Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 07-09-2013 01 Ran by Właściciel (administrator) on RR on 07-09-2013 13:57:55 Running from D:\Documents and Settings\Właściciel\Moje dokumenty Microsoft Windows XP Home Edition Dodatek Service Pack 2 (X86) OS Language: Polish Internet Explorer Version 6 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) D:\WINDOWS\system32\wscntfy.exe (Mozilla Corporation) E:\Program Files\FF\firefox.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [uTorrent] - E:\Program Files\utorrent\uTorrent.exe [802136 2013-07-06] (BitTorrent Inc.) IMEO\Your Image File Name Here without a path: [Debugger] ntsd -d ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) Toolbar: HKCU -&Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - D:\Windows\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU -&Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - D:\Windows\system32\SHELL32.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 217.172.224.170 89.231.1.206 Tcpip\..\Interfaces\{FE7A80FF-7C2E-475A-80E4-B163E7DFFB38}: [NameServer]8.8.8.8,8.8.4.4 FireFox: ======== FF ProfilePath: D:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\po5p0jub.default FF Plugin: @adobe.com/FlashPlayer - D:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin: Adobe Reader - E:\Program Files\Adobe\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF StartMenuInternet: FIREFOX.EXE - E:\Program Files\FF\firefox.exe ========================== Services (Whitelisted) ================= ==================== Drivers (Whitelisted) ==================== R1 AmdK8; D:\Windows\System32\DRIVERS\AmdK8.sys [43520 2006-06-18] (Advanced Micro Devices) R1 dtsoftbus01; D:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-06-30] (DT Soft Ltd) R3 NVENETFD; D:\Windows\System32\DRIVERS\NVENETFD.sys [57856 2006-09-11] (NVIDIA Corporation) R3 nvnetbus; D:\Windows\System32\DRIVERS\nvnetbus.sys [19968 2006-09-11] (NVIDIA Corporation) S3 Secdrv; D:\Windows\System32\DRIVERS\secdrv.sys [27440 2006-03-02] () S4 IntelIde; No ImagePath U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-07 13:57 - 2013-09-07 13:57 - 00000000 ____D D:\FRST 2013-09-07 13:56 - 2013-09-07 13:56 - 01081963 _____ (Farbar) D:\Documents and Settings\Właściciel\Moje dokumenty\FRST.exe 2013-09-07 02:02 - 2013-09-07 13:07 - 00000000 ____D D:\Program Files\Google 2013-09-07 02:02 - 2013-09-07 02:06 - 04188160 _____ D:\Program Files\GUT11.tmp 2013-09-07 02:02 - 2013-09-07 02:02 - 00000000 ____D D:\Program Files\GUM10.tmp 2013-09-07 02:01 - 2013-09-07 13:39 - 00002358 _____ D:\WINDOWS\setupapi.log 2013-09-07 02:01 - 2013-09-07 02:02 - 00784840 _____ (Google Inc.) D:\Documents and Settings\Właściciel\Moje dokumenty\ChromeSetup.exe 2013-09-01 14:55 - 2013-09-01 14:55 - 00000864 _____ D:\Documents and Settings\Właściciel\Pulpit\histline.lnk 2013-09-01 14:54 - 2013-09-01 14:54 - 00000526 _____ D:\Documents and Settings\Właściciel\Pulpit\KoH.exe.lnk 2013-08-31 15:11 - 2013-08-31 15:11 - 00000000 ____D D:\Documents and Settings\Właściciel\Dane aplikacji\Black Sea Studios 2013-08-31 14:28 - 2013-08-31 14:28 - 00000000 ___HD D:\WINDOWS\PIF 2013-08-31 11:43 - 2013-08-31 11:44 - 00000000 ____D D:\AdwCleaner 2013-08-27 09:48 - 2013-08-27 09:48 - 16883056 _____ (Microsoft Corporation) D:\Documents and Settings\Właściciel\Moje dokumenty\internet-explorer-8 [1].exe 2013-08-18 22:29 - 2013-08-18 22:29 - 00000000 ____D D:\Documents and Settings\Właściciel\Dane aplikacji\Help 2013-08-18 11:12 - 2013-08-18 11:12 - 00000000 ____D D:\Program Files\Mozilla Maintenance Service 2013-08-17 19:03 - 2013-09-07 01:59 - 00000000 ____D D:\WINDOWS\Minidump 2013-08-17 18:49 - 2013-08-17 18:53 - 00000000 ____D D:\Documents and Settings\Właściciel\Dane aplikacji\Moje pliki zapisu Bitwy o Śródziemie 2013-08-11 13:24 - 2013-08-11 13:36 - 00000000 ____D D:\Documents and Settings\Właściciel\Dane aplikacji\NapiProjekt 2013-08-11 13:21 - 2013-08-11 13:21 - 10382789 _____ ( ) D:\Documents and Settings\Właściciel\Moje dokumenty\NapiProjekt_newest.exe 2013-08-11 01:55 - 2013-08-11 01:56 - 00000000 ____D D:\Documents and Settings\Właściciel\Dane aplikacji\GHISLER ==================== One Month Modified Files and Folders ======= 2013-09-07 13:57 - 2013-09-07 13:57 - 00000000 ____D D:\FRST 2013-09-07 13:56 - 2013-09-07 13:56 - 01081963 _____ (Farbar) D:\Documents and Settings\Właściciel\Moje dokumenty\FRST.exe 2013-09-07 13:56 - 2013-06-30 17:17 - 00000000 ___RD D:\Documents and Settings\Właściciel\Moje dokumenty 2013-09-07 13:39 - 2013-09-07 02:01 - 00002358 _____ D:\WINDOWS\setupapi.log 2013-09-07 13:19 - 2013-06-30 20:47 - 00007356 _____ D:\WINDOWS\system32\nvAppTimestamps 2013-09-07 13:07 - 2013-09-07 02:02 - 00000000 ____D D:\Program Files\Google 2013-09-07 13:07 - 2013-06-30 17:12 - 00414148 _____ D:\WINDOWS\WindowsUpdate.log 2013-09-07 13:05 - 2013-06-30 19:04 - 01115816 _____ D:\WINDOWS\system32\PerfStringBackup.INI 2013-09-07 13:05 - 2006-03-02 14:00 - 00501498 _____ D:\WINDOWS\system32\perfh015.dat 2013-09-07 13:05 - 2006-03-02 14:00 - 00088124 _____ D:\WINDOWS\system32\perfc015.dat 2013-09-07 13:04 - 2013-07-06 13:22 - 00000000 ____D D:\Documents and Settings\Właściciel\Dane aplikacji\uTorrent 2013-09-07 13:01 - 2013-06-30 19:06 - 00000157 _____ D:\WINDOWS\wiadebug.log 2013-09-07 13:01 - 2013-06-30 19:06 - 00000050 _____ D:\WINDOWS\wiaservc.log 2013-09-07 13:01 - 2013-06-30 17:17 - 00000006 ____H D:\WINDOWS\Tasks\SA.DAT 2013-09-07 02:06 - 2013-09-07 02:02 - 04188160 _____ D:\Program Files\GUT11.tmp 2013-09-07 02:06 - 2013-06-30 17:17 - 00018766 _____ D:\WINDOWS\SchedLgU.Txt 2013-09-07 02:06 - 2013-06-30 17:17 - 00000188 ___SH D:\Documents and Settings\Właściciel\ntuser.ini 2013-09-07 02:02 - 2013-09-07 02:02 - 00000000 ____D D:\Program Files\GUM10.tmp 2013-09-07 02:02 - 2013-09-07 02:01 - 00784840 _____ (Google Inc.) D:\Documents and Settings\Właściciel\Moje dokumenty\ChromeSetup.exe 2013-09-07 02:02 - 2013-06-30 17:17 - 00000000 ___HD D:\DOCUME~1\WACICI~1\USTAWI~1\Dane aplikacji 2013-09-07 01:59 - 2013-08-17 19:03 - 00000000 ____D D:\WINDOWS\Minidump 2013-09-07 01:59 - 2013-06-30 20:54 - 00000000 ____D D:\Documents and Settings\Właściciel\Dane aplikacji\DAEMON Tools Lite 2013-09-07 01:59 - 2013-06-30 17:17 - 00000000 ____D D:\Documents and Settings\Właściciel 2013-09-07 01:57 - 2013-06-30 17:17 - 00000000 __RHD D:\Documents and Settings\Właściciel\Dane aplikacji 2013-09-07 01:52 - 2013-06-30 17:57 - 00000000 ____D D:\Documents and Settings\Właściciel\Moje dokumenty\Pobieranie 2013-09-06 18:34 - 2013-07-06 16:25 - 00000000 ____D D:\Documents and Settings\Właściciel\Pulpit\Filmy 2013-09-05 19:32 - 2006-03-02 14:00 - 00013646 _____ D:\WINDOWS\system32\wpa.dbl 2013-09-01 14:55 - 2013-09-01 14:55 - 00000864 _____ D:\Documents and Settings\Właściciel\Pulpit\histline.lnk 2013-09-01 14:55 - 2013-06-30 17:17 - 00000000 ____D D:\Documents and Settings\Właściciel\Pulpit 2013-09-01 14:54 - 2013-09-01 14:54 - 00000526 _____ D:\Documents and Settings\Właściciel\Pulpit\KoH.exe.lnk 2013-08-31 23:15 - 2013-07-24 22:35 - 00000000 ____D D:\Documents and Settings\Właściciel\Pulpit\1 2013-08-31 15:11 - 2013-08-31 15:11 - 00000000 ____D D:\Documents and Settings\Właściciel\Dane aplikacji\Black Sea Studios 2013-08-31 14:29 - 2013-06-30 17:31 - 00000000 ____D D:\Program Files\Common Files\InstallShield 2013-08-31 14:28 - 2013-08-31 14:28 - 00000000 ___HD D:\WINDOWS\PIF 2013-08-31 11:44 - 2013-08-31 11:43 - 00000000 ____D D:\AdwCleaner 2013-08-31 11:44 - 2013-06-30 17:17 - 00000000 ___RD D:\Documents and Settings\Właściciel\Menu Start\Programy 2013-08-27 09:48 - 2013-08-27 09:48 - 16883056 _____ (Microsoft Corporation) D:\Documents and Settings\Właściciel\Moje dokumenty\internet-explorer-8 [1].exe 2013-08-18 22:29 - 2013-08-18 22:29 - 00000000 ____D D:\Documents and Settings\Właściciel\Dane aplikacji\Help 2013-08-18 22:29 - 2013-06-30 18:56 - 00000000 ____D D:\WINDOWS\Help 2013-08-18 11:12 - 2013-08-18 11:12 - 00000000 ____D D:\Program Files\Mozilla Maintenance Service 2013-08-18 11:12 - 2013-06-30 19:03 - 00000000 __RHD D:\Documents and Settings\All Users\Dane aplikacji 2013-08-17 18:53 - 2013-08-17 18:49 - 00000000 ____D D:\Documents and Settings\Właściciel\Dane aplikacji\Moje pliki zapisu Bitwy o Śródziemie 2013-08-16 21:24 - 2013-06-30 19:03 - 00000000 ____D D:\Documents and Settings\All Users\Pulpit 2013-08-11 13:36 - 2013-08-11 13:24 - 00000000 ____D D:\Documents and Settings\Właściciel\Dane aplikacji\NapiProjekt 2013-08-11 13:21 - 2013-08-11 13:21 - 10382789 _____ ( ) D:\Documents and Settings\Właściciel\Moje dokumenty\NapiProjekt_newest.exe 2013-08-11 01:56 - 2013-08-11 01:55 - 00000000 ____D D:\Documents and Settings\Właściciel\Dane aplikacji\GHISLER 2013-08-08 17:55 - 2013-06-30 19:03 - 00095072 _____ D:\WINDOWS\system32\FNTCACHE.DAT ==================== Bamital & volsnap Check ================= D:\Windows\explorer.exe [2006-03-02 14:00] - [2006-03-02 14:00] - 1033728 ____A (Microsoft Corporation) 379098a96e6c165b659de7e4328010ea D:\Windows\System32\winlogon.exe [2006-03-02 14:00] - [2006-03-02 14:00] - 0504832 ____A (Microsoft Corporation) 0344407089b08548d4feba62bb0f32d0 D:\Windows\System32\svchost.exe [2006-03-02 14:00] - [2006-03-02 14:00] - 0014336 ____A (Microsoft Corporation) ba98327e90022dbd6ee76490e0622e2e D:\Windows\System32\services.exe [2006-03-02 14:00] - [2006-03-02 14:00] - 0108544 ____A (Microsoft Corporation) 3da8d964d2cc12ef8e8c342471a37917 D:\Windows\System32\User32.dll [2006-03-02 14:00] - [2006-03-02 14:00] - 0578560 ____A (Microsoft Corporation) 0c81764f50f32d376e6e4b9e9f4b01a0 D:\Windows\System32\userinit.exe [2006-03-02 14:00] - [2006-03-02 14:00] - 0025088 ____A (Microsoft Corporation) bd768099b4c44aa631728cb74eb54396 D:\Windows\System32\Drivers\volsnap.sys [2006-03-02 14:00] - [2006-03-02 14:00] - 0052864 ___AC (Microsoft Corporation) ecd173739b8ec10a814cc18653df5a36 ==================== End Of Log ============================