
Gmer:
- Kod: Zaznacz wszystko
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-03-03 17:42:30
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 SAMSUNG_ rev.2AC1
Running: 9xkeec4m.exe; Driver: C:\Users\samsung\AppData\Local\Temp\pxtdrfoc.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13BD 81E53589 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 81E78092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
PAGE peauth.sys A5B62E20 101 Bytes JMP 158F1805
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\System32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject] [86E11D56] \SystemRoot\system32\drivers\BMLoad.sys (Bytemobile Kernel Driver Loader/Bytemobile, Inc.)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [749B2494] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74995624] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [749956E2] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipFree] [749B250F] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [749A8573] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [749A4D27] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [749A50CE] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [749A51A3] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [749A66D0] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [749A82CA] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [749A8819] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [749A907A] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [749AE21D] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.EXE[1628] @ C:\windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [749A4C59] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Aparat wykonawczy struktury sterowników trybu jądra/Microsoft Corporation)
Device \Driver\BTHUSB \Device\0000009e bthport.sys (Sterownik magistrali Bluetooth/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Aparat wykonawczy struktury sterowników trybu jądra/Microsoft Corporation)
Device \Driver\BTHUSB \Device\000000a0 bthport.sys (Sterownik magistrali Bluetooth/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp tcpipBM.sys
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\00000073 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0026b654f6e1
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076fedcf2
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076fedd81
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\506313b915b0
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\506313b915b0@347e395023f9 0x19 0x89 0x18 0xFC ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\506313b915b0@347e39500af9 0x4E 0xBE 0x3B 0x5D ...
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind ????NA????????.?????????????????@??????????s?????????????????????????l?l?l??????????????????\\?\wpdbusenumroot#umb#2&37c186b&1&storage#volume#_??_usbstor#disk&ven_sony&prod_sony_dsc&rev_6.00#6&1d2aa9bf&0##{6ac27878-a6fa-4155-ba85-f98f491d4f33}?73??? ??????????????????????ll??? `??????5??????s}????????????????????????????????????*?????????????????? ?????????????????????1????????????????????? ???????????????????k?1?????????????????????????????9??E9??????-1??? ???????}??????nR???????&????N??????c????????????<???????????h?????*isatap?t???????????? ???????????????????j?1?????????????????????????????B???????7??????E2???????????????????2??tB??????????????????? ?????????????????????6?????????????????????????????????????????????????????????????????????????????????????????}??????#?????.?????????????11???????????????o??e???? ???????????????????u??????????"??? ???????????*6to4mp?????????????Intel(R) 82802 Firmwarehub???????????????????????????k???????????????????????r??????????????????????d?????6?????????in?????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Route ???p???????????????????sF-??system32\drivers\RTKVHDA.sys??????<??p????????h?????system32\DRIVERS\intelppm.sys?ntelppm.sys?????.????????????e????????????????p???? ??????????????????????????? |????????????????????p?????????6??????sh??int??????????????=???=????N??p?????????e????@%SystemRoot%\system32\ikeext.dll,-501????????Z??p????????h?????%systemroot%\system32\svchost.exe -k netsvcs??????N??p?????????n????@%SystemRoot%\system32\ikeext.dll,-502??????? ???p??????????????LocalSystem?????????????????????????????????????t??????????????g???????? ????????????? ??k???????????e????,??p???????????????????????????????????????p??????????????????SeAuditPrivilege?SeImpersonatePrivilege?SeTcbPrivilege?SeDebugPrivilege??????p?p?p?p?p?p?p?p?p?p?p????????????????????????????$??s????????????????8??}???????????????????p??system32\DRIVERS\cdfs.sys????????p???????????????????????????????????????????k???j???????k????.??p???n??b_??????????????t???????????????t???\SystemRoot\System32\drivers\dxgkrnl.sys???????????????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Export ????de??????????????????????{35e93fd3-91ca-11df-9597-506313b915b0}?E-8??? l??????5?????22-??????????Stereo 3W???????s???????????????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0029???????X??????&???&????6????????????e????tunnel??????????????? l?????????????????????????*6to4mp???????????????????<????????g????int???????????????????????N????????????D????USB\MS_COMP_BLUTUTH&MS_SUBCOMP_1112EDR?USB\MS_COMP_BLUTUTH?USB\Class_E0&SubClass_01&Prot_01?USB\Class_E0&SubClass_01?USB\Class_E0????????????????E?????s23??Karta Microsoft 6to4 #11????????????????int?el??????????????????????????????? ????????????????????<????????g????NetBIOSGroup????? b?????? ????????????F?????????????????? B??????????????????????f???????????????g???????e?????????????????????????????D?????????????????e??????r???{4d36e978-e325-11ce-bfc1-08002be10318}??????{4d36e978-e325-11ce-bfc1-08002be10318}\0000?????{4d36e972-e325-11ce-bfc1-08002be10318}???????j?j?k?k?k?k?k?l?k?l?l???????g???????e??????????????????????????6to4mp.ndi?????????? D??? ?????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Bind ????????????????????????????? ???2??????????d???*6to4mp???????N????????????????????????????j?j??@machine.inf,%*pnp0100.devicedesc%;Systemzeitgeber??????????????????????????????????? ??text?4??Karta Microsoft 6to4??????0??????????????????????????0??????os??t???????????????????9-11-2009???????????? ???????Z?????????????1????????????&???????????????????????????????????????????????de???k???????????????????????????i??????????????6.1.7600.16385????????$?????????p????:?6?m?i?o?|?j???????????????????f???h??VolumeSnapshot????????*??????????t????N??????u???????a??Microsoft????????=???=??volsnap?????.NTx86???????????????-??????8B??Bluetooth-Ger?t (PAN)???????????nettun.inf???????????????????????????}??????????????bf??????????????? $??????????????????????????\??????????????? ?????????????}??????????????$?N???????????????????ti??Microsoft???????????{36fc9e60-c465-11cf-8056-444553540000}???????&??????????Microsoft???? ?????????????????????1??????*?,??? ?????????????F??????????????2??????????? ???????????????????h?????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Route ???p?????????6??????sh??int??????????????=???=????N??p?????????e????@%SystemRoot%\system32\ikeext.dll,-501????????Z??p????????h?????%systemroot%\system32\svchost.exe -k netsvcs??????N??p?????????n????@%SystemRoot%\system32\ikeext.dll,-502??????? ???p??????????????LocalSystem?????????????????????????????????????t??????????????g???????? ????????????? ??k???????????e????,??p???????????????????????????????????????p??????????????????SeAuditPrivilege?SeImpersonatePrivilege?SeTcbPrivilege?SeDebugPrivilege??????p?p?p?p?p?p?p?p?p?p?p????????????????????????????$??s????????????????8??}???????????????????p??system32\DRIVERS\cdfs.sys????????p???????????????????????????????????????????k???j???????k????.??p???n??b_??????????????t???????????????t???\SystemRoot\System32\drivers\dxgkrnl.sys????????????????????????????????????????????????????PerfMon_Collect???????N??p???????????d???? ??p??????t\????????????`?????????????*isatap?t????????u???u???p??????????????cdrom.inf_x86_neutral_db87d184bc84f910??????????????????p??????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Export ????????????????? ???????????????????:?1????????z???????????nettun.inf:Microsoft.NTx86:6to4mp.ndi:6.1.7600.16385:*6to4mp?????????????4??????????? ??????? ????? Mi???????????4???}???????????_??????????? ?????????????????????1????????????????????????????????????l???????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip_{D4F29DE6-B8DF-41FB-97FF-D4??????????????????????????????????????????????????????????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{6CF947D9-0FAD-4EB7-B62F-F75A92F22782}] DATAGRAM 34?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????E8??? ???????7?????????????,??0??????????????????????????6???????e??? *??????_??????n???tunnel???&???????????B??? ?????????????????????1????????????????????E}??????????????????????)???? ??????????????????????????????????????{D811C810-682F-4146-807F-EEFE1AF9B4C4}????????R??????????????????????????N??????ip(??????????e?????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA2 0x23 0xB7 0x9E ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0026b654f6e1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076fedcf2 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076fedd81 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\506313b915b0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\506313b915b0@347e395023f9 0x19 0x89 0x18 0xFC ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\506313b915b0@347e39500af9 0x4E 0xBE 0x3B 0x5D ...
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Bind ???f?f??????25??25???????????????i?????????????n?????p?????f???f????{00000000-0000-0000-ffff-ffffffffffff}????????L?????????????????????????????????? ???h???f?????002??s???????????DiskDrive???? ???i???E?????6&D???????e???????e??tcpipreg????????????????????????????????????? ???????f?????f???????,????????????????????? ???????f?????????????,??"??????????????????*???????9??????????????????00??volsnap??????????????? ??6???/???e???e???f?f?????f???????????V???????e???????????/??????{4d36e97d-e325-11ce-bfc1-08002be10318}???8???????h???&?????????nUB????????????????????????N??l???q????D?????oem19.inf???? ???g??? ??????????BTAUDIO??????????i???f?????????nS\???????d???.???e???f?f?f????????????N??f????????D??????????f??????p???{4d36e96f-e325-11ce-bfc1-08002be10318}???????????`???????????????????????.??????BL????X?????????????WmiOpenPerfData??????%??????????????????????OT????<????????g????? ???????f???????????f?-??????$???????????????s??.???????????C?????????3?*??? ???????f???????????f?,??????"??????????????????f ??-?????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Route ???k?p?????????????????????????s?????????p???k?????k?&???????????S??tS????R??t????????h??????????u???????k??????????????????????? ???????k???????????k?,???????????? ???????E???RasPppoe?????f?k?k?k?????k???????k???0??e2???????????????|??????????btusbflt?????????{???????k???3??? ???????????p???????u??? ???????????????????????v???????????.???i???????????h??t???UMB\UMBUS????????????4???t???????????????u????????????????????????N??k???/??????????PEAUTH???/???????k???????????????k??? ???????k???????????k?,???????????? ???????E???LegacyDriver????????????????????????????????????????????????????????????????LegacyDriver?????????k???????????????????e?????????|?|???|???????????????|?????? ??????????s?????????i????????????s??????????p???????{??????????????????N????v???????k???k?????????????????s??????????????????????X??????,???Z???k??? ???????k???????????k?,?????????? ?????????????LegacyDriver?????????????4???????????`????????????>??l?????g???????????????????????????????????????????k?{???????{???k?k?k?k?k???k??? l????????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Export ???k?p??PEAUTH??????? ???????k???????????j?,????????Z????????????????u??????????6???MS_RFCOMM??????k?&???????????????????????k???????e??ROOT\VOLMGR?????????????????????????????????????????????????????????????sg???k???k?k?k?k?k???k???k???k???????k??????????VgaSave??8???????????????????????k???????????????????????k??? ???????k?????k?????k?,?????????????????????E???????????????????t??? ???????k???????????j?,????????b????????????????????????????????g?j?k?k???????????k?&???i?j?l?l????????????????s?????P??s?????????n?????????f???9???e??{4d36e972-e325-11ce-bfc1-08002be10318}???????????????????????????{??PNP_TDI?????????????? ?????s?-????Z??o?????????e??????N??}???????????????????????????????????????k???k??? ???????k???????????k?,?????????????????????????????????0???}???????????????????????????????????{??????????????ta??????*6to4mp?????? ???????k?????k?????k?,??????????=? ??????????????????????????????????k?&???k?k?????????????4??????40???k?k?k?k?k?k?k???k??????????????? ???????k???????????k?,????????\??????????????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Bind ???W?p???????2???;???;???????W??System?8????????????e529be5c????? ???????W?????W?????W?,??4?????8????????????s??? 8??W??????????r???Windows NT Access Provider?????????W????? ???????W???????????W?,????????D?????????????????????????D??W??????????????%SystemRoot%\system32\ntmarta.dll??????W????? ???????W?????W???????0????????????????t??????W?????W??? ???????W???????????W?0???????????????????y????? ???W??????????D???????????????????????????AuditPolicySD????? ??????????????????????? ?????????????????p?????????????????????????????????????????????????????????@?????????????????????????????????????? ???????W?????W???????0?????????????????????g?????W???W????? ???????W??????????????????????????????????? ???????W?????W?????W?0?????????????????p??? ??????????????????? ???V???0??????????? ???????W?????W???????0??R?????????????????????? ???????W?????????????0?????????????????????????s??????????? ???????W?????????????0????????????????????????????n???????????????? ???????W?????????????0????????????#??????????????????y???????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Route ???l?o???????e???????????????p??????????????????????????????????11??????????????????????????????? ???????k?????l?????k?,??????????X? ???????Dt???????????r??tO??????? ???????l???????????k?,????????\????????????g?g?h?h?h?h?k?l?k?l?l???l?l?p?????l?&??{4d36e972-e325-11ce-bfc1-08002be10318}???????????l???0???2????2??{????????h????????????????????????????????????????????l?|???????????????????3???????f?i?k?l?l?l?l????????????X?????????????????????ms_sstpminiport?????????????????????? ???????k???????????k?,??????????Y? ???????0?????6??n????????h??????i?j????????6944?????????????l???????5??{4d36e972-e325-11ce-bfc1-08002be10318}??????@netsstpa.inf,%msft%;Microsoft??????{36fc9e60-c465-11cf-8056-444553540000}????????`?????????????????t????????l???a??pv???????????????2???????2?????l???l????{4d36e972-e325-11ce-bfc1-08002be10318}\0008??????????????l?l????????????? ???????k???????????k?,??????????Z? ???????X????????l??????????ms_ndiswanipv6??ms???????????v???????????l??????????Microsoft????l?l???????????????????????????????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Export ???l?|???????????????????3???????f?i?k?l?l?l?l????????????X?????????????????????ms_sstpminiport?????????????????????? ???????k???????????k?,??????????Y? ???????0?????6??n????????h??????i?j????????6944?????????????l???????5??{4d36e972-e325-11ce-bfc1-08002be10318}??????@netsstpa.inf,%msft%;Microsoft??????{36fc9e60-c465-11cf-8056-444553540000}????????`?????????????????t????????l???a??pv???????????????2???????2?????l???l????{4d36e972-e325-11ce-bfc1-08002be10318}\0008??????????????l?l????????????? ???????k???????????k?,??????????Z? ???????X????????l??????????ms_ndiswanipv6??ms???????????v???????????l??????????Microsoft????l?l?????????????????????????????????????l?lFF??????????????ms??????????????t???? ???????l?????l???????1????????????&???????????????????????? ???????l?????l???????1?????????????????????????????????????l?l???????l?&???l???l???????????????????????????????????l??????????????? ???????k?????l?????k?,??????????[?????????D????`?`?????????????2??? ???????l???????????k?,????????P????????/??ms_pppoeminipor
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA2 0x23 0xB7 0x9E ...
---- EOF - GMER 1.0.15 ----
OTL
- Kod: Zaznacz wszystko
OTL logfile created on: 03.03.2011 18:05:11 - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\samsung\Desktop
Starter Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Polen | Language: PLK | Date Format: yyyy-MM-dd
1.013,00 Mb Total Physical Memory | 35,00 Mb Available Physical Memory | 3,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 45,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 58,59 Gb Total Space | 40,52 Gb Free Space | 69,16% Space Free | Partition Type: NTFS
Drive D: | 159,19 Gb Total Space | 158,91 Gb Free Space | 99,82% Space Free | Partition Type: NTFS
Computer Name: SAMSUNG-PC | User Name: samsung | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2011.03.03 17:45:30 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\samsung\Desktop\OTL.exe
PRC - [2010.12.12 08:56:19 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2010.11.14 12:28:33 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010.11.14 12:28:28 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.07.12 17:32:48 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe
PRC - [2010.06.16 10:57:22 | 000,835,952 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2010.04.16 08:18:34 | 000,173,352 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
PRC - [2010.02.09 06:51:04 | 002,500,096 | ---- | M] (Vodafone) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
PRC - [2010.02.09 06:50:50 | 000,009,216 | ---- | M] (Vodafone) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
PRC - [2010.01.19 03:34:48 | 002,201,192 | ---- | M] (SEC) -- C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
PRC - [2010.01.14 21:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.12.21 02:15:30 | 000,838,656 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.10.26 12:53:14 | 000,091,136 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
PRC - [2009.10.13 11:03:04 | 000,716,800 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
PRC - [2009.10.02 09:48:26 | 002,364,704 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
PRC - [2009.10.02 09:48:26 | 000,795,936 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2009.10.02 09:48:26 | 000,595,232 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
PRC - [2009.09.30 07:59:26 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.07.22 03:11:56 | 000,390,272 | ---- | M] (Bytemobile, Inc.) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\bmctl.exe
PRC - [2009.07.14 02:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2009.03.05 10:54:50 | 000,311,296 | ---- | M] () -- C:\Windows\System32\Rezip.exe
PRC - [2009.02.23 03:48:50 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
[color=#E56717]========== Modules (SafeList) ==========[/color]
MOD - [2011.03.03 17:45:30 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\samsung\Desktop\OTL.exe
MOD - [2010.08.21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - [2010.12.12 08:56:19 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010.11.14 12:28:33 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.04.16 08:18:34 | 000,173,352 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5)
SRV - [2010.02.09 06:50:50 | 000,009,216 | ---- | M] (Vodafone) [Auto | Running] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2009.10.02 09:48:26 | 000,595,232 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2009.07.14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.03.05 10:54:50 | 000,311,296 | ---- | M] () [Auto | Running] -- C:\Windows\System32\Rezip.exe -- (Rezip)
SRV - [2009.02.23 03:48:50 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2010.12.20 21:30:55 | 000,135,096 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2010.12.04 10:36:15 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.01.15 03:09:52 | 000,068,608 | ---- | M] (Samsung) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\samsung_hspa_datacard_cdc_acm.sys -- (samsung_hspa_datacard_cdc_acm)
DRV - [2010.01.15 03:09:52 | 000,062,464 | ---- | M] (Samsung) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\samsung_hspa_datacard_dc_enum.sys -- (samsung_hspa_datacard_dc_enum)
DRV - [2010.01.15 03:09:50 | 000,081,920 | ---- | M] (Samsung) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\samsung_hspa_datacard_cdc_ecm.sys -- (samsung_hspa_datacard_cdc_ecm)
DRV - [2009.11.06 21:53:58 | 001,227,776 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009.09.28 10:22:00 | 000,315,392 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk62x86.sys -- (yukonw7)
DRV - [2009.07.22 03:11:50 | 000,024,192 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2009.07.14 00:53:40 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rmcast.sys -- (RMCAST)
DRV - [2009.07.14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009.07.01 21:46:20 | 000,043,944 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btusbflt.sys -- (btusbflt)
DRV - [2009.05.11 09:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.vodafonelive.de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=15003&l=dis
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
FF - HKLM\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\addon\ [2010.03.29 09:41:06 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - Startup: C:\Users\samsung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.100
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{18051340-5ed9-11df-8f40-506313b915b0}\Shell - "" = AutoRun
O33 - MountPoints2\{18051340-5ed9-11df-8f40-506313b915b0}\Shell\AutoRun\command - "" = E:\start.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2011.03.03 17:45:30 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Users\samsung\Desktop\OTL.exe
[2011.03.03 16:23:21 | 000,590,392 | ---- | C] (Duplex Secure Ltd.) -- C:\Users\samsung\Desktop\SPTDinst-v177-x86.exe
[2011.02.28 20:56:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011.02.28 20:54:36 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\javaws.exe
[2011.02.28 20:54:36 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\javaw.exe
[2011.02.28 20:54:36 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\windows\System32\java.exe
[2011.02.28 20:52:26 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2011.02.22 21:29:26 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XpsPrint.dll
[2011.02.22 21:29:24 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XpsGdiConverter.dll
[2011.02.10 19:04:34 | 002,329,088 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\win32k.sys
[2011.02.10 19:04:27 | 000,219,008 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\drivers\dxgmms1.sys
[2011.02.10 19:04:12 | 000,294,400 | ---- | C] (Adobe Systems Incorporated) -- C:\windows\System32\atmfd.dll
[2011.02.10 19:04:11 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\windows\System32\atmlib.dll
[2011.02.10 19:03:24 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeeds.dll
[2011.02.10 19:03:23 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iedkcs32.dll
[2011.02.10 19:03:22 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mstime.dll
[2011.02.10 19:03:21 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iepeers.dll
[2011.02.10 19:03:21 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedsbs.dll
[2011.02.10 19:03:21 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\licmgr10.dll
[2011.02.10 19:03:20 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedssync.exe
[2011.02.10 19:03:19 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mshtml.tlb
[2011.02.10 19:03:19 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\html.iec
[2011.02.10 19:02:58 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jscript.dll
[2011.02.10 19:02:58 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\vbscript.dll
[2011.02.10 19:02:50 | 003,901,824 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ntoskrnl.exe
[2011.02.10 19:02:49 | 003,957,120 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ntkrnlpa.exe
[2011.02.10 19:02:30 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\upnp.dll
[2011.02.10 19:02:21 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\davclnt.dll
[2011.02.10 19:02:21 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\wscapi.dll
[2011.02.10 19:02:20 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\slwga.dll
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2011.03.03 18:03:14 | 000,001,038 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.03.03 18:03:14 | 000,001,034 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.03.03 17:45:30 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\samsung\Desktop\OTL.exe
[2011.03.03 16:45:31 | 000,296,448 | ---- | M] () -- C:\Users\samsung\Desktop\9xkeec4m.exe
[2011.03.03 16:41:33 | 000,010,272 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.03.03 16:41:33 | 000,010,272 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.03.03 16:40:22 | 000,747,220 | ---- | M] () -- C:\windows\System32\perfh015.dat
[2011.03.03 16:40:22 | 000,667,948 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2011.03.03 16:40:22 | 000,153,710 | ---- | M] () -- C:\windows\System32\perfc015.dat
[2011.03.03 16:40:22 | 000,126,338 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2011.03.03 16:32:41 | 000,016,384 | ---- | M] () -- C:\windows\System32\Ikeext.etl
[2011.03.03 16:32:11 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2011.03.03 16:32:05 | 1062,518,784 | -HS- | M] () -- C:\hiberfil.sys
[2011.03.03 16:26:53 | 227,515,653 | ---- | M] () -- C:\windows\MEMORY.DMP
[2011.03.03 16:23:22 | 000,590,392 | ---- | M] (Duplex Secure Ltd.) -- C:\Users\samsung\Desktop\SPTDinst-v177-x86.exe
[2011.02.11 12:54:52 | 000,405,704 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2011.02.10 18:59:26 | 000,001,172 | ---- | M] () -- C:\Users\samsung\Desktop\Prawo Jazdy ABCDT - egzamin wewnętrzny.lnk
[2011.02.03 06:45:07 | 000,219,008 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\drivers\dxgmms1.sys
[2011.02.02 21:40:39 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\javaws.exe
[2011.02.02 21:40:38 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\javaw.exe
[2011.02.02 21:40:36 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\java.exe
[2011.02.02 21:40:23 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\windows\System32\deployJava1.dll
[2011.02.02 17:11:20 | 000,222,080 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\MpSigStub.exe
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2011.03.03 16:45:31 | 000,296,448 | ---- | C] () -- C:\Users\samsung\Desktop\9xkeec4m.exe
[2010.05.14 01:08:19 | 000,337,158 | ---- | C] () -- C:\windows\System32\perfi015.dat
[2010.05.14 01:08:17 | 000,747,220 | ---- | C] () -- C:\windows\System32\perfh015.dat
[2010.05.14 01:08:17 | 000,153,710 | ---- | C] () -- C:\windows\System32\perfc015.dat
[2010.05.14 01:08:17 | 000,038,710 | ---- | C] () -- C:\windows\System32\perfd015.dat
[2010.05.13 20:09:10 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.05.13 19:57:04 | 000,165,376 | ---- | C] () -- C:\windows\System32\unrar.dll
[2010.05.13 19:56:58 | 000,000,038 | ---- | C] () -- C:\windows\avisplitter.ini
[2010.05.13 19:56:25 | 000,881,664 | ---- | C] () -- C:\windows\System32\xvidcore.dll
[2010.05.13 19:56:24 | 000,205,824 | ---- | C] () -- C:\windows\System32\xvidvfw.dll
[2010.05.13 19:56:17 | 003,596,288 | ---- | C] () -- C:\windows\System32\qt-dx331.dll
[2010.05.13 19:56:04 | 000,085,504 | ---- | C] () -- C:\windows\System32\ff_vfw.dll
[2010.03.29 08:49:42 | 000,000,455 | ---- | C] () -- C:\windows\HotFixList.ini
[2010.03.29 08:36:09 | 000,311,296 | ---- | C] () -- C:\windows\System32\Rezip.exe
[2010.02.04 06:04:40 | 000,154,904 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2009.07.14 05:57:37 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat
[2009.07.14 05:33:53 | 000,405,704 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2009.07.14 03:05:48 | 000,667,948 | ---- | C] () -- C:\windows\System32\perfh009.dat
[2009.07.14 03:05:48 | 000,291,294 | ---- | C] () -- C:\windows\System32\perfi009.dat
[2009.07.14 03:05:48 | 000,126,338 | ---- | C] () -- C:\windows\System32\perfc009.dat
[2009.07.14 03:05:48 | 000,031,548 | ---- | C] () -- C:\windows\System32\perfd009.dat
[2009.07.14 03:05:05 | 000,000,741 | ---- | C] () -- C:\windows\System32\NOISE.DAT
[2009.07.14 03:04:11 | 000,215,943 | ---- | C] () -- C:\windows\System32\dssec.dat
[2009.07.14 00:55:01 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2009.07.14 00:51:43 | 000,073,728 | ---- | C] () -- C:\windows\System32\BthpanContextHandler.dll
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\windows\System32\BWContextHandler.dll
[2009.07.13 23:09:19 | 000,982,196 | ---- | C] () -- C:\windows\System32\igkrng500.bin
[2009.07.13 23:09:19 | 000,417,344 | ---- | C] () -- C:\windows\System32\igcompkrng500.bin
[2009.07.13 23:09:19 | 000,139,824 | ---- | C] () -- C:\windows\System32\igfcg500.bin
[2009.07.13 23:09:19 | 000,097,448 | ---- | C] () -- C:\windows\System32\igfcg500m.bin
[2009.06.10 22:26:10 | 000,673,088 | ---- | C] () -- C:\windows\System32\mlang.dat
[2009.04.09 07:47:02 | 000,013,824 | ---- | C] () -- C:\windows\System32\CallSimReader.dll
[2009.04.09 07:46:02 | 000,055,808 | ---- | C] () -- C:\windows\System32\SimReader.dll
< End of report >
OTL extras
- Kod: Zaznacz wszystko
OTL Extras logfile created on: 03.03.2011 18:05:11 - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\samsung\Desktop
Starter Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Polen | Language: PLK | Date Format: yyyy-MM-dd
1.013,00 Mb Total Physical Memory | 35,00 Mb Available Physical Memory | 3,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 45,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 58,59 Gb Total Space | 40,52 Gb Free Space | 69,16% Space Free | Partition Type: NTFS
Drive D: | 159,19 Gb Total Space | 158,91 Gb Free Space | 99,82% Space Free | Partition Type: NTFS
Computer Name: SAMSUNG-PC | User Name: samsung | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Extra Registry (SafeList) ==========[/color]
[color=#E56717]========== File Associations ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\windows\winhlp32.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)
[color=#E56717]========== Shell Spawning ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Opera\opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files\Opera\opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[color=#E56717]========== Security Center Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[color=#E56717]========== Firewall Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[color=#E56717]========== Authorized Applications List ==========[/color]
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{028ED9C4-25EE-4DEE-9CF4-91034BC89B18}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution 4
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{178EE5F4-0F86-4BF0-A0D1-9790AFF409D1}" = EasyBatteryManager
"{1D1D8ADC-BF08-4E61-9393-5FA305B16864}" = Microsoft SQL Server Native Client
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 24
"{27A34859-3E29-438B-BBF6-19BDC6CA9C06}" = Samsung HSPA DataCard 4.3.29.7814
"{2BA722D1-48D1-406E-9123-8AE5431D63EF}" = Windows Live Fotogalerie
"{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EFEF049-23D4-4B46-8903-4592FEA51018}" = Windows Live Movie Maker
"{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{45535A5E-1F81-4F35-BE1D-43D10A7D03B4}" = Easy Resolution Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4cb9f93c-9edc-4be9-ae61-af128ddbecfa}" = Business Contact Manager für Outlook 2007 SP2
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent
"{5C759B74-34F4-43C6-A5D9-039CB754C5E9}" = Microsoft SQL Server VSS Writer
"{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call
"{76618402-179D-4699-A66B-D351C59436BC}" = Windows Live Sync
"{853F8A41-A3C9-43FA-87FA-1AE74FC6F3F7}" = BatteryLifeExtender
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C825992-6005-42DF-8836-8A42B23D2FFA}" = Internet Explorer
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_PROHYBRIDR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_PROHYBRIDR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_PROHYBRIDR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_PROHYBRIDR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90A40407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92D50865-FC60-4EA8-BA7A-5581B0D13EFB}" = ChargeableUSB
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1031-7B44-A91000000001}" = Adobe Reader 9.1 - Deutsch
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{BF37F514-3E5E-4F59-9E75-196A073E2089}" = Vodafone Mobile Connect
"{C441297F-C9F2-4177-9D5F-1B10F0358E32}" = Opera 10.54
"{C4D738F7-996A-4C81-B8FA-C4E26D767E41}" = Windows Live Mail
"{CCC2B140-B47A-45FA-AAE3-BD60DA41AE00}" = Samsung Support Center
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1434266-0486-4469-B338-A60082CC04E1}" = Atheros Client Installation Program
"{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}" = Samsung Update Plus
"{E0A4805D-280A-4DD7-9E74-3A5F85E302A1}" = Windows Live Writer
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2BC3383-F000-410C-A038-3846ADBE8D90}" = REALTEK Wireless LAN Software
"{F40963EC-223E-4E65-8CF0-A60E9A227245}_is1" = Prawo Jazdy ABCDT - egzamin wewnętrzny
"{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials
"755087041320E005CB1E8A67C5C55A260EB81B90" = Windows Driver Package - Broadcom Bluetooth (09/11/2009 6.2.0.9407)
"A6A8668C0A13640CA28FE2A7D9654BE4AE478B13" = Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405)
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BF20603967CFDCB2BBF91950E8A56DFBC5C833FE" = Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800)
"Business Contact Manager" = Business Contact Manager für Outlook 2007 SP2
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"KaraFun_is1" = KaraFun 1.18
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.9.0
"Marvell Miniport Driver" = Marvell Miniport Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"PROHYBRIDR" = 2007 Microsoft Office system
"SopCast" = SopCast 3.2.9
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamViewer 5" = TeamViewer 5
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = Archiwizator WinRAR
[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Detector Plug-in
[color=#E56717]========== Last 10 Event Log Errors ==========[/color]
[ Application Events ]
Error - 18.02.2011 11:41:37 | Computer Name = samsung-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Nie można wyodrębnić listy głównej innych firm z pliku cab automatycznej
aktualizacji z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>,
wystąpił błąd: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji
bieżącego zegara systemowego lub sygnatury czasowej. .
Error - 19.02.2011 06:57:39 | Computer Name = samsung-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Nie można wyodrębnić listy głównej innych firm z pliku cab automatycznej
aktualizacji z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>,
wystąpił błąd: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji
bieżącego zegara systemowego lub sygnatury czasowej. .
Error - 19.02.2011 06:57:39 | Computer Name = samsung-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Nie można wyodrębnić listy głównej innych firm z pliku cab automatycznej
aktualizacji z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>,
wystąpił błąd: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji
bieżącego zegara systemowego lub sygnatury czasowej. .
Error - 19.02.2011 08:06:56 | Computer Name = samsung-PC | Source = VMCService | ID = 0
Description = GetProcessOwner
Error - 19.02.2011 15:06:54 | Computer Name = samsung-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Nie można wyodrębnić listy głównej innych firm z pliku cab automatycznej
aktualizacji z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>,
wystąpił błąd: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji
bieżącego zegara systemowego lub sygnatury czasowej. .
Error - 19.02.2011 15:06:55 | Computer Name = samsung-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Nie można wyodrębnić listy głównej innych firm z pliku cab automatycznej
aktualizacji z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>,
wystąpił błąd: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji
bieżącego zegara systemowego lub sygnatury czasowej. .
Error - 20.02.2011 11:46:36 | Computer Name = samsung-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Nie można wyodrębnić listy głównej innych firm z pliku cab automatycznej
aktualizacji z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>,
wystąpił błąd: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji
bieżącego zegara systemowego lub sygnatury czasowej. .
Error - 20.02.2011 11:46:36 | Computer Name = samsung-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Nie można wyodrębnić listy głównej innych firm z pliku cab automatycznej
aktualizacji z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>,
wystąpił błąd: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji
bieżącego zegara systemowego lub sygnatury czasowej. .
Error - 20.02.2011 14:05:56 | Computer Name = samsung-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Nie można wyodrębnić listy głównej innych firm z pliku cab automatycznej
aktualizacji z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>,
wystąpił błąd: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji
bieżącego zegara systemowego lub sygnatury czasowej. .
Error - 20.02.2011 14:05:56 | Computer Name = samsung-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Nie można wyodrębnić listy głównej innych firm z pliku cab automatycznej
aktualizacji z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>,
wystąpił błąd: Wymagany certyfikat jest poza okresem ważności, co wynika z weryfikacji
bieżącego zegara systemowego lub sygnatury czasowej. .
[ System Events ]
Error - 09.12.2010 14:32:45 | Computer Name = samsung-PC | Source = NetBT | ID = 4307
Description = Zainicjowanie nie powiodło się, ponieważ transport odmówił otwarcia
adresów początkowych.
Error - 10.12.2010 01:19:50 | Computer Name = samsung-PC | Source = EventLog | ID = 6008
Description = Poprzednie zamknięcie systemu przy 05:52:45 na ?2010-?12-?10 było
nieoczekiwane.
Error - 13.12.2010 13:31:39 | Computer Name = samsung-PC | Source = NetBT | ID = 4321
Description = Nie można zarejestrować nazwy „WORKGROUP :1d” w interfejsie o
adresie IP 192.168.1.101. Komputer o adresie IP 192.168.1.102 nie zezwolił na przejęcie
tej nazwy przez ten komputer.
Error - 05.01.2011 08:06:05 | Computer Name = samsung-PC | Source = EventLog | ID = 6008
Description = Poprzednie zamknięcie systemu przy 12:46:20 na ?2011-?01-?05 było
nieoczekiwane.
Error - 05.01.2011 08:06:12 | Computer Name = SAMSUNG-PC | Source = BugCheck | ID = 1001
Description =
Error - 11.01.2011 15:50:32 | Computer Name = samsung-PC | Source = Service Control Manager | ID = 7011
Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na odpowiedź transakcji
z usługi Wlansvc.
Error - 12.01.2011 13:56:13 | Computer Name = samsung-PC | Source = DCOM | ID = 10010
Description =
Error - 17.01.2011 16:04:50 | Computer Name = samsung-PC | Source = Service Control Manager | ID = 7011
Description = Upłynął limit czasu (30000 ms) podczas oczekiwania na odpowiedź transakcji
z usługi ShellHWDetection.
Error - 17.01.2011 16:07:50 | Computer Name = samsung-PC | Source = EventLog | ID = 6008
Description = Poprzednie zamknięcie systemu przy 21:06:23 na ?2011-?01-?17 było
nieoczekiwane.
Error - 17.01.2011 16:07:57 | Computer Name = SAMSUNG-PC | Source = BugCheck | ID = 1001
Description =
< End of report >