FRST.txt

Wirus zamieniający pliki w skróty na pamięciach przenośnych

Po USBFix wszystko wraca do normy ale po ponownym włączeniu komputer znowu skróty w załącznikach logi z USBFix i FRST


Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-08-2014 01
Ran by Wojtek (administrator) on KOMPUTER on 24-08-2014 14:34:07
Running from C:\Users\Wojtek\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polski (Polska)
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [VizorHtmlDialog.exe] = & gt; C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe [1123664 2010-10-08] (Trend Micro Inc.)
HKLM\...\Run: [Trend Micro Client Framework] = & gt; C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [192520 2010-10-12] (Trend Micro Inc.)
HKLM\...\Run: [Trend Micro Titanium] = & gt; C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe [322384 2010-09-17] (Trend Micro Inc.)
HKLM\...\Run: [RtHDVBg] = & gt; C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2189416 2011-03-01] (Realtek Semiconductor)
HKLM\...\Run: [AmIcoSinglun64] = & gt; C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324096 2010-08-11] (Alcor Micro Corp.)
HKLM\...\Run: [ETDCtrl] = & gt; C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-13] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AtherosBtStack] = & gt; C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [617120 2011-03-13] (Atheros Communications)
HKLM\...\Run: [AthBtTray] = & gt; C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [379552 2011-03-13] (Atheros Commnucations)
HKLM\...\Run: [Setwallpaper] = & gt; c:\programdata\SetWallpaper.cmd
HKLM-x32\...\Run: [Nuance PDF Reader-reminder] = & gt; C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ASUSPRP] = & gt; C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-01] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] = & gt; C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme)
HKLM-x32\...\Run: [ATKOSD2] = & gt; C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] = & gt; C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] = & gt; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] = & gt; C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] ()
HKLM-x32\...\Run: [RemoteControl10] = & gt; C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-03] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] = & gt; C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2010-11-12] (cyberlink)
HKLM-x32\...\Run: [UpdateLBPShortCut] = & gt; C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] = & gt; C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [GrooveMonitor] = & gt; C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [TkBellExe] = & gt; C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296056 2012-01-22] (RealNetworks, Inc.)
HKLM-x32\...\Run: [WinampAgent] = & gt; C:\Program Files (x86)\Winamp\winampa.exe [74752 2011-12-09] (Nullsoft, Inc.)
HKLM-x32\...\Run: [e-Kiosk] = & gt; C:\Program Files (x86)\e-Kiosk Reader\eGazetaST.exe [1690624 2011-09-21] (e-Kiosk S.A.)
HKLM-x32\...\Run: [Adobe ARM] = & gt; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] = & gt; C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] = & gt; C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] = & gt; C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Boot pc] = & gt; wscript.exe //B " C:\Users\Wojtek\AppData\Local\Temp\Boot pc.vbs "
HKLM-x32\...\RunOnce: [] = & gt; [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\Run: [ISUSPM] = & gt; C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-06] (Acresso Corporation)
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\RunOnce: [InetReg] = & gt; " C:\Program Files (x86)\Creative\Product Registration\English\InetReg.exe " /PreProcess=RegFlash.exe /PortableDevice /Delay=6
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: F - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {2d22503d-4cc1-11e1-a194-742f68b783d9} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {31ffc813-3e8f-11e1-af57-5404a607abbb} - F:\MicroLauncher.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {372a64e7-5001-11e1-bcb0-742f68b783d9} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {372a64f4-5001-11e1-bcb0-742f68b783d9} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {3c9ed81e-5352-11e1-8fa5-742f68b783d9} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {43ccd188-4c3a-11e1-8292-5404a607abbb} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {43ccd194-4c3a-11e1-8292-5404a607abbb} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {6a811bb1-4cbf-11e1-8ba5-742f68b783d9} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {6a811bb5-4cbf-11e1-8ba5-742f68b783d9} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {6a811bd1-4cbf-11e1-8ba5-742f68b783d9} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {886b5767-5254-11e1-97ff-742f68b783d9} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {9bcec144-e386-11e0-aa3f-806e6f6e6963} - E:\CTRun\Start.EXE
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {a25df556-3d64-11e1-bc2e-742f68b783d9} - G:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {c28953f7-3d60-11e1-b575-742f68b783d9} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {cfc46b1f-528d-11e1-aa4f-742f68b783d9} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {dddb85ed-50ed-11e1-82a8-742f68b783d9} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {f9f9435f-4c5f-11e1-a3db-5404a607abbb} - F:\MicroLauncher.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {fcf08fa5-3d60-11e1-b781-742f68b783d9} - F:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1000\...\MountPoints2: {fcf08fab-3d60-11e1-b781-742f68b783d9} - G:\AutoRun.exe
HKU\S-1-5-21-200153710-2499995584-3205563836-1001\...\Run: [SoftAuto.exe] = & gt; C:\Program Files (x86)\Creative\Software Update 3\SoftAuto.exe [405504 2008-08-13] (Creative Technology Ltd)
HKU\S-1-5-21-200153710-2499995584-3205563836-1001\...\Run: [WITaj!] = & gt; rem -- Anulowane uruchamianie programu WITaj! 2000
HKU\S-1-5-21-200153710-2499995584-3205563836-1001\...\Run: [AlcoholAutomount] = & gt; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
HKU\S-1-5-21-200153710-2499995584-3205563836-1001\...\Run: [Mobile Partner] = & gt; C:\Program Files (x86)\MobileWiFi\MobileWiFi
HKU\S-1-5-21-200153710-2499995584-3205563836-1001\...\Run: [GoogleChromeAutoLaunch_56EF70C430023F2B7A193A5130740B52] = & gt; C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488 2014-08-07] (Google Inc.)
HKU\S-1-5-21-200153710-2499995584-3205563836-1001\...\Run: [Boot pc] = & gt; wscript.exe //B " C:\Users\Wojtek\AppData\Local\Temp\Boot pc.vbs " & lt; ===== ATTENTION
AppInit_DLLs: C:\Windows\System32\nvinitx.dll = & gt; C:\Windows\System32\nvinitx.dll [226920 2011-02-08] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\Windows\SysWOW64\nvinit.dll = & gt; c:\Windows\SysWOW64\nvinit.dll [192616 2011-02-08] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk - & gt; C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe ()
Startup: C:\Users\Wojtek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Boot pc.vbs ()
Startup: C:\Users\Wojtek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Calendar.vbs ()
Startup: C:\Users\Wojtek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Essentials.vbs ()
ShellIconOverlayIdentifiers: AsusWSShellExt_B - & gt; {6D4133E5-0742-4ADC-8A8C-9303440F7190} = & gt; C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: AsusWSShellExt_O - & gt; {64174815-8D98-4CE6-8646-4C039977D808} = & gt; C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
GroupPolicy: Group Policy on Chrome detected & lt; ======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie & ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_page_url = http://www.microsoft.com/isapi/redir.dll?prd=ie & pver=6 & ar=msnhome
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie & ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie & pver=6 & ar=msnhome
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search bar = http://search.msn.com/spbasic.htm
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=ie7 & q={searchTerms} & rls=com.microsoft:{language}:{referrer:source?} & ie={inputEncoding} & oe={outputEncoding} & rlz=1I7ASUT
SearchScopes: HKCU - ${searchCLSID} URL = http://search.live.com/results.aspx?q={searchTerms} & src={referrer:source?}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear
BHO: TmIEPlugInBHO Class - & gt; {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - & gt; C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll (Trend Micro Inc.)
BHO: Java(tm) Plug-In SSV Helper - & gt; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - & gt; C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - & gt; {9030D464-4C02-4ABF-8ECC-5164760863C6} - & gt; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - & gt; {AA58ED58-01DD-4d91-8333-CF10577473F7} - & gt; C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - & gt; {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - & gt; C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll (Google Inc.)
BHO: TmBpIeBHO Class - & gt; {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - & gt; C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe64.dll (Trend Micro Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - & gt; {DBC80044-A445-435b-BC74-9C25C1C588A9} - & gt; C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: TmIEPlugInBHO Class - & gt; {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - & gt; C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg32.dll (Trend Micro Inc.)
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer - & gt; {3049C3E9-B461-4BC5-8870-4C09146192CA} - & gt; C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO-x32: Groove GFS Browser Helper - & gt; {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - & gt; C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - & gt; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - & gt; C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - & gt; {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - & gt; C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper - & gt; {9030D464-4C02-4ABF-8ECC-5164760863C6} - & gt; C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - & gt; {AA58ED58-01DD-4d91-8333-CF10577473F7} - & gt; C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Google Toolbar Notifier BHO - & gt; {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - & gt; C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
BHO-x32: TmBpIeBHO Class - & gt; {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - & gt; C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll (Trend Micro Inc.)
BHO-x32: Google Dictionary Compression sdch - & gt; {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - & gt; C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
BHO-x32: Free Download Manager - & gt; {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - & gt; C:\Program Files (x86)\Free Download Manager\iefdm2.dll ()
BHO-x32: Bing Bar Helper - & gt; {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - & gt; C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - & gt; {DBC80044-A445-435b-BC74-9C25C1C588A9} - & gt; C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe64.dll (Trend Micro Inc.)
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll (Trend Micro Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll (Trend Micro Inc.)
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg32.dll (Trend Micro Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - & gt; C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - & gt; C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - & gt; C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - & gt; C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - & gt; C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - & gt; C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - & gt; C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - & gt; C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - & gt; C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - & gt; C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - & gt; C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - & gt; C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - & gt; C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=15.0.1.13 - & gt; C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=15.0.1.13 - & gt; C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.1.13 - & gt; C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.1.13 - & gt; C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=15.0.1.13 - & gt; C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - & gt; C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - & gt; C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - & gt; C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 - & gt; C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - & gt; C:\Users\Wojtek\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - & gt; C:\Users\Wojtek\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension
FF Extension: Trend Micro NSC Firefox Extension - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension [2011-04-01]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-01-22]

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: " hxxp://www.google.com/ "
CHR DefaultSearchURL: https://www.google.com/calendar/render?cid=%s
CHR Extension: (YouTube) - C:\Users\Wojtek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-01-12]
CHR Extension: (Szukaj w Google) - C:\Users\Wojtek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-01-12]
CHR Extension: (Mapy Google) - C:\Users\Wojtek\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2013-06-22]
CHR Extension: (Pic and Click San Francisco) - C:\Users\Wojtek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkpmjmcgjoidcjgdfmeaajknmjcecdii [2014-08-01]
CHR Extension: (Google Wallet) - C:\Users\Wojtek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Gmail) - C:\Users\Wojtek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-01-12]
CHR HKLM-x32\...\Chrome\Extension: [hpilclpacieflhmobalmaccogiioldoo] - C:\ProgramData\TheBflix\hpilclpacieflhmobalmaccogiioldoo.crx []
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2012-01-22]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 Atheros Bt & Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-03-13] (Atheros) [File not signed]
S2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [74912 2011-03-13] (Atheros Commnucations) [File not signed]
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2010-11-13] (CyberLink)
S2 CTDevice_Srv; C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe [61440 2007-04-02] (Creative Technology Ltd) [File not signed]
S3 CTUPnPSv; C:\Program Files (x86)\Creative\Creative Centrale\CTUPnPSv.exe [64000 2008-05-21] (Creative Technology Ltd) [File not signed]
S2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [351824 2013-02-06] ()
S2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
S2 TiMiniService; C:\Program Files\Trend Micro\Titanium\TiMiniService.exe [241488 2010-09-17] (Trend Micro Inc.)
S3 Amsp; " C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe " coreFrameworkHost.exe -m=rb -dt=60000 [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [165504 2012-12-15] (ITE )
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-10-22] (Duplex Secure Ltd.)
R2 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [90704 2010-09-17] (Trend Micro Inc.)
R2 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [144464 2010-09-17] (Trend Micro Inc.)
R2 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [67664 2010-09-17] (Trend Micro Inc.)
R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105552 2010-09-17] (Trend Micro Inc.)
U3 a3hg92of; C:\Windows\System32\Drivers\a3hg92of.sys [0 ] (Microsoft Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 hwusbfake; system32\DRIVERS\ewusbfake.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-24 14:34 - 2014-08-24 14:34 - 00025628 _____ () C:\Users\Wojtek\Desktop\FRST.txt
2014-08-24 14:34 - 2014-08-24 14:34 - 00000000 ____D () C:\FRST
2014-08-24 14:33 - 2014-08-24 14:33 - 00007072 _____ () C:\Users\Wojtek\Desktop\UsbFix.txt
2014-08-24 14:30 - 2014-08-24 14:31 - 17292208 _____ (Malwarebytes Corporation ) C:\Users\Wojtek\Desktop\mbam-setup.exe
2014-08-24 14:29 - 2014-08-24 14:29 - 02103296 _____ (Farbar) C:\Users\Wojtek\Desktop\FRST64.exe
2014-08-24 14:26 - 2014-08-24 14:26 - 00000000 ___RD () C:\Users\Wojtek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-08-24 14:23 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-24 14:21 - 2014-08-24 14:24 - 00000000 ____D () C:\AdwCleaner
2014-08-24 14:21 - 2014-08-24 14:21 - 01364531 _____ () C:\Users\Wojtek\Desktop\adwcleaner_3.308.exe
2014-08-22 13:07 - 2014-08-22 13:07 - 00000077 _____ () C:\Users\Wojtek\Desktop\radiofreeeacp.m3u
2014-08-15 01:03 - 2013-02-17 05:16 - 00244736 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juwwanecm.sys
2014-08-15 01:03 - 2013-02-17 05:15 - 00076800 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcecm.sys
2014-08-15 01:03 - 2013-01-25 05:35 - 00105984 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcacm.sys
2014-08-15 01:03 - 2013-01-25 03:16 - 00109568 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys
2014-08-15 01:03 - 2013-01-23 09:02 - 00452096 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbwwan.sys
2014-08-15 01:03 - 2013-01-23 08:57 - 00225920 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys
2014-08-15 01:03 - 2013-01-23 05:32 - 00091648 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jubusenum.sys
2014-08-15 01:03 - 2013-01-23 05:32 - 00030720 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juextctrl.sys
2014-08-15 01:03 - 2012-12-22 03:46 - 00014976 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbenumfilter.sys
2014-08-15 01:03 - 2010-10-08 10:59 - 00032768 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys
2014-08-15 01:03 - 2010-09-26 12:09 - 00022016 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwupgrade.sys
2014-08-15 01:03 - 2010-08-06 01:43 - 01001472 _____ (DiBcom SA) C:\Windows\system32\Drivers\mod7700.sys
2014-08-08 23:41 - 2014-08-08 23:41 - 00000000 ___HD () C:\Users\Wojtek\Desktop\.picasaoriginals
2014-08-01 22:08 - 2014-08-01 22:08 - 00022942 ____N () C:\ComboFix.txt
2014-08-01 21:50 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-01 21:50 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-01 21:50 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-01 21:50 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-01 21:50 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-01 21:50 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-01 21:50 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-01 21:50 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-01 21:49 - 2014-08-01 22:08 - 00000000 ____D () C:\Qoobox
2014-08-01 21:46 - 2014-08-01 21:47 - 00000000 ____D () C:\Users\Wojtek\AppData\Roaming\GetRightToGo

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2049-07-16 02:31 - 2012-07-07 12:40 - 00003970 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{BEC2371F-D700-4116-A54A-5192CFFA17DE}
2014-08-24 14:34 - 2014-08-24 14:34 - 00025628 _____ () C:\Users\Wojtek\Desktop\FRST.txt
2014-08-24 14:34 - 2014-08-24 14:34 - 00000000 ____D () C:\FRST
2014-08-24 14:33 - 2014-08-24 14:33 - 00007072 _____ () C:\Users\Wojtek\Desktop\UsbFix.txt
2014-08-24 14:33 - 2014-05-12 22:54 - 00007072 _____ () C:\UsbFix.txt
2014-08-24 14:33 - 2014-05-12 22:25 - 01455566 _____ () C:\UsbFix_Upload_Me_KOMPUTER.zip
2014-08-24 14:33 - 2014-05-12 22:16 - 00000000 ____D () C:\UsbFix
2014-08-24 14:33 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-24 14:33 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-24 14:32 - 2011-02-19 07:31 - 00761692 _____ () C:\Windows\system32\perfh015.dat
2014-08-24 14:32 - 2011-02-19 07:31 - 00165478 _____ () C:\Windows\system32\perfc015.dat
2014-08-24 14:32 - 2009-07-14 07:13 - 01730234 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-24 14:31 - 2014-08-24 14:30 - 17292208 _____ (Malwarebytes Corporation ) C:\Users\Wojtek\Desktop\mbam-setup.exe
2014-08-24 14:31 - 2011-04-01 10:58 - 00001062 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-24 14:29 - 2014-08-24 14:29 - 02103296 _____ (Farbar) C:\Users\Wojtek\Desktop\FRST64.exe
2014-08-24 14:29 - 2011-09-20 14:40 - 02051186 _____ () C:\Windows\WindowsUpdate.log
2014-08-24 14:26 - 2014-08-24 14:26 - 00000000 ___RD () C:\Users\Wojtek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-08-24 14:26 - 2014-07-18 22:10 - 00003342 _____ () C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-200153710-2499995584-3205563836-1001
2014-08-24 14:26 - 2014-02-21 23:41 - 00086304 _____ () C:\Windows\setupact.log
2014-08-24 14:26 - 2012-01-22 17:01 - 00003210 _____ () C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-200153710-2499995584-3205563836-1001
2014-08-24 14:26 - 2012-01-12 23:05 - 00045056 _____ () C:\Windows\system32\acovcnt.exe
2014-08-24 14:26 - 2011-04-01 10:58 - 00001058 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-24 14:26 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-24 14:25 - 2014-04-12 22:04 - 00151334 _____ () C:\Windows\PFRO.log
2014-08-24 14:24 - 2014-08-24 14:21 - 00000000 ____D () C:\AdwCleaner
2014-08-24 14:24 - 2012-01-12 23:05 - 00000000 ____D () C:\Users\Wojtek
2014-08-24 14:21 - 2014-08-24 14:21 - 01364531 _____ () C:\Users\Wojtek\Desktop\adwcleaner_3.308.exe
2014-08-24 13:44 - 2012-10-06 10:51 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-24 12:12 - 2012-05-07 17:20 - 00000932 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-200153710-2499995584-3205563836-1001UA.job
2014-08-24 12:12 - 2012-05-07 17:20 - 00000910 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-200153710-2499995584-3205563836-1001Core.job
2014-08-22 13:07 - 2014-08-22 13:07 - 00000077 _____ () C:\Users\Wojtek\Desktop\radiofreeeacp.m3u
2014-08-22 13:07 - 2012-01-23 19:15 - 00000000 ____D () C:\Users\Wojtek\AppData\Roaming\Winamp
2014-08-14 21:28 - 2014-02-18 17:33 - 00000266 __RSH () C:\ProgramData\ntuser.pol
2014-08-08 23:41 - 2014-08-08 23:41 - 00000000 ___HD () C:\Users\Wojtek\Desktop\.picasaoriginals
2014-08-07 22:16 - 2014-07-06 21:44 - 00001390 _____ () C:\Users\Wojtek\Desktop\rachunki.txt
2014-08-01 22:08 - 2014-08-01 22:08 - 00022942 ____N () C:\ComboFix.txt
2014-08-01 22:08 - 2014-08-01 21:49 - 00000000 ____D () C:\Qoobox
2014-08-01 22:04 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-08-01 21:47 - 2014-08-01 21:46 - 00000000 ____D () C:\Users\Wojtek\AppData\Roaming\GetRightToGo
2014-07-26 21:22 - 2012-01-12 23:07 - 00000000 ____D () C:\Users\Wojtek\Documents\Bluetooth Folder

Some content of TEMP:
====================
C:\Users\Wojtek\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe = & gt; File is digitally signed
C:\Windows\System32\wininit.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\wininit.exe = & gt; File is digitally signed
C:\Windows\explorer.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\explorer.exe = & gt; File is digitally signed
C:\Windows\System32\svchost.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\svchost.exe = & gt; File is digitally signed
C:\Windows\System32\services.exe = & gt; File is digitally signed
C:\Windows\System32\User32.dll = & gt; File is digitally signed
C:\Windows\SysWOW64\User32.dll = & gt; File is digitally signed
C:\Windows\System32\userinit.exe = & gt; File is digitally signed
C:\Windows\SysWOW64\userinit.exe = & gt; File is digitally signed
C:\Windows\System32\rpcss.dll = & gt; File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys = & gt; File is digitally signed


LastRegBack: 2014-08-17 00:40

==================== End Of Log ============================


Pobierz plik - link do postu