Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-12-2013 01 Ran by kixx (administrator) on KIX on 30-12-2013 13:58:20 Running from D:\Documents and Settings\kixx\Pulpit\FRST\frst Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polish Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) D:\WINDOWS\system32\nvsvc32.exe (HP) D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (Hewlett-Packard Company) D:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company) D:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Microsoft Corporation) C:\BBB\instalki\Office12\GrooveMonitor.exe (Adobe Systems Incorporated) C:\BBB\instalki\Adobe\Reader\reader_sl.exe (Adobe Systems Incorporated) D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Sun Microsystems, Inc.) D:\Program Files\Common Files\Java\Java Update\jusched.exe (Oracle Corporation) D:\Program Files\Java\jre7\bin\jqs.exe (Microsoft Corporation) D:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) D:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) D:\WINDOWS\system32\wuauclt.exe (Mozilla Corporation) D:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) D:\WINDOWS\system32\wscntfy.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [nwiz] - D:\Program Files\NVIDIA Corporation\nView\nwiz.exe [1657376 2009-07-08] () HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [HPDJ Taskbar Utility] - D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe [172032 2004-03-04] (HP) HKLM\...\Run: [HP Component Manager] - D:\Program Files\HP\hpcoretech\hpcmpmgr.exe [241664 2004-05-12] (Hewlett-Packard Company) HKLM\...\Run: [HP Software Update] - D:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe [49152 2004-02-18] (Hewlett-Packard Company) HKLM\...\Run: [GrooveMonitor] - C:\BBB\instalki\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\BBB\instalki\Adobe\Reader\reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [Cmaudio] - RunDll32 cmicnfg.cpl,CMICtrlWnd HKLM\...\Run: [SunJavaUpdateSched] - D:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.) Winlogon\Notify\Antiwpa: D:\Windows\system32\antiwpa.dll () MountPoints2: {9985a6d6-9adf-11e2-ae31-000b6a887a5f} - H:\Install.exe HKU\Administrator\...\RunOnce: [TSClientMSIUninstaller] - cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" HKU\Administrator\...\RunOnce: [TSClientAXDisabler] - cmd.exe /C "%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat" Lsa: [Notification Packages] scecli scecli ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =,0.html?p=005 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\BBB\instalki\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - D:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - D:\WINDOWS\system32\shell32.dll (Microsoft Corporation) DPF: {17492023-C23A-453E-A040-C7C580BBF700} DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - D:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company) Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\BBB\instalki\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: D:\Documents and Settings\kixx\Dane aplikacji\Mozilla\Firefox\Profiles\ih21z9tp.default FF SelectedSearchEngine: Google FF Homepage: FF NetworkProxy: "type", 0 FF Plugin: - D:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF Plugin:,version=10.11.2 - D:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin:,version=1.0 - d:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF Plugin:,version=3.5 - D:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: - D:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Extension: Live HTTP Headers - D:\Documents and Settings\kixx\Dane aplikacji\Mozilla\Firefox\Profiles\ih21z9tp.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} FF Extension: DownloadHelper - D:\Documents and Settings\kixx\Dane aplikacji\Mozilla\Firefox\Profiles\ih21z9tp.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: Menu Editor - D:\Documents and Settings\kixx\Dane aplikacji\Mozilla\Firefox\Profiles\ih21z9tp.default\Extensions\{EDA7B1D7-F793-4e03-B074-E6F303317FB0} FF Extension: 1-Click Dailymotion Video Downloader - D:\Documents and Settings\kixx\Dane aplikacji\Mozilla\Firefox\Profiles\ih21z9tp.default\Extensions\ FF Extension: FoxFilter - D:\Documents and Settings\kixx\Dane aplikacji\Mozilla\Firefox\Profiles\ih21z9tp.default\Extensions\ FF Extension: RAMBack - D:\Documents and Settings\kixx\Dane aplikacji\Mozilla\Firefox\Profiles\ih21z9tp.default\Extensions\ FF Extension: Test Pilot - D:\Documents and Settings\kixx\Dane aplikacji\Mozilla\Firefox\Profiles\ih21z9tp.default\Extensions\ FF Extension: Procon Latte Content Filter - D:\Documents and Settings\kixx\Dane aplikacji\Mozilla\Firefox\Profiles\ih21z9tp.default\Extensions\{9D6218B8-03C7-4b91-AA43-680B305DD35C}.xpi FF Extension: Adblock Plus - D:\Documents and Settings\kixx\Dane aplikacji\Mozilla\Firefox\Profiles\ih21z9tp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - D:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - D:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF StartMenuInternet: FIREFOX.EXE - C:\BBB\instalki\FF4\firefox.exe ========================== Services (Whitelisted) ================= S3 Microsoft Office Groove Audit Service; C:\BBB\instalki\Office12\GrooveAuditService.exe [65824 2006-10-26] (Microsoft Corporation) S4 MSSQLServerADHelper; D:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45272 2005-10-14] (Microsoft Corporation) R2 JavaQuickStarterService; "D:\Program Files\Java\jre7\bin\jqs.exe" -service -config "D:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" ==================== Drivers (Whitelisted) ==================== R3 cmuda; D:\Windows\System32\drivers\cmuda.sys [754560 2003-10-17] (C-Media Inc) R3 gameenum; D:\Windows\System32\DRIVERS\gameenum.sys [10624 2008-04-13] (Microsoft Corporation) R3 GT680x; D:\Windows\System32\Drivers\gt680x.sys [17504 2003-02-19] ( ) S3 hitmanpro37; D:\WINDOWS\system32\drivers\hitmanpro37.sys [30976 2013-12-27] () R1 ISODrive; C:\BBB\instalki\UltraISO\drivers\ISODrive.sys [82320 2010-01-29] (EZB Systems, Inc.) R3 SISNIC; D:\Windows\System32\DRIVERS\sisnic.sys [32768 2004-08-03] (SiS Corporation) S4 aswSP; No ImagePath S4 IntelIde; No ImagePath U5 ScsiPort; D:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-30 13:47 - 2013-12-30 13:50 - 00000000 ____D D:\AdwCleaner 2013-12-30 13:42 - 2013-12-30 13:42 - 00000000 ____D D:\Documents and Settings\kixx\Dane aplikacji\ 2013-12-29 20:38 - 2013-12-29 20:38 - 00000000 ____D D:\TDSSKiller_Quarantine 2013-12-29 18:17 - 2013-12-30 13:54 - 00000000 ____D D:\Documents and Settings\kixx\Pulpit\FRST 2013-12-29 18:16 - 2013-12-30 13:42 - 00000000 ____D D:\FRST 2013-12-28 22:43 - 2013-12-30 00:12 - 00022777 _____ D:\WINDOWS\setupapi.log 2013-12-28 20:22 - 2013-12-28 21:11 - 137189352 _____ (AVG Technologies) D:\Documents and Settings\kixx\Pulpit\avg_free_x86_all_2014_4259a6848.exe 2013-12-27 23:42 - 2013-12-27 23:42 - 00000000 ____D D:\Documents and Settings\All Users\Menu Start\Programy\Metin2 2013-12-27 22:42 - 2013-12-27 22:42 - 00001612 _____ D:\WINDOWS\wmsetup.log 2013-12-27 20:35 - 2013-12-27 21:05 - 00000000 ____D D:\Documents and Settings\kixx\Moje dokumenty\Gameforge Live 2013-12-27 20:34 - 2013-12-27 20:34 - 00000000 ____D D:\Documents and Settings\kixx\Ustawienia lokalne\Dane aplikacji\Gameforge4d 2013-12-27 20:33 - 2013-12-27 20:33 - 00000000 ____D D:\Program Files\GameforgeLive 2013-12-27 20:33 - 2013-12-27 20:33 - 00000000 ____D D:\Documents and Settings\All Users\Menu Start\Programy\Gameforge Live 2013-12-27 17:50 - 2013-12-27 17:50 - 00012872 _____ (SurfRight B.V.) D:\WINDOWS\system32\bootdelete.exe 2013-12-27 17:30 - 2013-12-27 17:30 - 00000436 _____ D:\WINDOWS\system32\.crusader 2013-12-27 17:18 - 2013-12-27 17:54 - 00030976 _____ D:\WINDOWS\system32\Drivers\hitmanpro37.sys 2013-12-27 17:17 - 2013-12-27 17:17 - 00000000 ____D D:\Program Files\HitmanPro 2013-12-27 17:15 - 2013-12-27 17:29 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\HitmanPro 2013-12-27 17:01 - 2013-12-27 17:01 - 00490648 _____ (AVAST Software) D:\Documents and Settings\kixx\Pulpit\avastclear.exe 2013-12-27 16:57 - 2013-12-27 17:16 - 91412976 _____ (AVAST Software) D:\Documents and Settings\kixx\Pulpit\avast_free_antivirus_setups.exe 2013-12-27 16:52 - 2013-12-30 00:18 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\AVAST Software 2013-12-27 11:18 - 2013-12-30 13:57 - 00052402 _____ D:\WINDOWS\WindowsUpdate.log 2013-12-25 17:31 - 2013-12-25 17:32 - 00000000 ____D D:\Documents and Settings\kixx\Menu Start\Programy\CodeBlocks 2013-12-25 17:31 - 2013-12-25 17:31 - 00000768 _____ D:\Documents and Settings\kixx\Pulpit\CodeBlocks.lnk 2013-12-25 17:31 - 2013-12-25 17:31 - 00000000 ____D D:\Documents and Settings\kixx\Moje dokumenty\Nowy folder (4) 2013-12-24 22:45 - 2013-12-24 22:45 - 00000000 ____D D:\Program Files\ 2013-12-24 22:40 - 2013-12-24 22:40 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\Real 2013-12-24 22:29 - 2010-12-28 13:38 - 00000000 ____D D:\Documents and Settings\kixx\Pulpit\Camera 2013-12-24 22:13 - 2013-12-24 22:13 - 00000000 ____D D:\Program Files\Common Files\InstallShield 2013-12-24 22:04 - 2013-12-24 22:04 - 00000000 ____D D:\Documents and Settings\kixx\Dane aplikacji\InstallShield 2013-12-24 21:56 - 2013-12-27 17:18 - 00000000 ____D D:\Documents and Settings\kixx\Dane aplikacji\Skype 2013-12-24 21:56 - 2013-12-27 17:15 - 00002211 _____ D:\Documents and Settings\All Users\Pulpit\Skype.lnk 2013-12-24 21:56 - 2013-12-24 21:56 - 00000000 ____D D:\Program Files\Common Files\Skype 2013-12-24 21:56 - 2013-12-24 21:56 - 00000000 ____D D:\Documents and Settings\All Users\Menu Start\Programy\Skype 2013-12-24 21:55 - 2013-12-24 21:56 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\Skype 2013-12-24 17:04 - 2013-12-25 18:29 - 00000000 ____D D:\Documents and Settings\kixx\Moje dokumenty\Dev 2013-12-24 16:54 - 2013-12-24 16:54 - 00000677 _____ D:\Documents and Settings\kixx\Pulpit\Dev-C++.lnk 2013-12-24 16:54 - 2013-12-24 16:54 - 00000000 ____D D:\Documents and Settings\All Users\Menu Start\Programy\Bloodshed Dev-C++ 2013-12-24 16:53 - 2013-12-24 16:53 - 00000000 ____D D:\Documents and Settings\kixx\Moje dokumenty\Nowy folder (3) 2013-12-24 16:44 - 2013-12-24 16:46 - 24952118 _____ D:\Documents and Settings\kixx\Pulpit\Dev-Cpp 5.5.3 MinGW 4.7.2 Setup.exe 2013-12-24 14:56 - 2013-12-28 00:06 - 00000000 ____D D:\Documents and Settings\kixx\Pulpit\PO 2013-12-23 20:13 - 2013-12-23 20:13 - 00000000 ____D D:\Program Files\PlayReady 2013-12-23 19:42 - 2013-12-23 19:45 - 18277248 _____ (pdfforge ) D:\Documents and Settings\kixx\Pulpit\PDFCreator-1_7_2_setup.exe 2013-12-23 12:54 - 2013-12-27 12:11 - 00000000 ____D D:\Documents and Settings\kixx\Dane aplikacji\ipla 2013-12-23 12:54 - 2013-12-25 18:46 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\ipla 2013-12-23 12:53 - 2013-12-23 12:54 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\RDRM 2013-12-23 12:53 - 2013-12-23 12:53 - 00000626 _____ D:\Documents and Settings\All Users\Pulpit\ipla.lnk 2013-12-23 12:53 - 2013-12-23 12:53 - 00000000 ____D D:\Documents and Settings\All Users\Menu Start\Programy\ipla 2013-12-23 12:52 - 2013-12-23 12:54 - 00000000 ____D D:\Program Files\ipla 2013-12-23 12:52 - 2013-12-23 12:52 - 01700352 _____ (Microsoft Corporation) D:\WINDOWS\system32\gdiplus.dll 2013-12-23 12:52 - 2013-12-23 12:52 - 01060864 _____ (Microsoft Corporation) D:\WINDOWS\system32\mfc71.dll 2013-12-23 12:52 - 2013-12-23 12:52 - 00348160 _____ (Microsoft Corporation) D:\WINDOWS\system32\msvcr71.dll 2013-12-23 12:08 - 2013-12-23 12:08 - 00879174 _____ D:\Documents and Settings\kixx\Pulpit\rołwr.bmp 2013-12-18 22:40 - 2013-12-26 12:51 - 00000349 _____ D:\Documents and Settings\kixx\Pulpit\access.txt 2013-12-10 18:55 - 2013-12-10 19:03 - 00000082 _____ D:\Documents and Settings\kixx\Pulpit\Nowy Dokument tekstowy.txt 2013-12-09 18:21 - 2013-12-23 19:28 - 00000000 ____D D:\Documents and Settings\kixx\Pulpit\Nowy folder 2013-12-02 20:22 - 2013-12-02 20:24 - 00000108 _____ D:\Documents and Settings\kixx\Moje dokumenty\Projek2.layout 2013-12-02 20:22 - 2013-12-02 20:23 - 00001883 _____ D:\Documents and Settings\kixx\Moje dokumenty\mainz.cpp 2013-12-02 20:22 - 2013-12-02 20:22 - 00001512 _____ D:\Documents and Settings\kixx\Moje dokumenty\ ==================== One Month Modified Files and Folders ======= 2013-12-30 13:57 - 2013-12-27 11:18 - 00052402 _____ D:\WINDOWS\WindowsUpdate.log 2013-12-30 13:56 - 2012-10-19 07:40 - 00000260 _____ D:\WINDOWS\Tasks\WGASetup.job 2013-12-30 13:56 - 2012-08-26 11:47 - 00000159 _____ D:\WINDOWS\wiadebug.log 2013-12-30 13:56 - 2012-08-26 11:47 - 00000052 _____ D:\WINDOWS\wiaservc.log 2013-12-30 13:56 - 2012-08-26 10:02 - 00000006 ____H D:\WINDOWS\Tasks\SA.DAT 2013-12-30 13:56 - 2009-07-14 12:34 - 00243457 _____ D:\WINDOWS\system32\NvApps.xml 2013-12-30 13:55 - 2012-08-26 10:03 - 00000188 ___SH D:\Documents and Settings\kixx\ntuser.ini 2013-12-30 13:55 - 2012-08-26 10:02 - 00032524 _____ D:\WINDOWS\SchedLgU.Txt 2013-12-30 13:54 - 2013-12-29 18:17 - 00000000 ____D D:\Documents and Settings\kixx\Pulpit\FRST 2013-12-30 13:50 - 2013-12-30 13:47 - 00000000 ____D D:\AdwCleaner 2013-12-30 13:50 - 2012-08-26 12:19 - 00003519 _____ D:\WINDOWS\WINCMD.INI 2013-12-30 13:50 - 2012-08-26 10:03 - 00000000 ___HD D:\Documents and Settings\kixx\Ustawienia lokalne\Dane aplikacji 2013-12-30 13:42 - 2013-12-30 13:42 - 00000000 ____D D:\Documents and Settings\kixx\Dane aplikacji\ 2013-12-30 13:42 - 2013-12-29 18:16 - 00000000 ____D D:\FRST 2013-12-30 13:42 - 2012-08-26 11:42 - 00000000 __RHD D:\Documents and Settings\All Users\Dane aplikacji 2013-12-30 13:42 - 2012-08-26 10:03 - 00000000 __RHD D:\Documents and Settings\kixx\Dane aplikacji 2013-12-30 13:42 - 2012-08-26 10:03 - 00000000 ____D D:\Documents and Settings\kixx 2013-12-30 00:18 - 2013-12-27 16:52 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\AVAST Software 2013-12-30 00:12 - 2013-12-28 22:43 - 00022777 _____ D:\WINDOWS\setupapi.log 2013-12-29 23:40 - 2012-08-26 10:03 - 00000000 ____D D:\Documents and Settings\kixx\Pulpit 2013-12-29 22:36 - 2012-08-26 10:41 - 00000000 ____D D:\Program Files\Mozilla Firefox 2013-12-29 20:38 - 2013-12-29 20:38 - 00000000 ____D D:\TDSSKiller_Quarantine 2013-12-29 19:27 - 2012-08-26 13:14 - 00002349 _____ D:\Documents and Settings\kixx\Pulpit\Microsoft Office Word 2007.lnk 2013-12-28 23:36 - 2012-08-26 11:43 - 00000000 ___RD D:\Documents and Settings\All Users\Menu Start\Programy 2013-12-28 23:36 - 2012-08-26 11:43 - 00000000 ____D D:\Documents and Settings\All Users\Pulpit 2013-12-28 21:11 - 2013-12-28 20:22 - 137189352 _____ (AVG Technologies) D:\Documents and Settings\kixx\Pulpit\avg_free_x86_all_2014_4259a6848.exe 2013-12-28 00:06 - 2013-12-24 14:56 - 00000000 ____D D:\Documents and Settings\kixx\Pulpit\PO 2013-12-27 23:50 - 2012-09-03 20:03 - 00000000 ____D D:\WINDOWS\Microsoft.NET 2013-12-27 23:42 - 2013-12-27 23:42 - 00000000 ____D D:\Documents and Settings\All Users\Menu Start\Programy\Metin2 2013-12-27 22:42 - 2013-12-27 22:42 - 00001612 _____ D:\WINDOWS\wmsetup.log 2013-12-27 21:05 - 2013-12-27 20:35 - 00000000 ____D D:\Documents and Settings\kixx\Moje dokumenty\Gameforge Live 2013-12-27 20:35 - 2012-08-26 10:03 - 00000000 ___RD D:\Documents and Settings\kixx\Moje dokumenty 2013-12-27 20:34 - 2013-12-27 20:34 - 00000000 ____D D:\Documents and Settings\kixx\Ustawienia lokalne\Dane aplikacji\Gameforge4d 2013-12-27 20:33 - 2013-12-27 20:33 - 00000000 ____D D:\Program Files\GameforgeLive 2013-12-27 20:33 - 2013-12-27 20:33 - 00000000 ____D D:\Documents and Settings\All Users\Menu Start\Programy\Gameforge Live 2013-12-27 19:19 - 2012-08-26 11:43 - 01351202 _____ D:\WINDOWS\system32\PerfStringBackup.INI 2013-12-27 19:19 - 2001-10-26 17:15 - 00606754 _____ D:\WINDOWS\system32\perfh015.dat 2013-12-27 19:19 - 2001-10-26 17:15 - 00124752 _____ D:\WINDOWS\system32\perfc015.dat 2013-12-27 19:17 - 2012-08-28 20:58 - 00000000 ____D D:\WINDOWS\system32\pl-PL 2013-12-27 19:01 - 2012-12-10 17:56 - 00000000 ____D D:\Program Files\Microsoft.NET 2013-12-27 17:54 - 2013-12-27 17:18 - 00030976 _____ D:\WINDOWS\system32\Drivers\hitmanpro37.sys 2013-12-27 17:52 - 2013-03-22 12:06 - 00000000 ____D D:\Program Files\Pando Networks 2013-12-27 17:50 - 2013-12-27 17:50 - 00012872 _____ (SurfRight B.V.) D:\WINDOWS\system32\bootdelete.exe 2013-12-27 17:45 - 2012-08-26 10:03 - 00000000 ___RD D:\Documents and Settings\kixx\Menu Start\Programy 2013-12-27 17:43 - 2012-08-26 11:43 - 00000000 ___HD D:\Documents and Settings\All Users\Szablony 2013-12-27 17:30 - 2013-12-27 17:30 - 00000436 _____ D:\WINDOWS\system32\.crusader 2013-12-27 17:29 - 2013-12-27 17:15 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\HitmanPro 2013-12-27 17:18 - 2013-12-24 21:56 - 00000000 ____D D:\Documents and Settings\kixx\Dane aplikacji\Skype 2013-12-27 17:17 - 2013-12-27 17:17 - 00000000 ____D D:\Program Files\HitmanPro 2013-12-27 17:16 - 2013-12-27 16:57 - 91412976 _____ (AVAST Software) D:\Documents and Settings\kixx\Pulpit\avast_free_antivirus_setups.exe 2013-12-27 17:15 - 2013-12-24 21:56 - 00002211 _____ D:\Documents and Settings\All Users\Pulpit\Skype.lnk 2013-12-27 17:11 - 2013-09-16 18:51 - 00000000 ____D D:\Documents and Settings\kixx\Pulpit\magda 2013-12-27 17:02 - 2012-08-26 09:56 - 00002596 _____ D:\WINDOWS\system32\CONFIG.NT 2013-12-27 17:01 - 2013-12-27 17:01 - 00490648 _____ (AVAST Software) D:\Documents and Settings\kixx\Pulpit\avastclear.exe 2013-12-27 12:11 - 2013-12-23 12:54 - 00000000 ____D D:\Documents and Settings\kixx\Dane aplikacji\ipla 2013-12-27 12:06 - 2012-10-16 18:50 - 00000000 ____D D:\Documents and Settings\kixx\Menu Start\Programy\Metin2 2013-12-27 12:06 - 2012-10-15 18:23 - 00000000 ____D D:\Documents and Settings\All Users\Menu Start\Programy\KeyFinder 2013-12-27 12:06 - 2012-10-15 18:05 - 00000000 ____D D:\Documents and Settings\kixx\Menu Start\Programy\KeyFinder 2013-12-27 12:06 - 2012-08-26 10:03 - 00000000 ___RD D:\Documents and Settings\kixx\Menu Start\Programy\Autostart 2013-12-26 12:51 - 2013-12-18 22:40 - 00000349 _____ D:\Documents and Settings\kixx\Pulpit\access.txt 2013-12-25 19:34 - 2012-08-26 13:05 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2013-12-25 19:05 - 2012-08-26 13:15 - 00002331 _____ D:\Documents and Settings\kixx\Pulpit\Microsoft Office Access 2007.lnk 2013-12-25 18:46 - 2013-12-23 12:54 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\ipla 2013-12-25 18:29 - 2013-12-24 17:04 - 00000000 ____D D:\Documents and Settings\kixx\Moje dokumenty\Dev 2013-12-25 17:52 - 2013-01-22 21:16 - 00000000 ____D D:\Documents and Settings\kixx\Dane aplikacji\codeblocks 2013-12-25 17:32 - 2013-12-25 17:31 - 00000000 ____D D:\Documents and Settings\kixx\Menu Start\Programy\CodeBlocks 2013-12-25 17:31 - 2013-12-25 17:31 - 00000768 _____ D:\Documents and Settings\kixx\Pulpit\CodeBlocks.lnk 2013-12-25 17:31 - 2013-12-25 17:31 - 00000000 ____D D:\Documents and Settings\kixx\Moje dokumenty\Nowy folder (4) 2013-12-25 17:31 - 2013-02-19 17:41 - 00000000 ____D D:\Documents and Settings\All Users\Menu Start\Programy\CodeBlocks 2013-12-24 22:45 - 2013-12-24 22:45 - 00000000 ____D D:\Program Files\ 2013-12-24 22:40 - 2013-12-24 22:40 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\Real 2013-12-24 22:31 - 2001-07-21 23:16 - 00000862 _____ D:\WINDOWS\win.ini 2013-12-24 22:13 - 2013-12-24 22:13 - 00000000 ____D D:\Program Files\Common Files\InstallShield 2013-12-24 22:04 - 2013-12-24 22:04 - 00000000 ____D D:\Documents and Settings\kixx\Dane aplikacji\InstallShield 2013-12-24 21:56 - 2013-12-24 21:56 - 00000000 ____D D:\Program Files\Common Files\Skype 2013-12-24 21:56 - 2013-12-24 21:56 - 00000000 ____D D:\Documents and Settings\All Users\Menu Start\Programy\Skype 2013-12-24 21:56 - 2013-12-24 21:55 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\Skype 2013-12-24 19:47 - 2013-11-25 19:27 - 00000000 ____D D:\Documents and Settings\kixx\Pulpit\C++ Projekt 2013-12-24 17:06 - 2012-10-29 19:29 - 00000000 ____D D:\Documents and Settings\kixx\Dane aplikacji\Dev-Cpp 2013-12-24 16:54 - 2013-12-24 16:54 - 00000677 _____ D:\Documents and Settings\kixx\Pulpit\Dev-C++.lnk 2013-12-24 16:54 - 2013-12-24 16:54 - 00000000 ____D D:\Documents and Settings\All Users\Menu Start\Programy\Bloodshed Dev-C++ 2013-12-24 16:53 - 2013-12-24 16:53 - 00000000 ____D D:\Documents and Settings\kixx\Moje dokumenty\Nowy folder (3) 2013-12-24 16:46 - 2013-12-24 16:44 - 24952118 _____ D:\Documents and Settings\kixx\Pulpit\Dev-Cpp 5.5.3 MinGW 4.7.2 Setup.exe 2013-12-23 23:19 - 2012-08-26 13:25 - 00000000 ____D D:\Documents and Settings\kixx\Moje dokumenty\Pobieranie 2013-12-23 20:13 - 2013-12-23 20:13 - 00000000 ____D D:\Program Files\PlayReady 2013-12-23 19:45 - 2013-12-23 19:42 - 18277248 _____ (pdfforge ) D:\Documents and Settings\kixx\Pulpit\PDFCreator-1_7_2_setup.exe 2013-12-23 19:28 - 2013-12-09 18:21 - 00000000 ____D D:\Documents and Settings\kixx\Pulpit\Nowy folder 2013-12-23 12:54 - 2013-12-23 12:53 - 00000000 ____D D:\Documents and Settings\All Users\Dane aplikacji\RDRM 2013-12-23 12:54 - 2013-12-23 12:52 - 00000000 ____D D:\Program Files\ipla 2013-12-23 12:53 - 2013-12-23 12:53 - 00000626 _____ D:\Documents and Settings\All Users\Pulpit\ipla.lnk 2013-12-23 12:53 - 2013-12-23 12:53 - 00000000 ____D D:\Documents and Settings\All Users\Menu Start\Programy\ipla 2013-12-23 12:52 - 2013-12-23 12:52 - 01700352 _____ (Microsoft Corporation) D:\WINDOWS\system32\gdiplus.dll 2013-12-23 12:52 - 2013-12-23 12:52 - 01060864 _____ (Microsoft Corporation) D:\WINDOWS\system32\mfc71.dll 2013-12-23 12:52 - 2013-12-23 12:52 - 00348160 _____ (Microsoft Corporation) D:\WINDOWS\system32\msvcr71.dll 2013-12-23 12:08 - 2013-12-23 12:08 - 00879174 _____ D:\Documents and Settings\kixx\Pulpit\rołwr.bmp 2013-12-22 19:24 - 2001-07-21 23:17 - 00002228 _____ D:\WINDOWS\system32\wpa.dbl 2013-12-17 23:17 - 2013-10-14 18:57 - 00000600 _____ D:\Documents and Settings\kixx\Ustawienia lokalne\Dane aplikacji\PUTTY.RND 2013-12-16 19:26 - 2013-02-22 14:32 - 00042496 ___SH D:\Documents and Settings\kixx\Pulpit\Thumbs.db 2013-12-16 19:26 - 2012-10-10 08:49 - 00000000 ____D D:\Documents and Settings\kixx\Pulpit\trzustka 2013-12-10 19:03 - 2013-12-10 18:55 - 00000082 _____ D:\Documents and Settings\kixx\Pulpit\Nowy Dokument tekstowy.txt 2013-12-09 18:23 - 2013-02-11 18:16 - 00000000 ____D D:\Documents and Settings\kixx\Pulpit\w 2013-12-02 20:24 - 2013-12-02 20:22 - 00000108 _____ D:\Documents and Settings\kixx\Moje dokumenty\Projek2.layout 2013-12-02 20:23 - 2013-12-02 20:22 - 00001883 _____ D:\Documents and Settings\kixx\Moje dokumenty\mainz.cpp 2013-12-02 20:23 - 2013-11-01 18:58 - 00002520 _____ D:\Documents and Settings\kixx\Moje dokumenty\ 2013-12-02 20:22 - 2013-12-02 20:22 - 00001512 _____ D:\Documents and Settings\kixx\Moje dokumenty\ Files to move or delete: ==================== D:\Documents and Settings\kixx\netcache.dat ==================== Bamital & volsnap Check ================= D:\Windows\explorer.exe [2004-08-03 23:44] - [2008-04-14 21:51] - 1035264 ____A (Microsoft Corporation) c791ed9eac5e76d9525e157b1d7a599a D:\Windows\System32\winlogon.exe [2004-08-03 23:44] - [2008-04-14 21:51] - 0510464 ____A (Microsoft Corporation) 51fd2e13d723857b9ca239ae77150f48 D:\Windows\System32\svchost.exe [2004-08-03 23:44] - [2008-04-14 21:51] - 0014336 ____A (Microsoft Corporation) 8607d35d92528e2df386f19a960d23ce D:\Windows\System32\services.exe [2012-10-16 16:52] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 02a467e27af55f7064c5b251e587315f D:\Windows\System32\User32.dll [2004-08-03 23:44] - [2008-04-14 21:50] - 0580096 ____A (Microsoft Corporation) a435c5c069afd901751ac323ad238793 D:\Windows\System32\userinit.exe [2012-10-16 16:52] - [2008-04-14 21:51] - 0026624 ____A (Microsoft Corporation) 2a5b37d520508be6570a3ea79695f5b5 D:\Windows\System32\Drivers\volsnap.sys [2012-10-16 16:52] - [2008-04-14 20:31] - 0052864 ____A (Microsoft Corporation) 56b191ac5fc0df219949c95a6c87afe7 ==================== End Of Log ============================