

pare dni mialem problem z wejsciem na dysk c lub d z poziomu mojego komputera - wyskakuje mi komunikat Outposta ze program probuje zmodyfikowac pliki systemowe, potem kolejny ze probuje uruchomic proces z dostepem do sieci. puscilem skana hijackiem i usunalem olhrwef.exe - myslalem ze juz bedzie dobrze ale niestety nie i tu sie zwracam z prosba do was. troszke poszperalem po forum i sprobowalem tego i owego, po uruchomieniu SDFix'a dzialanie sytemu nieco sie poprawilo ale dalej wyskakuja komunikaty przy wchodzieniu na dyski i wciaz nie ma plikow ukrytych, oto log:
- Kod: Zaznacz wszystko
[b]SDFix: Version 1.240 [/b]
Run by TXP on 2009-07-04 at 11:38
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Restoring Default ScreenSaver value
Restoring Missing Security Center Service
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\system32\blphcg8kj0el51.scr - Deleted
C:\autorun.inf - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-04 12:03:14
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:b0727fa0
"s2"=dword:bfb94333
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:50,5a,c8,60,fc,9e,f0,6d,ce,2c,05,4e,f3,6e,12,dc,b0,5e,31,18,5f,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,df,ba,b6,5a,a5,14,8d,b2,fb,c4,a0,cd,61,9f,5d,46,01,..
"khjeh"=hex:7a,ec,74,e7,8e,d3,50,a4,bd,55,b3,d2,f0,03,53,9b,fc,fe,6f,2f,9f,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:67,48,20,fc,62,2d,46,df,27,b8,f8,5d,ec,76,9a,23,bf,57,d8,36,67,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:50,5a,c8,60,fc,9e,f0,6d,ce,2c,05,4e,f3,6e,12,dc,b0,5e,31,18,5f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,df,ba,b6,5a,a5,14,8d,b2,fb,c4,a0,cd,61,9f,5d,46,01,..
"khjeh"=hex:7a,ec,74,e7,8e,d3,50,a4,bd,55,b3,d2,f0,03,53,9b,fc,fe,6f,2f,9f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:67,48,20,fc,62,2d,46,df,27,b8,f8,5d,ec,76,9a,23,bf,57,d8,36,67,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[b]Remaining Files [/b]:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Tue 30 Jun 2009 108,386 ..SHR --- "C:\2nuk.com"
Thu 2 Jul 2009 106,352 ..SHR --- "C:\cj1m.com"
Tue 30 Jun 2009 107,917 ..SHR --- "C:\hifdmgt.com"
Mon 29 Jun 2009 106,931 ..SHR --- "C:\n0euybx.exe"
Mon 8 Dec 2008 0 ..SH. --- "C:\WINDOWS\SB2DF70A4.tmp"
Mon 17 Mar 2008 126,976 A..H. --- "C:\Documents and Settings\NetworkService\NTUSER.bak"
Mon 17 Mar 2008 1,048,576 A..H. --- "C:\Documents and Settings\TXP\NTUSER.bak"
Fri 3 Jul 2009 105,984 ..SHR --- "C:\WINDOWS\system32\nmdfgds0.dll"
Thu 2 Jul 2009 105,984 ..SHR --- "C:\WINDOWS\system32\nmdfgds1.dll"
Thu 2 Jul 2009 106,352 ..SHR --- "C:\WINDOWS\system32\olhrwef.exe"
Sun 24 May 2009 10,053,112 A..H. --- "C:\Program Files\Google\Picasa3\setup.exe"
Mon 17 Mar 2008 262,144 A..H. --- "C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.bak"
Mon 17 Mar 2008 262,144 A..H. --- "C:\Documents and Settings\TXP\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.bak"
[b]Finished![/b]
ktos jeszcze otrzymal rade zeby wkleic loga z OTL'a wiec od razu tez wrzucam
- Kod: Zaznacz wszystko
OTL logfile created on: 2009-07-04 12:56:29 - Run 2
OTL by OldTimer - Version 3.0.6.4 Folder = C:\Documents and Settings\TXP\Pulpit
Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
510,73 Mb Total Physical Memory | 79,95 Mb Available Physical Memory | 15,65% Memory free
1,23 Gb Paging File | 0,82 Gb Available in Paging File | 66,27% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 45,27 Gb Total Space | 2,89 Gb Free Space | 6,38% Space Free | Partition Type: NTFS
Drive D: | 29,26 Gb Total Space | 3,25 Gb Free Space | 11,11% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 44,46 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: 620450A6811A41F
Current User Name: TXP
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2007-12-06 22:03:41 | 00,660,768 | ---- | M] (ABBYY (BIT Software)) -- C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
PRC - [2007-01-15 16:12:35 | 01,549,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2008-02-14 19:27:38 | 00,314,584 | R--- | M] (cFos Software GmbH) -- C:\Program Files\cFosSpeed\spd.exe
PRC - [2008-11-14 23:11:18 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2008-03-17 19:48:24 | 00,552,064 | ---- | M] (Eset ) -- C:\Program Files\Eset\nod32krn.exe
PRC - [2007-01-12 23:47:22 | 00,707,344 | ---- | M] (O&O Software GmbH) -- C:\WINDOWS\System32\oodag.exe
PRC - [2008-03-17 19:48:24 | 00,949,376 | ---- | M] (Eset ) -- C:\Program Files\Eset\nod32kui.exe
PRC - [2008-03-23 12:41:41 | 00,387,584 | ---- | M] () -- C:\Program Files\Labtec Keyboard V5.1\KBDAP32A.EXE
PRC - [2008-02-14 19:27:32 | 00,863,448 | R--- | M] (cFos Software GmbH) -- C:\Program Files\cFosSpeed\cfosspeed.exe
PRC - [2007-05-16 10:27:16 | 00,153,136 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2007-05-16 10:27:28 | 00,271,920 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
PRC - [2007-05-16 10:27:38 | 01,209,904 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2009-06-12 20:20:43 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2005-05-24 23:41:09 | 00,503,808 | ---- | M] (Stamina) -- C:\Program Files\Konnekt\konnekt.exe
PRC - [2009-07-04 12:29:50 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\TXP\Pulpit\OTL.exe
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - [2007-12-06 22:03:41 | 00,660,768 | ---- | M] (ABBYY (BIT Software)) -- C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Professional.9.0 [Auto | Running])
SRV - [2008-08-05 16:50:50 | 01,238,344 | ---- | M] (Agnitum Ltd.) -- C:\Program Files\Agnitum\Outpost Firewall Pro\acs.exe -- (acssrv [Auto | Running])
SRV - [2007-10-24 02:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008-02-14 19:27:38 | 00,314,584 | R--- | M] (cFos Software GmbH) -- C:\Program Files\cFosSpeed\spd.exe -- (cFosSpeedS [Auto | Running])
SRV - [2007-10-24 02:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009-02-04 14:51:05 | 00,655,624 | ---- | M] (Acresso Software Inc.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped])
SRV - [2007-10-09 13:58:12 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008-08-01 00:16:28 | 00,136,120 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2005-11-14 01:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2007-10-11 10:55:10 | 00,864,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008-11-14 23:11:18 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2007-10-11 10:55:14 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007-05-16 10:27:28 | 00,271,920 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Running])
SRV - [2008-03-17 19:48:24 | 00,552,064 | ---- | M] (Eset ) -- C:\Program Files\Eset\nod32krn.exe -- (NOD32krn [Auto | Running])
SRV - [2006-10-22 13:22:00 | 00,159,810 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Disabled | Stopped])
SRV - [2007-01-12 23:47:22 | 00,707,344 | ---- | M] (O&O Software GmbH) -- C:\WINDOWS\System32\oodag.exe -- (O&O Defrag [Auto | Running])
SRV - [2006-10-26 20:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006-10-26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2007-06-15 16:55:00 | 00,300,544 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer [On_Demand | Stopped])
SRV - File not found -- -- (UPHClean [Disabled | Stopped])
SRV - [2006-12-01 12:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2008-08-14 08:57:42 | 00,074,720 | ---- | M] (Adobe Systems, Inc.) -- C:\WINDOWS\System32\drivers\adfs.sys -- (adfs [Auto | Running])
DRV - [2003-03-13 12:34:48 | 00,100,224 | R--- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\System32\drivers\aeaudio.sys -- (aeaudio [On_Demand | Running])
DRV - [2005-02-23 14:58:56 | 00,011,776 | ---- | M] (Arcsoft, Inc.) -- C:\WINDOWS\System32\drivers\Afc.sys -- (Afc [On_Demand | Running])
DRV - [2008-06-30 18:16:00 | 00,030,864 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\System32\DRIVERS\afw.sys -- (afw [On_Demand | Running])
DRV - [2008-06-30 18:16:14 | 00,234,640 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\System32\drivers\afwcore.sys -- (afwcore [On_Demand | Running])
DRV - [2008-03-17 19:48:24 | 00,512,096 | ---- | M] (Eset ) -- C:\WINDOWS\system32\drivers\amon.sys -- (AMON [Auto | Running])
DRV - [2008-07-11 16:42:08 | 00,033,408 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\System32\Filt\ASWFilt.dll -- (ASWFilt [On_Demand | Stopped])
DRV - File not found -- -- (catchme [On_Demand | Running])
DRV - [2008-02-14 19:27:42 | 00,715,992 | R--- | M] (cFos Software GmbH) -- C:\WINDOWS\System32\DRIVERS\cfosspeed.sys -- (cFosSpeed [On_Demand | Running])
DRV - [2006-02-26 17:19:20 | 00,147,456 | ---- | M] (3Com Corporation) -- C:\WINDOWS\System32\DRIVERS\EL2K_XP.sys -- (EL2000 [On_Demand | Running])
DRV - [2007-02-16 02:57:04 | 00,034,760 | ---- | M] (SlySoft, Inc.) -- C:\WINDOWS\System32\Drivers\ElbyCDFL.sys -- (ElbyCDFL [On_Demand | Running])
DRV - [2007-08-07 21:48:33 | 00,025,160 | ---- | M] (Elaborate Bytes AG) -- C:\WINDOWS\System32\Drivers\ElbyCDIO.sys -- (ElbyCDIO [System | Running])
DRV - [2006-07-19 13:27:26 | 00,013,568 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\System32\DRIVERS\L8042Kbd.sys -- (L8042Kbd [On_Demand | Running])
DRV - [2007-02-22 11:15:56 | 00,137,216 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcd.sys -- (nmwcd [On_Demand | Stopped])
DRV - [2007-02-22 11:15:14 | 00,008,320 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdc.sys -- (nmwcdc [On_Demand | Stopped])
DRV - [2007-02-22 11:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdcj.sys -- (nmwcdcj [On_Demand | Stopped])
DRV - [2007-02-22 11:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdcm.sys -- (nmwcdcm [On_Demand | Stopped])
DRV - [2008-03-17 19:48:24 | 00,015,424 | ---- | M] () -- C:\WINDOWS\system32\drivers\nod32drv.sys -- (nod32drv [System | Running])
DRV - [2006-10-22 13:22:00 | 03,994,624 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2007-01-31 19:54:54 | 00,047,360 | ---- | M] (VSO Software) -- C:\WINDOWS\System32\Drivers\pcouffin.sys -- (pcouffin [On_Demand | Running])
DRV - [2006-11-08 00:02:36 | 00,021,760 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\point32.sys -- (Point32 [On_Demand | Running])
DRV - [2004-05-05 22:48:40 | 00,004,228 | ---- | M] (PowerQuest Corporation) -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv [System | Running])
DRV - [2004-03-09 11:45:49 | 00,077,184 | ---- | M] (Protection Technology) -- C:\WINDOWS\System32\drivers\prodrv06.sys -- (prodrv06 [System | Running])
DRV - [2004-03-09 12:18:09 | 00,065,504 | ---- | M] (Protection Technology) -- C:\WINDOWS\System32\drivers\prohlp02.sys -- (prohlp02 [Boot | Running])
DRV - [2003-09-06 14:22:08 | 00,006,944 | ---- | M] (Protection Technology) -- C:\WINDOWS\System32\drivers\prosync1.sys -- (prosync1 [Boot | Running])
DRV - [2001-08-18 00:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008-07-11 16:41:28 | 00,673,920 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\System32\DRIVERS\SandBox.sys -- (SandBox [System | Running])
DRV - [2008-08-02 22:48:03 | 00,163,644 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [Auto | Running])
DRV - [2004-04-26 04:49:56 | 00,381,056 | ---- | M] (Sensaura) -- C:\WINDOWS\System32\drivers\senfilt.sys -- (senfilt [On_Demand | Stopped])
DRV - [2003-12-01 17:20:52 | 00,004,832 | ---- | M] (Protection Technology) -- C:\WINDOWS\System32\drivers\sfhlp01.sys -- (sfhlp01 [Boot | Running])
DRV - [2003-06-02 07:42:14 | 00,578,304 | R--- | M] (Analog Devices, Inc.) -- C:\WINDOWS\System32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])
DRV - [2006-09-24 15:28:47 | 00,005,248 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\system32\speedfan.sys -- (speedfan [Boot | Running])
DRV - [2008-03-26 21:29:49 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.pl
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\G, = http://www.google.pl/search?q=%s
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.startup.homepage: "http://www.google.pl/ig?hl=pl"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2
FF - prefs.js..extensions.enabledItems: autopager@mozilla.org:0.5.2.2
FF - prefs.js..extensions.enabledItems: {40520fe7-6336-4df2-bab1-1f1f8e11bf27}:0.3
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5
FF - prefs.js..extensions.enabledItems: faviconizetab@espion.just-size.jp:0.9.8.2
FF - prefs.js..extensions.enabledItems: firegestures@xuldev.org:1.5.1
FF - prefs.js..extensions.enabledItems: max@subfighter.com:1.0.2
FF - prefs.js..extensions.enabledItems: {b66bc4c3-6d25-4a10-8c59-01daa9063051}:1.5.1
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1
FF - prefs.js..extensions.enabledItems: {6e84150a-d526-41f1-a480-a67d3fed910d}:1.4.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}:6.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {2a4ea141-f5c9-413d-9d11-af76170d33cb}:0.4
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.0.8
FF - prefs.js..extensions.enabledItems: {4217f6d7-406e-4b66-856d-d1a373e4f41a}:2.6.42
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.7.3
FF - prefs.js..extensions.enabledItems: {139a120b-c2ea-41d2-bf70-542d9f063dfd}:2.02.3
FF - prefs.js..extensions.enabledItems: youplayer@addons.mozilla.org:0.9.8
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008-11-14 23:11:18 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-06-15 04:29:17 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-06-12 20:20:47 | 00,000,000 | ---D | M]
[2008-12-07 15:44:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Extensions
[2008-12-07 15:44:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-07-04 01:20:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions
[2008-10-17 09:08:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\{139a120b-c2ea-41d2-bf70-542d9f063dfd}
[2009-04-12 23:20:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\{2a4ea141-f5c9-413d-9d11-af76170d33cb}
[2008-06-01 12:51:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\{40520fe7-6336-4df2-bab1-1f1f8e11bf27}
[2009-06-29 15:06:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\{4217f6d7-406e-4b66-856d-d1a373e4f41a}
[2009-06-13 16:44:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2009-05-28 13:32:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2009-04-09 10:31:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\{b66bc4c3-6d25-4a10-8c59-01daa9063051}
[2008-03-20 03:02:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\{c36177c0-224a-11da-8cd6-0800200c9a66}
[2009-04-16 18:10:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-05-03 00:30:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2008-11-23 19:58:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2009-02-19 17:15:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2009-06-29 15:06:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\autopager@mozilla.org
[2008-06-20 19:44:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\faviconizetab@espion.just-size.jp
[2009-06-29 15:06:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\firegestures@xuldev.org
[2008-12-02 14:04:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\max@subfighter.com
[2008-05-26 00:55:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TXP\Dane aplikacji\mozilla\Firefox\Profiles\sy4fdsjm.default\extensions\youplayer@addons.mozilla.org
[2009-07-04 01:20:41 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-06-12 20:20:47 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008-03-17 19:58:49 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
[2008-11-14 23:11:35 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2009-06-12 20:20:42 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-06-12 20:20:42 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007-04-10 17:21:08 | 00,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2008-11-14 23:11:18 | 00,410,976 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2006-12-12 11:48:22 | 01,440,560 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009-06-12 20:20:45 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006-10-26 21:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2007-05-10 22:52:00 | 00,095,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009-02-19 16:28:01 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009-02-19 16:28:01 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009-02-19 16:28:01 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009-02-19 16:28:01 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009-02-19 16:28:01 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009-02-19 16:28:01 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009-02-19 16:28:01 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2006-06-03 18:43:22 | 00,000,896 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2008-04-03 19:19:08 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2008-04-16 06:08:20 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2007-03-31 19:11:54 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2006-06-03 18:43:22 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2008-03-28 23:36:04 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2007-01-05 13:40:56 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IE7pro BHO) - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7pro.dll (IE7pro.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (FGCatchUrl) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll (www.flashget.com)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Licence] C:\WINDOWS\System32\Licence.exe ()
O4 - HKLM..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe (Eset )
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall Pro\feedback.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [OutpostMonitor] C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [Vistadrv] C:\Program Files\VistaDrives\vsdrv.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [cdoosoft] C:\Documents and Settings\TXP\Ustawienia lokalne\Temp\olhrwef.exe ()
O4 - HKCU..\Run: [CFosSpeed] C:\Program Files\cFosSpeed\cfosspeed.exe (cFos Software GmbH)
O4 - HKCU..\Run: [Labtec Keyboard] C:\Program Files\Labtec Keyboard V5.1\KBDAP32A.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceClassicControlPanel = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoExpandedNewMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTaskGrouping = 1
O8 - Extra context menu item: &Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm ()
O8 - Extra context menu item: &Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll (IE7pro.com)
O9 - Extra 'Tools' menuitem : IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll (IE7pro.com)
O9 - Extra Button: Ustawienia Outpost Firewall Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall Pro\ie_bar.dll (Agnitum Ltd.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\imon.dll (Eset )
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} Reg Error: Key error. (Reg Error: Value error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 80.244.140.241 89.228.6.83
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~1\agnitum\outpos~1\wl_hook.dll) - c:\Program Files\Agnitum\Outpost Firewall Pro\wl_hook.dll (Agnitum Ltd.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe ()
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-03-17 19:03:11 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008-04-09 00:28:17 | 00,000,000 | ---D | M] - C:\Automap -- [ NTFS ]
O32 - AutoRun File - [2009-07-04 11:32:59 | 00,000,061 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2004-06-24 00:40:52 | 00,000,050 | R--- | M] () - F:\autorun.bat -- [ CDFS ]
O32 - AutoRun File - [2004-06-24 00:28:58 | 00,000,029 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{05e1cfd5-f447-11dc-bab2-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{05e1cfd5-f447-11dc-bab2-806d6172696f}\Shell\AutoRun\command - "" = F:\autorun.bat -- [2004-06-24 00:40:52 | 00,000,050 | R--- | M] ()
O33 - MountPoints2\{344aaaef-f52d-11dd-8390-000c6e9d438a}\Shell\AutoRun\command - "" = G:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\system32.exe -- File not found
O33 - MountPoints2\{344aaaef-f52d-11dd-8390-000c6e9d438a}\Shell\open\command - "" = G:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\system32.exe -- File not found
O33 - MountPoints2\{3e8c99ee-656c-11de-8588-000c6e9d438a}\Shell\AutoRun\command - "" = G:\n0euybx.exe -- File not found
O33 - MountPoints2\{3e8c99ee-656c-11de-8588-000c6e9d438a}\Shell\open\Command - "" = G:\n0euybx.exe -- File not found
O33 - MountPoints2\{b9b8c5b3-f456-11dc-80e0-000c6e9d438a}\Shell\AutoRun\command - "" = D:\3j2h0tf.bat -- [2009-07-03 23:25:39 | 00,107,500 | RHS- | M] ()
O33 - MountPoints2\{b9b8c5b3-f456-11dc-80e0-000c6e9d438a}\Shell\open\Command - "" = D:\3j2h0tf.bat -- [2009-07-03 23:25:39 | 00,107,500 | RHS- | M] ()
O33 - MountPoints2\C\Shell\AutoRun\command - "" = C:\3j2h0tf.bat -- [2009-07-03 23:25:39 | 00,107,500 | RHS- | M] ()
O33 - MountPoints2\C\Shell\open\Command - "" = C:\3j2h0tf.bat -- [2009-07-03 23:25:39 | 00,107,500 | RHS- | M] ()
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\3j2h0tf.bat -- [2009-07-03 23:25:39 | 00,107,500 | RHS- | M] ()
O33 - MountPoints2\D\Shell\open\Command - "" = D:\3j2h0tf.bat -- [2009-07-03 23:25:39 | 00,107,500 | RHS- | M] ()
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\autorun.bat -- [2004-06-24 00:40:52 | 00,000,050 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O Software GmbH)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[4 C:\WINDOWS\*.tmp files]
[2009-07-04 12:29:27 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\TXP\Pulpit\OTL.exe
[2009-07-04 12:22:15 | 00,000,000 | ---D | C] -- C:\Program Files\trend micro
[2009-07-04 12:22:07 | 00,000,000 | ---D | C] -- C:\rsit
[2009-07-04 12:21:30 | 00,781,909 | ---- | C] () -- C:\Documents and Settings\TXP\Pulpit\RSIT.exe
[2009-07-04 11:48:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TXP\Dane aplikacji\WinRAR
[2009-07-04 11:37:27 | 00,578,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2009-07-04 11:35:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2009-07-04 10:55:14 | 00,000,000 | ---D | C] -- C:\SDFix
[2009-07-04 10:54:14 | 01,529,241 | ---- | C] () -- C:\Documents and Settings\TXP\Pulpit\SDFix.exe
[2009-07-03 23:46:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TXP\Pulpit\ekonomeria
[2009-07-03 23:43:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TXP\Pulpit\Miarecka
[2009-07-03 23:26:07 | 00,107,500 | RHS- | C] () -- C:\3j2h0tf.bat
[2009-07-02 21:29:24 | 00,136,192 | ---- | C] () -- C:\Documents and Settings\TXP\Moje dokumenty\ekonomia menedzerska dl czesc 2.doc
[2009-07-02 19:13:33 | 00,381,440 | ---- | C] () -- C:\Documents and Settings\TXP\Moje dokumenty\ekonomia menedzerska w2.doc
[2009-07-02 18:35:01 | 02,145,889 | ---- | C] () -- C:\Documents and Settings\TXP\Pulpit\(11529) wsip_R_I-VII.pdf
[2009-07-02 18:34:54 | 00,091,648 | ---- | C] () -- C:\Documents and Settings\TXP\Pulpit\(12430) tows_swot.xls
[2009-07-02 18:33:53 | 00,034,304 | ---- | C] () -- C:\Documents and Settings\TXP\Pulpit\(12565) Projekt ze strategii.doc
[2009-07-02 18:13:50 | 00,106,352 | RHS- | C] () -- C:\cj1m.com
[2009-07-01 18:07:29 | 00,106,656 | RHS- | C] () -- C:\ix8bmwx.bat
[2009-06-30 19:55:54 | 00,107,917 | RHS- | C] () -- C:\hifdmgt.com
[2009-06-30 13:54:40 | 00,108,386 | RHS- | C] () -- C:\2nuk.com
[2009-06-30 13:54:14 | 00,105,984 | RHS- | C] () -- C:\WINDOWS\System32\nmdfgds1.dll
[2009-06-30 13:53:58 | 00,106,931 | RHS- | C] () -- C:\n0euybx.exe
[2009-06-30 13:53:31 | 00,106,352 | RHS- | C] () -- C:\WINDOWS\System32\olhrwef.exe
[2009-06-30 13:53:31 | 00,105,984 | RHS- | C] () -- C:\WINDOWS\System32\nmdfgds0.dll
[2009-06-30 11:27:50 | 00,103,424 | ---- | C] (MailShare.pl) -- C:\WINDOWS\System32\Http Client_nat.dll
[2009-06-30 11:12:20 | 00,000,000 | ---D | C] -- C:\Program Files\MailShare
[2009-06-29 18:56:55 | 00,013,819 | ---- | C] () -- C:\Documents and Settings\TXP\Moje dokumenty\METODY PŁATNOŚCI.docx
[2009-06-26 12:03:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TXP\Pulpit\Therion - 1997 - A' arab Zaraq Lucid Dreaming
[2009-06-24 19:24:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TXP\Dane aplikacji\SmsDiscount
[2009-06-24 19:21:22 | 00,000,000 | ---D | C] -- C:\Program Files\SmsDiscount.com
[2009-06-23 01:48:58 | 00,012,237 | ---- | C] () -- C:\Documents and Settings\TXP\Pulpit\dolica.docx
[2009-06-17 02:10:35 | 00,000,000 | ---- | C] () -- C:\WINDOWS\glp.INI
[2009-01-12 02:27:12 | 00,000,065 | ---- | C] () -- C:\WINDOWS\FISHUI.INI
[2009-01-12 01:31:07 | 00,921,600 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2009-01-12 01:31:07 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2009-01-12 01:31:06 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2009-01-12 01:31:06 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\Ogg.dll
[2008-10-27 19:05:50 | 00,003,071 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008-10-27 19:05:48 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008-10-06 11:00:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PhEdit.INI
[2008-10-06 10:52:58 | 00,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2008-09-22 14:55:24 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-09-22 00:05:51 | 00,000,559 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2008-07-23 03:12:04 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2008-07-23 03:12:04 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2008-05-29 16:22:32 | 00,000,235 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008-05-29 16:21:04 | 00,002,672 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2008-03-21 13:21:00 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS66.DLL
[2008-03-17 19:56:58 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008-03-17 19:56:58 | 01,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008-03-17 19:56:58 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008-03-17 19:56:58 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008-03-17 19:52:08 | 00,000,014 | ---- | C] () -- C:\WINDOWS\System32\systeminfo3.dll
[2008-03-17 19:48:44 | 00,000,153 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-03-17 19:48:25 | 00,015,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\nod32drv.sys
[2008-03-17 19:46:59 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008-03-17 19:46:57 | 00,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2008-03-17 19:46:46 | 00,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2008-03-17 19:46:16 | 00,143,360 | ---- | C] ( ) -- C:\WINDOWS\System32\ICSharpCode.SharpZipLib.dll
[2008-03-17 19:46:15 | 00,315,392 | ---- | C] () -- C:\WINDOWS\System32\tidylib.dll
[2008-03-17 19:46:15 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\ue32ctmn.dll
[2008-03-17 19:46:10 | 00,409,184 | ---- | C] () -- C:\WINDOWS\System32\WCMICONS.DLL
[2008-03-17 19:46:10 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\WCMZIP32.ORG.DLL
[2008-03-17 19:46:10 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\wcmzip32.dll
[2008-03-17 19:46:09 | 00,157,696 | ---- | C] () -- C:\WINDOWS\System32\UNRAR.DLL
[2008-03-17 19:46:09 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\TCUNZLIB.DLL
[2008-03-17 19:46:09 | 00,077,312 | ---- | C] () -- C:\WINDOWS\System32\UNACEV2.DLL
[2008-03-17 19:46:09 | 00,043,008 | ---- | C] () -- C:\WINDOWS\System32\CABRK.DLL
[2008-03-17 19:46:09 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\FRERES32.DLL
[2008-03-17 19:45:54 | 00,014,828 | ---- | C] () -- C:\WINDOWS\System32\wincmd.ini
[2008-03-17 19:45:54 | 00,003,083 | ---- | C] () -- C:\WINDOWS\System32\ShellDetails.ini
[2008-03-17 19:45:54 | 00,001,419 | ---- | C] () -- C:\WINDOWS\System32\color.ini
[2008-03-17 19:45:54 | 00,001,319 | ---- | C] () -- C:\WINDOWS\System32\DirSizeCalc.ini
[2008-03-17 19:45:54 | 00,001,237 | ---- | C] () -- C:\WINDOWS\System32\visualdirsize.ini
[2008-03-17 19:45:54 | 00,000,636 | ---- | C] () -- C:\WINDOWS\System32\fsplugin.ini
[2008-03-17 19:45:54 | 00,000,347 | ---- | C] () -- C:\WINDOWS\System32\pkplugin.ini
[2008-03-17 19:45:54 | 00,000,055 | ---- | C] () -- C:\WINDOWS\System32\buttonbar.ini
[2008-03-17 19:45:41 | 00,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
[2008-03-17 19:45:41 | 00,000,096 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2008-03-17 19:45:40 | 00,054,784 | ---- | C] () -- C:\WINDOWS\System32\sfextra.dll
[2008-03-17 19:45:38 | 00,003,752 | ---- | C] () -- C:\WINDOWS\RegWorkshop.ini
[2008-03-17 19:45:36 | 01,197,936 | ---- | C] () -- C:\WINDOWS\System32\everest_cpuid.dll
[2008-03-17 19:45:36 | 01,131,888 | ---- | C] () -- C:\WINDOWS\System32\everest_mondiag.dll
[2008-03-17 19:45:36 | 00,256,880 | ---- | C] () -- C:\WINDOWS\System32\everest_rcs.dll
[2008-03-17 19:45:36 | 00,250,736 | ---- | C] () -- C:\WINDOWS\System32\everest_rcc.dll
[2008-03-17 19:45:36 | 00,185,176 | ---- | C] () -- C:\WINDOWS\System32\everest_xpicons.dll
[2008-03-17 19:45:36 | 00,133,968 | ---- | C] () -- C:\WINDOWS\System32\everest_icons.dll
[2008-03-17 19:45:36 | 00,055,160 | ---- | C] () -- C:\WINDOWS\System32\everest_zipdll.dll
[2008-03-17 19:45:31 | 00,135,168 | ---- | C] () -- C:\WINDOWS\System32\VSLWP.DLL
[2008-03-17 19:45:30 | 01,567,232 | ---- | C] () -- C:\WINDOWS\System32\LWPAPIN.DLL
[2008-03-17 19:45:30 | 01,085,440 | ---- | C] () -- C:\WINDOWS\System32\mxlinkdb.dll
[2008-03-17 19:45:30 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\SCSILIB.dll
[2008-03-17 19:45:19 | 00,000,156 | ---- | C] () -- C:\WINDOWS\System32\cpuz.ini
[2008-03-17 19:45:18 | 00,000,063 | ---- | C] () -- C:\WINDOWS\System32\FTPsrv.ini
[2008-03-17 19:25:26 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2007-03-29 23:00:40 | 00,203,264 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
[2001-10-26 18:45:34 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\NSREG.DLL
[2001-07-22 01:16:20 | 00,000,527 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-22 01:15:52 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[4 C:\WINDOWS\*.tmp files]
[2009-07-04 12:29:50 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\TXP\Pulpit\OTL.exe
[2009-07-04 12:21:36 | 00,781,909 | ---- | M] () -- C:\Documents and Settings\TXP\Pulpit\RSIT.exe
[2009-07-04 12:04:53 | 00,003,752 | ---- | M] () -- C:\WINDOWS\RegWorkshop.ini
[2009-07-04 11:47:08 | 00,478,184 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2009-07-04 11:47:07 | 01,055,160 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009-07-04 11:47:07 | 00,420,946 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009-07-04 11:47:07 | 00,079,498 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2009-07-04 11:47:07 | 00,063,788 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009-07-04 11:42:26 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-07-04 11:42:17 | 00,352,401 | ---- | M] () -- C:\WINDOWS\System32\OODBS.lor
[2009-07-04 11:38:33 | 00,000,686 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2009-07-04 11:37:27 | 00,578,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2009-07-04 10:54:54 | 01,529,241 | ---- | M] () -- C:\Documents and Settings\TXP\Pulpit\SDFix.exe
[2009-07-04 10:40:13 | 00,000,527 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-07-04 10:40:13 | 00,000,232 | -HS- | M] () -- C:\boot.ini
[2009-07-04 10:40:13 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-07-03 23:46:53 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-07-03 23:25:39 | 00,107,500 | RHS- | M] () -- C:\3j2h0tf.bat
[2009-07-03 23:24:53 | 00,105,984 | RHS- | M] () -- C:\WINDOWS\System32\nmdfgds0.dll
[2009-07-03 15:31:15 | 00,002,184 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-07-02 21:29:25 | 00,136,192 | ---- | M] () -- C:\Documents and Settings\TXP\Moje dokumenty\ekonomia menedzerska dl czesc 2.doc
[2009-07-02 19:13:37 | 00,381,440 | ---- | M] () -- C:\Documents and Settings\TXP\Moje dokumenty\ekonomia menedzerska w2.doc
[2009-07-02 18:35:17 | 02,145,889 | ---- | M] () -- C:\Documents and Settings\TXP\Pulpit\(11529) wsip_R_I-VII.pdf
[2009-07-02 18:34:55 | 00,091,648 | ---- | M] () -- C:\Documents and Settings\TXP\Pulpit\(12430) tows_swot.xls
[2009-07-02 18:33:54 | 00,034,304 | ---- | M] () -- C:\Documents and Settings\TXP\Pulpit\(12565) Projekt ze strategii.doc
[2009-07-02 18:13:20 | 00,105,984 | RHS- | M] () -- C:\WINDOWS\System32\nmdfgds1.dll
[2009-07-02 18:13:18 | 00,106,352 | RHS- | M] () -- C:\WINDOWS\System32\olhrwef.exe
[2009-07-02 18:13:18 | 00,106,352 | RHS- | M] () -- C:\cj1m.com
[2009-07-02 16:07:45 | 00,002,672 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2009-07-01 18:07:01 | 00,106,656 | RHS- | M] () -- C:\ix8bmwx.bat
[2009-07-01 10:05:42 | 02,323,632 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009-06-30 22:39:13 | 00,066,168 | ---- | M] () -- C:\Documents and Settings\TXP\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2009-06-30 19:55:13 | 00,107,917 | RHS- | M] () -- C:\hifdmgt.com
[2009-06-30 13:54:13 | 00,108,386 | RHS- | M] () -- C:\2nuk.com
[2009-06-30 11:27:50 | 00,103,424 | ---- | M] (MailShare.pl) -- C:\WINDOWS\System32\Http Client_nat.dll
[2009-06-29 18:56:57 | 00,013,819 | ---- | M] () -- C:\Documents and Settings\TXP\Moje dokumenty\METODY PŁATNOŚCI.docx
[2009-06-29 10:00:00 | 00,106,931 | RHS- | M] () -- C:\n0euybx.exe
[2009-06-23 01:48:59 | 00,012,237 | ---- | M] () -- C:\Documents and Settings\TXP\Pulpit\dolica.docx
[2009-06-17 02:10:35 | 00,000,000 | ---- | M] () -- C:\WINDOWS\glp.INI
< End of report >