Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-04-2015 Ran by User (administrator) on WINXP-47C0FA42D on 14-04-2015 14:15:00 Running from C:\Documents and Settings\User\Desktop\frst Loaded Profiles: User (Available profiles: User & Ania i Grześ) Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States) Internet Explorer Version 8 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel Corporation ) C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\afwServ.exe (Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (SigmaTel, Inc.) C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe () C:\Program Files\Greener Web\updateGreenerWeb.exe () C:\Program Files\Greener Web\bin\utilGreenerWeb.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe (SigmaTel, Inc.) C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Sonix) C:\WINDOWS\vsnp2uvc.exe (Creative Technology Ltd.) C:\WINDOWS\V0770Mon.exe (Sony) C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe (Nikon Corporation) C:\Program Files\Nikon\PictureProject\NkbMonitor.exe (Microsoft Corporation) C:\Program Files\Windows Desktop Search\WindowsSearch.exe (WinZip Computing, Inc.) C:\PROGRA~1\WinZip\WZQKPICK.EXE () C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe (Intel Corporation) C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SigmatelSysTrayApp] => C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [405504 2007-05-10] (SigmaTel, Inc.) HKLM\...\Run: [IntelZeroConfig] => C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [995328 2007-10-08] (Intel Corporation) HKLM\...\Run: [IntelWireless] => C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [1101824 2007-10-08] (Intel Corporation) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5512912 2015-04-09] (Avast Software s.r.o.) HKLM\...\Run: [OrderReminder] => C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [98304 2006-07-21] (Hewlett-Packard) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [fst_pl_145] => [X] HKLM\...\Run: [upfst_pl_145.exe] => C:\Documents and Settings\User\Local Settings\Application Data\fst_pl_145\upfst_pl_145.exe -runhelper HKLM\...\Run: [snp2uvc] => C:\WINDOWS\vsnp2uvc.exe [662016 2009-08-12] (Sonix) HKLM\...\Run: [V0770Mon.exe] => C:\WINDOWS\V0770Mon.exe [32884 2012-06-01] (Creative Technology Ltd.) HKU\S-1-5-21-527237240-706699826-725345543-1003\...\Run: [Sony PC Companion] => C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [466144 2014-11-27] (Sony) HKU\S-1-5-21-527237240-706699826-725345543-1003\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.) HKU\S-1-5-21-527237240-706699826-725345543-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5503768 2015-02-19] (Piriform Ltd) HKU\S-1-5-21-527237240-706699826-725345543-1003\...\MountPoints2: {90ed4f3f-8623-11e4-b085-001c231eb7f9} - E:\Startme.exe Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk ShortcutTarget: NkbMonitor.exe.lnk -> C:\Program Files\Nikon\PictureProject\NkbMonitor.exe (Nikon Corporation) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk ShortcutTarget: WinZip Quick Pick.lnk -> C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (Avast Software s.r.o.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1403270212&from=obw&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1403270212&from=obw&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX&q={searchTerms} HKU\S-1-5-21-527237240-706699826-725345543-1003\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-527237240-706699826-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-527237240-706699826-725345543-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX&q={searchTerms} SearchScopes: HKU\S-1-5-21-527237240-706699826-725345543-1003 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1419843648&from=wpm12262&uid=HitachiXHTS541680J9SA00_SB22DBKGEB7B4NEB7B4NX&q={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-04-03] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-09] (Avast Software s.r.o.) BHO: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll No File BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-04-03] (Oracle Corporation) DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1382356944921 DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} http://download.microsoft.com/download/C/9/C/C9C3D86D-84AC-4AF0-8584-842756A66467/MicrosoftDownloadManager.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation) ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\2xnp05xh.default-1428015754187 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-18] () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-04-03] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-04-03] (Oracle Corporation) FF Plugin: @Microsoft.com/DownloadManager,version=1.1 -> C:\WINDOWS\ [2015-04-03] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll No File FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation) FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\delta-homes.xml [2014-12-29] FF Extension: Adblock Plus - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\2xnp05xh.default-1428015754187\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-03] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-10-21] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-06-14] FF HKLM\...\Firefox\Extensions: [detgdp@gmail.com] - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\w4ibkb2u.default\extensions\detgdp@gmail.com Chrome: ======= CHR Profile: C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-25] CHR Extension: (Google Drive) - C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-25] CHR Extension: (YouTube) - C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-25] CHR Extension: (Google Search) - C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-25] CHR Extension: (avast! Online Security) - C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-06-25] CHR Extension: (Google Wallet) - C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-25] CHR Extension: (Gmail) - C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-25] CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx [2014-08-04] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-17] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-09] (Avast Software s.r.o.) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [107448 2015-04-09] (Avast Software s.r.o.) R2 EvtEng; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [794624 2007-10-08] (Intel Corporation) [File not signed] S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 RegSrvc; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [483328 2007-10-08] (Intel Corporation) [File not signed] R2 S24EventMonitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [1183744 2007-10-08] (Intel Corporation ) [File not signed] S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) R2 STacSV; C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\StacSV.exe [94208 2007-05-10] (SigmaTel, Inc.) R2 Update Greener Web; C:\Program Files\Greener Web\updateGreenerWeb.exe [318752 2014-06-29] () R2 Util Greener Web; C:\Program Files\Greener Web\bin\utilGreenerWeb.exe [318752 2014-06-29] () S4 WindowsMangerProtect; C:\Documents and Settings\All Users\Application Data\WindowsMangerProtect\ProtectWindowsManager.exe [473088 2014-12-26] (Fuyu LIMITED) [File not signed] R2 WLANKEEPER; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [356352 2007-10-08] (Intel Corporation) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [21361 2013-10-01] (Cisco Systems, Inc.) R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24144 2015-04-09] () R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [26096 2015-04-09] (Avast Software s.r.o.) R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [73440 2015-04-09] (Avast Software s.r.o.) R0 aswNdis; C:\WINDOWS\System32\DRIVERS\aswNdis.sys [12112 2015-03-21] (ALWIL Software) R0 aswNdis2; C:\WINDOWS\system32\Drivers\aswNdis2.sys [253728 2015-04-09] (Avast Software s.r.o.) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-04-09] (Avast Software s.r.o.) R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49904 2015-04-09] () R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [788272 2015-04-09] (Avast Software s.r.o.) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [427736 2015-04-09] (Avast Software s.r.o.) S3 aswTap; C:\WINDOWS\System32\DRIVERS\aswTap.sys [35144 2014-07-13] (The OpenVPN Project) R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-04-09] (Avast Software s.r.o.) R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208024 2015-04-09] () S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation) S0 cercsr6; C:\WINDOWS\system32\Drivers\cercsr6.sys [39904 2004-12-13] (Adaptec, Inc.) [File not signed] S3 CSRBC; C:\WINDOWS\System32\Drivers\csrbcxp.sys [31744 2007-09-04] (CSR, plc) S3 ggsomc; C:\WINDOWS\System32\DRIVERS\ggsomc.sys [26328 2014-12-17] (Sony Mobile Communications) R3 guardian2; C:\WINDOWS\System32\Drivers\oz776.sys [68696 2007-12-24] (O2Micro) R3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [211200 2007-08-03] (Conexant Systems, Inc.) R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [989952 2007-08-03] (Conexant Systems, Inc.) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation) R3 NETw4x32; C:\WINDOWS\System32\DRIVERS\NETw4x32.sys [2236032 2007-09-26] (Intel Corporation) R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation) R2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [12288 2007-08-27] (Intel Corporation) R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1222840 2007-05-10] (SigmaTel, Inc.) S3 V0770Afx; C:\WINDOWS\System32\DRIVERS\V0770Afx.sys [408320 2011-04-28] (Creative Technology Ltd.) S3 V0770Vid; C:\WINDOWS\System32\DRIVERS\V0770Vid.sys [325376 2012-06-01] (Creative Technology Ltd.) S4 IntelIde; No ImagePath S1 iSafeKrnlMon; \??\C:\Program Files\Elex-tech\YAC\iSafeKrnlMon.sys [X] U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation) U1 WS2IFSL; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-14 13:12 - 2015-04-14 14:15 - 00000000 ____D () C:\Documents and Settings\User\Desktop\frst 2015-04-14 11:37 - 2015-04-14 11:37 - 00001880 _____ () C:\WINDOWS\bitssetup.log 2015-04-09 23:02 - 2015-04-09 23:00 - 00291312 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\aswBoot.exe 2015-04-09 23:00 - 2015-04-09 23:00 - 00043112 _____ (Avast Software s.r.o.) C:\WINDOWS\avastSS.scr 2015-04-08 14:54 - 2015-04-08 14:58 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-04-08 12:27 - 2015-04-14 14:17 - 00000000 ____D () C:\FRST 2015-04-08 12:18 - 2015-04-08 12:18 - 00370943 _____ () C:\Documents and Settings\User\Desktop\gmer.zip 2015-04-06 19:25 - 2015-04-06 19:25 - 00000000 ____D () C:\Documents and Settings\Ania i Grześ\Local Settings\Application Data\Opera Software 2015-04-06 19:25 - 2015-04-06 19:25 - 00000000 ____D () C:\Documents and Settings\Ania i Grześ\Application Data\Opera Software 2015-04-03 21:49 - 2015-04-03 21:49 - 00000000 ___HD () C:\WINDOWS\PIF 2015-04-03 19:33 - 2015-04-03 19:33 - 00001521 _____ () C:\Documents and Settings\User\Local Settings\Application Data\recently-used.xbel 2015-04-03 15:49 - 2015-04-03 15:49 - 00000736 _____ () C:\Documents and Settings\All Users\Start Menu\WinZip.lnk 2015-04-03 15:49 - 2015-04-03 15:49 - 00000736 _____ () C:\Documents and Settings\All Users\Desktop\WinZip.lnk 2015-04-03 15:49 - 2015-04-03 15:49 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\WinZip 2015-04-03 13:54 - 2015-04-03 13:54 - 00000509 _____ () C:\WINDOWS\wmsetup.log 2015-04-03 11:57 - 2015-04-14 13:18 - 00000000 ____D () C:\syfy-w-komputerze 2015-04-03 01:37 - 2015-04-03 01:37 - 00000000 ____D () C:\Program Files\Common Files\Java 2015-04-03 01:37 - 2015-04-03 01:37 - 00000000 ____D () C:\Documents and Settings\User\Application Data\Oracle 2015-04-03 01:02 - 2015-04-03 01:02 - 00000000 ____D () C:\Documents and Settings\User\Desktop\Stare dane programu Firefox 2015-04-02 22:24 - 2015-04-14 13:59 - 00000004 _____ () C:\WINDOWS\system32\029B560A371F4E00AB32838EBC01B9E7 2015-04-02 21:24 - 2015-04-14 14:10 - 00001368 _____ () C:\WINDOWS\Tasks\fun4us_notification_service.job 2015-04-02 21:24 - 2015-04-14 14:09 - 00000730 _____ () C:\WINDOWS\Tasks\fun4us_updating_service.job 2015-04-02 21:24 - 2015-04-02 21:24 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Application Data\fun4us 2015-03-31 10:14 - 2015-03-31 10:14 - 00004387 _____ () C:\Documents and Settings\User\Application Data\lTW1Bf6xfjnC 2015-03-31 10:14 - 2015-03-31 10:14 - 00004387 _____ () C:\Documents and Settings\User\Application Data\i7OPoKuArNBT 2015-03-29 15:55 - 2015-04-14 13:45 - 00271360 _____ () C:\Documents and Settings\User\Desktop\backup.pst 2015-03-26 09:17 - 2015-04-14 11:48 - 00052975 _____ () C:\WINDOWS\setupapi.log 2015-03-25 20:05 - 2015-03-25 20:05 - 00000682 _____ () C:\Documents and Settings\All Users\Desktop\CCleaner.lnk 2015-03-25 20:05 - 2015-03-25 20:05 - 00000000 ____D () C:\Program Files\CCleaner 2015-03-25 20:05 - 2015-03-25 20:05 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner 2015-03-21 17:24 - 2015-03-21 17:24 - 00001689 _____ () C:\Documents and Settings\All Users\Desktop\Avast Premier.lnk 2015-03-21 17:23 - 2015-04-09 22:58 - 00253728 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswNdis2.sys 2015-03-21 17:23 - 2015-03-21 17:23 - 00012112 _____ (ALWIL Software) C:\WINDOWS\system32\Drivers\aswNdis.sys 2015-03-20 02:15 - 2015-03-20 02:15 - 00000000 ____D () C:\Documents and Settings\LocalService\Local Settings\Application Data\Google ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-14 14:19 - 2013-10-01 01:03 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Temp 2015-04-14 14:09 - 2014-06-14 16:59 - 00000364 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job 2015-04-14 14:08 - 2013-10-01 00:53 - 01577107 _____ () C:\WINDOWS\WindowsUpdate.log 2015-04-14 14:08 - 2004-08-04 12:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl 2015-04-14 14:00 - 2014-06-25 20:39 - 00001036 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-04-14 14:00 - 2014-06-23 15:54 - 00000450 _____ () C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1403531640.job 2015-04-14 14:00 - 2013-09-30 16:52 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2015-04-14 14:00 - 2013-09-30 16:52 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2015-04-14 13:59 - 2014-06-25 20:39 - 00001032 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-04-14 13:59 - 2014-06-20 15:19 - 00002152 _____ () C:\WINDOWS\Tasks\ffc1b485-31d9-46a5-a2fb-3de6a491d187-4.job 2015-04-14 13:59 - 2014-06-20 15:19 - 00001452 _____ () C:\WINDOWS\Tasks\ffc1b485-31d9-46a5-a2fb-3de6a491d187-1.job 2015-04-14 13:59 - 2013-10-01 01:01 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-04-14 13:48 - 2013-10-01 01:03 - 00000278 ___SH () C:\Documents and Settings\User\ntuser.ini 2015-04-14 13:48 - 2013-10-01 01:01 - 00032636 _____ () C:\WINDOWS\SchedLgU.Txt 2015-04-14 12:51 - 2014-06-14 17:11 - 00000930 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-04-14 12:27 - 2014-07-02 15:41 - 00007680 ___SH () C:\WINDOWS\Thumbs.db 2015-04-14 12:05 - 2014-12-01 20:07 - 00000000 ____D () C:\Program Files\Java 2015-04-14 11:59 - 2014-12-29 11:01 - 00000000 ____D () C:\Program Files\WinZipper 2015-04-14 11:52 - 2014-06-20 15:18 - 00000000 ____D () C:\Program Files\HQ-V1.4 2015-04-14 01:19 - 2015-01-19 17:47 - 00000178 ___SH () C:\Documents and Settings\Ania i Grześ\ntuser.ini 2015-04-14 01:19 - 2015-01-19 17:47 - 00000000 ____D () C:\Documents and Settings\Ania i Grześ 2015-04-13 23:08 - 2014-06-29 10:51 - 00000330 _____ () C:\WINDOWS\Tasks\bench-sys.job 2015-04-13 22:59 - 2015-01-19 17:47 - 00000000 ____D () C:\Documents and Settings\Ania i Grześ\Local Settings\Temp 2015-04-13 15:45 - 2014-06-16 14:23 - 00001088 _____ () C:\Documents and Settings\User\intlname.ols 2015-04-09 23:01 - 2014-06-14 16:59 - 00427736 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswSP.sys 2015-04-09 23:01 - 2014-06-14 16:59 - 00208024 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys 2015-04-09 23:01 - 2014-06-14 16:59 - 00073440 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2015-04-09 23:01 - 2014-06-14 16:59 - 00057888 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswTdi.sys 2015-04-09 23:01 - 2014-06-14 16:59 - 00055200 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswRdr.sys 2015-04-09 23:01 - 2014-06-14 16:59 - 00049904 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys 2015-04-09 23:01 - 2014-06-14 16:59 - 00024144 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys 2015-04-09 23:00 - 2014-06-14 16:59 - 00788272 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswSnx.sys 2015-04-09 23:00 - 2014-06-14 16:59 - 00026096 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswKbd.sys 2015-04-08 16:24 - 2014-12-29 12:14 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-04-08 15:00 - 2014-06-14 17:19 - 00000214 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job 2015-04-08 12:18 - 2014-06-20 15:15 - 00000000 ____D () C:\Documents and Settings\User\My Documents\Pobrane 2015-04-07 23:54 - 2014-06-19 11:08 - 00000000 ____D () C:\Documents and Settings\User\Desktop\Originals 2015-04-07 23:51 - 2014-12-01 14:31 - 00000000 ____D () C:\Originals 2015-04-07 20:31 - 2014-06-20 15:31 - 00000000 ____D () C:\Documents and Settings\User\Application Data\vlc 2015-04-07 18:24 - 2014-07-02 15:41 - 00012288 _____ () C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-04-03 19:33 - 2015-01-05 13:59 - 00000000 ____D () C:\Documents and Settings\User\.gimp-2.8 2015-04-03 15:46 - 2014-06-19 20:11 - 00000000 ____D () C:\Program Files\WinZip 2015-04-03 15:43 - 2014-11-13 12:46 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\WinZip 2015-04-03 01:38 - 2013-10-02 08:46 - 00778928 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2015-04-03 01:38 - 2013-10-02 08:46 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2015-04-03 01:37 - 2014-12-01 20:09 - 00146432 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2015-04-03 01:37 - 2014-12-01 20:09 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2015-04-02 13:53 - 2014-07-28 21:21 - 00000020 ____H () C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT 2015-04-02 13:53 - 2014-07-28 21:15 - 00000020 ____H () C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT 2015-04-02 13:29 - 2015-01-05 14:25 - 01245696 ___SH () C:\Documents and Settings\User\My Documents\Thumbs.db 2015-03-31 12:23 - 2013-09-30 16:49 - 00556630 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-03-29 13:23 - 2014-12-27 15:00 - 00000000 ____D () C:\Documents and Settings\User\My Documents\polaczone 2015-03-29 13:18 - 2015-01-31 22:18 - 00000000 ____D () C:\Documents and Settings\User\My Documents\Originals 2015-03-28 15:47 - 2014-07-02 15:41 - 00366592 ___SH () C:\Thumbs.db 2015-03-28 15:46 - 2014-06-19 11:05 - 00000000 ____D () C:\Documents and Settings\User\Application Data\PhotoScape 2015-03-24 12:20 - 2014-06-14 18:17 - 00000000 ____D () C:\Program Files\Opera 2015-03-20 19:48 - 2014-12-28 21:20 - 00000000 ____D () C:\Documents and Settings\User\Application Data\Skype 2015-03-18 11:27 - 2014-06-16 13:56 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Application Data\Adobe ==================== Files in the root of some directories ======= 2014-07-28 21:15 - 2014-07-28 21:15 - 0000268 ___RH () C:\Documents and Settings\User\Application Data\ColorTable 2015-03-31 10:14 - 2015-03-31 10:14 - 0004387 _____ () C:\Documents and Settings\User\Application Data\i7OPoKuArNBT 2015-03-31 10:14 - 2015-03-31 10:14 - 0004387 _____ () C:\Documents and Settings\User\Application Data\lTW1Bf6xfjnC 2014-07-02 15:41 - 2015-04-07 18:24 - 0012288 _____ () C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-04-03 19:33 - 2015-04-03 19:33 - 0001521 _____ () C:\Documents and Settings\User\Local Settings\Application Data\recently-used.xbel Some content of TEMP: ==================== C:\Documents and Settings\User\Local Settings\Temp\jre-8u31-windows-au.exe C:\Documents and Settings\User\Local Settings\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================