Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-10-2013 01 Ran by Tomek (administrator) on TOMEK-9E0E97734 on 26-10-2013 02:59:55 Running from G:\ Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 7 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\WINDOWS\system32\savedump.exe (AMD) C:\Program Files\AMD\RAIDXpert\bin\RAIDXpertService.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Program Files\AMD\RAIDXpert\bin\RAIDXpert.exe () C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jqs.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe (Prolific Technology Inc.) C:\WINDOWS\system32\IoctlSvc.exe () C:\WINDOWS\system32\PnkBstrA.exe () C:\WINDOWS\system32\PnkBstrB.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe () C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe () C:\Program Files\ASUS\Ai Suite\Q-Button\QButton.exe (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe (AlcaTech) C:\WINDOWS\system32\mmrtkrnl.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Microsoft Corporation) C:\Program Files\Wcescomm.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\PROGRA~1\rapimgr.exe () C:\WINDOWS\system32\WinMsgBalloonServer.exe () C:\WINDOWS\system32\WinMsgBalloonClient.exe (TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Six Engine] - C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe [5782528 2009-07-08] () HKLM\...\Run: [ASUS Update Checker] - C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe [114688 2008-12-11] () HKLM\...\Run: [Ai Nap] - C:\Program Files\ASUS\Ai Suite\Q-Button\QButton.exe [1968640 2009-06-02] () HKLM\...\Run: [QFan Help] - C:\Program Files\ASUS\Ai Suite\QFan3\QFanHelp.exe [601088 2009-07-01] () HKLM\...\Run: [Cpu Level Up help] - C:\Program Files\ASUS\Ai Suite\CpuLevelUpHelp.exe [881152 2007-11-30] () HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [nwiz] - nwiz.exe /install HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696 2011-04-08] (Sun Microsystems, Inc.) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-08-27] (Apple Inc.) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [74752 2011-12-09] (Nullsoft, Inc.) HKLM\...\Run: [Realtime Audio Engine] - "mmrtkrnl.exe" /i HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [421888 2011-07-05] (Apple Inc.) HKLM\...\Run: [NeroFilterCheck] - C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [NBKeyScan] - C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2221352 2008-02-18] (Nero AG) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [421776 2012-09-09] (Apple Inc.) HKLM\...\Run: [NeroCheck] - C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [17881600 2009-05-21] (Realtek Semiconductor Corp.) HKLM\...\Run: [tuto4pc_pl_6] - [x] HKCU\...\Run: [RGSC] - C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe [306088 2010-01-30] (Take-Two Interactive Software, Inc.) HKCU\...\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation) HKCU\...\Run: [Gadu-Gadu] - C:\Program Files\Gadu-Gadu\gg.exe [2127296 2008-03-20] (Gadu-Gadu S.A.) HKCU\...\Run: [Nowe Gadu-Gadu] - C:\Program Files\Nowe Gadu-Gadu\gg.exe [11539048 2009-10-28] (GG Network S.A.) HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2741616 2011-03-04] (Hewlett-Packard Company) HKCU\...\Run: [Skymonk2] - C:\Documents and Settings\Tomek\Ustawienia lokalne\Dane aplikacji\Skymonk2\skymonk2.exe [520336 2013-08-30] () HKCU\...\Run: [H/PC Connection Agent] - C:\Program Files\Wcescomm.exe [1289000 2006-11-13] (Microsoft Corporation) HKCU\...\Run: [Ovmyvav] - "C:\Documents and Settings\Tomek\Dane aplikacji\Vepai\yxhi.exe" HKCU\...\RunOnce: [WiseStubReboot] - MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I "C:\Program Files\Common Files\Wise Installation Wizard\WISDD1865F0AD7340FBB23E1822E02396FF_9_09_0203.MSI" TRANSFORMS="C:\Program Files\Common Files\Wise Installation Wizard\WISDD1865F0AD7340FBB23E1822E02396FF_9_09_0203.MST" WISE_SETUP_EXE_PATH="e:\driver\common\win2k_xp\PhysX_9.09.0203_SystemSoftware.exe" [41984 2010-01-29] () HKU\Default User\...\RunOnce: [nltide_2] - regsvr32 /s /n /i:U shell32 HKU\Default User\...\RunOnce: [nltide_3] - rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N Lsa: [Authentication Packages] msv1_0 nwprovau Startup: C:\Documents and Settings\Tomek\Menu Start\Programy\Autostart\zjl7bdod.lnk ShortcutTarget: zjl7bdod.lnk -> C:\DOCUME~1\ALLUSE~1\DANEAP~1\dodb7ljz.plz (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKLM - DefaultScope value is missing. BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 01 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.3 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Tomek\Dane aplikacji\Mozilla\Firefox\Profiles\4lwtnxww.default-1381812255453 FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=6.0.11.2852 - C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nppl3260;version=6.0.12.46 - C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1662 - C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.46 - C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff FF Extension: Java Quick Starter - C:\Program Files\Java\jre6\lib\deploy\jqs\ff ========================== Services (Whitelisted) ================= R2 6to4; C:\Windows\System32\6to4svc.dll [100352 2008-04-14] (Microsoft Corporation) R2 AMD_RAIDXpert; C:\Program Files\AMD\RAIDXpert\bin\RAIDXpertService.exe [122880 2009-03-16] (AMD) S4 AODService; C:\Program Files\AMD\OverDrive\AODAssist.exe [124256 2009-04-22] () R2 AsSysCtrlService; C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [90112 2009-04-02] () R2 NWCWorkstation; C:\Windows\System32\nwwks.dll [65536 2008-04-14] (Microsoft Corporation) R2 NwSapAgent; C:\Windows\System32\ipxsap.dll [66560 2001-10-26] (Microsoft Corporation) R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [75064 2010-10-16] () R2 PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [215128 2011-06-06] () R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1699168 2012-10-15] (TuneUp Software) R2 JavaQuickStarterService; "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" ==================== Drivers (Whitelisted) ==================== S3 Ambfilt; C:\Windows\System32\drivers\Ambfilt.sys [1684736 2008-08-05] (Creative) R1 AmdPPM; C:\Windows\System32\DRIVERS\AmdPPM.sys [33792 2007-04-16] (Advanced Micro Devices) R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12400 2007-12-17] () S3 ddsxeiservice; C:\Program Files\sXe Injected\ddsxei.sys [92800 2011-09-01] () R1 FileDisk; C:\Windows\System32\Drivers\FileDisk.sys [12928 2005-10-16] (Bo Brantén) R0 Imagedrv; C:\Windows\System32\DRIVERS\imagedrv.sys [89184 2003-03-29] (Ahead Software AG and its licensors) R0 MMRTKRNL; C:\Windows\System32\drivers\mmrtkrnl.sys [94624 2008-12-02] (AlcaTech) S3 MobileAdapter; C:\Windows\System32\DRIVERS\hmumdm.sys [88960 2007-03-27] (Huawei Technologies Co., Ltd.) S3 Monfilt; C:\Windows\System32\drivers\Monfilt.sys [1389056 2006-01-04] (Creative Technology Ltd.) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] () S3 nm; C:\Windows\System32\DRIVERS\NMnt.sys [40320 2008-04-14] (Microsoft Corporation) R2 NwlnkIpx; C:\Windows\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-14] (Microsoft Corporation) R2 NwlnkNb; C:\Windows\System32\DRIVERS\nwlnknb.sys [63232 2001-08-17] (Microsoft Corporation) R2 NwlnkSpx; C:\Windows\System32\DRIVERS\nwlnkspx.sys [55936 2001-08-17] (Microsoft Corporation) R3 NWRDR; C:\Windows\System32\DRIVERS\nwrdr.sys [163584 2008-04-14] (Microsoft Corporation) S3 PnkBstrK; C:\WINDOWS\system32\drivers\PnkBstrK.sys [139128 2011-06-06] () S3 RTLTEAMING; C:\Windows\System32\DRIVERS\RTLTEAMING.SYS [25984 2008-01-23] (Realtek Semiconductor Corporation) S3 RTLVLAN; C:\Windows\System32\DRIVERS\RTLVLAN.SYS [17408 2008-05-26] (Realtek Semiconductor Corporation ) R2 RtNdPt5x; C:\Windows\System32\DRIVERS\RtNdPt5x.sys [22016 2008-07-09] (Realtek Semiconductor Corporation ) R0 Si3112; C:\Windows\System32\Drivers\Si3112.sys [62208 2008-05-02] (Silicon Image, Inc.) R1 Tcpip6; C:\Windows\System32\DRIVERS\tcpip6.sys [225664 2008-04-14] (Microsoft Corporation) R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-09-19] (TuneUp Software) S3 wceusbsh; C:\Windows\System32\DRIVERS\wceusbsh.sys [31872 2008-04-14] (Microsoft Corporation) S3 ZDPSp50; C:\Windows\System32\Drivers\ZDPSp50.sys [17664 2004-10-25] (Printing Communications Assoc., Inc. (PCAUSA)) S4 IntelIde; No ImagePath U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation) U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-25 16:58 - 2013-10-25 16:58 - 00010846 _____ C:\UsbFix [Listing 1 ] TOMEK-9E0E97734.txt 2013-10-25 16:58 - 2013-10-25 16:58 - 00000000 ____D C:\UsbFix 2013-10-25 00:55 - 2013-10-25 00:55 - 00065536 _____ C:\WINDOWS\Minidump\Mini102513-01.dmp 2013-10-24 00:34 - 2013-10-24 00:34 - 00065536 _____ C:\WINDOWS\Minidump\Mini102413-01.dmp 2013-10-15 15:00 - 2013-10-15 15:00 - 00000000 ____D C:\WINDOWS\pss 2013-10-15 06:52 - 2013-10-15 06:54 - 00000000 ____D C:\AdwCleaner 2013-10-06 03:17 - 2013-10-06 03:17 - 00000000 ____D C:\FRST 2013-10-06 03:02 - 2013-10-25 00:54 - 2145386496 _____ C:\WINDOWS\MEMORY.DMP ==================== One Month Modified Files and Folders ======= 2013-10-26 03:00 - 2011-07-03 09:42 - 00000462 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{14A46570-82F3-4301-878F-3787BEFE62C8}.job 2013-10-26 02:57 - 2010-01-29 17:14 - 00210919 _____ C:\WINDOWS\system32\nvapps.xml 2013-10-26 02:56 - 2011-01-01 20:04 - 00001030 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-26 02:56 - 2010-01-29 17:49 - 00000159 _____ C:\WINDOWS\wiadebug.log 2013-10-26 02:56 - 2010-01-29 17:49 - 00000050 _____ C:\WINDOWS\wiaservc.log 2013-10-26 02:56 - 2010-01-29 16:53 - 00409024 _____ C:\WINDOWS\WindowsUpdate.log 2013-10-26 02:55 - 2010-01-29 16:56 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-10-25 17:17 - 2012-11-21 21:56 - 00065536 _____ C:\WINDOWS\system32\config\TuneUp.evt 2013-10-25 17:17 - 2010-01-29 16:56 - 00032492 _____ C:\WINDOWS\SchedLgU.Txt 2013-10-25 17:13 - 2012-03-24 21:11 - 00000000 ____D C:\Documents and Settings\Tomek\Dane aplikacji\Winamp 2013-10-25 17:13 - 2010-01-29 20:04 - 00000203 _____ C:\WINDOWS\NeroDigital.ini 2013-10-25 16:58 - 2013-10-25 16:58 - 00010846 _____ C:\UsbFix [Listing 1 ] TOMEK-9E0E97734.txt 2013-10-25 16:58 - 2013-10-25 16:58 - 00000000 ____D C:\UsbFix 2013-10-25 16:49 - 2011-01-01 20:04 - 00001034 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-25 07:37 - 2010-01-29 17:47 - 00376616 _____ C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat 2013-10-25 07:37 - 2010-01-29 16:56 - 00000000 ___HD C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji 2013-10-25 07:32 - 2012-12-06 16:32 - 00000930 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-10-25 00:55 - 2013-10-25 00:55 - 00065536 _____ C:\WINDOWS\Minidump\Mini102513-01.dmp 2013-10-25 00:55 - 2010-06-26 00:24 - 00000000 ____D C:\WINDOWS\Minidump 2013-10-25 00:54 - 2013-10-06 03:02 - 2145386496 _____ C:\WINDOWS\MEMORY.DMP 2013-10-24 00:34 - 2013-10-24 00:34 - 00065536 _____ C:\WINDOWS\Minidump\Mini102413-01.dmp 2013-10-24 00:03 - 2013-09-22 01:48 - 00555661 _____ C:\WINDOWS\setupapi.log 2013-10-24 00:03 - 2010-01-29 17:46 - 00257950 _____ C:\WINDOWS\setupact.log 2013-10-24 00:00 - 2001-07-21 22:17 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl 2013-10-15 15:00 - 2013-10-15 15:00 - 00000000 ____D C:\WINDOWS\pss 2013-10-15 07:20 - 2010-01-29 17:41 - 00000000 ____D C:\Program Files\D-Tools 2013-10-15 07:00 - 2010-01-29 17:46 - 00000000 __RHD C:\Documents and Settings\All Users\Dane aplikacji 2013-10-15 06:54 - 2013-10-15 06:52 - 00000000 ____D C:\AdwCleaner 2013-10-15 06:54 - 2010-01-29 16:57 - 00000000 __RHD C:\Documents and Settings\Tomek\Dane aplikacji 2013-10-15 06:54 - 2010-01-29 16:57 - 00000000 ___RD C:\Documents and Settings\Tomek\Menu Start\Programy 2013-10-15 06:54 - 2010-01-29 16:57 - 00000000 ___HD C:\Documents and Settings\Tomek\Ustawienia lokalne\Dane aplikacji 2013-10-15 06:53 - 2010-01-29 17:46 - 00000000 ___RD C:\Documents and Settings\All Users\Menu Start\Programy 2013-10-15 06:53 - 2010-01-29 16:56 - 00000000 ___HD C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji 2013-10-15 06:43 - 2010-01-30 00:00 - 00000000 ____D C:\Program Files\Free Download Manager 2013-10-15 06:43 - 2010-01-29 16:57 - 00000000 ____D C:\Documents and Settings\Tomek\Pulpit 2013-10-15 06:38 - 2013-02-24 09:57 - 00001612 _____ C:\Documents and Settings\Tomek\Pulpit\Wyczyść rejestr za darmo!.lnk 2013-10-15 06:34 - 2010-01-29 17:11 - 00000177 ____H C:\dvmexp.idx 2013-10-15 06:33 - 2010-01-29 16:57 - 00000000 ___RD C:\Documents and Settings\Tomek\Menu Start 2013-10-15 06:27 - 2010-01-29 21:12 - 00000000 ____D C:\Program Files\Winamp 2013-10-14 08:38 - 2010-01-29 16:51 - 00054220 _____ C:\WINDOWS\wmsetup.log 2013-10-14 08:31 - 2010-01-29 17:42 - 00018080 _____ C:\Documents and Settings\Tomek\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2013-10-14 08:12 - 2011-01-01 20:03 - 00000000 ____D C:\Documents and Settings\Tomek\Ustawienia lokalne\Dane aplikacji\Google 2013-10-14 08:11 - 2010-01-29 16:57 - 00000000 ___RD C:\Documents and Settings\Tomek\Menu Start\Programy\Autostart 2013-10-14 08:11 - 2010-01-29 16:57 - 00000000 ____D C:\Documents and Settings\Tomek 2013-10-14 08:08 - 2011-07-25 14:15 - 00000000 ____D C:\Program Files\Metin2_PL 2013-10-14 08:02 - 2010-01-29 17:47 - 01281234 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2013-10-14 08:02 - 2001-10-26 16:15 - 00564674 _____ C:\WINDOWS\system32\perfh015.dat 2013-10-14 08:02 - 2001-10-26 16:15 - 00109634 _____ C:\WINDOWS\system32\perfc015.dat 2013-10-06 03:17 - 2013-10-06 03:17 - 00000000 ____D C:\FRST 2013-10-06 02:42 - 2010-01-29 17:07 - 00000000 ___HD C:\ASUS.000 2013-10-06 01:51 - 2010-01-29 16:57 - 00000188 ___SH C:\Documents and Settings\Tomek\ntuser.ini Files to move or delete: ==================== C:\Documents and Settings\Tomek\counter strike 1 6 completo, instalador cs16_full_v26-dz(5).exe Some content of TEMP: ==================== C:\Documents and Settings\Tomek\Ustawienia lokalne\Temp\Quarantine.exe C:\Documents and Settings\Tomek\Ustawienia lokalne\Temp\uninst1.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe [2013-09-22 01:41] - [2008-04-14 22:51] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\Windows\System32\winlogon.exe [2013-09-22 01:41] - [2008-04-14 22:51] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\Windows\System32\svchost.exe [2013-09-22 01:41] - [2008-04-14 22:51] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\Windows\System32\services.exe [2013-09-22 01:41] - [2008-04-14 22:51] - 0109056 ____A (Microsoft Corporation) 3e3ae424e27c4cefe4cab368c7b570ea C:\Windows\System32\User32.dll [2013-09-22 01:41] - [2008-04-14 22:50] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\Windows\System32\userinit.exe [2013-09-22 01:41] - [2008-04-14 22:51] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\Windows\System32\Drivers\volsnap.sys [2013-09-22 01:41] - [2008-04-14 21:31] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================