Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-01-2015 Ran by Grześ i Paula (administrator) on GRZEŚIPAULA-PC on 22-01-2015 19:16:03 Running from C:\Users\Grześ i Paula\Downloads Loaded Profiles: Grześ i Paula (Available profiles: Grześ i Paula) Platform: Microsoft® Windows Vista™ Home Basic Service Pack 1 (X86) OS Language: Polski (Polska) Internet Explorer Version 7 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgcsrvx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE (Agere Systems) C:\Windows\System32\agrsmsvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe (Absolute Software Corp.) C:\Windows\System32\rpcnet.exe (Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (PDF Complete Inc) C:\Program Files\PDF Complete\pdfsty.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgnsx.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgemcx.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgui.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe () C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1183744 2007-02-21] (Analog Devices, Inc.) HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-04-18] (Intel Corporation) HKLM\...\Run: [PDF Complete] => C:\Program Files\PDF Complete\pdfsty.exe [331552 2007-05-08] (PDF Complete Inc) HKLM\...\Run: [PTHOSTTR] => C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [145184 2007-01-09] (Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1045800 2008-03-27] (Synaptics, Inc.) HKLM\...\Run: [hpWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [488752 2008-04-15] (Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [HP Health Check Scheduler] => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [70912 2008-04-15] (Hewlett-Packard) HKLM\...\Run: [WatchDog] => C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [197904 2008-04-21] (InterVideo Inc.) HKLM\...\Run: [QlbCtrl] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [177456 2007-11-07] ( Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [HP Software Update] => c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49152 2005-02-17] (Hewlett-Packard Co.) HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3667472 2014-12-18] (AVG Technologies CZ, s.r.o.) Winlogon\Notify\DeviceNP: C:\windows\system32\DeviceNP.dll (Hewlett-Packard Limited) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-3955943541-4005116618-4156945744-1004\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2289664 2008-03-18] (Hewlett-Packard Company) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DVD Check.lnk ShortcutTarget: DVD Check.lnk -> C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-3955943541-4005116618-4156945744-1004\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.firefox.pl/ Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Grześ i Paula\AppData\Roaming\Mozilla\Firefox\Profiles\7q6x7umr.default-1421949709805 FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll () FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) Chrome: ======= ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3432976 2014-12-18] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [298080 2014-12-18] (AVG Technologies CZ, s.r.o.) S3 Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [110592 2007-03-05] (Hewlett-Packard Development Company, L.P.) [File not signed] S3 FLCDLOCK; C:\Windows\system32\flcdlock.exe [172131 2007-06-08] (Hewlett-Packard Ltd) [File not signed] R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-04-15] (Hewlett-Packard) [File not signed] S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed] R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2008-03-18] (Hewlett-Packard Company) [File not signed] R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-09] (Hewlett-Packard) [File not signed] R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [540448 2007-05-08] (PDF Complete Inc) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-09] (Hewlett-Packard) [File not signed] R2 rpcnet; C:\windows\system32\rpcnet.exe [69792 2014-11-12] (Absolute Software Corp.) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiskx; C:\windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-18] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\windows\System32\DRIVERS\avgidsdriverx.sys [208152 2014-12-08] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\windows\System32\DRIVERS\avgidshx.sys [154904 2014-11-18] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-18] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\windows\System32\DRIVERS\avgldx86.sys [192792 2014-08-28] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\windows\System32\DRIVERS\avglogx.sys [230680 2014-07-18] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\windows\System32\DRIVERS\avgmfx86.sys [98584 2014-10-05] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-18] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\windows\System32\DRIVERS\avgtdix.sys [200984 2014-10-10] (AVG Technologies CZ, s.r.o.) S3 DAMDrv; C:\windows\System32\DRIVERS\DAMDrv.sys [30008 2007-06-08] (Hewlett-Packard Development Company L.P.) [File not signed] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ========================== Drivers MD5 ======================= C:\windows\System32\drivers\acpi.sys FCB8C7210F0135E24C6580F7F649C73C C:\windows\System32\drivers\ADIHdAud.sys FB9ECE3F7B8A03E474E611031AD4CD23 C:\windows\system32\drivers\adp94xx.sys 04F0FCAC69C7C71A3AC4EB97FAFC8303 C:\windows\system32\drivers\adpahci.sys 60505E0041F7751BDBB80F88BF45C2CE C:\windows\system32\drivers\adpu160m.sys 8A42779B02AEC986EAB64ECFC98F8BD7 C:\windows\system32\drivers\adpu320.sys 241C9E37F8CE45EF51C3DE27515CA4E5 C:\windows\system32\drivers\afd.sys 763E172A55177E478CB419F88FD0BA03 C:\windows\System32\DRIVERS\AGRSM.sys 38325C6AA8EAE011897D61CE48EC6435 C:\windows\system32\drivers\agp440.sys 13F9E33747E6B41A3FF305C37DB0D360 C:\windows\system32\drivers\djsvs.sys ==> MD5 is legit C:\windows\system32\drivers\aliide.sys 9EAEF5FC9B8E351AFA7E78A6FAE91F91 C:\windows\system32\drivers\amdagp.sys C47344BC706E5F0B9DCE369516661578 C:\windows\system32\drivers\amdide.sys 9B78A39A4C173FDBC1321E0DD659B34C C:\windows\system32\drivers\amdk7.sys 18F29B49AD23ECEE3D2A826C725C8D48 C:\windows\System32\DRIVERS\amdk8.sys 93AE7F7DD54AB986A6F1A1B37BE7442D C:\windows\system32\drivers\arc.sys 5D2888182FB46632511ACEE92FDAD522 C:\windows\system32\drivers\arcsas.sys 5E2A321BD7C8B3624E41FDEC3E244945 C:\windows\System32\DRIVERS\asyncmac.sys 53B202ABEE6455406254444303E87BE1 C:\windows\System32\drivers\atapi.sys 2D9C903DC76A66813D350A562DE40ED9 C:\windows\System32\DRIVERS\avgdiskx.sys CB2C2B24BD7E64CFB2B24D401FF5BBC0 C:\windows\System32\DRIVERS\avgidsdriverx.sys EB1AA821F99D5D2DA05511AE8D4704C4 C:\windows\System32\DRIVERS\avgidshx.sys D1663A0114691080C624D857A8343D5B C:\windows\System32\DRIVERS\avgidsshimx.sys 2429F7F025F63532B6B264D97E4ECA49 C:\windows\System32\DRIVERS\avgldx86.sys 9AFD535116E986D49877B811F3665E8E C:\windows\System32\DRIVERS\avglogx.sys D94378757947E02AE9BC484DF196A44D C:\windows\System32\DRIVERS\avgmfx86.sys 35DD83C14AA01F4817BA46A4D6B6A520 C:\windows\System32\DRIVERS\avgrkx86.sys F016B95273E0B1961F204F7FD2FFD811 C:\windows\System32\DRIVERS\avgtdix.sys 5A22A7A67BFB67D3223B7A339FC97780 C:\windows\System32\DRIVERS\b57nd60x.sys 502F1C30BD50B32D00CE4DCAECC3D3C7 C:\windows\System32\DRIVERS\bcmwl6.sys 3F5E7621CDF6867D3D8417D13A098277 C:\windows\system32\Drivers\Beep.sys 67E506B75BD5326A3EC7B70BD014DFB6 C:\windows\system32\drivers\blbdrive.sys D4DF28447741FD3D953526E33A617397 C:\windows\System32\DRIVERS\bowser.sys 74B442B2BE1260B7588C136177CEAC66 C:\windows\system32\drivers\brfiltlo.sys ==> MD5 is legit C:\windows\system32\drivers\brfiltup.sys ==> MD5 is legit C:\windows\system32\drivers\brserid.sys ==> MD5 is legit C:\windows\system32\drivers\brserwdm.sys ==> MD5 is legit C:\windows\system32\drivers\brusbmdm.sys ==> MD5 is legit C:\windows\system32\drivers\brusbser.sys ==> MD5 is legit C:\windows\System32\DRIVERS\BthEnum.sys DA7B195275BDA7F8FCF79B40E0F45DDE C:\windows\system32\drivers\bthmodem.sys ==> MD5 is legit C:\windows\System32\DRIVERS\bthpan.sys 5904EFA25F829BF84EA6FB045134A1D8 C:\windows\System32\Drivers\BTHport.sys 671134053D59E23704F08DB19F11E10B C:\windows\System32\Drivers\BTHUSB.sys 93D7007E2C660DFCCA6AE72622740B14 C:\windows\System32\DRIVERS\cdfs.sys 7ADD03E75BEB9E6DD102C3081D29840A C:\windows\System32\DRIVERS\cdrom.sys 1EC25CEA0DE6AC4718BF89F9E1778B57 C:\windows\system32\drivers\circlass.sys E5D4133F37219DBCFE102BC61072589D C:\windows\System32\CLFS.sys 465745561C832B29F7C48B488AAB3842 C:\windows\System32\DRIVERS\CmBatt.sys 99AFC3795B58CC478FBBBCDC658FCB56 C:\windows\system32\drivers\cmdide.sys 0CA25E686A4928484E9FDABD168AB629 C:\windows\System32\DRIVERS\compbatt.sys 6AFEF0B60FA25DE07C0968983EE4F60A C:\windows\System32\drivers\crcdisk.sys 741E9DFF4F42D2D8477D0FC1DC0DF871 C:\windows\system32\drivers\crusoe.sys 1F07BECDCA750766A96CDA811BA86410 C:\windows\System32\DRIVERS\DAMDrv.sys 5D5984255A4BFAA4262FB750DF7CD537 C:\windows\System32\Drivers\dfsc.sys 9E635AE5E8AD93E2B5989E2E23679F97 C:\windows\System32\drivers\disk.sys 64109E623ABD6955C8FB110B592E68B7 C:\windows\System32\drivers\drmkaud.sys 97FEF831AB90BEE128C9AF390E243F80 C:\windows\System32\drivers\dxgkrnl.sys F8BF50A8D862F8CC089080BEC509BCA6 C:\windows\System32\DRIVERS\e1e6032.sys 9636E42B3114B66CE6EDFB34B9D8E81B C:\windows\System32\DRIVERS\E1G60I32.sys 5425F74AC0C1DBD96A1E04F17D63F94C C:\windows\System32\drivers\ecache.sys DD2CD259D83D8B72C02C5F2331FF9D68 C:\windows\system32\drivers\elxstor.sys 23B62471681A124889978F6295B3F4C6 C:\windows\system32\drivers\errdev.sys 3DB974F3935483555D7148663F726C61 C:\windows\system32\Drivers\exfat.sys 0D858EB20589A34EFB25695ACAA6AA2D C:\windows\system32\Drivers\fastfat.sys 3C489390C2E2064563727752AF8EAB9E C:\windows\System32\DRIVERS\fdc.sys AFE1E8B9782A0DD7FB46BBD88E43F89A C:\windows\System32\drivers\fileinfo.sys A8C0139A884861E3AAE9CFE73B208A9F C:\windows\System32\drivers\filetrace.sys 0AE429A696AECBC5970E3CF2C62635AE C:\windows\System32\DRIVERS\flpydisk.sys 85B7CF99D532820495D68D747FDA9EBD C:\windows\System32\drivers\fltmgr.sys 05EA53AFE985443011E36DAB07343B46 C:\windows\system32\Drivers\Fs_Rec.sys 65EA8B77B5851854F0C55C43FA51A198 C:\windows\system32\drivers\gagp30kx.sys 34582A6E6573D54A07ECE5FE24A126B5 C:\windows\System32\DRIVERS\cpqbttn.sys DE15777902A5D9121857D155873A1D1B C:\windows\System32\drivers\HdAudio.sys ==> MD5 is legit C:\windows\System32\DRIVERS\HDAudBus.sys C87B1EE051C0464491C1A7B03FA0BC99 C:\windows\system32\drivers\hidbth.sys ==> MD5 is legit C:\windows\system32\drivers\hidir.sys ==> MD5 is legit C:\windows\System32\DRIVERS\hidusb.sys 854CA287AB7FAF949617A788306D967E C:\windows\system32\drivers\hpcisss.sys 16EE7B23A009E00D835CDB79574A91A6 C:\windows\System32\DRIVERS\HpqKbFiltr.sys 35956140E686D53BF676CF0C778880FC C:\windows\System32\drivers\HTTP.sys 406C027C18E98A396FAA1963DAD5FF70 C:\windows\system32\drivers\i2omp.sys C6B032D69650985468160FC9937CF5B4 C:\windows\System32\DRIVERS\i8042prt.sys 22D56C8184586B7A1F6FA60BE5F5A2BD C:\windows\System32\drivers\iastor.sys DB0CC620B27A928D968C1A1E9CD9CB87 C:\windows\system32\drivers\iastorv.sys 54155EA1B0DF185878E0FC9EC3AC3A14 C:\windows\System32\DRIVERS\igdkmd32.sys 9378D57E2B96C0A185D844770AD49948 C:\windows\system32\drivers\iirsp.sys ==> MD5 is legit C:\windows\system32\drivers\intelide.sys 83AA759F3189E6370C30DE5DC5590718 C:\windows\System32\DRIVERS\intelppm.sys 224191001E78C89DFA78924C3EA595FF C:\windows\System32\DRIVERS\ipfltdrv.sys 62C265C38769B864CB25B4BCF62DF6C3 C:\windows\system32\drivers\ipmidrv.sys B25AAF203552B7B3491139D582B39AD1 C:\windows\System32\DRIVERS\ipnat.sys 8793643A67B42CEC66490B2A0CF92D68 C:\windows\System32\drivers\irenum.sys 109C0DFB82C3632FBD11949B73AEEAC9 C:\windows\system32\drivers\isapnp.sys 6C70698A3E5C4376C6AB5C7C17FB0614 C:\windows\System32\DRIVERS\msiscsi.sys F247EEC28317F6C739C16DE420097301 C:\windows\system32\drivers\iteatapi.sys ==> MD5 is legit C:\windows\system32\drivers\iteraid.sys ==> MD5 is legit C:\windows\System32\DRIVERS\kbdclass.sys 37605E0A8CF00CBBA538E753E4344C6E C:\windows\System32\DRIVERS\kbdhid.sys 18247836959BA67E3511B62846B9C2E0 C:\windows\System32\Drivers\ksecdd.sys 5367DC846CAE9639B899BFD13B97A8C9 C:\windows\System32\DRIVERS\lltdio.sys D1C5883087A0C3F1344D9D55A44901F6 C:\windows\system32\drivers\lsi_fc.sys C7E15E82879BF3235B559563D4185365 C:\windows\system32\drivers\lsi_sas.sys EE01EBAE8C9BF0FA072E0FF68718920A C:\windows\system32\drivers\lsi_scsi.sys 912A04696E9CA30146A62AFA1463DD5C C:\windows\system32\drivers\luafv.sys 8F5C7426567798E62A3B3614965D62CC C:\windows\system32\drivers\megasas.sys 0001CE609D66632FA17B84705F658879 C:\windows\system32\drivers\megasr.sys C252F32CD9A49DBFC25ECF26EBD51A99 C:\windows\System32\drivers\modem.sys E13B5EA0F51BA5B1512EC671393D09BA C:\windows\System32\DRIVERS\monitor.sys 0A9BB33B56E294F686ABB7C1E4E2D8A8 C:\windows\System32\DRIVERS\mouclass.sys 5BF6A1326A335C5298477754A506D263 C:\windows\System32\DRIVERS\mouhid.sys 93B8D4869E12CFBE663915502900876F C:\windows\System32\drivers\mountmgr.sys BDAFC88AA6B92F7842416EA6A48E1600 C:\windows\system32\drivers\mpio.sys 511D011289755DD9F9A7579FB0B064E6 C:\windows\System32\drivers\mpsdrv.sys 22241FEBA9B2DEFA669C8CB0A8DD7D2E C:\windows\system32\drivers\mraid35x.sys ==> MD5 is legit C:\windows\system32\drivers\mrxdav.sys AE3DE84536B6799D2267443CEC8EDBB9 C:\windows\System32\DRIVERS\mrxsmb.sys C4AD205530888404E2B5FC8D9319B119 C:\windows\System32\DRIVERS\mrxsmb10.sys 67E55CED3FC143C82A8197988BFC1F9A C:\windows\System32\DRIVERS\mrxsmb20.sys 3268B8C3FA92BFC086355C39B45E9CC9 C:\windows\system32\drivers\msahci.sys 28023E86F17001F7CD9B15A5BC9AE07D C:\windows\system32\drivers\msdsm.sys 4468B0F385A86ECDDAF8D3CA662EC0E7 C:\windows\system32\Drivers\Msfs.sys A9927F4A46B816C92F461ACB90CF8515 C:\windows\System32\drivers\msisadrv.sys 0F400E306F385C56317357D6DEA56F62 C:\windows\System32\drivers\MSKSSRV.sys D8C63D34D9C9E56C059E24EC7185CC07 C:\windows\System32\drivers\MSPCLOCK.sys 1D373C90D62DDB641D50E55B9E78D65E C:\windows\System32\drivers\MSPQM.sys B572DA05BF4E098D4BBA3A4734FB505B C:\windows\system32\Drivers\MsRPC.sys B5614AECB05A9340AA0FB55BF561CC63 C:\windows\System32\DRIVERS\mssmbios.sys E384487CB84BE41D09711C30CA79646C C:\windows\System32\drivers\MSTEE.sys 7199C1EEC1E4993CAF96B8C0A26BD58A C:\windows\System32\Drivers\mup.sys 6DFD1D322DE55B0B7DB7D21B90BEC49C C:\windows\System32\DRIVERS\nwifi.sys DD721F8635191132992E7CEAA3C43C84 C:\windows\System32\drivers\ndis.sys C8560010A542B5DCA94C62468DC20784 C:\windows\System32\DRIVERS\ndistapi.sys 0E186E90404980569FB449BA7519AE61 C:\windows\System32\DRIVERS\ndisuio.sys D6973AA34C4D5D76C0430B181C3CD389 C:\windows\System32\DRIVERS\ndiswan.sys 3D14C3B3496F88890D431E8AA022A411 C:\windows\system32\Drivers\NDProxy.sys 71DAB552B41936358F3B541AE5997FB3 C:\windows\System32\DRIVERS\netbios.sys BCD093A5A6777CF626434568DC7DBA78 C:\windows\System32\DRIVERS\netbt.sys 7C5FEE5B1C5728507CD96FB4A13E7A02 C:\windows\System32\DRIVERS\NETw5v32.sys E559EA9138C77B5D1FDA8C558764A25F C:\windows\system32\drivers\nfrd960.sys ==> MD5 is legit C:\windows\system32\Drivers\Npfs.sys ECB5003F484F9ED6C608D6D6C7886CBB C:\windows\System32\drivers\nsiproxy.sys 609773E344A97410CE4EBF74A8914FCF C:\windows\system32\Drivers\Ntfs.sys B4EFFE29EB4F15538FD8A9681108492D C:\windows\system32\drivers\ntrigdigi.sys ==> MD5 is legit C:\windows\system32\Drivers\Null.sys C5DBBCDA07D780BDA9B685DF333BB41E C:\windows\system32\drivers\nvraid.sys 2EDF9E7751554B42CBB60116DE727101 C:\windows\system32\drivers\nvstor.sys ABED0C09758D1D97DB0042DBB2688177 C:\windows\system32\drivers\nv_agp.sys 18BBDF913916B71BD54575BDB6EEAC0B C:\windows\System32\DRIVERS\ohci1394.sys 790E27C3DB53410B40FF9EF2FD10A1D9 C:\windows\System32\DRIVERS\parport.sys 8A79FDF04A73428597E2CAF9D0D67850 C:\windows\System32\drivers\partmgr.sys 3B38467E7C3DAED009DFE359E17F139F C:\windows\System32\DRIVERS\parvdm.sys 6C580025C81CAF3AE9E3617C22CAD00E C:\windows\System32\drivers\pci.sys 01B94418DEB235DFF777CC80076354B4 C:\windows\System32\DRIVERS\pciide.sys FC175F5DDAB666D7F4D17449A547626F C:\windows\system32\DRIVERS\pcmcia.sys B7C5A8769541900F6DFA6FE0C5E4D513 C:\windows\System32\drivers\peauth.sys ==> MD5 is legit C:\windows\System32\DRIVERS\raspptp.sys ECFFFAEC0C1ECD8DBC77F39070EA1DB1 C:\windows\system32\drivers\processr.sys 2027293619DD0F047C584CF2E7DF4FFD C:\windows\System32\DRIVERS\pacer.sys A114CFE308C24B8235B03CFDFFE11E99 C:\windows\System32\Drivers\PxHelp20.sys 153D02480A0A2F45785522E814C634B6 C:\windows\system32\drivers\ql2300.sys 0A6DB55AFB7820C99AA1F3A1D270F4F6 C:\windows\system32\drivers\ql40xx.sys ==> MD5 is legit C:\windows\system32\drivers\qwavedrv.sys 9F5E0E1926014D17486901C88ECA2DB7 C:\windows\System32\DRIVERS\rasacd.sys 147D7F9C556D259924351FEB0DE606C3 C:\windows\System32\DRIVERS\rasl2tp.sys A214ADBAF4CB47DD2728859EF31F26B0 C:\windows\System32\DRIVERS\raspppoe.sys 3E9D9B048107B40D87B97DF2E48E0744 C:\windows\System32\DRIVERS\rassstp.sys A7D141684E9500AC928A772ED8E6B671 C:\windows\System32\DRIVERS\rdbss.sys 6E1C5D0457622F9EE35F683110E93D14 C:\windows\System32\DRIVERS\RDPCDD.sys 89E59BE9A564262A3FB6C4F4F1CD9899 C:\windows\system32\drivers\rdpdr.sys FBC0BACD9C3D7F6956853F64A66E252D C:\windows\System32\drivers\rdpencdd.sys 9D91FE5286F748862ECFFA05F8A0710C C:\windows\system32\Drivers\RDPWD.sys E1C18F4097A5ABCEC941DC4B2F99DB7E C:\windows\System32\DRIVERS\rfcomm.sys 34CC78C06587718C2AD6D3AA83B1F072 C:\windows\System32\DRIVERS\rspndr.sys 9C508F4074A39E8B4B31D27198146FAD C:\windows\system32\drivers\sbp2port.sys ==> MD5 is legit C:\windows\system32\Drivers\secdrv.sys ==> MD5 is legit C:\windows\system32\drivers\serenum.sys ==> MD5 is legit C:\windows\system32\drivers\serial.sys ==> MD5 is legit C:\windows\system32\drivers\sermouse.sys 8AF3D28A879BF75DB53A0EE7A4289624 C:\windows\system32\drivers\sffdisk.sys 3EFA810BDCA87F6ECC24F9832243FE86 C:\windows\system32\drivers\sffp_mmc.sys E95D451F7EA3E583AEC75F3B3EE42DC5 C:\windows\system32\drivers\sffp_sd.sys 3D0EA348784B7AC9EA9BD9F317980979 C:\windows\system32\drivers\sfloppy.sys ==> MD5 is legit C:\windows\system32\drivers\sisagp.sys 1D76624A09A054F682D746B924E2DBC3 C:\windows\system32\drivers\sisraid2.sys 43CB7AA756C7DB280D01DA9B676CFDE2 C:\windows\system32\drivers\sisraid4.sys A99C6C8B0BAA970D8AA59DDC50B57F94 C:\windows\System32\DRIVERS\smb.sys 031E6BCD53C9B2B9ACE111EAFEC347B6 C:\windows\system32\Drivers\spldr.sys 7AEBDEEF071FE28B0EEF2CDD69102BFF C:\windows\System32\DRIVERS\srv.sys 3D7C04ABA41AC96BA7E9D123EC8F7FA3 C:\windows\System32\DRIVERS\srv2.sys 805FAC010405AD3F82EF8DF0BB035D81 C:\windows\System32\DRIVERS\srvnet.sys F63A0A58AAFE34D7A1A0A74ABCCDD9C0 C:\windows\System32\DRIVERS\swenum.sys 7BA58ECF0C0A9A69D44B3DCA62BECF56 C:\windows\system32\drivers\symc8xx.sys ==> MD5 is legit C:\windows\system32\drivers\sym_hi.sys ==> MD5 is legit C:\windows\system32\drivers\sym_u3.sys ==> MD5 is legit C:\windows\System32\DRIVERS\SynTP.sys F5D926807BD9BC0AF68F9376144DE425 C:\windows\System32\drivers\tcpip.sys FC6E2835D667774D409C7C7021EAF9C4 C:\windows\System32\DRIVERS\tcpip.sys FC6E2835D667774D409C7C7021EAF9C4 C:\windows\System32\drivers\tcpipreg.sys D4A2E4A4B011F3A883AF77315A5AE76B C:\windows\System32\drivers\tdpipe.sys 5DCF5E267BE67A1AE926F2DF77FBCC56 C:\windows\System32\drivers\tdtcp.sys 389C63E32B3CEFED425B61ED92D3F021 C:\windows\System32\DRIVERS\tdx.sys D09276B1FAB033CE1D40DCBDF303D10F C:\windows\System32\DRIVERS\termdd.sys A048056F5E1A96A9BF3071B91741A5AA C:\windows\System32\drivers\tpm.sys CB258C2F726F1BE73C507022BE33EBB3 C:\windows\System32\DRIVERS\tssecsrv.sys DCF0F056A2E4F52287264F5AB29CF206 C:\windows\System32\DRIVERS\tunmp.sys CAECC0120AC49E3D2F758B9169872D38 C:\windows\System32\DRIVERS\tunnel.sys 119B8184E106BAEDC83FCE5DDF3950DA C:\windows\system32\drivers\uagp35.sys 7D33C4DB2CE363C8518D2DFCF533941F C:\windows\System32\DRIVERS\udfs.sys 8B5088058FA1D1CD897A2113CCFF6C58 C:\windows\system32\drivers\uliagpkx.sys B0ACFDC9E4AF279E9116C03E014B2B27 C:\windows\system32\drivers\uliahci.sys 9224BB254F591DE4CA8D572A5F0D635C C:\windows\system32\drivers\ulsata.sys ==> MD5 is legit C:\windows\system32\drivers\ulsata2.sys ==> MD5 is legit C:\windows\System32\DRIVERS\umbus.sys 32CFF9F809AE9AED85464492BF3E32D2 C:\windows\System32\DRIVERS\usbccgp.sys CAF811AE4C147FFCD5B51750C7F09142 C:\windows\system32\drivers\usbcir.sys ==> MD5 is legit C:\windows\System32\DRIVERS\usbehci.sys CEBE90821810E76320155BEBA722FCF9 C:\windows\System32\DRIVERS\usbhub.sys CC6B28E4CE39951357963119CE47B143 C:\windows\System32\DRIVERS\usbohci.sys 7BDB7B0E7D45AC0402D78B90789EF47C C:\windows\system32\drivers\usbprint.sys ==> MD5 is legit C:\windows\System32\DRIVERS\USBSTOR.SYS 87BA6B83C5D19B69160968D07D6E2982 C:\windows\System32\DRIVERS\usbuhci.sys 814D653EFC4D48BE3B04A307ECEFF56F C:\windows\System32\DRIVERS\vgapnp.sys 87B06E1F30B749A114F74622D013F8D4 C:\windows\System32\drivers\vga.sys 2E93AC0A1D8C79D019DB6C51F036636C C:\windows\system32\drivers\viaagp.sys 5D7159DEF58A800D5781BA3A879627BC C:\windows\system32\drivers\viac7.sys C4F3A691B5BAD343E6249BD8C2D45DEE C:\windows\system32\drivers\viaide.sys AADF5587A4063F52C2C3FED7887426FC C:\windows\System32\drivers\volmgr.sys 69503668AC66C77C6CD7AF86FBDF8C43 C:\windows\System32\drivers\volmgrx.sys 98F5FFE6316BD74E9E2C97206C190196 C:\windows\System32\drivers\volsnap.sys D8B4A53DD2769F226B3EB374374987C9 C:\windows\system32\drivers\vsmraid.sys 587253E09325E6BF226B299774B728A9 C:\windows\system32\drivers\wacompen.sys ==> MD5 is legit C:\windows\System32\DRIVERS\wanarp.sys 55201897378CCA7AF8B5EFD874374A26 C:\windows\System32\DRIVERS\wanarp.sys 55201897378CCA7AF8B5EFD874374A26 C:\windows\system32\drivers\wd.sys 78FE9542363F297B18C027B2D7E7C07F C:\windows\System32\drivers\Wdf01000.sys B6F0A7AD6D4BD325FBCD8BAC96CD8D96 C:\windows\System32\DRIVERS\wmiacpi.sys 2E7255D172DF0B8283CDFB7B433B864E C:\windows\System32\DRIVERS\wpdusb.sys 0CEC23084B51B8288099EB710224E955 C:\windows\system32\drivers\ws2ifsl.sys E3A3CB253C0EC2494D4A61F5E43A389C C:\windows\System32\DRIVERS\WUDFRd.sys AC13CB789D93412106B0FB6C7EB2BCB6 ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-22 19:01 - 2015-01-22 19:01 - 00000000 ____D () C:\Users\Grześ i Paula\Desktop\Stare dane programu Firefox 2015-01-22 18:54 - 2015-01-22 18:54 - 00000020 ___SH () C:\Users\Grześ i Paula\ntuser.ini 2015-01-21 11:41 - 2015-01-21 11:41 - 00380416 _____ () C:\Users\Grześ i Paula\Downloads\9ciiqhtd.exe 2015-01-21 11:28 - 2015-01-21 11:28 - 00024922 _____ () C:\Users\Grześ i Paula\Downloads\Shortcut.txt 2015-01-21 11:25 - 2015-01-22 19:16 - 00027532 _____ () C:\Users\Grześ i Paula\Downloads\FRST.txt 2015-01-21 11:25 - 2015-01-21 11:28 - 00016649 _____ () C:\Users\Grześ i Paula\Downloads\Addition.txt 2015-01-21 11:24 - 2015-01-22 19:16 - 00000000 ____D () C:\FRST 2015-01-21 11:24 - 2015-01-21 11:24 - 01118208 _____ (Farbar) C:\Users\Grześ i Paula\Downloads\FRST.exe 2015-01-21 10:15 - 2015-01-21 10:15 - 00044938 _____ () C:\Users\Grześ i Paula\Downloads\OTL.Txt 2015-01-21 10:15 - 2015-01-21 10:15 - 00034726 _____ () C:\Users\Grześ i Paula\Downloads\Extras.Txt 2015-01-21 09:14 - 2015-01-21 09:14 - 00000000 ____D () C:\_OTL 2015-01-19 20:32 - 2015-01-22 18:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-01-09 19:06 - 2015-01-09 19:06 - 00000000 ____D () C:\Users\Grześ i Paula\Desktop\iphone 2015-01-04 19:02 - 2015-01-04 19:02 - 00000000 ____D () C:\Users\Grześ i Paula\AppData\Roaming\InterVideo 2014-12-25 11:42 - 2014-12-25 11:43 - 00000000 _____ () C:\Users\Grześ i Paula\AppData\Local\FnF4.txt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-22 19:14 - 2014-11-12 22:43 - 00069792 _____ (Absolute Software Corp.) C:\windows\system32\rpcnet.dll 2015-01-22 19:14 - 2014-11-12 22:37 - 00017408 _____ () C:\windows\system32\rpcnetp.exe 2015-01-22 19:14 - 2006-11-02 13:45 - 00003216 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-22 19:14 - 2006-11-02 13:45 - 00003216 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-22 19:13 - 2006-11-02 13:58 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2015-01-22 19:12 - 2014-11-11 16:49 - 00000012 _____ () C:\windows\bthservsdp.dat 2015-01-22 19:12 - 2014-11-11 16:16 - 00157322 _____ () C:\windows\WindowsUpdate.log 2015-01-22 19:12 - 2006-11-02 13:58 - 00028414 _____ () C:\windows\Tasks\SCHEDLGU.TXT 2015-01-22 18:59 - 2014-11-11 17:06 - 00000000 ____D () C:\ProgramData\MFAData 2015-01-22 18:54 - 2014-11-11 16:18 - 00000000 ____D () C:\Users\Grześ i Paula 2015-01-21 11:49 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public 2015-01-21 09:03 - 2006-11-02 13:44 - 00418680 _____ () C:\windows\system32\FNTCACHE.DAT 2015-01-21 09:02 - 2008-01-21 04:02 - 00009856 _____ () C:\windows\PFRO.log 2015-01-21 08:48 - 2014-11-11 16:48 - 00115312 _____ () C:\Users\Grześ i Paula\AppData\Local\GDIPFONTCACHEV1.DAT 2015-01-21 07:21 - 2014-11-11 17:10 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-01-20 20:04 - 2008-04-16 21:35 - 01497926 _____ () C:\windows\system32\PerfStringBackup.INI 2015-01-20 20:04 - 2008-04-16 21:34 - 00671722 _____ () C:\windows\system32\perfh015.dat 2015-01-20 20:04 - 2008-04-16 21:34 - 00132422 _____ () C:\windows\system32\perfc015.dat 2015-01-20 18:32 - 2014-11-11 16:48 - 00000944 _____ () C:\Users\Grześ i Paula\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2015-01-18 20:44 - 2014-11-11 17:11 - 00000000 ____D () C:\ProgramData\AVG2015 2015-01-12 18:40 - 2014-11-11 17:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2015-01-09 18:41 - 2006-11-02 13:49 - 00172292 _____ () C:\windows\setupact.log 2014-12-31 18:56 - 2014-11-12 22:37 - 00017408 _____ () C:\windows\system32\rpcnetp.dll 2014-12-27 17:06 - 2014-11-30 08:56 - 00005632 _____ () C:\Users\Grześ i Paula\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ==================== Files in the root of some directories ======= 2014-11-11 16:49 - 2014-11-11 16:49 - 0000000 _____ () C:\Users\Grześ i Paula\AppData\Local\AtStart.txt 2014-11-15 09:41 - 2014-11-15 09:41 - 0000680 _____ () C:\Users\Grześ i Paula\AppData\Local\d3d9caps.dat 2014-11-30 08:56 - 2014-12-27 17:06 - 0005632 _____ () C:\Users\Grześ i Paula\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-11-11 16:49 - 2014-11-11 16:49 - 0000000 _____ () C:\Users\Grześ i Paula\AppData\Local\DSwitch.txt 2014-12-25 11:42 - 2014-12-25 11:43 - 0000000 _____ () C:\Users\Grześ i Paula\AppData\Local\FnF4.txt 2014-11-11 16:49 - 2014-11-11 16:49 - 0000000 _____ () C:\Users\Grześ i Paula\AppData\Local\QSwitch.txt ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\windows\explorer.exe => File is digitally signed C:\windows\system32\winlogon.exe => File is digitally signed C:\windows\system32\wininit.exe => File is digitally signed C:\windows\system32\svchost.exe => File is digitally signed C:\windows\system32\services.exe => File is digitally signed C:\windows\system32\User32.dll => File is digitally signed C:\windows\system32\userinit.exe => File is digitally signed C:\windows\system32\rpcss.dll => File is digitally signed C:\windows\system32\Drivers\volsnap.sys => File is digitally signed ==================== BCD ================================ Menedľer rozruchu systemu Windows --------------------------------- Identyfikator {bootmgr} device partition=C: description Windows Boot Manager locale pl-PL inherit {globalsettings} default {current} resumeobject {95820d8b-0c97-11dd-9844-0002a55e8f37} displayorder {current} toolsdisplayorder {memdiag} timeout 30 Moduˆ ˆadujĄcy rozruchu systemu Windows --------------------------------------- Identyfikator {572bcd55-ffa7-11d9-aae0-0007e994107d} device ramdisk=[D:]\sources\winre.wim,{ramdiskoptions} path \windows\system32\boot\winload.exe description Windows Recovery Environment osdevice ramdisk=[D:]\sources\winre.wim,{ramdiskoptions} systemroot \windows nx OptIn detecthal Yes winpe Yes Moduˆ ˆadujĄcy rozruchu systemu Windows --------------------------------------- Identyfikator {current} device partition=C: path \windows\system32\winload.exe description Microsoft Windows Vista locale pl-PL inherit {bootloadersettings} recoverysequence {572bcd55-ffa7-11d9-aae0-0007e994107d} recoveryenabled Yes osdevice partition=C: systemroot \windows resumeobject {95820d8b-0c97-11dd-9844-0002a55e8f37} nx OptIn Wznawianie ze stanu hibernacji ------------------------------ Identyfikator {95820d8b-0c97-11dd-9844-0002a55e8f37} device partition=C: path \windows\system32\winresume.exe description Windows Resume Application locale pl-PL inherit {resumeloadersettings} filedevice partition=C: filepath \hiberfil.sys pae Yes debugoptionenabled No Moduˆ testujĄcy pami©† systemu Windows -------------------------------------- Identyfikator {memdiag} device partition=C: path \boot\memtest.exe description Diagnostyka pami©ci systemu Windows locale pl-PL inherit {globalsettings} badmemoryaccess Yes Ustawienia usˆug EMS -------------------- Identyfikator {emssettings} bootems Yes Ustawienia debugera ------------------- Identyfikator {dbgsettings} debugtype Serial debugport 1 baudrate 115200 Uszkodzenia pami©ci RAM ----------------------- Identyfikator {badmemory} Ustawienia globalne ------------------- Identyfikator {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Ustawienia moduˆu ˆadujĄcego rozruchu ------------------------------------- Identyfikator {bootloadersettings} inherit {globalsettings} Ustawienia moduˆu ˆadujĄcego wznawiania --------------------------------------- Identyfikator {resumeloadersettings} inherit {globalsettings} Opcje instalacji urzĄdzenia Ramdisk ----------------------------------- Identyfikator {ramdiskoptions} description Ramdisk options ramdisksdidevice partition=D: ramdisksdipath \boot\boot.sdi LastRegBack: 2015-01-22 19:01 ==================== End Of Log ============================