marta900
Nowy
Liczba postów: 2
|
RE: przełącznik wifi toshiba satellite a 660 -190
taaa i okazało się ze nie ma ani 1 punktu przywrocenia :/ , nie mam pojecia dlaczego. zrobiłam ale nie wiem jak wkleic pliki, dlatego wklejam tutaj
Kod:
OTL logfile created on: 2014-04-14 01: 21: 21 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C: \Users\m\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
3,80 Gb Total Physical Memory | 1,74 Gb Available Physical Memory | 45,81% Memory free
7,60 Gb Paging File | 5,13 Gb Available in Paging File | 67,59% Paging File free
Paging file location(s): ?: \pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C: \Windows | %ProgramFiles% = C: \Program Files (x86)
Drive C: | 465,76 Gb Total Space | 391,82 Gb Free Space | 84,12% Space Free | Partition Type: NTFS
Computer Name: MARTA-KOMPUTER | User Name: m | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2014-04-14 01: 20: 28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C: \Users\m\Downloads\OTL.exe
PRC - [2014-04-11 04: 05: 52 | 000,705,136 | ---- | M] (Cherished Technololgy LIMITED) -- C: \ProgramData\IePluginService\PluginService.exe
PRC - [2014-04-08 15: 35: 46 | 000,662,696 | ---- | M] (AdTrustMedia) -- C: \Program Files (x86)\AdTrustMedia\PrivDog\2.1.0.19\trustedadssvc.exe
PRC - [2014-04-03 01: 07: 36 | 003,774,312 | ---- | M] (AVAST Software) -- C: \Program Files\AVAST Software\Avast\avastui.exe
PRC - [2014-04-02 13: 19: 51 | 001,380,704 | ---- | M] () -- C: \Program Files (x86)\Opera\20.0.1387.91\opera_crashreporter.exe
PRC - [2014-04-02 13: 19: 50 | 046,143,840 | ---- | M] (Opera Software) -- C: \Program Files (x86)\Opera\20.0.1387.91\opera.exe
PRC - [2014-04-02 03: 58: 05 | 000,841,032 | ---- | M] (Google Inc.) -- C: \Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014-02-26 14: 49: 52 | 000,425,104 | ---- | M] (Taiwan Shui Mu Chih Ching Technology Limited.) -- C: \Program Files (x86)\WinZipper\winzipersvc.exe
PRC - [2014-02-26 10: 30: 22 | 000,501,904 | ---- | M] (Cherished Technololgy LIMITED) -- C: \ProgramData\WPM\wprotectmanager.exe
PRC - [2014-01-23 18: 22: 58 | 000,050,344 | ---- | M] (AVAST Software) -- C: \Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013-12-21 08: 04: 16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C: \Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2010-08-15 19: 54: 50 | 000,034,160 | ---- | M] (TOSHIBA CORPORATION) -- C: \Program Files (x86)\Toshiba\Utilities\KeNotify.exe
PRC - [2010-02-22 13: 23: 50 | 000,304,496 | ---- | M] (TOSHIBA CORPORATION) -- C: \Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2009-07-28 20: 26: 42 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C: \Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009-03-10 18: 51: 20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C: \Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2014-04-02 13: 19: 53 | 000,908,640 | ---- | M] () -- C: \Program Files (x86)\Opera\20.0.1387.91\libglesv2.dll
MOD - [2014-04-02 13: 19: 53 | 000,108,896 | ---- | M] () -- C: \Program Files (x86)\Opera\20.0.1387.91\libegl.dll
MOD - [2014-04-02 13: 19: 52 | 000,895,328 | ---- | M] () -- C: \Program Files (x86)\Opera\20.0.1387.91\ffmpegsumo.dll
MOD - [2014-04-02 13: 19: 51 | 001,380,704 | ---- | M] () -- C: \Program Files (x86)\Opera\20.0.1387.91\opera_crashreporter.exe
MOD - [2014-04-02 03: 58: 03 | 000,390,472 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll
MOD - [2014-04-02 03: 58: 02 | 013,691,720 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll
MOD - [2014-04-02 03: 57: 59 | 004,081,480 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll
MOD - [2014-04-02 03: 57: 54 | 000,674,632 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libglesv2.dll
MOD - [2014-04-02 03: 57: 53 | 000,093,000 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libegl.dll
MOD - [2014-04-02 03: 57: 52 | 001,647,432 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll
MOD - [2014-04-02 03: 57: 49 | 000,065,352 | ---- | M] () -- C: \Program Files (x86)\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll
MOD - [2014-03-12 11: 27: 59 | 016,276,872 | ---- | M] () -- C: \Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll
MOD - [2014-01-22 02: 03: 12 | 019,336,120 | ---- | M] () -- C: \Program Files\AVAST Software\Avast\libcef.dll
[color=#E56717]========== Services (SafeList) ==========[/color]
SRV: [b]64bit: [/b] - [2014-03-11 12: 34: 10 | 000,347,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c: \Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV: [b]64bit: [/b] - [2014-03-11 12: 34: 10 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c: \Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV: [b]64bit: [/b] - [2014-01-23 18: 22: 58 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C: \Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV: [b]64bit: [/b] - [2013-11-26 11: 18: 09 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C: \Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV: [b]64bit: [/b] - [2013-05-27 07: 50: 47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C: \Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV: [b]64bit: [/b] - [2010-04-06 14: 53: 14 | 000,258,928 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C: \Program Files\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV: [b]64bit: [/b] - [2009-08-21 10: 31: 06 | 000,488,800 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C: \Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV: [b]64bit: [/b] - [2009-07-08 10: 41: 02 | 000,531,520 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C: \Windows\SysNative\ThpSrv.exe -- (Thpsrv)
SRV - [2014-04-11 04: 05: 52 | 000,705,136 | ---- | M] (Cherished Technololgy LIMITED) [Auto | Running] -- C: \ProgramData\IePluginService\PluginService.exe -- (IePluginService)
SRV - [2014-03-12 11: 28: 07 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C: \Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014-02-26 14: 49: 52 | 000,425,104 | ---- | M] (Taiwan Shui Mu Chih Ching Technology Limited.) [Auto | Running] -- C: \Program Files (x86)\WinZipper\winzipersvc.exe -- (winzipersvc)
SRV - [2014-02-26 10: 30: 22 | 000,501,904 | ---- | M] (Cherished Technololgy LIMITED) [Auto | Running] -- C: \ProgramData\WPM\wprotectmanager.exe -- (Wpm)
SRV - [2013-12-21 08: 04: 16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C: \Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013-10-23 09: 15: 08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C: \Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013-09-11 22: 21: 54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C: \Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010-01-28 16: 44: 40 | 000,249,200 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C: \Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe -- (cfWiMAXService)
SRV - [2009-06-10 23: 23: 09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C: \Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009-03-10 18: 51: 20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C: \Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV: [b]64bit: [/b] - [2014-04-13 17: 27: 01 | 000,020,592 | ---- | M] (Compal Electronics, INC.) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\CeKbFilter.sys -- (CeKbFilter)
DRV: [b]64bit: [/b] - [2014-03-11 09: 52: 30 | 000,133,928 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C: \Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV: [b]64bit: [/b] - [2014-01-23 18: 23: 19 | 001,038,072 | ---- | M] (AVAST Software) [File_System | System | Running] -- C: \Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV: [b]64bit: [/b] - [2014-01-23 18: 23: 19 | 000,421,704 | ---- | M] (AVAST Software) [File_System | System | Running] -- C: \Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV: [b]64bit: [/b] - [2014-01-23 18: 23: 19 | 000,080,184 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\aswstm.sys -- (aswStm)
DRV: [b]64bit: [/b] - [2014-01-23 18: 23: 18 | 000,078,648 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C: \Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV: [b]64bit: [/b] - [2014-01-22 02: 03: 18 | 000,207,904 | ---- | M] () [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV: [b]64bit: [/b] - [2014-01-22 02: 03: 18 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV: [b]64bit: [/b] - [2014-01-22 02: 03: 17 | 000,092,544 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV: [b]64bit: [/b] - [2013-12-02 22: 14: 15 | 000,386,680 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV: [b]64bit: [/b] - [2013-05-29 04: 10: 52 | 011,524,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\NETwsw00.sys -- (NETwNs64)
DRV: [b]64bit: [/b] - [2013-04-26 09: 40: 22 | 000,176,880 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\jmcr.sys -- (JMCR)
DRV: [b]64bit: [/b] - [2013-02-19 11: 44: 10 | 012,312,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV: [b]64bit: [/b] - [2013-02-19 10: 59: 38 | 000,057,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV: [b]64bit: [/b] - [2013-02-04 11: 15: 02 | 000,120,704 | ---- | M] (StarWind Software) [Kernel | System | Running] -- C: \Windows\SysNative\drivers\StarPortLite.sys -- (StarPortLite)
DRV: [b]64bit: [/b] - [2012-03-01 08: 46: 16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C: \Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV: [b]64bit: [/b] - [2012-01-26 19: 37: 26 | 000,042,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\WDKMD.sys -- (wdkmd)
DRV: [b]64bit: [/b] - [2011-03-11 08: 41: 12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV: [b]64bit: [/b] - [2011-03-11 08: 41: 12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV: [b]64bit: [/b] - [2010-11-20 15: 33: 35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV: [b]64bit: [/b] - [2010-11-20 13: 07: 05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV: [b]64bit: [/b] - [2010-11-20 11: 37: 42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV: [b]64bit: [/b] - [2010-04-09 16: 49: 20 | 000,330,856 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C: \Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV: [b]64bit: [/b] - [2010-03-22 10: 55: 20 | 000,046,192 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\LPCFilter.sys -- (LPCFilter)
DRV: [b]64bit: [/b] - [2009-07-14 16: 31: 18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)
DRV: [b]64bit: [/b] - [2009-07-14 03: 52: 20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV: [b]64bit: [/b] - [2009-07-14 03: 48: 04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV: [b]64bit: [/b] - [2009-07-14 03: 45: 55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV: [b]64bit: [/b] - [2009-06-29 17: 16: 20 | 000,014,784 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\Thpevm.sys -- (Thpevm)
DRV: [b]64bit: [/b] - [2009-06-29 11: 25: 22 | 000,034,880 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C: \Windows\SysNative\drivers\thpdrv.sys -- (Thpdrv)
DRV: [b]64bit: [/b] - [2009-06-10 22: 34: 33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV: [b]64bit: [/b] - [2009-06-10 22: 34: 28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV: [b]64bit: [/b] - [2009-06-10 22: 34: 23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV: [b]64bit: [/b] - [2009-06-10 22: 31: 59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C: \Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009-07-14 03: 19: 10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C: \Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http: //www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=hp&from=wpm0226&uid=TOSHIBAXMK5065GSX_90K4D1AVBXX90K4D1AVB&ts=1393418939
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http: //www.aartemis.com/web/?type=ds&ts=1387585774&from=cor&uid=TOSHIBAXMK5065GSX_90K4D1AVBXX90K4D1AVB&q={searchTerms}
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http: //www.aartemis.com/web/?type=ds&ts=1387585774&from=cor&uid=TOSHIBAXMK5065GSX_90K4D1AVBXX90K4D1AVB&q={searchTerms}
IE: [b]64bit: [/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp
IE: [b]64bit: [/b] - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE: [b]64bit: [/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http: //www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE: [b]64bit: [/b] - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http: //www.aartemis.com/web/?type=ds&ts=1387585774&from=cor&uid=TOSHIBAXMK5065GSX_90K4D1AVBXX90K4D1AVB&q={searchTerms}
IE: [b]64bit: [/b] - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http: //www.google.com/search?q={searchTerms}&rls=com.microsoft: {language}: {referrer: source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http: //www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=hp&from=wpm0226&uid=TOSHIBAXMK5065GSX_90K4D1AVBXX90K4D1AVB&ts=1393418939
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http: //www.aartemis.com/web/?type=ds&ts=1387585774&from=cor&uid=TOSHIBAXMK5065GSX_90K4D1AVBXX90K4D1AVB&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C: \Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http: //www.aartemis.com/web/?type=ds&ts=1387585774&from=cor&uid=TOSHIBAXMK5065GSX_90K4D1AVBXX90K4D1AVB&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp
IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http: //www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http: //www.aartemis.com/web/?type=ds&ts=1387585774&from=cor&uid=TOSHIBAXMK5065GSX_90K4D1AVBXX90K4D1AVB&q={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http: //www.google.com/search?q={searchTerms}&rls=com.microsoft: {language}: {referrer: source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-249598573-2074806791-3069120502-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp
IE - HKU\S-1-5-21-249598573-2074806791-3069120502-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 77 78 E7 82 A4 51 CF 01 [binary data]
IE - HKU\S-1-5-21-249598573-2074806791-3069120502-1003\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKU\S-1-5-21-249598573-2074806791-3069120502-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http: //www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
IE - HKU\S-1-5-21-249598573-2074806791-3069120502-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http: //www.google.com/search?q={searchTerms}&rls=com.microsoft: {language}: {referrer: source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-249598573-2074806791-3069120502-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C: \Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll File not found
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF: [b]64bit: [/b] - HKLM\Software\MozillaPlugins\[url=http: //windows7forum.pl/microsoft-33418-u]Microsoft[/url].com/NpCtrl,version=1.0: c: \Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C: \Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\[url=http: //windows7forum.pl/microsoft-33418-u]Microsoft[/url].com/NpCtrl,version=1.0: c: \Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C: \Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C: \Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C: \Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
[color=#E56717]========== Chrome ==========[/color]
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google: baseURL}search?q={searchTerms}&{google: RLZ}{google: originalQueryForSuggestion}{google: assistedQueryStats}{google: searchFieldtrialParameter}{google: bookmarkBarPinned}{google: searchClient}{google: sourceId}{google: instantExtendedEnabledParameter}{google: omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google: baseSuggestURL}search?{google: searchFieldtrialParameter}client={google: suggestClient}&gs_ri={google: suggestRid}&xssi=t&q={searchTerms}&{google: cursorPosition}{google: currentPageUrl}{google: pageClassification}sugkey={google: suggestAPIKeyParameter},
CHR - homepage: www.wp.pl/?src01=dp
CHR - plugin: Error reading preferences file
CHR - Extension: Dokumenty Google = C: \Users\m\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Dysk Google = C: \Users\m\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C: \Users\m\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: PrivDog = C: \Users\m\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja\2.1.0.19_0\
CHR - Extension: Szukaj w Google = C: \Users\m\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: avast! Online Security = C: \Users\m\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2018.93_0\
CHR - Extension: Google Wallet = C: \Users\m\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C: \Users\m\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009-06-10 23: 00: 26 | 000,000,824 | ---- | M]) - C: \Windows\SysNative\drivers\etc\hosts
O2: [b]64bit: [/b] - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C: \Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2: [b]64bit: [/b] - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C: \Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2: [b]64bit: [/b] - BHO: (PrivDog Extension) - {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} - C: \Program Files\AdTrustMedia\PrivDog\2.1.0.19\trustedads.dll (AdTrustMedia)
O2 - BHO: (IETabPage Class) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C: \Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited)
O2 - BHO: (BuzzSearch) - {5cf5a690-c8f4-488e-9d20-f21aef602d41} - C: \Program Files (x86)\BuzzSearch\BuzzSearchBHO.dll File not found
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C: \Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (PrivDog Extension) - {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} - C: \Program Files (x86)\AdTrustMedia\PrivDog\2.1.0.19\trustedads.dll (AdTrustMedia)
O3: [b]64bit: [/b] - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C: \Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3: [b]64bit: [/b] - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C: \Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C: \Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4: [b]64bit: [/b] - HKLM..\Run: [00TCrdMain] C: \Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4: [b]64bit: [/b] - HKLM..\Run: [HotKeysCmds] C: \Windows\SysNative\hkcmd.exe (Intel Corporation)
O4: [b]64bit: [/b] - HKLM..\Run: [HSON] C: \Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4: [b]64bit: [/b] - HKLM..\Run: [IgfxTray] C: \Windows\SysNative\igfxtray.exe (Intel Corporation)
O4: [b]64bit: [/b] - HKLM..\Run: [MSC] c: \Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4: [b]64bit: [/b] - HKLM..\Run: [Persistence] C: \Windows\SysNative\igfxpers.exe (Intel Corporation)
O4: [b]64bit: [/b] - HKLM..\Run: [SmoothView] C: \Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4: [b]64bit: [/b] - HKLM..\Run: [Teco] C: \Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4: [b]64bit: [/b] - HKLM..\Run: [ThpSrv] C: \Windows\SysNative\thpsrv.exe (TOSHIBA Corporation)
O4: [b]64bit: [/b] - HKLM..\Run: [TPwrMain] C: \Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [AvastUI.exe] C: \Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [ComodoFSChrome] "C: \Program Files (x86)\AdTrustMedia\PrivDog\FinalizeSetup.exe" /c File not found
O4 - HKLM..\Run: [KeNotify] C: \Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [mobilegeni daemon] C: \Program Files (x86)\Mobogenie\DaemonProcess.exe File not found
O4 - HKLM..\Run: [PrivDogService] C: \Program Files (x86)\AdTrustMedia\PrivDog\2.1.0.19\trustedadssvc.exe (AdTrustMedia)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C: \Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C: \Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [SPReview] "C: \Windows\System32\SPReview\SPReview.exe" /sp: 1 /errorfwlink: "http: //go.microsoft.com/fwlink/?LinkID=122915" /build: 7601 File not found
O4 - HKU\S-1-5-18..\RunOnce: [SPReview] "C: \Windows\System32\SPReview\SPReview.exe" /sp: 1 /errorfwlink: "http: //go.microsoft.com/fwlink/?LinkID=122915" /build: 7601 File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C: \Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C: \Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-249598573-2074806791-3069120502-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9: [b]64bit: [/b] - Extra Button: PrivDog - {2F5C139F-79BD-4C84-A95A-E7140525BC55} - C: \Program Files\AdTrustMedia\PrivDog\2.1.0.19\trustedads.dll (AdTrustMedia)
O9 - Extra Button: PrivDog - {2F5C139F-79BD-4C84-A95A-E7140525BC55} - C: \Program Files (x86)\AdTrustMedia\PrivDog\2.1.0.19\trustedads.dll (AdTrustMedia)
O13[b]64bit: [/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.187.200.250 194.187.200.253
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7ECD45B1-469F-414D-836A-937EBCD85BAA}: DhcpNameServer = 194.187.200.250 194.187.200.253
O18: [b]64bit: [/b] - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C: \PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20: [b]64bit: [/b] - HKLM Winlogon: Shell - (explorer.exe) - C: \Windows\explorer.exe (Microsoft Corporation)
O20: [b]64bit: [/b] - HKLM Winlogon: UserInit - (C: \Windows\system32\userinit.exe) - C: \Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C: \Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C: \Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20: [b]64bit: [/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C: \Windows\SysNative\igfxdev.dll (Intel Corporation)
O21: [b]64bit: [/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35: [b]64bit: [/b] - HKLM\..comfile [open] -- "%1" %*
O35: [b]64bit: [/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37: [b]64bit: [/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37: [b]64bit: [/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv: UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv: ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2014-04-13 17: 29: 15 | 000,000,000 | ---D | C] -- C: \Windows\SysWow64\Microsoft.VC80.MFC
[2014-04-13 17: 29: 15 | 000,000,000 | ---D | C] -- C: \Windows\SysNative\Microsoft.VC80.MFC
[2014-04-13 17: 29: 10 | 000,000,000 | ---D | C] -- C: \ProgramData\vista64
[2014-04-13 17: 29: 00 | 000,000,000 | ---D | C] -- C: \ProgramData\XP
[2014-04-13 17: 29: 00 | 000,000,000 | ---D | C] -- C: \ProgramData\win7_64
[2014-04-13 17: 28: 51 | 000,000,000 | ---D | C] -- C: \ProgramData\win7_32
[2014-04-13 17: 28: 51 | 000,000,000 | ---D | C] -- C: \ProgramData\vista32
[2014-04-13 17: 27: 01 | 000,020,592 | ---- | C] (Compal Electronics, INC.) -- C: \Windows\SysNative\drivers\CeKbFilter.sys
[2014-04-13 16: 03: 38 | 000,000,000 | ---D | C] -- C: \Program Files\TOSHIBA CORPORATION
[2014-04-13 16: 02: 49 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\InstallShield
[2014-04-13 15: 23: 16 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Local\Toshiba
[2014-04-13 15: 23: 16 | 000,000,000 | ---D | C] -- C: \ProgramData\Toshiba
[2014-04-13 15: 00: 43 | 000,000,000 | ---D | C] -- C: \Windows\Downloaded Installations
[2014-04-13 15: 00: 34 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\WinBatch
[2014-04-13 14: 59: 36 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\WinZipper
[2014-04-12 01: 28: 33 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Local\ElevatedDiagnostics
[2014-04-08 23: 22: 16 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Local\AdTrustMedia
[2014-04-07 11: 48: 41 | 000,000,000 | ---D | C] -- C: \Users\Public\Documents\PITy
[2014-04-07 11: 48: 41 | 000,000,000 | ---D | C] -- C: \ProgramData\PITy
[2014-04-07 11: 48: 38 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\Program PITy
[2014-04-07 11: 48: 32 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\ProgramPITy
[2014-04-07 11: 38: 43 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\Podatnik.info
[2014-04-07 11: 38: 43 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\Podatnik.info
[2014-04-07 11: 38: 38 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\Podatnik.info
[2014-04-07 11: 33: 04 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Local\Programs
[2014-04-05 21: 11: 33 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\Originals
[2014-04-03 19: 56: 40 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\Skype
[2014-04-01 11: 18: 14 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\koty
[2014-03-29 01: 49: 21 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\psy
[2014-03-26 01: 42: 40 | 000,000,000 | ---D | C] -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Corporation
[2014-03-26 01: 42: 28 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\Intel Corporation
[2014-03-26 01: 42: 28 | 000,000,000 | ---D | C] -- C: \Program Files (x86)\Common Files\Intel Corporation
[2014-03-26 01: 42: 28 | 000,000,000 | ---D | C] -- C: \ProgramData\Intel
[2014-03-26 01: 32: 59 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Local\Intel WiDi
[2014-03-24 01: 42: 00 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\PhotoScape
[2014-03-19 00: 56: 26 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Local\Adobe
[2014-03-19 00: 01: 48 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\zdjęcia
[2014-03-19 00: 01: 46 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\tato
[2014-03-19 00: 01: 45 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\siwy
[2014-03-19 00: 01: 45 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\programy
[2014-03-18 23: 44: 48 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\Macromedia
[2014-03-18 23: 44: 22 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\Muzyka
[2014-03-18 23: 43: 32 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Local\Opera Software
[2014-03-18 23: 43: 31 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\Opera Software
[2014-03-18 23: 42: 47 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\inne
[2014-03-18 23: 32: 36 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\OpenOffice.ux.pl
[2014-03-18 23: 31: 24 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\filmy
[2014-03-18 23: 31: 16 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\dokumenty
[2014-03-18 23: 29: 18 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\Nowy folder
[2014-03-18 23: 28: 27 | 000,000,000 | ---D | C] -- C: \Users\m\Desktop\ada
[2014-03-18 23: 27: 21 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\AVAST Software
[2014-03-18 23: 26: 22 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\Adobe
[2014-03-18 23: 26: 03 | 000,000,000 | R--D | C] -- C: \Users\m\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2014-03-18 23: 26: 03 | 000,000,000 | R--D | C] -- C: \Users\m\Searches
[2014-03-18 23: 26: 03 | 000,000,000 | R--D | C] -- C: \Users\m\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2014-03-18 23: 25: 36 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\Identities
[2014-03-18 23: 25: 30 | 000,000,000 | R--D | C] -- C: \Users\m\Contacts
[2014-03-18 23: 24: 43 | 000,000,000 | -HSD | C] -- C: \Users\m\Ustawienia lokalne
[2014-03-18 23: 24: 43 | 000,000,000 | -HSD | C] -- C: \Users\m\AppData\Local\Temporary Internet Files
[2014-03-18 23: 24: 43 | 000,000,000 | -HSD | C] -- C: \Users\m\Szablony
[2014-03-18 23: 24: 43 | 000,000,000 | -HSD | C] -- C: \Users\m\AppData\Local\Historia
[2014-03-18 23: 24: 43 | 000,000,000 | -HSD | C] -- C: \Users\m\AppData\Local\Dane aplikacji
[2014-03-18 23: 24: 42 | 000,000,000 | -HSD | C] -- C: \Users\m\SendTo
[2014-03-18 23: 24: 42 | 000,000,000 | -HSD | C] -- C: \Users\m\Recent
[2014-03-18 23: 24: 42 | 000,000,000 | -HSD | C] -- C: \Users\m\PrintHood
[2014-03-18 23: 24: 42 | 000,000,000 | -HSD | C] -- C: \Users\m\NetHood
[2014-03-18 23: 24: 42 | 000,000,000 | -HSD | C] -- C: \Users\m\Documents\Moje wideo
[2014-03-18 23: 24: 42 | 000,000,000 | -HSD | C] -- C: \Users\m\Documents\Moje obrazy
[2014-03-18 23: 24: 42 | 000,000,000 | -HSD | C] -- C: \Users\m\Moje dokumenty
[2014-03-18 23: 24: 42 | 000,000,000 | -HSD | C] -- C: \Users\m\Documents\Moja muzyka
[2014-03-18 23: 24: 42 | 000,000,000 | -HSD | C] -- C: \Users\m\Menu Start
[2014-03-18 23: 24: 42 | 000,000,000 | -HSD | C] -- C: \Users\m\Dane aplikacji
[2014-03-18 23: 24: 42 | 000,000,000 | -HSD | C] -- C: \Users\m\Cookies
[2014-03-18 23: 24: 42 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Local\Temp
[2014-03-18 23: 24: 42 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Local\Microsoft
[2014-03-18 23: 24: 42 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Roaming\Media Center Programs
[2014-03-18 23: 24: 42 | 000,000,000 | ---D | C] -- C: \Users\m\AppData\Local\Google
[2014-03-18 23: 24: 41 | 000,000,000 | --SD | C] -- C: \Users\m\AppData\Roaming\Microsoft
[2014-03-18 23: 24: 41 | 000,000,000 | R--D | C] -- C: \Users\m\Videos
[2014-03-18 23: 24: 41 | 000,000,000 | R--D | C] -- C: \Users\m\Saved Games
[2014-03-18 23: 24: 41 | 000,000,000 | R--D | C] -- C: \Users\m\Pictures
[2014-03-18 23: 24: 41 | 000,000,000 | R--D | C] -- C: \Users\m\Music
[2014-03-18 23: 24: 41 | 000,000,000 | R--D | C] -- C: \Users\m\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2014-03-18 23: 24: 41 | 000,000,000 | R--D | C] -- C: \Users\m\Links
[2014-03-18 23: 24: 41 | 000,000,000 | R--D | C] -- C: \Users\m\Favorites
[2014-03-18 23: 24: 41 | 000,000,000 | R--D | C] -- C: \Users\m\Downloads
[2014-03-18 23: 24: 41 | 000,000,000 | R--D | C] -- C: \Users\m\Documents
[2014-03-18 23: 24: 41 | 000,000,000 | R--D | C] -- C: \Users\m\Desktop
[2014-03-18 23: 24: 41 | 000,000,000 | R--D | C] -- C: \Users\m\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2014-03-18 23: 24: 41 | 000,000,000 | -H-D | C] -- C: \Users\m\AppData
[2014-03-18 18: 32: 07 | 000,000,000 | ---D | C] -- C: \Windows\Minidump
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2014-04-14 01: 00: 00 | 000,000,930 | ---- | M] () -- C: \Windows\tasks\Adobe Flash Player Updater.job
[2014-04-14 00: 56: 19 | 000,001,046 | ---- | M] () -- C: \Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014-04-14 00: 55: 09 | 000,067,584 | --S- | M] () -- C: \Windows\bootstat.dat
[2014-04-13 17: 40: 20 | 000,015,328 | -H-- | M] () -- C: \Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014-04-13 17: 40: 20 | 000,015,328 | -H-- | M] () -- C: \Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014-04-13 17: 33: 05 | 000,001,042 | ---- | M] () -- C: \Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014-04-13 17: 30: 59 | 3059,748,864 | -HS- | M] () -- C: \hiberfil.sys
[2014-04-13 17: 27: 01 | 000,020,592 | ---- | M] (Compal Electronics, INC.) -- C: \Windows\SysNative\drivers\CeKbFilter.sys
[2014-04-13 16: 36: 51 | 000,000,000 | ---- | M] () -- C: \Windows\NDSTray.INI
[2014-04-13 16: 03: 38 | 000,000,731 | ---- | M] () -- C: \Users\Public\Desktop\TOSHIBA Assist.lnk
[2014-04-13 15: 53: 34 | 006,369,628 | ---- | M] () -- C: \Users\m\Desktop\A660_PL.pdf
[2014-04-12 11: 31: 07 | 001,669,190 | ---- | M] () -- C: \Windows\SysNative\PerfStringBackup.INI
[2014-04-12 11: 31: 07 | 000,740,348 | ---- | M] () -- C: \Windows\SysNative\perfh015.dat
[2014-04-12 11: 31: 07 | 000,654,140 | ---- | M] () -- C: \Windows\SysNative\perfh009.dat
[2014-04-12 11: 31: 07 | 000,155,890 | ---- | M] () -- C: \Windows\SysNative\perfc015.dat
[2014-04-12 11: 31: 07 | 000,122,012 | ---- | M] () -- C: \Windows\SysNative\perfc009.dat
[2014-04-12 01: 43: 24 | 000,006,896 | ---- | M] () -- C: \bootsqm.dat
[2014-04-11 14: 10: 12 | 000,031,483 | ---- | M] () -- C: \Users\m\Desktop\cross.odt
[2014-04-09 10: 45: 59 | 000,002,189 | ---- | M] () -- C: \Users\Public\Desktop\Google Chrome.lnk
[2014-04-08 23: 37: 42 | 000,081,971 | ---- | M] () -- C: \Users\m\Desktop\10168502_613061902118505_303454189_n.jpg
[2014-04-07 11: 48: 39 | 000,001,004 | ---- | M] () -- C: \Users\m\Desktop\PITy roczne.lnk
[2014-04-07 11: 38: 43 | 000,001,215 | ---- | M] () -- C: \Users\m\Desktop\PIT pro 2013.lnk
[2014-04-05 21: 11: 24 | 000,188,416 | -H-- | M] () -- C: \Users\m\Desktop\photothumb.db
[2014-04-03 03: 02: 38 | 000,002,155 | ---- | M] () -- C: \Windows\epplauncher.mif
[2014-03-31 23: 29: 10 | 000,100,024 | ---- | M] () -- C: \Users\m\Desktop\974572_608181059273256_463100850_n.jpg
[2014-03-26 01: 31: 46 | 000,000,000 | -H-- | M] () -- C: \Windows\SysNative\drivers\Msft_Kernel_WDKMD_01009.Wdf
[2014-03-19 00: 56: 52 | 000,002,010 | ---- | M] () -- C: \Users\Public\Desktop\avast! Free Antivirus.lnk
[2014-03-19 00: 28: 22 | 000,013,504 | ---- | M] () -- C: \Users\m\Desktop\filmy.odt
[2014-03-18 18: 31: 57 | 332,059,454 | ---- | M] () -- C: \Windows\MEMORY.DMP
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2014-04-13 16: 36: 51 | 000,000,000 | ---- | C] () -- C: \Windows\NDSTray.INI
[2014-04-13 16: 35: 41 | 100,013,752 | R--- | C] () -- C: \Users\m\Desktop\TC00249500I.exe
[2014-04-13 16: 03: 38 | 000,000,731 | ---- | C] () -- C: \Users\Public\Desktop\TOSHIBA Assist.lnk
[2014-04-13 15: 53: 29 | 006,369,628 | ---- | C] () -- C: \Users\m\Desktop\A660_PL.pdf
[2014-04-12 01: 43: 24 | 000,006,896 | ---- | C] () -- C: \bootsqm.dat
[2014-04-09 15: 52: 30 | 000,100,024 | ---- | C] () -- C: \Users\m\Desktop\974572_608181059273256_463100850_n.jpg
[2014-04-08 23: 37: 41 | 000,081,971 | ---- | C] () -- C: \Users\m\Desktop\10168502_613061902118505_303454189_n.jpg
[2014-04-07 11: 48: 39 | 000,001,004 | ---- | C] () -- C: \Users\m\Desktop\PITy roczne.lnk
[2014-04-07 11: 38: 43 | 000,001,215 | ---- | C] () -- C: \Users\m\Desktop\PIT pro 2013.lnk
[2014-04-02 12: 47: 57 | 000,031,483 | ---- | C] () -- C: \Users\m\Desktop\cross.odt
[2014-03-26 01: 42: 40 | 000,002,052 | ---- | C] () -- C: \ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) WiDi.lnk
[2014-03-26 01: 31: 46 | 000,000,000 | -H-- | C] () -- C: \Windows\SysNative\drivers\Msft_Kernel_WDKMD_01009.Wdf
[2014-03-24 01: 42: 55 | 000,188,416 | -H-- | C] () -- C: \Users\m\Desktop\photothumb.db
[2014-03-19 00: 45: 33 | 000,001,031 | ---- | C] () -- C: \Users\m\Desktop\PhotoScape.lnk
[2014-03-19 00: 28: 19 | 000,013,504 | ---- | C] () -- C: \Users\m\Desktop\filmy.odt
[2014-03-18 23: 26: 22 | 000,001,421 | ---- | C] () -- C: \Users\m\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014-03-18 18: 31: 57 | 332,059,454 | ---- | C] () -- C: \Windows\MEMORY.DMP
[2014-02-28 13: 42: 09 | 001,641,068 | ---- | C] () -- C: \Windows\SysWow64\PerfStringBackup.INI
[2013-12-02 18: 28: 03 | 013,913,600 | ---- | C] () -- C: \Windows\SysWow64\ig4icd32.dll
[2013-12-02 18: 27: 53 | 000,867,020 | ---- | C] () -- C: \Windows\SysWow64\igkrng575.bin
[2013-12-02 18: 27: 53 | 000,128,204 | ---- | C] () -- C: \Windows\SysWow64\igcompkrng575.bin
[2013-12-02 18: 27: 53 | 000,105,608 | ---- | C] () -- C: \Windows\SysWow64\igfcg575m.bin
[color=#E56717]========== ZeroAccess Check ==========[/color]
[2009-07-14 06: 55: 00 | 000,000,227 | RHS- | M] () -- C: \Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C: \Windows\SysNative\shell32.dll -- [2013-07-26 04: 24: 57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013-07-26 03: 55: 59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C: \Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03: 40: 51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 14: 19: 02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C: \Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03: 41: 56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
[color=#E56717]========== LOP Check ==========[/color]
[2014-01-25 21: 49: 25 | 000,000,000 | ---D | M] -- C: \Users\Gość\AppData\Roaming\AVAST Software
[2014-03-15 21: 41: 35 | 000,000,000 | ---D | M] -- C: \Users\Gość\AppData\Roaming\OpenOffice.ux.pl
[2014-03-15 01: 20: 05 | 000,000,000 | ---D | M] -- C: \Users\Gość\AppData\Roaming\Opera Software
[2014-03-18 23: 27: 21 | 000,000,000 | ---D | M] -- C: \Users\m\AppData\Roaming\AVAST Software
[2014-03-18 23: 32: 36 | 000,000,000 | ---D | M] -- C: \Users\m\AppData\Roaming\OpenOffice.ux.pl
[2014-03-18 23: 43: 31 | 000,000,000 | ---D | M] -- C: \Users\m\AppData\Roaming\Opera Software
[2014-03-24 01: 48: 52 | 000,000,000 | ---D | M] -- C: \Users\m\AppData\Roaming\PhotoScape
[2014-04-07 11: 38: 43 | 000,000,000 | ---D | M] -- C: \Users\m\AppData\Roaming\Podatnik.info
[2014-04-13 15: 00: 34 | 000,000,000 | ---D | M] -- C: \Users\m\AppData\Roaming\WinBatch
[2014-04-13 14: 59: 36 | 000,000,000 | ---D | M] -- C: \Users\m\AppData\Roaming\WinZipper
[color=#E56717]========== Purity Check ==========[/color]
< End of report >
Kod:
OTL Extras logfile created on: 2014-04-14 01: 21: 21 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C: \Users\m\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
3,80 Gb Total Physical Memory | 1,74 Gb Available Physical Memory | 45,81% Memory free
7,60 Gb Paging File | 5,13 Gb Available in Paging File | 67,59% Paging File free
Paging file location(s): ?: \pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C: \Windows | %ProgramFiles% = C: \Program Files (x86)
Drive C: | 465,76 Gb Total Space | 391,82 Gb Free Space | 84,12% Space Free | Partition Type: NTFS
Computer Name: MARTA-KOMPUTER | User Name: m | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = OperaStable] -- C: \Program Files (x86)\Opera\Launcher.exe (Opera Software)
.url[@ = InternetShortcut] -- C: \Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C: \Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = OperaStable] -- C: \Program Files (x86)\Opera\Launcher.exe (Opera Software)
[HKEY_USERS\S-1-5-21-249598573-2074806791-3069120502-1003\SOFTWARE\Classes\<extension>]
.html [@ = OperaStable] -- C: \Program Files (x86)\Opera\Launcher.exe (Opera Software)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C: \Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C: \Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C: \Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
https [open] -- "C: \Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C: \Windows\System32\rundll32.exe" "C: \Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C: \Windows\System32\rundll32.exe" "C: \Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C: \Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C: \Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C: \Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C: \Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C: \Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
https [open] -- "C: \Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C: \Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{035298DB-5B9B-4E94-80DB-4A589A65A4AA}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{14943B2A-885C-4317-8863-582892EBCB24}" = rport=138 | protocol=17 | dir=out | app=system |
"{21FE2908-11EB-4276-AA10-432F0ADF5518}" = rport=445 | protocol=6 | dir=out | app=system |
"{44A3A5C6-36A5-4879-A61C-C1445F0EEAFA}" = rport=139 | protocol=6 | dir=out | app=system |
"{5C695659-8AE5-437D-AF8A-215B79C5B7A5}" = lport=139 | protocol=6 | dir=in | app=system |
"{7405CB91-AE2D-476C-B5FC-664060BE268F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7BA6A5E2-4E32-4650-B0F5-C44C37862223}" = lport=137 | protocol=17 | dir=in | app=system |
"{820482D9-8C95-42AD-A4F5-17DA77997511}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8F19E9C2-C1A3-47A9-B70E-84778053FEAA}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A3831A4E-8815-45E6-8077-A08D48E6E86F}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AD051F5C-0EE0-4271-8921-4B6F77816C5E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{ADFF130C-9CF3-4F15-B9E9-7359EC8B0F65}" = lport=10243 | protocol=6 | dir=in | app=system |
"{B673BA47-387B-4D77-8177-F9CD6C16869B}" = rport=137 | protocol=17 | dir=out | app=system |
"{BF6AB544-2D9B-4322-9669-72C03C6E945E}" = lport=138 | protocol=17 | dir=in | app=system |
"{C43CA6AE-D200-49BE-863D-8DCCE89E8C53}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{CDD01877-ED97-45A8-887F-E862E2ED4DD0}" = rport=10243 | protocol=6 | dir=out | app=system |
"{CFB4E986-C60C-4E85-AFCB-5B6A0FE040A8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CFE44843-A4AD-4EE5-B2BB-93CFEA7586AD}" = lport=445 | protocol=6 | dir=in | app=system |
"{D3655A51-B9E7-4C99-B76C-7AC484376A24}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DA35454F-FD3E-4AB8-BBA3-940755647898}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FE0EDD22-60EB-43A1-8518-31585820F331}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{15BA36AB-2F23-47EF-B4F9-D4C59577B422}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{212F21B3-12AF-441E-BA92-D6D750D0678D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2874C748-F50C-49EC-8C1F-5AD8F21D8563}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{28E26691-CDB1-4838-AF5F-BCA4BC31B859}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{41AB304D-7A92-47C3-837E-BE9ECC137F2F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{58186F34-E94D-4B34-B255-6308F71DA973}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{61DF09F3-81AC-488B-B010-D5597FED7B3C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{667A77BC-9F45-425A-B3DD-616157C4D5BC}" = protocol=6 | dir=out | app=system |
"{6F76A746-5A01-4EF2-B5B2-08691F2FFF9B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7268393E-062F-4A05-AAA4-73FDDA5AA9AC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{8183223F-7A15-455F-BE49-26FBB4CDD66B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{85F6EB4A-10C0-4DC1-8D76-40EFDB430EF7}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{957B4D1E-7FF9-40E5-98EC-EB4EF4AFE801}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9F7238D4-BB90-4D6D-96C4-098C50D514F0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A8228FC1-8337-4F21-8458-7ECF27145CC2}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C43596FB-4E95-4225-A29C-ED15F4AB4984}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{C54D9D85-583D-4B72-BF53-0144E2421151}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DF4C4A23-75C8-437B-917B-D603850E4075}" = dir=in | app=c: \program files (x86)\skype\phone\skype.exe |
"{EBAF33C1-40B2-4AE1-A38A-7E2F85982972}" = dir=in | app=c: \program files (x86)\intel corporation\intel widi\widiapp.exe |
"{F46C5FDB-2FE2-4136-8E41-7C47A09B921D}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F590E25E-3FB7-4718-9165-736EC6FCE796}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel® Wireless Display
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{45F1F774-38B4-3CC3-BAAF-051E6D19E48E}" = Microsoft .NET Framework 4.5.1 (PLK)
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1045" = Microsoft .NET Framework 4.5.1 (Polski)
"{94A90C69-71C1-470A-88F5-AA47ECC96B40}" = TOSHIBA HDD Protection
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{BFAE8D5B-F918-486F-B74E-90762DF11C5C}" = Microsoft Security Client
"Microsoft Security Client" = Microsoft Security Essentials
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{011B5F12-F1CB-4C14-A99E-62C55831D78A}" = OpenOffice.ux.pl 3.4
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{1777CCDA-F2F2-4A77-ACF4-0B7341229BBB}" = TOSHIBA ConfigFree
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1B87C40B-A60B-4EF3-9A68-706CF4B69978}" = Toshiba Assist
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.11
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{7FCB8D5D-9396-4D17-8CFA-349D6D49CD32}" = Intel® WiDi
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1045-7B44-AB0000000001}" = Adobe Reader XI (11.0.06) - Polish
"{B239B43B-3E99-40B0-80BF-1B1BCA868D4E}_is1" = Podatnik.info PIT pro 2013 wersja 2.0.17.21411
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}" = Google Drive
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"Adobe Flash Player ActiveX" = Adobe Flash Player 12 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin
"Avast" = avast! Free Antivirus
"Google Chrome" = Google Chrome
"IePlugins" = IePluginService12.27.0.3326
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"MpcStar" = MpcStar 5.4
"Opera 19.0.1326.63" = Opera Stable 19.0.1326.63
"Opera 20.0.1387.64" = Opera Stable 20.0.1387.64
"Opera 20.0.1387.91" = Opera Stable 20.0.1387.91
"PhotoScape" = PhotoScape
"PITy 2013/2014_is1" = PITy 2013/2014
"PrivDog" = PrivDog
"StarBurn_is1" = StarBurn Version 15.2 (Build 0x20131129)
"SupTab" = SupTab
"WinZipper" = WinZipper
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 2014-04-10 16: 33: 15 | Computer Name = Marta-Komputer | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 2014-04-11 08: 27: 33 | Computer Name = Marta-Komputer | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 2014-04-13 01: 33: 10 | Computer Name = Marta-Komputer | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd: svchost.exe_SysMain, wersja: 6.1.7600.16385,
sygnatura czasowa: 0x4a5bc3c1 Nazwa modułu powodującego błąd: sysmain.dll, wersja:
6.1.7601.17514, sygnatura czasowa: 0x4ce7c9db Kod wyjątku: 0xc0000006 Przesunięcie
błędu: 0x000000000001d859 Identyfikator procesu powodującego błąd: 0x1a4 Godzina
uruchomienia aplikacji powodującej błąd: 0x01cf56310c4491e1 Ścieżka aplikacji powodującej
błąd: C: \Windows\System32\svchost.exe Ścieżka modułu powodującego błąd: c: \windows\system32\sysmain.dll
Identyfikator
raportu: 18d9fc4e-c2cd-11e3-9804-002710b16cc8
Error - 2014-04-13 01: 33: 10 | Computer Name = Marta-Komputer | Source = Application Error | ID = 1005
Description = System Windows nie może uzyskać dostępu do pliku C: \Windows\Prefetch\AgCx_SC1.db
z jednej z następujących przyczyn: problem z połączeniem sieciowym; problem z dyskiem,
na którym jest przechowywany plik; problem ze sterownikami magazynu zainstalowanymi
na tym komputerze; brak dysku. System Windows zamknął program Proces hosta dla usług
systemu Windows z powodu tego błędu. Program: Proces hosta dla usług systemu Windows
Plik:
C: \Windows\Prefetch\AgCx_SC1.db Wartość błędu jest wyświetlona w sekcji Dodatkowe
dane. Akcja użytkownika 1. Otwórz plik ponownie. Ta sytuacja może być przejściowym
problemem, który sam się rozwiąże po ponownym uruchomieniu programu. 2. Jeśli nadal
nie można uzyskać dostępu do pliku i - jest w sieci, administrator sieci powinien
sprawdzić, czy nie ma problemu z siecią i czy można skontaktować się z serwerem.
-
jest na dysku wymiennym, na przykład dyskietce lub dysku CD-ROM, sprawdź, czy cały
dysk jest włożony do komputera. 3. Sprawdź i napraw system plików, uruchamiając
program CHKDSK. Aby uruchomić program CHKDSK, kliknij przycisk Start, kliknij polecenie
Uruchom, wpisz polecenie CMD, a następnie kliknij przycisk OK. W wierszu polecenia
wpisz polecenie CHKDSK /F, a następnie naciśnij klawisz ENTER. 4. Jeżeli problem
nie ustąpi, przywróć plik z kopii zapasowej. 5. Ustal, czy można otworzyć inne pliki
na tym samym dysku. Jeśli nie, dysk może być uszkodzony. Jeśli jest to dysk twardy,
skontaktuj się z administratorem komputera lub dostawcą sprzętu komputerowego, aby
uzyskać dalszą pomoc. Dodatkowe dane Wartość błędu: C000009C Typ dysku: 3
Error - 2014-04-13 01: 33: 13 | Computer Name = Marta-Komputer | Source = Desktop Window Manager | ID = 9020
Description = Menedżer okien pulpitu napotkał błąd krytyczny (0x88980406).
Error - 2014-04-13 07: 23: 05 | Computer Name = Marta-Komputer | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd: svchost.exe_SysMain, wersja: 6.1.7600.16385,
sygnatura czasowa: 0x4a5bc3c1 Nazwa modułu powodującego błąd: sysmain.dll, wersja:
6.1.7601.17514, sygnatura czasowa: 0x4ce7c9db Kod wyjątku: 0xc0000006 Przesunięcie
błędu: 0x000000000001d7f5 Identyfikator procesu powodującego błąd: 0xd60 Godzina
uruchomienia aplikacji powodującej błąd: 0x01cf56d9dd1080b8 Ścieżka aplikacji powodującej
błąd: C: \Windows\System32\svchost.exe Ścieżka modułu powodującego błąd: c: \windows\system32\sysmain.dll
Identyfikator
raportu: fb1be6dd-c2fd-11e3-9804-002710b16cc8
Error - 2014-04-13 07: 23: 05 | Computer Name = Marta-Komputer | Source = Application Error | ID = 1005
Description = System Windows nie może uzyskać dostępu do pliku C: \Windows\Prefetch\AgCx_SC1.db
z jednej z następujących przyczyn: problem z połączeniem sieciowym; problem z dyskiem,
na którym jest przechowywany plik; problem ze sterownikami magazynu zainstalowanymi
na tym komputerze; brak dysku. System Windows zamknął program Proces hosta dla usług
systemu Windows z powodu tego błędu. Program: Proces hosta dla usług systemu Windows
Plik:
C: \Windows\Prefetch\AgCx_SC1.db Wartość błędu jest wyświetlona w sekcji Dodatkowe
dane. Akcja użytkownika 1. Otwórz plik ponownie. Ta sytuacja może być przejściowym
problemem, który sam się rozwiąże po ponownym uruchomieniu programu. 2. Jeśli nadal
nie można uzyskać dostępu do pliku i - jest w sieci, administrator sieci powinien
sprawdzić, czy nie ma problemu z siecią i czy można skontaktować się z serwerem.
-
jest na dysku wymiennym, na przykład dyskietce lub dysku CD-ROM, sprawdź, czy cały
dysk jest włożony do komputera. 3. Sprawdź i napraw system plików, uruchamiając
program CHKD
(Ten post był ostatnio modyfikowany: 14.04.2014 00:39 przez marta900.)
14.04.2014 00:38
|