Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-06-2014 Ran by Kasia (administrator) on A45F7D7627C54C0 on 04-06-2014 16:08:22 Running from D:\ Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jqs.exe (Symantec Corporation) C:\Program Files\Norton AntiVirus\Engine\21.3.0.12\NAV.exe (Symantec Corporation) C:\Program Files\Norton Identity Safe\Engine\2014.7.0.47\nst.exe (Symantec Corporation) C:\Program Files\Norton AntiVirus\Engine\21.3.0.12\NAV.exe (Symantec Corporation) C:\Program Files\Norton Identity Safe\Engine\2014.7.0.47\nst.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254896 2012-09-17] (Sun Microsystems, Inc.) Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pl.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://pl.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.bing.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.bing.com/ SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\21.3.0.12\IPS\IPSBHO.DLL (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files\Norton Identity Safe\Engine\2014.7.0.47\coIEPlg.dll (Symantec Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) Toolbar: HKLM - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2014.7.0.47\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) Toolbar: HKCU - Norton Identity Safe Toolbar - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2014.7.0.47\coIEPlg.dll (Symantec Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_45-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_45-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_45-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Kasia\Dane aplikacji\Mozilla\Firefox\Profiles\yb3bazy3.default-1401890091609 FF Plugin: @java.com/DTPlugin,version=1.6.0_45 - C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\Documents and Settings\All Users\Dane aplikacji\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_21.3.0.12\IPSFF FF Extension: Norton Vulnerability Protection - C:\Documents and Settings\All Users\Dane aplikacji\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_21.3.0.12\IPSFF [2014-06-03] FF HKLM\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] - C:\Documents and Settings\All Users\Dane aplikacji\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.7.0.43\coFFPlgn\ FF Extension: Norton Identity Safe Toolbar - C:\Documents and Settings\All Users\Dane aplikacji\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.7.0.43\coFFPlgn\ [] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR RestoreOnStartup: "hxxp://home.sweetim.com/?barid={53F781C3-D4B1-48E2-A7B5-491FC7A8FBAF}&st=14" CHR HKLM\...\Chrome\Extension: [nppllibpnmahfaklnpggkibhkapjkeob] - C:\Program Files\Norton Identity Safe\Engine\2014.7.0.47\Exts\Chrome.crx [2014-06-03] ========================== Services (Whitelisted) ================= R2 JavaQuickStarterService; C:\Program Files\Java\jre6\bin\jqs.exe [158128 2014-03-15] (Sun Microsystems, Inc.) R2 NAV; C:\Program Files\Norton AntiVirus\Engine\21.3.0.12\NAV.exe [262968 2014-05-11] (Symantec Corporation) R2 NCO; C:\Program Files\Norton Identity Safe\Engine\2014.7.0.47\NST.exe [130104 2014-05-14] (Symantec Corporation) ==================== Drivers (Whitelisted) ==================== R3 AR5211; C:\WINDOWS\System32\DRIVERS\ar5211.sys [488992 2006-03-23] (Atheros Communications, Inc.) R1 BHDrvx86; C:\Program Files\Norton AntiVirus\NortonData\21.3.0.12\Definitions\BASHDefs\20140510.001\BHDrvx86.sys [1101616 2014-05-10] (Symantec Corporation) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation) R1 ccSet_NAV; C:\WINDOWS\system32\drivers\NAV\1503000.00C\ccSetx86.sys [127064 2014-02-21] (Symantec Corporation) R1 ccSet_NST; C:\WINDOWS\system32\drivers\NST\7DE07000.02F\ccSetx86.sys [127064 2014-02-21] (Symantec Corporation) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2014-05-31] (Symantec Corporation) S3 hamachi; C:\WINDOWS\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2005-01-07] (Windows (R) Server 2003 DDK provider) R3 IDSxpx86; C:\Program Files\Norton AntiVirus\NortonData\21.3.0.12\Definitions\IPSDefs\20140603.001\IDSxpx86.sys [383120 2014-06-02] (Symantec Corporation) R3 NAVENG; C:\Program Files\Norton AntiVirus\NortonData\21.3.0.12\Definitions\VirusDefs\20140603.018\NAVENG.SYS [93272 2014-05-31] (Symantec Corporation) R3 NAVEX15; C:\Program Files\Norton AntiVirus\NortonData\21.3.0.12\Definitions\VirusDefs\20140603.018\NAVEX15.SYS [1612376 2014-05-31] (Symantec Corporation) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation) S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-14] (Realtek Semiconductor Corporation) R1 SRTSP; C:\WINDOWS\system32\drivers\NAV\1503000.00C\SRTSP.SYS [664280 2014-02-13] (Symantec Corporation) R1 SRTSPX; C:\WINDOWS\system32\drivers\NAV\1503000.00C\SRTSPX.SYS [32344 2013-10-30] (Symantec Corporation) R0 SymDS; C:\WINDOWS\System32\drivers\NAV\1503000.00C\SYMDS.SYS [367704 2013-10-30] (Symantec Corporation) R0 SymEFA; C:\WINDOWS\System32\drivers\NAV\1503000.00C\SYMEFA.SYS [936152 2014-03-04] (Symantec Corporation) R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT.SYS [142936 2014-06-01] (Symantec Corporation) R1 SymIRON; C:\WINDOWS\system32\drivers\NAV\1503000.00C\Ironx86.SYS [206936 2013-10-30] (Symantec Corporation) R1 SYMTDI; C:\WINDOWS\system32\drivers\NAV\1503000.00C\SYMTDI.SYS [423256 2014-02-18] (Symantec Corporation) S4 IntelIde; No ImagePath U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-04 16:07 - 2014-06-04 16:07 - 00001319 _____ () C:\Documents and Settings\Kasia\Pulpit\AdwCleaner[S1].txt 2014-06-04 15:59 - 2014-06-04 16:08 - 00000000 ____D () C:\Documents and Settings\Kasia\Ustawienia lokalne\Temp 2014-06-03 23:38 - 2014-06-03 23:38 - 00000000 ____D () C:\Documents and Settings\LocalService\Pulpit 2014-06-03 22:12 - 2014-06-04 16:03 - 00000000 ___DC () C:\AdwCleaner 2014-06-03 22:12 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\system32\sqlite3.dll 2014-06-03 22:06 - 2014-06-04 15:54 - 00000000 ____D () C:\Documents and Settings\Kasia\Pulpit\Stare dane programu Firefox 2014-06-03 21:48 - 2014-06-03 22:48 - 00000544 _____ () C:\Documents and Settings\Kasia\Pulpit\notatnik fi.txt 2014-06-03 13:15 - 2014-06-03 13:27 - 00000000 ____D () C:\Documents and Settings\Kasia\Pulpit\Nowy folder 2014-06-03 13:05 - 2014-06-03 13:05 - 00000803 _____ () C:\Documents and Settings\Kasia\Menu Start\Programy\Internet Explorer.lnk 2014-06-03 13:04 - 2014-06-03 13:04 - 00000000 __SHD () C:\Documents and Settings\Kasia\IETldCache 2014-06-03 13:04 - 2014-06-03 13:04 - 00000000 ____D () C:\Program Files\xerox 2014-06-03 13:04 - 2014-06-03 13:04 - 00000000 ____D () C:\Program Files\windows nt 2014-06-03 13:04 - 2014-06-03 13:04 - 00000000 ____D () C:\Program Files\msn gaming zone 2014-06-03 13:04 - 2014-06-03 13:04 - 00000000 ____D () C:\Program Files\movie maker 2014-06-03 13:04 - 2014-06-03 13:04 - 00000000 ____D () C:\Program Files\microsoft frontpage 2014-06-03 13:02 - 2014-06-03 13:02 - 00000000 ___DC () C:\TDSSKiller_Quarantine 2014-06-02 00:33 - 2014-06-04 16:08 - 00000000 ___DC () C:\FRST 2014-06-01 22:39 - 2014-06-01 22:39 - 01347418 ____C () C:\Documents and Settings\Administrator\Pulpit\wyniki Norton antywirusa.txt 2014-06-01 18:14 - 2014-06-04 14:38 - 00000000 ____D () C:\WINDOWS\system32\Drivers\NST 2014-06-01 18:14 - 2014-06-04 14:36 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Norton Identity Safe 2014-06-01 18:14 - 2014-06-03 13:13 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared 2014-06-01 18:14 - 2014-06-01 18:14 - 00142936 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 2014-06-01 18:14 - 2014-06-01 18:14 - 00008194 _____ () C:\WINDOWS\system32\Drivers\SYMEVENT.CAT 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\Program Files\Symantec 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\Program Files\Norton Identity Safe 2014-06-01 18:13 - 2014-06-01 18:13 - 00001885 _____ () C:\Documents and Settings\All Users\Pulpit\Norton AntiVirus.LNK 2014-06-01 18:12 - 2014-06-03 13:05 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\Norton 2014-06-01 18:12 - 2014-06-01 18:13 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Norton AntiVirus 2014-06-01 18:12 - 2014-06-01 18:12 - 00000000 ____D () C:\WINDOWS\system32\Drivers\NAV 2014-06-01 18:12 - 2014-06-01 18:12 - 00000000 ____D () C:\Program Files\Norton AntiVirus 2014-06-01 18:03 - 2014-06-01 18:03 - 294185016 ____C (Symantec Corporation) C:\Documents and Settings\Administrator\Moje dokumenty\NAV-ESD-21.3.0-PL.exe 2014-06-01 17:21 - 2014-06-01 17:21 - 123790440 ____C (Copyright © 2012 TrustPort, a.s. ) C:\Documents and Settings\Administrator\Moje dokumenty\TrustPort_USB_Antivirus_14.0.3.5256.exe 2014-06-01 17:18 - 2014-06-01 17:18 - 00000176 ____C () C:\Documents and Settings\Administrator\avgrep.txt 2014-06-01 16:57 - 2014-06-01 16:57 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\TuneUp Software 2014-06-01 16:47 - 2014-06-01 16:47 - 04487240 ____C (AVG Technologies) C:\Documents and Settings\Administrator\Moje dokumenty\avg_avct_stb_all_2014_4592.exe 2014-06-01 16:31 - 2014-06-01 16:31 - 00000667 _____ () C:\Documents and Settings\Administrator\Pulpit\Skrót do iexplore.lnk 2014-06-01 16:31 - 2014-06-01 16:31 - 00000000 _SHDC () C:\Documents and Settings\Administrator\PrivacIE 2014-06-01 16:30 - 2014-06-01 16:30 - 00000000 _SHDC () C:\Documents and Settings\Administrator\IETldCache 2014-06-01 16:26 - 2014-06-01 16:28 - 00065536 _____ () C:\WINDOWS\system32\config\Internet.evt 2014-06-01 16:24 - 2014-06-01 16:26 - 00071482 _____ () C:\WINDOWS\ie8.log 2014-06-01 16:24 - 2014-06-01 16:26 - 00000000 ___HD () C:\WINDOWS\msdownld.tmp 2014-06-01 16:24 - 2014-06-01 16:25 - 00000000 __HDC () C:\WINDOWS\ie8 2014-06-01 16:23 - 2014-06-01 16:27 - 00038563 _____ () C:\WINDOWS\ie8_main.log 2014-06-01 14:38 - 2014-06-01 14:46 - 00000000 ___DC () C:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie 2014-06-01 14:26 - 2014-06-01 14:26 - 00021920 ____C () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2014-06-01 14:20 - 2014-06-01 14:20 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Adobe 2014-06-01 14:20 - 2014-06-01 14:20 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\Adobe 2014-06-01 14:15 - 2014-06-01 14:15 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\ipla 2014-06-01 13:37 - 2014-06-01 13:37 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Mozilla 2014-06-01 13:37 - 2014-06-01 13:37 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla 2014-06-01 08:10 - 2014-06-01 08:10 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\Package Cache 2014-06-01 08:10 - 2014-06-01 08:10 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard 2014-06-01 02:11 - 2014-06-01 02:11 - 299454696 _____ (Arcabit Ltd.) C:\Documents and Settings\Kasia\Moje dokumenty\ArcabitSetup_av_demo.exe 2014-06-01 01:44 - 2014-06-01 01:44 - 08165432 _____ (NETGATE Technologies s.r.o. ) C:\Documents and Settings\Kasia\Moje dokumenty\aa-setup-ngt.exe 2014-06-01 01:40 - 2009-01-07 18:21 - 00018976 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsg.dll 2014-06-01 01:39 - 2014-06-01 01:40 - 00015219 _____ () C:\WINDOWS\KB942288-v3.log 2014-06-01 01:39 - 2014-06-01 01:40 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB942288-v3$ 2014-06-01 01:37 - 2014-06-01 01:37 - 01724552 _____ () C:\Documents and Settings\Kasia\Moje dokumenty\Adaware_Installer.exe 2014-06-01 01:30 - 2014-06-01 01:30 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-06-01 01:30 - 2014-06-01 01:30 - 00000000 ____D () C:\Program Files\Adobe 2014-06-01 00:53 - 2014-06-03 12:55 - 00000000 __SHD () C:\WINDOWS\CSC 2014-05-31 19:56 - 2014-05-31 19:56 - 17938608 _____ (Adobe Systems Incorporated) C:\Documents and Settings\Kasia\Moje dokumenty\install_flash_player.exe 2014-05-31 19:46 - 2014-06-01 01:30 - 00000000 ____D () C:\Documents and Settings\Kasia\Ustawienia lokalne\Dane aplikacji\Adobe 2014-05-28 19:05 - 2014-05-28 19:05 - 00000000 ____D () C:\Documents and Settings\Kasia\Pulpit\magda 2014-05-23 18:32 - 2014-05-31 16:25 - 00000000 _____ () C:\WINDOWS\system32\s.o 2014-05-22 19:09 - 2014-05-22 19:09 - 00000000 ____D () C:\Documents and Settings\Kasia\Pulpit\warcraft 2014-05-22 19:03 - 2014-05-25 21:09 - 00000000 ____D () C:\Documents and Settings\Kasia\Moje dokumenty\Gameforge Live 2014-05-22 19:03 - 2014-05-22 19:03 - 00000000 ____D () C:\Documents and Settings\Kasia\Ustawienia lokalne\Dane aplikacji\Gameforge4d 2014-05-22 19:02 - 2014-06-01 14:15 - 00000000 ____D () C:\Program Files\GameforgeLive 2014-05-17 20:19 - 2014-05-17 20:21 - 00000000 ____D () C:\Documents and Settings\Kasia\Pulpit\SETTLER II + dodatek Nowe misje (PL) 2014-05-09 23:57 - 2014-06-03 21:58 - 00000000 ____D () C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-06-04 16:08 - 2014-06-04 15:59 - 00000000 ____D () C:\Documents and Settings\Kasia\Ustawienia lokalne\Temp 2014-06-04 16:08 - 2014-06-02 00:33 - 00000000 ___DC () C:\FRST 2014-06-04 16:07 - 2014-06-04 16:07 - 00001319 _____ () C:\Documents and Settings\Kasia\Pulpit\AdwCleaner[S1].txt 2014-06-04 16:07 - 2010-01-16 17:13 - 00000000 ____D () C:\Documents and Settings\Kasia\Pulpit 2014-06-04 16:06 - 2010-01-16 15:30 - 01799300 _____ () C:\WINDOWS\WindowsUpdate.log 2014-06-04 16:05 - 2010-01-16 17:11 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-06-04 16:05 - 2010-01-16 16:23 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-06-04 16:05 - 2010-01-16 16:23 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-06-04 16:05 - 2008-04-15 14:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl 2014-06-04 16:04 - 2010-01-16 17:11 - 00032470 _____ () C:\WINDOWS\SchedLgU.Txt 2014-06-04 16:03 - 2014-06-03 22:12 - 00000000 ___DC () C:\AdwCleaner 2014-06-04 16:01 - 2014-01-16 15:31 - 00000000 ____D () C:\Documents and Settings\Kasia\Moje dokumenty\Pobieranie 2014-06-04 15:59 - 2010-01-16 17:13 - 00000000 ___HD () C:\Documents and Settings\Kasia\Ustawienia lokalne 2014-06-04 15:54 - 2014-06-03 22:06 - 00000000 ____D () C:\Documents and Settings\Kasia\Pulpit\Stare dane programu Firefox 2014-06-04 15:26 - 2010-01-16 16:18 - 00959212 _____ () C:\WINDOWS\setupapi.log 2014-06-04 15:22 - 2008-04-15 14:00 - 00000624 _____ () C:\WINDOWS\win.ini 2014-06-04 14:49 - 2010-01-16 17:13 - 00000188 ___SH () C:\Documents and Settings\Kasia\ntuser.ini 2014-06-04 14:38 - 2014-06-01 18:14 - 00000000 ____D () C:\WINDOWS\system32\Drivers\NST 2014-06-04 14:36 - 2014-06-01 18:14 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Norton Identity Safe 2014-06-03 23:38 - 2014-06-03 23:38 - 00000000 ____D () C:\Documents and Settings\LocalService\Pulpit 2014-06-03 23:38 - 2010-01-16 17:11 - 00000000 __SHD () C:\Documents and Settings\LocalService 2014-06-03 22:48 - 2014-06-03 21:48 - 00000544 _____ () C:\Documents and Settings\Kasia\Pulpit\notatnik fi.txt 2014-06-03 22:13 - 2010-01-16 17:13 - 00000000 __RHD () C:\Documents and Settings\Kasia\Dane aplikacji 2014-06-03 22:13 - 2010-01-16 17:13 - 00000000 ___RD () C:\Documents and Settings\Kasia\Moje dokumenty 2014-06-03 22:13 - 2010-01-16 17:13 - 00000000 ___HD () C:\Documents and Settings\Kasia\Ustawienia lokalne\Dane aplikacji 2014-06-03 22:13 - 2010-01-16 17:13 - 00000000 ____D () C:\Documents and Settings\Kasia 2014-06-03 22:13 - 2010-01-16 16:18 - 00000000 _RHDC () C:\Documents and Settings\All Users\Dane aplikacji 2014-06-03 21:59 - 2010-01-16 18:06 - 00524288 _____ () C:\WINDOWS\system32\config\ACEEvent.evt 2014-06-03 21:58 - 2014-05-09 23:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-06-03 20:43 - 2012-08-27 23:22 - 00000000 ____D () C:\Documents and Settings\Kasia\Dane aplikacji\.minecraft 2014-06-03 18:21 - 2010-01-16 17:13 - 00000000 ___RD () C:\Documents and Settings\Kasia\Menu Start 2014-06-03 17:42 - 2012-08-11 17:06 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Skype 2014-06-03 17:41 - 2010-01-16 16:19 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy 2014-06-03 13:27 - 2014-06-03 13:15 - 00000000 ____D () C:\Documents and Settings\Kasia\Pulpit\Nowy folder 2014-06-03 13:13 - 2014-06-01 18:14 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared 2014-06-03 13:05 - 2014-06-03 13:05 - 00000803 _____ () C:\Documents and Settings\Kasia\Menu Start\Programy\Internet Explorer.lnk 2014-06-03 13:05 - 2014-06-01 18:12 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\Norton 2014-06-03 13:05 - 2010-01-20 02:26 - 00011310 ____C () C:\WINDOWS\spupdsvc.log 2014-06-03 13:05 - 2010-01-16 17:13 - 00000000 ___RD () C:\Documents and Settings\Kasia\Ulubione 2014-06-03 13:05 - 2010-01-16 17:13 - 00000000 ___RD () C:\Documents and Settings\Kasia\Moje dokumenty\Moje obrazy 2014-06-03 13:05 - 2010-01-16 17:13 - 00000000 ___RD () C:\Documents and Settings\Kasia\Moje dokumenty\Moja muzyka 2014-06-03 13:05 - 2010-01-16 17:13 - 00000000 ___RD () C:\Documents and Settings\Kasia\Menu Start\Programy\Akcesoria 2014-06-03 13:05 - 2010-01-16 17:13 - 00000000 ___RD () C:\Documents and Settings\Kasia\Menu Start\Programy 2014-06-03 13:04 - 2014-06-03 13:04 - 00000000 __SHD () C:\Documents and Settings\Kasia\IETldCache 2014-06-03 13:04 - 2014-06-03 13:04 - 00000000 ____D () C:\Program Files\xerox 2014-06-03 13:04 - 2014-06-03 13:04 - 00000000 ____D () C:\Program Files\windows nt 2014-06-03 13:04 - 2014-06-03 13:04 - 00000000 ____D () C:\Program Files\msn gaming zone 2014-06-03 13:04 - 2014-06-03 13:04 - 00000000 ____D () C:\Program Files\movie maker 2014-06-03 13:04 - 2014-06-03 13:04 - 00000000 ____D () C:\Program Files\microsoft frontpage 2014-06-03 13:04 - 2010-01-16 17:11 - 00000000 ____D () C:\Documents and Settings\LocalService\Ustawienia lokalne\Temp 2014-06-03 13:02 - 2014-06-03 13:02 - 00000000 ___DC () C:\TDSSKiller_Quarantine 2014-06-03 13:02 - 2014-01-23 23:14 - 00000188 __SHC () C:\Documents and Settings\Administrator\ntuser.ini 2014-06-03 12:55 - 2014-06-01 00:53 - 00000000 __SHD () C:\WINDOWS\CSC 2014-06-02 01:04 - 2014-01-23 23:14 - 00000000 ___DC () C:\Documents and Settings\Administrator\Pulpit 2014-06-01 22:39 - 2014-06-01 22:39 - 01347418 ____C () C:\Documents and Settings\Administrator\Pulpit\wyniki Norton antywirusa.txt 2014-06-01 20:22 - 2014-01-23 23:14 - 00000000 _RHDC () C:\Documents and Settings\Administrator\Dane aplikacji 2014-06-01 20:22 - 2014-01-23 23:14 - 00000000 __HDC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji 2014-06-01 18:14 - 2014-06-01 18:14 - 00142936 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 2014-06-01 18:14 - 2014-06-01 18:14 - 00008194 _____ () C:\WINDOWS\system32\Drivers\SYMEVENT.CAT 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\Program Files\Symantec 2014-06-01 18:14 - 2014-06-01 18:14 - 00000000 ____D () C:\Program Files\Norton Identity Safe 2014-06-01 18:13 - 2014-06-01 18:13 - 00001885 _____ () C:\Documents and Settings\All Users\Pulpit\Norton AntiVirus.LNK 2014-06-01 18:13 - 2014-06-01 18:12 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Norton AntiVirus 2014-06-01 18:13 - 2010-01-16 16:19 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2014-06-01 18:12 - 2014-06-01 18:12 - 00000000 ____D () C:\WINDOWS\system32\Drivers\NAV 2014-06-01 18:12 - 2014-06-01 18:12 - 00000000 ____D () C:\Program Files\Norton AntiVirus 2014-06-01 18:03 - 2014-06-01 18:03 - 294185016 ____C (Symantec Corporation) C:\Documents and Settings\Administrator\Moje dokumenty\NAV-ESD-21.3.0-PL.exe 2014-06-01 18:03 - 2014-01-23 23:14 - 00000000 ___DC () C:\Documents and Settings\Administrator\Moje dokumenty 2014-06-01 17:21 - 2014-06-01 17:21 - 123790440 ____C (Copyright © 2012 TrustPort, a.s. ) C:\Documents and Settings\Administrator\Moje dokumenty\TrustPort_USB_Antivirus_14.0.3.5256.exe 2014-06-01 17:18 - 2014-06-01 17:18 - 00000176 ____C () C:\Documents and Settings\Administrator\avgrep.txt 2014-06-01 17:18 - 2014-01-23 23:14 - 00000000 ___DC () C:\Documents and Settings\Administrator 2014-06-01 16:57 - 2014-06-01 16:57 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\TuneUp Software 2014-06-01 16:47 - 2014-06-01 16:47 - 04487240 ____C (AVG Technologies) C:\Documents and Settings\Administrator\Moje dokumenty\avg_avct_stb_all_2014_4592.exe 2014-06-01 16:31 - 2014-06-01 16:31 - 00000667 _____ () C:\Documents and Settings\Administrator\Pulpit\Skrót do iexplore.lnk 2014-06-01 16:31 - 2014-06-01 16:31 - 00000000 _SHDC () C:\Documents and Settings\Administrator\PrivacIE 2014-06-01 16:31 - 2014-01-23 23:14 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ulubione 2014-06-01 16:30 - 2014-06-01 16:30 - 00000000 _SHDC () C:\Documents and Settings\Administrator\IETldCache 2014-06-01 16:29 - 2010-01-16 16:09 - 00000000 ____D () C:\WINDOWS\system32\pl-pl 2014-06-01 16:29 - 2010-01-16 16:09 - 00000000 ____D () C:\WINDOWS\Help 2014-06-01 16:28 - 2014-06-01 16:26 - 00065536 _____ () C:\WINDOWS\system32\config\Internet.evt 2014-06-01 16:27 - 2014-06-01 16:23 - 00038563 _____ () C:\WINDOWS\ie8_main.log 2014-06-01 16:26 - 2014-06-01 16:24 - 00071482 _____ () C:\WINDOWS\ie8.log 2014-06-01 16:26 - 2014-06-01 16:24 - 00000000 ___HD () C:\WINDOWS\msdownld.tmp 2014-06-01 16:26 - 2010-01-20 02:24 - 00049847 ____C () C:\WINDOWS\updspapi.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00522164 ____C () C:\WINDOWS\iis6.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00435905 ____C () C:\WINDOWS\FaxSetup.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00226996 ____C () C:\WINDOWS\ocgen.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00208882 ____C () C:\WINDOWS\tsoc.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00157599 ____C () C:\WINDOWS\comsetup.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00147382 ____C () C:\WINDOWS\msmqinst.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00094897 ____C () C:\WINDOWS\ntdtcsetup.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00077728 ____C () C:\WINDOWS\netfxocm.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00031316 ____C () C:\WINDOWS\MedCtrOC.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00027575 ____C () C:\WINDOWS\ocmsn.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00022952 ____C () C:\WINDOWS\tabletoc.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00022481 ____C () C:\WINDOWS\msgsocm.log 2014-06-01 16:26 - 2010-01-16 16:19 - 00001355 _____ () C:\WINDOWS\imsins.log 2014-06-01 16:25 - 2014-06-01 16:24 - 00000000 __HDC () C:\WINDOWS\ie8 2014-06-01 16:25 - 2010-01-16 16:09 - 00000000 ____D () C:\WINDOWS\Media 2014-06-01 14:46 - 2014-06-01 14:38 - 00000000 ___DC () C:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie 2014-06-01 14:26 - 2014-06-01 14:26 - 00021920 ____C () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2014-06-01 14:22 - 2014-01-23 23:14 - 00000000 __HDC () C:\Documents and Settings\Administrator\Ustawienia lokalne 2014-06-01 14:20 - 2014-06-01 14:20 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Adobe 2014-06-01 14:20 - 2014-06-01 14:20 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\Adobe 2014-06-01 14:15 - 2014-06-01 14:15 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\ipla 2014-06-01 14:15 - 2014-05-22 19:02 - 00000000 ____D () C:\Program Files\GameforgeLive 2014-06-01 14:15 - 2010-01-16 16:19 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start 2014-06-01 14:11 - 2010-01-16 16:19 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy\Autostart 2014-06-01 14:10 - 2012-05-01 15:20 - 00000000 ____D () C:\WINDOWS\system32\appmgmt 2014-06-01 13:37 - 2014-06-01 13:37 - 00000000 ___DC () C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Mozilla 2014-06-01 13:37 - 2014-06-01 13:37 - 00000000 ___DC () C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla 2014-06-01 08:10 - 2014-06-01 08:10 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\Package Cache 2014-06-01 08:10 - 2014-06-01 08:10 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard 2014-06-01 02:11 - 2014-06-01 02:11 - 299454696 _____ (Arcabit Ltd.) C:\Documents and Settings\Kasia\Moje dokumenty\ArcabitSetup_av_demo.exe 2014-06-01 01:44 - 2014-06-01 01:44 - 08165432 _____ (NETGATE Technologies s.r.o. ) C:\Documents and Settings\Kasia\Moje dokumenty\aa-setup-ngt.exe 2014-06-01 01:40 - 2014-06-01 01:39 - 00015219 _____ () C:\WINDOWS\KB942288-v3.log 2014-06-01 01:40 - 2014-06-01 01:39 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB942288-v3$ 2014-06-01 01:40 - 2010-01-16 16:19 - 00001355 _____ () C:\WINDOWS\imsins.BAK 2014-06-01 01:37 - 2014-06-01 01:37 - 01724552 _____ () C:\Documents and Settings\Kasia\Moje dokumenty\Adaware_Installer.exe 2014-06-01 01:30 - 2014-06-01 01:30 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-06-01 01:30 - 2014-06-01 01:30 - 00000000 ____D () C:\Program Files\Adobe 2014-06-01 01:30 - 2014-05-31 19:46 - 00000000 ____D () C:\Documents and Settings\Kasia\Ustawienia lokalne\Dane aplikacji\Adobe 2014-06-01 01:30 - 2010-01-20 01:37 - 00000000 ___DC () C:\Documents and Settings\All Users\Dane aplikacji\Adobe 2014-06-01 01:19 - 2010-01-16 15:35 - 00000000 __SHD () C:\Documents and Settings\NetworkService 2014-06-01 01:19 - 2010-01-16 15:27 - 00000000 ____D () C:\WINDOWS\Registration 2014-05-31 19:56 - 2014-05-31 19:56 - 17938608 _____ (Adobe Systems Incorporated) C:\Documents and Settings\Kasia\Moje dokumenty\install_flash_player.exe 2014-05-31 16:25 - 2014-05-23 18:32 - 00000000 _____ () C:\WINDOWS\system32\s.o 2014-05-31 16:25 - 2012-08-14 23:17 - 00000000 ____D () C:\Documents and Settings\Kasia\Dane aplikacji\Skype 2014-05-29 12:57 - 2014-03-19 23:56 - 00000800 _____ () C:\Documents and Settings\Kasia\Pulpit\Skrót do MinecraftSP.lnk 2014-05-28 19:05 - 2014-05-28 19:05 - 00000000 ____D () C:\Documents and Settings\Kasia\Pulpit\magda 2014-05-25 21:09 - 2014-05-22 19:03 - 00000000 ____D () C:\Documents and Settings\Kasia\Moje dokumenty\Gameforge Live 2014-05-22 19:09 - 2014-05-22 19:09 - 00000000 ____D () C:\Documents and Settings\Kasia\Pulpit\warcraft 2014-05-22 19:03 - 2014-05-22 19:03 - 00000000 ____D () C:\Documents and Settings\Kasia\Ustawienia lokalne\Dane aplikacji\Gameforge4d 2014-05-21 21:44 - 2014-01-22 23:16 - 00000000 ____D () C:\Documents and Settings\Kasia\Moje dokumenty\OpenTTD 2014-05-21 16:00 - 2010-06-13 18:53 - 00000664 _____ () C:\WINDOWS\system32\d3d9caps.dat 2014-05-17 20:21 - 2014-05-17 20:19 - 00000000 ____D () C:\Documents and Settings\Kasia\Pulpit\SETTLER II + dodatek Nowe misje (PL) 2014-05-15 23:58 - 2014-01-16 15:29 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service Some content of TEMP: ==================== C:\Documents and Settings\Kasia\Ustawienia lokalne\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\WINDOWS\explorer.exe [2008-04-15 14:00] - [2008-04-15 14:00] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\WINDOWS\system32\winlogon.exe [2008-04-15 14:00] - [2008-04-15 14:00] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\WINDOWS\system32\svchost.exe [2008-04-15 14:00] - [2008-04-15 14:00] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\WINDOWS\system32\services.exe [2008-04-15 14:00] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f C:\WINDOWS\system32\User32.dll [2008-04-15 14:00] - [2008-04-15 14:00] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\WINDOWS\system32\userinit.exe [2008-04-15 14:00] - [2008-04-15 14:00] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\WINDOWS\system32\rpcss.dll [2008-04-15 14:00] - [2009-02-09 12:53] - 0401408 ____A (Microsoft Corporation) a37311d9d628c1042a2836731787f0f3 ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected. C:\WINDOWS\system32\Drivers\volsnap.sys [2008-04-15 14:00] - [2008-04-15 14:00] - 0052864 ___AC (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================