
c:\documents and settings\admin\dipetozo.exe
c:\windows\system32\actskn45.ocx
ten drugi skasowałem ręcznie bo gdzieś tak wyczytałem

- Kod: Zaznacz wszystko
OTListIt logfile created on: 2009-05-27 18:47:04 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\admin\Pulpit
Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
447.48 Mb Total Physical Memory | 115.10 Mb Available Physical Memory | 25.72% Memory free
1.03 Gb Paging File | 0.61 Gb Available in Paging File | 59.46% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 22.07 Gb Free Space | 75.33% Space Free | Partition Type: NTFS
Drive D: | 39.06 Gb Total Space | 36.95 Gb Free Space | 94.60% Space Free | Partition Type: NTFS
Drive E: | 6.15 Gb Total Space | 6.15 Gb Free Space | 99.97% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: XPN33
Current User Name: admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
[color=orange]========== Processes (SafeList) ==========[/color]
PRC - [2008-04-14 19:21:16 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2009-04-14 12:52:58 | 00,086,016 | ---- | M] (alch) -- C:\Program Files\ClamWin\bin\ClamTray.exe
PRC - [2009-04-10 19:29:08 | 00,037,888 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe
PRC - [2005-10-26 16:17:24 | 00,159,744 | R--- | M] (Sony Ericsson Mobile Communications AB) -- C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
PRC - [2009-05-27 15:34:27 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2003-10-15 16:24:34 | 00,165,888 | ---- | M] () -- C:\Documents and Settings\admin\Dipetozo.exe
PRC - [2009-05-27 15:34:26 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2006-10-31 08:35:00 | 00,155,715 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe
PRC - [2005-06-08 16:45:04 | 00,278,528 | ---- | M] (Teleca Software Solutions AB) -- C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
PRC - [2005-08-10 07:54:34 | 00,385,024 | R--- | M] (Teleca Software Solutions) -- C:\Program Files\Common Files\Teleca Shared\Generic.exe
PRC - [2006-02-24 11:58:14 | 00,868,352 | R--- | M] (Sony Ericsson Mobile Communications AB) -- C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
PRC - [2008-04-14 19:21:50 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe
PRC - [2009-04-24 11:54:23 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-02-06 12:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
PRC - [2009-05-27 17:49:05 | 01,005,904 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2006-03-02 14:00:00 | 00,016,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\unsecapp.exe
PRC - [2009-05-27 17:49:06 | 00,518,488 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2009-05-27 18:46:46 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\admin\Pulpit\OTListIt2.exe
[color=orange]========== Win32 Services (SafeList) ==========[/color]
SRV - File not found -- -- (gusvc [Disabled | Stopped])
SRV - [2008-04-14 19:20:44 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2009-05-27 15:34:26 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2009-05-27 17:49:05 | 01,005,904 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service [On_Demand | Running])
SRV - [2006-10-31 08:35:00 | 00,155,715 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Auto | Running])
[color=orange]========== Driver Services (SafeList) ==========[/color]
DRV - [2006-06-18 23:51:32 | 00,043,520 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\DRIVERS\AmdK8.sys -- (AmdK8 [System | Running])
DRV - [2008-09-04 13:09:24 | 00,014,656 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\gdrv.sys -- (gdrv [On_Demand | Stopped])
DRV - [2008-04-13 18:36:05 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2007-01-30 12:57:50 | 04,474,368 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2005-06-03 13:46:52 | 00,055,216 | R--- | M] (MCCI) -- C:\WINDOWS\system32\DRIVERS\k750bus.sys -- (k750bus [On_Demand | Stopped])
DRV - [2005-06-03 13:46:58 | 00,006,576 | R--- | M] (MCCI) -- C:\WINDOWS\system32\DRIVERS\k750mdfl.sys -- (k750mdfl [On_Demand | Stopped])
DRV - [2005-06-03 13:47:00 | 00,089,872 | R--- | M] (MCCI) -- C:\WINDOWS\system32\DRIVERS\k750mdm.sys -- (k750mdm [On_Demand | Stopped])
DRV - [2005-06-03 13:47:04 | 00,081,728 | R--- | M] (MCCI) -- C:\WINDOWS\system32\DRIVERS\k750mgmt.sys -- (k750mgmt [On_Demand | Stopped])
DRV - [2005-06-03 13:47:06 | 00,079,488 | R--- | M] (MCCI) -- C:\WINDOWS\system32\DRIVERS\k750obex.sys -- (k750obex [On_Demand | Stopped])
DRV - [2009-05-25 11:45:16 | 00,064,160 | ---- | M] (Lavasoft AB) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd [Boot | Running])
DRV - [2006-10-31 08:35:00 | 03,964,256 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2006-10-18 16:31:38 | 00,105,472 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata [Boot | Running])
DRV - [2006-11-27 16:33:50 | 00,058,368 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\NVENETFD.sys -- (NVENETFD [On_Demand | Running])
DRV - [2006-11-27 16:33:54 | 00,019,968 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvnetbus.sys -- (nvnetbus [On_Demand | Running])
DRV - [2006-03-02 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008-08-20 19:58:58 | 00,044,944 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2008-04-13 18:39:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2006-11-04 00:45:48 | 00,178,913 | R--- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\DRIVERS\V0260Vid.sys -- (V0260VID [On_Demand | Stopped])
[color=orange]========== Standard Registry (SafeList) ==========[/color]
[color=orange]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/firefox
IE - URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
[color=orange]========== FireFox ==========[/color]
FF - prefs.js..browser.search.defaultenginename: "Winamp Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="
FF - prefs.js..browser.search.selectedEngine: "Winamp Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.pl/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.10.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query="
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009-05-27 15:34:27 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009-05-11 16:46:51 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009-05-25 11:24:28 | 00,000,000 | ---D | M]
[2009-03-12 18:00:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\mozilla\Extensions
[2009-03-12 18:00:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-05-25 20:42:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\mozilla\Firefox\Profiles\nv9uoa91.default\extensions
[2009-05-25 20:43:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\mozilla\Firefox\Profiles\nv9uoa91.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2009-05-25 20:43:55 | 00,001,196 | ---- | M] () -- C:\Documents and Settings\admin\Dane aplikacji\Mozilla\FireFox\Profiles\nv9uoa91.default\searchplugins\winamp-search.xml
[2009-05-27 16:07:07 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-05-11 16:46:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-03-12 19:21:07 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009-05-27 15:34:40 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009-04-24 11:54:25 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-04-24 11:54:25 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2006-06-03 18:43:22 | 00,000,896 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2008-04-03 19:19:08 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2008-04-16 06:08:20 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2007-03-31 19:11:54 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2006-06-03 18:43:22 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2008-03-28 23:36:04 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2007-01-05 13:40:56 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon (alch)
O4 - HKLM..\Run: [CreativeTaskScheduler] "C:\Program Files\Creative\Shared Files\CTSched.exe" /logon File not found
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions (Sony Ericsson Mobile Communications AB)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" ()
O4 - HKCU..\Run: [Dipetozo] C:\Documents and Settings\admin\Dipetozo.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-09-04 12:56:41 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{00dbbf5a-461b-11de-8d6b-001a4d80ed78}\Shell\aUtoPlAy\commANd - "" = G:\lxrh.pif -- File not found
O33 - MountPoints2\{00dbbf5a-461b-11de-8d6b-001a4d80ed78}\Shell\AutoRun\command - "" = G:\lxrh.pif -- File not found
O33 - MountPoints2\{00dbbf5a-461b-11de-8d6b-001a4d80ed78}\Shell\exPLoRE\COMmaNd - "" = G:\lxrh.pif -- File not found
O33 - MountPoints2\{00dbbf5a-461b-11de-8d6b-001a4d80ed78}\Shell\oPEN\ComMAND - "" = G:\lxrh.pif -- File not found
O33 - MountPoints2\{135af8e2-139b-11de-8c2a-001a4d80ed78}\Shell\AuTopLaY\coMMaND - "" = G:\fetp.exe -- File not found
O33 - MountPoints2\{135af8e2-139b-11de-8c2a-001a4d80ed78}\Shell\AutoRun\command - "" = G:\fetp.exe -- File not found
O33 - MountPoints2\{135af8e2-139b-11de-8c2a-001a4d80ed78}\Shell\eXPloRE\CommanD - "" = G:\fetp.exe -- File not found
O33 - MountPoints2\{135af8e2-139b-11de-8c2a-001a4d80ed78}\Shell\opEn\cOmmanD - "" = G:\fetp.exe -- File not found
O33 - MountPoints2\{135af8e3-139b-11de-8c2a-001a4d80ed78}\Shell\Autoplay\cOMmANd - "" = H:\glca.exe -- File not found
O33 - MountPoints2\{135af8e3-139b-11de-8c2a-001a4d80ed78}\Shell\AutoRun\command - "" = H:\glca.exe -- File not found
O33 - MountPoints2\{135af8e3-139b-11de-8c2a-001a4d80ed78}\Shell\explore\COmMand - "" = H:\glca.exe -- File not found
O33 - MountPoints2\{135af8e3-139b-11de-8c2a-001a4d80ed78}\Shell\opEn\COmmand - "" = H:\glca.exe -- File not found
O33 - MountPoints2\{225c2a04-46c8-11de-8d6f-001a4d80ed78}\Shell\autOplaY\CommaNd - "" = G:\xtlrx.exe -- File not found
O33 - MountPoints2\{225c2a04-46c8-11de-8d6f-001a4d80ed78}\Shell\AutoRun\command - "" = G:\xtlrx.exe -- File not found
O33 - MountPoints2\{225c2a04-46c8-11de-8d6f-001a4d80ed78}\Shell\eXPlORe\command - "" = G:\xtlrx.exe -- File not found
O33 - MountPoints2\{225c2a04-46c8-11de-8d6f-001a4d80ed78}\Shell\open\COMmAND - "" = G:\xtlrx.exe -- File not found
O33 - MountPoints2\{225c2a08-46c8-11de-8d6f-001a4d80ed78}\Shell\AutOPlay\CommanD - "" = G:\jxgmar.pif -- File not found
O33 - MountPoints2\{225c2a08-46c8-11de-8d6f-001a4d80ed78}\Shell\AutoRun\command - "" = G:\jxgmar.pif -- File not found
O33 - MountPoints2\{225c2a08-46c8-11de-8d6f-001a4d80ed78}\Shell\expLoRE\COMmaNd - "" = G:\jxgmar.pif -- File not found
O33 - MountPoints2\{225c2a08-46c8-11de-8d6f-001a4d80ed78}\Shell\OPen\CommAnd - "" = G:\jxgmar.pif -- File not found
O33 - MountPoints2\{76d32ffc-14a4-11de-8c31-001a4d80ed78}\Shell\AUtopLay\cOMMand - "" = H:\whut.cmd -- File not found
O33 - MountPoints2\{76d32ffc-14a4-11de-8c31-001a4d80ed78}\Shell\AutoRun\command - "" = H:\whut.cmd -- File not found
O33 - MountPoints2\{76d32ffc-14a4-11de-8c31-001a4d80ed78}\Shell\expLore\Command - "" = H:\whut.cmd -- File not found
O33 - MountPoints2\{76d32ffc-14a4-11de-8c31-001a4d80ed78}\Shell\OPen\COMmaNd - "" = H:\whut.cmd -- File not found
O33 - MountPoints2\{b6c57ec6-0f1a-11de-8c0c-001a4d80ed78}\Shell\AutoRun\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe
O33 - MountPoints2\{b6c57ec6-0f1a-11de-8c0c-001a4d80ed78}\Shell\open\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe
O33 - MountPoints2\{ee64aee6-45e7-11de-8d67-001a4d80ed78}\Shell\autoPlAy\cOMMaNd - "" = G:\jenw.exe -- File not found
O33 - MountPoints2\{ee64aee6-45e7-11de-8d67-001a4d80ed78}\Shell\AutoRun\command - "" = G:\jenw.exe -- File not found
O33 - MountPoints2\{ee64aee6-45e7-11de-8d67-001a4d80ed78}\Shell\ExPlORe\Command - "" = G:\jenw.exe -- File not found
O33 - MountPoints2\{ee64aee6-45e7-11de-8d67-001a4d80ed78}\Shell\open\CommanD - "" = G:\jenw.exe -- File not found
O33 - MountPoints2\{f8752a69-4ab6-11de-8d8a-001a4d80ed78}\Shell\AutoRun\command - "" = G:\upw.bat -- File not found
O33 - MountPoints2\{f8752a69-4ab6-11de-8d8a-001a4d80ed78}\Shell\open\Command - "" = G:\upw.bat -- File not found
O33 - MountPoints2\{f9dd1636-1d31-11de-8c57-001a4d80ed78}\Shell - "" = AutoRun
O33 - MountPoints2\{f9dd1636-1d31-11de-8c57-001a4d80ed78}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -- File not found
O33 - MountPoints2\{f9dd1637-1d31-11de-8c57-001a4d80ed78}\Shell\AutoRun\command - "" = J:\lc.exe -- File not found
O33 - MountPoints2\{f9dd1637-1d31-11de-8c57-001a4d80ed78}\Shell\open\Command - "" = J:\lc.exe -- File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009-05-27 18:46:45 | 00,000,000 | ---D | M]
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
[color=orange]========== Files/Folders - Created Within 30 Days ==========[/color]
[2009-05-27 18:46:42 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\admin\Pulpit\OTListIt2.exe
[2009-05-27 17:02:53 | 00,000,000 | ---D | C] -- C:\Program Files\SkanerOnline
[2009-05-27 15:47:24 | 00,000,653 | ---- | C] () -- C:\Documents and Settings\admin\Pulpit\Gadu-Gadu.lnk
[2009-05-27 14:07:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Dane aplikacji\Teleca
[2009-05-27 14:07:39 | 00,001,958 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Sony Ericsson PC Suite.lnk
[2009-05-27 14:07:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Sony Ericsson
[2009-05-27 14:07:23 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Teleca Shared
[2009-05-27 14:07:19 | 00,000,000 | ---D | C] -- C:\Program Files\Sony Ericsson
[2009-05-27 14:07:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Teleca
[2009-05-27 14:04:52 | 00,005,744 | ---- | C] (MCCI) -- C:\WINDOWS\System32\drivers\k750wh.sys
[2009-05-27 14:04:51 | 00,006,144 | ---- | C] (MCCI) -- C:\WINDOWS\System32\drivers\k750cm.sys
[2009-05-27 14:04:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Downloaded Installations
[2009-05-27 14:03:14 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2009-05-27 14:03:14 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2009-05-26 11:10:21 | 00,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2009-05-25 21:17:39 | 00,000,000 | ---D | C] -- C:\Program Files\WinAce
[2009-05-25 20:42:28 | 00,000,664 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Winamp.lnk
[2009-05-25 20:42:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar
[2009-05-25 20:42:01 | 00,000,000 | ---D | C] -- C:\WINDOWS\RegisteredPackages
[2009-05-25 20:41:10 | 00,000,000 | ---D | C] -- C:\Program Files\Winamp
[2009-05-25 20:41:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Dane aplikacji\Winamp
[2009-05-25 20:39:36 | 09,915,072 | ---- | C] (Nullsoft, Inc.) -- C:\Documents and Settings\admin\Pulpit\winamp5552_full_emusic-7plus_en-us-[www.legalne.info].exe
[2009-05-25 13:50:51 | 00,000,697 | ---- | C] () -- C:\Documents and Settings\admin\Pulpit\Metin2 PL.lnk
[2009-05-25 13:49:56 | 00,000,000 | ---D | C] -- C:\Program Files\Metin2_PL
[2009-05-25 13:35:28 | 00,000,000 | ---D | C] -- C:\Program Files\Valve
[2009-05-25 13:35:27 | 00,001,369 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Counter-Strike 1.6.lnk
[2009-05-25 12:08:39 | 00,000,000 | ---D | C] -- C:\Program Files\OpenOffice.org 3
[2009-05-25 11:43:48 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009-05-25 11:43:42 | 00,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2009-05-25 11:41:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Dane aplikacji\.clamwin
[2009-05-25 11:41:30 | 00,000,000 | ---D | C] -- C:\Program Files\ClamWin
[2009-05-25 11:23:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM
[2009-05-25 11:23:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Dane aplikacji\OpenFM
[2009-05-23 10:55:03 | 00,389,382 | ---- | C] () -- C:\Documents and Settings\admin\Moje dokumenty\dokument pruss.odt
[2009-05-23 10:52:11 | 00,014,638 | ---- | C] () -- C:\Documents and Settings\admin\Moje dokumenty\Dokument666.rtf
[2009-05-22 17:25:45 | 00,000,434 | ---- | C] () -- C:\Documents and Settings\admin\Moje dokumenty\Skrót do Dokumenty udostępnione.lnk
[2009-05-22 12:33:10 | 00,000,717 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\OpenFM.lnk
[2009-05-22 12:32:28 | 00,000,000 | ---D | C] -- C:\Program Files\Nowe Gadu-Gadu
[2009-05-20 17:18:00 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009-05-20 16:56:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Ustawienia lokalne\temp
[2009-05-20 16:51:08 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009-05-20 16:51:08 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009-05-20 16:51:08 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009-05-20 16:51:08 | 00,117,248 | ---- | C] () -- C:\WINDOWS\vFind.exe
[2009-05-20 16:51:08 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009-05-20 16:51:08 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009-05-20 16:51:08 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009-05-20 16:51:08 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009-05-18 19:56:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Moje dokumenty\GoD
[2009-05-18 16:32:28 | 00,010,630 | ---- | C] () -- C:\Documents and Settings\admin\Moje dokumenty\lista.odt
[2009-05-16 10:17:37 | 00,483,328 | ---- | C] (SoftShape Development) -- C:\WINDOWS\System32\actskn45.ocx
[2009-05-16 10:07:27 | 00,000,000 | ---D | C] -- C:\Program Files\WapSter
[2009-05-14 15:26:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Dane aplikacji\Help
[2009-05-07 20:30:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2009-05-06 20:32:00 | 00,051,232 | ---- | C] (gkweb) -- C:\Documents and Settings\All Users\Dokumenty\wwdc_[www.programosy.pl].exe
[2009-03-12 11:44:30 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2006-10-31 08:35:00 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006-10-31 08:35:00 | 01,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006-10-31 08:35:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006-10-31 08:35:00 | 00,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006-10-31 08:35:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006-10-31 08:35:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006-10-31 08:35:00 | 00,196,608 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2006-03-02 14:00:00 | 00,000,477 | ---- | C] () -- C:\WINDOWS\win.ini
[2006-03-02 14:00:00 | 00,000,263 | ---- | C] () -- C:\WINDOWS\system.ini
[color=orange]========== Files - Modified Within 30 Days ==========[/color]
[7 C:\WINDOWS\System32\*.tmp files]
[2009-05-27 18:46:46 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\admin\Pulpit\OTListIt2.exe
[2009-05-27 17:49:27 | 00,015,688 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe
[2009-05-27 16:58:44 | 00,081,496 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009-05-27 16:58:35 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\admin\Ustawienia lokalne\desktop.ini
[2009-05-27 16:58:32 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-05-27 15:47:24 | 00,000,653 | ---- | M] () -- C:\Documents and Settings\admin\Pulpit\Gadu-Gadu.lnk
[2009-05-27 14:07:39 | 00,001,958 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Sony Ericsson PC Suite.lnk
[2009-05-27 14:04:52 | 00,005,744 | ---- | M] (MCCI) -- C:\WINDOWS\System32\drivers\k750wh.sys
[2009-05-27 14:04:51 | 00,006,144 | ---- | M] (MCCI) -- C:\WINDOWS\System32\drivers\k750cm.sys
[2009-05-27 14:04:10 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009-05-27 14:04:10 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2009-05-26 11:10:21 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009-05-25 20:42:28 | 00,000,664 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Winamp.lnk
[2009-05-25 20:42:15 | 00,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2009-05-25 20:40:18 | 09,915,072 | ---- | M] (Nullsoft, Inc.) -- C:\Documents and Settings\admin\Pulpit\winamp5552_full_emusic-7plus_en-us-[www.legalne.info].exe
[2009-05-25 13:50:51 | 00,000,697 | ---- | M] () -- C:\Documents and Settings\admin\Pulpit\Metin2 PL.lnk
[2009-05-25 13:35:28 | 00,001,369 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Counter-Strike 1.6.lnk
[2009-05-25 13:32:24 | 00,112,584 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009-05-25 11:45:47 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009-05-25 11:45:16 | 00,064,160 | ---- | M] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009-05-25 11:21:56 | 00,002,259 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk
[2009-05-25 11:17:43 | 00,000,477 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-05-25 11:17:43 | 00,000,293 | RHS- | M] () -- C:\boot.ini
[2009-05-25 11:17:43 | 00,000,263 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-05-25 10:00:28 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-05-23 11:05:13 | 00,000,434 | ---- | M] () -- C:\Documents and Settings\admin\Moje dokumenty\Skrót do Dokumenty udostępnione.lnk
[2009-05-23 10:56:31 | 00,000,754 | ---- | M] () -- C:\WINDOWS\WORDPAD.INI
[2009-05-23 10:55:04 | 00,389,382 | ---- | M] () -- C:\Documents and Settings\admin\Moje dokumenty\dokument pruss.odt
[2009-05-23 10:52:11 | 00,014,638 | ---- | M] () -- C:\Documents and Settings\admin\Moje dokumenty\Dokument666.rtf
[2009-05-22 12:33:10 | 00,000,717 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\OpenFM.lnk
[2009-05-20 20:16:46 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-05-20 16:54:03 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009-05-18 16:32:28 | 00,010,630 | ---- | M] () -- C:\Documents and Settings\admin\Moje dokumenty\lista.odt
[2009-05-14 17:50:08 | 00,117,248 | ---- | M] () -- C:\WINDOWS\vFind.exe
[2009-05-11 16:46:54 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk
[2009-05-07 09:16:29 | 24,699,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009-05-06 20:32:00 | 00,051,232 | ---- | M] (gkweb) -- C:\Documents and Settings\All Users\Dokumenty\wwdc_[www.programosy.pl].exe
< End of report >