Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015 Ran by user (administrator) on USER-124D74DD0C on 18-03-2015 14:30:26 Running from C:\Documents and Settings\user\Pulpit\naprawa system Loaded Profiles: user (Available profiles: user) Platform: Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 8 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe (OptionNV) C:\Program Files\iPlus\Drivers\Driver2k\GTMax\GtDetectSc.exe (Option) C:\Program Files\iPlus\Drivers\Driver2k\GTMax\GtFlashSwitch.exe (Aladdin Knowledge Systems Ltd.) C:\WINDOWS\system32\hasplms.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TOSHIBA Corp.) C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe ( TOSHIBA CORPORATION) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA) C:\Program Files\Toshiba\TOSHIBA Applet\THotkey.exe () C:\Program Files\iPlus\iPlusChecker.exe () C:\Program Files\CryptoTech\CryptoCard\CCMonitor.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe () C:\Program Files\ZTE MF823\CheckNDISPort_df.exe () C:\Program Files\ZTE MF823\CancelAutoPlay_df.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe () C:\Program Files\ZTE MF823\ShowTip.exe (Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe (Google Inc.) C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 11.0\Reader\reader_sl.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Skype Technologies) C:\Program Files\Skype\Updater\Updater.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ITSecMng] => C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [75136 2007-09-28] ( TOSHIBA CORPORATION) HKLM\...\Run: [THotkey] => C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe [360448 2008-03-04] (TOSHIBA) HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [iPlusManager] => C:\Program Files\iPlus\iPlusChecker.exe [446464 2009-12-21] () HKLM\...\Run: [CryptoCard Suite Cert Monitor] => C:\Program Files\CryptoTech\CryptoCard\CCMonitor.exe [524800 2012-05-08] () HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2007-03-11] (Hewlett-Packard Co.) HKLM\...\Run: [CheckNDISPortF0ac70] => C:\Program Files\ZTE MF823\CheckNDISPort_df.exe [417536 2013-03-19] () HKLM\...\Run: [CancelAutoPlay_df] => C:\Program Files\ZTE MF823\CancelAutoPlay_df.exe [446720 2013-02-25] () HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation) HKU\S-1-5-21-1229272821-115176313-725345543-1004\...\Run: [Google Update] => C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [116648 2012-06-21] (Google Inc.) HKU\S-1-5-21-1229272821-115176313-725345543-1004\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.) HKU\S-1-5-21-1229272821-115176313-725345543-1004\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation) HKU\S-1-5-21-1229272821-115176313-725345543-1004\...\Run: [Adobe Reader Synchronizer] => C:\Program Files\Adobe\Reader 11.0\Reader\AdobeCollabSync.exe [746376 2014-05-08] (Adobe Systems Incorporated) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1229272821-115176313-725345543-1004\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ HKU\S-1-5-21-1229272821-115176313-725345543-1004\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22] (Hewlett-Packard Co.) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22] (Hewlett-Packard Co.) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2004-02-05] (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== Chrome: ======= CHR Plugin: (Widevine Content Decryption Module) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\WidevineCDM\1.4.7.771\_platform_specific\win_x86\widevinecdmadapter.dll (Google Inc.) CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\41.0.2272.89\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\41.0.2272.89\internal-nacl-plugin No File CHR Plugin: (Chrome PDF Viewer) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\41.0.2272.89\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation) CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.)) CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation) CHR Profile: C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default CHR Extension: (YouTube) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-06-21] CHR Extension: (Google Search) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-06-21] CHR Extension: (AdBlock) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-03-14] CHR Extension: (Google Wallet) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (Gmail) - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-06-21] StartMenuInternet: chrome.exe - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 GtDetectSc; C:\Program Files\iPlus\Drivers\driver2k\GTMax\GtDetectSc.exe [204800 2007-08-29] (OptionNV) [File not signed] R2 GtFlashSwitch; C:\Program Files\iPlus\Drivers\driver2k\GTMax\GtFlashSwitch.exe [204800 2007-08-29] (Option) [File not signed] R2 hasplms; C:\WINDOWS\system32\hasplms.exe [2549248 2008-07-17] (Aladdin Knowledge Systems Ltd.) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-06-04] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-06-04] (Hewlett-Packard Co.) [File not signed] R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation) R2 MSSQL$INSERTGT; C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29178224 2007-02-10] (Microsoft Corporation) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45272 2005-10-14] (Microsoft Corporation) R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed] R2 TAPPSRV; C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe [35840 2007-04-10] (TOSHIBA Corp.) [File not signed] S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aksfridge; C:\WINDOWS\System32\DRIVERS\aksfridge.sys [350720 2008-03-27] (Aladdin Knowledge Systems Ltd.) S3 akshasp; C:\WINDOWS\System32\DRIVERS\akshasp.sys [238976 2007-07-05] (Aladdin Knowledge Systems Ltd.) S3 akshhl; C:\WINDOWS\System32\DRIVERS\akshhl.sys [46336 2007-07-23] (Aladdin Knowledge Systems Ltd.) S3 aksusb; C:\WINDOWS\System32\DRIVERS\aksusb.sys [14976 2007-07-05] (Aladdin Knowledge Systems Ltd.) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation) R2 Hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [586240 2008-02-11] (Aladdin Knowledge Systems Ltd.) S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-03-08] (HP) S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-03-08] (HP) S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-03-08] (HP) R3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [211456 2007-11-01] (Conexant Systems, Inc.) R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [989696 2007-11-01] (Conexant Systems, Inc.) R0 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation) S3 nm; C:\WINDOWS\System32\DRIVERS\NMnt.sys [40320 2008-04-13] (Microsoft Corporation) S3 NPF; C:\WINDOWS\System32\drivers\npf.sys [32512 2005-08-02] (CACE Technologies) [File not signed] R3 RTL8187B; C:\WINDOWS\System32\DRIVERS\RTL8187B.sys [288000 2007-12-26] (Realtek Semiconductor Corporation ) S3 SCR3XX2K; C:\WINDOWS\System32\DRIVERS\SCR3XX2K.sys [59776 2011-09-07] (SCM Microsystems Inc.) R3 UVCFTR; C:\WINDOWS\System32\Drivers\UVCFTR_S.SYS [18432 2007-12-17] (Chicony Electronics Co., Ltd.) U2 CertPropSvc; No ImagePath S4 IntelIde; No ImagePath U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) S3 Tosrfcom; No ImagePath U1 WS2IFSL; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-18 14:27 - 2015-03-18 14:27 - 00000000 __SHD () C:\Documents and Settings\user\IETldCache 2015-03-18 14:21 - 2015-03-18 14:23 - 00080570 _____ () C:\WINDOWS\KB2936068-IE8.log 2015-03-18 14:19 - 2015-03-18 14:21 - 00086582 _____ () C:\WINDOWS\KB2909921-IE8.log 2015-03-18 14:19 - 2015-03-18 14:19 - 00079768 _____ () C:\WINDOWS\KB2598845-IE8.log 2015-03-18 14:18 - 2015-03-18 14:18 - 00000000 ____D () C:\WINDOWS\ie8updates 2015-03-18 14:16 - 2015-03-18 14:19 - 00103278 _____ () C:\WINDOWS\KB982381-IE8.log 2015-03-18 14:14 - 2015-03-18 14:28 - 00007520 _____ () C:\WINDOWS\spupdsvc.log 2015-03-18 14:14 - 2015-03-18 14:23 - 00030918 _____ () C:\WINDOWS\FaxSetup.log 2015-03-18 14:14 - 2015-03-18 14:23 - 00014780 _____ () C:\WINDOWS\ocgen.log 2015-03-18 14:14 - 2015-03-18 14:23 - 00011835 _____ () C:\WINDOWS\tsoc.log 2015-03-18 14:14 - 2015-03-18 14:23 - 00010299 _____ () C:\WINDOWS\comsetup.log 2015-03-18 14:14 - 2015-03-18 14:23 - 00007089 _____ () C:\WINDOWS\setupapi.log 2015-03-18 14:14 - 2015-03-18 14:23 - 00006235 _____ () C:\WINDOWS\ntdtcsetup.log 2015-03-18 14:14 - 2015-03-18 14:23 - 00004932 _____ () C:\WINDOWS\iis6.log 2015-03-18 14:14 - 2015-03-18 14:23 - 00001930 _____ () C:\WINDOWS\ocmsn.log 2015-03-18 14:14 - 2015-03-18 14:23 - 00001545 _____ () C:\WINDOWS\msgsocm.log 2015-03-18 14:14 - 2015-03-18 14:23 - 00001374 _____ () C:\WINDOWS\imsins.log 2015-03-18 14:14 - 2015-03-18 14:21 - 00001374 _____ () C:\WINDOWS\imsins.BAK 2015-03-18 14:14 - 2015-03-18 14:14 - 00000000 _____ () C:\WINDOWS\setuperr.log 2015-03-18 14:14 - 2015-03-18 14:14 - 00000000 _____ () C:\WINDOWS\setupact.log 2015-03-18 14:09 - 2015-03-18 14:23 - 00059139 _____ () C:\WINDOWS\updspapi.log 2015-03-18 14:09 - 2015-03-18 14:14 - 00000000 __HDC () C:\WINDOWS\ie8 2015-03-18 14:08 - 2015-03-18 14:14 - 00089237 _____ () C:\WINDOWS\ie8.log 2015-03-18 13:42 - 2014-03-06 18:58 - 00522240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jsdbgui.dll 2015-03-18 13:41 - 2014-03-06 18:58 - 00743424 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iedvtool.dll 2015-03-18 13:41 - 2014-03-06 18:58 - 00247808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ieproxy.dll 2015-03-18 13:41 - 2014-03-06 18:58 - 00012800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpshims.dll 2015-03-18 13:41 - 2011-08-16 11:45 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iecompat.dll 2015-03-18 13:39 - 2015-03-18 14:24 - 00208742 _____ () C:\WINDOWS\ie8_main.log 2015-03-14 11:36 - 2015-03-18 14:30 - 00000000 ____D () C:\FRST 2015-03-14 11:35 - 2015-03-18 14:30 - 00000000 ____D () C:\Documents and Settings\user\Pulpit\naprawa system 2015-02-20 21:00 - 2015-03-16 20:42 - 00000300 _____ () C:\WINDOWS\Tasks\WebReg Deskjet F4100 series.job ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-18 14:33 - 2008-07-15 12:40 - 00000000 ____D () C:\Documents and Settings\user\Ustawienia lokalne\Temp 2015-03-18 14:33 - 2008-07-15 12:34 - 01081643 _____ () C:\WINDOWS\WindowsUpdate.log 2015-03-18 14:27 - 2008-07-15 14:23 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2015-03-18 14:27 - 2008-07-15 14:23 - 00000000 _____ () C:\WINDOWS\wiaservc.log 2015-03-18 14:27 - 2008-07-15 12:40 - 00000812 _____ () C:\Documents and Settings\user\Menu Start\Programy\Internet Explorer.lnk 2015-03-18 14:27 - 2008-07-15 12:40 - 00000000 ___RD () C:\Documents and Settings\user\Moje dokumenty\Moje obrazy 2015-03-18 14:27 - 2008-07-15 12:40 - 00000000 ___RD () C:\Documents and Settings\user\Moje dokumenty\Moja muzyka 2015-03-18 14:27 - 2008-07-15 12:40 - 00000000 ___RD () C:\Documents and Settings\user\Moje dokumenty 2015-03-18 14:27 - 2008-07-15 12:40 - 00000000 ___RD () C:\Documents and Settings\user\Menu Start\Programy 2015-03-18 14:27 - 2008-07-15 12:39 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-03-18 14:27 - 2008-07-15 12:39 - 00000000 ____D () C:\Documents and Settings\NetworkService\Ustawienia lokalne\Temp 2015-03-18 14:26 - 2008-07-15 14:12 - 00000000 ____D () C:\WINDOWS\Media 2015-03-18 14:26 - 2008-07-15 14:12 - 00000000 ____D () C:\WINDOWS\Help 2015-03-18 14:26 - 2008-07-15 13:40 - 00000000 ____D () C:\WINDOWS\system32\pl-pl 2015-03-18 14:24 - 2008-07-15 12:40 - 00000188 ___SH () C:\Documents and Settings\user\ntuser.ini 2015-03-18 14:24 - 2008-07-15 12:39 - 00032438 _____ () C:\WINDOWS\SchedLgU.Txt 2015-03-18 14:19 - 2008-07-15 12:35 - 00000000 ___HD () C:\WINDOWS\$hf_mig$ 2015-03-18 14:00 - 2012-06-21 07:23 - 00001128 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-115176313-725345543-1004UA.job 2015-03-18 13:29 - 2015-02-13 18:14 - 00000384 ____H () C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job 2015-03-18 13:18 - 2008-07-15 12:40 - 00000000 __SHD () C:\Documents and Settings\user\Ustawienia lokalne\Historia 2015-03-18 13:18 - 2008-07-15 12:39 - 00000000 __SHD () C:\Documents and Settings\LocalService\Ustawienia lokalne\Historia 2015-03-18 13:15 - 2011-02-10 19:19 - 00000000 ____D () C:\Documents and Settings\user\Pulpit\Nieużywane skróty pulpitu 2015-03-18 13:15 - 2008-07-15 14:20 - 00000000 __SHD () C:\Documents and Settings\Default User\Ustawienia lokalne\Historia 2015-03-18 13:15 - 2008-07-15 12:39 - 00000000 ___HD () C:\Documents and Settings\NetworkService\Ustawienia lokalne\Historia 2015-03-18 13:15 - 2008-07-15 12:39 - 00000000 ____D () C:\Documents and Settings\LocalService\Ustawienia lokalne\Temp 2015-03-18 13:14 - 2015-01-22 07:43 - 00000000 ____D () C:\WINDOWS\system32\GroupPolicy 2015-03-18 13:14 - 2008-07-16 13:37 - 00000000 ____D () C:\Documents and Settings\user\Moje dokumenty\CERTYFIKATY 2015-03-18 13:14 - 2008-07-15 14:20 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy 2015-03-18 13:14 - 2008-07-15 12:40 - 00000000 __RHD () C:\Documents and Settings\user\Dane aplikacji 2015-03-18 13:14 - 2008-07-15 12:40 - 00000000 ____D () C:\Documents and Settings\user\Pulpit 2015-03-18 13:11 - 2008-07-15 14:20 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2015-03-18 13:11 - 2008-07-15 14:03 - 00000000 ____D () C:\Program Files\Opera 2015-03-16 20:06 - 2009-03-18 19:47 - 00000658 _____ () C:\Documents and Settings\user\Pulpit\Kobra 7.lnk 2015-03-16 20:06 - 2009-03-18 17:15 - 00013030 _____ () C:\PDOXUSRS.NET 2015-03-16 19:49 - 2008-08-08 16:26 - 00000000 ____D () C:\Program Files\KOBRA7 2015-03-16 18:01 - 2006-03-02 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl 2015-03-14 20:42 - 2013-06-03 12:36 - 00153012 _____ () C:\WINDOWS\hpoins14.dat 2015-03-14 20:42 - 2008-07-15 15:55 - 00054405 _____ () C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log 2015-03-14 20:41 - 2006-03-02 13:00 - 00000614 _____ () C:\WINDOWS\win.ini 2015-03-14 11:19 - 2008-07-15 14:20 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji 2015-03-14 09:00 - 2015-01-21 14:34 - 00000336 _____ () C:\WINDOWS\Tasks\PITax rss checker.job 2015-03-13 21:38 - 2014-09-09 18:58 - 00524288 _____ () C:\WINDOWS\system32\config\WEBWRF_L.evt 2015-03-13 21:38 - 2014-03-14 20:16 - 00524288 _____ () C:\WINDOWS\system32\config\WEBWRF.evt 2015-03-13 13:56 - 2013-03-17 19:12 - 00000000 ____D () C:\WINDOWS\Minidump 2015-03-04 20:22 - 2010-07-20 18:59 - 00000000 ____D () C:\Documents and Settings\user\Dane aplikacji\HpUpdate 2015-03-03 14:16 - 2015-02-13 18:10 - 00246920 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2015-02-26 21:20 - 2008-07-16 14:07 - 119837696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe ==================== Files in the root of some directories ======= 2008-08-15 11:08 - 2012-11-21 15:18 - 0005120 _____ () C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-01-22 16:33 - 2015-01-27 13:49 - 0005917 _____ () C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\unins000.dat 2015-01-27 13:49 - 2015-01-27 13:49 - 0707744 _____ () C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\unins000.exe 2015-01-22 16:33 - 2015-01-27 13:49 - 0011761 _____ () C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\unins000.msg ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================