Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-10-2014 Ran by R (administrator) on RZZ on 20-10-2014 00:25:23 Running from C:\Documents and Settings\R\Pulpit\czyszczenie Loaded Profile: R (Available profiles: R & Administrator) Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe (SigmaTel, Inc.) C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (Creative Technology Ltd.) C:\WINDOWS\V0420Mon.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (OpenOffice.org) C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe (OpenOffice.org) C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (SigmaTel, Inc.) C:\WINDOWS\system32\stacsv.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\WLKEEPER.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NVHotkey] => rundll32.exe nvHotkey.dll,Start HKLM\...\Run: [SigmatelSysTrayApp] => C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [405504 2007-05-10] (SigmaTel, Inc.) HKLM\...\Run: [V0420Mon.exe] => C:\WINDOWS\V0420Mon.exe [32768 2007-04-30] (Creative Technology Ltd.) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated) HKLM\...\Run: [MSConfig] => C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [171520 2008-09-06] (Microsoft Corporation) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-10-19] (AVAST Software) HKLM Group Policy restriction on software: C:\Program Files\AVAST Software <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\Alwil Software <====== ATTENTION HKLM\...\Winlogon: [UIHost] C:\WINDOWS\system32\logonui.exe [515072 2008-09-06] ( (Microsoft Corporation)) HKU\S-1-5-21-1251762338-734992631-2010050143-1004\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [21650016 2014-07-24] (Skype Technologies S.A.) HKU\S-1-5-21-1251762338-734992631-2010050143-1004\...\MountPoints2: {275846d8-ff6f-11e1-a72d-001f3c171994} - D:\NokiaPCIA_Autorun.exe HKU\S-1-5-21-1251762338-734992631-2010050143-1004\...\MountPoints2: {42fd1ad4-19f5-11e3-a9a5-001d09ccea21} - F:\SISetup.exe Startup: C:\Documents and Settings\R\Menu Start\Programy\Autostart\OpenOffice.ux.pl 3.3.lnk ShortcutTarget: OpenOffice.ux.pl 3.3.lnk -> C:\Program Files\OpenOffice.ux.pl 3\program\quickstart.exe () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=125 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKCU - DefaultScope {D289716E-10C6-48A3-AE5D-72738AA62F63} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {D289716E-10C6-48A3-AE5D-72738AA62F63} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) BHO: IplexToALLPlayer -> {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} -> C:\Program Files\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A41} https://www.pekaobiznes24.pl/sme/static/components/1,3,0,82/SignActivXPEKAO.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.123.254 FireFox: ======== FF ProfilePath: C:\Documents and Settings\R\Dane aplikacji\Mozilla\Firefox\Profiles\w3nv1rut.default-1413665436890 FF Homepage: google.pl FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @vividas.com/npVividasPlayer -> C:\Program Files\Vividas\Player\npVividasPlayer.dll ( ) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Documents and Settings\R\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-10-19] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-10-15] Chrome: ======= CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-19] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-19] (AVAST Software) S3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-03-12] (Hewlett-Packard Co.) [File not signed] R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed] R2 S24EventMonitor; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [909312 2009-05-21] (Intel(R) Corporation) [File not signed] R2 STacSV; C:\WINDOWS\system32\StacSV.exe [94208 2007-05-10] (SigmaTel, Inc.) R2 WLANKEEPER; C:\Program Files\Intel\WiFi\bin\WLKeeper.exe [348160 2009-05-21] (Intel(R) Corporation) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-10-19] () R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-10-19] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55112 2014-10-19] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-10-19] () R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [779536 2014-10-19] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [414392 2014-10-19] (AVAST Software) R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57800 2014-10-19] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [192352 2014-10-19] () S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation) R3 guardian2; C:\WINDOWS\System32\Drivers\oz776.sys [62208 2007-03-26] (O2Micro) S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-03-08] (HP) S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-03-08] (HP) S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-03-08] (HP) R3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [209152 2006-11-03] (Conexant Systems, Inc.) R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [989696 2006-11-03] (Conexant Systems, Inc.) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [114904 2014-10-19] (Malwarebytes Corporation) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation) R3 NETw5x32; C:\WINDOWS\System32\DRIVERS\NETw5x32.sys [4203392 2009-05-29] (Intel Corporation) R2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [11904 2008-08-14] (Intel Corporation) R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1222840 2007-05-10] (SigmaTel, Inc.) S3 V0420VID; C:\WINDOWS\System32\DRIVERS\V0420Vid.sys [99648 2007-05-31] (Creative Technology Ltd.) [File not signed] S4 IntelIde; No ImagePath S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [X] U1 WS2IFSL; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-20 00:23 - 2014-10-20 00:25 - 00000000 ____D () C:\FRST 2014-10-19 23:53 - 2014-10-19 23:36 - 00069584 ____H () C:\WINDOWS\Minidump\Mini101914-01.dmp 2014-10-19 23:32 - 2014-10-19 23:32 - 00001740 _____ () C:\Documents and Settings\All Users\Pulpit\avast! Free Antivirus.lnk 2014-10-19 23:32 - 2014-10-19 23:32 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Avast 2014-10-19 23:31 - 2014-10-19 23:31 - 00779536 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2014-10-19 23:31 - 2014-10-19 23:31 - 00414392 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2014-10-19 23:31 - 2014-10-19 23:31 - 00276432 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2014-10-19 23:31 - 2014-10-19 23:31 - 00192352 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys 2014-10-19 23:31 - 2014-10-19 23:31 - 00067824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2014-10-19 23:31 - 2014-10-19 23:31 - 00057800 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys 2014-10-19 23:31 - 2014-10-19 23:31 - 00055112 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys 2014-10-19 23:31 - 2014-10-19 23:31 - 00049944 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys 2014-10-19 23:31 - 2014-10-19 23:31 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr 2014-10-19 23:30 - 2014-10-19 23:31 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software 2014-10-18 23:52 - 2014-10-18 23:52 - 00000000 ____D () C:\Documents and Settings\R\Dane aplikacji\CrystalIdea Software 2014-10-18 23:27 - 2014-10-18 23:27 - 00001804 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk 2014-10-18 23:27 - 2014-10-18 23:27 - 00001741 _____ () C:\Documents and Settings\All Users\Pulpit\Adobe Reader XI.lnk 2014-10-18 23:23 - 2014-10-18 23:23 - 00000000 ____D () C:\WINDOWS\Sun 2014-10-18 23:21 - 2014-10-18 23:21 - 00146432 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2014-10-18 23:21 - 2014-10-18 23:21 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2014-10-18 23:21 - 2014-10-18 23:21 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-10-18 23:21 - 2014-10-18 23:21 - 00000000 ____D () C:\Documents and Settings\R\Ustawienia lokalne\Dane aplikacji\Sun 2014-10-18 23:21 - 2014-10-18 23:21 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Java 2014-10-18 23:21 - 2014-10-18 23:21 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Sun 2014-10-18 23:21 - 2014-10-18 23:21 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Oracle 2014-10-18 23:20 - 2014-10-18 23:20 - 00000000 ____D () C:\Program Files\Java 2014-10-18 23:18 - 2014-10-18 23:18 - 00000000 ____D () C:\Documents and Settings\R\Dane aplikacji\Sun 2014-10-18 22:50 - 2014-10-18 22:50 - 00000000 ____D () C:\Documents and Settings\R\Pulpit\Stare dane programu Firefox 2014-10-18 22:43 - 2014-10-18 22:43 - 00000737 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk 2014-10-18 22:43 - 2014-10-18 22:43 - 00000731 _____ () C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk 2014-10-18 22:43 - 2014-10-18 22:43 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-10-18 22:43 - 2014-10-18 22:43 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-10-18 21:49 - 2014-10-19 23:55 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-10-18 21:48 - 2014-10-18 21:48 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-10-18 21:48 - 2014-10-18 21:48 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes Anti-Malware 2014-10-18 21:48 - 2014-10-18 21:48 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes 2014-10-18 21:48 - 2014-10-01 11:11 - 00054360 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-10-18 21:48 - 2014-10-01 11:11 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-10-18 21:47 - 2014-10-18 21:47 - 00004644 _____ () C:\DelFix.txt 2014-10-18 21:47 - 2014-10-18 21:47 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-10-18 21:46 - 2014-10-19 09:40 - 00000000 ____D () C:\Documents and Settings\R\Dane aplikacji\AVAST Software 2014-10-18 21:44 - 2014-10-19 23:31 - 00000000 ____D () C:\Program Files\AVAST Software 2014-10-18 21:31 - 2014-10-20 00:25 - 00000000 ____D () C:\Documents and Settings\R\Pulpit\czyszczenie 2014-10-17 09:34 - 2014-10-17 09:34 - 00000000 ____D () C:\WINDOWS\jumpshot.com 2014-10-16 22:46 - 2014-10-19 23:31 - 00024184 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys 2014-10-16 22:45 - 2014-10-16 22:45 - 00051056 _____ () C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2014-10-16 22:19 - 2014-10-18 23:20 - 00000000 ____D () C:\Documents and Settings\R\Ustawienia lokalne\Dane aplikacji\Opera Software 2014-10-16 22:19 - 2014-10-18 23:20 - 00000000 ____D () C:\Documents and Settings\R\Dane aplikacji\Opera Software 2014-10-14 23:29 - 2014-10-14 23:29 - 00176605 _____ () C:\unp304025494206212496.mdmp 2014-10-07 09:41 - 2014-10-18 23:43 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\BucavRaqun 2014-10-06 13:29 - 2014-10-19 20:57 - 00000000 ____D () C:\Documents and Settings\R\Pulpit\Strona NSP 2014-09-29 10:35 - 2014-09-29 10:33 - 00069584 ____H () C:\WINDOWS\Minidump\Mini092914-01.dmp ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-20 00:25 - 2011-07-20 20:26 - 00000000 ____D () C:\Documents and Settings\R\Ustawienia lokalne\Temp 2014-10-20 00:21 - 2014-06-23 20:39 - 00000000 ____D () C:\Documents and Settings\R\Moje dokumenty\Pobrane 2014-10-19 23:56 - 2012-08-02 21:11 - 00000354 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job 2014-10-19 23:56 - 2011-01-25 21:25 - 01447702 _____ () C:\WINDOWS\WindowsUpdate.log 2014-10-19 23:54 - 2011-01-25 21:30 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-10-19 23:54 - 2011-01-25 21:13 - 00012598 _____ () C:\WINDOWS\system32\wpa.dbl 2014-10-19 23:54 - 2011-01-25 13:23 - 00000157 _____ () C:\WINDOWS\wiadebug.log 2014-10-19 23:54 - 2011-01-25 13:23 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-10-19 23:53 - 2011-11-27 20:10 - 00000000 ____D () C:\WINDOWS\Minidump 2014-10-19 23:53 - 2011-07-20 20:26 - 00000188 ___SH () C:\Documents and Settings\R\ntuser.ini 2014-10-19 23:53 - 2011-01-25 21:30 - 00032596 _____ () C:\WINDOWS\SchedLgU.Txt 2014-10-19 23:32 - 2011-01-25 13:20 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy 2014-10-19 23:32 - 2011-01-25 13:20 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2014-10-19 23:30 - 2011-01-25 13:20 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji 2014-10-19 23:28 - 2011-07-20 20:26 - 00000000 ____D () C:\Documents and Settings\R\Pulpit 2014-10-19 23:25 - 2011-01-25 21:26 - 00002596 _____ () C:\WINDOWS\system32\CONFIG.NT 2014-10-19 23:21 - 2011-01-25 21:14 - 00000211 __RSH () C:\boot.ini 2014-10-19 23:21 - 2011-01-25 21:13 - 00000498 _____ () C:\WINDOWS\win.ini 2014-10-19 23:21 - 2011-01-25 21:13 - 00000227 _____ () C:\WINDOWS\system.ini 2014-10-19 09:40 - 2011-12-08 23:06 - 00000000 ____D () C:\Documents and Settings\R\Ustawienia lokalne\Dane aplikacji\Adobe 2014-10-19 09:40 - 2011-08-11 23:29 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-10-19 09:40 - 2011-08-11 23:29 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Adobe 2014-10-19 09:39 - 2011-01-25 21:25 - 00000000 ____D () C:\WINDOWS\system32\Restore 2014-10-18 23:42 - 2011-01-25 13:16 - 00000000 ____D () C:\WINDOWS\L2Schemas 2014-10-18 23:27 - 2011-08-11 23:29 - 00000000 ____D () C:\Program Files\Adobe 2014-10-18 23:21 - 2011-08-11 23:38 - 00000000 ____D () C:\Program Files\Opera 2014-10-18 23:21 - 2011-07-20 20:26 - 00000000 ___HD () C:\Documents and Settings\R\Ustawienia lokalne\Dane aplikacji 2014-10-18 23:18 - 2011-07-20 20:26 - 00000000 __RHD () C:\Documents and Settings\R\Dane aplikacji 2014-10-18 22:07 - 2011-12-08 23:06 - 00000000 ____D () C:\Documents and Settings\R\Ustawienia lokalne\Dane aplikacji\Temp 2014-10-18 21:45 - 2012-08-02 23:46 - 00000000 ____D () C:\Program Files\Google 2014-10-18 21:44 - 2012-02-13 19:25 - 00050664 _____ () C:\Documents and Settings\R\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2014-10-18 21:41 - 2011-08-11 23:27 - 00000000 ____D () C:\Program Files\Alwil Software 2014-10-18 21:41 - 2011-08-11 23:27 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software 2014-10-18 21:35 - 2011-01-25 13:20 - 00220040 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-10-18 21:05 - 2014-02-14 22:46 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Ulead Systems 2014-10-17 22:46 - 2013-05-14 14:56 - 00000000 ____D () C:\Documents and Settings\R\Pulpit\Poradnia 2014-10-16 22:45 - 2011-01-25 21:30 - 00000000 ___HD () C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji 2014-10-15 22:25 - 2013-07-16 15:17 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-10-15 22:21 - 2012-01-12 10:32 - 100290944 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-10-14 09:48 - 2011-07-20 20:26 - 00000000 ___RD () C:\Documents and Settings\R\Moje dokumenty 2014-10-08 15:00 - 2014-03-19 21:34 - 00000208 _____ () C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job 2014-09-29 20:45 - 2014-08-13 21:30 - 00011917 _____ () C:\Documents and Settings\R\Pulpit\Koszty szkoły.xlsx Some content of TEMP: ==================== C:\Documents and Settings\R\Ustawienia lokalne\Temp\CheckLang.dll C:\Documents and Settings\R\Ustawienia lokalne\Temp\CtRunApp.dll C:\Documents and Settings\R\Ustawienia lokalne\Temp\siinst.exe C:\Documents and Settings\R\Ustawienia lokalne\Temp\SkypeSetup.exe C:\Documents and Settings\R\Ustawienia lokalne\Temp\strings.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================