Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-11-2014 01 Ran by Fabisiak (administrator) on FABISIAK-4CA8FE on 27-11-2014 19:58:53 Running from C:\Documents and Settings\Fabisiak\Moje dokumenty\Downloads Loaded Profile: Fabisiak (Available profiles: Fabisiak) Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 8 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (TeamViewer GmbH) C:\DOCUME~1\Fabisiak\USTAWI~1\Temp\TeamViewer\Version6\TeamViewer.exe (TeamViewer GmbH) C:\DOCUME~1\Fabisiak\USTAWI~1\Temp\TeamViewer\Version6\TeamViewer_Desktop.exe (TeamViewer GmbH) C:\DOCUME~1\Fabisiak\USTAWI~1\Temp\TeamViewer\Version6\tv_w32.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-11-18] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [124208 2014-10-22] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) HKU\S-1-5-21-1177238915-220523388-1801674531-1003\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation) HKU\S-1-5-21-1177238915-220523388-1801674531-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4825880 2014-10-23] (Piriform Ltd) Lsa: [Authentication Packages] msv1_0 nwprovau ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKU\S-1-5-21-1177238915-220523388-1801674531-1003 -> &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation) Toolbar: HKU\S-1-5-21-1177238915-220523388-1801674531-1003 -> &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{5347FFB3-BCC5-49F7-9757-713A83B8D977}: [NameServer] 192.168.88.1,82.160.1.1 FireFox: ======== Chrome: ======= CHR Profile: C:\Documents and Settings\Fabisiak\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default CHR Extension: (Docs) - C:\Documents and Settings\Fabisiak\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-27] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2014-11-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2014-11-18] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [164656 2014-10-22] (Avira Operations GmbH & Co. KG) S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed] R2 NWCWorkstation; C:\WINDOWS\System32\nwwks.dll [65536 2008-04-14] (Microsoft Corporation) R2 NwSapAgent; C:\WINDOWS\System32\ipxsap.dll [66560 2001-10-26] (Microsoft Corporation) S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 AR5416; C:\WINDOWS\System32\DRIVERS\athw.sys [1574112 2009-06-22] (Atheros Communications, Inc.) R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [98160 2014-09-24] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [136216 2014-09-24] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\WINDOWS\System32\DRIVERS\avkmgr.sys [37352 2014-09-24] (Avira Operations GmbH & Co. KG) S3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [533024 2009-06-18] (Broadcom Corporation.) R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [991136 2009-04-15] (Broadcom Corporation.) S3 btwhid; C:\WINDOWS\System32\DRIVERS\btwhid.sys [56992 2009-05-11] (Broadcom Corporation.) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation) R3 CnxtHdAudService; C:\WINDOWS\System32\drivers\CHDAU32.sys [822400 2010-07-18] (Conexant Systems Inc.) R3 HDAudBus; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [138752 2010-06-16] (Windows (R) Server 2003 DDK provider) [File not signed] S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [30976 2014-10-24] () S3 L1c; C:\WINDOWS\System32\DRIVERS\l1c51x86.sys [39424 2009-04-07] (Atheros Communications, Inc.) [File not signed] S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation) R2 NwlnkIpx; C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys [88320 2008-04-13] (Microsoft Corporation) R2 NwlnkNb; C:\WINDOWS\System32\DRIVERS\nwlnknb.sys [63232 2001-08-18] (Microsoft Corporation) R2 NwlnkSpx; C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys [55936 2001-08-18] (Microsoft Corporation) R3 NWRDR; C:\WINDOWS\System32\DRIVERS\nwrdr.sys [163584 2008-04-13] (Microsoft Corporation) R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [466008 2013-08-16] (Duplex Secure Ltd.) R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [28520 2014-09-24] (Avira GmbH) S4 IntelIde; No ImagePath U1 WS2IFSL; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-27 19:58 - 2014-11-27 19:58 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Ustawienia lokalne\Dane aplikacji\Google 2014-11-27 19:47 - 2014-11-27 19:47 - 00013044 _____ () C:\Documents and Settings\Fabisiak\Pulpit\GMER.txt 2014-11-27 19:44 - 2014-11-27 19:43 - 00003811 _____ () C:\Documents and Settings\Fabisiak\Pulpit\AdwCleaner[R5].txt 2014-11-27 19:27 - 2014-11-27 19:27 - 00001880 _____ () C:\WINDOWS\bitssetup.log 2014-11-27 19:16 - 2014-11-27 19:58 - 00002055 _____ () C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk 2014-11-27 19:16 - 2014-11-27 19:16 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Google Chrome 2014-11-27 19:11 - 2014-11-27 19:11 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Ustawienia lokalne\Dane aplikacji\Deployment 2014-11-27 17:59 - 2014-11-27 19:58 - 00000000 ____D () C:\FRST 2014-11-26 18:28 - 2014-11-27 19:57 - 00080304 _____ () C:\WINDOWS\setupapi.log 2014-11-23 13:36 - 2014-11-20 16:14 - 1031105672 ____R () C:\Documents and Settings\Fabisiak\Pulpit\The.Hunger.Games.Catching.Fire.2013.720p.BluRay.x264.YIFY.mp4 2014-11-16 15:34 - 2014-11-16 15:34 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Dane aplikacji\NCH Software 2014-11-15 17:12 - 2014-11-15 17:13 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\NCH Software 2014-11-15 17:12 - 2014-11-15 17:12 - 00000805 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\VideoPad Video Editor.lnk 2014-11-15 17:12 - 2014-11-15 17:12 - 00000799 _____ () C:\Documents and Settings\All Users\Pulpit\VideoPad Video Editor.lnk 2014-11-15 17:11 - 2014-11-15 17:46 - 00000000 ____D () C:\Program Files\NCH Software 2014-11-15 16:27 - 2014-11-15 16:55 - 00000000 ____D () C:\CamersoftOutput 2014-11-15 16:26 - 2014-11-15 16:26 - 00000000 ____D () C:\Program Files\Camersoft 2014-11-15 16:17 - 2014-11-15 16:17 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Moje dokumenty\SMRecorder 2014-11-15 16:17 - 2014-11-15 16:17 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Dane aplikacji\SMRecorder 2014-11-15 16:16 - 2014-11-15 16:33 - 00000000 ____D () C:\Program Files\SMRecorder 2014-11-12 21:55 - 2014-11-12 21:55 - 00098304 _____ () C:\WINDOWS\Minidump\Mini111214-01.dmp 2014-11-11 21:30 - 2014-11-11 21:30 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-11-11 21:29 - 2014-11-11 21:29 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Java 2014-11-11 21:29 - 2014-11-11 21:28 - 00146432 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl 2014-11-11 21:29 - 2014-11-11 21:28 - 00096680 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll 2014-11-11 20:00 - 2014-11-11 21:29 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Oracle 2014-11-11 19:59 - 2014-11-11 19:59 - 00000000 ____D () C:\Program Files\Java 2014-11-11 19:27 - 2014-11-11 19:27 - 00001677 _____ () C:\Documents and Settings\Fabisiak\Ustawienia lokalne\Dane aplikacji\recently-used.xbel 2014-11-11 14:48 - 2014-11-11 14:48 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-11-11 14:48 - 2014-11-11 14:48 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Adobe 2014-11-11 14:47 - 2014-11-11 14:47 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Ustawienia lokalne\Dane aplikacji\Adobe 2014-11-10 21:36 - 2014-11-27 17:51 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Pulpit\Weselee 2014-11-08 12:29 - 2014-11-08 12:29 - 00000736 _____ () C:\Documents and Settings\Fabisiak\Pulpit\GIMP 2.lnk 2014-11-08 12:24 - 2014-11-08 12:28 - 00000000 ____D () C:\Program Files\GIMP 2 2014-10-28 16:21 - 2014-11-25 20:52 - 01044608 _____ () C:\WINDOWS\setupapi.log.14.old 2014-10-28 16:19 - 2014-10-28 16:19 - 00098304 _____ () C:\WINDOWS\Minidump\Mini102814-01.dmp ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-27 19:59 - 2010-08-18 17:27 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Ustawienia lokalne\Temp 2014-11-27 19:58 - 2010-08-18 17:27 - 00000000 ___HD () C:\Documents and Settings\Fabisiak\Ustawienia lokalne\Dane aplikacji 2014-11-27 19:58 - 2010-08-18 17:27 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Pulpit 2014-11-27 19:57 - 2010-08-18 17:22 - 01927357 _____ () C:\WINDOWS\WindowsUpdate.log 2014-11-27 19:56 - 2014-08-27 11:48 - 00000008 __RSH () C:\Documents and Settings\All Users\ntuser.pol 2014-11-27 19:56 - 2010-08-18 19:17 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2014-11-27 19:56 - 2010-08-18 19:17 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2014-11-27 19:56 - 2010-08-18 17:27 - 00000000 __SHD () C:\Documents and Settings\LocalService\Ustawienia lokalne\Historia 2014-11-27 19:55 - 2014-10-13 14:37 - 00138104 _____ () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat 2014-11-27 19:55 - 2014-04-04 20:44 - 00000228 _____ () C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job 2014-11-27 19:55 - 2011-08-31 15:12 - 00001036 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-27 19:55 - 2010-08-18 17:27 - 00032384 _____ () C:\WINDOWS\SchedLgU.Txt 2014-11-27 19:55 - 2010-08-18 17:27 - 00000188 ___SH () C:\Documents and Settings\Fabisiak\ntuser.ini 2014-11-27 19:55 - 2010-08-18 17:27 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-11-27 19:55 - 2010-08-18 17:27 - 00000000 __SHD () C:\Documents and Settings\Fabisiak\Ustawienia lokalne\Historia 2014-11-27 19:55 - 2010-08-18 17:27 - 00000000 ___HD () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji 2014-11-27 19:55 - 2010-08-18 17:27 - 00000000 ____D () C:\Documents and Settings\Fabisiak 2014-11-27 19:55 - 2001-07-22 01:17 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl 2014-11-27 19:51 - 2010-08-18 17:26 - 00000000 ___HD () C:\Documents and Settings\NetworkService\Ustawienia lokalne\Historia 2014-11-27 19:50 - 2010-08-18 19:14 - 00000000 __SHD () C:\Documents and Settings\Default User\Ustawienia lokalne\Historia 2014-11-27 19:50 - 2010-08-18 19:14 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji 2014-11-27 19:50 - 2010-08-18 17:27 - 00000000 __RHD () C:\Documents and Settings\Fabisiak\Dane aplikacji 2014-11-27 19:50 - 2010-08-18 17:27 - 00000000 ___RD () C:\Documents and Settings\Fabisiak\Menu Start 2014-11-27 19:50 - 2010-08-18 17:20 - 00000000 ____D () C:\WINDOWS\Registration 2014-11-27 19:49 - 2014-08-27 11:48 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy 2014-11-27 19:43 - 2014-10-10 16:33 - 00000000 ____D () C:\AdwCleaner 2014-11-27 19:43 - 2010-10-03 17:06 - 00007168 ___SH () C:\WINDOWS\Thumbs.db 2014-11-27 19:29 - 2014-02-13 13:24 - 00000930 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-11-27 19:16 - 2011-08-31 15:12 - 00001040 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-27 19:16 - 2010-08-18 19:14 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2014-11-27 19:16 - 2010-08-18 19:14 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy 2014-11-27 19:07 - 2010-08-18 17:27 - 00000000 ___RD () C:\Documents and Settings\Fabisiak\Menu Start\Programy 2014-11-27 18:33 - 2011-08-31 15:12 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Dane aplikacji\PhotoScape 2014-11-27 18:18 - 2012-03-13 13:44 - 01192448 ___SH () C:\Documents and Settings\Fabisiak\Pulpit\Thumbs.db 2014-11-27 18:04 - 2010-08-18 18:10 - 00000000 ____D () C:\WINDOWS\system32\NtmsData 2014-11-27 18:03 - 2010-08-18 17:27 - 00000803 _____ () C:\Documents and Settings\Fabisiak\Menu Start\Programy\Internet Explorer.lnk 2014-11-27 17:55 - 2014-10-02 17:13 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Dane aplikacji\TeamViewer 2014-11-26 19:38 - 2014-10-09 20:40 - 00023552 ____H () C:\Documents and Settings\Fabisiak\Pulpit\photothumb.db 2014-11-26 19:38 - 2014-10-09 20:19 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Pulpit\fb 2014-11-26 18:30 - 2014-02-13 13:24 - 00701104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2014-11-26 18:30 - 2014-02-13 13:24 - 00071344 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2014-11-23 23:13 - 2010-08-18 18:03 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Dane aplikacji\AIMP 2014-11-16 21:37 - 2013-07-26 23:30 - 00000000 ____D () C:\Documents and Settings\Fabisiak\.gimp-2.8 2014-11-16 15:37 - 2010-12-10 20:55 - 00095744 _____ () C:\Documents and Settings\Fabisiak\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-11-16 15:11 - 2014-02-22 09:45 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-11-16 14:59 - 2012-03-08 16:51 - 100445232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-11-15 17:45 - 2010-08-18 17:27 - 00000000 ___RD () C:\Documents and Settings\Fabisiak\Ulubione 2014-11-15 17:17 - 2010-08-18 17:27 - 00000000 ___RD () C:\Documents and Settings\Fabisiak\Moje dokumenty\Moje obrazy 2014-11-15 17:13 - 2011-08-31 13:34 - 00000000 ___RD () C:\Documents and Settings\Fabisiak\Moje dokumenty\Moje wideo 2014-11-15 16:17 - 2010-08-18 17:27 - 00000000 ___RD () C:\Documents and Settings\Fabisiak\Moje dokumenty 2014-11-15 09:50 - 2012-04-01 22:38 - 00000664 _____ () C:\WINDOWS\system32\d3d9caps.dat 2014-11-12 21:55 - 2010-10-11 07:42 - 00000000 ____D () C:\WINDOWS\Minidump 2014-11-11 19:27 - 2013-07-26 23:32 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Ustawienia lokalne\Dane aplikacji\gtk-2.0 2014-11-11 13:35 - 2011-08-31 15:10 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Google 2014-11-11 13:32 - 2010-12-30 14:00 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Electronic Arts 2014-11-11 13:32 - 2010-08-18 17:33 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-11-11 13:31 - 2014-10-24 15:56 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Dane aplikacji\uTorrent 2014-11-11 12:55 - 2010-08-18 20:08 - 00000000 ____D () C:\Documents and Settings\Fabisiak\Dane aplikacji\dvdcss 2014-11-08 20:02 - 2010-08-18 19:15 - 01089352 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-11-08 20:02 - 2001-10-26 19:15 - 00491314 _____ () C:\WINDOWS\system32\perfh015.dat 2014-11-08 20:02 - 2001-10-26 19:15 - 00084526 _____ () C:\WINDOWS\system32\perfc015.dat 2014-11-08 19:57 - 2014-10-13 14:18 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Package Cache 2014-11-08 15:09 - 2014-10-13 14:19 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Avira 2014-11-08 15:09 - 2010-08-18 18:05 - 00000000 ____D () C:\Program Files\Avira 2014-11-08 15:00 - 2014-04-04 20:44 - 00000222 _____ () C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job Some content of TEMP: ==================== C:\Documents and Settings\Fabisiak\Ustawienia lokalne\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================