Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-09-2014 Ran by Paweł (administrator) on PAWEL on 14-09-2014 12:14:03 Running from C:\Documents and Settings\Paweł\Pulpit\Od wirusawianie Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (ASUSTeK COMPUTER INC.) C:\WINDOWS\ATKKBService.exe (CrypKey (Canada) Ltd.) C:\WINDOWS\system32\Crypserv.exe (ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe (Aladdin Knowledge Systems Ltd.) C:\WINDOWS\system32\hasplms.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (EnTech Taiwan) C:\Program Files\softOSD\softOSD.exe (EnTech Taiwan) C:\WINDOWS\system32\softLCP.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (DAEMON'S HOME) C:\Program Files\D-Tools\daemon.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (InstallShield Software Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe () C:\Program Files\PWN\Definicje\BIN\Starter.exe (Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE () C:\Program Files\OpenVPN\bin\openvpn-gui.exe (CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files\EaseUS\EaseUS Partition Master 9.2.1 Home Edition\bin\EpmNews.exe (Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe (Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe (GG Network S.A.) C:\Program Files\Gadu-Gadu 10\gg.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Ghisler Software GmbH) C:\Program Files\TC UP\TOTALCMD.EXE (Farbar) C:\Documents and Settings\Paweł\Pulpit\Od wirusawianie\FRST(1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [nwiz] => nwiz.exe /install HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [16862720 2008-05-16] (Realtek Semiconductor Corp.) HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [1443072 2008-02-20] (ESET) HKLM\...\Run: [DAEMON Tools-1033] => C:\Program Files\D-Tools\daemon.exe [81920 2004-08-22] (DAEMON'S HOME) HKLM\...\Run: [OrderReminder] => C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [98304 2006-01-30] (Hewlett-Packard) HKLM\...\Run: [ISUSPM Startup] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-16] (InstallShield Software Corporation) HKLM\...\Run: [ISUSScheduler] => C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2004-06-16] (InstallShield Software Corporation) HKLM\...\Run: [NeroFilterCheck] => C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [DemonStarter] => C:\Program Files\PWN\Definicje\Bin\Starter.exe [36864 1999-12-01] () HKLM\...\Run: [RemoteControl] => C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [32768 2004-11-02] (Cyberlink Corp.) HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [689488 2008-03-11] (CANON INC.) HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1848648 2009-07-07] (CANON INC.) HKLM\...\Run: [openvpn-gui] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe [99328 2005-08-18] () HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2012-04-18] (Apple Inc.) HKLM\...\Run: [EaseUS EPM tray] => C:\Program Files\EaseUS\EaseUS Partition Master 9.2.1 Home Edition\bin\EpmNews.exe [2086984 2012-11-29] (CHENGDU YIWO Tech Development Co., Ltd) HKLM\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [702024 2012-12-13] (Cisco Systems, Inc.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-10-10] (RealNetworks, Inc.) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [HTC Sync Loader] => C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [659456 2013-09-03] () HKLM\...99B7938DA9E4}\LocalServer32: [Default-wmiprvse] <==== ATTENTION! HKU\S-1-5-21-1275210071-162531612-1417001333-1003\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation) HKU\S-1-5-21-1275210071-162531612-1417001333-1003\...\Run: [ALLUpdate] => C:\Program Files\ALLPlayer\ALLUpdate.exe [869888 2009-06-04] () HKU\S-1-5-21-1275210071-162531612-1417001333-1003\...\Run: [Gadu-Gadu 10] => C:\Program Files\Gadu-Gadu 10\gg.exe [12477024 2010-07-22] (GG Network S.A.) Startup: C:\Documents and Settings\Paweł\Menu Start\Programy\Autostart\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) ShellIconOverlayIdentifiers: Uchwyt nakładania ikony podpisu cyfrowego -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll (Autodesk, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Default_search_url = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Search bar = http://search.msn.com/spbasic.htm SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: metaspinner media GmbH -> {12FC9A49-CFE0-49AA-BE9E-8F4EEAFC9443} -> C:\Program Files\Yetisports\IEButtonYetiSportsEBayInterface.dll () BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Documents and Settings\All Users\Dane aplikacji\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: PDFXChange 4.0 -> {42DFA04F-0F16-418e-B80C-AB97A5AFAD39} -> C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll (Tracker Software Products (Canada) Ltd.) BHO: extrafind -> {46c1e419-f8a0-6279-7668-4628b1b5537f} -> No File BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO: Skype Plug-In -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - PDFXChange 4.0 - {42DFA04F-0F16-418e-B80C-AB97A5AFAD39} - C:\Program Files\Tracker Software\PDF-XChange 4\PXCIEAddin4.dll (Tracker Software Products (Canada) Ltd.) Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [94208] (Apple Computer, Inc.) Tcpip\Parameters: [DhcpNameServer] 62.21.99.94 62.21.99.95 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default FF NewTab: hxxp://www.istartsurf.com/newtab/?type=nt&ts=1410374380&from=ild&uid=SAMSUNGXHD502HI_S1VZJ90S508817 FF DefaultSearchEngine: Web Search FF SearchEngineOrder.1: Search the web (Babylon) FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: about:blank FF Keyword.URL: hxxp://search.babylon.com/?babsrc=adbartrp&AF=15627&q= FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=16.0.2.32 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 -> C:\Documents and Settings\All Users\Dane aplikacji\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 -> C:\Documents and Settings\All Users\Dane aplikacji\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 -> C:\Documents and Settings\All Users\Dane aplikacji\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1739 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=16.0.2.32 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\Documents and Settings\All Users\Dane aplikacji\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpplugin.dll (RealPlayer) FF SearchPlugin: C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\searchplugins\babylon.xml FF SearchPlugin: C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\searchplugins\delta.xml FF SearchPlugin: C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\searchplugins\startsear.xml FF Extension: TheHDvid-Codec V10 - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\43f13f31-cec7-4ac7-ad4a-18dfdaeae120@gmail.com [2014-09-10] FF Extension: SunLogin Controller Plugin - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\dev@oray.com [2012-02-29] FF Extension: DownloadHelper - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-08] FF Extension: Website Counselor - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\{cc6cc772-f121-49e0-b1f0-c26583cb0c5e} [2014-09-10] FF Extension: FoxClocks - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1} [2014-01-26] FF Extension: dlWrzuta - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\dlwrzuta@helpstudent.pl.xpi [2013-07-13] FF Extension: Ciuvo - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\extension@ciuvo.com.xpi [2012-02-29] FF Extension: Firebug - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\firebug@software.joehewitt.com.xpi [2013-03-22] FF Extension: Personas Plus - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\personas@christopher.beard.xpi [2012-11-15] FF Extension: PlusWinks - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\pluswinks@PlusWinks.xpi [2013-07-20] FF Extension: Speed Analysis 2 - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\speedanalysis02@SpeedAnalysis.com.xpi [2013-10-06] FF Extension: Twojanuta.pl - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\zacz3k@gmail.com.xpi [2012-10-06] FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2013-03-22] FF Extension: Easy YouTube Video Downloader - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi [2013-03-22] FF Extension: Adblock Plus - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-07-23] FF Extension: Geckomenu - C:\Documents and Settings\Paweł\Dane aplikacji\Mozilla\Firefox\Profiles\ae4p35fp.default\Extensions\{eef03057-e4c4-4cbe-bdd3-9b21ce8e7ac2}.xpi [2012-02-29] FF Extension: z - C:\Program Files\Mozilla Firefox\extensions\{d1390b95-4c0f-d5cb-c249-9a3953af7413} [2014-09-13] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-16] FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\Documents and Settings\All Users\Dane aplikacji\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\Documents and Settings\All Users\Dane aplikacji\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-10-10] FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Documents and Settings\All Users\Dane aplikacji\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext Chrome: ======= CHR HomePage: Default -> hxxp://www.istartsurf.com/?type=hp&ts=1410374380&from=ild&uid=SAMSUNGXHD502HI_S1VZJ90S508817 CHR StartupUrls: Default -> "hxxp://www.istartsurf.com/?type=hp&ts=1410374380&from=ild&uid=SAMSUNGXHD502HI_S1VZJ90S508817" CHR DefaultSearchKeyword: Default -> istartsurf CHR DefaultSearchProvider: Default -> istartsurf CHR DefaultSearchURL: Default -> http://www.istartsurf.com/web/?type=ds&ts=1410374380&from=ild&uid=SAMSUNGXHD502HI_S1VZJ90S508817&q={searchTerms} CHR DefaultSuggestURL: Default -> CHR CustomProfile: C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default CHR Extension: (StartSearch Video plug-in) - C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\bildoibdboopgomcbiplincneeicgipj [2012-05-12] CHR Extension: (YouTube) - C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-16] CHR Extension: (Google Search) - C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-16] CHR Extension: (Babylon Translator) - C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb [2011-09-16] CHR Extension: (AdBlock) - C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2012-05-12] CHR Extension: (RealDownloader) - C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-09-12] CHR Extension: (No Name) - C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc [2013-11-14] CHR Extension: (AdSweep) - C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\milkhonmecplandlkfbjplfbdenjlkmp [2012-05-12] CHR Extension: (Google Wallet) - C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-12] CHR Extension: (Gmail) - C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-16] CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\Documents and Settings\All Users\Dane aplikacji\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-04-16] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ATKKeyboardService; C:\WINDOWS\ATKKBService.exe [262144 2008-08-29] (ASUSTeK COMPUTER INC.) [File not signed] S4 Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [File not signed] R2 Crypkey License; C:\WINDOWS\system32\crypserv.exe [122880 2008-05-08] (CrypKey (Canada) Ltd.) [File not signed] S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [19200 2008-02-20] (ESET) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [472320 2008-02-20] (ESET) S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2010-02-03] (Macrovision Europe Ltd.) [File not signed] R2 hasplms; C:\WINDOWS\system32\hasplms.exe [2869760 2009-04-21] (Aladdin Knowledge Systems Ltd.) S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-10-08] (Oracle Corporation) S2 NOD32FiXTemDono; C:\WINDOWS\system32\regedt32.exe [3584 2008-04-15] (Microsoft Corporation) S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [16384 2006-10-01] () [File not signed] R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] () S4 Service_VersionChecker; C:\POZYTON\SOLEN\SVC.exe [1020928 2010-10-05] () [File not signed] R2 softOSD; C:\Program Files\softOSD\softosd.exe [259832 2007-07-31] (EnTech Taiwan) [File not signed] S4 Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [1174664 2009-06-26] (Symantec Corporation) R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [544840 2012-12-13] (Cisco Systems, Inc.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 acsint; C:\WINDOWS\System32\DRIVERS\acsint.sys [39888 2012-12-13] (Cisco Systems, Inc.) S3 acsmux; C:\WINDOWS\System32\DRIVERS\acsmux.sys [58320 2012-12-13] (Cisco Systems, Inc.) R2 aksfridge; C:\WINDOWS\System32\DRIVERS\aksfridge.sys [352256 2009-01-16] (Aladdin Knowledge Systems Ltd.) R3 akshasp; C:\WINDOWS\System32\DRIVERS\akshasp.sys [238208 2009-03-13] (Aladdin Knowledge Systems Ltd.) R3 akshhl; C:\WINDOWS\System32\DRIVERS\akshhl.sys [46336 2007-07-23] (Aladdin Knowledge Systems Ltd.) R3 aksusb; C:\WINDOWS\System32\DRIVERS\aksusb.sys [16384 2009-06-22] (Aladdin Knowledge Systems Ltd.) R1 Amfilter; C:\WINDOWS\System32\DRIVERS\Amfilter.sys [8704 2007-01-24] (A4Tech Co.,Ltd.) [File not signed] S3 Amusbprt; C:\WINDOWS\System32\DRIVERS\Amusbprt.sys [13824 2007-02-11] (A4Tech Co.,Ltd.) [File not signed] R2 aslm75; C:\WINDOWS\system32\drivers\aslm75.sys [6272 2007-08-02] () [File not signed] R3 asusgsb; C:\WINDOWS\System32\drivers\asusgsb.sys [12416 2008-08-29] (ASUSTeK Computer Inc.) [File not signed] R1 asuskbnt; C:\WINDOWS\System32\drivers\atkkbnt.sys [11136 2008-08-29] (ASUSTeK COMPUTER INC.) [File not signed] R3 ASUSVRC; C:\WINDOWS\System32\DRIVERS\AsusVRC.sys [18432 2007-01-29] (ASUSTeK COMPUTER INC.) [File not signed] S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation) R0 d347bus; C:\WINDOWS\System32\DRIVERS\d347bus.sys [155136 2004-08-22] ( ) [File not signed] R0 d347prt; C:\WINDOWS\System32\Drivers\d347prt.sys [5248 2004-08-22] ( ) [File not signed] R2 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [39944 2008-02-20] (ESET) R1 easdrv; C:\WINDOWS\System32\DRIVERS\easdrv.sys [29704 2008-02-20] (ESET) R1 EIO_XP; C:\WINDOWS\system32\drivers\EIO_XP.sys [12288 2006-06-14] (ASUSTeK Computer Inc.) [File not signed] R2 epfw; C:\WINDOWS\System32\DRIVERS\epfw.sys [71176 2008-02-20] (ESET) R3 Epfwndis; C:\WINDOWS\System32\DRIVERS\Epfwndis.sys [30728 2008-02-20] (ESET) R1 epfwtdi; C:\WINDOWS\System32\DRIVERS\epfwtdi.sys [54280 2008-02-20] (ESET) S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [13896 2012-12-21] () [File not signed] S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [9160 2012-12-21] () [File not signed] R2 hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [587776 2009-07-09] (Aladdin Knowledge Systems Ltd.) R2 Haspnt; C:\WINDOWS\system32\drivers\Haspnt.sys [47616 2010-11-25] (Aladdin Knowledge Systems) [File not signed] R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-11] () S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation) R1 NetworkX; C:\WINDOWS\system32\ckldrv.sys [21638 2008-08-22] () [File not signed] R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [54400 2008-03-25] (NVIDIA Corporation) R3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [38176 2008-05-02] (NVIDIA Corporation) R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [22016 2008-03-25] (NVIDIA Corporation) R1 PQNTDrv; C:\WINDOWS\system32\Drivers\PQNTDrv.sys [4228 2002-09-16] (PowerQuest Corporation) [File not signed] R1 se32; C:\WINDOWS\System32\Drivers\se32.sys [12112 2007-05-03] (EnTech Taiwan) S3 ssudserd; C:\WINDOWS\System32\DRIVERS\ssudserd.sys [181432 2012-06-04] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 tap0801; C:\WINDOWS\System32\DRIVERS\tap0801.sys [26624 2006-10-01] (The OpenVPN Project) [File not signed] R1 VD_FileDisk; C:\WINDOWS\system32\Drivers\VD_FileDisk.sys [15872 2006-01-13] (Flint Incorporation) [File not signed] R3 Video3D; C:\WINDOWS\System32\Drivers\Video3D32.sys [10752 2008-08-29] (ASUSTeK COMPUTER INC.) [File not signed] S3 wceusbsh; C:\WINDOWS\System32\DRIVERS\wceusbsh.sys [31273 2003-02-22] (Microsoft Corporation) [File not signed] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S4 IntelIde; No ImagePath U1 WS2IFSL; No ImagePath S3 zlportio; \??\C:\Program Files\UltraStar Deluxe\zlportio.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) NETSVC: SSHNAS -> No Registry Path. ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-14 12:10 - 2014-09-14 12:14 - 00000000 ____D () C:\FRST 2014-09-14 11:54 - 2014-09-14 11:54 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempQZ3832.html 2014-09-14 11:54 - 2014-09-14 11:54 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempGC3832.html 2014-09-14 11:50 - 2014-09-14 11:50 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-09-13 20:02 - 2014-09-13 21:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-09-13 17:26 - 2014-09-13 23:18 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempzH3372.html 2014-09-13 17:26 - 2014-09-13 23:18 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempLN3372.html 2014-09-13 17:23 - 2014-09-14 11:51 - 00000248 _____ () C:\WINDOWS\error.log 2014-09-13 17:23 - 2014-09-14 11:50 - 00000078 _____ () C:\WINDOWS\errord.log 2014-09-13 00:39 - 2014-09-14 12:14 - 00000000 ____D () C:\Documents and Settings\Paweł\Pulpit\Od wirusawianie 2014-09-12 23:52 - 2014-09-13 01:00 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempAC2092.html 2014-09-12 23:52 - 2014-09-13 01:00 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempqq2092.html 2014-09-12 23:45 - 2014-09-12 23:48 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempjy4092.html 2014-09-12 23:45 - 2014-09-12 23:48 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempvD4092.html 2014-09-12 23:32 - 2014-09-12 23:42 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempiE3156.html 2014-09-12 23:32 - 2014-09-12 23:42 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempJk3156.html 2014-09-12 22:44 - 2014-09-12 23:27 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempnN1744.html 2014-09-12 22:44 - 2014-09-12 23:27 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempUU1744.html 2014-09-12 22:38 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\system32\sqlite3.dll 2014-09-12 22:36 - 2014-09-13 18:50 - 00000000 ____D () C:\AdwCleaner 2014-09-12 22:36 - 2014-09-12 22:51 - 00000000 ____D () C:\Documents and Settings\Paweł\Dane aplikacji\iSafe 2014-09-12 22:36 - 2014-09-12 22:36 - 00000000 ____D () C:\Documents and Settings\Paweł\Dane aplikacji\eCyber 2014-09-12 21:46 - 2014-09-12 22:39 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempWn2400.html 2014-09-12 21:46 - 2014-09-12 22:39 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempkE2400.html 2014-09-12 13:38 - 2014-09-12 17:13 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempqH2292.html 2014-09-12 13:38 - 2014-09-12 17:13 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempnA2292.html 2014-09-11 20:25 - 2014-09-11 23:03 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempwGe456.html 2014-09-11 20:25 - 2014-09-11 23:03 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempMwg456.html 2014-09-11 13:08 - 2014-09-11 20:21 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempvF2156.html 2014-09-11 13:08 - 2014-09-11 20:21 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempWy2156.html 2014-09-10 21:52 - 2014-09-10 21:52 - 00632712 _____ (ClickMeIn Limited) C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\nss3AA5.tmp 2014-09-10 20:55 - 2014-09-10 21:57 - 00000322 _____ () C:\Documents and Settings\Paweł\Dane aplikacji\aps.uninstall.scan.results 2014-09-10 20:53 - 2014-09-10 20:53 - 00617277 _____ (ClickMeIn Limited) C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\nsl2B2B.tmp 2014-09-10 20:42 - 2014-09-10 20:42 - 01913208 _____ (HQ-VPro) C:\Documents and Settings\Paweł\Dane aplikacji\XKOJNO.exe 2014-09-10 20:42 - 2014-09-10 20:42 - 01466744 _____ (HQ-VPro) C:\Documents and Settings\Paweł\Dane aplikacji\IQSF.exe 2014-09-10 20:41 - 2014-09-10 20:41 - 00000000 ____D () C:\Documents and Settings\Paweł\Dane aplikacji\WebExtend 2014-09-10 20:39 - 2014-09-10 20:39 - 01466728 _____ (home) C:\Documents and Settings\Paweł\Dane aplikacji\JXVOBY.exe 2014-09-10 20:38 - 2014-09-10 20:38 - 01913192 _____ (home) C:\Documents and Settings\Paweł\Dane aplikacji\CWNHZV.exe 2014-09-10 20:38 - 2014-09-10 20:38 - 00000000 ____D () C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\globalUpdate 2014-09-10 17:48 - 2014-09-10 22:59 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempJg2224.html 2014-09-10 17:48 - 2014-09-10 22:59 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempel2224.html 2014-09-09 17:26 - 2014-09-09 22:33 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempgQ2284.html 2014-09-09 17:26 - 2014-09-09 22:33 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempzA2284.html 2014-09-09 12:50 - 2014-09-09 13:01 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempfn2884.html 2014-09-09 12:50 - 2014-09-09 13:01 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempij2884.html 2014-09-08 20:30 - 2014-09-08 22:43 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempPg3188.html 2014-09-08 20:30 - 2014-09-08 22:43 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempdy3188.html 2014-09-08 15:18 - 2014-09-08 18:25 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TemppO3232.html 2014-09-08 15:18 - 2014-09-08 18:25 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempfq3232.html 2014-09-05 12:32 - 2014-09-05 13:59 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempLq2628.html 2014-09-05 12:32 - 2014-09-05 13:59 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempvG2628.html 2014-09-04 20:08 - 2014-09-04 20:08 - 00000000 ____D () C:\Documents and Settings\Paweł\Dane aplikacji\onlysearch 2014-09-04 17:23 - 2014-09-04 23:22 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempBL2872.html 2014-09-04 17:23 - 2014-09-04 23:22 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempQz2872.html 2014-09-03 14:05 - 2014-09-03 22:26 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempRp2952.html 2014-09-03 14:05 - 2014-09-03 22:26 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Temptz2952.html 2014-09-02 14:42 - 2014-09-02 21:47 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempmo3404.html 2014-09-02 14:42 - 2014-09-02 21:47 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempVg3404.html 2014-09-01 14:09 - 2014-09-01 22:33 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempHe2152.html 2014-09-01 14:09 - 2014-09-01 22:33 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempiG2152.html 2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Documents and Settings\Paweł\Dane aplikacji\JXVOBY 2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Documents and Settings\Paweł\Dane aplikacji\IQSF 2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Documents and Settings\Paweł\Dane aplikacji\XKOJNO 2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Documents and Settings\Paweł\Dane aplikacji\CWNHZV 2014-08-31 16:55 - 2014-08-31 21:49 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempQU2860.html 2014-08-31 16:55 - 2014-08-31 21:49 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempuw2860.html 2014-08-31 12:48 - 2014-08-31 15:42 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TemphB4028.html 2014-08-31 12:48 - 2014-08-31 15:42 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempxs4028.html 2014-08-30 18:58 - 2014-08-31 00:47 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempjP3268.html 2014-08-30 18:58 - 2014-08-31 00:47 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempVj3268.html 2014-08-30 12:52 - 2014-08-30 12:52 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempew2188.html 2014-08-30 12:52 - 2014-08-30 12:52 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempss2188.html 2014-08-30 08:09 - 2014-08-30 08:16 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempyla792.html 2014-08-30 08:09 - 2014-08-30 08:16 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TemprKo792.html 2014-08-29 21:43 - 2014-08-29 23:56 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempEy3912.html 2014-08-29 21:43 - 2014-08-29 23:56 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempCt3912.html 2014-08-29 16:41 - 2014-08-29 19:48 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempPEP196.html 2014-08-29 16:41 - 2014-08-29 19:48 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempeTI196.html 2014-08-29 14:45 - 2014-08-29 15:45 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempSo3860.html 2014-08-29 14:45 - 2014-08-29 15:45 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempnW3860.html 2014-08-29 07:38 - 2014-08-29 07:51 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempbQ3208.html 2014-08-29 07:38 - 2014-08-29 07:51 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempIk3208.html 2014-08-28 14:37 - 2014-08-28 20:43 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TemptJ2020.html 2014-08-28 14:37 - 2014-08-28 20:43 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempgZ2020.html 2014-08-27 15:21 - 2014-08-27 21:16 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempcW3880.html 2014-08-27 15:21 - 2014-08-27 21:16 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempno3880.html 2014-08-26 15:28 - 2014-09-04 18:46 - 00016689 _____ () C:\Documents and Settings\Paweł\Pulpit\2014-08-26_CAPAROL_FARBY.xlsx 2014-08-26 09:24 - 2014-08-26 22:12 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempIT3388.html 2014-08-26 09:24 - 2014-08-26 22:12 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Temptl3388.html 2014-08-25 23:07 - 2014-08-25 23:09 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Templzs752.html 2014-08-25 23:07 - 2014-08-25 23:09 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempCRs752.html 2014-08-25 18:54 - 2014-08-25 20:07 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempta2536.html 2014-08-25 18:54 - 2014-08-25 20:07 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempSt2536.html 2014-08-23 07:47 - 2014-08-23 09:10 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Temptl3764.html 2014-08-23 07:47 - 2014-08-23 09:10 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempaP3764.html 2014-08-22 13:37 - 2014-08-22 16:36 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempYl3808.html 2014-08-22 13:37 - 2014-08-22 16:36 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempRU3808.html 2014-08-22 10:48 - 2014-08-22 11:05 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempmC2116.html 2014-08-22 10:48 - 2014-08-22 11:05 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempuz2116.html 2014-08-20 23:32 - 2014-08-21 00:42 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempaMU504.html 2014-08-20 23:32 - 2014-08-21 00:42 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempgGy504.html 2014-08-20 08:40 - 2014-08-20 09:51 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempTB3508.html 2014-08-20 08:40 - 2014-08-20 09:51 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Temppv3508.html 2014-08-20 07:54 - 2014-08-20 07:54 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempbI3640.html 2014-08-20 07:54 - 2014-08-20 07:54 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempEE3640.html 2014-08-18 20:26 - 2014-08-18 20:26 - 00000183 _____ () C:\Documents and Settings\Paweł\Pulpit\Uchwyt do TV.txt 2014-08-18 11:30 - 2014-08-18 20:35 - 00000000 ____D () C:\Documents and Settings\Paweł\Pulpit\KOLORY ŚCIAN 2014-08-18 09:26 - 2014-08-19 21:04 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempdh3168.html 2014-08-18 09:26 - 2014-08-19 21:04 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempYD3168.html 2014-08-17 12:05 - 2014-08-17 23:43 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempHv1348.html 2014-08-17 12:05 - 2014-08-17 23:43 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempph1348.html 2014-08-16 10:04 - 2014-08-16 17:10 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempVx4036.html 2014-08-16 10:04 - 2014-08-16 17:10 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Temprw4036.html 2014-08-16 00:53 - 2014-08-16 00:53 - 00000768 _____ () C:\Documents and Settings\Paweł\Pulpit\radia w łazience.txt 2014-08-15 12:46 - 2014-08-15 12:49 - 09477477 _____ () C:\Documents and Settings\Paweł\Pulpit\Fachowa instrukcja montażu paneli laminowanych - Quick-Step .flv 2014-08-15 09:56 - 2014-08-16 01:04 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempnCC780.html 2014-08-15 09:56 - 2014-08-16 01:04 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempoJc780.html ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-14 12:14 - 2014-09-14 12:10 - 00000000 ____D () C:\FRST 2014-09-14 12:14 - 2014-09-13 00:39 - 00000000 ____D () C:\Documents and Settings\Paweł\Pulpit\Od wirusawianie 2014-09-14 12:14 - 2009-06-26 19:55 - 00000000 ____D () C:\Documents and Settings\Paweł\Ustawienia lokalne\Temp 2014-09-14 12:05 - 2014-06-23 17:23 - 00000000 ____D () C:\Documents and Settings\Paweł\Moje dokumenty\Pobrane 2014-09-14 11:55 - 2009-06-26 19:50 - 02045925 _____ () C:\WINDOWS\WindowsUpdate.log 2014-09-14 11:54 - 2014-09-14 11:54 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempQZ3832.html 2014-09-14 11:54 - 2014-09-14 11:54 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempGC3832.html 2014-09-14 11:54 - 2009-06-26 19:55 - 00000000 ___HD () C:\Documents and Settings\Paweł\Ustawienia lokalne 2014-09-14 11:53 - 2013-11-27 20:02 - 00000000 ____D () C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Htc 2014-09-14 11:52 - 2009-06-26 20:06 - 00194487 _____ () C:\WINDOWS\system32\nvapps.xml 2014-09-14 11:52 - 2008-04-15 14:00 - 00013680 _____ () C:\WINDOWS\system32\wpa.dbl 2014-09-14 11:51 - 2014-09-13 17:23 - 00000248 _____ () C:\WINDOWS\error.log 2014-09-14 11:51 - 2009-06-27 03:30 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-09-14 11:51 - 2009-06-27 03:30 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-09-14 11:50 - 2014-09-14 11:50 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-09-14 11:50 - 2014-09-13 17:23 - 00000078 _____ () C:\WINDOWS\errord.log 2014-09-13 23:18 - 2014-09-13 17:26 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempzH3372.html 2014-09-13 23:18 - 2014-09-13 17:26 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempLN3372.html 2014-09-13 23:18 - 2013-01-08 19:54 - 03997696 _____ () C:\WINDOWS\system32\config\ACVPN.evt 2014-09-13 23:18 - 2009-06-26 19:53 - 00031916 _____ () C:\WINDOWS\SchedLgU.Txt 2014-09-13 21:01 - 2014-09-13 20:02 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-09-13 19:14 - 2009-06-27 03:28 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy 2014-09-13 18:51 - 2009-06-26 19:55 - 00000000 __SHD () C:\Documents and Settings\Paweł 2014-09-13 18:50 - 2014-09-12 22:36 - 00000000 ____D () C:\AdwCleaner 2014-09-13 01:00 - 2014-09-12 23:52 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempAC2092.html 2014-09-13 01:00 - 2014-09-12 23:52 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempqq2092.html 2014-09-13 00:46 - 2009-06-26 19:55 - 00000000 __SHD () C:\Documents and Settings\Paweł\Pulpit 2014-09-12 23:54 - 2009-06-27 03:26 - 00000211 ____N () C:\boot.ini 2014-09-12 23:54 - 2008-04-15 14:00 - 00000705 _____ () C:\WINDOWS\win.ini 2014-09-12 23:54 - 2008-04-15 14:00 - 00000227 _____ () C:\WINDOWS\system.ini 2014-09-12 23:48 - 2014-09-12 23:45 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempjy4092.html 2014-09-12 23:48 - 2014-09-12 23:45 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempvD4092.html 2014-09-12 23:48 - 2009-06-26 19:55 - 00000188 ___SH () C:\Documents and Settings\Paweł\ntuser.ini 2014-09-12 23:42 - 2014-09-12 23:32 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempiE3156.html 2014-09-12 23:42 - 2014-09-12 23:32 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempJk3156.html 2014-09-12 23:39 - 2009-06-27 03:28 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start 2014-09-12 23:39 - 2009-06-27 03:28 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2014-09-12 23:27 - 2014-09-12 22:44 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempnN1744.html 2014-09-12 23:27 - 2014-09-12 22:44 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempUU1744.html 2014-09-12 22:51 - 2014-09-12 22:36 - 00000000 ____D () C:\Documents and Settings\Paweł\Dane aplikacji\iSafe 2014-09-12 22:39 - 2014-09-12 21:46 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempWn2400.html 2014-09-12 22:39 - 2014-09-12 21:46 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempkE2400.html 2014-09-12 22:39 - 2009-06-27 03:27 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji 2014-09-12 22:37 - 2013-03-22 13:15 - 00000910 _____ () C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk 2014-09-12 22:37 - 2011-08-28 18:24 - 00000916 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk 2014-09-12 22:36 - 2014-09-12 22:36 - 00000000 ____D () C:\Documents and Settings\Paweł\Dane aplikacji\eCyber 2014-09-12 22:36 - 2009-06-26 19:55 - 00000000 __SHD () C:\Documents and Settings\Paweł\Dane aplikacji 2014-09-12 22:24 - 2011-09-16 10:48 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Google Chrome 2014-09-12 21:45 - 2013-12-31 16:19 - 00000000 ____D () C:\Documents and Settings\Paweł\Dane aplikacji\newnext.me 2014-09-12 17:13 - 2014-09-12 13:38 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempqH2292.html 2014-09-12 17:13 - 2014-09-12 13:38 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempnA2292.html 2014-09-12 16:23 - 2010-11-14 01:30 - 00000000 ____D () C:\Documents and Settings\Paweł\dwhelper 2014-09-11 23:03 - 2014-09-11 20:25 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempwGe456.html 2014-09-11 23:03 - 2014-09-11 20:25 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempMwg456.html 2014-09-11 21:16 - 2009-06-28 23:57 - 00000000 ____D () C:\Documents and Settings\Paweł\Dane aplikacji\Media Player Classic 2014-09-11 21:16 - 2009-06-26 21:45 - 00000000 ____D () C:\Documents and Settings\Paweł\Dane aplikacji\Winamp 2014-09-11 20:40 - 2009-06-29 17:28 - 00000000 ____D () C:\WINDOWS\Minidump 2014-09-11 20:31 - 2009-06-26 19:55 - 00000000 ____D () C:\Documents and Settings\Paweł\Menu Start\Programy 2014-09-11 20:21 - 2014-09-11 13:08 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempvF2156.html 2014-09-11 20:21 - 2014-09-11 13:08 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempWy2156.html 2014-09-11 13:38 - 2013-11-27 19:52 - 00000000 ____D () C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Mobogenie 2014-09-10 23:00 - 2009-06-26 22:23 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2014-09-10 22:59 - 2014-09-10 17:48 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempJg2224.html 2014-09-10 22:59 - 2014-09-10 17:48 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempel2224.html 2014-09-10 22:59 - 2013-11-27 19:52 - 00121610 _____ () C:\Documents and Settings\Paweł\daemonprocess.txt 2014-09-10 21:57 - 2014-09-10 20:55 - 00000322 _____ () C:\Documents and Settings\Paweł\Dane aplikacji\aps.uninstall.scan.results 2014-09-10 21:52 - 2014-09-10 21:52 - 00632712 _____ (ClickMeIn Limited) C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\nss3AA5.tmp 2014-09-10 21:52 - 2009-06-26 19:55 - 00000000 ___HD () C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji 2014-09-10 20:53 - 2014-09-10 20:53 - 00617277 _____ (ClickMeIn Limited) C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\nsl2B2B.tmp 2014-09-10 20:42 - 2014-09-10 20:42 - 01913208 _____ (HQ-VPro) C:\Documents and Settings\Paweł\Dane aplikacji\XKOJNO.exe 2014-09-10 20:42 - 2014-09-10 20:42 - 01466744 _____ (HQ-VPro) C:\Documents and Settings\Paweł\Dane aplikacji\IQSF.exe 2014-09-10 20:41 - 2014-09-10 20:41 - 00000000 ____D () C:\Documents and Settings\Paweł\Dane aplikacji\WebExtend 2014-09-10 20:39 - 2014-09-10 20:39 - 01466728 _____ (home) C:\Documents and Settings\Paweł\Dane aplikacji\JXVOBY.exe 2014-09-10 20:38 - 2014-09-10 20:38 - 01913192 _____ (home) C:\Documents and Settings\Paweł\Dane aplikacji\CWNHZV.exe 2014-09-10 20:38 - 2014-09-10 20:38 - 00000000 ____D () C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\globalUpdate 2014-09-10 19:40 - 2012-10-16 17:29 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2014-09-10 19:40 - 2012-10-16 17:29 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2014-09-09 22:33 - 2014-09-09 17:26 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempgQ2284.html 2014-09-09 22:33 - 2014-09-09 17:26 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempzA2284.html 2014-09-09 13:01 - 2014-09-09 12:50 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempfn2884.html 2014-09-09 13:01 - 2014-09-09 12:50 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempij2884.html 2014-09-08 22:43 - 2014-09-08 20:30 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempPg3188.html 2014-09-08 22:43 - 2014-09-08 20:30 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempdy3188.html 2014-09-08 18:25 - 2014-09-08 15:18 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TemppO3232.html 2014-09-08 18:25 - 2014-09-08 15:18 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempfq3232.html 2014-09-05 13:59 - 2014-09-05 12:32 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempLq2628.html 2014-09-05 13:59 - 2014-09-05 12:32 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempvG2628.html 2014-09-04 23:22 - 2014-09-04 17:23 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempBL2872.html 2014-09-04 23:22 - 2014-09-04 17:23 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempQz2872.html 2014-09-04 20:08 - 2014-09-04 20:08 - 00000000 ____D () C:\Documents and Settings\Paweł\Dane aplikacji\onlysearch 2014-09-04 19:23 - 2012-05-21 01:08 - 00000000 ____D () C:\Documents and Settings\Paweł\Pulpit\ARCHIWUM 2014-09-04 18:46 - 2014-08-26 15:28 - 00016689 _____ () C:\Documents and Settings\Paweł\Pulpit\2014-08-26_CAPAROL_FARBY.xlsx 2014-09-03 22:26 - 2014-09-03 14:05 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempRp2952.html 2014-09-03 22:26 - 2014-09-03 14:05 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Temptz2952.html 2014-09-02 21:47 - 2014-09-02 14:42 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempmo3404.html 2014-09-02 21:47 - 2014-09-02 14:42 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempVg3404.html 2014-09-01 22:33 - 2014-09-01 14:09 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempHe2152.html 2014-09-01 22:33 - 2014-09-01 14:09 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempiG2152.html 2014-09-01 19:38 - 2014-01-01 20:32 - 00000000 ____D () C:\Documents and Settings\Paweł\Pulpit\monika 2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Documents and Settings\Paweł\Dane aplikacji\JXVOBY 2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Documents and Settings\Paweł\Dane aplikacji\IQSF 2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Documents and Settings\Paweł\Dane aplikacji\XKOJNO 2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Documents and Settings\Paweł\Dane aplikacji\CWNHZV 2014-08-31 21:49 - 2014-08-31 16:55 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempQU2860.html 2014-08-31 21:49 - 2014-08-31 16:55 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempuw2860.html 2014-08-31 15:42 - 2014-08-31 12:48 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TemphB4028.html 2014-08-31 15:42 - 2014-08-31 12:48 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempxs4028.html 2014-08-31 14:12 - 2009-07-05 22:43 - 00196608 _____ () C:\WINDOWS\system32\Drivers\nStandard.bin 2014-08-31 00:47 - 2014-08-30 18:58 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempjP3268.html 2014-08-31 00:47 - 2014-08-30 18:58 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempVj3268.html 2014-08-30 22:34 - 2009-06-29 00:16 - 00000049 _____ () C:\WINDOWS\NeroDigital.ini 2014-08-30 22:29 - 2013-06-09 18:50 - 00000000 ____D () C:\Documents and Settings\Paweł\Dane aplikacji\GoPlayer 2014-08-30 12:52 - 2014-08-30 12:52 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempew2188.html 2014-08-30 12:52 - 2014-08-30 12:52 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempss2188.html 2014-08-30 08:16 - 2014-08-30 08:09 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempyla792.html 2014-08-30 08:16 - 2014-08-30 08:09 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TemprKo792.html 2014-08-29 23:56 - 2014-08-29 21:43 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempEy3912.html 2014-08-29 23:56 - 2014-08-29 21:43 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempCt3912.html 2014-08-29 19:48 - 2014-08-29 16:41 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempPEP196.html 2014-08-29 19:48 - 2014-08-29 16:41 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempeTI196.html 2014-08-29 15:45 - 2014-08-29 14:45 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempSo3860.html 2014-08-29 15:45 - 2014-08-29 14:45 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempnW3860.html 2014-08-29 07:51 - 2014-08-29 07:38 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempbQ3208.html 2014-08-29 07:51 - 2014-08-29 07:38 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempIk3208.html 2014-08-28 20:43 - 2014-08-28 14:37 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TemptJ2020.html 2014-08-28 20:43 - 2014-08-28 14:37 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempgZ2020.html 2014-08-27 21:16 - 2014-08-27 15:21 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempcW3880.html 2014-08-27 21:16 - 2014-08-27 15:21 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempno3880.html 2014-08-26 22:12 - 2014-08-26 09:24 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempIT3388.html 2014-08-26 22:12 - 2014-08-26 09:24 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Temptl3388.html 2014-08-25 23:09 - 2014-08-25 23:07 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Templzs752.html 2014-08-25 23:09 - 2014-08-25 23:07 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempCRs752.html 2014-08-25 20:07 - 2014-08-25 18:54 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempta2536.html 2014-08-25 20:07 - 2014-08-25 18:54 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempSt2536.html 2014-08-23 09:10 - 2014-08-23 07:47 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Temptl3764.html 2014-08-23 09:10 - 2014-08-23 07:47 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempaP3764.html 2014-08-22 16:36 - 2014-08-22 13:37 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempYl3808.html 2014-08-22 16:36 - 2014-08-22 13:37 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempRU3808.html 2014-08-22 11:05 - 2014-08-22 10:48 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempmC2116.html 2014-08-22 11:05 - 2014-08-22 10:48 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempuz2116.html 2014-08-21 00:42 - 2014-08-20 23:32 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempaMU504.html 2014-08-21 00:42 - 2014-08-20 23:32 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempgGy504.html 2014-08-20 09:51 - 2014-08-20 08:40 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempTB3508.html 2014-08-20 09:51 - 2014-08-20 08:40 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Temppv3508.html 2014-08-20 07:54 - 2014-08-20 07:54 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempbI3640.html 2014-08-20 07:54 - 2014-08-20 07:54 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempEE3640.html 2014-08-19 21:04 - 2014-08-18 09:26 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempdh3168.html 2014-08-19 21:04 - 2014-08-18 09:26 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempYD3168.html 2014-08-18 20:35 - 2014-08-18 11:30 - 00000000 ____D () C:\Documents and Settings\Paweł\Pulpit\KOLORY ŚCIAN 2014-08-18 20:26 - 2014-08-18 20:26 - 00000183 _____ () C:\Documents and Settings\Paweł\Pulpit\Uchwyt do TV.txt 2014-08-17 23:43 - 2014-08-17 12:05 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempHv1348.html 2014-08-17 23:43 - 2014-08-17 12:05 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Tempph1348.html 2014-08-16 17:10 - 2014-08-16 10:04 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempVx4036.html 2014-08-16 17:10 - 2014-08-16 10:04 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\Temprw4036.html 2014-08-16 01:04 - 2014-08-15 09:56 - 00002432 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempnCC780.html 2014-08-16 01:04 - 2014-08-15 09:56 - 00002089 _____ () C:\Documents and Settings\Paweł\Ustawienia lokalne\TempoJc780.html 2014-08-16 00:53 - 2014-08-16 00:53 - 00000768 _____ () C:\Documents and Settings\Paweł\Pulpit\radia w łazience.txt 2014-08-15 12:49 - 2014-08-15 12:46 - 09477477 _____ () C:\Documents and Settings\Paweł\Pulpit\Fachowa instrukcja montażu paneli laminowanych - Quick-Step .flv Some content of TEMP: ==================== C:\Documents and Settings\Paweł\Ustawienia lokalne\Temp\DefaultTabSetup2.exe C:\Documents and Settings\Paweł\Ustawienia lokalne\Temp\extrafind4.exe C:\Documents and Settings\Paweł\Ustawienia lokalne\Temp\jre-7u17-windows-i586-iftw.exe C:\Documents and Settings\Paweł\Ustawienia lokalne\Temp\Quarantine.exe C:\Documents and Settings\Paweł\Ustawienia lokalne\Temp\uninst1.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================