Scan result of Farbars's Recovery Tool (FRST written by farbar) Version 2.3.2 Ran by SYSTEM at 2012-01-17 23:05:28 Running from G:\ Windows 7 Home Premium (X64) OS Language: Polish The current controlset is ControlSet001 ========================== Registry (Whitelisted) ============= HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10920552 2010-06-22] (Realtek Semiconductor) HKLM\...\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe [649608 2010-04-12] (ELAN Microelectronic Corp.) HKLM\...\Run: [Acer ePower Management] C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated) HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation) HKLM-x32\...\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" -h -k [263936 2010-06-28] (NewTech Infosystems, Inc.) HKLM-x32\...\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation) HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-05-27] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.) HKLM-x32\...\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume [439568 2010-05-10] (Microsoft Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253672 2011-01-07] (Sun Microsystems, Inc.) HKU\Madzia\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized [25623336 2009-10-09] (Skype Technologies S.A.) HKU\Madzia\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-01-04] (Google Inc.) HKU\Madzia\...\Run: [Facebook Update] "C:\Users\Madzia\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [137536 2012-01-12] (Facebook Inc.) HKU\Madzia\...\Run: [Malware Protection Center] "C:\ProgramData\873065\MP873_8016.exe" /s /d [3386368 2012-01-17] () HKU\Madzia\...\Policies\system: [disableregistrytools] 0 Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0 SubSystems: [Windows] ==> ZeroAccess ==================== Services (Whitelisted) ====== 2 DsiWMIService; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [321104 2010-08-10] (Dritek System Inc.) 2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [868896 2010-06-11] (Acer Incorporated) 3 GamesAppService; "C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe" [206072 2010-10-12] (WildTangent, Inc.) 2 GREGService; C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated) 2 IAStorDataMgrSvc; "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe" [13336 2010-04-13] (Intel Corporation) 3 Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [935208 2010-01-15] (Nero AG) 2 NIS; "C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\diMaster.dll" /prefetch:1 [262584 2011-03-31] (Symantec Corporation) 2 NOBU; "C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE [2804568 2010-06-01] (Symantec Corporation) 2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [255744 2010-06-28] (NewTech Infosystems, Inc.) 2 sagefserver; C:\Windows\System32\IBM_LLC2.dll [5120 2009-07-13] (Iomega) 2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2320920 2010-03-17] (Intel Corporation) 2 Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [243232 2010-01-28] (Acer Group) 2 AdobeActiveFileMonitor8.0; c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [x] ========================== Drivers (Whitelisted) ============= 1 BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.0.0.128\Definitions\BASHDefs\20110616.003\BHDrvx64.sys [1143416 2011-05-19] (Symantec Corporation) 3 BridgeMP; C:\Windows\System32\DRIVERS\bridge.sys [95232 2009-07-13] (Microsoft Corporation) 1 eeCtrl; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [481912 2011-05-21] (Symantec Corporation) 3 EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [136824 2011-05-21] (Symantec Corporation) 3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [33856 2009-03-18] (LogMeIn, Inc.) 1 IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.0.0.128\Definitions\IPSDefs\20110629.050\IDSvia64.sys [488056 2011-06-02] (Symantec Corporation) 3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.0.0.128\Definitions\VirusDefs\20110630.002\ENG64.SYS [117880 2011-05-21] (Symantec Corporation) 3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.0.0.128\Definitions\VirusDefs\20110630.002\EX64.SYS [2011768 2011-05-21] (Symantec Corporation) 3 nmwcd; C:\Windows\System32\drivers\ccdcmbx64.sys [19968 2011-08-17] (Nokia) 3 nmwcdc; C:\Windows\System32\drivers\ccdcmbox64.sys [27136 2011-08-17] (Nokia) 3 SRTSP; C:\Windows\System32\Drivers\NISx64\1206000.01D\SRTSP64.SYS [744568 2011-03-30] (Symantec Corporation) 1 SRTSPX; C:\Windows\System32\drivers\NISx64\1206000.01D\SRTSPX64.SYS [40568 2011-03-30] (Symantec Corporation) 0 SymDS; C:\Windows\System32\drivers\NISx64\1206000.01D\SYMDS64.SYS [450680 2011-01-26] (Symantec Corporation) 0 SymEFA; C:\Windows\System32\drivers\NISx64\1206000.01D\SYMEFA64.SYS [912504 2011-03-14] (Symantec Corporation) 3 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2011-05-21] (Symantec Corporation) 1 SymIRON; C:\Windows\System32\drivers\NISx64\1206000.01D\Ironx64.SYS [171128 2011-01-26] (Symantec Corporation) 1 SymNetS; C:\Windows\System32\Drivers\NISx64\1206000.01D\SYMNETS.SYS [386168 2011-07-08] (Symantec Corporation) 3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerfltx64.sys [9216 2011-08-17] (Nokia) 3 usbser; C:\Windows\System32\drivers\usbser.sys [32768 2009-07-13] (Microsoft Corporation) 3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltjx64.sys [9216 2011-08-17] (Nokia) 3 catchme; \??\C:\ComboFix\catchme.sys [x] ========================== NetSvcs (Whitelisted) =========== NETSVC: sagefserver ============ One Month Created Files and Folders ============== 2012-01-17 12:38 - 2012-01-17 12:38 - 0000000 __SHD C:\$RECYCLE.BIN 2012-01-17 12:37 - 2012-01-17 21:49 - 0000000 ___SD C:\ComboFix 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\SYSTEM.tmp.LOG2 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\SYSTEM.tmp.LOG1 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\SECURITY.tmp.LOG2 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\SECURITY.tmp.LOG1 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\SAM.tmp.LOG2 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\SAM.tmp.LOG1 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\DEFAULT.tmp.LOG2 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\DEFAULT.tmp.LOG1 2012-01-17 12:21 - 2012-01-17 12:21 - 0000000 __ASH C:\Windows\System32\config\SOFTWARE.tmp.LOG2 2012-01-17 12:21 - 2012-01-17 12:21 - 0000000 __ASH C:\Windows\System32\config\SOFTWARE.tmp.LOG1 2012-01-17 12:11 - 2009-04-19 20:56 - 0060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2012-01-17 11:43 - 2012-01-17 12:37 - 0000000 ____D C:\Windows\ERDNT 2012-01-17 10:40 - 2012-01-17 12:24 - 0001627 ____A C:\Users\Madzia\Desktop\Malware Protection Center.lnk 2012-01-17 10:40 - 2012-01-17 10:42 - 0000000 __SHD C:\Users\Madzia\AppData\Roaming\Malware Protection Center 2012-01-17 10:40 - 2012-01-17 10:40 - 0000000 __SHD C:\Users\All Users\MPJOZMXTDUC 2012-01-17 10:40 - 2012-01-17 10:40 - 0000000 __SHD C:\ProgramData\MPJOZMXTDUC 2012-01-17 10:39 - 2012-01-17 11:49 - 0000000 __SHD C:\Users\All Users\873065 2012-01-17 10:39 - 2012-01-17 11:49 - 0000000 __SHD C:\ProgramData\873065 2012-01-17 10:28 - 2012-01-17 10:28 - 0000828 ____A C:\Users\Madzia\Documents\zadanie3.rtf 2012-01-16 22:12 - 2012-01-16 22:12 - 0001424 ____A C:\Users\Madzia\Desktop\MADZIA KLIMEK LAT 9.rtf 2012-01-16 09:08 - 2012-01-16 09:08 - 0000541 ____A C:\Users\Madzia\Documents\zadanie2.rtf 2012-01-12 10:54 - 2011-11-16 23:17 - 0152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2012-01-12 10:54 - 2011-11-16 23:17 - 0095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-01-12 10:54 - 2011-11-16 23:15 - 0460296 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2012-01-12 10:54 - 2011-11-16 23:12 - 0395776 ____A (Microsoft Corporation) C:\Windows\System32\webio.dll 2012-01-12 10:54 - 2011-11-16 23:11 - 0136192 ____A (Microsoft Corporation) C:\Windows\System32\sspicli.dll 2012-01-12 10:54 - 2011-11-16 23:11 - 0028672 ____A (Microsoft Corporation) C:\Windows\System32\sspisrv.dll 2012-01-12 10:54 - 2011-11-16 23:11 - 0028160 ____A (Microsoft Corporation) C:\Windows\System32\secur32.dll 2012-01-12 10:54 - 2011-11-16 23:10 - 0340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-01-12 10:54 - 2011-11-16 23:08 - 1446912 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll 2012-01-12 10:54 - 2011-11-16 23:05 - 0031232 ____A (Microsoft Corporation) C:\Windows\System32\lsass.exe 2012-01-12 10:54 - 2011-11-16 21:39 - 0314368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2012-01-12 10:54 - 2011-11-16 21:39 - 0224768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2012-01-12 10:54 - 2011-11-16 21:39 - 0022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2012-01-12 10:54 - 2011-11-16 21:35 - 0096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2012-01-12 07:17 - 2012-01-17 10:22 - 0000932 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-827740546-2513162357-1136232517-1000UA.job 2012-01-12 07:17 - 2012-01-17 07:22 - 0000910 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-827740546-2513162357-1136232517-1000Core.job 2012-01-12 07:17 - 2012-01-12 07:18 - 0000000 ____D C:\Users\Madzia\AppData\Local\Facebook 2012-01-11 08:00 - 2012-01-11 08:01 - 0691696 ____A C:\Windows\Minidump\011112-31418-01.dmp 2012-01-11 06:16 - 2011-10-25 21:22 - 1572864 ____A (Microsoft Corporation) C:\Windows\System32\quartz.dll 2012-01-11 06:16 - 2011-10-25 21:22 - 0366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll 2012-01-11 06:16 - 2011-10-25 20:28 - 1328640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2012-01-11 06:16 - 2011-10-25 20:28 - 0514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2012-01-11 06:15 - 2011-11-16 23:14 - 1739160 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll 2012-01-11 06:15 - 2011-11-16 21:41 - 1292592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2012-01-11 06:15 - 2011-10-13 21:21 - 0852480 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-01-11 06:15 - 2011-10-13 20:42 - 0716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-01-11 06:09 - 2011-11-19 07:07 - 0077312 ____A (Microsoft Corporation) C:\Windows\System32\packager.dll 2012-01-11 06:09 - 2011-11-19 06:06 - 0067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2012-01-10 12:55 - 2012-01-10 12:55 - 0001870 ____A C:\Users\Public\Desktop\Konfiguracja.lnk 2012-01-10 12:55 - 2012-01-10 12:55 - 0000169 ____A C:\Users\Public\Desktop\neostrada tp.url 2012-01-10 12:55 - 2012-01-10 12:55 - 0000000 ____D C:\Program Files (x86)\SAGEM 2012-01-09 12:49 - 2012-01-10 12:55 - 0000159 ____A C:\Setup.log 2012-01-09 12:49 - 2012-01-09 12:49 - 0000000 ____D C:\Users\Madzia\AppData\Roaming\InstallShield 2012-01-07 03:44 - 2012-01-07 03:44 - 0000000 ____D C:\Users\Madzia\AppData\Roaming\Bakoma 2012-01-07 03:29 - 2012-01-07 03:29 - 0000944 ____A C:\Users\Madzia\Desktop\Hipcio.lnk 2012-01-07 03:29 - 2012-01-07 03:29 - 0000000 ____D C:\Program Files (x86)\bakus2 2012-01-07 02:47 - 2012-01-07 02:47 - 0000000 __SHD C:\Windows\ftpcache 2012-01-07 02:46 - 2012-01-07 02:57 - 0000944 ____A C:\Users\Madzia\Desktop\Pies.lnk 2012-01-07 02:46 - 2012-01-07 02:57 - 0000000 ____D C:\Program Files (x86)\bakus1 2012-01-06 10:40 - 2012-01-06 10:40 - 0000000 ____D C:\Program Files\Noviy Disk 2012-01-04 08:11 - 2012-01-10 11:24 - 0000956 ____A C:\Users\Madzia\Documents\zadanie.rtf 2012-01-04 05:06 - 2012-01-17 12:23 - 0001044 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-01-04 05:06 - 2012-01-17 12:16 - 0001048 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-01-04 05:06 - 2012-01-14 08:09 - 0000000 ____D C:\Users\Madzia\AppData\Local\Google 2012-01-04 05:06 - 2012-01-04 05:07 - 0000000 ____D C:\Users\Madzia\AppData\Roaming\Google 2012-01-04 05:06 - 2012-01-04 05:06 - 0000000 ____D C:\Users\All Users\Google 2012-01-04 05:06 - 2012-01-04 05:06 - 0000000 ____D C:\ProgramData\Google 2012-01-04 05:06 - 2012-01-04 05:06 - 0000000 ____D C:\Program Files\Google 2012-01-04 05:06 - 2012-01-04 05:06 - 0000000 ____D C:\Program Files (x86)\Google 2011-12-30 15:56 - 2011-12-30 15:56 - 0000000 ____D C:\Users\All Users\McAfee 2011-12-30 15:56 - 2011-12-30 15:56 - 0000000 ____D C:\ProgramData\McAfee 2011-12-30 15:18 - 2011-12-30 15:18 - 0000000 ____D C:\Windows\System32\Macromed 2011-12-30 15:12 - 2011-12-30 15:12 - 0712520 ____A C:\Windows\Minidump\123111-26660-01.dmp 2011-12-30 10:29 - 2012-01-11 08:00 - 510164703 ____A C:\Windows\MEMORY.DMP 2011-12-30 10:29 - 2012-01-11 08:00 - 0000000 ____D C:\Windows\Minidump 2011-12-30 10:29 - 2011-12-30 10:29 - 0702136 ____A C:\Windows\Minidump\123011-28064-01.dmp 2011-12-30 02:58 - 2011-12-30 02:58 - 0000000 ____D C:\Users\Madzia\AppData\Roaming\Tific 2011-12-30 02:58 - 2011-12-30 02:58 - 0000000 ____D C:\Users\Madzia\AppData\Local\Symantec 2011-12-29 04:11 - 2011-12-29 04:11 - 0000000 __SHD C:\Windows\System32\%APPDATA% 2011-12-29 02:25 - 2012-01-17 12:20 - 0000000 __SHD C:\Users\Madzia\AppData\Local\514618ee 2011-12-26 08:03 - 2012-01-07 03:54 - 0000000 ____D C:\zdj z aparatu 2011-12-22 05:52 - 2011-12-22 05:52 - 0000000 ____D C:\Program Files (x86)\Microsoft WSE 2011-12-21 08:27 - 2011-12-21 08:27 - 0000000 ____D C:\Users\All Users\Electronic Arts 2011-12-21 08:27 - 2011-12-21 08:27 - 0000000 ____D C:\Users\All Users\EA Core 2011-12-21 08:27 - 2011-12-21 08:27 - 0000000 ____D C:\ProgramData\Electronic Arts 2011-12-21 08:27 - 2011-12-21 08:27 - 0000000 ____D C:\ProgramData\EA Core ============ 3 Months Modified Files and Folders ============= 2012-01-17 23:05 - 2012-01-17 23:04 - 0000000 ____D C:\FRST 2012-01-17 21:49 - 2012-01-17 12:37 - 0000000 ___SD C:\ComboFix 2012-01-17 21:49 - 2011-08-29 13:49 - 0000000 ____D C:\Users\Madzia\AppData\Roaming\Skype 2012-01-17 21:49 - 2011-05-02 07:23 - 0000000 ____D C:\users\Madzia 2012-01-17 21:49 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\registration 2012-01-17 13:12 - 2011-02-09 12:53 - 3113254912 __ASH C:\hiberfil.sys 2012-01-17 12:50 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\config\TxR 2012-01-17 12:38 - 2012-01-17 12:38 - 0000000 __SHD C:\$RECYCLE.BIN 2012-01-17 12:37 - 2012-01-17 11:43 - 0000000 ____D C:\Windows\ERDNT 2012-01-17 12:37 - 2011-09-30 00:44 - 0000000 ____D C:\Programy 2012-01-17 12:34 - 2009-07-13 20:45 - 0009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-01-17 12:34 - 2009-07-13 20:45 - 0009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-01-17 12:31 - 2009-07-13 19:20 - 0000000 __RHD C:\users\Default 2012-01-17 12:31 - 2009-07-13 19:20 - 0000000 ___RD C:\users\Public 2012-01-17 12:30 - 2011-02-09 12:56 - 1609292 ____A C:\Windows\WindowsUpdate.log 2012-01-17 12:29 - 2011-02-09 21:47 - 0738636 ____A C:\Windows\System32\perfh015.dat 2012-01-17 12:29 - 2011-02-09 21:47 - 0155034 ____A C:\Windows\System32\perfc015.dat 2012-01-17 12:29 - 2009-07-13 21:13 - 1664924 ____A C:\Windows\System32\PerfStringBackup.INI 2012-01-17 12:24 - 2012-01-17 10:40 - 0001627 ____A C:\Users\Madzia\Desktop\Malware Protection Center.lnk 2012-01-17 12:23 - 2012-01-04 05:06 - 0001044 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-01-17 12:23 - 2009-07-13 21:08 - 0000006 ___AH C:\Windows\Tasks\SA.DAT 2012-01-17 12:23 - 2009-07-13 20:51 - 0092068 ____A C:\Windows\setupact.log 2012-01-17 12:23 - 2009-07-13 18:34 - 0000215 ____A C:\Windows\system.ini 2012-01-17 12:23 - 2009-07-13 18:34 - 0000027 ____A C:\Windows\System32\Drivers\etc\hosts 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\SYSTEM.tmp.LOG2 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\SYSTEM.tmp.LOG1 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\SECURITY.tmp.LOG2 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\SECURITY.tmp.LOG1 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\SAM.tmp.LOG2 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\SAM.tmp.LOG1 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\DEFAULT.tmp.LOG2 2012-01-17 12:22 - 2012-01-17 12:22 - 0000000 __ASH C:\Windows\System32\config\DEFAULT.tmp.LOG1 2012-01-17 12:22 - 2011-05-02 12:55 - 0009298 ____A C:\Windows\PFRO.log 2012-01-17 12:22 - 2009-07-13 18:34 - 57147392 ____A C:\Windows\System32\config\SOFTWARE.bak 2012-01-17 12:22 - 2009-07-13 18:34 - 20709376 ____A C:\Windows\System32\config\SYSTEM.bak 2012-01-17 12:22 - 2009-07-13 18:34 - 1048576 ____A C:\Windows\System32\config\DEFAULT.bak 2012-01-17 12:22 - 2009-07-13 18:34 - 0262144 ____A C:\Windows\System32\config\SECURITY.bak 2012-01-17 12:22 - 2009-07-13 18:34 - 0262144 ____A C:\Windows\System32\config\SAM.bak 2012-01-17 12:21 - 2012-01-17 12:21 - 0000000 __ASH C:\Windows\System32\config\SOFTWARE.tmp.LOG2 2012-01-17 12:21 - 2012-01-17 12:21 - 0000000 __ASH C:\Windows\System32\config\SOFTWARE.tmp.LOG1 2012-01-17 12:20 - 2011-12-29 02:25 - 0000000 __SHD C:\Users\Madzia\AppData\Local\514618ee 2012-01-17 12:16 - 2012-01-04 05:06 - 0001048 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-01-17 11:49 - 2012-01-17 10:39 - 0000000 __SHD C:\Users\All Users\873065 2012-01-17 11:49 - 2012-01-17 10:39 - 0000000 __SHD C:\ProgramData\873065 2012-01-17 10:42 - 2012-01-17 10:40 - 0000000 __SHD C:\Users\Madzia\AppData\Roaming\Malware Protection Center 2012-01-17 10:40 - 2012-01-17 10:40 - 0000000 __SHD C:\Users\All Users\MPJOZMXTDUC 2012-01-17 10:40 - 2012-01-17 10:40 - 0000000 __SHD C:\ProgramData\MPJOZMXTDUC 2012-01-17 10:28 - 2012-01-17 10:28 - 0000828 ____A C:\Users\Madzia\Documents\zadanie3.rtf 2012-01-17 10:22 - 2012-01-12 07:17 - 0000932 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-827740546-2513162357-1136232517-1000UA.job 2012-01-17 07:22 - 2012-01-12 07:17 - 0000910 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-827740546-2513162357-1136232517-1000Core.job 2012-01-17 06:22 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\NDF 2012-01-17 05:52 - 2011-07-01 09:08 - 0000000 ____D C:\Users\Madzia\Documents\Euro Truck Simulator 2012-01-17 05:16 - 2011-06-16 08:01 - 0000000 ____D C:\Users\Madzia\AppData\Local\CrashDumps 2012-01-16 22:12 - 2012-01-16 22:12 - 0001424 ____A C:\Users\Madzia\Desktop\MADZIA KLIMEK LAT 9.rtf 2012-01-16 09:08 - 2012-01-16 09:08 - 0000541 ____A C:\Users\Madzia\Documents\zadanie2.rtf 2012-01-14 11:43 - 2011-06-16 03:56 - 0000000 ____D C:\Program Files (x86)\Softonic_Deutsch_FF 2012-01-14 08:20 - 2011-07-02 03:09 - 0002698 ____N C:\Users\Public\Desktop\WildTangent Games App - packardbell.lnk 2012-01-14 08:09 - 2012-01-04 05:06 - 0000000 ____D C:\Users\Madzia\AppData\Local\Google 2012-01-14 06:42 - 2011-05-21 11:47 - 0000000 ____D C:\Users\All Users\boost_interprocess 2012-01-14 06:42 - 2011-05-21 11:47 - 0000000 ____D C:\ProgramData\boost_interprocess 2012-01-12 07:18 - 2012-01-12 07:17 - 0000000 ____D C:\Users\Madzia\AppData\Local\Facebook 2012-01-11 08:01 - 2012-01-11 08:00 - 0691696 ____A C:\Windows\Minidump\011112-31418-01.dmp 2012-01-11 08:00 - 2011-12-30 10:29 - 510164703 ____A C:\Windows\MEMORY.DMP 2012-01-11 08:00 - 2011-12-30 10:29 - 0000000 ____D C:\Windows\Minidump 2012-01-10 12:55 - 2012-01-10 12:55 - 0001870 ____A C:\Users\Public\Desktop\Konfiguracja.lnk 2012-01-10 12:55 - 2012-01-10 12:55 - 0000169 ____A C:\Users\Public\Desktop\neostrada tp.url 2012-01-10 12:55 - 2012-01-10 12:55 - 0000000 ____D C:\Program Files (x86)\SAGEM 2012-01-10 12:55 - 2012-01-09 12:49 - 0000159 ____A C:\Setup.log 2012-01-10 12:55 - 2010-09-16 03:46 - 0000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2012-01-10 11:47 - 2011-11-22 10:43 - 0000000 ____D C:\Program Files (x86)\VS Revo Group 2012-01-10 11:24 - 2012-01-04 08:11 - 0000956 ____A C:\Users\Madzia\Documents\zadanie.rtf 2012-01-10 10:12 - 2011-05-02 07:24 - 0000000 ____D C:\Users\Madzia\AppData\Local\VirtualStore 2012-01-09 12:49 - 2012-01-09 12:49 - 0000000 ____D C:\Users\Madzia\AppData\Roaming\InstallShield 2012-01-07 10:58 - 2011-06-16 12:51 - 0000000 ____D C:\Users\Madzia\AppData\Roaming\SoftGrid Client 2012-01-07 03:54 - 2011-12-26 08:03 - 0000000 ____D C:\zdj z aparatu 2012-01-07 03:44 - 2012-01-07 03:44 - 0000000 ____D C:\Users\Madzia\AppData\Roaming\Bakoma 2012-01-07 03:29 - 2012-01-07 03:29 - 0000944 ____A C:\Users\Madzia\Desktop\Hipcio.lnk 2012-01-07 03:29 - 2012-01-07 03:29 - 0000000 ____D C:\Program Files (x86)\bakus2 2012-01-07 02:57 - 2012-01-07 02:46 - 0000944 ____A C:\Users\Madzia\Desktop\Pies.lnk 2012-01-07 02:57 - 2012-01-07 02:46 - 0000000 ____D C:\Program Files (x86)\bakus1 2012-01-07 02:47 - 2012-01-07 02:47 - 0000000 __SHD C:\Windows\ftpcache 2012-01-06 11:45 - 2011-02-09 12:56 - 0000000 ____D C:\Program Files (x86)\ATI Technologies 2012-01-06 10:40 - 2012-01-06 10:40 - 0000000 ____D C:\Program Files\Noviy Disk 2012-01-04 05:07 - 2012-01-04 05:06 - 0000000 ____D C:\Users\Madzia\AppData\Roaming\Google 2012-01-04 05:06 - 2012-01-04 05:06 - 0000000 ____D C:\Users\All Users\Google 2012-01-04 05:06 - 2012-01-04 05:06 - 0000000 ____D C:\ProgramData\Google 2012-01-04 05:06 - 2012-01-04 05:06 - 0000000 ____D C:\Program Files\Google 2012-01-04 05:06 - 2012-01-04 05:06 - 0000000 ____D C:\Program Files (x86)\Google 2012-01-04 05:06 - 2011-05-31 13:38 - 0414368 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-01-01 16:51 - 2011-05-03 09:22 - 1641062 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2011-12-30 15:56 - 2011-12-30 15:56 - 0000000 ____D C:\Users\All Users\McAfee 2011-12-30 15:56 - 2011-12-30 15:56 - 0000000 ____D C:\ProgramData\McAfee 2011-12-30 15:18 - 2011-12-30 15:18 - 0000000 ____D C:\Windows\System32\Macromed 2011-12-30 15:12 - 2011-12-30 15:12 - 0712520 ____A C:\Windows\Minidump\123111-26660-01.dmp 2011-12-30 10:29 - 2011-12-30 10:29 - 0702136 ____A C:\Windows\Minidump\123011-28064-01.dmp 2011-12-30 02:58 - 2011-12-30 02:58 - 0000000 ____D C:\Users\Madzia\AppData\Roaming\Tific 2011-12-30 02:58 - 2011-12-30 02:58 - 0000000 ____D C:\Users\Madzia\AppData\Local\Symantec 2011-12-29 04:11 - 2011-12-29 04:11 - 0000000 __SHD C:\Windows\System32\%APPDATA% 2011-12-22 10:51 - 2011-05-03 09:14 - 0000000 ____D C:\Program Files (x86)\Electronic Arts 2011-12-22 10:44 - 2011-05-03 09:34 - 0000000 ____D C:\Users\Madzia\Documents\Electronic Arts 2011-12-22 05:52 - 2011-12-22 05:52 - 0000000 ____D C:\Program Files (x86)\Microsoft WSE 2011-12-21 08:27 - 2011-12-21 08:27 - 0000000 ____D C:\Users\All Users\Electronic Arts 2011-12-21 08:27 - 2011-12-21 08:27 - 0000000 ____D C:\Users\All Users\EA Core 2011-12-21 08:27 - 2011-12-21 08:27 - 0000000 ____D C:\ProgramData\Electronic Arts 2011-12-21 08:27 - 2011-12-21 08:27 - 0000000 ____D C:\ProgramData\EA Core 2011-12-18 15:03 - 2009-07-13 21:08 - 0032604 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2011-12-15 06:59 - 2009-07-13 20:45 - 0271440 ____A C:\Windows\System32\FNTCACHE.DAT 2011-12-15 04:34 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\SysWOW64\pl-PL 2011-12-15 04:34 - 2009-07-13 19:20 - 0000000 ____D C:\Windows\System32\pl-PL 2011-12-11 07:17 - 2011-12-11 07:17 - 0000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_ccdcmbx64_01009.Wdf 2011-12-10 12:45 - 2011-07-02 06:53 - 0002562 ____N C:\Users\Public\Desktop\WildTangent Games App - wildgames.lnk 2011-12-10 10:28 - 2011-12-10 10:28 - 0001019 ____A C:\Users\Madzia\Desktop\Kopciuszek.lnk 2011-12-10 10:24 - 2011-12-10 08:31 - 0000000 ____D C:\Program Files\AidemMedia 2011-12-10 08:36 - 2011-12-10 08:36 - 0001044 ____A C:\Users\Madzia\Desktop\Królewna Śnieżka.lnk 2011-12-10 08:36 - 2011-12-10 08:36 - 0000000 ____D C:\Windows\AM 2011-12-04 10:52 - 2011-12-04 10:05 - 0021507 ____A C:\Users\Madzia\Desktop\hdf.docx 2011-12-02 02:26 - 2011-09-19 09:06 - 0000000 ____D C:\Filmy 2004 2011-12-02 01:49 - 2011-09-24 16:20 - 0000000 ____D C:\Filmy 2005 2011-12-01 05:34 - 2011-08-22 03:34 - 0000000 ____D C:\Filmy 2003 2011-11-30 05:17 - 2011-05-02 07:23 - 0058640 ____A C:\Users\Madzia\AppData\Local\GDIPFONTCACHEV1.DAT 2011-11-29 13:14 - 2011-11-29 13:14 - 0000000 ___HD C:\Users\All Users\CanonBJ 2011-11-29 13:14 - 2011-11-29 13:14 - 0000000 ___HD C:\ProgramData\CanonBJ 2011-11-28 03:32 - 2011-05-31 13:26 - 0000000 ____D C:\Program Files (x86)\Mozilla Firefox 2011-11-26 06:07 - 2011-06-16 02:24 - 0000000 ____D C:\Filmy 2001 2011-11-23 21:00 - 2011-12-14 08:35 - 3141632 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2011-11-23 10:42 - 2011-11-23 10:42 - 0000000 ____D C:\Users\Madzia\Documents\Pierwszaki 2011-11-19 07:07 - 2012-01-11 06:09 - 0077312 ____A (Microsoft Corporation) C:\Windows\System32\packager.dll 2011-11-19 06:06 - 2012-01-11 06:09 - 0067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2011-11-16 23:17 - 2012-01-12 10:54 - 0152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2011-11-16 23:17 - 2012-01-12 10:54 - 0095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2011-11-16 23:15 - 2012-01-12 10:54 - 0460296 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2011-11-16 23:14 - 2012-01-11 06:15 - 1739160 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll 2011-11-16 23:12 - 2012-01-12 10:54 - 0395776 ____A (Microsoft Corporation) C:\Windows\System32\webio.dll 2011-11-16 23:11 - 2012-01-12 10:54 - 0136192 ____A (Microsoft Corporation) C:\Windows\System32\sspicli.dll 2011-11-16 23:11 - 2012-01-12 10:54 - 0028672 ____A (Microsoft Corporation) C:\Windows\System32\sspisrv.dll 2011-11-16 23:11 - 2012-01-12 10:54 - 0028160 ____A (Microsoft Corporation) C:\Windows\System32\secur32.dll 2011-11-16 23:10 - 2012-01-12 10:54 - 0340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2011-11-16 23:08 - 2012-01-12 10:54 - 1446912 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll 2011-11-16 23:05 - 2012-01-12 10:54 - 0031232 ____A (Microsoft Corporation) C:\Windows\System32\lsass.exe 2011-11-16 21:41 - 2012-01-11 06:15 - 1292592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2011-11-16 21:39 - 2012-01-12 10:54 - 0314368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2011-11-16 21:39 - 2012-01-12 10:54 - 0224768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2011-11-16 21:39 - 2012-01-12 10:54 - 0022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2011-11-16 21:35 - 2012-01-12 10:54 - 0096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2011-11-15 06:07 - 2011-09-25 13:20 - 0000000 ____D C:\Filmy 2000 2011-11-14 05:50 - 2011-08-20 07:38 - 0000000 ____D C:\Filmy 2002 2011-11-10 22:41 - 2011-12-14 08:55 - 12370944 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2011-11-10 22:41 - 2011-12-14 08:55 - 0247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2011-11-10 21:50 - 2011-12-14 08:55 - 10990080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2011-11-10 21:50 - 2011-12-14 08:55 - 0176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2011-11-09 12:29 - 2009-07-13 19:20 - 0000000 ____D C:\Program Files\Common Files\System 2011-11-04 21:26 - 2011-12-14 08:55 - 1501184 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2011-11-04 21:26 - 2011-12-14 08:55 - 1197568 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2011-11-04 21:26 - 2011-12-14 08:55 - 0134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2011-11-04 21:23 - 2011-12-14 08:55 - 9332736 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2011-11-04 21:23 - 2011-12-14 08:55 - 1026560 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll 2011-11-04 21:23 - 2011-12-14 08:55 - 0703488 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2011-11-04 21:23 - 2011-12-14 08:55 - 0097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2011-11-04 21:23 - 2011-12-14 08:55 - 0082944 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2011-11-04 21:23 - 2011-12-14 08:55 - 0057856 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2011-11-04 21:22 - 2011-12-14 08:55 - 2458624 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2011-11-04 21:22 - 2011-12-14 08:55 - 0445952 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2011-11-04 21:22 - 2011-12-14 08:55 - 0256000 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2011-11-04 21:22 - 2011-12-14 08:55 - 0064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2011-11-04 21:19 - 2011-12-14 08:55 - 0012288 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2011-11-04 21:17 - 2011-12-14 08:35 - 0002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll 2011-11-04 20:35 - 2011-12-14 08:55 - 1230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2011-11-04 20:35 - 2011-12-14 08:55 - 0981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2011-11-04 20:35 - 2011-12-14 08:55 - 0132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2011-11-04 20:34 - 2011-12-14 08:55 - 5997568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2011-11-04 20:34 - 2011-12-14 08:55 - 2072576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2011-11-04 20:34 - 2011-12-14 08:55 - 0606208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll 2011-11-04 20:34 - 2011-12-14 08:55 - 0599552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2011-11-04 20:34 - 2011-12-14 08:55 - 0185856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2011-11-04 20:34 - 2011-12-14 08:55 - 0067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2011-11-04 20:34 - 2011-12-14 08:55 - 0064512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2011-11-04 20:34 - 2011-12-14 08:55 - 0048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2011-11-04 20:34 - 2011-12-14 08:55 - 0044544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2011-11-04 20:33 - 2011-12-14 08:55 - 0381440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2011-11-04 20:32 - 2011-12-14 08:55 - 0012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2011-11-04 20:30 - 2011-12-14 08:35 - 0002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2011-11-04 20:07 - 2011-12-14 08:55 - 0482816 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2011-11-04 19:28 - 2011-12-14 08:55 - 0386048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2011-11-04 19:25 - 2011-12-14 08:55 - 1638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2011-11-04 18:55 - 2011-12-14 08:55 - 1638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2011-10-31 07:41 - 2011-10-31 07:38 - 0000172 ____A C:\Users\Madzia\Desktop\nr tel.txt 2011-10-28 09:38 - 2011-10-28 09:38 - 0187904 ____A C:\Users\Madzia\Desktop\Kopia gm_matematyczny_lista1.xls 2011-10-28 09:34 - 2011-10-28 09:34 - 0000000 ___RD C:\MSOCache 2011-10-25 21:22 - 2012-01-11 06:16 - 1572864 ____A (Microsoft Corporation) C:\Windows\System32\quartz.dll 2011-10-25 21:22 - 2012-01-11 06:16 - 0366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll 2011-10-25 21:19 - 2011-12-14 08:40 - 0043520 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll 2011-10-25 20:28 - 2012-01-11 06:16 - 1328640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2011-10-25 20:28 - 2012-01-11 06:16 - 0514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2011-10-24 11:07 - 2011-10-24 11:03 - 3290789 ____A C:\Users\Madzia\Desktop\Puc, bursztyn i goA›cie.pdf ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ========================= Memory info ====================== Percentage of memory in use: 17% Total physical RAM: 3958.71 MB Available physical RAM: 3279.05 MB Total Pagefile: 3956.86 MB Available Pagefile: 3270.15 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB ======================= Partitions ========================= 1 Drive c: (Packard Bell) (Fixed) (Total:451.66 GB) (Free:8.48 GB) NTFS 2 Drive e: (PQSERVICE) (Fixed) (Total:14 GB) (Free:2.84 GB) NTFS ==>[System with boot components (obtained from reading drive)] 4 Drive g: (KINGSTON) (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32 5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 6 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Nr dysku Stan Rozmiar Wolne Dyn GPT -------- ------------- ------- ------- --- --- Dysk 0 Online 465 GB 0 B Dysk 1 Online 3827 MB 0 B Trwa opuszczanie programu DiskPart... ========================================================== Last Boot: 2011-12-01 04:25 ======================= End Of Log ==========================