Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:01-06-2014 01 Ran by Administrator (administrator) on A45F7D7627C54C0 on 02-06-2014 00:36:31 Running from D:\ Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Safe Mode (with Networking) The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [fst_pl_46] => [X] HKLM\...\Run: [upfst_pl_46.exe] => C:\Documents and Settings\Kasia\Ustawienia lokalne\Dane aplikacji\fst_pl_46\upfst_pl_46.exe -runhelper HKLM\...\Run: [mobilegeni daemon] => C:\Program Files\Mobogenie\DaemonProcess.exe HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254896 2012-09-17] (Sun Microsystems, Inc.) HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k HKLM\...\Run: [DApp] => C:\Program Files\PCDApp\start.vbs HKLM\...\RunOnce: [BrandClearStubs] - RUNDLL32 IEDKCS32.DLL,BrandCleanInstallStubs >{79ac307a-d6a7-4542-9975-92f05e88eb45} [391536 2009-03-08] (Microsoft Corporation) HKLM\...\RunOnce: [NoIE4StubProcessing] - C:\WINDOWS\system32\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /v "NoIE4StubProcessing" /f [53248 2008-04-15] (Microsoft Corporation) Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA4FDD768A67DCF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mks.com.pl/ URLSearchHook: HKLM - Default Value = {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Rock Turner - {527b365c-1bd3-4a66-906f-8729805ce78c} - C:\Program Files\Rock Turner\RockTurnerbho.dll (Rock Turner) BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\21.3.0.12\IPS\IPSBHO.DLL (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files\Norton Identity Safe\Engine\2014.7.0.43\coIEPlg.dll (Symantec Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) Toolbar: HKLM - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2014.7.0.43\coIEPlg.dll (Symantec Corporation) DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_45-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_45-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_45-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 23.253.94.129 128.199.225.64 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\5u42ruja.default FF Plugin: @java.com/DTPlugin,version=1.6.0_45 - C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA} [2014-05-09] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [] FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2014-03-15] FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\Documents and Settings\All Users\Dane aplikacji\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_21.3.0.12\IPSFF FF HKLM\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] - C:\Documents and Settings\All Users\Dane aplikacji\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.7.0.43\coFFPlgn\ ========================== Services (Whitelisted) ================= Locked "3fc68e249a2755ff" service could not be unlocked. <===== ATTENTION S2 JavaQuickStarterService; C:\Program Files\Java\jre6\bin\jqs.exe [158128 2014-03-15] (Sun Microsystems, Inc.) S2 NAV; C:\Program Files\Norton AntiVirus\Engine\21.3.0.12\NAV.exe [262968 2014-05-11] (Symantec Corporation) S2 NCO; C:\Program Files\Norton Identity Safe\Engine\2014.7.0.43\NST.exe [130104 2014-03-11] (Symantec Corporation) S2 spupdsvc; C:\WINDOWS\system32\spupdsvc.exe [26144 2009-01-07] (Microsoft Corporation) S2 syshost32; C:\WINDOWS\Installer\{3469CA44-9B17-89EF-F40D-B9B5D3949C56}\syshost.exe [90112 2014-05-31] () S2 Update Rock Turner; C:\Program Files\Rock Turner\updateRockTurner.exe [317728 2014-06-01] () S2 UpdaterSvcRockTurner; C:\Program Files\Rock Turner\updater.exe [109568 2014-06-01] () S2 Wpm; C:\Documents and Settings\All Users\Dane aplikacji\WPM\wprotectmanager.exe [510608 2014-03-05] (Cherished Technololgy LIMITED) S2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [X] ==================== Drivers (Whitelisted) ==================== R0 ACPI; C:\WINDOWS\System32\DRIVERS\ACPI.sys [188544 2008-04-15] () R0 ACPIEC; C:\WINDOWS\System32\DRIVERS\ACPIEC.sys [12032 2008-04-15] () S3 aec; C:\WINDOWS\System32\drivers\aec.sys [142592 2008-04-13] () R1 AFD; C:\WINDOWS\System32\drivers\afd.sys [138496 2008-08-14] () S3 ApfiltrService; C:\WINDOWS\System32\DRIVERS\Apfiltr.sys [95970 2003-10-25] () R3 AR5211; C:\WINDOWS\System32\DRIVERS\ar5211.sys [488992 2006-03-23] () S3 AsyncMac; C:\WINDOWS\System32\DRIVERS\asyncmac.sys [14336 2008-04-15] () R0 atapi; C:\WINDOWS\System32\DRIVERS\atapi.sys [96512 2008-04-15] () S3 ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [1918464 2006-12-16] () S3 Atmarpc; C:\WINDOWS\System32\DRIVERS\atmarpc.sys [59904 2008-04-15] () S3 audstub; C:\WINDOWS\System32\DRIVERS\audstub.sys [3072 2001-08-17] () R1 Beep; C:\WINDOWS\system32\Drivers\Beep.sys [4224 2008-04-15] () S1 BHDrvx86; C:\Program Files\Norton AntiVirus\NortonData\21.3.0.12\Definitions\BASHDefs\20140214.001\BHDrvx86.sys [1098968 2013-12-23] (Symantec Corporation) S4 cbidf2k; C:\WINDOWS\system32\Drivers\cbidf2k.sys [13952 2008-04-15] () S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] () S1 ccSet_NAV; C:\WINDOWS\system32\drivers\NAV\1503000.00C\ccSetx86.sys [127064 2014-02-21] (Symantec Corporation) S1 ccSet_NST; C:\WINDOWS\system32\drivers\NST\7DE07000.02B\ccSetx86.sys [127064 2013-09-27] (Symantec Corporation) S1 Cdaudio; C:\WINDOWS\system32\Drivers\Cdaudio.sys [18688 2008-04-15] () R4 Cdfs; C:\WINDOWS\system32\Drivers\Cdfs.sys [63744 2008-04-15] () R1 Cdrom; C:\WINDOWS\System32\DRIVERS\cdrom.sys [62976 2008-04-15] () S3 CmBatt; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [13952 2008-04-14] () R0 Compbatt; C:\WINDOWS\System32\DRIVERS\compbatt.sys [10240 2008-04-14] () S2 DgiVecp; C:\WINDOWS\system32\Drivers\DgiVecp.sys [41984 2008-01-10] () R0 Disk; C:\WINDOWS\System32\DRIVERS\disk.sys [36352 2008-04-15] () S4 dmboot; C:\WINDOWS\System32\drivers\dmboot.sys [800000 2008-04-15] () R0 dmio; C:\WINDOWS\System32\drivers\dmio.sys [153856 2008-04-15] () R0 dmload; C:\WINDOWS\System32\drivers\dmload.sys [5888 2008-04-15] () S3 DMusic; C:\WINDOWS\System32\drivers\DMusic.sys [52864 2008-04-14] () S3 drmkaud; C:\WINDOWS\System32\drivers\drmkaud.sys [2944 2008-04-14] () S4 Fastfat; C:\WINDOWS\system32\Drivers\Fastfat.sys [143744 2008-04-15] () S1 Fdc; C:\WINDOWS\system32\Drivers\Fdc.sys [27392 2008-04-15] () S1 Fips; C:\WINDOWS\system32\Drivers\Fips.sys [44672 2008-04-15] () S1 Flpydisk; C:\WINDOWS\system32\Drivers\Flpydisk.sys [20480 2008-04-15] () R0 FltMgr; C:\WINDOWS\System32\DRIVERS\fltMgr.sys [129792 2008-04-15] () U1 Fs_Rec; C:\WINDOWS\system32\Drivers\Fs_Rec.sys [7936 2008-04-15] () R0 Ftdisk; C:\WINDOWS\System32\DRIVERS\ftdisk.sys [125568 2008-04-15] () R3 Gpc; C:\WINDOWS\System32\DRIVERS\msgpc.sys [35072 2008-04-15] () S3 hamachi; C:\WINDOWS\System32\DRIVERS\hamachi.sys [26176 2009-03-18] () S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2005-01-07] () R3 HDAudBus; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [138752 2005-01-07] () R3 HidUsb; C:\WINDOWS\System32\DRIVERS\hidusb.sys [10368 2008-04-14] () S3 HTTP; C:\WINDOWS\System32\Drivers\HTTP.sys [265728 2009-10-20] () R1 i8042prt; C:\WINDOWS\System32\DRIVERS\i8042prt.sys [53248 2008-04-14] () S3 IDSxpx86; C:\Program Files\Norton AntiVirus\NortonData\21.3.0.12\Definitions\IPSDefs\20140224.002\IDSxpx86.sys [383128 2014-02-21] (Symantec Corporation) R1 Imapi; C:\WINDOWS\System32\DRIVERS\imapi.sys [42112 2008-04-15] () S3 IntcAzAudAddService; C:\WINDOWS\System32\drivers\RtkHDAud.sys [4405248 2006-12-21] () S1 intelppm; C:\WINDOWS\System32\DRIVERS\intelppm.sys [40448 2008-04-15] () S3 Ip6Fw; C:\WINDOWS\System32\DRIVERS\Ip6Fw.sys [36608 2008-04-15] () S3 IpFilterDriver; C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys [32896 2008-04-15] () S3 IpInIp; C:\WINDOWS\System32\DRIVERS\ipinip.sys [20864 2008-04-15] () R3 IpNat; C:\WINDOWS\System32\DRIVERS\ipnat.sys [152832 2008-04-15] () R1 IPSec; C:\WINDOWS\System32\DRIVERS\ipsec.sys [75264 2008-04-15] () S3 IRENUM; C:\WINDOWS\System32\DRIVERS\irenum.sys [11264 2008-04-15] () R0 isapnp; C:\WINDOWS\System32\DRIVERS\isapnp.sys [37632 2008-04-15] () R1 Kbdclass; C:\WINDOWS\System32\DRIVERS\kbdclass.sys [24960 2008-04-15] () S3 kmixer; C:\WINDOWS\System32\drivers\kmixer.sys [172416 2008-04-14] () R0 KSecDD; C:\WINDOWS\system32\Drivers\KSecDD.sys [92928 2009-06-24] () S1 mnmdd; C:\WINDOWS\system32\Drivers\mnmdd.sys [4224 2008-04-15] () S3 Modem; C:\WINDOWS\system32\Drivers\Modem.sys [30208 2008-04-15] () R1 Mouclass; C:\WINDOWS\System32\DRIVERS\mouclass.sys [23296 2008-04-14] () R3 mouhid; C:\WINDOWS\System32\DRIVERS\mouhid.sys [12160 2001-10-26] () R0 MountMgr; C:\WINDOWS\system32\Drivers\MountMgr.sys [42368 2008-04-15] () S3 MRxDAV; C:\WINDOWS\System32\DRIVERS\mrxdav.sys [180608 2008-04-15] () R1 MRxSmb; C:\WINDOWS\System32\DRIVERS\mrxsmb.sys [455296 2008-10-24] () R1 Msfs; C:\WINDOWS\system32\Drivers\Msfs.sys [19072 2008-04-15] () S3 MSKSSRV; C:\WINDOWS\System32\drivers\MSKSSRV.sys [7552 2008-04-14] () S3 MSPCLOCK; C:\WINDOWS\System32\drivers\MSPCLOCK.sys [5376 2008-04-14] () S3 MSPQM; C:\WINDOWS\System32\drivers\MSPQM.sys [4992 2008-04-14] () R3 mssmbios; C:\WINDOWS\System32\DRIVERS\mssmbios.sys [15488 2008-04-15] () S3 MSTEE; C:\WINDOWS\System32\drivers\MSTEE.sys [5504 2008-04-14] () R0 Mup; C:\WINDOWS\system32\Drivers\Mup.sys [105344 2008-04-15] () S3 NABTSFEC; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [85248 2008-04-14] () R0 NDIS; C:\WINDOWS\system32\Drivers\NDIS.sys [182656 2008-04-15] () S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] () R3 NdisTapi; C:\WINDOWS\System32\DRIVERS\ndistapi.sys [10112 2008-04-15] () R3 Ndisuio; C:\WINDOWS\System32\DRIVERS\ndisuio.sys [14592 2008-04-15] () R3 NdisWan; C:\WINDOWS\System32\DRIVERS\ndiswan.sys [91520 2008-04-15] () R3 NDProxy; C:\WINDOWS\system32\Drivers\NDProxy.sys [40576 2008-04-15] () R1 NetBIOS; C:\WINDOWS\System32\DRIVERS\netbios.sys [34688 2008-04-15] () R1 NetBT; C:\WINDOWS\System32\DRIVERS\netbt.sys [162816 2008-04-15] () R1 Npfs; C:\WINDOWS\system32\Drivers\Npfs.sys [30848 2008-04-15] () R4 Ntfs; C:\WINDOWS\system32\Drivers\Ntfs.sys [574976 2008-04-15] () R1 Null; C:\WINDOWS\system32\Drivers\Null.sys [2944 2008-04-15] () S3 NwlnkFlt; C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys [12416 2008-04-15] () S3 NwlnkFwd; C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys [32512 2008-04-15] () S3 Parport; C:\WINDOWS\system32\Drivers\Parport.sys [80256 2008-04-15] () R0 PartMgr; C:\WINDOWS\system32\Drivers\PartMgr.sys [19712 2008-04-15] () S2 ParVdm; C:\WINDOWS\system32\Drivers\ParVdm.sys [6912 2008-04-15] () R0 PCI; C:\WINDOWS\System32\DRIVERS\pci.sys [68608 2008-04-15] () R0 PCIIde; C:\WINDOWS\System32\DRIVERS\pciide.sys [3456 2008-04-15] () R0 Pcmcia; C:\WINDOWS\System32\DRIVERS\pcmcia.sys [120320 2008-04-15] () R3 PptpMiniport; C:\WINDOWS\System32\DRIVERS\raspptp.sys [48384 2008-04-15] () R3 PSched; C:\WINDOWS\System32\DRIVERS\psched.sys [69120 2008-04-15] () R3 Ptilink; C:\WINDOWS\System32\DRIVERS\ptilink.sys [17792 2008-04-15] () R1 RasAcd; C:\WINDOWS\System32\DRIVERS\rasacd.sys [8832 2008-04-15] () R3 Rasl2tp; C:\WINDOWS\System32\DRIVERS\rasl2tp.sys [51328 2008-04-15] () R3 RasPppoe; C:\WINDOWS\System32\DRIVERS\raspppoe.sys [41472 2008-04-15] () R3 Raspti; C:\WINDOWS\System32\DRIVERS\raspti.sys [16512 2008-04-15] () R1 Rdbss; C:\WINDOWS\System32\DRIVERS\rdbss.sys [175744 2008-04-15] () R1 RDPCDD; C:\WINDOWS\System32\DRIVERS\RDPCDD.sys [4224 2008-04-15] () R3 rdpdr; C:\WINDOWS\System32\DRIVERS\rdpdr.sys [196224 2008-04-14] () S3 RDPWD; C:\WINDOWS\system32\Drivers\RDPWD.sys [139656 2008-04-15] () R1 redbook; C:\WINDOWS\System32\DRIVERS\redbook.sys [58880 2008-04-14] () S3 RTL8023xp; C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys [85120 2006-12-14] () S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-14] () S3 Secdrv; C:\WINDOWS\System32\DRIVERS\secdrv.sys [20480 2008-04-15] () S2 Serial; C:\WINDOWS\system32\Drivers\Serial.sys [65280 2008-04-15] () S1 Sfloppy; C:\WINDOWS\system32\Drivers\Sfloppy.sys [11392 2008-04-15] () S3 SLIP; C:\WINDOWS\System32\DRIVERS\SLIP.sys [11136 2008-04-14] () S3 splitter; C:\WINDOWS\System32\drivers\splitter.sys [6272 2008-04-14] () S0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [691696 2010-12-12] (Duplex Secure Ltd.) R0 sr; C:\WINDOWS\System32\DRIVERS\sr.sys [73472 2008-04-15] () S1 SRTSP; C:\WINDOWS\system32\drivers\NAV\1503000.00C\SRTSP.SYS [664280 2014-02-13] (Symantec Corporation) S1 SRTSPX; C:\WINDOWS\system32\drivers\NAV\1503000.00C\SRTSPX.SYS [32344 2013-10-30] (Symantec Corporation) R3 Srv; C:\WINDOWS\System32\DRIVERS\srv.sys [333952 2008-12-11] () S3 streamip; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [15232 2008-04-14] () R3 swenum; C:\WINDOWS\System32\DRIVERS\swenum.sys [4352 2008-04-15] () S3 swmidi; C:\WINDOWS\System32\drivers\swmidi.sys [56576 2008-04-14] () S0 SymDS; C:\WINDOWS\System32\drivers\NAV\1503000.00C\SYMDS.SYS [367704 2013-10-30] (Symantec Corporation) S0 SymEFA; C:\WINDOWS\System32\drivers\NAV\1503000.00C\SYMEFA.SYS [936152 2014-03-04] (Symantec Corporation) S3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT.SYS [142936 2014-06-01] (Symantec Corporation) S1 SymIRON; C:\WINDOWS\system32\drivers\NAV\1503000.00C\Ironx86.SYS [206936 2013-10-30] (Symantec Corporation) S1 SYMTDI; C:\WINDOWS\system32\drivers\NAV\1503000.00C\SYMTDI.SYS [423256 2014-02-18] (Symantec Corporation) S3 sysaudio; C:\WINDOWS\System32\drivers\sysaudio.sys [60800 2008-04-14] () R1 Tcpip; C:\WINDOWS\System32\DRIVERS\tcpip.sys [361600 2008-06-20] () S3 TDPIPE; C:\WINDOWS\system32\Drivers\TDPIPE.sys [12040 2008-04-15] () S3 TDTCP; C:\WINDOWS\system32\Drivers\TDTCP.sys [21896 2008-04-15] () R1 TermDD; C:\WINDOWS\System32\DRIVERS\termdd.sys [40840 2008-04-14] () S4 Udfs; C:\WINDOWS\system32\Drivers\Udfs.sys [66048 2008-04-15] () R3 Update; C:\WINDOWS\System32\DRIVERS\update.sys [384768 2008-04-15] () S3 usbccgp; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [32128 2008-04-14] () R3 usbehci; C:\WINDOWS\System32\DRIVERS\usbehci.sys [30208 2008-04-15] () R3 usbhub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [59520 2008-04-15] () R3 usbohci; C:\WINDOWS\System32\DRIVERS\usbohci.sys [17152 2008-04-15] () S3 usbprint; C:\WINDOWS\System32\DRIVERS\usbprint.sys [25856 2008-04-14] () S3 usbscan; C:\WINDOWS\System32\DRIVERS\usbscan.sys [15104 2008-04-14] () S3 USBSTOR; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [26368 2008-04-14] () S3 usbvideo; C:\WINDOWS\System32\Drivers\usbvideo.sys [121984 2008-04-14] () R1 VgaSave; C:\WINDOWS\System32\drivers\vga.sys [20992 2008-04-15] () R0 VolSnap; C:\WINDOWS\system32\Drivers\VolSnap.sys [52864 2008-04-15] () S3 Wanarp; C:\WINDOWS\System32\DRIVERS\wanarp.sys [34560 2008-04-15] () S3 wdmaud; C:\WINDOWS\System32\drivers\wdmaud.sys [83072 2008-04-14] () S3 WSTCODEC; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [19200 2008-04-14] () R1 {b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}t; C:\WINDOWS\System32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}t.sys [55224 2014-05-19] () U5 3fc68e249a2755ff; C:\Windows\System32\Drivers\3fc68e249a2755ff.sys [32768 2014-05-31] () <===== ATTENTION Necurs Rootkit? U5 BattC; C:\Windows\System32\Drivers\BattC.sys [14208 2008-04-14] () S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S4 IntelIde; No ImagePath S3 NAVENG; \??\C:\Program Files\Norton AntiVirus\NortonData\21.3.0.12\Definitions\VirusDefs\20140303.018\NAVENG.SYS [X] S3 NAVEX15; \??\C:\Program Files\Norton AntiVirus\NortonData\21.3.0.12\Definitions\VirusDefs\20140303.018\NAVEX15.SYS [X] S1 SpyEmrg; System32\Drivers\spyemrg.sys [X] S2 SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys [X] U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-02 00:33 - 2014-06-02 00:36 - 00000000 ___DC () C:\FRST 2014-06-02 00:02 - 2014-06-02 00:02 - 00000000 ____C () C:\Documents and Settings\Administrator\Pulpit\Nowy Dokument tekstowy (2).txt 2014-06-01 23:43 - 2014-06-01 23:43 - 00001770 ____C () C:\Documents and Settings\Administrator\Pulpit\Nowy Dokument tekstowy.txt 2014-06-01 22:39 - 2014-06-01 22:39 - 01347418 ____C () C:\Documents and Settings\Administrator\Pulpit\wyniki Norton antywirusa.txt 2014-06-01 18:14 - 2014-06-01 18:14 - 00142936 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 2014-06-01 18:14 - 2014-06-01 18:14 - 00008194 _____ () C:\WINDOWS\system32\Drivers\SYMEVENT.CAT 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\WINDOWS\system32\Drivers\NST 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\Program Files\Symantec 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\Program Files\Norton Identity Safe 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Norton Identity Safe 2014-06-01 18:13 - 2014-06-01 18:13 - 00001885 _____ () C:\Documents and Settings\All Users\Pulpit\Norton AntiVirus.LNK 2014-06-01 18:12 - 2014-06-01 18:14 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\Norton 2014-06-01 18:12 - 2014-06-01 18:13 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Norton AntiVirus 2014-06-01 18:12 - 2014-06-01 18:12 - 00000000 ____D () C:\WINDOWS\system32\Drivers\NAV 2014-06-01 18:12 - 2014-06-01 18:12 - 00000000 ____D () C:\Program Files\Norton AntiVirus 2014-06-01 18:03 - 2014-06-01 18:03 - 294185016 ____C (Symantec Corporation) C:\Documents and Settings\Administrator\Moje dokumenty\NAV-ESD-21.3.0-PL.exe 2014-06-01 17:21 - 2014-06-01 17:21 - 123790440 ____C (Copyright © 2012 TrustPort, a.s. ) C:\Documents and Settings\Administrator\Moje dokumenty\TrustPort_USB_Antivirus_14.0.3.5256.exe 2014-06-01 17:18 - 2014-06-01 17:18 - 00000176 ____C () C:\Documents and Settings\Administrator\avgrep.txt 2014-06-01 16:57 - 2014-06-01 16:57 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\TuneUp Software 2014-06-01 16:47 - 2014-06-01 20:22 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\MFAData 2014-06-01 16:47 - 2014-06-01 20:22 - 00000000 ____D () C:\Program Files\Rock Turner 2014-06-01 16:47 - 2014-06-01 16:47 - 04487240 ____C (AVG Technologies) C:\Documents and Settings\Administrator\Moje dokumenty\avg_avct_stb_all_2014_4592.exe 2014-06-01 16:47 - 2014-06-01 16:47 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\MFAData 2014-06-01 16:31 - 2014-06-01 16:31 - 00000667 _____ () C:\Documents and Settings\Administrator\Pulpit\Skrót do iexplore.lnk 2014-06-01 16:31 - 2014-06-01 16:31 - 00000000 _SHDC () C:\Documents and Settings\Administrator\PrivacIE 2014-06-01 16:30 - 2014-06-01 16:30 - 00000000 _SHDC () C:\Documents and Settings\Administrator\IETldCache 2014-06-01 16:26 - 2014-06-01 16:28 - 00065536 _____ () C:\WINDOWS\system32\config\Internet.evt 2014-06-01 16:24 - 2014-06-01 16:26 - 00071482 _____ () C:\WINDOWS\ie8.log 2014-06-01 16:24 - 2014-06-01 16:26 - 00000000 ___HD () C:\WINDOWS\msdownld.tmp 2014-06-01 16:24 - 2014-06-01 16:25 - 00000000 __HDC () C:\WINDOWS\ie8 2014-06-01 16:23 - 2014-06-01 16:27 - 00038563 _____ () C:\WINDOWS\ie8_main.log 2014-06-01 14:38 - 2014-06-01 14:46 - 00000000 ___DC () C:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie 2014-06-01 14:26 - 2014-06-01 14:26 - 00021920 ____C () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2014-06-01 14:20 - 2014-06-01 14:20 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Adobe 2014-06-01 14:20 - 2014-06-01 14:20 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\Adobe 2014-06-01 14:15 - 2014-06-01 14:15 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\ipla 2014-06-01 13:37 - 2014-06-01 13:37 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Mozilla 2014-06-01 13:37 - 2014-06-01 13:37 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla 2014-06-01 08:10 - 2014-06-01 08:10 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\Package Cache 2014-06-01 08:10 - 2014-06-01 08:10 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard 2014-06-01 01:40 - 2009-01-07 18:21 - 00018976 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsg.dll 2014-06-01 01:39 - 2014-06-01 18:11 - 00000000 ____D () C:\WINDOWS\LastGood 2014-06-01 01:39 - 2014-06-01 01:40 - 00015219 _____ () C:\WINDOWS\KB942288-v3.log 2014-06-01 01:39 - 2014-06-01 01:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB942288-v3$ 2014-06-01 01:38 - 2014-06-01 01:38 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft 2014-06-01 01:30 - 2014-06-01 01:30 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-06-01 01:30 - 2014-06-01 01:30 - 00000000 ____D () C:\Program Files\Adobe 2014-06-01 00:53 - 2014-06-01 00:53 - 00000000 __SHD () C:\WINDOWS\CSC 2014-05-31 19:12 - 2014-05-31 19:12 - 00032768 _____ () C:\WINDOWS\system32\Drivers\3fc68e249a2755ff.sys 2014-05-30 01:19 - 2014-05-30 01:19 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-05-23 18:32 - 2014-05-31 16:25 - 00000000 _____ () C:\WINDOWS\system32\s.o 2014-05-22 22:10 - 2014-05-19 15:30 - 00055224 _____ () C:\WINDOWS\system32\Drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}t.sys 2014-05-22 20:36 - 2014-05-31 16:25 - 00000378 _____ () C:\WINDOWS\Tasks\AmiUpdXp.job 2014-05-22 20:27 - 2014-05-22 20:27 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Metin2 2014-05-22 19:02 - 2014-06-01 14:15 - 00000000 ____D () C:\Program Files\GameforgeLive 2014-05-09 23:57 - 2014-05-10 00:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-04 23:32 - 2014-05-04 23:32 - 00098304 _____ () C:\WINDOWS\Minidump\Mini050414-01.dmp ==================== One Month Modified Files and Folders ======= 2014-06-02 00:36 - 2014-06-02 00:33 - 00000000 ___DC () C:\FRST 2014-06-02 00:36 - 2014-01-23 23:14 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp 2014-06-02 00:02 - 2014-06-02 00:02 - 00000000 ____C () C:\Documents and Settings\Administrator\Pulpit\Nowy Dokument tekstowy (2).txt 2014-06-02 00:02 - 2014-01-23 23:14 - 00000000 ___DC () C:\Documents and Settings\Administrator\Pulpit 2014-06-01 23:56 - 2008-04-15 14:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl 2014-06-01 23:49 - 2014-01-23 23:14 - 00000188 __SHC () C:\Documents and Settings\Administrator\ntuser.ini 2014-06-01 23:49 - 2010-01-16 15:30 - 01758942 _____ () C:\WINDOWS\WindowsUpdate.log 2014-06-01 23:43 - 2014-06-01 23:43 - 00001770 ____C () C:\Documents and Settings\Administrator\Pulpit\Nowy Dokument tekstowy.txt 2014-06-01 22:39 - 2014-06-01 22:39 - 01347418 ____C () C:\Documents and Settings\Administrator\Pulpit\wyniki Norton antywirusa.txt 2014-06-01 20:22 - 2014-06-01 16:47 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\MFAData 2014-06-01 20:22 - 2014-06-01 16:47 - 00000000 ____D () C:\Program Files\Rock Turner 2014-06-01 20:22 - 2014-01-23 23:14 - 00000000 _RHDC () C:\Documents and Settings\Administrator\Dane aplikacji 2014-06-01 20:22 - 2014-01-23 23:14 - 00000000 __HDC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji 2014-06-01 20:22 - 2010-01-16 16:18 - 00000000 _RHDC () C:\Documents and Settings\All Users\Dane aplikacji 2014-06-01 18:14 - 2014-06-01 18:14 - 00142936 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 2014-06-01 18:14 - 2014-06-01 18:14 - 00008194 _____ () C:\WINDOWS\system32\Drivers\SYMEVENT.CAT 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\WINDOWS\system32\Drivers\NST 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\Program Files\Symantec 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\Program Files\Norton Identity Safe 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Norton Identity Safe 2014-06-01 18:14 - 2014-06-01 18:12 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\Norton 2014-06-01 18:14 - 2010-01-16 16:19 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy 2014-06-01 18:13 - 2014-06-01 18:13 - 00001885 _____ () C:\Documents and Settings\All Users\Pulpit\Norton AntiVirus.LNK 2014-06-01 18:13 - 2014-06-01 18:12 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Norton AntiVirus 2014-06-01 18:13 - 2010-01-16 16:19 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2014-06-01 18:12 - 2014-06-01 18:12 - 00000000 ____D () C:\WINDOWS\system32\Drivers\NAV 2014-06-01 18:12 - 2014-06-01 18:12 - 00000000 ____D () C:\Program Files\Norton AntiVirus 2014-06-01 18:11 - 2014-06-01 01:39 - 00000000 ____D () C:\WINDOWS\LastGood 2014-06-01 18:03 - 2014-06-01 18:03 - 294185016 ____C (Symantec Corporation) C:\Documents and Settings\Administrator\Moje dokumenty\NAV-ESD-21.3.0-PL.exe 2014-06-01 18:03 - 2014-01-23 23:14 - 00000000 ___DC () C:\Documents and Settings\Administrator\Moje dokumenty 2014-06-01 17:21 - 2014-06-01 17:21 - 123790440 ____C (Copyright © 2012 TrustPort, a.s. ) C:\Documents and Settings\Administrator\Moje dokumenty\TrustPort_USB_Antivirus_14.0.3.5256.exe 2014-06-01 17:18 - 2014-06-01 17:18 - 00000176 ____C () C:\Documents and Settings\Administrator\avgrep.txt 2014-06-01 17:18 - 2014-01-23 23:14 - 00000000 ___DC () C:\Documents and Settings\Administrator 2014-06-01 16:57 - 2014-06-01 16:57 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\TuneUp Software 2014-06-01 16:57 - 2010-01-16 16:18 - 00927870 _____ () C:\WINDOWS\setupapi.log 2014-06-01 16:47 - 2014-06-01 16:47 - 04487240 ____C (AVG Technologies) C:\Documents and Settings\Administrator\Moje dokumenty\avg_avct_stb_all_2014_4592.exe 2014-06-01 16:47 - 2014-06-01 16:47 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\MFAData 2014-06-01 16:31 - 2014-06-01 16:31 - 00000667 _____ () C:\Documents and Settings\Administrator\Pulpit\Skrót do iexplore.lnk 2014-06-01 16:31 - 2014-06-01 16:31 - 00000000 _SHDC () C:\Documents and Settings\Administrator\PrivacIE 2014-06-01 16:31 - 2014-01-23 23:14 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ulubione 2014-06-01 16:30 - 2014-06-01 16:30 - 00000000 _SHDC () C:\Documents and Settings\Administrator\IETldCache 2014-06-01 16:29 - 2010-01-16 16:09 - 00000000 ____D () C:\WINDOWS\system32\pl-pl 2014-06-01 16:29 - 2010-01-16 16:09 - 00000000 ____D () C:\WINDOWS\Help 2014-06-01 16:28 - 2014-06-01 16:26 - 00065536 _____ () C:\WINDOWS\system32\config\Internet.evt 2014-06-01 16:27 - 2014-06-01 16:23 - 00038563 _____ () C:\WINDOWS\ie8_main.log 2014-06-01 16:26 - 2014-06-01 16:24 - 00071482 _____ () C:\WINDOWS\ie8.log 2014-06-01 16:26 - 2014-06-01 16:24 - 00000000 ___HD () C:\WINDOWS\msdownld.tmp 2014-06-01 16:26 - 2010-01-20 02:26 - 00004012 ____C () C:\WINDOWS\spupdsvc.log 2014-06-01 16:26 - 2010-01-20 02:24 - 00049847 ____C () C:\WINDOWS\updspapi.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00522164 ____C () C:\WINDOWS\iis6.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00435905 ____C () C:\WINDOWS\FaxSetup.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00226996 ____C () C:\WINDOWS\ocgen.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00208882 ____C () C:\WINDOWS\tsoc.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00157599 ____C () C:\WINDOWS\comsetup.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00147382 ____C () C:\WINDOWS\msmqinst.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00094897 ____C () C:\WINDOWS\ntdtcsetup.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00077728 ____C () C:\WINDOWS\netfxocm.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00031316 ____C () C:\WINDOWS\MedCtrOC.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00027575 ____C () C:\WINDOWS\ocmsn.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00022952 ____C () C:\WINDOWS\tabletoc.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00022481 ____C () C:\WINDOWS\msgsocm.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00001355 _____ () C:\WINDOWS\imsins.log 2014-06-01 16:25 - 2014-06-01 16:24 - 00000000 __HDC () C:\WINDOWS\ie8 2014-06-01 16:25 - 2010-01-16 16:09 - 00000000 ____D () C:\WINDOWS\Media 2014-06-01 14:46 - 2014-06-01 14:38 - 00000000 ___DC () C:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie 2014-06-01 14:26 - 2014-06-01 14:26 - 00021920 ____C () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2014-06-01 14:22 - 2014-01-23 23:14 - 00000000 __HDC () C:\Documents and Settings\Administrator\Ustawienia lokalne 2014-06-01 14:20 - 2014-06-01 14:20 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Adobe 2014-06-01 14:20 - 2014-06-01 14:20 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\Adobe 2014-06-01 14:15 - 2014-06-01 14:15 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\ipla 2014-06-01 14:15 - 2014-05-22 19:02 - 00000000 ____D () C:\Program Files\GameforgeLive 2014-06-01 14:15 - 2010-01-16 16:19 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start 2014-06-01 14:11 - 2010-01-16 16:19 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy\Autostart 2014-06-01 14:10 - 2012-05-01 15:20 - 00000000 ____D () C:\WINDOWS\system32\appmgmt 2014-06-01 13:37 - 2014-06-01 13:37 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Mozilla 2014-06-01 13:37 - 2014-06-01 13:37 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla 2014-06-01 08:10 - 2014-06-01 08:10 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\Package Cache 2014-06-01 08:10 - 2014-06-01 08:10 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard 2014-06-01 01:40 - 2014-06-01 01:39 - 00015219 _____ () C:\WINDOWS\KB942288-v3.log 2014-06-01 01:40 - 2014-06-01 01:39 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB942288-v3$ 2014-06-01 01:40 - 2010-01-16 16:19 - 00001355 _____ () C:\WINDOWS\imsins.BAK 2014-06-01 01:38 - 2014-06-01 01:38 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft 2014-06-01 01:30 - 2014-06-01 01:30 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-06-01 01:30 - 2014-06-01 01:30 - 00000000 ____D () C:\Program Files\Adobe 2014-06-01 01:30 - 2010-01-20 01:37 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\Adobe 2014-06-01 01:19 - 2010-01-16 17:13 - 00000000 ____D () C:\Documents and Settings\Kasia 2014-06-01 01:19 - 2010-01-16 17:11 - 00000000 __SHD () C:\Documents and Settings\LocalService 2014-06-01 01:19 - 2010-01-16 15:35 - 00000000 __SHD () C:\Documents and Settings\NetworkService 2014-06-01 01:19 - 2010-01-16 15:27 - 00000000 ____D () C:\WINDOWS\Registration 2014-06-01 00:53 - 2014-06-01 00:53 - 00000000 __SHD () C:\WINDOWS\CSC 2014-06-01 00:47 - 2010-01-16 18:06 - 00524288 _____ () C:\WINDOWS\system32\config\ACEEvent.evt 2014-05-31 21:30 - 2008-04-15 14:00 - 00000579 _____ () C:\WINDOWS\win.ini 2014-05-31 19:12 - 2014-05-31 19:12 - 00032768 _____ () C:\WINDOWS\system32\Drivers\3fc68e249a2755ff.sys 2014-05-31 16:25 - 2014-05-23 18:32 - 00000000 _____ () C:\WINDOWS\system32\s.o 2014-05-31 16:25 - 2014-05-22 20:36 - 00000378 _____ () C:\WINDOWS\Tasks\AmiUpdXp.job 2014-05-31 16:25 - 2010-01-16 17:11 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-05-31 16:25 - 2010-01-16 16:23 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-05-31 16:25 - 2010-01-16 16:23 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-05-30 01:19 - 2014-05-30 01:19 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-05-30 01:19 - 2012-08-11 17:06 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Skype 2014-05-30 01:17 - 2010-01-16 17:11 - 00032578 _____ () C:\WINDOWS\SchedLgU.Txt 2014-05-22 20:27 - 2014-05-22 20:27 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Metin2 2014-05-21 16:00 - 2010-06-13 18:53 - 00000664 _____ () C:\WINDOWS\system32\d3d9caps.dat 2014-05-19 15:30 - 2014-05-22 22:10 - 00055224 _____ () C:\WINDOWS\system32\Drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}t.sys 2014-05-15 23:58 - 2014-01-16 15:29 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-05-10 00:06 - 2014-05-09 23:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-04 23:32 - 2014-05-04 23:32 - 00098304 _____ () C:\WINDOWS\Minidump\Mini050414-01.dmp 2014-05-04 23:32 - 2012-11-02 14:49 - 00000000 ____D () C:\WINDOWS\Minidump ==================== Bamital & volsnap Check ================= C:\WINDOWS\explorer.exe [2008-04-15 14:00] - [2008-04-15 14:00] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\WINDOWS\system32\winlogon.exe [2008-04-15 14:00] - [2008-04-15 14:00] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\WINDOWS\system32\svchost.exe [2008-04-15 14:00] - [2008-04-15 14:00] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\WINDOWS\system32\services.exe [2008-04-15 14:00] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f C:\WINDOWS\system32\User32.dll [2008-04-15 14:00] - [2008-04-15 14:00] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\WINDOWS\system32\userinit.exe [2008-04-15 14:00] - [2008-04-15 14:00] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\WINDOWS\system32\rpcss.dll [2008-04-15 14:00] - [2009-02-09 12:53] - 0401408 ____A (Microsoft Corporation) a37311d9d628c1042a2836731787f0f3 ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected. C:\WINDOWS\system32\Drivers\volsnap.sys [2008-04-15 14:00] - [2008-04-15 14:00] - 0052864 ___AC () C:\WINDOWS\system32\Drivers\volsnap.sys No Company Name <===== ATTENTION! ==================== End Of Log ============================