Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:14-08-2015 01 Ran by Irek (administrator) on GNIADEK (15-08-2015 10:04:22) Running from C:\Documents and Settings\Irek\Moje dokumenty\Moje pobrane Loaded Profiles: Irek (Available Profiles: Irek) Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) Language: Polski Internet Explorer Version 8 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (Ralink Technology, Corp.) C:\Program Files\Tenda\Common\RaRegistry.exe (Realtek Semiconductor Corp.) C:\WINDOWS\SOUNDMAN.EXE (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [57344 2003-10-08] (Realtek Semiconductor Corp.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [nwiz] => nwiz.exe /install HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6127840 2015-08-11] (AVAST Software) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-08-11] (AVAST Software) BootExecute: autocheck autochk * ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-07-15] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-11] (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-15] (Oracle Corporation) Toolbar: HKLM - &Tłumaczenie - {2F7DB8D7-9BE7-4666-901E-F380555BCAC7} - C:\Program Files\Słowniki\Russkij Translator\InternetTranslatorRusPol.dll [2008-02-07] (Techland) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 62.179.1.60 62.179.1.61 Tcpip\..\Interfaces\{CBD9C71F-B4ED-4D56-985B-3BFCA316E4FC}: [DhcpNameServer] 62.179.1.60 62.179.1.61 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Irek\Dane aplikacji\Mozilla\Firefox\Profiles\pmftnuzz.default FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-15] () FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-15] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-15] (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.) FF SearchPlugin: C:\Documents and Settings\Irek\Dane aplikacji\Mozilla\Firefox\Profiles\pmftnuzz.default\searchplugins\-ru.xml [2015-02-28] FF SearchPlugin: C:\Documents and Settings\Irek\Dane aplikacji\Mozilla\Firefox\Profiles\pmftnuzz.default\searchplugins\filmwebpl.xml [2015-01-04] FF SearchPlugin: C:\Documents and Settings\Irek\Dane aplikacji\Mozilla\Firefox\Profiles\pmftnuzz.default\searchplugins\wyszukiwarka-filmw-w-youtube.xml [2015-02-25] FF Extension: NetVideoHunter - C:\Documents and Settings\Irek\Dane aplikacji\Mozilla\Firefox\Profiles\pmftnuzz.default\Extensions\netvideohunter@netvideohunter.com [2015-05-29] FF Extension: Download Manager (S3) - C:\Documents and Settings\Irek\Dane aplikacji\Mozilla\Firefox\Profiles\pmftnuzz.default\Extensions\s3download@statusbar.xpi [2014-12-02] FF Extension: Adblock Plus - C:\Documents and Settings\Irek\Dane aplikacji\Mozilla\Firefox\Profiles\pmftnuzz.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-12-02] FF Extension: Greasemonkey - C:\Documents and Settings\Irek\Dane aplikacji\Mozilla\Firefox\Profiles\pmftnuzz.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2014-12-04] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-12-03] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-12-08] Chrome: ======= CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-06-28] CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-06-28] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-11] (AVAST Software) S4 PuranDefrag; C:\WINDOWS\system32\PuranDefragS.exe [260992 2013-08-15] (Puran Software) [File not signed] R2 RalinkRegistryWriter; C:\Program Files\Tenda\Common\RaRegistry.exe [193888 2010-06-28] (Ralink Technology, Corp.) S4 WMZuneComm; c:\Program Files\Zune PC\WMZuneComm.exe [268512 2011-08-05] (Microsoft Corporation) S4 ZuneBusEnum; c:\Program Files\Zune PC\ZuneBusEnum.exe [57056 2011-08-05] (Microsoft Corporation) S4 ZuneNetworkSvc; c:\Program Files\Zune PC\ZuneNss.exe [6363872 2011-08-05] (Microsoft Corporation) S4 ZuneWlanCfgSvc; c:\Program Files\Zune PC\ZuneWlanCfgSvc.exe [444640 2011-08-05] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [21361 2015-06-25] (Cisco Systems, Inc.) [File not signed] R3 ALCXSENS; C:\WINDOWS\System32\drivers\ALCXSENS.SYS [401152 2003-10-04] (Sensaura Ltd) R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [475788 2003-10-09] (Realtek Semiconductor Corp.) S3 AR9271; C:\WINDOWS\System32\DRIVERS\athuw.sys [1714176 2010-01-05] (Atheros Communications, Inc.) R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-08-11] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [76000 2015-08-11] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-08-11] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-08-11] (AVAST Software) R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [788784 2015-08-11] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [433264 2015-08-11] (AVAST Software) R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [161472 2015-08-11] (AVAST Software) S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-08-11] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208664 2015-08-11] (AVAST Software) R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2014-12-25] (Disc Soft Ltd) S3 FET5X86V; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [46592 2011-02-10] (VIA Technologies, Inc. ) R3 FETNDISB; C:\WINDOWS\System32\DRIVERS\fetnd5b.sys [40960 2002-10-29] (VIA Technologies, Inc. ) S3 hamachi; C:\WINDOWS\System32\DRIVERS\hamachi.sys [25280 2015-02-12] (LogMeIn, Inc.) S3 RT80x86; C:\WINDOWS\System32\DRIVERS\RT2860.sys [1663456 2010-10-18] (Ralink Technology, Corp.) R2 Scutum50; C:\WINDOWS\System32\Drivers\Scutum50.sys [19072 2009-04-21] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed] R0 viaagp1; C:\WINDOWS\System32\DRIVERS\viaagp1.sys [27904 2003-07-02] (VIA Technologies, Inc.) R0 viamraid; C:\WINDOWS\System32\DRIVERS\viamraid.sys [117248 2011-02-10] (VIA Technologies inc,.ltd) [File not signed] R0 viasraid; C:\WINDOWS\System32\DRIVERS\viasraid.sys [77056 2003-09-05] (VIA Technologies inc,.ltd) S3 XFDriver; C:\Program Files\Xfire\XFDriver.sys [16648 2013-03-14] (XFire) R2 zumbus; C:\WINDOWS\System32\DRIVERS\zumbus.sys [41472 2011-08-05] (Microsoft Corporation) S2 EAPPkt; system32\DRIVERS\EAPPkt.sys [X] S4 IntelIde; no ImagePath S3 RtlWlanu; system32\DRIVERS\rtwlanu.sys [X] U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () [File not signed] U1 WS2IFSL; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-08-15 10:02 - 2015-08-15 10:04 - 00000000 ____D C:\FRST 2015-08-15 09:57 - 2015-08-15 09:57 - 00000000 _____ C:\Documents and Settings\Irek\defogger_reenable 2015-08-15 00:26 - 2015-08-15 09:38 - 00000000 _____ C:\Documents and Settings\Irek\Pulpit\TWD Season 2 Episode 5 SECRET BEST ENDING.mp4 2015-08-12 15:55 - 2015-08-12 15:56 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-08-11 11:01 - 2015-08-11 11:03 - 00104804 _____ C:\WINDOWS\Wdf01009Inst.log 2015-08-11 11:01 - 2015-08-11 11:02 - 00009585 _____ C:\WINDOWS\setupapi.log 2015-08-11 11:01 - 2015-08-11 11:01 - 00000000 _____ C:\WINDOWS\setuperr.log 2015-08-11 11:01 - 2015-08-11 11:01 - 00000000 _____ C:\WINDOWS\setupact.log 2015-08-11 11:00 - 2015-08-11 10:59 - 00161472 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStmXP.sys 2015-08-11 10:59 - 2015-08-11 10:59 - 00313472 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2015-08-11 10:59 - 2015-08-11 10:59 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr 2015-08-10 22:00 - 2015-08-10 22:00 - 00000839 _____ C:\Documents and Settings\Irek\Pulpit\Robin Hood.exe.lnk 2015-08-10 22:00 - 2015-08-10 22:00 - 00000718 _____ C:\Documents and Settings\Irek\Pulpit\Praetorians.exe.lnk 2015-08-10 12:51 - 2015-08-10 12:51 - 00000000 ____D C:\Documents and Settings\Irek\Menu Start\Programy\Praetorians 2015-08-10 12:50 - 2015-08-10 12:57 - 00000000 ____D C:\Program Files\Praetorians 2015-08-10 12:22 - 2015-08-10 12:22 - 00000000 ____D C:\Documents and Settings\Irek\Menu Start\Programy\Robin Hood - Legenda Sherwood 2015-08-10 12:08 - 2015-08-10 12:24 - 00000000 ____D C:\Program Files\Robin Hood - Legenda Sherwood 2015-08-08 22:48 - 2015-08-09 01:31 - 00001093 _____ C:\Documents and Settings\Irek\Moje dokumenty\Nowy Dokument tekstowy (4).txt 2015-08-07 17:43 - 2015-08-07 17:47 - 00000000 ____D C:\Gry 2015-08-07 17:39 - 2015-08-09 16:20 - 00000000 ____D C:\Program Files\DOSBox-0.74 2015-08-07 17:39 - 2015-08-07 17:39 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\DOSBox-0.74 2015-08-07 11:32 - 2015-08-07 15:39 - 00000800 _____ C:\Documents and Settings\Irek\Moje dokumenty\Nowy Dokument tekstowy (2).txt 2015-08-07 11:32 - 2015-08-07 11:32 - 00000000 _____ C:\Documents and Settings\Irek\Moje dokumenty\Nowy Dokument tekstowy (3).txt 2015-08-06 22:18 - 2015-08-08 17:31 - 00000822 _____ C:\Documents and Settings\Irek\Moje dokumenty\Nowy Dokument tekstowgy.txt 2015-07-29 18:18 - 2015-07-29 18:18 - 04803487 _____ C:\Documents and Settings\Irek\Moje dokumenty\Bros before hoes.mp4 2015-07-27 13:04 - 2015-07-27 13:04 - 00000000 ____D C:\Program Files\Mario Forever 3 2015-07-27 13:04 - 2015-07-27 13:04 - 00000000 ____D C:\Documents and Settings\Irek\Menu Start\Programy\Buziol Games 2015-07-26 21:12 - 2015-08-06 17:27 - 00000000 ____D C:\Documents and Settings\Irek\Pulpit\Recover 2015-07-26 21:04 - 2015-08-12 18:55 - 00000000 ____D C:\Documents and Settings\Irek\Pulpit\Inne filmy do obejrzenia 2015-07-26 21:03 - 2015-08-10 11:18 - 00000000 ____D C:\Documents and Settings\Irek\Pulpit\Durn filmy do obejrzenia 2015-07-25 12:59 - 2015-07-25 12:59 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_00_00.Wdf 2015-07-23 11:30 - 2015-07-23 12:28 - 00000689 _____ C:\Documents and Settings\Irek\Moje dokumenty\rapsy.txt ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-08-15 10:04 - 2014-12-04 21:54 - 00000000 ____D C:\TEMP 2015-08-15 10:04 - 2014-12-02 00:00 - 00000000 ___RD C:\Documents and Settings\Irek\Moje dokumenty\Moje pobrane 2015-08-15 10:00 - 2014-12-03 00:36 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job 2015-08-15 10:00 - 2014-01-04 16:42 - 02080647 _____ C:\WINDOWS\WindowsUpdate.log 2015-08-15 09:59 - 2014-12-08 18:40 - 00000220 _____ C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job 2015-08-15 09:59 - 2014-12-03 00:16 - 00182441 _____ C:\WINDOWS\system32\nvapps.xml 2015-08-15 09:59 - 2014-01-04 16:50 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-08-15 09:58 - 2014-01-04 16:52 - 00000188 ___SH C:\Documents and Settings\Irek\ntuser.ini 2015-08-15 09:58 - 2014-01-04 16:50 - 00032590 _____ C:\WINDOWS\SchedLgU.Txt 2015-08-15 09:57 - 2014-01-04 16:52 - 00000000 ____D C:\Documents and Settings\Irek 2015-08-15 09:43 - 2014-12-18 18:55 - 00000000 ____D C:\Documents and Settings\Irek\Dane aplikacji\uTorrent 2015-08-15 00:26 - 2014-01-04 16:52 - 00000000 ____D C:\Documents and Settings\Irek\Pulpit 2015-08-14 15:51 - 2014-05-04 16:11 - 00000000 ____D C:\Documents and Settings\Irek\Dane aplikacji\Skype 2015-08-14 15:48 - 2014-12-23 17:00 - 00000000 ____D C:\Program Files\Call of Duty 2 2015-08-14 13:27 - 2014-12-02 22:42 - 00000000 ____D C:\Program Files\Steam 2015-08-14 11:49 - 2014-12-03 01:08 - 00003747 _____ C:\WINDOWS\VPlayer.INI 2015-08-14 11:49 - 2014-12-03 01:08 - 00000171 _____ C:\WINDOWS\VplayerINI.vpl 2015-08-12 20:10 - 2014-12-01 23:55 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-08-12 11:43 - 2014-12-06 22:51 - 00000000 ____D C:\WINDOWS\system32\MRT 2015-08-12 11:36 - 2014-12-06 22:50 - 129304528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-08-12 11:31 - 2014-12-23 20:03 - 00000000 ____D C:\Documents and Settings\Irek\Moje dokumenty\ChomikBox 2015-08-12 00:14 - 2014-12-23 20:03 - 00000000 ____D C:\Documents and Settings\Irek\.gstreamer-0.10 2015-08-12 00:07 - 2014-01-04 16:52 - 00000000 ___RD C:\Documents and Settings\Irek\Moje dokumenty 2015-08-11 11:14 - 2015-03-22 16:48 - 00000298 _____ C:\Documents and Settings\Irek\Moje dokumenty\hof.txt 2015-08-11 10:59 - 2014-12-03 00:36 - 00433264 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2015-08-11 10:59 - 2014-12-03 00:36 - 00208664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys 2015-08-11 10:59 - 2014-12-03 00:36 - 00076000 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2015-08-11 10:59 - 2014-12-03 00:36 - 00057888 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys 2015-08-11 10:59 - 2014-12-03 00:36 - 00055200 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys 2015-08-11 10:59 - 2014-12-03 00:36 - 00049776 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2015-08-11 10:59 - 2014-12-03 00:36 - 00024016 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys 2015-08-11 10:58 - 2014-12-03 00:36 - 00788784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2015-08-11 10:49 - 2008-04-15 14:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl 2015-08-10 12:51 - 2014-01-04 16:52 - 00000000 ___RD C:\Documents and Settings\Irek\Menu Start\Programy 2015-08-10 11:18 - 2014-01-04 16:52 - 00000000 ___RD C:\Documents and Settings\Irek\Moje dokumenty\Moje obrazy 2015-08-08 15:00 - 2014-12-08 18:40 - 00000214 _____ C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job 2015-08-08 13:59 - 2014-12-02 00:29 - 00000000 ____D C:\Program Files\Puran Defrag 2015-08-07 17:41 - 2014-12-22 21:02 - 00000000 ____D C:\Documents and Settings\Irek\Pulpit\Gry 2015-08-07 17:39 - 2014-01-04 17:32 - 00000000 ___RD C:\Documents and Settings\All Users\Menu Start\Programy 2015-08-07 17:39 - 2014-01-04 17:32 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit 2015-08-07 17:36 - 2014-01-04 16:52 - 00000000 ___RD C:\Documents and Settings\Irek\Moje dokumenty\Moja muzyka 2015-08-07 17:12 - 2014-12-25 23:15 - 00000000 ____D C:\Documents and Settings\Irek\Dane aplikacji\DAEMON Tools Lite 2015-08-07 17:12 - 2014-12-03 01:08 - 00000000 ____D C:\Documents and Settings\Irek\Dane aplikacji\XnView 2015-08-06 10:48 - 2014-12-22 21:02 - 00000000 ____D C:\Documents and Settings\Irek\Pulpit\Programy 2015-08-03 10:02 - 2014-12-18 20:45 - 00000000 ____D C:\Documents and Settings\Irek\.gimp-2.8 2015-08-01 15:03 - 2015-02-12 12:22 - 00000000 ____D C:\Program Files\Knights and Merchants Remake 2015-07-29 18:19 - 2014-12-09 08:41 - 02915380 ___SH C:\Documents and Settings\Irek\Moje dokumenty\Thumbs.db 2015-07-27 13:06 - 2014-12-22 19:53 - 00000160 _____ C:\WINDOWS\mafosav.INI 2015-07-26 21:24 - 2014-12-22 17:09 - 00065536 _____ C:\WINDOWS\system32\config\WindowsPowerShell.evt 2015-07-26 17:46 - 2014-12-23 19:40 - 00000000 ____D C:\Documents and Settings\Irek\Pulpit\DO NAUKI PRZEZ TE FERIE 2015-07-21 18:30 - 2015-04-17 08:33 - 00000000 ____D C:\Program Files\The Simpsons Hit & Run ==================== Files in the root of some directories ======= 2014-12-22 17:31 - 2015-06-22 18:40 - 0006144 _____ () C:\Documents and Settings\Irek\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-08-03 10:02 - 2015-08-03 10:02 - 0001029 _____ () C:\Documents and Settings\Irek\Ustawienia lokalne\Dane aplikacji\recently-used.xbel ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End of log ============================