Plik cmd.exe wykrywany przez AVG jako zagrożenie

Hejka. 

 

Wstawiam od razu logi z OTL

 

OTL Extras logfile created on: 2014-05-31 11:15:19 - Run 2

OTL by OldTimer - Version 3.2.69.0     Folder = C:\Documents and Settings\Właściciel\Pulpit

Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

 

3,00 Gb Total Physical Memory | 2,03 Gb Available Physical Memory | 67,75% Memory free

4,84 Gb Paging File | 3,67 Gb Available in Paging File | 75,81% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 60,00 Gb Total Space | 35,35 Gb Free Space | 58,92% Space Free | Partition Type: NTFS

Drive D: | 202,81 Gb Total Space | 202,59 Gb Free Space | 99,89% Space Free | Partition Type: NTFS

Drive E: | 202,81 Gb Total Space | 119,01 Gb Free Space | 58,68% Space Free | Partition Type: NTFS

 

Computer Name: MICHA-F48D09B6D | User Name: Właściciel | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\extension]

.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL “%1”,%*

.html [@ = Opera.HTML] – C:\Program Files\Opera\Opera.exe (Opera Software)

 

[HKEY_CURRENT_USER\SOFTWARE\Classes\extension]

.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\key\shell[command]\command]

batfile [open] – “%1” %*

cmdfile [open] – “%1” %*

comfile [open] – “%1” %*

cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL “%1”,%*

exefile [open] – “%1” %*

htmlfile [edit] – Reg Error: Key error.

http [open] – “C:\Program Files\Opera\Opera.exe” “%1” (Opera Software)

https [open] – “C:\Program Files\Opera\Opera.exe” “%1” (Opera Software)

piffile [open] – “%1” %*

regfile [merge] – Reg Error: Key error.

scrfile [config] – “%1”

scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] – “%1” /S

txtfile [edit] – Reg Error: Key error.

Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

“FirstRunDisabled” = 1

“AntiVirusDisableNotify” = 0

“FirewallDisableNotify” = 0

“UpdatesDisableNotify” = 0

“AntiVirusOverride” = 0

“FirewallOverride” = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

========== System Restore Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

“DisableSR” = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

“Start” = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

“Start” = 2

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

“EnableFirewall” = 1

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

“EnableFirewall” = 1

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

“1900:UDP” = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007

“2869:TCP” = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

“%windir%\Network Diagnostic\xpnetdiag.exe” = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)

“%windir%\system32\sessmgr.exe” = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

“%windir%\Network Diagnostic\xpnetdiag.exe” = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)

“%windir%\system32\sessmgr.exe” = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)

“C:\Program Files\Opera\opera.exe” = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)

“C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE” = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)

“C:\Program Files\Microsoft Office\Office12\GROOVE.EXE” = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)

“C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE” = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)

“E:\Gry\CS\hl.exe” = E:\Gry\CS\hl.exe:*:Enabled:Half-Life Launcher

“E:\Instalki\Gadu-Gadu 10\gg.exe” = E:\Instalki\Gadu-Gadu 10\gg.exe:*:Enabled:Gadu-Gadu 10 – (GG Network S.A.)

“C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe” = C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe – (NVIDIA Corporation)

“C:\Program Files\Skype\Phone\Skype.exe” = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)

“E:\Instalki\DAEMON Tools Lite\avgmfapx.exe” = E:\Instalki\DAEMON Tools Lite\avgmfapx.exe:*:Enabled:Instalator AVG

“C:\Program Files\AVG\AVG2014\avgmfapx.exe” = C:\Program Files\AVG\AVG2014\avgmfapx.exe:*:Enabled:Instalator AVG – (AVG Technologies CZ, s.r.o.)

“C:\Program Files\AVG\AVG2014\avgnsx.exe” = C:\Program Files\AVG\AVG2014\avgnsx.exe:*:Enabled:Ochrona Sieci – (AVG Technologies CZ, s.r.o.)

“C:\Program Files\AVG\AVG2014\avgdiagex.exe” = C:\Program Files\AVG\AVG2014\avgdiagex.exe:*:Enabled:Diagnostyka AVG 2014 – (AVG Technologies CZ, s.r.o.)

“C:\Program Files\AVG\AVG2014\avgemcx.exe” = C:\Program Files\AVG\AVG2014\avgemcx.exe:*:Enabled:Uniwersalny skaner poczty email – (AVG Technologies CZ, s.r.o.)

“E:\Gry\Counter Strike 1.6\hl.exe” = E:\Gry\Counter Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher – (Valve)

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

“{0A0CADCF-78DA-33C4-A350-CD51849B9702}” = Microsoft .NET Framework 4 Extended

“{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}” = PlayStation®Store

“{196BB40D-1578-3D01-B289-BEFC77A11A1E}” = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319

“{26A24AE4-039D-4CA4-87B4-2F83216022FF}” = Java 6 Update 22

“{2AFF2951-86B1-3C53-B34D-B440F11E7D0A}” = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PLK

“{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}” = Microsoft .NET Framework 4 Client Profile PLK Language Pack

“{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}” = WebFldrs XP

“{3C3901C5-3455-3E0A-A214-0B093A5070A6}” = Microsoft .NET Framework 4 Client Profile

“{4A03706F-666A-4037-7777-5F2748764D10}” = Java Auto Updater

“{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}” = Skype™ 6.11

“{4FD60DA7-3BC9-4D9A-BC15-9C53D1283709}” = AVG 2014

“{5C19E2DC-4CCF-3114-B40A-6E565987025F}” = Microsoft .NET Framework 4 Extended PLK Language Pack

“{5C7025FD-6BD0-4E48-8948-696E26AF6F15}” = Media Go

“{5DB849D6-9392-4FB7-9ABB-87ED433152E5}” = LG United Mobile Drivers

“{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}” = Microsoft Visual C++ 2005 Redistributable

“{75C22B40-6D12-4439-80DC-CAB3313EADA5}” = dj_sf_software_req

“{7B5AA67E-FEA0-40BB-BAB5-CA56645A589C}” = NVIDIA PhysX

“{7F1AD376-F6A0-4C2D-B93B-6FECC45620D2}” = AVG 2014

“{81999787-A518-4218-86D5-C5D25E6808F5}_is1” = Testy Bplus 5.1.3.65

“{8227BCD8-AA43-B935-7134-2732A298364A}” = Media Go Video Playback Engine 1.120.102.05010

“{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}” = Microsoft Silverlight

“{90120000-0010-0415-0000-0000000FF1CE}” = Microsoft Software Update for Web Folders  (Polish) 12

“{90120000-0015-0415-0000-0000000FF1CE}” = Microsoft Office Access MUI (Polish) 2007

“{90120000-0015-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}” = Microsoft Office 2007 Service Pack 3 (SP3)

“{90120000-0016-0415-0000-0000000FF1CE}” = Microsoft Office Excel MUI (Polish) 2007

“{90120000-0016-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}” = Microsoft Office 2007 Service Pack 3 (SP3)

“{90120000-0018-0415-0000-0000000FF1CE}” = Microsoft Office PowerPoint MUI (Polish) 2007

“{90120000-0018-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}” = Microsoft Office 2007 Service Pack 3 (SP3)

“{90120000-0019-0415-0000-0000000FF1CE}” = Microsoft Office Publisher MUI (Polish) 2007

“{90120000-0019-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}” = Microsoft Office 2007 Service Pack 3 (SP3)

“{90120000-001A-0415-0000-0000000FF1CE}” = Microsoft Office Outlook MUI (Polish) 2007

“{90120000-001A-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}” = Microsoft Office 2007 Service Pack 3 (SP3)

“{90120000-001B-0415-0000-0000000FF1CE}” = Microsoft Office Word MUI (Polish) 2007

“{90120000-001B-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}” = Microsoft Office 2007 Service Pack 3 (SP3)

“{90120000-001F-0407-0000-0000000FF1CE}” = Microsoft Office Proof (German) 2007

“{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}” = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

“{90120000-001F-0409-0000-0000000FF1CE}” = Microsoft Office Proof (English) 2007

“{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}” = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

“{90120000-001F-0415-0000-0000000FF1CE}” = Microsoft Office Proof (Polish) 2007

“{90120000-001F-0415-0000-0000000FF1CE}_ENTERPRISE_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}” = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

“{90120000-002C-0415-0000-0000000FF1CE}” = Microsoft Office Proofing (Polish) 2007

“{90120000-0030-0000-0000-0000000FF1CE}” = Microsoft Office Enterprise 2007

“{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}” = Microsoft Office 2007 Service Pack 3 (SP3)

“{90120000-0044-0415-0000-0000000FF1CE}” = Microsoft Office InfoPath MUI (Polish) 2007

“{90120000-0044-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}” = Microsoft Office 2007 Service Pack 3 (SP3)

“{90120000-006E-0415-0000-0000000FF1CE}” = Microsoft Office Shared MUI (Polish) 2007

“{90120000-006E-0415-0000-0000000FF1CE}_ENTERPRISE_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}” = Microsoft Office 2007 Service Pack 3 (SP3)

“{90120000-00A1-0415-0000-0000000FF1CE}” = Microsoft Office OneNote MUI (Polish) 2007

“{90120000-00A1-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}” = Microsoft Office 2007 Service Pack 3 (SP3)

“{90120000-00BA-0415-0000-0000000FF1CE}” = Microsoft Office Groove MUI (Polish) 2007

“{90120000-00BA-0415-0000-0000000FF1CE}_ENTERPRISE_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}” = Microsoft Office 2007 Service Pack 3 (SP3)

“{90140000-2005-0000-0000-0000000FF1CE}” = Microsoft Office File Validation Add-In

“{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}” = Visual Studio 2012 x86 Redistributables

“{9A25302D-30C0-39D9-BD6F-21E6EC160475}” = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

“{9BE518E6-ECC6-35A9-88E4-87755C07200F}” = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

“{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}” = Microsoft .NET Framework 3.0 Service Pack 2

“{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}” = Google Update Helper

“{AB3F9176-E74A-4F28-9A09-4F22349B145E}” = livebox tp

“{AC76BA86-7AD7-1045-7B44-AB0000000001}” = Adobe Reader XI - Polish

“{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel” = Panel sterowania NVIDIA 331.65

“{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver” = NVIDIA Sterownik graficzny 331.65

“{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience” = NVIDIA GeForce Experience 1.7

“{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView” = NVIDIA nView 140.75

“{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX” = NVIDIA Oprogramowanie systemu PhysX 9.13.0725

“{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update” = Aktualizacje NVIDIA 9.3.16

“{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer” = NVIDIA Install Application

“{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update” = NVIDIA Update Components

“{B742757A-7658-4E09-A51A-085CF0F7F4D3}” = Brother MFL-Pro Suite DCP-J105

“{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}” = Microsoft .NET Framework 2.0 Service Pack 2

“{C2523AE6-F335-4D0B-BC15-1C07E4ACE629}” = Pro Evolution Soccer 2013

“{C9BED750-1211-4480-B1A5-718A3BE15525}” = REALTEK GbE FE Ethernet PCI-E NIC Driver

“{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}” = PlayReady PC Runtime x86

“{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}” = Microsoft .NET Framework 3.5 SP1

“{E0C18BB0-32CA-4679-B422-9B9FA825378F}” = HP Deskjet Printer Driver Software 9.0

“{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}” = Toolbox

“{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}” = Sony PC Companion 2.10.206

“{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}” = Realtek High Definition Audio Driver

“{F4933D9F-89CC-4CA9-B5B0-CF32968890C7}” = BookScanWhiteboard Suite

“{FBB850CF-999E-44B3-BC11-C96661873BFF}_is1” = Testy na Prawo Jazdy 2012 - kat. C - ver. 5.0

“Adobe Flash Player ActiveX” = Adobe Flash Player 13 ActiveX

“Adobe Flash Player Plugin” = Adobe Flash Player 13 Plugin

“AVG” = AVG 2014

“Cheat Engine 6.3_is1” = Cheat Engine 6.3

“CS16 Full v32.1 Non-Steam” = CS16 Full v32.1 Non-Steam

“DAEMON Tools Lite” = DAEMON Tools Lite

“Deluxe Ski Jump_is1” = Deluxe Ski Jump 2.1

“ENTERPRISE” = Microsoft Office Enterprise 2007

“ffdshow_is1” = ffdshow v1.2.4422 [2012-04-09]

“FIFA 12 © EA_is1” = FIFA 12 © EA version 1

“Free Games 111” = Free Games 111

“Gadu-Gadu 10” = Gadu-Gadu 10

“GameDesire-Pool Snooker” = GameDesire-Pool Snooker

“Google Chrome” = Google Chrome

“Gutscheinmieze - Toolbar” = Gutscheinmieze - Toolbar

“HaaliMkx” = Haali Media Splitter

“Hard Truck 18 Wheels of Steel” = Hard Truck 18 Wheels of Steel

“Heroes III Armageddon’s Blade” = Heroes III Armageddon’s Blade

“Heroes III The Restoration of Erathia” = Heroes III The Restoration of Erathia

“Heroes III The Shadow of Death” = Heroes III The Shadow of Death

“ie8” = Windows Internet Explorer 8

“ipla” = ipla 2.7

“iSafe” = Yet Another Cleaner!

“JDownloader” = JDownloader

“KLiteCodecPack_is1” = K-Lite Codec Pack 7.2.0 (Full)

“Microsoft .NET Framework 3.5 SP1” = Microsoft .NET Framework 3.5 SP1

“Microsoft .NET Framework 4 Client Profile” = Microsoft .NET Framework 4 Client Profile

“Microsoft .NET Framework 4 Client Profile PLK Language Pack” = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile

“Microsoft .NET Framework 4 Extended” = Microsoft .NET Framework 4 Extended

“Microsoft .NET Framework 4 Extended PLK Language Pack” = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended

“Mozilla Firefox 28.0 (x86 pl)” = Mozilla Firefox 28.0 (x86 pl)

“MozillaMaintenanceService” = Mozilla Maintenance Service

“Opera 12.17.1863” = Opera 12.17

“PacFunction” = PacFunction

“Satsuki Decoder Pack” = Satsuki Decoder Pack

“Speed Test 127” = Speed Test 127

“Starcraft II Heart of the Swarm_is1” = Starcraft II Heart of the Swarm wersja 2.0.11

“Themen aktuell 1” = Themen aktuell 1

“Tła Pulpitu_is1” = Tła Pulpitu v1.2.8

“UEFA EURO 2012_is1” = UEFA EURO 2012

“Vtune_is1” = Vtune 6.6

“Wdf01009” = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9

“Windows Media Format Runtime” = Windows Media Format 11 runtime

“WinRAR archiver” = WinRAR 4.01 (32-bitowy)

“winusb0200” = Microsoft WinUsb 2.0

“WMFDist11” = Windows Media Format 11 runtime

“Wudf01000” = Microsoft User-Mode Driver Framework Feature Pack 1.0

 

========== Last 20 Event Log Errors ==========

 

[Application Events]

Error - 2014-05-21 13:07:51 | Computer Name = MICHA-F48D09B6D | Source = Brother BrLog | ID = 1001

Description = TWN BrtTWN: [2014/05/21 19:07:51.109]: [00002056]: ##### Device Open

 Error! #####  

 

Error - 2014-05-21 13:07:51 | Computer Name = MICHA-F48D09B6D | Source = Brother BrLog | ID = 1001

Description = STI BrtSTI: [2014/05/21 19:07:51.109]: [00002056]: CUsbScnDev: ReadUsbScannerDevice

 Device is not Opened  

 

Error - 2014-05-21 13:07:51 | Computer Name = MICHA-F48D09B6D | Source = Brother BrLog | ID = 1001

Description = STI BrtSTI: [2014/05/21 19:07:51.109]: [00002056]: ReadThread:: ReadDevice

 Error[0x1]   

 

Error - 2014-05-21 13:07:51 | Computer Name = MICHA-F48D09B6D | Source = Brother BrLog | ID = 1001

Description = TWN BrtTWN: [2014/05/21 19:07:51.984]: [00002056]: ##### Device Open

 ERROR! #####  

 

Error - 2014-05-21 13:07:51 | Computer Name = MICHA-F48D09B6D | Source = Brother BrLog | ID = 1001

Description = TWN BrtTWN: [2014/05/21 19:07:51.984]: [00002056]: OpenDevice is failed

 

 

Error - 2014-05-21 13:07:57 | Computer Name = MICHA-F48D09B6D | Source = Brother BrLog | ID = 1001

Description = STI BrtSTI: [2014/05/21 19:07:57.406]: [00004032]: CUsbScnDev: DeviceIoControl

 Illegal response [0x0]  

 

Error - 2014-05-23 09:58:03 | Computer Name = MICHA-F48D09B6D | Source = Application Hang | ID = 1002

Description = Aplikacja zawieszająca hl.exe, wersja 1.1.1.1, moduł zawieszenia hungapp,

 wersja 0.0.0.0, adres zawieszenia 0x00000000.

 

Error - 2014-05-30 08:13:41 | Computer Name = MICHA-F48D09B6D | Source = Brother BrLog | ID = 1001

Description = STI BrtSTI: [2014/05/30 14:13:41.062]: [00001904]: CUsbScnDev: DeviceIoControl

 Illegal response [0x0]  

 

Error - 2014-05-30 08:13:58 | Computer Name = MICHA-F48D09B6D | Source = Brother BrLog | ID = 1001

Description = STI BrtSTI: [2014/05/30 14:13:58.062]: [00001904]: CUsbScnDev: DeviceIoControl

 Illegal response [0x0]  

 

Error - 2014-05-30 08:16:43 | Computer Name = MICHA-F48D09B6D | Source = Brother BrLog | ID = 1001

Description = STI BrtSTI: [2014/05/30 14:16:43.578]: [00001904]: CUsbScnDev: DeviceIoControl

 Illegal response [0x0]  

 

[System Events]

Error - 2014-05-23 10:11:53 | Computer Name = MICHA-F48D09B6D | Source = Service Control Manager | ID = 7023

Description = Usługa Zarządzanie aplikacjami zakończyła działanie; wystąpił następujący

 błąd:   %%126

 

Error - 2014-05-23 10:11:53 | Computer Name = MICHA-F48D09B6D | Source = Service Control Manager | ID = 7023

Description = Usługa Zarządzanie aplikacjami zakończyła działanie; wystąpił następujący

 błąd:   %%126

 

Error - 2014-05-23 10:11:53 | Computer Name = MICHA-F48D09B6D | Source = Service Control Manager | ID = 7023

Description = Usługa Zarządzanie aplikacjami zakończyła działanie; wystąpił następujący

 błąd:   %%126

 

Error - 2014-05-23 10:11:54 | Computer Name = MICHA-F48D09B6D | Source = Service Control Manager | ID = 7023

Description = Usługa Zarządzanie aplikacjami zakończyła działanie; wystąpił następujący

 błąd:   %%126

 

Error - 2014-05-23 10:11:54 | Computer Name = MICHA-F48D09B6D | Source = Service Control Manager | ID = 7023

Description = Usługa Zarządzanie aplikacjami zakończyła działanie; wystąpił następujący

 błąd:   %%126

 

Error - 2014-05-23 10:11:54 | Computer Name = MICHA-F48D09B6D | Source = Service Control Manager | ID = 7023

Description = Usługa Zarządzanie aplikacjami zakończyła działanie; wystąpił następujący

 błąd:   %%126

 

Error - 2014-05-23 10:11:54 | Computer Name = MICHA-F48D09B6D | Source = Service Control Manager | ID = 7023

Description = Usługa Zarządzanie aplikacjami zakończyła działanie; wystąpił następujący

 błąd:   %%126

 

Error - 2014-05-23 10:11:54 | Computer Name = MICHA-F48D09B6D | Source = Service Control Manager | ID = 7023

Description = Usługa Zarządzanie aplikacjami zakończyła działanie; wystąpił następujący

 błąd:   %%126

 

Error - 2014-05-24 05:36:59 | Computer Name = MICHA-F48D09B6D | Source = Service Control Manager | ID = 7034

Description = Usługa iSafeService niespodziewanie zakończyła pracę. Wystąpiło to

 razy: 1.

 

Error - 2014-05-29 07:58:17 | Computer Name = MICHA-F48D09B6D | Source = sr | ID = 1

Description = Filtr Przywracania systemu napotkał nieoczekiwany błąd ‘0xC0000001’

 podczas przetwarzania pliku ‘’ w woluminie ‘HarddiskVolume1’. W rezultacie zostało

 zatrzymane monitorowanie woluminu.

 

 

End of report

 

 

OTL logfile created on: 2014-05-31 11:15:19 - Run 2

OTL by OldTimer - Version 3.2.69.0     Folder = C:\Documents and Settings\Właściciel\Pulpit

Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

 

3,00 Gb Total Physical Memory | 2,03 Gb Available Physical Memory | 67,75% Memory free

4,84 Gb Paging File | 3,67 Gb Available in Paging File | 75,81% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 60,00 Gb Total Space | 35,35 Gb Free Space | 58,92% Space Free | Partition Type: NTFS

Drive D: | 202,81 Gb Total Space | 202,59 Gb Free Space | 99,89% Space Free | Partition Type: NTFS

Drive E: | 202,81 Gb Total Space | 119,01 Gb Free Space | 58,68% Space Free | Partition Type: NTFS

 

Computer Name: MICHA-F48D09B6D | User Name: Właściciel | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

 

========== Processes (SafeList) ==========

 

PRC - [2014-05-31 10:49:12 | 000,602,112 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Właściciel\Pulpit\OTL.exe

PRC - [2014-05-22 12:36:57 | 000,802,984 | ---- | M] (Elex do Brasil Participações Ltda) – C:\Program Files\iSafe\iSafeTray.exe

PRC - [2014-05-22 12:36:50 | 000,379,560 | ---- | M] (Elex do Brasil Participações Ltda) – C:\Program Files\iSafe\iSafeTHlp.exe

PRC - [2014-05-22 12:36:42 | 000,118,056 | ---- | M] (Elex do Brasil Participações Ltda) – C:\Program Files\iSafe\iSafeSvc2.exe

PRC - [2014-05-22 12:36:35 | 000,118,056 | ---- | M] (Elex do Brasil Participações Ltda) – C:\Program Files\iSafe\iSafeSvc.exe

PRC - [2014-05-14 01:40:56 | 000,860,488 | ---- | M] (Google Inc.) – C:\Program Files\Google\Chrome\Application\chrome.exe

PRC - [2014-04-06 21:21:36 | 005,180,432 | ---- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2014\avgui.exe

PRC - [2014-04-01 16:35:46 | 000,466,144 | ---- | M] (Sony) – C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe

PRC - [2014-03-27 22:10:20 | 000,291,912 | ---- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2014\avgwdsvc.exe

PRC - [2013-10-31 12:35:46 | 000,070,880 | ---- | M] () – C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe

PRC - [2013-10-18 03:34:57 | 001,028,384 | ---- | M] (NVIDIA Corporation) – C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe

PRC - [2013-10-18 03:34:26 | 001,914,656 | ---- | M] (NVIDIA Corporation) – C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

PRC - [2013-01-18 11:01:12 | 002,009,088 | ---- | M] (Brother Industries, Ltd.) – C:\Program Files\Brother\Brother Help\BrotherHelp.exe

PRC - [2011-06-01 15:14:56 | 013,349,472 | ---- | M] (GG Network S.A.) – E:\Instalki\Gadu-Gadu 10\gg.exe

PRC - [2011-01-20 11:20:12 | 001,305,408 | ---- | M] (DT Soft Ltd) – E:\Instalki\DAEMON Tools Lite\DTLite.exe

PRC - [2008-09-05 18:24:24 | 002,154,496 | ---- | M] () – C:\Program Files\Vtune\TBPANEL.exe

PRC - [2008-04-15 14:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2014-05-22 12:40:54 | 000,065,704 | ---- | M] () – C:\Program Files\iSafe\zlib1.dll

MOD - [2014-05-22 12:40:38 | 000,185,000 | ---- | M] () – C:\Program Files\iSafe\libpng.dll

MOD - [2014-05-22 12:37:43 | 000,092,328 | ---- | M] () – C:\Program Files\iSafe\curlpp.dll

MOD - [2014-05-14 01:40:54 | 000,414,536 | ---- | M] () – C:\Program Files\Google\Chrome\Application\35.0.1916.114\ppgooglenaclpluginchrome.dll

MOD - [2014-05-14 01:40:53 | 013,695,816 | ---- | M] () – C:\Program Files\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll

MOD - [2014-05-14 01:40:50 | 004,217,672 | ---- | M] () – C:\Program Files\Google\Chrome\Application\35.0.1916.114\pdf.dll

MOD - [2014-05-14 01:40:43 | 001,732,424 | ---- | M] () – C:\Program Files\Google\Chrome\Application\35.0.1916.114\ffmpegsumo.dll

MOD - [2014-05-13 21:10:39 | 016,361,136 | ---- | M] () – C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll

MOD - [2014-04-21 10:22:16 | 000,176,976 | ---- | M] () – C:\Program Files\iSafe\tws\unrar.dll

MOD - [2014-04-21 10:22:16 | 000,087,744 | ---- | M] () – C:\Program Files\iSafe\tws\unacev2.dll

MOD - [2014-04-21 10:22:15 | 000,068,432 | ---- | M] () – C:\Program Files\iSafe\tws\zlib1.dll

MOD - [2014-03-06 15:42:08 | 000,528,384 | ---- | M] () – C:\Program Files\Sony\Sony PC Companion\PhoneUpdate.dll

MOD - [2013-10-31 12:35:46 | 000,070,880 | ---- | M] () – C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe

MOD - [2013-09-13 11:02:30 | 000,208,896 | ---- | M] () – C:\Program Files\Sony\Sony PC Companion\MExplorer.dll

MOD - [2013-05-20 12:58:08 | 000,620,718 | ---- | M] () – C:\Program Files\Sony\Sony PC Companion\sqlite3.dll

MOD - [2012-04-30 11:57:42 | 000,039,936 | ---- | M] () – C:\Program Files\Sony\Sony PC Companion\TMonitorAPI.dll

MOD - [2011-07-07 14:54:36 | 000,233,984 | ---- | M] () – C:\Program Files\Sony\Sony PC Companion\Report.dll

MOD - [2011-06-01 15:15:42 | 000,217,696 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\gglog.dll

MOD - [2011-06-01 15:15:40 | 000,123,488 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\ggipcradioproxy.dll

MOD - [2011-06-01 15:15:38 | 000,017,504 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\ggipc.dll

MOD - [2011-06-01 15:15:36 | 000,027,744 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\ggcrypto.dll

MOD - [2011-06-01 15:15:32 | 000,356,960 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\ggcommon.dll

MOD - [2011-04-16 05:04:30 | 014,749,696 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\QtWebKit4.dll

MOD - [2011-02-17 11:00:28 | 001,781,760 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\QtScript4.dll

MOD - [2011-02-17 11:00:28 | 000,393,216 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\QtXml4.dll

MOD - [2011-02-17 11:00:28 | 000,327,680 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\QtSvg4.dll

MOD - [2011-02-17 11:00:26 | 001,044,480 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\QtNetwork4.dll

MOD - [2011-02-17 11:00:24 | 009,097,216 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\QtGui4.dll

MOD - [2011-02-17 11:00:24 | 002,560,000 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\QtCore4.dll

MOD - [2011-02-17 10:59:40 | 000,311,296 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\imageformats\qtiff4.dll

MOD - [2011-02-17 10:59:40 | 000,274,432 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\imageformats\qmng4.dll

MOD - [2011-02-17 10:59:40 | 000,143,360 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\imageformats\qjpeg4.dll

MOD - [2011-02-17 10:59:40 | 000,027,648 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\imageformats\qgif4.dll

MOD - [2011-02-17 10:59:40 | 000,018,944 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\imageformats\qsvg4.dll

MOD - [2011-02-17 10:59:32 | 000,059,904 | ---- | M] () – E:\Instalki\Gadu-Gadu 10\zlib1.dll

MOD - [2010-01-11 16:44:54 | 000,053,248 | ---- | M] () – C:\Program Files\Sony\Sony PC Companion\VObject.dll

MOD - [2009-02-27 16:38:20 | 000,139,264 | R— | M] () – C:\Program Files\Brother\BrUtilities\BrLogAPI.dll

MOD - [2008-09-11 11:13:43 | 000,466,944 | ---- | M] () – C:\WINDOWS\system32\nvshell.dll

MOD - [2008-09-05 18:24:24 | 002,154,496 | ---- | M] () – C:\Program Files\Vtune\TBPANEL.exe

MOD - [2008-04-15 14:00:00 | 000,014,336 | ---- | M] () – C:\WINDOWS\system32\msdmo.dll

MOD - [2007-01-31 11:33:24 | 000,032,768 | ---- | M] () – C:\Program Files\Vtune\TBPanelExt.dll

MOD - [1998-10-31 04:55:56 | 000,005,120 | ---- | M] () – C:\Program Files\Vtune\TBMANAGE.DLL

 

 

========== Services (SafeList) ==========

 

SRV - File not found [On_Demand | Stopped] – %SystemRoot%\System32\appmgmts.dll – (AppMgmt)

SRV - [2014-05-22 12:36:35 | 000,118,056 | ---- | M] (Elex do Brasil Participações Ltda) [Auto | Running] – C:\Program Files\iSafe\iSafeSvc.exe – (iSafeService)

SRV - [2014-05-13 21:10:40 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)

SRV - [2014-04-18 15:22:28 | 003,645,456 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] – C:\Program Files\AVG\AVG2014\avgidsagent.exe – (AVGIDSAgent)

SRV - [2014-03-31 22:56:07 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)

SRV - [2014-03-27 22:10:20 | 000,291,912 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2014\avgwdsvc.exe – (avgwd)

SRV - [2013-10-23 09:15:08 | 000,172,192 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files\Skype\Updater\Updater.exe – (SkypeUpdate)

SRV - [2013-10-18 03:34:26 | 001,914,656 | ---- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe – (nvUpdatusService)

SRV - [2013-02-04 18:43:22 | 000,155,824 | ---- | M] (Avanquest Software) [On_Demand | Stopped] – C:\Program Files\Sony\Sony PC Companion\PCCService.exe – (Sony PC Companion)

SRV - [2012-10-26 10:40:10 | 000,282,112 | ---- | M] (Brother Industries, Ltd.) [On_Demand | Stopped] – C:\Program Files\Browny02\BrYNSvc.exe – (BrYNSvc)

 

 

========== Driver Services (SafeList) ==========

 

DRV - File not found [Kernel | On_Demand | Stopped] –  – (WDICA)

DRV - File not found [Kernel | On_Demand | Stopped] –  – (PDRFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] –  – (PDRELI)

DRV - File not found [Kernel | On_Demand | Stopped] –  – (PDFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] –  – (PDCOMP)

DRV - File not found [Kernel | System | Stopped] –  – (PCIDump)

DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\PCANDIS5.SYS – (PCANDIS5)

DRV - File not found [Kernel | System | Stopped] –  – (lbrtfdc)

DRV - File not found [Kernel | System | Stopped] –  – (i2omgmt)

DRV - File not found [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\fubtixui.sys – (fubtixui)

DRV - File not found [Kernel | System | Stopped] –  – (Changer)

DRV - [2014-05-22 12:43:13 | 000,054,784 | ---- | M] (Elex do Brasil Participações Ltda) [Kernel | System | Running] – C:\Program Files\iSafe\iSafeNetFilter.sys – (iSafeNetFilter)

DRV - [2014-05-22 12:42:57 | 000,059,392 | ---- | M] (Elex do Brasil Participações Ltda) [Kernel | System | Running] – C:\Program Files\iSafe\iSafeKrnlKit.sys – (iSafeKrnlKit)

DRV - [2014-05-22 12:42:56 | 000,202,240 | ---- | M] (Elex do Brasil Participações Ltda) [File_System | On_Demand | Running] – C:\Program Files\iSafe\iSafeKrnl.sys – (iSafeKrnl)

DRV - [2014-05-22 12:42:56 | 000,038,912 | ---- | M] (Elex do Brasil Participações Ltda) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\iSafeKrnlBoot.sys – (iSafeKrnlBoot)

DRV - [2014-04-18 15:02:04 | 000,199,960 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgidsdriverx.sys – (AVGIDSDriver)

DRV - [2014-03-31 16:11:58 | 000,211,224 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtdix.sys – (Avgtdix)

DRV - [2014-03-31 16:11:50 | 000,108,312 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\avgmfx86.sys – (Avgmfx86)

DRV - [2014-03-27 22:15:18 | 000,193,304 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgldx86.sys – (Avgldx86)

DRV - [2014-03-27 22:14:40 | 000,123,160 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgdiskx.sys – (Avgdiskx)

DRV - [2014-03-27 22:04:22 | 000,150,296 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\avgidshx.sys – (AVGIDSHX)

DRV - [2014-03-27 22:04:02 | 000,238,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\avglogx.sys – (Avglogx)

DRV - [2014-03-27 22:03:22 | 000,028,440 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\avgrkx86.sys – (Avgrkx86)

DRV - [2014-03-27 22:03:20 | 000,022,296 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgidsshimx.sys – (AVGIDSShim)

DRV - [2013-10-27 18:04:59 | 000,218,688 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\dtsoftbus01.sys – (dtsoftbus01)

DRV - [2013-10-04 21:16:08 | 000,016,608 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\gdrv.sys – (gdrv)

DRV - [2013-02-12 02:32:23 | 000,012,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\usb8023.sys – (USB_RNDIS)

DRV - [2012-07-03 11:43:00 | 000,027,776 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lgandnetmodem.sys – (ANDNetModem)

DRV - [2012-07-03 11:43:00 | 000,023,040 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lgandnetdiag.sys – (AndNetDiag)

DRV - [2009-07-13 16:51:12 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\winusb.sys – (WinUSB)

DRV - [2008-02-14 11:04:06 | 004,676,096 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService)

DRV - [2008-01-03 16:10:16 | 000,105,856 | R— | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Rtenicxp.sys – (RTLE8023xp)

DRV - [2007-03-16 10:11:38 | 000,012,256 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\TBPanel.sys – (TBPanel)

DRV - [2007-03-16 10:11:38 | 000,012,256 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\TBPanel.sys – (Cardex)

 

 

========== Standard Registry (All) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=dsts=1395431845from=ilduid=WDCXWD5000AAKS-00A7B2_WD-WMASY346116861168q={searchTerms}

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=dsts=1395431845from=ilduid=WDCXWD5000AAKS-00A7B2_WD-WMASY346116861168q={searchTerms}

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.awesomehp.com/web/?type=dsts=1395431845from=ilduid=WDCXWD5000AAKS-00A7B2_WD-WMASY346116861168q={searchTerms}

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.awesomehp.com/web/?type=dsts=1395431845from=ilduid=WDCXWD5000AAKS-00A7B2_WD-WMASY346116861168q={searchTerms}

IE - HKLM…\SearchScopes,DefaultScope = {0191A6B0-1154-4C22-9182-23A95BBE92D9}

IE - HKLM…\SearchScopes{0191A6B0-1154-4C22-9182-23A95BBE92D9}: “URL” = http://www.google.com/search?q={searchTerms}

IE - HKLM…\SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://search.live.com/results.aspx?q={searchTerms}src={referrer:source?}

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=iear=iesearch

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKCU…\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

IE - HKCU…\SearchScopes,DefaultScope = {0191A6B0-1154-4C22-9182-23A95BBE92D9}

IE - HKCU…\SearchScopes{0191A6B0-1154-4C22-9182-23A95BBE92D9}: “URL” = http://www.google.com/search?q={searchTerms}

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0

 

========== FireFox ==========

 

FF - prefs.js…browser.search.defaultenginename: “foxsearch”

FF - prefs.js…browser.search.order.1: “foxsearch”

FF - prefs.js…browser.search.selectedEngine: “foxsearch”

FF - prefs.js…extensions.enabledAddons: 5a6bf058-b978-4b84-a2ec-6f5462cfccb2%4010120365-d3c0-4ec9-8624-5fac2592d0df.com:0.94.27

FF - prefs.js…extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:28.0

FF - prefs.js…keyword.URL: "http://www.finduny.com?client=mozilla-firefoxcd=UTF-8search=1q="

 

FF - user.js…browser.search.selectedEngine: “foxsearch”

FF - user.js…browser.search.order.1: “foxsearch”

FF - user.js…browser.search.defaultenginename: “foxsearch”

FF - user.js…keyword.URL: "http://www.finduny.com?client=mozilla-firefoxcd=UTF-8search=1q="

 

FF - HKLM\Software\MozillaPlugins@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()

FF - HKLM\Software\MozillaPlugins@ganymede/GanymedeNetPlugin,version=1.0: C:\Program Files\Ganymede\Plugins\npganymedenet.dll ( )

FF - HKLM\Software\MozillaPlugins@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins@SonyCreativeSoftware.com/Media Go,version=1.0:  File not found

FF - HKLM\Software\MozillaPlugins@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\Adobe Reader: E:\Instalki\Adobe Reader\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2013-10-04 21:54:45 | 000,000,000 | —D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2013-11-10 19:02:59 | 000,000,000 | —D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 28.0\extensions\Components: C:\Program Files\Mozilla Firefox\components

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 28.0\extensions\Plugins: C:\Program Files\Mozilla Firefox\plugins

 

[2014-04-25 15:06:30 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Extensions

[2014-04-25 15:06:30 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Extensions{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2014-05-01 18:32:11 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\y0d0zyzp.default\extensions

[2014-03-21 21:56:29 | 000,000,000 | —D | M] (“Torntv V9.0”) – C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\y0d0zyzp.default\extensions\5a6bf058-b978-4b84-a2ec-6f5462cfccb2@10120365-d3c0-4ec9-8624-5fac2592d0df.com

[2013-10-31 15:28:31 | 000,000,000 | —D | M] (“DAEMON Tools Toolbar”) – C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\y0d0zyzp.default\extensions\DTToolbar@toolbarnet.com

[2013-10-27 18:04:25 | 000,000,000 | —D | M] (Gutscheinmieze) – C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\y0d0zyzp.default\extensions\gutscheinmieze@synatix-gmbh.de

[2014-05-21 17:48:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\y0d0zyzp.default\extensions\5a6bf058-b978-4b84-a2ec-6f5462cfccb2@10120365-d3c0-4ec9-8624-5fac2592d0df.com\extensionData

[2014-05-21 17:48:59 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\y0d0zyzp.default\extensions\5a6bf058-b978-4b84-a2ec-6f5462cfccb2@10120365-d3c0-4ec9-8624-5fac2592d0df.com\extensionData\plugins

[2014-05-21 17:48:59 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\y0d0zyzp.default\extensions\5a6bf058-b978-4b84-a2ec-6f5462cfccb2@10120365-d3c0-4ec9-8624-5fac2592d0df.com\extensionData\userCode

[2014-05-01 18:36:28 | 000,002,004 | ---- | M] () (No name found) – C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Extensions{ec8030f7-c20a-464f-9b0e-13a3a9e97384}{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi

[2013-10-15 15:38:05 | 000,006,227 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\y0d0zyzp.default\searchplugins\dokotoolbar.xml

[2014-05-31 08:22:13 | 000,000,609 | ---- | M] () – C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\y0d0zyzp.default\searchplugins\Google.xml

[2014-03-31 22:55:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions

[2014-03-31 22:56:07 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions{972ce4c6-7e08-4474-a285-3208198ce6fd}

File not found (No name found) – C:\DOCUMENTS AND SETTINGS\WĹ‚AĹ›CICIEL\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\Y0D0ZYZP.DEFAULT\EXTENSIONS\5A6BF058-B978-4B84-A2EC-6F5462CFCCB2@10120365-D3C0-4EC9-8624-5FAC2592D0DF.COM

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = http://www.google.com/search?q={searchTerms}

CHR - default_search_provider: suggest_url = ,

CHR - plugin: Error reading preferences file

CHR - Extension: Dokumenty Google = C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.6_0\

CHR - Extension: Dysk Google = C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_1\

CHR - Extension: YouTube = C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\

CHR - Extension: Szukaj w Google = C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\

CHR - Extension: Google Wallet = C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\

CHR - Extension: Gmail = C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_2\

 

O1 HOSTS File: ([2008-04-15 14:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1       localhost

O2 - BHO: (no name) - {11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} - No CLSID value found.

O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O2 - BHO: (no name) - {C45EC9F0-8333-465D-9728-074BD41985C9} - No CLSID value found.

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

O3 - HKLM…\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No CLSID value found.

O3 - HKCU…\Toolbar\WebBrowser: (Adres) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O3 - HKCU…\Toolbar\WebBrowser: (Łącza) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O4 - HKLM…\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)

O4 - HKLM…\Run: [AVG_UI] C:\Program Files\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)

O4 - HKLM…\Run: [brHelp] C:\Program Files\Brother\Brother Help\BrotherHelp.exe (Brother Industries, Ltd.)

O4 - HKLM…\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)

O4 - HKLM…\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)

O4 - HKLM…\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)

O4 - HKLM…\Run: [Nvtmru] C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation)

O4 - HKLM…\Run: [sunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)

O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKCU…\Run: [DAEMON Tools Lite] E:\Instalki\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)

O4 - HKCU…\Run: [sony PC Companion] C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Sony)

O4 - HKCU…\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe ()

O4 - Startup: C:\Documents and Settings\Właściciel\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = 

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = 

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1

O8 - Extra context menu item: Eksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra ‘Tools’ menuitem : Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra ‘Tools’ menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra ‘Tools’ menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)

O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 0.0.0.0

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces{3F5A6D38-A5FB-4CAB-A61E-3B94E1B89776}: DhcpNameServer = 192.168.1.1 0.0.0.0

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces{CC097540-151A-4628-B586-51EDD29C6685}: DhcpNameServer = 192.168.1.1 0.0.0.0

O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)

O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)

O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (Control_RunDLL “sysdm.cpl”) - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)

O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)

O20 - Winlogon\Notify\dimsntfy: DllName - (%SystemRoot%\System32\dimsntfy.dll) - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\termsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Moduł wstępnego ładowania interfejsu Browseui - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Demon buforu kategorii składników - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)

O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2013-10-03 22:39:51 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT – [NTFS]

O33 - MountPoints2{4647718e-dc5b-11e3-93dd-001bbf546fe1}\Shell - “” = AutoRun

O33 - MountPoints2{4647718e-dc5b-11e3-93dd-001bbf546fe1}\Shell\AutoRun\command - “” = H:\LGAutoRun.exe

O33 - MountPoints2{6bf2f7dc-31ec-11e3-8f89-001fd00d83ba}\Shell - “” = AutoRun

O33 - MountPoints2{6bf2f7dc-31ec-11e3-8f89-001fd00d83ba}\Shell\AutoRun\command - “” = H:\Startme.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2014\avgrsx.exe /sync /restart)

O35 - HKLM…comfile [open] – “%1” %*

O35 - HKLM…exefile [open] – “%1” %*

O37 - HKLM…com [@ = comfile] – “%1” %*

O37 - HKLM…exe [@ = exefile] – “%1” %*

O38 - SubSystems\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

 

========== Files/Folders - Created Within 60 Days ==========

 

[2014-05-31 10:49:09 | 000,602,112 | ---- | C] (OldTimer Tools) – C:\Documents and Settings\Właściciel\Pulpit\OTL.exe

[2014-05-31 08:50:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Menu Start\Programy\Counter-Strike

[2014-05-31 08:46:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Pulpit\maps

[2014-05-23 16:08:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Dane aplikacji\eCyber

[2014-05-23 16:08:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Start\Programy\YAC

[2014-05-23 16:08:08 | 000,038,912 | ---- | C] (Elex do Brasil Participações Ltda) – C:\WINDOWS\System32\drivers\iSafeKrnlBoot.sys

[2014-05-23 16:07:59 | 000,000,000 | —D | C] – C:\Program Files\iSafe

[2014-05-23 16:07:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Dane aplikacji\iSafe

[2014-05-23 16:00:38 | 011,568,296 | ---- | C] (Elex do Brasil Participações Ltda) – C:\Documents and Settings\Właściciel\Pulpit\yet_another_cleaner_sk.exe

[2014-05-23 15:59:35 | 000,000,000 | —D | C] – C:\WINDOWS\System32\MRT

[2014-05-21 18:16:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Start\Programy\Reallusion

[2014-05-21 18:16:30 | 000,000,000 | —D | C] – C:\Program Files\Reallusion

[2014-05-21 18:11:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Dane aplikacji\Reallusion

[2014-05-21 18:06:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Dane aplikacji\ControlCenter4

[2014-05-21 17:59:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Start\Programy\Brother

[2014-05-21 17:58:29 | 000,000,000 | —D | C] – C:\Brother

[2014-05-21 17:58:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\ControlCenter4

[2014-05-21 17:58:22 | 000,000,000 | —D | C] – C:\Program Files\Browny02

[2014-05-21 17:58:09 | 000,253,952 | ---- | C] (brother) – C:\WINDOWS\System32\NSSearch.dll

[2014-05-21 17:58:09 | 000,073,728 | ---- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\BrDctF2.dll

[2014-05-21 17:58:09 | 000,004,608 | ---- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\BrDctF2L.dll

[2014-05-21 17:58:09 | 000,002,560 | ---- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\BrDctF2S.dll

[2014-05-21 17:58:08 | 000,000,000 | —D | C] – C:\Program Files\Brother

[2014-05-21 17:58:05 | 000,180,224 | ---- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\BROSNMP.DLL

[2014-05-21 17:49:33 | 000,133,744 | ---- | C] (Brother Industries Ltd) – C:\WINDOWS\System32\BRRBI13A.EXE

[2014-05-21 17:49:33 | 000,077,824 | ---- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\BRLMW03A.DLL

[2014-05-21 17:49:32 | 000,179,200 | ---- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\BRCOI13I.DLL

[2014-05-21 17:49:32 | 000,050,688 | ---- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\BRPRTINK.DLL

[2014-05-21 17:49:32 | 000,025,299 | ---- | C] (Brother Industries, Ltd) – C:\WINDOWS\System32\BRLM03A.DLL

[2014-05-21 17:49:28 | 001,481,728 | ---- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\BrWia12c.dll

[2014-05-21 17:49:28 | 000,217,088 | ---- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\BrJDec.dll

[2014-05-21 17:49:28 | 000,058,880 | ---- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\BrUsi12c.dll

[2014-05-21 17:49:27 | 000,011,776 | ---- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\BrCiImg.dll

[2014-05-21 17:48:53 | 000,000,000 | —D | C] – C:\Program Files\ControlCenter4

[2014-05-21 17:46:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\Brother

[2014-05-18 18:13:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Pulpit\Top Riffs

[2014-05-16 21:41:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Pulpit\ppp

[2014-05-14 22:43:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER

[2014-05-13 14:04:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\Avg_Update_0414b

[2014-05-11 15:28:46 | 000,013,312 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xp_eos.exe

[2014-05-11 15:28:46 | 000,013,312 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xp_eos.exe

[2014-04-30 08:49:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Ashampoo

[2014-04-30 08:49:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\Ashampoo

[2014-04-26 18:34:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Menu Start\Programy\Haali Media Splitter

[2014-04-26 18:34:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Start\Programy\ffdshow

[2014-04-26 18:34:02 | 000,000,000 | —D | C] – C:\Program Files\Speed Test 127

[2014-04-26 18:33:37 | 000,000,000 | —D | C] – C:\Program Files\Free Games 111

[2014-04-24 16:45:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Menu Start\Programy\1-abc

[2014-04-24 16:45:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Dane aplikacji\1-abc

[2014-04-19 13:23:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Dane aplikacji\41

[2014-04-14 16:12:40 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump

[2014-04-06 20:56:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Temp

[2014-04-06 20:56:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ChomikBox

[7 C:\WINDOWS\System32*.tmp files - C:\WINDOWS\System32*.tmp -]

[3 C:\WINDOWS*.tmp files - C:\WINDOWS*.tmp -]

 

========== Files - Modified Within 60 Days ==========

 

[2014-05-31 11:09:00 | 000,000,930 | ---- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job

[2014-05-31 11:08:20 | 000,010,144 | ---- | M] () – C:\WINDOWS\System32\nvAppTimestamps

[2014-05-31 10:49:12 | 000,602,112 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Właściciel\Pulpit\OTL.exe

[2014-05-31 10:37:00 | 000,001,044 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2014-05-31 10:20:10 | 000,000,672 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\Counter-Strike 1.6.lnk

[2014-05-31 10:20:10 | 000,000,645 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\Half-Life.lnk

[2014-05-31 10:20:10 | 000,000,639 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\Half-Life Dedicated Server.lnk

[2014-05-31 08:56:00 | 000,003,090 | ---- | M] () – C:\WINDOWS\tasks\Torntv V9.0-chromeinstaller.job

[2014-05-31 08:56:00 | 000,002,408 | ---- | M] () – C:\WINDOWS\tasks\Torntv V9.0-firefoxinstaller.job

[2014-05-31 08:21:27 | 000,001,040 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2014-05-31 08:21:27 | 000,000,232 | ---- | M] () – C:\WINDOWS\tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job

[2014-05-31 08:21:14 | 000,002,048 | --S- | M] () – C:\WINDOWS\bootstat.dat

[2014-05-30 14:16:09 | 000,007,864 | ---- | M] () – C:\WINDOWS\BRRBCOM.INI

[2014-05-27 15:39:21 | 000,001,739 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Sony PC Companion 2.1.lnk

[2014-05-25 17:12:03 | 000,086,743 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\tumblr_memecedghC1r99egpo1_500.jpg

[2014-05-24 10:41:35 | 000,001,819 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk

[2014-05-23 16:08:09 | 000,001,455 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\YAC.lnk

[2014-05-23 16:01:32 | 011,568,296 | ---- | M] (Elex do Brasil Participações Ltda) – C:\Documents and Settings\Właściciel\Pulpit\yet_another_cleaner_sk.exe

[2014-05-22 12:42:56 | 000,038,912 | ---- | M] (Elex do Brasil Participações Ltda) – C:\WINDOWS\System32\drivers\iSafeKrnlBoot.sys

[2014-05-21 18:24:58 | 000,001,837 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Whiteboard Enhancer.lnk

[2014-05-21 18:24:58 | 000,001,829 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\BookScan Enhancer.lnk

[2014-05-21 18:16:34 | 000,000,000 | RHS- | M] () – C:\WINDOWS\FFSSET.BIN

[2014-05-21 17:59:22 | 000,001,664 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\OmniJoin — okres próbny.lnk

[2014-05-21 17:59:19 | 000,001,781 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Brother Creative Center.lnk

[2014-05-21 17:59:13 | 000,007,817 | ---- | M] () – C:\WINDOWS\BROPJ105.INI

[2014-05-21 15:47:00 | 000,000,276 | ---- | M] () – C:\WINDOWS\tasks\DriverDoc_UPDATES.job

[2014-05-15 12:13:29 | 000,209,363 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\kon-mustang-ford-kontra.jpeg

[2014-05-15 12:11:56 | 000,000,490 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\url.htm

[2014-05-13 21:10:39 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe

[2014-05-13 21:10:39 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl

[2014-05-12 18:32:17 | 000,000,226 | ---- | M] () – C:\WINDOWS\tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job

[2014-05-12 10:04:23 | 000,000,732 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\AVG 2014.lnk

[2014-05-12 09:56:19 | 000,271,784 | ---- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT

[2014-05-12 07:35:28 | 000,001,374 | ---- | M] () – C:\WINDOWS\imsins.BAK

[2014-05-12 07:34:39 | 000,559,454 | ---- | M] () – C:\WINDOWS\System32\perfh015.dat

[2014-05-12 07:34:39 | 000,496,946 | ---- | M] () – C:\WINDOWS\System32\perfh009.dat

[2014-05-12 07:34:39 | 000,106,518 | ---- | M] () – C:\WINDOWS\System32\perfc015.dat

[2014-05-12 07:34:39 | 000,085,430 | ---- | M] () – C:\WINDOWS\System32\perfc009.dat

[2014-05-05 12:37:24 | 000,061,952 | ---- | M] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2014-04-30 10:12:53 | 006,022,144 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll

[2014-04-30 08:49:08 | 000,000,250 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Your Software Deals.url

[2014-04-26 18:34:03 | 000,001,210 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\Speed Test.lnk

[2014-04-26 18:33:37 | 000,001,184 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\Free Games.lnk

[2014-04-24 16:54:04 | 000,000,724 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk

[2014-04-24 16:53:41 | 000,001,492 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Opera.lnk

[2014-04-18 15:02:04 | 000,199,960 | ---- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgidsdriverx.sys

[2014-04-16 21:27:30 | 000,282,233 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\photo.htm

[2014-04-16 11:22:34 | 000,083,654 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\29584622_F_20008576_04_14_F.pdf

[2014-04-09 23:21:56 | 002,236,416 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\DirectX_11_Sciagnij.pl.exe

[2014-04-09 22:37:20 | 002,236,416 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\Sterowniki_Intel_HD_Graphics_Driver_dla_Windows_7_i_8_x64_Sciagnij.pl.exe

[2014-04-06 20:34:06 | 028,266,496 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\ChomikBox.msi

[2014-04-05 10:31:14 | 000,000,664 | ---- | M] () – C:\WINDOWS\System32\d3d9caps.dat

[2014-04-03 21:06:41 | 000,149,080 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\ciąg arytmetyczny-zadania info cz.1.pdf

[2014-04-01 19:37:42 | 000,116,434 | ---- | M] () – C:\Documents and Settings\Właściciel\Pulpit\2.jpg

[7 C:\WINDOWS\System32*.tmp files - C:\WINDOWS\System32*.tmp -]

[3 C:\WINDOWS*.tmp files - C:\WINDOWS*.tmp -]

 

========== Files Created - No Company Name ==========

 

[2014-05-31 09:48:41 | 000,000,672 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\Counter-Strike 1.6.lnk

[2014-05-31 08:50:51 | 000,000,645 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\Half-Life.lnk

[2014-05-31 08:50:51 | 000,000,639 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\Half-Life Dedicated Server.lnk

[2014-05-25 17:12:03 | 000,086,743 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\tumblr_memecedghC1r99egpo1_500.jpg

[2014-05-23 16:08:09 | 000,001,455 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\YAC.lnk

[2014-05-21 18:24:58 | 000,001,837 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\Whiteboard Enhancer.lnk

[2014-05-21 18:24:58 | 000,001,829 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\BookScan Enhancer.lnk

[2014-05-21 18:16:34 | 000,000,000 | RHS- | C] () – C:\WINDOWS\FFSSET.BIN

[2014-05-21 17:59:22 | 000,001,664 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\OmniJoin — okres próbny.lnk

[2014-05-21 17:59:19 | 000,001,781 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\Brother Creative Center.lnk

[2014-05-21 17:56:27 | 000,007,864 | ---- | C] () – C:\WINDOWS\BRRBCOM.INI

[2014-05-21 17:56:27 | 000,007,817 | ---- | C] () – C:\WINDOWS\BROPJ105.INI

[2014-05-21 17:49:33 | 000,000,114 | ---- | C] () – C:\WINDOWS\System32\BRLMW03A.INI

[2014-05-21 17:49:32 | 000,045,056 | ---- | C] () – C:\WINDOWS\System32\BRTCPCON.DLL

[2014-05-15 12:13:29 | 000,209,363 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\kon-mustang-ford-kontra.jpeg

[2014-05-15 12:11:55 | 000,000,490 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\url.htm

[2014-05-12 09:56:42 | 000,000,232 | ---- | C] () – C:\WINDOWS\tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job

[2014-05-12 09:56:42 | 000,000,226 | ---- | C] () – C:\WINDOWS\tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job

[2014-04-30 08:49:08 | 000,000,250 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\Your Software Deals.url

[2014-04-26 18:34:03 | 000,001,210 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\Speed Test.lnk

[2014-04-26 18:33:37 | 000,001,184 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\Free Games.lnk

[2014-04-16 21:27:30 | 000,282,233 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\photo.htm

[2014-04-16 11:22:34 | 000,083,654 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\29584622_F_20008576_04_14_F.pdf

[2014-04-09 23:21:51 | 002,236,416 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\DirectX_11_Sciagnij.pl.exe

[2014-04-09 22:36:51 | 002,236,416 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\Sterowniki_Intel_HD_Graphics_Driver_dla_Windows_7_i_8_x64_Sciagnij.pl.exe

[2014-04-06 20:30:07 | 028,266,496 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\ChomikBox.msi

[2014-04-03 21:06:40 | 000,149,080 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\ciąg arytmetyczny-zadania info cz.1.pdf

[2014-04-01 19:37:42 | 000,116,434 | ---- | C] () – C:\Documents and Settings\Właściciel\Pulpit\2.jpg

[2014-03-21 23:41:17 | 000,122,884 | ---- | C] () – C:\WINDOWS\UnGins.exe

[2014-03-18 22:30:00 | 000,126,976 | ---- | C] () – C:\WINDOWS\System32\coclassfast.dll

[2014-02-23 21:55:38 | 000,114,688 | ---- | C] () – C:\WINDOWS\System32\WLANUTL.dll

[2014-02-14 19:44:58 | 000,170,496 | ---- | C] () – C:\WINDOWS\APCBTUn.exe

[2014-02-14 19:44:58 | 000,000,104 | ---- | C] () – C:\WINDOWS\APCBT.ini

[2014-01-22 23:33:57 | 000,000,038 | ---- | C] () – C:\WINDOWS\avisplitter.ini

[2014-01-22 23:33:56 | 000,644,608 | ---- | C] () – C:\WINDOWS\System32\xvidcore.dll

[2014-01-22 23:33:56 | 000,243,200 | ---- | C] () – C:\WINDOWS\System32\xvidvfw.dll

[2013-12-31 21:19:02 | 000,000,148 | ---- | C] () – C:\Documents and Settings\Właściciel\Video.lnk

[2013-12-31 21:19:02 | 000,000,148 | ---- | C] () – C:\Documents and Settings\Właściciel\Pictures.lnk

[2013-12-31 21:19:02 | 000,000,148 | ---- | C] () – C:\Documents and Settings\Właściciel\Passwords.lnk

[2013-12-31 21:19:02 | 000,000,148 | ---- | C] () – C:\Documents and Settings\Właściciel\New Folder.lnk

[2013-12-31 21:19:02 | 000,000,148 | ---- | C] () – C:\Documents and Settings\Właściciel\Music.lnk

[2013-12-31 21:19:02 | 000,000,148 | ---- | C] () – C:\Documents and Settings\Właściciel\Documents.lnk

[2013-12-14 09:21:09 | 001,311,744 | ---- | C] () – C:\WINDOWS\is-ILVAP.exe

[2013-12-02 22:49:37 | 000,269,198 | ---- | C] () – C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-842925246-1500820517-682003330-1003-0.dat

[2013-12-02 22:49:36 | 000,269,198 | ---- | C] () – C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat

[2013-11-11 15:00:52 | 001,127,092 | ---- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin

[2013-11-11 15:00:52 | 001,127,092 | ---- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin

[2013-11-11 15:00:52 | 000,000,001 | ---- | C] () – C:\WINDOWS\System32\nvdrssel.bin

[2013-11-11 14:54:51 | 003,555,144 | ---- | C] () – C:\WINDOWS\System32\nvdata.data

[2013-11-09 20:26:07 | 000,003,072 | ---- | C] () – C:\WINDOWS\System32\iacenc.dll

[2013-10-27 22:52:33 | 000,000,664 | ---- | C] () – C:\WINDOWS\System32\d3d9caps.dat

[2013-10-15 15:53:23 | 000,124,420 | ---- | C] () – C:\WINDOWS\HPHins15.dat

[2013-10-15 15:53:23 | 000,002,885 | ---- | C] () – C:\WINDOWS\hphmdl15.dat

[2013-10-04 22:30:57 | 000,175,616 | ---- | C] () – C:\WINDOWS\System32\unrar.dll

[2013-10-04 21:25:07 | 000,061,952 | ---- | C] () – C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2013-10-04 21:14:55 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe

[2013-10-04 00:27:49 | 000,004,293 | ---- | C] () – C:\WINDOWS\ODBCINST.INI

[2013-10-04 00:25:15 | 000,271,784 | ---- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

[2013-10-03 22:41:03 | 000,002,048 | --S- | C] () – C:\WINDOWS\bootstat.dat

[2013-10-03 22:37:58 | 000,021,856 | ---- | C] () – C:\WINDOWS\System32\emptyregdb.dat

 

========== ZeroAccess Check ==========

 

[2013-10-10 22:39:38 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

 

[HKEY_CURRENT_USER\Software\Classes\clsid{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

 

[HKEY_CURRENT_USER\Software\Classes\clsid{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

 

[HKEY_LOCAL_MACHINE\Software\Classes\clsid{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

“” = %SystemRoot%\system32\shdocvw.dll – [2013-09-23 09:38:58 | 001,510,400 | ---- | M] (Microsoft Corporation)

“ThreadingModel” = Apartment

 

[HKEY_LOCAL_MACHINE\Software\Classes\clsid{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]

“” = C:\WINDOWS\system32\wbem\fastprox.dll – [2009-02-09 12:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation)

“ThreadingModel” = Free

 

[HKEY_LOCAL_MACHINE\Software\Classes\clsid{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

“” = C:\WINDOWS\system32\wbem\wbemess.dll – [2008-04-15 14:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)

“ThreadingModel” = Both

 

End of report

 

 

Czy da się z tym coś zrobić ? 

Witaj, popraw proszę tytuł tematu tak aby wstępnie informował o problemie, użyj przycisku EDYTUJ , który znajdziesz w prawym dolnym rogu Swojego posta-> następnie skorzystaj z opcji Użyj pełnego edytora. Dziękuję za uwagę.

Tip: Unikaj słów: “problem”, “help”, “pomocy” i.t.p. Tego typu słowa nie spowodują szybszej reakcji a mogą odnieść odwrotny skutek od oczekiwanego, tytuł tematu ma być skróconym opisem Twojego posta- powodzenia.

W panelu sterowania odinstaluj Yet Another Cleaner, Gutscheinmieze Toolbar, PacFunction.

Pobierz i uruchom AdwCleaner Kliknij Szukaj i później Usuń.

Pobierz Farbar Recovery Scan Tool 32-Bit Version

Uruchom FRST i kliknij Scan. Pokaż raport FRST i Addition.

Raporty umieść na http://wklej.org/ i podaj link.

http://wklej.org/id/1378456/    <----- FRST

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

SearchScopes: HKLM - DefaultScope value is missing.
Toolbar: HKLM - No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File
Toolbar: HKCU - No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File
FF DefaultSearchEngine: foxsearch
FF SearchEngineOrder.1: foxsearch
FF SelectedSearchEngine: foxsearch
FF Extension: Widget context - C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi [2014-04-25]
S1 fubtixui; \??\C:\WINDOWS\system32\drivers\fubtixui.sys [X]
S4 IntelIde; No ImagePath
S3 PCANDIS5; \??\C:\WINDOWS\system32\PCANDIS5.SYS [X]
C:\AdwCleaner
C:\Documents and Settings\Właściciel\Ustawienia lokalne\Temp\*.exe
Task: C:\WINDOWS\Tasks\DriverDoc_UPDATES.job => C:\Program Files\DriverDoc\Solvusoftdd.exe
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f

Uruchom FRST i kliknij Fix. Pokaż raport z usuwania Fixlog.

Kliknij Scan i pokaż nowy raport z FRST bez Addition.

Fixlog: http://wklej.org/id/1378496/

Skasuj folder C:\FRST

Wyłącz i ponownie włącz przywracanie systemu:

http://support.microsoft.com/kb/310405/pl

Dysk przeskanuj Malwarebytes Anti-Malware

Podczas instalacji usuń zaznaczenie przy Uruchom okres testowy Malwarebytes Anti-Malware Premium.

http://wstaw.org/m/2014/03/25/2014-03-25_123039.png

Język PL > Settings > General Settings > Language > Polish

Odinstaluj Java 6 Update 22 i Adobe Reader XI.

Zainstaluj Java 7 Update 55 i Adobe Reader XI 11.0.7

Już nic niechcianego nie wyskakuje :smiley: