Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013 Ran by user (administrator) on USER-1EA621C4F8 on 05-11-2013 14:38:03 Running from C:\Documents and Settings\user.USER-1EA621C4F8\Pulpit\Programy do usuwania syfu Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 7 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Taiwan Shui Mu Chih Ching Technology Limited.) G:\Gry\WinZipper\winzipersvc.exe (Wsys Co., Ltd.) C:\Documents and Settings\All Users\Dane aplikacji\eSafe\eGdpSvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe () C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jqs.exe (Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Rocket Division Software) C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe () C:\WINDOWS\system32\UAService7.exe () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.exe [16857600 2008-02-13] (Realtek Semiconductor Corp.) HKLM\...\Run: [Alcmtr] - C:\WINDOWS\Alcmtr.exe [69632 2005-05-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [ASUSGamerOSD] - C:\Program Files\ASUS\GamerOSD\GamerOSD.exe [380928 2007-07-12] (ASUSTeK Computer Inc.) HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [866584 2006-11-03] (Microsoft Corporation) HKLM\...\Run: [ISUSPM Startup] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-16] (InstallShield Software Corporation) HKLM\...\Run: [ISUSScheduler] - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2004-06-16] (InstallShield Software Corporation) HKLM\...\Run: [RemoteControl] - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [32768 2003-10-31] (Cyberlink Corp.) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime Alternative\QTTask.exe [413696 2008-11-04] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [290088 2008-11-20] (Apple Inc.) HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [248552 2010-05-14] (Sun Microsystems, Inc.) HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k HKLM\...\Run: [Adobe ARM] - G:\GRY\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated) HKLM\...\Run: [NeroFilterCheck] - C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKU\user\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [ 2006-10-09] (Nero AG) HKU\user\...\Run: [H/PC Connection Agent] - C:\Program Files\Microsoft ActiveSync\wcescomm.exe [ 2006-11-13] (Microsoft Corporation) HKU\user\...\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [ 2008-04-14] (Microsoft Corporation) HKU\user\...\Run: [Trojan Killer] - "C:\PROGRA~1\GRIDIN~1\TROJAN~1.COM" 0 HKU\user\...\Run: [HP Photosmart 5510 series (NET)] - C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe [ 2011-09-16] (Hewlett-Packard Co.) HKU\user\...\RunOnce: [FlashPlayerUpdate] - C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_7_700_224_Plugin.exe -update plugin Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BlueSoleil.lnk ShortcutTarget: BlueSoleil.lnk -> C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe (IVT Corporation) Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Documents and Settings\user.USER-1EA621C4F8\Dane aplikacji\Dropbox\bin\Dropbox.exe (No File) ==================== Internet (Whitelisted) ==================== HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=hp&from=newgdp&uid=ST3320613AS_6SZ0C3PCXXXX6SZ0C3PC&ts=1380391567 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=hp&from=newgdp&uid=ST3320613AS_6SZ0C3PCXXXX6SZ0C3PC&ts=1380391567 HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST3320613AS_6SZ0C3PCXXXX6SZ0C3PC&ts=1377255093 BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.) BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - G:\GRY\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll () BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.) BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) BHO: IEPluginBHO Class - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\user\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.) Toolbar: HKLM - &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll () DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1222780767051 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl/jinstall-1_4_0_03-win.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\PROGRA~1\WINDOW~4\MpShHook.dll [83224 2006-11-03] (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\user.USER-1EA621C4F8\Dane aplikacji\Mozilla\Firefox\Profiles\4lmff0lm.default FF NewTab: hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST3320613AS_6SZ0C3PCXXXX6SZ0C3PC&ts=1379521004 FF DefaultSearchEngine: delta-homes FF SearchEngineOrder.1: qvo6 FF SelectedSearchEngine: delta-homes FF Homepage: hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST3320613AS_6SZ0C3PCXXXX6SZ0C3PC&ts=1379521004 FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - G:\Gry\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=6.0.11.2852 - C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nppl3260;version=6.0.12.46 - C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1662 - C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.46 - C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 - C:\Documents and Settings\All Users\Dane aplikacji\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP) FF Plugin: @tools.google.com/Google Update;version=3 - G:\Gry\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - G:\Gry\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.18 - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin: @zylom.com/ZylomGamesPlayer - C:\Documents and Settings\All Users\Dane aplikacji\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom) FF Plugin: Adobe Reader - G:\Gry\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=sc&from=newgdp&uid=ST3320613AS_6SZ0C3PCXXXX6SZ0C3PC&ts=1380391567 ========================== Services (Whitelisted) ================= R2 6to4; C:\Windows\System32\6to4svc.dll [100864 2010-02-12] (Microsoft Corporation) R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [132424 2008-11-07] (Apple Inc.) S2 ATKKeyboardService; C:\WINDOWS\ATKKBService.exe [257024 2007-07-12] (ASUSTeK COMPUTER INC.) R2 BlueSoleil Hid Service; C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe [110592 2005-04-06] () S2 gupdate; G:\Gry\Google\Update\GoogleUpdate.exe [116648 2013-08-27] (Google Inc.) S3 gupdatem; G:\Gry\Google\Update\GoogleUpdate.exe [116648 2013-08-27] (Google Inc.) S3 gusvc; G:\GRY\Google\Common\Google Updater\GoogleUpdaterService.exe [136120 2011-05-09] (Google) R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [275968 2007-05-28] (Rocket Division Software) R2 UserAccess7; C:\WINDOWS\system32\UAService7.exe [126976 2009-07-26] () R2 vToolbarUpdater15.0.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe [990896 2013-04-07] () R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [13592 2006-11-03] (Microsoft Corporation) R2 winzipersvc; G:\Gry\WinZipper\winzipersvc.exe [424104 2013-08-23] (Taiwan Shui Mu Chih Ching Technology Limited.) R2 WsysSvc; C:\Documents and Settings\All Users\Dane aplikacji\eSafe\eGdpSvc.exe [303680 2013-08-22] (Wsys Co., Ltd.) R2 JavaQuickStarterService; "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" ==================== Drivers (Whitelisted) ==================== R3 AR9271; C:\Windows\System32\DRIVERS\athuw.sys [1763584 2011-07-28] (Atheros Communications, Inc.) R3 asusgsb; C:\Windows\System32\drivers\asusgsb.sys [12416 2007-07-12] (ASUSTeK Computer Inc.) R1 asuskbnt; C:\Windows\System32\drivers\atkkbnt.sys [11136 2007-07-12] (ASUSTeK COMPUTER INC.) R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [33624 2013-04-07] (AVG Technologies) R3 BlueletAudio; C:\Windows\System32\DRIVERS\blueletaudio.sys [20480 2005-05-31] (IVT Corporation) R3 BT; C:\Windows\System32\DRIVERS\btnetdrv.sys [10804 2005-04-30] (IVT Corporation) S3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [23000 2005-05-31] (IVT Corporation) R3 BTHidEnum; C:\Windows\System32\DRIVERS\vbtenum.sys [11860 2005-04-30] () R0 BTHidMgr; C:\Windows\System32\Drivers\BTHidMgr.sys [28271 2005-04-30] (IVT Corporation) S3 BTNetFilter; C:\WINDOWS\system32\drivers\BTNetFilter.sys [13304 2004-12-16] () S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation) R1 EIO; C:\WINDOWS\system32\drivers\EIO.sys [12288 2007-07-12] (ASUSTeK Computer Inc.) S3 ET5Drv; C:\WINDOWS\system32\Drivers\ET5Drv.sys [30008 2007-10-11] (Windows (R) 2000 DDK provider) S3 gdrv; C:\WINDOWS\gdrv.sys [16608 2008-09-24] (Windows (R) 2000 DDK provider) S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2007-03-07] (HP) S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2007-03-07] (HP) S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2007-03-07] (HP) R1 ISODrive; C:\Program Files\UltraISO\drivers\ISODrive.sys [82320 2009-02-10] (EZB Systems, Inc.) S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation) R3 NVHDA; C:\Windows\System32\drivers\nvhda32.sys [57320 2009-11-12] (NVIDIA Corporation) S3 PCANDIS5; C:\WINDOWS\system32\PCANDIS5.SYS [16128 2003-08-04] (Printing Communications Assoc., Inc. (PCAUSA)) S3 SONYPVU1; C:\Windows\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation) R1 Tcpip6; C:\Windows\System32\DRIVERS\tcpip6.sys [226880 2010-02-11] (Microsoft Corporation) R3 VComm; C:\Windows\System32\DRIVERS\VComm.sys [61312 2004-10-19] (IVT Corporation) R3 VcommMgr; C:\Windows\System32\Drivers\VcommMgr.sys [82148 2005-03-25] (IVT Corporation) R3 Video3D; C:\Windows\System32\Drivers\Video3D32.sys [10752 2007-07-12] (ASUSTeK COMPUTER INC.) S3 wceusbsh; C:\Windows\System32\DRIVERS\wceusbsh.sys [28672 2006-11-06] (Microsoft Corporation) S3 e4usbaw; system32\DRIVERS\e4usbaw.sys [x] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [x] S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [x] S3 filtertdidriver; system32\drivers\ewfiltertdidriver.sys [x] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [x] S3 huawei_cdcecm; system32\DRIVERS\ew_jucdcecm.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [x] S2 IKANLOADER2; System32\Drivers\e4ldr.sys [x] S4 IntelIde; No ImagePath S3 PCAMPR5; \??\C:\WINDOWS\system32\PCAMPR5.SYS [x] U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [x] U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-05 14:37 - 2013-11-05 14:37 - 00000000 ____D C:\FRST 2013-11-05 11:42 - 2013-11-05 11:47 - 00000000 ____D C:\Documents and Settings\user.USER-1EA621C4F8\Pulpit\Programy do usuwania syfu 2013-10-26 18:00 - 2013-10-26 18:00 - 00000000 ____D C:\Documents and Settings\user.USER-1EA621C4F8\Dane aplikacji\LucasArts 2013-10-13 16:46 - 2013-10-13 16:46 - 00090112 _____ C:\WINDOWS\Minidump\Mini101313-01.dmp 2013-10-13 10:02 - 2013-10-13 10:02 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2847311$ 2013-10-13 10:01 - 2013-10-13 10:01 - 00115105 _____ C:\WINDOWS\KB2862335.log 2013-10-13 10:01 - 2013-10-13 10:01 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$ 2013-10-13 09:57 - 2013-10-13 09:57 - 00006905 _____ C:\WINDOWS\KB2868038.log 2013-10-13 09:57 - 2013-10-13 09:57 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868038$ 2013-10-13 09:56 - 2013-10-13 09:56 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2883150$ 2013-10-13 09:56 - 2013-10-13 09:56 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862330$ 2013-10-12 12:37 - 2013-10-13 10:02 - 00119332 _____ C:\WINDOWS\KB2847311.log 2013-10-12 12:37 - 2013-07-03 03:12 - 00025088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hidparse.sys 2013-10-12 12:34 - 2013-08-09 01:55 - 00144128 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbport.sys 2013-10-12 12:34 - 2013-08-09 01:55 - 00005376 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbd.sys 2013-10-12 12:34 - 2013-07-17 01:58 - 00123008 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbvideo.sys 2013-10-12 12:34 - 2009-03-18 12:02 - 00030336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbehci.sys ==================== One Month Modified Files and Folders ======= 2013-11-05 14:37 - 2013-11-05 14:37 - 00000000 ____D C:\FRST 2013-11-05 14:21 - 2011-12-28 13:06 - 00001016 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-05 14:14 - 2013-03-11 16:24 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-11-05 14:01 - 2012-03-12 19:39 - 00000326 _____ C:\WINDOWS\Tasks\HP Photo Creations Messager.job 2013-11-05 14:00 - 2012-03-12 19:38 - 00000472 _____ C:\WINDOWS\Tasks\At4.job 2013-11-05 13:57 - 2013-03-03 13:36 - 00000480 _____ C:\WINDOWS\Tasks\HP Photo Creations Communicator.job 2013-11-05 12:21 - 2008-09-24 16:33 - 00032566 _____ C:\WINDOWS\SchedLgU.Txt 2013-11-05 11:47 - 2013-11-05 11:42 - 00000000 ____D C:\Documents and Settings\user.USER-1EA621C4F8\Pulpit\Programy do usuwania syfu 2013-11-05 11:47 - 2013-08-12 14:04 - 00000000 ____D C:\Documents and Settings\user.USER-1EA621C4F8\Moje dokumenty\Pobieranie 2013-11-05 11:43 - 2013-05-20 19:55 - 00000000 ____D G:\Gry\Google 2013-11-05 11:42 - 2013-07-23 19:20 - 00000000 ____D C:\Documents and Settings\user.USER-1EA621C4F8\Pulpit 2013-11-05 11:38 - 2013-08-25 22:32 - 00000330 ____H C:\WINDOWS\Tasks\MP Scheduled Scan.job 2013-11-05 11:38 - 2008-09-24 16:30 - 01647480 _____ C:\WINDOWS\WindowsUpdate.log 2013-11-05 11:32 - 2010-07-28 12:37 - 00000000 ____D C:\WINDOWS\Microsoft.NET 2013-11-05 11:23 - 2013-08-23 11:51 - 00000000 ____D G:\Gry\WinZipper 2013-11-05 11:23 - 2013-08-12 14:12 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\eSafe 2013-11-05 11:22 - 2012-03-14 22:38 - 01020473 _____ C:\WINDOWS\setupapi.log 2013-11-05 11:19 - 2008-09-24 18:24 - 00000159 _____ C:\WINDOWS\wiadebug.log 2013-11-05 11:19 - 2008-09-24 18:24 - 00000050 _____ C:\WINDOWS\wiaservc.log 2013-11-05 11:17 - 2013-03-19 17:28 - 00000350 _____ C:\WINDOWS\Tasks\SmartPCFix Task.job 2013-11-05 11:17 - 2011-12-28 13:06 - 00001012 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-05 11:17 - 2008-09-24 16:33 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-11-05 11:17 - 2006-03-02 13:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl 2013-10-29 20:40 - 2012-03-12 19:38 - 00000472 _____ C:\WINDOWS\Tasks\At2.job 2013-10-29 19:38 - 2012-03-12 19:38 - 00000472 _____ C:\WINDOWS\Tasks\At3.job 2013-10-26 18:00 - 2013-10-26 18:00 - 00000000 ____D C:\Documents and Settings\user.USER-1EA621C4F8\Dane aplikacji\LucasArts 2013-10-26 18:00 - 2013-08-08 10:03 - 00000000 ____D C:\Documents and Settings\user.USER-1EA621C4F8\Dane aplikacji 2013-10-23 11:14 - 2011-01-29 20:21 - 00001788 _____ C:\Documents and Settings\user.USER-1EA621C4F8\Pulpit\Launch LEGO® Indiana Jones™.lnk 2013-10-14 10:57 - 2010-01-31 03:52 - 00271641 _____ C:\WINDOWS\system32\NvApps.xml 2013-10-13 16:46 - 2013-10-13 16:46 - 00090112 _____ C:\WINDOWS\Minidump\Mini101313-01.dmp 2013-10-13 10:09 - 2008-09-24 18:19 - 00283720 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2013-10-13 10:04 - 2008-10-01 22:12 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2013-10-13 10:04 - 2008-09-24 18:21 - 01044334 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2013-10-13 10:04 - 2006-03-02 13:00 - 00491064 _____ C:\WINDOWS\system32\perfh015.dat 2013-10-13 10:04 - 2006-03-02 13:00 - 00084316 _____ C:\WINDOWS\system32\perfc015.dat 2013-10-13 10:02 - 2013-10-13 10:02 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2847311$ 2013-10-13 10:02 - 2013-10-12 12:37 - 00119332 _____ C:\WINDOWS\KB2847311.log 2013-10-13 10:02 - 2008-09-30 14:42 - 00325983 _____ C:\WINDOWS\updspapi.log 2013-10-13 10:02 - 2008-09-24 18:22 - 00747456 _____ C:\WINDOWS\tsoc.log 2013-10-13 10:02 - 2008-09-24 18:22 - 00396010 _____ C:\WINDOWS\ntdtcsetup.log 2013-10-13 10:02 - 2008-09-24 18:22 - 00121219 _____ C:\WINDOWS\ocmsn.log 2013-10-13 10:02 - 2008-09-24 18:22 - 00097293 _____ C:\WINDOWS\msgsocm.log 2013-10-13 10:02 - 2008-09-24 18:22 - 00001393 _____ C:\WINDOWS\imsins.log 2013-10-13 10:02 - 2008-09-24 18:21 - 01941186 _____ C:\WINDOWS\FaxSetup.log 2013-10-13 10:02 - 2008-09-24 18:21 - 00939599 _____ C:\WINDOWS\ocgen.log 2013-10-13 10:02 - 2008-09-24 18:21 - 00655809 _____ C:\WINDOWS\comsetup.log 2013-10-13 10:02 - 2008-09-24 18:21 - 00308121 _____ C:\WINDOWS\iis6.log 2013-10-13 10:01 - 2013-10-13 10:01 - 00115105 _____ C:\WINDOWS\KB2862335.log 2013-10-13 10:01 - 2013-10-13 10:01 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$ 2013-10-13 10:01 - 2013-08-20 15:16 - 00000000 ____D C:\WINDOWS\system32\MRT 2013-10-13 10:01 - 2008-09-24 18:22 - 00001393 _____ C:\WINDOWS\imsins.BAK 2013-10-13 09:59 - 2008-10-02 19:55 - 78106760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2013-10-13 09:58 - 2013-07-12 11:49 - 00000000 ____D G:\Gry\Microsoft Silverlight 2013-10-13 09:57 - 2013-10-13 09:57 - 00006905 _____ C:\WINDOWS\KB2868038.log 2013-10-13 09:57 - 2013-10-13 09:57 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868038$ 2013-10-13 09:56 - 2013-10-13 09:56 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2883150$ 2013-10-13 09:56 - 2013-10-13 09:56 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862330$ 2013-10-12 13:15 - 2013-03-11 16:24 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2013-10-12 13:15 - 2011-07-20 17:40 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl Files to move or delete: ==================== C:\Windows\Tasks\At1.job C:\Windows\Tasks\At2.job C:\Windows\Tasks\At3.job C:\Windows\Tasks\At4.job ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe [2006-03-02 13:00] - [2008-04-14 18:21] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\Windows\System32\winlogon.exe [2006-03-02 13:00] - [2008-04-14 18:21] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\Windows\System32\svchost.exe [2006-03-02 13:00] - [2008-04-14 18:21] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\Windows\System32\services.exe [2006-03-02 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f C:\Windows\System32\User32.dll [2006-03-02 13:00] - [2008-04-14 18:20] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\Windows\System32\userinit.exe [2006-03-02 13:00] - [2008-04-14 18:21] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\Windows\System32\Drivers\volsnap.sys [2006-03-02 13:00] - [2008-04-14 17:01] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================