Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-09-2013 02 Ran by SYSTEM on MININT-MDFBMGH on 12-09-2013 10:58:13 Running from H:\ Windows 7 Ultimate (X64) OS Language: Polish Internet Explorer Version 10 Boot Mode: Recovery The current controlset is ControlSet001 [b]ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.[/b] ==================== Registry (Whitelisted) ================== HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [2839840 2010-04-07] (ESET) HKLM-x32\...\Run: [TurboV] - C:\Program Files (x86)\ASUS\TurboV\TurboV.exe [5391872 2009-05-25] () BootExecute: autocheck autochk * OODBS ==================== Services (Whitelisted) ================= S2 .EsetTrialReset; C:\Windows\reset.exe [357182 2009-03-20] () S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-28] (Advanced Micro Devices, Inc.) S2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [90112 2009-04-02] () S3 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [544768 2009-08-24] (mst software GmbH, Germany) S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [42336 2010-04-07] (ESET) S2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [810120 2010-04-07] (ESET) S2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2013-03-05] () S2 O&O Defrag; C:\Program Files\OO Software\Defrag\oodag.exe [2287360 2009-09-11] (O&O Software GmbH) S2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-08-14] () S2 PnkBstrB; C:\Windows\SysWow64\PnkBstrB.exe [280600 2013-09-09] () ==================== Drivers (Whitelisted) ==================== S2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) S2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) S1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13368 2009-04-06] () S1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13368 2009-04-06] () S3 CisUtMonitor; C:\Windows\System32\DRIVERS\CisUtMonitor.sys [33360 2012-11-01] (CrystalIdea Software) S2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [163888 2010-04-07] (ESET) S2 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [139704 2010-04-07] (ESET) S2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [169592 2010-04-07] (ESET) S3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33608 2010-04-07] (ESET) S2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50600 2010-04-07] (ESET) S3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-05-14] () S0 tdrpman258; C:\Windows\System32\DRIVERS\tdrpm258.sys [1477728 2010-08-31] (Acronis) S4 NVHDA; system32\drivers\nvhda64v.sys [x] S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-11 17:10 - 2013-09-11 17:10 - 00016384 _____ C:\Users\Marta & Mateusz\Desktop\szczegóły diagnostyki i naprawy2.txt 2013-09-11 17:09 - 2013-09-11 17:10 - 00008191 _____ C:\Users\Marta & Mateusz\Desktop\szczegóły diagnostyki i naprawy.txt 2013-09-11 17:03 - 2013-09-11 17:03 - 00000745 _____ C:\Users\Marta & Mateusz\Desktop\raport błędu.txt 2013-09-11 10:44 - 2013-09-10 10:18 - 23101440 _____ C:\Windows\system3 2013-09-03 20:35 - 2013-09-03 21:00 - 00000000 ____D C:\Users\Marta & Mateusz\Desktop\Nowy folder 2013-09-02 06:14 - 2013-07-26 06:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-09-02 06:14 - 2013-07-26 06:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-09-02 06:14 - 2013-07-26 06:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-09-02 06:14 - 2013-07-26 06:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-09-02 06:14 - 2013-07-26 06:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-09-02 06:14 - 2013-07-26 06:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-09-02 06:14 - 2013-07-26 06:12 - 02647040 _____ C:\Windows\System32\iertutil.dll 2013-09-02 06:14 - 2013-07-26 06:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-09-02 06:14 - 2013-07-26 06:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-09-02 06:14 - 2013-07-26 06:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-09-02 06:14 - 2013-07-26 06:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-09-02 06:14 - 2013-07-26 06:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-09-02 06:14 - 2013-07-26 06:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-09-02 06:14 - 2013-07-26 06:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-09-02 06:14 - 2013-07-26 04:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-09-02 06:14 - 2013-07-26 04:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-02 06:14 - 2013-07-26 04:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-02 06:14 - 2013-07-26 04:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-02 06:14 - 2013-07-26 04:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-02 06:14 - 2013-07-26 04:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-02 06:14 - 2013-07-26 04:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-02 06:14 - 2013-07-26 04:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-02 06:14 - 2013-07-26 04:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-02 06:14 - 2013-07-26 04:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-02 06:14 - 2013-07-26 04:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-02 06:14 - 2013-07-26 04:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-02 06:14 - 2013-07-26 04:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-02 06:14 - 2013-07-26 04:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-02 06:14 - 2013-07-26 03:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-02 06:14 - 2013-07-26 03:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-09-02 06:14 - 2013-07-26 02:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-02 06:09 - 2013-09-02 06:10 - 00000000 ____D C:\Windows\System32\MRT 2013-09-02 06:04 - 2013-07-19 02:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll 2013-09-02 06:04 - 2013-07-19 02:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-09-02 06:04 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\System32\wintrust.dll 2013-09-02 06:04 - 2013-07-09 06:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-09-02 06:04 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-09-02 06:04 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-09-02 06:04 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-09-02 06:04 - 2013-07-09 05:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-09-02 06:04 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-09-02 06:04 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-09-02 06:03 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL 2013-09-02 06:03 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-09-02 06:03 - 2013-07-09 06:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll 2013-09-02 06:03 - 2013-07-09 05:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-09-02 06:03 - 2013-07-06 07:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-09-02 06:02 - 2013-06-15 05:35 - 01111552 _____ (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll 2013-09-02 06:02 - 2013-06-15 05:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tssecsrv.sys 2013-09-01 21:27 - 2013-09-01 21:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-14 12:11 - 2013-08-14 12:11 - 00000717 _____ C:\Users\Public\Desktop\Medal of Honor™ Warfighter.lnk ==================== One Month Modified Files and Folders ======= 2013-09-12 10:57 - 2013-09-12 10:57 - 00000000 ____D C:\FRST 2013-09-12 09:38 - 2010-08-29 07:11 - 00236244 _____ C:\Windows\System32\oodbs.lor 2013-09-11 17:10 - 2013-09-11 17:10 - 00016384 _____ C:\Users\Marta & Mateusz\Desktop\szczegóły diagnostyki i naprawy2.txt 2013-09-11 17:10 - 2013-09-11 17:09 - 00008191 _____ C:\Users\Marta & Mateusz\Desktop\szczegóły diagnostyki i naprawy.txt 2013-09-11 17:03 - 2013-09-11 17:03 - 00000745 _____ C:\Users\Marta & Mateusz\Desktop\raport błędu.txt 2013-09-10 10:18 - 2013-09-11 10:44 - 23101440 _____ C:\Windows\system3 2013-09-10 09:56 - 2009-07-14 05:45 - 00017168 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-10 09:56 - 2009-07-14 05:45 - 00017168 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-10 09:53 - 2013-03-07 23:00 - 01435934 _____ C:\Windows\WindowsUpdate.log 2013-09-10 09:49 - 2013-07-04 15:27 - 00006910 _____ C:\Windows\setupact.log 2013-09-10 09:49 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-09 20:48 - 2013-07-12 20:30 - 00000000 ____D C:\Users\Marta & Mateusz\Documents\FIFA 13 2013-09-09 20:24 - 2013-03-05 17:38 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-09 17:59 - 2013-03-05 21:16 - 00000000 ____D C:\Program Files (x86)\Origin 2013-09-09 13:38 - 2013-07-14 15:37 - 00280600 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-09-09 13:38 - 2013-07-14 15:34 - 00280600 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-09-04 19:27 - 2013-07-14 15:34 - 00291328 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-09-03 21:00 - 2013-09-03 20:35 - 00000000 ____D C:\Users\Marta & Mateusz\Desktop\Nowy folder 2013-09-02 17:04 - 2013-08-09 15:49 - 00000000 ____D C:\Users\Marta & Mateusz\Desktop\mada 2013-09-02 10:00 - 2010-08-28 11:15 - 00000000 ____D C:\Windows\Panther 2013-09-02 09:59 - 2013-03-05 18:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-02 06:13 - 2010-08-31 08:06 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-02 06:12 - 2009-07-14 18:55 - 00737730 _____ C:\Windows\System32\perfh015.dat 2013-09-02 06:12 - 2009-07-14 18:55 - 00154418 _____ C:\Windows\System32\perfc015.dat 2013-09-02 06:12 - 2009-07-14 06:13 - 01681786 _____ C:\Windows\System32\PerfStringBackup.INI 2013-09-02 06:10 - 2013-09-02 06:09 - 00000000 ____D C:\Windows\System32\MRT 2013-09-01 21:27 - 2013-09-01 21:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-01 12:41 - 2013-03-05 17:38 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-01 12:41 - 2013-03-05 17:38 - 00003868 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-01 12:41 - 2013-03-05 15:47 - 00071048 _____ C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-08-14 12:11 - 2013-08-14 12:11 - 00000717 _____ C:\Users\Public\Desktop\Medal of Honor™ Warfighter.lnk 2013-08-14 12:10 - 2013-07-14 15:34 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-08-14 12:10 - 2013-07-12 15:54 - 00070508 _____ C:\Windows\DirectX.log Files to move or delete: ==================== C:\Users\Marta & Mateusz\AppData\Local\Temp\comver.dll C:\Users\Marta & Mateusz\AppData\Local\Temp\vlc-2.0.7-win32.exe ==================== Known DLLs (Whitelisted) ================ [2013-09-02 06:14] - [2013-07-26 06:12] - 2647040 ____A () C:\Windows\System32\IERTUTIL.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 18% Total physical RAM: 4095.11 MB Available physical RAM: 3350.61 MB Total Pagefile: 4093.26 MB Available Pagefile: 3402.32 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ==================== Drives ================================ Drive c: (SYSTEM) (Fixed) (Total:50.01 GB) (Free:14.97 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (GRY) (Fixed) (Total:100.01 GB) (Free:67.63 GB) NTFS Drive e: (ROZRYWKA) (Fixed) (Total:200.01 GB) (Free:190.28 GB) NTFS Drive f: (MAGAZYN) (Fixed) (Total:581.48 GB) (Free:581.37 GB) NTFS Drive g: (Dysk naprawy Windows 7 64-bitowy) (CDROM) (Total:0.16 GB) (Free:0 GB) UDF Drive h: (KINGSTON) (Removable) (Total:1.87 GB) (Free:1.86 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: C48C6B14) Partition 1: (Active) - (Size=50 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=100 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=200 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=581 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 2 GB) (Disk ID: 5375C2B6) Partition 1: (Active) - (Size=2 GB) - (Type=0B) LastRegBack: 2013-09-10 10:18 ==================== End Of Log ============================