Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013 Ran by endorro (administrator) on PLATKOVS-31410D on 20-10-2013 13:26:22 Running from C:\Documents and Settings\endorro\Moje dokumenty\Pobieranie Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (BitTorrent Inc.) C:\Program Files\uTorrent\uTorrent.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Skype Technologies) C:\Program Files\Skype\Updater\Updater.exe (Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AzMixerSel] - C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe [53248 2006-07-17] (Realtek Semiconductor Corp.) HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [159744 2007-07-21] (Alps Electric Co., Ltd.) HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] () HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [18084864 2009-01-13] (Realtek Semiconductor Corp.) HKLM\...\Run: [Alcmtr] - C:\Windows\ALCMTR.EXE [57344 2008-06-19] (Realtek Semiconductor Corp.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Run: [uTorrent] - C:\Program Files\uTorrent\uTorrent.exe [802136 2013-05-05] (BitTorrent Inc.) HKCU\...\Run: [Facebook Update] - C:\Documents and Settings\endorro\Ustawienia lokalne\Dane aplikacji\Facebook\Update\FacebookUpdate.exe [138096 2013-02-10] (Facebook Inc.) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20684656 2013-07-25] (Skype Technologies S.A.) Lsa: [Authentication Packages] msv1_0 nwprovau ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - DefaultScope value is missing. BHO: ALLYouTubeDownloader - {61DB16C5-B733-43F4-872E-B20DC9E72740} - C:\PROGRA~1\ALLYOU~1\ALLYOU~1.DLL (ALLCinema Ltd.) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 84.208.20.110 84.208.20.111 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\endorro\Dane aplikacji\Mozilla\Firefox\Profiles\86sh2s10.default-1382266768109 FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Documents and Settings\endorro\Ustawienia lokalne\Dane aplikacji\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Documents and Settings\endorro\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) ========================== Services (Whitelisted) ================= R2 NWCWorkstation; C:\Windows\System32\nwwks.dll [65536 2010-01-22] (Microsoft Corporation) R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" ==================== Drivers (Whitelisted) ==================== R3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl5.sys [1123328 2007-09-20] (Broadcom Corp.) S3 cmshusbser; C:\Windows\System32\DRIVERS\cmshusbser.sys [111104 2011-11-30] (QUALCOMM Incorporated) R3 L1c; C:\Windows\System32\DRIVERS\l1c51x86.sys [38912 2009-01-15] (Atheros Communications, Inc.) S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation) R2 NwlnkIpx; C:\Windows\System32\DRIVERS\nwlnkipx.sys [88320 2010-01-22] (Microsoft Corporation) R2 NwlnkNb; C:\Windows\System32\DRIVERS\nwlnknb.sys [63232 2010-01-22] (Microsoft Corporation) R2 NwlnkSpx; C:\Windows\System32\DRIVERS\nwlnkspx.sys [55936 2010-01-22] (Microsoft Corporation) R3 NWRDR; C:\Windows\System32\DRIVERS\nwrdr.sys [163584 2010-01-22] (Microsoft Corporation) R3 Sftfs; C:\Windows\System32\DRIVERS\Sftfsxp.sys [584680 2011-10-01] (Microsoft Corporation) R3 Sftplay; C:\Windows\System32\DRIVERS\Sftplayxp.sys [209512 2011-10-01] (Microsoft Corporation) R3 Sftredir; C:\Windows\System32\DRIVERS\Sftredirxp.sys [20584 2011-10-01] (Microsoft Corporation) R3 Sftvol; C:\Windows\System32\DRIVERS\Sftvolxp.sys [18280 2011-10-01] (Microsoft Corporation) R0 Si3112; C:\Windows\System32\Drivers\Si3112.sys [62336 2010-01-22] (Silicon Image, Inc.) S0 Si3114r5; C:\Windows\System32\Drivers\Si3114r5.sys [195072 2010-01-22] (Silicon Image, Inc) R0 Si3124; C:\Windows\System32\Drivers\Si3124.sys [69248 2010-01-22] (Silicon Image, Inc.) R0 Si3132; C:\Windows\System32\Drivers\Si3132.sys [74672 2010-01-22] (Silicon Image, Inc.) R0 Si3132r5; C:\Windows\System32\Drivers\Si3132r5.sys [215856 2010-01-22] (Silicon Image, Inc) R0 Si3531; C:\Windows\System32\Drivers\Si3531.sys [212520 2010-01-22] (Silicon Image, Inc) S4 IntelIde; No ImagePath U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-20 13:23 - 2013-10-20 13:23 - 00005795 _____ C:\Documents and Settings\endorro\Pulpit\AdwCleaner[S0].txt 2013-10-20 13:14 - 2013-10-20 13:16 - 00000000 ____D C:\AdwCleaner 2013-10-20 12:59 - 2013-10-20 12:59 - 00000000 ____D C:\Documents and Settings\endorro\Pulpit\Stare dane programu Firefox 2013-10-20 12:52 - 2013-10-20 12:52 - 00000000 ____D C:\WINDOWS\system32\appmgmt 2013-10-18 18:29 - 2013-10-18 18:29 - 00004704 _____ C:\Documents and Settings\endorro\Pulpit\gmer.log 2013-10-18 18:01 - 2013-10-20 12:48 - 00000000 ____D C:\FRST 2013-10-16 22:37 - 2013-10-16 22:37 - 00000000 ____D C:\Documents and Settings\endorro\Pulpit\Solstafir - Svartir Sandar 2013-10-15 19:37 - 2013-10-15 19:37 - 00001810 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Cisco Connect.lnk 2013-10-15 19:36 - 2013-10-15 19:36 - 00000000 ____D C:\Program Files\Cisco Systems 2013-10-15 19:32 - 2013-10-15 19:32 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Cisco Systems 2013-10-13 10:28 - 2013-10-13 19:59 - 00000000 ____D C:\Documents and Settings\endorro\Pulpit\gaupne 2013-10-08 22:47 - 2013-10-08 22:47 - 17813896 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe 2013-10-02 12:57 - 2013-10-02 14:49 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-27 13:13 - 2013-09-27 13:13 - 00000000 ____D C:\WINDOWS\Sun 2013-09-25 12:12 - 2013-09-26 16:20 - 00003221 _____ C:\Documents and Settings\endorro\Pulpit\ada hihi.txt 2013-09-25 11:25 - 2013-09-25 11:25 - 00000000 ____D C:\Documents and Settings\endorro\Ustawienia lokalne\Dane aplikacji\Sun 2013-09-24 20:03 - 2013-09-24 20:03 - 00868264 _____ (Oracle Corporation) C:\WINDOWS\system32\npDeployJava1.dll 2013-09-24 20:03 - 2013-09-24 20:03 - 00790440 _____ (Oracle Corporation) C:\WINDOWS\system32\deployJava1.dll 2013-09-24 20:03 - 2013-09-24 20:03 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2013-09-24 20:03 - 2013-09-24 20:03 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2013-09-24 20:03 - 2013-09-24 20:03 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2013-09-24 20:03 - 2013-09-24 20:03 - 00144896 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2013-09-24 20:03 - 2013-09-24 20:03 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2013-09-24 20:03 - 2013-09-24 20:03 - 00000000 ____D C:\Program Files\Java 2013-09-24 20:03 - 2013-09-24 20:03 - 00000000 ____D C:\Program Files\Common Files\Java 2013-09-24 20:03 - 2013-09-24 20:03 - 00000000 ____D C:\Documents and Settings\endorro\Dane aplikacji\Sun 2013-09-24 20:03 - 2013-09-24 20:03 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Java 2013-09-24 20:03 - 2013-09-24 20:03 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Sun 2013-09-23 22:01 - 2013-09-23 22:01 - 00000000 ____D C:\Documents and Settings\endorro\Pulpit\Norweski-AudioKurs ==================== One Month Modified Files and Folders ======= 2013-10-20 13:26 - 2012-09-23 18:34 - 00000000 ____D C:\Documents and Settings\endorro\Moje dokumenty\Pobieranie 2013-10-20 13:25 - 2013-05-24 21:32 - 00000000 ____D C:\Documents and Settings\endorro\Dane aplikacji\Skype 2013-10-20 13:25 - 2012-09-23 19:00 - 00000000 ____D C:\Documents and Settings\endorro\Dane aplikacji\uTorrent 2013-10-20 13:25 - 2012-07-24 01:00 - 00000050 _____ C:\WINDOWS\wiaservc.log 2013-10-20 13:25 - 2012-07-24 00:59 - 00000159 _____ C:\WINDOWS\wiadebug.log 2013-10-20 13:25 - 2012-07-23 23:08 - 00446630 _____ C:\WINDOWS\WindowsUpdate.log 2013-10-20 13:24 - 2012-07-23 23:12 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-10-20 13:23 - 2013-10-20 13:23 - 00005795 _____ C:\Documents and Settings\endorro\Pulpit\AdwCleaner[S0].txt 2013-10-20 13:23 - 2012-07-24 00:58 - 00765502 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2013-10-20 13:23 - 2012-07-23 23:13 - 00000188 ___SH C:\Documents and Settings\endorro\ntuser.ini 2013-10-20 13:23 - 2012-07-23 23:13 - 00000000 ____D C:\Documents and Settings\endorro\Pulpit 2013-10-20 13:23 - 2012-07-23 23:12 - 00032500 _____ C:\WINDOWS\SchedLgU.Txt 2013-10-20 13:23 - 2010-01-22 00:47 - 00356512 _____ C:\WINDOWS\system32\perfh015.dat 2013-10-20 13:23 - 2010-01-22 00:47 - 00050096 _____ C:\WINDOWS\system32\perfc015.dat 2013-10-20 13:18 - 2012-12-27 01:01 - 00000000 ____D C:\Program Files\v9Soft 2013-10-20 13:17 - 2013-07-29 14:09 - 00000000 ____D C:\Documents and Settings\All Users\Dokumenty\SoftGrid Client 2013-10-20 13:16 - 2013-10-20 13:14 - 00000000 ____D C:\AdwCleaner 2013-10-20 13:16 - 2012-07-23 23:13 - 00000000 ___RD C:\Documents and Settings\endorro\Menu Start\Programy 2013-10-20 13:16 - 2012-07-23 23:13 - 00000000 ___HD C:\Documents and Settings\endorro\Ustawienia lokalne\Dane aplikacji 2013-10-20 13:16 - 2012-07-23 23:12 - 00000000 ___HD C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji 2013-10-20 13:09 - 2013-02-10 14:04 - 00001010 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1547161642-861567501-1417001333-1003UA.job 2013-10-20 13:09 - 2013-02-10 14:04 - 00000988 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1547161642-861567501-1417001333-1003Core.job 2013-10-20 12:59 - 2013-10-20 12:59 - 00000000 ____D C:\Documents and Settings\endorro\Pulpit\Stare dane programu Firefox 2013-10-20 12:57 - 2012-07-24 00:58 - 00000000 ___RD C:\Documents and Settings\All Users\Menu Start\Programy 2013-10-20 12:57 - 2012-07-23 23:13 - 00000000 __RHD C:\Documents and Settings\endorro\Dane aplikacji 2013-10-20 12:56 - 2012-07-24 00:57 - 00000000 __RHD C:\Documents and Settings\All Users\Dane aplikacji 2013-10-20 12:55 - 2012-07-24 00:58 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit 2013-10-20 12:52 - 2013-10-20 12:52 - 00000000 ____D C:\WINDOWS\system32\appmgmt 2013-10-20 12:48 - 2013-10-18 18:01 - 00000000 ____D C:\FRST 2013-10-20 12:48 - 2012-07-23 23:12 - 00000000 ____D C:\Documents and Settings\LocalService\Dane aplikacji 2013-10-20 12:45 - 2012-09-23 18:35 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-10-18 18:29 - 2013-10-18 18:29 - 00004704 _____ C:\Documents and Settings\endorro\Pulpit\gmer.log 2013-10-18 11:44 - 2012-07-24 00:57 - 00941293 _____ C:\WINDOWS\setupapi.log 2013-10-18 11:41 - 2012-07-23 23:06 - 00034700 _____ C:\WINDOWS\wmsetup.log 2013-10-18 11:06 - 2012-07-24 00:57 - 00215690 _____ C:\WINDOWS\setupact.log 2013-10-17 07:58 - 2010-01-22 00:47 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl 2013-10-16 22:37 - 2013-10-16 22:37 - 00000000 ____D C:\Documents and Settings\endorro\Pulpit\Solstafir - Svartir Sandar 2013-10-16 12:17 - 2012-10-16 13:24 - 00000000 ____D C:\Documents and Settings\endorro\Pulpit\Język No 2013-10-15 19:37 - 2013-10-15 19:37 - 00001810 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Cisco Connect.lnk 2013-10-15 19:36 - 2013-10-15 19:36 - 00000000 ____D C:\Program Files\Cisco Systems 2013-10-15 19:32 - 2013-10-15 19:32 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Cisco Systems 2013-10-13 19:59 - 2013-10-13 10:28 - 00000000 ____D C:\Documents and Settings\endorro\Pulpit\gaupne 2013-10-12 19:19 - 2012-10-16 13:18 - 00000000 ____D C:\Documents and Settings\endorro\Pulpit\Norweski 2013-10-08 22:47 - 2013-10-08 22:47 - 17813896 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe 2013-10-08 22:47 - 2012-09-23 18:35 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2013-10-08 22:47 - 2012-09-23 18:35 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2013-10-07 17:13 - 2012-07-24 22:08 - 00178176 _____ C:\Documents and Settings\endorro\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-10-02 22:47 - 2013-07-29 14:10 - 00000000 ____D C:\Documents and Settings\endorro\Dane aplikacji\SoftGrid Client 2013-10-02 14:49 - 2013-10-02 12:57 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-02 14:49 - 2013-01-05 18:37 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-09-30 13:47 - 2012-07-23 23:13 - 00000000 ____D C:\Documents and Settings\endorro 2013-09-30 09:23 - 2012-11-20 13:01 - 00000000 ____D C:\Documents and Settings\endorro\Dane aplikacji\AIMP3 2013-09-28 11:43 - 2013-05-24 21:32 - 00000000 ___RD C:\Program Files\Skype 2013-09-28 11:43 - 2013-05-24 21:32 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Skype 2013-09-27 13:13 - 2013-09-27 13:13 - 00000000 ____D C:\WINDOWS\Sun 2013-09-26 16:20 - 2013-09-25 12:12 - 00003221 _____ C:\Documents and Settings\endorro\Pulpit\ada hihi.txt 2013-09-25 21:53 - 2012-11-20 13:02 - 00015272 _____ C:\Documents and Settings\endorro\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2013-09-25 11:25 - 2013-09-25 11:25 - 00000000 ____D C:\Documents and Settings\endorro\Ustawienia lokalne\Dane aplikacji\Sun 2013-09-24 20:03 - 2013-09-24 20:03 - 00868264 _____ (Oracle Corporation) C:\WINDOWS\system32\npDeployJava1.dll 2013-09-24 20:03 - 2013-09-24 20:03 - 00790440 _____ (Oracle Corporation) C:\WINDOWS\system32\deployJava1.dll 2013-09-24 20:03 - 2013-09-24 20:03 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2013-09-24 20:03 - 2013-09-24 20:03 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2013-09-24 20:03 - 2013-09-24 20:03 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2013-09-24 20:03 - 2013-09-24 20:03 - 00144896 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2013-09-24 20:03 - 2013-09-24 20:03 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2013-09-24 20:03 - 2013-09-24 20:03 - 00000000 ____D C:\Program Files\Java 2013-09-24 20:03 - 2013-09-24 20:03 - 00000000 ____D C:\Program Files\Common Files\Java 2013-09-24 20:03 - 2013-09-24 20:03 - 00000000 ____D C:\Documents and Settings\endorro\Dane aplikacji\Sun 2013-09-24 20:03 - 2013-09-24 20:03 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Java 2013-09-24 20:03 - 2013-09-24 20:03 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Sun 2013-09-23 22:01 - 2013-09-23 22:01 - 00000000 ____D C:\Documents and Settings\endorro\Pulpit\Norweski-AudioKurs 2013-09-22 22:54 - 2013-09-17 22:40 - 00000000 ____D C:\Documents and Settings\endorro\Pulpit\galgeberg przygotowanie 2013-09-22 10:49 - 2012-10-08 22:32 - 00000000 ___RD C:\Documents and Settings\endorro\Pulpit\foty Some content of TEMP: ==================== C:\Documents and Settings\endorro\Ustawienia lokalne\Temp\RtkBtMnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe [2010-01-22 00:47] - [2010-01-22 00:47] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\Windows\System32\winlogon.exe [2010-01-22 00:47] - [2010-01-22 00:47] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\Windows\System32\svchost.exe [2010-01-22 00:47] - [2010-01-22 00:47] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\Windows\System32\services.exe [2010-01-22 00:47] - [2010-01-22 00:47] - 0111104 ____A (Microsoft Corporation) 8816e60bf654353e8e0d35ed98875445 C:\Windows\System32\User32.dll [2010-01-22 00:47] - [2010-01-22 00:47] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\Windows\System32\userinit.exe [2010-01-22 00:47] - [2010-01-22 00:47] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\Windows\System32\Drivers\volsnap.sys [2010-01-22 00:47] - [2010-01-22 00:47] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================