Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-09-2013 Ran by Pc (administrator) on A-96B92B01A7D94 on 09-09-2013 12:23:52 Running from C:\Documents and Settings\Pc\Pulpit Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Ralink Technology, Corp.) C:\Program Files\Tenda\Common\RaRegistry.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Cmaudio] - RunDll32 cmicnfg.cpl,CMICtrlWnd HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-29] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - &Tłumaczenie - {2F7DB8D7-9BE7-4666-901E-F380555BCAC7} - C:\Program Files\Russkij Translator\InternetTranslatorRusPol.dll (Techland) Toolbar: HKCU -&Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU -&Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Documents and Settings\Pc\Dane aplikacji\Mozilla\Firefox\Profiles\7hceoxe6.default FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: No Name - C:\Documents and Settings\Pc\Dane aplikacji\Mozilla\Firefox\Profiles\7hceoxe6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKCU\...\Firefox\Extensions: [mozilla_cc@internetdownloadmanager.com] C:\Documents and Settings\Pc\Dane aplikacji\IDM\idmmzcc3 FF Extension: IDM CC - C:\Documents and Settings\Pc\Dane aplikacji\IDM\idmmzcc3 FF HKCU\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] C:\Documents and Settings\Pc\Dane aplikacji\IDM\idmmzcc3 FF Extension: IDM CC - C:\Documents and Settings\Pc\Dane aplikacji\IDM\idmmzcc3 ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-08-29] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-29] (Avira Operations GmbH & Co. KG) S4 Hamachi2Svc; C:\Program Files\Hamachi\hamachi-2.exe [1435984 2013-05-15] (LogMeIn Inc.) R2 RalinkRegistryWriter; C:\Program Files\Tenda\Common\RaRegistry.exe [193888 2010-06-28] (Ralink Technology, Corp.) S4 ZuneBusEnum; c:\Program Files\Zune\ZuneBusEnum.exe [57056 2011-08-05] (Microsoft Corporation) R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-04] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-08-29] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-31] (Avira Operations GmbH & Co. KG) R3 cmuda; C:\Windows\System32\drivers\cmuda.sys [754560 2003-10-17] (C-Media Inc) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-03-08] (DT Soft Ltd) S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [27165 2001-08-17] (VIA Technologies, Inc. ) S3 FETNDISB; C:\Windows\System32\DRIVERS\fetnd5b.sys [41984 2003-11-11] (VIA Technologies, Inc. ) R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) S3 IDMTDI; C:\Windows\System32\DRIVERS\idmtdi.sys [97112 2011-01-25] (Tonec Inc.) S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\mbamswissarmy.sys [40776 2013-08-14] (Malwarebytes Corporation) S3 NTSIM; C:\WINDOWS\system32\ntsim.sys [7040 2003-07-17] (VIA Networking Technologies, Inc. ) R3 RT80x86; C:\Windows\System32\DRIVERS\RT2860.sys [1663456 2010-10-18] (Ralink Technology, Corp.) R2 Scutum50; C:\Windows\System32\Drivers\Scutum50.sys [19072 2009-04-21] (Printing Communications Assoc., Inc. (PCAUSA)) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [98432 2013-01-31] (MCCI) S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14848 2013-01-31] (MCCI Corporation) S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [123648 2013-01-31] (MCCI Corporation) S3 ss_bserd; C:\Windows\System32\DRIVERS\ss_bserd.sys [100224 2013-01-31] (MCCI Corporation) R1 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [5632 2006-07-24] () R0 viaagp1; C:\Windows\System32\DRIVERS\viaagp1.sys [26880 2002-12-27] (VIA Technologies, Inc.) R2 zumbus; C:\Windows\System32\DRIVERS\zumbus.sys [41472 2011-08-05] (Microsoft Corporation) S4 IntelIde; No ImagePath U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2006-09-07] () U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-09 12:23 - 2013-09-09 12:23 - 00000000 ____D C:\FRST 2013-09-09 12:22 - 2013-09-09 12:22 - 01082207 _____ (Farbar) C:\Documents and Settings\Pc\Pulpit\FRST.exe 2013-09-09 12:19 - 2013-09-09 12:19 - 96601965 _____ C:\WINDOWS\system32\ꫀƌ 2013-09-08 19:13 - 2013-09-08 19:13 - 00000000 ____D C:\Documents and Settings\Pc\Pulpit\Służewiec 2013-09-07 16:41 - 2013-09-07 16:41 - 00056770 _____ C:\Documents and Settings\Pc\Pulpit\OTL.Txt 2013-09-07 16:41 - 2013-09-07 16:41 - 00039486 _____ C:\Documents and Settings\Pc\Pulpit\Extras.Txt 2013-09-07 16:23 - 2013-09-07 16:23 - 00000466 _____ C:\Documents and Settings\Pc\Pulpit\defogger_disable.log 2013-09-07 16:23 - 2013-09-07 16:23 - 00000000 _____ C:\Documents and Settings\Pc\defogger_reenable 2013-09-07 16:22 - 2013-09-07 16:22 - 00016858 _____ C:\Documents and Settings\Pc\Pulpit\AVSCAN-20130907-160814-C4FC295A.LOG 2013-09-07 16:18 - 2013-09-07 16:18 - 00050477 _____ C:\Documents and Settings\Pc\Pulpit\Defogger.exe 2013-09-07 16:08 - 2013-09-07 16:09 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Pc\Pulpit\OTL.exe 2013-09-06 16:08 - 2013-09-07 23:07 - 00010987 _____ C:\WINDOWS\setupapi.log 2013-09-06 14:29 - 2013-09-06 14:29 - 00984735 _____ (Macromedia, Inc.) C:\WINDOWS\Speedo Clock.exe 2013-09-06 14:29 - 2013-09-06 14:29 - 00259184 _____ (MacSourcery) C:\WINDOWS\Speedo Clock.scr 2013-09-06 14:29 - 2013-09-06 14:29 - 00029696 _____ (MacSourcery) C:\WINDOWS\mickey32.dll 2013-09-05 21:45 - 2013-09-05 21:45 - 96185213 _____ C:\WINDOWS\system32\뿙ƌ 2013-09-04 17:32 - 2013-09-04 17:32 - 95863165 _____ C:\WINDOWS\system32\皻墽ƌ 2013-09-04 12:46 - 2013-09-04 12:46 - 00000696 _____ C:\Documents and Settings\Pc\Pulpit\Skrót do open-fm.lnk 2013-09-04 12:46 - 2013-09-04 12:46 - 00000000 ____D C:\Documents and Settings\Pc\Dane aplikacji\OpenFM 2013-09-02 18:25 - 2013-09-02 18:25 - 95286781 _____ C:\WINDOWS\system32\悆ꢬƌ 2013-09-01 18:38 - 2013-09-01 18:38 - 95199041 _____ C:\WINDOWS\system32\潣ƌ 2013-08-31 23:32 - 2013-08-31 23:32 - 00026661 _____ C:\Documents and Settings\Pc\.recently-used.xbel 2013-08-29 01:17 - 2013-08-29 01:17 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$ 2013-08-24 22:13 - 1998-11-03 14:31 - 00061440 _____ (Immersion Corporation) C:\WINDOWS\system32\IFORCE2.dll 2013-08-24 22:12 - 2013-08-24 22:13 - 00000216 _____ C:\WINDOWS\PowerReg.dat 2013-08-24 22:09 - 2013-08-24 22:34 - 00000000 ____D C:\Program Files\MechWarrior 3 2013-08-22 10:10 - 2013-09-08 23:49 - 00000000 ____D C:\Documents and Settings\Pc\Pulpit\jpgs 2013-08-17 17:56 - 2013-08-17 17:57 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-14 20:48 - 2013-08-14 20:52 - 00000000 ____D C:\WINDOWS\system32\MRT 2013-08-14 20:38 - 2013-08-14 20:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$ 2013-08-14 20:38 - 2013-08-14 20:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$ 2013-08-14 20:38 - 2013-08-14 20:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$ 2013-08-14 20:37 - 2013-08-14 20:37 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$ 2013-08-12 21:53 - 2013-09-02 00:01 - 00000000 ____D C:\Documents and Settings\Pc\Pulpit\Psychiatryk ==================== One Month Modified Files and Folders ======= 2013-09-09 12:23 - 2013-09-09 12:23 - 00000000 ____D C:\FRST 2013-09-09 12:22 - 2013-09-09 12:22 - 01082207 _____ (Farbar) C:\Documents and Settings\Pc\Pulpit\FRST.exe 2013-09-09 12:22 - 2013-04-10 12:29 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-09-09 12:22 - 2004-07-19 03:16 - 00000000 ____D C:\Documents and Settings\Pc\Pulpit 2013-09-09 12:22 - 2004-07-19 02:28 - 01703729 _____ C:\WINDOWS\WindowsUpdate.log 2013-09-09 12:19 - 2013-09-09 12:19 - 96601965 _____ C:\WINDOWS\system32\ꫀƌ 2013-09-09 12:17 - 2013-03-11 19:02 - 00000260 _____ C:\WINDOWS\Tasks\WGASetup.job 2013-09-09 12:16 - 2004-07-19 03:15 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-09-09 12:16 - 2001-07-21 23:17 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl 2013-09-08 23:52 - 2004-07-19 03:16 - 00000188 ___SH C:\Documents and Settings\Pc\ntuser.ini 2013-09-08 23:52 - 2004-07-19 03:16 - 00000000 ____D C:\Documents and Settings\Pc 2013-09-08 23:52 - 2004-07-19 03:15 - 00032520 _____ C:\WINDOWS\SchedLgU.Txt 2013-09-08 23:49 - 2013-08-22 10:10 - 00000000 ____D C:\Documents and Settings\Pc\Pulpit\jpgs 2013-09-08 20:22 - 2013-03-08 00:26 - 00001658 _____ C:\WINDOWS\VPlayer.INI 2013-09-08 20:22 - 2013-03-08 00:26 - 00000073 _____ C:\WINDOWS\VplayerINI.vpl 2013-09-08 20:04 - 2004-07-19 03:16 - 00000000 ___RD C:\Documents and Settings\Pc\Moje dokumenty 2013-09-08 19:19 - 2013-04-22 20:28 - 00000000 ____D C:\Documents and Settings\Pc\Pulpit\Docs 2013-09-08 19:13 - 2013-09-08 19:13 - 00000000 ____D C:\Documents and Settings\Pc\Pulpit\Służewiec 2013-09-08 18:56 - 2013-03-15 18:05 - 00000000 ____D C:\Documents and Settings\Pc\Pulpit\Games 2013-09-07 23:07 - 2013-09-06 16:08 - 00010987 _____ C:\WINDOWS\setupapi.log 2013-09-07 20:37 - 2004-07-19 23:51 - 00000000 ____D C:\Documents and Settings\Pc\Moje dokumenty\Pobieranie 2013-09-07 20:34 - 2013-03-08 12:40 - 00000000 ____D C:\Documents and Settings\Pc\.gstreamer-0.10 2013-09-07 16:41 - 2013-09-07 16:41 - 00056770 _____ C:\Documents and Settings\Pc\Pulpit\OTL.Txt 2013-09-07 16:41 - 2013-09-07 16:41 - 00039486 _____ C:\Documents and Settings\Pc\Pulpit\Extras.Txt 2013-09-07 16:23 - 2013-09-07 16:23 - 00000466 _____ C:\Documents and Settings\Pc\Pulpit\defogger_disable.log 2013-09-07 16:23 - 2013-09-07 16:23 - 00000000 _____ C:\Documents and Settings\Pc\defogger_reenable 2013-09-07 16:22 - 2013-09-07 16:22 - 00016858 _____ C:\Documents and Settings\Pc\Pulpit\AVSCAN-20130907-160814-C4FC295A.LOG 2013-09-07 16:18 - 2013-09-07 16:18 - 00050477 _____ C:\Documents and Settings\Pc\Pulpit\Defogger.exe 2013-09-07 16:09 - 2013-09-07 16:08 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Pc\Pulpit\OTL.exe 2013-09-06 14:29 - 2013-09-06 14:29 - 00984735 _____ (Macromedia, Inc.) C:\WINDOWS\Speedo Clock.exe 2013-09-06 14:29 - 2013-09-06 14:29 - 00259184 _____ (MacSourcery) C:\WINDOWS\Speedo Clock.scr 2013-09-06 14:29 - 2013-09-06 14:29 - 00029696 _____ (MacSourcery) C:\WINDOWS\mickey32.dll 2013-09-06 14:29 - 2001-07-21 23:15 - 00000259 _____ C:\WINDOWS\system.ini 2013-09-05 21:45 - 2013-09-05 21:45 - 96185213 _____ C:\WINDOWS\system32\뿙ƌ 2013-09-04 17:32 - 2013-09-04 17:32 - 95863165 _____ C:\WINDOWS\system32\皻墽ƌ 2013-09-04 12:46 - 2013-09-04 12:46 - 00000696 _____ C:\Documents and Settings\Pc\Pulpit\Skrót do open-fm.lnk 2013-09-04 12:46 - 2013-09-04 12:46 - 00000000 ____D C:\Documents and Settings\Pc\Dane aplikacji\OpenFM 2013-09-04 12:46 - 2004-07-19 04:17 - 00000000 __RHD C:\Documents and Settings\All Users\Dane aplikacji 2013-09-04 12:46 - 2004-07-19 03:16 - 00000000 __RHD C:\Documents and Settings\Pc\Dane aplikacji 2013-09-04 11:30 - 2013-03-13 11:36 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 2013-09-03 12:37 - 2013-03-11 10:53 - 00000000 ____D C:\Documents and Settings\Pc\Dane aplikacji\XnView 2013-09-02 18:25 - 2013-09-02 18:25 - 95286781 _____ C:\WINDOWS\system32\悆ꢬƌ 2013-09-02 18:16 - 2013-08-06 20:29 - 00000000 ____D C:\Program Files\The Sims 8 in 1 2013-09-02 00:01 - 2013-08-12 21:53 - 00000000 ____D C:\Documents and Settings\Pc\Pulpit\Psychiatryk 2013-09-01 18:38 - 2013-09-01 18:38 - 95199041 _____ C:\WINDOWS\system32\潣ƌ 2013-09-01 00:10 - 2013-03-15 18:09 - 00000000 ____D C:\Documents and Settings\Pc\.gimp-2.6 2013-08-31 23:32 - 2013-08-31 23:32 - 00026661 _____ C:\Documents and Settings\Pc\.recently-used.xbel 2013-08-31 23:32 - 2013-03-13 11:14 - 00000000 ____D C:\Documents and Settings\Pc\Dane aplikacji\gtk-2.0 2013-08-29 16:27 - 2013-03-13 11:36 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 2013-08-29 01:17 - 2013-08-29 01:17 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$ 2013-08-25 00:32 - 2013-03-08 12:47 - 00000000 ____D C:\Documents and Settings\Pc\Pulpit\Obrazy płyt 2013-08-24 22:34 - 2013-08-24 22:09 - 00000000 ____D C:\Program Files\MechWarrior 3 2013-08-24 22:13 - 2013-08-24 22:12 - 00000216 _____ C:\WINDOWS\PowerReg.dat 2013-08-24 22:09 - 2004-07-19 04:17 - 00000000 ___RD C:\Documents and Settings\All Users\Menu Start 2013-08-21 16:45 - 2004-07-19 04:17 - 00000000 ___RD C:\Documents and Settings\All Users\Dokumenty 2013-08-17 19:40 - 2004-07-19 23:48 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-17 17:57 - 2013-08-17 17:56 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-16 16:03 - 2013-03-13 12:14 - 00000000 ____D C:\WINDOWS\Microsoft.NET 2013-08-14 23:12 - 2013-07-25 20:08 - 00000000 ____D C:\WINDOWS\system32\NtmsData 2013-08-14 22:42 - 2004-07-19 04:16 - 00000211 ___SH C:\boot.ini 2013-08-14 22:42 - 2001-07-21 23:16 - 00000477 _____ C:\WINDOWS\win.ini 2013-08-14 22:07 - 2004-07-19 02:24 - 00000000 ____D C:\WINDOWS\Registration 2013-08-14 21:56 - 2004-07-19 04:17 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit 2013-08-14 21:31 - 2013-03-13 11:30 - 00040776 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2013-08-14 20:52 - 2013-08-14 20:48 - 00000000 ____D C:\WINDOWS\system32\MRT 2013-08-14 20:52 - 2013-03-08 00:48 - 00000000 ____D C:\WINDOWS\ie8updates 2013-08-14 20:48 - 2013-03-08 00:43 - 75778376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2013-08-14 20:42 - 2004-07-19 04:18 - 01276418 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2013-08-14 20:42 - 2001-10-26 17:15 - 00564498 _____ C:\WINDOWS\system32\perfh015.dat 2013-08-14 20:42 - 2001-10-26 17:15 - 00109584 _____ C:\WINDOWS\system32\perfc015.dat 2013-08-14 20:38 - 2013-08-14 20:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2863058$ 2013-08-14 20:38 - 2013-08-14 20:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$ 2013-08-14 20:38 - 2013-08-14 20:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$ 2013-08-14 20:38 - 2013-03-08 00:39 - 00012546 _____ C:\WINDOWS\system32\TZLog.log 2013-08-14 20:37 - 2013-08-14 20:37 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2849470$ 2013-08-11 17:13 - 2013-03-19 23:02 - 00000000 ___RD C:\Documents and Settings\Pc\Moje dokumenty\Moje wideo 2013-08-11 16:24 - 2004-08-02 03:15 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-08-11 16:21 - 2013-06-26 20:40 - 00000309 _____ C:\WINDOWS\SIERRA.INI 2013-08-11 16:20 - 2004-07-19 03:16 - 00000000 ___RD C:\Documents and Settings\Pc\Menu Start\Programy 2013-08-11 16:16 - 2013-03-13 22:44 - 00000000 ____D C:\WINDOWS\Minidump ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe [2008-04-14 22:51] - [2008-04-14 22:51] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\Windows\System32\winlogon.exe [2008-04-14 22:51] - [2008-04-14 22:51] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\Windows\System32\svchost.exe [2008-04-14 22:51] - [2008-04-14 22:51] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\Windows\System32\services.exe [2008-04-14 22:51] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f C:\Windows\System32\User32.dll [2008-04-14 22:50] - [2008-04-14 22:50] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\Windows\System32\userinit.exe [2008-04-14 22:51] - [2008-04-14 22:51] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\Windows\System32\Drivers\volsnap.sys [2008-04-14 21:31] - [2008-04-14 21:31] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================