Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:30-08-2014 01 Ran by OptiPlex GX620 (administrator) on MARTAKS on 30-08-2014 22:36:34 Running from C:\Documents and Settings\OptiPlex GX620\Pulpit Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 8 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Download link for 64-Bit Version: Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (CobianSoft, Luis Cobian) C:\Program Files\Cobian Backup 10\cbVSCService.exe (Luis Cobian, CobianSoft) C:\Program Files\Cobian Backup 10\cbService.exe (ESET) C:\Program Files\ESET\ESET Endpoint Security\ekrn.exe (Oracle Corporation) C:\JAVA\bin\jqs.exe (TeamViewer GmbH) C:\DOCUME~1\OPTIPL~1\USTAWI~1\TEMP\TeamViewer\Version9\TeamViewer_Service.exe (GlavSoft LLC.) C:\Program Files\TightVNC\tvnserver.exe (TeamViewer GmbH) C:\DOCUME~1\OPTIPL~1\USTAWI~1\TEMP\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\DOCUME~1\OPTIPL~1\USTAWI~1\TEMP\TeamViewer\Version9\tv_w32.exe (Intel Corporation) C:\WINDOWS\SYSTEM32\hkcmd.exe (Intel Corporation) C:\WINDOWS\SYSTEM32\igfxpers.exe (Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe (GlavSoft LLC.) C:\Program Files\TightVNC\tvnserver.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Luis Cobian, CobianSoft) C:\Program Files\Cobian Backup 10\cbInterface.exe (ESET) C:\Program Files\ESET\ESET Endpoint Security\egui.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Microsoft Corporation) C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (TeamViewer GmbH) C:\DOCUME~1\OPTIPL~1\USTAWI~1\TEMP\TeamViewer\Version9\TeamViewer_Desktop.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Farbar) C:\Documents and Settings\OptiPlex GX620\Pulpit\FRST (1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1404928 2004-10-14] (Analog Devices, Inc.) HKLM\...\Run: [tvncontrol] => C:\Program Files\TightVNC\tvnserver.exe [815704 2010-07-08] (GlavSoft LLC.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [gemstrmw] => C:\WINDOWS\system32\gemstrmw.exe [24576 2005-02-07] (Gemplus) HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM\...\Run: [] => [X] HKLM\...\Run: [Cobian Backup 10 Interface] => C:\Program Files\Cobian Backup 10\cbInterface.exe [3154432 2010-09-23] (Luis Cobian, CobianSoft) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Endpoint Security\egui.exe [3159744 2014-04-04] (ESET) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKU\S-1-5-21-1844237615-1336601894-682003330-1003\...\MountPoints2: {c369cc90-0d21-11e0-87bf-00123fc16ad5} - "E:\WD SmartWare.exe" autoplay=true HKU\S-1-5-21-1844237615-1336601894-682003330-1003\...\MountPoints2: {c369cc93-0d21-11e0-87bf-00123fc16ad5} - F:\setup.exe Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Windows Search.lnk ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation) Startup: C:\Documents and Settings\OptiPlex GX620\Menu Start\Autostart\Powiadomienia monitorowania tuszu - HP Deskjet 2540 series.lnk ShortcutTarget: Powiadomienia monitorowania tuszu - HP Deskjet 2540 series.lnk -> C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) BootExecute: ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar ={SUB_RFC1766}/srchasst/srchasst.htm SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL ={searchTerms}&affID=114506&tt=4312_7&babsrc=SP_clro&mntrId=0053670300000000000000123fc16ad5 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL ={searchTerms}&affID=114506&tt=4312_7&babsrc=SP_clro&mntrId=0053670300000000000000123fc16ad5 BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\JAVA\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\JAVA\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: {17492023-C23A-453E-A040-C7C580BBF700} DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2008-05-26] (Microsoft Corporation) Tcpip\..\Interfaces\{48F071E8-9822-4A0E-A798-F009AC119233}: [NameServer], FireFox: ======== FF ProfilePath: C:\Documents and Settings\OptiPlex GX620\Dane aplikacji\Mozilla\Firefox\Profiles\08catrfr.default FF SelectedSearchEngine: Google FF Homepage: about:home FF Plugin: -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin:,version=10.67.2 -> C:\JAVA\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin:,version=10.67.2 -> C:\JAVA\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin:,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: Update;version=3 -> C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Update;version=9 -> C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF user.js: detected! => C:\Documents and Settings\OptiPlex GX620\Dane aplikacji\Mozilla\Firefox\Profiles\08catrfr.default\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Documents and Settings\OptiPlex GX620\Dane aplikacji\Mozilla\Firefox\Profiles\08catrfr.default\searchplugins\babylon.xml FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\OptiPlex GX620\Dane aplikacji\Mozilla\Firefox\Profiles\08catrfr.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2013-06-17] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-07-15] FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-07-15] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-12-21] FF HKLM\...\Firefox\Extensions: [] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-10-30] FF HKLM\...\Thunderbird\Extensions: [] - C:\Program Files\ESET\ESET Endpoint Security\Mozilla Thunderbird FF Extension: ESET Endpoint Security Extension - C:\Program Files\ESET\ESET Endpoint Security\Mozilla Thunderbird [2014-08-07] FF HKCU\...\Firefox\Extensions: [] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR HomePage: Default -> hxxp:// CHR StartupUrls: Default -> "hxxp://" CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\36.0.1985.143\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\36.0.1985.143\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\36.0.1985.143\pdf.dll () CHR Plugin: (Microsoft Office 2003) - C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL No File CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation) CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.)) CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\JAVA\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Java(TM) Platform SE 7 U45) - C:\JAVA\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR CustomProfile: C:\Documents and Settings\OptiPlex GX620\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default CHR Extension: (Dokumenty Google) - C:\Documents and Settings\OptiPlex GX620\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-28] CHR Extension: (Google Wallet) - C:\Documents and Settings\OptiPlex GX620\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-28] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 cbVSCService; C:\Program Files\Cobian Backup 10\cbVSCService.exe [67584 2010-09-23] (CobianSoft, Luis Cobian) [File not signed] R2 CobianBackup10; C:\Program Files\Cobian Backup 10\cbService.exe [1125376 2010-09-23] (Luis Cobian, CobianSoft) [File not signed] S3 EhttpSrv; C:\Program Files\ESET\ESET Endpoint Security\EHttpSrv.exe [34296 2014-04-04] (ESET) R2 ekrn; C:\Program Files\ESET\ESET Endpoint Security\ekrn.exe [1029704 2014-04-04] (ESET) S3 ESHASRV; C:\Program Files\ESET\ESET Endpoint Security\EShaSrv.exe [189224 2014-04-04] (ESET) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [694784 2009-09-08] (Hewlett-Packard Co.) [File not signed] R2 JavaQuickStarterService; C:\JAVA\bin\jqs.exe [182696 2014-07-25] (Oracle Corporation) R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [44544 2008-12-03] (Hewlett-Packard) [File not signed] R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53760 2008-12-03] (Hewlett-Packard) [File not signed] R2 TeamViewer9; c:\Documents and Settings\OptiPlex GX620\Ustawienia lokalne\TEMP\teamviewer\Version9\TeamViewer_Service.exe [4670272 2014-08-06] (TeamViewer GmbH) R2 tvnserver; C:\Program Files\TightVNC\tvnserver.exe [815704 2010-07-08] (GlavSoft LLC.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S0 cercsr6; C:\WINDOWS\system32\Drivers\cercsr6.sys [39904 2004-12-14] (Adaptec, Inc.) [File not signed] R1 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [167184 2014-04-10] (ESET) R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [128056 2013-09-09] (ESET) R2 epfw; C:\WINDOWS\System32\DRIVERS\epfw.sys [157408 2013-09-09] (ESET) R3 Epfwndis; C:\WINDOWS\System32\DRIVERS\Epfwndis.sys [41536 2013-09-09] (ESET) R1 epfwtdi; C:\WINDOWS\System32\DRIVERS\epfwtdi.sys [63672 2013-09-09] (ESET) S3 GemCCID; C:\WINDOWS\System32\Drivers\GemCCID.sys [89600 2009-08-10] (Gemalto) R0 giveio; C:\WINDOWS\System32\giveio.sys [5248 1996-04-03] () [File not signed] R0 speedfan; C:\WINDOWS\System32\speedfan.sys [24184 2012-12-29] (Almico Software) U2 CertPropSvc; No ImagePath S4 IntelIde; No ImagePath S3 RT73; system32\DRIVERS\rt73.sys [X] U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation) U1 WS2IFSL; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-30 22:39 - 2014-08-30 22:39 - 00380416 _____ () C:\Documents and Settings\OptiPlex GX620\Pulpit\9dn7z838.exe 2014-08-30 22:36 - 2014-08-30 22:37 - 00016093 _____ () C:\Documents and Settings\OptiPlex GX620\Pulpit\FRST.txt 2014-08-30 22:34 - 2014-08-30 22:34 - 01095680 _____ (Farbar) C:\Documents and Settings\OptiPlex GX620\Pulpit\FRST (1).exe 2014-08-30 21:17 - 2014-08-30 21:17 - 00000000 ____D () C:\Documents and Settings\OptiPlex GX620\Dane aplikacji\Windows Desktop Search 2014-08-30 20:59 - 2014-08-30 20:59 - 00001799 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\Windows Search.lnk 2014-08-30 20:58 - 2014-08-30 20:58 - 00000000 ____D () C:\WINDOWS\system32\GroupPolicy 2014-08-30 20:58 - 2014-08-30 20:58 - 00000000 ____D () C:\Program Files\Windows Desktop Search 2014-08-30 20:56 - 2014-08-30 20:59 - 00005659 _____ () C:\WINDOWS\tsoc.log 2014-08-30 20:56 - 2014-08-30 20:59 - 00003850 _____ () C:\WINDOWS\msmqinst.log 2014-08-30 20:56 - 2014-08-30 20:59 - 00002476 _____ () C:\WINDOWS\ntdtcsetup.log 2014-08-30 20:56 - 2014-08-30 20:59 - 00002166 _____ () C:\WINDOWS\netfxocm.log 2014-08-30 20:56 - 2014-08-30 20:59 - 00001374 _____ () C:\WINDOWS\imsins.log 2014-08-30 20:56 - 2014-08-30 20:59 - 00000850 _____ () C:\WINDOWS\MedCtrOC.log 2014-08-30 20:56 - 2014-08-30 20:59 - 00000772 _____ () C:\WINDOWS\ocmsn.log 2014-08-30 20:56 - 2014-08-30 20:59 - 00000638 _____ () C:\WINDOWS\tabletoc.log 2014-08-30 20:56 - 2014-08-30 20:59 - 00000618 _____ () C:\WINDOWS\msgsocm.log 2014-08-30 20:56 - 2014-08-30 20:57 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB940157$ 2014-08-30 20:56 - 2014-08-30 20:56 - 00001374 _____ () C:\WINDOWS\imsins.BAK 2014-08-30 20:55 - 2014-08-30 20:59 - 00013346 _____ () C:\WINDOWS\iis6.log 2014-08-30 20:55 - 2014-08-30 20:59 - 00012367 _____ () C:\WINDOWS\FaxSetup.log 2014-08-30 20:55 - 2014-08-30 20:59 - 00005912 _____ () C:\WINDOWS\ocgen.log 2014-08-30 20:55 - 2014-08-30 20:59 - 00004107 _____ () C:\WINDOWS\comsetup.log 2014-08-30 20:55 - 2014-08-30 20:55 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-08-30 20:55 - 2014-08-30 20:55 - 00000000 _____ () C:\WINDOWS\setupact.log 2014-08-30 20:54 - 2014-08-30 20:54 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB915800-v4$ 2014-08-30 20:51 - 2014-08-30 20:51 - 00000000 ____D () C:\WINDOWS\LastGood 2014-08-30 20:50 - 2014-08-30 20:56 - 00003950 _____ () C:\WINDOWS\KB915800-v4.log 2014-08-30 20:50 - 2008-03-07 19:02 - 00192000 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\offfilt.dll 2014-08-30 20:50 - 2008-03-07 19:02 - 00098304 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\nlhtml.dll 2014-08-30 20:50 - 2008-03-07 19:02 - 00029696 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mimefilt.dll 2014-08-30 20:49 - 2014-08-30 21:17 - 00000000 ____D () C:\8f0e1763411a656a64e9ed8613205788 2014-08-30 20:49 - 2014-08-30 21:01 - 00024836 _____ () C:\WINDOWS\KB940157.log 2014-08-30 20:13 - 2014-08-30 20:13 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Microsoft Office 2014-08-30 20:13 - 2006-10-26 19:56 - 00032592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msonpmon.dll 2014-08-30 20:12 - 2014-08-30 20:29 - 00065536 _____ () C:\WINDOWS\system32\config\ODiag.evt 2014-08-30 20:09 - 2014-08-30 20:09 - 00000000 ____D () C:\Program Files\Microsoft Works 2014-08-30 20:06 - 2014-08-30 20:06 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 2014-08-30 20:06 - 2014-08-30 20:06 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-08-30 20:02 - 2014-08-30 20:02 - 00000000 ____D () C:\Program Files\Microsoft.NET 2014-08-30 19:52 - 2014-08-30 19:53 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 8 2014-08-30 19:50 - 2014-08-30 20:25 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2014-08-30 19:50 - 2014-08-30 19:50 - 00000000 ____D () C:\Documents and Settings\OptiPlex GX620\Ustawienia lokalne\Dane aplikacji\Microsoft Help 2014-08-30 19:36 - 2014-08-30 19:40 - 00000000 ____D () C:\MS.Office.2007.Enterprise.PL.[SOTBMP].[] 2014-08-29 10:46 - 2014-08-29 10:46 - 00000645 _____ () C:\Documents and Settings\OptiPlex GX620\Pulpit\RegCleaner.lnk 2014-08-29 10:46 - 2014-08-29 10:46 - 00000000 ____D () C:\Program Files\RegCleaner 2014-08-29 10:45 - 2014-08-29 10:46 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-08-29 10:44 - 2014-08-29 10:44 - 00000777 _____ () C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk 2014-08-29 10:44 - 2014-08-29 10:44 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-08-29 10:44 - 2014-08-29 10:44 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes Anti-Malware 2014-08-29 10:44 - 2014-05-12 07:26 - 00053208 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-08-29 10:44 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-08-29 10:22 - 2014-08-30 21:22 - 00008113 _____ () C:\WINDOWS\WindowsUpdate.log 2014-08-29 10:05 - 2014-08-29 10:05 - 00001406 _____ () C:\Documents and Settings\OptiPlex GX620\Moje dokumenty\cc_20140829_100530.reg 2014-08-29 09:58 - 2014-08-29 09:58 - 04697376 _____ (TeamViewer) C:\Documents and Settings\OptiPlex GX620\Pulpit\TeamViewerQS_pl-ckq.exe 2014-08-28 15:27 - 2014-08-28 16:48 - 00050688 _____ () C:\Documents and Settings\OptiPlex GX620\Pulpit\Szpital.xls 2014-08-27 14:07 - 2014-08-27 14:07 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\ODIR 2014-08-27 14:06 - 2014-08-27 14:06 - 00000000 ____D () C:\Program Files\ODIR 2014-08-27 14:06 - 2014-08-27 14:06 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\ODIR 2014-08-27 14:06 - 2000-12-06 00:00 - 00209608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Tabctl32.ocx 2014-08-27 14:06 - 1999-03-26 01:00 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\VB6STKIT.DLL 2014-08-25 13:29 - 2014-08-25 13:29 - 00001542 ____N () C:\Documents and Settings\OptiPlex GX620\Moje dokumenty\cc_20140825_132930.reg 2014-08-25 10:34 - 2014-08-25 10:34 - 00000000 ____D () C:\Program Files\SnadBoy's Revelation v2 2014-08-25 10:34 - 2014-08-25 10:34 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\SnadBoy's Revelation v2 2014-08-19 16:35 - 2014-08-19 17:08 - 00025600 ____N () C:\Documents and Settings\OptiPlex GX620\Pulpit\pko - rozliczenie.xls 2014-08-18 19:39 - 2014-08-18 19:39 - 00000623 _____ () C:\Documents and Settings\admin\Pulpit\Skrót do TeamViewerQS_pl.lnk 2014-08-18 19:39 - 2014-08-18 19:39 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-08-18 19:39 - 2014-07-25 12:49 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe 2014-08-18 19:39 - 2014-07-25 12:26 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2014-08-18 19:38 - 2014-08-18 19:38 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Java 2014-08-18 19:38 - 2014-07-25 12:55 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2014-08-18 19:38 - 2014-07-25 12:49 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe 2014-08-18 19:38 - 2014-07-25 12:49 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe 2014-08-18 19:36 - 2014-08-18 19:38 - 00004396 _____ () C:\WINDOWS\system32\jupdate-1.7.0_67-b01.log 2014-08-18 18:21 - 2014-08-18 18:21 - 00448512 _____ (OldTimer Tools) C:\Documents and Settings\admin\Pulpit\TFC.exe 2014-08-18 18:19 - 2014-08-18 18:19 - 00000992 _____ () C:\Documents and Settings\admin\Moje dokumenty\cc_20140818_181911.reg 2014-08-18 08:56 - 2014-08-18 08:56 - 00000000 ____D () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\ESET 2014-08-16 13:18 - 2014-08-16 13:22 - 00023552 ____N () C:\Documents and Settings\OptiPlex GX620\Pulpit\obiady - zakupy grupowe.xls 2014-08-12 10:38 - 2014-08-12 10:41 - 00000000 ____D () C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\HP 2014-08-12 10:37 - 2014-08-12 10:37 - 00022904 _____ () C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2014-08-12 10:37 - 2014-08-12 10:37 - 00000000 ____D () C:\Documents and Settings\admin\Dane aplikacji\HP 2014-08-12 10:37 - 2014-08-12 10:37 - 00000000 ____D () C:\Documents and Settings\admin\Dane aplikacji\Adobe 2014-08-07 17:05 - 2014-08-07 17:05 - 00000000 ____D () C:\Documents and Settings\OptiPlex GX620\Ustawienia lokalne\Dane aplikacji\ESET 2014-08-07 17:05 - 2014-08-07 17:05 - 00000000 ____D () C:\Documents and Settings\OptiPlex GX620\Dane aplikacji\ESET 2014-08-07 17:05 - 2014-08-07 17:05 - 00000000 ____D () C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\ESET 2014-08-07 17:05 - 2014-08-07 17:05 - 00000000 ____D () C:\Documents and Settings\admin\Dane aplikacji\ESET 2014-08-07 17:00 - 2014-08-07 17:00 - 00000000 ____D () C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\ESET 2014-08-07 16:56 - 2014-08-07 16:56 - 00000000 ____D () C:\Program Files\ESET 2014-08-07 16:56 - 2014-08-07 16:56 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\ESET 2014-08-07 16:56 - 2014-08-07 16:56 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\ESET 2014-08-07 16:51 - 2014-08-07 16:51 - 00000000 ____D () C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Sun 2014-08-07 16:51 - 2014-08-07 16:51 - 00000000 ____D () C:\Documents and Settings\admin\Dane aplikacji\Sun 2014-07-31 13:18 - 2014-07-31 17:42 - 00015360 ____N () C:\Documents and Settings\OptiPlex GX620\Moje dokumenty\rozliczenie opł. miejsc..xls ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-30 22:39 - 2014-08-30 22:39 - 00380416 _____ () C:\Documents and Settings\OptiPlex GX620\Pulpit\9dn7z838.exe 2014-08-30 22:39 - 2010-03-30 15:31 - 00000000 ____D () C:\Documents and Settings\OptiPlex GX620\Pulpit 2014-08-30 22:37 - 2014-08-30 22:36 - 00016093 _____ () C:\Documents and Settings\OptiPlex GX620\Pulpit\FRST.txt 2014-08-30 22:37 - 2010-04-08 15:29 - 00000000 ____D () C:\Documents and Settings\OptiPlex GX620\Ustawienia lokalne\TEMP 2014-08-30 22:36 - 2014-03-20 11:21 - 00000000 ____D () C:\FRST 2014-08-30 22:34 - 2014-08-30 22:34 - 01095680 _____ (Farbar) C:\Documents and Settings\OptiPlex GX620\Pulpit\FRST (1).exe 2014-08-30 22:27 - 2013-11-28 19:47 - 00001052 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-30 22:04 - 2012-05-14 18:42 - 00000930 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-08-30 21:22 - 2014-08-29 10:22 - 00008113 _____ () C:\WINDOWS\WindowsUpdate.log 2014-08-30 21:17 - 2014-08-30 21:17 - 00000000 ____D () C:\Documents and Settings\OptiPlex GX620\Dane aplikacji\Windows Desktop Search 2014-08-30 21:17 - 2014-08-30 20:49 - 00000000 ____D () C:\8f0e1763411a656a64e9ed8613205788 2014-08-30 21:17 - 2010-03-30 15:31 - 00000000 __RHD () C:\Documents and Settings\OptiPlex GX620\Dane aplikacji 2014-08-30 21:01 - 2014-08-30 20:49 - 00024836 _____ () C:\WINDOWS\KB940157.log 2014-08-30 20:59 - 2014-08-30 20:59 - 00001799 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\Windows Search.lnk 2014-08-30 20:59 - 2014-08-30 20:56 - 00005659 _____ () C:\WINDOWS\tsoc.log 2014-08-30 20:59 - 2014-08-30 20:56 - 00003850 _____ () C:\WINDOWS\msmqinst.log 2014-08-30 20:59 - 2014-08-30 20:56 - 00002476 _____ () C:\WINDOWS\ntdtcsetup.log 2014-08-30 20:59 - 2014-08-30 20:56 - 00002166 _____ () C:\WINDOWS\netfxocm.log 2014-08-30 20:59 - 2014-08-30 20:56 - 00001374 _____ () C:\WINDOWS\imsins.log 2014-08-30 20:59 - 2014-08-30 20:56 - 00000850 _____ () C:\WINDOWS\MedCtrOC.log 2014-08-30 20:59 - 2014-08-30 20:56 - 00000772 _____ () C:\WINDOWS\ocmsn.log 2014-08-30 20:59 - 2014-08-30 20:56 - 00000638 _____ () C:\WINDOWS\tabletoc.log 2014-08-30 20:59 - 2014-08-30 20:56 - 00000618 _____ () C:\WINDOWS\msgsocm.log 2014-08-30 20:59 - 2014-08-30 20:55 - 00013346 _____ () C:\WINDOWS\iis6.log 2014-08-30 20:59 - 2014-08-30 20:55 - 00012367 _____ () C:\WINDOWS\FaxSetup.log 2014-08-30 20:59 - 2014-08-30 20:55 - 00005912 _____ () C:\WINDOWS\ocgen.log 2014-08-30 20:59 - 2014-08-30 20:55 - 00004107 _____ () C:\WINDOWS\comsetup.log 2014-08-30 20:59 - 2010-03-30 18:03 - 01122114 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-08-30 20:59 - 2010-03-30 17:03 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy\Autostart 2014-08-30 20:59 - 2010-03-30 17:03 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy 2014-08-30 20:59 - 2004-08-04 13:00 - 00516474 _____ () C:\WINDOWS\system32\perfh015.dat 2014-08-30 20:59 - 2004-08-04 13:00 - 00094608 _____ () C:\WINDOWS\system32\perfc015.dat 2014-08-30 20:58 - 2014-08-30 20:58 - 00000000 ____D () C:\WINDOWS\system32\GroupPolicy 2014-08-30 20:58 - 2014-08-30 20:58 - 00000000 ____D () C:\Program Files\Windows Desktop Search 2014-08-30 20:58 - 2010-03-30 18:04 - 00000000 ____D () C:\WINDOWS\system32\PL-PL 2014-08-30 20:57 - 2014-08-30 20:56 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB940157$ 2014-08-30 20:56 - 2014-08-30 20:56 - 00001374 _____ () C:\WINDOWS\imsins.BAK 2014-08-30 20:56 - 2014-08-30 20:50 - 00003950 _____ () C:\WINDOWS\KB915800-v4.log 2014-08-30 20:55 - 2014-08-30 20:55 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-08-30 20:55 - 2014-08-30 20:55 - 00000000 _____ () C:\WINDOWS\setupact.log 2014-08-30 20:54 - 2014-08-30 20:54 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB915800-v4$ 2014-08-30 20:51 - 2014-08-30 20:51 - 00000000 ____D () C:\WINDOWS\LastGood 2014-08-30 20:50 - 2013-10-22 10:03 - 00000480 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{75BD28E6-7EDA-41F8-BCA5-1EE0C14D0022}.job 2014-08-30 20:34 - 2013-11-28 19:47 - 00001048 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-30 20:34 - 2013-06-03 08:13 - 00000350 _____ () C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2014-08-30 20:34 - 2004-08-04 13:00 - 00002206 _____ () C:\WINDOWS\system32\WPA.DBL 2014-08-30 20:31 - 2013-07-31 20:48 - 00000157 _____ () C:\WINDOWS\wiadebug.log 2014-08-30 20:31 - 2013-07-31 20:48 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-08-30 20:31 - 2010-03-30 16:23 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-08-30 20:30 - 2010-03-30 18:02 - 00271784 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-08-30 20:29 - 2014-08-30 20:12 - 00065536 _____ () C:\WINDOWS\system32\config\ODiag.evt 2014-08-30 20:29 - 2010-03-30 16:31 - 00000292 ___SH () C:\Documents and Settings\OptiPlex GX620\ntuser.ini 2014-08-30 20:29 - 2010-03-30 16:23 - 00032598 _____ () C:\WINDOWS\SCHEDLGU.TXT 2014-08-30 20:26 - 2010-03-30 18:03 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-08-30 20:25 - 2014-08-30 19:50 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2014-08-30 20:24 - 2010-12-21 19:54 - 00000000 ____D () C:\WINDOWS\SHELLNEW 2014-08-30 20:24 - 2010-03-30 16:14 - 00000000 ____D () C:\Program Files\Common Files\SYSTEM 2014-08-30 20:24 - 2004-08-04 13:00 - 00000638 _____ () C:\WINDOWS\WIN.INI 2014-08-30 20:13 - 2014-08-30 20:13 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Microsoft Office 2014-08-30 20:09 - 2014-08-30 20:09 - 00000000 ____D () C:\Program Files\Microsoft Works 2014-08-30 20:08 - 2010-12-21 19:48 - 00000000 ____D () C:\Program Files\MSBuild 2014-08-30 20:07 - 2010-12-21 19:54 - 00000000 ____D () C:\Program Files\Microsoft Office 2014-08-30 20:06 - 2014-08-30 20:06 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 2014-08-30 20:06 - 2014-08-30 20:06 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-08-30 20:02 - 2014-08-30 20:02 - 00000000 ____D () C:\Program Files\Microsoft.NET 2014-08-30 19:53 - 2014-08-30 19:52 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 8 2014-08-30 19:50 - 2014-08-30 19:50 - 00000000 ____D () C:\Documents and Settings\OptiPlex GX620\Ustawienia lokalne\Dane aplikacji\Microsoft Help 2014-08-30 19:50 - 2010-03-30 18:03 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji 2014-08-30 19:50 - 2010-03-30 15:31 - 00000000 ___HD () C:\Documents and Settings\OptiPlex GX620\Ustawienia lokalne\Dane aplikacji 2014-08-30 19:41 - 2014-07-23 15:19 - 00000188 ___SH () C:\Documents and Settings\admin\ntuser.ini 2014-08-30 19:41 - 2014-07-23 15:19 - 00000000 ____D () C:\Documents and Settings\admin 2014-08-30 19:40 - 2014-08-30 19:36 - 00000000 ____D () C:\MS.Office.2007.Enterprise.PL.[SOTBMP].[] 2014-08-30 19:36 - 2014-07-23 15:19 - 00000000 ____D () C:\Documents and Settings\admin\Ustawienia lokalne\Temp 2014-08-29 22:54 - 2010-03-30 16:55 - 00000000 ____D () C:\WINDOWS\repair 2014-08-29 22:00 - 2010-03-30 16:13 - 00000000 ____D () C:\WINDOWS\Registration 2014-08-29 15:36 - 2010-12-22 10:28 - 00022519 _____ () C:\Documents and Settings\OptiPlex GX620\intlname.ols 2014-08-29 10:46 - 2014-08-29 10:46 - 00000645 _____ () C:\Documents and Settings\OptiPlex GX620\Pulpit\RegCleaner.lnk 2014-08-29 10:46 - 2014-08-29 10:46 - 00000000 ____D () C:\Program Files\RegCleaner 2014-08-29 10:46 - 2014-08-29 10:45 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-08-29 10:44 - 2014-08-29 10:44 - 00000777 _____ () C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk 2014-08-29 10:44 - 2014-08-29 10:44 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-08-29 10:44 - 2014-08-29 10:44 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes Anti-Malware 2014-08-29 10:44 - 2010-03-30 17:03 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2014-08-29 10:05 - 2014-08-29 10:05 - 00001406 _____ () C:\Documents and Settings\OptiPlex GX620\Moje dokumenty\cc_20140829_100530.reg 2014-08-29 10:05 - 2010-03-30 15:31 - 00000000 ___RD () C:\Documents and Settings\OptiPlex GX620\Moje dokumenty 2014-08-29 10:03 - 2010-03-30 16:31 - 00000000 ____D () C:\Documents and Settings\OptiPlex GX620 2014-08-29 09:58 - 2014-08-29 09:58 - 04697376 _____ (TeamViewer) C:\Documents and Settings\OptiPlex GX620\Pulpit\TeamViewerQS_pl-ckq.exe 2014-08-28 16:48 - 2014-08-28 15:27 - 00050688 _____ () C:\Documents and Settings\OptiPlex GX620\Pulpit\Szpital.xls 2014-08-27 14:07 - 2014-08-27 14:07 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\ODIR 2014-08-27 14:06 - 2014-08-27 14:06 - 00000000 ____D () C:\Program Files\ODIR 2014-08-27 14:06 - 2014-08-27 14:06 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\ODIR 2014-08-26 16:17 - 2014-04-23 11:39 - 00016384 ____N () C:\Documents and Settings\OptiPlex GX620\Pulpit\pranie.xls 2014-08-25 13:29 - 2014-08-25 13:29 - 00001542 ____N () C:\Documents and Settings\OptiPlex GX620\Moje dokumenty\cc_20140825_132930.reg 2014-08-25 10:34 - 2014-08-25 10:34 - 00000000 ____D () C:\Program Files\SnadBoy's Revelation v2 2014-08-25 10:34 - 2014-08-25 10:34 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\SnadBoy's Revelation v2 2014-08-19 17:08 - 2014-08-19 16:35 - 00025600 ____N () C:\Documents and Settings\OptiPlex GX620\Pulpit\pko - rozliczenie.xls 2014-08-18 19:39 - 2014-08-18 19:39 - 00000623 _____ () C:\Documents and Settings\admin\Pulpit\Skrót do TeamViewerQS_pl.lnk 2014-08-18 19:39 - 2014-08-18 19:39 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-08-18 19:39 - 2014-07-23 15:19 - 00000000 ____D () C:\Documents and Settings\admin\Pulpit 2014-08-18 19:39 - 2011-10-21 15:17 - 00000000 ____D () C:\Nowy folder 2014-08-18 19:38 - 2014-08-18 19:38 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Java 2014-08-18 19:38 - 2014-08-18 19:36 - 00004396 _____ () C:\WINDOWS\system32\jupdate-1.7.0_67-b01.log 2014-08-18 19:38 - 2013-10-22 10:58 - 00000000 ____D () C:\JAVA 2014-08-18 18:22 - 2010-12-07 09:54 - 00000000 ____D () C:\Documents and Settings\NetworkService\Ustawienia lokalne\Temp 2014-08-18 18:22 - 2010-12-07 09:54 - 00000000 ____D () C:\Documents and Settings\LocalService\Ustawienia lokalne\Temp 2014-08-18 18:21 - 2014-08-18 18:21 - 00448512 _____ (OldTimer Tools) C:\Documents and Settings\admin\Pulpit\TFC.exe 2014-08-18 18:19 - 2014-08-18 18:19 - 00000992 _____ () C:\Documents and Settings\admin\Moje dokumenty\cc_20140818_181911.reg 2014-08-18 18:19 - 2014-07-23 15:19 - 00000000 ___RD () C:\Documents and Settings\admin\Moje dokumenty 2014-08-18 08:56 - 2014-08-18 08:56 - 00000000 ____D () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\ESET 2014-08-17 02:22 - 2013-11-19 04:11 - 00000406 ____H () C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job 2014-08-16 13:22 - 2014-08-16 13:18 - 00023552 ____N () C:\Documents and Settings\OptiPlex GX620\Pulpit\obiady - zakupy grupowe.xls 2014-08-14 10:37 - 2013-11-28 19:49 - 00001819 _____ () C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk 2014-08-12 10:41 - 2014-08-12 10:38 - 00000000 ____D () C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\HP 2014-08-12 10:38 - 2014-07-23 15:19 - 00000000 ___HD () C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji 2014-08-12 10:37 - 2014-08-12 10:37 - 00022904 _____ () C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2014-08-12 10:37 - 2014-08-12 10:37 - 00000000 ____D () C:\Documents and Settings\admin\Dane aplikacji\HP 2014-08-12 10:37 - 2014-08-12 10:37 - 00000000 ____D () C:\Documents and Settings\admin\Dane aplikacji\Adobe 2014-08-12 10:37 - 2014-07-23 15:19 - 00000000 __RHD () C:\Documents and Settings\admin\Dane aplikacji 2014-08-07 17:05 - 2014-08-07 17:05 - 00000000 ____D () C:\Documents and Settings\OptiPlex GX620\Ustawienia lokalne\Dane aplikacji\ESET 2014-08-07 17:05 - 2014-08-07 17:05 - 00000000 ____D () C:\Documents and Settings\OptiPlex GX620\Dane aplikacji\ESET 2014-08-07 17:05 - 2014-08-07 17:05 - 00000000 ____D () C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\ESET 2014-08-07 17:05 - 2014-08-07 17:05 - 00000000 ____D () C:\Documents and Settings\admin\Dane aplikacji\ESET 2014-08-07 17:00 - 2014-08-07 17:00 - 00000000 ____D () C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\ESET 2014-08-07 17:00 - 2010-03-30 16:20 - 00000000 ___HD () C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji 2014-08-07 16:56 - 2014-08-07 16:56 - 00000000 ____D () C:\Program Files\ESET 2014-08-07 16:56 - 2014-08-07 16:56 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\ESET 2014-08-07 16:56 - 2014-08-07 16:56 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\ESET 2014-08-07 16:51 - 2014-08-07 16:51 - 00000000 ____D () C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Sun 2014-08-07 16:51 - 2014-08-07 16:51 - 00000000 ____D () C:\Documents and Settings\admin\Dane aplikacji\Sun 2014-07-31 17:42 - 2014-07-31 13:18 - 00015360 ____N () C:\Documents and Settings\OptiPlex GX620\Moje dokumenty\rozliczenie opł. miejsc..xls Some content of TEMP: ==================== C:\Documents and Settings\admin\Ustawienia lokalne\TEMP\jre-7u67-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================