Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-04-2015 Ran by Mateusz (administrator) on INTEL on 21-04-2015 20:58:38 Running from E:\Download Loaded Profiles: Mateusz (Available profiles: Mateusz & Administrator) Platform: Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) OS Language: Polski Internet Explorer Version 8 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (Logitech Inc.) C:\Program Files\Logitech\iTouch\iTouch.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE (Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe () C:\Program Files\RivaTuner v2.21\Tools\RivaTunerStatisticsServer\RivaTunerStatisticsServer.exe () C:\Program Files\RivaTuner v2.21\RivaTuner.exe (Agnitum Ltd.) C:\PROGRA~1\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.) C:\PROGRA~1\Agnitum\Outpost Firewall\acs.exe (Renesas Electronics Corporation) C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe (SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\Event Manager\EEventManager.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (EnTech Taiwan) C:\Program Files\Dell\Dell Display Manager\ddm.exe (Seiko Epson Corporation) C:\WINDOWS\system32\escsvc.exe (Dropbox, Inc.) C:\Documents and Settings\Mateusz\Dane aplikacji\Dropbox\bin\Dropbox.exe (Teruten) C:\WINDOWS\system32\FsUsbExService.Exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Mathias Svensson) C:\MultiCommander\MultiCommander.exe (Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [zBrowser Launcher] => C:\Program Files\Logitech\iTouch\iTouch.exe [892928 2004-03-18] (Logitech Inc.) HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [17508864 2009-02-17] (Realtek Semiconductor Corp.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit HKLM\...\Run: [RivaTunerStartupDaemon] => C:\Program Files\RivaTuner v2.21\RivaTuner.exe [2732032 2008-12-10] () HKLM\...\Run: [RivaTunerStatisticsServer] => C:\Program Files\RivaTuner v2.21\Tools\RivaTunerStatisticsServer\RivaTunerStatisticsServer.exe [57344 2008-12-10] () HKLM\...\Run: [RivaTuner] => C:\Program Files\RivaTuner v2.21\RivaTuner.exe [2732032 2008-12-10] () HKLM\...\Run: [OutpostMonitor] => C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe [2374464 2009-04-28] (Agnitum Ltd.) HKLM\...\Run: [OutpostFeedBack] => C:\Program Files\Agnitum\Outpost Firewall\feedback.exe [428032 2009-04-28] (Agnitum Ltd.) HKLM\...\Run: [nwiz] => nwiz.exe /install HKLM\...\Run: [NUSB3MON] => C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048 2011-09-16] (Renesas Electronics Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5512912 2015-04-09] (Avast Software s.r.o.) HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1058400 2011-10-31] (SEIKO EPSON CORPORATION) HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [2303256 2014-05-19] (Logitech, Inc.) HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [335232 2015-02-10] (Oracle Corporation) Winlogon\Notify\crypt32chain: C:\WINDOWS\system32\crypt32.dll [2013-10-07] (Microsoft Corporation) Winlogon\Notify\cryptnet: C:\WINDOWS\system32\cryptnet.dll [2008-04-15] (Microsoft Corporation) Winlogon\Notify\cscdll: C:\WINDOWS\system32\cscdll.dll [2008-04-15] (Microsoft Corporation) Winlogon\Notify\dimsntfy: C:\WINDOWS\System32\dimsntfy.dll [2008-04-15] (Microsoft Corporation) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2014-03-25] (Logitech, Inc.) Winlogon\Notify\ScCertProp: C:\WINDOWS\system32\wlnotify.dll [2008-04-15] (Microsoft Corporation) Winlogon\Notify\Schedule: C:\WINDOWS\system32\wlnotify.dll [2008-04-15] (Microsoft Corporation) Winlogon\Notify\sclgntfy: C:\WINDOWS\system32\sclgntfy.dll [2008-04-15] (Microsoft Corporation) Winlogon\Notify\SensLogn: C:\WINDOWS\system32\WlNotify.dll [2008-04-15] (Microsoft Corporation) Winlogon\Notify\termsrv: C:\WINDOWS\system32\wlnotify.dll [2008-04-15] (Microsoft Corporation) Winlogon\Notify\wlballoon: C:\WINDOWS\system32\wlnotify.dll [2008-04-15] (Microsoft Corporation) HKU\S-1-5-18\...\Run: [DWQueuedReporting] => C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [437160 2007-02-26] (Microsoft Corporation) Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Dell Display Manager.lnk [2015-03-18] ShortcutTarget: Dell Display Manager.lnk -> C:\Program Files\Dell\Dell Display Manager\ddm.exe (EnTech Taiwan) Startup: C:\Documents and Settings\Mateusz\Menu Start\Programy\Autostart\Dropbox.lnk [2015-04-10] ShortcutTarget: Dropbox.lnk -> C:\Documents and Settings\Mateusz\Dane aplikacji\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Mateusz\Dane aplikacji\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Mateusz\Dane aplikacji\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Mateusz\Dane aplikacji\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Mateusz\Dane aplikacji\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Mateusz\Dane aplikacji\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Mateusz\Dane aplikacji\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Mateusz\Dane aplikacji\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Mateusz\Dane aplikacji\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-04-09] (Avast Software s.r.o.) BootExecute: autocheck autochk * ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2052111302-1767777339-1801674531-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-2052111302-1767777339-1801674531-1004\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-2052111302-1767777339-1801674531-1004\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-14] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-09] (Avast Software s.r.o.) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-14] (Oracle Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default FF Homepage: google.pl FF NetworkProxy: "http", "proxy.dialog.net.pl" FF NetworkProxy: "http_port", 8080 FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] () FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1212152.dll [2014-05-30] (Adobe Systems, Inc.) FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-07-12] (Google) FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-14] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-14] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=6.0.12.450 -> C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll [2010-02-15] (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.448 -> C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll [2010-02-15] (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll [2013-07-14] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll [2013-07-14] (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2052111302-1767777339-1801674531-1004: ubisoft.com/uplaypc -> C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-01-04] () FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll [2008-06-27] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2010-02-15] (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2013-06-10] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2013-06-10] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2013-06-10] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2013-06-10] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2013-06-10] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll [2010-02-15] (RealNetworks, Inc.) FF SearchPlugin: C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\searchplugins\pwn---sownik-jzyka-polskiego.xml [2007-11-29] FF SearchPlugin: C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\searchplugins\pwn---sownik-ortograficzny.xml [2007-11-29] FF Extension: No Name - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\artur.dubovoy@gmail.com [2015-04-18] FF Extension: ArzoFox - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\ArzoFox@sjcmankimo.ilovetw [2009-12-19] FF Extension: Redirector - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\redirector@einaregilsson.com [2014-11-05] FF Extension: Vista-aero - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\{07b2a769-ed19-4483-87ce-c643914c81bb} [2010-06-10] FF Extension: Autocopy - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\{0FED7D55-65D4-47b6-A6DE-9A4ADB55355F} [2013-01-06] FF Extension: Simpler Glass - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\{43505cd0-6e9a-11da-8cd6-0800200c9a66} [2010-06-10] FF Extension: DownThemAll! - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}(2) [2009-05-15] FF Extension: No Name - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\{eb46c787-131a-4eb7-9b93-7f62ca550917} [2009-12-19] FF Extension: FireGestures - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\firegestures@xuldev.org.xpi [2015-04-18] FF Extension: Multi Links - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\multilinks@plugin.xpi [2011-03-23] FF Extension: Personas Plus - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\personas@christopher.beard.xpi [2013-03-02] FF Extension: Status-4-Evar - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\status4evar@caligonstudios.com.xpi [2011-03-23] FF Extension: Undo Closed Tabs Button - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\undoclosedtabsbutton@supernova00.biz.xpi [2013-08-15] FF Extension: Linkification - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}.xpi [2011-03-22] FF Extension: Downloads Window - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\{a7213cf2-fa1e-4373-88ff-255d0abd3020}.xpi [2014-03-18] FF Extension: Adblock Plus - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-03-26] FF Extension: Extended Statusbar - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\{daf44bf7-a45e-4450-979c-91cf07434c3d}.xpi [2011-03-23] FF Extension: DownThemAll! - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2013-03-21] FF Extension: Multirow Bookmarks Toolbar - C:\Documents and Settings\Mateusz\Dane aplikacji\Mozilla\Firefox\Profiles\fg6f3jrz.default\Extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}.xpi [2013-12-07] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-04-18] FF HKLM\...\Firefox\Extensions: [fe_7.0@nokia.com] - C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_7.0 FF Extension: Firefox Synchronisation Extension - C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_7.0 [2012-05-01] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-12-16] Chrome: ======= CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-17] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY) R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [846048 2012-04-27] (Acronis) R2 acssrv; C:\Program Files\Agnitum\Outpost Firewall\acs.exe [1195008 2009-04-28] (Agnitum Ltd.) [File not signed] R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-09] (Avast Software s.r.o.) R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc.exe [122000 2011-12-12] (Seiko Epson Corporation) R2 FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [233472 2013-04-18] (Teruten) [File not signed] S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S2 PEVSystemStart; C:\ComboFix\SWREG.3XE [518144 2000-08-31] (SteelWerX) [File not signed] S4 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [75064 2009-08-31] () R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5436176 2015-02-17] (TeamViewer GmbH) S4 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [67056 2007-03-03] (Ulead Systems, Inc.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 afw; C:\WINDOWS\System32\DRIVERS\afw.sys [31128 2009-02-18] (Agnitum Ltd.) R3 afwcore; C:\WINDOWS\System32\drivers\afwcore.sys [257432 2009-02-10] (Agnitum Ltd.) S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1684736 2008-08-05] (Creative) R1 Amfilter; C:\WINDOWS\System32\DRIVERS\Amfilter.sys [9216 2007-05-15] (A4Tech Co.,Ltd.) [File not signed] S3 Amusbprt; C:\WINDOWS\System32\DRIVERS\Amusbprt.sys [14336 2007-05-15] (A4Tech Co.,Ltd.) [File not signed] S3 AR9271; C:\WINDOWS\System32\DRIVERS\athuw.sys [1714176 2010-01-05] (Atheros Communications, Inc.) R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24144 2015-04-09] () R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [73440 2015-04-09] (Avast Software s.r.o.) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-04-09] (Avast Software s.r.o.) R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49904 2015-04-09] () R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [788272 2015-04-09] (Avast Software s.r.o.) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [427736 2015-04-09] (Avast Software s.r.o.) R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-04-09] (Avast Software s.r.o.) R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208024 2015-04-09] () R0 BtHidBus; C:\WINDOWS\System32\Drivers\BtHidBus.sys [20744 2009-01-07] (IVT Corporation.) S3 btnetBUs; C:\WINDOWS\System32\Drivers\btnetBus.sys [30088 2008-12-07] () S3 BVRPMPR5; C:\WINDOWS\system32\drivers\BVRPMPR5.SYS [49904 2007-05-23] (Avanquest Software) [File not signed] S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [16384 2004-07-09] (Microsoft Corporation) S3 ENTECH; C:\WINDOWS\system32\DRIVERS\ENTECH.sys [21664 2004-10-25] (EnTech Taiwan) [File not signed] S3 ET5Drv; C:\WINDOWS\system32\Drivers\ET5Drv.sys [30008 2009-03-20] (Windows (R) 2000 DDK provider) R3 FsUsbExDisk; C:\WINDOWS\system32\FsUsbExDisk.SYS [37344 2013-04-18] () [File not signed] S3 FTDIBUS; C:\WINDOWS\System32\drivers\ftdibus.sys [24177 2004-02-04] (FTDI Ltd.) [File not signed] S3 FTSER2K; C:\WINDOWS\System32\drivers\ftser2k.sys [57372 2004-02-04] (FTDI Ltd.) [File not signed] S3 gdrv; C:\WINDOWS\gdrv.sys [16608 2013-10-08] (Windows (R) 2000 DDK provider) R0 giveio; C:\WINDOWS\System32\giveio.sys [5248 1996-04-03] () [File not signed] R3 itchfltr; C:\WINDOWS\System32\DRIVERS\itchfltr.sys [12953 2004-03-10] (Logitech, Inc.) S3 IvtBtBUs; C:\WINDOWS\System32\Drivers\IvtBtBus.sys [26248 2008-07-02] (IVT Corporation.) R3 LEqdUsb; C:\WINDOWS\System32\Drivers\LEqdUsb.Sys [42264 2014-03-19] (Logitech, Inc.) R3 LHidEqd; C:\WINDOWS\System32\Drivers\LHidEqd.Sys [10136 2014-03-19] (Logitech, Inc.) S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1389056 2006-01-04] (Creative Technology Ltd.) S3 MPE; C:\WINDOWS\System32\DRIVERS\MPE.sys [15104 2004-07-09] (Microsoft Corporation) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10112 2004-07-09] (Microsoft Corporation) S3 NETDLWL; C:\WINDOWS\System32\DRIVERS\NETDLWL.SYS [159104 2003-07-14] (D-Link Corporation ) [File not signed] R3 nusb3hub; C:\WINDOWS\System32\DRIVERS\nusb3hub.sys [85768 2012-08-27] (Renesas Electronics Corporation) R3 nusb3xhc; C:\WINDOWS\System32\DRIVERS\nusb3xhc.sys [177800 2012-08-27] (Renesas Electronics Corporation) S3 PortTalk; C:\WINDOWS\System32\Drivers\PortTalk.sys [3567 2002-01-12] (Beyond Logic http://www.beyondlogic.org) [File not signed] S3 ProcObsrv; d:\Program Files\Glary Utilities 3\ProcObsrv.sys [11552 2013-07-06] (Glarysoft Ltd) R1 PSSDK42; C:\WINDOWS\system32\Drivers\pssdk42.sys [38976 2010-12-05] (microOLAP Technologies LTD) R3 RivaTuner32; C:\Program Files\RivaTuner v2.21\RivaTuner32.sys [9088 2008-12-10] () [File not signed] S3 Rockusb; C:\WINDOWS\System32\DRIVERS\rockusb.sys [45040 2012-06-18] (Fuzhou Rockchip Electronics Co,Ltd.) S3 RTL8023xp; C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys [85120 2006-12-14] (Realtek Semiconductor Corporation ) [File not signed] S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2008-04-14] (Realtek Semiconductor Corporation) R1 SandBox; C:\WINDOWS\system32\drivers\SandBox.sys [704384 2009-04-06] (Agnitum Ltd.) R0 speedfan; C:\WINDOWS\System32\speedfan.sys [5248 2006-09-24] (Windows (R) 2000 DDK provider) [File not signed] S3 ss_bbus; C:\WINDOWS\System32\DRIVERS\ss_bbus.sys [98432 2010-04-27] (MCCI) S3 ss_bmdfl; C:\WINDOWS\System32\DRIVERS\ss_bmdfl.sys [14848 2010-04-27] (MCCI Corporation) S3 ss_bmdm; C:\WINDOWS\System32\DRIVERS\ss_bmdm.sys [123648 2010-04-27] (MCCI Corporation) S3 ss_bserd; C:\WINDOWS\System32\DRIVERS\ss_bserd.sys [100224 2010-04-27] (MCCI Corporation) R2 StarOpen; C:\WINDOWS\system32\Drivers\StarOpen.sys [13120 2013-08-25] () R2 TVICHW32; C:\WINDOWS\system32\Drivers\TVICHW32.sys [25040 2012-09-07] (EnTech Taiwan) R0 vididr; C:\WINDOWS\System32\DRIVERS\vididr.sys [125472 2013-09-25] (Acronis) R0 vidsflt53; C:\WINDOWS\System32\DRIVERS\vsflt53.sys [83392 2013-09-26] (Acronis) R3 VMHybrid; C:\WINDOWS\System32\DRIVERS\VMHybrid.sys [1060352 2008-11-12] (Compro Technology, Inc.) S3 WRSWanDD; C:\WINDOWS\System32\DRIVERS\WrKPoETNic2000.sys [65604 2007-07-04] () S3 BT; system32\DRIVERS\btnetdrv.sys [X] S3 Btcsrusb; System32\Drivers\btcusb.sys [X] S3 GPU-Z; No ImagePath U5 GVTDrv; C:\WINDOWS\system32\Drivers\GVTDrv.sys [24944 2009-09-20] () S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S4 IntelIde; No ImagePath U3 TlntSvr; No ImagePath U5 UnlockerDriver5; d:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () [File not signed] S3 VComm; system32\DRIVERS\VComm.sys [X] S3 VcommMgr; System32\Drivers\VcommMgr.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-21 20:48 - 2015-04-21 20:48 - 00106496 _____ () C:\WINDOWS\Minidump\Mini042115-03.dmp 2015-04-21 20:35 - 2015-04-21 20:35 - 00106496 _____ () C:\WINDOWS\Minidump\Mini042115-02.dmp 2015-04-21 20:26 - 2015-04-21 20:26 - 00106496 _____ () C:\WINDOWS\Minidump\Mini042115-01.dmp 2015-04-21 20:22 - 2015-04-21 20:58 - 00000000 ____D () C:\FRST 2015-04-20 20:50 - 2015-04-20 20:51 - 00000000 ___SD () C:\ComboFix 2015-04-20 18:29 - 2015-04-20 18:29 - 00000000 _RSHD () C:\cmdcons 2015-04-20 18:29 - 2013-12-13 21:32 - 00000210 _____ () C:\Boot.bak 2015-04-20 18:29 - 2004-08-03 23:00 - 00262400 __RSH () C:\cmldr 2015-04-20 17:53 - 2010-11-07 19:20 - 00208896 _____ () C:\WINDOWS\MBR.exe 2015-04-20 17:52 - 2015-04-20 17:52 - 00000000 ____D () C:\Qoobox 2015-04-20 17:51 - 2015-04-21 20:17 - 00000000 ____D () C:\AdwCleaner 2015-04-17 22:59 - 2015-04-21 20:49 - 00077519 _____ () C:\WINDOWS\setupapi.log 2015-04-09 23:19 - 2015-04-09 23:19 - 00291312 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\aswBoot.exe 2015-04-09 23:19 - 2015-04-09 23:19 - 00043112 _____ (Avast Software s.r.o.) C:\WINDOWS\avastSS.scr 2015-04-08 18:19 - 2015-04-08 18:20 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-04-06 19:51 - 2015-04-06 19:51 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\CCleaner 2015-04-06 19:45 - 2015-04-06 19:45 - 00000000 ____D () C:\Documents and Settings\Mateusz\Ustawienia lokalne\Dane aplikacji\Steam 2015-04-06 19:42 - 2015-04-06 19:43 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird 2015-04-06 19:16 - 2015-04-06 19:16 - 00000000 ____D () C:\Program Files\e-Deklaracje ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-21 20:58 - 2009-10-21 20:03 - 00000000 ____D () C:\Documents and Settings\Mateusz\Ustawienia lokalne\temp 2015-04-21 20:51 - 2010-11-06 21:34 - 00271478 _____ () C:\WINDOWS\system32\config\prcdrv.acl 2015-04-21 20:51 - 2010-11-06 21:02 - 00271382 _____ () C:\WINDOWS\system32\config\prc.acl 2015-04-21 20:49 - 2013-03-03 13:24 - 00000000 ____D () C:\Documents and Settings\Mateusz\Dane aplikacji\Dropbox 2015-04-21 20:49 - 2012-07-04 20:58 - 00000364 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job 2015-04-21 20:49 - 2011-03-31 19:14 - 00000159 _____ () C:\WINDOWS\wiadebug.log 2015-04-21 20:49 - 2011-03-31 19:14 - 00000050 _____ () C:\WINDOWS\wiaservc.log 2015-04-21 20:48 - 2009-06-10 08:28 - 00235624 _____ () C:\WINDOWS\system32\NvApps.xml 2015-04-21 20:48 - 2008-12-19 20:44 - 00000000 ____D () C:\WINDOWS\Minidump 2015-04-21 20:48 - 2008-10-10 20:43 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-04-21 20:39 - 2010-11-07 00:34 - 00000884 _____ () C:\WINDOWS\system32\config\afw_hm.conf 2015-04-21 20:39 - 2010-11-07 00:34 - 00000004 _____ () C:\WINDOWS\system32\config\afw_db.conf 2015-04-21 20:37 - 2009-07-10 22:42 - 01290113 _____ () C:\WINDOWS\WindowsUpdate.log 2015-04-21 20:32 - 2010-11-06 21:02 - 00459776 _____ () C:\WINDOWS\system32\config\fsdb.sdb 2015-04-21 20:32 - 2009-08-31 14:01 - 00032446 _____ () C:\WINDOWS\Tasks\SCHEDLGU.TXT 2015-04-21 20:32 - 2008-10-10 20:44 - 00000188 ___SH () C:\Documents and Settings\Mateusz\ntuser.ini 2015-04-21 20:26 - 2008-04-15 14:00 - 00012598 _____ () C:\WINDOWS\system32\wpa.dbl 2015-04-21 18:35 - 2008-10-10 20:44 - 00000000 ____D () C:\Documents and Settings\Mateusz\Pulpit 2015-04-20 20:51 - 2008-10-10 20:44 - 00000000 __RHD () C:\Documents and Settings\Mateusz\Dane aplikacji 2015-04-20 20:12 - 2012-04-10 17:03 - 00000930 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-04-20 19:41 - 2008-10-10 20:44 - 00000000 ___HD () C:\Documents and Settings\Mateusz\Ustawienia lokalne\Dane aplikacji 2015-04-20 19:41 - 2008-10-10 20:44 - 00000000 ____D () C:\Documents and Settings\Mateusz 2015-04-20 18:29 - 2008-10-10 22:30 - 00000327 __RSH () C:\boot.ini 2015-04-19 13:07 - 2008-10-11 18:44 - 00002059 _____ () C:\WINDOWS\bestplayer.ini 2015-04-19 13:07 - 2008-10-11 18:44 - 00001337 _____ () C:\WINDOWS\bestplayer.bbt 2015-04-19 13:07 - 2008-10-11 18:44 - 00000047 _____ () C:\WINDOWS\bestplayer.bpp 2015-04-19 12:25 - 2009-01-06 23:11 - 00000000 __SHD () C:\Documents and Settings\Mateusz\UserData 2015-04-18 23:47 - 2010-08-13 19:55 - 00000000 ____D () C:\Documents and Settings\Mateusz\Dane aplikacji\vlc 2015-04-18 22:34 - 2008-10-10 20:44 - 00000000 ____D () C:\Documents and Settings\Mateusz\Moje dokumenty 2015-04-18 18:30 - 2013-03-22 21:27 - 00000000 ____D () C:\MultiCommander 2015-04-18 15:15 - 2012-07-03 14:30 - 00000000 ____D () C:\Documents and Settings\Mateusz\Moje dokumenty\Mieszkanie 2015-04-17 23:00 - 2008-10-10 22:25 - 00000000 ____D () C:\WINDOWS\system32\ias 2015-04-17 20:44 - 2009-03-19 21:48 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy 2015-04-17 20:44 - 2008-10-10 22:32 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy 2015-04-15 20:41 - 2013-07-10 23:23 - 00000000 ____D () C:\WINDOWS\system32\MRT 2015-04-15 20:36 - 2008-10-10 22:50 - 125832184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-04-15 00:12 - 2012-04-10 17:03 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2015-04-15 00:12 - 2011-05-19 20:29 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2015-04-14 21:03 - 2008-10-10 21:09 - 00035368 _____ () C:\Documents and Settings\Mateusz\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2015-04-14 20:36 - 2015-02-13 21:13 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-04-14 20:34 - 2009-08-23 20:30 - 00000000 ____D () C:\Documents and Settings\Mateusz\Dane aplikacji\TeamViewer 2015-04-13 20:46 - 2008-10-11 10:23 - 00000000 ____D () C:\Program Files\Winamp 2015-04-13 20:31 - 2008-10-10 20:44 - 00000000 ___RD () C:\Documents and Settings\Mateusz\Menu Start\Programy 2015-04-12 09:46 - 2014-01-01 18:07 - 00000000 ____D () C:\MK 2015-04-10 20:58 - 2008-10-10 20:44 - 00000000 ___RD () C:\Documents and Settings\Mateusz\Menu Start\Programy\Autostart 2015-04-10 20:54 - 2012-07-04 19:55 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-04-09 23:19 - 2014-04-23 19:34 - 00024144 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys 2015-04-09 23:19 - 2013-03-15 20:06 - 00208024 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys 2015-04-09 23:19 - 2013-03-15 20:06 - 00073440 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2015-04-09 23:19 - 2013-03-15 20:06 - 00049904 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys 2015-04-09 23:19 - 2011-12-16 18:29 - 00788272 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswSnx.sys 2015-04-09 23:19 - 2011-12-16 18:29 - 00427736 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswSP.sys 2015-04-09 23:19 - 2011-12-16 18:29 - 00057888 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswTdi.sys 2015-04-09 23:19 - 2011-12-16 18:29 - 00055200 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswRdr.sys 2015-04-06 19:51 - 2012-09-05 20:17 - 00000000 ____D () C:\Program Files\CCleaner 2015-04-06 19:16 - 2011-03-02 18:48 - 00000684 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\e-Deklaracje.lnk 2015-04-01 07:04 - 2008-10-10 22:32 - 01336770 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-04-01 07:04 - 2008-04-15 14:00 - 00596168 _____ () C:\WINDOWS\system32\perfh015.dat 2015-04-01 07:04 - 2008-04-15 14:00 - 00121106 _____ () C:\WINDOWS\system32\perfc015.dat 2015-04-01 07:02 - 2008-10-10 22:31 - 00162728 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2015-03-27 22:06 - 2008-10-10 22:32 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit 2015-03-22 21:33 - 2014-10-22 18:48 - 00000000 ____D () C:\Program Files\TeamViewer 2015-03-22 20:27 - 2008-10-12 19:48 - 00022630 ____H () C:\Documents and Settings\Mateusz\Moje dokumenty\arkusz.ods 2015-03-22 13:26 - 2012-07-03 14:28 - 00000000 ____D () C:\Documents and Settings\Mateusz\Moje dokumenty\Mazda 323 ==================== Files in the root of some directories ======= 2010-08-31 21:03 - 2010-08-31 21:03 - 0002528 _____ () C:\Documents and Settings\Mateusz\Dane aplikacji\$_hpcst$.hpc 2014-05-31 22:40 - 2014-08-20 22:29 - 0002861 _____ () C:\Documents and Settings\Mateusz\Dane aplikacji\.ptbt0 2009-10-10 19:19 - 2009-10-10 19:19 - 0000541 _____ () C:\Documents and Settings\Mateusz\Dane aplikacji\AutoGK.ini 2008-12-14 23:34 - 2012-11-08 20:30 - 0000000 _____ () C:\Documents and Settings\Mateusz\Dane aplikacji\AVSDVDPlayer.m3u 2009-09-25 18:02 - 2009-10-24 13:26 - 0000877 _____ () C:\Documents and Settings\Mateusz\Dane aplikacji\coreavc.ini 2009-08-31 16:17 - 2009-08-31 16:17 - 0139152 _____ () C:\Documents and Settings\Mateusz\Dane aplikacji\PnkBstrK.sys 2012-12-29 00:42 - 2012-12-29 00:42 - 0000696 _____ () C:\Documents and Settings\Mateusz\Dane aplikacji\qnapi.ini 2008-10-12 16:46 - 2015-01-26 23:16 - 0118784 _____ () C:\Documents and Settings\Mateusz\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2010-04-09 11:44 - 2010-04-09 11:44 - 0000132 ____N () C:\Documents and Settings\Mateusz\Ustawienia lokalne\Dane aplikacji\fusioncache.dat 2015-02-15 23:02 - 2015-02-15 23:02 - 0000759 _____ () C:\Documents and Settings\Mateusz\Ustawienia lokalne\Dane aplikacji\recently-used.xbel Some content of TEMP: ==================== C:\Documents and Settings\Administrator\Ustawienia lokalne\temp\mgwz.dll C:\Documents and Settings\Mateusz\Ustawienia lokalne\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpdphaaz.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================