Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:11-07-2014
- Ran by SYSTEM on MININT-J6TH0OM on 11-07-2014 10:19:49
- Running from h:\
- Platform: Windows 7 Ultimate (X86) OS Language: Polski (Polska)
- Internet Explorer Version 8
- Boot Mode: Recovery
- The current controlset is ControlSet003
- [b]ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.[/b]
- The only official download link for FRST:
- Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
- Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
- Download link from any site other than Bleeping Computer is unpermitted or outdated.
- See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Registry (Whitelisted) ==================
- HKLM\...\Run: [QlbCtrl.exe] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [202032 2007-10-19] ( Hewlett-Packard Development Company, L.P.)
- HKLM\...\Run: [Conime] => %windir%\system32\conime.exe
- HKLM\...\Run: [ADAiO2StatusMonitor] => C:\Windows\system32\spool\DRIVERS\W32X86\3\ADAiO2MUI.exe [2362880 2010-10-18] (DSGi)
- HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
- HKLM\...\Run: [64upw3264] => C:\Program Files\64upw3264\_rudo64w32.exe [119414 2013-12-08] (mpolkiujhy)
- HKLM\...\Policies\Explorer\Run: [WindowsUpdate] => C:\Users\Ania\AppData\Roaming\Microsoft\Windows\svchost.exe [143360 2013-12-08] ( (Texas Instruments Incorporated))
- HKLM\...\Policies\Explorer\Run: [12290] => c:\ProgramData\msvcwdae.exe [88706 2009-07-14] ( (jukihygtfe))
- HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
- HKLM\...\Policies\Explorer: [HideSCAHealth] 1
- HKU\Ania\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
- HKU\Ania\...\Run: [BearShare] => C:\Program Files\BearShare Applications\BearShare\BearShare.exe [31159360 2013-11-03] (MusicLab, LLC)
- HKU\Ania\...\Run: [Google Search] => C:\Users\Ania\AppData\Roaming\nIwRH\ltc.exe [19456 2013-12-08] (COMODO)
- HKU\Ania\...\Run: [OpenMin] => C:\Users\Ania\AppData\Local\OpenMin\wincheck.vbs [197 2013-12-08] ()
- HKU\Ania\...\Policies\Explorer: [TaskbarNoNotification] 1
- HKU\Ania\...\Policies\Explorer: [HideSCAHealth] 1
- IFEO\bitguard.exe: [Debugger] tasklist.exe
- IFEO\bprotect.exe: [Debugger] tasklist.exe
- IFEO\browserdefender.exe: [Debugger] tasklist.exe
- IFEO\browserprotect.exe: [Debugger] tasklist.exe
- IFEO\rstrui.exe: [Debugger] mwva_.exe
- Startup: C:\Users\Ania\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\frlfbnqmqw.lnk
- ShortcutTarget: frlfbnqmqw.lnk -> C:\ProgramData\wqmqnbflrf.jss (Microsoft Corporation)
- HKLM\...\AppCertDlls: [x64] -> c:\program files\music toolbar\datamngr\x64\apcrtldr.dll <===== ATTENTION
- ========================== Services (Whitelisted) =================
- S2 Advent AIO Network Discovery Service; C:\Program Files\Advent\AIO\Center\ADAIOHostService.exe [361904 2010-09-30] (DSGi)
- S2 AlotService; C:\Users\Ania\AppData\Roaming\alotservice\alotservice.exe [256328 2013-04-23] (Inuvo Inc.)
- S3 Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [110592 2007-03-05] (Hewlett-Packard Development Company, L.P.)
- S2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.)
- S2 syshost32; C:\Windows\Installer\{EA41CDFE-625A-626D-689F-0A1748471D03}\syshost.exe [72192 2013-12-08] ()
- S3 Winmgmt; C:\ProgramData\wqmqnbflrf.jss [207360 2013-12-07] (Microsoft Corporation)
- ==================== Drivers (Whitelisted) ====================
- S3 HpqRemHid; C:\Windows\System32\DRIVERS\HpqRemHid.sys [7168 2007-07-11] (Hewlett-Packard Development Company, L.P.)
- S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [47744 2006-07-06] ()
- S3 ST50220; C:\Windows\System32\Drivers\ST50220.sys [26752 2006-11-24] (Sonix)
- S1 eabfiltr;
- ==================== NetSvcs (Whitelisted) ===================
- ==================== One Month Created Files and Folders ========
- 2014-07-11 10:19 - 2014-07-11 10:19 - 00000000 ____D () C:\FRST
- 2014-07-10 20:49 - 2014-07-10 20:49 - 00000000 ____D () C:\ProgramData\2B22E
- ==================== One Month Modified Files and Folders =======
- 2014-07-11 10:19 - 2014-07-11 10:19 - 00000000 ____D () C:\FRST
- 2014-07-11 09:14 - 2013-09-18 18:48 - 21052282 _____ () C:\alotserviceruntime.log
- 2014-07-11 09:12 - 2013-12-07 18:31 - 95025368 ____T () C:\ProgramData\frlfbnqmqw.fee
- 2014-07-11 09:12 - 2013-12-07 18:31 - 00000000 _____ () C:\ProgramData\frlfbnqmqw.odd
- 2014-07-11 09:12 - 2013-07-25 20:48 - 00000000 ____D () C:\ProgramData\Advent
- 2014-07-11 09:12 - 2009-07-14 05:39 - 00065913 _____ () C:\Windows\setupact.log
- 2014-07-10 21:43 - 2009-07-14 05:34 - 00010016 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- 2014-07-10 21:43 - 2009-07-14 05:34 - 00010016 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- 2014-07-10 20:49 - 2014-07-10 20:49 - 00000000 ____D () C:\ProgramData\2B22E
- 2014-07-10 20:49 - 2012-05-25 22:22 - 00000000 ____D () C:\Users\Ania\AppData\Roaming\Skype
- Files to move or delete:
- ====================
- C:\ProgramData\frlfbnqmqw.fee
- C:\ProgramData\frlfbnqmqw.odd
- C:\ProgramData\frlfbnqmqw.reg
- C:\ProgramData\msvcwdae.exe
- C:\ProgramData\wqmqnbflrf.jss
- Some content of TEMP:
- ====================
- C:\Users\Ania\AppData\Local\Temp\AutoRun.exe
- C:\Users\Ania\AppData\Local\Temp\AutoRunGUI.dll
- C:\Users\Ania\AppData\Local\Temp\BackupSetup.exe
- C:\Users\Ania\AppData\Local\Temp\BundleSweetIMSetup.exe
- C:\Users\Ania\AppData\Local\Temp\csw.exe
- C:\Users\Ania\AppData\Local\Temp\Delta.exe
- C:\Users\Ania\AppData\Local\Temp\DeltaTB.exe
- C:\Users\Ania\AppData\Local\Temp\download-aresregular219_installer.exe
- C:\Users\Ania\AppData\Local\Temp\DrvInst32.exe
- C:\Users\Ania\AppData\Local\Temp\DrvInst64.exe
- C:\Users\Ania\AppData\Local\Temp\eauninstall.exe
- C:\Users\Ania\AppData\Local\Temp\hssinst.dll
- C:\Users\Ania\AppData\Local\Temp\MybabylonTB.exe
- C:\Users\Ania\AppData\Local\Temp\Need for Speed Most Wanted_uninst.exe
- C:\Users\Ania\AppData\Local\Temp\nsaEE05.exe
- C:\Users\Ania\AppData\Local\Temp\nsk92CB.exe
- C:\Users\Ania\AppData\Local\Temp\nskFC98.exe
- C:\Users\Ania\AppData\Local\Temp\nss18EF.exe
- C:\Users\Ania\AppData\Local\Temp\nst33A0.exe
- C:\Users\Ania\AppData\Local\Temp\nsvBAA9.exe
- C:\Users\Ania\AppData\Local\Temp\nsy3568.exe
- C:\Users\Ania\AppData\Local\Temp\propsys.dll
- C:\Users\Ania\AppData\Local\Temp\SkypeSetup.exe
- C:\Users\Ania\AppData\Local\Temp\SPStub.exe
- C:\Users\Ania\AppData\Local\Temp\st50220.dll
- C:\Users\Ania\AppData\Local\Temp\tbappm.dll
- C:\Users\Ania\AppData\Local\Temp\tbedrs.dll
- C:\Users\Ania\AppData\Local\Temp\tbWis2.dll
- C:\Users\Ania\AppData\Local\Temp\TB_7924.exe
- C:\Users\Ania\AppData\Local\Temp\vcredist_x86.exe
- C:\Users\Ania\AppData\Local\Temp\WOWInst.exe
- C:\Users\Ania\AppData\Local\Temp\WSSetup.exe
- ==================== Known DLLs (Whitelisted) ============
- ==================== Bamital & volsnap Check =================
- C:\Windows\explorer.exe => MD5 is legit
- C:\Windows\System32\winlogon.exe => MD5 is legit
- C:\Windows\System32\wininit.exe => MD5 is legit
- C:\Windows\System32\svchost.exe => MD5 is legit
- C:\Windows\System32\services.exe => MD5 is legit
- C:\Windows\System32\User32.dll => MD5 is legit
- C:\Windows\System32\userinit.exe => MD5 is legit
- C:\Windows\System32\rpcss.dll => MD5 is legit
- C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
- ==================== Restore Points =========================
- ==================== Memory info ===========================
- Percentage of memory in use: 20%
- Total physical RAM: 2046.43 MB
- Available physical RAM: 1632.39 MB
- Total Pagefile: 2046.43 MB
- Available Pagefile: 1635.76 MB
- Total Virtual: 2047.88 MB
- Available Virtual: 1943.74 MB
- ==================== Drives ================================
- Drive c: (WINDOWS 7 ULTIMATE) (Fixed) (Total:49.71 GB) (Free:21.75 GB) NTFS
- Drive d: (MULTIMEDIA) (Fixed) (Total:87.72 GB) (Free:70.08 GB) NTFS
- Drive f: (HP_RECOVERY) (Fixed) (Total:11.52 GB) (Free:2.18 GB) NTFS ==>[System with boot components (obtained from reading drive)]
- Drive h: (HITMANPRO) (Removable) (Total:7.45 GB) (Free:7.44 GB) FAT32
- Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
- Drive y: (Zastrzeżone przez system) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
- ==================== MBR & Partition Table ==================
- ========================================================
- Disk: 0 (Size: 149 GB) (Disk ID: 3DE1879C)
- Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
- Partition 2: (Not Active) - (Size=50 GB) - (Type=07 NTFS)
- Partition 3: (Not Active) - (Size=88 GB) - (Type=OF Extended)
- Partition 4: (Not Active) - (Size=12 GB) - (Type=07 NTFS)
- ========================================================
- Disk: 1 (Size: 7 GB) (Disk ID: 2FD51CB6)
- Partition 1: (Active) - (Size=7 GB) - (Type=0B)
- LastRegBack: 2013-12-06 22:20
- ==================== End Of Log ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement