Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-11-2014 01 Ran by Ewa (administrator) on EWA-KOMPUTER on 14-11-2014 16:11:25 Running from C:\otl Loaded Profile: Ewa (Available profiles: Ewa & konto) Platform: Microsoft Windows 7 Professional N Service Pack 1 (X86) OS Language: Polski (Polska) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe () C:\ProgramData\DatacardService\DCService.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKU\S-1-5-21-2846243105-2044209956-1520485455-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-2846243105-2044209956-1520485455-1000\...\MountPoints2: {63a9430a-898c-11e2-be55-e839dfc91cf7} - F:\AutoRun.exe HKU\S-1-5-21-2846243105-2044209956-1520485455-1000\...\MountPoints2: {6ab85ce3-895c-11e2-9143-e839dfc91cf7} - F:\AutoRun.exe HKU\S-1-5-21-2846243105-2044209956-1520485455-1000\...\MountPoints2: {6ab85cff-895c-11e2-9143-e839dfc91cf7} - F:\AutoRun.exe HKU\S-1-5-21-2846243105-2044209956-1520485455-1000\...\MountPoints2: {ffecbc6c-a406-11e2-91ee-e839dfc91cf7} - F:\AutoRun.exe ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKLM - DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = BHO: No Name -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> No File Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll No File Tcpip\Parameters: [DhcpNameServer] Tcpip\..\Interfaces\{0E5C8208-E8F6-4938-B614-F5732E96C738}: [NameServer] Tcpip\..\Interfaces\{63AB73A5-6AD7-4F31-9932-AAC2CB9410BA}: [NameServer] Tcpip\..\Interfaces\{CFB5FFF2-3979-43F7-A104-99F251EF6F6A}: [NameServer] FireFox: ======== FF ProfilePath: C:\Users\Ewa\AppData\Roaming\Mozilla\Firefox\Profiles\ovvqtwsa.default FF DefaultSearchEngine: YAC Safe Search FF SearchEngineOrder.1: YAC Safe Search FF SearchEngineOrder.3: Bing FF SelectedSearchEngine: YAC Safe Search FF Homepage: hxxp:// FF Plugin: -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll () FF Plugin: -> disabled No File FF Plugin:,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\ddg.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\wtu-secure-search.xml FF Extension: antmarkantcom - C:\Users\Ewa\AppData\Roaming\Mozilla\Firefox\Profiles\ovvqtwsa.default\Extensions\ [2014-10-25] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14] Chrome: ======= CHR Profile: C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (No Name) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecldhagehndokdmaiaigoaecbmbnmfkc [2014-10-25] CHR Extension: (No Name) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kidmhllhjmmmnpbiaihafgchacpmokof [2013-08-16] CHR Extension: (No Name) - C:\Users\Ewa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-10-25] CHR HKLM\...\Chrome\Extension: [kidmhllhjmmmnpbiaihafgchacpmokof] - C:\Program Files\Lyrmix\130.crx [] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] () [File not signed] R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) S3 MozillaMaintenance; C:\Program Files\Mozilla Maintenance Service\maintenanceservice_tmp.exe [114288 2014-11-07] (Mozilla Foundation) S2 vToolbarUpdater18.1.10; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.10\ToolbarUpdater.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-10-28] (AVG Technologies) S3 KMWDFILTERx86; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [25088 2009-04-29] (Windows (R) Codename Longhorn DDK provider) R3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [109256 2014-10-24] (Qualcomm Atheros Co., Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2014-11-14] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation) S2 SPDRIVER_1.37.0.1375; \??\C:\Program Files\ShopperPro\JSDriver\\jsdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-14 16:10 - 2014-11-14 16:11 - 00000000 ____D () C:\FRST 2014-11-14 16:07 - 2014-11-14 16:07 - 01108480 _____ (Farbar) C:\Users\Ewa\Downloads\FRST.exe 2014-11-14 16:04 - 2014-11-14 16:04 - 00602112 _____ (OldTimer Tools) C:\Users\Ewa\Downloads\OTL.exe 2014-11-14 16:02 - 2014-11-14 16:11 - 00000000 ____D () C:\otl 2014-11-13 22:11 - 2014-11-13 22:11 - 00000000 ____D () C:\Users\konto\AppData\Roaming\Skype 2014-11-13 22:11 - 2014-11-13 22:11 - 00000000 ____D () C:\Users\konto\AppData\Local\Skype 2014-11-13 22:10 - 2014-11-13 22:10 - 00000000 ____D () C:\Users\konto\AppData\Local\Macromedia 2014-11-13 22:09 - 2014-11-13 22:09 - 00001069 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-11-13 22:09 - 2014-11-13 22:09 - 00000000 ____D () C:\Users\konto\AppData\Roaming\Mozilla 2014-11-13 22:09 - 2014-11-13 22:09 - 00000000 ____D () C:\Users\konto\AppData\Local\Mozilla 2014-11-13 22:06 - 2014-11-13 22:06 - 00000000 __SHD () C:\Users\konto\AppData\Local\EmieUserList 2014-11-13 22:06 - 2014-11-13 22:06 - 00000000 __SHD () C:\Users\konto\AppData\Local\EmieSiteList 2014-11-13 22:06 - 2014-11-13 22:06 - 00000000 __SHD () C:\Users\konto\AppData\Local\EmieBrowserModeList 2014-11-13 22:06 - 2014-11-13 22:06 - 00000000 ____D () C:\Users\konto\AppData\Roaming\Macromedia 2014-11-13 22:04 - 2014-11-13 22:05 - 00000000 ____D () C:\Users\konto 2014-11-13 22:04 - 2014-11-13 22:04 - 00001385 _____ () C:\Users\konto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-11-13 22:04 - 2014-11-13 22:04 - 00000020 ___SH () C:\Users\konto\ntuser.ini 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 _SHDL () C:\Users\konto\Ustawienia lokalne 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 _SHDL () C:\Users\konto\Szablony 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 _SHDL () C:\Users\konto\Moje dokumenty 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 _SHDL () C:\Users\konto\Menu Start 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 _SHDL () C:\Users\konto\Documents\Moje wideo 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 _SHDL () C:\Users\konto\Documents\Moje obrazy 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 _SHDL () C:\Users\konto\Documents\Moja muzyka 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 _SHDL () C:\Users\konto\Dane aplikacji 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 _SHDL () C:\Users\konto\AppData\Roaming\Microsoft\Windows\Start Menu\Programy 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 _SHDL () C:\Users\konto\AppData\Local\Historia 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 _SHDL () C:\Users\konto\AppData\Local\Dane aplikacji 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 ____D () C:\Users\konto\AppData\Roaming\Adobe 2014-11-13 22:04 - 2014-11-13 22:04 - 00000000 ____D () C:\Users\konto\AppData\Local\VirtualStore 2014-11-13 22:04 - 2009-07-14 05:09 - 00000000 ___RD () C:\Users\konto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-11-13 22:04 - 2009-07-14 05:06 - 00000000 ___RD () C:\Users\konto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-11-13 20:21 - 2014-11-14 16:01 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-11-13 20:21 - 2014-11-13 20:21 - 00001024 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-11-13 20:21 - 2014-11-13 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-11-13 20:21 - 2014-11-13 20:21 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-11-13 20:21 - 2014-11-13 20:21 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-11-13 20:21 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-11-13 20:21 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-11-13 20:21 - 2014-10-01 11:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-11-13 20:09 - 2014-11-13 21:16 - 00000000 ____D () C:\AdwCleaner 2014-11-13 20:02 - 2014-11-13 20:02 - 00000000 __SHD () C:\Users\Ewa\AppData\Local\EmieBrowserModeList 2014-11-12 15:53 - 2014-11-05 18:50 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-11-12 15:53 - 2014-11-05 18:50 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-11-12 15:53 - 2014-11-05 18:47 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-11-12 15:53 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-12 15:53 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-11-12 15:53 - 2014-10-03 02:44 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-12 15:53 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-12 15:53 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-11-12 15:53 - 2014-10-03 02:44 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-12 15:53 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-11-12 15:53 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-11-12 15:53 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-11-12 15:53 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-11-12 15:52 - 2014-11-07 20:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-11-12 15:52 - 2014-11-06 04:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-11-12 15:52 - 2014-11-06 04:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-11-12 15:52 - 2014-11-06 04:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-11-12 15:52 - 2014-11-06 04:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-11-12 15:52 - 2014-11-06 04:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-11-12 15:52 - 2014-11-06 04:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-11-12 15:52 - 2014-11-06 04:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-11-12 15:52 - 2014-11-06 04:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-11-12 15:52 - 2014-11-06 04:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-11-12 15:52 - 2014-11-06 04:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-11-12 15:52 - 2014-11-06 04:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-11-12 15:52 - 2014-11-06 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-11-12 15:52 - 2014-11-06 03:59 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-11-12 15:52 - 2014-11-06 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-11-12 15:52 - 2014-11-06 03:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-11-12 15:52 - 2014-11-06 03:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-11-12 15:52 - 2014-11-06 03:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-11-12 15:52 - 2014-11-06 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-11-12 15:52 - 2014-11-06 03:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-11-12 15:52 - 2014-11-06 03:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-11-12 15:52 - 2014-11-06 03:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-11-12 15:52 - 2014-11-06 03:22 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-11-12 15:52 - 2014-11-06 03:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-11-12 15:52 - 2014-11-06 03:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-11-12 15:52 - 2014-11-06 03:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-11-12 15:52 - 2014-11-06 03:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-11-12 15:52 - 2014-11-06 02:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-11-12 15:52 - 2014-11-06 02:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-11-12 15:52 - 2014-11-06 02:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-11-12 15:52 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-12 15:52 - 2014-10-14 02:56 - 00136632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-12 15:52 - 2014-10-14 02:50 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-12 15:52 - 2014-10-14 02:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-11-12 15:52 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-12 15:52 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-12 15:52 - 2014-10-10 01:45 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-12 15:52 - 2014-09-19 10:23 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-12 15:52 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-11-12 15:52 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-12 15:52 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-11-12 15:52 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-11-12 15:52 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-11-12 15:52 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-11-09 14:22 - 2014-11-13 22:04 - 00424498 _____ () C:\Windows\PFRO.log 2014-11-09 14:09 - 2014-11-09 14:09 - 00000000 __SHD () C:\Users\Ewa\AppData\Local\EmieUserList 2014-11-09 14:09 - 2014-11-09 14:09 - 00000000 __SHD () C:\Users\Ewa\AppData\Local\EmieSiteList 2014-11-09 14:03 - 2014-11-09 14:03 - 00100760 _____ () C:\Users\Ewa\AppData\Local\GDIPFONTCACHEV1.DAT 2014-11-08 20:42 - 2014-11-14 15:50 - 00002694 _____ () C:\Windows\setupact.log 2014-11-08 20:42 - 2014-11-13 15:18 - 00435768 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-08 20:42 - 2014-11-08 20:42 - 00000000 _____ () C:\Windows\setuperr.log 2014-10-28 15:20 - 2014-10-28 19:20 - 00000000 ____D () C:\Users\Ewa\AppData\Local\AVG Web TuneUp 2014-10-28 15:18 - 2014-11-09 14:05 - 00000000 ____D () C:\Program Files\AVG Web TuneUp 2014-10-28 15:18 - 2014-10-28 15:19 - 00000000 ____D () C:\ProgramData\AVG Web TuneUp 2014-10-28 15:18 - 2014-10-28 15:17 - 00042784 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys 2014-10-26 18:43 - 2014-10-26 18:43 - 00000000 ____D () C:\Users\Ewa\AppData\Roaming\AVG2015 2014-10-26 18:42 - 2014-11-13 20:07 - 00000000 ____D () C:\ProgramData\AVG2015 2014-10-26 18:42 - 2014-11-13 20:05 - 00000000 ___HD () C:\$AVG 2014-10-26 18:42 - 2014-10-26 18:42 - 00000000 ____D () C:\Users\Ewa\AppData\Roaming\TuneUp Software 2014-10-26 18:37 - 2014-11-13 20:07 - 00000000 ____D () C:\ProgramData\MFAData 2014-10-26 18:37 - 2014-11-09 14:15 - 00000000 ____D () C:\Users\Ewa\AppData\Local\Avg2015 2014-10-26 18:37 - 2014-10-26 18:37 - 00000000 ____D () C:\Users\Ewa\AppData\Local\MFAData 2014-10-24 18:29 - 2014-10-24 18:29 - 01112288 _____ (Microsoft Corporation) C:\Windows\system32\wdfcoinstaller01007.dll 2014-10-24 18:29 - 2014-10-24 18:29 - 00109256 _____ (Qualcomm Atheros Co., Ltd.) C:\Windows\system32\Drivers\L1C62x86.sys 2014-10-24 18:29 - 2014-10-24 18:29 - 00076544 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jubusenum.sys 2014-10-24 18:29 - 2014-10-24 18:29 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf 2014-10-19 18:56 - 2014-10-19 19:05 - 00000000 ____D () C:\ProgramData\TEMP 2014-10-19 18:56 - 2014-10-19 18:56 - 00172032 _____ (Jin Hui E-mail: Web: C:\Windows\system32\AniGIF.ocx 2014-10-19 18:53 - 2014-10-19 18:54 - 00000000 ____D () C:\Users\Ewa\AppData\Roaming\DAEMON Tools Lite 2014-10-19 18:52 - 2014-10-19 18:55 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite 2014-10-17 15:01 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-10-17 15:00 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2014-10-17 15:00 - 2014-07-17 02:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-10-17 15:00 - 2014-07-17 02:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-10-17 15:00 - 2014-07-17 02:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-10-17 15:00 - 2014-07-17 02:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2014-10-17 15:00 - 2014-07-17 02:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2014-10-17 15:00 - 2014-07-17 02:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-10-17 15:00 - 2014-07-17 02:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-10-17 14:59 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-17 14:59 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-17 14:59 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-14 16:11 - 2009-07-14 05:02 - 00029184 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-14 16:11 - 2009-07-14 05:02 - 00029184 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-14 16:01 - 2013-06-05 16:27 - 00000350 _____ () C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2014-11-14 15:56 - 2013-01-22 10:00 - 01246181 _____ () C:\Windows\WindowsUpdate.log 2014-11-14 15:50 - 2009-07-14 05:17 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-13 22:18 - 2011-04-12 05:45 - 00740446 _____ () C:\Windows\system32\perfh015.dat 2014-11-13 22:18 - 2011-04-12 05:45 - 00155988 _____ () C:\Windows\system32\perfc015.dat 2014-11-13 22:18 - 2010-11-20 22:03 - 01669606 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-13 22:17 - 2013-02-28 21:08 - 00000000 ____D () C:\Users\Ewa\AppData\Roaming\Skype 2014-11-13 22:11 - 2014-07-25 19:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-11-13 22:11 - 2013-02-28 21:08 - 00002505 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-11-13 22:11 - 2013-02-28 21:08 - 00000000 ____D () C:\ProgramData\Skype 2014-11-13 22:09 - 2013-07-04 09:35 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-11-13 22:09 - 2013-01-22 17:50 - 00001081 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-11-13 22:09 - 2013-01-22 17:50 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-11-13 21:52 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-11-13 17:42 - 2013-01-22 10:10 - 00000000 ___RD () C:\Users\Ewa\Desktop\koniu 2014-11-13 15:16 - 2014-04-30 15:54 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-11-13 15:16 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\pl-PL 2014-11-12 15:57 - 2013-08-15 09:42 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-12 15:55 - 2013-01-25 18:40 - 100445232 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-11 14:55 - 2013-01-22 10:11 - 00000000 ____D () C:\Users\Ewa\Desktop\Prev Med-Rogula 2014-11-11 14:54 - 2013-01-22 10:09 - 00000000 ____D () C:\Users\Ewa\Desktop\fb 2014-11-11 14:52 - 2013-01-22 10:07 - 00000000 ___RD () C:\Users\Ewa\Desktop\boczusiek 2014-11-09 14:12 - 2013-01-22 10:06 - 00000000 ____D () C:\Users\Ewa 2014-11-09 14:09 - 2013-01-22 10:06 - 00001633 _____ () C:\Users\Ewa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-11-08 20:48 - 2013-01-22 18:09 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-11-08 20:48 - 2013-01-22 18:09 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-11-08 20:48 - 2013-01-22 11:42 - 00000000 ____D () C:\Users\Ewa\AppData\Local\Adobe 2014-11-08 15:45 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-11-04 14:30 - 2013-01-22 10:59 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-10-26 18:32 - 2014-01-03 20:04 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-10-24 12:41 - 2009-07-14 05:17 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-10-22 15:02 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF 2014-10-21 16:28 - 2014-07-28 09:38 - 00000000 ____D () C:\Program Files\Google Some content of TEMP: ==================== C:\Users\Ewa\AppData\Local\Temp\Quarantine.exe C:\Users\Ewa\AppData\Local\Temp\SkypeSetup.exe C:\Users\Ewa\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-09 14:46 ==================== End Of Log ============================