Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-11-2013 01 Ran by Rafał (administrator) on KARWAT-0811C423 on 12-11-2013 19:34:45 Running from C:\Documents and Settings\Rafał\Moje dokumenty\Downloads Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe (ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe (France Telecom) C:\WINDOWS\System32\FTRTSVC.exe (Microsoft Corporation) C:\Program Files\Zune\ZuneBusEnum.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Opera Software) C:\Program Files\Opera\opera.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Alcmtr] - C:\WINDOWS\Alcmtr.exe [69632 2005-05-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [Zune Launcher] - C:\Program Files\Zune\ZuneLauncher.exe [159456 2011-08-05] (Microsoft Corporation) HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5078504 2013-03-21] (ESET) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation) HKCU\...\Winlogon: [Shell] explorer.exe, <==== ATTENTION HKU\Administrator.-0811C423\...\RunOnce: [^SetupICWDesktop] - ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=128 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {275972C0-EB14-49CB-876F-E6EC657A1D91} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3289075&CUI=UN90816846228022719&UM=1 BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl/jinstall-1_4_0_03-win.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab Hosts: 127.0.0.1 localhost Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Rafał\Dane aplikacji\Mozilla\Firefox\Profiles\cnjk7iis.default-1384278834125 FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=6.0.12.450 - C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird Chrome: ======= CHR Extension: (Google Docs) - C:\DOCUME~1\RAFA~1\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\DOCUME~1\RAFA~1\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\DOCUME~1\RAFA~1\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_1 CHR Extension: (Google Search) - C:\DOCUME~1\RAFA~1\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1 CHR Extension: (Google Wallet) - C:\DOCUME~1\RAFA~1\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (Gmail) - C:\DOCUME~1\RAFA~1\USTAWI~1\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_2 ========================== Services (Whitelisted) ================= R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1341664 2013-03-21] (ESET) R2 FTRTSVC; C:\WINDOWS\System32\FTRTSVC.exe [40960 2004-08-23] (France Telecom) S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP4c\RpcAgentSrv.exe [68760 2009-06-13] (SiSoftware) R2 ZuneBusEnum; C:\Program Files\Zune\ZuneBusEnum.exe [57056 2011-08-05] (Microsoft Corporation) S2 HDD & SSD access service; "C:\Program Files\Common Files\BinarySense\disksvc.exe" [x] R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" ==================== Drivers (Whitelisted) ==================== R1 AmdK8; C:\Windows\System32\DRIVERS\AmdK8.sys [43520 2006-06-18] (Advanced Micro Devices) S3 BVRPMPR5; C:\WINDOWS\system32\drivers\BVRPMPR5.SYS [49904 2010-03-22] (Avanquest Software) S3 e4usbaw; C:\Windows\System32\DRIVERS\e4usbaw.sys [116992 2006-09-19] (Analog Devices Inc.) R1 eamon; C:\Windows\System32\DRIVERS\eamon.sys [161368 2013-01-10] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [122240 2013-01-10] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [150080 2013-01-10] (ESET) R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [40376 2013-01-10] (ESET) R1 epfwtdi; C:\Windows\System32\DRIVERS\epfwtdi.sys [62512 2013-02-14] (ESET) S3 EverestDriver; C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [27760 2010-03-30] () S3 gdrv; C:\WINDOWS\gdrv.sys [14656 2012-10-09] (Windows (R) Codename Longhorn DDK provider) S2 IKANLOADER2; C:\Windows\System32\Drivers\e4ldr.sys [64000 2006-09-15] (Analog Deivces) R0 nvata; C:\Windows\System32\DRIVERS\nvata.sys [105472 2006-10-18] (NVIDIA Corporation) R3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [58368 2006-11-27] (NVIDIA Corporation) R3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [19968 2006-11-27] (NVIDIA Corporation) S3 PCANDIS5; C:\WINDOWS\system32\PCANDIS5.SYS [16128 2003-08-04] (Printing Communications Assoc., Inc. (PCAUSA)) S3 pwdrvio; C:\WINDOWS\system32\pwdrvio.sys [15576 2013-03-07] () S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [10200 2013-03-07] () S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP4c\WNt500x86\Sandra.sys [23112 2009-08-07] (SiSoftware) R2 zumbus; C:\Windows\System32\DRIVERS\zumbus.sys [41472 2011-08-05] (Microsoft Corporation) S3 ALSysIO; \??\C:\DOCUME~1\RAFA~1\USTAWI~1\Temp\ALSysIO.sys [x] S4 IntelIde; No ImagePath S3 PCAMPR5; \??\C:\WINDOWS\system32\PCAMPR5.SYS [x] U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation) S3 SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\idsdefs\20060106.055\symidsco.sys [x] U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-12 19:29 - 2013-11-12 19:29 - 00001780 _____ C:\Documents and Settings\Rafał\Pulpit\RKreport[0]_D_11122013_192911.txt 2013-11-12 19:29 - 2013-11-12 19:29 - 00001702 _____ C:\Documents and Settings\Rafał\Pulpit\RKreport[0]_S_11122013_192908.txt 2013-11-12 19:29 - 2013-11-12 19:29 - 00001010 _____ C:\Documents and Settings\Rafał\Pulpit\RKreport[0]_H_11122013_192917.txt 2013-11-12 19:27 - 2013-11-12 19:29 - 00000000 ____D C:\Documents and Settings\Rafał\Pulpit\RK_Quarantine 2013-11-12 19:21 - 2013-11-12 19:21 - 00000000 ____D C:\FRST 2013-11-12 18:54 - 2013-11-12 18:54 - 00000000 ____D C:\Documents and Settings\Rafał\Pulpit\Stare dane programu Firefox 2013-11-12 18:51 - 2013-11-12 18:51 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2013-11-12 18:51 - 2013-11-12 18:51 - 00000000 ____D C:\Program Files\Common Files\Java 2013-11-12 18:51 - 2013-11-12 18:51 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Java 2013-11-12 18:51 - 2013-11-12 18:50 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2013-11-12 18:51 - 2013-11-12 18:50 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2013-11-12 18:51 - 2013-11-12 18:50 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2013-11-12 18:38 - 2013-11-12 18:39 - 00002347 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk 2013-11-12 18:38 - 2013-11-12 18:38 - 00001734 _____ C:\Documents and Settings\All Users\Pulpit\Adobe Reader XI.lnk 2013-11-12 18:17 - 2013-11-12 18:20 - 00000000 ____D C:\AdwCleaner 2013-11-12 18:08 - 2013-11-12 18:08 - 00000000 ____D C:\_OTL 2013-11-10 16:08 - 2013-11-12 19:33 - 00074716 _____ C:\Documents and Settings\Rafał\Pulpit\OTL.Txt 2013-11-10 16:08 - 2013-11-10 16:08 - 00040038 _____ C:\Documents and Settings\Rafał\Pulpit\Extras.Txt 2013-11-09 14:36 - 2013-11-09 14:36 - 00131072 _____ (Microsoft Corporation) C:\Documents and Settings\All Users\Dane aplikacji\ld89fjz.dss 2013-11-06 00:09 - 2013-11-06 00:09 - 00012199 _____ C:\Documents and Settings\Rafał\.recently-used.xbel 2013-11-05 23:57 - 2013-11-06 00:00 - 00000000 ____D C:\Documents and Settings\Rafał\Pulpit\do wysłania 2013-11-03 20:10 - 2013-11-03 20:10 - 00009500 _____ C:\Documents and Settings\Rafał\Pulpit\Bez tytułu 1.odt 2013-10-21 20:30 - 2013-11-05 21:17 - 00000000 ____D C:\Documents and Settings\Rafał\Pulpit\dachy vot poprawki 2013-10-20 21:51 - 2013-10-30 22:23 - 00000000 ____D C:\Documents and Settings\Rafał\Pulpit\blachodachówka ==================== One Month Modified Files and Folders ======= 2013-11-12 19:33 - 2013-11-10 16:08 - 00074716 _____ C:\Documents and Settings\Rafał\Pulpit\OTL.Txt 2013-11-12 19:29 - 2013-11-12 19:29 - 00001780 _____ C:\Documents and Settings\Rafał\Pulpit\RKreport[0]_D_11122013_192911.txt 2013-11-12 19:29 - 2013-11-12 19:29 - 00001702 _____ C:\Documents and Settings\Rafał\Pulpit\RKreport[0]_S_11122013_192908.txt 2013-11-12 19:29 - 2013-11-12 19:29 - 00001010 _____ C:\Documents and Settings\Rafał\Pulpit\RKreport[0]_H_11122013_192917.txt 2013-11-12 19:29 - 2013-11-12 19:27 - 00000000 ____D C:\Documents and Settings\Rafał\Pulpit\RK_Quarantine 2013-11-12 19:29 - 2012-10-07 21:21 - 00000000 ____D C:\Documents and Settings\Rafał\Pulpit 2013-11-12 19:21 - 2013-11-12 19:21 - 00000000 ____D C:\FRST 2013-11-12 19:17 - 2012-10-08 18:09 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat 2013-11-12 19:00 - 2012-10-07 21:17 - 01647832 _____ C:\WINDOWS\WindowsUpdate.log 2013-11-12 18:54 - 2013-11-12 18:54 - 00000000 ____D C:\Documents and Settings\Rafał\Pulpit\Stare dane programu Firefox 2013-11-12 18:51 - 2013-11-12 18:51 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2013-11-12 18:51 - 2013-11-12 18:51 - 00000000 ____D C:\Program Files\Common Files\Java 2013-11-12 18:51 - 2013-11-12 18:51 - 00000000 ____D C:\Documents and Settings\All Users\Menu Start\Programy\Java 2013-11-12 18:51 - 2012-10-07 23:10 - 00000000 ___RD C:\Documents and Settings\All Users\Menu Start\Programy 2013-11-12 18:50 - 2013-11-12 18:51 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2013-11-12 18:50 - 2013-11-12 18:51 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2013-11-12 18:50 - 2013-11-12 18:51 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2013-11-12 18:50 - 2012-10-18 16:16 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2013-11-12 18:50 - 2012-10-07 21:25 - 00000000 ____D C:\Program Files\Java 2013-11-12 18:39 - 2013-11-12 18:38 - 00002347 _____ C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk 2013-11-12 18:38 - 2013-11-12 18:38 - 00001734 _____ C:\Documents and Settings\All Users\Pulpit\Adobe Reader XI.lnk 2013-11-12 18:38 - 2012-10-18 16:12 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-11-12 18:38 - 2012-10-18 16:12 - 00000000 ____D C:\Program Files\Adobe 2013-11-12 18:38 - 2012-10-12 16:02 - 00000000 ____D C:\Documents and Settings\All Users\Dane aplikacji\Adobe 2013-11-12 18:38 - 2012-10-07 23:10 - 00000000 ____D C:\Documents and Settings\All Users\Pulpit 2013-11-12 18:37 - 2012-10-18 16:22 - 00000000 ____D C:\Documents and Settings\Rafał\Ustawienia lokalne\Dane aplikacji\Adobe 2013-11-12 18:23 - 2012-11-23 00:17 - 00000260 _____ C:\WINDOWS\Tasks\WGASetup.job 2013-11-12 18:23 - 2012-10-28 17:35 - 00001030 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-12 18:23 - 2012-10-07 23:13 - 00000159 _____ C:\WINDOWS\wiadebug.log 2013-11-12 18:23 - 2012-10-07 23:13 - 00000050 _____ C:\WINDOWS\wiaservc.log 2013-11-12 18:22 - 2012-10-07 21:20 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-11-12 18:21 - 2012-10-07 21:21 - 00000188 ___SH C:\Documents and Settings\Rafał\ntuser.ini 2013-11-12 18:21 - 2012-10-07 21:20 - 00032426 _____ C:\WINDOWS\SchedLgU.Txt 2013-11-12 18:20 - 2013-11-12 18:17 - 00000000 ____D C:\AdwCleaner 2013-11-12 18:20 - 2012-10-07 21:21 - 00000000 ___HD C:\Documents and Settings\Rafał\Ustawienia lokalne\Dane aplikacji 2013-11-12 18:19 - 2012-10-07 23:10 - 00000000 __RHD C:\Documents and Settings\All Users\Dane aplikacji 2013-11-12 18:13 - 2012-10-28 17:35 - 00001034 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-12 18:08 - 2013-11-12 18:08 - 00000000 ____D C:\_OTL 2013-11-12 18:08 - 2013-03-30 15:51 - 00000000 ____D C:\Documents and Settings\Rafał\Pulpit\BitComet 2013-11-12 18:08 - 2012-10-07 21:21 - 00000000 __RHD C:\Documents and Settings\Rafał\Dane aplikacji 2013-11-12 18:05 - 2001-07-22 01:17 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl 2013-11-10 16:08 - 2013-11-10 16:08 - 00040038 _____ C:\Documents and Settings\Rafał\Pulpit\Extras.Txt 2013-11-09 17:11 - 2012-11-15 19:27 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB952004$ 2013-11-09 16:20 - 2012-10-07 23:05 - 00000000 ____D C:\WINDOWS\security 2013-11-09 14:37 - 2012-10-07 21:21 - 00000000 ___RD C:\Documents and Settings\Rafał\Menu Start\Programy\Autostart 2013-11-09 14:36 - 2013-11-09 14:36 - 00131072 _____ (Microsoft Corporation) C:\Documents and Settings\All Users\Dane aplikacji\ld89fjz.dss 2013-11-06 00:09 - 2013-11-06 00:09 - 00012199 _____ C:\Documents and Settings\Rafał\.recently-used.xbel 2013-11-06 00:09 - 2012-10-07 21:21 - 00000000 ____D C:\Documents and Settings\Rafał 2013-11-06 00:00 - 2013-11-05 23:57 - 00000000 ____D C:\Documents and Settings\Rafał\Pulpit\do wysłania 2013-11-05 21:17 - 2013-10-21 20:30 - 00000000 ____D C:\Documents and Settings\Rafał\Pulpit\dachy vot poprawki 2013-11-03 20:10 - 2013-11-03 20:10 - 00009500 _____ C:\Documents and Settings\Rafał\Pulpit\Bez tytułu 1.odt 2013-10-30 22:23 - 2013-10-20 21:51 - 00000000 ____D C:\Documents and Settings\Rafał\Pulpit\blachodachówka 2013-10-27 10:49 - 2012-10-07 23:11 - 01254156 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2013-10-27 10:49 - 2001-10-26 19:15 - 00555118 _____ C:\WINDOWS\system32\perfh015.dat 2013-10-27 10:49 - 2001-10-26 19:15 - 00104274 _____ C:\WINDOWS\system32\perfc015.dat Files to move or delete: ==================== C:\Documents and Settings\Rafał\Dane aplikacji\settings.ini Some content of TEMP: ==================== C:\Documents and Settings\Rafał\Ustawienia lokalne\Temp\ntdll_dump.dll C:\Documents and Settings\Rafał\Ustawienia lokalne\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe [2004-08-03 23:44] - [2008-04-14 22:51] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a C:\Windows\System32\winlogon.exe [2004-08-03 23:44] - [2008-04-14 22:51] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 C:\Windows\System32\svchost.exe [2004-08-03 23:44] - [2008-04-14 22:51] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce C:\Windows\System32\services.exe [2004-08-03 23:44] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f C:\Windows\System32\User32.dll [2004-08-03 23:44] - [2008-04-14 22:50] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 C:\Windows\System32\userinit.exe [2004-08-03 23:44] - [2008-04-14 22:51] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 C:\Windows\System32\Drivers\volsnap.sys [2004-08-03 23:36] - [2008-04-14 21:31] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================