Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015 Ran by Marek (administrator) on MIKOMA7 on 28-03-2015 20:52:05 Running from C:\Documents and Settings\Marek\Moje dokumenty\Pobrane Loaded Profiles: Marek (Available profiles: Marek & Administrator & Gość) Platform: Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 6 (Default browser: FF) Boot Mode: Safe Mode (minimal) Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AGRSMMSG] => C:\WINDOWS\AGRSMMSG.exe [88363 2004-08-24] (Agere Systems) HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe [1388544 2004-10-14] (Analog Devices, Inc.) HKLM\...\Run: [SoundMAX] => C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [860160 2004-09-23] (Analog Devices, Inc.) HKLM\...\Run: [PTHOSTTR] => C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE [73728 2005-04-08] (Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [UpdateManager] => C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe [110592 2003-08-19] (Sonic Solutions) HKLM\...\Run: [dla] => C:\WINDOWS\system32\dla\tfswctrl.exe [122941 2005-04-27] (Sonic Solutions) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [729178 2005-06-20] (Synaptics, Inc.) HKLM\...\Run: [hpWirelessAssistant] => C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe [794624 2005-05-04] (Hewlett-Packard Company) HKLM\...\Run: [eabconfg.cpl] => C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe [290816 2004-12-03] (Hewlett-Packard ) HKLM\...\Run: [Cpqset] => C:\Program Files\HPQ\Default Settings\cpqset.exe [213054 2004-09-07] () HKLM\...\Run: [WatchDog] => C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [184320 2005-03-09] (InterVideo Inc.) HKLM\...\Run: [RemoteControl] => C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [32768 2004-06-28] (Cyberlink Corp.) HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] => "C:\Program Files\Java\jre7\bin\jusched.exe" HKLM\...\Policies\Explorer: [NoCDBurning] 0 HKU\S-1-5-21-181976360-1301346324-1263509086-1006\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DVD Check.lnk ShortcutTarget: DVD Check.lnk -> C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: [S-1-5-21-181976360-1301346324-1263509086-1006] => w3cache.ppnet.pl:8080 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wyborcza.pl/0,0.html?p=008 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-181976360-1301346324-1263509086-1006\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ HKU\S-1-5-21-181976360-1301346324-1263509086-1006\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch URLSearchHook: HKU\S-1-5-21-181976360-1301346324-1263509086-1006 - Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation) HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "" <======= ATTENTION SearchScopes: HKLM -> DefaultScope value is missing. BHO: DriveLetterAccess -> {5CA3D70E-1895-11CF-8E15-001234567890} -> C:\WINDOWS\system32\dla\tfswshx.dll [2005-04-27] (Sonic Solutions) BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-12-06] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-12-06] (Oracle Corporation) DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} http://mks.com.pl/skaner/SkanerOnline.cab DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_71-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0017-0000-0071-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_71-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_71-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Marek\Dane aplikacji\Mozilla\Firefox\Profiles\s3nrw22u.default-1427542294940 FF Homepage: https://www.google.pl/webhp?hl=pl FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll [2013-07-15] () FF Plugin: @cuminas.jp/DjVuPlugin -> C:\Program Files\Cuminas\Document Express DjVu Plug-in\npdjvu.dll [2014-04-12] (Cuminas Corporation) FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-12-06] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-12-06] (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-181976360-1301346324-1263509086-1006: @unity3d.com/UnityPlayer,version=1.0 -> C:\Documents and Settings\Marek\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdjvu.dll [2009-07-31] (LizardTech) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL [2007-03-22] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2013-12-21] (Adobe Systems Inc.) FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\Marek\Dane aplikacji\Mozilla\Firefox\Profiles\8bw1gf23.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-09-16] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-09-05] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 btwdins; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [254007 2005-03-29] (Broadcom Corporation.) [File not signed] S3 hpqwmi; C:\Program Files\HPQ\SHARED\HPQWMI.exe [98304 2005-04-01] (Hewlett-Packard Development Company, L.P.) [File not signed] S2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-12-06] (Oracle Corporation) S2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [73728 2007-08-09] (HP) [File not signed] S3 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [575488 2008-08-07] (Nokia.) [File not signed] S2 SoundMAX Agent Service (default); C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [45056 2002-09-20] (Analog Devices, Inc.) [File not signed] S3 WmcCds; c:\program files\windows media connect\mswmccds.exe [483328 2004-08-10] (Microsoft Corporation) [File not signed] S3 WmcCdsLs; C:\Program Files\Windows Media Connect\mswmcls.exe [28160 2004-08-10] (Microsoft Corporation) [File not signed] S2 WMDM PMSP Service; C:\WINDOWS\system32\MsPMSPSv.exe [53248 2001-05-01] (Microsoft Corporation) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [400256 2005-03-29] (Broadcom Corporation.) [File not signed] S3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [30299 2005-03-29] (Broadcom Corporation.) [File not signed] S3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [1340698 2005-03-29] (Broadcom Corporation.) [File not signed] S3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [148040 2005-03-29] (Broadcom Corporation.) [File not signed] S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [55448 2005-03-29] (Broadcom Corporation.) [File not signed] S1 ClntMgmt.sys; C:\WINDOWS\System32\Drivers\ClntMgmt.sys [59044 2004-02-20] (Hewlett-Packard) [File not signed] R0 d343bus; C:\WINDOWS\System32\DRIVERS\d343bus.sys [136704 2003-12-15] ( ) [File not signed] R0 d343port; C:\WINDOWS\System32\DRIVERS\d343port.sys [5632 2003-12-15] ( ) [File not signed] S2 DgiVecp; C:\WINDOWS\System32\Drivers\DgiVecp.sys [41984 2005-08-17] (DeviceGuys, Inc.) [File not signed] R0 drvmcdb; C:\WINDOWS\System32\drivers\drvmcdb.sys [88352 2005-04-14] (Sonic Solutions) [File not signed] S2 drvnddm; C:\WINDOWS\System32\drivers\drvnddm.sys [40544 2004-12-23] (Sonic Solutions) [File not signed] S1 eabfiltr; C:\WINDOWS\system32\drivers\EABFiltr.sys [7432 2004-04-14] (Hewlett-Packard Company) S3 eabusb; C:\WINDOWS\system32\drivers\eabusb.sys [5220 2003-06-06] (Hewlett-Packard Company) S3 GTIPCI21; C:\WINDOWS\System32\DRIVERS\gtipci21.sys [80384 2004-05-03] (Texas Instruments) S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [51120 2004-09-29] (HP) S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2004-09-29] (HP) S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21744 2004-09-29] (HP) R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [46080 2006-05-16] (Sonic Solutions) [File not signed] S3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation) R0 sfsync04; C:\WINDOWS\System32\drivers\sfsync04.sys [59264 2006-06-14] (Protection Technology (StarForce)) S3 SMCIRDA; C:\WINDOWS\System32\DRIVERS\smcirda.sys [46080 2004-06-16] (SMSC) R1 sscdbhk5; C:\WINDOWS\System32\drivers\sscdbhk5.sys [5627 2004-12-02] (Sonic Solutions) [File not signed] R1 ssrtln; C:\WINDOWS\System32\drivers\ssrtln.sys [23545 2004-12-02] (Sonic Solutions) [File not signed] S2 tfsnboio; C:\WINDOWS\System32\dla\tfsnboio.sys [25725 2005-04-27] (Sonic Solutions) [File not signed] S2 tfsncofs; C:\WINDOWS\System32\dla\tfsncofs.sys [34845 2005-04-27] (Sonic Solutions) [File not signed] S2 tfsndrct; C:\WINDOWS\System32\dla\tfsndrct.sys [4125 2005-04-27] (Sonic Solutions) [File not signed] S2 tfsndres; C:\WINDOWS\System32\dla\tfsndres.sys [2241 2005-04-27] (Sonic Solutions) [File not signed] S2 tfsnifs; C:\WINDOWS\System32\dla\tfsnifs.sys [86684 2005-04-27] (Sonic Solutions) [File not signed] S2 tfsnopio; C:\WINDOWS\System32\dla\tfsnopio.sys [14877 2005-04-27] (Sonic Solutions) [File not signed] S2 tfsnpool; C:\WINDOWS\System32\dla\tfsnpool.sys [6365 2005-04-27] (Sonic Solutions) [File not signed] S2 tfsnudf; C:\WINDOWS\System32\dla\tfsnudf.sys [98716 2005-04-27] (Sonic Solutions) [File not signed] S2 tfsnudfa; C:\WINDOWS\System32\dla\tfsnudfa.sys [100605 2005-04-27] (Sonic Solutions) [File not signed] S3 upperdev; C:\WINDOWS\System32\DRIVERS\usbser_lowerflt.sys [8064 2008-06-06] (Windows (R) Codename Longhorn DDK provider) S3 UsbserFilt; C:\WINDOWS\System32\DRIVERS\usbser_lowerfltj.sys [8064 2008-05-07] (Windows (R) Codename Longhorn DDK provider) S3 w29n51; C:\WINDOWS\System32\DRIVERS\w29n51.sys [3222784 2005-05-02] (Intel® Corporation) S3 Ad-Watch Connect Filter; \??\C:\WINDOWS\system32\drivers\NSDriver.sys [X] U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) U1 WS2IFSL; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2028-06-18 02:09 - 2028-06-18 02:09 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB960225$ 2028-06-18 02:08 - 2028-06-18 02:08 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB967715$ 2028-06-18 02:08 - 2028-06-18 02:08 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB958690$ 2015-03-28 18:20 - 2015-03-28 18:26 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-03-28 14:45 - 2015-03-28 20:52 - 00000000 ____D () C:\FRST 2015-03-28 14:13 - 2015-03-28 14:14 - 00000000 ____D () C:\Documents and Settings\Marek\Moje dokumenty\z pulpitu 2015-03-28 13:33 - 2015-03-28 20:37 - 00016122 _____ () C:\WINDOWS\setupapi.log 2015-03-28 13:08 - 2015-03-28 13:08 - 00000000 _____ () C:\WINDOWS\setuperr.log 2015-03-28 13:07 - 2015-03-28 13:08 - 00000000 ____D () C:\Documents and Settings\Marek\Pulpit\kalinka 2015-03-20 19:59 - 2015-03-26 13:52 - 00058368 _____ () C:\Documents and Settings\Marek\Moje dokumenty\Kopia zapasowa M Bobrzyński.wbk 2015-03-20 01:27 - 2015-03-20 01:27 - 00024055 _____ () C:\Documents and Settings\Marek\Moje dokumenty\m bobrz.odt 2015-03-18 10:36 - 2015-03-20 01:04 - 00036352 _____ () C:\Documents and Settings\Marek\Moje dokumenty\Kopia zapasowa Michał Bobrzyński.wbk 2015-03-18 10:24 - 2015-03-18 10:24 - 00024064 _____ () C:\Documents and Settings\Marek\Moje dokumenty\Kopia zapasowa Dok1Michał Bobrzy©.wbk ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2028-06-18 02:09 - 2009-03-26 10:23 - 00012788 ____C () C:\WINDOWS\KB960225.log 2028-06-18 02:08 - 2009-03-26 10:23 - 00012575 ____C () C:\WINDOWS\KB967715.log 2015-03-28 20:53 - 2006-04-06 08:35 - 00000000 ____D () C:\Documents and Settings\Marek\Ustawienia lokalne\Temp 2015-03-28 20:52 - 2014-07-25 11:21 - 00000000 ____D () C:\Documents and Settings\Marek\Moje dokumenty\Pobrane 2015-03-28 20:49 - 2004-09-20 09:31 - 01350995 _____ () C:\WINDOWS\WindowsUpdate.log 2015-03-28 20:48 - 2006-04-06 08:35 - 00000292 ___SH () C:\Documents and Settings\Marek\ntuser.ini 2015-03-28 20:48 - 2004-09-20 11:12 - 00000216 _____ () C:\WINDOWS\wiadebug.log 2015-03-28 20:48 - 2004-09-20 11:12 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2015-03-28 20:48 - 2004-09-20 09:31 - 00032506 _____ () C:\WINDOWS\SchedLgU.Txt 2015-03-28 20:48 - 2004-09-20 09:31 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-03-28 20:39 - 2014-03-31 20:27 - 00000222 _____ () C:\WINDOWS\Tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job 2015-03-28 20:39 - 2004-09-20 09:31 - 00001158 _____ () C:\WINDOWS\system32\wpa.dbl 2015-03-28 20:26 - 2012-05-30 15:58 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-03-28 20:03 - 2006-04-06 08:35 - 00000000 ___RD () C:\Documents and Settings\Marek\Moje dokumenty 2015-03-28 14:24 - 2004-09-20 09:22 - 00292480 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2015-03-28 14:20 - 2006-04-06 08:35 - 00000000 ____D () C:\Documents and Settings\Marek\Pulpit 2015-03-28 14:06 - 2008-11-14 11:57 - 00000000 ____D () C:\Program Files\3DO 2015-03-28 14:06 - 2006-04-06 17:25 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy 2015-03-28 14:05 - 2007-10-28 11:51 - 00000060 ____C () C:\WINDOWS\compedia.ini 2015-03-28 14:05 - 2006-04-06 17:25 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2015-03-28 14:04 - 2006-04-06 17:25 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2015-03-28 14:03 - 2006-05-02 21:13 - 00000000 ____D () C:\Program Files\Elaborate Bytes 2015-03-28 13:58 - 2006-04-06 08:35 - 00000000 __RHD () C:\Documents and Settings\Marek\Dane aplikacji 2015-03-28 13:56 - 2007-07-29 22:47 - 00000000 ____D () C:\Program Files\Nikon 2015-03-28 13:56 - 2007-07-29 22:44 - 00000000 ____D () C:\Program Files\Common Files\Nikon 2015-03-28 13:40 - 2008-06-10 20:19 - 00000000 ____D () C:\Program Files\Nokia 2015-03-28 13:39 - 2007-06-22 13:49 - 00135070 ____C () C:\WINDOWS\DPINST.LOG 2015-03-28 13:36 - 2008-10-21 13:05 - 00000000 ____D () C:\Program Files\Gazeta Wyborcza 2015-03-28 13:36 - 2008-10-21 13:05 - 00000000 ____D () C:\Documents and Settings\Marek\Menu Start\Programy\Gazeta Wyborcza 2015-03-28 13:34 - 2006-04-20 12:49 - 00000165 _____ () C:\WINDOWS\ssndii_is.log 2015-03-28 13:34 - 2006-04-06 17:25 - 00000000 ____D () C:\WINDOWS\twain_32 2015-03-28 13:31 - 2006-10-02 11:04 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Eidos 2015-03-28 13:31 - 2006-04-06 17:25 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start 2015-03-28 13:30 - 2007-01-21 21:20 - 00000000 ____D () C:\Program Files\CyberLink 2015-03-28 13:29 - 2007-07-30 11:45 - 00004320 ____C () C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log 2015-03-28 13:26 - 2007-07-30 11:48 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\HP 2015-03-28 13:08 - 2004-09-20 09:21 - 00222795 _____ () C:\WINDOWS\setupact.log 2015-03-22 19:00 - 2010-09-04 15:40 - 00002539 _____ () C:\Documents and Settings\Marek\Pulpit\Microsoft Office Word 2003.lnk 2015-03-19 10:52 - 2004-09-20 09:26 - 01125618 ____C () C:\WINDOWS\system32\PerfStringBackup.INI 2015-03-19 10:52 - 2004-09-20 09:26 - 00504204 ____C () C:\WINDOWS\system32\perfh015.dat 2015-03-19 10:52 - 2004-09-20 09:26 - 00090740 ____C () C:\WINDOWS\system32\perfc015.dat 2015-03-18 15:59 - 2013-08-19 20:06 - 00000000 ____D () C:\WINDOWS\system32\MRT 2015-02-26 21:20 - 2006-04-19 21:23 - 119837696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe ==================== Files in the root of some directories ======= 2007-07-31 18:30 - 2007-07-31 18:30 - 0000000 ____C () C:\Documents and Settings\Marek\Dane aplikacji\HelpFilesUpdatePatch_HELPFILEREPLACE.log 2007-07-31 18:30 - 2007-07-31 18:30 - 0000352 ____C () C:\Documents and Settings\Marek\Dane aplikacji\HelpFilesUpdatePatch_PRINTHELPWRAPPER.log 2007-07-31 18:31 - 2007-07-31 18:31 - 0052192 ____C () C:\Documents and Settings\Marek\Dane aplikacji\PatchUpdate_HP_CounterReport_Update_HPSU.log 2007-07-31 18:29 - 2007-07-31 18:29 - 0002816 ____C () C:\Documents and Settings\Marek\Dane aplikacji\PatchUpdate_InstantShareJPG.log 2007-07-31 18:25 - 2007-07-31 18:28 - 0003623 ____C () C:\Documents and Settings\Marek\Dane aplikacji\PatchUpdate_IZClosingDiscError.log 2007-07-31 18:22 - 2007-07-31 18:23 - 0210554 ____C () C:\Documents and Settings\Marek\Dane aplikacji\Update_HP_RedboxHprblog_HPSU.log 2008-09-02 11:26 - 2014-12-06 16:28 - 0001028 ____C () C:\Documents and Settings\Marek\Dane aplikacji\WavCodec.wff 2006-04-06 09:02 - 2014-04-18 21:10 - 0027648 ____C () C:\Documents and Settings\Marek\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2006-04-06 08:35 - 2007-07-10 20:37 - 0000130 ____C () C:\Documents and Settings\Marek\Ustawienia lokalne\Dane aplikacji\fusioncache.dat Some content of TEMP: ==================== C:\Documents and Settings\Marek\Ustawienia lokalne\Temp\hpzmsi01.exe C:\Documents and Settings\Marek\Ustawienia lokalne\Temp\hpzscr01.exe C:\Documents and Settings\Marek\Ustawienia lokalne\Temp\SSDelAll.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================