Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01 Ran by JA (administrator) on JA on 03-04-2014 21:28:31 Running from D:\Documents and Settings\JA\Pulpit Microsoft Windows XP Professional Dodatek Service Pack 2 (X86) OS Language: Polish Internet Explorer Version 7 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= () D:\Documents and Settings\JA\Moje dokumenty\LClock\lclock.exe (Mozilla Corporation) D:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Winlogon: [UIHost] %windir%\XP ARENA.exe [x ] () HKLM\...\Policies\Explorer: [NoDesktopCleanupWizard] 1 HKLM\...\Policies\Explorer: [HideRunAsVerb] 1 HKLM\...\Policies\Explorer: [NoRemoteRecursiveEvents] 1 HKU\.DEFAULT\...\Run: [VisualTaskTips] - D:\Program Files\Utilities\VisualTaskTips\VisualTaskTips.exe HKU\.DEFAULT\...\RunOnce: [nltide_2] - regsvr32 /s /n /i:U shell32 HKU\.DEFAULT\...\RunOnce: [nltide_3] - rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N HKU\.DEFAULT\...\Policies\Explorer: [NoSMHelp] 1 HKU\.DEFAULT\...\Policies\Explorer: [ForceClassicControlPanel] 1 HKU\.DEFAULT\...\Policies\Explorer: [NoSMConfigurePrograms] 1 HKU\.DEFAULT\...\Policies\Explorer: [NoRecentDocsMenu] 1 HKU\.DEFAULT\...\Policies\Explorer: [NoRecentDocsHistory] 1 HKU\.DEFAULT\...\Policies\Explorer: [NoStartBanner] 1 HKU\.DEFAULT\...\Policies\Explorer: [NoInstrumentation] 1 HKU\.DEFAULT\...\Policies\Explorer: [NoStartMenuMFUprogramsList] 1 HKU\.DEFAULT\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\.DEFAULT\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1 HKU\.DEFAULT\...\Policies\Explorer: [NoResolveSearch] 1 HKU\S-1-5-20\...\Policies\Explorer: [NoSMHelp] 1 HKU\S-1-5-20\...\Policies\Explorer: [ForceClassicControlPanel] 1 HKU\S-1-5-20\...\Policies\Explorer: [NoSMConfigurePrograms] 1 HKU\S-1-5-20\...\Policies\Explorer: [NoRecentDocsMenu] 1 HKU\S-1-5-20\...\Policies\Explorer: [NoRecentDocsHistory] 1 HKU\S-1-5-20\...\Policies\Explorer: [NoStartBanner] 1 HKU\S-1-5-20\...\Policies\Explorer: [NoInstrumentation] 1 HKU\S-1-5-20\...\Policies\Explorer: [NoStartMenuMFUprogramsList] 1 HKU\S-1-5-20\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-20\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1 HKU\S-1-5-20\...\Policies\Explorer: [NoResolveSearch] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Run: [LClock] - D:\Documents and Settings\JA\Moje dokumenty\LClock\lclock.exe [65536 2004-09-19] () HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoSMHelp] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [ForceClassicControlPanel] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoSMConfigurePrograms] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoRecentDocsMenu] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoRecentDocsHistory] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoStartBanner] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoInstrumentation] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoStartMenuMFUprogramsList] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoResolveSearch] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoSharedDocuments] 0x01000000 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoLogoff] 0x00000000 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoSMMyDocs] 0x00000000 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoSMMyPictures] 0x01000000 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoNetworkConnections] 0x01000000 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoSetFolders] 1 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\Policies\Explorer: [NoDrives] 0x00000000 HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\MountPoints2: {62e496fa-cbf6-11e0-ad32-00197d100915} - F:\MLLaunch.exe HKU\S-1-5-21-1547161642-527237240-839522115-1001\...\MountPoints2: {6a0a0712-abc6-11e0-ac98-00197d100915} - F:\Launch.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - D:\WINDOWS\system32\ieframe.dll (Microsoft Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ] Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.1.1 FireFox: ======== FF ProfilePath: D:\Documents and Settings\JA\Dane aplikacji\Mozilla\Firefox\Profiles\0gw24j3u.default FF user.js: detected! => D:\Documents and Settings\JA\Dane aplikacji\Mozilla\Firefox\Profiles\0gw24j3u.default\user.js FF NewTab: about:blank FF Homepage: file:///D:/Program%20Files/Mozilla%20Firefox/Sp/Start%20Page/start/home.htm FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF Plugin: @adobe.com/FlashPlayer - D:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @java.com/JavaPlugin - D:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - d:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Extension: No Name - D:\Documents and Settings\JA\Dane aplikacji\Mozilla\Firefox\Profiles\0gw24j3u.default\Extensions\elemhidehelper@adblockplus.org.xpi [2011-07-13] FF Extension: No Name - D:\Documents and Settings\JA\Dane aplikacji\Mozilla\Firefox\Profiles\0gw24j3u.default\Extensions\modtabs@gmail.com.xpi [2011-06-04] FF Extension: No Name - D:\Documents and Settings\JA\Dane aplikacji\Mozilla\Firefox\Profiles\0gw24j3u.default\Extensions\nasanightlaunch@example.com.xpi [2011-12-02] FF Extension: No Name - D:\Documents and Settings\JA\Dane aplikacji\Mozilla\Firefox\Profiles\0gw24j3u.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2011-07-10] FF Extension: No Name - D:\Documents and Settings\JA\Dane aplikacji\Mozilla\Firefox\Profiles\0gw24j3u.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-05-03] ========================== Services (Whitelisted) ================= S2 helpsvc; D:\WINDOWS\System32\svchost.exe [14336 2004-08-03] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S3 alcan5wn; D:\WINDOWS\System32\DRIVERS\alcan5wn.sys [53600 2003-12-08] (THOMSON) S3 alcaudsl; D:\WINDOWS\System32\DRIVERS\alcaudsl.sys [70688 2003-12-08] (THOMSON) R3 AR5211; D:\WINDOWS\System32\DRIVERS\ar5211.sys [546112 2007-07-05] (Atheros Communications, Inc.) R2 Aspi32; D:\WINDOWS\system32\Drivers\Aspi32.sys [16877 2006-02-25] (Adaptec) R3 EMSCR; D:\WINDOWS\System32\DRIVERS\EMS7SK.sys [61056 2006-06-16] (ENE Technology Inc.) R3 ESDCR; D:\WINDOWS\System32\DRIVERS\ESD7SK.sys [40064 2006-06-16] (ENE Technology Inc.) R3 ESMCR; D:\WINDOWS\System32\DRIVERS\ESM7SK.sys [74752 2006-06-16] (ENE Technology Inc.) S3 hamachi; D:\WINDOWS\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R0x01000000 papycpu2; D:\WINDOWS\System32\DRIVERS\papycpu2.sys [1984 2003-01-17] () R0x01000000 papyjoy; D:\WINDOWS\System32\DRIVERS\papyjoy.sys [1856 2003-01-17] () S3 PCANDIS5; D:\WINDOWS\system32\PCANDIS5.SYS [16128 2003-08-04] (Printing Communications Assoc., Inc. (PCAUSA)) R0 sptd; D:\WINDOWS\System32\Drivers\sptd.sys [691696 2010-12-25] () S4 IntelIde; No ImagePath U5 LmHosts; D:\WINDOWS\system32\svchost.exe [14336 2004-08-03] (Microsoft Corporation) U5 Messenger; D:\WINDOWS\system32\svchost.exe [14336 2004-08-03] (Microsoft Corporation) U4 NetDDE; U4 NetDDEdsdm; U3 NtmsSvc; %SystemRoot%\system32\svchost.exe -k netsvcs U5 PolicyAgent; D:\WINDOWS\system32\lsass.exe [13312 2004-08-03] (Microsoft Corporation) U3 TlntSvr; U3 VSS; U2 W32Time; %SystemRoot%\System32\svchost.exe -k netsvcs ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-03 21:28 - 2014-04-03 21:28 - 00009793 _____ () D:\Documents and Settings\JA\Pulpit\FRST.txt 2014-04-03 21:27 - 2014-04-03 21:27 - 01145856 _____ (Farbar) D:\Documents and Settings\JA\Pulpit\FRST.exe 2014-04-03 21:26 - 2014-04-03 21:26 - 00003819 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix_Report((telefon)).txt 2014-04-03 21:24 - 2014-04-03 21:26 - 00003819 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix [Scan 4] JA((telefon)).txt 2014-04-03 21:23 - 2014-04-03 21:23 - 00003481 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix_Report((mp3)).txt 2014-04-03 21:22 - 2014-04-03 21:23 - 00003481 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix [Scan 3] JA((mp3)).txt 2014-04-03 21:21 - 2014-04-03 21:21 - 00003728 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix_Report((pendrive)).txt 2014-04-03 21:21 - 2014-04-03 21:21 - 00003728 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix [Scan 2] JA ((pendrive)).txt 2014-04-03 21:20 - 2014-04-03 21:24 - 00001376 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix.lnk 2014-04-03 13:52 - 2014-04-03 14:48 - 00000142 _____ () D:\Documents and Settings\JA\Pulpit\Orzeł, reszka.txt 2014-04-01 22:43 - 2014-04-02 22:58 - 00000569 _____ () D:\Documents and Settings\JA\Pulpit\Typowanie na typerku - Kwiecień.txt 2014-04-01 16:32 - 2014-04-01 18:44 - 477961940 _____ () D:\Documents and Settings\JA\Pulpit\Sport+.30.03.2014.avi 2014-04-01 14:05 - 2014-04-03 15:36 - 00000148 _____ () D:\Documents and Settings\JA\Pulpit\Kwiecień 1.txt 2014-03-25 19:51 - 2014-03-25 21:20 - 545361164 _____ () D:\Sport2 2014-03-19 20:56 - 2014-04-03 21:28 - 00000000 ____D () D:\FRST 2014-03-19 20:46 - 2014-03-19 20:46 - 00001376 _____ () D:\UsbFix.lnk 2014-03-19 20:46 - 2014-03-19 20:46 - 00000000 ____D () D:\UsbFix 2014-03-19 20:43 - 2014-03-19 20:43 - 03099901 _____ (El Desaparecido - SosVirus.net - UsbFix.net) D:\usbfix0.exe 2014-03-07 23:21 - 2014-03-08 00:36 - 449148254 _____ () D:\Sport ==================== One Month Modified Files and Folders ======= 2014-04-03 21:28 - 2014-04-03 21:28 - 00009793 _____ () D:\Documents and Settings\JA\Pulpit\FRST.txt 2014-04-03 21:28 - 2014-03-19 20:56 - 00000000 ____D () D:\FRST 2014-04-03 21:28 - 2010-08-19 16:47 - 00000000 ____D () D:\Documents and Settings\JA\Pulpit 2014-04-03 21:27 - 2014-04-03 21:27 - 01145856 _____ (Farbar) D:\Documents and Settings\JA\Pulpit\FRST.exe 2014-04-03 21:26 - 2014-04-03 21:26 - 00003819 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix_Report((telefon)).txt 2014-04-03 21:26 - 2014-04-03 21:24 - 00003819 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix [Scan 4] JA((telefon)).txt 2014-04-03 21:24 - 2014-04-03 21:20 - 00001376 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix.lnk 2014-04-03 21:23 - 2014-04-03 21:23 - 00003481 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix_Report((mp3)).txt 2014-04-03 21:23 - 2014-04-03 21:22 - 00003481 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix [Scan 3] JA((mp3)).txt 2014-04-03 21:21 - 2014-04-03 21:21 - 00003728 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix_Report((pendrive)).txt 2014-04-03 21:21 - 2014-04-03 21:21 - 00003728 _____ () D:\Documents and Settings\JA\Pulpit\UsbFix [Scan 2] JA ((pendrive)).txt 2014-04-03 21:18 - 2010-08-19 18:08 - 00707192 _____ () D:\WINDOWS\system32\PerfStringBackup.INI 2014-04-03 21:18 - 2001-10-26 18:15 - 00335926 _____ () D:\WINDOWS\system32\perfh015.dat 2014-04-03 21:18 - 2001-10-26 18:15 - 00041818 _____ () D:\WINDOWS\system32\perfc015.dat 2014-04-03 21:13 - 2010-08-19 16:47 - 00032512 _____ () D:\WINDOWS\SchedLgU.Txt 2014-04-03 21:13 - 2010-08-19 16:47 - 00000006 ____H () D:\WINDOWS\Tasks\SA.DAT 2014-04-03 21:12 - 2012-12-20 16:02 - 00092652 _____ () D:\WINDOWS\WindowsUpdate.log 2014-04-03 21:12 - 2010-08-19 16:48 - 00000188 ___SH () D:\Documents and Settings\JA\ntuser.ini 2014-04-03 15:36 - 2014-04-01 14:05 - 00000148 _____ () D:\Documents and Settings\JA\Pulpit\Kwiecień 1.txt 2014-04-03 14:48 - 2014-04-03 13:52 - 00000142 _____ () D:\Documents and Settings\JA\Pulpit\Orzeł, reszka.txt 2014-04-03 13:23 - 2012-01-31 16:58 - 00000000 ____D () D:\Documents and Settings\JA\Dane aplikacji\foobar2000 2014-04-02 22:58 - 2014-04-01 22:43 - 00000569 _____ () D:\Documents and Settings\JA\Pulpit\Typowanie na typerku - Kwiecień.txt 2014-04-02 14:31 - 2010-08-19 16:47 - 00000000 ____D () D:\Documents and Settings\JA 2014-04-01 18:44 - 2014-04-01 16:32 - 477961940 _____ () D:\Documents and Settings\JA\Pulpit\Sport+.30.03.2014.avi 2014-03-30 22:27 - 2010-08-19 16:47 - 00000000 ___RD () D:\Documents and Settings\JA\Moje dokumenty\Ulubione 2014-03-25 21:20 - 2014-03-25 19:51 - 545361164 _____ () D:\Sport2 2014-03-24 18:42 - 2011-11-01 14:23 - 00000000 ____D () D:\Documents and Settings\JA\Moje dokumenty\FIFA 07 2014-03-24 11:51 - 2001-07-22 00:17 - 00002184 _____ () D:\WINDOWS\system32\wpa.dbl 2014-03-20 12:09 - 2013-07-23 14:27 - 00000000 ____D () D:\Program Files\Mozilla Firefox 2014-03-20 12:05 - 2013-12-26 23:35 - 00000000 ___HD () D:\Program Files\Rainmeter 2014-03-20 12:05 - 2013-12-26 22:44 - 00000000 ___HD () D:\Program Files\Rainlendar2 2014-03-20 12:00 - 2014-02-02 00:11 - 00000000 ____D () D:\Program Files\ePSXe180 2014-03-19 23:48 - 2010-08-19 16:48 - 00000000 __RSD () D:\Documents and Settings\JA\Moje dokumenty\Moje obrazy 2014-03-19 20:46 - 2014-03-19 20:46 - 00001376 _____ () D:\UsbFix.lnk 2014-03-19 20:46 - 2014-03-19 20:46 - 00000000 ____D () D:\UsbFix 2014-03-19 20:43 - 2014-03-19 20:43 - 03099901 _____ (El Desaparecido - SosVirus.net - UsbFix.net) D:\usbfix0.exe 2014-03-18 11:55 - 2010-08-19 17:22 - 00000000 ____D () D:\Documents and Settings\JA\Dane aplikacji\Mozilla 2014-03-18 01:09 - 2010-08-19 16:47 - 00000000 ___RD () D:\Documents and Settings\JA\Moje dokumenty 2014-03-18 00:54 - 2010-08-19 16:47 - 00000000 ____D () D:\Documents and Settings\JA\Dane aplikacji\uTorrent 2014-03-18 00:47 - 2013-12-26 22:44 - 00000000 ____D () D:\Documents and Settings\JA\.rainlendar2 2014-03-18 00:44 - 2010-12-28 21:23 - 00000000 ___HD () D:\Program Files\InstallShield Installation Information 2014-03-18 00:44 - 2010-08-19 18:08 - 00000000 ___RD () D:\Documents and Settings\All Users\Menu Start\Programy 2014-03-08 00:36 - 2014-03-07 23:21 - 449148254 _____ () D:\Sport 2014-03-04 11:17 - 2013-06-05 16:02 - 00058364 _____ () D:\WINDOWS\setupapi.log ZeroAccess: D:\Windows\assembly\GAC\Desktop.ini Some content of TEMP: ==================== D:\Documents and Settings\JA\Ustawienia lokalne\Temp\RtkBtMnt.exe ==================== Bamital & volsnap Check ================= D:\WINDOWS\explorer.exe [2008-01-29 01:09] - [2008-01-29 01:09] - 1502720 ____A (Microsoft Corporation) 43fa4144a1459f4acad155347d39be4b D:\WINDOWS\system32\winlogon.exe [2004-08-03 23:44] - [2004-08-03 23:44] - 0504832 ____A (Microsoft Corporation) 0344407089b08548d4feba62bb0f32d0 D:\WINDOWS\system32\svchost.exe [2004-08-03 23:44] - [2004-08-03 23:44] - 0014336 ____A (Microsoft Corporation) ba98327e90022dbd6ee76490e0622e2e D:\WINDOWS\system32\services.exe [2004-08-03 23:44] - [2004-08-03 23:44] - 0108544 ____A (Microsoft Corporation) 3da8d964d2cc12ef8e8c342471a37917 D:\WINDOWS\system32\User32.dll [2008-01-29 01:17] - [2008-01-29 01:17] - 0486912 ____A (Microsoft Corporation) 84e2e68559d201e3d660309b35ee4abf D:\WINDOWS\system32\userinit.exe [2004-08-03 23:44] - [2004-08-03 23:44] - 0025088 ____A (Microsoft Corporation) bd768099b4c44aa631728cb74eb54396 D:\WINDOWS\system32\rpcss.dll [2008-01-28 23:15] - [2008-01-28 23:15] - 0398848 ____A (Microsoft Corporation) 330bd351585b2f5826d1565bce35ec9b ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected. D:\WINDOWS\system32\Drivers\volsnap.sys IS MISSING <==== ATTENTION!. ==================== End Of Log ============================