Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 483

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Strict Standards: Non-static method utf_normalizer::nfkc() should not be called statically in /home/mati/domains/forum.programosy.pl/public_html/includes/utf/utf_tools.php on line 1663
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3900: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3902: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3903: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3904: Cannot modify header information - headers already sent by (output started at /includes/bbcode.php:483)
znowu te wyskakujace reklamy! • programosy.pl

  • Ogłoszenie:

znowu te wyskakujace reklamy!

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Znowu te wyskakujace reklamy!

Postprzez zabkakum 22 Lis 2005, 09:17

reklama
Mam problem z wyskakujacymi reklamami i minimalizacja do paska. LOg z l2mfix

L2MFIX find log 1.04a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
"DLLName"="Ati2evxx.dll"
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000001
"Lock"="AtiLockEvent"
"Logoff"="AtiLogoffEvent"
"Logon"="AtiLogonEvent"
"Disconnect"="AtiDisConnectEvent"
"Reconnect"="AtiReConnectEvent"
"Safe"=dword:00000000
"Shutdown"="AtiShutdownEvent"
"StartScreenSaver"="AtiStartScreenSaverEvent"
"StartShell"="AtiStartShellEvent"
"Startup"="AtiStartupEvent"
"StopScreenSaver"="AtiStopScreenSaverEvent"
"Unlock"="AtiUnLockEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SMDEn]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\mv8ul9l91.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access ZARZ¤DZANIE NT\SYSTEM
(IO) ALLOW Full access ZARZ¤DZANIE NT\SYSTEM
(NI) ALLOW Full access ZARZ¤DZANIE NT\SYSTEM
(IO) ALLOW Full access ZARZ¤DZANIE NT\SYSTEM
(ID-CI) DENY --C------- BUILTIN\Administratorzy
(ID-NI) ALLOW Read BUILTIN\Uľytkownicy
(ID-IO) ALLOW Read BUILTIN\Uľytkownicy
(ID-NI) ALLOW Read BUILTIN\Uľytkownicy zaawansowani
(ID-IO) ALLOW Read BUILTIN\Uľytkownicy zaawansowani
(ID-NI) ALLOW Full access BUILTIN\Administratorzy
(ID-IO) ALLOW Full access BUILTIN\Administratorzy
(ID-NI) ALLOW Full access ZARZ¤DZANIE NT\SYSTEM
(ID-IO) ALLOW Full access ZARZ¤DZANIE NT\SYSTEM
(ID-IO) ALLOW Full access TWŕRCA-WťA—CICIEL


**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{1FF1A26C-4301-F9E0-77A1-954A6224A8CA}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Karta wˆa˜ciwo˜ci pliku multimedialnego"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ZarzĄdzanie skanerem ICM"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Strona zabezpieczeä NTFS"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Strona wˆa˜ciwo˜ci OLE Docfile"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Rozszerzenia powˆoki dla udost©pniania zasob˘w"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Rozszerzenie CPL karty graficznej"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Rozszerzenie CPL monitora wy˜wietlania"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Rozszerzenie CPL kadrowania wy˜wietlania"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Strona zabezpieczeä usˆugi DS"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Strona zgodno˜ci"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Program obsˆugi danych wycinkowych powˆoki"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Rozszerzenie Disc Copy"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Rozszerzenia powˆoki dla obiekt˘w Microsoft Windows Network"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ZarzĄdzanie monitorem ICM"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ZarzĄdzanie drukarkĄ ICM"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Rozszerzenia powˆoki dla kompresji plik˘w"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Rozszerzenie powˆoki drukarek sieci Web"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu kontekstowe szyfrowania"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Akt˘wka"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="Rozszerzenie ikony HyperTerminalu"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Strona zabezpieczeä drukarek"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Rozszerzenia powˆoki dla udost©pniania zasob˘w"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Rozszerzenie Crypto PKO"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Rozszerzenie Crypto Sign"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="PoˆĄczenia sieciowe"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="PoˆĄczenia sieciowe"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Skanery i aparaty fotograficzne"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Skanery i aparaty fotograficzne"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="&Skanery i aparaty fotograficzne"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Skanery i aparaty fotograficzne"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Skanery i aparaty fotograficzne"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Rozszerzenia powˆoki dla hosta skrypt˘w systemu Windows"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Zaplanowane zadania"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Pasek zadaä i menu Start"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Wyszukaj"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Pomoc i obsˆuga techniczna"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Pomoc i obsˆuga techniczna"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Uruchom..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Czcionki"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Narz©dzia administracyjne"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Pasek narz©dzi programu Microsoft Internet"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Stan pobierania"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Folder powˆoki zwi©kszonej"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Folder powˆoki zwi©kszonej 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Pasek przeglĄdarki Microsoft"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Pasek wyszukiwania"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Pasek multimedi˘w"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Wyszukiwanie w okienku"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Wyszukiwanie w sieci Web"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Narz©dzie opcji drzewa rejestru"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adres"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Pole edycji adresu"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Autouzupeˆnianie Microsoft"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="Wyodr©bnianie obraz˘w Trident"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="Lista autouzupeˆniania MRU"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Niestandardowa lista autouzupeˆniania MRU"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Dost©pny"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Pasek podr©czny ˜ledzenia"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analizator paska adresu"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Lista autouzupeˆniania historii Microsoft"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Lista autouzupeˆniania folderu powˆoki Microsoft"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Kontener wielu list autouzupeˆniania Microsoft"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu witryny paska powˆoki"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Pasek pulpitu powˆoki"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Pomoc dla uľytkownika"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Globalne ustawienia folder˘w"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="Historia"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Tymczasowe pliki internetowe"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Tymczasowe pliki internetowe"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Ekran powitalny pakietu IE4"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Pasek eksploratora"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="Folder pami©ci podr©cznej ActiveX"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Folder subskrypcji"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Menedľer aplikacji powˆoki"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Wyliczanie zainstalowanych aplikacji"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Publikator aplikacji Darwin"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+program wyodr©bniajĄcy miniatury plik˘w"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Informacje podsumowujĄce obsˆugi miniatur (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Wyodr©bnianie miniatur HTML"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Kreator publikacji w sieci Web"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Zamawianie odbitek w sieci Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Obiekt powˆoki kreatora publikacji"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Kreator uzyskiwania profilu usˆugi Passport"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="Konta uľytkownik˘w"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Plik kanaˆu"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Skr˘t kanaˆu"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Obiekt obsˆugi kanaˆu"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Folder plik˘w trybu offline"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="&Do os˘b..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow"
"{acb4a560-3606-11d3-aef4-00104bd0f92d}"="KodakShellExtension"
"{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}"="Adobe.Acrobat.ContextMenu"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Foldery w sieci Web"
"{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"="TrojanHunter Menu Shell Extension"
"{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{36518101-49AC-42CB-8E4C-40C1F328A565}"="Rad2 Extension"
"{5380C14E-C0A1-4D66-87DB-5995E6FF4623}"="Rad Extension"
"{75B8D633-9021-442C-9EA4-FF4BE72CE20F}"="NRad2 Extension"
"{C6844A1E-2C59-415A-84B3-C6A458372779}"="RadType Extension"
"{D00900BC-23F7-4FD6-BFA2-8232112C5C49}"="NRad Extension"
"{D2FD83AE-994A-4D4B-9097-2C9E11ED85F0}"="RadClkr Extension"
"{7700EB62-DB7C-47AF-A092-04376CA1D24C}"="RadMnu Extension"
"{5E2121EE-0300-11D4-8D3B-444553540000}"="st"
"{E2007745-5EF8-469B-870B-3D0687F3FFE1}"=""
"{403938F2-59DC-4C37-B258-55B78516B933}"=""
"{DEF5E964-097D-436D-A1BD-B76BF5534FF0}"=""
"{E14A81D0-5F7E-4587-BF9F-9C114D30FB29}"=""
"{B06F296C-0AB5-43F7-890C-75D70492BF47}"=""
"{13BFD0B9-3675-4903-BE34-4CA0990D4D0F}"=""
"{E12E4835-E85D-424A-B01E-DAFC17D9DEDB}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{E2007745-5EF8-469B-870B-3D0687F3FFE1}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E2007745-5EF8-469B-870B-3D0687F3FFE1}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E2007745-5EF8-469B-870B-3D0687F3FFE1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E2007745-5EF8-469B-870B-3D0687F3FFE1}\InprocServer32]
@="C:\\WINDOWS\\system32\\dcdmo.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{403938F2-59DC-4C37-B258-55B78516B933}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{403938F2-59DC-4C37-B258-55B78516B933}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{403938F2-59DC-4C37-B258-55B78516B933}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{403938F2-59DC-4C37-B258-55B78516B933}\InprocServer32]
@="C:\\WINDOWS\\system32\\mwident.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{DEF5E964-097D-436D-A1BD-B76BF5534FF0}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DEF5E964-097D-436D-A1BD-B76BF5534FF0}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DEF5E964-097D-436D-A1BD-B76BF5534FF0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DEF5E964-097D-436D-A1BD-B76BF5534FF0}\InprocServer32]
@="C:\\WINDOWS\\system32\\dkkquoui.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{E14A81D0-5F7E-4587-BF9F-9C114D30FB29}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E14A81D0-5F7E-4587-BF9F-9C114D30FB29}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E14A81D0-5F7E-4587-BF9F-9C114D30FB29}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E14A81D0-5F7E-4587-BF9F-9C114D30FB29}\InprocServer32]
@="C:\\WINDOWS\\system32\\duintf.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{B06F296C-0AB5-43F7-890C-75D70492BF47}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B06F296C-0AB5-43F7-890C-75D70492BF47}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B06F296C-0AB5-43F7-890C-75D70492BF47}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B06F296C-0AB5-43F7-890C-75D70492BF47}\InprocServer32]
@="C:\\WINDOWS\\system32\\mrvcr70.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{13BFD0B9-3675-4903-BE34-4CA0990D4D0F}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{13BFD0B9-3675-4903-BE34-4CA0990D4D0F}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{13BFD0B9-3675-4903-BE34-4CA0990D4D0F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{13BFD0B9-3675-4903-BE34-4CA0990D4D0F}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{E12E4835-E85D-424A-B01E-DAFC17D9DEDB}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E12E4835-E85D-424A-B01E-DAFC17D9DEDB}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E12E4835-E85D-424A-B01E-DAFC17D9DEDB}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E12E4835-E85D-424A-B01E-DAFC17D9DEDB}\InprocServer32]
@="C:\\WINDOWS\\system32\\kvdinbe1.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
bnbklcbn.dll Sat 2005-11-19 13:26:54 A.... 36 864 36,00 K
child.dll Sat 2005-11-12 10:40:56 A.... 14 336 14,00 K
chke.dll Sat 2005-11-19 13:26:58 A.... 53 248 52,00 K
cmdlin~1.dll Wed 2005-09-21 18:33:30 A.... 98 304 96,00 K
dgquery.dll Mon 2005-11-21 21:21:00 ..S.R 236 389 230,85 K
dkkquoui.dll Tue 2005-11-22 7:49:52 ..S.R 234 242 228,75 K
efmdidkl.dll Sat 2005-11-19 13:27:16 A.... 40 960 40,00 K
gkhlqifn.dll Sat 2005-11-12 10:40:56 A.... 36 864 36,00 K
hhhlflkj.dll Sat 2005-11-12 10:40:56 A.... 45 056 44,00 K
jtp407~1.dll Tue 2005-11-22 7:49:52 ..S.R 234 719 229,21 K
k4no0e~1.dll Mon 2005-11-21 15:40:44 ..S.R 236 743 231,19 K
kvdinbe1.dll Mon 2005-11-21 15:40:44 ..S.R 236 389 230,85 K
lonoocqc.dll Sat 2005-11-19 13:26:20 A.... 40 960 40,00 K
lvl609~1.dll Mon 2005-11-21 7:41:44 ..S.R 233 999 228,51 K
msctl32.dll Sat 2005-11-19 13:26:14 A.... 37 888 37,00 K
mv8ul9~1.dll Mon 2005-11-21 21:32:42 ..S.R 234 242 228,75 K
o448le~1.dll Mon 2005-11-21 21:20:10 ..S.R 236 528 230,98 K
sintf16.dll Sat 2005-09-17 14:15:40 A.... 12 067 11,78 K
sintf32.dll Sat 2005-09-17 14:15:40 A.... 17 212 16,81 K
sintfnt.dll Sat 2005-09-17 14:15:40 A.... 21 840 21,33 K
zlbw.dll Sat 2005-11-12 10:41:42 A.... 46 592 45,50 K

21 items found: 21 files (8 H/S), 0 directories.
Total of file sizes: 2 385 442 bytes 2,27 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Wolumin w stacji C nie ma etykiety.
Numer seryjny woluminu: 50FE-18C3

Katalog: C:\WINDOWS\System32

2005-11-22 07:49 234˙242 dkkquoui.dll
2005-11-22 07:49 234˙719 jtp4077qe.dll
2005-11-21 21:32 234˙242 mv8ul9l91.dll
2005-11-21 21:20 236˙389 dgquery.dll
2005-11-21 21:20 236˙528 o448lehu1h48.dll
2005-11-21 15:40 236˙389 kvdinbe1.dll
2005-11-21 15:40 236˙743 k4no0e53eh.dll
2005-11-21 07:41 233˙999 lvl6093se.dll
2005-10-28 11:25 <DIR> dllcache
2005-06-17 07:06 <DIR> Microsoft
2005-04-27 23:31 159˙813 RadType.dll
2005-04-27 23:30 65˙536 RadRegs.dll
2005-04-27 23:30 188˙416 RadExe.dll
2005-04-27 23:29 98˙304 RadClock.exe
2005-04-27 23:29 249˙856 RadClkR.dll
2005-04-27 23:28 536˙576 RadMnu.dll
2005-04-27 23:28 430˙080 Rad.dll
2005-04-27 23:26 167˙936 NRad.dll
2005-04-27 02:47 1˙403 Probe.inf
2005-04-27 02:46 20˙428 RadProbe.sys
2005-03-05 11:24 9˙424 radregs.inf
2005-03-05 08:48 61˙440 RadEnu.dll
2004-12-19 17:52 61˙440 RadPlk.dll
2004-12-07 01:35 61˙440 RadNlb.dll
2004-12-07 01:33 65˙536 RadIta.dll
2004-12-07 01:33 61˙440 RadHun.dll
2004-12-07 01:30 65˙536 RadFra.dll
2004-12-07 01:29 61˙440 RadEsp.dll
2004-12-07 01:02 53˙248 OEM.dll
2004-11-27 22:05 61˙440 RadDeu.dll
1999-09-30 18:21 166˙672 mstext35.dll
1999-09-28 20:42 1˙050˙896 msjet35.dll
1999-09-09 21:06 168˙720 msltus35.dll
1999-09-09 21:06 252˙688 msexcl35.dll
1999-08-25 13:57 415˙504 msrepl35.dll
1999-06-10 08:34 24˙848 msjter35.dll
1999-06-10 08:34 123˙664 msjint35.dll
1999-06-07 17:59 250˙128 mspdox35.dll
1999-04-25 16:00 252˙176 Msrd2x35.dll
1999-04-25 16:00 287˙504 Msxbse35.dll
1999-04-25 16:00 368˙912 Vbar332.dll
39 plik(˘w) 7˙725˙695 bajt˘w
2 katalog(˘w) 8˙875˙487˙232 bajt˘w wolnych
zabkakum
~user
 
Posty: 136
Dołączenie: 19 Mar 2005, 10:29
Miejscowość: Kraków



Postprzez Red 22 Lis 2005, 09:47

wstepnie przeskanuj kompa tym:
przeskanuj kompa :
http://www.ewido.net/en/download/
http://www.pobieralnia.pl/index.php/item-show/39f/

po scasnowaniu raz jeszcze dasz log z L2MFIX
Awatar użytkownika
Red
^zasłużony
 
Posty: 8694
Dołączenie: 01 Wrz 2005, 10:57
Miejscowość: Piaseczno
Pochwały: 701



Postprzez zabkakum 01 Gru 2005, 19:44

przeskanowalam innym ale to jest log:
Kod: Zaznacz wszystko
McAfee VirusScan for Win32 v4.40.0
Copyright (c) 1992-2004 Networks Associates Technology Inc. All rights reserved.
(408) 988-3832  LICENSED COPY - Sep 23 2004

Scan engine v4.4.00 for Win32.
Virus data file v4632 created Nov 18 2005
Scanning for 159869 viruses, trojans and variants.



12/01/2005  17:46:07


Options:
/ADL /ALL /ANALYSE /CLEAN /MAILBOX /MIME /NOEXPIRE /NORENAME /PANALYSE /PROGRAM /REPORT C:\MCAFEE.TXT /STREAMS /SUB /UNZIP /WINMEM

Scanning C: []
C:\secure32.html ... Found the StartPage-IH trojan !!!
        The file or process has been deleted.
Scanning C:\*.*
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\maxdd.game ... Found potentially unwanted program Dialer-257.
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\vx1.game\vx1.game\00003200.EXE ... Found the Spy-Birdi trojan !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\vx4.game\vx4.game ... Found the QDial-34 trojan !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\vxt4.game\vxt4.game ... Found the Generic Downloader.h trojan !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~1.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~11.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~13.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~15.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~17.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~19.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~1B.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~1C.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~1D.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~1F.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~23.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~25.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~27.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~29.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~2B.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~2D.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~2E.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~2F.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~3.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~31.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~33.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~35.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~37.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~39.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~3B.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~3D.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~3E.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~4F.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~5.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~56.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~7.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~9.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~AE.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~B.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~B1.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~B4.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~D.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kamil\Ustawienia lokalne\Temp\~F.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kasia\Menu Start\Internet Explorer.lnk ... Found potentially unwanted program Adware-ActivShop.lnk.
        The file or process has been deleted.
C:\Documents and Settings\Kasia\Menu Start\Programy\Power Scan\Power Scan.lnk ... Found potentially unwanted program PowerScan.lnk.
        The file or process has been deleted.
C:\Documents and Settings\Kasia\temp.bak\temp.bak ... Found the W32/Loosky.gen@MM virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kasia\Ustawienia lokalne\Temp\1213.4516 ... Found the Generic Downloader.f trojan !!!
        The file or process has been deleted.
C:\Documents and Settings\Kasia\Ustawienia lokalne\Temp\dmx6.tmp\dmx6.tmp ... Found the W32/Loosky.gen@MM virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Kasia\Ustawienia lokalne\Temp\qvxt2.game ... Found the Generic Downloader.f trojan !!!
        The file or process has been deleted.
C:\Documents and Settings\Kasia\Ustawienia lokalne\Temp\qvxt4.game\qvxt4.game ... Found the MultiDropper-OC trojan !!!
        The file or process has been deleted.
C:\Documents and Settings\Kasia\Ustawienia lokalne\Temporary Internet Files\Content.IE5\4L2RKH2J\osa6[2].gif ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Rodzice\Ustawienia lokalne\Temporary Internet Files\Content.IE5\AD2DUXG9\osa6[1].gif ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\Documents and Settings\Rodzice\Ustawienia lokalne\Temporary Internet Files\Content.IE5\AD2DUXG9\v010954[1].exe ... Found the Spy-Agent.k trojan !!!
        The file or process has been deleted.
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00017.dll ... Found the PWS-JA trojan !!!
        The file or process has been deleted.
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00017.exe ... Found the PWS-JA trojan !!!
        The file or process has been deleted.
C:\Program Files\Hyperlinker\uninst.exe ... Found potentially unwanted program Adware-LinkMaker.
        The file or process has been deleted.
C:\WINDOWS\10120859.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\16fd55nn.exe\16fd55nn.exe ... Found the Generic Downloader.u trojan !!!
        The file or process has been deleted.
C:\WINDOWS\2803203.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\3116156.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\3119765.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\3122843.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\350875.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\382687.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\403687.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\433359.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\4716656.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\490906.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\527765.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\5498609.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\733953.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\getb.exe ... Found the Spy-Agent.k trojan !!!
        The file or process has been deleted.
C:\WINDOWS\hammer.exe\hammer.exe ... Found the BackDoor-CLK trojan !!!
        The file or process has been deleted.
C:\WINDOWS\inet20021\alg.exe ... Found the W32/Generic.m virus !!!
        The file or process has been deleted.
C:\WINDOWS\inet20021\services.exe ... Found trojan or variant New Malware.j !!!
        Please send a copy of the file to McAfee
C:\WINDOWS\inet20041\services.exe ... Found the Downloader-AQV trojan !!!
        The file or process has been deleted.
C:\WINDOWS\j6vz2lyo.exe\j6vz2lyo.exe ... Found the Generic Downloader.u trojan !!!
        The file or process has been deleted.
C:\WINDOWS\k7rvgzp7.exe\k7rvgzp7.exe ... Found the Generic Downloader.k trojan !!!
        The file or process has been deleted.
C:\WINDOWS\loadnew.exe\loadnew.exe ... Found the Generic Downloader.u trojan !!!
        The file or process has been deleted.
C:\WINDOWS\sachostx.exe\sachostx.exe ... Found the W32/Loosky.gen@MM virus !!!
        The file or process has been deleted.
C:\WINDOWS\secure32.html ... Found the StartPage-IH trojan !!!
        The file or process has been deleted.
C:\WINDOWS\sysbinar\bin3.exe ... Found the BackDoor-AZV trojan !!!
        The file or process has been deleted.
C:\WINDOWS\sysbinar\bin4.exe ... Found the Downloader-AQV trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\birdihuy.dll ... Found potentially unwanted program Generic Adware.txt.
        The file or process has been deleted.
C:\WINDOWS\system32\birdihuy32.dll ... Found the Spy-Birdi trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\bnbklcbn.dll ... Found the Downloader-JF trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\bre.dll ... Found the Downloader-ABF trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\bre32.dll ... Found potentially unwanted program Generic Adware.txt.
        The file or process has been deleted.
C:\WINDOWS\system32\child.dll ... Found the Downloader-GS trojan !!!
C:\WINDOWS\system32\combo.exe ... Found the W32/Bagz.gen@MM virus !!!
        The file or process has been deleted.
C:\WINDOWS\system32\cuzovep.dll\cuzovep.dll ... Found the Downloader-NL trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\doser.exe ... Found the W32/Bagz.gen@MM virus !!!
        The file or process has been deleted.
C:\WINDOWS\system32\drivers\etc\hosts ... Found potentially unwanted program Adware-Look2Me!hosts.
        The virus has been removed from the file.
Checking for another virus in the file ...             
C:\WINDOWS\system32\efmdidkl.dll ... Found the Downloader-JF trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\gkhlqifn.dll ... Found the Downloader-JF trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\hhcbkmop.exe ... Found the Downloader-JF.dr trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\hhhlflkj.dll ... Found the Downloader-JF trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\hpcgipff.exe ... Found the Downloader-JF.dr trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\kernels32.exe ... Found the BackDoor-AZV trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\latest.exe ... Found the Galapoper trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\lonoocqc.dll ... Found the Downloader-JF trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\maxd1.exe ... Found potentially unwanted program Dialer-257.
        The file or process has been deleted.
C:\WINDOWS\system32\mdms.exe\mdms.exe ... Found the BackDoor-CLK trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\mmf32.exe ... Found the Generic BackDoor.d trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\paytime.exe\paytime.exe ... Found the StartPage-IH trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\PreUninstallHL.exe ... Found potentially unwanted program Adware-LinkMaker.
        The file or process has been deleted.
C:\WINDOWS\system32\qvxgamet2.exe ... Found the Generic Downloader.f trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\qvxgamet4.exe\qvxgamet4.exe ... Found the MultiDropper-OC trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\sender.exe ... Found the W32/Bagz.gen@MM virus !!!
        The file or process has been deleted.
C:\WINDOWS\system32\split1.exe ... Found the Generic Downloader.f trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\sysvcs.exe ... Found the Galapoper trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\vxgame1.exe\vxgame1.exe\00003200.EXE ... Found the Spy-Birdi trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\vxgamet1.exe ... Found the Generic Downloader.f trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\vxgamet4.exe\vxgamet4.exe ... Found the Generic Downloader.h trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\vxh8jkdq1.exe\vxh8jkdq1.exe ... Found potentially unwanted program Adware-AZESearch.dr.
        The file or process has been deleted.
C:\WINDOWS\system32\vxh8jkdq2.exe ... Found the Downloader-AFH trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\vxh8jkdq5.exe ... Found the Generic Downloader.f trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\vxh8jkdq6.exe ... Found the Generic Downloader.f trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\vxh8jkdq7.exe ... Found the Generic Downloader.f trojan !!!
        The file or process has been deleted.
C:\WINDOWS\system32\vxh8jkdq8.exe\vxh8jkdq8.exe ... Found potentially unwanted program Adware-AZESearch.dr.
        The file or process has been deleted.
C:\WINDOWS\system32\windll2.exe ... Found the W32/Bagle.gen virus !!!
        The file or process has been deleted.
C:\WINDOWS\system32\winsysms.exe ... Found trojan or variant New Malware.j !!!
        Please send a copy of the file to McAfee
C:\WINDOWS\system32\___e ... Found the W32/Maslan.eml virus !!!
        The file or process has been deleted.
C:\WINDOWS\system32\~update.exe ... Found the Galapoper trojan !!!
        The file or process has been deleted.
C:\WINDOWS\Temp\1.qtdfmp\1.qtdfmp ... Found potentially unwanted program Adware-AZESearch.dr.
        The file or process has been deleted.
C:\WINDOWS\Temp\2.qtdfmp ... Found the Downloader-AFH trojan !!!
        The file or process has been deleted.
C:\WINDOWS\Temp\5.qtdfmp ... Found the Generic Downloader.f trojan !!!
        The file or process has been deleted.
C:\WINDOWS\Temp\6.qtdfmp ... Found the Generic Downloader.f trojan !!!
        The file or process has been deleted.
C:\WINDOWS\Temp\7.qtdfmp ... Found the Generic Downloader.f trojan !!!
        The file or process has been deleted.
C:\WINDOWS\Temp\msarch.exe ... Found trojan or variant New Malware.u !!!
        Please send a copy of the file to McAfee
C:\WINDOWS\tool2.exe ... Found the Downloader-AFH trojan !!!
        The file or process has been deleted.

A file(s) requires a reboot to complete the repair.
You are recommended to reboot the computer.

Summary report on C:\*.*
File(s)
        Total files: ...........   81221
        Clean: .................   81078
        Possibly Infected: .....     119
        Cleaned: ...............       1
        Deleted: ...............     126
Non-critical Error(s):                 1
Master Boot Record(s): .........       1
        Possibly Infected: .....       0
Boot Sector(s): ................       1
        Possibly Infected: .....       0
Scanning G: []
Scanning G:\*.*
G:\backups\backup-20051112-104428-933.dll ... Found the PWS-Goldun trojan !!!
        The file or process has been deleted.
G:\backups\backup-20051201-171149-482.dll\backup-20051201-171149-482.dll ... Found the QLowZones-4 trojan !!!
        The file or process has been deleted.
G:\backups\backup-20051201-171149-556.dll ... Found potentially unwanted program Adware-AZESearch.
        The file or process has been deleted.
G:\backups\backup-20051201-171149-970.dll ... Found potentially unwanted program Adware-AZESearch.
        The file or process has been deleted.
zabkakum
~user
 
Posty: 136
Dołączenie: 19 Mar 2005, 10:29
Miejscowość: Kraków



Postprzez Red 01 Gru 2005, 20:25

zabkakum napisał(a):McAfee

>>>ok
przeskanuj rowniez ewido ,a log zamiesc z programu L2MFIX

wszystko co znajdą scanery postaraj sie usunac oczywiscie :)
Awatar użytkownika
Red
^zasłużony
 
Posty: 8694
Dołączenie: 01 Wrz 2005, 10:57
Miejscowość: Piaseczno
Pochwały: 701



Postprzez zabkakum 02 Gru 2005, 08:35

Kod: Zaznacz wszystko
L2MFIX find log 1.04a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
"DLLName"="Ati2evxx.dll"
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000001
"Lock"="AtiLockEvent"
"Logoff"="AtiLogoffEvent"
"Logon"="AtiLogonEvent"
"Disconnect"="AtiDisConnectEvent"
"Reconnect"="AtiReConnectEvent"
"Safe"=dword:00000000
"Shutdown"="AtiShutdownEvent"
"StartScreenSaver"="AtiStartScreenSaverEvent"
"StartShell"="AtiStartShellEvent"
"Startup"="AtiStartupEvent"
"StopScreenSaver"="AtiStopScreenSaverEvent"
"Unlock"="AtiUnLockEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
  6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
  6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
  6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
  6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
  6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI)    ALLOW  Full access    ZARZ¤DZANIE NT\SYSTEM
(IO)    ALLOW  Full access    ZARZ¤DZANIE NT\SYSTEM
(ID-CI) DENY   --C-------      BUILTIN\Administratorzy
(ID-NI) ALLOW  Read           BUILTIN\Uľytkownicy
(ID-IO) ALLOW  Read           BUILTIN\Uľytkownicy
(ID-NI) ALLOW  Read           BUILTIN\Uľytkownicy zaawansowani
(ID-IO) ALLOW  Read           BUILTIN\Uľytkownicy zaawansowani
(ID-NI) ALLOW  Full access    BUILTIN\Administratorzy
(ID-IO) ALLOW  Full access    BUILTIN\Administratorzy
(ID-NI) ALLOW  Full access    ZARZ¤DZANIE NT\SYSTEM
(ID-IO) ALLOW  Full access    ZARZ¤DZANIE NT\SYSTEM
(ID-IO) ALLOW  Full access    TWŕRCA-WťA—CICIEL


**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{1FF1A26C-4301-F9E0-77A1-954A6224A8CA}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Karta wˆa˜ciwo˜ci pliku multimedialnego"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ZarzĄdzanie skanerem ICM"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Strona zabezpieczeä NTFS"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Strona wˆa˜ciwo˜ci OLE Docfile"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Rozszerzenia powˆoki dla udost&copy;pniania zasob˘w"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Rozszerzenie CPL karty graficznej"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Rozszerzenie CPL monitora wy˜wietlania"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Rozszerzenie CPL kadrowania wy˜wietlania"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Strona zabezpieczeä usˆugi DS"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Strona zgodno˜ci"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Program obsˆugi danych wycinkowych powˆoki"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Rozszerzenie Disc Copy"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Rozszerzenia powˆoki dla obiekt˘w Microsoft Windows Network"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ZarzĄdzanie monitorem ICM"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ZarzĄdzanie drukarkĄ ICM"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Rozszerzenia powˆoki dla kompresji plik˘w"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Rozszerzenie powˆoki drukarek sieci Web"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu kontekstowe szyfrowania"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Akt˘wka"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="Rozszerzenie ikony HyperTerminalu"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Strona zabezpieczeä drukarek"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Rozszerzenia powˆoki dla udost&copy;pniania zasob˘w"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Rozszerzenie Crypto PKO"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Rozszerzenie Crypto Sign"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="PoˆĄczenia sieciowe"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="PoˆĄczenia sieciowe"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Skanery i aparaty fotograficzne"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Skanery i aparaty fotograficzne"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="&Skanery i aparaty fotograficzne"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Skanery i aparaty fotograficzne"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Skanery i aparaty fotograficzne"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Rozszerzenia powˆoki dla hosta skrypt˘w systemu Windows"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Zaplanowane zadania"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Pasek zadaä i menu Start"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Wyszukaj"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Pomoc i obsˆuga techniczna"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Pomoc i obsˆuga techniczna"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Uruchom..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Czcionki"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Narz&copy;dzia administracyjne"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Pasek narz&copy;dzi programu Microsoft Internet"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Stan pobierania"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Folder powˆoki zwi&copy;kszonej"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Folder powˆoki zwi&copy;kszonej 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Pasek przeglĄdarki Microsoft"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Pasek wyszukiwania"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Pasek multimedi˘w"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Wyszukiwanie w okienku"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Wyszukiwanie w sieci Web"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Narz&copy;dzie opcji drzewa rejestru"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adres"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Pole edycji adresu"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Autouzupeˆnianie Microsoft"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="Wyodr&copy;bnianie obraz˘w Trident"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="Lista autouzupeˆniania MRU"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Niestandardowa lista autouzupeˆniania MRU"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Dost&copy;pny"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Pasek podr&copy;czny ˜ledzenia"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analizator paska adresu"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Lista autouzupeˆniania historii Microsoft"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Lista autouzupeˆniania folderu powˆoki Microsoft"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Kontener wielu list autouzupeˆniania Microsoft"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu witryny paska powˆoki"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Pasek pulpitu powˆoki"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Pomoc dla uľytkownika"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Globalne ustawienia folder˘w"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="Historia"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Tymczasowe pliki internetowe"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Tymczasowe pliki internetowe"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Ekran powitalny pakietu IE4"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Pasek eksploratora"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="Folder pami&copy;ci podr&copy;cznej ActiveX"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Folder subskrypcji"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Menedľer aplikacji powˆoki"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Wyliczanie zainstalowanych aplikacji"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Publikator aplikacji Darwin"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+program wyodr&copy;bniajĄcy miniatury plik˘w"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Informacje podsumowujĄce obsˆugi miniatur (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Wyodr&copy;bnianie miniatur HTML"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Kreator publikacji w sieci Web"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Zamawianie odbitek w sieci Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Obiekt powˆoki kreatora publikacji"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Kreator uzyskiwania profilu usˆugi Passport"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="Konta uľytkownik˘w"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Plik kanaˆu"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Skr˘t kanaˆu"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Obiekt obsˆugi kanaˆu"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Folder plik˘w trybu offline"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="&Do os˘b..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow"
"{acb4a560-3606-11d3-aef4-00104bd0f92d}"="KodakShellExtension"
"{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}"="Adobe.Acrobat.ContextMenu"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Foldery w sieci Web"
"{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"="TrojanHunter Menu Shell Extension"
"{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{36518101-49AC-42CB-8E4C-40C1F328A565}"="Rad2 Extension"
"{5380C14E-C0A1-4D66-87DB-5995E6FF4623}"="Rad Extension"
"{75B8D633-9021-442C-9EA4-FF4BE72CE20F}"="NRad2 Extension"
"{C6844A1E-2C59-415A-84B3-C6A458372779}"="RadType Extension"
"{D00900BC-23F7-4FD6-BFA2-8232112C5C49}"="NRad Extension"
"{D2FD83AE-994A-4D4B-9097-2C9E11ED85F0}"="RadClkr Extension"
"{7700EB62-DB7C-47AF-A092-04376CA1D24C}"="RadMnu Extension"
"{5E2121EE-0300-11D4-8D3B-444553540000}"="st"
"{E2007745-5EF8-469B-870B-3D0687F3FFE1}"=""
"{403938F2-59DC-4C37-B258-55B78516B933}"=""
"{E14A81D0-5F7E-4587-BF9F-9C114D30FB29}"=""
"{B06F296C-0AB5-43F7-890C-75D70492BF47}"=""
"{13BFD0B9-3675-4903-BE34-4CA0990D4D0F}"=""
"{E12E4835-E85D-424A-B01E-DAFC17D9DEDB}"=""
"{E23E81AC-FB07-487F-8EAF-4443DC218D29}"=""
"{ACF556F9-94A8-4EEC-B0CA-35FF907055F2}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{E2007745-5EF8-469B-870B-3D0687F3FFE1}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E2007745-5EF8-469B-870B-3D0687F3FFE1}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E2007745-5EF8-469B-870B-3D0687F3FFE1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E2007745-5EF8-469B-870B-3D0687F3FFE1}\InprocServer32]
@="C:\\WINDOWS\\system32\\dcdmo.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{403938F2-59DC-4C37-B258-55B78516B933}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{403938F2-59DC-4C37-B258-55B78516B933}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{403938F2-59DC-4C37-B258-55B78516B933}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{403938F2-59DC-4C37-B258-55B78516B933}\InprocServer32]
@="C:\\WINDOWS\\system32\\mwident.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{E14A81D0-5F7E-4587-BF9F-9C114D30FB29}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E14A81D0-5F7E-4587-BF9F-9C114D30FB29}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E14A81D0-5F7E-4587-BF9F-9C114D30FB29}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E14A81D0-5F7E-4587-BF9F-9C114D30FB29}\InprocServer32]
@="C:\\WINDOWS\\system32\\duintf.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{B06F296C-0AB5-43F7-890C-75D70492BF47}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B06F296C-0AB5-43F7-890C-75D70492BF47}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B06F296C-0AB5-43F7-890C-75D70492BF47}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B06F296C-0AB5-43F7-890C-75D70492BF47}\InprocServer32]
@="C:\\WINDOWS\\system32\\mrvcr70.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{13BFD0B9-3675-4903-BE34-4CA0990D4D0F}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{13BFD0B9-3675-4903-BE34-4CA0990D4D0F}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{13BFD0B9-3675-4903-BE34-4CA0990D4D0F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{13BFD0B9-3675-4903-BE34-4CA0990D4D0F}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{E12E4835-E85D-424A-B01E-DAFC17D9DEDB}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E12E4835-E85D-424A-B01E-DAFC17D9DEDB}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E12E4835-E85D-424A-B01E-DAFC17D9DEDB}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E12E4835-E85D-424A-B01E-DAFC17D9DEDB}\InprocServer32]
@="C:\\WINDOWS\\system32\\clmuid.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{E23E81AC-FB07-487F-8EAF-4443DC218D29}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E23E81AC-FB07-487F-8EAF-4443DC218D29}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E23E81AC-FB07-487F-8EAF-4443DC218D29}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E23E81AC-FB07-487F-8EAF-4443DC218D29}\InprocServer32]
@="C:\\WINDOWS\\system32\\iggutil.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{ACF556F9-94A8-4EEC-B0CA-35FF907055F2}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{ACF556F9-94A8-4EEC-B0CA-35FF907055F2}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{ACF556F9-94A8-4EEC-B0CA-35FF907055F2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{ACF556F9-94A8-4EEC-B0CA-35FF907055F2}\InprocServer32]
@="C:\\WINDOWS\\system32\\syhcinst.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
   chke.dll       Sat  2005-11-19  13:26:58   A....         53 248    52,00 K
   chp.dll        Thu  2005-12-01  17:06:56   A....         16 384    16,00 K
   clmuid.dll     Thu  2005-12-01  16:42:10   ..S.R        235 618   230,09 K
   cmdlin~1.dll   Wed  2005-09-21  18:33:30   A....         98 304    96,00 K
   d4j0le~1.dll   Wed  2005-11-30   7:30:24   ..S.R        236 330   230,79 K
   d6j0lg~1.dll   Wed  2005-11-30  16:32:38   ..S.R        235 434   229,91 K
   ddr64.dll      Thu  2005-12-01  17:06:56   A....             27     0,02 K
   ddskmon.dll    Thu  2005-12-01  17:10:02   ..S.R        235 618   230,09 K
   dgquery.dll    Mon  2005-11-21  21:21:00   ..S.R        236 389   230,85 K
   dn8s01~1.dll   Sun  2005-11-27  15:06:58   ..S.R        233 638   228,16 K
   dwsec.dll      Thu  2005-12-01  17:31:04   ..S.R        236 137   230,60 K
   en46l1~1.dll   Sat  2005-11-26  13:49:36   ..S.R        234 357   228,86 K
   enrql1~1.dll   Fri  2005-11-25  14:44:16   ..S.R        235 394   229,88 K
   f8j20i~1.dll   Tue  2005-11-22  13:03:44   ..S.R        234 937   229,43 K
   fp2603~1.dll   Tue  2005-11-22  15:24:38   .....        235 342   229,82 K
   fpl003~1.dll   Mon  2005-11-28  15:12:10   ..S.R        234 134   228,64 K
   h2l20c~1.dll   Thu  2005-12-01  16:26:50   ..S.R        235 850   230,32 K
   hvetcfg.dll    Thu  2005-11-24  14:41:26   ..S.R        236 866   231,31 K
   i4600e~1.dll   Sun  2005-11-27  14:49:22   ..S.R        237 231   231,67 K
   iggutil.dll    Wed  2005-11-30  16:32:34   ..S.R        233 966   228,48 K
   ir08l5~1.dll   Thu  2005-12-01  17:06:16   ..S.R        234 150   228,66 K
   j0j60a~1.dll   Sun  2005-11-27  11:58:44   ..S.R        236 242   230,70 K
   j4l40e~1.dll   Thu  2005-11-24  17:39:16   ..S.R        233 803   228,32 K
   j82qli~1.dll   Thu  2005-11-24  16:43:44   ..S.R        235 331   229,81 K
   j8p0li~1.dll   Tue  2005-11-22   9:56:54   ..S.R        234 242   228,75 K
   k4no0e~1.dll   Mon  2005-11-21  15:40:44   ..S.R        236 743   231,19 K
   lv8o09~1.dll   Thu  2005-12-01  16:42:10   ..S.R        236 007   230,47 K
   lvl609~1.dll   Mon  2005-11-21   7:41:44   ..S.R        233 999   228,51 K
   msctl32.dll    Thu  2005-12-01  16:39:48   A....         37 888    37,00 K
   msg3922.dll    Thu  2005-12-01  17:40:14   A....         39 200    38,28 K
   msupda~1.dll   Thu  2005-12-01  17:07:22   A....        473 088   462,00 K
   msvcrl.dll     Thu  2005-12-01  17:07:30   A....          8 567     8,36 K
   mvj8l9~1.dll   Fri  2005-11-25  15:04:26   ..S.R        233 803   228,32 K
   nbevtmsg.dll   Thu  2005-12-01  17:06:16   ..S.R        235 618   230,09 K
   o448le~1.dll   Mon  2005-11-21  21:20:10   ..S.R        236 528   230,98 K
   o6rolg~1.dll   Thu  2005-12-01  17:14:24   ..S.R        233 946   228,46 K
   q0nula~1.dll   Tue  2005-11-29  10:18:24   ..S.R        234 101   228,61 K
   q6rqlg~1.dll   Sat  2005-11-26  12:59:40   ..S.R        235 953   230,42 K
   r4p80e~1.dll   Mon  2005-11-28  19:57:18   .....        234 706   229,20 K
   rpcxss.dll     Thu  2005-12-01  16:39:36   A....         24 576    24,00 K
   sintf16.dll    Sat  2005-09-17  14:15:40   A....         12 067    11,78 K
   sintf32.dll    Sat  2005-09-17  14:15:40   A....         17 212    16,81 K
   sintfnt.dll    Sat  2005-09-17  14:15:40   A....         21 840    21,33 K
   st3.dll        Thu  2005-12-01  16:43:14   A....         70 144    68,50 K
   syhcinst.dll   Wed  2005-11-30  17:57:28   ..S.R        234 092   228,61 K
   szprv.dll      Thu  2005-12-01  18:43:18   ..S.R        235 618   230,09 K
   zlbw.dll       Sat  2005-11-12  10:41:42   A....         46 592    45,50 K

47 items found:  47 files (31 H/S), 0 directories.
   Total of file sizes:  8 681 260 bytes      8,28 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Wolumin w stacji C nie ma etykiety.
Numer seryjny woluminu: 50FE-18C3

Katalog: C:\WINDOWS\System32

2005-12-01  18:43           235˙618 szprv.dll
2005-12-01  17:31           236˙137 dwsec.dll
2005-12-01  17:14           233˙946 o6rolg9316.dll
2005-12-01  17:10           235˙618 ddskmon.dll
2005-12-01  17:06           235˙618 nbevtmsg.dll
2005-12-01  17:06           234˙150 ir08l5du1.dll
2005-12-01  16:42           235˙618 clmuid.dll
2005-12-01  16:42           236˙007 lv8o09l3e.dll
2005-12-01  16:26           235˙850 h2l20c3oef.dll
2005-11-30  17:57           234˙092 syhcinst.dll
2005-11-30  16:32           235˙434 d6j0lg1m16.dll
2005-11-30  16:32           233˙966 iggutil.dll
2005-11-30  07:30           236˙330 d4j0le1m1h.dll
2005-11-29  10:18           234˙101 q0nula591d.dll
2005-11-28  15:12           234˙134 fpl0033me.dll
2005-11-27  15:06           233˙638 dn8s01l7e.dll
2005-11-27  14:49           237˙231 i4600ejmehoa0.dll
2005-11-27  11:58           236˙242 j0j60a1sed.dll
2005-11-26  13:49           234˙357 en46l1hs1.dll
2005-11-26  12:59           235˙953 q6rqlg9516.dll
2005-11-25  15:04           233˙803 mvj8l91u1.dll
2005-11-25  14:44           235˙394 enrql1951.dll
2005-11-24  17:39           233˙803 j4l40e3qeh.dll
2005-11-24  16:43           235˙331 j82qlif5182.dll
2005-11-24  14:41           236˙866 hvetcfg.dll
2005-11-22  13:03           234˙937 f8j20i1oe8.dll
2005-11-22  09:56           234˙242 j8p0li7m18.dll
2005-11-21  21:20           236˙389 dgquery.dll
2005-11-21  21:20           236˙528 o448lehu1h48.dll
2005-11-21  15:40           236˙743 k4no0e53eh.dll
2005-11-21  07:41           233˙999 lvl6093se.dll
2005-06-17  07:06    <DIR>          Microsoft
2005-04-27  23:31           159˙813 RadType.dll
2005-04-27  23:30            65˙536 RadRegs.dll
2005-04-27  23:30           188˙416 RadExe.dll
2005-04-27  23:29            98˙304 RadClock.exe
2005-04-27  23:29           249˙856 RadClkR.dll
2005-04-27  23:28           536˙576 RadMnu.dll
2005-04-27  23:28           430˙080 Rad.dll
2005-04-27  23:26           167˙936 NRad.dll
2005-04-27  02:47             1˙403 Probe.inf
2005-04-27  02:46            20˙428 RadProbe.sys
2005-03-05  11:24             9˙424 radregs.inf
2005-03-05  08:48            61˙440 RadEnu.dll
2004-12-19  17:52            61˙440 RadPlk.dll
2004-12-07  01:35            61˙440 RadNlb.dll
2004-12-07  01:33            65˙536 RadIta.dll
2004-12-07  01:33            61˙440 RadHun.dll
2004-12-07  01:30            65˙536 RadFra.dll
2004-12-07  01:29            61˙440 RadEsp.dll
2004-12-07  01:02            53˙248 OEM.dll
2004-11-27  22:05            61˙440 RadDeu.dll
2002-08-05  16:39    <DIR>          dllcache
1999-09-30  18:21           166˙672 mstext35.dll
1999-09-28  20:42         1˙050˙896 msjet35.dll
1999-09-09  21:06           252˙688 msexcl35.dll
1999-09-09  21:06           168˙720 msltus35.dll
1999-08-25  13:57           415˙504 msrepl35.dll
1999-06-10  08:34            24˙848 msjter35.dll
1999-06-10  08:34           123˙664 msjint35.dll
1999-06-07  17:59           250˙128 mspdox35.dll
1999-04-25  16:00           252˙176 Msrd2x35.dll
1999-04-25  16:00           368˙912 Vbar332.dll
1999-04-25  16:00           287˙504 Msxbse35.dll
              62 plik(˘w)      13˙134˙519 bajt˘w
               2 katalog(˘w)   9˙071˙869˙952 bajt˘w wolnych



aha i porobilam pare rzeczy i te stronki i reklamy juz nie wyskakuja (narazie) ale strasznie zamula kompa :/ pewnie cos w nim jeszcze siedzi tylko pomozcie to usunac please!

[ Dodano: Dzisiaj o 8:35 ]
z góry prosze nie zbanujcie mnie, bo pisze po to zeby ktos zauwazyl ojego posta i w wilekiej desperacji :P dziekuje :D
zabkakum
~user
 
Posty: 136
Dołączenie: 19 Mar 2005, 10:29
Miejscowość: Kraków




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 14 gości