przez radek3345 21 Sty 2010, 17:14
Oto mój log chciałbym się spytać jak usunąć plik raw32 wiem ze to jest wirus tylko jak go usunąć
- Kod: Zaznacz wszystko
OTL logfile created on: 2010-01-21 16:03:32 - Run 1
OTL by OldTimer - Version 3.1.25.3 Folder = D:\inne
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 52,00% Memory free
6,00 Gb Paging File | 4,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 30,00 Gb Total Space | 2,68 Gb Free Space | 8,94% Space Free | Partition Type: NTFS
Drive D: | 266,08 Gb Total Space | 265,93 Gb Free Space | 99,95% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 964,10 Mb Total Space | 841,77 Mb Free Space | 87,31% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TOMEK-PC
Current User Name: Kempanowski
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2010-01-21 16:01:52 | 00,547,840 | ---- | M] (OldTimer Tools) -- D:\inne\OTL.exe
PRC - [2010-01-14 21:20:46 | 00,058,744 | ---- | M] () -- C:\ProgramData\QuestService\questservice135.exe
PRC - [2010-01-14 21:20:46 | 00,058,744 | ---- | M] () -- C:\Program Files\QuestService\questservice.exe
PRC - [2010-01-07 13:53:03 | 00,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-12-16 15:52:42 | 04,288,512 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\Program Files\SiS VGA Utilities\SiS.exe
PRC - [2009-12-14 17:48:28 | 00,053,248 | ---- | M] (Google Inc) -- C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\GoogleUpdateBeta.exe
PRC - [2009-12-08 19:13:02 | 00,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\REALSCHED.EXE
PRC - [2009-12-07 15:47:38 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\JUSCHED.EXE
PRC - [2009-12-02 18:53:44 | 11,833,960 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe
PRC - [2009-12-02 17:39:46 | 00,077,824 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\spellchecker_gg.exe
PRC - [2009-11-16 09:04:30 | 00,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2009-11-16 09:03:32 | 02,054,360 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2009-10-29 12:27:54 | 01,074,568 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2009-09-10 16:21:05 | 00,168,960 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmplayer.exe
PRC - [2009-07-29 15:52:10 | 01,024,512 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Dealio Toolbar\SearchSettings.exe
PRC - [2009-07-13 20:52:22 | 00,103,736 | ---- | M] () -- C:\Windows\System32\PnkBstrB.exe
PRC - [2009-07-13 20:52:16 | 00,066,872 | ---- | M] () -- C:\Windows\System32\PnkBstrA.exe
PRC - [2008-10-29 07:29:41 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008-02-29 22:13:12 | 00,307,200 | ---- | M] (Fujitsu Siemens Computers) -- C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
PRC - [2008-01-21 03:35:20 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2008-01-21 03:34:48 | 00,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WUDFHost.exe
PRC - [2008-01-21 03:33:00 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007-08-15 01:41:54 | 00,650,752 | ---- | M] (ITE Tech Inc.) -- C:\Program Files\FSC\Wireless Utility\WIRELESSSELECTOR.EXE
PRC - [2007-08-13 13:47:38 | 00,364,544 | ---- | M] () -- C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe
PRC - [2007-08-09 18:26:42 | 04,702,208 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007-05-10 18:48:50 | 00,869,936 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2006-11-03 10:01:16 | 00,319,488 | ---- | M] (PixArt Imaging Incorporation) -- C:\Windows\PixArt\PAC207\Monitor.exe
PRC - [2002-07-18 12:28:50 | 00,868,352 | ---- | M] (Fourelle Systems, Inc) -- C:\Program Files\Venturi2\Client\VentC.exe
[color=#E56717]========== Modules (SafeList) ==========[/color]
MOD - [2010-01-21 16:01:52 | 00,547,840 | ---- | M] (OldTimer Tools) -- D:\inne\OTL.exe
MOD - [2010-01-14 21:20:30 | 00,598,016 | ---- | M] () -- C:\Program Files\QuestService\questservice.dll
MOD - [2008-01-21 03:33:14 | 01,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - File not found [Auto | Stopped] -- -- (TOSHIBA Bluetooth Service)
SRV - File not found [Auto | Stopped] -- -- (gupdate1ca7831eb12e058) Usługa Google Update (gupdate1ca7831eb12e058)
SRV - File not found [On_Demand | Stopped] -- -- (avast! Web Scanner)
SRV - File not found [On_Demand | Stopped] -- -- (avast! Mail Scanner)
SRV - File not found [Auto | Stopped] -- -- (avast! Antivirus)
SRV - File not found [Auto | Stopped] -- -- (aswUpdSv)
SRV - [2010-01-14 21:20:46 | 00,058,744 | ---- | M] () [Auto | Running] -- C:\ProgramData\QuestService\questservice135.exe -- (QuestService Service)
SRV - [2010-01-07 18:26:51 | 02,431,024 | ---- | M] () [Auto | Running] -- C:/Program Files/Common Files/Akamai/rswin_3629.dll -- (Akamai)
SRV - [2009-12-14 17:48:28 | 00,053,248 | ---- | M] (Google Inc) [Auto | Running] -- C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\GoogleUpdateBeta.exe -- (GoogleUpdateBeta)
SRV - [2009-11-16 09:12:54 | 00,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009-11-16 09:04:30 | 00,735,960 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2009-10-29 12:27:54 | 01,074,568 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2009-08-24 13:16:12 | 00,378,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2009-07-13 20:52:22 | 00,103,736 | ---- | M] () [Auto | Running] -- C:\Windows\System32\PnkBstrB.exe -- (PnkBstrB)
SRV - [2009-07-13 20:52:16 | 00,066,872 | ---- | M] () [Auto | Running] -- C:\Windows\System32\PnkBstrA.exe -- (PnkBstrA)
SRV - [2009-06-02 09:10:08 | 00,637,952 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008-11-04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008-02-29 22:13:12 | 00,307,200 | ---- | M] (Fujitsu Siemens Computers) [Auto | Running] -- C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe -- (TestHandler)
SRV - [2008-01-21 03:33:00 | 00,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2006-10-26 22:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2002-07-18 12:28:50 | 00,868,352 | ---- | M] (Fourelle Systems, Inc) [Auto | Running] -- C:\Program Files\Venturi2\Client\VentC.exe -- (Venturi2)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2009-12-26 15:43:13 | 00,005,632 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009-12-18 15:02:26 | 00,095,896 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV - [2009-12-16 15:45:58 | 00,465,920 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SISGRKMD.sys -- (SiS6350)
DRV - [2009-11-16 09:03:36 | 00,108,792 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009-11-16 08:56:12 | 00,116,520 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\System32\drivers\eamon.sys -- (eamon)
DRV - [2009-09-23 09:41:58 | 00,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2009-08-11 20:37:23 | 00,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008-08-26 09:26:12 | 00,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008-05-16 00:20:32 | 00,078,416 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2008-05-16 00:18:00 | 00,050,768 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2008-05-16 00:16:06 | 00,020,560 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2008-05-16 00:15:29 | 00,023,152 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2008-05-16 00:14:11 | 00,042,912 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2008-04-23 11:21:08 | 00,058,416 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\SISAGPX.sys -- (SISAGP)
DRV - [2008-01-21 03:32:53 | 00,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2008-01-21 03:32:53 | 00,031,288 | ---- | M] (LSI Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2008-01-21 03:32:52 | 00,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)
DRV - [2008-01-21 03:32:52 | 00,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2008-01-21 03:32:52 | 00,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2008-01-21 03:32:52 | 00,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2008-01-21 03:32:51 | 00,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2008-01-21 03:32:51 | 00,089,656 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2008-01-21 03:32:50 | 01,122,360 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2008-01-21 03:32:50 | 00,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)
DRV - [2008-01-21 03:32:50 | 00,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2008-01-21 03:32:49 | 00,235,064 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2008-01-21 03:32:49 | 00,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2008-01-21 03:32:49 | 00,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2008-01-21 03:32:49 | 00,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2008-01-21 03:32:49 | 00,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2008-01-21 03:32:48 | 00,342,584 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2008-01-21 03:32:48 | 00,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2008-01-21 03:32:47 | 00,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2008-01-21 03:32:47 | 00,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2008-01-21 03:32:46 | 00,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2008-01-21 03:32:45 | 00,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2008-01-21 03:32:44 | 00,179,712 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2008-01-21 03:32:21 | 00,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2008-01-21 03:32:21 | 00,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2008-01-21 03:32:21 | 00,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007-08-10 12:49:16 | 01,941,848 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007-07-30 02:00:56 | 00,014,168 | ---- | M] (Zeal SoftStudio) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\zntport.sys -- (zntport)
DRV - [2007-07-04 10:04:54 | 00,047,616 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SiSGB6.sys -- (SiSGbeLH)
DRV - [2007-06-19 11:04:48 | 00,737,280 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2007-05-10 18:48:56 | 00,187,320 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
DRV - [2007-05-09 08:57:18 | 00,035,328 | ---- | M] (CACE Technologies) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\WPXT.sys -- (WPXT) WinPcap Packet Driver (WPXT)
DRV - [2007-05-02 11:12:36 | 00,109,704 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssm_mdm.sys -- (ssm_mdm)
DRV - [2007-05-02 11:12:36 | 00,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssm_mdfl.sys -- (ssm_mdfl)
DRV - [2007-05-02 11:12:34 | 00,083,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssm_bus.sys -- (ssm_bus) SAMSUNG Mobile USB Device II 1.0 driver (WDM)
DRV - [2007-05-02 11:11:18 | 00,109,704 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_mdm.sys -- (ss_mdm)
DRV - [2007-05-02 11:11:18 | 00,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV - [2007-05-02 11:11:16 | 00,083,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bus.sys -- (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM)
DRV - [2007-04-24 10:33:46 | 00,100,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125mgmt.sys -- (s125mgmt) Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM)
DRV - [2007-04-24 10:33:46 | 00,098,696 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125obex.sys -- (s125obex)
DRV - [2007-04-24 10:33:44 | 00,108,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125mdm.sys -- (s125mdm)
DRV - [2007-04-24 10:33:42 | 00,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125mdfl.sys -- (s125mdfl)
DRV - [2007-04-24 10:33:34 | 00,083,336 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125bus.sys -- (s125bus) Sony Ericsson Device 125 driver (WDM)
DRV - [2007-01-04 13:48:04 | 00,104,344 | ---- | M] (Analog Devices Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e4usbaw.sys -- (e4usbaw)
DRV - [2007-01-04 13:47:48 | 00,069,656 | ---- | M] (Analog Deivces) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\e4ldr.sys -- (E4LOADER) General Purpose USB Driver (e4ldr.sys)
DRV - [2006-12-05 10:34:42 | 00,507,136 | ---- | M] (PixArt Imaging Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PFC027.SYS -- (PAC207)
DRV - [2006-11-02 10:50:35 | 00,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006-11-02 10:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006-11-02 10:50:19 | 00,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006-11-02 10:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006-11-02 10:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006-11-02 10:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006-11-02 10:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006-11-02 10:50:05 | 00,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006-11-02 10:50:03 | 00,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006-11-02 10:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006-11-02 10:49:56 | 00,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006-11-02 09:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006-11-02 09:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006-11-02 09:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006-11-02 09:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006-11-02 09:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006-11-02 09:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006-11-02 08:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006-11-02 07:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv)
DRV - [2006-10-19 03:10:57 | 01,380,864 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\igdkmd32.sys -- (ialm)
DRV - [2005-02-23 13:58:56 | 00,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\afc.sys -- (Afc)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.fujitsu-siemens.com/index2
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFree.dll (Conduit Ltd.)
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.fujitsu-siemens.com/index2
IE - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/ie
IE - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.theprizeday.com/today.php
IE - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Dealio Toolbar\SearchSettings.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001\S-1-5-21-2791711727-1804065476-1678765446-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=966134"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://pl.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:pl:official"
FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.1
FF - prefs.js..extensions.enabledItems: {E63605FC-D583-4C81-867F-9457BDB3EA1B}:3.1.0.1840
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=966134&p="
FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: D:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
FF - HKLM\software\mozilla\Firefox\Extensions\\{40f1eb95-4de4-4f36-a826-054ee36bb905}: C:\Program Files\Gameztar Toolbar\2.1.1.5750\FFToolbar
FF - HKLM\software\mozilla\Firefox\Extensions\\{E63605FC-D583-4C81-867F-9457BDB3EA1B}: C:\Program Files\Web Search Operator\3.1.0.1840\FF [2009-12-06 21:36:19 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{8141440E-08F0-4339-9959-5C31C6A69F23}: C:\Program Files\Automated Content Enhancer\4.1.0.5190\FF [2009-12-06 21:36:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{E889F097-B0BE-471B-89AD-B86B6F04B506}: C:\Program Files\Customized Platform Advancer\4.1.0.1800\FF [2009-12-06 21:36:45 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-01-07 13:53:04 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-01-07 13:53:04 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010-01-20 22:48:07 | 00,000,000 | ---D | M]
[2009-12-10 13:21:19 | 00,000,000 | ---D | M] -- C:\Users\Kempanowski\AppData\Roaming\mozilla\Extensions
[2010-01-21 13:26:21 | 00,000,000 | ---D | M] -- C:\Users\Kempanowski\AppData\Roaming\mozilla\Firefox\Profiles\uc4ximt3.default\extensions
[2009-12-10 13:24:40 | 00,000,000 | ---D | M] (Firefox Showcase) -- C:\Users\Kempanowski\AppData\Roaming\mozilla\Firefox\Profiles\uc4ximt3.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2010-01-16 18:40:34 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009-12-09 13:55:06 | 00,000,000 | ---D | M] (Dealio Toolbar Plugin) -- C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
[2010-01-16 18:40:34 | 00,000,000 | ---D | M] (QuestService) -- C:\Program Files\Mozilla Firefox\extensions\{F2DDDB92-1605-4260-9B25-45A4DAE87B50}
[2009-12-09 13:55:07 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
[2009-07-17 09:40:12 | 00,704,512 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2009-12-01 19:40:43 | 00,238,776 | ---- | M] (Pando Networks) -- C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
[2009-11-03 02:54:10 | 00,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2009-11-03 02:54:10 | 00,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2009-11-03 02:54:10 | 00,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2009-11-03 02:54:10 | 00,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2010-01-16 18:40:34 | 00,002,405 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\questservice135.xml
[2009-11-03 02:54:10 | 00,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2009-11-03 02:54:10 | 00,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml
O1 HOSTS File: ([2006-09-18 22:41:30 | 00,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Dealio Toolbar) - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Automated Content Enhancer) - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - C:\Program Files\Automated Content Enhancer\4.1.0.5190\ACEIEAddOn.dll ()
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (My Global Search Bar BHO) - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL File not found
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll File not found
O2 - BHO: (Customized Platform Advancer) - {42C7C39F-3128-4a17-BDB7-91C46032B5B9} - C:\Program Files\Customized Platform Advancer\4.1.0.1800\CPAIEAddOn.dll ()
O2 - BHO: (Free Lunch Design Toolbar) - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFree.dll (Conduit Ltd.)
O2 - BHO: (UrlHelper Class) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare\BearShareIEHelper.dll File not found
O2 - BHO: (Content Management Wizard) - {B72681C0-A222-4b21-A0E2-53A5A5CA3D41} - C:\Program Files\Content Management Wizard\1.1.0.1870\CMWIE.dll ()
O2 - BHO: (TCP) - {CAC89FF9-34A9-4431-8CFE-292A47F843BC} - C:\Program Files\Textual Content Provider\1.1.0.1610\TCPIE.dll ()
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Dealio Toolbar\SearchSettings.dll (Spigot, Inc.)
O2 - BHO: (Web Search Operator) - {EB4A577D-BCAD-4b1c-8AF2-9A74B8DD3431} - C:\Program Files\Web Search Operator\3.1.0.1840\WSO.dll ()
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Users\Kempanowski\AppData\Roaming\Gadu-Gadu 10\_userdata\ggbho.2.dll (GG Network S.A.)
O3 - HKLM\..\Toolbar: (Dealio Toolbar) - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll File not found
O3 - HKLM\..\Toolbar: (My Global Search Bar) - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL File not found
O3 - HKLM\..\Toolbar: (Free Lunch Design Toolbar) - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFree.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll File not found
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Gameztar Toolbar) - {D45817B8-3EAD-4d1d-8FCA-EC63A8E35DE2} - C:\Program Files\Gameztar Toolbar\2.1.1.5750\mvb0.dll File not found
O3 - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001\..\Toolbar\WebBrowser: (Free Lunch Design Toolbar) - {57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC} - C:\Program Files\Free_Lunch_Design\tbFree.dll (Conduit Ltd.)
O4 - HKLM..\Run: [adiras] C:\Windows\ADIRAS.EXE ()
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe File not found
O4 - HKLM..\Run: [avast!] d:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe File not found
O4 - HKLM..\Run: [BearShare] C:\Program Files\BearShare\BearShare.exe File not found
O4 - HKLM..\Run: [dki] c:\tst.com File not found
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [InstalkiLite] C:\Program Files\INSTALKI.pl\InstalkiLite\InstalkiLite.exe File not found
O4 - HKLM..\Run: [Internet Today Task] C:\Program Files\Internet Today\1.1.0.1190\InternetToday.exe File not found
O4 - HKLM..\Run: [Microsoft Shell Execute] C:\WINDOWS\isass.exe File not found
O4 - HKLM..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [RegistryMonitor1] C:\Windows\System32\qtplugin.exe File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Dealio Toolbar\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [SiSTray] C:\Program Files\SiS VGA Utilities\SiSTray.exe (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TouchPadHotKey] C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe ()
O4 - HKLM..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [cbssreg] C:\Windows\TEMP\kxaa.tmp\svchost.exe File not found
O4 - HKU\S-1-5-18..\Run: [cbssreg] C:\Windows\TEMP\kxaa.tmp\svchost.exe File not found
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.)
O4 - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001..\Run: [svhost] C:\Windows\System32\svhost.exe File not found
O4 - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\nye22.dll ()
O4 - Startup: C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\raw32.dll ()
O4 - Startup: C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\raw32.exe ()
O4 - Startup: C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SCVHOST.EXE ()
O4 - Startup: C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\smgr32.exe ()
O4 - Startup: C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\smgr34.exe ()
O4 - Startup: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\nye22.dll ()
O4 - Startup: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\scvhost.exe ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2791711727-1804065476-1678765446-1001_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - D:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LogonInit: DllName - logonInit.dll - C:\Program Files\Common Files\logonInit.dll ()
O24 - Desktop WallPaper: C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg
O24 - Desktop BackupWallPaper: C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-09-18 22:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - Unable to obtain root file information for disk G:\
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2010-01-21 14:12:39 | 00,000,000 | ---D | C] -- C:\Program Files\Tibia 8.54
[2010-01-21 13:55:47 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\Desktop\Muza 2010
[2010-01-21 00:32:59 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\AppData\Roaming\gtk-2.0
[2010-01-21 00:32:53 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\.thumbnails
[2010-01-21 00:30:36 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\Documents\gegl-0.0
[2010-01-21 00:30:36 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\.gimp-2.6
[2010-01-21 00:29:09 | 00,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2010-01-21 00:16:01 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010-01-20 22:48:35 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\AppData\Local\ESET
[2010-01-20 22:48:05 | 00,000,000 | ---D | C] -- C:\Program Files\ESET
[2010-01-20 16:40:23 | 00,306,688 | ---- | C] (InstallShield Software Corporation) -- C:\Windows\IsUninst.exe
[2010-01-20 16:05:43 | 00,006,656 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\Windows\System32\SiSApi.dll
[2010-01-20 11:09:45 | 00,000,000 | ---D | C] -- C:\Program Files\SiS VGA Utilities
[2010-01-19 14:20:45 | 04,080,128 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\Windows\System32\SiSGlv.dll
[2010-01-19 14:20:45 | 03,653,120 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\Windows\System32\SISGRUMD.dll
[2010-01-19 14:20:45 | 00,655,360 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\Windows\System32\SiSClone.dll
[2010-01-19 14:20:45 | 00,465,920 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\Windows\System32\drivers\SISGRKMD.sys
[2010-01-19 14:20:45 | 00,212,992 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\Windows\System32\SiSFunc.dll
[2010-01-19 14:20:45 | 00,006,656 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\Windows\System32\SiSCo.dll
[2010-01-19 14:20:45 | 00,005,632 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\Windows\System32\SiSKrl.dll
[2010-01-19 13:12:46 | 00,058,416 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\Windows\System32\drivers\SISAGPX.SYS
[2010-01-14 20:06:40 | 00,000,000 | ---D | C] -- C:\Program Files\No-IP
[2010-01-13 17:19:30 | 00,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll
[2010-01-13 17:19:30 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2010-01-08 15:54:53 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\AppData\Local\LogMeIn Hamachi
[2010-01-08 15:53:08 | 00,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi
[2010-01-07 18:26:29 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Akamai
[2010-01-07 15:45:11 | 00,000,000 | ---D | C] -- C:\Program Files\Metin2_PL
[2010-01-06 18:56:16 | 00,000,000 | ---D | C] -- C:\Program Files\Audacity
[2009-12-31 15:04:26 | 00,000,000 | ---D | C] -- C:\Program Files\Password Spyer 2k
[2009-12-31 14:14:23 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2009-12-31 14:11:54 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\AppData\Local\NOS
[2009-12-31 11:08:26 | 00,000,000 | ---D | C] -- C:\Program Files\Asprate
[2009-12-31 00:55:12 | 00,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2009-12-30 20:18:38 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\Documents\Pobieranie
[2009-12-29 17:54:10 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\AppData\Roaming\Search Settings
[2009-12-29 17:54:08 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\AppData\Local\Customized Platform Advancer
[2009-12-29 17:54:08 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\AppData\Local\Automated Content Enhancer
[2009-12-29 11:47:16 | 00,000,000 | ---D | C] -- C:\Program Files\KeyFinder
[2009-12-28 21:28:48 | 00,000,000 | ---D | C] -- C:\Windows\System32\Tools
[2009-12-28 21:28:48 | 00,000,000 | ---D | C] -- C:\Windows\System32\Doc
[2009-12-28 21:28:46 | 00,000,000 | ---D | C] -- C:\Windows\System32\tcl
[2009-12-28 21:28:46 | 00,000,000 | ---D | C] -- C:\Windows\System32\libs
[2009-12-28 21:28:46 | 00,000,000 | ---D | C] -- C:\Windows\System32\include
[2009-12-28 21:28:45 | 00,000,000 | ---D | C] -- C:\Windows\System32\DLLs
[2009-12-28 21:28:40 | 00,000,000 | ---D | C] -- C:\Windows\System32\Lib
[2009-12-28 21:25:25 | 00,000,000 | ---D | C] -- C:\Program Files\Tibia Auto
[2009-12-26 15:48:51 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\Documents\My Art
[2009-12-26 15:47:49 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\AppData\Roaming\Samsung
[2009-12-26 15:40:53 | 00,000,000 | ---D | C] -- C:\Users\Kempanowski\AppData\Local\Silver_Squirrel_Software_
[1 C:\*.tmp files -> C:\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2010-01-21 16:10:00 | 00,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{8EAB2DAE-28F0-4ECD-978F-0EF278F34D3E}.job
[2010-01-21 16:09:11 | 01,835,008 | -HS- | M] () -- C:\Users\Kempanowski\NTUSER.DAT
[2010-01-21 15:31:40 | 00,004,603 | ---- | M] () -- C:\Users\Kempanowski\Desktop\images.jpg
[2010-01-21 15:28:22 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010-01-21 15:04:41 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010-01-21 15:04:41 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010-01-21 14:23:00 | 00,001,036 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010-01-21 14:13:10 | 00,000,825 | ---- | M] () -- C:\Users\Public\Desktop\Tibia.lnk
[2010-01-21 13:06:27 | 00,000,430 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{A462846B-17FB-429B-BA37-25D3DDF2646C}.job
[2010-01-21 13:04:55 | 00,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010-01-21 08:11:01 | 01,477,664 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010-01-21 08:11:01 | 00,665,404 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2010-01-21 08:11:01 | 00,590,082 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010-01-21 08:11:01 | 00,128,164 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2010-01-21 08:11:01 | 00,102,094 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010-01-21 08:03:33 | 00,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2010-01-21 08:03:19 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010-01-21 08:02:55 | 29,477,47840 | -HS- | M] () -- C:\hiberfil.sys
[2010-01-21 08:02:53 | 32,296,0249 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010-01-21 00:47:30 | 00,003,324 | ---- | M] () -- C:\Users\Kempanowski\.recently-used.xbel
[2010-01-21 00:30:31 | 00,000,904 | ---- | M] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2010-01-21 00:04:13 | 00,524,288 | -HS- | M] () -- C:\Users\Kempanowski\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms
[2010-01-21 00:04:13 | 00,065,536 | -HS- | M] () -- C:\Users\Kempanowski\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf
[2010-01-20 18:46:07 | 00,000,680 | ---- | M] () -- C:\Users\Kempanowski\AppData\Local\d3d9caps.dat
[2010-01-20 17:59:59 | 00,000,474 | ---- | M] () -- C:\Windows\tasks\Norton Security Scan for Tomek.job
[2010-01-20 11:41:52 | 00,099,864 | ---- | M] () -- C:\Users\Kempanowski\AppData\Local\GDIPFONTCACHEV1.DAT
[2010-01-20 11:16:41 | 00,369,064 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010-01-14 11:12:06 | 00,181,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010-01-12 03:01:51 | 00,000,492 | ---- | M] () -- C:\Windows\win.ini
[2010-01-05 18:05:50 | 00,000,157 | ---- | M] () -- C:\whx.bat
[2010-01-05 17:36:57 | 00,011,264 | ---- | M] () -- C:\Users\Kempanowski\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-01-01 14:50:42 | 00,000,000 | ---- | M] () -- C:\ProgramData\LauncherAccess.dt
[2009-12-31 11:08:34 | 00,020,992 | ---- | M] () -- C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\raw32.exe
[2009-12-31 11:08:28 | 00,001,984 | ---- | M] () -- C:\Users\Public\Desktop\Tibia MULTI-IP Changer.lnk
[2009-12-29 21:06:14 | 00,027,958 | ---- | M] () -- C:\Program Files\Common Files\logonInit.dll
[2009-12-28 22:18:52 | 00,037,888 | -HS- | M] () -- C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\raw32.dll
[2009-12-27 16:16:18 | 02,148,795 | -H-- | M] () -- C:\Users\Kempanowski\AppData\Local\IconCache.db
[2009-12-26 15:43:13 | 00,005,632 | ---- | M] () -- C:\Windows\System32\drivers\StarOpen.sys
[1 C:\*.tmp files -> C:\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2010-01-21 15:31:39 | 00,004,603 | ---- | C] () -- C:\Users\Kempanowski\Desktop\images.jpg
[2010-01-21 15:07:57 | 00,988,160 | ---- | C] () -- C:\Users\Kempanowski\Desktop\FindIt.exe
[2010-01-21 14:12:43 | 00,000,825 | ---- | C] () -- C:\Users\Public\Desktop\Tibia.lnk
[2010-01-21 00:47:30 | 00,003,324 | ---- | C] () -- C:\Users\Kempanowski\.recently-used.xbel
[2010-01-21 00:30:31 | 00,000,904 | ---- | C] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2010-01-20 18:46:07 | 00,000,680 | ---- | C] () -- C:\Users\Kempanowski\AppData\Local\d3d9caps.dat
[2010-01-17 01:58:07 | 32,296,0249 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010-01-15 15:05:09 | 00,039,424 | ---- | C] () -- C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\smgr34.exe
[2010-01-15 15:05:09 | 00,039,424 | ---- | C] () -- C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\smgr32.exe
[2010-01-05 18:05:50 | 00,000,157 | ---- | C] () -- C:\whx.bat
[2009-12-31 11:08:34 | 00,037,888 | -HS- | C] () -- C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\raw32.dll
[2009-12-31 11:08:34 | 00,020,992 | ---- | C] () -- C:\Users\Kempanowski\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\raw32.exe
[2009-12-31 11:08:28 | 00,001,984 | ---- | C] () -- C:\Users\Public\Desktop\Tibia MULTI-IP Changer.lnk
[2009-12-29 21:06:14 | 00,027,958 | ---- | C] () -- C:\Program Files\Common Files\logonInit.dll
[2009-12-25 18:34:35 | 00,011,264 | ---- | C] () -- C:\Users\Kempanowski\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-11-27 18:01:09 | 00,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2009-11-27 17:30:49 | 00,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2009-11-23 16:58:30 | 00,000,168 | ---- | C] () -- C:\Windows\adidsl.ini
[2009-11-23 16:58:30 | 00,000,021 | ---- | C] () -- C:\Windows\Fast800.ini
[2009-11-23 16:53:29 | 00,001,094 | ---- | C] () -- C:\Windows\adiras.ini
[2009-11-23 16:53:25 | 00,046,892 | ---- | C] () -- C:\Windows\System32\ADADIX16.DLL
[2009-11-23 14:01:44 | 00,000,232 | ---- | C] () -- C:\Windows\wininit.ini
[2009-11-23 14:00:34 | 00,000,100 | ---- | C] () -- C:\Windows\Kit.ini
[2009-08-25 12:47:57 | 00,000,399 | ---- | C] () -- C:\Windows\System32\Remover.ini
[2009-08-18 21:02:27 | 00,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009-08-11 20:37:23 | 00,721,904 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2009-07-13 20:52:33 | 00,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2009-07-13 20:52:13 | 00,000,261 | ---- | C] () -- C:\Windows\game.ini
[2009-06-19 15:53:48 | 00,154,624 | ---- | C] () -- C:\Windows\System32\zlib4.dll
[2009-06-17 08:11:25 | 00,000,055 | ---- | C] () -- C:\Windows\System32\VGAunistlog.ini
[2008-11-26 07:55:02 | 00,324,376 | ---- | C] () -- C:\Windows\System32\PhysXCplUI.exe
[2008-10-22 08:23:25 | 01,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008-10-07 08:13:30 | 00,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008-10-07 08:13:22 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008-10-07 08:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008-10-07 08:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008-10-07 08:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008-10-07 08:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008-10-07 08:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008-10-07 08:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008-10-07 08:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008-10-07 08:13:20 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008-05-08 10:04:07 | 00,040,448 | ---- | C] () -- C:\Windows\REGOBJ.DLL
[2008-02-29 22:13:14 | 00,012,288 | ---- | C] () -- C:\Windows\System32\EvOnlDiag.dll
[2006-11-02 11:25:21 | 00,061,440 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2006-11-02 08:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006-11-02 08:27:46 | 00,000,518 | ---- | C] () -- C:\Windows\System32\SP207.INI
< End of report >
Ostatnio edytowany przez
radek3345, 21 Sty 2010, 19:36, edytowano w sumie 1 raz