Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-09-2014 Ran by GOSIA (administrator) on YOUR-89F46DCB53 on 19-09-2014 12:01:57 Running from E:\FIXlog Platform: Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Check Point Software Technologies) C:\Program Files\CheckPoint\SSL Network Extender\slimsvc.exe () C:\Program Files\eMPendium\eMPendiumService.exe () C:\WINDOWS\system32\dmwu.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (Nero AG) C:\Program Files\Nero\Update\NASvc.exe () C:\Program Files\Samsung\Samsung Network Manager\SNMWLANService.exe (Atheros) C:\Program Files\Bluetooth XP Suite\Ath_CoexAgent.exe () C:\WINDOWS\system32\mjcm\dnkt.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE (Samsung Electronics,.LTD) C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe () C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe (Ask) C:\Program Files\Ask.com\Updater\Updater.exe (SweetIM Technologies Ltd.) C:\Program Files\SweetIM\Messenger\SweetIM.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe (SweetIM Technologies Ltd.) C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe (Atheros Commnucations) C:\Program Files\Bluetooth XP Suite\BluetoothSuit.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (SAMSUNG Electronics Co., Ltd.) C:\Program Files\Samsung\MagicKBD\MagicKBD.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\MagicKBD\PerformanceManager.exe (Intel Corporation) C:\WINDOWS\system32\igfxext.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [16851456 2008-08-26] (Realtek Semiconductor Corp.) HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [57344 2008-06-20] (Realtek Semiconductor Corp.) HKLM\...\Run: [] => [X] HKLM\...\Run: [EDS] => C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe [659456 2007-12-20] (Samsung Electronics,.LTD) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1044480 2008-08-28] (Synaptics, Inc.) HKLM\...\Run: [DMHotKey] => C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe [466944 2006-12-27] (SAMSUNG Electronics) HKLM\...\Run: [BatteryManager] => C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe [2768896 2008-10-20] () HKLM\...\Run: [MagicKeyboard] => C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe [151552 2006-05-14] () HKLM\...\Run: [SUPBackGround] => C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe [300912 2010-04-20] () HKLM\...\Run: [ApnUpdater] => C:\Program Files\Ask.com\Updater\Updater.exe [1646216 2013-01-24] (Ask) HKLM\...\Run: [SweetIM] => C:\Program Files\SweetIM\Messenger\SweetIM.exe [115032 2012-05-29] (SweetIM Technologies Ltd.) HKLM\...\Run: [Sweetpacks Communicator] => C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [AtherosBtXpStack] => C:\Program Files\Bluetooth XP Suite\BluetoothSuit.exe [2186880 2012-04-27] (Atheros Commnucations) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) HKLM\...99B7938DA9E4}\LocalServer32: [Default-wmiprvse] <==== ATTENTION! HKU\S-1-5-21-3818409279-1744527441-83536557-1005\...\Run: [Gadu-Gadu] => C:\Program Files\Gadu-Gadu\gg.exe [2127296 2008-03-20] (Gadu-Gadu S.A.) HKU\S-1-5-21-3818409279-1744527441-83536557-1005\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [21650016 2014-07-24] (Skype Technologies S.A.) HKU\S-1-5-21-3818409279-1744527441-83536557-1005\...\MountPoints2: {6a2c96fa-0244-11e2-b555-001377d078b5} - E:\AutoRun.exe /s HKU\S-1-5-21-3818409279-1744527441-83536557-1005\...\MountPoints2: {a9133670-017b-11e2-b54b-001377d078b5} - E:\AutoRun.exe /s HKU\S-1-5-21-3818409279-1744527441-83536557-1005\...\MountPoints2: {ff7af8cb-f211-11de-ae10-001377d0b3a9} - E:\wd_windows_tools\WDSetup.exe Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) SearchScopes: HKCU - DefaultScope {0521FE7E-5546-4D79-BA0E-7E0150858D43} URL = http://www.google.com/search?hl=pl&q={searchTerms}&rlz=1I7SKPB_en SearchScopes: HKCU - {0521FE7E-5546-4D79-BA0E-7E0150858D43} URL = http://www.google.com/search?hl=pl&q={searchTerms}&rlz=1I7SKPB_en SearchScopes: HKCU - {3BFBB3F6-51AF-47B6-87DD-D078DEAC846F} URL = http://en.wikipedia.org/w/index.php?title=Special:Search&search={searchTerms} SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://mysearch.sweetpacks.com?src=6&q={searchTerms}&barid=&&st=23 SearchScopes: HKCU - {F0D29DED-CD5D-4E23-8ABD-5082022F8547} URL = http://www.allegro.pl/search.php?sg=0&string={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Nero Toolbar -> {D4027C7F-154A-4066-A1AD-4243D8127440} -> C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Nero Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) Toolbar: HKCU - Nero Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_45-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_45-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_45-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: empbook - {F4673987-2C36-49e4-B23C-29DF753D84A5} - C:\Program Files\eMPendium\eMPendiumHandler.dll () Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{1AC6AA18-D4EB-4B55-9BDB-2796687A4602}: [NameServer] 194.204.159.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\GOSIA\Dane aplikacji\Mozilla\Firefox\Profiles\dflcsib9.default FF SearchEngineOrder.1: Ask.com FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-06-06] Chrome: ======= CHR HomePage: Default -> hxxp://home.sweetim.com/?crg=3.1010000&st=12&barid={FDBD2955-C08C-11E1-B4BE-001377D0B3A9} CHR RestoreOnStartup: Default -> "hxxp://home.sweetim.com/?crg=3.1010000&st=12&barid={FDBD2955-C08C-11E1-B4BE-001377D0B3A9}","hxxp://www.google.com" CHR DefaultSearchURL: Default -> {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\22.0.1229.94\pdf.dll No File CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\22.0.1229.94\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation) CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation) CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.)) CHR Plugin: (Unity Player) - C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File CHR CustomProfile: C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default CHR Extension: (YouTube) - C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-05-21] CHR Extension: (Szukaj w Google) - C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-05-21] CHR Extension: (avast! WebRep) - C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda [2012-05-21] CHR Extension: (SweetIM for Facebook) - C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn [2012-10-21] CHR Extension: (SweetPacks Chrome Extension) - C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj [2012-10-21] CHR Extension: (Gmail) - C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-05-21] CHR HKLM\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx [2012-06-27] CHR HKLM\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Windows\System32\jmdp\SweetNT.crx [2014-04-06] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 cpextender; C:\Program Files\CheckPoint\SSL Network Extender\slimsvc.exe [368272 2014-06-02] (Check Point Software Technologies) R2 eMPendiumService; C:\Program Files\eMPendium\eMPendiumService.exe [117248 2010-11-03] () [File not signed] R2 IBUpdaterService; C:\WINDOWS\system32\dmwu.exe [2375984 2014-08-27] () R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-07-25] (Oracle Corporation) R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [584488 2011-03-04] (Nero AG) R2 SNM WLAN Service; C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe [36864 2006-10-30] () [File not signed] R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files\Bluetooth XP Suite\Ath_CoexAgent.exe [163456 2012-04-27] (Atheros) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 AR5416; C:\WINDOWS\System32\DRIVERS\athw.sys [2092768 2012-07-24] (Atheros Communications, Inc.) S3 BrScnUsb; C:\WINDOWS\System32\DRIVERS\BrScnUsb.sys [15295 2004-10-15] (Brother Industries Ltd.) S3 BTATHPROT; C:\WINDOWS\System32\DRIVERS\btathprot.sys [663808 2012-04-27] (Atheros) S3 BTATHUSB; C:\WINDOWS\System32\DRIVERS\btathusb.sys [79488 2012-04-27] (Atheros) R3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [539072 2007-03-23] (Broadcom Corporation.) R3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [37424 2007-03-23] (Broadcom Corporation.) S3 btfilter; C:\WINDOWS\System32\DRIVERS\btfilter.sys [531456 2012-04-27] (Atheros) R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [876384 2007-03-31] (Broadcom Corporation.) S3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [149123 2007-03-23] (Broadcom Corporation.) S3 btwmodem; C:\WINDOWS\System32\DRIVERS\btwmodem.sys [37280 2007-03-23] (Broadcom Corporation.) S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [67960 2007-03-23] (Broadcom Corporation.) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation) R3 DNSeFilter; C:\WINDOWS\System32\drivers\SamsungEDS.sys [30208 2008-01-14] (Samsung Electronics,.LTD) [File not signed] R2 DOSMEMIO; C:\WINDOWS\system32\MEMIO.SYS [4300 2005-10-27] () [File not signed] S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49664 2005-10-28] (HP) S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2005-10-28] (HP) S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2009-08-26] (HP) S3 hspabus; C:\WINDOWS\System32\DRIVERS\hspabus.sys [91776 2008-09-29] (MCCI Corporation) S3 hspamdfl; C:\WINDOWS\System32\DRIVERS\hspamdfl.sys [14976 2008-09-29] (MCCI Corporation) S3 hspamdm; C:\WINDOWS\System32\DRIVERS\hspamdm.sys [119808 2008-09-29] (MCCI Corporation) S3 hspaserd; C:\WINDOWS\System32\DRIVERS\hspaserd.sys [98560 2008-09-29] (MCCI Corporation) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation) S3 RT73; C:\WINDOWS\System32\DRIVERS\rt73.sys [459520 2008-01-15] (Ralink Technology, Corp.) S3 SUEPD; C:\WINDOWS\System32\DRIVERS\SUE_PD.sys [19840 2006-10-30] (Samsung) [File not signed] R3 VMC326; C:\WINDOWS\System32\Drivers\VMC326.sys [238464 2008-09-23] (Vimicro Corporation) R3 VNA; C:\WINDOWS\System32\DRIVERS\vna.sys [129304 2014-06-02] (Check Point Software Technologies) S1 wceusbsh; C:\WINDOWS\System32\DRIVERS\wceusbsh.sys [31872 2008-04-14] (Microsoft Corporation) R3 yukonwxp; C:\WINDOWS\System32\DRIVERS\yk51x86.sys [299424 2012-03-27] (Marvell) S4 IntelIde; No ImagePath S3 massfilter_lte; system32\DRIVERS\massfilter_LTE.sys [X] U1 WS2IFSL; No ImagePath S3 zgdcat; system32\DRIVERS\zgdcat.sys [X] S3 zgdcdiag; system32\DRIVERS\zgdcdiag.sys [X] S3 zgdcmdm; system32\DRIVERS\zgdcmdm.sys [X] S3 zgdcnet; system32\DRIVERS\zgdcnet.sys [X] S3 zgdcnmea; system32\DRIVERS\zgdcnmea.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-19 12:00 - 2014-09-19 12:02 - 00000000 ____D () C:\FRST 2014-09-19 11:25 - 2014-09-19 11:25 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Microsoft Office 2014-09-19 11:24 - 2014-09-19 11:29 - 00000000 ____D () C:\Program Files\Microsoft Works 2014-09-19 11:23 - 2014-09-19 11:23 - 00000000 ____D () C:\Program Files\Microsoft.NET 2014-09-19 11:23 - 2014-09-19 11:23 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 2014-09-19 11:23 - 2014-09-19 11:23 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-09-19 11:20 - 2014-09-19 11:20 - 00000000 ____D () C:\WINDOWS\SHELLNEW 2014-09-19 11:18 - 2014-09-19 11:18 - 00000000 __RHD () C:\MSOCache 2014-09-18 15:48 - 2014-09-18 15:48 - 00000000 ____D () C:\Documents and Settings\tato\Ustawienia lokalne\Dane aplikacji\Sun 2014-09-18 15:48 - 2014-09-18 15:48 - 00000000 ____D () C:\Documents and Settings\tato\Dane aplikacji\Sun 2014-09-18 15:43 - 2014-09-18 15:43 - 00000000 ____D () C:\Documents and Settings\tato\Ustawienia lokalne\Dane aplikacji\SWDS 2014-09-18 10:38 - 2014-09-18 10:41 - 00000000 ____D () C:\Documents and Settings\GOSIA\Moje dokumenty\Pobrane 2014-09-17 16:05 - 2014-09-17 16:06 - 00001832 _____ () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\SLC_GOSIA.prx 2014-09-17 16:04 - 2014-09-17 16:04 - 00000000 ____D () C:\Program Files\CheckPoint 2014-09-17 16:02 - 2014-09-17 16:02 - 00000000 ____D () C:\Documents and Settings\GOSIA\Dane aplikacji\CheckPoint 2014-09-17 16:01 - 2014-09-17 16:01 - 00000000 ____D () C:\WINDOWS\Sun 2014-09-17 15:32 - 2014-09-17 15:43 - 00065536 _____ () C:\WINDOWS\system32\config\ODiag.evt 2014-09-17 15:27 - 2014-09-19 11:23 - 00000000 ____D () C:\Program Files\Microsoft Office 2014-09-17 13:56 - 2014-09-19 11:43 - 00000292 _____ () C:\WINDOWS\Tasks\AutoKMS.job 2014-09-17 13:56 - 2014-09-17 15:01 - 00000000 ____D () C:\WINDOWS\AutoKMS 2014-09-17 13:55 - 2014-09-19 11:43 - 00151552 _____ () C:\WINDOWS\KMSEmulator.exe 2014-09-17 12:43 - 2014-09-17 14:59 - 00065536 _____ () C:\WINDOWS\system32\config\OAlerts.evt 2014-09-17 12:35 - 2014-09-19 11:32 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2014-09-17 12:35 - 2014-09-17 12:35 - 00000000 ____D () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Microsoft Help 2014-09-17 12:03 - 2014-09-17 12:03 - 00000000 ____D () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\GHISLER 2014-09-17 11:56 - 2014-09-17 11:57 - 00000000 ____D () C:\Documents and Settings\GOSIA\Dane aplikacji\Mozilla 2014-09-17 11:56 - 2014-09-17 11:56 - 00000730 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk 2014-09-17 11:56 - 2014-09-17 11:56 - 00000724 _____ () C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk 2014-09-17 11:56 - 2014-09-17 11:56 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-09-17 11:56 - 2014-09-17 11:56 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-09-17 11:56 - 2014-09-17 11:56 - 00000000 ____D () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Mozilla 2014-09-17 11:56 - 2014-09-17 11:56 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Mozilla 2014-09-17 11:54 - 2014-09-17 11:54 - 00244264 _____ () C:\Documents and Settings\GOSIA\Pulpit\Firefox Setup Stub 32.0.1.exe 2014-09-17 11:49 - 2014-09-17 15:21 - 00000000 ____D () C:\totalcmd 2014-09-17 11:49 - 2014-09-17 11:49 - 00000548 _____ () C:\Documents and Settings\GOSIA\Pulpit\Total Commander.lnk 2014-09-17 11:49 - 2014-09-17 11:49 - 00000000 ____D () C:\Documents and Settings\GOSIA\Menu Start\Programy\Total Commander 2014-09-17 11:49 - 2014-09-17 11:49 - 00000000 ____D () C:\Documents and Settings\GOSIA\Dane aplikacji\GHISLER 2014-09-17 11:49 - 2010-12-17 07:56 - 00000545 _____ () C:\WINDOWS\UC.PIF 2014-09-17 11:49 - 2010-12-17 07:56 - 00000545 _____ () C:\WINDOWS\RAR.PIF 2014-09-17 11:49 - 2010-12-17 07:56 - 00000545 _____ () C:\WINDOWS\PKZIP.PIF 2014-09-17 11:49 - 2010-12-17 07:56 - 00000545 _____ () C:\WINDOWS\PKUNZIP.PIF 2014-09-17 11:49 - 2010-12-17 07:56 - 00000545 _____ () C:\WINDOWS\NOCLOSE.PIF 2014-09-17 11:49 - 2010-12-17 07:56 - 00000545 _____ () C:\WINDOWS\LHA.PIF 2014-09-17 11:49 - 2010-12-17 07:56 - 00000545 _____ () C:\WINDOWS\ARJ.PIF 2014-09-17 11:46 - 2014-07-25 12:55 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2014-09-17 11:46 - 2014-07-25 12:49 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2014-09-17 11:46 - 2014-07-25 12:49 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2014-09-17 11:46 - 2014-07-25 12:49 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2014-09-17 11:45 - 2014-09-17 11:46 - 00004606 _____ () C:\WINDOWS\system32\jupdate-1.7.0_67-b01.log 2014-09-17 11:15 - 2014-09-17 11:15 - 00000000 ____D () C:\Documents and Settings\GOSIA\Moje dokumenty\Odebrane pliki 2014-09-17 10:51 - 2014-09-17 10:53 - 00126623 _____ () C:\WINDOWS\KB2964358-IE8.log 2014-09-06 23:22 - 2014-09-06 23:22 - 00000000 ____D () C:\WINDOWS\system32\mjcm 2014-09-06 23:21 - 2014-09-06 23:21 - 00000000 ____D () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\SWDS 2014-09-05 16:29 - 2014-09-05 16:29 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-08-21 11:24 - 2014-08-21 11:24 - 00000000 ____D () C:\Documents and Settings\tato\Ustawienia lokalne\Dane aplikacji\Skype ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-19 12:02 - 2014-09-19 12:00 - 00000000 ____D () C:\FRST 2014-09-19 12:02 - 2008-12-10 04:04 - 00000000 ____D () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp 2014-09-19 12:01 - 2011-09-22 13:24 - 00000234 _____ () C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job 2014-09-19 11:52 - 2008-10-31 16:48 - 01144031 _____ () C:\WINDOWS\WindowsUpdate.log 2014-09-19 11:46 - 2014-03-25 16:34 - 00000222 _____ () C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job 2014-09-19 11:46 - 2012-05-21 12:48 - 00001030 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-09-19 11:43 - 2014-09-17 13:56 - 00000292 _____ () C:\WINDOWS\Tasks\AutoKMS.job 2014-09-19 11:43 - 2014-09-17 13:55 - 00151552 _____ () C:\WINDOWS\KMSEmulator.exe 2014-09-19 11:43 - 2008-10-31 17:44 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-09-19 11:43 - 2008-10-31 17:44 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-09-19 11:43 - 2008-10-31 16:53 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-09-19 11:42 - 2008-10-31 17:41 - 00213672 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-09-19 11:41 - 2013-08-03 15:25 - 00000987 _____ () C:\Documents and Settings\GOSIA\bmarchive.bms 2014-09-19 11:41 - 2012-10-21 21:03 - 00000930 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-09-19 11:41 - 2008-12-10 04:04 - 00000188 ___SH () C:\Documents and Settings\GOSIA\ntuser.ini 2014-09-19 11:41 - 2008-12-10 04:04 - 00000000 ____D () C:\Documents and Settings\GOSIA 2014-09-19 11:41 - 2008-10-31 16:53 - 00032616 _____ () C:\WINDOWS\SchedLgU.Txt 2014-09-19 11:32 - 2014-09-17 12:35 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2014-09-19 11:30 - 2008-10-31 17:42 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-09-19 11:29 - 2014-09-19 11:24 - 00000000 ____D () C:\Program Files\Microsoft Works 2014-09-19 11:25 - 2014-09-19 11:25 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Microsoft Office 2014-09-19 11:25 - 2008-10-31 17:41 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy 2014-09-19 11:23 - 2014-09-19 11:23 - 00000000 ____D () C:\Program Files\Microsoft.NET 2014-09-19 11:23 - 2014-09-19 11:23 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 2014-09-19 11:23 - 2014-09-19 11:23 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-09-19 11:23 - 2014-09-17 15:27 - 00000000 ____D () C:\Program Files\Microsoft Office 2014-09-19 11:20 - 2014-09-19 11:20 - 00000000 ____D () C:\WINDOWS\SHELLNEW 2014-09-19 11:18 - 2014-09-19 11:18 - 00000000 __RHD () C:\MSOCache 2014-09-19 10:44 - 2008-12-12 18:38 - 00000000 ____D () C:\Documents and Settings\GOSIA\Dane aplikacji\Skype 2014-09-19 10:40 - 2011-11-22 12:25 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software 2014-09-19 10:38 - 2008-10-31 16:49 - 00002596 _____ () C:\WINDOWS\system32\CONFIG.NT 2014-09-19 10:37 - 2013-08-13 20:18 - 00000981 _____ () C:\Documents and Settings\tato\bmarchive.bms 2014-09-19 10:37 - 2010-02-05 22:08 - 00000188 ___SH () C:\Documents and Settings\tato\ntuser.ini 2014-09-19 10:37 - 2010-02-05 22:08 - 00000000 ____D () C:\Documents and Settings\tato 2014-09-18 16:04 - 2012-05-21 12:48 - 00001034 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-09-18 15:48 - 2014-09-18 15:48 - 00000000 ____D () C:\Documents and Settings\tato\Ustawienia lokalne\Dane aplikacji\Sun 2014-09-18 15:48 - 2014-09-18 15:48 - 00000000 ____D () C:\Documents and Settings\tato\Dane aplikacji\Sun 2014-09-18 15:48 - 2010-02-05 22:08 - 00000000 __RHD () C:\Documents and Settings\tato\Dane aplikacji 2014-09-18 15:48 - 2010-02-05 22:08 - 00000000 ___HD () C:\Documents and Settings\tato\Ustawienia lokalne\Dane aplikacji 2014-09-18 15:48 - 2010-02-05 22:08 - 00000000 ____D () C:\Documents and Settings\tato\Ustawienia lokalne\Temp 2014-09-18 15:45 - 2010-03-01 08:28 - 00000460 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{4559B72B-FAEA-48FC-B183-237D3B4A4BC5}.job 2014-09-18 15:43 - 2014-09-18 15:43 - 00000000 ____D () C:\Documents and Settings\tato\Ustawienia lokalne\Dane aplikacji\SWDS 2014-09-18 13:37 - 2009-07-03 22:14 - 00000462 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{7F839764-891A-4E8C-AA2E-DF29772567BD}.job 2014-09-18 13:33 - 2011-07-01 03:01 - 00131948 _____ () C:\WINDOWS\setupapi.log 2014-09-18 10:43 - 2008-12-10 04:04 - 00000000 __RHD () C:\Documents and Settings\GOSIA\Dane aplikacji 2014-09-18 10:43 - 2008-10-31 17:41 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2014-09-18 10:41 - 2014-09-18 10:38 - 00000000 ____D () C:\Documents and Settings\GOSIA\Moje dokumenty\Pobrane 2014-09-18 10:38 - 2008-12-10 04:04 - 00000000 ___RD () C:\Documents and Settings\GOSIA\Moje dokumenty 2014-09-17 16:49 - 2013-08-26 01:21 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-09-17 16:40 - 2008-12-14 21:33 - 98758480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-09-17 16:32 - 2012-06-06 14:32 - 00000000 ____D () C:\WINDOWS\Microsoft.NET 2014-09-17 16:07 - 2008-12-10 04:04 - 00000000 ___HD () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji 2014-09-17 16:06 - 2014-09-17 16:05 - 00001832 _____ () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\SLC_GOSIA.prx 2014-09-17 16:04 - 2014-09-17 16:04 - 00000000 ____D () C:\Program Files\CheckPoint 2014-09-17 16:02 - 2014-09-17 16:02 - 00000000 ____D () C:\Documents and Settings\GOSIA\Dane aplikacji\CheckPoint 2014-09-17 16:01 - 2014-09-17 16:01 - 00000000 ____D () C:\WINDOWS\Sun 2014-09-17 15:43 - 2014-09-17 15:32 - 00065536 _____ () C:\WINDOWS\system32\config\ODiag.evt 2014-09-17 15:21 - 2014-09-17 11:49 - 00000000 ____D () C:\totalcmd 2014-09-17 15:07 - 2012-10-21 21:03 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2014-09-17 15:07 - 2011-06-27 12:40 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2014-09-17 15:01 - 2014-09-17 13:56 - 00000000 ____D () C:\WINDOWS\AutoKMS 2014-09-17 14:59 - 2014-09-17 12:43 - 00065536 _____ () C:\WINDOWS\system32\config\OAlerts.evt 2014-09-17 13:52 - 2008-12-12 19:22 - 00049896 _____ () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2014-09-17 12:35 - 2014-09-17 12:35 - 00000000 ____D () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Microsoft Help 2014-09-17 12:35 - 2008-10-31 17:41 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji 2014-09-17 12:03 - 2014-09-17 12:03 - 00000000 ____D () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\GHISLER 2014-09-17 11:57 - 2014-09-17 11:56 - 00000000 ____D () C:\Documents and Settings\GOSIA\Dane aplikacji\Mozilla 2014-09-17 11:56 - 2014-09-17 11:56 - 00000730 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk 2014-09-17 11:56 - 2014-09-17 11:56 - 00000724 _____ () C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk 2014-09-17 11:56 - 2014-09-17 11:56 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-09-17 11:56 - 2014-09-17 11:56 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-09-17 11:56 - 2014-09-17 11:56 - 00000000 ____D () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\Mozilla 2014-09-17 11:56 - 2014-09-17 11:56 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Mozilla 2014-09-17 11:54 - 2014-09-17 11:54 - 00244264 _____ () C:\Documents and Settings\GOSIA\Pulpit\Firefox Setup Stub 32.0.1.exe 2014-09-17 11:54 - 2008-12-10 04:04 - 00000000 ____D () C:\Documents and Settings\GOSIA\Pulpit 2014-09-17 11:49 - 2014-09-17 11:49 - 00000548 _____ () C:\Documents and Settings\GOSIA\Pulpit\Total Commander.lnk 2014-09-17 11:49 - 2014-09-17 11:49 - 00000000 ____D () C:\Documents and Settings\GOSIA\Menu Start\Programy\Total Commander 2014-09-17 11:49 - 2014-09-17 11:49 - 00000000 ____D () C:\Documents and Settings\GOSIA\Dane aplikacji\GHISLER 2014-09-17 11:49 - 2008-12-10 04:04 - 00000000 ___RD () C:\Documents and Settings\GOSIA\Menu Start\Programy 2014-09-17 11:46 - 2014-09-17 11:45 - 00004606 _____ () C:\WINDOWS\system32\jupdate-1.7.0_67-b01.log 2014-09-17 11:46 - 2011-11-29 00:00 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp 2014-09-17 11:46 - 2008-10-31 16:53 - 00000000 ____D () C:\Program Files\Java 2014-09-17 11:46 - 2008-10-31 16:53 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-09-17 11:41 - 2008-12-10 04:04 - 00000000 ___RD () C:\Documents and Settings\GOSIA\Menu Start\Programy\Autostart 2014-09-17 11:40 - 2011-09-20 11:05 - 00000000 ____D () C:\Program Files\OpenOffice.org 2.4 2014-09-17 11:40 - 2008-12-10 04:04 - 00000000 ___HD () C:\Documents and Settings\GOSIA\Szablony 2014-09-17 11:39 - 2011-09-20 11:11 - 00000000 ____D () C:\Documents and Settings\GOSIA\Dane aplikacji\OpenOffice.org2 2014-09-17 11:23 - 2008-10-31 16:56 - 00000000 ____D () C:\Program Files\Samsung 2014-09-17 11:23 - 2008-10-31 16:56 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Samsung 2014-09-17 11:23 - 2008-10-31 16:55 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-09-17 11:21 - 2008-10-31 17:41 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy\Autostart 2014-09-17 11:20 - 2012-06-27 21:19 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\SweetIM 2014-09-17 11:19 - 2008-12-12 18:38 - 00000000 ____D () C:\Program Files\Google 2014-09-17 11:16 - 2008-11-01 00:31 - 00526810 _____ () C:\WINDOWS\system32\perfh015.dat 2014-09-17 11:16 - 2008-11-01 00:31 - 00102628 _____ () C:\WINDOWS\system32\perfc015.dat 2014-09-17 11:16 - 2008-10-31 17:42 - 01190304 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-09-17 11:15 - 2014-09-17 11:15 - 00000000 ____D () C:\Documents and Settings\GOSIA\Moje dokumenty\Odebrane pliki 2014-09-17 11:02 - 2011-02-24 09:41 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-09-17 10:53 - 2014-09-17 10:51 - 00126623 _____ () C:\WINDOWS\KB2964358-IE8.log 2014-09-17 10:53 - 2008-12-12 20:13 - 00350115 _____ () C:\WINDOWS\updspapi.log 2014-09-17 10:53 - 2008-10-31 17:42 - 02198771 _____ () C:\WINDOWS\FaxSetup.log 2014-09-17 10:53 - 2008-10-31 17:42 - 01024327 _____ () C:\WINDOWS\ocgen.log 2014-09-17 10:53 - 2008-10-31 17:42 - 00785966 _____ () C:\WINDOWS\tsoc.log 2014-09-17 10:53 - 2008-10-31 17:42 - 00731026 _____ () C:\WINDOWS\comsetup.log 2014-09-17 10:53 - 2008-10-31 17:42 - 00442461 _____ () C:\WINDOWS\ntdtcsetup.log 2014-09-17 10:53 - 2008-10-31 17:42 - 00344714 _____ () C:\WINDOWS\iis6.log 2014-09-17 10:53 - 2008-10-31 17:42 - 00135462 _____ () C:\WINDOWS\ocmsn.log 2014-09-17 10:53 - 2008-10-31 17:42 - 00104996 _____ () C:\WINDOWS\msgsocm.log 2014-09-17 10:53 - 2008-10-31 17:42 - 00001374 _____ () C:\WINDOWS\imsins.log 2014-09-17 10:51 - 2013-08-11 18:47 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Microsoft Silverlight 2014-09-17 10:16 - 2008-10-31 17:41 - 00221521 _____ () C:\WINDOWS\setupact.log 2014-09-17 10:12 - 2008-11-01 00:31 - 00001158 _____ () C:\WINDOWS\system32\wpa.dbl 2014-09-06 23:22 - 2014-09-06 23:22 - 00000000 ____D () C:\WINDOWS\system32\mjcm 2014-09-06 23:21 - 2014-09-06 23:21 - 00000000 ____D () C:\Documents and Settings\GOSIA\Ustawienia lokalne\Dane aplikacji\SWDS 2014-09-06 23:21 - 2013-06-09 15:45 - 00000000 ____D () C:\WINDOWS\system32\WNLT 2014-09-06 23:21 - 2013-06-09 15:45 - 00000000 ____D () C:\WINDOWS\system32\ARFC 2014-09-05 16:33 - 2014-03-25 16:34 - 00000216 _____ () C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job 2014-09-05 16:29 - 2014-09-05 16:29 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-09-05 16:29 - 2009-08-19 09:14 - 00000000 ___RD () C:\Program Files\Skype 2014-09-05 16:29 - 2008-12-12 18:37 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Skype 2014-08-27 12:08 - 2013-06-09 15:45 - 02375984 _____ () C:\WINDOWS\system32\dmwu.exe 2014-08-27 12:02 - 2013-06-09 15:45 - 00027136 _____ (IncrediMail, Ltd.) C:\WINDOWS\system32\ImHttpComm.dll 2014-08-27 11:24 - 2013-06-09 15:45 - 00632656 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr80.dll 2014-08-27 11:24 - 2013-06-09 15:45 - 00554832 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp80.dll 2014-08-27 11:24 - 2013-06-09 15:45 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcm80.dll 2014-08-27 11:24 - 2013-06-09 15:45 - 00001870 _____ () C:\WINDOWS\system32\Microsoft.VC80.CRT.manifest 2014-08-21 11:24 - 2014-08-21 11:24 - 00000000 ____D () C:\Documents and Settings\tato\Ustawienia lokalne\Dane aplikacji\Skype 2014-08-21 11:24 - 2010-02-05 22:23 - 00000000 ____D () C:\Documents and Settings\tato\Dane aplikacji\Skype 2014-08-21 11:23 - 2011-09-23 14:19 - 00000000 ____D () C:\Documents and Settings\tato\Ustawienia lokalne\Dane aplikacji\AskToolbar Some content of TEMP: ==================== C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\contentDATs.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\dotNetFx35setup.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\EngineInstaller.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\GoogleToolbarInstaller_en.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\jre-6u45-windows-i586-iftw_2f3dd198.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\jre-7u51-windows-i586-iftw.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\jre-7u67-windows-i586-iftw.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\mgsqlite3.dll C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\RazossUpdater.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\SecurityScan_Release.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\setup.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\setup_wm.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\Shortcut_Shortcut_SweetIMSetup.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\Shortcut_SweetIMSetup.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\SIMEEI2Installer.exe C:\Documents and Settings\GOSIA\Ustawienia lokalne\Temp\SIMEEIInstaller.exe C:\Documents and Settings\tato\Ustawienia lokalne\Temp\GoogleChromeInstaller.exe C:\Documents and Settings\tato\Ustawienia lokalne\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================