Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015 Ran by Dell-2012 (administrator) on DELL on 06-04-2015 19:11:43 Running from C:\Documents and Settings\Dell-2012\Moje dokumenty Loaded Profiles: Dell-2012 (Available profiles: Dell-2012 & Administrator) Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 8 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\WLKEEPER.exe (Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe (Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe (Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe (ActMask Co.,Ltd - http://www.all2pdf.com) C:\WINDOWS\system32\PrintDisp.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe (Intel Corporation) C:\Program Files\Intel\AMT\LMS.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe (Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe () C:\Documents and Settings\All Users\Dane aplikacji\MobileBrServ\mbbService.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvservice.exe (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\WINDOWS\system32\PrintCtrl.exe (ActMask Co.,Ltd - http://www.all2pdf.com) C:\WINDOWS\system32\PrintDisp.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel Corporation) C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Watch Tower Bible and Tract Society of Pennsylvania.) E:\Watchtower Library 2014\P\WTLibrary.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [picon] => C:\Program Files\Common Files\Intel\Privacy Icon\PIconStartup.exe [111640 2010-08-05] () HKLM\...\Run: [NVHotkey] => rundll32.exe nvHotkey.dll,Start HKLM\...\Run: [PrintDisp] => C:\WINDOWS\system32\PrintDisp.exe [877568 2013-06-25] (ActMask Co.,Ltd - http://www.all2pdf.com) HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [200704 2008-08-18] (Alps Electric Co., Ltd.) HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC) HKLM\...\Run: [IntelZeroConfig] => C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe [1392640 2010-01-19] (Intel(R) Corporation) HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1206544 2010-01-19] (Intel(R) Corporation) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [1138780 2011-03-17] (IDT, Inc.) HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM\...\Run: [] => [X] HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2014-11-21] (Malwarebytes Corporation) HKLM\...\Winlogon: [Userinit] \WINDOWS\system32\userinit.exe, HKLM\...\Policies\Explorer\Run: [] => No File HKLM\...\Policies\Explorer: [NoCDBurning] 0 HKU\S-1-5-21-1957994488-1659004503-839522115-1003\...\Policies\Explorer: [NoDriveAutoRun] 0xFFFFFFFF HKU\S-1-5-21-1957994488-1659004503-839522115-1003\...\MountPoints2: {9b8a489d-bde0-11e4-b796-0024d687152e} - F:\Lenovo_Suite.exe HKU\S-1-5-21-1957994488-1659004503-839522115-1003\...\MountPoints2: {b8dc288e-3a66-11e4-b61e-806d6172696f} - F:\LG_PC_Programs.exe HKU\S-1-5-21-1957994488-1659004503-839522115-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [9216 2008-04-14] (Microsoft Corporation) HKU\S-1-5-18\...\Run: [DWQueuedReporting] => C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [437160 2007-02-26] (Microsoft Corporation) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\Documents and Settings\Dell-2012\Menu Start\Programy\Autostart\WinFlip.lnk ShortcutTarget: WinFlip.lnk -> C:\Documents and Settings\Dell-2012\Pulpit\RÓŻNE\Nowy folder\WinFlip.exe (No File) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1957994488-1659004503-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1957994488-1659004503-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-12-18] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-12-18] (Oracle Corporation) DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Tcpip\..\Interfaces\{7F2A30DD-A236-4606-BBE7-3C227F56BA5E}: [NameServer] 213.77.92.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Dell-2012\Dane aplikacji\Mozilla\Firefox\Profiles\3xiybotp.default FF NewTab: www.google.pl FF Homepage: www.jw.org FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-23] () FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1215155.dll [2014-12-02] (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2014-02-18] (DivX, LLC) FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-01-08] (Tracker Software Products (Canada) Ltd.) FF Plugin: @ganymede/CARDS,version=1.0 -> C:\Program Files\Ganymede\Plugins\CARDS\NPCARDS.dll [2011-04-21] (Ganymede Technologies) FF Plugin: @ganymede/MAKAOV2,version=1.0 -> C:\Program Files\Ganymede\Plugins\MAKAOV2\NPMAKAOV2.dll [2011-04-21] (Ganymede Technologies) FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-18] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-12-18] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-01-08] (Tracker Software Products (Canada) Ltd.) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPCARDS.dll [2011-04-21] (Ganymede Technologies) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPMAKAOV2.dll [2011-04-21] (Ganymede Technologies) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-01-08] (Tracker Software Products (Canada) Ltd.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-02-06] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-02-06] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-02-06] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-02-06] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-02-06] (Apple Inc.) FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Documents and Settings\Dell-2012\Dane aplikacji\Mozilla\Firefox\Profiles\3xiybotp.default\Extensions\artur.dubovoy@gmail.com [2015-02-16] FF Extension: WOT - C:\Documents and Settings\Dell-2012\Dane aplikacji\Mozilla\Firefox\Profiles\3xiybotp.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-02-12] FF Extension: DownloadHelper - C:\Documents and Settings\Dell-2012\Dane aplikacji\Mozilla\Firefox\Profiles\3xiybotp.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-07] FF Extension: Easy Google Translate - C:\Documents and Settings\Dell-2012\Dane aplikacji\Mozilla\Firefox\Profiles\3xiybotp.default\Extensions\easygtranslate@wrlf.com.br.xpi [2014-02-12] FF Extension: To Google Translate - C:\Documents and Settings\Dell-2012\Dane aplikacji\Mozilla\Firefox\Profiles\3xiybotp.default\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2014-02-12] FF Extension: Adblock Plus - C:\Documents and Settings\Dell-2012\Dane aplikacji\Mozilla\Firefox\Profiles\3xiybotp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-15] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-11-24] Chrome: ======= CHR HomePage: Profile 3 -> CHR Profile: C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3 CHR Extension: (Google Translate) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-02-17] CHR Extension: (Google Slides) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-16] CHR Extension: (Google Docs) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-16] CHR Extension: (Google Drive) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-16] CHR Extension: (Please enter your password) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2015-02-17] CHR Extension: (WOT) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2015-02-17] CHR Extension: (YouTube) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-16] CHR Extension: (TV) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\bppbpeijolfcampacpljolaegibfhjph [2015-02-17] CHR Extension: (Google Search) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-16] CHR Extension: (Video Downloader professional) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2015-02-17] CHR Extension: (Google Sheets) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-16] CHR Extension: (AdBlock) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-02-17] CHR Extension: (QuickTime for Chrome) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\glkdifongmamddfegpjkmghbmoikkjai [2015-02-17] CHR Extension: (Youtube-to-MP3) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\jekmfmemcfggilfpgplgjbfaijgchhfc [2015-02-17] CHR Extension: (Movie Downloader Professional) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\kmbapgnhedgedkgomjjdlkonfadkpole [2015-02-17] CHR Extension: (Auto HD For YouTube™) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2015-02-17] CHR Extension: (FVD Video Downloader) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp [2015-02-17] CHR Extension: (SPOI Options) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\medeknkggnkeffoahbphecmjoakbpiab [2015-02-17] CHR Extension: (Video download helper) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\mnkioblodjcgkdailhejgcocjkkoochj [2015-02-17] CHR Extension: (Google Wallet) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-16] CHR Extension: (Gmail) - C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-16] Opera: ======= OPR Extension: (Easy Youtube Video Downloader For Opera) - C:\Documents and Settings\Dell-2012\Dane aplikacji\Opera Software\Opera Stable\Extensions\acghaimmohdiildbgkbcjfmkdgglpofi [2013-11-26] OPR Extension: (YouTube MP3 Downloader) - C:\Documents and Settings\Dell-2012\Dane aplikacji\Opera Software\Opera Stable\Extensions\aolbifkplflbhkjpohkejjcoahldigfn [2015-01-05] OPR Extension: (Ultimate YouTube Downloader) - C:\Documents and Settings\Dell-2012\Dane aplikacji\Opera Software\Opera Stable\Extensions\bfkpkealncpcbfklpgnggcgjjdkbljop [2013-11-26] OPR Extension: (Speed Dial for Gmail) - C:\Documents and Settings\Dell-2012\Dane aplikacji\Opera Software\Opera Stable\Extensions\bpnilbmleimgkpdemlobfaaghhohpfco [2013-11-20] OPR Extension: (YouTube Center) - C:\Documents and Settings\Dell-2012\Dane aplikacji\Opera Software\Opera Stable\Extensions\cdcifocibecgcgigbanojipblimlaoij [2013-11-26] OPR Extension: (WOT) - C:\Documents and Settings\Dell-2012\Dane aplikacji\Opera Software\Opera Stable\Extensions\eeokceolphhfjdfcibaiiopmekmcbedp [2013-11-19] OPR Extension: (Tłumacz) - C:\Documents and Settings\Dell-2012\Dane aplikacji\Opera Software\Opera Stable\Extensions\ibnombjmjocaccigcefonnipcnlaeaed [2013-11-19] OPR Extension: (YouTube Downloader) - C:\Documents and Settings\Dell-2012\Dane aplikacji\Opera Software\Opera Stable\Extensions\kclijeogghhkmenkommbnjobhnndpfba [2013-11-19] OPR Extension: (Download YouTube Videos as MP4) - C:\Documents and Settings\Dell-2012\Dane aplikacji\Opera Software\Opera Stable\Extensions\maeombkgfpjdnjkhohbjachnnmpbipol [2013-11-26] OPR Extension: (Adblock Plus) - C:\Documents and Settings\Dell-2012\Dane aplikacji\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2014-01-20] OPR Extension: (FastestTube - YouTube Video Downloader) - C:\Documents and Settings\Dell-2012\Dane aplikacji\Opera Software\Opera Stable\Extensions\phahnhbgfdhgobenebnjbgmacgpbfaag [2014-04-16] StartMenuInternet: (HKLM) OperaMail - C:\Program Files\Opera Mail\OperaMail.exe StartMenuInternet: (HKU\S-1-5-21-1957994488-1659004503-839522115-1003) Opera - "C:\Program Files\Opera\Opera.exe" ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Credential Vault Host Control Service; C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [812448 2010-03-24] (Broadcom Corporation) R2 Credential Vault Host Storage; C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [27040 2010-03-24] (Broadcom Corporation) S3 FirebirdServerMAGIXInstance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed] S3 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-12-18] (Oracle Corporation) S2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 Mobile Broadband HL Service; C:\Documents and Settings\All Users\Dane aplikacji\MobileBrServ\mbbservice.exe [232288 2012-03-12] () R2 nvservice; C:\WINDOWS\system32\nvservice.exe [160544 2013-01-25] (NVIDIA Corporation) R2 Printer Control; C:\WINDOWS\system32\PrintCtrl.exe [102400 2012-10-21] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) [File not signed] R2 S24EventMonitor; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [954368 2010-01-19] (Intel(R) Corporation) [File not signed] R2 UNS; C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2062872 2010-08-05] (Intel Corporation) R2 WLANKEEPER; C:\Program Files\Intel\WiFi\bin\WLKeeper.exe [364544 2010-01-19] (Intel(R) Corporation) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 AESTAud; C:\WINDOWS\System32\drivers\AESTAud.sys [108160 2008-05-20] (Andrea Electronics Corporation) S3 AndNetDiag; C:\WINDOWS\System32\DRIVERS\lgandnetdiag.sys [23680 2014-10-09] (LG Electronics Inc.) S3 ANDNetModem; C:\WINDOWS\System32\DRIVERS\lgandnetmodem.sys [28416 2014-10-09] (LG Electronics Inc.) S3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [534440 2008-05-21] (Broadcom Corporation.) R3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [37160 2008-02-04] (Broadcom Corporation.) R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [991016 2008-08-07] (Broadcom Corporation.) S3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [156392 2007-09-20] (Broadcom Corporation.) S3 btwmodem; C:\WINDOWS\System32\DRIVERS\btwmodem.sys [37032 2008-02-04] (Broadcom Corporation.) S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [47272 2008-08-03] (Broadcom Corporation.) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation) R3 cvusbdrv; C:\WINDOWS\System32\Drivers\cvusbdrv.sys [33832 2009-11-03] (Broadcom Corporation) R3 e1yexpress; C:\WINDOWS\System32\DRIVERS\e1y5132.sys [240344 2009-08-04] (Intel Corporation) R3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [210688 2008-06-25] (Conexant Systems, Inc.) R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [985728 2008-06-25] (Conexant Systems, Inc.) R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO32.SYS [23840 2015-02-14] (REALiX(tm)) U0 lnlx; C:\WINDOWS\System32\drivers\hxgd.sys [52440 2015-04-06] (Malwarebytes Corporation) R1 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [54360 2014-11-21] (Malwarebytes Corporation) S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation) R3 NETw5x32; C:\WINDOWS\System32\DRIVERS\NETw5x32.sys [6598656 2010-01-13] (Intel Corporation) R0 PBADRV; C:\WINDOWS\System32\DRIVERS\PBADRV.sys [26608 2008-06-04] (Dell Inc) R2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [13952 2009-08-10] (Intel Corporation) S3 SRS_PremiumSound_Service; C:\WINDOWS\System32\drivers\srs_PremiumSound_i386.sys [232744 2009-03-24] () R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1381914 2008-05-22] (IDT, Inc.) R1 Tcpip; C:\WINDOWS\System32\DRIVERS\tcpip.sys [361600 2008-06-20] (Microsoft Corporation) [File not signed] S3 andnetndis; system32\DRIVERS\lgandnetndis.sys [X] U2 CertPropSvc; No ImagePath S3 cnnctfy2MP; system32\DRIVERS\cnnctfy2.sys [X] S4 IntelIde; No ImagePath S3 NETwNx32; system32\DRIVERS\NETwNx32.sys [X] U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation) U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation) U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () [File not signed] U4 vsserv; No ImagePath U1 WS2IFSL; No ImagePath U3 pxtdapod; \??\C:\DOCUME~1\DELL-2~1\USTAWI~1\Temp\pxtdapod.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-06 19:11 - 2015-04-06 19:12 - 00024693 _____ () C:\Documents and Settings\Dell-2012\Moje dokumenty\FRST.txt 2015-04-06 19:10 - 2015-04-06 19:11 - 00000000 ____D () C:\FRST 2015-04-06 19:09 - 2015-04-06 19:09 - 01135104 _____ (Farbar) C:\Documents and Settings\Dell-2012\Moje dokumenty\FRST.exe 2015-04-06 18:46 - 2015-04-06 18:46 - 00380416 _____ () C:\Documents and Settings\Dell-2012\Moje dokumenty\ppzytt39.exe 2015-04-06 18:30 - 2015-04-06 18:30 - 00091902 _____ () C:\Documents and Settings\Dell-2012\Pulpit\OTL.Txt 2015-04-06 18:30 - 2015-04-06 18:30 - 00038232 _____ () C:\Documents and Settings\Dell-2012\Pulpit\Extras.Txt 2015-04-06 18:25 - 2015-04-06 18:30 - 00038232 _____ () C:\Documents and Settings\Dell-2012\Moje dokumenty\Extras.Txt 2015-04-06 18:25 - 2015-04-06 18:25 - 00091902 _____ () C:\Documents and Settings\Dell-2012\Moje dokumenty\OTL.Txt 2015-04-06 18:15 - 2015-04-06 18:15 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Dell-2012\Moje dokumenty\OTL.exe 2015-04-06 18:11 - 2015-04-06 18:11 - 00052440 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\hxgd.sys 2015-04-06 17:12 - 2015-04-06 17:12 - 02208768 _____ () C:\Documents and Settings\Dell-2012\Moje dokumenty\adwcleaner_4.200.exe 2015-04-05 14:21 - 2015-04-05 15:45 - 00000000 ____D () C:\Program Files\WZebra 2015-04-05 14:21 - 2015-04-05 14:21 - 05022099 _____ (Gunnar Andersson & Lars Ivansson ) C:\Documents and Settings\Dell-2012\Moje dokumenty\wz424.exe 2015-04-05 14:21 - 2015-04-05 14:21 - 00000606 _____ () C:\Documents and Settings\Dell-2012\Pulpit\WZebra.lnk 2015-04-05 14:21 - 2015-04-05 14:21 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\WZebra 2015-04-04 19:26 - 2015-04-05 10:47 - 00000691 _____ () C:\Documents and Settings\Dell-2012\Pulpit\FILMY DO POBRANIAAAAAA.txt 2015-04-02 22:31 - 2015-04-02 22:36 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Pulpit\Ośrodek Budzisław 2015 2015-04-01 17:59 - 2015-04-01 17:59 - 00023352 _____ () C:\Documents and Settings\Dell-2012\Pulpit\plan obsługi.odt 2015-03-31 16:42 - 2015-03-31 16:42 - 00000044 _____ () C:\Documents and Settings\Dell-2012\Pulpit\parki.txt 2015-03-26 23:19 - 2015-03-26 23:20 - 35407257 _____ () C:\Documents and Settings\Dell-2012\Pulpit\PARANIENORMALNI TONIGHT- Komornik Janusz Zabieraj.mp4 2015-03-23 21:20 - 2015-03-28 17:15 - 00001223 _____ () C:\Documents and Settings\Dell-2012\Pulpit\Muzyka.lnk 2015-03-18 21:31 - 2015-03-18 21:32 - 28509232 _____ () C:\Documents and Settings\Dell-2012\Moje dokumenty\vlc-2.2.0-win32.exe 2015-03-10 23:25 - 2015-03-10 23:25 - 00000000 ____D () C:\Program Files\Youtube Downloader HD 2015-03-10 23:25 - 2015-03-10 23:25 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Youtube Downloader HD 2015-03-07 20:55 - 2015-03-07 20:55 - 00000586 _____ () C:\Documents and Settings\Dell-2012\Pulpit\Watchtower Library 2014 - wydanie polskie.lnk 2015-03-07 20:55 - 2015-03-07 20:55 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Watchtower Library 2014 ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-06 19:12 - 2012-01-20 12:01 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Temp 2015-04-06 19:11 - 2012-01-20 12:01 - 00000000 ___SD () C:\Documents and Settings\Dell-2012\Moje dokumenty 2015-04-06 19:08 - 2012-01-20 12:01 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Pulpit 2015-04-06 19:07 - 2014-06-03 19:08 - 00000426 _____ () C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1393096411.job 2015-04-06 19:02 - 2014-07-23 18:21 - 00001036 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-04-06 18:21 - 2014-07-04 18:55 - 00000930 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-04-06 18:21 - 2012-01-20 12:50 - 00000211 _____ () C:\WINDOWS\wiadebug.log 2015-04-06 18:11 - 2015-02-16 20:05 - 00000000 __HDC () C:\WINDOWS\$NtUninstallwinusb0200$ 2015-04-06 17:59 - 2014-11-09 22:20 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-04-06 17:57 - 2012-01-20 12:48 - 01257736 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-04-06 17:57 - 2004-08-04 14:00 - 00556616 _____ () C:\WINDOWS\system32\perfh015.dat 2015-04-06 17:57 - 2004-08-04 14:00 - 00105608 _____ () C:\WINDOWS\system32\perfc015.dat 2015-04-06 17:56 - 2014-01-29 16:43 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Dane aplikacji\AIMP3 2015-04-06 17:56 - 2012-01-20 12:01 - 00000000 ____D () C:\Documents and Settings\Dell-2012 2015-04-06 17:55 - 2014-09-15 14:28 - 00000000 ____D () C:\AdwCleaner 2015-04-06 17:55 - 2013-11-26 20:29 - 00000000 ____D () C:\WINDOWS\Minidump 2015-04-06 17:53 - 2014-07-23 18:21 - 00001032 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-04-06 17:53 - 2014-03-31 12:02 - 00000230 _____ () C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job 2015-04-06 17:53 - 2014-02-10 02:09 - 00000484 _____ () C:\WINDOWS\Tasks\CIS_{15198508-521A-4D69-8E5B-B94A6CCFF805}.job 2015-04-06 17:53 - 2012-01-20 12:50 - 00000050 ____N () C:\WINDOWS\wiaservc.log 2015-04-06 17:53 - 2012-01-20 11:59 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-04-06 17:53 - 2004-08-04 14:00 - 00001374 _____ () C:\WINDOWS\system32\wpa.dbl 2015-04-06 17:52 - 2012-01-20 12:01 - 00000188 ___SH () C:\Documents and Settings\Dell-2012\ntuser.ini 2015-04-06 17:52 - 2012-01-20 12:01 - 00000000 ___HD () C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji 2015-04-06 17:52 - 2012-01-20 11:59 - 00032278 ____N () C:\WINDOWS\SchedLgU.Txt 2015-04-06 17:52 - 2012-01-20 11:56 - 01815241 ____N () C:\WINDOWS\WindowsUpdate.log 2015-04-06 15:17 - 2013-09-15 22:21 - 00144384 _____ () C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-04-06 13:14 - 2014-05-08 21:12 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\ipla 2015-04-06 11:57 - 2013-11-25 16:15 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Dane aplikacji\ipla 2015-04-05 14:21 - 2012-01-20 12:48 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy 2015-04-02 11:53 - 2013-12-29 20:28 - 00000000 ____D () C:\PLIKI 2015-03-30 17:31 - 2015-02-20 14:17 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Pulpit\31.05 wykład 2015-03-28 17:25 - 2015-01-06 16:12 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Pulpit\Nieużywane skróty pulpitu 2015-03-28 17:16 - 2014-02-17 16:18 - 00000000 ____D () C:\Muzyka 2015-03-28 17:15 - 2012-01-20 12:48 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2015-03-28 17:13 - 2015-01-03 22:28 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Pulpit\OŚRODEK JUNNO 2014 2015-03-28 16:39 - 2015-02-16 11:08 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Pulpit\Grafik wózek 2015-03-28 16:10 - 2014-11-05 13:13 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Pulpit\Wcześniejsze wykłady 2015-03-27 20:39 - 2014-01-29 17:07 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Dane aplikacji\vlc 2015-03-27 20:07 - 2014-02-22 21:13 - 00000000 ____D () C:\Program Files\Opera 2015-03-23 21:15 - 2014-11-09 22:14 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\Adobe 2015-03-23 20:41 - 2014-07-04 18:55 - 00778928 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2015-03-23 20:41 - 2014-07-04 18:55 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2015-03-11 20:37 - 2004-08-04 14:00 - 00000880 _____ () C:\WINDOWS\win.ini 2015-03-11 16:28 - 2014-05-28 20:22 - 00000000 ____D () C:\Documents and Settings\Dell-2012\Dane aplikacji\Youtube Downloader HD 2015-03-11 09:27 - 2014-01-29 17:13 - 00000000 ____D () C:\WINDOWS\system32\MRT 2015-03-11 09:22 - 2013-11-23 14:56 - 119837696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe ==================== Files in the root of some directories ======= 2013-11-11 11:32 - 2013-11-11 12:32 - 0000737 _____ () C:\Documents and Settings\Dell-2012\Dane aplikacji\AutoGK.ini 2013-09-14 18:29 - 2013-09-24 21:25 - 0000000 _____ () C:\Documents and Settings\Dell-2012\Dane aplikacji\AVSDVDPlayer.m3u 2013-11-20 17:13 - 2013-11-20 17:13 - 0000096 _____ () C:\Documents and Settings\Dell-2012\Dane aplikacji\WB.CFG 2013-11-20 17:13 - 2013-11-20 17:13 - 0000006 _____ () C:\Documents and Settings\Dell-2012\Dane aplikacji\WBPU-TTL.DAT 2013-09-15 22:21 - 2015-04-06 15:17 - 0144384 _____ () C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-08-17 14:52 - 2014-08-17 14:52 - 0001639 _____ () C:\Documents and Settings\Dell-2012\Ustawienia lokalne\Dane aplikacji\recently-used.xbel ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================