Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-10-2014 01 Ran by User (administrator) on 039D8371C0124F5 on 13-10-2014 19:33:05 Running from C:\Documents and Settings\User\Moje dokumenty\Pobrane Loaded Profile: User (Available profiles: User & Administrator) Platform: Microsoft Windows XP Professional Dodatek Service Pack 2 (X86) OS Language: Polski Internet Explorer Version 6 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ABBYY) C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe (Dassault Systèmes) C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe (Deutsche Kahneisen Gesellschaft mbH) C:\Program Files\Common Files\Jordahl\Update\JordahlUpdateService.exe (HP) C:\WINDOWS\system32\HPZipm12.exe (SafeNet, Inc.) C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe (SafeNet, Inc) C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe (SafeNet, Inc.) C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe () C:\Program Files\Common Files\RbtProt\sgsrv.exe (GEMTEKS) C:\Program Files\Linksys\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe (Linksys) C:\Program Files\Linksys\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE (Old McDonald's Farm) C:\Program Files\Autorun Eater\oldmcdonald.exe () C:\Program Files\QPrinter Bookmaker\qprintmon.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe () C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Old McDonald's Farm) C:\Program Files\Autorun Eater\billy.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe (TeamViewer GmbH) C:\DOCUME~1\User\USTAWI~1\temp\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\DOCUME~1\User\USTAWI~1\temp\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\DOCUME~1\User\USTAWI~1\temp\TeamViewer\Version9\TeamViewer_Desktop.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [17887232 2009-06-25] (Realtek Semiconductor Corp.) HKLM\...\Run: [Autorun Eater] => C:\Program Files\Autorun Eater\oldmcdonald.exe [516216 2010-05-06] (Old McDonald's Farm) HKLM\...\Run: [QPrinter 2.0 monitor] => C:\Program Files\QPrinter Bookmaker\qprintmon --server HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2005-05-11] (Hewlett-Packard Co.) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-10-13] (AVAST Software) HKU\S-1-5-21-2000478354-842925246-725345543-1003\...\Run: [KiesPDLR] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21432 2012-05-30] () HKU\S-1-5-21-2000478354-842925246-725345543-1003\...\Run: [ALLUpdate] => C:\Program Files\ALLPlayer\ALLUpdate.exe [1379840 2011-08-16] () Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Image Zone - szybkie uruchamianie.lnk ShortcutTarget: HP Image Zone - szybkie uruchamianie.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Przyspieszenie uruchomienia programu AutoCAD.lnk ShortcutTarget: Przyspieszenie uruchomienia programu AutoCAD.lnk -> C:\Program Files\Common Files\Autodesk Shared\acstart17.exe (Autodesk, Inc) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ShellIconOverlayIdentifiers: [GGDriveOverlay1] -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => C:\Documents and Settings\All Users\Dane aplikacji\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay2] -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => C:\Documents and Settings\All Users\Dane aplikacji\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay3] -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => C:\Documents and Settings\All Users\Dane aplikacji\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: [GGDriveOverlay4] -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => C:\Documents and Settings\All Users\Dane aplikacji\GG\ggdrive\ggdrive-overlay.dll (GG Network S.A.) ShellIconOverlayIdentifiers: [Uchwyt nakładania ikony podpisu cyfrowego] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll (Autodesk) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home URLSearchHook: HKCU - Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Livebox\SearchURLHook\SearchPageURL.dll No File SearchScopes: HKLM - DefaultScope value is missing. BHO: IplexToALLPlayer -> {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} -> C:\Program Files\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\mtkqsmsv.default-1413216346156 FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: Adblock Plus - C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\mtkqsmsv.default-1413216346156\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-13] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-10-13] Chrome: ======= CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-13] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ABBYY.Licensing.FineReader.Professional.10.0; C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [809736 2009-09-29] (ABBYY) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-13] (AVAST Software) R2 DraftSight API Service; C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe [86016 2012-12-27] (Dassault Systèmes) [File not signed] S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2010-11-01] (Macrovision Europe Ltd.) [File not signed] R2 JordahlUpdateSvc; C:\Program Files\Common Files\Jordahl\Update\JordahlUpdateService.exe [3158096 2013-01-11] (Deutsche Kahneisen Gesellschaft mbH) R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [69632 2004-09-29] (HP) [File not signed] R2 SentinelKeysServer; C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [374304 2011-09-22] (SafeNet, Inc.) R2 SentinelProtectionServer; C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [1259040 2011-09-22] (SafeNet, Inc) R2 SentinelSecurityRuntime; C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe [292384 2011-09-22] (SafeNet, Inc.) R2 SG_Service; C:\Program Files\Common Files\RbtProt\sgsrv.exe [155648 2003-10-25] () [File not signed] R2 WUSB54GCSVC; "C:\Program Files\Linksys\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [20747 2010-05-17] (Meetinghouse Data Communications) [File not signed] R3 AIRPLUS; C:\WINDOWS\System32\DRIVERS\airplus.sys [255360 2010-04-02] (D-Link) S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1684736 2009-06-25] (Creative) R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-10-13] () R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-10-13] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55112 2014-10-13] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-10-13] () R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [779536 2014-10-13] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [414520 2014-10-13] (AVAST Software) R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57800 2014-10-13] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [192352 2014-10-13] () S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2004-08-04] (Microsoft Corporation) R3 GTNDIS5; C:\WINDOWS\system32\GTNDIS5.SYS [15872 2003-09-25] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed] R2 Haspnt; C:\WINDOWS\system32\drivers\Haspnt.sys [47616 2010-06-13] (Aladdin Knowledge Systems) [File not signed] R3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [51120 2005-03-08] (HP) R3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2005-03-08] (HP) R3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21744 2005-03-08] (HP) R3 L1c; C:\WINDOWS\System32\DRIVERS\l1c51x86.sys [44032 2009-07-27] (Atheros Communications, Inc.) S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1389056 2009-06-25] (Creative Technology Ltd.) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2004-08-04] (Microsoft Corporation) S3 PCAMPR5; C:\WINDOWS\system32\PCAMPR5.SYS [34688 2003-09-23] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed] S3 PCANDIS5; C:\WINDOWS\system32\PCANDIS5.SYS [32128 2006-03-01] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed] R3 RT73; C:\WINDOWS\System32\DRIVERS\rt73.sys [252928 2006-01-12] (Ralink Technology, Corp.) S3 Secdrv; C:\WINDOWS\System32\DRIVERS\secdrv.sys [27440 2004-07-17] () S3 SNPP106; C:\WINDOWS\System32\DRIVERS\snpp106.sys [239488 2002-12-05] () S3 SNTNLUSB; C:\WINDOWS\System32\DRIVERS\SNTNLUSB.SYS [41896 2011-09-22] (SafeNet, Inc.) R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [691696 2010-09-16] () [File not signed] S3 ssudserd; C:\WINDOWS\System32\DRIVERS\ssudserd.sys [181432 2012-05-21] (DEVGURU Co., LTD.(www.devguru.co.kr)) R0 tffsport; C:\WINDOWS\System32\DRIVERS\tffsport.sys [149376 2004-08-03] (M-Systems) R2 WIBUKEY; C:\WINDOWS\System32\DRIVERS\WibuKey.sys [72704 2008-06-27] (WIBU-SYSTEMS AG) [File not signed] U3 ajd2na3w; C:\WINDOWS\system32\Drivers\ajd2na3w.sys [0 ] (Microsoft Corporation) S4 IntelIde; No ImagePath S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-13 18:22 - 2014-10-13 18:22 - 00000000 ____D () C:\Documents and Settings\User\Dane aplikacji\AVAST Software 2014-10-13 18:20 - 2014-10-13 19:30 - 00000360 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job 2014-10-13 18:20 - 2014-10-13 18:20 - 00779536 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2014-10-13 18:20 - 2014-10-13 18:20 - 00414520 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys 2014-10-13 18:20 - 2014-10-13 18:20 - 00192352 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys 2014-10-13 18:20 - 2014-10-13 18:20 - 00067824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2014-10-13 18:20 - 2014-10-13 18:20 - 00057800 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys 2014-10-13 18:20 - 2014-10-13 18:20 - 00055112 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys 2014-10-13 18:20 - 2014-10-13 18:20 - 00049944 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys 2014-10-13 18:20 - 2014-10-13 18:20 - 00024184 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys 2014-10-13 18:20 - 2014-10-13 18:20 - 00001733 _____ () C:\Documents and Settings\All Users\Pulpit\avast! Free Antivirus.lnk 2014-10-13 18:20 - 2014-10-13 18:20 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Avast 2014-10-13 18:20 - 2014-10-13 18:19 - 00276432 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2014-10-13 18:19 - 2014-10-13 18:19 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr 2014-10-13 18:15 - 2014-10-13 18:15 - 00000000 ____D () C:\Program Files\AVAST Software 2014-10-13 18:14 - 2014-10-13 18:15 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software 2014-10-13 15:39 - 2014-10-13 19:33 - 00000000 ____D () C:\FRST 2014-10-13 15:25 - 2014-10-13 15:25 - 00000000 ___HD () C:\WINDOWS\PIF 2014-10-13 14:05 - 2014-10-13 19:29 - 00000000 ____D () C:\Documents and Settings\LocalService\Ustawienia lokalne\temp 2014-10-13 14:05 - 2014-10-13 14:05 - 00000000 ____D () C:\Documents and Settings\NetworkService\Ustawienia lokalne\temp 2014-10-13 14:05 - 2014-10-13 14:05 - 00000000 ____D () C:\Documents and Settings\Administrator\Ustawienia lokalne\temp 2014-10-13 13:48 - 2014-10-13 13:48 - 00000000 _RSHD () C:\cmdcons 2014-10-13 13:48 - 2011-04-07 21:49 - 00000211 _____ () C:\Boot.bak 2014-10-13 13:48 - 2004-08-03 23:00 - 00262400 __RSH () C:\cmldr 2014-10-13 13:15 - 2014-10-13 13:15 - 00006104 __RSH () C:\Documents and Settings\All Users\ntuser.pol 2014-10-13 13:14 - 2014-10-13 13:14 - 00000000 ___RD () C:\Documents and Settings\User\Menu Start\Programy\Narzędzia administracyjne 2014-10-13 13:09 - 2014-10-13 13:14 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy 2014-10-13 12:55 - 2014-10-13 12:55 - 00000000 ____D () C:\Documents and Settings\User\Dane aplikacji\TeamViewer 2014-10-03 11:02 - 2014-10-03 11:03 - 00395819 _____ () C:\Documents and Settings\User\Pulpit\pow2.PLN 2014-09-27 13:30 - 2014-10-13 18:03 - 00000000 ____D () C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-13 19:33 - 2014-06-20 02:10 - 00000000 ____D () C:\Documents and Settings\User\Moje dokumenty\Pobrane 2014-10-13 19:33 - 2011-04-05 20:55 - 00000000 ____D () C:\Documents and Settings\User\Ustawienia lokalne\temp 2014-10-13 19:30 - 2010-04-02 15:40 - 00440704 _____ () C:\WINDOWS\WindowsUpdate.log 2014-10-13 19:29 - 2010-04-02 17:35 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-10-13 19:29 - 2010-04-02 17:35 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-10-13 19:29 - 2010-04-02 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-10-13 19:29 - 2010-04-02 15:45 - 00000000 ___SD () C:\Documents and Settings\NetworkService\Ustawienia lokalne\Historia 2014-10-13 19:29 - 2010-04-02 15:45 - 00000000 ___SD () C:\Documents and Settings\LocalService\Ustawienia lokalne\Historia 2014-10-13 19:28 - 2011-02-22 23:59 - 00170162 _____ () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat 2014-10-13 19:28 - 2010-04-02 15:46 - 00000188 ___SH () C:\Documents and Settings\User\ntuser.ini 2014-10-13 19:28 - 2010-04-02 15:46 - 00000000 ___SD () C:\Documents and Settings\User\Ustawienia lokalne\Historia 2014-10-13 19:28 - 2010-04-02 15:45 - 00032630 _____ () C:\WINDOWS\SchedLgU.Txt 2014-10-13 19:14 - 2010-04-02 15:46 - 00000000 ____D () C:\Documents and Settings\User\Pulpit 2014-10-13 19:13 - 2010-04-02 17:33 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2014-10-13 18:51 - 2010-04-02 17:33 - 01281298 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-10-13 18:51 - 2001-10-26 16:15 - 00564344 _____ () C:\WINDOWS\system32\perfh015.dat 2014-10-13 18:51 - 2001-10-26 16:15 - 00109430 _____ () C:\WINDOWS\system32\perfc015.dat 2014-10-13 18:45 - 2013-06-18 12:17 - 00000000 ____D () C:\Documents and Settings\User\Dane aplikacji\GG 2014-10-13 18:22 - 2010-04-02 15:46 - 00000000 __RHD () C:\Documents and Settings\User\Dane aplikacji 2014-10-13 18:20 - 2010-04-02 17:33 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy 2014-10-13 18:14 - 2010-04-02 17:31 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji 2014-10-13 18:07 - 2010-04-02 17:31 - 00662973 _____ () C:\WINDOWS\setupapi.log 2014-10-13 18:00 - 2010-04-02 15:46 - 00000000 ___HD () C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji 2014-10-13 17:41 - 2010-04-02 17:26 - 00000000 ____D () C:\WINDOWS\security 2014-10-13 17:01 - 2011-04-04 22:20 - 00000000 ___HD () C:\Documents and Settings\Administrator\Ustawienia lokalne\Historia 2014-10-13 17:01 - 2010-04-02 17:33 - 00000000 ___SD () C:\Documents and Settings\Default User\Ustawienia lokalne\Historia 2014-10-13 16:00 - 2012-08-20 19:13 - 00000364 _____ () C:\WINDOWS\Tasks\HPpromotions journeysoftware.job 2014-10-13 14:07 - 2010-04-02 15:45 - 00000000 __SHD () C:\Documents and Settings\NetworkService 2014-10-13 14:05 - 2011-04-04 22:20 - 00000000 ___HD () C:\Documents and Settings\Administrator\Ustawienia lokalne 2014-10-13 14:05 - 2010-04-02 15:45 - 00000000 ___HD () C:\Documents and Settings\NetworkService\Ustawienia lokalne 2014-10-13 14:05 - 2010-04-02 15:45 - 00000000 ___HD () C:\Documents and Settings\LocalService\Ustawienia lokalne 2014-10-13 14:01 - 2001-07-21 22:15 - 00000227 _____ () C:\WINDOWS\system.ini 2014-10-13 13:59 - 2010-04-02 17:33 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start 2014-10-13 13:48 - 2010-04-02 17:30 - 00000327 __RSH () C:\boot.ini 2014-10-13 13:45 - 2010-04-02 15:39 - 00000000 ____D () C:\WINDOWS\system32\Restore 2014-10-13 13:27 - 2011-02-25 00:02 - 00691098 _____ () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-2000478354-842925246-725345543-1003-0.dat 2014-10-13 13:14 - 2010-04-02 15:46 - 00000000 ___RD () C:\Documents and Settings\User\Menu Start\Programy 2014-10-13 13:05 - 2013-06-18 12:17 - 00000000 ____D () C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\GG 2014-10-13 10:47 - 2001-07-21 22:17 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl 2014-10-10 10:26 - 2014-06-06 14:44 - 00000104 _____ () C:\Documents and Settings\User\Pulpit\Robota.txt 2014-10-09 21:38 - 2014-07-19 14:11 - 00000000 ____D () C:\Program Files\Common Files\Jordahl 2014-10-09 21:34 - 2010-04-02 15:46 - 00000000 ___RD () C:\Documents and Settings\User\Menu Start 2014-10-09 21:05 - 2010-11-30 00:38 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes 2014-10-09 20:17 - 2011-09-14 09:45 - 00000000 ____D () C:\Teczka ArchiCADa 6.5 2014-10-09 20:16 - 2014-04-30 00:51 - 00000000 ____D () C:\Documents and Settings\User\Pulpit\Inne 2014-10-09 18:41 - 2012-12-28 14:27 - 00002347 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk 2014-10-09 18:15 - 2010-05-25 19:15 - 00000000 ____D () C:\Program Files\ABBYY FineReader 10 2014-10-09 18:14 - 2010-07-18 13:13 - 00002515 _____ () C:\Documents and Settings\User\Pulpit\Microsoft Word.lnk 2014-10-04 14:42 - 2010-04-02 15:38 - 00046482 _____ () C:\WINDOWS\wmsetup.log 2014-10-02 20:12 - 2014-04-03 13:12 - 00000000 ____D () C:\Documents and Settings\User\Moje dokumenty\Vitooptima - autozapis 2014-10-02 19:32 - 2013-08-23 19:00 - 00000000 ____D () C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\Deployment 2014-09-30 15:09 - 2012-05-05 15:23 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-09-17 10:42 - 2014-04-29 23:26 - 00000000 ____D () C:\Documents and Settings\User\Pulpit\Dziadek ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================