Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-09-2014 Ran by mb (administrator) on MB-188B048854B8 on 05-09-2014 10:37:37 Running from D:\Pliki załadowane Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (HP) C:\WINDOWS\system32\HPZipm12.exe (StarWind Software) C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe (Microsoft) C:\Program Files\USB 2.0 PC CAMERA\Camera Snap.exe (Hewlett-Packard) D:\Program Files\HP\HP Software Update\hpwuschd2.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Cmaudio] => RunDll32 cmicnfg.cpl,CMICtrlWnd HKLM\...\Run: [Snap] => C:\Program Files\USB 2.0 PC CAMERA\Camera Snap.exe [163840 2011-07-13] (Microsoft) HKLM\...\Run: [HP Software Update] => D:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5188112 2014-08-25] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.) HKU\S-1-5-21-1957994488-1275210071-1547161642-1003\...\Run: [AlcoholAutomount] => C:\Program Files\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) HKU\S-1-5-21-1957994488-1275210071-1547161642-1003\...\Run: [Akamai NetSession Interface] => "C:\Documents and Settings\mb\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe" HKU\S-1-5-21-1957994488-1275210071-1547161642-1003\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Documents and Settings\mb\Dane aplikacji\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=924133cc3f7447d0ba99d1581d9d6ac0-06ce4fc639803a2e3563922518183d8e94088cb9 /CMPID=1213b HKU\S-1-5-21-1957994488-1275210071-1547161642-1003\...\Run: [AQQ] => C:\Program Files\WapSter\WapSter AQQ\AQQ.exe [8565760 2014-04-22] (AQQ Sp. z o.o.) HKU\S-1-5-21-1957994488-1275210071-1547161642-1003\...\Run: [Badoo Desktop] => C:\Documents and Settings\All Users\Dane aplikacji\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe HKU\S-1-5-21-1957994488-1275210071-1547161642-1003\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [21445248 2014-05-08] (Skype Technologies S.A.) Startup: C:\Documents and Settings\mb\Menu Start\Programy\Autostart\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe () ShellIconOverlayIdentifiers: GGDriveOverlay1 -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => C:\Documents and Settings\All Users\Dane aplikacji\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: GGDriveOverlay2 -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => C:\Documents and Settings\All Users\Dane aplikacji\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: GGDriveOverlay3 -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => C:\Documents and Settings\All Users\Dane aplikacji\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: GGDriveOverlay4 -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => C:\Documents and Settings\All Users\Dane aplikacji\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) BootExecute: autocheck autochk * C:\PROGRA~1\AVG\AVG2014\avgrsx.exe /sync /restart ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ SearchScopes: HKCU - {26A6BE4B-B2AC-4018-920D-D7FABADEEFE6} URL = https://www.google.com/search?q={searchTerms} SearchScopes: HKCU - {36B7D707-D522-4D20-8762-483B349F6C38} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=490215B5-23E8-463D-8451-99D04C4B5117&apn_sauid=2D405B27-1C6D-41E4-8D4A-AAE52660F7EB BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @ganymede/GanymedeNetPlugin,version=1.0 -> C:\Program Files\Ganymede\Plugins\npganymedenet.dll ( ) FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npganymedenet.dll ( ) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-10-03] Chrome: ======= CHR DefaultSearchKeyword: Default -> bing.com CHR DefaultSearchProvider: Default -> Bing CHR DefaultSearchURL: Default -> http://www.bing.com/search?setmkt=pl-PL&q={searchTerms} CHR DefaultSuggestURL: Default -> http://api.bing.com/osjson.aspx?query={searchTerms}&language={language} CHR CustomProfile: C:\Documents and Settings\mb\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default CHR Extension: (Dokumenty Google) - C:\Documents and Settings\mb\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-03] CHR Extension: (Dysk Google) - C:\Documents and Settings\mb\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-03] CHR Extension: (YouTube) - C:\Documents and Settings\mb\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-03] CHR Extension: (Szukaj w Google) - C:\Documents and Settings\mb\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-03] CHR Extension: (Google Wallet) - C:\Documents and Settings\mb\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-03] CHR Extension: (Gmail) - C:\Documents and Settings\mb\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-03] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [520192 2006-05-03] () [File not signed] R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3242000 2014-08-25] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-08-25] (AVG Technologies CZ, s.r.o.) S2 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-08-30] (Oracle Corporation) R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed] S2 vToolbarUpdater18.1.9; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [121624 2014-06-30] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriverl; C:\WINDOWS\System32\DRIVERS\avgidsdriverlx.sys [191256 2014-07-21] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\WINDOWS\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [188696 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [98584 2014-08-06] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\WINDOWS\System32\DRIVERS\avgtdix.sys [197400 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [42784 2014-08-12] (AVG Technologies) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation) R3 cmuda; C:\WINDOWS\System32\drivers\cmuda.sys [818496 2004-04-23] (C-Media Inc) R3 FETNDIS; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [27165 2001-08-17] (VIA Technologies, Inc. ) S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49664 2005-10-28] (HP) S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2005-10-28] (HP) S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2005-10-28] (HP) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation) R0 Si3112; C:\WINDOWS\system32\Drivers\Si3112.sys [62336 2010-01-22] (Silicon Image, Inc.) [File not signed] S0 Si3114r5; C:\WINDOWS\system32\Drivers\Si3114r5.sys [195072 2010-01-22] (Silicon Image, Inc) [File not signed] R0 Si3124; C:\WINDOWS\system32\Drivers\Si3124.sys [69248 2010-01-22] (Silicon Image, Inc.) [File not signed] R0 Si3132; C:\WINDOWS\system32\Drivers\Si3132.sys [74672 2010-01-22] (Silicon Image, Inc.) R0 Si3132r5; C:\WINDOWS\system32\Drivers\Si3132r5.sys [215856 2010-01-22] (Silicon Image, Inc) R0 Si3531; C:\WINDOWS\system32\Drivers\Si3531.sys [212520 2010-01-22] (Silicon Image, Inc) R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [477240 2012-10-07] (Duplex Secure Ltd.) S3 usbcamcl; C:\WINDOWS\System32\DRIVERS\usbcamcl.sys [38784 2011-11-25] (usb camera) R0 viamraid; C:\WINDOWS\System32\DRIVERS\viamraid.sys [117248 2010-01-22] (VIA Technologies inc,.ltd) U3 aemhvlic; C:\WINDOWS\system32\Drivers\aemhvlic.sys [0 ] (Silicon Image, Inc) S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [X] S4 IntelIde; No ImagePath U1 WS2IFSL; No ImagePath ========================== Drivers MD5 ======================= C:\WINDOWS\System32\DRIVERS\ACPI.sys 05118282F5D039595A2B92B4A4AFE197 C:\WINDOWS\system32\Drivers\ACPIEC.sys 66A42B7DB194E24B973BBCCE840A0F3F C:\WINDOWS\System32\drivers\aec.sys 8BED39E3C35D6A489438B8141717A557 C:\WINDOWS\System32\drivers\afd.sys D80ED631D3AFD47C27311B0614AFA89F C:\WINDOWS\System32\DRIVERS\amdk7.sys 6F41705041A671FEB1FC8CFBADBB90CA C:\WINDOWS\System32\DRIVERS\asyncmac.sys B153AFFAC761E7F5FCFA822B9C4E97BC C:\WINDOWS\System32\DRIVERS\atapi.sys 9F3A2F5AA6875C72BF062C712CFA2674 C:\WINDOWS\System32\DRIVERS\ati2mtag.sys 492BD2A5F65F218D4EDE5764A3BB67E9 C:\WINDOWS\System32\DRIVERS\atmarpc.sys 9916C1225104BA14794209CFA8012159 C:\WINDOWS\System32\DRIVERS\audstub.sys D9F724AA26C010A217C97606B160ED68 C:\WINDOWS\System32\DRIVERS\avgdiskx.sys 21C2F3000A7233E517D7AB62F97BF509 C:\WINDOWS\System32\DRIVERS\avgidsdriverlx.sys DE1A454BBD7F43F9DF628F51C39BFD6C C:\WINDOWS\System32\DRIVERS\avgidshx.sys C0701A3C53F0A0F5E4900F26365A10A1 C:\WINDOWS\System32\DRIVERS\avgidsshimx.sys E7FEE532CEF01C97D7682E35D156244F C:\WINDOWS\System32\DRIVERS\avgldx86.sys FA868D5784DE755DD8A1B4B1A80574E4 C:\WINDOWS\System32\DRIVERS\avglogx.sys 8D37558421330218C98722DF4AD85E83 C:\WINDOWS\System32\DRIVERS\avgmfx86.sys 3AC9661AB1624F322B20844DDE8EBC14 C:\WINDOWS\System32\DRIVERS\avgrkx86.sys 86FCB8CE3E68C4777B98F7AF06FE8519 C:\WINDOWS\System32\DRIVERS\avgtdix.sys ACFEE559442E1FCD48EC74C7D3452608 C:\WINDOWS\system32\drivers\avgtpx86.sys D15D2E9F5567075740B88F16F01810D6 C:\WINDOWS\system32\Drivers\Beep.sys DA1F27D85E0D1525F6621372E7B685E9 C:\WINDOWS\system32\Drivers\cbidf2k.sys 90A673FC8E12A79AFBED2576F6A7AAF9 C:\WINDOWS\System32\DRIVERS\CCDECODE.sys 0BE5AEF125BE881C4F854C554F2B025C C:\WINDOWS\system32\Drivers\Cdaudio.sys C1B486A7658353D33A10CC15211A873B C:\WINDOWS\system32\Drivers\Cdfs.sys C885B02847F5D2FD45A24E219ED93B32 C:\WINDOWS\System32\DRIVERS\cdrom.sys 1F4260CC5B42272D71F79E570A27A4FE C:\WINDOWS\System32\drivers\cmuda.sys 5A2004F687D4E55914E6E8898FB51C9D C:\WINDOWS\System32\DRIVERS\disk.sys 044452051F3E02E7963599FC8F4F3E25 C:\WINDOWS\System32\drivers\dmboot.sys BC9219ABC5696942E6F9AC8A9B28670F C:\WINDOWS\System32\drivers\dmio.sys 5FA232E3BA6E1346F9F5A7E519320CB0 C:\WINDOWS\System32\drivers\dmload.sys E9317282A63CA4D188C0DF5E09C6AC5F C:\WINDOWS\System32\drivers\DMusic.sys 8A208DFCF89792A484E76C40E5F50B45 C:\WINDOWS\System32\drivers\drmkaud.sys 8F5FCFF8E8848AFAC920905FBD9D33C8 C:\WINDOWS\system32\Drivers\Fastfat.sys 38D332A6D56AF32635675F132548343E C:\WINDOWS\System32\DRIVERS\fdc.sys 92CDD60B6730B9F50F6A1A0C1F8CDC81 C:\WINDOWS\System32\DRIVERS\fetnd5.sys E9648254056BCE81A85380C0C3647DC4 C:\WINDOWS\system32\Drivers\Fips.sys 09E2A4D33F81A06A8AAB2BA0A0B5D235 C:\WINDOWS\System32\DRIVERS\flpydisk.sys 9D27E7B80BFCDF1CDD9B555862D5E7F0 C:\WINDOWS\System32\DRIVERS\fltMgr.sys B2CF4B0786F8212CB92ED2B50C6DB6B0 C:\WINDOWS\system32\Drivers\Fs_Rec.sys 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A C:\WINDOWS\System32\DRIVERS\ftdisk.sys ED6D921D8AB423138FB35BEEE6D6A6CB C:\WINDOWS\System32\DRIVERS\msgpc.sys 0A02C63C8B144BD8C86B103DEE7C86A2 C:\WINDOWS\System32\DRIVERS\hidusb.sys CCF82C5EC8A7326C3066DE870C06DAF1 C:\WINDOWS\System32\DRIVERS\HPZid412.sys 30CA91E657CEDE2F95359D6EF186F650 C:\WINDOWS\System32\DRIVERS\HPZipr12.sys EFD31AFA752AA7C7BBB57BCBE2B01C78 C:\WINDOWS\System32\DRIVERS\HPZius12.sys 7AC43C38CA8FD7ED0B0A4466F753E06E C:\WINDOWS\System32\Drivers\HTTP.sys 937031C085718C1C04A9C0864625EC6B C:\WINDOWS\System32\DRIVERS\i8042prt.sys 177B372AF55C4460D0968B5F1D02AA1C C:\WINDOWS\System32\DRIVERS\imapi.sys 083A052659F5310DD8B6A6CB05EDCF8E C:\WINDOWS\System32\DRIVERS\Ip6Fw.sys 3BB22519A194418D5FEC05D800A19AD0 C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys 731F22BA402EE4B62748ADAF6363C182 C:\WINDOWS\System32\DRIVERS\ipinip.sys B87AB476DCF76E72010632B5550955F5 C:\WINDOWS\System32\DRIVERS\ipnat.sys CC748EA12C6EFFDE940EE98098BF96BB C:\WINDOWS\System32\DRIVERS\ipsec.sys 23C74D75E36E7158768DD63D92789A91 C:\WINDOWS\System32\DRIVERS\irenum.sys C93C9FF7B04D772627A3646D89F7BF89 C:\WINDOWS\System32\DRIVERS\isapnp.sys C8EEF2E93835B81BD335DE2123121283 C:\WINDOWS\System32\DRIVERS\kbdclass.sys 2AECA45D4AEAACBDCB77AD11184E4601 C:\WINDOWS\System32\drivers\kmixer.sys 692BCF44383D056AED41B045A323D378 C:\WINDOWS\system32\Drivers\KSecDD.sys C6EBF1D6AD71DF30DB49B8D3287E1368 C:\WINDOWS\system32\Drivers\mnmdd.sys 4AE068242760A1FB6E1A44BF4E16AFA6 C:\WINDOWS\system32\Drivers\Modem.sys 4A068DB7DC37D5AFEDB6512D2931D7B3 C:\WINDOWS\System32\DRIVERS\mouclass.sys FBED3DF6B884F8CF00447B73507F2C48 C:\WINDOWS\System32\DRIVERS\mouhid.sys ECEC1E6CD558AB80F944F31326E9D3B5 C:\WINDOWS\system32\Drivers\MountMgr.sys A80B9A0BAD1B73637DBCBBA7DF72D3FD C:\WINDOWS\System32\DRIVERS\mrxdav.sys 11D42BB6206F33FBB3BA0288D3EF81BD C:\WINDOWS\System32\DRIVERS\mrxsmb.sys FB2FCCC70F7174C7BF64F48E96D3ADF4 C:\WINDOWS\system32\Drivers\Msfs.sys C941EA2454BA8350021D774DAF0F1027 C:\WINDOWS\System32\drivers\MSKSSRV.sys D1575E71568F4D9E14CA56B7B0453BF1 C:\WINDOWS\System32\drivers\MSPCLOCK.sys 325BB26842FC7CCC1FCCE2C457317F3E C:\WINDOWS\System32\drivers\MSPQM.sys BAD59648BA099DA4A17680B39730CB3D C:\WINDOWS\System32\DRIVERS\mssmbios.sys AF5F4F3F14A8EA2C26DE30F7A1E17136 C:\WINDOWS\System32\drivers\MSTEE.sys E53736A9E30C45FA9E7B5EAC55056D1D C:\WINDOWS\system32\Drivers\Mup.sys DE6A75F5C270E756C5508D94B6CF68F5 C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys 5B50F1B2A2ED47D560577B221DA734DB C:\WINDOWS\system32\Drivers\NDIS.sys 1DF7F42665C94B825322FAE71721130D C:\WINDOWS\System32\DRIVERS\NdisIP.sys 7FF1F1FD8609C149AA432F95A8163D97 C:\WINDOWS\System32\DRIVERS\ndistapi.sys 0109C4F3850DFBAB279542515386AE22 C:\WINDOWS\System32\DRIVERS\ndisuio.sys F927A4434C5028758A842943EF1A3849 C:\WINDOWS\System32\DRIVERS\ndiswan.sys EDC1531A49C80614B2CFDA43CA8659AB C:\WINDOWS\system32\Drivers\NDProxy.sys 2F597BB467E05B1FE3830EABD821B8E0 C:\WINDOWS\System32\DRIVERS\netbios.sys 5D81CF9A2F1A3A756B66CF684911CDF0 C:\WINDOWS\System32\DRIVERS\netbt.sys 74B2B2F5BEA5E9A3DC021D685551BD3D C:\WINDOWS\system32\Drivers\Npfs.sys 3182D64AE053D6FB034F44B6DEF8034A C:\WINDOWS\system32\Drivers\Ntfs.sys 78A08DD6A8D65E697C18E1DB01C5CDCA C:\WINDOWS\system32\Drivers\Null.sys 73C1E1F395918BC2C6DD67AF7591A3AD C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys B305F3FAD35083837EF46A0BBCE2FC57 C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys C99B3415198D1AAB7227F2C88FD664B9 C:\WINDOWS\System32\DRIVERS\parport.sys 2D4CDAEBCED17743AA9E25D3016DC229 C:\WINDOWS\system32\Drivers\PartMgr.sys BEB3BA25197665D82EC7065B724171C6 C:\WINDOWS\system32\Drivers\ParVdm.sys 453EC2C2A20A1382F564541918520EEB C:\WINDOWS\System32\DRIVERS\pci.sys 6862C69168D787B85A7D95CCD33C694E C:\WINDOWS\system32\Drivers\Pcmcia.sys 8DB27F1AE9593C94095485305A583862 C:\WINDOWS\System32\DRIVERS\raspptp.sys EFEEC01B1D3CF84F16DDD24D9D9D8F99 C:\WINDOWS\System32\DRIVERS\psched.sys 09298EC810B07E5D582CB3A3F9255424 C:\WINDOWS\System32\DRIVERS\ptilink.sys 80D317BD1C3DBC5D4FE7B1678C60CADD C:\WINDOWS\System32\DRIVERS\rasacd.sys FE0D99D6F31E4FAD8159F690D68DED9C C:\WINDOWS\System32\DRIVERS\rasl2tp.sys 11B4A627BC9614B885C4969BFA5FF8A6 C:\WINDOWS\System32\DRIVERS\raspppoe.sys 5BC962F2654137C9909C3D4603587DEE C:\WINDOWS\System32\DRIVERS\raspti.sys FDBB1D60066FCFBB7452FD8F9829B242 C:\WINDOWS\System32\DRIVERS\rdbss.sys 7AD224AD1A1437FE28D89CF22B17780A C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 4912D5B403614CE99C28420F75353332 C:\WINDOWS\System32\DRIVERS\rdpdr.sys 15CABD0F7C00C47C70124907916AF3F1 C:\WINDOWS\system32\Drivers\RDPWD.sys 43AF5212BD8FB5BA6EED9754358BD8F7 C:\WINDOWS\System32\DRIVERS\redbook.sys E0C7BBD18040B58651BAC700C804861D C:\WINDOWS\System32\DRIVERS\secdrv.sys ==> MD5 is legit C:\WINDOWS\System32\DRIVERS\serenum.sys 0F29512CCD6BEAD730039FB4BD2C85CE C:\WINDOWS\System32\DRIVERS\serial.sys D07B02F88165E69B9F17162CF592C8A6 C:\WINDOWS\system32\Drivers\Sfloppy.sys 8E6B8C671615D126FDC553D1E2DE5562 C:\WINDOWS\system32\Drivers\Si3112.sys C17EAD2A29695916EBA59CEC1F7F96A0 C:\WINDOWS\system32\Drivers\Si3114r5.sys 62B429C87ED5D3655B70D574D31B807B C:\WINDOWS\system32\Drivers\Si3124.sys AAAA385FFBAAF3FD89F8CE26FF0D0751 C:\WINDOWS\system32\Drivers\Si3132.sys 4CDAF939DF995B0EEFD91E069BFDA30D C:\WINDOWS\system32\Drivers\Si3132r5.sys 0A5DF632416FDFA8A265F6CA2B80F23B C:\WINDOWS\system32\Drivers\Si3531.sys 93BEACC3815A4653A655C8BD7622FF63 C:\WINDOWS\System32\DRIVERS\SLIP.sys 866D538EBE33709A5C9F5C62B73B7D14 C:\WINDOWS\System32\drivers\splitter.sys AB8B92451ECB048A4D1DE7C3FFCB4A9F C:\WINDOWS\System32\Drivers\sptd.sys 0022CFFF1A41E5CE3A764050A7DDF22A C:\WINDOWS\System32\DRIVERS\sr.sys EB032822BE406EF220D546DDFFCF0002 C:\WINDOWS\System32\DRIVERS\srv.sys 9B390283569EA58D43D2586032B892F5 C:\WINDOWS\System32\DRIVERS\StreamIP.sys 77813007BA6265C4B6098187E6ED79D2 C:\WINDOWS\System32\DRIVERS\swenum.sys 3941D127AEF12E93ADDF6FE6EE027E0F C:\WINDOWS\System32\drivers\swmidi.sys 8CE882BCC6CF8A62F2B2323D95CB3D01 C:\WINDOWS\System32\drivers\sysaudio.sys 8B83F3ED0F1688B4958F77CD6D2BF290 C:\WINDOWS\System32\DRIVERS\tcpip.sys AD978A1B783B5719720CFF204B666C8E C:\WINDOWS\system32\Drivers\TDPIPE.sys 6471A66807F5E104E4885F5B67349397 C:\WINDOWS\system32\Drivers\TDTCP.sys C56B6D0402371CF3700EB322EF3AAF61 C:\WINDOWS\System32\DRIVERS\termdd.sys 88155247177638048422893737429D9E C:\WINDOWS\System32\DRIVERS\uagp35.sys D85938F272D1BCF3DB3A31FC0A048928 C:\WINDOWS\system32\Drivers\Udfs.sys 5787B80C2E3C5E2F56C2A233D91FA2C9 C:\WINDOWS\System32\DRIVERS\update.sys 402DDC88356B1BAC0EE3DD1580C76A31 C:\WINDOWS\System32\drivers\usbaudio.sys 65898A183FBF1D1F7759D5CCB364DCD4 C:\WINDOWS\System32\DRIVERS\usbcamcl.sys C246C29816DC42DD2828F1582FD446C7 C:\WINDOWS\System32\DRIVERS\usbccgp.sys 1B611611C28D2DF25BC057D79C6F13FC C:\WINDOWS\System32\DRIVERS\usbehci.sys 4BAC8DF07F1D8434FC640E677A62204E C:\WINDOWS\System32\DRIVERS\usbhub.sys 1AB3CDDE553B6E064D2E754EFE20285C C:\WINDOWS\System32\DRIVERS\usbprint.sys A717C8721046828520C9EDF31288FC00 C:\WINDOWS\System32\DRIVERS\usbscan.sys F8EDE2B6928970DCE3D5614C27D9E7F6 C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS A32426D9B14A089EAA1D922E0C5801A9 C:\WINDOWS\System32\DRIVERS\usbuhci.sys 26496F9DEE2D787FC3E61AD54821FFE6 C:\WINDOWS\System32\Drivers\usbvideo.sys 813236B1183CFCF289E367BD5DE6E29E C:\WINDOWS\System32\drivers\vga.sys 0D3A8FAFCEACD8B7625CD549757A7DF1 C:\WINDOWS\System32\DRIVERS\viaide.sys 3B3EFCDA263B8AC14FDF9CBDD0791B2E C:\WINDOWS\System32\DRIVERS\viamraid.sys 00046AA2E396EDC2238556E740A8E5AF C:\WINDOWS\system32\Drivers\VolSnap.sys 56B191AC5FC0DF219949C95A6C87AFE7 C:\WINDOWS\System32\DRIVERS\wanarp.sys E20B95BAEDB550F32DD489265C1DA1F6 C:\WINDOWS\System32\drivers\wdmaud.sys 6768ACF64B18196494413695F0C3A00F C:\WINDOWS\System32\DRIVERS\wpdusb.sys CF4DEF1BF66F06964DC0D91844239104 C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS C98B39829C2BBD34E454150633C62C78 C:\WINDOWS\System32\DRIVERS\WudfPf.sys F15FEAFFFBB3644CCC80C5DA584E6311 C:\WINDOWS\System32\DRIVERS\wudfrd.sys 28B524262BCE6DE1F7EF9F510BA3985B C:\WINDOWS\system32\Drivers\aemhvlic.sys ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-30 18:00 - 2014-08-30 18:00 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2014-08-30 18:00 - 2014-08-30 18:00 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2014-08-30 18:00 - 2014-08-30 18:00 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2014-08-30 18:00 - 2014-08-30 18:00 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2014-08-30 18:00 - 2014-08-30 18:00 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2014-08-30 18:00 - 2014-08-30 18:00 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-08-30 18:00 - 2014-08-30 18:00 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Java 2014-08-28 18:55 - 2014-08-28 18:55 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2993651$ 2014-08-28 18:52 - 2014-08-28 18:52 - 00098304 _____ () C:\WINDOWS\Minidump\Mini082814-01.dmp 2014-08-28 14:58 - 2014-08-28 18:55 - 00020956 _____ () C:\WINDOWS\KB2993651.log 2014-08-26 20:11 - 2014-08-26 20:11 - 00010240 ___SH () C:\Documents and Settings\mb\Moje dokumenty\Thumbs.db 2014-08-26 09:59 - 2014-08-27 14:53 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Avg_Update_0814tb 2014-08-25 21:02 - 2014-08-25 21:02 - 00015173 _____ () C:\Documents and Settings\mb\Moje dokumenty\Bez tytułu 1.odt 2014-08-24 20:30 - 2014-08-24 20:30 - 00000673 _____ () C:\Documents and Settings\mb\Pulpit\8cars.lnk 2014-08-16 14:33 - 2014-08-16 14:34 - 00017710 _____ () C:\WINDOWS\KB2976627-IE8.log 2014-08-16 14:33 - 2014-08-16 14:33 - 00010723 _____ () C:\WINDOWS\KB2961072.log 2014-08-16 14:33 - 2014-08-16 14:33 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2961072$ 2014-08-16 14:32 - 2014-08-16 14:32 - 00009944 _____ () C:\WINDOWS\KB2957503.log 2014-08-16 14:32 - 2014-08-16 14:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2957509$ 2014-08-16 14:32 - 2014-08-16 14:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2957503$ 2014-08-16 14:32 - 2014-08-16 14:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2939576$ 2014-08-16 14:32 - 2014-08-16 14:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2926765$ 2014-08-16 14:31 - 2014-08-16 14:31 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2981580$ 2014-08-16 12:53 - 2014-08-16 14:33 - 00020373 _____ () C:\WINDOWS\KB2957509.log 2014-08-16 12:53 - 2014-08-16 14:32 - 00019822 _____ () C:\WINDOWS\KB2926765.log 2014-08-16 12:53 - 2014-08-16 14:32 - 00019751 _____ () C:\WINDOWS\KB2939576.log 2014-08-15 13:16 - 2014-05-24 11:37 - 00000108 _____ () C:\Documents and Settings\mb\Pulpit\xp-security-updates.reg 2014-08-15 13:14 - 2014-08-15 13:14 - 00000288 _____ () C:\Documents and Settings\mb\Pulpit\xp-security-updates.zip ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-05 10:38 - 2012-09-28 14:45 - 00000000 ____D () C:\Documents and Settings\mb\Ustawienia lokalne\Temp 2014-09-05 10:37 - 2014-06-03 13:31 - 00000000 ____D () C:\FRST 2014-09-05 10:34 - 2012-10-02 18:27 - 01124884 _____ () C:\WINDOWS\KB2481109.log 2014-09-05 10:34 - 2012-09-28 14:33 - 01219058 _____ () C:\WINDOWS\WindowsUpdate.log 2014-09-05 10:33 - 2014-03-27 11:51 - 00000216 _____ () C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job 2014-09-05 10:33 - 2013-10-16 18:57 - 00001024 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-09-05 10:33 - 2012-10-05 20:05 - 00000000 ____D () C:\Documents and Settings\mb\Dane aplikacji\Skype 2014-09-05 10:31 - 2012-09-28 16:21 - 00000157 _____ () C:\WINDOWS\wiadebug.log 2014-09-05 10:31 - 2012-09-28 16:21 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-09-05 10:31 - 2012-09-28 14:40 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-09-05 09:11 - 2012-09-28 14:45 - 00000188 ___SH () C:\Documents and Settings\mb\ntuser.ini 2014-09-05 09:11 - 2012-09-28 14:40 - 00032636 _____ () C:\WINDOWS\SchedLgU.Txt 2014-09-05 08:56 - 2012-10-05 17:52 - 00000930 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-09-05 08:47 - 2013-10-16 18:57 - 00001028 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-09-05 08:31 - 2012-09-28 15:06 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\MFAData 2014-09-04 13:14 - 2012-11-24 11:10 - 00172822 _____ () C:\WINDOWS\setupapi.log 2014-09-04 12:58 - 2012-09-28 14:45 - 00000000 ____D () C:\Documents and Settings\mb\Pulpit 2014-09-04 12:13 - 2014-01-27 01:56 - 00000000 ____D () C:\Documents and Settings\mb\Pulpit\Nowy folder 2014-09-04 12:13 - 2012-12-28 16:09 - 00000000 ____D () C:\Documents and Settings\mb\Pulpit\Nieużywane skróty pulpitu 2014-09-04 11:37 - 2010-01-22 00:47 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl 2014-09-03 17:45 - 2012-09-28 16:17 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji 2014-09-03 17:45 - 2012-09-28 14:45 - 00000000 __RHD () C:\Documents and Settings\mb\Dane aplikacji 2014-09-03 17:43 - 2012-09-28 14:45 - 00000000 ___HD () C:\Documents and Settings\mb\Ustawienia lokalne\Dane aplikacji 2014-09-02 10:42 - 2012-11-07 18:15 - 01114042 ___SH () C:\Documents and Settings\mb\Pulpit\Thumbs.db 2014-08-30 18:00 - 2014-08-30 18:00 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2014-08-30 18:00 - 2014-08-30 18:00 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2014-08-30 18:00 - 2014-08-30 18:00 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2014-08-30 18:00 - 2014-08-30 18:00 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2014-08-30 18:00 - 2014-08-30 18:00 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2014-08-30 18:00 - 2014-08-30 18:00 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-08-30 18:00 - 2014-08-30 18:00 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Java 2014-08-30 18:00 - 2013-06-24 09:24 - 00000000 ____D () C:\Program Files\Java 2014-08-30 18:00 - 2012-09-28 16:18 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy 2014-08-29 14:05 - 2012-09-28 16:17 - 00131688 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-08-28 21:05 - 2012-09-28 14:45 - 00000000 ____D () C:\Documents and Settings\mb 2014-08-28 18:55 - 2014-08-28 18:55 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2993651$ 2014-08-28 18:55 - 2014-08-28 14:58 - 00020956 _____ () C:\WINDOWS\KB2993651.log 2014-08-28 18:55 - 2014-04-19 15:22 - 00000000 ____D () C:\WINDOWS\system32\cache 2014-08-28 18:55 - 2012-10-02 18:37 - 00082440 _____ () C:\WINDOWS\updspapi.log 2014-08-28 18:55 - 2012-09-28 16:19 - 01149627 _____ () C:\WINDOWS\iis6.log 2014-08-28 18:55 - 2012-09-28 16:19 - 01026108 _____ () C:\WINDOWS\FaxSetup.log 2014-08-28 18:55 - 2012-09-28 16:19 - 00599107 _____ () C:\WINDOWS\ocgen.log 2014-08-28 18:55 - 2012-09-28 16:19 - 00476559 _____ () C:\WINDOWS\tsoc.log 2014-08-28 18:55 - 2012-09-28 16:19 - 00352241 _____ () C:\WINDOWS\comsetup.log 2014-08-28 18:55 - 2012-09-28 16:19 - 00327876 _____ () C:\WINDOWS\msmqinst.log 2014-08-28 18:55 - 2012-09-28 16:19 - 00212254 _____ () C:\WINDOWS\ntdtcsetup.log 2014-08-28 18:55 - 2012-09-28 16:19 - 00180911 _____ () C:\WINDOWS\netfxocm.log 2014-08-28 18:55 - 2012-09-28 16:19 - 00071481 _____ () C:\WINDOWS\MedCtrOC.log 2014-08-28 18:55 - 2012-09-28 16:19 - 00064272 _____ () C:\WINDOWS\ocmsn.log 2014-08-28 18:55 - 2012-09-28 16:19 - 00053576 _____ () C:\WINDOWS\tabletoc.log 2014-08-28 18:55 - 2012-09-28 16:19 - 00051717 _____ () C:\WINDOWS\msgsocm.log 2014-08-28 18:55 - 2012-09-28 16:19 - 00001374 _____ () C:\WINDOWS\imsins.log 2014-08-28 18:52 - 2014-08-28 18:52 - 00098304 _____ () C:\WINDOWS\Minidump\Mini082814-01.dmp 2014-08-28 18:52 - 2012-11-24 01:37 - 00000000 ____D () C:\WINDOWS\Minidump 2014-08-27 14:53 - 2014-08-26 09:59 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Avg_Update_0814tb 2014-08-26 20:11 - 2014-08-26 20:11 - 00010240 ___SH () C:\Documents and Settings\mb\Moje dokumenty\Thumbs.db 2014-08-26 20:11 - 2012-09-28 14:45 - 00000000 ___RD () C:\Documents and Settings\mb\Moje dokumenty 2014-08-25 21:02 - 2014-08-25 21:02 - 00015173 _____ () C:\Documents and Settings\mb\Moje dokumenty\Bez tytułu 1.odt 2014-08-24 20:30 - 2014-08-24 20:30 - 00000673 _____ () C:\Documents and Settings\mb\Pulpit\8cars.lnk 2014-08-23 03:12 - 2010-01-22 00:47 - 00287744 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\gdi32.dll 2014-08-23 03:12 - 2010-01-22 00:47 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2014-08-23 03:02 - 2010-01-22 00:47 - 01881728 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\win32k.sys 2014-08-23 03:02 - 2010-01-22 00:47 - 01881728 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2014-08-17 15:22 - 2012-10-02 20:55 - 00000000 ____D () C:\WINDOWS\Microsoft.NET 2014-08-16 14:34 - 2014-08-16 14:33 - 00017710 _____ () C:\WINDOWS\KB2976627-IE8.log 2014-08-16 14:34 - 2012-10-02 18:38 - 00000000 ____D () C:\WINDOWS\ie8updates 2014-08-16 14:34 - 2012-09-28 16:19 - 00001374 _____ () C:\WINDOWS\imsins.BAK 2014-08-16 14:33 - 2014-08-16 14:33 - 00010723 _____ () C:\WINDOWS\KB2961072.log 2014-08-16 14:33 - 2014-08-16 14:33 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2961072$ 2014-08-16 14:33 - 2014-08-16 12:53 - 00020373 _____ () C:\WINDOWS\KB2957509.log 2014-08-16 14:32 - 2014-08-16 14:32 - 00009944 _____ () C:\WINDOWS\KB2957503.log 2014-08-16 14:32 - 2014-08-16 14:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2957509$ 2014-08-16 14:32 - 2014-08-16 14:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2957503$ 2014-08-16 14:32 - 2014-08-16 14:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2939576$ 2014-08-16 14:32 - 2014-08-16 14:32 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2926765$ 2014-08-16 14:32 - 2014-08-16 12:53 - 00019822 _____ () C:\WINDOWS\KB2926765.log 2014-08-16 14:32 - 2014-08-16 12:53 - 00019751 _____ () C:\WINDOWS\KB2939576.log 2014-08-16 14:31 - 2014-08-16 14:31 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB2981580$ 2014-08-16 14:31 - 2012-09-28 14:35 - 00041016 _____ () C:\WINDOWS\system32\TZLog.log 2014-08-16 14:29 - 2012-09-28 16:19 - 01071128 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-08-16 14:29 - 2010-01-22 00:47 - 00500074 _____ () C:\WINDOWS\system32\perfh015.dat 2014-08-16 14:29 - 2010-01-22 00:47 - 00089380 _____ () C:\WINDOWS\system32\perfc015.dat 2014-08-15 13:31 - 2013-08-14 16:54 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-08-15 13:20 - 2012-10-02 18:44 - 96303304 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-08-15 13:14 - 2014-08-15 13:14 - 00000288 _____ () C:\Documents and Settings\mb\Pulpit\xp-security-updates.zip 2014-08-12 17:43 - 2014-04-19 15:23 - 00042784 _____ (AVG Technologies) C:\WINDOWS\system32\Drivers\avgtpx86.sys 2014-08-06 10:49 - 2011-12-23 13:32 - 00098584 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx86.sys Files to move or delete: ==================== C:\Documents and Settings\mb\jagex_cl_runescape_LIVE.dat C:\Documents and Settings\mb\random.dat Some content of TEMP: ==================== C:\Documents and Settings\mb\Ustawienia lokalne\Temp\536.9558118013571_Update.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\APNStub.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\AutoRun.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\AutoRunGUI.dll C:\Documents and Settings\mb\Ustawienia lokalne\Temp\gdinstall4091.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\ggdrive-menu.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\ggdrive-overlay.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\hpzmsi01.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\hpzscr01.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\ICReinstall_gta-iv-san-andreas.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\installstats.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\jre-7u11-windows-i586-iftw.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\jre-7u13-windows-i586-iftw.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\jre-7u15-windows-i586-iftw.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\jre-7u17-windows-i586-iftw.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\jre-7u25-windows-i586-iftw.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\jre-7u45-windows-i586-iftw.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\jre-7u51-windows-i586-iftw.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\jre-7u55-windows-i586-iftw.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\jre-7u65-windows-i586-iftw.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\jre-7u67-windows-i586-iftw.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\MyBabylonTB.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\OptimizerPro.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\pl_ww_Package.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\Quarantine.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\SkypeSetup.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\Super_Bros_3_Mario_Forever.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\uninst1.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\UpdateCheckerSetup.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\YontooSetup-S.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\{06EBCCEB-4BBF-436F-BFDA-2AA8D8E21FE8}-32.0.1700.76_31.0.1650.63_chrome_updater.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\{AB7EFDB0-4EF9-425A-BE3E-13036F050722}-33.0.1750.117_chrome_installer.exe C:\Documents and Settings\mb\Ustawienia lokalne\Temp\{E5F8F8E9-6EFF-4045-87C8-A76AFDFC0910}-33.0.1750.117_chrome_installer.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================