Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-01-2015 01 Ran by MCU at 2015-01-12 02:15:00 Running from C:\Documents and Settings\MCU\Moje dokumenty\Pobrane Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: ArcaVir (Disabled - Up to date) {430EE792-8EF9-4D8A-B486-78BBF686F0E1} FW: ArcaVir Firewall (Disabled) {B640009B-6FF6-4CA7-9CE8-7DA160B95A5B} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated) Adobe Reader 8.1.2 (HKLM\...\{AC76BA86-7AD7-1033-7B44-A81200000003}) (Version: 8.1.2 - Adobe Systems Incorporated) AIMP3 (HKLM\...\AIMP3) (Version: v3.55.1355, 14.07.2014 - AIMP DevTeam) ASUS VGA Driver (Version: 4.00.0000 - Nazwa firmy) Hidden ATI AVIVO Codecs (HKLM\...\{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}) (Version: 10.0.0.31121 - ATI Technologies Inc.) ATI Catalyst Control Center (HKLM\...\{055EE59D-217B-43A7-ABFF-507B966405D8}) (Version: 2.009.0203.2156 - ) ATI Display Driver (HKLM\...\ATI Display Driver) (Version: 8.561.9-090203a-075622E-Asus - ) ATI Parental Control & Encoder (HKLM\...\{9862B19F-4CAD-4EED-920F-2F378D84393F}) (Version: 3.0 - Nazwa firmy) Brother MFL-Pro Suite DCP-375CW (HKLM\...\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}) (Version: 1.0.2.0 - Brother Industries, Ltd.) ccc-core-preinstall (Version: 2009.0203.2157.39370 - ATI) Hidden ccc-core-static (Version: 2009.0203.2157.39370 - ATI) Hidden ChomikBox (HKLM\...\{C7B52FAF-58D8-438C-B810-F78C3C927504}) (Version: 2.0.8.0 - Chomikuj.pl) CyberLink DVD Suite (HKLM\...\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 5.0.3019 - CyberLink Corp.) FormatFactory 3.5.1.0 (HKLM\...\FormatFactory) (Version: 3.5.1.0 - Format Factory) LG ODD Auto Firmware Update (HKLM\...\{6179550A-3E7C-499E-BCC9-9E8113E0A285}) (Version: 10.01.0712.01 - ) Microsoft .NET Framework 2.0 (HKLM\...\Microsoft .NET Framework 2.0) (Version: - Microsoft Corporation) Microsoft Office Standard 2007 (HKLM\...\STANDARD) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft WinUsb 2.0 (HKLM\...\winusb0200) (Version: - Microsoft Corporation) Mobogenie3 (HKLM\...\Mobogenie3) (Version: 3.0.0.45783 - Mobogenie.com) <==== ATTENTION Mozilla Firefox 34.0.5 (x86 pl) (HKLM\...\Mozilla Firefox 34.0.5 (x86 pl)) (Version: 34.0.5 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla) MTP Porting Kit (HKLM\...\{353B1E6D-7073-4450-8C80-699BD8FCFB49}) (Version: 12.0.0 - Microsoft Corp) Narzędzie Software Uninstall Utility firmy ATI (HKLM\...\All ATI Software) (Version: 6.14.10.1022 - ) Nero 7 Essentials (HKLM\...\{66B6D13A-9CC1-417D-B6F2-58AA539D1045}) (Version: 7.03.1303 - Nero AG) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) NVIDIA PhysX (HKLM\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation) PaperPort Image Printer (HKLM\...\{2BC2781A-F7F6-452E-95EB-018A522F1B2C}) (Version: 1.00.0000 - Nuance Communications, Inc.) PowerProducer (HKLM\...\{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 063604(3.7)_Vista_LG - CyberLink Corp.) Pro Evolution Soccer 2013 (HKLM\...\{C2523AE6-F335-4D0B-BC15-1C07E4ACE629}) (Version: 1.00.0000 - KONAMI) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 5.10.0.5605 - Realtek Semiconductor Corp.) ScanSoft PaperPort 11 (HKLM\...\{5C4ED859-875F-4299-AA2C-E0E393BDCD21}) (Version: 11.2.0000 - Nuance Communications, Inc.) SecurDisc Viewer (HKLM\...\{6E06FC10-2DA5-42AA-A1E5-2D8AEF651045}) (Version: 7.02.9556 - Nero AG) SHIFT 2 UNLEASHED™ (HKLM\...\{E8C37E27-5205-4C8A-BECB-B00533045AAE}) (Version: 1.0.0.0 - Electronic Arts) Skins (Version: 2009.0203.2157.39370 - ATI) Hidden Skoki Narciarskie 2006 (HKLM\...\Skoki Narciarskie 2006) (Version: - ) VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden Winamp (HKLM\...\Winamp) (Version: 5.666 - Nullsoft, Inc) Windows Media Format Runtime (HKLM\...\Windows Media Format Runtime) (Version: - ) WinRAR 5.20 (32-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1214440339-362288127-725345543-1003_Classes\CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\WINDOWS\system32\msxml4.dll (Microsoft Corporation) ==================== Restore Points ========================= 29-12-2014 20:47:44 Punkt kontrolny systemu 29-12-2014 20:51:08 Installed ArcaVir Prerequistes 29-12-2014 20:55:46 Installed ArcaVir 29-12-2014 21:02:11 Zainstalowane ASUS VGA Driver 29-12-2014 21:10:02 Zainstalowane Realtek High Definition Audio Driver 29-12-2014 21:32:57 Zainstalowano: SecurDisc Viewer 29-12-2014 21:36:06 Zainstalowany program DirectX 29-12-2014 21:36:32 Zainstalowano: Nero 7 Essentials 29-12-2014 21:51:49 avast! antivirus system restore point 29-12-2014 21:55:35 avast! antivirus system restore point 29-12-2014 22:00:39 Skonfigurowane ASUS VGA Driver 29-12-2014 22:12:59 Installed Adobe Reader 8.1.2 29-12-2014 22:16:58 Zainstalowano: ScanSoft PaperPort 11 29-12-2014 22:17:58 Zainstalowano: PaperPort Image Printer 29-12-2014 22:18:03 Zainstalowane sterowniki drukarek: Nuance Image Printer Driver 29-12-2014 22:18:17 Zainstalowano: Microsoft Visual C++ 2005 Redistributable 29-12-2014 22:18:51 Zainstalowane MFL-Pro Suite 29-12-2014 22:40:49 Zainstalowany program DirectX 30-12-2014 01:04:14 Removed ArcaVir 30-12-2014 01:04:16 Removed ArcaVir Prerequistes 30-12-2014 01:08:27 avast! antivirus system restore point 30-12-2014 19:19:37 Removed ArcaVir 30-12-2014 01:25:10 avast! antivirus system restore point 30-12-2014 19:19:14 Installed Microsoft Office Standard 2007 30-12-2014 19:21:38 Zainstalowane sterowniki drukarek: Microsoft Office Document Im 01-01-2015 20:19:06 Punkt kontrolny systemu 02-01-2015 13:03:33 Installed Pro Evolution Soccer 2013. 02-01-2015 19:08:43 Zainstalowano: ChomikBox 03-01-2015 01:23:07 Installed MTP Porting Kit 03-01-2015 01:37:00 Installed Windows XP Wdf01009. 03-01-2015 01:37:11 Installed Windows XP winusb0200. 04-01-2015 01:58:45 Zainstalowany program DirectX 04-01-2015 02:14:05 Removed Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 05-01-2015 14:36:51 Punkt kontrolny systemu 05-01-2015 15:07:42 Zainstalowano: SHIFT 2 UNLEASHED™ 06-01-2015 15:17:38 Punkt kontrolny systemu 07-01-2015 23:47:32 Punkt kontrolny systemu 09-01-2015 23:38:24 Punkt kontrolny systemu 12-01-2015 00:51:52 Removed ArcaVir ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2001-10-26 18:45 - 2001-10-26 18:45 - 00000742 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Loaded Modules (whitelisted) ============= 2011-06-14 13:19 - 2011-06-14 13:19 - 00535120 _____ () C:\Program Files\ArcaBit\ArcaAgent\ArcaRemoteSvc.exe 2014-12-29 22:19 - 2009-01-09 17:10 - 00139264 ____N () C:\Program Files\Brother\BrUtilities\BrLogAPI.dll 2011-01-14 12:38 - 2011-01-14 12:38 - 00178768 _____ () C:\Program Files\ArcaBit\arcavir\avshell.dll 2014-12-29 21:21 - 2014-11-26 17:40 - 03758192 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2014-12-30 00:50 - 2014-12-30 00:50 - 16843952 _____ () C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll 2006-10-26 13:56 - 2006-10-26 13:56 - 00757008 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{1a3e09be-1e45-494b-9174-d7385b45bbf5} => ""="" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-1214440339-362288127-725345543-500 - Administrator - Enabled) Gość (S-1-5-21-1214440339-362288127-725345543-501 - Limited - Disabled) MCU (S-1-5-21-1214440339-362288127-725345543-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\MCU Pomocnik (S-1-5-21-1214440339-362288127-725345543-1000 - Limited - Disabled) SUPPORT_388945a0 (S-1-5-21-1214440339-362288127-725345543-1002 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/06/2015 10:34:06 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd game.exe, wersja 0.0.0.0, moduł powodujący błąd game.exe, wersja 0.0.0.0, adres błędu 0x00150e9d. Przetwarzanie zdarzenia określonego nośnika dla [game.exe!ws!] Error: (12/30/2014 07:19:36 PM) (Source: MsiInstaller) (EventID: 11704) (User: MANCHESTER) Description: Produkt: Microsoft Office Shared MUI (Polish) 2007 — Błąd 1704. Instalacja produktu ArcaVir jest aktualnie wstrzymana. Aby kontynuować, musisz cofnąć zmiany wprowadzone przez tę instalację. Czy chcesz cofnąć te zmiany? Error: (12/30/2014 01:34:09 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd plugin-container.exe, wersja 34.0.5.5443, moduł powodujący błąd mozalloc.dll, wersja 34.0.5.5443, adres błędu 0x00001425. Przetwarzanie zdarzenia określonego nośnika dla [plugin-container.exe!ws!] Error: (12/30/2014 01:31:40 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd plugin-container.exe, wersja 34.0.5.5443, moduł powodujący błąd mozalloc.dll, wersja 34.0.5.5443, adres błędu 0x00001425. Przetwarzanie zdarzenia określonego nośnika dla [plugin-container.exe!ws!] Error: (12/30/2014 01:22:21 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd plugin-container.exe, wersja 34.0.5.5443, moduł powodujący błąd mozalloc.dll, wersja 34.0.5.5443, adres błędu 0x00001425. Przetwarzanie zdarzenia określonego nośnika dla [plugin-container.exe!ws!] Error: (12/30/2014 01:15:34 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd avastui.exe, wersja 10.0.2208.719, moduł powodujący błąd kernel32.dll, wersja 5.1.2600.5512, adres błędu 0x00012aeb. Przetwarzanie zdarzenia określonego nośnika dla [avastui.exe!ws!] Error: (12/30/2014 01:10:44 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd formatfactory.exe, wersja 3.5.1.0, moduł powodujący błąd mfc120u.dll, wersja 12.0.21005.1, adres błędu 0x0024e428. Przetwarzanie zdarzenia określonego nośnika dla [formatfactory.exe!ws!] Error: (12/30/2014 01:09:33 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Aplikacja powodująca błąd plugin-container.exe, wersja 34.0.5.5443, moduł powodujący błąd mozalloc.dll, wersja 34.0.5.5443, adres błędu 0x00001425. Przetwarzanie zdarzenia określonego nośnika dla [plugin-container.exe!ws!] Error: (12/30/2014 01:04:12 AM) (Source: MsiInstaller) (EventID: 11704) (User: MANCHESTER) Description: Product: ArcaVir Prerequistes -- Error 1704. An installation for ArcaVir is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes? System errors: ============= Error: (01/12/2015 01:54:37 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego: iSafeKrnlMon Error: (01/12/2015 01:22:50 AM) (Source: PlugPlayManager) (EventID: 11) (User: ) Description: Urządzenie Root\LEGACY_ISAFEKRNLR3\0000 zniknęło z systemu bez uprzedniego przygotowania go do usunięcia. Error: (01/12/2015 00:51:55 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Usługa Instalator Windows niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error: (01/11/2015 03:49:58 PM) (Source: Dhcp) (EventID: 1002) (User: ) Description: Adres IP połączenia 192.168.0.5 dla karty sieciowej o adresie 002421A5EE90 został zabroniony przez serwer DHCP 192.168.0.1 (Serwer DHCP wysłał komunikat DHCPNACK). Error: (01/04/2015 03:16:22 AM) (Source: 0) (EventID: 7) (User: ) Description: \Device\Harddisk0\D Error: (01/04/2015 03:16:22 AM) (Source: 0) (EventID: 5) (User: ) Description: \Device\Scsi\nvgts1 Error: (01/03/2015 02:49:27 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Usługa MobogenieService niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 1000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie. Error: (01/02/2015 11:47:30 PM) (Source: 0) (EventID: 7) (User: ) Description: \Device\Harddisk0\D Error: (01/02/2015 11:47:30 PM) (Source: 0) (EventID: 5) (User: ) Description: \Device\Scsi\nvgts1 Error: (01/02/2015 11:47:27 PM) (Source: 0) (EventID: 7) (User: ) Description: \Device\Harddisk0\D Microsoft Office Sessions: =========================