
http://img153.imageshack.us/img153/5310/beztytuunjm.jpg
taka sytuacja powtarza się też w losowym czasie w trakcie użytkowania kompa, po prostu nagle staje i koniec.
załączam logi.
Gmer:
http://wklej.org/hash/fe5a440a5db/
OTL:
- Kod: Zaznacz wszystko
OTL logfile created on: 2010-09-07 11:32:43 - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Piondis\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
495,00 Mb Total Physical Memory | 32,00 Mb Available Physical Memory | 6,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 52,00% Paging File free
Paging file location(s): C:\pagefile.sys 744 1488 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29,29 Gb Total Space | 5,00 Gb Free Space | 17,06% Space Free | Partition Type: NTFS
Drive D: | 59,57 Gb Total Space | 16,72 Gb Free Space | 28,07% Space Free | Partition Type: NTFS
Drive E: | 60,18 Gb Total Space | 2,53 Gb Free Space | 4,20% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NOM
Current User Name: Piondis
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2010-09-07 11:31:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Piondis\Pulpit\OTL.exe
PRC - [2010-08-18 03:58:17 | 000,945,720 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
PRC - [2010-07-22 01:24:16 | 012,477,024 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe
PRC - [2010-03-30 11:16:12 | 001,107,336 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2009-11-25 01:51:40 | 000,081,000 | ---- | M] (ALWIL Software) -- D:\Programy\Alwil Software\Avast4\ashDisp.exe
PRC - [2009-11-25 01:51:35 | 000,138,680 | ---- | M] (ALWIL Software) -- d:\Programy\Alwil Software\Avast4\ashServ.exe
PRC - [2009-11-25 01:51:21 | 000,254,040 | ---- | M] (ALWIL Software) -- d:\Programy\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009-11-25 01:48:48 | 000,352,920 | ---- | M] (ALWIL Software) -- d:\Programy\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009-11-25 01:43:56 | 000,018,752 | ---- | M] (ALWIL Software) -- d:\Programy\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009-09-20 10:01:39 | 001,799,952 | ---- | M] (COMODO) -- D:\Zabezpieczenia\Comodo\COMODO Internet Security\cfp.exe
PRC - [2009-09-20 10:01:10 | 000,723,632 | ---- | M] (COMODO) -- D:\Zabezpieczenia\Comodo\COMODO Internet Security\cmdagent.exe
PRC - [2009-06-19 09:17:54 | 000,045,056 | ---- | M] () -- C:\WINDOWS\system32\UTSCSI.EXE
PRC - [2009-04-21 17:29:42 | 000,877,568 | ---- | M] () -- C:\Program Files\HACE\Mmm\Mmm.exe
PRC - [2008-04-14 19:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[color=#E56717]========== Modules (SafeList) ==========[/color]
MOD - [2010-09-07 11:31:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Piondis\Pulpit\OTL.exe
MOD - [2009-09-20 10:03:10 | 000,179,792 | ---- | M] (COMODO) -- C:\WINDOWS\system32\guard32.dll
MOD - [2008-04-14 19:16:32 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2010-03-30 11:16:12 | 001,107,336 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2009-12-10 22:23:00 | 003,480,408 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2009-11-25 01:51:35 | 000,138,680 | ---- | M] (ALWIL Software) [Auto | Running] -- d:\Programy\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2009-11-25 01:51:21 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand | Running] -- d:\Programy\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2009-11-25 01:48:48 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand | Running] -- d:\Programy\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2009-11-25 01:43:56 | 000,018,752 | ---- | M] (ALWIL Software) [Auto | Running] -- d:\Programy\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV - [2009-09-20 10:01:10 | 000,723,632 | ---- | M] (COMODO) [Auto | Running] -- D:\Zabezpieczenia\Comodo\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2009-06-19 09:17:54 | 000,045,056 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\UTSCSI.EXE -- (UTSCSI)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - File not found [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\NTGLM7X.sys -- (SetupNTGLM7X)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\NTACCESS.sys -- (NTACCESS)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - [2010-02-03 15:56:56 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2009-11-25 01:50:59 | 000,094,160 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2009-11-25 01:50:12 | 000,114,768 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2009-11-25 01:50:00 | 000,020,560 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009-11-25 01:49:07 | 000,048,560 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2009-11-25 01:48:57 | 000,023,120 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2009-11-25 01:47:54 | 000,027,408 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009-09-20 10:03:06 | 000,087,104 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2009-09-20 10:03:05 | 000,025,160 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2009-09-20 10:03:02 | 000,132,296 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdguard.sys -- (cmdGuard)
DRV - [2009-07-27 04:43:18 | 000,058,908 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2008-04-13 18:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2006-05-16 11:32:58 | 004,275,712 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006-04-24 11:52:28 | 000,100,736 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2006-02-17 05:28:32 | 000,013,056 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2006-02-17 05:28:30 | 000,034,176 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006-01-24 12:15:00 | 003,535,520 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2005-03-09 08:53:00 | 000,036,352 | R--- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2001-08-17 22:58:04 | 000,008,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\memcard.sys -- (memcard)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wyborcza.pl/0,0.html?p=029
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-73586283-789336058-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.wyborcza.pl/0,0.html?p=029
IE - HKU\S-1-5-21-73586283-789336058-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.pl"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 9
FF - prefs.js..extensions.enabledItems: 1
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Plugins: D:\Programy\K-Meleon\Plugins [2010-08-09 10:23:05 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Components: D:\Programy\K-Meleon\Components [2010-08-18 14:13:50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.3\extensions\\Components: d:\Mozilla Firefox\components
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.3\extensions\\Plugins: d:\Mozilla Firefox\plugins
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: D:\Programy\Mozilla Firefox\components [2010-08-09 13:27:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: D:\Programy\Mozilla Firefox\plugins [2010-08-09 10:23:05 | 000,000,000 | ---D | M]
[2009-08-04 00:13:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\Mozilla\Extensions
[2010-09-06 23:29:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\Mozilla\Firefox\Profiles\bsexdlyw.default\extensions
[2010-09-04 22:52:21 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\Piondis\Dane aplikacji\Mozilla\Firefox\Profiles\bsexdlyw.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010-02-22 21:39:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\Mozilla\Firefox\Profiles\bsexdlyw.default\extensions\firefox@tvunetworks.com
[2009-09-01 22:14:51 | 000,002,293 | ---- | M] () -- C:\Documents and Settings\Piondis\Dane aplikacji\Mozilla\Firefox\Profiles\bsexdlyw.default\searchplugins\demonoid-search.xml
O1 HOSTS File: ([2001-10-26 17:45:16 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - d:\Programy\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.
O4 - HKLM..\Run: [avast!] d:\Programy\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [COMODO Internet Security] D:\Zabezpieczenia\Comodo\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKU\S-1-5-21-73586283-789336058-725345543-1003..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.)
O4 - HKU\S-1-5-21-73586283-789336058-725345543-1003..\Run: [Mmm] C:\Program Files\HACE\Mmm\Mmm.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-73586283-789336058-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-73586283-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-73586283-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-73586283-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - D:\Programy\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Pobierz wszystkie VIdeo za pomocą BitComet - D:\Programy\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Pobierz wszystko za pomocą BitComet - D:\Programy\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Pobierz za pomocą BitComet - D:\Programy\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Programy\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - d:\Programy\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://downloads.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1249332941656 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} file://F:\CDVIEWER\CdViewer.cab (AMI DicomDir TreeView Control 2.1)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-10-19 20:34:10 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{20abc875-5ca1-11de-bcfd-001617872415}\Shell\AutoRun\command - "" = I:\USBNB.exe -- File not found
O33 - MountPoints2\{9f48c148-f877-11dd-bc5a-001617872415}\Shell\AutoRun\command - "" = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\iuhx32.exe -- File not found
O33 - MountPoints2\{9f48c148-f877-11dd-bc5a-001617872415}\Shell\open\command - "" = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\iuhx32.exe -- File not found
O33 - MountPoints2\{e34783cf-9e19-11dd-bf2f-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{e34783cf-9e19-11dd-bf2f-806d6172696f}\Shell\AutoRun\command - "" = F:\Setup.exe -- File not found
O33 - MountPoints2\{f9e23022-32a3-11df-bedc-001617872415}\Shell\AutoRun\command - "" = H:\s1.exe -- File not found
O33 - MountPoints2\{f9e23022-32a3-11df-bedc-001617872415}\Shell\open\Command - "" = H:\s1.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2010-09-07 11:31:25 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Piondis\Pulpit\OTL.exe
[2010-09-07 09:54:05 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Piondis\Recent
[2010-09-07 09:51:57 | 000,880,624 | ---- | C] (Duplex Secure Ltd.) -- C:\Documents and Settings\Piondis\Pulpit\SPTDinst-v162-x86.exe
[2010-09-04 19:25:28 | 000,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbscan.sys
[2010-09-04 19:25:28 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
[2010-09-04 19:25:25 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
[2010-08-30 00:14:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piondis\Pulpit\Karko
[2010-08-29 23:50:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piondis\Dane aplikacji\skypePM
[2010-08-29 23:50:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piondis\Dane aplikacji\Skype
[2010-08-29 23:49:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2010-08-29 23:49:27 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2010-08-29 23:49:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Skype
[2010-08-23 11:29:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM
[2010-08-23 11:29:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piondis\Dane aplikacji\OpenFM
[2010-08-18 11:37:26 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\gdiplus.dll
[2010-08-18 11:31:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piondis\Dane aplikacji\Gadu-Gadu 10
[2010-08-18 11:31:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10
[2010-08-18 11:29:39 | 000,000,000 | ---D | C] -- C:\Program Files\Gadu-Gadu 10
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2010-09-07 11:31:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Piondis\Pulpit\OTL.exe
[2010-09-07 11:28:30 | 000,043,531 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010-09-07 11:28:19 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010-09-07 11:28:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010-09-07 11:28:02 | 000,000,000 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2010-09-07 10:49:05 | 000,001,140 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-789336058-725345543-1003UA.job
[2010-09-07 10:04:47 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\Piondis\Pulpit\57y6ef25.exe
[2010-09-07 09:56:41 | 009,175,040 | -H-- | M] () -- C:\Documents and Settings\Piondis\NTUSER.DAT
[2010-09-07 09:56:41 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\Piondis\ntuser.ini
[2010-09-07 09:52:01 | 000,880,624 | ---- | M] (Duplex Secure Ltd.) -- C:\Documents and Settings\Piondis\Pulpit\SPTDinst-v162-x86.exe
[2010-09-07 09:51:07 | 000,070,136 | ---- | M] () -- C:\Documents and Settings\Piondis\Pulpit\bez tytułu.JPG
[2010-09-07 09:25:39 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-09-07 01:13:38 | 006,949,454 | -H-- | M] () -- C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2010-09-06 22:41:18 | 003,859,941 | ---- | M] () -- C:\Documents and Settings\Piondis\Pulpit\patiikarol.jpg
[2010-09-06 20:48:07 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-789336058-725345543-1003Core.job
[2010-08-31 22:18:14 | 000,000,049 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010-08-30 00:16:28 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Piondis\Moje dokumenty\100_8844.JPG
[2010-08-30 00:16:24 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Piondis\100_8844.JPG
[2010-08-30 00:16:14 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Piondis\Moje dokumenty\100_8843.JPG
[2010-08-30 00:16:08 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Piondis\100_8843.JPG
[2010-08-30 00:15:57 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Piondis\Moje dokumenty\100_8842.JPG
[2010-08-30 00:15:56 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Piondis\100_8842.JPG
[2010-08-30 00:15:38 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Piondis\Moje dokumenty\100_8841.JPG
[2010-08-30 00:15:31 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Piondis\100_8841.JPG
[2010-08-29 23:50:48 | 000,000,056 | -H-- | M] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010-08-29 23:49:33 | 000,001,880 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk
[2010-08-27 22:59:14 | 000,041,472 | ---- | M] () -- C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-08-27 12:31:43 | 000,000,500 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\DarkSwords.lnk
[2010-08-27 10:06:59 | 000,000,594 | ---- | M] () -- C:\WINDOWS\win.ini
[2010-08-27 10:06:59 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010-08-27 10:06:59 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010-08-23 16:54:47 | 000,001,498 | ---- | M] () -- C:\Documents and Settings\Piondis\.recently-used.xbel
[2010-08-18 11:37:30 | 001,700,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\gdiplus.dll
[2010-08-18 11:33:53 | 000,000,738 | ---- | M] () -- C:\Documents and Settings\Piondis\Pulpit\Gadu-Gadu 10.lnk
[2010-08-15 22:39:50 | 000,307,200 | ---- | M] () -- C:\Documents and Settings\Piondis\Pulpit\Kot Felix.exe
[2010-08-12 15:17:58 | 000,213,672 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2010-09-07 10:04:02 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Piondis\Pulpit\57y6ef25.exe
[2010-09-07 09:51:07 | 000,070,136 | ---- | C] () -- C:\Documents and Settings\Piondis\Pulpit\bez tytułu.JPG
[2010-09-06 22:40:48 | 003,859,941 | ---- | C] () -- C:\Documents and Settings\Piondis\Pulpit\patiikarol.jpg
[2010-09-03 11:57:57 | 000,307,200 | ---- | C] () -- C:\Documents and Settings\Piondis\Pulpit\Kot Felix.exe
[2010-08-30 00:16:28 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Piondis\Moje dokumenty\100_8844.JPG
[2010-08-30 00:16:24 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Piondis\100_8844.JPG
[2010-08-30 00:16:14 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Piondis\Moje dokumenty\100_8843.JPG
[2010-08-30 00:16:08 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Piondis\100_8843.JPG
[2010-08-30 00:15:57 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Piondis\Moje dokumenty\100_8842.JPG
[2010-08-30 00:15:56 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Piondis\100_8842.JPG
[2010-08-30 00:15:38 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Piondis\Moje dokumenty\100_8841.JPG
[2010-08-30 00:15:31 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Piondis\100_8841.JPG
[2010-08-29 23:50:48 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010-08-29 23:49:33 | 000,001,880 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk
[2010-08-23 16:54:47 | 000,001,498 | ---- | C] () -- C:\Documents and Settings\Piondis\.recently-used.xbel
[2010-08-18 11:33:53 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\Piondis\Pulpit\Gadu-Gadu 10.lnk
[2010-07-02 12:43:33 | 000,374,272 | ---- | C] () -- C:\WINDOWS\System32\mss32.dll
[2009-08-30 14:36:49 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2009-07-01 17:05:06 | 000,000,181 | ---- | C] () -- C:\WINDOWS\HomeCollections.ini
[2009-07-01 17:05:06 | 000,000,062 | ---- | C] () -- C:\WINDOWS\FavoritList.ini
[2009-07-01 17:04:26 | 000,000,024 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2009-04-16 16:50:44 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Piondis\Dane aplikacji\PnkBstrK.sys
[2009-03-16 23:55:07 | 000,024,580 | ---- | C] () -- C:\WINDOWS\System\wuaclt.exe
[2009-03-16 23:55:04 | 000,032,770 | ---- | C] () -- C:\WINDOWS\System\svhost.sd7
[2009-03-16 23:55:04 | 000,024,580 | ---- | C] () -- C:\WINDOWS\System\wuaclt.sd7
[2009-03-01 21:52:40 | 000,000,297 | ---- | C] () -- C:\WINDOWS\doom3.ini
[2008-12-19 23:30:43 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2008-12-19 23:30:43 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2008-12-19 23:30:43 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2008-11-10 16:07:02 | 000,000,059 | ---- | C] () -- C:\WINDOWS\dcmvwr.INI
[2008-11-03 17:28:44 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008-11-03 17:28:43 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2008-11-03 17:28:38 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008-11-03 17:28:38 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008-11-03 17:28:37 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008-11-03 17:28:34 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008-11-03 17:28:34 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008-10-21 07:32:36 | 000,000,049 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-10-20 17:41:56 | 000,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-10-20 17:33:10 | 000,041,472 | ---- | C] () -- C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008-10-20 13:01:45 | 000,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008-08-27 23:02:20 | 000,042,320 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2008-02-11 10:39:26 | 000,253,952 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2008-02-11 10:39:18 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2008-02-08 14:53:46 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerLang.dll
[2007-07-27 15:49:02 | 000,225,355 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiW.dll
[2007-07-27 15:49:02 | 000,196,683 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiA.dll
[2006-01-24 12:15:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006-01-24 12:15:00 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006-01-24 12:15:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006-01-24 12:15:00 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006-01-24 12:15:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006-01-24 12:15:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006-01-24 12:15:00 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2005-12-05 20:25:22 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\lnod32umc.dll
[2005-12-05 13:37:10 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\lnod32upd.dll
[2003-04-08 11:40:22 | 000,005,679 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[color=#E56717]========== LOP Check ==========[/color]
[2010-08-18 11:31:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10
[2009-06-27 11:31:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\id Software
[2009-04-18 18:41:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Last.fm
[2010-08-23 11:29:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM
[2008-10-20 17:33:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\DAEMON Tools
[2010-09-05 14:30:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\foobar2000
[2008-10-20 13:35:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\Gadu-Gadu
[2010-08-18 11:32:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\Gadu-Gadu 10
[2010-02-07 17:32:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\gtk-2.0
[2009-04-16 17:07:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\id Software
[2010-06-09 22:59:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\K-Meleon
[2009-07-10 23:30:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\Nowe Gadu-Gadu
[2010-08-23 11:29:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\OpenFM
[2010-08-27 19:33:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piondis\Dane aplikacji\uTorrent
[color=#E56717]========== Purity Check ==========[/color]
< End of report >
- Kod: Zaznacz wszystko
OTL Extras logfile created on: 2010-09-07 11:32:43 - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Piondis\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
495,00 Mb Total Physical Memory | 32,00 Mb Available Physical Memory | 6,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 52,00% Paging File free
Paging file location(s): C:\pagefile.sys 744 1488 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29,29 Gb Total Space | 5,00 Gb Free Space | 17,06% Space Free | Partition Type: NTFS
Drive D: | 59,57 Gb Total Space | 16,72 Gb Free Space | 28,07% Space Free | Partition Type: NTFS
Drive E: | 60,18 Gb Total Space | 2,53 Gb Free Space | 4,20% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NOM
Current User Name: Piondis
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Extra Registry (SafeList) ==========[/color]
[color=#E56717]========== File Associations ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = K-Meleon.HTML] -- D:\Programy\K-Meleon\K-Meleon.exe (http://kmeleon.sf.net/)
[HKEY_USERS\S-1-5-21-73586283-789336058-725345543-1003\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
[color=#E56717]========== Shell Spawning ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "D:\Programy\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "D:\Programy\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "D:\Programy\K-Meleon\K-Meleon.exe" "%1" (http://kmeleon.sf.net/)
https [open] -- "D:\Programy\K-Meleon\K-Meleon.exe" "%1" (http://kmeleon.sf.net/)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Odkurz tutaj] -- d:\Programy\Odkurzacz\odkurzacz.exe %1 (Franmo Software)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[color=#E56717]========== Security Center Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"8461:TCP" = 8461:TCP:*:Enabled:GoD High Port
"8462:TCP" = 8462:TCP:*:Enabled:GoD Low Port
"14453:TCP" = 14453:TCP:*:Enabled:BitComet 14453 TCP
"14453:UDP" = 14453:UDP:*:Enabled:BitComet 14453 UDP
[color=#E56717]========== Authorized Applications List ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\Programy\LimeWire\LimeWire.exe" = D:\Programy\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC)
"D:\Gry\3do\HEROES3.EXE" = D:\Gry\3do\HEROES3.EXE:*:Enabled:Heroes of Might and Magic® III -- (The 3DO Company)
"D:\Programy\Nowe Gadu-Gadu\gg.exe" = D:\Programy\Nowe Gadu-Gadu\gg.exe:*:Enabled:Nowe Gadu-Gadu -- File not found
"C:\WINDOWS\system32\PnkBstrB.exe" = C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB -- File not found
"D:\Gry\q3\quake3.exe" = D:\Gry\q3\quake3.exe:*:Enabled:quake3 -- ()
"D:\Programy\Mozilla Firefox\firefox.exe" = D:\Programy\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"D:\Gry\CABAL Online (Europe)\launcher\update\ESTdnheadless.exe" = D:\Gry\CABAL Online (Europe)\launcher\update\ESTdnheadless.exe:*:Enabled:EST! download engine -- ()
"D:\Gry\3do\h3blade.exe" = D:\Gry\3do\h3blade.exe:*:Enabled:Heroes of Might and Magic(tm) III -- (The 3DO Company)
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper -- (Microsoft Corporation)
"C:\Program Files\Hamachi\hamachi.exe" = C:\Program Files\Hamachi\hamachi.exe:*:Enabled:Hamachi Client -- File not found
"D:\Programy\uTorrent\uTorrent.exe" = D:\Programy\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Gadu-Gadu 10\gg.exe" = C:\Program Files\Gadu-Gadu 10\gg.exe:*:Disabled:Gadu-Gadu 10 -- (GG Network S.A.)
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java(TM) 6 Update 19
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EFDE051-D7D3-4860-B559-98FF316184D4}_is1" = DarkSwords 1.2.3.4
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{90110415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{AC76BA86-7AD7-1045-7B44-A93000000001}" = Adobe Reader 9.3.3 - Polish
"{C3C9EB3D-24FA-4462-B784-0EC6AAFCD2DD}" = Fable - The Lost Chapters
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}" = Doom 3
"{EFE1AB94-5466-4B6E-BE31-FF4C115FD25D}" = Max Payne 2
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5C521B6-1AF2-432C-A061-E79E2141A32F}" = Quake Live Mozilla Plugin
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ALLPlayer_is1" = ALLPlayer V3.X
"Audacity_is1" = Audacity 1.2.6
"avast!" = avast! Antivirus
"BitComet" = BitComet 1.06
"CABAL Online (Europe)_is1" = CABAL Online
"CCleaner" = CCleaner (remove only)
"COMODO Internet Security" = COMODO Internet Security
"Dark Swords" = Dark Swords
"DS-Map" = DS-Map, version 2.0
"EsetOnlineScanner" = ESET Online Scanner
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"foobar2000" = foobar2000 v0.9.6.4
"Gadu-Gadu" = Gadu-Gadu 7.7
"Gadu-Gadu 10" = Gadu-Gadu 10
"HDCleaner" = HDCleaner
"Heroes III The Shadow of Death" = Heroes of Might and Magic® III The Shadow of Death(TM)
"Heroes of Might and Magic II" = Heroes of Might and Magic II
"Heroes of Might and Magic IV" = Heroes of Might and Magic IV
"Heroes of Might and Magic(TM) III Armageddon's Blade" = Heroes of Might and Magic(TM) III Armageddon's Blade
"HijackThis" = HijackThis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{C3C9EB3D-24FA-4462-B784-0EC6AAFCD2DD}" = Fable - The Lost Chapters
"InstallShield_{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}" = Doom 3
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.2.5 (Full)
"K-Meleon" = K-Meleon 1.5.1 pl-PL (remove only)
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LastFM_is1" = Last.fm 1.5.4.24567
"LimeWire" = LimeWire 4.9.21
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.5.11)" = Mozilla Firefox (3.5.11)
"NAPIPROJEKT_is1" = NAPIPROJEKT 1.0.6.2
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NeroVision!UninstallKey" = NeroVision Express 2
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Odkurzacz 11.3_is1" = Odkurzacz 11.3
"PowerISO" = PowerISO
"RealAlt_is1" = Real Alternative 1.9.0
"Torrent Master_is1" = Torrent Master 2.0 Full
"uTorrent" = µTorrent
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.3
"WinRAR archiver" = Archiwizator WinRAR
"Xfire" = Xfire (remove only)
[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]
[HKEY_USERS\S-1-5-21-73586283-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Mmm" = Mmm
[color=#E56717]========== Last 10 Event Log Errors ==========[/color]
[ Antivirus Events ]
Error - 2010-07-13 19:06:24 | Computer Name = NOM | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User
Data\Default\databases\http_www.filmweb.pl_0\2-journal failed, 00000005.
Error - 2010-07-13 19:07:40 | Computer Name = NOM | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User
Data\Default\databases\http_www.filmweb.pl_0\3-journal failed, 00000005.
Error - 2010-07-13 19:07:40 | Computer Name = NOM | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User
Data\Default\databases\http_www.filmweb.pl_0\3-journal failed, 00000005.
Error - 2010-07-13 19:07:40 | Computer Name = NOM | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User
Data\Default\databases\http_www.filmweb.pl_0\2-journal failed, 00000005.
Error - 2010-07-13 19:07:40 | Computer Name = NOM | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User
Data\Default\databases\http_www.filmweb.pl_0\2-journal failed, 00000005.
Error - 2010-07-17 16:20:15 | Computer Name = NOM | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User
Data\Default\databases\http_www.filmweb.pl_0\3-journal failed, 00000005.
Error - 2010-07-17 16:20:16 | Computer Name = NOM | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User
Data\Default\databases\http_www.filmweb.pl_0\3-journal failed, 00000005.
Error - 2010-07-17 16:20:16 | Computer Name = NOM | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User
Data\Default\databases\http_www.filmweb.pl_0\2-journal failed, 00000005.
Error - 2010-07-17 16:20:16 | Computer Name = NOM | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Piondis\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User
Data\Default\databases\http_www.filmweb.pl_0\2-journal failed, 00000005.
Error - 2010-08-03 05:45:55 | Computer Name = NOM | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
H:\DCIM\104_PANA\P1040129.JPG failed, 0000001E.
[ Application Events ]
Error - 2009-11-26 18:36:06 | Computer Name = NOM | Source = Google Update | ID = 20
Description =
Error - 2009-11-27 04:23:49 | Computer Name = NOM | Source = Google Update | ID = 20
Description =
Error - 2009-11-27 04:36:05 | Computer Name = NOM | Source = Google Update | ID = 20
Description =
Error - 2009-12-11 17:05:39 | Computer Name = NOM | Source = PerfNet | ID = 2004
Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie
zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.
Error - 2009-12-12 06:18:32 | Computer Name = NOM | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca gg.exe, wersja 8.0.0.9453, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.
Error - 2009-12-12 19:27:42 | Computer Name = NOM | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd allplayer.exe, wersja 3.7.6.5, moduł powodujący
błąd allplayer.exe, wersja 3.7.6.5, adres błędu 0x000e703c.
Error - 2009-12-23 19:01:33 | Computer Name = NOM | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca explorer.exe, wersja 6.0.2900.5512, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.
Error - 2010-01-01 19:53:33 | Computer Name = NOM | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca OIS.EXE, wersja 11.0.8161.0, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.
Error - 2010-02-07 08:11:46 | Computer Name = NOM | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca gg.exe, wersja 8.0.0.9453, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.
Error - 2010-02-14 04:09:15 | Computer Name = NOM | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca gg.exe, wersja 8.0.0.9453, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.
[ System Events ]
Error - 2009-05-08 09:54:10 | Computer Name = NOM | Source = DCOM | ID = 10000
Description = Nie można uruchomić serwera DCOM: {46986115-84D6-459C-8F95-52DD653E532E}.
Błąd:
„%3”
wystąpił
podczas uruchamiania tego polecenia: "d:\Programy\Winamp\winamp.exe" -Embedding
Error - 2009-05-08 09:54:12 | Computer Name = NOM | Source = DCOM | ID = 10000
Description = Nie można uruchomić serwera DCOM: {46986115-84D6-459C-8F95-52DD653E532E}.
Błąd:
„%3”
wystąpił
podczas uruchamiania tego polecenia: "d:\Programy\Winamp\winamp.exe" -Embedding
Error - 2009-05-08 10:33:22 | Computer Name = NOM | Source = DCOM | ID = 10000
Description = Nie można uruchomić serwera DCOM: {46986115-84D6-459C-8F95-52DD653E532E}.
Błąd:
„%3”
wystąpił
podczas uruchamiania tego polecenia: "d:\Programy\Winamp\winamp.exe" -Embedding
Error - 2009-05-08 14:57:22 | Computer Name = NOM | Source = DCOM | ID = 10000
Description = Nie można uruchomić serwera DCOM: {46986115-84D6-459C-8F95-52DD653E532E}.
Błąd:
„%3”
wystąpił
podczas uruchamiania tego polecenia: "d:\Programy\Winamp\winamp.exe" -Embedding
Error - 2009-05-08 15:48:43 | Computer Name = NOM | Source = DCOM | ID = 10000
Description = Nie można uruchomić serwera DCOM: {46986115-84D6-459C-8F95-52DD653E532E}.
Błąd:
„%3”
wystąpił
podczas uruchamiania tego polecenia: "d:\Programy\Winamp\winamp.exe" -Embedding
Error - 2009-05-08 16:44:49 | Computer Name = NOM | Source = DCOM | ID = 10000
Description = Nie można uruchomić serwera DCOM: {46986115-84D6-459C-8F95-52DD653E532E}.
Błąd:
„%3”
wystąpił
podczas uruchamiania tego polecenia: "d:\Programy\Winamp\winamp.exe" -Embedding
Error - 2009-05-08 18:26:26 | Computer Name = NOM | Source = DCOM | ID = 10000
Description = Nie można uruchomić serwera DCOM: {46986115-84D6-459C-8F95-52DD653E532E}.
Błąd:
„%3”
wystąpił
podczas uruchamiania tego polecenia: "d:\Programy\Winamp\winamp.exe" -Embedding
Error - 2009-05-09 03:44:01 | Computer Name = NOM | Source = DCOM | ID = 10000
Description = Nie można uruchomić serwera DCOM: {46986115-84D6-459C-8F95-52DD653E532E}.
Błąd:
„%3”
wystąpił
podczas uruchamiania tego polecenia: "d:\Programy\Winamp\winamp.exe" -Embedding
Error - 2009-05-09 03:52:10 | Computer Name = NOM | Source = DCOM | ID = 10000
Description = Nie można uruchomić serwera DCOM: {46986115-84D6-459C-8F95-52DD653E532E}.
Błąd:
„%3”
wystąpił
podczas uruchamiania tego polecenia: "d:\Programy\Winamp\winamp.exe" -Embedding
Error - 2009-05-09 04:42:45 | Computer Name = NOM | Source = DCOM | ID = 10000
Description = Nie można uruchomić serwera DCOM: {46986115-84D6-459C-8F95-52DD653E532E}.
Błąd:
„%3”
wystąpił
podczas uruchamiania tego polecenia: "d:\Programy\Winamp\winamp.exe" -Embedding
< End of report >