Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-05-2014 Ran by sklep (administrator) on M14 on 15-05-2014 09:20:45 Running from C:\Users\sklep\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 9 Boot Mode: Safe Mode (with Networking) The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Google Inc.) C:\Users\sklep\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\sklep\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\sklep\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\sklep\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\sklep\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\sklep\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1822504 2009-08-24] (Synaptics Incorporated) HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.) HKLM\...\Run: [FreeFallProtection] => C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe [2384896 2009-07-22] () HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-01-21] (IDT, Inc.) HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.) HKLM\...\Run: [rfagent] => C:\Program Files\RFA 8\rfagent64.exe [3145864 2012-01-27] (KsL Software) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-11-18] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [PDVDDXSrv] => C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe [140520 2009-12-29] (CyberLink Corp.) HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [409744 2009-06-24] (Creative Technology Ltd) HKLM-x32\...\Run: [Desktop Disc Tool] => c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [498160 2009-10-15] () HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31072 2008-10-25] (Microsoft Corporation) HKLM-x32\...\Run: [NBKeyScan] => C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2221352 2008-02-18] (Nero AG) HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [74752 2010-12-09] (Nullsoft, Inc.) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-10-17] (Intel Corporation) HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296056 2012-01-15] (RealNetworks, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\S-1-5-21-1081826087-927070240-1253586494-1000\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1828136 2008-02-28] (Nero AG) HKU\S-1-5-21-1081826087-927070240-1253586494-1000\...\Run: [Argus Monitor] => C:\Program Files (x86)\ArgusMonitor\ArgusMonitor.exe [1762504 2012-08-06] (Argotronic UG (haftungsbeschraenkt)) HKU\S-1-5-21-1081826087-927070240-1253586494-1000\...\Run: [SoniqueQuickStart] => C:\Program Files (x86)\Sonique\sqstart.exe [44832 2011-05-27] () HKU\S-1-5-21-1081826087-927070240-1253586494-1000\...\Run: [ModemOnHold] => C:\Program Files (x86)\NetWaiting\netWaiting.exe [26144 2007-05-10] (BVRP) HKU\S-1-5-21-1081826087-927070240-1253586494-1000\...\Run: [WirelessManager] => C:\Program Files (x86)\Dell\Dell Mobile Broadband Manager\WirelessManager.exe [175616 2009-11-26] (Ericsson AB) HKU\S-1-5-21-1081826087-927070240-1253586494-1000\...\Run: [ALLUpdate] => C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [1379840 2011-08-16] () HKU\S-1-5-21-1081826087-927070240-1253586494-1000\...\Run: [Google Update] => C:\Users\sklep\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2010-11-11] (Google Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files (x86)\Digital Line Detect\DLG.exe (Avanquest Software ) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\quickset — skrót.lnk ShortcutTarget: quickset — skrót.lnk -> C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SetPoint.lnk ShortcutTarget: SetPoint.lnk -> C:\Program Files\SetPoint\SetPoint.exe (Logitech, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files (x86)\Mplayer\Assets\Blank.htm HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files (x86)\Mplayer\Assets\Blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files (x86)\Mplayer\Assets\Blank.htm HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: IplexToALLPlayer - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\Program Files (x86)\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Tcpip\Parameters: [DhcpNameServer] 62.179.1.63 62.179.1.62 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @ganymede/GanymedeNetPlugin,version=1.0 - C:\Program Files (x86)\Ganymede\Plugins\npganymedenet.dll ( ) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @real.com/nppl3260;version=15.0.1.13 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprjplug;version=15.0.1.13 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.1.13 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.1.13 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpjplug;version=15.0.1.13 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\sklep\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\sklep\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\sklep\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-01-15] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://google.pl/" CHR Plugin: (Shockwave Flash) - C:\Users\sklep\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.225\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\sklep\AppData\Local\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\sklep\AppData\Local\Google\Chrome\Application\34.0.1847.131\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.240.7) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U24) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (GanymedeNet.Detector) - C:\Users\sklep\AppData\Local\Google\Chrome\Application\plugins\npganymedenet.dll ( ) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (Unity Player) - C:\Users\sklep\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Google Update) - C:\Users\sklep\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File CHR Extension: (YouTube) - C:\Users\sklep\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-30] CHR Extension: (Szukaj w Google) - C:\Users\sklep\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-30] CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\sklep\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2012-01-24] CHR Extension: (Google Wallet) - C:\Users\sklep\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (Gmail) - C:\Users\sklep\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-30] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2012-12-01] CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2012-01-15] CHR StartMenuInternet: Google Chrome - C:\Users\sklep\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= S3 BITCOMET_HELPER_SERVICE; C:\Program Files (x86)\BitComet\tools\BitCometService.exe [1296728 2010-12-28] (www.BitComet.com) S2 InstallFilterService; C:\Program Files (x86)\STMicroelectronics\Accelerometer\InstallFilterService.exe [60928 2009-06-23] () S2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) S2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-02-18] (Nero AG) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [529704 2008-02-28] (Nero AG) S2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) S2 QDLService2kDell; C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kDell.exe [330488 2010-01-14] (QUALCOMM, Inc.) S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) S2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\STacSV64.exe [244736 2010-01-21] (IDT, Inc.) S2 UserAccess7; C:\Windows\SysWOW64\UAService7.exe [143360 2013-11-13] (Sony DADC Austria AG.) S2 wltrysvc; C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe [3417088 2009-07-17] (Dell Inc.) S2 WMCoreService; C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe [447488 2009-11-26] () ==================== Drivers (Whitelisted) ==================== S1 acedrv05; C:\Windows\system32\drivers\acedrv05.sys [136192 2011-03-31] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 ArgusMonitor; C:\Windows\SysWow64\drivers\ArgusMonitor.sys [67272 2012-06-01] (Argotronic UG (haftungsbeschraenkt)) S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [303616 2012-07-26] () S3 bdfsfltr; C:\Windows\SysWOW64\DRIVERS\bdfsfltr.sys [327368 2010-07-27] (BitDefender) S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [35328 2012-07-26] () R0 sfdrv01; C:\Windows\System32\drivers\sfdrv01.sys [75384 2009-02-03] (Protection Technology (StarForce)) R0 sfdrv01a; C:\Windows\System32\drivers\sfdrv01a.sys [77432 2009-02-03] (Protection Technology (StarForce)) S0 sfsync02; C:\Windows\System32\drivers\sfsync02.sys [22936 2006-07-10] (Protection Technology) R0 sfvfs02; C:\Windows\System32\drivers\sfvfs02.sys [107384 2007-02-08] (Protection Technology (StarForce)) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-07-06] (Duplex Secure Ltd.) S2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] () S3 zlportio; C:\Program Files (x86)\UltraStar\zlportio.sys [4016 2012-08-08] (SpecoSoft) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-15 09:20 - 2014-05-15 09:21 - 00018138 ____C () C:\Users\sklep\Downloads\FRST.txt 2014-05-15 09:18 - 2014-05-15 09:20 - 00000000 ___DC () C:\FRST 2014-05-15 09:17 - 2014-05-15 09:17 - 02066944 ____C (Farbar) C:\Users\sklep\Downloads\FRST64.exe 2014-05-15 08:50 - 2014-05-15 08:50 - 00000000 ___DC () C:\ProgramData\b5240000-6513-4c4b-d7e9-c6fb99050493 2014-05-15 02:06 - 2014-05-15 02:06 - 00000000 ___DC () C:\ProgramData\BitDefender 2014-05-13 15:48 - 2014-05-13 15:48 - 00001199 ____C () C:\Users\Public\Desktop\Stupid Invaders.lnk 2014-05-13 15:48 - 2014-05-13 15:48 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xilam 2014-05-13 15:20 - 2014-05-13 15:20 - 00000000 ___DC () C:\Program Files (x86)\Xilam 2014-05-13 14:30 - 2014-05-13 14:30 - 00112302 ____C () C:\Users\sklep\Downloads\3FA52C0A67605776DFCCEB5819FFB5784F9D6BFE.torrent 2014-05-13 08:42 - 2014-05-13 09:05 - 00000000 ___DC () C:\Users\sklep\Desktop\Ekotoksykologia 2014-05-12 18:04 - 2014-05-14 13:23 - 03161088 ____C () C:\Users\sklep\Desktop\Zmiany w zespołach i ekosystemach.ppt 2014-05-12 16:33 - 2014-05-12 16:33 - 00021119 ____C () C:\Users\sklep\Downloads\7BF0635867BA3C6147C7CA907103DA2D8ABBF573.torrent 2014-05-12 16:32 - 2014-05-12 16:32 - 00021236 ____C () C:\Users\sklep\Downloads\Simpsonowie The Simpsons Sezon 2 [TVRip] [Lektor PL][torren.pl].torrent 2014-05-12 16:32 - 2014-05-12 16:32 - 00021235 ____C () C:\Users\sklep\Downloads\[www.tnt24.info] Simpsonowie - The Simpsons - Sezon 2 [TVRip] [Lektor PL].torrent 2014-05-10 02:02 - 2014-05-10 02:02 - 00033851 ____C () C:\Users\sklep\Downloads\South.Park.S17E09.PROPER.HDTV.XviD-AFG.srt 2014-05-07 23:53 - 2014-05-07 23:53 - 00002081 ____C () C:\Users\Public\Desktop\NBA Live 2003.lnk 2014-05-06 21:07 - 2014-05-06 21:07 - 00063505 ____C () C:\Users\sklep\Downloads\dane do bet.xlsx 2014-05-06 20:03 - 2014-05-06 20:03 - 00347648 ____C () C:\Users\sklep\Downloads\dane do bet.xls 2014-05-06 14:06 - 2014-05-06 14:06 - 00003643 ____C () C:\Users\sklep\Downloads\C12.DFT.RAW 2014-05-06 13:52 - 2014-05-06 13:52 - 00004387 ____C () C:\Users\sklep\Downloads\MCM-E58.RAW 2014-05-05 22:16 - 2014-05-05 22:22 - 604056936 ____C () C:\Users\sklep\Downloads\BBC Życie ptaków odc.4 PL Mięsożercy.avi 2014-05-05 21:34 - 2014-05-05 21:42 - 604277282 ____C () C:\Users\sklep\Downloads\BBC Życie ptaków odc.3 PL Nienasycony apetyt.avi 2014-05-05 21:30 - 2014-05-05 21:34 - 288655698 ____C () C:\Users\sklep\Downloads\BBC Życie ptaków odc.02 PL Mistrzowie lotu.avi 2014-05-05 21:26 - 2014-05-05 21:29 - 324374890 ____C () C:\Users\sklep\Downloads\BBC Życie ptaków odc.01 PL Latać, czy nie latać.avi 2014-04-29 15:09 - 2014-04-29 15:09 - 00002264 ____C () C:\Users\sklep\Desktop\Gothic II Złota Edycja.lnk 2014-04-29 15:06 - 2014-04-29 15:06 - 00000000 ___DC () C:\Users\sklep\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JoWood 2014-04-29 14:59 - 2014-04-29 14:59 - 00000000 ___DC () C:\Program Files (x86)\JoWood 2014-04-29 08:58 - 2014-04-29 10:23 - 00000000 ___DC () C:\Program Files (x86)\Telltale Games 2014-04-27 15:43 - 2014-04-27 21:32 - 00000000 ___DC () C:\Program Files (x86)\3DO 2014-04-27 15:43 - 1998-10-07 12:54 - 00327168 ____C (InstallShield Software Corporation) C:\Windows\IsUn0415.exe 2014-04-27 14:17 - 2014-04-27 14:17 - 10231953 ____C () C:\Users\sklep\Downloads\wpn_s2_pl.exe 2014-04-18 23:37 - 2014-04-18 23:37 - 00000000 ___DC () C:\Users\sklep\Downloads\Proceente_-_Znaki_Zapytania__2004_ 2014-04-15 14:55 - 2014-04-15 14:55 - 00000000 ___DC () C:\ProgramData\CODEX 2014-04-15 14:52 - 2014-04-15 14:52 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Walking Dead Season 2 EP 2 2014-04-15 13:55 - 2014-04-15 13:55 - 03887821 ____C () C:\Users\sklep\Downloads\zt_s2_pl.exe 2014-04-15 13:44 - 2014-04-15 13:44 - 00019134 ____C () C:\Users\sklep\Downloads\[kickass.to]the.walking.dead.season.2.multi.pcdvd.episode.2.codex (1).torrent 2014-04-15 13:41 - 2014-04-15 13:41 - 00019134 ____C () C:\Users\sklep\Downloads\[kickass.to]the.walking.dead.season.2.multi.pcdvd.episode.2.codex.torrent 2014-04-15 13:34 - 2014-04-15 13:34 - 00000954 ____C () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Walking Dead Season 2.lnk 2014-04-15 13:32 - 2014-04-15 14:49 - 00000000 ___DC () C:\Program Files (x86)\The Walking Dead Season 2 ==================== One Month Modified Files and Folders ======= 2014-05-15 09:21 - 2014-05-15 09:20 - 00018138 ____C () C:\Users\sklep\Downloads\FRST.txt 2014-05-15 09:20 - 2014-05-15 09:18 - 00000000 ___DC () C:\FRST 2014-05-15 09:17 - 2014-05-15 09:17 - 02066944 ____C (Farbar) C:\Users\sklep\Downloads\FRST64.exe 2014-05-15 08:51 - 2012-08-16 13:57 - 00306900 ____C () C:\ProgramData\bdinstall.bin 2014-05-15 08:50 - 2014-05-15 08:50 - 00000000 ___DC () C:\ProgramData\b5240000-6513-4c4b-d7e9-c6fb99050493 2014-05-15 08:47 - 2009-07-14 06:45 - 00014240 ___HC () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-15 08:47 - 2009-07-14 06:45 - 00014240 ___HC () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-15 08:44 - 2009-07-14 07:10 - 01462504 ____C () C:\Windows\WindowsUpdate.log 2014-05-15 08:37 - 2009-07-14 07:08 - 00000006 ___HC () C:\Windows\Tasks\SA.DAT 2014-05-15 08:37 - 2009-07-14 06:51 - 00181119 ____C () C:\Windows\setupact.log 2014-05-15 03:05 - 2012-03-07 23:00 - 00000000 ___DC () C:\ProgramData\RFA_Backups 2014-05-15 02:06 - 2014-05-15 02:06 - 00000000 ___DC () C:\ProgramData\BitDefender 2014-05-15 01:36 - 2014-02-04 13:51 - 00000000 ___DC () C:\ProgramData\AVG2014 2014-05-15 01:36 - 2012-08-16 14:29 - 00000000 ___DC () C:\Program Files (x86)\AVG 2014-05-15 01:36 - 2012-08-16 14:10 - 00000000 ___DC () C:\ProgramData\MFAData 2014-05-15 01:36 - 2010-05-07 05:31 - 00349934 ____C () C:\Windows\PFRO.log 2014-05-15 01:33 - 2010-09-24 20:00 - 00000000 ___DC () C:\Programy 2014-05-14 13:23 - 2014-05-12 18:04 - 03161088 ____C () C:\Users\sklep\Desktop\Zmiany w zespołach i ekosystemach.ppt 2014-05-14 12:58 - 2010-11-11 23:58 - 00001058 ____C () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1081826087-927070240-1253586494-1000UA.job 2014-05-14 10:57 - 2010-09-24 23:00 - 00000000 ___DC () C:\Users\sklep\AppData\Roaming\Winamp 2014-05-13 23:25 - 2010-09-26 10:56 - 00000000 ___DC () C:\Users\sklep\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-05-13 19:58 - 2010-11-11 23:58 - 00001006 ____C () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1081826087-927070240-1253586494-1000Core.job 2014-05-13 16:08 - 2013-05-22 15:46 - 00000000 ___DC () C:\Program Files\My Dell 2014-05-13 16:08 - 2011-12-12 14:15 - 00000000 ___DC () C:\ProgramData\PCDr 2014-05-13 16:01 - 2013-05-22 15:46 - 00003440 ____C () C:\Windows\System32\Tasks\PCDEventLauncherTask 2014-05-13 15:48 - 2014-05-13 15:48 - 00001199 ____C () C:\Users\Public\Desktop\Stupid Invaders.lnk 2014-05-13 15:48 - 2014-05-13 15:48 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xilam 2014-05-13 15:44 - 2010-09-25 18:54 - 00000000 ___DC () C:\Users\sklep\AppData\Local\Last.fm 2014-05-13 15:20 - 2014-05-13 15:20 - 00000000 ___DC () C:\Program Files (x86)\Xilam 2014-05-13 15:19 - 2010-11-06 16:04 - 00000000 ___DC () C:\Users\sklep\AppData\Roaming\BitComet 2014-05-13 14:30 - 2014-05-13 14:30 - 00112302 ____C () C:\Users\sklep\Downloads\3FA52C0A67605776DFCCEB5819FFB5784F9D6BFE.torrent 2014-05-13 12:08 - 2012-11-12 16:55 - 00000000 ___DC () C:\Games 2014-05-13 12:08 - 2010-09-26 02:36 - 00000000 ___DC () C:\Users\sklep\Desktop\Gamez 2014-05-13 09:05 - 2014-05-13 08:42 - 00000000 ___DC () C:\Users\sklep\Desktop\Ekotoksykologia 2014-05-12 23:31 - 2013-02-13 19:07 - 00014542 ____C () C:\Users\sklep\Desktop\płyty.xlsx 2014-05-12 16:54 - 2010-09-24 23:51 - 00000000 ___DC () C:\filmy 2014-05-12 16:33 - 2014-05-12 16:33 - 00021119 ____C () C:\Users\sklep\Downloads\7BF0635867BA3C6147C7CA907103DA2D8ABBF573.torrent 2014-05-12 16:33 - 2012-03-17 09:27 - 00000000 ___DC () C:\Users\sklep\Desktop\My Shared Folder 2014-05-12 16:32 - 2014-05-12 16:32 - 00021236 ____C () C:\Users\sklep\Downloads\Simpsonowie The Simpsons Sezon 2 [TVRip] [Lektor PL][torren.pl].torrent 2014-05-12 16:32 - 2014-05-12 16:32 - 00021235 ____C () C:\Users\sklep\Downloads\[www.tnt24.info] Simpsonowie - The Simpsons - Sezon 2 [TVRip] [Lektor PL].torrent 2014-05-11 16:20 - 2010-09-24 19:33 - 00000000 ___DC () C:\Zdjecia 2014-05-11 16:15 - 2010-09-24 20:29 - 00000000 ___DC () C:\mp3 2014-05-11 16:13 - 2012-03-07 21:32 - 00000000 ___DC () C:\Users\sklep\Desktop\PULPIT 2014-05-10 19:53 - 2010-11-11 23:58 - 00004032 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1081826087-927070240-1253586494-1000UA 2014-05-10 19:53 - 2010-11-11 23:58 - 00003636 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1081826087-927070240-1253586494-1000Core 2014-05-10 19:47 - 2013-01-09 12:38 - 00000000 ___DC () C:\Users\sklep\Documents\Telltale Games 2014-05-10 18:40 - 2014-01-18 12:20 - 00000000 ___DC () C:\Users\sklep\AppData\Local\Battle.net 2014-05-10 18:05 - 2009-07-14 19:55 - 00810692 ____C () C:\Windows\system32\perfh015.dat 2014-05-10 18:05 - 2009-07-14 19:55 - 00182808 ____C () C:\Windows\system32\perfc015.dat 2014-05-10 18:05 - 2009-07-14 07:13 - 01862404 ____C () C:\Windows\system32\PerfStringBackup.INI 2014-05-10 02:02 - 2014-05-10 02:02 - 00033851 ____C () C:\Users\sklep\Downloads\South.Park.S17E09.PROPER.HDTV.XviD-AFG.srt 2014-05-08 21:57 - 2012-08-12 15:38 - 00000000 ___DC () C:\Program Files (x86)\AirXonix 2014-05-08 21:43 - 2014-03-02 18:47 - 00000000 ___DC () C:\Program Files (x86)\Hearthstone 2014-05-08 15:16 - 2013-07-17 10:32 - 00000000 ___DC () C:\Nowy folder 2014-05-08 13:28 - 2013-12-02 18:15 - 00000000 ____C () C:\sparkraw.log 2014-05-08 13:21 - 2014-04-08 16:35 - 00000137 ____C () C:\Users\sklep\Desktop\juwenalia 2014.txt 2014-05-07 23:53 - 2014-05-07 23:53 - 00002081 ____C () C:\Users\Public\Desktop\NBA Live 2003.lnk 2014-05-07 23:53 - 2014-01-22 17:32 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA SPORTS 2014-05-07 23:51 - 2012-09-29 23:42 - 00000000 ___DC () C:\Program Files (x86)\EA SPORTS 2014-05-07 23:51 - 2011-02-04 15:02 - 00001335 ____C () C:\Windows\eReg.dat 2014-05-07 23:51 - 2009-07-14 05:20 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-07 23:48 - 2013-12-01 12:24 - 00000110 ____C () C:\Windows\wininit.ini 2014-05-07 23:38 - 2010-05-07 12:50 - 00000000 __HDC () C:\Program Files (x86)\InstallShield Installation Information 2014-05-07 10:35 - 2010-09-25 18:57 - 00000000 ___DC () C:\Program Files (x86)\Opera 2014-05-06 21:07 - 2014-05-06 21:07 - 00063505 ____C () C:\Users\sklep\Downloads\dane do bet.xlsx 2014-05-06 20:03 - 2014-05-06 20:03 - 00347648 ____C () C:\Users\sklep\Downloads\dane do bet.xls 2014-05-06 14:06 - 2014-05-06 14:06 - 00003643 ____C () C:\Users\sklep\Downloads\C12.DFT.RAW 2014-05-06 13:52 - 2014-05-06 13:52 - 00004387 ____C () C:\Users\sklep\Downloads\MCM-E58.RAW 2014-05-05 22:22 - 2014-05-05 22:16 - 604056936 ____C () C:\Users\sklep\Downloads\BBC Życie ptaków odc.4 PL Mięsożercy.avi 2014-05-05 21:42 - 2014-05-05 21:34 - 604277282 ____C () C:\Users\sklep\Downloads\BBC Życie ptaków odc.3 PL Nienasycony apetyt.avi 2014-05-05 21:34 - 2014-05-05 21:30 - 288655698 ____C () C:\Users\sklep\Downloads\BBC Życie ptaków odc.02 PL Mistrzowie lotu.avi 2014-05-05 21:29 - 2014-05-05 21:26 - 324374890 ____C () C:\Users\sklep\Downloads\BBC Życie ptaków odc.01 PL Latać, czy nie latać.avi 2014-05-04 21:40 - 2014-01-18 12:19 - 00000000 ___DC () C:\Program Files (x86)\Battle.net 2014-04-29 15:09 - 2014-04-29 15:09 - 00002264 ____C () C:\Users\sklep\Desktop\Gothic II Złota Edycja.lnk 2014-04-29 15:08 - 2011-11-26 17:45 - 00496099 ____C () C:\Windows\DirectX.log 2014-04-29 15:06 - 2014-04-29 15:06 - 00000000 ___DC () C:\Users\sklep\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JoWood 2014-04-29 14:59 - 2014-04-29 14:59 - 00000000 ___DC () C:\Program Files (x86)\JoWood 2014-04-29 10:23 - 2014-04-29 08:58 - 00000000 ___DC () C:\Program Files (x86)\Telltale Games 2014-04-28 17:12 - 2009-07-14 07:32 - 00000000 __RDC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-04-28 17:11 - 2013-06-28 13:56 - 00000000 ___DC () C:\Users\sklep\AppData\Roaming\Rovio Entertainment Ltd 2014-04-28 17:11 - 2013-05-27 20:35 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rovio Entertainment Ltd 2014-04-27 21:50 - 2014-01-18 12:21 - 00000000 ___DC () C:\Program Files (x86)\Diablo III 2014-04-27 21:32 - 2014-04-27 15:43 - 00000000 ___DC () C:\Program Files (x86)\3DO 2014-04-27 21:31 - 2013-12-10 16:43 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\3DO 2014-04-27 14:18 - 2014-01-31 16:17 - 00000000 ___DC () C:\Program Files (x86)\The Wolf Among Us 2014-04-27 14:17 - 2014-04-27 14:17 - 10231953 ____C () C:\Users\sklep\Downloads\wpn_s2_pl.exe 2014-04-18 23:37 - 2014-04-18 23:37 - 00000000 ___DC () C:\Users\sklep\Downloads\Proceente_-_Znaki_Zapytania__2004_ 2014-04-15 14:55 - 2014-04-15 14:55 - 00000000 ___DC () C:\ProgramData\CODEX 2014-04-15 14:52 - 2014-04-15 14:52 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Walking Dead Season 2 EP 2 2014-04-15 14:49 - 2014-04-15 13:32 - 00000000 ___DC () C:\Program Files (x86)\The Walking Dead Season 2 2014-04-15 13:55 - 2014-04-15 13:55 - 03887821 ____C () C:\Users\sklep\Downloads\zt_s2_pl.exe 2014-04-15 13:44 - 2014-04-15 13:44 - 00019134 ____C () C:\Users\sklep\Downloads\[kickass.to]the.walking.dead.season.2.multi.pcdvd.episode.2.codex (1).torrent 2014-04-15 13:41 - 2014-04-15 13:41 - 00019134 ____C () C:\Users\sklep\Downloads\[kickass.to]the.walking.dead.season.2.multi.pcdvd.episode.2.codex.torrent 2014-04-15 13:34 - 2014-04-15 13:34 - 00000954 ____C () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Walking Dead Season 2.lnk Some content of TEMP: ==================== C:\Users\sklep\AppData\Local\Temp\AutoRun.exe C:\Users\sklep\AppData\Local\Temp\AutoRunGUI.dll C:\Users\sklep\AppData\Local\Temp\Core.dll C:\Users\sklep\AppData\Local\Temp\Window.dll C:\Users\sklep\AppData\Local\Temp\_is2896.exe C:\Users\sklep\AppData\Local\Temp\_is6F3.exe C:\Users\sklep\AppData\Local\Temp\_is8287.exe C:\Users\sklep\AppData\Local\Temp\_isA91A.exe C:\Users\sklep\AppData\Local\Temp\_isB3CB.exe C:\Users\sklep\AppData\Local\Temp\_isBC2F.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-09 15:10 ==================== End Of Log ============================