Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-10-2013 01 Ran by e (administrator) on GH-404AFC3B0F5B on 25-10-2013 17:52:30 Running from C:\Documents and Settings\e\Moje dokumenty Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AVG Technologies CZ, s.r.o.) D:\avg\avgrsx.exe (AVG Technologies CZ, s.r.o.) D:\avg\avgcsrvx.exe (AVG Technologies CZ, s.r.o.) D:\avg\avgidsagent.exe (AVG Technologies CZ, s.r.o.) D:\avg\avgwdsvc.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe () C:\WINDOWS\system32\PnkBstrA.exe () C:\WINDOWS\system32\PnkBstrB.exe () C:\Program Files\VIA\RAID\vialogsv.exe (AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\loggingserver.exe (AVG Technologies CZ, s.r.o.) D:\avg\avgnsx.exe (AVG Technologies CZ, s.r.o.) D:\avg\avgemcx.exe () C:\Program Files\AVG Secure Search\vprot.exe (Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE (AVG Technologies CZ, s.r.o.) D:\avg\avgui.exe () C:\Program Files\VIA\RAID\raid_tool.exe (SweetIM Technologies Ltd.) C:\Program Files\SweetIM\Messenger\SweetIM.exe () C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe (Spotify Ltd) C:\Documents and Settings\e\Dane aplikacji\Spotify\Data\SpotifyWebHelper.exe () C:\Program Files\RocketDock\RocketDock.exe () C:\Program Files\Pando Networks\Media Booster\PMB.exe (WebCake LLC) C:\Documents and Settings\e\Dane aplikacji\Betcat\WebCakeDesktop.exe (Sony) C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe () C:\Program Files\Rainmeter\Rainmeter.exe (Almico Software (www.almico.com)) C:\Program Files\SpeedFan\speedfan.exe (Google Inc.) C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.165\GoogleCrashHandler.exe () C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Google Inc.) C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [vProt] - C:\Program Files\AVG Secure Search\vprot.exe [2404376 2013-10-12] () HKLM\...\Run: [PWRISOVM.EXE] - C:\Program Files\PowerISO\PWRISOVM.EXE [336992 2012-08-17] (Power Software Ltd) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [AVG_UI] - D:\avg\avgui.exe [4411952 2013-09-23] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [AudioDeck] - C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe [528384 2007-08-09] (VIA Technologies, Inc.) HKLM\...\Run: [VIARaidUtl] - C:\Program Files\VIA\RAID\raid_tool.exe [4914840 2008-07-24] () HKLM\...\Run: [CmPCIaudio] - RunDll32 CMICNFG3.CPL,CMICtrlWnd HKLM\...\Run: [SweetIM] - C:\Program Files\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.) HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [nwiz] - nwiz.exe /install HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit HKCU\...\Run: [Google Update] - C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [116648 2012-08-21] (Google Inc.) HKCU\...\Run: [KiesPDLR] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-08-07] () HKCU\...\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation) HKCU\...\Run: [Spotify Web Helper] - C:\Documents and Settings\e\Dane aplikacji\Spotify\Data\SpotifyWebHelper.exe [1140736 2013-10-13] (Spotify Ltd) HKCU\...\Run: [RocketDock] - C:\Program Files\RocketDock\RocketDock.exe [495616 2007-09-02] () HKCU\...\Run: [Pando Media Booster] - C:\Program Files\Pando Networks\Media Booster\PMB.exe [4284976 2013-05-11] () HKCU\...\Run: [WebCake Desktop] - C:\Documents and Settings\e\Dane aplikacji\Betcat\WebCakeDesktop.exe [50968 2013-08-23] (WebCake LLC) HKCU\...\Run: [ares] - C:\Program Files\Ares\Ares.exe [934400 2013-02-14] (Ares Development Group) HKCU\...\Run: [Sony PC Companion] - C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [449248 2013-05-29] (Sony) HKCU\...\Run: [Facebook Update] - C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Facebook\Update\FacebookUpdate.exe [138096 2013-10-23] (Facebook Inc.) HKU\Administrator\...\Run: [AVG-Secure-Search-Update_JUNE2013_TB] - C:\Program Files\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe [ 2013-05-31] (AVG Secure Search) HKU\Administrator\...\Run: [AVG-Secure-Search-Update_JUNE2013_HP] - C:\Program Files\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_HP.exe [ 2013-06-08] (AVG Secure Search) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (McAfee, Inc.) Startup: C:\Documents and Settings\e\Menu Start\Programy\Autostart\Facebook Messenger.lnk ShortcutTarget: Facebook Messenger.lnk -> C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (Facebook) Startup: C:\Documents and Settings\e\Menu Start\Programy\Autostart\hamachi.lnk ShortcutTarget: hamachi.lnk -> C:\Program Files\Hamachi\hamachi.exe (LogMeIn Inc.) Startup: C:\Documents and Settings\e\Menu Start\Programy\Autostart\Rainmeter.lnk ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe () Startup: C:\Documents and Settings\e\Menu Start\Programy\Autostart\SpeedFan.lnk ShortcutTarget: SpeedFan.lnk -> C:\Program Files\SpeedFan\speedfan.exe (Almico Software (www.almico.com)) SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - No File BootExecute: autocheck autochk * sprestrtD:\avg\avgrsx.exe /sync /restart ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=128 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://search.babylon.com/?affID=110808&tt=3412_4&babsrc=HP_ss&mntrId=903cdfbb0000000000007a7905b7cb01 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=pbr&from=pbr&uid=5JVM97QV_ST340014A&ts=1362143746 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=pbr&from=pbr&uid=5JVM97QV_ST340014A&ts=1362143746 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com/?utm_source=b&utm_medium=pbr&from=pbr&uid=5JVM97QV_ST340014A&ts=1362143746 HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm URLSearchHook: uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.) URLSearchHook: (No Name) - {16CC3586-3547-4025-9E2F-F04C365D8B90} - No File SearchScopes: HKLM - DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10009&barid={342EB569-45D8-11E2-959D-003018CBADBC} SearchScopes: HKLM - Backup.Old.DefaultScope {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} SearchScopes: HKLM - {30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12} URL = http://www.searchya.com/?q={searchTerms}&s=1&a=foxtab&chnl=tc-100&cd=2XzuyEtN2Y1L1QzuyB0AyBzytDyD0ByB0C0BtDtC0D0F0B0BtN0D0Tzu0StBtAtAtN1L2XzutBtFtCtFtCtFtAtCtB&cr=688992464 SearchScopes: HKLM - {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=ironpub&chnl=ironpub&cd=2XzuyEtN2Y1L1QzuyB0AyBzytDyD0ByB0C0BtDtC0D0F0B0BtN0D0Tzu0StBtAtAtN1L2XzutBtFtCtFtCtFtAtCtB&cr=688992464 SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10009&barid={342EB569-45D8-11E2-959D-003018CBADBC} SearchScopes: HKCU - DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={02818A4E-076C-482E-8871-E01C9F583D1F}&mid=3c4ec686dd8447d0b798ab30435322f2-b602d594afd2b0b327e07a06f36ca6a7e42546d0&lang=pl&ds=tc011&pr=sa&d=2012-09-29 14:41:09&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} SearchScopes: HKCU - Backup.Old.DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=903C00C0DF0FC240&affID=119828&tt=160713_91114&tsp=4945 SearchScopes: HKCU - {16CC3586-3547-4025-9E2F-F04C365D8B90} URL = http://search.eazel.com/results.php?cat=web&co=&lg=en&q={searchTerms} SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=CE1DA4A0-7D69-4B8C-8C39-05A021B92234&apn_sauid=FB6BB294-467B-47C4-8590-7D2E6CE4306A SearchScopes: HKCU - {30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12} URL = http://www.searchya.com/?q={searchTerms}&s=1&a=foxtab&chnl=tc-100&cd=2XzuyEtN2Y1L1QzuyB0AyBzytDyD0ByB0C0BtDtC0D0F0B0BtN0D0Tzu0StBtAtAtN1L2XzutBtFtCtFtCtFtAtCtB&cr=688992464 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={02818A4E-076C-482E-8871-E01C9F583D1F}&mid=3c4ec686dd8447d0b798ab30435322f2-b602d594afd2b0b327e07a06f36ca6a7e42546d0&lang=pl&ds=tc011&pr=sa&d=2012-09-29 14:41:09&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468 SearchScopes: HKCU - {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=ironpub&chnl=ironpub&cd=2XzuyEtN2Y1L1QzuyB0AyBzytDyD0ByB0C0BtDtC0D0F0B0BtN0D0Tzu0StBtAtAtN1L2XzutBtFtCtFtCtFtAtCtB&cr=688992464 SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10009&barid={342EB569-45D8-11E2-959D-003018CBADBC} BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Ironsource LTD Helper Object - {25927741-5E5B-4D27-8D8B-9188FE64373F} - C:\PROGRA~1\SearchYa!\1.5.25.0\bh\searchya.dll (Montera Technologeis LTD) BHO: WebCake - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:\Program Files\WebCake\WebCakeIEClient.dll (WebCake LLC) BHO: uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.) BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\17.0.1.12\AVG Secure Search_toolbar.dll (AVG Secure Search) BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.21.5\bh\delta.dll (Delta-search.com) Toolbar: HKLM - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\17.0.1.12\AVG Secure Search_toolbar.dll (AVG Secure Search) Toolbar: HKLM - No Name - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - No File Toolbar: HKLM - SearchYa Toolbar - {33AA308B-B565-4376-AC66-59EE9B6AD13E} - C:\PROGRA~1\SearchYa!\1.5.25.0\searchyaTlbr.dll (Montera Technologeis LTD) Toolbar: HKLM - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.) Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.21.5\deltaTlbr.dll (Delta-search.com) Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation) Toolbar: HKCU - uTorrentControl_v2 Toolbar - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.) Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll (AVG Secure Search) Hosts: 74.125.230.84 4 moviestarplanet.com # Tcpip\Parameters: [DhcpNameServer] 192.168.168.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.12\\npsitesafety.dll (AVG Technologies) FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin: @real.com/nppl3260;version=6.0.12.69 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.69 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml FF HKLM\...\Firefox\Extensions: [avg@toolbar] - C:\Documents and Settings\All Users\Dane aplikacji\AVG Secure Search\FireFoxExt\17.0.1.12 FF Extension: AVG Security Toolbar - C:\Documents and Settings\All Users\Dane aplikacji\AVG Secure Search\FireFoxExt\17.0.1.12 FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ Chrome: ======= CHR HomePage: hxxp://www.gazeta.pl/0,0.html?p=128 CHR RestoreOnStartup: "hxxp://search.babylon.com/?affID=119776&tt=gc_&babsrc=HP_ss_din2g&mntrId=903C003018CBADBC", "hxxp://www.delta-search.com/?affID=119776&tt=gc_&babsrc=HP_ss&mntrId=903C003018CBADBC" CHR Extension: (Stickman) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\acfhjcbakbeldmlfghoaaalejnekaknd\1.0.1_0 CHR Extension: (Plants vs. Zombies HD) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ahdfeknjbgfbkmemaoffkebceonhcjfd\1.0.0_0 CHR Extension: (Big Time Gangsta) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ajplbhgiljhgjomddcnchfoimakkbmkc\1.2.2_0 CHR Extension: (Angry Birds) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0 CHR Extension: (Theme Creator) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllgombffc\2.5_0 CHR Extension: (Turn Off the Lights) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.2.0.22_0 CHR Extension: (SearchYa __MSG_newtab__) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\9.4.1_0 CHR Extension: (Adblock for Youtube\u2122) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk\2.9_0 CHR Extension: (Kingdoms Of Camelot) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\dkadejngfdiifodimfhejphllfecigmm\1.1_0 CHR Extension: (The Godfather: Five Families) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\edfkoljdeffeedleidebkmmamepgbnbl\1.2_0 CHR Extension: (uTorrentControl_v2) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.16.100.504_0 CHR Extension: (Delta Toolbar) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.5.1_0 CHR Extension: (Stylish) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe\1.2_0 CHR Extension: (WebCake) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh\1.0.3_1 CHR Extension: (AdBlock) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.10_0 CHR Extension: (Cut the Rope) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\gkddaofiamhgfjmaccfcfpfolpgbeomj\16_0 CHR Extension: (Website Blocker (Beta)) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\hclgegipaehbigmbhdpfapmjadbaldib\0.2.4_0 CHR Extension: (The Walking Dead) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\hohiiopfdolnjdlkocccddkmlghhnadh\1.0.0_0 CHR Extension: (WGT Baseball: MLB) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\hpbjopfokekaencoephlgdbnljhcflhm\2.1.2_0 CHR Extension: (SweetIM for Facebook) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0 CHR Extension: (Cargo Bridge) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\keembkgclppcbilkekfgpobhldjjhpmn\1.5.7_0 CHR Extension: (Torntv 2) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje\1.0_0 CHR Extension: (AVG Secure Search) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0 CHR Extension: (Wolverine) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nkdhgfoolofphkohccekdkoeocleaiin\1.0_0 CHR Extension: (Chrome In-App Payments service) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Gem Invasion) - C:\DOCUME~1\e\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nndmjlhmogchhmpbdehpnjanijdalhnh\3.0_0 CHR HKLM\...\Chrome\Extension: [bbjciahceamgodcoidkjpchnokgfpphh] - C:\DOCUME~1\e\USTAWI~1\DANEAP~1\funmoods.crx CHR HKLM\...\Chrome\Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C:\DOCUME~1\e\USTAWI~1\DANEAP~1\speeddial.crx CHR HKLM\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx CHR HKLM\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Documents and Settings\e\Dane aplikacji\BabSolution\CR\Delta.crx CHR HKLM\...\Chrome\Extension: [fjoijdanhaiflhibkljeklcghcmmfffh] - C:\Program Files\Betcat\WebCakeLayers.crx CHR HKLM\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx CHR HKLM\...\Chrome\Extension: [nbmafkdmkkckhggblphicnnhlgljnoje] - C:\Program Files\TornTV.com\torn2_10.crx CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\Documents and Settings\All Users\Dane aplikacji\AVG Secure Search\ChromeExt\17.0.1.12\avg.crx CHR HKLM\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx ========================== Services (Whitelisted) ================= R2 AVGIDSAgent; D:\avg\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.) R2 avgwd; D:\avg\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [235216 2013-09-06] (McAfee, Inc.) R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [66872 2013-05-04] () R2 PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [103736 2013-05-04] () S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) R2 VRAID Log Service; C:\Program Files\VIA\RAID\vialogsv.exe [45056 2008-07-09] () R2 vToolbarUpdater17.0.12; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe [1734680 2013-10-12] (AVG Secure Search) ==================== Drivers (Whitelisted) ==================== S3 arusb(TP-LINK); C:\Windows\System32\DRIVERS\arusb.sys [598528 2010-02-25] (Atheros Communications, Inc.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-09-05] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [37664 2013-10-12] (AVG Technologies) R3 cmuda3; C:\Windows\System32\drivers\cmuda3.sys [801280 2004-09-24] (C-Media Inc) S3 DrvAgent32; C:\WINDOWS\system32\Drivers\DrvAgent32.sys [23456 2012-09-29] (Phoenix Technologies) S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [27165 2001-08-17] (VIA Technologies, Inc. ) R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [25280 2013-10-12] (LogMeIn, Inc.) R3 rtl8139; C:\Windows\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation) S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation) S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation) S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation) S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation) S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [25512 2008-05-16] (MCCI Corporation) S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation) S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [115752 2008-05-16] (MCCI Corporation) R1 SCDEmu; C:\Windows\System32\Drivers\SCDEmu.sys [113104 2012-08-17] (Power Software Ltd) S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2010-07-01] (Screaming Bee LLC) R0 sfvfs02; C:\Windows\System32\drivers\sfvfs02.sys [66048 2005-09-29] (Protection Technology) R0 speedfan; C:\Windows\System32\speedfan.sys [25240 2011-03-18] (Almico Software) S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13024 2012-10-04] () S3 taphss; C:\Windows\System32\DRIVERS\taphss.sys [33512 2012-08-01] (AnchorFree Inc) R0 viamraid; C:\Windows\System32\DRIVERS\viamraid.sys [117248 2008-07-10] (VIA Technologies inc,.ltd) S3 VIAudio; C:\Windows\System32\drivers\vinyl97.sys [207488 2007-06-27] (VIA Technologies, Inc.) R0 videX32; C:\Windows\System32\DRIVERS\videX32.sys [9216 2007-11-21] (VIA Technologies, Inc.) S3 WinRing0_1_2_0; C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys [14416 2010-11-01] (OpenLibSys.org) S3 ALCXWDM; system32\drivers\ALCXWDM.SYS [x] S3 RivaTuner32; \??\C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys [x] S3 s3chipid; \??\C:\DOCUME~1\e\USTAWI~1\Temp\s3chipid.sys [x] U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation) U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-25 17:51 - 2013-10-25 17:51 - 01088113 _____ (Farbar) C:\Documents and Settings\e\Moje dokumenty\FRST.exe 2013-10-25 17:51 - 2013-10-25 17:51 - 00000000 ____D C:\FRST 2013-10-25 15:10 - 2013-10-25 15:11 - 10012564 _____ C:\Documents and Settings\e\Moje dokumenty\spelunky_1_1.zip 2013-10-24 17:34 - 2013-10-24 17:34 - 00000000 ____D C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\uTorrentControl_v2 2013-10-24 17:33 - 2013-10-24 17:33 - 00000000 ____D C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Apple 2013-10-24 16:48 - 2013-10-24 16:48 - 00009022 _____ C:\WINDOWS\DPINST.LOG 2013-10-24 16:48 - 2013-10-24 16:48 - 00001745 _____ C:\Documents and Settings\All Users\Pulpit\Sony PC Companion 2.1.lnk 2013-10-24 06:57 - 2013-10-24 06:57 - 00685248 _____ C:\Documents and Settings\e\Moje dokumenty\HijackThis(12030).exe 2013-10-24 06:49 - 2013-10-24 06:50 - 00685248 _____ C:\Documents and Settings\e\Moje dokumenty\ZoneAlarm(12684).exe 2013-10-23 17:33 - 2013-10-23 17:33 - 00000000 ____D C:\Documents and Settings\e\Menu Start\Programy\Facebook 2013-10-23 17:32 - 2013-10-25 17:38 - 00000986 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-436374069-2139871995-1417001333-1004UA.job 2013-10-23 17:32 - 2013-10-25 17:37 - 00000964 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-436374069-2139871995-1417001333-1004Core.job 2013-10-23 17:27 - 2013-10-23 17:27 - 00501240 _____ (Facebook Inc.) C:\Documents and Settings\e\Moje dokumenty\FacebookMessengerSetup_v1.2.205.0.exe 2013-10-23 15:12 - 2013-10-23 15:12 - 00000000 ____D C:\Documents and Settings\Dominika\Ustawienia lokalne\Dane aplikacji\Adobe 2013-10-23 14:41 - 2013-10-23 14:41 - 00000104 _____ C:\Documents and Settings\Dominika\Pulpit\Internet.lnk 2013-10-22 15:26 - 2013-10-22 15:26 - 00001422 _____ C:\WINDOWS\wmsetup.log 2013-10-22 15:05 - 2013-10-22 15:05 - 00065536 _____ C:\WINDOWS\Minidump\Mini102213-01.dmp 2013-10-22 11:01 - 2013-10-22 11:01 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\gBurner 2013-10-21 19:34 - 2013-10-21 19:34 - 00000000 ____D C:\Documents and Settings\e\Dane aplikacji\gBurner 2013-10-21 19:33 - 2013-10-21 19:33 - 00000672 _____ C:\Documents and Settings\All Users\Pulpit\gBurner.lnk 2013-10-21 19:31 - 2013-10-22 11:00 - 00000000 ____D C:\Program Files\gBurner 2013-10-21 19:31 - 2013-10-21 19:31 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\gBurner 2013-10-17 11:23 - 2013-10-25 17:20 - 00008825 _____ C:\WINDOWS\setupapi.log 2013-10-17 11:22 - 2013-10-17 11:22 - 00000000 _____ C:\WINDOWS\setuperr.log 2013-10-17 11:22 - 2013-10-17 11:22 - 00000000 _____ C:\WINDOWS\setupact.log 2013-10-16 12:39 - 2013-10-16 12:39 - 00001783 _____ C:\Documents and Settings\All Users\Pulpit\McAfee Security Scan Plus.lnk 2013-10-16 12:39 - 2013-10-16 12:39 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\McAfee Security Scan Plus 2013-10-15 09:01 - 2013-10-23 15:12 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\Adobe 2013-10-15 09:01 - 2013-10-15 09:01 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\Macromedia 2013-10-15 09:00 - 2013-10-15 09:00 - 00000000 ____D C:\Documents and Settings\Dominika\Ustawienia lokalne\Dane aplikacji\Opera 2013-10-15 09:00 - 2013-10-15 09:00 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\Opera 2013-10-15 08:56 - 2013-10-15 08:56 - 00000809 _____ C:\Documents and Settings\Dominika\Menu Start\Programy\Internet Explorer.lnk 2013-10-15 08:56 - 2013-10-15 08:56 - 00000000 ____D C:\Documents and Settings\Dominika\Ustawienia lokalne\Dane aplikacji\Avg2013 2013-10-15 08:56 - 2013-10-15 08:56 - 00000000 ____D C:\Documents and Settings\Dominika\Ustawienia lokalne\Dane aplikacji\AVG Secure Search 2013-10-15 08:56 - 2013-10-15 08:56 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\AVG2013 2013-10-15 08:56 - 2013-10-15 08:56 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\AVG Secure Search 2013-10-15 08:55 - 2013-10-23 15:18 - 00000188 ___SH C:\Documents and Settings\Dominika\ntuser.ini 2013-10-15 08:55 - 2013-10-23 15:12 - 00000000 ___HD C:\Documents and Settings\Dominika\Ustawienia lokalne\Dane aplikacji 2013-10-15 08:55 - 2013-10-23 14:41 - 00000000 ____D C:\Documents and Settings\Dominika\Pulpit 2013-10-15 08:55 - 2013-10-22 11:01 - 00000000 __RHD C:\Documents and Settings\Dominika\Dane aplikacji 2013-10-15 08:55 - 2013-10-15 14:08 - 00000000 ___RD C:\Documents and Settings\Dominika\Moje dokumenty\Moje obrazy 2013-10-15 08:55 - 2013-10-15 08:59 - 00000000 ___HD C:\Documents and Settings\Dominika\Ustawienia lokalne 2013-10-15 08:55 - 2013-10-15 08:56 - 00000744 _____ C:\Documents and Settings\Dominika\Menu Start\Programy\Outlook Express.lnk 2013-10-15 08:55 - 2013-10-15 08:56 - 00000000 ___RD C:\Documents and Settings\Dominika\Ulubione 2013-10-15 08:55 - 2013-10-15 08:56 - 00000000 ___RD C:\Documents and Settings\Dominika\Moje dokumenty\Moja muzyka 2013-10-15 08:55 - 2013-10-15 08:56 - 00000000 ___RD C:\Documents and Settings\Dominika\Moje dokumenty 2013-10-15 08:55 - 2013-10-15 08:56 - 00000000 ___RD C:\Documents and Settings\Dominika\Menu Start\Programy\Akcesoria 2013-10-15 08:55 - 2013-10-15 08:56 - 00000000 ___RD C:\Documents and Settings\Dominika\Menu Start\Programy 2013-10-15 08:55 - 2013-10-15 08:55 - 00000798 _____ C:\Documents and Settings\Dominika\Menu Start\Programy\Windows Media Player.lnk 2013-10-15 08:55 - 2013-10-15 08:55 - 00000000 __SHD C:\Documents and Settings\Dominika\IETldCache 2013-10-15 08:55 - 2013-10-15 08:55 - 00000000 ____D C:\Documents and Settings\Dominika 2013-10-15 08:55 - 2012-09-21 11:00 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\TuneUp Software 2013-10-15 08:55 - 2012-08-12 07:28 - 00000000 __SHD C:\Documents and Settings\Dominika\Ustawienia lokalne\Historia 2013-10-15 08:55 - 2012-08-12 07:28 - 00000000 ___RD C:\Documents and Settings\Dominika\Menu Start\Programy\Autostart 2013-10-15 08:55 - 2012-08-12 07:28 - 00000000 ___RD C:\Documents and Settings\Dominika\Menu Start 2013-10-15 08:55 - 2012-08-12 05:33 - 00000000 ___HD C:\Documents and Settings\Dominika\Szablony 2013-10-15 08:55 - 2003-12-31 22:51 - 00001599 _____ C:\Documents and Settings\Dominika\Menu Start\Programy\Pomoc zdalna.lnk 2013-10-12 18:27 - 2013-10-25 17:17 - 00000000 ____D C:\Documents and Settings\e\Dane aplikacji\Hamachi 2013-10-12 18:25 - 2013-10-12 18:27 - 00000000 ____D C:\Program Files\Hamachi 2013-10-12 18:25 - 2013-10-12 18:25 - 00000638 _____ C:\Documents and Settings\All Users\Pulpit\hamachi.lnk 2013-10-12 18:25 - 2013-10-12 18:25 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Hamachi 2013-09-28 10:09 - 2013-09-28 10:09 - 00000474 _____ C:\Documents and Settings\e\Pulpit\Scarface.lnk 2013-09-28 10:09 - 2013-09-28 10:09 - 00000000 ____D C:\Documents and Settings\e\Menu Start\Programy\Radical Games ==================== One Month Modified Files and Folders ======= 2013-10-25 17:56 - 2013-05-11 11:45 - 00000000 ____D C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\PMB Files 2013-10-25 17:51 - 2013-10-25 17:51 - 01088113 _____ (Farbar) C:\Documents and Settings\e\Moje dokumenty\FRST.exe 2013-10-25 17:51 - 2013-10-25 17:51 - 00000000 ____D C:\FRST 2013-10-25 17:51 - 2012-08-12 05:41 - 00000000 ___RD C:\Documents and Settings\e\Moje dokumenty 2013-10-25 17:38 - 2013-10-23 17:32 - 00000986 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-436374069-2139871995-1417001333-1004UA.job 2013-10-25 17:38 - 2012-08-12 05:40 - 00032370 _____ C:\WINDOWS\SchedLgU.Txt 2013-10-25 17:38 - 2012-08-12 05:40 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-10-25 17:37 - 2013-10-23 17:32 - 00000964 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-436374069-2139871995-1417001333-1004Core.job 2013-10-25 17:24 - 2012-08-12 05:35 - 01216180 _____ C:\WINDOWS\WindowsUpdate.log 2013-10-25 17:20 - 2013-10-17 11:23 - 00008825 _____ C:\WINDOWS\setupapi.log 2013-10-25 17:17 - 2013-10-12 18:27 - 00000000 ____D C:\Documents and Settings\e\Dane aplikacji\Hamachi 2013-10-25 17:16 - 2012-09-29 15:24 - 00000000 ____D C:\Program Files\SpeedFan 2013-10-25 17:16 - 2004-10-29 16:50 - 00017145 _____ C:\WINDOWS\system32\nvapps.xml 2013-10-25 17:15 - 2013-06-08 17:39 - 00000350 _____ C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job 2013-10-25 17:15 - 2013-05-31 19:25 - 00000350 _____ C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2013-10-25 17:15 - 2013-01-05 13:41 - 00000270 _____ C:\WINDOWS\Tasks\Game_Booster_AutoUpdate.job 2013-10-25 17:15 - 2012-12-14 12:20 - 00000290 _____ C:\WINDOWS\Tasks\Express FilesUpdate.job 2013-10-25 17:15 - 2008-04-15 14:00 - 00012598 _____ C:\WINDOWS\system32\wpa.dbl 2013-10-25 17:11 - 2012-11-09 07:48 - 00001176 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-2139871995-1417001333-1005UA.job 2013-10-25 17:07 - 2013-03-30 12:15 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-10-25 17:01 - 2013-08-10 08:39 - 00000000 ____D C:\Documents and Settings\e\Dane aplikacji\Betcat 2013-10-25 17:00 - 2012-08-21 12:34 - 00001116 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-2139871995-1417001333-1004UA.job 2013-10-25 16:09 - 2012-08-22 00:11 - 00103714 _____ C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat 2013-10-25 16:09 - 2012-08-12 05:41 - 00000188 ___SH C:\Documents and Settings\e\ntuser.ini 2013-10-25 15:11 - 2013-10-25 15:10 - 10012564 _____ C:\Documents and Settings\e\Moje dokumenty\spelunky_1_1.zip 2013-10-25 14:48 - 2004-01-01 00:22 - 1073299456 _____ C:\WINDOWS\MEMORY.DMP 2013-10-25 13:04 - 2012-08-21 12:49 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\MFAData 2013-10-25 07:33 - 2012-10-02 08:01 - 00000188 ___SH C:\Documents and Settings\Administrator\ntuser.ini 2013-10-24 17:34 - 2013-10-24 17:34 - 00000000 ____D C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\uTorrentControl_v2 2013-10-24 17:34 - 2012-08-12 05:40 - 00000000 ___HD C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji 2013-10-24 17:33 - 2013-10-24 17:33 - 00000000 ____D C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Apple 2013-10-24 17:33 - 2013-04-13 17:12 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job 2013-10-24 16:48 - 2013-10-24 16:48 - 00009022 _____ C:\WINDOWS\DPINST.LOG 2013-10-24 16:48 - 2013-10-24 16:48 - 00001745 _____ C:\Documents and Settings\All Users\Pulpit\Sony PC Companion 2.1.lnk 2013-10-24 16:48 - 2013-08-28 19:51 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Sony 2013-10-24 16:48 - 2012-08-12 07:28 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit 2013-10-24 16:39 - 2012-08-12 06:02 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-10-24 14:00 - 2012-08-21 12:34 - 00001064 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-2139871995-1417001333-1004Core.job 2013-10-24 07:11 - 2012-11-09 07:47 - 00001124 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-2139871995-1417001333-1005Core.job 2013-10-24 06:57 - 2013-10-24 06:57 - 00685248 _____ C:\Documents and Settings\e\Moje dokumenty\HijackThis(12030).exe 2013-10-24 06:50 - 2013-10-24 06:49 - 00685248 _____ C:\Documents and Settings\e\Moje dokumenty\ZoneAlarm(12684).exe 2013-10-23 20:43 - 2012-08-22 00:11 - 00625274 _____ C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-436374069-2139871995-1417001333-1004-0.dat 2013-10-23 19:54 - 2013-03-10 10:58 - 00000000 ____D C:\Documents and Settings\e\Dane aplikacji\Spotify 2013-10-23 17:34 - 2012-08-12 05:41 - 00000000 ___RD C:\Documents and Settings\e\Menu Start\Programy\Autostart 2013-10-23 17:33 - 2013-10-23 17:33 - 00000000 ____D C:\Documents and Settings\e\Menu Start\Programy\Facebook 2013-10-23 17:33 - 2012-08-12 05:41 - 00000000 ___RD C:\Documents and Settings\e\Menu Start\Programy 2013-10-23 17:30 - 2012-12-29 14:45 - 00000000 ____D C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Facebook 2013-10-23 17:27 - 2013-10-23 17:27 - 00501240 _____ (Facebook Inc.) C:\Documents and Settings\e\Moje dokumenty\FacebookMessengerSetup_v1.2.205.0.exe 2013-10-23 15:18 - 2013-10-15 08:55 - 00000188 ___SH C:\Documents and Settings\Dominika\ntuser.ini 2013-10-23 15:12 - 2013-10-23 15:12 - 00000000 ____D C:\Documents and Settings\Dominika\Ustawienia lokalne\Dane aplikacji\Adobe 2013-10-23 15:12 - 2013-10-15 09:01 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\Adobe 2013-10-23 15:12 - 2013-10-15 08:55 - 00000000 ___HD C:\Documents and Settings\Dominika\Ustawienia lokalne\Dane aplikacji 2013-10-23 14:41 - 2013-10-23 14:41 - 00000104 _____ C:\Documents and Settings\Dominika\Pulpit\Internet.lnk 2013-10-23 14:41 - 2013-10-15 08:55 - 00000000 ____D C:\Documents and Settings\Dominika\Pulpit 2013-10-22 16:47 - 2013-04-12 17:29 - 00130048 __SHC C:\Documents and Settings\e\Moje dokumenty\Thumbs.db 2013-10-22 15:26 - 2013-10-22 15:26 - 00001422 _____ C:\WINDOWS\wmsetup.log 2013-10-22 15:05 - 2013-10-22 15:05 - 00065536 _____ C:\WINDOWS\Minidump\Mini102213-01.dmp 2013-10-22 15:05 - 2012-08-23 08:46 - 00000000 ____D C:\WINDOWS\Minidump 2013-10-22 11:01 - 2013-10-22 11:01 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\gBurner 2013-10-22 11:01 - 2013-10-15 08:55 - 00000000 __RHD C:\Documents and Settings\Dominika\Dane aplikacji 2013-10-22 11:00 - 2013-10-21 19:31 - 00000000 ____D C:\Program Files\gBurner 2013-10-21 19:34 - 2013-10-21 19:34 - 00000000 ____D C:\Documents and Settings\e\Dane aplikacji\gBurner 2013-10-21 19:34 - 2012-08-12 05:41 - 00000000 __RHD C:\Documents and Settings\e\Dane aplikacji 2013-10-21 19:33 - 2013-10-21 19:33 - 00000672 _____ C:\Documents and Settings\All Users\Pulpit\gBurner.lnk 2013-10-21 19:31 - 2013-10-21 19:31 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\gBurner 2013-10-21 19:31 - 2012-08-12 07:28 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy 2013-10-21 19:09 - 2012-08-21 17:11 - 00000000 ____D C:\Documents and Settings\e\Dane aplikacji\uTorrent 2013-10-21 18:12 - 2013-03-10 11:01 - 00000000 ____D C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\Spotify 2013-10-20 08:56 - 2012-08-22 11:50 - 00085504 _____ C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-10-17 11:22 - 2013-10-17 11:22 - 00000000 _____ C:\WINDOWS\setuperr.log 2013-10-17 11:22 - 2013-10-17 11:22 - 00000000 _____ C:\WINDOWS\setupact.log 2013-10-17 08:41 - 2013-02-09 16:54 - 00000000 ____D C:\Documents and Settings\e\Dane aplikacji\Media Player Classic 2013-10-17 08:41 - 2012-08-12 05:41 - 00000000 ____D C:\Documents and Settings\e 2013-10-16 13:46 - 2013-07-08 22:44 - 00002276 _____ C:\Documents and Settings\e\Pulpit\Google Chrome.lnk 2013-10-16 12:39 - 2013-10-16 12:39 - 00001783 _____ C:\Documents and Settings\All Users\Pulpit\McAfee Security Scan Plus.lnk 2013-10-16 12:39 - 2013-10-16 12:39 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\McAfee Security Scan Plus 2013-10-16 12:39 - 2012-08-21 12:37 - 00000000 ____D C:\Program Files\McAfee Security Scan 2013-10-16 12:39 - 2012-08-12 07:28 - 00000000 ___RD C:\Documents and Settings\All Users\Menu Start\Programy\Autostart 2013-10-16 12:39 - 2012-08-12 05:41 - 00000000 ___RD C:\Documents and Settings\e\Moje dokumenty\Moje obrazy 2013-10-15 14:08 - 2013-10-15 08:55 - 00000000 ___RD C:\Documents and Settings\Dominika\Moje dokumenty\Moje obrazy 2013-10-15 13:48 - 2013-01-26 15:09 - 00000188 ___SH C:\Documents and Settings\Radek\ntuser.ini 2013-10-15 09:01 - 2013-10-15 09:01 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\Macromedia 2013-10-15 09:00 - 2013-10-15 09:00 - 00000000 ____D C:\Documents and Settings\Dominika\Ustawienia lokalne\Dane aplikacji\Opera 2013-10-15 09:00 - 2013-10-15 09:00 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\Opera 2013-10-15 08:59 - 2013-10-15 08:55 - 00000000 ___HD C:\Documents and Settings\Dominika\Ustawienia lokalne 2013-10-15 08:56 - 2013-10-15 08:56 - 00000809 _____ C:\Documents and Settings\Dominika\Menu Start\Programy\Internet Explorer.lnk 2013-10-15 08:56 - 2013-10-15 08:56 - 00000000 ____D C:\Documents and Settings\Dominika\Ustawienia lokalne\Dane aplikacji\Avg2013 2013-10-15 08:56 - 2013-10-15 08:56 - 00000000 ____D C:\Documents and Settings\Dominika\Ustawienia lokalne\Dane aplikacji\AVG Secure Search 2013-10-15 08:56 - 2013-10-15 08:56 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\AVG2013 2013-10-15 08:56 - 2013-10-15 08:56 - 00000000 ____D C:\Documents and Settings\Dominika\Dane aplikacji\AVG Secure Search 2013-10-15 08:56 - 2013-10-15 08:55 - 00000744 _____ C:\Documents and Settings\Dominika\Menu Start\Programy\Outlook Express.lnk 2013-10-15 08:56 - 2013-10-15 08:55 - 00000000 ___RD C:\Documents and Settings\Dominika\Ulubione 2013-10-15 08:56 - 2013-10-15 08:55 - 00000000 ___RD C:\Documents and Settings\Dominika\Moje dokumenty\Moja muzyka 2013-10-15 08:56 - 2013-10-15 08:55 - 00000000 ___RD C:\Documents and Settings\Dominika\Moje dokumenty 2013-10-15 08:56 - 2013-10-15 08:55 - 00000000 ___RD C:\Documents and Settings\Dominika\Menu Start\Programy\Akcesoria 2013-10-15 08:56 - 2013-10-15 08:55 - 00000000 ___RD C:\Documents and Settings\Dominika\Menu Start\Programy 2013-10-15 08:55 - 2013-10-15 08:55 - 00000798 _____ C:\Documents and Settings\Dominika\Menu Start\Programy\Windows Media Player.lnk 2013-10-15 08:55 - 2013-10-15 08:55 - 00000000 __SHD C:\Documents and Settings\Dominika\IETldCache 2013-10-15 08:55 - 2013-10-15 08:55 - 00000000 ____D C:\Documents and Settings\Dominika 2013-10-14 17:09 - 2012-08-12 05:41 - 00000000 ____D C:\Documents and Settings\e\Pulpit 2013-10-12 21:13 - 2012-08-29 15:57 - 00000000 ____D C:\WINDOWS\system32\cache 2013-10-12 21:10 - 2012-09-29 14:41 - 00000000 ____D C:\Program Files\AVG Secure Search 2013-10-12 21:09 - 2012-08-21 13:20 - 00037664 _____ (AVG Technologies) C:\WINDOWS\system32\Drivers\avgtpx86.sys 2013-10-12 18:27 - 2013-10-12 18:25 - 00000000 ____D C:\Program Files\Hamachi 2013-10-12 18:25 - 2013-10-12 18:25 - 00000638 _____ C:\Documents and Settings\All Users\Pulpit\hamachi.lnk 2013-10-12 18:25 - 2013-10-12 18:25 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Hamachi 2013-10-12 18:25 - 2009-03-18 16:35 - 00025280 _____ (LogMeIn, Inc.) C:\WINDOWS\system32\Drivers\hamachi.sys 2013-10-12 11:04 - 2013-08-11 09:48 - 00000246 _____ C:\Documents and Settings\e\Pulpit\Filmy do pobrania.txt 2013-10-12 07:34 - 2013-01-05 13:40 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\IObit 2013-10-11 14:36 - 2013-01-26 15:09 - 00000000 ___RD C:\Documents and Settings\Radek\Moje dokumenty\Moja muzyka 2013-10-10 19:21 - 2012-08-30 10:16 - 00000000 ____D C:\Documents and Settings\e\Dane aplikacji\GG 2013-10-10 19:02 - 2012-08-30 10:16 - 00000000 ____D C:\Documents and Settings\e\Ustawienia lokalne\Dane aplikacji\GG 2013-09-28 10:09 - 2013-09-28 10:09 - 00000474 _____ C:\Documents and Settings\e\Pulpit\Scarface.lnk 2013-09-28 10:09 - 2013-09-28 10:09 - 00000000 ____D C:\Documents and Settings\e\Menu Start\Programy\Radical Games Some content of TEMP: ==================== C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\htmlayout.dll C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\uninstall529156.exe C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\uninstall529234.exe C:\Documents and Settings\e\Ustawienia lokalne\Temp\drm_dialogs.dll C:\Documents and Settings\e\Ustawienia lokalne\Temp\sfamcc00001.dll C:\Documents and Settings\e\Ustawienia lokalne\Temp\sfareca00001.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe [2006-03-02 14:00] - [2008-04-14 22:51] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\Windows\System32\winlogon.exe [2006-03-02 14:00] - [2008-04-14 22:51] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\Windows\System32\svchost.exe [2006-03-02 14:00] - [2008-04-14 22:51] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\Windows\System32\services.exe [2006-03-02 14:00] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f C:\Windows\System32\User32.dll [2006-03-02 14:00] - [2008-04-14 22:50] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\Windows\System32\userinit.exe [2006-03-02 14:00] - [2008-04-14 22:51] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\Windows\System32\Drivers\volsnap.sys [2006-03-02 14:00] - [2008-04-14 21:31] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================