Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013 Ran by Ania (administrator) on ANIAI on 04-10-2013 18:31:04 Running from G:\Anty Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Safe Mode (with Networking) ==================== Processes (Whitelisted) =================== (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [16380416 2007-07-05] (Realtek Semiconductor Corp.) HKLM\...\Run: [SkyTel] - C:\Windows\SkyTel.EXE [1826816 2007-06-15] (Realtek Semiconductor Corp.) HKLM\...\Run: [Alcmtr] - C:\Windows\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [OrderReminder] - C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [98304 2006-07-21] (Hewlett-Packard) HKLM\...\Run: [SSBkgdUpdate] - C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [210472 2006-10-25] (Nuance Communications, Inc.) HKLM\...\Run: [PaperPort PTD] - C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe [29984 2008-07-09] (Nuance Communications, Inc.) HKLM\...\Run: [IndexSearch] - C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe [46368 2008-07-09] (Nuance Communications, Inc.) HKLM\...\Run: [PPort11reminder] - C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe [328992 2007-08-31] (Nuance Communications, Inc.) HKLM\...\Run: [BrMfcWnd] - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [1089536 2008-02-19] (Brother Industries, Ltd.) HKLM\...\Run: [ControlCenter3] - C:\Program Files\Brother\ControlCenter3\brctrcen.exe [86016 2007-12-21] (Brother Industries, Ltd.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APVXDWIN] - C:\Program Files\Panda Security\Panda Antivirus Pro 2013\APVXDWIN.EXE [1038192 2012-12-12] (Panda Security, S.L.) HKLM\...\Run: [SCANINICIO] - C:\Program Files\Panda Security\Panda Antivirus Pro 2013\Inicio.exe [70432 2012-11-08] (Panda Security, S.L.) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-04-23] (Samsung Electronics Co., Ltd.) HKLM\...\Runonce: [Malwarebytes Anti-Malware (cleanup)] - rundll32.exe "C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript HKLM\...\Runonce: [{D8351590-16AB-49D4-85F3-C0235DB8FA02}] - cmd.exe /C start /D "C:\DOCUME~1\Ania\USTAWI~1\Temp" /B {D8351590-16AB-49D4-85F3-C0235DB8FA02}.exe -accepteula -accepteulaksn -activeimages -postboot Winlogon\Notify\avldr: C:\Windows\SYSTEM32\avldr.dll (On-Access Anti-Malware Scanner Sync) HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1561968 2013-04-23] (Samsung) HKCU\...\Policies\Explorer: [HideSCAHealth] 1 MountPoints2: {24879b70-8b41-11df-890f-001d7d501110} - G:\autorun.exe MountPoints2: {8dca85f8-80ad-11e2-8bfa-001d7d501110} - G:\autorun.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm SearchScopes: HKCU - {5C6B196C-E678-40D0-8B54-113D931613F9} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll (Yahoo! Inc.) Toolbar: HKLM - &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll (Yahoo! Inc.) Toolbar: HKLM - No Name - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No File Toolbar: HKCU -&Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU -&Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation) Toolbar: HKCU -&Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll (Yahoo! Inc.) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 95.160.170.92 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Ania\Dane aplikacji\Mozilla\Firefox\Profiles\gps9kr1e.default FF NewTab: hxxp://www2.delta-search.com/?babsrc=NT_ss&mntrId=B0B9001D7D501110&affID=122476&tsp=4995 FF Homepage: hxxp://www.google.pl/ FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: QuickStores-Toolbar - C:\Program Files\Mozilla Firefox\extensions\quickstores@quickstores.de FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ========================== Services (Whitelisted) ================= S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 Panda Software Controller; C:\Program Files\Panda Security\Panda Antivirus Pro 2013\PsCtrls.exe [177440 2012-11-19] (Panda Security, S.L.) S2 PAVFNSVR; C:\Program Files\Panda Security\Panda Antivirus Pro 2013\PavFnSvr.exe [202016 2012-09-21] (Panda Security, S.L.) S2 PavPrSrv; C:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exe [62768 2008-02-04] (Panda Security, S.L.) S2 PAVSRV; C:\Program Files\Panda Security\Panda Antivirus Pro 2013\pavsrvx86.exe [313664 2011-04-13] (Panda Security, S.L.) S2 PSHost; C:\Program Files\Panda Security\Panda Antivirus Pro 2013\Firewall\PSHOST.EXE [226560 2009-11-26] (Panda Security International) S2 PSIMSVC; C:\Program Files\Panda Security\Panda Antivirus Pro 2013\PsImSvc.exe [108288 2008-06-19] (Panda Security S.L.) S2 PskSvcRetail; C:\Program Files\Panda Security\Panda Antivirus Pro 2013\PskSvc.exe [28992 2010-08-16] (Panda Security, S.L.) S2 TPSrv; C:\Program Files\Panda Security\Panda Antivirus Pro 2013\TPSrv.exe [156960 2012-11-16] (Panda Security, S.L.) ==================== Drivers (Whitelisted) ==================== S1 AmdK8; C:\Windows\System32\DRIVERS\AmdK8.sys [43520 2006-06-18] (Advanced Micro Devices) S2 AmFSM; C:\Windows\System32\DRIVERS\amm8651.sys [63240 2012-03-26] (Panda Security, S.L.) S1 APPFLT; C:\WINDOWS\system32\Drivers\APPFLT.SYS [83528 2011-01-31] (Panda Security, S.L.) S3 BrScnUsb; C:\Windows\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.) S1 DSAFLT; C:\WINDOWS\system32\Drivers\DSAFLT.SYS [53256 2009-09-25] (Panda Security, S.L.) S1 FNETMON; C:\WINDOWS\system32\Drivers\fnetmon.SYS [22024 2009-09-25] (Panda Security, S.L.) S3 gdrv; C:\WINDOWS\gdrv.sys [15600 2008-04-21] (Windows (R) 2000 DDK provider) S3 GT680x; C:\Windows\System32\Drivers\gt680x.sys [18120 2001-11-08] ( ) S1 IDSFLT; C:\WINDOWS\system32\Drivers\IDSFLT.SYS [193864 2010-09-09] (Panda Security, S.L.) S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\mbamswissarmy.sys [40776 2013-10-04] (Malwarebytes Corporation) R1 NETFLTDI; C:\WINDOWS\system32\Drivers\NETFLTDI.SYS [159112 2009-09-25] (Panda Security, S.L.) R3 NETIMFLT01060044; C:\Windows\System32\DRIVERS\neti1644.sys [201032 2010-09-01] (Panda Security, S.L.) S3 NPF; C:\Windows\System32\drivers\NPF.sys [50704 2012-03-12] (CACE Technologies, Inc.) R0 nvata; C:\Windows\System32\DRIVERS\nvata.sys [105472 2006-10-18] (NVIDIA Corporation) R3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [58368 2006-11-27] (NVIDIA Corporation) R3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [19968 2006-11-27] (NVIDIA Corporation) S0 pavboot; C:\Windows\System32\Drivers\pavboot.sys [26696 2010-06-22] (Panda Security, S.L.) S2 PavProc; C:\WINDOWS\system32\DRIVERS\PavProc.sys [164488 2012-05-08] (Panda Security, S.L.) S1 ShldDrv; C:\Windows\System32\DRIVERS\ShlDrv51.sys [37448 2011-02-21] (Panda Security, S.L.) S1 WNMFLT; C:\WINDOWS\system32\Drivers\WNMFLT.SYS [46856 2009-09-25] (Panda Security, S.L.) S3 AvFlt; \SystemRoot\system32\drivers\av5flt.sys [x] S4 IntelIde; No ImagePath U1 luafv; S3 PavSRK.sys; \??\C:\WINDOWS\system32\PavSRK.sys [x] S3 PavTPK.sys; \??\C:\WINDOWS\system32\PavTPK.sys [x] U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-04 18:30 - 2013-10-04 18:30 - 00000000 ____D C:\FRST 2013-10-04 17:49 - 2013-10-04 18:23 - 00040776 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2013-10-04 16:20 - 2013-10-04 16:20 - 00000000 __SHD C:\WINDOWS\CSC 2013-10-04 15:14 - 2013-10-04 15:14 - 00000339 _____ C:\WINDOWS\wininit.ini 2013-10-04 13:04 - 2013-10-04 13:04 - 00000784 _____ C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk 2013-10-04 13:04 - 2013-10-04 13:04 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-04 13:04 - 2013-10-04 13:04 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes' Anti-Malware 2013-10-04 13:04 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2013-10-04 12:55 - 2013-10-04 12:57 - 00000000 ____D C:\Documents and Settings\Ania\Ustawienia lokalne\Dane aplikacji\Lollipop 2013-10-04 12:51 - 2013-10-04 12:54 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-10-02 09:53 - 2013-10-02 09:53 - 00000000 ____D C:\Documents and Settings\Ania\Ustawienia lokalne\Dane aplikacji\Thunderbird 2013-10-02 09:53 - 2013-10-02 09:53 - 00000000 ____D C:\Documents and Settings\Ania\Dane aplikacji\Thunderbird 2013-10-02 09:15 - 2013-10-02 09:15 - 00000920 _____ C:\Documents and Settings\All Users\Pulpit\Panda Cloud Cleaner.lnk 2013-10-01 09:11 - 2013-10-02 08:21 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-01 08:08 - 2013-10-04 15:29 - 00000252 _____ C:\WINDOWS\system32\Drivers\etc\IdsFlt.cfg.bck 2013-10-01 08:08 - 2013-10-04 15:29 - 00000252 _____ C:\WINDOWS\system32\Drivers\etc\IdsFlt.cfg 2013-10-01 08:08 - 2013-10-04 15:29 - 00000080 _____ C:\WINDOWS\system32\Drivers\etc\NetLoc.wlt.bck 2013-10-01 08:08 - 2013-10-04 15:29 - 00000080 _____ C:\WINDOWS\system32\Drivers\etc\NetLoc.wlt 2013-10-01 08:08 - 2013-10-04 15:29 - 00000056 _____ C:\WINDOWS\system32\Drivers\etc\WnmFlt.cfg.bck 2013-10-01 08:08 - 2013-10-04 15:29 - 00000056 _____ C:\WINDOWS\system32\Drivers\etc\WnmFlt.cfg 2013-10-01 08:08 - 2013-10-04 15:29 - 00000056 _____ C:\WINDOWS\system32\Drivers\etc\DsaFlt.cfg.bck 2013-10-01 08:08 - 2013-10-04 15:29 - 00000056 _____ C:\WINDOWS\system32\Drivers\etc\DsaFlt.cfg 2013-10-01 08:01 - 2013-10-04 15:29 - 00000068 _____ C:\WINDOWS\system32\Drivers\etc\NetFlt.cfg.bck 2013-10-01 08:01 - 2013-10-04 15:29 - 00000068 _____ C:\WINDOWS\system32\Drivers\etc\NetFlt.cfg 2013-10-01 08:01 - 2013-10-04 15:23 - 00000064 _____ C:\WINDOWS\system32\Drivers\etc\NetAR.wlt.bck 2013-10-01 08:01 - 2013-10-04 15:23 - 00000064 _____ C:\WINDOWS\system32\Drivers\etc\NetAR.wlt 2013-10-01 08:00 - 2013-10-04 18:13 - 00000088 _____ C:\WINDOWS\system32\Drivers\etc\NetAdapt.cfg 2013-10-01 08:00 - 2013-10-04 15:23 - 00000088 _____ C:\WINDOWS\system32\Drivers\etc\NetAdapt.cfg.bck 2013-10-01 07:59 - 2013-10-04 15:29 - 00001132 _____ C:\WINDOWS\system32\Drivers\APPFLTR.CFG.bck 2013-10-01 07:59 - 2013-10-04 15:29 - 00001132 _____ C:\WINDOWS\system32\Drivers\APPFLTR.CFG 2013-10-01 07:59 - 2013-10-04 12:48 - 00303044 _____ C:\WINDOWS\system32\Drivers\etc\DsaFlt.rls.bck 2013-10-01 07:59 - 2013-10-04 12:48 - 00303044 _____ C:\WINDOWS\system32\Drivers\etc\DsaFlt.rls 2013-10-01 07:59 - 2013-10-03 13:52 - 00219116 _____ C:\WINDOWS\system32\Drivers\APPFCONT.DAT.bck 2013-10-01 07:59 - 2013-10-03 13:52 - 00219116 _____ C:\WINDOWS\system32\Drivers\APPFCONT.DAT 2013-10-01 07:58 - 2011-01-31 16:41 - 00083528 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\APPFLT.SYS 2013-10-01 07:58 - 2010-09-09 16:23 - 00193864 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\idsflt.sys 2013-10-01 07:58 - 2009-09-25 14:54 - 00159112 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\NETFLTDI.SYS 2013-10-01 07:58 - 2009-09-25 14:54 - 00053256 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\dsaflt.sys 2013-10-01 07:58 - 2009-09-25 14:54 - 00046856 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\wnmflt.sys 2013-10-01 07:58 - 2009-09-25 14:54 - 00022024 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\fnetmon.sys 2013-09-23 09:14 - 2013-09-23 09:14 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2864063$ 2013-09-23 09:08 - 2013-09-23 09:08 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876217$ 2013-09-23 09:07 - 2013-09-23 09:07 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876315$ 2013-09-13 15:16 - 2013-09-13 15:16 - 00942916 _____ C:\Documents and Settings\Ania\Pulpit\tar.zip 2013-09-04 13:40 - 2013-09-04 13:40 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\APN ==================== One Month Modified Files and Folders ======= 2013-10-04 18:30 - 2013-10-04 18:30 - 00000000 ____D C:\FRST 2013-10-04 18:23 - 2013-10-04 17:49 - 00040776 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2013-10-04 18:14 - 2007-10-29 14:00 - 00013766 _____ C:\WINDOWS\system32\wpa.dbl 2013-10-04 18:13 - 2013-10-01 08:00 - 00000088 _____ C:\WINDOWS\system32\Drivers\etc\NetAdapt.cfg 2013-10-04 18:12 - 2012-03-19 12:34 - 01713158 _____ C:\WINDOWS\WindowsUpdate.log 2013-10-04 18:12 - 2008-05-03 13:45 - 00000188 ___SH C:\Documents and Settings\Ania\ntuser.ini 2013-10-04 17:38 - 2013-07-22 09:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2802968$ 2013-10-04 16:20 - 2013-10-04 16:20 - 00000000 __SHD C:\WINDOWS\CSC 2013-10-04 15:48 - 2008-04-21 19:44 - 00000516 _____ C:\WINDOWS\wiadebug.log 2013-10-04 15:48 - 2008-04-21 19:44 - 00000050 _____ C:\WINDOWS\wiaservc.log 2013-10-04 15:48 - 2008-04-21 17:54 - 00032580 _____ C:\WINDOWS\SchedLgU.Txt 2013-10-04 15:48 - 2008-04-21 17:54 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-10-04 15:36 - 2012-04-10 14:27 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-10-04 15:29 - 2013-10-01 08:08 - 00000252 _____ C:\WINDOWS\system32\Drivers\etc\IdsFlt.cfg.bck 2013-10-04 15:29 - 2013-10-01 08:08 - 00000252 _____ C:\WINDOWS\system32\Drivers\etc\IdsFlt.cfg 2013-10-04 15:29 - 2013-10-01 08:08 - 00000080 _____ C:\WINDOWS\system32\Drivers\etc\NetLoc.wlt.bck 2013-10-04 15:29 - 2013-10-01 08:08 - 00000080 _____ C:\WINDOWS\system32\Drivers\etc\NetLoc.wlt 2013-10-04 15:29 - 2013-10-01 08:08 - 00000056 _____ C:\WINDOWS\system32\Drivers\etc\WnmFlt.cfg.bck 2013-10-04 15:29 - 2013-10-01 08:08 - 00000056 _____ C:\WINDOWS\system32\Drivers\etc\WnmFlt.cfg 2013-10-04 15:29 - 2013-10-01 08:08 - 00000056 _____ C:\WINDOWS\system32\Drivers\etc\DsaFlt.cfg.bck 2013-10-04 15:29 - 2013-10-01 08:08 - 00000056 _____ C:\WINDOWS\system32\Drivers\etc\DsaFlt.cfg 2013-10-04 15:29 - 2013-10-01 08:01 - 00000068 _____ C:\WINDOWS\system32\Drivers\etc\NetFlt.cfg.bck 2013-10-04 15:29 - 2013-10-01 08:01 - 00000068 _____ C:\WINDOWS\system32\Drivers\etc\NetFlt.cfg 2013-10-04 15:29 - 2013-10-01 07:59 - 00001132 _____ C:\WINDOWS\system32\Drivers\APPFLTR.CFG.bck 2013-10-04 15:29 - 2013-10-01 07:59 - 00001132 _____ C:\WINDOWS\system32\Drivers\APPFLTR.CFG 2013-10-04 15:23 - 2013-10-01 08:01 - 00000064 _____ C:\WINDOWS\system32\Drivers\etc\NetAR.wlt.bck 2013-10-04 15:23 - 2013-10-01 08:01 - 00000064 _____ C:\WINDOWS\system32\Drivers\etc\NetAR.wlt 2013-10-04 15:23 - 2013-10-01 08:00 - 00000088 _____ C:\WINDOWS\system32\Drivers\etc\NetAdapt.cfg.bck 2013-10-04 15:22 - 2008-04-21 19:32 - 00000000 ____D C:\WINDOWS\addins 2013-10-04 15:14 - 2013-10-04 15:14 - 00000339 _____ C:\WINDOWS\wininit.ini 2013-10-04 15:14 - 2008-05-03 13:45 - 00000000 __RHD C:\Documents and Settings\Ania\Dane aplikacji 2013-10-04 14:17 - 2012-03-16 09:35 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2013-10-04 14:11 - 2008-04-21 19:39 - 00000000 __RHD C:\Documents and Settings\All Users\Dane aplikacji 2013-10-04 13:04 - 2013-10-04 13:04 - 00000784 _____ C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk 2013-10-04 13:04 - 2013-10-04 13:04 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-04 13:04 - 2013-10-04 13:04 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes' Anti-Malware 2013-10-04 13:04 - 2008-04-21 19:41 - 00000000 ___RD C:\Documents and Settings\All Users\Menu Start\Programy 2013-10-04 13:04 - 2008-04-21 19:41 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit 2013-10-04 13:01 - 2012-03-16 09:35 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy 2013-10-04 12:57 - 2013-10-04 12:55 - 00000000 ____D C:\Documents and Settings\Ania\Ustawienia lokalne\Dane aplikacji\Lollipop 2013-10-04 12:57 - 2008-05-03 13:45 - 00000000 ___RD C:\Documents and Settings\Ania\Menu Start\Programy 2013-10-04 12:55 - 2008-05-03 13:45 - 00000000 ___HD C:\Documents and Settings\Ania\Ustawienia lokalne\Dane aplikacji 2013-10-04 12:54 - 2013-10-04 12:51 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-10-04 12:54 - 2008-05-03 13:45 - 00000000 ____D C:\Documents and Settings\Ania\Pulpit 2013-10-04 12:52 - 2008-05-03 13:45 - 00000000 ____D C:\Documents and Settings\Ania 2013-10-04 12:48 - 2013-10-01 07:59 - 00303044 _____ C:\WINDOWS\system32\Drivers\etc\DsaFlt.rls.bck 2013-10-04 12:48 - 2013-10-01 07:59 - 00303044 _____ C:\WINDOWS\system32\Drivers\etc\DsaFlt.rls 2013-10-03 13:52 - 2013-10-01 07:59 - 00219116 _____ C:\WINDOWS\system32\Drivers\APPFCONT.DAT.bck 2013-10-03 13:52 - 2013-10-01 07:59 - 00219116 _____ C:\WINDOWS\system32\Drivers\APPFCONT.DAT 2013-10-03 11:48 - 2012-03-16 13:53 - 00008627 _____ C:\WINDOWS\system32\PAV_FOG.OPC 2013-10-03 07:56 - 2012-05-07 08:09 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-10-02 09:53 - 2013-10-02 09:53 - 00000000 ____D C:\Documents and Settings\Ania\Ustawienia lokalne\Dane aplikacji\Thunderbird 2013-10-02 09:53 - 2013-10-02 09:53 - 00000000 ____D C:\Documents and Settings\Ania\Dane aplikacji\Thunderbird 2013-10-02 09:15 - 2013-10-02 09:15 - 00000920 _____ C:\Documents and Settings\All Users\Pulpit\Panda Cloud Cleaner.lnk 2013-10-02 09:15 - 2013-03-13 15:14 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Panda Security 2013-10-02 09:15 - 2008-05-21 07:29 - 00000000 ____D C:\Program Files\Panda Security 2013-10-02 08:21 - 2013-10-01 09:11 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-01 08:17 - 2012-03-19 12:12 - 00000000 ____D C:\Documents and Settings\Ania\Dane aplikacji\TeamViewer 2013-10-01 08:17 - 2012-03-19 12:11 - 04432704 _____ (TeamViewer) C:\Documents and Settings\Ania\Pulpit\TeamViewerQS_pl.exe 2013-09-26 11:13 - 2008-05-03 13:55 - 00000000 ____D C:\Documents and Settings\Ania\Dane aplikacji\OpenOffice.org2 2013-09-23 09:32 - 2008-04-21 19:39 - 00281336 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2013-09-23 09:31 - 2008-05-03 13:48 - 00000000 __SHD C:\Documents and Settings\Ania\UserData 2013-09-23 09:16 - 2009-10-08 12:37 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2013-09-23 09:14 - 2013-09-23 09:14 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2864063$ 2013-09-23 09:14 - 2013-07-29 08:33 - 00000000 ____D C:\WINDOWS\system32\MRT 2013-09-23 09:09 - 2008-05-24 08:27 - 76725432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2013-09-23 09:08 - 2013-09-23 09:08 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876217$ 2013-09-23 09:08 - 2011-03-31 14:46 - 00000000 ____D C:\WINDOWS\ie8updates 2013-09-23 09:07 - 2013-09-23 09:07 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876315$ 2013-09-20 11:36 - 2012-04-10 14:27 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2013-09-20 11:36 - 2011-07-21 08:43 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2013-09-13 15:16 - 2013-09-13 15:16 - 00942916 _____ C:\Documents and Settings\Ania\Pulpit\tar.zip 2013-09-13 09:18 - 2009-10-08 12:42 - 00002507 _____ C:\Documents and Settings\Ania\Pulpit\Microsoft Office Excel 2007.lnk 2013-09-12 15:58 - 2013-01-23 12:39 - 00002347 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk 2013-09-05 10:18 - 2013-02-18 08:57 - 00000000 ____D C:\Program Files\Google 2013-09-05 10:17 - 2013-02-18 08:57 - 00000000 ____D C:\Documents and Settings\Ania\Ustawienia lokalne\Dane aplikacji\Google 2013-09-04 13:43 - 2012-03-22 12:18 - 00000000 ____D C:\Documents and Settings\Ania\Moje dokumenty\Pobieranie 2013-09-04 13:40 - 2013-09-04 13:40 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\APN Some content of TEMP: ==================== C:\Documents and Settings\Ania\Ustawienia lokalne\Temp\nircmd.exe C:\Documents and Settings\Ania\Ustawienia lokalne\Temp\pv.exe C:\Documents and Settings\Ania\Ustawienia lokalne\Temp\vfind.exe C:\Documents and Settings\Ania\Ustawienia lokalne\Temp\{D8351590-16AB-49D4-85F3-C0235DB8FA02}.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe [2007-10-29 14:00] - [2008-04-14 23:51] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\Windows\System32\winlogon.exe [2007-10-29 14:00] - [2008-04-14 23:51] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\Windows\System32\svchost.exe [2007-10-29 14:00] - [2008-04-14 23:51] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\Windows\System32\services.exe [2007-10-29 14:00] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f C:\Windows\System32\User32.dll [2007-10-29 14:00] - [2008-04-14 23:50] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\Windows\System32\userinit.exe [2007-10-29 14:00] - [2008-04-14 23:51] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\Windows\System32\Drivers\volsnap.sys [2007-10-29 14:00] - [2008-04-14 22:31] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================