Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:22-06-2014 Ran by Właściciel (administrator) on YOUR-17A6EC0835 on 25-06-2014 10:56:28 Running from C:\Documents and Settings\Właściciel\Desktop\lukasz\FRST Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Angielski (Stany Zjednoczone) Internet Explorer Version 7 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (Microsoft Corporation) C:\WINDOWS\ehome\ehtray.exe (ATI Technologies, Inc.) C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (Chicony) C:\WINDOWS\CNYHKey.exe (Realtek Semiconductor Corp.) C:\WINDOWS\SOUNDMAN.EXE (RealTek Semicoductor Corp.) C:\WINDOWS\ALCWZRD.EXE () C:\WINDOWS\SDDetect.exe (Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Cyberlink Corp.) C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe () C:\Program Files\blueconnect\BackgroundService\ModemListener.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Microsoft Corporation) C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.3.132.0\BBSvc.EXE (Microsoft Corporation) C:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\WINDOWS\ehome\ehrecvr.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe (Microsoft Corporation) C:\WINDOWS\ehome\ehSched.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin (Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Computer Associates) C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe () C:\Program Files\blueconnect\BackgroundService\ServiceManager.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe (HP) C:\WINDOWS\system32\HPZipm12.exe (Microsoft Corporation) C:\Program Files\Zune\ZuneBusEnum.exe (Microsoft Corporation) C:\WINDOWS\ehome\ehmsas.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\klwtblfs.exe (Opera Software) C:\Program Files\Opera\opera.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ehTray] => C:\WINDOWS\ehome\ehtray.exe [64512 2005-08-05] (Microsoft Corporation) HKLM\...\Run: [ATIPTA] => C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [344064 2005-06-08] (ATI Technologies, Inc.) HKLM\...\Run: [High Definition Audio Property Page Shortcut] => C:\WINDOWS\system32\HDAShCut.exe [61952 2005-01-08] (Windows (R) Server 2003 DDK provider) HKLM\...\Run: [FlashIcon] => C:\Program Files\Generic\USB Card Reader Driver v2.3d\FlashIcon.exe [40960 2005-03-02] (Neodio Corp.) HKLM\...\Run: [CHotkey] => C:\WINDOWS\mHotkey.exe [508416 2004-02-25] (Chicony) HKLM\...\Run: [ledpointer] => C:\WINDOWS\CNYHKey.exe [5794816 2004-02-04] (Chicony) HKLM\...\Run: [AntivirusRegistration] => C:\Program Files\CA\Etrust Antivirus\Register.exe [258048 2005-08-23] () HKLM\...\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [90112 2005-06-10] (Realtek Semiconductor Corp.) HKLM\...\Run: [AlcWzrd] => C:\WINDOWS\ALCWZRD.EXE [2754560 2005-06-09] (RealTek Semicoductor Corp.) HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-06-09] (Realtek Semiconductor Corp.) HKLM\...\Run: [LED] => C:\WINDOWS\SDDetect.exe [20480 2004-09-14] () HKLM\...\Run: [Symantec PIF AlertEng] => C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [583048 2008-01-29] (Symantec Corporation) HKLM\...\Run: [RemoteControl] => C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [32768 2004-06-28] (Cyberlink Corp.) HKLM\...\Run: [] => [X] HKLM\...\Run: [Zune Launcher] => c:\Program Files\Zune\ZuneLauncher.exe [159456 2011-08-05] (Microsoft Corporation) HKLM\...\Run: [ERA_SEPANG ModemListener] => C:\Program Files\blueconnect\BackgroundService\ModemListener.exe [102400 2010-12-07] () HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.) Winlogon\Notify\klogon: C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO) HKU\.DEFAULT\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x91000000 HKU\S-1-5-21-703209829-1500858801-3654270280-1005\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [68856 2007-11-28] (Google Inc.) HKU\S-1-5-21-703209829-1500858801-3654270280-1005\...\Run: [H/PC Connection Agent] => C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [1289000 2006-11-13] (Microsoft Corporation) HKU\S-1-5-21-703209829-1500858801-3654270280-1005\...\MountPoints2: {3fa39032-9669-11e0-91f9-0040caab8913} - G:\autorun.exe HKU\S-1-5-21-703209829-1500858801-3654270280-1005\...\MountPoints2: {6c77e102-9f0c-11db-8b7f-0040caab8913} - K:\setup.exe HKU\S-1-5-21-703209829-1500858801-3654270280-1005\...\MountPoints2: {7988d9c6-5be5-11de-90a1-0040caab8913} - G:\AutoRun.exe HKU\S-1-5-21-703209829-1500858801-3654270280-1005\...\MountPoints2: {7988d9c7-5be5-11de-90a1-0040caab8913} - G:\AutoRun.exe Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk ShortcutTarget: Service Manager.lnk -> C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation) Startup: C:\Documents and Settings\Właściciel\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Documents and Settings\Właściciel\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - HP Deskjet 2510 series.lnk ShortcutTarget: Powiadomienia monitorowania tuszu - HP Deskjet 2510 series.lnk -> C:\Program Files\HP\HP Deskjet 2510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wyborcza.pl/ HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKCU - DefaultScope {19397BC3-D8BA-40B8-9AFC-3BB592308315} URL = http://www.google.pl/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_pl SearchScopes: HKCU - {19397BC3-D8BA-40B8-9AFC-3BB592308315} URL = http://www.google.pl/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_pl BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Skype Plug-In - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\..\Interfaces\{0ADFB9B4-5402-41E8-A673-174018527EE0}: [NameServer]213.134.134.134,194.204.159.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_14_0_0_125.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 - C:\Documents and Settings\All Users\Application Data\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File FF user.js: detected! => C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPQUEST3D.DLL ( ) FF SearchPlugin: C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\babylon.xml FF SearchPlugin: C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\BrowserDefender.xml FF SearchPlugin: C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\delta.xml FF SearchPlugin: C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\Firefox.xml FF SearchPlugin: C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\searchplugins\holasearch.xml FF Extension: HolaSearch - C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\Extensions\ffxtlbr@holasearch.com [2013-06-11] FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\Właściciel\Application Data\Mozilla\Firefox\Profiles\gymd578x.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-04-27] FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com [2014-06-16] FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@holasearch.com [2014-06-16] FF Extension: Blokowanie banerów - C:\Program Files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak [2014-06-16] FF Extension: Kaspersky URL Advisor - C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak [2014-06-16] FF Extension: Skype extension - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-06-16] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-03-26] FF HKLM\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru FF HKLM\...\Firefox\Extensions: [url_advisor@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-05-26] FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-05-26] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-05-26] FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Chặn quảng cáo - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-05-26] FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-05-26] ========================== Services (Whitelisted) ================= R2 avp; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-16] (Kaspersky Lab ZAO) S3 CA_LIC_CLNT; C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe [126976 2005-03-23] (Computer Associates International Inc.) [File not signed] R2 LiveUpdate Notice Service; C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [583048 2008-01-29] (Symantec Corporation) R2 LogWatch; C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe [53248 2005-02-23] (Computer Associates) [File not signed] R2 McrdSvc; C:\WINDOWS\ehome\mcrdsvc.exe [99328 2005-08-05] (Microsoft Corporation) S3 MHN; C:\WINDOWS\System32\mhn.dll [85504 2004-08-10] (Microsoft Corporation) [File not signed] R2 Modem Device Helper; C:\Program Files\blueconnect\BackgroundService\ServiceManager.exe [45056 2010-07-23] () [File not signed] R2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe [7442493 2000-08-06] (Microsoft Corporation) [File not signed] S3 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [65602 2000-08-06] (Microsoft Corporation) [File not signed] R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [73728 2007-08-09] (HP) [File not signed] S3 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE [303170 2000-08-06] (Microsoft Corporation) [File not signed] R2 ZuneBusEnum; c:\Program Files\Zune\ZuneBusEnum.exe [57056 2011-08-05] (Microsoft Corporation) S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] ==================== Drivers (Whitelisted) ==================== R3 3xHybrid; C:\WINDOWS\System32\DRIVERS\3xHybrid.sys [846592 2006-02-02] (Philips Semiconductors GmbH) S3 Cap7134; C:\WINDOWS\System32\DRIVERS\Cap7134.sys [350752 2003-06-05] (Philips Semiconductors) [File not signed] S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation) R3 filter; C:\WINDOWS\System32\drivers\filter.sys [8832 2004-11-26] (Walter Oney Software) [File not signed] S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2005-01-08] (Windows (R) Server 2003 DDK provider) S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [51120 2004-12-14] (HP) S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2004-12-14] (HP) S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21744 2004-12-14] (HP) S3 hwdatacard; C:\WINDOWS\System32\DRIVERS\ewusbmdm.sys [101120 2007-10-02] (Huawei Technologies Co., Ltd.) [File not signed] R3 IrBus; C:\WINDOWS\System32\DRIVERS\IrBus.sys [46848 2013-07-17] (Microsoft Corporation) S3 jrdusbser; C:\WINDOWS\System32\DRIVERS\jrdusbser.sys [105344 2010-07-23] (TCT International Mobile Ltd) R0 KL1; C:\WINDOWS\System32\DRIVERS\kl1.sys [135776 2014-05-26] (Kaspersky Lab ZAO) R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [576096 2014-05-26] (Kaspersky Lab ZAO) R3 klim5; C:\WINDOWS\System32\DRIVERS\klim5.sys [36448 2013-04-19] (Kaspersky Lab ZAO) R3 klkbdflt; C:\WINDOWS\System32\DRIVERS\klkbdflt.sys [24672 2014-05-26] (Kaspersky Lab ZAO) R3 klmouflt; C:\WINDOWS\System32\DRIVERS\klmouflt.sys [24672 2013-10-16] (Kaspersky Lab ZAO) R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\WINDOWS\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\WINDOWS\System32\DRIVERS\kneps.sys [144992 2014-05-26] (Kaspersky Lab ZAO) S3 MHNDRV; C:\WINDOWS\System32\DRIVERS\mhndrv.sys [11008 2004-08-10] (Microsoft Corporation) [File not signed] S3 MPE; C:\WINDOWS\System32\DRIVERS\MPE.sys [15232 2008-04-13] (Microsoft Corporation) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation) S3 nm; C:\WINDOWS\System32\DRIVERS\NMnt.sys [40320 2008-04-13] (Microsoft Corporation) S3 NPF; C:\WINDOWS\System32\drivers\npf.sys [32512 2005-08-02] (CACE Technologies) [File not signed] R3 pfc; C:\WINDOWS\System32\drivers\pfc.sys [10368 2003-12-05] (Padus, Inc.) [File not signed] S3 PhTVTune; C:\WINDOWS\System32\DRIVERS\PhTVTune.sys [24704 2003-06-12] (Philips Semiconductors) [File not signed] R3 RT2500; C:\WINDOWS\System32\DRIVERS\RT2500.sys [104448 2004-02-17] (Ralink Technology Inc.) R3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-04] (Realtek Semiconductor Corporation) S3 SONYPVU1; C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation) R3 UKBFLT; C:\WINDOWS\System32\DRIVERS\UKBFLT.sys [11672 2003-12-19] (Chicony) S3 USBAAPL; C:\WINDOWS\System32\Drivers\usbaapl.sys [42496 2011-08-02] (Apple, Inc.) [File not signed] S3 usbsermpt; C:\WINDOWS\System32\DRIVERS\usbsermpt.sys [22768 2008-09-01] (Microsoft Corporation) [File not signed] S3 wceusbsh; C:\WINDOWS\System32\DRIVERS\wceusbsh.sys [28672 2006-11-06] (Microsoft Corporation) R2 zumbus; C:\WINDOWS\System32\DRIVERS\zumbus.sys [41472 2011-08-05] (Microsoft Corporation) R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}t; C:\WINDOWS\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}t.sys [55232 2014-06-16] (StdLib) U5 klflt; C:\Windows\System32\Drivers\klflt.sys [93792 2014-05-26] (Kaspersky Lab ZAO) U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== NETSVC: MHN -> C:\Windows\System32\mhn.dll (Microsoft Corporation) ==================== One Month Created Files and Folders ======== 2014-06-25 10:55 - 2014-06-25 10:56 - 00000000 ____D () C:\FRST 2014-06-25 10:46 - 2014-06-25 10:46 - 00163640 _____ () C:\Documents and Settings\Właściciel\My Documents\cc_20140625_104644.reg 2014-06-24 16:00 - 2014-06-24 16:00 - 00000000 ____D () C:\Program Files\9-lab 2014-06-24 16:00 - 2014-06-24 16:00 - 00000000 ____D () C:\Documents and Settings\Właściciel\Application Data\9-lab 2014-06-24 16:00 - 2014-06-24 16:00 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\9-lab Removal Tool 2014-06-24 16:00 - 2014-06-24 16:00 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\9-lab 2014-06-24 15:32 - 2014-06-25 10:43 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\lukasz 2014-06-17 20:42 - 2014-06-16 15:52 - 00055232 _____ (StdLib) C:\WINDOWS\system32\Drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}t.sys 2014-06-16 16:43 - 2014-06-16 16:43 - 00001498 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Opera 12.16 1860.lnk 2014-06-16 16:43 - 2014-06-16 16:43 - 00001492 _____ () C:\Documents and Settings\All Users\Desktop\Opera 12.16 1860.lnk 2014-06-16 16:34 - 2014-06-25 10:41 - 00000000 ____D () C:\Program Files\Greener Web 2014-06-16 16:26 - 2014-06-16 16:26 - 00679208 _____ () C:\Documents and Settings\Właściciel\My Documents\Opera 12.16.exe 2014-06-16 16:15 - 2014-06-25 10:42 - 00000450 _____ () C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1402928087.job 2014-06-16 16:14 - 2014-06-16 16:14 - 00000669 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk 2014-06-16 16:14 - 2014-06-16 16:14 - 00000669 _____ () C:\Documents and Settings\All Users\Desktop\Opera.lnk 2014-06-16 16:06 - 2014-06-16 16:08 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-06-16 12:52 - 2014-06-16 12:53 - 27623336 _____ (Opera Software ASA) C:\Documents and Settings\Właściciel\My Documents\Opera_22.0.1471.50_Setup.exe 2014-06-16 12:51 - 2014-06-16 12:51 - 00000000 ____D () C:\Documents and Settings\Właściciel\Local Settings\Application Data\Opera Software 2014-06-16 12:50 - 2014-06-16 12:50 - 00000000 ____D () C:\Documents and Settings\Właściciel\Application Data\Opera Software 2014-06-03 11:41 - 2014-06-06 17:45 - 00256238 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-703209829-1500858801-3654270280-1005-0.dat 2014-05-28 14:44 - 2014-05-28 15:09 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\Turcja 2014-05-28 14:41 - 2014-05-28 14:41 - 00001756 _____ () C:\Documents and Settings\Właściciel\Desktop\HP Photo Creations (2).lnk 2014-05-28 14:26 - 2014-05-28 14:26 - 00006656 ___SH () C:\Documents and Settings\Właściciel\My Documents\Thumbs.db 2014-05-27 11:20 - 2014-06-25 10:40 - 00257594 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat 2014-05-26 11:40 - 2014-05-27 11:26 - 00001999 _____ () C:\Documents and Settings\Właściciel\Desktop\Bezpieczne pieniądze.lnk 2014-05-26 11:35 - 2014-05-26 11:35 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Kaspersky Internet Security 2014-05-26 11:35 - 2014-05-26 11:30 - 00000889 _____ () C:\Documents and Settings\All Users\Desktop\Kaspersky Internet Security.lnk 2014-05-26 11:13 - 2014-05-26 11:13 - 00000000 ____D () C:\Program Files\Microsoft.NET ==================== One Month Modified Files and Folders ======= 2014-06-25 10:57 - 2012-07-02 11:58 - 00000930 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-06-25 10:57 - 2010-04-27 12:25 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2014-06-25 10:57 - 2007-11-27 18:40 - 00000000 ____D () C:\Documents and Settings\Właściciel\Local Settings\Temp 2014-06-25 10:56 - 2014-06-25 10:55 - 00000000 ____D () C:\FRST 2014-06-25 10:48 - 2007-11-27 18:40 - 00000000 ____D () C:\Documents and Settings\Właściciel 2014-06-25 10:46 - 2014-06-25 10:46 - 00163640 _____ () C:\Documents and Settings\Właściciel\My Documents\cc_20140625_104644.reg 2014-06-25 10:44 - 2005-09-13 21:29 - 01897632 ____C () C:\WINDOWS\WindowsUpdate.log 2014-06-25 10:43 - 2014-06-24 15:32 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\lukasz 2014-06-25 10:42 - 2014-06-16 16:15 - 00000450 _____ () C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1402928087.job 2014-06-25 10:42 - 2005-09-13 21:28 - 00000000 ____D () C:\WINDOWS\Registration 2014-06-25 10:42 - 2005-09-13 14:26 - 00000159 ____C () C:\WINDOWS\wiadebug.log 2014-06-25 10:42 - 2005-09-13 14:26 - 00000050 ____C () C:\WINDOWS\wiaservc.log 2014-06-25 10:41 - 2014-06-16 16:34 - 00000000 ____D () C:\Program Files\Greener Web 2014-06-25 10:41 - 2014-03-31 10:07 - 00000232 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job 2014-06-25 10:41 - 2010-02-12 12:22 - 00001032 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-25 10:41 - 2005-09-13 21:34 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-06-25 10:41 - 2005-09-13 14:22 - 00203088 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-06-25 10:40 - 2014-05-27 11:20 - 00257594 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat 2014-06-25 10:40 - 2007-11-27 18:40 - 00000178 ___SH () C:\Documents and Settings\Właściciel\ntuser.ini 2014-06-25 10:40 - 2005-09-13 21:34 - 00032556 ____N () C:\WINDOWS\SchedLgU.Txt 2014-06-25 10:35 - 2012-07-02 11:58 - 00699056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2014-06-25 10:35 - 2012-07-02 11:58 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2014-06-25 10:31 - 2013-06-11 11:05 - 00000000 ____D () C:\Documents and Settings\Właściciel\Application Data\Babylon 2014-06-25 10:31 - 2013-06-11 11:05 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\IBUpdaterService 2014-06-25 10:10 - 2013-09-23 11:10 - 00000468 _____ () C:\WINDOWS\Tasks\At1.job 2014-06-25 10:10 - 2010-02-12 12:22 - 00001036 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-25 10:05 - 2013-09-23 12:10 - 00000500 _____ () C:\WINDOWS\Tasks\HP Photo Creations Communicator.job 2014-06-25 08:00 - 2010-02-16 14:04 - 00000376 _____ () C:\WINDOWS\Tasks\HPpromotions journeysoftware.job 2014-06-24 20:40 - 2013-09-23 11:10 - 00000468 _____ () C:\WINDOWS\Tasks\At2.job 2014-06-24 16:00 - 2014-06-24 16:00 - 00000000 ____D () C:\Program Files\9-lab 2014-06-24 16:00 - 2014-06-24 16:00 - 00000000 ____D () C:\Documents and Settings\Właściciel\Application Data\9-lab 2014-06-24 16:00 - 2014-06-24 16:00 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\9-lab Removal Tool 2014-06-24 16:00 - 2014-06-24 16:00 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\9-lab 2014-06-24 15:46 - 2005-09-13 21:15 - 00000666 ____C () C:\WINDOWS\win.ini 2014-06-24 15:43 - 2012-07-13 12:45 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-06-24 15:10 - 2007-11-28 12:26 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\Wapro 2014-06-24 14:00 - 2013-09-23 11:10 - 00000468 _____ () C:\WINDOWS\Tasks\At4.job 2014-06-24 11:10 - 2013-09-23 11:10 - 00000468 _____ () C:\WINDOWS\Tasks\At3.job 2014-06-23 12:18 - 2005-09-13 21:15 - 00001158 _____ () C:\WINDOWS\system32\wpa.dbl 2014-06-18 16:21 - 2007-12-03 14:43 - 00000000 ____D () C:\Program Files\Opera 2014-06-18 15:35 - 2007-11-28 17:07 - 00002525 _____ () C:\Documents and Settings\Właściciel\Desktop\Microsoft Word.lnk 2014-06-18 14:43 - 2013-08-02 12:34 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\PKO historia 2014-06-17 12:56 - 2013-12-13 11:16 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\GO SPORT 2014-06-17 12:55 - 2008-10-09 15:20 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\ABM 2014-06-16 16:43 - 2014-06-16 16:43 - 00001498 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Opera 12.16 1860.lnk 2014-06-16 16:43 - 2014-06-16 16:43 - 00001492 _____ () C:\Documents and Settings\All Users\Desktop\Opera 12.16 1860.lnk 2014-06-16 16:26 - 2014-06-16 16:26 - 00679208 _____ () C:\Documents and Settings\Właściciel\My Documents\Opera 12.16.exe 2014-06-16 16:14 - 2014-06-16 16:14 - 00000669 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk 2014-06-16 16:14 - 2014-06-16 16:14 - 00000669 _____ () C:\Documents and Settings\All Users\Desktop\Opera.lnk 2014-06-16 16:11 - 2007-11-29 10:37 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\Różne 2014-06-16 16:08 - 2014-06-16 16:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-06-16 15:52 - 2014-06-17 20:42 - 00055232 _____ (StdLib) C:\WINDOWS\system32\Drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}t.sys 2014-06-16 12:53 - 2014-06-16 12:52 - 27623336 _____ (Opera Software ASA) C:\Documents and Settings\Właściciel\My Documents\Opera_22.0.1471.50_Setup.exe 2014-06-16 12:51 - 2014-06-16 12:51 - 00000000 ____D () C:\Documents and Settings\Właściciel\Local Settings\Application Data\Opera Software 2014-06-16 12:50 - 2014-06-16 12:50 - 00000000 ____D () C:\Documents and Settings\Właściciel\Application Data\Opera Software 2014-06-12 14:33 - 2010-08-04 12:47 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\Adres 2014-06-12 03:11 - 2013-07-12 10:07 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-06-12 03:03 - 2005-11-21 14:44 - 92708840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-06-10 13:07 - 2007-11-29 10:37 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\Checkpoint 2014-06-09 13:06 - 2009-08-07 10:13 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\EKO CYKL 2014-06-06 17:45 - 2014-06-03 11:41 - 00256238 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-703209829-1500858801-3654270280-1005-0.dat 2014-06-06 14:36 - 2013-07-23 12:57 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\liczyk dok 2014-06-06 14:13 - 2007-11-29 10:14 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\Dennison 2014-06-05 13:32 - 2013-05-23 12:35 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\dokumenty bank 2014-06-05 12:35 - 2013-10-18 11:33 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\instrukcja 2014-05-29 13:11 - 2007-12-11 16:24 - 00002409 _____ () C:\Documents and Settings\Właściciel\Desktop\Remik Carioca.lnk 2014-05-28 15:09 - 2014-05-28 14:44 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\Turcja 2014-05-28 14:58 - 2013-09-23 12:11 - 00000000 ___RD () C:\Documents and Settings\Właściciel\My Documents\HP Photo Creations 2014-05-28 14:58 - 2013-09-23 11:11 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\HP Photo Creations 2014-05-28 14:43 - 2007-12-03 13:15 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\PŁATNOŚCI 2014-05-28 14:41 - 2014-05-28 14:41 - 00001756 _____ () C:\Documents and Settings\Właściciel\Desktop\HP Photo Creations (2).lnk 2014-05-28 14:41 - 2013-11-21 12:16 - 00000000 ___RD () C:\Documents and Settings\Właściciel\Desktop\Nawigator HP 2014-05-28 14:26 - 2014-05-28 14:26 - 00006656 ___SH () C:\Documents and Settings\Właściciel\My Documents\Thumbs.db 2014-05-28 14:26 - 2013-09-02 12:39 - 00000000 ____D () C:\Documents and Settings\Właściciel\Desktop\CHORWACJA 2014-05-27 13:59 - 2005-09-13 21:27 - 00000000 ____D () C:\WINDOWS\Microsoft.NET 2014-05-27 11:26 - 2014-05-26 11:40 - 00001999 _____ () C:\Documents and Settings\Właściciel\Desktop\Bezpieczne pieniądze.lnk 2014-05-27 11:07 - 2005-09-13 14:23 - 00589846 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-05-26 12:27 - 2013-05-23 14:06 - 00093792 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys 2014-05-26 12:27 - 2013-05-23 13:43 - 00576096 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys 2014-05-26 12:27 - 2013-02-28 21:13 - 00024672 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klkbdflt.sys 2014-05-26 12:27 - 2012-08-13 16:49 - 00144992 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kneps.sys 2014-05-26 12:27 - 2012-06-19 17:28 - 00135776 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kl1.sys 2014-05-26 11:37 - 2013-05-23 12:21 - 00000000 ____D () C:\Documents and Settings\All Users\Kaspersky Lab Setup Files 2014-05-26 11:35 - 2014-05-26 11:35 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Kaspersky Internet Security 2014-05-26 11:33 - 2010-05-28 10:08 - 00000000 ____D () C:\Program Files\Kaspersky Lab 2014-05-26 11:30 - 2014-05-26 11:35 - 00000889 _____ () C:\Documents and Settings\All Users\Desktop\Kaspersky Internet Security.lnk 2014-05-26 11:13 - 2014-05-26 11:13 - 00000000 ____D () C:\Program Files\Microsoft.NET Files to move or delete: ==================== C:\Windows\Tasks\At1.job C:\Windows\Tasks\At2.job C:\Windows\Tasks\At3.job C:\Windows\Tasks\At4.job Some content of TEMP: ==================== C:\Documents and Settings\Właściciel\Local Settings\Temp\uninst1.exe ==================== Bamital & volsnap Check ================= C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================