combofix mi nie dziala. sciagnalem avangera ale nie umiem zrobic w nim loga pomocy!!!
Na samym starcie dajemy loga z RSITA lub z DSS lub OTListIt 2. wklejamy je na forum w tagach code.
OTListIt logfile created on: 2009-05-17 17:29:54 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\User\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
1,99 Gb Total Physical Memory | 1,58 Gb Available Physical Memory | 79,49% Memory free
3,33 Gb Paging File | 3,02 Gb Available in Paging File | 90,68% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39,06 Gb Total Space | 24,45 Gb Free Space | 62,61% Space Free | Partition Type: NTFS
Drive D: | 39,07 Gb Total Space | 8,29 Gb Free Space | 21,22% Space Free | Partition Type: NTFS
Drive E: | 70,92 Gb Total Space | 48,10 Gb Free Space | 67,82% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
Drive G: | 1,80 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive H: | 609,95 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
I: Drive not present or media not loaded
Computer Name: BARTEKLAP
Current User Name: User
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2008-04-18 14:53:58 | 00,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
PRC - [2008-03-27 19:28:50 | 01,048,576 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2008-05-22 22:40:28 | 00,166,424 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\hkcmd.exe
PRC - [2008-05-22 22:40:38 | 00,137,752 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\igfxpers.exe
PRC - [2008-05-22 22:40:40 | 00,256,536 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\igfxsrvc.exe
PRC - [2007-01-05 18:36:48 | 00,880,640 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
PRC - [2009-02-11 11:12:46 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008-11-02 10:38:58 | 00,176,128 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2006-11-03 12:01:16 | 00,327,680 | ---- | M] (PixArt Imaging Incorporation) -- C:\WINDOWS\PixArt\PAC7302\Monitor.exe
PRC - [2008-03-20 12:04:46 | 02,127,296 | ---- | M] (Gadu-Gadu S.A.) -- D:\Program Files\Gadu-Gadu\gg.exe
PRC - [2009-05-06 18:27:07 | 00,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008-08-19 09:47:38 | 01,795,656 | ---- | M] (FLASHGET) -- E:\FlashGet universal\FlashGet.exe
PRC - [2008-03-18 17:27:12 | 00,020,480 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe
PRC - [2008-04-18 14:54:02 | 00,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
PRC - [2009-02-11 11:12:46 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009-02-26 10:49:18 | 00,106,496 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2008-06-27 17:36:58 | 01,432,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2009-05-17 17:29:44 | 00,509,440 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2008-03-18 17:27:12 | 00,020,480 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio [Auto | Running])
SRV - File not found -- -- (ALG [On_Demand | Stopped])
SRV - [2007-10-24 02:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2007-10-24 02:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009-05-06 18:27:07 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2008-04-18 14:54:02 | 00,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON [Auto | Running])
SRV - [2009-02-11 11:12:46 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2007-05-28 18:57:54 | 00,283,136 | ---- | M] (Rocket Division Software) -- D:\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE [Auto | Stopped])
SRV - [2006-12-01 13:46:28 | 00,925,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2008-04-24 15:28:08 | 00,281,600 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService [On_Demand | Running])
DRV - [2007-07-13 11:26:12 | 00,094,976 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\drivers\AEAudio.sys -- (AEAudio [On_Demand | Running])
DRV - [2008-03-21 17:13:00 | 01,203,776 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\DRIVERS\AGRSM.sys -- (AgereSoftModem [On_Demand | Running])
DRV - [2009-01-24 01:00:05 | 01,287,552 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\DRIVERS\bcmwl5.sys -- (BCM43XX [On_Demand | Running])
DRV - [2008-06-16 15:28:36 | 00,242,320 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\DRIVERS\e1e5132.sys -- (e1express [On_Demand | Running])
DRV - [2008-08-05 13:56:27 | 00,007,808 | R--- | M] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\system32\DRIVERS\eabfiltr.sys -- (eabfiltr [On_Demand | Stopped])
DRV - [2008-08-05 13:56:27 | 00,005,760 | R--- | M] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\system32\DRIVERS\eabusb.sys -- (eabusb [On_Demand | Stopped])
DRV - [2008-08-05 13:56:27 | 00,009,344 | R--- | M] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\system32\DRIVERS\cpqbttn.sys -- (HBtnKey [On_Demand | Running])
DRV - [2008-07-18 02:34:58 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2008-03-17 22:45:50 | 05,955,872 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\DRIVERS\igxpmp32.sys -- (ialm [On_Demand | Running])
DRV - [2008-04-15 18:53:44 | 00,312,344 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\DRIVERS\iaStor.sys -- (iaStor [Boot | Running])
DRV - [2007-09-10 09:50:56 | 00,457,984 | ---- | M] (PixArt Imaging Inc.) -- C:\WINDOWS\system32\DRIVERS\PAC7302.SYS -- (PAC7302 [On_Demand | Stopped])
DRV - [2008-06-16 15:28:36 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008-11-02 10:44:10 | 00,056,572 | ---- | M] (PowerISO Computing, Inc.) -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu [System | Running])
DRV - [2008-06-16 15:28:36 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2008-06-16 15:28:36 | 00,062,208 | ---- | M] (Silicon Image, Inc.) -- C:\WINDOWS\System32\drivers\si3112.sys -- (Si3112 [Boot | Stopped])
DRV - [2009-05-08 09:59:13 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2008-03-27 19:14:06 | 00,224,672 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\DRIVERS\SynTP.sys -- (SynTP [On_Demand | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.google.com/toolbar/ie8/intl/pl/done.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009-02-11 11:12:46 | 00,000,000 | ---D | M]
O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 NtKrnlpa.info
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (FG2CatchUrl) - {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} - E:\FlashGet universal\ComDlls\bhoCATCH.dll (FlashGet)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [FlashGet] "E:\FlashGet universal\FlashGet.exe" /min (FLASHGET)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [AlcoholAutomount] "D:\Alcohol 120\axcmd.exe" /automount (Alcohol Soft Development Team)
O4 - HKCU..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" ()
O4 - HKCU..\Run: [FlashGet] "E:\FlashGet universal\FlashGet.exe" /min (FLASHGET)
O4 - HKCU..\Run: [Gadu-Gadu] "D:\Program Files\Gadu-Gadu\gg.exe" /tray (Gadu-Gadu S.A.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MaxRecentDocs = 15
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &Download All by FlashGet - E:\FlashGet universal\ComDlls\Bhoall.htm ()
O8 - Extra context menu item: &Download by FlashGet - E:\FlashGet universal\ComDlls\Bholink.htm ()
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windows ... 2753346448 (WUWebControl Class)
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-01.sun.com/s/ESD7/JSCDL/ ... 586-jc.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{BCFAB08F-6A08-4814-8C80-FBF0EACB619E}\\NameServer = 172.16.1.1,172.16.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{E2F11D32-17D2-4E6E-A3CA-254394DE9D68}\\NameServer = 172.16.1.1,172.16.2.1
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (%SystemRoot%\system32\logonui.exe) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Bieżąca strona główna) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-01-24 00:40:38 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001-03-01 10:05:20 | 00,000,079 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ]
O32 - AutoRun File - [1998-12-08 05:36:38 | 00,712,704 | R--- | M] () - H:\Autoplay.exe -- [ CDFS ]
O32 - AutoRun File - [1998-11-25 17:23:22 | 00,000,053 | R--- | M] () - H:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{44e39e44-105a-11de-afe0-002100861f7c}\Shell\AutoRun\command - "" = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{44e39e44-105a-11de-afe0-002100861f7c}\Shell\open\command - "" = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{4bdd3d94-e9a0-11dd-af66-0022646c118a}\Shell\AutoRun\command - "" = G:\iq.bat -- File not found
O33 - MountPoints2\{4bdd3d94-e9a0-11dd-af66-0022646c118a}\Shell\open\Command - "" = G:\iq.bat -- File not found
O33 - MountPoints2\{64940d4c-3008-11de-b02b-002100861f7c}\Shell\AutoRun\command - "" = K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{64940d4c-3008-11de-b02b-002100861f7c}\Shell\open\command - "" = K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{66f4eaca-f5fb-11dd-af7a-002100861f7c}\Shell\AutoRun\command - "" = K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{66f4eaca-f5fb-11dd-af7a-002100861f7c}\Shell\open\command - "" = K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{90350e85-3a6c-11de-b040-0022646c118a}\Shell\AutoRun\command - "" = RECYCLER\autorun.exe
O33 - MountPoints2\{90350e85-3a6c-11de-b040-0022646c118a}\Shell\open\command - "" = RECYCLER\autorun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\FalloutTacticsLauncher.exe -- [2001-03-06 05:31:10 | 00,479,232 | R--- | M] ()
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\autoplay.exe -- [1998-12-08 05:36:38 | 00,712,704 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009-05-17 17:29:37 | 00,000,000 | ---D | M]
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009-05-17 17:29:37 | 00,509,440 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe
[2009-05-17 16:57:40 | 00,000,000 | ---D | C] -- C:\Avenger
[2009-05-17 16:56:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Pulpit\avenger
[2009-05-17 16:52:21 | 00,724,952 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\avenger.zip
[2009-05-17 16:49:05 | 00,404,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF22301.exe
[2009-05-17 16:49:05 | 00,000,000 | ---D | C] -- C:\ComboFix
[2009-05-17 16:48:36 | 00,404,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF22203.exe
[2009-05-17 16:48:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009-05-17 16:36:55 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009-05-15 11:44:25 | 00,073,107 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\oplaty_za_studia_niestacjonarne.pdf
[2009-05-14 23:35:58 | 00,099,862 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\196878801 _ Gaia.rep
[2009-05-13 08:58:03 | 00,065,641 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\CV Bartosz Gawroński.pdf
[2009-05-13 08:55:08 | 00,000,043 | ---- | C] () -- C:\WINDOWS\gswin32.ini
[2009-05-12 08:01:35 | 00,115,300 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\IMG_5103.JPG
[2009-05-11 14:08:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Pulpit\MWC03-finals
[2009-05-10 20:05:57 | 12,734,754 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\Myth2_160.exe
[2009-05-10 19:52:11 | 00,562,619 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\MWC03-finals.zip
[2009-05-10 18:26:37 | 00,000,000 | ---D | C] -- C:\Program Files\Myth II
[2009-05-10 18:25:33 | 00,026,658 | ---- | C] () -- C:\WINDOWS\_detmp.1
[2009-05-10 17:58:59 | 00,000,486 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\MYTH2.mds
[2009-05-10 17:57:01 | 73,452,4896 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\MYTH2.mdf
[2009-05-09 01:16:32 | 00,000,000 | ---D | C] -- C:\Program Files\ALLPlayer
[2009-05-08 10:01:37 | 00,000,473 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Alcohol 120%.lnk
[2009-05-08 09:59:13 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009-05-08 00:34:45 | 00,305,664 | ---- | C] (InstallShield Corporation, Inc.) -- C:\WINDOWS\uninst.exe
[2009-05-07 07:31:07 | 00,000,000 | ---D | C] -- C:\Program Files\ElcomSoft
[2009-05-07 07:30:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Pulpit\archpr
[2009-05-07 01:08:04 | 00,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2009-05-06 20:51:16 | 00,014,533 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\default
[2009-05-06 20:34:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Dane aplikacji\Google
[2009-05-06 18:27:18 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009-05-06 18:23:35 | 00,000,000 | -H-D | C] -- C:\WINDOWS\msdownld.tmp
[2009-05-06 18:23:35 | 00,000,000 | ---D | C] -- C:\Program Files\Google
[2009-05-06 18:23:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Google
[2009-05-06 18:02:15 | 00,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009-05-06 17:19:04 | 00,002,234 | ---- | C] () -- C:\WINDOWS\Opera.INI
[2009-05-06 17:19:04 | 00,000,000 | ---D | C] -- C:\plugin
[2009-05-06 17:14:08 | 00,000,000 | ---D | C] -- C:\Program Files\Opera
[2009-05-06 17:13:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2009-05-06 16:27:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Dane aplikacji\BITS
[2009-05-05 13:42:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Moje dokumenty\spidrmam
[2009-05-04 19:25:16 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2009-05-04 08:21:41 | 00,098,304 | ---- | C] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2009-05-04 08:20:12 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2009-05-03 15:50:38 | 00,038,560 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2009-05-03 15:50:01 | 00,038,560 | ---- | C] () -- C:\WINDOWS\System\zlib.dll
[2009-05-02 20:27:24 | 00,000,000 | ---D | C] -- C:\Program Files\NAPI-PROJEKT
[2009-04-27 20:14:09 | 00,000,104 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\Komputer.lnk
[2009-04-27 15:23:07 | 00,000,658 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\StarCraft Brood War.lnk
[2009-04-27 15:23:07 | 00,000,585 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\StarCraft Key Changer.lnk
[2009-04-27 11:14:32 | 98,259,105 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\moniscbw.exe
[2009-04-27 10:49:15 | 00,001,644 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\ICCup Launcher.lnk
[2009-04-27 10:49:15 | 00,000,000 | ---D | C] -- C:\Program Files\ICCup
[2009-04-23 18:05:54 | 00,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
[2009-04-23 18:05:54 | 00,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbscan.sys
[2009-04-23 18:05:54 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
[2009-04-23 16:43:25 | 00,000,000 | ---D | C] -- C:\WINDOWS\speech
[2009-04-23 16:43:15 | 00,000,000 | ---D | C] -- C:\Program Files\ivo
[2009-04-21 10:38:11 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Progs_.ini
[2009-04-21 10:38:11 | 00,000,000 | ---- | C] () -- C:\WINDOWS\1Way.ini
[2009-04-21 10:20:03 | 00,000,000 | ---D | C] -- C:\Program Files\gs
[2009-04-21 10:14:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Dane aplikacji\WordToPDF Pro
[2009-04-21 10:14:30 | 00,000,000 | ---D | C] -- C:\Program Files\WordToPDF Pro
[2009-04-21 10:04:02 | 00,000,000 | ---D | C] -- C:\Program Files\CZ-Doc2Pdf
[2009-04-21 09:59:36 | 00,000,000 | ---D | C] -- C:\Program Files\MSECache
[2009-04-21 09:42:06 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\User\Moje dokumenty\~$ Bartosz Gawroński.doc
[2009-04-21 09:41:50 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\User\Moje dokumenty\~$st_Motywacyjny..doc
[2009-04-21 09:41:43 | 00,039,936 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\CV Bartosz Gawroński.doc
[2009-04-21 09:41:43 | 00,025,600 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\List_Motywacyjny..doc
[2009-04-20 16:31:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Pulpit\mapy do fot
[2009-03-07 22:56:51 | 00,000,768 | ---- | C] () -- C:\WINDOWS\System32\Remover.ini
[2009-02-21 21:53:45 | 00,000,715 | ---- | C] () -- C:\WINDOWS\Stars.ini
[2009-02-15 19:16:29 | 00,000,129 | ---- | C] () -- C:\WINDOWS\festo.ini
[2009-02-11 13:55:05 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2009-02-11 13:55:05 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2009-02-11 13:55:05 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2009-02-08 17:25:05 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009-01-24 08:37:53 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009-01-24 08:37:51 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009-01-24 08:37:51 | 00,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009-01-24 08:37:51 | 00,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009-01-24 08:37:50 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009-01-24 08:37:50 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009-01-24 08:27:05 | 00,000,427 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009-01-24 01:04:21 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4935.dll
[2008-07-20 02:16:28 | 00,000,107 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2008-06-16 15:28:36 | 00,000,683 | ---- | C] () -- C:\WINDOWS\win.ini
[2008-06-16 15:28:36 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2007-03-20 17:44:02 | 00,000,566 | ---- | C] () -- C:\WINDOWS\System32\SP7302.ini
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009-05-17 17:29:44 | 00,509,440 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe
[2009-05-17 17:21:58 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-05-17 17:21:30 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-05-17 17:21:27 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\desktop.ini
[2009-05-17 17:21:25 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-05-17 17:21:19 | 21,383,61856 | -HS- | M] () -- C:\hiberfil.sys
[2009-05-17 16:56:22 | 00,724,952 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\avenger.zip
[2009-05-17 16:49:02 | 00,404,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF22301.exe
[2009-05-17 16:48:33 | 00,404,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF22203.exe
[2009-05-16 15:06:03 | 00,000,129 | ---- | M] () -- C:\WINDOWS\festo.ini
[2009-05-15 11:44:25 | 00,073,107 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\oplaty_za_studia_niestacjonarne.pdf
[2009-05-14 23:36:00 | 00,099,862 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\196878801 _ Gaia.rep
[2009-05-13 08:58:03 | 00,065,641 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\CV Bartosz Gawroński.pdf
[2009-05-13 08:57:50 | 00,039,936 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\CV Bartosz Gawroński.doc
[2009-05-13 08:55:08 | 00,000,043 | ---- | M] () -- C:\WINDOWS\gswin32.ini
[2009-05-11 22:40:19 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-05-10 20:10:22 | 12,734,754 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\Myth2_160.exe
[2009-05-10 19:52:28 | 00,562,619 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\MWC03-finals.zip
[2009-05-10 18:08:26 | 00,026,658 | ---- | M] () -- C:\WINDOWS\_detmp.1
[2009-05-08 10:01:37 | 00,000,473 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Alcohol 120%.lnk
[2009-05-08 09:59:13 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009-05-06 20:51:17 | 00,014,533 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\default
[2009-05-06 20:32:13 | 00,000,072 | -HS- | M] () -- C:\Documents and Settings\User\Moje dokumenty\desktop.ini
[2009-05-06 18:02:15 | 00,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2009-05-06 17:22:53 | 00,002,234 | ---- | M] () -- C:\WINDOWS\Opera.INI
[2009-05-04 08:21:41 | 00,098,304 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2009-04-28 08:21:19 | 00,000,658 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\StarCraft Brood War.lnk
[2009-04-28 08:21:19 | 00,000,585 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\StarCraft Key Changer.lnk
[2009-04-27 20:14:09 | 00,000,104 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\Komputer.lnk
[2009-04-27 15:08:43 | 98,259,105 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\moniscbw.exe
[2009-04-27 11:16:07 | 00,001,644 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\ICCup Launcher.lnk
[2009-04-21 10:38:11 | 00,000,000 | ---- | M] () -- C:\WINDOWS\Progs_.ini
[2009-04-21 10:38:11 | 00,000,000 | ---- | M] () -- C:\WINDOWS\1Way.ini
[2009-04-21 09:56:31 | 00,025,600 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\List_Motywacyjny..doc
[2009-04-21 09:51:31 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\User\Moje dokumenty\~$ Bartosz Gawroński.doc
[2009-04-21 09:41:50 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\User\Moje dokumenty\~$st_Motywacyjny..doc
[2009-04-20 16:37:02 | 00,002,533 | ---- | M] () -- C:\bos.cfg
< End of report >
:OTLI
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O32 - AutoRun File - [2001-03-01 10:05:20 | 00,000,079 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ]
O32 - AutoRun File - [1998-11-25 17:23:22 | 00,000,053 | R--- | M] () - H:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{44e39e44-105a-11de-afe0-002100861f7c}\Shell\AutoRun\command - "" = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{44e39e44-105a-11de-afe0-002100861f7c}\Shell\open\command - "" = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{4bdd3d94-e9a0-11dd-af66-0022646c118a}\Shell\AutoRun\command - "" = G:\iq.bat -- File not found
O33 - MountPoints2\{4bdd3d94-e9a0-11dd-af66-0022646c118a}\Shell\open\Command - "" = G:\iq.bat -- File not found
O33 - MountPoints2\{64940d4c-3008-11de-b02b-002100861f7c}\Shell\AutoRun\command - "" = K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{64940d4c-3008-11de-b02b-002100861f7c}\Shell\open\command - "" = K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{66f4eaca-f5fb-11dd-af7a-002100861f7c}\Shell\AutoRun\command - "" = K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{66f4eaca-f5fb-11dd-af7a-002100861f7c}\Shell\open\command - "" = K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{90350e85-3a6c-11de-b040-0022646c118a}\Shell\AutoRun\command - "" = RECYCLER\autorun.exe
O33 - MountPoints2\{90350e85-3a6c-11de-b040-0022646c118a}\Shell\open\command - "" = RECYCLER\autorun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
:Files
C:\WINDOWS\System32\CF22301.exe
C:\ComboFix
C:\WINDOWS\System32\CF22203.exe
C:\Qoobox
C:\WINDOWS\ERDNT
:Commands
[emptytemp]
[start explorer]
[Reboot]
OTListIt logfile created on: 2009-05-17 21:35:33 - Run 3
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\User\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
1,99 Gb Total Physical Memory | 1,49 Gb Available Physical Memory | 74,59% Memory free
3,33 Gb Paging File | 2,89 Gb Available in Paging File | 86,70% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39,06 Gb Total Space | 28,69 Gb Free Space | 73,45% Space Free | Partition Type: NTFS
Drive D: | 39,07 Gb Total Space | 10,54 Gb Free Space | 26,97% Space Free | Partition Type: NTFS
Drive E: | 70,92 Gb Total Space | 51,61 Gb Free Space | 72,78% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
Drive G: | 1,80 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive H: | 609,95 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
I: Drive not present or media not loaded
Computer Name: BARTEKLAP
Current User Name: User
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
[color=orange]========== Processes (SafeList) ==========[/color]
PRC - [2008-06-27 17:36:58 | 01,432,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2008-04-18 14:53:58 | 00,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
PRC - [2008-03-27 19:28:50 | 01,048,576 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2008-05-22 22:40:40 | 00,256,536 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\igfxsrvc.exe
PRC - [2008-05-22 22:40:28 | 00,166,424 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\hkcmd.exe
PRC - [2008-05-22 22:40:38 | 00,137,752 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\igfxpers.exe
PRC - [2007-01-05 18:36:48 | 00,880,640 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
PRC - [2008-01-11 23:16:00 | 00,039,792 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
PRC - [2009-02-11 11:12:46 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008-11-02 10:38:58 | 00,176,128 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2006-11-03 12:01:16 | 00,327,680 | ---- | M] (PixArt Imaging Incorporation) -- C:\WINDOWS\PixArt\PAC7302\Monitor.exe
PRC - [2008-03-20 12:04:46 | 02,127,296 | ---- | M] (Gadu-Gadu S.A.) -- D:\Program Files\Gadu-Gadu\gg.exe
PRC - [2009-05-06 18:27:07 | 00,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008-08-19 09:47:38 | 01,795,656 | ---- | M] (FLASHGET) -- E:\FlashGet universal\FlashGet.exe
PRC - [2008-03-18 17:27:12 | 00,020,480 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe
PRC - [2008-04-18 14:54:02 | 00,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
PRC - [2009-02-11 11:12:46 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009-03-08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\IEXPLORE.EXE
PRC - [2009-03-08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\IEXPLORE.EXE
PRC - [2009-02-11 11:12:46 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\java.exe
PRC - [2009-02-26 10:49:18 | 00,106,496 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2009-05-17 21:35:17 | 00,509,440 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe
[color=orange]========== Win32 Services (SafeList) ==========[/color]
SRV - [2008-03-18 17:27:12 | 00,020,480 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio [Auto | Running])
SRV - File not found -- -- (ALG [On_Demand | Stopped])
SRV - [2007-10-24 02:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2007-10-24 02:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009-05-06 18:27:07 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2008-04-18 14:54:02 | 00,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON [Auto | Running])
SRV - [2009-02-11 11:12:46 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2007-05-28 18:57:54 | 00,283,136 | ---- | M] (Rocket Division Software) -- D:\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE [Auto | Stopped])
SRV - [2006-12-01 13:46:28 | 00,925,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
[color=orange]========== Driver Services (SafeList) ==========[/color]
DRV - [2008-04-24 15:28:08 | 00,281,600 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService [On_Demand | Running])
DRV - [2007-07-13 11:26:12 | 00,094,976 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\drivers\AEAudio.sys -- (AEAudio [On_Demand | Running])
DRV - [2008-03-21 17:13:00 | 01,203,776 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\DRIVERS\AGRSM.sys -- (AgereSoftModem [On_Demand | Running])
DRV - [2009-01-24 01:00:05 | 01,287,552 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\DRIVERS\bcmwl5.sys -- (BCM43XX [On_Demand | Running])
DRV - [2008-06-16 15:28:36 | 00,242,320 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\DRIVERS\e1e5132.sys -- (e1express [On_Demand | Running])
DRV - [2008-08-05 13:56:27 | 00,007,808 | R--- | M] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\system32\DRIVERS\eabfiltr.sys -- (eabfiltr [On_Demand | Stopped])
DRV - [2008-08-05 13:56:27 | 00,005,760 | R--- | M] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\system32\DRIVERS\eabusb.sys -- (eabusb [On_Demand | Stopped])
DRV - [2008-08-05 13:56:27 | 00,009,344 | R--- | M] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\system32\DRIVERS\cpqbttn.sys -- (HBtnKey [On_Demand | Running])
DRV - [2008-07-18 02:34:58 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2008-03-17 22:45:50 | 05,955,872 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\DRIVERS\igxpmp32.sys -- (ialm [On_Demand | Running])
DRV - [2008-04-15 18:53:44 | 00,312,344 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\DRIVERS\iaStor.sys -- (iaStor [Boot | Running])
DRV - [2007-09-10 09:50:56 | 00,457,984 | ---- | M] (PixArt Imaging Inc.) -- C:\WINDOWS\system32\DRIVERS\PAC7302.SYS -- (PAC7302 [On_Demand | Stopped])
DRV - [2008-06-16 15:28:36 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008-11-02 10:44:10 | 00,056,572 | ---- | M] (PowerISO Computing, Inc.) -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu [System | Running])
DRV - [2008-06-16 15:28:36 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2008-06-16 15:28:36 | 00,062,208 | ---- | M] (Silicon Image, Inc.) -- C:\WINDOWS\System32\drivers\si3112.sys -- (Si3112 [Boot | Running])
DRV - [2009-05-08 09:59:13 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2008-03-27 19:14:06 | 00,224,672 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\DRIVERS\SynTP.sys -- (SynTP [On_Demand | Running])
[color=orange]========== Standard Registry (SafeList) ==========[/color]
[color=orange]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.google.com/toolbar/ie8/intl/pl/done.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009-02-11 11:12:46 | 00,000,000 | ---D | M]
O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 NtKrnlpa.info
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (FG2CatchUrl) - {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} - E:\FlashGet universal\ComDlls\bhoCATCH.dll (FlashGet)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [FlashGet] "E:\FlashGet universal\FlashGet.exe" /min (FLASHGET)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [AlcoholAutomount] "D:\Alcohol 120\axcmd.exe" /automount (Alcohol Soft Development Team)
O4 - HKCU..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" ()
O4 - HKCU..\Run: [FlashGet] "E:\FlashGet universal\FlashGet.exe" /min (FLASHGET)
O4 - HKCU..\Run: [Gadu-Gadu] "D:\Program Files\Gadu-Gadu\gg.exe" /tray (Gadu-Gadu S.A.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MaxRecentDocs = 15
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &Download All by FlashGet - E:\FlashGet universal\ComDlls\Bhoall.htm ()
O8 - Extra context menu item: &Download by FlashGet - E:\FlashGet universal\ComDlls\Bholink.htm ()
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1232753346448 (WUWebControl Class)
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk/6u12-b04/jinstall-6u12-windows-i586-jc.cab?e=1234343566593&h=a6bb13a66e4457c8b384a908cee654c3/&filename=jinstall-6u12-windows-i586-jc.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{BCFAB08F-6A08-4814-8C80-FBF0EACB619E}\\NameServer = 172.16.1.1,172.16.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{E2F11D32-17D2-4E6E-A3CA-254394DE9D68}\\NameServer = 172.16.1.1,172.16.2.1
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (%SystemRoot%\system32\logonui.exe) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Bieżąca strona główna) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-01-24 00:40:38 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001-03-01 10:05:20 | 00,000,079 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ]
O32 - AutoRun File - [1998-12-08 05:36:38 | 00,712,704 | R--- | M] () - H:\Autoplay.exe -- [ CDFS ]
O32 - AutoRun File - [1998-11-25 17:23:22 | 00,000,053 | R--- | M] () - H:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\autoplay.exe -- [1998-12-08 05:36:38 | 00,712,704 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009-05-17 21:35:03 | 00,000,000 | ---D | M]
[color=orange]========== Files/Folders - Created Within 30 Days ==========[/color]
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009-05-17 21:35:03 | 00,509,440 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe
[2009-05-17 19:08:02 | 00,000,663 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\fix.reg
[2009-05-15 11:44:25 | 00,073,107 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\oplaty_za_studia_niestacjonarne.pdf
[2009-05-14 23:35:58 | 00,099,862 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\196878801 _ Gaia.rep
[2009-05-13 08:58:03 | 00,065,641 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\CV Bartosz Gawroński.pdf
[2009-05-13 08:55:08 | 00,000,043 | ---- | C] () -- C:\WINDOWS\gswin32.ini
[2009-05-12 08:01:35 | 00,115,300 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\IMG_5103.JPG
[2009-05-11 14:08:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Pulpit\MWC03-finals
[2009-05-10 20:05:57 | 12,734,754 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\Myth2_160.exe
[2009-05-10 19:52:11 | 00,562,619 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\MWC03-finals.zip
[2009-05-10 18:26:37 | 00,000,000 | ---D | C] -- C:\Program Files\Myth II
[2009-05-10 18:25:33 | 00,026,658 | ---- | C] () -- C:\WINDOWS\_detmp.1
[2009-05-10 17:58:59 | 00,000,486 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\MYTH2.mds
[2009-05-10 17:57:01 | 73,452,4896 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\MYTH2.mdf
[2009-05-09 01:16:32 | 00,000,000 | ---D | C] -- C:\Program Files\ALLPlayer
[2009-05-08 10:01:37 | 00,000,473 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Alcohol 120%.lnk
[2009-05-08 09:59:13 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009-05-08 00:34:45 | 00,305,664 | ---- | C] (InstallShield Corporation, Inc.) -- C:\WINDOWS\uninst.exe
[2009-05-07 07:31:07 | 00,000,000 | ---D | C] -- C:\Program Files\ElcomSoft
[2009-05-07 07:30:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Pulpit\archpr
[2009-05-07 01:08:04 | 00,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2009-05-06 20:51:16 | 00,014,533 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\default
[2009-05-06 20:34:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Dane aplikacji\Google
[2009-05-06 18:27:18 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009-05-06 18:23:35 | 00,000,000 | -H-D | C] -- C:\WINDOWS\msdownld.tmp
[2009-05-06 18:23:35 | 00,000,000 | ---D | C] -- C:\Program Files\Google
[2009-05-06 18:23:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Google
[2009-05-06 18:02:15 | 00,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009-05-06 17:19:04 | 00,002,234 | ---- | C] () -- C:\WINDOWS\Opera.INI
[2009-05-06 17:19:04 | 00,000,000 | ---D | C] -- C:\plugin
[2009-05-06 17:14:08 | 00,000,000 | ---D | C] -- C:\Program Files\Opera
[2009-05-06 17:13:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2009-05-06 16:27:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Dane aplikacji\BITS
[2009-05-05 13:42:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Moje dokumenty\spidrmam
[2009-05-04 19:25:16 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2009-05-04 08:21:41 | 00,098,304 | ---- | C] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2009-05-04 08:20:12 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2009-05-03 15:50:38 | 00,038,560 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2009-05-03 15:50:01 | 00,038,560 | ---- | C] () -- C:\WINDOWS\System\zlib.dll
[2009-05-02 20:27:24 | 00,000,000 | ---D | C] -- C:\Program Files\NAPI-PROJEKT
[2009-04-27 20:14:09 | 00,000,104 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\Komputer.lnk
[2009-04-27 15:23:07 | 00,000,658 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\StarCraft Brood War.lnk
[2009-04-27 15:23:07 | 00,000,585 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\StarCraft Key Changer.lnk
[2009-04-27 11:14:32 | 98,259,105 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\moniscbw.exe
[2009-04-27 10:49:15 | 00,001,644 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\ICCup Launcher.lnk
[2009-04-27 10:49:15 | 00,000,000 | ---D | C] -- C:\Program Files\ICCup
[2009-04-23 18:05:54 | 00,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
[2009-04-23 18:05:54 | 00,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbscan.sys
[2009-04-23 18:05:54 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
[2009-04-23 16:43:25 | 00,000,000 | ---D | C] -- C:\WINDOWS\speech
[2009-04-23 16:43:15 | 00,000,000 | ---D | C] -- C:\Program Files\ivo
[2009-04-21 10:38:11 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Progs_.ini
[2009-04-21 10:38:11 | 00,000,000 | ---- | C] () -- C:\WINDOWS\1Way.ini
[2009-04-21 10:20:03 | 00,000,000 | ---D | C] -- C:\Program Files\gs
[2009-04-21 10:14:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Dane aplikacji\WordToPDF Pro
[2009-04-21 10:14:30 | 00,000,000 | ---D | C] -- C:\Program Files\WordToPDF Pro
[2009-04-21 10:04:02 | 00,000,000 | ---D | C] -- C:\Program Files\CZ-Doc2Pdf
[2009-04-21 09:59:36 | 00,000,000 | ---D | C] -- C:\Program Files\MSECache
[2009-04-21 09:42:06 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\User\Moje dokumenty\~$ Bartosz Gawroński.doc
[2009-04-21 09:41:50 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\User\Moje dokumenty\~$st_Motywacyjny..doc
[2009-04-21 09:41:43 | 00,039,936 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\CV Bartosz Gawroński.doc
[2009-04-21 09:41:43 | 00,025,600 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\List_Motywacyjny..doc
[2009-04-20 16:31:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Pulpit\mapy do fot
[2009-03-07 22:56:51 | 00,000,768 | ---- | C] () -- C:\WINDOWS\System32\Remover.ini
[2009-02-21 21:53:45 | 00,000,715 | ---- | C] () -- C:\WINDOWS\Stars.ini
[2009-02-15 19:16:29 | 00,000,129 | ---- | C] () -- C:\WINDOWS\festo.ini
[2009-02-11 13:55:05 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2009-02-11 13:55:05 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2009-02-11 13:55:05 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2009-02-08 17:25:05 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009-01-24 08:37:53 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009-01-24 08:37:51 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009-01-24 08:37:51 | 00,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009-01-24 08:37:51 | 00,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009-01-24 08:37:50 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009-01-24 08:37:50 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009-01-24 08:27:05 | 00,000,427 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009-01-24 01:04:21 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4935.dll
[2008-07-20 02:16:28 | 00,000,107 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2008-06-16 15:28:36 | 00,000,683 | ---- | C] () -- C:\WINDOWS\win.ini
[2008-06-16 15:28:36 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2007-03-20 17:44:02 | 00,000,566 | ---- | C] () -- C:\WINDOWS\System32\SP7302.ini
[color=orange]========== Files - Modified Within 30 Days ==========[/color]
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009-05-17 21:35:17 | 00,509,440 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe
[2009-05-17 21:32:42 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-05-17 21:32:15 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-05-17 21:32:11 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\desktop.ini
[2009-05-17 21:32:09 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-05-17 21:32:04 | 21,383,61856 | -HS- | M] () -- C:\hiberfil.sys
[2009-05-17 19:08:02 | 00,000,663 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\fix.reg
[2009-05-16 15:06:03 | 00,000,129 | ---- | M] () -- C:\WINDOWS\festo.ini
[2009-05-15 11:44:25 | 00,073,107 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\oplaty_za_studia_niestacjonarne.pdf
[2009-05-14 23:36:00 | 00,099,862 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\196878801 _ Gaia.rep
[2009-05-13 08:58:03 | 00,065,641 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\CV Bartosz Gawroński.pdf
[2009-05-13 08:57:50 | 00,039,936 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\CV Bartosz Gawroński.doc
[2009-05-13 08:55:08 | 00,000,043 | ---- | M] () -- C:\WINDOWS\gswin32.ini
[2009-05-11 22:40:19 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-05-10 20:10:22 | 12,734,754 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\Myth2_160.exe
[2009-05-10 19:52:28 | 00,562,619 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\MWC03-finals.zip
[2009-05-10 18:08:26 | 00,026,658 | ---- | M] () -- C:\WINDOWS\_detmp.1
[2009-05-08 10:01:37 | 00,000,473 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Alcohol 120%.lnk
[2009-05-08 09:59:13 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009-05-06 20:51:17 | 00,014,533 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\default
[2009-05-06 20:32:13 | 00,000,072 | -HS- | M] () -- C:\Documents and Settings\User\Moje dokumenty\desktop.ini
[2009-05-06 18:02:15 | 00,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2009-05-06 17:22:53 | 00,002,234 | ---- | M] () -- C:\WINDOWS\Opera.INI
[2009-05-04 08:21:41 | 00,098,304 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2009-04-28 08:21:19 | 00,000,658 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\StarCraft Brood War.lnk
[2009-04-28 08:21:19 | 00,000,585 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\StarCraft Key Changer.lnk
[2009-04-27 20:14:09 | 00,000,104 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\Komputer.lnk
[2009-04-27 15:08:43 | 98,259,105 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\moniscbw.exe
[2009-04-27 11:16:07 | 00,001,644 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\ICCup Launcher.lnk
[2009-04-21 10:38:11 | 00,000,000 | ---- | M] () -- C:\WINDOWS\Progs_.ini
[2009-04-21 10:38:11 | 00,000,000 | ---- | M] () -- C:\WINDOWS\1Way.ini
[2009-04-21 09:56:31 | 00,025,600 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\List_Motywacyjny..doc
[2009-04-21 09:51:31 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\User\Moje dokumenty\~$ Bartosz Gawroński.doc
[2009-04-21 09:41:50 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\User\Moje dokumenty\~$st_Motywacyjny..doc
[2009-04-20 16:37:02 | 00,002,533 | ---- | M] () -- C:\bos.cfg
< End of report >
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 23 gości