Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013 Ran by Administrator (administrator) on GIGABYTE-737D2C on 04-10-2013 16:57:12 Running from C:\Documents and Settings\Administrator\Moje dokumenty Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 6 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE (InstallShield Software Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (PixArt Imaging Incorporation) C:\WINDOWS\PixArt\PAC7302\Monitor.exe () C:\Program Files\Winamp\winampa.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\Program Files\Vtune\TBPanel.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Opera Software) C:\Program Files\Opera\15.0.1147.153\opera.exe () C:\Program Files\Opera\15.0.1147.153\opera_crashreporter.exe (Opera Software) C:\Program Files\Opera\15.0.1147.153\opera.exe (Opera Software) C:\Program Files\Opera\15.0.1147.153\opera.exe (Opera Software) C:\Program Files\Opera\15.0.1147.153\opera.exe (Opera Software) C:\Program Files\Opera\15.0.1147.153\opera.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [19521056 2010-03-12] (Realtek Semiconductor Corp.) HKLM\...\Run: [ISUSPM Startup] - C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [221184 2005-02-17] (InstallShield Software Corporation) HKLM\...\Run: [ISUSScheduler] - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-17] (InstallShield Software Corporation) HKLM\...\Run: [PAC7302_Monitor] - C:\WINDOWS\PixArt\PAC7302\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [36352 2008-08-04] () HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [1387288 2011-10-07] (Logitech, Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKCU\...\Run: [Pando Media Booster] - C:\Program Files\Pando Networks\Media Booster\PMB.exe [3077528 2011-09-15] () HKCU\...\Run: [TBPanel] - C:\Program Files\Vtune\TBPanel.exe [2158592 2010-07-30] () HKU\Default User\...\RunOnce: [nltide_3] - rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N BootExecute: ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU -&Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU -&Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\vvbst129.default-1380898560968 FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Extension: Skype extension for Firefox - C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ========================== Services (Whitelisted) ================= R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NwSapAgent; C:\Windows\System32\ipxsap.dll [66560 2001-10-26] (Microsoft Corporation) R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" S2 wuauserv; %systemroot%\system32\wuauserv.dll [x] ==================== Drivers (Whitelisted) ==================== S3 Ambfilt; C:\Windows\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative) R1 AmdPPM; C:\Windows\System32\DRIVERS\AmdPPM.sys [33792 2007-04-16] (Advanced Micro Devices) R3 Cardex; C:\WINDOWS\system32\drivers\TBPANEL.SYS [12256 2007-03-16] (Windows (R) 2000 DDK provider) S3 dtscsi; C:\Windows\System32\Drivers\dtscsi.sys [223128 2011-03-07] (DT Soft Ltd.) S3 etdrv; C:\WINDOWS\etdrv.sys [17488 2010-01-01] (Windows (R) 2000 DDK provider) S3 gdrv; C:\WINDOWS\gdrv.sys [17488 2010-01-01] (Windows (R) 2000 DDK provider) R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO32.SYS [22560 2013-10-03] (REALiX(tm)) R3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [30360 2011-09-02] (Logitech, Inc.) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\mbamswissarmy.sys [40776 2013-10-03] (Malwarebytes Corporation) S3 Monfilt; C:\Windows\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.) S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation) R3 NVHDA; C:\Windows\System32\drivers\nvhda32.sys [91496 2010-06-22] (NVIDIA Corporation) R2 NwlnkIpx; C:\Windows\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-14] (Microsoft Corporation) R2 NwlnkNb; C:\Windows\System32\DRIVERS\nwlnknb.sys [63232 2001-08-17] (Microsoft Corporation) R2 NwlnkSpx; C:\Windows\System32\DRIVERS\nwlnkspx.sys [55936 2001-08-17] (Microsoft Corporation) S3 PAC7302; C:\Windows\System32\DRIVERS\PAC7302.SYS [458752 2007-11-08] (PixArt Imaging Inc.) S3 PCAMPR5; C:\WINDOWS\system32\PCAMPR5.SYS [34688 2003-09-23] (Printing Communications Assoc., Inc. (PCAUSA)) S3 PCANDIS5; C:\WINDOWS\system32\PCANDIS5.SYS [32128 2006-03-01] (Printing Communications Assoc., Inc. (PCAUSA)) R1 SAVRKBootTasks; C:\WINDOWS\system32\SAVRKBootTasks.sys [18816 2009-06-18] (Sophos Plc) S3 SG762_XP; C:\Windows\System32\DRIVERS\WlanBZXP.sys [402432 2006-01-19] (ZyDAS Technology Corporation) S3 SONYPVU1; C:\Windows\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation) S3 TBPanel; C:\Windows\System32\Drivers\TBPanel.sys [12256 2007-03-16] (Windows (R) 2000 DDK provider) U5 GVTDrv; C:\WINDOWS\system32\Drivers\GVTDrv.sys [24944 2010-01-01] () S4 IntelIde; No ImagePath U3 afxcraog; \??\C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\afxcraog.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-04 16:39 - 2013-10-04 16:41 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\blablabla 2013-10-04 14:48 - 2013-10-04 14:48 - 00090112 _____ C:\WINDOWS\Minidump\Mini100413-02.dmp 2013-10-04 14:34 - 2013-10-04 14:33 - 00090112 _____ C:\WINDOWS\Minidump\Mini100413-01.dmp 2013-10-04 12:44 - 2013-10-04 12:44 - 00030451 _____ C:\Documents and Settings\Administrator\Pulpit\FRST.txt 2013-10-04 12:21 - 2013-10-04 14:50 - 00000000 ____D C:\AdwCleaner 2013-10-04 12:21 - 2013-10-04 12:21 - 00000919 _____ C:\Documents and Settings\Administrator\Pulpit\AdwCleaner[S1].txt.txt 2013-10-04 12:21 - 2013-10-04 12:21 - 00000859 _____ C:\Documents and Settings\Administrator\Pulpit\AdwCleaner[R1].txt.txt 2013-10-04 12:04 - 2013-10-04 12:04 - 00448512 _____ (OldTimer Tools) C:\Documents and Settings\Administrator\Moje dokumenty\TFC.exe 2013-10-04 12:02 - 2013-10-04 12:02 - 01045226 _____ C:\Documents and Settings\Administrator\Moje dokumenty\AdwCleaner.exe 2013-10-04 11:34 - 2013-10-04 16:39 - 00000928 _____ C:\WINDOWS\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job 2013-10-04 11:28 - 2013-10-04 11:28 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\Stare dane programu Firefox 2013-10-04 04:06 - 2013-10-04 10:58 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\FRST 2013-10-04 04:04 - 2013-10-04 11:03 - 00000000 ____D C:\FRST 2013-10-04 04:03 - 2013-10-04 04:03 - 01087213 _____ (Farbar) C:\Documents and Settings\Administrator\Moje dokumenty\FRST.exe 2013-10-04 03:57 - 2013-10-04 10:44 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\GMER 2013-10-03 22:45 - 2013-10-03 22:45 - 00377856 _____ C:\Documents and Settings\Administrator\Moje dokumenty\cmpz2uvt.exe 2013-10-03 22:43 - 2013-10-04 04:23 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\OTL 2013-10-03 22:30 - 2013-10-03 22:30 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Administrator\Moje dokumenty\OTL.exe 2013-10-03 22:09 - 2013-10-03 22:09 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\OCCT 2013-10-03 22:08 - 2013-10-03 22:08 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\OCCT 2013-10-03 21:48 - 2013-10-03 21:49 - 00001161 _____ C:\Documents and Settings\Administrator\Pulpit\Opis.txt 2013-10-03 20:52 - 2013-10-03 21:29 - 00204977 _____ C:\WINDOWS\setupapi.log 2013-10-03 20:33 - 2013-10-03 20:33 - 00019711 _____ C:\Documents and Settings\Administrator\Pulpit\ComboFix.txt 2013-10-03 20:17 - 2011-06-26 08:45 - 00256000 _____ C:\WINDOWS\PEV.exe 2013-10-03 20:17 - 2010-11-07 19:20 - 00208896 _____ C:\WINDOWS\MBR.exe 2013-10-03 20:17 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe 2013-10-03 20:17 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe 2013-10-03 20:17 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe 2013-10-03 20:17 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe 2013-10-03 20:17 - 2000-08-31 02:00 - 00098816 _____ C:\WINDOWS\sed.exe 2013-10-03 20:17 - 2000-08-31 02:00 - 00080412 _____ C:\WINDOWS\grep.exe 2013-10-03 20:17 - 2000-08-31 02:00 - 00068096 _____ C:\WINDOWS\zip.exe 2013-10-03 20:15 - 2013-10-03 20:33 - 00000000 ____D C:\Qoobox 2013-10-03 20:12 - 2013-10-03 20:12 - 00040776 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2013-10-03 18:35 - 2010-08-16 10:10 - 00007191 ____R C:\WINDOWS\system32\nvinfo.pb 2013-10-03 18:33 - 2013-10-03 18:33 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-10-03 18:29 - 2013-10-03 18:51 - 00235368 _____ C:\WINDOWS\system32\nvdrsdb1.bin 2013-10-03 18:29 - 2013-10-03 18:51 - 00235368 _____ C:\WINDOWS\system32\nvdrsdb0.bin 2013-10-03 18:29 - 2013-10-03 18:51 - 00000001 _____ C:\WINDOWS\system32\nvdrssel.bin 2013-10-03 18:29 - 2013-10-03 18:29 - 00000000 _____ C:\WINDOWS\system32\nvdrswr.lk 2013-10-03 18:23 - 2010-08-16 10:10 - 09892160 ____C (NVIDIA Corporation) C:\WINDOWS\system32\dllcache\nv4_mini.sys 2013-10-03 18:23 - 2010-08-16 10:10 - 09892160 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nv4_mini.sys 2013-10-03 18:18 - 2013-10-03 18:18 - 00000000 ____D C:\Program Files\Vtune 2013-10-03 18:18 - 2013-10-03 18:18 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Vtune 2013-10-03 18:18 - 2007-03-16 10:11 - 00012256 _____ (Windows (R) 2000 DDK provider) C:\WINDOWS\system32\Drivers\TBPanel.sys 2013-10-03 13:10 - 2013-10-03 14:46 - 00002315 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk 2013-10-03 13:10 - 2013-10-03 13:10 - 00001734 _____ C:\Documents and Settings\All Users\Pulpit\Adobe Reader XI.lnk 2013-10-03 13:04 - 2013-10-03 13:04 - 38966928 _____ (Adobe Systems Incorporated) C:\Documents and Settings\Administrator\Moje dokumenty\AdbeRdr11000_pl_PL.exe 2013-10-03 12:52 - 2013-10-03 12:52 - 00000000 ____D C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\OCCT_-_Ocbase_-_Adrien_Me 2013-10-03 12:39 - 2013-10-03 12:39 - 00000642 _____ C:\Documents and Settings\Administrator\Moje dokumenty\OCCT.lnk 2013-10-03 12:39 - 2013-10-03 12:39 - 00000000 ____D C:\Documents and Settings\Administrator\Menu Start\Programy\OCCT 2013-10-03 12:37 - 2013-10-03 12:39 - 00000000 ____D C:\Program Files\OCCTPT 2013-10-03 12:37 - 2013-10-03 12:37 - 06891341 _____ C:\Documents and Settings\Administrator\Moje dokumenty\OCCTPT4.4.0.exe 2013-10-03 12:12 - 2013-10-03 12:12 - 00000000 ____D C:\Program Files\eSupport.com 2013-10-03 12:11 - 2013-10-03 12:11 - 05510712 _____ (Copyright © 2013 eSupport.com, Inc • All Rights Reserved ) C:\Documents and Settings\Administrator\Moje dokumenty\biosagentplus_setup_avg_875.exe 2013-10-03 12:09 - 2013-10-03 12:09 - 00022560 _____ (REALiX(tm)) C:\WINDOWS\system32\Drivers\HWiNFO32.SYS 2013-10-03 12:09 - 2013-10-03 12:09 - 00000694 _____ C:\Documents and Settings\Administrator\Pulpit\HWiNFO32 Program.lnk 2013-10-03 12:09 - 2013-10-03 12:09 - 00000000 ____D C:\Program Files\HWiNFO32 2013-10-03 12:08 - 2013-10-03 12:08 - 02842360 _____ (Martin Malík - REALiX ) C:\Documents and Settings\Administrator\Moje dokumenty\hw32_424.exe 2013-10-02 14:35 - 2013-10-02 14:35 - 00000000 ____D C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\eSupport.com 2013-10-02 11:58 - 2013-10-02 11:58 - 00000000 ____D C:\Program Files\AGEIA Technologies 2013-10-02 11:25 - 2013-10-02 11:25 - 00000000 ____D C:\Program Files\Microsoft.NET 2013-10-02 11:20 - 2013-09-12 10:42 - 01049376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco3232723.dll 2013-10-02 11:20 - 2013-09-12 10:42 - 00893728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco3232723.dll 2013-10-02 10:18 - 2013-10-02 10:18 - 00000000 _RSHD C:\cmdcons 2013-10-02 10:18 - 2004-08-03 23:00 - 00262400 __RSH C:\cmldr 2013-10-02 10:11 - 2013-10-03 20:15 - 00000000 ____D C:\WINDOWS\erdnt 2013-10-02 10:09 - 2013-10-03 20:14 - 05130107 ____R (Swearware) C:\Documents and Settings\Administrator\Moje dokumenty\ComboFix.exe 2013-10-01 21:42 - 2009-06-18 13:55 - 00018816 ____N (Sophos Plc) C:\WINDOWS\system32\SAVRKBootTasks.sys 2013-09-16 12:09 - 2013-10-02 14:44 - 00000000 ____D C:\Program Files\CCleaner 2013-09-13 22:18 - 2013-09-21 10:18 - 03723656 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe ==================== One Month Modified Files and Folders ======= 2013-10-04 16:41 - 2013-10-04 16:39 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\blablabla 2013-10-04 16:39 - 2013-10-04 11:34 - 00000928 _____ C:\WINDOWS\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job 2013-10-04 16:39 - 2011-03-05 19:50 - 00000000 ___RD C:\Documents and Settings\Administrator\Moje dokumenty 2013-10-04 16:39 - 2011-03-05 19:50 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit 2013-10-04 16:33 - 2011-03-05 19:50 - 00000000 ___RD C:\Documents and Settings\Administrator\Menu Start\Programy 2013-10-04 16:18 - 2012-04-18 09:14 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-10-04 15:19 - 2011-09-15 17:48 - 00000000 ____D C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\PMB Files 2013-10-04 14:50 - 2013-10-04 12:21 - 00000000 ____D C:\AdwCleaner 2013-10-04 14:49 - 2011-03-05 20:41 - 00000159 _____ C:\WINDOWS\wiadebug.log 2013-10-04 14:49 - 2011-03-05 20:41 - 00000050 _____ C:\WINDOWS\wiaservc.log 2013-10-04 14:48 - 2013-10-04 14:48 - 00090112 _____ C:\WINDOWS\Minidump\Mini100413-02.dmp 2013-10-04 14:48 - 2012-01-18 20:17 - 00000000 ____D C:\WINDOWS\Minidump 2013-10-04 14:48 - 2011-03-05 19:50 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-10-04 14:39 - 2011-03-05 19:50 - 00032128 _____ C:\WINDOWS\SchedLgU.Txt 2013-10-04 14:33 - 2013-10-04 14:34 - 00090112 _____ C:\WINDOWS\Minidump\Mini100413-01.dmp 2013-10-04 12:44 - 2013-10-04 12:44 - 00030451 _____ C:\Documents and Settings\Administrator\Pulpit\FRST.txt 2013-10-04 12:21 - 2013-10-04 12:21 - 00000919 _____ C:\Documents and Settings\Administrator\Pulpit\AdwCleaner[S1].txt.txt 2013-10-04 12:21 - 2013-10-04 12:21 - 00000859 _____ C:\Documents and Settings\Administrator\Pulpit\AdwCleaner[R1].txt.txt 2013-10-04 12:12 - 2011-03-05 20:39 - 00000000 __RHD C:\Documents and Settings\All Users\Dane aplikacji 2013-10-04 12:12 - 2011-03-05 20:39 - 00000000 ___RD C:\Documents and Settings\All Users\Menu Start\Programy 2013-10-04 12:12 - 2011-03-05 19:50 - 00000000 __RHD C:\Documents and Settings\Administrator\Dane aplikacji 2013-10-04 12:12 - 2011-03-05 19:50 - 00000000 ___HD C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji 2013-10-04 12:04 - 2013-10-04 12:04 - 00448512 _____ (OldTimer Tools) C:\Documents and Settings\Administrator\Moje dokumenty\TFC.exe 2013-10-04 12:02 - 2013-10-04 12:02 - 01045226 _____ C:\Documents and Settings\Administrator\Moje dokumenty\AdwCleaner.exe 2013-10-04 11:28 - 2013-10-04 11:28 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\Stare dane programu Firefox 2013-10-04 11:23 - 2013-05-08 08:35 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\Majówka 2013 2013-10-04 11:20 - 2011-03-06 19:39 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\Mp3 2013-10-04 11:03 - 2013-10-04 04:04 - 00000000 ____D C:\FRST 2013-10-04 10:58 - 2013-10-04 04:06 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\FRST 2013-10-04 10:44 - 2013-10-04 03:57 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\GMER 2013-10-04 04:23 - 2013-10-03 22:43 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\OTL 2013-10-04 04:03 - 2013-10-04 04:03 - 01087213 _____ (Farbar) C:\Documents and Settings\Administrator\Moje dokumenty\FRST.exe 2013-10-03 22:45 - 2013-10-03 22:45 - 00377856 _____ C:\Documents and Settings\Administrator\Moje dokumenty\cmpz2uvt.exe 2013-10-03 22:30 - 2013-10-03 22:30 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Administrator\Moje dokumenty\OTL.exe 2013-10-03 22:09 - 2013-10-03 22:09 - 00000000 ____D C:\Documents and Settings\Administrator\Pulpit\OCCT 2013-10-03 22:08 - 2013-10-03 22:08 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\OCCT 2013-10-03 21:58 - 2013-06-20 11:35 - 00000000 ____D C:\Documents and Settings\Administrator\Dane aplikacji\GG 2013-10-03 21:49 - 2013-10-03 21:48 - 00001161 _____ C:\Documents and Settings\Administrator\Pulpit\Opis.txt 2013-10-03 21:35 - 2011-03-05 19:44 - 00000000 ____D C:\WINDOWS\system32\Restore 2013-10-03 21:29 - 2013-10-03 20:52 - 00204977 _____ C:\WINDOWS\setupapi.log 2013-10-03 20:33 - 2013-10-03 20:33 - 00019711 _____ C:\Documents and Settings\Administrator\Pulpit\ComboFix.txt 2013-10-03 20:33 - 2013-10-03 20:15 - 00000000 ____D C:\Qoobox 2013-10-03 20:33 - 2011-03-05 19:50 - 00000000 ___HD C:\Documents and Settings\LocalService\Ustawienia lokalne 2013-10-03 20:33 - 2011-03-05 19:48 - 00000000 ___HD C:\Documents and Settings\NetworkService\Ustawienia lokalne 2013-10-03 20:30 - 2001-07-22 00:15 - 00000246 _____ C:\WINDOWS\system.ini 2013-10-03 20:15 - 2013-10-02 10:11 - 00000000 ____D C:\WINDOWS\erdnt 2013-10-03 20:14 - 2013-10-02 10:09 - 05130107 ____R (Swearware) C:\Documents and Settings\Administrator\Moje dokumenty\ComboFix.exe 2013-10-03 20:12 - 2013-10-03 20:12 - 00040776 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2013-10-03 20:12 - 2011-09-15 17:48 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\PMB Files 2013-10-03 19:40 - 2011-03-05 19:50 - 00000000 ____D C:\Documents and Settings\Administrator 2013-10-03 18:51 - 2013-10-03 18:29 - 00235368 _____ C:\WINDOWS\system32\nvdrsdb1.bin 2013-10-03 18:51 - 2013-10-03 18:29 - 00235368 _____ C:\WINDOWS\system32\nvdrsdb0.bin 2013-10-03 18:51 - 2013-10-03 18:29 - 00000001 _____ C:\WINDOWS\system32\nvdrssel.bin 2013-10-03 18:43 - 2011-03-05 19:50 - 00000188 ___SH C:\Documents and Settings\Administrator\ntuser.ini 2013-10-03 18:38 - 2011-03-05 20:34 - 00000000 ____D C:\WINDOWS\Help 2013-10-03 18:33 - 2013-10-03 18:33 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-10-03 18:32 - 2011-03-05 20:16 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-10-03 18:29 - 2013-10-03 18:29 - 00000000 _____ C:\WINDOWS\system32\nvdrswr.lk 2013-10-03 18:18 - 2013-10-03 18:18 - 00000000 ____D C:\Program Files\Vtune 2013-10-03 18:18 - 2013-10-03 18:18 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Vtune 2013-10-03 18:18 - 2011-03-05 19:45 - 00000000 ____D C:\WINDOWS\system32\DirectX 2013-10-03 17:46 - 2011-03-05 20:34 - 00000000 ____D C:\WINDOWS\java 2013-10-03 16:00 - 2012-04-10 18:36 - 00000784 _____ C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk 2013-10-03 16:00 - 2012-04-10 18:36 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-03 16:00 - 2012-04-10 18:36 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes' Anti-Malware 2013-10-03 16:00 - 2011-03-05 20:39 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit 2013-10-03 14:52 - 2011-03-05 20:39 - 01261912 ____C C:\WINDOWS\system32\PerfStringBackup.INI 2013-10-03 14:52 - 2001-10-26 18:15 - 00557734 _____ C:\WINDOWS\system32\perfh015.dat 2013-10-03 14:52 - 2001-10-26 18:15 - 00105488 _____ C:\WINDOWS\system32\perfc015.dat 2013-10-03 14:46 - 2013-10-03 13:10 - 00002315 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk 2013-10-03 13:10 - 2013-10-03 13:10 - 00001734 _____ C:\Documents and Settings\All Users\Pulpit\Adobe Reader XI.lnk 2013-10-03 13:09 - 2012-10-23 09:50 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-10-03 13:09 - 2012-03-30 11:57 - 00000000 ____D C:\Program Files\Adobe 2013-10-03 13:09 - 2011-03-08 12:04 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Adobe 2013-10-03 13:04 - 2013-10-03 13:04 - 38966928 _____ (Adobe Systems Incorporated) C:\Documents and Settings\Administrator\Moje dokumenty\AdbeRdr11000_pl_PL.exe 2013-10-03 12:52 - 2013-10-03 12:52 - 00000000 ____D C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\OCCT_-_Ocbase_-_Adrien_Me 2013-10-03 12:39 - 2013-10-03 12:39 - 00000642 _____ C:\Documents and Settings\Administrator\Moje dokumenty\OCCT.lnk 2013-10-03 12:39 - 2013-10-03 12:39 - 00000000 ____D C:\Documents and Settings\Administrator\Menu Start\Programy\OCCT 2013-10-03 12:39 - 2013-10-03 12:37 - 00000000 ____D C:\Program Files\OCCTPT 2013-10-03 12:37 - 2013-10-03 12:37 - 06891341 _____ C:\Documents and Settings\Administrator\Moje dokumenty\OCCTPT4.4.0.exe 2013-10-03 12:12 - 2013-10-03 12:12 - 00000000 ____D C:\Program Files\eSupport.com 2013-10-03 12:11 - 2013-10-03 12:11 - 05510712 _____ (Copyright © 2013 eSupport.com, Inc • All Rights Reserved ) C:\Documents and Settings\Administrator\Moje dokumenty\biosagentplus_setup_avg_875.exe 2013-10-03 12:09 - 2013-10-03 12:09 - 00022560 _____ (REALiX(tm)) C:\WINDOWS\system32\Drivers\HWiNFO32.SYS 2013-10-03 12:09 - 2013-10-03 12:09 - 00000694 _____ C:\Documents and Settings\Administrator\Pulpit\HWiNFO32 Program.lnk 2013-10-03 12:09 - 2013-10-03 12:09 - 00000000 ____D C:\Program Files\HWiNFO32 2013-10-03 12:08 - 2013-10-03 12:08 - 02842360 _____ (Martin Malík - REALiX ) C:\Documents and Settings\Administrator\Moje dokumenty\hw32_424.exe 2013-10-03 11:59 - 2012-11-20 21:17 - 00000000 ____D C:\Program Files\SpeedFan 2013-10-02 14:44 - 2013-09-16 12:09 - 00000000 ____D C:\Program Files\CCleaner 2013-10-02 14:35 - 2013-10-02 14:35 - 00000000 ____D C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\eSupport.com 2013-10-02 13:25 - 2012-10-21 19:26 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\NVIDIA 2013-10-02 13:11 - 2011-03-11 00:37 - 00000000 ____D C:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie 2013-10-02 12:07 - 2011-03-05 20:01 - 00000000 ____D C:\WINDOWS\Microsoft.NET 2013-10-02 11:58 - 2013-10-02 11:58 - 00000000 ____D C:\Program Files\AGEIA Technologies 2013-10-02 11:57 - 2011-03-05 20:05 - 00000000 ____D C:\WINDOWS\system32\ReinstallBackups 2013-10-02 11:39 - 2011-03-05 20:34 - 00000000 ____D C:\WINDOWS\system32\pl-pl 2013-10-02 11:25 - 2013-10-02 11:25 - 00000000 ____D C:\Program Files\Microsoft.NET 2013-10-02 10:34 - 2011-03-05 19:50 - 00000000 __SHD C:\Documents and Settings\LocalService 2013-10-02 10:34 - 2011-03-05 19:50 - 00000000 ___HD C:\Documents and Settings\Administrator\Ustawienia lokalne 2013-10-02 10:18 - 2013-10-02 10:18 - 00000000 _RSHD C:\cmdcons 2013-10-02 10:18 - 2011-03-05 20:38 - 00000360 __RSH C:\boot.ini 2013-09-30 14:38 - 2011-03-05 19:48 - 00000000 __SHD C:\Documents and Settings\NetworkService 2013-09-30 14:37 - 2011-03-05 19:43 - 00000000 ____D C:\WINDOWS\Registration 2013-09-30 09:46 - 2001-07-22 00:17 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl 2013-09-26 14:51 - 2013-06-20 11:35 - 00000000 ____D C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\GG 2013-09-21 10:18 - 2013-09-13 22:18 - 03723656 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe 2013-09-21 10:18 - 2012-04-18 09:14 - 00692616 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2013-09-21 10:18 - 2012-01-18 19:30 - 00071048 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2013-09-16 12:09 - 2013-09-01 10:14 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\CCleaner 2013-09-16 12:08 - 2013-09-01 10:13 - 04454952 _____ (Piriform Ltd) C:\Documents and Settings\Administrator\Moje dokumenty\ccsetup405.exe 2013-09-12 10:42 - 2013-10-02 11:20 - 01049376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco3232723.dll 2013-09-12 10:42 - 2013-10-02 11:20 - 00893728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco3232723.dll 2013-09-12 10:42 - 2012-10-21 19:25 - 06324224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2013-09-12 10:42 - 2012-10-21 19:25 - 02313192 _____ C:\WINDOWS\system32\nvdata.data 2013-09-04 05:10 - 2011-03-08 10:41 - 00000000 ___SD C:\Documents and Settings\Administrator\UserData ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe [2008-04-14 22:51] - [2008-04-14 22:51] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\Windows\System32\winlogon.exe [2008-04-14 22:51] - [2008-04-14 22:51] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\Windows\System32\svchost.exe [2008-04-14 22:51] - [2008-04-14 22:51] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\Windows\System32\services.exe [2008-04-14 22:51] - [2008-04-14 22:51] - 0109056 ____A (Microsoft Corporation) 3e3ae424e27c4cefe4cab368c7b570ea C:\Windows\System32\User32.dll [2008-04-14 22:50] - [2008-04-14 22:50] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\Windows\System32\userinit.exe [2008-04-14 22:51] - [2008-04-14 22:51] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\Windows\System32\Drivers\volsnap.sys [2008-04-14 21:31] - [2008-04-14 21:31] - 0052864 ___AC (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================