Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013 Ran by KONTRAST (administrator) on KONTRAST-FF4D7A on 12-10-2013 23:08:19 Running from C:\Documents and Settings\KONTRAST\Pulpit\Fixitpc Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 7 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Spigot, Inc.) C:\Program Files\Application Updater\ApplicationUpdater.exe (Eset ) C:\Program Files\Eset\nod32krn.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe (Adobe Sytems Incorporated) C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe (Adobe Systems Inc.) C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE (InstallShield Software Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Wireless Service) C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Spigot, Inc.) C:\Program Files\pdfforge Toolbar\SearchSettings.exe (Microsoft Corporation) C:\WINDOWS\System32\reader_s.exe (Microsoft Corporation) C:\Documents and Settings\KONTRAST\reader_s.exe () C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (InstallShield Software Corporation) c:\progra~1\common~1\instal~1\update~1\isuspm.exe (InstallShield Software Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (Microsoft Corporation) C:\WINDOWS\system32\dwwin.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] () HKLM\...\Run: [NeroFilterCheck] - C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [Adobe Version Cue CS2] - C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe [856064 2005-05-25] (Adobe Sytems Incorporated) HKLM\...\Run: [Acrobat Assistant 7.0] - C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe [483328 2004-12-14] (Adobe Systems Inc.) HKLM\...\Run: [] - [x] HKLM\...\Run: [OrderReminder] - C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [98304 2006-01-30] (Hewlett-Packard) HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [16261632 2006-07-21] (Realtek Semiconductor Corp.) HKLM\...\Run: [SkyTel] - C:\Windows\SkyTel.EXE [2879488 2006-05-16] (Realtek Semiconductor Corp.) HKLM\...\Run: [Alcmtr] - C:\Windows\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [D-Link AirPlus G] - C:\Program Files\D-Link\AirPlus G\AirGCFG.exe [1556480 2007-04-14] (D-Link) HKLM\...\Run: [ISUSPM Startup] - C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [221184 2004-06-16] (InstallShield Software Corporation) HKLM\...\Run: [ISUSScheduler] - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2004-06-16] (InstallShield Software Corporation) HKLM\...\Run: [ANIWZCS2Service] - C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe [49152 2007-01-19] (Wireless Service) HKLM\...\Run: [nod32kui] - C:\Program Files\Eset\nod32kui.exe [949376 2011-05-14] (Eset ) HKLM\...\Run: [SearchSettings] - C:\Program Files\pdfforge Toolbar\SearchSettings.exe [974848 2010-01-08] (Spigot, Inc.) HKLM\...\Run: [Calc32] - C:\WINDOWS\system32\regedit.exe [165376 2010-03-01] () HKLM\...\Run: [reader_s] - C:\WINDOWS\System32\reader_s.exe [28672 2010-03-01] (Microsoft Corporation) HKLM\...\Run: [Regedit32] - C:\WINDOWS\system32\regedit.exe [165376 2010-03-01] () HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k HKLM\...\Policies\Explorer\Run: [36972] - C:\DOCUME~1\ALLUSE~1\LOCALS~1\Temp\ccxfrwu.com [96107 2009-08-06] ( (Hause)) HKCU\...\Run: [kamsoft] - C:\WINDOWS\system32\kamsoft.exe HKCU\...\Run: [cdoosoft] - C:\WINDOWS\system32\olhrwef.exe HKCU\...\Run: [reader_s] - C:\Documents and Settings\KONTRAST\reader_s.exe [28672 2010-03-01] (Microsoft Corporation) HKCU\...\Run: [12CFG214-K641-12SF-N85P] - C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe [23040 2010-03-01] () HKCU\...\Winlogon: [Shell] C:\RECYCLER\S-1-5-21-1075669394-9092640014-191519155-4240\nissan.exe,C:\RECYCLER\S-1-5-21-5961824694-1487050695-811326330-6529\nissan.exe,C:\RECYCLER\S-1-5-21-3560061014-3923081885-960717613-5671\nissan.exe,C:\RECYCLER\S-1-5-21-7006071116-0161309563-998999077-6411\nissan.exe,C:\RECYCLER\S-1-5-21-9104716490-4923726443-688720094-7931\nissan.exe,C:\RECYCLER\S-1-5-21-2121278286-1043422187-160470404-3289\nissan.exe,C:\RECYCLER\S-1-5-21-3051092228-1166181049-303274144-5805\nissan.exe,C:\RECYCLER\S-1-5-21-8585681285-5361595766-703231775-1118\nissan.exe,C:\RECYCLER\S-1-5-21-3169526979-3774492196-645545595-9758\nissan.exe,explorer.exe,C:\RECYCLER\S-1-5-21-8411314343-9828541303-862194347-7595\wnzip32.exe [98816 2010-03-01] () <==== ATTENTION MountPoints2: F - F:\LaunchU3.exe -a MountPoints2: H - H:\LaunchU3.exe -a MountPoints2: {10199ff6-0b5d-11e0-ab87-9f06c8297c8b} - G:\TREBALJO///nazdravljep.exe MountPoints2: {1c2bbfc7-fd97-11e1-ad21-a8b5336807a8} - G:\AutoRun.exe MountPoints2: {5c5835b9-5d0d-11da-9d8d-806d6172696f} - em8tqm.cmd MountPoints2: {a3ed0b80-cc64-11dd-a8de-001cf09bb708} - G:\p1y2.cmd MountPoints2: {a68aeda2-fda8-11e1-ad23-91aebebf3615} - G:\AutoRun.exe MountPoints2: {b02c3b4e-fd95-11e1-ad20-e71f4d66dd3f} - G:\AutoRun.exe MountPoints2: {d6df637d-2125-11df-aaa7-001cf09bb708} - H:\LaunchU3.exe -a MountPoints2: {e3f7867c-cc4e-11dc-a78c-0016e68b35b5} - G:\LaunchU3.exe -a MountPoints2: {f96f94fd-c460-11de-aa0a-001cf09bb708} - H:\USBNB.exe Lsa: [Notification Packages] :\WINDOWS\syste Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Acrobat Speed Launcher.lnk ShortcutTarget: Adobe Acrobat Speed Launcher.lnk -> C:\WINDOWS\Installer\{AC76BA86-1033-C740-7760-000000000002}\SC_Acrobat.exe () Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma.lnk ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\Documents and Settings\KONTRAST\Menu Start\Programy\Autostart\ihaupd32.exe (TWX Corp.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm URLSearchHook: (No Name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (Spigot, Inc.) SearchScopes: HKCU - {E3086A2F-FAF7-4737-A4C6-A51299E8DF86} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=971163&p={searchTerms} BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (Spigot, Inc.) BHO: No Name - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (Spigot, Inc.) Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM - pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (Spigot, Inc.) Toolbar: HKCU -&Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU -&Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation) Toolbar: HKCU -Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated) DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} https://www.bph.pl/sezam/components/SignActivX.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab ShellExecuteHooks: - {BB4C402F-882A-4526-8C08-51278EA437C1} - C:\WINDOWS\system32\afmain1.dll No File [ ] Winsock: Catalog9 01 C:\WINDOWS\system32\imon.dll [298104] (Eset ) Winsock: Catalog9 02 C:\WINDOWS\system32\imon.dll [298104] (Eset ) Winsock: Catalog9 03 C:\WINDOWS\system32\imon.dll [298104] (Eset ) Winsock: Catalog9 04 C:\WINDOWS\system32\imon.dll [298104] (Eset ) Winsock: Catalog9 05 C:\WINDOWS\system32\imon.dll [298104] (Eset ) Winsock: Catalog9 27 C:\WINDOWS\system32\imon.dll [298104] (Eset ) Tcpip\Parameters: [DhcpNameServer] 194.204.159.1 Tcpip\..\Interfaces\{3655446C-23BD-4BCF-A262-2E4B917D5A0F}: [NameServer]213.134.128.19,213.134.128.20 FireFox: ======== FF ProfilePath: C:\Documents and Settings\KONTRAST\Dane aplikacji\Mozilla\Firefox\Profiles\b9ncautv.default FF Homepage: www.onet.pl FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF Extension: pdfforge - C:\Program Files\Mozilla Firefox\extensions\pdfforge@mybrowserbar.com FF Extension: searchsettings - C:\Program Files\Mozilla Firefox\extensions\searchsettings@spigot.com ========================== Services (Whitelisted) ================= S2 Adobe Version Cue CS2; C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe [163840 2005-05-25] (Adobe Systems Incorporated) S2 ANIWZCSdService; C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe [49152 2007-01-19] (Wireless Service) R2 Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [380928 2010-01-08] (Spigot, Inc.) R2 NOD32krn; C:\Program Files\Eset\nod32krn.exe [552064 2011-05-14] (Eset ) S2 UTSCSI; C:\WINDOWS\system32\UTSCSI.EXE [0 2010-03-09] () ==================== Drivers (Whitelisted) ==================== S3 akshasp; C:\Windows\System32\DRIVERS\akshasp.sys [327808 2005-07-20] (Aladdin Knowledge Systems Ltd.) S3 aksusb; C:\Windows\System32\DRIVERS\aksusb.sys [100096 2005-07-20] (Aladdin Knowledge Systems Ltd.) R2 AMON; C:\Windows\system32\drivers\amon.sys [512096 2011-05-14] (Eset ) S2 ANIO; C:\WINDOWS\system32\ANIO.SYS [28195 2005-12-11] (Alpha Networks Inc.) R2 Hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [685056 2005-07-28] (Aladdin Knowledge Systems Ltd.) R2 Haspnt; C:\WINDOWS\system32\drivers\Haspnt.sys [47616 2005-11-24] (Aladdin Knowledge Systems) R3 ialm; C:\Windows\System32\DRIVERS\ialmnt5.sys [830684 2005-04-05] (Intel Corporation) S3 k750bus; C:\Windows\System32\DRIVERS\k750bus.sys [55216 2005-02-11] (MCCI) S3 k750mdfl; C:\Windows\System32\DRIVERS\k750mdfl.sys [6576 2005-02-11] (MCCI) S3 k750mdm; C:\Windows\System32\DRIVERS\k750mdm.sys [89872 2005-02-11] (MCCI) S3 k750mgmt; C:\Windows\System32\DRIVERS\k750mgmt.sys [81728 2005-02-11] (MCCI) S3 k750obex; C:\Windows\System32\DRIVERS\k750obex.sys [79488 2005-02-11] (MCCI) R1 nod32drv; C:\Windows\system32\drivers\nod32drv.sys [15424 2011-05-14] () S0 oujwhci; C:\Windows\System32\Drivers\oujwhci.sys [0 2011-03-08] () S3 RT61; C:\Windows\System32\DRIVERS\RT61.sys [380928 2006-05-04] (Ralink Technology Inc.) S3 rtl8139; C:\Windows\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation) S3 yukonwxp; C:\Windows\System32\DRIVERS\yk51x86.sys [223104 2004-10-27] (Marvell) S4 IntelIde; No ImagePath S0 NDIS; No ImagePath U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-12 23:07 - 2013-10-12 23:07 - 00000000 ____D C:\FRST 2013-10-12 23:06 - 2013-10-12 23:07 - 00000000 ____D C:\Documents and Settings\KONTRAST\Pulpit\Fixitpc ==================== One Month Modified Files and Folders ======= 2013-10-12 23:07 - 2013-10-12 23:07 - 00000000 ____D C:\FRST 2013-10-12 23:07 - 2013-10-12 23:06 - 00000000 ____D C:\Documents and Settings\KONTRAST\Pulpit\Fixitpc 2013-10-12 23:07 - 2005-11-24 18:45 - 00000000 ____D C:\Documents and Settings\KONTRAST\Pulpit 2013-10-12 23:06 - 2008-09-04 08:01 - 01032100 _____ C:\WINDOWS\setupapi.log 2013-10-12 23:00 - 2010-02-26 10:42 - 00000246 ____H C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job 2013-10-12 22:48 - 2005-11-24 19:28 - 00181161 _____ C:\WINDOWS\setupact.log 2013-10-12 22:47 - 2010-02-26 10:42 - 00000294 ____H C:\WINDOWS\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job 2013-10-12 22:47 - 2008-02-18 16:38 - 00000007 _____ C:\WINDOWS\system32\ANIWZCSUSERNAME 2013-10-12 22:47 - 2005-12-27 16:30 - 08405015 _____ C:\WINDOWS\TempFile 2013-10-12 22:47 - 2005-11-24 19:31 - 00000159 _____ C:\WINDOWS\wiadebug.log 2013-10-12 22:47 - 2005-11-24 19:31 - 00000050 _____ C:\WINDOWS\wiaservc.log 2013-10-12 22:47 - 2005-11-24 18:44 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-10-12 22:47 - 2005-11-24 18:40 - 01092259 _____ C:\WINDOWS\WindowsUpdate.log 2013-10-12 22:46 - 2004-08-04 14:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl Files to move or delete: ==================== C:\Documents and Settings\KONTRAST\reader_s.exe C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job Some content of TEMP: ==================== C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\070.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\088.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\284.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\535.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\617.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\790.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\856.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\894.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\995.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\apatch.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\crxt.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\DataCard_Setup.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\elika.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\htdkw.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\iqgfypvt.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\jnnpkn.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\ldewlp.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\Opb.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\Opc.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\Opd.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\Ope.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\Opf.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\Opg.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\Oph.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\Opi.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\Opj.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\Opk.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\Opl.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\Opm.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\pdfupd.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\ResetDevice.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\rjvjlsvw.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\sshnas21.dll C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\tdkbvyq.exe C:\Documents and Settings\KONTRAST\Ustawienia lokalne\Temp\vmmim.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe [2008-08-27 17:35] - [2008-04-14 19:21] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\Windows\System32\winlogon.exe [2008-08-27 17:34] - [2008-04-14 19:21] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\Windows\System32\svchost.exe [2008-08-27 17:34] - [2008-04-14 19:21] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\Windows\System32\services.exe [2008-08-27 17:34] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f C:\Windows\System32\User32.dll [2008-08-27 17:34] - [2008-04-14 19:20] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\Windows\System32\userinit.exe [2008-08-27 17:34] - [2008-04-14 19:21] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\Windows\System32\Drivers\volsnap.sys [2008-08-27 17:34] - [2008-04-14 18:01] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================