
Ogolnie problem natury sprzetu skopanego fizycznie wykluczylem... takze wydaje mi sie ze cos nie halo w systemie. Zamieszczam logi:
- Kod: Zaznacz wszystko
OTL logfile created on: 2012-01-31 10:42:44 - Run 6
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Welcome\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
2,00 Gb Total Physical Memory | 1,33 Gb Available Physical Memory | 66,48% Memory free
3,85 Gb Paging File | 3,38 Gb Available in Paging File | 87,87% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 146,48 Gb Total Space | 7,99 Gb Free Space | 5,45% Space Free | Partition Type: NTFS
Drive D: | 195,31 Gb Total Space | 3,89 Gb Free Space | 1,99% Space Free | Partition Type: NTFS
Drive E: | 123,97 Gb Total Space | 0,67 Gb Free Space | 0,54% Space Free | Partition Type: NTFS
Computer Name: PC | User Name: Welcome | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2012-01-30 23:00:36 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Welcome\Pulpit\OTL.exe
PRC - [2012-01-18 19:54:06 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Welcome\Dane aplikacji\Dropbox\bin\Dropbox.exe
PRC - [2012-01-09 00:59:47 | 000,912,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011-12-18 20:24:58 | 000,493,056 | ---- | M] (LOL Replay) -- C:\Program Files\LOLReplay\LOLRecorder.exe
PRC - [2009-11-16 08:04:30 | 000,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2009-11-16 08:03:32 | 002,054,360 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2008-09-20 20:36:11 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-09-20 20:35:59 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2012-01-09 00:59:48 | 000,849,368 | ---- | M] () -- C:\Program Files\Mozilla Firefox\js3250.dll
MOD - [2011-12-18 12:47:38 | 000,263,680 | ---- | M] () -- C:\Program Files\LOLReplay\LOLUtils.dll
MOD - [2010-11-04 07:51:44 | 000,555,624 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\nView\nvShell.dll
MOD - [2009-11-02 01:04:05 | 000,970,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\cb4cb21d14767292e079366a5d3d76cd\System.Configuration.ni.dll
MOD - [2009-11-01 23:53:08 | 005,449,728 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\36f3953f24d4f0b767bf172331ad6f3e\System.Xml.ni.dll
MOD - [2009-11-01 23:53:03 | 012,428,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\9a254c455892c02355ab0ab0f0727c5b\System.Windows.Forms.ni.dll
MOD - [2009-11-01 23:52:49 | 001,587,200 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\6978f2e90f13bc720d57fa6895c911e2\System.Drawing.ni.dll
MOD - [2009-11-01 23:52:33 | 002,294,784 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\6c69930d05c557da70144bcc0add7065\System.Core.ni.dll
MOD - [2009-11-01 23:52:25 | 000,539,648 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\b4dc4bd8534d90fbb7430926ad990cd9\PresentationFramework.Luna.ni.dll
MOD - [2009-11-01 23:52:23 | 014,320,128 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9519494798a88867406b5755e1dbded6\PresentationFramework.ni.dll
MOD - [2009-11-01 23:52:08 | 012,213,248 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\12dcb10b76012416357bdbb010fdaa97\PresentationCore.ni.dll
MOD - [2009-11-01 23:51:57 | 003,311,104 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\df20e56b59b1b1a595af305ddc0777ba\WindowsBase.ni.dll
MOD - [2009-11-01 23:51:51 | 007,867,392 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\aa7926460a336408c8041330ad90929d\System.ni.dll
MOD - [2009-11-01 23:51:42 | 011,485,184 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\9adb89fa22fd5b4ce433b5aca7fb1b07\mscorlib.ni.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - [2010-05-03 18:01:00 | 003,658,096 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2009-11-16 08:12:54 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009-11-16 08:04:30 | 000,735,960 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2008-09-20 20:35:59 | 000,015,872 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (W3SVC)
SRV - [2008-09-20 20:35:59 | 000,015,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (IISADMIN)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2011-02-17 18:06:10 | 000,111,152 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV - [2011-01-23 20:57:34 | 000,279,712 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2011-01-23 20:57:34 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2010-12-18 12:03:56 | 000,021,696 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2010-05-28 12:47:07 | 000,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZDPSp50.sys -- (ZDPSp50)
DRV - [2009-11-25 23:06:34 | 000,034,384 | ---- | M] (Screaming Bee LLC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ScreamingBAudio.sys -- (SCREAMINGBDRIVER)
DRV - [2009-11-16 08:06:50 | 000,096,408 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2009-11-16 08:03:36 | 000,108,792 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009-11-16 07:56:12 | 000,116,520 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2009-03-30 03:09:28 | 000,239,336 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\RsFx0103.sys -- (RsFx0103)
DRV - [2009-03-18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2008-12-26 11:56:04 | 000,017,792 | ---- | M] (Avnex) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vcsvad.sys -- (VCSVADHWSer) Avnex Virtual Audio Device (WDM)
DRV - [2008-04-29 09:00:00 | 000,288,896 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2008-04-17 15:33:26 | 004,707,328 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007-10-23 17:48:16 | 000,012,416 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\asusgsb.sys -- (asusgsb)
DRV - [2006-11-30 15:13:56 | 000,061,536 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se45bus.sys -- (se45bus) Sony Ericsson Device 069 driver (WDM)
DRV - [2006-06-14 13:44:30 | 000,012,288 | R--- | M] (ASUSTeK Computer Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\EIO_XP.sys -- (EIO_XP)
DRV - [1996-04-03 20:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1659004503-1801674531-682003330-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1659004503-1801674531-682003330-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-1659004503-1801674531-682003330-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1659004503-1801674531-682003330-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1659004503-1801674531-682003330-1005\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1659004503-1801674531-682003330-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.pl"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.14
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: ""
FF - prefs.js..network.proxy.backup.gopher: ""
FF - prefs.js..network.proxy.backup.gopher_port: ""
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: ""
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: ""
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.3088: C:\Program Files\Kodeki\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.11.3006: C:\Program Files\Kodeki\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-01-18 11:24:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-01-09 00:59:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010-05-30 20:47:59 | 000,000,000 | ---D | M]
[2010-04-27 22:44:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Welcome\Dane aplikacji\Mozilla\Extensions
[2012-01-30 16:32:40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Welcome\Dane aplikacji\Mozilla\Firefox\Profiles\ocbmo63o.default\extensions
[2008-10-12 20:33:32 | 000,000,000 | ---D | M] (X-Wars GHOST Plugin) -- C:\Documents and Settings\Welcome\Dane aplikacji\Mozilla\Firefox\Profiles\ocbmo63o.default\extensions\{90BCCD47-C818-41be-910E-0582947E30AF}
[2012-01-21 16:03:38 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Welcome\Dane aplikacji\Mozilla\Firefox\Profiles\ocbmo63o.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2012-01-21 16:03:45 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Welcome\Dane aplikacji\Mozilla\Firefox\Profiles\ocbmo63o.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011-01-04 13:09:59 | 000,000,523 | ---- | M] () -- C:\Documents and Settings\Welcome\Dane aplikacji\Mozilla\Firefox\Profiles\ocbmo63o.default\searchplugins\daemon-search.xml
[2012-01-30 16:32:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010-06-05 16:59:11 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010-06-05 16:58:59 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010-06-05 16:58:57 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007-12-11 09:07:00 | 000,307,200 | ---- | M] (ESKA) -- C:\Program Files\mozilla firefox\plugins\npOggX.dll
[2012-01-09 00:59:52 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2012-01-09 00:59:52 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2012-01-09 00:59:52 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2012-01-09 00:59:52 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2012-01-09 00:59:52 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2012-01-09 00:59:52 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
O1 HOSTS File: ([2011-06-25 10:56:06 | 000,000,770 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 195.242.152.210 polishtracker.org irc.polishtracker.org announce.polishtracker.org
O3 - HKU\S-1-5-21-1659004503-1801674531-682003330-1005\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\LOLRecorder.lnk = C:\Program Files\LOLReplay\LOLRecorder.exe (LOL Replay)
O4 - Startup: C:\Documents and Settings\Welcome\Menu Start\Programy\Autostart\Dropbox.lnk = C:\Documents and Settings\Welcome\Dane aplikacji\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Documents and Settings\Welcome\Menu Start\Programy\Autostart\HDDlife.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1659004503-1801674531-682003330-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1659004503-1801674531-682003330-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1659004503-1801674531-682003330-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1659004503-1801674531-682003330-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1659004503-1801674531-682003330-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.62 62.179.1.63
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D677C574-B488-4858-A185-B350FDA7399A}: DhcpNameServer = 62.179.1.62 62.179.1.63
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Welcome\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Welcome\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-10-12 18:44:55 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2012-01-30 23:00:30 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Welcome\Pulpit\OTL.exe
[2012-01-30 22:24:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Welcome\Moje dokumenty\LOLReplay
[2012-01-30 20:39:30 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012-01-30 20:31:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Welcome\Dane aplikacji\InstallShield
[2012-01-30 20:21:30 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Welcome\Recent
[2012-01-24 22:46:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Welcome\Moje dokumenty\Dropbox
[2012-01-24 22:45:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Welcome\Menu Start\Programy\Dropbox
[2012-01-24 22:45:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Welcome\Dane aplikacji\Dropbox
[2012-01-06 13:32:58 | 000,014,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhid.sys
[1 C:\Documents and Settings\Welcome\Moje dokumenty\*.tmp files -> C:\Documents and Settings\Welcome\Moje dokumenty\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2012-01-30 23:00:36 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Welcome\Pulpit\OTL.exe
[2012-01-30 22:29:44 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Welcome\Pulpit\e4b2gj6p.exe
[2012-01-30 22:27:04 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012-01-30 22:24:45 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012-01-30 21:21:35 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012-01-30 21:21:34 | 000,196,096 | ---- | M] () -- C:\Documents and Settings\Welcome\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-01-24 22:45:54 | 000,000,995 | ---- | M] () -- C:\Documents and Settings\Welcome\Menu Start\Programy\Autostart\Dropbox.lnk
[1 C:\Documents and Settings\Welcome\Moje dokumenty\*.tmp files -> C:\Documents and Settings\Welcome\Moje dokumenty\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2012-01-30 22:29:44 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Welcome\Pulpit\e4b2gj6p.exe
[2012-01-24 22:45:54 | 000,000,995 | ---- | C] () -- C:\Documents and Settings\Welcome\Menu Start\Programy\Autostart\Dropbox.lnk
[2011-12-24 00:17:11 | 000,424,226 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-1659004503-1801674531-682003330-1005-0.dat
[2011-12-24 00:17:11 | 000,216,414 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat
[2011-09-28 13:48:48 | 000,000,032 | ---- | C] () -- C:\WINDOWS\MenuCD.INI
[2011-06-21 13:46:45 | 000,038,408 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011-03-27 12:02:19 | 000,252,080 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011-03-27 12:02:17 | 000,252,080 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011-03-27 12:02:17 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011-03-27 12:01:18 | 002,292,678 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2011-01-23 20:57:34 | 000,279,712 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2011-01-23 20:57:34 | 000,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2011-01-18 20:45:14 | 000,000,361 | ---- | C] () -- C:\WINDOWS\pdf2word.INI
[2010-09-03 12:25:42 | 000,196,096 | ---- | C] () -- C:\Documents and Settings\Welcome\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-03-22 15:30:47 | 000,000,404 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2010-03-22 15:30:05 | 000,000,050 | ---- | C] () -- C:\WINDOWS\System32\bridf08b.dat
[2010-03-22 15:28:28 | 000,031,767 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2009-12-03 18:10:34 | 000,008,192 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2009-11-01 23:50:16 | 002,056,112 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat
[2009-08-29 18:35:29 | 000,000,040 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\ra3.ini
[2009-08-26 12:41:05 | 000,109,789 | ---- | C] () -- C:\WINDOWS\War3Unin.dat
[2009-07-20 12:08:14 | 000,219,648 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009-07-12 21:49:53 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009-02-12 10:37:24 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008-12-08 13:53:37 | 000,000,499 | ---- | C] () -- C:\WINDOWS\BDE.INI
[2008-12-08 13:53:37 | 000,000,177 | ---- | C] () -- C:\WINDOWS\BCW5.INI
[2008-12-08 13:53:37 | 000,000,085 | ---- | C] () -- C:\WINDOWS\TDW.INI
[2008-12-08 13:53:36 | 000,188,448 | ---- | C] () -- C:\WINDOWS\System32\bocof.dll
[2008-12-08 13:53:36 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\bw32000c.dll
[2008-12-08 13:53:36 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\bw320007.dll
[2008-12-08 13:53:36 | 000,091,136 | ---- | C] () -- C:\WINDOWS\BC5RMV.EXE
[2008-12-08 13:53:36 | 000,000,586 | ---- | C] () -- C:\WINDOWS\owl.ini
[2008-11-29 21:18:27 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008-11-20 14:44:17 | 000,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-11-02 11:07:56 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2008-10-25 21:51:56 | 000,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys
[2008-10-13 06:28:12 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008-10-12 20:34:15 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008-10-12 20:25:36 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008-10-12 20:23:29 | 000,220,840 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008-10-12 19:38:00 | 000,001,907 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2008-10-12 19:12:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008-10-12 18:55:04 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008-10-12 18:41:32 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008-10-12 18:40:33 | 000,058,750 | ---- | C] () -- C:\WINDOWS\System32\w3ctrs.ini
[2008-10-12 18:40:32 | 000,014,972 | ---- | C] () -- C:\WINDOWS\System32\axperf.ini
[2008-10-12 18:40:31 | 000,018,031 | ---- | C] () -- C:\WINDOWS\System32\infoctrs.ini
[2008-09-20 20:36:45 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008-09-20 20:36:14 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008-09-20 20:35:50 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008-09-20 20:35:48 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008-09-20 20:35:23 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2008-09-20 20:35:15 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008-09-20 20:35:13 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008-09-20 20:35:09 | 000,659,238 | ---- | C] () -- C:\WINDOWS\System32\perfh015.dat
[2008-09-20 20:35:09 | 000,594,410 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008-09-20 20:35:09 | 000,313,828 | ---- | C] () -- C:\WINDOWS\System32\perfi015.dat
[2008-09-20 20:35:09 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008-09-20 20:35:09 | 000,140,696 | ---- | C] () -- C:\WINDOWS\System32\perfc015.dat
[2008-09-20 20:35:09 | 000,117,232 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008-09-20 20:35:09 | 000,034,990 | ---- | C] () -- C:\WINDOWS\System32\perfd015.dat
[2008-09-20 20:35:09 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008-09-20 20:34:29 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2003-04-08 11:40:22 | 000,005,679 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002-01-14 12:37:00 | 000,459,776 | ---- | C] () -- C:\WINDOWS\System32\converter.dll
[1996-04-03 20:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
[color=#E56717]========== LOP Check ==========[/color]
[2010-03-18 00:05:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AlawarWrapper
[2010-05-04 13:52:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\EA Core
[2010-05-30 20:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ESET
[2010-02-20 19:42:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10
[2011-11-19 22:33:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM
[2011-12-09 23:39:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PreEmptive Solutions
[2010-03-22 15:28:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ScanSoft
[2010-06-14 20:14:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Screaming Bee
[2010-04-02 10:20:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\stamina
[2011-12-25 12:38:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP
[2010-12-21 16:45:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\avidemux
[2010-10-26 14:30:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\BESTplayer
[2011-12-25 12:38:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\BinarySense
[2010-07-17 13:31:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\BugTrap Console Test
[2010-07-18 11:54:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\BugTrap Console Test105
[2010-05-10 19:29:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\Command and Conquer 4
[2008-10-26 07:55:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\DAEMON Tools
[2012-01-30 22:27:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\Dropbox
[2011-04-13 19:31:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\EVEMon
[2011-12-20 16:56:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\f2fUpperIntermediate
[2011-04-01 23:19:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\Gadu-Gadu 10
[2010-12-17 11:33:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\GHISLER
[2011-12-25 12:51:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\HD Tune Pro
[2010-02-25 11:54:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\LG Electronics
[2010-07-17 13:10:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\LolClient
[2010-03-28 23:40:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\Mount&Blade
[2010-06-05 10:27:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\Octoshape
[2011-04-05 20:26:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\OpenFM
[2011-06-03 22:53:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\RIFT
[2010-08-05 20:06:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\TS3Client
[2012-01-30 22:23:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Welcome\Dane aplikacji\uTorrent
[color=#E56717]========== Purity Check ==========[/color]
< End of report >
- Kod: Zaznacz wszystko
OTL Extras logfile created on: 2012-01-31 10:42:44 - Run 6
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Welcome\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
2,00 Gb Total Physical Memory | 1,33 Gb Available Physical Memory | 66,48% Memory free
3,85 Gb Paging File | 3,38 Gb Available in Paging File | 87,87% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 146,48 Gb Total Space | 7,99 Gb Free Space | 5,45% Space Free | Partition Type: NTFS
Drive D: | 195,31 Gb Total Space | 3,89 Gb Free Space | 1,99% Space Free | Partition Type: NTFS
Drive E: | 123,97 Gb Total Space | 0,67 Gb Free Space | 0,54% Space Free | Partition Type: NTFS
Computer Name: PC | User Name: Welcome | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Extra Registry (SafeList) ==========[/color]
[color=#E56717]========== File Associations ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[color=#E56717]========== Shell Spawning ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[color=#E56717]========== Security Center Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[color=#E56717]========== System Restore Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
[color=#E56717]========== Firewall Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"57653:TCP" = 57653:TCP:*:Enabled:Pando Media Booster
"57653:UDP" = 57653:UDP:*:Enabled:Pando Media Booster
"58782:TCP" = 58782:TCP:*:Enabled:Pando Media Booster
"58782:UDP" = 58782:UDP:*:Enabled:Pando Media Booster
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
"57653:TCP" = 57653:TCP:*:Enabled:Pando Media Booster
"57653:UDP" = 57653:UDP:*:Enabled:Pando Media Booster
"8394:TCP" = 8394:TCP:*:Enabled:League of Legends Launcher
"8394:UDP" = 8394:UDP:*:Enabled:League of Legends Launcher
"8378:TCP" = 8378:TCP:*:Enabled:League of Legends Launcher
"8378:UDP" = 8378:UDP:*:Enabled:League of Legends Launcher
"8379:TCP" = 8379:TCP:*:Enabled:League of Legends Launcher
"8379:UDP" = 8379:UDP:*:Enabled:League of Legends Launcher
"6955:TCP" = 6955:TCP:*:Enabled:League of Legends Launcher
"6955:UDP" = 6955:UDP:*:Enabled:League of Legends Launcher
"8380:TCP" = 8380:TCP:*:Enabled:League of Legends Launcher
"8380:UDP" = 8380:UDP:*:Enabled:League of Legends Launcher
"6966:TCP" = 6966:TCP:*:Enabled:League of Legends Launcher
"6966:UDP" = 6966:UDP:*:Enabled:League of Legends Launcher
"6917:TCP" = 6917:TCP:*:Enabled:League of Legends Launcher
"6917:UDP" = 6917:UDP:*:Enabled:League of Legends Launcher
"6882:TCP" = 6882:TCP:*:Enabled:League of Legends Launcher
"6882:UDP" = 6882:UDP:*:Enabled:League of Legends Launcher
"6938:TCP" = 6938:TCP:*:Enabled:League of Legends Launcher
"6938:UDP" = 6938:UDP:*:Enabled:League of Legends Launcher
"8395:TCP" = 8395:TCP:*:Enabled:League of Legends Launcher
"8395:UDP" = 8395:UDP:*:Enabled:League of Legends Launcher
"6968:TCP" = 6968:TCP:*:Enabled:League of Legends Launcher
"6968:UDP" = 6968:UDP:*:Enabled:League of Legends Launcher
"8381:TCP" = 8381:TCP:*:Enabled:League of Legends Launcher
"8381:UDP" = 8381:UDP:*:Enabled:League of Legends Launcher
"8396:TCP" = 8396:TCP:*:Enabled:League of Legends Launcher
"8396:UDP" = 8396:UDP:*:Enabled:League of Legends Launcher
"6927:TCP" = 6927:TCP:*:Enabled:League of Legends Launcher
"6927:UDP" = 6927:UDP:*:Enabled:League of Legends Launcher
"6979:TCP" = 6979:TCP:*:Enabled:League of Legends Launcher
"6979:UDP" = 6979:UDP:*:Enabled:League of Legends Launcher
"6921:TCP" = 6921:TCP:*:Enabled:League of Legends Launcher
"6921:UDP" = 6921:UDP:*:Enabled:League of Legends Launcher
"8397:TCP" = 8397:TCP:*:Enabled:League of Legends Launcher
"8397:UDP" = 8397:UDP:*:Enabled:League of Legends Launcher
"6975:TCP" = 6975:TCP:*:Enabled:League of Legends Launcher
"6975:UDP" = 6975:UDP:*:Enabled:League of Legends Launcher
"8382:TCP" = 8382:TCP:*:Enabled:League of Legends Launcher
"8382:UDP" = 8382:UDP:*:Enabled:League of Legends Launcher
"6911:TCP" = 6911:TCP:*:Enabled:League of Legends Launcher
"6911:UDP" = 6911:UDP:*:Enabled:League of Legends Launcher
"6949:TCP" = 6949:TCP:*:Enabled:League of Legends Launcher
"6949:UDP" = 6949:UDP:*:Enabled:League of Legends Launcher
"8383:TCP" = 8383:TCP:*:Enabled:League of Legends Launcher
"8383:UDP" = 8383:UDP:*:Enabled:League of Legends Launcher
"6931:TCP" = 6931:TCP:*:Enabled:League of Legends Launcher
"6931:UDP" = 6931:UDP:*:Enabled:League of Legends Launcher
"8398:TCP" = 8398:TCP:*:Enabled:League of Legends Launcher
"8398:UDP" = 8398:UDP:*:Enabled:League of Legends Launcher
"58782:TCP" = 58782:TCP:*:Enabled:Pando Media Booster
"58782:UDP" = 58782:UDP:*:Enabled:Pando Media Booster
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"51476:TCP" = 51476:TCP:*:Enabled:hjik
"51476:UDP" = 51476:UDP:*:Enabled:51476
[color=#E56717]========== Authorized Applications List ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Gadu-Gadu\gg.exe" = C:\Program Files\Gadu-Gadu\gg.exe:*:Enabled:Gadu-Gadu - program glowny
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC -- (mIRC Co. Ltd.)
"C:\Gry\EVE\bin\ExeFile.exe" = C:\Gry\EVE\bin\ExeFile.exe:*:Enabled:CCP ExeFile
"C:\Program Files\FlashGet\flashget.exe" = C:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Gry\Heroes of Might and Magic V - Dzikie Hordy\bin\H5_Game.exe" = C:\Gry\Heroes of Might and Magic V - Dzikie Hordy\bin\H5_Game.exe:*:Enabled:Heroes of Might and Magic V - Dzikie Hordy
"C:\Program Files\Hamachi\hamachi.exe" = C:\Program Files\Hamachi\hamachi.exe:*:Enabled:Hamachi
"C:\Gry\Spring\SpringDownloader.exe" = C:\Gry\Spring\SpringDownloader.exe:*:Enabled:SpringDownloader -- (caspring.org)
"C:\Program Files\NX Client for Windows\nxclient.exe" = C:\Program Files\NX Client for Windows\nxclient.exe:*:Enabled:nxclient
"C:\Program Files\NX Client for Windows\bin\nxssh.exe" = C:\Program Files\NX Client for Windows\bin\nxssh.exe:*:Enabled:nxssh
"C:\Gry\Władca Pierścieni® - Podbój™\Conquest.exe" = C:\Gry\Władca Pierścieni® - Podbój™\Conquest.exe:*:Enabled:Game
"C:\Gry\World of Warcraft\WoW-3.0.8.9464-to-3.0.8.9506-enGB-downloader.exe" = C:\Gry\World of Warcraft\WoW-3.0.8.9464-to-3.0.8.9506-enGB-downloader.exe:*:Enabled:Blizzard Downloader
"C:\Program Files\Konnekt\konnekt.exe" = C:\Program Files\Konnekt\konnekt.exe:*:Enabled:Konnekt - Core
"C:\Program Files\Curse\CurseClient.exe" = C:\Program Files\Curse\CurseClient.exe:*:Enabled:Curse Client
"C:\Gry\World of Warcraft\BackgroundDownloader.exe" = C:\Gry\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader
"C:\Gry\World of Warcraft\Launcher.exe" = C:\Gry\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher
"C:\Gry\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe" = C:\Gry\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe:*:Enabled:Blizzard Downloader
"C:\Gry\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe" = C:\Gry\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe:*:Enabled:Blizzard Downloader
"D:\Gry\Warcraft III\Warcraft III.exe" = D:\Gry\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III
"C:\Gry\Warcraft III\Warcraft III.exe" = C:\Gry\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III -- (Blizzard Entertainment)
"D:\Red Alert 3\Data\ra3_1.0.game" = D:\Red Alert 3\Data\ra3_1.0.game:*:Enabled:Command & Conquer™ Red Alert™ 3
"C:\Documents and Settings\Welcome\Pulpit\bullfrog\MatchMaker\identd.exe" = C:\Documents and Settings\Welcome\Pulpit\bullfrog\MatchMaker\identd.exe:*:Enabled:identd
"C:\Documents and Settings\Welcome\Pulpit\bullfrog\bullfrog\MatchMaker\identd.exe" = C:\Documents and Settings\Welcome\Pulpit\bullfrog\bullfrog\MatchMaker\identd.exe:*:Enabled:identd
"C:\Documents and Settings\Welcome\Pulpit\bullfrog\bullfrog\populous\popTB.exe" = C:\Documents and Settings\Welcome\Pulpit\bullfrog\bullfrog\populous\popTB.exe:*:Enabled:D3Ddpop3w
"C:\Documents and Settings\Welcome\Moje dokumenty\OpenLieroX_0.57_beta8.win32\OpenLieroX\OpenLieroX.exe" = C:\Documents and Settings\Welcome\Moje dokumenty\OpenLieroX_0.57_beta8.win32\OpenLieroX\OpenLieroX.exe:*:Enabled:OpenLieroX
"C:\Gry\EA GAMES\Need for Speed Most Wanted\speed.exe" = C:\Gry\EA GAMES\Need for Speed Most Wanted\speed.exe:*:Enabled:speed
"C:\Documents and Settings\Welcome\Pulpit\Command.and.Conquer.Red.Alert.3.Multi4.Full-Rip.Skullptura\Red Alert 3\Data\ra3_1.0.game" = C:\Documents and Settings\Welcome\Pulpit\Command.and.Conquer.Red.Alert.3.Multi4.Full-Rip.Skullptura\Red Alert 3\Data\ra3_1.0.game:*:Enabled:Command & Conquer™ Red Alert™ 3
"C:\Gry\DoW DC\Dawn of War - Dark Crusade\DarkCrusade.exe" = C:\Gry\DoW DC\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Enabled:DarkCrusade
"C:\Gry\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enGB-downloader.exe" = C:\Gry\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enGB-downloader.exe:*:Enabled:Blizzard Downloader
"C:\Gry\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe" = C:\Gry\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe:*:Enabled:Blizzard Downloader
"D:\World of Warcraft Public Test\WoW-0.3.0.10522-enGB-ptr-downloader.exe" = D:\World of Warcraft Public Test\WoW-0.3.0.10522-enGB-ptr-downloader.exe:*:Enabled:Blizzard Downloader
"D:\World of Warcraft Public Test\WoW-0.3.0.10522-to-0.3.0.10554-enGB-ptr-downloader.exe" = D:\World of Warcraft Public Test\WoW-0.3.0.10522-to-0.3.0.10554-enGB-ptr-downloader.exe:*:Enabled:Blizzard Downloader
"D:\World of Warcraft Public Test\Launcher.exe" = D:\World of Warcraft Public Test\Launcher.exe:*:Enabled:Blizzard Launcher
"D:\World of Warcraft Public Test\WoW-0.3.0.10554-to-0.3.0.10571-enGB-ptr-downloader.exe" = D:\World of Warcraft Public Test\WoW-0.3.0.10554-to-0.3.0.10571-enGB-ptr-downloader.exe:*:Enabled:Blizzard Downloader
"D:\World of Warcraft Public Test\WoW-0.3.0.10571-to-0.3.0.10596-enGB-ptr-downloader.exe" = D:\World of Warcraft Public Test\WoW-0.3.0.10571-to-0.3.0.10596-enGB-ptr-downloader.exe:*:Enabled:Blizzard Downloader
"C:\Documents and Settings\Welcome\Dane aplikacji\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" = C:\Documents and Settings\Welcome\Dane aplikacji\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe:*:Enabled:Main program for Octoshape client
"C:\Gry\Ubisoft\Settlers IV - Zlota Edycja\Exe\S4_Main.exe" = C:\Gry\Ubisoft\Settlers IV - Zlota Edycja\Exe\S4_Main.exe:*:Enabled:S4_Main
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"C:\Program Files\Steam\steamapps\teitbite\counter-strike\hl.exe" = C:\Program Files\Steam\steamapps\teitbite\counter-strike\hl.exe:*:Enabled:Counter-Strike -- (Valve)
"C:\Gry\League of Legends\Air\LolClient.exe" = C:\Gry\League of Legends\Air\LolClient.exe:*:Enabled:League of Legends Lobby
"C:\Gry\League of Legends\Game\League of Legends.exe" = C:\Gry\League of Legends\Game\League of Legends.exe:*:Enabled:League of Legends Game Client
"C:\Riot Games\League of Legends\air\LolClient.exe" = C:\Riot Games\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby
"C:\Riot Games\League of Legends\game\League of Legends.exe" = C:\Riot Games\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client
"C:\Gry\League of Legends\lol.launcher.exe" = C:\Gry\League of Legends\lol.launcher.exe:*:Enabled:League of Legends Launcher
"C:\Program Files\PANDORA.TV\PanService\PandoraService.exe" = C:\Program Files\PANDORA.TV\PanService\PandoraService.exe:*:Enabled:PandoraService
"C:\Documents and Settings\Welcome\Dane aplikacji\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Welcome\Dane aplikacji\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- (Dropbox, Inc.)
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{011D1ECA-74C7-429E-B97F-8FF154A0EC19}" = Wiggles
"{035400A4-29BD-3723-BEED-E2718A68CDE0}" = Microsoft Visual Studio 2010 Office Developer Tools (x86)
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0DDCEC37-369C-484B-B16D-B4413FD42FB9}" = Microsoft SQL Server 2008 R2 Data-Tier Application Framework
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{1803A630-3C38-4D2B-9B9A-0CB37243539C}" = Microsoft ASP.NET MVC 2
"{1871FE54-36AA-478F-B374-A46BA54474CC}" = ESET NOD32 Antivirus
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{1BA7B068-4719-42A3-B553-D4ED97434F92}" = ASUS Utilities
"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20
"{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Red Alert™ 3
"{2A2F3AE8-246A-4252-BB26-1BEB45627074}" = Microsoft SQL Server System CLR Types
"{2AFF2951-86B1-3C53-B34D-B440F11E7D0A}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PLK
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{2D9FEBEE-F1B7-344F-BFDF-760E18332D96}" = Microsoft Visual Studio 2010 SharePoint Developer Tools
"{32A3A4F4-B792-11D6-A78A-00B0D0160170}" = Java(TM) SE Development Kit 6 Update 17
"{33AE9E89-47C9-4A0D-9E9D-BDD6966A3804}" = Microsoft SQL Server 2008 RsFx Driver
"{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3BB19A2B-B9C5-3872-8FDF-3047CC9F9841}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40416836-56CC-4C0E-A6AF-5C34BADCE483}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
"{41B31ABE-5A6E-498A-8F28-3BA3B8779A41}" = Dotfuscator Software Services - Community Edition
"{47C39E4A-28F2-33B1-B9B7-97F24E52D917}" = Microsoft Help Viewer 1.0
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{4E968D9C-21A7-4915-B698-F7AEB913541D}" = Microsoft SQL Server 2008 R2 Management Objects
"{4F44B5AE-82A6-4A8A-A3E3-E24D489728E3}" = Microsoft SQL Server 2008 Native Client
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
"{5A0DDC27-88E5-3CAD-BC3D-28FFD05CA6B9}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - PLK
"{5C4ED859-875F-4299-AA2C-E0E393BDCD21}" = ScanSoft PaperPort 11
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A86554B-8928-30E4-A53C-D7337689134D}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319
"{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}" = Brother MFL-Pro Suite DCP-365CN
"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools
"{6ED37A91-7710-3183-BE50-AB043FF6689E}" = Microsoft Team Foundation Server 2010 Object Model - ENU
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{729A3000-BC8A-3B74-BA5D-5068FE12D70C}" = Microsoft Visual F# 2.0 Runtime
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{78C3657E-742C-40B1-9F53-E5A921D40F17}" = Microsoft SQL Server 2008 R2 Transact-SQL Language Service
"{81C6BFED-691E-402A-95DA-F6DE1A351045}" = Nero 8
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90110415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0415-0000-0000000FF1CE}" = Pakiet zgodności dla systemu Office 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97CE8B73-AA5A-4987-A1BE-50DD1A187478}" = Microsoft Sync Framework SDK v1.0 SP1
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.50
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Oprogramowanie systemu PhysX 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{B9CA59A0-3B70-48F8-9054-67595DE6E72B}" = League of Legends
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C6DD625F-4B61-4561-8286-87CA0275CEA1}" = Microsoft Sync Framework Runtime v1.0 SP1 (x86)
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D441BD04-E548-4F8E-97A4-1B66135BAAA8}" = Microsoft SQL Server 2008 Setup Support Files
"{D54640A3-2C2B-4CB1-9666-01E55F54E7F5}" = NCsoft Launcher
"{DC3D6AFB-78B4-489F-81D7-30B66E0C2417}" = Microsoft Sync Services for ADO.NET v2.0 SP1 (x86)
"{E5AE9031-79A5-4627-9641-BEFA82819B08}" = Microsoft SQL Server 2008 R2 Data-Tier Application Project
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F990B526-8F7C-46E0-B1F1-6C893A8B478F}" = Microsoft Sync Framework Services v1.0 SP1 (x86)
"7-Zip" = 7-Zip 4.65
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Avidemux 2.5" = Avidemux 2.5
"CCleaner" = CCleaner
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.30
"ffdshow_is1" = ffdshow [rev 1803] [2008-01-20]
"Foxit Reader" = Foxit Reader
"Gadu-Gadu 10" = Gadu-Gadu 10
"Graphical Enhancement Textures" = Graphical Enhancement Textures 2.5
"ie8" = Windows Internet Explorer 8
"IrfanView" = IrfanView (remove only)
"Knights and Merchants TPR" = Knights and Merchants TPR
"LOLReplay" = LOLReplay
"Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft Team Foundation Server 2010 Object Model - ENU" = Microsoft Team Foundation Server 2010 Object Model - ENU
"Microsoft Visual Studio 2010 Tools for Office Runtime (x86)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools
"mIRC" = mIRC
"Mount&Blade" = Mount&Blade
"Mozilla Firefox (3.6.25)" = Mozilla Firefox (3.6.25)
"NAPIPROJEKT_is1" = NAPIPROJEKT 1.0.6.2
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"oDC" = oDC (remove only)
"Picasa 3" = Picasa 3
"PRJPRO" = Microsoft Office Project Professional 2007
"RealAlt_is1" = Real Alternative 1.7.5
"SkanerOnline" = Skaner on-line mks_vir
"SpeedFan" = SpeedFan (remove only)
"Steam App 10" = Counter-Strike
"SubEdit-Player_is1" = SubEdit-Player
"SystemRequirementsLab" = System Requirements Lab
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Totalcmd" = Total Commander (Remove or Repair)
"uTorrent" = µTorrent
"VeryPDF PDF2Word v3.0_is1" = VeryPDF PDF2Word v3.0
"Virtua Tennis" = Virtua Tennis
"Winamp" = Winamp
"WinRAR archiver" = WinRAR archiver
"X-DVD_Player" = X-DVD_Player
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"xvid" = XviD MPEG-4 Video Codec
[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]
[HKEY_USERS\S-1-5-21-1659004503-1801674531-682003330-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"Dropbox" = Dropbox
"uTorrent" = µTorrent
"Warcraft III" = Warcraft III: wszystkie elementy
"World of Logs Client" = World of Logs Client
[color=#E56717]========== Last 10 Event Log Errors ==========[/color]
[ Application Events ]
Error - 2012-01-11 01:51:01 | Computer Name = PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/01/11 06:51:01.281]: [00001768]: CUsbScnDev: DeviceIoControl
Illegal response
Error - 2012-01-11 01:51:02 | Computer Name = PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/01/11 06:51:02.281]: [00001768]: CUsbScnDev: DeviceIoControl
Illegal response
Error - 2012-01-11 01:51:03 | Computer Name = PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/01/11 06:51:03.281]: [00001768]: CUsbScnDev: DeviceIoControl
Illegal response
Error - 2012-01-11 01:51:04 | Computer Name = PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/01/11 06:51:04.281]: [00001768]: CUsbScnDev: DeviceIoControl
Illegal response
Error - 2012-01-11 01:51:05 | Computer Name = PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/01/11 06:51:05.296]: [00001768]: CUsbScnDev: DeviceIoControl
Illegal response
Error - 2012-01-11 01:51:06 | Computer Name = PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/01/11 06:51:06.296]: [00001768]: CUsbScnDev: DeviceIoControl
Illegal response
Error - 2012-01-11 01:51:07 | Computer Name = PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/01/11 06:51:07.296]: [00001768]: CUsbScnDev: DeviceIoControl
Illegal response
Error - 2012-01-11 01:51:08 | Computer Name = PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/01/11 06:51:08.718]: [00001768]: CUsbScnDev: DeviceIoControl
Illegal response
Error - 2012-01-12 19:25:14 | Computer Name = PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/01/13 00:25:14.859]: [00001768]: CUsbScnDev: DeviceIoControl
Illegal response
Error - 2012-01-29 13:20:39 | Computer Name = PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/01/29 18:20:39.593]: [00000504]: CUsbScnDev: DeviceIoControl
Illegal response
[ System Events ]
Error - 2012-01-27 19:10:41 | Computer Name = PC | Source = Service Control Manager | ID = 7034
Description = Usługa SQL Server (SQLEXPRESS) niespodziewanie zakończyła pracę. Wystąpiło
to razy: 1.
Error - 2012-01-27 19:10:42 | Computer Name = PC | Source = Service Control Manager | ID = 7034
Description = Usługa Windows Presentation Foundation Font Cache 3.0.0.0 niespodziewanie
zakończyła pracę. Wystąpiło to razy: 2.
Error - 2012-01-27 19:10:50 | Computer Name = PC | Source = Service Control Manager | ID = 7034
Description = Usługa NVIDIA Display Driver Service niespodziewanie zakończyła pracę.
Wystąpiło to razy: 1.
Error - 2012-01-28 05:09:20 | Computer Name = PC | Source = Service Control Manager | ID = 7023
Description = Usługa Publikowanie w sieci World Wide Web zakończyła działanie; wystąpił
następujący błąd: %%87
Error - 2012-01-28 05:14:48 | Computer Name = PC | Source = Service Control Manager | ID = 7034
Description = Usługa SQL Server VSS Writer niespodziewanie zakończyła pracę. Wystąpiło
to razy: 1.
Error - 2012-01-28 05:14:49 | Computer Name = PC | Source = Service Control Manager | ID = 7034
Description = Usługa Java Quick Starter niespodziewanie zakończyła pracę. Wystąpiło
to razy: 1.
Error - 2012-01-28 05:14:50 | Computer Name = PC | Source = Service Control Manager | ID = 7034
Description = Usługa NVIDIA Display Driver Service niespodziewanie zakończyła pracę.
Wystąpiło to razy: 1.
Error - 2012-01-28 05:14:52 | Computer Name = PC | Source = Service Control Manager | ID = 7034
Description = Usługa SQL Server (SQLEXPRESS) niespodziewanie zakończyła pracę. Wystąpiło
to razy: 1.
Error - 2012-01-30 17:24:59 | Computer Name = PC | Source = Service Control Manager | ID = 7023
Description = Usługa Publikowanie w sieci World Wide Web zakończyła działanie; wystąpił
następujący błąd: %%87
Error - 2012-01-30 17:27:19 | Computer Name = PC | Source = Service Control Manager | ID = 7023
Description = Usługa Publikowanie w sieci World Wide Web zakończyła działanie; wystąpił
następujący błąd: %%87
< End of report >
- Kod: Zaznacz wszystko
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-31 09:16:11
Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-10 ST3500630AS rev.3.AAK
Running: e4b2gj6p.exe; Driver: C:\DOCUME~1\Welcome\USTAWI~1\Temp\pxtdapow.sys
---- System - GMER 1.0.15 ----
SSDT 894CCC90 ZwAssignProcessToJobObject
SSDT 894CD200 ZwDebugActiveProcess
SSDT 894CD2F0 ZwDuplicateObject
SSDT 894CC590 ZwOpenProcess
SSDT 894CC800 ZwOpenThread
SSDT 894CCFD0 ZwProtectVirtualMemory
SSDT 894CD0E0 ZwQueueApcThread
SSDT 894CCEC0 ZwSetContextThread
SSDT 894CCD90 ZwSetInformationThread
SSDT 894C9DA0 ZwSetSecurityObject
SSDT 894CCB90 ZwSuspendProcess
SSDT 894CCA80 ZwSuspendThread
SSDT 894CC6E0 ZwTerminateProcess
SSDT 894CCA50 ZwTerminateThread
SSDT 894CD6D0 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB69E93A0, 0x5FE082, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xB185C300, 0x3AF78, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xB34D6300, 0x1BCE, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[448] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 4 Bytes [C2, 04, 00, 00]
.text C:\Program Files\Mozilla Firefox\firefox.exe[2420] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0040131F C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x23 0xAC 0xEE 0xE8 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x6D 0x3C 0x77 0xF3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xB5 0x74 0x04 0x47 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x23 0xAC 0xEE 0xE8 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x6D 0x3C 0x77 0xF3 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xB5 0x74 0x04 0x47 ...
---- EOF - GMER 1.0.15 ----