ADVERTISEMENT

FRST.txt

Allegro - strony z aukcjami nie ładują się, kręci się kółko ładowania

Proszę plik FRST.


Download file - link to post

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 07-01-2015
Ran by Rafał (administrator) on RAFAŁ-PC on 07-01-2015 19:38:32
Running from D:\programy
Loaded Profiles: Rafał & (Available profiles: Rafał & Alien & Guest)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Polski (Polska)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Elex do Brasil Participações Ltda) C:\Program Files\Elex-tech\YAC\iSafeSvc.exe
(Elex do Brasil Participações Ltda) C:\Program Files\Elex-tech\YAC\iSafeSvc2.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\ProgramData\685d26dc-c30a-434b-bda2-3004e8743669\maintainer.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Elex do Brasil Participações Ltda) C:\Program Files\Elex-tech\YAC\iSafeTray.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Malwarebytes Corporation) D:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) D:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) D:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [GrooveMonitor] = & gt; C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [SwitchBoard] = & gt; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] = & gt; c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKU\S-1-5-21-2219367604-1025886676-3108875783-1001\...\Run: [EpicScale] = & gt; (the data entry has 824 more characters).
HKU\S-1-5-21-2219367604-1025886676-3108875783-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2219367604-1025886676-3108875783-1001\...\MountPoints2: {19cf91aa-dce2-11e3-8eba-1c6f65feff66} - G:\LGAutoRun.exe
HKU\S-1-5-21-2219367604-1025886676-3108875783-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [EpicScale] = & gt; (the data entry has 824 more characters).
HKU\S-1-5-21-2219367604-1025886676-3108875783-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2219367604-1025886676-3108875783-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {19cf91aa-dce2-11e3-8eba-1c6f65feff66} - G:\LGAutoRun.exe
HKU\S-1-5-21-2219367604-1025886676-3108875783-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {19cf91aa-dce2-11e3-8eba-1c6f65feff66} - G:\LGAutoRun.exe
ShellIconOverlayIdentifiers: [00avast] - & gt; {472083B0-C522-11CF-8763-00608CC02F24} = & gt; No File
GroupPolicy: Group Policy on Chrome detected & lt; ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction & lt; ======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction & lt; ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
SearchScopes: HKLM - & gt; DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM - & gt; {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\.DEFAULT - & gt; DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\.DEFAULT - & gt; {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-19 - & gt; DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-19 - & gt; {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - & gt; DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - & gt; {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-20 - & gt; DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-20 - & gt; {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - & gt; DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - & gt; {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2219367604-1025886676-3108875783-1001 - & gt; DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2219367604-1025886676-3108875783-1001 - & gt; {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2219367604-1025886676-3108875783-1001 - & gt; {6FE07814-AE50-471A-9B9E-25C48D059576} URL = http://rts.dsrlte.com/?q={searchTerms} & r=423
SearchScopes: HKU\S-1-5-21-2219367604-1025886676-3108875783-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - & gt; DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2219367604-1025886676-3108875783-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - & gt; {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2219367604-1025886676-3108875783-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - & gt; {6FE07814-AE50-471A-9B9E-25C48D059576} URL = http://rts.dsrlte.com/?q={searchTerms} & r=423
SearchScopes: HKU\S-1-5-21-2219367604-1025886676-3108875783-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - & gt; DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2219367604-1025886676-3108875783-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - & gt; {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
BHO: CouponDownloader - & gt; {157cfeb3-4476-a848-8994-3968abc578c9} - & gt; C:\Program Files\C78087A8-C960-4464-A618-3D351DF6C0D7\bacgajubob.dll ()
BHO: Adobe PDF Link Helper - & gt; {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - & gt; C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper - & gt; {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - & gt; C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll No File
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Rafał\AppData\Roaming\Mozilla\Firefox\Profiles\ozz3q0xw.default
FF Plugin: @microsoft.com/GENUINE - & gt; disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - & gt; c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - & gt; C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - & gt; C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - & gt; D:\programy\adobe_reader\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2219367604-1025886676-3108875783-1001: @Skype Limited.com/Facebook Video Calling Plugin - & gt; C:\Users\Rafał\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKU\S-1-5-21-2219367604-1025886676-3108875783-1001: @unity3d.com/UnityPlayer,version=1.0 - & gt; C:\Users\Rafał\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2219367604-1025886676-3108875783-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @Skype Limited.com/Facebook Video Calling Plugin - & gt; C:\Users\Rafał\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKU\S-1-5-21-2219367604-1025886676-3108875783-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 - & gt; C:\Users\Rafał\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Users\Rafał\AppData\Roaming\Mozilla\Firefox\Profiles\ozz3q0xw.default\searchplugins\dsrlte.xml
FF SearchPlugin: C:\Users\Rafał\AppData\Roaming\Mozilla\Firefox\Profiles\ozz3q0xw.default\searchplugins\keepmysearch.xml
FF Extension: Fast Start - C:\Users\Rafał\AppData\Roaming\Mozilla\Firefox\Profiles\ozz3q0xw.default\Extensions\1404222125_xpi [2014-07-01]
FF Extension: CouponDownloader - C:\Users\Rafał\AppData\Roaming\Mozilla\Firefox\Profiles\ozz3q0xw.default\Extensions\j004-efxyrmbzyotmaw@jetpack.xpi [2014-07-28]
FF Extension: CouponDownloader - C:\Users\Rafał\AppData\Roaming\Mozilla\Firefox\Profiles\ozz3q0xw.default\Extensions\j004-megggxjuiuogyr@jetpack.xpi [2014-07-08]
FF Extension: Techgile 1.0.1 - C:\Users\Rafał\AppData\Roaming\Mozilla\Firefox\Profiles\ozz3q0xw.default\Extensions\{fb5e64f3-3d3c-4496-8ec2-98c67600e3a5}.xpi [2014-11-30]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-11-28]
FF Extension: No Name - C:\Users\Rafał\AppData\Roaming\Mozilla\Firefox\Profiles\ozz3q0xw.default\extensions\sonnypenn@aol.com [Not Found]

Chrome:
=======
CHR HomePage: Default - & gt; hxxp://google.pl/
CHR StartupUrls: Default - & gt; " https://www.google.pl/ " , " hxxp://www.google.com "
CHR DefaultSearchKeyword: Default - & gt; google
CHR DefaultSuggestURL: Default - & gt;
CHR Profile: C:\Users\Rafał\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Rafał\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-15]
CHR Extension: (Dysk Google) - C:\Users\Rafał\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-15]
CHR Extension: (YouTube) - C:\Users\Rafał\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-15]
CHR Extension: (Szukaj w Google) - C:\Users\Rafał\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-15]
CHR Extension: (AdBlock) - C:\Users\Rafał\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-06-02]
CHR Extension: (Google Wallet) - C:\Users\Rafał\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-15]
CHR Extension: (Gmail) - C:\Users\Rafał\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-15]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 iSafeService; C:\Program Files\Elex-tech\YAC\iSafeSvc.exe [118048 2014-12-04] (Elex do Brasil Participações Ltda)
R2 MaintainerSvc4.29.2173613; C:\ProgramData\685d26dc-c30a-434b-bda2-3004e8743669\maintainer.exe [123632 2015-01-07] ()
R2 MBAMScheduler; D:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; D:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
S3 Origin Client Service; D:\programy\Origin\OriginClientService.exe [1900400 2014-11-25] (Electronic Arts)
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 TeamViewer9; D:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe [4799760 2014-09-12] (TeamViewer GmbH)
S3 wampapache; c:\wamp\bin\apache\apache2.4.4\bin\httpd.exe [22016 2013-06-23] (Apache Software Foundation) [File not signed]
S3 wampmysqld; c:\wamp\bin\mysql\mysql5.6.12\bin\mysqld.exe [10923520 2013-06-23] () [File not signed]
S2 Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [25856 2012-07-03] (Google Inc)
R2 BT848; C:\Windows\System32\drivers\Bt848.sys [163840 2004-07-06] (AVerMedia Technologies, Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-12-01] (Disc Soft Ltd)
R1 iSafeKrnl; C:\Program Files\Elex-tech\YAC\iSafeKrnl.sys [215336 2014-12-04] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlKit; C:\Program Files\Elex-tech\YAC\iSafeKrnlKit.sys [83112 2014-12-04] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlR3; C:\Program Files\Elex-tech\YAC\iSafeKrnlR3.sys [38440 2014-12-04] (Elex do Brasil Participações Ltda)
R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [43688 2014-11-03] (Elex do Brasil Participações Ltda)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-01-07] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R3 phaudlwr; C:\Windows\System32\DRIVERS\phaudlwr.sys [89648 2009-10-20] (Philips Applied Technologies)
R3 SPC520; C:\Windows\System32\drivers\SPC520.sys [483328 2007-10-01] (Philips )
R3 SPC520m; C:\Windows\System32\drivers\SPC520m.sys [7680 2007-10-01] (Philips )
S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X]
S1 netfilter2; system32\drivers\netfilter2.sys [X]
S3 NVNET; system32\DRIVERS\nvmf6232.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-07 19:36 - 2015-01-07 19:36 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-07 19:35 - 2015-01-07 19:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-07 19:34 - 2015-01-07 19:34 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-07 19:34 - 2014-11-21 06:23 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-07 19:34 - 2014-11-21 06:23 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-07 19:34 - 2014-11-21 06:23 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-07 19:32 - 2015-01-07 19:38 - 00000000 ____D () C:\FRST
2015-01-07 19:29 - 2015-01-07 19:29 - 00000000 ____D () C:\Users\Rafał\AppData\Roaming\Elex-tech
2015-01-07 19:22 - 2015-01-07 19:26 - 00000000 ____D () C:\AdwCleaner
2015-01-07 19:07 - 2015-01-07 19:07 - 00002171 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-07 19:07 - 2015-01-07 19:07 - 00001030 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d02aa4c55714b0.job
2015-01-07 19:07 - 2015-01-07 19:07 - 00001030 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-07 19:07 - 2015-01-07 19:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-01-03 16:42 - 2015-01-03 16:43 - 00050902 _____ () C:\Users\Rafał\Desktop\jpg (1).rar
2015-01-03 16:42 - 2015-01-03 16:42 - 00000000 ____D () C:\Users\Rafał\Desktop\jpg (1)
2015-01-02 17:04 - 2015-01-02 17:15 - 00000000 ___RD () C:\Users\Rafał\Documents\skroty
2015-01-02 12:35 - 2015-01-02 12:35 - 00000059 _____ () C:\Users\Rafa
2015-01-02 11:46 - 2015-01-02 11:46 - 07965775 _____ () C:\Users\Rafał\Desktop\cv.rar
2015-01-02 11:41 - 2015-01-02 11:41 - 00000000 ____D () C:\Users\Rafał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AbiWord Word Processor
2015-01-02 11:41 - 2015-01-02 11:41 - 00000000 ____D () C:\Users\Rafał\AbiSuite
2015-01-02 11:41 - 2015-01-02 11:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AbiWord Word Processor
2015-01-02 11:38 - 2015-01-02 11:38 - 08335349 _____ (AbiSource Developers) C:\Users\Rafał\Downloads\abiword-setup-2.8.6.exe
2015-01-02 11:37 - 2015-01-02 11:37 - 02841350 _____ () C:\Users\Rafał\Desktop\10656851_789519587763404_520656627_n.abw
2014-12-27 21:36 - 2014-12-27 21:36 - 00285792 _____ () C:\Windows\msxml4-KB954430-enu.LOG
2014-12-27 21:35 - 2014-12-27 21:36 - 00291168 _____ () C:\Windows\msxml4-KB973688-enu.LOG
2014-12-27 21:35 - 2014-12-27 21:35 - 00000000 ____D () C:\Program Files\MSXML 4.0
2014-12-26 18:46 - 2014-12-26 18:47 - 00001908 _____ () C:\Windows\diagwrn.xml
2014-12-26 18:46 - 2014-12-26 18:47 - 00001908 _____ () C:\Windows\diagerr.xml
2014-12-26 18:25 - 2014-12-26 18:25 - 00000000 ____D () C:\Users\Rafał\Documents\Ashampoo Burning Studio 2015
2014-12-26 18:24 - 2014-12-26 18:24 - 00000000 ____D () C:\Users\Rafał\AppData\Roaming\Ashampoo
2014-12-26 18:24 - 2014-12-26 18:24 - 00000000 ____D () C:\Users\Rafał\AppData\Local\ashampoo
2014-12-26 18:24 - 2014-12-26 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2014-12-26 18:23 - 2014-12-26 18:24 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-12-26 18:16 - 2014-12-26 18:16 - 98327200 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Rafał\Downloads\ashampoo_burning_studio_2015_18299.exe
2014-12-26 15:28 - 2014-12-26 15:28 - 00000000 ____D () C:\Users\Rafał\AppData\Roaming\Nero
2014-12-26 15:18 - 2014-12-29 17:30 - 00000000 ____D () C:\Program Files\Common Files\Nero
2014-12-26 15:18 - 2014-12-29 17:20 - 00000000 ____D () C:\ProgramData\Nero
2014-12-26 15:14 - 2014-12-26 15:14 - 57182136 _____ () C:\Users\Rafał\Downloads\Nero Free 9.4.12.3d [1].exe
2014-12-24 14:31 - 2014-12-24 14:31 - 00000000 ____D () C:\Users\Rafał\Desktop\Nowy folder
2014-12-20 15:05 - 2014-12-20 15:15 - 00000000 ____D () C:\Windows\Minidump
2014-12-20 15:05 - 2014-12-20 15:05 - 210232766 _____ () C:\Windows\MEMORY.DMP
2014-12-18 15:10 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-14 00:13 - 2014-12-14 00:13 - 00001283 _____ () C:\Users\Rafał\AppData\Local\recently-used.xbel
2014-12-11 13:36 - 2014-12-11 13:36 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-10 23:07 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-10 16:40 - 2014-12-10 16:40 - 00000000 ____D () C:\Users\Rafał\Documents\Moje pliki paint.net
2014-12-10 14:55 - 2014-12-04 05:38 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-10 14:55 - 2014-12-04 05:38 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-10 14:55 - 2014-12-04 05:38 - 00337920 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-10 14:55 - 2014-12-04 05:38 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-10 14:55 - 2014-12-04 05:38 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-10 14:55 - 2014-12-04 05:38 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-10 14:55 - 2014-12-04 05:34 - 00873984 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-10 14:55 - 2014-12-02 00:28 - 01160872 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-10 14:55 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-10 14:55 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-10 14:55 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-10 14:55 - 2014-11-22 03:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-10 14:55 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-10 14:55 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-10 14:55 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-10 14:55 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-10 14:55 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-10 14:55 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-10 14:55 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-10 14:55 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-10 14:55 - 2014-11-22 02:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-10 14:55 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-10 14:55 - 2014-11-22 02:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-10 14:55 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-10 14:55 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 14:55 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-10 14:55 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-10 14:55 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-10 14:55 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-10 14:55 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-10 14:55 - 2014-11-22 02:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-10 14:55 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-10 14:55 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-10 14:55 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-10 14:55 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-10 14:55 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-10 14:55 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-10 14:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-10 14:55 - 2014-11-11 02:32 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-10 14:55 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-10 14:55 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-10 14:55 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-10 14:55 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-10 14:55 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-10 14:55 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-10 14:55 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-09 21:22 - 2014-12-09 21:22 - 00000000 ____D () C:\Users\Rafał\AppData\Roaming\inkscape
2014-12-09 21:21 - 2014-12-09 21:21 - 00000689 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inkscape.lnk

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-07 19:37 - 2014-05-15 20:27 - 00000000 ____D () C:\Users\Rafał\AppData\Roaming\foobar2000
2015-01-07 19:36 - 2009-07-14 05:34 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-07 19:36 - 2009-07-14 05:34 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-07 19:35 - 2014-05-15 17:40 - 02047549 _____ () C:\Windows\WindowsUpdate.log
2015-01-07 19:28 - 2014-05-15 17:54 - 01034240 _____ () C:\Windows\PFRO.log
2015-01-07 19:28 - 2009-07-14 05:39 - 00004979 _____ () C:\Windows\setupact.log
2015-01-07 19:07 - 2014-05-15 17:43 - 00000000 ____D () C:\Program Files\Google
2015-01-07 19:02 - 2014-06-02 15:04 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-01-07 17:37 - 2014-11-16 15:11 - 00000000 ____D () C:\ProgramData\685d26dc-c30a-434b-bda2-3004e8743669
2015-01-06 23:13 - 2014-08-25 16:17 - 00000000 ____D () C:\Users\Rafał\AppData\Local\PokerStars.EU
2015-01-06 18:58 - 2014-06-23 18:56 - 00000000 ____D () C:\Users\Rafał\AppData\Roaming\Kadu
2015-01-06 18:58 - 2014-05-16 11:24 - 00000000 ____D () C:\Users\Rafał\AppData\Roaming\TS3Client
2015-01-06 15:24 - 2014-05-15 18:21 - 00000000 ____D () C:\Users\Rafał\AppData\Roaming\Skype
2015-01-05 21:14 - 2014-05-15 17:51 - 00739694 _____ () C:\Windows\system32\perfh015.dat
2015-01-05 21:14 - 2014-05-15 17:51 - 00155268 _____ () C:\Windows\system32\perfc015.dat
2015-01-05 21:14 - 2014-05-15 17:46 - 01668226 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-02 17:37 - 2014-05-23 11:44 - 00000000 ____D () C:\Users\Rafał\AppData\Roaming\FileZilla
2015-01-02 17:14 - 2014-10-07 20:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxthon Cloud Browser
2015-01-02 17:13 - 2014-08-22 15:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6 [cswos.com v8.0]
2015-01-02 11:41 - 2014-05-15 17:41 - 00000000 ____D () C:\Users\Rafał
2014-12-31 12:13 - 2014-05-15 17:46 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-12-26 18:46 - 2009-07-14 05:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-12-24 14:29 - 2009-07-14 05:33 - 03810528 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-23 16:50 - 2014-05-15 17:43 - 00125712 _____ () C:\Users\Rafał\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-23 15:41 - 2014-06-05 14:12 - 00000132 _____ () C:\Users\Rafał\AppData\Roaming\Adobe PNG Format CS5 Prefs
2014-12-22 15:08 - 2014-05-23 11:52 - 00000000 ____D () C:\Users\Rafał\Documents\Aptana Studio 3 Workspace
2014-12-20 14:21 - 2014-05-15 18:21 - 00000000 ___RD () C:\Program Files\Skype
2014-12-20 14:20 - 2014-05-15 18:21 - 00000000 ____D () C:\ProgramData\Skype
2014-12-19 22:58 - 2014-06-24 08:43 - 00000000 ____D () C:\Users\Rafał\AppData\Local\Thunderbird
2014-12-11 13:36 - 2014-05-19 13:43 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-11 13:36 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\pl-PL
2014-12-11 13:36 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\AppCompat
2014-12-10 23:08 - 2014-05-20 19:27 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-10 23:04 - 2014-05-15 18:31 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-10 22:56 - 2014-05-15 18:31 - 109818608 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-09 21:08 - 2014-06-01 17:35 - 00123656 _____ () C:\Users\Alien\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-08 19:41 - 2014-10-06 16:00 - 00000000 ____D () C:\Users\Rafał\AppData\Roaming\TeamViewer

Some content of TEMP:
====================
C:\Users\Alien\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Alien\AppData\Local\Temp\xmlUpdater.exe
C:\Users\Rafał\AppData\Local\Temp\amd-catalyst-14-9-win7-win8.1-32bit-dd-ccc-whql.exe
C:\Users\Rafał\AppData\Local\Temp\AstroburnLite180-0182.exe
C:\Users\Rafał\AppData\Local\Temp\bitool.dll
C:\Users\Rafał\AppData\Local\Temp\drm_dyndata_7380014.dll
C:\Users\Rafał\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp0ywaay.dll
C:\Users\Rafał\AppData\Local\Temp\offer-AA6AFB34-45F5-46B1-9CC2-0587E60CCA91.exe
C:\Users\Rafał\AppData\Local\Temp\offer-C76E8B20-B638-497C-BEC7-606928AD997A.exe
C:\Users\Rafał\AppData\Local\Temp\paint.net.4.0.4.install.exe
C:\Users\Rafał\AppData\Local\Temp\Quarantine.exe
C:\Users\Rafał\AppData\Local\Temp\setup.exe
C:\Users\Rafał\AppData\Local\Temp\sqlite3.dll
C:\Users\Rafał\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Rafał\AppData\Local\Temp\xmlUpdater.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe = & gt; File is digitally signed
C:\Windows\system32\winlogon.exe = & gt; File is digitally signed
C:\Windows\system32\wininit.exe = & gt; File is digitally signed
C:\Windows\system32\svchost.exe = & gt; File is digitally signed
C:\Windows\system32\services.exe = & gt; File is digitally signed
C:\Windows\system32\User32.dll = & gt; File is digitally signed
C:\Windows\system32\userinit.exe = & gt; File is digitally signed
C:\Windows\system32\rpcss.dll = & gt; File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys = & gt; File is digitally signed


LastRegBack: 2014-05-15 17:34

==================== End Of Log ============================