Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-11-2013 Ran by Adrian (administrator) on AS on 16-11-2013 18:49:08 Running from C:\Documents and Settings\Adrian\Pulpit Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (Agere Systems) C:\WINDOWS\system32\agrsmsvc.exe (Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe () C:\Documents and Settings\All Users\Dane aplikacji\DatacardService\HWDeviceService.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Locktime Software) D:\NetLimiter 3\nlsvc.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe () C:\Documents and Settings\All Users\Dane aplikacji\PLAY ONLINE\OnlineUpdate\ouc.exe (Microsoft Corporation) C:\WINDOWS\System32\snmp.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated) HKCU\...\Policies\Explorer: [] MountPoints2: {254e284c-1d8e-11e3-8ec8-001644a11421} - F:\AutoRun.exe MountPoints2: {254e284f-1d8e-11e3-8ec8-001644a11421} - F:\AutoRun.exe HKU\Administrator\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe [ 2009-03-16] (TOSHIBA) HKU\Default User\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe [ 2009-03-16] (TOSHIBA) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation) DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1375365552907 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1375367192236 DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 Chrome: ======= CHR HomePage: hxxp://search.babylon.com/?affID=121845&tt=gc_&babsrc=HP_ss_gin2g&mntrId=2676742F6852480E CHR RestoreOnStartup: "hxxp://www.google.pl/" CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.57\pdf.dll () CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation) CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.)) CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Java(TM) Platform SE 7 U45) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (AdBlock) - C:\DOCUME~1\Adrian\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.14_1 CHR Extension: (Auto HD For YouTube\u2122) - C:\DOCUME~1\Adrian\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak\5.24_1 CHR Extension: (Google Wallet) - C:\DOCUME~1\Adrian\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_1 ========================== Services (Whitelisted) ================= R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.) S3 FlexNet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1064312 2013-10-15] (Flexera Software LLC) R2 HWDeviceService.exe; C:\Documents and Settings\All Users\Dane aplikacji\DatacardService\HWDeviceService.exe [271712 2011-03-14] () S3 LPDSVC; C:\Windows\system32\tcpsvcs.exe [19456 2006-03-02] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2013-07-18] (Microsoft Corporation) R2 nlsvc; D:\NetLimiter 3\nlsvc.exe [1126400 2011-03-21] (Locktime Software) S2 PLAY ONLINE. RunOuc; C:\Program Files\PLAY ONLINE\UpdateDog\ouc.exe [246112 2013-09-14] () R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" ==================== Drivers (Whitelisted) ==================== S3 BrScnUsb; C:\Windows\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.) S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [95616 2013-09-14] (Huawei Technologies Co., Ltd.) S3 huawei_cdcecm; C:\Windows\System32\DRIVERS\ew_jucdcecm.sys [67584 2013-09-14] (Huawei Technologies Co., Ltd.) S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [27520 2013-09-14] (Huawei Technologies Co., Ltd.) S3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [5760 2007-11-06] () R2 Netdevio; C:\Windows\System32\DRIVERS\netdevio.sys [12032 2007-11-06] (TOSHIBA Corporation.) R3 NLNdisMP; C:\Windows\System32\DRIVERS\nlndis.sys [5230088 2011-03-21] (Locktime Software) S3 NLNdisPT; C:\Windows\System32\DRIVERS\nlndis.sys [5230088 2011-03-21] (Locktime Software) R1 nltdi; D:\NetLimiter 3\nltdi.sys [5281672 2011-03-21] (Locktime Software) S3 rtl8139; C:\Windows\System32\DRIVERS\RTL8139.SYS [20992 2004-08-03] (Realtek Semiconductor Corporation) R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [342784 2010-03-31] (Realtek Semiconductor Corporation ) S3 Andbus; system32\DRIVERS\lgandbus.sys [x] S3 AndDiag; system32\DRIVERS\lganddiag.sys [x] S3 AndGps; system32\DRIVERS\lgandgps.sys [x] S3 ANDModem; system32\DRIVERS\lgandmodem.sys [x] S3 androidusb; System32\Drivers\lgandadb.sys [x] U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [245376 2013-09-14] (Huawei Technologies Co., Ltd.) U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [102784 2013-09-14] (Huawei Technologies Co., Ltd.) S4 IntelIde; No ImagePath U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-16 18:49 - 2013-11-16 18:49 - 00010474 _____ C:\Documents and Settings\Adrian\Pulpit\FRST.txt 2013-11-16 18:48 - 2013-11-16 18:48 - 00000000 ____D C:\FRST 2013-11-16 18:45 - 2013-11-16 18:46 - 01090529 _____ (Farbar) C:\Documents and Settings\Adrian\Pulpit\FRST.exe 2013-11-16 18:18 - 2013-11-16 18:18 - 00000784 _____ C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk 2013-11-16 18:18 - 2013-11-16 18:18 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-11-16 18:18 - 2013-11-16 18:18 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes' Anti-Malware 2013-11-16 18:18 - 2013-11-16 18:18 - 00000000 ____D C:\Documents and Settings\Adrian\Dane aplikacji\Malwarebytes 2013-11-16 18:18 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2013-11-16 17:28 - 2013-11-16 17:39 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes' Anti-Malware (portable) 2013-11-16 17:28 - 2013-11-16 17:28 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes 2013-11-16 17:26 - 2013-11-16 18:12 - 00047064 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2013-11-16 17:26 - 2013-11-16 18:12 - 00000000 ____D C:\Documents and Settings\Adrian\Pulpit\mbar 2013-11-16 17:19 - 2013-11-16 18:24 - 00004458 _____ C:\WINDOWS\setupapi.log 2013-11-16 17:17 - 2013-11-16 17:17 - 00181040 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2013-11-16 17:15 - 2013-11-16 17:15 - 00001804 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk 2013-11-16 17:13 - 2013-11-16 17:13 - 00000060 _____ C:\WINDOWS\setupact.log 2013-11-16 17:13 - 2013-11-16 17:13 - 00000000 _____ C:\WINDOWS\setuperr.log 2013-11-16 17:09 - 2013-11-16 17:09 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2013-11-16 17:09 - 2013-11-16 17:09 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2013-11-16 17:09 - 2013-11-16 17:09 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2013-11-16 17:09 - 2013-11-16 17:09 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2013-11-16 17:09 - 2013-11-16 17:09 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2013-11-16 17:09 - 2013-11-16 17:09 - 00000000 ____D C:\Program Files\Common Files\Java 2013-11-16 17:09 - 2013-11-16 17:09 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Java 2013-11-16 16:42 - 2013-11-16 18:33 - 00000406 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job 2013-11-16 16:42 - 2013-11-16 16:43 - 00004705 _____ C:\WINDOWS\system32\jupdate-1.7.0_45-b18.log 2013-11-16 16:28 - 2013-11-16 16:31 - 00000000 ____D C:\AdwCleaner 2013-11-16 16:28 - 2013-11-16 16:28 - 01085542 _____ C:\Documents and Settings\Adrian\Pulpit\AdwCleaner.exe 2013-11-16 16:22 - 2013-11-16 16:22 - 00000000 ____D C:\_OTL 2013-11-16 01:42 - 2013-11-16 01:42 - 00000000 ____D C:\Documents and Settings\Adrian\Moje dokumenty\XenoBot 2013-11-16 01:42 - 2013-11-16 01:42 - 00000000 ____D C:\Documents and Settings\Adrian\Dane aplikacji\MSDrvCfg 2013-11-16 01:39 - 2013-11-16 01:39 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Adrian\Pulpit\OTL.exe 2013-11-16 01:33 - 2013-11-16 16:22 - 00000000 ___HD C:\Documents and Settings\Adrian\Dane aplikacji\SettingsWin 2013-11-16 01:21 - 2013-11-16 01:21 - 00000000 ____D C:\Documents and Settings\Adrian\Dane aplikacji\Win32 2013-11-16 01:19 - 2012-08-30 13:01 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr71.dll 2013-11-16 01:17 - 2013-11-16 01:54 - 00000000 ____D C:\Documents and Settings\Adrian\Menu Start\Programy\Tibia Auto 2013-11-16 01:17 - 2013-08-07 12:13 - 01871872 _____ (Python Software Foundation) C:\WINDOWS\system32\python24.dll 2013-11-16 01:16 - 2013-11-16 01:54 - 00000000 ____D C:\Program Files\Tibia Auto 2013-11-15 23:55 - 2013-11-16 01:53 - 00000000 ____D C:\Program Files\Tibia 2013-11-15 23:55 - 2013-11-15 23:55 - 00000638 _____ C:\Documents and Settings\All Users\Pulpit\Tibia.lnk 2013-11-15 23:55 - 2013-11-15 23:55 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Tibia 2013-11-10 23:27 - 2013-11-10 23:27 - 00000823 _____ C:\Documents and Settings\Adrian\Pulpit\µTorrent.lnk 2013-11-10 23:27 - 2013-11-10 23:27 - 00000823 _____ C:\Documents and Settings\Adrian\Menu Start\µTorrent.lnk 2013-11-08 18:00 - 2013-11-08 18:02 - 00000000 ____D C:\Documents and Settings\Adrian\Pulpit\Wytrzymałość materiałów 2013-11-08 18:00 - 2013-11-08 18:00 - 00000000 ____D C:\Documents and Settings\Adrian\Pulpit\fizyka 2013-11-08 17:59 - 2013-11-08 17:59 - 00000000 ____D C:\Documents and Settings\Adrian\Pulpit\Mechanika Techniczna 2013-10-23 18:25 - 2013-11-14 18:11 - 00000000 ____D C:\Documents and Settings\Adrian\Pulpit\ELektrotechnika ==================== One Month Modified Files and Folders ======= 2013-11-28 13:00 - 2013-08-04 08:08 - 00001917 ____C C:\WINDOWS\epplauncher.mif 2013-11-16 18:49 - 2013-11-16 18:49 - 00010474 _____ C:\Documents and Settings\Adrian\Pulpit\FRST.txt 2013-11-16 18:49 - 2013-08-01 13:23 - 00000000 ____D C:\Documents and Settings\Adrian\Pulpit 2013-11-16 18:48 - 2013-11-16 18:48 - 00000000 ____D C:\FRST 2013-11-16 18:46 - 2013-11-16 18:45 - 01090529 _____ (Farbar) C:\Documents and Settings\Adrian\Pulpit\FRST.exe 2013-11-16 18:39 - 2013-08-02 06:46 - 00000000 ____D C:\WINDOWS\Microsoft.NET 2013-11-16 18:33 - 2013-11-16 16:42 - 00000406 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job 2013-11-16 18:26 - 2013-08-01 13:15 - 01369524 _____ C:\WINDOWS\WindowsUpdate.log 2013-11-16 18:24 - 2013-11-16 17:19 - 00004458 _____ C:\WINDOWS\setupapi.log 2013-11-16 18:23 - 2013-08-25 18:16 - 00000159 _____ C:\WINDOWS\wiadebug.log 2013-11-16 18:23 - 2013-08-25 18:16 - 00000050 _____ C:\WINDOWS\wiaservc.log 2013-11-16 18:23 - 2013-08-01 13:20 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-11-16 18:18 - 2013-11-16 18:18 - 00000784 _____ C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk 2013-11-16 18:18 - 2013-11-16 18:18 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-11-16 18:18 - 2013-11-16 18:18 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes' Anti-Malware 2013-11-16 18:18 - 2013-11-16 18:18 - 00000000 ____D C:\Documents and Settings\Adrian\Dane aplikacji\Malwarebytes 2013-11-16 18:18 - 2013-08-01 15:08 - 00000000 ___RD C:\Documents and Settings\All Users\Menu Start\Programy 2013-11-16 18:18 - 2013-08-01 15:08 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit 2013-11-16 18:12 - 2013-11-16 17:26 - 00047064 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2013-11-16 18:12 - 2013-11-16 17:26 - 00000000 ____D C:\Documents and Settings\Adrian\Pulpit\mbar 2013-11-16 17:39 - 2013-11-16 17:28 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes' Anti-Malware (portable) 2013-11-16 17:28 - 2013-11-16 17:28 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes 2013-11-16 17:28 - 2013-08-01 15:08 - 00000000 __RHD C:\Documents and Settings\All Users\Dane aplikacji 2013-11-16 17:22 - 2013-08-01 13:23 - 00000000 ___HD C:\Documents and Settings\Adrian\Ustawienia lokalne 2013-11-16 17:17 - 2013-11-16 17:17 - 00181040 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2013-11-16 17:16 - 2013-09-26 16:12 - 00065536 _____ C:\WINDOWS\system32\config\NetLimit.evt 2013-11-16 17:16 - 2013-08-01 13:23 - 00000188 ___SH C:\Documents and Settings\Adrian\ntuser.ini 2013-11-16 17:16 - 2013-08-01 13:20 - 00032482 _____ C:\WINDOWS\SchedLgU.Txt 2013-11-16 17:15 - 2013-11-16 17:15 - 00001804 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk 2013-11-16 17:15 - 2013-08-04 08:02 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-11-16 17:15 - 2013-08-04 08:02 - 00000000 ____D C:\Program Files\Adobe 2013-11-16 17:15 - 2013-08-04 08:02 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Adobe 2013-11-16 17:13 - 2013-11-16 17:13 - 00000060 _____ C:\WINDOWS\setupact.log 2013-11-16 17:13 - 2013-11-16 17:13 - 00000000 _____ C:\WINDOWS\setuperr.log 2013-11-16 17:10 - 2013-08-04 08:02 - 00000000 ____D C:\Documents and Settings\Adrian\Ustawienia lokalne\Dane aplikacji\Adobe 2013-11-16 17:09 - 2013-11-16 17:09 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2013-11-16 17:09 - 2013-11-16 17:09 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2013-11-16 17:09 - 2013-11-16 17:09 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2013-11-16 17:09 - 2013-11-16 17:09 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2013-11-16 17:09 - 2013-11-16 17:09 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2013-11-16 17:09 - 2013-11-16 17:09 - 00000000 ____D C:\Program Files\Common Files\Java 2013-11-16 17:09 - 2013-11-16 17:09 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Java 2013-11-16 17:08 - 2013-08-01 16:25 - 00000000 ____D C:\Program Files\Java 2013-11-16 17:05 - 2013-08-01 15:08 - 00000000 ___RD C:\Documents and Settings\All Users\Dokumenty 2013-11-16 16:43 - 2013-11-16 16:42 - 00004705 _____ C:\WINDOWS\system32\jupdate-1.7.0_45-b18.log 2013-11-16 16:37 - 2013-08-01 13:23 - 00000000 ____D C:\Documents and Settings\Adrian 2013-11-16 16:35 - 2013-08-01 13:23 - 00000000 ___HD C:\Documents and Settings\Adrian\Ustawienia lokalne\Dane aplikacji 2013-11-16 16:31 - 2013-11-16 16:28 - 00000000 ____D C:\AdwCleaner 2013-11-16 16:28 - 2013-11-16 16:28 - 01085542 _____ C:\Documents and Settings\Adrian\Pulpit\AdwCleaner.exe 2013-11-16 16:22 - 2013-11-16 16:22 - 00000000 ____D C:\_OTL 2013-11-16 16:22 - 2013-11-16 01:33 - 00000000 ___HD C:\Documents and Settings\Adrian\Dane aplikacji\SettingsWin 2013-11-16 16:22 - 2013-08-01 13:23 - 00000000 __RHD C:\Documents and Settings\Adrian\Dane aplikacji 2013-11-16 01:55 - 2013-08-01 13:20 - 00000188 __SHC C:\Documents and Settings\LocalService\ntuser.ini 2013-11-16 01:54 - 2013-11-16 01:17 - 00000000 ____D C:\Documents and Settings\Adrian\Menu Start\Programy\Tibia Auto 2013-11-16 01:54 - 2013-11-16 01:16 - 00000000 ____D C:\Program Files\Tibia Auto 2013-11-16 01:53 - 2013-11-15 23:55 - 00000000 ____D C:\Program Files\Tibia 2013-11-16 01:53 - 2013-08-09 21:47 - 00000000 ____D C:\Documents and Settings\Adrian\Dane aplikacji\uTorrent 2013-11-16 01:52 - 2013-08-05 08:17 - 00000000 ____D C:\WINDOWS\system32\LogFiles 2013-11-16 01:42 - 2013-11-16 01:42 - 00000000 ____D C:\Documents and Settings\Adrian\Moje dokumenty\XenoBot 2013-11-16 01:42 - 2013-11-16 01:42 - 00000000 ____D C:\Documents and Settings\Adrian\Dane aplikacji\MSDrvCfg 2013-11-16 01:42 - 2013-08-01 13:23 - 00000000 ___RD C:\Documents and Settings\Adrian\Moje dokumenty 2013-11-16 01:41 - 2013-08-01 15:09 - 01240264 ____C C:\WINDOWS\system32\PerfStringBackup.INI 2013-11-16 01:41 - 2006-03-02 13:00 - 00566318 _____ C:\WINDOWS\system32\perfh015.dat 2013-11-16 01:41 - 2006-03-02 13:00 - 00111308 _____ C:\WINDOWS\system32\perfc015.dat 2013-11-16 01:39 - 2013-11-16 01:39 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Adrian\Pulpit\OTL.exe 2013-11-16 01:21 - 2013-11-16 01:21 - 00000000 ____D C:\Documents and Settings\Adrian\Dane aplikacji\Win32 2013-11-16 01:17 - 2013-08-01 13:23 - 00000000 ___RD C:\Documents and Settings\Adrian\Menu Start\Programy 2013-11-16 00:19 - 2013-08-01 16:07 - 00001819 _____ C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk 2013-11-15 23:56 - 2013-08-11 18:18 - 00000000 ____D C:\Documents and Settings\Adrian\Dane aplikacji\Tibia 2013-11-15 23:55 - 2013-11-15 23:55 - 00000638 _____ C:\Documents and Settings\All Users\Pulpit\Tibia.lnk 2013-11-15 23:55 - 2013-11-15 23:55 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Tibia 2013-11-14 18:11 - 2013-10-23 18:25 - 00000000 ____D C:\Documents and Settings\Adrian\Pulpit\ELektrotechnika 2013-11-12 11:23 - 2006-03-02 13:00 - 00002422 _____ C:\WINDOWS\system32\wpa.dbl 2013-11-11 08:45 - 2013-08-11 18:18 - 00002081 _____ C:\Documents and Settings\All Users\Pulpit\Tiberna.exe.lnk 2013-11-10 23:27 - 2013-11-10 23:27 - 00000823 _____ C:\Documents and Settings\Adrian\Pulpit\µTorrent.lnk 2013-11-10 23:27 - 2013-11-10 23:27 - 00000823 _____ C:\Documents and Settings\Adrian\Menu Start\µTorrent.lnk 2013-11-10 23:27 - 2013-08-01 13:23 - 00000000 ___RD C:\Documents and Settings\Adrian\Menu Start 2013-11-10 20:39 - 2013-08-01 22:48 - 00000000 ____D C:\Documents and Settings\Adrian\Dane aplikacji\Media Player Classic 2013-11-08 18:02 - 2013-11-08 18:00 - 00000000 ____D C:\Documents and Settings\Adrian\Pulpit\Wytrzymałość materiałów 2013-11-08 18:00 - 2013-11-08 18:00 - 00000000 ____D C:\Documents and Settings\Adrian\Pulpit\fizyka 2013-11-08 17:59 - 2013-11-08 17:59 - 00000000 ____D C:\Documents and Settings\Adrian\Pulpit\Mechanika Techniczna 2013-11-08 17:59 - 2013-08-26 13:39 - 00000000 ____D C:\Documents and Settings\Adrian\Pulpit\Matma Egzaminy 2013-10-27 12:49 - 2013-08-01 16:15 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat Some content of TEMP: ==================== C:\Documents and Settings\Adrian\Ustawienia lokalne\Temp\install_reader11_pl_mssd_aaa_aih.exe C:\Documents and Settings\Adrian\Ustawienia lokalne\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe [2006-03-02 13:00] - [2008-04-14 21:51] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\Windows\System32\winlogon.exe [2006-03-02 13:00] - [2008-04-14 21:51] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\Windows\System32\svchost.exe [2006-03-02 13:00] - [2008-04-14 21:51] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\Windows\System32\services.exe [2006-03-02 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f C:\Windows\System32\User32.dll [2006-03-02 13:00] - [2008-04-14 21:50] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\Windows\System32\userinit.exe [2006-03-02 13:00] - [2008-04-14 21:51] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\Windows\System32\Drivers\volsnap.sys [2006-03-02 13:00] - [2008-04-14 20:31] - 0052864 ___AC (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================