Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2014 Ran by Ania (administrator) on MA-KOMPUTER on 20-02-2014 14:45:37 Running from C:\Users\Ania\Desktop\skanowanie antywirusowe Windows 7 Professional (X64) OS Language: Polish Internet Explorer Version 9 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) D:\programy\avgrsa.exe (AVG Technologies CZ, s.r.o.) D:\programy\avgcsrva.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVG Technologies CZ, s.r.o.) D:\programy\avgidsagent.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) C:\Windows\system32\prevhost.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1289704 2012-09-12] (Microsoft Corporation) HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [AudCtrl] - RunDll32 AudCtrl.dll,RCMonitor HKLM\...\RunOnce: [đW‹=\] - C:\Windows\system32\MsiExec.exe /@ "đW‹=\ VVV+ĂVŃř@PSVV‰Eô˙׉Eř;Ćt8Pč…ő˙˙Y‰Eü;Ćt*VV˙uřP˙uôSVV˙×…Ŕu ˙uüčËá˙˙Y‰uüS˙X ‹Eüë S˙X 3Ŕ_^[ÉĂĚĚĚĚĚ‹˙V¸¨ľ¨W‹ř;Ćs‹…Ŕt˙ЃÇ;ţrń_^ĂĚĚĚĚĚ‹˙V¸°ľ°W‹ř;Ćs‹…Ŕt˙ЃÇ;ţrń_^ĂĚĚĚĚĚj h  j ˙d 3É…Ŕ•ÁŁ8¶‹ÁĂĚĚĚĚĚ˙58¶˙h ƒ%8¶ ĂĚĚĚĚĚĚĚĚĚĚhĐ.d˙5 ‹D$‰l$Ťl$+ŕSVWˇ` 1Eü3ĹP‰eč˙uř‹EüÇEüţ˙˙˙‰EřŤEđdŁ Ă‹Mđd‰ Y__^[‹ĺ]QĂĚĚĚĚĚĚĚ‹˙U‹ěƒěS‹] V‹s35` W‹ĆE˙ ÇEô Ť{ƒřţt ‹NĎ3 8čřŘ˙˙‹N ‹FĎ3 8ččŘ˙˙‹Eö@f… ‹MŤUč‰Sü‹[ ‰Eč‰Měƒűţt_ŤI Ť[‹L†ŤD†‰Eđ‹ ‰Eř…Ét‹×čtR ĆE˙…Ŕx@G‹Eř‹Řƒřţu΀}˙ t$‹ƒřţt ‹NĎ3 8čuŘ˙˙‹N ‹VĎ3 :čeŘ˙˙‹Eô_^[‹ĺ]ĂÇEô ëÉ‹M9csmŕu)ƒ=ô6  t hô6 čÓO ƒÄ…Ŕt‹UjR˙ô6 ƒÄ‹M ‹UčR ‹E 9X th` W‹Ó‹ČčR ‹E ‹Mř‰H ‹ƒřţt ‹NĎ3 8čß×˙˙‹N ‹VĎ3 :čĎ×˙˙‹Eđ‹H‹×čŞQ şţ˙˙˙9S „O˙˙˙h` W‹ËčÁQ é˙˙˙ĚĚĚĚĚ‹˙U‹ěVčćî˙˙‹đ…ö„2 ‹N\‹U‹ÁW9t ƒŔ Ťą ;ÇrďÁ ;Ás9t3Ŕ…Ŕt‹P…Ňu3Ŕéő ƒúu ƒ` 3Ŕ@éä ƒú„Ř ‹M S‹^`‰N`‹Hƒů…¶ j$Y‹~\ƒd9 ƒÁ ů |í‹ ‹~d=Ž Ŕu ÇFdƒ ë~= Ŕu ÇFd ën=‘ Ŕu ÇFd„ ë^=“ Ŕu ÇFd… ëN=Ť Ŕu ÇFd‚ ë>=Ź Ŕu ÇFd† ë.=’ Ŕu ÇFdŠ ë=µ Ŕu ÇFdŤ ë=´ ŔuÇFdŽ ˙vdj˙ŇY‰~dëƒ` Q˙ŇY‰^`[ƒČ˙_^]ĂĚĚĚĚĚ‹˙U‹ě¸csmŕ9Eu ˙u Pč™ţ˙˙YY]Ă3Ŕ]ĂĚĚĚĚĚ‹˙U‹ěƒěˇ` ƒeř ƒeü SWżNć@»» ˙˙;Çt …Ăt ÷ĐŁd ëeVŤEřP˙ ‹uü3uř˙t 3đ˙ü 3đ˙p 3đŤEđP˙l ‹Eô3Eđ3đ;÷uľOć@»ë…óu ‹Ć G Áŕ đ‰5` ÷Ö‰5d ^_[ÉĂĚĚĚĚĚ‹˙U‹ěě( ŁH·‰ D·‰@·‰<·‰58·‰=4·fŚ`·fŚ T·fŚ0·fŚ,·fŚ%(·fŚ-$·śŹX·‹E ŁL·‹EŁP·ŤEŁ\·‹…ŕü˙˙ǘ¶  ˇP·ŁL¶Ç@¶  ŔÇD¶ ˇ` ‰…Řü˙˙ˇd ‰…Üü˙˙˙ˆ Ł¶jčňN Yj ˙„ h ˙€ ƒ=¶ ujčÎN Yh  Ŕ˙| P˙x ÉĂĚĚĚĚĚ‹˙U‹ěQV‹u Vč†Z ‰E ‹F Y¨‚uč  Ç ƒN ƒČ˙é/ ¨@t čń Ç " ëăS3ۨt‰^¨„‡ ‹Nƒŕţ‰‰F ‹F ƒŕďƒČ‰F ‰^‰]ü©  u,č@X ƒŔ ;đt č4X ƒŔ@;đu ˙u čĘW Y…ŔuVčqW Y÷F  W„€ ‹F‹>ŤH‰‹N+řI‰N;ű~WP˙u čhV ƒÄ ‰EüëMƒČ ‰F ƒČ˙ëy‹M ƒů˙tƒůţt‹Áƒŕ‹ŃÁúÁŕ•@Úë¸  ö@ tjSSQč,N #ƒÄƒř˙t%‹FŠMˆë3˙GWŤEP˙u čůU ƒÄ ‰Eü9}üt ƒN ƒČ˙ë‹E%˙ _[^ÉĂĚĚĚĚĚ‹˙U‹ěět ˇ` 3ʼnEü‹ESV‹u 3ŰW‹}˙uŤŤ¨ű˙˙‰…Üű˙˙‰˝äű˙˙‰ťĽű˙˙‰ťřű˙˙‰ťĐű˙˙‰ťôű˙˙‰ťŘű˙˙‰ť¸ű˙˙‰ťÔű˙˙č Ó˙˙9ťÜű˙˙u*čO Ç  čč 8ť´ű˙˙t ‹…°ű˙˙ƒ`pýƒČ˙éů ;ótŇ·3ɉťčű˙˙‰ťěű˙˙‰ťÄű˙˙‰•ŕű˙˙f;Ó„¶ j[óƒ˝čű˙˙ ‰µŔű˙˙Śž ŤBŕfƒřXw·Âľ€0" ƒŕë3Ŕľ„ÁP" jÁřY‰…¤ű˙˙;Á‡% ˙$…@3ŔƒŤôű˙˙˙‰… ű˙˙‰…¸ű˙˙‰…Đű˙˙‰…Řű˙˙‰…řű˙˙‰…Ôű˙˙éě ·Âƒč tJƒčt6ƒčt%+Ătƒč…Í ƒŤřű˙˙éÁ ƒŤřű˙˙éµ ƒŤřű˙˙é© Ťřű˙˙€ éš ťřű˙˙éŹ fƒú*u,ƒÇ‰˝äű˙˙‹ü‰˝Đű˙˙…˙‰o ƒŤřű˙˙÷ťĐű˙˙é] ‹…Đű˙˙kŔ ·ĘŤDЉ…Đű˙˙éB ƒĄôű˙˙ é6 fƒú*u&ƒÇ‰˝äű˙˙‹ü‰˝ôű˙˙…˙‰ ƒŤôű˙˙˙é ‹…ôű˙˙kŔ ·ĘŤDЉ…ôű˙˙éď ·ÂƒřItWƒřhtFƒřltƒřw…Ô Ťřű˙˙  éĹ fƒ>luóŤřű˙˙  ‰µŔű˙˙é¨ ƒŤřű˙˙éś ƒŤřű˙˙ é ·ƒř6ufƒ~4uƒĆŤřű˙˙ € ‰µŔű˙˙éi ƒř3ufƒ~2uƒĆĄřű˙˙˙˙˙‰µŔű˙˙éE ƒřd„< ƒři„3 ƒřo„* ƒřu„! ƒřx„ ƒřX„ ƒĄ¤ű˙˙ ‹…Üű˙˙RŤµčű˙˙Ç…Ôű˙˙ č éć ·ÂƒřdŹ/ „Ŕ ƒřSŹ t~ƒčAt+ĂtY+Ăt+Ă…ă ƒÂ Ç… ű˙˙ ‰•ŕű˙˙ƒŤřű˙˙@ƒ˝ôű˙˙ Ť˝üű˙˙¸  ‰˝đű˙˙‰…ěű˙˙Ť’ Ç…ôű˙˙ éó ÷…řű˙˙0 …Č ƒŤřű˙˙ éĽ ÷…řű˙˙0 uƒŤřű˙˙ ‹ťôű˙˙ƒű˙u»˙˙˙ƒÇö…řű˙˙ ‰˝äű˙˙‹ü‰˝đű˙˙„ű …˙u ˇ ­‰…đű˙˙ƒĄěű˙˙ ‹µđű˙˙…ŰŽ Š„Ŕ„  ŤŤ¨ű˙˙¶ŔQPčĎW YY…ŔtFF˙…ěű˙˙9ťěű˙˙|Đéß ƒčX„ţ +Ă„” +Á„öţ˙˙+Ă…ľ ·ƒÇ3öFö…řű˙˙ ‰µÔű˙˙‰˝äű˙˙‰…śű˙˙tBˆ…Čű˙˙Ť…¨ű˙˙P‹…¨ű˙˙Ć…Éű˙˙ ˙°¬ Ť…Čű˙˙PŤ…üű˙˙PčV ƒÄ…Ŕy‰µ¸ű˙˙ëf‰…üű˙˙Ť…üű˙˙‰…đű˙˙‰µěű˙˙é: ‹ƒÇ‰˝äű˙˙…Ŕt:‹H…Ét3÷…řű˙˙  ż ‰Ťđű˙˙t™+ÂÇ…Ôű˙˙ éő ƒĄÔű˙˙ éë ˇ ­‰…đű˙˙Pč  YéÔ ƒřpŹ „é ƒřeŚÂ ƒřgŽéý˙˙ƒřitqƒřnt(ƒřo…¦ ö…řű˙˙€Ç…ŕű˙˙ taŤřű˙˙  ëU‹7ƒÇ‰˝äű˙˙č÷T …Ŕ„h ö…řű˙˙ t f‹…čű˙˙f‰ë‹…čű˙˙‰Ç…¸ű˙˙ éů ƒŤřű˙˙@Ç…ŕű˙˙ ‹Ťřű˙˙÷Á € „° ‹‹WƒÇéÜ ufƒúguhÇ…ôű˙˙ ë\9…ôű˙˙~‰…ôű˙˙»Ł 9ťôű˙˙~;‹µôű˙˙Ć] Vč›ç˙˙‹•ŕű˙˙Y‰…Äű˙˙…Ŕt‰…đű˙˙‰µěű˙˙‹ř뉝ôű˙˙ë‹•ŕű˙˙‹…äű˙˙‹ƒŔ‹5  ‰…äű˙˙‹@ü‰…˜ű˙˙Ť…¨ű˙˙P˙µ ű˙˙ľÂ˙µôű˙˙‰Ť”ű˙˙P˙µěű˙˙Ť…”ű˙˙WP˙5Ş˙Ö˙Đ‹ťřű˙˙ƒÄă€ tƒ˝ôű˙˙ uŤ…¨ű˙˙PW˙5śŞ˙Ö˙ĐYYfƒ˝ŕű˙˙gu…ŰuŤ…¨ű˙˙PW˙5˜Ş˙Ö˙ĐYY€?-uŤřű˙˙  G‰˝đű˙˙Wéýý˙˙Ç…ôű˙˙ ‰ŤĽű˙˙ë$ƒčs„`ü˙˙+Ă„ƒţ˙˙ƒč…¶ Ç…Ľű˙˙' ö…řű˙˙€Ç…ŕű˙˙ „cţ˙˙j0Xf‰…Ěű˙˙‹…Ľű˙˙ƒŔQf‰…Îű˙˙‰ťŘű˙˙é>ţ˙˙÷Á  …Dţ˙˙ƒÇöÁ t‰˝äű˙˙öÁ@tżGüë·Gü™ë‹GüöÁ@t™ë3҉˝äű˙˙öÁ@t…Ň|…Ŕs÷ŘƒŇ ÷ځŤřű˙˙  ÷…řű˙˙  ‹Ú‹řu3ۃ˝ôű˙˙ } Ç…ôű˙˙ ëƒĄřű˙˙÷¸  9…ôű˙˙~‰…ôű˙˙‹Ç Ău!…Řű˙˙Ťµűý˙˙‹…ôű˙˙˙Ťôű˙˙…Ŕ‹Ç Ăt-‹…ŕű˙˙™RPSWč8 ƒÁ0‰ťű˙˙‹ř‹Úƒů9~ŤĽű˙˙ˆN뽍…űý˙˙+ĆF÷…řű˙˙  ‰…ěű˙˙‰µđű˙˙tZ…Ŕt‹Î€90tO˙Ťđű˙˙‹Ťđű˙˙Ć0@ë7…˙u ˇ$­‰…đű˙˙‹…đű˙˙Ç…Ôű˙˙ ë Kfƒ8 tƒŔ…Űuň+…đű˙˙Ńř‰…ěű˙˙ƒ˝¸ű˙˙ …© ‹…řű˙˙¨@t+©  tj-ë¨tj+ë¨tj Xf‰…Ěű˙˙Ç…Řű˙˙ ‹ťĐű˙˙+ťěű˙˙+ťŘű˙˙ö…řű˙˙ ‰ťű˙˙u(‹ű…Ű~"‹…Üű˙˙j Ťµčű˙˙Oč€ ƒ˝čű˙˙˙Yt…˙Ţ˙µŘű˙˙‹˝Üű˙˙Ť…čű˙˙ŤŤĚű˙˙č , ö…řű˙˙Yt1ö…řű˙˙u(‹ű…Ű~"‹…Üű˙˙j0Ťµčű˙˙Oč( ƒ˝čű˙˙˙Yt…˙ރ˝Ôű˙˙ upƒ˝ěű˙˙ ~g‹˝đű˙˙‹ťěű˙˙Ť…¨ű˙˙P‹…¨ű˙˙˙°¬ Ť…śű˙˙WPKčyP ƒÄ‰…ŕű˙˙…Ŕ~$˙µśű˙˙‹…Üű˙˙Ťµčű˙˙č· ˝ŕű˙˙Y…Ű°ë'ƒŤčű˙˙˙ë˙µěű˙˙‹˝Üű˙˙‹Ťđű˙˙Ť…čű˙˙čĎ+ Yƒ˝čű˙˙ |3ö…řű˙˙t*‹˝ű˙˙ë‹…Üű˙˙j Ťµčű˙˙OčU ƒ˝čű˙˙˙Yt…˙ރ˝Äű˙˙ t˙µÄű˙˙čgĎ˙˙ƒĄÄű˙˙ Y‹µŔű˙˙·‰…ŕű˙˙f…Ŕt/‹Ť¤ű˙˙‹˝äű˙˙‹Đéfő˙˙ča Ç  čú €˝´ű˙˙ é ő˙˙€˝´ű˙˙ t ‹…°ű˙˙ƒ`pý‹…čű˙˙‹Mü_^3Í[čvÇ˙˙ÉĂŤI 8666“6ŕ6ě637;8ĚĚĚĚĚ‹˙U‹ě‹EŁdą]ĂĚĚĚĚĚ‹˙U‹ěě( ˇ` 3ʼnEüS‹]Wƒű˙tSčIA YƒĄŕü˙˙ jLŤ…äü˙˙j PčzP Ť…ŕü˙˙‰…Řü˙˙Ť…0ý˙˙ƒÄ ‰…Üü˙˙‰…ŕý˙˙‰ŤÜý˙˙‰•Řý˙˙‰ťÔý˙˙‰µĐý˙˙‰˝Ěý˙˙fŚ•řý˙˙fŚŤěý˙˙fŚťČý˙˙fŚ…Äý˙˙fŚĄŔý˙˙fŚ­Ľý˙˙śŹ…đý˙˙‹EŤM‰Ťôý˙˙Ç…0ý˙˙  ‰…čý˙˙‹Iü‰Ťäý˙˙‹M ‰Ťŕü˙˙‹M‰Ťäü˙˙‰…ěü˙˙˙ˆ j ‹ř˙„ Ť…Řü˙˙P˙€ …Ŕu…˙u ƒű˙tSčT@ Y‹Mü_3Í[čĆ˙˙ÉĂĚĚĚĚĚ‹˙Vjľ ŔVjčŔţ˙˙ƒÄ V˙| P˙x ^ĂĚĚĚĚĚ‹˙U‹ě˙5dą˙  …Ŕt]˙ŕ˙u˙u˙u˙u ˙učŞ˙˙˙ĚĚĚĚĚĚ3ŔPPPPPčÂ˙˙˙ƒÄĂĚĚĚĚĚ‹˙U‹ě‹E3É;Íh tAƒů-rńŤHíƒůwj X]Ă‹Íl ]ĂD˙˙˙jY;ČŔ#ÁƒŔ]ĂĚĚĚĚĚčˇÜ˙˙…Ŕu¸ĐˇÃŔĂĚĚĚĚĚč‰Ü˙˙…Ŕu¸ÔˇÃŔ ĂĚĚĚĚĚ‹˙U‹ěVčÝ˙˙˙‹MQ‰čs˙˙˙Y‹đč˛˙˙˙‰0^]ĂĚĚĚĚĚ-¤ t"ƒčtƒč t Ht3Ŕø ø ø ø ĂĚĚĚĚĚ‹˙VW‹đh 3˙ŤFWPč.N 3Ŕ·Č‹Á‰~‰~‰~ Áá ÁŤ~«««ąŘˇƒÄ ŤF+Îż Šˆ@Ou÷Ť† ľ  Šˆ@Nu÷_^ĂĚĚĚĚĚ‹˙U‹ěě ˇ` 3ʼnEüSWŤ…čú˙˙P˙v˙Ś ż  …Ŕ„ü 3Ŕˆ„üţ˙˙@;ÇrôŠ…îú˙˙Ć…üţ˙˙ „Ŕt0Ťťďú˙˙¶Č¶;Čw+Á@PŤ” üţ˙˙j RčfM ƒÄ ŠCƒĂ„ŔuÖj ˙v Ť…üú˙˙˙vPWŤ…üţ˙˙Pjj č Q 3ŰS˙vŤ…üý˙˙WPWŤ…üţ˙˙PW˙v Sč©O ƒÄDS˙vŤ…üü˙˙WPWŤ…üţ˙˙Ph  ˙v Sč„O ƒÄ$3Ŕ·ŚEüú˙˙öÁt€LŠŚüý˙˙ëöÁt€L ŠŚüü˙˙ˆŚ ëˆś @;ÇrżëRŤ† Ç…äú˙˙ź˙˙˙3É)…äú˙˙‹•äú˙˙Ť„ ĐŤZ ƒűw €LŤQ ë ƒúw €L ŤQŕˆëĆ A;ĎrĆ‹Mü_3Í[čĎÂ˙˙ÉĂĚĚĚĚĚj h(jč+é˙˙č‰Ú˙˙‹řˇř¦…Gptƒl t‹wh…öuj čÎá˙˙Y‹ĆčCé˙˙Ăj č˝3 Yƒeü ‹wh‰uä;5 ¦t6…ötV˙4 …ŔuţءtVč×É˙˙Yˇ ¦‰Gh‹5 ¦‰uäV˙( ÇEüţ˙˙˙č 뎋uäj čy2 YĂĚĚĚĚĚ‹˙U‹ěƒěS3ŰSŤMđčhÂ˙˙‰hąƒţţuÇhą ˙” 8]ütE‹Mřƒapýë<ƒţýuÇhą ˙ ëۃţüu‹Eđ‹@Çhą ëÄ8]üt‹Eřƒ`pý‹Ć[ÉĂĚĚĚĚĚ‹˙U‹ěƒě ˇ` 3ʼnEüS‹] V‹uWč_˙˙˙‹ř3ö‰};ţu‹Ăč¦ü˙˙3Ŕéˇ ‰uä3Ŕ9¸¦„‘ ˙EäƒŔ0=đ rç˙čý „t ˙éý „h ·ÇP˙˜ …Ŕ„V ŤEčPW˙Ś …Ŕ„7 h ŤCVPčzJ 3ŇBƒÄ ‰{‰s 9Uč†ü €}î „Ó ŤuďŠ„É„Ć ¶F˙¶Éé© h ŤCVPč3J ‹MäƒÄ kÉ0‰uŕŤ±¦‰uäë+ŠF„Ŕt)¶>¶Ŕë‹EŕŠ€¦D;¶FG;řvę‹}ƒĆ€> uĐ‹uä˙EŕƒĆƒ}ŕ‰uäré‹Ç‰{ÇC čPű˙˙j‰C ŤCŤ‰ ¦Zf‹1f‰0ƒÁƒŔJuń‹óčČű˙˙é´ţ˙˙€L@;ÁvöƒĆ€~˙ …0˙˙˙ŤCąţ €@Iuů‹Cčřú˙˙‰C ‰Së‰s3Ŕ·Č‹ÁÁá ÁŤ{«««ë§95hą…Tţ˙˙ƒČ˙‹Mü_^3Í[č·ż˙˙ÉĂĚĚĚĚĚjhHjčć˙˙ƒMŕ˙čm×˙˙‹ř‰}ÜčÉü˙˙‹_h‹učgý˙˙‰E;C„W h  čˆÚ˙˙Y‹Ř…Ű„F ąˆ ‹wh‹űóĄƒ# S˙učŻý˙˙YY‰Eŕ…Ŕ…ü ‹uÜ˙vh˙4 …Ŕu‹Fh=ءtPč Ć˙˙Y‰^hS‹=( ˙×öFp…ę öř¦…Ý j č+0 Yƒeü ‹CŁxą‹CŁ|ą‹C Ł€ą3Ŕ‰Eäƒř}f‹LCf‰ Elą@ëč3Ŕ‰Eä= } ŠLˆˆřŁ@ëé3Ŕ‰Eä=  }ŠŚ ˆˆ Ą@ëć˙5 ¦˙4 …Ŕuˇ ¦=ءtPčçĹ˙˙Y‰ ¦S˙×ÇEüţ˙˙˙č ë0j č›. YĂë%ƒř˙u űءtSč±Ĺ˙˙YčŮř˙˙Ç  ëƒeŕ ‹EŕčËä˙˙ĂĚĚĚĚ̃=LŰ ujýčQţ˙˙YÇLŰ 3ŔĂĚĚĚĚĚ‹˙U‹ěSV‹5( W‹}W˙Ö‹‡° …ŔtP˙Ö‹‡¸ …ŔtP˙Ö‹‡´ …ŔtP˙Ö‹‡Ŕ …ŔtP˙ÖŤ_PÇE {řü¦t ‹…ŔtP˙փ{ü t ‹C…ŔtP˙փĂ˙MuÖ‹‡Ô ´ P˙Ö_^[]ĂĚĚĚĚĚ‹˙U‹ěW‹}…˙„ƒ SV‹54 W˙Ö‹‡° …ŔtP˙Ö‹‡¸ …ŔtP˙Ö‹‡´ …ŔtP˙Ö‹‡Ŕ …ŔtP˙ÖŤ_PÇE {řü¦t ‹…ŔtP˙փ{ü t ‹C…ŔtP˙փĂ˙MuÖ‹‡Ô ´ P˙Ö^[‹Ç_]ĂĚĚĚĚĚ‹˙U‹ěSV‹u‹†Ľ 3ŰW;Ăto=8­th‹†° ;Ăt^9uZ‹†¸ ;Ăt9uPčüĂ˙˙˙¶Ľ čćM YY‹†´ ;Ăt9uPčŰĂ˙˙˙¶Ľ čWM YY˙¶° čĂĂ˙˙˙¶Ľ č¸Ă˙˙YY‹†Ŕ ;ĂtD9u@‹†Ä -ţ Pč—Ă˙˙‹†Ě ż€ +ÇPč„Ă˙˙‹†Đ +ÇPčvĂ˙˙˙¶Ŕ čkĂ˙˙ƒÄ‹†Ô = §t9˜´ uPčXI ˙¶Ô čBĂ˙˙YYŤ~PÇE řü¦t‹;Ăt 9uPčĂ˙˙Y9_üt‹G;Ăt 9uPčĂ˙˙YƒÇ˙MuÇVč÷Â˙˙Y_^[]ĂĚĚĚĚĚ‹˙U‹ěW‹} …˙t;‹E…Ŕt4V‹0;÷t(W‰8č[ý˙˙Y…ötVčäý˙˙ƒ> Yuţh¨tVčnţ˙˙Y‹Ç^ë3Ŕ_]ĂĚĚĚĚĚj hhjč}á˙˙čŰŇ˙˙‹đˇř¦…Fpt"ƒ~l tčÄŇ˙˙‹pl…öuj čÚ˙˙Y‹Ćčá˙˙Ăj č , Yƒeü ˙5@©ƒĆlVčT˙˙˙YY‰EäÇEüţ˙˙˙č ëľj čů* Y‹uäĂĚĚĚĚĚ‹˙U‹ě¸˙˙ ƒěf9E„‡ SV˙u ŤMěčŐş˙˙‹uě‹N3Ű;Ëu‹EŤHżfƒůwfƒŔ ·ŔëK¸  jf9Es˙učîL Y…Ŕ·EYt,‹ŽĚ ¶ë ŤUüRjŤURPQč“L ƒÄ…Ŕ·Et·Eü8]řt‹Môƒapý^[ÉĂĚĚĚĚĚ‹˙U‹ě‹UVW…Ňt‹} …˙uč‹ô˙˙j^‰0č%ô˙˙‹Ćë3‹E…Ŕuˆëâ‹ň+đŠˆ @„ÉtOuó…˙uĆ čUô˙˙j"Y‰‹ńëĆ3Ŕ_^]ĂĚĚĚĚĚĚĚ‹L$÷Á t$ŠƒÁ„ŔtN÷Á uď Ť¤$ Ť¤$ ‹ş˙ţţ~Ѓđ˙3ƒÁ© tč‹Aü„Ŕt2„ät$© ˙ t© ˙tëÍŤA˙‹L$+ÁĂŤAţ‹L$+ÁĂŤAý‹L$+ÁĂŤAü‹L$+ÁĂĚĚĚĚĚW‹Ćƒŕ…Ŕ…Á ‹ŃƒáÁęte덛 fofoNfoV fo^0ffOfW f_0fof@fonPfov`fo~pfg@foPfw`fpŤ¶€ Ťż€ JuŁ…ÉtI‹ŃÁę…ŇtŤ› fofŤvŤJuďƒát$‹ÁÁét ‹‰ŤvŤIuó‹Čƒát ŠˆFGIu÷X^_]Ăş +Đ+ĘQ‹Â‹Čƒát ŠˆFGIu÷Áčt ‹‰ŤvŤHuóYé ˙˙˙ĚĚĚĚĚj ˙ś Ł(Ú3ŔĂĚĚĚĚĚ‹˙U‹ěQQ‹E W‹}…Ŕt‰8…˙učuň˙˙Ç  čň˙˙3Ŕé ƒ} t ƒ}|݃}$׃eü SVj[·7SVƒÇč9J YY…Ŕuífƒţ-uƒMëfƒţ+u·7ƒÇƒ} u-VčwN Y…Ŕt ÇE ë>·ƒřxt ƒřXt‰]ë,ÇE ƒ}uVčDN Y…Ŕu·ƒřxtƒřXu·wƒÇƒČ˙3Ň÷u‰Uř‹ŘVčN Yƒř˙u)jAXf;ĆwfƒţZv ŤFźfƒřw1ŤFźfƒř·Ćwƒč ƒŔÉ;EsƒM9]ür*u;Eřv#ƒMƒ} u%‹Eƒď¨u&ƒ} t‹}ƒeü ëa‹MüŻMȉMü·7ƒÇé|˙˙˙ľ˙˙˙¨u¨u=ƒŕt }ü €w …Ŕu+9uüv&č ń˙˙öEÇ " tƒMü˙ëöEj X•ŔƉEü‹E ^[…Ŕt‰8öEt÷]ü‹Eü_ÉĂĚĚĚĚĚ‹˙U‹ěj ˙u˙u ˙uč$ţ˙˙ƒÄ]ĂĚĚĚĚĚ‹˙U‹ě3Ŕ‹M; Ĺx t @ƒřrî3Ŕ]Ă‹Ĺ| ]ĂĚĚĚĚĚ‹˙U‹ěěü ˇ` 3ʼnEüSV‹uWVč´˙˙˙‹ř3ŰY‰˝ţ˙˙;ű„l jč!P Yƒř„ jčP Y…Ŕu ƒ=Đ´„î ţü „6 h´! h żˆąWč(Á˙˙ƒÄ …Ŕ…¸ h ľşąVSfŁÂ»˙¤ »ű …Ŕuh„! SVčđŔ˙˙ƒÄ …Ŕt 3ŔPPPPPč˙î˙˙VčlO @Yƒřî˙˙Ç  č×í˙˙ƒČ˙]Ă˙uj ˙58¶˙¨ ]ĂĚĚĚĚĚj hˆjčËŮ˙˙jč‹$ Yƒeü ‹u‹N…Ét/ˇĽżş¸ż‰Eä…Ŕt9u,‹H‰JP襺˙˙Y˙včśş˙˙Yƒf ÇEüţ˙˙˙č čşŮ˙˙Ă‹ĐëĹjčM# YĂĚĚĚĚĚĚĚ‹T$‹L$÷ u<‹:u. Ŕt&:au% ätÁč:Au Ŕt:auƒÁƒÂ äuŇ‹˙3ŔÐŔŃŕƒŔĂ÷ tŠƒÂ:uçƒÁ ŔtÜ÷ t¤f‹ƒÂ:uÎ ŔtĆ:auĹ ät˝ƒÁëˆĚĚĚĚĚ‹˙U‹ěƒě ‹EVWjYľč! Ť}ŕóĄ‰Eř‹E _‰Eü^…Ŕt ö tÇEô @™ŤEôP˙uđ˙uä˙uŕ˙¬ É ĚĚĚĚĚĚĚV‹D$ Ŕu(‹L$‹D$ 3Ň÷ń‹Ř‹D$÷ń‹đ‹Ă÷d$‹Č‹Ć÷d$ŃëG‹Č‹\$‹T$ ‹D$ŃéŃŰŃęŃŘ Éuô÷ó‹đ÷d$‹Č‹D$÷ćŃr;T$ wr;D$v N+D$T$3Ű+D$T$ ÷Ú÷ŘƒÚ ‹Ę‹Ó‹Ů‹Č‹Ć^ ĚĚĚĚĚĚĚĚĚĚĚSV‹D$ Ŕu‹L$‹D$3Ň÷ń‹Ř‹D$ ÷ń‹ÓëA‹Č‹\$‹T$‹D$ ŃéŃŰŃęŃŘ Éuô÷ó‹đ÷d$‹Č‹D$÷ćŃr;T$wr;D$ vN3Ň‹Ć^[ ĚĚĚĚĚ‹˙U‹ěVf‹uW‹}·Gƒřp„" fƒţp„ ƒřst ƒřSt3Ňë3ŇBfƒţst fƒţSt3Éë3ÉA…Ň…É …É…ŕ ji_jdZf;Ât]f;Çt6ƒřot1ƒřut,ƒřxt'ƒřXt"f;ňtf;÷tfƒţotfƒţut fƒţxtfƒţXulf;Âtf;Çtƒřotƒřutƒřxt ƒřXt3Éë3ÉAf;ňt!f;÷tfƒţotfƒţutfƒţxt fƒţXt3Ŕë3Ŕ@;ČuH‹E‹@ ‹Č3M÷Á  u53E¨ u.‹M‹ 3Ŕ;M ”Ŕë-;Ńu‹G ‹MÁčÁé÷Đ÷Ń3Á¨u3Ŕ@ë3Ŕë 3Éf;Ć”Á‹Á_^]ĂĚĚĚĚĚ‹˙U‹ěö@ @tƒx tP˙učÝ5 YYą˙˙ f;Áuƒ˙]Ă˙]ĂĚĚĚĚĚ‹˙U‹ěěĚ ˇ` 3ʼnEü‹ESV‹u W‹}˙u3ŰŤŤő˙˙‰˝lő˙˙‰…´ő˙˙‰ťXő˙˙‰ť¸ő˙˙‰ťtő˙˙‰ťPő˙˙‰ťhő˙˙č‚Ż˙˙ƒŤ¬ő˙˙˙‰ťpő˙˙;űu*č˝é˙˙Ç  čVé˙˙8ťśő˙˙t ‹…˜ő˙˙ƒ`pýƒČ˙éŘ ;ót҉ť„ő˙˙‰µ<ő˙˙‰ť¨ő˙˙ƒ˝¨ő˙˙u 9ť¬ő˙˙„” ·ƒŤxő˙˙˙ƒŤ ő˙˙˙ƒŤ¬ő˙˙˙‰ťŚő˙˙‰ťdő˙˙‰ťTő˙˙‰ť|ő˙˙‰ť°ő˙˙‰µ€ő˙˙‰•ˆő˙˙f;Ó„- ë‹•ˆő˙˙j_÷ƒ˝„ő˙˙ ‰µ€ő˙˙Ś€ ŤBŕfƒřXw·Â¶€@2 ƒŕë3Ŕ‹Ťdő˙˙kŔ ¶ś`2 Á뉝dő˙˙ƒű…ß fƒ>%„Î ƒ˝¬ő˙˙˙uZj Ť…pő˙˙PVčŘ÷˙˙ƒÄ …Ŕ~7‹…pő˙˙fƒ8$u+ƒ˝¨ő˙˙ uh@ Ť…Ľů˙˙j PčE7 ƒÄ Ç…¬ő˙˙ ëƒĄ¬ő˙˙ ‹•ˆő˙˙ƒ˝¬ő˙˙ubj Ť…pő˙˙PVču÷˙˙‹Ťpő˙˙ƒÄ Hƒ˝¨ő˙˙ ŤQ‰… ő˙˙‰•€ő˙˙u)…Ŕˆ° fƒ9$…¦ ƒřdŤť ;…xő˙˙~‰…xő˙˙‹ň‹•ˆő˙˙˙$ťkƒű„w ƒű‡: ë僽¨ő˙˙ u ƒ˝¬ő˙˙„" ƒ˝¨ő˙˙… ƒ˝¬ő˙˙˙…  é 3ŔƒŤ°ő˙˙˙‰…Hő˙˙‰…Pő˙˙‰…|ő˙˙‰…tő˙˙‰…¸ő˙˙‰…hő˙˙éŃ ·Âƒč tJƒčt6ƒčt%+Çtƒč…˛ ƒŤ¸ő˙˙é¦ ƒŤ¸ő˙˙éš ƒŤ¸ő˙˙éŽ Ť¸ő˙˙€ é ˝¸ő˙˙ét fƒú*… ƒ˝¬ő˙˙ uƒ…´ő˙˙‹…´ő˙˙‹@üé„ j Ť…pő˙˙PVč ö˙˙‹Ťpő˙˙ƒÄ Hƒ˝¨ő˙˙ ŤQ‰•€ő˙˙uN…ŔˆM fƒ9$…C ƒ˝ ő˙˙dŤ6 ;…xő˙˙~‰…xő˙˙ŔŤŚĹĽů˙˙ƒ9 „Ú ˙µ¸ő˙˙j*jéö Ŕ‹„ĹŔů˙˙‹ ‰…|ő˙˙…ŔŤş ƒŤ¸ő˙˙÷ť|ő˙˙é¨ ‹…|ő˙˙kŔ ·ĘŤDЉ…|ő˙˙éŤ ƒĄ°ő˙˙ é fƒú*…’ ƒ˝¬ő˙˙ uƒ…´ő˙˙‹…´ő˙˙‹@üë:j Ť…pő˙˙PVčő˙˙‹Ťpő˙˙ƒÄ Hƒ˝¨ő˙˙ ŤQ‰•€ő˙˙„ ˙˙˙Ŕ‹„ĹŔů˙˙‹ ‰…°ő˙˙…ŔŤ ƒŤ°ő˙˙˙é Ç j*Yf‰ŚĹÄů˙˙‹Ť¸ő˙˙‰ŚĹČů˙˙éĺ ‹…°ő˙˙kŔ ·ĘŤDЉ…°ő˙˙éĘ ·ÂƒřItWƒřhtFƒřltƒřw…Ż Ť¸ő˙˙  é  fƒ>lu÷Ť¸ő˙˙  ‰µ€ő˙˙éƒ ƒŤ¸ő˙˙éw ƒŤ¸ő˙˙ ék ·ƒř6ufƒ~4uƒĆŤ¸ő˙˙ € ‰µ€ő˙˙éD ƒř3ufƒ~2uƒĆĄ¸ő˙˙˙˙˙‰µ€ő˙˙é ƒřdtAƒřit<ƒřot7ƒřut2ƒřxt-ƒřXt(ƒĄdő˙˙ ‹…lő˙˙RŤµ„ő˙˙Ç…hő˙˙ čú˙˙éŮ Ť¸ő˙˙  éË ·ÂƒřdŹ• „ˆ ƒřSŹâ „– ƒčAt+Çtx+Çt+Ç…Ŕ ƒÂ Ç…Hő˙˙ ‰•ˆő˙˙ƒŤ¸ő˙˙@ƒ˝¬ő˙˙…ľ ƒ˝¨ő˙˙ …± ƒ˝ ő˙˙c‡ˆ ‹… ő˙˙ŔŤŚĹĽů˙˙ƒ9 …V Ç f‰”ĹÄů˙˙é2ţ˙˙÷…¸ő˙˙0 uqƒŤ¸ő˙˙ ëh÷…¸ő˙˙0 uƒŤ¸ő˙˙ ‹ť°ő˙˙ƒű˙u»˙˙˙3ö9µ¬ő˙˙…% ƒ…´ő˙˙‹…´ő˙˙‹@üé] ƒčX„§ +Ç„ř ƒč„2˙˙˙+Ç…× ƒ˝¬ő˙˙ Ç…hő˙˙ uƒ…´ő˙˙‹…´ő˙˙·@üëJƒ˝ ő˙˙c‡­ ‹… ő˙˙Ŕƒ˝¨ő˙˙ u"ŤŚĹĽů˙˙ƒ9 u Ç é˝ ˙µ¸ő˙˙é  ‹„ĹŔů˙˙· ö…¸ő˙˙ ‰…Lő˙˙tFˆ…\ő˙˙Ť…ő˙˙P‹…ő˙˙Ć…]ő˙˙ ˙°¬ Ť…\ő˙˙PŤ…Ľő˙˙PčĐ/ ƒÄ…ŔyÇ…Pő˙˙ ëf‰…Ľő˙˙Ť…Ľő˙˙‰…¤ő˙˙Ç…Śő˙˙ éđ ƒ˝¬ő˙˙ uƒ…´ő˙˙‹…´ő˙˙‹@üë+ƒ˝ ő˙˙c‡Ń ‹… ő˙˙Ŕƒ˝¨ő˙˙ „ř ‹„ĹŔů˙˙‹ …Ŕt:‹H…Ét3÷…¸ő˙˙  ż ‰Ť¤ő˙˙t™+ÂÇ…hő˙˙ ép ƒĄhő˙˙ éf ˇ ­‰…¤ő˙˙Pč‹í˙˙YéO ƒřpŹ „ó ƒřeŚ= ƒřgŽ‡ý˙˙ƒři„Ď ƒřnt2ƒřo… ‹ť¸ő˙˙Ç…ˆő˙˙ „ۉŔ Ë  ‰ť¸ő˙˙éŻ ƒ˝¬ő˙˙ uƒ…´ő˙˙‹…´ő˙˙‹püëDƒ˝ ő˙˙c‡Ő ‹… ő˙˙Ŕƒ˝¨ő˙˙ uŤŚĹĽů˙˙ƒ9 „ę ˙µ¸ő˙˙RWé< ‹„ĹŔů˙˙‹0č . …Ŕ„‘ ö…¸ő˙˙ t f‹…„ő˙˙f‰ë‹…„ő˙˙‰Ç…Pő˙˙ é\ ƒŤ¸ő˙˙@Ç…ˆő˙˙ ‹ť¸ő˙˙3ö÷Ă € „’ 9µ¬ő˙˙…N ‹Ť´ő˙˙ƒÁ‰Ť´ő˙˙‹Ař‹Qüé ˙µ¸ő˙˙RjQčżô˙˙ƒÄ…Ŕ…Ě čaŕ˙˙Ç  čúß˙˙€˝śő˙˙ éžö˙˙ƒ˝°ő˙˙ Ť˝Ľő˙˙¸  ‰˝¤ő˙˙‰…Śő˙˙} Ç…°ő˙˙ ëhufƒúgu`Ç…°ő" [127488 2009-07-14] (Microsoft Corporation) HKLM-x32\...\Runonce: [GrpConv] - grpconv -o [X] HKU\S-1-5-21-4178929525-3400120167-3252471758-1002\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_170_Plugin.exe [839560 2014-01-13] (Adobe Systems Incorporated) HKU\S-1-5-21-4178929525-3400120167-3252471758-1002\...\MountPoints2: H - H:\AutoRun.exe HKU\S-1-5-21-4178929525-3400120167-3252471758-1002\...\MountPoints2: {2d6359a0-6480-11e0-b953-001fd05c6213} - H:\AutoRun.exe HKU\S-1-5-21-4178929525-3400120167-3252471758-1002\...\MountPoints2: {3a1de4cb-5be9-11e0-ae98-001fd05c6213} - H:\AutoRun.exe HKU\S-1-5-21-4178929525-3400120167-3252471758-1002\...\MountPoints2: {3a1de4fc-5be9-11e0-ae98-001fd05c6213} - H:\AutoRun.exe HKU\S-1-5-21-4178929525-3400120167-3252471758-1002\...\MountPoints2: {47026064-cf9b-11e1-91c5-001fd05c6213} - H:\setup.exe -a HKU\S-1-5-21-4178929525-3400120167-3252471758-1002\...\MountPoints2: {a660fcaf-00b7-11e0-848d-001fd05c6213} - H:\LaunchU3.exe -a HKU\S-1-5-21-4178929525-3400120167-3252471758-1002\...\MountPoints2: {a9a7b367-b9d4-11e0-b779-001fd05c6213} - K:\start.exe HKU\S-1-5-21-4178929525-3400120167-3252471758-1002\...\MountPoints2: {b59e5d01-e9ac-11e0-a072-001fd05c6213} - H:\AutoRun.exe HKU\S-1-5-21-4178929525-3400120167-3252471758-1002\...\MountPoints2: {b59e5d0e-e9ac-11e0-a072-001fd05c6213} - H:\AutoRun.exe HKU\S-1-5-21-4178929525-3400120167-3252471758-1002\...\MountPoints2: {df4e97ac-fe99-11e0-be14-001fd05c6213} - J:\ICM_ML.exe HKU\S-1-5-21-4178929525-3400120167-3252471758-1002\...\MountPoints2: {e446db28-5be8-11e0-bd20-001fd05c6213} - H:\AutoRun.exe Startup: C:\Users\Ania\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk ShortcutTarget: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Ania\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_60589510.lnk ShortcutTarget: _uninst_60589510.lnk -> C:\Users\Ania\AppData\Local\Temp\_uninst_60589510.bat () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.pl/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredibar.com/mb201/?search={searchTerms}&loc=IB_DS&a=6PQWAuXjW9&i=26 BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File BHO-x32: Pomocnik rejestracji usługi Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\c4q3k26y.default FF user.js: detected! => C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\c4q3k26y.default\user.js FF NewTab: hxxp://mystart.incredibar.com/mb201?a=6PQWAuXjW9&i=26 FF SearchEngineOrder.1: v9 FF Homepage: hxxp://www.google.pl/ FF Keyword.URL: hxxp://mystart.incredibar.com/mb201/?loc=IB_DS&a=6PQWAuXjW9&&i=26&search= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @4game.com/plugin - C:\Program Files (x86)\4game\npplugin4game.dll (Innova Co S.a r.l.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_35 - C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Ania\AppData\Roaming\Mozilla\Firefox\Profiles\c4q3k26y.default\searchplugins\MyStart Search.xml FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2013-01-22] FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\IB Updater\Firefox FF HKLM\...\Firefox\Extensions: [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}] - C:\Program Files\IB Updater\Firefox Chrome: ======= CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\IB Updater\source.crx [] CHR HKLM-x32\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\IB Updater\source.crx [] ==================== Services (Whitelisted) ================= S2 4game-service; C:\Program Files (x86)\4game\4game-service.exe [1133056 2013-05-23] (Innova Co S.a r.l.) R2 AVGIDSAgent; D:\programy\avgidsagent.exe [5814904 2012-11-15] (AVG Technologies CZ, s.r.o.) S2 avgwd; D:\programy\avgwdsvc.exe [196664 2012-10-22] (AVG Technologies CZ, s.r.o.) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22072 2012-09-12] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368896 2012-09-12] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [154464 2012-10-22] (AVG Technologies CZ, s.r.o. ) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [63328 2012-10-15] (AVG Technologies CZ, s.r.o. ) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [185696 2012-10-02] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [225120 2012-09-21] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [111968 2012-11-15] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40800 2012-09-14] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [200032 2012-09-21] (AVG Technologies CZ, s.r.o.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [228768 2012-08-30] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [128456 2012-08-30] (Microsoft Corporation) S2 PfModNT; C:\Windows\SysWOW64\PfModNT.sys [6752 1999-12-17] (Creative Technology Ltd.) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2012-06-18] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [12384 2012-06-18] () S3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [416768 2009-06-10] (Realtek Semiconductor Corporation ) S3 ts_arnusb; C:\Windows\System32\DRIVERS\ts_arnusbx.sys [1983688 2013-07-23] (TamoSoft) S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-20 12:40 - 2014-02-20 12:40 - 00000000 ____D () C:\FRST 2014-02-20 12:12 - 2014-02-20 14:45 - 00000000 ____D () C:\Users\Ania\Desktop\skanowanie antywirusowe 2014-02-20 07:34 - 2014-02-20 07:34 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-02-20 07:23 - 2014-02-20 07:32 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files 2014-02-20 07:22 - 2014-02-20 07:22 - 00000000 ____D () C:\Users\Ania\Desktop\Ręczna Zmiana języka KIS 2013 en na PL i odwrotnie 2014-02-19 23:20 - 2014-02-19 23:20 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\Malwarebytes 2014-02-19 23:17 - 2014-02-20 12:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-19 23:17 - 2014-02-19 23:17 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-19 20:01 - 2014-02-19 20:01 - 00000395 _____ () C:\Windows\pwnativedev.bak 2014-02-19 20:00 - 2014-02-19 20:06 - 00000981 _____ () C:\Windows\PWCMDLST.BAK 2014-02-19 19:26 - 2012-06-18 13:34 - 02966720 _____ () C:\Windows\system32\pwNative.exe 2014-02-19 19:26 - 2012-06-18 13:34 - 00019032 ____N () C:\Windows\system32\pwdrvio.sys 2014-02-19 19:26 - 2012-06-18 13:34 - 00012384 ____N () C:\Windows\system32\pwdspio.sys 2014-02-19 18:33 - 2014-02-20 06:59 - 00006838 _____ () C:\Windows\PFRO.log 2014-02-19 17:11 - 2014-02-19 17:11 - 00000000 __SHD () C:\found.000 2014-02-19 16:16 - 2014-02-19 16:16 - 00280080 _____ () C:\Windows\Minidump\021914-56253-01.dmp 2014-02-19 16:16 - 2014-02-19 16:16 - 00000000 ____D () C:\Windows\Minidump 2014-02-03 03:17 - 2014-02-09 22:17 - 00000320 _____ () C:\Windows\DirectX.log 2014-02-02 21:25 - 2014-02-20 10:02 - 00006323 _____ () C:\Windows\setupact.log 2014-02-02 21:25 - 2014-02-02 21:25 - 00000000 _____ () C:\Windows\setuperr.log ==================== One Month Modified Files and Folders ======= 2014-02-20 14:45 - 2014-02-20 12:12 - 00000000 ____D () C:\Users\Ania\Desktop\skanowanie antywirusowe 2014-02-20 14:42 - 2010-06-11 21:30 - 01324347 _____ () C:\Windows\WindowsUpdate.log 2014-02-20 12:40 - 2014-02-20 12:40 - 00000000 ____D () C:\FRST 2014-02-20 12:25 - 2014-02-19 23:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-20 12:22 - 2013-01-22 11:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-20 10:10 - 2009-07-14 05:45 - 00014976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-20 10:10 - 2009-07-14 05:45 - 00014976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-20 10:02 - 2014-02-02 21:25 - 00006323 _____ () C:\Windows\setupact.log 2014-02-20 10:02 - 2010-06-11 22:05 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-20 10:02 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-20 07:34 - 2014-02-20 07:34 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-02-20 07:34 - 2010-06-13 09:12 - 00000000 ___RD () C:\Users\Ania\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-20 07:32 - 2014-02-20 07:23 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files 2014-02-20 07:22 - 2014-02-20 07:22 - 00000000 ____D () C:\Users\Ania\Desktop\Ręczna Zmiana języka KIS 2013 en na PL i odwrotnie 2014-02-20 07:20 - 2011-02-10 19:58 - 00002093 _____ () C:\Windows\epplauncher.mif 2014-02-20 06:59 - 2014-02-19 18:33 - 00006838 _____ () C:\Windows\PFRO.log 2014-02-19 23:32 - 2014-01-12 22:01 - 00000000 ____D () C:\Users\Ania\AppData\Local\genienext 2014-02-19 23:20 - 2014-02-19 23:20 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\Malwarebytes 2014-02-19 23:17 - 2014-02-19 23:17 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-19 22:58 - 2013-01-29 01:31 - 00000000 ____D () C:\ProgramData\MFAData 2014-02-19 21:36 - 2010-06-28 17:42 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\uTorrent 2014-02-19 20:40 - 2009-07-14 06:08 - 00032604 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-19 20:21 - 2011-02-10 19:57 - 00000000 ____D () C:\Windows\TempE6A7AAB7-A069-20B6-47C6-6495D9F48018-Signatures 2014-02-19 20:06 - 2014-02-19 20:00 - 00000981 _____ () C:\Windows\PWCMDLST.BAK 2014-02-19 20:01 - 2014-02-19 20:01 - 00000395 _____ () C:\Windows\pwnativedev.bak 2014-02-19 19:01 - 2010-07-27 13:08 - 00000000 ____D () C:\Program Files (x86)\Google 2014-02-19 18:33 - 2010-07-27 13:09 - 00000000 ____D () C:\Program Files\Google 2014-02-19 18:16 - 2012-02-04 19:15 - 00000866 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-02-19 18:14 - 2010-07-27 13:12 - 00000000 ____D () C:\Users\Ania\AppData\Local\Google 2014-02-19 18:14 - 2010-07-27 13:08 - 00000000 ____D () C:\ProgramData\Google 2014-02-19 17:11 - 2014-02-19 17:11 - 00000000 __SHD () C:\found.000 2014-02-19 16:16 - 2014-02-19 16:16 - 00280080 _____ () C:\Windows\Minidump\021914-56253-01.dmp 2014-02-19 16:16 - 2014-02-19 16:16 - 00000000 ____D () C:\Windows\Minidump 2014-02-19 16:16 - 2010-06-13 09:11 - 00000000 ____D () C:\Users\Ania 2014-02-09 22:17 - 2014-02-03 03:17 - 00000320 _____ () C:\Windows\DirectX.log 2014-02-02 21:25 - 2014-02-02 21:25 - 00000000 _____ () C:\Windows\setuperr.log 2014-01-29 01:22 - 2013-11-18 11:10 - 00000000 ____D () C:\Program Files (x86)\4game Files to move or delete: ==================== C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_170_Plugin.exe C:\Users\Ania\utorrent.exe Some content of TEMP: ==================== C:\Users\Ania\AppData\Local\Temp\Quarantine.exe C:\Users\Ania\AppData\Local\Temp\Uninstall.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit