OTL logfile created on: 2014-05-02 10:48:54 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Dawid\Pulpit\Nowy folder Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1015,23 Mb Total Physical Memory | 483,87 Mb Available Physical Memory | 47,66% Memory free 2,39 Gb Paging File | 1,85 Gb Available in Paging File | 77,61% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 54,84 Gb Total Space | 3,71 Gb Free Space | 6,76% Space Free | Partition Type: NTFS Drive D: | 36,46 Gb Total Space | 24,38 Gb Free Space | 66,87% Space Free | Partition Type: NTFS Computer Name: ASUS-KOMP | User Name: Dawid | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-05-01 00:36:50 | 000,316,704 | ---- | M] () -- C:\Program Files\BrowseMark\bin\utilBrowseMark.exe PRC - [2014-04-30 23:35:41 | 000,316,704 | ---- | M] () -- C:\Program Files\BrowseMark\updateBrowseMark.exe PRC - [2014-04-28 22:43:31 | 003,873,704 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2014-04-28 22:43:24 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2014-04-28 22:42:39 | 000,109,048 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\afwServ.exe PRC - [2014-04-23 20:49:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dawid\Pulpit\Nowy folder\OTL.exe PRC - [2014-04-18 21:10:02 | 000,150,504 | ---- | M] (PriceMeter) -- C:\Program Files\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe PRC - [2014-04-18 16:43:55 | 000,566,272 | ---- | M] (Cherished Technololgy LIMITED) -- C:\Documents and Settings\All Users\Dane aplikacji\WPM\wprotectmanager.exe PRC - [2014-04-13 13:35:53 | 000,309,256 | ---- | M] (PriceMeter) -- C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\PriceMeter\pricemeterw.exe PRC - [2014-04-11 04:05:52 | 000,705,136 | ---- | M] (Cherished Technololgy LIMITED) -- C:\Documents and Settings\All Users\Dane aplikacji\IePluginService\PluginService.exe PRC - [2011-08-04 17:08:56 | 000,593,032 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\Solution Menu EX\CNSEUPDT.EXE PRC - [2011-08-04 17:06:12 | 001,612,920 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE PRC - [2011-03-14 19:09:00 | 002,565,520 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE PRC - [2011-02-07 09:56:11 | 000,138,192 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe PRC - [2011-01-15 16:48:44 | 000,452,016 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2006-10-18 18:04:28 | 000,802,816 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe PRC - [2006-10-18 17:58:16 | 000,696,320 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe PRC - [2006-10-18 17:53:24 | 000,479,232 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe PRC - [2006-08-14 13:54:54 | 000,196,608 | R--- | M] () -- C:\WINDOWS\system32\UMonit.exe PRC - [2006-05-03 14:05:00 | 000,055,808 | R--- | M] (Cognizance Corporation) -- c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\asghost.exe PRC - [2006-03-14 17:46:00 | 000,090,112 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\Asus\Power4 Gear\BatteryLife.exe PRC - [2005-11-23 02:47:00 | 000,532,480 | ---- | M] (Logitech Inc.) -- C:\Program Files\SetPoint\SetPoint.exe PRC - [2005-11-23 02:47:00 | 000,028,160 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE PRC - [2005-10-17 17:09:34 | 000,987,136 | ---- | M] () -- C:\Program Files\Wireless Console 2\wcourier.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-05-02 09:08:33 | 002,252,800 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\14050200\algo.dll MOD - [2014-05-01 00:36:50 | 000,316,704 | ---- | M] () -- C:\Program Files\BrowseMark\bin\utilBrowseMark.exe MOD - [2014-04-30 23:35:41 | 000,316,704 | ---- | M] () -- C:\Program Files\BrowseMark\updateBrowseMark.exe MOD - [2014-04-06 16:07:29 | 000,490,496 | ---- | M] () -- c:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll MOD - [2014-02-13 19:32:41 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8cd995f00848816e3ec49dc326e3d49b\System.ServiceProcess.ni.dll MOD - [2014-02-13 19:32:30 | 000,998,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\5c157466d360a10b2c97e94b41ddc588\System.Management.ni.dll MOD - [2014-02-13 08:02:32 | 003,194,880 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll MOD - [2014-02-13 08:02:29 | 000,425,984 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll MOD - [2014-02-13 08:02:22 | 000,372,736 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll MOD - [2014-02-13 08:02:14 | 002,052,096 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll MOD - [2014-02-13 08:02:09 | 000,114,688 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll MOD - [2014-02-13 07:59:02 | 000,978,944 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b6e70acd99dc22e29b7fc8f9ac340c4\System.Configuration.ni.dll MOD - [2014-02-13 07:54:06 | 005,462,016 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\7faf645dc46781225cb722edf9e1e738\System.Xml.ni.dll MOD - [2014-02-13 07:53:52 | 012,434,432 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1cdfe1998ad6794db3237006906c6fa2\System.Windows.Forms.ni.dll MOD - [2014-02-13 07:53:23 | 001,593,344 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\424bff3295c6e7539cc6df62b9425bd0\System.Drawing.ni.dll MOD - [2014-02-13 07:47:01 | 007,977,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\4b0455ae94e3cecca4bb3ba8c96828c9\System.ni.dll MOD - [2014-02-13 07:46:23 | 011,497,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\dae02331a443fb52216ca83292cb2f21\mscorlib.ni.dll MOD - [2013-10-23 23:58:08 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll MOD - [2011-02-07 09:56:11 | 000,138,192 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe MOD - [2006-10-18 17:51:48 | 000,118,784 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll MOD - [2006-10-18 17:50:22 | 000,348,160 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\IntStngs.dll MOD - [2006-10-02 13:07:26 | 001,167,360 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\acAuth.dll MOD - [2006-08-14 13:54:54 | 000,196,608 | R--- | M] () -- C:\WINDOWS\system32\UMonit.exe MOD - [2006-06-09 14:35:44 | 000,151,552 | R--- | M] () -- C:\WINDOWS\system32\ustor.dll MOD - [2005-10-17 17:09:34 | 000,987,136 | ---- | M] () -- C:\Program Files\Wireless Console 2\wcourier.exe [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2014-05-01 00:36:50 | 000,316,704 | ---- | M] () [Auto | Running] -- C:\Program Files\BrowseMark\bin\utilBrowseMark.exe -- (Util BrowseMark) SRV - [2014-04-30 23:35:41 | 000,316,704 | ---- | M] () [Auto | Running] -- C:\Program Files\BrowseMark\updateBrowseMark.exe -- (Update BrowseMark) SRV - [2014-04-29 23:00:48 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014-04-28 22:43:24 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2014-04-28 22:42:39 | 000,109,048 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall) SRV - [2014-04-18 21:10:02 | 000,150,504 | ---- | M] (PriceMeter) [On_Demand | Stopped] -- C:\Program Files\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe -- (pricemeterliveUpdatem) SRV - [2014-04-18 21:10:02 | 000,150,504 | ---- | M] (PriceMeter) [Auto | Stopped] -- C:\Program Files\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe -- (pricemeterliveUpdate) SRV - [2014-04-18 16:43:55 | 000,566,272 | ---- | M] (Cherished Technololgy LIMITED) [Auto | Running] -- C:\Documents and Settings\All Users\Dane aplikacji\WPM\wprotectmanager.exe -- (Wpm) SRV - [2014-04-11 04:05:52 | 000,705,136 | ---- | M] (Cherished Technololgy LIMITED) [Auto | Running] -- C:\Documents and Settings\All Users\Dane aplikacji\IePluginService\PluginService.exe -- (IePluginService) SRV - [2014-03-29 02:16:33 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2011-02-07 09:56:11 | 000,138,192 | ---- | M] () [Auto | Running] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC) SRV - [2006-03-06 04:36:00 | 000,132,096 | R--- | M] (Cognizance Corporation) [Auto | Running] -- c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASChnl.dll -- (ASChannel) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2014-04-28 22:43:58 | 000,057,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi) DRV - [2014-04-28 22:43:57 | 000,776,976 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\aswSnx.sys -- (aswSnx) DRV - [2014-04-28 22:43:57 | 000,180,632 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm) DRV - [2014-04-28 22:43:55 | 000,411,552 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\aswsp.sys -- (aswSP) DRV - [2014-04-28 22:43:54 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswmonflt.sys -- (aswMonFlt) DRV - [2014-04-28 22:43:54 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt) DRV - [2014-04-28 22:43:53 | 000,054,832 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswRdr.sys -- (AswRdr) DRV - [2014-04-28 22:43:53 | 000,024,184 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\aswHwid.sys -- (aswHwid) DRV - [2014-04-28 22:42:40 | 000,252,464 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswNdis2.sys -- (aswNdis2) DRV - [2014-04-19 10:13:42 | 000,055,232 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tStLibG.sys -- (tStLibG) DRV - [2014-04-06 16:07:18 | 000,031,096 | ---- | M] (Bandoo Media Inc) [Kernel | System | Running] -- C:\Program Files\Movies Toolbar\Datamngr\setmgrc1.cfg -- (F06DEFF2-5B9C-490D-910F-35D3A9119622) DRV - [2014-03-31 20:35:17 | 000,026,136 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswKbd.sys -- (aswKbd) DRV - [2013-10-23 23:57:46 | 000,035,272 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\aswTap.sys -- (aswTap) DRV - [2013-03-07 00:11:20 | 000,012,112 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\aswNdis.sys -- (aswNdis) DRV - [2006-11-02 20:32:30 | 004,394,496 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) DRV - [2006-10-19 09:29:22 | 000,012,544 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans) DRV - [2006-08-29 19:10:34 | 000,107,696 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent) DRV - [2006-08-10 09:38:04 | 000,011,136 | R--- | M] (Genesys Logic) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\fixustor.sys -- (FIXUSTOR) DRV - [2006-08-07 09:13:50 | 000,980,608 | R--- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smserial.sys -- (smserial) DRV - [2006-05-16 22:14:00 | 000,017,840 | R--- | M] (Cognizance Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\itsdisk.sys -- (ItSDisk) DRV - [2006-02-20 15:40:10 | 000,130,048 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\atswpdrv.sys -- (ATSWPDRV) DRV - [2006-01-24 10:45:56 | 000,034,944 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ipswuio.sys -- (ipswuio) DRV - [2005-11-03 14:19:42 | 000,027,136 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidKE.Sys -- (LHidKe) DRV - [2005-11-03 14:19:30 | 000,069,376 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMOUKE.sys -- (LMouKE) DRV - [2005-11-03 14:18:42 | 000,036,608 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidUsbK.sys -- (LHidUsbK) DRV - [2005-11-03 14:18:08 | 000,013,440 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd) DRV - [2005-02-17 10:07:48 | 000,005,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor) DRV - [2005-02-16 18:19:00 | 000,070,144 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp) DRV - [2004-08-03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1397832165&from=cor&uid=HitachiXHTS541610J9SA00_SB2C01SMG1LDEBG1LDEBX IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1397832165&from=cor&uid=HitachiXHTS541610J9SA00_SB2C01SMG1LDEBG1LDEBX&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1397832165&from=cor&uid=HitachiXHTS541610J9SA00_SB2C01SMG1LDEBG1LDEBX&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sweet-page.com/?type=hp&ts=1397832165&from=cor&uid=HitachiXHTS541610J9SA00_SB2C01SMG1LDEBG1LDEBX IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.sweet-page.com/web/?type=ds&ts=1397832165&from=cor&uid=HitachiXHTS541610J9SA00_SB2C01SMG1LDEBG1LDEBX&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.sweet-page.com/web/?type=ds&ts=1397832165&from=cor&uid=HitachiXHTS541610J9SA00_SB2C01SMG1LDEBG1LDEBX&q={searchTerms} IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.sweet-page.com/web/?type=ds&ts=1397832165&from=cor&uid=HitachiXHTS541610J9SA00_SB2C01SMG1LDEBG1LDEBX&q={searchTerms} IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.asus.com IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.asus.com IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.asus.com IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.asus.com IE - HKU\S-1-5-21-1845119400-1298913301-3594010967-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1397832165&from=cor&uid=HitachiXHTS541610J9SA00_SB2C01SMG1LDEBG1LDEBX IE - HKU\S-1-5-21-1845119400-1298913301-3594010967-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sweet-page.com/?type=hp&ts=1397832165&from=cor&uid=HitachiXHTS541610J9SA00_SB2C01SMG1LDEBG1LDEBX IE - HKU\S-1-5-21-1845119400-1298913301-3594010967-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1845119400-1298913301-3594010967-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-1845119400-1298913301-3594010967-1005\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.sweet-page.com/web/?type=ds&ts=1397832165&from=cor&uid=HitachiXHTS541610J9SA00_SB2C01SMG1LDEBG1LDEBX&q={searchTerms} IE - HKU\S-1-5-21-1845119400-1298913301-3594010967-1005\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=974&systemid=406&v=n12281-321&apn_uid=5075453358044284&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} IE - HKU\S-1-5-21-1845119400-1298913301-3594010967-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.selectedEngine: "sweet-page" FF - prefs.js..browser.startup.homepage: "http://www.sweet-page.com/?type=hppp&ts=1398496994&from=cor&uid=HitachiXHTS541610J9SA00_SB2C01SMG1LDEBG1LDEBX" FF - prefs.js..extensions.enabledAddons: quick_start%40gmail.com:3.2.0 FF - prefs.js..extensions.enabledAddons: %7Bd1dac034-9fd9-4c13-a388-d2e10e57707f%7D:1.8.1.0 FF - prefs.js..extensions.enabledAddons: discoverypro%40discoverypro.com:1.0.1 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:28.0 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=3: C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll (PriceMeter) FF - HKLM\Software\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=9: C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll (PriceMeter) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-28 22:44:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\quick_start@gmail.com: C:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\k892xccp.default\extensions\quick_start@gmail.com [2014-04-18 16:42:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 28.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 28.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013-04-14 18:44:17 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Extensions [2014-04-30 10:32:29 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\k892xccp.default\extensions [2014-04-18 23:12:35 | 000,000,000 | ---D | M] (Movies Toolbar (Dist. by Bandoo Media, Inc.)) -- C:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\k892xccp.default\extensions\{d1dac034-9fd9-4c13-a388-d2e10e57707f} [2014-04-30 10:32:29 | 000,000,000 | ---D | M] ("Website Discovery Pro") -- C:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\k892xccp.default\extensions\discoverypro@discoverypro.com [2014-04-18 16:42:48 | 000,000,000 | ---D | M] ("Quick Start") -- C:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\k892xccp.default\extensions\quick_start@gmail.com [2014-04-19 00:46:10 | 000,000,000 | ---D | M] (WebSaveros) -- C:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\k892xccp.default\extensions\vkcoyyuphw@ei-oii.edu [2014-04-18 16:45:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profilesk892xccp.default\extensions [2014-04-18 16:45:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profilesk892xccp.default\extensions\staged [2014-03-29 02:14:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions [2014-03-29 02:16:39 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} O1 HOSTS File: ([2004-08-04 13:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (IETabPage Class) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\SupTab\SupTab.dll (Thinknice Co. Limited) O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (ASUS Security Protect Manager) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll (Infineon Technologies AG) O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKU\S-1-5-21-1845119400-1298913301-3594010967-1005\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found. O3 - HKU\S-1-5-21-1845119400-1298913301-3594010967-1005\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.EXE (ASYSTeK Computer INC.) O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.) O4 - HKLM..\Run: [CognizanceTS] c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASTSVCC.dll (Cognizance Corporation) O4 - HKLM..\Run: [IJNetworkScannerSelectorEX] C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (CANON INC.) O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation) O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation) O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.) O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe (ASUSTeK Computer Inc.) O4 - HKLM..\Run: [UMonit] C:\WINDOWS\system32\UMonit.exe () O4 - HKLM..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe () O4 - HKU\S-1-5-21-1845119400-1298913301-3594010967-1005..\Run: [iLivid] "C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\iLivid\iLivid.exe" -autorun File not found O4 - HKU\S-1-5-21-1845119400-1298913301-3594010967-1005..\Run: [PriceMeterW] C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\PriceMeter\pricemeterw.exe (PriceMeter) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Logitech SetPoint.lnk = C:\Program Files\SetPoint\SetPoint.exe (Logitech Inc.) O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1845119400-1298913301-3594010967-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1365943212078 (WUWebControl Class) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1365943429671 (MUWebControl Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 150.254.193.78 217.97.143.187 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2C64B8A3-A7E5-48CA-B51B-0D56F8ADE668}: DhcpNameServer = 150.254.193.78 217.97.143.187 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\OneCard: DllName - (c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll) - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll (Cognizance Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O27 - HKLM IFEO\bitguard.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\bprotect.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\bpsvc.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\browserdefender.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\browserprotect.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\browsersafeguard.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\dprotectsvc.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\jumpflip: Debugger - tasklist.exe File not found O27 - HKLM IFEO\protectedsearch.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\searchinstaller.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\searchprotection.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\searchprotector.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\searchsettings.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\searchsettings64.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\snapdo.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\stinst32.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\stinst64.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\umbrella.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\utiljumpflip.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\volaro: Debugger - tasklist.exe File not found O27 - HKLM IFEO\vonteera: Debugger - tasklist.exe File not found O27 - HKLM IFEO\websteroids.exe: Debugger - tasklist.exe File not found O27 - HKLM IFEO\websteroidsservice.exe: Debugger - tasklist.exe File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-12-15 15:33:06 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O36 - AppCertDlls: x64 - (c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll) - File not found O36 - AppCertDlls: x86 - (c:\program files\movies toolbar\datamngr\apcrtldr.dll) - c:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll () O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-05-02 10:42:29 | 000,000,000 | ---D | C] -- C:\FRST [2014-05-02 10:36:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Pulpit\Nowy folder [2014-04-28 22:43:50 | 000,043,152 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2014-04-19 10:13:41 | 000,055,232 | ---- | C] (StdLib) -- C:\WINDOWS\System32\drivers\tStLibG.sys [2014-04-19 00:44:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\SuperbApp [2014-04-19 00:44:01 | 000,000,000 | ---D | C] -- C:\Program Files\WebSaveros [2014-04-19 00:44:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\WebSaveros [2014-04-19 00:44:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\48e4ac4dbef777db [2014-04-19 00:44:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\Torch [2014-04-19 00:43:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\Comodo [2014-04-19 00:42:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\InstallMate [2014-04-18 23:26:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Dane aplikacji\vlc [2014-04-18 23:12:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Dane aplikacji\ilividmoviestoolbar181 [2014-04-18 23:12:05 | 000,000,000 | ---D | C] -- C:\Program Files\Movies Toolbar [2014-04-18 23:11:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Datamngr [2014-04-18 22:50:32 | 000,889,416 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Dawid\Moje dokumenty\dotNetFx40_Full_setup (1).exe [2014-04-18 22:15:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\AVG [2014-04-18 22:15:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dane aplikacji\AVG [2014-04-18 22:14:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\AVG [2014-04-18 22:14:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Dane aplikacji\AVG [2014-04-18 22:09:10 | 000,000,000 | ---D | C] -- C:\Program Files\AVG [2014-04-18 22:07:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\AVG [2014-04-18 22:07:16 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Dane aplikacji\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} [2014-04-18 22:07:15 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Common Files [2014-04-18 22:05:32 | 000,889,416 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Dawid\Moje dokumenty\dotNetFx40_Full_setup.exe [2014-04-18 21:38:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\Opera Software [2014-04-18 21:36:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Dane aplikacji\Opera Software [2014-04-18 21:18:09 | 000,000,000 | ---D | C] -- C:\Program Files\Opera [2014-04-18 21:10:45 | 000,000,000 | ---D | C] -- C:\Program Files\PriceMeterLiveUpdate [2014-04-18 21:10:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\PriceMeterLiveUpdate [2014-04-18 21:10:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\PriceMeterLiveUpdate [2014-04-18 21:09:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Dane aplikacji\PriceMeterUpdater [2014-04-18 21:09:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Menu Start\Programy\PriceMeter [2014-04-18 21:09:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\PriceMeter [2014-04-18 16:45:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Dane aplikacji\OpenCandy [2014-04-18 16:45:09 | 000,000,000 | ---D | C] -- C:\Program Files\SiteFinder [2014-04-18 16:45:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Dane aplikacji\SimilarSites [2014-04-18 16:44:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Dane aplikacji\SupTab [2014-04-18 16:44:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\IePluginService [2014-04-18 16:44:12 | 000,000,000 | ---D | C] -- C:\Program Files\SupTab [2014-04-18 16:43:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\WPM [2014-04-18 16:43:06 | 000,000,000 | ---D | C] -- C:\Program Files\BrowseMark [2014-04-18 16:42:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Dane aplikacji\sweet-page [2014-04-18 13:27:24 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJEPPEX [2014-04-18 13:27:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\Canon Easy-PhotoPrint EX [2014-04-18 13:23:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Moje dokumenty\Marek Pawlak MP [2014-04-12 23:29:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawid\Moje dokumenty\JPII - świętość [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-05-02 10:44:08 | 000,000,364 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2014-05-02 10:27:26 | 000,001,030 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2014-05-02 10:27:25 | 000,000,948 | ---- | M] () -- C:\WINDOWS\tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job [2014-05-02 10:27:19 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2014-05-02 10:27:17 | 1064,620,032 | -HS- | M] () -- C:\hiberfil.sys [2014-05-02 09:17:28 | 000,000,952 | ---- | M] () -- C:\WINDOWS\tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job [2014-05-02 09:09:35 | 000,000,426 | ---- | M] () -- C:\WINDOWS\tasks\At5.job [2014-05-02 09:06:32 | 000,001,693 | ---- | M] () -- C:\Documents and Settings\Dawid\Menu Start\Programy\Autostart\Powiadomienia monitorowania tuszu - HP Deskjet 3520 series.lnk [2014-05-02 09:00:05 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2014-05-02 08:48:57 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2014-05-02 08:19:38 | 000,001,034 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2014-05-01 00:48:04 | 000,000,468 | ---- | M] () -- C:\WINDOWS\tasks\At3.job [2014-04-30 10:12:53 | 006,022,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll [2014-04-30 10:10:02 | 000,000,468 | ---- | M] () -- C:\WINDOWS\tasks\At1.job [2014-04-29 23:00:48 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2014-04-29 23:00:48 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2014-04-29 21:28:32 | 000,000,494 | ---- | M] () -- C:\WINDOWS\tasks\pricemetertask.job [2014-04-29 21:28:05 | 000,000,496 | ---- | M] () -- C:\WINDOWS\tasks\pricemeterwatcher.job [2014-04-28 22:46:13 | 000,001,739 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\avast! Internet Security.lnk [2014-04-28 22:43:58 | 000,057,672 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2014-04-28 22:43:57 | 000,776,976 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2014-04-28 22:43:57 | 000,180,632 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswVmm.sys [2014-04-28 22:43:55 | 000,411,552 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswsp.sys [2014-04-28 22:43:54 | 000,067,824 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmonflt.sys [2014-04-28 22:43:54 | 000,049,944 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys [2014-04-28 22:43:53 | 000,054,832 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2014-04-28 22:43:53 | 000,024,184 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswHwid.sys [2014-04-28 22:43:50 | 000,271,264 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [2014-04-28 22:43:50 | 000,043,152 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2014-04-28 22:42:40 | 000,252,464 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswNdis2.sys [2014-04-28 15:58:15 | 000,022,472 | ---- | M] () -- C:\Documents and Settings\Dawid\Pulpit\Dave.jpg [2014-04-27 20:40:05 | 000,000,468 | ---- | M] () -- C:\WINDOWS\tasks\At2.job [2014-04-26 17:46:54 | 000,002,539 | ---- | M] () -- C:\Documents and Settings\Dawid\Pulpit\Microsoft Office Word 2003.lnk [2014-04-21 10:15:42 | 000,741,050 | ---- | M] () -- C:\Documents and Settings\Dawid\Pulpit\Wielkanoc 2014.pdf [2014-04-19 16:58:28 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2014-04-19 16:58:24 | 000,005,120 | ---- | M] () -- C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2014-04-19 16:53:47 | 000,183,808 | ---- | M] () -- C:\Documents and Settings\Dawid\Pulpit\Zmartwychwstanie.MSWMM [2014-04-19 16:49:25 | 000,092,889 | ---- | M] () -- C:\Documents and Settings\Dawid\Pulpit\Zmartwychwstanie.jpg [2014-04-19 10:13:42 | 000,055,232 | ---- | M] (StdLib) -- C:\WINDOWS\System32\drivers\tStLibG.sys [2014-04-19 10:05:01 | 004,925,318 | ---- | M] () -- C:\Documents and Settings\Dawid\Pulpit\Wybór Karola Wojtyły na papieża Jan Paweł II 16. X.1978.avi [2014-04-19 10:02:39 | 054,111,732 | ---- | M] () -- C:\Documents and Settings\Dawid\Pulpit\Serial Biblia - Zmartwychwstanie Jezusa.avi [2014-04-19 00:58:41 | 008,177,522 | ---- | M] () -- C:\Documents and Settings\Dawid\Moje dokumenty\-Habemus Papam!- John XXIII (1).avi [2014-04-19 00:56:36 | 008,177,522 | ---- | M] () -- C:\Documents and Settings\Dawid\Pulpit\-Habemus Papam!- John XXIII.avi [2014-04-18 23:53:55 | 053,625,657 | ---- | M] () -- C:\Documents and Settings\Dawid\Pulpit\Serial Biblia - Zmartwychwstanie Jezusa.mp4 [2014-04-18 22:50:35 | 000,889,416 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Dawid\Moje dokumenty\dotNetFx40_Full_setup (1).exe [2014-04-18 22:05:37 | 000,889,416 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Dawid\Moje dokumenty\dotNetFx40_Full_setup.exe [2014-04-18 14:00:02 | 000,000,468 | ---- | M] () -- C:\WINDOWS\tasks\At4.job [2014-04-09 23:58:25 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-05-02 08:21:16 | 000,000,426 | ---- | C] () -- C:\AVScanner.ini [2014-04-28 22:44:28 | 000,024,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswHwid.sys [2014-04-28 15:56:12 | 000,022,472 | ---- | C] () -- C:\Documents and Settings\Dawid\Pulpit\Dave.jpg [2014-04-21 10:15:41 | 000,741,050 | ---- | C] () -- C:\Documents and Settings\Dawid\Pulpit\Wielkanoc 2014.pdf [2014-04-20 08:10:03 | 000,000,045 | ---- | C] () -- C:\Documents and Settings\NetworkService\Dane aplikacji\WB.CFG [2014-04-19 16:49:21 | 000,092,889 | ---- | C] () -- C:\Documents and Settings\Dawid\Pulpit\Zmartwychwstanie.jpg [2014-04-19 16:08:46 | 000,183,808 | ---- | C] () -- C:\Documents and Settings\Dawid\Pulpit\Zmartwychwstanie.MSWMM [2014-04-19 10:04:38 | 004,925,318 | ---- | C] () -- C:\Documents and Settings\Dawid\Pulpit\Wybór Karola Wojtyły na papieża Jan Paweł II 16. X.1978.avi [2014-04-19 09:56:56 | 054,111,732 | ---- | C] () -- C:\Documents and Settings\Dawid\Pulpit\Serial Biblia - Zmartwychwstanie Jezusa.avi [2014-04-19 01:00:33 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2014-04-19 00:58:08 | 008,177,522 | ---- | C] () -- C:\Documents and Settings\Dawid\Moje dokumenty\-Habemus Papam!- John XXIII (1).avi [2014-04-19 00:56:01 | 008,177,522 | ---- | C] () -- C:\Documents and Settings\Dawid\Pulpit\-Habemus Papam!- John XXIII.avi [2014-04-18 23:51:40 | 053,625,657 | ---- | C] () -- C:\Documents and Settings\Dawid\Pulpit\Serial Biblia - Zmartwychwstanie Jezusa.mp4 [2014-04-18 21:26:26 | 000,000,496 | ---- | C] () -- C:\WINDOWS\tasks\pricemeterwatcher.job [2014-04-18 21:26:17 | 000,000,494 | ---- | C] () -- C:\WINDOWS\tasks\pricemetertask.job [2014-04-18 21:12:35 | 000,000,952 | ---- | C] () -- C:\WINDOWS\tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job [2014-04-18 21:12:22 | 000,000,948 | ---- | C] () -- C:\WINDOWS\tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job [2014-04-18 21:09:45 | 000,000,426 | ---- | C] () -- C:\WINDOWS\tasks\At5.job [2014-02-10 01:47:12 | 000,000,057 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\Ament.ini [2013-10-11 22:45:08 | 000,000,872 | ---- | C] () -- C:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\recently-used.xbel [2013-05-26 09:35:30 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2013-04-14 18:36:28 | 000,178,688 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2013-04-14 17:50:05 | 000,000,057 | ---- | C] () -- C:\WINDOWS\security1400x1050.ini [2013-04-14 17:48:09 | 000,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2013-04-14 15:32:26 | 000,180,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys [2013-04-14 15:32:26 | 000,049,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys [2013-04-14 15:14:20 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2013-04-14 00:29:19 | 000,000,546 | ---- | C] () -- C:\WINDOWS\System32\ABF2HF.DAT [color=#E56717]========== ZeroAccess Check ==========[/color] [2013-10-18 02:24:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2013-02-21 21:10:13 | 001,510,400 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009-02-09 12:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-14 22:50:58 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2014-04-19 00:44:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\48e4ac4dbef777db [2013-10-23 23:38:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software [2014-04-18 22:14:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVG [2013-04-16 20:46:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Canon IJ Network Tool [2013-04-16 20:39:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonBJ [2013-04-16 20:55:13 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonEPP [2013-07-30 17:52:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJ [2014-04-18 13:27:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJEPPEX [2013-04-16 20:55:13 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJEPPEX2 [2013-04-16 20:55:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJMyPrinter [2014-05-01 01:20:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJPLM [2013-07-30 17:52:34 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJScan [2013-04-16 20:55:14 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJSolutionMenuEX [2013-04-16 20:43:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJWSpt [2014-04-18 22:07:15 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Common Files [2014-04-19 09:13:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Datamngr [2014-05-02 08:26:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\F-Secure [2014-04-18 16:44:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\IePluginService [2014-04-19 00:44:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\InstallMate [2014-04-18 21:10:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PriceMeterLiveUpdate [2014-04-19 00:44:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\SuperbApp [2014-02-10 01:49:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Visan [2014-04-26 09:21:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\WebSaveros [2014-04-18 16:44:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\WPM [2014-04-18 22:07:26 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Dane aplikacji\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} [2013-10-24 00:03:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\AVAST Software [2014-04-18 22:14:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\AVG [2013-07-30 17:52:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\Canon [2013-04-17 07:04:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\Canon Easy-WebPrint EX [2014-03-31 21:18:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\Dropbox [2014-03-31 21:18:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\DropboxMaster [2013-04-14 16:51:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\GHISLER [2014-04-18 23:12:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\ilividmoviestoolbar181 [2013-04-14 18:11:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\LibreOffice [2014-04-18 22:42:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\OpenCandy [2014-04-18 21:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\Opera Software [2014-04-18 21:09:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\PriceMeterUpdater [2014-04-18 16:45:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\SimilarSites [2014-04-18 16:44:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\SupTab [2014-04-25 23:11:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\sweet-page [2013-04-16 21:46:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawid\Dane aplikacji\TeamViewer [2014-04-18 22:15:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\AVG [color=#E56717]========== Purity Check ==========[/color] < End of report >