Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-02-2015 01 Ran by DOM (administrator) on DOM-CB1A357076F on 28-02-2015 20:20:45 Running from C:\Documents and Settings\DOM\Pulpit\Nowy folder Loaded Profiles: DOM (Available profiles: DOM) Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 8 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2015\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgcsrvx.exe (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgui.exe () C:\Program Files\802.11g Wireless LAN\Monitor.exe (Creative Technology Ltd.) C:\WINDOWS\system32\devldr32.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgnsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgemcx.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [nwiz] => nwiz.exe /install HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3674576 2015-01-06] (AVG Technologies CZ, s.r.o.) Startup: C:\Documents and Settings\DOM\Menu Start\Programy\Autostart\Monitor.lnk ShortcutTarget: Monitor.lnk -> C:\Program Files\802.11g Wireless LAN\Monitor.exe () BootExecute: autocheck autochk * C:\PROGRA~1\AVG\AVG2015\avgrsx.exe /sync /restart ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0 FireFox: ======== FF ProfilePath: C:\Documents and Settings\DOM\Dane aplikacji\Mozilla\Firefox\Profiles\sytn14zv.default-1425145548937 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll () FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3440080 2015-01-06] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [309232 2015-01-06] (AVG Technologies CZ, s.r.o.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [121624 2014-06-18] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriverl; C:\WINDOWS\System32\DRIVERS\avgidsdriverlx.sys [192792 2014-12-08] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [154904 2014-11-18] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\WINDOWS\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-18] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [192792 2014-08-28] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [230680 2014-07-18] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [98584 2014-10-05] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [27416 2014-06-18] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\WINDOWS\System32\DRIVERS\avgtdix.sys [200984 2014-10-10] (AVG Technologies CZ, s.r.o.) R3 ctljystk; C:\WINDOWS\System32\DRIVERS\ctljystk.sys [3712 2001-08-17] (Creative Technology Ltd.) R3 emu10k; C:\WINDOWS\System32\drivers\emu10k1m.sys [283904 2001-08-17] (Creative Technology Ltd.) R3 emu10k1; C:\WINDOWS\System32\drivers\ctlfacem.sys [6912 2001-08-17] (Creative Technology Ltd.) R3 FET5X86V; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [46592 2011-02-10] (VIA Technologies, Inc. ) R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-14] (Microsoft Corporation) R3 RT61; C:\WINDOWS\System32\DRIVERS\RT61.sys [339072 2005-07-01] (Ralink Technology Inc.) [File not signed] R3 sfman; C:\WINDOWS\System32\drivers\sfmanm.sys [36480 2001-08-17] (Creative Technology Ltd.) R0 viaagp1; C:\WINDOWS\System32\DRIVERS\viaagp1.sys [26880 2002-12-27] (VIA Technologies, Inc.) S4 IntelIde; No ImagePath U1 WS2IFSL; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-28 18:45 - 2015-02-28 18:45 - 00000000 ____D () C:\Documents and Settings\DOM\Pulpit\Stare dane programu Firefox 2015-02-28 18:39 - 2015-02-28 18:39 - 00001880 _____ () C:\WINDOWS\bitssetup.log 2015-02-28 13:42 - 2015-02-28 20:20 - 00000000 ____D () C:\FRST 2015-02-28 13:23 - 2015-02-28 20:20 - 00000000 ____D () C:\Documents and Settings\DOM\Pulpit\Nowy folder 2015-02-15 11:39 - 2015-02-15 11:39 - 00012328 _____ () C:\Documents and Settings\DOM\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2015-02-15 11:39 - 2015-02-15 11:39 - 00000000 ____D () C:\Documents and Settings\DOM\Dane aplikacji\AVG2015 2015-02-15 11:38 - 2015-02-15 11:38 - 00000732 _____ () C:\Documents and Settings\All Users\Pulpit\AVG 2015.lnk 2015-02-15 11:38 - 2015-02-15 11:38 - 00000000 ____D () C:\Documents and Settings\DOM\Dane aplikacji\TuneUp Software 2015-02-15 11:38 - 2015-02-15 11:38 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\AVG 2015-02-15 11:36 - 2015-02-15 11:39 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\AVG2015 2015-02-15 11:36 - 2015-02-15 11:36 - 00000000 ___HD () C:\$AVG 2015-02-15 11:35 - 2015-02-15 11:35 - 00000000 ____D () C:\Program Files\AVG 2015-02-15 11:31 - 2015-02-15 11:47 - 00000000 ____D () C:\Documents and Settings\DOM\Ustawienia lokalne\Dane aplikacji\Avg2015 2015-02-15 11:30 - 2015-02-28 18:33 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\MFAData 2015-02-15 11:30 - 2015-02-15 11:30 - 00000000 ____D () C:\Documents and Settings\DOM\Ustawienia lokalne\Dane aplikacji\MFAData 2015-02-15 11:30 - 2015-02-15 11:30 - 00000000 ____D () C:\Documents and Settings\DOM\Ustawienia lokalne\Dane aplikacji\Avg2014 2015-02-05 18:31 - 2015-02-05 18:31 - 00000000 ____D () C:\Documents and Settings\LocalService\Dane aplikacji\McAfee 2015-01-31 15:15 - 2015-01-31 15:15 - 00090112 _____ () C:\WINDOWS\Minidump\Mini013115-01.dmp 2015-01-31 15:15 - 2015-01-31 15:15 - 00000000 ____D () C:\WINDOWS\Minidump 2015-01-31 15:05 - 2015-01-31 15:05 - 00701616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2015-01-31 15:05 - 2015-01-31 15:05 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2015-01-31 15:03 - 2015-01-31 15:05 - 00000000 ____D () C:\Documents and Settings\DOM\Ustawienia lokalne\Dane aplikacji\Adobe 2015-01-29 15:49 - 2015-01-29 15:51 - 00000000 ____D () C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-28 20:21 - 2015-01-10 13:52 - 00000000 ____D () C:\Documents and Settings\DOM\Ustawienia lokalne\Temp 2015-02-28 20:19 - 2015-01-10 13:52 - 00000000 __SHD () C:\Documents and Settings\DOM\Ustawienia lokalne\Historia 2015-02-28 20:18 - 2015-01-10 14:40 - 00182038 _____ () C:\WINDOWS\system32\nvapps.xml 2015-02-28 20:18 - 2015-01-10 13:27 - 00109127 _____ () C:\WINDOWS\WindowsUpdate.log 2015-02-28 20:17 - 2015-01-10 13:50 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-02-28 19:17 - 2015-01-10 13:52 - 00000188 ___SH () C:\Documents and Settings\DOM\ntuser.ini 2015-02-28 19:17 - 2015-01-10 13:50 - 00012396 _____ () C:\WINDOWS\SchedLgU.Txt 2015-02-28 18:54 - 2015-01-10 13:50 - 00000000 __SHD () C:\Documents and Settings\LocalService\Ustawienia lokalne\Historia 2015-02-28 18:50 - 2015-01-10 14:11 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji 2015-02-28 18:50 - 2015-01-10 14:11 - 00000000 ___SD () C:\Documents and Settings\Default User\Ustawienia lokalne\Historia 2015-02-28 18:50 - 2015-01-10 13:49 - 00000000 ___HD () C:\Documents and Settings\NetworkService\Ustawienia lokalne\Historia 2015-02-28 18:45 - 2015-01-10 13:52 - 00000000 ____D () C:\Documents and Settings\DOM\Pulpit 2015-02-28 18:43 - 2015-01-10 14:11 - 00280840 _____ () C:\WINDOWS\setupapi.log 2015-02-28 12:59 - 2008-04-15 13:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl 2015-02-15 11:39 - 2015-01-10 13:52 - 00000000 __RHD () C:\Documents and Settings\DOM\Dane aplikacji 2015-02-15 11:39 - 2015-01-10 13:52 - 00000000 ___HD () C:\Documents and Settings\DOM\Ustawienia lokalne\Dane aplikacji 2015-02-15 11:38 - 2015-01-10 14:11 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy 2015-02-15 11:38 - 2015-01-10 14:11 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2015-02-15 11:10 - 2015-01-10 14:37 - 00000000 ____D () C:\Documents and Settings\DOM\Ustawienia lokalne\Dane aplikacji\Google 2015-02-15 11:10 - 2015-01-10 14:36 - 00000000 ____D () C:\Program Files\Google 2015-02-15 11:10 - 2015-01-10 14:11 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy\Autostart 2015-01-29 16:02 - 2015-01-10 14:45 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service ==================== Files in the root of some directories ======= 2015-01-10 14:55 - 2015-01-13 18:54 - 0008192 _____ () C:\Documents and Settings\DOM\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================