Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013 Ran by Ola Koszyk (administrator) on OLAKOSZYK on 12-10-2013 18:52:50 Running from C:\Users\Ola Koszyk\Desktop Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Polish Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe () C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe (AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.1\ToolbarUpdater.exe () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.1\loggingserver.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\WDC.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (ASUS) C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUS) C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Ask) C:\Program Files\Ask.com\Updater\Updater.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe () C:\Program Files\AVG Secure Search\vprot.exe (www.BitComet.com) C:\Program Files\BitComet\BitComet.exe (GG Network S.A.) C:\Users\Ola Koszyk\AppData\Local\GG\Application\gghub.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe () C:\Program Files\Kaspersky Security Scan\KSS.exe (GG Network S.A.) C:\Users\Ola Koszyk\AppData\Local\GG\Application\ggapp.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HControlUser] - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM\...\Run: [ATKMEDIA] - C:\Program Files\ASUS\ATK Media\DMedia.exe [170624 2009-08-19] (ASUS) HKLM\...\Run: [ATKOSD2] - C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS) HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2029640 2009-05-14] (ESET) HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.) HKLM\...\Run: [] - [x] HKLM\...\Run: [ApnUpdater] - C:\Program Files\Ask.com\Updater\Updater.exe [1561768 2012-05-04] (Ask) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated) HKLM\...\Run: [hpqSRMon] - C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKLM\...\Run: [vProt] - C:\Program Files\AVG Secure Search\vprot.exe [2404376 2013-09-28] () HKCU\...\Run: [BitComet] - C:\Program Files\BitComet\BitComet.exe [12805888 2013-02-19] (www.BitComet.com) HKCU\...\Run: [Browser Infrastructure Helper] - C:\Users\Ola Koszyk\AppData\Local\Smartbar\Application\Linkury.exe startup HKCU\...\Run: [GG] - C:\Users\Ola Koszyk\AppData\Local\GG\Application\gghub.exe [4009024 2013-09-16] (GG Network S.A.) HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-01-14] (Google Inc.) HKCU\...\Run: [efcccddacdfbc] - C:\ProgramData\efcccddacdfbc.exe [280064 2013-09-30] () MountPoints2: {f5fe5ccd-3bb6-11e1-858e-806e6f6e6963} - F:\setup.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=a02e7f38-2a50-4cf7-8e7d-0b4d2d857bd3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=a02e7f38-2a50-4cf7-8e7d-0b4d2d857bd3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=opc&from=opc&uid=3219913727_1789_8C4BC7E8&ts=1351455557 SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=TJ&userid=a02e7f38-2a50-4cf7-8e7d-0b4d2d857bd3&affid=111585&searchtype=ds&babsrc=lnkry&q={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=a02e7f38-2a50-4cf7-8e7d-0b4d2d857bd3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {126B987E-8312-4401-94BE-70C4BA41A653} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {6E4DA852-611D-4F39-8807-74AA3ED227C8} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033 SearchScopes: HKCU - {7B020A0A-CE1F-4606-A503-20E27849BD2E} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=2A8C200A-76DD-4F24-B7A2-74C7A1B48C13&apn_sauid=25EA7E61-90B6-4FD2-A0D7-AE382E2E1364 SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={4FBD8DC0-3FA5-43AB-B52D-5E9A1F1F5EA5}&mid=4e5619e61b5f42b99db9d1ef10b2cad1-27228bf1ea501aad254aeb86831eaabdb660ef9f&lang=en&ds=hk011&pr=&d=2012-11-23 22:02:25&v=15.4.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Linkury SmartbarEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.) BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\17.0.0.9\AVG Secure Search_toolbar.dll (AVG Secure Search) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) BHO: Ashampoo PO Toolbar - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Program Files\Ashampoo_PO\prxtbAsha.dll (Conduit Ltd.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.) Toolbar: HKLM - Ashampoo PO Toolbar - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Program Files\Ashampoo_PO\prxtbAsha.dll (Conduit Ltd.) Toolbar: HKLM - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM - Linkury Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\17.0.0.9\AVG Secure Search_toolbar.dll (AVG Secure Search) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -DVDVideoSoftTB Toolbar - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.) Toolbar: HKCU -Ashampoo PO Toolbar - {D43723AE-1AE1-4A25-A6A4-BF0929273CAB} - C:\Program Files\Ashampoo_PO\prxtbAsha.dll (Conduit Ltd.) Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.1\ViProtocol.dll (AVG Secure Search) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt FireFox: ======== FF ProfilePath: C:\Users\Ola Koszyk\AppData\Roaming\Mozilla\Firefox\Profiles\gbu3z5mo.default FF DefaultSearchEngine: AVG Secure Search FF SearchEngineOrder.1: v9 FF SelectedSearchEngine: Web Search FF Homepage: hxxp://search.conduit.com/?ctid=CT2481033&SearchSource=13 FF Keyword.URL: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2481033&SearchSource=2&CUI=UN54380292783254043&UM=&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.1\\npsitesafety.dll (AVG Technologies) FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.5.1 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Ola Koszyk\AppData\Roaming\Mozilla\Firefox\Profiles\gbu3z5mo.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\Ola Koszyk\AppData\Roaming\Mozilla\Firefox\Profiles\gbu3z5mo.default\searchplugins\conduit.xml FF SearchPlugin: C:\Users\Ola Koszyk\AppData\Roaming\Mozilla\Firefox\Profiles\gbu3z5mo.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\v9.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml FF Extension: No Name - C:\Users\Ola Koszyk\AppData\Roaming\Mozilla\Firefox\Profiles\gbu3z5mo.default\Extensions\helperbar@helperbar.com FF Extension: No Name - C:\Users\Ola Koszyk\AppData\Roaming\Mozilla\Firefox\Profiles\gbu3z5mo.default\Extensions\staged FF Extension: Ask Toolbar - C:\Users\Ola Koszyk\AppData\Roaming\Mozilla\Firefox\Profiles\gbu3z5mo.default\Extensions\toolbar@ask.com FF Extension: DVDVideoSoftTB Community Toolbar - C:\Users\Ola Koszyk\AppData\Roaming\Mozilla\Firefox\Profiles\gbu3z5mo.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} FF Extension: No Name - C:\Users\Ola Koszyk\AppData\Roaming\Mozilla\Firefox\Profiles\gbu3z5mo.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} FF Extension: BitComet 视频下载器 - C:\Users\Ola Koszyk\AppData\Roaming\Mozilla\Firefox\Profiles\gbu3z5mo.default\Extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB} FF Extension: Ashampoo PO - C:\Users\Ola Koszyk\AppData\Roaming\Mozilla\Firefox\Profiles\gbu3z5mo.default\Extensions\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKLM\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\17.0.0.9 FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\17.0.0.9 FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF Extension: Eset Plugin - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR RestoreOnStartup: "urls_to_restore_on_startup": null CHR DefaultSearchURL: (Web) - http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=a02e7f38-2a50-4cf7-8e7d-0b4d2d857bd3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} CHR DefaultSuggestURL: (Web) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\30.0.1599.69\pdf.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (BitCometAgent) - C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll (BitComet) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll (AVG Technologies) CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll No File CHR Plugin: (Java(TM) Platform SE 7 U5) - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll () CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Extension: (Linkury Smartbar) - C:\Users\OLAKOS~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0 CHR Extension: (AVG Security Toolbar) - C:\Users\OLAKOS~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\14.2.0.1_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\OLAKOS~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\17.0.0.9\avg.crx ========================== Services (Whitelisted) ================= R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS) R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2010-12-28] (www.BitComet.com) S3 EhttpSrv; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [20680 2009-05-14] (ESET) R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [731840 2009-05-14] (ESET) R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () R2 vToolbarUpdater17.0.1; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.1\ToolbarUpdater.exe [1734680 2013-09-28] (AVG Secure Search) ==================== Drivers (Whitelisted) ==================== R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-09-28] (AVG Technologies) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [239168 2012-01-10] (DT Soft Ltd) R2 eamon; C:\Windows\System32\DRIVERS\eamon.sys [114472 2009-05-14] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [107256 2009-05-14] (ESET) R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [93312 2009-05-14] (ESET) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2012-01-10] ( ) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [14392 2012-01-10] (ASUS) S3 ASUSProcObsrv; \??\F:\I386\AsProcOb.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-12 18:51 - 2013-10-12 18:51 - 00000000 ____D C:\FRST 2013-10-12 18:51 - 2013-10-12 18:25 - 01087213 _____ (Farbar) C:\Users\Ola Koszyk\Desktop\FRST.exe 2013-10-12 18:49 - 2013-10-12 18:49 - 00052258 _____ C:\Users\Ola Koszyk\Desktop\Extras.Txt 2013-10-12 18:46 - 2013-10-12 18:46 - 00128748 _____ C:\Users\Ola Koszyk\Desktop\OTL.Txt 2013-10-12 18:28 - 2013-10-12 18:26 - 00602112 _____ (OldTimer Tools) C:\Users\Ola Koszyk\Desktop\OTL.exe 2013-10-11 20:59 - 2013-10-11 20:59 - 00219136 _____ C:\Users\Ola Koszyk\AppData\Roaming\iESionWMyuc 2013-10-11 20:59 - 2013-10-11 20:59 - 00219136 _____ C:\Users\Ola Koszyk\AppData\Local\7mTfwxXJwgy 2013-10-11 20:59 - 2013-10-11 20:59 - 00219136 _____ C:\ProgramData\DPtPnrWzWVi 2013-10-10 20:08 - 2013-10-10 20:08 - 00219136 _____ C:\Users\Ola Koszyk\AppData\Roaming\LZIf8Jl9V 2013-10-10 20:08 - 2013-10-10 20:08 - 00219136 _____ C:\Users\Ola Koszyk\AppData\Local\kYNIzaV8dsO 2013-10-10 20:08 - 2013-10-10 20:08 - 00219136 _____ C:\ProgramData\OxTYAhuzWHz 2013-09-18 22:11 - 2013-09-30 18:09 - 00010240 _____ (Microsoft Corporation) C:\ProgramData\libnspr4.dll 2013-09-18 20:41 - 2013-09-18 20:41 - 00035328 _____ C:\ProgramData\qmbtpijbrjqdrqn 2013-09-18 20:38 - 2013-09-18 20:38 - 00192512 _____ C:\ProgramData\buxosexehnsqmrc 2013-09-18 20:35 - 2013-09-21 13:20 - 00000316 _____ C:\ProgramData\efcccddacdfbc.cfg 2013-09-18 20:35 - 2013-09-18 20:35 - 00174592 _____ C:\ProgramData\bwsvprcqvxiiyca 2013-09-18 20:32 - 2013-09-30 18:17 - 00280064 _____ C:\ProgramData\efcccddacdfbc.exe 2013-09-16 18:24 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-16 18:24 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-16 18:24 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-16 18:24 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-16 18:24 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-16 18:24 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-16 18:24 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-16 18:02 - 2013-10-12 18:14 - 00000000 ____D C:\Users\Ola Koszyk\Desktop\Nowy folder 2013-09-16 17:53 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-16 17:53 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-16 17:53 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-16 17:53 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-16 17:53 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-16 17:53 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-16 17:53 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-16 17:53 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll ==================== One Month Modified Files and Folders ======= 2013-10-12 18:51 - 2013-10-12 18:51 - 00000000 ____D C:\FRST 2013-10-12 18:51 - 2012-01-15 00:01 - 00000000 ____D C:\Users\Ola Koszyk\AppData\Roaming\BitComet 2013-10-12 18:49 - 2013-10-12 18:49 - 00052258 _____ C:\Users\Ola Koszyk\Desktop\Extras.Txt 2013-10-12 18:46 - 2013-10-12 18:46 - 00128748 _____ C:\Users\Ola Koszyk\Desktop\OTL.Txt 2013-10-12 18:28 - 2012-01-10 20:58 - 01549932 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-12 18:28 - 2009-07-14 10:07 - 00698146 _____ C:\Windows\system32\perfh015.dat 2013-10-12 18:28 - 2009-07-14 10:07 - 00135224 _____ C:\Windows\system32\perfc015.dat 2013-10-12 18:26 - 2013-10-12 18:28 - 00602112 _____ (OldTimer Tools) C:\Users\Ola Koszyk\Desktop\OTL.exe 2013-10-12 18:25 - 2013-10-12 18:51 - 01087213 _____ (Farbar) C:\Users\Ola Koszyk\Desktop\FRST.exe 2013-10-12 18:21 - 2013-06-12 20:26 - 00000000 ____D C:\Users\Ola Koszyk\AppData\Roaming\GG 2013-10-12 18:20 - 2013-08-29 21:48 - 00002186 _____ C:\Windows\setupact.log 2013-10-12 18:20 - 2013-06-08 11:40 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job 2013-10-12 18:20 - 2013-05-31 19:55 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2013-10-12 18:20 - 2012-01-14 23:44 - 00001040 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-12 18:20 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-12 18:18 - 2012-01-14 16:27 - 00811520 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2013-10-12 18:18 - 2012-01-14 16:26 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll 2013-10-12 18:18 - 2012-01-14 16:26 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll 2013-10-12 18:18 - 2012-01-10 20:17 - 01854905 _____ C:\Windows\WindowsUpdate.log 2013-10-12 18:18 - 2009-07-14 06:34 - 00010128 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-12 18:18 - 2009-07-14 06:34 - 00010128 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-12 18:16 - 2012-01-10 20:45 - 00000000 ____D C:\Users\Ola Koszyk 2013-10-12 18:14 - 2013-09-16 18:02 - 00000000 ____D C:\Users\Ola Koszyk\Desktop\Nowy folder 2013-10-12 18:14 - 2012-11-23 23:02 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search 2013-10-12 18:14 - 2012-11-23 23:02 - 00000000 ____D C:\Program Files\AVG Secure Search 2013-10-12 18:14 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\wfp 2013-10-12 18:13 - 2012-01-10 22:43 - 00000000 ____D C:\Users\Ola Koszyk\AppData\Local\Mozilla 2013-10-12 18:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration 2013-10-12 18:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-10-11 20:59 - 2013-10-11 20:59 - 00219136 _____ C:\Users\Ola Koszyk\AppData\Roaming\iESionWMyuc 2013-10-11 20:59 - 2013-10-11 20:59 - 00219136 _____ C:\Users\Ola Koszyk\AppData\Local\7mTfwxXJwgy 2013-10-11 20:59 - 2013-10-11 20:59 - 00219136 _____ C:\ProgramData\DPtPnrWzWVi 2013-10-10 20:08 - 2013-10-10 20:08 - 00219136 _____ C:\Users\Ola Koszyk\AppData\Roaming\LZIf8Jl9V 2013-10-10 20:08 - 2013-10-10 20:08 - 00219136 _____ C:\Users\Ola Koszyk\AppData\Local\kYNIzaV8dsO 2013-10-10 20:08 - 2013-10-10 20:08 - 00219136 _____ C:\ProgramData\OxTYAhuzWHz 2013-10-06 20:34 - 2012-01-10 20:13 - 00000000 ____D C:\Windows\Panther 2013-09-30 18:17 - 2013-09-18 20:32 - 00280064 _____ C:\ProgramData\efcccddacdfbc.exe 2013-09-30 18:09 - 2013-09-18 22:11 - 00010240 _____ (Microsoft Corporation) C:\ProgramData\libnspr4.dll 2013-09-28 19:52 - 2012-11-23 23:02 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys 2013-09-21 13:20 - 2013-09-18 20:35 - 00000316 _____ C:\ProgramData\efcccddacdfbc.cfg 2013-09-20 15:50 - 2012-01-14 23:52 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-18 20:41 - 2013-09-18 20:41 - 00035328 _____ C:\ProgramData\qmbtpijbrjqdrqn 2013-09-18 20:38 - 2013-09-18 20:38 - 00192512 _____ C:\ProgramData\buxosexehnsqmrc 2013-09-18 20:35 - 2013-09-18 20:35 - 00174592 _____ C:\ProgramData\bwsvprcqvxiiyca 2013-09-17 16:37 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-09-16 19:11 - 2013-06-12 20:26 - 00000000 ____D C:\Users\Ola Koszyk\AppData\Local\GG 2013-09-16 19:09 - 2009-07-14 06:33 - 00407824 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-16 19:07 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\pl-PL 2013-09-16 18:23 - 2013-08-15 11:15 - 00000000 ____D C:\Windows\system32\MRT 2013-09-16 18:21 - 2012-01-10 23:22 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Files to move or delete: ==================== C:\ProgramData\efcccddacdfbc.exe C:\ProgramData\libnspr4.dll C:\Users\Ola Koszyk\microsoft.dat Some content of TEMP: ==================== C:\Users\Ola Koszyk\AppData\Local\Temp\ggdrive-menu.exe C:\Users\Ola Koszyk\AppData\Local\Temp\ggdrive-overlay.exe C:\Users\Ola Koszyk\AppData\Local\Temp\ICReinstall_FlvPlayerSetup.exe C:\Users\Ola Koszyk\AppData\Local\Temp\installstats.exe C:\Users\Ola Koszyk\AppData\Local\Temp\libnspr4.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-01 17:07 ==================== End Of Log ============================