Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-01-2015 Ran by Główne (administrator) on MARCIN on 04-01-2015 23:16:47 Running from C:\Documents and Settings\Główne\Moje dokumenty\Pobrane Loaded Profile: Główne (Available profiles: Główne & Gość) Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 6 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (AVAST Software) C:\PROGRA~1\ALWILS~1\Avast5\AvastUI.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\Toshiba.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe (Microsoft Corporation) C:\PROGRA~1\MICROS~4\rapimgr.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe () C:\Documents and Settings\Główne\Moje dokumenty\Pobrane\p4qcc2yd.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [avast5] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4858968 2013-08-30] (AVAST Software) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [761945 2005-12-16] (Synaptics, Inc.) Winlogon\Notify\psfus: C:\WINDOWS\system32\psqlpwd.dll (UPEK Inc.) HKU\S-1-5-21-1935655697-261478967-682003330-1004\...\Run: [H/PC Connection Agent] => C:\Program Files\Microsoft ActiveSync\wcescomm.exe [1289000 2006-11-13] (Microsoft Corporation) HKU\S-1-5-21-1935655697-261478967-682003330-1004\...\Run: [Polar Sync] => :\program files\polar\polar sync\ (the data entry has 59 more characters). HKU\S-1-5-21-1935655697-261478967-682003330-1004\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd) HKU\S-1-5-21-1935655697-261478967-682003330-1004\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x91000000 HKU\S-1-5-21-1935655697-261478967-682003330-1004\...\MountPoints2: {984eca60-ebc5-11e0-80d3-001302bda0ca} - F:\AutoRun.exe Lsa: [Notification Packages] scecli psqlpwd ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShell.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-1935655697-261478967-682003330-1004\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch URLSearchHook: HKU\S-1-5-21-1935655697-261478967-682003330-1004 - Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation) HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "" <======= ATTENTION SearchScopes: HKLM -> DefaultScope value is missing. BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: text/html - {574940E0-1B7A-4881-8FA3-1E809714B156} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Główne\Dane aplikacji\Mozilla\Firefox\Profiles\touqbu4g.default FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @ganymede/GanymedeNetPlugin,version=1.0 -> C:\Program Files\Ganymede\Plugins\npganymedenet.dll ( ) FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1935655697-261478967-682003330-1004: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Documents and Settings\Główne\Ustawienia lokalne\Dane aplikacji\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Oracle Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npganymedenet.dll ( ) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Extension: PEKAO S.A. Sign Plugin - C:\Documents and Settings\Główne\Dane aplikacji\Mozilla\Firefox\Profiles\touqbu4g.default\Extensions\SignPlugin@pekao.pl [2014-02-04] FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\Główne\Dane aplikacji\Mozilla\Firefox\Profiles\touqbu4g.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}(2) [2012-01-10] FF Extension: Adblock Plus - C:\Documents and Settings\Główne\Dane aplikacji\Mozilla\Firefox\Profiles\touqbu4g.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(2) [2012-01-10] FF Extension: Imageshack-Clickberry Browser Add-on - C:\Documents and Settings\Główne\Dane aplikacji\Mozilla\Firefox\Profiles\touqbu4g.default\Extensions\jid1-2XvMEc6Luckz4w@jetpack.xpi [2013-08-20] FF Extension: Greasemonkey - C:\Documents and Settings\Główne\Dane aplikacji\Mozilla\Firefox\Profiles\touqbu4g.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2012-08-25] FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-04-29] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-12-25] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012-03-29] Chrome: ======= ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed] R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [161664 2012-09-25] (Oracle Corporation) S2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) S2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed] S2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed] S4 Samsung UPD Service2; C:\WINDOWS\system32\SUPDSvc2.exe [129536 2012-04-06] (Samsung Electronics) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 Afc; C:\WINDOWS\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.) R2 aswFsBlk; C:\WINDOWS\system32\Drivers\aswFsBlk.sys [29816 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [66336 2013-08-30] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\Drivers\aswRdr.sys [49760 2013-08-30] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49376 2013-08-30] () R1 aswSnx; C:\WINDOWS\system32\Drivers\aswSnx.sys [770784 2014-12-03] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\Drivers\aswSP.sys [369584 2013-08-30] (AVAST Software) R1 aswTdi; C:\WINDOWS\system32\Drivers\aswTdi.sys [56080 2013-08-30] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [177864 2013-08-30] () S3 Bulk1528; C:\WINDOWS\System32\Drivers\Bulk1528.sys [11648 2008-06-27] (SunPlus) S2 Ca1528av; C:\WINDOWS\System32\Drivers\Ca1528av.sys [516480 2008-12-16] (Digital Camera) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation) S3 cpudrv; C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2009-12-18] () R2 FdRedir; c:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [13568 2005-12-21] (UPEK Inc.) [File not signed] R2 FileDisk2; c:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys [33024 2005-12-21] (UPEK Inc.) [File not signed] S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP) S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP) S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP) S3 KS-959; C:\WINDOWS\System32\DRIVERS\KS-959.sys [19034 2005-09-05] (Kingsun Corporation) [File not signed] S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation) S3 MPE; C:\WINDOWS\System32\DRIVERS\MPE.sys [15232 2008-04-13] (Microsoft Corporation) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation) R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation) S3 RTL2832UBDA; C:\WINDOWS\System32\drivers\RTL2832UBDA.sys [93344 2009-10-26] (REALTEK SEMICONDUCTOR Corp.) S3 RTL2832UUSB; C:\WINDOWS\System32\Drivers\RTL2832UUSB.sys [32800 2009-10-26] (REALTEK SEMICONDUCTOR Corp.) S3 RTL2832U_IRHID; C:\WINDOWS\System32\DRIVERS\RTL2832U_IRHID.sys [31872 2009-10-05] (Realtek) S3 s1018obex; C:\WINDOWS\System32\DRIVERS\s1018obex.sys [104744 2009-03-25] (MCCI Corporation) R2 smihlp; c:\Program Files\Protector Suite QL\smihlp.sys [3456 2005-12-21] (UPEK Inc.) [File not signed] S3 SONYPVU1; C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation) U0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [320120 2015-01-04] (Duplex Secure Ltd.) R3 w39n51; C:\WINDOWS\System32\DRIVERS\w39n51.sys [1428096 2005-12-05] (Intel® Corporation) S3 wceusbsh; C:\WINDOWS\System32\DRIVERS\wceusbsh.sys [28672 2006-11-06] (Microsoft Corporation) U5 BTHPORT; C:\Windows\System32\Drivers\BTHPORT.sys [273024 2008-06-14] (Microsoft Corporation) S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S4 IntelIde; No ImagePath U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) S3 taphss; system32\DRIVERS\taphss.sys [X] S3 tbiosdrv; \??\E:\TBIOSDRV.SYS [X] U5 Tosrfcom; C:\Windows\System32\Drivers\Tosrfcom.sys [64896 2005-08-01] (TOSHIBA Corporation) [File not signed] U3 pxtdypog; \??\C:\DOCUME~1\GWNE~1\USTAWI~1\Temp\pxtdypog.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-04 23:14 - 2015-01-04 23:16 - 00000000 ____D () C:\FRST 2015-01-04 23:12 - 2015-01-04 23:12 - 00002145 _____ () C:\Documents and Settings\Główne\Pulpit\GMER szybki.txt 2015-01-04 23:08 - 2015-01-04 23:08 - 00088029 _____ () C:\Documents and Settings\Główne\Pulpit\GMER pełny.txt 2015-01-04 20:30 - 2015-01-04 20:30 - 00000000 _____ () C:\Documents and Settings\Główne\defogger_reenable 2015-01-04 20:28 - 2015-01-04 20:28 - 00320120 _____ (Duplex Secure Ltd.) C:\WINDOWS\system32\Drivers\sptd.sys 2015-01-04 13:50 - 2015-01-04 13:50 - 00000777 _____ () C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk 2015-01-04 13:41 - 2015-01-04 20:31 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-01-04 13:25 - 2015-01-04 13:25 - 00124608 _____ () C:\Documents and Settings\Główne\Moje dokumenty\cc_20150104_132518.reg 2015-01-04 13:15 - 2015-01-04 13:15 - 00000682 _____ () C:\Documents and Settings\All Users\Pulpit\CCleaner.lnk 2014-12-29 15:55 - 2014-12-29 15:55 - 01575530 _____ () C:\Documents and Settings\Główne\Pulpit\wizytówka.psd 2014-12-28 23:23 - 2014-12-28 23:23 - 00000000 ____D () C:\Program Files\astrojargon.net 2014-12-28 23:23 - 2014-12-28 23:23 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\astrojargon.net 2014-12-28 22:56 - 2015-01-03 18:59 - 00000000 ____D () C:\Documents and Settings\Główne\Pulpit\wizytówki 2014-12-20 21:41 - 2014-12-29 00:44 - 00000000 ____D () C:\Documents and Settings\Główne\Pulpit\aukcje 2014-12-19 00:02 - 2014-12-20 13:34 - 00000000 ____D () C:\Documents and Settings\Główne\Pulpit\dywany 2014-12-18 10:05 - 2014-12-18 11:04 - 00000000 ____D () C:\Documents and Settings\Główne\Pulpit\polar 2014-12-12 23:42 - 2014-12-12 23:42 - 00097792 _____ () C:\Documents and Settings\Główne\Pulpit\Efekt forestera.ppt 2014-12-09 22:14 - 2014-12-09 22:19 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-12-07 19:27 - 2014-12-07 19:27 - 00001092 _____ () C:\Documents and Settings\Główne\Pulpit\Live PC Help.lnk ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-04 23:17 - 2011-07-10 22:45 - 00000000 ____D () C:\Documents and Settings\Główne\Ustawienia lokalne\Temp 2015-01-04 23:16 - 2014-06-21 22:15 - 00000000 ____D () C:\Documents and Settings\Główne\Moje dokumenty\Pobrane 2015-01-04 23:12 - 2011-07-10 22:45 - 00000000 ____D () C:\Documents and Settings\Główne\Pulpit 2015-01-04 22:51 - 2012-05-09 16:05 - 00001036 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-04 22:10 - 2013-05-23 15:05 - 00001006 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1935655697-261478967-682003330-1004UA.job 2015-01-04 21:20 - 2013-01-04 19:29 - 00000366 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job 2015-01-04 20:30 - 2011-07-10 22:45 - 00000000 ____D () C:\Documents and Settings\Główne 2015-01-04 19:19 - 2010-04-07 13:42 - 01520448 _____ () C:\WINDOWS\WindowsUpdate.log 2015-01-04 19:14 - 2014-03-27 15:53 - 00000224 _____ () C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job 2015-01-04 19:14 - 2012-05-09 16:05 - 00001032 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-04 19:13 - 2010-04-07 13:47 - 00032582 _____ () C:\WINDOWS\SchedLgU.Txt 2015-01-04 19:13 - 2004-08-04 13:00 - 00013646 _____ () C:\WINDOWS\system32\wpa.dbl 2015-01-04 19:07 - 2010-04-07 15:34 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2015-01-04 19:07 - 2010-04-07 15:34 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2015-01-04 19:06 - 2010-04-07 15:30 - 00146808 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2015-01-04 19:06 - 2010-04-07 13:47 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-01-04 19:03 - 2011-07-10 22:45 - 00000188 ___SH () C:\Documents and Settings\Główne\ntuser.ini 2015-01-04 16:10 - 2013-05-23 15:05 - 00000984 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1935655697-261478967-682003330-1004Core.job 2015-01-04 13:50 - 2014-10-01 23:01 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2015-01-04 13:50 - 2014-10-01 23:01 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes Anti-Malware 2015-01-04 13:50 - 2010-04-07 15:31 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2015-01-04 13:25 - 2011-07-10 22:45 - 00000000 ___RD () C:\Documents and Settings\Główne\Moje dokumenty 2015-01-04 13:23 - 2012-09-26 21:14 - 00000000 ____D () C:\Program Files\PDFCreator 2015-01-04 13:23 - 2011-01-11 17:54 - 00000000 ____D () C:\WINDOWS\Minidump 2015-01-04 13:15 - 2012-08-24 11:04 - 00000000 ____D () C:\Program Files\CCleaner 2015-01-04 13:15 - 2012-01-22 20:57 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\CCleaner 2015-01-04 13:12 - 2012-01-25 23:45 - 00000000 ____D () C:\Program Files\Get Styles 2015-01-03 23:43 - 2011-07-10 22:45 - 00000000 ___HD () C:\Documents and Settings\Główne\Ustawienia lokalne\Dane aplikacji 2015-01-01 23:20 - 2011-07-10 22:45 - 00000000 __RHD () C:\Documents and Settings\Główne\Dane aplikacji 2015-01-01 23:20 - 2010-04-07 15:30 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji 2014-12-31 17:39 - 2010-04-07 15:31 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy 2014-12-31 17:30 - 2010-04-07 14:02 - 00000000 ____D () C:\WINDOWS\system32\ReinstallBackups 2014-12-28 23:28 - 2014-01-11 00:20 - 00003268 _____ () C:\winzip.log 2014-12-28 23:28 - 2004-08-04 13:00 - 00000929 _____ () C:\WINDOWS\win.ini 2014-12-20 22:44 - 2011-10-02 14:35 - 00363520 ___SH () C:\Documents and Settings\Główne\Pulpit\Thumbs.db 2014-12-19 00:30 - 2012-06-03 18:53 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2014-12-19 00:21 - 2014-11-20 21:52 - 00000000 ____D () C:\Program Files\SpringPublisher 2014-12-19 00:21 - 2013-08-20 14:38 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-12-19 00:09 - 2010-04-11 19:56 - 109818608 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-12-18 10:08 - 2012-05-09 23:18 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-12-12 23:46 - 2011-07-10 22:45 - 00000000 ___RD () C:\Documents and Settings\Główne\Moje dokumenty\Moje obrazy 2014-12-09 20:46 - 2010-04-07 15:31 - 01139166 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-12-09 20:46 - 2004-08-04 13:00 - 00508910 _____ () C:\WINDOWS\system32\perfh015.dat 2014-12-09 20:46 - 2004-08-04 13:00 - 00093434 _____ () C:\WINDOWS\system32\perfc015.dat 2014-12-08 16:11 - 2011-07-10 22:45 - 00000000 ___HD () C:\Documents and Settings\Główne\Ustawienia lokalne 2014-12-07 19:37 - 2011-07-10 22:45 - 00000000 ___RD () C:\Documents and Settings\Główne\Menu Start\Programy 2014-12-07 19:27 - 2014-11-20 21:54 - 00000000 ____D () C:\Documents and Settings\Główne\Dane aplikacji\systweak 2014-12-07 19:11 - 2014-11-20 21:52 - 00002309 _____ () C:\Documents and Settings\All Users\Pulpit\SpringPublisher.lnk 2014-12-07 19:02 - 2012-04-23 11:49 - 00000000 ____D () C:\Documents and Settings\Główne\Pulpit\paul 2014-12-07 16:18 - 2012-04-10 00:04 - 00000000 ____D () C:\Documents and Settings\Główne\Pulpit\CD2 2014-12-07 00:26 - 2014-08-22 19:50 - 00000000 ____D () C:\Documents and Settings\Główne\Moje dokumenty\spadochrony 2014-12-07 00:26 - 2013-11-10 22:44 - 00000000 ____D () C:\Documents and Settings\Główne\Moje dokumenty\strona baszty 2014-12-07 00:26 - 2013-06-01 16:51 - 00025088 ___SH () C:\Documents and Settings\Główne\Moje dokumenty\Thumbs.db Some content of TEMP: ==================== C:\Documents and Settings\Główne\Ustawienia lokalne\Temp\Adobe DNG Converter.exe C:\Documents and Settings\Główne\Ustawienia lokalne\Temp\pity2011ngsetup_aktual.exe C:\Documents and Settings\Główne\Ustawienia lokalne\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================