

[b]LOG Z RSIT[/b]
Logfile of random's system information tool 1.06 (written by random/random)
Run by MT at 2009-06-19 19:19:34
Microsoft Windows XP Professional Dodatek Service Pack 2
System drive C: has 8 GB (21%) free of 39 GB
Total RAM: 1022 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:22:03, on 2009-06-19
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Common Files\BinarySense\hldasvc.exe
C:\Program Files\Common Files\BinarySense\hldasvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Vista Drive Icon\DrvIcon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Vista Sidebar\sidebar.exe
D:\Program Files\VisualTaskTips\VisualTaskTips.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
D:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
D:\Program Files\SysInfoMyWork\SysInfoMyWork.exe
C:\WINDOWS\explorer.exe
D:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Documents and Settings\MT\Pulpit\RSITv.exe
C:\Program Files\trend micro\MT.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchgateway.net/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - D:\Program Files\Desktop Sidebar\sbhelp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Expressivo - {85F685C3-20D9-4943-95E4-EB4224056C3F} - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O3 - Toolbar: Expressivo - {85F685C3-20D9-4943-95E4-EB4224056C3F} - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll
O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
O4 - HKLM\..\Run: [WellPhone DirectSync - ScheduleSync] D:\PROGRA~1\WELLPH~1\SCHEDU~1.EXE
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [DrvIcon] D:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Windows Intranet controller] C:\WINDOWS\security\lsass.exe
O4 - HKCU\..\Run: [Vista Sidebar] C:\Program Files\Vista Sidebar\sidebar.exe
O4 - HKCU\..\Run: [VisualTaskTips] D:\Program Files\VisualTaskTips\VisualTaskTips.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\WINDOWS\ERUNT\AUTOBACK.EXE
O4 - Startup: HDDlife.lnk = C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
O4 - Startup: Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: SyncBack.lnk = D:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
O4 - Startup: SysInfoMyWork.lnk = D:\Program Files\SysInfoMyWork\SysInfoMyWork.exe
O4 - Startup: Thoosje Vista Sidebar.lnk = C:\Program Files\Vista Sidebar\sidebar.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Ustawienia Outpost Security Suite Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Security Suite Pro\ie_bar.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{93791610-F0BC-4990-A977-06B47E9077D5}: NameServer = 212.2.96.52 212.2.96.51
O18 - Protocol: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - "C:\Program Files\Common Files\BinarySense\hlAPP.dll" (file missing)
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: HDDlife HDD Access service - BinarySense, Inc. - C:\Program Files\Common Files\BinarySense\hldasvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 7276 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GlaryInitialize.job
C:\WINDOWS\tasks\SyncBack Adv disk catalog.job
C:\WINDOWS\tasks\SyncBack Documents and SettingsMTDane aplikacjiThunderbird.job
C:\WINDOWS\tasks\SyncBack Documents and SettingsRobertGadu-Gadu.job
C:\WINDOWS\tasks\SyncBack GG marcin.job
C:\WINDOWS\tasks\SyncBack MTDane aplikacjiMyPhoneExplorer.job
C:\WINDOWS\tasks\SyncBack My phone explorer.job
C:\WINDOWS\tasks\SyncBack Nowe gg MT.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45AD732C-2CE2-4666-B366-B2214AD57A49}]
Idea2 SidebarBrowserMonitor Class - D:\Program Files\Desktop Sidebar\sbhelp.dll [2006-07-09 278528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 440056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{85F685C3-20D9-4943-95E4-EB4224056C3F}]
Expressivo - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll [2007-05-15 315392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - StylerToolBar - C:\Program Files\Styler\TB\StylerTB.dll [2006-05-02 102400]
{85F685C3-20D9-4943-95E4-EB4224056C3F} - Expressivo - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll [2007-05-15 315392]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"OutpostMonitor"=C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe [2008-08-25 1208664]
"WellPhone DirectSync - ScheduleSync"=D:\PROGRA~1\WELLPH~1\SCHEDU~1.EXE [2005-08-08 45056]
"VisualTooltip"= []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"DrvIcon"=D:\Program Files\Vista Drive Icon\DrvIcon.exe [2008-04-13 49152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"Windows Intranet controller"=C:\WINDOWS\security\lsass.exe [2009-04-08 1826871]
"Vista Sidebar"=C:\Program Files\Vista Sidebar\sidebar.exe [2007-11-20 524288]
"VisualTaskTips"=D:\Program Files\VisualTaskTips\VisualTaskTips.exe [2006-05-28 36864]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
D:\Program Files\Gadu-GaduR\gg.exe [2008-03-20 2127296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sTabLauncher]
D:\Program Files\sTabLauncher\sTabLauncher.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Live]
C:\Documents and Settings\MT\Dane aplikacji\WindowsLive.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Core Temp.lnk]
D:\PROGRA~1\CoreTemp\CORETE~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UPS"=3
"Autodesk Licensing Service"=3
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Documents and Settings\MT\Menu Start\Programy\Autostart
ERUNT AutoBackup.lnk - C:\WINDOWS\ERUNT\AUTOBACK.EXE
HDDlife.lnk - C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
Stardock ObjectDock.lnk - D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
SyncBack.lnk - D:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
SysInfoMyWork.lnk - D:\Program Files\SysInfoMyWork\SysInfoMyWork.exe
Thoosje Vista Sidebar.lnk - C:\Program Files\Vista Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-06-13 118784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=36
"NoRecycleFiles"=0
"NoWelcomeScreen"=0
"NoStartMenuEjectPC"=0
"EditLevel"=0
"NoCommonGroups"=0
"NoDriveAutoRun"=FFFFFFFF
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoStartMenuEjectPC"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"D:\Program Files\Gadu-Gadu\gg.exe"="D:\Program Files\Gadu-Gadu\gg.exe:*:Enabled:Gadu-Gadu - program główny"
"D:\Program Files\Sony Ericsson\Update Service\Update Service.exe"="D:\Program Files\Sony Ericsson\Update Service\Update Service.exe:*:Enabled:Update Service"
"D:\Program Files\ICQ6\ICQ.exe"="D:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Documents and Settings\MT\Pulpit\utorrent-1.8-rc7.upx.exe"="C:\Documents and Settings\MT\Pulpit\utorrent-1.8-rc7.upx.exe:*:Enabled:µTorrent"
"D:\Program Files\uTorrent\utorrent-1.8-rc7.upx.exe"="D:\Program Files\uTorrent\utorrent-1.8-rc7.upx.exe:*:Enabled:µTorrent"
"D:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe"="D:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager"
"D:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe"="D:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"D:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe"="D:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe:*:Enabled:umi"
"D:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe"="D:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
shell\AutoRun\command - D:\explorefiles.exe
shell\explore\command - D:\explorefiles.exe
shell\open\command - D:\explorefiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
shell\AutoRun\command - E:\explorefiles.exe
shell\explore\command - E:\explorefiles.exe
shell\open\command - E:\explorefiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\P]
shell\AutoRun\command - P:\explorefiles.exe
shell\explore\command - P:\explorefiles.exe
shell\open\command - P:\explorefiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\R]
shell\AutoRun\command - R:\explorefiles.exe
shell\explore\command - R:\explorefiles.exe
shell\open\command - R:\explorefiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1de35da4-e47b-11dc-8d8a-c78261217473}]
shell\AutoRun\command - S:\explorefiles.exe
shell\explore\command - S:\explorefiles.exe
shell\open\command - S:\explorefiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7384ae84-857a-11dd-8ffb-0011679add53}]
shell\AutoRun\command - P:\explorefiles.exe
shell\explore\command - P:\explorefiles.exe
shell\open\command - P:\explorefiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97ae7c71-e474-11dc-95a0-806d6172696f}]
shell\AutoRun\command - E:\viewfiles.exe
shell\explore\command - E:\viewfiles.exe
shell\open\command - E:\viewfiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d54df804-2cc4-11de-921d-0011679add53}]
shell\AutoRun\command - P:\explorefiles.exe
shell\explore\command - P:\explorefiles.exe
shell\open\command - P:\explorefiles.exe
======File associations======
.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 months======
2009-06-19 19:19:34 ----D---- C:\rsit
2009-06-19 19:19:34 ----D---- C:\Program Files\trend micro
2009-06-19 17:59:44 ----RASHD---- C:\autorun.inf
2009-06-18 18:46:47 ----A---- C:\WINDOWS\system32\CF30042.exe
2009-06-18 18:44:44 ----A---- C:\WINDOWS\system32\CF29595.exe
2009-06-17 20:39:07 ----A---- C:\WINDOWS\ntbtlog.txt
2009-06-12 19:49:06 ----D---- C:\Documents and Settings\MT\Dane aplikacji\Stardock
2009-06-12 18:40:46 ----A---- C:\WINDOWS\unins004.exe
2009-06-10 17:04:43 ----D---- C:\Documents and Settings\MT\Dane aplikacji\AVI ReComp
2009-06-05 15:43:09 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\BVRP Software
2009-06-01 18:39:09 ----D---- C:\Program Files\TRACERMM SOFT
2009-05-21 22:41:19 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\KLS Soft
======List of files/folders modified in the last 1 months======
2009-06-19 19:19:34 ----D---- C:\Program Files
2009-06-19 18:37:30 ----D---- C:\WINDOWS\Temp
2009-06-19 18:06:50 ----A---- C:\WINDOWS\ModemLog_Sony Ericsson K320 USB WMC Data Modem.txt
2009-06-19 17:31:38 ----AD---- C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2009-06-19 17:30:05 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-06-19 17:29:21 ----D---- C:\Program Files\Stardock
2009-06-19 16:45:08 ----SH---- C:\boot.ini
2009-06-19 16:45:08 ----A---- C:\WINDOWS\win.ini
2009-06-19 16:45:08 ----A---- C:\WINDOWS\system.ini
2009-06-19 16:23:29 ----D---- C:\WINDOWS
2009-06-19 14:57:37 ----A---- C:\WINDOWS\ModemLog_Mobile 115200.txt
2009-06-19 12:25:20 ----A---- C:\WINDOWS\NeroDigital.ini
2009-06-18 19:30:07 ----D---- C:\Program Files\Downloaded Installations
2009-06-18 19:28:48 ----D---- C:\WINDOWS\system32
2009-06-18 19:26:40 ----D---- C:\Temp
2009-06-18 18:50:39 ----D---- C:\WINDOWS\security
2009-06-18 18:45:49 ----D---- C:\WINDOWS\system32\drivers
2009-06-18 18:44:49 ----D---- C:\WINDOWS\ERDNT
2009-06-18 18:44:44 ----D---- C:\WINDOWS\system32\CatRoot2
2009-06-18 18:44:24 ----D---- C:\WINDOWS\Prefetch
2009-06-17 20:42:54 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-06-17 20:41:14 ----D---- C:\WINDOWS\ERUNT
2009-06-15 18:57:18 ----SHD---- C:\WINDOWS\Installer
2009-06-15 18:57:17 ----HD---- C:\Config.Msi
2009-06-15 18:53:00 ----D---- C:\WINDOWS\system32\config
2009-06-15 18:51:13 ----D---- C:\WINDOWS\system32\wbem
2009-06-15 18:51:12 ----D---- C:\WINDOWS\Registration
2009-06-12 19:54:32 ----RSD---- C:\WINDOWS\assembly
2009-06-12 16:06:37 ----A---- C:\WINDOWS\ModemLog_Bluetooth DUN Modem.txt
2009-06-09 21:44:49 ----D---- C:\WINDOWS\program files
2009-06-09 21:40:17 ----D---- C:\WINDOWS\25 Windows Vista Themes
2009-06-09 21:34:27 ----RSD---- C:\WINDOWS\Fonts
2009-06-09 21:32:11 ----D---- C:\WINDOWS\WinSxS
2009-06-09 21:31:45 ----D---- C:\WINDOWS\Help
2009-06-09 21:31:45 ----D---- C:\Program Files\Common Files
2009-06-09 19:51:15 ----D---- C:\Documents and Settings\MT\Dane aplikacji\avidemux
2009-06-09 19:25:54 ----D---- C:\VueScan
2009-06-09 18:55:08 ----A---- C:\WINDOWS\AVerTV.ini
2009-06-06 20:44:57 ----A---- C:\WINDOWS\Informat.ini
2009-06-06 18:01:37 ----D---- C:\Program Files\Common Files\Teleca Shared
2009-06-04 15:46:45 ----D---- C:\WINDOWS\system
2009-06-01 19:39:23 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-05-22 00:01:24 ----SHD---- C:\System Volume Information
2009-05-20 23:17:45 ----D---- C:\Documents and Settings\MT\Dane aplikacji\Adobe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;Sterownik procesora AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-02 43520]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\D:\Program Files\UltraISO\drivers\ISODrive.sys []
R1 SandBox;SandBox; C:\WINDOWS\system32\DRIVERS\SandBox.sys [2008-07-11 673920]
R1 VBoxDrv;VirtualBox Service; C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [2008-09-12 95888]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [2008-09-12 41680]
R1 WS2IFSL;Środowisko wspomagające dostawcę usług innych niż IFS - Windows Socket 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-17 12032]
R2 CrypticDisk;CrypticDisk; \??\C:\WINDOWS\system32\Drivers\CrypticDisk.sys []
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2006-12-26 15440]
R2 nxsIO32;NextSensor Kernel I/O Driver; \??\C:\WINDOWS\System32\DRIVERS\nxsIO32.sys []
R2 port_nt;port_nt; \??\C:\WINDOWS\System32\Drivers\port_nt.sys []
R3 afw;Agnitum firewall driver; C:\WINDOWS\system32\DRIVERS\afw.sys [2008-06-30 30864]
R3 afwcore;afwcore; C:\WINDOWS\system32\drivers\afwcore.sys [2008-06-30 234640]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-02-17 3846848]
R3 ASWFilt;ASWFilt; C:\WINDOWS\system32\Filt\ASWFilt.dll [2008-07-11 33408]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-06-13 2155520]
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\System32\DRIVERS\blueletaudio.sys [2007-05-11 34704]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\System32\DRIVERS\BlueletSCOAudio.sys [2007-03-05 27792]
R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\System32\DRIVERS\btnetdrv.sys [2007-05-23 16272]
R3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-05-23 36496]
R3 Cap7134;AVerMedia, AVerTV WDM Video Capture (Silicon); C:\WINDOWS\System32\DRIVERS\Cap7134.sys [2009-03-24 346304]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2006-12-26 34760]
R3 K320bus;Sony Ericsson K320 driver (WDM); C:\WINDOWS\System32\DRIVERS\K320bus.sys [2006-08-18 61504]
R3 K320mdfl;Sony Ericsson K320 USB WMC Modem Filter; C:\WINDOWS\System32\DRIVERS\K320mdfl.sys [2006-08-18 9328]
R3 K320mdm;Sony Ericsson K320 USB WMC Modem Driver; C:\WINDOWS\System32\DRIVERS\K320mdm.sys [2006-08-18 97056]
R3 K320mgmt;Sony Ericsson K320 USB WMC Device Management Drivers (WDM); C:\WINDOWS\System32\DRIVERS\K320mgmt.sys [2006-08-18 88560]
R3 K320obex;Sony Ericsson K320 USB WMC OBEX Interface; C:\WINDOWS\System32\DRIVERS\K320obex.sys [2006-08-18 86368]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2008-02-26 47360]
R3 PhTVTune;Cap7134 TVTuner; C:\WINDOWS\System32\DRIVERS\PhTVTune.sys [2009-03-24 54304]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-08-17 5888]
R3 usbehci;Sterownik Miniport rozszerzonego kontrolera hosta USB 2.0 Microsoft; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Koncentrator z obsługą USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbstor;Sterownik magazynu masowego USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Sterownik Miniport uniwersalnego kontrolera hosta USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 VBEngNT;VBEngNT; C:\WINDOWS\system32\DRIVERS\VBEngNT.sys [2008-06-04 1072722]
R3 VBFilt;VBFilt; C:\WINDOWS\system32\Filt\VBFilt.dll [2008-07-11 158816]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\System32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
S1 SysTool;SysTool Overclocking Utility; C:\WINDOWS\system32\DRIVERS\SysTool.sys [2006-11-10 24064]
S3 af36dfq8;af36dfq8; C:\WINDOWS\system32\drivers\af36dfq8.sys []
S3 AMD64CA;AMD64CA; \??\C:\WINDOWS\System32\Drivers\AMD64CAx86.sys []
S3 ASFWHide;ASFWHide; \??\C:\DOCUME~1\MT\USTAWI~1\Temp\ASFWHide []
S3 BTNetFilter;Bluetooth Network Filter; \??\C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\MT\USTAWI~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 C-Dilla;C-Dilla; \??\C:\WINDOWS\system32\drivers\CDANT.SYS []
S3 DSDrv4;DSDrv4; \??\D:\PROGRA~1\DScaler\DSDrv4.sys []
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys []
S3 HidUsb;Sterownik Microsoft klasy HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [2005-10-28 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [2005-10-28 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [2005-10-28 21568]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys [2006-02-26 81408]
S3 rtl8139;Sterownik NT karty Realtek RTL8139(A/B/C)-based PCI Fast Ethernet; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM); C:\WINDOWS\system32\DRIVERS\s3017bus.sys [2007-12-10 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s3017mdfl.sys [2007-12-10 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s3017mdm.sys [2007-12-10 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s3017mgmt.sys [2007-12-10 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS); C:\WINDOWS\system32\DRIVERS\s3017nd5.sys [2007-12-10 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s3017obex.sys [2007-12-10 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM); C:\WINDOWS\system32\DRIVERS\s3017unic.sys [2007-12-10 110120]
S3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-02-08 806400]
S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\WINDOWS\system32\DRIVERS\s916bus.sys [2007-11-02 83496]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s916mdfl.sys [2007-11-02 15016]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s916mdm.sys [2007-11-02 109992]
S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s916mgmt.sys [2007-11-02 103976]
S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s916obex.sys [2007-11-02 100008]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbccgp;Rodzajowy sterownik nadrzędny USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Klasa PRINTER USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Sterownik skanera USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 acssrv;Agnitum Client Security Service; C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe [2008-08-05 1570136]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-06-13 483328]
R2 C-DillaSrv;C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2008-10-07 46080]
R2 HDDlife HDD Access service;HDDlife HDD Access service; C:\Program Files\Common Files\BinarySense\hldasvc.exe [2008-02-15 832760]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\HPZipm12.exe [2007-02-21 73728]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2007-06-13 520192]
S3 aspnet_state;„Usługa stanu ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-08-21 382248]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-05-30 572416]
S3 WMPNetworkSvc;Usługa udostępniania w sieci programu Windows Media Player; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-12-01 918016]
S4 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-03-03 85096]
S4 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-08-08 836904]
-----------------EOF-----------------
[i][size=85]Dodano Dzisiaj, 19:26:[/size][/i]
[b] I DRUGI[/b]
info.txt logfile of random's system information tool 1.06 2009-06-19 19:22:05
======Uninstall list======
-->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->MsiExec.exe /I{9A346205-EA92-4406-B1AB-50379DA3F057}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
1-abc.net File Washer (Remove only)-->"D:\Program Files\1-abc\File Washer\uninst.exe"
3GP Video Converter 3-->D:\Program Files\Xilisoft\3GP Video Converter 3\Uninstall.exe
ACDSee 10 Photo Manager-->MsiExec.exe /I{F8B98EB6-FC06-45BF-87D4-9784E0408611}
Adobe Flash Player 9 ActiveX-->C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{BB65C393-C76E-4F06-9B0C-2124AA8AF97B}
Adobe Flash Player Plugin-->C:\WINDOWS\System32\Macromed\Flash\uninstall_plugin.exe
Adobe Photoshop 7.0 CE-->C:\WINDOWS\ISUN0415.EXE -f"D:\Program Files\Adobe\Photoshop 7.0 CE\Uninst.isu" -c"D:\Program Files\Adobe\Photoshop 7.0 CE\Uninst.dll"
Adobe Reader 7.0.5 - Polish-->MsiExec.exe /I{AC76BA86-7AD7-1045-7B44-A70500000002}
Advanced Disk Catalog-->D:\PROGRA~1\ADVANC~1\UNWISE.EXE D:\PROGRA~1\ADVANC~1\INSTALL.LOG
Agnitum Outpost Security Suite Pro-->"C:\Program Files\Agnitum\Outpost Security Suite Pro\unins000.exe"
ALLPlayer V3.X-->"C:\Program Files\ALLPlayer\unins000.exe"
AMD Processor Driver-->C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe -runfromtemp -l0x0015 -removeonly
Angielski At Once!-->"D:\Program Files\Atonce\unins000.exe"
AoA Audio Extractor 1.0-->"D:\Program Files\AoA Audio Extractor\unins000.exe"
Archiwizator WinRAR-->D:\Program Files\WinRAR\uninstall.exe
Ashampoo UnInstaller 3.10-->"D:\Program Files\Ashampoo\Ashampoo UnInstaller 3\unins000.exe"
ATI Catalyst Control Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
ATI HYDRAVISION-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}\setup.exe"
ATI Parental Control & Encoder-->MsiExec.exe /I{36CDA33B-909B-4719-97D1-C4B99309BDC7}
AutoCAD 2008 - Polski-->D:\Program Files\AutoCAD 2008\Setup\Setup.exe /P {5783F2D7-6001-0415-0002-0060B0CE6BBA} /M ACAD
Autodesk DWF Viewer 7-->MsiExec.exe /I{9A346205-EA92-4406-B1AB-50379DA3F057}
AVerTV GO 007 Plus-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{8DF56C91-281F-4C15-B954-F45FDC919568} /l1045
AVI ReComp 1.4.5-->D:\Program Files\AVI ReComp\Uninstall.exe
AVIVO Codecs-->MsiExec.exe /X{C941F1F1-25B3-4DF5-83E6-888C51A1AAB6}
BE Inspired! Beginner and Elementary 2008-->"C:\WINDOWS\BE Inspired! Beginner and Elementary 2008\uninstall.exe" "/U:D:\Program Files\BE Inspired! Beginner and Elementary 2008\Uninstall\uninstall.xml"
bEncoder-->D:\PROGRA~1\bPlayer2\UNWISE.EXE D:\PROGRA~1\bPlayer2\INSTALL.LOG
Bluesoleil2.6.0.9 Release 070606-->MsiExec.exe /X{846AC73B-9394-48B9-B941-8F7F472F0047}
CamStudio-->D:\Program Files\CamStudio\uninstall.exe
CCleaner (remove only)-->"D:\Program Files\CCleaner\uninst.exe"
C-Dilla Licence Management System-->C:\C_DILLA\setup\cdunin16.exe
CDRoller version 7.70-->"D:\Program Files\CDRoller\unins000.exe"
CloneCD-->"D:\Program Files\SlySoft\CloneCD\ccd-uninst.exe" /D="D:\Program Files\SlySoft\CloneCD"
ClonyXXL_2.0.1.5_PL-->D:\Program Files\ClonyXXL PL\Uninstal.exe
CodeStuff Starter-->"D:\Program Files\CodeStuff\Starter\unStarter.exe"
Combined Community Codec Pack 2008-01-24-->"D:\Program Files\Combined Community Codec Pack\unins000.exe"
Cryptic Disk 2.4.7.0-->"D:\Program Files\Cryptic Disk\unins000.exe"
Defraggler (remove only)-->"D:\Program Files\Defraggler\uninst.exe"
Desktop Sidebar-->MsiExec.exe /I{A92D7264-1A13-45BE-B769-88445DD04FD6}
Deutsch Translator 2-->D:\Program Files\Deutsch Translator 2\setup.exe -uninstall
Digital Clock Screen Saver-->"C:\WINDOWS\unins004.exe"
DriveImage XML-->"D:\Program Files\Runtime Software\DriveImage XML\Uninstall.exe" "D:\Program Files\Runtime Software\DriveImage XML\install.log" -u
DScaler 4.1.15-->"D:\Program Files\DScaler\unins000.exe"
EfreeSoft Boss Key Version 3.30-->"D:\Program Files\Mgboss\unins000.exe"
Ekspert CD-->C:\WINDOWS\unins002.exe
ERUNT 1.1j-->C:\WINDOWS\ERUNT\unins000.exe
ETI-pro-->MsiExec.exe /I{0ACB1594-6EEC-472F-9B1B-7C8178BBAFEA}
Expressivo-->D:\Program Files\ivo\Expressivo\UsunExpressivo.exe
Festo FluidSim 3.6-->"D:\Program Files\Festo Fluidsim\unins000.exe"
Folder Marker v 1.4-->"D:\Program Files\Folder Marker\unins000.exe"
FotoOffice-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3AC92370-5804-413C-89DA-C9172574E228}\Setup.exe"
FreeDVD Codec Installer Version 1.0-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\CodecInstaller\ST6UNST.LOG"
Gadu-Gadu 7.7-->D:\Program Files\Gadu-GaduR\Setup.exe
Glary Utilities 2.5-->"D:\Program Files\Glary Utilities\unins000.exe"
GMail Drive Shell Extension-->rundll32.exe C:\WINDOWS\system32\ShellExt\GMailFS.dll,Uninstall C:\WINDOWS\system32\ShellExt\GMailFS.inf
GOM Player-->"C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
GoNaomi Dictionary-->D:\Program Files\GoNaomi Dictionary\uninstall.exe
GTA San Andreas-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x9 -removeonly
Hackman Hex Editor-->"D:\Program Files\Hackman\Uninstall.exe" "D:\Program Files\Hackman\install.log"
HDDlife Pro 3.1-->MsiExec.exe /X{E81D9FF6-B45F-4DD4-9673-86B08AF6F705}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
HP Print Diagnostic Utility-->MsiExec.exe /I{5E06C076-E4E7-4239-A886-B3D8AC84C166}
HP PSC & OfficeJet 6.1.A-->"C:\Program Files\HP\Digital Imaging\{27555031-A116-4EC6-9991-7B400142A936}\setup\hpzscr01.exe" -datfile hposcr08.dat
Icon Restore 1.0-->C:\WINDOWS\unins003.exe
ICQ6-->"C:\Program Files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe" -runfromtemp -l0x0009 -removeonly
J2SE Runtime Environment 5.0 Update 10-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
KLS Mail Backup 1.7.0.0-->"D:\Program Files\KLS Soft\KLS Mail Backup\unins000.exe"
KNK-->D:\Program Files\KNK\uninstal.exe
Komputer ŚWIAT - Leksykonia-->"D:\Program Files\Leksykonia\unins000.exe"
Kursy Walut R-->C:\WINDOWS\uninst.exe -f"D:\Program Files\KursyWalut\DeIsL1.isu" -c"D:\Program Files\KursyWalut\_ISREG32.DLL"
Listonosz : Klient Poczty 1.1.6.0-->D:\Program Files\Onet\Listonosz\deinstalacja.exe
MediaMonkey 3.0-->"D:\Program Files\MediaMonkey\unins000.exe"
Memento v1.06-->"D:\Program Files\Memento\unins000.exe"
Microsoft .NET Framework 2.0 — pakiet języka polskiego-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - PLK\install.exe
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110415-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Monopoly by Parker Brothers-->D:\PROGRA~1\Hasbro\MONOPO~1\UNWISE.EXE /U D:\PROGRA~1\Hasbro\MONOPO~1\INSTALL.LOG
Movie DVD Maker 2.6.1123-->"D:\Program Files\Movie DVD Maker\unins000.exe"
Mozilla 1.7.7 (PL)-->C:\WINDOWS\MozillaUninstall.exe /ua "1.7.7 (PL)"
Mozilla Thunderbird (1.0.6)-->C:\WINDOWS\UninstallThunderbird.exe /ua "1.0.6 (pl)"
MSVC80_x86-->MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
MSXML 6.0 Parser-->MsiExec.exe /I{AEB9948B-4FF2-47C9-990E-47014492A0FE}
My Lockbox 1.1 for Windows 2000/XP-->"D:\Program Files\My Lockbox\unins000.exe"
MyPhoneExplorer-->D:\Program Files\MyPhoneExplorer\uninstall.exe
Narzędzie Software Uninstall Utility firmy ATI-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
Need for Speed™ Most Wanted-->D:\Program Files\EA GAMES\Need for Speed Most Wanted\EAUninstall.exe
Nero 8-->MsiExec.exe /X{FAB3A0EF-C845-4AFF-BE3C-98EB480F1045}
New Star Soccer 3-->D:\Program Files\New Star Soccer 3\Usun.exe
Niezbednik CD-->C:\WINDOWS\unins001.exe
Niezbędnik CD-->C:\WINDOWS\unins000.exe
Nowe Gadu-Gadu-->D:\Program Files\Nowe Gadu-Gadu\Uninstall.exe
ObjectDock-->D:\PROGRA~1\Stardock\OBJECT~2\UNWISE.EXE D:\PROGRA~1\Stardock\OBJECT~2\INSTALL.LOG
Paragon Hard Disk Manager 8 Special Edition-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E9E4BB29-FA98-401B-9EDE-9906906E33DE}\Setup.exe" -l0x9
PC Connectivity Solution-->MsiExec.exe /I{9C7C8898-DC29-4E8B-9E77-55A77C3250F6}
PDFCreator-->MsiExec.exe /I{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}
PerformanceTest v6.1-->"D:\Program Files\PerformanceTest\unins000.exe"
PhotoFiltre-->"D:\Program Files\PhotoFiltre\Uninst.exe"
PhotoScape-->"D:\Program Files\PhotoScape\uninstall.exe"
Picasa 2-->"D:\Program Files\Picasa2\Uninstall.exe"
Polski VAG 4.9-->"d:\Program Files\Polski VAG 4.9\unins000.exe"
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
Prawo 2008-->"D:\Program Files\Play\Prawo 2008\unins000.exe"
Profiler v1.2 PL-->D:\Program Files\Profiler PL\Uninstal.exe
ProScan 5.2-->"D:\Program Files\ProScan\uninstall.exe"
QuickTime Alternative 1.66-->"D:\Program Files\QuickTime Alternative\unins000.exe"
Real Alternative 1.7.5-->"D:\Program Files\Real Alternative\unins000.exe"
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\Setup.exe" -l0x15 -removeonly
REALTEK GbE & FE Ethernet PCI NIC Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\Setup.exe" -l0x15 -removeonly
Resident Evil 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9701A4CC-C144-4482-9776-B64BF4A5343F}\setup.exe" -l0x9
Rezystor do Leda 1.0-->"D:\Program Files\Rezystor do Led'a\unins000.exe"
RocketDock 1.3.0-->"C:\WINDOWS\BricoPacks\Vista Inspirat 2Robert\RocketDock\RocketDock\unins000.exe"
Serials 2005-->MsiExec.exe /I{A31838F1-8E0D-4CA3-A40A-20825B92F125}
Słownik Języka Polskiego GoNaomi 1.4-->D:\Program Files\Słownik Języka Polskiego GoNaomi 1.4\uninstall.exe
Słownik-->C:\WINDOWS\uninst.exe -f"C:\Program Files\Słownik\DeIsL1.isu" -c"C:\Program Files\Słownik\_ISREG32.DLL"
Sony Ericsson MMS Home Studio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9462C4AD-D6C4-4365-B4AD-BFE0B1E216C3}\Setup.exe" -l0x9 -l0009 --remove=y
Sony Ericsson PC Suite 3.209.00-->C:\Program Files\InstallShield Installation Information\{2FFE93F0-BB72-4E52-8761-354D1AAA9387}\Setup.exe -runfromtemp -l0x0015 -removeonly
Sony Ericsson PC Suite-->MsiExec.exe /I{5F0FC860-ADE1-4B2D-B0A9-CB9FB17C46E8}
Sony Ericsson Themes Creator 3.11-->D:\Program Files\Sony Ericsson\Themes Creator\Uninstall.exe
Sp5-->MsiExec.exe /I{560F47F7-EB23-44B1-AAFC-667F1CD8FE5C}
Sp5Intl-->MsiExec.exe /I{FD4B33E1-24AE-4535-AA7B-162B30FB57CD}
Sp5TTInt-->MsiExec.exe /I{E415C943-37E5-473F-8BAE-043C56734124}
SpCommon-->MsiExec.exe /I{6C3959C6-943E-44B3-BAAD-570B04B134E5}
Spirit of Fire 3D Screensaver 2.4-->"D:\Program Files\Spirit of Fire 3D Screensaver\unins000.exe"
SpPhones-->MsiExec.exe /I{4DFF1415-4C29-44A8-BFD4-2BCE249C4991}
Sun xVM VirtualBox-->MsiExec.exe /I{30A01FF6-D5DD-4DEE-AA57-253AF79A57B9}
SUPER © Version 2008.bld.30 (Mar 22, 2008)-->D:\PROGRA~1\ERIGHT~1\SUPER\Setup.exe /remove /q0
SyncBack-->"D:\Program Files\2BrightSparks\SyncBack\unins000.exe"
UltraISO Premium V9.2-->"D:\Program Files\UltraISO\unins000.exe"
Unlocker 1.8.0-->D:\Program Files\Unlocker\uninst.exe
Update Service-->D:\Program Files\Sony Ericsson\Update Service\uninst.exe
VIA Platform Device Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
Virtual DJ - Atomix Productions-->D:\PROGRA~1\VIRTUA~3\UNWISE.EXE D:\PROGRA~1\VIRTUA~3\INSTALL.LOG
Virtual DJ 5.2 (Crack v2)-->D:\Program Files\VirtualDJ\Uninstal Crack VirtualDJ.exe
VirtualDubMod 1.5.10.2 PL-->D:\Program Files\VirtualDubMod\Odinstaluj.exe
Vista Drive Icon 1.4-->D:\Program Files\Vista Drive Icon\uninst.exe
Vista Transformation Pack 8.0-->C:\WINDOWS\system32\viwc.exe
Visual Task Tips 2.0-->D:\Program Files\VisualTaskTips\uninst.exe
VobSub 2.23-->D:\Program Files\Gabest\VobSub\uninstall.exe
VueScan-->C:\VueScan\vuescan.exe /remove
WellPhone DirectSync-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CFEC7E01-B73C-451D-A366-96978AFD233B}\setup.exe" UNINSTALL
WellPhone-->"D:\Program Files\SmartCom\WellPhone\UnInst32.exe"
Winamp (remove only)-->"D:\Program Files\Winamp\UninstWA.exe"
Winamp 5.33 PL-->"D:\Program Files\Winamp\uninst-winamp_pl.exe"
Winamp reverb/speaker simulator plugin (remove only)-->"D:\Program Files\Winamp\Plugins\uninst_kreverb.exe"
Windows Configurator v0.6-->"D:\Program Files\Windows Configurator\unins000.exe"
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 2-->C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
Xvid 1.2.1-->D:\Program Files\Xvid\unins000.exe
zaprojektuj swój DOM-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{24576216-414E-4B17-B752-F5ECA71326D2}\setup.exe" -l0x15
Zoner Photo Studio 10-->"D:\Program Files\Zoner\Photo Studio 10\unins000.exe" /SILENT
======Hosts File======
127.0.0.1 localhost
======System event log======
Computer Name: KOWALSKI-MQAXU1
Event Code: 7036
Message: Usługa Usługa odnajdywania SSDP weszła w stan uruchomienia.
Record Number: 18590
Source Name: Service Control Manager
Time Written: 20090524150512.000000+120
Event Type: informacje
User:
Computer Name: KOWALSKI-MQAXU1
Event Code: 7035
Message: Do usługi Usługa odnajdywania SSDP został pomyślnie wysłany kod sterowania uruchom.
Record Number: 18589
Source Name: Service Control Manager
Time Written: 20090524150512.000000+120
Event Type: informacje
User: ZARZĄDZANIE NT\SYSTEM
Computer Name: KOWALSKI-MQAXU1
Event Code: 7036
Message: Usługa Menedżer połączeń usługi Dostęp zdalny weszła w stan uruchomienia.
Record Number: 18588
Source Name: Service Control Manager
Time Written: 20090524150511.000000+120
Event Type: informacje
User:
Computer Name: KOWALSKI-MQAXU1
Event Code: 7035
Message: Do usługi Menedżer połączeń usługi Dostęp zdalny został pomyślnie wysłany kod sterowania uruchom.
Record Number: 18587
Source Name: Service Control Manager
Time Written: 20090524150511.000000+120
Event Type: informacje
User: ZARZĄDZANIE NT\SYSTEM
Computer Name: KOWALSKI-MQAXU1
Event Code: 7036
Message: Usługa Telefonia weszła w stan uruchomienia.
Record Number: 18586
Source Name: Service Control Manager
Time Written: 20090524150511.000000+120
Event Type: informacje
User:
=====Application event log=====
Computer Name: KOWALSKI-MQAXU1
Event Code: 0
Message:
Record Number: 5
Source Name: PD91Agent
Time Written: 20090302141117.000000+060
Event Type: informacje
User:
Computer Name: KOWALSKI-MQAXU1
Event Code: 105
Message: The service was started.
Record Number: 4
Source Name: ATI Smart
Time Written: 20090302141110.000000+060
Event Type: informacje
User:
Computer Name: KOWALSKI-MQAXU1
Event Code: 1
Message:
Record Number: 3
Source Name: Diskeeper
Time Written: 20090301204457.000000+060
Event Type: informacje
User:
Computer Name: KOWALSKI-MQAXU1
Event Code: 0
Message:
Record Number: 2
Source Name: PD91Agent
Time Written: 20090301204456.000000+060
Event Type: informacje
User:
Computer Name: KOWALSKI-MQAXU1
Event Code: 105
Message: The service was started.
Record Number: 1
Source Name: ATI Smart
Time Written: 20090301204450.000000+060
Event Type: informacje
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\PC Connectivity Solution;C:\Program Files\Common Files\Teleca Shared;D:\PROGRA~1\DISKEE~1\DISKEE~1;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=6b01
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"DEFAULT_CA_NR"=CA6
"FP_NO_HOST_CHECK"=NO
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by MT at 2009-06-19 19:19:34
Microsoft Windows XP Professional Dodatek Service Pack 2
System drive C: has 8 GB (21%) free of 39 GB
Total RAM: 1022 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:22:03, on 2009-06-19
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Common Files\BinarySense\hldasvc.exe
C:\Program Files\Common Files\BinarySense\hldasvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Vista Drive Icon\DrvIcon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Vista Sidebar\sidebar.exe
D:\Program Files\VisualTaskTips\VisualTaskTips.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
D:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
D:\Program Files\SysInfoMyWork\SysInfoMyWork.exe
C:\WINDOWS\explorer.exe
D:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Documents and Settings\MT\Pulpit\RSITv.exe
C:\Program Files\trend micro\MT.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchgateway.net/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - D:\Program Files\Desktop Sidebar\sbhelp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Expressivo - {85F685C3-20D9-4943-95E4-EB4224056C3F} - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O3 - Toolbar: Expressivo - {85F685C3-20D9-4943-95E4-EB4224056C3F} - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll
O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
O4 - HKLM\..\Run: [WellPhone DirectSync - ScheduleSync] D:\PROGRA~1\WELLPH~1\SCHEDU~1.EXE
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [DrvIcon] D:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Windows Intranet controller] C:\WINDOWS\security\lsass.exe
O4 - HKCU\..\Run: [Vista Sidebar] C:\Program Files\Vista Sidebar\sidebar.exe
O4 - HKCU\..\Run: [VisualTaskTips] D:\Program Files\VisualTaskTips\VisualTaskTips.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\WINDOWS\ERUNT\AUTOBACK.EXE
O4 - Startup: HDDlife.lnk = C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
O4 - Startup: Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: SyncBack.lnk = D:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
O4 - Startup: SysInfoMyWork.lnk = D:\Program Files\SysInfoMyWork\SysInfoMyWork.exe
O4 - Startup: Thoosje Vista Sidebar.lnk = C:\Program Files\Vista Sidebar\sidebar.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Ustawienia Outpost Security Suite Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Security Suite Pro\ie_bar.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{93791610-F0BC-4990-A977-06B47E9077D5}: NameServer = 212.2.96.52 212.2.96.51
O18 - Protocol: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - "C:\Program Files\Common Files\BinarySense\hlAPP.dll" (file missing)
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: HDDlife HDD Access service - BinarySense, Inc. - C:\Program Files\Common Files\BinarySense\hldasvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 7276 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GlaryInitialize.job
C:\WINDOWS\tasks\SyncBack Adv disk catalog.job
C:\WINDOWS\tasks\SyncBack Documents and SettingsMTDane aplikacjiThunderbird.job
C:\WINDOWS\tasks\SyncBack Documents and SettingsRobertGadu-Gadu.job
C:\WINDOWS\tasks\SyncBack GG marcin.job
C:\WINDOWS\tasks\SyncBack MTDane aplikacjiMyPhoneExplorer.job
C:\WINDOWS\tasks\SyncBack My phone explorer.job
C:\WINDOWS\tasks\SyncBack Nowe gg MT.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45AD732C-2CE2-4666-B366-B2214AD57A49}]
Idea2 SidebarBrowserMonitor Class - D:\Program Files\Desktop Sidebar\sbhelp.dll [2006-07-09 278528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 440056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{85F685C3-20D9-4943-95E4-EB4224056C3F}]
Expressivo - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll [2007-05-15 315392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - StylerToolBar - C:\Program Files\Styler\TB\StylerTB.dll [2006-05-02 102400]
{85F685C3-20D9-4943-95E4-EB4224056C3F} - Expressivo - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll [2007-05-15 315392]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"OutpostMonitor"=C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe [2008-08-25 1208664]
"WellPhone DirectSync - ScheduleSync"=D:\PROGRA~1\WELLPH~1\SCHEDU~1.EXE [2005-08-08 45056]
"VisualTooltip"= []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"DrvIcon"=D:\Program Files\Vista Drive Icon\DrvIcon.exe [2008-04-13 49152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"Windows Intranet controller"=C:\WINDOWS\security\lsass.exe [2009-04-08 1826871]
"Vista Sidebar"=C:\Program Files\Vista Sidebar\sidebar.exe [2007-11-20 524288]
"VisualTaskTips"=D:\Program Files\VisualTaskTips\VisualTaskTips.exe [2006-05-28 36864]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
D:\Program Files\Gadu-GaduR\gg.exe [2008-03-20 2127296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sTabLauncher]
D:\Program Files\sTabLauncher\sTabLauncher.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Live]
C:\Documents and Settings\MT\Dane aplikacji\WindowsLive.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Core Temp.lnk]
D:\PROGRA~1\CoreTemp\CORETE~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UPS"=3
"Autodesk Licensing Service"=3
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Documents and Settings\MT\Menu Start\Programy\Autostart
ERUNT AutoBackup.lnk - C:\WINDOWS\ERUNT\AUTOBACK.EXE
HDDlife.lnk - C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
Stardock ObjectDock.lnk - D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
SyncBack.lnk - D:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
SysInfoMyWork.lnk - D:\Program Files\SysInfoMyWork\SysInfoMyWork.exe
Thoosje Vista Sidebar.lnk - C:\Program Files\Vista Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-06-13 118784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=36
"NoRecycleFiles"=0
"NoWelcomeScreen"=0
"NoStartMenuEjectPC"=0
"EditLevel"=0
"NoCommonGroups"=0
"NoDriveAutoRun"=FFFFFFFF
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoStartMenuEjectPC"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"D:\Program Files\Gadu-Gadu\gg.exe"="D:\Program Files\Gadu-Gadu\gg.exe:*:Enabled:Gadu-Gadu - program główny"
"D:\Program Files\Sony Ericsson\Update Service\Update Service.exe"="D:\Program Files\Sony Ericsson\Update Service\Update Service.exe:*:Enabled:Update Service"
"D:\Program Files\ICQ6\ICQ.exe"="D:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Documents and Settings\MT\Pulpit\utorrent-1.8-rc7.upx.exe"="C:\Documents and Settings\MT\Pulpit\utorrent-1.8-rc7.upx.exe:*:Enabled:µTorrent"
"D:\Program Files\uTorrent\utorrent-1.8-rc7.upx.exe"="D:\Program Files\uTorrent\utorrent-1.8-rc7.upx.exe:*:Enabled:µTorrent"
"D:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe"="D:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager"
"D:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe"="D:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"D:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe"="D:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe:*:Enabled:umi"
"D:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe"="D:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
shell\AutoRun\command - D:\explorefiles.exe
shell\explore\command - D:\explorefiles.exe
shell\open\command - D:\explorefiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
shell\AutoRun\command - E:\explorefiles.exe
shell\explore\command - E:\explorefiles.exe
shell\open\command - E:\explorefiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\P]
shell\AutoRun\command - P:\explorefiles.exe
shell\explore\command - P:\explorefiles.exe
shell\open\command - P:\explorefiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\R]
shell\AutoRun\command - R:\explorefiles.exe
shell\explore\command - R:\explorefiles.exe
shell\open\command - R:\explorefiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1de35da4-e47b-11dc-8d8a-c78261217473}]
shell\AutoRun\command - S:\explorefiles.exe
shell\explore\command - S:\explorefiles.exe
shell\open\command - S:\explorefiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7384ae84-857a-11dd-8ffb-0011679add53}]
shell\AutoRun\command - P:\explorefiles.exe
shell\explore\command - P:\explorefiles.exe
shell\open\command - P:\explorefiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97ae7c71-e474-11dc-95a0-806d6172696f}]
shell\AutoRun\command - E:\viewfiles.exe
shell\explore\command - E:\viewfiles.exe
shell\open\command - E:\viewfiles.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d54df804-2cc4-11de-921d-0011679add53}]
shell\AutoRun\command - P:\explorefiles.exe
shell\explore\command - P:\explorefiles.exe
shell\open\command - P:\explorefiles.exe
======File associations======
.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 months======
2009-06-19 19:19:34 ----D---- C:\rsit
2009-06-19 19:19:34 ----D---- C:\Program Files\trend micro
2009-06-19 17:59:44 ----RASHD---- C:\autorun.inf
2009-06-18 18:46:47 ----A---- C:\WINDOWS\system32\CF30042.exe
2009-06-18 18:44:44 ----A---- C:\WINDOWS\system32\CF29595.exe
2009-06-17 20:39:07 ----A---- C:\WINDOWS\ntbtlog.txt
2009-06-12 19:49:06 ----D---- C:\Documents and Settings\MT\Dane aplikacji\Stardock
2009-06-12 18:40:46 ----A---- C:\WINDOWS\unins004.exe
2009-06-10 17:04:43 ----D---- C:\Documents and Settings\MT\Dane aplikacji\AVI ReComp
2009-06-05 15:43:09 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\BVRP Software
2009-06-01 18:39:09 ----D---- C:\Program Files\TRACERMM SOFT
2009-05-21 22:41:19 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\KLS Soft
======List of files/folders modified in the last 1 months======
2009-06-19 19:19:34 ----D---- C:\Program Files
2009-06-19 18:37:30 ----D---- C:\WINDOWS\Temp
2009-06-19 18:06:50 ----A---- C:\WINDOWS\ModemLog_Sony Ericsson K320 USB WMC Data Modem.txt
2009-06-19 17:31:38 ----AD---- C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2009-06-19 17:30:05 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-06-19 17:29:21 ----D---- C:\Program Files\Stardock
2009-06-19 16:45:08 ----SH---- C:\boot.ini
2009-06-19 16:45:08 ----A---- C:\WINDOWS\win.ini
2009-06-19 16:45:08 ----A---- C:\WINDOWS\system.ini
2009-06-19 16:23:29 ----D---- C:\WINDOWS
2009-06-19 14:57:37 ----A---- C:\WINDOWS\ModemLog_Mobile 115200.txt
2009-06-19 12:25:20 ----A---- C:\WINDOWS\NeroDigital.ini
2009-06-18 19:30:07 ----D---- C:\Program Files\Downloaded Installations
2009-06-18 19:28:48 ----D---- C:\WINDOWS\system32
2009-06-18 19:26:40 ----D---- C:\Temp
2009-06-18 18:50:39 ----D---- C:\WINDOWS\security
2009-06-18 18:45:49 ----D---- C:\WINDOWS\system32\drivers
2009-06-18 18:44:49 ----D---- C:\WINDOWS\ERDNT
2009-06-18 18:44:44 ----D---- C:\WINDOWS\system32\CatRoot2
2009-06-18 18:44:24 ----D---- C:\WINDOWS\Prefetch
2009-06-17 20:42:54 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-06-17 20:41:14 ----D---- C:\WINDOWS\ERUNT
2009-06-15 18:57:18 ----SHD---- C:\WINDOWS\Installer
2009-06-15 18:57:17 ----HD---- C:\Config.Msi
2009-06-15 18:53:00 ----D---- C:\WINDOWS\system32\config
2009-06-15 18:51:13 ----D---- C:\WINDOWS\system32\wbem
2009-06-15 18:51:12 ----D---- C:\WINDOWS\Registration
2009-06-12 19:54:32 ----RSD---- C:\WINDOWS\assembly
2009-06-12 16:06:37 ----A---- C:\WINDOWS\ModemLog_Bluetooth DUN Modem.txt
2009-06-09 21:44:49 ----D---- C:\WINDOWS\program files
2009-06-09 21:40:17 ----D---- C:\WINDOWS\25 Windows Vista Themes
2009-06-09 21:34:27 ----RSD---- C:\WINDOWS\Fonts
2009-06-09 21:32:11 ----D---- C:\WINDOWS\WinSxS
2009-06-09 21:31:45 ----D---- C:\WINDOWS\Help
2009-06-09 21:31:45 ----D---- C:\Program Files\Common Files
2009-06-09 19:51:15 ----D---- C:\Documents and Settings\MT\Dane aplikacji\avidemux
2009-06-09 19:25:54 ----D---- C:\VueScan
2009-06-09 18:55:08 ----A---- C:\WINDOWS\AVerTV.ini
2009-06-06 20:44:57 ----A---- C:\WINDOWS\Informat.ini
2009-06-06 18:01:37 ----D---- C:\Program Files\Common Files\Teleca Shared
2009-06-04 15:46:45 ----D---- C:\WINDOWS\system
2009-06-01 19:39:23 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-05-22 00:01:24 ----SHD---- C:\System Volume Information
2009-05-20 23:17:45 ----D---- C:\Documents and Settings\MT\Dane aplikacji\Adobe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;Sterownik procesora AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-02 43520]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\D:\Program Files\UltraISO\drivers\ISODrive.sys []
R1 SandBox;SandBox; C:\WINDOWS\system32\DRIVERS\SandBox.sys [2008-07-11 673920]
R1 VBoxDrv;VirtualBox Service; C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [2008-09-12 95888]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [2008-09-12 41680]
R1 WS2IFSL;Środowisko wspomagające dostawcę usług innych niż IFS - Windows Socket 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-17 12032]
R2 CrypticDisk;CrypticDisk; \??\C:\WINDOWS\system32\Drivers\CrypticDisk.sys []
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2006-12-26 15440]
R2 nxsIO32;NextSensor Kernel I/O Driver; \??\C:\WINDOWS\System32\DRIVERS\nxsIO32.sys []
R2 port_nt;port_nt; \??\C:\WINDOWS\System32\Drivers\port_nt.sys []
R3 afw;Agnitum firewall driver; C:\WINDOWS\system32\DRIVERS\afw.sys [2008-06-30 30864]
R3 afwcore;afwcore; C:\WINDOWS\system32\drivers\afwcore.sys [2008-06-30 234640]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-02-17 3846848]
R3 ASWFilt;ASWFilt; C:\WINDOWS\system32\Filt\ASWFilt.dll [2008-07-11 33408]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-06-13 2155520]
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\System32\DRIVERS\blueletaudio.sys [2007-05-11 34704]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\System32\DRIVERS\BlueletSCOAudio.sys [2007-03-05 27792]
R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\System32\DRIVERS\btnetdrv.sys [2007-05-23 16272]
R3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-05-23 36496]
R3 Cap7134;AVerMedia, AVerTV WDM Video Capture (Silicon); C:\WINDOWS\System32\DRIVERS\Cap7134.sys [2009-03-24 346304]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2006-12-26 34760]
R3 K320bus;Sony Ericsson K320 driver (WDM); C:\WINDOWS\System32\DRIVERS\K320bus.sys [2006-08-18 61504]
R3 K320mdfl;Sony Ericsson K320 USB WMC Modem Filter; C:\WINDOWS\System32\DRIVERS\K320mdfl.sys [2006-08-18 9328]
R3 K320mdm;Sony Ericsson K320 USB WMC Modem Driver; C:\WINDOWS\System32\DRIVERS\K320mdm.sys [2006-08-18 97056]
R3 K320mgmt;Sony Ericsson K320 USB WMC Device Management Drivers (WDM); C:\WINDOWS\System32\DRIVERS\K320mgmt.sys [2006-08-18 88560]
R3 K320obex;Sony Ericsson K320 USB WMC OBEX Interface; C:\WINDOWS\System32\DRIVERS\K320obex.sys [2006-08-18 86368]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2008-02-26 47360]
R3 PhTVTune;Cap7134 TVTuner; C:\WINDOWS\System32\DRIVERS\PhTVTune.sys [2009-03-24 54304]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-08-17 5888]
R3 usbehci;Sterownik Miniport rozszerzonego kontrolera hosta USB 2.0 Microsoft; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Koncentrator z obsługą USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbstor;Sterownik magazynu masowego USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Sterownik Miniport uniwersalnego kontrolera hosta USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 VBEngNT;VBEngNT; C:\WINDOWS\system32\DRIVERS\VBEngNT.sys [2008-06-04 1072722]
R3 VBFilt;VBFilt; C:\WINDOWS\system32\Filt\VBFilt.dll [2008-07-11 158816]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\System32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
S1 SysTool;SysTool Overclocking Utility; C:\WINDOWS\system32\DRIVERS\SysTool.sys [2006-11-10 24064]
S3 af36dfq8;af36dfq8; C:\WINDOWS\system32\drivers\af36dfq8.sys []
S3 AMD64CA;AMD64CA; \??\C:\WINDOWS\System32\Drivers\AMD64CAx86.sys []
S3 ASFWHide;ASFWHide; \??\C:\DOCUME~1\MT\USTAWI~1\Temp\ASFWHide []
S3 BTNetFilter;Bluetooth Network Filter; \??\C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\MT\USTAWI~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 C-Dilla;C-Dilla; \??\C:\WINDOWS\system32\drivers\CDANT.SYS []
S3 DSDrv4;DSDrv4; \??\D:\PROGRA~1\DScaler\DSDrv4.sys []
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys []
S3 HidUsb;Sterownik Microsoft klasy HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [2005-10-28 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [2005-10-28 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [2005-10-28 21568]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys [2006-02-26 81408]
S3 rtl8139;Sterownik NT karty Realtek RTL8139(A/B/C)-based PCI Fast Ethernet; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM); C:\WINDOWS\system32\DRIVERS\s3017bus.sys [2007-12-10 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s3017mdfl.sys [2007-12-10 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s3017mdm.sys [2007-12-10 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s3017mgmt.sys [2007-12-10 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS); C:\WINDOWS\system32\DRIVERS\s3017nd5.sys [2007-12-10 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s3017obex.sys [2007-12-10 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM); C:\WINDOWS\system32\DRIVERS\s3017unic.sys [2007-12-10 110120]
S3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-02-08 806400]
S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\WINDOWS\system32\DRIVERS\s916bus.sys [2007-11-02 83496]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s916mdfl.sys [2007-11-02 15016]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s916mdm.sys [2007-11-02 109992]
S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s916mgmt.sys [2007-11-02 103976]
S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s916obex.sys [2007-11-02 100008]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbccgp;Rodzajowy sterownik nadrzędny USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Klasa PRINTER USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Sterownik skanera USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 acssrv;Agnitum Client Security Service; C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe [2008-08-05 1570136]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-06-13 483328]
R2 C-DillaSrv;C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2008-10-07 46080]
R2 HDDlife HDD Access service;HDDlife HDD Access service; C:\Program Files\Common Files\BinarySense\hldasvc.exe [2008-02-15 832760]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\HPZipm12.exe [2007-02-21 73728]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2007-06-13 520192]
S3 aspnet_state;„Usługa stanu ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-08-21 382248]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-05-30 572416]
S3 WMPNetworkSvc;Usługa udostępniania w sieci programu Windows Media Player; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-12-01 918016]
S4 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-03-03 85096]
S4 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-08-08 836904]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.06 2009-06-19 19:22:05
======Uninstall list======
-->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->MsiExec.exe /I{9A346205-EA92-4406-B1AB-50379DA3F057}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
1-abc.net File Washer (Remove only)-->"D:\Program Files\1-abc\File Washer\uninst.exe"
3GP Video Converter 3-->D:\Program Files\Xilisoft\3GP Video Converter 3\Uninstall.exe
ACDSee 10 Photo Manager-->MsiExec.exe /I{F8B98EB6-FC06-45BF-87D4-9784E0408611}
Adobe Flash Player 9 ActiveX-->C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{BB65C393-C76E-4F06-9B0C-2124AA8AF97B}
Adobe Flash Player Plugin-->C:\WINDOWS\System32\Macromed\Flash\uninstall_plugin.exe
Adobe Photoshop 7.0 CE-->C:\WINDOWS\ISUN0415.EXE -f"D:\Program Files\Adobe\Photoshop 7.0 CE\Uninst.isu" -c"D:\Program Files\Adobe\Photoshop 7.0 CE\Uninst.dll"
Adobe Reader 7.0.5 - Polish-->MsiExec.exe /I{AC76BA86-7AD7-1045-7B44-A70500000002}
Advanced Disk Catalog-->D:\PROGRA~1\ADVANC~1\UNWISE.EXE D:\PROGRA~1\ADVANC~1\INSTALL.LOG
Agnitum Outpost Security Suite Pro-->"C:\Program Files\Agnitum\Outpost Security Suite Pro\unins000.exe"
ALLPlayer V3.X-->"C:\Program Files\ALLPlayer\unins000.exe"
AMD Processor Driver-->C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe -runfromtemp -l0x0015 -removeonly
Angielski At Once!-->"D:\Program Files\Atonce\unins000.exe"
AoA Audio Extractor 1.0-->"D:\Program Files\AoA Audio Extractor\unins000.exe"
Archiwizator WinRAR-->D:\Program Files\WinRAR\uninstall.exe
Ashampoo UnInstaller 3.10-->"D:\Program Files\Ashampoo\Ashampoo UnInstaller 3\unins000.exe"
ATI Catalyst Control Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
ATI HYDRAVISION-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}\setup.exe"
ATI Parental Control & Encoder-->MsiExec.exe /I{36CDA33B-909B-4719-97D1-C4B99309BDC7}
AutoCAD 2008 - Polski-->D:\Program Files\AutoCAD 2008\Setup\Setup.exe /P {5783F2D7-6001-0415-0002-0060B0CE6BBA} /M ACAD
Autodesk DWF Viewer 7-->MsiExec.exe /I{9A346205-EA92-4406-B1AB-50379DA3F057}
AVerTV GO 007 Plus-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{8DF56C91-281F-4C15-B954-F45FDC919568} /l1045
AVI ReComp 1.4.5-->D:\Program Files\AVI ReComp\Uninstall.exe
AVIVO Codecs-->MsiExec.exe /X{C941F1F1-25B3-4DF5-83E6-888C51A1AAB6}
BE Inspired! Beginner and Elementary 2008-->"C:\WINDOWS\BE Inspired! Beginner and Elementary 2008\uninstall.exe" "/U:D:\Program Files\BE Inspired! Beginner and Elementary 2008\Uninstall\uninstall.xml"
bEncoder-->D:\PROGRA~1\bPlayer2\UNWISE.EXE D:\PROGRA~1\bPlayer2\INSTALL.LOG
Bluesoleil2.6.0.9 Release 070606-->MsiExec.exe /X{846AC73B-9394-48B9-B941-8F7F472F0047}
CamStudio-->D:\Program Files\CamStudio\uninstall.exe
CCleaner (remove only)-->"D:\Program Files\CCleaner\uninst.exe"
C-Dilla Licence Management System-->C:\C_DILLA\setup\cdunin16.exe
CDRoller version 7.70-->"D:\Program Files\CDRoller\unins000.exe"
CloneCD-->"D:\Program Files\SlySoft\CloneCD\ccd-uninst.exe" /D="D:\Program Files\SlySoft\CloneCD"
ClonyXXL_2.0.1.5_PL-->D:\Program Files\ClonyXXL PL\Uninstal.exe
CodeStuff Starter-->"D:\Program Files\CodeStuff\Starter\unStarter.exe"
Combined Community Codec Pack 2008-01-24-->"D:\Program Files\Combined Community Codec Pack\unins000.exe"
Cryptic Disk 2.4.7.0-->"D:\Program Files\Cryptic Disk\unins000.exe"
Defraggler (remove only)-->"D:\Program Files\Defraggler\uninst.exe"
Desktop Sidebar-->MsiExec.exe /I{A92D7264-1A13-45BE-B769-88445DD04FD6}
Deutsch Translator 2-->D:\Program Files\Deutsch Translator 2\setup.exe -uninstall
Digital Clock Screen Saver-->"C:\WINDOWS\unins004.exe"
DriveImage XML-->"D:\Program Files\Runtime Software\DriveImage XML\Uninstall.exe" "D:\Program Files\Runtime Software\DriveImage XML\install.log" -u
DScaler 4.1.15-->"D:\Program Files\DScaler\unins000.exe"
EfreeSoft Boss Key Version 3.30-->"D:\Program Files\Mgboss\unins000.exe"
Ekspert CD-->C:\WINDOWS\unins002.exe
ERUNT 1.1j-->C:\WINDOWS\ERUNT\unins000.exe
ETI-pro-->MsiExec.exe /I{0ACB1594-6EEC-472F-9B1B-7C8178BBAFEA}
Expressivo-->D:\Program Files\ivo\Expressivo\UsunExpressivo.exe
Festo FluidSim 3.6-->"D:\Program Files\Festo Fluidsim\unins000.exe"
Folder Marker v 1.4-->"D:\Program Files\Folder Marker\unins000.exe"
FotoOffice-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3AC92370-5804-413C-89DA-C9172574E228}\Setup.exe"
FreeDVD Codec Installer Version 1.0-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\CodecInstaller\ST6UNST.LOG"
Gadu-Gadu 7.7-->D:\Program Files\Gadu-GaduR\Setup.exe
Glary Utilities 2.5-->"D:\Program Files\Glary Utilities\unins000.exe"
GMail Drive Shell Extension-->rundll32.exe C:\WINDOWS\system32\ShellExt\GMailFS.dll,Uninstall C:\WINDOWS\system32\ShellExt\GMailFS.inf
GOM Player-->"C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
GoNaomi Dictionary-->D:\Program Files\GoNaomi Dictionary\uninstall.exe
GTA San Andreas-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x9 -removeonly
Hackman Hex Editor-->"D:\Program Files\Hackman\Uninstall.exe" "D:\Program Files\Hackman\install.log"
HDDlife Pro 3.1-->MsiExec.exe /X{E81D9FF6-B45F-4DD4-9673-86B08AF6F705}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
HP Print Diagnostic Utility-->MsiExec.exe /I{5E06C076-E4E7-4239-A886-B3D8AC84C166}
HP PSC & OfficeJet 6.1.A-->"C:\Program Files\HP\Digital Imaging\{27555031-A116-4EC6-9991-7B400142A936}\setup\hpzscr01.exe" -datfile hposcr08.dat
Icon Restore 1.0-->C:\WINDOWS\unins003.exe
ICQ6-->"C:\Program Files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe" -runfromtemp -l0x0009 -removeonly
J2SE Runtime Environment 5.0 Update 10-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
KLS Mail Backup 1.7.0.0-->"D:\Program Files\KLS Soft\KLS Mail Backup\unins000.exe"
KNK-->D:\Program Files\KNK\uninstal.exe
Komputer ŚWIAT - Leksykonia-->"D:\Program Files\Leksykonia\unins000.exe"
Kursy Walut R-->C:\WINDOWS\uninst.exe -f"D:\Program Files\KursyWalut\DeIsL1.isu" -c"D:\Program Files\KursyWalut\_ISREG32.DLL"
Listonosz : Klient Poczty 1.1.6.0-->D:\Program Files\Onet\Listonosz\deinstalacja.exe
MediaMonkey 3.0-->"D:\Program Files\MediaMonkey\unins000.exe"
Memento v1.06-->"D:\Program Files\Memento\unins000.exe"
Microsoft .NET Framework 2.0 — pakiet języka polskiego-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - PLK\install.exe
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110415-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Monopoly by Parker Brothers-->D:\PROGRA~1\Hasbro\MONOPO~1\UNWISE.EXE /U D:\PROGRA~1\Hasbro\MONOPO~1\INSTALL.LOG
Movie DVD Maker 2.6.1123-->"D:\Program Files\Movie DVD Maker\unins000.exe"
Mozilla 1.7.7 (PL)-->C:\WINDOWS\MozillaUninstall.exe /ua "1.7.7 (PL)"
Mozilla Thunderbird (1.0.6)-->C:\WINDOWS\UninstallThunderbird.exe /ua "1.0.6 (pl)"
MSVC80_x86-->MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
MSXML 6.0 Parser-->MsiExec.exe /I{AEB9948B-4FF2-47C9-990E-47014492A0FE}
My Lockbox 1.1 for Windows 2000/XP-->"D:\Program Files\My Lockbox\unins000.exe"
MyPhoneExplorer-->D:\Program Files\MyPhoneExplorer\uninstall.exe
Narzędzie Software Uninstall Utility firmy ATI-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
Need for Speed™ Most Wanted-->D:\Program Files\EA GAMES\Need for Speed Most Wanted\EAUninstall.exe
Nero 8-->MsiExec.exe /X{FAB3A0EF-C845-4AFF-BE3C-98EB480F1045}
New Star Soccer 3-->D:\Program Files\New Star Soccer 3\Usun.exe
Niezbednik CD-->C:\WINDOWS\unins001.exe
Niezbędnik CD-->C:\WINDOWS\unins000.exe
Nowe Gadu-Gadu-->D:\Program Files\Nowe Gadu-Gadu\Uninstall.exe
ObjectDock-->D:\PROGRA~1\Stardock\OBJECT~2\UNWISE.EXE D:\PROGRA~1\Stardock\OBJECT~2\INSTALL.LOG
Paragon Hard Disk Manager 8 Special Edition-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E9E4BB29-FA98-401B-9EDE-9906906E33DE}\Setup.exe" -l0x9
PC Connectivity Solution-->MsiExec.exe /I{9C7C8898-DC29-4E8B-9E77-55A77C3250F6}
PDFCreator-->MsiExec.exe /I{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}
PerformanceTest v6.1-->"D:\Program Files\PerformanceTest\unins000.exe"
PhotoFiltre-->"D:\Program Files\PhotoFiltre\Uninst.exe"
PhotoScape-->"D:\Program Files\PhotoScape\uninstall.exe"
Picasa 2-->"D:\Program Files\Picasa2\Uninstall.exe"
Polski VAG 4.9-->"d:\Program Files\Polski VAG 4.9\unins000.exe"
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
Prawo 2008-->"D:\Program Files\Play\Prawo 2008\unins000.exe"
Profiler v1.2 PL-->D:\Program Files\Profiler PL\Uninstal.exe
ProScan 5.2-->"D:\Program Files\ProScan\uninstall.exe"
QuickTime Alternative 1.66-->"D:\Program Files\QuickTime Alternative\unins000.exe"
Real Alternative 1.7.5-->"D:\Program Files\Real Alternative\unins000.exe"
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\Setup.exe" -l0x15 -removeonly
REALTEK GbE & FE Ethernet PCI NIC Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\Setup.exe" -l0x15 -removeonly
Resident Evil 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9701A4CC-C144-4482-9776-B64BF4A5343F}\setup.exe" -l0x9
Rezystor do Leda 1.0-->"D:\Program Files\Rezystor do Led'a\unins000.exe"
RocketDock 1.3.0-->"C:\WINDOWS\BricoPacks\Vista Inspirat 2Robert\RocketDock\RocketDock\unins000.exe"
Serials 2005-->MsiExec.exe /I{A31838F1-8E0D-4CA3-A40A-20825B92F125}
Słownik Języka Polskiego GoNaomi 1.4-->D:\Program Files\Słownik Języka Polskiego GoNaomi 1.4\uninstall.exe
Słownik-->C:\WINDOWS\uninst.exe -f"C:\Program Files\Słownik\DeIsL1.isu" -c"C:\Program Files\Słownik\_ISREG32.DLL"
Sony Ericsson MMS Home Studio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9462C4AD-D6C4-4365-B4AD-BFE0B1E216C3}\Setup.exe" -l0x9 -l0009 --remove=y
Sony Ericsson PC Suite 3.209.00-->C:\Program Files\InstallShield Installation Information\{2FFE93F0-BB72-4E52-8761-354D1AAA9387}\Setup.exe -runfromtemp -l0x0015 -removeonly
Sony Ericsson PC Suite-->MsiExec.exe /I{5F0FC860-ADE1-4B2D-B0A9-CB9FB17C46E8}
Sony Ericsson Themes Creator 3.11-->D:\Program Files\Sony Ericsson\Themes Creator\Uninstall.exe
Sp5-->MsiExec.exe /I{560F47F7-EB23-44B1-AAFC-667F1CD8FE5C}
Sp5Intl-->MsiExec.exe /I{FD4B33E1-24AE-4535-AA7B-162B30FB57CD}
Sp5TTInt-->MsiExec.exe /I{E415C943-37E5-473F-8BAE-043C56734124}
SpCommon-->MsiExec.exe /I{6C3959C6-943E-44B3-BAAD-570B04B134E5}
Spirit of Fire 3D Screensaver 2.4-->"D:\Program Files\Spirit of Fire 3D Screensaver\unins000.exe"
SpPhones-->MsiExec.exe /I{4DFF1415-4C29-44A8-BFD4-2BCE249C4991}
Sun xVM VirtualBox-->MsiExec.exe /I{30A01FF6-D5DD-4DEE-AA57-253AF79A57B9}
SUPER © Version 2008.bld.30 (Mar 22, 2008)-->D:\PROGRA~1\ERIGHT~1\SUPER\Setup.exe /remove /q0
SyncBack-->"D:\Program Files\2BrightSparks\SyncBack\unins000.exe"
UltraISO Premium V9.2-->"D:\Program Files\UltraISO\unins000.exe"
Unlocker 1.8.0-->D:\Program Files\Unlocker\uninst.exe
Update Service-->D:\Program Files\Sony Ericsson\Update Service\uninst.exe
VIA Platform Device Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
Virtual DJ - Atomix Productions-->D:\PROGRA~1\VIRTUA~3\UNWISE.EXE D:\PROGRA~1\VIRTUA~3\INSTALL.LOG
Virtual DJ 5.2 (Crack v2)-->D:\Program Files\VirtualDJ\Uninstal Crack VirtualDJ.exe
VirtualDubMod 1.5.10.2 PL-->D:\Program Files\VirtualDubMod\Odinstaluj.exe
Vista Drive Icon 1.4-->D:\Program Files\Vista Drive Icon\uninst.exe
Vista Transformation Pack 8.0-->C:\WINDOWS\system32\viwc.exe
Visual Task Tips 2.0-->D:\Program Files\VisualTaskTips\uninst.exe
VobSub 2.23-->D:\Program Files\Gabest\VobSub\uninstall.exe
VueScan-->C:\VueScan\vuescan.exe /remove
WellPhone DirectSync-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CFEC7E01-B73C-451D-A366-96978AFD233B}\setup.exe" UNINSTALL
WellPhone-->"D:\Program Files\SmartCom\WellPhone\UnInst32.exe"
Winamp (remove only)-->"D:\Program Files\Winamp\UninstWA.exe"
Winamp 5.33 PL-->"D:\Program Files\Winamp\uninst-winamp_pl.exe"
Winamp reverb/speaker simulator plugin (remove only)-->"D:\Program Files\Winamp\Plugins\uninst_kreverb.exe"
Windows Configurator v0.6-->"D:\Program Files\Windows Configurator\unins000.exe"
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 2-->C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
Xvid 1.2.1-->D:\Program Files\Xvid\unins000.exe
zaprojektuj swój DOM-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{24576216-414E-4B17-B752-F5ECA71326D2}\setup.exe" -l0x15
Zoner Photo Studio 10-->"D:\Program Files\Zoner\Photo Studio 10\unins000.exe" /SILENT
======Hosts File======
127.0.0.1 localhost
======System event log======
Computer Name: KOWALSKI-MQAXU1
Event Code: 7036
Message: Usługa Usługa odnajdywania SSDP weszła w stan uruchomienia.
Record Number: 18590
Source Name: Service Control Manager
Time Written: 20090524150512.000000+120
Event Type: informacje
User:
Computer Name: KOWALSKI-MQAXU1
Event Code: 7035
Message: Do usługi Usługa odnajdywania SSDP został pomyślnie wysłany kod sterowania uruchom.
Record Number: 18589
Source Name: Service Control Manager
Time Written: 20090524150512.000000+120
Event Type: informacje
User: ZARZĄDZANIE NT\SYSTEM
Computer Name: KOWALSKI-MQAXU1
Event Code: 7036
Message: Usługa Menedżer połączeń usługi Dostęp zdalny weszła w stan uruchomienia.
Record Number: 18588
Source Name: Service Control Manager
Time Written: 20090524150511.000000+120
Event Type: informacje
User:
Computer Name: KOWALSKI-MQAXU1
Event Code: 7035
Message: Do usługi Menedżer połączeń usługi Dostęp zdalny został pomyślnie wysłany kod sterowania uruchom.
Record Number: 18587
Source Name: Service Control Manager
Time Written: 20090524150511.000000+120
Event Type: informacje
User: ZARZĄDZANIE NT\SYSTEM
Computer Name: KOWALSKI-MQAXU1
Event Code: 7036
Message: Usługa Telefonia weszła w stan uruchomienia.
Record Number: 18586
Source Name: Service Control Manager
Time Written: 20090524150511.000000+120
Event Type: informacje
User:
=====Application event log=====
Computer Name: KOWALSKI-MQAXU1
Event Code: 0
Message:
Record Number: 5
Source Name: PD91Agent
Time Written: 20090302141117.000000+060
Event Type: informacje
User:
Computer Name: KOWALSKI-MQAXU1
Event Code: 105
Message: The service was started.
Record Number: 4
Source Name: ATI Smart
Time Written: 20090302141110.000000+060
Event Type: informacje
User:
Computer Name: KOWALSKI-MQAXU1
Event Code: 1
Message:
Record Number: 3
Source Name: Diskeeper
Time Written: 20090301204457.000000+060
Event Type: informacje
User:
Computer Name: KOWALSKI-MQAXU1
Event Code: 0
Message:
Record Number: 2
Source Name: PD91Agent
Time Written: 20090301204456.000000+060
Event Type: informacje
User:
Computer Name: KOWALSKI-MQAXU1
Event Code: 105
Message: The service was started.
Record Number: 1
Source Name: ATI Smart
Time Written: 20090301204450.000000+060
Event Type: informacje
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\PC Connectivity Solution;C:\Program Files\Common Files\Teleca Shared;D:\PROGRA~1\DISKEE~1\DISKEE~1;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=6b01
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"DEFAULT_CA_NR"=CA6
"FP_NO_HOST_CHECK"=NO
-----------------EOF-----------------
Windows Registry Editor Version 5.00
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\P]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\R]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1de35da4-e47b-11dc-8d8a-c78261217473}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7384ae84-857a-11dd-8ffb-0011679add53}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97ae7c71-e474-11dc-95a0-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d54df804-2cc4-11de-921d-0011679add53}]
daj executeFiles to delete:
D:\explorefiles.exe
E:\explorefiles.exe
P:\explorefiles.exe
R:\explorefiles.exe
S:\explorefiles.exe
P:\explorefiles.exe
E:\viewfiles.exe
P:\explorefiles.exe
OTL logfile created on: 2009-06-20 13:18:01 - Run 5
OTL by OldTimer - Version 2.1.1.0 Folder = F:\Nowy folder (2)
Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
1022,42 Mb Total Physical Memory | 581,19 Mb Available Physical Memory | 56,84% Memory free
2,41 Gb Paging File | 2,01 Gb Available in Paging File | 83,58% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38,31 Gb Total Space | 7,59 Gb Free Space | 19,82% Space Free | Partition Type: NTFS
Drive D: | 129,31 Gb Total Space | 47,22 Gb Free Space | 36,52% Space Free | Partition Type: NTFS
Drive E: | 51,12 Gb Total Space | 16,07 Gb Free Space | 31,43% Space Free | Partition Type: NTFS
Drive F: | 9,09 Gb Total Space | 3,61 Gb Free Space | 39,68% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KOWALSKI-MQAXU1
Current User Name: MT
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
[color=orange]========== Processes (SafeList) ==========[/color]
PRC - [2007-06-13 21:15:38 | 00,483,328 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2008-10-07 14:34:22 | 00,046,080 | ---- | M] (C-Dilla Ltd) -- C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
PRC - [2008-02-15 14:17:00 | 00,832,760 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\Common Files\BinarySense\hldasvc.exe
PRC - [2008-02-15 14:17:00 | 00,832,760 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\Common Files\BinarySense\hldasvc.exe
PRC - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2007-02-21 03:35:02 | 00,073,728 | ---- | M] (HP) -- C:\WINDOWS\System32\HPZipm12.exe
PRC - [2007-06-13 21:15:38 | 00,483,328 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2004-08-04 00:44:20 | 01,423,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2008-04-13 14:39:20 | 00,049,152 | ---- | M] (artArmin) -- D:\Program Files\Vista Drive Icon\DrvIcon.exe
PRC - [2006-09-29 09:57:30 | 00,049,152 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
PRC - [2007-11-20 14:51:46 | 00,524,288 | ---- | M] () -- C:\Program Files\Vista Sidebar\sidebar.exe
PRC - [2006-05-28 09:07:11 | 00,036,864 | ---- | M] (VisualTaskTips.com) -- D:\Program Files\VisualTaskTips\VisualTaskTips.exe
PRC - [2007-06-06 16:50:42 | 00,657,168 | ---- | M] (IVT Corporation.) -- C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
PRC - [2009-02-06 01:40:06 | 03,702,807 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
PRC - [2007-04-30 20:43:54 | 03,450,608 | ---- | M] (Stardock) -- D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
PRC - [2006-10-30 15:16:54 | 02,721,536 | ---- | M] (2BrightSparks) -- D:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
PRC - [2005-08-09 15:26:47 | 00,100,352 | ---- | M] (Vetch Utilities) -- D:\Program Files\SysInfoMyWork\SysInfoMyWork.exe
PRC - [2006-09-29 09:57:36 | 00,049,152 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
PRC - [2005-04-14 20:08:00 | 00,098,192 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla.org\Mozilla\mozilla.exe
PRC - [2008-05-30 23:09:46 | 00,731,136 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\avenger\avenger.exe
PRC - [2009-06-18 16:58:47 | 00,501,760 | ---- | M] (OldTimer Tools) -- F:\Nowy folder (2)\OTL.exe
[color=orange]========== Win32 Services (SafeList) ==========[/color]
SRV - [2008-08-05 16:51:56 | 01,570,136 | ---- | M] (Agnitum Ltd.) -- C:\Program Files\Agnitum\Outpost Security Suite Pro\acs.exe -- (acssrv [Auto | Running])
SRV - [2005-09-23 07:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2007-06-13 21:15:38 | 00,483,328 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
SRV - [2007-06-13 14:29:00 | 00,520,192 | ---- | M] () -- C:\WINDOWS\system32\ati2sgag.exe -- (ATI Smart [Auto | Stopped])
SRV - [2009-03-03 18:20:34 | 00,085,096 | ---- | M] (Autodesk) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service [Disabled | Stopped])
SRV - [2008-10-07 14:34:22 | 00,046,080 | ---- | M] (C-Dilla Ltd) -- C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE -- (C-DillaSrv [Auto | Running])
SRV - [2005-09-23 07:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - File not found -- -- (gusvc [Disabled | Stopped])
SRV - [2008-02-15 14:17:00 | 00,832,760 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\Common Files\BinarySense\hldasvc.exe -- (HDDlife HDD Access service [Auto | Running])
SRV - [2004-08-04 00:44:08 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
SRV - [2007-08-08 09:25:08 | 00,836,904 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe -- (Nero BackItUp Scheduler 3 [Disabled | Stopped])
SRV - [2007-08-21 14:52:54 | 00,382,248 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Stopped])
SRV - [2003-07-28 21:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2007-02-21 03:35:02 | 00,073,728 | ---- | M] (HP) -- C:\WINDOWS\System32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2008-05-30 12:32:16 | 00,572,416 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer [On_Demand | Stopped])
SRV - [2006-12-01 12:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
[color=orange]========== Driver Services (SafeList) ==========[/color]
DRV - [2002-10-09 13:53:54 | 00,043,904 | ---- | M] (Alfa Corporation) -- C:\WINDOWS\System32\Drivers\AFPAnsi.sys -- (AFPAnsi [Boot | Running])
DRV - [2008-06-30 18:16:00 | 00,030,864 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\DRIVERS\afw.sys -- (afw [On_Demand | Running])
DRV - [2008-06-30 18:16:14 | 00,234,640 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\drivers\afwcore.sys -- (afwcore [On_Demand | Running])
DRV - [2006-02-17 11:15:34 | 03,846,848 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
DRV - [2008-06-09 18:16:53 | 00,005,888 | ---- | M] (Alexey V.Voronin @ Hexy) -- C:\WINDOWS\System32\Drivers\AMD64CAx86.sys -- (AMD64CA [On_Demand | Stopped])
DRV - [2006-07-02 00:32:26 | 00,043,520 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\DRIVERS\AmdK8.sys -- (AmdK8 [System | Running])
DRV - [2008-07-11 16:42:08 | 00,033,408 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\Filt\ASWFilt.dll -- (ASWFilt [On_Demand | Running])
DRV - [2007-06-13 21:24:12 | 02,155,520 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
DRV - [2007-05-11 04:10:50 | 00,034,704 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\DRIVERS\blueletaudio.sys -- (BlueletAudio [On_Demand | Running])
DRV - [2007-03-05 07:00:04 | 00,027,792 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\DRIVERS\BlueletSCOAudio.sys -- (BlueletSCOAudio [On_Demand | Running])
DRV - [2007-05-23 05:21:12 | 00,016,272 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\DRIVERS\btnetdrv.sys -- (BT [On_Demand | Running])
DRV - [2007-05-23 05:20:58 | 00,036,496 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\Drivers\btcusb.sys -- (Btcsrusb [On_Demand | Running])
DRV - [2007-03-05 06:55:12 | 00,020,880 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\Drivers\vbtenum.sys -- (BTHidEnum [Boot | Running])
DRV - [2007-03-05 06:56:18 | 00,035,600 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr [Boot | Running])
DRV - [2006-11-21 23:41:18 | 00,022,416 | ---- | M] (IVT Corporation.) -- C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys -- (BTNetFilter [On_Demand | Stopped])
DRV - [2008-10-07 13:53:25 | 00,058,288 | ---- | M] (Macrovision) -- C:\WINDOWS\system32\drivers\CDANT.SYS -- (C-Dilla [On_Demand | Stopped])
DRV - [2009-03-24 13:06:07 | 00,346,304 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) -- C:\WINDOWS\System32\DRIVERS\Cap7134.sys -- (Cap7134 [On_Demand | Running])
DRV - [2006-11-25 17:14:58 | 00,066,688 | ---- | M] (EXLADE, Inc.) -- C:\WINDOWS\system32\Drivers\CrypticDisk.sys -- (CrypticDisk [Auto | Running])
DRV - [2005-12-18 20:42:12 | 00,008,801 | ---- | M] () -- D:\Program Files\DScaler\DSDrv4.sys -- (DSDrv4 [On_Demand | Stopped])
DRV - [2006-12-26 14:54:35 | 00,034,760 | ---- | M] (SlySoft, Inc.) -- C:\WINDOWS\System32\Drivers\ElbyCDFL.sys -- (ElbyCDFL [On_Demand | Running])
DRV - [2006-12-26 14:54:34 | 00,015,440 | ---- | M] (Elaborate Bytes AG) -- C:\WINDOWS\System32\Drivers\ElbyCDIO.sys -- (ElbyCDIO [Auto | Running])
DRV - [2003-07-17 12:56:32 | 00,089,216 | ---- | M] () -- C:\WINDOWS\System32\Drivers\FO_PAnt.sys -- (FO_PAnt [Boot | Running])
DRV - [2007-02-03 05:56:58 | 00,030,808 | ---- | M] (Paragon Software Group) -- C:\WINDOWS\system32\drivers\hotcore2.sys -- (hotcore2 [Boot | Running])
DRV - [2005-10-28 03:24:28 | 00,049,664 | ---- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys -- (HPZid412 [On_Demand | Stopped])
DRV - [2005-10-28 03:24:29 | 00,016,496 | ---- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys -- (HPZipr12 [On_Demand | Stopped])
DRV - [2005-10-28 03:24:30 | 00,021,568 | ---- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys -- (HPZius12 [On_Demand | Stopped])
DRV - [2008-05-24 21:09:08 | 00,073,728 | ---- | M] (EZB Systems, Inc.) -- D:\Program Files\UltraISO\drivers\ISODrive.sys -- (ISODrive [System | Running])
DRV - [2006-08-18 12:10:24 | 00,061,504 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320bus.sys -- (K320bus [On_Demand | Running])
DRV - [2006-08-18 12:10:22 | 00,009,328 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320mdfl.sys -- (K320mdfl [On_Demand | Running])
DRV - [2006-08-18 12:10:22 | 00,097,056 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320mdm.sys -- (K320mdm [On_Demand | Running])
DRV - [2006-08-18 12:10:20 | 00,088,560 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320mgmt.sys -- (K320mgmt [On_Demand | Running])
DRV - [2006-08-18 12:10:18 | 00,086,368 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320obex.sys -- (K320obex [On_Demand | Running])
DRV - [2007-04-18 00:52:38 | 00,017,264 | ---- | M] (FSPro Labs) -- C:\WINDOWS\SYSTEM32\DRIVERS\MPRIFL.SYS -- (MPRIFL [Boot | Running])
DRV - [2008-03-11 18:53:32 | 00,002,208 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\nxsIO32.sys -- (nxsIO32 [Auto | Running])
DRV - [2008-02-26 17:58:33 | 00,047,360 | ---- | M] (VSO Software) -- C:\WINDOWS\System32\Drivers\pcouffin.sys -- (pcouffin [On_Demand | Running])
DRV - [2009-03-24 13:06:07 | 00,054,304 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) -- C:\WINDOWS\System32\DRIVERS\PhTVTune.sys -- (PhTVTune [On_Demand | Running])
DRV - [2001-11-08 17:02:50 | 00,003,912 | ---- | M] () -- C:\WINDOWS\System32\Drivers\port_nt.sys -- (port_nt [Auto | Running])
DRV - [2001-08-17 23:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2006-09-27 23:53:22 | 00,036,560 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2001-08-17 23:57:36 | 00,005,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Drivers\RootMdm.sys -- (ROOTMODEM [On_Demand | Running])
DRV - [2006-02-26 23:46:20 | 00,081,408 | R--- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys -- (RTL8023xp [On_Demand | Stopped])
DRV - [2004-08-03 22:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS -- (rtl8139 [On_Demand | Stopped])
DRV - [2007-12-10 15:22:14 | 00,083,880 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017bus.sys -- (s3017bus [On_Demand | Stopped])
DRV - [2007-12-10 15:22:18 | 00,015,016 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017mdfl.sys -- (s3017mdfl [On_Demand | Stopped])
DRV - [2007-12-10 15:22:18 | 00,110,632 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017mdm.sys -- (s3017mdm [On_Demand | Stopped])
DRV - [2007-12-10 15:22:20 | 00,104,616 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017mgmt.sys -- (s3017mgmt [On_Demand | Stopped])
DRV - [2007-12-10 15:22:20 | 00,025,512 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017nd5.sys -- (s3017nd5 [On_Demand | Stopped])
DRV - [2007-12-10 15:22:22 | 00,100,648 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017obex.sys -- (s3017obex [On_Demand | Stopped])
DRV - [2007-12-10 15:22:22 | 00,110,120 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017unic.sys -- (s3017unic [On_Demand | Stopped])
DRV - [2006-02-08 01:40:24 | 00,806,400 | R--- | M] (S3 Graphics Co., Ltd.) -- C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys -- (S3GIGP [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,083,496 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916bus.sys -- (s916bus [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,015,016 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916mdfl.sys -- (s916mdfl [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,109,992 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916mdm.sys -- (s916mdm [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,103,976 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916mgmt.sys -- (s916mgmt [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,100,008 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916obex.sys -- (s916obex [On_Demand | Stopped])
DRV - [2008-07-11 16:41:28 | 00,673,920 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\DRIVERS\SandBox.sys -- (SandBox [System | Running])
DRV - [2002-03-25 20:02:14 | 00,027,440 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2005-08-10 14:44:04 | 00,050,688 | ---- | M] (Protection Technology) -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01 [Boot | Running])
DRV - [2006-07-05 14:46:06 | 00,063,352 | ---- | M] (Protection Technology (StarForce)) -- C:\WINDOWS\System32\drivers\sfdrv01a.sys -- (sfdrv01a [Boot | Running])
DRV - [2006-06-14 16:56:56 | 00,013,680 | ---- | M] (Protection Technology (StarForce)) -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02 [Boot | Running])
DRV - [2005-11-03 16:40:07 | 00,063,488 | ---- | M] (Protection Technology) -- C:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02 [Boot | Running])
DRV - [2009-01-23 18:29:43 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2006-11-10 15:08:50 | 00,024,064 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\SysTool.sys -- (SysTool [System | Stopped])
DRV - [2008-06-04 18:36:14 | 01,072,722 | ---- | M] (VirusBuster Kft.) -- C:\WINDOWS\system32\DRIVERS\VBEngNT.sys -- (VBEngNT [On_Demand | Running])
DRV - [2008-07-11 16:42:04 | 00,158,816 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\Filt\VBFilt.dll -- (VBFilt [On_Demand | Running])
DRV - [2008-09-12 17:00:46 | 00,095,888 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys -- (VBoxDrv [System | Running])
DRV - [2008-09-12 17:00:50 | 00,041,680 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys -- (VBoxUSBMon [System | Running])
DRV - [2007-03-05 06:52:18 | 00,034,448 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\DRIVERS\VComm.sys -- (VComm [On_Demand | Running])
DRV - [2007-03-05 06:53:18 | 00,044,304 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\Drivers\VcommMgr.sys -- (VcommMgr [On_Demand | Running])
DRV - [2003-07-01 22:42:00 | 00,027,904 | R--- | M] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\viaagp1.sys -- (viaagp1 [Boot | Running])
[color=orange]========== Standard Registry (SafeList) ==========[/color]
[color=orange]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/
IE - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=orange]========== FireFox ==========[/color]
FF - prefs.js..browser.startup.homepage: "http://www.google.pl"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:0.7.5.5
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.0.3
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.6
FF - prefs.js..extensions.enabledItems: {53A03D43-5363-4669-8190-99061B2DEBA5}:1.3.3.7
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0
FF - HKLM\software\mozilla\Mozilla 1.7.7\Extensions\\Components: D:\PROGRAM FILES\MOZILLA.ORG\MOZILLA\COMPONENTS [2008-07-04 16:34:14 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla 1.7.7\Extensions\\Plugins: D:\PROGRAM FILES\MOZILLA.ORG\MOZILLA\PLUGINS [2009-06-09 21:37:40 | 00,000,000 | ---D | M]
[2009-02-18 15:05:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Extensions
[2009-02-18 15:05:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-02-18 15:15:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions
[2009-02-18 15:15:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2009-02-18 15:14:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2009-02-18 15:09:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-02-18 15:11:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Idea2 SidebarBrowserMonitor Class) - {45AD732C-2CE2-4666-B366-B2214AD57A49} - D:\Program Files\Desktop Sidebar\sbhelp.dll (Idea2)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Expressivo) - {85F685C3-20D9-4943-95E4-EB4224056C3F} - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll (IVO Software Sp. z o.o.)
O3 - HKLM\..\Toolbar: (Expressivo) - {85F685C3-20D9-4943-95E4-EB4224056C3F} - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll (IVO Software Sp. z o.o.)
O3 - HKLM\..\Toolbar: (StylerToolBar) - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll (StyleFantasist)
O3 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [DrvIcon] D:\Program Files\Vista Drive Icon\DrvIcon.exe (artArmin)
O4 - HKLM..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice (Agnitum Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [VisualTooltip] File not found
O4 - HKLM..\Run: [WellPhone DirectSync - ScheduleSync] D:\PROGRA~1\WELLPH~1\SCHEDU~1.EXE (SmartCom)
O4 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003..\Run: [Vista Sidebar] C:\Program Files\Vista Sidebar\sidebar.exe ()
O4 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003..\Run: [VisualTaskTips] D:\Program Files\VisualTaskTips\VisualTaskTips.exe (VisualTaskTips.com)
O4 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003..\Run: [Windows Intranet controller] C:\WINDOWS\security\lsass.exe ()
O4 - HKLM..\RunOnce: [Cleanup] C:\cleanup.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe (IVT Corporation.)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\ERUNT AutoBackup.lnk = C:\WINDOWS\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\HDDlife.lnk = C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe (BinarySense, Inc.)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\SyncBack.lnk = D:\Program Files\2BrightSparks\SyncBack\SyncBack.exe (2BrightSparks)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\SysInfoMyWork.lnk = D:\Program Files\SysInfoMyWork\SysInfoMyWork.exe (Vetch Utilities)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\Thoosje Vista Sidebar.lnk = C:\Program Files\Vista Sidebar\sidebar.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuEjectPC = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecycleFiles = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuEjectPC = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EditLevel = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra 'Tools' menuitem : Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra Button: Ustawienia Outpost Security Suite Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Security Suite Pro\ie_bar.dll (Agnitum Ltd.)
O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java (Reg Error: Key error.)
O18 - Protocol\Handler\hddlife {BD758015-47D9-477A-8873-4B688A2BC0E2} - C:\Program Files\Common Files\BinarySense\hlAPP.dll (BinarySense, Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (vistaui.exe) - C:\WINDOWS\system32\vistaui.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-02-26 15:34:55 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009-06-19 17:59:44 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-20 12:47:35 | 00,000,225 | RH-- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-20 12:47:36 | 00,000,225 | RH-- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-20 13:07:44 | 00,000,225 | ---- | M] () - F:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009-06-20 13:17:44 | 00,000,000 | ---D | M]
[color=orange]========== Files/Folders - Created Within 30 Days ==========[/color]
[2009-06-20 13:15:32 | 00,135,168 | ---- | C] () -- C:\zip.exe
[2009-06-20 13:15:32 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\gbzw.sys
[2009-06-20 13:15:32 | 00,019,286 | ---- | C] () -- C:\cleanup.exe
[2009-06-20 13:15:32 | 00,000,574 | ---- | C] () -- C:\cleanup.bat
[2009-06-20 13:15:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MT\Pulpit\avenger
[2009-06-20 11:32:53 | 00,026,956 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\avenger.jpg
[2009-06-20 11:20:02 | 00,000,000 | ---D | C] -- C:\Avenger
[2009-06-20 11:11:08 | 00,724,952 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\avenger.zip
[2009-06-19 19:19:34 | 00,000,000 | ---D | C] -- C:\rsit
[2009-06-19 19:19:34 | 00,000,000 | ---D | C] -- C:\Program Files\trend micro
[2009-06-19 19:14:28 | 00,781,909 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\RSITv.exe
[2009-06-19 17:59:44 | 00,000,000 | RHSD | C] -- C:\autorun.inf
[2009-06-18 22:08:13 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\AutoCAD Zestawy arkuszy
[2009-06-18 22:08:09 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\CyberLink
[2009-06-18 22:08:09 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Bluetooth
[2009-06-18 22:07:28 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Dokumenty
[2009-06-18 22:07:22 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\GTA San Andreas User Files
[2009-06-18 22:07:22 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\G DATA
[2009-06-18 22:07:22 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Dokumenty nie posegregowane
[2009-06-18 22:07:21 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\GTA Vice City User Files
[2009-06-18 21:30:50 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\Moja muzyka
[2009-06-18 21:27:00 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\Moje obrazy
[2009-06-18 21:26:35 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\Moje wideo
[2009-06-18 21:26:29 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\Moje zakupy allegro
[2009-06-18 21:26:29 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\My Backups
[2009-06-18 21:26:21 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\NFS Most Wanted
[2009-06-18 21:26:21 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\NeroVision
[2009-06-18 21:26:17 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Recover
[2009-06-18 21:24:24 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\sony ericsson
[2009-06-18 21:24:23 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\torrenty
[2009-06-18 21:24:23 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\TikGames
[2009-06-18 21:24:23 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Stardock
[2009-06-18 21:24:20 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\ZPS10
[2009-06-18 21:24:20 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\VirtualDJ
[2009-06-18 19:48:45 | 00,001,280 | -H-- | C] () -- E:\Moje dokumenty\Memento.notes
[2009-06-18 19:48:45 | 00,000,000 | -HS- | C] () -- E:\Moje dokumenty\desktop.ini
[2009-06-18 18:46:47 | 00,395,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF30042.exe
[2009-06-18 18:44:44 | 00,395,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF29595.exe
[2009-06-17 20:42:54 | 00,578,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2009-06-16 11:18:05 | 00,000,671 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\File Washer.lnk
[2009-06-15 19:10:12 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Advanced Disk Catalog.lnk
[2009-06-15 19:09:59 | 00,000,593 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\AoA Audio Extractor.lnk
[2009-06-15 19:09:39 | 00,000,663 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\CCleaner.lnk
[2009-06-15 19:09:29 | 00,000,585 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\CDRoller.lnk
[2009-06-15 19:09:19 | 00,000,779 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\CyberLink PowerDVD.lnk
[2009-06-15 19:08:50 | 00,001,806 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\FotoOffice 3.lnk
[2009-06-15 19:08:41 | 00,000,560 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Glary Utilities.lnk
[2009-06-15 19:08:34 | 00,000,770 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\GOM Player.lnk
[2009-06-15 19:08:11 | 00,000,551 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\MediaMonkey.lnk
[2009-06-15 19:08:04 | 00,002,551 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Microsoft Office Word 2003.lnk
[2009-06-15 19:07:57 | 00,002,106 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Microsoft Office Excel 2003.lnk
[2009-06-15 19:07:50 | 00,000,779 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Nawigator.lnk
[2009-06-15 19:07:37 | 00,000,811 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\MyPhoneExplorer.lnk
[2009-06-15 19:07:30 | 00,002,075 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Nero Express.lnk
[2009-06-15 19:07:20 | 00,000,609 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\PhotoFiltre.lnk
[2009-06-15 19:07:10 | 00,000,601 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\PhotoScape.lnk
[2009-06-15 19:07:04 | 00,000,573 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Picasa2.lnk
[2009-06-15 19:06:32 | 00,000,683 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\VirtualBox.lnk
[2009-06-15 19:06:27 | 00,000,770 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\SUPER ©.lnk
[2009-06-15 19:06:18 | 00,000,539 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Virtual DJ.lnk
[2009-06-15 19:06:11 | 00,000,643 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\VirtualDubMod 1.5.10.2 PL.lnk
[2009-06-15 19:05:54 | 00,000,565 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Winamp.lnk
[2009-06-15 19:05:44 | 00,000,741 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Xilisoft 3GP Video Converter 3.lnk
[2009-06-15 19:05:33 | 00,000,874 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Resident Evil 3.lnk
[2009-06-15 19:05:22 | 00,000,704 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Adobe Photoshop 7.0 CE.lnk
[2009-06-15 19:05:16 | 00,000,609 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\ClonyXXL_PL.lnk
[2009-06-15 19:05:10 | 00,000,600 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Profiler_PL.lnk
[2009-06-15 19:05:00 | 00,000,657 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\CloneCD.lnk
[2009-06-15 19:04:50 | 00,000,658 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\ALLPlayer V3.4.lnk
[2009-06-15 19:04:45 | 00,002,193 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\AutoCAD 2008.lnk
[2009-06-15 19:04:38 | 00,000,575 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Movie DVD Maker.lnk
[2009-06-15 19:04:33 | 00,002,080 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\ACDSee 10 Photo Manager.lnk
[2009-06-15 19:04:20 | 00,001,532 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\AVerTV GO 007 Plus.lnk
[2009-06-15 19:03:49 | 00,000,523 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\DScaler.lnk
[2009-06-14 11:15:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MT\Pulpit\Nowy folder
[2009-06-12 19:49:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MT\Dane aplikacji\Stardock
[2009-06-12 19:36:06 | 00,000,748 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Cryptic Disk.lnk
[2009-06-12 18:40:46 | 05,552,104 | ---- | C] (Xequte Software) -- C:\WINDOWS\xdclock.scr
[2009-06-12 18:40:46 | 00,674,138 | ---- | C] () -- C:\WINDOWS\unins004.exe
[2009-06-12 18:40:46 | 00,001,652 | ---- | C] () -- C:\WINDOWS\unins004.dat
[2009-06-12 18:39:20 | 00,118,845 | ---- | C] (Matt Ginzton) -- C:\WINDOWS\Flurry.scr
[2009-06-10 17:04:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MT\Dane aplikacji\AVI ReComp
[2009-06-05 15:43:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\BVRP Software
[2009-06-04 15:46:45 | 01,018,104 | ---- | C] () -- C:\WINDOWS\System\windefx.exe
[2009-06-01 18:39:09 | 00,000,000 | ---D | C] -- C:\Program Files\TRACERMM SOFT
[2009-05-27 16:28:10 | 00,868,445 | ---- | C] () -- C:\WINDOWS\System\pagefile2.exe
[2009-05-21 22:41:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\KLS Soft
[2009-04-28 19:54:06 | 00,000,032 | ---- | C] () -- C:\WINDOWS\CD-Start.INI
[2009-04-21 18:05:07 | 00,000,126 | ---- | C] () -- C:\WINDOWS\SCRABMAN.INI
[2009-03-09 01:05:59 | 00,000,076 | ---- | C] () -- C:\WINDOWS\System32\w3url.dll
[2009-03-06 00:14:13 | 00,000,126 | RH-- | C] () -- C:\WINDOWS\System32\NTIDBD32.dll
[2009-03-03 22:40:43 | 00,129,024 | ---- | C] () -- C:\WINDOWS\System32\AVERM.dll
[2009-03-03 22:40:43 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll
[2009-02-13 21:59:18 | 00,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2009-02-06 13:29:25 | 00,000,046 | ---- | C] () -- C:\WINDOWS\Resecik.ini
[2009-01-25 22:13:10 | 00,000,096 | ---- | C] () -- C:\WINDOWS\docs.ini
[2009-01-13 13:12:06 | 00,000,029 | ---- | C] () -- C:\WINDOWS\System32\vfolx32n.dll
[2009-01-13 12:33:35 | 00,000,065 | ---- | C] () -- C:\WINDOWS\WaterIllusion.ini
[2009-01-13 01:42:20 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\wbload.dll
[2009-01-12 12:45:08 | 00,001,046 | ---- | C] () -- C:\WINDOWS\ARCHPR.INI
[2009-01-12 01:24:35 | 00,000,169 | ---- | C] () -- C:\WINDOWS\Clony2.ini
[2009-01-11 23:56:50 | 00,000,215 | ---- | C] () -- C:\WINDOWS\Informat.ini
[2009-01-05 18:13:19 | 00,000,063 | ---- | C] () -- C:\WINDOWS\DeskTopBird_K.ini
[2008-12-18 00:30:06 | 00,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008-12-18 00:30:06 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008-12-08 19:54:53 | 00,090,112 | ---- | C] ( ) -- C:\WINDOWS\System32\STAPI.dll
[2008-12-08 19:52:33 | 00,000,035 | ---- | C] () -- C:\WINDOWS\System32\RTELM.dll
[2008-11-19 23:05:48 | 00,000,026 | ---- | C] () -- C:\WINDOWS\mgboss_reg.ini
[2008-11-19 16:15:49 | 00,000,058 | ---- | C] () -- C:\WINDOWS\GScript.INI
[2008-11-19 16:01:02 | 00,000,131 | ---- | C] () -- C:\WINDOWS\CRC.INI
[2008-11-18 23:02:07 | 00,095,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\VBoxDrv.sys
[2008-11-18 22:05:10 | 00,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008-11-06 15:22:21 | 02,416,128 | R--- | C] () -- C:\WINDOWS\System32\s3gcil_inv.dll
[2008-10-11 00:50:37 | 00,000,193 | ---- | C] () -- C:\WINDOWS\Net2fone.ini
[2008-10-07 18:06:20 | 00,000,990 | ---- | C] () -- C:\WINDOWS\psmplay.ini
[2008-09-23 20:17:11 | 00,000,000 | ---- | C] () -- C:\WINDOWS\TeleText.INI
[2008-09-23 20:17:10 | 00,000,064 | ---- | C] () -- C:\WINDOWS\AVerText.ini
[2008-09-09 23:42:24 | 00,000,038 | ---- | C] () -- C:\WINDOWS\WindowSystemCheck.ini
[2008-09-04 19:36:54 | 00,000,359 | ---- | C] () -- C:\WINDOWS\MP3trt.ini
[2008-09-03 13:22:30 | 00,000,135 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008-09-01 18:41:02 | 00,000,388 | ---- | C] () -- C:\WINDOWS\Swish.INI
[2008-09-01 17:13:59 | 00,000,115 | ---- | C] () -- C:\WINDOWS\AIMPR.INI
[2008-08-31 12:02:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\IQ test.INI
[2008-08-23 17:43:48 | 00,000,031 | ---- | C] () -- C:\WINDOWS\System32\Days5.ini
[2008-08-23 17:17:18 | 00,001,144 | ---- | C] () -- C:\WINDOWS\Cerberus.ini
[2008-08-23 17:07:04 | 00,089,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\FO_PAnt.sys
[2008-08-20 18:34:38 | 00,000,024 | ---- | C] () -- C:\WINDOWS\dlb.ini
[2008-08-20 18:31:05 | 00,000,035 | ---- | C] () -- C:\WINDOWS\S&D22.INI
[2008-07-21 14:11:25 | 00,408,576 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
[2008-07-21 14:11:25 | 00,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2008-07-21 14:02:49 | 00,027,648 | -HS- | C] () -- C:\WINDOWS\System32\Smab0.dll
[2008-07-18 17:28:25 | 00,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2008-07-02 18:30:03 | 00,003,240 | ---- | C] () -- C:\WINDOWS\jmshw-n16.ini
[2008-06-09 17:19:13 | 04,239,360 | ---- | C] () -- C:\WINDOWS\System32\qtp-mt334.dll
[2008-06-09 17:19:13 | 00,008,192 | ---- | C] () -- C:\WINDOWS\System32\wnaspi32.dll
[2008-05-23 13:00:16 | 00,000,306 | ---- | C] () -- C:\WINDOWS\kingpong1.INI
[2008-05-22 11:14:00 | 00,000,216 | ---- | C] () -- C:\WINDOWS\gfscore.ini
[2008-05-22 11:05:44 | 00,000,281 | ---- | C] () -- C:\WINDOWS\hero.ini
[2008-05-06 20:26:23 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2008-05-06 10:51:26 | 00,000,176 | ---- | C] () -- C:\WINDOWS\CDPlayer.ini
[2008-05-01 17:56:46 | 00,000,035 | ---- | C] () -- C:\WINDOWS\galaxy.ini
[2008-05-01 17:43:37 | 00,029,696 | ---- | C] () -- C:\WINDOWS\System32\pthread.dll
[2008-03-22 21:00:36 | 00,000,018 | ---- | C] () -- C:\WINDOWS\gfact.ini
[2008-03-11 18:53:32 | 00,002,208 | ---- | C] () -- C:\WINDOWS\System32\drivers\nxsIO32.sys
[2008-03-06 00:45:40 | 00,003,912 | ---- | C] () -- C:\WINDOWS\System32\drivers\port_nt.sys
[2008-02-27 17:52:47 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-02-27 16:52:37 | 00,000,641 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-02-26 20:52:01 | 00,000,100 | ---- | C] () -- C:\WINDOWS\festo.ini
[2008-02-26 18:44:23 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2008-02-26 17:48:56 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008-02-26 17:18:32 | 00,000,000 | ---- | C] () -- C:\WINDOWS\mngui.INI
[2008-02-26 16:59:13 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008-02-26 16:43:08 | 00,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008-02-26 16:43:00 | 00,000,164 | R--- | C] () -- C:\WINDOWS\avrack.ini
[2008-02-26 16:24:29 | 00,000,223 | ---- | C] () -- C:\WINDOWS\System32\BOOTBAK.INI
[2006-11-10 15:08:50 | 00,024,064 | ---- | C] () -- C:\WINDOWS\System32\drivers\SysTool.sys
[2005-10-30 14:28:39 | 00,107,008 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005-10-30 14:28:33 | 00,020,992 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2004-10-31 18:39:02 | 00,005,526 | ---- | C] () -- C:\WINDOWS\AVerTV.ini
[2003-03-15 09:27:30 | 00,000,117 | ---- | C] () -- C:\WINDOWS\Prof.ini
[2002-10-16 00:54:04 | 00,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2002-09-20 18:04:04 | 00,021,811 | ---- | C] () -- C:\WINDOWS\System32\aaqveq.dll
[2002-03-25 20:02:14 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2001-10-28 17:42:30 | 00,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2001-08-13 20:09:48 | 00,659,520 | ---- | C] () -- C:\WINDOWS\System32\vbid3lib.dll
[2001-07-22 00:16:20 | 00,000,825 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-22 00:15:52 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2001-04-20 19:23:28 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\PManager.dll
[1999-01-20 06:01:00 | 00,210,032 | ---- | C] () -- C:\WINDOWS\System32\DBCLIENT.DLL
[1998-09-07 01:03:36 | 00,012,208 | ---- | C] () -- C:\WINDOWS\System32\Cdio16.dll
[1998-09-07 00:55:42 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\cdio32.dll
[color=orange]========== Files - Modified Within 30 Days ==========[/color]
[2 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009-06-20 13:15:32 | 00,135,168 | ---- | M] () -- C:\zip.exe
[2009-06-20 13:15:32 | 00,061,440 | ---- | M] () -- C:\WINDOWS\System32\drivers\gbzw.sys
[2009-06-20 13:15:32 | 00,019,286 | ---- | M] () -- C:\cleanup.exe
[2009-06-20 13:15:32 | 00,000,574 | ---- | M] () -- C:\cleanup.bat
[2009-06-20 13:08:22 | 00,000,847 | ---- | M] () -- C:\Documents and Settings\MT\Menu Start\Programy\Autostart\HDDlife.lnk
[2009-06-20 13:08:15 | 00,000,306 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2009-06-20 13:08:14 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\MT\Ustawienia lokalne\desktop.ini
[2009-06-20 13:04:18 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-06-20 13:04:15 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-06-20 11:32:53 | 00,026,956 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\avenger.jpg
[2009-06-20 11:28:04 | 00,724,952 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\avenger.zip
[2009-06-19 21:00:02 | 00,000,482 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack MTDane aplikacjiMyPhoneExplorer.job
[2009-06-19 20:19:01 | 00,000,494 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Documents and SettingsRobertGadu-Gadu.job
[2009-06-19 20:10:01 | 00,000,518 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Documents and SettingsMTDane aplikacjiThunderbird.job
[2009-06-19 20:08:00 | 00,000,440 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Nowe gg MT.job
[2009-06-19 20:00:01 | 00,000,438 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack GG marcin.job
[2009-06-19 19:57:42 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-06-19 19:19:01 | 00,781,909 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\RSITv.exe
[2009-06-19 16:45:08 | 00,000,825 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-06-19 16:45:08 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-06-19 16:45:08 | 00,000,215 | -HS- | M] () -- C:\boot.ini
[2009-06-18 19:48:45 | 00,000,000 | -HS- | M] () -- E:\Moje dokumenty\desktop.ini
[2009-06-18 18:46:36 | 00,395,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF30042.exe
[2009-06-18 18:44:19 | 00,395,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF29595.exe
[2009-06-18 17:18:17 | 00,000,686 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2009-06-17 20:42:55 | 00,578,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2009-06-16 11:18:05 | 00,000,671 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\File Washer.lnk
[2009-06-15 18:53:18 | 00,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-06-12 18:40:47 | 00,001,652 | ---- | M] () -- C:\WINDOWS\unins004.dat
[2009-06-12 18:40:37 | 00,674,138 | ---- | M] () -- C:\WINDOWS\unins004.exe
[2009-06-10 18:03:58 | 00,000,666 | ---- | M] () -- C:\Documents and Settings\MT\Menu Start\Programy\Autostart\Thoosje Vista Sidebar.lnk
[2009-06-10 17:07:00 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\DScaler.lnk
[2009-06-10 09:00:00 | 00,000,454 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack My phone explorer.job
[2009-06-10 09:00:00 | 00,000,452 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Adv disk catalog.job
[2009-06-10 08:20:36 | 00,102,416 | ---- | M] () -- C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT
[2009-06-09 21:53:04 | 00,351,384 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009-06-09 18:55:08 | 00,005,526 | ---- | M] () -- C:\WINDOWS\AVerTV.ini
[2009-06-07 16:54:22 | 00,000,811 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\MyPhoneExplorer.lnk
[2009-06-07 16:40:29 | 00,013,030 | -H-- | M] () -- C:\PDOXUSRS.NET
[2009-06-06 20:44:57 | 00,000,215 | ---- | M] () -- C:\WINDOWS\Informat.ini
[2009-06-04 17:43:44 | 00,035,268 | ---- | M] () -- C:\WINDOWS\unins000.dat
[2009-06-04 15:50:41 | 01,018,104 | ---- | M] () -- C:\WINDOWS\System\windefx.exe
[2009-05-27 16:31:21 | 00,868,445 | ---- | M] () -- C:\WINDOWS\System\pagefile2.exe
[color=orange]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:2BE9FEFC
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:8CE646EE
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:6DFF1A8A
< End of report >
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O32 - AutoRun File - [2009-06-19 17:59:44 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-20 12:47:35 | 00,000,225 | RH-- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-20 12:47:36 | 00,000,225 | RH-- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-20 13:07:44 | 00,000,225 | ---- | M] () - F:\autorun.inf -- [ NTFS ]
:Files
C:\cleanup.exe
C:\cleanup.bat
C:\WINDOWS\System\windefx.exe
C:\WINDOWS\System\pagefile2.exe
:Commands
[emptytemp]
[start explorer]
[Reboot]
========== OTL ==========
Process explorer.exe killed successfully!
File not found.
D:\autorun.inf moved successfully.
E:\autorun.inf moved successfully.
F:\autorun.inf moved successfully.
========== FILES ==========
File\Folder C:\cleanup.exe not found.
File\Folder C:\cleanup.bat not found.
C:\WINDOWS\System\windefx.exe moved successfully.
C:\WINDOWS\System\pagefile2.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\MT\Ustawienia lokalne\Temp\1.wmz scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\MT\Ustawienia lokalne\Temp\lsasswin scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\MT\Ustawienia lokalne\Temp\Perflib_Perfdata_8a0.dat scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_798.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Temp folders emptied.
Explorer started successfully
OTL by OldTimer - Version 2.1.1.0 log created on 06212009_135004
Files moved on Reboot...
C:\Documents and Settings\MT\Ustawienia lokalne\Temp\1.wmz moved successfully.
File C:\Documents and Settings\MT\Ustawienia lokalne\Temp\lsasswin not found!
File C:\Documents and Settings\MT\Ustawienia lokalne\Temp\Perflib_Perfdata_8a0.dat not found!
C:\WINDOWS\temp\Perflib_Perfdata_798.dat moved successfully.
Registry entries deleted on Reboot...
OTL logfile created on: 2009-06-21 14:02:03 - Run 6
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\MT\Pulpit
Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
1022,42 Mb Total Physical Memory | 560,32 Mb Available Physical Memory | 54,80% Memory free
2,41 Gb Paging File | 2,00 Gb Available in Paging File | 83,12% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38,31 Gb Total Space | 7,25 Gb Free Space | 18,93% Space Free | Partition Type: NTFS
Drive D: | 129,31 Gb Total Space | 47,22 Gb Free Space | 36,52% Space Free | Partition Type: NTFS
Drive E: | 51,12 Gb Total Space | 16,07 Gb Free Space | 31,43% Space Free | Partition Type: NTFS
Drive F: | 9,09 Gb Total Space | 3,61 Gb Free Space | 39,66% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KOWALSKI-MQAXU1
Current User Name: MT
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
[color=orange]========== Processes (SafeList) ==========[/color]
PRC - [2007-06-13 21:15:38 | 00,483,328 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2007-06-13 21:15:38 | 00,483,328 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2008-10-07 14:34:22 | 00,046,080 | ---- | M] (C-Dilla Ltd) -- C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
PRC - [2008-02-15 14:17:00 | 00,832,760 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\Common Files\BinarySense\hldasvc.exe
PRC - [2008-02-15 14:17:00 | 00,832,760 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\Common Files\BinarySense\hldasvc.exe
PRC - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2007-02-21 03:35:02 | 00,073,728 | ---- | M] (HP) -- C:\WINDOWS\System32\HPZipm12.exe
PRC - [2004-08-04 00:44:20 | 01,423,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2004-08-04 00:44:26 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
PRC - [2008-04-13 14:39:20 | 00,049,152 | ---- | M] (artArmin) -- D:\Program Files\Vista Drive Icon\DrvIcon.exe
PRC - [2006-09-29 09:57:30 | 00,049,152 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
PRC - [2007-11-20 14:51:46 | 00,524,288 | ---- | M] () -- C:\Program Files\Vista Sidebar\sidebar.exe
PRC - [2006-05-28 09:07:11 | 00,036,864 | ---- | M] (VisualTaskTips.com) -- D:\Program Files\VisualTaskTips\VisualTaskTips.exe
PRC - [2006-09-29 09:57:36 | 00,049,152 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
PRC - [2007-06-06 16:50:42 | 00,657,168 | ---- | M] (IVT Corporation.) -- C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
PRC - [2009-02-06 01:40:06 | 03,702,807 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
PRC - [2007-04-30 20:43:54 | 03,450,608 | ---- | M] (Stardock) -- D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
PRC - [2006-10-30 15:16:54 | 02,721,536 | ---- | M] (2BrightSparks) -- D:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
PRC - [2005-08-09 15:26:47 | 00,100,352 | ---- | M] (Vetch Utilities) -- D:\Program Files\SysInfoMyWork\SysInfoMyWork.exe
PRC - [2009-06-18 16:58:47 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MT\Pulpit\OTL.exe
PRC - [2005-04-14 20:08:00 | 00,098,192 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla.org\Mozilla\mozilla.exe
[color=orange]========== Win32 Services (SafeList) ==========[/color]
SRV - [2008-08-05 16:51:56 | 01,570,136 | ---- | M] (Agnitum Ltd.) -- C:\Program Files\Agnitum\Outpost Security Suite Pro\acs.exe -- (acssrv [Auto | Running])
SRV - [2005-09-23 07:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2007-06-13 21:15:38 | 00,483,328 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
SRV - [2007-06-13 14:29:00 | 00,520,192 | ---- | M] () -- C:\WINDOWS\system32\ati2sgag.exe -- (ATI Smart [Auto | Stopped])
SRV - [2009-03-03 18:20:34 | 00,085,096 | ---- | M] (Autodesk) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service [Disabled | Stopped])
SRV - [2008-10-07 14:34:22 | 00,046,080 | ---- | M] (C-Dilla Ltd) -- C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE -- (C-DillaSrv [Auto | Running])
SRV - [2005-09-23 07:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - File not found -- -- (gusvc [Disabled | Stopped])
SRV - [2008-02-15 14:17:00 | 00,832,760 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\Common Files\BinarySense\hldasvc.exe -- (HDDlife HDD Access service [Auto | Running])
SRV - [2004-08-04 00:44:08 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
SRV - [2007-08-08 09:25:08 | 00,836,904 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe -- (Nero BackItUp Scheduler 3 [Disabled | Stopped])
SRV - [2007-08-21 14:52:54 | 00,382,248 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Stopped])
SRV - [2003-07-28 21:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2007-02-21 03:35:02 | 00,073,728 | ---- | M] (HP) -- C:\WINDOWS\System32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2008-05-30 12:32:16 | 00,572,416 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer [On_Demand | Stopped])
SRV - [2006-12-01 12:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
[color=orange]========== Driver Services (SafeList) ==========[/color]
DRV - [2002-10-09 13:53:54 | 00,043,904 | ---- | M] (Alfa Corporation) -- C:\WINDOWS\System32\Drivers\AFPAnsi.sys -- (AFPAnsi [Boot | Running])
DRV - [2008-06-30 18:16:00 | 00,030,864 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\DRIVERS\afw.sys -- (afw [On_Demand | Running])
DRV - [2008-06-30 18:16:14 | 00,234,640 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\drivers\afwcore.sys -- (afwcore [On_Demand | Running])
DRV - [2006-02-17 11:15:34 | 03,846,848 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
DRV - [2008-06-09 18:16:53 | 00,005,888 | ---- | M] (Alexey V.Voronin @ Hexy) -- C:\WINDOWS\System32\Drivers\AMD64CAx86.sys -- (AMD64CA [On_Demand | Stopped])
DRV - [2006-07-02 00:32:26 | 00,043,520 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\DRIVERS\AmdK8.sys -- (AmdK8 [System | Running])
DRV - [2008-07-11 16:42:08 | 00,033,408 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\Filt\ASWFilt.dll -- (ASWFilt [On_Demand | Running])
DRV - [2007-06-13 21:24:12 | 02,155,520 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
DRV - [2007-05-11 04:10:50 | 00,034,704 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\DRIVERS\blueletaudio.sys -- (BlueletAudio [On_Demand | Running])
DRV - [2007-03-05 07:00:04 | 00,027,792 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\DRIVERS\BlueletSCOAudio.sys -- (BlueletSCOAudio [On_Demand | Running])
DRV - [2007-05-23 05:21:12 | 00,016,272 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\DRIVERS\btnetdrv.sys -- (BT [On_Demand | Running])
DRV - [2007-05-23 05:20:58 | 00,036,496 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\Drivers\btcusb.sys -- (Btcsrusb [On_Demand | Running])
DRV - [2007-03-05 06:55:12 | 00,020,880 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\Drivers\vbtenum.sys -- (BTHidEnum [Boot | Running])
DRV - [2007-03-05 06:56:18 | 00,035,600 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr [Boot | Running])
DRV - [2006-11-21 23:41:18 | 00,022,416 | ---- | M] (IVT Corporation.) -- C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys -- (BTNetFilter [On_Demand | Stopped])
DRV - [2008-10-07 13:53:25 | 00,058,288 | ---- | M] (Macrovision) -- C:\WINDOWS\system32\drivers\CDANT.SYS -- (C-Dilla [On_Demand | Stopped])
DRV - [2009-03-24 13:06:07 | 00,346,304 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) -- C:\WINDOWS\System32\DRIVERS\Cap7134.sys -- (Cap7134 [On_Demand | Running])
DRV - [2006-11-25 17:14:58 | 00,066,688 | ---- | M] (EXLADE, Inc.) -- C:\WINDOWS\system32\Drivers\CrypticDisk.sys -- (CrypticDisk [Auto | Running])
DRV - [2005-12-18 20:42:12 | 00,008,801 | ---- | M] () -- D:\Program Files\DScaler\DSDrv4.sys -- (DSDrv4 [On_Demand | Stopped])
DRV - [2006-12-26 14:54:35 | 00,034,760 | ---- | M] (SlySoft, Inc.) -- C:\WINDOWS\System32\Drivers\ElbyCDFL.sys -- (ElbyCDFL [On_Demand | Running])
DRV - [2006-12-26 14:54:34 | 00,015,440 | ---- | M] (Elaborate Bytes AG) -- C:\WINDOWS\System32\Drivers\ElbyCDIO.sys -- (ElbyCDIO [Auto | Running])
DRV - [2003-07-17 12:56:32 | 00,089,216 | ---- | M] () -- C:\WINDOWS\System32\Drivers\FO_PAnt.sys -- (FO_PAnt [Boot | Running])
DRV - [2007-02-03 05:56:58 | 00,030,808 | ---- | M] (Paragon Software Group) -- C:\WINDOWS\system32\drivers\hotcore2.sys -- (hotcore2 [Boot | Running])
DRV - [2005-10-28 03:24:28 | 00,049,664 | ---- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys -- (HPZid412 [On_Demand | Stopped])
DRV - [2005-10-28 03:24:29 | 00,016,496 | ---- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys -- (HPZipr12 [On_Demand | Stopped])
DRV - [2005-10-28 03:24:30 | 00,021,568 | ---- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys -- (HPZius12 [On_Demand | Stopped])
DRV - [2008-05-24 21:09:08 | 00,073,728 | ---- | M] (EZB Systems, Inc.) -- D:\Program Files\UltraISO\drivers\ISODrive.sys -- (ISODrive [System | Running])
DRV - [2006-08-18 12:10:24 | 00,061,504 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320bus.sys -- (K320bus [On_Demand | Running])
DRV - [2006-08-18 12:10:22 | 00,009,328 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320mdfl.sys -- (K320mdfl [On_Demand | Running])
DRV - [2006-08-18 12:10:22 | 00,097,056 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320mdm.sys -- (K320mdm [On_Demand | Running])
DRV - [2006-08-18 12:10:20 | 00,088,560 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320mgmt.sys -- (K320mgmt [On_Demand | Running])
DRV - [2006-08-18 12:10:18 | 00,086,368 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320obex.sys -- (K320obex [On_Demand | Running])
DRV - [2007-04-18 00:52:38 | 00,017,264 | ---- | M] (FSPro Labs) -- C:\WINDOWS\SYSTEM32\DRIVERS\MPRIFL.SYS -- (MPRIFL [Boot | Running])
DRV - [2008-03-11 18:53:32 | 00,002,208 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\nxsIO32.sys -- (nxsIO32 [Auto | Running])
DRV - [2008-02-26 17:58:33 | 00,047,360 | ---- | M] (VSO Software) -- C:\WINDOWS\System32\Drivers\pcouffin.sys -- (pcouffin [On_Demand | Running])
DRV - [2009-03-24 13:06:07 | 00,054,304 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) -- C:\WINDOWS\System32\DRIVERS\PhTVTune.sys -- (PhTVTune [On_Demand | Running])
DRV - [2001-11-08 17:02:50 | 00,003,912 | ---- | M] () -- C:\WINDOWS\System32\Drivers\port_nt.sys -- (port_nt [Auto | Running])
DRV - [2001-08-17 23:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2006-09-27 23:53:22 | 00,036,560 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2001-08-17 23:57:36 | 00,005,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Drivers\RootMdm.sys -- (ROOTMODEM [On_Demand | Running])
DRV - [2006-02-26 23:46:20 | 00,081,408 | R--- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys -- (RTL8023xp [On_Demand | Stopped])
DRV - [2004-08-03 22:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS -- (rtl8139 [On_Demand | Stopped])
DRV - [2007-12-10 15:22:14 | 00,083,880 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017bus.sys -- (s3017bus [On_Demand | Stopped])
DRV - [2007-12-10 15:22:18 | 00,015,016 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017mdfl.sys -- (s3017mdfl [On_Demand | Stopped])
DRV - [2007-12-10 15:22:18 | 00,110,632 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017mdm.sys -- (s3017mdm [On_Demand | Stopped])
DRV - [2007-12-10 15:22:20 | 00,104,616 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017mgmt.sys -- (s3017mgmt [On_Demand | Stopped])
DRV - [2007-12-10 15:22:20 | 00,025,512 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017nd5.sys -- (s3017nd5 [On_Demand | Stopped])
DRV - [2007-12-10 15:22:22 | 00,100,648 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017obex.sys -- (s3017obex [On_Demand | Stopped])
DRV - [2007-12-10 15:22:22 | 00,110,120 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017unic.sys -- (s3017unic [On_Demand | Stopped])
DRV - [2006-02-08 01:40:24 | 00,806,400 | R--- | M] (S3 Graphics Co., Ltd.) -- C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys -- (S3GIGP [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,083,496 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916bus.sys -- (s916bus [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,015,016 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916mdfl.sys -- (s916mdfl [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,109,992 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916mdm.sys -- (s916mdm [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,103,976 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916mgmt.sys -- (s916mgmt [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,100,008 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916obex.sys -- (s916obex [On_Demand | Stopped])
DRV - [2008-07-11 16:41:28 | 00,673,920 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\DRIVERS\SandBox.sys -- (SandBox [System | Running])
DRV - [2002-03-25 20:02:14 | 00,027,440 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2005-08-10 14:44:04 | 00,050,688 | ---- | M] (Protection Technology) -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01 [Boot | Running])
DRV - [2006-07-05 14:46:06 | 00,063,352 | ---- | M] (Protection Technology (StarForce)) -- C:\WINDOWS\System32\drivers\sfdrv01a.sys -- (sfdrv01a [Boot | Running])
DRV - [2006-06-14 16:56:56 | 00,013,680 | ---- | M] (Protection Technology (StarForce)) -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02 [Boot | Running])
DRV - [2005-11-03 16:40:07 | 00,063,488 | ---- | M] (Protection Technology) -- C:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02 [Boot | Running])
DRV - [2009-01-23 18:29:43 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2006-11-10 15:08:50 | 00,024,064 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\SysTool.sys -- (SysTool [System | Stopped])
DRV - [2008-06-04 18:36:14 | 01,072,722 | ---- | M] (VirusBuster Kft.) -- C:\WINDOWS\system32\DRIVERS\VBEngNT.sys -- (VBEngNT [On_Demand | Running])
DRV - [2008-07-11 16:42:04 | 00,158,816 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\Filt\VBFilt.dll -- (VBFilt [On_Demand | Running])
DRV - [2008-09-12 17:00:46 | 00,095,888 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys -- (VBoxDrv [System | Running])
DRV - [2008-09-12 17:00:50 | 00,041,680 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys -- (VBoxUSBMon [System | Running])
DRV - [2007-03-05 06:52:18 | 00,034,448 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\DRIVERS\VComm.sys -- (VComm [On_Demand | Running])
DRV - [2007-03-05 06:53:18 | 00,044,304 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\Drivers\VcommMgr.sys -- (VcommMgr [On_Demand | Running])
DRV - [2003-07-01 22:42:00 | 00,027,904 | R--- | M] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\viaagp1.sys -- (viaagp1 [Boot | Running])
[color=orange]========== Standard Registry (SafeList) ==========[/color]
[color=orange]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/
IE - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=orange]========== FireFox ==========[/color]
FF - prefs.js..browser.startup.homepage: "http://www.google.pl"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:0.7.5.5
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.0.3
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.6
FF - prefs.js..extensions.enabledItems: {53A03D43-5363-4669-8190-99061B2DEBA5}:1.3.3.7
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0
FF - HKLM\software\mozilla\Mozilla 1.7.7\Extensions\\Components: D:\PROGRAM FILES\MOZILLA.ORG\MOZILLA\COMPONENTS [2008-07-04 16:34:14 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla 1.7.7\Extensions\\Plugins: D:\PROGRAM FILES\MOZILLA.ORG\MOZILLA\PLUGINS [2009-06-09 21:37:40 | 00,000,000 | ---D | M]
[2009-02-18 15:05:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Extensions
[2009-02-18 15:05:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-02-18 15:15:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions
[2009-02-18 15:15:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2009-02-18 15:14:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2009-02-18 15:09:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-02-18 15:11:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Idea2 SidebarBrowserMonitor Class) - {45AD732C-2CE2-4666-B366-B2214AD57A49} - D:\Program Files\Desktop Sidebar\sbhelp.dll (Idea2)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Expressivo) - {85F685C3-20D9-4943-95E4-EB4224056C3F} - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll (IVO Software Sp. z o.o.)
O3 - HKLM\..\Toolbar: (Expressivo) - {85F685C3-20D9-4943-95E4-EB4224056C3F} - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll (IVO Software Sp. z o.o.)
O3 - HKLM\..\Toolbar: (StylerToolBar) - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll (StyleFantasist)
O3 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [DrvIcon] D:\Program Files\Vista Drive Icon\DrvIcon.exe (artArmin)
O4 - HKLM..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice (Agnitum Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [VisualTooltip] File not found
O4 - HKLM..\Run: [WellPhone DirectSync - ScheduleSync] D:\PROGRA~1\WELLPH~1\SCHEDU~1.EXE (SmartCom)
O4 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003..\Run: [Vista Sidebar] C:\Program Files\Vista Sidebar\sidebar.exe ()
O4 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003..\Run: [VisualTaskTips] D:\Program Files\VisualTaskTips\VisualTaskTips.exe (VisualTaskTips.com)
O4 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003..\Run: [Windows Intranet controller] C:\WINDOWS\security\lsass.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe (IVT Corporation.)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\ERUNT AutoBackup.lnk = C:\WINDOWS\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\HDDlife.lnk = C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe (BinarySense, Inc.)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\SyncBack.lnk = D:\Program Files\2BrightSparks\SyncBack\SyncBack.exe (2BrightSparks)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\SysInfoMyWork.lnk = D:\Program Files\SysInfoMyWork\SysInfoMyWork.exe (Vetch Utilities)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\Thoosje Vista Sidebar.lnk = C:\Program Files\Vista Sidebar\sidebar.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuEjectPC = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecycleFiles = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuEjectPC = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EditLevel = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra 'Tools' menuitem : Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra Button: Ustawienia Outpost Security Suite Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Security Suite Pro\ie_bar.dll (Agnitum Ltd.)
O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java (Reg Error: Key error.)
O18 - Protocol\Handler\hddlife {BD758015-47D9-477A-8873-4B688A2BC0E2} - C:\Program Files\Common Files\BinarySense\hlAPP.dll (BinarySense, Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (vistaui.exe) - C:\WINDOWS\system32\vistaui.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-02-26 15:34:55 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009-06-19 17:59:44 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-21 13:52:29 | 00,000,225 | RH-- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-21 13:52:30 | 00,000,225 | RH-- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-21 13:52:30 | 00,000,225 | RH-- | M] () - F:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009-06-21 14:01:57 | 00,000,000 | ---D | M]
[color=orange]========== Files/Folders - Created Within 30 Days ==========[/color]
[2009-06-21 13:50:04 | 00,000,000 | ---D | C] -- C:\_OTL
[2009-06-21 13:49:39 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\MT\Pulpit\OTL.exe
[2009-06-20 13:15:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MT\Pulpit\avenger
[2009-06-20 11:32:53 | 00,026,956 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\avenger.jpg
[2009-06-20 11:20:02 | 00,000,000 | ---D | C] -- C:\Avenger
[2009-06-20 11:11:08 | 00,724,952 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\avenger.zip
[2009-06-19 19:19:34 | 00,000,000 | ---D | C] -- C:\rsit
[2009-06-19 19:19:34 | 00,000,000 | ---D | C] -- C:\Program Files\trend micro
[2009-06-19 19:14:28 | 00,781,909 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\RSITv.exe
[2009-06-19 17:59:44 | 00,000,000 | RHSD | C] -- C:\autorun.inf
[2009-06-18 22:08:13 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\AutoCAD Zestawy arkuszy
[2009-06-18 22:08:09 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\CyberLink
[2009-06-18 22:08:09 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Bluetooth
[2009-06-18 22:07:28 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Dokumenty
[2009-06-18 22:07:22 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\GTA San Andreas User Files
[2009-06-18 22:07:22 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\G DATA
[2009-06-18 22:07:22 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Dokumenty nie posegregowane
[2009-06-18 22:07:21 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\GTA Vice City User Files
[2009-06-18 21:30:50 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\Moja muzyka
[2009-06-18 21:27:00 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\Moje obrazy
[2009-06-18 21:26:35 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\Moje wideo
[2009-06-18 21:26:29 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\Moje zakupy allegro
[2009-06-18 21:26:29 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\My Backups
[2009-06-18 21:26:21 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\NFS Most Wanted
[2009-06-18 21:26:21 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\NeroVision
[2009-06-18 21:26:17 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Recover
[2009-06-18 21:24:24 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\sony ericsson
[2009-06-18 21:24:23 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\torrenty
[2009-06-18 21:24:23 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\TikGames
[2009-06-18 21:24:23 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Stardock
[2009-06-18 21:24:20 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\ZPS10
[2009-06-18 21:24:20 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\VirtualDJ
[2009-06-18 19:48:45 | 00,001,280 | -H-- | C] () -- E:\Moje dokumenty\Memento.notes
[2009-06-18 19:48:45 | 00,000,000 | -HS- | C] () -- E:\Moje dokumenty\desktop.ini
[2009-06-18 18:46:47 | 00,395,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF30042.exe
[2009-06-18 18:44:44 | 00,395,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF29595.exe
[2009-06-17 20:42:54 | 00,578,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2009-06-16 11:18:05 | 00,000,671 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\File Washer.lnk
[2009-06-15 19:10:12 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Advanced Disk Catalog.lnk
[2009-06-15 19:09:59 | 00,000,593 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\AoA Audio Extractor.lnk
[2009-06-15 19:09:39 | 00,000,663 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\CCleaner.lnk
[2009-06-15 19:09:29 | 00,000,585 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\CDRoller.lnk
[2009-06-15 19:09:19 | 00,000,779 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\CyberLink PowerDVD.lnk
[2009-06-15 19:08:50 | 00,001,806 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\FotoOffice 3.lnk
[2009-06-15 19:08:41 | 00,000,560 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Glary Utilities.lnk
[2009-06-15 19:08:34 | 00,000,770 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\GOM Player.lnk
[2009-06-15 19:08:11 | 00,000,551 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\MediaMonkey.lnk
[2009-06-15 19:08:04 | 00,002,551 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Microsoft Office Word 2003.lnk
[2009-06-15 19:07:57 | 00,002,106 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Microsoft Office Excel 2003.lnk
[2009-06-15 19:07:50 | 00,000,779 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Nawigator.lnk
[2009-06-15 19:07:37 | 00,000,811 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\MyPhoneExplorer.lnk
[2009-06-15 19:07:30 | 00,002,075 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Nero Express.lnk
[2009-06-15 19:07:20 | 00,000,609 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\PhotoFiltre.lnk
[2009-06-15 19:07:10 | 00,000,601 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\PhotoScape.lnk
[2009-06-15 19:07:04 | 00,000,573 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Picasa2.lnk
[2009-06-15 19:06:32 | 00,000,683 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\VirtualBox.lnk
[2009-06-15 19:06:27 | 00,000,770 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\SUPER ©.lnk
[2009-06-15 19:06:18 | 00,000,539 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Virtual DJ.lnk
[2009-06-15 19:06:11 | 00,000,643 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\VirtualDubMod 1.5.10.2 PL.lnk
[2009-06-15 19:05:54 | 00,000,565 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Winamp.lnk
[2009-06-15 19:05:44 | 00,000,741 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Xilisoft 3GP Video Converter 3.lnk
[2009-06-15 19:05:33 | 00,000,874 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Resident Evil 3.lnk
[2009-06-15 19:05:22 | 00,000,704 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Adobe Photoshop 7.0 CE.lnk
[2009-06-15 19:05:16 | 00,000,609 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\ClonyXXL_PL.lnk
[2009-06-15 19:05:10 | 00,000,600 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Profiler_PL.lnk
[2009-06-15 19:05:00 | 00,000,657 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\CloneCD.lnk
[2009-06-15 19:04:50 | 00,000,658 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\ALLPlayer V3.4.lnk
[2009-06-15 19:04:45 | 00,002,193 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\AutoCAD 2008.lnk
[2009-06-15 19:04:38 | 00,000,575 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Movie DVD Maker.lnk
[2009-06-15 19:04:33 | 00,002,080 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\ACDSee 10 Photo Manager.lnk
[2009-06-15 19:04:20 | 00,001,532 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\AVerTV GO 007 Plus.lnk
[2009-06-15 19:03:49 | 00,000,523 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\DScaler.lnk
[2009-06-14 11:15:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MT\Pulpit\Nowy folder
[2009-06-12 19:49:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MT\Dane aplikacji\Stardock
[2009-06-12 19:36:06 | 00,000,748 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Cryptic Disk.lnk
[2009-06-12 18:40:46 | 05,552,104 | ---- | C] (Xequte Software) -- C:\WINDOWS\xdclock.scr
[2009-06-12 18:40:46 | 00,674,138 | ---- | C] () -- C:\WINDOWS\unins004.exe
[2009-06-12 18:40:46 | 00,001,652 | ---- | C] () -- C:\WINDOWS\unins004.dat
[2009-06-12 18:39:20 | 00,118,845 | ---- | C] (Matt Ginzton) -- C:\WINDOWS\Flurry.scr
[2009-06-10 17:04:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MT\Dane aplikacji\AVI ReComp
[2009-06-05 15:43:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\BVRP Software
[2009-06-01 18:39:09 | 00,000,000 | ---D | C] -- C:\Program Files\TRACERMM SOFT
[2009-04-28 19:54:06 | 00,000,032 | ---- | C] () -- C:\WINDOWS\CD-Start.INI
[2009-04-21 18:05:07 | 00,000,126 | ---- | C] () -- C:\WINDOWS\SCRABMAN.INI
[2009-03-09 01:05:59 | 00,000,076 | ---- | C] () -- C:\WINDOWS\System32\w3url.dll
[2009-03-06 00:14:13 | 00,000,126 | RH-- | C] () -- C:\WINDOWS\System32\NTIDBD32.dll
[2009-03-03 22:40:43 | 00,129,024 | ---- | C] () -- C:\WINDOWS\System32\AVERM.dll
[2009-03-03 22:40:43 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll
[2009-02-13 21:59:18 | 00,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2009-02-06 13:29:25 | 00,000,046 | ---- | C] () -- C:\WINDOWS\Resecik.ini
[2009-01-25 22:13:10 | 00,000,096 | ---- | C] () -- C:\WINDOWS\docs.ini
[2009-01-13 13:12:06 | 00,000,029 | ---- | C] () -- C:\WINDOWS\System32\vfolx32n.dll
[2009-01-13 12:33:35 | 00,000,065 | ---- | C] () -- C:\WINDOWS\WaterIllusion.ini
[2009-01-13 01:42:20 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\wbload.dll
[2009-01-12 12:45:08 | 00,001,046 | ---- | C] () -- C:\WINDOWS\ARCHPR.INI
[2009-01-12 01:24:35 | 00,000,169 | ---- | C] () -- C:\WINDOWS\Clony2.ini
[2009-01-11 23:56:50 | 00,000,215 | ---- | C] () -- C:\WINDOWS\Informat.ini
[2009-01-05 18:13:19 | 00,000,063 | ---- | C] () -- C:\WINDOWS\DeskTopBird_K.ini
[2008-12-18 00:30:06 | 00,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008-12-18 00:30:06 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008-12-08 19:54:53 | 00,090,112 | ---- | C] ( ) -- C:\WINDOWS\System32\STAPI.dll
[2008-12-08 19:52:33 | 00,000,035 | ---- | C] () -- C:\WINDOWS\System32\RTELM.dll
[2008-11-19 23:05:48 | 00,000,026 | ---- | C] () -- C:\WINDOWS\mgboss_reg.ini
[2008-11-19 16:15:49 | 00,000,058 | ---- | C] () -- C:\WINDOWS\GScript.INI
[2008-11-19 16:01:02 | 00,000,131 | ---- | C] () -- C:\WINDOWS\CRC.INI
[2008-11-18 23:02:07 | 00,095,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\VBoxDrv.sys
[2008-11-18 22:05:10 | 00,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008-11-06 15:22:21 | 02,416,128 | R--- | C] () -- C:\WINDOWS\System32\s3gcil_inv.dll
[2008-10-11 00:50:37 | 00,000,193 | ---- | C] () -- C:\WINDOWS\Net2fone.ini
[2008-10-07 18:06:20 | 00,000,990 | ---- | C] () -- C:\WINDOWS\psmplay.ini
[2008-09-23 20:17:11 | 00,000,000 | ---- | C] () -- C:\WINDOWS\TeleText.INI
[2008-09-23 20:17:10 | 00,000,064 | ---- | C] () -- C:\WINDOWS\AVerText.ini
[2008-09-09 23:42:24 | 00,000,038 | ---- | C] () -- C:\WINDOWS\WindowSystemCheck.ini
[2008-09-04 19:36:54 | 00,000,359 | ---- | C] () -- C:\WINDOWS\MP3trt.ini
[2008-09-03 13:22:30 | 00,000,135 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008-09-01 18:41:02 | 00,000,388 | ---- | C] () -- C:\WINDOWS\Swish.INI
[2008-09-01 17:13:59 | 00,000,115 | ---- | C] () -- C:\WINDOWS\AIMPR.INI
[2008-08-31 12:02:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\IQ test.INI
[2008-08-23 17:43:48 | 00,000,031 | ---- | C] () -- C:\WINDOWS\System32\Days5.ini
[2008-08-23 17:17:18 | 00,001,144 | ---- | C] () -- C:\WINDOWS\Cerberus.ini
[2008-08-23 17:07:04 | 00,089,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\FO_PAnt.sys
[2008-08-20 18:34:38 | 00,000,024 | ---- | C] () -- C:\WINDOWS\dlb.ini
[2008-08-20 18:31:05 | 00,000,035 | ---- | C] () -- C:\WINDOWS\S&D22.INI
[2008-07-21 14:11:25 | 00,408,576 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
[2008-07-21 14:11:25 | 00,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2008-07-21 14:02:49 | 00,027,648 | -HS- | C] () -- C:\WINDOWS\System32\Smab0.dll
[2008-07-18 17:28:25 | 00,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2008-07-02 18:30:03 | 00,003,240 | ---- | C] () -- C:\WINDOWS\jmshw-n16.ini
[2008-06-09 17:19:13 | 04,239,360 | ---- | C] () -- C:\WINDOWS\System32\qtp-mt334.dll
[2008-06-09 17:19:13 | 00,008,192 | ---- | C] () -- C:\WINDOWS\System32\wnaspi32.dll
[2008-05-23 13:00:16 | 00,000,306 | ---- | C] () -- C:\WINDOWS\kingpong1.INI
[2008-05-22 11:14:00 | 00,000,216 | ---- | C] () -- C:\WINDOWS\gfscore.ini
[2008-05-22 11:05:44 | 00,000,281 | ---- | C] () -- C:\WINDOWS\hero.ini
[2008-05-06 20:26:23 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2008-05-06 10:51:26 | 00,000,176 | ---- | C] () -- C:\WINDOWS\CDPlayer.ini
[2008-05-01 17:56:46 | 00,000,035 | ---- | C] () -- C:\WINDOWS\galaxy.ini
[2008-05-01 17:43:37 | 00,029,696 | ---- | C] () -- C:\WINDOWS\System32\pthread.dll
[2008-03-22 21:00:36 | 00,000,018 | ---- | C] () -- C:\WINDOWS\gfact.ini
[2008-03-11 18:53:32 | 00,002,208 | ---- | C] () -- C:\WINDOWS\System32\drivers\nxsIO32.sys
[2008-03-06 00:45:40 | 00,003,912 | ---- | C] () -- C:\WINDOWS\System32\drivers\port_nt.sys
[2008-02-27 17:52:47 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-02-27 16:52:37 | 00,000,641 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-02-26 20:52:01 | 00,000,100 | ---- | C] () -- C:\WINDOWS\festo.ini
[2008-02-26 18:44:23 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2008-02-26 17:48:56 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008-02-26 17:18:32 | 00,000,000 | ---- | C] () -- C:\WINDOWS\mngui.INI
[2008-02-26 16:59:13 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008-02-26 16:43:08 | 00,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008-02-26 16:43:00 | 00,000,164 | R--- | C] () -- C:\WINDOWS\avrack.ini
[2008-02-26 16:24:29 | 00,000,223 | ---- | C] () -- C:\WINDOWS\System32\BOOTBAK.INI
[2006-11-10 15:08:50 | 00,024,064 | ---- | C] () -- C:\WINDOWS\System32\drivers\SysTool.sys
[2005-10-30 14:28:39 | 00,107,008 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005-10-30 14:28:33 | 00,020,992 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2004-10-31 18:39:02 | 00,005,526 | ---- | C] () -- C:\WINDOWS\AVerTV.ini
[2003-03-15 09:27:30 | 00,000,117 | ---- | C] () -- C:\WINDOWS\Prof.ini
[2002-10-16 00:54:04 | 00,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2002-09-20 18:04:04 | 00,021,811 | ---- | C] () -- C:\WINDOWS\System32\aaqveq.dll
[2002-03-25 20:02:14 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2001-10-28 17:42:30 | 00,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2001-08-13 20:09:48 | 00,659,520 | ---- | C] () -- C:\WINDOWS\System32\vbid3lib.dll
[2001-07-22 00:16:20 | 00,000,825 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-22 00:15:52 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2001-04-20 19:23:28 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\PManager.dll
[1999-01-20 06:01:00 | 00,210,032 | ---- | C] () -- C:\WINDOWS\System32\DBCLIENT.DLL
[1998-09-07 01:03:36 | 00,012,208 | ---- | C] () -- C:\WINDOWS\System32\Cdio16.dll
[1998-09-07 00:55:42 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\cdio32.dll
[color=orange]========== Files - Modified Within 30 Days ==========[/color]
[2 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009-06-21 13:52:27 | 00,000,847 | ---- | M] () -- C:\Documents and Settings\MT\Menu Start\Programy\Autostart\HDDlife.lnk
[2009-06-21 13:52:11 | 00,000,306 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2009-06-21 13:52:01 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\MT\Ustawienia lokalne\desktop.ini
[2009-06-21 13:51:48 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-06-21 13:51:43 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-06-21 13:44:21 | 00,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-06-20 11:32:53 | 00,026,956 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\avenger.jpg
[2009-06-20 11:28:04 | 00,724,952 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\avenger.zip
[2009-06-19 21:00:02 | 00,000,482 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack MTDane aplikacjiMyPhoneExplorer.job
[2009-06-19 20:19:01 | 00,000,494 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Documents and SettingsRobertGadu-Gadu.job
[2009-06-19 20:10:01 | 00,000,518 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Documents and SettingsMTDane aplikacjiThunderbird.job
[2009-06-19 20:08:00 | 00,000,440 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Nowe gg MT.job
[2009-06-19 20:00:01 | 00,000,438 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack GG marcin.job
[2009-06-19 19:57:42 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-06-19 19:19:01 | 00,781,909 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\RSITv.exe
[2009-06-19 16:45:08 | 00,000,825 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-06-19 16:45:08 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-06-19 16:45:08 | 00,000,215 | -HS- | M] () -- C:\boot.ini
[2009-06-18 19:48:45 | 00,000,000 | -HS- | M] () -- E:\Moje dokumenty\desktop.ini
[2009-06-18 18:46:36 | 00,395,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF30042.exe
[2009-06-18 18:44:19 | 00,395,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF29595.exe
[2009-06-18 17:18:17 | 00,000,686 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2009-06-18 16:58:47 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MT\Pulpit\OTL.exe
[2009-06-17 20:42:55 | 00,578,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2009-06-16 11:18:05 | 00,000,671 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\File Washer.lnk
[2009-06-12 18:40:47 | 00,001,652 | ---- | M] () -- C:\WINDOWS\unins004.dat
[2009-06-12 18:40:37 | 00,674,138 | ---- | M] () -- C:\WINDOWS\unins004.exe
[2009-06-10 18:03:58 | 00,000,666 | ---- | M] () -- C:\Documents and Settings\MT\Menu Start\Programy\Autostart\Thoosje Vista Sidebar.lnk
[2009-06-10 17:07:00 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\DScaler.lnk
[2009-06-10 09:00:00 | 00,000,454 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack My phone explorer.job
[2009-06-10 09:00:00 | 00,000,452 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Adv disk catalog.job
[2009-06-10 08:20:36 | 00,102,416 | ---- | M] () -- C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT
[2009-06-09 21:53:04 | 00,351,384 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009-06-09 18:55:08 | 00,005,526 | ---- | M] () -- C:\WINDOWS\AVerTV.ini
[2009-06-07 16:54:22 | 00,000,811 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\MyPhoneExplorer.lnk
[2009-06-07 16:40:29 | 00,013,030 | -H-- | M] () -- C:\PDOXUSRS.NET
[2009-06-06 20:44:57 | 00,000,215 | ---- | M] () -- C:\WINDOWS\Informat.ini
[2009-06-04 17:43:44 | 00,035,268 | ---- | M] () -- C:\WINDOWS\unins000.dat
[color=orange]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:2BE9FEFC
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:8CE646EE
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:6DFF1A8A
< End of report >
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O32 - AutoRun File - [2009-06-19 17:59:44 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-21 13:52:29 | 00,000,225 | RH-- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-21 13:52:30 | 00,000,225 | RH-- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-21 13:52:30 | 00,000,225 | RH-- | M] () - F:\autorun.inf -- [ NTFS ]
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""
:Commands
[emptytemp]
[start explorer]
[Reboot]
========== OTL ==========
Process explorer.exe killed successfully!
File not found.
D:\autorun.inf moved successfully.
E:\autorun.inf moved successfully.
F:\autorun.inf moved successfully.
========== REGISTRY ==========
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\\"SuperHidden"|dword:00000001 /E : value set successfully!
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\\"Hidden"|dword:00000001 /E : value set successfully!
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\\"ShowSuperHidden"|dword:00000001 /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\\"CheckedValue"|dword:00000001 /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden\ deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden\\@|"" /E : value set successfully!
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\MT\Ustawienia lokalne\Temp\1.wmz scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\MT\Ustawienia lokalne\Temp\lsasswin scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\MT\Ustawienia lokalne\Temp\Perflib_Perfdata_664.dat scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_774.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Temp folders emptied.
Explorer started successfully
OTL by OldTimer - Version 2.1.1.0 log created on 06222009_071536
Files moved on Reboot...
C:\Documents and Settings\MT\Ustawienia lokalne\Temp\1.wmz moved successfully.
File C:\Documents and Settings\MT\Ustawienia lokalne\Temp\lsasswin not found!
File C:\Documents and Settings\MT\Ustawienia lokalne\Temp\Perflib_Perfdata_664.dat not found!
C:\WINDOWS\temp\Perflib_Perfdata_774.dat moved successfully.
Registry entries deleted on Reboot...
OTL logfile created on: 2009-06-22 07:24:32 - Run 7
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\MT\Pulpit
Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
1022,42 Mb Total Physical Memory | 573,20 Mb Available Physical Memory | 56,06% Memory free
2,41 Gb Paging File | 2,00 Gb Available in Paging File | 82,95% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38,31 Gb Total Space | 6,98 Gb Free Space | 18,21% Space Free | Partition Type: NTFS
Drive D: | 129,31 Gb Total Space | 47,22 Gb Free Space | 36,51% Space Free | Partition Type: NTFS
Drive E: | 51,12 Gb Total Space | 16,06 Gb Free Space | 31,43% Space Free | Partition Type: NTFS
Drive F: | 9,09 Gb Total Space | 3,60 Gb Free Space | 39,64% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KOWALSKI-MQAXU1
Current User Name: MT
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
[color=orange]========== Processes (SafeList) ==========[/color]
PRC - [2007-06-13 21:15:38 | 00,483,328 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2007-06-13 21:15:38 | 00,483,328 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2008-10-07 14:34:22 | 00,046,080 | ---- | M] (C-Dilla Ltd) -- C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
PRC - [2008-02-15 14:17:00 | 00,832,760 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\Common Files\BinarySense\hldasvc.exe
PRC - [2008-02-15 14:17:00 | 00,832,760 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\Common Files\BinarySense\hldasvc.exe
PRC - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2007-02-21 03:35:02 | 00,073,728 | ---- | M] (HP) -- C:\WINDOWS\System32\HPZipm12.exe
PRC - [2004-08-04 00:44:20 | 01,423,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2004-08-04 00:44:26 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
PRC - [2008-04-13 14:39:20 | 00,049,152 | ---- | M] (artArmin) -- D:\Program Files\Vista Drive Icon\DrvIcon.exe
PRC - [2006-09-29 09:57:30 | 00,049,152 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
PRC - [2009-04-08 20:02:55 | 01,826,871 | RH-- | M] () -- C:\WINDOWS\security\lsass.exe
PRC - [2007-11-20 14:51:46 | 00,524,288 | ---- | M] () -- C:\Program Files\Vista Sidebar\sidebar.exe
PRC - [2006-05-28 09:07:11 | 00,036,864 | ---- | M] (VisualTaskTips.com) -- D:\Program Files\VisualTaskTips\VisualTaskTips.exe
PRC - [2006-09-29 09:57:36 | 00,049,152 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
PRC - [2007-06-06 16:50:42 | 00,657,168 | ---- | M] (IVT Corporation.) -- C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
PRC - [2009-02-06 01:40:06 | 03,702,807 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
PRC - [2007-04-30 20:43:54 | 03,450,608 | ---- | M] (Stardock) -- D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
PRC - [2006-10-30 15:16:54 | 02,721,536 | ---- | M] (2BrightSparks) -- D:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
PRC - [2005-08-09 15:26:47 | 00,100,352 | ---- | M] (Vetch Utilities) -- D:\Program Files\SysInfoMyWork\SysInfoMyWork.exe
PRC - [2005-04-14 20:08:00 | 00,098,192 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla.org\Mozilla\mozilla.exe
PRC - [2009-06-18 16:58:47 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MT\Pulpit\OTL.exe
[color=orange]========== Win32 Services (SafeList) ==========[/color]
SRV - [2008-08-05 16:51:56 | 01,570,136 | ---- | M] (Agnitum Ltd.) -- C:\Program Files\Agnitum\Outpost Security Suite Pro\acs.exe -- (acssrv [Auto | Running])
SRV - [2005-09-23 07:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2007-06-13 21:15:38 | 00,483,328 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
SRV - [2007-06-13 14:29:00 | 00,520,192 | ---- | M] () -- C:\WINDOWS\system32\ati2sgag.exe -- (ATI Smart [Auto | Stopped])
SRV - [2009-03-03 18:20:34 | 00,085,096 | ---- | M] (Autodesk) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service [Disabled | Stopped])
SRV - [2008-10-07 14:34:22 | 00,046,080 | ---- | M] (C-Dilla Ltd) -- C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE -- (C-DillaSrv [Auto | Running])
SRV - [2005-09-23 07:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - File not found -- -- (gusvc [Disabled | Stopped])
SRV - [2008-02-15 14:17:00 | 00,832,760 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\Common Files\BinarySense\hldasvc.exe -- (HDDlife HDD Access service [Auto | Running])
SRV - [2004-08-04 00:44:08 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
SRV - [2007-08-08 09:25:08 | 00,836,904 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe -- (Nero BackItUp Scheduler 3 [Disabled | Stopped])
SRV - [2007-08-21 14:52:54 | 00,382,248 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Stopped])
SRV - [2003-07-28 21:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2007-02-21 03:35:02 | 00,073,728 | ---- | M] (HP) -- C:\WINDOWS\System32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2008-05-30 12:32:16 | 00,572,416 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer [On_Demand | Stopped])
SRV - [2006-12-01 12:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
[color=orange]========== Driver Services (SafeList) ==========[/color]
DRV - [2002-10-09 13:53:54 | 00,043,904 | ---- | M] (Alfa Corporation) -- C:\WINDOWS\System32\Drivers\AFPAnsi.sys -- (AFPAnsi [Boot | Running])
DRV - [2008-06-30 18:16:00 | 00,030,864 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\DRIVERS\afw.sys -- (afw [On_Demand | Running])
DRV - [2008-06-30 18:16:14 | 00,234,640 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\drivers\afwcore.sys -- (afwcore [On_Demand | Running])
DRV - [2006-02-17 11:15:34 | 03,846,848 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
DRV - [2008-06-09 18:16:53 | 00,005,888 | ---- | M] (Alexey V.Voronin @ Hexy) -- C:\WINDOWS\System32\Drivers\AMD64CAx86.sys -- (AMD64CA [On_Demand | Stopped])
DRV - [2006-07-02 00:32:26 | 00,043,520 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\DRIVERS\AmdK8.sys -- (AmdK8 [System | Running])
DRV - [2008-07-11 16:42:08 | 00,033,408 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\Filt\ASWFilt.dll -- (ASWFilt [On_Demand | Running])
DRV - [2007-06-13 21:24:12 | 02,155,520 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
DRV - [2007-05-11 04:10:50 | 00,034,704 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\DRIVERS\blueletaudio.sys -- (BlueletAudio [On_Demand | Running])
DRV - [2007-03-05 07:00:04 | 00,027,792 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\DRIVERS\BlueletSCOAudio.sys -- (BlueletSCOAudio [On_Demand | Running])
DRV - [2007-05-23 05:21:12 | 00,016,272 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\DRIVERS\btnetdrv.sys -- (BT [On_Demand | Running])
DRV - [2007-05-23 05:20:58 | 00,036,496 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\Drivers\btcusb.sys -- (Btcsrusb [On_Demand | Running])
DRV - [2007-03-05 06:55:12 | 00,020,880 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\Drivers\vbtenum.sys -- (BTHidEnum [Boot | Running])
DRV - [2007-03-05 06:56:18 | 00,035,600 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr [Boot | Running])
DRV - [2006-11-21 23:41:18 | 00,022,416 | ---- | M] (IVT Corporation.) -- C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys -- (BTNetFilter [On_Demand | Stopped])
DRV - [2008-10-07 13:53:25 | 00,058,288 | ---- | M] (Macrovision) -- C:\WINDOWS\system32\drivers\CDANT.SYS -- (C-Dilla [On_Demand | Stopped])
DRV - [2009-03-24 13:06:07 | 00,346,304 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) -- C:\WINDOWS\System32\DRIVERS\Cap7134.sys -- (Cap7134 [On_Demand | Running])
DRV - [2006-11-25 17:14:58 | 00,066,688 | ---- | M] (EXLADE, Inc.) -- C:\WINDOWS\system32\Drivers\CrypticDisk.sys -- (CrypticDisk [Auto | Running])
DRV - [2005-12-18 20:42:12 | 00,008,801 | ---- | M] () -- D:\Program Files\DScaler\DSDrv4.sys -- (DSDrv4 [On_Demand | Stopped])
DRV - [2006-12-26 14:54:35 | 00,034,760 | ---- | M] (SlySoft, Inc.) -- C:\WINDOWS\System32\Drivers\ElbyCDFL.sys -- (ElbyCDFL [On_Demand | Running])
DRV - [2006-12-26 14:54:34 | 00,015,440 | ---- | M] (Elaborate Bytes AG) -- C:\WINDOWS\System32\Drivers\ElbyCDIO.sys -- (ElbyCDIO [Auto | Running])
DRV - [2003-07-17 12:56:32 | 00,089,216 | ---- | M] () -- C:\WINDOWS\System32\Drivers\FO_PAnt.sys -- (FO_PAnt [Boot | Running])
DRV - [2007-02-03 05:56:58 | 00,030,808 | ---- | M] (Paragon Software Group) -- C:\WINDOWS\system32\drivers\hotcore2.sys -- (hotcore2 [Boot | Running])
DRV - [2005-10-28 03:24:28 | 00,049,664 | ---- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys -- (HPZid412 [On_Demand | Stopped])
DRV - [2005-10-28 03:24:29 | 00,016,496 | ---- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys -- (HPZipr12 [On_Demand | Stopped])
DRV - [2005-10-28 03:24:30 | 00,021,568 | ---- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys -- (HPZius12 [On_Demand | Stopped])
DRV - [2008-05-24 21:09:08 | 00,073,728 | ---- | M] (EZB Systems, Inc.) -- D:\Program Files\UltraISO\drivers\ISODrive.sys -- (ISODrive [System | Running])
DRV - [2006-08-18 12:10:24 | 00,061,504 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320bus.sys -- (K320bus [On_Demand | Running])
DRV - [2006-08-18 12:10:22 | 00,009,328 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320mdfl.sys -- (K320mdfl [On_Demand | Running])
DRV - [2006-08-18 12:10:22 | 00,097,056 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320mdm.sys -- (K320mdm [On_Demand | Running])
DRV - [2006-08-18 12:10:20 | 00,088,560 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320mgmt.sys -- (K320mgmt [On_Demand | Running])
DRV - [2006-08-18 12:10:18 | 00,086,368 | R--- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\K320obex.sys -- (K320obex [On_Demand | Running])
DRV - [2007-04-18 00:52:38 | 00,017,264 | ---- | M] (FSPro Labs) -- C:\WINDOWS\SYSTEM32\DRIVERS\MPRIFL.SYS -- (MPRIFL [Boot | Running])
DRV - [2008-03-11 18:53:32 | 00,002,208 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\nxsIO32.sys -- (nxsIO32 [Auto | Running])
DRV - [2008-02-26 17:58:33 | 00,047,360 | ---- | M] (VSO Software) -- C:\WINDOWS\System32\Drivers\pcouffin.sys -- (pcouffin [On_Demand | Running])
DRV - [2009-03-24 13:06:07 | 00,054,304 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) -- C:\WINDOWS\System32\DRIVERS\PhTVTune.sys -- (PhTVTune [On_Demand | Running])
DRV - [2001-11-08 17:02:50 | 00,003,912 | ---- | M] () -- C:\WINDOWS\System32\Drivers\port_nt.sys -- (port_nt [Auto | Running])
DRV - [2001-08-17 23:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2006-09-27 23:53:22 | 00,036,560 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2001-08-17 23:57:36 | 00,005,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Drivers\RootMdm.sys -- (ROOTMODEM [On_Demand | Running])
DRV - [2006-02-26 23:46:20 | 00,081,408 | R--- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys -- (RTL8023xp [On_Demand | Stopped])
DRV - [2004-08-03 22:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS -- (rtl8139 [On_Demand | Stopped])
DRV - [2007-12-10 15:22:14 | 00,083,880 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017bus.sys -- (s3017bus [On_Demand | Stopped])
DRV - [2007-12-10 15:22:18 | 00,015,016 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017mdfl.sys -- (s3017mdfl [On_Demand | Stopped])
DRV - [2007-12-10 15:22:18 | 00,110,632 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017mdm.sys -- (s3017mdm [On_Demand | Stopped])
DRV - [2007-12-10 15:22:20 | 00,104,616 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017mgmt.sys -- (s3017mgmt [On_Demand | Stopped])
DRV - [2007-12-10 15:22:20 | 00,025,512 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017nd5.sys -- (s3017nd5 [On_Demand | Stopped])
DRV - [2007-12-10 15:22:22 | 00,100,648 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017obex.sys -- (s3017obex [On_Demand | Stopped])
DRV - [2007-12-10 15:22:22 | 00,110,120 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s3017unic.sys -- (s3017unic [On_Demand | Stopped])
DRV - [2006-02-08 01:40:24 | 00,806,400 | R--- | M] (S3 Graphics Co., Ltd.) -- C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys -- (S3GIGP [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,083,496 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916bus.sys -- (s916bus [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,015,016 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916mdfl.sys -- (s916mdfl [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,109,992 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916mdm.sys -- (s916mdm [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,103,976 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916mgmt.sys -- (s916mgmt [On_Demand | Stopped])
DRV - [2007-11-02 12:47:38 | 00,100,008 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\s916obex.sys -- (s916obex [On_Demand | Stopped])
DRV - [2008-07-11 16:41:28 | 00,673,920 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\DRIVERS\SandBox.sys -- (SandBox [System | Running])
DRV - [2002-03-25 20:02:14 | 00,027,440 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2005-08-10 14:44:04 | 00,050,688 | ---- | M] (Protection Technology) -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01 [Boot | Running])
DRV - [2006-07-05 14:46:06 | 00,063,352 | ---- | M] (Protection Technology (StarForce)) -- C:\WINDOWS\System32\drivers\sfdrv01a.sys -- (sfdrv01a [Boot | Running])
DRV - [2006-06-14 16:56:56 | 00,013,680 | ---- | M] (Protection Technology (StarForce)) -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02 [Boot | Running])
DRV - [2005-11-03 16:40:07 | 00,063,488 | ---- | M] (Protection Technology) -- C:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02 [Boot | Running])
DRV - [2009-01-23 18:29:43 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2006-11-10 15:08:50 | 00,024,064 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\SysTool.sys -- (SysTool [System | Stopped])
DRV - [2008-06-04 18:36:14 | 01,072,722 | ---- | M] (VirusBuster Kft.) -- C:\WINDOWS\system32\DRIVERS\VBEngNT.sys -- (VBEngNT [On_Demand | Running])
DRV - [2008-07-11 16:42:04 | 00,158,816 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\Filt\VBFilt.dll -- (VBFilt [On_Demand | Running])
DRV - [2008-09-12 17:00:46 | 00,095,888 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys -- (VBoxDrv [System | Running])
DRV - [2008-09-12 17:00:50 | 00,041,680 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys -- (VBoxUSBMon [System | Running])
DRV - [2007-03-05 06:52:18 | 00,034,448 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\DRIVERS\VComm.sys -- (VComm [On_Demand | Running])
DRV - [2007-03-05 06:53:18 | 00,044,304 | ---- | M] (IVT Corporation.) -- C:\WINDOWS\System32\Drivers\VcommMgr.sys -- (VcommMgr [On_Demand | Running])
DRV - [2003-07-01 22:42:00 | 00,027,904 | R--- | M] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\viaagp1.sys -- (viaagp1 [Boot | Running])
[color=orange]========== Standard Registry (SafeList) ==========[/color]
[color=orange]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/
IE - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=orange]========== FireFox ==========[/color]
FF - prefs.js..browser.startup.homepage: "http://www.google.pl"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:0.7.5.5
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.0.3
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.6
FF - prefs.js..extensions.enabledItems: {53A03D43-5363-4669-8190-99061B2DEBA5}:1.3.3.7
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0
FF - HKLM\software\mozilla\Mozilla 1.7.7\Extensions\\Components: D:\PROGRAM FILES\MOZILLA.ORG\MOZILLA\COMPONENTS [2008-07-04 16:34:14 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla 1.7.7\Extensions\\Plugins: D:\PROGRAM FILES\MOZILLA.ORG\MOZILLA\PLUGINS [2009-06-09 21:37:40 | 00,000,000 | ---D | M]
[2009-02-18 15:05:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Extensions
[2009-02-18 15:05:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-02-18 15:15:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions
[2009-02-18 15:15:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2009-02-18 15:14:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2009-02-18 15:09:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-02-18 15:11:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MT\Dane aplikacji\mozilla\Firefox\Profiles\5r6o15oy.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Idea2 SidebarBrowserMonitor Class) - {45AD732C-2CE2-4666-B366-B2214AD57A49} - D:\Program Files\Desktop Sidebar\sbhelp.dll (Idea2)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Expressivo) - {85F685C3-20D9-4943-95E4-EB4224056C3F} - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll (IVO Software Sp. z o.o.)
O3 - HKLM\..\Toolbar: (Expressivo) - {85F685C3-20D9-4943-95E4-EB4224056C3F} - D:\Program Files\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll (IVO Software Sp. z o.o.)
O3 - HKLM\..\Toolbar: (StylerToolBar) - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll (StyleFantasist)
O3 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [DrvIcon] D:\Program Files\Vista Drive Icon\DrvIcon.exe (artArmin)
O4 - HKLM..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice (Agnitum Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [VisualTooltip] File not found
O4 - HKLM..\Run: [WellPhone DirectSync - ScheduleSync] D:\PROGRA~1\WELLPH~1\SCHEDU~1.EXE (SmartCom)
O4 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003..\Run: [Vista Sidebar] C:\Program Files\Vista Sidebar\sidebar.exe ()
O4 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003..\Run: [VisualTaskTips] D:\Program Files\VisualTaskTips\VisualTaskTips.exe (VisualTaskTips.com)
O4 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003..\Run: [Windows Intranet controller] C:\WINDOWS\security\lsass.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe (IVT Corporation.)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\ERUNT AutoBackup.lnk = C:\WINDOWS\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\HDDlife.lnk = C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe (BinarySense, Inc.)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\SyncBack.lnk = D:\Program Files\2BrightSparks\SyncBack\SyncBack.exe (2BrightSparks)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\SysInfoMyWork.lnk = D:\Program Files\SysInfoMyWork\SysInfoMyWork.exe (Vetch Utilities)
O4 - Startup: C:\Documents and Settings\MT\Menu Start\Programy\Autostart\Thoosje Vista Sidebar.lnk = C:\Program Files\Vista Sidebar\sidebar.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuEjectPC = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecycleFiles = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuEjectPC = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EditLevel = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1993962763-1606980848-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra 'Tools' menuitem : Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll (Idea2)
O9 - Extra Button: Ustawienia Outpost Security Suite Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Security Suite Pro\ie_bar.dll (Agnitum Ltd.)
O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java (Reg Error: Key error.)
O18 - Protocol\Handler\hddlife {BD758015-47D9-477A-8873-4B688A2BC0E2} - C:\Program Files\Common Files\BinarySense\hlAPP.dll (BinarySense, Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (vistaui.exe) - C:\WINDOWS\system32\vistaui.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-02-26 15:34:55 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009-06-19 17:59:44 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-22 07:18:03 | 00,000,225 | RH-- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-22 07:18:04 | 00,000,225 | RH-- | M] () - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-22 07:18:06 | 00,000,225 | RH-- | M] () - F:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{1de35da4-e47b-11dc-8d8a-c78261217473}\Shell\AutoRun\command - "" = S:\explorefiles.exe -- File not found
O33 - MountPoints2\{1de35da4-e47b-11dc-8d8a-c78261217473}\Shell\explore\command - "" = S:\explorefiles.exe -- File not found
O33 - MountPoints2\{1de35da4-e47b-11dc-8d8a-c78261217473}\Shell\open\command - "" = S:\explorefiles.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009-06-22 07:19:02 | 00,000,000 | ---D | M]
[color=orange]========== Files/Folders - Created Within 30 Days ==========[/color]
[2009-06-21 13:50:04 | 00,000,000 | ---D | C] -- C:\_OTL
[2009-06-21 13:49:39 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\MT\Pulpit\OTL.exe
[2009-06-20 13:15:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MT\Pulpit\avenger
[2009-06-20 11:32:53 | 00,026,956 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\avenger.jpg
[2009-06-20 11:20:02 | 00,000,000 | ---D | C] -- C:\Avenger
[2009-06-20 11:11:08 | 00,724,952 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\avenger.zip
[2009-06-19 19:19:34 | 00,000,000 | ---D | C] -- C:\rsit
[2009-06-19 19:19:34 | 00,000,000 | ---D | C] -- C:\Program Files\trend micro
[2009-06-19 19:14:28 | 00,781,909 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\RSITv.exe
[2009-06-19 17:59:44 | 00,000,000 | RHSD | C] -- C:\autorun.inf
[2009-06-18 22:08:13 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\AutoCAD Zestawy arkuszy
[2009-06-18 22:08:09 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\CyberLink
[2009-06-18 22:08:09 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Bluetooth
[2009-06-18 22:07:28 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Dokumenty
[2009-06-18 22:07:22 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\GTA San Andreas User Files
[2009-06-18 22:07:22 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\G DATA
[2009-06-18 22:07:22 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Dokumenty nie posegregowane
[2009-06-18 22:07:21 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\GTA Vice City User Files
[2009-06-18 21:30:50 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\Moja muzyka
[2009-06-18 21:27:00 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\Moje obrazy
[2009-06-18 21:26:35 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\Moje wideo
[2009-06-18 21:26:29 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\Moje zakupy allegro
[2009-06-18 21:26:29 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\My Backups
[2009-06-18 21:26:21 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\NFS Most Wanted
[2009-06-18 21:26:21 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\NeroVision
[2009-06-18 21:26:17 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Recover
[2009-06-18 21:24:24 | 00,000,000 | --SD | C] -- E:\Moje dokumenty\sony ericsson
[2009-06-18 21:24:23 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\torrenty
[2009-06-18 21:24:23 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\TikGames
[2009-06-18 21:24:23 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\Stardock
[2009-06-18 21:24:20 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\ZPS10
[2009-06-18 21:24:20 | 00,000,000 | ---D | C] -- E:\Moje dokumenty\VirtualDJ
[2009-06-18 19:48:45 | 00,001,280 | -H-- | C] () -- E:\Moje dokumenty\Memento.notes
[2009-06-18 19:48:45 | 00,000,000 | -HS- | C] () -- E:\Moje dokumenty\desktop.ini
[2009-06-18 18:46:47 | 00,395,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF30042.exe
[2009-06-18 18:44:44 | 00,395,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF29595.exe
[2009-06-17 20:42:54 | 00,578,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2009-06-16 11:18:05 | 00,000,671 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\File Washer.lnk
[2009-06-15 19:10:12 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Advanced Disk Catalog.lnk
[2009-06-15 19:09:59 | 00,000,593 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\AoA Audio Extractor.lnk
[2009-06-15 19:09:39 | 00,000,663 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\CCleaner.lnk
[2009-06-15 19:09:29 | 00,000,585 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\CDRoller.lnk
[2009-06-15 19:09:19 | 00,000,779 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\CyberLink PowerDVD.lnk
[2009-06-15 19:08:50 | 00,001,806 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\FotoOffice 3.lnk
[2009-06-15 19:08:41 | 00,000,560 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Glary Utilities.lnk
[2009-06-15 19:08:34 | 00,000,770 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\GOM Player.lnk
[2009-06-15 19:08:11 | 00,000,551 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\MediaMonkey.lnk
[2009-06-15 19:08:04 | 00,002,551 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Microsoft Office Word 2003.lnk
[2009-06-15 19:07:57 | 00,002,106 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Microsoft Office Excel 2003.lnk
[2009-06-15 19:07:50 | 00,000,779 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Nawigator.lnk
[2009-06-15 19:07:37 | 00,000,811 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\MyPhoneExplorer.lnk
[2009-06-15 19:07:30 | 00,002,075 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Nero Express.lnk
[2009-06-15 19:07:20 | 00,000,609 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\PhotoFiltre.lnk
[2009-06-15 19:07:10 | 00,000,601 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\PhotoScape.lnk
[2009-06-15 19:07:04 | 00,000,573 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Picasa2.lnk
[2009-06-15 19:06:32 | 00,000,683 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\VirtualBox.lnk
[2009-06-15 19:06:27 | 00,000,770 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\SUPER ©.lnk
[2009-06-15 19:06:18 | 00,000,539 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Virtual DJ.lnk
[2009-06-15 19:06:11 | 00,000,643 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\VirtualDubMod 1.5.10.2 PL.lnk
[2009-06-15 19:05:54 | 00,000,565 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Winamp.lnk
[2009-06-15 19:05:44 | 00,000,741 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Xilisoft 3GP Video Converter 3.lnk
[2009-06-15 19:05:33 | 00,000,874 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Resident Evil 3.lnk
[2009-06-15 19:05:22 | 00,000,704 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Adobe Photoshop 7.0 CE.lnk
[2009-06-15 19:05:16 | 00,000,609 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\ClonyXXL_PL.lnk
[2009-06-15 19:05:10 | 00,000,600 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Profiler_PL.lnk
[2009-06-15 19:05:00 | 00,000,657 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\CloneCD.lnk
[2009-06-15 19:04:50 | 00,000,658 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\ALLPlayer V3.4.lnk
[2009-06-15 19:04:45 | 00,002,193 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\AutoCAD 2008.lnk
[2009-06-15 19:04:38 | 00,000,575 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Movie DVD Maker.lnk
[2009-06-15 19:04:33 | 00,002,080 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\ACDSee 10 Photo Manager.lnk
[2009-06-15 19:04:20 | 00,001,532 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\AVerTV GO 007 Plus.lnk
[2009-06-15 19:03:49 | 00,000,523 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\DScaler.lnk
[2009-06-14 11:15:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MT\Pulpit\Nowy folder
[2009-06-12 19:49:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MT\Dane aplikacji\Stardock
[2009-06-12 19:36:06 | 00,000,748 | ---- | C] () -- C:\Documents and Settings\MT\Pulpit\Cryptic Disk.lnk
[2009-06-12 18:40:46 | 05,552,104 | ---- | C] (Xequte Software) -- C:\WINDOWS\xdclock.scr
[2009-06-12 18:40:46 | 00,674,138 | ---- | C] () -- C:\WINDOWS\unins004.exe
[2009-06-12 18:40:46 | 00,001,652 | ---- | C] () -- C:\WINDOWS\unins004.dat
[2009-06-12 18:39:20 | 00,118,845 | ---- | C] (Matt Ginzton) -- C:\WINDOWS\Flurry.scr
[2009-06-10 17:04:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MT\Dane aplikacji\AVI ReComp
[2009-06-05 15:43:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\BVRP Software
[2009-06-01 18:39:09 | 00,000,000 | ---D | C] -- C:\Program Files\TRACERMM SOFT
[2009-04-28 19:54:06 | 00,000,032 | ---- | C] () -- C:\WINDOWS\CD-Start.INI
[2009-04-21 18:05:07 | 00,000,126 | ---- | C] () -- C:\WINDOWS\SCRABMAN.INI
[2009-03-09 01:05:59 | 00,000,076 | ---- | C] () -- C:\WINDOWS\System32\w3url.dll
[2009-03-06 00:14:13 | 00,000,126 | RH-- | C] () -- C:\WINDOWS\System32\NTIDBD32.dll
[2009-03-03 22:40:43 | 00,129,024 | ---- | C] () -- C:\WINDOWS\System32\AVERM.dll
[2009-03-03 22:40:43 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll
[2009-02-13 21:59:18 | 00,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2009-02-06 13:29:25 | 00,000,046 | ---- | C] () -- C:\WINDOWS\Resecik.ini
[2009-01-25 22:13:10 | 00,000,096 | ---- | C] () -- C:\WINDOWS\docs.ini
[2009-01-13 13:12:06 | 00,000,029 | ---- | C] () -- C:\WINDOWS\System32\vfolx32n.dll
[2009-01-13 12:33:35 | 00,000,065 | ---- | C] () -- C:\WINDOWS\WaterIllusion.ini
[2009-01-13 01:42:20 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\wbload.dll
[2009-01-12 12:45:08 | 00,001,046 | ---- | C] () -- C:\WINDOWS\ARCHPR.INI
[2009-01-12 01:24:35 | 00,000,169 | ---- | C] () -- C:\WINDOWS\Clony2.ini
[2009-01-11 23:56:50 | 00,000,215 | ---- | C] () -- C:\WINDOWS\Informat.ini
[2009-01-05 18:13:19 | 00,000,063 | ---- | C] () -- C:\WINDOWS\DeskTopBird_K.ini
[2008-12-18 00:30:06 | 00,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008-12-18 00:30:06 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008-12-08 19:54:53 | 00,090,112 | ---- | C] ( ) -- C:\WINDOWS\System32\STAPI.dll
[2008-12-08 19:52:33 | 00,000,035 | ---- | C] () -- C:\WINDOWS\System32\RTELM.dll
[2008-11-19 23:05:48 | 00,000,026 | ---- | C] () -- C:\WINDOWS\mgboss_reg.ini
[2008-11-19 16:15:49 | 00,000,058 | ---- | C] () -- C:\WINDOWS\GScript.INI
[2008-11-19 16:01:02 | 00,000,131 | ---- | C] () -- C:\WINDOWS\CRC.INI
[2008-11-18 23:02:07 | 00,095,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\VBoxDrv.sys
[2008-11-18 22:05:10 | 00,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008-11-06 15:22:21 | 02,416,128 | R--- | C] () -- C:\WINDOWS\System32\s3gcil_inv.dll
[2008-10-11 00:50:37 | 00,000,193 | ---- | C] () -- C:\WINDOWS\Net2fone.ini
[2008-10-07 18:06:20 | 00,000,990 | ---- | C] () -- C:\WINDOWS\psmplay.ini
[2008-09-23 20:17:11 | 00,000,000 | ---- | C] () -- C:\WINDOWS\TeleText.INI
[2008-09-23 20:17:10 | 00,000,064 | ---- | C] () -- C:\WINDOWS\AVerText.ini
[2008-09-09 23:42:24 | 00,000,038 | ---- | C] () -- C:\WINDOWS\WindowSystemCheck.ini
[2008-09-04 19:36:54 | 00,000,359 | ---- | C] () -- C:\WINDOWS\MP3trt.ini
[2008-09-03 13:22:30 | 00,000,135 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008-09-01 18:41:02 | 00,000,388 | ---- | C] () -- C:\WINDOWS\Swish.INI
[2008-09-01 17:13:59 | 00,000,115 | ---- | C] () -- C:\WINDOWS\AIMPR.INI
[2008-08-31 12:02:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\IQ test.INI
[2008-08-23 17:43:48 | 00,000,031 | ---- | C] () -- C:\WINDOWS\System32\Days5.ini
[2008-08-23 17:17:18 | 00,001,144 | ---- | C] () -- C:\WINDOWS\Cerberus.ini
[2008-08-23 17:07:04 | 00,089,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\FO_PAnt.sys
[2008-08-20 18:34:38 | 00,000,024 | ---- | C] () -- C:\WINDOWS\dlb.ini
[2008-08-20 18:31:05 | 00,000,035 | ---- | C] () -- C:\WINDOWS\S&D22.INI
[2008-07-21 14:11:25 | 00,408,576 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
[2008-07-21 14:11:25 | 00,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2008-07-21 14:02:49 | 00,027,648 | -HS- | C] () -- C:\WINDOWS\System32\Smab0.dll
[2008-07-18 17:28:25 | 00,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2008-07-02 18:30:03 | 00,003,240 | ---- | C] () -- C:\WINDOWS\jmshw-n16.ini
[2008-06-09 17:19:13 | 04,239,360 | ---- | C] () -- C:\WINDOWS\System32\qtp-mt334.dll
[2008-06-09 17:19:13 | 00,008,192 | ---- | C] () -- C:\WINDOWS\System32\wnaspi32.dll
[2008-05-23 13:00:16 | 00,000,306 | ---- | C] () -- C:\WINDOWS\kingpong1.INI
[2008-05-22 11:14:00 | 00,000,216 | ---- | C] () -- C:\WINDOWS\gfscore.ini
[2008-05-22 11:05:44 | 00,000,281 | ---- | C] () -- C:\WINDOWS\hero.ini
[2008-05-06 20:26:23 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2008-05-06 10:51:26 | 00,000,176 | ---- | C] () -- C:\WINDOWS\CDPlayer.ini
[2008-05-01 17:56:46 | 00,000,035 | ---- | C] () -- C:\WINDOWS\galaxy.ini
[2008-05-01 17:43:37 | 00,029,696 | ---- | C] () -- C:\WINDOWS\System32\pthread.dll
[2008-03-22 21:00:36 | 00,000,018 | ---- | C] () -- C:\WINDOWS\gfact.ini
[2008-03-11 18:53:32 | 00,002,208 | ---- | C] () -- C:\WINDOWS\System32\drivers\nxsIO32.sys
[2008-03-06 00:45:40 | 00,003,912 | ---- | C] () -- C:\WINDOWS\System32\drivers\port_nt.sys
[2008-02-27 17:52:47 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-02-27 16:52:37 | 00,000,641 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-02-26 20:52:01 | 00,000,100 | ---- | C] () -- C:\WINDOWS\festo.ini
[2008-02-26 18:44:23 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2008-02-26 17:48:56 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008-02-26 17:18:32 | 00,000,000 | ---- | C] () -- C:\WINDOWS\mngui.INI
[2008-02-26 16:59:13 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008-02-26 16:43:08 | 00,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008-02-26 16:43:00 | 00,000,164 | R--- | C] () -- C:\WINDOWS\avrack.ini
[2008-02-26 16:24:29 | 00,000,223 | ---- | C] () -- C:\WINDOWS\System32\BOOTBAK.INI
[2006-11-10 15:08:50 | 00,024,064 | ---- | C] () -- C:\WINDOWS\System32\drivers\SysTool.sys
[2005-10-30 14:28:39 | 00,107,008 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005-10-30 14:28:33 | 00,020,992 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2004-10-31 18:39:02 | 00,005,526 | ---- | C] () -- C:\WINDOWS\AVerTV.ini
[2003-03-15 09:27:30 | 00,000,117 | ---- | C] () -- C:\WINDOWS\Prof.ini
[2002-10-16 00:54:04 | 00,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2002-09-20 18:04:04 | 00,021,811 | ---- | C] () -- C:\WINDOWS\System32\aaqveq.dll
[2002-03-25 20:02:14 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2001-10-28 17:42:30 | 00,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2001-08-13 20:09:48 | 00,659,520 | ---- | C] () -- C:\WINDOWS\System32\vbid3lib.dll
[2001-07-22 00:16:20 | 00,000,825 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-22 00:15:52 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2001-04-20 19:23:28 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\PManager.dll
[1999-01-20 06:01:00 | 00,210,032 | ---- | C] () -- C:\WINDOWS\System32\DBCLIENT.DLL
[1998-09-07 01:03:36 | 00,012,208 | ---- | C] () -- C:\WINDOWS\System32\Cdio16.dll
[1998-09-07 00:55:42 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\cdio32.dll
[color=orange]========== Files - Modified Within 30 Days ==========[/color]
[2 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009-06-22 07:18:00 | 00,000,847 | ---- | M] () -- C:\Documents and Settings\MT\Menu Start\Programy\Autostart\HDDlife.lnk
[2009-06-22 07:17:45 | 00,000,306 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2009-06-22 07:17:35 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\MT\Ustawienia lokalne\desktop.ini
[2009-06-22 07:17:20 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-06-22 07:17:16 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-06-21 16:26:40 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-06-21 13:44:21 | 00,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-06-20 11:32:53 | 00,026,956 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\avenger.jpg
[2009-06-20 11:28:04 | 00,724,952 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\avenger.zip
[2009-06-19 21:00:02 | 00,000,482 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack MTDane aplikacjiMyPhoneExplorer.job
[2009-06-19 20:19:01 | 00,000,494 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Documents and SettingsRobertGadu-Gadu.job
[2009-06-19 20:10:01 | 00,000,518 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Documents and SettingsMTDane aplikacjiThunderbird.job
[2009-06-19 20:08:00 | 00,000,440 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Nowe gg MT.job
[2009-06-19 20:00:01 | 00,000,438 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack GG marcin.job
[2009-06-19 19:19:01 | 00,781,909 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\RSITv.exe
[2009-06-19 16:45:08 | 00,000,825 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-06-19 16:45:08 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-06-19 16:45:08 | 00,000,215 | -HS- | M] () -- C:\boot.ini
[2009-06-18 19:48:45 | 00,000,000 | -HS- | M] () -- E:\Moje dokumenty\desktop.ini
[2009-06-18 18:46:36 | 00,395,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF30042.exe
[2009-06-18 18:44:19 | 00,395,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF29595.exe
[2009-06-18 17:18:17 | 00,000,686 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2009-06-18 16:58:47 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MT\Pulpit\OTL.exe
[2009-06-17 20:42:55 | 00,578,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2009-06-16 11:18:05 | 00,000,671 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\File Washer.lnk
[2009-06-12 18:40:47 | 00,001,652 | ---- | M] () -- C:\WINDOWS\unins004.dat
[2009-06-12 18:40:37 | 00,674,138 | ---- | M] () -- C:\WINDOWS\unins004.exe
[2009-06-10 18:03:58 | 00,000,666 | ---- | M] () -- C:\Documents and Settings\MT\Menu Start\Programy\Autostart\Thoosje Vista Sidebar.lnk
[2009-06-10 17:07:00 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\DScaler.lnk
[2009-06-10 09:00:00 | 00,000,454 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack My phone explorer.job
[2009-06-10 09:00:00 | 00,000,452 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Adv disk catalog.job
[2009-06-10 08:20:36 | 00,102,416 | ---- | M] () -- C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT
[2009-06-09 21:53:04 | 00,351,384 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009-06-09 18:55:08 | 00,005,526 | ---- | M] () -- C:\WINDOWS\AVerTV.ini
[2009-06-07 16:54:22 | 00,000,811 | ---- | M] () -- C:\Documents and Settings\MT\Pulpit\MyPhoneExplorer.lnk
[2009-06-07 16:40:29 | 00,013,030 | -H-- | M] () -- C:\PDOXUSRS.NET
[2009-06-06 20:44:57 | 00,000,215 | ---- | M] () -- C:\WINDOWS\Informat.ini
[2009-06-04 17:43:44 | 00,035,268 | ---- | M] () -- C:\WINDOWS\unins000.dat
[color=orange]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:2BE9FEFC
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:8CE646EE
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:6DFF1A8A
< End of report >
ComboFix 09-06-17.04 - MT 2009-06-22 13:19.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.48.1045.18.1022.631 [GMT 2:00]
Uruchomiony z: c:\documents and settings\MT\Pulpit\ComboFix.exe
AV: Outpost Security Suite Pro *On-access scanning disabled* (Updated) {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
FW: Outpost Security Suite Pro *disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
* Rezydentny antywirus jest aktywny
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\outlook
c:\windows\security\lsass.exe
c:\windows\system\msvbvm60.dll
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf
.
((((((((((((((((((((((((( Pliki utworzone od 2009-05-22 do 2009-06-22 )))))))))))))))))))))))))))))))
.
2009-06-21 11:50 . 2009-06-21 11:50 -------- d-----w- C:\_OTL
2009-06-19 17:19 . 2009-06-19 17:22 -------- d-----w- C:\rsit
2009-06-19 17:19 . 2009-06-19 17:22 -------- d-----w- c:\program files\trend micro
2009-06-17 18:42 . 2009-06-17 18:42 578560 -c--a-w- c:\windows\system32\dllcache\user32.dll
2009-06-15 16:51 . 2009-06-15 16:51 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-12 17:49 . 2009-06-12 17:49 -------- d-----w- c:\documents and settings\MT\Dane aplikacji\Stardock
2009-06-12 17:09 . 2009-06-12 17:26 -------- d-----w- c:\documents and settings\MT\Ustawienia lokalne\Dane aplikacji\sTabLauncher
2009-06-12 16:40 . 2009-06-12 16:40 1652 ----a-w- c:\windows\unins004.dat
2009-06-12 16:40 . 2009-06-12 16:40 674138 ----a-w- c:\windows\unins004.exe
2009-06-12 16:40 . 2006-09-22 07:58 5552104 ----a-w- c:\windows\xdclock.scr
2009-06-12 16:39 . 2003-08-18 23:44 118845 ----a-w- c:\windows\Flurry.scr
2009-06-10 15:04 . 2009-06-10 15:04 -------- d-----w- c:\documents and settings\MT\Dane aplikacji\AVI ReComp
2009-06-05 13:43 . 2009-06-05 13:43 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\BVRP Software
2009-06-01 16:39 . 2009-06-01 16:39 -------- d-----w- c:\program files\TRACERMM SOFT
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-22 10:25 . 2009-02-28 12:31 -------- d---a-w- c:\documents and settings\All Users\Dane aplikacji\TEMP
2009-06-21 14:33 . 2008-11-19 20:10 -------- d-----w- c:\documents and settings\Robert\Dane aplikacji\Desktop Sidebar
2009-06-19 15:29 . 2008-10-07 19:24 -------- d-----w- c:\program files\Stardock
2009-06-18 17:30 . 2008-11-17 18:55 -------- d-----w- c:\program files\Downloaded Installations
2009-06-11 13:15 . 2008-03-19 12:46 102416 ----a-w- c:\documents and settings\praca\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-06-10 06:20 . 2008-09-22 13:38 102416 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-06-10 06:20 . 2008-09-01 11:21 8224 ----a-w- c:\documents and settings\Robert\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-06-09 19:54 . 2008-02-26 14:54 102416 ----a-w- c:\documents and settings\MT\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-06-09 17:51 . 2008-12-19 18:54 -------- d-----w- c:\documents and settings\MT\Dane aplikacji\avidemux
2009-06-06 16:01 . 2008-02-26 15:14 -------- d-----w- c:\program files\Common Files\Teleca Shared
2009-06-04 15:43 . 2008-02-26 18:46 35268 ----a-w- c:\windows\unins000.dat
2009-05-21 20:41 . 2009-05-21 20:41 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\KLS Soft
2009-05-21 18:41 . 2009-05-21 18:41 -------- d-----w- c:\documents and settings\Robert\Dane aplikacji\Silver Style Entertainment
2009-05-14 18:34 . 2009-01-23 17:51 102400 ----a-w- c:\windows\DUMP828d.tmp
2009-05-04 18:25 . 2008-08-23 15:45 -------- d-----w- c:\documents and settings\MT\Dane aplikacji\Thinstall
2009-05-03 09:22 . 2008-05-22 08:02 5277 ----a-w- c:\windows\unins001.dat
2009-05-03 09:22 . 2001-12-29 22:00 73392 ----a-w- c:\windows\unins001.exe
2009-05-03 09:22 . 2008-05-22 08:02 -------- d-----w- c:\program files\kswiat
2009-04-28 17:57 . 2009-04-28 17:57 -------- d-----w- c:\documents and settings\MT\Dane aplikacji\Silver Style Entertainment
2009-04-23 21:06 . 2009-04-23 21:06 -------- d-----w- c:\documents and settings\MT\Dane aplikacji\BinarySense
2009-04-23 21:04 . 2009-04-23 21:04 -------- d-----w- c:\program files\Common Files\BinarySense
2009-04-23 21:04 . 2009-04-23 21:04 -------- d-----w- c:\program files\BinarySense
2009-04-23 19:58 . 2009-01-21 16:10 -------- d-----w- c:\program files\ViStart
2009-04-23 19:58 . 2009-01-13 10:30 -------- d-----w- c:\program files\Słownik
2009-04-23 18:09 . 2009-02-09 15:56 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Team MediaPortal
2009-04-23 18:04 . 2008-02-26 14:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-04-21 19:05 . 2009-04-21 19:05 9158 ----a-r- c:\documents and settings\MT\Dane aplikacji\Microsoft\Installer\{C941F1F1-25B3-4DF5-83E6-888C51A1AAB6}\ARPPRODUCTICON.exe
2009-04-21 19:04 . 2001-10-26 16:15 75706 ----a-w- c:\windows\system32\perfc015.dat
2009-04-21 19:04 . 2001-10-26 16:15 451564 ----a-w- c:\windows\system32\perfh015.dat
2006-05-03 10:06 . 2008-07-21 12:02 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2008-07-21 12:02 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-07-31 13:46 . 2009-01-14 23:10 254768 --sh--r- c:\windows\system32\setup_vf.exe
2007-12-17 13:43 . 2008-07-21 12:02 27648 --sh--w- c:\windows\system32\Smab0.dll
2008-10-21 10:36 . 2008-10-21 09:22 130848 --sha-w- c:\windows\system32\drivers\fidbox.dat
2008-10-21 10:36 . 2008-10-21 09:22 19744 --sha-w- c:\windows\system32\drivers\fidbox2.dat
.
------- Sigcheck -------
[-] 2002-09-20 16:18 1921536 3805154F53701C0F3DC438329BF89EFB c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
[7] 2004-08-03 22:38 2058112 44D1BC1B05E0C7C82E81687B79C653C7 c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
[-] 2004-08-03 22:39 2028544 13C1B77A566371822916BFCCB7509E52 c:\windows\system32\ntkrnlpa.exe
[7] 2004-08-03 22:39 2016768 33FDAD88EEC315EE4CFB147FB19FD2B6 c:\windows\system32\VITrans\ntkrnlpa.exe
[-] 2002-09-20 15:12 1892864 0F8E5919D769F7DCEFB559013400038C c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
[7] 2004-08-03 22:39 2182272 DCF53422B7EDDED3B7431FBAE4A7EE3F c:\windows\ServicePackFiles\i386\ntoskrnl.exe
[-] 2004-08-03 22:38 2161664 B15404765491926B970B62BE4EB8BDE4 c:\windows\system32\ntoskrnl.exe
[7] 2004-08-03 22:38 2149888 A1B8225D45EF88FA294FE1E371BB594A c:\windows\system32\VITrans\ntoskrnl.exe
[-] 2004-08-03 22:38 2161664 B15404765491926B970B62BE4EB8BDE4 c:\windows\VIPv3\backup\ntoskrnl.exe
[-] 2004-08-03 22:44 1423872 25614B8253EE9140A2062E6FE8E09E9F c:\windows\explorer.exe
[-] 2002-09-20 16:05 947712 C37682B5ADCD0D6DD78DBD023C7452C3 c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2004-08-03 22:44 1423872 25614B8253EE9140A2062E6FE8E09E9F c:\windows\ServicePackFiles\i386\explorer.exe
[7] 2004-08-03 22:44 1033728 379098A96E6C165B659DE7E4328010EA c:\windows\system32\VITrans\explorer.exe
[-] 2004-08-03 22:44 1423872 25614B8253EE9140A2062E6FE8E09E9F c:\windows\VIPv3\backup\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Vista Sidebar"="c:\program files\Vista Sidebar\sidebar.exe" [2007-11-20 524288]
"VisualTaskTips"="d:\program files\VisualTaskTips\VisualTaskTips.exe" [2006-05-28 36864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2008-08-25 1208664]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"DrvIcon"="d:\program files\Vista Drive Icon\DrvIcon.exe" [2008-04-13 49152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\MT\Menu Start\Programy\Autostart\
ERUNT AutoBackup.lnk - c:\windows\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
HDDlife.lnk - c:\program files\BinarySense\HDDlife 3\HDDlifePro.exe [2008-2-15 3702807]
Stardock ObjectDock.lnk - d:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-12-18 3450608]
SyncBack.lnk - d:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-9-24 2721536]
SysInfoMyWork.lnk - d:\program files\SysInfoMyWork\SysInfoMyWork.exe [2005-8-9 100352]
Thoosje Vista Sidebar.lnk - c:\program files\Vista Sidebar\sidebar.exe [2008-12-18 524288]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-6-6 657168]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuEjectPC"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecycleFiles"= 0 (0x0)
"NoWelcomeScreen"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"EditLevel"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):76,69,73,74,61,75,69,2e,65,78,65,00
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Core Temp.lnk]
backup=c:\windows\pss\Core Temp.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UPS"=3 (0x3)
"Autodesk Licensing Service"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"d:\\Program Files\\Gadu-Gadu\\gg.exe"=
"d:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"d:\\Program Files\\ICQ6\\ICQ.exe"=
"d:\\Program Files\\uTorrent\\utorrent-1.8-rc7.upx.exe"=
R0 AFPAnsi;G-DATA Ukrywacz Ansi;c:\windows\system32\drivers\AFPAnsi.sys [2008-08-23 43904]
R0 FO_PAnt;FotoOffice VirtualDisc Driver;c:\windows\system32\drivers\FO_PAnt.sys [2008-08-23 89216]
R0 hotcore2;hotcore2;c:\windows\system32\drivers\hotcore2.sys [2008-06-09 30808]
R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [2008-03-19 17264]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [2006-07-05 63352]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [2008-11-17 673920]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2008-11-18 95888]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2008-11-18 41680]
R2 CrypticDisk;CrypticDisk;c:\windows\system32\drivers\CrypticDisk.sys [2009-01-12 66688]
R2 HDDlife HDD Access service;HDDlife HDD Access service;c:\program files\Common Files\BinarySense\hldasvc.exe [2008-02-15 832760]
R2 nxsIO32;NextSensor Kernel I/O Driver;c:\windows\system32\drivers\nxsIO32.sys [2008-03-11 2208]
R2 port_nt;port_nt;c:\windows\system32\drivers\port_nt.sys [2008-03-06 3912]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [2008-11-17 30864]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [2008-11-17 234640]
R3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [2008-11-17 33408]
R3 K320bus;Sony Ericsson K320 driver (WDM);c:\windows\system32\drivers\K320bus.sys [2008-02-26 61504]
R3 K320mdfl;Sony Ericsson K320 USB WMC Modem Filter;c:\windows\system32\drivers\K320mdfl.sys [2008-02-26 9328]
R3 K320mdm;Sony Ericsson K320 USB WMC Modem Driver;c:\windows\system32\drivers\K320mdm.sys [2008-02-26 97056]
R3 K320mgmt;Sony Ericsson K320 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\K320mgmt.sys [2008-02-26 88560]
R3 K320obex;Sony Ericsson K320 USB WMC OBEX Interface;c:\windows\system32\drivers\K320obex.sys [2008-02-26 86368]
R3 PhTVTune;Cap7134 TVTuner;c:\windows\system32\drivers\PhTVTune.sys [2009-03-24 54304]
R3 VBEngNT;VBEngNT;c:\windows\system32\drivers\VBEngNT.sys [2008-11-17 1072722]
R3 VBFilt;VBFilt;c:\windows\system32\Filt\VBFilt.dll [2008-11-17 158816]
S1 SysTool;SysTool Overclocking Utility;c:\windows\system32\drivers\SysTool.sys [2006-11-10 24064]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [2008-11-17 1570136]
S3 AMD64CA;AMD64CA;c:\windows\system32\drivers\AMD64CAx86.sys [2008-06-09 5888]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\system32\drivers\s3017bus.sys [2009-03-17 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\system32\drivers\s3017mdfl.sys [2009-03-17 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\system32\drivers\s3017mdm.sys [2009-03-17 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s3017mgmt.sys [2009-03-17 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\system32\drivers\s3017nd5.sys [2009-03-17 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\system32\drivers\s3017obex.sys [2009-03-17 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\system32\drivers\s3017unic.sys [2009-03-17 110120]
S3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [2008-11-06 806400]
S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\drivers\s916bus.sys [2009-03-17 83496]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\system32\drivers\s916mdfl.sys [2009-03-17 15016]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\system32\drivers\s916mdm.sys [2009-03-17 109992]
S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s916mgmt.sys [2009-03-17 103976]
S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface;c:\windows\system32\drivers\s916obex.sys [2009-03-17 100008]
.
Zawartość folderu 'Zaplanowane zadania'
2009-06-22 c:\windows\Tasks\GlaryInitialize.job
- d:\program files\Glary Utilities\initialize.exe [2009-01-27 12:19]
2009-06-10 c:\windows\Tasks\SyncBack Adv disk catalog.job
- d:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-09-24 13:16]
2009-06-19 c:\windows\Tasks\SyncBack Documents and SettingsMTDane aplikacjiThunderbird.job
- d:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-09-24 13:16]
2009-06-19 c:\windows\Tasks\SyncBack Documents and SettingsRobertGadu-Gadu.job
- d:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-09-24 13:16]
2009-06-19 c:\windows\Tasks\SyncBack GG marcin.job
- d:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-09-24 13:16]
2009-06-19 c:\windows\Tasks\SyncBack MTDane aplikacjiMyPhoneExplorer.job
- d:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-09-24 13:16]
2009-06-10 c:\windows\Tasks\SyncBack My phone explorer.job
- d:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-09-24 13:16]
2009-06-19 c:\windows\Tasks\SyncBack Nowe gg MT.job
- d:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-09-24 13:16]
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-Windows Intranet controller - c:\windows\security\lsass.exe
HKLM-Run-VisualTooltip - (no file)
Notify-WgaLogon - (no file)
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.google.pl/
uSearchURL,(Default) = hxxp://www.searchgateway.net/search/%s
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {93791610-F0BC-4990-A977-06B47E9077D5} = 212.2.96.54 212.2.96.53
Handler: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - c:\program files\Common Files\BinarySense\hlAPP.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-22 13:22
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\MT\USTAWI~1\Temp\ASFWHide"
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_USERS\S-1-5-21-1993962763-1606980848-839522115-1003\Software\%s (%s)\«Ůç >ńz|ďnđz|ďCStringList*đłćßç!AńoŢçnđz|ďCMapPtrToPtr\PLK_Settings\BCGCommandManager]
"CommandsWithoutImages"=hex:00,00
"MenuUserImages"=hex:00,00
[HKEY_USERS\S-1-5-21-1993962763-1606980848-839522115-1003\Software\%s (%s)\«Ůç >ńz|ďnđz|ďCStringList*đłćßç!AńoŢçnđz|ďCMapPtrToPtr\PLK_Settings\BCGControlBarVersion]
"Major"=dword:00000008
"Minor"=dword:0000003c
[HKEY_USERS\S-1-5-21-1993962763-1606980848-839522115-1003\Software\%s (%s)\«Ůç >ńz|ďnđz|ďCStringList*đłćßç!AńoŢçnđz|ďCMapPtrToPtr\PLK_Settings\BCGToolbarParameters]
"Tooltips"=dword:00000001
"ShortcutKeys"=dword:00000001
"LargeIcons"=dword:00000001
"MenuAnimation"=dword:00000000
"RecentlyUsedMenus"=dword:00000001
"MenuShadows"=dword:00000001
"ShowAllMenusAfterDelay"=dword:00000001
"Look2000"=dword:00000001
"CommandsUsage"=hex:05,00,00,00,00,00
[HKEY_USERS\S-1-5-21-1993962763-1606980848-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{084E3262-1D6B-6C5E-71E8-9972D23FC53A}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"manllgpimglahchfkckdoeaapo"=hex:64,61,66,62,70,66,6c,6c,00,00
"lanllgpiohbfbafnkadpejho"=hex:64,61,66,62,70,66,63,6c,00,00
"nanllgpiaifdljgfabacplmainnn"=hex:64,61,66,62,70,66,69,6c,00,00
"iaimcdhomnclpgmmkn"=hex:62,61,67,62,00,00
"laimeafkpliaemfnibclbiga"=hex:62,61,67,62,00,00
"oahpnkmpjjgegmmnicehnadaikogob"=hex:62,61,67,62,00,00
"oahpnkmpjjgegmmnicehnllddjnhbj"=hex:62,61,67,62,00,00
"bbhpnkmpjjgegmmnicehdmkdoamejnpipkbe"=hex:62,61,66,62,00,00
"paimoafkgddcabkbolodiogfihcadeib"=hex:62,61,67,62,00,00
"oaimoafkgddcabdcfbdphpogdeegfl"=hex:62,61,67,62,00,00
"dbimoafkgddcabjcedjjekllkhihelimnfflfnfj"=hex:62,61,67,62,00,00
"jaimcdhmgcgikcakbkpf"=hex:62,61,66,62,00,00
"kaimcdhmeciilinmmihjeg"=hex:62,61,66,62,00,00
"maimcdhmcccinjofihbibpbchm"=hex:62,61,66,62,00,00
"oaimcdhmpbpcjcmddenfabhjiemidf"=hex:62,61,67,62,00,00
"haimcdhmobiddnmc"=hex:62,61,67,62,00,00
"nanlejmbphacocfoocjkghgkmmap"=hex:63,61,6d,61,64,6b,00,00
"kbhphkblfaemailgibjeeabgjlddpidnhhifdclmgaiekhafapjcjd"=hex:62,61,67,62,00,66
"iacoeccgelhopnhmhh"=hex:68,61,6a,6f,6b,66,66,61,70,6f,62,64,6c,65,63,69,00,0a
"haipgknoldmihidf"=hex:6f,61,70,6e,6c,63,63,62,65,64,62,67,6b,6e,68,64,6a,6a,
6b,65,68,6c,66,70,65,69,6e,61,6f,70,00,00
"jahpjlhldjcjcaflpoae"=hex:64,62,6a,6f,6c,64,61,6d,70,6b,65,61,70,63,6d,64,61,
62,63,62,65,65,6f,6c,61,6c,61,65,68,6b,64,63,70,6c,66,6e,6f,70,65,63,00,05
"jabohcmignjnciphadbl"=hex:62,61,67,62,00,00
"baom"=hex:67,61,62,61,6c,65,6a,70,67,64,67,68,65,6b,00,00
"banm"=hex:67,61,62,61,6c,65,6a,70,67,64,67,68,65,6b,00,00
"cahmop"=hex:64,61,66,62,6d,66,65,65,00,64
"cahmnp"=hex:63,61,69,62,64,66,00,65
"iahnifkemboikgpoba"=hex:65,61,66,62,61,66,6b,64,64,66,00,68
"iahnifkemboikgpoca"=hex:64,61,6e,61,64,6c,67,62,00,66
"gbimcdhomnclmjgaoiajdpfilbandkmhpilnfojhainmbl"=hex:62,61,66,62,00,bf
"kbfonmhjbgdnmcoengcdhbmfjflfeecmehhfjglimddkgojbaioaak"=hex:6e,61,66,6f,6f,70,
70,66,6d,68,61,68,66,61,64,67,69,63,66,6f,65,65,66,64,63,6f,64,6a,00,00
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:2e,e8,e1,00,eb,16,2b,de,c8,84,ff,04,28,
f2,1a,9d,c8,28,51,af,b0,29,a3,98,83,3f,f5,5f,44,84,e8,d6,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,ab,c2,36,23,12,
aa,e2,14,71,3b,04,66,8b,46,0d,96,63,83,2b,a3,59,50,35,0b,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,0e,e7,09,34,2f,
2e,b1,08,25,da,ec,7e,55,20,c9,26,97,4d,ba,1a,59,0a,22,19,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:6b,65,49,6a,7e,99,74,f7,fe,b4,7f,01,79,
84,81,8a,3e,1e,9e,e0,57,5a,93,61,bf,b1,8d,41,6e,3c,fe,09,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,b3,d8,d3,d2,91,
70,61,34,cd,44,cd,b9,a6,33,6c,cd,22,b5,e5,81,55,52,9e,e6,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,61,96,05,e1,80,
07,66,19,b0,18,ed,a7,3f,8d,37,a4,30,a2,1b,4e,3e,8f,25,89,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,54,92,87,c6,40,
a5,83,f5,31,77,e1,ba,b1,f8,68,02,79,e4,32,0f,ac,96,4c,0b,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,5a,52,16,0d,51,
c4,32,bb,83,6c,56,8b,a0,85,96,ab,e3,8f,3e,d0,d3,a6,91,d2,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,68,70,ca,eb,7e,
cc,76,b1,51,fa,6e,91,28,9e,14,cc,7f,7f,5a,fa,49,f4,61,71,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:37,a4,aa,c3,a6,15,56,0a,6d,28,fd,94,89,
98,5d,00,b1,cd,45,5a,a8,c4,f8,b9,a0,51,56,27,15,19,d6,f5,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,07,4b,e6,2a,c9,
b1,cb,a2,e3,0e,66,d5,eb,bc,2f,6b,62,2f,73,c1,eb,11,87,cc,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,d5,a4,3e,a0,24,
9a,d3,31,fa,ea,66,7f,d4,3b,6b,70,52,4a,86,8b,bf,76,1b,f8,6c,43,2d,1e,aa,22,\
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(972)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\cscui.dll
.
Czas ukończenia: 2009-06-22 13:24
ComboFix-quarantined-files.txt 2009-06-22 11:24
Przed: 7 346 741 248 bajtów wolnych
Po: 7 341 850 624 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /FASTDETECT /NoExecute=AlwaysOff
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
352
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 7 gości