Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015 Ran by user (administrator) on USER-124D74DD0C on 14-03-2015 11:37:19 Running from C:\Documents and Settings\user\Pulpit\naprawa system Loaded Profiles: user (Available profiles: user) Platform: Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 7 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe (OptionNV) C:\Program Files\iPlus\Drivers\Driver2k\GTMax\GtDetectSc.exe (Option) C:\Program Files\iPlus\Drivers\Driver2k\GTMax\GtFlashSwitch.exe (Aladdin Knowledge Systems Ltd.) C:\WINDOWS\system32\hasplms.exe (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe ( TOSHIBA CORPORATION) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe (TOSHIBA) C:\Program Files\Toshiba\TOSHIBA Applet\THotkey.exe () C:\Program Files\iPlus\iPlusChecker.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe () C:\Program Files\CryptoTech\CryptoCard\CCMonitor.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe () C:\Program Files\ZTE MF823\CheckNDISPort_df.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe () C:\Program Files\ZTE MF823\CancelAutoPlay_df.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TOSHIBA Corp.) C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe () C:\Program Files\ZTE MF823\ShowTip.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Google Inc.) C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ITSecMng] => C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [75136 2007-09-28] ( TOSHIBA CORPORATION) HKLM\...\Run: [THotkey] => C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe [360448 2008-03-04] (TOSHIBA) HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [iPlusManager] => C:\Program Files\iPlus\iPlusChecker.exe [446464 2009-12-21] () HKLM\...\Run: [CryptoCard Suite Cert Monitor] => C:\Program Files\CryptoTech\CryptoCard\CCMonitor.exe [524800 2012-05-08] () HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2007-03-11] (Hewlett-Packard Co.) HKLM\...\Run: [CheckNDISPortF0ac70] => C:\Program Files\ZTE MF823\CheckNDISPort_df.exe [417536 2013-03-19] () HKLM\...\Run: [CancelAutoPlay_df] => C:\Program Files\ZTE MF823\CancelAutoPlay_df.exe [446720 2013-02-25] () HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation) HKU\S-1-5-21-1229272821-115176313-725345543-1004\...\Run: [Google Update] => C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [116648 2012-06-21] (Google Inc.) HKU\S-1-5-21-1229272821-115176313-725345543-1004\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.) HKU\S-1-5-21-1229272821-115176313-725345543-1004\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation) HKU\S-1-5-21-1229272821-115176313-725345543-1004\...\Run: [Adobe Reader Synchronizer] => C:\Program Files\Adobe\Reader 11.0\Reader\AdobeCollabSync.exe [746376 2014-05-08] (Adobe Systems Incorporated) HKU\S-1-5-21-1229272821-115176313-725345543-1004\...\RunOnce: [Ad Muncher Reboot Required] => [X] Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-1229272821-115176313-725345543-1004\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ HKU\S-1-5-21-1229272821-115176313-725345543-1004\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22] (Hewlett-Packard Co.) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-07-27] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-07-27] (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22] (Hewlett-Packard Co.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2004-02-05] (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\ap461t1o.default FF NetworkProxy: "type", 2 FF Homepage: www.wp.pl/?src01=dp2 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll [2007-11-21] () FF Plugin: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-27] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-07-27] (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1229272821-115176313-725345543-1004: @tools.google.com/Google Update;version=3 -> C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-10] (Google Inc.) FF Plugin HKU\S-1-5-21-1229272821-115176313-725345543-1004: @tools.google.com/Google Update;version=9 -> C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-10] (Google Inc.) FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\ap461t1o.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-08-26] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010-08-26] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} [2012-05-15] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-11] FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-05-13] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF FF HKU\S-1-5-21-1229272821-115176313-725345543-1004\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2012-05-15] FF Extension: No Name - C:\Program Files\Alwil Software\Avast5\WebRep\FF [Not Found] FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found] Chrome: ======= CHR HomePage: Default -> hxxp://www.wp.pl/ CHR StartupUrls: Default -> "hxxp://isearch.omiga-plus.com/?type=hp&ts=1421849315&from=cor&uid=FUJITSUXMHY2200BH_K429T832ADRBT832ADRBX" CHR Profile: C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default CHR Extension: (YouTube) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-06-21] CHR Extension: (Google Search) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-06-21] CHR Extension: (AdBlock) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-03-14] CHR Extension: (Dynamo Combo) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\kpgkaimemdlpgfgohekgcjddinhmphfb [2015-01-22] CHR Extension: (Google Wallet) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (Gmail) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-06-21] StartMenuInternet: chrome.exe - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 GtDetectSc; C:\Program Files\iPlus\Drivers\driver2k\GTMax\GtDetectSc.exe [204800 2007-08-29] (OptionNV) [File not signed] R2 GtFlashSwitch; C:\Program Files\iPlus\Drivers\driver2k\GTMax\GtFlashSwitch.exe [204800 2007-08-29] (Option) [File not signed] R2 hasplms; C:\WINDOWS\system32\hasplms.exe [2549248 2008-07-17] (Aladdin Knowledge Systems Ltd.) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-06-04] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-06-04] (Hewlett-Packard Co.) [File not signed] R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-07-27] (Oracle Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation) R2 MSSQL$INSERTGT; C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29178224 2007-02-10] (Microsoft Corporation) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45272 2005-10-14] (Microsoft Corporation) R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed] R2 TAPPSRV; C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe [35840 2007-04-10] (TOSHIBA Corp.) [File not signed] S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aksfridge; C:\WINDOWS\System32\DRIVERS\aksfridge.sys [350720 2008-03-27] (Aladdin Knowledge Systems Ltd.) R3 akshasp; C:\WINDOWS\System32\DRIVERS\akshasp.sys [238976 2007-07-05] (Aladdin Knowledge Systems Ltd.) R3 akshhl; C:\WINDOWS\System32\DRIVERS\akshhl.sys [46336 2007-07-23] (Aladdin Knowledge Systems Ltd.) R3 aksusb; C:\WINDOWS\System32\DRIVERS\aksusb.sys [14976 2007-07-05] (Aladdin Knowledge Systems Ltd.) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation) R2 Hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [586240 2008-02-11] (Aladdin Knowledge Systems Ltd.) S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-03-08] (HP) S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-03-08] (HP) S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-03-08] (HP) R3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [211456 2007-11-01] (Conexant Systems, Inc.) R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [989696 2007-11-01] (Conexant Systems, Inc.) R0 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation) S3 nm; C:\WINDOWS\System32\DRIVERS\NMnt.sys [40320 2008-04-13] (Microsoft Corporation) S3 NPF; C:\WINDOWS\System32\drivers\npf.sys [32512 2005-08-02] (CACE Technologies) [File not signed] R3 RTL8187B; C:\WINDOWS\System32\DRIVERS\RTL8187B.sys [288000 2007-12-26] (Realtek Semiconductor Corporation ) S3 SCR3XX2K; C:\WINDOWS\System32\DRIVERS\SCR3XX2K.sys [59776 2011-09-07] (SCM Microsystems Inc.) R3 UVCFTR; C:\WINDOWS\System32\Drivers\UVCFTR_S.SYS [18432 2007-12-17] (Chicony Electronics Co., Ltd.) U2 CertPropSvc; No ImagePath S4 IntelIde; No ImagePath U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) S3 Tosrfcom; No ImagePath U1 WS2IFSL; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-14 11:36 - 2015-03-14 11:37 - 00000000 ____D () C:\FRST 2015-03-14 11:35 - 2015-03-14 11:37 - 00000000 ____D () C:\Documents and Settings\user\Pulpit\naprawa system 2015-02-20 21:00 - 2015-02-20 21:00 - 00000252 _____ () C:\WINDOWS\Tasks\WebReg Deskjet F4100 series.job 2015-02-14 03:55 - 2012-06-02 15:18 - 00275696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mucltui.dll 2015-02-14 03:55 - 2012-06-02 15:18 - 00214256 _____ (Microsoft Corporation) C:\WINDOWS\system32\muweb.dll 2015-02-14 03:55 - 2012-06-02 15:18 - 00018160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mucltui.dll.mui 2015-02-13 18:41 - 2015-02-13 18:52 - 00000000 ____D () C:\Program Files\Defraggler 2015-02-13 18:41 - 2015-02-13 18:41 - 00001589 _____ () C:\Documents and Settings\All Users\Pulpit\Defraggler.lnk 2015-02-13 18:41 - 2015-02-13 18:41 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Defraggler 2015-02-13 18:30 - 2015-03-14 11:19 - 00000000 ____D () C:\Program Files\Ad Muncher 2015-02-13 18:14 - 2015-03-14 11:11 - 00000384 ____H () C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job 2015-02-13 18:10 - 2015-03-03 14:16 - 00246920 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2015-02-13 18:05 - 2015-02-13 18:30 - 00001919 _____ () C:\WINDOWS\epplauncher.mif 2015-02-13 18:04 - 2015-02-13 18:04 - 00001707 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\Microsoft Security Essentials.lnk 2015-02-13 18:03 - 2015-02-13 18:04 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2015-02-13 18:01 - 2015-02-13 18:01 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Windows Genuine Advantage 2015-02-13 17:42 - 2015-02-13 17:42 - 00000967 _____ () C:\aswBoot.log ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-14 11:37 - 2008-07-15 12:40 - 00000000 ____D () C:\Documents and Settings\user\Ustawienia lokalne\Temp 2015-03-14 11:35 - 2008-07-15 12:40 - 00000000 ____D () C:\Documents and Settings\user\Pulpit 2015-03-14 11:34 - 2008-07-15 12:34 - 01791459 _____ () C:\WINDOWS\WindowsUpdate.log 2015-03-14 11:19 - 2008-07-15 14:20 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji 2015-03-14 11:19 - 2008-07-15 14:20 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy 2015-03-14 11:01 - 2012-11-21 15:06 - 00000364 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job 2015-03-14 11:01 - 2008-07-15 14:23 - 00000157 _____ () C:\WINDOWS\wiadebug.log 2015-03-14 11:01 - 2008-07-15 14:23 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2015-03-14 11:01 - 2008-07-15 12:39 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-03-14 11:01 - 2008-07-15 12:39 - 00000000 ____D () C:\Documents and Settings\NetworkService\Ustawienia lokalne\Temp 2015-03-14 09:17 - 2008-07-15 12:40 - 00000188 ___SH () C:\Documents and Settings\user\ntuser.ini 2015-03-14 09:17 - 2008-07-15 12:39 - 00032438 _____ () C:\WINDOWS\SchedLgU.Txt 2015-03-14 09:01 - 2012-06-21 07:23 - 00001128 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-115176313-725345543-1004UA.job 2015-03-14 09:00 - 2015-01-21 14:34 - 00000336 _____ () C:\WINDOWS\Tasks\PITax rss checker.job 2015-03-13 21:38 - 2014-09-09 18:58 - 00524288 _____ () C:\WINDOWS\system32\config\WEBWRF_L.evt 2015-03-13 21:38 - 2014-03-14 20:16 - 00524288 _____ () C:\WINDOWS\system32\config\WEBWRF.evt 2015-03-13 20:53 - 2009-03-18 19:47 - 00000658 _____ () C:\Documents and Settings\user\Pulpit\Kobra 7.lnk 2015-03-13 20:53 - 2009-03-18 17:15 - 00013030 _____ () C:\PDOXUSRS.NET 2015-03-13 13:56 - 2013-03-17 19:12 - 00000000 ____D () C:\WINDOWS\Minidump 2015-03-11 19:02 - 2008-08-08 16:26 - 00000000 ____D () C:\Program Files\KOBRA7 2015-03-08 20:03 - 2008-07-15 14:12 - 00000000 ____D () C:\WINDOWS\Help 2015-03-07 20:16 - 2006-03-02 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl 2015-03-04 20:22 - 2010-07-20 18:59 - 00000000 ____D () C:\Documents and Settings\user\Dane aplikacji\HpUpdate 2015-03-01 17:47 - 2008-07-15 12:40 - 00000000 ___RD () C:\Documents and Settings\user\Moje dokumenty 2015-02-15 19:08 - 2013-06-03 12:36 - 00153012 _____ () C:\WINDOWS\hpoins14.dat 2015-02-15 19:08 - 2008-07-15 15:55 - 00053913 _____ () C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log 2015-02-15 19:04 - 2006-03-02 13:00 - 00000614 _____ () C:\WINDOWS\win.ini 2015-02-14 12:59 - 2015-01-21 15:25 - 00002315 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk 2015-02-14 12:31 - 2008-07-15 12:40 - 00000000 __RHD () C:\Documents and Settings\user\Dane aplikacji 2015-02-14 08:00 - 2012-06-21 07:23 - 00001076 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-115176313-725345543-1004Core.job 2015-02-13 18:41 - 2008-07-15 14:20 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2015-02-13 17:54 - 2015-01-21 15:04 - 00000000 ____D () C:\Program Files\Dynamo Combo 2015-02-13 17:54 - 2014-02-05 17:16 - 00000000 ____D () C:\AdwCleaner 2015-02-13 17:51 - 2014-09-06 08:39 - 02112512 _____ () C:\Documents and Settings\user\Moje dokumenty\AdwCleaner.exe ==================== Files in the root of some directories ======= 2008-08-15 11:08 - 2012-11-21 15:18 - 0005120 _____ () C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-01-22 16:33 - 2015-01-27 13:49 - 0005917 _____ () C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\unins000.dat 2015-01-27 13:49 - 2015-01-27 13:49 - 0707744 _____ () C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\unins000.exe 2015-01-22 16:33 - 2015-01-27 13:49 - 0011761 _____ () C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\unins000.msg Some content of TEMP: ==================== C:\Documents and Settings\user\Ustawienia lokalne\Temp\ICReinstall_Adobe-Reader(12627)-dp.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================