2 TempoMonitoringService; C:\Program Files\Toshiba TEMPRO\TempoSVC.exe [99720 2008-04-24] (Toshiba Europe GmbH) R2 TOSHIBA SMART Log Service; C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [126976 2007-12-03] (TOSHIBA Corporation) R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.) ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-03-19] (AVAST Software) R1 AswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2014-03-19] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-03-19] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [776976 2014-03-19] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [411552 2014-03-19] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2014-03-19] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180760 2014-03-19] () R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [141408 2008-02-27] (Realtek Semiconductor Corp.) R3 UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [18432 2007-12-17] (Chicony Electronics Co., Ltd.) S3 igfx; system32\DRIVERS\igdkmd32.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-20 00:21 - 2014-04-20 00:22 - 00000000 ____D () C:\Users\Ania\Desktop\Nowy folder 2014-04-20 00:21 - 2014-04-20 00:22 - 00000000 ____D () C:\FRST 2014-04-18 12:02 - 2014-04-18 12:02 - 00000680 _____ () C:\Users\Ania\AppData\Local\d3d9caps.dat 2014-04-14 17:28 - 2014-04-14 17:28 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-14 17:28 - 2014-04-14 17:28 - 00000000 _____ () C:\Windows\setupact.log 2014-04-09 22:42 - 2014-04-09 22:42 - 00344864 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-05 20:51 - 2014-04-19 23:32 - 00000000 ____D () C:\Users\Ania\Desktop\narty jungfrau 03.2014 2014-04-03 00:01 - 2014-04-03 00:01 - 01908225 _____ () C:\Users\Ania\Downloads\VirtualDub-1.10.4.zip 2014-04-03 00:00 - 2014-04-03 00:00 - 00692376 _____ () C:\Users\Ania\Downloads\VirtualDub(13335).exe 2014-04-02 23:37 - 2014-04-03 00:05 - 00000000 ____D () C:\piz 2014-04-02 23:32 - 2014-04-02 23:32 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\IrfanView 2014-04-02 23:32 - 2014-04-02 23:32 - 00000000 ____D () C:\Program Files\IrfanView 2014-04-02 23:31 - 2014-04-02 23:31 - 01883792 _____ (Irfan Skiljan) C:\Users\Ania\Downloads\iview437_setup.exe 2014-04-02 17:59 - 2014-04-02 17:59 - 00000000 ____D () C:\Users\Ania\Documents\Ulead DVD MovieFactory 2014-04-02 17:59 - 2014-04-02 17:59 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\Ulead Systems 2014-04-02 17:05 - 2014-04-02 17:05 - 00000235 _____ () C:\Users\Ania\Desktop\Mała Księgowość Rzeczpospolitej.lnk 2014-04-02 17:05 - 2014-04-02 17:05 - 00000221 _____ () C:\Users\Ania\Desktop\Biuro Rachunkowe Rzeczpospolitej.lnk 2014-04-02 17:05 - 2014-04-02 17:05 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mała Księgowość Rzeczpospolitej 2014-04-02 17:02 - 2014-04-02 17:02 - 17877048 _____ () C:\Users\Ania\Downloads\Mała Księgowość (BR) 2014.exe 2014-03-23 00:00 - 2014-03-23 00:00 - 00000000 ____D () C:\ProgramData\WindowsSearch ==================== One Month Modified Files and Folders ======= 2014-04-20 00:22 - 2014-04-20 00:21 - 00000000 ____D () C:\Users\Ania\Desktop\Nowy folder 2014-04-20 00:22 - 2014-04-20 00:21 - 00000000 ____D () C:\FRST 2014-04-20 00:17 - 2013-08-12 16:08 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-20 00:01 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-20 00:01 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-19 23:32 - 2014-04-05 20:51 - 00000000 ____D () C:\Users\Ania\Desktop\narty jungfrau 03.2014 2014-04-19 23:18 - 2013-09-17 23:50 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\vlc 2014-04-19 22:50 - 2013-03-21 20:55 - 01681386 _____ () C:\Windows\WindowsUpdate.log 2014-04-19 22:49 - 2008-01-21 08:24 - 01495264 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-19 22:49 - 2008-01-21 08:24 - 00672140 _____ () C:\Windows\system32\perfh015.dat 2014-04-19 22:49 - 2008-01-21 08:24 - 00130516 _____ () C:\Windows\system32\perfc015.dat 2014-04-19 22:43 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-19 01:40 - 2006-11-02 15:01 - 00032546 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-18 16:14 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-04-18 12:02 - 2014-04-18 12:02 - 00000680 _____ () C:\Users\Ania\AppData\Local\d3d9caps.dat 2014-04-14 17:28 - 2014-04-14 17:28 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-14 17:28 - 2014-04-14 17:28 - 00000000 _____ () C:\Windows\setupact.log 2014-04-14 17:23 - 2013-03-21 22:24 - 00099328 _____ () C:\Users\Ania\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-04-09 23:12 - 2013-03-21 23:52 - 00000000 ____D () C:\Users\Ania\Desktop\jacek 2014-04-09 22:42 - 2014-04-09 22:42 - 00344864 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-07 21:23 - 2008-07-04 11:49 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-04-05 20:50 - 2013-03-21 22:13 - 00000000 ____D () C:\Users\Ania 2014-04-03 00:05 - 2014-04-02 23:37 - 00000000 ____D () C:\piz 2014-04-03 00:01 - 2014-04-03 00:01 - 01908225 _____ () C:\Users\Ania\Downloads\VirtualDub-1.10.4.zip 2014-04-03 00:00 - 2014-04-03 00:00 - 00692376 _____ () C:\Users\Ania\Downloads\VirtualDub(13335).exe 2014-04-02 23:32 - 2014-04-02 23:32 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\IrfanView 2014-04-02 23:32 - 2014-04-02 23:32 - 00000000 ____D () C:\Program Files\IrfanView 2014-04-02 23:31 - 2014-04-02 23:31 - 01883792 _____ (Irfan Skiljan) C:\Users\Ania\Downloads\iview437_setup.exe 2014-04-02 17:59 - 2014-04-02 17:59 - 00000000 ____D () C:\Users\Ania\Documents\Ulead DVD MovieFactory 2014-04-02 17:59 - 2014-04-02 17:59 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\Ulead Systems 2014-04-02 17:05 - 2014-04-02 17:05 - 00000235 _____ () C:\Users\Ania\Desktop\Mała Księgowość Rzeczpospolitej.lnk 2014-04-02 17:05 - 2014-04-02 17:05 - 00000221 _____ () C:\Users\Ania\Desktop\Biuro Rachunkowe Rzeczpospolitej.lnk 2014-04-02 17:05 - 2014-04-02 17:05 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mała Księgowość Rzeczpospolitej 2014-04-02 17:02 - 2014-04-02 17:02 - 17877048 _____ () C:\Users\Ania\Downloads\Mała Księgowość (BR) 2014.exe 2014-04-01 11:04 - 2013-03-22 22:31 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-03-31 09:35 - 2013-03-22 23:35 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-03-30 20:27 - 2013-04-24 21:52 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\Skype 2014-03-24 20:26 - 2014-03-07 12:51 - 00000000 ____D () C:\Users\Ania\Documents\Sony PMB 2014-03-23 00:00 - 2014-03-23 00:00 - 00000000 ____D () C:\ProgramData\WindowsSearch ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-19 22:51 ==================== End Of Log ============================