
# AdwCleaner v3.213 - Log utworzony 24/06/2014 o 19:23:09
# Aktualizacja 23/06/2014 przez Xplode
# System operacyjny : Microsoft Windows XP Dodatek Service Pack 3 (32 bits)
# Użytkownik : Andrzej - ANDRZEJ-1977
# Ścieżka : C:\Documents and Settings\Andrzej\Moje dokumenty\Downloads\adwcleaner_3.213.exe
# Opcja : Usuń
***** [ Usługi ] *****
***** [ Pliki / Foldery ] *****
Folder Usunięto : C:\DOCUME~1\Andrzej\USTAWI~1\Temp\Greener Web
***** [ Skróty ] *****
***** [ Rejestr ] *****
Klucz Usunięto : HKCU\Software\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd
Klucz Usunięto : HKLM\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd
Klucz Usunięto : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B}
Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B}
***** [ Przeglądarki internetowe ] *****
-\\ Internet Explorer v6.0.2900.5512
-\\ Google Chrome v35.0.1916.153
[ Plik : C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\preferences ]
Usunięto [Extension] : bakijjialdiiboeaknfpmflphhmljfkd
Usunięto [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Usunięto [Extension] : flpcjncodpafbgdpnkljologafpionhb
*************************
AdwCleaner[R0].txt - [4421 octets] - [19/06/2014 19:57:52]
AdwCleaner[R1].txt - [1645 octets] - [24/06/2014 19:22:11]
AdwCleaner[S0].txt - [3321 octets] - [19/06/2014 19:58:27]
AdwCleaner[S1].txt - [1547 octets] - [24/06/2014 19:23:09]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1607 octets] ##########
OTL logfile created on: 2014-06-24 19:28:55 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Andrzej\Moje dokumenty\Downloads
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
1023,53 Mb Total Physical Memory | 581,61 Mb Available Physical Memory | 56,82% Memory free
2,40 Gb Paging File | 2,05 Gb Available in Paging File | 85,19% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97,66 Gb Total Space | 80,67 Gb Free Space | 82,60% Space Free | Partition Type: NTFS
Drive D: | 181,81 Gb Total Space | 161,11 Gb Free Space | 88,61% Space Free | Partition Type: NTFS
Computer Name: ANDRZEJ-1977 | User Name: Andrzej | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2014-06-24 19:28:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Andrzej\Moje dokumenty\Downloads\OTL.exe
PRC - [2014-06-05 15:58:39 | 000,860,488 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2013-05-14 11:50:44 | 000,140,936 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe
PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2014-06-05 15:58:38 | 000,414,536 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\35.0.1916.153\ppgooglenaclpluginchrome.dll
MOD - [2014-06-05 15:58:36 | 004,217,672 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\35.0.1916.153\pdf.dll
MOD - [2014-06-05 15:58:30 | 001,732,424 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\35.0.1916.153\ffmpegsumo.dll
MOD - [2013-05-14 11:50:44 | 000,140,936 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe
MOD - [2006-10-22 12:22:00 | 000,212,992 | ---- | M] () -- C:\WINDOWS\system32\nvapi.dll
[color=#E56717]========== Services (SafeList) ==========[/color]
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2013-05-14 11:50:44 | 000,140,936 | ---- | M] () [Auto | Running] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2008-04-14 00:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2004-08-04 00:31:36 | 000,032,768 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisnic.sys -- (SISNIC)
DRV - [2001-08-17 22:19:34 | 000,040,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\es1371mp.sys -- (es1371)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.bing.com/search?q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/search?q={searchTerms}
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-842925246-789336058-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKU\S-1-5-21-842925246-789336058-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-842925246-789336058-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-842925246-789336058-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-21-842925246-789336058-839522115-1003\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-842925246-789336058-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
[color=#E56717]========== Chrome ==========[/color]
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: https://www.google.pl/
CHR - plugin: Error reading preferences file
CHR - Extension: Dysk Google = C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Szukaj w Google = C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock = C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.7.1_0\
CHR - Extension: Google Wallet = C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2001-10-26 17:45:16 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [CanonQuickMenu] C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-842925246-789336058-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CDCECC24-A6F4-4D18-941D-2CF489B5D08B}: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2014-04-23 19:06:58 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2014-06-24 19:09:53 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
[2014-06-24 19:09:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes Anti-Malware
[2014-06-24 19:09:23 | 000,053,208 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2014-06-24 19:09:23 | 000,023,256 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2014-06-24 19:09:23 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2014-06-24 19:09:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
[2014-06-24 19:00:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\McAfee
[2014-06-19 21:10:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrzej\Pulpit\Nowy folder
[2014-06-19 19:58:11 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\WINDOWS\System32\sqlite3.dll
[2014-06-19 19:57:50 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014-06-19 13:00:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrzej\Pulpit\DCIM1
[2014-06-19 13:00:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrzej\Pulpit\DCIM2
[2014-06-19 12:36:12 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Andrzej\Pulpit\Programy
[2014-06-19 11:33:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Wisdom-soft
[2014-06-19 11:32:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrzej\Menu Start\Programy\Wisdom-soft ScreenHunter 6 Free
[2014-06-19 11:32:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Wisdom-soft ScreenHunter 6 Free
[2014-06-19 11:32:26 | 000,000,000 | ---D | C] -- C:\Program Files\Wisdom-soft ScreenHunter 6.0 Free
[2014-06-15 18:41:02 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJEGV
[2014-06-15 18:36:07 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJMyPrinter
[2014-06-15 17:53:41 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJMIG
[2014-06-15 17:49:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrzej\Dane aplikacji\Unity
[2014-06-02 21:27:30 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJScan
[2014-06-02 21:25:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrzej\Dane aplikacji\Canon
[2014-06-02 21:25:45 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJQuickMenu
[2014-06-02 21:16:19 | 000,321,536 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNC_BUL.dll
[2014-06-02 21:16:19 | 000,262,656 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNC_BUC.dll
[2014-06-02 21:16:19 | 000,096,768 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNC_BUI.dll
[2014-06-02 21:16:19 | 000,015,872 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNHMCA.dll
[2014-06-02 21:16:18 | 000,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbscan.sys
[2014-06-02 21:16:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Rejestracja użytkownika drukarki Canon MG5500 series
[2014-06-02 21:15:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJWSpt
[2014-06-02 21:09:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Canon Utilities
[2014-06-02 21:09:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Canon MG5500 series Manual
[2014-06-02 21:08:51 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonBJ
[2014-06-02 21:08:43 | 000,317,952 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNMLMBU.DLL
[2014-06-02 21:08:32 | 000,000,000 | -H-D | C] -- C:\Program Files\CanonBJ
[2014-06-02 21:08:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Adobe
[2014-06-02 21:08:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrzej\Dane aplikacji\Adobe
[2014-06-02 21:07:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2014-06-02 21:07:25 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2014-06-02 21:07:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Adobe
[2014-06-02 21:03:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\assembly
[2014-06-02 21:03:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2014-06-02 21:03:07 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2014-06-02 21:03:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2014-06-02 21:01:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJPLM
[2014-06-02 21:01:47 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJETV
[2014-06-02 21:01:17 | 000,000,000 | ---D | C] -- C:\Program Files\Canon
[2014-06-02 21:01:11 | 000,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbprint.sys
[2014-06-02 21:00:54 | 000,032,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbccgp.sys
[2014-05-29 21:32:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Unity
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2014-06-24 19:28:41 | 000,001,038 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014-06-24 19:28:00 | 000,001,034 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014-06-24 19:24:17 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2014-06-24 19:24:12 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014-06-24 19:24:11 | 1073,319,936 | -HS- | M] () -- C:\hiberfil.sys
[2014-06-24 19:10:13 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
[2014-06-24 19:09:27 | 000,000,777 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk
[2014-06-24 18:58:23 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2014-06-19 12:50:11 | 000,005,632 | ---- | M] () -- C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014-06-15 18:42:30 | 000,001,819 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk
[2014-06-15 18:41:17 | 001,247,354 | ---- | M] () -- C:\Documents and Settings\Andrzej\Moje dokumenty\IMG_20140615_0006.pdf
[2014-06-15 18:23:48 | 001,289,579 | ---- | M] () -- C:\Documents and Settings\Andrzej\Moje dokumenty\IMG_20140615_0005.pdf
[2014-06-15 18:22:30 | 001,297,830 | ---- | M] () -- C:\Documents and Settings\Andrzej\Moje dokumenty\IMG_20140615_0004.pdf
[2014-06-15 18:05:48 | 001,259,247 | ---- | M] () -- C:\Documents and Settings\Andrzej\Moje dokumenty\IMG_20140615_0003.pdf
[2014-06-15 17:55:07 | 001,292,189 | ---- | M] () -- C:\Documents and Settings\Andrzej\Moje dokumenty\IMG_20140615_0002.pdf
[2014-06-15 17:53:11 | 000,065,001 | ---- | M] () -- C:\Documents and Settings\Andrzej\Moje dokumenty\IMG_20140615_0001.pdf
[2014-06-02 21:07:04 | 000,460,164 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2014-06-02 21:07:04 | 000,405,148 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2014-06-02 21:07:04 | 000,067,922 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2014-06-02 21:07:04 | 000,054,492 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2014-06-24 19:09:27 | 000,000,777 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk
[2014-06-15 18:41:03 | 001,247,354 | ---- | C] () -- C:\Documents and Settings\Andrzej\Moje dokumenty\IMG_20140615_0006.pdf
[2014-06-15 18:23:44 | 001,289,579 | ---- | C] () -- C:\Documents and Settings\Andrzej\Moje dokumenty\IMG_20140615_0005.pdf
[2014-06-15 18:22:24 | 001,297,830 | ---- | C] () -- C:\Documents and Settings\Andrzej\Moje dokumenty\IMG_20140615_0004.pdf
[2014-06-15 18:05:43 | 001,259,247 | ---- | C] () -- C:\Documents and Settings\Andrzej\Moje dokumenty\IMG_20140615_0003.pdf
[2014-06-15 17:55:02 | 001,292,189 | ---- | C] () -- C:\Documents and Settings\Andrzej\Moje dokumenty\IMG_20140615_0002.pdf
[2014-06-15 17:53:07 | 000,065,001 | ---- | C] () -- C:\Documents and Settings\Andrzej\Moje dokumenty\IMG_20140615_0001.pdf
[2014-06-02 21:29:37 | 000,330,567 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-842925246-789336058-839522115-1003-0.dat
[2014-06-02 21:29:37 | 000,083,246 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat
[2014-06-02 21:16:19 | 000,095,744 | ---- | C] () -- C:\WINDOWS\System32\CNC1771D.TBL
[2014-06-02 21:07:34 | 000,002,347 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk
[2014-04-29 11:54:24 | 000,005,632 | ---- | C] () -- C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014-04-23 19:19:41 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2014-04-23 19:18:41 | 000,095,072 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2014-04-23 19:09:03 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2014-04-23 19:03:51 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[color=#E56717]========== ZeroAccess Check ==========[/color]
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008-04-14 22:50:48 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2008-04-14 22:50:32 | 000,472,064 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-14 22:50:58 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[color=#E56717]========== LOP Check ==========[/color]
[2014-06-02 21:08:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonBJ
[2014-06-15 18:41:02 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJEGV
[2014-06-02 21:01:47 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJETV
[2014-06-15 18:06:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJMIG
[2014-06-15 18:36:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJMyPrinter
[2014-06-15 18:49:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJPLM
[2014-06-02 21:25:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJQuickMenu
[2014-06-02 21:27:30 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJScan
[2014-06-02 21:15:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJWSpt
[2014-06-15 17:47:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrzej\Dane aplikacji\Canon
[2014-04-29 11:31:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrzej\Dane aplikacji\PhotoScape
[2014-06-15 17:49:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrzej\Dane aplikacji\Unity
[color=#E56717]========== Purity Check ==========[/color]
< End of report >
Users shortcut scan result (x86) Version:22-06-2014
Ran by Andrzej at 2014-06-24 19:36:26
Running from C:\Documents and Settings\Andrzej\Moje dokumenty\Downloads
Boot Mode: Normal
==================== Shortcuts =============================
Shortcut: C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Windows Update.lnk -> C:\WINDOWS\system32\wupdmgr.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk -> C:\WINDOWS\Installer\{AC76BA86-7AD7-1045-7B44-AB0000000001}\SC_Reader.ico ()
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Windows Messenger.lnk -> C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Windows Movie Maker.lnk -> C:\Program Files\Movie Maker\moviemk.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Wisdom-soft ScreenHunter 6 Free\ScreenHunter 6.0 Free.lnk -> C:\Program Files\Wisdom-soft ScreenHunter 6.0 Free\ScreenHunter.exe (Wisdom Software Inc. )
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Rejestracja użytkownika drukarki Canon MG5500 series\Rejestracja użytkownika.LNK -> C:\Program Files\Canon\IJEREG\MG5500 series\IJEREG.exe (CANON INC.)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Narzędzia administracyjne\Usługi składowe.lnk -> C:\WINDOWS\system32\Com\comexp.msc ()
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Narzędzia administracyjne\Źródła danych (ODBC).lnk -> C:\WINDOWS\system32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes Anti-Malware\Deinstalacja programu Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes Anti-Malware\unins000.exe ()
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk -> C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm ()
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Gry\FreeCell.lnk -> C:\WINDOWS\system32\freecell.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Gry\Internetowa gra Backgammon.lnk -> C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Gry\Internetowa gra Kierki.lnk -> C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Gry\Internetowa gra Piki.lnk -> C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Gry\Internetowa gra Reversi.lnk -> C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Gry\Internetowa gra Warcaby.lnk -> C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Gry\Kierki.lnk -> C:\WINDOWS\system32\mshearts.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Gry\Pasjans - Pająk.lnk -> C:\WINDOWS\system32\spider.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Gry\Pasjans.lnk -> C:\WINDOWS\system32\sol.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Gry\Pinball.lnk -> C:\Program Files\Windows NT\Pinball\pinball.exe (Cinematronics)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Gry\Saper.lnk -> C:\WINDOWS\system32\winmine.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Google Chrome\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Canon Utilities\Quick Menu\Quick Menu.lnk -> C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE (CANON INC.)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Canon Utilities\My Image Garden\My Image Garden.lnk -> C:\Program Files\Canon\My Image Garden\cnmigmain.exe (CANON INC.)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Canon Utilities\IJ Scan Utility\IJ Scan Utility.lnk -> C:\Program Files\Canon\IJ Scan Utility\SCANUTILITY.exe (CANON INC.)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Kalkulator.lnk -> C:\WINDOWS\system32\calc.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Paint.lnk -> C:\WINDOWS\system32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Podłączanie pulpitu zdalnego.lnk -> C:\WINDOWS\system32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\WordPad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Ułatwienia dostępu\Kreator ułatwień dostępu.lnk -> C:\WINDOWS\system32\accwiz.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Rozrywka\Regulacja głośności.lnk -> C:\WINDOWS\system32\sndvol32.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Rozrywka\Rejestrator dźwięku.lnk -> C:\WINDOWS\system32\sndrec32.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Defragmentator dysków.lnk -> C:\WINDOWS\system32\dfrg.msc ()
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Informacje o systemie.lnk -> C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Kopia zapasowa.lnk -> C:\WINDOWS\system32\ntbackup.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Kreator transferu plików i ustawień.lnk -> C:\WINDOWS\system32\usmt\migwiz.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Oczyszczanie dysku.lnk -> C:\WINDOWS\system32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Przywracanie systemu.lnk -> C:\WINDOWS\system32\Restore\rstrui.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Tablica znaków.lnk -> C:\WINDOWS\system32\charmap.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Komunikacja\HyperTerminal.lnk -> C:\Program Files\Windows NT\hypertrm.exe (Hilgraeve, Inc.)
Shortcut: C:\Documents and Settings\Andrzej\Pulpit\Programy\Adobe Reader XI.lnk -> C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
Shortcut: C:\Documents and Settings\Andrzej\Pulpit\Programy\Canon Quick Menu.lnk -> C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE (CANON INC.)
Shortcut: C:\Documents and Settings\Andrzej\Pulpit\Programy\PhotoScape.lnk -> C:\Program Files\PhotoScape\PhotoScape.exe ()
Shortcut: C:\Documents and Settings\Andrzej\Pulpit\Programy\ScreenHunter 6.0 Free.lnk -> C:\Program Files\Wisdom-soft ScreenHunter 6.0 Free\ScreenHunter.exe (Wisdom Software Inc. )
Shortcut: C:\Documents and Settings\Andrzej\Moje dokumenty\Moje obrazy\Przykładowe obrazy.lnk -> C:\Documents and Settings\All Users\Dokumenty\Moje obrazy\Przykładowe obrazy ()
Shortcut: C:\Documents and Settings\Andrzej\Moje dokumenty\Moja muzyka\Przykładowa muzyka.lnk -> C:\Documents and Settings\All Users\Dokumenty\Moja muzyka\Przykładowa muzyka ()
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\ScreenHunter 6.0 Free.lnk -> C:\Program Files\Wisdom-soft ScreenHunter 6.0 Free\ScreenHunter.exe (Wisdom Software Inc. )
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\Outlook Express.lnk -> C:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\Wisdom-soft ScreenHunter 6 Free\ScreenHunter User Guide.lnk -> C:\Program Files\Wisdom-soft ScreenHunter 6.0 Free\ScreenHunter.chm ()
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\Wisdom-soft ScreenHunter 6 Free\Uninstall.lnk -> C:\Program Files\Wisdom-soft ScreenHunter 6.0 Free\UNWISE.EXE ()
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\HTC Home\Weather.lnk -> C:\Program Files\HTC Home\Weather.exe (No File)
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\Akcesoria\Eksplorator Windows.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\Akcesoria\Książka adresowa.lnk -> C:\Program Files\Outlook Express\wab.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\Akcesoria\Notatnik.lnk -> C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\Akcesoria\Samouczek systemu Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\Akcesoria\Synchronizuj.lnk -> C:\WINDOWS\system32\mobsync.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\Akcesoria\Wiersz polecenia.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\Akcesoria\Ułatwienia dostępu\Klawiatura ekranowa.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Andrzej\Menu Start\Programy\Akcesoria\Ułatwienia dostępu\Lupa.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Andrzej\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Documents and Settings\Andrzej\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Uruchom przeglądarkę Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Menu Start\Programy\Akcesoria\Eksplorator Windows.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Menu Start\Programy\Akcesoria\Notatnik.lnk -> C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Menu Start\Programy\Akcesoria\Samouczek systemu Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Menu Start\Programy\Akcesoria\Synchronizuj.lnk -> C:\WINDOWS\system32\mobsync.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Menu Start\Programy\Akcesoria\Wiersz polecenia.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Menu Start\Programy\Akcesoria\Ułatwienia dostępu\Klawiatura ekranowa.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
Shortcut: C:\Documents and Settings\Default User\Menu Start\Programy\Akcesoria\Ułatwienia dostępu\Lupa.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Określ dostęp do programów i ich ustawienia domyślne.lnk -> C:\WINDOWS\system32\control.exe (Microsoft Corporation) -> appwiz.cpl,,3
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Narzędzia administracyjne\Podgląd zdarzeń.lnk -> C:\WINDOWS\system32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Narzędzia administracyjne\Usługi.lnk -> C:\WINDOWS\system32\services.msc () -> /s
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Narzędzia administracyjne\Wydajność.lnk -> C:\WINDOWS\system32\perfmon.msc () -> /s
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Narzędzia administracyjne\Zarządzanie komputerem.lnk -> C:\WINDOWS\system32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Narzędzia administracyjne\Zasady zabezpieczeń lokalnych.lnk -> C:\WINDOWS\system32\secpol.msc () -> /s
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Canon Utilities\My Printer\My Printer.lnk -> C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) -> /mn
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Canon MG5500 series Manual\Canon MG5500 series Podręcznik ekranowy.lnk -> C:\Program Files\Canon\IJ Manual\Easy Guide Viewer\cmview.exe (CANON INC.) -> "C:\PROGRAM FILES\Canon\IJ Manual\CANON MG5500 SERIES\Polish\Info.egv"
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Scanner and Camera Wizard.lnk -> C:\WINDOWS\system32\wiaacmgr.exe (Microsoft Corporation) -> -SelectDevice
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Zaplanowane zadania.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{21EC2020-3AEA-1069-A2DD-08002B30309D}\::{D6277990-4C6A-11CF-8D87-00AA0060F5BF}
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Komunikacja\Kreator konfiguracji sieci.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> hnetwiz.dll,HomeNetWizardRunDll
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Komunikacja\Kreator nowego połączenia.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> netshell.dll,StartNCW
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Komunikacja\Kreator sieci bezprzewodowej.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> shell32.dll,Control_RunDLL NetSetup.cpl,@0,WNSW
ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria\Komunikacja\Połączenia sieciowe.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{21EC2020-3AEA-1069-A2DD-08002B30309D}\::{7007acc7-3202-11d1-aad2-00805fc1270e}
ShortcutWithArgument: C:\Documents and Settings\Andrzej\Menu Start\Programy\Pomoc zdalna.lnk -> C:\WINDOWS\system32\rcimlby.exe (Microsoft Corporation) -> -LaunchRA
ShortcutWithArgument: C:\Documents and Settings\Andrzej\Menu Start\Programy\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\Documents and Settings\Andrzej\Menu Start\Programy\Akcesoria\Ułatwienia dostępu\Menedżer narzędzi.lnk -> C:\WINDOWS\system32\utilman.exe (Microsoft Corporation) -> /start
ShortcutWithArgument: C:\Documents and Settings\Andrzej\Menu Start\Programy\Akcesoria\Rozrywka\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\Documents and Settings\Default User\Menu Start\Programy\Pomoc zdalna.lnk -> C:\WINDOWS\system32\rcimlby.exe (Microsoft Corporation) -> -LaunchRA
ShortcutWithArgument: C:\Documents and Settings\Default User\Menu Start\Programy\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\Documents and Settings\Default User\Menu Start\Programy\Akcesoria\Ułatwienia dostępu\Menedżer narzędzi.lnk -> C:\WINDOWS\system32\utilman.exe (Microsoft Corporation) -> /start
ShortcutWithArgument: C:\Documents and Settings\Default User\Menu Start\Programy\Akcesoria\Rozrywka\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
InternetURL: C:\Documents and Settings\Andrzej\Ulubione\MSN.com.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=IStart
InternetURL: C:\Documents and Settings\Andrzej\Ulubione\Przewodnik po stacjach radiowych.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=windows&sbp=mediaplayer&plcid=&pver=6.1&os=&over=&olcid=&clcid=&ar=Media&sba=RadioBar&o1=&o2=&o3=
InternetURL: C:\Documents and Settings\Andrzej\Ulubione\Łącza\Bezpłatna usługa pocztowa Hotmail.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=hotmail
InternetURL: C:\Documents and Settings\Andrzej\Ulubione\Łącza\Dostosuj łącza.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=CLinks
InternetURL: C:\Documents and Settings\Andrzej\Ulubione\Łącza\Windows Media.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=windowsmedia
InternetURL: C:\Documents and Settings\Andrzej\Ulubione\Łącza\Windows.url -> hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=windows
==================== End of log =============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version:22-06-2014
Ran by Andrzej at 2014-06-24 19:35:55
Running from C:\Documents and Settings\Andrzej\Moje dokumenty\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
==================== Installed Programs ======================
Adobe Reader XI (11.0.07) - Polish (HKLM\...\{AC76BA86-7AD7-1045-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Canon IJ Scan Utility (HKLM\...\Canon_IJ_Scan_Utility) (Version: - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\...\CANONIJPLM100) (Version: 4.1.0 - Canon Inc.)
Canon MG5500 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5500_series) (Version: 1.01 - Canon Inc.)
Canon MG5500 series On-screen Manual (HKLM\...\Canon MG5500 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
Canon My Image Garden (HKLM\...\Canon My Image Garden) (Version: 2.0.1 - Canon Inc.)
Canon My Image Garden Design Files (HKLM\...\Canon My Image Garden Design Files) (Version: 2.0.0 - Canon Inc.)
Canon My Printer (HKLM\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
Canon Quick Menu (HKLM\...\CanonQuickMenu) (Version: 2.2.1 - Canon Inc.)
Google Chrome (HKLM\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden
Malwarebytes Anti-Malware wersja 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - )
PhotoScape (HKLM\...\PhotoScape) (Version: - )
Rejestracja użytkownika drukarki Canon MG5500 series (HKLM\...\Rejestracja użytkownika drukarki Canon MG5500 series) (Version: - Canon Inc.)
Unity Web Player (HKCU\...\UnityWebPlayer) (Version: 4.5.1f3 - Unity Technologies ApS)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.175805 - Microsoft Corporation)
Wisdom-soft ScreenHunter 6.0 Free (HKLM\...\Wisdom-soft ScreenHunter 6.0 Free) (Version: - Wisdom Software Inc.)
==================== Restore Points =========================
23-04-2014 17:12:23 Punkt kontrolny systemu
23-04-2014 17:37:22 Zainstalowano Windows XP Service Pack 3.
10-05-2014 17:50:14 Punkt kontrolny systemu
15-06-2014 18:53:21 Punkt kontrolny systemu
==================== Hosts content: ==========================
2001-10-26 17:45 - 2001-10-26 17:45 - 00000742 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-06-02 21:25 - 2013-05-14 11:50 - 00140936 _____ () C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
2006-10-22 12:22 - 2006-10-22 12:22 - 00212992 _____ () C:\WINDOWS\system32\nvapi.dll
2014-06-15 18:42 - 2014-06-05 15:58 - 04217672 _____ () C:\Program Files\Google\Chrome\Application\35.0.1916.153\pdf.dll
2014-06-15 18:42 - 2014-06-05 15:58 - 00414536 _____ () C:\Program Files\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll
2014-06-15 18:42 - 2014-06-05 15:58 - 01732424 _____ () C:\Program Files\Google\Chrome\Application\35.0.1916.153\ffmpegsumo.dll
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (05/29/2014 09:24:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Aplikacja powodująca błąd au_.exe, wersja 0.0.0.0, moduł powodujący błąd unknown, wersja 0.0.0.0, adres błędu 0x00d791e5.
Przetwarzanie zdarzenia określonego nośnika dla [au_.exe!ws!]
Error: (04/23/2014 07:14:59 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Aplikacja zawieszająca IEXPLORE.EXE, wersja 6.0.2900.2180, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.
System errors:
=============
Error: (06/24/2014 07:19:52 PM) (Source: 0) (EventID: 1) (User: )
Description: 0xC0000001HarddiskVolume1
Microsoft Office Sessions:
=========================
Error: (05/29/2014 09:24:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: au_.exe0.0.0.0unknown0.0.0.000d791e5
Error: (04/23/2014 07:14:59 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE6.0.2900.2180hungapp0.0.0.000000000
==================== Memory info ===========================
Percentage of memory in use: 42%
Total physical RAM: 1023.53 MB
Available physical RAM: 585.64 MB
Total Pagefile: 2462.25 MB
Available Pagefile: 2075.82 MB
Total Virtual: 2047.88 MB
Available Virtual: 1957.12 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:97.66 GB) (Free:80.65 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:181.81 GB) (Free:161.11 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 279 GB) (Disk ID: 00000001)
Partition 1: (Active) - (Size=98 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=182 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:22-06-2014
Ran by Andrzej (administrator) on ANDRZEJ-1977 on 24-06-2014 19:35:22
Running from C:\Documents and Settings\Andrzej\Moje dokumenty\Downloads
Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) OS Language: Polski
Internet Explorer Version 6
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
() C:\Program Files\Canon\IJPLM\ijplmsvc.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvCplDaemon] => C:\WINDOWS\system32\NvCpl.dll [7700480 2006-10-22] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [NvMediaCenter] => C:\WINDOWS\system32\NvMcTray.dll [86016 2006-10-22] (NVIDIA Corporation)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [CanonQuickMenu] => C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE [1282120 2013-05-02] (CANON INC.)
==================== Internet (Whitelisted) ====================
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
Toolbar: HKCU - &Adres - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Łącza - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
Chrome:
=======
CHR HomePage: https://www.google.pl/
CHR Extension: (Dysk Google) - C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-23]
CHR Extension: (YouTube) - C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-23]
CHR Extension: (Szukaj w Google) - C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-23]
CHR Extension: (AdBlock) - C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-06-19]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-23]
CHR Extension: (Gmail) - C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-23]
CHR StartMenuInternet: Google Chrome - chrome.exe
========================== Services (Whitelisted) =================
R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
==================== Drivers (Whitelisted) ====================
R3 es1371; C:\WINDOWS\System32\drivers\es1371mp.sys [40704 2001-08-17] (Creative Technology Ltd.)
R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-14] (Microsoft Corporation)
R3 SISNIC; C:\WINDOWS\System32\DRIVERS\sisnic.sys [32768 2004-08-04] (SiS Corporation)
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-24 19:34 - 2014-06-24 19:35 - 00000000 ____D () C:\FRST
2014-06-24 19:09 - 2014-06-24 19:10 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-06-24 19:09 - 2014-06-24 19:09 - 00000777 _____ () C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk
2014-06-24 19:09 - 2014-06-24 19:09 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-24 19:09 - 2014-06-24 19:09 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes Anti-Malware
2014-06-24 19:09 - 2014-06-24 19:09 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
2014-06-24 19:09 - 2014-05-12 07:26 - 00053208 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-06-24 19:09 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-06-24 19:00 - 2014-06-24 19:00 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\McAfee
2014-06-19 21:10 - 2014-06-19 21:16 - 00000000 ____D () C:\Documents and Settings\Andrzej\Pulpit\Nowy folder
2014-06-19 19:58 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\system32\sqlite3.dll
2014-06-19 19:57 - 2014-06-24 19:23 - 00000000 ____D () C:\AdwCleaner
2014-06-19 13:00 - 2014-06-19 13:01 - 00000000 ____D () C:\Documents and Settings\Andrzej\Pulpit\DCIM1
2014-06-19 13:00 - 2014-06-19 13:00 - 00000000 ____D () C:\Documents and Settings\Andrzej\Pulpit\DCIM2
2014-06-19 12:36 - 2014-06-19 12:37 - 00000000 ___RD () C:\Documents and Settings\Andrzej\Pulpit\Programy
2014-06-19 11:33 - 2014-06-19 11:33 - 00000000 ____D () C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Wisdom-soft
2014-06-19 11:32 - 2014-06-19 11:32 - 00001701 _____ () C:\Documents and Settings\Andrzej\Menu Start\ScreenHunter 6.0 Free.lnk
2014-06-19 11:32 - 2014-06-19 11:32 - 00000000 ____D () C:\Program Files\Wisdom-soft ScreenHunter 6.0 Free
2014-06-19 11:32 - 2014-06-19 11:32 - 00000000 ____D () C:\Documents and Settings\Andrzej\Menu Start\Programy\Wisdom-soft ScreenHunter 6 Free
2014-06-19 11:32 - 2014-06-19 11:32 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Wisdom-soft ScreenHunter 6 Free
2014-06-15 18:41 - 2014-06-15 18:41 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJEGV
2014-06-15 18:36 - 2014-06-15 18:36 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJMyPrinter
2014-06-15 17:53 - 2014-06-15 18:06 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJMIG
2014-06-15 17:49 - 2014-06-15 17:49 - 00000000 ____D () C:\Documents and Settings\Andrzej\Dane aplikacji\Unity
2014-06-02 21:29 - 2014-06-19 13:02 - 00330567 _____ () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-842925246-789336058-839522115-1003-0.dat
2014-06-02 21:29 - 2014-06-19 13:02 - 00083246 _____ () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat
2014-06-02 21:27 - 2014-06-02 21:27 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJScan
2014-06-02 21:25 - 2014-06-15 17:47 - 00000000 ____D () C:\Documents and Settings\Andrzej\Dane aplikacji\Canon
2014-06-02 21:25 - 2014-06-02 21:25 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJQuickMenu
2014-06-02 21:16 - 2014-06-02 21:16 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Rejestracja użytkownika drukarki Canon MG5500 series
2014-06-02 21:16 - 2013-02-04 15:10 - 00321536 _____ (CANON INC.) C:\WINDOWS\system32\CNC_BUL.dll
2014-06-02 21:16 - 2012-11-26 12:24 - 00095744 _____ () C:\WINDOWS\system32\CNC1771D.TBL
2014-06-02 21:16 - 2012-11-08 13:03 - 00262656 _____ (CANON INC.) C:\WINDOWS\system32\CNC_BUC.dll
2014-06-02 21:16 - 2012-11-08 13:02 - 00096768 _____ (CANON INC.) C:\WINDOWS\system32\CNC_BUI.dll
2014-06-02 21:16 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\WINDOWS\system32\CNHMCA.dll
2014-06-02 21:16 - 2008-04-14 00:15 - 00015104 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbscan.sys
2014-06-02 21:16 - 2008-04-14 00:15 - 00015104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbscan.sys
2014-06-02 21:15 - 2014-06-02 21:15 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJWSpt
2014-06-02 21:09 - 2014-06-02 21:17 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Canon Utilities
2014-06-02 21:09 - 2014-06-02 21:09 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Canon MG5500 series Manual
2014-06-02 21:08 - 2014-06-02 21:08 - 00000000 ___HD () C:\Program Files\CanonBJ
2014-06-02 21:08 - 2014-06-02 21:08 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonBJ
2014-06-02 21:08 - 2014-06-02 21:08 - 00000000 ____D () C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Adobe
2014-06-02 21:08 - 2014-06-02 21:08 - 00000000 ____D () C:\Documents and Settings\Andrzej\Dane aplikacji\Adobe
2014-06-02 21:08 - 2013-04-04 05:00 - 00317952 _____ (CANON INC.) C:\WINDOWS\system32\CNMLMBU.DLL
2014-06-02 21:07 - 2014-06-02 21:15 - 00002347 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk
2014-06-02 21:07 - 2014-06-02 21:09 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Adobe
2014-06-02 21:07 - 2014-06-02 21:07 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-06-02 21:07 - 2014-06-02 21:07 - 00000000 ____D () C:\Program Files\Adobe
2014-06-02 21:03 - 2014-06-02 21:15 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-06-02 21:03 - 2014-06-02 21:03 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-06-02 21:01 - 2014-06-15 18:49 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJPLM
2014-06-02 21:01 - 2014-06-02 21:17 - 00000000 ____D () C:\Program Files\Canon
2014-06-02 21:01 - 2014-06-02 21:01 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJETV
2014-06-02 21:01 - 2008-04-14 00:17 - 00025856 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbprint.sys
2014-06-02 21:01 - 2008-04-14 00:17 - 00025856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbprint.sys
2014-06-02 21:00 - 2008-04-14 00:15 - 00032128 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbccgp.sys
2014-06-02 21:00 - 2008-04-14 00:15 - 00032128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2014-05-29 21:32 - 2014-05-29 21:34 - 00000000 ____D () C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Unity
==================== One Month Modified Files and Folders =======
2014-06-24 19:35 - 2014-06-24 19:34 - 00000000 ____D () C:\FRST
2014-06-24 19:35 - 2014-04-23 19:12 - 00000000 ____D () C:\Documents and Settings\Andrzej\Ustawienia lokalne\Temp
2014-06-24 19:30 - 2014-04-23 19:05 - 00044064 _____ () C:\WINDOWS\WindowsUpdate.log
2014-06-24 19:28 - 2014-04-23 19:17 - 00001038 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-24 19:28 - 2014-04-23 19:17 - 00001034 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-24 19:24 - 2014-04-23 19:22 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-06-24 19:24 - 2014-04-23 19:22 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-06-24 19:24 - 2014-04-23 19:15 - 00088566 _____ () C:\WINDOWS\system32\nvapps.xml
2014-06-24 19:24 - 2014-04-23 19:10 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-06-24 19:23 - 2014-06-19 19:57 - 00000000 ____D () C:\AdwCleaner
2014-06-24 19:23 - 2014-04-23 19:12 - 00000188 ___SH () C:\Documents and Settings\Andrzej\ntuser.ini
2014-06-24 19:23 - 2014-04-23 19:10 - 00023684 _____ () C:\WINDOWS\SchedLgU.Txt
2014-06-24 19:19 - 2014-04-23 19:05 - 00000000 ___RD () C:\WINDOWS\Offline Web Pages
2014-06-24 19:18 - 2014-04-23 19:12 - 00000000 ___HD () C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji
2014-06-24 19:10 - 2014-06-24 19:09 - 00110296 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-06-24 19:09 - 2014-06-24 19:09 - 00000777 _____ () C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk
2014-06-24 19:09 - 2014-06-24 19:09 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-24 19:09 - 2014-06-24 19:09 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes Anti-Malware
2014-06-24 19:09 - 2014-06-24 19:09 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
2014-06-24 19:09 - 2014-04-23 19:19 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy
2014-06-24 19:09 - 2014-04-23 19:19 - 00000000 ____D () C:\Documents and Settings\All Users\Pulpit
2014-06-24 19:09 - 2014-04-23 19:18 - 00000000 __RHD () C:\Documents and Settings\All Users\Dane aplikacji
2014-06-24 19:00 - 2014-06-24 19:00 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\McAfee
2014-06-24 18:58 - 2001-07-22 00:17 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2014-06-19 21:16 - 2014-06-19 21:10 - 00000000 ____D () C:\Documents and Settings\Andrzej\Pulpit\Nowy folder
2014-06-19 21:10 - 2014-04-23 19:12 - 00000000 ____D () C:\Documents and Settings\Andrzej\Pulpit
2014-06-19 19:58 - 2014-04-23 19:12 - 00000000 __RHD () C:\Documents and Settings\Andrzej\Dane aplikacji
2014-06-19 13:02 - 2014-06-02 21:29 - 00330567 _____ () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-842925246-789336058-839522115-1003-0.dat
2014-06-19 13:02 - 2014-06-02 21:29 - 00083246 _____ () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat
2014-06-19 13:01 - 2014-06-19 13:00 - 00000000 ____D () C:\Documents and Settings\Andrzej\Pulpit\DCIM1
2014-06-19 13:00 - 2014-06-19 13:00 - 00000000 ____D () C:\Documents and Settings\Andrzej\Pulpit\DCIM2
2014-06-19 12:50 - 2014-04-29 11:54 - 00005632 _____ () C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-19 12:37 - 2014-06-19 12:36 - 00000000 ___RD () C:\Documents and Settings\Andrzej\Pulpit\Programy
2014-06-19 12:26 - 2014-04-23 19:18 - 00335105 _____ () C:\WINDOWS\setupapi.log
2014-06-19 11:33 - 2014-06-19 11:33 - 00000000 ____D () C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Wisdom-soft
2014-06-19 11:32 - 2014-06-19 11:32 - 00001701 _____ () C:\Documents and Settings\Andrzej\Menu Start\ScreenHunter 6.0 Free.lnk
2014-06-19 11:32 - 2014-06-19 11:32 - 00000000 ____D () C:\Program Files\Wisdom-soft ScreenHunter 6.0 Free
2014-06-19 11:32 - 2014-06-19 11:32 - 00000000 ____D () C:\Documents and Settings\Andrzej\Menu Start\Programy\Wisdom-soft ScreenHunter 6 Free
2014-06-19 11:32 - 2014-06-19 11:32 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Wisdom-soft ScreenHunter 6 Free
2014-06-19 11:32 - 2014-04-23 19:12 - 00000000 ___RD () C:\Documents and Settings\Andrzej\Menu Start\Programy
2014-06-19 11:32 - 2014-04-23 19:12 - 00000000 ___RD () C:\Documents and Settings\Andrzej\Menu Start
2014-06-15 18:49 - 2014-06-02 21:01 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJPLM
2014-06-15 18:42 - 2014-04-23 19:18 - 00001819 _____ () C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk
2014-06-15 18:41 - 2014-06-15 18:41 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJEGV
2014-06-15 18:41 - 2014-04-23 19:12 - 00000000 ___RD () C:\Documents and Settings\Andrzej\Moje dokumenty
2014-06-15 18:36 - 2014-06-15 18:36 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJMyPrinter
2014-06-15 18:07 - 2014-04-23 19:12 - 00000000 ___RD () C:\Documents and Settings\Andrzej\Moje dokumenty\Moje obrazy
2014-06-15 18:06 - 2014-06-15 17:53 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJMIG
2014-06-15 17:49 - 2014-06-15 17:49 - 00000000 ____D () C:\Documents and Settings\Andrzej\Dane aplikacji\Unity
2014-06-15 17:47 - 2014-06-02 21:25 - 00000000 ____D () C:\Documents and Settings\Andrzej\Dane aplikacji\Canon
2014-06-02 21:29 - 2014-04-23 19:10 - 00000000 ___HD () C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji
2014-06-02 21:27 - 2014-06-02 21:27 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJScan
2014-06-02 21:25 - 2014-06-02 21:25 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJQuickMenu
2014-06-02 21:17 - 2014-06-02 21:09 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Canon Utilities
2014-06-02 21:17 - 2014-06-02 21:01 - 00000000 ____D () C:\Program Files\Canon
2014-06-02 21:16 - 2014-06-02 21:16 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Rejestracja użytkownika drukarki Canon MG5500 series
2014-06-02 21:16 - 2014-04-23 19:14 - 00000000 ____D () C:\WINDOWS\twain_32
2014-06-02 21:16 - 2014-04-23 19:14 - 00000000 ____D () C:\WINDOWS\Media
2014-06-02 21:16 - 2014-04-23 19:01 - 00000000 ___RD () C:\Documents and Settings\All Users\Menu Start\Programy\Akcesoria
2014-06-02 21:15 - 2014-06-02 21:15 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJWSpt
2014-06-02 21:15 - 2014-06-02 21:07 - 00002347 _____ () C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk
2014-06-02 21:15 - 2014-06-02 21:03 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-06-02 21:09 - 2014-06-02 21:09 - 00000000 ____D () C:\Documents and Settings\All Users\Menu Start\Programy\Canon MG5500 series Manual
2014-06-02 21:09 - 2014-06-02 21:07 - 00000000 ____D () C:\Documents and Settings\All Users\Dane aplikacji\Adobe
2014-06-02 21:08 - 2014-06-02 21:08 - 00000000 ___HD () C:\Program Files\CanonBJ
2014-06-02 21:08 - 2014-06-02 21:08 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonBJ
2014-06-02 21:08 - 2014-06-02 21:08 - 00000000 ____D () C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Adobe
2014-06-02 21:08 - 2014-06-02 21:08 - 00000000 ____D () C:\Documents and Settings\Andrzej\Dane aplikacji\Adobe
2014-06-02 21:07 - 2014-06-02 21:07 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-06-02 21:07 - 2014-06-02 21:07 - 00000000 ____D () C:\Program Files\Adobe
2014-06-02 21:07 - 2014-04-23 19:19 - 00996194 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-06-02 21:07 - 2001-10-26 18:15 - 00460164 _____ () C:\WINDOWS\system32\perfh015.dat
2014-06-02 21:07 - 2001-10-26 18:15 - 00067922 _____ () C:\WINDOWS\system32\perfc015.dat
2014-06-02 21:03 - 2014-06-02 21:03 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-06-02 21:03 - 2014-04-23 19:14 - 00000000 ____D () C:\WINDOWS\system32\mui
2014-06-02 21:01 - 2014-06-02 21:01 - 00000000 ___HD () C:\Documents and Settings\All Users\Dane aplikacji\CanonIJETV
2014-05-29 21:34 - 2014-05-29 21:32 - 00000000 ____D () C:\Documents and Settings\Andrzej\Ustawienia lokalne\Dane aplikacji\Unity
Some content of TEMP:
====================
C:\Documents and Settings\Andrzej\Ustawienia lokalne\Temp\MSETUP4.EXE
C:\Documents and Settings\Andrzej\Ustawienia lokalne\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
C:\Documents and Settings\Andrzej\Ustawienia lokalne\Temp\MSETUP4.EXE
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-21-842925246-789336058-839522115-1003\Software\Microsoft\Internet Explorer\SearchScopes" /f
U1 WS2IFSL;
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
Reboot:
DeleteQuarantine:
A jezeli chodzi o antywirusa to nic nie wykrywa.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:22-06-2014
Ran by Andrzej at 2014-06-24 21:21:53 Run:1
Running from C:\Documents and Settings\Andrzej\Pulpit
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
C:\Documents and Settings\Andrzej\Ustawienia lokalne\Temp\MSETUP4.EXE
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-21-842925246-789336058-839522115-1003\Software\Microsoft\Internet Explorer\SearchScopes" /f
U1 WS2IFSL;
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
Reboot:
*****************
C:\Documents and Settings\Andrzej\Ustawienia lokalne\Temp\MSETUP4.EXE => Moved successfully.
========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f =========
Operacja ukończona pomyślnie
========= End of Reg: =========
========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f =========
Operacja ukończona pomyślnie
========= End of Reg: =========
========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f =========
Operacja ukończona pomyślnie
========= End of Reg: =========
========= reg delete "HKU\S-1-5-21-842925246-789336058-839522115-1003\Software\Microsoft\Internet Explorer\SearchScopes" /f =========
Operacja ukończona pomyślnie
========= End of Reg: =========
WS2IFSL => Service deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck => value deleted successfully.
The system needed a reboot.
==== End of Fixlog ====
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 2 gości